Try our new research platform with insights from 80,000+ expert users
SrAdvisof832 - PeerSpot reviewer
Senior Adviser Cyber Security at a comms service provider with 10,001+ employees
Real User
It's pretty useful when you have an audit going on, but I don't like the way the reports are shown
Pros and Cons
  • "It provides a great visibility around the roots: Root implementing which can be done, roots that have changed, and what has been done. So, it's pretty useful when you have an audit going on."
  • "I would rate their reports as a four out of ten. I don't like the way that they are shown. It is too hard to export and send them to our clients."

What is our primary use case?

We use it for advanced reporting and root analysis. In some cases for clients, we use it for root deployment. 

How has it helped my organization?

Some clients wanted to have more latitude with root deployment. Instead of deploying through us every time, they want to deploy a new root, making quick roots or small roots, like adding an object to a root. They now have the possibility to go direct.

It has helped our clients to meet their compliance mandates. They will ask us for evidence that we can provide them.

What is most valuable?

The analysis is the most valuable feature. People see it first and that is why they want in their enterprises, then they start explore the other features.

It provides a great visibility around the roots: Root implementing which can be done, roots that have changed, and what has been done. So, it's pretty useful when you have an audit going on. 

What needs improvement?

I would rate their reports as a four out of ten. I don't like the way that they are shown. It is too hard to export and send them to our clients.

We are switching to AlgoSec. It's a corporate decision. There's probably room for improvement. 

Buyer's Guide
Tufin Orchestration Suite
December 2024
Learn what your peers think about Tufin Orchestration Suite. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
830,455 professionals have used our research since 2012.

What do I think about the stability of the solution?

It is pretty stable. We have more issues with the VMs than with the software.

What do I think about the scalability of the solution?

We have not had any issues with scalability. When we needed more power, we just added a new server, and that was straightforward. So, it is pretty scalable. 

How are customer service and support?

I have not personally used Tufin's technical support.

How was the initial setup?

The last time that we initialed setup, it was straightforward. 

If you want to install a new root automatically using the tool, the change impact analysis capabilities are useful.

What about the implementation team?

We deployed it in-house. 

What was our ROI?

This solution helps us to reduce the time it takes to make changes (by 10 to 15 percent).

Which other solutions did I evaluate?

We are going to keep Tufin as is, but we are going to add AlgoSec. The prices are comparable. We have corporate pricing with AlgoSec. The ease of use of AlgoSec is one of the reasons why we considered using it.

What other advice do I have?

You need a product like this, but look at difference solutions in the market. I would rate it a seven out of ten.

We do not use the product across our entire network. We do not use the cloud native security features.

In the future, we will use the solution to check if a change request will violate any security policy rules.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user489210 - PeerSpot reviewer
Security Engineer at a healthcare company with 1,001-5,000 employees
Real User
It can look at specific metrics across technologies. We would like the ability to correlate it with other toolsets

Valuable Features:

Policy management.

Improvements to My Organization:

It understands my need to make sure that there are specific metrics that we are looking at and with those seeing across our technologies, as opposed to just a vendor technology building reports. It's easier for us.

So far, with the asks that have been requested, we have been able to find the metrics we need. 

Room for Improvement:

My suggestion would be to be able to correlate it with other toolsets, and not just have it contained in their own toolsets. I’d like to be able to extract it so it can be consumed by other tools, like a governance tool such as GRC2, Archer, and by algorithms. It should not be contained in their environment. Let them perform their functions, but allow me to absorb others and use other governing tool sets to take a look at your metrics.

I’m rating it a seven just because I don't think I'm using the tool at its full functionality yet. It's meeting my current needs, but I don't know what the future use cases would be. So I can't say it's a ten, yet, but I'm moving towards ten. So, I start with a five as I use its functionality as meeting my needs. It will grow, I have confidence.

Deployment Issues:

The speed is good. As we continue to upgrade the software, I've been keeping up to date. Every version that I install, I see some improvement on the speed actually. So far so good.

