Reviews from AWS customer

35 AWS reviews

External reviews

355 reviews
from and

External reviews are not included in the AWS star rating for the product.


4-star reviews ( Show all reviews )

    Stefan Baumgartner

Unified management and policies enable secure workload transitions to the cloud

  • February 04, 2025
  • Review from a verified AWS customer

What is our primary use case?

I use Check Point CloudGuard Network Security to ensure we have the same management system for managing firewall policies both on-premises and in the cloud.

How has it helped my organization?

Check Point CloudGuard Network Security enabled us to move to cloud workloads safely while having the same level of security as we have on-prem.

What is most valuable?

The unified management, unified log management, and unified policies are all invaluable. We like that everything is unified.

CloudGuard Network Security provides us with unified security management across hybrid clouds as well as on-premise. Security operations are simplified by unified management, easing troubleshooting, and maintenance. Using the same objects in both the on-prem and cloud policies reduces the need to switch between different interfaces and log stores, enhancing our security operations significantly.

It's helped us reduce organizational risk. I cannot say by how much. Just having the same policies everywhere without having to move around different management interfaces and log stores just helps with security operations. We can see everything in one pane of glass.

We have confidence in our secure deployments and migrations. In fact, it has enabled us to move to the cloud securely. The confidence is there based on our confidence in Check Point products on-prem.

What needs improvement?

Improvement is needed in the deployment models. Currently, I have deployed VMs and installed CloudGuard as if they were gateways. Having some as-a-service models would be great.

Scalability could be improved as well; needing to purchase a new license each time I want to add a new interface is not ideal.

For how long have I used the solution?

I have used the solution for three years now.

What do I think about the stability of the solution?

The solution works adequately, meeting my expectations for a firewall.

What do I think about the scalability of the solution?

Scalability could be improved. When we need to buy a new license, to add a new interface is not ideal.

How are customer service and support?

Support is okay. Sometimes, it is necessary to reiterate the importance of a case; however, generally, the cases are handled to our satisfaction.

Which solution did I use previously and why did I switch?

We did not use a different solution previously.

How was the initial setup?

We have an on-prem and cloud environment. The setup was relatively easy, even the first time. I just select it from the marketplace, and it appears. After that, it's the same as installing on-premise gateways, including a first-time installation wizard.

What about the implementation team?

I received assistance from an external third-party company. The experience was great and has continued to be good over the seven years I've employed them.

What's my experience with pricing, setup cost, and licensing?

The cost is adequate. I am not responsible for pricing and licensing aspects, I would say pricing is adequate. It is not cheap, however, I am not seeking cheap solutions; I want the best solutions.

Which other solutions did I evaluate?

We have not evaluated other solutions.

What other advice do I have?

I would give it a solid eight out of ten. I am not yet fully utilizing all its functionalities and I cannot assess all features. There is always room for improvement.


    Meir Carmel

Makes things easier and helps on a daily basis because it optimizes the understanding of what we have

  • February 04, 2025
  • Review from a verified AWS customer

What is our primary use case?

My primary use case is for the protection of environments that are in the cloud and multiple branches and areas that are in the layout of all the systems.

How has it helped my organization?

This solution helped us migrate to cloud environments from environments that were on premises. It helped us implement protection for our systems. The fact that it is part of Check Point's overall protection system within some kind of central management system allows us to easily manage and gain visibility on everything that happens in the organization.

What is most valuable?

The protection is at a very good level. There's a very high catch rate. It has good flexibility in operating and implementing the system.

Protection is valuable to me because security is the most important aspect. At the end of the day we are looking for what will give us the answer at the best level.

It is easy to implement, and it has a lot of flexibility compared to other systems you have in the organization. In the end, this is a parameter that, in my eyes, is very central.

In the end, it saves time. It's all in one place and you can quickly see how you're doing with the cloud environment. It just makes things easier and helps on a daily basis because it optimizes the understanding of what we have.

Instead of logging into the system by yourself and starting to check, there's another management system that sees logs. It examines the data daily, and it creates flexibility regarding what we want to investigate. It is much easier for everything to be in the same management and not scattered in all sorts of different places.

Check Point helped me a lot to know that I have a solution that is stable and answers my needs. It really gave me the confidence to move forward with the whole migration to the cloud. It was very helpful.

When I moved to the cloud, I looked at Check Point's solution and as soon as it suited me, I bought it. We chose CheckPoint right away, it was our go-to choice.



What needs improvement?

From my point of view and my needs, I don't see room for improvement. In my opinion, the more it has support for more environments and the more integration there is with wider areas, not only in Check Point's systems, but also with other systems, then I think it will allow access to more customers which is not specifically my case, but in principle the wider the system, the more it will be able to appeal to a larger audience; integration with other manufacturers in other words.

For how long have I used the solution?

I have been using CloudGuard Network Security for two years.

What do I think about the stability of the solution?

The platform is very good in terms of stability. We never encountered any issue with it.

What do I think about the scalability of the solution?

Scalability is very good.

How are customer service and support?

Support is very good. The response time is good and fast, and they are also very professional.

How was the initial setup?

I had help from a Check Point CS and it all went smoothly. There was only one person from Check Point who was in constant communication with us and provided us service in installing the solution, my experience with him was very good.

What was our ROI?

After running a test against what alternatives exist in the market and seeing what they offer, this is the solution that fits perfectly into our budget. This is a very important parameter for us, and Check Point CloudGuard Network Security did so.

What's my experience with pricing, setup cost, and licensing?

The price was really good, that's the main reason we chose it. In addition, the licensing model was very simple.


What other advice do I have?

