What is our primary use case?
What I appreciate is that centralized management is obtained from SmartConsole with MDS, which seems very positive to me, as that is the strongest point. With that, you can have threat prevention with the blades, IPS, Anti-Bot, and Anti-Virus. I think it is very well integrated, and also for ClusterXL for high availability, it works very well; it is very reliable.
The primary impact we have had is the ability to manage security policies in a centralized manner for multiple customers from a single platform, because this significantly reduces operational time when performing, for example, rule changes or policy updates. What is more important is the availability from ClusterXL, which allows you to have production environments without service interruptions—that is, business continuity. Additionally, the threat prevention capabilities, and what I like most is that they have added a robust protection layer without the need for third-party solutions; everything is very well contained there. I estimate a reduction of between 30% and 40% in management time compared to solutions without multi-domain centralized management.
What is most valuable?
I use it in multitenant environments with an MDS architecture, the Multi-Domain Management, to manage security policies in a centralized manner for different organizations at the same time.
As I mentioned in the previous section, what I think are the best features it has is centralized management from SmartConsole with MDS. I think that is the strongest point it has, because you can have threat prevention with the blades, as I mentioned, IPS, Anti-Bot, and Anti-Virus, which are very well integrated. The ClusterXL function for high availability works very well. As I said, it is very reliable, very intuitive, and I think it is a very good tool.
What seems very good to me, as I mentioned, is the integration it has for threat prevention with the IPS, Anti-Bot, and Anti-Virus blades. That seems to be its best integration. It is very intuitive—significantly, even if you come from other firewalls, this is very intuitive; you can manage it without any problem. You do not have to learn absolutely everything from scratch. I think this part is very well integrated.
What needs improvement?
What I would like, what I think they should improve a little is the management of objects at large scale. When you work with multiple domains, there are thousands of network objects. Detecting duplicates and consistency across domains is a very manual process that should be more automated. Another thing: the SmartConsole interface is very powerful and very good, but the learning curve, compared to other solutions in the market from other manufacturers, could be modernized. I think it does not necessarily have to be done from a client application; it could be done via web, because via web I know that not all the options you have in SmartConsole are available. So it would be good if it could also be done from the web and all the options were available. Another thing that I would really like is more automation with Ansible or Terraform. I know it has improved in recent versions, but I think it is still not mature enough. Compared to other manufacturers that do have a bit more in terms of automation capabilities in integration flows with Ansible or Terraform, Check Point Cloud Firewall (formerly CloudGuard Network Security) could improve. Another thing that could be improved a little would be the TAC response time, because when there are very complex cases, I think there should be more speed initially, more ownership of those urgent cases, and not leave the customer waiting. This has happened to me: when I have cases open with Check Point Cloud Firewall (formerly CloudGuard Network Security) TAC, sometimes they do not respond and I have to keep insisting, and I think that part should improve. I do not know if it depends on who takes the ticket or on the severity of the ticket, but sometimes I have had to insist a lot, and that would be the only problem. Once they attend to me and become involved in the case, the responses they give are very professional and really help directly resolve the problems when there is a bug or troubleshooting to do.
As I said, I would like to see a specific improvement in SmartConsole. I think if they improved it—how to say it—gave it a facelift so you could access all the options directly from a browser, that would be great, because sometimes, for one reason or another, you cannot download SmartConsole or, for some reason, the SmartConsole client does not start correctly, and you could do it directly from the browser. I think that would be a good option to improve. Another thing would be that in multidomain environments, I would like a global search function for objects and rules. That is, you could enter and search across all domains at once, because right now you have to go domain by domain, and in environments with many customers, you spend quite a bit of time; you have to exit one domain and enter another. So those would be the improvements I would like to see.
For how long have I used the solution?
I have been working for approximately fifteen years since I began in the world of networking and cybersecurity.
What do I think about the stability of the solution?
