No more typing reviews! Try our Samantha, our new voice AI agent.

Palo Alto Networks PA-Series vs Sangfor NGAF comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 25, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
592
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Palo Alto Networks PA-Series
Ranking in Firewalls
20th
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
37
Ranking in other categories
No ranking in other categories
Sangfor NGAF
Ranking in Firewalls
21st
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
34
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2026, in the Firewalls category, the mindshare of Fortinet FortiGate is 15.1%, down from 21.7% compared to the previous year. The mindshare of Palo Alto Networks PA-Series is 1.2%, up from 0.6% compared to the previous year. The mindshare of Sangfor NGAF is 1.1%, down from 1.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls Mindshare Distribution
ProductMindshare (%)
Fortinet FortiGate15.1%
Palo Alto Networks PA-Series1.2%
Sangfor NGAF1.1%
Other82.6%
Firewalls
 

Featured Reviews

PD
IT Consultant at a tech services company with 1-10 employees
Cloud features enhance security measures and simplify network management
I've dealt with many firewalls, such as SonicWalls, UniFi, pfSense, and Cisco. We found SonicWall very confusing for the average network engineer or network administrator. I don't recommend SonicWall due to its hard-to-find auditing process for exploits. Although they have fewer exploits, when they do occur, they're significant. With Fortinet FortiGate, you can access the whole firewall, with no hidden spots. pfSense is great, however, it requires a lot of manual work and has no Cloud Connect or easy management from an MSP's perspective. Palo Alto is another option that's great, but their price point isn't for everyone, especially for medium and small businesses; a $10,000 investment doesn't necessarily fit into most budgets. UniFi is another product we've started to use more alongside Fortinet FortiGate, as they have almost all features without a license, with advanced rules that are relatively inexpensive compared to Fortinet FortiGate's $1,500 a year. Fortinet FortiGate and UniFi are the two firewalls we primarily deal with. My opinion is that UniFi has better integration and oversight of the environments compared to Fortinet FortiGate.
Rohit Ghorpade - PeerSpot reviewer
Cloud Network Engineer at a insurance company with 5,001-10,000 employees
Identity-based perimeter control has improved security and supports reliable remote access
Currently, we are working with vendors such as Palo Alto Networks PA-Series, Cisco, Check Point, and Citrix. Palo Alto Networks PA-Series is a better firewall. Deep packet inspection and threat prevention basically comply with whatever traffic is incoming and outgoing through the firewall. I do not think anything improvement is required. The thing is that Palo Alto Networks PA-Series works mostly on a license-based model. If you want to utilize any feature, you have to purchase the license. For example, URL filtering requires a license purchase. It simplifies the implementation because LDAP server profile can be integrated. Basically, that simplifies the implementation of access rule or security policy.
Zaid Farooqui - PeerSpot reviewer
CIO at Indus Motor Company
Enhanced threat detection with integrated security features and good support
We are using application firewalling, WAF, and SD-WAN. The capabilities are mostly within the box. For example, you will get web application firewall WAF as part and parcel of this. SD-WAN is also bundled. It integrates with their SIEM and SOAR solutions very nicely. Lastly, the pricing point is very cost-efficient as well.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The initial setup is very easy."
"We receive substantial help from Fortinet, which is very valuable as they assist us in choosing the right solutions. If we need configuration assistance, they can send specialists who help design the solution."
"My company never had any complaints about the tool in terms of performance or stability."
"New users should be aware that this solution offers very good security."
"Provides good firewall security and has great VPN features."
"Fortinet FortiGate is a very good next-generation firewall."
"The most important feature is that it's easy to use, it is user-friendly and has all the features you need."
"The solution is superior to Cisco in terms of security."
"With the help of Palo Alto Networks PA-Series, we are saving money, time, and multiple other resources."
"Palo Alto blocks the new threats better than other tools."
"The most effective features for threat prevention in the PA-Series are its integration with Cortex and the use of machine learning AI for advanced threat detection."
"Palo Alto Networks firewalls offer single-mode panel processing with live scanning."
"It is a scalable solution."
"The solution provides good customer support."
"It is stable when you set up something and put it into production. Once it works, you don't have other tasks or actions to perform."
"The solution is robust."
"The absolute best part of Sangfor NGAF is their support; it's a 24/7 support channel, and the last time I requested their assistance I got a reply within three minutes and they helped solve the problem immediately."
"Sangfor NGAF's standout feature is its powerful application control, enabling precise restrictions on mobile user access to approved applications."
"The level of support provided to local companies is good. They transform their application control and other settings according to that country."
"In terms of the most valuable features, the IPS report is quick and updated, and performance is also valuable."
"You might try Sangfor if you are on a tight budget. The price is affordable, and Sangfor offers a lot of features. We don't have any complaints about Sangfor."
"So far, the performance and reliability of the product have supported our company's critical network traffic."
"The price versus value is good because the solution is less expensive than Sophos, Fortinet, or SonicWall."
"We've found the technical support to be helpful."
 

