We are using CloudGuard Network Security for comprehensive security. We have hardware appliances from Check Point, and we also have their firewall installed.
System administrator at a consultancy with 201-500 employees
Provides unified security management and improves our security posture
Pros and Cons
- "It gives us all-encompassing security and overview. Previously, we did not have any kind of overview of what was happening with the network."
- "CloudGuard Network Security provides unified security management across hybrid-clouds as well as on-prem."
- "Right now, I am not sure what improvements are needed. We are having occasional issues related to gateways, but we are still analyzing it."
- "We have had occasional issues with two gateways that used to break or are broken. We are not sure yet."
What is our primary use case?
How has it helped my organization?
CloudGuard Network Security provides unified security management across hybrid-clouds as well as on-prem. It has improved our security posture.
CloudGuard Network Security helped reduce our organizational risk. It has not yet helped us save time and costs because we are understaffed. However, it has helped to see what is happening and what we should mitigate or allow to happen.
What is most valuable?
It gives us all-encompassing security and overview. Previously, we did not have any kind of overview of what was happening with the network.
The interface is unifying all the data in one place. I can see the network side and the policy attached to using USB devices. Everything is stored and related.
What needs improvement?
A Check Point problem was that there were different solutions, and each had its own interface, section, and logs. Things are going great with the new feature that consolidates all the data from those systems in one place. Right now, I am not sure what improvements are needed. We are having occasional issues related to gateways, but we are still analyzing it.
Buyer's Guide
Check Point CloudGuard Network Security
March 2025

Learn what your peers think about Check Point CloudGuard Network Security. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
844,944 professionals have used our research since 2012.
For how long have I used the solution?
I have been using CloudGuard Network Security for the past six months since I joined the company.
What do I think about the stability of the solution?
Until now, it has been stable, but we have had occasional issues with two gateways that used to break or are broken. We are not sure yet. We are still analyzing it. We might be sending it to the warranty team.
What do I think about the scalability of the solution?
We implemented it keeping in mind all the requirements in terms of licenses, hardware, and other things. Everything is pretty much as we needed. We have no plans to upscale it. However, I am waiting for the OS version R82 to see how we can add more data on the fly.
How are customer service and support?
So far, customer service has been almost great. We have had some issues, such as needing to escalate every time because one gateway was not working at some point. We had an endless loop of emails trying to fix this, and the suggestion was to reinstall the gateway and do it from scratch, which was not an option at that point because it would leave that specific location without access, and business hours did not permit it. Other than that, things went smoothly most of the time.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Previously, we only had security with a basic VPN and firewall in place.
What other advice do I have?
I would rate CloudGuard Network Security a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Last updated: Feb 14, 2025
Flag as inappropriate
Sr Security Engineer at a consultancy with 10,001+ employees
Makes securing our cloud workload super easy and has amazing stability
Pros and Cons
- "It makes securing our cloud workload super easy, and we are able to push any sort of policy changes we need pretty quickly"
- "I want the upgrades of their CloudGuard solution to major versions to be easier. We have had a few small hiccups. They have different types of cloud clusters called Geo Clusters, and those just cannot be upgraded past a certain point, which is a hurdle that we are currently experiencing."
What is our primary use case?
We mainly use the firewall part. We use it to interface with our cloud environments.
We have a CloudGuard firewall in place, and we have Azure or AWS networks at the backend. We use it to secure workloads and be a bridge to our on-prem as a hybrid solution.
How has it helped my organization?
It makes securing our cloud workload super easy, and we are able to push any sort of policy changes we need pretty quickly. It is a lot better than the native cloud firewalls that are available in terms of ease of use and features. Check Point IPS is way more advanced than the native cloud firewall solutions.
CloudGuard Network Security provides us with unified security management across hybrid clouds as well as on-prem. It is fantastic. It makes our security operations a lot smoother because we only have to push policy once to our cloud firewalls and our on-prem firewalls. We can select whichever firewalls we want and hit install. The changes are made across all different types of devices. We had evaluated the native cloud firewalls for a specific use case, but we saw that Check Point firewalls were superior in the aspects that we were looking at for our requirements.
