AlgoSec Room for Improvement

CW
Vice President Head of Information Security at Itaú

We are using AlgoSec directly against our Cisco Firepower. At first, AlgoSec didn't work with Firepower. It didn't know how to read the logs. So, improvement has been made. Now, the feature that was available on the older generation firewall is available on the current one, but this is a problem which has already been dealt with.

View full review »
AZ
Sr. Network and Security Administrator at a insurance company with 501-1,000 employees

The reports are lacking information when they come out. They will not pull the URL or application information from Cisco FTDs. I know this works for Palo Alto Firewalls, which we currently do not have. If they could improve the integration with Cisco FTDs as a whole, that would be immensely helpful.

View full review »
MG
Network engineer at a insurance company with 10,001+ employees

A few features could be more customizable. For example, one of our issues is related to the comments. When using FireFlow and ActiveChange, the comments by AlgoSec can be changed, but they always have the FireFlow number first. That's mandatory. It can be a bit bothersome because that's sometimes not exactly what we want. The templates we use have some scripts running in the background that aren't easy to change or remake. 

These options could be improved. Some features take time to learn and understand. It would be hard to figure out without AlgoSec support. Every bug or every problem we encounter is challenging to understand and fix without them. We try to solve our own issues, but sometimes we can't, and we need AlgoSec support. 

View full review »
Buyer's Guide
AlgoSec
April 2024
Learn what your peers think about AlgoSec. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,578 professionals have used our research since 2012.
Tempreviewer F - PeerSpot reviewer
Staff Software Engineer and Machine Learning Scientist at Google

While AlgoSec provides comprehensive visibility and management of security policies across hybrid environments, there is an opportunity to further expand its intelligence capabilities. 

Specifically, AlgoSec could look to incorporate more machine learning to analyze network traffic patterns and application behavior to detect anomalies indicative of emerging threats and policy violations. Going beyond just mapping connections, it can automatically flag high-risk flows and unusual events for further investigation.

View full review »
reviewer162462 - PeerSpot reviewer
Asistent stavbyvedoucího at STRABAG Rail GmbH

Introducing greater flexibility in editing alerts would be a highly appreciated improvement.

The solution currently faces visibility and compatibility challenges when it comes to Palo Alto firewalls, making it difficult to generate reports. Since the reports heavily rely on logging, the product encounters obstacles with Palo Alto's logging system. Enhancing compatibility with Palo Alto firewall reports is crucial for seamless reporting.

A notable customer demand is the implementation of a user-based policy within AlgoSec. This feature would enable the solution to provide advice on user policy rules while also ensuring compatibility with identity awareness functionalities. Meeting this customer requirement would be highly beneficial.

View full review »
Guy Soudant - PeerSpot reviewer
CISO at a real estate/law firm with 1,001-5,000 employees

AlgoSec is not a tool where people with little knowledge of security or IT can find their way around. AlgoSec has a less user-friendly interface compared to competitors, but it is comparatively more customizable. As such, the interface is more on the complex side.

View full review »
reviewer0185153 - PeerSpot reviewer
Network & Security Engineer at ALTEPRO solutions a.s.

While AlgoSec offers many advantages, there are some areas for improvement. Certain features, like comments in FireFlow, could be made more customizable. Additionally, some features require a learning curve and may necessitate support from AlgoSec, which can be challenging at times.

While AlgoSec offers many advantages, there are some areas for improvement. Certain features, like comments in FireFlow, could be made more customizable. Additionally, some features require a learning curve and may necessitate support from AlgoSec, which can be challenging at times.

View full review »
erdemerdag - PeerSpot reviewer
Cybersecurity Operations Engineer at a tech services company with 201-500 employees

At the integration point, a manual page could be added to the dashboard where directions about the products are explained in detail. In this way, if the system administrator wants to integrate a new product, they will be able to integrate this product by following these directions, even if they do not have deep knowledge of the product in question. Integrating different products should not require us to have to wait for coordinated work with a product specialist.

View full review »
reviewer262735 - PeerSpot reviewer
Network Engineer at New York Community Bancorp, Inc.

RFEs are kept open for too long. We had requested a couple of features, including the ability to trust implicit rules, and IPT doesn't run on IPSEC-enabled firewalls (Cisco to be specific). We had reported these issues for over four years now and still we do not see any resolution.

There is no visibility for the changes made to the NAT rule policies.

Adding objects or object groups on the firewall also do not generate a change notification.

There is no visibility for changes made to the secondary standby firewall if the firewalls are added as a cluster.

View full review »
VS
Lead Infrastructure Engineer at a financial services firm with 5,001-10,000 employees

Some of the auditing functionality needs improvement. Our major focus is the firewall validation process and tracking and verifying that changes are implemented correctly. We are actually doing parts of the auditing process manually. And getting any one of the vendors to bring out a good auditing process has been very difficult. AlgoSec does a good job of showing us the changes, but we're doing a manual process to actually audit it and do documentation that we can provide to our auditors that shows we're validating everything, and on top of it, that nothing gets implemented without being caught. Part of that could be improved upon.

View full review »
IbrahimAlsharif - PeerSpot reviewer
Director of IT at CITG

Releasing hot fixes or patches is late compared to other security products.

Also, the integration with the Cisco FTD security group tagging is still not supported, so we cannot get the rules with SGT-ACL, and still there is no clear roadmap to support such a feature.

The user interface can be more friendly. They could work on enhancing it by adding step-by-step guides in the GUI of the AlgoSec AFA.

It's better to give some priority to the integration with other security systems and enhance this capability.

View full review »
Gabriel Borlean - PeerSpot reviewer
Network Specialist at UFST.dk

I would say that the cases opened with AlgoSec could be solved faster or escalated sooner to the senior engineers/2nd or 3rd tier. AlgoSec Support is very good at responding very fast (faster than the required SLA) and very timely. Their engineers are based either in India or Israel. Each region has its sales person and technical engineer person.  

Another pet peeve is that there are hotfixes for new issues or bugs at least once a month, if not more frequently.  Overall, AlgoSec is trying to improve its case-resolution support team and process, and we are optimistic that our issues or bugs will be fixed much timelier.

View full review »
SC
Regional Sales Manager - South India at Exclusive Networks

AlgoSec provides very good support to their clients. There are no complaints. That said, these items can be improved:

  • Support can be improved as there are time delays for resolutions
  • In the current version of AngloSec analyzer, we can not delete the object from all firewalls and need to do the task manually
  • We need more effective topology diagram
  • There are challenges in connecting the different security vendors
  • User creation and assigning roles are a little bit difficult
  • While upgrading we have to upload package files which can be downloaded from the Algosec website yet the downloading takes time
View full review »
reviewer184691 - PeerSpot reviewer
Technical Architect at Tata Consultancy

They need to do some improvements in multi-vendor firewall policy migration. They need improvements in network discovery. The solution could fix some bugs in the A32. Fireflow needs to be a little more user-friendly.

View full review »
JC
MITP-2 at State of Nevada Department of Administration Message

I can't think of specific improvements. If anything, the product has been improving in usefulness constantly. 

View full review »
HS
IT Support Specialist at Taarak India Private Limited

To provide comprehensive instructions on product integration, a manual page can be added to the dashboard at the integration point. This will make it simple for the system administrator to incorporate new goods, even if they are unfamiliar with them thoroughly. Every time we integrate a new product, we shouldn't have to wait for coordinated work with a product specialist.

Due to the fact that AlgoSec's user interface is less friendly than that of other programs, it might not be appropriate for persons with little experience in security or IT. It does, however, allow for more customization. As a result, the interface can be regarded as more sophisticated.

