Try our new research platform with insights from 80,000+ expert users
it_user489249 - PeerSpot reviewer
Network Security Engineer at a pharma/biotech company with 10,001+ employees
Real User
I like how it optimizes your policy, and does a compliance check and risk analysis.

What is most valuable?

I like how it's able to optimize your policy, look at the objects, and other similar functions. We only have Check Point integrated with Tufin SecureTrack, so that's a key benefit of using it. We can check policies against past policies. It does a kind of compliance check or risk analysis if there are unused policies or unused objects. It highlights them and it gives you a good view of what doesn't need to be there.

What needs improvement?

It would be better if Tufin could integrate with the Cisco routers, FireEye, and other devices like that, so you can do the routing changes and so on straight from SecureChange. That would be good.

I haven't looked at their latest versions or releases, what's new, and what's not. We're still running a version that's at least a year old, so I still have to look at it. If they have added integration with Cisco routers already, that's good, but we don't have that in the version that we have. It doesn't support Cisco routers at all.

What do I think about the stability of the solution?

It's been stable in our multi-domain environment. We have more than 20 or 30 policies.

Which other solutions did I evaluate?

When we were looking at products that can do this, I think we only looked at Tufin. Its integration with Check Point is what led us to Tufin. That was the main reason why we looked at it.

Buyer's Guide
Tufin Orchestration Suite
February 2025
Learn what your peers think about Tufin Orchestration Suite. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.

What other advice do I have?

I hope that Tufin just keeps doing what they’ve been doing. We look forward for future enhancements.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user489237 - PeerSpot reviewer
Network Security Operations Manager at a non-tech company with 1,001-5,000 employees
Vendor
We use it to record policy changes, and the speed is good.

Improvements to My Organization

We're using it to write down policy changes. We have lots of jobs making firewall changes. We track down all of those in the reports and we can see what is going on. If something goes wrong, we can track down the latest changes and determine how to fix it.

Room for Improvement

We would like to use Tufin through the cloud. We don't want to keep the hardware or all those devices on premises, where we have to manage them and upgrade them. If we could use Tufin through the cloud, we could just tweak the firewalls, keep the changes, and then track them.

Right now, Tufin is on premises, which means we have to manage it, we have to upgrade it, and we have to take care of the devices. The infrastructure is not very critical for us, and we just need to use it, so we would prefer to use it through the cloud. Everything is in the cloud.

Stability Issues

I have not found it to be slow at all. The speed is good. At first, we installed Tufin in one of our offices, but now we are using it everywhere.

Customer Service and Technical Support

Technical support has been good.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Tufin Orchestration Suite
February 2025
Learn what your peers think about Tufin Orchestration Suite. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
it_user489264 - PeerSpot reviewer
Sr Network Security Engineer with 1,001-5,000 employees
Real User
I permanently use it for their Automatic Policy Generator, and for object lookup.

Valuable Features

I permanently use it for their Automatic Policy Generator, and for object lookup.

Improvements to My Organization

We use Tufin for object lookup. We often get requests from the business. They give us an IP and they request something like, "We need to know what the rules are for this.", so they can add more similar rules. We go into the object lookup, give the IP that we're looking for, and then it generates a report, either Excel or PDF.

We have probably a hundred policies using Tufin.

Room for Improvement

I would like to see a little bit more of enhancement on their PCI-compliance piece. We reviewed a Skybox product. They seem to be doing a lot better than Tufin does on the PCI reports.

Scalability Issues

I think we're ready for an upgrade, it's getting kind of slow. They did tell us that you can break up the database in the actual server application into two separate units. That's supposed to make it a lot faster. I think we'll probably do that in the next upgrade.

We have seen some slowness, but I think it's because we're on some aging hardware. We're quite larger than a lot of people that probably use it too. It has been scalable for our size so far.

Customer Service and Technical Support

I actually hadn't really had the need to reach out to technical support. We're a pretty big customer of theirs, and they're always coming around. I usually deal with my technical issues when they do that.

Implementation Team

I went through one upgrade, but they already had Tufin when I arrived.

Other Solutions Considered

We did a proof of concept to compare Skybox and Tufin.

Other Advice

It’s a pretty good product. The PCI compliance piece probably accounts for the rating of 8 as opposed to ten.

As far as comparing Tufin with another product, I would just look at some of Tufin’s features like the APG that is not used that often, but it's a really good feature. They do also have an extended tool section where you can kind of get a little bit more in depth.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user437142 - PeerSpot reviewer
Senior Security Consultant at a comms service provider with 10,001+ employees
Real User
We use it for PCI audit compliance.

