Support at a security firm with 51-200 employees
User
Top 5Leaderboard
Great for blocking threats, including malware, viruses, and zero-day attacks
Pros and Cons
  • "Its integration and use of features, such as advanced threat prevention, have helped us a lot with malware prevention and also with avoiding exposure to false positives."
  • "The costs are high."

What is our primary use case?

This feature is integrated into the security solution of Check Point, and its CloudGuard flagship product is very valuable to our company. It has helped us to make posture, recommendations, and security improvements to the network of our Azure public cloud. We have been able to improve our current implementations and future deployments of networks in our infrastructure in the best way, making assessments that provide us with improvements that include building a more secure environment.

How has it helped my organization?

This tool managed to help us improve our security from deployment to reconfiguration of networks - both in our Azure public cloud and on-premise networks, thanks to its improvement reports.

Its integration and use of features, such as advanced threat prevention, have helped us a lot with malware prevention and also with avoiding exposure to false positives.

The best practices that this product has at the network level are incredible. We have improved a lot so far, and now we have a more secure and complete infrastructure.

What is most valuable?

CloudGuard Network Security provides advanced threat prevention capabilities that can detect and block known and unknown threats, including malware, viruses, and zero-day attacks. This helps a lot for companies that have their infrastructure both on-premise and in Azure.

CloudGuard Network Security includes application control features that allow administrators to control which applications can access the network and how they can be used.

The automation of Check Point CloudGuard Network Security is incredible. It helps us to deploy implementations with good practices in the network; this is a great value add to the tool.

What needs improvement?

It would be very good if the company could expand the current public documentation in order to improve the implementation of the solution, and initial configurations, among other items. It would help us be able to implement it in the fastest and safest way possible.

The costs are high. They could revalue them by lowering them a bit and making them more attractive to many customers, and likely they would be able to sell more.

It would also be good to validate the Check Point Infinity Portal. Sometimes it sticks a bit or responds a little slowly.

Buyer's Guide
Check Point CloudGuard Network Security
June 2024
Learn what your peers think about Check Point CloudGuard Network Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2024.
772,679 professionals have used our research since 2012.

For how long have I used the solution?

The solution was used during the last year. It is a feature integrated with the Check Point CloudGuard tool.

Which solution did I use previously and why did I switch?

It's a very comprehensive solution. However, we have not found any other solution that generates the same level of security as Check Point.

What's my experience with pricing, setup cost, and licensing?

The costs seem high. However, the product is also incredible. It provides great value.

Which other solutions did I evaluate?

We value tools such as Defender for cloud, among others, however, this solution is the most complete, and we trust Check Point.

What other advice do I have?

I recommend doing a little research before purchasing the product.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Network and Security Engineer at a consultancy with 11-50 employees
Real User
Top 20
Makes security operations faster and error-free
Pros and Cons
  • "The product offers an easy and nice way to manage the gateways, similar to on-prem hardware. It has packet filtering features. Our security operations are faster and less prone to errors. We selected CloudGuard Network Security due to its visibility."
  • "The solution needs to improve the interruptions that happen during gateway upgrades."

What is our primary use case?

We use the product for network security and cloud workload protection. 

How has it helped my organization?

It's easy to set up in Azure Cloud. The ease of setup helps us save time.

What is most valuable?

It offers an easy and nice way to manage the gateways, similar to on-prem hardware. It has packet filtering features. Our security operations are faster and less prone to errors. We selected CloudGuard Network Security due to its visibility. 

CloudGuard Network Security more or less provides us with unified security management across hybrid-clouds as well as on-prem. We manage both environments on the same console. It makes our security operations faster and less prone to error. 

What needs improvement?

The solution needs to improve the interruptions that happen during gateway upgrades. 

For how long have I used the solution?

I have been using the product for two years. 

What do I think about the stability of the solution?

There were no major stability issues, although switching gateways could cause some downtime, approximately a minute until the new gateway is fully deployed.

What do I think about the scalability of the solution?

CloudGuard Network Security's scalability is good. 

How are customer service and support?

The tool's support is good. Their responses can get delayed due to time zone differences. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have only used the built-in solutions from Azure. 

CloudGuard is easier to understand. CloudGuard is very easy to translate and easy to incorporate features. CloudGuard has better features like packet filters, EPS, threat prevention, and filtering.

We chose CloudGuard because of the visibility. It's much better.

How was the initial setup?

The setup process saves us time, especially in the Azure cloud, as the system continually improves.

What was our ROI?

We have seen ROI through its visibility and through understanding attacks on the workloads.

What other advice do I have?

