Firewalls
Firewalls
Firewalls
Contents
Firewalls Recap . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3 ‐ 4
Firewalls Recap
Firewalls recap
Firewalls serve as a crucial line of defense against cyber threats by monitoring and controlling
incoming and outgoing network traffic.
Firewalls analyze network traffic based on pre‐defined security rules to block unauthorized
access, providing a barrier between trusted internal networks and untrusted external
networks. They are essential for organizations seeking to protect their digital assets.
Firewalls are utilized in industries like finance, healthcare, and education to safeguard
sensitive information. Financial institutions use them to secure transactions, while healthcare
organizations protect patient data. Educational institutions ensure safe internet access for
students.
Firewalls are indispensable for organizations aiming to maintain robust cybersecurity. They
provide essential defense mechanisms to protect critical assets from evolving cyber threats.
Firewalls
Top Solutions
Netgate pfSense
Fortinet FortiGate
OPNsense
Sophos XG
Focus on solutions
Netgate pfSense
Executive summary
Netgate pfSense stands out in diverse environments with its enterprise‐grade features and
cost‐effective operations compared to competitors like Cisco. Deployed as an edge device, it
optimizes routing, ad‐blocking, content filtering, and traffic shaping. Users benefit from its
versatile configurations, robust firewall protection, VPN functionality, and ISP load balancing.
The open‐source nature allows for extensive customization, integrating plugins like Snort and
pfBlockerNG, and compatibility with third‐party tools enhances its utility. The intuitive GUI
combined with detailed logging and centralized management fortifies network security.
• Firewall: Provides robust network security through advanced filtering and stateful
packet inspections.
• VPN: Ensures secure remote access with high‐performing VPN capabilities.
• Load Balancing: Efficiently distributes traffic across multiple ISPs, ensuring uptime and
performance.
• Customization: Supports various plugins for enhanced functionality, tailor‐made to
specific needs.
• Scalability: Adapts easily to varying network demands, providing high availability and
flexibility.
Organizations in industries such as finance, healthcare, and education find Netgate pfSense integral due to its
advanced security features and cost benefits. Its scalable architecture and strong VPN support are crucial for
industries requiring stringent data protection and reliable remote access. The adaptability of pfSense makes it suitable
for dynamic environments seeking comprehensive, secure networking solutions.
Sample customers
Nerds On Site Inc., RKC Development Inc., Expertech, Fisher's Technology, Ncisive,
Consulting, CPURX, Vaughn's Computer House Calls, Imeretech LLC, Digital Crisis,
Carolina Digital Phone, Technigogo Technology Services, The Simple Solution,
SwiftecITInc, Rocky Mountain Tech Team, Free Range Geeks, Alaska Computer
Geeks, Lark Information Technology, Renaissance Systems Inc., Cutting Edge
Computers, Caretech LLC, GoVanguard, Network Touch Ltd, P.C. [Link],
Vision Voice and Data Systems LLC, Montgomery Technologies, Techforce, Concero
Networks, ASONInc, CPS Electronics and Consulting, [Link] LLC, IT
Specialists, MBS‐Net Inc., VOICE1 LLC, Advantage Networking Inc., Powerhouse
Systems, Doxa Multimedia Inc., Pro Computer Service, Virtual IT Services, A&J
Computers Inc., Envision IT LLC, CommunicaONE Inc., Bone Computer Inc., Amax
Engineering Corporation, QPG Ltd. Co., IT 101 Inc., Perfect Cloud Solutions, Applied
Technology Group Inc., The Digital Sun Group LLC, Firespring
Compared 36% of the time Compared 22% of the time Compared 8% of the time
Learn more Learn more Learn more
University 7%
Educational Organization 6%
University 6%
Company size
Valuable features
AvilashBiswal
Information Technology Infrastructure Manager at a tech services company with
11‐50 employees
“Netgate pfSense's best features are that it's open source and flexible.”
Sel uk Türkmen
General manager at Step Computer
“The Tailscale integration is very helpful. The DHCP and DNS server
functionalities, as well as the package manager, are also good.”
Verified user
IT at Hunor
Verified user
Vice President at a consultancy with 51‐200 employees
“pfSense's user interface is very nice for simpler configs and monitoring. It
is very stable, and it works very well.”
Verified user
Works
“The best features of Netgate pfSense include its open-source nature, and one of
the most appealing aspects is the absence of recurring expenses, as there are no
licensing fees. Users get enterprise-class firewall networking with this product.
“Customers who use other firewall products such as Sophos or FortiGate often
conduct research and choose Netgate pfSense because the yearly expenses of other
firewall products are higher compared to pfSense, which has no licensing fee.
While there is no yearly licensing fee with this product, users still receive all the
enterprise-class firewall features.
“From my perspective, the best feature of Netgate pfSense is the load balancer, as I
usually take multiple internet connections. I can use both internet providers'
bandwidth as a single network bandwidth, which helps in a very smooth network
traffic flow. Netgate pfSense has a very interactive and intuitive dashboard that
provides all the major and informative information that is readily available.
“From my usage, controlling the bandwidth for each user is valuable. Also, the
availability of working as a backup or aggregating downloads is useful. All these
capabilities are key.
“Its ease of use is great. If I do not continue forward with pfSense, it would be
going to VyOS, which is all command line. pfSense's user interface is very nice for
simpler configs and monitoring. It is very stable, and it works very well. Flexibility
is great, and the plug-in model is very nice for pfBlocker and other things. It is a
very robust solution that works very well..”
The key thing I found is saving on the cost of equipment. Whether CapEx or OpEx,
we appreciate this..”
“What I like most about the product is that it is simple to use. I use it at home and
in other locations. It offers great value for money because there are no licensing
issues apart from the support package. I don't have to worry about licenses
expiring or the firewall not working. The overall security gain is stable and
reliable..”
Pain Points
“AI would always be a plus point, and if pfSense could change its framework
from FreeBSD and PHP to a different language and Linux OS, that could
enhance security.”
AvilashBiswal
Information Technology Infrastructure Manager at a tech services company with
11‐50 employees
“We appreciate the flexibility of the Netgate pfSense solution, but we have
waited approximately two years for new updates to the Community Edition.
We are now moving to OPNsense.”
Sel uk Türkmen
General manager at Step Computer
Verified user
IT at Hunor
Verified user
Vice President at a consultancy with 51‐200 employees
“They could do better with their licensing in the home use space. For me,
that has been a struggle.”
Verified user
Works
“Areas of Netgate pfSense that can be improved include the customers' requests
for antivirus protection, which they refer to as Unified Threat Management,
available in other products. Unified Threat Management can match up with other
brands as well..”
“For my requirements and use cases, it is sufficient for me, and I have never faced
a need for additional features. AI would always be a plus point, and if pfSense could
change its framework from FreeBSD and PHP to a different language and Linux OS,
that could enhance security..”
“We appreciate the flexibility of the Netgate pfSense solution, but we have waited
approximately two years for new updates to the Community Edition. We are now
moving to OPNsense.
“I am using its paid version. I am paying at home for the Plus version, but I wish
they would pay attention to the community version. I know there is less incentive
for Netgate to develop the community version, but it would be cool to have that.
pfSense does not give us a single pane of glass management. I know that they are
coming out with that as a beta or alpha feature, but it is not there yet.
I have experienced only hardware-related issues with Netgate. They are not related
to pfSense as a software. I purchased a Netgate firewall, an SG-4100, which is a
$600 device, intending to make it a solid piece of my home lab and support the
project. It died in one and a half years. I do not see the value in buying their
hardware, as their customer support was not friendly or helpful. Eventually, I
bought pfSense Plus, which allows using a roughly $200 device that offers part-
swapping to keep the device alive or even buying two of them. The pfSense Plus
subscription is roughly the same value.
