It is a bit expensive according to the required blades but it is a platform that is worth having as security in a corporate.
Contracted IT Staff at Sağlık Bakanlığı-Turkish Ministry of Health
User-friendly, easy to configure, and great for corporate environments
Pros and Cons
- "It is a very friendly platform and easy to configure."
- "It is a bit expensive according to the required blades but it is a platform that is worth having as security in a corporate."
How has it helped my organization?
What is most valuable?
I have worked for several years with the Check Point platform (NGFW) and it is by far the most stable in hardware and software.
It is a very friendly platform and easy to configure. It is true that it is a bit expensive (according to the required blades), however, it is a platform that is worth having as security in a corporate environment.
For how long have I used the solution?
I've used the solution for more than five years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Linux Administrator at Cartrack
Simple to scale with a nice management interface and good technical support
Pros and Cons
- "Many problems have been solved with these firewalls and we've largely been very satisfied."
- "The predefined reports are few and it would be nice to increase them since the logs are excellent."
What is our primary use case?
Check Point's Next Generation Firewall has definitely improved our organization as we previously used a Linux firewall and we have had to manually configure internet control measures. When it comes to configuring firewall policies it was time-consuming. This has been taken care of by Check Point's Next Generation firewall. Even the integration to the Active Directory has been made to be seamless and requires a minimum effort from our security and network administrators. The technologies that are in place are amazing. For example, the Threat Extraction and Threat Emulation technologies. The Sandbox technology, or Threat Cloud, is world-class.
How has it helped my organization?
The remote access blade functionality is really valuable as we now need to just install the client on the user's machines and the client can be preconfigured with the site details. This makes our lives very simple. The logging of the firewall is also phenomenal as it is very granular and very easy to filter.
The Application control blade is another valuable feature as we now only need to create a rule to be applied and to specify the applicable application which is categorized. The ability to configure dynamic objects, for example, Microsoft Office 365, is also a valuable feature.
The reports are very detailed and the variety is amazing. It caters to everything and is even more that what we had bargained for. They are also customizable, which makes them extremely valuable to us.
Another great feature is the ability to publish corporate applications in a secure web environment.
What is most valuable?
Many problems have been solved with these firewalls and we've largely been very satisfied. Thanks to this infrastructure that we have managed, in this pandemic time, to quickly and effectively offer the potential to remotely work for everyone has been good.
Also important is the separate management interface that has made it possible to carry out even the most operations while comfortably seated at the desk. It provides multiple profiles that you can apply depending on the scenario that presents itself.
What needs improvement?
It takes a while to install the rules so that if you make a mistake you can only fix it after a few minutes. There's no problem with traffic processing.
Sometimes you are forced to interact on several levels: on the one hand, you put in the rules, and on the other, you put in the route. The predefined reports are few and it would be nice to increase them since the logs are excellent.
In my work experience, I have been able to use multiple firewall platforms. There are only two valid ones for me and one of them is definitely Check Point. The others charge less but there is a reason for that. It is a good idea to think carefully before rather than after you suffer from a serious attack.
For how long have I used the solution?
We have been using the solution for three years now.
What do I think about the stability of the solution?
For me, the solution has been stable. Perhaps running it on a small scale helps.
What do I think about the scalability of the solution?
I like the fact that it's so simple to scale.
How are customer service and technical support?
I find the support to be very prompt. They go the extra mile to assist and are thorough in their troubleshooting.
Which solution did I use previously and why did I switch?
I did not use a different solution, however, I came to know about this product while I was working for a company called Syrex.
How was the initial setup?
It was set up for us by a company I used to work for.
What about the implementation team?
It was through a vendor, and they were very good and did it on time as they promised.
What was our ROI?
A stable and fully functioning solution has enabled us to focus on other aspects of growing the business.
Which other solutions did I evaluate?
I looked at Fortigate, and it was not as clearly defined, and easy to follow as Check Point is.
