Try our new research platform with insights from 80,000+ expert users
it_user818859 - PeerSpot reviewer
Works with 1,001-5,000 employees
Real User
We are able to quickly review 100's of firewalls and stay compliant.

What is our primary use case?

Firewall and Compliance.  We use the product to support the firewall review process and risk of over 400 firewalls

How has it helped my organization?

We are able to quickly review 100's of firewalls and stay compliant.  The product has been invaluable to our information security department

What is most valuable?

Policy review and compliance.  We are now using the AlgoSec FireFlow feature to help us automate the firewall ACL submission process and implementation of firewall rules.

What needs improvement?

Product has improved quite a bite in the years we have been using the product. We look forward to completing the AlgoSec Fireflow implementation and piloting the Business flow product.  AlgoSec continues to improve their product every year. 

Buyer's Guide
AlgoSec
February 2025
Learn what your peers think about AlgoSec. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,737 professionals have used our research since 2012.

For how long have I used the solution?

More than five years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Freelance System Security Consultant at a consultancy
Consultant
It can really optimise configuring firewall policy rules.

What is most valuable?

  • It can identify the policy rules in the firewall that have a high risk and could have an impact on network infrastructure.
  • It suggests solutions to these issues, and provide compliance reports by standardizing PCI-DSS, ISO 27001, SOX and more.
  • It can monitor policy changes, and who made those changes.
  • It generates a topology of the network when it has scanned the network.
  • Using the network mapping, it identifies bottlenecks.

How has it helped my organization?

We have improved the performance of the firewall to handle requests and responses to/from clients as reduces the number of policies that are needed when the network is exposed to high risk.

What needs improvement?

They need to improve auditing of IP tables, as only monitoring them does not reduce their vulnerabilities.

For how long have I used the solution?

I used it for nine to ten months.

What was my experience with deployment of the solution?

No issues encountered.

What do I think about the stability of the solution?

It is quite stable for 24-hour network monitoring.

What do I think about the scalability of the solution?

There is no problem in the process of scanning and monitoring firewalls, and IP tables in
considerable quantities.

How are customer service and technical support?

Customer Service:

8/10 as they were quite fast in responding to my issues.

Technical Support:

10/10 as the technical support provide assistance if there is a problem via both email and telephone.

Which solution did I use previously and why did I switch?

I have not used a different solution previously.

How was the initial setup?

The initial set up is a bit complicated, because you have to open special ports in the firewall, and give open access to be able to read the configuration topology mapping in the firewall. This means that the process of scanning and monitoring AlgoSec can run smoothly.
Unlike the case with the initial setup for monitoring IP tables, you must use the root access serve (sudo su) so that the process of scanning and monitoring AFA could run smoothly.

What about the implementation team?

We implemented this in-house.

What was our ROI?

The advantage is that it can really optimise configuring firewall policy rules, and can
reduce the configuration that is vulnerable. It can provide solutions to make policy rules more simple and efficient.

What's my experience with pricing, setup cost, and licensing?

If you want to conduct an audit of firewall and want to optimize the configuration, you can try and use AlgoSec.

Which other solutions did I evaluate?

I didn't evaluate other options.

What other advice do I have?

Be patient and careful when doing the initial configuration of the firewall with AFA, but after the process is completed, everything has to run smoothly.

An example screenshot of network mapping results from AFA. Network mapping can
be useful also to detect if there is a connection network traffic is interrupted and can assist in documenting the topology that is owned.

The following screenshot shows an example of the policy rules that need to optimized, so you can improve the performance of firewall and its security level.

The following screenshot shows the result of scanning AFA reports that compliance with ISO 27001.

Disclosure: My company has a business relationship with this vendor other than being a customer: AlgoSec’s partner in Indonesia.
PeerSpot user
it_user277002 - PeerSpot reviewer
it_user277002Infrastructure and Networking Staff at a tech services company
Consultant

clearly explanation with real study case, this tools helpfull for infrastucture and security audit, beside that can be tool reporting and documentation infrastructure network.

