Try our new research platform with insights from 80,000+ expert users

KerioControl vs Trellix Intrusion Prevention System comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 19, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

KerioControl
Ranking in Intrusion Detection and Prevention Software (IDPS)
16th
Average Rating
8.2
Reviews Sentiment
6.9
Number of Reviews
58
Ranking in other categories
Firewalls (26th), Unified Threat Management (UTM) (10th)
Trellix Intrusion Preventio...
Ranking in Intrusion Detection and Prevention Software (IDPS)
13th
Average Rating
8.4
Reviews Sentiment
6.6
Number of Reviews
16
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of February 2026, in the Intrusion Detection and Prevention Software (IDPS) category, the mindshare of KerioControl is 2.7%, down from 3.8% compared to the previous year. The mindshare of Trellix Intrusion Prevention System is 2.9%, up from 2.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Intrusion Detection and Prevention Software (IDPS) Market Share Distribution
ProductMarket Share (%)
Trellix Intrusion Prevention System2.9%
KerioControl2.7%
Other94.4%
Intrusion Detection and Prevention Software (IDPS)
 

Featured Reviews

MM
Senior Systems Tech/Admin at Samco Software Inc.
Comprehensive Security Features and High Ease of Setup Elevate User Experience
The best features for KerioControl are its proprietary VPN protocol, which does not connect easily with other firewalls unless you enable IPsec. It will only connect to KerioControl. KerioControl is very valuable for business. Key points where KerioControl is valuable include its own anti-spam, intrusion prevention, and antivirus, which is included in the yearly subscription renewals. The VPN capabilities are helpful in managing my remote or distributed workforce, as we create documents and set up a location for clients to download. Clients can download KerioControl's VPN client online, and they just have to log in from the VPN client, which connects easily. I assess the firewall function in filtering both incoming and outgoing network traffic with KerioControl as excellent. Everything is logged, and any intrusion, antivirus, virus, or anything foreign to the system trying to hack in gets logged, and we can easily block those IPs.
BS
Large account Manager at Softcell Technologies Limited
Has offered reliable threat protection and detailed network insights but could expand features beyond existing capabilities
The best features of Trellix Intrusion Prevention System include advanced ATP (Advanced Threat Protection), which uses signatures, behavior analysis, and machine learning to stop zero-day exploits and malware advanced persistent threats (APTs). They track and collect data from APTs, which allows them to track malicious files entering the environment. The system offers inline prevention and real-time automatic blocking of malicious packets before they reach the network. It integrates with the Trellix ecosystem and provides application visibility and control. The solution provides deep insight into network traffic, applications, and protocols for better information. All packets coming through the application are analyzed and reported. They share intelligence updates regularly to protect from different malicious files and sector-specific threats. It supports both on-premise and cloud environments.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The ease of use in the GUI itself is the most valuable feature. The GUI is really the best part of it. We like the traffic rules so we can control who can get to what. It's easy to determine the flow of the traffic itself so we aren't having to guess through command lines and reading out basically command-driven output. It's just a very easy-to-use interface. The interface is the best part of the product."
"I like intrusion detection and prevention and bandwidth management. The routing part is also awesome. It is a good firewall. We never had a major breach from outside. We've never been impacted by ransomware, and our systems have never been infiltrated."
"The user interface and the ease of use are pretty good. Everything fits together so nicely."
"The firewall and the content filtering options are valuable."
"The initial setup is a breeze."
"It is very comprehensive and simple. It has all the active protections. It's updated. We love that you can set how often it is updated so you can work what is right for you. A large company with a lot of bandwidth can update the virus definitions and security definitions hourly, if they want. A smaller site that's remote, where maybe updating the definitions will eat into the bandwidth, we can schedule those more to go later at night. It's very flexible and works for us in all types of situations. This is great because then we don't have to learn seven different products to be able to work with seven different scenarios."
"The installation is straightforward."
"The most valuable features include geo-tagging, which blocks all other IPs except for the specified accounts, and web filtering."
"It has a lot of functions, such as firewall. We are administrators, and we create some rules to protect our network. We also monitor the traffic in and out and have disk encryption on-premises. When we detect malware, we scan for the virus on the PC. We can then delete or block the malware."
"The most valuable features in Trellix for me are the automated signature updates. It is a great and convenient feature."
"The product is worth the investment."
"The most valuable features are the customization of the signature and the unlimited amount of signatures in IPS."
"The initial setup is straightforward."
"The threat intelligence updates are very accurate."
"The best feature of the Trellix Intrusion Prevention System is the rules that Trellix provides, I think that's the best value from IPS."
"The feature I found most valuable is the network threat analyzer in the security platform. It also integrates with GTI, or Global Threat Intelligence. Otherwise, I just use the basic features."
 

