My main use case for Check Point Application Control is to allow necessary applications while blocking others, ensuring efficient usage.
Check Point Application Control enhances security and productivity by filtering applications through a vast database and granular policies. It optimizes bandwidth and improves compliance, offering real-time visibility and automatic updates.



| Product | Mindshare (%) |
|---|---|
| Check Point Application Control | 5.6% |
| ThreatLocker Zero Trust Platform | 17.2% |
| Zscaler Zero Trust Exchange Platform | 11.9% |
| Other | 65.30000000000001% |
| Type | Title | Date | |
|---|---|---|---|
| Category | Application Control | Jun 22, 2026 | Download |
| Product | Reviews, tips, and advice from real users | Jun 22, 2026 | Download |
| Comparison | Check Point Application Control vs ThreatLocker Zero Trust Platform | Jun 22, 2026 | Download |
| Comparison | Check Point Application Control vs WatchGuard Firebox | Jun 22, 2026 | Download |
| Comparison | Check Point Application Control vs Zscaler Zero Trust Exchange Platform | Jun 22, 2026 | Download |
| Title | Rating | Mindshare | Recommending | |
|---|---|---|---|---|
| Zscaler Zero Trust Exchange Platform | 4.2 | 11.9% | 98% | 68 interviewsAdd to research |
| WatchGuard Firebox | 4.2 | 9.8% | 93% | 138 interviewsAdd to research |
| Company Size | Count |
|---|---|
| Small Business | 21 |
| Midsize Enterprise | 17 |
| Large Enterprise | 11 |
| Company Size | Count |
|---|---|
| Small Business | 146 |
| Midsize Enterprise | 34 |
| Large Enterprise | 51 |
Check Point Application Control provides organizations with a powerful tool for managing application access and usage efficiently. Its integration with Active Directory facilitates the creation of user group-based policies, enhancing security measures. By employing real-time visibility and automatic updates, it ensures that only authorized applications are operational, optimizing bandwidth and boosting overall productivity. Its deployment is straightforward, which aids in customizing access controls to meet specific requirements.
What are the key features?Check Point Application Control is widely used in industries to bolster security by implementing granular application and traffic control. It prevents unauthorized application access and efficiently manages bandwidth while helping maintain compliance. Companies leverage it to mitigate risks by blocking high-risk applications and monitoring usage to align with regulatory standards, thus enhancing productivity across teams.
| Author info | Rating | Review Summary |
|---|---|---|
| Network Engineer at ATG Systems | 4.5 | Check Point Application Control improved our productivity by enabling precise app access per user group, reducing IT tickets, and enhancing bandwidth management, though it could benefit from faster updates, easier policy handling, and better analytics. |
| Cyber Security Manager at BT - British Telecom | 4.5 | I've found Check Point Application Control effective for boosting productivity and managing bandwidth, though occasional misclassifications and minor performance lags exist; overall, it's stable, scalable, and provides precise application control with smooth integration and reliable updates. |
| Cybersecurity Analyst at DigitalTrack solution pvt ltd | 4.5 | I've used Check Point Application Control for over three years to manage app access across our network, finding it easy to configure, highly effective, stable, and scalable, with excellent support and clear benefits in productivity and cost savings. |
| Cybersecurity Engineer at a tech services company with 11-50 employees | 4.0 | I've used Check Point Application Control for over two years to manage application access, improve security, and boost productivity, though I find its overlapping network and application policy layers confusing and believe that part needs improvement. |
| Technical Specialist at Wysetek Systems Technologiest | 4.0 | I find Check Point Application Control highly effective for granular social media access, proving very reliable and time-saving. Although its setup cost is high and technical support response for major issues can be slow, I believe it's worth it. |
| Network Security Engineer at Digitaltrack | 4.0 | I've used Check Point Application Control for over two years to manage user web access by department, benefiting from detailed reporting and easy configuration, though older versions impact firewall throughput. I rate it 8 out of 10. |
| Cyber Security Solution Engineer at a computer software company with 201-500 employees | 4.0 | I've used Check Point Application Control for a year to manage web traffic and boost security. It offers strong visibility and bandwidth control, though it could improve analytics, real-time insights, and reduce false positives. |
| Technique at Digitaltrack | 4.0 | I've used Check Point Application Control for over two years to enable user-based policies via AD integration, gaining granular web access control and visibility, though occasionally it misclassifies allowed sites; overall, it's stable, efficient, and time-saving. |
| Inside Sales Manager at Digitaltrack Solutions Pvt Ltd | 4.5 | I've used Check Point Application Control for three years to manage internet access, finding it stable, scalable, and time-saving, with automatic updates and category filtering; pricing could improve for smaller organizations, but overall it's highly effective. |
| Technical Support Executive at Softcell Technologies Limited | 4.5 | I find Check Point Application Control excellent for granular access, boosting security, compliance, and bandwidth by restricting unnecessary apps. Policy management needs app categorization, but its stability and user focus benefits are clear. |

My main use case for Check Point Application Control is to allow necessary applications while blocking others, ensuring efficient usage.
