No more typing reviews! Try our Samantha, our new voice AI agent.

Check Point Cloud Firewall (formerly CloudGuard Network Security) vs ShieldX comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 16, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
591
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Firewalls (1st), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Check Point Cloud Firewall ...
Average Rating
8.4
Reviews Sentiment
7.4
Number of Reviews
166
Ranking in other categories
Firewalls (8th), Managed Security Services Providers (MSSP) (1st), Software Defined WAN (SD-WAN) Solutions (5th), Cloud and Data Center Security (6th), WAN Edge (3rd), Unified Threat Management (UTM) (4th)
ShieldX
Average Rating
9.2
Number of Reviews
4
Ranking in other categories
Microsegmentation Software (11th)
 

Mindshare comparison

Firewalls Mindshare Distribution
ProductMindshare (%)
Check Point Cloud Firewall (formerly CloudGuard Network Security)2.1%
Fortinet FortiGate16.0%
OPNsense8.9%
Other73.0%
Firewalls
Microsegmentation Software Mindshare Distribution
ProductMindshare (%)
ShieldX1.7%
Illumio24.7%
Akamai Guardicore Segmentation21.3%
Other52.3%
Microsegmentation Software
 

Featured Reviews

Abhi - PeerSpot reviewer
Network Security Engineer at a consultancy with 51-200 employees
Unified security and sd-wan have improved uptime and cut wan costs for multi-site branches
Users report stability issues in certain versions, which requires regular updates. Real-world attacks have also highlighted the need for urgent patching of vulnerabilities.Fortinet FortiGate, while a powerful and feature-rich web firewall, could improve in areas like firmware stability, documentation, and ease of use. The learning curve can be steep for some users. For beginners, support quality can vary, and frequent updates with occasional vulnerabilities call for careful patch management. However, once Fortinet FortiGate is configured, it remains highly reliable and efficient. Customer support needs improvement, as I find it very slow, with reports from other users reflecting that customer support is inadequate.
Tejas Jain - PeerSpot reviewer
Principle Cloud Architect at a tech services company with 11-50 employees
Cloud security has unified visibility and risk mitigation but still needs stronger features
Check Point Cloud Firewall (formerly CloudGuard Network Security) is definitely lagging behind its peers. I am not sure what the reason is. Compared to Palo Alto, they are not there in terms of capabilities and feature set. I do not think there are any obvious misses, but there is mostly lesser adoption in the industry. Regarding the negatives, sometimes we encounter challenges, especially if a feature may not be working, but that is typical of any vendor. There is no glaring gap; it is a solid product, but based on my experience, the adoption has not been on par with what its peers are doing. From time to time, we do face challenges with some features, especially if you need to configure a policy where you may need false positive fine-tuning. Sometimes, you have these anomaly detections, which are crucial from a zero-day attack perspective, but they can create a lot of false positives. When you have to tweak, you sometimes need to bring in technical assistance or professional services to achieve what you want. The documentation may not be quite sufficient. There were instances in the past, but I am not sure if they have ramped it up quite significantly recently.
MP
IT Director at park holidays uk
Proactively monitors, blocks, and reports what it has blocked; and self-updates meaning there is zero maintenance
The most valuable feature is the automatic scaling. With its microservices, it scales both up and down, depending on traffic and throughput. The traffic through our website depends on holiday bookings. It's very quiet in November through January, and then our traffic picks up quite rapidly and, at our peak, we will take in excess of a million pounds of business a day through our website. The UI was also one of the huge selling points. My web development manager was blown away with the detail and the granularity that you can get out of the UI. It is a very strong and informative UI, with the amount of data it provides. Uptime on the system has been 648 days and we do very little to it because it self-updates and alerts. It does everything that we need it to do, so the administration side of it is zero. One of the beauties about ShieldX is that it's such a good "fire-and-forget" product.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"By using Fortinet FortiGate, I significantly reduced major attacks that could exploit my network."
"The most valuable features of Fortinet FortiGate are its SD-WAN capabilities, such as dynamic routing, and other features, including security options such as antivirus, IPS, and IDS—all integrated into one device."
"Web filtering is the most useful feature."
"The best features of Fortinet FortiGate are that it does the job effectively and protects our environment."
"Fortinet provides us all that we need for security."
"In almost every case, I've experienced (or had customers experience) an ROI within 12 months, based on better performance for the same price or increased functionality for the same (or less) price."
"It is a stable solution compared to other vendors."
"It is useful for protecting and segregating the internal networks from the internet. Most of our customers also use the FortiGate client to connect to their offices by using the VPN client, and of course, they usually activate the antivirus, deep inspection, and intrusion prevention services. They are also using it for web filtering and implementing various policies dealing with forwardings, NAT, etc."
"We have found the overall functionality of the product to be exactly similar to the physical product. The one good advantage is that it is cloud-based and can be deployed either as a part of a scale set or one can shut down the virtual machine and adjust the physical parameters of the virtual machine easily and bring it right back up."
"Monitoring using SmartConsole and all its features is extremely easy, and I find SmartEvent an excellent monitoring tool for spotting threats and user behaviour."
"As per the solution's blade design, there are many options. For example, you have to buy a UTM blade and an advanced malware blade, etc. If the blade license is there, we can configure from the firewall GUI."
"It gives us more confidence in secure cloud deployments."
"Security effectiveness is the most valuable feature. Operational efficiency, reporting, and support are also good."
"The most valuable feature of this solution is that you can start off with a simple firewall and expand it to UTM."
"Its integration and use of features, such as advanced threat prevention, have helped us a lot with malware prevention and also with avoiding exposure to false positives."
"SSL/TLS traffic inspection features are used for advanced threat prevention against secure SSL traffic."
"It has helped us tighten our security posture. Now, staff can only access things that they should be accessing."
"We were able to see what devices are talking to each other, giving us more visibility."
"ShieldX has been designed from the very beginning to work well in cloud environments. It understands autoscaling, automation, and auto-configuration. These are the things which are important in today's operating environment."
"...It takes the exact same policies that you would apply to your on-premise environment and enables you to simply apply them to the cloud. It becomes one policy for both on-prem and for the cloud."
"ShieldX makes it a lot easier and a lot simpler to define your policies and define your rules, and that greatly reduces the opportunity for user error."
"The Adaptive Intention Engine is fantastic. It allows us to develop security policies using the language of our internal customers. It's machine-learning applied to security workflows. That allows us to much more easily construct the policies that will protect those workflows."
"Once you install it you can virtually forget about it; it's very low-maintenance and high-protection."
"The UI was also one of the huge selling points. My web development manager was blown away with the detail and the granularity that you can get out of the UI. It is a very strong and informative UI, with the amount of data it provides."
 