For us, the solution was easy to understand. The syncing of the CloudGuard Network Security is like that of the gateway on-prem. Translating in a very easy path to bring the features is very easy. I rate the product a nine out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Buyer's Guide
Check Point CloudGuard Network Security
June 2024
Learn what your peers think about Check Point CloudGuard Network Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2024.
772,679 professionals have used our research since 2012.
Cloud engineer at a energy/utilities company with 5,001-10,000 employees
Real User
Comes with IPS and blade features
Pros and Cons
  • "The tool's most valuable features are IPS and blades. These features are valuable for security."
  • "CloudGuard Network Security's pricing is expensive. We have encountered issues with its licensing."

What is our primary use case?


What is most valuable?

The tool's most valuable features are IPS and blades. These features are valuable for security. 

What needs improvement?

CloudGuard Network Security's pricing is expensive. We have encountered issues with its licensing. 

For how long have I used the solution?

I have been using the product for six years. 

What do I think about the stability of the solution?

CloudGuard Network Security's stability is good. 

What do I think about the scalability of the solution?

In terms of scalability in the cloud, manual deployment is straightforward. However, the challenge arises due to the pay-as-you-go model. The issue of buying licenses is not specific to the Check Point but is more related to our ordering process.

How are customer service and support?

The tool's support is good. 

How would you rate customer service and support?

Positive

What about the implementation team?

Check Point helped us with the deployment. 

What other advice do I have?

CloudGuard Network Security is an efficient solution. I rate it an eight out of ten. 

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
AlexOgbalu - PeerSpot reviewer
Director at LiveFromSpace Limited
Reseller
Top 10
Helps us with basic cloud network security, posture management and threat hunting
Pros and Cons
  • "The solution is reliable."
  • "The user interface can be improved."

What is our primary use case?

Our primary use case for this solution is for basic cloud network security, posture management and threat hunting. The solution is deployed on cloud.

How has it helped my organization?

The solution assures protection on cloud and ensures the workload is protected in the same manner when deployed on-premises.

What is most valuable?

The threat prevention capabilities are very valuable.

What needs improvement?

The product's support team, the UI, and the user interface can be improved.

For how long have I used the solution?

We have been using this solution for four years.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

The solution is scalable. However, we have not needed to scale yet.

How are customer service and support?

Our experience with technical support can be improved in terms of response time.

How was the initial setup?

The initial setup was straightforward. Some processes were easy click-through processes which needed some configurations and technical expertise to set up. Hence, some technical expertise is required.

What's my experience with pricing, setup cost, and licensing?

The solution is reasonably priced in comparison with other products.

What other advice do I have?

I rate the solution seven out of ten. The solution is reliable and would fulfil what it is marketed to achieve. It provides very good security protection, but the customer support response times could be improved.

Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
PeerSpot user
Senior Manager at a financial services firm with 10,001+ employees
Real User
Provides consolidated visibility and management, but the HA failover time is slow and the documentation needs to be improved
Pros and Cons
  • "SSL/TLS traffic inspection features are used for advanced threat prevention against secure SSL traffic."
  • "Micro-Segmentation functionality for EAST-WEST traffic is not native and requires integration with a third-party OEM."

What is our primary use case?

As we are moving our workloads to the cloud, it means that we now have a need to protect our cloud infrastructure. This will ensure that our business is deploying products faster and with all of the required security.

Our solution needs to be able to protect workloads hosted on multiple clouds with the required security control. The license should be a subscription-based model so that we can add or remove depending upon the requirement to scale.

It needs to support a microservice platform such as Docker or another container, and it should be quick to deploy.

How has it helped my organization?

This solution gives us advanced threat prevention to protect our workloads from attacks including zero-day and other types of attacks.

It is able to provide cloud network security along with orchestration and automation. It also provides consolidated, consistent visibility and management across all clouds including public, private, and hybrid environments.

This product is quick to deploy, scalable, and is a fully functional firewall available in the cloud. We were able to scale as required based on load and performance. With Covid-19, our users, including our Customer Center agents, are completely remote and rely on Check Point Cloud Guard to provide flexibility and seamless access. 

We have the ability to easily encrypt/decrypt traffic according to the security policy, as well as integrate between Active Directory, Cloud Guard Azure objects & application control.

It provides micro-segmentation functionality through complete visibility and control of traffic following between EAST-WEST and North-SOUTH with VPC and Outside VPC.

What is most valuable?

We are using multiple security features including the firewall, DLP, IPS, application control, IPsec VPN, Antivirus, and Anti-Bot. SandBlast provides Threat Extraction and Threat Emulation for zero-day attacks.

SSL/TLS traffic inspection features are used for advanced threat prevention against secure SSL traffic.

Unified Security Management provides security policy management, enforcement, and reporting for public, private, hybrid-clouds, and on-premises networks in a single-pane-of-glass.

Seamless cloud-native integration with Azure, AWS, GCP, Oracle Cloud, and more.

What needs improvement?

