No more typing reviews! Try our Samantha, our new voice AI agent.

Palo Alto Networks NG Firewalls vs Sangfor NGAF comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 25, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
591
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Palo Alto Networks NG Firew...
Ranking in Firewalls
6th
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
199
Ranking in other categories
No ranking in other categories
Sangfor NGAF
Ranking in Firewalls
22nd
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
34
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2026, in the Firewalls category, the mindshare of Fortinet FortiGate is 16.0%, down from 21.6% compared to the previous year. The mindshare of Palo Alto Networks NG Firewalls is 5.1%, up from 3.6% compared to the previous year. The mindshare of Sangfor NGAF is 1.1%, down from 1.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls Mindshare Distribution
ProductMindshare (%)
Fortinet FortiGate16.0%
Palo Alto Networks NG Firewalls5.1%
Sangfor NGAF1.1%
Other77.8%
Firewalls
 

Featured Reviews

Abhinandan Yadav - PeerSpot reviewer
Network Security Engineer at Arrow PC Network Pvt Ltd
Unified security and sd-wan have improved uptime and cut wan costs for multi-site branches
Users report stability issues in certain versions, which requires regular updates. Real-world attacks have also highlighted the need for urgent patching of vulnerabilities.Fortinet FortiGate, while a powerful and feature-rich web firewall, could improve in areas like firmware stability, documentation, and ease of use. The learning curve can be steep for some users. For beginners, support quality can vary, and frequent updates with occasional vulnerabilities call for careful patch management. However, once Fortinet FortiGate is configured, it remains highly reliable and efficient. Customer support needs improvement, as I find it very slow, with reports from other users reflecting that customer support is inadequate.
Abhinandan Yadav - PeerSpot reviewer
Network Security Engineer at Arrow PC Network Pvt Ltd
Advanced visibility has transformed security policies and provides proactive threat prevention
Palo Alto Networks NG Firewalls are powerful, but there are areas for improvement that could enhance their effectiveness, such as cost and licensing models. One of the main challenges we face is the high cost, especially for small to mid-sized businesses (SMBs), with licensing for features such as threat prevention, URL filtering, and WildFire being quite expensive. Additionally, centralized management with Panorama is a dependency for managing multiple firewalls, leading to added costs and complexity, and the built-in centralized management features could be made more user-friendly. Moreover, the learning curve associated with the initial setup and advanced configuration including NAT, decryption, and routing can be complex for new users, and enhancements in logging and reporting could also improve the user experience. There are a few more areas where improvements could streamline operations, such as optimizing commit times. Sometimes committing changes takes a noticeable amount of time, particularly for larger configurations, so a faster commit option would significantly help during urgent troubleshooting. Easier policy troubleshooting is necessary as well. Even though logs are detailed, finding the exact rule match and issue can still be time-consuming in complex environments, so having automated policy simulation and a recommendation tool would expedite troubleshooting. Additionally, better default templates and best practices for SMB data centers and branch offices would speed up deployment and reduce errors. Enhancing integration visibility through a unified dashboard would simplify monitoring, and improving the firmware upgrade process to allow for a more seamless zero downtime upgrade would also enhance operations, as upgrades are stable but typically require careful planning and downtime.
Zaid Farooqui - PeerSpot reviewer
CIO at Indus Motor Company
Enhanced threat detection with integrated security features and good support
We are using application firewalling, WAF, and SD-WAN. The capabilities are mostly within the box. For example, you will get web application firewall WAF as part and parcel of this. SD-WAN is also bundled. It integrates with their SIEM and SOAR solutions very nicely. Lastly, the pricing point is very cost-efficient as well.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Fortinet FortiGate provides combined features that other firewalls do not offer, offering a full package cost-effective manager with all integration supported."
"The best feature of Fortinet FortiGate is SD-WAN; it ensures continuous connectivity by taking over during link failures, preventing any downtime for the company."
"The firewall and VPN features are the most valuable in protecting our customers' networks."
"My primary use is for border protection for connectivity out onto the Internet, and this product has performed exceptionally well."
"The product is easy to use and is stable. The SV1 functionality is a benefit."
"FortiGate is very simple to manage and easy to use."
"The best features of Fortinet FortiGate include good functionality, though the licensing cost is a bit higher; their response time and throughput are very good advantages."
"The most valuable features of Fortinet FortiGate are it is one of the most mature firewalls in the UTM bundle."
"It's a flexible solution and integrates well with apps and other security tools like SIEM, web applications."
"I have found it to be reliable and very easy to use. I haven't really encountered many problems with it because its documentation is clear and readily available on their website."
"One of the things I really like about it is that we have the same features and functions available on the entry-level device (PA-220), as do large corporations with much more costly appliances."
"With its single pane of glass, it makes monitoring and troubleshooting a bit more homogeneous. We are not looking at multiple platforms and monitoring management tools. It is more efficient from that perspective. It is more of a common monitoring and control system for multiple aspects of what used to be different systems. It provides efficiency and time savings."
"Operationally, it is easier, and the manageability and their security features are good."
"I'm using most of its features such as antivirus, anti-spam, and WAF. I'm also using its DNS Security and DNS sinkhole features, as well as the URL filtering and application security features."
"Palo Alto NGFW provides a unified platform that natively integrates all security capabilities, which is very useful. This prevents us from having to go to a lot of different systems, and in some cases, many different systems in many different regions, because we are a global company with 60 remote offices around the world in 30 different countries. Its centralized platform is really what we look for in all services, whether it be security or otherwise."
"Palo Alto Networks NG Firewalls provide a unified platform that natively integrates all security capabilities."
"It enables us to not only detect but also prevent various types of incoming threats, allowing us to take appropriate corrective actions and exercise control over the network."
"This product is very user-friendly, and its Layer 7 security is very much improved."
"Particularly good in the DPI where we can inspect inbound and outbound traffic."
"I think the tool has the feature to detect and kill ransomware in three seconds."
"We are Sangfor Gold partners and I'd recommend this solution for the SMB market, as it is cost-effective and reliable."
"Sangfor is a good solution that provides a WAF and firewall solution. Most other vendors, like Sophos and Fortinet and Cisco, only provide one solution. That's a valuable feature of Sangfor."
"The capabilities are mostly within the box."
"Sangfor has the best capabilities for securing connections, securing web browsers, securing servers, and general threat protection."
 