Cons

"The cloud features and integration could be improved."
"We have experienced a number of failures when trying to upgrade firmware and the process takes a long time. We only experienced this when doing major upgrades between versions."
"The customization is a little bit difficult because we have to customize everything."
"Lacks sufficient security options."
"Some features in Fortinet FortiGate need improvement as we discover when calling support that certain actions must be done from the command line."
"There can be more security in hybrid implementations. When a customer has a hybrid environment where some parts are in the cloud, we need a consistent security solution for such scenarios."
"Fortinet could improve the windows opener or the virtual IP solutions for opening windows. The virtual IP settings need improvement as firewalls are trending in new development directions."
"There are some tiny bugs that sometimes affect the operations. In the past revision of it, there was a bug. Because of the bug, we had to downgrade the version. It happened only with the last revision."
"While Check Point does offer some VWAN offerings, they appear to be more static and less tailored to cloud-native environments compared to Palo Alto's dynamic and flexible approach."
"We faced issues while upgrading our CloudGuard Network Gateway. When we tried to use the template that Check Point offers on their site, it was not available for the second to the latest version, so I was forced to upgrade my management server. That was very challenging for us."
"We miss full blade support for all blades that are compatible with the cluster. Especially notable is the lack of support for Identity Awareness in active standby environments for customers. In our setup, transitioning to Connective clusters would be preferable for maintaining connections during failover situations."
"The initial deployment using the ARM template in Azure was straightforward, but migrating to Terraform added complexity, although we managed to make it work."
"Its architecture and user interface need improvement. The user experience for this solution also needs to be improved, particularly in implementation, management, and operations."
"From my experience, the failover times are unsatisfactory when dealing with HA failovers in the cloud, but this is connected to API calls within Azure. While this is largely due to limitations of the cloud architecture, an improvement in this area would be beneficial."
"Stability wise the product is stable but we had issues when we had really old hardware that had a less than stable OS."
"The SD-WAN could be better."
"We are having some issues with their LDAP and integrating it with the Active Directory. We can't seem to set it up."
"There should be a bit more customer care, with regular review meetings on it or regular reports. It would be nice to have a quarterly or biannual review of what ShieldX has blocked."
"With any kind of tool like ShieldX, where you're in the cloud instead of a traditional firewall, you're using CPU resources in those environments to provide the protection. So there's a cost associated with CPU resources."
"The one criticism I might have is there should be a bit more customer care, with regular review meetings on it or regular reports."
"We are having some issues with their LDAP and integrating it with the Active Directory."
"I would like better reports and in-depth reporting."
"With any kind of tool like ShieldX, where you're in the cloud instead of a traditional firewall, you're using CPU resources in those environments to provide the protection. So there's a cost associated with CPU resources. I'm pressing upon them to make the product much more efficient and use less CPUs to do the same thing."
"They need to be consistent in performance and capabilities over time, given the fact that this is new and I want to see where this goes in the next year or so. As the vendor continues to evolve and add future functionality, we want to make sure that we are still keeping up with the integrations, etc. Time will be the key factor here. The proper support for some of the latest technologies, Docker containers, etc. They need to keep up with threat landscape, so we will see how the security get layered. This is what we are going to be keeping an eye on."
 

