Try our new research platform with insights from 80,000+ expert users

AWS Firewall Manager vs Tufin Orchestration Suite comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Nov 4, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

AWS Firewall Manager
Ranking in Firewall Security Management
7th
Average Rating
8.0
Reviews Sentiment
7.1
Number of Reviews
11
Ranking in other categories
No ranking in other categories
Tufin Orchestration Suite
Ranking in Firewall Security Management
2nd
Average Rating
8.0
Reviews Sentiment
7.2
Number of Reviews
182
Ranking in other categories
AI Observability (78th)
 

Mindshare comparison

As of February 2026, in the Firewall Security Management category, the mindshare of AWS Firewall Manager is 3.2%, down from 4.8% compared to the previous year. The mindshare of Tufin Orchestration Suite is 20.2%, down from 21.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewall Security Management Market Share Distribution
ProductMarket Share (%)
Tufin Orchestration Suite20.2%
AWS Firewall Manager3.2%
Other76.6%
Firewall Security Management
 

Featured Reviews

Venda E - PeerSpot reviewer
Cloud Option Engineer at a tech vendor with 10,001+ employees
Centralized security policies have streamlined audits and ensure consistent protection by default
One area for improvement is the reporting and customization option. The compliance reports are helpful, but having more granular insights or export options would make it even easier to use during audits. Also, support for more third-party integration could improve flexibility. Another improvement I need to see is a smoother setup experience. Some of the initial configuration steps, especially around the organization and permissions, can feel complex. A more guided setup or clear UI explanation would make it easier for teams to adopt quickly. One more improvement would be better alerting options. Right now, we mostly rely on AWS Security Hub or CloudWatch for detailed alerts. Having more built-in, real-time notification directly from AWS Firewall Manager would make it easier to monitor policy violations without extra setup.
Vulnerability control saves audit costs and reduces expenses for organizations
Tufin Orchestration Suite is not commonly used in Thailand due to a lack of local support, and many customers are switching to AlgoSec or other vendors. The analytics features of Tufin Orchestration Suite are challenging to use and require technical expertise, which is a concern as there is not much knowledge in this field in Thailand. The issue of technical knowledge, especially regarding English language proficiency, is significant for government and some companies, making Tufin Orchestration Suite harder to use.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature is scaling, which allows you to deploy one configuration and scan and deploy it across the network. The automated policy application feature also streamlines security operations."
"Once this solution is set up, we hardly have to touch it."
"It is helpful for our compliance, as the compliance manager manages compliance with leading industry standards such as FedRAMP, which my company complies with, GDPR laws, and ISO 27001."
"The most valuable feature is the centrally managed rule. I also like the central orchestration."
"It has centralized cloud firewall management rules. It provides compliance in tracking and reporting."
"The interface is intuitive and it is easy for the users."
"Also, the strength of the community is invaluable."
"AWS Firewall Manager isn't a separate solution when you create the virtual private cloud (VPC), so you can control the traffic through that security group."
"We use this product to sharpen our change cycle. A request used to take quite a while as we did manual assessments. A lot of that is now done through SecureTrack."
"We use Tufin to clean up our firewall policies. It benefits us, because you can run a query for whatever your cleanup criteria is, e.g., "Has it been hit in 90 days?" It displays the list, then you can see the rules right there. If you want to get rid of it (or highlight it), then it creates a ticket that goes ahead and flags them all as disabled. While you can delete them, we always disable first. Then, we have a strip that comes back, and if it's been disabled for 90 days, then the system will remove them."
"It's hard to pick the most valuable feature. All of them are valuable, they're all critical for us... ChangeTrack obviously has a lot of very good features, like the risk analysis, the USP, and the Policy Browser."
"The solution is quite scalable."
"We've scaled it to hundreds of firewalls."
"The most valuable feature of this solution is that it reduces both the time required and the number of errors when making changes."
"We built the policy comparison reporting into our processes that before we push any change to production, an engineer will stage actual date rule changes and policy changes. Another engineer will go in and do a comparison report of the last push policy to the last save, making sure what has been changed is what is expected to. From an operational excellence, it's huge for us. We have huge policies. All it takes is one accidental right click, delete, or backspace button, which could impact our business. So, this is something that we use almost day in and day out."
"It has helped us to meet our compliance mandates. We have some requirements that we need to provide more visibility on the risk levels of our firewall base and Tufin helped us with that requirement."
 

