Cisco Defense Orchestrator vs Tufin Orchestration Suite comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Cisco Defense Orchestrator
Ranking in Firewall Security Management
14th
Average Rating
8.2
Number of Reviews
14
Ranking in other categories
No ranking in other categories
Tufin Orchestration Suite
Ranking in Firewall Security Management
2nd
Average Rating
8.0
Number of Reviews
180
Ranking in other categories
Container Security (22nd)
 

Market share comparison

As of June 2024, in the Firewall Security Management category, the market share of Cisco Defense Orchestrator is 1.4% and it increased by 49.3% compared to the previous year. The market share of Tufin Orchestration Suite is 19.4% and it increased by 1.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewall Security Management
Unique Categories:
No other categories found
Container Security
0.6%
 

Featured Reviews

TE
Jul 10, 2019
Provides visibility into entire infrastructure and bulk changes save time and resources
Some of the issues we've had aren't really a CDO problem. For example, we had some MX devices that were blocking Windows Update from happening. We found out it was a Meraki issue, but it would have been nice if it had been flagged for us: "Hey, these updates are failing because the MX is blocking it." It wasn't a huge problem, but there was a loss of our time as well as the fact that the updates didn't get pushed out. You could look at that as a security issue but, at the same time, when updates won't run for any reason on certain machines, you freak out a little bit. We thought it was a licensing issue with Microsoft or it could have been Dell EMC. But we were wasting time making all these phone calls and having people remotely troubleshoot it. The troubleshooters were saying, "Man, this looks like a network issue." They tethered a phone and joined it to the wireless on the phone to see if it would update and, boom, it started working. The weird thing was that when we switched it back over to the network, the Meraki was letting it through at that point. It would have been nice if CDO had let us know that that was an issue. There are probably some things that it could do as far as some of the analytics are concerned, things I know it would be capable of: "Hey, why are all these requests coming in? The reason is that a firmware update needs to happen on the Meraki. It's a known issue." That would be helpful.
Amroy Lumban Gaol - PeerSpot reviewer
Sep 26, 2022
A flexible, very secure solution that works well in Layer 2 environments
Our company uses the solution to auto deploy and analyze locks for hundreds of Layer 2 firewalls which are more challenging than Layer 3.  We write script for manual configurations, create policies, analyze all rules and locks, and then auto deploy. We currently have 40 engineers and 100 staff who…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"When we're looking to the policies, it identifies the shadow rules. It notifies us about anything that will supersede other rules."
"The initial setup was straightforward. We spun up the VM onsite. We generated the key that it needed to talk to the Cloud Orchestrator. After that, as I started adding devices, it was relatively quick and easy."
"We use a lot of image upgrades. We take some 20 devices and then we update everything at once, including the policies. We apply policies for groups. For certain groups, like anti-viruses, we send out policies and apply them to every single device. It's really easy and simple."
"The ability to see the uptimes on the different VPNs that we have configured for site-to-site."
"If we have a firewall go down, I can hop into CDO, pull the latest configuration off and apply it. That's really good. It helps save time."
"This product provides excellent centralized device controls and reporting."
"With Cisco Defense Orchestrator, we can manage the complete Cisco Security solution. It provides a simple and centralized way to manage all products."
"The most valuable feature is the Intrusion prevention."
"The automation because it is saving a lot of work, time, and effort required to do all of our manual work. The change impact analysis is pretty good, and with the automation, it takes care of a lot of things which we would be doing manually."
"The filtering of lots of criteria is very valuable."
"We use it to clean up our firewall policies, which gives us better security policy and less junk on the firewalls."
"The visibility is huge. In order to figure out what was going on previously, we would have to pull stuff out of firewalls and put them in spreadsheets, then do sorts. Now, it's all right there in Tufin. We can write reports to look for what we need, ad hoc searches to find object groups, and know which firewalls are on. This was almost impossible to do previously."
"I like the policy topology map, which allows us to visualize the picture of the security policy of the whole organization."
"This solution has helped our clients because it allows them to leverage the tools so that they can actually reduce their overall expenses for the environment."
"It is extremely scalable. It really addresses the scale of a company's firewall footprint."
"Tufin has made handling firewall rule request tickets more centralized and easier to manage."
 

