Try our new research platform with insights from 80,000+ expert users

Forcepoint Next Generation Firewall vs Trellix Intrusion Prevention System comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
581
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Firewalls (1st), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Forcepoint Next Generation ...
Average Rating
7.6
Reviews Sentiment
6.6
Number of Reviews
49
Ranking in other categories
Firewalls (20th), Software Defined WAN (SD-WAN) Solutions (8th), WAN Edge (8th)
Trellix Intrusion Preventio...
Average Rating
8.4
Reviews Sentiment
6.6
Number of Reviews
16
Ranking in other categories
Intrusion Detection and Prevention Software (IDPS) (13th)
 

Mindshare comparison

Firewalls Market Share Distribution
ProductMarket Share (%)
Forcepoint Next Generation Firewall0.6%
Fortinet FortiGate18.7%
OPNsense10.5%
Other70.2%
Firewalls
Intrusion Detection and Prevention Software (IDPS) Market Share Distribution
ProductMarket Share (%)
Trellix Intrusion Prevention System2.9%
Fortinet FortiGate13.2%
Darktrace11.5%
Other72.4%
Intrusion Detection and Prevention Software (IDPS)
 

Featured Reviews

Vasu Gala - PeerSpot reviewer
Manager, Information Technology Operation/Presales at TechMonarch
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
reviewer2774055 - PeerSpot reviewer
Cybersecurity Engineer at a tech consulting company with 51-200 employees
Improved network segmentation has reduced lateral movement while the interface still needs modernization
For threat prevention, I noticed on another customer that there were repeated scanning and exploit attempts against some public-facing service running on HTTPS. I configured Forcepoint Next Generation Firewall to handle IPS by enabling it with critical and high severity signatures only to reduce false positives. I turned on IP reputation filtering to filter out known malicious networks, applied rate limiting on specific services in the DMZ, and logged events centrally for correlation. As a result, exploit attempts were much less than before, being blocked before reaching the back-end servers from the firewall itself, with no performance degradation on the applications. The security team received clear and actionable logs that were centralized, so they knew what was happening all the time. Strong network segmentation is my favorite feature that Forcepoint Next Generation Firewall offers. The policies are very deterministic and readable, and it has excellent east-west blocking and least privilege architecture. Application awareness identifies traffic beyond just the port itself; I can identify the application using a specific port and block risky applications even if they use allowed ports, which is great for environments with shadow IT. The integrated threat prevention is also very good, with IPS featuring well-tuned signatures and reputation-based filtering that blocks known bad actors before they can touch any applications. It supports both IPsec and SSL VPN tunnels, along with site-to-site, client-to-site, and hybrid cloud links, integrating well with Active Directory and LDAP. Additionally, centralized log management and reporting are very actionable and structured, with clarity in the policies for auditing. Overall, its stability and reliability are commendable. A real example of how Forcepoint Next Generation Firewall's readable policies and application awareness features made my work easier was fixing a flat network problem without breaking actual applications. I inherited an environment where users, application servers, and databases were loosely segmented, with port-based and messy firewall rules. Security audits flagged lateral movement risks, and application owners were scared of outages if I tightened security too much. Forcepoint Next Generation Firewall made it easy by providing very easy-to-read and logical policies. I built policies that are clear, showing communications from the user zone to the application zone to specific applications, or from the app zone to the database zone, using only required database protocols. By default, I applied a deny rule between zones unless explicitly allowed by the readable rules I implemented. The policy view clarified who talks to whom, which rules exist, why they exist, and the business function they support, effectively stopping port abuse. Security posture has definitely improved greatly since using Forcepoint Next Generation Firewall. From a flat or semi-flat network, I now have clear zone-based segmentation, with increased operational efficiency. The admins using the firewall have rules that are easy to read and intent-based, making changes easier to review and approve. There is less fear that one wrong rule could break production and fewer outages caused by security changes, without hidden matches or rule shadowing surprises. Clear hit count visibility helps me clean unused rules, leading