Sign in Agent Mode
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

CloudGuard Network Security All-In-One

Check Point Software Technologies

Reviews from AWS customer

31 AWS reviews

External reviews

221 reviews
from and

External reviews are not included in the AWS star rating for the product.


    Jan Vobruba

Offers a user-friendly and efficient interface

  • March 03, 2024
  • Review provided by PeerSpot

What is our primary use case?

I can easily secure communication between our Azure Stack Hub and local Azure environments using CloudGuard gateways. This ensures that when I deploy applications in Azure, I can securely access databases and other resources in my local environment through a VPN channel. It is a straightforward way to keep everything protected as I work between the cloud and on-premises infrastructure.

What is most valuable?

The central management feature is a big plus, allowing us to manage both local and cloud gateways from one platform. Another advantage is the unified logging system, which makes it easy to track all communications. Index logs enable us to see all of the logs with all of the features in one place. Unlike other solutions like Palo Alto's Panorama, where checking logs can be cumbersome, CloudGuard's interface is user-friendly and efficient. I have to manually click on every log, one at a time. This helps streamline our deployment process, as I focus on the initial setup before handing it off to other departments for ongoing management.

CloudGuard's ease of policy creation and centralized logging are definite strengths.

What needs improvement?

There is room for improvement in addressing bugs and support issues. Communication with support, particularly with certain teams, can sometimes be challenging and slow, impacting problem resolution.

For how long have I used the solution?

I have been working with CloudGuard Cloud Network Security for almost eight years.

What do I think about the scalability of the solution?

We use CloudGuard to manage 15,000 people. We have ten applications and 14 subscriptions.

How are customer service and support?

The Israel tech support is better than other regions because they respond quickly and help us resolve our issues.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

Check Point's management interface is easier to use compared to products like Palo Alto's Panorama and FortiManager.

Palo Alto and FortiManager are more complicated than CloudGuard.

When it comes to identifying security threats, CloudGuard is on par with other solutions. While Palo Alto doesn't have zero-day protection, it ultimately depends on how customers configure their security rules.

How was the initial setup?

I'm quite pleased with CloudGuard because it is incredibly easy to deploy. Whether I'm using the marketplace or SmartConsole, setting up the gateway takes just a few seconds or minutes, and connecting to local or cloud management is seamless.

Deploying Check Point CloudGuard has been generally straightforward, but we have encountered challenges with Azure Stack Hub due to feature discrepancies with public Azure. The absence of a console in Azure Stack Hub and outdated versions can pose issues. However, if project preparation and resource allocation are done correctly, deployments usually go smoothly. Typically, we purchase between two to six cores for our deployments.

If we prepare the right CPUs it's okay.

What's my experience with pricing, setup cost, and licensing?

The pricing is okay. I know the cost for the competitors and CloudGuard pricing is fine. It is cheaper than other firewalls.

What other advice do I have?

Overall, I would rate CloudGuard Cloud Network Security as a ten out of ten.


    Raimondo Lemma

Enables connections between the cloud, data center, and hybrid infrastructure

  • March 03, 2024
  • Review provided by PeerSpot

What is our primary use case?

Our use case is simple. We utilize CloudGuard Network Security with a bridge to connect all components in the cloud directly to the on-premise. By establishing peering with the bridge, we route traffic to the Google Cloud-based cluster. We apply our standard on-premise environment rules to CloudGuard, utilizing threat prevention, EPS, etc.

What is most valuable?

The most valuable feature for us is the simplicity of creating this environment. Even though our current cloud usage is limited, the process of setting up machines in the product and establishing an HR system was straightforward.

CloudGuard Network Security helped us create stable VPN connections from our Google Cloud to our data center. This was important because we had issues with dependencies between Google, the data center, etc.

We have an on-premise management system, and it's straightforward. We use it within the same management of our other files.

What needs improvement?

