What is our primary use case?
Our primary use case is as a Security Web Gateway for off-premises users.
We use Check Point for application control, IPS, and web filter on-premises and wanted an in-kind solution for off-prem users. The primary requirement was for the Harmony policy to be able to be managed from the same SmartConsole instance as our on-premises gateways are managed.
We wanted to be able to have one single policy, managed in one place, and for our users to have the same browsing experience whether off-prem or on-prem. It was also a primary requirement to be able to have the logs generated from Harmony merged into the same locations (SmartConsole and our SIEM) as our on-prem gateway logs go.
How has it helped my organization?
It has not improved our organization due to being unable to fully implement in the manner it was sold to us as being able to.
After attempting to use the same policy for Harmony that we use for on-prem users (managed by on-prem smartConsole), and after much time going through Check Point account reps and support, we were informed it is not possible to manage Harmony Connect policy from SmartConsole if layers or source objects (such as AD users, machines) were used.
We then were told by Check Point it would be possible to manage both policies from the same platform if we used the Management-as-a-Service Smart1Cloud smartconsole, but after further investigation, we were then later told by Check Point account executives and support that we are unable to manage Harmony policies from Smart1 Cloud, even though they are both housed in the Check Point Infinity Portal.
It is also not even possible to send our Harmony Connect logs to the Smart1Cloud portal, again - even though they are both within the Infinity portal.
What is most valuable?
HTTPS decryption is a valuable service and not always found in cloud-based secure web gateways. With as much traffic being HTTPS as opposed to HTTP these days it is very important to be able to run that traffic through all the security modules such as IPS and Application Control.
We also found the SAML integration to be useful. It is handy to be able to access the portal from anywhere in the world, though as mentioned above we are not fully implementing the product at this time due to other issues.
What needs improvement?
We want the overall ability to manage Harmony and on-prem policies from the same platform. Harmony lacks this ability when anything more than a vanilla access policy is used (we use layers and source user objects in our policy which make this impossible according to Check Point).
Also, we need the ability to send/merge Harmony logs into the same SmartConsole as our on-prem Gateways send logs to. Have been told this is not possible by Check Point. It makes it really difficult when you have to use two different platforms/portals to see logs
For how long have I used the solution?
I've used the solution for about six months.
What do I think about the stability of the solution?
I have not had any issues with stability, although we have not fully used the solution in the manner intended.
What do I think about the scalability of the solution?
I have not had any issues with cloud-based resources, so I assume it would be easily scalable.
How are customer service and support?
We have had many issues with customer support on this product.
One example: I created a support ticket for a simple issue on the product not being able to be installed on our client machines.
It took over a month to resolve with my team having to repeatedly follow up with support in order to get a result. My team eventually had to dig into the issue at a great depth ourselves and discovered the problem - it was that Check Point developers did not properly sign multiple scripts associated with installation, which would not allow it to install in our secure environment.
My team had to unpack the installer and dig around to examine the files and find the mistake in signing. The issue was then finally solved by Check Point developers in Tel Aviv.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We previously used Check Point Cloud Capsule, which is a similar product. However, we were never happy with its performance and its Application Control objects were very out of date. Support was always hard to get on it from Check Point as well. It was also unable to be used alongside our VPN solution (Microsoft Always-On VPN).
How was the initial setup?
The initial portal setup was straightforward in that the portal is automatically provisioned.
Getting users integrated through SAML was not straightforward in that the instructions from Check Point on linking it with Azure AD were not accurate. The pre-built Enterprise Application object within Azure AD that is provided for Harmony did not work either. We had to adjust several of the settings to make it work (which were not covered by any support article).
What about the implementation team?
We handled the implementation in-house.
What was our ROI?
We have seen a negative return on investment
What's my experience with pricing, setup cost, and licensing?
Pricing and licensing seemed acceptable; we have no complaints there.
Which other solutions did I evaluate?
We also evaluated solutions from Cisco and Palo Alto.
What other advice do I have?
Users should just make sure the solution will actually do what is expected, regardless of what the company says it can do.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.
How many devices does our customer have on average? They should use Harmony.