IT Operation Manager at a transportation company with 1,001-5,000 employees
Real User
Good management functionality using a single pane of glass
Pros and Cons
  • "The scalability is very good."
  • "The user interface for management could be improved."

What is our primary use case?

We primarily use this solution for routing and the protection of our internal corporate network.

What is most valuable?

The most valuable feature is the management using the Single Pane of Glass.

What needs improvement?

The user interface for management could be improved.

In the future, I would like to see support for SD-WAN capabilities.

For how long have I used the solution?

I have been working with the Check Point Next-Generation firewall for four years.

Buyer's Guide
Check Point NGFW
May 2024
Learn what your peers think about Check Point NGFW. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
771,212 professionals have used our research since 2012.

What do I think about the stability of the solution?

I would like to see better stability in newly-released versions.

What do I think about the scalability of the solution?

The scalability is very good.

How are customer service and support?

Dealing with the support team in Israel can be a struggle because of the difference in working hours, holidays, and priorities.

Which solution did I use previously and why did I switch?

I would with firewall solutions from several vendors including Palo Alto, Fortinet, and Meraki.

What other advice do I have?

My advice for anybody who is implementing this solution is to ensure that they have good support from local experts. The biggest lesson that I have learned from using this product has to do with the capabilities of the smallest models. Care should be taken to select the appropriate one for your environment.

I would rate this solution an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1281831 - PeerSpot reviewer
Security and Network Engineer at a tech services company with 501-1,000 employees
Real User
User-friendly configuration, good support, and trouble-free upgrades have made our jobs easier
Pros and Cons
  • "The rules are very easy to deploy and can be optimized pretty quickly."
  • "One of the main features that need improvement is the rule filter export."

What is our primary use case?

The Check Point NGFW is the best product that I have ever used. It has pluses and minuses, as do others, but the usability, simplicity, and the configuration abilities are very user-friendly. After a while, other vendors just don’t come close to it.

The second thing is that is just works and it does it with ease. The upgrades and bug fixes are frequent and well documented. Also, the patches just work ;-)

There are some negatives but as I already said, they aren’t many and from my point of view, we can see past them.

How has it helped my organization?

It has made our lives and working in the company a lot easier. We have a better overview of the logs and what happens with the traffic in our company. Which means that the search for the certain logs is easy, quick and smooth. The overview of the logs is also very good as it is very detailed. The installation is allot quicker as it was before what also helps us with the implementation of the firewall rules. The rule consolidation is also very important as we have more than 60 fw rule change requests per day.

What is most valuable?

The rules are very easy to deploy and can be optimized pretty quickly. The R80 has a great feature on how the rules are processed, which costs less in terms of CPU and threads than it did before.

The features that are integrated into the firewall are very useful for our everyday use. Examples of these are the log manager, the firewall monitor commands, and the Linux commands. These are all very useful and helpful.

The VPN tunnels are easy to set up once you understand how they have to be configured.

What needs improvement?

One of the main features that need improvement is the rule filter export. All of the other vendors can export the filtered IPS as a PDF or CSV file, but with the smart dashboard, it’s just not possible. One can only export the whole rule base and then search for the IPS, which is super time-consuming as you can’t send the whole rule base to a customer. You would get weird questions about certain rules, why they are deployed or configured as they are, and maybe even get unwanted tips on how to change them.

For how long have I used the solution?

We have been using Check Point NGFW for eight years.

What do I think about the stability of the solution?

In terms of stability, this solution is very good.

What do I think about the scalability of the solution?

The scalability is high.

How are customer service and technical support?

The technical support is very good.

Which solution did I use previously and why did I switch?

We did not use another solution prior to this one.

How was the initial setup?

The initial setup is very easy.

What about the implementation team?

I implemented and deployed Check Point NGFW alone.

What's my experience with pricing, setup cost, and licensing?

Maybe the pricing is a bit high but you get the durability and the duration.

Which other solutions did I evaluate?

We evaluated Palo Alto and Cisco ASA.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Check Point NGFW
May 2024
Learn what your peers think about Check Point NGFW. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
771,212 professionals have used our research since 2012.
General Manager at Qhawariy
Real User
Stable and scalable with an easy setup and configuration
Pros and Cons
  • "The initial setup is easy."
  • "The interface could be better."

