My customers use the solution for technical and internal Azure resources, including remote access VPN.
CloudGuard Network Security All-In-One
Check Point Software TechnologiesExternal reviews
External reviews are not included in the AWS star rating for the product.
Helps to handle increased loads and firewalls
What is our primary use case?
What is most valuable?
Some retail customers find the scale-up and scale-down features valuable, particularly with scale sets. This is useful for handling increased loads on devices and utilizing firewalls, similar to on-premises setups with active standby configurations.
The solution allows customers to migrate workloads securely into the cloud space with a trusted vendor, maintaining everything under a single platform. This ensures visibility into their cloud environments similar to on-premises setups, all managed through a single smart console.
Unified security management simplifies operations by providing visibility into both cloud and on-premises infrastructure. The skill set required to manage it remains the same for both environments.
The level of confidence in CloudGuard Network Security, both for myself and my customers, is very high. The product operates familiarly, consistent with what customers are used to, and it is a trusted name in the space.
What needs improvement?
Based on my previous experience, there were improvements, especially in in-place upgrades. Regarding cost, it might be potentially cheaper considering resource utilization in Azure and VM costs, but licensing could be improved, possibly moving towards a simpler model.
For how long have I used the solution?
I have been using the product for four to five years.
What do I think about the stability of the solution?
CloudGuard Network Security has improved its stability. It is a stable platform.
What do I think about the scalability of the solution?
The tool has improved its scalability over the four years.
How are customer service and support?
The support experience can be hit or miss. It depends on the expertise of the support representative. Some are highly skilled and knowledgeable, while others require more guidance. There might be room for improvement in this aspect.
How would you rate customer service and support?
Neutral
How was the initial setup?
The tool's deployment is straightforward, whether through the marketplace or templates. It offers flexibility for making amendments before deployment.
What other advice do I have?
On a scale of one to ten, I would rate the solution an eight. The ease of deployment, the single management function, and the features it provides, especially in terms of scale sets and scaling, contribute to it being a solid platform. Many customers are increasingly interested in using it to protect their assets within Azure and AWS, which are the two main areas of operation.
If a colleague is considering purchasing the solution for its security features and licensing, my advice would be to ensure correct deployment. While the solutions are generally straightforward to deploy, there are nuances, especially in Azure infrastructure, that can make troubleshooting more challenging. It's crucial to either use a knowledgeable partner for deployment or ensure a clear understanding of the process before proceeding, as it may be more complicated than anticipated.
Makes security operations faster and error-free
What is our primary use case?
We use the product for network security and cloud workload protection.
How has it helped my organization?
It's easy to set up in Azure Cloud. The ease of setup helps us save time.
What is most valuable?
It offers an easy and nice way to manage the gateways, similar to on-prem hardware. It has packet filtering features. Our security operations are faster and less prone to errors. We selected CloudGuard Network Security due to its visibility.
CloudGuard Network Security more or less provides us with unified security management across hybrid-clouds as well as on-prem. We manage both environments on the same console. It makes our security operations faster and less prone to error.
What needs improvement?
The solution needs to improve the interruptions that happen during gateway upgrades.
For how long have I used the solution?
I have been using the product for two years.
What do I think about the stability of the solution?
There were no major stability issues, although switching gateways could cause some downtime, approximately a minute until the new gateway is fully deployed.
What do I think about the scalability of the solution?
CloudGuard Network Security's scalability is good.
How are customer service and support?
The tool's support is good. Their responses can get delayed due to time zone differences.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have only used the built-in solutions from Azure.
CloudGuard is easier to understand. CloudGuard is very easy to translate and easy to incorporate features. CloudGuard has better features like packet filters, EPS, threat prevention, and filtering.
We chose CloudGuard because of the visibility. It's much better.
How was the initial setup?
The setup process saves us time, especially in the Azure cloud, as the system continually improves.
What was our ROI?
We have seen ROI through its visibility and through understanding attacks on the workloads.
What other advice do I have?
