Try our new research platform with insights from 80,000+ expert users
PeerSpot user
Network & Security Operations Manager at a retailer with 1,001-5,000 employees
Vendor
It's a complete product, and we find the SecureTrack and SecureChange features to be most valuable to us.

What is most valuable?

We use both modules, SecureTrack and SecureChange. With Securetrack, we follow rules implementation and compliance; with SecureChange we manage the workflow of firewalls openings.

How has it helped my organization?

Thanks to Tufin we're able to manage the life cycle of rules and to keep logs of each firewall modification. Policies are also optimized using the tool.

What needs improvement?

Checkpoint and Cisco products are well implemented and managed. For Fortinet firewalls some features are not yet available.

In networks where the WAN is managed by a third party, some features may be missing if you're not able to have information about routing, ACL, etc

For how long have I used the solution?

2 years.

Buyer's Guide
Tufin Orchestration Suite
February 2025
Learn what your peers think about Tufin Orchestration Suite. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.

What was my experience with deployment of the solution?

Product is quite complete. The hard work concerned building a topology on the product base on reality of the network. Some workaround we do in reality may be hard to model using the tool. Topology is mandatory for SecureChange to work.

What do I think about the stability of the solution?

Product is stable and we've had no problems concerning stability, even if we're not able to have a clear view of the capacity of this tool. There is no reporting on capacity. For instance, there is no alarm.

What do I think about the scalability of the solution?

No issue specifically, but for large networks several appliances are required to have a distributed architecture. Also, for SecureChange it's necessary to have a separate instance so the topology calculation has no impact on user interfaces.

How are customer service and support?

Customer Service:

Excellent, even if we have more contact with support team, customer service is always checking that everything is fine.

Technical Support:

Excellent, the support and the post sales service is the best I ever had. They're always available and listen our concerns. Even some features required have been delivered a few weeks after the requirement.

Which solution did I use previously and why did I switch?

We used another solution some years ago, but we switched, first of all, for performance and stability issues. The old solution was not able to handle the number of rules we can manage in our network.

How was the initial setup?

The main setup subject will be to check what's the first need you want to answer. In our cases we want to manage our life cycle of rules and we work on it. Start small and grow up smoothly while you understand your network topology.

What about the implementation team?

Vendor was quite good. This is a tool with which the need to understand your network is mandatory. You must have an in-house team to be fully operate this tool. This is also the easiest for support.

What was our ROI?

Our main ROI is to be more agile and flexible for rules lifecycle. We're able to answer faster with the same number of people.

What's my experience with pricing, setup cost, and licensing?

Pricing is correct. You've got one or several appliances and pricing is not too high. After licensing is per firewall managed by the tool, so you can grow smoothly.

Which other solutions did I evaluate?

We did an evaluation of the different solutions on the market, and it was our vendor that recommend us the solution.

What other advice do I have?

I recommend this solution. In our case, it was the missing part to be able to provide a better service to our clients.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
reviewer1543566 - PeerSpot reviewer
Principal Consultant at a consultancy with 1-10 employees
Consultant
Good visibility, user-friendly, and stable, but needs better graphical representation capabilities
Pros and Cons
  • "Being able to customize your own clarity to that aspect of change management."
  • "I would like to see AI elements included with this solution."

What is our primary use case?

The solution is predominantly used for managing firewall changes, policy changes, and understanding those aspects.

Most people use it for the basics, even though they could use it for a lot more.

What is most valuable?

The most valuable feature is being able to customize your own clarity to that aspect of change management.

Having better visibility of what is going on. If it gets out of control, you can keep it in your head no matter how smart your administrators are.

From what I have seen, it's user-friendly.

What needs improvement?

It's a bit clunky, but that may be because of different environments, and it is struggling to get the information. It's possible that the performance issue is because of the network and not the right architecture.

I would like to see anything that is graphical, as much graphical representation of things. Modeling, and what-ifs. It becomes more intuitive and allows you to close some of the gaps between drawing stakeholders in, for example. If they ask "Why are you spending so much money on this tool?"  or "Why are you doing this?", you can show them examples and it becomes more obvious.

I would like to see AI elements included with this solution. There is quite a lot of human element in understanding the consequences of change within the firewall environment, but they might benefit from more of an AI element as well.