What is our primary use case?

We are using the new version of Check Point NGFW. 

We use the solution for web page protection to provide the security service which is lacking in Bolivia, a poverty ridden country. 

What is most valuable?

I like the facility of the product configuration. The ease with which the solution can be put into production makes it easy for my employers and for me to provide client support. 

What needs improvement?

The interface could be better. There is much equipment that is involved in the monitoring of many clients in a single interface. 

With other platforms, such as WatchGuard, it is very simple to manage four, five or six of these. We are talking about a lot of clients. The platforms for doing monitoring should be addressed. 

What do I think about the stability of the solution?

The solution boasts good stability. 

What do I think about the scalability of the solution?

The solution boasts good scalability. 

How are customer service and support?

I have not had need to make use of technical support. 

How was the initial setup?

The initial setup is easy. 

What about the implementation team?

When it comes to the deployment and maintenance, there are two people involved, one for the deployment and the other for monitoring, consisting of an engineer and a technician. 

What other advice do I have?

I feel that the clients are very satisfied with the product.

I don't have any particular advice when it comes to the deployment process. This will depend on the client's needs. 

I rate Check Point NGFW as an eight out of ten. 

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Anupama Perera - PeerSpot reviewer
Marketing at Bluechip Technical Services Pvt Ltd
Reseller
Top 10
Strong security and management features
Pros and Cons
  • "Check Point has strong security features as well as some decent monitoring and management capabilities."
  • "My customers complain that the interface isn't user-friendly."

What is most valuable?

Check Point has strong security features as well as some decent monitoring and management capabilities.

What needs improvement?

My customers complain that the interface isn't user-friendly.

For how long have I used the solution?

I have been using Check Point for eight years.

What do I think about the stability of the solution?

Check Point stable. I've had no problems.

What do I think about the scalability of the solution?

Check Point is scalable.

How are customer service and support?

Check Point support is good.

How was the initial setup?

Check Point's setup process isn't very user-friendly.

What's my experience with pricing, setup cost, and licensing?

Check Point is a little more expensive than FortiGate.

What other advice do I have?

I rate Check Point nine out of 10. I work with both Check Point and FortiGate. Each has its advantages and disadvantages. Check Point is more secure than FortiGate. However, Fortigate is more affordable and user-friendly. FortiGate offers seamless solutions to customers, so If they want a solution that's easy to use, they go with FortiGate.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: reseller
PeerSpot user
Security Engineer at a tech services company with 1,001-5,000 employees
Real User
You only need to use one rule for both the DMZ and the Internet
Pros and Cons
  • "The Check Point API let me make 100 net rules in just 10 minutes, which saved us time."
  • "I would rate the technical support as a seven out of 10. Sometimes, it's difficult to get them to understand what the issue is. Sometimes, the issue is not resolved, then we solve it by ourselves with Check Point's documentation, which can be useful. When you open a case with Check Point, they can be a little slow. Sometimes, they don't solve things."

What is our primary use case?

I am using this solution for perimeter security in the company. Our firewall security is centralized under one management. Also, we use this firewall to manage some of the VPN clients and the employees' access across the company. 

Each firewall is capable of using the VPN client, but we only use two. We have five in total, but we only use two for these issues.

I am using the firmware version for the operating system. The blades are firewalled for IPS and mobile access.

How has it helped my organization?

Last year, we used the Check Point Identity Awareness Software Blade. Now, we only use a normal firewall with IP address rules, address destination, and services. Then, we can filter by users. So, my boss has access to these things by user. Even if it's connected with the Active Directory, we can filter by user name, or in this case by server name, and it works perfectly. This is very valuable for our company.

What is most valuable?

The most valuable features about Check Point are the API and automation process.

Using the GUI, you can add comments from your PC or the client server. If I want to check the firewall rules, I can send one line of command to determine if it is configured or not. 

Its implementation and integration with the rest of the network are better than its competitors.

What needs improvement?

