No more typing reviews! Try our Samantha, our new voice AI agent.
Application Developer at CyberAge
Real User
Oct 2, 2022
Very valuable firewall security with decent licensing costs
Pros and Cons
  • "The solution is good, and no clients complained about it."
  • "The solution is good, and no clients complained about it, therefore, I recommend this solution for people seeking to use it, as they can never go wrong with it."
  • "The firewall management is complex for beginners."
  • "The firewall management is complex for beginners, and the solution could be improved by including icons that provide insight into what they are and how they function."

What is our primary use case?

We deployed the solution based on the preferences and needs of our clients. The solution was deployed on cloud and on-premises. However, it was primarily deployed on cloud.

What is most valuable?

The firewall security was very valuable.

What needs improvement?

The firewall management is complex for beginners, and the solution could be improved by including icons that provide insight into what they are and how they function. For example, the ability to understand what an icon does by hovering over it.

For how long have I used the solution?

We have been using this solution for three months.

Buyer's Guide
Tufin Orchestration Suite
August 2026
Learn what your peers think about Tufin Orchestration Suite. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
910,454 professionals have used our research since 2012.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

The solution is scalable.

How are customer service and support?

We have had a good experience with customer service and support.

How was the initial setup?

I rate the initial setup a seven out of ten. Deployment on cloud is done through a web platform, and deployment on-premises takes two to three days.

What about the implementation team?

We implemented it in-house but got assistance from someone with hands-on experience with the product.

What's my experience with pricing, setup cost, and licensing?

The licensing costs for this solution are decent for the services provided. From my perspective, the prices should be higher because the organization that often uses this solution is critical.

What other advice do I have?

I rate this solution a ten out of ten. The solution is good, and no clients complained about it. Therefore, I recommend this solution for people seeking to use it, as they can never go wrong with it. However, for a beginner, it could be tricky to implement.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer1800321 - PeerSpot reviewer
Works at a media company with 10,001+ employees
Real User
Apr 3, 2022
Helps in analyzing the current status of our firewall rules, but its pricing is not transparent
Pros and Cons
  • "We can check and analyze the current status of our firewall rules."
  • "Their pricing can be better. It is not very transparent."
  • "Their pricing is not very transparent. This is my biggest point regarding Tufin."

What is our primary use case?

We are an IT service provider. We are using it in our company and on the customer side. So, we have internal customers, and we are also a solution provider for external customers.

What is most valuable?

We can check and analyze the current status of our firewall rules.

What needs improvement?

Their pricing can be better. It is not very transparent. 

In terms of functionality, we have not had any particular or special disadvantages other than the integration, but every tool that you take to integrate with your infrastructure is more or less complicated. For example, you have a history in your firewall infrastructure, and the longer the history is, the more you have to work on it to integrate. We see that in our infrastructure. We have been a service provider for more than 40 years, and we have been on the market for 20 years. We have a lot of customers, and there are some individual requests and setups. For the integration of Tufin or any other tool, you need a certain level of standardization. We have more disadvantages on the site from different firewall vendors. For example, with Drupal, you can integrate any individual firewall, but for Fortinet, you have to use a Fortinet manager.

We are not looking for any additional features at the moment. We are not planning to buy any other modules.

For how long have I used the solution?

I have been using this solution for five years.

What do I think about the stability of the solution?

Until now, we have not had any problems in terms of stability.

What do I think about the scalability of the solution?

It has been scalable so far. We don't have any issues.

On the administration side, 15 people are working with it.

How are customer service and support?

I would rate them a six out of 10. In many cases, we had to escalate.

Which solution did I use previously and why did I switch?

I didn't work with a similar product previously.

How was the initial setup?

Its implementation process is complicated.

What's my experience with pricing, setup cost, and licensing?

It is expensive, but as compared to other players, it's more or less okay. Their pricing is not very transparent. This is my biggest point regarding Tufin. I've never seen a price list or something like that. It's always individual, and in many cases, it's very confusing to know what is the base and what is the price.