I think it is a stable platform, and that is precisely one of Check Point Cloud Firewall (formerly CloudGuard Network Security)'s strengths. What I have seen is that when there is a bug that may limit functionality or a bug that affects Check Point Cloud Firewall (formerly CloudGuard Network Security) directly, I see it directly from the Check Point Cloud Firewall (formerly CloudGuard Network Security) interface—from SmartConsole or from Gaia—when you log in, it automatically shows you what bug appears and what the solution is. I think that is a great feature: the firewall itself, Gaia itself, tells you: "Look, there is this error, this problem; verify if your device is affected; if so, here is the solution." So I think it is very stable in that respect.
What do I think about the scalability of the solution?
I think scalability is one of its strong points, especially in enterprise environments with growth. The horizontal scalability of the MDS architecture allows you to add new management domains and new gateways without impacting existing environments. In terms of vertical scalability, physical appliances and virtual machines allow you to increase processing resources. If traffic or processing needs increase, you can scale up. In Azure environments, we have adjusted instance sizes without service interruption. Where I do think there are some scalability limitations is in the management of objects and rules. When the system grows a lot, I see that policy compilation does get stuck; it feels there is a bottleneck. That scalability in the management of objects and rules is a negative point for Check Point Cloud Firewall (formerly CloudGuard Network Security) because you see a very significant operational bottleneck in very large environments with many client companies.
How are customer service and support?
I think the most critical point is the initial response time. For cases of medium severity, which are the most frequent in day-to-day operations, response times are usually very slow, sometimes many hours. You open a case one day and the next day you still do not have a response. However, once the technicians take the ticket, I think they are very professional. We have done updates, troubleshooting sessions, log reviews, rule changes and networking changes, many things. I think TAC of Check Point Cloud Firewall (formerly CloudGuard Network Security) is very competent; they really know what they are doing. But in terms of agility in the response, I think the problem is in the first line of support: the person who initially manages the incidents. I think that is where the problem is and where they could improve so that tickets are immediately redirected to engineers and then a quick solution can be provided. I think the bottleneck is in the first-line support, and that could be improved, because once a specialist engineer takes the ticket, they are very professional and resolve it. They are engineers who are there every day consulting, asking questions, working with you, and they do not leave you alone with the incident or the case you opened.
Which solution did I use previously and why did I switch?
Before we used, for example, solutions from Cisco ASA and, in other cases, Fortinet, as they did not offer a multitenant management model as mature as Check Point Cloud Firewall (formerly CloudGuard Network Security) MDS. So when the number of customers and devices grew significantly, it became evident that we needed a platform or tool that would allow us to manage all these completely isolated domains from a single console without compromising the separation between customers. That is when we made this migration.
I have used other manufacturers. For example, I have a lot of experience with Palo Alto, and you could say that the main difference is the user experience when using Panorama as the centralized management console, which is like an MDS. It has a more modern and intuitive interface than SmartConsole, which, I repeat, I think should be web and should have a facelift. I have been using SmartConsole since 2018 or 2019, and it looks very similar now that we are in 2026; many years have passed. Another point is the visibility of applications with App-ID; it is very well integrated into the security policy from the beginning, while in Check Point Cloud Firewall (formerly CloudGuard Network Security) it requires more configuration to reach a similar level. For example, in multitenant environments with MDS, I feel that Check Point Cloud Firewall (formerly CloudGuard Network Security) is much better than Panorama for managing many customers in an isolated manner. We also use Fortinet, whose equivalent would be FortiManager, but it also has many complexities. I think Check Point Cloud Firewall (formerly CloudGuard Network Security) surpasses Fortinet in threat prevention and the inspection engine; I think Check Point Cloud Firewall (formerly CloudGuard Network Security) is much better than Fortinet. With Cisco Firewalls, with the FMC, Cisco has many shortcomings; I do not like Cisco much. I do not think the firewalls and the FMC are Cisco's strength. You need a very high learning curve to manage an FMC or Cisco Firepower Firewalls because within Firepower there are several layers of firewall—FTD and other derivatives of that—so Check Point Cloud Firewall (formerly CloudGuard Network Security) is very intuitive compared to Cisco. In conclusion, we could say that Check Point Cloud Firewall (formerly CloudGuard Network Security) is not easy to use, nor is it economical, but it is very robust and very mature in complex enterprise environments.
How was the initial setup?
This could be when migrations are carried out.
