Firewall analyzer and traffic simulation based on configuration analyzer of all rules on the firewall. Implementation of new rules without the need for manual configuration of rules on all firewalls in the traffic path.
Network Engineer at a comms service provider with 1,001-5,000 employees
Implementation of new rules without the need for manual configuration of rules on all firewalls in the traffic path has been good for us.
What is most valuable?
How has it helped my organization?
It helped to improve our automation and simplified the configuration of new access rules.
What needs improvement?
In our experience, AlgoSec need to improve the integration of firewall vendors, because at the moment they don't support all vendors that are out there.
Algosec Firewall Analyzer has a feature called 'Implement on device' which automatically creates access rules based on your request and sends it to the appropriate device. At the moment, this feature can not be implemented on Fortigate firewalls or Juniper EX switches which act as a layer three device with ACL's etc. I mean they need to improve interoperability with more vendors in order to automate access rules modification on these unsupported yet equipment.
For how long have I used the solution?
I've used this solution for approximately five months.
Buyer's Guide
AlgoSec
June 2025

Learn what your peers think about AlgoSec. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
What was my experience with deployment of the solution?
According to my colleagues who implemented it, there were some problems during the implementation. They contacted their support team who provided us with good support and we were able to get it implemented.
What do I think about the stability of the solution?
We had no issues with the performance.
What do I think about the scalability of the solution?
It's been able to scale for our needs.
How was the initial setup?
I wasn't involved in the original implementation.
What other advice do I have?
It's an amazing product for those admins who have huge variety of firewall vendors and would like to be able to automate the implementation of new firewall rules for access across the network.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Sr. IT Security Engineer at a pharma/biotech company with 10,001+ employees
We use it to clean up unused objects. The risk team uses it to validate existing traffic flow.
Valuable Features
- Firewall rule monitoring
- Consolidated report on unused objects and rules
Improvements to My Organization
We use this tool for rule monitoring and cleaning up the unused objects to improve performance. The risk team uses this tool to validate the existing traffic flow for their approval.
Room for Improvement
It is currently unable to export the report to a CSV file, and I look forward to seeing it in the next version/release.
Use of Solution
I have used it for more than four years.
Deployment Issues
Deployment was very easy; the vendor-provided documentation was good.
Customer Service and Technical Support
Technical support is 8/10.
Implementation Team
I was able to implement it on my own.
Other Advice
It's a very useful product and I highly recommend everyone having this product in place on their security infrastructure.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
AlgoSec
June 2025

Learn what your peers think about AlgoSec. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
Network Security Engineer at a aerospace/defense firm with 1,001-5,000 employees
It provides policy optimization reports, is easy to install on your own, and runs smoothly.
Valuable Features
The reports for the policy optimization are the product’s most valuable feature.
Improvements to My Organization
It provides better performance on our firewalls.
Room for Improvement
- Filtering in the reports
- Adjusting parameters for reports
- To be able to generate custom-made reports
For example, it would be nice if you could define a report to show the unused objects for a specific timeframe. Now, it’s for the whole log period. Or, another example would be: deny rules that have been adjusted in the last 90 days.
Use of Solution
I have used it for about two years.
Stability Issues
I have not encounter any deployment, stability or scalability issues. It runs very smoothly.
Customer Service and Technical Support
Technical support is very good, providing fast responses and good knowledge of their product.
Initial Setup
Initial setup is very straightforward and it is easy to implement.
Implementation Team
We did it in-house, as it’s easy to install on your own.
Other Advice
Just try it and you’ll see where the problems are in your firewall. You can easily request trial licenses.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security and Network Architect at a tech services company with 10,001+ employees
For FireFlow, workflow customization and active change are the best features. Interaction with a lot of vendors results in a lot of options and bugs.
What is most valuable?
With a network like ours - more than 100 routing points with around 6 VRF on each - traffic simulation query is one of the most valuable feature on AFA.
For FireFlow, workflow customization and active change are the best features.
In BusinessFlow, the ability to simulate documented flow against configuration by AFA is the best feature to limit differences between documentation and production.
How has it helped my organization?
This product allowed us to identify unused rules more easily and doing this simplifies policies in our firewall. We now have documentation of our application with objects sync with real configuration. Our approval in change management has been improve through FireFlow and errors have been reduced through change advised and active change. We also save time by identifying earlier than usual routing issues associated to a change request.
What needs improvement?
A lot of areas have room for improvement!! This product is still young and in constant development. Interaction with a lot of vendors generates a lot of firewall options (specifically, a timer on services, application control, and so on...). This interaction also generates a lot of bugs in the product. Every new version contains about 10 to 20 bugs for our environment. This is partially explained by the fact it has to understand all of the architecture and specificity associated with all of the supported vendors.
