reviewer1275342 - PeerSpot reviewer
IP network expert at a comms service provider with 201-500 employees
Real User
Improves efficiency and network visibility, scalable, and has good technical support
Pros and Cons
  • "It provides faster go to market with fewer resources."
  • "I would like to be able to see what objects have the same IP, but different names in different firewalls."

What is our primary use case?

The primary use for AlgoSec is managing firewalls and to introduce a workflow system for requesting access through firewalls, which is fully integrated with them.

How has it helped my organization?

It provides faster go to market with fewer resources. In one system, users are able to request access through the firewall for business services, which can be approved by the appropriate team and can be implemented automatically by the system itself. Furthermore, users are able to track whether one particular access is blocked on any of firewalls or not, etc.

What is most valuable?

The most valuable modules are Firewall Analyzer and FireFlow. FireFlow is the workflow system, whereas Analyzer is the module responsible for tracking the configuration of firewalls, routers, switches, load balancers, etc.

There are many more useful features that cannot be listed here in a detailed manner.

What needs improvement?

I would like to be able to see what objects have the same IP, but different names in different firewalls. Since the system is able to show all of the objects for the integrated devices, it can be confusing if one particular object (eg. IP address/host) has different names in different firewalls.

Buyer's Guide
AlgoSec
May 2024
Learn what your peers think about AlgoSec. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
770,458 professionals have used our research since 2012.

For how long have I used the solution?

I have been using AlgoSec for two years.

What do I think about the stability of the solution?

We have not experienced any problem with the system.

What do I think about the scalability of the solution?

The system can be run on virtual machines, so we don't have any issue with scalability.

How are customer service and support?

I would rate the technical support with five stars. :-)

We always received the necessary help quite fast, and the answers were valuable.

Which solution did I use previously and why did I switch?

We didn't have a similar system before this solution.

How was the initial setup?

It was not so complex and didn't take more than several days until we integrated all of the important networking devices.

What about the implementation team?

It was implemented by a vendor, they had the necessary expertise.

What was our ROI?

Actually, I cannot really estimate because I am responsible for the operation of the system. I can say that we have saved some resources with the automatic implementation feature.

What's my experience with pricing, setup cost, and licensing?

I propose to purchase licenses for all of the networking devices in the network, because if not all of the devices are integrated then the query of particular access cannot be discovered entirely.

Which other solutions did I evaluate?

We have chosen this system after evaluation (RFQ). The other competitor was Tufin.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
System Engineer at Dimension Data
Real User
Enables us to analyze and optimize our firewall by evaluating the rules and services
Pros and Cons
  • "The features that are most valuable are the interactive topology map and the traffic simulation queries."
  • "The MAP has a persistent issue with a firewall that is using a double BVI (Bridge virtual interface)."

What is our primary use case?

The AlgoSec Firewall analyzer has helped us to analyze and optimize our firewall by evaluating the rules and services. These include routing, access rules, and restricting both applications and servers.

How has it helped my organization?

This solution has helped my client to analyze and assess whether any service or routes are needed for connections that are going to be created. It has also optimized the efficiency of the firewall by evaluating the rule set.

This solution helps us to save time, making the job more efficient for our network engineer.

What is most valuable?

The features that are most valuable are the interactive topology map and the traffic simulation queries.

The MAP helps us by generating a network topology map and checking the routing table for every device that is connected. The traffic simulation queries help us to check the connection between two objects. This allows us to gather information about the devices pertaining to blocked traffic or services that we need to add.

What needs improvement?

The MAP has a persistent issue with a firewall that is using a double BVI (Bridge Virtual Interface). In this configuration, it cannot give the correct and proper topology, so the traffic simulation query cannot run properly between the source and destination.

For how long have I used the solution?

Less than one year.

Which solution did I use previously and why did I switch?

We have used other firewall products and it is very complex to check if any connections are down or blocked. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
AlgoSec
May 2024
Learn what your peers think about AlgoSec. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
770,458 professionals have used our research since 2012.
Olivier Beytrison - PeerSpot reviewer
System Architect at HES-SO//Fribourg
Real User
The traffic simulation query helps to understand which rules match or don't match for a specific traffic pattern, helping troubleshoot application issues.

What is our primary use case?

  • To change management of the rules
  • History of changes
  • Risk analysis and evolution of the risk factors over time.

