Try our new research platform with insights from 80,000+ expert users

AWS Firewall Manager vs Tufin Orchestration Suite comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Nov 4, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

AWS Firewall Manager
Ranking in Firewall Security Management
9th
Average Rating
8.0
Reviews Sentiment
7.1
Number of Reviews
11
Ranking in other categories
No ranking in other categories
Tufin Orchestration Suite
Ranking in Firewall Security Management
2nd
Average Rating
8.0
Reviews Sentiment
7.2
Number of Reviews
182
Ranking in other categories
AI Observability (78th)
 

Mindshare comparison

As of January 2026, in the Firewall Security Management category, the mindshare of AWS Firewall Manager is 3.3%, down from 5.1% compared to the previous year. The mindshare of Tufin Orchestration Suite is 21.0%, down from 21.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewall Security Management Market Share Distribution
ProductMarket Share (%)
Tufin Orchestration Suite21.0%
AWS Firewall Manager3.3%
Other75.7%
Firewall Security Management
 

Featured Reviews

Venda E - PeerSpot reviewer
Cloud Option Engineer at a tech vendor with 10,001+ employees
Centralized security policies have streamlined audits and ensure consistent protection by default
One area for improvement is the reporting and customization option. The compliance reports are helpful, but having more granular insights or export options would make it even easier to use during audits. Also, support for more third-party integration could improve flexibility. Another improvement I need to see is a smoother setup experience. Some of the initial configuration steps, especially around the organization and permissions, can feel complex. A more guided setup or clear UI explanation would make it easier for teams to adopt quickly. One more improvement would be better alerting options. Right now, we mostly rely on AWS Security Hub or CloudWatch for detailed alerts. Having more built-in, real-time notification directly from AWS Firewall Manager would make it easier to monitor policy violations without extra setup.
Vulnerability control saves audit costs and reduces expenses for organizations
Tufin Orchestration Suite is not commonly used in Thailand due to a lack of local support, and many customers are switching to AlgoSec or other vendors. The analytics features of Tufin Orchestration Suite are challenging to use and require technical expertise, which is a concern as there is not much knowledge in this field in Thailand. The issue of technical knowledge, especially regarding English language proficiency, is significant for government and some companies, making Tufin Orchestration Suite harder to use.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature is the centrally managed rule. I also like the central orchestration."
"Overall, it improved our security posture and made audits much easier."
"It has centralized cloud firewall management rules. It provides compliance in tracking and reporting."
"The interface is intuitive and it is easy for the users."
"The most valuable feature is scaling, which allows you to deploy one configuration and scan and deploy it across the network. The automated policy application feature also streamlines security operations."
"We work with compliance monitoring in the product, which is helpful for identifying framework-based misconfigurations, as it can tell you where to deploy firewall policies based on the frameworks."
"Once this solution is set up, we hardly have to touch it."
"AWS Firewall Manager isn't a separate solution when you create the virtual private cloud (VPC), so you can control the traffic through that security group."
"The best feature for me is being able to look up objects within all of our policies, because we have a little over 12,000 rules and over 30,000 objects. When one person says, 'Hey, where's my server?' I can just go to Tufin and say, 'Hey, where is that server?' and very quickly it tells you where it is, what policy it's on. That is a life saver."
"I had been impressed with the depth of capabilities within SecureTrack, particularly, in terms of generating insights for a user and firewall operator. With SecureTrack, I've been impressed with the level of flexibility with workflow design and its ability to generate different work streams and flows through the tool that are customized for our organization processes."
"The product is good at auditing the changes that we make in our environment."
"In the past, we would do certain things because of private knowledge of people's own understanding of the network. We don't have to rely on just that piece of it, because of the topology. We now know which firewalls come into play."
"We are using the visibility with notifications on every firewall change and what those changes were. We have visibility to see who is making the changes, and when."
"We can check and analyze the current status of our firewall rules."
"Tufin allows our say junior guys to learn how to view policies. It gives them a tool that will help them consolidate and optimize."
"We are able to discover firewall rules that are too broad and widen the security footprint."
 

