Try our new research platform with insights from 80,000+ expert users

Sangfor NGAF vs WatchGuard Firebox comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Nov 9, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
580
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Sangfor NGAF
Ranking in Firewalls
23rd
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
34
Ranking in other categories
No ranking in other categories
WatchGuard Firebox
Ranking in Firewalls
11th
Average Rating
8.2
Reviews Sentiment
6.9
Number of Reviews
127
Ranking in other categories
Data Loss Prevention (DLP) (11th), Intrusion Detection and Prevention Software (IDPS) (4th), Anti-Malware Tools (7th), Endpoint Detection and Response (EDR) (18th), Application Control (5th), Unified Threat Management (UTM) (4th)
 

Mindshare comparison

As of January 2026, in the Firewalls category, the mindshare of Fortinet FortiGate is 18.8%, down from 20.7% compared to the previous year. The mindshare of Sangfor NGAF is 1.1%, down from 1.1% compared to the previous year. The mindshare of WatchGuard Firebox is 2.6%, down from 2.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls Market Share Distribution
ProductMarket Share (%)
Fortinet FortiGate18.8%
WatchGuard Firebox2.6%
Sangfor NGAF1.1%
Other77.5%
Firewalls
 

Featured Reviews

Vasu Gala - PeerSpot reviewer
Manager, Information Technology Operation/Presales at TechMonarch
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
Zaid Farooqui - PeerSpot reviewer
CIO at Indus Motor Company
Enhanced threat detection with integrated security features and good support
We are using application firewalling, WAF, and SD-WAN. The capabilities are mostly within the box. For example, you will get web application firewall WAF as part and parcel of this. SD-WAN is also bundled. It integrates with their SIEM and SOAR solutions very nicely. Lastly, the pricing point is very cost-efficient as well.
PS
CEO at ajuntament del Prat
Network protection has improved with stronger VPN connectivity but administration remains complex
Deploying WatchGuard Firebox was quite easy, but we have had some problems regarding the VPN and the administration of the tool and the two firewalls that we have. When comparing WatchGuard Firebox with our previous solution, Palo Alto, we have had some problems in administration because of the tools. I think that they have some aspects in their system that are cloud-provided, but they also have an on-premise solution, which makes this combination good. Although I should say that when compared to Palo Alto, we have taken a step backwards. In general, I would rate WatchGuard Firebox around 6-7; it is a good firewall, but they lack good administration tools. We experience many problems with the performance and administration tools on the web, including several issues with VPNs.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The best feature of Fortinet FortiGate is SD-WAN."
"FortiGate is a great solution, although initially, it faced challenges in the Brazilian market due to lower brand recognition than Cisco. However, explaining and demonstrating its product format and offerings has proven easy. The cost-effectiveness and better features of FortiGate have made some clients skeptical. We set up a trial period, and they eventually opted for it. Many clients were convinced it was great after experiencing the solution's capabilities firsthand."
"My clients appreciate it for its features. It is easy to install and manage, and it offers all-around protection, including web filtering, content filtering, IPS, and IDS."
"The most valuable feature is the web filter."
"The pricing is excellent. It's much less expensive than Cisco."
"Fortinet FortiGate has helped me reduce Mean Time To Respond, or MTTR, and helped my organization consolidate all of the tools in one application."
"FortiGate Next Generation Firewall can be described as the most complete solution."
"It has a good UI and overall integration, including FortiGate Manager for controlling all firewalls from a single place."
"Sangfor has the best capabilities for securing connections, securing web browsers, securing servers, and general threat protection."
"I think Sangfor NGAF is more valuable than Cisco products because of its simplicity and ease of management. If I compare it with Palo Alto and Cisco, both are quite complex products. And if I compare it with FortiGate firewalls from Fortinet, I have also used all these products. Fortinet and Sangfor NGAF are similar products because the applications behind the application and policy layers are almost identical."
"The top functionality is the reporting feature."
"So far, the performance and reliability of the product have supported our company's critical network traffic."
"The price versus value is good because the solution is less expensive than Sophos, Fortinet, or SonicWall."
"The absolute best part of Sangfor NGAF is their support. It's a 24/7 support channel, and the last time I requested their assistance I got a reply within three minutes. They helped solve the problem immediately."
"In our hospital, Sangfor NGAF works well for us in terms of ensuring confidentiality and availability, which are crucial in the healthcare industry."
"It seems to be a durable, stable product."
"It does its job very well, and it is quite easy to put to use."
"There are no problems with the technical support. If a problem occurs it gets resolved immediately with our technical support partners."
"The ports that I have assigned appear to be unattainable to outside 'mal-actors,' unless they have an address registered on the internet that this thing is expecting. That's a layer of security."
"The solution has a useful traffic monitor."
"The main features of the solution are the control of the site-to-site network access and the overall features."
"I have found the DNS Watch feature for intrusion and prevention response and APT Locker most valuable to me."
"From my experience with their customer service team, I would say that they seem quite knowledgeable and fairly quick to respond."
"The set up was quite straightforward and we handled it in-house. It took a few hours to deploy the product."
 