We just set up the firewalls and forget about them. We only have to do jumbo hotfix upgrades on the major version upgrades. For the most part, the uptime on them is fantastic. We do not have any downtime on them, so we never have to worry about them, which is why I do not have a lot of experience with them. We just set them up and forget about them.
CloudGuard Network Security has been fantastic in terms of identifying threats. Being able to log those cloud firewalls to the same place where all of our other Check Point firewalls are is a huge plus because we can see where something gets prevented by IPS or something like that.
What is most valuable?
We only use it for the firewall, so it is about security.
What needs improvement?
I want the upgrades of their CloudGuard solution to major versions to be easier. We have had a few small hiccups. They have different types of cloud clusters called Geo Clusters, and those just cannot be upgraded past a certain point, which is a hurdle that we are currently experiencing.
For how long have I used the solution?
We have been using CloudGuard Network Security for four years.
What do I think about the stability of the solution?
Its stability is amazing. We have never had any weird downtime issues with our CloudGuard firewalls.
What do I think about the scalability of the solution?
We do not use any of the auto-scaling features that Check Point provides. We do not have a use case for it, so I cannot attest to that.
How are customer service and support?
When you get the right person, Check Point TAC is fantastic, but sometimes, it can take a while to find the right tech engineer to be able to answer your problem within a reasonable amount of time. Most TAC engineers can answer a question, but some might take longer than others. I would rate their support an eight out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
It is super easy to deploy. In a few clicks, it is up and going.
What about the implementation team?
I deployed it myself.
What was our ROI?
We have definitely seen an ROI, but I am not sure how to quantify that. I am satisfied with it.
It is definitely easy to use and simple. Compared to the native cloud firewalls where if they do not have a feature, you are out of luck, I feel that Check Point has a very superior feature set.
What's my experience with pricing, setup cost, and licensing?
I like the flexibility because I am pretty sure you can use the same license on Azure or AWS. I forgot the name of the license, but there is a specific type you can use that lets you interchange them, and that is pretty good. I like that.
What other advice do I have?
I would rate it a nine out of ten. The only reason it is not a ten is that sometimes there are hiccups when we have to interact with it, such as while upgrading. These are small things, but I wish it was more seamless than it already is. It is already pretty seamless, but there can always be improvements.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Check Point CloudGuard Network Security
March 2025

Learn what your peers think about Check Point CloudGuard Network Security. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
844,944 professionals have used our research since 2012.
Project Manager at a training & coaching company with 11-50 employees
Provided good visibility, saved a lot of time and resources, and didn't have any downtime
Pros and Cons
- "The notifications, the visibility, and the deployment are the most valuable. It could be packaged in such a way that it took a lot of time and resources off our hands, so it was more efficient."
- "With the incorporation of a lot of AI and machine learning, they can build some sort of a matrix for low-level threats or low-level things that require attention. There can be automation of those tasks so that we don't have to take more time and effort. There should be machine learning to eliminate level-one types of tasks."
What is our primary use case?
We were providing infrastructure security. Our corporate headquarters at the time was overseas, so we had GDPR compliance regulations. It was helping us to keep in line with our compliance.
How has it helped my organization?
It saved us resources. We were a lean IT department, so I was able to reassign some staff to other projects because it didn't require so much hands-on manpower.
What is most valuable?
The notifications, the visibility, and the deployment are the most valuable. It could be packaged in such a way that it took a lot of time and resources off our hands, so it was more efficient. I don't know how to quantify the time saved. It would have saved us at least two to three hours a day just because the traditional IT department has a lot of other tasks and duties. It didn't require a lot for us to become experts on the product. It was seamless. It didn't require too much learning. It was easy to use.
What needs improvement?
With the incorporation of a lot of AI and machine learning, they can build some sort of a matrix for low-level threats or low-level things that require attention. There can be automation of those tasks so that we don't have to take more time and effort. There should be machine learning to eliminate level-one types of tasks.
For how long have I used the solution?
I used this solution for six years. I'm a Cybersecurity Instructor. I used it in my previous role. I'm not using it in my current role.
What do I think about the stability of the solution?
I thought it was extremely stable. I didn't see any downtime. Any of the maintenance windows were either on weekends or in time frames that didn't affect our organization. It was very good.