Stability Issues:

I haven't had any issues. Even though my interaction has not yet provided me with a full understanding of whether it's stable or not, I have been interacting with the tool enough to determine whether there are any stability issues.

Other Advice:

If the tool meets your needs, evaluation process wise, then you should make sure that you reap the benefits. It has a lot of functions, and a lot of benefits and features. Start using them all.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Tufin Orchestration Suite
December 2024
Learn what your peers think about Tufin Orchestration Suite. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
830,455 professionals have used our research since 2012.
it_user488118 - PeerSpot reviewer
Security Engineer at a financial services firm with 10,001+ employees
Real User
Policy analysis is the product’s most valuable feature.

Valuable Features:

Policy analysis is the product’s most valuable feature. It can pull out various rules that we need to work on, edit, update, and so on. It can identify rules that need to be moved, or need to be optimized.

Improvements to My Organization:

Tufin analyzes tens of thousands of rules for us. Not all one firewall, but there's thousands and thousands of rules that Tufin analyzes.

Reporting is great. The only issues that we ever run into are with usage reports. You can run into things where something will have been modified and it ends up changed or something like that. Other than that, reporting is great.

Room for Improvement:

The capabilities Tufin has for Check Point products are excellent. It'd be nice to get the same level of features that it does for Check Point up to par with Cisco, Palo Alto, and so on. There's a couple of things that are lacking. For example, on the Palo Alto side, if you're using a lot of layer 7 rules, there's very little visibility into that. When you run policy analysis, you're still only getting back source IP, dest IP, ports. It's not showing the URLs, all that kind of stuff. That's the main thing.

The only other thing I could see being improved would be regarding one bug. Once in a while when you save a policy analysis query and you click save, it goes back to the screen where it lists them all. Someone else's will be there, and it's somehow swapped them with another engineer who was saving something at the same time. It doesn't happen often, but when it does, it's annoying. Especially if you've just entered a whole lot of info into it.

I’m rating it an 8 because of a couple of those little nagging features, the little bugs. But by and large, it does the job that we need it to do at the moment. We're going into the new world of SecureChange. We'll see how that goes, too.

Stability Issues:

In our previous configuration, it would take a beating. It would take days to get certain reports out of the system. We've just purchased a whole bunch of new hardware, and Tufin’s been a lot more stable. I'm getting reports again very fast.

Other Advice:

Based on looking at some of the other products out there, Tufin is definitely the leader of the pack. It's a good choice. Make sure you buy enough hardware, and make sure you know how you're going to use it. A lot of the features get very processor- and database-intensive, and you should have the proper gear to use it.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user475923 - PeerSpot reviewer
Security Engineer at a retailer with 10,001+ employees
Vendor
The best feature is being able to query all our devices to find unused rules and objects and then clean them up.

Valuable Features:

The best feature is being able to query all our Check Point devices and certain other vendors like Fortinet as well. It can query and find unused rules and unused objects to clean things up for us.

I use reporting and assistance as a tool for cleanup. I would love to be able to get the newest version into our company and have it be used as a manager of not only Check Point but also the other vendors that we use. It looks like it's all there. - Fortinet, Palo Alto, some Cisco and other devices.

The fact that that we won't have to log into a Fortimaneger to manage Fortinet and then log into another to do Check Point, being able to log in straight to Tufin, build a rule and have it push it to the correct devices. That's huge and that's something that I really like about the new version.

Stability Issues:

We had some issues because of our unique configuration.

Scalability Issues:

I can't say too much about scalability, simply because it was not scalable for our environment because we are using a splintered specialized version just for our company. The Tufin apliance just doesn't play well with that specialized version. But for the things that we do have that are general release, it's awesome. It takes a little bit of a fiddling around but again, we're on an older version. It works flawlessly.

Other Advice:

Rating: because it's our unique older version, I'd give it a 6 or 7 but we only use it for reporting and cleanup. If we had the latest version, I'd easily give it an 8 or 9 because it can do so much more.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Network Infrastructure Engineer at Ropes & Gray
Real User
Easy to set up and use with helpful alerting on rule changes
Pros and Cons
  • "The most valuable feature is alerting, which lets me know when someone has made a change."
  • "I would like to see visibility into the FW features like IPS/Content Filter policies, the same way it does for FW rules/policies."

