We use it to provide security to our environment from the outside world. We are using it to provide security against vulnerabilities using threat prevention, Antivirus, and IPS.
IT Specialist at a tech services company with 10,001+ employees
Protects our environment with security checks against vulnerabilities
Pros and Cons
- "We like the centralized management for configuring multiple firewalls. It also gives us the Antivirus, threat prevention, and vulnerability tests. These four features protect the environment with security checks. Vulnerability tests allow us to configure changes that can protect the environment."
- "The Antivirus feature is something that could be improved. We don't get much from the Antivirus update in comparison to their competitor's firewalls. It needs to be more advanced because Check Point is nowadays sent all over the world. Therefore, the Antivirus feature should be of very good quality and cover all virus checks. I would also like the Antivirus updates to be more frequent."
What is our primary use case?
How has it helped my organization?
In advance, we get security vulnerabilities. So, we can configure new security policies, update our antivirus, or check the configuration to protect the environment.
What is most valuable?
We like the centralized management for configuring multiple firewalls. It also gives us the Antivirus, threat prevention, and vulnerability tests. These four features protect the environment with security checks. Vulnerability tests allow us to configure changes that can protect the environment.
What needs improvement?
The Antivirus feature is something that could be improved. We don't get much from the Antivirus update in comparison to their competitor's firewalls. It needs to be more advanced because Check Point is nowadays sent all over the world. Therefore, the Antivirus feature should be of very good quality and cover all virus checks. I would also like the Antivirus updates to be more frequent.
Buyer's Guide
Check Point NGFW
December 2024
Learn what your peers think about Check Point NGFW. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
823,875 professionals have used our research since 2012.
For how long have I used the solution?
I have been working with it for the last seven years.
What do I think about the stability of the solution?
It is a very stable firewall. The updates that we get from this Check Point Firewall are also very stable.
What do I think about the scalability of the solution?
The scalability is good.
There are more than 10,000 users. The Check Point Firewall is deployed through the company.
How are customer service and support?
All their technical people are very solid in their knowledge.
Which solution did I use previously and why did I switch?
I have used Cisco ASA and FTD. We switched from Cisco ASA to Check Point because there were no antivirus, vulnerabilities, or security prevention features. Check Point has more advance features, which are easier to use, than Cisco.
We also had to install IPS devices with Cisco.
How was the initial setup?
The initial setup was straightforward. It was not too difficult to deploy the Check Point firewall. Deployment takes between 12 to 15 months.
We have done a cloud-based deployment throughout our network.
What about the implementation team?
We did the deployment ourselves. We have onsite specialists who have done many deployments.
20 people take care of the deployment and troubleshooting of this firewall.
What was our ROI?
There is a money saving because we no longer require other devices, like an IPS, a separate antivirus, or vulnerability tests. We get all the devices within a single tool. Before, we would have different teams taking care of different devices. Now, we take care of only one device, which is another source of savings. We have saved a lot of money with this solution.
What's my experience with pricing, setup cost, and licensing?
The prices are good for its features. The benefit of its license is we get timely security prevention updates. The price is good for the technology that we get.
What other advice do I have?
This is a good solution. I would recommend to take advantage of as many features as you can. It has many features, and to protect security, you should use all the best features that you can.
As soon as the company will grow, we will definitely increase our usage of the firewall. We have already increased our usage due to employees working from home.
The biggest lesson that I learned is we can use the features of a firewall security to protect our environment. Also, rather than deploying multiple firewalls, we can configure a centralized management system, and this saves time.
I would rate this solution an eight out of 10.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Solutions Architect, Cyber Security & Networking team at Expert Systems Ltd
Well designed web-based dashboard good GUI and great load sharing
Pros and Cons
- "The solution provides better stability and some interesting features such as the ease of throughput expansion."
- "Check Point is not a cheap solution and it's always painful to see exactly how much we need to spend on this."
What is our primary use case?
We have proposed and deployed Check Point in a university environment that has multi-layer firewall protection for different zones, including DMZ, a server zone, Wi-Fi, a staff zone, a student hostel zone, guests, etc. Each zone is guarded by a firewall.
We need the NGFW to protect and secure the campus networks for more than 50,000 users. One of the key points is it is cost-effective and scalable to expand the throughput capacity. We expect the solution is possible to protect the networks for at least five to eight years without replacing the hardware investment.
How has it helped my organization?
The solution provides better stability and some interesting features such as the ease of throughput expansion (or we can say the load sharing).
