Try our new research platform with insights from 80,000+ expert users

Palo Alto Networks NG Firewalls vs Sangfor NGAF comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 25, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
580
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Palo Alto Networks NG Firew...
Ranking in Firewalls
6th
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
197
Ranking in other categories
No ranking in other categories
Sangfor NGAF
Ranking in Firewalls
23rd
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
34
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of January 2026, in the Firewalls category, the mindshare of Fortinet FortiGate is 18.8%, down from 20.7% compared to the previous year. The mindshare of Palo Alto Networks NG Firewalls is 4.6%, up from 3.2% compared to the previous year. The mindshare of Sangfor NGAF is 1.1%, down from 1.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls Market Share Distribution
ProductMarket Share (%)
Fortinet FortiGate18.8%
Palo Alto Networks NG Firewalls4.6%
Sangfor NGAF1.1%
Other75.5%
Firewalls
 

Featured Reviews

Vasu Gala - PeerSpot reviewer
Manager, Information Technology Operation/Presales at TechMonarch
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
SV
Solution Architect // Network Consultant at Group S
Network security has improved and allows detailed user-based control over encrypted traffic
Bandwidth usage is not something we use much, but it depends on the SD-WAN plugin because the application load balancing is based on the SD-WAN product. That functionality does not work as it should, although the App-ID is working very well. SD-WAN functionality is working, but when you compare it with other products on the market, it is very limited. Palo Alto also has ION devices, and ION devices together with Prisma Access or Strata Cloud Manager now are more the way to go than using Palo Alto Networks NG Firewalls on-premises. At the moment I have some issues, but the issues are more related to the general way of working of many vendors. They implement new things very fast and it is not always bug-free. With new releases, sometimes you still have some issues. This is the main concern. If you look back five or maybe ten years ago, the products were more stable and you had more decent releases, but that is something in general for many vendors. Palo Alto is also a factor with that. They want to bring new features to the market too fast. Features are a concern because all vendors try to compete against each other. If one vendor comes out with a new feature, then other vendors do the same. Sometimes they want to be the first on the market with it, and that sometimes introduces bugs or issues with the product.
Zaid Farooqui - PeerSpot reviewer
CIO at Indus Motor Company
Enhanced threat detection with integrated security features and good support
We are using application firewalling, WAF, and SD-WAN. The capabilities are mostly within the box. For example, you will get web application firewall WAF as part and parcel of this. SD-WAN is also bundled. It integrates with their SIEM and SOAR solutions very nicely. Lastly, the pricing point is very cost-efficient as well.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The best features of Fortinet FortiGate include good functionality, though the licensing cost is a bit higher; their response time and throughput are very good advantages."
"Whenever we raise a complaint with FortiGate, their response and resolution times are minimal."
"One of the best features of Fortinet FortiGate is that it's a very powerful equipment that gives many security features in a single box with good performance, and the user interface is friendly to use and configure."
"In terms of cost, features, and security, everything is top-notch."
"The most valuable features of Fortinet FortiGate are the ability to work in proxy mode, which other solutions, such as Palo Alto cannot. There are some features that are better that come at no extra license or subscriptions cost, such as basic SD-WAN. The DLT is useful, other solutions have the same feature too, such as Palo Alto."
"The most valuable feature is the deep inspection for traffic, which is capable of identifying zero-day attacks."
"The most valuable feature of Fortinet FortiGate SWG is inspection."
"The main reason customers prefer Fortinet FortiGate is that it's security-centric, allowing them to implement security features such as a next-generation firewall and translate this to the WAN or SD-WAN architectures, or as a base if they want to grow in more security features or other verticals such as ZTNA and SASE."
"The best feature is the packet inspection; compared to solutions like Cisco and FortiGate, Palo Alto's packet inspection is much less CPU intensive, allowing it to detect threats embedded within packages more quickly and efficiently."
"The solution does a great job of identifying malicious items and vulnerabilities with URL filtering."
"I have found it to be reliable and very easy to use. I haven't really encountered many problems with it because its documentation is clear and readily available on their website."
"One of the things I really like about it is that we have the same features and functions available on the entry-level device (PA-220), as do large corporations with much more costly appliances."
"The fact that the Next-Gen firewalls are integrated with identity is the best. It gives us the ability to track what an individual is doing and helps us provide access to only what they need in order to do their job."
"The packet level inspection is the most valuable feature. The traffic restriction features allow us to restrict the sub-features of any platform."
"The fact that I can perform several security functions in one device at wire speed is a valuable feature. I don't have to slow down my business transactions, and I don't have to inconvenience my users with 16 different solutions. I can have it all in one box, and it protects my organization at wire speed."
"The technical support is great."
"The VPN connectivity feature is really nice."
"The top functionality is the reporting feature."
"In our hospital, Sangfor NGAF works well for us in terms of ensuring confidentiality and availability, which are crucial in the healthcare industry."
"While the features are not dissimilar to other brands, configuration is much more simple, which works out great for Indonesian people."
"The capabilities are mostly within the box."
"I think Sangfor NGAF is more valuable than Cisco products because of its simplicity and ease of management. If I compare it with Palo Alto and Cisco, both are quite complex products. And if I compare it with FortiGate firewalls from Fortinet, I have also used all these products. Fortinet and Sangfor NGAF are similar products because the applications behind the application and policy layers are almost identical."
"You might try Sangfor if you are on a tight budget. The price is affordable, and Sangfor offers a lot of features. We don't have any complaints about Sangfor."
"It is a stable solution."
 

