Our company uses the solution for perimeter security. We are distributors in the Middle East and Africa. We look for competitive analysis against Fortinet and Sophos.
Technical Sales Manager at a tech services company with 1-10 employees
Good price but the interface, user experience, and performance are horrible
Pros and Cons
- "The price versus value is good because the solution is less expensive than Sophos, Fortinet, or SonicWall."
- "The interface and user experience are horrible."
What is our primary use case?
What is most valuable?
The price versus value is good because the solution is less expensive than Sophos, Fortinet, or SonicWall.
What needs improvement?
The interface and user experience are horrible. To perform simple things, you need to jump between many screens. There is no simplicity, everything is complex.
The available information is lacking. I'm struggling to give my coworker information about how to configure. The public information available is too old and hasn't been updated.
The solution is not out-of-the-box because it requires a mandatory license.
Outside of China, the solution does not offer active-active, virtual domains, or concurrent sessions. The CCB or UTB sessions and BPM channels are very low. The solution is a Chinese product and that side is different from the rest of the world. China has version 8.0.59 but the rest of the world has 8.0.47 only.
The solution has very, very slow hardware performance.
For how long have I used the solution?
I have been using the solution for one year.
Buyer's Guide
Sangfor NGAF
August 2026
Learn what your peers think about Sangfor NGAF. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,806 professionals have used our research since 2012.
What do I think about the stability of the solution?
The solution is stable so I rate stability an nine out of ten.
What do I think about the scalability of the solution?
The solution is not really scalable because it is limited by the capability of the box. You cannot scale out or up because there are hardware limitations.
Scalability is rated a zero out of ten.
How are customer service and support?
In Asia, technical support is good but it is very weak in our region. When you are looking for information from technical support, it will take ages for them to respond but chances are good that they won't respond at all.
Even presale support is not good.
I rate support a two out of ten.
How was the initial setup?
The setup is complex because the interface is not good.
For someone who is already a professional with another product, the setup is rated a five out of ten. For someone with security experience only, the setup is rated a one out of ten.
What about the implementation team?
We implemented the solution in-house. One experienced person can deploy.
Setup for someone who is experienced with other products will take a day for configuration.
Someone who knows security but doesn't know other products like Fortinet, Sophos, or SonicWall will struggle. It takes days to fetch out between sequences and you have to jump between screens for things like ABI, email security, and DLP. It takes time to figure out the proper sequence.
What's my experience with pricing, setup cost, and licensing?
The solution has a total cost of ownership that is 32% to 50% less than Sophos, Fortinet, and SonicWall. Licenses are also less expensive than Sophos.
The solution is not out-of-the box because a license is mandatory. You cannot operate the device by itself. This makes no sense because you should be able to use the default features or operate it without a license. Even if the device is capable, you still need a license.
The four categories of licenses are features, hardware, software updates or technical support, and advanced features. The vendor insists it is mandatory to buy the minimum features license. This license mandate is very strange.
The solution might raise its prices because Fortinet is increasing between 5% to 20% depending on the product and the solution competes with Fortinet. If the leader in the industry increases prices, other vendors will likely follow.
The pricing right now is an eight out of ten because it is good.
Which other solutions did I evaluate?
Fortinet is one of the best products so I recommend its use instead. There is continuous development and good R&D for the product.
What other advice do I have?
I would not recommend use of the solution at all. There has not been one single improvement or feature update in the last year. The solution is very bad at R&D.
The solution also keeps changing names and product positioning. It used to be called Butler, then Cloud Platforms.
There is not a single Sangfor employee right now outside of China who can give an explanation of their products. They don't know how the products even work. For example, they can't explain who can book the NGAF with Neural-X, with Engine Zero, or with a Platform-X or Butler cyber command.
I rate the solution a four out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Presales Specialist at a tech services company with 1,001-5,000 employees
Cost-effective and has an initial setup phase
Pros and Cons
- "I think the tool has the feature to detect and kill ransomware in three seconds."
- "The tool's support is an area of concern where improvements are required."
What is our primary use case?
My company's customers use the solution as a firewall. Some prefer Sangfor NGAF as a replacement for their current existing firewall. The reason why I am proposing Sangfor NGAF is mainly because of its price point. The tool is very cost-effective compared to other brands.
What is most valuable?
The tool's most effective part stems from the product's ease of use, which is very important because the client has to manage it at the end of the day.
I think the tool has the feature to detect and kill ransomware in three seconds. The tool claims that it can kill the ransomware on the spot in three seconds and restore all the encrypted files.
What needs improvement?
