There is a limitation with the version upgrade. We are using version 81.10 and from what I understand, it is problematic to upgrade this version. I do not know if that is true. I am trying to figure it out. If I want to upgrade to a newer version, I have to make new machines. If this is true, it will negatively impact my thoughts regarding the solution.
Check Point Cloud Firewall (formerly CloudGuard Network Security) Room for Improvement
What I would like, what I think they should improve a little is the management of objects at large scale. When you work with multiple domains, there are thousands of network objects. Detecting duplicates and consistency across domains is a very manual process that should be more automated. Another thing: the SmartConsole interface is very powerful and very good, but the learning curve, compared to other solutions in the market from other manufacturers, could be modernized. I think it does not necessarily have to be done from a client application; it could be done via web, because via web I know that not all the options you have in SmartConsole are available. So it would be good if it could also be done from the web and all the options were available. Another thing that I would really like is more automation with Ansible or Terraform. I know it has improved in recent versions, but I think it is still not mature enough. Compared to other manufacturers that do have a bit more in terms of automation capabilities in integration flows with Ansible or Terraform, Check Point Cloud Firewall (formerly CloudGuard Network Security) could improve. Another thing that could be improved a little would be the TAC response time, because when there are very complex cases, I think there should be more speed initially, more ownership of those urgent cases, and not leave the customer waiting. This has happened to me: when I have cases open with Check Point Cloud Firewall (formerly CloudGuard Network Security) TAC, sometimes they do not respond and I have to keep insisting, and I think that part should improve. I do not know if it depends on who takes the ticket or on the severity of the ticket, but sometimes I have had to insist a lot, and that would be the only problem. Once they attend to me and become involved in the case, the responses they give are very professional and really help directly resolve the problems when there is a bug or troubleshooting to do.
As I said, I would like to see a specific improvement in SmartConsole. I think if they improved it—how to say it—gave it a facelift so you could access all the options directly from a browser, that would be great, because sometimes, for one reason or another, you cannot download SmartConsole or, for some reason, the SmartConsole client does not start correctly, and you could do it directly from the browser. I think that would be a good option to improve. Another thing would be that in multidomain environments, I would like a global search function for objects and rules. That is, you could enter and search across all domains at once, because right now you have to go domain by domain, and in environments with many customers, you spend quite a bit of time; you have to exit one domain and enter another. So those would be the improvements I would like to see.
View full review »The main limitations of Check Point Cloud Firewall (formerly CloudGuard Network Security) are not in Check Point itself but in the cloud platforms on which it is deployed. Because not all clouds have L2 infrastructure, you cannot build a unified clustering system everywhere. As a result, the problem usually is not with Check Point, but with the cloud.
The main problem with Check Point Cloud Firewall (formerly CloudGuard Network Security) is that it uses a separate thick client instead of a browser. A browser-based SmartConsole exists, but it still has a number of limitations, while the thick client, the so-called SmartConsole, often works unstably, freezes, and has to be restarted.
I do not recommend using Check Point Cloud Firewall (formerly CloudGuard Network Security) as a VPN hub for site-to-site VPN because it is inconvenient to monitor the state of its tunnels, especially visually. It does not have a convenient snap-in and everything can be checked only via the console, which is very inconvenient. Check Point is not the most universal solution as a device that provides routing and administration capabilities in addition to security. It is an excellent firewall, but it has a number of limitations in terms of routing and in creating VPN sessions, especially in terms of displaying their states.
View full review »The initial setup was primarily configured by our cybersecurity team, but as we progress using it based on our customer needs or as we progress and mature in terms of exposing our applications, we request ongoing amendments or changes to the security policies, including allowing a certain IP address or configuring the firewall rules that are potentially required for our applications. This is an ongoing process of how it is set up with base policies and how we upgrade it according to our customer needs.
For most of the software available out there, the initial complexity is to configure and use it, particularly in terms of large AWS accounts. We have multiple VPCs, transit gateways, and direct connect associations with on-premises infrastructure. What I would think is that if you have something like a readymade agent or some sort of automation that makes the deployment automation easier, that would be beneficial. We now see each and every single day tens and twenties of new products emerging, but I would still stick to my point that the initial configuration is somewhat difficult. This can be improved. Another point is that the dashboards are pretty much standard. Since I am from an AWS background, I will talk from an AWS perspective. If we have specific AWS-related dashboards or AWS service-related dashboards, for example, if we want to see who is accessing our EKS cluster, I would like to simply see what are all my metrics or dashboards. For example, we have something like Grafana dashboards. If you see, there are some prefabricated dashboards there for node level, EKS level, cluster level, DB level, and network level. If we have certain use-case-specific dashboards, that would really be helpful. From a policy configuration, deployment, and synchronization perspective, that would eventually take time. I would not specifically call it an improvement or to speed it up, but it is okay to manage. Then there are cost factors. Perhaps some sort of discounts for long-running customers, or if a customer is managing some 200 accounts, a discount would help.
