Check Point Cloud Firewall All-In-One (FKA CloudGuard Network Security)
Cloud security has supported auto-scaling protection for internet-facing workloads on AWS
What is our primary use case?
I am still using Check Point Cloud Firewall (formerly CloudGuard Network Security), and using it means I am working on Check Point Cloud Firewall (formerly CloudGuard Network Security). I am working with Check Point Cloud Firewall (formerly CloudGuard Network Security). Today, I work with Check Point Cloud Firewall (formerly CloudGuard Network Security) as a service provider and partner. Clients are using Check Point Cloud Firewall (formerly CloudGuard Network Security), and the major purpose is that the application is running on the cloud, so Check Point Cloud Firewall (formerly CloudGuard Network Security) is working as a perimeter for the traffic which is coming from the internet.
What is most valuable?
The biggest advantage of Check Point Cloud Firewall (formerly CloudGuard Network Security) is that, specifically on AWS cloud, Check Point Cloud Firewall (formerly CloudGuard Network Security) deployment happens in the auto-scaling mechanism, so if a high amount of traffic hits the application, and if Check Point Cloud Firewall (formerly CloudGuard Network Security) CPU is getting increased or it is getting about 80 or 60%, a new Check Point Cloud Firewall (formerly CloudGuard Network Security) gateway will automatically be deployed and it will be functional within 10 minutes. This auto-scaling feature is very helpful and great.
Check Point Cloud Firewall (formerly CloudGuard Network Security) ensures confidence for cloud deployments and migrations, and I am happy. Check Point Cloud Firewall (formerly CloudGuard Network Security) is helpful for cloud deployments and migrations, and specifically on cloud, I can say the gateways deployed with the auto-scaling mechanism will be a great feature.
What needs improvement?
The area of improvement is minimal and not especially a super big problem currently. I would like to see some additional features added to the product, such as integrating Check Point Cloud Firewall (formerly CloudGuard Network Security) with some AI tools.
The purpose of AI integration could be helpful for security as it will analyze the logs, analyze the patterns, and based on that, suggest the security parameters or the IPS signatures and the policies, and then such configuration.
For how long have I used the solution?
I started using Check Point Cloud Firewall (formerly CloudGuard Network Security) two years ago.
What do I think about the stability of the solution?
I give Check Point Cloud Firewall (formerly CloudGuard Network Security) a nine for stability.
What do I think about the scalability of the solution?
I can give Check Point Cloud Firewall (formerly CloudGuard Network Security) a nine for scalability.
How are customer service and support?
I can give Check Point Cloud Firewall (formerly CloudGuard Network Security) nine points for support and technical service.
Which solution did I use previously and why did I switch?
I have worked with other firewalls, specifically on Check Point Cloud Firewall (formerly CloudGuard Network Security), and I can say that as compared to FortiGate and Palo Alto, I found Check Point Cloud Firewall (formerly CloudGuard Network Security) as a market leader in the security, as their IPS signature and the firewall provide enhancements with the IPS signature and the traffic.
How was the initial setup?
I give Check Point Cloud Firewall (formerly CloudGuard Network Security) a nine for installation and firewall deployment.
What's my experience with pricing, setup cost, and licensing?
I cannot take a decision on whether Check Point Cloud Firewall (formerly CloudGuard Network Security) is an expensive or quite affordable tool as I am a technical engineer, and the pricing is taken care of by the sales team only and the management.
What other advice do I have?
I am not using other products such as Harmony or CloudGuard, only Check Point Cloud Firewall (formerly CloudGuard Network Security) with management and gateway.
I cannot say why I chose Check Point Cloud Firewall (formerly CloudGuard Network Security) because I am working as a professional engineer, and that OEM partnership and engagement decision is taken by the management only. The engineers deploy and work on Check Point Cloud Firewall (formerly CloudGuard Network Security).
Currently, I do not have any examples where Check Point Cloud Firewall (formerly CloudGuard Network Security) helps to reduce organizational risk, but it does help to reduce the risk.
I give a final rating for Check Point Cloud Firewall (formerly CloudGuard Network Security) a nine.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Cloud security has protected hybrid infrastructures and supports continuous business operations
What is our primary use case?