Check Point Application Control has improved our organization by giving us greater visibility into application usage, enabling us to block risky or non-business applications, prioritize bandwidth for critical services, and enforce compliance policies more effectively, which has strengthened overall security and boosted employee productivity.
The best features Check Point Application Control offers are the ability to identify thousands of applications and sub-functions, for example, Facebook Chat or Facebook Post, and user and group-based policy integration with AD, which made it possible to apply different application rules per department or user role. For example, allowing YouTube only for the marketing group, but blocking it for others, and seamless integration with URL Filtering and threat prevention work together with other blades to provide both application control and security against malware or data leaks. Bandwidth and QoS prioritization and the ability to not only block but also prioritize business-critical applications, for example, Office 365 or VoIP, are also standout features.
The granular control offered by Check Point Application Control impacts my daily work and the organization as a whole by allowing our marketing team to access YouTube and Facebook for campaign work while other departments don't have that access. In the past, we either had to block everyone, causing friction and workarounds, or allow everyone, leading to productivity loss and bandwidth issues. With Check Point Application Control, we create a rule that allows YouTube and Facebook for the Marketing AD group but blocks these apps for all other users. Bandwidth for business-critical tools like Microsoft Teams and O365 is prioritized, and this helps us avoid a service impact. Marketing gets the access they need without raising tickets, while bandwidth-clogging from unnecessary video streaming is reduced, leading to fewer complaints for the IT team and better visibility into traffic.
Using Check Point Application Control has definitely improved productivity and saved time for my team. Before implementing the rules, our IT helpdesk was getting 5-7 user tickets per week from employees either requesting access to blocked applications or reporting slow network performance due to streaming. After rolling out rule-based access and bandwidth prioritization, those tickets dropped to 1-2 per month.
Check Point Application Control can be improved with faster updates for emerging applications. While the signature database is comprehensive, new apps or app features sometimes appear before signatures are updated. A faster update process or a community-driven signature model could help keep policies current. Additionally, simpler policy management for large organizations is needed, as the policy interface can feel complex in environments with hundreds of rules and multiple user groups. Features like bulk editing, smart suggestions, or policy templates could reduce admin workload. An improvement in reporting and analytics is also essential, as reports are detailed but sometimes hard to digest at a glance. More visual dashboards, trend analysis, or predictive insights would help the team spot operations and issues faster.
This is my first time using Check Point Application Control.
Check Point Application Control is very stable; I haven't encountered any special issues.
It's very scalable and has shown substantial improvement, making it a trusted solution.
I evaluated other options before choosing Check Point Application Control, and we tried using the Palo Alto firewall.
I have seen a return on investment with Check Point Application Control. Before granular application control, IT support saw 5 to 7 tickets per week related to blocked apps or network slowdown. After implementing rule-based access and bandwidth prioritization, that dropped to 1-2 tickets per month, saving 6 to 8 hours per month for our team. There is also risk reduction, as blocking risky or unauthorized apps, like file-sharing tools, minimizes the potential for data leaks and security incidents. Although it's harder to quantify in dollars, avoiding even a single data breach or compliance violation represents significant cost avoidance.