The scalability helps to offload the high traffic volume during school time. It also enhances redundancy.
The load sharing capabilities using ClusterXL is possible to switch over the cluster mode to load sharing or Maestro. I also appreciate how easy it is to scale this product.
It is also great that the Check Point community (CheckMates portal) has a lot of helpful guidance. It helps us to work better and ease to find unfamiliar configurations on the new features, it is great for larger organizations as well as very small ones.
What is most valuable?
They offer very scalable solutions to extend computing resources if needed. We can expand the capacity in a very short time.
The threat analysis reporting from their management console is very comprehensive and easy to use.
Their web-based dashboard is well designed and offers much out-of-the-box reporting, and provides admins extensive customizations.
In the operational GUI, Check Point provides rich customization methods to allow us to easily visualize/categorize objects in different colors. It makes operating the firewall much easier.
What needs improvement?
Under the same capacity requirements, Cheak Point is a bit higher than Fortinet yet much cheaper than Palo Alto. Although using Quantum Maestro to enhance scalability expansion is very helpful to cut down the total cost, it is still an issue for most of the company. Check Point is not a cheap solution and it's always painful to see exactly how much we need to spend on this.
The upgrade process is not as easy as may be expected. If there is something that goes wrong, it causes the internet service to go down for the whole campus network. I am not happy with that situation since the upgrade process is a very common process. The outcome is not acceptable.
What do I think about the scalability of the solution?
It is scalable and very easy to expand the throughput and resources.
Check Point firewall provide a very cool feature using Quantum Maestro Hyperscale Orchestrator, it provides on-demand cloud-like scaling of our on-premises security gateways. By using Maestro, we can aggregate multiple mid-level Check Point appliances to provide a high throughput volume. It is very useful to scale up to 52 appliances. If we use other firewall solutions, they can only aggregate up to TWO firewalls with same model in clustering or purchase a more high end model firewall.
For a long term planning, we can expand the throughput by reusing the existing Check Point hardware investment and adding new appliances to.
How was the initial setup?
The deployment is straightforward, however, the ongoing upgrades are not satisfactory.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: One of the Solutions Integrators offering Check Point, Palo Alto, and Fortinet solutions
Buyer's Guide
Check Point NGFW
December 2024
Learn what your peers think about Check Point NGFW. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
823,875 professionals have used our research since 2012.
Senior Consultant at Integrity360
Great Smart View Tracker and smart dashboard with useful upgrade functionality
Pros and Cons
- "The Smart Dashboard allows for rule creation and administration and management and is user-friendly."
- "Error logs can be more specific."
What is our primary use case?
We use the solution for network security, perimeter security, DMZ, antibot, antivirus, endpoint protection, email security, sandblast, and DLP. The environment is a multi-environment and consists of multiple networks, segmented and managed by a management server. These firewalls protect the network, external and internal.
We are also protecting several customers and it allows remote access connection from anywhere in a secure way.
There are also site-to-site VPNs with different customers, vendors, and cloud providers, using the highest security encryption algorithms.
How has it helped my organization?
The organization is more secure. These firewalls work as expected. We have a perimeter and network segmentation well defined and firewall features and blades like IPS, Identity awareness, antibot, antivirus, threat prevention, endpoint security, and DLP, all allow the organization to have most of the security components centralized which allows for easier maintenance and monitoring.
In relation to the monitoring, Check Point has tools that allow the administrator to track the traffic, and identify threats, attacks, and also check the forensics to understand what happened in case of a breach and ensure it won't happen again.
What is most valuable?
The most valuable elements include:
Smart View Tracker: To check the traffic logs easily. This is the best logging tool for me so far. You can identify almost everything from the logs, using a smart view tracker.
Smart Dashboard: allows for rule creation and administration and management and is user-friendly. The administration allows you to copy and paste rules, move the order, and create objects, pretty easily. It is very handy.
CPUSE: A Smart way to upgrade firewall software versions. You can easily verify if you can upgrade to the desired version, download the right package and upgrade, and also check the status of the upgrade. It's a great tool.
What needs improvement?
Error logs can be more specific. Sometimes the error shows only a general error and the solution could be hard to find or difficult to apply.
Documentation can be improved. It has been improved, however, when you search for errors, in relation to documentation and how to solve it, sometimes it is not that simple to find the right solution. Troubleshooting errors could be sometimes difficult and some tools are only available for the Check Point support team.