View full review »
VS
Information Security Specialist at a financial services firm with 10,001+ employees

The Firewall Analyzer module can be improved to implement a vulnerability management solution, or they can link Firewall Analyzer with a vulnerability management solution in order to get a better overview of what's going on in our network in terms of vulnerabilities.

View full review »
reviewer1120656 - PeerSpot reviewer
Information Security Specialist at a maritime company with 10,001+ employees

For the most part, this AlgoSec tool does meet our needs. If I was to think of any improvements I think the main one that stands out to me is confidence in future proofing. A good example is that we are looking at various SOAR which we'd like it to be fully compatible with (but not entirely convinced it is yet). Lastly, I have also heard a few qualms about the technical support and that it could be improved. However, this doesn't detract from the value the tool brings to our business.

View full review »
SC
Regional Sales Manager - South India at Exclusive Networks

The solution needs improvements in the following areas:

  • Algosec does not support vendors like Sophos, SonicWall, Forecepoint, and so on.
  • Traffic simulation and fire flow need to be improved.
  • The solution has insufficient documentation.
  • They need to improve tech support in India.
  • Deleting objects from each firewall is tedious, and it has to be done manually.
  • An effective topology diagram can be provided.
  • It is a challenge to combine different security vendors. 
  • To upgrade, we have to upload package files which can be downloaded from the Algosec website, however, downloading takes time.
View full review »
Kasper Tjellesen - PeerSpot reviewer
Security Engineer at a tech consulting company with 1,001-5,000 employees

All our firewalls were renamed, and AlgoSec saw these devices as new devices. As a result, all the reports from the same device but with the old hostname were no longer connected. AlgoSec did not clean up the old reports as well. After a few days, it depleted its own storage, and then, the server became inaccessible. 

There's no fail-safe for AlgoSec to not stop creating reports if its own storage is at 98% or 99% capacity because the server becomes inaccessible when it reaches 100%.

I've also been fighting an issue with the Chisel service running on the server regarding AlgoCare for some time now. I have been in contact with AlgoSec's technical support regarding this, and they've been helpful and responsive.

View full review »
HM
Network Security Officer at a energy/utilities company with 1,001-5,000 employees

My only concern is related to how they count the number of licenses. We have active and standby devices. If someone adds the standby device by mistake and does an analysis, it consumes two licenses. They need to improve the way they are counting the number of licenses because someone can do analysis on a standby device by mistake. We need a way to fix or solve this issue.

I noticed that some of the oil companies in Kuwait have started to use AlgoSec Analyzer. I see AlgoSec solutions in Kuwait. AlgoSec needs to have sales engineers here. They should have presales or sales consultants so that they can offer solutions to companies in Kuwait.

View full review »
SL
Project Engineer at a tech vendor with 51-200 employees

The FireFlow's out-of-the-box workflow configuration/customization wizard could be improved to be more user-friendly and have a shorter learning curve. The current configuration wizard is quite complex and complicated, which will result in the need to engage with an AlgoSec professional services team to perform even the simplest workflow adjustment.

I had tried AlgoSec's direct competitor's workflow configuration wizard and found it to suit most organization requirements even though the customization capability may not be as advanced as AlgoSec.

View full review »
reviewer1175712 - PeerSpot reviewer
Works at a energy/utilities company with 10,001+ employees

Support for Layer 7 policies, including User-ID and threat profiles with Palo Alto firewalls, has been a pain point from us. We would like to include the additional info specifically because we believe it changes the riskiness of the rule if it is only set for a specific user or a group of users. For example, if we have what looks like an "allow all" to a certain /24 network, but for only one user, we would give that a different score than if no user was identified.

View full review »
TW
IT Security Engineer III at Paychex, Inc.

I would like to see more object-based reports on groups and object usage. When cleaning up old rules, it is easy to disable the rule and then delete after a while. Trying to find unused groups or used objects in groups gets a little harder and I would like to see an easier view into those objects. 

View full review »
BK
Senior Technical Analyst at a maritime company with 1,001-5,000 employees

We have a fairly complex routing environment that AlgoSec struggled with. The initial period when we were doing an installation with their support desk was fairly challenging.

View full review »
Ilya_Kondratyev - PeerSpot reviewer
Deputy Information Security Department Director at AMT Group

The initial setup can be complex for beginners.

View full review »
Sahanawaz khan - PeerSpot reviewer
Sr Platform Owner at Emirates NBD

AlgoSec should explore integrating more multi-vendor platforms and should be looking towards ready infrastructure for providing Infrastructure as service (IAAS) on any cloud platforms as the trend and technology is gradually moving from In House platforms to Cloud platforms.

Algosec should also be exploring the integration with the open source firewalls as well.

The GUI features of Algosec solution should be more flexible to use and adopt.

View full review »
AS
Senior Networking Engineer at Schneider Electric

It would be nice to have a good tool for network map discovery in the GUI to make it more user-friendly. I would also like to be able to check and modify network maps in a graphical and more intuitive way. This will improve our network overview for new deployments and troubleshooting.

An API to connect to Palo Alto Prisma and Zscaler to be used after SD-WAN deployment would be a helpful feature. We have discussed this with AlgoSec and are hoping to see it in the near future. 

View full review »
Srdjan - PeerSpot reviewer
Senior Technical and Integration Designer / Center of Excellence / Europe & Indonesia at Ahold Delhaize

All of the search options needed are there but the search menu could be a bit more intuitive. In other words, I can perform any search I want without any problems but combining different search parameters can sometimes be a problem.

Creating more intuitive menus could be helpful, especially for the first-time users.

For example, it would be useful to be able to save searches with complex structure so they can be easily reused with simple change of parameter. Also, "contain" criteria sometimes misses just like ability to search using any value in basic search box, instead of reaching out to Advanced search (it would be great if simple typing IP address, or Project ID in basic search box lists all rules containing such a value).

View full review »
MP
Network Administrator at City of Calgary

We love all the features of this device. It can be a bit expensive for small companies but they also have a VM model for that.

It seems that AlgoSec created a VSYS (Virtual system) for each virtual router name, even though our firewall has only a single VSYS. We are ok to work with this, but if this can be fixed in a future release then that will be great.

View full review »
AW
Security Engineer at Genuine Parts Company

Currently, the product is doing everything we have asked for. Its a huge component for our Firewall maintenance. One key component is the integration with ServiceNow for Firewall rule requests. This helps expedite the process and track every step from user to configuration. 

Some area's where the product can improve is with the knowledgebase. Sometimes you have to do additional reading for your particular error.

Some additional features I'd like to see are for the reports. As opposed to showing me the entire objects/rules on the change detection email for that particular firewall, I'd like to see just the changes. I think this would be beneficial to none technical personal that may get overwhelmed with all of the data.

Also, having a Linux or programming background makes troubleshooting easier. That is one challenge I'm working on now to improve fixing our issues quicker.  

View full review »
VS
Network Security Services Engineer at Softcell Technologies Limited

AlgoSec offers almost everything that clients want and has a robust set of features. That said, there are a few areas where it could improve. The user interface, although functional, could benefit from a more modern and intuitive design. Additionally, the initial setup and configuration process may require some technical expertise, which could pose a challenge for organizations with limited security resources. A simple tutorial about the initial configuration on Youtube could provide a lot of help. Even a self-guide link inside the GUI would be helpful.

View full review »
reviewer252573 - PeerSpot reviewer
System Analist at Compugraf

Plugins for integration with other tools as ServiceNow, for example, would be ideal. This would facilitate the work without needing a developer to carry out integrations, mainly for market tools.

