it_user808449 - PeerSpot reviewer
Extranet Architect with 1,001-5,000 employees
Real User
It has streamlined our process for access and firewall management
Pros and Cons
  • "AFA provides project teams with a simplified way to obtain the status on their current rule set."
  • "It has streamlined our process for access and firewall management."
  • "Needs integration to cloud ITSM tools, such ServiceNow."
  • "Be able to automatically analyze application traffic with machine learning capabilities and propose simplification for rule set optimization."

What is our primary use case?

We use AlgoSec FireFlow and AFA modules for risk analysis, audit, and change management to enforce appropriate security compliance.

How has it helped my organization?

It has streamlined our processes for access and firewall management. It is used by all the IT user community internally and by our service provider who is in charge of our IT run activities.

What is most valuable?

AFA and FireFlow modules are the one that we use. 

  • AFA provides project teams with a simplified way to obtain the status on their current rule set. 
  • Fireflow is used for our change management process and is linked to our CP FW. 

What needs improvement?

Integration to cloud ITSM tools, such ServiceNow.

Be able to automatically analyze application traffic with machine learning capabilities and propose simplification for rule set optimization.

Buyer's Guide
AlgoSec
May 2024
Learn what your peers think about AlgoSec. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
770,616 professionals have used our research since 2012.

For how long have I used the solution?

Three to five years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Cyber Security/ Network Intelligence Professional at EliteVAD
Consultant
ALGOSEC - Automate Firewall Security Policy Orchestration

What is most valuable?

  • Granular visibility
  • Risk rules evaluation
  • Saves with manual processes and dependencies

How has it helped my organization?

  • Saves person-hours
  • Security tightening and optimization in minutes
  • Loophole identification which helps with compliance
  • Effective tracking and automation of change management

What needs improvement?

Automated policy push for the Fortinet product family. The Active Change/Automated Policy push feature is already there for all other leading devices such as Cisco, Check Point, Juniper, and Palo Alto, etc.

For how long have I used the solution?

I've used it for two years.

What was my experience with deployment of the solution?

It's not hard to deploy, and can be run on a virtual environment.

What do I think about the stability of the solution?

It is a robust easy to use platform.

What do I think about the scalability of the solution?

It has highly scalable architecture.

How is customer service and technical support?

Customer Service:

The customer service team is reliable.

Technical Support:

They have time-zone matched technical/SLA support and local response team available.

How was the initial setup?

It is pretty straightforward and a piece of cake for the network engineers.

What about the implementation team?

Initial implementation is highly recommended to be done through a vendor and/or subject matter expert so you can leverage the best of the features.

What's my experience with pricing, setup cost, and licensing?

AlgoSec is a best of class solution with unique value proposition. Licensing has flexibility perpetual and subscription models, and by identifying your own real needs can achieve savings.

Which other solutions did I evaluate?

As a fair evaluation, other solutions are available in the security policy cleanup area. However, AlgoSec stands apart with a visionary business centric approach – not limiting itself to a mere firewall security cleanup tool. With AlgoSec, we also get an automated security change management/compliance solution. It has the unique and powerful application connectivity auto-discovery and then translates these to firewall rules. This is useful to achieve automation during datacenter migration, etc.

What other advice do I have?

AlgoSec is a business-driven security management solution, a comprehensive and visionary solution which covers what needs to be covered in firewall security visibility, security change management, and application-security connectivity. AlgoSec as a platform fills the gaps between the otherwise disconnected teams - Security, Network and Applications - within an organization.

Disclosure: My company has a business relationship with this vendor other than being a customer: We are value added distributors of the solution and are confident that we have the best choice in helping customers manage security at the speed of business.
PeerSpot user
Buyer's Guide
AlgoSec
May 2024
Learn what your peers think about AlgoSec. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
770,616 professionals have used our research since 2012.
Presales Engineer at a tech services company with 11-50 employees
Reseller
Automated firewall rule analysis saves time, and automated rule modification eliminates human error
Pros and Cons
  • "AlgoSec Firewall Analyzer can detect misconfigurations and unused or permissive rules, as well as rules without logging. Through a single dashboard, I can see all the problematic rules from all the firewalls. It's very simple, with AlgoSec, to get an analysis of all the rules, and that helps with visibility."
  • "AlgoSec integrates with most of the leading firewall vendors, but one issue is that AlgoSec doesn't support Sophos and Forcepoint. AlgoSec competitors, like FireMon, support Forcepoint."

