Tufin has helped us a lot. It lets us clean up the rule base in a short period of time and remove unused rules. Tufin provides you a report on rules for this that lets you delete objects that are obsolete and no longer needed in the rule base. If you don't use a tool like Tufin, this is done manually and may take days, because for every object, before you delete it, you have to make sure that it is not being used by someone else.
Senior Advisor Security Architect at a comms service provider with 10,001+ employees
Tufin Lets Us Clean Up the Rule Base Quickly and Remove Unused Rules.
What is most valuable?
How has it helped my organization?
From a security point of view, Tufin can provide the posture of your environment, meaning whether your rule base is secure or not. It will analyze the file rule base, tell you if the service you enabled is secure, and give you some advice how to deal with the situation.
What needs improvement?
I want Tufin to be used by my entire team, but due to a lack of training and lack of resources, we are not able to do that. I would like to see more training videos that can be distributed to my team in order to really take advantage of the product.
For how long have I used the solution?
We have been using it for about 3 years now.
Buyer's Guide
Tufin Orchestration Suite
March 2025

Learn what your peers think about Tufin Orchestration Suite. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
842,690 professionals have used our research since 2012.
What do I think about the stability of the solution?
I find it very stable. We haven't had any big issues since we started using it. Issues we have had have mostly been related to new features being added that weren’t supported by the device. In those scenarios, we submit the case to Tufin and they tell us about the new release.
What do I think about the scalability of the solution?
We are a big company and I can say that we are not using the product in its fullest capacity. We have a different type of policy because we are using different vendors and different technologies, and while we have some issues with the juniper devices, it has absolutely been scalable.
How are customer service and support?
Tech support has been fine. Right now I have an ongoing case and there is a delay, but it mostly comes from me because I took time to respond and they are telling me other ways that I know.
Which other solutions did I evaluate?
I implemented FireMon three years ago for a customer because the customer specifically requested it. I found it very hard to put in place. I wasn’t a part of the Tufin implementation, but in terms of the product itself, Tufin is easier to use.
What other advice do I have?
I would give Tufin an 8 out of ten because some vendors own multi-contexts, and there are challenges supporting these devices. We are having issues with the Juniper device, for example.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.

IT Security Engineer at a energy/utilities company with 1,001-5,000 employees
Gives you the ability see what changes have been made and who made them, as well as pinpoint what has changed.
Valuable Features
Tufin gives you the ability see what changes have been made and who made them, as well as pinpoint what has changed so if there is an issue you can easily review it. I also like that if there is a new request that's coming in, you have the ability to compare the request with what is already in the system so you don't have to go into the firewall rules to try to figure it out. You can just do a comparison between different policies.
Improvements to My Organization
We use reports a lot for cleaning up, which is part of our regulatory requirement. You need to review the policies for any old reports, used objects or used services. That's basically what draws the purchase of this product.
I also like the product’s ability to reduce security risks. Being able to do some of the compliance checks has been very good for us.
Room for Improvement
The ability to search could be improved, and it would be helpful to be able to display more than a hundred results on a search or share when you do the workflow with multiple people at the user level on your same team. If you have a team of three people each one should be able to see each other's request without having high-level access rights.
Also, the workflow is very rigid. It's not very easy to manipulate. The graphical interface needs to be a little more user-friendly. You need to be able to move objects around to make a nice display. Right now, if you select an object, it just sits there and everything goes sequentially. I want to be able to move objects around to make the interface more presentable in the way you would normally code something. That's a big concern, because we've gotten several complaints.
Use of Solution
We have used Tufin for at least seven years.
Stability Issues
We haven’t had any problems, except for some licensing issues a long time ago.
Scalability Issues
For what we do we haven't seen any performance issues so far.
Customer Service and Technical Support
Technical support has been good. We've had different engineers help us out and they've all been very helpful.
Other Solutions Considered
We compared Tufin to AlgoSec. At that time, we felt that what Tufin had in terms of their workflow and the option to transfer over our existing workflow was more flexible. It was a hard decision. One of the other reasons we picked Tufin up versus AlgoSec was the responsiveness of the people we were working with. They understood the company and our relationship, and we felt that it would be easier to have the ear of the company if we needed customization. They did the changes that we requested, which made life easier. We felt that if we were to go with AlgoSec, it would be a lot harder.
We closed the deal after they made a change to DNS lookup. Objects need to be created on our DNS system before they’re populated, and you didn’t have a way to validate your IP with a host name at that time.
Other Advice
If I had to rate it one to ten, I’d give it a nine, since there’s room for improvement, even though they’ve been doing a lot of improvements over the years. I would also say that if you buy the product make use of it. There are more features available than you always realize, so a lot of times you might try the harder way first because you are used to working that way. You might discover that your life can get a lot easier.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
Tufin Orchestration Suite
March 2025

Learn what your peers think about Tufin Orchestration Suite. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
842,690 professionals have used our research since 2012.
