Our company uses the solution for perimeter security. We are distributors in the Middle East and Africa. We look for competitive analysis against Fortinet and Sophos.
Technical Sales Manager at a tech services company with 1-10 employees
Good price but the interface, user experience, and performance are horrible
Pros and Cons
- "The price versus value is good because the solution is less expensive than Sophos, Fortinet, or SonicWall."
- "The interface and user experience are horrible."
What is our primary use case?
What is most valuable?
The price versus value is good because the solution is less expensive than Sophos, Fortinet, or SonicWall.
What needs improvement?
The interface and user experience are horrible. To perform simple things, you need to jump between many screens. There is no simplicity, everything is complex.
The available information is lacking. I'm struggling to give my coworker information about how to configure. The public information available is too old and hasn't been updated.
The solution is not out-of-the-box because it requires a mandatory license.
Outside of China, the solution does not offer active-active, virtual domains, or concurrent sessions. The CCB or UTB sessions and BPM channels are very low. The solution is a Chinese product and that side is different from the rest of the world. China has version 8.0.59 but the rest of the world has 8.0.47 only.
The solution has very, very slow hardware performance.
For how long have I used the solution?
I have been using the solution for one year.
Buyer's Guide
Sangfor NGAF
May 2026
Learn what your peers think about Sangfor NGAF. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
900,644 professionals have used our research since 2012.
What do I think about the stability of the solution?
The solution is stable so I rate stability an nine out of ten.
What do I think about the scalability of the solution?
The solution is not really scalable because it is limited by the capability of the box. You cannot scale out or up because there are hardware limitations.
Scalability is rated a zero out of ten.
How are customer service and support?
In Asia, technical support is good but it is very weak in our region. When you are looking for information from technical support, it will take ages for them to respond but chances are good that they won't respond at all.
Even presale support is not good.
I rate support a two out of ten.
How was the initial setup?
The setup is complex because the interface is not good.
For someone who is already a professional with another product, the setup is rated a five out of ten. For someone with security experience only, the setup is rated a one out of ten.
What about the implementation team?
We implemented the solution in-house. One experienced person can deploy.
Setup for someone who is experienced with other products will take a day for configuration.
Someone who knows security but doesn't know other products like Fortinet, Sophos, or SonicWall will struggle. It takes days to fetch out between sequences and you have to jump between screens for things like ABI, email security, and DLP. It takes time to figure out the proper sequence.
What's my experience with pricing, setup cost, and licensing?
The solution has a total cost of ownership that is 32% to 50% less than Sophos, Fortinet, and SonicWall. Licenses are also less expensive than Sophos.
The solution is not out-of-the box because a license is mandatory. You cannot operate the device by itself. This makes no sense because you should be able to use the default features or operate it without a license. Even if the device is capable, you still need a license.
The four categories of licenses are features, hardware, software updates or technical support, and advanced features. The vendor insists it is mandatory to buy the minimum features license. This license mandate is very strange.
The solution might raise its prices because Fortinet is increasing between 5% to 20% depending on the product and the solution competes with Fortinet. If the leader in the industry increases prices, other vendors will likely follow.
The pricing right now is an eight out of ten because it is good.
Which other solutions did I evaluate?
Fortinet is one of the best products so I recommend its use instead. There is continuous development and good R&D for the product.
What other advice do I have?
I would not recommend use of the solution at all. There has not been one single improvement or feature update in the last year. The solution is very bad at R&D.
The solution also keeps changing names and product positioning. It used to be called Butler, then Cloud Platforms.
There is not a single Sangfor employee right now outside of China who can give an explanation of their products. They don't know how the products even work. For example, they can't explain who can book the NGAF with Neural-X, with Engine Zero, or with a Platform-X or Butler cyber command.
I rate the solution a four out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
A scalable and comprehensive solution that specializes in ransomware detection
Pros and Cons
- "Sangfor NGAF specializes in ransomware detection and helps to protect our network from ransomware threats and malware."
- "We use Sangfor NGAF primarily for security, which has helped save our files from being encrypted by ransomware."
- "The firewall system needs gradual improvements because there are more threats and challenges in the world every day."
What is our primary use case?
Sangfor NGAF specializes in ransomware detection and helps to protect our network from ransomware threats and malware. This is the primary reason we purchased this solution, and we are currently negotiating to upgrade our appliances to volume M5200 Series. Additionally, Sangfor NGAF provides a web application for financial software.
How has it helped my organization?