System hardening could be improved, as password complexity is not enforced by default on root / command-line passwords.

The documentation provided by Check Point can be rough and needs to have a lot more detail incorporated in order to help the implementor and administrator.

The HA failover time is not as fast as expected and due to this, the convergence time between cluster members is still not perfect. Consequently, there may be an issue in migrating the mission-critical business applications. 

Micro-Segmentation functionality for EAST-WEST traffic is not native and requires integration with a third-party OEM.

For how long have I used the solution?

We are performing a PoC with the product. 

What do I think about the scalability of the solution?

As with other Check Point products, this solution is scalable.

How are customer service and technical support?

Support from OEM is excellent.

Which solution did I use previously and why did I switch?

We have a different solution that works in silos and we are doing this PoC to check the functionality/features.

How was the initial setup?

Integration and setting up the solution are straightforward.

What about the implementation team?

We are performing our PoC with assistance from the OEM.

What's my experience with pricing, setup cost, and licensing?

The cost is on the higher side, as it is based on workload, hence we need to decide which VPC or workload needs to be part of CloudGuard.

Which other solutions did I evaluate?

We did not evaluate other options.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior System Engineer at a energy/utilities company with 201-500 employees
Real User
Secures our assets in the cloud while providing access to applications in our vendor hosted data centers via IPSEC tunnels
Pros and Cons
  • "We have found the overall functionality of the product to be exactly similar to the physical product. The one good advantage is that it is cloud-based and can be deployed either as a part of a scale set or one can shut down the virtual machine and adjust the physical parameters of the virtual machine easily and bring it right back up."
  • "I think they have pretty much mastered what can be done. There are some nuances like when you fail over from one cluster member to the other, the external IP address takes about two minutes to fail over."

What is our primary use case?

It secures our assets in the cloud while providing access to applications in our vendor hosted data centers via IPSEC tunnels. We also use it for endpoint vpn for all our users. We have it deployed in our cloud and it forms the gateway for all external connectivity and access to the assets in the cloud. We also have a backup site to site connection with our on premise data center so in case the primary connection to the cloud fails we can quick fail over to this backup connection and business can continue as normal .

How has it helped my organization?

We have it deployed in our cloud and it forms the gateway for all external connectivity and access to the assets in the cloud. CloudGuard IaaS has given us the complete redundancy that we have been designing and planning for over 2 years. CloudGuard provided the Gas South remote users with an alternate and secure connection into our completed IT infrastructure so that our remote users can log into CloudGuard end-user VPN over a secure and encrypted method and work as normal. This has come in very handy during this COVID-19 times.

What is most valuable?

We have found the overall functionality of the product to be exactly similar to the physical product. The one good advantage is that it is cloud-based and can be deployed either as a part of a scale set or one can shut down the virtual machine and adjust the physical parameters of the virtual machine easily and bring it right back up. Also if deployed as a cluster this can be done without any downtime at all since you can take down one virtual machine at a time to upgrade. Overall a very well designed product

What needs improvement?

I think they have pretty much mastered what can be done. There are some nuances like when you fail over from one cluster member to the other, the external IP address takes about two minutes to fail over. During this time there is an outage of service. On digging into this further I found that this is more on the cloud fabric and provider side than the actual Checkpoint CloudGuard side. The Cloud provider is taking that long to actually detach the Virtual IP Address (VIP) from one machine and fail it over to the other

For how long have I used the solution?

Almost two years.

Which solution did I use previously and why did I switch?

We have always been a Check Point customer.

What's my experience with pricing, setup cost, and licensing?

If you are a Microsoft Azure customer the setup is very simple. There is already a great template there ready for deployment. Read the deployment guide fully before attempting it. Licensing is built into the deployment but you will get billed separately as a market place deployment and does not get charged to your subscription. This is a bit frustrating but they are working on fixing this

Which other solutions did I evaluate?

We did look at bring in other alternate vendors before settling on CloudGuard. We did a POC of Fortinet.

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Umair Siddiqi - PeerSpot reviewer
Network Security Specialist at a government with 1,001-5,000 employees
Real User
Top 20
All-in-one-box solution with easy configuration and great routing
Pros and Cons
  • "As per the solution's blade design, there are many options. For example, you have to buy a UTM blade and an advanced malware blade, etc. If the blade license is there, we can configure from the firewall GUI."
  • "If you compare the GUI with the Palo Alto and Forcepoint in the Cisco, they're very easy. Check Point, due to its design, is a little bit complex. They should make the GUI easy to use so that anyone can understand it easily, like Fortinet's GUI. Many companies end up using Fortinet because the GUI is very easy, and there's no need for training. They just deploy the box and do the configuration."

What is most valuable?

As per the solution's blade design, there are many options. For example, you have to buy a UTM blade and an advanced malware blade, etc. If the blade license is there, we can configure from the firewall GUI. 