to much fewer outages caused by changes on the firewalls. The centralized log management with supported log types provides better visibility for the SOC team and the SIEM team, as Forcepoint Next Generation Firewall sends very easy-to-parse and search clear logs to the SOC team. I did see measurable, defensible results after using Forcepoint Next Generation Firewall, including fewer security incidents reaching the back-end servers. This reduction is due to strong segmentation, application awareness, and IPS features, leading to a 60 to 70 percent reduction in security alerts that actually reach the servers. DMZ exploit attempts dropped to near zero, and no lateral movement incidents were detected post network segmentation. Additionally, overall SOC efficiency improved due to well-structured and contextual logs reflecting clear policy intent, resulting in a 35 to 40 percent reduction in mean time to triage. SOC analysts stopped chasing noise and false positives, as they had much clearer logs to use confidently.
BS
Large account Manager at Softcell Technologies Limited
Has offered reliable threat protection and detailed network insights but could expand features beyond existing capabilities
The best features of Trellix Intrusion Prevention System include advanced ATP (Advanced Threat Protection), which uses signatures, behavior analysis, and machine learning to stop zero-day exploits and malware advanced persistent threats (APTs). They track and collect data from APTs, which allows them to track malicious files entering the environment. The system offers inline prevention and real-time automatic blocking of malicious packets before they reach the network. It integrates with the Trellix ecosystem and provides application visibility and control. The solution provides deep insight into network traffic, applications, and protocols for better information. All packets coming through the application are analyzed and reported. They share intelligence updates regularly to protect from different malicious files and sector-specific threats. It supports both on-premise and cloud environments.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Fortinet FortiGate has positively impacted my organization by centralizing the way to access all of our network firewalls."
"The initial setup is straightforward."
"The product is easy to use and is stable. The SV1 functionality is a benefit."
"FortiGate firewalls are easy to manage through a user-friendly web interface. They also have advanced features like DDoS and DLP. However, I wouldn't recommend enabling all of these features on one device because it can cause performance issues."
"The user interface is relatively easy. The devices are easy to deploy and figure out when you have experience with other security appliances."
"The solution is very user friendly. The user interface in particular is quite nice."
"The most valuable feature is the bundled subscription, which is IPS, TV and web filtering."
"The most helpful features of FortiGate include its firewall policy, specifically the user-based policy, which I find to be quite beneficial in managing our network security effectively."
"The most valuable feature is controlling the traffic and the logging. They have real-time logins for traffic logs. Troubleshooting was very easy for me."
"The Forcepoint Next Generation Firewall is a scalable product."
"One of the most valuable features is having the ability to cluster multiple firewalls even if they are different versions."
"Forcepoint Next Generation Firewall is very simple, easy to use, and flexible."
"We like the scalability of Forcepoint because with the Forcepoint NGFW solution, we can scale anything. The solution has central management, so we can manage all the branches and devices centrally in one controller."
"I found the initial setup process to be very simple and straightforward."
"Forcepoint is a good, stable solution."
"The most valuable features of Forcepoint Next Generation Firewall are the advanced threat protection, including features like IPS and DDoS prevention, which help avoid internal DDoS attacks."
"The product is worth the investment."
"There's a good dashboard you can drill down into. It helps you easily locate intrusions and the source of attacks."
"Great monitoring feature."
"The most valuable features in Trellix for me are the automated signature updates. It is a great and convenient feature."
"The ability to centrally manage all the IPS sensors, track the different security events generated by it, and customize the different policies, depending on their location."
"The most valuable features of the solution stem from the fact that it is a good product for dealing with DDoS attacks and for the inspection of network traffic."
"The initial setup is straightforward."
"Overall the solution is very good. It offers great protection and gives us a good overview of what is on the network."
 

