Try our new research platform with insights from 80,000+ expert users

Forcepoint Next Generation Firewall vs Sangfor NGAF comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 25, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
587
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Forcepoint Next Generation ...
Ranking in Firewalls
19th
Average Rating
7.6
Reviews Sentiment
6.4
Number of Reviews
51
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (8th), WAN Edge (8th)
Sangfor NGAF
Ranking in Firewalls
26th
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
34
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of March 2026, in the Firewalls category, the mindshare of Fortinet FortiGate is 18.3%, down from 21.1% compared to the previous year. The mindshare of Forcepoint Next Generation Firewall is 0.6%, up from 0.4% compared to the previous year. The mindshare of Sangfor NGAF is 1.0%, down from 1.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls Mindshare Distribution
ProductMindshare (%)
Fortinet FortiGate18.3%
Forcepoint Next Generation Firewall0.6%
Sangfor NGAF1.0%
Other80.1%
Firewalls
 

Featured Reviews

Vasu Gala - PeerSpot reviewer
Manager, Information Technology Operation/Presales at TechMonarch
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
reviewer2774055 - PeerSpot reviewer
Cybersecurity Engineer at a tech consulting company with 51-200 employees
Improved network segmentation has reduced lateral movement while the interface still needs modernization
For threat prevention, I noticed on another customer that there were repeated scanning and exploit attempts against some public-facing service running on HTTPS. I configured Forcepoint Next Generation Firewall to handle IPS by enabling it with critical and high severity signatures only to reduce false positives. I turned on IP reputation filtering to filter out known malicious networks, applied rate limiting on specific services in the DMZ, and logged events centrally for correlation. As a result, exploit attempts were much less than before, being blocked before reaching the back-end servers from the firewall itself, with no performance degradation on the applications. The security team received clear and actionable logs that were centralized, so they knew what was happening all the time. Strong network segmentation is my favorite feature that Forcepoint Next Generation Firewall offers. The policies are very deterministic and readable, and it has excellent east-west blocking and least privilege architecture. Application awareness identifies traffic beyond just the port itself; I can identify the application using a specific port and block risky applications even if they use allowed ports, which is great for environments with shadow IT. The integrated threat prevention is also very good, with IPS featuring well-tuned signatures and reputation-based filtering that blocks known bad actors before they can touch any applications. It supports both IPsec and SSL VPN tunnels, along with site-to-site, client-to-site, and hybrid cloud links, integrating well with Active Directory and LDAP. Additionally, centralized log management and reporting are very actionable and structured, with clarity in the policies for auditing. Overall, its stability and reliability are commendable. A real example of how Forcepoint Next Generation Firewall's readable policies and application awareness features made my work easier was fixing a flat network problem without breaking actual applications. I inherited an environment where users, application servers, and databases were loosely segmented, with port-based and messy firewall rules. Security audits flagged lateral movement risks, and application owners were scared of outages if I tightened security too much. Forcepoint Next Generation Firewall made it easy by providing very easy-to-read and logical policies. I built policies that are clear, showing communications from the user zone to the application zone to specific applications, or from the app zone to the database zone, using only required database protocols. By default, I applied a deny rule between zones unless explicitly allowed by the readable rules I implemented. The policy view clarified who talks to whom, which rules exist, why they exist, and the business function they support, effectively stopping port abuse. Security posture has definitely improved greatly since using Forcepoint Next Generation Firewall. From a flat or semi-flat network, I now have clear zone-based segmentation, with increased operational efficiency. The admins using the firewall have rules that are easy to read and intent-based, making changes easier to review and approve. There is less fear that one wrong rule could break production and fewer outages caused by security changes, without hidden matches or rule shadowing surprises. Clear hit count visibility helps me clean unused rules, leading to much fewer outages caused by changes on the firewalls. The centralized log management with supported log types provides better visibility for the SOC team and the SIEM team, as Forcepoint Next Generation Firewall sends very easy-to-parse and search clear logs to the SOC team. I did see measurable, defensible results after using Forcepoint Next Generation Firewall, including fewer security incidents reaching the back-end servers. This reduction is due to strong segmentation, application awareness, and IPS features, leading to a 60 to 70 percent reduction in security alerts that actually reach the servers. DMZ exploit attempts dropped to near zero, and no lateral movement incidents were detected post network segmentation. Additionally, overall SOC efficiency improved due to well-structured and contextual logs reflecting clear policy intent, resulting in a 35 to 40 percent reduction in mean time to triage. SOC analysts stopped chasing noise and false positives, as they had much clearer logs to use confidently.
Zaid Farooqui - PeerSpot reviewer
CIO at Indus Motor Company
Enhanced threat detection with integrated security features and good support
We are using application firewalling, WAF, and SD-WAN. The capabilities are mostly within the box. For example, you will get web application firewall WAF as part and parcel of this. SD-WAN is also bundled. It integrates with their SIEM and SOAR solutions very nicely. Lastly, the pricing point is very cost-efficient as well.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"FortiGate Next Generation Firewall (NGFW) is more realistic in application, allowing for more specific, customized security policies without the extensive work involved with static rules."
"ROI is very high, it has hands-down the best price/performance/features ratio in the market."
"Generally, every aspect of it being a next-generation firewall provides good value."
"FortiGate is flexible and easy to use."
"Fortinet solutions are very easy to implement, proven, certified and tested."
"The most valuable feature of this solution is Quota."
"It's very easy to set up, it's very easy to make policies and, for an organization, that means you don't need IT expert in firewalls. You just need to have somebody who knows a little bit of IT, and that's it. With other products, you need someone with a "Masters" degree in firewalls."
"The best features of Fortinet FortiGate are its simplicity, ease of installation, and ease of functionality."
"Forcepoint's stability is satisfactory, for the most part."
"It provides decent protection for the LAN, especially in run mode."
"We like the scalability of Forcepoint because with the Forcepoint NGFW solution, we can scale anything. The solution has central management, so we can manage all the branches and devices centrally in one controller."
"It is a stable solution, and there are no issues so far."
"The most valuable features of Forcepoint Next Generation Firewall are the advanced threat protection, including features like IPS and DDoS prevention, which help avoid internal DDoS attacks."
"I have found that Forcepoint Next Generation Firewall is easy to use, highly secure, and the main VPN tunnel is created automatically which is a benefit."
"I like the IPS. IPS is the master feature. I depend on the firewall and sandbox."
"McAfee NSP helps the organization by filtering most of the active inbound attacks that would otherwise compromise the users and servers."
"You might try Sangfor if you are on a tight budget. The price is affordable, and Sangfor offers a lot of features. We don't have any complaints about Sangfor."
"It is a stable solution."
"Sangfor NGAF works accordingly with our customers. The solution has good performance, easy to use, and integrates well with the endpoints."
"The most valuable feature of Sangfor NGAF is its integration."
"In our hospital, Sangfor NGAF works well for us in terms of ensuring confidentiality and availability, which are crucial in the healthcare industry."
"In terms of the most valuable features, the IPS report is quick and updated. Performance is also valuable."
"Sangfor NGAF's standout feature is its powerful application control, enabling precise restrictions on mobile user access to approved applications."
"The product is very fast and reliable."
 