What do I think about the scalability of the solution?
It would be able to scale up even bigger and beyond what our local site needed. There were about a hundred and fifty employees. It was a manufacturing organization in San Antonio, Texas, but we were just one of twenty sites all throughout the US and Europe.
How are customer service and support?
They were helpful in total. I'd rate them an eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I believe we had a WatchGuard firewall with other services coupled around it. It didn't necessarily do all of the protection that we needed, but that's what we had at the time.
How was the initial setup?
I was involved in its deployment. It wasn't too challenging. It was easy to medium. Configuration with the compliance side was what took time and effort and was challenging, but it didn't have anything to do with the way the software is built. It was about getting our settings and configurations to be in alignment with the compliance.
What about the implementation team?
I believe headquarters had Check Point support.
What was our ROI?
The return on the investment was probably more beneficial to the headquarters or the mother corporation because we were just one of the remote sites that had the checkpoint infrastructure sent to us to build up our site. The bigger benefit was for the headquarters because they could manage all these individual sites from one platform. The consolidation and the standardization would have made their lives easier, but I didn't sit in a seat, so I don't know what that looked like.
We have seen time to value with this solution. It provided us with great benefits across the entire organization. We could see its value within about a month. That was probably enough time to let all of the initial shakeout and other things take place. We created a baseline after those thirty days, and we could see where we no longer needed to spend time. We could also see things where we had to take some action but were not apparent to us.
What's my experience with pricing, setup cost, and licensing?
They're a little high in price. The price could be lower.
Which other solutions did I evaluate?
I wasn't that high in the chain to be able to make that decision. Corporate pushed it down to our site, and that's what we had to go with.
What other advice do I have?
Attending an RSA Conference provides the ability to connect with others in the industry. It allows me to have a line of communication where I can reach out to them in person rather than just a digital introduction.
In terms of the impact of attending an RSA Conference on the cybersecurity purchases made throughout the year afterward, I don't necessarily think about our purchases, but considering I'm a Cybersecurity Instructor, the people that attend our classes are going to be able to benefit because I can provide them more solutions and answers to the questions that they have.
I enjoyed it as a product. It works well. Overall, I'd rate it an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IT Security Manager at a retailer with 10,001+ employees
Enables us to deliver connectivity in very short time frames and gives us much better control over sizing of firewalls
Pros and Cons
- "The features of the solution which I have found most valuable are its flexibility and agility. It's a fully scalable solution, from our perspective. We can define scaling groups and, based on the load, it will create new instances. It's truly a product which is oriented toward the cloud mindset, cloud agility, and this is a great feature."
- "The convergence time between cluster members is still not perfect. It's far away from what we get in traditional appliances. If a company wants to move mission-critical applications for an environment to the cloud, it somehow has to accept that it could have downtime of up to 40 seconds, until cluster members switch virtual IP addresses between themselves and start accepting the traffic. That is a little bit too high in my opinion. It's not fully Check Point's fault, because it's a hybrid mechanism with AWS. The blame is 50/50."
What is our primary use case?
We use CloudGuard IaaS for cloud security in AWS, and it serves all kinds of purposes for us. It could be internal segmentation between on-prem or between application VPCs, and it can also help us to provide perimeter security for those parts of the network that require internet access.
How has it helped my organization?
Our company has a very dynamic IT landscape, and the demand to go live is very high. That means we have to deliver connectivity in very short time frames, and we can do that using CloudGuard IaaS. Once we have figured out a working template for connectivity, it becomes our standard, and we can run connectivity for new applications within a day or two, and sometimes it might only take hours. In the past this would take a much longer time. We also now have much better control over the sizing of the firewalls, which gives us a lot of flexibility in our planning.
In addition, we use an existing on-premise appliance, which is a multi-domain security server. The use of CloudGuard's Unified Security Management was an easy part of our integration. We didn't need to make a lot of effort to incorporate the new firewalls. We just needed to apply some existing policies to the new firewall. We didn't have to develop something from scratch. We just used our existing infrastructure and existing policies, and it was the easiest part of the deployment. And the use of the Unified Security Management has definitely freed up security engineers to perform more important tasks.
What is most valuable?
