We use the tool as a data center firewall. Some of our customers use it as a perimeter firewall. We are only using the security gateway.
The product is highly scalable and flexible, but the cost of add-on features is too high
Pros and Cons
- "The product is flexible."
- "The cost of add-on features is too high."
What is our primary use case?
What is most valuable?
The product is flexible. I like the product’s performance and throughput.
What needs improvement?
The cost of add-on features is too high.
For how long have I used the solution?
I have been using the solution for five to six years.
Buyer's Guide
Check Point NGFW
February 2025

Learn what your peers think about Check Point NGFW. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
What do I think about the stability of the solution?
The tool is stable. We haven’t faced any issues after configuring and putting it in production.
What do I think about the scalability of the solution?
We have roughly 7000 appliances. The tool is scalable. I like the scalability of the solution. We have 10 to 20 customers.
How are customer service and support?
The technical support is good.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is easy.
What's my experience with pricing, setup cost, and licensing?
The pricing is moderate. The license cost is good. However, some features like VPN are costly.
What other advice do I have?
We use the solution for our clients. My recommendation depends upon the requirements. I do not recommend the product for an SMB. I recommend it for enterprises. It has good performance and throughput. Overall, I rate the solution a seven or eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: customer/partner

IT Security Administrator at a tech services company with 51-200 employees
Easy to manage with good features but there are security bugs that are annoying
Pros and Cons
- "We have all the features we want or need in this appliance. It's been good so far."
- "Sometimes there are security bugs, which is frustrating."
What is our primary use case?
We primarily use it for internet security. We use it for firewalling, ePass, and threat detection including anti-malware protection, bug protection, and social inspection. We can also use it for DLP.
What is most valuable?
The solution helps out in our security goals. It acts as a primary source of protection for threats from the internet and is great for data leakage protection.
Most of the time, it's pretty stable.
We have all the features we want or need in this appliance. It's been good so far.
What needs improvement?
Sometimes there are security bugs, which is frustrating.
Right now, we have a problem with DLP and this problem has become very big. Check Point, our firewall, is not handling data properly. There seems to be some sort of security bug.
For how long have I used the solution?
I've used the solution for ten years or so. It's been a decade at least.
What do I think about the stability of the solution?
The solution, for the most part, is very stable. We find it to be quite reliable. There are bugs, however, which have caused some issues.
What do I think about the scalability of the solution?
The solution is not scalable per se. There is only one way to upgrade and that is to buy new appliances.
Currently, we have around 7,000 people using this solution.
Likely, we won't be increasing usage. We are building new releases and we are considering changing this solution to another vendor. We might switch from Check Point to maybe Palo Alto or Cisco. We don't know which yet.
How are customer service and support?
We haven't really dealt with technical support. We typically go through our partners.
Which solution did I use previously and why did I switch?
We also use Cisco as well. We use Cisco ASA. Check Point, right now, is our primary firewall.
Check Point offers very good management. For an administrator, it's easy to manage this appliance, this firewall. Cisco, historically, has a big problem with this, specifically with FTD firewalls. There also tend to be some bugs you have to contend with.
How was the initial setup?
I can't speak to the initial setup process. Our partner handled it and therefore I wasn't really part of the process. That said, for me. the process is pretty simple.
My understanding is that the deployment took a few days.
I'd rate the experience of the initial setup at a four out of five.
About two people were able to handle the implementation process. Typically, they are architects and engineers.
What about the implementation team?
We had a partner set up the solution for us.
What was our ROI?
We have seen a decent ROI. I'd rate it at a four out of five.
What's my experience with pricing, setup cost, and licensing?
I can't speak to the cost of the solution. We deal with it through a partner, and I'm not involved in any of the pricing aspects.
Which other solutions did I evaluate?
We are considering switching to Palo Alto or maybe Cisco in the near future.
What other advice do I have?
We are a customer and an end-user.
Some blades, some function blades on Check Point, are very good, however, it's not all of them. Right now, I know DLP and social inspection are a problem. New users should be aware of this.