What is most valuable?

Audit compliance. We need the PCI audit compliance and that's what Tufin delivers for us.

How has it helped my organization?

Before we'd have to manually go down rule bases three-thousand lines long, rule by rule finding the stuff that's missing. So it saves us a lot of time.

What needs improvement?

Well there's parts of the product that we can't use, the SecureChange, the network address translation, and users as it's all very difficult, so we've never managed to use it for that. We just use it for PCI and for rule based management, rules that have no hits, and I use it to help with the rule-based.

What do I think about the stability of the solution?

It's only broken twice in the ten years we've had it, so it's very good.

What do I think about the scalability of the solution?

It scales because you can put multiple devices in multiple networks. We've got some things where the firewalls aren't routable back to the central, so we can put these proxy-serve type things in, so it's very scalable. You can have as many of them as you want.

How are customer service and technical support?

I've used them only twice. Once for an RFE and once for a little issue that we had. I found them very knowledgeable, and UK based.

Which solution did I use previously and why did I switch?

We bought Firemon in the interim and then got rid of it and went back exclusively to Tufin. We had a special environment and Firemon came in, took a pitch, and it was cheaper than Tufin and it checked all the boxes. But when it was actually deployed in the network it didn't fit the purpose so we cut our losses.

How was the initial setup?

Very easy. You need Check Point skills for sure, and it goes with other products as well.

Which other solutions did I evaluate?

No, we didn't. We went straight to Tufin initially because we bought it. There wasn't anything else back then, because we got it ten years ago.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user437187 - PeerSpot reviewer
General Manager at a tech services company with 51-200 employees
Consultant
The most valuable feature for us is SecureTrack. With it, we have rule documentation, change documentation, and the ability to create various reports.

Valuable Features

The most valuable feature for us is SecureTrack. With it, we have rule documentation, change documentation, and the ability to create various reports. We can also enforce compliance with our security policy, as well as to define exceptions.

Another valuable feature is SecureChange, which enables us to have individual workflows. Individual workflows have to be followed step-by-step without skipping a step. That's the great thing that we can do with automation so that firewall administrators don't have to do so much manual, routine work.

Improvements to My Organization

There's an automatic compliance check. If you have an accessory test from A to B, the system will check the entire firewall infrastructure to see if it's possible immediately or not, and if it's not possible now, then the change will be started, and if it's a standard change, the standard change will be run more or less automatically, and it's not necessary to involve the technical team for a standard change.

Room for Improvement

The GUI is not really adaptable as you cannot configure it. The buttons are fixed and it's not really intuitive. It's good for selling training, but in daily work, it's not very easy for those who are new at it.

Deployment Issues

We've had no issues deploying it.

Stability Issues

I think the stability is very good. We've had no issues with instability.

Scalability Issues

It scales from small network segments up to very, very big companies with thousands of firewalls.

Customer Service and Technical Support

Once I heard from a German Tufin guy something about enthusiastic support, and I thought he was crazy. But now, I think it's true. Even when there's standard support, I become nervous when I don't get feedback within one or two hours, even if the SLA says twenty-four hours. They're very responsive, and also very technical. Technically, they're quite good.

Initial Setup

It depends, but mostly the initial setup is straightforward. Just install the operating system, take the appliance, install the software, and then connect all the devices you want to monitor, then you have the basis. Maybe it takes some effort to implement or to import unsupported devices, or defining generic devices and so on. But the standard installation is very straightforward and easy.

Other Solutions Considered

I don't evaluate other vendors every two weeks, but I've evaluated them before, and I think Tufin is quite a technically-leading solution. It's very robust and Tufin has focused on stability and topology. Correct topology is the main factor for authorization speed, and Tufin is the best.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user437145 - PeerSpot reviewer
Head of Network and Security at a financial services firm with 1,001-5,000 employees
Vendor
We use SecureTrack to walk us through the implementations of our firewalls and for all our policy checks, reporting and overview of our monitoring policies.

Valuable Features

We use SecureTrack to walk us through the implementations of our firewalls and for all our policy checks, complaint checks, and reporting and overview of our monitoring policies.

Improvements to My Organization

It's given us an easier workflow since we go through the different steps of network validation to make sure that the request coming from the user is technically sound and implementable. It also helps us with security validation, that is, compliance with company goals and so on. We've also added change management so that we're able to implement solutions at the at the optimal time.

