Try our new research platform with insights from 80,000+ expert users
PeerSpot user
Technical Manager at Global Technologies for Trading and Contracting
Real User
Automated rule re-ordering helps improve performance, but it needs an intelligent tuner
Pros and Cons
  • "I found that for policy optimization it does a great job."
  • "I would like an intelligent tuner where it could help update rules with the application ID."

What is our primary use case?

The primary use for this solution is to clean-up and fine-tune firewall rules.

How has it helped my organization?

I found that for policy optimization it does a great job. It handles covered rules, duplicate rules, and consolidated rules.

What is most valuable?

The most valuable feature is the ability to reorder rules because of the enhancement of firewall CPU performance when they are applied.

What needs improvement?

I would like an intelligent tuner where it could help update rules with the application ID.

Buyer's Guide
AlgoSec
February 2025
Learn what your peers think about AlgoSec. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,737 professionals have used our research since 2012.

For how long have I used the solution?

I have been using this solution for one month.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
AndyWodzien - PeerSpot reviewer
Network Engineer at WPPI Energy
Real User
The change management feature is great for environments with multiple firewall engineers

What is our primary use case?

We used AlgoSec during a migration between firewall vendors. We needed a tool that could help evaluate the effectiveness of our existing rule base and inventory network objects.

How has it helped my organization?

Running AlgoSec helped us clean up years worth of obsolete rules and objects. This left us with a clean and up-to-date policy on our new firewalls.

What is most valuable?

  • Policy risk mitigation identifies and helps tighten risky rules rendering the policy more secure. 
  • The change management feature is great for environments with multiple firewall engineers.

What needs improvement?

The only thing I had slight issues with is the web UI which is a bit tricky to navigate. It can be difficult to find what you're looking for without having to click around for a bit, but once you get to know where things are, it's not bad.

For how long have I used the solution?

Trial/evaluations only.

Which solution did I use previously and why did I switch?

This is the first solution of this kind I have used.

What's my experience with pricing, setup cost, and licensing?

Setup is a breeze.

Which other solutions did I evaluate?

I did not evaluate any other solutions.

What other advice do I have?

No.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
AlgoSec
February 2025
Learn what your peers think about AlgoSec. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,737 professionals have used our research since 2012.
reviewer877923 - PeerSpot reviewer
Account Director
User
FireFlow continues to drive customer efficiencies, allowing an organisation to keep up with the pace of change
Pros and Cons
  • "We see the value of BusinessFlow for organisations involved in digital transformation projects migrating to public/private/hybrid cloud models."
  • "FireFlow continues to drive customer efficiencies, allowing an organisation to keep up with the pace of change."
  • "Further integration with ACI and NSX will be key to our customers' requirements moving forward, as customers adopt new, innovative environments."

What is our primary use case?

The majority of customer use cases are around rule optimisation, workflow management, and risk/compliance. 

How has it helped my organization?

Our customers are able to optimise and clean the rule sets on our FW estate and streamline the change management process whilst adhering to compliance, governance, and risk requirements.

What is most valuable?

  • Firewall Analyser due to its initial ability to cleanse and provide efficiencies to legacy estates. 
  • FireFlow continues to drive customer efficiencies, allowing an organisation to keep up with the pace of change.  
  • We see the value of BusinessFlow for organisations involved in digital transformation projects migrating to public/private/hybrid cloud models.

What needs improvement?

Further integration with ACI and NSX will be key to our customers' requirements moving forward, as customers adopt new, innovative environments.

For how long have I used the solution?

Three to five years.

Which solution did I use previously and why did I switch?

Not applicable.

What was our ROI?

Our customers are receiving quick ROI using the AlgoSec platform when compared to the FTE costs for using legacy manual processes.

What's my experience with pricing, setup cost, and licensing?

Licensing is offered as a subscription and as a perpetual model.

Pricing is easy to grasp.

Which other solutions did I evaluate?

We looked at Tufin and Skybox. AlgoSec was the only vendor who had the full suite of products which met the customer and business demands. BusinessFlow was (still is) the game changer.