We use both on-premises and cloud solutions and work with both. Regarding the use cases for Check Point Cloud Firewall (formerly CloudGuard Network Security), customers want to protect their infrastructure, and it was particularly valuable when part of the infrastructure is on-premises and another part is on the cloud. Government requirements sometimes mandate only on-premises infrastructure when these requirements are not present, necessitating this solution. Government customers often prefer the on-premises solution, as cloud options are not always suitable.
How has it helped my organization?
As a partner, the biggest advantage of the tool is simpler and easier implementation. I believe it is more reliable, particularly regarding electricity and non-stop business processes in companies because the major equipment is not in Ukraine territory. Some customers ask about cloud solutions because they seek safer options during dangerous situations.
Check Point Cloud Firewall (formerly CloudGuard Network Security) helps reduce organizational risk because it provides correct connections to cloud infrastructure and acts as a cloud access security broker. This function is critical in the first year of using this solution, allowing us to monitor our cloud infrastructure.
What is most valuable?
Check Point is the leader in gateways, and this is supported by Gartner, Forrester, and other review platforms. My customers with real cases also speak about this.
The major reason for choosing Check Point is that we have qualified engineers for this product, which influences my decision towards this solution. If you speak about small and medium-sized businesses, middle market, and the enterprise level, we provide appropriate solutions for these customers, and we use this vendor's solution. For smaller businesses, we also use other solutions, which are quieter.
All Check Point products are integrated with each other. We use Harmony, we use solutions from gateways, Harmony, Quantum Group solutions, web application firewall, and SmartCM, which is a tool for log analysis and visibility. We use more than fifty percent of the portfolio.
What needs improvement?
Regarding negative aspects about Check Point, previous issues included productivity metrics. Check Point solutions often do not provide as much productivity for machines' CPUs, and the implementation requires qualified engineers. It is not an easy solution to implement, and the price is above average—at least three points regarding these factors.
For how long have I used the solution?
I have been working with Check Point Cloud Firewall (formerly CloudGuard Network Security) for two years. Overall in the business, my experience in cybersecurity products stretches to five years.
What do I think about the stability of the solution?
We encounter some obstacles in our projects, but in general, I am satisfied with the stability and reliability.
What do I think about the scalability of the solution?
In terms of scalability within the product, it is not easy to expand in terms of price or market expenses.
How are customer service and support?
I am very happy with the customer service from Check Point. We have a private engineer who is closely connected to the vendor and engaged in ongoing learning programs and accreditation. For support, I would rate it around seven to eight.
What was our ROI?
Despite the price being on the higher side, the value for investments is substantial. It meets the requirements of suppliers or other business parts for security and protection against cyber risks, functioning like insurance.
What other advice do I have?
I know Trend Micro and Palo Alto products, but I am not too focused on them, and I think approximately ten to fifteen percent resemble Check Point, for example. That is why I cannot be so objective about this.
We are a partner with Check Point, and we have status, although unfortunately I cannot remember what kind of partnership we have.
Check Point Cloud Firewall (formerly CloudGuard Network Security) deployment model is primarily cloud-based. We use different cloud providers, primarily private clouds and seldom AWS or Azure.
I am absolutely happy with how secure my cloud deployments are, as the government requirements are being met. It requires qualified engineers for selling at a high level and some competitive engineering expertise.
My general rating of the product is around eight to nine.
Cloud security has strengthened hybrid deployments and supports smooth policy-driven operations
What is our primary use case?
I work for Check Point as a distributor here in Sri Lanka, and I serve as the technical architect.
We provide the entire Check Point stack, including Check Point firewalls, Check Point Email Security, and Check Point ERM. We also offer Check Point Cloud Firewall (formerly CloudGuard Network Security), though it has limited adoption in the Sri Lankan market with only a few customers. We have one customer for Check Point WAF.
We operate as a value-added distributor, providing sales support along with implementation assistance, POCs, solution architecting, and comprehensive support services.
