Try our new research platform with insights from 80,000+ expert users
Consultant at Critical Design Analytics
Reseller
The change workflow process is very easy to customize
Pros and Cons
  • "The change workflow process is very easy to customize. You can do a workflow however you want, so you can have an approval every single step. Or, you can remove approvals on certain steps, automating some steps."
  • "We have had a couple issues with the VMs, but I think it was just because they were starving for resources. A recommendation on what the virtual appliances should have for resources would be appreciated."

What is our primary use case?

We implement Tufin for other customers and help set it up. 

I'm not the end user. I just set it up for the end user.

We are using the latest version from 2018.

How has it helped my organization?

We use Tufin to clean up our firewall policies. They already have the compliance policies sort of prepopulated in there to point out violations.

Most customers will go through and check the USP to see if it violated with the designer tool.

We are in the process of working with a customer right now to set up the Unified Security Policy (USP). We got all the violations from the first phase and will go through to do the mediations, then run the scan again to show the progression of the clients.

What is most valuable?

The preconfigured PCI compliance USPs are the best part for me. These make things a lot easier.

The visualizer for the Network Topology is really good. You can see all the routes throughout your entire environment.

The change workflow process is very easy to customize. You can do a workflow however you want, so you can have an approval every single step. Or, you can remove approvals on certain steps, automating some steps.

It capabilities are very good.

What needs improvement?

Sometimes, the user interface is a little cumbersome, trying to navigate between them. In the new version, it looks like they resolved those issues. 

Buyer's Guide
Tufin Orchestration Suite
February 2025
Learn what your peers think about Tufin Orchestration Suite. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.

What do I think about the stability of the solution?

We have had a couple issues with the VMs, but I think it was just because they were starving for resources. A recommendation on what the virtual appliances should have for resources would be appreciated.

What do I think about the scalability of the solution?

We have done PR strategies and added Tufin appliances. It is super easy to just back up and restore to a new one. You can get a new appliance up and running in 20 minutes.

How are customer service and support?

We worked with their professional support before, but we have not worked with their Professional services.

How was the initial setup?

The initial setup is straightforward.

What about the implementation team?

We are a reseller.

What was our ROI?

We've install it to make money.

Tufin does make the process faster for customers, depending on if they use SecureChange to automate their process. Everything is all in one then.

What's my experience with pricing, setup cost, and licensing?

Licensing is on a customer by customer basis.

What other advice do I have?

Try Tufin out. Make a PoC of it. That is how we sell most of our products because it works well.

Our customers do not have a hybrid network.

Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
PeerSpot user
Firewall Architect at a financial services firm with 10,001+ employees
Real User
Helps us tighten up our firewall policy, but reporting should include automation metrics
Pros and Cons
  • "The automation piece is the most valuable feature: having SecureChange make the change on the firewalls, instead of my having to go manually make the changes on the vendor product."
  • "We would like to see automation metrics, from a reporting standpoint. We would also like to see automation of site-to-site VPN tunnels. We would like to see automation of Check Point application-based firewall rules."

What is our primary use case?

Our primary use case is firewall automation. We use SecureTrack and SecureChange. We have distribution serves, Remote Collectors, but what we primarily use is SecureChange integrated with ServiceNow for users to submit firewall requests. They then go to SecureChange which designs the rules and implements them.

How has it helped my organization?

When it comes to the turnaround of firewall rule requests, it used to take about a week to implement and have the customer test for firewall access. Now, it can take just one day. The implementation itself takes a minute or two. For the customer, it may take the rest of the day, by the time that the policy is installed and the customer tests, either that evening or the next day.

While I'm not involved in the leadership, I believe the solution has helped us to meet our compliance mandates: from a firewall perspective, as well as an audit perspective, as well as review of the rules and source and destination port requests.

As for ensuring that security policy is followed across the entire hybrid network, we're getting there. That's part of why we implemented Tufin. We are implementing that across our multiple offices. Once we get to that state, it will ensure that security policy is followed.