What other advice do I have?
Check Point does cost a lot, but for me, it's worth the money I paid.
Some of the products are easier to deploy. For example, the Harmony products are simpler as they have a per user/per device pricing model.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Check Point NGFW
January 2025
Learn what your peers think about Check Point NGFW. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,071 professionals have used our research since 2012.
Firewall Engineer at a logistics company with 1,001-5,000 employees
Scalable, stable, and configurable
Pros and Cons
- "Check Point helps a lot with automatization which definitely reduces the effort to maintain the environment."
- "The policy installation length is still too long. It was promised that the time would be severely reduced in newer versions, but it is still too long."
What is our primary use case?
We use Check Point Gateways for securing our data centers including DMZ networks as well as gateways for our branch offices around the world. They are connected via MPLS, internet, or site-to-site VPNs depending on the branch connectivity.
A minimum standard for the whole environment is the NGFW. Firewall rules according to our security policy. VPN for site-to-site tunnels to our own gateways or to partners and customers. IPS is set primarily to prevent, and for some signatures to detect.
Application Control is still in the early stages.
How has it helped my organization?
Firewalling is one of Check Point's core business attributes, and it just works.
Creating site-to-site VPNs between Check Point Gateways that are within the same management is unbelievably easy. If you create VPNs for 3rd parties and there are mismatches or issues, you will see logs that help pinpoint issues or misconfiguration.
Application control help with identifying applications and therefore makes firewall rules easier since changing ports don't have to be adapted every time an application changes or updates.
What is most valuable?
Generally speaking, all features are well documented and the two platforms help with configuration. Documentation and knowledgebase articles in the user center as well as user recommendation within the forums are great. The Admin Guides are really well documented, but it's a lot to read.
Check Point helps a lot with automatization which definitely reduces the effort to maintain the environment. The best example would be the CDT tool which helps with decreasing the amount of time for upgrading whole environments.
What needs improvement?
The policy installation length is still too long. It was promised that the time would be severely reduced in newer versions, but it is still too long. R81 promises at least parallel policy installations, which help in larger environments.
Check Point's advantage (to be able to configure everything) is also a disadvantage. The environment is quite complex. Troubleshooting is not always easy as there are a lot of possible debugs that can be taken, and the support will not always send the right or necessary debugs. Some debugs also can cause a heavy load, so you have to keep an eye on what you troubleshoot.
For how long have I used the solution?
Our company has used Check Point for well over 10 years.
What do I think about the stability of the solution?
If it's running, it's stable. New setups have to be tested though.
What do I think about the scalability of the solution?
The solution can be scaled from very small branch offices to huge data centers or even cloud data centers.
How are customer service and technical support?
Support depends on how well you describe the issue and send information. Sometimes escalation is necessary.
How was the initial setup?
The more features (blades) are turned on, the more complex the environment becomes. If something goes wrong, you have to rule out several issues (hardware, blades, et cetera).
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Manager IT & Security at mCarbon Tech Innovations Pvt., Ltd.
Scalable, easy to install, and quick to deploy
Pros and Cons
- "It's quite a stable solution."
- "The pricing could always be more competitive."
What is our primary use case?
As a next-generation firewall, this product is capable of handling all kinds of threats that might try to attack the network, including events such as DDoS attacks.
How has it helped my organization?
The compliance part of the product has been very useful to our organization. There are many useful reports from this firewall device. For example, it can tell us how much of our network has compliance with the guidelines that are in place.
What is most valuable?
The product is very easy to use.
It's quite a stable solution.
The scalability is very good.
The solution is easy to install and deploy.
What needs improvement?
The product could always be even more stable and secure, as it would improve protection.
As we aren't using the very latest iteration, it's hard to say which features are lacking, as some might have been added in the latest releases we haven't yet migrated over to.
The pricing could always be more competitive.
Technical support needs to be more helpful.
For how long have I used the solution?
