Check Point Cloud Firewall All-In-One (FKA CloudGuard Network Security) logo

    Check Point Cloud Firewall All-In-One (FKA CloudGuard Network Security)

    Advanced threat prevention security for AWS and hybrid cloud environments, with Threat Extraction and Threat Emulation, and a built-in security management server

    Ratings and reviews

    4.4
    452 ratings
    63%
    33%
    3%
    1%
    0%
    58 AWS reviews
    |
    394 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (452)
    Prasanth Penuboina

    Centralized cloud security has streamlined multi-account protection but still needs better dashboards

    Reviewed on Aug 23, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I have been using Check Point Cloud Firewall (formerly CloudGuard Network Security) for the past one and a half years.

    My focus is on cloud-related aspects like AWS cloud and Azure cloud. The primary purpose that we use Check Point Cloud Firewall (formerly CloudGuard Network Security) is for the AWS account environment, securing our AWS accounts and environments.

    We manage approximately 500-plus AWS accounts, handling all of our internal customers' AWS accounts. Most of the customers expose their applications using the internet-facing load balancers and expose some APIs to external web vendors or something similar. Our AWS environment is primarily made of EKS clusters, load balancers, transit gateways, and we have direct connect associations with our on-premises infrastructure. We have a lot of ECS and EC2 services. To manage all of them, when you build applications, you primarily expose them to the outside world or internet users across the globe. To protect all of this infrastructure, our applications, and our data running behind a VPC, we deployed Check Point Cloud Firewall (formerly CloudGuard Network Security) to monitor all our inbound traffic, ingress and egress traffic, and to potentially have some kind of threat intelligence in place.

    We use it only for cloud, so I can recommend it only for cloud. I am not aware of the on-premises capabilities, but the name says CloudGuard Network Security, so I have focused my discussion on AWS.

    What is most valuable?

    From our personal usage, the most valuable feature I would say is the centralized policy management. We have organization accounts or root accounts in AWS through Landing Zones. In the case of Check Point Cloud Firewall (formerly CloudGuard Network Security) as well, we have centralized policy management. As I highlighted, we have closely 500 AWS accounts. If we have to configure them independently or individually, that becomes a complex, mammoth, and very tedious task, even to update something. With centralized policy management, we can apply consistent firewall and threat prevention rules across AWS environments without managing security for each VPC. I would say you configure something there, and it is applicable for all our AWS environments. The single view of all policies across all AWS accounts, I would consider it as the most beneficial feature. We have other options as well, such as integration with other AWS network services. Apart from that, the centralized monitoring and logging is very valuable. If we want to see which customers are having some issues or check the DDoS attacks, it will be easy for us to keep an eye on the monitoring and then evaluate the logs. There might be genuine cases of failures as well, which we are supposed to address. We have both the monitoring and logging capabilities.

    What needs improvement?

    The initial setup was primarily configured by our cybersecurity team, but as we progress using it based on our customer needs or as we progress and mature in terms of exposing our applications, we request ongoing amendments or changes to the security policies, including allowing a certain IP address or configuring the firewall rules that are potentially required for our applications. This is an ongoing process of how it is set up with base policies and how we upgrade it according to our customer needs.

    For most of the software available out there, the initial complexity is to configure and use it, particularly in terms of large AWS accounts. We have multiple VPCs, transit gateways, and direct connect associations with on-premises infrastructure. What I would think is that if you have something like a readymade agent or some sort of automation that makes the deployment automation easier, that would be beneficial. We now see each and every single day tens and twenties of new products emerging, but I would still stick to my point that the initial configuration is somewhat difficult. This can be improved. Another point is that the dashboards are pretty much standard. Since I am from an AWS background, I will talk from an AWS perspective. If we have specific AWS-related dashboards or AWS service-related dashboards, for example, if we want to see who is accessing our EKS cluster, I would like to simply see what are all my metrics or dashboards. For example, we have something like Grafana dashboards. If you see, there are some prefabricated dashboards there for node level, EKS level, cluster level, DB level, and network level. If we have certain use-case-specific dashboards, that would really be helpful. From a policy configuration, deployment, and synchronization perspective, that would eventually take time. I would not specifically call it an improvement or to speed it up, but it is okay to manage. Then there are cost factors. Perhaps some sort of discounts for long-running customers, or if a customer is managing some 200 accounts, a discount would help.

    Documentation can be considered as an area for improvement. Use case-specific dashboards, if it is possible, would also be beneficial. Providing customer insights onto the ongoing focus areas would be helpful. Dashboards can be improved, and documentation can be made easier, or use case-specific features can be introduced. Cost visibility, showing how much we are spending and how much we saved, and recommendations on new threats to customers to consider in the next iteration, would all be valuable additions. All these things are currently a bit lacking in the tool.

    What do I think about the scalability of the solution?

    In terms of scalability, it has a capability to handle as many AWS accounts as possible. Since it is a centralized system, it does not have any restrictions on how many consumers would be onboarded onto it. I do not think scalability is a problem or an issue for Check Point Cloud Firewall (formerly CloudGuard Network Security).

    How are customer service and support?

    I have not been involved directly in the customer support activities, but from my cybersecurity team, that support was top-notch.

    Which solution did I use previously and why did I switch?

    We previously relied on the standard AWS cloud-native services such as WAF, NACL, and security groups.

    The licensing and pricing are beyond my responsibilities, as the cybersecurity team handles configuration at the top layer. They take care of the licensing, and pricing is purely from an organization decision. I do not have a say on that.

    How was the initial setup?

    The configuration was easy, time-saving, and cost-saving, resulting in customer satisfaction, time to market improvements, and we have confidence in the solution. We pretty much focus on the custom requirements rather than standard requirements of all the accounts.

    What was our ROI?

    The return on investment is certainly positive. The time to market is very fast compared to the standard process that we used to do. The fewer employees needed category shows that we technically are now focusing only on the customer-specific rules rather than on the standard rules. Whenever you build an account, those configurations come in-built from the Landing Zone configurations. We are pretty much sure that our environment is secured from day one.

