Volkan Tastan - PeerSpot reviewer
Security Engineer at Infosec
Real User
Provides excellent visibility into security policies with robust reports and notifications
Pros and Cons
  • "The Firewall Analyzer component has excellent compatibility with the solution, and it's highly useful and easy to manage."
  • "More scope for editing alerts would be a welcome change."

What is our primary use case?

We work on the support side, and our customers use AlgoSec, primarily via on-prem deployments. They use the solution to analyze and engage firewall policies, increase their security, and receive advice for firewall optimization. 

The solution component we use is AlgoSec Firewall Analyzer. We have a customer who uses FireFlow, and we carried out a POC of AppViz, which some of our customers may want to implement in the next year.  

How has it helped my organization?

AlgoSec reduced the time it takes to implement firewall rules for our organization. 

The product helps us prepare for audits and ensure firewalls are in compliance; we can check the security and firewall rating points and advise our customers on optimizing their firewall and security rules. 

AlgoSec helped simplify the job of our security engineers, primarily through the advice it provides to admins managing the firewalls, which is essential. It also made them more efficient at their jobs.   

What is most valuable?

The Firewall Analyzer component has excellent compatibility with the solution, and it's highly useful and easy to manage.

Our customers find the Intelligent Policy Tuner very helpful, and it was useful for us during the POC because it was a significant selling point for our clients; they liked it and wanted to use it.

The solution provides excellent visibility into our network security policies, especially when we set the log options to ''extensive''; this gives us a lot of visibility for reports and change notifications. 

AlgoSec provides complete visibility into the risk involved in firewall change requests, which is especially important when presenting security reports to upper management.  

The solution's automation helped to reduce human error and misconfigurations; if the tool detects a drop in security and firewall policy points, it notifies admins via email of a potential misconfiguration, allowing us to fix the issue and raise the points again.  

What needs improvement?

More scope for editing alerts would be a welcome change. 

The solution has visibility and compatibility issues with Palo Alto firewalls, which makes it challenging to provide reports. The reports rely on logging, and the product has problems with Palo Alto's logging. Better compatibility with Palo Alto firewall reports is a must.

Some of our customers want to see AlgoSec with a user-based policy that can advise on user policy rules and be compatible with identity awareness.

Buyer's Guide
AlgoSec
April 2024
Learn what your peers think about AlgoSec. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,415 professionals have used our research since 2012.

For how long have I used the solution?

I've been using the solution for over eight years across two companies.

What do I think about the stability of the solution?

The stability is good; there's no problem with it. 

How are customer service and support?

The customer service is responsive and reliable enough, and most of our cases are solved within a day or two.

How would you rate customer service and support?

Positive

How was the initial setup?

The setup is very straightforward; we use VMs, so our customers don't need appliances. We can set up a VM and install AlgoSec in 15-30 minutes, then further configuration such as DNS, names, IP addresses, and adding the firewalls takes two to three hours.

The upgrade process is also straightforward; when the upgrade package is released, we download it, import it to a machine, and implement it with one SSH command. The solution doesn't require any further maintenance. 

What's my experience with pricing, setup cost, and licensing?

I'm not involved in the financial aspect, but I understand the platform to be expensive, though I need to find out how it compares to competitors like Tufin, for example.

What other advice do I have?

I rate the solution a nine out of ten. 

Some of our customers work with different security vendors, including FortiGate, Palo Alto, and Check Point, and integration with their firewalls is straightforward when using AlgoSec.  

We are also a supporter of Tufin in Turkey, and there are some advantages to using AlgoSec, as it's more useful in specific ways. With the latter, it's quick and easy to get reports, and AlgoSec has lower spec requirements for new installs. It requires a maximum of 16-32 GB of memory and 500 GB to one TB of storage, but Tufin requires 60 GB of memory and one to two TB of storage. AlgoSec is more straightforward and user-friendly; the options are named clearly, so it's easy to add identities or active directories.