Finally, using the solution, our engineers are spending less time on manual processors.

What is most valuable?

In general, the automation piece is the most valuable feature: having SecureChange make the change on the firewalls, instead of my having to go manually make the changes on the vendor product.

In terms of cleanup of our firewall policies, we don't officially use Tufin, but I, as an architect, do use the Automatic Policy Generator to review existing rules: high hit-count rules and open rules which aren't very secure. We use that to then build firewall rules which tighten up our firewall policy.

The change workflow process is flexible and customizable. We have had to edit and alter some of our workflow and it's pretty easy, pretty simple, pretty straightforward. We use Tufin support, their helpdesk, for that because we're a very new customer.

What needs improvement?

In terms of the visibility the solution provides, we have hits and misses with it. Overall, we think it works. We would like to get more automated, but that could be an issue internally with services and ports that we allow between different zones and our USP matrix. We're working with Tufin representatives to help solidify that and clean that up a little bit. That's one of the headaches and hiccups that we have right now: the full automation piece. We have automation to an extent, but we still have requesters who submit requests that still require approval, whether it be firewall leadership approval or cyber leadership approval. We want to determine what ports are allowed between the zones, as I mentioned, so that we can have full automation and there's no human interaction at all.

We would like to see automation metrics, from a reporting standpoint. We would also like to see automation of site-to-site VPN tunnels. We would like to see automation of Check Point application-based firewall rules. That's available on the Palo Alto side, but we are primarily a Check Point site on-prem. We have Palo Alto on the cloud but most of our on-prem stuff is from Check Point, so we're waiting for that. Those are some of the key things we're waiting for.

For how long have I used the solution?

We've been using Tufin for about four months.

What do I think about the stability of the solution?

My impression of the stability is positive. We haven't had any issues. We even went through an upgrade about a month ago and it was a smooth process.

What do I think about the scalability of the solution?

As for scalability, we're finding that out right now. We're building out two new Remote Collectors for our global deployment of an additional 150 to 180 firewalls, plus additional Layer 3 appliances. We're working through that right now. Hopefully, it will be a smooth transition but I can't say for sure because we haven't actually implemented it yet.

How are customer service and technical support?

I would rate tech support as "fair." Response time is a little slow, but when they do respond, and when time is available for them, we work through things pretty quickly to resolution.

How was the initial setup?

I wasn't involved in the initial setup, but from what I've heard from others from whom I took it over, it was very straightforward.

Which other solutions did I evaluate?

I know they reviewed other solutions but I don't know which, for sure, since I inherited the project. I would assume AlgoSec and FireMon were reviewed as well.

What other advice do I have?

Be as detailed as you can within your introductory meetings, and your planning and implementation phases, because if you don't mention something and it comes back later, you're going to have to work through it. That could take time, it could take extra money. You want to make sure, upfront, that you know everything you want to do so that it's all included in the cost for the Professional Services implementation.

We do use it on the cloud; we're having some trouble right now defining the network policy on our cloud. We're working through that; it's part of being a new client.

I would rate Tufin a seven out of ten. We're a very large, complex organization, so we're still working through some stuff that we focus on, things that, perhaps, other customers don't, or that Tufin doesn't have integrated in the TOS software.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Tufin Orchestration Suite
February 2025
Learn what your peers think about Tufin Orchestration Suite. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
Senior Specialist at Cigna
Real User
Allows non-technical people to keep track of firewall rules, but the API needs to be improved
Pros and Cons
  • "Tufin is the only multi-vendor firewall tool that is available, and it helps to bring everything together and report on what all of the rules are."
  • "I would like to see API access into every aspect of Tufin."

What is our primary use case?

My company primarily uses this solution for reporting and enforcing policy. My role has to do with developing applications to allow integration with our other tools.

How has it helped my organization?

When I was using Tufin for analysis, there was a tool that would tell me which rules could be consolidated. It was amazing and helped me to clean up the firewall policies.