The price is also a factor to take into account. Other competitors offer low prices in relation to Check Point and the executive team may opt for the cheapest vendor (if you have to compare to another good one yet note a cheaper price).
For how long have I used the solution?
I've used the solution for ten years.
What do I think about the scalability of the solution?
The solution offers good scalability.
How are customer service and support?
The solution offers good customer service and good support.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have been using Check Point since the beginning.
How was the initial setup?
The initial setup is straightforward.
What about the implementation team?
We handled the setup in-house.
What was our ROI?
The solution is super stable.
What's my experience with pricing, setup cost, and licensing?
The pricing could be better, however, the vendor is excellent and I strongly recommend it.
Which other solutions did I evaluate?
I did not evaluate other options.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Technical Architect at a computer software company with 10,001+ employees
It's easier to manage and has better support than competing solutions
Pros and Cons
- "Check Point is more expensive but easier to manage, and their presales and after-sale support are way better than Fortinet's."
- "I would like to see Check Point add more cloud management features and better integration with LAN software-defined networking."
What needs improvement?
I would like to see Check Point add more cloud management features and better integration with LAN software-defined networking.
What do I think about the stability of the solution?
I rate Check Point eight out of 10 for stability.
What do I think about the scalability of the solution?
Check Point is definitely scalable.
Which solution did I use previously and why did I switch?
It really depends on the customer's deployment and environment, but we often mix and match firewalls. Check Point is more expensive but easier to manage, and their presales and after-sale support are way better than Fortinet's.
How was the initial setup?
Check Point is more complicated to deploy than Fortinet.
What's my experience with pricing, setup cost, and licensing?
Check Point needs to lower its price drastically, and the licensing model is very complex.
What other advice do I have?
I rate Check Point NGFW nine out of 10. I would only recommend it for medium to large enterprises.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
Chester at Iocane
Great centralized management with good threat extraction and excellent commitment to innovation
Pros and Cons
- "Management integration is holistic as centralized management has been core to the solution for decades."
- "Potential improvements could be made around simplifying VPN functionality and configuration."
What is our primary use case?
I work for a systems integrator and have designed and deployed solutions over many years with Check Point components. Problems solved with Check Point NGFWs have included securing the edge, data center segregation, SWG replacement, Remote Access, and many others.
I have designed and installed Check Point deployments from a single SMB appliance to multiple highly available chassis, running numerous virtual systems. Numerous different use cases include appliance form-factors, running modules, and licenses.
How has it helped my organization?
I have always found that Check Point's fully integrated management provides significant improvements to organisations where I have deployed them. As management has always been integral in the Check Point deployment, all functionality and visibility is natively baked into the management platform, which provides a single point to configure and monitor every function. Alternative vendors have added centralized management functionality as a secondary feature and therefore have never been able to compete on this front.
What is most valuable?
Management integration is holistic as centralized management has been core to the solution for decades. Where other vendors have bolted management on over time, Check Point has always made it central to everything that they do.
I find that this is one of the most significant and valuable features of Check Point. In addition to that, many new features that eventually become the standard across the industry end up being first introduced by Check Point - sometimes years ahead (such as Threat Extraction which allows active content to be stripped from files being downloaded and a "clean" copy to be provided in near real-time, while sandbox inspection is being performed).
What needs improvement?
Product-wise, I have no real complaints.
Potential improvements could be made around simplifying VPN functionality and configuration.
The main area that the organization can improve is around the lack of local, in-state technical support. Competitor vendors have a strong presence in the Adelaide Market, however, Check Point has always been limited with its commitment to staffing local technical resources. If this focus is made, I could see Check Point returning to the strength that it once had in the Adelaide market.
For how long have I used the solution?
I've used the solution for 17 years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security product manager at RRC
An easy-to-use and easy-to-manage protection solution at a reasonable price
Pros and Cons
- "It is easy to use, and its management is the best. Check Point has a great unified management solution for firewalls and security products."
- "Their technical support can be better. In addition, when we need to use it in a government environment, we face a lot of legal issues related to different types of certifications. It would be better to improve it for these issues. Check Point doesn't have a SOAR system. They work with Siemplify, but it is an integration with another vendor. It would be great if Check Point has an integrated SOAR system."
What is our primary use case?
We use Check Point NGFW for perimeter protection of our network from the internet. We also use it for threat protection at the network level and the endpoint level.
We provide implementation, installation, and support services. We know about all types of firewalls, and we work with all types of installations. We usually use appliances, but in test environments, we use virtual appliances.