Documentation can be considered as an area for improvement. Use case-specific dashboards, if it is possible, would also be beneficial. Providing customer insights onto the ongoing focus areas would be helpful. Dashboards can be improved, and documentation can be made easier, or use case-specific features can be introduced. Cost visibility, showing how much we are spending and how much we saved, and recommendations on new threats to customers to consider in the next iteration, would all be valuable additions. All these things are currently a bit lacking in the tool.
View full review »Buyer's Guide
Check Point Cloud Firewall (formerly CloudGuard Network Security)
September 2026
Learn what your peers think about Check Point Cloud Firewall (formerly CloudGuard Network Security). Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,322 professionals have used our research since 2012.
I find troubleshooting a bit challenging with Check Point Cloud Firewall (formerly CloudGuard Network Security); one area needing improvement is log clarity, as sometimes policy installation takes longer than expected, and resolving cloud-native routing conflicts requires advanced knowledge due to the differences in how AWS and GCP operate.
The UI is significantly good and user-friendly, but adding more advanced features to the reporting perspective, especially concerning administrative changes, would be beneficial. However, these points are not deal-breaking feedback; they would just be beneficial for future releases.
View full review »Check Point Cloud Firewall (formerly CloudGuard Network Security) is definitely lagging behind its peers. I am not sure what the reason is. Compared to Palo Alto, they are not there in terms of capabilities and feature set. I do not think there are any obvious misses, but there is mostly lesser adoption in the industry.
Regarding the negatives, sometimes we encounter challenges, especially if a feature may not be working, but that is typical of any vendor. There is no glaring gap; it is a solid product, but based on my experience, the adoption has not been on par with what its peers are doing.
From time to time, we do face challenges with some features, especially if you need to configure a policy where you may need false positive fine-tuning. Sometimes, you have these anomaly detections, which are crucial from a zero-day attack perspective, but they can create a lot of false positives. When you have to tweak, you sometimes need to bring in technical assistance or professional services to achieve what you want. The documentation may not be quite sufficient. There were instances in the past, but I am not sure if they have ramped it up quite significantly recently.
View full review »RK
RahulKamble
Sales Manager For Network at One Network Infosol Pvt. Ltd.
Check Point Cloud Firewall (formerly CloudGuard Network Security) is already good in the enterprise segment and corporate industries. However, they should have some smaller appliances for some small SMB customers.
View full review »Check Point CloudGuard Network Security needs to focus more on the VPN side by being more flexible with configuring the VPN with route-based VPN and having a failover with it.
View full review »PL
Pedro Leão
Networking and System Consultant at Orbcom,Lda.
I think the initial setup of Check Point CloudGuard Network Security can be simpler; onboarding could be more intuitive for new cloud teams, and it could also have more flexible custom reporting and better documentation examples.
View full review »Check Point Cloud Firewall (formerly CloudGuard Network Security) can be improved by bundling more products. As a consumer in the market, I would appreciate at least one or two extra features within the box.
Competitors in the market such as Palo Alto or Fortinet offer more features within their ecosystem. Palo Alto offers extra features within their offering, though it is expensive. If Check Point is not bidding competitively, people may let go of Check Point. The offerings and the price being paid sometimes make Check Point difficult to justify during the initial purchase.
Check Point Cloud Firewall (formerly CloudGuard Network Security) is not very user-friendly. The UI is complex to understand initially, but once I became familiar with it, it became easier.
Exploring the full capabilities by just browsing the website is not possible. Visiting the website regularly is necessary if you are new to Check Point Cloud Firewall (formerly CloudGuard Network Security).
View full review »The only negative aspect is that they have to improve the UI. The UI is very slow, and getting the graph details on the security performance metrics is lagging. That is the only thing I feel is not currently available in Check Point.
I would like to see improvements in the graphical aspect of the UI. They definitely have to enhance that.
View full review »The only thing I think can be improved about Check Point Cloud Firewall (formerly CloudGuard Network Security) is their syslog logging facility. Currently, the logs that come into our SIEM platform via syslog are creating a lot of noise. If something had to be improved, I would suggest it improves its logging facility and provides more contextualized logs so that it is easier for security analysts to understand and make queries around it.
View full review »Check Point CloudGuard Network Security could be improved with faster policy propagation across large multi-cloud environments and more intuitive dashboards for complex rule sets.
View full review »The pricing is a bit very high.
Especially when it comes to pricing, Palo Alto is cheaper. We have to compare pricing between the two solutions.
View full review »Regarding negative aspects about Check Point, previous issues included productivity metrics. Check Point solutions often do not provide as much productivity for machines' CPUs, and the implementation requires qualified engineers. It is not an easy solution to implement, and the price is above average—at least three points regarding these factors.
View full review »The area of improvement is minimal and not especially a super big problem currently. I would like to see some additional features added to the product, such as integrating Check Point Cloud Firewall (formerly CloudGuard Network Security) with some AI tools.
