Try our new research platform with insights from 80,000+ expert users
reviewer1402668 - PeerSpot reviewer
Security Engineer at a tech services company with 1,001-5,000 employees
Real User
You only need to use one rule for both the DMZ and the Internet
Pros and Cons
  • "The Check Point API let me make 100 net rules in just 10 minutes, which saved us time."
  • "I would rate the technical support as a seven out of 10. Sometimes, it's difficult to get them to understand what the issue is. Sometimes, the issue is not resolved, then we solve it by ourselves with Check Point's documentation, which can be useful. When you open a case with Check Point, they can be a little slow. Sometimes, they don't solve things."

What is our primary use case?

I am using this solution for perimeter security in the company. Our firewall security is centralized under one management. Also, we use this firewall to manage some of the VPN clients and the employees' access across the company. 

Each firewall is capable of using the VPN client, but we only use two. We have five in total, but we only use two for these issues.

I am using the firmware version for the operating system. The blades are firewalled for IPS and mobile access.

How has it helped my organization?

Last year, we used the Check Point Identity Awareness Software Blade. Now, we only use a normal firewall with IP address rules, address destination, and services. Then, we can filter by users. So, my boss has access to these things by user. Even if it's connected with the Active Directory, we can filter by user name, or in this case by server name, and it works perfectly. This is very valuable for our company.

What is most valuable?

The most valuable features about Check Point are the API and automation process.

Using the GUI, you can add comments from your PC or the client server. If I want to check the firewall rules, I can send one line of command to determine if it is configured or not. 

Its implementation and integration with the rest of the network are better than its competitors.

What needs improvement?

The stability needs improvement for its version releases. They have a feature called Inline Layer as part of the R80.10 release. In the last version, it still had bugs and is not working very well. I would like the developers to release a version that is more stable, because if you start to use the latest release and try to use this newest feature, I'm not 100 percent sure that it will work very well. After six months of development, it might start working better. However, at the beginning, it's not a good choice to implement in your company with your first attempt. But one or two releases later, it might be better. 

If you only have one vendor and they are downgraded or no longer a leader in their industry, then you need to change the entire solution, making it more expensive. For example, Check Point's components are not interchangeable with other vendors.

Buyer's Guide
Check Point NGFW
November 2024
Learn what your peers think about Check Point NGFW. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
815,854 professionals have used our research since 2012.

For how long have I used the solution?

Around four years.

What do I think about the stability of the solution?

The stability of the firewall is nice if you use the legacy mode, because the new mode is not good. Things worked in version 77, which is older. It was more stable. When they jumped from version 77 to 88, sometimes things didn't work that used to work in the earlier version.

What do I think about the scalability of the solution?

The scalability of the firewall depends on the model. In terms of the implementation, it's really easy.

We have about 25 users for the entire solution. We have two engineers who work on deployments and implementation. We have another 18 engineers who do support and operations. They have responsibility to monitor the firewall 24/7.

It protects the core network and ISP: the routing, switching, and APM backbone. This is around 8,000 pieces of equipment. 

We don't have plans to increase our usage right now.

How are customer service and support?

I would rate the technical support as a seven out of 10. Sometimes, it's difficult to get them to understand what the issue is. Sometimes, the issue is not resolved, then we solve it by ourselves with Check Point's documentation, which can be useful. When you open a case with Check Point, they can be a little slow. Sometimes, they don't solve things.

Which solution did I use previously and why did I switch?

In the beginning, we used Fortinet, Juniper, and Cisco. Now, we only use Check Point for firewalls. 

Last year, we changed the Fortinet firewall to the Check Point firewall. The Check Point API let me make 100 net rules in just 10 minutes, which saved us time.

The administration is awful in Fortinet. They have the FortiGate portal on an HTTP portal. Therefore, if you want to make a change, you can make a change. But if you do the change, then it's directly applied on the network, and we don't want to do that. We configure and change the policy and routing. We only apply the changes in the night. However, with Fortinet, you need to configure and apply the changes at the same time. So, it's not useful for our operations.

With Fortinet, you need to duplicate the rules from the DMZ to the Internet and the Internet to the DMZ. In Check Point, you only use one rule, which works on both sites.