Cons

"Palo Alto has a feature called WildFire Analysis that is unavailable in FortiGate. WildFire is better than a sandbox because it can address zero-day threats and vulnerabilities. It can immediately identify zero-day threats from the cloud."
"I prefer Palo Alto over Fortinet FortiGate. Its IPS engine is not better than the Palo Alto version. The monitoring tool needs improvement, and the syslog configuration needs enhancement."
"The main thing they have to improve in Fortinet FortiGate is the technical support; the rest of the features are good enough. We can handle them, but sometimes you really need support, and in that case, we are not getting it at the proper time."
"The only challenge with Fortinet FortiGate is the pricing model."
"We had some issues in the beginning while setting it up, but after doing the firmware update, it is working fine."
"The Wi-Fi controller feature needs a lot of improvement."
"Need to Improvement in Reporting"
"I don't like that anything more than very basic reporting is not included. You have to buy their cloud module that's an add-on for getting more customized reporting."
"In future releases, maybe Palo Alto can enhance and enlarge their portfolio with SIEM solutions. They already have an endpoint protection solution, SOAR solution, that's fine. But when it comes to standalone IDS/IPS solution or email security solution, for example, we don't have any product in that category for Palo Alto."
"Utilizing these features as a unified solution can require additional setup, particularly when incorporating Panorama for centralized management, which may involve extra costs."
"Licenses are too costly. As I compare with Check Point or other OEM, the licenses are too much more costly and they should work on bundled licenses."
"The web interface is slow."
"Palo Alto should integrate artificial intelligence for security purposes in the background for well-known threats and new risks coming to the market."
"The product's gateway services can be improved."
"The solution’s pricing could be improved because it is an expensive solution."
"I encountered a slight issue with the application portal, which was not functioning correctly."
"An area of improvement for Sangfor NGAF could be in the field of reporting and logging."
"Sangfor need greater exposer in the market because the market is mainly saturated by Fortinet. The user experience of Fortinet is quite different compared to NGAF. If we want to switch our users from Fortinet to NGAF, we have to convince them that the user experience will be much easier once once they start to use it."
"I believe that IAM and NGFW need to merge into a single box, instead of there being two separate box solutions."
"The web interface needs to be improved, making it more user-friendly."
"Sangfor NGAF could improve the policies and default criteria. They could be much better."
"The interface and user experience are horrible."
"Sangfor could improve by providing better real-time reporting, as the current reports don't offer the level of detail we need, especially for runtime insights."
"The user interface isn't user-friendly though."
 

Pricing and Cost Advice

"The pricing of Fortinet FortiGate is average, not cheap or overly expensive compared to other firewall solutions in the market. It's effective and affordable for customers."
"I give the pricing a nine out of ten."
"Fortinet FortiGate IPS' licensing is quite simple to understand."
"Fortinet FortiGate IPS is cheaper than other solutions like Cisco or Check Point."
"Before choosing a piece of equipment you have to take into account the cost-benefit offered by each one. Sometimes it is not worth paying a very cheap price to have a minimum level of security."
"Cost-wise, there is not much difference from Sophos, but feature-wise, we get more features."
"There is a subscription-based model to use Fortinet FortiGate. We pay annually for the solution along with the support. If you want to have all the updates, and security patches you will need to renew your support."
"The pricing depends on the FortiGate model we are using, ranging from $3,000 to $20,000 US dollars."
"The pricing is fair."
"The product is offered to users at high prices compared to the pricing model of the other vendors in the market."
"With Palo Alto, even when you enable all the modules, it still provides the exact throughput they advertise."
"We have to pay a yearly licensing fee for the solution."
"The product is expensive."
"Palo Alto is more expensive than FortiGate."
"While other firewalls may come with a higher cost, when you consider the cost in relation to the services and features that Palo Alto offers, it is clear that Palo Alto is delivering excellent value."
"The cost varies depending on the device model, with entry-level firewalls priced around $1,300 to $1,500, while higher-end models can reach prices of several hundred thousand dollars."
"For four to five physical appliances for a licensed firewall, it costs approximately $4,000."
"In my opinion, the price of the tool is good in the Pakistani market. We can easily get discounts if needed."
"The license of Sangfor NGAF can be purchased at different interval lengths, such as annually or three years. They offer a range of packages to choose from, such as combo or hybrid packages. We are using the complete solution package which includes IM, NGF and SSL VPN, and WAF."
"Sangfor is cheaper than competing vendors."
"The product is very cost-effective compared to other brands or vendors."
"Sangfor NGAF price is reasonable and there is an annual license. However, the maintenance cost can be a bit high."
"For over 2000 users, the cost is around 5000 to 6000 USD. If you want a web application firewall, you have to purchase an additional license for it."
"The solution has a TCO that is 32% to 50% less than Sophos, Fortinet, and SonicWall."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
900,747 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
10%
Computer Software Company
9%
Manufacturing Company
9%
Financial Services Firm
7%
Comms Service Provider
9%
Computer Software Company
8%
Government
8%
Outsourcing Company
7%
Financial Services Firm
11%
Manufacturing Company
10%
Comms Service Provider
9%
Construction Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business370
Midsize Enterprise138
Large Enterprise195
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise6
Large Enterprise17
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise10
Large Enterprise10
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is your experience regarding pricing and costs for Palo Alto Networks PA-Series?
If we look at the features, then the price is good, but they do charge for the GlobalProtect VPNs. Overall, the prici...
What needs improvement with Palo Alto Networks PA-Series?
There is room for improvement in Palo Alto Networks PA-Series in the areas where they can minimize applications and i...
What is your primary use case for Palo Alto Networks PA-Series?
I am using Palo Alto Networks PA-Series to ensure protection and cybersecurity by preventing and implementing network...
What is your experience regarding pricing and costs for Sangfor NGAF?
The licensing cost is quite high compared to other available firewalls in the market.
What needs improvement with Sangfor NGAF?
The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardwa...
What is your primary use case for Sangfor NGAF?
We are hosting applications over the platform, including websites and NAT traffic from our side. Because it's deploye...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
No data available
Sangfor NGAF Firewall Platform
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Information Not Available
The Ministry of Science, Technology, and Innovation (Indonesia), Lawson, Inc. (Philippines), Universiti Sultan Zainal Abidin (Indonesia), TEK Automotive (Italy), etc.
Find out what your peers are saying about Palo Alto Networks PA-Series vs. Sangfor NGAF and other solutions. Updated: June 2026.
900,747 professionals have used our research since 2012.