Being able to run reports to see what rules are there and which rules are not needed is very useful to me. It allows me to optimize the policies. Also, every time someone pushes policy it sends an email to say that the change was made. I have it set up to run reports every two days to let me see the state of the firewall or the state of the policies.
HoD IP MPLS Department at a comms service provider with 1,001-5,000 employees
Being able to run reports to see which rules aren't needed is useful. It allows me to optimize the policies.
What is most valuable?
How has it helped my organization?
The ability to get a sanity check for the rule base is important. Right now, we write our own firewall rules, and with Tufin, we can cut those down to four hundred.
What needs improvement?
The upgrade was a bit cumbersome because we had to do a complete reinstall. We removed it from a version of Linux that wasn’t supported and we had to do our first fresh install.
For how long have I used the solution?
We’ve used it for a couple months now.
Buyer's Guide
Tufin Orchestration Suite
September 2025

Learn what your peers think about Tufin Orchestration Suite. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
872,008 professionals have used our research since 2012.
What do I think about the stability of the solution?
We haven’t had any issues with stability so far.
What do I think about the scalability of the solution?
We’re a small team and we manage five clusters, so it’s not too bad.
How are customer service and support?
We used technical support for the upgrade and they were very helpful. We haven’t had any issues, apart from the fact that we had to do a fresh install, but we were provided support through that process. They were online with us right through using WebEx. That was great.
What other advice do I have?
My experience with Tufin has been good. We haven’t had any technical issues and the features that I have seen in the software so far are excellent.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.

Security Specialist at a financial services firm with 501-1,000 employees
It’s not a dangerous solution because we use it for looking at things and not for making changes.
Valuable Features
I use Tufin SecureTrack, which means I use it for looking at things and not for making changes. The value of it there is that, since I deal with Check Point policies a lot, I can use it to see what changes have been made to the policy since the last time I looked at it, because it may have been a couple of weeks since I last installed a policy or maybe somebody else has had their hand at it.
Tufin gives me a really easy way to graphically look at the policy, before and after changes are made, through two panes. As you drag around one pane, the other moves with it, and they resemble the Check Point dashboard view so it’s very familiar. You can easily spot all the differences and see what has changed in the policy to make sure there are not any mistakes and that nobody accidentally added a block edited any rule at the top of the policy—that’s probably happened to everybody, right?
I also use a feature where you can run a report on rule and object usage. This helps me spot rules or objects that aren’t really ever hit, so I can remove them from the database if they no longer exist.
Improvements to My Organization
Tufin is easy to use, which was really important for us. Also, it’s not a dangerous solution because we can’t make changes with it.
Room for Improvement
I'm running R77, and I'm concerned with how well it will work with R80, the new release of the operating system. R80 changes the way that the dashboard you use to manage the policy looks and operates, and we will have to see whether Tufin keeps up with that or not. Also, in the current R77, the various blades appear as different tabs in the interface and dashboard, and Tufin doesn't look at any of those tabs except the security policy. I'd like it to be able to look for changes in some of the other configurations. In R80, it's all tied together, but for now, it's in a separate panel. I don't currently have any way of using Tufin to audit what changes have been made to the web filtering configuration, for example.
Stability Issues
It's very stable.
Scalability Issues
I don't have a huge environment, but it doesn't seem to require a lot of horsepower. We're running it as a virtual machine, and that's working fine.
Customer Service and Technical Support
We haven’t needed technical support since we moved from a physical to a virtual world.
Initial Setup
It was straightforward. It’s been a few years, but I don’t recall any problems with setup.
Other Advice
I have no problems with Tufin, and it works great, but I would have to give it an eight out of ten. It’s just not as amazing as some of the other technologies I use, like Lancope StealthWatch. I wouldn’t tell anyone to stay away from it—It’s just a good idea to look at the competition and see what’s out there.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Tufin Orchestration Suite
September 2025

Learn what your peers think about Tufin Orchestration Suite. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
872,008 professionals have used our research since 2012.
IT Security Engineer at a energy/utilities company with 1,001-5,000 employees
Gives you the ability see what changes have been made and who made them, as well as pinpoint what has changed.