Cons

"They could improve the response time and quality of support."
"We were not able to build a full-mesh VPN; however, I am not sure if this was the fault of Fortinet FortiGate."
"If I had any criticism that I would give FortiGate, it would be that they need to stop changing their logging format. Every time we do a firmware upgrade, it is a massive issue on the SIM. Parsers have to be rebuilt. Even the FortiGate guys came in and said that they don't play well in the sandbox."
"Areas of improvement for Fortinet FortiGate include the need for more training and certification, especially when dealing with distributors globally, which presents challenges in product availability and delivery timelines."
"It is somewhat expensive compared to other solutions such as Sophos."
"Fortinet FortiGate IPS could improve the configuration. In some use cases, there can be some configuration conflicts."
"Some of the web policy reports could be improved."
"I would like to see more advanced developments of a wireless controller in the future."
"The support for YouTube or the Internet is not enough."
"The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardware scalability, allowing for more storage and memory capacity."
"The tool is expensive."
"The product must provide more IPS features."
"There is room for improvement in dependency on certain infrastructure, like the DNS dependency on the current DNS server that the company has. It should be standalone. It should not depend on any other DNS server."
"Sangfor NGAF could improve by refining its application control policies, especially in addressing challenges with certain types of applications."
"An area of improvement for Sangfor NGAF could be in the field of reporting and logging."
"An area for improvement would be the number of ports defined on the box. In the next release, I would like them to develop their provisioning stage of enrolling end devices."
"They need to stop the VLAN limitation. They have a VLAN limitation on the size of their boxes. It is the worst thing ever. They basically sell their boxes by the size and the number of VLANs it can handle, which is a real issue. You spend a couple of thousand dollars for a firewall, and you can only do 30 VLANs, which is extremely silly, as a matter of fact. It would be really great to have something for easier mass rule changes. It also needs a drag-and-drop function so that you don't have to constantly duplicate firewall rules. It would be nice to have such a feature because you got one WatchGuard, and you want to mirror its config and change a couple of things in another one and move some things around. It is not as easy as you would necessarily think. It is kind of expensive, and its pricing can be a little better for sure."
"They are working on cloud-based options. However, they do not have the options fully functional in their solution at this time."
"There's always room for improvement, especially if the threats are getting more sophisticated and the IT department cannot sufficiently meet this kind of sophistication with their own knowledge and experience. Knowing that this solution can get up to the level of addressing a lot of these threats is something that everybody wishes for. If we look at the dark web and the lawful web, they are two opposites, and if these two good and bad collide in the world of the internet, you want the best possible product—especially if you cannot get to that point of knowledge. I am just an individual and end user, with limited knowledge of usage. That's why I say there's always room for improvement, from their side and also from mine, because by knowing exactly what they can achieve and the knowledge that they can get on an everyday basis, and the portion that is understandable to me, it's an improvement for them as well."
"Its documentation could be improved. Sometimes, you need to search a bit longer to find what you are looking for."
"Its graphical user interface could be improved because not everybody is technical. There is a lack of knowledge, and they can give some training for this solution."
"I believe there is a need for additional measures to connect mobile devices securely to the Firebox router."
"The scalability of the solution needs improvement."
"In terms of the reporting and management features — and this isn't necessarily a WatchGuard issue, this seems to be more of an industry-wide issue — you get reports, but a lot of times you don't know what you're looking at. You're so overwhelmed with the data. You're getting a lot of stuff that doesn't matter, so it takes time to parse through it, to actually get what you want to know."
 