What is most valuable?
It is easy to use, and its management is the best. Check Point has a great unified management solution for firewalls and security products.
What needs improvement?
Their technical support can be better. In addition, when we need to use it in a government environment, we face a lot of legal issues related to different types of certifications. It would be better to improve it for these issues.
Check Point doesn't have a SOAR system. They work with Siemplify, but it is an integration with another vendor. It would be great if Check Point has an integrated SOAR system.
For how long have I used the solution?
We have been dealing with Check Point firewalls in our company for more than 20 years.
What do I think about the stability of the solution?
It is quite stable, but it can vary based on the version.
What do I think about the scalability of the solution?
It is scalable. We can use the Maestro solution from Check Point for scalability. We can add new appliances as the company grows. If we need more performance and throughput, we can add additional appliances and have more performance. Check Point Maestro is the best solution for scalability.
How are customer service and technical support?
Their technical support can be better.
How was the initial setup?
Its initial setup is easy for me. The deployment duration varies. A simple deployment takes two or three days. A complex deployment that involves a cluster configuration or appliance replacement can take up to five days.
What's my experience with pricing, setup cost, and licensing?
Its price is reasonable. If we compare its TCO for three years, it is more reasonable than some of the other vendors such as Fortinet, Palo Alto, etc.
What other advice do I have?
I would recommend this solution. It is a great solution for endpoint protection and threat prevention. I have been working with Check Point products for a very long time. Check Point is one of our best vendors, and they make great products.
I would advise others to learn about firewalls and other Check Point solutions. They have a lot of different solutions. If you choose their firewall, it would be useful to know more about other solutions. It would be one of the ways to improve the protection of your network with Check Point.
I would rate Check Point NGFW a ten out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Distributor
Solutions Lead at a tech services company with 1,001-5,000 employees
We are seeing less traffic going to the server, improving server performance
Pros and Cons
- "My favorite feature is the UTM piece and that was the main reason we bought it. It helps us to fine tune the network."
- "When I was creating the VPN on it and the client side through the portal, that feature was very annoying. I could not use it. It was much more usable after downloading it to the laptop. That was very good compared to using it directly from the browser."
What is our primary use case?
It's an on-prem deployment where we use it to protect our client and end-users who are working with the internet, and to protect their servers from external access. They have about 100 users and two servers.
How has it helped my organization?
When we did not have SSO, we had problems related to attacks compromising our firewall. That has been mitigated. We have the traffic going through the firewall to the server, so those types of things have really improved. We are seeing less traffic going to the server. When there was direct access to it, there was more and more traffic going to our server. So it has improved our server performance.
What is most valuable?
My favorite feature is the UTM piece and that was the main reason we bought it. It helps us to fine tune the network. We use it to block certain websites, to block access to particular locations, such as in Singapore or say Malaysia, where we have offices. We keep the previous device updated and, based on that, we also have static MAC address binding.
We also use the VPN services. The VPN features are mostly for our cloud connectivity and for our remote users to have local server access.
What needs improvement?
When I was creating the VPN on it and the client side through the portal, that feature was very annoying. I could not use it. It was much more usable after downloading it to the laptop. That was very good compared to using it directly from the browser.
For how long have I used the solution?
I have been using Check Point NGFW for almost two-and-a-half years.
What do I think about the stability of the solution?
It's a stable solution. In the time I have been using this product, I have hardly seen anything break.
What do I think about the scalability of the solution?
In terms of scalability, they have products that can fit into the environment. It's a very scalable solution. For our requirements, it fits very well. You can go with whatever kind of setup you want: Active-Passive, Active-Active. Check Point is very easy. Their solution is ready for our market; it's very well suited. Wherever we want to go, Check Point can provide a solution.
Currently, we are using somewhere around 50 to 60 percent of the box's capacity.
How are customer service and technical support?
Sometimes, when I have gotten stuck, I have reached out to support and it's okay. They have helped me very quickly.
Which solution did I use previously and why did I switch?
We did not have a previous solution. We went directly with Check Point. We liked the features provided by Check Point and we went for it.
How was the initial setup?
The setup is not complex. It's easy to deploy. The documentation provided is very good. Deployment takes me two to three days. The hardware takes one-and-a-half days and then I get all the features up and running.
We have a standard implementation strategy. We have a checklist. We plan it out. Then we go into the field for the deployment. We have one dedicated engineer for deployment, and I also check it on a regular basis. The two of us are also the ones who manage the solution.