We need a screen to view system logs. This would facilitate the problem analysis process. The possibility of placing buttons in another system to trigger actions within AlgoSec would be great. For example, placing an HTML button in ServiceNow that triggers the active change. Being able to view the ticket flow within other tools would be useful.

View full review »
AS
Senior Consultant at Deloitte Portugal

The network mapping interface could be improved in the next version. In a complex landscape, with several nodes/equipment, it can be somewhat more difficult to properly visualize the network map. It requires several zoom-in and zoom-out operations, and it is not so visually appealing. Nevertheless, it is still a valuable feature and was highly used by my team.

View full review »
reviewer1109571 - PeerSpot reviewer
Works at a retailer with 10,001+ employees

AlgoSec now has cloud products that they are rolling out. This is the next space for which everyone is dedicating more resources. We would like to see them utilize the cloud to help with performance improvement, and with various processes needed on a daily basis. We have two remote agents that help with daily processing and would like to integrate more power from the cloud to be as flexible as possible.

View full review »
MD
Global Network Security Engineer at General Motors

Faster HA/DR failover - with very large databases, it takes a long time to failover / failback.

Provide even more REST API calls (ex: rule removal API)

View full review »
SP
Manager - Network Service Delivery (IP & Security) at Prudential Corporation Asia at Prudential Corporation Asia

ABF is not very mature compare to AFA and AFF, but the module and concepts are quite good. I would suggest more concentration on ABF, especially on object and application permissions. 

View full review »
Gulu Demirag - PeerSpot reviewer
Cyber Security Expert at Soitron Siber Güvenlik Servisleri

Enhancements that allow for more automated policy management, change workflows, and orchestration can significantly streamline network security operations. 

Advanced analytics and reporting capabilities that provide deeper insights into network traffic, security policy effectiveness, compliance, and risk management can be beneficial. 

Features that allow security policies to be defined and managed based on specific applications' needs would be ideal.

View full review »
JR
Security Consultant at a computer software company with 501-1,000 employees

Certain firewalls don't integrate with AlgoSec, and it would be great if this bug could be fixed.

AlgoSec looks into compliance and is helpful. However, it would be nice to have validations that can run before the changes are posted and implemented. Now, if something goes wrong the user would need to reach out to us, and then we would have to troubleshoot. Instead of that, if there are validations for simple tasks, it would be great.

I've also heard from our AlgoSec vendor about a feature that is coming up in the future. With the topology table, we can see the interconnected devices to understand the traffic flow. I was told that with this new feature, if we find a blockage, maybe on a firewall, that we would be able to go to that firewall and allow traffic through a specific rule. This would be done just by right-clicking on that particular device and getting the change implemented through automation. This would be a helpful feature.

View full review »
Volkan Tastan - PeerSpot reviewer
Security Engineer at Infosec

More scope for editing alerts would be a welcome change. 

The solution has visibility and compatibility issues with Palo Alto firewalls, which makes it challenging to provide reports. The reports rely on logging, and the product has problems with Palo Alto's logging. Better compatibility with Palo Alto firewall reports is a must.

Some of our customers want to see AlgoSec with a user-based policy that can advise on user policy rules and be compatible with identity awareness.

View full review »
MG
IT Security Manager at a retailer with 10,001+ employees

In my opinion, the user should be granted more flexibility to choose exactly which devices per CMA should be analyzed.

The process to replace a decommissioned device with a new device is not straightforward.

With the upgrade to CheckPoint R80.xx we have started to see some issues, although this version was already some time on the market, hence I was surprised that there was no full compatibility achieved. Nevertheless, working with support and professional services solved our problems.

View full review »
MarcelTe - PeerSpot reviewer
IT Technical Consultant at Schneider Electric

There are a few things that we have already raised to AlgoSec in order to improve the tool. First, as the highest volume in our network is SaaS traffic, we need to secure this connection. To secure SaaS traffic there are a few vendors such as Palo Alto and Zscaler, but AlgoSec is not yet able to push rules onto these clouds. It’s in the roadmap but this is something that blocks our whole design.

The network map design is not very useful for the administrator as the information displayed is not user-friendly.

View full review »
it_user837879 - PeerSpot reviewer
Senior Security Analyst at The Hartford Financial Services Group, Inc.

We have had challenges with technical support as mentioned earlier. However, we have a new account team and they are very responsive and addressing our concerns. 

View full review »
RF
Resp. Area de Segurança at REN

AlgoBot should be more developed by adding more features to the chat.

We will be integrating with Cisco ACI soon. Hopefully, new features with this integration will be developed as well in terms of automation.

I came across a difficulty recently with a BGP enabled firewall that had a large number of routes. This wasn't directly supported due to a 3000 rule per firewall limit.

View full review »
reviewer1335075 - PeerSpot reviewer
Network Security Engineer at Chubb

A vulnerability management module might be interesting, though not integrated with a third-party vendor. It should be an AlgoSec VM module.

I would like some server integration for vulnerability management.  

Some PDF reports are not so good. E.g., the graphics and reports are not so good. Sometimes, we need to create graphics and reports to compare security ratings across months and groups. 

View full review »
MK
Network Security Engineer at Türkiye İş Bankası

Cisco Firepower device support is limited in our AlgoSec system and I think AlgoSec can improve in that area. For example, in FireFlow we can easily track using the ticketing system to integrated Check Point devices. However, with Cisco Firepower devices, we couldn't integrate with them.

View full review »
Sunil Kumar.  - PeerSpot reviewer
Works at Maple Leaf Foods

There is huge scope for improvement in the level of support, especially around the issue of resolution time. That is the only negative point I find in the solution. I hope you guys will work on it and improve your resolution time which will help customers to keep their AlgoSec device healthy.

View full review »
AS
Director of Information Security Operations at First Quality Enterprises

I would like to see Bi-Directional API support in order to integrate with SOAR platforms that provide SOC automation and IRR.

Integration with CISO dashboards would be an improvement.

It would be nice to have support for IaaS, CASB, and DLP tools, which will allow full life cycle management of security incidents.

It would be nice to have an out of the box "best practices recommendation" with the relevant "what-ifs". 

View full review »
NR
Network Manager at iPSL
  • The maps are a little clunky and could be made easier with some automatic layout technology which assists in spacing out the devices for easier viewing.
View full review »
ZS
IT Security Analyst at The Hartford Financial Services Group, Inc.

Support/upgrade processes and documentation. The platform would benefit from additional support articles and guides on the Algopedia knowledge base.

View full review »
AG
Consultant at HCL Technologies

We are running multiple hybrid cloud solutions, working with cloud providers, and looking for API integrations with cloud and related interoperability. Sometimes, when we are trying to delete or disable any rule, it takes more time than expected. 

Sometimes, the web browser has issues with slowness. It can be worked out with a click or two. 

View full review »
MR
Cloud and Digital Transformation Architect at a tech services company with 10,001+ employees

The overall visibility it gives us into our network security policies is pretty good but it has some bugs and shortcomings. It doesn't support all features on our firewalls. For instance, planning changes, which include net rules, doesn't work. It didn't integrate so well with the ACI network. It doesn't work with all firewall rules or with net rules on our firewalls.

For about 70 percent of firewall changes it does show us the risks, while for 30 percent of the changes, we can't plan because of these bugs and shortcomings.

View full review »
EL
Level 3 Security Engineer at a tech services company with 10,001+ employees

Support could be improved. Support of the KB database is extensive but still does not cover all subjects, at least from my experience. 

Another area of concern that I think could be improved is the licensing system. With the version we are currently running, it is a bit confusing since, for some reason, AlgoSec license usage is handled differently between firewall vendors. It may be a bit challenging to properly size the purchase of a new license - especially if a client is running multiple vendor firewalls in the environment.

