My customers use the solution for technical and internal Azure resources, including remote access VPN.
Check Point Cloud Firewall with Threat Prevention and SandBlast
Check Point Software TechnologiesExternal reviews
External reviews are not included in the AWS star rating for the product.
Helps to handle increased loads and firewalls
What is our primary use case?
What is most valuable?
Some retail customers find the scale-up and scale-down features valuable, particularly with scale sets. This is useful for handling increased loads on devices and utilizing firewalls, similar to on-premises setups with active standby configurations.
The solution allows customers to migrate workloads securely into the cloud space with a trusted vendor, maintaining everything under a single platform. This ensures visibility into their cloud environments similar to on-premises setups, all managed through a single smart console.
Unified security management simplifies operations by providing visibility into both cloud and on-premises infrastructure. The skill set required to manage it remains the same for both environments.
The level of confidence in CloudGuard Network Security, both for myself and my customers, is very high. The product operates familiarly, consistent with what customers are used to, and it is a trusted name in the space.
What needs improvement?
Based on my previous experience, there were improvements, especially in in-place upgrades. Regarding cost, it might be potentially cheaper considering resource utilization in Azure and VM costs, but licensing could be improved, possibly moving towards a simpler model.
For how long have I used the solution?
I have been using the product for four to five years.
What do I think about the stability of the solution?
CloudGuard Network Security has improved its stability. It is a stable platform.
What do I think about the scalability of the solution?
The tool has improved its scalability over the four years.
How are customer service and support?
The support experience can be hit or miss. It depends on the expertise of the support representative. Some are highly skilled and knowledgeable, while others require more guidance. There might be room for improvement in this aspect.
How was the initial setup?
The tool's deployment is straightforward, whether through the marketplace or templates. It offers flexibility for making amendments before deployment.
What other advice do I have?
On a scale of one to ten, I would rate the solution an eight. The ease of deployment, the single management function, and the features it provides, especially in terms of scale sets and scaling, contribute to it being a solid platform. Many customers are increasingly interested in using it to protect their assets within Azure and AWS, which are the two main areas of operation.
If a colleague is considering purchasing the solution for its security features and licensing, my advice would be to ensure correct deployment. While the solutions are generally straightforward to deploy, there are nuances, especially in Azure infrastructure, that can make troubleshooting more challenging. It's crucial to either use a knowledgeable partner for deployment or ensure a clear understanding of the process before proceeding, as it may be more complicated than anticipated.
Helps to manage cloud traffic locally without routing it through data centers
What is most valuable?
I like the tool's ability to manage cloud traffic locally without routing it through our data centers.
What needs improvement?
The product needs to improve technical support.
For how long have I used the solution?
I have been using the product for four years.
How are customer service and support?
The tool's support has been excellent. We can maintain our Check Point Firewalls effectively, both on-premises and in the cloud.
What's my experience with pricing, setup cost, and licensing?
The tool's monthly costs have undergone a significant reduction, dropping from approximately 12,000 euros to around 4,000. This represents a cost reduction of over 60 percent. However, it's essential to note that while costs decreased in some areas, they increased in others due to shifts in our environment. As our overall environment has grown, currently connecting 50 accounts to the cloud, it's challenging to directly compare costs with the state of our setup three years ago.
What other advice do I have?
Initially, we faced some challenges, especially with the AWS transit gateway, involving manual routing configurations and complex setup tasks. I rate the overall product a nine out of ten.
Protects the file server on the cloud and comes with threat prevention features
What is our primary use case?
What is most valuable?
The tool's most valuable features are threat prevention and protection mechanisms.
What needs improvement?
The connection to the on-premises management requires using the CLI. It's not just a click, and you cannot edit in the management to prepare everything. You need to do it online and in real time. After that, you must execute a script, and then you should be happy that it appears in the management.
For how long have I used the solution?
I have been using the product for five years.
What do I think about the stability of the solution?
CloudGuard Network Security is stable. I haven't encountered any issues with its stability.
What do I think about the scalability of the solution?
The tool is scalable.
Which solution did I use previously and why did I switch?
Choosing between Palo Alto and Check Point is more of a personal preference based on the management you prefer. However, in terms of protection, both provide a comparable level of security, making you feel equally safe. The choice between Palo Alto and Check Point often depends on the customer. If a customer is already using Palo Alto, it might be challenging to convince them to switch to Check Point.
