Try our new research platform with insights from 80,000+ expert users

Cloudflare One vs Forcepoint Next Generation Firewall comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Software Defined WAN (SD-WAN) Solutions
1st
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
587
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Firewalls (1st), Intrusion Detection and Prevention Software (IDPS) (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Cloudflare One
Ranking in Software Defined WAN (SD-WAN) Solutions
13th
Average Rating
8.8
Reviews Sentiment
6.7
Number of Reviews
22
Ranking in other categories
Email Security (20th), Secure Web Gateways (SWG) (15th), Data Loss Prevention (DLP) (21st), Cloud Access Security Brokers (CASB) (11th), Distributed Denial-of-Service (DDoS) Protection (7th), Access Management (12th), Bot Management (3rd), ZTNA as a Service (8th), ZTNA (3rd), Secure Access Service Edge (SASE) (10th), Remote Browser Isolation (RBI) (3rd)
Forcepoint Next Generation ...
Ranking in Software Defined WAN (SD-WAN) Solutions
8th
Average Rating
7.6
Reviews Sentiment
6.4
Number of Reviews
51
Ranking in other categories
Firewalls (19th), WAN Edge (8th)
 

Mindshare comparison

As of March 2026, in the Software Defined WAN (SD-WAN) Solutions category, the mindshare of Fortinet FortiGate is 12.3%, down from 20.0% compared to the previous year. The mindshare of Cloudflare One is 3.5%, up from 1.9% compared to the previous year. The mindshare of Forcepoint Next Generation Firewall is 2.4%, up from 2.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Software Defined WAN (SD-WAN) Solutions Mindshare Distribution
ProductMindshare (%)
Fortinet FortiGate12.3%
Forcepoint Next Generation Firewall2.4%
Cloudflare One3.5%
Other81.8%
Software Defined WAN (SD-WAN) Solutions
 