The purpose of AI integration could be helpful for security as it will analyze the logs, analyze the patterns, and based on that, suggest the security parameters or the IPS signatures and the policies, and then such configuration.
View full review »PL
Pedro Leão
Networking and System Consultant at Orbcom,Lda.
Check Point CloudGuard CNAPP can improve with more intuitive onboarding and policy templates for new users who are not accustomed to it, better customizable dashboards for different team roles, and deeper automated remediation suggestions to speed up fixes.
View full review »Areas of improvement for Check Point CloudGuard CNAPP can be the UI navigation. The dashboard is feature-rich, but it can sometimes feel overwhelming. A more streamlined or customizable view would help teams focus on the highest priority risks more quickly. While it integrates with AWS and GCP, deeper integration with DevOps and third-party SIEM tools could make workflows even smoother. For first-time users, the documentation could be more intuitive or hands-on.
View full review »YN
Yabaluru Deepthi Naga Ramya Sravani
Admin at Infosys
After working with Check Point Cloud Firewall (formerly CloudGuard Network Security) for three years, most areas including firewall rules, network segmentation, and threat prevention are solid. However, vulnerability and patch management could be improved by providing the best version of vulnerabilities and exact track numbers, which would allow for easier detection of issues with the vulnerability numbers affected in the environment.
View full review »Currently, we have one customer using Check Point Cloud Firewall (formerly CloudGuard Network Security), and they are satisfied. However, we need to complete an integration with a Nutanix environment for the hybrid component that the customer requested. This integration has not yet been delivered by Check Point. Once this is properly addressed, the customer will be fully satisfied with the platform.
We have not yet completed the integration and are about to begin the integration process.
View full review »One area that Check Point CloudGuard CNAPP could use improvement is the navigation when switching between modules. A more streamlined interface and a quicker drill-down into findings would make the workflow feel even smoother.
View full review »DG
David Gippner
Network administrator at Helios IT Service GmbH
I honestly do not know how it can be improved anymore. There are probably people with more knowledge or experience who could suggest improvements. Most of the solutions we have used have been straightforward and effective.
Occasionally, there is a strange bug, however, we just contact Check Point for a hotfix if we are a significant client. And since that is our situation, the solution works.
There might be a possibility for Check Point to offer more training opportunities for users to get to know the solution better, perhaps through courses or similar resources. However, it depends on our company's arrangements with Check Point. In our case, we have a vendor involved. Everything we do with Check Point must go through the vendor first, which is somewhat inconvenient. It would be easier to deal with Check Point directly, however, it depends on the vendor.
There is a wealth of material available online for those technically inclined. In this fast-paced industry, we must continue learning. Courses or online meetings, like Zoom or Teams sessions, for one or two hours each week, would be helpful.
Despite using it for a long time, there are always new features. For example, just last week, I discovered a new feature that had been in the software for years yet it was not visible due to its placement behind multiple menus. Teaching sessions would be beneficial, yet it is our responsibility to learn, so we cannot entirely rely on Check Point.
View full review »The user interface needs work. Sometimes, it is a transition from the old tool to the new CNAPP Two that I currently have, and remnants of the old environment can still be detected. I require consistency in the user interface to ensure everything is streamlined into the same look and feel.
More work is needed in fine-tuning the threat data towards your CSPM and activity logs, aligning them with business intelligence, which requires a cohesive console interface.
My assessment of CloudGuard CDRs in intrusion detection and threat hunting capabilities is that it still needs some work. All the threat data that comes in, you need to fine tune it a bit.
View full review »TV
TVargas
Cloud Support at a security firm with 51-200 employees
Check Point CloudGuard Network Security could be improved by enhancing its user interface, simplifying policy management, and expanding third-party integrations. The documentation has a learning curve, which can be dense and sometimes outdated. At first, I needed to learn different documentations, but now it is easier. More interactive guides, real-world examples, and clearer walkthroughs would help new users get up to speed faster.
View full review »It should be more unified across all platforms. There are different kinds of releases for private cloud, public cloud (HA), NSX, and VSX. It is a little bit different on every platform where I install it, and each platform has many limitations like SMB or Maestro. So I need to know that and decide on which platform I should install it on.
View full review »The tool has been quite easy to handle. However, when we were new in this phase, whenever an implementation was going on, there were some areas that we identified with the overall complexity of managing a cloud environment, particularly when we dealt with multiple cloud accounts and networks. Making those workflows more streamlined is an area that can be improved.
View full review »IZ
Idrees Zargar
Senior Solution Consultant at a tech services company with 51-200 employees
Check Point CloudGuard Network Security can make deployment and configuration less complex.
View full review »One aspect that I noticed is that we already have a substantial Check Point setup, so management is a consideration. I'd like to have an ease of management. That's important. I am anticipating the introduction of features like AI or advanced supporting functions on the on-premises side. This would be beneficial by providing insights into capacity and enabling me to project future needs, such as enhancements or additional layers for the Check Point infrastructure. Ease of management and reporting would be crucial for capacity planning and budgeting. If I see capacity increasing, I want to be able to plan appropriately.