Network & Security Service Delivery Manager in Spain at a transportation company with 10,001+ employees
Depending on the kind of device, we can correlate information from both the device and from the client.
Valuable Features:
The most valuable feature for us is Tufin's versatility. Depending on the kind of device, we can correlate information from both the device and from the client. This is highly useful for us.
Improvements to My Organization:
Tufin's given us the ability to correlate between policy and firewall rules. We can even search for the correlations to determine violations and exceptions. Also, it's a solution where we can define our entire company's security policies.
Room for Improvement:
It needs better correlation so that it's easier to not have to look for information underneath all the data. So, even though the policy and firewalls are correlated, it's difficult to find them when we need to.
Deployment Issues:
We haven't had any issues with deployment. In fact, it was very easy to do.
Stability Issues:
We haven't had any issues with stability.
Scalability Issues:
We haven't had any issues with scalability.
Initial Setup:
The initial setup was not complex. It was fairly easy and straightforward.
Implementation Team:
We implemented it with our in-house team.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Network System Architect / Technical Project Leader at a local government with 1,001-5,000 employees
The multi-vendor support is the most important feature because our system has integrations of software and hardware from many vendors. I think that it needs to be in the cloud.
Valuable Features:
The multi-vendor support is very important for us. This is the most important feature because our system has integrations of software and hardware from many vendors. Tufin has also integrated well, supporting our system of multiple vendors.
Improvements to My Organization:
Our company has a common policy that we need to ensure covers three different vendors we work with. Tufin helps us to manage this as it's where we've defined the common policy and also where we manage it.
Room for Improvement:
I think that Tufin needs to be as-a-service, that is, in the cloud. The installation also needs to be easier. Additionally, with Tufin's business model, the licenses are quite expensive.
Deployment Issues:
It's hard to stay updated with the last version. That's really the main hurdle we have with our deployments of Tufin.
Stability Issues:
It's quite stable, but you always need to do updates. Staying updated has prevented instabilities.
Scalability Issues:
We don't have this issue because we only have four firewalls. It has scaled for our needs.
Initial Setup:
The initial setup was straightforward and pretty easy.
Implementation Team:
We implemented it ourselves with our in-house team. It was easy.
ROI:
Sometimes it's very difficult to get the ideal revenue out of this tool. It's expensive.
Cost and Licensing Advice:
The licensing is expensive. Maybe for a big company, the price and the licensing is not a problem. For a small or medium company, though, it could be an issue.
Other Solutions Considered:
We also looked at AlgoSec and FireMon.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Network Security Engineer at a government with 1,001-5,000 employees
Good for retrieval and for policy remediation, as far as cleaning up policies.
Valuable Features:
The last account I was working for had just implemented Tufin. It was good for retrieval and for policy remediation, as far as cleaning up policies and so on. When I got there, they had a lot of old policies. Everything was all over the place. Tufin was good for policy cleanup.
Once you install Tufin, it performs a query and it searches all active policies. Once it does that, it places all the policies that you know in priority order, as far as which policies are being most used and which ones aren’t being used. Then it gives you something like a survey of things that were being used or any things that weren't being used. You can decide whether you want to take out or if you have some machines which are totally dead. That was really the big benefit of using Tufin.
Room for Improvement:
It took a long time just to try to gather the information. I would like Tufin to be faster.
Use of Solution:
For what we needed, it searched all of the information we wanted it to.
Stability Issues:
It was stable. We didn’t have any stability issues.
Scalability Issues:
It was very scalable and very customizable for what we needed it for. We had about 4,500 users on our network, and then we had six firewalls. It came in handy with that.
Initial Setup:
Installation was a little bit complex, so we did get help. We had to have professional services from Tufin come and help us. They were great. Once they came, it was simple to setup.
I’m giving the product a rating of seven mostly because of the initial setup. It took us a while because we couldn't figure it out. After about three weeks, we had to hire someone to come and set it up. Once that happened, then it flowed.
Other Solutions Considered:
When we were deciding whether to implement Tufin, a lot of the other agencies were using it at the time. We went with Tufin because it was receiving favorable scores from the other agencies.
The only one I can compare it to is AlgoSec. AlgoSec has a few more features but a lot of similar agencies were going towards Tufin, so that's why we went with them.
Other Advice:
Define exactly the specifics of what you need it for. If you need it for remediation of policies, then it's definitely the product to go to.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Architect at HCA
It’s nice to have a central location for remediating rules that are not compliant. I hope they add the ability to manage NATs and improve the interface.
Valuable Features:
What I’ve found very useful in a short period of time is the visibility it provides. It looks at the tools that don't meet our compliance requirements. We’re part of a program where we’re going back and remediating a lot of the rules that are falling out on compliance. Having a central location for that is very nice.
Improvements to My Organization:
It provides pretty decent visibility to the rule set that we have. Right now, we're looking to better utilize the zoning. When we start utilizing the zoning better, I think it will be a lot more useful tool.