What other advice do I have?

I would advise thinking about which modules you really want to use. We are using it only to have a transparent view of the firewall rule base and nothing more. We are not using any modules of this solution because we want to be and stay independent. For example, for the execution of the firewall rules, we use our own system. We have also developed all the other things ourselves so that in the future, we can switch to another product. So, you have to take care that you are not fully dependent on Tufin. 

I would rate it a seven out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Tufin Orchestration Suite
August 2026
Learn what your peers think about Tufin Orchestration Suite. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
910,454 professionals have used our research since 2012.
reviewer1033653 - PeerSpot reviewer
DSI France retail banking networks at a financial services firm with 10,001+ employees
Real User
Jan 27, 2022
Suits customer needs in complex environments but licensing model for routing devices could be simplified
Pros and Cons
  • "Policy management and the cartography of the network have been the most valuable features."
  • "Once it is done, the solution runs by itself; exporting, reporting, topology, and changes are all handled by this solution."
  • "The network part of the solution could be improved. It's too hard because of the Tufin licensing model for the routing devices."

What is our primary use case?

We use the solution on-premises.

What is most valuable?

Policy management and the cartography of the network have been the most valuable features.

What needs improvement?

The network part of the solution could be improved, specifically the licensing model for routing devices. Customers need to get the license easily in order to have the cartography of the network and build the other solution of Tufin, such as a secure change and secure application. To do that, we need the licenses for the network devices in complex environments where customers have a lot of network devices. It is too hard to get a license for each device, so Tufin should remodel the license model for these kinds of devices.

For the license for the security devices, it's okay that Tufin has a model for physical devices and for virtual devices. For the network devices, the main reason to have a license is to get topological information, routing information, and so on. With Tufin, it's a bit hard to tag all the devices that you need to build the topology of your network. 

We have already talked to Tufin in order to simplify the license model for the routing devices because these devices are the main technology. The RN is just for routing information, not for the security and building access list, and building VPNs, and stuff.

In order to have that topological view, you need a license for each device. For that, the cost of the solution rises exponentially. Because there are a lot of routing devices for your network, in order to build the topology of your network, you have to spend a lot of money just on licenses for devices that aren't security but do routing work only.

They have to rebuild their licensing model in order to fit the needs of their customers.

For routing devices, we would like to have something related to the orchestration for the solution because we know that there is one for Tufin, but I don't know how it works, if it has to work with all the models installed, what the features are for that orchestration, and what the needs are for that model to work properly in a complex environment. 

For example, we work in complex banking environments where there are a lot of bricks to communicate with. For that, what is the information needed for the orchestration in order to have an extensive look at the topology of our network, and after that, how the orchestration is going to implement the right accesses to main privileges on security devices all around the topology of our employment.

For how long have I used the solution?

I have been using this solution for five years.

What do I think about the stability of the solution?

We didn't have a lot of problems regarding the solution. It's a stable solution.

In order to have it running correctly, we had to dedicate a person to manage the solution. I work on it with Tufin and with some of our partners in the group. We have our Société Générale in the group. We have some other partners inside the group with Tufin in order to build this kind of model for the time to market objectives.

We didn't have a lot of problems concerning maintenance. We had two or three hardware problems that were solved remotely by support and for the upgrade and the OS upgrade because there are two kinds of upgrades to operate. The OSTs and the secure channel also have upgrades, which we did ourselves.

Tufin has a policy of publishing new versions of the Dell OS, so two versions a year. One is a final version, and the other one is a beta version. In a year, you get two or three updates. It's not very hard to follow the stream of changes in one year.

What do I think about the scalability of the solution?

We didn't have to expand the solution, but management has had thoughts about expanding the solution for other environments, for other clients, and for the customers.

How are customer service and support?

Technical support was present and responsive for our needs. We had some problems with the appliances. They were very quick to respond to our support tickets and to give the right solutions for the problems we had.