Support for third-party hardware is less documented, not being their preferred
option. For most things, it is pretty solid. Other firewalls such as SonicWall offer
more protection features such as deep packet inspection. I know that is possible
with Snort or Suricata. That is one thing that could differentiate open-source
firewalls from the main players.
“They could do better with their licensing in the home use space. For me, that has
been a struggle.
I got three pfSense Plus licenses when they were giving them away to the
community for free because pfSense decided that they do not enable the QAT. They
do not enable the network acceleration function that is on the Intel Atom CPUs and
some of the Xeon D's in the Community edition. IPSec acceleration and OpenVPN
acceleration do not work on those smaller boxes because it is going to use the CPU,
so I got the three licenses, which worked well. It was all good, but they decided to
take that away and are charging $129 a year. Somebody savvy like me is going to
pay for it. I will pay for it for myself, but I also maintain the routers of my parents,
my mother-in-law, and a friend. I have IPSec tunnels to them, and they need the
acceleration technology that is disabled, but they are not willing to pay $129. I
wrote to the Netgate salesperson asking to consider a model with a $60 per year
subscription because they are putting a barrier on themselves. They have
abandoned the Community edition. There has not been an update in a year, but
then you hear that they are contributing. They are making updates, but they have
not released it. There is an opportunity to make more money in the home user
space if they change their licensing model.
The other little hiccup that I see with it is they have it tied to MAC addresses. It
generates a license based on the MAC address. If you change any MAC address, you
have to issue a new license. They were nice about it for me when they did a one-
time change for me, but if I put another Ethernet adapter in the box, it says it
needs another license. They should work on that. It seems they are going to change
this..”
“The user interface needs improvement. Even though it's a system that's easy to
get working upon installation, the configurations are not intuitive. The interface
needs to be friendlier. That's the only complaint I have about pfSense..”
Pricing
“The cost of other firewalls goes to thousands and lakhs of rupees compared to
pfSense, which costs zero. If we opt for Fortinet, it costs about one lakh thirty
thousand Indian rupees for the firewall, and then it costs up to almost fifteen to
twenty thousand annually for the user subscription. With Netgate pfSense, all
those things get covered at zero cost.”
“Because the Community edition is free, we only charge for our services to the
customers. In Turkey, we cannot demand normal pricing; if we were in Europe or
the United States, we might collect more money from customers.”
“It is on the higher side. If you want to purchase pfSense Plus alone, the cost is
roughly $150 a year, but the value provided justifies the expense. However, a
lower-end tier option, around $100, would be beneficial.”
“The licensing model needs improvement, especially for home users. There should
be more flexibility to change licenses with hardware changes. The pricing model
could be more accessible for home users.”
Fortinet FortiGate
Executive summary
Fortinet FortiGate offers comprehensive network security and firewall protection across
multiple locations. It effectively manages data traffic and secures environments with features
like VPN, intrusion prevention, and UTM controls.
Organizations rely on Fortinet FortiGate for its robust integration with advanced security
policies, ensuring significant protection for enterprises, cloud environments, and educational
sectors. It facilitates network segmentation, application‐level security, and authentication
management, securing communication within and between locations such as branches and
data centers. Its efficient SD‐WAN and UTM features enable streamlined data management
and enhanced threat protection capabilities. Users appreciate its centralized management,
facilitating seamless operations across diverse environments.
• VPN Capabilities: Ensure secure remote access for users and seamless site‐to‐site
connections.
• Intrusion Prevention System (IPS): Detect and prevent security threats and
vulnerabilities.
• Advanced Firewall: Offers robust firewalling with application control and web filtering.
• SD‐WAN: Optimizes application performance and enhances bandwidth management.
• SSL VPN: Provides reliable and secure access for remote workers.
Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T‐
Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast,
Compared 20% of the time Compared 12% of the time Compared 11% of the time
Learn more Learn more Learn more
Manufacturing Company 9%
Retailer 5%
Manufacturing Company 7%
Company size
Valuable features
Verified user
System Administrator, Security Engineer, Security Result at a tech vendor with
201‐500 employees
Verified user
Head of Research at a construction company with 501‐1,000 employees
“I appreciate the ease of use, ease of setup, and the different abilities it has; I
have been very pleased with it over SonicWall, the interface of Fortinet
FortiGate is a lot easier to use and more robust, plus their VPN option is
much better.”
Jay Barwick
President at River Mill Data Management, LLC
“There’s something magical about the way the flavors blend together,
creating a dish that is both comforting and exciting.”
Verified user
Project Manager at a tech services company with 51‐200 employees
“I find that Fortinet FortiGate is pretty easy to use and integrated, offering
many features in one box at a decent price compared to other enterprise
vendors.”
Verified user
Works at a comms service provider with 1‐10 employees
“The standout features of Fortinet FortiGate include its ease of use, intuitive
interface for implementation, and simplified maintenance, administration, and
daily management from deployment to monitoring. The accessible support and
documentation that Fortinet makes available to all users is essential.
One of the advantages of using Fortinet is that it uses an identical FortiOS system
for all Fortinet products. They all have an intuitive interface that is easy to use and
learn, even for novices. They can easily integrate and adapt to use Fortinet in
different use cases. In my experience with products from other providers such as
Palo Alto, Cisco, and Check Point, Fortinet is the only provider to have successfully
set up a unified operating system on all its products in the network security
ecosystem.
Through a Fortinet FortiGate, you have the ability to manage the entire ecosystem
of your network through a simple management system. The Security Fabric of
FortiGate allows you to simplify management and threat response from all security
equipment that can collaborate and be used together. Additionally, FortiManager
accompanies this solution to unify the centralized management of all Fortinet
products, using the same FortiOS system.
“The main reason customers prefer Fortinet FortiGate is that it's security-centric,
allowing them to implement security features such as a next-generation firewall
and translate this to the WAN or SD-WAN architectures, or as a base if they want
to grow in more security features or other verticals such as ZTNA and SASE. It's a
little baseline for the rest of the verticals or features that can be exploited.
Fortinet Unified SASE is strong for providing consistent security policies across
multiple locations. Working with Fortinet in the SASE aspect has been easy.
Customers appreciate the features we can offer with Fortinet SASE and ZTNA
solutions. They particularly appreciate how they can integrate everything with the
baseline of Fortinet FortiGate, and how they can easily apply all the features they
need to secure access to different applications from a single console. Some clients
use the Fortinet FortiGate data center solution for their data centers as a hub and
the perimeter security service..”
“I assess Fortinet FortiGate firewall as a one-stop shop that helps me secure and
protect mission-critical data. Fortinet FortiGate also has products for protecting
the edge. Everything can be managed through one dashboard, so I cannot quantify
the time saved. Fortinet FortiGate has helped me remediate threats more
quickly..”
“The most valuable features of Fortinet FortiGate that I found are its next-
generation firewall capabilities with stateful inspection and antivirus, along with
features such as a reverse proxy that are missed by some other firewall products
such as Palo Alto or Check Point. We have a product suitable for the mid-sized
market where we can handle all necessary features without the need to build every
security feature with a separate device or product; thus, Fortinet FortiGate offers
the completest feature set for a firewall on the perimeter to the internet or for
internal segmentation..”
“The best features in Fortinet FortiGate are the VPNs for the outside network and
IPsec tunnels between the point-to-point links between their head office and
branch offices. Software VPNs provide remote access features and remote access
services. Fortinet Unified settings are good for our cloud-based management and
centralized management. I think it is a better option for that..”
“I appreciate the ease of use, ease of setup, and the different abilities it has. I have
been very pleased with it over SonicWall. The interface of Fortinet FortiGate is a lot
easier to use and more robust, plus their VPN option is much better; SonicWall is
ridiculously slow. I have been very happy with the effectiveness of the unified
SASE for providing consistent security policies across multiple locations. It has
positively impacted my organization by freeing me up regarding administration; I
spend a lot less time on administration. It probably saves me about 30 to 45
minutes a week..”