View full review »It should be more agile, as it seems to me that they took their on-prem devices and uploaded them to the cloud. Every time we need a new interface or something like that, we need to make major changes. This is a problem.
When we try to install a new lab, it appears we need to reinstall the firewall because the interfaces were missing. This took a lot of time, and we had to use the professional service again. I believe this is the point that Check Point should improve.
View full review »I believe that presentations on artificial intelligence indicate that analyzing logs via SmartEvent and SmartLog Security Event Information Management can offer insights into emerging trends and potential next steps. By correlating logs related to BYOD, BYOL, and Shadow IT, it will become easier to manage and hopefully mitigate or understand risks.
View full review »RG
Reffat Gharaibeh
Cloud Security Architect at controlware
The shift left part is not yet at a maturity level I desire. I need more integration from the code-to-cloud principle. It feels somewhat fractured to me. I haven't grasped all the parts yet, and better integration would make CNAPP most valuable.
View full review »MM
Mantas Mazeika
Sales manager/ project manager at Atea
This year, I have noticed that Check Point is working on consolidating all aspects into one management platform to provide a comprehensive view. This platform should include Check Point vendors as well as third-party vendors.
I am unsure what else can be done, however, customers need a holistic view of all security solutions across their platforms, which is critical at this moment due to the limited availability of IT professionals.
More integration into one solution with increased automation would be beneficial.
View full review »From my point of view and my needs, I don't see room for improvement. In my opinion, the more it has support for more environments and the more integration there is with wider areas, not only in Check Point's systems, but also with other systems, then I think it will allow access to more customers which is not specifically my case, but in principle the wider the system, the more it will be able to appeal to a larger audience; integration with other manufacturers in other words.
DS
Daniel Sander
System engineer at a manufacturing company with 1,001-5,000 employees
VPN troubleshooting can certainly be improved. It is horrible at this point, honestly. It is horrible compared to other vendors on the market. They have tools where I can directly extract some information on the VPN. In Check Point, it becomes complicated. I need to open a very old-fashioned legacy tool, and operate it by myself, transfer it to my computer, and open the legacy program. This legacy program will not provide detailed insights; it will only indicate if something is working or not, making it challenging to communicate.
View full review »Everything is in one place, and it seems it's easier to use than before. Making it even easier is a good way to improve it more. When it's easier to use, there are fewer mistakes.
View full review »The only thing that Check Point CloudGuard Network Security lacks is that for VPN, you need to buy a different model. You need to be in the HA sort of things to establish the IPSec between another firewall or maybe another cloud vendor, and that is the only thing that bothers me about Check Point CloudGuard Network Security.
View full review »The license model could be simpler. We have some issues with the license since it tries to be simple, and yet in some cases, it tends to be complex. Apart from that, I do not recall any other issues.
View full review »RM
RohitMutha
Infrastructure Engineer at a tech vendor with 10,001+ employees
There is nothing where I have come to a roadblock where I think that a particular feature is missing. There is no feature that I think is missing.
View full review »It is pretty great in all aspects, but the integration could be easier, especially with Scale Set and related features. It was somewhat challenging a few years ago to set it up, but once completed, it worked well. Easier integration with on-premises solutions could be beneficial.
View full review »
In my experience, the failover times are a bit poor during an HA failover in the Cloud. However, this also depends on API calls in Azure, so there is not much I can do there. If there is something I could improve, it would be this aspect.
View full review »
More support from our partners would be beneficial. A lot could be explained more. It's often a use case that the management is behind NAT, and I need to know what to do to connect my cloud gateways. Documentation is very good from Check Point, however, in this case, it could be better. Maybe more support in building up these environments would be helpful. We are a big company, so we have different teams, and guidance from Check Point would be useful. I need certain things, teams, and permissions, which might make it easier.
View full review »Areas for improvement for Check Point CloudGuard Network Security include user interface and usability, pricing and licensing, integration with third-party tools, reporting and analytics, depth of automation, and support.
In terms of user interface and usability, the Smart Console UI is feature-rich; however, for new admins, navigation is not always intuitive, and log search feels clunky compared to SIM tools. Policy editing could be faster with bulk or drag-and-drop options, and dashboards need more customization. Streamlining these would make day-to-day use much better.
View full review »I do not have any specific improvements in mind for the tool. It is a solution that is what we need at the moment. There could always be something to enhance deployment, however, for now, it is quite adequate.
The pricing could always be reduced.
View full review »SB
Stefan Baumgartner
Security architect at Twinformatics
Improvement is needed in the deployment models. Currently, I have deployed VMs and installed CloudGuard as if they were gateways. Having some as-a-service models would be great.
Scalability could be improved as well; needing to purchase a new license each time I want to add a new interface is not ideal.