I appreciate the cloud network security. I find it to be very effective, and I am pleased with securing cloud deployments.

I would rate CloudGuard Network Security an eight out of ten. There's always room for improvement. It could become a 10 if they had more accessibility to other platforms. Overall, it is a good product.


    Krishna KantUpadhyay

Effortless threat prevention with seamless cloud integration and responsive support

  • November 11, 2024
  • Review from a verified AWS customer

What is our primary use case?

Our primary use case for CloudGuard Network Security is to secure the cloud environment where we host our backend systems. The platform helps to guard the network security of our infrastructure by securing the traffic and preventing cyber threats.

It also ensures compliance with industry regulations. Moreover, it integrates easily with AWS and Google Cloud, allowing us to apply a unified security policy throughout our cloud infrastructure.

How has it helped my organization?

Check Point CloudGuard has been very helpful in maintaining a high level of security across our cloud environments as our apps integrate with multiple cloud services.

It ensures secure communication between services and user devices, protecting sensitive data like user information and financial transactions. This has resulted in increased client satisfaction and retention, particularly in sectors requiring stringent data protection like finance and healthcare.

What is most valuable?

One of the most valuable features is the automated threat prevention, which helps us detect and block potential cyberattacks in real-time, minimizing data breaches.

The ability to integrate with multiple cloud platforms provides a centralized view of our applications, enhancing security management. The solution also offers real-time visibility and protection against network threats.

What needs improvement?

The user interface could be more intuitive, and the initial setup and configuration can be complex, requiring a technical team.

Additional improved documentation and support would make it easier for beginners and small-scale startups. Furthermore, the pricing model is quite expensive, which could be a barrier for smaller companies.

For how long have I used the solution?

I have been using the solution for approximately one year.

What do I think about the stability of the solution?

The platform is quite stable. We have not faced any difficulties with its stability.

What do I think about the scalability of the solution?

The solution is very scalable. I would rate its scalability as nine out of ten.

How are customer service and support?

My experience with customer support has been positive. They are responsive and knowledgeable, available twenty-four by seven. However, they could improve by providing documentation for offline issues to better assist users who may not reach out to them directly.

Which solution did I use previously and why did I switch?

Before using Check Point CloudGuard, we managed security through a team of experts. Due to budget cuts during a recession, we switched to using this solution to maintain our security standards.

How was the initial setup?

The initial setup was quite complex, requiring a technical team to understand the processes and implement the solution. More intuitive configuration tools and better documentation would be helpful.

What about the implementation team?

We deployed the solution with a team of fifty-seven people, including cybersecurity engineers and cloud experts, along with support from customer service.

What was our ROI?

Implementing CloudGuard has resulted in an excellent return on investment over one hundred percent ROI. It has saved costs in our security team, saved potential security breach costs, and enhanced client satisfaction.

What's my experience with pricing, setup cost, and licensing?

The pricing and licensing are expensive, costing between seven thousand to eight thousand dollars. While it offers good features like threat prediction management, reducing the cost will make it more accessible to a broader audience.

Which other solutions did I evaluate?

We have not used other network security solutions before Check Point CloudGuard.

What other advice do I have?

It is important to prioritize security if managing data in multi-cloud environments. Having a technical team familiar with cloud security is recommended. Working closely with Check Point's support team can help in navigating complex terminologies and enhancing security across cloud platforms.

I'd rate the solution eight out of ten.


    PRASHANT GARJE

Cost-effective, supports automation, and provides good security

  • May 22, 2024
  • Review from a verified AWS customer

What is our primary use case?

We are using Check Point CloudGuard as a firewall. Along with the firewall, we have incorporated multiple blades. Initially, the firewall used to be a single security device, and along with that, we required antibot, antivirus, IPS, and IDS devices. Check Point CloudGuard is a combination of all the devices and functionalities in a single device. It is a next-generation firewall. The main use case of this firewall is to protect our entire cloud and provide perimeter cloud security at L3 and L4 levels.

How has it helped my organization?

It is a next-generation firewall. Threat prevention and threat detection blades are available with the firewall. As soon as you enable the blades and you have the license for it, you are good in terms of threat prevention. You do not need to do any specific settings. You just need to enable the blade, and the firewall will take care of the rest of the things. That is how it works.

We are using the Check Point CloudGuard firewall with autoscaling in the AWS and Azure cloud. We have a minimum capacity of two firewalls and a maximum capacity of ten firewalls. If the CPU utilization increases or the memory utilization increases, the capacity will be increased to three from two. Till the service comes down to the threshold level, it will keep on adding more firewalls, so we have ease of operations. We do need not to worry about what we will do if a firewall fails.

When I joined my organization, we were using this CloudGuard firewall in the active/standby firewall cluster. In such a setup, the firewall that is active processes your traffic. The other firewall is in the standby mode. It is not processing the traffic, but it is still costing you. Even though it is not being used, it is still cost-consuming at the cloud level. We changed the setting to autoscaling. After adopting the autoscaling mode for this firewall, we need a lower number of CPU and memory. All the firewalls are active, so we need not worry about the standby firewalls and all those things. So, we have transitioned from these conventional active/standby firewalls to autoscaling firewalls. With this, we are able to save costs and improve performance. All the firewalls are active/active but with fewer CPU cores. When we have fewer CPU cores, we need less number of licenses, so we were able to save the cost. The performance has also been great.

What is most valuable?

The most important feature is that we are able to use Check Point CloudGuard Firewall for our cloud security. We can make the deployment automated. We do not require manual intervention. With the help of automation, we are able to deploy it within minutes, and we are able to discard it within minutes. We can do hardening and create policies. All those things are very advanced.