Cons

"The cloud features and integration could be improved."
"Fortinet technical support is lacking, as OEM support is slightly better."
"They could simplify their deployment process, especially when customers have existing devices."
"In my opinion, Fortinet FortiGate could be improved by making the appliance smaller than what we have here, as it is pretty big."
"One issue that I have had is that sometimes I need to monitor the traffic, so I need to filter it according to the user and which user is using it the most. I experience a bottleneck most of the time, particularly at the peak time when the number of contracts and users are at maximum."
"Security is a continuous process. In every product, there is a requirement for improvement. Its pricing should also be improved according to Indian market requirements. They must also improve on the reporting part. Its reporting can be more precise. If we can get a real-time report in a specific format, it will be helpful for customers to know about the current status of their security."
"The support system could be improved."
"The license renewal process, annual renewal price, and the web application firewall features should be improved."
"Its management center should be easier to use. The management interface of Forcepoint is unique and a little bit different from some of the firewall solutions on which people might have worked before. Sometimes, the customers say that it is not very friendly, and we help them with how to use this management interface. It just takes a little bit of time, and after some time, it gets easy to manage or use. It is quite similar to Palo Alto, Fortinet, and legacy Juniper solutions. Their support should be faster. We have received complaints that they are not responding fast, which is not good for the vendor and us."
"It's a complicated firewall. Until you come to know the firewall inducers, most people don't like the firewall because the components for the firewall are a little bit complex. User-friendliness is a little bit tough. It needs to be user-friendly when creating policies, and pushing policies. Committing takes more time compared to Palo Alto."
"The interface is complicated. It's difficult to locate all the necessary menus and functions."
"While the policies are easy to read, the UI feels a bit dated and sometimes clunky on certain pages."
"Making this solution easier to use would be an improvement."
"A VPN client feature is missing in our region, which we hope Forcepoint will address in future updates."
"Forcepoint Next Generation Firewall could change its interface, allowing standard or direct connect modes to be configured."
"I found one problem with Forcepoint Next Generation Firewall. They still do not have any VPN clients for Windows computers with ARM processors."
"The support for YouTube or the Internet is not enough."
"Sangfor NGAF could improve the policies and default criteria. They could be much better."
"The solution should be able to work in a hybrid setup."
"The cost of licensing is very high compared to other firewalls available here."
"Sangfor NGAF could improve by refining its application control policies, especially in addressing challenges with certain types of applications."
"Sangfor could improve by providing better real-time reporting, as the current reports don't offer the level of detail we need, especially for runtime insights."
"Our experience with its customer support was quite challenging."
"The setup phase is quite complex."
 