Overall, I would rate the solution at a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Check Point NGFW
February 2025

Learn what your peers think about Check Point NGFW. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
Security and Network Engineer at a tech services company with 501-1,000 employees
User-friendly configuration, good support, and trouble-free upgrades have made our jobs easier
Pros and Cons
- "The rules are very easy to deploy and can be optimized pretty quickly."
- "One of the main features that need improvement is the rule filter export."
What is our primary use case?
The Check Point NGFW is the best product that I have ever used. It has pluses and minuses, as do others, but the usability, simplicity, and the configuration abilities are very user-friendly. After a while, other vendors just don’t come close to it.
The second thing is that is just works and it does it with ease. The upgrades and bug fixes are frequent and well documented. Also, the patches just work ;-)
There are some negatives but as I already said, they aren’t many and from my point of view, we can see past them.
How has it helped my organization?
It has made our lives and working in the company a lot easier. We have a better overview of the logs and what happens with the traffic in our company. Which means that the search for the certain logs is easy, quick and smooth. The overview of the logs is also very good as it is very detailed. The installation is allot quicker as it was before what also helps us with the implementation of the firewall rules. The rule consolidation is also very important as we have more than 60 fw rule change requests per day.
What is most valuable?
The rules are very easy to deploy and can be optimized pretty quickly. The R80 has a great feature on how the rules are processed, which costs less in terms of CPU and threads than it did before.
The features that are integrated into the firewall are very useful for our everyday use. Examples of these are the log manager, the firewall monitor commands, and the Linux commands. These are all very useful and helpful.
The VPN tunnels are easy to set up once you understand how they have to be configured.
What needs improvement?
One of the main features that need improvement is the rule filter export. All of the other vendors can export the filtered IPS as a PDF or CSV file, but with the smart dashboard, it’s just not possible. One can only export the whole rule base and then search for the IPS, which is super time-consuming as you can’t send the whole rule base to a customer. You would get weird questions about certain rules, why they are deployed or configured as they are, and maybe even get unwanted tips on how to change them.
For how long have I used the solution?
We have been using Check Point NGFW for eight years.
What do I think about the stability of the solution?
In terms of stability, this solution is very good.
What do I think about the scalability of the solution?
The scalability is high.
How are customer service and technical support?
The technical support is very good.
Which solution did I use previously and why did I switch?
We did not use another solution prior to this one.
How was the initial setup?
The initial setup is very easy.
What about the implementation team?
I implemented and deployed Check Point NGFW alone.
What's my experience with pricing, setup cost, and licensing?
Maybe the pricing is a bit high but you get the durability and the duration.
Which other solutions did I evaluate?
We evaluated Palo Alto and Cisco ASA.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Chester at Iocane
Great centralized management with good threat extraction and excellent commitment to innovation
Pros and Cons
- "Management integration is holistic as centralized management has been core to the solution for decades."
- "Potential improvements could be made around simplifying VPN functionality and configuration."
What is our primary use case?
I work for a systems integrator and have designed and deployed solutions over many years with Check Point components. Problems solved with Check Point NGFWs have included securing the edge, data center segregation, SWG replacement, Remote Access, and many others.
I have designed and installed Check Point deployments from a single SMB appliance to multiple highly available chassis, running numerous virtual systems. Numerous different use cases include appliance form-factors, running modules, and licenses.
How has it helped my organization?
I have always found that Check Point's fully integrated management provides significant improvements to organisations where I have deployed them. As management has always been integral in the Check Point deployment, all functionality and visibility is natively baked into the management platform, which provides a single point to configure and monitor every function. Alternative vendors have added centralized management functionality as a secondary feature and therefore have never been able to compete on this front.
What is most valuable?
Management integration is holistic as centralized management has been core to the solution for decades. Where other vendors have bolted management on over time, Check Point has always made it central to everything that they do.
I find that this is one of the most significant and valuable features of Check Point. In addition to that, many new features that eventually become the standard across the industry end up being first introduced by Check Point - sometimes years ahead (such as Threat Extraction which allows active content to be stripped from files being downloaded and a "clean" copy to be provided in near real-time, while sandbox inspection is being performed).
What needs improvement?
Product-wise, I have no real complaints.
Potential improvements could be made around simplifying VPN functionality and configuration.