What is our primary use case?

One of the use cases for the solution is when you have many firewalls from different vendors and would like to handle all the configurations from a single pane of glass.

We are an AlgoSec distributor, and another use case that is very important to our customers, especially in the financial sector, is generating compliance reports. AlgoSec has very comprehensive compliance reporting. Most of our customers who use AlgoSec care a lot about compliance reports, whether ISO or PCI or other types of compliance.

How has it helped my organization?

AlgoSec saves time by providing an analysis of all the firewall rules. For example, I might find 10 unused rules, or rules without objects or without a subnet. To get that information manually can take time. I might have to go through a firewall and check the rules and it would take at least 10 minutes for 10 rules. And a manual process can result in errors. AlgoSec saves time because it can detect all unused rules and I can just remove them via the AlgoSec platform through FireFlow. Removing those 10 rules manually can take about 20 minutes, but through AlgoSec it takes one or two minutes.

The solution can find all the misconfigurations in firewall rules and it can delete or modify them automatically, with no human action needed. As a result, there will no longer be errors in the firewalls. FireFlow handles the workflow of adding and removing policies. Sometimes, an engineer may not have solid experience when it comes to firewall rules. If he goes to the firewall portal itself and tries to add or remove a policy, this policy may cause errors or potential risk. AlgoSec handles this process instead. It helps eliminate human error.

Also, if you have a network engineer with less experience, he can still go through AlgoSec and submit rules. AlgoSec supports another tier of engineers who approve the policies. This is all done using FireFlow.

What is most valuable?

We use the AFA (AlgoSec Firewall Analyzer) and FireFlow. AFA is the most popular feature in our region and FireFlow is good for managing workflow.

AlgoSec Firewall Analyzer can detect misconfigurations and unused or permissive rules, as well as rules without logging. Through a single dashboard, I can see all the problematic rules from all the firewalls. It's very simple, with AlgoSec, to get an analysis of all the rules, and that helps with visibility. AlgoSec can do a risk assessment for each policy or rule in the firewall and detect the severity of each rule, whether low, medium, high, or critical. I can get a quick overview of the risk policies that a customer needs to change because, perhaps, there is a rule where the risk is high.

The AlgoSec dashboard is very simple. I can find all the information without any effort. All the tabs are clear and straightforward.

I can apply changes to rules through FireFlow. For example, when I detect many unused rules, I can remove them and, using FireFlow's process, it is very simple to do so.

It is very easy to generate a compliance report for ISO or PCI. It can be done with one click. Some organizations may have a baseline for compliance. The beauty of AlgoSec is that it can adjust compliance according to the corporate needs or environment, when standards vary from one region to another.

When it comes to visibility, the solution can make a network map for all the devices in the network, whether routers or firewalls. I can run queries to detect network policies. For example, if a customer cannot access the corporate stack or the application site, using AlgoSec I can detect which firewall, and which policy inside the firewall, may be fully or partially blocking access. This is a very important feature and most of our customers use network mapping to create visibility into the network.

What needs improvement?

AlgoSec integrates with most of the leading firewall vendors, but one issue is that AlgoSec doesn't support Sophos and Forcepoint. AlgoSec competitors, like FireMon, support Forcepoint. I have told AlgoSec a number of times that we have many customers that use Forcepoint. I have asked why they don't support integration with Forcepoint. They have said they don't care about Sophos, Forcepoint, and SonicWall. They don't consider those vendors to be leaders in the firewall market and they don't have plans to support them.

For how long have I used the solution?