View full review »There is room for improvement in how it handles deployment itself, but I am not sure. It could be due to Azure's limitations, not Check Point's. Deploying a new firewall is quite bulky and not straightforward, especially in managing the resource group and networks. These issues seem to come more from the Azure part. It is hard to tell.
View full review »Today, we are trying to look more into encrypted traffic. API security is one of the most highlighted aspects we are currently evaluating. Network Detection Response (NDR) and AI protection are the main areas I am focusing on now. In addition, I am looking into Secure Access Service Edge (SASE) solutions in general.
View full review »VA
Amaratunga Arachchige VimukthiAmaratunga
Sr Manager Engineering at a consumer goods company with 1,001-5,000 employees
The pricing is too high. We pay more than twenty-five thousand USD per year, which could be reduced.
Moreover, Check Point does not initially support serverless architecture, requiring additional efforts from our team to manage it.
View full review »KU
Krishna KantUpadhyay
Android Developer at Droidforge
The user interface could be more intuitive, and the initial setup and configuration can be complex, requiring a technical team.
Additional improved documentation and support would make it easier for beginners and small-scale startups. Furthermore, the pricing model is quite expensive, which could be a barrier for smaller companies.
View full review »I would focus on the implementation in the cloud, as it relies on third-party vendors like Azure and AWS. It's not seamless; the solution should be more straightforward for complicated environments.
View full review »I'm quite satisfied with the solution. I don't have any notes for improvements.
I think Check Point CloudGuard Network Security is an ideal product, so I see no improvements needed.
If I had to think of one area where it could be improved or made easier, I would say that support isn't very good and documentation sometimes is lacking.
View full review »SZ
Stefan Zara
Information Security Officer at Cargus
I would appreciate a way to receive periodic updates, like through email. I am the kind of person who likes to receive data passively. It would be nice to have periodic updates on what people should do, maybe with some analysis or something.
View full review »KJ
Krunal Jagdish
Senior consultant at a consultancy with 10,001+ employees
We haven’t seen any kind of problems so far.
We generally used everything on-premise, but now it's all in the cloud through CloudGuard. The transition was a bit challenging. Maybe they could improve their services by including more tutorials and labs on migration.
View full review »AG
Andrei Ganciu
System administrator at a consultancy with 201-500 employees
A Check Point problem was that there were different solutions, and each had its own interface, section, and logs. Things are going great with the new feature that consolidates all the data from those systems in one place. Right now, I am not sure what improvements are needed. We are having occasional issues related to gateways, but we are still analyzing it.
View full review »I don't have any notes for improvements. I'd need some more time to work with it.
View full review »SP
SanjayPatel3
Sr network engineer at a outsourcing company with 10,001+ employees
The GUI hadn't been that good. However, they fixed that and the GUI is pretty good now.
There may be some latency. In the beginning, you won't really notice - when you have 10 to 15 sessions. However, if you have 40,000 sessions and you are running the dev check in the background, then you will start to notice some issues. It's probably under milliseconds.
It's not as organized as a Palo Alto solution.
We wanted to go with the Azure Network solutions, and CloudGuard was a big expansion compared to Azure Dev, which is a built-in dev solution. I hear Azure is integrating Palo Alto as a back-end solution.
I had a high level of confidence in CloudGuard Network Security. We used it for nearly six months and were comparing different products. I'd rate it at an eight or nine out of ten.
View full review »The user interface could be improved. Sometimes, the visibility is not immediately available for the environment. We have the native servers that come with the solutions, but we cannot see them in the Check Point log. Another issue is with the integrated file monitoring. It would make sense to have stuff like file integrity monitoring and malware scanning available within this module because we don't want to integrate another product.
For example, let's say it's showing a process violation. It should be able to do some additional malware scanning in that particular bucket to get some additional information. I don't want to integrate with another third-party tool or go to the native server to check something. It would be helpful to have integrated monitoring and malware scanning for the file types.
There are a few flaws with the security management portal where I have limited visibility into the workload protection features. There is no error visibility where I can see the communication and workflow between services. Some of the dashboards need to be fine-tuned if they are not customized. For example, I cannot customize anything on the effective risk management dashboard. Some of the information is not correct for my tenant. With respect to passwords and user management, there are no policies I can measure at the user level. If the user was created more than six months ago, you don't need to worry about that password or do anything like two-factor authentication associated with that user. They can still log in after six months or one year.
It's also a challenge to use CloudGuard's agentless workload posture with AWS. An Azure storage is summed up with a CNAPP encryption by default. We tried onboarding this data, but the problem is the attachment is not done. After a few days, we identified that it was impossible to do the encryption detection. But CloudGuard's default rules say that this has to be encrypted.
The AWS module says that we cannot access this volume with this encryption, so we cannot use an agentless workload posture with AWS because of this. It is a best practice to ensure that all the volumes are being encrypted. Without the encryption, how can I do this? It is a big challenge for CloudGuard.
