I mainly use AlgoSec for policy change management and to intercept dangerous changes to firewall rules.
Programme Manager
It is used for change management and to intercept dangerous changes to firewall rules.
Pros and Cons
- "Multi-vendor feature in a multi-vendor environment is a must. Ensures changes adhere to internal and regulatory standards."
- "We don't dare push the new policy automatically, We don't have confidence in this feature."
What is our primary use case?
How has it helped my organization?
In the past, policy changes were applied, but not always with the correct approval. Because of this, we ended up with huge holes in the rule base.
What is most valuable?
Multi-vendor feature in a multi-vendor environment is a must. Ensures changes adhere to internal and regulatory standards.
What needs improvement?
Today, we don't dare push the new policy automatically, We don't have confidence in this feature.
Buyer's Guide
AlgoSec
June 2025

Learn what your peers think about AlgoSec. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
For how long have I used the solution?
One to three years.
Which solution did I use previously and why did I switch?
No.
Which other solutions did I evaluate?
Yes, Tufin.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Engineer
We can easily make our firewall flow change requests using the web interface
Pros and Cons
- "We can easily make our firewall flow change requests using the web interface."
- "It would be great if the product could be more simplified when defining the rules."
How has it helped my organization?
- Centrally manage firewall flow requests
- Approval/implementation and validation
- We can easily make our firewall flow change requests using the web interface.
What needs improvement?
It would be great if the product could be more simplified when defining the rules.
Documentation could be added to the tools, then generate documentation and send it to the relevant people.
For how long have I used the solution?
More than five years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
AlgoSec
June 2025

Learn what your peers think about AlgoSec. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
Networks and Security Engineer
Users utilize this tool to make their change requests
Pros and Cons
- "Users utilize this tool to make their change requests."
- "Automate the change documentation in MS Word format. Therefore, we can customize it, if needed."
What is our primary use case?
- Workflow: Users utilize this tool to make their change requests, then once it is approved by a security team assessment, the network team will implement the changes.
- Troubleshooting: Tracks the flow and sees where it is blocked.
What needs improvement?
Automate the change documentation in MS Word format. Therefore, we can customize it, if needed.
For how long have I used the solution?
More than five years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Expert Tehnique securité réseau at a pharma/biotech company with 10,001+ employees
When we add firewall change requests, it decreases the time for design and implementation significantly
Pros and Cons
- "It permits us to save a lot of time and make some firewall policy clean up. Then, when we add firewall change requests to management through this tool, it decreases the time for design and implementation significantly."
- "The Firewall Analyser feature is the most important and valuable part of this tool. This provides quick and simple visibility on the firewall's risk assessment."
- "Default standard support at Level 1 is to answer by upgrading to the latest released version, if you are not using it yet."
- "Improve the dashboarding capability for FireFlow which is currently very limited in terms of presentation and customisation."
What is our primary use case?
This solution was implemented to provide risk analyse, audit on rules, and changes, as well as giving visibility to the application or project manager on firewall rules that are linked to their servers for a massive datacenter migration.
How has it helped my organization?
For a massive migration, it permits project/application owners to estimate and anticipate changes which are needed autonomously and only involve the security administrator for implementation of the rules. This permits us to save a lot of time and make some firewall policy clean up. Then, when we add firewall change requests to management through this tool, it decreases the time for design and implementation significantly.
What is most valuable?
The Firewall Analyser feature is the most important and valuable part of this tool. This provides quick and simple visibility on the firewall's risk assessment in regards to compliance's referential that can be also customised to fit our organisation's requirements.
What needs improvement?
Improve the dashboarding capability for FireFlow which is currently very limited in terms of presentation and customisation.
For how long have I used the solution?
More than five years.
What do I think about the stability of the solution?
Not really. Sometime after the version upgrade, a few bugs appeared.
What do I think about the scalability of the solution?
Not yet.
How are customer service and technical support?
At the beginning, support was good.
Now as support is composed of several levels, default standard support at Level 1 is to answer by upgrading to the latest released version, if you are not using it yet.
Which solution did I use previously and why did I switch?
We did not have such a tool before installing AlgoSec for a firewall policy audit with reports. We had a homemade tool for change management.
How was the initial setup?
Find a good integrator.
What about the implementation team?
We went through a vendor team. His expertise was medium.
Which other solutions did I evaluate?
We evaluated differents solution when launching the project, like Tufin. This one was the most mature.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Extranet Architect with 1,001-5,000 employees
It has streamlined our process for access and firewall management
Pros and Cons
- "AFA provides project teams with a simplified way to obtain the status on their current rule set."
- "It has streamlined our process for access and firewall management."
- "Needs integration to cloud ITSM tools, such ServiceNow."
- "Be able to automatically analyze application traffic with machine learning capabilities and propose simplification for rule set optimization."
What is our primary use case?
We use AlgoSec FireFlow and AFA modules for risk analysis, audit, and change management to enforce appropriate security compliance.
How has it helped my organization?
It has streamlined our processes for access and firewall management. It is used by all the IT user community internally and by our service provider who is in charge of our IT run activities.
What is most valuable?
AFA and FireFlow modules are the one that we use.
- AFA provides project teams with a simplified way to obtain the status on their current rule set.
- Fireflow is used for our change management process and is linked to our CP FW.
What needs improvement?
Integration to cloud ITSM tools, such ServiceNow.
Be able to automatically analyze application traffic with machine learning capabilities and propose simplification for rule set optimization.
For how long have I used the solution?
Three to five years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Network Security Specialist at a tech vendor with 10,001+ employees
We now have baseline and rules checking.
Pros and Cons
- "We now have baseline and rules checking."
