What is our primary use case?
The product protects our environment from specific threats; we 'approve' signatures manually (or automatically) based on the applications/appliances in use in our company. We are a logistics company hosting several websites/order management. The company is about 1000 FTE across several locations (in the Netherlands & Belgium). We have been using this for the last 10 years at least (since I have worked at the company). It's easy to use. The reporting is good. Usually, when threats emerge on the internet, there are signatures for this within a few hours.
How has it helped my organization?
We manually approve the signatures daily, for the software/appliances that we use. Based on the experience of the administrator, we prevent threats if they are present in our network; and we sometimes use the signatures in detect mode to gather intelligence (for instance to detect TLS1.0/TLS1.1 usage through the firewall).
This has helped us to identify several key webservers that would be vulnerable to 'downgrade attacks'. We could easily identify the vulnerable servers and remediate the issue based on the information we got from the reports we can generate.
What is most valuable?
The quick updates of the signatures when a new threat is identified are great. For instance, when Microsoft releases patches, we usually see new signatures for those issues that have to be patched in a day. This gives us time to test/deploy the patches while already being protected from the threats.
Also, it's very good with reporting. I can generate reports for management automatically based on the threats of the last day/week/whatever is needed.
It also clearly states the performance impact of a signature and the 'confidence' of a signature so you can quickly evaluate if you need to start panicking or not.
What needs improvement?
Sometimes protections are 'aggregated' into a single threat name when you look at the logs. I would prefer to see all protections named individually (for example, right now, 'web enforcement' is a category that contains several signatures).
I also wish there was an option to run reports of the individual signature 'usage'; it's not easy to generate views based on the number of 'hits' a signature has generated. (it is possible, however, there could be an easier option). For example, if you have a signature activated, for instance, a MS issue then patch your environment, it's 'hard' to identify if the individual signature has been 'hit'.
For how long have I used the solution?
I personally have used the solution since December 2012 - almost 10 years.
What do I think about the stability of the solution?
It's very stable. I haven't seen issues with signatures, downloading, or implementing the signatures, or the 'hits' that it generates.
What do I think about the scalability of the solution?
The product is very scalable; if you size your requirements properly when buying and don't 'prevent all signatures' and customize it for your environment.
How are customer service and support?
Customer support is fine. We have a vendor we use, and, if needed, can fall back on Check Point (I had a few very good remote sessions when we had issues with our firewall; no issues were seen with IDS/IPS).
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
The company I work for has used it since I've worked there; no switching was needed. We are happy with the solution.
How was the initial setup?
When implementing the solution, you must activate the blade on your firewall and decide if you want to do it manually or automatically and then (when doing it manually) approve/detect/ignore the relevant signatures. It is pretty straightforward.
What about the implementation team?
We had a vendor team install the firewall and handle the basic configuration, then we went on training. In terms of implementation, I can do it myself now. The vendor team was very good and had a high level of expertise.
What was our ROI?
I'm a network admin; not involved in the money.
What's my experience with pricing, setup cost, and licensing?
I'd advise users to bundle the things they want; so they get a cheaper offer.
Which other solutions did I evaluate?
We've had the same solution since I've worked there.
What other advice do I have?
I am happy with the solution and have been using it since i started working for the company (10 years now). I dont want to be without it.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.