View full review »
GB
L3 Security Engineer at NTT Security

AlgoSec firewall analyzer is already an awesome product but there are still some areas that definitely need improving.

For instance, the risky rules reporting should have more information available in the risky rules report - especially when you export the data into a .CSV format. .CSV format being a text-based visualization, some information and formatting cause the reports to lose meaning and only become just another character in the file since it cannot port over some properties (like severity represented by colors).

View full review »
SE
Senior Systems Engineer with 51-200 employees

AlgoSec needs improvement with its support level.

I know that they have 3D architecture like SMB and enterprise on top of that. Some people consider this as a noncritical device. But because it's not as critical as a firewall, some people think that the support level does not need to be equal to a firewall level of support. But if some people are monitoring and managing firewalls through AlgoSec, the level of support should be equal to a firewall level. It shouldn't be dragging over two or three days. I know that they have three levels of support, but at the very first level, I believe you should be able to directly contact the tech and get a solution as soon as possible.

The only problem I have with AlgoSec is just its level of support, not with the product. Not with the organization or the documentation or anything else, but if I need any additional support, the only problem is the time it takes to get it.

View full review »
HS
Managed Security Services Product Manager at a comms service provider with 10,001+ employees

AlgoSec can probably do better at introducing features for the cloud firewall scenarios. This is something that will probably help customers. It needs a hybrid scenario that includes private cloud, public cloud, and on-prem things. If a feature could cover all three different types of deployment, that could probably make it even more desirable for clients.

View full review »
reviewer1432929 - PeerSpot reviewer
Network Security Engineer III at Choctaw Nation of Oklahoma

This is a tough one because it has a lot of good features.

I think that the rate of false positives can be improved. I would like a FireFlow or packet-tracer-like capability at a lower licensing level.

I liked the additional capabilities for an analyst or lower-level network admin or service desk tech to be able to check the rules to see if there is something blocking the traffic. However, I was not able to get the licensing approved above just FA.

I like the training available as it is very informative, but, I wish it was just available from YouTube and I could easily play it from my cell phone without additional logins.

View full review »
Sergi - PeerSpot reviewer
Service Delivery Manager at Schneider Electric

What the technical teams report to me is that the network maps are a concern and should be improved. It would be easier if the network maps could be updated using the GUI portal instead of from the OS. This would benefit the operations teams working daily with this tool.

In the end, we are striving to improve efficiency, and taking into account that Operations are really under pressure from SLAs to keep support ticket queues clean, and with the least amount of backfill possible, it is key to get better tools that make it easier and faster to update the network maps.

View full review »
IM
Global Network and Security Team Leader at Ormat Technologies Inc

The pricing structure is not good because there is no difference between a Data Center firewall for a small branch. The pricing for smaller installations should be lowered because sometimes there is just no ROI to add AlgoSec to the small branch offices with only 10 rules.

View full review »
MK
Key-Account-Manager at DATAKOM Gesellschaft für Datenkommunikation mbH

It is always possible to improve the product.

We would like to have a kind of "Time Capsule" to be able to restore to a certain state from a backup.

We would like to have a BSI Compliance Report for Germany.

Interfaces are worked on continuously, and small firewall manufacturers such as Sophos should still be included as standard.

View full review »
reviewer1114632 - PeerSpot reviewer
Works at a maritime company with 10,001+ employees

Some UI experience is a little clunky (for e.g. MAPS module) and could be made more user-friendly.

We experienced some initial challenges with technical support, although this considerably improved once the teams got to know one another.

The API support isn't as versatile as we would like it to be. It needs more integration.

View full review »
reviewer1000023 - PeerSpot reviewer
Works with 10,001+ employees

Although I'm very satisfied with the product, one of the ways of improving the product could lie, perhaps, in the acceleration of the analysis process and especially in the section — traffic simulation query.

Another improvement would be the support of an orchestration of different firewalls in a heterogeneous environment, mainly at the level of the management of the objects so as to have a homogeneous nomenclature.

View full review »
AJC-2000 - PeerSpot reviewer
Security Consultant at Total System Services, Inc.

I look forward to cloud service integration, which is coming in future releases and this should help make the product more of a complete solution. I would also like to see AlgoBot integrate with other communication systems such as Rocket Chat.

View full review »
KK
Client Manager - TE Services at NTT Security

There could be certain improvements such as supporting secure email. We have some cases where the client SMTP /POP email system is discarded, which is very important factor change notifications.

Fireflow workflow rule/change implementation for time-based rules is not currently supported. 

These improvements in upcoming code will definitely help with end-to-end firewall rule implementation. 

NAT rule implementations were in the roadmap. We are expecting this soon. 

Certain optimization of AFA/AFF SMS resources would ease daily operations.

View full review »
SS
Business Development Manager at Vibs

The blacklisting and whitelisting of IP addresses should be improved. There are many false positives.

The cloud migration process should be more streamlined for my customer-facing issues.

The price should be less. The customers who have just started using the AlgoSec firewall management tool, as of now, have not faced any major issues apart from some small debugging. 

Improvement can be done in many areas. For example, it would be great if AlgoSec could integrate with an endpoint solution and directly integrate with firewall and endpoint solutions to bring much more visibility.  

View full review »
Paltxe - PeerSpot reviewer
Network Engineer at Schneider Electric

It would be very helpful to have a direct link to the relevant firewall policy embedded within reports when there are warnings or risks indicated. Regardless of how serious the risk is, we could jump to the policy with a single click. In this way, the administration would be much easier and we would not have to be changing the screen every time we want to look at or modify something in our firewall. I understand that they are third-party software packages that can achieve this, but it would be more comfortable to have it integrated.

View full review »
reviewer1112223 - PeerSpot reviewer
Works at a manufacturing company with 10,001+ employees

We have a complaint about the compliance check, in that sometimes we want to keep rules rather than merge them.

View full review »
reviewer946827 - PeerSpot reviewer
Works at a insurance company with 5,001-10,000 employees

I always wanted AlgoSec to support cloud base security firewalls such as Amazon security groups-AWS or Microsoft Azure network security groups. Hoping they will have it ready by end of 2018. 

View full review »
AM
Regional Sales Engineer at RedSeal, Inc.

There are some integration-related issues too. For example, AlgoSec does not integrate with Forcepoint, and Forcepoint Firewalls have become very prevalent these days. They also don't integrate with Aruba devices. So, the integration ecosystem of AlgoSec is very limited, which is also the case with Firemon.

These days, people are looking at products which can visualize not only their firewalls, but also their networking equipment, under a single map. Can AlgoSec do this? Yes, it can, but with very limited capacity. If I try to sell the automation story of firewall management, there are vendors, like Forcepoint, who are not supported, so if a customer has Forcepoint, then I have to straight away walk off. The worst part of the story is they don't have even a roadmap for this.

Another problem with AlgoSec is that it gives you the capability to make changes to hundreds of your firewalls at the same time, but big enterprises have change management policies. Change managers will never allow you to make changes to more than 10 devices at the same time, which is a feature in AlgoSec. Because, what if something goes wrong, then you have to roll back and figure out what caused the impact, e.g., which firewall did not work well. Doing that post-mortem becomes a difficult thing. So, change automation on a firewall is actually defeating the purpose of the change management policies in any organization. If you run a bank, you will not allow anyone to make changes at the same time from a single click for 10 firewalls. The bank will never allow this. So, what is the use of this automation? Even if you are using this automation, you can do it from your native firewall vendor, e.g., Panorama or FortiManager, where everyone has their own cluster managers. At least if something goes wrong, you can still call Palo Alto and tell them you are Panorama has not done the change right, causing you an impact, and this is your Palo Alto firewall. 