We use Sangfor NGAF primarily for security, which has helped save our files from being encrypted by ransomware. Our desktop PCs have essential data, like word files and excel documents.
We previously had a ransomware attack on our file server, and Sangfor NGAF protected us by alerting and disconnecting the server from the network.
What needs improvement?
The firewall system needs gradual improvements because there are more threats and challenges in the world every day. Sangfor NGAF has a comprehensive database for ransomware and viruses, but when we compare it to other solutions, the price could be more competitive.
Since we have a very comprehensive solution with Sangfor NGAF, it is hard to identify any additional features we want to add. It already provides good features for ransomware attacks and data recovery. In the past, we wanted encrypted data for a virus to be recoverable, and Sangfor offered the solution.
For how long have I used the solution?
We have been using Sangfor NGAF for four years. We use it for overall IT infrastructure protection and are currently using version 1 of Model M5100.
We currently deploy a hybrid infrastructure of cloud and on-premises. We use the solution for our accounting and financial software, websites, internet blocking, and other features. Some clients are on the cloud, and others are on-premises. We also have a Sangfor solution that filters the in and out traffic.
What do I think about the stability of the solution?
The solution is relatively stable. Interestingly, we discontinued the updates and software licenses about a year ago, and the appliance and solutions are still working. In addition, there is no limitation on the license, so services won't stop if it expires. You can also update the license at any time for a partial cost.
What do I think about the scalability of the solution?
This solution is scalable. We can add many features and lengths and expand according to our needs.
The IT specialists and engineers in my organization use this solution. Our whole organization is under the protection of Sangfor NGAF. The solution has footprints in India and Europe and many government agencies use Sangfor NGAF in Pakistan.
For deployment, we needed three people who were all IT specialists, and only one of them was from Sangfor. As a result, we deployed it with very few resources, and there were no recurring charges. Also, most people are very well-versed in technology and can multitask.
How are customer service and support?
The technical support team was very helpful, provided support, and guided us during our initial deployment. We were good to go in 15 to 20 minutes.
Which solution did I use previously and why did I switch?
We previously used Sophos and pfSense, an open-source firewall.
How was the initial setup?
The initial setup was very straightforward. The solution is out of the box, and the software and appliance can be quickly installed. It has a very nice AI feature, and we only needed to implement parameters and define some policies. The deployment took 15 to 20 minutes because we had to get familiar with the new system.
We defined WAN and LAN networks for our implementation strategy and then defined the servers. Next, we identified the modes and decided the desktop would be the best. There were other considerations but it has been four years, so it is hard to remember all of them.
What about the implementation team?
We completed our deployment in-house.
What was our ROI?
We have seen a return on investment. The systems are protected, and their operating systems are readily available. We are protected from ransomware attacks and the loss of data. This solution protects us, and it has benefits.
What's my experience with pricing, setup cost, and licensing?
On a scale of one to ten, with one being the cheapest, I rate the price a six out of ten. There are no hidden or additional costs other than what we were provided. Therefore, we are happy with our initial decisions.
Which other solutions did I evaluate?
We evaluated other options and completed some financial comparisons but the IT specialists advised that Sangfor NGAF worked well.
What other advice do I have?
I rate this product an eight out of ten because we don't know what we may need from this solution in the future. We are satisfied and hope to upgrade to a new version soon. However, right now, our current version is working fine.
In terms of advice, we would recommend Sangfor NGAF. But, a company should first prepare an analysis, compare different products, and then decide what they want.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Sangfor NGAF
May 2026
Learn what your peers think about Sangfor NGAF. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
900,644 professionals have used our research since 2012.
Teamlead IT Core at SoloInsight Inc.
Next generation firewall that is scalable and one of the best on the market
Pros and Cons
- "Sangfor is a good solution that provides a WAF and firewall solution; most other vendors, like Sophos and Fortinet and Cisco, only provide one solution, and that's a valuable feature of Sangfor."
- "Sangfor could improve their interface capacity on the 5100 series model and upgrade their hardware from one gig to 10 gig. This would improve the overall throughput."
What is our primary use case?
Sangfor is an on-prem firewall I use for my local infrastructure. It is used as an aggregated interface. Behind Sangfor, I have built a data center that is deployed on high availability using a model that is 5100 CV with 10 gig ports.
What is most valuable?
Sangfor is a good solution that provides a WAF and firewall solution. Most other vendors, like Sophos and Fortinet and Cisco, only provide one solution. That's a valuable feature of Sangfor.
What needs improvement?