For us, the solution was easy to understand. The syncing of the CloudGuard Network Security is like that of the gateway on-prem. Translating in a very easy path to bring the features is very easy. I rate the product a nine out of ten.
Protects network security with threat detection
What is our primary use case?
The solution helps protect network security by offering threat prevention, addressing vulnerabilities, and utilizing blades.
We use it for the protection of our internal services. We're a Telco company, our internal users are on the machines. We also have some external services that we protect. We protect our customers and our public cloud with it.
VMware is our public cloud provider.
How has it helped my organization?
Threat prevention is the biggest benefit we see from it.
What is most valuable?
The network security is the most valuable aspect of CloudGuard. I am a network engineer so it's the most relevant feature to me.
CloudGuard Network Security provides us with unified security management across hybrid-clouds and on-prem. We manage all of those environments through this one solution.
It's user-friendly. It's a multi-domain solution. CloudGuard is really, really good.
I have experience with FortiGate and Cisco. I worked with them at previous jobs. FortiGate is easy and user-friendly when it comes to the configuration, but it is unstable in some countries and the routing tables have problems. The configuration of the network is in the same management platform, which might be better for some.
In comparison, CloudGaurd is very stable.
Cisco is hard to use, FortiGate is easy and CloudGuard is somewhere in the middle when it comes to ease of use.
When it comes to identifying security threats, CloudGuard is really good compared to its competition.
I am confident that CloudGuard's Network Security can protect us. It enables me to sleep very well at night.
What needs improvement?
We utilize logging systems, and geolocation is crucial for us as some applications must only be accessible from our country. However, there have been occasional issues with this feature. It drops requests. It's not always precise.
For how long have I used the solution?
I have been using the product for two years.
My team has been using it for five to six years.
What do I think about the stability of the solution?
CloudGuard Network Security is very stable.
What do I think about the scalability of the solution?
We have 28 licenses. We have 800 servers on our private cloud.
How are customer service and support?
Their support is fast. They answer quickly.
How would you rate customer service and support?
Positive
How was the initial setup?
We integrate with NSX. The setup wasn't hard.
What was our ROI?
We have seen ROI. It saves us time because it's stable. It's easily administered. We have time to do other tasks. It is easy.
What's my experience with pricing, setup cost, and licensing?
Licensing is complicated. When a license expires, we have to renew it and the process is complicated. They should make the process easier.
What other advice do I have?
Using CloudGuard Network Security saves time due to its stability and ease of administration. The solution is not complex, allowing administrators to focus on other tasks. The configuration process is straightforward. It can integrate with NSX.
I rate the product a nine out of ten. We manage a total of 800 servers that host a variety of components, including our infrastructure, customer applications, databases, application sites, and disaster recovery systems
Can easily increase the number of CPUs, memory, and firewalls throughout
What is our primary use case?
We use the product to protect Azure workloads.
What is most valuable?
The solution's most valuable feature is scalability. We can increase the number of CPUs, memory, and firewalls throughout easily. Using CloudGuard Network Security for managing cloud firewall rules is considered easier than using the normal security groups provided by Azure or AWS.
What needs improvement?
The solution needs to support more hypervisors.
For how long have I used the solution?
I have been using the product for two years.
What do I think about the stability of the solution?
The solution's stability is good.
What do I think about the scalability of the solution?
The tool's scalability is good.
How are customer service and support?
Sometimes Check Point's technical support takes a long time when you need assistance with developing or fixing issues.
How would you rate customer service and support?
Positive
How was the initial setup?
CloudGuard Network Security's deployment is straightforward.
What other advice do I have?
It took around a year to see the benefits of using CloudGuard Network Security. If you have CloudGuard Network Security managed by the same management server used for on-premises, you can control all policies in one management tool. I am confident in using the product.
We are a Check Point partner, hence we trust the product and the company. I rate the overall product a nine out of ten.
Offers central console management that ensures we have uniform threat prevention policies
What is our primary use case?