    I cannot quantify it, but I would say the centralized system has really helped us achieve things a bit faster.

    Which other solutions did I evaluate?

    There is something like a SmartConsole. We do not have the full permissions on the SmartConsole interface, but we got to know that there is a SmartConsole interface that provides very good visibility and simplifies the ongoing security management. We have two to three people that have access to that SmartConsole, and we can see whatever ongoing security changes are made in terms of good visibility onto where could be our next focus areas.

    What other advice do I have?

    Since I am not the one who configured it end-to-end, and since my expertise is not in cybersecurity, I would rate the solution a seven.

    Check Point Cloud Firewall (formerly CloudGuard Network Security) saves a lot of time, effort, and cost. Rather than managing each individual account, having the centralized deployment across all accounts really makes our life easier. If you are currently handling 500 accounts or something similar, you cannot have a single entity that manages everything, which we did not have initially. But with Check Point Cloud Firewall (formerly CloudGuard Network Security), we have that option in place. It potentially improves visibility, reduces cost, reduces effort, reduces time, and certainly increases the time to market or improves the customer experience.

    My deployment is in AWS.

    It is not a direct use of the AI features from Check Point Cloud Firewall (formerly CloudGuard Network Security). But from my experience, I would rate it a seven, considering the feedback I have received from my cybersecurity team.

    We are using cloud-native products like AWS WAF. We have NACLs, security groups, and AWS WAF is there. All of them are internal services. If you want to rely on that, you end up configuring all such rules or configurations across all the accounts. But when you compare this with Check Point Cloud Firewall (formerly CloudGuard Network Security), it provides a significantly much better centralized policy management, good visibility onto the policies, and advanced threat prevention capabilities. From an administrative perspective, that would be beyond my expertise, but closely working with the cybersecurity architects, we are convinced that Check Point Cloud Firewall has brought in a lot of value-add, rather than purely relying on the cloud-native AWS services for our day-to-day policy management.

    My overall rating for this solution is seven out of ten.

    Oscar Nunez

    Centralized management has reduced policy time and provides reliable multitenant protection

    Reviewed on Aug 18, 2026
    Review from a verified AWS customer

    What is our primary use case?

    What I appreciate is that centralized management is obtained from SmartConsole with MDS, which seems very positive to me, as that is the strongest point. With that, you can have threat prevention with the blades, IPS, Anti-Bot, and Anti-Virus. I think it is very well integrated, and also for ClusterXL for high availability, it works very well; it is very reliable.

    The primary impact we have had is the ability to manage security policies in a centralized manner for multiple customers from a single platform, because this significantly reduces operational time when performing, for example, rule changes or policy updates. What is more important is the availability from ClusterXL, which allows you to have production environments without service interruptions—that is, business continuity. Additionally, the threat prevention capabilities, and what I like most is that they have added a robust protection layer without the need for third-party solutions; everything is very well contained there. I estimate a reduction of between 30% and 40% in management time compared to solutions without multi-domain centralized management.

    What is most valuable?

    I use it in multitenant environments with an MDS architecture, the Multi-Domain Management, to manage security policies in a centralized manner for different organizations at the same time.

    As I mentioned in the previous section, what I think are the best features it has is centralized management from SmartConsole with MDS. I think that is the strongest point it has, because you can have threat prevention with the blades, as I mentioned, IPS, Anti-Bot, and Anti-Virus, which are very well integrated. The ClusterXL function for high availability works very well. As I said, it is very reliable, very intuitive, and I think it is a very good tool.

    What seems very good to me, as I mentioned, is the integration it has for threat prevention with the IPS, Anti-Bot, and Anti-Virus blades. That seems to be its best integration. It is very intuitive—significantly, even if you come from other firewalls, this is very intuitive; you can manage it without any problem. You do not have to learn absolutely everything from scratch. I think this part is very well integrated.

    What needs improvement?

    What I would like, what I think they should improve a little is the management of objects at large scale. When you work with multiple domains, there are thousands of network objects. Detecting duplicates and consistency across domains is a very manual process that should be more automated. Another thing: the SmartConsole interface is very powerful and very good, but the learning curve, compared to other solutions in the market from other manufacturers, could be modernized. I think it does not necessarily have to be done from a client application; it could be done via web, because via web I know that not all the options you have in SmartConsole are available. So it would be good if it could also be done from the web and all the options were available. Another thing that I would really like is more automation with Ansible or Terraform. I know it has improved in recent versions, but I think it is still not mature enough. Compared to other manufacturers that do have a bit more in terms of automation capabilities in integration flows with Ansible or Terraform, Check Point Cloud Firewall (formerly CloudGuard Network Security) could improve. Another thing that could be improved a little would be the TAC response time, because when there are very complex cases, I think there should be more speed initially, more ownership of those urgent cases, and not leave the customer waiting. This has happened to me: when I have cases open with Check Point Cloud Firewall (formerly CloudGuard Network Security) TAC, sometimes they do not respond and I have to keep insisting, and I think that part should improve. I do not know if it depends on who takes the ticket or on the severity of the ticket, but sometimes I have had to insist a lot, and that would be the only problem. Once they attend to me and become involved in the case, the responses they give are very professional and really help directly resolve the problems when there is a bug or troubleshooting to do.

    As I said, I would like to see a specific improvement in SmartConsole. I think if they improved it—how to say it—gave it a facelift so you could access all the options directly from a browser, that would be great, because sometimes, for one reason or another, you cannot download SmartConsole or, for some reason, the SmartConsole client does not start correctly, and you could do it directly from the browser. I think that would be a good option to improve. Another thing would be that in multidomain environments, I would like a global search function for objects and rules. That is, you could enter and search across all domains at once, because right now you have to go domain by domain, and in environments with many customers, you spend quite a bit of time; you have to exit one domain and enter another. So those would be the improvements I would like to see.