I can't say much about the pricing, setup cost, and licensing for Check Point Application Control, as I only know what the business management team discusses. Our team is focused on operations and technical aspects, so we're not privy to the detailed setup costs and pricing.
My advice for others looking into using Check Point Application Control is to consider its ability to balance security and productivity effectively.
One of the strongest points of Check Point Application Control is its ability to protect the network without overly restricting users. Granular rules let you target risky apps while still allowing business-critical access. Continuous monitoring and updates through regular reviews of app usage reports and keeping signatures up-to-date ensure policies remain effective as applications evolve. Scalability can be a consideration for growing organizations, as the solution works well for small deployments, but with hundreds of rules or multiple department policy management, it can become complex, so planning and regular cleanup are key.
On a scale of one to ten, I rate Check Point Application Control a nine.

The main use case for Check Point Application Control is to help us in productivity control because from the application control, we can limit the usage or restrict the usage of time-wasting applications, such as social media or other heavy streaming applications. Moreover, we can block risky and anonymizer applications using the application control feature.
For Microsoft 365 applications, it is easier using Check Point Application Control to decide what happens with the data. Earlier there were multiple FQDNs or the updateable objects being used, but now since we have the application control, we can simply call an application and all the dependent or prerequisite URLs get allowed with that.
The best features Check Point Application Control offers include next-gen application visibility with the help of application controls and the sync with the cloud, which continuously keeps track of the application signatures and known applications. Whenever a new application is identified, the signature is embedded into the application control signature database.
The next-gen application visibility and cloud sync features are valuable for us because they allow us to provide granular controls over the traffic that is flowing in and out. Earlier, when we had the visibility up to Layer 4, we could only take action based on the IP addresses and the ports. If we were allowing HTTPS, we would allow HTTPS for all the internet websites. But now with Check Point Application Control, we can specifically control which applications we want to provide access to our internal users and which ones to be blocked.
Check Point Application Control has positively impacted our organization because productivity has increased through putting bandwidth limits and restrictions to non-legit or less productive applications. The people in the organization are bound to have their time diverted towards other productive applications. The bandwidth control on streaming applications was limited, which saves bandwidth for the production workloads, helping to increase efficient communication among the organization resources.
From the bandwidth perspective, earlier there was a specific site where the bandwidth was choking during peak hours. Currently, it is just 70 to 80% utilized even during peak hours, due to implementing bandwidth control policies along with the application control from the firewall devices. This has helped us reduce a load of around 20-30%.
There are some legitimate apps which may be blocked mistakenly if signatures are outdated or traffic is misidentified. A custom business app should be detected as an unknown application and the action should be observe or caution instead of blocking so that legitimate traffic does not get impacted if it goes unidentified due to any reason.
There is some performance lag on the device itself when we turn on Check Point Application Control features. Check Point can do a deep dive to understand how they can improve the performance while we enable the application control feature on all the policies. Something can be done with the underlying architecture or the integration, examining how it is embedded and how the hardware is supporting Check Point Application Control.
If you are enhancing the productivity of the organization and employees, that can translate into money saved. We have not quantified that.
The experience with pricing, setup cost, and licensing for Check Point Application Control is quite in line. It is not on the higher side, so the experience has been fair.
It is quite in line. The updates are regular and can be scheduled. There are no outstanding issues.
The advice I would give to others looking into using Check Point Application Control is that Check Point brings in significant industry experience from the stateful firewall. They moved into next-generation firewalls, the application control features, and the integration within the product is quite good. The transition is very smooth. The application control features have minimal false positivity with a minimum level of misclassifications based on the signature. The results are good.
On a scale of 1-10, I rate Check Point Application Control a 9.

Check Point Application Control is built for controlling application access to our organization network. It is an inbuilt feature of the security gateway of Check Point, where we have enabled this blade and are using the application control security feature.
We have a security gateway of Check Point where we have configured this security profile of Check Point Application Control and it is mapped to all of our firewall security policies. We are able to control application usage in the network on a category-based level. We have blocked some application categories and have allowed some particular ones according to our compliance and policy.