How was the initial setup?

The initial setup is really easy. You can do it in 30 minutes. Setting up an environment for a firewall and its management with a licensed demo took me an hour last week, and that includes the time for configuring the rules. The whole installation is 30 minutes and the configuration is another 30 minutes.

If you are implementing from another vendor, Check Point has a program called SmartMove. Then, all you need is the configuration of the previous firewall. Once you do some optimization, then you are ready for the integration. This might take a month overall.

What about the implementation team?

We consulted with one partner of Check Point, who is our provider. If the issue is really big, then we open a case with Check Point directly via the partner. My experience with them was really nice. It was the best experience that I had ever had.

They have amazing engineers. Their expertise is unbelievable. They do integrations really well. They could improve on routing and networking, but the product is what is important for me. 

What was our ROI?

The firewall is only for protection. It is not used to sell services.

What's my experience with pricing, setup cost, and licensing?

The pricing and licensing are expensive. If you compare it with Fortinet, then it is cheaper on a yearly basis. However, Check Point is the most expensive firewall right now in terms of licenses and its appliance. My recommendation is if you want a long-term investment, then you should use an open server. If you use an open server, then the latency is really low. If you pay for a full appliance, it's more expensive.

Which other solutions did I evaluate?

Check Point's web administration is not complete. If you compare it to Fortinet's web administration, Check Point's web administration is not nice. However, Check Point's full solution, including SmartConsole, is better than Fortinet's solution.

What other advice do I have?

If you use Apple computers or Linux, the product may not be a good choice for you.

I would rate the solution as a seven point eight out of 10. They can improve some things. They can make it more flexible in terms of its software. It is a good solution, and I like it. For me, it's the best firewall solution.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Engineer at CENACE
Real User
Efficient firewall protection
Pros and Cons
  • "It is easy to configure and it is a valuable antivirus protection. I especially like the IPS feature of this product."
  • "The presentation of the reports need to be more user-friendly."

What is our primary use case?

We use this product as firewall protection.

How has it helped my organization?

We are a utility company, so we need efficient antivirus protocols. The firewall support is extremely important to our organization. Checkpoint helps us protect our company from outside threats.

What is most valuable?

It is easy to configure and it is a valuable antivirus protection. I especially like the IPS feature of this product.

What needs improvement?

The presentation of the reports need to be more user-friendly. 

For how long have I used the solution?

More than five years.

What do I think about the stability of the solution?

Sometimes we have problems. In those cases, we just need to reboot the system.

What do I think about the scalability of the solution?

The scalability of the solution is not great for us because we have old equipment. With newer equipment, I think the scalability would be much better. It is no fault of the solution itself. 

How are customer service and technical support?

The Checkpoint tech support takes a long time to resolve problems. 

Which solution did I use previously and why did I switch?

Prior to Checkpoint, we considered Cisco. 

How was the initial setup?

It was a complex setup. We had a partner configure the equipment. 

What's my experience with pricing, setup cost, and licensing?

The price is high in comparison to other solutions. 

Which other solutions did I evaluate?

We are currently considering Fortinet as another possible option. 

What other advice do I have?

After much evaluation, we have decided to change our firewall.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Check Point NGFW
November 2024
Learn what your peers think about Check Point NGFW. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
815,854 professionals have used our research since 2012.
it_user1364367 - PeerSpot reviewer
Sales Engineer at Unistar
Real User
Good technical support, reliable, and offers effective threat prevention
Pros and Cons
  • "The most valuable features are application control, regulation, and threat prevention."
  • "Compliance and centralized management can be improved."

What is our primary use case?

We are a system integrator and the Check Point Next-Generation Firewall is one of the solutions that we implement for our clients. It is primarily used for data protection, VPNs, and sandboxing. We also use it in our own data center.

What is most valuable?

The most valuable features are application control, regulation, and threat prevention.

What needs improvement?

Compliance and centralized management can be improved.

For how long have I used the solution?

I have been using the Check Point NGFW for perhaps ten years.

What do I think about the stability of the solution?