How has it helped my organization?

  • Transparency over the actions made in the rulebase by the different firewall operators
  • Documentation of the rules.

What is most valuable?

The traffic simulation query helps to understand which rules match or don't match for a specific traffic pattern, helping troubleshoot application issues.

What needs improvement?

We use the "rules change notification" feature to inform the different firewall managers when someone made a change. The actual change comes in a PDF file attached to the e-mail, while it would be faster to have it directly embedded in the notification mail.

Depending on your network topology, the traffic simulator might have some hard time tracing the traffic path between your devices correctly. This has already been improved in the past but could still be enhanced.

For how long have I used the solution?

Three to five years.

What do I think about the stability of the solution?

The solution is very stable. Some caution is required when you do major upgrades on your firewalls to ensure that AlgoSec can still work with the new software release of the firewall.

How was the initial setup?

The setup is very easy, as it comes as a virtual appliance you deploy in your own virtual environment. The setup is straightforward, and you can very quickly add your firewalls and start tracking changes, query the traffic simulator, and so on.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Technical Manager at Global Technologies for Trading and Contracting
Real User
Automated rule re-ordering helps improve performance, but it needs an intelligent tuner
Pros and Cons
  • "I found that for policy optimization it does a great job."
  • "I would like an intelligent tuner where it could help update rules with the application ID."

What is our primary use case?

The primary use for this solution is to clean-up and fine-tune firewall rules.

How has it helped my organization?

I found that for policy optimization it does a great job. It handles covered rules, duplicate rules, and consolidated rules.

What is most valuable?

The most valuable feature is the ability to reorder rules because of the enhancement of firewall CPU performance when they are applied.

What needs improvement?

I would like an intelligent tuner where it could help update rules with the application ID.

For how long have I used the solution?

I have been using this solution for one month.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Technical Director at Keystone Solutions, Inc.
Real User
The product, directly implementing the policies to be enforced by the gateways, makes life easier for IT

What is our primary use case?

  • A systems integrator to implement for clients
  • To help them manage their firewalls that were bought from us as well.

How has it helped my organization?

It provides the organization by giving us visibility in the process of our clients and automates policy implementations and checks. It gives value to our managed services that we provide.

What is most valuable?

  • Algosec Firewall Analyzer and Algosec FireFlow: They basically give us a full picture of how traffic flows and how we can secure it.
  • The product, directly implementing the policies to be enforced by the gateways, makes life easier to the IT.

What needs improvement?

Based on the conference I just attended, it is improving by Algosec opening their API more. This allows us as a systems integrator to give more value to our clients. We will be able to integrate more things that do not come out of the box.

For how long have I used the solution?

Less than one year.

What do I think about the stability of the solution?

Stability is fine as it's been in the market for a long time.

What do I think about the scalability of the solution?

Scalability is fine especially as they just released their CloudFlow as well.

Which solution did I use previously and why did I switch?

No.

How was the initial setup?

AlgoSec helps us be ramped up on our technical expertise on the product.

What was our ROI?

N/A.

What's my experience with pricing, setup cost, and licensing?

Licensing is simple, and the setup is straightforward.

Which other solutions did I evaluate?

Yes, Tufin.

Disclosure: My company has a business relationship with this vendor other than being a customer: Systems Integrator
PeerSpot user
PeerSpot user
Technical Consultant at a tech services company with 10,001+ employees
Consultant
By leveraging BusinessFlow/FireFlow/ActiveChange we have been able to reduce the time from initial requirements gathering to implementation of complex firewall designs.

What is most valuable?

We were immediately able to leverage the workflow tools in FireFlow with ActiveChange to speed up our deployment of firewall policies.

How has it helped my organization?

By leveraging BusinessFlow/FireFlow/ActiveChange we have been able to reduce the time from initial requirements gathering to implementation of complex firewall designs by approximately 80% without compromising our security posture. 

What needs improvement?

Additional understanding of complex routing in multiple systems.

For how long have I used the solution?

We have had this working in our production environment for about 6 months.

What was my experience with deployment of the solution?

The initial deployment was unsuccessful as the product had not initially support our use of virtual routing instances on Juniper SRX devices however AlgoSec engineering was quick to deploy fixes to allow us to reach our desired outcome. 

What do I think about the stability of the solution?

None.

