We performed a comparison between Huawei NGFW and Zscaler Internet Access based on real PeerSpot user reviews.
Find out what your peers are saying about Netgate, Fortinet, OPNsense and others in Firewalls."The most valuable feature of this solution is Quota."
"The inspection and web security features are most valuable."
"The solution is extremely reliable."
"Fortigate represents a really scalable way of delivering perimeter network security, some level of layer 7 security, WAF, and also a way to create a meshed ADVPN solution."
"Fortinet FortiGate is stable. It's used across all the countries, this is the way most multinationals run their system."
"It increases security posture and is helpful for firewall reporting, intrusion protection, web filtering, and SD-WAN implementation."
"The pricing is great and very reasonable."
"Fortigate is very scalable to serve our customers' needs. We have scaled already from fifty to more than a hundred instances of Fortinet FortiGate. Around 20 staff are required for deployment and maintenance, mostly engineers."
"The solution's initial setup process is easy."
"We have found the initial setup to be straightforward."
"I had no difficulty using the Huawei NGFW."
"I like that the initial setup is straighforward. It's also a scalable solution."
"The mapping features and traffic logging are good."
"The support for the solution has been excellent. If we ever had an issue they would send an engineer to help us with our problem."
"The security is good. It's as effective as anything else on the market."
"We make use of the new data center, specifically the containerized data center which is built and reviewed by Huawei, including all the device's infrastructure."
"The policies are very intuitive and easy to configure, with very little possibility of messing things up."
"For our needs, the cloud-native proxy architecture is a very good solution. We are moving away from on-prem appliances and moving more toward cloud-based solutions. Zscaler is a good fit for our strategy. This architecture helps with cyber threats because we inspect most of the traffic and we can see that a lot of threats are stopped directly in the secure web gateway."
"I like the granularity of the control of all the traffic, including SSL inspection. I also like the fact that the user interface is intuitive. The latencies with Zscaler are minimal compared to those of any other competitor. Other competitors do not really have the global scale that Zscaler has and cannot promise low latencies."
"The protection is most valuable."
"The most valuable feature is the ability to drop packets."
"All internet access flows through the Zscaler proxy, regardless of whether people are in office or remote. I have greater control site access and I minimize the number of compromises that we experience to almost none."
"The cloud proxy and integration are some of the key features. Since there is cloud waste, we can quickly provision it and start working on the configuration. On top of that, they have added a few more features. They have integrated CASB, and file sandboxing is part of it."
"We don't have to buy equipment to use it. And when our engineers set it up on our side, we just configured a few settings and we were in."
"Fortinet FortiGate could improve by adding FortiAnalyzer to its solution, we should not have to use another solution. FortiAnalyzer can provide more detailed information."
"The feature which gives us a lot of pain is ASIC architecture."
"It would be nice if backups could more easily migrate between different models."
"If they had better integration with security products, such as Cisco ISE or Rapid Threat Containment, then it would be an improvement."
"If I had any criticism that I would give FortiGate, it would be that they need to stop changing their logging format. Every time we do a firmware upgrade, it is a massive issue on the SIM. Parsers have to be rebuilt. Even the FortiGate guys came in and said that they don't play well in the sandbox."
"WAN load-balancing could be a lot better at detecting when a link is poor or inconsistent, and not just flat out dead."
"The UTM filtering needs improvement."
"It needs more available central management."
"The solution requires a more interactive dashboard. That would make it easier than playing with configurations the way we have to now."
"The solution could be more secure and have better integration."
"The solution doesn't seem to be very mature. Our networking team says they are experiencing a lot of issues in the firewalls and some routers."
"The user interface could be more user-friendly."
"The tool lacks features."
"The solution could be cheaper."
"Wi-Fi scanning and Wi-Fi analysis would be useful features to include in the future."
"The solution is scalable but it is difficult because you need to purchase new systems, it is not just one click."
"One thing that needs to be improved is their presence in China. I'm not sure if that's a Zscaler thing or if it's a problem with all vendors in this space, but it would be nice to have better coverage in China. This concern is a common one for vendors across the board when dealing with the Chinese market."
"Sometimes it's not easy to use during large deployments of workstations."
"The OS capabilities and WSL support could be improved."
"One thing that they could improve is the ability to import rules from other platforms."
"Zscaler should provide adjacent services, which would be complementary to their current offering that could to be more pragmatic for a customer. For example, if you take Akamai, you get multiple sets of services, all depending on the customer and the strategy and the complexity and the problems. In some areas, they are more varied in terms of coverage."
"They block Zscaler IPs when the traffic origin is from Zscaler IPs. They've been blocked by certain government organizations so the end users are not able to visit those websites unless we ask them to unblock those IP. This is a bit problematic."
"Currently, the solution's interface is not that user-friendly."
"An improvement would be if they could provide an out-of-the-box experience, like 20 to 30 features all ready to go. In comparison, LogRhythm offers out-of-the-box features. With Zscaler Internet Access, there is firewall IPS, multiple security services, filtering, DLP, and CASB browser isolation. These are things that all users are going to be using. However, when an administrator or architect would start building this, I would definitely need to engage professional services to help clients do it."
Huawei NGFW is ranked 31st in Firewalls with 20 reviews while Zscaler Internet Access is ranked 2nd in Secure Web Gateways (SWG) with 46 reviews. Huawei NGFW is rated 7.2, while Zscaler Internet Access is rated 8.2. The top reviewer of Huawei NGFW writes "A scalable and easy-to-setup product that can be used to configure different policies for specific users". On the other hand, the top reviewer of Zscaler Internet Access writes "Provides integrated CASB and file sandboxing but could be less expensive ". Huawei NGFW is most compared with Cisco Secure Firewall, Netgate pfSense, Meraki MX, Palo Alto Networks NG Firewalls and OPNsense, whereas Zscaler Internet Access is most compared with Cisco Umbrella, Microsoft Defender for Cloud Apps, Netskope , Prisma Access by Palo Alto Networks and Appgate SDP.
We monitor all Firewalls reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.