I've been using the solution for the last six months or so. It's been less than a year, and therefore, it hasn't been that long.
What do I think about the stability of the solution?
The stability is good. There are no bugs and glitches. It doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
The solution offers good scalability. If a company needs to expand it, it can do so. It's not hard.
We have 50 users on the solution right now.
How are customer service and technical support?
I would say that technical support could be better. We also use Cisco, and, in comparison, Cisco's support is way better in terms of how helpful and responsive they are. We aren't as satisfied with Check Point. They need to be faster, friendlier, and much more knowledgeable.
Which solution did I use previously and why did I switch?
Right now I am using Check Point and Cisco ASA.
How was the initial setup?
The initial setup is not overly complex or difficult. It's pretty straightforward.
The deployment doesn't take long either. It's a fast process.
You only really need two people for deployment and maintenance for most setups.
What about the implementation team?
I handled the implementation myself. I did not need the assistance of an integrator or consultant.
What's my experience with pricing, setup cost, and licensing?
The solution could work to make the pricing a bit lower. It's similar in cost to Palo Alto, however, if it was lower, it would make them more competitive.
What other advice do I have?
We are a customer and an end-user. We don't have a business relationship with Check Point.
We are not using the latest version of the solution, however, I cannot speak to the actual version number. We might be a version or two behind the latest update.
I'd rate the solution at an eight out of ten. We've largely been quite pleased with its capabilities.
I would recommend the solution to other users and companies.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Good VPN and deep packet inspection capabilities, helpful reporting
Pros and Cons
- "The most valuable feature is the powerful, deep packet inspection engine."
- "There should be better integration with our current NAC solution to increase the granularity of policies that we implement."
What is our primary use case?
Our primary use case is to secure the perimeter and users in our network.
We use IPS/IDS, deep packet inspection, and VPN.
How has it helped my organization?
Our network performance and safety have improved. The reporting also gives us more information about our network, including cost and risk reduction.
This solution helps to keep our network safe and secure, protecting our investment.
What is most valuable?
The most valuable feature is the powerful, deep packet inspection engine.
The management console and diagnostic tools are powerful and we are happy with them.
The reporting is detailed and helpful.
What needs improvement?
There should be better integration with our current NAC solution to increase the granularity of policies that we implement.
For how long have I used the solution?
We have been using the Check Point NGFW for two years.
What other advice do I have?
Overall, this is a very complete tool.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Network Security Assurance Specialist at Visa Inc.
Easy to configure, facilitates security compliance, and provides good visibility
Pros and Cons
- "I think the VSX has been the most valuable feature for us."
- "Debugging could be improved when compared to the competition."
What is our primary use case?
The main use case is Firewall provisioning and integration with Tufin and Skybox. Also, we focus on firewall compliance, rule review, VPN configuration, and network troubleshooting.
How has it helped my organization?
Working for one of the largest companies, I found that using Check Point has made firewall provisioning very easy for us, and integration with the above-mentioned tools has eased the process of PCI audit, security compliance, and rule recertification.
What is most valuable?
I think the VSX has been the most valuable feature for us. We use it for tunnel management, which is great. The configuration has been quite straightforward.
What needs improvement?
Debugging could be improved when compared to the competition.
I think the product release lifecycle should be improved.
For how long have I used the solution?
We have been using Check Point NGFW for almost eight years.
Which solution did I use previously and why did I switch?
Previously, we used Cisco ASA. We switched because of the fact that Check Point offers more stability and visibility into the firewalls. Management is easier, especially using the GUI version.
What's my experience with pricing, setup cost, and licensing?
I think that the pricing is different for every organization.
Which other solutions did I evaluate?
We did evaluate Juniper, as well.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Network Engineer at Getronics
Very intuitive solution that is easy to configure, deploy, and maintain
Pros and Cons
- "It provides a central station where it is very easy to deploy our firewall policy in one click to many firewalls. This is one of the leading perks. It saves time by having one central station because I can deploy the same kind of policy to many firewalls at once."