In the Sri Lankan market, we recommend Check Point Cloud Firewall (formerly CloudGuard Network Security) to manufacturing industries and conglomerates who are on their cloud journey. However, we have a substantial market for firewalls among banks, though they are not yet ready to transition to the cloud. Therefore, our primary focus is approaching the manufacturing industry and conglomerates.
What is most valuable?
I believe the VDOM functionality from the firewall side, particularly the virtual firewalls, could be improved. For multiple virtual firewalls in cloud instances, it would be beneficial to optimize this aspect and provide consistent security levels across all instances where multiple micro-segmentation networks exist in the cloud.
One area for improvement involves policy optimization at the VDOM level to enable simultaneous policy enforcement. The policy configuration is somewhat complicated compared to other vendors in the market, and simplification would be advantageous. Enhanced ecosystem integration would also be valuable.
Additionally, incorporating CSPM into Check Point Cloud Firewall (formerly CloudGuard Network Security) portfolio would improve visibility on the application side of the cloud network, not only on the network side but also on the application side. We expect these features because vendors like Palo Alto provide comprehensive cloud security. We want our customers to experience Check Point Cloud Firewall (formerly CloudGuard Network Security) as a comprehensive cloud security platform rather than simply a cloud firewall.
What needs improvement?
Currently, we have one customer using Check Point Cloud Firewall (formerly CloudGuard Network Security), and they are satisfied. However, we need to complete an integration with a Nutanix environment for the hybrid component that the customer requested. This integration has not yet been delivered by Check Point. Once this is properly addressed, the customer will be fully satisfied with the platform.
We have not yet completed the integration and are about to begin the integration process.
For how long have I used the solution?
Overall, I have been working with Check Point for approximately five years.
What do I think about the scalability of the solution?
For this specific customer, the implementation of Check Point Cloud Firewall (formerly CloudGuard Network Security) was very smooth. However, regarding the VDOM component, the customer expected it to be at a more optimal level rather than being complicated regarding policy enforcement for the multiple micro-segmented environment. Other than that, everything functioned well.
How are customer service and support?
Technical support is excellent, and we have a country SE who provides support. The TAC support is also strong. The support from TAC has been consistently good, and there is nothing negative to comment on regarding that aspect.
How was the initial setup?
The setup process is straightforward and easy.
What other advice do I have?
Competition with Fortinet in the Sri Lankan market is limited, as they are considerably cheaper and claim to address customer requirements. When approaching this market, Check Point pricing is somewhat expensive. We reduced our prices to acquire that customer, but I think that if pricing could be lowered further, we could approach other sectors where price is a critical evaluation factor. Better pricing in relation to competition would provide us an advantage in promoting Check Point Cloud Firewall (formerly CloudGuard Network Security) in this market. My overall review rating for Check Point Cloud Firewall (formerly CloudGuard Network Security) is nine out of ten.
Comprehensive Cloud Security with Strong Threat Prevention and Centralized Policies
Single Pane of Glass for Multi-Cloud Visibility and Faster Triage
Unified security policies have protected our hybrid network with deep, user-based controls
What is our primary use case?
Check Point Cloud Firewall (formerly CloudGuard Network Security) is the main manager that provides network security in different forms in my organization. The primary task that Check Point solves is serving as the main means of network security.
Check Point Cloud Firewall (formerly CloudGuard Network Security) has several classes of modules. The main modules include Firewall, Antivirus, Anti-Bot, URL Filtering, the IPS module, and Identity Awareness, which is tightly integrated into our organization and ensures connectivity of corporate users with the corporate network, allowing us to create dynamic sessions and policies.
In our practice, we use a single common profile for all gateways in Check Point Cloud Firewall (formerly CloudGuard Network Security), which allows us to unify all policies and, with the help of sections, display what accesses exist for particular services.
The Identity Awareness module helps our company by allowing us to have approximately fifty Active Directory controllers. We have deployed three Identity Awareness controllers, which are connected to all our security gateways. It works on the principle that when a user logs into their device, data about their current IP address and login is written to the Active Directory logs. The Identity Awareness controller integration reads them and sends them to the security gateway. Check Point Cloud Firewall (formerly CloudGuard Network Security) then queries the Active Directory controller, pulls in all the user's groups, and allows access for each user based on their Active Directory groups, which makes it possible to create dynamic policies and dynamic accesses.
