Try our new research platform with insights from 80,000+ expert users
it_user588591 - PeerSpot reviewer
Enterprise Security Architect at a insurance company with 1,001-5,000 employees
Vendor
The normalization of the rule sets across different firewall platforms is valuable. Version 8 wasn't ready for prime time.

What is most valuable?

Holistically, the product is well thought out. The normalization of the rule sets across different firewall platforms is all valuable to us. You can't really separate it out; for me, you can’t.

How has it helped my organization?

I can mention high-level stuff. Basically, it gives us visibility that we were lacking; having everything being able to be viewed in one pane of glass. Instead of having to go jumping all over the place into the different platforms, you can use the tool to get a single pane of glass view.

It's not a jack-of-all-trades product; it's very focused. It does what it does and it does it well. We use it that way. Basically, that's the reason we obtained it. That's what we use it for: to normalize the platforms all into one single view. A place for us to do our analysis, review of rules and things of that sort.

What needs improvement?

I can mention a ton of areas with room for improvement, but from a high-level standpoint, I just don't think version 8 was ready for prime time, yet. They're still working on it. There are still major swaths of the tool that need attention. To get into the details, I would have to engage my engineers.

For how long have I used the solution?

We've had it in our portfolio since July of 2013.

Buyer's Guide
FireMon Security Manager
February 2025
Learn what your peers think about FireMon Security Manager. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.

What do I think about the stability of the solution?

We have not encountered any stability issues with the product itself. It's been easy to maintain, to upgrade and to do all of the support work for it. There hasn't been an issue with that at all.

What do I think about the scalability of the solution?

We have not encountered any scalability issues. We haven't run into a limitation yet.

How are customer service and support?

Any time we've engaged technical support for assistance, we've come away with a resolution, so the only thing that we've had difficulty with is programming or making fixes that require coding. That sometimes can take a little while.

Technical support is at least 8/10.

Which solution did I use previously and why did I switch?

We did not previously use a different solution. This was the first firewall management platform that we've used, except for the built-in, out-of-the-box tool that came with the platform.

How was the initial setup?

Initial setup was all pretty straightforward. You stand up your platform, get your database ready to go, and that all happens out of the box. Then, you start to populate it with your devices. It's all pretty straightforward.

Which other solutions did I evaluate?

Before choosing this product, we also evaluated Tufin and AlgoSec.

What other advice do I have?

Just like any other IT product on the market today, everything is green grass and high tides. Everything is beautiful. During the sales process, it's all, "Oh, just do this, do that." It's a little more than that. It's a little more complex and a little more effort than just, plug it in and go.

I think that's the mistake of many of the sales teams; that they sell the ease of implementation. I think they should just be straight up and honest with the purchaser, saying, "Look, it's going to take some effort and you're going to have to understand your environment. You're going to have to understand the network flows. You're going to have to understand how your network is segmented, so you can properly implement the tool."

I think when they try to make it seem easier than it really is, then that's inviting problems.

FireMon is just better than average. It's better than average, but not quite stellar yet. They've got a little work to do to address some of the challenges that could be introduced perhaps by the customer and the way the customer has used the different platforms. They have to be able to account for that, and react to it in a timely manner; at least come up with some sort of usable solution in the meantime when they do encounter a problem.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user630399 - PeerSpot reviewer
it_user630399FireMon Customer Success Manager at FireMon
Real User

Thank you for providing your detailed feedback on FireMon Security Manager. We truly appreciate the investment of your time to post a review.

In regards to your statement about FireMon version 8, not ready for prime time, there have been quite a few version 8 revisions released to address stability issues and improve performance. The most recent version released is FireMon 8.15. Hopefully your organization has the latest version installed to take advantage of the performance improvements and new features.

it_user616515 - PeerSpot reviewer
Sr Network Security Specialist at a government with 1,001-5,000 employees
Vendor
The most valuable features are the reporting for change control as well as rule utilization.

What is most valuable?

The most valuable features are the FireMon reporting for change control as well as rule utilization.

How has it helped my organization?

It allows us to do utilization and cleaning of our policies. For your firewall, you have a series of rules and stuff that identify traffic, sort of whether or not the rules within your firewall policy are actually being used; what part of the rule is being used; whether or not it's identifying issues. You've got 1000 rules and only 900 are actually being used. About 100 of them are not.

We're now getting hit counts within Check Point that give us that information, but sometimes a rule says that it has been hit a lot even though it's not all the services within that rule. So it allows us to edit, modify and clean in order to remove anything that's not used.