How was the initial setup?
What's my experience with pricing, setup cost, and licensing?
CloudGuard Network Security's pricing is fine.
What other advice do I have?
In most cases, we use the smart management on-premises. With the hybrid solution, we have one log visibility of every single management, which is an advantageous concept. I rate it an eight out of ten.
Appreciate the CME plugin for automatically understanding assets within the cloud
What is our primary use case?
We use the solution for the ingress and egress, often for VMSS auto-scaling groups. This involves linking on-premises to the cloud and managing incoming traffic within the same cloud environment.
What is most valuable?
Customers appreciate the CME plugin for automatically understanding assets within the cloud. This information appears in the manager, allowing users to tag the assets and adjust policies and rules accordingly.
The IT personnel who transition from on-premises to the cloud experience the same understanding, knowledge, and comfort with the cloud environment, using the familiar interface they had on-premises.
What needs improvement?
People don't know about the tool's features. There's a lack of skill. Users require more knowledge on how to integrate it into the cloud environment and orchestrate routing. So, it's not necessarily a CloudGuard Network Security or Check Point issue but more about integration, knowledge, and understanding.
For how long have I used the solution?
I have been using the product for six years.
What do I think about the stability of the solution?
The product's stability is good.
What do I think about the scalability of the solution?
The solution's scalability is good.
How are customer service and support?
The solution's support is good.
What's my experience with pricing, setup cost, and licensing?
The tool's pricing is good. Customers want it to be cheap. I consider the pricing to be elastic. CloudGuard Network Security is perceived as cost-effective compared to using the built-in tools provided by the cloud. Specifically, the VPN functionality is more economical in CloudGuard Network Security, where users can create multiple VPNs without additional charges for each VPN, paying only for the bandwidth. This is contrasted with cloud providers that may charge for each VPN on a per-minute basis, including Ingress and Egress costs.
What other advice do I have?
Unified Security Management provides a consistent interface and knowledge base, allowing those who were trained in Check Point for on-premise use to apply that same understanding across various cloud environments such as Google, AWS, Alibaba, Oracle, and more.
I rate the product an eight out of ten. There is always work to be done. However, some customers may find other technologies more understandable, and there could be a perceived difficulty in the human-computer interaction with Check Point. This might create challenges in comparison to competitors, as customers may find competitors' solutions easier to use.
Helps with internet surfing and handles inter-sector traffic between VPCs
What is our primary use case?
We utilize CloudGuard Network Security for internet surfing and handle inter-sector traffic between VPCs. Specifically, we have over 200 accounts in AWS, each with its own VPC. The solution interconnects all the regions.
What is most valuable?
The tool's most valuable feature is its scalability. You will only have to pay less for scaling up. Its notable benefit is deployment complexity. Regional deployment is simpler compared to on-premise setup.
What needs improvement?
When upgrading the firewall, the old VPC containing the firewalls needs to be destroyed. After that, a new firewall is redeployed in the setup. Additionally, there's a need to separate the routing, and the routing from the old VPC has to be recreated in the new one.
For how long have I used the solution?
I have been using the product for two years.
What do I think about the stability of the solution?
We had issues with stability. We have an open ticket at the support regarding this.
What do I think about the scalability of the solution?
CloudGuard Network Security is scalable.
How are customer service and support?
The tool's support is good.
What's my experience with pricing, setup cost, and licensing?
CloudGuard Network Security is not too cheap.
What other advice do I have?
I don't see any difference in user experience between on-prem and the cloud setup. We have an MDS environment where we can manage the whole country. The tool enables us to manage policies on the same platform for branches and regions in the country. I rate the product an eight out of ten.
Allows filtering of servers on AWS for Internet access and significantly reduced the risk of unauthorized access
What is our primary use case?
We use it to protect Internet access from our AWS environment.
How has it helped my organization?
Before we implemented CloudGuard, we had no filtering on what was accessed on the internet from our AWS environment.
Now, we can filter which websites users can access and block categories that are a risk. For example, we can block social media and gambling sites. This has helped to decrease the risk of access to malicious content on the internet.
What is most valuable?
It allows us to filter what the servers on AWS can access on the Internet and allows us to filter in terms of IPS, antivirus, and so on, for the contents that are accessed on the Internet.
