Try our new research platform with insights from 80,000+ expert users

Palo Alto Networks NG Firewalls vs Sangfor NGAF comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jul 13, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
2nd
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
411
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st)
Palo Alto Networks NG Firew...
Ranking in Firewalls
7th
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
195
Ranking in other categories
No ranking in other categories
Sangfor NGAF
Ranking in Firewalls
19th
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
34
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2025, in the Firewalls category, the mindshare of Fortinet FortiGate is 20.8%, up from 17.8% compared to the previous year. The mindshare of Palo Alto Networks NG Firewalls is 3.8%, up from 3.0% compared to the previous year. The mindshare of Sangfor NGAF is 1.3%, up from 1.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls
 

Featured Reviews

Vasu Gala - PeerSpot reviewer
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
AmjadKhan1 - PeerSpot reviewer
Provides inline protection with a unified view and anti-spyware capabilities
I would rate Palo Alto Networks NG Firewalls ten out of ten because it is the best. Our disaster recovery site utilizes Palo Alto Networks Next-Generation Firewalls. We are also in the process of upgrading the firewalls at our 365 sites in Pakistan to Palo Alto Networks firewalls. While budget firewalls may advertise comparable features, they often fall short of effectively detecting viruses, threats, and ransomware. In contrast, Palo Alto Networks NG Firewalls, combined with Cortex XDR, provide comprehensive threat intelligence and detection capabilities, ensuring superior security coverage. I recommend conducting a proof of concept before selecting a firewall. This will allow you to evaluate different options and determine which best suits your needs. While Palo Alto offers robust firewall solutions, it's essential to compare them with other vendors to ensure you make an informed decision.
Zaid Farooqui - PeerSpot reviewer
Enhanced threat detection with integrated security features and good support
We are using application firewalling, WAF, and SD-WAN. The capabilities are mostly within the box. For example, you will get web application firewall WAF as part and parcel of this. SD-WAN is also bundled. It integrates with their SIEM and SOAR solutions very nicely. Lastly, the pricing point is very cost-efficient as well.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Whenever we raise a complaint with FortiGate, their response and resolution times are minimal."
"The ECC management and the GUI that offers single interface management are the most valuable features of Fortinet FortiGate."
"The main reason why I purchased the particular unit was that it had good reviews and what other people were saying as far as its completeness and its leading capabilities in terms of endpoint security was very good."
"The most valuable features of Fortinet FortiGate are the APIs. They are the most widely known."
"It is useful for protecting and segregating the internal networks from the internet. Most of our customers also use the FortiGate client to connect to their offices by using the VPN client, and of course, they usually activate the antivirus, deep inspection, and intrusion prevention services. They are also using it for web filtering and implementing various policies dealing with forwardings, NAT, etc."
"The most valuable features of Fortinet FortiGate are the ease of use and there are several operating systems that can include the hardware capacities. In the newer releases, the resources were more useful because they were included in the operating system."
"Fortinet FortiGate's reliability is valuable."
"The security on offer is very good."
"The effectiveness of this technology improves with each release, bolstering confidence in the product's ability to provide robust security."
"We standardized on the product and got rid of several other types of firewalls from different vendors."
"Operationally, it is easier, and the manageability and their security features are good."
"AI and machine learning are valuable aspects."
"The most valuable features are Wildfire, URL filtering, and IPS."
"The best features of this solution are URL filtering and traffic visibility."
"The packet level inspection is the most valuable feature. The traffic restriction features allow us to restrict the sub-features of any platform."
"I find Palo Alto Networks NG Firewalls to be a stable product and very easy to manage from layer 4 to layer 7. They are also seamless for environments with high availability."
"The level of support provided to local companies is good. They transform their application control and other settings according to that country."
"Sangfor has the best capabilities for securing connections, securing web browsers, securing servers, and general threat protection."
"In terms of the most valuable features, the IPS report is quick and updated. Performance is also valuable."
"It seems to be a durable, stable product."
"The stability of Sangfor NGAF is good."
"In four steps one can configure the entire firewall."
"The top functionality is the reporting feature."
"It offers application control features."
 