The tool's support is an area of concern where improvements are required. The support should be available locally, I would say. As of now, I think the tool is moving towards offering local support. I have heard from my previous customer that the support is actually from another region, making it quite hard for them to get in touch with the technical team.
For how long have I used the solution?
I have been using Sangfor NGAF for a year. My company is a reseller of the product. I don't remember the version of the solution.
What do I think about the stability of the solution?
It is a stable solution because of the ease of use and inside the firewall itself, the tool offers WAF. Customers who hear that WAF is integrated into the firewall get interested in the solution. WAF is actually another solution. Instead of purchasing a WAF product, you get it inside Sangfor NGAF. Stability-wise, I rate the solution a nine out of ten.
What do I think about the scalability of the solution?
It is a scalable solution. Scalability-wise, I rate the solution an eight out of ten.
In our company, we deal with a wide range of things. The scalability depends on what range the customer chooses. I can't pinpoint or explain the tool's scalability aspect in detail. Different types of firewall models are available.
Under five customers of my company use the tool, and they are all enterprise businesses.
How are customer service and support?
I rate the technical support a seven out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
If one is difficult and ten is easy to set up, I rate the product's initial setup phase an eight out of ten. I never deployed the tool. I am sharing my engineering experience.
I am not quite sure about the deployment situation.
The solution is deployed on the cloud.
What's my experience with pricing, setup cost, and licensing?
If one is very cheap and ten is very expensive, I rate the tool's price as three out of ten. I am not quite sure about the tool's pricing point.
What other advice do I have?
Sangfor NGAF has not shared how it has impacted our customer security operations with my company's sales team. If they do share such information, it is usually with the sales team while I am on the presales team. I am only a consultant, so the product doesn't share such details directly with me.
The tool helped our customers with threat mitigation strategies because it has AI functionalities that are helpful.
Suppose an enterprise customer wants a firewall as the first thing inside the company because of its cost-effectiveness. In that case, I think Sangfor NGAF can be a good option as it comes with the features and abilities of the firewall. I think it is quite a great option for enterprise users.
I rate the tool an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. consultant
Buyer's Guide
Sangfor NGAF
August 2026
Learn what your peers think about Sangfor NGAF. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,806 professionals have used our research since 2012.
System Network Administrator at Connect Logistics
Affordable and offers powerful application control but could use refinement in its application control policies
Pros and Cons
- "Sangfor NGAF's standout feature is its powerful application control, enabling precise restrictions on mobile user access to approved applications."
- "Sangfor NGAF could improve by refining its application control policies, especially in addressing challenges with certain types of applications."
What is most valuable?
Sangfor NGAF's standout feature is its powerful application control, enabling precise restrictions on mobile user access to approved applications. The system's adept intrusion detection further fortifies our network, preventing potential threats.
What needs improvement?
Sangfor NGAF could improve by refining its application control policies, especially in addressing challenges with certain types of applications.
For how long have I used the solution?
I have been using Sangfor NGAF for ten months.
What do I think about the stability of the solution?
So far, we have not had any issues with the stability of the solution.
What do I think about the scalability of the solution?
We have approximately 250 users of Sangfor NGAF at our company, but around 400 users all around.
How are customer service and support?
The support team is excellent. Very helpful and competent.
Which solution did I use previously and why did I switch?
My company opted for Sangfor NGAF over other products because of its affordability, compact size, and easy management features. I like Sangfor more than Fortinet because it is cheaper, has a friendlier interface, and comes with great support. It just feels like a better fit for me.
How was the initial setup?
The initial setup is very easy.
What's my experience with pricing, setup cost, and licensing?
Sangfor NGAF is quite affordable.
Which other solutions did I evaluate?
What other advice do I have?
Although Sangfor NGAF is a great product, I would rate it as a six out of ten just because I'm new in this field and still exploring other options and solutions.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Networking Solutions Specialist at GBM
An affordable solution that is reliable and provides a quick response
Pros and Cons
- "The product is very fast and reliable."
- "The solution should be able to work in a hybrid setup."
What is our primary use case?
We use the solution to connect and protect all the internal servers. All publicly accessible websites and servers are connected to the solution.
What is most valuable?
The product is very fast and reliable. It has a quick response.
What needs improvement?
The solution should be able to work in a hybrid setup.
For how long have I used the solution?
I have been using the solution for one and a half years.
What do I think about the scalability of the solution?
Around 150 users are using the solution in my organization. Both internal and external traffic goes through the firewall because the firewall is placed on the main data center.
How are customer service and support?
If we have any issues, we read the documentation. If the issue cannot be fixed, we can contact the support team. I have not contacted the support team yet. I configure things by myself.
Which solution did I use previously and why did I switch?