Valuable Features
Tufin gives you the ability see what changes have been made and who made them, as well as pinpoint what has changed so if there is an issue you can easily review it. I also like that if there is a new request that's coming in, you have the ability to compare the request with what is already in the system so you don't have to go into the firewall rules to try to figure it out. You can just do a comparison between different policies.
Improvements to My Organization
We use reports a lot for cleaning up, which is part of our regulatory requirement. You need to review the policies for any old reports, used objects or used services. That's basically what draws the purchase of this product.
I also like the product’s ability to reduce security risks. Being able to do some of the compliance checks has been very good for us.
Room for Improvement
The ability to search could be improved, and it would be helpful to be able to display more than a hundred results on a search or share when you do the workflow with multiple people at the user level on your same team. If you have a team of three people each one should be able to see each other's request without having high-level access rights.
Also, the workflow is very rigid. It's not very easy to manipulate. The graphical interface needs to be a little more user-friendly. You need to be able to move objects around to make a nice display. Right now, if you select an object, it just sits there and everything goes sequentially. I want to be able to move objects around to make the interface more presentable in the way you would normally code something. That's a big concern, because we've gotten several complaints.
Use of Solution
We have used Tufin for at least seven years.
Stability Issues
We haven’t had any problems, except for some licensing issues a long time ago.
Scalability Issues
For what we do we haven't seen any performance issues so far.
Customer Service and Technical Support
Technical support has been good. We've had different engineers help us out and they've all been very helpful.
Other Solutions Considered
We compared Tufin to AlgoSec. At that time, we felt that what Tufin had in terms of their workflow and the option to transfer over our existing workflow was more flexible. It was a hard decision. One of the other reasons we picked Tufin up versus AlgoSec was the responsiveness of the people we were working with. They understood the company and our relationship, and we felt that it would be easier to have the ear of the company if we needed customization. They did the changes that we requested, which made life easier. We felt that if we were to go with AlgoSec, it would be a lot harder.
We closed the deal after they made a change to DNS lookup. Objects need to be created on our DNS system before they’re populated, and you didn’t have a way to validate your IP with a host name at that time.
Other Advice
If I had to rate it one to ten, I’d give it a nine, since there’s room for improvement, even though they’ve been doing a lot of improvements over the years. I would also say that if you buy the product make use of it. There are more features available than you always realize, so a lot of times you might try the harder way first because you are used to working that way. You might discover that your life can get a lot easier.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Security Engineer at a financial services firm with 1,001-5,000 employees
We use it as an auditing tool, since it’s a risk-based approach, which fits a lot of the needs of our auditors.
What is most valuable?
We use it as an auditing tool, since it’s a risk-based approach, which fits a lot of the needs of our auditors. We're able to clean up our firewall rules and use the security score in our monthly reports to executive management, showing them that we are making improvements within the security of our firewall policy. We can generate different inventory reports when rules are not in use. It allows us to print policy out for our auditors as well.
You can print off reports, either in Excel format or PDF format and deliver them to whoever needs those reports. It can also send you any report on a regular basis. For example, if you want to see your security scores, you can have that sent to you weekly.
How has it helped my organization?
Before we had Tufin, we had to do firewall policy cleanup and it was pretty painful. It would take us 6 weeks just to get through one review, and we had to do it quarterly. With Tufin, you can generate a report in 20 minutes and start taking action on it right away. It's a huge difference. You build up trust with the product. When you are looking at a rule and you don't know if it's been used before, you're kind of rolling the dice. When you have a tool that can look out 6 months and it hasn't been used, then you have a lot more confidence in cleaning that rule up.
What needs improvement?
Some of the challenges we have include getting the reports and the tools to look at our specific environment. There are some challenges with setup for that. You want to make sure that your PCI environment, your wireless environment, your DMZs and your internal network are all laid out in Tufin so they can be correctly scored and rated. A little more ease of use in that area would be helpful.
For how long have I used the solution?
We've had Tufin for 8 or 9 years. I was the one that brought it in.
