Hillstone CloudEdge Virtual-Firewall (BYOL) logo

    Hillstone CloudEdge Virtual-Firewall (BYOL)

    The Hillstone CloudEdge Virtual-Firewall (BYOL) supports 2-4-core EC2 instance providing high performance. The Hillstone Virtual Firewall features most of the networking services common to Hillstone's hardware based appliances and is an ideal solution for protecting network resources within AWS.

    Ratings and reviews

    5
    3 ratings
    4 star
    3 star
    2 star
    1 star
    100%
    0%
    0%
    0%
    0%
    1 AWS reviews
    |
    2 external reviews
    External reviews are from PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (3)
    reviewer2892729

    Cloud security has improved and supports compliant operations across development and production

    Reviewed on Aug 26, 2026
    Review provided by PeerSpot

    What is our primary use case?

    We have utilized Hillstone virtual firewalls to secure cloud-hosted solutions, including recharge service platforms and applications operating across development and production environments.

    How has it helped my organization?

    We have enhanced the security of cloud-hosted solutions and ensured they are deployed and operated within a secure, reliable, and compliant environment.

    What is most valuable?

    Hillstone CloudEdge Virtual Firewall provides advanced security for cloud and virtualized environments through next-generation firewall (NGFW) capabilities, including application visibility and control, intrusion prevention (IPS), antivirus protection, VPN services, threat intelligence, and advanced attack defense mechanisms. It supports deployment across major public and private cloud platforms such as Microsoft Azure, AWS, VMware, and OpenStack, enabling consistent security policies in hybrid and multi-cloud architectures.

    What needs improvement?

    There is room for improvement in Value-Added Services and Information Technology departments.

    For how long have I used the solution?

    I have used Hillstone CloudEdge for approximately two years.

    Which solution did I use previously and why did I switch?

    I used Huawei, but it was due for End Of Support Life.

    What's my experience with pricing, setup cost, and licensing?

    The setup cost is more expensive with similar features.

    reviewer2892591

    Centralized security has protected hybrid workloads and provides deep visibility into cloud traffic

    Reviewed on Aug 26, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My primary use case is twofold: as a centralized VPN concentrator —terminating site-to-site IPsec tunnels to remote offices and providing secure remote access via SSL VPN— and as a perimeter firewall for the edge of my virtualized workloads.

    CloudEdge inspects north-south traffic toward my virtual instances by applying intrusion prevention (IPS) and inline antivirus, complemented by application identification and policy-based control.

    With this, I protect the data of my main systems against intrusions, malware, and malicious traffic, while maintaining visibility and granular control over inbound and outbound connections.

    How has it helped my organization?

    CloudEdge consolidated VPN, IPS, and antivirus into a single virtual appliance, reducing operational complexity and cost compared to tier-one solutions.

    We gained full visibility into north-south traffic toward our virtual instances and granular policy-based control, which strengthened our perimeter security posture.

    Inline inspection reduced the exposure surface of our critical systems against intrusions and malware, while the centralized termination of IPsec and SSL VPN tunnels simplified secure connectivity with remote offices and remote-access users.

    In addition, CloudEdge has helped us apply consistent security controls across both our AWS workloads and our on-premises workloads.

    It provides an additional security layer beyond basic security groups and network ACLs, allowing us to inspect traffic more closely and enforce more detailed and specific policies.

    What is most valuable?

    The most valuable features for us have been:

    Intrusion prevention (IPS) and inline antivirus: real-time threat inspection on north-south traffic allows us to block intrusions and malware before they reach our critical systems, without relying on external controls or a second inspection layer.

    VPN termination (IPsec and SSL): consolidating site-to-site tunnels to remote offices and secure remote access on the same appliance simplified our connectivity architecture and reduced administration points.

    Behavioral analysis and anomaly detection: this is one of Hillstone's key differentiators; anomalous-traffic detection gives us visibility depth beyond traditional signatures, helping us identify suspicious patterns that a conventional firewall would miss.

    Traffic visibility and logging: granular logs and full connection visibility let us audit, correlate events, and tune policies based on concrete data, which is essential for daily operations and compliance.

    Deployment flexibility: being able to deploy the same virtual appliance both in public cloud and on our own hypervisor lets us apply consistent security controls across hybrid environments, without fragmenting our security policy between platforms.

    What needs improvement?

    Cloud-native automation and IaC: Terraform support, auto-scaling templates, and API maturity lag behind Palo Alto VM-Series and FortiGate-VM.

    Dynamically scaling in public cloud requires more manual effort.

    Third-party integrations and ecosystem: fewer native connectors with SIEM/SOAR platforms, CSPM, and third-party tools compared to market leaders.