We use this solution to automatically check to see if change requests will violate any security policy rules, but I do not have any specific details or examples.

Tufin is the only multi-vendor firewall tool that is available, and it helps to bring everything together and report on what all of the rules are.

This solution helps to ensure that security policy is followed across the network because it is the main tool that non-technical security people use to keep track of firewall rules. Without it, they wouldn't even know where to begin. 

What is most valuable?

In my current role, the most valuable features are the API and the accessing. In my previous job, the analysis was my favorite.

What needs improvement?

I would like to see API access into every aspect of Tufin. For example, every feature and everything that's in the database, I would like to have programmatic access to. This would give me the ability to do anything that the product can do but from a script. This way, we are not beholden to the GUI in any way. If an operation requires that somebody click somewhere into the interface, manually, especially if it's just part of many other things that they have to do, then we want to fully automate that.

Some of the manual processes are taking longer because, without the proper API access, there are a lot of tickets coming in. These are from people who need to perform a task, but only a handful of them have access to it. This is because we're too afraid to give access to all of the people who actually need it.

What do I think about the stability of the solution?

In every instance that I've ever worked with it, it was stable.

How are customer service and technical support?

I have not dealt with technical support.

What about the implementation team?

In my previous company, I handled the deployment of this solution myself.

What's my experience with pricing, setup cost, and licensing?

Turning on certain options in the solution comes at an additional cost.

What other advice do I have?

My advice for anybody who is researching this solution is that if they are a larger company with a lot of money to spend, and they have a heterogeneous network with more than three different firewall vendors, then they absolutely need it. There is no competitor or really anybody who is even close.

For what this product does, it does well. There are, however, things that are missing.

Overall, I would rate this solution a seven out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Security Analyst at Equifax Inc.
Real User
Provides important visibility and saves us considerable time when making changes
Pros and Cons
  • "The most valuable feature is that it extends security entries in the firewall policies."
  • "I would like the ability to export information in other formats including PDF, HTML, or Excel."

What is our primary use case?

We use this solution for auditing our security and system access entries, then alerting us to problems.

How has it helped my organization?

The auditing reports generated by this solution help us to find issues.

This solution has helped us to meet our compliance mandates. We have very strict standards and security policies that we must follow. This tool is very flexible for the management team. It also helps us to ensure that our security policy is followed across our entire hybrid network, but we have a lack of security in some points.

What is most valuable?

The most valuable feature is that it extends security entries in the firewall policies. Given the number of entries in the access control, this would take a lot of time, so this feature is very valuable for us.

The visibility this solution provides us is great. At the moment, we are in the process of continuous improvement, and we need to include these new features.

The change workflow process is okay.

What needs improvement?

I would like the ability to export information in other formats including PDF, HTML, or Excel.

For how long have I used the solution?

We are still implementing.

What do I think about the stability of the solution?

The stability is very good. It's better than the other tools that we have in the company.

What do I think about the scalability of the solution?

To this point, we have only used the basic functionality. We have several teams working with the tools.

How are customer service and technical support?

Technical support for this solution is excellent. At the moment, we have very good communication with support.

How was the initial setup?

The initial setup was good and we had no trouble with it.

What about the implementation team?

We handled the deployment of this solution internally.

Which other solutions did I evaluate?

We did not evaluate other solutions before choosing this one.

What other advice do I have?

This tool is excellent in the specific areas where it is applied. We are spending less time on manual processes and at some point, we will be stopping them.

This solution definitely helps to reduce the time it takes to make changes. With other tools, I have spent five or six hours or even days, but with this solution, it takes me thirty minutes. It can take even less, depending on the complexity of the firewall.

My only complaint is that I would like to be able to export data to different formats.

I would rate this solution a nine out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
ITManage3885 - PeerSpot reviewer
IT Manager at a financial services firm with 10,001+ employees
Real User
Valuable reporting helps us to satisfy our audit requirements
Pros and Cons
  • "The most valuable feature is the reporting of our risk poster in our firewall."
  • "I would like to see improved role-based access."