What do I think about the stability of the solution?
We don't have any issues with stability of the product.
What do I think about the scalability of the solution?
We have a relatively small environment. We've got 30 firewalls, basically 15 clusters that Tufin monitors, and our policy rule base isn’t huge. We moved over to VMware and haven't had any issues with caring for the product.
Which solution did I use previously and why did I switch?
We actually used one of Tufin’s competitor’s products, AlgoSec, but found that the Tufin product is a lot more flexible from a reporting standpoint.
How was the initial setup?
It’s easy to set up. I would say to do a proof of concept and give it a try. It doesn’t take much effort to get it set up and start getting benefits.
What other advice do I have?
I would give it an 8 on a scale of 1-10 because it works really well in helping you create your own reports. You can drill down into each of the different risks that are in the environment and take action on it. It actually tells you, in a descriptive manner, what the issue is and how to fix it.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Engineer at a retailer with 10,001+ employees
The best feature is being able to query all our devices to find unused rules and objects and then clean them up.
Valuable Features:
The best feature is being able to query all our Check Point devices and certain other vendors like Fortinet as well. It can query and find unused rules and unused objects to clean things up for us.
I use reporting and assistance as a tool for cleanup. I would love to be able to get the newest version into our company and have it be used as a manager of not only Check Point but also the other vendors that we use. It looks like it's all there. - Fortinet, Palo Alto, some Cisco and other devices.
The fact that that we won't have to log into a Fortimaneger to manage Fortinet and then log into another to do Check Point, being able to log in straight to Tufin, build a rule and have it push it to the correct devices. That's huge and that's something that I really like about the new version.
Stability Issues:
We had some issues because of our unique configuration.
Scalability Issues:
I can't say too much about scalability, simply because it was not scalable for our environment because we are using a splintered specialized version just for our company. The Tufin apliance just doesn't play well with that specialized version. But for the things that we do have that are general release, it's awesome. It takes a little bit of a fiddling around but again, we're on an older version. It works flawlessly.
Other Advice:
Rating: because it's our unique older version, I'd give it a 6 or 7 but we only use it for reporting and cleanup. If we had the latest version, I'd easily give it an 8 or 9 because it can do so much more.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Director of Network and System Engineering at Allegiant Air
Provides insight into all changes that are done within your network.
Valuable Features:
The visibility of the changes that are being made on the network. From a firewall perspective and router perspective, we have all our network devices in Tufin. We monitor all the changes that are made constantly. Prior to changes being made, they get approved by our IT security department, and then they're monitored after they're changed as well.
We haven't used it to push configuration yet, but we do have a third party network vendor that does our network changes for us. We immediately know if something was typed wrong or configured incorrectly. We'll get an email from Tufin, and we'll know that they typed something in wrong or incorrectly because that's the email that we receive from Tufin. A lot of times they'll transcribe things, and rules will get set in different directions. We'll know immediately when something happens.
Being the Director of Networking, that's what I'm primarily concerned about. It's to make sure that all the network changes that are being made are the correct changes, we're not opening things up to vulnerabilities that we shouldn't have, as well as making sure that we're locking down what we need to lock down.
Room for Improvement:
I like what's there today. I don't use the product that heavily as much as our IT security department does. Right now the product is doing exactly everything that I want to see it done. I would like to see the ability to have the changes in the configurations pushed out more easily and managed through Tufin to eliminate that human error factor more.
Scalability Issues:
We haven't run out of room with the product yet. It's very scalable. We fly to 115 different locations,we have 3 different data centers, and we monitor all our network devices, firewalls and routers through Tufin.
Other Advice:
If you don't have a product like Tufin, get a product like Tufin because it's amazing. It gives you insight into all changes that are done within your network. It's awesome, and it gives you the ability to manage it even though we haven't rolled that piece out ourselves yet.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Manager at a pharma/biotech company with 1,001-5,000 employees
There are a lot of advanced features that we've investigated but the real core strength is for our compliance team to be able to pull the rule usage reports.
Valuable Features
The ability to create out of the box reporting and to have real time awareness of the changes in our environment.