Cons

"I've found dozens of bugs over the year we've been using it. The more I use it for different things, the more problems I find... Most of the problems have to do with the user interface. A lot of thought and work has gone into the back-end component to make the product do what it's intended to do, but the way it is presented for use hasn't gotten nearly as much thought to make it smart and bug-free."
"It would be a better product if it incorporated device control for third-party products easily."
"CDO doesn't have a report, an official report that I can check daily. It has another module called FTD, but it doesn't have that specifically for ASA. In the reporting, there are a lot of things that aren't there. There is also room for improvement in the daily monitoring."
"There could be some slight improvements to navigation. In some of the navigation you've got to go back to be able to get into where you need to be once you've made a change. If I make a change, I've then got to go back to submit and send the change."
"If I make a change locally to the firewall, CDO gives an alarm or an error message and says there's a change in compliance: "The firewall has this configuration but the last time it was compiled it had that configuration." That view of new changes versus the old could be better... I had to log in manually, locally on the firewall, to check which version, which configuration was actually running. I couldn't see it in CDO."
"The dashboard needs to be more customizable to provide better reporting for our network."
"Cisco Defense Orchestrator can improve by providing more support for third-party security components."
"They need to work on the user interface. It needs to be improved to make it more user-friendly."
"A big improvement would be on the USP policy. If we could use Palo Alto to take those zone names and auto import them into the policy, then just do the policy based on the zone names instead of having to put in every single subnet."
"The documentation site is horrible as well. It has a tree structure, and you really get lost quite easily."
"For me, there are two things that can make Tufin a bit better... [It needs] a better focus on automation - automating a lot of the processes; and automating rule re-certification, or at least finding a way to simplify it."
"Lacks ability to create a Terraform that would enable deployment without manual steps."
"One of the areas that I've had challenges with is making complicated reports."
"In the next release I would like to see better migration in the Cloud because that will allow more visibility in the network."
"They need to offer more support to vendors, such as Cisco, Checkpoint, Fortinet, and Forcepoint."
"I would like to see the setup of the Unified Security Policy simplified."
 

Pricing and Cost Advice

"It is covered under the CIsco Enterprise License Agreement (ELA). So, it is licensed and ours."
"It is about a $100 per year for an ASA 5506 firewall, and from there it keeps going up if you have a bigger box. For example, the 5516 is $200 to $300 per year."
"After our free trial was done we got a subscription for three years and it was under $3,000 or so. It's part of the EA we already paid for, so I don't know what it would be if it was a la carte."
"If you compare to what is available on the market, they are in the same range with respect to pricing."
"I work with a lot of clients, and the price or value of the Cisco Defense Orchestrator can vary from one client to another. If you have a lot of Cisco solutions, the price of the Cisco Defense Orchestrator is justified. Whereas if you have some security components from other vendors, such as Check Point or Palo Alto. This solution would be a pretty expensive proposition considering that they don't integrate with them well."
"It's around £500 per unit for a three-year license."
"We have seen ROI just in the time savings and knowledge. Knowledge is power. Having the solution do it automatically for you without you doing the work is huge. If you are spending $50,000 a year, it could have cost you a $100,000 in man-hours without it, especially if you are working with a team.."
"Our evaluation showed that Tufin's features were on par with AlgoSec, but Tufin was the better financial choice."
"Pricing played a big part here... The customer had evaluated other products but, due to price as well as support, they chose Tufin."
"The price of Tufin could be lower."
"The solution has helped us to reduce the time it takes to make changes. With Tufin, it takes ten to 15 minutes. Before, it was 30 minutes or more."
"Because we're quite a large company, the price wasn't too much of a factor for us."
"The cost is pretty high. It's close to seven figures."
"I believe our cost is more than $100,000 per year."
report
Use our free recommendation engine to learn which Firewall Security Management solutions are best for your needs.
787,061 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
45%
Financial Services Firm
7%
Manufacturing Company
7%
Government
5%
Financial Services Firm
18%
Computer Software Company
18%
Manufacturing Company
7%
Retailer
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Ask a question
Earn 20 points
What do you like most about Tufin?
The most valuable feature of Tufin is security auditing. We are able to check the rules and compliance of the company, for example, what is allowed or not. We are able to check the rules over diffe...
What is your experience regarding pricing and costs for Tufin?
Tuffin is expensive, and we have to explain to our customers the benefit for them to purchase. If we explain the benefits in the correct way they do not mind the price. We typically do costing for ...
What needs improvement with Tufin?
The reporting function could improve in Tufin. For our clients with companies that have strong compliance, reporting privacy data is mostly a problem. In the IT department, private data needs a fun...
 

Also Known As

CDO
Tufin SecureCloud
 

Learn More

Video not available
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

Insurance Company of British Columbia, Shawmut
3M, AT&T, Blue Cross Blue Shield, BNP Parabas, ConocoPhillips, Deutsche Bank, GE, IBM, Pfizer, United States Postal Service 
Find out what your peers are saying about Cisco Defense Orchestrator vs. Tufin Orchestration Suite and other solutions. Updated: May 2024.
787,061 professionals have used our research since 2012.