The system comprises three primary functionalities: defense solutions, detection solutions, and the ability to identify, block, and analyze network traffic. It enables us to not only detect but also prevent various types of incoming threats, allowing us to take appropriate corrective actions and exercise control over the network.
Infrastructure Department Head at a manufacturing company with 11-50 employees
Robust security features with scalability challenges
Pros and Cons
- "It enables us to not only detect but also prevent various types of incoming threats, allowing us to take appropriate corrective actions and exercise control over the network."
- "It does not offer any recommendations on how to mitigate or control attacks."
What is our primary use case?
How has it helped my organization?
We have observed numerous threats targeting our network from both internal and external sources. While we have reports detailing these incidents, we currently lack a clear method for prioritizing internal threats.
What is most valuable?
The information provided alerts us to the presence of threats from specific sources, which is highly beneficial.
What needs improvement?
It does not offer any recommendations on how to mitigate or control attacks.
Buyer's Guide
Sangfor NGAF
September 2025

Learn what your peers think about Sangfor NGAF. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,787 professionals have used our research since 2012.
For how long have I used the solution?
I have been using it for three years.
What do I think about the stability of the solution?
We face occasional stability issues. I would rate it seven out of ten.
What do I think about the scalability of the solution?
It doesn't offer significant scalability features.
How are customer service and support?
In the event of a performance issue, such as users reporting slow access to specific websites, we conduct an internal investigation to identify the root cause. If it's determined to be a problem with the equipment, we escalate the issue to the vendor for resolution.
How would you rate customer service and support?
Neutral
What about the implementation team?
When we installed the equipment, we depended on an external consulting party to guide us through the setup and functionality for approximately two weeks. The project team, consisting of both project members and experts in the field, were actively engaged during this period.
What's my experience with pricing, setup cost, and licensing?
The pricing is reasonable. At the time of our decision to acquire the equipment, we were working with a constrained budget and it turned out to be the most suitable choice to meet our specific requirements
Which other solutions did I evaluate?
We considered FortiGate as an option but ultimately decided on Sangfor NGAF due to its more favorable pricing.
What other advice do I have?
I hope that its distributor possesses a high level of product knowledge, and the same applies to Sangfor itself as the principal company. This would enable customers to have a more seamless and enriching experience with the product, eliminating any barriers or disconnect between our team, the customers, and the software. Overall, I would rate it seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Great for inspecting traffic on a very granular level but the GUI lacks logic in some areas
Pros and Cons
- "Particularly good in the DPI where we can inspect inbound and outbound traffic."
- "The GUI needs to be improved, lacks logic in some areas."
What is our primary use case?
This solution is our firewall. I'm a network administrator.
What is most valuable?
Sangfor serves most of the basic purposes of a firewall. It's particularly good in the DPI where we can inspect the inbound and outbound traffic on a very granular level. It gives a very good predictive measure as well as the current measure of things going on in our network. When it comes to the VPNs, it has a very good throughput when remote users connect, particularly when it comes to site-to-site VPNs, where it provides a good analysis module. You can analyze inbound traffic and different policies on this. It gives us value for money overall.
What needs improvement?
I think the GUI needs to be improved, there are a lot of areas where the panes do not make sense. They have put the NAT in the policy section but at the same time the DPI is in the network pane. The placement of different options in the menu system of this firewall is not that logical and often doesn't make a lot of sense. The operational procedures are a little tricky and require some technical skills. A level one person will have problems. The compatibility needs to be improved.
For how long have I used the solution?
I've been using this solution for three years.
What do I think about the stability of the solution?
We have been experiencing power failures but the solution has been very stable, both from the hardware and the software perspective. We have built a lot of VPN solutions for the firewalls including Cisco, Firewall 2, and pfSense, and it has been very good with that.
What do I think about the scalability of the solution?
We don't require a very highly scalable coefficient but I believe it's scalable.
How are customer service and support?