Featured Reviews

Vasu Gala - PeerSpot reviewer
Manager, Information Technology Operation/Presales at TechMonarch
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
CV
Network Architect at IP Dimension
Cloud security has improved remote access and has reduced costs for smaller client sites
I have used Cloudflare One's Identity-Aware Proxy, and it is quite straightforward from what I have seen so far. The app registration on the Azure side integrates fully into Cloudflare, and I am very satisfied with that part because it is easy to set up. The integration of Cloudflare One's Secure Web Gateway and Zero Trust Network Access works without any issues. That part is pretty automatic, and if you complete the rest of the setup, it comes together by itself with no issues from my side. What makes it nice is that we can actually start replacing on-site firewalls at this stage for the smaller clients because it does not matter if they go to a coffee shop or work from home; they are still secured by the same connection. The hops get shorter and you get better latency. We have done testing to see if it is better. One thing that we did notice with our proof of concept with our current client is that they have people connecting from the UK. When they used their previous VPN solution, uploading CAD drawings and other files to the server took a long time. They mentioned that it is much quicker on Cloudflare One's solution. I definitely believe that is part of the improved performance, and I am satisfied with that as well. What is nice about Cloudflare One is that it makes the setup easier and also easier to train technicians to maintain it. Compared to legacy systems, we do not need to get fancy firewalls in place that are costly. That is definitely also a cost-saver with Cloudflare One.
reviewer2774055 - PeerSpot reviewer
Cybersecurity Engineer at a tech consulting company with 51-200 employees
Improved network segmentation has reduced lateral movement while the interface still needs modernization
For threat prevention, I noticed on another customer that there were repeated scanning and exploit attempts against some public-facing service running on HTTPS. I configured Forcepoint Next Generation Firewall to handle IPS by enabling it with critical and high severity signatures only to reduce false positives. I turned on IP reputation filtering to filter out known malicious networks, applied rate limiting on specific services in the DMZ, and logged events centrally for correlation. As a result, exploit attempts were much less than before, being blocked before reaching the back-end servers from the firewall itself, with no performance degradation on the applications. The security team received clear and actionable logs that were centralized, so they knew what was happening all the time. Strong network segmentation is my favorite feature that Forcepoint Next Generation Firewall offers. The policies are very deterministic and readable, and it has excellent east-west blocking and least privilege architecture. Application awareness identifies traffic beyond just the port itself; I can identify the application using a specific port and block risky applications even if they use allowed ports, which is great for environments with shadow IT. The integrated threat prevention is also very good, with IPS featuring well-tuned signatures and reputation-based filtering that blocks known bad actors before they can touch any applications. It supports both IPsec and SSL VPN tunnels, along with site-to-site, client-to-site, and hybrid cloud links, integrating well with Active Directory and LDAP. Additionally, centralized log management and reporting are very actionable and structured, with clarity in the policies for auditing. Overall, its stability and reliability are commendable. A real example of how Forcepoint Next Generation Firewall's readable policies and application awareness features made my work easier was fixing a flat network problem without breaking actual applications. I inherited an environment where users, application servers, and databases were loosely segmented, with port-based and messy firewall rules. Security audits flagged lateral movement risks, and application owners were scared of outages if I tightened security too much. Forcepoint Next Generation Firewall made it easy by providing very easy-to-read and logical policies. I built policies that are clear, showing communications from the user zone to the application zone to specific applications, or from the app zone to the database zone, using only required database protocols. By default, I applied a deny rule between zones unless explicitly allowed by the readable rules I implemented. The policy view clarified who talks to whom, which rules exist, why they exist, and the business function they support, effectively stopping port abuse. Security posture has definitely improved greatly since using Forcepoint Next Generation Firewall. From a flat or semi-flat network, I now have clear zone-based segmentation, with increased operational efficiency. The admins using the firewall have rules that are easy to read and intent-based, making changes easier to review and approve. There is less fear that one wrong rule could break production and fewer outages caused by security changes, without hidden matches or rule shadowing surprises. Clear hit count visibility helps me clean unused rules, leading to much fewer outages caused by changes on the firewalls. The centralized log management with supported log types provides better visibility for the SOC team and the SIEM team, as Forcepoint Next Generation Firewall sends very easy-to-parse and search clear logs to the SOC team. I did see measurable, defensible results after using Forcepoint Next Generation Firewall, including fewer security incidents reaching the back-end servers. This reduction is due to strong segmentation, application awareness, and IPS features, leading to a 60 to 70 percent reduction in security alerts that actually reach the servers. DMZ exploit attempts dropped to near zero, and no lateral movement incidents were detected post network segmentation. Additionally, overall SOC efficiency improved due to well-structured and contextual logs reflecting clear policy intent, resulting in a 35 to 40 percent reduction in mean time to triage. SOC analysts stopped chasing noise and false positives, as they had much clearer logs to use confidently.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I have found Fortinet FortiGate to be scalable."
"Fortinet FortiGate provides excellent security against ransomware attacks."
"The performance is good."
"It's very good and very stable for businesses. It works very well."
"I am "headache free" that I don't have to categorize all the websites and that security has been pre categorized by the people, and that the services are getting updated. At least one part of my problem is over."
"This solution made it very easy to manage our bandwidth."
"Customers are more inclined towards FortiGate because of application control, web filtering, and anti-spam features. The support from the FortiGate team is good, and price-wise, it is affordable."
"The best features of Fortinet FortiGate are its simplicity, ease of installation, and ease of functionality."
"The blocking feature is very good."
"The solution has different options that can be used to differentiate DDoS attacks."
"Cloudflare, in my opinion, was easy to implement."
"Cloudflare Zero Trust Platform removes the risk of exposing the applications to the public."
"Cloudflare DDoS mitigates DDoS attacks."
"It's the endpoint exposition. We don't need to expose our VPN server to the internet and need a zero-test solution. I can apply some conditional access to the endpoint that's connecting to our network to check their security policies or the security condition of their workstation. Once the workstation is trying to connect to my internal network, then I would like to check the discrete condition of these endpoints that are trying to access my internal network. We created some conditional access. We have CrowdStrike, to check if the CrowdStrike is installed, to check if it's updated, and to check for Windows updates. We created some conditional policies to check it."
"The capabilities of the software are strong enough for me to do what it's supposed to do. For me, we don't need to do a lot of configuration on our site. We just enable it and monitor it."
"I'm very satisfied with the environment and the dashboard."
"The solution offers sandboxing, which can be integrated at any time."
"Forcepoint Next Generation Firewall has positively impacted my organization by providing always-on perimeter security."
"Forcepoint Next Generation Firewall's IPS feature has four operational modes, including IPS, Layer 2 and Layer 3 Firewalls, and the IPS mode offers many controls, profiles, and signatures for inspecting traffic while allowing for applying firewall rules followed by IPS engine inspection so that many decisions including blocking and controlling traffic actions are possible."
"Overall, it is an excellent product, highly reliable, and among the top contenders; Forcepoint Next Generation Firewall is well known."
"The most valuable features of Forcepoint Next Generation Firewall are the advanced threat protection, including features like IPS and DDoS prevention, which help avoid internal DDoS attacks."
"Next Generation Firewall's best feature is that it can be managed on one platform."
"The simplicity of the solution is its most valuable asset. It's very user-friendly."
"The blocking, based on the signal provided, is the solution's most valuable aspect."
 