I have been using this solution for about two years.

What do I think about the stability of the solution?

Sometimes a customer's platform is down, but overall AlgoSec is stable.

How are customer service and support?

Support from AlgoSec is good. When I create tickets, they support us and solve all the tickets. There is no delay in support.

One of the things I don't like about AlgoSec is that when a customer has an issue with the platform, it takes time to resolve. Issues often need more than tier-one or tier-two; they're often not easy for the customer to resolve. It requires the AlgoSec team to solve issues with configurations or performance.

For example, AlgoSec upgraded the platform six months ago and it was mandatory for all customers. On my side, it was not easy to perform the upgrade and I had to request support from AlgoSec.

How would you rate customer service and support?

Positive

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Reseller.
PeerSpot user
Sr Technical Consultant at a tech services company with 11-50 employees
Reseller
Provides full visibility into multi-vendor firewalls with a centralized solution
Pros and Cons
  • "If you go through that compliance report, it will give you whether your firewall is in compliance or not. It will also give you a recommendation whether you need to change it. The compliance has helped us with customers, e.g., internal audit from the quality team and external auditors."
  • "I would like more documents and support for the cloud firewall."

What is our primary use case?

We are not personally using AlgoSec in our organization. We consult with the customer, as to why they have to buy such a solution like Firewall Analyzer. We are a distributor for the Indian market. We guide the customer to why they have to buy this kind of solution, what are the business requirements, etc. 

I have done PoCs and demos on the product.

The solution allows multi-vendor firewalls to have a centralized solution where they can analyze all the rules, duplicates rules, etc. Also, it helps them understand if a change can be automated.

How has it helped my organization?

We consult with big customers who have multiple locations. In every location, they have various firewalls available. With AlgoSec as our product, it has really helped with our operational tasks and activities.

If you go through that compliance report, it will give you whether your firewall is in compliance or not. It will also give you a recommendation whether you need to change it. The compliance has helped us with customers, e.g., internal audit from the quality team and external auditors.

AlgoSec integrates with multiple security vendors. It captures the rules, policies and authentication required.

What is most valuable?

It is pretty simple to use. Resources are readily available.

Firewall Analyzer and FireFlow are very helpful for IT guys, especially for multi-vendor firewalls.

We get a lot of visibility from Firewall Analyzer. It is definitely helpful to see the details of duplicate rules on the firewall. It can define the connectivity and routing.

The solution provides us with full visibility into the risk involved in firewall change requests. This is always required. For example, if you are implementing one rule for network A to network B, but you don't have that visibility in terms of network when you have multiple firewalls, then you have to deploy the rule on every firewall. However, if you have FireFlow, then FireFlow will automatically deploy this rule where it is needed.

What needs improvement?

I would like more documents and support for the cloud firewall.

For how long have I used the solution?

We have been using it for one year. I am level 2 certified. I am familiar with AFA (Algosec Firewall Analyzer), FireFlow, and CloudFlow. I have done the online training for AppViz and AppChange.

What do I think about the stability of the solution?

It has been good. I have not seen any issues.

One to two people are enough for deployment and maintenance. 

What do I think about the scalability of the solution?

The scalability is good.

How are customer service and technical support?

The technical support is good because it is already available in India as well as the R&D. Whenever I need help, they take my call. I don't have complaints in respect to the AlgoSec support.

Which solution did I use previously and why did I switch?

I also have experience with Tufin.

How was the initial setup?

It is straightforward and easy to deploy. Two to three days was enough time to complete the configuration along with the device integrations.

For implementation, I always follow these steps:

  1. Understand the customer's infrastructure, e.g., what are the customer expectations and primary pain points?
  2. Deployment architecture
  3. Hardware requirements and prerequisites
  4. Port prerequisites
  5. initial configuration and setup
  6. Onboard devices with default configuration
  7. Monitor devices for seven days, then apply the recommendation based on the AFA solution.

For the migration, it is really helpful because we all capture all their policies. We can clean up things with Firewall Analyzer. When doing a migration, we take a backup and that is really helpful for the migration process.