What needs improvement?

I would say the most recent release caused us a lot of trouble as we couldn't get it working for a while, so we weren't getting the reports that we wanted, but it has improved. It's just very, very different. The most recent release level was dramatically different.

Maybe better videos or whatever could be included as to how to work with the updated product.

For how long have I used the solution?

I believe it's going on about five years, maybe as much as six.

What do I think about the stability of the solution?

When we transferred from one release to the next, the most recent upgrade, the integration with Check Point gateways was very poor and so it was for almost a year that the product was unusable to us.

What do I think about the scalability of the solution?

I think the scalability seems fine, although not all of our gateways are licensed so that in itself also caused some issues, because the product had to be more tuned to the fact that our environment doesn't utilize FireMon for all of its gateways.

How are customer service and technical support?

I would say technical support is about 8/10. Some issues just weren't handled quickly enough, I guess.

Which solution did I use previously and why did I switch?

We previously used an earlier release of FireMon and they had good success with that. In the newest release, we had a lot of problems. Prior to that, we really didn't have a tool to do that type of analysis for us. Although the most recent releases from Check Point have given us better analytics within our environment, FireMon has provided us with a better view into our environment. We didn't have anything prior to that.

How was the initial setup?

I haven't really been involved much with the licensing. It seems fairly straightforward. Regarding the training after setup, I find the videos maybe could be a little bit better in respect to how to work with your FireMon product to get the best out of it; so maybe some better training videos on how to work with the product.

Which other solutions did I evaluate?

I believe the only other option I looked at was Check Point's reporting option and it was quite costly.

What other advice do I have?

When using this product, you have to spend time understanding not only how it was installed but what information you can get from the product. The customization of reports, whether they can be automated or on demand. So just getting a better understanding of what you can get from the application is useful.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user632862 - PeerSpot reviewer
it_user632862Technical Account Manager at a computer software company with 201-500 employees
Real User

Thanks for your review and feedback. The changes in our products from Version 7 to Version 8 were significant and many customers asked for help making the transition. Not only did we move from a client-based to web-based user interface, we focused much of that UI on metric Dashboards with Key Performance Indicators (KPIs) and drill-down capability to explore those KPIs. One of our responses to the demand for help transitioning to Version 8 was to add a free, online, instructor-led Post-Migration training course available to all customers following their migration. Hopefully, you have been able to avail yourself of that training. If not, you can get more information from our User Center - along with links to topic videos.

Buyer's Guide
FireMon Security Manager
February 2025
Learn what your peers think about FireMon Security Manager. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
it_user617388 - PeerSpot reviewer
Works at a financial services firm with 1,001-5,000 employees
Vendor
We use the forwarding capabilities and we use it for cleanup.

What is most valuable?

We use the forwarding capabilities because we don't have another way to report on the firewall. We use it for cleanup and also for our biannual firewall review. Pretty much that's the big reason that we use FireMon.

How has it helped my organization?

The time that it takes for us to do the review: Previous to FireMon, we would have to go through the firewall pretty much manually, every line. This took an incredible amount of time. With the FireMon product, we did notice a significant decrease in the time that it takes for us to do any type of review. Also, just a general report, if you have an inquiry throughout the year, without actually doing a full review, you can just go to FireMon and click a few buttons and it tells you what you need to know. There's no need to dig around and spend additional time. So, it's mainly time.

What needs improvement?

We've had issues with backups. We almost lost our database at one point. It would be nice to be able to back up the backup configuration to a network share or some other function. The only way that we know how to do it right now is to do a manual backup. Or the server backs itself up to itself, which is not helpful. If you lose the server, the backup that's stored on the server is also lost. So, it's not that helpful.

One thing that is missing is the ability to export the entire rule base of a firewall. Suppose we were going to be migrating to a different firewall. Not getting rid of FireMon, but moving to a different firewall; either a different vendor or a different model of a firewall. So instead of taking bad stuff, or maybe old stuff out of the current firewall and going to a new firewall and using the exact same configuration, we may want to export that information into an Excel spreadsheet or some other format, so that we could work with that data outside of FireMon. That would be really helpful. I've called FireMon, I've also played around trying to figure out if I could get it to work and I still didn't get it. Nobody knew how to get the info out of FireMon to work on it. Also, potentially the ability to import it back into the system and maybe get some sort of a diff report; a difference of the configuration from the system.

For how long have I used the solution?

I have used FireMin for about four years.

What do I think about the stability of the solution?