    For how long have I used the solution?

    I have been working for approximately fifteen years since I began in the world of networking and cybersecurity.

    What do I think about the stability of the solution?

    I think it is a stable platform, and that is precisely one of Check Point Cloud Firewall (formerly CloudGuard Network Security)'s strengths. What I have seen is that when there is a bug that may limit functionality or a bug that affects Check Point Cloud Firewall (formerly CloudGuard Network Security) directly, I see it directly from the Check Point Cloud Firewall (formerly CloudGuard Network Security) interface—from SmartConsole or from Gaia—when you log in, it automatically shows you what bug appears and what the solution is. I think that is a great feature: the firewall itself, Gaia itself, tells you: "Look, there is this error, this problem; verify if your device is affected; if so, here is the solution." So I think it is very stable in that respect.

    What do I think about the scalability of the solution?

    I think scalability is one of its strong points, especially in enterprise environments with growth. The horizontal scalability of the MDS architecture allows you to add new management domains and new gateways without impacting existing environments. In terms of vertical scalability, physical appliances and virtual machines allow you to increase processing resources. If traffic or processing needs increase, you can scale up. In Azure environments, we have adjusted instance sizes without service interruption. Where I do think there are some scalability limitations is in the management of objects and rules. When the system grows a lot, I see that policy compilation does get stuck; it feels there is a bottleneck. That scalability in the management of objects and rules is a negative point for Check Point Cloud Firewall (formerly CloudGuard Network Security) because you see a very significant operational bottleneck in very large environments with many client companies.

    How are customer service and support?

    I think the most critical point is the initial response time. For cases of medium severity, which are the most frequent in day-to-day operations, response times are usually very slow, sometimes many hours. You open a case one day and the next day you still do not have a response. However, once the technicians take the ticket, I think they are very professional. We have done updates, troubleshooting sessions, log reviews, rule changes and networking changes, many things. I think TAC of Check Point Cloud Firewall (formerly CloudGuard Network Security) is very competent; they really know what they are doing. But in terms of agility in the response, I think the problem is in the first line of support: the person who initially manages the incidents. I think that is where the problem is and where they could improve so that tickets are immediately redirected to engineers and then a quick solution can be provided. I think the bottleneck is in the first-line support, and that could be improved, because once a specialist engineer takes the ticket, they are very professional and resolve it. They are engineers who are there every day consulting, asking questions, working with you, and they do not leave you alone with the incident or the case you opened.

    Which solution did I use previously and why did I switch?

    Before we used, for example, solutions from Cisco ASA and, in other cases, Fortinet, as they did not offer a multitenant management model as mature as Check Point Cloud Firewall (formerly CloudGuard Network Security) MDS. So when the number of customers and devices grew significantly, it became evident that we needed a platform or tool that would allow us to manage all these completely isolated domains from a single console without compromising the separation between customers. That is when we made this migration.

    I have used other manufacturers. For example, I have a lot of experience with Palo Alto, and you could say that the main difference is the user experience when using Panorama as the centralized management console, which is like an MDS. It has a more modern and intuitive interface than SmartConsole, which, I repeat, I think should be web and should have a facelift. I have been using SmartConsole since 2018 or 2019, and it looks very similar now that we are in 2026; many years have passed. Another point is the visibility of applications with App-ID; it is very well integrated into the security policy from the beginning, while in Check Point Cloud Firewall (formerly CloudGuard Network Security) it requires more configuration to reach a similar level. For example, in multitenant environments with MDS, I feel that Check Point Cloud Firewall (formerly CloudGuard Network Security) is much better than Panorama for managing many customers in an isolated manner. We also use Fortinet, whose equivalent would be FortiManager, but it also has many complexities. I think Check Point Cloud Firewall (formerly CloudGuard Network Security) surpasses Fortinet in threat prevention and the inspection engine; I think Check Point Cloud Firewall (formerly CloudGuard Network Security) is much better than Fortinet. With Cisco Firewalls, with the FMC, Cisco has many shortcomings; I do not like Cisco much. I do not think the firewalls and the FMC are Cisco's strength. You need a very high learning curve to manage an FMC or Cisco Firepower Firewalls because within Firepower there are several layers of firewall—FTD and other derivatives of that—so Check Point Cloud Firewall (formerly CloudGuard Network Security) is very intuitive compared to Cisco. In conclusion, we could say that Check Point Cloud Firewall (formerly CloudGuard Network Security) is not easy to use, nor is it economical, but it is very robust and very mature in complex enterprise environments.

    How was the initial setup?

    This could be when migrations are carried out.

    For several customers, but I will mention one: when a migration to a centralized architecture with MDS was performed. The customer asked us to unify the management of multiple gateways distributed geographically, because before, each policy change required manual intervention on each individual device; instead, with Check Point Cloud Firewall (formerly CloudGuard Network Security) and centralized management, changes propagate simultaneously to absolutely all gateways—that is, all the firewalls that are distributed geographically across several cities from a single console. This drastically reduces time; we went from using hours to minutes, and we also eliminated errors of inconsistency between devices. It is one thing to create several rules and then have to replicate them on multiple firewalls, or create objects and have to replicate them, but now with this, what you do is create a single rule, a single object, a single network and propagate it to the rest of the firewalls. This way you maintain, you could say, a single object, a single rule that is the same for everyone. This eliminates human errors such as a missing IP, a different rule name, misconfigured IP ranges, or ports, those things.

    What about the implementation team?

    We are not partners or resellers at this moment; we simply have some equipment, some customers who use these tools.

    What was our ROI?