What is our primary use case?

Our primary use case for this solution is risk visibility.

How has it helped my organization?

We use this solution to clean up our firewall policies.

Prior to using this solution, and according to our best practices, we didn't have a baseline of the security poster that we have with our rule sets. Now, with this reporting, we're able to provide that to our management.

It has helped us meet your compliance mandates. We are getting this from the data and reports. This was one of our requirements.

What is most valuable?

The most valuable feature is the reporting of our risk poster in our firewall. We clean up our firewall rules using this solution. The reporting helps us carry this out quickly.

This visibility is good and I would say that the change workflow process is average to good.

We expect that SecureChange will help us to reduce the time it takes to make changes. It is on our roadmap.

What needs improvement?

The reporting still has a lot of improvements to be made.

I would like to see improved role-based access. 

For how long have I used the solution?

We are still implementing.

What do I think about the stability of the solution?

For us, this product has been very stable. We don't have any trouble with it.

What do I think about the scalability of the solution?

Our deployment is quite small, so I cannot speak to the scalability yet.

How are customer service and technical support?

Technical support for this solution needs improvement. We usually get a callback from an engineer, but the escalation of support should be faster.

Our account manager at Tufin is very engaged and has been super helpful.

Which solution did I use previously and why did I switch?

Adopting this solution was an easy decision for us because it is an audit requirement.

How was the initial setup?

The initial setup of this solution is straightforward. Installing SecureTrack was not difficult, after browsing through the knowledge base. With the documentation that is available, it is easy to deploy.

What about the implementation team?

We implemented this solution ourselves.

What was our ROI?

We have not yet seen ROI, but when we go with the SecureChange model, we will automate and reduce overtime hours. At this point, we will see a very valuable return on investment. For the time being, it is on our roadmap.

Which other solutions did I evaluate?

We did evaluate other solutions before choosing Tufin. This solution is used by many large companies, which is one of the reasons that we selected it.

What other advice do I have?

There is always room for improvement, but with the performance and the day to day stability that we have, I think that it's a very good product. Overall, I am very happy and satisfied with the product, and I am looking forward to a lot of new features.

I would rate this solution an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Managerfac3 - PeerSpot reviewer
Manager at a manufacturing company with 10,001+ employees
Real User
Enables us to automatically check if a change request will violate any security policy rules but they should get rid of the REST APIs
Pros and Cons
  • "The change workflow process is flexible and customizable. We have one guy who has never logged into Tufin ever in his life. He sits down and in 30 minutes had written an automation routine, then went back and changed it. He did that with no training. For me, that is a major benefit."
  • "I would like to see them get rid of the REST APIs and use something more modern."
  • "I would also like to see them do more cloud integration within the Tufin Orchestration Suite, not within a SaaS solution."

What is our primary use case?

Our primary use case is for automation and orchestration.

How has it helped my organization?

We use Tufin to automatically check if a change request will violate any security policy rules. One of the things we want to do is to have a blacklist/whitelist policy. A blacklist of things that can never be allowed and a whitelist of things which are always allowed. I want this tool to block or report ports that should not be used, putting somebody in a change. In addition to that, I want it to be able to block people from mapping IP addresses in North Korea, Iran, or whatever is on the blacklist.

Our corporate policy mandates that we can only make changes to our firewalls daily. Once we get ServiceNow integrated with our whitelist policy, Tufin should be able to initiate the change and get us to reduce time.

It should help us meet our compliance mandates going forward. It is replacing AlgoSec.

What is most valuable?

The ease of use is the most valuable feature. 

The change workflow process is flexible and customizable. We have one guy who has never logged into Tufin ever in his life. He sits down and in 30 minutes had written an automation routine, then went back and changed it. He did that with no training. For me, that is a major benefit.

The two reasons that we wanted Tufin

  1. The single pane of glass, so our Tier 1 and Tier 2 could make changes.
  2. The network mapping which is something that we have never had before.

