Most Helpful Review
The most valuable feature is the IPsec VPN.
The Smart Dashboard and other user interfaces are very easy to use and can be handled without any significant IT skills.
After introducing this NGFW, we have improved our security posture, and now, have peace of mind.
It filters unwanted traffic.
It integrates well with Fortinet and Palo Alto.
It uses many applications, like antivirus blocking and web filtering.
The high availability of the application is good.
It protects the data behind our switches.
It helps us perform our daily jobs.
We mostly use the Layer 4 firewall functions: Access rules, NAT, and site-to-site IPsec VPN.
Juniper has the "recovery safety feature", so if you perform a "commit confirmed" and the new configuration disconnects you. then there is no "confirmed" command with X mins (default = 10 mins). It automatically reverts (recovers) to the previous configuration. This is handy for when you do not want to make that trip down range just to reboot a router.
Using a Juniper CLI, you configure a "candidate configuration", then "commit" it to bring it live. If you do not like it or messed up something, you just "rollback" to the previous configuration. It can all be done in a matter of minutes. This is super handy once you get use to it.
Check Point Smart Dashboard does not support my Apple MacBook Air. It only supports Windows versions.
Check Point Smart Dashboard does not support my Apple MacBook Air.
We looked very closely at ArcSight's solution because it's a multi-vendor solution. With ArcSight we could have Check Point, we could have RSA, we could have any brand and integrate several brands, from a security point of view. With Check Point, you cannot do so, you can integrate with Check Point products.
There are some issues compared to other products. Ease of use is one.
Stability issues. I built out this firewall in a cluster, and I had stability issues day one. Needs to be rebooted frequently. Tunnels need to be bounced frequently. Their hardware compatibility guide, when I built out the servers to host them on, was not accurate.
The CLI is verbose. You have to say a lot to do a little. I don't like that part of it. Cisco's command syntax seems to be a good bit more concise. When you're trying to get something done, you don't want to have to type a bunch.
Juniper needs to focus more on their perimeter firewalls.
The GUI needs to be easier to handle.
I would like to see endpoint control and endpoint testing security.
I would like them to add a dashboard because it's difficult to operate.
The product only has basic features.
It needs better interoperability with Cisco gear.
Third-party support for Juniper is a lot less than Cisco. This is no surprise, but a definite consideration if you are expecting to use a lot of third party support. In my guesstimate, for every 100 Cisco shops, you will find one Juniper shop.
Pricing and Cost Advice
Check Point solutions are very expensive here. They're good, but they're expensive... Check Point is only useful for customers that have a big IT budget.
I don't think the product's pricing is a good value. I feel it's very overpriced. I feel a lot of the features for a next gen firewall are there. But I feel it's overpriced, because of the stability issues. As far as support goes, I really can't speak to direct Check Point support, but the third-party was pretty terrible... As far as the licensing goes, it's pretty complex. If anybody was to purchase the Check Point product, definitely make sure they have an account rep come on site, and explain it line by line, what each thing is. It's not straightforward. It's very convoluted. There's no way you could just figure it out by looking at it.
It has a low price.
It is not that expensive.
Pricing is good. Most of the costs are in the UTM (IDS/IPS, virus scanning, etc) subscription.
Palo Alto was nice, but much more expensive.
We were able to lower our overall operating costs over a three year period by 25%, mostly recovered from maintenance/support costs.
Small enterprises or telco have variant licenses, and this licensing should be improved.
I would say about $20,000 for a SRX650 with IDP licence.
Pricing is very good, not expensive.
|Top Comparisons||See more Check Point Next Generation Firewall competitors »|
Compared 31% of the time.
Compared 23% of the time.
See more Juniper SRX competitors »
Compared 10% of the time.
Also Known As
|Also Known As||Check Point NGFW||SRX|
Your network is under constant threat. To secure it, you need the most advanced firewall protection. Check Point Next Generation Firewall identifies and controls applications by user and scans content to stop threats.
|High-performance security with advanced, integrated threat intelligence, delivered on the industry's most scalable and resilient platform. SRX Series gateways set new benchmarks with 100GbE interfaces and feature Express Path technology, which enables up to 1 Tbps performance for the data center.|
Learn more about Check Point Next Generation Firewall
Learn more about Juniper SRX
Information Not Available
|7-Eleven, AARNet Pty Ltd, Allegro Networks, alltours GmbH, Apollo Hotel Papendrecht, Armstrong Atlantic State University, Atlantech Online, Availity, Bajaj Capital, Baloise Insurance, BancABC, BAS Group, Black Lotus, Blue Box, Borealis, Carilion Clinic, Catholic Health System, CATV, Champlain College, Chinas Ministry of Railways, China University of Mining and Technology (CUMT), Cloud Dynamics, CloudSeeds, Cloudwatt, CODONiS, Colt Technology Services, Cork Internet Exchange, CSS Versicherung AG, CyrusOne, Danish Crown, Deloitte Belgium, Department of Energy, Divona Telecom, DQE Communications, DreamHost, European Government Agency, Expedient, Financial Market Information Services Provider, Fluidata, Fonality, Fox Sports, Global Financial Institution, Global Investment Bank, Global Investment Company, Energy Sciences Network (ESnet), Goethe University, HEAnet, High Performance Networks Inc., Hillenbrand|
No Data Available
VISITORS READING REVIEWS
No Data Available
VISITORS READING REVIEWS