I have been using Check Point Application Control for more than three years.
The best feature is that we can configure and deploy Check Point Application Control based on application categories, determining whether we need to allow or block access for a particular user or an entire subnet of the network. We can even control application usage at the granular level. For example, if we want to allow Facebook usage in our organization but want only uploading or chatting to be allowed with other functions blocked, we can achieve that through application controls.
The configuration for Check Point Application Control is straightforward. The configuration part for granular controls is straightforward and very easy to implement.
One valuable aspect is that the database updates for Check Point Application Control are automated. We do not have to perform any manual updates, which is also a good feature of the application control.
Since we have been using Check Point Application Control, we are able to control unused application categories, such as applications that are not related to our organization's work environment. We are blocking those effectively, and therefore, the productivity of our organization's employees has increased significantly.
We can generate reports of application usage and clearly see in the logs that we have successfully blocked unused applications. When a user makes a request, it is directly blocked, preventing them from accessing those unproductive applications in the network.
Based on my experience and the current work environment, I do not see anything lacking in the current features of Check Point Application Control. In the future, some artificial intelligence or more automation could be added to the solution, which would also be beneficial for any organization.
I have been using Check Point Application Control for more than three years.
Check Point Application Control is a stable solution. There is no performance degradation that we have observed since we started using this solution.
Check Point Application Control's scalability is totally dependent on the throughput of the security gateway of Check Point. Currently, the application control is excellent from a scalability perspective. There is no scalability issue that we are facing in our organization.
I have contacted Check Point's customer support multiple times for technical support, and they are good from a technical perspective. Service-wise, they are excellent, providing guidance to resolve any technical issues.
Positive
I do not have information about whether we previously used a different solution for application control, so I would need to check with my team.
I can say that both time and money are being saved by the organization since using Check Point Application Control.
Unproductive applications are not being accessed in our network, which is indirectly saving our employees' precious work hours, and money is being saved by the organization because users are focused only on working applications.
I was not part of the team concerning pricing, setup cost, and licensing as everything is handled by a different team.
I do not have information about whether any different original equipment manufacturer was evaluated before choosing Check Point Application Control because that team is separate.
I will advise any organization already having a security gateway in their network environment to leverage Check Point Application Control by purchasing the license for the application control and enabling this security blade. The configuration is very easy and can be straightforwardly configured and applied to the security policy to control application usage in the organization. We are a partner with Check Point. I give this review a rating of nine.

I have been using Check Point Application Control almost since I got to this company. I'm working with Check Point products, all of the firewall blade features. For almost two and a half years, I'm working with the Application Control blade.
My main use case for Check Point Application Control is to implement or deploy Check Point firewalls including the Application Control blade. That's included in the firewall as a firewall blade. I am using Check Point Application Control for granular control. For example, to block or allow interrupts from the application infection or to allow social media specifically for some departments or to block some departments from accessing social media and different websites and web apps.
In our latest deployments in a banking environment, we blocked Telegram, social media, and all social media access, video streaming such as YouTube from the application and URL filtering policy tab. Check Point Application Control has its own application database, and I can use my custom application to define and enforce policies on in-house or less-known apps. For this deployment, the bank needed the marketing teams to access social media and video streaming such as YouTube, so we allowed that for this department, while we blocked access for other departments. This allows us to use our resource or our network bandwidth effectively.
The best features Check Point Application Control offers include integration with Identity Awareness such as Active Directory, which allows me to block or allow user groups that are integrated through or that are fetched from the Active Directory. I can allow some resources and block some resources from accessing certain applications on the internet.
The integration with Active Directory benefits my team by enabling us to group users into some groups and block some users from accessing social media or different malicious websites. Before deploying Check Point firewall, we had no option to integrate Active Directory through old firewalls such as Cisco ASA. To block malicious applications or sites, we needed to use Application Control. By integrating Check Point firewall with Identity Awareness, we can accommodate access based on team needs while restricting others.
The feature that allows Check Point Application Control to define or enforce policies on in-house developed applications means I can customize those applications and feed them into Check Point Application Control to differentiate them from malicious websites, allowing those websites to be used in the organization. This database can be customized by my own in-house applications, promoting flexibility to manage custom apps made by our in-house team.
