We performed a comparison between Netgate pfSense and Sangfor NGAF based on real PeerSpot user reviews.
Find out in this report how the two Firewalls solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."The signature database and zero-day detection are Fortinet FortiGate's most valuable features."
"One of the nice things about FortiGate is that it can be deployed on the cloud or on-premises. You can actually do both. That's the biggest reason why I stick with this solution as opposed to something like Cisco Meraki. Another nice thing is that I can log directly into a FortiGate or get to it through their FortiCloud access products. They're pretty reliable and consistent. One of the reasons why I started using the product was their single pane of management. I can deploy their line of firewalls in conjunction with their switching and access points, and I can manage the entire network from one interface. I don't have to log into one interface for the firewall, another one for the access points, and another one for the switches. These firewalls have access point controller functionality built right into the system, so I don't even have to purchase additional devices to manage them."
"The FortiGate controls the user's activities and maximizes my bandwidth use overall."
"It is a safe product."
"One of the valuable features is a standardized OS."
"Their reliability and their policy of pre-shipping replacements when a unit has failed."
"Fortinet FortiGate has many valuable features, such as IDS, and intrusion detection. It has security features that are in part with the technologies that are available in the market."
"The most valuable features of the solution are SD-WAN, filtering testing applications, web filtering, and the new VPN."
"pfSense is a nice product, and I find that there's a lot of information out there. There are some good tutorials on YouTube and other websites with helpful information."
"For everyday tasks, we just get alerts. It's anything that's suspicious, including from our Netgate. So, it's part of how we maintain cybersecurity in our school. This is working alongside our endpoint security solution."
"This solution has increased the level of security, given us more control, provided a deep insight into network traffic, and is a great VPN solution."
"I have found the most valuable features to be antivirus and malware protection."
"The scalability is very good, where you can do an HA configuration and then bring in another box, if necessary."
"Content protection, content inspection, and the application level firewall."
"The plugins or add-ons are most valuable. Sometimes, they are free of charge, and sometimes, you have to pay for them, but you can purchase or download very valuable plugins or add-ons to perform internal testing of your network and simulate a denial-of-service attack or whichever attack you want to simulate. You can also remote and monitor your network and see where the gap is. Did you forget a printer port? Most attacks at the moment are happening through printers, and they can tell you immediately that you forgot to close the port of the printer. There are more than one million printers that are in danger, and everybody knows that hackers are using them to enter the network. So, you can download plugins to protect your network."
"The initial setup was straightforward, therefore I wanted to continue using the product."
"While the features are not dissimilar to other brands, configuration is much more simple, which works out great for Indonesian people."
"It offers application control features."
"Particularly good in the DPI where we can inspect inbound and outbound traffic."
"We can utilize our own network rather than paying for a private one."
"It enables us to not only detect but also prevent various types of incoming threats, allowing us to take appropriate corrective actions and exercise control over the network."
"Sangfor has the best capabilities for securing connections, securing web browsers, securing servers, and general threat protection."
"The stability of Sangfor NGAF is good."
"It is a stable solution."
"There can be more security in hybrid implementations. When a customer has a hybrid environment where some parts are in the cloud, we need a consistent security solution for such scenarios."
"The initial setup and configuration are not intuitive and require training."
"I would like reporting to be improved and should offer a lot more tools to monitor the products."
"FortiLink is the interface on the firewall that allows you to extend switch management across all of your switches in the network. The problem with it is that you can't use multiple interfaces unless you set them up in a lag. Only then you can run them. So, it forces you to use a core type of switch to propagate that management out to the rest of the switches, and then it is running the case at 200. It leaves you with 18 ports on the firewall because it is also a layer-three router that could also be used as a switch, but as soon as you do that, you can't really use them. They could do a little bit more clean up in the way the stacking interface works. Some use cases and the documentation on the FortiLink checking interface are a little outdated. I can find stuff on version 5 or more, but it is hard to find information on some of the newer firmware. The biggest thing I would like to see is some improvement in the switch management feature. I would like to be able to relegate some of the ports, which are on the firewall itself, to act as a switch to take advantage of those ports. Some of these firewalls have clarity ports on them. If I can use those, it would mean that I need to buy two less switches, which saves time. I get why they don't, but I would still like to see it because it would save a little bit of space in the server rack."
"The central management for the FortiGate Fortinet Firewall needs improvement. They have the manager to do the essential management for both SD-WAN and for the security policy. They should also improve the SD-WAN function."
"Performance and technical support are the main issues with this solution."
"It would be good if they had fewer updates."
"Its filtering is sometimes too precise or strict. We sometimes have to bypass and authorize some of the sites, but they get blocked. We know that they are trusted sites, but they are blocked, and we don't know why."
"I have been using WireGuard VPN because it is a lot faster and more secure than an open VPN. However, in the latest version of pfSense, they have removed this feature, which is one of the main features that I need. They should include this feature."
"Many people have problems setting up the web cache for the web system."
"We have not had any problems with it, and we also do not have a need for any new features. If anything, its reporting can be better. Sophos has better reporting than pfSense. Sophos has more detailed information. pfSense is not as detailed. It is summarized."
"The Netgate forums and community don’t provide extensive discussions and topics related to every pfSense service."
"It's just not listed as FIPS compliant for where we're at now in government, which is an issue."
"A way to clean squid cache from the GUI."
"It requires more attention to provide a better alternative for open source to small government or educational institutions with reduced budgets in terms of technology."
"Perhaps the documentation is not clear and because it is supported in the community there is no basic documentation."
"The setup phase is quite complex."
"The solution has too many bugs and these slow down the implementation."
"Sangfor need greater exposer in the market because the market is mainly saturated by Fortinet. The user experience of Fortinet is quite different compared to NGAF. If we want to switch our users from Fortinet to NGAF, we have to convince them that the user experience will be much easier once once they start to use it."
"The web interface needs to be improved, making it more user-friendly."
"I would be happy if Sangfor developed a firewall designed specifically for home use, as well as for small businesses such as clinics and so on. A household version of the Sangfor firewall for your personal computer or laptop would be ideal, in my opinion."
"The product must provide more IPS features."
"The GUI needs to be improved, lacks logic in some areas."
"Sangfor NGAF could improve the policies and default criteria. They could be much better."
Netgate pfSense is ranked 1st in Firewalls with 128 reviews while Sangfor NGAF is ranked 20th in Firewalls with 31 reviews. Netgate pfSense is rated 8.6, while Sangfor NGAF is rated 8.0. The top reviewer of Netgate pfSense writes "User-friendly, easy to manage the firewall, rule-wise and interface-wise". On the other hand, the top reviewer of Sangfor NGAF writes "Affordable, easy to configure firewall with fast, responsive support". Netgate pfSense is most compared with OPNsense, Sophos XG, KerioControl, Sophos UTM and Cisco Secure Firewall, whereas Sangfor NGAF is most compared with Sophos XG, Palo Alto Networks NG Firewalls, Check Point NGFW, Fortinet FortiOS and Huawei NGFW. See our Netgate pfSense vs. Sangfor NGAF report.
See our list of best Firewalls vendors.
We monitor all Firewalls reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.