Pricing and Cost Advice

"Currently, we are paying about $1,500 a month for three sites."
"The pricing for this solution is reasonable."
"The solution is cheap."
"Its price is normal. If I compare it with other vendors, such as Palo Alto, it's normal. Palo Alto is expensive."
"For the price, I'd rate it a ten because it's very cost-effective."
"The cost has increased since the update so I would rate it eight out of ten."
"No comment."
"The price of Fortinet FortiGate is affordable. Most of our customers are on a three-year license to use the solution. All the features and support are included in the price."
"The price of Check Point CloudGuard Network Security is very high compared to other solutions, such as Fortinet FortiMail. For the over 2,000 mailboxes we use with the solution it is very expensive."
"The tool's pricing is not cheap."
"Pricing-wise, it is pretty competitive. However, I would like to see more flexible licensing. There should be more of a consume what you need and true-up type of model."
"We are using our BYOL. We are using our existing Check Point discounts to work with licensing. Overall, it is very competitive. Its pricing is reasonable to me."
"It is the most expensive part of the product. There is a lot of room for improvement. Security comes with a price, but it is still a big chunk just for the service."
"It is fairly priced, but it can be a little expensive from time to time."
"The licesning has some good features. For example, the scaling feature is free of charge, allowing multiple scale-ups and scale-downs over a two-week period, which is pretty good."
"It is expensive."
"Security policies are now applied as applications are going up. Because it's automated, we don't have the three to four week delay. The insertion of applications in the cloud for us dropped from an average of three to four weeks to a couple of days."
"ShieldX also enables us to migrate to cloud environments faster. That is an important part of it for sure because it takes the exact same policies that we would apply to our on-premise environment and enables us to simply apply them to the cloud. It becomes one policy for both on-prem and for the cloud."
"We are actually expecting our costs to drop in the coming year, but it is just a matter of the licensing expiring. That is going to happen in the next six months or so. Then, we will start to see a decrease in overall spend."
"ShieldX ensures that we can have the separation needed for our environment to avoid drastically increasing the cost on the licensing side. From this perspective, it's been very positive and helpful."
"For a three-year deal we paid £55,000 plus tax... But, and this is a big "but," this was over two years ago. ShieldX had only just hit the market. We were the first company in Europe to buy ShieldX."
"For other security professions who are looking for something which is low in cost that does microsegmentation, they should look at ShieldX. It might not be the big name out there, but it does everything that you are looking for in microsegmentation at a very low price."
"We are very happy with the pricing and licensing. It's about getting a site-wide license. One of the challenges that we've had with our previous vendor had been the cost of licensing."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
896,202 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
10%
Comms Service Provider
10%
Manufacturing Company
9%
Financial Services Firm
7%
Computer Software Company
10%
Financial Services Firm
9%
Outsourcing Company
9%
Manufacturing Company
7%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business367
Midsize Enterprise135
Large Enterprise193
By reviewers
Company SizeCount
Small Business71
Midsize Enterprise41
Large Enterprise79
No data available
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is your experience regarding pricing and costs for Check Point CloudGuard Network Security?
We have encountered a few subscription-based licensing models for the virtual gateway and security enablement. We hav...
What needs improvement with Check Point CloudGuard Network Security?
I find troubleshooting a bit challenging with Check Point Cloud Firewall (formerly CloudGuard Network Security); one ...
What is your primary use case for Check Point CloudGuard Network Security?
My usual use cases for Check Point Cloud Firewall (formerly CloudGuard Network Security) involve onboarding as an ene...
Ask a question
Earn 20 points
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
CloudGuard IaaS, Check Point vSEC, CloudGuard IaaS, Check Point Virtual Systems, Check Point CloudGuard Network Security
APEIRO, ShieldX APEIRO
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Physicians Choice Laboratory Services, Helvetica Insurance
Iowa State University
Find out what your peers are saying about Check Point Cloud Firewall (formerly CloudGuard Network Security) vs. ShieldX and other solutions. Updated: November 2024.
896,202 professionals have used our research since 2012.