What needs improvement?
The complexity to deploy should be decreased.
For how long have I used the solution?
I have been using this solution for about five years.
What do I think about the stability of the solution?
It is a stable solution. It has been pretty stable for us. We haven't faced any problems since it rolled out.
I would rate the stability a nine out of ten.
What do I think about the scalability of the solution?
I would rate the scalability a nine out of ten. We have around 200 end users using this solution in our company.
How are customer service and support?
The customer service and support from the vendor take a lot of time.
The first line of support is not very good. They usually start with junior engineers when you open a case, which can be time-consuming.
How would you rate customer service and support?
Neutral
How was the initial setup?
I would rate my experience with the initial setup an eight out of ten, where one is easy and ten is difficult to setup.
What about the implementation team?
For the deployment, we work with the vendor. So, the deployment took two weeks.
We need to provision the firewall, deploy the manager, and understand where the firewall needs to connect, which AWS area, and so on.
We just needed more than two people for the deployment. We worked with the security network security architect and called them engineers.
What's my experience with pricing, setup cost, and licensing?
With ten being very expensive, I would rate the pricing an eight out of ten.
It is expensive.
What other advice do I have?
It's worth it in the sense that it can protect your network, and it's very scalable.
Overall, I would rate the solution an eight out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
A strong cloud security platform that has protected us against zero-day attacks
What is our primary use case?
The solution is a core operating system, and we use it for threat intelligence.
How has it helped my organization?
CloudGuard has a better catch rate with respect to any attack which is happening. We once faced an attack in a customer's environment on one of our data centers, and Check Point Firewall blocked that attack. The solution's performance is on the higher side.
What is most valuable?
The feature most valuable to me is the NDTX blade that Check Point provides, and I like how the solution is not vulnerable. We haven't had any vulnerabilities in Check Point in the last six months, which is a plus point because the OS Check Point provides is hardened enough that it's not vulnerable to the newer issues, so the network security solution is given in a proper way. These features are an advantage for our customers.
The solution is easy to use once deployed if the administrators have a basic understanding of firewalling. Administrators just have to check the traffic passing through the solution, which will log the traffic properly. And if anything gets dropped, the solution will showcase that to you. The management server Check Point uses is a gold standard.
What needs improvement?
Check Point CloudGuard is not a feature-centric product because Check Point concentrates on security. For example, if a customer asks for reporting, it might not be available, like a bandwidth report. At most, the reports are given with respect to security, not infrastructure.
For how long have I used the solution?
I've used CloudGuard for the last three years.
What do I think about the scalability of the solution?
We have more than 50 customers.
How are customer service and support?
Customer support needs to think about what the customer is talking about. They need to improve on that.
How was the initial setup?
CloudGuard is not a plug-and-play product and requires proper technical knowledge to deploy it. You need the help of a proper professional to deploy it. Deployment hardly takes four hours, but that's only if you know what you're doing. You need to plan the deployment with respect to AWS. You have to know what exactly the customers have deployed in AWS or Azure, or any cloud solution, and based on the review, you need to do their architecture before you can start the deployment. The first step, then, is to understand the customer's data because everything is on a template when it comes to the cloud. You should understand which template you need to use on any cloud. It is impossible to deploy if you're not aware of the customer's environment and how the cloud infrastructure is made. After selecting the proper template, you have to do the implementation. The implementation will go smoothly if you understand the customer's requirements and infrastructure.
What's my experience with pricing, setup cost, and licensing?
I would not say Check Point is very expensive, but when customers compare it with Sophos or any other products, the price is on the higher side.
Which other solutions did I evaluate?
In terms of features, FortiGate has more features in terms of routing.
What other advice do I have?
Our customers use Check Point solutions both on-premise and on the cloud.
Check Point's research and development happening in terms of threat intelligence is better than its competitors, and Check Point's vulnerabilities are fewer. Check Point CloudGuard Network Security has proper security in place with respect to the vulnerabilities. They do not have any vulnerabilities right now. And the research and development happening on Check Point is on the higher side. Most zero-day attacks are protected against. Customers should go for Check Point because of these two points.
If a customer wants FortiGate instead, it's all about whether they can map the budget with Check Point or any other security solution. I cannot compare Check Point and FortiGate, though, because each has its own market.
I rate Check Point CloudGuard Network Security a nine out of ten.