The technical support is very good. They have a local vendor they have hired for the technical support and if anything cannot be resolved remotely, they come to us. They are very agile and very technically supportive.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup was a little complex because we were previously dealing with command line scenarios and we were not very comfortable with the GUI which is a little complex.
What's my experience with pricing, setup cost, and licensing?
Our licensing costs are around $15,000 per year which is nominal compared to other solutions.
What other advice do I have?
Whether or not this solution is good for you depends on your network. If you have sufficient technical support, then you can go for an open-source solution. Without that and if you have the funds, then this is a good solution. If not, then most of what firewalls do these days can be handled by an open-source solution.
This is a new solution in our country where the price tag really matters. They have targeted the public sector and I'm seeing more and more people moving towards Sangfor because it's cheaper than other products, and the support is quite good.
I rate the solution seven out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Sangfor NGAF
September 2025

Learn what your peers think about Sangfor NGAF. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,787 professionals have used our research since 2012.
A scalable and comprehensive solution that specializes in ransomware detection
Pros and Cons
- "Sangfor NGAF specializes in ransomware detection and helps to protect our network from ransomware threats and malware."
- "The firewall system needs gradual improvements because there are more threats and challenges every day."
What is our primary use case?
Sangfor NGAF specializes in ransomware detection and helps to protect our network from ransomware threats and malware. This is the primary reason we purchased this solution, and we are currently negotiating to upgrade our appliances to volume M5200 Series. Additionally, Sangfor NGAF provides a web application for financial software.
How has it helped my organization?
We use Sangfor NGAF primarily for security, which has helped save our files from being encrypted by ransomware. Our desktop PCs have essential data, like word files and excel documents.
We previously had a ransomware attack on our file server, and Sangfor NGAF protected us by alerting and disconnecting the server from the network.
What needs improvement?
The firewall system needs gradual improvements because there are more threats and challenges in the world every day. Sangfor NGAF has a comprehensive database for ransomware and viruses, but when we compare it to other solutions, the price could be more competitive.
Since we have a very comprehensive solution with Sangfor NGAF, it is hard to identify any additional features we want to add. It already provides good features for ransomware attacks and data recovery. In the past, we wanted encrypted data for a virus to be recoverable, and Sangfor offered the solution.
For how long have I used the solution?
We have been using Sangfor NGAF for four years. We use it for overall IT infrastructure protection and are currently using version 1 of Model M5100.
We currently deploy a hybrid infrastructure of cloud and on-premises. We use the solution for our accounting and financial software, websites, internet blocking, and other features. Some clients are on the cloud, and others are on-premises. We also have a Sangfor solution that filters the in and out traffic.
What do I think about the stability of the solution?
The solution is relatively stable. Interestingly, we discontinued the updates and software licenses about a year ago, and the appliance and solutions are still working. In addition, there is no limitation on the license, so services won't stop if it expires. You can also update the license at any time for a partial cost.
What do I think about the scalability of the solution?
This solution is scalable. We can add many features and lengths and expand according to our needs.
The IT specialists and engineers in my organization use this solution. Our whole organization is under the protection of Sangfor NGAF. The solution has footprints in India and Europe and many government agencies use Sangfor NGAF in Pakistan.
For deployment, we needed three people who were all IT specialists, and only one of them was from Sangfor. As a result, we deployed it with very few resources, and there were no recurring charges. Also, most people are very well-versed in technology and can multitask.
How are customer service and support?
The technical support team was very helpful, provided support, and guided us during our initial deployment. We were good to go in 15 to 20 minutes.
Which solution did I use previously and why did I switch?
We previously used Sophos and pfSense, an open-source firewall.
How was the initial setup?
The initial setup was very straightforward. The solution is out of the box, and the software and appliance can be quickly installed. It has a very nice AI feature, and we only needed to implement parameters and define some policies. The deployment took 15 to 20 minutes because we had to get familiar with the new system.
We defined WAN and LAN networks for our implementation strategy and then defined the servers. Next, we identified the modes and decided the desktop would be the best. There were other considerations but it has been four years, so it is hard to remember all of them.
What about the implementation team?
