My primary use case is for firewall protection. It is a highly available cluster for firewall protection of a site.
McAfee StoneGate [EOL] was previously known as McAfee Next Generation Firewall, Stonesoft, Intel Next Generation Firewall, Intel Security StoneGate.
| Author info | Rating | Review Summary |
|---|---|---|
| Computer Framework at a healthcare company with 1,001-5,000 employees | 4.0 | My primary use is highly available firewall cluster protection. I find its stability fantastic and scalability good. Despite needing some redesign, I am generally happy with its seamless node failover and straightforward setup. |
| Network Security Engineer at a tech services company with 501-1,000 employees | 3.0 | I find Apprism valuable for application control, though its administration isn't user-friendly. I've experienced unstable HA failovers and low customer support, and it lacks SSL VPN. Installation was straightforward. |
| Presales System Engineer with 51-200 employees | 3.5 | I found this solution highly available and stable, improving network administration; initial setup was easy. However, we experienced recurring hard drive reliability issues, which is a major area for hardware improvement. |
My primary use case is for firewall protection. It is a highly available cluster for firewall protection of a site.
It is important for us in case of a disaster, or in case of a failure of one server. This means that the high availability is the most important part for us. It is important for us that the system is available and no connection is going to be lost if the system is restarting one note, or something like that. This is the main request for us for a good firewall protection product.
The most valuable feature is that there is the possibility to have a highly-active cluster, which allowed us to switch off on one note without any connection loss.
After some experience with the solution, we had to do some redesign, but generally, we were happy with the product.
The stability of the product is fantastic. It is a really proofed system. I never have had any type of problem where the system was unstable, or even a a software failure.
In terms of the scalability of the solution, we had two nodes. It was never necessary to add a third node. It was an HP DL360 server which was designed for this application. We had to change it once because the server was too old. We never had any kind of performance problems. If there were ever problems, it was due to the server being too old. But, never any other scalability issues.
I can't comment on technical support, because we really did not use it other than for downloading new versions or for upgrading. We personally do our own application updates.
The setup was very straightforward. It was really simple to implement. I had to take a three day course to know how it works, and then I knew how to set it up.
One big advantage of this product is that it has the possibility to make a lot of network cards inside. It allows many DMZs. We had a lot of workers who were connected to our site, and we needed to divide them on the firewall basic, giving them their own network cards. It was possible to do, because it was w server, and not an appliance only for ports. We were happy to make this happen.
In the past, we had CheckPoint. But, they did not have a really highly available solution. It was very complex to setup.
When considering a vendor, I often consider the real functionality of the product. If it is not functional, we really can't set it up properly.
Apprism is valuable.
It has given us better application control.
It's not user friendly in terms of administration, and it doesn't support SSL VPN.
I've been using it for three years.
There were issues with the HA cluster.
HA failover is not stable.
So far we haven't had any issues.
5/10.
Technical Support:4/10.
McAfee came from Sidewinder, and Sidewinder didn't have much issues in terms of cluster.
It's straightforward, no different than other technology.
We did it in-house.
We also looked at an option from CheckPoint.
HA should be more stable, as most customers are concerned with HA failover - how fast and how stable it is.
Before the installation of the firewall, the network was divided into less zones and the administration was more difficult to manage.
The hardware needs improving as we had a lot of problems with the hard drive reliability, both with the firewall and the intrusion protection system.
I've used it for three years.
None in particular.
Nothing except for a few hard drive fails.
We did need to scale.
8/10 when they needed to help us.
Technical Support:7/10.
Previously the solution was Netasq. The new architecture and the product was chosen by the customer.
Not so complicated. You just need to understand the solution with an external management console instead of an HTTP one.
We implemented it in-house with the support of the internal IT team.
Palo Alto but it was more expensive.