The product is suitable for small, medium, and large businesses; they could all find a use for it. 

I recommend the solution; I've been using it for eight years, and it's more user-friendly and useful than other products.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner/Integrator
PeerSpot user
IT Security Manager at a retailer with 10,001+ employees
Real User
Impressive rule base analysis, compliance features, and report generation
Pros and Cons
    • "The process to replace a decommissioned device with a new device is not straightforward."

    What is our primary use case?

    We use this solution for rulebase analysis. AlgoSec provides great unified visibility into all policy packages in one place. Also, the compliance feature is quite useful. 

    It is great for checking rules/objects across numerous policies/domains, as well as generating advanced reports about risks, trends in recent changes, covered and unused rules, and if you want to go really deep in rule base optimisation - unused objects. This helps our team to keep network access up to date and secure. 


    How has it helped my organization?

    Growing big requires an increased level of automation and less manual tasks, and this is where AlgoSec comes into the picture.

    It has being used for CheckPoint environment with numerous domains, hundreds of Firewalls and numerous policy packages, and Algosec able to provide single point of review. Security risks reports and rules analysis are very handy to optimise company's security posture and operational excellence. 

    What is most valuable?

    The most valuable feature is the rule base optimization, which provides extremely valuable information about inactive rules, and rules that can be optimized or unified.

    In addition it is about tracking insecure changes and getting better visibility into network security environment - either on-prem, cloud or mixed.

    We are also going to implement full change management via Algosec as it allows to eliminate human error, ease on security governance and improve general ROI.

    What needs improvement?

    In my opinion, the user should be granted more flexibility to choose exactly which devices per CMA should be analyzed.

    The process to replace a decommissioned device with a new device is not straightforward.

    With the upgrade to CheckPoint R80.xx we have started to see some issues, although this version was already some time on the market, hence I was surprised that there was no full compatibility achieved. Nevertheless, working with support and professional services solved our problems.

    For how long have I used the solution?

    I have been using this solution for one to three years.

    What do I think about the stability of the solution?

    This solution is stable. There has been zero technical support interaction during last two years.

    How are customer service and technical support?

    Support is build in tier model so the case can be always escalated to more advanced level if needed

    Which solution did I use previously and why did I switch?

    We did not use another solution prior to this one. However, it was picked up after careful review and comparison with similar products.

    How was the initial setup?

    The setup was long in the past but recent upgrades were flawless and support engineers knowledgeable 

    What about the implementation team?

    Our company have close relationship with Algosec team and they are always showing great level of expertise along with the will to develop custom solutions in case of need

    What's my experience with pricing, setup cost, and licensing?

    The pricing for this solution seems to be reasonable for the functionality.

    Which other solutions did I evaluate?

    We have evaluated number of solutions which are available on the Market. In my opinion several of them were concentrating to much on security operations and SOAR while not having that much functionality related to managing rulebases. Solid firewall change management is something must to have as it is provide strong basis for security governance, improves company's posture and allow to reduce risks in rapidly growing companies associated with multiple changes which might be not properly assessed or implemented as a security exception.

    What other advice do I have?

    As my company uses basic package, I quite happy with the functionality.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Buyer's Guide
    AlgoSec
    April 2024
    Learn what your peers think about AlgoSec. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
    768,415 professionals have used our research since 2012.
    MarcelTe - PeerSpot reviewer
    IT Technical Consultant at Schneider Electric
    Real User
    Good support, optimized our security, and streamlined our process
    Pros and Cons
    • "This is something that increases business efficiency and helps avoid bottlenecks in our NOC team."
    • "To secure SaaS traffic there are a few vendors such as Palo Alto and Zscaler, but AlgoSec is not yet able to push rules onto these clouds."

    What is our primary use case?

    First and mostly, as a large company, we had some issues regarding the main rating companies as they found some issues compromising our assets. There are different management systems and models with human interaction and sometimes with a different validation. This was impacting our business, so we put a lot of effort into solving problems, case by case, with manual operations. AlgoSec came into action in order to avoid this and streamline our process.