Pain Points
Verified user
System Administrator, Security Engineer, Security Result at a tech vendor with
201‐500 employees
Verified user
Head of Research at a construction company with 501‐1,000 employees
Jay Barwick
President at River Mill Data Management, LLC
“In the past six to seven years with the Fortinet FortiGate, we've had two
major downtimes, both caused by firmware upgrades.”
Joseph Koomson
IP Network Security Specialist at MTN Ghana
“The issue with Fortinet FortiGate is the many security CVEs around; I have
read there are probably multiple critical CVEs above 9.0 in Fortinet FortiGate
products.”
Tanaka Murinata
IT Director at a consumer goods company with 501‐1,000 employees
The implementation depends more on the engineer's skill when integrating SD-
WAN with Fortinet FortiGate. If you don't have extensive skills in implementing
Fortinet FortiGate, it can be difficult, but with more experience, it becomes easier.
.”
“At the moment, I cannot think of any areas where Fortinet FortiGate could be
improved. In future updates, I would like to see more RAM and lower prices..”
“The main issue we have dealt with in the last few months is the number of
vulnerabilities, which has caused concerns for both customers and integrators
regarding whether Fortinet is a secure product; this has affected my rating, as it is
why I do not give a ten, instead rating it an eight. The feature set works, but the
excessive vulnerabilities bring risks, necessitating upgrades and patches, which
complicate matters..”
“A shorter response time when we have questions could improve Fortinet's first-
level support quality. The knowledge base is comprehensive, so that is okay. For
additional features that could make Fortinet FortiGate even better in the future,
they have the SD-WAN, but I do not know if they have quantum VPN.
I saw one brand that has a quantum random number generator, so maybe that
could enhance security, along with a smaller version of their product to fit into the
budgets of smaller departments..”
Pricing
“The setup cost was good. The Egyptian pound is declining, and upgrading Fortinet
FortiGate yearly costs about $2000 USD, which equals one hundred Egyptian
pounds. I maintain a business relationship with the vendor and receive support
from them.”
“My experience with the pricing, setup cost, and licensing for Fortinet FortiGate is
quite good. I don't have a public site, such as in Azure, where I can see the pricing. I
always have to go through the distributor, and that could take some time to get the
real price for each appliance.”
“It is not the cheapest one, but its price is very competitive.”
“Some of our customers are using Sophos and SonicWall due to price concerns, as
they can't manage the pricing of Fortinet FortiGate.”
OPNsense
Executive summary
OPNsense is widely used for firewall functionalities, intrusion detection, VPN and IPSec,
content filtering, securing network traffic, and remote access. It protects internal networks
and manages servers securely, suitable for small to medium‐sized businesses.
OPNsense is implemented across various industries to secure network infrastructure and ensure reliable connectivity.
In fintech, it safeguards sensitive financial data while maintaining compliance. Educational institutions deploy it to
protect student information and enable secure remote learning environments. Healthcare organizations use it to
secure patient data and comply with HIPAA regulations. By integrating with tools like WireGuard and CrowdSec,
businesses enhance their cybersecurity posture and streamline network management, making OPNsense a versatile
choice for diverse operational needs.
Sample customers
1. Deciso B.V.
2. iXsystems, Inc.
3. EuroBSDCon
4. Netgate
5. Claranet
6. Voleatech
7. Open Systems AG
8. Securebit AG
9. Proxmox Server Solutions GmbH
10. AVM Computersysteme Vertriebs GmbH
Additional customers include: T‐Systems International GmbH, Deutsche Telekom AG,
Vodafone GmbH, 1&1 IONOS SE, OVHcloud, Hetzner Online GmbH, Strato AG,
PlusServer GmbH, Host Europe GmbH, United Internet AG, 1&1 Versatel
Deutschland GmbH, QSC AG, Bechtle AG, Cancom SE, Computacenter AG & Co.
oHG, T‐Systems Multimedia Solutions GmbH, Atos SE, Capgemini SE, Accenture plc,
IBM Corporation, Hewlett Packard Enterprise Company, Cisco Systems, Inc.
Compared 36% of the time Compared 15% of the time Compared 8% of the time
Learn more Learn more Learn more
Aerospace/Defense Firm 7%
Government 7%
University 6%
Manufacturing Company 6%
Company size
Valuable features
Stephen Zoran
Senior Client Solutions Architect at a tech services company with 1,001‐5,000
employees
Verified user
Senior Network Engineer at a comms service provider with 11‐50 employees
Chirosca Alecsandru
Owner at Networks srl
RicardoDias
Network and Programming Specialist at Twentytwo Integration
SergioRocha
IT infrastructure manager at a tech services company with 51‐200 employees
The main features I find valuable are ease of use, code stability, and the ability to
add features such as Zenarmor, which provides fourth-generation firewall
capabilities with deep packet inspection. Additionally, integrating solutions like
Tailscale for VPN is very valuable for my uses.
“The most valuable features include the basic firewall functionality and the GeoIP
location services. OPNsense is very stable, easy to upgrade, and maintain. I can
work efficiently, knowing it does what it needs to do..”
“It is easy to maintain. It is free. So, it is for small offices. It is a very good solution.
I like the dashboard. I can see what is going on and manage it as I like it. .”
“The most valuable feature is the Dual WAN in OPNSense, which offers advanced
capabilities. It has cost-effective communication options and the flexibility to
deploy on your hardware. I like the security aspects, particularly through package
managers. It allows for subscription-based enhancements, providing an additional
layer of security to the network..”
“The DNS-level filtering is impressive for thwarting time scanners. The VPN
functionality is also crucial for my needs, as I connect to multiple locations
simultaneously. Running the CBN server on the VPN is exceptionally reliable and
efficient..”
Pain Points
Verified user
Senior Network Engineer at a comms service provider with 11‐50 employees
Chirosca Alecsandru
Owner at Networks srl
RicardoDias
Network and Programming Specialist at Twentytwo Integration
SergioRocha
IT infrastructure manager at a tech services company with 51‐200 employees
PeterMuiruri
IT Manager at Pride in Azure
I pretty much like the solution's APIs, but it's somehow limited. I would like the
APIs to be more mature and more developed and have more options to automate
threat hunting. Also, I would like to see more drill-down possibilities.
“I would like better documentation concerning the provided packages and their
integration. Improved guidance on package usage and integration beyond relying
on external tutorials or community support would be beneficial. Additionally,
having community support available for the free edition, which is suitable for
home users, would be valuable..”
“There are some add-ons that need enhancements to make management easier
for users, especially the reporting features. Some reports don't show the level of
detail I'm looking for, and I've had trouble installing certain add-ons, especially
for Internet bandwidth shaping within my company. So, this is an area of
improvement for me. .”
“There are a few weaknesses. For example, there is a lack of some features that I
have in certain commercial products.
Some of the features include classified traffic and better blocking of newly
registered DNS domains..”
Pricing
“I've used the free version. My computer with two network cards at home allows
me to try as many different software options as I want. I did pay for the license, but
it was for the Zenarmor license, which is the packet inspection tool. They use AI
for packet inspection, which integrates with OPNsense and pfSense.”
“It is free.”
“I would rate the pricing a nine out of ten, especially considering the availability of
a free community edition.”
“It is a free solution, and when you compare it to alternatives like FortiGate, which
is quite powerful but also costly, the value becomes evident.”
Sophos XG
Executive summary
Sophos XG is a versatile network security solution that offers network protection, firewall
management, VPN access, web filtering, and intrusion prevention, providing comprehensive
security for businesses from small offices to large enterprises.
Sophos XG stands out for its Synchronized Security, easy setup, and robust templates. It
manages VPN access, protects against threats, and handles load balancing and traffic
monitoring. The cloud‐based management, centralized dashboard, and detailed logging make
it user‐friendly and reliable. Integration of features like email protection, SD‐WAN, and
unified threat management ensures a broad spectrum of security needs are covered.
