What is our primary use case?
I use AlgoSec for policy optimization, basic rule review, and network automation through FireFlow, as we implement policies on the firewall using AlgoSec and utilize risk profile and baseline compliance to meet the standards required for compliance in our market.
After onboarding the firewalls, we analyze the devices, monitoring, log collection, and analysis to ensure everything is working correctly. Once verified, we receive analysis reports that display multiple insights including unused rules from the last 90 or 180 days. Any rule not receiving traffic is considered an unused rule. The reports also identify redundant and special case rules, and show which rules have logging disabled. AlgoSec includes a special feature called Intelligent Policy Tuner (IPT), which provides suggestions for wider subnets to break down rules. The policy automation report displays risky rules where risk has been triggered.
We have implemented multiple automations in AlgoSec. We integrated AlgoSec FireFlow module with ServiceNow, where a user raises a request that triggers an API call between ServiceNow and AlgoSec. Once a manager approves the request, AlgoSec raises a ticket and checks the source and destination services to implement the policy on the relevant firewall.
What is most valuable?
The best feature in AlgoSec is in Firewall Analyzer, specifically IPT, which provides suggestions to break down rules, along with the baseline compliance feature that advises on modifications per market standards.
In IPT, on firewalls, there are multiple rules with wider subnets open, like 192.168.0.0/24. AlgoSec analyzes the traffic based on firewall logs to provide suggestions, such as dividing that subnet and suggesting traffic use cases from specific addresses.
The policy optimization reports from AlgoSec give a detailed overview of firewall rules, allowing us to monitor them effectively. AlgoSec provides change and audit reports on firewall rules, which we check whenever required. By using FireFlow, it significantly reduces the time needed to implement firewall policies and eliminates human errors during automation.
Multiple features in AlgoSec assist with automation, saving time in implementing firewall policies and reducing human errors through the API call between ServiceNow and AlgoSec.
What needs improvement?
For baseline compliance, modifying any standard profile according to our organization's needs requires adding customization. It would be beneficial to have training sessions on how to add custom risk profiles and baseline compliance profiles.
With 10 to 20 firewalls from Check Point, we need a single dashboard to verify firewall versions or vulnerabilities, functioning as a CISO dashboard for tracking purposes and allowing direct access to check current firewall versions and vulnerabilities.
TAC support takes too much time. When raising any request for technical support, the response is slow despite their efforts to help according to their standards.
For how long have I used the solution?
I have been using AlgoSec for 2.5 years.
What do I think about the stability of the solution?
AlgoSec is stable.
What do I think about the scalability of the solution?
AlgoSec is scalable for our organization.
How are customer service and support?
TAC support takes too much time. When raising any request for technical support, the response is slow despite their efforts to help according to their standards.
Which solution did I use previously and why did I switch?
I have used multiple solutions, including AlgoSec and competitors FireMon and Tufin, but AlgoSec stands out as really user-friendly and easy for any security engineer to handle.
How was the initial setup?
AlgoSec is really helpful. The tool is user-friendly and can be handled by anyone, as the GUI interface is very good.
What about the implementation team?
We are a partner of AlgoSec.
What was our ROI?
I do not know about the return on investment because we have used AlgoSec for more than four to five years and found it very helpful from a user-friendly perspective as network security operations, but I am not privy to the financial aspects.
What's my experience with pricing, setup cost, and licensing?
The pricing, setup cost, and licensing are managed by higher management, so we are not involved in that part.
Which other solutions did I evaluate?
We chose AlgoSec for the first time; however, some colleagues shared their experiences with competitors Tufin and FireMon, but we did not have a good experience with them during the POC. We have not evaluated too many options before choosing AlgoSec.
What other advice do I have?
TAC support takes too much time. When raising any request for technical support, the response is slow despite their efforts to help according to their standards.
AlgoSec is really helpful. The tool is user-friendly and can be handled by anyone, as the GUI interface is very good. I would rate this review 9 out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner