What is our primary use case?
We use it for firewall management and security management, firewall health, and processing firewall change requests.
How has it helped my organization?
Firewalls are very complex, and FireMon allows us to identify a firewall rule that may have a lot of sources, destinations, and paths, and identify various high-risk ports and high-risk situations that either shouldn't be implemented or need to be rectified prior to implementation.
It has not really saved us time yet because there is still some pretty significant manual intervention involved. We haven't implemented it on all firewall types yet because we have hundreds and hundreds of firewalls that do different things and because different firewalls have different risk conditions. But for the ones we have implemented it on, while it doesn't really save time, per se, it does provide higher visibility into high-risk situations, which were very difficult to identify before. As a result, it has decreased risk.
What is most valuable?
The most valuable features are the security assessments and the ability to identify unused rules or objects.
The real-time compliance management, in general, is also pretty good, as is the cleanup of firewall rules in a large, enterprise environment.
What needs improvement?
It doesn't yet handle our firewall brand very well and some of the complexities that exist in a very large organization like ours. For example, it doesn't handle network address translation very well for cleanup and it doesn't handle nested objects very well for cleanup. It does unused-firewall-rule cleanup pretty well, but we have had to do some extensive modification because it sometimes gave us false positives. It would identify a firewall rule as unused when it really wasn't unused, due to the nature of how Palo Alto works and how FireMon works. That has required some manual workarounds.
I also wouldn't say the solution automatically warns before new firewall rules, or changes to existing ones, violate compliance policies. Not totally. When a change request comes through, it runs through the FireMon process and if it is a high-risk situation, FireMon will flag it. It then requires manual intervention or manual evaluation or correction. Other than that, we work from a monthly audit report that runs to flag any rules that are high-risk. We want to streamline our operations and make them more effective and automated so that high-risk requests are filtered out and validated automatically or semi-automatically, prior to implementation.
We're working on automating the request process, but we're at a standstill right now because FireMon doesn't handle Palo Alto attributes very well yet. It's very Check Point-centric. We've had limited success with automating, as a result. They need to be able to handle Palo Alto firewalls better. For example, they don't do App-ID very well.
For how long have I used the solution?
I have been using FireMon for almost two years.
What do I think about the stability of the solution?
We've had some stability issues in the past with FireMon. We still have a few that they say are fixed in version 9.5. But we can't run version 9.5 yet because they took out the SNMP management and our ability to remotely monitor our FireMon instance. As a result, we can't put that version into production yet. They're putting that ability back. That's a feature that we absolutely require. We're not the only ones that require It. In talking with them, a number of customers have complained about that.
We've had some issues with file systems filling up because it identifies unused or unlicensed firewalls and it adds them to the list. It's trying to pull unused firewalls and that is filling up the file system and crashing the system. It still does that on version 9.3, but they say it's fixed in version 9.5.
What do I think about the scalability of the solution?
It's hard to scale FireMon. You have to add a lot more appliances or virtual machines to run the software and scale it appropriately. Because we're a worldwide organization, we've had to do a lot of that. We've had to split out our application servers and databases. We have three instances around the world and we're probably going to need to add more as we go forward, because it does have some limitations in how much it can process at any point in time.
It's also, in part, a Palo Alto issue because Palo Alto processing is very slow. So in the handoff between Palo Alto and FireMon, we've had some issues where FireMon doesn't always retrieve the configurations in a timely manner. When we run a report that is not necessarily running on the current data for all firewall rules, a firewall rule will suddenly be flagged as "not used," for example, when it really is used.
How are customer service and support?
In general, their tech support is pretty good.
I do have a concern with them, and I did express it to them already: Sometimes, it seems that when a new release comes out and changes take place, their development team doesn't always let the field support people know what the changes are. We have run into something on several occasions that caught the technical account manager off guard because he wasn't aware of it. It was only when we surfaced it that he realized it and said, "Oh yeah, that has changed and they never told me."
But generally, their technical support has been able to resolve issues. They're good, but I don't think they have enough expertise yet in Palo Alto.
Some of our requests are feature requests. We're working with them on a lot of those and they take more time. Some have to be put into a future release, and some are on their roadmap but haven't been pushed out yet.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
Before FireMon everything was manual.
How was the initial setup?
Our initial setup of FireMon was pretty complex, but we're trying to simplify things by choosing where we start. We're starting with some of our simpler, more straightforward firewalls. We haven't even gotten to the complex ones yet. It's a very slow process.
What was our ROI?
We haven't calculated ROI but the return when it comes to value is getting there. FireMon doesn't scale well enough with the complexity of our Palo Alto environment yet. I think the value will get there. We're at about the midway point when it comes to value. On a scale of one to 10, we're at about a four or five. On the simple firewalls, it works pretty well. On the complex firewalls, it kind of works, but there are a lot of exceptions that it doesn't know about or can't handle, and that causes us to have to backtrack into a lot of manual work.
What's my experience with pricing, setup cost, and licensing?
I don't see an issue with the pricing.
Which other solutions did I evaluate?
AlgoSec was one of the three other products we looked at. FireMon seemed to be a better fit for where we're going and what we're doing. It seemed to have more capabilities and features than some of the others did, features that fit our environment.
What other advice do I have?
If a colleague at another company were to say to me that firewall policy cleanup and management is important, but it's just not a priority compared to other more urgent items, I would say that firewall cleanup is pretty subjective. We think it's important because if you don't clean things up it leaves potential holes where vulnerabilities can come into your network. I would tell them it ought to be a priority.
In a small organization, I think FireMon would be absolutely fantastic. Just be sure you do a good job of documenting your use cases in terms of the scalability you need, before you talk to FireMon. You need to be clear with FireMon about what kind of scale you need to be able to scale up to.
When you get into an organization like ours, with hundreds upon hundreds of firewalls for different purposes, our firewalls don't line up in a linear fashion. It's not a case of "more of the same, more of the same," when it comes to our firewalls. They all have their own risks and nuances, their own rule sets, and their own security implications. Our firewalls have multiple paths through them and FireMon falls short a little bit because it's not Palo Alto-centric.
I don't think FireMon has kept up with where Palo Alto is at. They started out being Check Point-centric for years and they've never really fully embraced the nuances others, like Palo Alto or Fortinet, have. They don't handle a lot of the capabilities and attributes that Palo Alto does yet. They're working on it. They're getting there.
We have an open issue list that we are working through with FireMon little by little, including things it doesn't do well. We meet with a technical account manager on a weekly basis. Of course, we're not their only customer, so we can't dictate what they do or don't do regarding Palo Alto, but we're making our concerns known.
We've had to customize a lot of the security. Their out-of-the-box risk situation was too restrictive in some areas and not restrictive enough in others. So we have had to tailor the risk conditions by firewall type and create custom risk reports by firewall type, because not all our firewalls are the same.
Which deployment model are you using for this solution?
On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.