Sangfor could improve their interface capacity on the 5100 series model and upgrade their hardware from one gig to 10 gig. This would improve the overall throughput.
For how long have I used the solution?
I have used this solution for the last six months.
What do I think about the scalability of the solution?
This is a scalable solution. We have approximately 1,000 users.
How are customer service and support?
The technical support team are available 24/7 and if we need any assistance for Sangfor, FortiGate or Sophos, we can call their support number and they provide assistance from their L2 or L3 engineers.
How would you rate customer service and support?
Positive
How was the initial setup?
It's very easy to set up because Sangfor provided us with export and HCI capabilities. Deployment took almost one week.
The process starts with low level design for internal teams to make a design on network requirements. This contains all current and future requirements.
What's my experience with pricing, setup cost, and licensing?
For four to five physical appliances for a licensed firewall, it costs approximately $4,000.
What other advice do I have?
We have six people managing IT operations. We have not had any issues in the first six months of using this solution.
If you want to deploy a firewall in your infrastructure, Fortinet, Sangfor and Sophos are the best solutions to protect traffic.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Presales Specialist at a tech services company with 1,001-5,000 employees
Cost-effective and has an initial setup phase
Pros and Cons
- "I think the tool has the feature to detect and kill ransomware in three seconds."
- "The tool's support is an area of concern where improvements are required."
What is our primary use case?
My company's customers use the solution as a firewall. Some prefer Sangfor NGAF as a replacement for their current existing firewall. The reason why I am proposing Sangfor NGAF is mainly because of its price point. The tool is very cost-effective compared to other brands.
What is most valuable?
The tool's most effective part stems from the product's ease of use, which is very important because the client has to manage it at the end of the day.
I think the tool has the feature to detect and kill ransomware in three seconds. The tool claims that it can kill the ransomware on the spot in three seconds and restore all the encrypted files.
What needs improvement?
The tool's support is an area of concern where improvements are required. The support should be available locally, I would say. As of now, I think the tool is moving towards offering local support. I have heard from my previous customer that the support is actually from another region, making it quite hard for them to get in touch with the technical team.
For how long have I used the solution?
I have been using Sangfor NGAF for a year. My company is a reseller of the product. I don't remember the version of the solution.
What do I think about the stability of the solution?
It is a stable solution because of the ease of use and inside the firewall itself, the tool offers WAF. Customers who hear that WAF is integrated into the firewall get interested in the solution. WAF is actually another solution. Instead of purchasing a WAF product, you get it inside Sangfor NGAF. Stability-wise, I rate the solution a nine out of ten.
What do I think about the scalability of the solution?
It is a scalable solution. Scalability-wise, I rate the solution an eight out of ten.
In our company, we deal with a wide range of things. The scalability depends on what range the customer chooses. I can't pinpoint or explain the tool's scalability aspect in detail. Different types of firewall models are available.
Under five customers of my company use the tool, and they are all enterprise businesses.
How are customer service and support?
I rate the technical support a seven out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
If one is difficult and ten is easy to set up, I rate the product's initial setup phase an eight out of ten. I never deployed the tool. I am sharing my engineering experience.
I am not quite sure about the deployment situation.
The solution is deployed on the cloud.
What's my experience with pricing, setup cost, and licensing?
If one is very cheap and ten is very expensive, I rate the tool's price as three out of ten. I am not quite sure about the tool's pricing point.
What other advice do I have?
Sangfor NGAF has not shared how it has impacted our customer security operations with my company's sales team. If they do share such information, it is usually with the sales team while I am on the presales team. I am only a consultant, so the product doesn't share such details directly with me.
The tool helped our customers with threat mitigation strategies because it has AI functionalities that are helpful.
Suppose an enterprise customer wants a firewall as the first thing inside the company because of its cost-effectiveness. In that case, I think Sangfor NGAF can be a good option as it comes with the features and abilities of the firewall. I think it is quite a great option for enterprise users.
I rate the tool an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. consultant
System Network Administrator at Connect Logistics
Affordable and offers powerful application control but could use refinement in its application control policies
Pros and Cons
- "Sangfor NGAF's standout feature is its powerful application control, enabling precise restrictions on mobile user access to approved applications."
- "Sangfor NGAF could improve by refining its application control policies, especially in addressing challenges with certain types of applications."
What is most valuable?
Sangfor NGAF's standout feature is its powerful application control, enabling precise restrictions on mobile user access to approved applications. The system's adept intrusion detection further fortifies our network, preventing potential threats.