Secondly, Check Point is one of the big OEMs available in the world from the firewall perspective. It is better than Palo Alto and Juniper firewalls. It is one of the best firewalls available in the industry.

What needs improvement?

We have done a lot of automation with the firewall, but sometimes, there are some failures because of some bugs. The fixes for them are still not available. We have daily or weekly communication with the Check Point people giving support in the India region, but we have not seen much improvement or response to our requests for some additional features. We are moving to infra as a code, so we are expecting more advancements in this product. Just installing the patches is not going to help us. They need to focus on this area.

I expect Check Point CloudGuard to come up with some AI/ML integration. A firewall is the first L3 security device available to you. It is the single point that manages or processes the traffic for an organization. There is a possibility that the device goes down or gets rebooted for any reason. The integration of artificial intelligence with the devices can help us to know in advance that there might be a surge in traffic. There might be a spike in the traffic, so we can have some additional firewalls integrated. This predictive analysis has to be there. This way, if required, a second, third, or fourth firewall can come into the picture. All the firewalls will process the traffic simultaneously. I am expecting such capability. This sort of feature is available with AWS. We are deploying all the firewalls on AWS, but it would be easy if, in the future, such a feature is available from the OEM or Check Point itself. It will be very helpful for the organization.

We have had a couple of outages because of some misconfiguration. They were human errors but there were no prior indications that if we were making these sorts of changes, this would happen. People making the changes on the firewall were not aware of this, and that is the reason why the outage happened. In a financial organization, an outage of even five minutes can cost a lot.

For how long have I used the solution?

In our organization, we have been using it for more than four or five years, but I have hands-on experience with it for the last three years.

What do I think about the stability of the solution?

I would rate it an eight out of ten for stability.

What do I think about the scalability of the solution?

It is scalable. I would rate it a ten out of ten for scalability.

How are customer service and support?

I would rate their support a five out of ten because I never got good support. Whenever I have raised a TAC case, their support has not been great. It is not as good as others.

They need to improve from a knowledge perspective. I had a couple of issues, and they could not understand those issues easily. They should not just take the logs and analyze the logs. They should be providing a solution. Being a financial organization, we cannot afford a long downtime. We expect a faster resolution. If a support engineer is not capable of handling a case, he or she should escalate it to a higher level, but they are not doing that on a regular basis. They make you lose days by dragging the case.

Which solution did I use previously and why did I switch?

In my organization, we have two different Infra teams. We have the Network Security Infrastructure team that manages the on-premises setup, and then we have the Cloud Network Security team that manages the cloud. I am a part of the Cloud Network Security team, and we are using the Check Point firewall. The on-premises team was using Juniper and Palo Alto firewalls, and they are now using the Check Point firewall. It is one of the most effective products we have ever used, and that is the reason why that team has moved from other OEMs to Check Point CloudGuard.

How was the initial setup?

We have deployed it on the cloud. We have AWS, Azure, and GCP clouds.

The deployment was done with the help of AWS CloudFormation templates which are very generalized. I just downloaded the templates and customized them as per our requirements. I faced a few challenges because I was not completely knowledgeable about CloudFormation, etc. It was not very challenging from the Check Point side. It was an easy deployment.

I faced a couple of challenges while integrating it with our existing ecosystem. Even though Check Point is the OEM, we have third-party vendor support here in India. The challenges that I was facing at the time were also new for them, so I sorted out those issues myself by referencing some online articles on Check Point. I was able to overcome those challenges at the time. It was not a big deal. There was no huge challenge.

What about the implementation team?

Initially, we involved people from Check Point and the third-party vendor of Check Point, but at later stages, we were capable enough to develop things in-house, so we did it ourselves.

The Cloud Network Security team has ten people. I am handling the AWS cloud deployment along with a colleague. Other colleagues are involved in Azure and GCP deployment. Overall, there are ten people for deployment and management, but mainly, two or three people are involved in the deployment at a time.

We have deployed it in two regions. It is deployed in the Mumbai and Hyderabad regions of AWS in India.

What was our ROI?

We have seen 70% to 80% ROI.

What's my experience with pricing, setup cost, and licensing?

I do not know the exact price, but it is fairly priced. It is neither cheap nor costly.

As compared to other OEM vendors in the market, it is cost-effective for us. There are multiple things we need to consider while selecting a certain product. We have AWS, Azure, and GCP clouds, and we have multiple firewalls. All of our firewalls are Check Point CloudGuard firewalls. The cost can vary based on the licenses that you are using. For IPS, IDS, antivirus, antibot, and other capabilities, additional licensing costs might be there. When it comes to security, it gives us great security. Considering that factor, it is cost-effective for us.

Which other solutions did I evaluate?

I have not evaluated other solutions. Based on the input from my seniors, this is the best solution available in the market. I have heard that Palo Alto also has a cloud-based product called Prisma Cloud, which has some advanced features integrated by using AI/ML technologies. I would love to evaluate Prisma Cloud.

What other advice do I have?

I feel confident using this product. In fact, I have completed a few certifications related to Check Point CloudGuard. I am a Check Point certified administrator, and I am also a Check Point Certified Cloud Specialist. I have also been working with automation-related things, and sometimes, we do some bash scripting and shell scripting to make things easier for us. Traditionally, you can only access the firewall via a CLI. That is the basic level, and at the next level, you should be able to do a few daily things in an automated way. I am very good at that.

I would recommend this solution, but it also depends on the requirements. It is a cost-effective solution. If you are a small organization or a startup, you do not need to have this solution. If you are a big organization with 5,000 to 10,000 users, you can go ahead with it. The ROI for our organization was up to 80%, but it necessarily would not be the same for other organizations.