For how long have I used the solution?

I am a security architect and I have been involved with it periodically for approximately five years.

What do I think about the stability of the solution?

It's a reliable solution.

What do I think about the scalability of the solution?

It's a scalable product. I have dealt with companies that are pretty sizeable, and it seems to handle it.

How are customer service and technical support?

I personally have not contacted technical support, but the information that is available on their website is pretty useful, it's pretty good.

How was the initial setup?

You need to allow a fair amount of time. That is the case for all firewall management tools.

It gives the appearance of being straightforward to get going but they need a bit of time particularly to do the sorting of the matrices for example.

When planning, people should estimate it then double it, just to make sure they get things right.

What's my experience with pricing, setup cost, and licensing?

Price could always be better, but there are always consequences. Normally, there are other issues that come into play. For example, you pay more and expect to lean on the vendor more for the services and support.

What other advice do I have?

I have recommended this solution from time to time and I would definitely recommend it to others.

I would rate Tufin a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Tufin Orchestration Suite
February 2025
Learn what your peers think about Tufin Orchestration Suite. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
CTO at Uridium Technologies
Real User
A complete solution with good reporting and excellent technical support
Pros and Cons
  • "The reporting on offer is very good. Tufin makes nice reports."
  • "The pricing could be a bit more competitive."

What is most valuable?

So far, the solution has been fantastic. The customer has been very happy with its capabilities overall. 

It works very well in an enterprise environment.

There aren't any gaps in its offering at this time. It's a very complete solution.

The reporting on offer is very good. Tufin makes nice reports.

Technical support has always been very helpful and responsive. 

What needs improvement?

The pricing could be a bit more competitive. If you compare it to, for example, AlgoSec, AlgoSec has better pricing.

The implementation could be a bit easier. 

For how long have I used the solution?

I've been working with the solution for about a year or so at this point. It hasn't been too long. 

How are customer service and technical support?

We've had to contact technical support a few times in the past. Their support is fantastic. They are very helpful and responsive. They are knowledgeable about the product. We are quite satisfied with the level of service we receive. 

Which solution did I use previously and why did I switch?

I also work with Cisco devices.

How was the initial setup?

We had some issues during the initial implementation. Our client had some devices that, for some reason, just weren't integrating. If they could look into issues that clients face at the outset, when the setup is happening, it would make the experience a lot easier to handle. They just seem to need to be able to handle more integrations with other devices. 

What's my experience with pricing, setup cost, and licensing?

The pricing could be a bit better. It's definitely not the least expensive option. It would be ideal if the product pricing came down a bit so that it was more competitive. The clients would appreciate that a lot.

Which other solutions did I evaluate?

I'm currently looking at other solutions to compare Tufin to. I have done some comparisons between Tufin and AlgoSec and my takeaway from that is that AlgoSec is less expensive.

What other advice do I have?

I would advise other organizations considering the solution to first be aware of what they want to achieve. As a company, you need to start there before you start choosing solutions. That way, you'll know if the solution will properly meet your expectations. Tufin has a few options as well. It's important to understand which would work best according to your requirements. 

I would rate the solution at a nine out of ten overall. We've been very please with the capabilities of the product and our clients have been happy. 

Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
Security7b20 - PeerSpot reviewer
Security Engineer at a insurance company with 201-500 employees
Real User
Every change is tracked down to the person and time
Pros and Cons
  • "This solution has helped us meet our compliance mandates. Everything is all auditable. Every change is tracked down to the person and time."
  • "We are using the visibility with notifications on every firewall change and what those changes were. We have visibility to see who is making the changes, and when."
  • "With scalability, we are going to run into some issues. We have been talking about converting over to actual hardware as opposed to virtual. Therefore, I don't think we are scalable at this time, especially with the updates coming. I'm told that they're going to need a lot more horsepower to push them."

What is our primary use case?

The primary use case is automation.

We are using the latest version.

How has it helped my organization?

We find that the change workflow process is flexible and customizable. If we want to change approvers, that is very easy. If we wanted to add a step or get rid of a step, this is easily customizable.