Buyer's Guide
AlgoSec
February 2025
Learn what your peers think about AlgoSec. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,737 professionals have used our research since 2012.
reviewer1436436 - PeerSpot reviewer
Presales Engineer at a tech services company with 11-50 employees
Reseller
Automated firewall rule analysis saves time, and automated rule modification eliminates human error
Pros and Cons
  • "AlgoSec Firewall Analyzer can detect misconfigurations and unused or permissive rules, as well as rules without logging. Through a single dashboard, I can see all the problematic rules from all the firewalls. It's very simple, with AlgoSec, to get an analysis of all the rules, and that helps with visibility."
  • "AlgoSec integrates with most of the leading firewall vendors, but one issue is that AlgoSec doesn't support Sophos and Forcepoint. AlgoSec competitors, like FireMon, support Forcepoint."

What is our primary use case?

One of the use cases for the solution is when you have many firewalls from different vendors and would like to handle all the configurations from a single pane of glass.

We are an AlgoSec distributor, and another use case that is very important to our customers, especially in the financial sector, is generating compliance reports. AlgoSec has very comprehensive compliance reporting. Most of our customers who use AlgoSec care a lot about compliance reports, whether ISO or PCI or other types of compliance.

How has it helped my organization?

AlgoSec saves time by providing an analysis of all the firewall rules. For example, I might find 10 unused rules, or rules without objects or without a subnet. To get that information manually can take time. I might have to go through a firewall and check the rules and it would take at least 10 minutes for 10 rules. And a manual process can result in errors. AlgoSec saves time because it can detect all unused rules and I can just remove them via the AlgoSec platform through FireFlow. Removing those 10 rules manually can take about 20 minutes, but through AlgoSec it takes one or two minutes.

The solution can find all the misconfigurations in firewall rules and it can delete or modify them automatically, with no human action needed. As a result, there will no longer be errors in the firewalls. FireFlow handles the workflow of adding and removing policies. Sometimes, an engineer may not have solid experience when it comes to firewall rules. If he goes to the firewall portal itself and tries to add or remove a policy, this policy may cause errors or potential risk. AlgoSec handles this process instead. It helps eliminate human error.

Also, if you have a network engineer with less experience, he can still go through AlgoSec and submit rules. AlgoSec supports another tier of engineers who approve the policies. This is all done using FireFlow.

What is most valuable?

We use the AFA (AlgoSec Firewall Analyzer) and FireFlow. AFA is the most popular feature in our region and FireFlow is good for managing workflow.

AlgoSec Firewall Analyzer can detect misconfigurations and unused or permissive rules, as well as rules without logging. Through a single dashboard, I can see all the problematic rules from all the firewalls. It's very simple, with AlgoSec, to get an analysis of all the rules, and that helps with visibility. AlgoSec can do a risk assessment for each policy or rule in the firewall and detect the severity of each rule, whether low, medium, high, or critical. I can get a quick overview of the risk policies that a customer needs to change because, perhaps, there is a rule where the risk is high.

The AlgoSec dashboard is very simple. I can find all the information without any effort. All the tabs are clear and straightforward.

I can apply changes to rules through FireFlow. For example, when I detect many unused rules, I can remove them and, using FireFlow's process, it is very simple to do so.

It is very easy to generate a compliance report for ISO or PCI. It can be done with one click. Some organizations may have a baseline for compliance. The beauty of AlgoSec is that it can adjust compliance according to the corporate needs or environment, when standards vary from one region to another.

When it comes to visibility, the solution can make a network map for all the devices in the network, whether routers or firewalls. I can run queries to detect network policies. For example, if a customer cannot access the corporate stack or the application site, using AlgoSec I can detect which firewall, and which policy inside the firewall, may be fully or partially blocking access. This is a very important feature and most of our customers use network mapping to create visibility into the network.

What needs improvement?

AlgoSec integrates with most of the leading firewall vendors, but one issue is that AlgoSec doesn't support Sophos and Forcepoint. AlgoSec competitors, like FireMon, support Forcepoint. I have told AlgoSec a number of times that we have many customers that use Forcepoint. I have asked why they don't support integration with Forcepoint. They have said they don't care about Sophos, Forcepoint, and SonicWall. They don't consider those vendors to be leaders in the firewall market and they don't have plans to support them.

For how long have I used the solution?

I have been using this solution for about two years.

What do I think about the stability of the solution?

Sometimes a customer's platform is down, but overall AlgoSec is stable.

How are customer service and support?

Support from AlgoSec is good. When I create tickets, they support us and solve all the tickets. There is no delay in support.