Cons

"It is quite new for us, and we need to go more in-depth into the monitoring tools. It provides different features that we need to do what we want. So far, it is okay for us. In terms of improvement, in the future, they can provide a faster implementation of features. Some of the features are first available in other solutions. Fortinet sometimes takes a little bit longer than other solutions, such as Check Point, to implement new features."
"I don't like that anything more than very basic reporting is not included."
"I don't really have anything negative to say as far as Fortinet firewalls are concerned. If anything, they can support a user a little bit better. They can stop being so time-sensitive about how much time the support call has taken, and they can help you do it yourself."
"FortiGate may include AI capabilities and integrate external threat intelligence. However, version management and backup/restore operations could be improved."
"Fortinet FortiGate is not a scalable solution, as they give you a number and each box comes with concurrent connections; if you need to expand, you have to change the box."
"I would like to see improvements in the IPS/IDS feature to enhance protection against attacks from attackers, including ransomware protection."
"The graphical user interface of Fortinet's FortiGate product does not function well with text-based interfaces."
"I would rate the technical support of Fortinet FortiGate as a five because it is not as strong as Cisco. Additionally, the turnaround time is very high compared to Cisco."
"As things are evolving, we want to make sure that Palo Alto is able to keep up with what is going on outside. They should continue to do more intelligence-related enhancements and integrate with some of the other security tools. We want to have a more intelligent toolset down the road."
"In the future, I would like to see more OTP features."
"I would like them to improve their GUI interface, making it more user-friendly."
"I would like them to bring in some features that would encourage traffic shaping or bandwidth routing, like other UTM firewalls, because the solution should be capable of limiting the bandwidth for rules."
"There is a bit of limitation with its next-generation capabilities. They could be better. In terms of logs, I feel like I am a bit limited as an administrator. While I see a lot of logs, and that is good, it could be better."
"I would like integration with Evident.io and RedLock."
"The scalability compared to other products is not good. You need to change the box whenever you want your number of connection sessions to increase."
"The configuration part could be improved. It's very difficult to configure. It doesn't have a user-friendly interface. You have to know Palo Alto deeply to use it."
"I feel Sangfor should follow the hierarchy and close deals via resellers instead of closing it all with their own team."
"The reporting and log management could be improved."
"Sangfor could improve by providing better real-time reporting, as the current reports don't offer the level of detail we need, especially for runtime insights."
"There is room for improvement in dependency on certain infrastructure, like the DNS dependency on the current DNS server that the company has. It should be standalone. It should not depend on any other DNS server."
"An area of improvement for Sangfor NGAF could be in the field of reporting and logging."
"I would be happy if Sangfor developed a firewall designed specifically for home use, as well as for small businesses such as clinics and so on. A household version of the Sangfor firewall for your personal computer or laptop would be ideal, in my opinion."
"The web interface needs to be improved, making it more user-friendly."
"Sangfor need greater exposer in the market because the market is mainly saturated by Fortinet. The user experience of Fortinet is quite different compared to NGAF. If we want to switch our users from Fortinet to NGAF, we have to convince them that the user experience will be much easier once once they start to use it."
 