The stability needs improvement for its version releases. They have a feature called Inline Layer as part of the R80.10 release. In the last version, it still had bugs and is not working very well. I would like the developers to release a version that is more stable, because if you start to use the latest release and try to use this newest feature, I'm not 100 percent sure that it will work very well. After six months of development, it might start working better. However, at the beginning, it's not a good choice to implement in your company with your first attempt. But one or two releases later, it might be better. 

If you only have one vendor and they are downgraded or no longer a leader in their industry, then you need to change the entire solution, making it more expensive. For example, Check Point's components are not interchangeable with other vendors.

For how long have I used the solution?

Around four years.

What do I think about the stability of the solution?

The stability of the firewall is nice if you use the legacy mode, because the new mode is not good. Things worked in version 77, which is older. It was more stable. When they jumped from version 77 to 88, sometimes things didn't work that used to work in the earlier version.

What do I think about the scalability of the solution?

The scalability of the firewall depends on the model. In terms of the implementation, it's really easy.

We have about 25 users for the entire solution. We have two engineers who work on deployments and implementation. We have another 18 engineers who do support and operations. They have responsibility to monitor the firewall 24/7.

It protects the core network and ISP: the routing, switching, and APM backbone. This is around 8,000 pieces of equipment. 

We don't have plans to increase our usage right now.

How are customer service and technical support?

I would rate the technical support as a seven out of 10. Sometimes, it's difficult to get them to understand what the issue is. Sometimes, the issue is not resolved, then we solve it by ourselves with Check Point's documentation, which can be useful. When you open a case with Check Point, they can be a little slow. Sometimes, they don't solve things.

Which solution did I use previously and why did I switch?

In the beginning, we used Fortinet, Juniper, and Cisco. Now, we only use Check Point for firewalls. 

Last year, we changed the Fortinet firewall to the Check Point firewall. The Check Point API let me make 100 net rules in just 10 minutes, which saved us time.

The administration is awful in Fortinet. They have the FortiGate portal on an HTTP portal. Therefore, if you want to make a change, you can make a change. But if you do the change, then it's directly applied on the network, and we don't want to do that. We configure and change the policy and routing. We only apply the changes in the night. However, with Fortinet, you need to configure and apply the changes at the same time. So, it's not useful for our operations.

With Fortinet, you need to duplicate the rules from the DMZ to the Internet and the Internet to the DMZ. In Check Point, you only use one rule, which works on both sites.

How was the initial setup?

The initial setup is really easy. You can do it in 30 minutes. Setting up an environment for a firewall and its management with a licensed demo took me an hour last week, and that includes the time for configuring the rules. The whole installation is 30 minutes and the configuration is another 30 minutes.

If you are implementing from another vendor, Check Point has a program called SmartMove. Then, all you need is the configuration of the previous firewall. Once you do some optimization, then you are ready for the integration. This might take a month overall.

What about the implementation team?

We consulted with one partner of Check Point, who is our provider. If the issue is really big, then we open a case with Check Point directly via the partner. My experience with them was really nice. It was the best experience that I had ever had.

They have amazing engineers. Their expertise is unbelievable. They do integrations really well. They could improve on routing and networking, but the product is what is important for me. 

What was our ROI?

The firewall is only for protection. It is not used to sell services.

What's my experience with pricing, setup cost, and licensing?

The pricing and licensing are expensive. If you compare it with Fortinet, then it is cheaper on a yearly basis. However, Check Point is the most expensive firewall right now in terms of licenses and its appliance. My recommendation is if you want a long-term investment, then you should use an open server. If you use an open server, then the latency is really low. If you pay for a full appliance, it's more expensive.

Which other solutions did I evaluate?

Check Point's web administration is not complete. If you compare it to Fortinet's web administration, Check Point's web administration is not nice. However, Check Point's full solution, including SmartConsole, is better than Fortinet's solution.

What other advice do I have?

If you use Apple computers or Linux, the product may not be a good choice for you.

I would rate the solution as a seven point eight out of 10. They can improve some things. They can make it more flexible in terms of its software. It is a good solution, and I like it. For me, it's the best firewall solution.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Engineer at CENACE
Real User
Efficient firewall protection
Pros and Cons
  • "It is easy to configure and it is a valuable antivirus protection. I especially like the IPS feature of this product."
  • "The presentation of the reports need to be more user-friendly."