We have an issue sometimes with the listener for logging. Sometimes the listeners, the ports, go down and the server has to be rebooted. It's very, very rare that that happens, but we have noticed that's really the only stability issue that we've had. The server application itself seems to be very, very stable. Even when the port goes down, the app stays up. It just has to be reset. That may be every three months or so we may notice that.

What do I think about the scalability of the solution?

We have three major production firewalls pushing thousands of logs every hour to this one box. We have two boxes in both of our data centers but they push a lot of logs to these guys. We've never had any issues.

How are customer service and technical support?

I would rate support a 4/5. I sort of get the feeling when I send an email that it's a little bit of a slow response time. There are things that we do need immediate attention on and sometimes when you call, they'll ask you to send an email in. That's sort of a backwards approach to technical support. If I've already got somebody on the phone, they should be able to take my information and proceed with handling the triage of the call. I shouldn't have to hang up the phone, write an email, and then wait for a telephone call back from them. I would rather see some sort of support model that has a better flow to it.

Which solution did I use previously and why did I switch?

Previously, we did not have a different solution.

How was the initial setup?

Setup was fairly straightforward. Our system is in a virtual environment. We pretty much turned logging on for the firewall, pointed it to the FireMon server, added the firewall to the FireMon server. Within seconds, there were tens of blocks being pushed over there. The reports pretty much created themselves. You just had to run them.

What other advice do I have?

If someone asked me for advice, I would definitely say that it would help them, especially with being able to navigate through if you have a complex rule set. I would definitely suggest FireMon. It's been extremely helpful for us to have. Even though they're missing a few functions, it's still workable from our standpoint.

Being able to export to Excel isn't a huge turnoff. It's a nice feature to have but I would definitely suggest purchasing FireMon. Especially if you have a large environment where you're trying to trim down your rule base, you're trying to optimize your firewall, or you're just trying to find stuff that's sort of lost in your configuration.

Also change management: I believe it's a PCI requirement. We use FireMon as well for notifications and that's helped satisfy a PCI. I don't have anything in front of me that shows me all the requirements but I believe a review of rules that are changed is part of that requirement, so they help fulfill that, too.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user630399 - PeerSpot reviewer
it_user630399FireMon Customer Success Manager at FireMon
Real User

Thank you for providing your detailed feedback on FireMon Security Manager. We truly appreciate the investment of your time to post a review.

To address your "Room for Improvment" comments:

The FireMon backups are placed in /var/lib/backup. This can be configured to be an NFS mounted file system from an external host. This would satisfy your desire for having backups placed on a network share.

The entire policy for a device can be exported to an XLS file from the | Policy | Policy View tab in Security Manager. The resulting XLS file will have separate worksheets for the security rules, network, objects, user objects, application objects, etc…

Please let us know if there is anything we can do to help you better utilize FireMon.

it_user613533 - PeerSpot reviewer
Sr. Systems and Network Engineer at a recruiting/HR firm with 1,001-5,000 employees
Vendor
The most valuable feature is more or less the ability to look for the shadowed-based rules or rules that are being used.

What is most valuable?

The most valuable feature is more or less the ability to look for the shadowed-based rules or rules that are being used, and also for change management, i.e., getting alerts from the system. This helps us to determine who is making the changes and have that historical information to give back to our auditors and say, "Okay, these are the changes that we've made and these are the corresponding service tickets that apply to them."

The ability for spotting the shadowed-based rules helps us to eliminate overlapping rules that may not be otherwise needed or maybe under-used. It helps us to identify that stuff and gives us the ability to go back and audit the firewalls.

On the whole, it gives us the ability to determine what our security architecture looks like, so as to help secure our company better.

How has it helped my organization?

It's kind of a two-fold type thing for us. We were in the middle of a project, where we were migrating from one set of firewalls that were old to a newer set. So, this tool has allowed us to go through and identify rules that we could get rid off and allowed our rule sets to be a lot smaller than we originally had intended them to be. This helps us with our ongoing maintenance of our firewalls, so as to understand what's being used and what's not.

It helps us to just do a research into what rules are already in place, so that way we don't have to add anything and it is a quick lookup for us. Instead of having to go through maybe 10 different firewalls, we can easily trace through our network and say, "Okay, it has to touch each one of these firewalls and these are the rules and this is maybe where it's blocked at." This is a feature that we like to use and it helps us save time.

What needs improvement?

