It's our main firewall and the first line of protection from outside attacks. We use it to interconnect our remote locations (that use different vendors and equipment) and let the employees work remotely. We're a small site with 300 users and this equipment is more than enough for us. We use almost all the blades and the equipment has run smoothly for years. This NGFW monitors all the traffic outside of the main network, prevents malicious activities, and lets us easily manage network policies to shape our connections.
IT Manager at a transportation company with 501-1,000 employees
Easy to set up, stable, and offers excellent technical support
Pros and Cons
- "The packet inspections have been a strong point."
- "I would like there to be a way to run packets that capture more easily in the GUI environment. Right now, if we want to read packet captures, we have to do so from the command line."
What is our primary use case?
How has it helped my organization?
We have a lot of flexibility now, and a leg up identifying zero-day threats. We have multiple ways of doing policies now that we didn't have before. The options are more robust than previous products and I would say that we're pleased with the product. The reports I'm getting are that we're satisfied, even impressed, with the options Check Point offers.
There is a scope of improvement in detecting zero-day threats using the SandBlast technology, by introducing emulation of Linux-based operating systems. We have also observed issues while using the products with SSL decryption. There is room for improvement in application-based filtering, as with other firewalls available in the market today. Check Point has improved its application filtering capabilities in the recent past and their latest version, R80, is more capable but still, creating an application-based filter policy is a little cumbersome.
What is most valuable?
It's a NGFW with all of the capabilities required to protect for next-generation attacks at the perimeter level. The module or Security features that are provided as part of the base license with Check Point include (VPN, IPS, Application Control, and Content Awareness) which itself is strong enough to protect the organization.
The packet inspections have been a strong point. Our identity collectors have also been helpful. In many ways, Check Point has been a step up from the SonicWall that we had in-house before that. There's a lot of additional flexibility that we didn't have before.
What needs improvement?
I would like there to be a way to run packets that capture more easily in the GUI environment. Right now, if we want to read packet captures, we have to do so from the command line.
The biggest improvement they could make is having one software to install on all three levels of their products, so that the SMBs, the normal models, and the chassis would all run the same software. Now, while there is central management, everything that has to be configured on the gateway itself works differently on the three kinds of devices.
Buyer's Guide
Check Point NGFW
November 2024
Learn what your peers think about Check Point NGFW. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
815,854 professionals have used our research since 2012.
For how long have I used the solution?
I started using the solution 3 months ago.
What do I think about the stability of the solution?
The web interface was easy for me. The configuration is logical, so it's easy to use and easy to understand how to protect, how to open a port, how to manage, and how to route a device. That's why I prefer Check Point. It's robust and I never have issues with the hardware.
What do I think about the scalability of the solution?
The scalability is quite good. You can scale well across locations for not too much cost. If a company needs to expand, it can do so relatively easily.
Also, cost-wise, it's very affordable to scale up. It's not expensive to add hardware and licenses as needed. They make upgrading very cheap.
We have 200 people on the solution. That said, they are using it with an IPsec tunnel. They don't use all of the capabilities of the hardware. They are using it just to encrypt tunneling between the sites.
How are customer service and support?
Technical support has been excellent
Which solution did I use previously and why did I switch?
Yes, we were previously using SonicWall but security is less robust in comparison to Check Point.
How was the initial setup?
The initial setup is very easy.
What about the implementation team?
We implemented it through a vendor called S G Informatics India Pvt Ltd.
The level of expertise I would rate at 10 out of 10.
What's my experience with pricing, setup cost, and licensing?
I would recommend going into Check Point solutions. Although Check Point has the option of implementing your firewall on a server, I would advise implementing it on a perimeter device because servers have latency. It's best to deploy it on a dedicated device. Carry out a survey to find out if the device can handle the kind of workload you need to put through it. Also, make it a redundant solution, apart from the Management Server, which can be just one device. Although I should note that, up until now, we have not had anything like that ourselves.
Which other solutions did I evaluate?
We have looked into Sophos.
What other advice do I have?
The most valuable features are the security blades and the ease of managing the policies, searching logs for events, and correlating them.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Manager IT & Security at mCarbon Tech Innovations Pvt., Ltd.