On a scale of one to give, I would give technical support a four.

How was the initial setup?

We needed someone from Tufin in order to get it installed. It's not a straightforward process from scratch. You have to build your own network with someone from the PS, and after that, you have to give a lot of information about your network, your devices, where they are located, what is the networking scheme of your network so that the PS can implement all that. After that, they can build the model for you.

On a scale of one to five, I would rate initial setup a three.

What about the implementation team?

We used engineers from Tufin for setup. They were responsive. They were experienced with the solution they sell.

What's my experience with pricing, setup cost, and licensing?

There is a permanent license for devices, but it's not relative to a device itself. Once you purchase 10 licenses for virtual appliances or virtual context, you can put them into different virtual firewalls, but you can reuse these licenses for other devices if you don't need them for the old ones. 

For example, if you deploy new ones, and you don't need these licenses for the old context, you can redeploy them in another one relative to a device, like a Mac address.

The problem is that once you redeploy the license for another context, another rhythm, or another virtual appliance, you lose all the history and reports from the Syslog from the old one.

Which other solutions did I evaluate?

I haven't looked into the competition because we don't have the ability to choose between solutions for central management.

What other advice do I have?

I would rate this solution 7 out of 10. 

The main brick in order to build your solution is the first step, which is having a good understanding of your network and good people to talk to when you want to build your topology. Once it is done, the solution runs by itself. Exporting, reporting, topology, and changes are all handled by this solution.

After the initial deployment, it is a stable solution. It can suit customer needs in complex environments.

A con is that it is very needy in terms of implementation such as small configurations. We had that problem with networking devices. We had to implement it to get all the information from all the routing devices. Even if they don't belong to our network, we had to have the information from MPLS devices on the telecom operator. Sometimes it was difficult to build the solution from scratch.

The Syslog part was a little difficult to handle. For the appliance we have right now, it handles the management, the Syslog, and all the needed modules in order to operate the solution. Sometimes, it is a little bit hard for the appliance to get straight to all the models it runs. Maybe with the new models of the appliances, it's easier for the appliances to run all the models. With the newer generations of the OS, I suppose that now it's more effective and less of a time-consuming process, but it's okay for us to upgrade after that in order to get all the new features in the new OS.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer898362 - PeerSpot reviewer
Information Security Engineer at a healthcare company with 10,001+ employees
Real User
Nov 21, 2021
Provides clarity around auditing but is a little behind on some of their support for the Palo Alto firewall platform
Pros and Cons
  • "The clarity around the auditing provides the most value for us."
  • "I am able to see auditing changes and changes in our firewall platform more clearly than with the native tools."
  • "They are a little bit behind on some of their support for the Palo Alto firewall platform. I'd like to see that catch up, specifically around importing certain objects."

What is our primary use case?

There are five people using this solution in my company. I manage the team that utilizes Tufin. I have had experience with the demos that my team has given me in relation to the auditing of our Palo Alto platform.

I'm a consumer of reports. The reports are clear as long as they're set up correctly. I'm able to see auditing changes, and changes in our firewall platform more clearly than with the native tools. It seems relatively useful. It can also provide guidance on different configurations that we have. 

The solution is on-premise.

What is most valuable?

The clarity around the auditing provides the most value for us.

What needs improvement?

They are a little bit behind on some of their support for the Palo Alto firewall platform. I'd like to see that catch up, specifically around importing certain objects.

What do I think about the stability of the solution?

From the Palo Alto platform, I remember hearing that Tufin required an update, so that would've been the only flash issue.

How are customer service and support?

Their customer support is responsive.

What's my experience with pricing, setup cost, and licensing?

The pricing is reasonable.

What other advice do I have?

I would rate this solution 7 out of 10.

