We performed a comparison between Palo Alto Networks NG Firewalls and Sangfor NGAF based on real PeerSpot user reviews.
Find out in this report how the two Firewalls solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."FortiGate firewalls are easy to manage through a user-friendly web interface. They also have advanced features like DDoS and DLP. However, I wouldn't recommend enabling all of these features on one device because it can cause performance issues."
"This solution made it very easy to manage our bandwidth."
"Good load balancing feature."
"Consolidated our network environment at all locations, but mainly at our datacenter."
"We use the filtering feature the most. It has filtering and inbuilt securities. We can create customized rules to define which users can access a particular type of site. We can create policies inside the firewall."
"The application control features, such as Facebook blocking and Spotify blocking, are the most valuable."
"There are great templates, so you don't have to customize them if you don't want to. You do have the option to custom create some folders and some reports, however, with what is there, you don't really need to go through extra effort, as they already give you a lot of predefined views of reports and so forth."
"The flexibility and ease of configuration are the most valuable features."
"Prisma Access is the most valuable feature of Palo Alto Networks NG Firewalls."
"The most valuable feature is the security provided by the ATP."
"Palo Alto NGFW provides a unified platform that natively integrates all security capabilities, which is very useful. This prevents us from having to go to a lot of different systems, and in some cases, many different systems in many different regions, because we are a global company with 60 remote offices around the world in 30 different countries. Its centralized platform is really what we look for in all services, whether it be security or otherwise."
"We have not had to replace hardware routers nor purchase additional hardware. So, that has provided a little bit of an ROI."
"The most valuable features are web filtering and application filtering."
"Its flexibility is the most valuable."
"The interface and dashboards are good."
"Palo Alto Networks NG Firewalls provide a unified platform that natively integrates all security capabilities."
"In terms of the most valuable features, the IPS report is quick and updated. Performance is also valuable."
"Sangfor is a good solution that provides a WAF and firewall solution. Most other vendors, like Sophos and Fortinet and Cisco, only provide one solution. That's a valuable feature of Sangfor."
"We've found the technical support to be helpful."
"It seems to be a durable, stable product."
"Sangfor NGAF works accordingly with our customers. The solution has good performance, easy to use, and integrates well with the endpoints."
"The most valuable feature of Sangfor NGAF is its integration."
"Sangfor has the best capabilities for securing connections, securing web browsers, securing servers, and general threat protection."
"Technical support is very good."
"We would like to have the ability to disable some of the security functionalities."
"Backup can be improved."
"Some features of Fortinet FortiGate are actually fee enabled that are inconvenient for deploying in production. Other issues relate to isolation with Cisco products and your server."
"The price of FortiGate should be reduced because there are some other leading products that are cheaper."
"The support costs and licensing are sometimes so expensive."
"The cloud features can be improved."
"Fortinet FortiGate could improve by having a frequent ask questions(FAQ) area for people to receive quick answers to popular questions. Additionally, it would be beneficial to have an SMS notification feature. For example, if you cannot access your email you could receive an SMS message."
"Fortinet FortiGate could improve by having more capabilities for troubleshooting VPN connections. For example, I do get some feedback about the current status, but I could use some history and logging of important events. The information is logged in our Syslog server, but I could use that information from the device. If they could provide a GUI to have some more insight on what's going with my VPN would be useful."
"We are not happy with Palo Alto at all. It would be better if they provided more support for the firewall. We have a few pending issues with the configuration for each application. We cannot deploy them yet due to some support-related problems in the firewall. We have deployed a few policies for DNS spoofing and DNS attacks, but we could only block a few IP addresses through the policy. That's DNS security, and we have configured a few policies for DNS spoofing and more. URL categorization and URL filtering are not yet adequately maintained. For example, if you created a few rules in the rule-based configuration and made some rules downstairs, you will lose some of them if you give access upstairs. It's not giving us a proper solution for which route it is using. We need to apply the application-based policies and URL filtering-based policies. It creates more issues because we are not getting good support from the team."
"The reports it provides are not helpful."
"With new features and applications you get bugs."
"This is a difficult product to manage, so the administrator needs to have a good knowledge of it, otherwise, they will not be able to handle it properly."
"Palo Alto should improve their support. It's sometimes difficult to get the right technician or engineer to fix the problem as soon as possible."
"I would like to see better integration with IoT technologies."
"The biggest thing that needs to be improved with them is their training. I took a training class for the 8.0 build, then I took it again for the 9.0 and 10 builds. They add new features every time that they do a new major release, but the training doesn't keep up. It is the same basic training that probably was with the 3.0 build, and they just change the screenshots. I would love to see them do some more work since they have all these bells and whistles, but we don't know how to use those features on a large scale."
"We have not taken Palo Alto's firewall management solution because it's too expensive and we don't feel it delivers significant value."
"I believe that IAM and NGFW need to merge into a single box, instead of there being two separate box solutions."
"The solution should be able to work in a hybrid setup."
"Sangfor NGAF could improve the policies and default criteria. They could be much better."
"Occasional issues with breaches which are dealt with expediently."
"Sangfor has recently increased their prices."
"The product must provide more IPS features."
"Sangfor could improve by providing better real-time reporting, as the current reports don't offer the level of detail we need, especially for runtime insights."
"Our experience with its customer support was quite challenging."
More Palo Alto Networks NG Firewalls Pricing and Cost Advice →
Palo Alto Networks NG Firewalls is ranked 6th in Firewalls with 162 reviews while Sangfor NGAF is ranked 20th in Firewalls with 31 reviews. Palo Alto Networks NG Firewalls is rated 8.6, while Sangfor NGAF is rated 8.0. The top reviewer of Palo Alto Networks NG Firewalls writes "We get reports back from WildFire on a minute-by-minute basis". On the other hand, the top reviewer of Sangfor NGAF writes "Affordable, easy to configure firewall with fast, responsive support". Palo Alto Networks NG Firewalls is most compared with Check Point NGFW, Azure Firewall, Meraki MX, Sophos XG and Stormshield Network Security, whereas Sangfor NGAF is most compared with Sophos XG, Netgate pfSense, Check Point NGFW, Fortinet FortiOS and Huawei NGFW. See our Palo Alto Networks NG Firewalls vs. Sangfor NGAF report.
See our list of best Firewalls vendors.
We monitor all Firewalls reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.