We were using Cisco’s firewall before. It ended support. We cannot use the products that have ended support. Cisco and Sangfor work similarly, but their GUIs are different.
How was the initial setup?
The initial setup is very easy.
What's my experience with pricing, setup cost, and licensing?
It is one of the cheapest tools in the market. The choice depends on the customer’s budget.
What other advice do I have?
Overall, I rate the product a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Infrastructure Department Head at a manufacturing company with 11-50 employees
Robust security features with scalability challenges
Pros and Cons
- "It enables us to not only detect but also prevent various types of incoming threats, allowing us to take appropriate corrective actions and exercise control over the network."
- "It does not offer any recommendations on how to mitigate or control attacks."
What is our primary use case?
The system comprises three primary functionalities: defense solutions, detection solutions, and the ability to identify, block, and analyze network traffic. It enables us to not only detect but also prevent various types of incoming threats, allowing us to take appropriate corrective actions and exercise control over the network.
How has it helped my organization?
We have observed numerous threats targeting our network from both internal and external sources. While we have reports detailing these incidents, we currently lack a clear method for prioritizing internal threats.
What is most valuable?
The information provided alerts us to the presence of threats from specific sources, which is highly beneficial.
What needs improvement?
It does not offer any recommendations on how to mitigate or control attacks.
For how long have I used the solution?
I have been using it for three years.
What do I think about the stability of the solution?
We face occasional stability issues. I would rate it seven out of ten.
What do I think about the scalability of the solution?
It doesn't offer significant scalability features.
How are customer service and support?
In the event of a performance issue, such as users reporting slow access to specific websites, we conduct an internal investigation to identify the root cause. If it's determined to be a problem with the equipment, we escalate the issue to the vendor for resolution.
How would you rate customer service and support?
Neutral
What about the implementation team?
When we installed the equipment, we depended on an external consulting party to guide us through the setup and functionality for approximately two weeks. The project team, consisting of both project members and experts in the field, were actively engaged during this period.
What's my experience with pricing, setup cost, and licensing?
The pricing is reasonable. At the time of our decision to acquire the equipment, we were working with a constrained budget and it turned out to be the most suitable choice to meet our specific requirements
Which other solutions did I evaluate?
We considered FortiGate as an option but ultimately decided on Sangfor NGAF due to its more favorable pricing.
What other advice do I have?
I hope that its distributor possesses a high level of product knowledge, and the same applies to Sangfor itself as the principal company. This would enable customers to have a more seamless and enriching experience with the product, eliminating any barriers or disconnect between our team, the customers, and the software. Overall, I would rate it seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Administrator at AI Processings
Good network security capabilities but lacks in logging capabilites
Pros and Cons
- "The stability of Sangfor NGAF is good."
- "An area of improvement for Sangfor NGAF could be in the field of reporting and logging."
What is our primary use case?
We are using Sangfor NGAF for the prevention of attacks in our network through the use of IPS, IDS, and web filtering features.
How has it helped my organization?
There are currently over 1000 active nodes of the solution in use, and we do not have any plans to increase usage at this time.
What is most valuable?
Our primary need is to prevent our users from misusing the Internet, which we achieve through implementing traffic shifting and bandwidth restrictions, among other features offered by Sangfor NGAF
What needs improvement?
An area of improvement for Sangfor NGAF could be in the field of reporting and logging.
For how long have I used the solution?
I have been using the Sangfor NGAF solution for three years now.
What do I think about the stability of the solution?
The stability of Sangfor NGAF is good, and I would rate it a seven out of ten. In fact, compared to its competitors, Sangfor is much better so far.
How are customer service and support?
We get good support from customer service.
How was the initial setup?
The initial setup is easy and it is user-friendly.
What's my experience with pricing, setup cost, and licensing?
We have an annual subscription, which is not expensive. In fact, compared to Fortinet, Sangfor is much more cost-effective.
Which other solutions did I evaluate?
Although we have used different solutions such as Proofpoint, Gadget Control, and FortiNet, we find Sangfor NGAF to be much better due to its security inclusion prevention feature, which is why we introduced this product.
What other advice do I have?
Overall, I would rate the solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Great for inspecting traffic on a very granular level but the GUI lacks logic in some areas
Pros and Cons
- "Particularly good in the DPI where we can inspect inbound and outbound traffic."
- "Sangfor serves most of the basic purposes of a firewall, is particularly good in the DPI where we can inspect the inbound and outbound traffic on a very granular level, gives a very good predictive measure as well as the current measure of things going on in our network, and gives us value for money overall."
- "The GUI needs to be improved, lacks logic in some areas."
- "I think the GUI needs to be improved, there are a lot of areas where the panes do not make sense."
