Try our new research platform with insights from 80,000+ expert users

Palo Alto Networks VM-Series vs Sangfor NGAF comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 25, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
580
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Palo Alto Networks VM-Series
Ranking in Firewalls
12th
Average Rating
8.6
Reviews Sentiment
6.9
Number of Reviews
66
Ranking in other categories
Advanced Threat Protection (ATP) (11th)
Sangfor NGAF
Ranking in Firewalls
23rd
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
34
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of January 2026, in the Firewalls category, the mindshare of Fortinet FortiGate is 18.8%, down from 20.7% compared to the previous year. The mindshare of Palo Alto Networks VM-Series is 1.3%, up from 0.7% compared to the previous year. The mindshare of Sangfor NGAF is 1.1%, down from 1.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls Market Share Distribution
ProductMarket Share (%)
Fortinet FortiGate18.8%
Palo Alto Networks VM-Series1.3%
Sangfor NGAF1.1%
Other78.8%
Firewalls
 

Featured Reviews

Vasu Gala - PeerSpot reviewer
Manager, Information Technology Operation/Presales at TechMonarch
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
AV
Cyber security consultant at L&T Technology Services
Enhance cybersecurity for large enterprises using advanced threat management
An improvement could be the integration of security intelligence with Palo Alto cloud via APIs. This would allow IOCs, domains, and hash values to be automatically entered, reducing manual entry. Integration with CSIRT across all use levels would make it easier for administrators to stay updated on the blocked entities without manual intervention.
Zaid Farooqui - PeerSpot reviewer
CIO at Indus Motor Company
Enhanced threat detection with integrated security features and good support
We are using application firewalling, WAF, and SD-WAN. The capabilities are mostly within the box. For example, you will get web application firewall WAF as part and parcel of this. SD-WAN is also bundled. It integrates with their SIEM and SOAR solutions very nicely. Lastly, the pricing point is very cost-efficient as well.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Two aspects I'm happy with regarding Fortinet FortiGate firewall are the easy user interface and its resilience during power interruptions."
"The product has an inbuilt IPS software. We can configure it to block specific anonymous attacks that are happening."
"Mainly the FortiGate reporting system is very good. It guides us through all the expectations of security. Fortinet provides us all that we need for security. Also, Fortinet FortiGate is a next-generation firewall. It is much more advanced than others."
"We are using the FortiGate 100D series. VPN, firewall, anti-malware, OTM, and intrusion prevention are useful features."
"Generally, every aspect of it being a next-generation firewall provides good value."
"It's very easy to configure."
"The best feature of Fortinet FortiGate is its SD-WAN capability, which is included and differs from other products that require an additional license."
"FortiGate SWG's most valuable feature is integration with vulnerability management."
"You already can scale it if you put it in Auto Scaling groups. If you put it in a load balancer, it should already be able to scale."
"The product provides more visibility into our traffic."
"The VM-Series reports how much bandwidth a particular IP is using. You don't need to regularly log into a website, like a Cisco command, to see what kind of ACL it's getting. There isn't an ACL use portal event. You can go there and see how much my ACL has been getting me."
"The most valuable features are web control and IPS/IDS."
"The most valuable features are the DNS security and threat prevention capabilities."
"The VM-Series scalability is fast and easy to implement, improving our security posture as our Azure network grows."
"Embedding it into my application development lifecycle prevents data loss and business disruption, allowing the adoption to operate at the speed of my AWS Cloud."
"We have reduced the number of configuration lines by 90%. We need fewer number of admins right now because of it."
"The stability of Sangfor NGAF is good."
"It enables us to not only detect but also prevent various types of incoming threats, allowing us to take appropriate corrective actions and exercise control over the network."
"It offers application control features."
"The most valuable feature of Sangfor NGAF is its integration."
"In four steps one can configure the entire firewall."
"In terms of the most valuable features, the IPS report is quick and updated. Performance is also valuable."
"The built-in features function as intended, providing exceptional value."
"I think Sangfor NGAF is more valuable than Cisco products because of its simplicity and ease of management. If I compare it with Palo Alto and Cisco, both are quite complex products. And if I compare it with FortiGate firewalls from Fortinet, I have also used all these products. Fortinet and Sangfor NGAF are similar products because the applications behind the application and policy layers are almost identical."
 