What needs improvement?

  • I would like to see them get rid of the REST APIs and use something more modern. 
  • I would also like to see them do more cloud integration within the Tufin Orchestration Suite, not within a SaaS solution. 
  • I would like them to move their community support off of Google and onto something more long-term.

For how long have I used the solution?

Less than one year.

What do I think about the stability of the solution?

So far, stability has been good. 

What do I think about the scalability of the solution?

It has already pulled in all our Layer 3 switches and routers across the company.

I don't know if I can expand on the cloud yet.

How are customer service and technical support?

We bought premium support. I have heard from my team that they are great. 

Which solution did I use previously and why did I switch?

We switched from AlgoSec because they had horrible customer support, and difficult change management and processes. 

How was the initial setup?

The initial setup was very straightforward. It was done in five days, which is pretty cool.  

What about the implementation team?

We used Tufin for the deployment. We had a positive experience with them. 

Which other solutions did I evaluate?

We compared AlgoSec, Tufin, and Skybox side-by-side. Originally, the team chose Skybox. They threw in what a lot of other groups had wanted, like the network team, security team, and DevOps team. When I sat them down (because I voted Tufin), I asked them why and they gave me all of the explanations that were all somebody else's reasons, not ours. I told them that this tool is for us and we needed a true orchestration automation tool. Not one that supports everyone else's automation, and we need one for firewalls.

What other advice do I have?

I would rate it a seven out of ten. 

I would advise someone considering this type of solution to not listen to the sales teams among the competitors. They all throw each other under the bus and a lot of it is not true. Tufin's competitors will tell you how bad of a company that Tufin is and how you can't trust them, and how their stuff doesn't work. Then, Tufin doesn't say anything bad about their competitors. So, don't trust everything that you hear. 

Do your own research. Do a proof of concept. Get all of the vendors in. Give it a month to test drive. Set it up and let them prove it out. In the end, the correct tool, not the better salesman, will win.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user488085 - PeerSpot reviewer
Sr. Security Administrator at a consultancy with 1,001-5,000 employees
Consultant
Most of the valuable features have to do with the reporting and the cleanup of policy.

Valuable Features

A lot of the most valuable features have to do with the reporting and the cleanup of policy. With our day-to-day busy lives, we just want to get the change in and implement it, and that just increases rule base exponentially. From time to time you need to go back and find duplicate services, objects, rules, and cleanup. With a lot of the cleanup effort, I think the product helps out a lot.

Tracking changes is beneficial. We get alerted immediately who made the change, what change was made, and things like that. That's probably the most valuable.

Room for Improvement

It is important to keep up to date with the vendors you support. For example, Palo Alto, CheckPoint, Cisco, F5, and so on. They should make sure that Tufin supports the latest version of those products.

We upgraded to R80 two months ago, and our Tufin product hasn't been working. It's because there's no support for R80. We're hoping that Tufin supports R80 soon so we can start getting all the changes. If a vendor upgrades to a certain version, Tufin needs to provide support fairly quickly.

Also, our 20/20 vision is to be in the cloud wherever we can. Cloud first. If Tufin had any kind of management in the cloud, that's one less piece of hardware to manage in-house. Being in the cloud would definitely provide that extra missing feature.

Use of Solution

We've had it for about 3 or 4 years now.

Stability Issues

We have not had any stability issues at all. Upgrading has been simple, no issues at all.

Scalability Issues

It is scalable. We manage about 150 firewalls. There are no issues at all.

Customer Service and Technical Support

The support portal has been quick. I actually emailed them about R80 support, and they were really fast at letting me know that it's coming in mid-2016.

Other Solutions Considered

Along with a colleague of mine, I was involved in the decision to start using Tufin a few years ago. We compared it to AlgoSec and a couple other vendors. Tufin seemed to meet our requirements at the time. Before our renewal, we are looking to re-evaluate what all the vendors have to make sure we are getting the most out of the product.