What's my experience with pricing, setup cost, and licensing?
We have to consider things, cost-wise, when we are expanding into other locations. We don't have the budget to use it in other platforms. We have some servers that we deploy in AWS and other locations. But instead of going with Check Point, we go with other vendors to fit into the budget.
Check Point is really costly. When it comes to the Indian market, where we are located, we always consider budget solutions. So this is an area where Check Point could use some improvement.
In addition to the standard fees, support is an added expense.
What other advice do I have?
The biggest lesson learned from using this solution is in terms of security. It is a really good product. I don't think there is anything missing from the Check Point firewalls. The features provided by the company are very good and provide what we need.
It's a very good security product, as long as you have the budget. It provides modern security and the architecture Check Point provides is good. And the application side will really help any size of business to deal with traffic based on the application.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer:
IT-Infrastruktur at Synthesa Chemie Ges.m.b.H
Provides centralized management, good logging capabilities, and granular application control
Pros and Cons
- "The most valuable feature is the centralized management, which gives us control over all of the Check Point gateways."
- "Without any training, it is very hard to administrate the whole Check Point NGFW."
What is our primary use case?
Check Point protects our environment from external threats. In particular, we use:
- Application Control for Internet access
- HTTPS Inspection for outgoing connections into the internet
- Separate the OT network from the normal data LANs
- SSL VPN for End Users - Check Point Mobile VPN Client is used on the end-user clients
- Site-to-Site VPN for connecting other companies to our environment
We are using two Check Point boxes in a ClusterXL Setup so that one appliance can die and the environment is not affected. We also use a cloud gateway for internet security on users, which are only connected to the internet (outside the office).
How has it helped my organization?
Check Point has improved our organization in the following ways:
- Provides for central management over all of the Check Point gateways
- Maintains a changelog that shows which users have made changes
- Version control allows us to roll back a ruleset after, for example, a misconfiguration
- Offers very granular application control
- Allows for various internet permissions for various users
- Gives us very good logging, which is nice for troubleshooting because you can instantly which rule is affected for each action
- The cloud gateway (Check Point Capsule Cloud) ensures that users are getting the same internet permissions as they would if inside the company, no matter which internet connection they are using
What is most valuable?
The most valuable feature is the centralized management, which gives us control over all of the Check Point gateways. This means that you do not need to connect to each gateway and make the necessary changes.
Cluster functionality, "ClusterXL", works like a charm. A rollover to the standby gateway does work with no noticeable delay in the network.
You can buy a Check Point appliance or install the Check Point NGFW as a VM on your own hardware.
The extremely wide function horizon covers almost every possible scenario.
What needs improvement?
The Performance on a policy install takes too long for my taste. This might be because, at each policy install, the management pushes the whole policy on the affected gateways.
Without any training, it is very hard to administrate the whole Check Point NGFW.
In our case, the main Check Point gateways are in a cluster configuration. Sadly, the management always shows the standby box as failed. This may be because it is set to STANDBY and not ACTIVE. It would be better to show the standby box as good.
For how long have I used the solution?
I have been using Check Point NGFW for about five years.
How are customer service and technical support?
Support is very customer-oriented and you are always in good hands.(customer wishes are often implemented in the next hotfix)
Most Support engineers are located in Israel. (Very good spoken english)
Very fast response from R&D Team
Which solution did I use previously and why did I switch?
We were using SonicWall and switched because of EOL.
What's my experience with pricing, setup cost, and licensing?
The pricing for Check Point depends on your environment.
Which other solutions did I evaluate?
Before choosing Check Point we evaluated Fortinet and a newer version of SonicWall.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Check Point NGFW Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
OPNsense
Cisco Secure Firewall
Sophos XG
Palo Alto Networks NG Firewalls
Azure Firewall
WatchGuard Firebox
SonicWall TZ
Juniper SRX Series Firewall
Untangle NG Firewall
Fortinet FortiGate-VM
SonicWall NSa
Sophos XGS
KerioControl
Buyer's Guide
Download our free Check Point NGFW Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- How does Check Point NGFW compare with Fortinet Fortigate?
- Is Palo Alto Networks NG Firewalls better than Check Point NGFW?
- Which would you recommend - Azure Firewall or Check Point NGFW?
- Is Check Point's software compatible with other products?
- What do you recommend for a corporate firewall implementation?
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Which is the best network firewall for a small retailer?
- When evaluating Firewalls, what aspect do you think is the most important to look for?
- Cyberoam or Fortinet?