One of the things I don't like about AlgoSec is that when a customer has an issue with the platform, it takes time to resolve. Issues often need more than tier-one or tier-two; they're often not easy for the customer to resolve. It requires the AlgoSec team to solve issues with configurations or performance.

For example, AlgoSec upgraded the platform six months ago and it was mandatory for all customers. On my side, it was not easy to perform the upgrade and I had to request support from AlgoSec.

How would you rate customer service and support?

Positive

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Reseller.
PeerSpot user
reviewer1690866 - PeerSpot reviewer
Technical Architect at a manufacturing company with 10,001+ employees
Real User
Provides valuable security ratings and security rules analysis
Pros and Cons
  • "Security ratings and security rules analysis are valuable features."
  • "The customization of dashboards should be simplified and more user-friendly."

What is our primary use case?

We use AlgoSec to integrate firewalls. I'm a senior network security engineer and we are customers of AlgoSec.

What is most valuable?

Security ratings and security rules analysis are two valuable features. In general, it's a very good and stable solution. 

What needs improvement?

I believe the customization of dashboards should be simplified and more user-friendly. Customization inside the domain level needs to be improved.

What do I think about the stability of the solution?

The solution is stable although there are occasionally issues with patches, but they are generally resolved quickly. The solution is extensively and regularly used for compliance reports. 

What do I think about the scalability of the solution?

The solution is scalable. We have close to 30 firewall admins.

How are customer service and support?

The technical support is good. The only drawback is that the product is not very user-friendly and it's too expensive to contact support each time we have a problem. 

How was the initial setup?

The initial setup was carried out using professional support and the company was happy with the integrator. We moved our ticketing up to AlgoSec using FireFlow. I wasn't around but I think it took some time.

What's my experience with pricing, setup cost, and licensing?

The license was initially renewed every three years but it's now done on an annual basis. I'm not aware of any additional costs. 

What other advice do I have?

I rate this solution eight out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1278546 - PeerSpot reviewer
Senior Network Engineer at a energy/utilities company with 1,001-5,000 employees
Real User
Automatically optimizes existing rule sets to comply with our security policy
Pros and Cons
  • "This has helped to restrict rules, delete rules that are too permissive, and create a configuration that complies with our security policy."
  • "There are sometimes issues with the Risky Rules reports where the number of hits is registering zero, but we know that this is incorrect because we have checked the rules and see that they are indeed registering traffic."

What is our primary use case?

The primary use of this solution is to extract Risky Rules reports obtained from our Firewalls, check the rules, and proceed with changes on the Firewall as needed. In these reports, we also see the traffic being applied for different rules.

The traffic used for different Firewall rules can be obtained and then, we have a clear idea of the use for different rules. If some service or protocol is more often used or not, we can see.

We use the FireFlow tool to create the rule to be validated and applied in the appropriate Firewall. FireFlow can install the rule automatically.

How has it helped my organization?

This solution has improved our Security in our Firewalls. This has helped to restrict rules, delete rules that are too permissive, and create a configuration that complies with our security policy.

The reports are very useful for determining whether our Firewalls are compliant with our security rules and directives.

What is most valuable?

The feature that I've found most valuable is the risk classifications for different rules. The number of different risky rules that we have for each Firewall is determined automatically. 

The traffic used or not for every service is very useful to check if some service is needed or not. In cases where it is not used, we can delete or disable it.

The FireFlow tool is very useful with the automatic installation of rules into Firewalls. It detects the router and applies the new rules, which saves us time in manual configuration.

What needs improvement?

There are sometimes issues with the Risky Rules reports where the number of hits is registering zero, but we know that this is incorrect because we have checked the rules and see that they are indeed registering traffic.

Sometimes the Trust setting on Firewall rules is changing to trusted by itself.

For how long have I used the solution?

I have been using AlgoSec for more than one year.

What do I think about the stability of the solution?

I have very good impressions of AlgoSec stability.

What do I think about the scalability of the solution?

The scalability is very good.

Which solution did I use previously and why did I switch?

I did not use another solution prior to this one.

Which other solutions did I evaluate?

I did not evaluate other options before choosing AlgoSec.

What other advice do I have?