The features of the solution which I have found most valuable are its flexibility and agility. It's a fully scalable solution, from our perspective. We can define scaling groups and, based on the load, it will create new instances. It's truly a product which is oriented toward the cloud mindset, cloud agility, and this is a great feature.
Check Point is a known leader in the area of block rate, so I don't have any complaints about it. It's working as expected. And similarly for malware prevention. When it comes to exploit resistance rate, it's excellent. I haven't seen any Zero-day vulnerabilities found in Check Point products in a very long time, which is not the case with other vendors.
The false positive rate is at an acceptable level. No one would expect a solution to be 100 percent free of false positives. It's obvious that we need to do some manual tuning. But for our specific environment and for our specific traffic, we don't see a lot of false positives.
Overall, the comprehensiveness of the solution's threat prevention security is great. It was changed in our "80." version and I know that Check Point put a lot of effort into threat prevention specifically, as a suite of products. They are trying to make it as simple as it can be. I have been working with Check Point for a long time, and in the past it was much more complicated for an average user, without advanced knowledge. Today it's more and more user-friendly. Check Point itself has started to offer managed services for transformation configuration. So if you don't have enough knowledge to do it yourself, you can rely on Check Point. It's a really great service.
Check Point recently released a feature which recognizes that many companies are going with the MITRE ATT&CK model of incident handling, and it has started to tailor its services to provide incident-related information in that format. It is easier for cyber security defense teams to analyze security incidents, based on the information that Check Point provides. It's great that this vendor looks for feedback from the industry and tries to make the lives of security professionals easier.
I highly rate the security that we are getting from the product, because the security research team is great. We all know that they proactively analyze numerous products available on the IT market, like applications and web platforms, and they find numerous vulnerabilities. And from a reactive point of view, as soon as a vulnerability is discovered, we see a very fast response time from Check Point and the relevant protection is usually released within a day, and sometimes even within a few hours. So the security is great.
What needs improvement?
Clustering has not been perfect from the very beginning. There weren't too many options for redundancy. It was improved in later versions, but that's something which should be available from the very beginning, because the cloud itself offers you a very redundant model with different availability zones, different regions, etc. But the Check Point product was a little bit behind in the past.
The convergence time between cluster members is still not perfect. It's far away from what we get in traditional appliances. If a company wants to move mission-critical applications for an environment to the cloud, it somehow has to accept that it could have downtime of up to 40 seconds, until cluster members switch virtual IP addresses between themselves and start accepting the traffic. That is a little bit too high in my opinion. It's not fully Check Point's fault, because it's a hybrid mechanism with AWS. The blame is 50/50.
For how long have I used the solution?
I have been using CloudGuard IaaS for close to one year.
What do I think about the stability of the solution?
In terms of the stability, so far everything is good. We have had no problems.
What do I think about the scalability of the solution?
The scalability is also great. It's not complicated to configure it and the environment can become really scalable. Everything can be auto-provisioned: instances created, policies pushed, licenses installed. Check Point did a great job in covering all these aspects and reducing manual intervention, which is how it is supposed to be on the cloud.
It is deployed in all AWS regions and we plan to increase the number of security features in use in the future.
How are customer service and technical support?
Check Point's technical support is great. We are a Diamond customer, meaning we have the highest level of support available from them. We always have very competent engineers and the right level of attention. We haven't had an opportunity to test technical support regarding this product, but in general we are happy with technical support we get.
Which solution did I use previously and why did I switch?
We did not have a similar previous solution.
The favorable results of its security effectiveness score from third-party lab tests were not a major part of our consideration because Check Point is a known leader. There were no doubts about security.
As for the solution being a leader for many years in industry reviews of network firewalls, it is important to go with a solution that not only has good specs on paper, but also has a known record of success.
How was the initial setup?
The setup process offered by Check Point is quite straightforward. The challenge is that there is no single blueprint for an organization, and that's why each and every company chooses its own design for the cloud. That means we have to be creative and start adjusting whatever Check Point provided as a setup guide, for our needs.
Setting up a working environment took us approximately 10 days.