In this case, if I have to raise a case first, then I have to call AlgoSec and check why it has not worked. Second, I have to call the firewall vendors that their firewall is not working well, but AlgoSec has done the right job. Handling multiple vendors for such a trivial issue becomes a problem.

View full review »
CS
Sr Technical Consultant at a tech services company with 51-200 employees

If we talk about Cloud and SDN Platforms it support AWS, Azure etc.... 

I'd like to see this solution support some other Cloud platforms as well such as Alibaba and a GCP to give the customer flexibility. 

View full review »
DG
Senior Cyber Security Specialist at Richemont

This solution would be improved if it were able to compare configurations and provide recommendations. For example, suggest cluster members.

View full review »
reviewer1028451 - PeerSpot reviewer
Works

AlgoSec is my favorite tool because it does what it is designed to do and it does it well. The service I've received from their support teams is second to none. They have always successfully answered my questions and solved my problems. So, it is difficult to improve a solid solution but, not everything is perfect. Having executive type reporting capabilities which explain the security posture and scoring to provide to executive management would be a nice feature to add. Reports can be printed, but an executive summary report would be an improvement. 

View full review »
TB
Defensive Security Leader at Stone Pagamentos
  • Support more and more vendors, like minor ones: WatchGuard and others. 
  • Also, it would be interesting if it could analyse iptables and IPFW rules and support migration.
  • Windows Firewall and Forefront would also be nice since we often need to migrate from those platforms and prove the value of the newly installed solutions.
View full review »
it_user369891 - PeerSpot reviewer
Security Architect at a healthcare company with 1,001-5,000 employees

I would say cloud is an area for improvement, but AlgoSec in is that market now, too. I do want to see, however, the ability to set up an instance within the cloud instead of having to use physical appliances.

View full review »
MU
R. Engineer at a tech services company with 11-50 employees

The documentation could be better. 

View full review »
MC
Security Analyst at Ethnos IT Solutions LTD

In late December or early January, we were trying to add another solution, but it wasn't working because there was no support for the version that we were running at that point. After they released the hotfix, that took care of this issue. That particular device was then supported. So, it has been very stable and working fine since then.

View full review »
MG
Lead - Security Infrastructure Consultant at TSYS

The tech support and ticketing system could use some improvement and need more of a personal touch.

View full review »
David Ord - PeerSpot reviewer
Works at Enbridge Gas

The Network Map is a feature that could use work, it is a big piece but is always a moving target with large routing tables in use and speed of use becomes an issue doing queries. 

View full review »
reviewer0175982 - PeerSpot reviewer
Network & Cloud Security Team Leader at Soitron Siber Güvenlik Servisleri

The simulation can be improved. Networks and interfaces to which the firewall is connected are kept in a visual simulation. The rules could also show us the traffic on these networks in red and green. When we add a rule, we should be able to see what kind of traffic obstruction we can cause and what can be improved. In the next release, it would be fun to visually present the dashboard with animations.

View full review »
NM
Digital Security Specialist at Derivco

There are areas where auditing rule changes are not accurate. It is important to be accurate when using rule changes, as users need to be accountable for their changes; however, I cannot trust AlgoSec when rule changes come through on reports as they reflect incorrectly. I have taken this up with support and have never really had a resolution for this. 

I would like to see enhanced dashboards or build meaningful reports for executive consumption. 

AlgoSec is a fantastic product, and I would like to see more "granular" breakdowns of traffic on IPT traffic analysis for source and destination, as the way it does it currently does not allow me to self problems for rules with ANY in the destination.

View full review »
reviewer1433391 - PeerSpot reviewer
Network and Security Engineer at Inmarsat

Nothing comes to mind in terms of things that need to be improved.

In terms of additional features in the next release, more integration with SD-WAN would be valuable.

I would also like to see more integration with Cloud security products and services but overall, the product compatibility and integration with multi-vendor and differing platforms/environments is pretty comprehensive. That said, with the fast-moving nature of SD-wan and Cloud Security, product features and enhancements will need to keep pace because clearly, Cloud Security is where the industry will be focusing. 

View full review »
reviewer1113381 - PeerSpot reviewer
Works at a manufacturing company with 10,001+ employees

The reporting portion is weaker than other competitors, although this is good enough to utilize in our environments.

Enhanced integration via API (typically, this is only known by few AlgoSec users).

The user interface could be a little more user-friendly. Other competitors have more of a dashboard look and feel. With AlgoSec, you have to launch new windows to see rule usage reports. It can be a little bit difficult when trying to find more information.

View full review »
RM
Works

This product could be improved in several ways, including:

  • More device support - such as barracuda devices
  • An automated rollback process and options in active push. when we do a active push Algosec takes a policy backup for recovery purpose. if we did any change using active push from Algosec and if the customer wanted to rollback the particular configuration, better if Algosec able provide automated rollback process through AFF rather creating a manual a ticket. 
  • Software-defined WAN integration and support 
  • Application-aware policy identification and optimization - now a days most of NGFW are creating applications (such as Salesforce, Skype for business etc..) aware policies using their application database. normally destination object will be these applications and not the legacy objects that we created in firewall. if Algosec able to understand these application it will be good move for future market. 
View full review »
it_user818859 - PeerSpot reviewer
Works with 1,001-5,000 employees

Product has improved quite a bite in the years we have been using the product. We look forward to completing the AlgoSec Fireflow implementation and piloting the Business flow product.  AlgoSec continues to improve their product every year. 

View full review »
it_user808863 - PeerSpot reviewer
Expert Tehnique securité réseau at a pharma/biotech company with 10,001+ employees

Improve the dashboarding capability for FireFlow which is currently very limited in terms of presentation and customisation. 

View full review »
DR
Technical Architect at a manufacturing company with 10,001+ employees

I believe the customization of dashboards should be simplified and more user-friendly. Customization inside the domain level needs to be improved.

View full review »
VZ
Chief Technology Officer at Accord Group

We see a very high demand for using containers and Dockers and therefore there is a need for managing access control to these platforms. I checked AlgoSec’s roadmap and, for now, there are no plans for developing these features.

View full review »
reviewer1173033 - PeerSpot reviewer
DevOps Engineer at a tech company with 10,001+ employees
  1. AlgoSec support needs improvement, and support needs training to better understand customer issues. ( Support team repeatedly fails to understand the customer issues, Response to the support ticket based on the severity is very poor, support team responses to severity 1 or 2 tickets are very very slow. Customer support representative need training on how to handle severity 1 or 2 tickets)
  2. Integration with other appliances needs improvement. ( AlgoSec integration with other ticketing systems like Service Manager / Service now is not good, It needs to have better integration with ticketing systems like Service Now and Atlassian JIRA)  
  3. Documentation needs improvement. ( There is lack of documentation integration with other ticketing systems like HP service manager, Rest APIs, SOAP)
  4. There are limited sets of Python API calls, so they need to add more features in the API.
  5. The FireFlow template does not allow the user to perform external actions like sending an email or triggering a specific action. It needs improvement there.
View full review »
WP
Global Network Solution Architech at AXA Tech
  • It needs better API integration with its third-party firewall management.
  • It needs support for its cloud-based solution.
View full review »
it_user859881 - PeerSpot reviewer
Director of Cybersecurity

A modernized GUI would be a nice feature upgrade. The GUI looks a little outdated. 

There are a lot of updates for the product which have been good. However, it is a pain to always have to upgrade the product. 

View full review »
Zufayri Zaidi - PeerSpot reviewer
Security Analyst at AceTeam Networks

AlgoSec's audit management is not good enough and can be improved. Also, AlgoSec should be made more scalable.

