We use Check Point NGFW as a perimeter NAT Gateway with the security features, it helps us to prevent hackers. We implement Check Point-based infrastructures for our customers. In most cases, this is the same perimeter gateway and internal segmentation firewalls. Many of our customers also using the VPN feature to organize remote access to the company's assets for employees, especially in the COVID period, and to connect their branch offices to the base infrastructure. Environments are differing from one out customer to another, but these are primary use cases.
Security Analyst at HOST
Enables us to catch much more malware and spam with incoming traffic, and we now are more protected with our environment
Pros and Cons
- "AV, IPS, AntiSpam, Sandbox. That's gentlemen set for any basic security, and it was implemented very well. In our reports, the most exciting results belong to AV and IPS. It can be explained by using ThreatCloud - a global knowledge base, which accumulates signatures for all existing and new coming malware, and all the Check Point solutions are always up to date with potential threats."
- "I hope for product simplification. It would be better to use one security console, instead of many of them (for licensing and monitoring). The solution is hard for newcomers and takes much time to deep in. Also, I want a historical graph for throughput and system resources usage. Maybe it will be great to make easy step-by-step installation and configuration cookbooks as Fortinet did, and integrate the documentation within the solution."
What is our primary use case?
How has it helped my organization?
We catch much more malware and spam with incoming traffic, and now we are more protected with our environment. For our customers, this is always a surprise, when we are running a pilot project - how mush malware and attacks we catch during the two weeks period. Check Point has a great report called "Security Check Up", that show these results on informative charts. In our region, our customers use primarily local solutions, that has no good security features inside. Check Point has a certification there, which allows them to work in our region and make the world safer.
What is most valuable?
AV, IPS, AntiSpam, Sandbox. That's gentlemen set for any basic security, and it was implemented very well. In our reports, the most exciting results belong to AV and IPS. It can be explained by using ThreatCloud - a global knowledge base, which accumulates signatures for all existing and new coming malware, and all the Check Point solutions are always up to date with potential threats. When we using sandbox with Sandblast agent, often there are not real-world exciting results, but when we show a solution in work with existing samples, it also shows good results.
What needs improvement?
I hope for product simplification. It would be better to use one security console, instead of many of them (for licensing and monitoring). The solution is hard for newcomers and takes much time to deep in. Also, I want a historical graph for throughput and system resources usage. Maybe it will be great to make easy step-by-step installation and configuration cookbooks as Fortinet did, and integrate the documentation within the solution. In most cases, the solution works great and I recommend it for our customers.
Buyer's Guide
Check Point NGFW
January 2025
Learn what your peers think about Check Point NGFW. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,071 professionals have used our research since 2012.
For how long have I used the solution?
3 years.
What do I think about the stability of the solution?
Everyone falls sometimes. I recommend using high availability or at least two power blocks.
What do I think about the scalability of the solution?
Nice, easy to connect and implement high availability.
How are customer service and support?
Support is great, we solved cases with solution integrations easily.
Which solution did I use previously and why did I switch?
We are using many solutions at the same time. Just to be closer to our customers.
How was the initial setup?
Initial is very easy. Further - harder.
What about the implementation team?
In-house
What was our ROI?
12 months.
What's my experience with pricing, setup cost, and licensing?
NGTP is easy and strong. If you need the best security - use SanbBlast in addition.
Which other solutions did I evaluate?
We always check security options before implementing them to customers.
What other advice do I have?
Good solution - I recommend it.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer: Our company is a Security Integrator. We are Check Point Partner and Deploy their solutions for our customers.
Senior Technical Consultant at Ivalue Infosolution
Feature-rich, easy to deploy, security oriented, and offers scalability and great throughput
Pros and Cons
- "The most valuable feature is the Stateful Inspection, which was developed by Check Point."
- "No product is perfect and there is always room for improvement."
What is our primary use case?
I am a Check Point distributor and the Next-Generation Firewall is one of the products that I am dealing with. My customers use this as part of their security solution that covers mobile devices, computers, their network, cloud, SD-WAN, IoT devices, IP phones, IP cameras, and others.
How has it helped my organization?
Checkpoint has provided Security to the entire data center.
What is most valuable?
This is a feature-rich product and all of them are useful.
The most valuable feature is the Stateful Inspection, which was developed by Check Point.
The throughput is very good with Check Point. Checkpoint ThreatCloud is the largest threat intelligence database.
Checkpoint management is a single pane of glass from where you can manage all the CP solutions from a single point be it on-prem or cloud or hybrid.
What needs improvement?