My advice is to look at what is currently supported in whatever security technology you have because some of the features may already be covered. However, if you identify a gap in what you currently have, specifically around auditing, then I would definitely suggest looking at Tufin.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Executive Director at a financial services firm with 1,001-5,000 employees
Real User
Jun 7, 2021
Works well with simple topologies; ingestion of flow data could be enhanced
Pros and Cons
  • "All the basic functions work well."
  • "Lacks ability to create a Terraform that would enable deployment without manual steps."
  • "It works really well when you have a single-vendor solution but it's just not as intuitive if you have back-to-back firewalls or you have a complex topology."

What is our primary use case?

Our primary use case is trying to make sure that when firewall rules are requested, they meet our compliance. Tufin has a notion of a universal security policy, where you line up the policies and we use the solution for that. We also use it to track all of the changes. I'm the executive director of the company. 

What is most valuable?

Tufin gives us the rule, definitions and things of that sort, which is great. All the basic functions work well. 

What needs improvement?

Our compliance goes through SecureChange and they give us the rule set and then the recommendation. Ideally we'd like to press a button and create a Terraform to put into the build and deploy. We can't do that yet and there are several manual steps which can lead to errors. We'd like that to change. 

I would also like to see the ingest of flow data enhanced, so that multiple flow data can be ingested from different points on the network and be mapped out. The basics work, the issue is when you have a complex network because maybe you want flow data from the firewall and with Tufin it's only from a single source.

For how long have I used the solution?

I've been using this solution for over two years. 

What other advice do I have?

Tufin is a good company. I think most of the products in this market have difficulty working across a multi-vendor solution, and that also applies with Tufin. It works really well when you have a single vendor solution but it's just not as intuitive if you have back-to-back firewalls or you have a complex topology. For simple topologies, it works really well.

There are currently some issues with this solution but if things improve with the new version, which apparently has some enhancements, I would give them a higher rating. For now, I rate this product a seven out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1126947 - PeerSpot reviewer
Project Manager at a comms service provider with 10,001+ employees
Real User
Apr 16, 2021
Good change manager and technical support but needs to be more comprehensive
Pros and Cons
  • "The technical support is pretty good."
  • "We really appreciate the change manager; it's one of the most valuable aspects of the solution."
  • "The pricing of the solution is rather expensive."

What is most valuable?

We use two main modules. We really appreciate the change manager. It's one of the most valuable aspects of the solution.

The technical support is pretty good.

What needs improvement?

We need the solution to have full compliance with IPV6. 

We also use VMware features and we need the solution to be fully integrated. We used to make micro-segmentation. We'd like to be able to do this again, and for that to happen, we need more integration.

The pricing of the solution is rather expensive. 

It needs to be more comprehensive. There are also some drawbacks in trying to import a policy matrix inside. If some people design a policy matrix in the file, in an Excel file, the problem is that we will have to work a bit to interact with it properly. Something more economical needs to be in place to deal with the policy matrix.

What do I think about the scalability of the solution?

We have a small team working with Tufin. That said, even though the team is not a big team, we have a lot for it to do. Tufin now is our policy manager for the private cloud. It's the main policy manager. We also use Skybox for the legacy part.

How are customer service and technical support?

I've dealt with technical support in the past. They are okay. They really try to work with us. I'd describe them as being helpful and responsive for the most part. We're largely satisfied with their level of service.

Which solution did I use previously and why did I switch?

We also use Skybox Security Suite. We use both that and Tufin simultaneously.

How was the initial setup?

The initial setup was actually handled by another team. I can't speak to the implementation process due to the fact that I did not participate in the process directly.

What's my experience with pricing, setup cost, and licensing?

As an architect, the pricing seems expensive to me. For what it does, I would say it's expensive. 

Which other solutions did I evaluate?

I can only really compare it to Skybox, which is a solution we also use. 

If I compare it with Skybox, I see it is the best. It is better than the Skybox. However, we need it to do more. 

What other advice do I have?