- "It would be nice if it was more variable when checking virtual domain baseline in the same way as Fortigate's firewalls do."
What is most valuable?
- Templates
- For baselines PCI-DSS
How has it helped my organization?
We now have baseline and rules checking.
What needs improvement?
It would be nice if it was more variable when checking virtual domain baseline in the same way as Fortigate's firewalls do.
For how long have I used the solution?
I've used it for one and a half years.
What was my experience with deployment of the solution?
We had issues with the clusters.
What do I think about the stability of the solution?
It's slow to synchronize a database that is not synchronized.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
It's good.
Technical Support:It's good.
Which solution did I use previously and why did I switch?
No previous solution was used.
How was the initial setup?
There were some issues when setting up the cluster and getting it to synchronize properly.
What about the implementation team?
I did it myself.
What other advice do I have?
You need to be able to script and have skills using Linux.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Technical Security at a tech services company with 501-1,000 employees
Traffic simulation queries identify all firewalls involved in the path between a source and a destination on a given service.
What is most valuable?
- Traffic simulation queries allow an engineer to simply find all firewalls involved in the path between a source and a destination on a given service. AlgoSec allows an engineer to issue their own traffic simulation query to be tested against a single device's policy, or against a group of devices. When running a traffic simulation query on a group, AFA finds the devices in the path of the traffic and queries all these devices. Querying the policy or a group of policies produces an AFA report that shows whether traffic of the given service is allowed between the source and destination. If traffic is blocked by the device, you can then find out which rules block it.
- The change history feature provides detailed information about changes to the device, over the entire history of AFA reports for the device. The information is divided into policy changes and risk profile changes.
- The optimize policy feature allows an engineer to find out which rules are redundant, unused or already covered by other, more general rules. We can find:
- Unused rules
- Covered rules
- Redundant special case rules
- Consolidate rules
- Disabled rules
- Time-inactive rules
- Rules without logging
- Rules with empty comments
- Duplicate objects
- Unused objects within rules
- VPN cleanup
- VPN analysis report
- Unused rules
- Unused objects within rules
How has it helped my organization?
We can optimize and produce reports for 744 firewalls from different vendors (Check Point, Juniper, FortiGate, and Cisco) with one application.
What needs improvement?
We have requested improvement to VRF functionality on Cisco IOS and Nexus L3 devices and to support Juniper routers.
We have discovered that AlgoSec doesn’t work with loopback interfaces. We use OSPF and BGP, which run over multiple Virtual Routing and Forwarding (VRF-Lite) instances and, in some cases, distributors are connected to the core via loopbacks routed by an OSPF instance and a BGP address family. AlgoSec doesn’t recognize those loopbacks as a route, so it doesn’t find a route to the destination. This behaviour makes the “traffic simulation query” feature unusable in our environment.
For how long have I used the solution?
3 years
What do I think about the stability of the solution?
I have not encountered any stability issues.
What do I think about the scalability of the solution?
I have not encountered any scalability issues at all.
How are customer service and technical support?
Customer Service:
7
Technical Support:The level of technical support is good.
Which solution did I use previously and why did I switch?
I did not previously use a different solution; we have been using this solution since 2012.
Which other solutions did I evaluate?
I don’t know if they evaluated other options before choosing this product.
What other advice do I have?
This product only supports L3 devices such as Cisco IOS and Cisco Nexus, so if your primary network is based on a different technology, AFA wouldn’t be the best choice.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Security Engineer at a financial services firm with 5,001-10,000 employees
The FireFlow feature stops users from overriding policies.
What is most valuable?
FireFlow, because you cannot override policies.
How has it helped my organization?
We have been able to add more vendors to support.
What needs improvement?
Validation: Many times I have to generate a report to validate tickets. When I try to verify an AlgoSec ticket that has been implemented, I have an option to validate the work I did. Many times, it has not worked immediately. I have to generate a report based on which I can check my work.
After implementation new rules on firewall algosec is not immediately aware about it. I have to make synchronization between algosec and firewall. In algosec is called analyze firewall. It is possible schedule this analyze more often but it consuming a lot of device resources like CPU, memory etc so I have this analyses one per day. After this analyze I am able make validation of implementation which I did because algosec can see rule which I added.
For how long have I used the solution?
I have been using it for five years.
How is customer service and technical support?
Technical support is quite OK.
AlgoSec provides different types and levels of support. I recommend asking about 24/7 support and being careful when deciding which support to buy.
How was the initial setup?
Initial setup was straightforward because we got support from vendor.
What about the implementation team?
If you are implementing it for the first time, it is good to ask vendor for help.
What other advice do I have?
It is a good product to use.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free AlgoSec Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Firewall Security ManagementPopular Comparisons
Tufin Orchestration Suite
Fortinet FortiGate Cloud
FireMon Security Manager
Skybox Security Suite
Palo Alto Networks Panorama
AWS Firewall Manager
Azure Firewall Manager
ManageEngine Firewall Analyzer
Fortinet FortiPortal
Cisco Security Cloud Control
Opinnate
Buyer's Guide
Download our free AlgoSec Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- From your experience, what are the technical differences between AlgoSec and FireMon?
- What Is The Biggest Difference Between AlgoSec and FireMon?
- What are the differences between Palo Alto Networks Panorama and AlgoSec?
- What is the biggest difference between AlgoSec and Tufin?
- What is your opinion on Fortinet FortiManager vs AlgoSec? Are they complementary?
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Comparing network security vendors and devices
- When should companies use SSL Inspection?
- When evaluating Firewall Security Management, what aspect do you think is the most important to look for?
- What are the most important features you would be looking for in a firewall?