Try our new research platform with insights from 80,000+ expert users

Palo Alto Networks PA-Series vs Sangfor NGAF comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 6, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
2nd
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
334
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st)
Palo Alto Networks PA-Series
Ranking in Firewalls
14th
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
32
Ranking in other categories
No ranking in other categories
Sangfor NGAF
Ranking in Firewalls
18th
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
36
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2025, in the Firewalls category, the mindshare of Fortinet FortiGate is 21.4%, up from 17.7% compared to the previous year. The mindshare of Palo Alto Networks PA-Series is 0.5%, up from 0.1% compared to the previous year. The mindshare of Sangfor NGAF is 1.3%, up from 0.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls
 

Featured Reviews

EhabAli - PeerSpot reviewer
Efficient, user-friendly, and affordable
In the past, NSS Labs was utilized to test files and verify the numbers and datasheets. It would be beneficial to have an organization or testing lab that can verify the numbers in our datasheets since changes are frequently made, which can be inconvenient for review. For instance, when comparing different competitors such as Forcepoint, Palo Alto, and Check Point, the throughput or numbers in the datasheet may be lower than the actual numbers. Conversely, Fortinet typically reports very high numbers, but they cannot be replicated in the real world. Therefore, it would be advantageous for them to partner with a neutral testing organization such as NSS Labs to validate these numbers, thus providing more credibility and comfort to everyone regarding the accuracy of the datasheets. For the migration, everyone has a firewall in use and I am selling Fortinet. Typically, I am replacing another firewall. Previously, there was a tool available to convert configurations from one firewall, such as Palo Alto, to Fortinet, but this tool is no longer free. If it could be made free again, it would be very beneficial. This tool shows a lot of promise and is very good. Making it free would help many companies deliver their products in a more efficient and integrated way. It would also be more valuable to include the tool with the firewall package or license instead of having to pay extra for it. Paying extra puts more pressure on small companies to deliver the firewall and complete the configuration, especially if they have hundreds or thousands of policies. It's very painful to move through these policies line by line. The stability has room for improvement. When it comes to Secure SD-WAN, everything is fine. They are going the right way. SD-WAN is very promising. They can provide the SD-WAN solution separately, but they will not take this approach because even the smallest firewall can support the features, so there is no need to have a separate service or appliance. They are following the right steps, and there is nothing to be improved. Feature-wise, I'm really satisfied with the new release, and the features they have added. For now, it's fine.
Deminda Dilan - PeerSpot reviewer
Good for enterprise-level businesses and offers many features like URL filtering and antivirus capabilities
Palo Alto can improve the web application firewall (WAF) feature at layer 7. Currently, I don't think it's available. If they can improve that, it would be better. We wouldn't need to purchase a separate WAF solution because they already have advanced URL filtering. But I don't think that advanced URL filtering has the same features as a dedicated WAF, like F5 or other solutions. That is an area for improvement. If they can improve the WAF feature, customers won't have to buy a separate WAF solution. They could do it with the same Palo Alto firewall, perhaps through a subscription-based model. So the web application firewall feature has to be improved.
Zaid Farooqui - PeerSpot reviewer
Enhanced threat detection with integrated security features and good support
We are using application firewalling, WAF, and SD-WAN. The capabilities are mostly within the box. For example, you will get web application firewall WAF as part and parcel of this. SD-WAN is also bundled. It integrates with their SIEM and SOAR solutions very nicely. Lastly, the pricing point is very cost-efficient as well.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It's great for capturing the traffic and troubleshooting it."
"The pricing is great and very reasonable."
"The strengths of Fortinet FortiGate include network security, VPN, site-to-site tunnels, client VPN solutions, two-factor authentication for VPN clients, and SD-WAN for branch level. We have implemented these solutions for various customers."
"The solution has very good threat and content filtering switches."
"The most useful functionality of Fortinet FortiGate is the user interface, multiple engines, and their cloud with the latest integrations. Additionally, the Security Fabric tool is very good."
"We purchased Fortinet because of the pricing, its functionality, because it met our requirements, and the total cost of ownership over five years was quite reasonable. In the market, Fortinet is rated quite well."
"FortiGate improved our security. It's one of the best hardware firewalls."
"It is a safe product."
"It has its own logging system. You can go to monitoring and check the logs to see if a connection is getting blocked. You can use multiple types of logs to check if a file or a port is getting blocked or if there are any TCP resets from the source or destination. It's easy to troubleshoot with the monitoring and logging it provides."
"The solution provides good customer support."
"Palo Alto has predefined applications that you can control at the application level."
"It is a scalable solution."
"The most valuable feature of Palo Alto Networks PA-Series is that it is highly customizable."
"The reporting feature and application ID functionality within Palo Alto Networks PA-Series are incredibly valuable to us."
"It is a stable solution. Stability-wise, I rate the solution a ten out of ten."
"The solution is used for security and IoT security."
"The most valuable feature of Sangfor NGAF is its integration."
"So far, the performance and reliability of the product have supported our company's critical network traffic."
"Sangfor is a good solution that provides a WAF and firewall solution. Most other vendors, like Sophos and Fortinet and Cisco, only provide one solution. That's a valuable feature of Sangfor."
"SSL VPN is the best feature."
"The most valuable features are the WAN optimization, the internet access gateway (IAG), and the central console, which allows us to implement on their firewall."
"The VPN connectivity feature is really nice."
"It's a very simple to use product."
"I think the tool has the feature to detect and kill ransomware in three seconds."
 