Cons

"The feedback that I have received is that the performance could be better, and the user experience is not as good compared to a previous solution we used. It could be more user-friendly. Of course, it still works fine for our operations."
"They could simplify their deployment process, especially when customers have existing devices."
"The dashboard is not user friendly so is a bit complicated."
"We had some issues in the beginning while setting it up, but after doing the firmware update, it is working fine."
"The interface could be better."
"I would rate the technical support of Fortinet FortiGate as a five because it is not as strong as Cisco. Additionally, the turnaround time is very high compared to Cisco."
"FortiGate is really good. We have been using it for quite some time. Initially, when we started off, we had around 70 plus devices of FortiGate, but then Check Point and Palo Alto took over the place. From the product perspective, there are no issues, but from the account perspective, we have had issues. Fortinet's presence in our company is very less. I don't see any Fortinet account managers talking to us, and that presence has diluted in the last two and a half or three years. We have close to 1,500 firewalls. Out of these, 60% of firewalls are from Palo Alto, and a few firewalls are from Check Point. FortiGate firewalls are very less now. It is not because of the product; it is because of the relationship. I don't think they had a good relationship with us, and there was some kind of disconnect for a very long time. The relationship between their accounts team and my leadership team seems to be the reason for phasing out FortiGate."
"They should improve high CPU and memory usage that occurs."
"It has to be more scalable for the deployment of VMs on the cloud."
"The performance of VM instances has some limitations in terms of threshold and throughput compared to appliances."
"The DLP functionality or data classification can be improved in the solution's basic firewalling."
"The current licensing model can be a sore point as we're paying for features we're not fully utilizing."
"It would be helpful if we had a direct number for the support manager or the supporting engineer. That would be better than having to email every time because there would be less wait."
"On the cloud side, they need to come up with more HA solutions to support the multi-region."
"We don't know how it will scale once we start putting more load on it."
"It would be good if the common features work consistently in physical and virtual environments. There was an integration issue in the virtual deployment where it didn't report the interface counters, and we had to upgrade to the latest version, whereas the same thing has been working in the physical deployment for ages now. It seems that it was because of Azure. We were using VMware before, and we didn't have any such issues. We do see such small issues where we expect things to work, but they don't because of some incompatibilities. There also seems to be a limitation on how to do high availability in a virtualized environment. All features should be consistently available in physical and virtual environments. It is not always easy to integrate Palo Alto in the network management system. We would like to be able to compare two network management systems. They can maybe allow monitoring an interface through the GUI to create a reference or do a baseline check about whether your network monitoring system is actually giving you the correct traffic figures. You need traffic figures to be able to recognize the trends and plan the capacity."
"The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardware scalability, allowing for more storage and memory capacity."
"Sangfor need greater exposer in the market because the market is mainly saturated by Fortinet. The user experience of Fortinet is quite different compared to NGAF. If we want to switch our users from Fortinet to NGAF, we have to convince them that the user experience will be much easier once once they start to use it."
"Lacks consistency in terms of filtering certain websites and applications."
"The product must provide more IPS features."
"The interface and user experience are horrible."
"They need to improve their research team and they need to study their data to analyze it and build the product."
"The GUI needs to be improved, lacks logic in some areas."
"Scalability for any network device is not very easy in terms of vertical scalability."
 

Pricing and Cost Advice

"This is not a cheap solution but it isn't expensive, either. It's a good solution for the right price."
"Fortinet has more device options that are affordable for small businesses than Palo Alto, and its enterprise-level models are also cheaper. Palo Alto also has a separate license for VPN connections and SD-WAN, but FortiGate offers these features standard."
"The solution could be better priced."
"Setup cost may be not so low, as you expect, because it depends on different factors, but TCO for 5 years may pleasantly surprise you."
"The pricing is comprehensive and clear. You can easily understand what you are purchasing, including which features correspond to each license and maintenance contract. Overall, the information is straightforward. Additionally, compared to other vendors, their prices are competitive."
"The price is high compared to some of the other solutions."
"The pricing is justified. It's a little pricey, but what you pay for is what you get."
"It is not a very costly product if you compare it with other products. The return on investment is also good. If you compare the return of investment and money that you are spending on this product with Palo Alto, Cisco, Check Point, and other solutions, the investment is very less. We are happy with this solution. The optional licenses are there, and you can choose which one you want and which one to avoid."
"For what you get, it does do what it says. It is a good value for an enterprise firewall.​"
"Because the solution was getting deployed on AWS, it was the best place to go and it was available there."
"The license fee is slightly high."
"Do not buy larges box if you do not need them. Rightsizing is a great task to do before​hand."
"We found purchasing process the product on the AWS Marketplace to be very good."
"The solution is expensive. I rate its pricing a three out of ten."
"It is an expensive product."
"The pricing was expensive but it was comparable to the competition."
"We purchased one year technical support and return to factory support, and we also purchased one-year technical support services. So those were additional."
"The price is unmatcheable."
"I rate the product price as one on a scale of one to ten, where one is low price and ten is high price."
"The license of Sangfor NGAF can be purchased at different interval lengths, such as annually or three years. They offer a range of packages to choose from, such as combo or hybrid packages. We are using the complete solution package which includes IM, NGF and SSL VPN, and WAF."
"If one is very cheap and ten is very expensive, I rate the tool's price as three out of ten."
"Sangfor NGAF price is reasonable and there is an annual license. However, the maintenance cost can be a bit high."
"Sangfor NGAF is a cheaply priced product, especially if I consider the previous product that was used in my company."
"For four to five physical appliances for a licensed firewall, it costs approximately $4,000."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
881,082 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Comms Service Provider
9%
Manufacturing Company
8%
Financial Services Firm
6%
Computer Software Company
11%
Manufacturing Company
10%
Financial Services Firm
10%
University
6%
Manufacturing Company
11%
Financial Services Firm
8%
Computer Software Company
8%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business357
Midsize Enterprise133
Large Enterprise188
By reviewers
Company SizeCount
Small Business29
Midsize Enterprise17
Large Enterprise24
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise10
Large Enterprise10
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it...
How does Azure Firewall compare with Palo Alto Networks VM Series?
Both products are very stable and easily scalable. The setup of Azure Firewall is easy and very user-friendly and the...
What do you like most about Sangfor NGAF?
I think Sangfor NGAF is more valuable than Cisco products because of its simplicity and ease of management. If I comp...
What is your experience regarding pricing and costs for Sangfor NGAF?
The licensing cost is quite high compared to other available firewalls in the market.
What needs improvement with Sangfor NGAF?
The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardwa...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
No data available
Sangfor NGAF Firewall Platform
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Warren Rogers Associates
The Ministry of Science, Technology, and Innovation (Indonesia), Lawson, Inc. (Philippines), Universiti Sultan Zainal Abidin (Indonesia), TEK Automotive (Italy), etc.
Find out what your peers are saying about Palo Alto Networks VM-Series vs. Sangfor NGAF and other solutions. Updated: December 2025.
881,082 professionals have used our research since 2012.