Check Point Application Control has positively impacted my organization by allowing us to segment internet access groups into social media access, organizational applications access, and working applications in the in-house developed applications. Check Point Application Control helps me group users into social media groups, video streaming groups, and remote access groups based on user privilege and position, which makes users more effective in their working hours by blocking applications that waste their time. Additionally, we improved our security by blocking anonymous websites through Check Point Application Control database, enhancing our security posture overall.
Check Point Application Control could be improved by differentiating the network access segment section in the policy from the application URL filtering. Administrators currently get confused as they cannot search effectively on both sides due to overlapping parameters. Network access should pertain to Layer 3 while application URL filtering should pertain to Layer 7. This differentiation should be improved in the future.
I have been working in my current field for almost three years.
The customer support is excellent; they provide everything they can. Previously, there was a lag in responses on the support portal, but it has improved to be faster. When I create a case, I receive responses and solutions quickly.
Positive
I previously used Cisco ASA, an old firewall that lacks application-side features, which is why we switched to Check Point Application Control. It doesn't have integration with Active Directory and cannot secure our environment from Layer 3 to Layer 7 attacks, so we switched for the needed features.
I have seen a return on investment, noting that after using Check Point Application Control blade, we minimized our bandwidth usage by half and also observed improved productivity, so we get what we invested in.
In my experience with pricing, setup cost, and licensing, there are some costs associated with Check Point Application Control licensing and products, but it is good at what it does. That's why it's costly.
Before choosing Check Point Application Control, I evaluated other options including Palo Alto and FortiGate, but our clients chose Check Point products, leading us to select Check Point Application Control.
I have noticed increased bandwidth because social media applications consume a lot of bandwidth. For example, Telegram consumes a lot of our organization's bandwidth, so Check Point Application Control helps me block those applications from being used by our organization employees. This also helps us save time and increase productivity.
The reporting feature is very nice on Check Point Application Control. It offers detailed reporting and can monitor usage patterns in SmartEvent and SmartConsole. Check Point Application Control is scalable, as I can easily scale it when necessary.
My advice to others looking into using Check Point Application Control is that if you want to have granular control of your entire apps or specific functioning apps, you need Application Control blade along with the Check Point firewall.
My company has a business relationship with Check Point as we are partners and resellers of Check Point products. I am responsible for deploying Check Point products to our customers, including Application Control in the firewall blade.
I rate Check Point Application Control eight out of ten because there needs to be improvement on the network and Application Control, which creates ambiguity for the administrator when configuring the security policy. The overlapping parameters on the network access policy layer and the application URL policy layer are the reasons for my rating. However, it has many good features.

I use Check Point Application Control for social media applications with granular access changes. Access to social media applications has been given to specific departments including sales, sales marketing, and the technical group. Roles have been defined for each particular department, meaning access has been provided according to their role in the company. Control is being used for some users.
With Check Point Application Control, for users utilizing it, browsing can be defined and only browsing can be allowed for some users. Others can use media streaming. Access has been provided in this application accordingly.
Check Point Application Control is used for a granular purpose, which is the most effective way of giving application access by providing access to users according to their role.
Check Point Application Control blade is working very effectively. No improvements are needed in that application.
No changes or corrections are needed in Check Point Application Control.
Check Point Application Control is more reliable, stable, and a scalable device compared to other devices or other service providers.
Check Point Application Control is very useful in our organization as it is more focused on time-saving. It aims to focus on the work in the organization, not on social media sites.
Time is saved with Check Point Application Control, and it is very useful at the enterprise level.
Check Point Application Control customer support is excellent, but the technical person is taking more time to get on the call. When a major issue has occurred, it takes more time to get on the session with the technical person.
I have been using Check Point Application Control for about six months.
No instability has been seen in Check Point Application Control blade. More than three years have passed without any instability. It is very reliable. There have been no downtime or reliability issues.
Check Point Application Control customer support is excellent, but the technical person is taking more time to get on the call. When a major issue has occurred, it takes more time to get on the session with the technical person.