Room for Improvement:
A major thing that it sounds like it's still going to be lacking, is the ability to create and push NATs. Our network is very large and very complex, we use NATing internally quite a bit. That's a fairly large pain point for our firewall admins. We can use SecureTrack and SecureChange to create and manage rules, firewall rules, but it doesn't have the ability to manage NATs, which we find, is key for management.
Some of the pain points like NATing and the interface brings my rating for the product down to a seven. The interface is workable, but it could be a little bit more intuitive. I would rate the function of the product a ten.
Use of Solution:
I'm very new to the Tufin products. I'm new to HCA and this is the first time I had professional experience with it.
Other Advice:
Dive in.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Security Specialist at a financial services firm with 501-1,000 employees
It’s not a dangerous solution because we use it for looking at things and not for making changes.
Valuable Features
I use Tufin SecureTrack, which means I use it for looking at things and not for making changes. The value of it there is that, since I deal with Check Point policies a lot, I can use it to see what changes have been made to the policy since the last time I looked at it, because it may have been a couple of weeks since I last installed a policy or maybe somebody else has had their hand at it.
Tufin gives me a really easy way to graphically look at the policy, before and after changes are made, through two panes. As you drag around one pane, the other moves with it, and they resemble the Check Point dashboard view so it’s very familiar. You can easily spot all the differences and see what has changed in the policy to make sure there are not any mistakes and that nobody accidentally added a block edited any rule at the top of the policy—that’s probably happened to everybody, right?
I also use a feature where you can run a report on rule and object usage. This helps me spot rules or objects that aren’t really ever hit, so I can remove them from the database if they no longer exist.
Improvements to My Organization
Tufin is easy to use, which was really important for us. Also, it’s not a dangerous solution because we can’t make changes with it.
Room for Improvement
I'm running R77, and I'm concerned with how well it will work with R80, the new release of the operating system. R80 changes the way that the dashboard you use to manage the policy looks and operates, and we will have to see whether Tufin keeps up with that or not. Also, in the current R77, the various blades appear as different tabs in the interface and dashboard, and Tufin doesn't look at any of those tabs except the security policy. I'd like it to be able to look for changes in some of the other configurations. In R80, it's all tied together, but for now, it's in a separate panel. I don't currently have any way of using Tufin to audit what changes have been made to the web filtering configuration, for example.
Stability Issues
It's very stable.
Scalability Issues
I don't have a huge environment, but it doesn't seem to require a lot of horsepower. We're running it as a virtual machine, and that's working fine.
Customer Service and Technical Support
We haven’t needed technical support since we moved from a physical to a virtual world.
Initial Setup
It was straightforward. It’s been a few years, but I don’t recall any problems with setup.
Other Advice
I have no problems with Tufin, and it works great, but I would have to give it an eight out of ten. It’s just not as amazing as some of the other technologies I use, like Lancope StealthWatch. I wouldn’t tell anyone to stay away from it—It’s just a good idea to look at the competition and see what’s out there.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Network Security Engineer at a pharma/biotech company with 10,001+ employees
I like how it optimizes your policy, and does a compliance check and risk analysis.
Valuable Features:
I like how it's able to optimize your policy, look at the objects, and other similar functions. We only have Check Point integrated with Tufin SecureTrack, so that's a key benefit of using it. We can check policies against past policies. It does a kind of compliance check or risk analysis if there are unused policies or unused objects. It highlights them and it gives you a good view of what doesn't need to be there.
Room for Improvement:
It would be better if Tufin could integrate with the Cisco routers, FireEye, and other devices like that, so you can do the routing changes and so on straight from SecureChange. That would be good.
I haven't looked at their latest versions or releases, what's new, and what's not. We're still running a version that's at least a year old, so I still have to look at it. If they have added integration with Cisco routers already, that's good, but we don't have that in the version that we have. It doesn't support Cisco routers at all.
Stability Issues:
It's been stable in our multi-domain environment. We have more than 20 or 30 policies.
Other Solutions Considered:
When we were looking at products that can do this, I think we only looked at Tufin. Its integration with Check Point is what led us to Tufin. That was the main reason why we looked at it.
Other Advice:
I hope that Tufin just keeps doing what they’ve been doing. We look forward for future enhancements.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Tufin Orchestration Suite Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2025
Product Categories
Firewall Security ManagementPopular Comparisons
FireMon Security Manager
Skybox Security Suite
Palo Alto Networks Panorama
AWS Firewall Manager
Azure Firewall Manager
ManageEngine Firewall Analyzer
Cisco Defense Orchestrator
Buyer's Guide
Download our free Tufin Orchestration Suite Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between AlgoSec and Tufin?
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Comparing network security vendors and devices
- When should companies use SSL Inspection?
- When evaluating Firewall Security Management, what aspect do you think is the most important to look for?
- What are the most important features you would be looking for in a firewall?
- How do I estimate the required firewall throughput for my organization?
- What are the pros and cons of Tufin, AlgoSec and RedSeal?
- Tasks to Perform on Preventive Maintenance.
- Why is network segmentation important?