Room for Improvement

I'd like to see automation of a number of steps. In particular, I think that the implementation and validation steps that we're currently doing manually should be automated. Even the input part at the beginning of our workflow could be automated with a link to our ITSM solution.

Deployment Issues

Deploying it has been without issues.

Stability Issues

I have no instability issues at all. It’s working so well that I’m not worried about it.

Scalability Issues

We have a number of firewalls with no concerns about scalability.

Customer Service and Technical Support

I have had a number of discussions with mostly the sales team and some engineers on how to go ahead and implement some things. So technical support in that regard has been great.

Initial Setup

I wasn’t involved because I wasn’t in with the company at that time. I was involved since April and we had some upgrades to perform. It was straightforward and we had no issues with it.

Implementation Team

We've implemented with just our in-house team since the initial setup.

Other Solutions Considered

We looked at some other solutions at events, but they are not as advanced or complete as what you get from Tufin.

Other Advice

Give it a try.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user400692 - PeerSpot reviewer
Security Advisor at a financial services firm with 10,001+ employees
Real User
We're able to generate reports to know what's going on with our rules, specifically expiration dates and PCI's, for our firewalls.

Valuable Features

We're able to generate reports to know what's going on with our rules, specifically expiration dates and PCI's, for our firewalls. It lets us know exactly what's happening.

Room for Improvement

When we make changes, we need to know exactly what's going on between each firewall and why a rule may pass or not pass between each. It would be good if Tufin gave us the ability to do this in a graphical way.

We have sixty firewalls, and sometimes the path between any two firewalls may have five rules. We need to know exactly what is going on and where we have to implement a rule. It's very complicated to do right now, and that's why we want to implement a security change.

Deployment Issues

We've had no issues with deployment.

Stability Issues

We've had no issues with stability.

Scalability Issues

We've had no issues with scalability.

Customer Service and Technical Support

We need a vendor that has good, responsive support. Tufin support has been that.

We have a virtual firewall and when we ran our system, there was a problem with mismatched object rules. We called support to help us clean the firewall. The rep looked around and, after an hour-and-a-half, confirmed the problem. Then another five or six technicians analyzed our request and, after three or four days, released a fix for us.

Initial Setup

We had no issues with the setup.

Other Solutions Considered

There may be a better product a year from now, but we're using Tufin now and we're satisfied with it. We'll use it until it doesn't do the job. It's a big deal changing firewall vendors, so we don't want to change unnecessarily.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Profferefb28 - PeerSpot reviewer
Professional Services Engineer at a tech services company
Reseller
While the product was a little slow, it did look full-featured
Pros and Cons
  • "The initial setup was straightforward."
  • "I needed more help getting the product to work in the lab."

What is our primary use case?

Our primary use case for this solution is firewall remediation.

I didn't get very far with it because I didn't used Tufin in production, only during the evaluation phase.

How has it helped my organization?

I tested it for the change orchestration. That is what my evaluation recently was specifically for. While the product was a little slow, it did look full-featured. 

What is most valuable?

The firewall remediation and compliance pieces are the most valuable features. 

What needs improvement?

I couldn't get it to work in the lab, even with help, on multiple occasions, from one of Tufin's engineers. It was set up in my private lab per all their instructions, and I gave them control of the system. However, they were unable to make it install the policies to Check Point in an automated fashion. So, I unfortunately gave up on the proof of concept at that point.

What do I think about the stability of the solution?

In terms of stability, the version I tested in the lab was okay.

What do I think about the scalability of the solution?

I don't know about the scalability, as I never got it out a very small VM.

How are customer service and technical support?

Their technical support was okay. I needed more help getting the product to work in the lab. 

Which solution did I use previously and why did I switch?

We did not have an automated provisioning solution. At that time, all firewall changes were being implemented manually by administrators.

How was the initial setup?

The initial setup was straightforward. 

What about the implementation team?

I was working directly with Tufin's sales team and SEs.

Which other solutions did I evaluate?

We looked at AlgoSec and Tufin. However, we did not chose Tufin because of the issues.

What other advice do I have?

Check the product out for yourself.

I wasn't using it for visibility into my firewall infrastructure, because I have other avenues.

I wasn't using the compliance portion when I was testing it, only the orchestration.

I want to look at Tufin for remediation and compliance in the future.

Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
PeerSpot user
Buyer's Guide
Download our free Tufin Orchestration Suite Report and get advice and tips from experienced pros sharing their opinions.
Updated: February 2025
Buyer's Guide
Download our free Tufin Orchestration Suite Report and get advice and tips from experienced pros sharing their opinions.