Try our new research platform with insights from 80,000+ expert users

AWS Firewall Manager vs Tufin Orchestration Suite comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Nov 4, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

AWS Firewall Manager
Ranking in Firewall Security Management
9th
Average Rating
7.8
Reviews Sentiment
6.6
Number of Reviews
9
Ranking in other categories
No ranking in other categories
Tufin Orchestration Suite
Ranking in Firewall Security Management
2nd
Average Rating
8.0
Reviews Sentiment
7.2
Number of Reviews
182
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of October 2025, in the Firewall Security Management category, the mindshare of AWS Firewall Manager is 3.7%, down from 5.7% compared to the previous year. The mindshare of Tufin Orchestration Suite is 22.6%, up from 21.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewall Security Management Market Share Distribution
ProductMarket Share (%)
Tufin Orchestration Suite22.6%
AWS Firewall Manager3.7%
Other73.7%
Firewall Security Management
 

Featured Reviews

Karthik Ekambaram - PeerSpot reviewer
Has centralized rule management and improved protection against suspicious traffic but needs better threat intelligence integration and automated policy enforcement
I have not compared AWS WAF with any other WAF solution yet, but whatever WAF you choose, there will always be challenges, and it cannot block all malicious traffic. For AWS WAF, we have seen cases where it allowed suspicious HTTPS headers even if they carried malicious payloads. However, the malicious payloads are not straightforward, and there are assembly scripts that come with the HTTP headers that sometimes AWS WAF misses. In the last four or five years, we have seen a case where WAF was unable to capture a threat. On the other hand, we also see alerts from WAF indicating that it has figured out many DDoS protection alerts and was able to block them, even with rate limiting. Rule-based WAF works perfectly fine, but I don't think any threat intelligence-based WAF solutions can be 100% accurate. The integration with AWS Organizations and enforcement of security policies, particularly SCP, is difficult to deploy in most of my companies due to client environments. When I say difficult, it depends on the client's organization processes, not AWS itself. The SCP feature is excellent in my view and is the best way to reduce the attack surface for organizations structured in a specific manner. While we have used it internally, limited features of SCPs can be utilized by customers. Regarding automating security policy deployment, we have utilized automated security policy features, but it is difficult in some instances. We have identified what has been identified, but enabling automated SCP policies can be restrictive, which is actually good but makes it hard to implement for all organizations. Automating security policy features could understand the customer's environment better. An AI- or ML-enabled automated SCP could be a better option since it can understand the actions of administrators or developers in the customer's organization within the AWS platform, providing more in-depth automated assessments and SCP features. I rate this solution 8 out of 10.
MithatBulut - PeerSpot reviewer
New employees can quickly grasp the various IPs, devices, and the network's logical and physical
Tufin is primarily used to orchestrate and manage network traffic and firewall devices. It is specifically useful for implementing firewall policies and handling requests from clients that require policy updates or changes Tufin simplifies understanding network topology. New employees can quickly…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It has centralized cloud firewall management rules. It provides compliance in tracking and reporting."
"The product is highly reliable."
"The interface is intuitive and it is easy for the users."
"The most valuable feature is the centrally managed rule. I also like the central orchestration."
"AWS Firewall Manager isn't a separate solution when you create the virtual private cloud (VPC), so you can control the traffic through that security group."
"Also, the strength of the community is invaluable."
"We work with compliance monitoring in the product, which is helpful for identifying framework-based misconfigurations, as it can tell you where to deploy firewall policies based on the frameworks."
"The most valuable feature is scaling, which allows you to deploy one configuration and scan and deploy it across the network. The automated policy application feature also streamlines security operations."
"Visibility is its largest and most valuable feature. You can see everything or all the devices on the network for each customer. It provides you a larger view of what might be wrong with the network and how you can improve it with firewall rules, etc. If you are talking about secure change, being able to automate the entire change process is pretty much the winner for us. It is going to really reduce the time that it takes for us to do changes, and we can just go out and get more customers."
"This has helped us to better clean up and audit changes to the firewall policy."
"Our customer has the ability to centrally monitor and view all changes that have been made in the network, and they are able to revert any problems that they encounter, if somebody has made a problematic change."
"It is very easy to use. We can get results back quickly."
"SecureChange is the most interesting part. It all comes down to having the user request firewall access and SecureChange, based on workflows, takes care of it, sending two or three emails to the business approvers. With one click, you can automate a firewall rule."
"We just got done with major audits. Tufin was able to provide information to give back to people, and say, "Hey, this is what I need to do, and what we're doing.""
"The Topology Map, which feeds into our SecureChange - the latter being an automation platform - there's a lot of synergy between the two."
"We were hit by the NotPetya attack. Therefore, our whole company and all its sites were down for several months. So, you don't have an attack like that and not need something like Tufin. Other companies can prevent these attacks, or at least slow them down, by having this type of a tool. We will never go back."
 

