
FireMon Security Manager for AWS
Centralized rule analysis has streamlined multi-vendor firewall audits and risk reporting
What is our primary use case?
We use FireMon Security Manager for managing the rule base on our various multi-vendor firewalls.
We did not use the policy manager, but with FireMon Security Manager, we checked for logging disabled. We used overly permissive features and ran SQL queries to find the overly permissive rules and conducted remediation based on those findings. We ran FQDN queries to find out which rules were using FQDN instead of URL filtering. Without FireMon Security Manager, the vendor did not have any such features, so FireMon Security Manager was the only tool we could use to get our retrievals. We use CLI scripts and GUI, both of which are doing something that no other tool can do as far as we have seen.
What is most valuable?
What I like the most about FireMon Security Manager is that it can go across a whole rule base and get the items we need, like rules that have a specific characteristic, such as logging disabled, and we can find which rules are there that match that criteria for any vendor. It can do this very quickly. Whereas, if we have to log into all the vendor websites and try to get access to all the infrastructure for every single vendor separately, it is a very time-consuming task. We can export results in CSV, and there are some good features that we can use right away.
What needs improvement?
What I dislike about FireMon Security Manager is that I use the Insights add-on option, which does add a visual dashboard. I would prefer more of a visual dashboard that I can customize. Right now, we have the visual dashboard in Security Manager, but it is not customizable, and the same applies to Insights. The AI feature is very useful in Insights, but the visual dashboard which can be customized is not there to track our progress if we are trying to mitigate any security blind spots.
I mention more customizable visual dashboards because every organization has different priorities. Sometimes our management asks us to prioritize and look for different items, and suddenly they change the direction. If you have a tool that does not customize a dashboard, then you cannot make graphs or visually represent over the past three months or six months how we have progressed. Have we gotten worse or better?
I think the pricing for FireMon Security Manager is fair. However, it could be better if you could have more customization options, such as medium and large firewalls. You could have different categories; small firewalls exist, but medium is no longer in the licensing. That would help save money.
FireMon Security Manager requires maintenance on my end. We have to pull retrievals, and the retrievals fail many times, and sometimes they succeed. Sometimes we have to investigate, troubleshoot, and do packet captures. There is a lot of work that management does not understand, and it is very difficult to convince them that we are actually working. They do not realize that we are actually working on many tasks just to keep things running and pulling reports. We need fresh retrievals, and sometimes things break. We have to remove devices and add devices. It is very difficult to portray to management that we are actually working, and it takes a lot of effort to manage the database server and keep things running smoothly and update licenses. A lot of background effort is involved, though it does not appear that way to management. It is very difficult to convey the efforts involved at performance evaluation time.
I have just used Panorama with FireMon Security Manager. However, my colleagues have used other tools, and they said there are advantages and disadvantages in every tool. FireMon Security Manager is a very good tool to do what we want to do, but it can be improved, as can every other tool.
For how long have I used the solution?
I have been using FireMon Security Manager in my career overall for about four years.
What do I think about the stability of the solution?
I think stability is very good. FireMon Security Manager is pretty stable. Sometimes we had issues, but we resolved those issues and restarted the server. That part is good.
What do I think about the scalability of the solution?
I think scalability with FireMon Security Manager is pretty easy.
How are customer service and support?
Our TAM helped us a lot and was very useful to have. He customized many features that were not customizable. He wrote custom scripts and did a great job customizing everything and keeping our management happy. We had very customized requests, and since we could not customize anything, our TAM helped us maneuver around the rigid dashboard display limitations. He wrote custom Python scripts and did a lot of effort behind the scenes. I am not even aware of how much effort he took to do all that work.
Which solution did I use previously and why did I switch?
I have just used Panorama with FireMon Security Manager. My colleagues have used other tools, and they said there are advantages and disadvantages in every tool. FireMon Security Manager is a very good tool to do what we want to do, but it can be improved, as can every other tool.
How was the initial setup?
I was not there when they did the initial deployment of FireMon Security Manager, but I was involved in an upgrade, and the upgrade went smoothly.
What about the implementation team?
I was not there when they did the initial deployment of FireMon Security Manager, but I was involved in an upgrade, and the upgrade went smoothly. Our TAM helped us a lot and was very useful to have.
Which other solutions did I evaluate?