We are not a reseller. We are an IT enterprise. We are customers and end-users. That said, our relationship is evolving. It's becoming something like a partnership, as we need more features and are making suggestions and trying to develop it out a bit. 

I'm not sure of which version of the solution we're using. I can't recall the version number off-hand.

I'd rate the solution at a seven out of ten.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Information Technology Graduate at a computer software company with 10,001+ employees
Real User
Aug 3, 2021
Provides great visibility, allows us to automate the entire change process, and saves A LOT of time
Pros and Cons
  • "Visibility is its largest and most valuable feature. You can see everything or all the devices on the network for each customer. It provides you a larger view of what might be wrong with the network and how you can improve it with firewall rules, etc. If you are talking about secure change, being able to automate the entire change process is pretty much the winner for us. It is going to really reduce the time that it takes for us to do changes, and we can just go out and get more customers."
  • "The huge ROI we witnessed has resulted in us identifying that we can go to market to gain more customers and really broaden our customer base without the 'con' of hiring more people."
  • "They've got such a large number of APIs, and it is so easy to use their APIs. Effectively, they allow us to use it with anything. The only way to improve it more is by offering support for implementing their APIs into certain hardware or software that we might use. They can provide support for implementing APIs."
  • "This is the biggest drawback to Tufin integration."

What is our primary use case?

Some of our customers has Tufin, and we manage it. We're also planning to have our own Tufin that we're going to use as a leveraged service for all of our customers.

What is most valuable?

Visibility is its largest and most valuable feature. You can see everything or all the devices on the network for each customer. It provides you a larger view of what might be wrong with the network and how you can improve it with firewall rules, etc. 

If you are talking about secure change, being able to automate the entire change process is pretty much the winner for us. It is going to really reduce the time that it takes for us to do changes, and we can just go out and get more customers.

What needs improvement?

They've got such a large number of APIs, and it is so easy to use their APIs. Effectively, they allow us to use it with anything. The only way to improve it more is by offering support for implementing their APIs into certain hardware or software that we might use. They can provide support for implementing APIs.

For how long have I used the solution?

We have been using this solution for three months.

How are customer service and technical support?

I have not contacted their technical support.

Which solution did I use previously and why did I switch?

We didn't work with any similar product, but we are just going with secure track and secure change, not secure cloud and secure app. That's all that we really need at this time, and obviously, we will work with Tufin in the future if we need more.

How was the initial setup?

A few of our clients have decided to implement Tufin themselves, whilst we just manage their firewalls. We were not involved in the setup of the management suite. However, after seeing the benefits of this, we have heavily considered the use of Tufin on a number of our other clients we manage.

We have identified that setup is a part of this and in our conversations with Tufin sought to address this. They offer a service for the full setup of the platform for use as an MSSP, and then providing a hand off service towards the end of this setup process which teaches engineers how to setup the remaining required devices.

For the full functionality, Tufin utilises all L3 devices on the network, so setup can be quite daunting. However, we identified that it would take ~30 minutes per L3 device, some of which can be done simultaneously. This is the biggest drawback to Tufin integration. However, Tufin can be used to some degree without this, meaning you can reap the benefits of it sooner rather than later.

What was our ROI?

What we found is that the return on investment will be pretty quick. This is because of the time saving that Tufin offers in FW changes, we can implement more changes at a faster rate. This has huge savings for employee's workload and the cost of their work. We have freed up a large majority of our FW engineer's time. The huge ROI we witnessed has resulted in us identifying that we can go to market to gain more customers and really broaden our customer base without the 'con' of hiring more people.

What's my experience with pricing, setup cost, and licensing?

Because we're quite a large company, the initial price wasn't too much of a factor for us. This is because the ROI was so significant for us.

Which other solutions did I evaluate?

We identified others, like Firemon and Skybox, however we found that they were not as mature as Tufin, not offering the same range of Firewall Vendors, e.g. Palo Alto, Check Point, etc., and the same level of automation.

What other advice do I have?