Overall, I would rate it a nine out of ten.


    NikhilKrishnan

Highly reliable, great visibility, and centralized management

  • April 16, 2024
  • Review from a verified AWS customer

What is our primary use case?

Basically, we are using Check Point CloudGuard firewalls everywhere. We are using them at the perimeter and internally.

By implementing this solution, we wanted to protect our perimeter. We are using Check Point along with other solutions to protect our perimeter. We also have many application-level use cases that can be solved with Check Point.

How has it helped my organization?

Most of the things that we have are on the cloud. Its main benefit is reliability. We have tested so many firewalls on the cloud, but when it comes to reliability, other firewalls fail miserably. Check Point is very good. It is a very reliable solution. With other vendors, when you move something to the cloud, the features that they are offering might only work partially. We never faced any such issue with Check Point. They offer features that will work completely. Apart from that, they have solutions for almost every cloud use case. That is another thing we love.

CloudGuard Network Security provides unified security management across hybrid-clouds as well as on-prem. They have a centralized management server. There is a process called CME. If you have multiple clouds, such as AWS, GCP, and Oracle, and you are deploying CloudGuard across all the clouds, you have single management to take care of everything. This is why they provided a unified management solution. CME takes care of scaling and integration. It has a zero-touch approach. It takes care of everything. You just need to deploy it, and the connectivity should be there. It then takes care of everything. It drastically reduces the deployment time and administration overhead.

When any incident happened, it was able to tell us the particular packet associated with that. Based on its internal intelligence, it identifies everything. We were not even aware that there was an attack like that, but it gave us complete clarity about what happened and what was the attack journey. Visibility-wise, it has been very good.

It makes us confident in our security. We have proper visibility into the network. We can see exactly what is happening. We get this level of clarity. Especially when we offload the SSL capability on the firewall, we have unparalleled visibility on even the SSL traffic.

What is most valuable?

The number of options it gives for deployment or security is valuable. When it comes to security, it has a feature that is super awesome for zero-day-based attacks. Their IPS is also very capable. We tested other firewalls, and we understood that it is the best one in the market.

When it comes to the firewall capabilities, the level of information that it offers for any security incident is very good. It gives a very good clarity about what happened and at what time. It is very good.

There is centralization. You can manage everything in a single pane, and you have support for all the software. If it is a Kubernetes, you have a solution for it. If it is IOT, you can cover that. You have gateways as well for network security.

What needs improvement?

The main issue that I have noticed is that for deployment, it still requires a dedicated management server, and the gateway is completely different. That sometimes can cause issues. If it loses communication with the management server and you want to push any sort of critical policy, that would be affected. Apart from that, I do not see any issues. Everything else is going well.

For how long have I used the solution?

We have been working with Check Point firewalls for more than ten years. We are currently using Check Point CloudGuard firewalls.

Check Point also has NGFW firewalls. They are hardware-based firewalls. All the features are identical. The only difference is that one is on a virtual platform, and the other one is on a physical platform.

What do I think about the stability of the solution?

It is reliable.

What do I think about the scalability of the solution?

We are only using auto-scaling firewalls. The good thing is that it scales well. Within seven to ten minutes, it gets integrated with the management server. If there is a failure, the firewall will be ready within ten minutes.

We have a team of around seven people who take care of the network security part. Our environment can go up to 3,000. If you combine the server users and the end users, there are more than 10,000 users.

How are customer service and support?

We work closely with Check Point support when there is any issue or limitation. When we face any issues related to processing, scale-out, or delay, we definitely connect with the Check Point support. They usually provide the solution quickly.

I would rate their support an eight out of ten. The reason why I am not giving them a ten is that we are connected through a third party. We cannot directly engage with Check Point. We usually contact this third party, and they engage Check Point support. We have a technical person assigned directly, which is a good thing, but this is how we initiate the process.

How was the initial setup?

We are mostly relying on TerraForm. For us, the deployment is very straightforward. When you deploy, it will automatically integrate with its management server, so you do not need to put in any effort. The only thing is that you should have the connectivity between the gateway and the management server. Once you deploy, it automatically gets added to the management. The policy push is automatic. That is very good. So, when it comes to deployment, after pushing the code, you do not need to do anything. Everything will come online. That is the best part.

We do have a couple of gateways in management, but I do not take care of that part. I am mostly on the cloud side.

It takes five to ten minutes for initialization and then there is the management part. At the maximum, it will go up to 30 minutes. I usually see everything happening within 15 to 20 minutes and not more than that, but if there is any connectivity issue or any other error, then the duration will get affected. If it is straightforward, it will take a maximum of 30 minutes and not more than that. Because the integration is automatic, I do not need to onboard the gateway to the management server. There is a functionality called CME that takes care of the entire thing.

In terms of maintenance, it does not require any maintenance. The only catch here is that because it is a cloud version, when it comes to upgrades, you cannot upgrade the existing versions to newer versions. We simply deploy the new one. It is not a complicated task. This is the only thing when it comes to maintenance.

What about the implementation team?

I was the main person who took care of the deployment engineering part.

What was our ROI?

I do not have visibility on the ROI, but we are completely satisfied with the performance. We will continue with Check Point in the future. We have been renewing their licenses without thinking about any other firewalls. I consider it as a good investment, but this aspect is managed by a different team.

What's my experience with pricing, setup cost, and licensing?

We have an enterprise licensing team that works closely with Check Point. I know that we have an enterprise agreement with Check Point. That gives us some benefits, but I do not have more information about that.

Which other solutions did I evaluate?