A few of the bugs are:
- Services composed with something else other than TCP or UDP are not well-handled and not working in simulation queries. (For example, AH or ESP or EthernetOverIP.)
- Traffic with same objects in source and destination are not working.
- When NAS is used to store reports, we have had a lot of bugs associated with wrong URL encoding.
- Role assignment with multiple LDAP issues.
- Some file cleanup not working as expected.
- Active change is available for only a few vendors.
- BusinessFlow doesn't offer auditing regarding object management and with a lot of application and managers, it quickly becomes an issue with duplicated objects and so on.
- There are also gaps in access right management.
For how long have I used the solution?
I have been using it nearly two years.
What do I think about the stability of the solution?
Every version came with its bug bundle... In two years, we opened 50 cases and about 40 of them escalated to development for resolution. This situation is also explained by complexity of our architecture.
What do I think about the scalability of the solution?
I have not encountered any scalability issues. Each version usually improves performance and the amount of required disk space.
How are customer service and technical support?
Technical support is 7/10; quick to give a new version solving the issue but long to identify the issue, even when it seems to be identified from the beginning.
For example, more than a month ago, we identified a wrong link associated to NAS configuration. We can clearly see that the wrong link was being generated, pointing from the NAS directly to the NAS repository, instead of a symlink. It took more than a month for support to accept this and to escalate the case to dev. After dev escalation, we are expecting a fix on Monday. So, it took four weeks to acknowledge the issue and two weeks to be fixed by development.
Which solution did I use previously and why did I switch?
We did not previously use a different solution.
How was the initial setup?
Initial setup is straightforward; some custom options can be tricky to set up, but will not be used by most customers.
What's my experience with pricing, setup cost, and licensing?
Be careful with VRFs. One router with two VRFs consumes two licenses. So a new VRF configured on all routers will double the number of licenses required on routing elements.
Which other solutions did I evaluate?
We benchmarked Tufin before choosing AlgoSec. We chose AlgoSec over Tufin for its capacity to be more customized and its support for MPLS and VRF.
What other advice do I have?
Offer me a job. ;) I will help you set it up.
More seriously, test it with caution through a POC to be sure that all your architecture specifics are addressed. If not all of them are addressed, ask for a commitment regarding support of missing features and ask for those commitments to be written down before ordering.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior IT Security Consultant at a tech services company with 501-1,000 employees
Valuable features include FireFlow, traffic simulation and the network map.
Valuable Features:
* Network map - to see how firewalls and routers are connected.
* Traffic simulation - to emulate traffic through the rule-base and see if you need to open additional ports/services.
* FireFlow - to order new firewall openings.
Improvements to My Organization:
* Less overhead on the network security department since the user can verify the rules themselves.
* Risk profiles helps find disallowed traffic.
* Policy cleanup feature is really good for removing unused rules, etc.
Room for Improvement:
* More unified UI
Use of Solution:
Since 2013
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Information Security Manager at a financial services firm with 10,001+ employees
You can observe risk trends, regulatory and baseline compliance, as well as live changes and change history.
What is most valuable?
AlgoSec AFA provides visibility and enhancement opportunities on the firewalls. You can observe risk trends, regulatory and baseline compliance, as well as live changes and change history.
How has it helped my organization?
AlgoSec improved our firewall visibility and related control points.
What needs improvement?
Needs continuous improvements in all areas since firewall vendors are improving their products and the IT security industry is definitely improving itself.
For how long have I used the solution?
3 years
What was my experience with deployment of the solution?
Deployment is easy, no issues at all.
What do I think about the scalability of the solution?
No issues so far.
How are customer service and technical support?
Customer Service:
8/10
Technical Support:8/10
Which solution did I use previously and why did I switch?
No previous solution
How was the initial setup?
Initial setup and deployment was straightforward.
What about the implementation team?
We got help from a partner, 8/10
Which other solutions did I evaluate?
We evaluated two other vendors in addition to AlgoSec.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Architect at a healthcare company with 1,001-5,000 employees
We like the ability to review and understand your firewall topology, run reports and have the ability for practitioners and auditors to review our security posture.
Valuable Features
The firewall analyzer allows for a quick and consistent method of reviewing your firewalls ruleset for security, compliance, and peace of mind. The ability to review and understand your firewall topology, run reports and have the ability for practitioners and auditors to review our security posture, gives us a sense of calm within this area of security.