Cons

"Fortinet FortiGate should improve the VPN tokens."
"The room for improvement is to have more flexibility on the virtual machines of their next-generation platforms."
"In my opinion, Fortinet FortiGate could be improved by making the appliance smaller than what we have here, as it is pretty big."
"Fortinet FortiGate could improve if it had a cloud-managed solution."
"The interface and product support could use improvement."
"During a recent upgrade from old devices to the latest ones, corporate IT faced challenges as there was no straightforward migration process, requiring many manual steps."
"They could simplify their deployment process, especially when customers have existing devices."
"One area for improvement is the licensing policy. If support licenses are not renewed, the product's functionality ceases, which can be disruptive."
"Forcepoint Next Generation Firewall could change its interface, allowing standard or direct connect modes to be configured."
"They should provide more details on potential cyber threats."
"In larger companies with extensive infrastructure, retrieving logs for a longer period of time can sometimes take a bit longer than desired."
"They should have a GUI on the product itself, not a separate management tool to be used on the management server or on a server to be used to manage the file. It should be all in one device. The device should be controlled through its own GUI. They also have to improve the learning center and the documents as the documents don't really help."
"This solution would be improved with the inclusion of custom reporting."
"My team is looking for more throughput and better integration with our security framework."
"Forcepoint would be improved if there were more training available."
"The optimization is not really ready. If you want very good optimization, you have to add it to the network."
"The management component could be simplified."
"The area of concern where the tool needs improvement is how the product prompts users at a network level that helps prevent any wireless network attacks through alerts and notifications."
"The technical support has room for improvement."
"The technical support must be improved."
"Integration with Global Thereat Intelligence could be better. Also, I think management solutions are end of life now at McAfee. Network threat analyzer may be used for endpoint quarantines. Integration between these sides, as well as endpoint APO, will help you quarantine the risky endpoints."
"We would like to have a simpler version. Some settings and functions on the McAfee console are complex and complicated. I want the management console to be simpler."
"The pricing could be improved."
"The solution needs to improve the graphical interface. And they had a limitation in some of the sensor modems as well."
 

Pricing and Cost Advice

"There is no challenge in Fortinet FortiGate pricing."
"The support subscription for the solution is annual. You are paying for support and there are two levels of support, professional and advanced."
"The platform offers a reasonable price point compared to its competitors."
"The pricing is based on a licensing model for each IPS in your environment."
"Fortinet is competitive price-wise."
"Pricing for this product is comparatively lower than other products. It's an affordable solution, but when expanding the number of users, they'll ask you to replace the model, so that's an added cost."
"Fortinet FortiGate's price can be reduced."
"It is cost-effective, and provides a good value for your money. The pricing, and license renewal, is very reasonable for us."
"It requires a yearly subscription."
"The training that they offer to their end-customers. It's quite expensive, I believe it costs roughly $11,000"
"The cost is fair, but it could be improved."
"The solution is expensive."
"There is a license required to use this solution and we can purchase it for one, two, three, or five years."
"We have found the price could be reduced. It is a little expensive."
"We have just a subscription for the cloud, and this license is great. The license is so good."
"It is an affordable product. We purchase its yearly license."
"I rate the product’s pricing an eight out of ten."
"The tool is competitively priced."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
881,733 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Comms Service Provider
9%
Manufacturing Company
8%
Financial Services Firm
6%
Manufacturing Company
10%
Financial Services Firm
8%
Government
7%
Computer Software Company
7%
Manufacturing Company
13%
Computer Software Company
10%
Comms Service Provider
9%
Financial Services Firm
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business357
Midsize Enterprise133
Large Enterprise189
By reviewers
Company SizeCount
Small Business28
Midsize Enterprise10
Large Enterprise11
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise6
Large Enterprise6
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is your experience regarding pricing and costs for Forcepoint Next Generation Firewall?
My experience with pricing, setup cost, and licensing is limited because I do not work with pricing, but I have exper...
What needs improvement with Forcepoint Next Generation Firewall?
Forcepoint Next Generation Firewall can be improved, perhaps in the user interface and policy management. While the p...
What do you like most about McAfee Network Security Platform?
The threat intelligence updates are very accurate.
What is your experience regarding pricing and costs for McAfee Network Security Platform?
The tool is competitively priced. I rate the pricing a six out of ten.
What needs improvement with McAfee Network Security Platform?
Trellix Intrusion Prevention System does not provide virtual patching. Patching involves updates on the OS side to ad...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
Forcepoint NGFW, Stonesoft Next Generation Firewall, McAfee Network Security Platform, Intel Security Network Security Platform
McAfee Network Security Platform, McAfee NSP, IntruShield Network Intrusion Prevention System, IntruShield Network IPS
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
California Department of Corrections and Rehabilitation (CDCR)
Desjardins Group, HollyFrontier, Nubia, Agbar, WNS Global Services, INAIL, Universidad de Las Américas Puebla (UDLAP), Cook County, China Pacific Insurance, Bank Central Asia, California Department of Corrections and Rehabilitation, City of Chicago, Macquarie Telecom, Sutherland Global Services, Texas Tech University Health Sciences Center, United Automotive Electronic Systems
Find out what your peers are saying about Fortinet, Netgate, Sophos and others in Firewalls. Updated: January 2026.
881,733 professionals have used our research since 2012.