Our implementation strategy was quite simple. We first needed to understand the business needs and what the stakeholders wanted us to deliver. Based on that we created a design draft: How to proceed with the least complexity, the best way to provide connectivity, and obviously, to do everything in a secure way. After creating a high-level draft, we started our work. Since the environment was not really in production yet, it was a long path of trial and error. But at the end of the day, all aspects were accounted for, lessons were learned, and we adjusted our initial design and prepared operational documentation for our operational team.
What's my experience with pricing, setup cost, and licensing?
Licensing is easy since this is a virtual instance which does not require RMA.
Which other solutions did I evaluate?
The cloud security provided by public cloud providers is great because it's cloud-native. Sometimes it comes without an additional cost or as part of a basic license, but it's definitely not enough for an enterprise environment. Everything comes back to operational complexity. I could incorporate a new, simple tool from a public provider, but on my side it would mean I would need to up-skill team members and manage an additional layer of security, and it could be hard for troubleshooting. To integrate these tools into the peripheral systems, like sending logs, and analyzing these logs, and maintaining additional rule sets from additional dashboards, would require additional efforts.
So cloud-native security has its own disadvantages. Many companies try to stick with the simplicity whenever they define the operational flows, but I prefer choosing Check Point everywhere in a hybrid environment to make my life easier from all perspectives.
What other advice do I have?
The biggest lesson I have learned from using this solution is that network security is moving away from traditional deployments and companies have to adapt themselves to stay competitive.
We are fully managing the service. As soon as a new version is released on the Check Point site, they make sure to release it for CloudGuard as well. But so far, we have stayed with our original version. We haven't done any upgrades.
The integration process between CloudGuard and AWS Transit Gateway is not straightforward, because we're not talking about traditional networking. There are a lot of different aspects that we are still not used to keeping in mind. For example, routing is completely reworked in AWS. It's just a matter of time to get used to it. Once you get used to it, everything becomes relatively easy.
In terms of our workflow when using the integration between CloudGuard and AWS Transit Gateway, we needed to review our operational documentation and prepare additional guides for our operations team on how to do it. We needed to up-skill our team members, and we needed to utilize new technologies or new features, like BGP over VPN, to make communication secure in the cloud.
The solution provides security for numerous corporate applications and is under the responsibility of the operations team which consists of about 15 people. For deployment and maintenance of the solution we have one security operations engineer, one network operations engineer, one AWS operations engineer, and one SDWAN engineer.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Security & Network Services at a tech company with 201-500 employees
Centralized management reduces workload and ensures continuous policy across infrastructure
Pros and Cons
- "We managed to reduce the effort and workload as well as the attack surface across our infrastructure. We now have a more continuous policy."
- "Centralized management is the feature I like best, resulting in reduced workload and more continuous policy."
- "Today, we are trying to look more into encrypted traffic."
What is our primary use case?
CloudGuard is protecting my cloud workloads. The secure communication between my on-premises network and the cloud network is the main use case. I am establishing one continuous rule set across all of my infrastructure and then maintaining all the guards and measures throughout my infrastructure.
How has it helped my organization?
We managed to reduce the effort and workload as well as the attack surface across our infrastructure. We now have a more continuous policy.
What is most valuable?
The centralized management is one of the key use cases.
I managed to reduce the effort, workload, and attack surface across my overall financial infrastructure. These are the main things. Centralized management is the feature I like best, resulting in reduced workload and more continuous policy.
We have unified security management across hybrid environments.
It's good for identifying security threats. We compare it to what cloud solutions providers offer. We look more into the actual traffic and the enforcement of the policy. What Check Point provides goes beyond and is not comparable to what is offered by the native network solutions.
We have confidence in secure cloud migrations. It's imperative to use a solution like this. We wouldn't want to run our cloud without this level of security and protection.
What needs improvement?
Today, we are trying to look more into encrypted traffic. API security is one of the most highlighted aspects we are currently evaluating. Network Detection Response (NDR) and AI protection are the main areas I am focusing on now. In addition, I am looking into Secure Access Service Edge (SASE) solutions in general.
For how long have I used the solution?
I have been using a Check Point solution for three and a half years now. I have used network security for a much longer period before that.
What do I think about the stability of the solution?
The stability is very good. I am very happy with stability.
What do I think about the scalability of the solution?