I use it to protect our public cloud workloads today. It safeguards them directly from the internet and also from the corporate network. We have interconnected our Azure environments with our on-premises network, including our data centre. CloudGuard Network Security helps protect workloads within Azure from both the corporate network and the internet.
How has it helped my organization?
CloudGuard Network Security has significantly improved our operations. Its automatic scaling capability, based on the network load, eliminates the need for capacity planning.
We don't need capacity planning anymore or do proactive actions in order to always have that capacity planning, it does it automatically. Our network engineers now focus on administering the entire cluster rather than managing individual members and their loads.
Our confidence in our cloud network security is pretty high, largely because of central console management. It ensures that we have uniform threat prevention policies applied globally, which significantly boosts our confidence in the system.
What is most valuable?
The most valuable feature for us is the scale set, which allows us to scale horizontally, vertically and dynamically depending on the traffic load.
It provides us with unified security management across both CloudGuard and on-premises environments. We use CloudGuard Network Security for Azure and have a single management console that allows full visibility into logs and consolidated logs across all environments. This ensures we maintain consistent IPS, IDS, and threat prevention policies across all regions and data centres.
What needs improvement?
There is room for improvement in the integration with PaaS services from the public cloud. It would be very helpful. A more cloud-native approach is needed because even it is PaaS services require public cloud resources, even if the traffic load is low. These resources are still required for high availability and resiliency.
So, a full PaaS solution with improvements on that end, basically.
For how long have I used the solution?
I have been using it for five years now.
How are customer service and support?
We have many different firewalls worldwide in our environment. Check Point support provides direct, 24/7 support, even when some components may be outdated. Since almost 95% of our hardware is supported, they're still able to provide support for the remaining 5%, which is greatly appreciated.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We opted for CloudGuard primarily due to two factors, which ultimately became three.
- First was the Azure consumption cost, which was lower compared to competitors.
- Secondly, its plug-and-play capability is straight out of the box, as deployment is directly made from the Azure Cloud Marketplace. In contrast, with competitors, you have to manually import and deploy the image they provide, which isn’t off the shelf.
- The third factor was the scaling solution offered by CloudGuard, which we found to be the fastest.
How was the initial setup?
I was involved. It was straightforward, out of the box, plug and play.
What about the implementation team?
We didn’t use a reseller or integrator; it’s really simple to deploy, and we had the capability to set it up on our own.
What was our ROI?
I haven't calculated it because we deployed CloudGuard Network Security as part of our cloud journey. The ROI wasn't calculated solely on that part; it was more about the overall process of closing the data centre and moving to the cloud.
What's my experience with pricing, setup cost, and licensing?
The licesning has some good features. For example, the scaling feature is free of charge, allowing multiple scale-ups and scale-downs over a two-week period, which is pretty good.
However, since we are still on an IaaS infrastructure, we end up paying for firewalls that are operational without actually handling traffic loads. This is why a PaaS approach would yield more benefits for us.
What other advice do I have?
Overall, I would rate the solution an eight out of ten. The reason it's not a ten relates to the need for a more cloud-native solution that fits today's requirements. The deployment was five years ago, and we're still waiting for Check Point to evolve to truly have cloud-native capabilities.
I'd advise looking into the scale set feature and the out-of-the-box capability, which were really the silver bullets for us. It was a strong requirement, and if anyone is seeking that kind of solution, I would greatly recommend it.
Helps to manage cloud traffic locally without routing it through data centers
What is most valuable?
I like the tool's ability to manage cloud traffic locally without routing it through our data centers.
What needs improvement?
The product needs to improve technical support.
For how long have I used the solution?
I have been using the product for four years.
How are customer service and support?
The tool's support has been excellent. We can maintain our Check Point Firewalls effectively, both on-premises and in the cloud.
How would you rate customer service and support?
Positive
What's my experience with pricing, setup cost, and licensing?
The tool's monthly costs have undergone a significant reduction, dropping from approximately 12,000 euros to around 4,000. This represents a cost reduction of over 60 percent. However, it's essential to note that while costs decreased in some areas, they increased in others due to shifts in our environment. As our overall environment has grown, currently connecting 50 accounts to the cloud, it's challenging to directly compare costs with the state of our setup three years ago.