    Based on the complexity and growth of users and the geographic distribution of offices—and ultimately we opted for Check Point Cloud Firewall (formerly CloudGuard Network Security). I think there is a long-term return that would be very beneficial for a company. I also think they should take into account the issue of updates. If they are already going with Check Point Cloud Firewall (formerly CloudGuard Network Security), they must be very careful when testing Jumbo Hotfixes and upgrades by doing it first in a preproduction environment, thoroughly reading the notes for each version, and verifying that the bugs that exist between one version and another are fixed in the new update. If necessary, consult directly with TAC of Check Point Cloud Firewall (formerly CloudGuard Network Security); they have helped me a lot when I have had doubts about version upgrades. TAC is very friendly and answers all these questions without problems, and I think that is a very good option. As for licenses, hardware, and training, you have to do a prior analysis so that the engineers who are going to be in charge of the licenses and the solution to be acquired fully understand what is needed and what is going to be deployed.

    What's my experience with pricing, setup cost, and licensing?

    As for costs, as I mentioned, it is a bit mixed, because we have to be honest. For licenses, Check Point Cloud Firewall (formerly CloudGuard Network Security) has a blade-based model, which seems flexible in theory, but in practice can become expensive when you need to activate multiple security features. Each additional blade—IPS, Anti-Bot, Anti-Virus, URL Filtering, and Application Control—increases the cost. You buy a package of licenses of a certain level, but then you realize you need additional capabilities and the cost scales. As for the cost of implementation, it is higher than with other manufacturers; you also need very detailed planning, and I think that when it is multidomain, it is a product that you cannot deploy in a few days. You need planning months in advance. However, I can say that once it is implemented, it works wonderfully. Before reaching that point where everything works perfectly, you clearly have to plan months in advance so that nothing is left out during the migration. It is not the most economical solution in the market, but for complex enterprise environments I think the investment is justified because it is very robust and has been in the market for many years.

    Which other solutions did I evaluate?

    We always looked at several options. We evaluated Palo Alto with Panorama first. The second option was FortiManager from Fortinet, and we also looked at Cisco Firewalls with its manager, which is the FMC. In the end, we put everything on the scale—what best covered our needs based on the complexity and growth of users and the geographic distribution of offices—and ultimately we opted for Check Point Cloud Firewall (formerly CloudGuard Network Security).

    What other advice do I have?

    I think if they are considering investing in Check Point Cloud Firewall (formerly CloudGuard Network Security), they should first look at the initial design of the architecture they are going to use or that they are going to need. Based on that, they should go directly with Check Point Cloud Firewall (formerly CloudGuard Network Security), because I think it is a product where initial architectural decisions have a very large impact on long-term operability. If you build a solid foundation with the architecture you need, I think Check Point Cloud Firewall (formerly CloudGuard Network Security) is a very good solution and, in the long term, will be a better ally than other manufacturers. However, this is achieved by working hand in hand with Check Point Cloud Firewall (formerly CloudGuard Network Security) engineers, and if it is implemented very well from the beginning, the investment is very good. I think there is a long-term return that would be very beneficial for a company. I would rate this review a 9 out of 10.

    Harshal Pachpande

    Centralized cloud security has improved perimeter protection and streamlined traffic monitoring

    Reviewed on Aug 14, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Check Point Cloud Firewall (formerly CloudGuard Network Security) has been acting as a perimeter device for our architecture, and it has been helping us to secure and have centralized management and visibility of the cloud network security. As a security analyst, we have been forwarding those logs with the SIEM solutions where we are monitoring network traffic flows for any abnormalities, applications and services, and for potential security breaches.

    We have been forwarding those logs over to the SIEM, and we have deployed this firewall in our environment to secure the perimeter by introducing policies. We have utilized the features to have the policies in place for communication with the destinations, to identify the source and destination ports and protocols, and the allowed and blocked connections to the firewalls. These were our basic use cases.

    We also use it for network traffic inspections, firewall policy enforcement, application and service controls, and the centralized policy management tool.

    What is most valuable?

    Check Point Cloud Firewall (formerly CloudGuard Network Security) has centralized policy management, and the logging and monitoring is the extensive solution that we have really appreciated, as it supports multiple SIEM solutions to have logging and monitoring in place from a security perspective.

    The product has native integration support, and all of them are integrated with each other. It has been quite simple for us as we have the entire Check Point suite. It has been quite helpful, and it has been easy to integrate with each other.

    We have been utilizing the overall Check Point suites, including the email collaborations, Harmony, and Check Point Cloud Firewall (formerly CloudGuard Network Security). This includes the Cloud Network Security, AppSec, the WAF firewalls, and Cloud Native Security.

    What needs improvement?

    The tool has been quite easy to handle. However, when we were new in this phase, whenever an implementation was going on, there were some areas that we identified with the overall complexity of managing a cloud environment, particularly when we dealt with multiple cloud accounts and networks. Making those workflows more streamlined is an area that can be improved.

    For how long have I used the solution?

    The implementation took around three months, as our environment was quite complex.

    What do I think about the stability of the solution?

    We are not having any downtime as of now. We have been getting notifications from the team regarding maintenance windows. There has been no downtime observed as of now, and with no glitches or bugs.

    What do I think about the scalability of the solution?

    As of now, Check Point Cloud Firewall (formerly CloudGuard Network Security) has been scalable. We have been onboarding our environment and deploying the policies. We have not observed any lagginess or slowness on the portal or in the central management.

    The tool has been quite scalable. We have been deploying the policies, but we have not observed any issues with the scalability.

    How are customer service and support?

    Initially, technical support was there to understand our architecture and to deploy them. They have been quite helpful in the initial phases.

    How was the initial setup?

    The initial setup was quite easy. We have the support team with us to have support, and they have all these SOPs and help documents and the steps on how to perform the tasks. How to perform the onboarding of these firewalls was all in one portal, which was documented with the SOPs. This helped us in a very positive manner.

    What other advice do I have?

    For new users, we would recommend starting with a clear understanding of the cloud network architecture first: how the traffic flows, how the security policies should be made before major configuration changes, and to start monitoring with logging first and understanding how the policy behaves. These are the primary checks that we would advise new users. Our overall score is eight out of ten.