    Documentation and training material: technical documentation and community resources (forums, tutorials, KB) are more limited, which lengthens the learning curve for new teams.

    SASE/SSE capabilities: the integrated SASE/ZTNA offering is less mature compared to the convergence already provided by Fortinet or Palo Alto.

    Centralized multi-instance management: managing large fleets of virtual appliances could be smoother; centralized management (HSM) works, but some users would like more granularity and automation.

    For how long have I used the solution?

    I have used it for 5 years.

    Which solution did I use previously and why did I switch?

    We previously used Fortinet (FortiGate) and migrated to Hillstone CloudEdge.

    The decision was primarily driven by the cost/performance ratio: Hillstone offered us a comparable feature set —NGFW firewall, IPS, antivirus, and VPN termination— at a lower total cost of ownership, with a more flexible licensing model for virtualized and cloud environments.

    Additionally, we valued the depth of Hillstone's behavioral analysis and anomaly detection capabilities, which aligned well with our visibility requirements.

    The migration allowed us to maintain our existing security posture while optimizing the investment, without sacrificing inspection or secure-connectivity capabilities.

    What's my experience with pricing, setup cost, and licensing?

    My main recommendation is to evaluate the total cost of ownership (TCO) over a three-year horizon, not just the initial acquisition or licensing price.

    That is where Hillstone CloudEdge shows its greatest advantage: when comparing the accumulated cost of licenses, security subscriptions, support, and renewals against alternatives like Palo Alto or Check Point, the differential is usually significant in Hillstone's favor, while maintaining a comparable feature set.

    I advise building the analysis around the full lifecycle including subscription renewals and projected instance growth to properly size the real savings.

    When evaluated from that perspective, the cost/performance ratio becomes a compelling argument.

    Which other solutions did I evaluate?

    Before making our decision, we evaluated other NGFW alternatives, primarily Palo Alto Networks (VM-Series) and Check Point (CloudGuard).

    Both are strong, well-recognized solutions in the market, but in our cost-benefit analysis Hillstone CloudEdge offered the best balance: a comparable feature set NGFW, IPS, antivirus, VPN, and behavioral analysis at a significantly lower total cost of ownership, with a more flexible licensing model for virtualized and cloud environments.

    Palo Alto and Check Point stand out in ecosystem maturity and integrations, but for our operational requirements, the price differential did not justify the additional investment, especially given our in-house expertise with the Hillstone platform.

    That combination of capabilities, flexibility, and cost was what tipped the decision.

    What other advice do I have?

    On balance, Hillstone CloudEdge is a solid and highly competitive solution within the virtual NGFW firewall segment.

    Its greatest strength is the cost/performance ratio: it delivers a feature set comparable to that of the market leaders NGFW, IPS, antivirus, VPN, and behavioral analysis at a considerably lower total cost of ownership, which makes it an especially attractive option for hybrid environments and organizations looking to optimize their security investment without sacrificing inspection capabilities.

    reviewer2891748

    Consistent cloud and on-prem security has protected workloads and provides granular traffic control

    Reviewed on Aug 25, 2026
    Review provided by PeerSpot

    What is our primary use case?

    We deploy Hillstone CloudEdge Virtual-Firewall in AWS to protect workloads hosted inside our VPC. We use it to inspect north-south traffic, enforce access-control policies, secure communication between environments, and protect internet-facing applications and servers. Our main requirements include firewall policy enforcement, VPN connectivity, intrusion prevention, application control, and improved visibility into network traffic. The Hillstone model is suitable for our cloud environment because it gives us flexibility.

    How has it helped my organization?

    CloudEdge has helped us apply consistent security controls to our AWS workloads with our on-premises workloads. It provides an additional security layer beyond basic security groups and network ACLs. This allows us to inspect traffic more closely and enforce more detailed policies.

    What is most valuable?

    The most valuable aspect is the combination of traditional firewall functionality with cloud deployment flexibility. Important features include granular access control, IPsec and SSL VPN, intrusion prevention, antivirus, application control, traffic monitoring, and attack protection. The interface is relatively straightforward for administrators who already have firewall experience. The firewall integrates well into an AWS VPC architecture and provides useful control over traffic entering and leaving protected networks. The CloudEdge uses the same StoneOS platform as Hillstone's physical security appliances. This helps maintain a consistent configuration and management experience across physical and virtual environments.

    What needs improvement?

    Additional automation resources for AWS would also be helpful. More comprehensive CloudFormation or Terraform examples, deployment templates, and guidance for high-availability architectures could make larger implementations easier.

    For how long have I used the solution?

    I have used the solution for three years.

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)