Akamai [Private Offer Only] logo

    Akamai [Private Offer Only]

    Akamai [Private Offer Only] combines the benefits of the Private Offer feature along with Carahsoft's contract vehicles in providing customers a seamless acquisition process for their cloud based products and solutions from AWS Marketplace.

    Ratings and reviews

    4
    1 ratings
    5 star
    3 star
    2 star
    1 star
    0%
    100%
    0%
    0%
    0%
    0 AWS reviews
    |
    1 external reviews
    External reviews are from PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (1)
    Brice-Abrioux

    Micro-segmentation has delivered deep flow visibility and simplified firewall rule management

    Reviewed on Sep 09, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Akamai Segmentation [Private Offer Only] has been in use for less than one year. The proof of concept began during summer last year and finished in September. Following discussions, migration to production began at the end of Q1 this year, with agents deployed on all workloads including containers before summer. Currently, approximately half of the workload has blocking mode enabled.

    The main use case for Akamai Segmentation [Private Offer Only] is observability and visibility of all flows on our on-premises infrastructure. The second priority is blocking flows to achieve the finest segregation between different workloads.

    For observability and blocking flows, we have implemented a policy based on labeling. We have implemented observability to ensure that all secret data has request access only from the secret application server. Currently, we block all flows that do not have labeling such as secret and application secret.

    During the project with Akamai Segmentation [Private Offer Only], we have gained observability through agents on our workloads and refined how we request to open flows between different workloads and applications. We make calls to the API from Akamai Segmentation and the API from Panorama, resulting in fine-grain segregation on the workload and a more extensive range on the firewall.

    What is most valuable?

    The best features Akamai Segmentation [Private Offer Only] offers are observability, mapping of all flows, and the ability to have granularity for one specific workload or another, which is really useful for understanding the flow and implementing rules to transition into blocking mode.

    The mapping of all flows helps my team in day-to-day operations by providing observability. For example, we can take one workload such as one DBMS server and have visibility of all servers that try to connect to this server. We can then request to see only SSH connections on this server, allowing us to see all workloads attempting SSH connections and to define whether those connections are legal or not, thereby blocking all illegal flows. Furthermore, we can request to see all flows in terms of file transfer protocol, focusing on transfers between secret and other zones, which provides excellent observability.

    Akamai Segmentation [Private Offer Only] has positively impacted our organization by giving us a better understanding of our flows. We save time implementing segregation and when fixing production issues because we have a complete overview, allowing us to determine whether the flow is functioning or if issues are due to flow problems.

    What needs improvement?

    Although mapping is currently fine, Akamai Segmentation [Private Offer Only] can improve by providing a more useful and visually appealing graphical user interface for mapping. While we can automate rules through API calls, this is not entirely possible with the same API. Navigation between different sources and generations of APIs can make it time-consuming to achieve cartography. While labeling is beneficial, there is still room for user experience improvements.

    The improvements are not solely due to the Akamai project; they also stem from issues related to CMDB and the information systems of our company, where sometimes the information is inconsistent, causing Akamai to be unable to automate labeling if that information is not consistently provided.

    For how long have I used the solution?

    Akamai Segmentation [Private Offer Only] has been in use for less than one year.

    What do I think about the stability of the solution?

    Akamai Segmentation [Private Offer Only] is very stable in my experience and works very well.

    What do I think about the scalability of the solution?

    The scalability of Akamai Segmentation [Private Offer Only] is pretty good. We just need to deploy agents and utilize different gateways. Currently, we only use two gateways for fewer than 6,000 workloads, making the scalability very effective.

    How are customer service and support?

    Customer support is really good. They take the time to answer questions and possess excellent knowledge about the product, with no issues encountered so far.

    Which solution did I use previously and why did I switch?

    In my company, UBP, we have not previously used any other solution before Akamai Segmentation [Private Offer Only]. This is the first time we employ micro-segmentation tools.

    How was the initial setup?

    We have discussed licensing because we want to migrate progressively from visibility to blocking mode, which led to difficult conversations about costs. However, in the end, I believe the price is pretty fair, although it is not a cheap solution. It is quite expensive, to be honest, but it is really useful, as we see positive results.

    What about the implementation team?

    The project is really good. The technical team and presales teams are pretty good. However, it is important to take into account that this is a huge change in your organization. It is not a difficult one because you have all the observability, but you need to deploy all agents first to have all the visibility. After that, you need to map the flow and design some rules and then implement them. Do not underestimate the time that you need to implement the rules to understand all flows because application owners do not really have an idea about the flow.

    What was our ROI?

    Regarding return on investment, we need to review the flow yearly for compliance regulations. I save time through API calls because I can retrieve all the implemented rules and tags, enabling me to review flows in hours instead of weeks as before, leading to significant time and cost savings, including for mapping the flow and reducing the number of firewall rules.

    A specific outcome we observe is that before this implementation, we had more than 45,000 firewall rules; currently, we have only 10,000. In terms of deploying open flows or blocking flows, we now take minutes instead of days due to automation. Our incident response time has also improved, providing answers in minutes about whether the flow seems open, although we lack visibility about the application sending the correct packet, only knowing if one packet is sent through an open path.

    What's my experience with pricing, setup cost, and licensing?

    We have discussed licensing because we want to migrate progressively from visibility to blocking mode, which led to difficult conversations about costs. However, in the end, I believe the price is pretty fair, although it is not a cheap solution. It is quite expensive, to be honest, but it is really useful, as we see positive results.

    Which other solutions did I evaluate?

    Before choosing Akamai Segmentation [Private Offer Only], we evaluated Illumio, NSX from VMware, and Cisco Tetration, the latter now known as Cisco Workload Protection.

    What other advice do I have?

    The accuracy and reliability of Akamai Segmentation [Private Offer Only] output are pretty good. Some suggestions are excellent, though we occasionally need to perform manual actions, yet we save time overall.

    Regarding its governance and security, Akamai Segmentation [Private Offer Only] is used for automation and suggestions regarding flow, but I do not have much insight into its current status. It is useful but not fully finished and requires enhancements in security hardening and clearer guardrails for our data. I would rate this review an overall rating of 8.