View full review »
it_user877515 - PeerSpot reviewer
Sr Firewall Engineer at a tech consulting company with 1,001-5,000 employees

We are still waiting to implement FireFlow, and getting it into place will hopefully speed up our implementation time and help with policy standardization. There have been some difficulties in getting this portion set up in our environment.

View full review »
it_user818688 - PeerSpot reviewer
Works at a insurance company with 10,001+ employees

The Flash to HTML5 rewrite has been bumpy. However, as a security professional, I appreciate the improvement in the product.

I am optimistic about possibly moving beyond AFA to other products.

View full review »
reviewer1278546 - PeerSpot reviewer
Senior Network Engineer at a energy/utilities company with 1,001-5,000 employees

There are sometimes issues with the Risky Rules reports where the number of hits is registering zero, but we know that this is incorrect because we have checked the rules and see that they are indeed registering traffic.

Sometimes the Trust setting on Firewall rules is changing to trusted by itself.

View full review »
NetworkAdmin - PeerSpot reviewer
Network Engineer at Ti Automotive

The GUI has not been upgraded for a long time and could use updating.

View full review »
reviewer1006992 - PeerSpot reviewer
Works at a tech services company with 10,001+ employees

I think that AlgoSec could improve the application by improving the treatment speed.

If AlgoSec could make few seconds less to analyze research, theses few seconds will be used by my team to be more efficient.

I mean, in the Traffic Simulation Query, it will be wonderful if Algosec could find a way to make the research faster than now. In fact, we are often waiting arround 1,30 min to see the results.

Maybe something can be done to make this reasearch faster?

View full review »
reviewer1003116 - PeerSpot reviewer
Works with 10,001+ employees

The versioning is a bit weird. We used to use version 2017 which is quite current, but it looks like it is a 2017 version. As far as I know, they want to have this changed soon. Nevertheless, this is something which definitely needs to be improved.

View full review »
it_user866376 - PeerSpot reviewer
Senior Network Security Engineer at Prudential Corporation Asia

ABF needs to be more integration with AFF/AFA. We needs object level permissions and application level recertifications.

View full review »
FB
IT Security Analyst at a tech services company with 1,001-5,000 employees

In our environment, we add rules in the firewall based on user logins, but currently, we can't do that with AlgoSec. AlgoSec can't create rules based on user logins. For example, generally, when we create a rule, we put IP Address, Destination IP Address, and Service Port. However, in our environment, we put IP Address, User Login, Destination IP Address, and Service Port, but AlgoSec doesn't support a rule in this format. We opened a ticket regarding this with their support two months ago, and they said that they will be able to add it in the future, but they don't know the timeframe. We are currently in the process of making changes in our environment for such rules, and after two months, we won't be using the rules that are based on user logins. We will make them consistent with the market, and we will use only the IP Address, Destination IP Address, and Service Port for rules. So, it won't be a problem for us, but this can be an improvement for other clients.

View full review »
RD
Senior Security Analyst at Compugraf

I would like an analysis to be created for user group rules (Check Point - identity awareness). 

Current versions of AlgoSec do not perform analysis of Identity awareness (Check Point). It would be important for the user to be able to request a rule by an access role group and then AlgoSec would create this rule automatically in the firewall.

An improvement in tool performance would be important. Environments with many devices need a lot of hardware resources to avoid slowdowns. Memory consumption of the server is very high.

View full review »
Paulo Ataides - PeerSpot reviewer
Senior Information Technology Security Analyst at a integrator with 1,001-5,000 employees

I would like to see support more technologies, but I know that AlgoSec is always in the process of evolution.

Perhaps a better financial option would allow customers to choose the complete solution. In an environment that is very large, with many firewalls and routers, it is sometimes impossible to buy all of the licenses. This makes the AFF solution impossible.

View full review »
FB
Network & Collaboration Engineer at a financial services firm with 1,001-5,000 employees

The product should support more vendors with the same in-depth analysis that it already is providing. This would give more reasons to for other companies to adopt it and make us preserve the investment in case we change the running environment.

View full review »
reviewer1115961 - PeerSpot reviewer
Works at a maritime company with 10,001+ employees

In terms of integrations, we would like to see a greater number with the upcoming and next-generation tools (i.e. SOAR and a selection of other SIEMs). This has been a problem for us, as we are going through the process of enhancing our security and some of the products we are looking at are lacking built-in support (integration). 

View full review »
JC
Works

The product has a lot of great features already. However, I would like the reporting to be more customizable, as per user and auditing needs.

View full review »
reviewer1019766 - PeerSpot reviewer
Works at a manufacturing company with 10,001+ employees

Ability to manage more diversity of equipment, as well as simplify the management of the various workflows.

View full review »
it_user859899 - PeerSpot reviewer
VP Global Cyber Security Operations at NTT Security
  • I would like to see continued expansion to other firewall versions, platforms, and vendors. 
  • I would also like to see continued work on the roadmap.
View full review »
it_user829395 - PeerSpot reviewer
Senior Software Engineer at a energy/utilities company with 10,001+ employees

Having the ability to patch an issue as oppose to upgrading the entire suite.

View full review »
it_user808449 - PeerSpot reviewer
Extranet Architect with 1,001-5,000 employees

Integration to cloud ITSM tools, such ServiceNow.

Be able to automatically analyze application traffic with machine learning capabilities and propose simplification for rule set optimization.

View full review »
it_user454551 - PeerSpot reviewer
Cyber Security/ Network Intelligence Professional at EliteVAD

Automated policy push for the Fortinet product family. The Active Change/Automated Policy push feature is already there for all other leading devices such as Cisco, Check Point, Juniper, and Palo Alto, etc.

View full review »
OA
Presales Engineer at a tech services company with 11-50 employees

AlgoSec integrates with most of the leading firewall vendors, but one issue is that AlgoSec doesn't support Sophos and Forcepoint. AlgoSec competitors, like FireMon, support Forcepoint. I have told AlgoSec a number of times that we have many customers that use Forcepoint. I have asked why they don't support integration with Forcepoint. They have said they don't care about Sophos, Forcepoint, and SonicWall. They don't consider those vendors to be leaders in the firewall market and they don't have plans to support them.

View full review »
SS
Sr Technical Consultant at a tech services company with 11-50 employees

I would like more documents and support for the cloud firewall.

View full review »
reviewer1242069 - PeerSpot reviewer
Works at a sports company with 1,001-5,000 employees

I would be nice to have a good tool for network map discovery in the GUI to make it more user friendly and be able to check and modify network maps in graphical and more intuitive way . This will improve our network overview for new deployments and troubleshooting. 

View full review »
JS
Works at a wireless company with 10,001+ employees

I believe Active Change needs to be improved because not all products are supported, and some functions cannot be implemented by Active Change either.

Technical support needs to find solutions more quickly.

Active Change could implement routes in Firewalls, it should also be able to perform the creation of APP control and URL filter rules.

View full review »
it_user1098237 - PeerSpot reviewer
Network and Security Engineer at Euronext Technologies

The product is severely lacking in vendor support. They claim to support some devices, but when you dig deeper, it is only basic support, with enterprise-grade features for those devices being unsupported. This is a big deal for us, as several sections of our network are not fully supported which, in turn, does not allow us to fully automate rule creation. Moreover, we cannot perform end to end connectivity checks. One such feature is the lack of VRRP support on devices other than Cisco or Juniper, which causes the software to interpret a non-existent router as the next hop for a particular flow (the VIP address of the VRRP).