What is our primary use case?
This solution is our firewall. I'm a network administrator.
What is most valuable?
Sangfor serves most of the basic purposes of a firewall. It's particularly good in the DPI where we can inspect the inbound and outbound traffic on a very granular level. It gives a very good predictive measure as well as the current measure of things going on in our network. When it comes to the VPNs, it has a very good throughput when remote users connect, particularly when it comes to site-to-site VPNs, where it provides a good analysis module. You can analyze inbound traffic and different policies on this. It gives us value for money overall.
What needs improvement?
I think the GUI needs to be improved, there are a lot of areas where the panes do not make sense. They have put the NAT in the policy section but at the same time the DPI is in the network pane. The placement of different options in the menu system of this firewall is not that logical and often doesn't make a lot of sense. The operational procedures are a little tricky and require some technical skills. A level one person will have problems. The compatibility needs to be improved.
For how long have I used the solution?
I've been using this solution for three years.
What do I think about the stability of the solution?
We have been experiencing power failures but the solution has been very stable, both from the hardware and the software perspective. We have built a lot of VPN solutions for the firewalls including Cisco, Firewall 2, and pfSense, and it has been very good with that.
What do I think about the scalability of the solution?
We don't require a very highly scalable coefficient but I believe it's scalable.
How are customer service and support?
The technical support is very good. They have a local vendor they have hired for the technical support and if anything cannot be resolved remotely, they come to us. They are very agile and very technically supportive.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup was a little complex because we were previously dealing with command line scenarios and we were not very comfortable with the GUI which is a little complex.
What's my experience with pricing, setup cost, and licensing?
Our licensing costs are around $15,000 per year which is nominal compared to other solutions.
What other advice do I have?
Whether or not this solution is good for you depends on your network. If you have sufficient technical support, then you can go for an open-source solution. Without that and if you have the funds, then this is a good solution. If not, then most of what firewalls do these days can be handled by an open-source solution.
This is a new solution in our country where the price tag really matters. They have targeted the public sector and I'm seeing more and more people moving towards Sangfor because it's cheaper than other products, and the support is quite good.
I rate the solution seven out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Sales Engineer at Comstar - Information Systems Associates Ltd.
Provides dashboards that are easy and user-friendly for users to use
Pros and Cons
- "The tool's performance is good."
- "I feel Sangfor should follow the hierarchy and close deals via resellers instead of closing it all with their own team."
What is our primary use case?
We have a huge market in Pakistan consisting of Sangfor clients. Sangfor itself is based in Pakistan. The tool's OEM team is also in Pakistan, and they are managing the tool quite well.
What is most valuable?
The solution's most valuable features are that it is scalable, super secure, and has a few features that secure client networks.
What needs improvement?
Sangfor’s team directly deals with clients. I feel Sangfor should follow the hierarchy and close deals via resellers instead of closing it all with their own team.
For how long have I used the solution?
I have experience working with Sangfor NGAF.
What do I think about the stability of the solution?
It is a stable solution. Stability-wise, I rate the solution a nine out of ten.
How are customer service and support?
The solution's technical support is super great. The tool's team is in Pakistan, and they have it all set up and available for users. The tool's after-sales support team is available.
How was the initial setup?
The product's initial setup phase is easy to handle. The tool has its own dashboards, which we can access to pitch clients and demonstrate the whole solution in a few steps, making it quite easy and user-friendly for users.
What's my experience with pricing, setup cost, and licensing?
In my opinion, the price of the tool is good in the Pakistani market. We can easily get discounts if needed. The tool's prices are not firm or strict.
What other advice do I have?
The solution improves network performance as it is a security product.
HCI solutions are used in the Pakistani market, and it is a virtualization solution. We are presenting two solutions for the Pakistani market. One is a security tool like a firewall, and the second is HCI, a storage solution for virtualization. My company sells Sangfor tools to more than 100 clients.
The tool's performance is good.
The tool's application control feature is a built-in option.
The tool's intrusion prevention system is a feature that can be described as a built-in functionality.
I recommend the tool to others because it is a good, economical, scalable, user-friendly, and super secure product.
The tool's updates are fine.
I rate the tool a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Solution Architect at Megaplus
Effective security for small and medium businesses with challenges related to scalability and integration
Pros and Cons
- "The built-in features function as intended, providing exceptional value."
- "Our experience with its customer support was quite challenging."
What is our primary use case?
Sangfor NGAF offers built-in Web Application Firewall capabilities, making it a valuable choice for securing WAF servers. We have implemented this feature in numerous deployments, particularly in the fields of financial management and enterprise environments.
What is most valuable?