We tried the Azure Firewall. It was good, but zero-day, URL filtering, and NAC capabilities were not there. It was a native firewall, but it was not able to fulfill our use cases. The main competition was against Palo Alto. When we did the comparison, we found Check Point to be more reliable. With the Palo Alto firewall, we had issues with autoscaling. It was not working as expected. These were the two that we tested. Being a bank, we cannot test everything. There was a discussion with Cisco as well, but we did not go with Cisco.

The advantage that Palo Alto has over Check Point is the GUI. They do not require a dedicated management appliance to be deployed to access the firewall capability. They do have that platform, but the individual gateway can be also accessed via a dedicated GUI. With Check Point, you have to have the software called SmartConsole. It is very good, but a company like ours has too many gateways. When you have so many gateways onboarded to the management, it will be slightly slow, but it is not a show-stopper. The GUI is good, but you require the client applications to be installed on your laptop. From the GUI itself, you would not be able to access them. That is one advantage of Palo Alto. You can straightaway access them through the GUI. The software that you need to install for Check Point is a huge one, so the performance depends on the machine. If you have many gateways associated, it can be a bit slow at times.

Check Point is a number one vendor based on the NSS labs and other regulators. In terms of performance and security, Check Point is always number one. Irrespective of how many firewall vendors are there, Check Point will always be number one. Check Point's capability to identify an incident is also very good. Its performance is also good. We were worried that if we moved to the cloud, unlike on-prem, we would not have any dedicated hardware to accelerate something. However, when we migrated to CloudGuard, we did not face any issues.

What other advice do I have?

When it comes to the cloud, I would definitely recommend the solution. One main thing is reliability. I appreciate Check Point for that. For an organization like ours, security is the main thing. Check Point has been able to protect us from various attacks. Autoscaling and other things are also working perfectly. We were able to achieve all of our use cases with the Check Point CloudGuard firewall. I do recommend this solution.

For zero-day attacks, I know there is technically no single solution, but our observation is that for most of the sophisticated attacks, if it is not already there, Check Point will have a solution within a day. When it comes to DDoS and bot-level attacks, Check Point has a sophisticated approach to prevent them in most cases.

Overall, I would rate this solution a nine out of ten.


    RajivT

Outstanding support, reasonable price, and enables our staff to securely work from home

  • April 12, 2024
  • Review from a verified AWS customer

What is our primary use case?

We had the firewalls set up in the cloud systems. We were using them for VPN as well as the encryption of traffic coming in and leaving the cloud.

When COVID-19 hit and everybody started to work from home, we did not have a scalable VPN technology. Also, with more people working from home, security was a bigger concern. CloudGuard Network Security addressed both needs in one single product.

How has it helped my organization?

After implementing CloudGuard Network Security, overnight, 500 people could work from home on a secure and encrypted tunnel. What more could we ask for? When COVID-19 hit and everything closed down, we were able to spin this up within 2 weeks.

CloudGuard Network Security provides us with unified security management across hybrid clouds as well as on-prem. There is a single admin client that you can use. You can have a firewall deployed on-prem. You can have a firewall deployed in GCP. You can have a firewall deployed in AWS or Microsoft Azure, but you can manage it all with a single pane of glass. You can have a single management station managing all of these.

We are very confident about it and our security. It is a very robust solution.

What is most valuable?

The endpoint VPN is super stable. The routing is also very good. We tried a competing product first, but we could not make it work. We came across CloudGuard. The network routing across different virtual networks in Azure and AWS was way ahead of any of the other technologies. That helped us be able to cover the whole network using one single cluster.

What needs improvement?

They have come such a long way. There may be other areas that other people use, but as far as I am concerned, I have been very happy with it. There are always newer features getting added and new encryption protocols coming. I can see where they are going and how far they have come. I have been using the Check Point firewall since 2010. It has been 14 years, and I have seen how they have improved.

They are coming out with more SD-WAN express route support from a firewall perspective. That would be great. They keep on launching new features. That is how they work.

For how long have I used the solution?

I was one of the first sites to use it as a PoC before they even introduced it to the world. It has been 4 or 5 years.

What do I think about the stability of the solution?

I would rate it a ten out of ten for stability. It has been running since we put it up.

What do I think about the scalability of the solution?

I would rate it a ten out of ten for scalability. It depends on your design. You can either have a static deployment where there is only one firewall, two firewalls, and four firewalls, or you can put it in the elastic mode where it will spin up as the load goes up. It will auto-scale up and auto-scale down. It is fantastic.

How are customer service and support?

They are fantastic. Their technical support is absolutely great. There is ownership right from the top down. They know their product. They stand by their product. If there is a feature that is not working, I have seen them write patches for me in 48 hours. They offered to provide the patch by Sunday evening in Tel Aviv, and by Sunday afternoon, I had an email saying that the patch was available for our download. We could download it and reinstall it. That patch was only written because of something in my deployment. It was not like they had 200 customers who complained about it. I was the only one complaining about it.

How was the initial setup?

We did a PoC for one week. We had some major issues because of sizing. We sized CloudGuard too small, so we made it bigger. The next week, we did another PoC, and it worked well. By the third week, we were done. We went live, and everybody was working from home.

I would rate it an eight out of ten in terms of ease of installation.

Their support was good. We set it up when nobody else in the world had seen it. We were probably the third company in the whole world to roll it out. We were that new to it. Nowadays, I would rate their support an eight out of ten, but in those days, it was one out of ten because we were all learning together.

What about the implementation team?

I was the only one involved in its deployment. To deploy this, you need to have a background in IT security and networking put together.

What was our ROI?

We have seen an ROI. 500 people were able to work from home. That itself is a huge ROI.