What was our ROI?

It has reduced the time it takes to implement firewall rules in hundreds of our customers' organizations. Without FireFlow and Firewall Analyzer, you would need one to two hours to deploy the firewall change request rule because you need to identify where to position that rule. It definitely reduces the time by half.

What's my experience with pricing, setup cost, and licensing?

The pricing is good. Though, I would like if pricing could better support small businesses.

Which other solutions did I evaluate?

We use Cisco ACI with Check Point , FortiGate, and Palo Alto.

What other advice do I have?

This technology gives us total control of our stuff, validation, and clean up of everything that we need.

If you are doing migration from on-prem to cloud, then there is definitely a very quick process and helpful process for that migration.

I would rate this product as an eight and a half out of 10.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
reviewer1242069 - PeerSpot reviewer
Works at a sports company with 1,001-5,000 employees
Real User
Automatic firewall rule configuration helps reduce our workload
Pros and Cons
  • "The automation of the firewall rule deployment, working together with our ticketing system, is the most valuable feature of this solution. The needs as required by a user request are automatically validated and configured in the specified firewalls without any human action."
  • "The interface needs to be more user-friendly for low-profile users so that we can give some kind of access to specific people around the company for self-configuration of specific rules."

What is our primary use case?

Our primary use for AlgoSec is to automate our firewall configuration. We use the AlgoSec system to remotely configure the firewalls, making our life easier.

We are in a multisite environment with plenty of firewalls for perimeter security and LAN segregation for specific proposes. This solution helped us to make the process more dynamic.

How has it helped my organization?

It has reduced the workload for the firewall team thanks to the API integration with our ticketing system, doing the standard type of request automatically. Before having it, we had to create a lot of standard rules that now can now be just pushed from the AlgoSec system.

What is most valuable?

The automation of the firewall rule deployment, working together with our ticketing system, is the most valuable feature of this solution. The needs as required by a user request are automatically validated and configured in the specified firewalls without any human action. This improves the firewall team's workload.

What needs improvement?

I would be nice to have a good tool for network map discovery in the GUI to make it more user friendly and be able to check and modify network maps in graphical and more intuitive way . This will improve our network overview for new deployments and troubleshooting. 

For how long have I used the solution?

I have been using this solution for three years.

What do I think about the stability of the solution?

In three years, we have only had one issue with respect to stability.

How are customer service and technical support?

When we had the issue they responded well.

Which solution did I use previously and why did I switch?

We did not use another solution before AlgoSec.

What about the implementation team?

We deployed this solution using our in-house team.

What was our ROI?

The reduction in workload reduces the cost in terms of human time.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Works at a wireless company with 10,001+ employees
Real User
Traffic simulation allows for testing before release into production
Pros and Cons
  • "The most valuable feature is traffic simulation because, with this function, it has become more practical to know if something is released or blocked in my environment."
  • "I believe Active Change needs to be improved because not all products are supported, and some functions cannot be implemented by Active Change either."

What is our primary use case?

We use this solution for managing an environment with more than five thousand registered devices across firewalls, routers, balancers, and VMware. Highly critical banking environment.

We use FireFlow as our primary ticket management tool.

How has it helped my organization?

With AlgoSec, it was able to conduct the environment so that it was possible to get more accurate and fast information about the changes that the environment went through.

It has reduced the time for firewall rule requests to be implemented in the environment.

What is most valuable?

The most valuable feature is traffic simulation because, with this function, it has become more practical to know if something is released or blocked in my environment.

IPT is valuable because this function is of great help to have a more effective security policy.

What needs improvement?

I believe Active Change needs to be improved because not all products are supported, and some functions cannot be implemented by Active Change either.

Technical support needs to find solutions more quickly.

Active Change could implement routes in Firewalls, it should also be able to perform the creation of APP control and URL filter rules.

For how long have I used the solution?

We have been using this solution for six years.

What do I think about the stability of the solution?

