We changed our name from IT Central Station: Here's why
Engineer at a manufacturing company with 10,001+ employees
User
Easy to troubleshoot with great log analytics and good security
Pros and Cons
  • "The most valuable feature is the highly integrated NGFW features such as the IPS or Check Point Identity Awareness, which makes Check Point the best choice on the market."
  • "For the next release, we would like to have better ruleset cleanup tools that are already included."

What is our primary use case?

Our network security is based heavily on Check Point products. We secure our Internet gateway with Check Point. We also secure our production and other very important systems and solution that are mission-critical with Check Point NGFW. For an extra layer of security, we heavily use Check Point Identity Awareness to make Client IP-based rules obsolete. We control the access via dedicated Active Directory Security to groups. These user groups are used instead of IP Client Subnet ranges, increasing our security.

How has it helped my organization?

The Check Point Management makes troubleshooting and log analytics very comfortable. Our Engineers only need a few seconds to see if a connection is dropped or allowed, et cetera. This makes fulfilling these standard tasks easy for the operation team. The easy ruleset management helps us not lose the overview over the Check Point Firewall (NGFW) rulesets in daily operation. Good security should always be simple and clean and this product helps to make our environment more secure against any attacks from the outside.

What is most valuable?

We are using the classic firewalling, the Intrusion Preventions System (IPS) and we also use Check Point Identity Awareness. The most useful feature is for sure the classic firewalling, however, we could get this feature also from other vendors. The most valuable feature is the highly integrated NGFW features such as the IPS or Check Point Identity Awareness, which makes Check Point the best choice on the market. They have been leading the market for 20 years. This is deserved, in our opinion.

What needs improvement?

Check Point, of course, has flaws. As a Check Point Engineer, you must also be a Junior Linux Engineer as many things are happening on the command line in daily operation and almost all the time during troubleshooting. This makes learning Check Point a little bit harder than other firewall brands. The licensing was always a pain and is still a pain to deal with. 

For the next release, we would like to have better ruleset cleanup tools that are already included. It would make security management tools obsolete.

For how long have I used the solution?

We've used Check Point for almost ten years.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
LuisRodriguez1
Support Manager at Sefisa
MSP
Top 5Leaderboard
Stable and very robust with helpful technical support
Pros and Cons
  • "The product is very scalable."
  • "Sometimes when they bring on new upgrades, they affect something else."

What is most valuable?

I do like that this solution is a very robust firewall.

It's very stable. 

The product is well supported. The solution is very scalable. 

Technical support has been quite good. 

What needs improvement?

The only thing I would like to improve is the updates. Sometimes when they bring on new upgrades, they affect something else. That happens sometimes. For example, something that was working well might have a new issue after an update. It's understandable as they do have like to add innovations. When you are innovative, you face some risks. 

They have already announced that they will be adding SD-WAN as a new feature.

For how long have I used the solution?

I've been using the solution for 18 years.

What do I think about the stability of the solution?

The solution is very stable. There are no bugs or glitches. It doesn't crash or freeze. It's reliable. That said, I would like the latest version to be more stable.

What do I think about the scalability of the solution?

The product is very scalable. You have very good options. For example, if you start with a smaller firewall and you want to upgrade to have newer hardware, they have different options. For example, you can run a script that is going to tell you the new appliances that you need, according to your new requirements according to your network consumption. 

It did launch Maestro about two years ago. Maestro is something that allows you to stack firewalls. If your current firewalls handle the traffic anymore, you can add new firewalls to it. 

If you want to change the firewall you can do these trade-ins. You can return the old firewall and they will give you a special discount. 

How are customer service and support?

Technical support has been very helpful and responsive. We've been happy with the level of support they offer. 

How was the initial setup?

The product is easy to set up. I am seasoned on Check Point. For me, it's very easy. I wouldn't say it's hard. 

What other advice do I have?

I'd rate the solution at a ten out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer:
Flag as inappropriate
Learn what your peers think about Check Point NGFW. Get advice and tips from experienced pros sharing their opinions. Updated: January 2022.
563,208 professionals have used our research since 2012.
Senior Cyber Security Consultant at Yapi Kredi
User
Great blade technology, easy to configure, and lowers administrative workloads
Pros and Cons
  • "The ease of configuring VPNs can be very useful especially for companies with lots of remote locations."
  • "If you have a long ruleset, you may experience performance issues on the GUI, and installing rule changes on gateways can take a comparatively long time."

What is our primary use case?

We use Check Point Next Generation Firewalls as a perimeter firewall for all sites, including the DMZ, disaster recovery center, and branch offices. We also use IPS, Anti-Bot, Antivirus, Identity Awareness, Application Control, and URL Filtering blades at all gateways. At our main site, these blades provide additional security controls to our existing security solutions. For our branch offices, Check Point Next Generation Firewalls work as unified security products and we do not need to implement additional security solutions.

How has it helped my organization?