CloudGuard scalability is what it is. It integrates perfectly into the cloud world, which is what I expect. With the centralized management in place, scalability is perfect. I can deploy it everywhere I need it. Scalability is one of the key factors for selecting this solution.
How are customer service and support?
Check Point support is similar to other support on the market.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I have looked at Cisco and Palo Alto. I evaluated these solutions and then came to terms with Check Point. We like that it integrates with other security solutions from Check Point we're running.
Which other solutions did I evaluate?
We have looked at competitive vendors a lot and we decided to go with Check Point. We've looked at Cisco and Palo Alto, however, we preferred Check Point's centralized management.
What other advice do I have?
Overall, I would rate the product eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Last updated: Feb 23, 2025
Flag as inappropriateGlobal network and telecom director at a hospitality company with 10,001+ employees
Offers central console management that ensures we have uniform threat prevention policies
Pros and Cons
- "The most valuable feature for us is the scale set, which allows us to scale horizontally, vertically and dynamically depending on the traffic load."
- "There is room for improvement in the integration with PaaS services from the public cloud. It would be very helpful."
What is our primary use case?
I use it to protect our public cloud workloads today. It safeguards them directly from the internet and also from the corporate network. We have interconnected our Azure environments with our on-premises network, including our data centre. CloudGuard Network Security helps protect workloads within Azure from both the corporate network and the internet.
How has it helped my organization?
CloudGuard Network Security has significantly improved our operations. Its automatic scaling capability, based on the network load, eliminates the need for capacity planning.
We don't need capacity planning anymore or do proactive actions in order to always have that capacity planning, it does it automatically. Our network engineers now focus on administering the entire cluster rather than managing individual members and their loads.
Our confidence in our cloud network security is pretty high, largely because of central console management. It ensures that we have uniform threat prevention policies applied globally, which significantly boosts our confidence in the system.
What is most valuable?
The most valuable feature for us is the scale set, which allows us to scale horizontally, vertically and dynamically depending on the traffic load.
It provides us with unified security management across both CloudGuard and on-premises environments. We use CloudGuard Network Security for Azure and have a single management console that allows full visibility into logs and consolidated logs across all environments. This ensures we maintain consistent IPS, IDS, and threat prevention policies across all regions and data centres.
What needs improvement?
There is room for improvement in the integration with PaaS services from the public cloud. It would be very helpful. A more cloud-native approach is needed because even it is PaaS services require public cloud resources, even if the traffic load is low. These resources are still required for high availability and resiliency.
So, a full PaaS solution with improvements on that end, basically.
For how long have I used the solution?
I have been using it for five years now.
How are customer service and support?
We have many different firewalls worldwide in our environment. Check Point support provides direct, 24/7 support, even when some components may be outdated. Since almost 95% of our hardware is supported, they're still able to provide support for the remaining 5%, which is greatly appreciated.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We opted for CloudGuard primarily due to two factors, which ultimately became three.
- First was the Azure consumption cost, which was lower compared to competitors.
- Secondly, its plug-and-play capability is straight out of the box, as deployment is directly made from the Azure Cloud Marketplace. In contrast, with competitors, you have to manually import and deploy the image they provide, which isn’t off the shelf.
- The third factor was the scaling solution offered by CloudGuard, which we found to be the fastest.
How was the initial setup?
I was involved. It was straightforward, out of the box, plug and play.
What about the implementation team?
We didn’t use a reseller or integrator; it’s really simple to deploy, and we had the capability to set it up on our own.
What was our ROI?
I haven't calculated it because we deployed CloudGuard Network Security as part of our cloud journey. The ROI wasn't calculated solely on that part; it was more about the overall process of closing the data centre and moving to the cloud.
What's my experience with pricing, setup cost, and licensing?
The licesning has some good features. For example, the scaling feature is free of charge, allowing multiple scale-ups and scale-downs over a two-week period, which is pretty good.
However, since we are still on an IaaS infrastructure, we end up paying for firewalls that are operational without actually handling traffic loads. This is why a PaaS approach would yield more benefits for us.
What other advice do I have?
Overall, I would rate the solution an eight out of ten. The reason it's not a ten relates to the need for a more cloud-native solution that fits today's requirements. The deployment was five years ago, and we're still waiting for Check Point to evolve to truly have cloud-native capabilities.