However, it could benefit from improvements in network security, user portals, technical
support, and more scalable SD‐WAN features.
Compared 47% of the time Compared 9% of the time Compared 9% of the time
Learn more Learn more Learn more
University 6%
Energy/Utilities Company 6%
Manufacturing Company 7%
Company size
Valuable features
“The firewall feature of Sophos XG has been the most effective for threat
prevention.”
Stelios Georgiou
Information Technology Specialist at stelios@[Link]
Verified user
DevOps Engineer at a tech vendor with 51‐200 employees
TarunPanchal
IT Manager , SAP HANA Administrator at Tara Paints & Chemicals
Rajesh Panwala
Managing Director at Smartlink Solutions Pvt. Ltd.
Verified user
it officer at a government with 1,001‐5,000 employees
“The firewall feature of Sophos XG has been the most effective for threat
prevention and in collaboration with the integration of another Cyber Security
solution..”
“Sophos XG is user-friendly, easily configured, and has all the latest features,
including URL filtering.
“I have used the Synchronized Security feature of Sophos XG along with the
Heartbeat functionality, specifically the Security Heartbeat.
“The IPsec VPN is the only feature we utilized in Sophos XG. We did not explore the
web and application filtering capabilities, and these features have not helped our
organization in managing bandwidth or access to malicious sites..”
“The synchronized security feature has proven to be very beneficial, and I have not
encountered any issues.
“Sophos XG Firewall has contributed to reducing overall costs because it helps save
money. We purchased endpoint security for the first time last year, and even
without endpoint security, it provides comprehensive security.
“The aspects I appreciate about Sophos XG are the ease of operations and customer
satisfaction, though pricing is slightly higher compared to Indian variants.
“Regarding threat detection capabilities, if there are any use cases, we definitely
would want to use it, and the Sophos XG definitely has those features.
“In terms of features for network security, it's of importance, but for this
particular reason, the customer was not keen on it because it's a transport of
offices. They were not concerned about the transport and security aspects, but
even if they were, it would have been reasonably good in Sophos XG. I don't see any
challenge on that..”
“We find the network security, protection, and web features most effective for
threat prevention.
Pain Points
Stelios Georgiou
Information Technology Specialist at stelios@[Link]
Simadri Gujuri
Customer Support Executive at simadrig
Verified user
DevOps Engineer at a tech vendor with 51‐200 employees
TarunPanchal
IT Manager , SAP HANA Administrator at Tara Paints & Chemicals
Rajesh Panwala
Managing Director at Smartlink Solutions Pvt. Ltd.
“An area that could be improved is technical support's ticket registration process.
Sometimes when I contact technical support, they do not register the tickets
properly. They ask about registered mail ID and registration number when I am
already under pressure. For instance, when the internet is not working or when I
cannot apply certain rules, I am already stressed, but the tech support did not
register the calls. This happened three to four months ago..”
“While all features of Sophos XG are good, some improvement is needed in the UI,
as sometimes beginner users get lost in UI settings and do not understand where
to find specific settings..”
“The support time needs improvement, as sometimes they ask everything via
email and then it takes additional time for them to respond. When asking for
something related to reporting or anything, many times their help desk doesn't
have a ready reckoner sort of solution, which requires improvement on those
timelines.
“They could change their licensing model, simplify it, and make it more available
to upgrade. We are looking into upgrading or refreshing these firewalls since they
will be end of life. We are looking to replace it with another firewall with a five-
year license, at least, so that we can survive..”
“I do not have any specific ideas on what disadvantages Sophos XG could improve
upon.
Everything has been good; I have not encountered any major challenges or
problems.
Pricing
“On a scale from one to ten, where one is cheap and ten is expensive, I rate the
solution's pricing a seven out of ten.”
“The tool's pricing and licensing are very complex. As a developing company, we
need approvals from management to make a purchase, which can take time. We
asked Sophos XG to renew our current firewall license for one or two months while
we plan to accommodate our increasing IT assets.”
Executive summary
Check Point Quantum Force NGFW provides centralized management with scalable security
for network perimeters. As a reliable firewall, it ensures advanced threat prevention and
offers seamless integration, making it suitable for various network environments.
Offering comprehensive security, Check Point Quantum Force NGFW helps control ingress
and egress traffic, secures data center firewalls, and integrates seamlessly with cloud and on‐
premises setups. Users appreciate its application control, deep packet inspection, and identity
awareness features for enhanced protection against cyber threats. Despite pricing issues and
interface complexity, its IPsec VPN and robust logging provide valuable insights into network
activities.
What are the key features of Check Point Quantum Force NGFW?
What benefits should users consider for Check Point Quantum Force NGFW?
Check Point Quantum Force NGFW is deployed across industries for securing network
boundaries, supporting critical data center operations, and enabling secure VPN connections.
In finance, it helps meet stringent compliance standards, while in healthcare, it's crucial for
protecting sensitive patient data through robust security protocols.
Sample customers
Compared 25% of the time Compared 12% of the time Compared 8% of the time
Learn more Learn more Learn more
Manufacturing Company 7%
Retailer 4%
Manufacturing Company 6%
Company size
Valuable features
Verified user
Assistant Manager at a computer software company with 201‐500 employees
Verified user
Network Cyber Security Specialist at a tech services company with 51‐200
employees
“What I found very valuable in Check Point Quantum Force (NGFW) is the
possibility to share everything with the ThreatCloud; for example, when a
customer encounters a new virus, malware, or signature, it gets uploaded
into the ThreatCloud and shared among all other customers.”
Verified user
Security Support Engineer at a tech vendor with 51‐200 employees
Verified user
ICT at a manufacturing company with 501‐1,000 employees
Verified user
Enterprise Network Engineer at a outsourcing company with 201‐500 employees
“The best features that Check Point Quantum Force (NGFW) offers in my
experience are threat prevention, which gives deep visibility and protection
against real-time threats, along with features like IPS, anti-bot, sandboxing, and
URL filtering. The centralized management with the Smart Console is extremely
powerful with a user single pane of glass view across all the firewalls, policy, logs,
threat events, and it also correlates incidents.
“Check Point Quantum Force (NGFW) has positively impacted our organization by
notably reducing intrusion prevention attempts, as we see a reduction in
phishing-related malware that were previously bypassed but now are blocked,
leading to reduced security incidents. Our SOC reported around a 20 to 30% drop in
tickets due to blocked C2 traffic. We also see operational efficiency improvements
by freeing up engineering hours for strategic tasks and gaining visibility and
compliance through the dashboard and logs..”
“The best features Check Point Quantum Force (NGFW) offers include the logging
feature, and the IPS and IDS is also great.
“What makes those features stand out for me is that the logging is very easy to get
an overview on what's happening inside the network, and the IPS and IDS is very
much hand-off; you just set it up the first time and it's up and running.
“The way risk management has improved is that getting an overview and seeing
what's happening inside the network and then being able to take decisions on
what to allow and not allow is much easier than on other firewalls..”
“The best features Check Point Quantum Force (NGFW) offers are that it's a good
product with a lot of features and a great GUI interface to manage it.
“The interface of Check Point Quantum Force (NGFW) stands out because in a
single point, I can read all the logs of my device.
“The best features Check Point NGFW offers include unified threat management,
web filter engines, and intrusion prevention, which I find valuable because it's
important for us to have the security behind the data center down to the dot, and
because of the granular policies we set, we can manage every bit of security when it
comes to the data center network.
“One standout feature relates to a user feature that puts users into sessions every
time they are configuring, meaning one person is not going to configure the same
thing that another does, and it locks the configuration to avoid confusion where
one changes one thing and another person changes something differently on the
other side, and when you're done, the session is committed, and you can still roll
back in case the commit has an issue, which I find quite beneficial.