Disclosure: My company has a business relationship with this vendor other than being a customer: Accredited AlgoSec Partner.
PeerSpot user
it_user827928 - PeerSpot reviewer
Network Support
User
The technical services personnel are very confident and provide good assistance
Pros and Cons
  • "​The initial setup process is excellent."
  • "The technical services personnel are very confident and provide good assistance​."
  • "It would be interesting if the product could automate the switch configuration and create a dynamic map of the entire network."
  • "The product could be improved by adding additional tools for troubleshooting, not only for the firewall, but for other devices like switch and dynamic routing display. Also, it would be good if it could retrieve all information regarding Cisco Nexus switches and devices.​"
  • "​In the VMware platform, sometimes the application is frozen and we have to reload the machine​."

What needs improvement?

The product could be improved by adding additional tools for troubleshooting, not only for the firewall, but for other devices like switch and dynamic routing display. Also, it would be good if it could retrieve all information regarding Cisco Nexus switches and devices.

It would be interesting if the product could automate the switch configuration and create a dynamic map of the entire network.

For how long have I used the solution?

Three to five years.

What do I think about the stability of the solution?

In the VMware platform, sometimes the application is frozen and we have to reload the machine.

What do I think about the scalability of the solution?

Not at all.

How are customer service and technical support?

The technical services personnel are very confident and provide good assistance.

Which solution did I use previously and why did I switch?

No previous solution was used.

How was the initial setup?

The initial setup process is excellent.

What about the implementation team?

The in-house implementation was good for FireFlow.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Network Security Engineer/Architect at a tech services company with 1,001-5,000 employees
Real User
Top 5Leaderboard
Excellent for firewall policy auditing and firewall policy automation
Pros and Cons
  • "It now takes less than half of the time it took before we had this tool to deploy the flows requested by the business."
  • "We would like to see more features in the GUI so that we don't have to work with the API as extensively."

What is our primary use case?

We've been using Algosec as our reference tool to clean our policies from old unused rules and objects and to assess rules that are categorized as risky so that we can fix those risks.

Firewall Analyzer from Algosec is our main tool for Firewall auditing and it makes our external auditors very confident on the way our policies are managed.

Fireflow from Algosec also helps us identifying which firewalls are on the way from source to destination when we need to open flows and it saves us a lot of time. We are still on our path to implement full automation of firewall policy creation with Algosec's Fireflow but the goal is to achieve it soon.

How has it helped my organization?

Since we deployed Algosec our Firewall policies which didn't have much maintenance over more than 15 years had their policies reduced to less than half the rules by using Algosec's Firewall Analyzer to remove unused rules, unused objects withing rules, compacting several firewall rules in one rule, etc.

We were also able with Firewall Analyzer to get risk reports of our firewall policies and start tackling them to close them or at least to be aware of its existance.

Firewall Analyzer is amazon in Policy Optimization and we feel we are much more secure since we have this product. If we add a rule that poses a risk we get an alert from Firewall Analyzer which is very important to us.

We are also starting to use Fireflow and our goal is to have the policy creation automated soon. For now we are already able to identify which firewalls are on the path between point A and point B and we are on the path to full automation which will reduce a lot the workload of our team.

What is most valuable?

The feature we find the most valuable is the Firewall Analyzer for the firewall policy audits and to show external auditors we have a process to identify risks and to tackle them. It's also very important for policy clean maintenance. 

This helps us know which devices are between the source and destination on the flows that we need to open for the business. The audit tools are also very important to us because we can easily have everything that needs to be presented to the security auditors.

We are in the process of implementing FireFlow for full automation which will save us time for more important things we need to to on daily basis that are not creating firewall rules. We aim to achieve the full automation soon.

What needs improvement?

In our case it would be very important to improve support to Dell switches and also some Juniper switches, which we have a lot of in our company network. This has been our difficulty for the full automation on the Fireflow. If all our network devices were Cisco I'm sure we would have the network map complete very easily and the full automation working with much less effort.

We already asked Algosec for the support of the switches we have that are not natively supported for the future versions and we expect that we are lucky enough for them to be supported on the next releases, although there are some ways of working around non-natively supported switches to complete the network map.

For how long have I used the solution?

We have been using Algosec solution for more than 5 years now.

What do I think about the stability of the solution?

We never had issues so far in terms of stability.

What do I think about the scalability of the solution?