Cons

"FortiGate IPS is somewhat pricey compared to other solutions. There is also room for improvement in terms of the radio signals. The FortiGate WiFi has a relatively short range. I've found there is a lag in its zero-day malware response that could be better, and FortiGate could integrate better with other brands of equipment or identity management solutions."
"Fortinet should improve its software, as we are seeing lots of firmware versions generated for each vulnerability issue. It becomes difficult for us to keep updating the firmware frequently due to bugs."
"FortiGate can only retain logs for 24 hours or 7 days. I'm not sure if it holds them for a longer period, such as for a month. It will be useful for assessing our strategy and monitoring our environment without investing in FortiGate Analyzer. It would be beneficial if Fortinet could enhance the FortiGate by providing more statistical and monitoring views for a longer timeframe, rather than requiring access to FortiGate Analyzer."
"I would like reporting to be improved and should offer a lot more tools to monitor the products."
"They have not yet extended to the cloud."
"I want some additional features. For example, I want something to ensure that when we are using Google email or Microsoft email, or Google Workspace, emails can only be accessed on designated machines given to our employees. I would like them to access data from designated machines, not from any machine. It should work for designated mobiles and laptops. I don't know if Fortinet provides something like that out of the box."
"Support could be improved."
"It needs more available central management."
"Our customers no longer use Cloudflare because its service is subpar."
"Cloudflare Zero Trust Platform needs to improve its documentation. It took time to do the implementation."
"The pricing is an area that can be improved. Pricing, as far as I recall, was the source of our problems."
"The initial onboarding was causing us some confusion."
"Our subscription plan for the solution has a limitation of bot signatures."
"The onboarding process can be improved a little bit."
"The tool should provide on-premise versions. Currently, all versions are cloud-based."
"The free plan has limitations. For example, I can only set up three rules, and the application firewall is unavailable."
"Making this solution easier to use would be an improvement."
"They should have a GUI on the product itself, not a separate management tool to be used on the management server or on a server to be used to manage the file. It should be all in one device. The device should be controlled through its own GUI. They also have to improve the learning center and the documents as the documents don't really help."
"The ability to dynamically change policies could be improved."
"My experience with this Forcepoint Next Generation Firewall wasn't very pleasant due to its complexity. For example, the firewall loses some features when working in a cluster, which is a huge challenge. It caused me several weeks to solve an issue to make the VPN work, even after opening several cases with support. Also, the debug, which should provide essential knowledge about everything going on, the flow of traffic, and how the engine works, wasn't very informative in identifying the issue."
"Something that I've noticed that Forcepoint lacks, is the training that they offer to their end-customers"
"The company should update the URL filtering database. They need to enhance the URL filtering and make it easier to customize."
"Forcepoint Next Generation Firewall should make some improvements because there is some instability with their software. Sometimes it could lag or become over-utilized, you need to clear some caches and do some restarts, and sometimes some traffic is being blocked and the reason is not entirely clear."
"Forcepoint would be improved if there were more training available."
 