Other Advice

It's a great product. It's pretty straightforward to use. It meets our needs and great support overall.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user335712 - PeerSpot reviewer
Senior Network Security Engineer at a retailer with 10,001+ employees
Real User
Using SecureChange and SecureApp, it makes life easier for the user community and the firewall engineers by not having to manually input firewall rules.

Valuable Features

I am working in a DevOps environment. We are trying to automate firewall rules and allow Tufin to push these changes for us. Using SecureChange and SecureApp, it makes life easier for the user community and the firewall engineers by not having to manually input firewall rules. The DevOps environment allows the users to pick from a catalog and request what they need. SecureTrack gives us the audit capability of what is/was implemented.

To me, SecureTrack is the greatest thing since sliced bread, it allows you to see what is used and not used with your firewall, and gives extensive analysis in a very short period of time.

Improvements to My Organization

I can run SecureTrack for a week and have a great idea of what’s being used. Ideally, you want to let it run for a year, accumulate data, go over a years’ worth of data and decide what really needs to be cleaned up.

You will see in one report what is being used (IP addresses or services) and what has never been used.

Gone are the days of reviewing logs to figure out, "do I still need this rule/service?" It’s been a really great piece of software.

Room for Improvement

Probably in the ad-hoc reporting. They give you the canned reports. We do use the API calls, but it would be nicer if they could just give you a drag-and-drop function in the reporting. Pick anything out of the database and massage that data the way you want it.

Tufin has been working with us hand-in-hand lately because they do see that we are doing a lot of cloud-development work with automation. It’s in all our best interest going forward and they have responded seeing the future is in the cloud.

Use of Solution

Personally I have been using Tufin for seven years across different companies.

Deployment Issues

No issues encountered. Strongly encourage an HA environment.

Scalability Issues

It’s holding up real good with scalability and stability. We have not run out of power on the box. They have been here on site and see what we are doing and how we are doing it. We are telling them what we need and they are doing it. They are pushing the envelope in their development side to try and meet our demands.

Customer Service and Technical Support

Customer Service:

The level of service is excellent. I can’t overstate that. We open a lot of tickets because we are using a lot of things that a lot of people are not using in the product, which is too bad. Most people don’t understand the power this product brings to the table.

The technical support team is right on top of it. They don’t just leave you hanging. They know the guts of the product. They are able to get in and figure out what is happening and get you up and running again.

A lot of companies will put the new guy on the front lines so that they learn the product line quicker, Tufin does not do that, these guys actually know their stuff. If they don’t know they go straight to the developers. I can’t praise them high enough.

Technical Support:

We have a great relationship. You need help and they are there. If that’s operating system support or the application, their engineers are very resourceful. Looking at their roadmap, we see great improvements coming to cover the new world of automation and cloud computing.

Bottom line they are very responsive, and very good.

Initial Setup

It’s easy to deploy. It’s a very easy product to work with. It’s one of the easier products to implement.

Implementation Team

In-house with Tufin on-call ready to help.

ROI

We have made a ROI. We have invested a lot of money in these products. Any company that puts in SecureTrack alone will see a very quick return on investment.

With SecureApp we are automating cloud development work, the only thing we have to do at the end of the day is go to the firewalls and click ‘install’. It will do the end to end analysis for you.

Pricing, Setup Cost and Licensing

You need to approach it from a cost perspective. If you have to go through and analyze a rule base, it’s going to take you months and months and a lot of people. If you use Tufin, right off the bat, it’s collecting the information and it’s going to tell you what’s been hit or not. It will tell you how many hits on each source/destination address, and services.

Other Advice

It’s the Swiss army knife of tools. I’m sold on it. It’s so easy to use. We use it to its full potential. It has some great bells and whistles.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Tufin Orchestration Suite Report and get advice and tips from experienced pros sharing their opinions.
Updated: February 2025
Buyer's Guide
Download our free Tufin Orchestration Suite Report and get advice and tips from experienced pros sharing their opinions.