What is our primary use case?

We use this solution for Firewall audit, compliance, and some automation.

How has it helped my organization?

Using Tufin makes it easy to visualize when investigating or auditing configs.

What is most valuable?

The most valuable feature is alerting, which lets me know when someone has made a change. When something stops working I can see what has been done and by whom.

This solution is easy to set up and use.

It is very easy to see what has changed when comparing two different revisions.

What needs improvement?

I would like to see visibility into the FW features like IPS/Content Filter policies, the same way it does for FW rules/policies.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Networki9624 - PeerSpot reviewer
Networking Engineer at a comms service provider with 1,001-5,000 employees
Real User
Handling firewall rule request tickets are more centralized and easier to manage, but its cloud-native security features are lacking in support
Pros and Cons
  • "Tufin has made handling firewall rule request tickets more centralized and easier to manage."
  • "I would like the application to have faster response times. E.g., the dashboard may take up to two minutes to load. Or, when we do the topology seating its two and a half hours. I would like to get those times down and increase the efficiency of the product there."

What is our primary use case?

The primary use case is tickets.

How has it helped my organization?

Tufin has made handling firewall rule request tickets more centralized and easier to manage.

We have previously use Tufin to clean up our firewall policies, but we are not doing that currently.

What is most valuable?

The workloads are the most valuable feature right now, as it stands.

We find that the change workflow process is flexible and customizable. We change our workflow several times a year.

What needs improvement?

The visibility is good for the most part, but there are limitations to it. E.g., there is a lack of certain routing/networking protocols across all the vendors that they support.

The solution is not sophisticated enough for us to automatically check if a change request will violate any security policy rules.

Tufin's cloud-native security features are lacking in support.

I would like the application to have faster response times. E.g., the dashboard may take up to two minutes to load. Or, when we do the topology seating its two and a half hours. I would like to get those times down and increase the efficiency of the product there.

I would like more support for Juniper and Junos Space. I would like more of the features which are offered for other platforms being extended to the Juniper platform.

The USP needs improvement. It is pretty much not usable right now for us. It is all IP-based. The issue with that is we may have one subnet, but we have multiple things that would go in different zones all in that same subnet. Therefore, to use the USP, we would have to bring it out in tons of /32s, and it's not usable. Whereas, it would be far better if we could just put tags associated with IPs, then do USP based on tags.

What do I think about the stability of the solution?

In the sense of operating, the stability is good, but in the sense of performance efficiency, it is bad.

What do I think about the scalability of the solution?

The scalability is bad.

Which solution did I use previously and why did I switch?

We did not have a previous solution that we were using. We were looking to work towards improving the whole requesting of firewall policies.

What about the implementation team?

We used a reseller for the deployment. Our experience was not that great, which has more to do with how our supply chain works and why we picked them. However, I don't ever really talk to them or hear from them.

What was our ROI?

We have seen ROI from the side of operations, and we'll probably get to more of that as time goes on. However it took a while to get to that point.

The solution has helped us reduce the time it takes us to make changes by at least a day.

It did reduce the time part of engineers manually spending time on processes from the aspect of manually having to go through the network and finding the path that a request would take to know where to put the rules. We have had some issues with topology, so not all of our tickets get that advantage. Probably 40 percent of them are that way, so that's why right now it is not as big of a gain.

Which other solutions did I evaluate?

We did consider other solutions.

What other advice do I have?

Do proper research. Look at Tufin and all of the other products.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
NetworkS3480 - PeerSpot reviewer
Network Security at a insurance company with 1,001-5,000 employees
Real User
The product streamlines our change management process
Pros and Cons
  • "The product streamlines our change management process."
  • "The product is good at auditing the changes that we make in our environment."
  • "There were some hiccups here and there with the initial setup."

What is our primary use case?

The primary use case is for firewall auditing. We use it for audit monitoring, login changes, and firewall changes. We are looking at automation, but not yet.