Cons

"The configuration part was challenging, especially converting configurations from another OEM to FortiGate."
"They are doing good, but they can improve the distributor assignment. The availability of the product and the timeline of delivery are the main things. The distribution should be swift, and the distributor should not reach out to end customers directly. They should work as a distributor. There should also be one more local distributor. Currently, there is only one distributor in Pakistan, and the rest of them are in UAE. It is difficult to work with only one distributor. Sometimes, you don't get along with the same distributor, and that's why they should have one more distributor. Their licensing should also be improved. The activation or renewal of the product should be done from the date of renewal, not from the date on which the license expired."
"Price, of course, can always be more competitive or better."
"Fortinet FortiGate should improve the VPN tokens."
"Fortinet FortiGate could improve if it had a cloud-managed solution."
"Fortinet FortiGate is a firewall solution and once it's deployed, you can rest assured that your system is secure."
"I'm not sure if it's something that they already have or are developing something, however, we need some dedicated features for container security."
"NGN, reporting and controls."
"The UI definitely needs work. In my opinion, the UI could be simpler and more user-friendly for the average user."
"Palo Alto Networks PA-Series is expensive. We would like to see additional threat hunting features."
"Palo Alto can improve the web application firewall (WAF) feature at layer 7."
"I have found that the tool works well for me, but there are areas where security testing and protection could be improved, especially in virtual or cloud environments. However, in this project, once we deployed it, we haven't encountered any issues. The cost is currently manageable, but as we migrate fully into the cloud, additional features like capacity upgrading and improvements to hardware resources will be necessary, especially since our equipment consists of older generation switches and routers. So, I'm looking for additional capabilities in these areas."
"The solution's licensing price could be improved."
"The SD-WAN feature of Palo Alto Networks is not good compared to FortiGate."
"With Palo Alto Networks PA-Series, I find that the support team takes a long time to resolve the issues that a user may face during the use of the product."
"The product must provide multiple threat detection features."
"Occasional issues with breaches which are dealt with expediently."
"The GUI needs to be improved, lacks logic in some areas."
"I feel Sangfor should follow the hierarchy and close deals via resellers instead of closing it all with their own team."
"The interface and user experience are horrible."
"The product must provide more IPS features."
"It has an issue with the Sangfor Cloud Platform rather than the firewall. When we run a virtual machine, the window tabs display Chinese characters."
"They need to improve their research team and they need to study their data to analyze it and build the product."
"Sangfor could improve by providing better real-time reporting, as the current reports don't offer the level of detail we need, especially for runtime insights."
 

Pricing and Cost Advice

"When I look around at other products, such as Sophos, Fortinet FortiGate is 20% to 30% more expensive with our current cost."
"The beauty is the price performance ratio is great with FortiGate. It provides all the features we needed and the price is comparable with others' firewalls. The price is quite competitive with the firewalls with similar features."
"Our licensing costs are on a yearly basis."
"I had to pay for the license for the firewall, but it is guaranteed to have updates. I expect a good service for it. It was about €1000 for a year, and there was no additional cost."
"They need to be competitive with other solutions."
"I would rate the pricing a five out of ten"
"It is quite affordable for our customers. There is a separate cost for IPS, antivirus, web filtering, and other features. They have a great choice of licenses. You can go for the license that you want, which is quite useful."
"I would say that all things considered, the pricing is pretty good."
"The solution's pricing is high compared to that of Cisco and Fortinet."
"This product has an affordable and reasonable price point."
"The tool's pricing was reasonable when we bought the product. We pay around 60,000 dollars per year."
"The cost varies depending on the device model, with entry-level firewalls priced around $1,300 to $1,500, while higher-end models can reach prices of several hundred thousand dollars."
"Palo Alto’s pricing is way higher than any other solution provider."
"With Palo Alto, even when you enable all the modules, it still provides the exact throughput they advertise."
"Compared to other vendors, Palo Alto Networks PA-Series is expensive."
"While other firewalls may come with a higher cost, when you consider the cost in relation to the services and features that Palo Alto offers, it is clear that Palo Alto is delivering excellent value."
"Sangfor is cheaper than competing vendors."
"Sangfor NGAF is a cheaply priced product, especially if I consider the previous product that was used in my company."
"It is one of the cheapest tools in the market."
"If one is very cheap and ten is very expensive, I rate the tool's price as three out of ten."
"I rate the product price as one on a scale of one to ten, where one is low price and ten is high price."
"The price is unmatcheable."
"The price falls in the mid-range, neither exceptionally low nor high."
"The price could be more competitive."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
851,604 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
19%
Computer Software Company
14%
Comms Service Provider
7%
Manufacturing Company
6%
Computer Software Company
18%
Manufacturing Company
12%
University
8%
Government
7%
Computer Software Company
13%
Manufacturing Company
10%
Financial Services Firm
9%
Educational Organization
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What do you like most about Palo Alto Networks PA-Series?
The reporting feature and application ID functionality within Palo Alto Networks PA-Series are incredibly valuable to...
What needs improvement with Palo Alto Networks PA-Series?
The interface of Palo Alto Networks PA-Series should be made much more user-friendly.
What do you like most about Sangfor NGAF?
I think Sangfor NGAF is more valuable than Cisco products because of its simplicity and ease of management. If I comp...
What is your experience regarding pricing and costs for Sangfor NGAF?
The licensing cost is quite high compared to other available firewalls in the market.
What needs improvement with Sangfor NGAF?
The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardwa...
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate, Fortinet Firewall
No data available
Sangfor NGAF Firewall Platform
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Information Not Available
The Ministry of Science, Technology, and Innovation (Indonesia), Lawson, Inc. (Philippines), Universiti Sultan Zainal Abidin (Indonesia), TEK Automotive (Italy), etc.
Find out what your peers are saying about Palo Alto Networks PA-Series vs. Sangfor NGAF and other solutions. Updated: April 2025.
851,604 professionals have used our research since 2012.