Sign in
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Reviews from AWS customer

22 AWS reviews

External reviews

208 reviews
from and

External reviews are not included in the AWS star rating for the product.


    Information Technology and Services

Advance platform for cloud infrastructure network protection and security

  • June 26, 2024
  • Review provided by G2

What do you like best about the product?
We can sync this tool with our whole cloud and hybrid cloud infrastructure for advance network security.
Protection to cloud server gateways.
Automations is biggest advantage of this tool.
Our VPC security.
What do you dislike about the product?
Nothing comes top of the my mind for dislikes for this tool.
What problems is the product solving and how is that benefiting you?
NSPM and helping or benifiting in our VPC server security.


    Information Technology and Services

Excellent for Network Security Protections

  • June 16, 2024
  • Review provided by G2

What do you like best about the product?
Check Point CloudGuard Network Security is very much advance as per my personal experience for protecting risk and threats for any cloud networks that cloud be let any like hybrid or say public or private cloud or virtual networks.
Helps in automations of Cloud pipelines work infra.
What do you dislike about the product?
Cloud be nothing as per my experience. N numbers of security and threat prevention features.
What problems is the product solving and how is that benefiting you?
Almost acting like a firewall software for our cloud network security.

Always recommended for DevOps.


    PRASHANT GARJE

Cost-effective, supports automation, and provides good security

  • May 22, 2024
  • Review from a verified AWS customer

What is our primary use case?

We are using Check Point CloudGuard as a firewall. Along with the firewall, we have incorporated multiple blades. Initially, the firewall used to be a single security device, and along with that, we required antibot, antivirus, IPS, and IDS devices. Check Point CloudGuard is a combination of all the devices and functionalities in a single device. It is a next-generation firewall. The main use case of this firewall is to protect our entire cloud and provide perimeter cloud security at L3 and L4 levels.

How has it helped my organization?

It is a next-generation firewall. Threat prevention and threat detection blades are available with the firewall. As soon as you enable the blades and you have the license for it, you are good in terms of threat prevention. You do not need to do any specific settings. You just need to enable the blade, and the firewall will take care of the rest of the things. That is how it works.

We are using the Check Point CloudGuard firewall with autoscaling in the AWS and Azure cloud. We have a minimum capacity of two firewalls and a maximum capacity of ten firewalls. If the CPU utilization increases or the memory utilization increases, the capacity will be increased to three from two. Till the service comes down to the threshold level, it will keep on adding more firewalls, so we have ease of operations. We do need not to worry about what we will do if a firewall fails.

When I joined my organization, we were using this CloudGuard firewall in the active/standby firewall cluster. In such a setup, the firewall that is active processes your traffic. The other firewall is in the standby mode. It is not processing the traffic, but it is still costing you. Even though it is not being used, it is still cost-consuming at the cloud level. We changed the setting to autoscaling. After adopting the autoscaling mode for this firewall, we need a lower number of CPU and memory. All the firewalls are active, so we need not worry about the standby firewalls and all those things. So, we have transitioned from these conventional active/standby firewalls to autoscaling firewalls. With this, we are able to save costs and improve performance. All the firewalls are active/active but with fewer CPU cores. When we have fewer CPU cores, we need less number of licenses, so we were able to save the cost. The performance has also been great.

What is most valuable?

The most important feature is that we are able to use Check Point CloudGuard Firewall for our cloud security. We can make the deployment automated. We do not require manual intervention. With the help of automation, we are able to deploy it within minutes, and we are able to discard it within minutes. We can do hardening and create policies. All those things are very advanced.

Secondly, Check Point is one of the big OEMs available in the world from the firewall perspective. It is better than Palo Alto and Juniper firewalls. It is one of the best firewalls available in the industry.

What needs improvement?

We have done a lot of automation with the firewall, but sometimes, there are some failures because of some bugs. The fixes for them are still not available. We have daily or weekly communication with the Check Point people giving support in the India region, but we have not seen much improvement or response to our requests for some additional features. We are moving to infra as a code, so we are expecting more advancements in this product. Just installing the patches is not going to help us. They need to focus on this area.