    Chetan Thakur

    Cloud security has supported auto-scaling protection for internet-facing workloads on AWS

    Reviewed on Aug 06, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I am still using Check Point Cloud Firewall (formerly CloudGuard Network Security), and using it means I am working on Check Point Cloud Firewall (formerly CloudGuard Network Security). I am working with Check Point Cloud Firewall (formerly CloudGuard Network Security). Today, I work with Check Point Cloud Firewall (formerly CloudGuard Network Security) as a service provider and partner. Clients are using Check Point Cloud Firewall (formerly CloudGuard Network Security), and the major purpose is that the application is running on the cloud, so Check Point Cloud Firewall (formerly CloudGuard Network Security) is working as a perimeter for the traffic which is coming from the internet.

    What is most valuable?

    The biggest advantage of Check Point Cloud Firewall (formerly CloudGuard Network Security) is that, specifically on AWS cloud, Check Point Cloud Firewall (formerly CloudGuard Network Security) deployment happens in the auto-scaling mechanism, so if a high amount of traffic hits the application, and if Check Point Cloud Firewall (formerly CloudGuard Network Security) CPU is getting increased or it is getting about 80 or 60%, a new Check Point Cloud Firewall (formerly CloudGuard Network Security) gateway will automatically be deployed and it will be functional within 10 minutes. This auto-scaling feature is very helpful and great.

    Check Point Cloud Firewall (formerly CloudGuard Network Security) ensures confidence for cloud deployments and migrations, and I am happy. Check Point Cloud Firewall (formerly CloudGuard Network Security) is helpful for cloud deployments and migrations, and specifically on cloud, I can say the gateways deployed with the auto-scaling mechanism will be a great feature.

    What needs improvement?

    The area of improvement is minimal and not especially a super big problem currently. I would like to see some additional features added to the product, such as integrating Check Point Cloud Firewall (formerly CloudGuard Network Security) with some AI tools.

    The purpose of AI integration could be helpful for security as it will analyze the logs, analyze the patterns, and based on that, suggest the security parameters or the IPS signatures and the policies, and then such configuration.

    For how long have I used the solution?

    I started using Check Point Cloud Firewall (formerly CloudGuard Network Security) two years ago.

    What do I think about the stability of the solution?

    I give Check Point Cloud Firewall (formerly CloudGuard Network Security) a nine for stability.

    What do I think about the scalability of the solution?

    I can give Check Point Cloud Firewall (formerly CloudGuard Network Security) a nine for scalability.

    How are customer service and support?

    I can give Check Point Cloud Firewall (formerly CloudGuard Network Security) nine points for support and technical service.

    Which solution did I use previously and why did I switch?

    I have worked with other firewalls, specifically on Check Point Cloud Firewall (formerly CloudGuard Network Security), and I can say that as compared to FortiGate and Palo Alto, I found Check Point Cloud Firewall (formerly CloudGuard Network Security) as a market leader in the security, as their IPS signature and the firewall provide enhancements with the IPS signature and the traffic.

    How was the initial setup?

    I give Check Point Cloud Firewall (formerly CloudGuard Network Security) a nine for installation and firewall deployment.

    What's my experience with pricing, setup cost, and licensing?

    I cannot take a decision on whether Check Point Cloud Firewall (formerly CloudGuard Network Security) is an expensive or quite affordable tool as I am a technical engineer, and the pricing is taken care of by the sales team only and the management.

    What other advice do I have?

    I am not using other products such as Harmony or CloudGuard, only Check Point Cloud Firewall (formerly CloudGuard Network Security) with management and gateway.

    I cannot say why I chose Check Point Cloud Firewall (formerly CloudGuard Network Security) because I am working as a professional engineer, and that OEM partnership and engagement decision is taken by the management only. The engineers deploy and work on Check Point Cloud Firewall (formerly CloudGuard Network Security).

    Currently, I do not have any examples where Check Point Cloud Firewall (formerly CloudGuard Network Security) helps to reduce organizational risk, but it does help to reduce the risk.

    I give a final rating for Check Point Cloud Firewall (formerly CloudGuard Network Security) a nine.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    ІгорКузьменко

    Cloud security has protected hybrid infrastructures and supports continuous business operations

    Reviewed on Aug 06, 2026
    Review provided by PeerSpot

    What is our primary use case?

    We use both on-premises and cloud solutions and work with both. Regarding the use cases for Check Point Cloud Firewall (formerly CloudGuard Network Security), customers want to protect their infrastructure, and it was particularly valuable when part of the infrastructure is on-premises and another part is on the cloud. Government requirements sometimes mandate only on-premises infrastructure when these requirements are not present, necessitating this solution. Government customers often prefer the on-premises solution, as cloud options are not always suitable.

    How has it helped my organization?

    As a partner, the biggest advantage of the tool is simpler and easier implementation. I believe it is more reliable, particularly regarding electricity and non-stop business processes in companies because the major equipment is not in Ukraine territory. Some customers ask about cloud solutions because they seek safer options during dangerous situations.

    Check Point Cloud Firewall (formerly CloudGuard Network Security) helps reduce organizational risk because it provides correct connections to cloud infrastructure and acts as a cloud access security broker. This function is critical in the first year of using this solution, allowing us to monitor our cloud infrastructure.

    What is most valuable?

    Check Point is the leader in gateways, and this is supported by Gartner, Forrester, and other review platforms. My customers with real cases also speak about this.

    The major reason for choosing Check Point is that we have qualified engineers for this product, which influences my decision towards this solution. If you speak about small and medium-sized businesses, middle market, and the enterprise level, we provide appropriate solutions for these customers, and we use this vendor's solution. For smaller businesses, we also use other solutions, which are quieter.

    All Check Point products are integrated with each other. We use Harmony, we use solutions from gateways, Harmony, Quantum Group solutions, web application firewall, and SmartCM, which is a tool for log analysis and visibility. We use more than fifty percent of the portfolio.