No other solution than Check Point Application Control has been chosen.
The pricing and setup cost for Check Point Application Control is higher than others. However, it is worth it based on the service that has been provided by Check Point Application Control.
No other options have been evaluated. Check Point Application Control was chosen directly, as the service that has been provided is excellent.
Check Point Application Control deployed in our organization is on-premises. Check Point Application Control is excellent. The overall review rating for this product is 8.

We are using Check Point Application Control for the last three years.
We are using this feature to gain granular control over URL and web access for users by categorization and known risk level.
In my company, there are multiple departments including HR, IT, and accounting. Different departments need different types of web access. With Check Point Application Control, we provide web access such as hiring applications exclusively to HR, not to other departments such as IT and accounting. Similarly, some websites are not accessible for the HR department but are accessed by IT. In all these scenarios, we implement Check Point Application Control.
We have a deny policy where all known URL threats are by default blocked so that no malicious website can be accessible through the network.
Check Point Application Control provides in-depth visibility of what users are accessing in real-time. We can get reports of top ten users or any specific users, and we can block any particular URL by categorizing or the specific domain.
The reporting is very useful as we must submit those reports to our higher management. We can easily identify the top ten users accessing malicious websites or the top ten risky users. With these reports, we are preventing unauthorized access.
The configuration of Check Point Application Control is straightforward as it is an inbuilt feature of the Next-Generation Check Point Next-Generation Firewall. There are multiple categorized URLs where we can block access with the help of categories.
After deploying Check Point Application Control, we have successfully controlled URL access, web access, and malicious website access for users.
Sometimes by enabling the application inspection, the firewall throughput becomes high in the older versions. This aspect can be improved.
It has been almost more than two years.
Check Point Application Control is stable.
We are using only Check Point Application Control.
We have evaluated Fortinet URL filtering.
Check Point Application Control is very useful, and time is significantly reduced. With this application, we can easily configure the policies and control web access for users.
I advise those who are looking for application control to consider Check Point Application Control feature, which is very easy to deploy and maintain.
On a scale of 1-10, I rate Check Point Application Control an 8.
The main use case of using Check Point Application Control is to provide visibility and control over web applications, web traffic, and user activity. It is for prioritizing bandwidth for business-critical applications like ERP and Office 365. It will also prevent the use of risky IT applications and helps in compliance with security standards.
The best features of Check Point Application Control are granular application and web control, user and group awareness, identity awareness, integration, SSL/TLS inspection, detailed visibility and reporting, and bandwidth management.
Bandwidth management with Check Point Application Control allows the organization to prioritize business-critical traffic such as Microsoft Teams, Office 365, and similar applications. This ensures that critical applications remain fast and reliable during peak hours. It also prevents the use of applications that consume too much bandwidth. In many organizations where employees depend on real-time applications such as voice, video conferencing, trading platforms, or healthcare systems, poor performance directly impacts productivity. This is where bandwidth management comes into the picture. It allows a smooth user experience, fair usage of network resources, and reduced business risk from downtime or lag.
Areas where Check Point Application Control could be improved are policy fine-tuning usability, reporting and analytics, application identification accuracy, and performance impact with SSL inspection. I would personally prefer to see more real-time, AI-assisted insights. For example, if an unusual app suddenly spikes bandwidth or starts behaving suspiciously, the system should automatically suggest a policy adjustment instead of waiting for the admin to dig into logs. That would make security more proactive and improve job efficiency.
The solution received an 8 out of 10 because it's a very strong solution with granular controls, user awareness, and deep visibility. However, they need to work on the customer support and false positive issues. Sometimes there are many false positives, which impacts user efficiency.
I have been using Check Point Application Control for the past one year.
Check Point Application Control improves both security posture and compliance. By controlling which applications are allowed and inspecting their traffic, the organization reduces the attack surface. That means fewer opportunities for malware, phishing, or data leakage. In terms of compliance, many standards such as PCI DSS, HIPAA, and ISO 27001 require visibility into application usage, data transfer, and prevention of unauthorized communication channels. Application control helps enforce those policies, generates audit logs, and demonstrates compliance during assessments.
