Tufin Review

It's a complete product, and we find the SecureTrack and SecureChange features to be most valuable to us.


What is most valuable?

We use both modules, SecureTrack and SecureChange. With Securetrack, we follow rules implementation and compliance; with SecureChange we manage the workflow of firewalls openings.

How has it helped my organization?

Thanks to Tufin we're able to manage the life cycle of rules and to keep logs of each firewall modification. Policies are also optimized using the tool.

What needs improvement?

Checkpoint and Cisco products are well implemented and managed. For Fortinet firewalls some features are not yet available.

In networks where the WAN is managed by a third party, some features may be missing if you're not able to have information about routing, ACL, etc

For how long have I used the solution?

2 years.

What was my experience with deployment of the solution?

Product is quite complete. The hard work concerned building a topology on the product base on reality of the network. Some workaround we do in reality may be hard to model using the tool. Topology is mandatory for SecureChange to work.

What do I think about the stability of the solution?

Product is stable and we've had no problems concerning stability, even if we're not able to have a clear view of the capacity of this tool. There is no reporting on capacity. For instance, there is no alarm.

What do I think about the scalability of the solution?

No issue specifically, but for large networks several appliances are required to have a distributed architecture. Also, for SecureChange it's necessary to have a separate instance so the topology calculation has no impact on user interfaces.

How are customer service and technical support?

Customer Service:

Excellent, even if we have more contact with support team, customer service is always checking that everything is fine.

Technical Support:

Excellent, the support and the post sales service is the best I ever had. They're always available and listen our concerns. Even some features required have been delivered a few weeks after the requirement.

Which solution did I use previously and why did I switch?

We used another solution some years ago, but we switched, first of all, for performance and stability issues. The old solution was not able to handle the number of rules we can manage in our network.

How was the initial setup?

The main setup subject will be to check what's the first need you want to answer. In our cases we want to manage our life cycle of rules and we work on it. Start small and grow up smoothly while you understand your network topology.

What about the implementation team?

Vendor was quite good. This is a tool with which the need to understand your network is mandatory. You must have an in-house team to be fully operate this tool. This is also the easiest for support.

What was our ROI?

Our main ROI is to be more agile and flexible for rules lifecycle. We're able to answer faster with the same number of people.

What's my experience with pricing, setup cost, and licensing?

Pricing is correct. You've got one or several appliances and pricing is not too high. After licensing is per firewall managed by the tool, so you can grow smoothly.

Which other solutions did I evaluate?

We did an evaluation of the different solutions on the market, and it was our vendor that recommend us the solution.

What other advice do I have?

I recommend this solution. In our case, it was the missing part to be able to provide a better service to our clients.

**Disclosure: IT Central Station contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
More Tufin reviews from users
...who work at a Financial Services Firm
...who compared it with AlgoSec
Add a Comment
Guest