Our operations team will make firewall rule changes and I actually get an email telling me everything that's been done. The way that we have the two things set up it will actually link to the change control that they're doing the work under. I'm then able to review and say "okay, this is what they said they were going to do, this is what they actually did and it's done compliantly."
The reporting simplifies the ability to report towards the business about how our rules are being used so we can make sure the security is always optimally maintained.
Improvements to My Organization
We currently use it at the most fundamental levels. There are a lot of advanced features that we've investigated but the real core strength is for our compliance team to be able to pull the rule usage reports.
Room for Improvement
When we were an early adopter and there were things that were not there, Tufin was very anxious to understand what the need was and then figure out how to integrate it into the product
Use of Solution
Over 5 years.
Stability Issues
It's reaching the edge of stability since we're putting a very strong demand on it. The resources within it are starting to now be challenged. We haven't had any significant issues.
Scalability Issues
We've reached the capacity of the current system and we're looking to upgrade. We went from about 100 firewalls in Tufin to almost 300. We've tripled the demand on the same appliance, but we intentionally bought a large appliance so we could grow into it.
Customer Service and Technical Support
We've used technical support and they've always been excellent.
Implementation Team
I deployed it. It was very easy. That was the one thing that we really appreciated about the product was the ease of deployment, the intuitive nature and that's what was one of it's strengths are. It came on an appliance, it was intuitive to deploy and it made it very beneficial.
Other Solutions Considered
When we selected we actually did a source selection analysis and from there we did a pilot with two of them
Other Advice
Regarding cloud solutions, it's going to be very interesting to do the security assessments with them.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Architect at a wholesaler/distributor with 5,001-10,000 employees
Identifies redundant rules that we're not aware of.
Valuable Features:
The ability for it to identify unused rules, and overlapping/redundant rules. If you had a more open rule at the top, but you put a more granular rule at the bottom, it would tell you that that granular rule wasn't needed because it was already covered by another rule. A lot of times you get multiple firewall admins who just go in and start adding stuff, and they're not always looking for what's already in place. It's redundant and they don't realize it.
So somebody could have added a rule but they couldn't find it, so they just went ahead and added access, and in the end, Tufin will identify it and say - you have rules that you don't need. When you're dealing with very large policies (hundreds - thousands of rules) it's a big advantage. Such as if you're dealing with firewalls that host 2000+ rules.
I used to use the reporting. It was able to at a glance tell me every rule that that particular IP address was given access.
Room for Improvement:
The ability to export the data outside of a PDF on some of the reports, I'm not sure that it can do that.
Scalability Issues:
It scaled for our needs.
Other Advice:
It fits in as part of the bigger picture. At the end of the day, I wish the firewall products themselves could do some of that stuff inherent to their own solution.
Make sure you understand the capabilities and use it for what it's intended. It's not going to tell you the intent of rules, it's not going to tell you if it's a good rule or is it a bad rule, but it's going to help you with firewall clean-up or redundancy. It doesn't help a firewall admin create a better rule.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Tufin Orchestration Suite Report and get advice and tips from experienced pros
        sharing their opinions. 
Updated: September 2025
Product Categories
Firewall Security ManagementPopular Comparisons
FireMon Security Manager
Skybox Security Suite
Palo Alto Networks Panorama
AWS Firewall Manager
Azure Firewall Manager
ManageEngine Firewall Analyzer
Cisco Security Cloud Control
Buyer's Guide
Download our free Tufin Orchestration Suite Report and get advice and tips from experienced pros
        sharing their opinions. 
Quick Links
Learn More: Questions:
- What is the biggest difference between AlgoSec and Tufin?
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Comparing network security vendors and devices
- When should companies use SSL Inspection?
- When evaluating Firewall Security Management, what aspect do you think is the most important to look for?
- What are the most important features you would be looking for in a firewall?
- How do I estimate the required firewall throughput for my organization?
- What are the pros and cons of Tufin, AlgoSec and RedSeal?
- Tasks to Perform on Preventive Maintenance.
- Why is network segmentation important?













