We just raised a $30M Series A: Read our story

Compare Sangfor NGAF vs. Sophos XG

Cancel
You must select at least 2 products to compare!
Sangfor NGAF Logo
4,911 views|2,795 comparisons
Sophos XG Logo
43,955 views|36,450 comparisons
Featured Review
Find out what your peers are saying about Sangfor NGAF vs. Sophos XG and other solutions. Updated: November 2021.
552,305 professionals have used our research since 2012.
Quotes From Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:

Pros
"The solution offers very easy configurations.""The most valuable features of this solution are the integrations and IPS throughput.""The integration of network and workload micro-segmentation helps a lot to provide unified segmentation policies across east-west and north-south traffic. One concrete example is with Cisco ACI for the data center. Not only are we doing what is called a service graph on the ACI to make sure that we can filter traffic east-west between two endpoints in the same network, but when we go north-south or east-west, we can then leverage what we have on the network with SGTs on Cisco ISE. Once you build your matrix, it is very easy to filter in and out on east-west or north-south traffic.""We get the Security Intelligence Feeds refreshed every hour from Talos, which from my understanding is that they're the largest intelligence Security Intelligence Group outside of the government.""Another benefit has been user integration. We try to integrate our policies so that we can create policies based on active users. We can create policies based on who is accessing a resource instead of just IP addresses and ports.""If you compare the ASA and the FirePOWER, the best feature with FirePOWER is easy to use GUI. It has most of the same functionality in the Next-Generation FirePOWER, such as IPS, IPS policies, security intelligence, and integration and identification of all the devices or hardware you have in your network. Additionally, this solution is user-friendly.""You do not have to do everything through a command line which makes it a lot easier to apply rules.""If configured, Firepower provides us with application visibility and control."

More Cisco Firepower NGFW Firewall Pros »

"In four steps one can configure the entire firewall.""In terms of the most valuable features, the IPS report is quick and updated. Performance is also valuable.""While the features are not dissimilar to other brands, configuration is much more simple, which works out great for Indonesian people.""Sangfor has the best capabilities for securing connections, securing web browsers, securing servers, and general threat protection.""We've found the technical support to be helpful.""It's a very simple to use product."

More Sangfor NGAF Pros »

"I have found the solution easy to use and fully integrated.""We get good usage out of the features. It has enabled us to gain popularity. It has great features.""It is stable, flexible, and easy to use. It has got a web management portal that can be accessed from anywhere.""We've deployed quite a number for our users and our customers, and the feedback is quite positive in terms of management and also administration.""The user authentication rules are very useful.""Great interface and in-built help is very intuitive.""The user interface is very good.""I recommend the solution due to its ease of use and pricing."

More Sophos XG Pros »

Cons
"This product is managed using the Firepower Management Center (FMC), but it would be better if it also supported the command-line interface (CLI).""They need a VTI. I know it's going to be available in the next software version, which is the 6.7 version. However, the problem with that is that the 6.7 is going to deprecate all the older IKEv1 deployment tunnels. Therefore, the problem is that we have a lot of customers which are using older encryptions. If I do that, update it, it's not going to work for me.""There is limited data storage on the appliance itself. So, you need to ship it out elsewhere in order for you to store it. The only point of consideration is around that area, basically limited storage on the machine and appliance. Consider logging it elsewhere or pushing it out to a SIEM to get better controls and manipulation over the data to generate additional metrics and visibility.""The initial setup can be a bit complex for those unfamiliar with the solution.""I was just trying to learn how this product actually operates and one thing that I see from internal processing is it does fire-walling and then sends it to the IPS model and any other model that needs to be performed. For example, content checking or filtering will be done in a field processing manner. That is something that causes delays in the network, from a security perspective. That is something that can be improved upon. Palo Alto already has implemented this as a pilot passed processing. So they put the same stream of data across multiple modules at the same time and see if it is giving a positive result by using an XR function. So, something similar can be done in the Cisco Firepower. Instead of single processing or in a sequential manner, they can do something similar to pile processing. Internal function that is something that they can improve upon.""The price and SD-WAN capabilities are the areas that need improvement.""The change-deployment time can always be improved. Even at 50 seconds, it's longer than some of its competitors. I would challenge Cisco to continue to improve in that area.""The intelligence has room for improvement. There are some hackers that we haven't seen before and its ability to detect those types of attacks needs to be improved."

More Cisco Firepower NGFW Firewall Cons »

"Occasional issues with breaches which are dealt with expediently.""They need to increase the number of ports in the firewall.""I believe that IAM and NGFW need to merge into a single box, instead of there being two separate box solutions.""The solution has too many bugs and these slow down the implementation.""The web interface needs to be improved, making it more user-friendly."