I have just used Panorama with FireMon Security Manager. My colleagues have used other tools, and they said there are advantages and disadvantages in every tool. FireMon Security Manager is a very good tool to do what we want to do, but it can be improved, as can every other tool.
What other advice do I have?
Overall, I would say FireMon Security Manager is hard to beat, except the AI features have been recently introduced in Insights. I would rate FireMon Security Manager 9 out of 10. There are hardly any tools that can do better, from what I have known. Perhaps there are some other tools, but I have not had experience with any of them. FireMon Security Manager is one of the best that I have seen so far. However, everyone has their own opinion, and management has their own expectations. They expect a miracle, so I cannot speak for management. We have told them that this tool does a lot of good work and it is very difficult to beat. The reporting features are very stable and reliable. It may not present the appearance of the latest or a shiny tool, as some tools are flashy. This is not the flashy tool, but it does a lot of basic reporting work and allows you to do all the queries. I think FireMon Security Manager is a well-rounded tool.
I have used the reporting capabilities of FireMon Security Manager to communicate risk reduction, compliance status, and the overall security posture to my higher-ups. We use it on a regular basis.
Automation for firewall changes has improved, but integration delays still limit daily use
What is our primary use case?
The intended use case is to have every firewall opening ticket processed through FireMon Security Manager. To accomplish this, we need to integrate it with ITSM, a ServiceNow tool, which is currently not implemented on our side. We have been waiting for this integration for a very long time and are awaiting support from FireMon Security Manager team to work with us and integrate it into our ITSM system. Currently, the way we would use it would be to manually enter all the data into FireMon Security Manager and then run it over, but this does not save us any time, so we are not currently doing that.
We have the topology built and are using FireMon Security Manager from time to time, but not for every use case. We sometimes use it for topology checks and rule verification, so we are using the secondary functions rather than the main function. The ideal scenario would be to have users enter information into ServiceNow that would be automatically populated to FireMon Security Manager, and then FireMon Security Manager would push the changes.
We are currently in the middle of changing our infrastructure. Previously, when we purchased FireMon Security Manager, we were using Cisco ASAs. Now we are migrating to FTD and next-generation firewalls from Cisco, and those devices are not yet integrated. Our engineer is working with the system, and we are seeking help from FireMon Security Manager in order to assist us with this transition.
What is most valuable?
AlgoSec is another tool we considered, as Tufin is a popular comparison. However, FireMon Security Manager is cheaper and fits well with our needs. The logic of these tools is mostly the same, with differences coming down to specific extra features available with each one.
What needs improvement?
Waiting one year to get help is unacceptable, particularly regarding the new setup and integration with ServiceNow. We need to pay extra for it, and it is frustrating to wait for an engineer from FireMon Security Manager to assist us.
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
From their side, there was one person, and if he had some issues, he was reaching out to the developers to solve the problems we faced. This implies a level of dependency on their internal team which can cause delays.
Better support is needed as waiting a year for assistance is way too long. We have known we wanted this setup from the start, but it has not integrated as expected.
Which solution did I use previously and why did I switch?
We were also considering AlgoSec, which has similar logic to FireMon Security Manager and Tufin. However, slight differences exist in potential extra features or what they support, but nothing was significant enough to impact our decision.
How was the initial setup?
I remember the timeframe for fully implementing it from start to finish was three to six months.
What about the implementation team?
What was our ROI?
What's my experience with pricing, setup cost, and licensing?
AlgoSec and Tufin were also evaluated by us along with their pricing.
Which other solutions did I evaluate?
If comparing them, depending on the use case and device compatibility, all three could potentially meet our needs.
What other advice do I have?
I do not want to blame FireMon Security Manager for this because our failure to use it is partially their fault. They are not giving us the engineer support we need.
We view this as a new setup issue requiring financial support. This is not directly a support problem for an existing issue, but more about expected availability to facilitate implementation.
My overall review rating for FireMon Security Manager is seven.
Easy to use and efficient, with features that streamline work
FireMon Policy Manager Brings Single-Pane Visibility and Strong Policy Governance
Automated firewall reviews have improved compliance and reduced misconfigurations
What is our primary use case?
FireMon Security Manager is mainly used for analyzing firewall configuration and rules. It is primarily for firewall analysis and configuration analysis of the firewall.