Check Point Cloud Firewall (formerly CloudGuard Network Security) is also used to provide VPN access for engineers. At the moment, we are no longer using Check Point Cloud Firewall (formerly CloudGuard Network Security) together with other Check Point solutions. Previously, we had approximately five projects integrated with Check Point. We used their IA (Identity and Access) solutions, their analyzers, and also their endpoint client at the workstation level.
What is most valuable?
The main benefit and main advantage of using Check Point Cloud Firewall (formerly CloudGuard Network Security) is that we use unified security approaches both on on-premises segments and in the cloud. We have the same set of policies applied to different types of gateways—both physical and virtual. A unified approach greatly simplifies the administration of the entire network.
By default, most companies do not use separate firewalling solutions in the cloud at all. They use basic functions such as security groups, NACLs, target evaluation, and similar tools. This is sufficient for them. However, all these solutions do not allow the network to be protected from more advanced attacks above standard firewalling. Check Point Cloud Firewall (formerly CloudGuard Network Security) or any NGFW solution makes it possible to protect against a large number of attacks at the IPS, antivirus, and anti-bot level. If there is a sandbox—SandBlast—then the solution can also inspect what is inside the packets themselves to maximally protect the corporate network. By default, cloud-native solutions do not provide this capability.
What needs improvement?
The main limitations of Check Point Cloud Firewall (formerly CloudGuard Network Security) are not in Check Point itself but in the cloud platforms on which it is deployed. Because not all clouds have L2 infrastructure, you cannot build a unified clustering system everywhere. As a result, the problem usually is not with Check Point, but with the cloud.
The main problem with Check Point Cloud Firewall (formerly CloudGuard Network Security) is that it uses a separate thick client instead of a browser. A browser-based SmartConsole exists, but it still has a number of limitations, while the thick client, the so-called SmartConsole, often works unstably, freezes, and has to be restarted.
I do not recommend using Check Point Cloud Firewall (formerly CloudGuard Network Security) as a VPN hub for site-to-site VPN because it is inconvenient to monitor the state of its tunnels, especially visually. It does not have a convenient snap-in and everything can be checked only via the console, which is very inconvenient. Check Point is not the most universal solution as a device that provides routing and administration capabilities in addition to security. It is an excellent firewall, but it has a number of limitations in terms of routing and in creating VPN sessions, especially in terms of displaying their states.
For how long have I used the solution?
I have been in my current position for more than seven years.
What do I think about the stability of the solution?
Regarding the firewall of Check Point Cloud Firewall (formerly CloudGuard Network Security), I would rate it an eight because of its not always stable operation. As a universal device that provides both security and some routing functions, I would rate it a seven.
Check Point Cloud Firewall (formerly CloudGuard Network Security) is an excellent central firewall. At the same time, it has some limitations in terms of optimization at the level of displaying VPN-tunnel operation. It also has a more complicated approach to building clusters. Unlike Fortinet, for example, it does not allow you to simply make an active-passive configuration using a shared config. Its clustering approach uses the presence of two IP addresses on each node and necessarily one shared virtual IP address using a VRRP-like architecture. I consider this inconvenient, especially when you need to swap nodes or when the role of each node changes.
I handled the entire technical part of Check Point Cloud Firewall (formerly CloudGuard Network Security); a separate manager was responsible for licensing and handled all licensing issues for all products, so that was not my area of responsibility.
Check Point Cloud Firewall (formerly CloudGuard Network Security) still has many additional tools that are not fully integrated into SmartConsole. To get to some specific Check Point functions, you have to open additional consoles, which is very inconvenient. The thick client, SmartConsole, is not maximally stable. It often freezes and requires a lot of resources.
I do consider Check Point Cloud Firewall (formerly CloudGuard Network Security) to be a stable solution, but I also believe that Check Point requires constant monitoring and timely reaction to possible failures.
What do I think about the scalability of the solution?
Check Point has two solutions: cluster and Maestro. ClusterXL is initially intended for a certain volume of traffic. Maestro technology allows you to scale out the firewall group and expand the capabilities of the logical group.