So far, we're not too much into the product yet. However, we're not really liking the web interface. We enjoy the so-called fat client a lot better because it just gives a bit more of the opportunities to work with the software faster, whereas there's been a huge learning curve for us to use the web interface. Then, we also have to learn their query language or define the details that we need.

Unfortunately, we are such a fast-paced environment that we don't have a lot of time to spend with the software to really learn it the way it probably should be learned. We have to kind of go back and reinvent it every single time we have to go look for something in particular. That's the only downside I can mention that we're having with the GUI.

For how long have I used the solution?

It's going on for at least three years now, if not more.

What do I think about the stability of the solution?

There were a few issues with stability initially, but luckily FireMon is very supportive in terms of their support staff. They have been able to identify the issues that we've been having, and in turn implement some kind of compensating mechanism or come up with a solution in order to fix it, so as to help us resolve our issues. Overall, we've been pretty happy with the support team.

What do I think about the scalability of the solution?

We have not had any scalability issues and I've been very impressed in that aspect. At one point, we had a single server and we overloaded it pretty quickly, with the amount of logs that we sent to it. The firewalls generate a ton of traffic as far as syslog goes. So, I had to out-size our environment to compensate for the additional logs and had to deploy to a couple of other different sites, that initially we didn't imagine having a need for. However, it scaled up great and we've had no issues with it since then.

How are customer service and technical support?

Overall, I would give the technical support team a 10/10. There have been maybe a few issues, here and there. Unfortunately, it has taken some time for them to resolve and it goes back to them, i.e., asking for updates, and working with myself and the team to understand what issues we're having. They try to help us resolve issues either through training or going back to the development team and asking for a feature.

Which solution did I use previously and why did I switch?

We didn't previously use any other solution. This was definitely one of the best of its breed that we researched. Eventually, this tool is what we selected to go with.

How was the initial setup?

The setup was pretty straightforward. It was just a matter of pointing the logs to the device and setting up a few basic things, so that it could go out and fetch the configurations/settings. Thus, it was relatively easy.

Which other solutions did I evaluate?

I believe the other option that we looked at was Infoblox and maybe one other tool. However, Infoblox was just too cumbersome and didn't offer a lot of features. In comparison, we felt that FireMon had those out-of-the-box features built-in.

What other advice do I have?

Definitely, you should look into how many syslogs you're getting because there is a limitation on how many syslog messages it can handle per second. We felt in a more distributed environment, it allowed us to support our network more adequately. So even with our main data centers, we had to usually have three or more collectors in order to deal with the amount of syslogs we're sending. We also had to include a few different offices needing their own implementation of data collectors.

This company does a pretty solid job and they're always constantly wanting to improve their products.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
SecArch3081 - PeerSpot reviewer
SecArch3081IT Security Consultant and Platform Architect at a pharma/biotech company with 10,001+ employees
Real User

Policy Test is extremely useful, as well--we use that constantly in request design phase to quickly identify zones and policy placement. Object search/Omni search is invaluable, as well, providing the ability to find all the rules that may need updating when a server migrates or is decommissioned. it would take forever to manually retrieve and search across hundreds of firewall configs.

See all 2 comments
it_user642174 - PeerSpot reviewer
Information Security Officer at a university with 10,001+ employees
Vendor
The ability to audit our firewall rule base allows us to determine which rules can be removed.

What is most valuable?

The ability to audit our firewall rule base is my favorite feature. It allows us to determine which rules can be removed and it helps us reduce our security footprint.

How has it helped my organization?

Over the past two years, we have been able to identify a bunch of rules that were orphaned and no longer have any need.

These rules were exposing our organization to undue risk associated with devices being exposed to the internet that shouldn’t have been exposed.

We use the feature to identify some rules that were no longer needed. That helps us reduce our overall, organizational risk profile.

What needs improvement?

What's funny is that if I had been asked eight months ago about areas with room for improvement, I would have said the product in general needed to be improved. It wasn't web-based. It was client-based and it was just kind of clunky.

In the last eight months since we upgraded to the web version, there isn't a lot of need for improvement. I feel like it is pretty good. Things have been a lot better for us since we upgraded to the web version. I'm happy with it right now and I don't have any complaints.

For how long have I used the solution?

We’ve been using this solution for just over two years.

What do I think about the stability of the solution?

We haven’t had any stability problems. I had one or two minor issues since the upgrade, such as upgrade failures. I couldn’t get the system to accept a maintenance release. Those issues were resolved pretty quickly. There have been no stability issues, nor long-term outage issues.

What do I think about the scalability of the solution?