I'd advise looking into the scale set feature and the out-of-the-box capability, which were really the silver bullets for us. It was a strong requirement, and if anyone is seeking that kind of solution, I would greatly recommend it.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Director at L8 Security
Offers seamless deployment, rapid scalability, and user-friendly management, providing robust protection against threats with ease
Pros and Cons
- "The SSL spectrum proved to be the most valuable for our incoming connections."
- "New features have been introduced recently, but they have not yet been integrated into CloudGuard Vsec."
What is our primary use case?
We utilize CloudGuard Network Security as virtual appliances deployed within virtual machines, acting as firewalls at the perimeter of our data center in QSaver. These virtual appliances safeguard all internet access originating from the virtual machines at our factory in Curitiba, Brazil.
How has it helped my organization?
The challenges we sought to tackle through the implementation of CloudGuard Network Security were to ensure the protection of our servers against threats and attempts to breach them via internet-facing avenues.
We found it advantageous due to its ease of implementation and use. There were no delays in receiving customer devices, which enhances security within the environment.
We enjoy all the benefits typically associated with physical appliances, even while utilizing virtual machines. Although it took some time for customers to fully grasp the benefits, as they weren't immediately clear, over time, they began to recognize the value it brings to their security infrastructure.
It offers us unified security management across hybrid CloudGuard deployments, as well as on-premises. The option to manage it bridges physical devices onto the data center. With consolidated logs accessible on the same management interface, it becomes highly convenient and straightforward to operate.
Comparing CloudGuard's network security to other solutions in terms of ease of use is challenging. Additionally, since we're already utilizing Check Point solutions, integrating it with hardware network security proves to be very straightforward and user-friendly.
We have a high level of confidence in the effectiveness of CloudGuard Network Security.
What is most valuable?
The SSL spectrum proved to be the most valuable for our incoming connections. This feature enabled us, for instance, to successfully prevent Log4J attack attempts.
What needs improvement?
New features have been introduced recently, but they have not yet been integrated into CloudGuard Vsec. It would be advantageous to have them implemented as they would improve the performance.
For how long have I used the solution?
I have been using it for three years.
What do I think about the stability of the solution?
It provides excellent stability capabilities.
What do I think about the scalability of the solution?
It offers good scalability abilities. We have a plan to increase the utilization of CloudGuard Network Security and its services in the future.
How are customer service and support?
I am satisfied with the customer service and support provided. I would rate it eight out of ten.
How would you rate customer service and support?
Positive
What about the implementation team?
In our deployment environment, each instance is strategically positioned at the forefront of the web servers within the data center, effectively serving its purpose. Specifically, it functions to regulate internet access for the servers and manage inbound connections from internet customers to the servers.
It's remarkably easy to deploy, by far the simplest. For instance, it only took us a few minutes to transition to production. This capability is incredibly beneficial, as it allows us to swiftly assist customers during emergencies by deploying a firewall and addressing any threats they may encounter.
What was our ROI?
Determining the return on investment can be challenging; however, we've observed other companies operating in the same sector with similar approaches. Despite encountering attacks, we have yet to experience any incidents. This absence of incidents serves as a metric for us, indicating the reliability of our alternative solution.
What's my experience with pricing, setup cost, and licensing?
The pricing is highly competitive and advantageous, offering great value.
What other advice do I have?
I recommend others to give it a try because of its simplicity in deployment, scalability, and usability. Overall, I would rate it ten out of ten.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Software Development and Information Security Manager at a manufacturing company with 201-500 employees
Makes policy management easy and helps to improve security score and uptime
Pros and Cons
- "The easy management of the policies is great for us because we are a small team and having easy management is great and useful for us."
- "At CPX, we heard that we can see all the things on the same platform. That is what we have been asking for, and hopefully, we are going to start seeing it this year."
What is our primary use case?
We use it to analyze all the traffic in our network. It is the main tool for security services and networking in our company.
How has it helped my organization?
We increased our security score by introducing the tool. We are continuing to grow and improve. In terms of policies, we have a lot of benefits in terms of the security cluster and how it works.