Improvements to My Organization
Adding AlgoSec as a process into our network, compliance, security, and audit teams allowed for quick turnaround on any issues that arise regarding security rulesets. We often find these issues before they are pointed out to us, which leads to a quicker turnaround from compliance, but more importantly from a security mindset. This tool is used as part of the M&A process to analyze any new companies looking to incorporate our network. It's become one of the indispensable products we can't live without.
Room for Improvement
I would say cloud is an area for improvement, but AlgoSec in is that market now, too. I do want to see, however, the ability to set up an instance within the cloud instead of having to use physical appliances.
Deployment Issues
I've had no issues with deployment.
Stability Issues
It's been stable for me.
Scalability Issues
It's able to hit all the devices that I've put it up against and it was able to find rules that put our organization at risk.
Customer Service and Technical Support
The technical support is standard. They do a good job and understand the product.
Other Advice
It's head and shoulders above all the competitors in the field. They're the ones pushing the boundaries of the market.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Freelance System Security Consultant at a consultancy
It can really optimise configuring firewall policy rules.
What is most valuable?
- It can identify the policy rules in the firewall that have a high risk and could have an impact on network infrastructure.
- It suggests solutions to these issues, and provide compliance reports by standardizing PCI-DSS, ISO 27001, SOX and more.
- It can monitor policy changes, and who made those changes.
- It generates a topology of the network when it has scanned the network.
- Using the network mapping, it identifies bottlenecks.
How has it helped my organization?
We have improved the performance of the firewall to handle requests and responses to/from clients as reduces the number of policies that are needed when the network is exposed to high risk.
What needs improvement?
They need to improve auditing of IP tables, as only monitoring them does not reduce their vulnerabilities.
For how long have I used the solution?
I used it for nine to ten months.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
It is quite stable for 24-hour network monitoring.
What do I think about the scalability of the solution?
There is no problem in the process of scanning and monitoring firewalls, and IP tables in
considerable quantities.
How are customer service and technical support?
Customer Service:
8/10 as they were quite fast in responding to my issues.
Technical Support:10/10 as the technical support provide assistance if there is a problem via both email and telephone.
Which solution did I use previously and why did I switch?
I have not used a different solution previously.
How was the initial setup?
The initial set up is a bit complicated, because you have to open special ports in the firewall, and give open access to be able to read the configuration topology mapping in the firewall. This means that the process of scanning and monitoring AlgoSec can run smoothly.
Unlike the case with the initial setup for monitoring IP tables, you must use the root access serve (sudo su) so that the process of scanning and monitoring AFA could run smoothly.
What about the implementation team?
We implemented this in-house.
What was our ROI?
The advantage is that it can really optimise configuring firewall policy rules, and can
reduce the configuration that is vulnerable. It can provide solutions to make policy rules more simple and efficient.
What's my experience with pricing, setup cost, and licensing?
If you want to conduct an audit of firewall and want to optimize the configuration, you can try and use AlgoSec.
Which other solutions did I evaluate?
I didn't evaluate other options.
What other advice do I have?
Be patient and careful when doing the initial configuration of the firewall with AFA, but after the process is completed, everything has to run smoothly.
An example screenshot of network mapping results from AFA. Network mapping can
be useful also to detect if there is a connection network traffic is interrupted and can assist in documenting the topology that is owned.
The following screenshot shows an example of the policy rules that need to optimized, so you can improve the performance of firewall and its security level.
The following screenshot shows the result of scanning AFA reports that compliance with ISO 27001.
Disclosure: My company has a business relationship with this vendor other than being a customer: AlgoSec’s partner in Indonesia.
clearly explanation with real study case, this tools helpfull for infrastucture and security audit, beside that can be tool reporting and documentation infrastructure network.

Buyer's Guide
Download our free AlgoSec Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Firewall Security ManagementPopular Comparisons
Tufin Orchestration Suite
Fortinet FortiGate Cloud
FireMon Security Manager
Skybox Security Suite
Palo Alto Networks Panorama
AWS Firewall Manager
Azure Firewall Manager
ManageEngine Firewall Analyzer
Fortinet FortiPortal
Cisco Security Cloud Control
Opinnate
Buyer's Guide
Download our free AlgoSec Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- From your experience, what are the technical differences between AlgoSec and FireMon?
- What Is The Biggest Difference Between AlgoSec and FireMon?
- What are the differences between Palo Alto Networks Panorama and AlgoSec?
- What is the biggest difference between AlgoSec and Tufin?
- What is your opinion on Fortinet FortiManager vs AlgoSec? Are they complementary?
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Comparing network security vendors and devices
- When should companies use SSL Inspection?
- When evaluating Firewall Security Management, what aspect do you think is the most important to look for?
- What are the most important features you would be looking for in a firewall?
If the product allowed you to generate those reports, how do you expect it would improve your workflow?