Scalable, easy to install, and quick to deploy
Pros and Cons
- "It's quite a stable solution."
- "The pricing could always be more competitive."
What is our primary use case?
As a next-generation firewall, this product is capable of handling all kinds of threats that might try to attack the network, including events such as DDoS attacks.
How has it helped my organization?
The compliance part of the product has been very useful to our organization. There are many useful reports from this firewall device. For example, it can tell us how much of our network has compliance with the guidelines that are in place.
What is most valuable?
The product is very easy to use.
It's quite a stable solution.
The scalability is very good.
The solution is easy to install and deploy.
What needs improvement?
The product could always be even more stable and secure, as it would improve protection.
As we aren't using the very latest iteration, it's hard to say which features are lacking, as some might have been added in the latest releases we haven't yet migrated over to.
The pricing could always be more competitive.
Technical support needs to be more helpful.
For how long have I used the solution?
I've been using the solution for the last six months or so. It's been less than a year, and therefore, it hasn't been that long.
What do I think about the stability of the solution?
The stability is good. There are no bugs and glitches. It doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
The solution offers good scalability. If a company needs to expand it, it can do so. It's not hard.
We have 50 users on the solution right now.
How are customer service and technical support?
I would say that technical support could be better. We also use Cisco, and, in comparison, Cisco's support is way better in terms of how helpful and responsive they are. We aren't as satisfied with Check Point. They need to be faster, friendlier, and much more knowledgeable.
Which solution did I use previously and why did I switch?
Right now I am using Check Point and Cisco ASA.
How was the initial setup?
The initial setup is not overly complex or difficult. It's pretty straightforward.
The deployment doesn't take long either. It's a fast process.
You only really need two people for deployment and maintenance for most setups.
What about the implementation team?
I handled the implementation myself. I did not need the assistance of an integrator or consultant.
What's my experience with pricing, setup cost, and licensing?
The solution could work to make the pricing a bit lower. It's similar in cost to Palo Alto, however, if it was lower, it would make them more competitive.
What other advice do I have?
We are a customer and an end-user. We don't have a business relationship with Check Point.
We are not using the latest version of the solution, however, I cannot speak to the actual version number. We might be a version or two behind the latest update.
I'd rate the solution at an eight out of ten. We've largely been quite pleased with its capabilities.
I would recommend the solution to other users and companies.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Check Point NGFW
November 2024
Learn what your peers think about Check Point NGFW. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
815,854 professionals have used our research since 2012.
Geography and History Teacher at a comms service provider with 10,001+ employees
Improved network performance, good management console and diagnostic tools, insightful reports
Pros and Cons
- "We are delighted with the powerful management console and diagnostic tools."
- "The number of physical network ports on the device should be increased to allow for greater capacity."
What is our primary use case?
In my company, we use the Check Point NG Firewall solution to secure the perimeter and user network. We use IPS/IDS, deep packet inspection, and VPN. We have implemented routing rules based on the destination of the traffic, and the performance of the global solution is satisfactory.
We use the solution, too, as the firewall in a core node, which is very important to the business. It secures the network equipment and service integrity.
We are delighted with the powerful management console and diagnostic tools.
How has it helped my organization?
The Check Point Next Generation Firewall has improved the performance of our network, bringing the IT administrator a lot of information and data to make decisions about security, vulnerability, strengths, and weaknesses in our deployed projects.
It provides a lot of information to help better understand our users. Now we feel more confident with our network and know what happens on it, as well as what kind of traffic we have.
In addition, we have many reports that include data to help with decision-making and information about how the solution reduces cost and risk.
What is most valuable?
The most valuable feature in my opinion is the powerful deep packet inspection engine. This engine provides me with a great capacity to control the traffic generated by my users and provides our company with a very real vision of the use that users make of the network.
The reporting capability is very important as we are able to show the company management the benefits and the return on investment, in terms of securing our network.
What needs improvement?
The number of physical network ports on the device should be increased to allow for greater capacity.
Another point of improvement would be to continue improving the integration line with our current NAC solution in order to exchange more attributes and increase the granularity of the implemented policies.
For how long have I used the solution?
We have been using the Check Point NGFW for three years.
Which other solutions did I evaluate?