What do I think about the scalability of the solution?

None.

How is customer service and technical support?

Top notch.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user494187 - PeerSpot reviewer
Security and Network Architect at a tech services company with 10,001+ employees
Consultant
For FireFlow, workflow customization and active change are the best features. Interaction with a lot of vendors results in a lot of options and bugs.

What is most valuable?

With a network like ours - more than 100 routing points with around 6 VRF on each - traffic simulation query is one of the most valuable feature on AFA.

For FireFlow, workflow customization and active change are the best features.

In BusinessFlow, the ability to simulate documented flow against configuration by AFA is the best feature to limit differences between documentation and production.

How has it helped my organization?

This product allowed us to identify unused rules more easily and doing this simplifies policies in our firewall. We now have documentation of our application with objects sync with real configuration. Our approval in change management has been improve through FireFlow and errors have been reduced through change advised and active change. We also save time by identifying earlier than usual routing issues associated to a change request.

What needs improvement?

A lot of areas have room for improvement!! This product is still young and in constant development. Interaction with a lot of vendors generates a lot of firewall options (specifically, a timer on services, application control, and so on...). This interaction also generates a lot of bugs in the product. Every new version contains about 10 to 20 bugs for our environment. This is partially explained by the fact it has to understand all of the architecture and specificity associated with all of the supported vendors.

A few of the bugs are:

  • Services composed with something else other than TCP or UDP are not well-handled and not working in simulation queries. (For example, AH or ESP or EthernetOverIP.)
  • Traffic with same objects in source and destination are not working.
  • When NAS is used to store reports, we have had a lot of bugs associated with wrong URL encoding.
  • Role assignment with multiple LDAP issues.
  • Some file cleanup not working as expected.
  • Active change is available for only a few vendors.
  • BusinessFlow doesn't offer auditing regarding object management and with a lot of application and managers, it quickly becomes an issue with duplicated objects and so on.
  • There are also gaps in access right management.

For how long have I used the solution?

I have been using it nearly two years.

What do I think about the stability of the solution?

Every version came with its bug bundle... In two years, we opened 50 cases and about 40 of them escalated to development for resolution. This situation is also explained by complexity of our architecture.

What do I think about the scalability of the solution?

I have not encountered any scalability issues. Each version usually improves performance and the amount of required disk space.

How are customer service and technical support?

Technical support is 7/10; quick to give a new version solving the issue but long to identify the issue, even when it seems to be identified from the beginning.

For example, more than a month ago, we identified a wrong link associated to NAS configuration. We can clearly see that the wrong link was being generated, pointing from the NAS directly to the NAS repository, instead of a symlink. It took more than a month for support to accept this and to escalate the case to dev. After dev escalation, we are expecting a fix on Monday. So, it took four weeks to acknowledge the issue and two weeks to be fixed by development.

Which solution did I use previously and why did I switch?

We did not previously use a different solution.

How was the initial setup?

Initial setup is straightforward; some custom options can be tricky to set up, but will not be used by most customers.

What's my experience with pricing, setup cost, and licensing?

Be careful with VRFs. One router with two VRFs consumes two licenses. So a new VRF configured on all routers will double the number of licenses required on routing elements.

Which other solutions did I evaluate?

We benchmarked Tufin before choosing AlgoSec. We chose AlgoSec over Tufin for its capacity to be more customized and its support for MPLS and VRF.

What other advice do I have?

Offer me a job. ;) I will help you set it up.

More seriously, test it with caution through a POC to be sure that all your architecture specifics are addressed. If not all of them are addressed, ask for a commitment regarding support of missing features and ask for those commitments to be written down before ordering.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
User
We can easily make our firewall flow change requests using the web interface
Pros and Cons
  • "We can easily make our firewall flow change requests using the web interface."
  • "It would be great if the product could be more simplified when defining the rules."

How has it helped my organization?

  • Centrally manage firewall flow requests
  • Approval/implementation and validation
  • We can easily make our firewall flow change requests using the web interface.

What needs improvement?

It would be great if the product could be more simplified when defining the rules.

Documentation could be added to the tools, then generate documentation and send it to the relevant people.

For how long have I used the solution?

More than five years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free AlgoSec Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2024
Buyer's Guide
Download our free AlgoSec Report and get advice and tips from experienced pros sharing their opinions.