I expect Check Point CloudGuard to come up with some AI/ML integration. A firewall is the first L3 security device available to you. It is the single point that manages or processes the traffic for an organization. There is a possibility that the device goes down or gets rebooted for any reason. The integration of artificial intelligence with the devices can help us to know in advance that there might be a surge in traffic. There might be a spike in the traffic, so we can have some additional firewalls integrated. This predictive analysis has to be there. This way, if required, a second, third, or fourth firewall can come into the picture. All the firewalls will process the traffic simultaneously. I am expecting such capability. This sort of feature is available with AWS. We are deploying all the firewalls on AWS, but it would be easy if, in the future, such a feature is available from the OEM or Check Point itself. It will be very helpful for the organization.

We have had a couple of outages because of some misconfiguration. They were human errors but there were no prior indications that if we were making these sorts of changes, this would happen. People making the changes on the firewall were not aware of this, and that is the reason why the outage happened. In a financial organization, an outage of even five minutes can cost a lot.

For how long have I used the solution?

In our organization, we have been using it for more than four or five years, but I have hands-on experience with it for the last three years. 

What do I think about the stability of the solution?

I would rate it an eight out of ten for stability.

What do I think about the scalability of the solution?

It is scalable. I would rate it a ten out of ten for scalability.

How are customer service and support?

I would rate their support a five out of ten because I never got good support. Whenever I have raised a TAC case, their support has not been great. It is not as good as others.

They need to improve from a knowledge perspective. I had a couple of issues, and they could not understand those issues easily. They should not just take the logs and analyze the logs. They should be providing a solution. Being a financial organization, we cannot afford a long downtime. We expect a faster resolution. If a support engineer is not capable of handling a case, he or she should escalate it to a higher level, but they are not doing that on a regular basis. They make you lose days by dragging the case.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

In my organization, we have two different Infra teams. We have the Network Security Infrastructure team that manages the on-premises setup, and then we have the Cloud Network Security team that manages the cloud. I am a part of the Cloud Network Security team, and we are using the Check Point firewall. The on-premises team was using Juniper and Palo Alto firewalls, and they are now using the Check Point firewall. It is one of the most effective products we have ever used, and that is the reason why that team has moved from other OEMs to Check Point CloudGuard.

How was the initial setup?

We have deployed it on the cloud. We have AWS, Azure, and GCP clouds.

The deployment was done with the help of AWS CloudFormation templates which are very generalized. I just downloaded the templates and customized them as per our requirements. I faced a few challenges because I was not completely knowledgeable about CloudFormation, etc. It was not very challenging from the Check Point side. It was an easy deployment.

I faced a couple of challenges while integrating it with our existing ecosystem. Even though Check Point is the OEM, we have third-party vendor support here in India. The challenges that I was facing at the time were also new for them, so I sorted out those issues myself by referencing some online articles on Check Point. I was able to overcome those challenges at the time. It was not a big deal. There was no huge challenge.

What about the implementation team?

Initially, we involved people from Check Point and the third-party vendor of Check Point, but at later stages, we were capable enough to develop things in-house, so we did it ourselves.

The Cloud Network Security team has ten people. I am handling the AWS cloud deployment along with a colleague. Other colleagues are involved in Azure and GCP deployment. Overall, there are ten people for deployment and management, but mainly, two or three people are involved in the deployment at a time.

We have deployed it in two regions. It is deployed in the Mumbai and Hyderabad regions of AWS in India.

What was our ROI?

We have seen 70% to 80% ROI. 

What's my experience with pricing, setup cost, and licensing?

I do not know the exact price, but it is fairly priced. It is neither cheap nor costly.