Compared to other similar solutions on the market, this product is quite complete.
What other advice do I have?
In my opinion, this solution is already quite complete with respect to our requirements.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Consultant at KoçSistem
Lots of features, with high availability and helpful support
Pros and Cons
- "If you want to share traffic loads to both cluster members you can use the active-active feature, if you don't want to share traffic loads you can prefer active standby."
- "Check Point should add additional management choices."
What is our primary use case?
I'm a consultant and Check Point partner. I have deployed a lot of Check Point firewalls and support Check Point firewalls for our customers. Our customer environments are different. I deployed standalone, cluster, and two-layer firewalls.
One of our customers has over 200 branch offices which were protected by Check Point SMB appliances. All these appliances are managed by CheckPoint SmartProvisioning.
This customer has one cluster Check Point which secures server segments and one cluster Check Point which secures client segments.
How has it helped my organization?
Check Point firewall products include a lot of modules. Application Control, IPS, email security, mobile access, content awareness, URL filtering, antivirus, antibot, and DLP. Check Point meets our customer requirements at the perimeter with an all-in-one solution.
For example, the IPS blade prevents attacks with updated signatures. URL filtering policy control customers users' internet activity. Antivirus and antibot blade controls malicious activity and files. Mobile access blades give customers to access their sites from anywhere securely.
What is most valuable?
There are a lot of features that I found valuable for our customers.
For example, active-active and active-standby high availability features are very useful.
If you want to share traffic loads to both cluster members you can use the active-active feature, if you don't want to share traffic loads you can prefer active standby. Your connections sync on both cluster members at both high availability choices. That way, your connections are never lost.
Another valuable feature is performance improvement ability. With ClusterXL and CoreXL you can improve performance.
What needs improvement?
Check Point should add additional management choices. For example, Check Point doesn't fully have management support via browser. You need to use Check Point's SmartConsole for management. SmartConsole is .exe and it is supported only on the MS Windows platform. If you are using Linux or a Mac you can not manage Check Point. You should be able to use a virtual PC whose OS is Windows inside the Linux or MAC. Check Point states that this is a decision made for security reasons, however, certain management features can be done through the browser, yet not fully.
For how long have I used the solution?
I have been using the Check Point firewall for about 20 years.
How are customer service and support?
Check Point support center is very professional.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We did not use a different solution previously.
What's my experience with pricing, setup cost, and licensing?
After buying the firewall, you can use Check Point for a lifetime, however, it is a subscription base for content security features.
Which other solutions did I evaluate?
We also evaluated Fortinet and Cisco.
What other advice do I have?
If you are looking for a firewall appliance that has a lot of security features, easy installation, and configuration, Check Point firewall products are the best for you.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: KocSistem
Works at a insurance company with 201-500 employees
Stable with good virtual patching and excellent filtering of URLs
Pros and Cons
- "The VPN tunnels are very effective in terms of stability and quick connection."
- "The interface can be more user-friendly in terms of design and the location of critical and commonly used icons."
What is our primary use case?
The environment in which it was deployed is a financial institution that requires high availability, confidentiality, and integrity of information within the supporting infrastructure. The NGFW is used specifically for the VPN, firewalling and it also serves as virtual patching in the event of zero-day vulnerabilities that are very common within some well know client desktop computers and servers.
How has it helped my organization?
Initially, I was using the Cisco ASA5500 series firewall. I never believed there could be better firewall devices in terms of ease of setup and management. The NGFW from Check Point has increased my confidence in terms of performance and ease of configuration with its intuitive interface. It supports the VPN configuration without any unnecessary latency and packet dropping.
It blocks over 97% of threats!
What is most valuable?
VPN, firewalling, and virtual patching are the most valuable aspects for me. The NGFW is so effective that I can go to sleep and vacation. Check Point products rarely have vulnerabilities that put the whole organization at risk, unlike some other firewall products.
The VPN tunnels are very effective in terms of stability and quick connection.
Virtual patching is useful as a workaround for zero-day vulnerabilities.
It offers excellent filtering of URLs.
What needs improvement?
The interface can be more user-friendly in terms of the design and location of critical and commonly used icons.
They could add a web user Interface.
For how long have I used the solution?
