What is our primary use case?
I have been using Check Point Application Control almost since I got to this company. I'm working with Check Point products, all of the firewall blade features. For almost two and a half years, I'm working with the Application Control blade.
My main use case for Check Point Application Control is to implement or deploy Check Point firewalls including the Application Control blade. That's included in the firewall as a firewall blade. I am using Check Point Application Control for granular control. For example, to block or allow interrupts from the application infection or to allow social media specifically for some departments or to block some departments from accessing social media and different websites and web apps.
In our latest deployments in a banking environment, we blocked Telegram, social media, and all social media access, video streaming such as YouTube from the application and URL filtering policy tab. Check Point Application Control has its own application database, and I can use my custom application to define and enforce policies on in-house or less-known apps. For this deployment, the bank needed the marketing teams to access social media and video streaming such as YouTube, so we allowed that for this department, while we blocked access for other departments. This allows us to use our resource or our network bandwidth effectively.
What is most valuable?
The best features Check Point Application Control offers include integration with Identity Awareness such as Active Directory, which allows me to block or allow user groups that are integrated through or that are fetched from the Active Directory. I can allow some resources and block some resources from accessing certain applications on the internet.
The integration with Active Directory benefits my team by enabling us to group users into some groups and block some users from accessing social media or different malicious websites. Before deploying Check Point firewall, we had no option to integrate Active Directory through old firewalls such as Cisco ASA. To block malicious applications or sites, we needed to use Application Control. By integrating Check Point firewall with Identity Awareness, we can accommodate access based on team needs while restricting others.
The feature that allows Check Point Application Control to define or enforce policies on in-house developed applications means I can customize those applications and feed them into Check Point Application Control to differentiate them from malicious websites, allowing those websites to be used in the organization. This database can be customized by my own in-house applications, promoting flexibility to manage custom apps made by our in-house team.
Check Point Application Control has positively impacted my organization by allowing us to segment internet access groups into social media access, organizational applications access, and working applications in the in-house developed applications. Check Point Application Control helps me group users into social media groups, video streaming groups, and remote access groups based on user privilege and position, which makes users more effective in their working hours by blocking applications that waste their time. Additionally, we improved our security by blocking anonymous websites through Check Point Application Control database, enhancing our security posture overall.
What needs improvement?
Check Point Application Control could be improved by differentiating the network access segment section in the policy from the application URL filtering. Administrators currently get confused as they cannot search effectively on both sides due to overlapping parameters. Network access should pertain to Layer 3 while application URL filtering should pertain to Layer 7. This differentiation should be improved in the future.
For how long have I used the solution?
I have been working in my current field for almost three years.
How are customer service and support?
The customer support is excellent; they provide everything they can. Previously, there was a lag in responses on the support portal, but it has improved to be faster. When I create a case, I receive responses and solutions quickly.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
I previously used Cisco ASA, an old firewall that lacks application-side features, which is why we switched to Check Point Application Control. It doesn't have integration with Active Directory and cannot secure our environment from Layer 3 to Layer 7 attacks, so we switched for the needed features.
What was our ROI?
I have seen a return on investment, noting that after using Check Point Application Control blade, we minimized our bandwidth usage by half and also observed improved productivity, so we get what we invested in.
What's my experience with pricing, setup cost, and licensing?
In my experience with pricing, setup cost, and licensing, there are some costs associated with Check Point Application Control licensing and products, but it is good at what it does. That's why it's costly.
Which other solutions did I evaluate?
Before choosing Check Point Application Control, I evaluated other options including Palo Alto and FortiGate, but our clients chose Check Point products, leading us to select Check Point Application Control.
What other advice do I have?
I have noticed increased bandwidth because social media applications consume a lot of bandwidth. For example, Telegram consumes a lot of our organization's bandwidth, so Check Point Application Control helps me block those applications from being used by our organization employees. This also helps us save time and increase productivity.
The reporting feature is very nice on Check Point Application Control. It offers detailed reporting and can monitor usage patterns in SmartEvent and SmartConsole. Check Point Application Control is scalable, as I can easily scale it when necessary.
My advice to others looking into using Check Point Application Control is that if you want to have granular control of your entire apps or specific functioning apps, you need Application Control blade along with the Check Point firewall.
My company has a business relationship with Check Point as we are partners and resellers of Check Point products. I am responsible for deploying Check Point products to our customers, including Application Control in the firewall blade.
I rate Check Point Application Control eight out of ten because there needs to be improvement on the network and Application Control, which creates ambiguity for the administrator when configuring the security policy. The overlapping parameters on the network access policy layer and the application URL policy layer are the reasons for my rating. However, it has many good features.
Which deployment model are you using for this solution?
On-premises