In the past year, I noticed that the challenging part, especially in the cloud, is upgrading to the next release of the firewall. Unlike on-premise upgrades, it's not as simple in the cloud. You need to recreate the machine, which makes the process more complex.

For how long have I used the solution?

We have been using CloudGuard Network Security for four years now. We initially adopted it when we began using the Google Cloud platform. It helps us enable connections between the cloud, data center, and hybrid infrastructure.

What do I think about the stability of the solution?

The solution is stable.

What's my experience with pricing, setup cost, and licensing?

The tool's pricing is not cheap.

What other advice do I have?

I rate the solution a nine out of ten.


    Dan Ramsell

Helps to handle increased loads and firewalls

  • March 03, 2024
  • Review from a verified AWS customer

What is our primary use case?

My customers use the solution for technical and internal Azure resources, including remote access VPN.

What is most valuable?

Some retail customers find the scale-up and scale-down features valuable, particularly with scale sets. This is useful for handling increased loads on devices and utilizing firewalls, similar to on-premises setups with active standby configurations.

The solution allows customers to migrate workloads securely into the cloud space with a trusted vendor, maintaining everything under a single platform. This ensures visibility into their cloud environments similar to on-premises setups, all managed through a single smart console.

Unified security management simplifies operations by providing visibility into both cloud and on-premises infrastructure. The skill set required to manage it remains the same for both environments.

The level of confidence in CloudGuard Network Security, both for myself and my customers, is very high. The product operates familiarly, consistent with what customers are used to, and it is a trusted name in the space.

What needs improvement?

Based on my previous experience, there were improvements, especially in in-place upgrades. Regarding cost, it might be potentially cheaper considering resource utilization in Azure and VM costs, but licensing could be improved, possibly moving towards a simpler model.

For how long have I used the solution?

I have been using the product for four to five years.

What do I think about the stability of the solution?

CloudGuard Network Security has improved its stability. It is a stable platform.

What do I think about the scalability of the solution?

The tool has improved its scalability over the four years.

How are customer service and support?

The support experience can be hit or miss. It depends on the expertise of the support representative. Some are highly skilled and knowledgeable, while others require more guidance. There might be room for improvement in this aspect.

How would you rate customer service and support?

Neutral

How was the initial setup?

The tool's deployment is straightforward, whether through the marketplace or templates. It offers flexibility for making amendments before deployment.

What other advice do I have?

On a scale of one to ten, I would rate the solution an eight. The ease of deployment, the single management function, and the features it provides, especially in terms of scale sets and scaling, contribute to it being a solid platform. Many customers are increasingly interested in using it to protect their assets within Azure and AWS, which are the two main areas of operation.

If a colleague is considering purchasing the solution for its security features and licensing, my advice would be to ensure correct deployment. While the solutions are generally straightforward to deploy, there are nuances, especially in Azure infrastructure, that can make troubleshooting more challenging. It's crucial to either use a knowledgeable partner for deployment or ensure a clear understanding of the process before proceeding, as it may be more complicated than anticipated.


    reviewer2353203

Makes security operations faster and error-free

  • March 03, 2024
  • Review provided by PeerSpot

What is our primary use case?

We use the product for network security and cloud workload protection.

How has it helped my organization?

It's easy to set up in Azure Cloud. The ease of setup helps us save time.

What is most valuable?

It offers an easy and nice way to manage the gateways, similar to on-prem hardware. It has packet filtering features. Our security operations are faster and less prone to errors. We selected CloudGuard Network Security due to its visibility.

CloudGuard Network Security more or less provides us with unified security management across hybrid-clouds as well as on-prem. We manage both environments on the same console. It makes our security operations faster and less prone to error.

What needs improvement?

The solution needs to improve the interruptions that happen during gateway upgrades.

For how long have I used the solution?

I have been using the product for two years.

What do I think about the stability of the solution?

There were no major stability issues, although switching gateways could cause some downtime, approximately a minute until the new gateway is fully deployed.

What do I think about the scalability of the solution?