We have a fairly limited amount of systems that are monitored by FireMon. Our box can support up to 20-25 devices. We only have eight devices to monitor. We still have a lot of overhead. We haven’t noticed any slowdown issues or any problems of a scalable nature on the device.

How was the initial setup?

Back then, it was client-based and the setup was not so straightforward. Most things worked well right out of the box.

Although I haven’t done an actual setup after it became web-based, I can see that it is much easier. You don’t have to download a client. You just have a website. There is no need for a command-line configuration to get it up and running. It was fine for overall level of difficultly before and I can assume it is easier now.

Which other solutions did I evaluate?

We did not evaluate other options. This was the first of its kind. I saw it at a vendor/expo demo and I was interested in it.

Our vendor that we work with threw it into a deal. We paid for support and they were trying to increase the overall install base footprint. They made a couple deals with us for a next generation firewall. I wasn’t budgeted to purchase it, but it was part of a deal, and it fell into our lap for next generation firewall monitoring.

What other advice do I have?

FireMon is a very good product; is a slippery slope in terms of deployment. It can monitor all of your network devices and firewalls. I would imagine a lot of people probably use it for that.

We are a small organization. From a cost and work standpoint, we only wanted the ability to audit and manage our firewall rule sets. It’s been good for us in that way.

People need to think about what’s important to them based on a monitoring point of view, which is regulation-based. That wasn’t an issue for us. I recommend that people considered the best-sized solution for them. Give it a try. It’s worked well for us.

I would rate it as the best firewall monitoring platform that I’ve used, but I’ve only used FireMon.

We are a Palo Alto customer and this is a great tool to augment the Palo Alto tool set. It’s a very beneficial product. It fills the gap of things you can’t get with standard Palo Alto management, such as long-term analysis and knowing what’s really going on with objects and rules in the firewall rule base.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user620586 - PeerSpot reviewer
Works at a financial services firm with 501-1,000 employees
Vendor
The Security Manager is the most valuable feature. It's been pretty stable.

What is most valuable?

The Security Manager is the most valuable feature.

How has it helped my organization?

It helps us eliminate rules that are not needed on the firewall and to consolidate them. It saves us a lot of time and makes my work easier.

What needs improvement?

Make writing the reports easier. There's a lot of canned reports and if you want to write a specific report that you're interested in looking at, it's rather hard because I'm not a programmer. I don't know all the programming languages needed to do that. I can look at what reports exist and try to take that and kind of change it to something that I want to see and it doesn't always work. It's not real easy to do.

For how long have I used the solution?

I have been using FireMon for about six months.

What do I think about the stability of the solution?

It's been pretty stable.

What do I think about the scalability of the solution?

I have not had any scalability problems at all.

How are customer service and technical support?

We have called them and they've always been really helpful. They've resolved our issue in a timely manner. I would rate them a 4/5.

Which solution did I use previously and why did I switch?

We didn't have any other solution. This is the first of its kind.

How was the initial setup?

Setup was straightforward. The instructions were really simple. We put in the basic information and then they scheduled some time with us to go through the setup and walk us through each one of the screens, what they do, what to look for and things like that. They kind of gave a little bit of a training class or training session.

What's my experience with pricing, setup cost, and licensing?

They set a round of what we wanted to see. They didn't just come in and say, "Here's how it works", because different companies are different. Different companies want to use it in different ways, so they found out what we wanted and helped us set the training up to look at things that we want to be able to use it for. That was nice.

Which other solutions did I evaluate?

We didn't evaluate any other products.

What other advice do I have?

I think it's a good product. It's very stable. It's quick and it's easy to learn. It's easy to run reports. There are a lot of reports that you can run. That helps the management of your firewall.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
SecArch3081 - PeerSpot reviewer
SecArch3081IT Security Consultant and Platform Architect at a pharma/biotech company with 10,001+ employees
Real User

Be careful with the "clean-up" report recommendations. Firemon tends to recommend deleting the hidden or shadowed rules, but those are often the more restrictive (better) rules, shadowed by an overly permissive rule at the top. Consider removing the top rule, and keeping the more restrictive policies.

See all 2 comments
it_user448857 - PeerSpot reviewer
Security Consultant at a tech services company with 501-1,000 employees
Consultant
Rule comparison and filters are an easy way to check if you policy is concise and clean.

Valuable Features

The instant and complete network graphical view it provides is amazing. Alerts give you complete control of firewall changes, its amazing for compliance and security policy validation. Rule comparison and filters are an easy way to check if you policy is concise and clean, giving your firewall the best performance and readability.