We work with FireMon Security Manager as a service provider. Our customers have it, but we use FireMon Security Manager on behalf of them.
We use FireMon Security Manager mainly for the on-prem environment, and we primarily use it for our on-prem firewalls.
We are not using FireMon Security Manager for SASE integration right now. We are just using it for firewall management.
We do use FireMon Security Manager for real-time compliance management primarily for that purpose, so we do have a positive impression of that because it can map the compliance against various standards available such as ISO 27001 or PCI DSS. That helps us in automating that compliance check on these firewalls.
We are not using FireMon Security Manager in an automatic fashion for compliance checks. We run it manually and run the tool periodically. We have not kept it for continuous scanning of the environment. However, whenever we run the tool, we do get a warning or an alert saying that this is a firewall rule that will potentially violate, for example, PCI DSS compliance.
FireMon Security Manager does affect our cleanup of firewall rules in a large enterprise environment because it helps us in identifying which rules are remaining unused since the previous FireMon Security Manager check. That helps us in prioritizing and saying that these are so many unused rules and why don't we clean them up.
What is most valuable?
One advantage of FireMon Security Manager is that it analyzes the firewall configuration against known standards. If there is a known firewall standard or configuration standard in NIST or any of the audit or compliance requirements such as PCI or ISO 27001, it can analyze the firewall configuration against those standards and give us a report of where we are missing so that we can comply with those standards as well.
FireMon Security Manager can also connect to multiple types of firewalls with different vendor firewalls. We use a multi-vendor firewall environment, and the advantage of FireMon Security Manager is that it can connect to different vendors that we use in the environment.
FireMon Security Manager helps to prioritize risks and prioritize fixes. When it points out errors or misconfigurations, it gives us a rating saying that this is a high critical misconfiguration which needs to be fixed first, versus a low-rating misconfiguration which might have a less or reduced impact and which we can fix later on.
We do observe a decrease in errors and misconfigurations that increase risk in the environment with FireMon Security Manager. It points out errors, so we mainly use it for that purpose. We don't use it to manage the firewall, but we use it for analyzing the firewall configuration that will reduce the risk and any kind of errors that are there in the firewall. We could say there is about a twenty percent decrease in errors and misconfigurations due to FireMon Security Manager. The reason is we were using some other tool earlier, so we had done quite a bit of improvements on the firewall. Once we introduced FireMon Security Manager, it found new areas where we could improve and there is about a twenty percent improvement.
FireMon Security Manager does affect our compliance reporting processes. It helps us automate reporting and prioritize all those compliances. This way, it is quite useful.
What needs improvement?
I think there are some disadvantages and areas for improvement. What is limited or has no capability in FireMon Security Manager is integration with all the cloud-based firewall native vendors. For example, in Azure or in AWS, if you have a Palo Alto firewall, FireMon Security Manager will work fine. However, if you use Azure's own native firewall or AWS's own native firewall capabilities, FireMon Security Manager does not have the ability to analyze the policy of such native cloud-based firewalls. That is a disadvantage that we are seeing because we are also using more and more native services rather than going for third-party services in the cloud environment.
The second disadvantage we see with FireMon Security Manager is some vendors which are now becoming popular, such as Cato Networks. We have one customer who uses Cato quite extensively, but we are not able to use FireMon Security Manager for them to do the policy analysis because it doesn't work with Cato.
For how long have I used the solution?
I started working with FireMon Security Manager approximately a year ago.
What do I think about the stability of the solution?
Stability-wise, FireMon Security Manager is not a problem. It is approximately a ninety-nine percent stable product.
What do I think about the scalability of the solution?
We haven't used FireMon Security Manager in a highly scalable manner, so when we factored it in, we haven't really tested its scalability. I am not aware of the scalability of the product or whether it can support thousands of firewalls. We do use it for hundreds of firewalls today, but not in the thousands. I am not sure on scalability.
How are customer service and support?
Customer service from FireMon Security Manager is good in terms of responding to any issues or any errors that we face. In terms of using the product as is and its customer support, I would say it is good enough. I would rate support at about an eight on the scale from zero to ten, with ten being the best.
Which solution did I use previously and why did I switch?
We were using some other tool earlier. We had done quite a bit of improvements on the firewall. Once we introduced FireMon Security Manager, it found new areas where we could improve and there was about a twenty percent improvement.