Cons

"They can do more tests before they release new versions because I would like to be more assured. We had some experiences where they release something new and great, but some of the old features are disabled or they don't work well, which impacts the product satisfaction. The manufacturer should be able to prove that everything works or not only that it might work. This is applicable to most of the other services, software, and hardware companies. They all should work on this. We cannot trust every new release, such as a beta release, on the first day. We wait for some comments on the forums and from other companies that we know. We always wait a few weeks before we use the updated version. They should also extend the VPN client application, especially for Linux versions. Currently, it has an application for Linux devices, but it doesn't work the way we want to connect to the VPN. They use only the old connection, not the new one. They have VPN client applications for Windows and Mac, but they can add more useful features to better manage the devices and monitor the current health of each device. Such features would be helpful for our company."
"I don't like that anything more than very basic reporting is not included."
"Fortinet FortiGate IPS could improve the VPN. There are times it is slow."
"While FortiGate is cheaper than most other solutions, we're seeing increased license renewal costs. Most of our clients are asking for more significant discounts because the price is going up."
"The user interface could be improved to make it less confusing and easier to set up."
"Like any hardware, it has finite scalability restrictions."
"The reporting needs to be improved."
"They should make the product user-friendly and enhance the security features."
"The VPN connectors should be better. We had some challenges in terms of the VPN with Palo Alto Networks NG Firewall, and that's one of the main reasons why we moved to Sophos. Its load handling can also be improved. There were challenges when traffic was high. During peak business hours, it did not function very well. There was a lot of slowness, and the users used to complain, especially when they were connecting from outside. We even reported this to the support team. Their support should also be improved. Technical support was a bit of a concern while using this solution. We didn't get very good support from the Palo Alto team."
"Palo Alto Firewalls could improve by introducing more features, particularly in load balancing."
"Everything has been great. More machine learning would be something great to see, but I don't know if it's a priority for Palo Alto."
"I wish that the Palos had better system logging for the hardware itself."
"They need to provide documentation for CLI, as most of the commands, we get from Community Forums."
"As part of our internet filtering, we integrate heavily with Active Directory, and we use security groups to separate staff into two groups: those who should have full access to the internet and those who should have limited access. It may be just the way the topology is for our domain controllers and that infrastructure, but at peak usage, there seems to be a delay in reading back against the security group to find out what group the user is in."
"Palo Alto has introduced new features in their next-generation firewall, such as SD-WAN. However, the technique of SD-WAN implementation is not easy to understand. It is not easy to deploy at this moment. Maybe, in the future, they can improve the process and how the administrators, partners, or support team can easily deploy this SD-WAN solution on their next-generation firewall. The SD-WAN solution from Fortinet is easy to do. It does not take more than five or 10 minutes. When we talk about Palo Alto, it takes extra effort to implement SD-WAN."
"The scalability compared to other products is not good. You need to change the box whenever you want your number of connection sessions to increase."
"I believe that IAM and NGFW need to merge into a single box, instead of there being two separate box solutions."
"The interface and user experience are horrible."
"Sangfor could improve their interface capacity on the 5100 series model and upgrade their hardware from one gig to 10 gig. This would improve the overall throughput."
"Sangfor NGAF could improve by refining its application control policies, especially in addressing challenges with certain types of applications."
"It does not offer any recommendations on how to mitigate or control attacks."
"Sangfor could improve their interface capacity on the 5100 series model and upgrade their hardware from one gig to 10 gig. This would improve the overall throughput."
"The tool's support is an area of concern where improvements are required."
"The support offered by the product has certain shortcomings where improvements are required. The knowledge levels and response time of the support team need improvement."
 