Improvements to My Organization

We managed around 70 different firewalls in more than 25 countries all over the world. The firewalls were from different vendors such as Palo Alto, Checkpoint, Cisco, Juniper, etc. FireMon helped to decrease the workload on risk analysis and also firewall rulebase review time by 50%, at least due to its very elaborate and easy to use filters.

Room for Improvement

It’s been a constant need not only to analyze firewall rules and configurations but also implement them, for which FireMon has no support. Also some of the firewall analysis involve weak password policy, FireMon could implement a way to send firewall hashes, when they exist, to third party cracking softwares.

Use of Solution

I used this solution for about three years in my previous job. I primarily used the Policy Planner and Policy Optimizer modules.

Deployment Issues

The deployment was already easy for v7.0, the upgrade to v8.0 is even easier.

Stability Issues

We had no issues with the performance.

Scalability Issues

It's been able to scale for our needs.

Customer Service and Technical Support

I would rate it 8/10. The only reason I don’t rate it 10/10 is because of the response time which, for us, sometimes took a little bit longer then expected. Customer service and technical support is very good.

Initial Setup

The initial setup was very easy and straightforward and we had no problems implementing it.

Implementation Team

It was initially implemented by a vendor team, but the implementation could easily be done in house.

Pricing, Setup Cost and Licensing

FireMon is not a cheap solution but its price is well balance for what it has to offer.

Other Solutions Considered

We have evaluated FireMon’s competitors like AlgoSec and others, but found FireMon to be the best solution for our needs due to having a complete set of tools.

Other Advice

Be sure you read all the specs, and test the application as deeply as you can to ensure it meets all your requirements.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user586950 - PeerSpot reviewer
it_user586950Customer Success Manager at FireMon
Real User

Felipe, thank you for taking the time to write a review of FireMon. I am glad to see you are finding overall satisfaction with the product. Please feel free to drop us a note at customersuccess@firemon.com with any future questions or concerns.

PeerSpot user
Conseiller sécurité des TI at a tech services company with 1,001-5,000 employees
Consultant
It is possible to highlight differences between policy revisions.

What is most valuable?

  • The possibility to highlight differences between policy revisions
  • FireMon Insight with FMSQL
  • Hidden reports
  • Rule usage/unused rules report
  • Object usage report

How has it helped my organization?

FMSQL allows us to quickly query our ruleset to check which trafic is allowed. That greatly helps us to fill in the compliance report.

What needs improvement?

  • Support of checkpoint clusters: Rule usage is logged for each cluster member but not for the whole cluster. It may lead to wrong conclusions when you clean rules.
  • Comments with special characters (French accent) are not supported. So we can't use the report for uncommented rules.

For how long have I used the solution?

I have used it for >5 years.

What was my experience with deployment of the solution?

We first had FireMon 5 on Windows Platform. It was a pain in the ...

Now, with the FireMon appliances, you just have to connect your Check Point SmartCenters and ... enjoy!

What do I think about the stability of the solution?

I have not encountered any stability issues because we purchased Linux appliances.

What do I think about the scalability of the solution?

We have quite a large Check Point environment (>60) with a lot of rules. Reports may be a bit slow but they are so valuable that they are worth the wait. Newer, beefier appliances may also be available from FireMon.

How are customer service and technical support?

Customer Service:

I don't have to deal with customer support, so I won't rate them.

Technical Support:

With Windows, it was difficult to get support.

I only had to open once a ticket with the FireMon appliances; fast handling of the case.

Which solution did I use previously and why did I switch?

I did not previously use a different solution.

How was the initial setup?

Initial setup was quite simple.

What about the implementation team?

I was not in charge of the implementation project. I think we installed the FireMon appliances on our own.

What was our ROI?

I'm not an accountant !!

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user632862 - PeerSpot reviewer
it_user632862Technical Account Manager at a computer software company with 201-500 employees
Real User

Thanks for your review and feedback. FireMon re-architected our Version 8 with scalability and better performance in mind, so faster reporting should be attainable. As you suspected, we do have newer, beefier appliances available. But the most significant performance and scalability impact comes from horizontal scaling and a more distributed architecture availability in Version 8.

Buyer's Guide
Download our free FireMon Security Manager Report and get advice and tips from experienced pros sharing their opinions.
Updated: February 2025
Buyer's Guide
Download our free FireMon Security Manager Report and get advice and tips from experienced pros sharing their opinions.