Check Point NGFW provides granular application control and detailed visibility
over application and user activity. It integrates with the ThreatCloud ecosystem,
enabling real-time threat detection and prevention. The User Identity Awareness
blade integrates with Active Directory, identifying user traffic sources. Check Point
NGFW is highly scalable and has centralized management through SmartConsole,
which manages policies, logs, and threat data. It reduced our incidents and
decreased the time to analyze cyber threats by 70 percent.
“Check Point NGFW has positively impacted my organization as the incidents have
reduced, resulting in no disruptions in the network. Everything is running
smoothly and the organization is protected by Check Point firewall. The users are
doing their desired tasks very efficiently, and everything is live in the network or
applications, providing excellent security. Therefore, there is no business
disruption so far..”
Pain Points
“While the Smart Console is powerful, I find that it can feel heavy and slow
with a large rules base, where a simple policy change sometimes takes longer
than expected, impacting agility in a fast-moving environment.”
Verified user
Assistant Manager at a computer software company with 201‐500 employees
“The scalability of Check Point Quantum Force (NGFW) is not very good;
what you buy the first time is what you get, and it's hard to scale from there,
but we over-scoped the deployment.”
Verified user
Network Cyber Security Specialist at a tech services company with 51‐200
employees
“The issues with Check Point Quantum Force (NGFW) are mainly related to
reliability. It depends significantly on the hotfix version of the gateway.”
Verified user
Security Support Engineer at a tech vendor with 51‐200 employees
“I find that the licenses are a bit expensive compared to other vendors, and
while the price is justified, at times, renewing them becomes a bit painful, so
if it could become a bit more budget-friendly, that would work for me.”
Verified user
Enterprise Network Engineer at a outsourcing company with 201‐500 employees
Hailemichael Yigrem
Senior Cyber Security Engineer at Deliver ICT and Telecommunication Technology
PLC
“While the Smart Console is powerful, I find that it can feel heavy and slow with a
large rules base, where a simple policy change sometimes takes longer than
expected, impacting agility in a fast-moving environment. The licensing and
advanced feature add-ons, like sand blast, require separate licenses, adding
complexity to budgeting and license adoption.
“Additionally, these challenges can lead to slower response times for urgent
changes due to extra coordination for licensing procurement and time spent..”
“The challenges with the licensing process come from its complexity..”
“The issues with Check Point Quantum Force (NGFW) are mainly related to
reliability. It depends significantly on the hotfix version of the gateway. You could
end up with a version that's stable or unstable, or for example, stable for one
scenario, but then in certain specific scenarios, it becomes unstable and creates an
issue. This requires contacting support, discussing with R&D, and verifying if there
is a new version or custom fix to install..”
“I find that the licenses are a bit expensive compared to other vendors, and while
the price is justified, at times, renewing them becomes a bit painful, so if it could
become a bit more budget-friendly, that would work for me.
“That licensing issue would be the main area regarding needed improvements..”
The licensing model can be confusing because it includes multiple software blades
and the initial cost is high for smaller organizations. The SmartConsole user
interface sometimes experiences latency which affects user response time and
could benefit from being faster in the future.
“To improve Check Point NGFW, I would suggest that AI features, such as Auto AI
autopilot, would be greatly appreciated because they can automate most of the
tedious tasks that take a lot of time. Having features such as AI can make the
process easier.
“A specific task I'd like to automate with AI in Check Point NGFW is adding
multiple users, users and address group configuration of address groups and
addresses, along with exporting firewall addresses in a certain format. That kind of
feature should be there, or if we try to export the data from the Check Point
firewall, we get only group address group names without seeing whatever
members of the address are included.
“Check Point should provide the feature of exporting group data with address
groups, so when I export address books, only the group name is visible in the Excel
file. Instead, it should show the actual members of the groups getting exported.
That kind of feature would be appreciated..”
Pricing
“I rate the solution's pricing an eight out of ten. It costs around 100,000-200,000
dollars per month. Besides standard licensing fees, we paid extra for enterprise-
level premium support. There were also onboarding costs factored in. These
additional costs made it more expensive overall. The total cost was around 100,000
dollars, which was challenging for our budget. Check Point was also pricey, not
much different from Palo Alto Networks. However, we decided switching to Check
Point was better because it offered more capabilities for a similar price.”
“The tool's price is reasonable in case you are not using it in a high-load
environment.”
“Check Point NGFW is much cheaper than other platforms, including Palo Alto. Its
scalability, especially with the Maestro solution, is a big advantage. If you're
looking for good security at a reasonable price with a good return on investment, I
believe Check Point NGFW is the way to go.”
“The product's price is on the higher side but I also feel that it is more secure than
the other solutions in the market.”
Executive summary
Cisco Secure Firewall stands as a robust and adaptable security solution, catering to
organizations of all sizes. It's designed to shield networks from a diverse array of cyber
threats, such as ransomware, malware, and phishing attacks. Beyond mere protection, it also
offers secure access to corporate resources, beneficial for employees, partners, and
customers alike. One of its key functions includes network segmentation, which serves to
isolate critical assets and minimize the risk of lateral movement within the network.
The benefits of deploying Cisco Secure Firewall are substantial. It significantly reduces the risk
of cyberattacks, thereby enhancing the security posture of an organization. This security also
translates into increased productivity, as secure access means uninterrupted work.
Compliance with industry regulations is another advantage, as secure access and network
segmentation align with many regulatory standards. Additionally, it helps in reducing IT costs
by automating security tasks and simplifying management processes.
In practical scenarios, Cisco Secure Firewall finds diverse applications. It's instrumental in
protecting branch offices from cyberattacks, securing remote access for various stakeholders,
safeguarding cloud workloads, and segmenting networks to isolate sensitive areas.
User reviews from PeerSpot reflect an overall positive experience with the Cisco Secure Firewall. Users appreciate its
ease of configuration, good management capabilities, robust protection, user‐friendly interface, and scalability.
However, some areas for improvement include better integration capabilities with other vendors, maturity, control
over bandwidth for end‐users, and addressing software bugs.
In summary, Cisco Secure Firewall is a comprehensive, versatile, and reliable security solution that effectively meets
the security needs of various organizations. It offers a balance of advanced protection, user‐friendly management,
and scalability, making it a valuable asset in the realm of network security.
Sample customers
There are more than one million Adaptive Security Appliances deployed globally. Top
customers include First American Financial Corp., Genzyme, Frankfurt Airport,
Hansgrohe SE, Rio Olympics, The French Laundry, Rackspace, and City of Tomorrow.
Compared 38% of the time Compared 9% of the time Compared 7% of the time
Learn more Learn more Learn more
Government 10%
Manufacturing Company 9%
University 8%
Manufacturing Company 7%
Educational Organization 6%
Company size
Valuable features
Phil Shiflett
Senior Manager, Network Engineering at TTi Power Equipment
“The features I appreciate the most about Cisco Secure Firewall are the
policies, ACLs, and traffic behavior analytics.”
Ben Kusa
Director, Information Technology at a engineering company with 501‐1,000
employees
Verified user
OT NETWORK MANAGER at a energy/utilities company with 10,001+ employees
“Regarding the zero-trust security model, Cisco Secure Firewall helps our
company. Our students and staff have the ability to do whatever they need to
do with their research. It helps them while keeping security top of mind.”
Corey Keyonnie
It Administration at Dilcon Community School
“Currently, I find the event viewer feature of Cisco Secure Firewall very useful as it
visually displays what is being blocked or allowed by the ACL. I also appreciate the
improved visual presentation of the ACL layout.
Cisco Secure Firewall's ability to unify policies across our environment is pretty
good.
We can deploy different features and ACLs between various firewalls easily with
the FMC, which has improved significantly from the initial deployment time,
which was once poor and is now manageable for multiple firewalls.
We use the new AnyConnect or Secure Connect VPNs, which works pretty well.
Although we haven't switched to the latest series to utilize the VPNs fully, I
appreciate the deployment phase where we can track our deployment progress.