    AlgoSec is one security management tool with the main target to find any rule that is not in compliance with our internal standards. New rules cannot be configured in any firewall unless it has been validated from security.

    How has it helped my organization?

    We were able to identify every rule configured on each firewall in our facilities with AlgoSec. This included every risky rule, shadow rule, and non-compliant rule. After this, we were working with a fully cleaned-up process.

    Now, any rule is pushed automatically with AlgoSec. In fact, every user in the company is raising tickets through it to request a new open flow across firewalls. If AlgoSec detects that this flow has no risk, it is automatically pushed onto the firewall. If not, it goes to a dedicated approval process.

    What is most valuable?

    Among all of the different AlgoSec modules, I think that FireFlow is the most valuable and we have integrated it into our internal processes. This is something that increases business efficiency and helps avoid bottlenecks in our NOC team. Moreover, we have eliminated any human mistakes that we have dealt with in the past and now we want to avoid as we are moving toward a completely automated network.

    What needs improvement?

    There are a few things that we have already raised to AlgoSec in order to improve the tool. First, as the highest volume in our network is SaaS traffic, we need to secure this connection. To secure SaaS traffic there are a few vendors such as Palo Alto and Zscaler, but AlgoSec is not yet able to push rules onto these clouds. It’s in the roadmap but this is something that blocks our whole design.

    The network map design is not very useful for the administrator as the information displayed is not user-friendly.

    For how long have I used the solution?

    It's been almost two and a half years since when we were looking for a fully integrated Security Management tool and we decided to run this solution in our multi-vendor network.

    What do I think about the stability of the solution?

    Stability is good, but we are still debugging tiny things because we have to accommodate the solution to our large IT infrastructure.

    What do I think about the scalability of the solution?

    It will be good as long as they can move this solution to hybrid or fully cloud deployments. 

    How are customer service and technical support?

    All issues raised so far have had a good response SLA.

    Which solution did I use previously and why did I switch?

    We didn't use any security managament tool prior to this one.

    How was the initial setup?

    This initial setup was tough because of the network map configuration. There is no visibility on the provider (ISP) because they cannot grant access to us. So, the configuration was mostly set up manually.

    What about the implementation team?

    AlgoSec was deployed with the support of professional services coming from the vendor. This made the implementation smooth for us. The expertise was good, as they had experience with this solution.

    Which other solutions did I evaluate?

    We were doing some workshops with both AlgoSec and Tufin. 

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    it_user837879 - PeerSpot reviewer
    Senior Security Analyst at The Hartford Financial Services Group, Inc.
    Real User
    We use it to assist in processing firewall changes, clean up unused rules and objects, and perform rule re-certifications.

    What is our primary use case?

    • We use the Firewall Analyzer extensively to manage our firewall security policies. 
    • We use it to assist in processing firewall changes, clean up unused rules and objects, and perform rule re-certifications.

    How has it helped my organization?

    We could not effectively manage our security policies before using the Firewall Analyzer tool. We had never performed a firewall cleanup. We could not meet our Audit Requirement of re-certifying without the Firewall analyzer tool.

    What is most valuable?

    Firewall Analyzer's policy optimization reports: They provide the data needed to perform all the activities mentioned above. 

    What needs improvement?

    We have had challenges with technical support as mentioned earlier. However, we have a new account team and they are very responsive and addressing our concerns. 

    For how long have I used the solution?

    More than five years.

    What do I think about the stability of the solution?

    We had a number of issues moving from 6.11 to 2107.1 but have found the latest code 2018.1 to be much more stable.

    What do I think about the scalability of the solution?

    No issues with scalability in our environment. We do not have a large number of managed devices as we only manage our 21 firewalls.

    How are customer service and technical support?

    We have had challenges with technical support as mentioned earlier. However, we have a new account team, and they are very responsive in attending to our concerns.

    Which solution did I use previously and why did I switch?