CloudGuard Network Security's scalability is good.

How are customer service and support?

The tool's support is good. Their responses can get delayed due to time zone differences.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have only used the built-in solutions from Azure.

CloudGuard is easier to understand. CloudGuard is very easy to translate and easy to incorporate features. CloudGuard has better features like packet filters, EPS, threat prevention, and filtering.

We chose CloudGuard because of the visibility. It's much better.

How was the initial setup?

The setup process saves us time, especially in the Azure cloud, as the system continually improves.

What was our ROI?

We have seen ROI through its visibility and through understanding attacks on the workloads.

What other advice do I have?

For us, the solution was easy to understand. The syncing of the CloudGuard Network Security is like that of the gateway on-prem. Translating in a very easy path to bring the features is very easy. I rate the product a nine out of ten.


    reviewer2353200

Protects network security with threat detection

  • March 03, 2024
  • Review provided by PeerSpot

What is our primary use case?

The solution helps protect network security by offering threat prevention, addressing vulnerabilities, and utilizing blades.

We use it for the protection of our internal services. We're a Telco company, our internal users are on the machines. We also have some external services that we protect. We protect our customers and our public cloud with it.

VMware is our public cloud provider.

How has it helped my organization?

Threat prevention is the biggest benefit we see from it.

What is most valuable?

The network security is the most valuable aspect of CloudGuard. I am a network engineer so it's the most relevant feature to me.

CloudGuard Network Security provides us with unified security management across hybrid-clouds and on-prem. We manage all of those environments through this one solution.

It's user-friendly. It's a multi-domain solution. CloudGuard is really, really good.

I have experience with FortiGate and Cisco. I worked with them at previous jobs. FortiGate is easy and user-friendly when it comes to the configuration, but it is unstable in some countries and the routing tables have problems. The configuration of the network is in the same management platform, which might be better for some.

In comparison, CloudGaurd is very stable.

Cisco is hard to use, FortiGate is easy and CloudGuard is somewhere in the middle when it comes to ease of use.

When it comes to identifying security threats, CloudGuard is really good compared to its competition.

I am confident that CloudGuard's Network Security can protect us. It enables me to sleep very well at night.

What needs improvement?

We utilize logging systems, and geolocation is crucial for us as some applications must only be accessible from our country. However, there have been occasional issues with this feature. It drops requests. It's not always precise.

For how long have I used the solution?

I have been using the product for two years.

My team has been using it for five to six years.

What do I think about the stability of the solution?

CloudGuard Network Security is very stable.

What do I think about the scalability of the solution?

We have 28 licenses. We have 800 servers on our private cloud.

How are customer service and support?

Their support is fast. They answer quickly.

How would you rate customer service and support?

Positive

How was the initial setup?

We integrate with NSX. The setup wasn't hard.

What was our ROI?

We have seen ROI. It saves us time because it's stable. It's easily administered. We have time to do other tasks. It is easy.

What's my experience with pricing, setup cost, and licensing?

Licensing is complicated. When a license expires, we have to renew it and the process is complicated. They should make the process easier.

What other advice do I have?

Using CloudGuard Network Security saves time due to its stability and ease of administration. The solution is not complex, allowing administrators to focus on other tasks. The configuration process is straightforward. It can integrate with NSX.

I rate the product a nine out of ten. We manage a total of 800 servers that host a variety of components, including our infrastructure, customer applications, databases, application sites, and disaster recovery systems


    Ajdin Heric

Comes with threat prevention, HTTPS inspection, and the Anti-Bot blade features

  • March 03, 2024
  • Review provided by PeerSpot

What is our primary use case?

The solution helps to protect our customers at the perimeter. We have integrated the solution into our NSX environment.

What is most valuable?

The tool's most valuable features for us are threat prevention, HTTPS inspection, and the Anti-Bot blade. Threat prevention helps to protect our assets from threats. HTTPS inspection ensures secure communication, and the Anti-Bot blade is particularly helpful in detecting C2 servers, enhancing our ability to identify malicious activities and protect our network.