It is one of the top solutions in the world. We know that it is protecting our entire cloud infrastructure, so it makes a lot of sense.

What's my experience with pricing, setup cost, and licensing?

I quite like the way they priced it. It is very reasonable.

Which other solutions did I evaluate?

We did evaluate other solutions. We looked at Fortinet, and they could not do cross-VNet traffic at that time. We spent almost five or six days. We worked 10 to 12 hours a day. Even after 60 to 70 hours, they could not make it work, but it worked out-of-the-box with CloudGuard Network Security. In terms of ease of use, CloudGuard Network Security is any day easier.

We did not just go with our cloud vendor's cloud firewall because the cloud vendor did not have a firewall at that time. Secondly, even if they did, it is always good to have a third-party product protecting the cloud. If we are using AWS, I would not put an AWS firewall there because if there is a compromise somewhere else, it is most likely going to carry over to their firewall too because everything runs on the same fabric, whereas this is separate. It gives a completely independent security front end.

What other advice do I have?

I would definitely recommend it. I have used it. I know how it works.

Check Point has been one of the pioneers of firewall technology. This is the only product that they really do. They are into cybersecurity firewall technology. They are not like other competitors, such as Cisco or Fortinet, who also have network switches, hubs, routers, etc. Check Point is a dedicated company that does cybersecurity. All in all, this is what they do. You can see the investment coming from the top down. They have ownership of the product. I have raised complaints that have gone up to Gil Shwed. He is the CEO and the founder of Check Point. I have got an email from Gil saying that he knows we are frustrated, but they are working on it, and he will make sure that this gets fixed. That is the kind of ownership they have.

Overall, I would rate CloudGuard Network Security a nine out of ten.


    Cassio Maciel

Protects very well against advanced threats and covers all features under one license

  • April 12, 2024
  • Review from a verified AWS customer

What is our primary use case?

We are using CloudGuard Network Security to protect North-South traffic or VPCs. We are using the CloudGuard firewall between the Internet and VPCs. All the traffic needs to pass through the firewall.

How has it helped my organization?

CloudGuard Network Security provides features, such as threat emulation, that native cloud solutions do not offer. AWS, Azure, and GCP have a lot of features, but you sometimes need to pay charges for specific features. With Check Point products, you have all these features in one license. You pay once and you can use everything.

CloudGuard Network Security improves our security against advanced threats. Others do not offer features like threat emulation out of the box. CloudGuard Network Security protects very well against advanced threats.

We have a high level of confidence in our cloud network security by using CloudGuard Network Security. The product is similar to what we use in traditional data centers. The infrastructure is almost the same. The way to manage the policies is the same. It is very easy to implement and manage CloudGuard networks. There is some difference when you are using auto-provision, but in the end, it is the same technology. It is easy for a traditional network engineer to work with CloudGuard.

We did not go for the cloud vendor's cloud firewall because we wanted to be able to manage all the firewalls, policies, and other things from a single point.

What is most valuable?

The most valuable feature for me is that you have just one license. You can test and implement everything you need with one license. You do not need to pay for separate module licenses when you want IPS or other features. The license includes everything that you need.

What needs improvement?

The version upgrades need improvement. We faced issues while upgrading our CloudGuard Network Gateway. When we tried to use the template that Check Point offers on their site, it was not available for the second to the latest version, so I was forced to upgrade my management server. That was very challenging for us.

For how long have I used the solution?

I have been working with Check Point CloudGuard Network Security for 8 years.

What do I think about the stability of the solution?

I cannot remember the last time I had an issue. It is stable, but every product has a few bugs. If you maintain the configuration and the versions, everything is fine.

What do I think about the scalability of the solution?

We do not have any problems because we can use the auto-provision templates. If I need to scale up or scale down, I can do this. If there is any issue, it is very transparent. For example, if I lose my gateway, the manager will automatically create a gateway and bring everything up.

How are customer service and support?

Their support is very good. Their response is fast. You can contact an engineer in a few minutes, but it depends on the severity of the issue. In the case of a high-severity issue, you can talk to an engineer to assist you with an issue.

Compared to other vendors our company has been working with, Check Point has better support. They have the best technical staff.

Which solution did I use previously and why did I switch?

We only use Check Point products. In our data center, we are only using CloudGuard.

How was the initial setup?

It is very easy. With a few clicks, you can implement your firewall.

What's my experience with pricing, setup cost, and licensing?

It is fair. Its license covers all the features. There is a cost-benefit. The licensing for the cloud is better than on-premises because, with on-premises, you have to pay separately for different things.

What other advice do I have?

Overall, I would rate CloudGuard Network Security a nine out of ten.


    reviewer2379468

Offers advanced threat prevention capabilities, network visibility, and control

  • March 15, 2024
  • Review from a verified AWS customer

What is our primary use case?

I use CloudGuard Network Security to enhance our cloud exchange points' security. Our customers can seamlessly connect across multiple clouds within the region, and CloudGuard provides next-generation firewall services to ensure their data and applications are protected.

How has it helped my organization?

CloudGuard Network Security has significantly improved our organization by helping us tap into the Check Point customer market.

What is most valuable?

The VPN features in CloudGuard Network Security have been the most valuable for us. It allows us to scale securely within our infrastructure, providing both strong security and VPN capabilities.

What needs improvement?

In the next release, including VRF support would be highly beneficial. Many customers have been requesting this feature, as it is currently lacking in Check Point's offerings, which can make architectural designs more cumbersome compared to competitors.

For how long have I used the solution?

I have been working with CloudGuard Network Security for two and a half years.

What do I think about the stability of the solution?