This firewall runs 24 hours a day and it is stable.

What do I think about the scalability of the solution?

It scales okay because they are SCADA compliant and follow the industry standards. It is best suited to enterprise-level organizations.

How are customer service and technical support?

Technical support is located in Prague, Israel, and America. The support is good and they are quick.

Which solution did I use previously and why did I switch?

We have also worked with Fortinet a little bit. We switched to Check Point because our team is a perfect fit for it. We know the solution well.

How was the initial setup?

The length of time required for deployment depends on the size of the environment. Our largest solution took us between 10 and 20 days.

What about the implementation team?

We have a contract with the vendor to implement and deploy this solution for customers. There are three engineers on the staff who are responsible for maintenance and support, including dealing with tickets.

In total, working with this solution, we have four engineers and two junior administrators.

What's my experience with pricing, setup cost, and licensing?

It is quite an expensive product, although security is a top priority. For people who want security, the price is not a problem, and everything is included in the price of the license.

What other advice do I have?

This is the number one, best firewall on the market. My biggest complaint is that the centralized management has to be improved.

I would rate this solution a ten out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Sathish Babu - PeerSpot reviewer
Solutions Consultant at a computer software company with 10,001+ employees
Real User
Tools for searching firewall rules make it easier for newcomers to manage devices
Pros and Cons
  • "The most valuable feature of the firewall is the packet inspection. That is an amazing feature from Check Point."
  • "It would be great if the access management, the user management features, were improved in terms of the number of users that can be connected, and how users can access the various resources with the help of firewall authentication."

What is our primary use case?

We provide solutions for various customers where we apply Check Point Firewalls, either for a VPN gateway or for securing their networks. We have provided them to a couple of financial customers to protect their mobile banking as well.

How has it helped my organization?

It has good features for searching the firewall rules and it has drastically changed daily operations. It's very easy, even for novice users or newcomers, to operate and manage this device. It has improved our operations that way.

What is most valuable?

The most valuable feature of the firewall is the packet inspection. That is an amazing feature from Check Point. Apart from that, we do have identity solutions which we use on a regular basis. Both are very good.

What needs improvement?

It would be great if the access management, the user management features, were improved in terms of the number of users that can be connected, and how users can access the various resources with the help of firewall authentication.

Also, one of the challenges I hear about from customers or engineers who work with and operate Check Point firewalls is not about the technical capabilities of the product but about understanding the product. There should be whitepapers available on the Check Point portal so that people can understand them more easily.

For how long have I used the solution?

I have been using Check Point's firewalls for almost 12 years. I started with the IP390.

What do I think about the stability of the solution?

Stability has improved a lot from Check Point's very early days over the last 12 years. Back then we had to reboot the firewall after every two to four days.

What do I think about the scalability of the solution?

The firewalls are scalable with our workload. We are at about 20 to 30 percent utilization so even if we doubled of our existing network resources and load on the firewalls, they would still have the space to scale. They're enough for the networks that we have implemented.

We recently finished a deployment and it's still in the user acceptance test phase. As of now, I cannot say anything in terms of increased usage. But for the customers that we have deployed it for within India and the APAC region, so far the results have been pretty good.

How are customer service and technical support?

I have used technical support a couple of times, when it was required, for hardware replacements. Of course, once or twice I contacted them for active devices when we had some glitches. But that turned out to have nothing to do with Check Point.

Overall, technical support has been good. They understand the situation and what part needs to be replaced or what needs troubleshooting through remote support tools.

Which solution did I use previously and why did I switch?

Before Check Point we used Cisco. And we use Cisco for a couple of customers because it's already pre-deployed, so it's not in our hands. We manage operations, so we are still managing Cisco devices. We don't have Juniper right now, but we have Palo Alto for one of our customers.

How was the initial setup?

The initial setup is very straightforward. When we boot the firewall we have instructions which say how to connect to the QR, and from that portal you go to your gateway and configure all the required network interfaces. Once you have installed your Smart controller, you need not log into the firewall every time. Instead, you can log in through your Smart controller. That's a pretty good method which no other firewall provides.