In addition to legacy firewall features, by using Check Point Next Generation Firewalls blade technology, you can improve your security. 

By using the smart console, you can control tens of gateways from a single point. The smart console also allows you to control all the blades from the same GUI. These features decrease our manpower needs. 

The identity awareness feature makes it easier to implement and manage firewall rules. 

The ease of configuring VPNs can be very useful especially for companies with lots of remote locations.

What is most valuable?

Check Point Next Generation Firewalls have numerous blade options such as Anti-bot, IPS, and URL filtering. In most cases, one box could be sufficient to use all these blades. You can manage all these blades from a single console. This feature lowers your administrative workload. 

If you have comparatively small branch offices, in addition to administrative workload, instead of spending money for security products such as proxy or IPS, Check Point Next Generation Firewalls could meet your requirements. 

What needs improvement?

If you have a long ruleset, you may experience performance issues on the GUI, and installing rule changes on gateways can take a comparatively long time. 

If you use Check Point firewalls for a long time, it is inevitable to have long rulesets over the years. The need for using different GUI applications for different versions can be confusing. A backward compatibility feature for smart console versions could be useful - especially if you are an enterprise customer, you probably need to use different versions at the same time. 

For how long have I used the solution?

We have used the solution for 9+ years.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
IT Security Manager at a retailer with 10,001+ employees
Real User
Top 5Leaderboard
Highly secure, good performance, and reliable
Pros and Cons
  • "Check Point NGFW is easy to use, flexible and provides good performance. The security of the product is excellent, we do not have to do a lot of patching or upgrades because of vulnerabilities."
  • "The solution could improve by keeping more up-to-date with technology. For example, if Amazon releases something in the security field, Check Point should have integration or adoption of this feature a bit faster than it is today. Sometimes we can hear a lot of the marketing information about an attractive feature, which we would like to have, but the feature will be released in two years. This timeframe should decrease."

What is our primary use case?

We use the solution for a perimeter firewall, an internal segmentation firewall, and a routing device in our organization.

What is most valuable?

Check Point NGFW is easy to use, flexible and provides good performance. The security of the product is excellent, we do not have to do a lot of patching or upgrades because of vulnerabilities.

What needs improvement?

The solution could improve by keeping more up-to-date with technology. For example, if Amazon releases something in the security field, Check Point should have integration or adoption of this feature a bit faster than it is today. Sometimes we can hear a lot of the marketing information about an attractive feature, which we would like to have, but the feature will be released in two years. This timeframe should decrease.

For how long have I used the solution?

I have been using Check Point NGFW for approximately nine years.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

This solution provides service for 50,000 employees in my organization.

How are customer service and technical support?

We have premium support which is different from regular support. We have had good experiences with the support.

Which solution did I use previously and why did I switch?

We have used BitScaler previously and use Check Point CloudGuard Network Security.

How was the initial setup?

The installation is easy. It can be installed through an image very quickly.

What was our ROI?

The solution has saved us a lot of costs from an operational perspective.

What's my experience with pricing, setup cost, and licensing?

There is an annual license required for this solution.

What other advice do I have?

I would recommend this solution. However, I would advise everyone to carefully evaluate their needs against this vendor and compare them with the competition. There is a lot of strong competition between Palo Alto and Fortinet. One could have an advantage over the other for a customer's specific use case.

I rate Check Point an eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
SaifKhan1
Network Security Engineer at a consumer goods company with 201-500 employees
Real User
Top 5
Descriptive logging, good dynamic port features, and the technical support is helpful
Pros and Cons
  • "The information stored in the logs is very descriptive and includes a lot of details."
  • "Until you have some experience, the installation and configuration are difficult."

What is our primary use case?

We primarily use this product for cloud computing security. It is an integration platform for IPS and I also use it for performance monitoring.

I also coach classes on the use of this firewall, which is installed on my personal laptop.

What is most valuable?

This product is more secure than other firewalls, such as FortiGate.

The information stored in the logs is very descriptive and includes a lot of details.

The dynamic port features are better when compared to other firewalls.

What needs improvement?

This firewall is difficult to manage and use when you first begin using it. However, once you are used to it, the interface is comfortable and easy to use.

The Smart Control feature is hard to install.

In the future, I would like to see more features in the unified security management platform.

What do I think about the stability of the solution?

This is a reliable firewall.

What do I think about the scalability of the solution?

Scalability is not an issue with Check Point.

How are customer service and technical support?

Technical support from Check Point is good.

Which solution did I use previously and why did I switch?

I have experience with other firewalls including FortiGate. Check Point is more secure, although it is more difficult to deploy and configure.

How was the initial setup?

Until you have some experience, the installation and configuration are difficult.

What's my experience with pricing, setup cost, and licensing?

The licensing fees are paid on a monthly basis and I am happy with the pricing.

What other advice do I have?

Check Point is responsible for inventing several firewall security features.

In summary, this is a good product and I recommend it because it the most secure firewall on the market.