We completed our deployment in-house.
What was our ROI?
We have seen a return on investment. The systems are protected, and their operating systems are readily available. We are protected from ransomware attacks and the loss of data. This solution protects us, and it has benefits.
What's my experience with pricing, setup cost, and licensing?
On a scale of one to ten, with one being the cheapest, I rate the price a six out of ten. There are no hidden or additional costs other than what we were provided. Therefore, we are happy with our initial decisions.
Which other solutions did I evaluate?
We evaluated other options and completed some financial comparisons but the IT specialists advised that Sangfor NGAF worked well.
What other advice do I have?
I rate this product an eight out of ten because we don't know what we may need from this solution in the future. We are satisfied and hope to upgrade to a new version soon. However, right now, our current version is working fine.
In terms of advice, we would recommend Sangfor NGAF. But, a company should first prepare an analysis, compare different products, and then decide what they want.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Teamlead IT Core at SoloInsight Inc.
Next generation firewall that is scalable and one of the best on the market
Pros and Cons
- "Sangfor is a good solution that provides a WAF and firewall solution. Most other vendors, like Sophos and Fortinet and Cisco, only provide one solution. That's a valuable feature of Sangfor."
- "Sangfor could improve their interface capacity on the 5100 series model and upgrade their hardware from one gig to 10 gig. This would improve the overall throughput."
What is our primary use case?
Sangfor is an on-prem firewall I use for my local infrastructure. It is used as an aggregated interface. Behind Sangfor, I have built a data center that is deployed on high availability using a model that is 5100 CV with 10 gig ports.
What is most valuable?
Sangfor is a good solution that provides a WAF and firewall solution. Most other vendors, like Sophos and Fortinet and Cisco, only provide one solution. That's a valuable feature of Sangfor.
What needs improvement?
Sangfor could improve their interface capacity on the 5100 series model and upgrade their hardware from one gig to 10 gig. This would improve the overall throughput.
For how long have I used the solution?
I have used this solution for the last six months.
What do I think about the scalability of the solution?
This is a scalable solution. We have approximately 1,000 users.
How are customer service and support?
The technical support team are available 24/7 and if we need any assistance for Sangfor, FortiGate or Sophos, we can call their support number and they provide assistance from their L2 or L3 engineers.
How would you rate customer service and support?
Positive
How was the initial setup?
It's very easy to set up because Sangfor provided us with export and HCI capabilities. Deployment took almost one week.
The process starts with low level design for internal teams to make a design on network requirements. This contains all current and future requirements.
What's my experience with pricing, setup cost, and licensing?
For four to five physical appliances for a licensed firewall, it costs approximately $4,000.
What other advice do I have?
We have six people managing IT operations. We have not had any issues in the first six months of using this solution.
If you want to deploy a firewall in your infrastructure, Fortinet, Sangfor and Sophos are the best solutions to protect traffic.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Solution Architect at Megaplus
Effective security for small and medium businesses with challenges related to scalability and integration
Pros and Cons
- "The built-in features function as intended, providing exceptional value."
- "Our experience with its customer support was quite challenging."
What is our primary use case?
Sangfor NGAF offers built-in Web Application Firewall capabilities, making it a valuable choice for securing WAF servers. We have implemented this feature in numerous deployments, particularly in the fields of financial management and enterprise environments.
What is most valuable?
We have established an SD-WAN infrastructure with Sangfor NGAF, which has proven to be highly beneficial. The built-in features function as intended, providing exceptional value.
What needs improvement?
It is a relatively new product in the market, so we are dealing with challenges related to security and malware detection. It will need time to assess its strengths and weaknesses thoroughly. We discovered that the SD-WAN capability is available within this product. It also includes built-in Value-Added Security Technology, which can be cost-effective, but improvements are needed, particularly in enhancing malware detection. Another area for improvement is integrating with other third-party providers' solutions for a more seamless security ecosystem.
For how long have I used the solution?
We have been working with it for two and a half years.
What do I think about the stability of the solution?