Cons

"When it comes to dealing with updates, there are often bugs on the solution. They should do a lot more testing before they release new versions."
"I would like for them to add more security features."
"The antivirus seemed to be a bit laggy on the connection so I disconnected that. It's definitely good. The only issue we've had with any sort of cyber attack seemed to be coming from a couple of distinct locations, people trying to get into known ports on remote desktops and stuff like that. The fact that we can block all that traffic is just great. It simplifies it."
"I find it a bit costly to pay for the products that I am not using. They need to change their model in such a way that you don't have to pay for the products that you are not using. Its local support and scalability are also not good. I am looking forward to a more scalable product that will be able to grow with time and technology."
"The security part of the software, like virus scanning, website, traffic monitoring, things like that, can take a beating on the appliance. And when there's a lot of things going on, the system can get bogged down. The actual security functionality of it needs a little bit more work, which I believe they are remedying or attempting to remedy at this time, but that's the downfall at this time."
"There's also room for improvement in the Traffic Rules. We define networks to use a specific outgoing interface, say VSAT, shore, or marine WiFi, which is okay. But then all we have is a checkbox that says "Use other internet interfaces if this one is unavailable." What we would prefer would be to have a priority list. So if VSAT is unavailable, try to use 4G, etc. We haven't really found a reliable way of doing that in the current release."
"The solution can be improved to create the capability for larger bandwidths that support our business needs."
"I would like to see geo-IP filtering added to the filtering rules. Incorporating these rules would be very beneficial if you have different ideas or reasons to filter, such as communication to the email server or specific websites."
"There are limited resources for configuration guidance."
"Trellix Intrusion Prevention System does not provide virtual patching."
"The technical support must be improved."
"The management console needs to be less complex and easier to navigate."
"Integration with Global Thereat Intelligence could be better. Also, I think management solutions are end of life now at McAfee. Network threat analyzer may be used for endpoint quarantines. Integration between these sides, as well as endpoint APO, will help you quarantine the risky endpoints."
"The technical support has room for improvement."
"The platform’s GUI could be the latest."
"The solution needs to improve the graphical interface. And they had a limitation in some of the sensor modems as well."
 

Pricing and Cost Advice

"The price of Kerio Control could be better, it is a bit overpriced compared to other solutions."
"The biggest advice that I could probably give people is when you buy the solution be prepared to either buy the unlimited license or buy more licenses than you think. Each user license gives you one employee and each a user gives you five devices. In the world nowadays where everybody has a cellphone, tablet, desktop, and laptop, that's four devices. You still get one more device per person. That covers your servers and back-ends."
"KerioControl's pricing is good."
"Pricing is good, but the licensing took a lot of time."
"GFI has made a stupid decision regarding small office licensing. For offices where there are only three to five employees and had five years towards a five user product, they now force these customers to a 10-year user license. I really don't understand it. It's a stupid decision for the small offices who want a good solution for security because they'll probably decide to go to another product. Why should they buy something that they don't use?"
"The price of the solution is reasonable. For additional costs, you can add on more features such as antivirus."
"We have to pay approximately EUR 175 for the product."
"I think it is a bit on the pricey side, but it's okay. I've got 50 licenses which I think is $250 a year or something like that."
"The tool is competitively priced."
"I rate the product’s pricing an eight out of ten."
report
Use our free recommendation engine to learn which Intrusion Detection and Prevention Software (IDPS) solutions are best for your needs.
881,384 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
18%
Comms Service Provider
8%
Manufacturing Company
7%
Media Company
7%
Manufacturing Company
13%
Computer Software Company
10%
Comms Service Provider
10%
Financial Services Firm
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business44
Midsize Enterprise9
Large Enterprise3
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise6
Large Enterprise6
 

Questions from the Community

What is your experience regarding pricing and costs for KerioControl?
KerioControl offers good pricing as one license covers all features needed without extra payment. The price for the product is rated as ten out of ten.
What needs improvement with KerioControl?
Regarding KerioControl's application awareness and control feature, I have not used it much.
What is your primary use case for KerioControl?
With KerioControl, we usually use them for site-to-site VPNs for most of our clients. With multiple offices, we use KerioControl as our solution.
What do you like most about McAfee Network Security Platform?
The threat intelligence updates are very accurate.
What is your experience regarding pricing and costs for McAfee Network Security Platform?
The tool is competitively priced. I rate the pricing a six out of ten.
What needs improvement with McAfee Network Security Platform?
Trellix Intrusion Prevention System does not provide virtual patching. Patching involves updates on the OS side to address vulnerabilities, which is a different functionality. Trellix Intrusion Pre...
 

Also Known As

No data available
McAfee Network Security Platform, McAfee NSP, IntruShield Network Intrusion Prevention System, IntruShield Network IPS
 

Overview

 

Sample Customers

Triton Technical, McDonald's
Desjardins Group, HollyFrontier, Nubia, Agbar, WNS Global Services, INAIL, Universidad de Las Américas Puebla (UDLAP), Cook County, China Pacific Insurance, Bank Central Asia, California Department of Corrections and Rehabilitation, City of Chicago, Macquarie Telecom, Sutherland Global Services, Texas Tech University Health Sciences Center, United Automotive Electronic Systems
Find out what your peers are saying about KerioControl vs. Trellix Intrusion Prevention System and other solutions. Updated: February 2026.
881,384 professionals have used our research since 2012.