What other advice do I have?
Initially, we faced some challenges, especially with the AWS transit gateway, involving manual routing configurations and complex setup tasks. I rate the overall product a nine out of ten.
Protects the file server on the cloud and comes with threat prevention features
What is our primary use case?
Our use case for the product is to prevent or protect the file server in the Cloud. The plan is to gradually integrate more solutions behind it. We work with Azure and AWS.
What is most valuable?
The tool's most valuable features are threat prevention and protection mechanisms.
What needs improvement?
The connection to the on-premises management requires using the CLI. It's not just a click, and you cannot edit in the management to prepare everything. You need to do it online and in real time. After that, you must execute a script, and then you should be happy that it appears in the management.
For how long have I used the solution?
I have been using the product for five years.
What do I think about the stability of the solution?
CloudGuard Network Security is stable. I haven't encountered any issues with its stability.
What do I think about the scalability of the solution?
The tool is scalable.
Which solution did I use previously and why did I switch?
Choosing between Palo Alto and Check Point is more of a personal preference based on the management you prefer. However, in terms of protection, both provide a comparable level of security, making you feel equally safe. The choice between Palo Alto and Check Point often depends on the customer. If a customer is already using Palo Alto, it might be challenging to convince them to switch to Check Point.
How was the initial setup?
Deploying the product on different cloud platforms, like Azure or AWS, poses challenges due to variations in terminology and identification methods among platforms.
What's my experience with pricing, setup cost, and licensing?
CloudGuard Network Security's pricing is fine.
What other advice do I have?
In most cases, we use the smart management on-premises. With the hybrid solution, we have one log visibility of every single management, which is an advantageous concept. I rate it an eight out of ten.
Appreciate the CME plugin for automatically understanding assets within the cloud
What is our primary use case?
We use the solution for the ingress and egress, often for VMSS auto-scaling groups. This involves linking on-premises to the cloud and managing incoming traffic within the same cloud environment.
What is most valuable?
Customers appreciate the CME plugin for automatically understanding assets within the cloud. This information appears in the manager, allowing users to tag the assets and adjust policies and rules accordingly.
The IT personnel who transition from on-premises to the cloud experience the same understanding, knowledge, and comfort with the cloud environment, using the familiar interface they had on-premises.
What needs improvement?
People don't know about the tool's features. There's a lack of skill. Users require more knowledge on how to integrate it into the cloud environment and orchestrate routing. So, it's not necessarily a CloudGuard Network Security or Check Point issue but more about integration, knowledge, and understanding.
For how long have I used the solution?
I have been using the product for six years.
What do I think about the stability of the solution?
The product's stability is good.
What do I think about the scalability of the solution?
The solution's scalability is good.
How are customer service and support?
The solution's support is good.
How would you rate customer service and support?
Neutral
What's my experience with pricing, setup cost, and licensing?
The tool's pricing is good. Customers want it to be cheap. I consider the pricing to be elastic. CloudGuard Network Security is perceived as cost-effective compared to using the built-in tools provided by the cloud. Specifically, the VPN functionality is more economical in CloudGuard Network Security, where users can create multiple VPNs without additional charges for each VPN, paying only for the bandwidth. This is contrasted with cloud providers that may charge for each VPN on a per-minute basis, including Ingress and Egress costs.
What other advice do I have?
Unified Security Management provides a consistent interface and knowledge base, allowing those who were trained in Check Point for on-premise use to apply that same understanding across various cloud environments such as Google, AWS, Alibaba, Oracle, and more.
I rate the product an eight out of ten. There is always work to be done. However, some customers may find other technologies more understandable, and there could be a perceived difficulty in the human-computer interaction with Check Point. This might create challenges in comparison to competitors, as customers may find competitors' solutions easier to use.
Has features like next-generation firewall features, including anti-spam, IPS, and URL filtering
What is our primary use case?