View full review »
IS
Security Operations Engineer at a security firm with 201-500 employees

AlgoSec should be optimized. There is a lot of RPA and we have scripts in AlgoSec that need recertification. With AlgoSec Firewall Analyzer, we can see lots of objects and lots of rules that tell us we need to clean the equipment. It will give us a solution but it doesn't always work. The solution that it gives us is not always accurate from the scripts.

For example, because we have a workflow, when the user creates his ticket, the ticket was automatically dispatched to different teams. We have a security team and another team to implement and push the rules. The ticket automatically will get sent to the wrong team and then we need to send it back to the user for them to update. 

View full review »
reviewer1126863 - PeerSpot reviewer
Works with 10,001+ employees

The user interface is better than some competitors, but it is starting to get old. Space is not always fully used, especially for the risk and compliance part. As example today, Excel file should be used to deal with network segment definition and risk matrix, it is hard to do it directly from user interface and there is no way to organize, order a set of test.

Priority should be to improve the user interface for the risk and compliance part, making it more responsive and user-friendly.

View full review »
reviewer947805 - PeerSpot reviewer
Works at a insurance company with 1,001-5,000 employees

I think the product is great from an overall observation, sometimes speed is an issue but I think it could be improved a little bit from a parsing perspective.

View full review »
MR
Freelance System Security Consultant at a consultancy

They need to improve auditing of IP tables, as only monitoring them does not reduce their vulnerabilities.

View full review »
JM
Network Security Engineer/Architect at Euronext Technologies SAS

In our case it would be very important to improve support to Dell switches and also some Juniper switches, which we have a lot of in our company network. This has been our difficulty for the full automation on the Fireflow. If all our network devices were Cisco I'm sure we would have the network map complete very easily and the full automation working with much less effort.

We already asked Algosec for the support of the switches we have that are not natively supported for the future versions and we expect that we are lucky enough for them to be supported on the next releases, although there are some ways of working around non-natively supported switches to complete the network map.

View full review »
GR
Senior Network Security Engineer at a tech services company with 1,001-5,000 employees

Support tickets and engineer assignments are one of the few concerns we are facing these days. Initially, they were hard to co-ordinate with the technical support team and the AlgoSec management team helped us to follow the defined Service Level Agreements.

We needed to directly communicate with the integrated solution TAC Teams, let say of Palo Alto or Checkpoint, and we needed to co-ordinate jointly for addressing an issue.

The AlgoSec support team came on a joint call to address the issue on time without saying "this is not my cup of tea" and by then we were happy about the support. This happened during one of our major migrations.

Our management is expecting us to set up a CXO/CISO dashboard from AlgoSec. It would be great for us if the AlgoSec team could assist in setting up the new benchmark.

View full review »
OO
Deputy CISO/ Security Architect at a financial services firm with 5,001-10,000 employees

The product or service could be improved by orchestration or automation that will help in changing the rule sets on the firewalls based on the detected used services/ports and IP addresses. 

View full review »
AndyWodzien - PeerSpot reviewer
Network Engineer at WPPI Energy

The only thing I had slight issues with is the web UI which is a bit tricky to navigate. It can be difficult to find what you're looking for without having to click around for a bit, but once you get to know where things are, it's not bad.

View full review »
it_user495018 - PeerSpot reviewer
Sr. IT Security Engineer at a pharma/biotech company with 10,001+ employees

It is currently unable to export the report to a CSV file, and I look forward to seeing it in the next version/release.

View full review »
reviewer1275342 - PeerSpot reviewer
IP network expert at a comms service provider with 201-500 employees

I would like to be able to see what objects have the same IP, but different names in different firewalls. Since the system is able to show all of the objects for the integrated devices, it can be confusing if one particular object (eg. IP address/host) has different names in different firewalls.

View full review »
BW
System Engineer at Dimension Data

The MAP has a persistent issue with a firewall that is using a double BVI (Bridge Virtual Interface). In this configuration, it cannot give the correct and proper topology, so the traffic simulation query cannot run properly between the source and destination.

View full review »
Olivier Beytrison - PeerSpot reviewer
System Architect at HES-SO//Fribourg

We use the "rules change notification" feature to inform the different firewall managers when someone made a change. The actual change comes in a PDF file attached to the e-mail, while it would be faster to have it directly embedded in the notification mail.

Depending on your network topology, the traffic simulator might have some hard time tracing the traffic path between your devices correctly. This has already been improved in the past but could still be enhanced.

View full review »
MH
Technical Manager at Global Technologies for Trading and Contracting

I would like an intelligent tuner where it could help update rules with the application ID.

View full review »
NN
Technical Director at Keystone Solutions, Inc.

Based on the conference I just attended, it is improving by Algosec opening their API more. This allows us as a systems integrator to give more value to our clients. We will be able to integrate more things that do not come out of the box.

View full review »
it_user552438 - PeerSpot reviewer
Technical Consultant at a tech services company with 10,001+ employees

Additional understanding of complex routing in multiple systems.

View full review »
it_user494187 - PeerSpot reviewer
Security and Network Architect at a tech services company with 10,001+ employees

A lot of areas have room for improvement!! This product is still young and in constant development. Interaction with a lot of vendors generates a lot of firewall options (specifically, a timer on services, application control, and so on...). This interaction also generates a lot of bugs in the product. Every new version contains about 10 to 20 bugs for our environment. This is partially explained by the fact it has to understand all of the architecture and specificity associated with all of the supported vendors.

A few of the bugs are:

  • Services composed with something else other than TCP or UDP are not well-handled and not working in simulation queries. (For example, AH or ESP or EthernetOverIP.)
  • Traffic with same objects in source and destination are not working.
  • When NAS is used to store reports, we have had a lot of bugs associated with wrong URL encoding.
  • Role assignment with multiple LDAP issues.
  • Some file cleanup not working as expected.
  • Active change is available for only a few vendors.
  • BusinessFlow doesn't offer auditing regarding object management and with a lot of application and managers, it quickly becomes an issue with duplicated objects and so on.
  • There are also gaps in access right management.
View full review »
it_user813339 - PeerSpot reviewer
Engineer

It would be great if the product could be more simplified when defining the rules.

Documentation could be added to the tools, then generate documentation and send it to the relevant people.

View full review »
it_user494916 - PeerSpot reviewer
Network Security Engineer at a financial services firm with 5,001-10,000 employees

Validation: Many times I have to generate a report to validate tickets. When I try to verify an AlgoSec ticket that has been implemented, I have an option to validate the work I did. Many times, it has not worked immediately. I have to generate a report based on which I can check my work.

After implementation new rules on firewall algosec is not immediately aware about it. I have to make synchronization between algosec and firewall. In algosec is called analyze firewall. It is possible schedule this analyze more often but it consuming a lot of device resources like CPU, memory etc so I have this analyses one per day. After this analyze I am able make validation of implementation which I did because algosec can see rule which I added.

View full review »
HF
Software Developer at Vivo (Telefônica Brasil)

I would like to seem improvements in performance and software stability.

View full review »
reviewer1112214 - PeerSpot reviewer
Works with 10,001+ employees

The risk matrix implementation is not easy from an Excel file, so it would be nice to have a solution for creating it directly within the web interface. This would be an improvement.

View full review »
reviewer877923 - PeerSpot reviewer
Account Director

Further integration with ACI and NSX will be key to our customers' requirements moving forward, as customers adopt new, innovative environments.

View full review »
it_user827928 - PeerSpot reviewer
Network Support

The product could be improved by adding additional tools for troubleshooting, not only for the firewall, but for other devices like switch and dynamic routing display. Also, it would be good if it could retrieve all information regarding Cisco Nexus switches and devices.