How was the initial setup?
Deploying FireMon Security Manager is quite easy to deploy.
What about the implementation team?
We bought FireMon Security Manager directly from a reseller. We did not buy it through AWS Marketplace.
What was our ROI?
FireMon Security Manager is worth buying and worth its money in terms of return on investment. As long as you have the firewalls in your environment which are supported by FireMon Security Manager, it is worth the investment.
What's my experience with pricing, setup cost, and licensing?
It does save time and money both because otherwise you would have to review the firewall configuration by hand or manually, whereas FireMon Security Manager automates it. In terms of money, you will have to reduce the number of people who are involved in the firewall review. FireMon Security Manager is also a lower-cost product than AlgoSec.
Which other solutions did I evaluate?
I am comparing FireMon Security Manager to a product such as AlgoSec, something which operates in the same market. AlgoSec is one big example where we did an evaluation.
What other advice do I have?
Cost-wise, it is very competitive if I compare it with its peers. The pros are that in terms of the tool capability, it is as good as any of the best of the market tools and cost-wise, it is lower. FireMon Security Manager is affordable compared to its competitors.
Time-wise, I am not sure how to measure it, but from a procurement perspective, because this is procured by the customer directly, we don't have visibility in terms of what was used and what was the cost of AlgoSec versus FireMon Security Manager. However, from a product perspective, our recommendation was that both were equal, and FireMon Security Manager slightly better. Cost-wise when FireMon Security Manager was better, I think the client went with FireMon Security Manager itself.
When I mentioned time saving, I meant that it saves time for when accurately creating, approving, and deploying firewall policies.
What organizations should remember is primarily to look at the compatibility of FireMon Security Manager with the firewalls that they have in their respective environments. In their environment, if they have only, for example, Palo Alto, Cisco, or FortiGate firewalls, and all of them are supported by FireMon Security Manager, however, if they use a very unusual firewall or a cloud-native firewall, they should check whether FireMon Security Manager supports those firewalls and then take a call accordingly. My overall rating for this product is eight out of ten.
Centralized firewall oversight has improved compliance and reduced configuration errors
What is our primary use case?
FireMon Security Manager is used to centrally manage multiple firewalls, enforce security policies, monitor threats, and simplify day-to-day firewall administration.
FireMon Security Manager allows us to manage multiple firewalls from a single console, making policy updates and monitoring very easy, and troubleshooting much faster and more consistent.
FireMon Security Manager is deployed in our organization on-premises within our data center.
What is most valuable?
The best features of FireMon Security Manager are centralized policy management and security policy analysis, which is very useful, along with compliance reporting and clear visibility across all the managed firewalls. These features help us to simplify firewall management and improve security.
FireMon Security Manager has positively impacted our organization by improving our firewall management by increasing visibility, reducing configuration errors, streamlining policy changes, and helping maintain compliance.
What needs improvement?
FireMon Security Manager could be improved with a more user-friendly interface. Otherwise, the performance and the deployment are perfect.
For how long have I used the solution?
We have not switched solutions; we started with FireMon Security Manager only.
What do I think about the stability of the solution?
FireMon Security Manager is a pretty stable solution.
What do I think about the scalability of the solution?
Scalability-wise, FireMon Security Manager is a very good solution that can handle our organization's growth.
How are customer service and support?
Customer support for FireMon Security Manager is very supportive, and they are able to provide support and troubleshoot issues at any time.
Which solution did I use previously and why did I switch?
We have not evaluated other options before choosing FireMon Security Manager.
What was our ROI?
FireMon Security Manager provides a very good return on investment because we are able to save our time and money.
What other advice do I have?
FireMon Security Manager helps reduce configuration errors by identifying duplicate, unused, and overly permissive firewall rules before changes are implemented. This reduces the risk of misconfiguration and keeps security policies consistent across all firewalls.
Regarding FireMon Security Manager's AI capabilities, its governance and security appear very well-designed. They provide controlled access, support compliance, and policy validation, which is very helpful.
The data that FireMon Security Manager provides is very accurate and reliable, with reliable output.
I recommend clearly defining your firewall management and compliance requirements before deploying FireMon Security Manager and taking advantage of its policy analysis and compliance features. This will help the organization to achieve a compliance-ready environment and gain proper visibility.
I rate this product 9 out of 10.