    What needs improvement?

    Regarding negative aspects about Check Point, previous issues included productivity metrics. Check Point solutions often do not provide as much productivity for machines' CPUs, and the implementation requires qualified engineers. It is not an easy solution to implement, and the price is above average—at least three points regarding these factors.

    For how long have I used the solution?

    I have been working with Check Point Cloud Firewall (formerly CloudGuard Network Security) for two years. Overall in the business, my experience in cybersecurity products stretches to five years.

    What do I think about the stability of the solution?

    We encounter some obstacles in our projects, but in general, I am satisfied with the stability and reliability.

    What do I think about the scalability of the solution?

    In terms of scalability within the product, it is not easy to expand in terms of price or market expenses.

    How are customer service and support?

    I am very happy with the customer service from Check Point. We have a private engineer who is closely connected to the vendor and engaged in ongoing learning programs and accreditation. For support, I would rate it around seven to eight.

    What was our ROI?

    Despite the price being on the higher side, the value for investments is substantial. It meets the requirements of suppliers or other business parts for security and protection against cyber risks, functioning like insurance.

    What other advice do I have?

    I know Trend Micro and Palo Alto products, but I am not too focused on them, and I think approximately ten to fifteen percent resemble Check Point, for example. That is why I cannot be so objective about this.

    We are a partner with Check Point, and we have status, although unfortunately I cannot remember what kind of partnership we have.

    Check Point Cloud Firewall (formerly CloudGuard Network Security) deployment model is primarily cloud-based. We use different cloud providers, primarily private clouds and seldom AWS or Azure.

    I am absolutely happy with how secure my cloud deployments are, as the government requirements are being met. It requires qualified engineers for selling at a high level and some competitive engineering expertise.

    My general rating of the product is around eight to nine.

    Arshad Fazly

    Cloud security has strengthened hybrid deployments and supports smooth policy-driven operations

    Reviewed on Aug 05, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I work for Check Point as a distributor here in Sri Lanka, and I serve as the technical architect.

    We provide the entire Check Point stack, including Check Point firewalls, Check Point Email Security, and Check Point ERM. We also offer Check Point Cloud Firewall (formerly CloudGuard Network Security), though it has limited adoption in the Sri Lankan market with only a few customers. We have one customer for Check Point WAF.

    We operate as a value-added distributor, providing sales support along with implementation assistance, POCs, solution architecting, and comprehensive support services.

    In the Sri Lankan market, we recommend Check Point Cloud Firewall (formerly CloudGuard Network Security) to manufacturing industries and conglomerates who are on their cloud journey. However, we have a substantial market for firewalls among banks, though they are not yet ready to transition to the cloud. Therefore, our primary focus is approaching the manufacturing industry and conglomerates.

    What is most valuable?

    I believe the VDOM functionality from the firewall side, particularly the virtual firewalls, could be improved. For multiple virtual firewalls in cloud instances, it would be beneficial to optimize this aspect and provide consistent security levels across all instances where multiple micro-segmentation networks exist in the cloud.

    One area for improvement involves policy optimization at the VDOM level to enable simultaneous policy enforcement. The policy configuration is somewhat complicated compared to other vendors in the market, and simplification would be advantageous. Enhanced ecosystem integration would also be valuable.

    Additionally, incorporating CSPM into Check Point Cloud Firewall (formerly CloudGuard Network Security) portfolio would improve visibility on the application side of the cloud network, not only on the network side but also on the application side. We expect these features because vendors like Palo Alto provide comprehensive cloud security. We want our customers to experience Check Point Cloud Firewall (formerly CloudGuard Network Security) as a comprehensive cloud security platform rather than simply a cloud firewall.

    What needs improvement?

    Currently, we have one customer using Check Point Cloud Firewall (formerly CloudGuard Network Security), and they are satisfied. However, we need to complete an integration with a Nutanix environment for the hybrid component that the customer requested. This integration has not yet been delivered by Check Point. Once this is properly addressed, the customer will be fully satisfied with the platform.

    We have not yet completed the integration and are about to begin the integration process.

    For how long have I used the solution?

    Overall, I have been working with Check Point for approximately five years.

    What do I think about the scalability of the solution?

    For this specific customer, the implementation of Check Point Cloud Firewall (formerly CloudGuard Network Security) was very smooth. However, regarding the VDOM component, the customer expected it to be at a more optimal level rather than being complicated regarding policy enforcement for the multiple micro-segmented environment. Other than that, everything functioned well.

    How are customer service and support?

    Technical support is excellent, and we have a country SE who provides support. The TAC support is also strong. The support from TAC has been consistently good, and there is nothing negative to comment on regarding that aspect.

    How was the initial setup?

    The setup process is straightforward and easy.

    What other advice do I have?

    Competition with Fortinet in the Sri Lankan market is limited, as they are considerably cheaper and claim to address customer requirements. When approaching this market, Check Point pricing is somewhat expensive. We reduced our prices to acquire that customer, but I think that if pricing could be lowered further, we could approach other sectors where price is a critical evaluation factor. Better pricing in relation to competition would provide us an advantage in promoting Check Point Cloud Firewall (formerly CloudGuard Network Security) in this market. My overall review rating for Check Point Cloud Firewall (formerly CloudGuard Network Security) is nine out of ten.

    Anurag D.