What stands out positively about Cisco is their training and support, which has
effectively prepared engineers to work with their products. When hiring, I find it
beneficial that most network engineers are familiar with Cisco, whereas I might
question the expertise of those trained with Palo Alto or Fortinet.
The interface of Cisco Secure Firewall works effectively once you become familiar
with its layout, although hiring engineers requires training on the platform,
especially as updates occur. They should prioritize adding to the existing product
rather than overcomplicating it with new features that may not be necessary..”
“The features I appreciate the most about Cisco Secure Firewall are the policies,
ACLs, and traffic behavior analytics. These features have benefited my
organization by keeping the environment more secure within the organization.
“The feature of Cisco Secure Firewall that I appreciate the most is the central
management. The central management feature makes it easier to configure once,
push out, and replace firewalls when they go bad. It's nice to have one pane of
view, one pane of glass.
You can quickly run certain commands on CLI or on FMC CLI to find out what could
be the root cause, and it varies from person to person, but it's very useful.
I prefer Cisco since it has been here for a very long time, we have a good
relationship with the sales team and Cisco representatives, and the support is
pretty good, providing us with 24/7 support, which makes me pretty happy.
“The performance part of Cisco Secure Firewall is pretty good. You can control the
bandwidth and features such as bandwidth shaping and quality of service, and I
appreciate that part. At our school, a lot of the kids use laptops, the staff use
laptops, and they have Wi-Fi.
I just tried the chat feature in Cisco Secure Firewall, and that was pretty cool; the AI
worked pretty good when I tried it at home in the evening, so that was a nice
feature.
For our students, we have them in certain groups, and then our staff in certain
groups, so with Cisco Secure Firewall, you can push out policies for each one.
Cisco Secure Firewall is important. You can control what students are looking at,
and if they're looking at something inappropriate, you can control it. You can also
see which device is taking up more bandwidth.
Regarding the zero-trust security model, Cisco Secure Firewall helps our company.
Our students and staff have the ability to do whatever they need to do with their
research. It helps them while keeping security top of mind..”
“Cisco Secure Firewall is easy to configure, and you can do it all in one pane of
glass. It is really simple to configure. The solution allows my junior admins to go
into the dashboard and look at any issues or reconfigure any features that need to
be tweaked without me physically having to be there.
I have been using the assurance feature in Cisco Secure Firewall recently, and I am
starting to see that it is a lot more beneficial for me, with all the analytics and
reporting that it provides.
Cisco Secure Firewall allows us to pinpoint exactly where the packets are being
delivered or dropped, and we are able to identify issues quicker than with other
models or other vendors.
Pain Points
Phil Shiflett
Senior Manager, Network Engineering at TTi Power Equipment
Ben Kusa
Director, Information Technology at a engineering company with 501‐1,000
employees
Verified user
OT NETWORK MANAGER at a energy/utilities company with 10,001+ employees
“I work for a school, so getting licensing and getting the budget for Cisco
Secure Firewall for certain products is a challenge. It's good to have them,
however, it costs us a lot.”
Corey Keyonnie
It Administration at Dilcon Community School
“Cisco Secure Firewall has some growth opportunities in terms of visibility and
control capabilities regarding managing encrypted traffic. It has the ability to
analyze encrypted traffic, and there is potential for more integration with APIs and
AI to enhance these capabilities.
Cisco Secure Firewall needs improvement in deployment time and the capability to
access the CLI during support calls. I often encounter issues when technical
support uses a CLI that is not familiar to me while troubleshooting through the
GUI.
My ongoing complaint for the last six years has been the lack of CLI functionality,
which hinders my ability to work on the firewall, alongside concerns regarding
deployment time.
For the next release, they should look at the features offered by competitors such
as Fortinet, including the ability to perform packet capture directly from the
interface.
If they enhanced their troubleshooting efficiency related to packet capture for each
specific rule, it would simplify the process significantly..”
“I have not recently used any new features or functionalities in Cisco Secure
Firewall, however, I would want to try more visibility and observability. My
impression of the visibility and control capabilities of Cisco Secure Firewall in
managing encrypted traffic is that it can improve. There is some traffic that is
encrypted that needs to be decrypted to catch something and analyze and give
some analytics, so that part needs to work more.
The dashboard needs to be more intuitive and easier to navigate. What stood out to
me about Cisco Secure Firewall that made me choose to use it is that it is intuitive,
but I feel it could be improved further in terms of intuitiveness. It could be
improved to achieve easier configuration and more efficiency..”
The second issue is the ROMmon mode, where during power outages the firewalls
go into ROMmon mode, causing outages and financial loss until we can send
someone on-site..”
Regarding stability and reliability, I have experienced false negative alerts with the
CS models, which indicate that my switch has gone down when in reality, it has
not. That is a fix that is needed..”
Pricing
“The pricing is very good for us, especially since we have a partnership with Cisco.
The challenge is the licensing. There are competitors that offer more flexible
licensing, such as daily licensing, some offer hourly, but Cisco is locked in for one,
three, and five years. We don't have much flexibility, especially if we want to shift
applications or shift users at any time. Hopefully, licensing becomes more
flexible.”
“Licensing with Cisco Secure Firewall isn't too difficult. However, pricing seems
high. We had been using a Meraki solution, and Cisco Secure Firewall seems more
expensive than Meraki, even though Meraki is also cloud-based.”
“Pricing is high.”
Executive summary
Palo Alto Networks NG Firewalls offer comprehensive security, including application control,
traffic shaping, threat prevention, and load balancing, designed to secure internal networks,
perimeter protection, VPN services, and cloud environments.
Palo Alto Networks NG Firewalls are a key choice for managing and protecting data centers,
securing remote access, network segmentation, malware prevention, and ensuring high
availability and performance for business‐critical applications. Known for stability and strong
security, these firewalls use application‐aware identifiers and IPS/IDS subscriptions to offer
advanced threat protection. The unified platform facilitates seamless integration, while
GlobalProtect and centralized management via Panorama enhance ease of use. However,
there are areas for improvement, including pricing strategies, training, user support, and
integration with third‐party applications.
In industries like finance, healthcare, and retail, Palo Alto Networks NG Firewalls secure sensitive data and meet
regulatory requirements. These firewalls help manage large‐scale networks in these sectors, providing essential
security features and maintaining high‐performance standards. They are implemented to ensure compliance, protect
patient information, secure financial transactions, and safeguard customer data.
Sample customers
SkiStar AB, Ada County, Global IT Services PSF, Southern Cross Hospitals, Verge
Compared 14% of the time Compared 12% of the time Compared 11% of the time
Learn more Learn more Learn more
Educational Organization 9%
Manufacturing Company 9%
Manufacturing Company 8%
Government 6%
Company size
Valuable features
Verified user
Founder at a tech services company with 11‐50 employees
“I would rate Palo Alto Networks NG Firewalls a nine out of ten, as it is a very
good and stable solution, and I recommend it over Check Point, Fortinet, and
Cisco; it stands out as the leader.”
IgorPinter
Director at PULSEC
“Overall, I rate Palo Alto Networks NG Firewalls ten out of ten because they
are unmatched in their function.”
OtokarFio
Presales Engineer at Vodafone
“I find all the features valuable, including the segmentation and cloud-
distributed security profiles.”
Verified user
Senior Pre‐Sales Engineer at a tech services company with 1,001‐5,000 employees
Venkatasubramanian Rajagopal
Director IT Infrastructure and Operations at a analyst firm with 51‐200 employees
“My clients use AI technology with Palo Alto for analytics; Palo Alto Networks NG
Firewalls has machine learning integrated into the firewalls that is actively
utilized.
“Palo Alto Networks NG Firewalls have precision AI that can recognize AI traffic,
allowing you to control it within the company by blocking it if you have policies
against employee use.
Palo Alto Networks NG Firewalls is most beneficial for network security as they use
AI and machine learning, which are especially effective against zero-day attacks.