How has it helped my organization?

The product is good at auditing the changes that we make in our environment.

We use this solution to automatically check if a change request will violate any security policy rules. For example, if the engineer is making a change that hasn't been authorized, we will know about it.

The product streamlines our change management process. It assists us in reporting on some of the compliance for our auditing department. It helps us in managing the process and having some auditing capabilities.

What is most valuable?

  • The reporting is its most valuable feature.
  • The change impact analysis capabilities of this solution are good. 
  • It is able to detect our changes, email, and alert us.

What needs improvement?

There are features that we haven't used, and we need to understand them first.

What do I think about the stability of the solution?

Product seems to be stable. We haven't had any outages yet.

How are customer service and technical support?

I personally haven't called into support yet, but some of my peers have. They seem to get their questions resolved.

Which solution did I use previously and why did I switch?

We previously had FireMon, but FireMon kept giving us inaccurate information and not up-to-date information. Therefore, we thought we would try out Tufin, which has provided us with the information that we needed.

How was the initial setup?

There were some hiccups here and there with the initial setup, but we used Tufin's support to assist us with that.

What about the implementation team?

We deployed it in-house.

Which other solutions did I evaluate?

On the shortlist was AlgoSec, which was the only one that we actually tested.

Tufin and AlgoSec were pretty much in the competitive price range, but this one provided us better integration into the Check Point environment.

What other advice do I have?

Seriously Tufin for your final decision.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Founder at a tech services company
Consultant
The product suite itself brings together organizational units. They can have their own interface and ability to understand what different parts of the company are doing.

What is most valuable?

From my perspective, I think that it’s hard to break it down to a single feature. The visibility it gives and the customizability it provides is invaluable and the change automation is the most powerful capability, at least for now. The application awareness component is a close second. As more organizations adopt this revolutionary way of visualizing enterprise connectivity, SecureApp will fundamentally change the way connectivity is provisioned and decommissioned.

How has it helped my organization?

The product suite itself brings together organizational units. So when you talk about operations, development, management and auditing, all of these organizations have their own interface and abilitie to understand what different parts of the company are doing.

What needs improvement?

I think Tufin is continuously moving towards broader support for other platforms. Including a significant focus on the cloud. This approach is critical to the model of normalizing policy management across the environment - regardless of platform.

For how long have I used the solution?

We've used it for nearly eight years.

What do I think about the stability of the solution?

It's absolutely stable and this is why I always promote it. They have the finest set of coders and developers you can find.

What do I think about the scalability of the solution?

The distributed architecture capabilities allows this solution to scale to anybody’s needs.

How is customer service and technical support?

The support team is second to none. They have multiple offices in multiple countries. They're always available. I know the support teams and leaders personally and they are of great quality.

How was the initial setup?

It’s very easy to get up and running. With anything that is so feature rich and customizable, the installations range from a couple of days to more complex with many days and script writing. It just depends.

What's my experience with pricing, setup cost, and licensing?

Spend the time to evaluate all of the components of the Tufin suite. When you bundle different features together and you bundle components, you get a better price.

What other advice do I have?

We often find customers that have purchased this product for a specific purpose and they limit its use to only that purpose. Do yourself a favor and really explore the entire product and maximize the features and functionality of what you have purchased.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: I used to work for Tufin. My current company is a Tufin Partner.
PeerSpot user
it_user270423 - PeerSpot reviewer
it_user270423VP Marketing and Strategy at a tech company with 201-500 employees
Real User

So many words - so little substance...
I can continue to explain to you why you are wrong (and why an audit license does not constitute as a customer - read what I wrote again about installing the product *on your network* - so you can attest to scalability, reliability etc.) but I realize it will fall on deaf ears.

Let's let the readers of this community be the judge.
Over and out...

See all 12 comments
Buyer's Guide
Download our free Tufin Orchestration Suite Report and get advice and tips from experienced pros sharing their opinions.
Updated: December 2024
Buyer's Guide
Download our free Tufin Orchestration Suite Report and get advice and tips from experienced pros sharing their opinions.