We have implemented the solution for our clients and customers. We are not using the Check Point cloud application control for our own environment.
For organizations considering this solution, I recommend defining their application usage policy and compliance requirements. Regarding business relationships, we are a customer only. We don't have any additional relationship; we are not a reseller or partner. I was not offered any gift card or incentive for this review. Overall, Check Point Application Control is a reliable solution that strengthens security posture. We are not using any other tech products.
This solution receives an 8 out of 10 rating.

We are using Check Point Application Control for URL filtering so that users don't have access to unwanted websites, and we are also using it for threat prevention and Identity Awareness to implement allow policies based on users' names.
Previously, we were using allow policies based on IP addresses, but with Check Point Application Control, we have integrated our AD server to the firewall and implemented user-based policies. We have different departments, and we use username-based policies for each user.
Check Point Application Control has provided granular control over websites and visibility.
Check Point Application Control provides excellent granular control. For example, when allowing YouTube access, we can easily control downloading videos or posting content, restricting users to accessing only particular channels.
Previously, everyone had access to everything, but now with Check Point Application Control we have department-wise and user-based policies. Users are accessing only the compliance websites that we allow them to access, which is useful for controlling user access. We are getting proper visibility and can generate user-based reporting to present to our management.
Check Point Application Control has saved time since once we configure a user-based policy, there is no need for upgrades. We rarely change configurations in the firewall, making it time-saving while preventing threats from outside. It is cost-effective and provides a return on investment.
Sometimes Check Point Application Control provides false positives. We allow some websites or domains, but it still blocks them under certain categories. These false positives given by Check Point Application Control can be improved.
We are using Check Point Application Control for more than two years.
Check Point Application Control is stable.
We evaluated Fortinet application control before choosing Check Point Application Control.
As per industry reputation of Check Point OEM, everything looks fine.
I advise anyone looking for application control in their organization to consider this solution as it provides packet inspection, granular control, visibility, and allows creating user-based policies. All these features are very good, and they can consider Check Point Application Control as the best solution in the industry.
I rate Check Point Application Control eight out of ten.
My main use case for Check Point Application Control is to control URL access while users are searching on the internet, and with the help of Application Control, we can allow them whatever they get in our organization. This solution comes with the Check Point Next Generation Firewall, so we have enabled the Application Access feature in Check Point Next Generation Firewall.
A specific example of how I use Check Point Application Control in my day-to-day work is that we have configured the Application Control in our Check Point Next Generation Firewall. There are multiple categories, and we have allowed only the required categories, such as for the HR department and for accounting, whatever applications they use in day-to-day work. Based on that, we have allowed the application. Apart from that, everything is blocked.
The best features Check Point Application Control offers include the automatic update of the application categories, which gets automatically updated, and based on that, if any new application is added, it will get blocked under the block categories.
The automatic updates help my team by saving time and reducing manual effort because if we need to block the entertainment applications, if a new application is introduced in the market that falls under the entertainment category, it is blocked by default, so we don't have to manually configure or block this newly added application.
Check Point Application Control has positively impacted my organization by controlling application access; previously, all the users had full internet access, and now we have controlled their application access based on this solution.
Currently, I do not feel any feature needs improvement in Application Control because everything functions perfectly.
The costing could be better for smaller organizations, as sometimes they feel they are not able to purchase these features due to pricing.
I have been using Check Point Application Control for three years.
Check Point Application Control is stable.
The scalability of Check Point Application Control is better.
The customer support is supportive.
Positive
We have been using the same solution from the start, so I did not previously use a different solution before Check Point Application Control.
I have seen a return on investment in terms of time saved and increased productivity.
My experience with pricing, setup cost, and licensing is good based on our organization's size, so the pricing, setup cost, and licensing is considered acceptable.
Before choosing Check Point Application Control, we evaluated Sophos Application Control.
After we enabled Check Point Application Control, I have seen improvements in security and productivity with fewer security events and increased productivity of the employees.
This is the industry's best solution, and organizations can consider Check Point Application Control tool in their organization.
Our company has a business relationship with this vendor as we are a partner.