Pricing and Cost Advice

"FortiGate Next Generation Firewall is a very cheap solution."
"It is somewhat expensive compared to other solutions such as Sophos."
"The price of Fortinet FortiGate is reasonable."
"The initial setup is super straight forward and as far as the licensing goes for the small product that we have, the pricing was pretty competitive. It wasn't as simple and as cheap as a SonicWall but for the service we would get it was a good price."
"We pay about $4,000 for a yearly license, and there aren't any additional fees."
"The solution requires a license annually, it is not a user license, you can have as many users as your want. I must renew the license regularly per device."
"It cost us around $73,000 for three years."
"Here in Brazil, we're going through difficult economic times and the tax on the dollar is high. All the solutions from minor competitors are growing in the market. The prices have come more competitive."
"Price-wise, I would not consider Sangfor NGAF to be a cheap product. It is an expensive firewall solution, though not as expensive as something like Palo Alto, which is costly. However, the higher price point is justifiable given the feature set the tool provides that other firewalls may not offer in a single dedicated appliance."
"It costs about 8 to 10 thousand dollars per year for 500 users, standard licensing fees included."
"The price could be more competitive."
"We purchased one year technical support and return to factory support, and we also purchased one-year technical support services. So those were additional."
"When it comes to the price of firewall solutions, Sangfor NGAF takes the cake."
"Sangfor NGAF price is reasonable and there is an annual license. However, the maintenance cost can be a bit high."
"It is one of the cheapest tools in the market."
"If one is very cheap and ten is very expensive, I rate the tool's price as three out of ten."
"The price of WatchGuard Intrusion Prevention Service is pretty reasonable compared to similar solutions."
"We pay about $3,500 every three years."
"WatchGuard offers competitive pricing with attractive margins, benefiting both the company and its partners."
"The licensing can be a one-time purchase unless you need the extra services for example twenty-four seven support."
"It has a very good price. It is not the most expensive one, and it is also not the cheapest one. It is just spot-on in terms of price."
"I usually tell people that it's really affordable as well, particularly compared to Cisco."
"I think the larger firewall packages are much better because a normal firewall is not enough for these times. You need IPS, APT, and all the security features of a firewall that you can buy."
"The two larger devices are about $1,000 each and the smaller ones are about $500 or $600 each... It's cheaper and you have more control because it's self-managed."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
881,082 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Comms Service Provider
9%
Manufacturing Company
8%
Financial Services Firm
6%
Manufacturing Company
11%
Financial Services Firm
8%
Computer Software Company
8%
Comms Service Provider
8%
Computer Software Company
11%
Comms Service Provider
11%
Manufacturing Company
7%
Retailer
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business357
Midsize Enterprise133
Large Enterprise188
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise10
Large Enterprise10
By reviewers
Company SizeCount
Small Business92
Midsize Enterprise27
Large Enterprise15
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What do you like most about Sangfor NGAF?
I think Sangfor NGAF is more valuable than Cisco products because of its simplicity and ease of management. If I comp...
What is your experience regarding pricing and costs for Sangfor NGAF?
The licensing cost is quite high compared to other available firewalls in the market.
What needs improvement with Sangfor NGAF?
The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardwa...
What is your primary use case for WatchGuard Firebox?
We are providing our services to all WatchGuard customers in the region.
What is your primary use case for WatchGuard Firebox?
We just use it as a secondary WiFi device. We're a small office and we needed to set up a WiFi device for a few of ou...
What is your primary use case for WatchGuard Firebox?
We're a hospital and we use it for developing our incoming and outgoing policies, and we also use it for VPN.
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
Sangfor NGAF Firewall Platform
WatchGuard Threat Detection and Response, WatchGuard Application Control, WatchGuard Data Loss Prevention, WatchGuard Gateway AntiVirus, WatchGuard Intrusion Prevention Service
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
The Ministry of Science, Technology, and Innovation (Indonesia), Lawson, Inc. (Philippines), Universiti Sultan Zainal Abidin (Indonesia), TEK Automotive (Italy), etc.
Ellips, Diecutstickers.com, Clarke Energy, NCR, Wrest Park, Homeslice Pizza, Fortessa Tableware Solutions, The Phoenix Residence
Find out what your peers are saying about Sangfor NGAF vs. WatchGuard Firebox and other solutions. Updated: December 2025.
881,082 professionals have used our research since 2012.