There is always room for improvement and CP Dev team is on right path.
For how long have I used the solution?
I have been working with Check Point firewalls for more than five years.
What do I think about the stability of the solution?
This is a stable firewall. It is very good.
What do I think about the scalability of the solution?
Scalability and throughput are very high. They have also launched a solution called Check Point Maestro, which provides cloud-level scalability on-premises. This makes it very scalable.
Which solution did I use previously and why did I switch?
My customers use firewall products from several vendors, including Sophos. Sometimes they replace their existing firewalls, and at other times, they run Check Point in parallel.
How was the initial setup?
The initial setup is very simple. This solution can be installed on-premises or on the cloud.
It takes between 30 and 45 minutes to deploy.
What about the implementation team?
Our in-house team does the installation for our clients. We also handle support, depending on what level of support the client has. Sometimes, they go directly to the OEM.
What other advice do I have?
Until earlier this year, the consolidated management was application-based and required installation. As of recently, they have launched web-based management, as well as cloud-based management. This is an upgrade that I had been waiting for because we no longer have to go to the dashboard. Instead, we just enter the IP into chrome and you get the dashboard on the web page, without having to install anything.
This is a very good product, although there is always room for improvement.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Check Point NGFW
January 2025
Learn what your peers think about Check Point NGFW. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,071 professionals have used our research since 2012.
Security Engineer at Tenece Professional services
Enables us to complete the network compliance rules and has a great GUI
Pros and Cons
- "We use Check Point to complete the network compliance rules."
- "This product has room for improvement in technical support for Africa."
What is our primary use case?
The management of our company requires a firewall implementation. We use Check Point to complete the network compliance rules.
How has it helped my organization?
We use Check Point NGFW for compliance. The initial request leads to secondary requests. By the time you have recognition, there is recollection. For the main service, it's collection.
What is most valuable?
The feature we have found to be the most valuable is the management firewall.
What needs improvement?
This product has room for improvement in technical support for Africa. There are some problems with African countries. We also need to provide excellent services.
The additional feature I would most like to see included in the next release of this solution is removal management.
What do I think about the stability of the solution?
The stability of the solution is quite good. It has a great GUI and it's comfortable. I love the content. Of course, you also have great support.
What do I think about the scalability of the solution?
The new version is highly scalable. Now all of our users depend on the firewall. We have about 150 users. We require two staff for deployment and management.
Which solution did I use previously and why did I switch?
We previously used Sophos. We switched for more security.
How was the initial setup?
The initial setup was straightforward. Our deployment took two or three weeks. Deploying the first one was two weeks, but the other ones were around one week.
What about the implementation team?
For the first setup, I used a consultant. For the second one, I didn't. We didn't need one.
What's my experience with pricing, setup cost, and licensing?
Licensing costs for this solution are on a yearly basis.
What other advice do I have?
On a scale from one to 10, I would rate this product a nine. Nobody's perfect.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security and Network Engineer at a tech services company with 501-1,000 employees
User-friendly configuration, good support, and trouble-free upgrades have made our jobs easier
Pros and Cons
- "The rules are very easy to deploy and can be optimized pretty quickly."
- "One of the main features that need improvement is the rule filter export."
What is our primary use case?
The Check Point NGFW is the best product that I have ever used. It has pluses and minuses, as do others, but the usability, simplicity, and the configuration abilities are very user-friendly. After a while, other vendors just don’t come close to it.
The second thing is that is just works and it does it with ease. The upgrades and bug fixes are frequent and well documented. Also, the patches just work ;-)
There are some negatives but as I already said, they aren’t many and from my point of view, we can see past them.
How has it helped my organization?
It has made our lives and working in the company a lot easier. We have a better overview of the logs and what happens with the traffic in our company. Which means that the search for the certain logs is easy, quick and smooth. The overview of the logs is also very good as it is very detailed. The installation is allot quicker as it was before what also helps us with the implementation of the firewall rules. The rule consolidation is also very important as we have more than 60 fw rule change requests per day.
What is most valuable?
The rules are very easy to deploy and can be optimized pretty quickly. The R80 has a great feature on how the rules are processed, which costs less in terms of CPU and threads than it did before.
The features that are integrated into the firewall are very useful for our everyday use. Examples of these are the log manager, the firewall monitor commands, and the Linux commands. These are all very useful and helpful.
The VPN tunnels are easy to set up once you understand how they have to be configured.
What needs improvement?