In terms of stability, there have been occasional issues, such as glitches and disruptions, leading to periods of downtime. Improvement in this area is necessary. I would rate it five out of ten.
What do I think about the scalability of the solution?
Scalability is a key aspect, and we haven't thoroughly tested its compatibility with various other products yet. I would rate it five out of ten.
How are customer service and support?
Our experience with its customer support was quite challenging. There's room for improvement in this aspect.
How was the initial setup?
The initial setup is remarkably straightforward and user-friendly.
What's my experience with pricing, setup cost, and licensing?
The price falls in the mid-range, neither exceptionally low nor high. I would rate it seven out of ten.
What other advice do I have?
Deploying Sangfor NGAF proves highly advantageous for small and medium-sized businesses. Overall, I would rate it seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Computer Programmer III at Leyte Normal University
Real-time reports are great but the filtering could be improved
Pros and Cons
- "We can utilize our own network rather than paying for a private one."
- "Lacks consistency in terms of filtering certain websites and applications."
What is our primary use case?
Sangfor NGAF is our gateway to the ISP. We also use it to filter the website that our employees deploy to the firewall and to access to our systems through the web.
How has it helped my organization?
Sangfor reports on any intrusions in real-time so you can immediately whitelist or blacklist these reported intrusions. It makes our work easier because we previously only used MikroTIK which required significant manual effort.
What is most valuable?
I really like the SSL VPN. Instead of paying for a virtual private network, we can utilize our own Internet service provider, and use our Internet connection to run access.
What needs improvement?
For some reason, Sangfor doesn't filter certain websites and applications. It should recognize them and utilize the bandwidth between applications. Also, if we try to block YouTube or Facebook videos, some users will use applications like Siphon for viewing so our bandwidth is still being utilized for non-work purposes. It might detect that somebody is using Siphon, but it cannot be blocked. It's inconsistent, sometimes one user can be blocked while another will have access.
For how long have I used the solution?
I've been using this solution for four years.
What do I think about the stability of the solution?
The solution is stable and it really protects our systems and the data within our company.
What do I think about the scalability of the solution?
What we are using now doesn't have the SFP+, only the gigabit ethernet ports. We need to purchase a different model to accommodate the one with SFP+ because what we have now doesn't accommodate additional expansion slots for SFP+. We probably have 100 users who communicate with our head office from outside our region.
How are customer service and support?
We don't encounter a lot of problems but if we do, there is access to 24/7 support, whether it's chat or email support. If there's an issue we make contact.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We did not used any network security solutions before
How was the initial setup?
The initial setup was very straightforward and deployment took less than a day. We had one in-house person responsible for deployment and we started using the solution immediately.
What about the implementation team?
I rate the implementation a nine out of ten.
What's my experience with pricing, setup cost, and licensing?
The setup is a breeze and the pricing is definitely low when compared to the competition.
Which other solutions did I evaluate?
I looked into Sophos XG.
What other advice do I have?
I rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Administrator at Shaheed Zulfiqar Ali Bhutto Institute of Science and Technology
Integrates well, reliable, and different pricing models available
Pros and Cons
- "The most valuable feature of Sangfor NGAF is its integration."
- "Sangfor NGAF could improve the policies and default criteria. They could be much better."
What is our primary use case?
What is most valuable?
The most valuable feature of Sangfor NGAF is its integration.
What needs improvement?
Sangfor NGAF could improve the policies and default criteria. They could be much better.
For how long have I used the solution?
I have been using Sangfor NGAF for approximately three years.
What do I think about the stability of the solution?
Sangfor NGAF is stable.
What do I think about the scalability of the solution?
The scalability of Sangfor NGAF is good.
We are using the Sangfor NGAF as our firewall, we have approximately 6,000 to 8,000 end users who are passing through. We have approximately 10 to 15 people using the Sangfor SSL VPN feature remotely from home.
How are customer service and support?
The support from Sangfor NGAF here in Pakistan is great. Whenever I have an issue the support helps me out efficiently.