    Comprehensive Cloud Security with Strong Threat Prevention and Centralized Policies

    Reviewed on Jul 24, 2026
    Review provided by G2
    What do you like best about the product?
    What I like most about Check Point Cloud Firewall (formerly CloudGuard Network Security) is the combination of comprehensive cloud security, advanced threat prevention, and centralized policy management. It delivers reliable protection across different cloud environments while also simplifying how security policies are created and maintained. Overall, it helps organizations keep a strong security posture without adding unnecessary operational complexity.
    What do you dislike about the product?
    The initial setup and configuration can feel complex, and some of the more advanced features come with a learning curve. On top of that, the licensing costs may be high for smaller organizations, and the management interface could be more intuitive and easier to navigate.
    What problems is the product solving and how is that benefiting you?
    Check Point Cloud Firewall (formerly CloudGuard Network Security) helps secure cloud workloads by preventing cyber threats, enforcing consistent security policies, and protecting network traffic across cloud environments. As a result, it strengthens overall security, lowers operational risk, and makes cloud security management simpler and more consistent.
    Banking

    Single Pane of Glass for Multi-Cloud Visibility and Faster Triage

    Reviewed on Jul 21, 2026
    Review provided by G2
    What do you like best about the product?
    It provides a single pane of glass across AWS, Azure, GCP, and hybrid environments. Instead of jumping between multiple consoles, I can view logs, alerts, and policy hits in one place, which speeds up the initial process.
    What do you dislike about the product?
    The UI can feel overwhelming at first. As an L1, it takes some time to figure out where the logs are, how the policies map to cloud resources, and what each alert actually means.
    What problems is the product solving and how is that benefiting you?
    Organizations migrating to AWS, Azure, or GCP often end up with different tools and policies in each environment. Cloud Firewall brings the same firewall, IPS, anti-malware, URL filtering, and application control logic into the cloud, so security doesn’t become fragmented across platforms.
    reviewer2875401

    Unified security policies have protected our hybrid network with deep, user-based controls

    Reviewed on Jul 20, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Check Point Cloud Firewall (formerly CloudGuard Network Security) is the main manager that provides network security in different forms in my organization. The primary task that Check Point solves is serving as the main means of network security.

    Check Point Cloud Firewall (formerly CloudGuard Network Security) has several classes of modules. The main modules include Firewall, Antivirus, Anti-Bot, URL Filtering, the IPS module, and Identity Awareness, which is tightly integrated into our organization and ensures connectivity of corporate users with the corporate network, allowing us to create dynamic sessions and policies.

    In our practice, we use a single common profile for all gateways in Check Point Cloud Firewall (formerly CloudGuard Network Security), which allows us to unify all policies and, with the help of sections, display what accesses exist for particular services.

    The Identity Awareness module helps our company by allowing us to have approximately fifty Active Directory controllers. We have deployed three Identity Awareness controllers, which are connected to all our security gateways. It works on the principle that when a user logs into their device, data about their current IP address and login is written to the Active Directory logs. The Identity Awareness controller integration reads them and sends them to the security gateway. Check Point Cloud Firewall (formerly CloudGuard Network Security) then queries the Active Directory controller, pulls in all the user's groups, and allows access for each user based on their Active Directory groups, which makes it possible to create dynamic policies and dynamic accesses.

    Check Point Cloud Firewall (formerly CloudGuard Network Security) is also used to provide VPN access for engineers. At the moment, we are no longer using Check Point Cloud Firewall (formerly CloudGuard Network Security) together with other Check Point solutions. Previously, we had approximately five projects integrated with Check Point. We used their IA (Identity and Access) solutions, their analyzers, and also their endpoint client at the workstation level.

    What is most valuable?

    The main benefit and main advantage of using Check Point Cloud Firewall (formerly CloudGuard Network Security) is that we use unified security approaches both on on-premises segments and in the cloud. We have the same set of policies applied to different types of gateways—both physical and virtual. A unified approach greatly simplifies the administration of the entire network.

    By default, most companies do not use separate firewalling solutions in the cloud at all. They use basic functions such as security groups, NACLs, target evaluation, and similar tools. This is sufficient for them. However, all these solutions do not allow the network to be protected from more advanced attacks above standard firewalling. Check Point Cloud Firewall (formerly CloudGuard Network Security) or any NGFW solution makes it possible to protect against a large number of attacks at the IPS, antivirus, and anti-bot level. If there is a sandbox—SandBlast—then the solution can also inspect what is inside the packets themselves to maximally protect the corporate network. By default, cloud-native solutions do not provide this capability.

    What needs improvement?

    The main limitations of Check Point Cloud Firewall (formerly CloudGuard Network Security) are not in Check Point itself but in the cloud platforms on which it is deployed. Because not all clouds have L2 infrastructure, you cannot build a unified clustering system everywhere. As a result, the problem usually is not with Check Point, but with the cloud.

    The main problem with Check Point Cloud Firewall (formerly CloudGuard Network Security) is that it uses a separate thick client instead of a browser. A browser-based SmartConsole exists, but it still has a number of limitations, while the thick client, the so-called SmartConsole, often works unstably, freezes, and has to be restarted.

    I do not recommend using Check Point Cloud Firewall (formerly CloudGuard Network Security) as a VPN hub for site-to-site VPN because it is inconvenient to monitor the state of its tunnels, especially visually. It does not have a convenient snap-in and everything can be checked only via the console, which is very inconvenient. Check Point is not the most universal solution as a device that provides routing and administration capabilities in addition to security. It is an excellent firewall, but it has a number of limitations in terms of routing and in creating VPN sessions, especially in terms of displaying their states.

    For how long have I used the solution?

    I have been in my current position for more than seven years.

    What do I think about the stability of the solution?

    Regarding the firewall of Check Point Cloud Firewall (formerly CloudGuard Network Security), I would rate it an eight because of its not always stable operation. As a universal device that provides both security and some routing functions, I would rate it a seven.

    Check Point Cloud Firewall (formerly CloudGuard Network Security) is an excellent central firewall. At the same time, it has some limitations in terms of optimization at the level of displaying VPN-tunnel operation. It also has a more complicated approach to building clusters. Unlike Fortinet, for example, it does not allow you to simply make an active-passive configuration using a shared config. Its clustering approach uses the presence of two IP addresses on each node and necessarily one shared virtual IP address using a VRRP-like architecture. I consider this inconvenient, especially when you need to swap nodes or when the role of each node changes.