The solution is very scalable and allows you to add all the firewalls and devices you need.

It is also scalable on the licensing as you can start by buying only the Firewall Analyzer license with which you can start onboarding all the devices and completing the network diagram so that Algosec's has the whole picture and know all the paths from network A to B.

After that you are ready to start using FireFlow and you can buy the license only when you are ready to start deploying it.

How are customer service and support?

Sometimes it takes more time than expected to have answers for support tickets, but in general the customer service is good.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Not in our case.

How was the initial setup?

The initial setup has been easy. The only difficult thing was the part in which we needed to onboard non natively supported switches. That part is a bit more complex.

What about the implementation team?

We implemented with a mix of external company and in-house. The external team was helpful and had a good expertise level.

What was our ROI?

The time we save on our daily operations is very important. We could reduce the team size with this tool as we had a trainee almost fully working on opening flows.

It also allows us to detect risks on firewall rules and fix them, keeping the company network safe.

What's my experience with pricing, setup cost, and licensing?

The price for the solution is not cheap but if you use it fully it will compensate in terms of securitization and in terms of time gained on the daily operations. It is also very helpful if your company is audited on the security part.

Which other solutions did I evaluate?

We heard about Tufin and Algosec, and after going through the specs we decided to go on a POC with Algosec and ended up buying it as it fitted our needs. We followed our Firewall integrator advice, who also recommended Algosec for our Firewall's park which is basically Fortinet and Check Point.

What other advice do I have?

We recommend trying fully automation in a controlled environment before widely deploying it to the production firewalls. It's important to gain confidence on the product.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1753230 - PeerSpot reviewer
Client Manager - TE Services at NTT Security
Real User
Good for managing firewall rules, offers extended support, and great for policy optimization
Pros and Cons
  • "Reporting helps us with deliverables, areas of focus for improvement, and much more."
  • "There could be certain improvements such as supporting secure email."

What is our primary use case?

We have a large setup of multi-vendor firewalls with large in numbers of policies and rules. Handling rules and policy visibility manually are very difficult for clients multi platform firewalls. AlgoSec AFA has eased day-to-day operation, firewalls rules optimization, clean-up for unused policies and reporting, and visibility on policy and rules. All of this improves the firewall performance.

AlgoSec FireFlow workflow change tracking in environment makes it easy to have a central repository also multiple stakeholder approved change management.   

How has it helped my organization?

The AFA workflow has helped us to manage firewall rules implementation using multiple stakeholders' approval with an end-to-end lifecycle of change management and tracking. 

Reporting helps us with deliverables, areas of focus for improvement, and much more. Algosec AFA is useful for policy optimization and clean-up and can measure capacity management. 

AFA provides greatly extended support for firewall rule review for risky rules, optimization, and clean-up for unused rules. 

Firewall rule automation for implementation also makes support easy for support firewall administrators.

What is most valuable?

AlgoSec currently has two useful features: AFA and AFF. 

The AFA workflow helped us to manage firewall rules implementation using multiple stakeholders' approval with an end-to-end lifecycle of change management and tracking. 

Algosec AFA is useful for policy optimization, cleanup, and measuring capacity management. 

AFA provides greatly extended support for firewall rule review for risky rules, optimization, and clean-up for unused rules. Firewall rule automation for implementation also makes support easy for support firewall administrators.

What needs improvement?

There could be certain improvements such as supporting secure email. We have some cases where the client SMTP /POP email system is discarded, which is very important factor change notifications.

Fireflow workflow rule/change implementation for time-based rules is not currently supported. 

These improvements in upcoming code will definitely help with end-to-end firewall rule implementation. 

NAT rule implementations were in the roadmap. We are expecting this soon. 

Certain optimization of AFA/AFF SMS resources would ease daily operations.

For how long have I used the solution?

I've used the solution for four years.

What do I think about the stability of the solution?

While stability is good, further improvement is needed.

What do I think about the scalability of the solution?

The scalability is good.

How are customer service and support?

Technical support is good.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We did not use a different solution previously.

How was the initial setup?

Some changes in setup are ongoing as we are growing.

What about the implementation team?

I am a vendor partner of AlgoSec.

What's my experience with pricing, setup cost, and licensing?