One of the main features that need improvement is the rule filter export. All of the other vendors can export the filtered IPS as a PDF or CSV file, but with the smart dashboard, it’s just not possible. One can only export the whole rule base and then search for the IPS, which is super time-consuming as you can’t send the whole rule base to a customer. You would get weird questions about certain rules, why they are deployed or configured as they are, and maybe even get unwanted tips on how to change them.
For how long have I used the solution?
We have been using Check Point NGFW for eight years.
What do I think about the stability of the solution?
In terms of stability, this solution is very good.
What do I think about the scalability of the solution?
The scalability is high.
How are customer service and technical support?
The technical support is very good.
Which solution did I use previously and why did I switch?
We did not use another solution prior to this one.
How was the initial setup?
The initial setup is very easy.
What about the implementation team?
I implemented and deployed Check Point NGFW alone.
What's my experience with pricing, setup cost, and licensing?
Maybe the pricing is a bit high but you get the durability and the duration.
Which other solutions did I evaluate?
We evaluated Palo Alto and Cisco ASA.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Chester at Iocane
Great centralized management with good threat extraction and excellent commitment to innovation
Pros and Cons
- "Management integration is holistic as centralized management has been core to the solution for decades."
- "Potential improvements could be made around simplifying VPN functionality and configuration."
What is our primary use case?
I work for a systems integrator and have designed and deployed solutions over many years with Check Point components. Problems solved with Check Point NGFWs have included securing the edge, data center segregation, SWG replacement, Remote Access, and many others.
I have designed and installed Check Point deployments from a single SMB appliance to multiple highly available chassis, running numerous virtual systems. Numerous different use cases include appliance form-factors, running modules, and licenses.
How has it helped my organization?
I have always found that Check Point's fully integrated management provides significant improvements to organisations where I have deployed them. As management has always been integral in the Check Point deployment, all functionality and visibility is natively baked into the management platform, which provides a single point to configure and monitor every function. Alternative vendors have added centralized management functionality as a secondary feature and therefore have never been able to compete on this front.
What is most valuable?
Management integration is holistic as centralized management has been core to the solution for decades. Where other vendors have bolted management on over time, Check Point has always made it central to everything that they do.
I find that this is one of the most significant and valuable features of Check Point. In addition to that, many new features that eventually become the standard across the industry end up being first introduced by Check Point - sometimes years ahead (such as Threat Extraction which allows active content to be stripped from files being downloaded and a "clean" copy to be provided in near real-time, while sandbox inspection is being performed).
What needs improvement?
Product-wise, I have no real complaints.
Potential improvements could be made around simplifying VPN functionality and configuration.
The main area that the organization can improve is around the lack of local, in-state technical support. Competitor vendors have a strong presence in the Adelaide Market, however, Check Point has always been limited with its commitment to staffing local technical resources. If this focus is made, I could see Check Point returning to the strength that it once had in the Adelaide market.
For how long have I used the solution?
I've used the solution for 17 years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Support Manager at Sefisa
Stable and very robust with helpful technical support
Pros and Cons
- "The product is very scalable."
- "Sometimes when they bring on new upgrades, they affect something else."
What is most valuable?
I do like that this solution is a very robust firewall.
It's very stable.
The product is well supported. The solution is very scalable.
Technical support has been quite good.
What needs improvement?
The only thing I would like to improve is the updates. Sometimes when they bring on new upgrades, they affect something else. That happens sometimes. For example, something that was working well might have a new issue after an update. It's understandable as they do have like to add innovations. When you are innovative, you face some risks.
They have already announced that they will be adding SD-WAN as a new feature.
For how long have I used the solution?
I've been using the solution for 18 years.
What do I think about the stability of the solution?
The solution is very stable. There are no bugs or glitches. It doesn't crash or freeze. It's reliable. That said, I would like the latest version to be more stable.
What do I think about the scalability of the solution?
The product is very scalable. You have very good options. For example, if you start with a smaller firewall and you want to upgrade to have newer hardware, they have different options. For example, you can run a script that is going to tell you the new appliances that you need, according to your new requirements according to your network consumption.
It did launch Maestro about two years ago. Maestro is something that allows you to stack firewalls. If your current firewalls handle the traffic anymore, you can add new firewalls to it.
If you want to change the firewall you can do these trade-ins. You can return the old firewall and they will give you a special discount.
How are customer service and support?
Technical support has been very helpful and responsive. We've been happy with the level of support they offer.
How was the initial setup?
The product is easy to set up. I am seasoned on Check Point. For me, it's very easy. I wouldn't say it's hard.
What other advice do I have?