    I handled the entire technical part of Check Point Cloud Firewall (formerly CloudGuard Network Security); a separate manager was responsible for licensing and handled all licensing issues for all products, so that was not my area of responsibility.

    Check Point Cloud Firewall (formerly CloudGuard Network Security) still has many additional tools that are not fully integrated into SmartConsole. To get to some specific Check Point functions, you have to open additional consoles, which is very inconvenient. The thick client, SmartConsole, is not maximally stable. It often freezes and requires a lot of resources.

    I do consider Check Point Cloud Firewall (formerly CloudGuard Network Security) to be a stable solution, but I also believe that Check Point requires constant monitoring and timely reaction to possible failures.

    What do I think about the scalability of the solution?

    Check Point has two solutions: cluster and Maestro. ClusterXL is initially intended for a certain volume of traffic. Maestro technology allows you to scale out the firewall group and expand the capabilities of the logical group.

    How are customer service and support?

    The work of Check Point's customer support for Check Point Cloud Firewall (formerly CloudGuard Network Security) varies. We had a large number of cases with Check Point. There were cases that were solved fairly quickly. There were very long ones. There are still cases that we have not closed, but we are no longer actively dealing with them—we have found workarounds to temporarily close certain problems.

    Which solution did I use previously and why did I switch?

    In my practice, I have also used Fortinet's solution, which is also very stable. Fortinet uses the same approaches as Check Point; it has one and the same operating system across its devices. Unlike Check Point, Fortinet has a number of advantages and a number of limitations. The main advantage is its versatility: it acts as both a firewall and a router, works perfectly with VPN, but in terms of security class, it has limitations. Check Point Cloud Firewall (formerly CloudGuard Network Security), as a firewall, has a number of advantages. If you analyze the datasheets provided by Check Point and Fortinet, Fortinet greatly inflates its performance figures.

    I have also used solutions from Fortinet and Cisco ASA before moving to Check Point Cloud Firewall (formerly CloudGuard Network Security) because it provides more capabilities in terms of security and deeper analysis, as well as more detailed troubleshooting options. At the same time, it has some limitations in terms of performance and stability, which I have already mentioned.

    How was the initial setup?

    We have had all possible options for deploying Check Point Cloud Firewall (formerly CloudGuard Network Security). Approximately sixty percent are solutions represented as Quantum (CloudGuard) in configurations like VSX and standalone. We had solutions integrated with VMware NSX, but we have already abandoned them because VMware no longer supports such architectures. Forty percent of our current firewalls are firewalls deployed in public clouds—Azure and AWS.

    What about the implementation team?

    We initially purchased Check Point Cloud Firewall (formerly CloudGuard Network Security) with licenses from AWS, and later we switched to purchasing licenses from an integrator and changed the licensing approach from pure cloud to external licensing.

    What was our ROI?

    The main investment effect and everything I can say is that for all the time of my personal work at companies, our services have never been hacked with Check Point Cloud Firewall (formerly CloudGuard Network Security). There were many attempts, they were all logged, but there were no successful hacks. This is the main benefit we gained from working with this product.

    What's my experience with pricing, setup cost, and licensing?

    Since we use a unified standard for using policies and modules in Check Point Cloud Firewall (formerly CloudGuard Network Security), we can clearly plan which modules we need to activate on a particular gateway for its maximum effective use and cost savings. It does not make sense to activate all blades on all gateways. In our architecture, we have two types of gateways: external and corporate. The corporate ones are more heavily loaded, so they have slightly weaker protection. The external ones are less loaded; therefore, they are maximally protected, and almost all possible Check Point blades are activated for them.

    Which other solutions did I evaluate?

    By default, most companies do not use separate firewalling solutions in the cloud at all. They use basic functions such as security groups, NACLs, target evaluation, and similar tools. This is sufficient for them. However, all these solutions do not allow the network to be protected from more advanced attacks above standard firewalling. Check Point Cloud Firewall (formerly CloudGuard Network Security) or any NGFW solution makes it possible to protect against a large number of attacks at the IPS, antivirus, and anti-bot level. If there is a sandbox—SandBlast—then the solution can also inspect what is inside the packets themselves to maximally protect the corporate network. By default, cloud-native solutions do not provide this capability.

    What other advice do I have?

    My advice to other professionals who are considering using Check Point Cloud Firewall (formerly CloudGuard Network Security) is to treat it exactly as a firewall. It is an excellent fit for some central nodes, data centers, and core levels. As a universal device, especially a small universal device, I would not recommend it because of the complex cluster configuration and also, in some cases, more complex troubleshooting. In particular, it has issues with role changes at the cluster level when older Check Point versions, the so-called R80.x and earlier, are used.

    I really hope that in the future, Check Point Cloud Firewall (formerly CloudGuard Network Security) will abandon the thick client and be able to fully switch to working only via the web interface, and also improve the operation of site-to-site VPN in terms of displaying tunnel states. This is the main problem I have encountered. At the same time, the logging system is excellent, and the troubleshooting system is also very good, but the client's operation definitely has room for improvement. I would rate this review an eight overall.

    Ahad A.

    Beautiful UI, Fine Traffic Control, and Amazing SupportHead of cheese

    Reviewed on Jul 16, 2026
    Review provided by G2
    What do you like best about the product?
    It allows me to have fine control over the traffic that is sent through to our systems. Especially the logging features allows our team to easily inspect any unauthorised intrusions into our network. The user interface is beautiful and it integrates easily into our own systems. The performance is comparable to top systems that we use previously and is good value for money helping us get a high roi. The support from the team is amazing with some exciting ai features.
    What do you dislike about the product?
    I love it so much, their is nothing i dislike about the platform other than a rude sales person but other than that they were amazing. Couldnt ask for a better team to suppor tthe work and provide the solution whciht hey did
    What problems is the product solving and how is that benefiting you?
    It sollves the very hard problemsof stopping intruders and bot traffic into our network. Form hackers to disgruntled employees. IThey helped soilve the problem really well