Cons

"The solution can have more features in a single box that can be multi-applied to integrate everything."
"The configuration part was challenging, especially converting configurations from another OEM to FortiGate."
"The scalability could be better."
"It could use more templates for third-party site-to-site VPN setups other than FortiGate and Cisco."
"Fortinet FortiGate could improve by having more storage in the hardware for log data."
"I would suggest that Fortinet add sandboxing to their solution."
"Fortinet technical support is lacking, as OEM support is slightly better."
"I wish that they could integrate zero-trust technology into Fortinet FortiGate. I am not sure whether it has been done already, but if they could implement that, it would help significantly."
"The only area I can see for improvement is that Palo Alto should do more marketing."
"Palo Alto Networks NG Firewalls work slowly for vulnerability management. Its performance could be faster."
"It is a complete product, but the SSL inspection feature requires some improvements. We need to deploy certificates at each end point to completely work out the UTM solutions. If you enable SSL encryption, it is a tedious process. It takes a lot of time to deploy the certificates to all endpoints. Without SSL inspection, UTM features will not work properly. So, we are forced to enable this SSL inspection feature."
"Palo Alto Networks NG Firewalls do not provide a unified platform that natively integrates all security capabilities."
"The integration with AI needs improvement."
"If you enable SSL you will face a problem. The throughput of the firewall will be degraded. SSL is a big issue on all firewalls. All products suffer from issues with SSL, but Palo Alto firewalls suffer more from it."
"I think automation and machine learning can be improved to make bulk configurations simpler, easier, and faster"
"In the future, I would like to see more OTP features."
"The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardware scalability, allowing for more storage and memory capacity."
"It has an issue with the Sangfor Cloud Platform rather than the firewall. When we run a virtual machine, the window tabs display Chinese characters."
"Sangfor NGAF could improve by refining its application control policies, especially in addressing challenges with certain types of applications."
"The tool is expensive."
"The tool's support is an area of concern where improvements are required."
"I feel Sangfor should follow the hierarchy and close deals via resellers instead of closing it all with their own team."
"The firewall system needs gradual improvements because there are more threats and challenges every day."
"The support for YouTube or the Internet is not enough."
 

Pricing and Cost Advice

"The price is fine."
"Fortinet has more device options that are affordable for small businesses than Palo Alto, and its enterprise-level models are also cheaper. Palo Alto also has a separate license for VPN connections and SD-WAN, but FortiGate offers these features standard."
"There is a license to use Fortinet FortiGate."
"Fortinet is competitive price-wise."
"Its price could be better."
"The solution requires a license annually, it is not a user license, you can have as many users as your want. I must renew the license regularly per device."
"The value is the capability of having multiple services with one unique license, not having the limitation per user licensing schema, like other vendors."
"It's one of the more expensive brands. The 100 series costs around $4,000. They are similar in pricing to what you might get from Cisco solutions and probably other similar ones. They're not more expensive than other similar solutions, but they're certainly not cheaper either."
"Palo Alto Networks NG Firewalls is expensive, but it is worth its price."
"With Palo Alto, the licensing is very straightforward. For example, if you only have a requirement for a firewall, you can go with that. If you want to go with a subscription, you get all the features with it."
"The solution’s cost is a little high compared to other products."
"There are security licenses."
"Palo Alto can be priced higher than some less capable firewalls. However, they are exceptional when you consider the completeness of the solution and its ability to handle threats. Palo Alto is better than other solutions, which justifies a slightly higher price point. You have other tools that are easier to deploy, reducing your total cost of ownership. The newer models are faster, making the pricing more attractive."
"The NG firewall is an expensive solution."
"The licensing leaves a lot to be desired. We buy the license and then we can't transfer the license without paying an exorbitant fee to our client if they leave us, and that just seems to be a bit of a pain point for us, and there's really no way to partner effectively to make that more reasonable."
"Palo Alto Networks NG Firewalls are very expensive compared to other firewalls such as Fortinet. As a result, Palo Alto is losing some of its market share."
"It is one of the cheapest tools in the market."
"The solution has a TCO that is 32% to 50% less than Sophos, Fortinet, and SonicWall."
"Sangfor NGAF price is reasonable and there is an annual license. However, the maintenance cost can be a bit high."
"The product is very cost-effective compared to other brands or vendors."
"If one is very cheap and ten is very expensive, I rate the tool's price as three out of ten."
"The price falls in the mid-range, neither exceptionally low nor high."
"For over 2000 users, the cost is around 5000 to 6000 USD. If you want a web application firewall, you have to purchase an additional license for it."
"It costs about 8 to 10 thousand dollars per year for 500 users, standard licensing fees included."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
865,295 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Comms Service Provider
9%
Manufacturing Company
7%
Financial Services Firm
6%
Computer Software Company
13%
Financial Services Firm
9%
Manufacturing Company
8%
Government
6%
Computer Software Company
11%
Manufacturing Company
11%
Financial Services Firm
9%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is a better choice, Azure Firewall or Palo Alto Networks NG Firewalls?
Azure Firewall Vs. Palo Alto Network NG Firewalls Both solutions provide stellar stability and security. Azure Firew...
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it...
Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat si...
What do you like most about Sangfor NGAF?
I think Sangfor NGAF is more valuable than Cisco products because of its simplicity and ease of management. If I comp...
What is your experience regarding pricing and costs for Sangfor NGAF?
The licensing cost is quite high compared to other available firewalls in the market.
What needs improvement with Sangfor NGAF?
The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardwa...
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate, Fortinet Firewall
Palo Alto NGFW, Palo Alto Networks Next-Generation Firewall
Sangfor NGAF Firewall Platform
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
SkiStar AB, Ada County, Global IT Services PSF, Southern Cross Hospitals, Verge Health, University of Portsmouth, Austrian Airlines, The Heinz Endowments
The Ministry of Science, Technology, and Innovation (Indonesia), Lawson, Inc. (Philippines), Universiti Sultan Zainal Abidin (Indonesia), TEK Automotive (Italy), etc.
Find out what your peers are saying about Palo Alto Networks NG Firewalls vs. Sangfor NGAF and other solutions. Updated: July 2025.
865,295 professionals have used our research since 2012.