- "The virtual environment is not stable at all. We have some customers who are using the virtual environment feature, and sometimes it crashes. We have many tickets open and the response is not as good as expected. We have to wait months for a resolution."
What is our primary use case?
The primary use of the firewall is to allow or block some traffic. Mainly, it is the perimeter firewall for the Internet. It filters the traffic from external to internal, e.g., to secure the traffic.
Some of our customers have been demanding Check Point as their firewall product.
I do the installation, support, firewalls, etc.
How has it helped my organization?
It provides a central station where it is very easy to deploy our firewall policy in one click to many firewalls. This is one of the leading perks. It saves time by having one central station because I can deploy the same kind of policy to many firewalls at once.
With the latest release, it's easy to configure firewall rules with the scripting. This is one of the features that we have been demanding for some time so we can script some actions for automation.
What is most valuable?
The best part is that it is very intuitive. It is easy to configure, deploy, and maintain. If it works, it works.
The troubleshooting: When you find something that is not working, it is very easy to check in the logs what is failing and fix it in a short time.
The login tool is really nice.
What needs improvement?
We can virtualize the physical firewall in a virtual environment. However, the virtual environment is not stable at all. We have some customers who are using the virtual environment feature, and sometimes it crashes. We have many tickets open and the response is not as good as expected. We have to wait months for a resolution.
If you use all the features available on the firewall, it's not working. If you keep it simple, then it works. When you try to do cool things, you start to have some problems because that kind of integration is not fully developed.
For how long have I used the solution?
I have worked with Check Point since 2007.
What do I think about the stability of the solution?
When it is failing, it is a nightmare. The stability has room for improvement. Sometimes, it is not working at all.
What do I think about the scalability of the solution?
The scalability is good. I haven't had any scalability issues. If the firewall gets stressed, we buy a new firewall.
There are many options, such as, virtualization. They have also release a new product, Quantum, that makes it possible to scale up and have more firewalls.
As an integrator, we have very big companies (like banks) to small companies, who have only 200 users or less.
How are customer service and technical support?
I would rate the technical support as a six out of 10. I have customers with no tickets open with Check Point and other customers who have many tickets open.
Solving some issues with them is a nightmare. They don't reply in time. They always ask the same questions. I expect better feedback from them, but that usually never happens.
Which solution did I use previously and why did I switch?
Before Check Point, I used Cisco and Fortinet FortiGate.
The big differences is really the full integration firewall, e.g., Cisco doesn't provide this. Also, the Check Point central console is so much better because it provides that one central station, which is a plus.
The con for Check Point is the stability. The hardware for Check Point fails more often than other vendors. Usually, other firewalls are more stable than Check Point so I don't have to open as many cases with other vendors, like I do with Check Point.
How was the initial setup?
There are two parts:
- In the physical, you deploy with a wizard, which makes it very easy. It is a standard wizard where you click "Next, Next," then you see the GUI and everything is done there.
- It is possible to do it in automatic way with the scripting. In the cases that you have some experience on it, it's very easy to deploy some scripts and the firewalls. For example, in the cloud, I created my own firewall with the same setup every day using the auto-integration since it's possible to integrate Azure with Check Point, which is very easy. One of the best features of the Check Point is its integration with the cloud, because not all vendors have that kind of integration.
The deployment time depends. If I do any scripting, it takes 30 minutes. If I do it manually, the deployment takes two hours. It also depends on the size and scope of the deploy, e.g., if I create a basic firewall rule or do a full automatic migration. However, It does take less time than other firewalls.
The implementation strategy depends on the customer.
What was our ROI?
I can deploy one firewall in an easy way. I can do it quickly by equiping firewall rules in text mode or in the API. However, when I have a problem, it's totally the opposite. I lose a lot of time.
What's my experience with pricing, setup cost, and licensing?