I rate the support from Sangfor NGAF a five out of five.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup of Sangfor NGAF is straightforward. Sophos and Fortinet have more difficult initial setups.
I rate the initial setup of Sangfor NGAF a five out of five.
What's my experience with pricing, setup cost, and licensing?
The license of Sangfor NGAF can be purchased at different interval lengths, such as annually or three years. They offer a range of packages to choose from, such as combo or hybrid packages. We are using the complete solution package which includes IM, NGF and SSL VPN, and WAF.
We have purchased the support for three years.
What other advice do I have?
My advice to others is they should try the solution. I have experienced other solutions, such as Fortinet and I feel much better using this solution overall.
I rate Sangfor NGAF a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Project Manager at Novu
Provides VPN tunneling and security at competitive pricing
Pros and Cons
- "Sangfor's tech features and technologies are more powerful than those of the other solution providers in terms of security. They also have big solutions in terms of cybersecurity."
- "It has an issue with the Sangfor Cloud Platform rather than the firewall. When we run a virtual machine, the window tabs display Chinese characters."
What is our primary use case?
We're using it more for VPN tunneling and security. We're integrating it with the SoundCloud platform to use it in our data center.
How has it helped my organization?
We're happily using the IP vSEC VPN. We will use some credentials to connect it to two different sites.
What is most valuable?
Sangfor's tech features and technologies are more powerful than those of the other solution providers in terms of security. They also have big solutions in terms of cybersecurity.
What needs improvement?
It has an issue with the Sangfor Cloud Platform rather than the firewall. When we run a virtual machine, the window tabs display Chinese characters. This could be a hindrance when presenting it to clients, especially since many of our clients prefer US-based products. We’re pitching Sangfor as part of our solutions, but the presence of Chinese characters might be a concern.
For how long have I used the solution?
I have been using Sangfor NGAF as a partner for two to three years.
What do I think about the stability of the solution?
We've encountered various glitches or bugs with the firewall, particularly when trying to configure redundancy. We're facing challenges with setting up two ISPs on a single, stacked firewall.
What do I think about the scalability of the solution?
We haven't encountered any issues scaling with Sangfor. It follows a more traditional approach to scaling, though we don’t yet fully understand all the scaling capabilities of Sangfor products. However, it does have the basic features needed for scaling.
How are customer service and support?
We have some contacts here locally. We do contact them for support.
How was the initial setup?
Sang four independently is easy to configure. It's very straightforward. However, we're having challenges with the interoperability matrix and other integration for other firewall brands.
The standard configuration, with basic policies, can take a couple of hours to set up.
One guy in our company can do the configuration.
What was our ROI?
We achieved a lot of ROI since the competitive pricing is much better than the other brands.
What's my experience with pricing, setup cost, and licensing?
Price is very competitive with other brands.
What other advice do I have?
We encounter different glitches or bugs in the firewall. More likely, we're having a problem with two ISPs being cited in our firewall to have redundancy. We don't know the primary or best practice of configuring two ISPs in a single firewall.
Overall, I rate the solution an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner

Buyer's Guide
Download our free Sangfor NGAF Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2025
Product Categories
FirewallsPopular Comparisons
Fortinet FortiGate
Netgate pfSense
OPNsense
Sophos XG
Cisco Secure Firewall
Palo Alto Networks NG Firewalls
WatchGuard Firebox
Cisco Meraki MX
Check Point Quantum Force (NGFW)
SonicWall TZ
Sophos XGS
Fortinet FortiGate-VM
Juniper SRX Series Firewall
SonicWall NSa
Fortinet FortiOS
Buyer's Guide
Download our free Sangfor NGAF Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What do you recommend for a corporate firewall implementation?
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Which is the best network firewall for a small retailer?
- When evaluating Firewalls, what aspect do you think is the most important to look for?
- Cyberoam or Fortinet?
- Fortinet, Palo Alto or Check Point?
- If you could go back, would you change your decision to buy that firewall and why?
- Sophos XG vs Fortigate UTM
- Can you recommend a solution to replace Cyberoam 200ing Firewall?