I would advise others to definitely work with Tufin and work out the best costs. Work out how soon you'll realize your return on investment. That has been a major kind of help. They've been brilliant in trying to help us develop a business case for using it, and then internally, I am sure there will be a massive help for implementing it in the future.

I would rate Tufin a nine out of ten based on the whole experience that we've had with it and the real kind of capabilities of the product.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1181328 - PeerSpot reviewer
IT Coordinator at a financial services firm with 10,001+ employees
Real User
Apr 29, 2021
Stable, good support, reasonable price, and useful for controlling and monitoring firewall rules
Pros and Cons
  • "It is an important application for controlling and monitoring firewall rules, and it is useful for making and monitoring the changes."
  • "Its price is reasonable, but it could be lower. It could have a more effective approach for creating and changing rules. It could provide advice or suggestions for a better understanding of rules and changing the rules. There should be suggestions for the rules that need to be changed to make them less risky."

What is most valuable?

It is an important application for controlling and monitoring firewall rules. It is useful for making and monitoring the changes.

What needs improvement?

Its price is reasonable, but it could be lower. 

It could have a more effective approach for creating and changing rules. It could provide advice or suggestions for a better understanding of rules and changing the rules. There should be suggestions for the rules that need to be changed to make them less risky.

For how long have I used the solution?

I have been using this solution for eight months. We have recently done an upgrade, and we are using the latest version.

What do I think about the stability of the solution?

It is stable.

What do I think about the scalability of the solution?

We have not been using it for a long time. So far, it is scalable for us. We have more or less ten people.

How are customer service and technical support?

Their technical support is good.

Which solution did I use previously and why did I switch?

We have worked with AlgoSec but in a restricted topology of the network. Both of these solutions are useful. It mainly comes down to the price. Even though Tufin is more costly, it has been more cost-effective for us, but it is not the same for all companies. It also depends on the integrator.

How was the initial setup?

Its initial setup has medium complexity. It was not complex, but it was also not easy. We had some problems because it was a fresh installation.

What's my experience with pricing, setup cost, and licensing?

Its price is reasonable, but it could be lower. It has been cost-effective for us. We have a contract for three years.

What other advice do I have?

I would rate Tufin a nine out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Network manager at Ekol Lojistik AS
Real User
Apr 28, 2021
A stable and scalable security solution with a user-friendly GUI
Pros and Cons
  • "It's user-friendly. It's easy to understand menus on the web GUI. That's a good feature for us. I can say that it's doing what it's supposed to do. It also integrates well with other products like Check Point."
  • "I also have AlgoSec, and it seems to be much more complicated."
  • "It would be better if they modernized the web GUI. The web interface GUI is simple and not complicated, but it's also too old."

What is our primary use case?

We're using this solution mainly to get some audit reports regarding the policy installations on our firewalls. We aren't using any changes or other features, and we're not installing policies automatically. We're just using it to collect some log data like who installed something and what they did.

What is most valuable?

It's user-friendly. It's easy to understand menus on the web GUI. That's a good feature for us. I can say that it's doing what it's supposed to do. It also integrates well with other products like Check Point.

What needs improvement?

It would be better if they modernized the web GUI. The web interface GUI is simple and not complicated, but it's also too old. It would also be better if they had an SMS gateway integration. I would like to have some integrations with other products like Jira for change management and incident management.

For how long have I used the solution?

I have been using Tufin for about three years.

What do I think about the stability of the solution?

Tufin is a stable product. We're not having any issues. Sometimes we do have problems with the product, but it wasn't related to Tufin. Sometimes when we had an upgrade on the firewall product itself, we encountered some problems.

What do I think about the scalability of the solution?

It's a scalable product. We have about 50 gateways, and Tufin collects data from all of them. We also have a management server, and we've integrated two important classes of databases. We're only using three instances, and we're not having any issues.

How are customer service and technical support?