We have established an SD-WAN infrastructure with Sangfor NGAF, which has proven to be highly beneficial. The built-in features function as intended, providing exceptional value.
What needs improvement?
It is a relatively new product in the market, so we are dealing with challenges related to security and malware detection. It will need time to assess its strengths and weaknesses thoroughly. We discovered that the SD-WAN capability is available within this product. It also includes built-in Value-Added Security Technology, which can be cost-effective, but improvements are needed, particularly in enhancing malware detection. Another area for improvement is integrating with other third-party providers' solutions for a more seamless security ecosystem.
For how long have I used the solution?
We have been working with it for two and a half years.
What do I think about the stability of the solution?
In terms of stability, there have been occasional issues, such as glitches and disruptions, leading to periods of downtime. Improvement in this area is necessary. I would rate it five out of ten.
What do I think about the scalability of the solution?
Scalability is a key aspect, and we haven't thoroughly tested its compatibility with various other products yet. I would rate it five out of ten.
How are customer service and support?
Our experience with its customer support was quite challenging. There's room for improvement in this aspect.
How was the initial setup?
The initial setup is remarkably straightforward and user-friendly.
What's my experience with pricing, setup cost, and licensing?
The price falls in the mid-range, neither exceptionally low nor high. I would rate it seven out of ten.
What other advice do I have?
Deploying Sangfor NGAF proves highly advantageous for small and medium-sized businesses. Overall, I would rate it seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Computer Programmer III at Leyte Normal University
Real-time reports are great but the filtering could be improved
Pros and Cons
- "We can utilize our own network rather than paying for a private one."
- "Lacks consistency in terms of filtering certain websites and applications."
What is our primary use case?
Sangfor NGAF is our gateway to the ISP. We also use it to filter the website that our employees deploy to the firewall and to access to our systems through the web.
How has it helped my organization?
Sangfor reports on any intrusions in real-time so you can immediately whitelist or blacklist these reported intrusions. It makes our work easier because we previously only used MikroTIK which required significant manual effort.
What is most valuable?
I really like the SSL VPN. Instead of paying for a virtual private network, we can utilize our own Internet service provider, and use our Internet connection to run access.
What needs improvement?
For some reason, Sangfor doesn't filter certain websites and applications. It should recognize them and utilize the bandwidth between applications. Also, if we try to block YouTube or Facebook videos, some users will use applications like Siphon for viewing so our bandwidth is still being utilized for non-work purposes. It might detect that somebody is using Siphon, but it cannot be blocked. It's inconsistent, sometimes one user can be blocked while another will have access.
For how long have I used the solution?
I've been using this solution for four years.
What do I think about the stability of the solution?
The solution is stable and it really protects our systems and the data within our company.
What do I think about the scalability of the solution?
What we are using now doesn't have the SFP+, only the gigabit ethernet ports. We need to purchase a different model to accommodate the one with SFP+ because what we have now doesn't accommodate additional expansion slots for SFP+. We probably have 100 users who communicate with our head office from outside our region.
How are customer service and support?
We don't encounter a lot of problems but if we do, there is access to 24/7 support, whether it's chat or email support. If there's an issue we make contact.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We did not used any network security solutions before
How was the initial setup?
The initial setup was very straightforward and deployment took less than a day. We had one in-house person responsible for deployment and we started using the solution immediately.
What about the implementation team?
I rate the implementation a nine out of ten.
What's my experience with pricing, setup cost, and licensing?
The setup is a breeze and the pricing is definitely low when compared to the competition.
Which other solutions did I evaluate?
I looked into Sophos XG.
What other advice do I have?
I rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Sangfor NGAF Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2026
Product Categories
FirewallsPopular Comparisons
Fortinet FortiGate
Cisco Secure Firewall
Netgate pfSense
OPNsense
Sophos Firewall
Check Point Cloud Firewall (formerly CloudGuard Network Security)
Palo Alto Networks NG Firewalls
WatchGuard Firebox
Cisco Meraki MX
Check Point Quantum Force (NGFW)
Azure Firewall
Palo Alto Networks VM-Series
Cisco Secure Access
Fortinet FortiGate-VM
Juniper SRX Series Firewall
Buyer's Guide
Download our free Sangfor NGAF Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What do you recommend for a corporate firewall implementation?
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Which is the best network firewall for a small retailer?
- When evaluating Firewalls, what aspect do you think is the most important to look for?
- Cyberoam or Fortinet?
- Fortinet, Palo Alto or Check Point?
- If you could go back, would you change your decision to buy that firewall and why?
- Sophos XG vs Fortigate UTM
- Can you recommend a solution to replace Cyberoam 200ing Firewall?

















