No more typing reviews! Try our Samantha, our new voice AI agent.

Palo Alto Networks NG Firewalls vs Sangfor NGAF comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 25, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Palo Alto Networks NG Firew...
Ranking in Firewalls
5th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
199
Ranking in other categories
No ranking in other categories
Sangfor NGAF
Ranking in Firewalls
22nd
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
34
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2026, in the Firewalls category, the mindshare of Palo Alto Networks NG Firewalls is 5.2%, up from 4.0% compared to the previous year. The mindshare of Sangfor NGAF is 1.1%, down from 1.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls Mindshare Distribution
ProductMindshare (%)
Palo Alto Networks NG Firewalls5.2%
Sangfor NGAF1.1%
Other93.7%
Firewalls
 

Featured Reviews

Nitin Yadav - PeerSpot reviewer
Network & Security Engineer at Arrow PC Network Pvt.Ltd.
Strong threat prevention has reduced phishing and malware while I monitor traffic in depth
Palo Alto Networks NG Firewalls offers application and user awareness, which allow me to control traffic based on threats. The product includes threat prevention, advanced threat prevention, and deep packet inspection that really helps prevent issues in our network. Deep packet inspection inspects full traffic content, even inside applications and encrypted sessions. Deep packet inspection makes a very practical difference day to day because it lets me see and control what is actually inside the traffic, not just the open port or IP. I have real visibility of which application is running instead of just seeing HTTPS. Palo Alto Networks NG Firewalls WildFire sandboxing is really good at detecting and blocking zero-day malware automatically, along with its GlobalProtect and DNS security features. Using Palo Alto Networks NG Firewalls positively impacts my organization by providing strong security, better visibility, faster response, and simplified operations. After deploying Palo Alto Networks NG Firewalls in our network, it blocks malicious traffic and prevents compromises that occurred before Palo Alto Networks NG Firewalls. I can now block outside IPs to prevent issues. After Palo Alto Networks NG Firewalls installation, I reduced 60 to 70 percent of malware and phishing attacks. Its threat prevention and DNS security features detect these attacks, block malicious domains, and reduce manual efforts for the security team.
Zaid Farooqui - PeerSpot reviewer
CIO at Indus Motor Company
Enhanced threat detection with integrated security features and good support
We are using application firewalling, WAF, and SD-WAN. The capabilities are mostly within the box. For example, you will get web application firewall WAF as part and parcel of this. SD-WAN is also bundled. It integrates with their SIEM and SOAR solutions very nicely. Lastly, the pricing point is very cost-efficient as well.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution does a great job of identifying malicious items and vulnerabilities with URL filtering."
"I like the sandbox feature, and it's very good. It kills each malware deployment in the sense of signatures within five minutes. So, we can secure our network and infrastructure very well within the stipulated time. The WildFire functionality is very good because a few files are also getting blocked. It's critical as malware attacks are also getting ignored, and the logging is very well maintained in this firewall. The most valuable solutions in this field are application-based firewalls. That is the main criteria of the firewall and functionality. We can get all the logs related to this and each and every packet. I like that the firewall is working as an application. The application-based entity we have deployed is well maintained and working very well. We were able to find lots of vulnerabilities when we deployed it, but we could not disclose all. But there were vulnerabilities we could block by updating the firewall and taking actions on clientside machines. So, we got to know that we have lots of vulnerabilities inside the organization too, and we took lots of steps and resolved the number of vulnerabilities. Palo Alto Networks NG Firewalls is an all-in-one solution. It provides every entity log, which is a very good functionality of this firewall. It gives every packet and aspect that the firewall is performing through its logs, and it does it very well. This firewall's unified platform helped eliminate multiple network security tools. If anyone uses P2P sites, cryptocurrency websites, or any illegal sites, we can block it easily. It gives us a proper alert for these kinds of sites, and it properly secures our network. Monitoring is the best thing we are doing here, and we can block this kind of vulnerability as soon as it comes to us."
"The performance of Palo Alto Networks NG Firewalls is the most valuable feature."
"The management options are good."
"From my experience, comparing it to other products, the granularity you can have in the application is very good, the application detection is excellent, and it's certainly one of the best."
"The fact that the Next-Gen firewalls are integrated with identity is the best. It gives us the ability to track what an individual is doing and helps us provide access to only what they need in order to do their job."
"The value of this solution for me is the protection from a single packet and ease of making security rules."
"It helps the organization function better by virtue of cleaner and more predictive Internet access and usage being conducted by the employees and constituents of the company. It helps ensure that they have a stronger security posture. It is preventive medicine If you have DNS Security in place. You will be happy you had it. If you don't have it, you may never need it. However, if you did need it, and didn't have it, you will wish that you did. It is one of those things, like insurance."
"Sangfor NGAF's standout feature is its powerful application control, enabling precise restrictions on mobile user access to approved applications."
"While the features are not dissimilar to other brands, configuration is much more simple, which works out great for Indonesian people."
"Particularly good in the DPI where we can inspect inbound and outbound traffic."
"The built-in features function as intended, providing exceptional value."
"In terms of the most valuable features, the IPS report is quick and updated, and performance is also valuable."
"The level of support provided to local companies is good. They transform their application control and other settings according to that country."
"We've found the technical support to be helpful."
"The price versus value is good because the solution is less expensive than Sophos, Fortinet, or SonicWall."
 