As compared to other OEM vendors in the market, it is cost-effective for us. There are multiple things we need to consider while selecting a certain product. We have AWS, Azure, and GCP clouds, and we have multiple firewalls. All of our firewalls are Check Point CloudGuard firewalls. The cost can vary based on the licenses that you are using. For IPS, IDS, antivirus, antibot, and other capabilities, additional licensing costs might be there. When it comes to security, it gives us great security. Considering that factor, it is cost-effective for us.

Which other solutions did I evaluate?

I have not evaluated other solutions. Based on the input from my seniors, this is the best solution available in the market. I have heard that Palo Alto also has a cloud-based product called Prisma Cloud, which has some advanced features integrated by using AI/ML technologies. I would love to evaluate Prisma Cloud.

What other advice do I have?

I feel confident using this product. In fact, I have completed a few certifications related to Check Point CloudGuard. I am a Check Point certified administrator, and I am also a Check Point Certified Cloud Specialist. I have also been working with automation-related things, and sometimes, we do some bash scripting and shell scripting to make things easier for us. Traditionally, you can only access the firewall via a CLI. That is the basic level, and at the next level, you should be able to do a few daily things in an automated way. I am very good at that.

I would recommend this solution, but it also depends on the requirements. It is a cost-effective solution. If you are a small organization or a startup, you do not need to have this solution. If you are a big organization with 5,000 to 10,000 users, you can go ahead with it. The ROI for our organization was up to 80%, but it necessarily would not be the same for other organizations.

Overall, I would rate it a nine out of ten.


    Venkatesh R.

"best network threat analyser for cloud"

  • May 13, 2024
  • Review provided by G2

What do you like best about the product?
It will monitor all our network and user level traffies and event. it provide a various feature such as content filtering and web application etc.one of the most excellent feature is it will provide a the real time monitoring.another one is easy to implementation in any environment without any issues.
What do you dislike about the product?
the main one is cost of the license and its maintance could be drawback for smaller environment and the limitation of the network security is supported only in VPC.
What problems is the product solving and how is that benefiting you?
it will help to reduce the malicious attack on our cloud,another one is it will monitor the all our network and user.


    Information Technology and Services

Thank you Check Point for inviting me to provide my insights as Security Analyst.

  • May 10, 2024
  • Review provided by G2

What do you like best about the product?
As Cloud infrastructure security analyst, we have been encountering to multiple network security compliances related issues. So thank you to Check Point CloudGuard to come with excellent and exceptional Cloud security tools. As far as my short experience using this Check Point CloudGuard Network Security tool has been amazing. Following few positive impact or features or things that benifited us:
1. It's seamless integration capabilities with our existing cloud infrastructure.
2. It's ability and capabilities on indentify and threat analysis of networks.
Monitoring and preventing vulnerability threats risk for networks.
Etc.
What do you dislike about the product?
Hard to list any or think of any dislikes or downside. Always recommended for cloud infrastructure security.
What problems is the product solving and how is that benefiting you?
NSPM, Cloud networks protections
Acting as firewall.


    K S S.

Guide to network log monitoring

  • May 06, 2024
  • Review provided by G2

What do you like best about the product?
I like the active threat monitoring engine to detect malicious traffics in our application. We can use the graph UI to view the logs on radar visibility and the intelligence engine will support custom ruleset to identify and detect organization usecases itself.
What do you dislike about the product?
The module will supports only on network and account activity logs.
What problems is the product solving and how is that benefiting you?
It will help us to reduce anomaly traffics on our application.


    Mallikarjun B.

Network security Work very efficiently

  • May 06, 2024
  • Review provided by G2

What do you like best about the product?
First advantage has to be that it supports multiple cloud vendors meaning that we can monitor multiple cloud accounts with one subscription.
IT provides a clean view of the network traffic
It is very capable of isolating the malicious traffic from the regular traffic
It monitors all the traffic to and from the containers including on Prem to cloud environment and vice versa also the connection between the containers
The UI is very clean and easy to understand
Implementation is quite fast
What do you dislike about the product?
There are not many downsides to the network security module but the logs supported are limited they only support cloud trial logs and vpc logs
We cannot get end to end traffic view which if present can be more helpful at times
What problems is the product solving and how is that benefiting you?
As said earlier the biggest problem we had with other solutions is that they only support native services where as cloud gaurd supports almost all the cloud service providers


    Chris Lynch

Works as an Edge firewall and East-West firewall but improvement is needed in the consolidated UI

  • May 02, 2024
  • Review provided by PeerSpot

What is our primary use case?