In general, it is a stable product. We have rarely had a problem that resulted in the total unavailability of the solution.

What do I think about the scalability of the solution?

AlgoSec requires a large amount of processing power to perform its tasks, making it a piece of equipment that always requires monitoring to be optimally optimized.

How are customer service and technical support?

Some troubleshooting took months to resolve. So, I think we have to improve this point.

Which solution did I use previously and why did I switch?

I used Nipper and FireMon, but I started using AlgoSec due to the great recommendations I received.

How was the initial setup?

The architecture was defined with one master, four slaves, and one remote.

What about the implementation team?

Our internal team handled the deployment.

What's my experience with pricing, setup cost, and licensing?

I do not have many details of this commercial part.

Which other solutions did I evaluate?

I evaluated FireMon and Nipper in addition to this solution.

What other advice do I have?

Many users have the tool but don't use it with everything it can offer. What I recommend is that you explore all of the features of the product.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Network and Security Engineer at Euronext Technologies
Real User
Relieves workload and increases efficiency by automating time-consuming tasks
Pros and Cons
  • "We are currently in a rule base performance improvement process and AlgoSec is an invaluable tool to accomplish this."
  • "The product is severely lacking in vendor support."

What is our primary use case?

We are currently using this solution to audit our firewall policies (both in performance and compliance), as well as automating the creation of new rules and improving application functionality delivery. We are also using AlgoSec to automate machine provisioning (creation of new rules associated with that machine) and machine decommissioning (removal of rules associated with that machine).

How has it helped my organization?

With AlgoSec, we are now able to automate several time-consuming tasks. We are currently in a rule base performance improvement process and AlgoSec is an invaluable tool to accomplish this. Furthermore, we are starting rule creation automation, which will also provide some relief on our workload.

What is most valuable?

The most valuable feature for us is AlgoSec's ability to analyze rules for risks and for performance while allowing the user to submit a change request immediately based on that assessment. Additionally, the fact that it integrates seamlessly with Ansible, as well as providing an API for the users to extend based on their own needs, is a great plus for us.

What needs improvement?

The product is severely lacking in vendor support. They claim to support some devices, but when you dig deeper, it is only basic support, with enterprise-grade features for those devices being unsupported. This is a big deal for us, as several sections of our network are not fully supported which, in turn, does not allow us to fully automate rule creation. Moreover, we cannot perform end to end connectivity checks. One such feature is the lack of VRRP support on devices other than Cisco or Juniper, which causes the software to interpret a non-existent router as the next hop for a particular flow (the VIP address of the VRRP).

For how long have I used the solution?

One year.

What do I think about the stability of the solution?

While this solution is somewhat stable, there is definitively room for improvement here. We've had some issues with the solution during our usage but, so far, no show stoppers. Other customers of this solution have complained that a large number of devices can severely hinder the stability of the solution.

What do I think about the scalability of the solution?

This is a very scalable solution, built mostly on open source technology. The customer is allowed to extend its functionalities via the API to integrate with other solutions or existing automation.

How are customer service and technical support?

Technical support is sometimes difficult to deal with as the response times are somewhat lacking. One good thing is that the case owner you are assigned to is generally the same,  which is great because, after several cases, the case owner is already familiar with your network.

How was the initial setup?

The initial setup is not cumbersome at all. The documentation and training videos are definitively a big plus.

What about the implementation team?

The implementation was mainly performed by us, with the help of a vendor team. The level of expertise of the third party was passable, but we were looking forward to having someone with more expertise with the product.

What was our ROI?

So far, the ROI is currently only due to the fact that rule automation has decreased the load on our support team, allowing them to work on other projects. We are also able to provide reports to auditors without losing a single day from the network support department. We simply provide AlgoSec reports and analysis.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Security Operations Engineer at a security firm with 201-500 employees
Real User
Enables us to create new rules and have a more secure flow
Pros and Cons
  • "We have critical security policies. With AlgoSec, we can create a security policy to manage critical applications. I have worked in the bank and they have critical applications. We created some security policies for those applications. Controlling the flow is critical for our customers."
  • "It can be optimized. There is a lot of RPA and we have scripts in AlgoSec that need recertification. With AlgoSec Firewall Analyzer, we can see lots of objects and lots of rules that tell us we need to clean the equipment. It will give us a solution but it doesn't always work. The solution that it gives us is not always accurate from the scripts."