The main area that the organization can improve is around the lack of local, in-state technical support. Competitor vendors have a strong presence in the Adelaide Market, however, Check Point has always been limited with its commitment to staffing local technical resources. If this focus is made, I could see Check Point returning to the strength that it once had in the Adelaide market.
For how long have I used the solution?
I've used the solution for 17 years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Support Manager at Sefisa
Stable and very robust with helpful technical support
Pros and Cons
- "The product is very scalable."
- "Sometimes when they bring on new upgrades, they affect something else."
What is most valuable?
I do like that this solution is a very robust firewall.
It's very stable.
The product is well supported. The solution is very scalable.
Technical support has been quite good.
What needs improvement?
The only thing I would like to improve is the updates. Sometimes when they bring on new upgrades, they affect something else. That happens sometimes. For example, something that was working well might have a new issue after an update. It's understandable as they do have like to add innovations. When you are innovative, you face some risks.
They have already announced that they will be adding SD-WAN as a new feature.
For how long have I used the solution?
I've been using the solution for 18 years.
What do I think about the stability of the solution?
The solution is very stable. There are no bugs or glitches. It doesn't crash or freeze. It's reliable. That said, I would like the latest version to be more stable.
What do I think about the scalability of the solution?
The product is very scalable. You have very good options. For example, if you start with a smaller firewall and you want to upgrade to have newer hardware, they have different options. For example, you can run a script that is going to tell you the new appliances that you need, according to your new requirements according to your network consumption.
It did launch Maestro about two years ago. Maestro is something that allows you to stack firewalls. If your current firewalls handle the traffic anymore, you can add new firewalls to it.
If you want to change the firewall you can do these trade-ins. You can return the old firewall and they will give you a special discount.
How are customer service and support?
Technical support has been very helpful and responsive. We've been happy with the level of support they offer.
How was the initial setup?
The product is easy to set up. I am seasoned on Check Point. For me, it's very easy. I wouldn't say it's hard.
What other advice do I have?
I'd rate the solution at a ten out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer:
Procurement Supervisor at Centenary Bank
Support is okay, but is inequitable with the price
Pros and Cons
- "The pricing is okay."
- "While the solution is good, we wish to have something that is a bit better, as the threats have evolved over time."
What needs improvement?
While the solution is good, we wish to have something that is a bit better, as the threats have evolved over time. We have been using Check Point for more than than eight years and are interested in a better solution. We entered a review site which ranks top security firewalls and saw that Palo Alto is ranked number one, followed by Fortinet, with Check Point in the lead. We noticed that Palo Alto was much more expensive than Fortinet, but wished to know which key features differentiated the two.
Though we did not take issue with the price of Check Point NGFW, we felt that it was providing us with inadequate support here in Uganda. This is why we decided to switch solutions. I should note that I do not have a technical background and am responsible for procurement.
The value we were getting for our money was an issue. I work for a bank for which security is very important, but we were not being assured of the appropriate support. The licensing fees we were paying did not equate with adequate local support. We had already had a bad experience with Check Point, so we did not bother with a quote from it and, instead, got one from several local companies that can support either Palo Alto or Fortinet.
How are customer service and technical support?
We do not feel that the local support given in Uganda is equitable with the pricing.
What's my experience with pricing, setup cost, and licensing?
While the pricing is okay, the local Ugandan support one gets is not commensurate with it.
What other advice do I have?
I rate Check Point NGFW as a six out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Founder Director at digisec
Well-established product with great flexibility and user-interface
Pros and Cons
- "The features that I have found most valuable are its flexibility and user interface. This is already a well-established product in the market for quite a long time, more than 20 years. They've got a huge customer base."
- "In terms of what could be improved, I would say the application control and the visibility. I'd like granularity where you can have all the levels of policies that are defined, including the intel threat. It depends on what kind of intel threat the company has."
What is our primary use case?
Our customers primarily buy the solution to protect the network from malware at the perimeter of the Network. The next-gen firewalls help the customer to have an application-level control of the traffic.
What is most valuable?
The features that I have found most valuable are its flexibility and user interface. This is already a well-established product in the market for quite a long time, more than 20 years. They've got a huge customer base.
What needs improvement?