Pricing and Cost Advice

"The pricing is based on a licensing model for each IPS in your environment."
"We are currently evaluating a Palo Alto solution, and the pricing could be a reason for going for Palo Alto."
"The Indian market is different than the European and American markets. When you compare they need to be a bit more aggressive on pricing."
"Fortinet is competitive price-wise."
"Fortinet FortiGate is expensive."
"Price-wise, it's at a good price point for our market."
"Compared to other firewall products, it's a little cheaper in terms of pricing."
"Its price is reasonable. They have a clear pricing policy. It is not complicated by the number of VPN users at a time. We know what the price is. The yearly subscription for the security license is rather high, but it is all included for whatever number of users you have and the kind of functions you need."
"Cost-wise, I don't see much difference in network-related costs, but this is a premium-grade firewall. There is a cost involved, and you must pay for that to get the most out of it. Its licensing costs are straightforward. There aren't any hidden costs."
"This solution is quite expensive because along with the license there is premium partner support that has to be purchased as a default addition. There is also a specific Threat Prevention License that has to be requested and purchased separately. However, licenses can be purchased for specific periods as opposed to just an annual offering."
"Palo Alto Networks NG Firewalls are very expensive compared to other firewalls such as Fortinet. As a result, Palo Alto is losing some of its market share."
"It is very expensive. You pay for a year."
"The licensing leaves a lot to be desired. We buy the license and then we can't transfer the license without paying an exorbitant fee to our client if they leave us, and that just seems to be a bit of a pain point for us, and there's really no way to partner effectively to make that more reasonable."
"Its price is higher than other vendors. They need to re-think its pricing. With Fortinet, the SD-WAN feature is totally free, whereas, with Palo Alto, I need to pay for this feature. With Fortinet, there is one licensing, and I can get many things, whereas, with Palo Alto, I need to go for individual licensing."
"The tool's pricing is similar to that of Cisco. It's a security appliance; the cost depends on your network topology and specific requirements. The suitability of NG firewalls should be chosen based on your network and what you need. If a colleague from a different company asked for the cheapest and fastest firewall, I suggest they consider options like Sophos. Sophos took over Cyberoam, which was previously a leader in NG firewalls"
"Palo Alto Networks NG Firewalls are expensive compared to other solutions."
"Price-wise, I would not consider Sangfor NGAF to be a cheap product. It is an expensive firewall solution, though not as expensive as something like Palo Alto, which is costly. However, the higher price point is justifiable given the feature set the tool provides that other firewalls may not offer in a single dedicated appliance."
"We purchased one year technical support and return to factory support, and we also purchased one-year technical support services. So those were additional."
"The price could be more competitive."
"The license of Sangfor NGAF can be purchased at different interval lengths, such as annually or three years. They offer a range of packages to choose from, such as combo or hybrid packages. We are using the complete solution package which includes IM, NGF and SSL VPN, and WAF."
"Sangfor is cheaper than competing vendors."
"Sangfor NGAF price is reasonable and there is an annual license. However, the maintenance cost can be a bit high."
"The price falls in the mid-range, neither exceptionally low nor high."
"The pricing is reasonable."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
893,438 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
10%
Comms Service Provider
10%
Manufacturing Company
9%
Financial Services Firm
7%
Computer Software Company
10%
Manufacturing Company
9%
Financial Services Firm
8%
Comms Service Provider
6%
Manufacturing Company
11%
Comms Service Provider
9%
Financial Services Firm
9%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business367
Midsize Enterprise135
Large Enterprise193
By reviewers
Company SizeCount
Small Business77
Midsize Enterprise56
Large Enterprise85
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise10
Large Enterprise10
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is a better choice, Azure Firewall or Palo Alto Networks NG Firewalls?
Azure Firewall Vs. Palo Alto Network NG Firewalls Both solutions provide stellar stability and security. Azure Firew...
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it...
Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat si...
What is your experience regarding pricing and costs for Sangfor NGAF?
The licensing cost is quite high compared to other available firewalls in the market.
What needs improvement with Sangfor NGAF?
The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardwa...
What is your primary use case for Sangfor NGAF?
We are hosting applications over the platform, including websites and NAT traffic from our side. Because it's deploye...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
Palo Alto NGFW, Palo Alto Networks Next-Generation Firewall
Sangfor NGAF Firewall Platform
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
SkiStar AB, Ada County, Global IT Services PSF, Southern Cross Hospitals, Verge Health, University of Portsmouth, Austrian Airlines, The Heinz Endowments
The Ministry of Science, Technology, and Innovation (Indonesia), Lawson, Inc. (Philippines), Universiti Sultan Zainal Abidin (Indonesia), TEK Automotive (Italy), etc.
Find out what your peers are saying about Palo Alto Networks NG Firewalls vs. Sangfor NGAF and other solutions. Updated: April 2026.
893,438 professionals have used our research since 2012.