What is our primary use case?

We use:

  • FireFlow 
  • AFA, AlgoSec Firewall Analyzer
  • BusinessFlow

I use AlgoSec to optimize the firewall rules and to analyze the logs of a lot of firewalls, like Palo Alto, Check Point, and Fortinet. 

When a user creates a ticket in AlgoSec, I validate the ticket or don't. It's opened flow in the firewalls also. 

I also use it to implement and push the rules in the equipment. 

I have used it for compliance and analytics. I audit Cisco ASA equipment. I do a compliance report for every piece of equipment. I do some reports and also weigh any risk on each piece of equipment. Some rules use, for example, a critical port. If it shows to be a risk, we'll take action. For example, we can optimize a permissive rule and create new rules to have a more secure flow.

I use FireFlow to help users when they create a ticket in AlgoSec. I help them with information like the IP source, IP destination, and endpoint. 

AlgoSec also helps users choose the right equipment. There are a lot of stages and at every stage, I can choose the equipment. We have a lot of equipment and a lot of firewalls so that we can identify equipment. I also use the map to see the flow from the source IP to the destination IP so we can discover the network. It's essential to have a picture of the flow in terms of the equipment, services, and protocol.

We have critical security policies. With AlgoSec, we can create a security policy to manage critical applications. I have worked in the bank and they have critical applications. We created some security policies for those applications. Controlling the flow is critical for our customers. 

How has it helped my organization?

In the beginning, we compared tools like AlgoSec, Tufin, and Skybox. We did some research. There was budget to purchase the resource. We did comparisons and found AlgoSec to be the best solution.  

What is most valuable?

It's easy to use. It's not very complex. You can do a lot of things with AlgoSec.

What needs improvement?

AlgoSec should be optimized. There is a lot of RPA and we have scripts in AlgoSec that need recertification. With AlgoSec Firewall Analyzer, we can see lots of objects and lots of rules that tell us we need to clean the equipment. It will give us a solution but it doesn't always work. The solution that it gives us is not always accurate from the scripts.

For example, because we have a workflow, when the user creates his ticket, the ticket was automatically dispatched to different teams. We have a security team and another team to implement and push the rules. The ticket automatically will get sent to the wrong team and then we need to send it back to the user for them to update. 

For how long have I used the solution?

I have used AlgoSec for two years. I use AlgoSec in French.

What do I think about the stability of the solution?

I find AlgoSec to be stable. Sometimes there are days that it doesn't work. We connect to AlgoSec via the web. Some days we don't have access to it and we get in touch with the support team to help us. This happens around once a month. 

What do I think about the scalability of the solution?

It is scalable. 

How are customer service and technical support?

I reach out to support when I have questions. I send emails with my questions. 

How was the initial setup?

The initial setup was not complex. It was easy.

What's my experience with pricing, setup cost, and licensing?

In terms of pricing, it is more expensive than other solutions. It's expensive because we also have the AFA module. 

Which other solutions did I evaluate?

AlgoSec is better than Skybox and Tufin. We have a lot of AlgoSec licenses. It offers the ability to do optimization and varied tasks.

AlgoSec offers diagrams about different pieces of equipment but Tufin and Skybox don't offer these features. I can also control external IPs. We can see the configuration. All equipment has configuration and AlgoSec enables us to log that traffic. We have control over the flow.

What other advice do I have?

I would rate it an eight out of ten. It's practical and easy to use. Many enterprises use it in France. Anytime we have questions, the support team is responsive.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Download our free AlgoSec Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2024
Buyer's Guide
Download our free AlgoSec Report and get advice and tips from experienced pros sharing their opinions.