What is our primary use case?
I think largely this is used by small and medium enterprises, and mid-market organizations is where I've actually seen them use this platform much more. It's used for secure internet gateway protection, remote office connectivity, and probably also for web content filtering, especially by the schools and enterprises.
Many of our customers have really benefited, especially in the small and medium businesses, schools and universities, and financial services as well. Typical benefits largely have been reduced malware infections, better visibility into user activity, very simplified firewall administration, reduction in network downtime, and easier compliance reporting.
What is most valuable?
I would first talk about the features then talk about what makes Arista Edge Threat Management NG Firewall very useful. It combines firewall and intrusion prevention system, web filtering, VPN, application control, bandwidth monitoring, and reporting. It's a very modular platform, easy to deploy, simple to manage, has fairly reasonable reporting, provides a strong value to the customers, and also it has good VPN capabilities, and in terms of deployment flexibility, it's very flexible.
SSL inspection, anti-phishing, DNS filtering, VPN, bandwidth control, and reporting are quite comprehensive.
Typically, we've seen a drop in the threats because they've been blocked, which contributes to cyber risk reduction. Firewall availability has been more than 99%, ensuring business continuity. We've seen a 30 to 50% reduction in manual firewall administration effort. There's an improvement in visibility across remote users and branch offices, web filtering, faster audit readiness, and it's been a lot from the perspective of mean time to detect and mean time to respond as well. We've seen quicker responses to threats and minimization of business impact.
Many of our clients have actually benefited from bandwidth optimization, and of course, regulatory compliance in terms of logging and reporting are also the other beneficial use cases.
What needs improvement?
Threat detection needs improvement; Arista Edge Threat Management NG Firewall should follow Alto and Fortinet. One limitation that I've seen is AI-driven automation which needs to vastly improve. It has fewer third-party integrations, and therefore the adoption amongst very large enterprises is less; it's largely with the SMBs.
Customer support can be improved. It's a smaller global footprint that Arista provides, with fewer certified partners in some regions and limited 24/7 support for premium vendors. I've categorically mentioned that it has sophisticated threat detection capabilities but they can be bettered. AI-driven automation can be improved, and therefore, I think the adoption with large enterprises can be much better.
I think the current AI capabilities of Arista Edge Threat Management NG Firewall are a bit limited compared to other vendors. It primarily relies on threat intelligence feeds, signature-based detection, and reputation services. Currently, I would rate its AI capabilities as probably a seven out of ten because it does not provide for extensive GenAI or advanced ML-driven autonomous capabilities like some of its competitors.
Threat intelligence aspects can be further improved, and I think there's a lot that the product can do with respect to the usage of AI. AI-driven automation and threat detection can vastly improve.
I don't think they were purchased through AWS Marketplace. The adoption has to increase amongst large customers, and threat intelligence needs to improve for many customers to adopt, enhancing the security ecosystem that is relatively small.
For how long have I used the solution?
I've been advising on Arista Edge Threat Management NG Firewall to my clients for over three years now.
What do I think about the stability of the solution?
I don't think we have seen any reliability issues. It is quite stable from that standpoint; I'm referring to the fact that there's a high availability. Overall stability would be a nine out of ten; it's quite reliable. Performance issues are not significant, and it provides fairly stable day-to-day firewall operations and reliable VPN connectivity. If there's anything regarding dependability, it is suited for small and mid-sized organizations as I was sharing earlier.
What do I think about the scalability of the solution?
There are no limitations; I think that's fairly okay.
How are customer service and support?
I would rate that as probably an eight out of ten, as I was sharing the fact that it's really good for small and medium enterprises. The response from the engineers is good, they have a strong documentation knowledge base, and the global support is where they lack a bit.
Which solution did I use previously and why did I switch?
We were not using any other solution, and I don't think any of our clients were using any next-generation firewall. It was basic firewall, Check Point firewalls that they were on, as I remember. I think they did not have a next-gen, AI-driven kind of a system, so it did not replace any other tool which is next-generation.
What was our ROI?
From the perspective of ROI, I can mention that it comes from multiple areas such as the reduction in annual security incidents, mean time to detect and mean time to respond, audit preparation time reduction, reduction in internet bandwidth misuse, and also with respect to firewall uptime and availability.
What's my experience with pricing, setup cost, and licensing?
That's one of the strong selling points. I would rate them nine or ten as far as pricing is concerned. Typically, their licensing works on the basis of appliances plus subscription-based, and there's annual licensing and multi-year subscriptions as well. Licensing is modular, allowing customers to pay only for the applications they need, and especially for non-profit organizations, education institutions, and government organizations, they offer discounted pricing.
Which other solutions did I evaluate?
I think there are other options available, but the pricing for those is a little higher. The others that were evaluated were Palo Alto and Fortinet.
What other advice do I have?
I would say that if you're a small and medium enterprise or an education institution and you have a distributed organization looking for a cost-effective and easy-to-manage next-generation firewall solution with fairly good security, VPN, filtering, and centralized management, then Arista Edge Threat Management NG Firewall is an excellent choice. This was pretty good; very comprehensive enough. I would rate this review an 8 out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other