CloudGuard Network Security provides unified security management across hybrid-clouds as well as on-prem. We have a hybrid scenario in the company. We have 3% of services in the cloud, and we can use the same clusters and the same policies that we have on the on-premise side for our cloud services. We have the same benefits for both.
We are pretty confident in our cloud network security using CloudGuard Network Security. We are not exactly an Internet-exposure company, but we have a cloud setup. We are pretty confident with its configuration assessment. With Check Point as our partners, we are protected, and we can be confident in our security.
What is most valuable?
Microsegmentation is very useful for us because we minimize the surface attack. The easy management of the policies is great for us because we are a small team and having easy management is great and useful for us.
What needs improvement?
At this point, we are very happy with what is happening with their horizon. At CPX, we heard that we can see all the things on the same platform. That is what we have been asking for, and hopefully, we are going to start seeing it this year.
For how long have I used the solution?
I have been using CloudGuard Network Security since 2020.
What do I think about the stability of the solution?
It is stable. I cannot remember a time when we had any issues with it. Our operations are 24/7.
What do I think about the scalability of the solution?
It is scalable. We do not have any problems with it.
How are customer service and support?
We have had a good experience with the support and customer service, and we are happy with them.
I would rate them a nine out of ten. A unique issue that we have is related to the language. When the first level of support cannot resolve an issue and the issue needs to be escalated, we have a language challenge because the team is based in India. There are some limitations on both ends.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We used our cloud vendor's security but did not get as many details when we had any issues. We immediately moved to Check Point, and we are more confident of Check Point.
At first, we used Azure and Defender, and before we changed to CheckPoint, we used ESET. So, we had ESET and then we started rolling out Check Point. We had a mix with the cloud vendor solution, and then we went for Check Point.
How was the initial setup?
We have a mix of on-premises and cloud. We use the Infinity services.
My team deployed it. I have three security engineers on the team, and with the help of Check Point, we deployed it. We upgraded very recently in December, and it was a good experience. It has been running well.
What about the implementation team?
We used the services of a company based in Panama. With the Infinity contract, we had some professional time with Check Point, and they helped us set up some of the things. They reviewed some of the things that we deployed, so we have all the best practices.
What was our ROI?
I do not have a lot of details on that, but our uptime is pretty high.
What's my experience with pricing, setup cost, and licensing?
It is an expensive product, but when you realize that you need it, it does not feel so expensive.
We have had a good experience with them as partners. They have helped us with designing and having good architecture and the best equipment at the best prices. We find it a good deal.
Which other solutions did I evaluate?
We evaluated Microsoft's security suite. The thing that made us decide on Check Point was that Check Point had the least zero-day attack score. We have a lot of solutions from Check Point, and we stayed with Check Point.
We are now not evaluating other solutions because, since 2020, we have chosen Check Point as our partner. It continues to be the best solution for us to improve our score. We are not looking for software solutions from other vendors.
We always keep track of the service and the score, and with Check Point, there has always been the highest score.
What other advice do I have?
I would rate CloudGuard Network Security a ten out of ten. We are happy with the uptime and management. It is a good tool, and it provides a lot of value for us. We are happy.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Check Point CloudGuard Network Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2025
Product Categories
Firewalls Managed Security Services Providers (MSSP) Software Defined WAN (SD-WAN) Solutions Cloud and Data Center Security WAN Edge Unified Threat Management (UTM)Popular Comparisons
Fortinet FortiGate
Netgate pfSense
Cisco Secure Firewall
Palo Alto Networks NG Firewalls
Check Point NGFW
WatchGuard Firebox
Juniper SRX Series Firewall
Fortinet FortiGate-VM
Palo Alto Networks VM-Series
Barracuda CloudGen Firewall
Buyer's Guide
Download our free Check Point CloudGuard Network Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- We're trying to choose between Fortinet or Checkpoint UTM firewalls. Can you help?
- Is Check Point's software compatible with other products?
- What do you recommend for a corporate firewall implementation?
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Which is the best network firewall for a small retailer?
- When evaluating Firewalls, what aspect do you think is the most important to look for?
- Cyberoam or Fortinet?
- Fortinet, Palo Alto or Check Point?
- If you could go back, would you change your decision to buy that firewall and why?