Their AI is adept at identifying potential attacks or unusual traffic. Among the top
three vendors—Fortinet, Check Point, and Palo Alto Networks—I find Palo Alto
Networks to be the most efficient in dealing with zero-day threats due to their
advanced use of AI and machine learning.
“I find all the features valuable, including the segmentation and cloud-distributed
security profiles. The Altice Optice spyware, URL protection, and additional
features are valuable since they prevent breaches and downtime. I can put it in
standby mode and failover to another firewall if needed, which enhances
security..”
“The most valuable feature of Palo Alto Networks NG Firewalls is Cortex Data Lake.
This AI tool leverages data from 70,000 Palo Alto customers, correlating breaches
and intrusion attempts into a back-end engine to analyze zero-day and incoming
threats rapidly. This means if someone was attacked two days ago, I am protected
from that same attack because the information is already in the system. My
subscription to the Cortex Data Lake AI platform applies to my latest Palo Alto
firewall, regardless of the specific model..”
“I find Palo Alto Networks NG Firewalls to be a stable product and very easy to
manage from layer 4 to layer 7. They are also seamless for environments with high
availability. During upgrades, there is a seamless failover to the secondary
firewalls. It is very reliable. I have upgraded these firewalls a lot, and I do not see
any issues or failures on the firewall or the hardware. It also depends on whether
you have a higher-end or a lower-end model, such as the 800 series or the 220
series, which can be very slow, but eventually, it manages to come up.
Pain Points
“The technical support from Palo Alto could be better; I find that it can be
improved. The issues are mainly with response time and quality, as their
first level support used to be better a couple of years ago, but now you
sometimes get support that isn't as good.”
IgorPinter
Director at PULSEC
OtokarFio
Presales Engineer at Vodafone
“These are not the cheapest firewalls; they are quite expensive.”
Verified user
Senior Pre‐Sales Engineer at a tech services company with 1,001‐5,000 employees
Venkatasubramanian Rajagopal
Director IT Infrastructure and Operations at a analyst firm with 51‐200 employees
Mihilesh Kumar
Specialists ‐ IT Operations Services at Coforge Growth Agency
“The only room for improvement I see for Palo Alto Networks NG Firewalls is with
their pricing; it could be more flexible for clients.
“It could be cheaper because Fortinet is very aggressive with their pricing, but the
functionalities of Palo Alto are really good.
“The technical support from Palo Alto could be better; I find that it can be
improved.
“The issues are mainly with response time and quality, as their first level support
used to be better a couple of years ago, but now you sometimes get support that
isn't as good..”
It is a bit complex to understand the flows and how the securities are applied to
each of those flows. It was a little bit challenging because we had to go to two
different sections to figure that out. It would be helpful if it is all unified so that we
can see the way the firewall connections and security are set up and the
applications that are using those connections. It could be structured differently so
that it is more understandable. It has been a while, but it was a bit of a complex
way. We had to hop from one area to the other and go back and forth to figure out
how a specific connection and application was set up..”
“Palo Alto Networks NG Firewalls offer best-in-breed security but could improve
by reducing their pricing. Their current premium pricing strategy limits
accessibility for many customers. A more competitive pricing model would enable
a wider range of organizations to benefit from their advanced security features..”
“When the primary Palo Alto Networks firewall fails over to the secondary, it
requires manual intervention to bounce the IPsec for it to work properly. Unlike
BGP peering, which automatically changes from idle to established, this process
needs automation. In Cisco, there is no need to bounce the IPsec traffic during
failover, and I suggest automation for Palo Alto Networks in that process..”
Pricing
“Palo Alto Networks offers more cost efficiency compared to Cisco, with better
operational and maintenance ease.”
“Palo Alto Networks NG Firewalls have a higher price tag, costing roughly twice as
much as competing products.”
“Its price is quite high but is justified for the features and capabilities provided,
although I would prefer a lower price.”
Executive summary
Check Point CloudGuard Network Security offers centralized management, robust threat
prevention, and seamless integration with major public clouds, ensuring consistent security
for cloud and on‐premises environments. It combines ease of use with flexibility across
diverse IT infrastructure.
What are the key features of Check Point CloudGuard Network Security?
• Ease of Setup and Use: Provides a user‐friendly setup process and intuitive operation.
• Robust Threat Prevention: Offers advanced capabilities to safeguard against potential
threats.
• Auto‐Scaling: Adjusts resources dynamically to meet demand without manual
intervention.
• Centralized Management: Ensures uniform security policies across cloud and on‐
premises environments.
• Integration with Major Public Clouds: Seamlessly works with AWS, Azure, and other
leading platforms.
• Intuitive ACL Menu: Simplifies access control list management with an easy‐to‐navigate
interface.
• Customizable Policy Options: Allows for personalized security settings suited to specific
requirements.
What benefits should companies look for in Check Point CloudGuard Network Security?
Improved Threat Detection: Increases the ability to identify and respond to threats quickly.
Scalability: Easily adapts to growing or changing infrastructure needs without compromising
security.
In industries such as finance, healthcare, and tech, Check Point CloudGuard Network Security
is vital for protecting sensitive data, managing compliance, and safeguarding daily operations.
Its robust integration capabilities support diverse infrastructure setups, assisting companies in
maintaining high‐security standards efficiently.
Sample customers
Physicians Choice Laboratory Services, Helvetica Insurance
Compared 14% of the time Compared 12% of the time Compared 10% of the time
Learn more Learn more Learn more
Security Firm 7%
Performing Arts 7%
Manufacturing Company 6%
Company size
Valuable features
“The few times I needed customer service, I was very happy with it.”
Sam Deprettere
Cloud Infrastructure Engineer at delaware BeLux
Krunal Jagdish
Senior consultant at a consultancy with 10,001+ employees
“Check Point helped me a lot to know that I have a solution that is stable and
answers my needs.”
Meir Carmel
Chief Business Officer at a consultancy with 11‐50 employees
James Arscott
Consultant at a tech services company with 51‐200 employees
Martin Raška
Senior Security Engineer & Instructor at Arrow Electronics
“There is not one feature in particular that stands out, it's just a very good product
that we are very fond of.
It is really easy to work with and has an easy learning curve. It integrates with
Azure without any problems.
It provides a huge benefit in many ways, offering a boost in confidence for secure
cloud deployment and migration.
We don't have any complaints with the solution terms of finding threats.
We have very good confidence in secure cloud management and migration. We're
very used to the product.
We have a direct line with the engineers of Check Point, which is very
important. .”
• database inspection
• threat prevention
• enhanced security.
It does what it’s supposed to do. I would say that it created a reduction of 25% in
organizational risk.
.”
“The protection is at a very good level. There's a very high catch rate. It has good
flexibility in operating and implementing the system.
It is easy to implement, and it has a lot of flexibility compared to other systems you
have in the organization. In the end, this is a parameter that, in my eyes, is very
central.
In the end, it saves time. It's all in one place and you can quickly see how you're
doing with the cloud environment. It just makes things easier and helps on a daily
basis because it optimizes the understanding of what we have.
Instead of logging into the system by yourself and starting to check, there's
another management system that sees logs. It examines the data daily, and it
creates flexibility regarding what we want to investigate. It is much easier for
everything to be in the same management and not scattered in all sorts of different
places.
Check Point helped me a lot to know that I have a solution that is stable and
answers my needs. It really gave me the confidence to move forward with the
whole migration to the cloud. It was very helpful.
When I moved to the cloud, I looked at Check Point's solution and as soon as it
suited me, I bought it. We chose CheckPoint right away, it was our go-to choice.
.”
I think it is secure and user-friendly. The interface is easy to understand and the
Check Point CloudGuard Network Security history assures me of its
trustworthiness.
“The overall network security is good. It's big-picture, all in one bundle. It's
valuable to have everything in one place instead of spreading across different
products.
