What is our primary use case?
We use the Check Point Maestro for data center firewalls. It has the ability to spread the load across multiple devices and still only have one source of management, which is incredible. Plus, everything duplicates across the firewalls without manual intervention.
We are currently moving from a flat network into this setup, and, with the amount of traffic that we are going to be sending through the firewalls, this is the only way it could have been done.
Also, the product offers the ability to have little to no downtime during patching.
This setup is a beast!
How has it helped my organization?
We didn't have anything before. This really creates a secure and fast solution. In order to be able to track everything coming in and out of our data center. We have a flat network and now that we are moving to this design, we needed something that can secure servers and users from each other and make sure we are only allowing what needs to be allowed and not allowing anyone to traverse the network maliciously.
Also, we have no ability for downtime - so having this solution helps make sure that we can patch and keep security going without having to talk to everyone for change management.
What is most valuable?
Scalability is a huge factor.
The need for no downtime is key for us - and this solution offers that. When you have six gateways you have to patch and no one even notices, it's phenomenal.
We need to be able to keep these connections running 100% of the time. The fact that we can patch and reboot firewalls and no one even notices is a huge plus. We need to be able to keep it secure but also keep it up and running.
Having the six gateways and being able to clone them in when we need a new gateway is excellent. I love that we are able to just put a new gateway in and clone it.
What needs improvement?
I don't really have any real suggestions for this to be improved. The biggest thing would be the ability to update the SMO's and gateways through Gaia instead of always completing it through the command line. As we train new people and have fewer hands that touch these firewalls, having a good understanding of how CLI works and how to install patches and remove patches from gateways using this method is dying. So, being able to do it the same way we do all the other gateways would be excellent.
For how long have I used the solution?
I've been using the solution for over one year.
What do I think about the stability of the solution?
I am very impressed. I didn't think anything like this would be possible.
What do I think about the scalability of the solution?
It has the MOST scalability of any product out there. You can slam another gateway in and clone it and off you go.
How are customer service and support?
We always have great support and service. I don't think any other vendor provides this level of support.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
I have used Fortigate before, however, the management on Check Point is unrivaled.
How was the initial setup?
The setup was slightly complex to begin with. That said, once you've set up a new connection a few times it gets easier.
What about the implementation team?
We handled the setup with the vendor team. They are the best at Check Point!
What was our ROI?
I don't pay the bills, however, it's my understanding that there is an argument out there for ROI.
What's my experience with pricing, setup cost, and licensing?
The cost is up there. However, when you are dealing with the best, you cannot really balk at pricing.
Which other solutions did I evaluate?
We did not evaluate other options.
What other advice do I have?
Check Point Support is top-notch. You cannot beat their support.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.