As for scalability, it could be even better with VRF support, as it would allow for more efficient scaling without the need to deploy separate firewalls for different workloads.

What do I think about the scalability of the solution?

CloudGuard Network Security has been quite stable.

How are customer service and support?

I would rate technical support for CloudGuard as an eight out of ten.To make it a ten, I would expect more proactive assistance and smoother transitions between support levels.

Which solution did I use previously and why did I switch?

When comparing CloudGuard Network Security to other solutions like Fortinet and Palo Alto Firewalls, they are similar in terms of identifying security threats. They all offer robust features such as antivirus, deep packet inspection, and IPS. Some of our customers have transitioned from Palo Alto to Check Point. While I don't have specific reasons, it could be related to factors like pricing.

How was the initial setup?

We deployed it across multiple locations, utilizing AWS for SMS management. The environment was designed to ensure security and privacy, with all deployments being private despite being in the public cloud. Our implementation strategy was flexible, depending on the customer's needs, focusing on workload security first and then gradually migrating workloads. The initial deployment was straightforward.

Which other solutions did I evaluate?

One significant difference between CloudGuard Network Security and other solutions is the lack of VRF support. This means that when dealing with customers who have multiple segments and exchange points, deploying new firewalls becomes necessary. Competitors' solutions typically include VRF support, making scaling much easier and eliminating the need for additional firewall purchases.

We chose CloudGuard over other vendors because it allows us to provide unified security across multiple cloud providers like AWS, Azure, and Google Cloud. Unlike native cloud firewalls, CloudGuard offers scalability and the ability to expand across different platforms, meeting our customers' needs for consistent security across diverse cloud environments.

What other advice do I have?

We implemented CloudGuard Network Security to meet our customers' demands for enhanced security features and centralized management. They specifically requested Check Point CloudGuard for its robust capabilities, including SMS and MDS for global management.

Using CloudGuard Duo Security has provided us with the ability to manage globally through MDS, which has been a valuable capability. It is convenient to have multiple pockets of global management from UniFi OS.

We realized the benefits of CloudGuard Duo Security quickly after deployment. Understanding the architecture, especially the MDS setup for higher-level organization control, allowed us to establish multiple pockets of management efficiently.

Unified security management allows us to streamline our security operations significantly. With centralized management through SMS and MDS, we can efficiently oversee not only the firewalls within our cloud exchange points but also on-premises devices, enabling a cohesive and unified security architecture across all environments.

I'm very confident in CloudGuard Network Security because it helps us secure our global network. With CloudGuard, we can set up rules to protect against risks from on-premises traffic and ensure security through various measures like single sign-on integration and VPN restrictions.

CloudGuard Network Security is a great product that fulfills firewall needs effectively and provides detailed insights. However, in multi-segment environments requiring multiple VRFs, it can be cumbersome and costly due to the need for separate firewalls.

The best lesson I have learned from using CloudGuard Network Security is to carefully consider the scalability requirements of each environment. While Check Point offers robust features, the lack of VRF support can lead to increased costs and complexity, especially in multi-segment setups where separate firewalls are needed for each segment.

Overall, I would rate CloudGuard Network Security as an eight out of ten.


    Jonathan Gamlin

Unified security management, excellent support, and competitive pricing

  • March 15, 2024
  • Review from a verified AWS customer

What is our primary use case?

We primarily use it for egress internet traffic for four clouds, as well as between clouds to on-prem. Those are the main use cases. We have another small use case for ingress traffic, but it is a very small use case right now.

By implementing CloudGuard Network Security, we wanted to get network visibility in our clouds. That was the main point. We also wanted to provide a segregation layer with stateful inspection with all the next-generation features, such as IPS.

How has it helped my organization?

CloudGuard Network Security certainly has made our organization more secure. Our business partners cannot inadvertently open up the access that they should not be just to get things done. They now have to go through our firewall. We have got the inspection layer. Our security organization can see threats if they come in and take action on them. We were able to realize its benefits almost instantly.

CloudGuard Network Security provides unified security management across hybrid-clouds as well as on-prem. We heavily use global policy to join on-prem and the cloud, as well as multiple clouds. It is a huge benefit for us as we can set a global standard for policy and then push that across all the different security zones.

We are very confident in our cloud network's security. We have had many years of experience developing it, so we were very aware of the design and the solution within each cloud. We are confident with how we deploy it, and we have plans to make it more efficient as we go.

What is most valuable?

Most recently, it would be the dynamic objects or datacenter objects. The query feature is going to be a game-changer for us as we move forward. It simplifies our policy, and it gives us a way to dynamically learn and discover things in the cloud instead of having a static way.

What needs improvement?

Currently, we are struggling with licensing just because of the pace and growth of our cloud. Keeping up with licensing for new regions and new gateway usage is certainly something we are looking into. We are working with our accounting to figure out how we can improve. The licensing piece is big for us.

We are at the place where we are looking at better integration with the management system. We use an MDS today, and it is self-deployed. We want to get to the Smart-1 Cloud, but we do not know what that looks like today because it does not support a multi-domain setup. Smart-1 should either be able to do multi-domain or there should be some form of taking a multi-domain environment and putting it in Smart-1.

For how long have I used the solution?

I have been using CloudGuard Network Security for probably five years.

What do I think about the stability of the solution?

From our experience in five years, it has been very stable.

What do I think about the scalability of the solution?

It seems to be very scalable. We have plans to increase the usage of CloudGuard Network Security.

We do scale sets across our clouds and across many regions globally. The number of applications behind it is in the hundreds if not thousands.

How are customer service and support?

It is an excellent service. I would rate their support a nine out of ten. Improving a little bit in the smaller clouds such as Oracle and Google would help a lot.