We can confidently assert that we are among the top cloud providers, protecting our customers from external threats. With Check Point's CloudGuard Network Security, we offer attack services protection.

What needs improvement?

CloudGuard Network Security needs to include new features. One specific feature I would like to see is the ability to protect external resources using single sign-on integration with various identity providers, including custom identity providers. Its pricing could also be cheaper.

For how long have I used the solution?

I have been using the product for six years.

What do I think about the stability of the solution?

CloudGuard Network Security is stable.

What do I think about the scalability of the solution?

CloudGuard Network Security is highly scalable in our virtual environment. We can easily add more ports, and it functions perfectly. We use it in cluster mode, deploying multiple Check Point clusters horizontally and vertically, making scalability easy and excellent.

How are customer service and support?

I find Check Point's technical support to be excellent. We have premium support, and whenever we open a case, especially for high-severity issues, we receive a phone call from their support team.

How would you rate customer service and support?

Positive

How was the initial setup?

CloudGuard Network Security's deployment is straightforward.

What's my experience with pricing, setup cost, and licensing?

The product is expensive but also valuable.

What other advice do I have?

CloudGuard Network Security provides unified security management across hybrid clouds as well as on-premises environments. It helps to manage everything from a single point.

I have been exploring Harmony SASE for remote security and zero-trust access in some proof-of-concept activities. Also, I'm checking out the CloudGuard Web Application Firewall for safeguarding our applications on the internet.

I rate the product a ten out of ten. We have had a great experience with Check Point, and we haven't faced any major incidents or attacks compromising our organization. It has helped us detect activities on our endpoints.

I would genuinely recommend it. Check Point is easy to manage, implement, and configure. The support is excellent, and the constant threat intelligence updates ensure protection against various threats. It's truly an amazing product for securing your environment.


    Fabio Carvalho

Can easily increase the number of CPUs, memory, and firewalls throughout

  • March 03, 2024
  • Review provided by PeerSpot

What is our primary use case?

We use the product to protect Azure workloads.

What is most valuable?

The solution's most valuable feature is scalability. We can increase the number of CPUs, memory, and firewalls throughout easily. Using CloudGuard Network Security for managing cloud firewall rules is considered easier than using the normal security groups provided by Azure or AWS.

What needs improvement?

The solution needs to support more hypervisors.

For how long have I used the solution?

I have been using the product for two years.

What do I think about the stability of the solution?

The solution's stability is good.

What do I think about the scalability of the solution?

The tool's scalability is good.

How are customer service and support?

Sometimes Check Point's technical support takes a long time when you need assistance with developing or fixing issues.

How would you rate customer service and support?

Positive

How was the initial setup?

CloudGuard Network Security's deployment is straightforward.

What other advice do I have?

It took around a year to see the benefits of using CloudGuard Network Security. If you have CloudGuard Network Security managed by the same management server used for on-premises, you can control all policies in one management tool. I am confident in using the product.

We are a Check Point partner, hence we trust the product and the company. I rate the overall product a nine out of ten.


    Paulo Lemos

Protects virtual data centers and offers savings on money

  • March 03, 2024
  • Review provided by PeerSpot

What is our primary use case?

We use the security gateways to protect the virtual data centers.

What is most valuable?

The most valuable feature for us is the ability to run the gateways as virtual machines in our virtual data center. The tool protects the virtual data centers.

What needs improvement?

The solution's integration with cloud providers has seen significant development in the past months, but there is room for improvement for better integration.

For how long have I used the solution?

I have been using the product for two years.

What do I think about the stability of the solution?

CloudGuard Network security is stable.

What do I think about the scalability of the solution?

Scaling up is straightforward, involving the purchase of additional licenses and allocating virtual CPUs to the client.

How are customer service and support?

CloudGuard Network Security's support is good. I would like the support to be faster. However, it is not possible all the time.