Overall, I think this tool is very useful and we think that it's difficult to improve.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1006992 - PeerSpot reviewer
Works at a tech services company with 10,001+ employees
Real User
Detects in a few seconds which flows are right or wrong which saves a lot of troubleshooting time

What is our primary use case?

I mainly use this application to check the flows. I work for a big company in the network team which needs to check the flows every day.

How has it helped my organization?

This application is very nice. We save a lot of time with troubleshooting the flows and we can detect in a few seconds what flows are right or wrong.

What is most valuable?

The AlgoSec Firewall Analyzer is for me the most valuable thing in this application. I don't know how much time we saved with this application, but I now know that without it, we would lose several hours every day solving networks incidents.

We also use the AlgoSec FireFlow to generate and manage the tickets concerning the flows.

What needs improvement?

I think that AlgoSec could improve the application by improving the treatment speed.

If AlgoSec could make few seconds less to analyze research, theses few seconds will be used by my team to be more efficient.

I mean, in the Traffic Simulation Query, it will be wonderful if Algosec could find a way to make the research faster than now. In fact, we are often waiting arround 1,30 min to see the results.

Maybe something can be done to make this reasearch faster?

For how long have I used the solution?

One to three years.

Which solution did I use previously and why did I switch?

No, it is my first application for this kind of work.

Which other solutions did I evaluate?

It was not my work to choose this solution; a project team did it.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1003116 - PeerSpot reviewer
Head of IT at a manufacturing company with 10,001+ employees
Real User
Tremendously improved our organization's security with much better and efficient firewall rules

What is our primary use case?

Our primary use case is to clean up firewall rules of migration from Cisco ASA to another firewall vendor. We try to get rid of old rules and get these converted into new rules which apply better to our environment.

How has it helped my organization?

It tremendously improved the security of our organization with much better and efficient firewall rules. We saved a lot of time using this tool to get the rules clean. Also, the overview of the network topology map is a very good thing to get a clear view of every single region in your network.

What is most valuable?

The best feature is, in my opinion, the firewall analyzer. Just let the tool analyze the traffic for a few days or weeks, and you will get perfect ideas on how to improve your rules and which rules are just unnecessary or too spacious. So getting a better security level by better firewall rules is just what you want to have if you're using a firewall. Otherwise, it would not make sense to have a firewall, right?

A nice feature as well is that it gives a compliance report on each of your security devices. This helps a lot to get an overview of every single security device in your network and its status.

What needs improvement?

The versioning is a bit weird. We used to use version 2017 which is quite current, but it looks like it is a 2017 version. As far as I know, they want to have this changed soon. Nevertheless, this is something which definitely needs to be improved.

For how long have I used the solution?

One to three years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Senior Network Security Engineer at Prudential Corporation Asia
Real User
Helps with application connectivity and our users are able to documents their rules
Pros and Cons
  • "ABF is application-centric. which helps to track changes in the application from day one."
  • "We needs object level permissions and application level recertifications."

What is our primary use case?

  • ABF application centric
  • Risk and compliance
  • Zone matrix
  • Conditional workflow
  • IPT
  • Active change 

How has it helped my organization?

It improved a lot in our flow database. In the past, application owners did not know their application connectivity. AlgoSec helps with this and our users are able to documents their rules.

What is most valuable?

ABF: It is application-centric. which helps to track changes in the application from day one.

Compliance: It helps to have a zone matrix and capture risks.

What needs improvement?

ABF needs to be more integration with AFF/AFA. We needs object level permissions and application level recertifications.

For how long have I used the solution?

Less than one year.

What do I think about the stability of the solution?

No stability issues.

What do I think about the scalability of the solution?

No scalability issues.

Which solution did I use previously and why did I switch?

We used a different network security policy management tool, but we felt it would not be able to fulfill our requirements and address our previous gap. We were looking for a place where we could keep our rules and also track ownership of each rule in the application.

How was the initial setup?

The initial setup was straightforward.

What about the implementation team?

We implemented through a vendor team, whose expertise level was high.

What was our ROI?

We are satisfied with our ROI.

Which other solutions did I evaluate?

We evaluated all of AlgoSec's competitors and chose AlgoSec as it was the best.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free AlgoSec Report and get advice and tips from experienced pros sharing their opinions.
Updated: February 2025
Buyer's Guide
Download our free AlgoSec Report and get advice and tips from experienced pros sharing their opinions.