Which solution did I use previously and why did I switch?

We did not specifically use any similar solution in the cloud. It was brand new.

How was the initial setup?

We have a public cloud and then a hybrid with on-prem. We have AWS, Azure, Google, and Oracle.

In terms of the version, on-prem, we use Maestro, and in the cloud, we use the latest CloudGuard. We use the software version R80.40 and are about to upgrade to R81.20.

Its deployment was a little complex for us because we have a very large cloud environment and we are multi-cloud. We had an existing estate, so it was hard to put a firewall in the path and not break things.

We are still implementing it because we are taking a cloud-by-cloud approach. We have done AWS and Azure. It took probably two years to do that, so I would assume that for Google and Oracle, it is going to take at least a year.

In terms of the implementation strategy, we first develop the IEC for the code to deploy it, and then we deploy it and test it in a sandbox environment. We then deploy it to non-prod and roll it out to those regions, and after that, we would do the same with prod.

What about the implementation team?

We implemented it ourselves.

What was our ROI?

We have seen an ROI, but I do not have any metrics.

What's my experience with pricing, setup cost, and licensing?

Pricing-wise, it is pretty competitive. However, I would like to see more flexible licensing. There should be more of a consume what you need and true-up type of model.

Which other solutions did I evaluate?

In the past, we have evaluated other solutions. When we tested them, they did not have the same feature set or functionality that CloudGuard had. When I initially tested years ago, the scaling probably was not as efficient. The support was also a big factor. The support that we got from those vendors was not as good as from our account team with Check Point.

When we looked at the cloud provider firewalls, they did not match up to what Check Point could do with the various deep packet features and functions like IPS. The feature set was the main difference. At the time, the cloud providers could not provide IPS or deep packet features. That was a big driver for us with Check Point. The fact that we could not integrate policy with our on-prem firewalls, which were from Check Point, was another big driver because we wanted a unified policy. Our existing relationship with Check Point helped as well.

What other advice do I have?

To those evaluating CloudGuard Network Security, I would advise certainly engaging with the Check Point account team. Get their solutions team to help you walk through the solution and talk to others in the industry about their experiences.

The biggest lesson that I have learned from using this solution is to deploy it as soon as you can in your cloud journey.

I would rate CloudGuard Network Security a nine out of ten.


    reviewer2379408

Makes securing our cloud workload super easy and has amazing stability

  • March 15, 2024
  • Review from a verified AWS customer

What is our primary use case?

We mainly use the firewall part. We use it to interface with our cloud environments.

We have a CloudGuard firewall in place, and we have Azure or AWS networks at the backend. We use it to secure workloads and be a bridge to our on-prem as a hybrid solution.

How has it helped my organization?

It makes securing our cloud workload super easy, and we are able to push any sort of policy changes we need pretty quickly. It is a lot better than the native cloud firewalls that are available in terms of ease of use and features. Check Point IPS is way more advanced than the native cloud firewall solutions.

CloudGuard Network Security provides us with unified security management across hybrid clouds as well as on-prem. It is fantastic. It makes our security operations a lot smoother because we only have to push policy once to our cloud firewalls and our on-prem firewalls. We can select whichever firewalls we want and hit install. The changes are made across all different types of devices. We had evaluated the native cloud firewalls for a specific use case, but we saw that Check Point firewalls were superior in the aspects that we were looking at for our requirements.

We just set up the firewalls and forget about them. We only have to do jumbo hotfix upgrades on the major version upgrades. For the most part, the uptime on them is fantastic. We do not have any downtime on them, so we never have to worry about them, which is why I do not have a lot of experience with them. We just set them up and forget about them.

CloudGuard Network Security has been fantastic in terms of identifying threats. Being able to log those cloud firewalls to the same place where all of our other Check Point firewalls are is a huge plus because we can see where something gets prevented by IPS or something like that.

What is most valuable?

We only use it for the firewall, so it is about security.

What needs improvement?

I want the upgrades of their CloudGuard solution to major versions to be easier. We have had a few small hiccups. They have different types of cloud clusters called Geo Clusters, and those just cannot be upgraded past a certain point, which is a hurdle that we are currently experiencing.

For how long have I used the solution?

We have been using CloudGuard Network Security for four years.

What do I think about the stability of the solution?

Its stability is amazing. We have never had any weird downtime issues with our CloudGuard firewalls.

What do I think about the scalability of the solution?

We do not use any of the auto-scaling features that Check Point provides. We do not have a use case for it, so I cannot attest to that.

How are customer service and support?

When you get the right person, Check Point TAC is fantastic, but sometimes, it can take a while to find the right tech engineer to be able to answer your problem within a reasonable amount of time. Most TAC engineers can answer a question, but some might take longer than others. I would rate their support an eight out of ten.

How was the initial setup?

It is super easy to deploy. In a few clicks, it is up and going.

What about the implementation team?

I deployed it myself.

What was our ROI?

We have definitely seen an ROI, but I am not sure how to quantify that. I am satisfied with it.

It is definitely easy to use and simple. Compared to the native cloud firewalls where if they do not have a feature, you are out of luck, I feel that Check Point has a very superior feature set.

What's my experience with pricing, setup cost, and licensing?

I like the flexibility because I am pretty sure you can use the same license on Azure or AWS. I forgot the name of the license, but there is a specific type you can use that lets you interchange them, and that is pretty good. I like that.

What other advice do I have?

I would rate it a nine out of ten. The only reason it is not a ten is that sometimes there are hiccups when we have to interact with it, such as while upgrading. These are small things, but I wish it was more seamless than it already is. It is already pretty seamless, but there can always be improvements.