The licensing is commendable.

Which other solutions did I evaluate?

We evaluated a few other options before positioning this solution. 

What other advice do I have?

The solution could use improved support.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1734192 - PeerSpot reviewer
L3 Security Engineer at NTT Security
Real User
Great policy optimization, makes management easier, and offers good reporting
Pros and Cons
  • "AlgoSec Firewall Analyser improves the firewall rules dramatically by identifying rules and objects that are not needed and consolidates rules and rule re-ordering."
  • "The risky rules reporting should have more information available in the risky rules report - especially when you export the data into a .CSV format. .CSV format being a text-based visualization, some information and formatting cause the reports to lose meaning and only become just another character in the file since it cannot port over some properties (like severity represented by colors)."

What is our primary use case?

I am part of the team providing managed security solutions and we have a number of clients that have a lot of network and security devices in their environment.

We use AlgoSec primarily to provide solutions to our clients in terms of how we can help tighten their security and optimize network performance.

AlgoSec Firewall Analyser makes this easily possible and with the help of AlgoSec's readily available reports, we are able to provide to all our clients the security and compliance report.

How has it helped my organization?

Before AlgoSec, our firewall rules got pretty big over time and it came to the point where it was barely manageable. Duplicate rules and objects were everywhere and there was nothing we could do about it. Performing a manual clean-up was a nightmare and near to impossible.

AlgoSec Firewall Analyser improves the firewall rules dramatically by identifying rules and objects that are not needed and consolidates rules and rule re-ordering.

It also helped our team to optimize performance and further secure the network by identifying risky rules.

What is most valuable?

I always find the policy optimization by identifying duplicate objects, shadowed rules, and unused objects pretty useful. By eliminating all these duplicate objects, unused rules, and unused objects, firewalls and other security devices will use fewer resources to process certain tasks/requests.

This will benefit both the security engineer managing the security devices and the client as they will spend less time in dealing with optimization and therefore can focus more on other important matters.

What needs improvement?

AlgoSec firewall analyzer is already an awesome product but there are still some areas that definitely need improving.

For instance, the risky rules reporting should have more information available in the risky rules report - especially when you export the data into a .CSV format. .CSV format being a text-based visualization, some information and formatting cause the reports to lose meaning and only become just another character in the file since it cannot port over some properties (like severity represented by colors).

For how long have I used the solution?

I've used the solution for more than ten years.

Which solution did I use previously and why did I switch?

We did not use a different solution previously.

What's my experience with pricing, setup cost, and licensing?

The setup is pretty easy and the cost is really worth it.

Which other solutions did I evaluate?

We did not evaluate other options. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Olivier Beytrison - PeerSpot reviewer
System Architect at HES-SO//Fribourg
Real User
The traffic simulation query helps to understand which rules match or don't match for a specific traffic pattern, helping troubleshoot application issues.

What is our primary use case?

  • To change management of the rules
  • History of changes
  • Risk analysis and evolution of the risk factors over time.

How has it helped my organization?

  • Transparency over the actions made in the rulebase by the different firewall operators
  • Documentation of the rules.

What is most valuable?

The traffic simulation query helps to understand which rules match or don't match for a specific traffic pattern, helping troubleshoot application issues.

What needs improvement?

We use the "rules change notification" feature to inform the different firewall managers when someone made a change. The actual change comes in a PDF file attached to the e-mail, while it would be faster to have it directly embedded in the notification mail.

Depending on your network topology, the traffic simulator might have some hard time tracing the traffic path between your devices correctly. This has already been improved in the past but could still be enhanced.

For how long have I used the solution?

Three to five years.

What do I think about the stability of the solution?

The solution is very stable. Some caution is required when you do major upgrades on your firewalls to ensure that AlgoSec can still work with the new software release of the firewall.

How was the initial setup?

The setup is very easy, as it comes as a virtual appliance you deploy in your own virtual environment. The setup is straightforward, and you can very quickly add your firewalls and start tracking changes, query the traffic simulator, and so on.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free AlgoSec Report and get advice and tips from experienced pros sharing their opinions.
Updated: February 2025
Buyer's Guide
Download our free AlgoSec Report and get advice and tips from experienced pros sharing their opinions.