What needs improvement?
Sangfor NGAF could improve by refining its application control policies, especially in addressing challenges with certain types of applications.
For how long have I used the solution?
I have been using Sangfor NGAF for ten months.
What do I think about the stability of the solution?
So far, we have not had any issues with the stability of the solution.
What do I think about the scalability of the solution?
We have approximately 250 users of Sangfor NGAF at our company, but around 400 users all around.
How are customer service and support?
The support team is excellent. Very helpful and competent.
Which solution did I use previously and why did I switch?
My company opted for Sangfor NGAF over other products because of its affordability, compact size, and easy management features. I like Sangfor more than Fortinet because it is cheaper, has a friendlier interface, and comes with great support. It just feels like a better fit for me.
How was the initial setup?
The initial setup is very easy.
What's my experience with pricing, setup cost, and licensing?
Sangfor NGAF is quite affordable.
Which other solutions did I evaluate?
What other advice do I have?
Although Sangfor NGAF is a great product, I would rate it as a six out of ten just because I'm new in this field and still exploring other options and solutions.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Networking Solutions Specialist at GBM
An affordable solution that is reliable and provides a quick response
Pros and Cons
- "The product is very fast and reliable."
- "The solution should be able to work in a hybrid setup."
What is our primary use case?
We use the solution to connect and protect all the internal servers. All publicly accessible websites and servers are connected to the solution.
What is most valuable?
The product is very fast and reliable. It has a quick response.
What needs improvement?
The solution should be able to work in a hybrid setup.
For how long have I used the solution?
I have been using the solution for one and a half years.
What do I think about the scalability of the solution?
Around 150 users are using the solution in my organization. Both internal and external traffic goes through the firewall because the firewall is placed on the main data center.
How are customer service and support?
If we have any issues, we read the documentation. If the issue cannot be fixed, we can contact the support team. I have not contacted the support team yet. I configure things by myself.
Which solution did I use previously and why did I switch?
We were using Cisco’s firewall before. It ended support. We cannot use the products that have ended support. Cisco and Sangfor work similarly, but their GUIs are different.
How was the initial setup?
The initial setup is very easy.
What's my experience with pricing, setup cost, and licensing?
It is one of the cheapest tools in the market. The choice depends on the customer’s budget.
What other advice do I have?
Overall, I rate the product a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Infrastructure Department Head at a manufacturing company with 11-50 employees
Robust security features with scalability challenges
Pros and Cons
- "It enables us to not only detect but also prevent various types of incoming threats, allowing us to take appropriate corrective actions and exercise control over the network."
- "It does not offer any recommendations on how to mitigate or control attacks."
What is our primary use case?
The system comprises three primary functionalities: defense solutions, detection solutions, and the ability to identify, block, and analyze network traffic. It enables us to not only detect but also prevent various types of incoming threats, allowing us to take appropriate corrective actions and exercise control over the network.
How has it helped my organization?
We have observed numerous threats targeting our network from both internal and external sources. While we have reports detailing these incidents, we currently lack a clear method for prioritizing internal threats.
What is most valuable?
The information provided alerts us to the presence of threats from specific sources, which is highly beneficial.
What needs improvement?
It does not offer any recommendations on how to mitigate or control attacks.
For how long have I used the solution?
I have been using it for three years.
What do I think about the stability of the solution?
We face occasional stability issues. I would rate it seven out of ten.
What do I think about the scalability of the solution?
It doesn't offer significant scalability features.
How are customer service and support?
In the event of a performance issue, such as users reporting slow access to specific websites, we conduct an internal investigation to identify the root cause. If it's determined to be a problem with the equipment, we escalate the issue to the vendor for resolution.
How would you rate customer service and support?
Neutral
What about the implementation team?
When we installed the equipment, we depended on an external consulting party to guide us through the setup and functionality for approximately two weeks. The project team, consisting of both project members and experts in the field, were actively engaged during this period.
What's my experience with pricing, setup cost, and licensing?
The pricing is reasonable. At the time of our decision to acquire the equipment, we were working with a constrained budget and it turned out to be the most suitable choice to meet our specific requirements
Which other solutions did I evaluate?
We considered FortiGate as an option but ultimately decided on Sangfor NGAF due to its more favorable pricing.
What other advice do I have?