It would be interesting if the product could automate the switch configuration and create a dynamic map of the entire network.

View full review »
it_user268725 - PeerSpot reviewer
Sênior Network Security Administrator at a government with 1,001-5,000 employees

The product needs improvement in all areas, but I don't use the product deep enough to say anything more specific.

View full review »
Security-Architect-Lux - PeerSpot reviewer
Works at POST Luxembourg

The production needs to be smarter and maybe have some AI capabilities to provide better firewall optimization and workflow integration.

View full review »
it_user813291 - PeerSpot reviewer
Networks and Security Engineer

Automate the change documentation in MS Word format. Therefore, we can customize it, if needed.

View full review »
it_user281946 - PeerSpot reviewer
Network Design/Network Security Administrator at a financial services firm with 1,001-5,000 employees

It would be nice to have it integrate with the existing change management portal.

View full review »
it_user810882 - PeerSpot reviewer
Programme Manager

Today, we don't dare push the new policy automatically, We don't have confidence in this feature.

View full review »
it_user284391 - PeerSpot reviewer
Senior Network Security Specialist at a tech vendor with 10,001+ employees

It would be nice if it was more variable when checking virtual domain baseline in the same way as Fortigate's firewalls do.

View full review »
MM
Presales Manager at SEFISA
  • The reporting could be a bit better. 
  • FireFlow was a bit tricky to configure with its customized flows. Maybe the latest release will resolve this.
View full review »
it_user541044 - PeerSpot reviewer
Works at a tech company with 51-200 employees

AlgoSec should support these features:

  • Expired time should be one of the components of firewall rules, not only source, destination
    For example: Now, in Algosec Fireflow, when creating a change request, there are only 3 component: Source, Destination and Service. I want to have expired date of the traffic
  • Detect duplicate objects in different firewalls
    Now, Algosec can only detect duplicate object within one firewall. I want to detect in different firewalls
    For example: firewall 1 has objet A with IP address 1.1.1.1, firewall 2 has object B with also IP address 1.1.1.1. I want Alogsec to detect this duplication
  • Show IP address of object in a report, query result
    Now, in report, query results, Algosec only displays name of the objects. I want to display IP address of these objects
View full review »
it_user502044 - PeerSpot reviewer
Senior IT Security Consultant at a tech services company with 501-1,000 employees

* More unified UI

View full review »
it_user457512 - PeerSpot reviewer
Information Security Manager at a financial services firm with 10,001+ employees

Needs continuous improvements in all areas since firewall vendors are improving their products and the IT security industry is definitely improving itself.

View full review »
it_user300489 - PeerSpot reviewer
Network Engineer at a tech services company with 10,001+ employees

The reporting features need to be improved.

View full review »
it_user272901 - PeerSpot reviewer
Network Administrator at a computer software company with 501-1,000 employees

The reporting feature needs work.

View full review »
reviewer1068567 - PeerSpot reviewer
Works with 51-200 employees

There is room for improvement in the rollback process.  

What we would like to see in the future is related to support. For integration with newly supported devices, we require a proper support matrix with an escalation process.

View full review »
it_user872862 - PeerSpot reviewer
Security and Network Consultant at a tech vendor with 51-200 employees

Needs better integration between modules and also a better troubleshooting methodology. There are still a few improvements to be done in the user interface.

View full review »
it_user502071 - PeerSpot reviewer
Network Technical Security at a tech services company with 501-1,000 employees

We have requested improvement to VRF functionality on Cisco IOS and Nexus L3 devices and to support Juniper routers.

We have discovered that AlgoSec doesn’t work with loopback interfaces. We use OSPF and BGP, which run over multiple Virtual Routing and Forwarding (VRF-Lite) instances and, in some cases, distributors are connected to the core via loopbacks routed by an OSPF instance and a BGP address family. AlgoSec doesn’t recognize those loopbacks as a route, so it doesn’t find a route to the destination. This behaviour makes the “traffic simulation query” feature unusable in our environment.

View full review »
it_user540339 - PeerSpot reviewer
Security Specialist with 1,001-5,000 employees

The Tighten Permissive Rules Function could be better, we need more specific information about source, destination and service on the rule we will handle.

View full review »
JV
Cyber Security PreSales Engineer at a comms service provider with 10,001+ employees

The UX control panel is in need of improvement.

View full review »
it_user960087 - PeerSpot reviewer
Security Architect, InfoSec at Euronext

The reporting component of AlgoSec Firewall Analyzer is something that, in my view, has room for improvement.

It will be welcome in a future version the possibility of having greater granularity, for example when defining the information that we want to see in the reports, to define customized reports by group / user and to make a scheduled sent of the reports.

Being more specific, in our use case for operational teams the report to send would only be the summary of changes of all the rules of a day by Firewall. Focused, without adding unnecessary information.

Other use case is for GRC teams. The report to send should only be the summary of risk changes of a week or a month, per Firewall. Again focused, without adding unnecessary information.

View full review »
JF
Security Analyst at a financial services firm with 201-500 employees
  • The font size on the Changes Summary Report is very small when reading the print out copy. 
  • AlgoSec can look at ways to include a change management workflow process or integrate with third-party ticketing solutions. 
  • Explore ways to detect unused port numbers per firewall rules.
View full review »
it_user456096 - PeerSpot reviewer
Network Engineer at a comms service provider with 1,001-5,000 employees

In our experience, AlgoSec need to improve the integration of firewall vendors, because at the moment they don't support all vendors that are out there. 

Algosec Firewall Analyzer has a feature called 'Implement on device' which automatically creates access rules based on your request and sends it to the appropriate device. At the moment, this feature can not be implemented on Fortigate firewalls or Juniper EX switches which act as a layer three device with ACL's etc. I mean they need to improve interoperability with more vendors in order to automate access rules modification on these unsupported yet equipment.

View full review »
it_user497694 - PeerSpot reviewer
Network Security Engineer at a aerospace/defense firm with 1,001-5,000 employees
  • Filtering in the reports
  • Adjusting parameters for reports
  • To be able to generate custom-made reports

For example, it would be nice if you could define a report to show the unused objects for a specific timeframe. Now, it’s for the whole log period. Or, another example would be: deny rules that have been adjusted in the last 90 days.


View full review »
FB
Network Expert at a integrator with 1,001-5,000 employees

They can make some improvements to the user interface because it can be slow at times.

View full review »
KK
Technical Presales Engineer at Exclusive Networks

I would like to suggest that cloud visibility feature is provided in the next release. We would be able to understand how traffic flows from the source to destination.

View full review »
it_user540387 - PeerSpot reviewer
Information Security Consultant at a tech company with 51-200 employees

One scope of improvement is to create an architecture diagram that combines intelligence from all integrated firewalls.

View full review »
it_user494103 - PeerSpot reviewer
Information Security Analyst, Team Lead Network Security Assesment at a financial services firm with 1,001-5,000 employees

The product has several compliance checks built in for PCIDSS, ISO, SOX, etc., and also a baseline security policy. It would be nice to allow customers to build their own policy, based on the customer’s own customization and business needs.

View full review »
it_user270741 - PeerSpot reviewer
Information Security Engineer at a tech services company with 1,001-5,000 employees

It needs to improve in all areas.

View full review »
it_user541047 - PeerSpot reviewer
Works at a tech company with 51-200 employees

Find duplicate objects in different firewalls.

View full review »
it_user302103 - PeerSpot reviewer
Network Security Engineer at a tech services company with 1,001-5,000 employees

The regulatory compliance rules.

View full review »
Buyer's Guide
AlgoSec
April 2024
Learn what your peers think about AlgoSec. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,578 professionals have used our research since 2012.