
Overview
Forcepoint NGFW (Next-Generation Firewall) delivers unparalleled scalability, robust protection, and comprehensive visibility to efficiently manage and secure traffic flowing into and out of your AWS network, as well as within various components of your cloud environment. By integrating advanced application control, sophisticated evasion prevention, and a leading Intrusion Prevention System (IPS) into a unified solution, Forcepoint NGFW streamlines security management across your data center, office, and branch firewalls from a single console. Independent testing highlights Forcepoint NGFW's superior capability in stopping Advanced Evasion Techniques (AETs) compared to other security devices, its effectiveness in blocking vulnerability exploits, and its sandboxing technology for identifying zero-day attacks and advanced malware. Additionally, Forcepoint NGFW offers robust protection against the exfiltration of sensitive data, ensuring a comprehensive defense for your network.
Highlights
- Effortlessly extend your network to AWS cloud via secure virtual private network (VPN) gateway connecting remote sites, branch offices, and more.
- Safeguard your virtualized network against advanced attacks with dynamic security controls application layer exfiltration security and advanced evasion techniques (AETs) identification.
- Express your business processes as technical controls quickly and naturally with Forcepoint's unique Smart Policies that can be updated globally in seconds, not minutes or hours.
Details
Unlock automation with AI agent solutions

Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Cost/hour |
---|---|
c6i.xlarge Recommended | $0.80 |
c4.4xlarge | $3.20 |
c5.4xlarge | $3.20 |
c4.2xlarge | $1.00 |
c5.2xlarge | $1.60 |
c7i.4xlarge | $3.20 |
c6i.4xlarge | $3.20 |
c5.xlarge | $0.80 |
c7i.xlarge | $0.80 |
c7i.2xlarge | $1.60 |
Vendor refund policy
You may terminate the instance at any time to stop incurring charges. There is no refund for charges incurred prior to termination.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Additional details
Usage instructions
To perform the initial configuration, use SSH and the username 'aws', then type 'sudo sg-reconfigure'. You can also give initial contact file engine.cfg via userdata encoded in base64. For additional information and configuration instructions see https://www.websense.com/content/support/library/ngfw/howto/ngfw_ht_deploy-ngfw-in-aws_en-us.pdfÂ
Support
Vendor support
Your subscription includes Forcepoint Premium Support, with 24x7 support for critical issues, Severity 1 response targets of 45 mins or less, and an online technical support site offering extensive support resources and request tracking.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

FedRAMP
GDPR
HIPAA
ISO/IEC 27001
PCI DSS
SOC 2 Type 2
Standard contract
Customer reviews
Clients have benefited from responsive support and consistent performance
What is our primary use case?
I might not be the right person to discuss the main use cases for Forcepoint Next Generation Firewall for these clients. I can send an email and reply with what we can in broad strokes without identifying any specific customers. I would have to ask my teams that handle these solutions.
What is most valuable?
I can share what we appreciate about Forcepoint Next Generation Firewall and what clients generally choose it for. We have had good experience with their responsiveness, which exceeds other products sometimes. Their customer service and price point are competitive for the US market primarily.
The centralized management console of Forcepoint Next Generation Firewall is something we have been struggling with because everybody has their own approach, but most customers have mixed solutions. We end up having customers that are either running two consoles or requiring a third-party solution to monitor everything. From a configuration standpoint, it has been easy to manage.
Regarding security, these are security solutions, and when referring to performance, it works effectively. Features are very similar across products. Each vendor has their own distinctive elements, but in general, for the most concerning and most sought-after features, it is very complete.
What needs improvement?
At this moment, nothing specific comes to mind regarding improvements for Forcepoint Next Generation Firewall.
The main feedback we receive concerns pricing. If I only have a chance to give one suggestion, it would be to keep pricing competitive. AI improvements could be beneficial, as having AI capabilities has become an important checkmark feature.
What do I think about the stability of the solution?
It has been stable.
How are customer service and support?
On a scale of 1 to 10 for customer service for Forcepoint Next Generation Firewall, I would rate it at least 9, 9.5.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup of Forcepoint Next Generation Firewall is usually straightforward from a professional use and expert perspective - it is normal and not difficult. However, these are products that require expert knowledge to some degree in my experience.
What about the implementation team?
For deploying Forcepoint Next Generation Firewall into client environments, the approach depends on the implementation. For deployment of individual components, we would typically deploy an engineer or technician for individual boxes. If it is going into an existing system, an engineer must be involved. For a full deployment, we need a solutions architect to examine it, and we involve different vendors for their guidance as they are the true experts in each of their components.
Which other solutions did I evaluate?
In terms of comparing Forcepoint Next Generation Firewall on a general level, they are very similar regarding features and quality of performance compared to Palo Alto or Cisco or some of the other major players for next generation.
What other advice do I have?
Our team has experience with multiple solutions including Palo Alto and Forcepoint Next Generation Firewall.
We have a mix of clients, primarily focusing on finance and telecom. As the CEO of the company, I lead the teams, negotiate the brands, and secure them. I am sometimes involved in purchasing products or quoting for bigger projects.
Regarding integration with third parties, we work as an MSSPÂ and support MSPs with their solutions. The integration has been very successful for monitoring and ongoing use of the solutions, particularly from an operational perspective for monitoring faults and issues.
Comparing pricing to other solutions on a scale of 1 to 10, with 10 being the highest price, Forcepoint Next Generation Firewall ranks around seven within the US market. There are other products that are less expensive, but they are frequently ranked among the industry leaders.