Cons

"The product could benefit from improvements in the user interface and integration capabilities."
"They could consider organizing and enhancing documentation in a more structured and chronological manner"
"The system should be more customizable."
"AWS Firewall Manager should be open to manage other third-party appliances as well."
"Enabling and configuring the logging is not that straightforward."
"This solution is suitable for a small-scale enterprise and may not scale up to a very high volume of traffic or a large number of servers."
"It needs to be more employee-friendly, and the security management could be more efficient."
"I would like to see AWS add some UTM features to the firewall. It would also be great if AWS Firewall had native IPS/IDS. They have the separate IPS/IDS, GuardDuty."
"There are at least two things that need improvement. One is the business workflow and the second is the integration with logging solutions."
"At least in our environment, the dynamic learning of the topology needs improvement."
"There was some complexity during the initial setup"
"The metrics need improvement. They need more consistency or understanding of automation, along lines of customization of automation."
"They are sort of at the pilot stage on some of their products. I saw the Orca and Iris products yesterday. My initial impression of these products were that they were good products, but I felt like some of their features overlapped with SecureTrack and SecureChange, which they are already doing. So, I just wondered what direction they're going in? I understand that they are cloud products, but are these security products going to overlap each other's features at some point? This is my initial concern."
"Its price is reasonable, but it could be lower. It could have a more effective approach for creating and changing rules. It could provide advice or suggestions for a better understanding of rules and changing the rules. There should be suggestions for the rules that need to be changed to make them less risky."
"I would like to see them get rid of the REST APIs and use something more modern."
"We will be using the appliance based product, which cannot be scaled as much. It is a limitation in the hardware."
 

Pricing and Cost Advice

"The AWS Firewall Manager is a little on the costly side."
"It is a cost-efficient product."
"From what I've heard from my colleagues, it appears that the pricing is competitive, which influenced our decision to choose this option."
"The licensing is on a pay-as-you-go basis and we are billed monthly."
"I just wrote a purchase order for it. It is a $150,000 a year."
"There is a permanent license for devices, but it's not relative to a device itself. Once you purchase 10 licenses for virtual appliances or virtual context, you can put them into different virtual firewalls, but you can reuse these licenses for other devices if you don't need them for the old ones."
"The price is on the cheaper side."
"Our licensing fees are approximately $100,000 USD yearly."
"We have seen ROI in operational aspects, in terms of how long it takes to resolve incidences which arise."
"We have seen ROI from the side of operations, and we'll probably get to more of that as time goes on. However it took a while to get to that point."
"While licensing varies greatly, it is about $50,000 a year."
"Licensing is available in both perpetual and subscription models, and it appears to be good for our scalable environments."
report
Use our free recommendation engine to learn which Firewall Security Management solutions are best for your needs.
870,697 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
10%
Financial Services Firm
10%
Comms Service Provider
7%
Retailer
6%
Financial Services Firm
17%
Computer Software Company
13%
Manufacturing Company
11%
Retailer
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business5
Large Enterprise6
By reviewers
Company SizeCount
Small Business29
Midsize Enterprise13
Large Enterprise152
 

Questions from the Community

What do you like most about AWS Firewall Manager?
It has centralized cloud firewall management rules. It provides compliance in tracking and reporting.
What is your experience regarding pricing and costs for AWS Firewall Manager?
Microsoft Firewall costs depend on region-based pricing. I don't recall the exact costs because we usually don't get the costing for the firewall alone but rather for the entire product we use, so ...
What needs improvement with AWS Firewall Manager?
I don't see any specific problems with AWS Firewall Manager, but the area of improvement could be in threat intelligence integration. For instance, while I'm not specifically saying Mandiant, which...
What needs improvement with Tufin SecureCloud?
Tufin Orchestration Suite ( /products/tufin-orchestration-suite-reviews ) is not commonly used in Thailand due to a lack of local support, and many customers are switching to AlgoSec or other vendo...
What is your primary use case for Tufin SecureCloud?
I have primarily used Skybox and AlgoSec ( /products/algosec-reviews ). I have also interacted with FireMon for compiling. However, I am not currently working with ACA, and I don't have any project...
What advice do you have for others considering Tufin SecureCloud?
There is potential for improvement in explaining the analytics in the dashboard for Tufin Orchestration Suite. Tufin Orchestration Suite does provide good monitoring; however, interpreting the grap...
 

Also Known As

No data available
Tufin SecureCloud
 

Overview

 

Sample Customers

Expedia, Intuit, Royal Dutch Shell, Brooks Brothers
3M, AT&T, Blue Cross Blue Shield, BNP Parabas, ConocoPhillips, Deutsche Bank, GE, IBM, Pfizer, United States Postal Service 
Find out what your peers are saying about AWS Firewall Manager vs. Tufin Orchestration Suite and other solutions. Updated: September 2025.
870,697 professionals have used our research since 2012.