CloudGuard's reporting could be better. It's good now, but there is room for improvement. If you're looking for a centralized platform, there are a lot of features that can be appreciated. However, you want complete security integration with SaaS, DAST, secret scanning, etc., and a single platform for all these features.
Check Point is known for its firewall. Six or seven years ago, it used to be a good thing because most businesses were on on-prem. If your business is on the cloud, you do not need a firewall because most of the cloud vendors already have that built into their cloud premises, and you can configure the rules there. You can do everything as a network security engineer.
It depends on your business model. Some companies are segregated and most of their things are on-prem. They have physical outlets in multiple countries. Managing everything in these business environments and deploying the Check Point firewall would be a good investment. However, it doesn't make sense if your business is totally in the cloud.
It depends on how Check Point sees things in the market. If they want to compete with all these vendors in terms of CNAPP, they need to first understand their audience. Once they have some visibility into who their audience is, they need to maintain their business.
View full review »We have done a lot of automation with the firewall, but sometimes, there are some failures because of some bugs. The fixes for them are still not available. We have daily or weekly communication with the Check Point people giving support in the India region, but we have not seen much improvement or response to our requests for some additional features. We are moving to infra as a code, so we are expecting more advancements in this product. Just installing the patches is not going to help us. They need to focus on this area.
I expect Check Point CloudGuard to come up with some AI/ML integration. A firewall is the first L3 security device available to you. It is the single point that manages or processes the traffic for an organization. There is a possibility that the device goes down or gets rebooted for any reason. The integration of artificial intelligence with the devices can help us to know in advance that there might be a surge in traffic. There might be a spike in the traffic, so we can have some additional firewalls integrated. This predictive analysis has to be there. This way, if required, a second, third, or fourth firewall can come into the picture. All the firewalls will process the traffic simultaneously. I am expecting such capability. This sort of feature is available with AWS. We are deploying all the firewalls on AWS, but it would be easy if, in the future, such a feature is available from the OEM or Check Point itself. It will be very helpful for the organization.
We have had a couple of outages because of some misconfiguration. They were human errors but there were no prior indications that if we were making these sorts of changes, this would happen. People making the changes on the firewall were not aware of this, and that is the reason why the outage happened. In a financial organization, an outage of even five minutes can cost a lot.
View full review »The main issue that I have noticed is that for deployment, it still requires a dedicated management server, and the gateway is completely different. That sometimes can cause issues. If it loses communication with the management server and you want to push any sort of critical policy, that would be affected. Apart from that, I do not see any issues. Everything else is going well.
View full review »SK
Salman Kaleem
Associate Director at Virtusa Global
The ability to help organizations modify their own policies is essential. For example, consider the CIS benchmark 1.5 for AWS. In the past, I would have added the CIS rulesets to my custom policy, along with my own rules for Internet requirements. This created a custom policy that was tailored to my specific needs. However, the CIS benchmark is constantly changing, and it can be difficult to keep my custom policy up-to-date. As a result, I now have to recreate my entire policy whenever the CIS benchmark is updated. This is a time-consuming and manual process. Adding a feature that allows me to easily identify the changes that have been made to the CIS benchmark and update my own policy accordingly would be a valuable addition to Check Point CloudGuard Posture Management. This would save me a significant amount of time and effort.
View full review »RT
RajivT
Senior System Engineer at a energy/utilities company with 201-500 employees
They have come such a long way. There may be other areas that other people use, but as far as I am concerned, I have been very happy with it. There are always newer features getting added and new encryption protocols coming. I can see where they are going and how far they have come. I have been using the Check Point firewall since 2010. It has been 14 years, and I have seen how they have improved.
They are coming out with more SD-WAN express route support from a firewall perspective. That would be great. They keep on launching new features. That is how they work.
View full review »Automation and advanced threat prevention have room for improvement. I would like the rules configuration which are manually reviewed to be automated according to the defined rules.
View full review »DB
Dimitris Baziotopoulos
Network security engineer at a tech services company with 201-500 employees
I'm not sure if I have the experience to discuss improvements.
The deployments can be difficult if a person doesn't know what they are doing.
Better documentation would be welcome.
View full review »The reporting needs enhancement. Currently, we are not always aware of the gateways' status, like CPU and RAM usage. It would be beneficial to have a report that manages everything and gives an overall view of what is going on.
View full review »Check Point's primary competitor, Palo Alto Networks, offers a SaaS firewall solution that can be deployed in both traditional virtual networks (VNETs) and virtual wide area networks (VWANs). This firewall solution features auto-scaling and consumption-based pricing, allowing users to scale according to their needs seamlessly. While Check Point does offer some VWAN offerings, they appear to be more static and less tailored to cloud-native environments compared to Palo Alto's dynamic and flexible approach.
One area where CloudGuard CNAPP could be improved is in its reporting capabilities. Customization options for building tailored reports would be beneficial, as it would allow for different views on vulnerabilities based on specific criteria such as tags or dimensions. Currently, the reporting features have some limitations in providing the level of customization we require.