More Sangfor NGAF Cons »

"I would want the level of integration to have another device on your network that is also reliable.""The interface could be simplified and diagnostic system graphs improved.""Even though things work on the back end, we have encountered bugs in the solution.""I would like to have more artificial intelligence in the web monitoring service that comes with it. It should alert us when particular events happen. It has already got some of that. I know that it is more of a service, and Sophos is already looking at it. It is called SIEM.""When you are using it as a controller for the wireless access points, it doesn't perform well. It is not suitable for the public cloud. It is more suitable for enterprise data. It is not really the equipment for cloud data centers. I am looking for a data center firewall.""XG is at its end of life. People are moving to XGS.""They can lower its price. It is very expensive. We are looking for a less expensive solution depending on our budget. They can also improve it in terms of firewall protection.""It is already secure but it could be better in terms of other breaches that may occur."

More Sophos XG Cons »

Pricing and Cost Advice
"When we purchased the firewall, we had to take the security license for IPS, malware protection, and VPN. If we are using high availability, we have to take a license for that. We also have to pay for hardware support and technical support. Its licensing is on a yearly basis.""When we are fighting against other competitors for customers, whether it is a small or big business, we feel very comfortable with the price that Firepower has today.""Pricing is the same as other competitors. It is comparable. The licensing has gotten better. It has been easier with Smart Licensing.""Cisco, as we all know, is expensive, but for the money you are paying, you know that you are also getting top-notch documentation as well as support if needed.""Its pricing is good and competitive. There is a maintenance cost. It includes SecureX that makes it cost-effective as compared to the other solutions where you have to pay for XDR and SOAR capabilities.""For me, personally, as an individual, Cisco Firepower NGFW Firewall is expensive.""I like the Smart Licensing, because it is more dynamic and easier to keep track of where you are at. If we have a high availability firewall pair and they are deployed in active/standby rather than active/active, I would expect that we would only pay for one set of licenses because you are using only one firewall at any one time. The other is there just for resiliency. The licensing, from a Firepower perspective, still requires you to have two licenses, even if the firewalls are in active/standby, which means that you pay for the two licenses, even though you might only be using one firewall any one time. This is probably not the best way to do it and doesn't represent the best value for money. This could be looked at to see if it could be done in a fairer way.""The price of Firepower is not bad compared to other products."

More Cisco Firepower NGFW Firewall Pricing and Cost Advice »

"The price is unmatcheable.""When it comes to the price of firewall solutions, Sangfor NGAF takes the cake.""Sangfor is cheaper than competing vendors."

More Sangfor NGAF Pricing and Cost Advice »

"We paid for our licensing for three years, upfront, and there are no costs in addition to the standard fees.""Sophos allows for its product to be evaluated without any financial commitment.""The price can be a bit steep but for the number of features, it is worth it.""Sophos XG isn't expensive compared to Check Point.""The price is reasonable but it would be great if it was reduced to half the price.""The price is good for the moment.""The product is well priced.""Licensing fees are on a yearly basis."

More Sophos XG Pricing and Cost Advice »

report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
552,305 professionals have used our research since 2012.
Questions from the Community
Top Answer:  When you compare these firewalls you can identify them with different features, advantages, practices and… more »
Top Answer:  The Cisco Firepower NGFW Firewall is a very powerful and very complex piece of anti-viral software. When one considers… more »
Top Answer: It is easy to integrate Cisco ASA with other Cisco products and also other NAC solutions. When you understand the Cisco… more »
Top Answer: In four steps one can configure the entire firewall.
Top Answer: The price is very cheap. It cannot be matched.
Top Answer: I believe that IAM and NGFW need to merge into a single box, instead of there being two separate box solutions.
Top Answer: Hi, This really gets to two things: - how fast your internet access is and how much are you planning to grow in the… more »
Top Answer: Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat… more »
Top Answer: Sophos UTM is no longer being developed, according to our reseller. All the development effort is going into XG. So XG… more »
Comparisons
Also Known As
Cisco Firepower NGFW, Cisco Firepower Next-Generation Firewall, FirePOWER, Cisco NGFWv
Sangfor NGAF Firewall Platform
Learn More
Overview