For the very basic features, it does not take more than two days. But, for a full-fledged implementation, it can take around two months.

Our implementation strategy is to replace existing firewalls in the network. We try to keep the business downtime as short as possible, especially for business-critical applications.

For deployment and maintenance of these firewalls we have a team, worldwide in different regions: APAC, Europe, America, and the Middle East, although in the Middle East we don't use Check Point.

What was our ROI?

We have definitely achieved ROI with Check Point firewalls.

Which other solutions did I evaluate?

We definitely evaluate other options based on the customer's budget, and the stability and technical specs of the firewall. We generally choose Check Point as our preferred product vendor.

What other advice do I have?

The biggest lesson I have learned from using Check Point's firewalls is that they are not complex.

I'm expecting a lot of solutions from Check Point and if there are more solutions from them, that would be great. I would like to see more product development.

Overall, I would rate it at 10 out of 10. It's the best firewall in the market.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Anupama Perera - PeerSpot reviewer
Marketing at Bluechip Technical Services Pvt Ltd
Reseller
Top 10
Strong security and management features
Pros and Cons
  • "Check Point has strong security features as well as some decent monitoring and management capabilities."
  • "My customers complain that the interface isn't user-friendly."

What is most valuable?

Check Point has strong security features as well as some decent monitoring and management capabilities.

What needs improvement?

My customers complain that the interface isn't user-friendly.

For how long have I used the solution?

I have been using Check Point for eight years.

What do I think about the stability of the solution?

Check Point stable. I've had no problems.

What do I think about the scalability of the solution?

Check Point is scalable.

How are customer service and support?

Check Point support is good.

How was the initial setup?

Check Point's setup process isn't very user-friendly.

What's my experience with pricing, setup cost, and licensing?

Check Point is a little more expensive than FortiGate.

What other advice do I have?

I rate Check Point nine out of 10. I work with both Check Point and FortiGate. Each has its advantages and disadvantages. Check Point is more secure than FortiGate. However, Fortigate is more affordable and user-friendly. FortiGate offers seamless solutions to customers, so If they want a solution that's easy to use, they go with FortiGate.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: reseller
PeerSpot user
CommMan719 - PeerSpot reviewer
Commercial Manager at a tech services company with 11-50 employees
Real User
Effective security and local support have been the key features for us
Pros and Cons
    • "We looked very closely at ArcSight's solution because it's a multi-vendor solution. With ArcSight we could have Check Point, we could have RSA, we could have any brand and integrate several brands, from a security point of view. With Check Point, you cannot do so, you can integrate with Check Point products."

    What is our primary use case?

    It is our next-generation firewall and IPS.

    How has it helped my organization?

    We had some security issues that WatchGuard could not resolve. Since installing Check Point, we have not had any troubles. We don't have any security problems anymore.

    Also, as we are systems integrators, we could not offer only one brand to our customers. We had to expand to several solutions to enable customers to make their own decisions.

    What is most valuable?

    It's a gateway and we can integrate some of their functionalities. It's a gateway for us to work with them. Compared to the previous solution we had - WatchGuard - Check Point really works.

    What needs improvement?

    We looked very closely at ArcSight's solution because it's a multi-vendor solution. With ArcSight we could have Check Point, we could have RSA, we could have any brand and integrate several brands, from a security point of view. With Check Point, you cannot do so, you can integrate with Check Point products. Check Point forces the customer to buy only one vendor's solution but the trends of the market are not to work with only one vendor. If Check Point could work with other vendor solutions, that would an improvement.

    It would also help if they had solutions for the SMB market. Check Point is only useful for customers that have a big IT budget. If they don't have the IT budget, the customer has to buy a solution that from another vendor.

    For how long have I used the solution?

    One to three years.

    What do I think about the stability of the solution?

    For the last 10 or 12 years, Check Point has been at the top of the industry ratings, so this demonstrates they make good products. The stability is really good.

    How are customer service and technical support?

    Technical support is really good. We work with a partner from Check Point, a very good partner. The time of response is very good. We are satisfied with the solutions that Check Point has provided us.

    Which solution did I use previously and why did I switch?