I have been using the Check Point NGFW since 2018 when it was deployed in my company.
What do I think about the stability of the solution?
The stability is awesome and it puts me in a no-worries mood!
What do I think about the scalability of the solution?
The scalability is awesome.
How are customer service and support?
Technical support is friendly and awesome.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I did use Cisco ASA. The administration was grueling coupled with some nefarious vulnerabilities and the cost of ownership.
How was the initial setup?
The initial deployment was demanding due to my network architecture, not because of the product.
What about the implementation team?
The implementation was done through a vendor.
What was our ROI?
We've seen ROI at 6 months to 1 year.
However, the ROI was realized within weeks of deployment.
What's my experience with pricing, setup cost, and licensing?
The solution is reasonably priced relative to some other brands.
Which other solutions did I evaluate?
We did not evaluate other options.
What other advice do I have?
It is the best amongst the rest.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Sr. Security Analyst at Atos
Great GUI with a good centralized management console and helpful technical support
Pros and Cons
- "The initial setup is very straightforward."
- "They could make the licensing a bit easier to deal with, especially for enterprise-level options."
What is most valuable?
Check Point is very strong as compared to the other vendors in the market.
The solution offers a very good centralized management console.
It works well even for small deployments.
The perimeter security is excellent.
It works well even for cloud environments and has been very useful during COVID when people weren't necessarily in the office.
The creation of policies is simple. It's easy to configure them when we need to.
We have found the troubleshooting process to be very easy and helpful.
The GUI is simple and straightforward.
The sandbox environment on offer has been great.
The support has been super-helpful. They've always been great, even at a pre-sales level.
The initial setup is very straightforward.
What needs improvement?
From a stability standpoint, sometimes when upgrading to a new version, there are some stability issues. The device occasionally may stop responding.
It would be beneficial if they offered better load balancing.
They could make the licensing a bit easier to deal with, especially for enterprise-level options.
For how long have I used the solution?
We primarily use the solution for security, as a next-generation firewall that we use in our environments. It is very good at detection and prevention. However, we are still exploring use cases.
What do I think about the stability of the solution?
While the solution is mostly stable, we do find that we have stability issues moving to different versions. You run the risk of the device not responding in some cases.
What do I think about the scalability of the solution?
The scalability is possible, however, it's based on requirements. When we get a new solution, we plan out for the next four or five years. It can scale so long as you design it properly at the outset.
How are customer service and technical support?
Technical support is helpful and responsive. We're quite satisfied with the level of service we can expect. They are very good.
Which solution did I use previously and why did I switch?
I've also worked with Palo Alto and Cisco.
How was the initial setup?
The initial setup is extremely straightforward. You don't even have to be overly technical to manage it. They make it very easy. It's not overly complex or difficult.
What's my experience with pricing, setup cost, and licensing?
The licensing is okay. Clients can go for a one, three, or five-year license.
Sometimes it's complicated to put new licensing on existing devices. If we have issues, we can raise questions with the sales management team and they are always very helpful. Larger, enterprise-level devices, in particular, can be a bit complex to deal with.
What other advice do I have?
We are integrated partners and we provide services to the customers.
I didn't get any chance to work on version 80.40, however, a lot of the customers are on versions 80.10, 80.20, and 80.40.
I would encourage users and companies to use Check Point. It's quite a good solution. I find it to be a better solution than, for example, Palo Alto.
I'd rate the solution at a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Security Engineer at Gosoft (Thailand)
Easy-to-use console, good logging, effective traffic and access control features, responsive support
Pros and Cons
- "From the logs, you can trace back to the rule with a click, which makes it easy to investigate cases."
- "They have few predefined reports and it would be nice to increase them since the logs are excellent."
What is our primary use case?
I use Check Point NGFW for controlling traffic and controlling access to the production server. It is a HA (high availability) environment. It is easy to use failover solutions.
We use it on our disaster recovery (DR Site) and it runs smoothly.
How has it helped my organization?
In the office, Check Point Infinity is the only fully consolidated cybersecurity architecture that protects your business and IT infrastructure.
Integrating the most advanced threat prevention and consolidated management, the security gateway appliance is designed to prevent any cyber attack, reduce complexity, and lower costs.