Cisco NGFW firewalls deliver advanced threat defense capabilities to meet diverse needs, from
small/branch offices to high performance data centers and service providers. Available in a wide
range of models, Cisco NGFW can be deployed as a physical or virtual appliance. Advanced threat
defense capabilities include Next-generation IPS (NGIPS), Security Intelligence (SI), Advanced
Malware Protection (AMP), URL filtering, Application Visibility and Control (AVC), and flexible VPN
features. Inspect encrypted traffic and enjoy automated risk ranking and impact flags to reduce event
volume so you can quickly prioritize threats. Cisco NGFW firewalls are also available with clustering
for increased performance, high availability configurations, and more.
Cisco Firepower NGFWv is the virtualized version of Cisco's Firepower NGFW firewall. Widely
deployed in leading private and public clouds, Cisco NGFWv automatically scales up/down to meet
the needs of dynamic cloud environments and high availability provides resilience. Also, Cisco NGFWv
can deliver micro-segmentation to protect east-west network traffic.
Cisco firewalls provide consistent security policies, enforcement, and protection across all your
environments. Unified management for Cisco ASA and FTD/NGFW physical and virtual firewalls is
delivered by Cisco Defense Orchestrator (CDO), with cloud logging also available. And with Cisco
SecureX included with every Cisco firewall, you gain a cloud-native platform experience that enables
greater simplicity, visibility, and efficiency.
Learn more about Cisco’s firewall solutions, including virtual appliances for public and private cloud.

Sangfor Next Generation Firewall (also known as NGAF) is a converged security solution providing protection against advanced threat, malware, viruses, ransomware and web-based attacks using integrated security features like firewall, IPS, anti-virus, anti-malware, APT, URL filtering, Cloud Sandbox, and WAF. As the world's first AI-enabled and fully integrated Next Generation Firewall & Web Application Firewall (WAF), NGAF offering the security visibility, real-time detection and response, simplified operation and maintenance and high-performance application layer security needed to operate an enterprise network in total security. Tested and proven to provide cutting-edge network security by ICSA Labs and endorsed by Gartner Inc., NGAF harnesses the power of Sangfor’s Neural-X threat intelligence and analytics platform and Engine Zero’s innovative malware detection to provide next-generation protection for today’s enterprise.

Sophos XG Firewall is next gen firewall that is optimized for today’s business, delivering all the protection and insights you need in a single, powerful appliance that’s easy to manage.

Offer
Learn more about Cisco Firepower NGFW Firewall
Learn more about Sangfor NGAF
Learn more about Sophos XG
Sample Customers
Rackspace, The French Laundry, Downer Group, Lewisville School District, Shawnee Mission School District, Lower Austria Firefighters Administration, Oxford Hospital, SugarCreek, Westfield
The Ministry of Science, Technology, and Innovation (Indonesia), Lawson, Inc. (Philippines), Universiti Sultan Zainal Abidin (Indonesia), TEK Automotive (Italy), etc.
Information Not Available
Top Industries
REVIEWERS
Comms Service Provider22%
Financial Services Firm16%
Manufacturing Company8%
Non Profit8%
VISITORS READING REVIEWS
Comms Service Provider32%
Computer Software Company21%
Government7%
Manufacturing Company4%
VISITORS READING REVIEWS
Comms Service Provider43%
Computer Software Company20%
Media Company5%
Government5%
REVIEWERS
Financial Services Firm11%
Manufacturing Company10%
Comms Service Provider9%
Healthcare Company8%
VISITORS READING REVIEWS
Comms Service Provider40%
Computer Software Company18%
Government6%
Media Company4%
Company Size
REVIEWERS
Small Business43%
Midsize Enterprise28%
Large Enterprise29%
VISITORS READING REVIEWS
Small Business21%
Midsize Enterprise13%
Large Enterprise66%
REVIEWERS
Small Business43%
Midsize Enterprise57%
REVIEWERS
Small Business64%
Midsize Enterprise23%
Large Enterprise12%
VISITORS READING REVIEWS
Small Business49%
Midsize Enterprise25%
Large Enterprise26%
Find out what your peers are saying about Sangfor NGAF vs. Sophos XG and other solutions. Updated: November 2021.
552,305 professionals have used our research since 2012.

Sangfor NGAF is ranked 23rd in Firewalls with 6 reviews while Sophos XG is ranked 6th in Firewalls with 116 reviews. Sangfor NGAF is rated 8.2, while Sophos XG is rated 8.2. The top reviewer of Sangfor NGAF writes "Great pricing, reliable stability, and easy to deploy". On the other hand, the top reviewer of Sophos XG writes "Light and stable with excellent real-time control ". Sangfor NGAF is most compared with Fortinet FortiGate, Fortinet FortiOS, Sophos UTM, pfSense and SonicWall NSa, whereas Sophos XG is most compared with Fortinet FortiGate, pfSense, Sophos UTM, Meraki MX and Sophos Cyberoam UTM. See our Sangfor NGAF vs. Sophos XG report.

See our list of best Firewalls vendors.

We monitor all Firewalls reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.