I hope that its distributor possesses a high level of product knowledge, and the same applies to Sangfor itself as the principal company. This would enable customers to have a more seamless and enriching experience with the product, eliminating any barriers or disconnect between our team, the customers, and the software. Overall, I would rate it seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Administrator at AI Processings
Good network security capabilities but lacks in logging capabilites
Pros and Cons
- "The stability of Sangfor NGAF is good."
- "An area of improvement for Sangfor NGAF could be in the field of reporting and logging."
What is our primary use case?
We are using Sangfor NGAF for the prevention of attacks in our network through the use of IPS, IDS, and web filtering features.
How has it helped my organization?
There are currently over 1000 active nodes of the solution in use, and we do not have any plans to increase usage at this time.
What is most valuable?
Our primary need is to prevent our users from misusing the Internet, which we achieve through implementing traffic shifting and bandwidth restrictions, among other features offered by Sangfor NGAF
What needs improvement?
An area of improvement for Sangfor NGAF could be in the field of reporting and logging.
For how long have I used the solution?
I have been using the Sangfor NGAF solution for three years now.
What do I think about the stability of the solution?
The stability of Sangfor NGAF is good, and I would rate it a seven out of ten. In fact, compared to its competitors, Sangfor is much better so far.
How are customer service and support?
We get good support from customer service.
How was the initial setup?
The initial setup is easy and it is user-friendly.
What's my experience with pricing, setup cost, and licensing?
We have an annual subscription, which is not expensive. In fact, compared to Fortinet, Sangfor is much more cost-effective.
Which other solutions did I evaluate?
Although we have used different solutions such as Proofpoint, Gadget Control, and FortiNet, we find Sangfor NGAF to be much better due to its security inclusion prevention feature, which is why we introduced this product.
What other advice do I have?
Overall, I would rate the solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Great for inspecting traffic on a very granular level but the GUI lacks logic in some areas
Pros and Cons
- "Particularly good in the DPI where we can inspect inbound and outbound traffic."
- "Sangfor serves most of the basic purposes of a firewall, is particularly good in the DPI where we can inspect the inbound and outbound traffic on a very granular level, gives a very good predictive measure as well as the current measure of things going on in our network, and gives us value for money overall."
- "The GUI needs to be improved, lacks logic in some areas."
- "I think the GUI needs to be improved, there are a lot of areas where the panes do not make sense."
What is our primary use case?
This solution is our firewall. I'm a network administrator.
What is most valuable?
Sangfor serves most of the basic purposes of a firewall. It's particularly good in the DPI where we can inspect the inbound and outbound traffic on a very granular level. It gives a very good predictive measure as well as the current measure of things going on in our network. When it comes to the VPNs, it has a very good throughput when remote users connect, particularly when it comes to site-to-site VPNs, where it provides a good analysis module. You can analyze inbound traffic and different policies on this. It gives us value for money overall.
What needs improvement?
I think the GUI needs to be improved, there are a lot of areas where the panes do not make sense. They have put the NAT in the policy section but at the same time the DPI is in the network pane. The placement of different options in the menu system of this firewall is not that logical and often doesn't make a lot of sense. The operational procedures are a little tricky and require some technical skills. A level one person will have problems. The compatibility needs to be improved.
For how long have I used the solution?
I've been using this solution for three years.
What do I think about the stability of the solution?
We have been experiencing power failures but the solution has been very stable, both from the hardware and the software perspective. We have built a lot of VPN solutions for the firewalls including Cisco, Firewall 2, and pfSense, and it has been very good with that.
What do I think about the scalability of the solution?
We don't require a very highly scalable coefficient but I believe it's scalable.
How are customer service and support?
The technical support is very good. They have a local vendor they have hired for the technical support and if anything cannot be resolved remotely, they come to us. They are very agile and very technically supportive.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup was a little complex because we were previously dealing with command line scenarios and we were not very comfortable with the GUI which is a little complex.
What's my experience with pricing, setup cost, and licensing?
Our licensing costs are around $15,000 per year which is nominal compared to other solutions.
What other advice do I have?
Whether or not this solution is good for you depends on your network. If you have sufficient technical support, then you can go for an open-source solution. Without that and if you have the funds, then this is a good solution. If not, then most of what firewalls do these days can be handled by an open-source solution.
This is a new solution in our country where the price tag really matters. They have targeted the public sector and I'm seeing more and more people moving towards Sangfor because it's cheaper than other products, and the support is quite good.
I rate the solution seven out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Enterprise System Engineer at Innolytix Pakistan Pvt Ltd
Scalable security solution deployed across multiple industries and is well priced compared to competitors
Pros and Cons
- "The level of support provided to local companies is good. They transform their application control and other settings according to that country."