Tufin support is good, and we managed to implement this solution by ourselves. But it would be better if some engineers from Tufin joined a session and did stuff together with us. That would have been much appreciated. I would expect them to organize the session and provide some support, at least in the beginning.

Which solution did I use previously and why did I switch?

I also have AlgoSec, and it seems to be much more complicated. I would say that Tufin is much more compatible with Check Point firewalls. That was the main reason for choosing Tufin over AlgoSec.

How was the initial setup?

The initial setup is complex. I didn't have any Linux knowledge in my past, but I could say Tufin support is good at it. When we need to get some support, they respond quickly. They explained everything to finalize issues regarding the installation.

What about the implementation team?

We implemented this solution by ourselves. It took us one or two hours to install and deploy this solution.

What's my experience with pricing, setup cost, and licensing?

The price is on the cheaper side. I'm not planning on adding additional resources, and I don't expect any additional costs.

Which other solutions did I evaluate?

Not before but after using tufin actively about a year, we have evaluated algosec as an alternative solution. It was also well designed alternative but it was not well integrated as tufin did with Checkpoint

What other advice do I have?

There aren't many products like Tufin and AlgoSec. I think both products are good, but when people are using Check Point applications, we recommend Tufin.

On a scale from one to ten, I would give Tufin a ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1543566 - PeerSpot reviewer
Principal Consultant at a consultancy with 1-10 employees
Consultant
Apr 24, 2021
Good visibility, user-friendly, and stable, but needs better graphical representation capabilities
Pros and Cons
  • "Being able to customize your own clarity to that aspect of change management."
  • "The most valuable feature is being able to customize your own clarity to that aspect of change management, having better visibility of what is going on, and from what I have seen, it's user-friendly."
  • "I would like to see AI elements included with this solution."
  • "It's a bit clunky, but that may be because of different environments, and it is struggling to get the information."

What is our primary use case?

The solution is predominantly used for managing firewall changes, policy changes, and understanding those aspects.

Most people use it for the basics, even though they could use it for a lot more.

What is most valuable?

The most valuable feature is being able to customize your own clarity to that aspect of change management.

Having better visibility of what is going on. If it gets out of control, you can keep it in your head no matter how smart your administrators are.

From what I have seen, it's user-friendly.

What needs improvement?

It's a bit clunky, but that may be because of different environments, and it is struggling to get the information. It's possible that the performance issue is because of the network and not the right architecture.

I would like to see anything that is graphical, as much graphical representation of things. Modeling, and what-ifs. It becomes more intuitive and allows you to close some of the gaps between drawing stakeholders in, for example. If they ask "Why are you spending so much money on this tool?"  or "Why are you doing this?", you can show them examples and it becomes more obvious.

I would like to see AI elements included with this solution. There is quite a lot of human element in understanding the consequences of change within the firewall environment, but they might benefit from more of an AI element as well.

For how long have I used the solution?

I am a security architect and I have been involved with it periodically for approximately five years.

What do I think about the stability of the solution?

It's a reliable solution.

What do I think about the scalability of the solution?

It's a scalable product. I have dealt with companies that are pretty sizeable, and it seems to handle it.

How are customer service and technical support?

I personally have not contacted technical support, but the information that is available on their website is pretty useful, it's pretty good.

How was the initial setup?

You need to allow a fair amount of time. That is the case for all firewall management tools.

It gives the appearance of being straightforward to get going but they need a bit of time particularly to do the sorting of the matrices for example.

When planning, people should estimate it then double it, just to make sure they get things right.

What's my experience with pricing, setup cost, and licensing?

Price could always be better, but there are always consequences. Normally, there are other issues that come into play. For example, you pay more and expect to lean on the vendor more for the services and support.

What other advice do I have?

I have recommended this solution from time to time and I would definitely recommend it to others.

I would rate Tufin a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Tufin Orchestration Suite Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2026
Buyer's Guide
Download our free Tufin Orchestration Suite Report and get advice and tips from experienced pros sharing their opinions.