The net policy and routing are also great features.

What needs improvement?

If you compare the GUI with the Palo Alto and Cisco, they're very easy. Check Point, due to its design, is a little bit complex. They should make the GUI easy to use so that anyone can understand it, like Fortinet's GUI. Many companies end up using Fortinet because the GUI is very easy, and there's no need for training. They just deploy the box and do the configuration.

Also, we have to inform customers that with Check Point there's no need to purchase any routing device. Check Point can do that routing as well as the Firewall and the IPS. The marketing should be stronger, to show that customers only need one box to handle all the features. It will be cost-effective and enhance the performance and value, but because of their poor marketing, customers don't realize this.

In the future, a color string would be powerful. Sandboxing should also be offered. Many people want the Trend Sandbox but not on the cloud. In the Middle East, there is a policy for Sandboxing that states it should be on Trend as per the government law. They have Sandboxing solutions on the cloud, but they have to bring the solution onto Trend also. Palo Alto has Wildfire, Cisco has Talos, and Forcepoint has one available as well.

In the future, routing protocols should be more supported like OSPF and BGP. There needs to be integration with the SDN. I don't know if SDN is there or not in Check Point, but SDN is one of the major requirements nowadays.

For how long have I used the solution?

I've been using the solution for one month.

What do I think about the stability of the solution?

The solution is very stable.

What do I think about the scalability of the solution?

We just deployed the solution, so scalability I cannot speak to right now. But, as per Gartner and NSS Lab, they're allegedly very good. I don't think there will be an issue with scalability.

Which solution did I use previously and why did I switch?

I am currently also working on Cisco ASA, Fortinet, and Palo Alto.

What about the implementation team?

I'm an Operation Engineer; I handle the deployments myself. 

What's my experience with pricing, setup cost, and licensing?

Compared to Cisco Firepower Threat Defense, the solution is cheap. However, not as cheap as Fortinet or Palo Alto. If clients have smaller budgets, we would have to advise one of those instead.

What other advice do I have?

There are two deployment model modes in Check Point. One is a gateway level and one is a no gateway all-in-one box solution. With the gateway level, only hardware will be there, all operating systems are stored in a VMware and if there are any issues in the hardware, you just replace the box; all of your policies will be saved into VMware.

The all-in-one box you have the GUI policies and also the gateway so it's secure. If there is an issue in the box - like failure or downtime - all of the networks will be affected.

I would rate the solution eight out of ten. We haven't been using it too long, so we haven't had a chance to look at all aspects of the solution. I would recommend Check Point to customers because it is an affordable option.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Achim Buettner - PeerSpot reviewer
Solution Architect at BNC Business Network Communications AG
Real User
Top 10
Protects the file server on the cloud and comes with threat prevention features
Pros and Cons
  • "The tool's most valuable features are threat prevention and protection mechanisms."
  • "The connection to the on-premises management requires using the CLI. It's not just a click, and you cannot edit in the management to prepare everything. You need to do it online and in real time. After that, you must execute a script, and then you should be happy that it appears in the management."

What is our primary use case?

Our use case for the product is to prevent or protect the file server in the Cloud. The plan is to gradually integrate more solutions behind it. We work with Azure and AWS. 

What is most valuable?

The tool's most valuable features are threat prevention and protection mechanisms. 

What needs improvement?

The connection to the on-premises management requires using the CLI. It's not just a click, and you cannot edit in the management to prepare everything. You need to do it online and in real time. After that, you must execute a script, and then you should be happy that it appears in the management.

For how long have I used the solution?

I have been using the product for five years. 

What do I think about the stability of the solution?

CloudGuard Network Security is stable. I haven't encountered any issues with its stability. 

What do I think about the scalability of the solution?

The tool is scalable. 

Which solution did I use previously and why did I switch?

Choosing between Palo Alto and Check Point is more of a personal preference based on the management you prefer. However, in terms of protection, both provide a comparable level of security, making you feel equally safe. The choice between Palo Alto and Check Point often depends on the customer. If a customer is already using Palo Alto, it might be challenging to convince them to switch to Check Point. 

How was the initial setup?

Deploying the product on different cloud platforms, like Azure or AWS, poses challenges due to variations in terminology and identification methods among platforms.

What's my experience with pricing, setup cost, and licensing?

CloudGuard Network Security's pricing is fine. 

What other advice do I have?

In most cases, we use the smart management on-premises. With the hybrid solution, we have one log visibility of every single management, which is an advantageous concept. I rate it an eight out of ten. 

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Flag as inappropriate
PeerSpot user
Buyer's Guide
Download our free Check Point CloudGuard Network Security Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2024
Buyer's Guide
Download our free Check Point CloudGuard Network Security Report and get advice and tips from experienced pros sharing their opinions.