    No, we evaluated AlgoSec and Tufin, and we selected AlgoSec.

    How was the initial setup?

    The initial setup is very intuitive and not an issue for those with a good understanding of security, networks and the company's use of them.

    What about the implementation team?

    In-house and we should have employed the vendor/professional services for an engagement to assist in the FireFlow implementation.

    What was our ROI?

    This is a difficult question to answer quantitatively. I'd say it is a great story when determining ROI for the Analyzer. We could not meet audit requirements, including PCI, which had the potential for large fines going forward.

    The ROI for FireFlow is more of an incomplete story, and much of the issue is the way in which we implemented it.

    What's my experience with pricing, setup cost, and licensing?

    We also purchased AlgoSec's FireFlow tool. We have had challenges getting value from it, and it is because the scope of this tool is very broad compared to Analyzer. In hindsight, we should have created a formal project and management backing to ensure success with this tool. 

    The scope of a Fireflow implementation touches many organizations and we did not have an appreciation of the need for involvement of so many.

    Which other solutions did I evaluate?

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    PeerSpot user
    Resp. Area de Segurança at REN
    Real User
    AlgoBot checks if rules already exist or finds out easily where they need to be configured
    Pros and Cons
    • "AlgoBot is a brilliantly, simple idea that lets us give our IT internal customers a way to check if rules are already in place before asking for more."
    • "The license rekeying needed for when you need to change a firewall usually takes a bit of time."

    What is our primary use case?

    Our main use cases for this solution are:

    • Firewall Rule optimization
    • Topology mapping of various firewalls
    • Automating the implementation of rules.
    • Reports warning before time based rules expire. 

    We also implemented the AlgoBot, which is extremely useful when checking if rules already exist or finding out easily where they need to be configured.

    We have 20-plus firewalls from multi-vendors in several sites, both IT and OT. Therefore, an automated way to manage firewalls is a must, especially since staff is always on the short side.

    How has it helped my organization?

    AlgoSec has saved us a lot of time in managing our rule base which has become increasingly large. With 20-plus multi-vendor firewalls, it gets really hard to manage without a solution like AlgoSec. This has helped us to fulfill our internal SLAs for change implementation.  

    The fine tuning of the policies is a lot faster and repeatable. 

    The compliance factor has also helped us a lot where we can show auditing that we have a repository for all the changes made in the firewalls, who made them, and at what time.

    Gone are the days where time-based rules expire without anyone noticing. We have now automated reports sent to the team. This allows us to ask the involved asset owners if rules can be disabled or need to be extended.

    What is most valuable?

    Most valuable features are the firewall rule optimization, topology mapping, and automating the deployment of new rules in several multi-vendor devices. 

    AlgoBot is a brilliantly, simple idea that lets us give our IT internal customers a way to check if rules are already in place before asking for more.

    With firewall rule optimization, you cannot only tune most used rules higher in the rule base, but also check for unused objects or rules to clean up.

    The automatic implementation of rules in several firewalls simultaneously is also a great feature, especially in large environments or on short staffed teams. 

    What needs improvement?

    AlgoBot should be more developed by adding more features to the chat.

    We will be integrating with Cisco ACI soon. Hopefully, new features with this integration will be developed as well in terms of automation.

    I came across a difficulty recently with a BGP enabled firewall that had a large number of routes. This wasn't directly supported due to a 3000 rule per firewall limit.

    For how long have I used the solution?

    We've been using AlgoSec for over six years.

    What do I think about the stability of the solution?

    It has been running flawlessly since installation. Even upgrades are pretty straightforward and have never given us problems.

    What do I think about the scalability of the solution?

    We have added 10 more firewalls to our 14 existing and have had no performance or scalability issues.

    How are customer service and technical support?

    We have had several tickets opened and the responses were fast. This enabled us to solve our problems quickly. The only complaint is about the license rekeying needed for when you need to change a firewall. That usually takes a bit of time.

    Which solution did I use previously and why did I switch?