What is our primary use case?

We use this product as firewall protection.

How has it helped my organization?

We are a utility company, so we need efficient antivirus protocols. The firewall support is extremely important to our organization. Checkpoint helps us protect our company from outside threats.

What is most valuable?

It is easy to configure and it is a valuable antivirus protection. I especially like the IPS feature of this product.

What needs improvement?

The presentation of the reports need to be more user-friendly. 

For how long have I used the solution?

More than five years.

What do I think about the stability of the solution?

Sometimes we have problems. In those cases, we just need to reboot the system.

What do I think about the scalability of the solution?

The scalability of the solution is not great for us because we have old equipment. With newer equipment, I think the scalability would be much better. It is no fault of the solution itself. 

How are customer service and technical support?

The Checkpoint tech support takes a long time to resolve problems. 

Which solution did I use previously and why did I switch?

Prior to Checkpoint, we considered Cisco. 

How was the initial setup?

It was a complex setup. We had a partner configure the equipment. 

What's my experience with pricing, setup cost, and licensing?

The price is high in comparison to other solutions. 

Which other solutions did I evaluate?

We are currently considering Fortinet as another possible option. 

What other advice do I have?

After much evaluation, we have decided to change our firewall.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Executivo de Negócios de TiC at a comms service provider with 10,001+ employees
Real User
Performs well and is easy to configure
Pros and Cons
  • "My customers cite performance and ease of configuration as two of the solution's most valuable features."
  • "The price is middling. It's much more expensive than Fortinet, although not so expensive when compared with Palo Alto."

What is our primary use case?

I have certain customers who make use of the solution for providing security in respect of internet access. I am aware only of the solution acting as a firewall. 

What is most valuable?

My customers cite performance and ease of configuration as two of the solution's most valuable features. 

What needs improvement?

The price is middling. It's much more expensive than Fortinet, although not so expensive when compared with Palo Alto. 

What's my experience with pricing, setup cost, and licensing?

The solution is significantly more expensive than Fortinet, although this holds true to a lesser extent when compared with Palo Alto. 

Which other solutions did I evaluate?

The solution is significantly more expensive than Fortinet, although this holds true to a lesser degree when compared with Palo Alto. 

What other advice do I have?

I do not have much familiarity with Check Point NGFW, although I do have several customers who make use of it. I can mainly comment based on what I have come across in user reviews in magazines.

I know the solution to be one of the top players in the world at the moment. 

As Check Point NGFW does not compare favorably price-wise with Fortinet, I am inclined to deduct a point from its rating and rate it as a nine out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Executive at a computer software company with 11-50 employees
Real User
Stable with good identity awareness and intrusion prevention
Pros and Cons
  • "We have found the solution to be scalable."
  • "The complexity could be fixed. It's a bit complex to set up, for example."

What is our primary use case?

We primarily use it for security.

What is most valuable?

The most valuable features for us are the solution's identity awareness and intrusion prevention.

The solution is very stable.

We have found the solution to be scalable. 

Technical support is very good.

What needs improvement?

The complexity could be fixed. It's a bit complex to set up, for example. They could make it a streamlined and easier process. 

In a future release, it would be nice if they added web administration capabilities. 

For how long have I used the solution?

I've been using the solution for about 20 years. It's been two decades at this point. I've used it for quite a while. 

What do I think about the stability of the solution?

The stability of the solution has been excellent so far. There are no bugs or glitches and it doesn't crash or freeze. It's reliable. 

What do I think about the scalability of the solution?

The scalability of the product is very good. If a company needs to expand it, it can. It's not hard. 

How are customer service and technical support?

We have found the technical support to be very helpful and responsive. We are satisfied with the level of support we get from them.

How was the initial setup?

The initial setup is not easy. It's a bit complex. 

What other advice do I have?

We're a partner.

I'd recommend this solution to other users and companies. We've been happy with its capabilities. 

I'd give the solution a rating of nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Buyer's Guide
Download our free Check Point NGFW Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2024
Buyer's Guide
Download our free Check Point NGFW Report and get advice and tips from experienced pros sharing their opinions.