
FireMon Security Manager for AWS
Solid workflow, but a lackluster UI makes ticket navigation and assignment difficult
Streamline policies and changes review
Centralized Visibility and Easy Rule Management That Streamlines Firewall Policies
Great for Auditing Firewall Policies and Catching Redundant Rules
Centralized view and compliance audit streamline firewall rule management
The Policy Manager addresses the lack of visibility and control over firewall rules in an environment with multiple manufacturers and many devices. Previously, rule review was manual, done in spreadsheets, time-consuming, and prone to error. Today, we quickly identify redundant, shadowed, unused, or overly permissive rules, reducing the attack surface and facilitating incident response, as it allows immediate knowledge of which network path is open. The change workflow with approval and audit trail generates ready evidence for internal audits and compliance requirements, saving hours of work in each cycle. The return is seen in the reduction of the team's operational effort, fewer errors in production changes, and increased security in periodic rule recertifications.
Powerful Centralized Policy Management, but Usability and Workflow Need Streamlining
Centralize Firewall Management Effectively
Excellent Firewall Review Rules, Best Practices, and Compliance Support
Simplifies Rule Analysis and Compliance Reporting
Visibility has transformed daily security operations and simplifies multi-vendor policy changes
What is our primary use case?
My main use case for FireMon Security Manager is bringing visibility throughout the heterogeneous environment that I manage, enabled by the flexibility of the licenses and compatibility with a variety of vendors, including Cisco, Palo Alto, Fortinet, Huawei, and cloud and VMware environments.
The visibility I gained with FireMon Security Manager became evident when we needed to change our firewall vendors from Cisco to Fortinet, allowing us to perform reusable checks on the rules across all devices while transitioning smoothly to the new vendor.
FireMon Security Manager helped us further by providing visibility on changes made outside of our scheduled change windows, integrating with an ITSM solution via API to track changes initiated through tickets and ensuring compliance with our internal protocols.
What is most valuable?
The best features that FireMon Security Manager offers include license flexibility, vendor compatibility, real-time information, and change checks, which enhances my day-to-day work by consolidating my entire environment into a single pane of glass.
The visibility, topology, compliance, vulnerability management, and daily filters provided by FireMon Security Manager have made our daily operations much easier, significantly saving us time and enhancing our security practices.
I can add that we can integrate FireMon Security Manager via API with almost any solution, and its add-on, FireMon Insights, allows for the creation of diverse KPIs and dashboards tailored to our environment's needs.
Since adding FireMon Security Manager inside our environment, our security perspective improves daily, giving us visibility on every change made and allowing us to address any potential security vulnerabilities timely.
What needs improvement?
I think FireMon Security Manager could improve with a SaaS delivery model for easier connectivity and perhaps provide more regular updates and flexible dashboard options for better usability.
I believe the solution is straightforward, and while it includes many integrations, additional technical information on its internal workings would allow for more flexibility and deeper integrations with our environment.
For how long have I used the solution?
I have been working with FireMon Security Manager for the past ten years, as it is the second solution that I started working with here at AtivaSec.
Which solution did I use previously and why did I switch?
I previously used AlgoSec and Tufin, switching from AlgoSec to Tufin, and when Tufin lost support in Brazil, I transitioned to FireMon Security Manager, which has proven to be a much better option.
Which other solutions did I evaluate?
I did not evaluate other options before choosing FireMon Security Manager, as I had worked with other solutions and found FireMon Security Manager's compatibility with multiple vendors to be a significant differentiator.
What other advice do I have?
My advice for those considering FireMon Security Manager is to conduct a POC, share your use cases with the FireMon Security Manager salesperson, and utilize the available templates for assessments.
I have shared everything about FireMon Security Manager, and I think it is a great solution. I have given this review a rating of ten out of ten.