Cons

"The functionalities are limited."
"The setup was complex. We have perimeter firewalls and multiple voice devices handling calls. Directing traffic through gateway perimeter firewalls becomes quite complex in such a scenario. The implementation took around two months and required three to four people for deployment."
"The user interface is probably not as slick as it could be."
"Its price can be better."
"The scalability compared to other products is not good. You need to change the box whenever you want your number of connection sessions to increase."
"My customers have been attacked by ransomware. It's difficult to understand how the ransomware got through Palo Alto Panorama and Palo Alto dashboard monitoring from reporting."
"When the primary Palo Alto Networks firewall fails over to the secondary, it requires manual intervention to bounce the IPsec for it to work properly. Unlike BGP peering, which automatically changes from idle to established, this process needs automation. In Cisco, there is no need to bounce the IPsec traffic during failover, and I suggest automation for Palo Alto Networks in that process."
"The SD-WAN feature needs improvement."
"Sangfor NGAF could improve by refining its application control policies, especially in addressing challenges with certain types of applications."
"An area of improvement for Sangfor NGAF could be in the field of reporting and logging."
"However, the maintenance cost can be a bit high."
"The solution has too many bugs and these slow down the implementation."
"Lacks consistency in terms of filtering certain websites and applications."
"The interface and user experience are horrible."
"The setup phase is quite complex."
"I think the GUI needs to be improved, there are a lot of areas where the panes do not make sense."
 

Pricing and Cost Advice

"It is expensive as compared to other brands."
"Palo Alto Networks NG Firewalls are affordable, and we get what we pay for."
"Annually, the licensing costs are too much."
"This solution is quite expensive because along with the license there is premium partner support that has to be purchased as a default addition. There is also a specific Threat Prevention License that has to be requested and purchased separately. However, licenses can be purchased for specific periods as opposed to just an annual offering."
"If you compare Palo Alto with other firewalls, it's a bit expensive."
"I am not involved in the commercial side, but I believe that Palo Alto is quite expensive compared to others."
"Palo Alto can be priced higher than some less capable firewalls. However, they are exceptional when you consider the completeness of the solution and its ability to handle threats. Palo Alto is better than other solutions, which justifies a slightly higher price point. You have other tools that are easier to deploy, reducing your total cost of ownership. The newer models are faster, making the pricing more attractive."
"These firewalls are not cheap, but they have a reasonable licensing model."
"Price-wise, I would not consider Sangfor NGAF to be a cheap product. It is an expensive firewall solution, though not as expensive as something like Palo Alto, which is costly. However, the higher price point is justifiable given the feature set the tool provides that other firewalls may not offer in a single dedicated appliance."
"The product is very cost-effective compared to other brands or vendors."
"Sangfor NGAF price is reasonable and there is an annual license. However, the maintenance cost can be a bit high."
"The price is unmatcheable."
"When it comes to the price of firewall solutions, Sangfor NGAF takes the cake."
"Sangfor is cheaper than competing vendors."
"For four to five physical appliances for a licensed firewall, it costs approximately $4,000."
"We purchased one year technical support and return to factory support, and we also purchased one-year technical support services. So those were additional."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
908,877 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
10%
Financial Services Firm
9%
Computer Software Company
8%
Outsourcing Company
7%
Financial Services Firm
11%
Comms Service Provider
11%
Manufacturing Company
10%
Construction Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business77
Midsize Enterprise57
Large Enterprise87
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise10
Large Enterprise10
 

Questions from the Community

What is a better choice, Azure Firewall or Palo Alto Networks NG Firewalls?
Azure Firewall Vs. Palo Alto Network NG Firewalls Both solutions provide stellar stability and security. Azure Firewall is easy to use and provides excellent support. Valuable features include int...
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it kind of depends what you value most. PA is good at app control, web filtering a...
Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat signatures and updates. I also appreciate that I can just import addresses and URL...
What is your experience regarding pricing and costs for Sangfor NGAF?
The licensing cost is quite high compared to other available firewalls in the market.
What needs improvement with Sangfor NGAF?
The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardware scalability, allowing for more storage and memory capacity. Making the soluti...
What is your primary use case for Sangfor NGAF?
We are hosting applications over the platform, including websites and NAT traffic from our side. Because it's deployed in our data center, which is fully operational, we have various applications h...
 

Also Known As

Palo Alto NGFW, Palo Alto Networks Next-Generation Firewall
Sangfor NGAF Firewall Platform
 

Overview

 

Sample Customers

SkiStar AB, Ada County, Global IT Services PSF, Southern Cross Hospitals, Verge Health, University of Portsmouth, Austrian Airlines, The Heinz Endowments
The Ministry of Science, Technology, and Innovation (Indonesia), Lawson, Inc. (Philippines), Universiti Sultan Zainal Abidin (Indonesia), TEK Automotive (Italy), etc.
Find out what your peers are saying about Palo Alto Networks NG Firewalls vs. Sangfor NGAF and other solutions. Updated: August 2026.
908,877 professionals have used our research since 2012.