    Before using Check Point we were using WatchGuard, but it was not a good brand. Support from them was very difficult. We decided on Check Point because, first of all, their salespeople did a good job. In addition, their position in the market helped us decide to buy. Also, we are systems integrators and many of our customers use Check Point. Their feedback helped us make the decision to go with Check Point.

    An important criterion when selecting a vendor is that the vendor has to provide support here in Peru. Our experience with WatchGuard not having a local representative was that the support was not good in terms of time of response as well as difficulties with the idioms of the language. We speak Spanish and the support was only in English, so it was difficult.

    How was the initial setup?

    I'm not part of the technical staff. But from what I heard, the setup was fine. I believe the installation and deployment were without any problems.

    What's my experience with pricing, setup cost, and licensing?

    Check Point solutions are very expensive here. It's good, but it's expensive.

    What other advice do I have?

    Some vendors offer a PoC. When you do a PoC you can more easily see which is the better solution. We would recommend requiring a PoC.

    I would rate Check Point an eight out of 10. They're not a 10 because of their pricing.

    Disclosure: My company has a business relationship with this vendor other than being a customer:
    PeerSpot user
    reviewer1028424 - PeerSpot reviewer
    General Manager with 51-200 employees
    Real User
    Beneficial hybrid cloud, effective application protection, and simple installation
    Pros and Cons
    • "The most valuable feature of Check Point NGFW is it is a complete solution for protecting not only the network but the applications. Additionally, it provides a hybrid cloud solution."
    • "The whole solution has room for improvement."

    What is our primary use case?

    Our primary use of Check Point NGFW is for network protection.

    What is most valuable?

    The most valuable feature of Check Point NGFW is it is a complete solution for protecting not only the network but the applications. Additionally, it provides a hybrid cloud solution.

    What needs improvement?

    The whole solution has room for improvement.

    For how long have I used the solution?

    I have been using Check Point NGFW for approximately five years.

    What do I think about the stability of the solution?

    The solution is very stable.

    What do I think about the scalability of the solution?

    Check Point NGFW has been scalable.

    How are customer service and support?

    I would rate the technical support of Check Point NGFW a seven out of ten.

    How was the initial setup?

    The installation is straightforward.

    What about the implementation team?

    We have one staff member that does the implementation of the solution.

    What other advice do I have?

    I would say that the customer has to implement Check Point NGFW with the reseller. They have experience in the implementation and with security.

    I rate Check Point NGFW a ten out of ten.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    reviewer1621341 - PeerSpot reviewer
    Executivo de Negócios de TiC at a comms service provider with 10,001+ employees
    Real User
    Performs well and is easy to configure
    Pros and Cons
    • "My customers cite performance and ease of configuration as two of the solution's most valuable features."
    • "The price is middling. It's much more expensive than Fortinet, although not so expensive when compared with Palo Alto."

    What is our primary use case?

    I have certain customers who make use of the solution for providing security in respect of internet access. I am aware only of the solution acting as a firewall. 

    What is most valuable?

    My customers cite performance and ease of configuration as two of the solution's most valuable features. 

    What needs improvement?

    The price is middling. It's much more expensive than Fortinet, although not so expensive when compared with Palo Alto. 

    What's my experience with pricing, setup cost, and licensing?

    The solution is significantly more expensive than Fortinet, although this holds true to a lesser extent when compared with Palo Alto. 

    Which other solutions did I evaluate?

    The solution is significantly more expensive than Fortinet, although this holds true to a lesser degree when compared with Palo Alto. 

    What other advice do I have?

    I do not have much familiarity with Check Point NGFW, although I do have several customers who make use of it. I can mainly comment based on what I have come across in user reviews in magazines.

    I know the solution to be one of the top players in the world at the moment. 

    As Check Point NGFW does not compare favorably price-wise with Fortinet, I am inclined to deduct a point from its rating and rate it as a nine out of ten.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Buyer's Guide
    Download our free Check Point NGFW Report and get advice and tips from experienced pros sharing their opinions.
    Updated: November 2024
    Buyer's Guide
    Download our free Check Point NGFW Report and get advice and tips from experienced pros sharing their opinions.