I'd rate the solution at a ten out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer:
Procurement Supervisor at Centenary Bank
Support is okay, but is inequitable with the price
Pros and Cons
- "The pricing is okay."
- "While the solution is good, we wish to have something that is a bit better, as the threats have evolved over time."
What needs improvement?
While the solution is good, we wish to have something that is a bit better, as the threats have evolved over time. We have been using Check Point for more than than eight years and are interested in a better solution. We entered a review site which ranks top security firewalls and saw that Palo Alto is ranked number one, followed by Fortinet, with Check Point in the lead. We noticed that Palo Alto was much more expensive than Fortinet, but wished to know which key features differentiated the two.
Though we did not take issue with the price of Check Point NGFW, we felt that it was providing us with inadequate support here in Uganda. This is why we decided to switch solutions. I should note that I do not have a technical background and am responsible for procurement.
The value we were getting for our money was an issue. I work for a bank for which security is very important, but we were not being assured of the appropriate support. The licensing fees we were paying did not equate with adequate local support. We had already had a bad experience with Check Point, so we did not bother with a quote from it and, instead, got one from several local companies that can support either Palo Alto or Fortinet.
How are customer service and technical support?
We do not feel that the local support given in Uganda is equitable with the pricing.
What's my experience with pricing, setup cost, and licensing?
While the pricing is okay, the local Ugandan support one gets is not commensurate with it.
What other advice do I have?
I rate Check Point NGFW as a six out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Founder Director at digisec
Well-established product with great flexibility and user-interface
Pros and Cons
- "The features that I have found most valuable are its flexibility and user interface. This is already a well-established product in the market for quite a long time, more than 20 years. They've got a huge customer base."
- "In terms of what could be improved, I would say the application control and the visibility. I'd like granularity where you can have all the levels of policies that are defined, including the intel threat. It depends on what kind of intel threat the company has."
What is our primary use case?
Our customers primarily buy the solution to protect the network from malware at the perimeter of the Network. The next-gen firewalls help the customer to have an application-level control of the traffic.
What is most valuable?
The features that I have found most valuable are its flexibility and user interface. This is already a well-established product in the market for quite a long time, more than 20 years. They've got a huge customer base.
What needs improvement?
In terms of what could be improved, I'd like granularity where you can have all the levels of policies that are defined.
In additional feature that could be added to this solution in the future is micro-segmentation, like Palo Alto has on the firewall itself.
For how long have I used the solution?
I began using Check Point Next Generation Firewall very recently, about four or five months ago.
What do I think about the stability of the solution?
We have an internal team for maintenance.
What do I think about the scalability of the solution?
In terms of scalability, what we have seen is that it has a big deployment right now. So it all depends on what kind of environment the customer has. If he's already a Check Point user, it is easy for them, but if it is migrating from one platform to another, it is a little complex. One more thing is that the skillset availability required for Check Point is, in terms of implementation, a little less compared to others. The resources and the technical stuff are there for implementation. You find fewer people on Check Point compared to Sophos or Fortinet or any other platform.
How was the initial setup?
The installation process, if it is a greenfield opportunity, is easy. If it is a migration from one platform to another, you need to have expertise on both the technologies. Let's say for example you're migrating from Fortinet to Check Point, or from Sophos to Check Point or Check Point to any other, you need to have expertise on the platform, even though you should have good experience in terms of migrating and technologies.
What other advice do I have?
In my experience, Check Point provides both in-depth experience and cost-effectiveness compared to Palo Alto. So, Check Point is good for customers already using Check Point and Palo Alto is for anybody who wants to have the latest and most advanced features and has a good budget.
On a scale of one to ten, I would rate Check Point NGFW an 8.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Download our free Check Point NGFW Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
OPNsense
Cisco Secure Firewall
Sophos XG
Palo Alto Networks NG Firewalls
Azure Firewall
WatchGuard Firebox
SonicWall TZ
Juniper SRX Series Firewall
Fortinet FortiGate-VM
Untangle NG Firewall
SonicWall NSa
Sophos XGS
KerioControl
Buyer's Guide
Download our free Check Point NGFW Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- How does Check Point NGFW compare with Fortinet Fortigate?
- Is Palo Alto Networks NG Firewalls better than Check Point NGFW?
- Which would you recommend - Azure Firewall or Check Point NGFW?
- Is Check Point's software compatible with other products?
- What do you recommend for a corporate firewall implementation?
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Which is the best network firewall for a small retailer?
- When evaluating Firewalls, what aspect do you think is the most important to look for?
- Cyberoam or Fortinet?