Check Point gateways provide superior security beyond any Next-Generation Firewall (NGFW).
Best designed for network protection, these gateways are the best at preventing the fifth generation of cyber attacks.
Overall, for us, it improves the private cloud security and helps to prevent the spread of threats while consolidating visibility and management across our physical and virtual networks.
What is most valuable?
The most valuable feature is the next-generation firewall (NGFW) protection.
Check Point has long been a leader in the firewall market. It offers Quantum Security Gateways for a wide range of use cases and CloudGuard FWaaS and cloud security products too. NSS Labs scored Check Point just behind Palo Alto in security effectiveness and ahead of Palo Alto in TCO. Check Point’s management features are among the best in the business, but SD-WAN capabilities are lagging.
A firewall rule is the same on all systems, and I am very happy with the correlation and the display of the rules.
From the logs, you can trace back to the rule with a click, which makes it easy to investigate cases. It is also easy to search the log.
What needs improvement?
They have few predefined reports and it would be nice to increase them since the logs are excellent.
They should be quicker to release fixes for known vulnerabilities, including those related to Microsoft products.
If you make a mistake when creating rules, it is time-consuming to fix them. However, there is no problem with traffic processing.
Sometimes you are forced to interact on several different levels. On the one hand, you put the rules in, and on the other, you put in the route.
For how long have I used the solution?
I have been using Check Point NGFW for between five and six years.
How are customer service and technical support?
They have a good support team that is fast to respond. However, there are open cases that should be resolved in a more timely fashion.
Which solution did I use previously and why did I switch?
We used another solution prior to this one, but the updates were too slow and it was harder to monitor the log.
How was the initial setup?
The initial setup is very hard.
What about the implementation team?
The vendor implemented this product for us.
What was our ROI?
This product is a good investment and I expect a full return in approximately three years.
What's my experience with pricing, setup cost, and licensing?
The price of the appliance should be decreased.
Which other solutions did I evaluate?
I evaluated several other solutions and compared them before choosing Check Point.
What other advice do I have?
This is a product that I recommend.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Network Engineering and IS Access at SFR
Easy to use with good management capabilities and advanced routing
Pros and Cons
- "The management of the firewall and advanced routing is great."
- "We need east/west Check Point firewalls in order to do micro-segmentation."
What is our primary use case?
We use Check Point as well as Cisco. The firewall is used in order to continue filtering with VMware VMotion on different data centers.
How has it helped my organization?
We have several data centers that are stretched. Our Check Point firewalls are used to filter north/south traffic.
With BGP on Gaia, when one of the clusters is unreacheable, the traffic is rerouted to another cluster.
We also use VSX which is really a very good product for macrosegmentation.
What is most valuable?
The management of the firewall and advanced routing is great. It's easy to use and troubleshoot.
What needs improvement?
We need east/west Check Point firewalls in order to do micro-segmentation. A good solution for us is a solution that can be installed on différent systems (Linux, Windows K8S, bare metal, etc.) and can have centralized management.
Troubleshooting is also a big feature that will be necessary in this use case.
For how long have I used the solution?
I've used the solution for many years.
Which other solutions did I evaluate?
We also looked at Ciscos ASA and Fortigate.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer: We are a french isp
Buyer's Guide
Download our free Check Point NGFW Report and get advice and tips from experienced pros
sharing their opinions.
Updated: November 2024
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
OPNsense
Cisco Secure Firewall
Sophos XG
Meraki MX
Zscaler Internet Access
Palo Alto Networks NG Firewalls
Azure Firewall
WatchGuard Firebox
SonicWall TZ
Sophos UTM
Juniper SRX Series Firewall
Untangle NG Firewall
Fortinet FortiGate-VM
Buyer's Guide
Download our free Check Point NGFW Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- How does Check Point NGFW compare with Fortinet Fortigate?
- Is Palo Alto Networks NG Firewalls better than Check Point NGFW?
- Which would you recommend - Azure Firewall or Check Point NGFW?
- Is Check Point's software compatible with other products?
- What do you recommend for a corporate firewall implementation?
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Which is the best network firewall for a small retailer?
- When evaluating Firewalls, what aspect do you think is the most important to look for?
- Cyberoam or Fortinet?