    We did use a different solution for several years. The features and usability made us switch.

    How was the initial setup?

    If you are knowledgeable about the firewalls that you intend to manage, the initial setup is really easy. The most difficult steps are configuring checkpoints for LEA integration where you need to create the object in each firewall, establish connectivity, install the database, install the policy, etc.

    What about the implementation team?

    It was initially implemented through a vendor. Their level of expertise was good enough to implement the solution effortlessly.

    What's my experience with pricing, setup cost, and licensing?

    Cost is based on firewall. There are bundles, e.g., virtual firewalls might make the solution cheaper.

    The licensing scheme should be done in a simpler way. For example, if we delete a firewall and want to add a new one, then the license doesn't get freed up automatically. You have to request a new license to customer support and install it. If you are testing new implementations, this can be cumbersome.

    Which other solutions did I evaluate?

    We evaluated the main competitor, Tufin, because we were using it!

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    reviewer1335075 - PeerSpot reviewer
    Network Security Engineer at Chubb
    Real User
    Risky rules reports help to reduce manual work
    Pros and Cons
    • "We need less time to identify any risks in our firewalls, as we can detect changes in real-time."
    • "A vulnerability management module might be interesting, though not integrated with a third-party vendor. It should be an AlgoSec VM module."

    How has it helped my organization?

    We need less time to identify any risks in our firewalls, as we can detect changes in real-time.

    We have obtained in easy way to do compliance reports for audit purposes. With this optimization reports, we can clean up unused rules, consolidate covered or redundant rules. We can also define trusted rules that apply.

    Risky rules reports help to reduce manual work and identify the main risky configurations to remove. This give us some recommendations on how remediate and their importance.

    What is most valuable?

    • Identifying and removing risky rules
    • Firewall rules cleanup (unused rules)
    • Security compliance reports
    • Security baseline settings

    What needs improvement?

    A vulnerability management module might be interesting, though not integrated with a third-party vendor. It should be an AlgoSec VM module.

    I would like some server integration for vulnerability management.  

    Some PDF reports are not so good. E.g., the graphics and reports are not so good. Sometimes, we need to create graphics and reports to compare security ratings across months and groups. 

    For how long have I used the solution?

    I have been using AlgoSec for two years. 

    What do I think about the stability of the solution?

    Awesome.

    What do I think about the scalability of the solution?

    Great.

    How are customer service and technical support?

    Excellent and very kind technical support.

    Which solution did I use previously and why did I switch?

    No.

    What's my experience with pricing, setup cost, and licensing?

    Licensing is very easy to set up. The pricing is relative to how you want to expand and harden your network security. 

    Which other solutions did I evaluate?

    I did not evaluate another solution.

    What other advice do I have?

    It is a great tool that makes work easier each day. I can't imagine working without AlgoSec and using it for my daily activities. 

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    PeerSpot user
    Network Security Engineer at Türkiye İş Bankası
    Real User
    Optimizes firewall policies and facilitates compliance auditing
    Pros and Cons
    • "The most valuable feature is the reporting, including the policy report and regulatory compliance reports."
    • "Cisco Firepower device support is limited in our AlgoSec system and I think AlgoSec can improve in that area."

    What is our primary use case?

    We primarily use the AlgoSec Firewall Analyzer.

    We have more than ten cluster firewalls and we have deployed the AlgoSec solution suite. We want to check compliance status of our devices. We also need to reduce the number of rules in each of the policies.

    In our new data center, we want to automate the firewall policies.

    How has it helped my organization?

    Now, we can easily track the changes in policies. With every change, AlgoSec automatically sends an email to the IT audit team. It increases our visibility of changes in every policy. 

    Every month, I use the optimizer to reduce firewall rules. In the summary tab, I can easily track the number of changes in the firewall policies.

    What is most valuable?

    The most valuable feature is the reporting, including the policy report and regulatory compliance reports.