How would you rate customer service and support?

Positive

How was the initial setup?

The tool's deployment is straightforward.

What was our ROI?

My customers have experienced ROI with the tool's use. If there's a security issue, it can lead to downtime or loss of data, which means losing money. So, the main focus is on the financial aspect. Security is also one of the benefits of using the product.

What other advice do I have?

We have both cloud and on-premises deployment models. The solution offers protection and full visibility of traffic on cloud solutions. It is rock solid and comes with proven technology. We can benefit from its detection rates and security. I rate the overall product a ten out of ten. It is a straightforward solution that uses existing technology. We don't have to learn new technology. We can use what we know and deploy it on to the cloud.


    Hans Moggert

Comprehensive protection for cloud environments offering seamless scalability and consolidated logging for enhanced security

  • March 03, 2024
  • Review provided by PeerSpot

What is our primary use case?

We use it to protect cloud infrastructure, workloads, and applications from advanced threats and attacks.

How has it helped my organization?

For our operations team, CloudGuard proved to be the ideal solution. Troubleshooting became much simpler as all traffic—allowed or blocked—could be found in a single point, the SmartConsole. Integrating CloudGuard with VMware was straightforward; we established a connection between Check Point Management and VMware, allowing for the automated deployment of CloudGuard in NSX as a service. This automation made deployment and management a breeze, allowing us to easily specify the number of CloudGuard instances needed, which would then be deployed automatically.

CloudGuard's integration with the SmartConsole ensured continuity for our administrators, who could continue using familiar tools and methods. The ability to manage everything within the virtual environment provided speed and flexibility. With CloudGuard, we could define rules to control traffic with precision, redirecting or blocking as needed.

Check Point's approach of preventing threats at the outset aligns with this perspective, eliminating the need to constantly battle against incoming threats. This proactive stance instills a strong sense of security, as it significantly reduces the likelihood of breaches. Given our positive experiences and lack of any negative encounters with the product, we feel extremely confident in its ability to safeguard our environment effectively.

One of the most crucial and beneficial aspects of Check Point is its ability to consolidate and present logs in a clear and easily accessible manner. This centralized approach offers immense value, as it allows users to access all network security information from a single point, eliminating the need to navigate through multiple tools and sources. With Check Point, users can conveniently find and manage all security-related data in one centralized location.

What is most valuable?

Its centralized control, ease of use, and flexibility are the most valuable for our data center security.

What needs improvement?

The licensing structure is unclear, so a transparent and flexible licensing structure would be preferable.

For how long have I used the solution?

We have been working with it for five years.

What do I think about the stability of the solution?

In terms of stability and reliability, the virtual machine running CloudGuard functions seamlessly and as anticipated, demonstrating no issues or disruptions.

What do I think about the scalability of the solution?

Regarding scalability, you have the flexibility to deploy as many instances as necessary. If additional instances are required, you can easily add them to production by obtaining the necessary licenses.

How are customer service and support?

While we haven't encountered significant issues necessitating support, we did face occasional challenges with perimeter gateways rather than CloudGuard itself.

Which solution did I use previously and why did I switch?

Before this project, we collaborated with a sister company that utilized Cisco ACI, but it didn't prove to be the right fit. Considering our longstanding partnership with Check Point as our security provider, particularly for network and cloud traffic, choosing CloudGuard for East-West traffic inspection seemed like a natural extension. Additionally, observing our sister company's positive experience with CloudGuard on Cisco ACI further reinforced our confidence in the product as the best solution for our needs.

What about the implementation team?

Initially, we sought the help of a partner for deployment, but for upgrades and migrations, we largely handled them ourselves. Fortunately, these processes weren't overly complex, and we found helpful documentation on the Check Point website to guide us through them.

What's my experience with pricing, setup cost, and licensing?

When we initially adopted CloudGuard, we operated under a different licensing model based on the number of hosts. The licensing model has since transitioned to a cluster-based variant.