We offer a full security and connectivity solution leveraging SD-WAN and SASE technologies. We partner with service integrators and providers who, in turn, sell the solution to business customers. Our solution is built on SD-WAN and SASE, facilitating the connection of offices and home users to the organization through various WAN connections. By aggregating multiple connections over the Internet, we deliver security and connectivity to meet the needs of retail and finance. We can help any vertical that needs a connection between the branch and the cloud.
What is most valuable?
We primarily secure our network using CloudGuard Network Security's next-generation firewall features, including anti-spam, IPS, and URL filtering. Our chosen package for the go-to-market strategy is NGTP. For customers seeking more features, we provide options to upgrade to the tool's advanced packages.
The product serves as a complement to our solution. While we integrate some firewall functionality into our edge device, we do not develop complete security solutions for the cloud. The combination of CloudGuard Network Security with SD-WAN connectivity allows us to offer a holistic solution.
What needs improvement?
The product needs to offer multi-tenancy.
For how long have I used the solution?
Eight months ago, we initiated the integration with CloudGuard Network Security, and currently, we are taking it to the market and presenting it to customers. We have three customers who are on the verge of signing agreements with us.
How are customer service and support?
Currently, the technical support we receive is from the US. While there is a team in the US supporting us, there is a need for this support to extend to other regions.
How would you rate customer service and support?
Positive
Which other solutions did I evaluate?
We got discounts on pricing.
What other advice do I have?
We utilize the tool's SmartConsole integrated into our management system. However, we encounter challenges with multi-tenancy. Since we integrate it as an application on the cloud we can integrate it with any other provider. We do think that the synergy with Check Point is very good because we also allow Check Point to move from the edge to the cloud while we provide security connectivity from the edge to the cloud. So we can support its transition from on-prem security solutions to the cloud. It looks like a very good win-win situation for both Check Point and BBT, and we see it in the market, bringing us big deals in Japan and France.
We can go with others as well in terms of architecture because our architecture is very open. We are a small company and cannot engage with everyone. We have good connections with Check Point in Israel. We also have some connections abroad. So far, we are getting good support.
We have an application that is running on our cloud. Normally, our main cloud provider is Google, but we can run over any cloud. It could be a private cloud or any data center that provides virtual machines and connectivity. We are agnostic.
We are in several POCs in France, Japan, and Thailand, and they are progressing well. However, we need more presales support. There is a lack of knowledge about the solution in the regions, and we are finding it challenging to get sufficient support from those regions. There seems to be a gap in support that needs to be addressed.
It seems that the product is the answer that we need. We haven't identified any missing components in the security suite, apart from the operational challenges related to working in a multi-tenancy environment. I rate the product an eight out of ten.
Helps to inspect internet traffic
What is most valuable?
The tool's most valuable features are inspecting internet traffic and IPS. We can manage the firewall using shared policies from a single management server.
What needs improvement?
The challenge mainly revolves around the slower functionality of virtual IP switching in Azure Virtual Network compared to on-premise solutions. On-premise, switching between clusters is faster, taking only a few seconds, while in Azure, it can extend up to five minutes. The downtime is a concern for us.
What do I think about the stability of the solution?
CloudGuard Network Security's stability is good.
How are customer service and support?
Overall, my experience with Check Point support has been positive. There were instances where basic questions were asked, even though I had already provided the information in the ticket. One ticket took two years to resolve.
How would you rate customer service and support?
Positive
How was the initial setup?
The tool's deployment is more complicated than an on-prem setup. Setting up and managing CloudGuard Network Security in Azure presents some challenges. There are complexities in handling downtime in on-premise and cloud firewalls. Additionally, difficulties arise in deploying a new cluster for an upgrade, as the in-place upgrade might not function as expected.
The process of exchanging virtual machines in Check Point is currently complex. You cannot simply deploy a new machine and use it; instead, you need to navigate through several steps. This involves associating the new machine with a network group, entering various details, and sometimes providing the entire path to locate the object in the cloud.
What other advice do I have?
The tool is working well so far for normal use cases. I rate it an eight out of ten.