The pricing and licensing are the worst part of Check Point. I usually don't know what I really am buying. When I have to do an inventory of the license, I don't know what it is being used for. Sometimes I feel I am being cheated, and the others times, I feel it is a bargain. Nobody knows! Even the Check Point representatives, they aren't clear on somethings, such as, what is the right license for what I need.
There is a possibility to have diamond support. You can have a technical engineer who is there just for you. When you have that type of feature, it's more expensive.
Which other solutions did I evaluate?
Cisco NGFWv
What other advice do I have?
- Check the price first.
- For migrations between different vendors, it's a nightmare. You need to do some tasks manually, otherwise it doesn't work when you migrate it.
- Check the performance if it is working as expected.
- Try to keep it simple.
It is a good product. I would rate the solution as an eight out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partners.
Network and IT Security Admin at DP World Callao
The configuration is easier than other firewalls and we have good support
Pros and Cons
- "We never had an outage of the appliances or the consoles. Stability is very strong. I never had a problem related to stability."
- "I would like for them to develop the ability to manage a cloud firewall with the same console. That would be very helpful."
What is our primary use case?
Check Point is a very good solution. My primary use case is as a perimeter firewall. I never use Check Point's IPS. I always work with another IPS, in a different appliance. I always use the firewall modem as a firewall.
How has it helped my organization?
We have good support from Check Point. They always send us information about new products, new technologies, and new attacks worldwide. We are looking for endpoint protection and Check Point is one of the brands that could provide that technology to us.
What is most valuable?
The most valuable feature of Check Point is the management console. Another feature that is most valuable for me is that the configuration is easier than other firewalls.
What needs improvement?
I would like for them to develop the ability to manage a cloud firewall with the same console. That would be very helpful.
Another thing I would like to see improved is that when I start policies in Check Point's console, it takes a few minutes. It could be better and faster.
For how long have I used the solution?
Three to five years.
What do I think about the stability of the solution?
We never had an outage of the appliances or the consoles. Stability is very strong. I never had a problem related to stability.
What do I think about the scalability of the solution?
Scalability is good. Since four years ago, we have been increasing the number of users and the traffic. The solution is working well and working with our progress.
How are customer service and technical support?
I always work with a partner so the partner is in contact with Check Point. Their response is very fast. In all of the cases, it's very fast.
Which solution did I use previously and why did I switch?
We switched because it is a good product and because of the cloud support. We are moving to the cloud step by step and the cloud support is important. If another company has better cloud support it may be a factor that would influence my company to switch to another solution.
Important criteria that we look at when choosing a solution is the local experience and the local support. That it is very important.
How was the initial setup?
I wasn't there for the initial setup but from what I heard, it was straightforward.
Which other solutions did I evaluate?
We looked at Cisco vs Fortinet. We chose Check Point because of the cost benefit that this product offers.
What other advice do I have?
I would rate this solution an eight. It's a good solution. The management is easy. The console is very practical but in order to be a ten, it should be faster.
I would advise someone considering this or a similar solution to prove the solution before choosing the final vendor. Prove that it will be very helpful for you.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Check Point NGFW Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
OPNsense
Cisco Secure Firewall
Sophos XG
Palo Alto Networks NG Firewalls
Azure Firewall
WatchGuard Firebox
SonicWall TZ
Juniper SRX Series Firewall
Fortinet FortiGate-VM
Untangle NG Firewall
SonicWall NSa
Sophos XGS
KerioControl
Buyer's Guide
Download our free Check Point NGFW Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- How does Check Point NGFW compare with Fortinet Fortigate?
- Is Palo Alto Networks NG Firewalls better than Check Point NGFW?
- Which would you recommend - Azure Firewall or Check Point NGFW?
- Is Check Point's software compatible with other products?
- What do you recommend for a corporate firewall implementation?
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Which is the best network firewall for a small retailer?
- When evaluating Firewalls, what aspect do you think is the most important to look for?
- Cyberoam or Fortinet?