Which other solutions did I evaluate?

Overall, I would rate it ten out of ten.

What other advice do I have?

For any private cloud data center leveraging software-defined networking through VMware or Cisco ACI, CloudGuard stands out as the optimal choice. It offers unparalleled flexibility and ease of management, making it the ideal solution for customers already utilizing Check Point in conjunction with virtual networks within their data centers.


    reviewer2353149

Offers central console management that ensures we have uniform threat prevention policies

  • March 03, 2024
  • Review provided by PeerSpot

What is our primary use case?

I use it to protect our public cloud workloads today. It safeguards them directly from the internet and also from the corporate network. We have interconnected our Azure environments with our on-premises network, including our data centre. CloudGuard Network Security helps protect workloads within Azure from both the corporate network and the internet.

How has it helped my organization?

CloudGuard Network Security has significantly improved our operations. Its automatic scaling capability, based on the network load, eliminates the need for capacity planning.

We don't need capacity planning anymore or do proactive actions in order to always have that capacity planning, it does it automatically. Our network engineers now focus on administering the entire cluster rather than managing individual members and their loads.

Our confidence in our cloud network security is pretty high, largely because of central console management. It ensures that we have uniform threat prevention policies applied globally, which significantly boosts our confidence in the system.

What is most valuable?

The most valuable feature for us is the scale set, which allows us to scale horizontally, vertically and dynamically depending on the traffic load.

It provides us with unified security management across both CloudGuard and on-premises environments. We use CloudGuard Network Security for Azure and have a single management console that allows full visibility into logs and consolidated logs across all environments. This ensures we maintain consistent IPS, IDS, and threat prevention policies across all regions and data centres.

What needs improvement?

There is room for improvement in the integration with PaaS services from the public cloud. It would be very helpful. A more cloud-native approach is needed because even it is PaaS services require public cloud resources, even if the traffic load is low. These resources are still required for high availability and resiliency.

So, a full PaaS solution with improvements on that end, basically.

For how long have I used the solution?

I have been using it for five years now.

How are customer service and support?

We have many different firewalls worldwide in our environment. Check Point support provides direct, 24/7 support, even when some components may be outdated. Since almost 95% of our hardware is supported, they're still able to provide support for the remaining 5%, which is greatly appreciated.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We opted for CloudGuard primarily due to two factors, which ultimately became three.

  • First was the Azure consumption cost, which was lower compared to competitors.
  • Secondly, its plug-and-play capability is straight out of the box, as deployment is directly made from the Azure Cloud Marketplace. In contrast, with competitors, you have to manually import and deploy the image they provide, which isn’t off the shelf.
  • The third factor was the scaling solution offered by CloudGuard, which we found to be the fastest.

How was the initial setup?

I was involved. It was straightforward, out of the box, plug and play.

What about the implementation team?

We didn’t use a reseller or integrator; it’s really simple to deploy, and we had the capability to set it up on our own.

What was our ROI?

I haven't calculated it because we deployed CloudGuard Network Security as part of our cloud journey. The ROI wasn't calculated solely on that part; it was more about the overall process of closing the data centre and moving to the cloud.

What's my experience with pricing, setup cost, and licensing?

The licesning has some good features. For example, the scaling feature is free of charge, allowing multiple scale-ups and scale-downs over a two-week period, which is pretty good.

However, since we are still on an IaaS infrastructure, we end up paying for firewalls that are operational without actually handling traffic loads. This is why a PaaS approach would yield more benefits for us.

What other advice do I have?

Overall, I would rate the solution an eight out of ten. The reason it's not a ten relates to the need for a more cloud-native solution that fits today's requirements. The deployment was five years ago, and we're still waiting for Check Point to evolve to truly have cloud-native capabilities.

I'd advise looking into the scale set feature and the out-of-the-box capability, which were really the silver bullets for us. It was a strong requirement, and if anyone is seeking that kind of solution, I would greatly recommend it.