I would rate this solution a nine out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
System Security Engineer at Ziraat Teknoloji
User
Great IPS and Antivirus features with responsive technical support
Pros and Cons
  • "The Blades work fine and the performance optimization is great."
  • "The upgrading process takes too much time."

What is our primary use case?

We primarily use the solution for security.

How has it helped my organization?

Check Point NGFW is a stable and user-friendly solution. It has increased the security level and stability within our organization. With the ATP solution, it works and is fully competent. It can catch many zero-day attacks and it fits NGFW well,

What is most valuable?

The most valuable features are IPS and Antivirus. 

The Blades work fine and the performance optimization is great.

What needs improvement?

In some features, it is not easy to use the Check Point firewall. 

The IPSEC VPN setup is not easy to configure. In some cases, if the VPN is not established, it is very hard to troubleshoot the configuration. It does not address the problem well. 

The upgrading process takes too much time.

For how long have I used the solution?

I've used the solution for seven years.

What do I think about the stability of the solution?

The stability is very good. I would rate it at a nine out of ten.

What do I think about the scalability of the solution?

The solution is scalable. I'd rate it at a nine out of ten.

How are customer service and technical support?

In most cases, they answer our ticket in one day. They are willing to solve the problems at hand.

How was the initial setup?

The initial setup is not easy, however, it is also not very complex. We have to use both the Gaia and smart console interface and it should be checked for some conf from the CLI.

What about the implementation team?

We did and their expertise was high. We did not face many problems.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
Mitchell Mugerwa
Procurement Supervisor at Centenary Bank
Real User
Top 20
Support is okay, but is inequitable with the price
Pros and Cons
  • "The pricing is okay."
  • "While the solution is good, we wish to have something that is a bit better, as the threats have evolved over time."

What needs improvement?

While the solution is good, we wish to have something that is a bit better, as the threats have evolved over time. We have been using Check Point for more than than eight years and are interested in a better solution. We entered a review site which ranks top security firewalls and saw that Palo Alto is ranked number one, followed by Fortinet, with Check Point in the lead. We noticed that Palo Alto was much more expensive than Fortinet, but wished to know which key features differentiated the two. 

Though we did not take issue with the price of Check Point NGFW, we felt that it was providing us with inadequate support here in Uganda. This is why we decided to switch solutions. I should note that I do not have a technical background and am responsible for procurement. 

The value we were getting for our money was an issue. I work for a bank for which security is very important, but we were not being assured of the appropriate support. The licensing fees we were paying did not equate with adequate local support. We had already had a bad experience with Check Point, so we did not bother with a quote from it and, instead, got one from several local companies that can support either Palo Alto or Fortinet. 

How are customer service and technical support?

We do not feel that the local support given in Uganda is equitable with the pricing. 

What's my experience with pricing, setup cost, and licensing?

While the pricing is okay, the local Ugandan support one gets is not commensurate with it. 

What other advice do I have?

I rate Check Point NGFW as a six out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
Co-Founder at a tech services company with 51-200 employees
Real User
Reporting need improvement and the stability is poor, but we have no complaints about the web-filtering capabilities

What is our primary use case?

We use this solution for web filtering and threat analysis.

What needs improvement?

The reporting needs to be improved. I still don't have access to the reporting service.

For how long have I used the solution?

I have been using Check Point NGFW for three years. I am not sure which version is being used at this time. If we are not using the latest version, we are using the version before that.

What do I think about the stability of the solution?

We have recently had some issues with the stability of this solution. It is not stable. We had an issue when we made some improvements to our power supply and the Check Point stopped working and needed to be recovered. There were many errors in the file system and it could not start. It blocked the work…

What is our primary use case?

We use this solution for web filtering and threat analysis.

What needs improvement?

The reporting needs to be improved. I still don't have access to the reporting service.

For how long have I used the solution?

I have been using Check Point NGFW for three years.

I am not sure which version is being used at this time. If we are not using the latest version, we are using the version before that.

What do I think about the stability of the solution?

We have recently had some issues with the stability of this solution. It is not stable.

We had an issue when we made some improvements to our power supply and the Check Point stopped working and needed to be recovered. There were many errors in the file system and it could not start. It blocked the work for the entire factory. We lost three days where we could not work.

That was the final straw for us and why we are moving to FortiGate.

How are customer service and technical support?

Our company is outsourcing the support.

Which solution did I use previously and why did I switch?

We are also using Fortinet FortiGate 600 and 200. We have also just ordered Palo Alto.

What's my experience with pricing, setup cost, and licensing?

We pay the licensing fees on a yearly basis.

What other advice do I have?

We are one of the largest manufacturers of steel in Europe.

I would not recommend this solution to others. I am very disappointed.

I would rate Check Point NGFW a five out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
Product Categories
Firewalls
Buyer's Guide
Download our free Check Point NGFW Report and get advice and tips from experienced pros sharing their opinions.