Pricing and Cost Advice

"The price of Fortinet FortiGate could improve, it is expensive."
"The beauty is the price performance ratio is great with FortiGate. It provides all the features we needed and the price is comparable with others' firewalls. The price is quite competitive with the firewalls with similar features."
"In my opinion, the pricing of the product is reasonable."
"The support subscription for the solution is annual. You are paying for support and there are two levels of support, professional and advanced."
"When comparing this solution to others, I would rate it a ten out of ten in terms of pricing. However, the issue of requiring a separate license for redundancy is a drawback, and I would rate it a nine out of ten."
"It is a good product from a price perspective versus functionality."
"FortiGate Next-Generation Firewall is cheaper than Cisco or CheckPoint."
"The price is high compared to some of the other solutions."
"The price tag is no longer $200,000, but rather $300,000 to $400,000. It's twice."
"The solution is not that expensive."
"The prices are slightly expensive."
"The pricing of the solution is cheap. The licensing cost is also very low. I rate the cost and pricing a three out of ten."
"Cloudflare Zero Trust Platform's pricing is good."
"The pricing is somewhere in the middle. I would rate the pricing a seven out of ten."
"The solution's pricing lacks transparency."
"My company has to make yearly payments towards the licensing costs attached to the solution. There are no hidden charges apart from the licensing costs of the solution."
"We have just a subscription for the cloud, and this license is great. The license is so good."
"It requires a yearly subscription."
"There is a license required to use this solution and we can purchase it for one, two, three, or five years."
"Forcepoint is very expensive but it's really secure."
"Next Generation Firewall is moderately priced."
"I consider Forcepoint Next Generation Firewall's price to be good."
"There is a need to make payments towards the licensing charges attached to the product. The product is not expensive."
"The solution is expensive."
report
Use our free recommendation engine to learn which Software Defined WAN (SD-WAN) Solutions solutions are best for your needs.
884,797 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
11%
Comms Service Provider
10%
Manufacturing Company
8%
Financial Services Firm
6%
Comms Service Provider
10%
Computer Software Company
9%
Financial Services Firm
8%
Manufacturing Company
8%
Computer Software Company
10%
Manufacturing Company
10%
Financial Services Firm
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business360
Midsize Enterprise135
Large Enterprise190
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise2
Large Enterprise10
By reviewers
Company SizeCount
Small Business29
Midsize Enterprise10
Large Enterprise12
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What needs improvement with Cloudflare Access?
Cloudflare Access has strong integration with Microsoft, among other platforms. However, when it comes to Kaspersky, ...
What is your primary use case for Cloudflare Access?
Cloudflare Access provides secure access to internal applications for employees, external members of the organization...
What advice do you have for others considering Cloudflare Access?
Cloudflare Access is one of the best integrations available. While about two hundred vendors offer similar services, ...
What is your experience regarding pricing and costs for Forcepoint Next Generation Firewall?
My experience with pricing, setup cost, and licensing is limited because I do not work with pricing, but I have exper...
What needs improvement with Forcepoint Next Generation Firewall?
I found one problem with Forcepoint Next Generation Firewall. They still do not have any VPN clients for Windows comp...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
Cloudflare Area 1 Email Security, Cloudflare Bot Management, Cloudflare Gateway, Cloudflare Zero Trust Platform, Cloudflare DDoS, Cloudflare SASE & SSE Platform
Forcepoint NGFW, Stonesoft Next Generation Firewall, McAfee Network Security Platform, Intel Security Network Security Platform
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
23andMe
California Department of Corrections and Rehabilitation (CDCR)
Find out what your peers are saying about Cloudflare One vs. Forcepoint Next Generation Firewall and other solutions. Updated: March 2026.
884,797 professionals have used our research since 2012.