For several customers, but I will mention one: when a migration to a centralized architecture with MDS was performed. The customer asked us to unify the management of multiple gateways distributed geographically, because before, each policy change required manual intervention on each individual device; instead, with Check Point Cloud Firewall (formerly CloudGuard Network Security) and centralized management, changes propagate simultaneously to absolutely all gateways—that is, all the firewalls that are distributed geographically across several cities from a single console. This drastically reduces time; we went from using hours to minutes, and we also eliminated errors of inconsistency between devices. It is one thing to create several rules and then have to replicate them on multiple firewalls, or create objects and have to replicate them, but now with this, what you do is create a single rule, a single object, a single network and propagate it to the rest of the firewalls. This way you maintain, you could say, a single object, a single rule that is the same for everyone. This eliminates human errors such as a missing IP, a different rule name, misconfigured IP ranges, or ports, those things.
What about the implementation team?
We are not partners or resellers at this moment; we simply have some equipment, some customers who use these tools.
What was our ROI?
Based on the complexity and growth of users and the geographic distribution of offices—and ultimately we opted for Check Point Cloud Firewall (formerly CloudGuard Network Security). I think there is a long-term return that would be very beneficial for a company. I also think they should take into account the issue of updates. If they are already going with Check Point Cloud Firewall (formerly CloudGuard Network Security), they must be very careful when testing Jumbo Hotfixes and upgrades by doing it first in a preproduction environment, thoroughly reading the notes for each version, and verifying that the bugs that exist between one version and another are fixed in the new update. If necessary, consult directly with TAC of Check Point Cloud Firewall (formerly CloudGuard Network Security); they have helped me a lot when I have had doubts about version upgrades. TAC is very friendly and answers all these questions without problems, and I think that is a very good option. As for licenses, hardware, and training, you have to do a prior analysis so that the engineers who are going to be in charge of the licenses and the solution to be acquired fully understand what is needed and what is going to be deployed.
What's my experience with pricing, setup cost, and licensing?
As for costs, as I mentioned, it is a bit mixed, because we have to be honest. For licenses, Check Point Cloud Firewall (formerly CloudGuard Network Security) has a blade-based model, which seems flexible in theory, but in practice can become expensive when you need to activate multiple security features. Each additional blade—IPS, Anti-Bot, Anti-Virus, URL Filtering, and Application Control—increases the cost. You buy a package of licenses of a certain level, but then you realize you need additional capabilities and the cost scales. As for the cost of implementation, it is higher than with other manufacturers; you also need very detailed planning, and I think that when it is multidomain, it is a product that you cannot deploy in a few days. You need planning months in advance. However, I can say that once it is implemented, it works wonderfully. Before reaching that point where everything works perfectly, you clearly have to plan months in advance so that nothing is left out during the migration. It is not the most economical solution in the market, but for complex enterprise environments I think the investment is justified because it is very robust and has been in the market for many years.
Which other solutions did I evaluate?
We always looked at several options. We evaluated Palo Alto with Panorama first. The second option was FortiManager from Fortinet, and we also looked at Cisco Firewalls with its manager, which is the FMC. In the end, we put everything on the scale—what best covered our needs based on the complexity and growth of users and the geographic distribution of offices—and ultimately we opted for Check Point Cloud Firewall (formerly CloudGuard Network Security).
What other advice do I have?
I think if they are considering investing in Check Point Cloud Firewall (formerly CloudGuard Network Security), they should first look at the initial design of the architecture they are going to use or that they are going to need. Based on that, they should go directly with Check Point Cloud Firewall (formerly CloudGuard Network Security), because I think it is a product where initial architectural decisions have a very large impact on long-term operability. If you build a solid foundation with the architecture you need, I think Check Point Cloud Firewall (formerly CloudGuard Network Security) is a very good solution and, in the long term, will be a better ally than other manufacturers. However, this is achieved by working hand in hand with Check Point Cloud Firewall (formerly CloudGuard Network Security) engineers, and if it is implemented very well from the beginning, the investment is very good. I think there is a long-term return that would be very beneficial for a company. I would rate this review a 9 out of 10.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?