- "It offers good value for money and is much cheaper compared to other firewalls."
- "Sangfor need greater exposer in the market because the market is mainly saturated by Fortinet. The user experience of Fortinet is quite different compared to NGAF. If we want to switch our users from Fortinet to NGAF, we have to convince them that the user experience will be much easier once once they start to use it."
- "We have deployed many firewalls and have faced two or three faulty devices that we have to replace over a year because their power supply was faulty."
What is our primary use case?
We have this solution deployed across multiple industries including education, pharmaceutical and different textile industries. This is a good product for network security and is popular right now. Sangfor is cheaper than well-known products like Fortinet and Palo Alto Firewall NGFS.
What is most valuable?
The level of support provided to local companies is good. They transform their application control and other settings according to that country.
What needs improvement?
Sangfor need greater exposer in the market because the market is mainly saturated by Fortinet. The user experience of Fortinet is quite different compared to NGAF. If we want to switch our users from Fortinet to NGAF, we have to convince them that the user experience will be much easier once once they start to use it.
What do I think about the stability of the solution?
We have deployed many firewalls and have faced two or three faulty devices that we have to replace over a year because their power supply was faulty. Some customers use the device for over five years and they have worked fine but got slower with the time.
What do I think about the scalability of the solution?
This is a scalable solution.
How are customer service and support?
I can vouch for the local support team. They are more than competitive in the market. They are always available for small and big customers. They are onsite whenever we need it and assist with any problem or deployment scenario and are willing to discuss it at any time. I would rate them a three out of five.
Which solution did I use previously and why did I switch?
I have previously used Fortinet. Fortinet is quite a mature product and offers so many features. Sangfor lack a bit in that area. Sangfor include a local database for URLs and other applications. When using Fortinet, you cannot block a local website by default.
How was the initial setup?
The simple deployment of a network on NGF is quite simple and their guides are quite simple as well. The do lack visual guides that are easier for some customers to follow. It's easy to configure a normal deployment scenario for networking and ET. When it comes to high level security and highly advanced features, you need to have some experience in that area to actually apply that on this firewall.
If you're experienced, it would take two or three hour maximum, depending on how many customers are using the policy and how much detailed configuration is needed. I would rate our experience with the setup an eight out of ten.
We have faced some of the issues after deployment with URL filtering which we have logged a ticket for. Our customers are unable to access certain websites. We have diagnosed the problem but we are unable to identify the URL signature or what is blocking the IAM and preventing access to that site.
What's my experience with pricing, setup cost, and licensing?
For over 2000 users, the cost is around 5000 to 6000 USD. If you want a web application firewall, you have to purchase an additional license for it. By default, they provide you with 10 SSL and a VPN. If you want more than 10, you have to pay more. From a pricing perspective, I would rate them a four out of five.
What other advice do I have?
They have a huge product line for large companies and we have deployed a firewall for over 5000 to 10000 users. It is suitable for all type of environments. I would advise others to spend one to two months after deployment on Sangfor to configure the many settings for security services. You have to work on it, keep looking at the logs and make changes as you go. You need this time to analyze, make future risk assessments and reconfigure the work from time to time. Only once this is done, can you consider deployment complete.
It offers good value for money and is much cheaper compared to other firewalls. I would suggest Sangfor to those who are cost conscious.
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Download our free Sangfor NGAF Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2026
Product Categories
FirewallsPopular Comparisons
Fortinet FortiGate
Netgate pfSense
Sophos Firewall
OPNsense
Cisco Secure Firewall
Palo Alto Networks NG Firewalls
WatchGuard Firebox
Check Point Quantum Force (NGFW)
Cisco Meraki MX
Check Point Cloud Firewall (formerly CloudGuard Network Security)
Palo Alto Networks VM-Series
Fortinet FortiGate-VM
SonicWall TZ
Juniper SRX Series Firewall
SonicWall NSa
Buyer's Guide
Download our free Sangfor NGAF Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What do you recommend for a corporate firewall implementation?
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Which is the best network firewall for a small retailer?
- When evaluating Firewalls, what aspect do you think is the most important to look for?
- Cyberoam or Fortinet?
- Fortinet, Palo Alto or Check Point?
- If you could go back, would you change your decision to buy that firewall and why?
- Sophos XG vs Fortigate UTM
- Can you recommend a solution to replace Cyberoam 200ing Firewall?
