My company uses the solution as an Edge firewall and East-West firewall. 

What is most valuable?

The tool's most valuable feature is its management console. 

What needs improvement?

Check Point CloudGuard Network Security needs to improve the management of the actual firewalls. Improvement is also needed for the consolidated UI of different security aspects. 

For how long have I used the solution?

I have been using the product for a year and a half. My company has been using it for eight years. 

What do I think about the stability of the solution?

We recently had some issues with stability, so it's hit or miss. It seems to have more minor bugs than other platforms, but overall stability is the same.

How are customer service and support?

The speed of the support's response varies. Sometimes, you can get a good engineer who can give you the right answers. 

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have used Cisco, Fortinet, Palo Alto, and SonicWall. The worst ones on the list are Cisco, Fortinet, and SonicWall. Palo Alto is better in some areas. Check PointCloudGuard Network Security is top in terms of actual security. But in terms of managing the whole platform, I would put it below Palo Alto.

How was the initial setup?

Check Point CloudGuard Network Security's deployment is easy and takes two hours to complete. 

What about the implementation team?

I did the solution's deployment myself. However, I connected with the consultants whenever needed. 

What was our ROI?

We've been secure and haven't had any security breaches.

What's my experience with pricing, setup cost, and licensing?

The tool's pricing is been higher than other solutions, but it seems like it's turning downwards.

What other advice do I have?

I rate the overall product a seven out of ten. 

Which deployment model are you using for this solution?

On-premises


    Financial Services

go to solution for multi platform cloud users

  • April 24, 2024
  • Review provided by G2

What do you like best about the product?
the first important advantage is that you can link multiple cloud accounts from multiple providers and works absolutely fine detecting the maliciuos traffic from open internet to VPCs and vice versa, it can also inspect the traffic between the VPCs from on prem to the cloud services basically it monitors all the traffic to ensure high security
it is easy to use and implement
UI is very clean and understandable
supports custom rulesets
traffic explorer comes handy to provide easy understanding on the network traffic
customer support is satisfactory
What do you dislike about the product?
only VPC and Cloud trails can be processed
despitee the traffic graph being a great feature it lacks the clear end to end details
What problems is the product solving and how is that benefiting you?
since we are using multiple cloud accounts to manage the applications it is hard to keep track of them in a single dashboard and cloudgaurd is solving this problem for us with its top notch expertise


    Financial Services

an amazing network security tool for cross platform environments

  • April 23, 2024
  • Review provided by G2

What do you like best about the product?
first and most impoertant advantage of cloud gaurd network security is that it is a cross platform tool and can greatly help us to keep a track of the security standards by filtering the malicious traffic
it comes with a very clean and neat user Interface.
the threat engine works so good.
it comes with sufficient built in filters to search for specific kind of traffic
traffic explorer helps in easier understanding of the network .
custom notification can be set
easy to integrate
easy to implement
What do you dislike about the product?
one can only get cloud trail and VPC logs.
using terraform to manage security policies can be tricky at times and might need to be reviewed to ensure objecte are created as per the expectation, these are not logged to ensure terraform state and the checkpoint databases are in sync with eachother.
What problems is the product solving and how is that benefiting you?
unlike native services specific to provider cloudgaurd provides cross platform support meaning that i can still get overall security of the cloud environments across the various proiders from a single dashboard and CloudGuard Network Security provides inspection throughout many parts of the cloud network.
Inspection of traffic from the internet to a VPC and from VPC to the internet .
inspects the traffic between VPCs
Inspeciton between VPCs and on-prem
IPS fuctionalities
Detailed traffic logging
identity based access