We are using the visibility with notifications on every firewall change and what those changes were. We have visibility to see who is making the changes, and when. This is the biggest thing because we are underutilizing the product right now.

This solution has helped us meet our compliance mandates. Everything is all auditable. Every change is tracked down to the person and time.

What is most valuable?

The auditing is a valuable feature. We can be audited, because it has the ability for approvals to be set up and to put in policies. It is all automated.

For how long have I used the solution?

We bought it about a year ago, but we have been doing other projects. We haven't fully implemented it.

What do I think about the stability of the solution?

So far, the stability is good.

What do I think about the scalability of the solution?

With scalability, we are going to run into some issues. We have been talking about converting over to actual hardware as opposed to virtual. Therefore, I don't think we are scalable at this time, especially with the updates coming. I'm told that they're going to need a lot more horsepower to push them. 

As far as scalability, it is great for adding network objects and so on.

How are customer service and technical support?

i have not talked to technical support.

As we start to dive in, I'll be reaching out to the customer success team.

How was the initial setup?

The initial setup was straightforward. We did it in three days.

What about the implementation team?

We used a reseller for the deployment. They were very good.

Which other solutions did I evaluate?

There was one other solution that we evaluated, but it didn't stack up. Tufin was the best solution.

What other advice do I have?

Everything is good right now.

Reach out to whoever does your implementation and support. Ask as many questions as you can and do research.

We haven't got to the point where we've used the solution to clean our firewall policies yet. That is the next phase.

This solution won't help us ensure that our security policy is followed across our entire hybrid network until the next stage.

We're not in the cloud.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Owner at Concepts Solutions Informatiques
User
The designer gives the ability to know where to add a rule or if a rule is already in place
Pros and Cons
  • "The designer gives the ability to know where to add a rule, or if the rule is already in place."
  • "It would be great to add a link to Visio to create shapes directly from Tufin, as it has the configuration."

What is our primary use case?

Firewall policy management over all firewalls from one single point. We browse policies, objects, and their usage. The report gives us an image of where risks are.

How has it helped my organization?

We now spend less time auditing rules with reports: 

  1. The designer helps us in creating rules
  2. It tells us what rule is missing and where to put it. 
  3. The predefined reports are then sent to administrators.
  4. It provides an exact image of how to improve security.

What is most valuable?

  • The policy browser gives the ability to browse all firewalls from a single point. It's possible to see where an IP is inserted in rules. 
  • The designer gives the ability to know where to add a rule, or if the rule is already in place. 
  • The reports are personalized now and the cleanup is helpful for administrators.

What needs improvement?

It would be great to add a link to Visio to create shapes directly from Tufin, as it has the configuration. 

For how long have I used the solution?

Three to five years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Founder at a tech services company
Consultant
The product suite itself brings together organizational units. They can have their own interface and ability to understand what different parts of the company are doing.

What is most valuable?

From my perspective, I think that it’s hard to break it down to a single feature. The visibility it gives and the customizability it provides is invaluable and the change automation is the most powerful capability, at least for now. The application awareness component is a close second. As more organizations adopt this revolutionary way of visualizing enterprise connectivity, SecureApp will fundamentally change the way connectivity is provisioned and decommissioned.

How has it helped my organization?

The product suite itself brings together organizational units. So when you talk about operations, development, management and auditing, all of these organizations have their own interface and abilitie to understand what different parts of the company are doing.

What needs improvement?

I think Tufin is continuously moving towards broader support for other platforms. Including a significant focus on the cloud. This approach is critical to the model of normalizing policy management across the environment - regardless of platform.

For how long have I used the solution?

We've used it for nearly eight years.

What do I think about the stability of the solution?

It's absolutely stable and this is why I always promote it. They have the finest set of coders and developers you can find.

What do I think about the scalability of the solution?

The distributed architecture capabilities allows this solution to scale to anybody’s needs.

How is customer service and technical support?

The support team is second to none. They have multiple offices in multiple countries. They're always available. I know the support teams and leaders personally and they are of great quality.

How was the initial setup?

It’s very easy to get up and running. With anything that is so feature rich and customizable, the installations range from a couple of days to more complex with many days and script writing. It just depends.

What's my experience with pricing, setup cost, and licensing?