Cons

"AWS Firewall Manager should be open to manage other third-party appliances as well."
"One area for improvement is the reporting and customization option."
"They could consider organizing and enhancing documentation in a more structured and chronological manner"
"I would like to see AWS add some UTM features to the firewall. It would also be great if AWS Firewall had native IPS/IDS. They have the separate IPS/IDS, GuardDuty."
"Enabling and configuring the logging is not that straightforward."
"The areas of improvement are definitely platform resiliency, as we have seen outages on the AWS backbone, and whenever there is an outage on the AWS backbone, it impacts all the services hosted on that region, so we expect regional resiliency."
"This solution is suitable for a small-scale enterprise and may not scale up to a very high volume of traffic or a large number of servers."
"It needs to be more employee-friendly, and the security management could be more efficient."
"I would like easier integration with more automation."
"The change workflow process is flexible and customizable to some extent, but there is room for improvement. In some cases, we've found it difficult to get the exact thing which we were looking for. Then, we end up having to go and do the thing manually."
"The integration with different products needs to be improved."
"I would like to see an improved reporting model that can be flexible for us to generate our own reports. The data's already there."
"The metrics need improvement. They need more consistency or understanding of automation, along lines of customization of automation."
"The network part of the solution could be improved. It's too hard because of the Tufin licensing model for the routing devices."
"Currently, we have to get different data from different sections of the site. It would be nice if it was all combined into one."
"It would be better if they modernized the web GUI. The web interface GUI is simple and not complicated, but it's also too old."
 

Pricing and Cost Advice

"From what I've heard from my colleagues, it appears that the pricing is competitive, which influenced our decision to choose this option."
"The licensing is on a pay-as-you-go basis and we are billed monthly."
"It is a cost-efficient product."
"The AWS Firewall Manager is a little on the costly side."
"Licensing is on a customer by customer basis."
"This solution helped us to reduce the time it takes to make changes. We used to spend up to an hour to do a change, and now, it's around five minutes."
"Tuffin is expensive, and we have to explain to our customers the benefit for them to purchase. If we explain the benefits in the correct way they do not mind the price. We typically do costing for the customer for three to five years. We make the general total cost of ownership at the beginning of a project for our customers."
"I suggest talking with Tufin about the flexibility of the pricing structure."
"Our engineers are spending less time on manual processes: 20 to 30 hour plus."
"We have seen ROI from the side of operations, and we'll probably get to more of that as time goes on. However it took a while to get to that point."
"It is expensive, but as compared to other players, it's more or less okay. Their pricing is not very transparent. This is my biggest point regarding Tufin. I've never seen a price list or something like that. It's always individual, and in many cases, it's very confusing to know what is the base and what is the price."
"Our licensing fees are more than $100,000 USD per year."
report
Use our free recommendation engine to learn which Firewall Security Management solutions are best for your needs.
881,082 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
9%
Comms Service Provider
7%
Hospitality Company
7%
Computer Software Company
7%
Financial Services Firm
15%
Manufacturing Company
12%
Computer Software Company
11%
Educational Organization
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business5
Large Enterprise8
By reviewers
Company SizeCount
Small Business29
Midsize Enterprise13
Large Enterprise152
 

Questions from the Community

What is your experience regarding pricing and costs for AWS Firewall Manager?
My experience with pricing, setup cost, and licensing for AWS Firewall Manager has been straightforward. There is no separate licensing cost for AWS Firewall Manager itself. It is included with AWS...
What needs improvement with AWS Firewall Manager?
One area for improvement is the reporting and customization option. The compliance reports are helpful, but having more granular insights or export options would make it even easier to use during a...
What is your primary use case for AWS Firewall Manager?
My main use case for AWS Firewall Manager is centrally managing and enforcing security policies across multiple AWS accounts. It helps me to ensure consistent WAF rules, security group policies, an...
What needs improvement with Tufin SecureCloud?
Tufin Orchestration Suite ( /products/tufin-orchestration-suite-reviews ) is not commonly used in Thailand due to a lack of local support, and many customers are switching to AlgoSec or other vendo...
What is your primary use case for Tufin SecureCloud?
I have primarily used Skybox and AlgoSec ( /products/algosec-reviews ). I have also interacted with FireMon for compiling. However, I am not currently working with ACA, and I don't have any project...
What advice do you have for others considering Tufin SecureCloud?
There is potential for improvement in explaining the analytics in the dashboard for Tufin Orchestration Suite. Tufin Orchestration Suite does provide good monitoring; however, interpreting the grap...
 

Also Known As

No data available
Tufin SecureCloud
 

Overview

 

Sample Customers

Expedia, Intuit, Royal Dutch Shell, Brooks Brothers
3M, AT&T, Blue Cross Blue Shield, BNP Parabas, ConocoPhillips, Deutsche Bank, GE, IBM, Pfizer, United States Postal Service 
Find out what your peers are saying about AWS Firewall Manager vs. Tufin Orchestration Suite and other solutions. Updated: December 2025.
881,082 professionals have used our research since 2012.