Pricing and Cost Advice

"There is a licensing fee; it is on a yearly basis."
"The solution's pricing is competitive."
"In my opinion, the pricing of the product is reasonable."
"The pricing is flexible."
"The pricing or licensing of Fortinet FortiGate is quite effective as it offers different bundles that aggregate most required features, while also allowing clients the option to select specific components alone."
"The solution could be better priced."
"The price is really low. It's cheap in comparison to the cost of Cisco or CheckPoint, for example."
"It is affordable. Palo Alto is much more expensive than Fortinet."
"The training that they offer to their end-customers. It's quite expensive, I believe it costs roughly $11,000"
"The cost is fair, but it could be improved."
"Forcepoint Next Generation Firewall is reasonable, it is priced the same as other firewalls."
"We have just a subscription for the cloud, and this license is great. The license is so good."
"There is a license required to use this solution and we can purchase it for one, two, three, or five years."
"I believe the licensing fee is for one year, three years, and five years, or something like that. If you wants to increase the support level from a simpler level to platinum, I think that there's a cost. There are differences between every kind of support, but I don't know the numbers."
"It is an affordable product. We purchase its yearly license."
"The big advantage of this solution is that we can select the right model for our requirements, which is not too expensive."
"The license of Sangfor NGAF can be purchased at different interval lengths, such as annually or three years. They offer a range of packages to choose from, such as combo or hybrid packages. We are using the complete solution package which includes IM, NGF and SSL VPN, and WAF."
"It costs about 8 to 10 thousand dollars per year for 500 users, standard licensing fees included."
"The product is very cost-effective compared to other brands or vendors."
"If one is very cheap and ten is very expensive, I rate the tool's price as three out of ten."
"Sangfor NGAF is a cheaply priced product, especially if I consider the previous product that was used in my company."
"We purchased one year technical support and return to factory support, and we also purchased one-year technical support services. So those were additional."
"The pricing is reasonable."
"If you know you have around 200+ computer users on your network, then the Sangfor NGAF 5200-F-I model would be the minimum recommended model for that amount of users. This model includes modules for packet filtering, deep packet inspection, malware scanning, DSCP filtration, and many other features."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
884,873 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
11%
Comms Service Provider
10%
Manufacturing Company
8%
Financial Services Firm
6%
Manufacturing Company
10%
Computer Software Company
10%
Financial Services Firm
8%
Government
7%
Manufacturing Company
12%
Comms Service Provider
9%
Financial Services Firm
8%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business360
Midsize Enterprise135
Large Enterprise190
By reviewers
Company SizeCount
Small Business29
Midsize Enterprise10
Large Enterprise12
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise10
Large Enterprise10
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is your experience regarding pricing and costs for Forcepoint Next Generation Firewall?
My experience with pricing, setup cost, and licensing is limited because I do not work with pricing, but I have exper...
What needs improvement with Forcepoint Next Generation Firewall?
I found one problem with Forcepoint Next Generation Firewall. They still do not have any VPN clients for Windows comp...
What do you like most about Sangfor NGAF?
I think Sangfor NGAF is more valuable than Cisco products because of its simplicity and ease of management. If I comp...
What is your experience regarding pricing and costs for Sangfor NGAF?
The licensing cost is quite high compared to other available firewalls in the market.
What needs improvement with Sangfor NGAF?
The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardwa...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
Forcepoint NGFW, Stonesoft Next Generation Firewall, McAfee Network Security Platform, Intel Security Network Security Platform
Sangfor NGAF Firewall Platform
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
California Department of Corrections and Rehabilitation (CDCR)
The Ministry of Science, Technology, and Innovation (Indonesia), Lawson, Inc. (Philippines), Universiti Sultan Zainal Abidin (Indonesia), TEK Automotive (Italy), etc.
Find out what your peers are saying about Forcepoint Next Generation Firewall vs. Sangfor NGAF and other solutions. Updated: March 2026.
884,873 professionals have used our research since 2012.