I rate Check Point Application Control nine out of ten.

My main use case for Check Point Application Control is controlling application access as per client requirements. The LAN users try to access various applications randomly, but with respect to business requirements, users should access only business applications such as Teams and FTP. For the marketing team specifically, they should have access to Facebook, while other users should not have access to Facebook and social media platforms. We have implemented this type of use case for the client.
This use case fits into my daily workflow by providing a particular scenario where Check Point Application Control made a difference for my client. For example, the marketing team has access to Facebook and other social media platforms for marketing purposes, while other users can only access business applications such as Teams. This provides a granular level of control over which applications users can access. With Facebook, users can view posts but cannot post anything or chat on the application, achieving granular level control in particular applications.
Check Point Application Control offers features that control around 4,000 users through the Check Point firewall. This application control is one of the blades of the Check Point firewall, which helps us control user traffic based on which applications users should access and which they should not, with respect to company or organization compliance policies.
Changes in network performance are noticeable after implementing Check Point Application Control. Restricting users from visiting unnecessary applications improves the bandwidth, meaning the bandwidth is utilized only for desired applications or required tasks.
Check Point Application Control has positively impacted my organization, as I have seen improvements in security and compliance. Another important factor is that unnecessary bandwidth is not getting utilized; only the required applications get higher priority. For example, Teams voice calling takes priority. If users wanted to browse on YouTube and stream videos, that would consume bandwidth, but after blocking unwanted social media platforms and streaming sites, we prevent unnecessary bandwidth utilization, allowing it to be used for desired tasks.
Check Point Application Control can be improved, particularly in policy management. When we add applications in the policy, we currently have the option to select individual applications, but a feature allowing categorization of applications based on types, such as social media applications, would make it easier to add multiple or bulk applications in the policy. This feature would be very valuable if introduced.
Feedback from management about how these changes improved productivity and network performance has been positive. Users were spending their time watching videos on YouTube or streaming content, wasting time on Instagram and Facebook while in the office. Managers complained about this, leading to compliance policies being defined to restrict access to these kinds of applications.
I have been using Check Point Application Control for more than one and a half years as an administrator.
Check Point Application Control is stable; I have not faced downtime or issues with reliability.
The scalability of Check Point Application Control is good. I have not needed to scale up or down, and the process has been smooth.
Customer support for Check Point Application Control is fair and good, and I have reached out to them with satisfactory results.
Neutral
I have not previously used a different solution before Check Point Application Control.
The initial setup with Check Point Application Control is not very complex. If you know Check Point firewall, then it is easy to implement.
If you want to implement Check Point Application Control, I advise you to implement HTTPS inspection for it to work 100% perfectly. Without HTTPS inspection, it may not function perfectly, as it will scan or judge applications based on their ratings. Additionally, implementing HTTPS inspection will yield better outputs and correct results.
I have seen a return on investment since implementing Check Point Application Control. We can say that 4,000 users are now accessing only legitimate business applications rather than wasting time on other applications that utilize unnecessary bandwidth. If we hadn't implemented Application Control, we might have needed to increase bandwidth for the users, which saved costs from that perspective. Additionally, users stay focused on their tasks, ultimately helping the organization save time, and from a security perspective, there are no disruptions seen.
The pricing, setup cost, and licensing of Check Point Application Control are higher than other vendors, but it justifies the features offered. The licensing is straightforward.
I evaluated Palo Alto before choosing Check Point Application Control. I noticed that in Palo Alto, we don't get a granular level of application management as we do in Check Point, which has a large database for the applications, making it easier to implement policies.
The process for setting up specific rules for user groups is straightforward. To work efficiently, we have to implement HTTPS inspection, which is important to work perfectly. The rest of the configuration process is very straightforward.
That level of detail is important for my clients because it prevents users from posting any internal information on social media platforms, which is crucial for our organization.
We are a partner of Check Point, so we have a business relationship with this vendor beyond just being a customer.
I use other tech products such as FortScout, FortiADC, and Netskope.
You can use my real name and company name when publishing my review.
On a scale of 1-10, I rate Check Point Application Control a 9.