    In the Intelligent Policy Tuner, the tighten permissive rules tab allows us to reduce the number of rules in each policy. I can easily control, report, and reduce the rules for policies. Also in the Rules Cleanup tab, I am removing unused rules as I feel confident in deleting these types of rules.

    Our Information team read Regulatory Compliance Reports that can easily track the compliance status of each device.

    What needs improvement?

    Cisco Firepower device support is limited in our AlgoSec system and I think AlgoSec can improve in that area. For example, in FireFlow we can easily track using the ticketing system to integrated Check Point devices. However, with Cisco Firepower devices, we couldn't integrate with them.

    For how long have I used the solution?

    We have been using AlgoSec for almost six years.

    Which solution did I use previously and why did I switch?

    We did not use another solution prior to this one.

    What's my experience with pricing, setup cost, and licensing?

    The pricing of AlgoSec is fair.

    Which other solutions did I evaluate?

    Before purchasing AlgoSec, we implemented a PoC with each of AlgoSec, Tufin, and FireMon.

    What other advice do I have?

    We have more than ten clusters behind our firewall. It is essential that we track the changes in policies and the compliance status of devices. AlgoSec can easily do that.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Sunil Kumar.  - PeerSpot reviewer
    Works at Maple Leaf Foods
    Real User
    Significantly improved our firewall security optimization
    Pros and Cons
    • "The Firewall Analyzer helps us achieve our various IT compliance requirements, like ISO-27001."
    • "There is huge scope for improvement in the level of support, especially around the issue of resolution time. That is the only negative point I find in the solution."

    What is our primary use case?

    We are using AlogSec mainly for firewall compliance reporting as well analyzing and evaluating firewall policy. That, in turn, means we can actively work on firewall policy optimization and elimination of unused and risky rules. We also using it for compliance reporting. 

    How has it helped my organization?

    The solution has helped us a lot in improving our firewall security optimization as well in evaluating security policy to eliminate the risky rules or secure them. 

    Its reporting modules solve all our monthly and quarterly compliance-related reporting requirements. 

    What is most valuable?

    Currently, we are using almost all the features of the product to take as much advantage as we can of what it offers. But our primary use is compliance reporting and the Firewall Analyzer helps us achieve our various IT compliance requirements, like ISO-27001.

    What needs improvement?

    There is huge scope for improvement in the level of support, especially around the issue of resolution time. That is the only negative point I find in the solution. I hope you guys will work on it and improve your resolution time which will help customers to keep their AlgoSec device healthy.

    For how long have I used the solution?

    We have been using AlgoSec for six years.

    What do I think about the stability of the solution?

    In the six years we have been using it, we have never seen an outage or failure of AlgoSec or any other software-related failure. 

    What do I think about the scalability of the solution?

    The product is very scalable. We have never faced any issues related to the scalability of the product. 

    How are customer service and technical support?

    As an individual, my experience has been good, but in terms of technical-issue resolution, I am not 100 percent satisfied because of time the AlgoSec team takes to fix issues, some of the time.

    Which solution did I use previously and why did I switch?

    Previously, we were using Tufin but we found that solution more complicated when compared with AlgoSec. 

    How was the initial setup?

    The initial setup was straightforward because of the well-defined GUI platform.

    What about the implementation team?

    We implemented it in-house.

    What was our ROI?

    Given that we have been using this product for the last six years, there is no question about ROI. If we were not seeing ROI, per our expectations, we would not continue with the product. 

    What's my experience with pricing, setup cost, and licensing?

    AlgoSec is not much more expensive compared to other products available in the market.

    Which other solutions did I evaluate?

    We evaluated FireMon but it was more complicated than AlgoSec and did not fulfill our basic requirements. 

    What other advice do I have?

    Overall, AlgoSec is doing a good job.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Buyer's Guide
    Download our free AlgoSec Report and get advice and tips from experienced pros sharing their opinions.
    Updated: April 2024
    Buyer's Guide
    Download our free AlgoSec Report and get advice and tips from experienced pros sharing their opinions.