How are customer service and support?
The work of Check Point's customer support for Check Point Cloud Firewall (formerly CloudGuard Network Security) varies. We had a large number of cases with Check Point. There were cases that were solved fairly quickly. There were very long ones. There are still cases that we have not closed, but we are no longer actively dealing with them—we have found workarounds to temporarily close certain problems.
Which solution did I use previously and why did I switch?
In my practice, I have also used Fortinet's solution, which is also very stable. Fortinet uses the same approaches as Check Point; it has one and the same operating system across its devices. Unlike Check Point, Fortinet has a number of advantages and a number of limitations. The main advantage is its versatility: it acts as both a firewall and a router, works perfectly with VPN, but in terms of security class, it has limitations. Check Point Cloud Firewall (formerly CloudGuard Network Security), as a firewall, has a number of advantages. If you analyze the datasheets provided by Check Point and Fortinet, Fortinet greatly inflates its performance figures.
I have also used solutions from Fortinet and Cisco ASA before moving to Check Point Cloud Firewall (formerly CloudGuard Network Security) because it provides more capabilities in terms of security and deeper analysis, as well as more detailed troubleshooting options. At the same time, it has some limitations in terms of performance and stability, which I have already mentioned.
How was the initial setup?
We have had all possible options for deploying Check Point Cloud Firewall (formerly CloudGuard Network Security). Approximately sixty percent are solutions represented as Quantum (CloudGuard) in configurations like VSX and standalone. We had solutions integrated with VMware NSX, but we have already abandoned them because VMware no longer supports such architectures. Forty percent of our current firewalls are firewalls deployed in public clouds—Azure and AWS.
What about the implementation team?
We initially purchased Check Point Cloud Firewall (formerly CloudGuard Network Security) with licenses from AWS, and later we switched to purchasing licenses from an integrator and changed the licensing approach from pure cloud to external licensing.
What was our ROI?
The main investment effect and everything I can say is that for all the time of my personal work at companies, our services have never been hacked with Check Point Cloud Firewall (formerly CloudGuard Network Security). There were many attempts, they were all logged, but there were no successful hacks. This is the main benefit we gained from working with this product.
What's my experience with pricing, setup cost, and licensing?
Since we use a unified standard for using policies and modules in Check Point Cloud Firewall (formerly CloudGuard Network Security), we can clearly plan which modules we need to activate on a particular gateway for its maximum effective use and cost savings. It does not make sense to activate all blades on all gateways. In our architecture, we have two types of gateways: external and corporate. The corporate ones are more heavily loaded, so they have slightly weaker protection. The external ones are less loaded; therefore, they are maximally protected, and almost all possible Check Point blades are activated for them.
Which other solutions did I evaluate?
By default, most companies do not use separate firewalling solutions in the cloud at all. They use basic functions such as security groups, NACLs, target evaluation, and similar tools. This is sufficient for them. However, all these solutions do not allow the network to be protected from more advanced attacks above standard firewalling. Check Point Cloud Firewall (formerly CloudGuard Network Security) or any NGFW solution makes it possible to protect against a large number of attacks at the IPS, antivirus, and anti-bot level. If there is a sandbox—SandBlast—then the solution can also inspect what is inside the packets themselves to maximally protect the corporate network. By default, cloud-native solutions do not provide this capability.
What other advice do I have?
My advice to other professionals who are considering using Check Point Cloud Firewall (formerly CloudGuard Network Security) is to treat it exactly as a firewall. It is an excellent fit for some central nodes, data centers, and core levels. As a universal device, especially a small universal device, I would not recommend it because of the complex cluster configuration and also, in some cases, more complex troubleshooting. In particular, it has issues with role changes at the cluster level when older Check Point versions, the so-called R80.x and earlier, are used.
I really hope that in the future, Check Point Cloud Firewall (formerly CloudGuard Network Security) will abandon the thick client and be able to fully switch to working only via the web interface, and also improve the operation of site-to-site VPN in terms of displaying tunnel states. This is the main problem I have encountered. At the same time, the logging system is excellent, and the troubleshooting system is also very good, but the client's operation definitely has room for improvement. I would rate this review an eight overall.