In terms of what could be improved, I'd like granularity where you can have all the levels of policies that are defined.
In additional feature that could be added to this solution in the future is micro-segmentation, like Palo Alto has on the firewall itself.
For how long have I used the solution?
I began using Check Point Next Generation Firewall very recently, about four or five months ago.
What do I think about the stability of the solution?
We have an internal team for maintenance.
What do I think about the scalability of the solution?
In terms of scalability, what we have seen is that it has a big deployment right now. So it all depends on what kind of environment the customer has. If he's already a Check Point user, it is easy for them, but if it is migrating from one platform to another, it is a little complex. One more thing is that the skillset availability required for Check Point is, in terms of implementation, a little less compared to others. The resources and the technical stuff are there for implementation. You find fewer people on Check Point compared to Sophos or Fortinet or any other platform.
How was the initial setup?
The installation process, if it is a greenfield opportunity, is easy. If it is a migration from one platform to another, you need to have expertise on both the technologies. Let's say for example you're migrating from Fortinet to Check Point, or from Sophos to Check Point or Check Point to any other, you need to have expertise on the platform, even though you should have good experience in terms of migrating and technologies.
What other advice do I have?
In my experience, Check Point provides both in-depth experience and cost-effectiveness compared to Palo Alto. So, Check Point is good for customers already using Check Point and Palo Alto is for anybody who wants to have the latest and most advanced features and has a good budget.
On a scale of one to ten, I would rate Check Point NGFW an 8.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Sales Engineer at Unistar
Good technical support, reliable, and offers effective threat prevention
Pros and Cons
- "The most valuable features are application control, regulation, and threat prevention."
- "Compliance and centralized management can be improved."
What is our primary use case?
We are a system integrator and the Check Point Next-Generation Firewall is one of the solutions that we implement for our clients. It is primarily used for data protection, VPNs, and sandboxing. We also use it in our own data center.
What is most valuable?
The most valuable features are application control, regulation, and threat prevention.
What needs improvement?
Compliance and centralized management can be improved.
For how long have I used the solution?
I have been using the Check Point NGFW for perhaps ten years.
What do I think about the stability of the solution?
This firewall runs 24 hours a day and it is stable.
What do I think about the scalability of the solution?
It scales okay because they are SCADA compliant and follow the industry standards. It is best suited to enterprise-level organizations.
How are customer service and technical support?
Technical support is located in Prague, Israel, and America. The support is good and they are quick.
Which solution did I use previously and why did I switch?
We have also worked with Fortinet a little bit. We switched to Check Point because our team is a perfect fit for it. We know the solution well.
How was the initial setup?
The length of time required for deployment depends on the size of the environment. Our largest solution took us between 10 and 20 days.
What about the implementation team?
We have a contract with the vendor to implement and deploy this solution for customers. There are three engineers on the staff who are responsible for maintenance and support, including dealing with tickets.
In total, working with this solution, we have four engineers and two junior administrators.
What's my experience with pricing, setup cost, and licensing?
It is quite an expensive product, although security is a top priority. For people who want security, the price is not a problem, and everything is included in the price of the license.
What other advice do I have?
This is the number one, best firewall on the market. My biggest complaint is that the centralized management has to be improved.
I would rate this solution a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner

Buyer's Guide
Download our free Check Point NGFW Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2025
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
OPNsense
Sophos XG
Cisco Secure Firewall
Palo Alto Networks NG Firewalls
Azure Firewall
WatchGuard Firebox
SonicWall TZ
Juniper SRX Series Firewall
Fortinet FortiGate-VM
SonicWall NSa
Untangle NG Firewall
Sophos XGS
KerioControl
Buyer's Guide
Download our free Check Point NGFW Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- How does Check Point NGFW compare with Fortinet Fortigate?
- Is Palo Alto Networks NG Firewalls better than Check Point NGFW?
- Which would you recommend - Azure Firewall or Check Point NGFW?
- Is Check Point's software compatible with other products?
- What do you recommend for a corporate firewall implementation?
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Which is the best network firewall for a small retailer?
- When evaluating Firewalls, what aspect do you think is the most important to look for?
- Cyberoam or Fortinet?