Some more built-in marketplace templates would be nice. It would be nice to see more vendor assistance in deployments and backup of recoveries versus having customers rely upon that themselves. That would make it a lot more seamless and aligned with the standard on-premise model that is there. Check Point can extend the same posture that they have to CloudGuard and make that transition very seamless.
Check Point does not have as big a footprint in engineering teams as Cisco or Palo Alto has, especially in the US market. Therefore, finding someone who understands Check Point is a lot harder. If Check Point can make it easier for seamless transitions, it will build the confidence of engineers and help with the adoption of a new vendor for those engineers. Anything they can do to help with that is a competitive advantage, and it works for any company looking into it.
View full review »I am not a technical person, but generically, the user interface can be a little more intuitive. Our staff has trained network security and cloud security professionals, and they get it, but when you are trying to get to the customers to be able to pick it up and maintain it, it can be a bit difficult, so the user interface can be a little better.
View full review »Currently, we are struggling with licensing just because of the pace and growth of our cloud. Keeping up with licensing for new regions and new gateway usage is certainly something we are looking into. We are working with our accounting to figure out how we can improve. The licensing piece is big for us.
We are at the place where we are looking at better integration with the management system. We use an MDS today, and it is self-deployed. We want to get to the Smart-1 Cloud, but we do not know what that looks like today because it does not support a multi-domain setup. Smart-1 should either be able to do multi-domain or there should be some form of taking a multi-domain environment and putting it in Smart-1.
View full review »IQ
Ignacio Quintas González
Cybersecurity Engineer at Altia Group
There is a lack of functionalities and usability. I used to compare it with another solution that is focused on specific features. All solutions have some gaps, and we are looking for the best one in every single scope.
I believe improvements could be made to the notification system, ease of use, and integrations.
The interface could be simplified and more focused on user experience. It appears somewhat unrefined in its current state.
If they improve their interface and integration capabilities, I would give them a higher rating.
View full review »We are having issues with updatable objects in the Scale Set solution. It needs to be fixed by Check Point.
The setup instructions are not correct. They should be corrected. We sent the product feedback last week. Several things were misspelled and incorrect in the documentation, and it got updated.
View full review »Making basic rules is easy, but it's complex if you want to do something a little more nuanced. I've been unable to make some rules that I wanted. I couldn't evaluate some values or parameters of the components I look for. I haven't always been able to assess them.
It feels like some attributes of resources can't be interrogated through the GSL the way I would like. For example, I wanted to figure out all the systems launched with a particular image that had been running for 31 days or more. Until I talked to the Dome9 people and the support team, I didn't understand how to frame that query in GSL. The support team told me how to do it, but I couldn't figure it out alone. The documentation is a little unclear about how to do some of those configurations. More tutorials and examples on the blogs and support pages would be helpful.
I had another problem when we tried to encrypt all of our storage volumes. There is a feature called batch jobs or Elastic MapReduce jobs. CloudGuard sometimes can't detect the encryption status of the underlying disks of those systems that process my workloads. It pops up with a bunch of alerts that say, "Non-encrypted volumes have been found in your account."
Those jobs are dynamic, so they spin up, run for an hour or two, and all the systems are destroyed. By the time I checked it, all the systems were gone. CloudGuard threw a bunch of alerts in the middle of the night when all these things happened, and I went back to evaluate the configuration. I know they were all encrypted because I can see how it was deployed. It didn't have a great insight into my actual workload, but it generally tells me when people launch unencrypted things. It isn't perfect, but it's okay.
View full review »The first improvement area is the impact analysis. The impact analysis that they perform can be improved. It is currently lacking. It should be more detailed.
The second improvement area is that they should adopt more remediation on various resources.
The third improvement area is that they should introduce Gen-AI capability on their platform so that remediation can be very easy. They have the threat hunting and detection part, but they need to adapt more on the Gen-AI side so that the remediation can happen automatically. People should be able to do remediation with a click. It would be a very good feature to have for remediation.
These are three main improvement areas for them. I have already provided Check Point feedback about these through another channel.
With respect to Cloud Workload Protection, they should introduce more granular security control in terms of policy. I feel they should work on it and develop it more. They need to provide more granular security control in terms of various attacks, such as the MITRE ATT&CK framework. They need to give a different policy for each technique and tactic such as ransomware, exploitation, etc. I also work with CrowdStrike, so I know about different types of granular controls. From the Cloud Workload Protection perspective, they need to improve the policy framework.
View full review »There is room for improvement in the integration with PaaS services from the public cloud. It would be very helpful. A more cloud-native approach is needed because even it is PaaS services require public cloud resources, even if the traffic load is low. These resources are still required for high availability and resiliency.
So, a full PaaS solution with improvements on that end, basically.
View full review »The setup can be better. With every other Check Point SaaS product, the setup is scripted. You just approve deployment scripts, and then you are off. The setup for this solution is still very much manual. I would like to see that transition to more of a scripted setup. That has been an issue when I set up a client because every client has different skill sets.