Spend the time to evaluate all of the components of the Tufin suite. When you bundle different features together and you bundle components, you get a better price.

What other advice do I have?

We often find customers that have purchased this product for a specific purpose and they limit its use to only that purpose. Do yourself a favor and really explore the entire product and maximize the features and functionality of what you have purchased.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: I used to work for Tufin. My current company is a Tufin Partner.
PeerSpot user
it_user270423 - PeerSpot reviewer
it_user270423VP Marketing and Strategy at a tech company with 201-500 employees
Real User

So many words - so little substance...
I can continue to explain to you why you are wrong (and why an audit license does not constitute as a customer - read what I wrote again about installing the product *on your network* - so you can attest to scalability, reliability etc.) but I realize it will fall on deaf ears.

Let's let the readers of this community be the judge.
Over and out...

See all 12 comments
it_user489207 - PeerSpot reviewer
Security Architect at a healthcare company with 1,001-5,000 employees
Real User
Improved policy management. With SecureTrack, I can track the policy and find all the policies that we're not using.

Valuable Features:

Policy management.

Improvements to My Organization:

A lot of policy is legacy. With SecureTrack, I can track the policy and find all the policies that we're not using. Basically, we create a process out of it and actually get rid of those legacy policies.

I don't have a real idea of how many policies we’ve found, but the outcome for that policy management is usually better for our file work because it runs much more smoothly because of less policy, less memory usage, and less CPU.

We try to make the file work much more efficient. We also do auditing for file work, such as who made changes on the file work. You can use it for accountability, if needed. 

We also use some of the compliance features. We define policy on what is compliant. If anyone tries to create certain stuff that is not compliant, we get notified. I haven't fully utilized Tufin yet and I'm working toward that area. Hopefully I can give it a higher rating as we explore more functions. We know the capability; we just need to get to that point. If we reach that point, it'll be much better actually. We’re just not there yet.

Room for Improvement:

We’re hoping to be able to share the data Tufin’s collecting with other platforms so they can be more integrated with those metrics, because the governance tool is where we create policy. And then using Tufin’s metric, we can actually know what kind of policy we can create. That would help out.

Stability Issues:

It's good. I haven't rebooted.

Scalability Issues:

We are big, but we are only using a fraction of what Tufin is capable right now. I'm hoping that we can explore a lot more and then try to utilize more on Tufin because my big way to look at Tufin is this ability to gather all that data. If Tufin doesn't have that footprint, you won't get that data. So right now, I'm working on that.

Initial Setup:

For my current company, I inherited it.

Other Solutions Considered:

I haven’t thought of using any other solution, so, I haven't looked at other solutions yet.

Other Advice:

Let Tufin help you see what can be. Make the tool work for you and be creative.

You can't always use it in a certain way. There are many ways to use a tool. You just have to be creative on how you use the tool. Find holes and ways to use it.

Figure out how you use the tool, and then figure out if you can create a process out of it, so you are not only using it when you are free. You want to use it as a process because it has to be repeatable. If something is not repeatable, there's no way to improve the process.

If I'm going to find a policy right now and I don't repeat that process, those policies will continue to become legacy, so you have to repeat using the tool.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user489216 - PeerSpot reviewer
WAN Border Engineer at a pharma/biotech company with 10,001+ employees
Real User
You can kind of see where the flows are coming and how they're working.

Valuable Features:

  • The ability to compare the old policy and the new policies is real handy.
  • The topology view is really good. 
  • You can kind of see where the flows are coming and how they're working.

Room for Improvement:

I come more from the WAN space as opposed to the security space, so I would obviously like to see Tufin integrate with Cisco routers. There's room for more integrations with other products.

Use of Solution:

I'm just kind of getting into it, so I don't think I have the full breadth of the product personally, but it is pretty usable.

Stability Issues:

It's been stable in our environment.

Scalability Issues:

We haven't had any trouble scaling it. We have about 100 policies.
There haven’t been any issues with speed, as far as I can tell.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Tufin Orchestration Suite Report and get advice and tips from experienced pros sharing their opinions.
Updated: February 2025
Buyer's Guide
Download our free Tufin Orchestration Suite Report and get advice and tips from experienced pros sharing their opinions.