It's easy to use. The management is the best on the market. It's very easy to work
with, read, understand, and navigate.
It helps increase our customer's security posture. We can see in some cases
CloudGuard improves our customers' posture overall. .”
“The most valuable feature is the automation and the APIs, making our life much
easier for integration. Check Point has excellent, very useful tools to help us with
the poster and to see if we're passing the grade.
It gives us more confidence in secure cloud deployments. The network security was
very easy to migrate. We did it with Terraform. I just filled in the blanks and
Terraform did everything else.
Check Point CloudGuard NetWork Security provides unified security across hybrid
clouds as well as on-prem. It's more or less the same across deployments.
Check Point helps companies with their security posture. It has useful tools to help
with this aspect to improve security. .”
Pain Points
Sam Deprettere
Cloud Infrastructure Engineer at delaware BeLux
Krunal Jagdish
Senior consultant at a consultancy with 10,001+ employees
“Pricing in Jamaica is a major issue, with users often citing it as a reason for
not using Check Point.”
James Arscott
Consultant at a tech services company with 51‐200 employees
Martin Raška
Senior Security Engineer & Instructor at Arrow Electronics
Dimitris Baziotopoulos
Network security engineer at a tech services company with 201‐500 employees
“I do not have any specific improvements in mind for the tool. It is a solution that
is what we need at the moment. There could always be something to enhance
deployment, however, for now, it is quite adequate.
We generally used everything on-premise, but now it's all in the cloud through
CloudGuard. The transition was a bit challenging. Maybe they could improve their
services by including more tutorials and labs on migration..”
“From my point of view and my needs, I don't see room for improvement. In my
opinion, the more it has support for more environments and the more integration
there is with wider areas, not only in Check Point's systems, but also with other
systems, then I think it will allow access to more customers which is not
specifically my case, but in principle the wider the system, the more it will be able
to appeal to a larger audience; integration with other manufacturers in other
words..”
“It should be more unified across all platforms. There are different kinds
of releases for private cloud, public cloud (HA), NSX, and VSX. It is a little bit
different on every platform where I install it, and each platform has many
limitations like SMB or Maestro. So I need to know that and decide on which
platform I should install it on..”
The deployments can be difficult if a person doesn't know what they are doing.
Pricing
“As a partner and solution provider for the last fifteen years, I have distanced
myself from specific numbers. However, customer trust in the product is evident
due to its comprehensive protective capabilities.”
“I do not have too much to compare to, but if I compare it with Azure Firewall,
Scale Set is quite good. It has quite a good price.”
“Generally, it has been fine for me. I can find my way around the price list, and it is
pretty simple.”
Let the community know what you think. Share your opinions now!
Ariel Lindenfeld
VP Product at PeerSpot
Security, aye, it is most important. But I would like to add the aspect of
"self‐sufficiency" for want of a better word. What I mean by this is,
that a firewall has to be the "last man standing" of sorts if a network is
under attack or already compromised. So a firewall in my opinion
should never be dependent on other components, be it on premises or
in the cloud. I have come across installations where firewalls are
integrated with Microsoft AD for user authentication or where they
were configured to accept input from cloud services as to how their
policy should be enforced. Call me oldfashioned, but for me a firewall
still hast to work even if all other services in the network are dead and
it still has to provide security controls to the last interface alive on the
net. We should very much mistrust all that new "AI" stuff and accept it
only as "on top" of a good old static policy of who may access what ‐
down to every single IP and port.
WiseCat
Enterprise Architect, CISSP at a tech services company with 1,001‐5,000 employees
There are already some good answers about it but this is what I
understand for a firewall. It is a luxury when compared in a networking
domain. So basics first, we would need to suit your networking
requirement. For this you need to settle down for Vendor whom you
need to buy this firewall. From an organization level, Try to get a best
deal. Now from networking perspective, take that spec sheet out and
look for the models they offer and see which one fits your network. I
mean check the throughput of the firewall. Can it handle the load you
are going to push it through ? Ok so you got your vendor and the
model but wait let's see that spec sheet again. Why? The features. Yes
the features are also important as everyone already pointed it out. You
need to compare the feature and see if it meets your organization
policy. Most of the firewalls have all that is required for an
organization. This includes but not limited to deployment mode, high
availability, application visibility, custom application definition, central
management (required if you have more than one firewall to
standardize your policy), Throughput post going through IPS / URLF,
SSL VPN capability (I don't want to spend more to get this new extra
feature right), IPSEC VPN, and others. The core of deploying the
firewall is the throughput. I don't know how to emphasize more on
that. Once you get this checklist complete. I believe you are good to
purchase a firewall for your organization. I would request people to try
these firewalls on the VM instance for demo and see how they
function. Check with your vendor for demo. This is to ensure that your
IT engineer is comfortable with the look and feel as he is the one going
to handle your firewall right ? All the best ! on getting a new firewall.
Girish Vyas
Architect ‐ Cloud Serviced at a computer software company with 501‐1,000
employees
Awesome answers all around! The most important aspect to look for is
relative to one question: How informed are you with the actual needs
of your network? Overall I think there are too many specific details to
choose any one primary aspect when selecting a security appliance
and/or firewall device based on functionality alone. Any company that
is online and running with proven technology has offered a solution
that meets the minimum standard for most situations and customers.
However some do perform better than others in certain environments
and this depends on the needs of the network and resources. Firewalls
fulfill one general role in the network: the protection of key resources.
This can be expanded upon in a number of ways but the idea is the
same all the time; the protection of key resources and the inspection of
traffic in and out of these resources. That being the case, it would
require in depth research based on specific needs and see how that
relates to the network in question when selecting a device. The one
aspect that will always matter regardless of the device capability is
Integration and Administration. Although customer support from the
vendor is extremely important, the first line of response will always be
the in‐house technical resource. ‐ How easily can I role this out? ‐ Am I
replacing a pre‐existing device or adding this in tandem? ‐ Do I have
people who can manage this device currently and if not, can they be
trained easily? ‐ If I have a single admin/engineer who manages this
device and they leave the company, how easy is it to find another
qualified person? I think these aspects and questions matter a great
deal. Regardless of specific strengths for a single device, if that device
cannot be installed easily or managed easily, that equals more
confusion and downtime which usually means a loss of money. When
considering a new firewall device or security appliance, I encourage my
clients to review their short and long term goals before allowing too
much time in debate over which device is better.
it_user339975
Project Consultant at a tech consulting company
Abdul Azim
Network Security Engineer at IIPL
Raj Metkar
Director, Head of Networks at MUFG, EMEA
Bijo Abraham
Technical Consultant | Network and Security at Interconnect Consulting Limited
Vendor Directory
Cisco Meraki MX
Fortinet FortiGate‐VM
Fortinet FortiOS
GFI KerioControl
Hillstone T‐Series
Hillstone CloudEdge
Hillstone A‐Series
Juniper vSRX
MegazoneCloud AXGATE
OPNsense OPNsense
SonicWall SonicWall TZ
SonicWall NSa
SonicWall NSSP
SonicWall NSv
Sophos Sophos XG
Sophos XGS
WiJungle WiJungle
The summaries, overviews and recaps in this report are all based on real user feedback and
reviews collected by PeerSpot’s team. Every reviewer on PeerSpot has been authenticated
with our triple authentication process. This is done to ensure that every review provided is an
unbiased review from a real user.
The customized report will include recommendations for you based on what other people like
you are using and researching.
Answer a few questions in our short wizard to get your customized report.
Get your personalized report here
About PeerSpot
PeerSpot is the leading review site for software running on AWS and other platforms. We
created PeerSpot to provide a trusted platform to share information about software,
applications, and services. Since 2012, over 22 million people have used PeerSpot to choose
the right software for their business.
PeerSpot
244 5th Avenue, Suite R‐230 • New York, NY 10001
reports@[Link]
+1 646.328.1944