Pricing and Cost Advice

"The solution is offered as an annual license."
"It is more affordable than Check Point and Palo Alto. Another thing is that all the features and the OS remain the same irrespective of the size of the device. Pricing-wise, Fortinet typically provides one-year support with the firewall appliance. There is also an option for three years which is how their licensing works."
"It is an expensive solution."
"It scales well if you know what to buy from a physical box standpoint. They seem to offer something for every level."
"The product is expensive. I rate its pricing a six out of ten."
"FortiGate Next Generation Firewall is an expensive solution."
"It's a very full-featured and it's priced well solution."
"If the customer is looking for SD-WAN, it comes free with FortiGate."
"We always aim to reduce the pricing, as it is currently a bit high and needs to be lowered."
"I rate the product’s pricing an eight out of ten."
"The price could be better. Pricing is very different compared to WatchGuard, which costs around 60 lakhs, and FortiGate, which costs approximately 40 lakhs. Palo Alto Networks costs about a crore which is very high pricing. We bought this firewall, and our organization did not want to pay so much. We spent around one crore rupees which is not within our budget at all, and we are unhappy with them."
"The price of this product should be reduced."
"It could be less expensive."
"Cheap and faster are the opposite sides of security. Security inspections have some technical and money costs. If you just purchase some cheap, fast firewalls, then you will lose a lot of the security features and fraud protection capabilities."
"The cost of the license is platform-dependent. It would be nice if they standardized that across the board to make the license a flat fee instead of based on scale and the platform you're using. Functionality shouldn't change based on the platform or the amount of data going through it. It's the same functionality on there. That's one aspect customers often raise. The platform's price is what it is, but the ongoing cost of the annual license is hard for some customers to wrap their heads around."
"Palo Alto Networks NG Firewalls are more expensive than Cisco firewalls, but slightly less expensive than Juniper firewalls."
"Sangfor is cheaper than competing vendors."
"If you know you have around 200+ computer users on your network, then the Sangfor NGAF 5200-F-I model would be the minimum recommended model for that amount of users. This model includes modules for packet filtering, deep packet inspection, malware scanning, DSCP filtration, and many other features."
"The license of Sangfor NGAF can be purchased at different interval lengths, such as annually or three years. They offer a range of packages to choose from, such as combo or hybrid packages. We are using the complete solution package which includes IM, NGF and SSL VPN, and WAF."
"The solution has a TCO that is 32% to 50% less than Sophos, Fortinet, and SonicWall."
"The product is very cost-effective compared to other brands or vendors."
"If one is very cheap and ten is very expensive, I rate the tool's price as three out of ten."
"When it comes to the price of firewall solutions, Sangfor NGAF takes the cake."
"The pricing is reasonable."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
881,082 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Comms Service Provider
9%
Manufacturing Company
8%
Financial Services Firm
6%
Computer Software Company
10%
Financial Services Firm
9%
Manufacturing Company
8%
Educational Organization
7%
Manufacturing Company
11%
Financial Services Firm
8%
Computer Software Company
8%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business357
Midsize Enterprise133
Large Enterprise188
By reviewers
Company SizeCount
Small Business74
Midsize Enterprise56
Large Enterprise85
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise10
Large Enterprise10
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is a better choice, Azure Firewall or Palo Alto Networks NG Firewalls?
Azure Firewall Vs. Palo Alto Network NG Firewalls Both solutions provide stellar stability and security. Azure Firew...
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it...
Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat si...
What do you like most about Sangfor NGAF?
I think Sangfor NGAF is more valuable than Cisco products because of its simplicity and ease of management. If I comp...
What is your experience regarding pricing and costs for Sangfor NGAF?
The licensing cost is quite high compared to other available firewalls in the market.
What needs improvement with Sangfor NGAF?
The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardwa...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
Palo Alto NGFW, Palo Alto Networks Next-Generation Firewall
Sangfor NGAF Firewall Platform
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
SkiStar AB, Ada County, Global IT Services PSF, Southern Cross Hospitals, Verge Health, University of Portsmouth, Austrian Airlines, The Heinz Endowments
The Ministry of Science, Technology, and Innovation (Indonesia), Lawson, Inc. (Philippines), Universiti Sultan Zainal Abidin (Indonesia), TEK Automotive (Italy), etc.
Find out what your peers are saying about Palo Alto Networks NG Firewalls vs. Sangfor NGAF and other solutions. Updated: December 2025.
881,082 professionals have used our research since 2012.