We generally work with SMBs and medium to smaller companies given our addressable market, and the experience has been good.
I rate Forcepoint Next Generation Firewall 9 out of 10.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Advanced features secure our network and improvements in licensing could enhance cost-efficiency
What is our primary use case?
What is most valuable?
What needs improvement?
For how long have I used the solution?
What was my experience with deployment of the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
How was the initial setup?
What about the implementation team?
What was our ROI?
What's my experience with pricing, setup cost, and licensing?
Which other solutions did I evaluate?
What other advice do I have?
Which deployment model are you using for this solution?
Cross setup simplifies implementation but support challenges persist
What is our primary use case?
We mostly work with finance, specifically with banks most of the time. We use Forcepoint Next Generation Firewall for these applications.
What is most valuable?
Today, the Next Generation Firewall from all companies are pretty similar, but the difference lies in the accuracy of setting up the risks. Another valuable aspect is the features and how friendly they are for cross setup. Cross setup refers to using multiple features from the same firewall simultaneously within the same environment. With Forcepoint, this process is simplified compared to others like Fortinet.
What needs improvement?
There is a lot of technical stuff that could be improved. We've encountered scenarios that were really hard to set up and required support. It would be beneficial if the support and contact with the development team were enhanced. Fast response and efficient handling of issues, similar to how Fortinet responds, would be great.
For how long have I used the solution?
I have been using Next Generation Firewall from Forcepoint for more than seven years and the Data Loss Prevention for just a couple of projects, no more than a year.
How are customer service and support?
It is really hard to work with their customer support. For example, unlike Fortinet where you can escalate an issue and quickly get responses from the development team, Forcepoint's process seems slow and challenging.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I moved from Oracle to use security vendors like Fortinet, Kaspersky, and Forcepoint.
How was the initial setup?
The initial setup can be quite complex. When trying to apply content filters with different network setups in the same machine, even with good planning and reference manuals, issues can arise. Combining different functionalities on the same box often results in problems.
What was our ROI?
I don't believe in ROI when talking about cybersecurity because there's no real way to measure it. Cybersecurity ROI could be $1 or $100 million, depending on the risk of data behind it. I've seen ROI analyses from many cybersecurity companies, but I find it hard to trust the numbers.
What's my experience with pricing, setup cost, and licensing?
In terms of pricing, I would place Forcepoint in the middle when compared to other firewalls like Fortinet and Palo Alto.
What other advice do I have?
Overall, I would rate Forcepoint Next Generation Firewall a seven. I believe a 6.5 would be more accurate though. Also, my name can be used for the review, but not my company name. I am no longer working with Consulting Services; I'm with a different company now.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Firewall for advanced threat protection with deep packet scanning capabilities
Advance configuration options are complex and requires subject matter expert to customize the rules.
An all-in-one solution that works as a firewall but very complicated for use
What is our primary use case?
Educational institutions are the main users. We planned to use it as an all-in-one solution, primarily as an edge solution and Internet-facing firewall.
What is most valuable?
We're trying to use all the firewall's features. Most of the features were effective, but the usability is a huge concern.Â
What needs improvement?
My experience with this Forcepoint Next Generation Firewall wasn't very pleasant due to its complexity. For example, the firewall loses some features when working in a cluster, which is a huge challenge. It caused me several weeks to solve an issue to make the VPN work, even after opening several cases with support. Also, the debug, which should provide essential knowledge about everything going on, the flow of traffic, and how the engine works, wasn't very informative in identifying the issue.
The problem was eventually solved by chance, thanks to an idea from an expert in the market. We had to refer to a freelancer engineer with huge experience with the Forcepoint Next Generation Firewall, and he noticed something that solved the issue by luck. We had no evidence or logs that showed this was the issue.
It's the most complicated firewall I've ever faced. You have to know what you're doing to achieve the plan and take action. It would be best to be an expert, take a course, or at least read the full documentation carefully. The interface isn't organized in the same way as other competitors.
You have to be an expert in it. You need to watch training videos or read the full documentation to understand how it works, even to implement a minor firewall change. Working with this firewall requires a lot of knowledge.
For how long have I used the solution?
I have been working with the product for three years.Â
What do I think about the stability of the solution?
The tool's stability, policy enforcement, and management are magnificent. I rate it a nine out of ten. It depends on the resources available. In my experience, I encountered a situation where the switch collapsed before the firewall did due to huge traffic. The switch crashed before the firewall crashed because of the enormous data transfer and network traffic.
How are customer service and support?
We contacted support three times, opened three cases for the same issue, and didn't find out what the issue was for two months.
How would you rate customer service and support?
Negative
Which solution did I use previously and why did I switch?
We need to rethink the usability and the availability of training and resources. These should make administration and operating this solution as easy as other competitors. For example, competitors like Fortinet and Palo Alto have easier management, especially Fortinet.
How was the initial setup?
It has some documents if you can reach them. That's one of the other things they need to improve badly - the documentation is inaccessible. But when we reach the right information for what we're trying to do, it is mostly informative and easy. I'd say it's seven out of ten for ease of use if you follow the instructions. It would work. It's deployed on-premises. I wasn't involved in the implementation phase. It was implemented before I joined the company.
What other advice do I have?
If you're not an expert and you haven't taken a course or have the correct materials to run the solution, I don't recommend it. You have to be an expert in this specific solution before using it. Overall, I'd rate Forcepoint Next Generation Firewall six out of ten.