Cons

"I would like to see AWS add some UTM features to the firewall. It would also be great if AWS Firewall had native IPS/IDS. They have the separate IPS/IDS, GuardDuty."
"They could consider organizing and enhancing documentation in a more structured and chronological manner"
"The product could benefit from improvements in the user interface and integration capabilities."
"AWS Firewall Manager should be open to manage other third-party appliances as well."
"Enabling and configuring the logging is not that straightforward."
"One area for improvement is the reporting and customization option."
"The areas of improvement are definitely platform resiliency, as we have seen outages on the AWS backbone, and whenever there is an outage on the AWS backbone, it impacts all the services hosted on that region, so we expect regional resiliency."
"The system should be more customizable."
"The initial setup was time consuming."
"I think that the interface could be cleaner, and easier to use."
"I would also like to see them do more cloud integration within the Tufin Orchestration Suite, not within a SaaS solution."
"We will be using the appliance based product, which cannot be scaled as much. It is a limitation in the hardware."
"The integration with different products needs to be improved."
"The two main negative points with Tufin Orca are the absence of full support and that accommodation of files and tools is not provided in a good way."
"The firewall management is complex for beginners."
"Lacks ability to create a Terraform that would enable deployment without manual steps."
 

Pricing and Cost Advice

"The licensing is on a pay-as-you-go basis and we are billed monthly."
"From what I've heard from my colleagues, it appears that the pricing is competitive, which influenced our decision to choose this option."
"The AWS Firewall Manager is a little on the costly side."
"It is a cost-efficient product."
"I believe our cost is more than $100,000 per year."
"Tufin and AlgoSec were pretty much in the competitive price range, but this one provided us better integration into the Check Point environment."
"The pricing is reasonable."
"For us it's around $40,000 or so."
"Pricing played a big part here... The customer had evaluated other products but, due to price as well as support, they chose Tufin."
"Our licensing costs are pretty low. We were grandfathered in, so we are at about $35,000 per year."
"This solution helped us to reduce the time it takes to make changes. We used to spend up to an hour to do a change, and now, it's around five minutes."
"We have seen ROI just in the time savings and knowledge. Knowledge is power. Having the solution do it automatically for you without you doing the work is huge. If you are spending $50,000 a year, it could have cost you a $100,000 in man-hours without it, especially if you are working with a team.."
report
Use our free recommendation engine to learn which Firewall Security Management solutions are best for your needs.
882,886 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
8%
Hospitality Company
8%
Retailer
7%
Manufacturing Company
7%
Financial Services Firm
15%
Manufacturing Company
12%
Computer Software Company
10%
Comms Service Provider
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business5
Large Enterprise8
By reviewers
Company SizeCount
Small Business29
Midsize Enterprise13
Large Enterprise152
 

Questions from the Community

What is your experience regarding pricing and costs for AWS Firewall Manager?
My experience with pricing, setup cost, and licensing for AWS Firewall Manager has been straightforward. There is no separate licensing cost for AWS Firewall Manager itself. It is included with AWS...
What needs improvement with AWS Firewall Manager?
One area for improvement is the reporting and customization option. The compliance reports are helpful, but having more granular insights or export options would make it even easier to use during a...
What is your primary use case for AWS Firewall Manager?
My main use case for AWS Firewall Manager is centrally managing and enforcing security policies across multiple AWS accounts. It helps me to ensure consistent WAF rules, security group policies, an...
What needs improvement with Tufin SecureCloud?
Tufin Orchestration Suite ( /products/tufin-orchestration-suite-reviews ) is not commonly used in Thailand due to a lack of local support, and many customers are switching to AlgoSec or other vendo...
What is your primary use case for Tufin SecureCloud?
I have primarily used Skybox and AlgoSec ( /products/algosec-reviews ). I have also interacted with FireMon for compiling. However, I am not currently working with ACA, and I don't have any project...
What advice do you have for others considering Tufin SecureCloud?
There is potential for improvement in explaining the analytics in the dashboard for Tufin Orchestration Suite. Tufin Orchestration Suite does provide good monitoring; however, interpreting the grap...
 

Also Known As

No data available
Tufin SecureCloud
 

Overview

 

Sample Customers

Expedia, Intuit, Royal Dutch Shell, Brooks Brothers
3M, AT&T, Blue Cross Blue Shield, BNP Parabas, ConocoPhillips, Deutsche Bank, GE, IBM, Pfizer, United States Postal Service 
Find out what your peers are saying about AWS Firewall Manager vs. Tufin Orchestration Suite and other solutions. Updated: February 2026.
882,886 professionals have used our research since 2012.