The general reporting also needs improvement. It is very cumbersome to pull the reports for big environments. I had a client environment with 50 tenants, and I had to manually run a CIS report for each tenant and download it. There were 50 different reports. I wish there was a way to get the reports for all 50 tenants in one report and not 50 different reports.
Its price is fair, but it can be more favorable.
View full review »Down the road, we would like to see automation. That is probably a feature that most people want. If they can automate patching a vulnerability, it will be much easier.
From the policy optimization point of view, they can do better. This is not just for CloudGuard. CloudGuard is one little piece managed by Check Point. They can also integrate a third-party policy management solution to improve that. For example, Tufin is focused on policy optimization and management.
They can also offer solutions faster to address customer concerns.
View full review »The only pain points we have had with it were when we did major version upgrades. Rather than being able to do incremental upgrades on those, we had to completely redeploy. I know that has changed recently, but we had some hiccups when we did the upgrades. This is the only issue we have had.
View full review »The service is already top-notch; both on the commercial side and on the technical side. I had the luck to be put in contact with a very talented and skilled technical after-sales team that guided us step by step through the configurations. Also, the commercial team was very comprehensive with our situation and allowed us to create a package that best fit our needs.
One feature of the product that I would like to enhance is the possibility to connect to vulnerability management platforms so that the issues that emerge from the scans can then be ingested directly into the vulnerability management process. It would be very nice to provide, on top of API connections, built-in plugins for the major ticketing systems.
View full review »I don't see much need for improvement.
In Czech, we are a little behind the USA and Germany so we have matured in our mentality to move towards the cloud.
Check Point could show us use cases that would help us in Czech and could help us with security threats in our specific country.
The level of confidence our clients have in their cloud network security using CloudGuard Network Security depends. Some are very confident but some are worried about information being exploited. When compared to other vendors, CloudGuard is the best when it comes to threat protection.
View full review »I want the upgrades of their CloudGuard solution to major versions to be easier. We have had a few small hiccups. They have different types of cloud clusters called Geo Clusters, and those just cannot be upgraded past a certain point, which is a hurdle that we are currently experiencing.
View full review »At this point, we are very happy with what is happening with their horizon. At CPX, we heard that we can see all the things on the same platform. That is what we have been asking for, and hopefully, we are going to start seeing it this year.
View full review »AH
Abdul Hanif
Cloud Security SME at a computer software company with 1-10 employees
The integration process could be enhanced by enabling integration at the organizational level rather than requiring the manual setup of individual accounts. The current workflow of creating and linking each role is time-consuming and labor-intensive. Streamlining account onboarding by allowing CloudGuard to identify and integrate at the organizational level would significantly simplify the process.
View full review »JA
James Arscott
Consultant at a tech services company with 51-200 employees
They could improve the documentation. The interface is fine for me since I have been using it for some time.
View full review »
Check Point CloudGuard Network Security needs to improve the management of the actual firewalls. Improvement is also needed for the consolidated UI of different security aspects.
View full review »EH
reviewer2379448
Director of Cybersecurity at a comms service provider with 10,001+ employees
The platform would be significantly enhanced by incorporating data security management capabilities.
I'd like to see CloudGuard offer more agentless functionality beyond what's currently available.
View full review »TM
Tsachi Mishori
Network and Security Manager at a financial services firm with 1,001-5,000 employees
In future releases, I would like to see the data loss prevention (DLP) feature could scale along with the virtual machine scale sets.
View full review »The reporting has a lot of opportunities to continuously improve so that we can continue to show value.
I would love to see more ability to automate and integrate into even more systems for automatic remediation.
View full review »New features have been introduced recently, but they have not yet been integrated into CloudGuard Vsec. It would be advantageous to have them implemented as they would improve the performance.
I have not dealt with it enough to find any pitfalls.
View full review »DR
Dan Ramsell
Customer Operations Director at Pentesec Limited
Based on my previous experience, there were improvements, especially in in-place upgrades. Regarding cost, it might be potentially cheaper considering resource utilization in Azure and VM costs, but licensing could be improved, possibly moving towards a simpler model.
View full review »The relationship between AWS and Check Point could be better. We had issues related to the type of instance and how it interconnects with AWS or cloud-native solutions. We overcame the pain points that we had, and now, AWS is evolving in a way that will facilitate how Check Point works. Our pain points were minimized, but they were there.
There could be more capabilities around the management protocol itself. We deploy the boxes very easily with the software. We want automation. We are already using it to deploy instances in AWS regardless of whether it is Check Point or something else we use. Integration is already there, but there is a possibility to have more functionalities. We are in a good state, but there can be new features.
View full review »The licensing structure is unclear, so a transparent and flexible licensing structure would be preferable.
We utilize logging systems, and geolocation is crucial for us as some applications must only be accessible from our country. However, there have been occasional issues with this feature. It drops requests. It's not always precise.
View full review »We miss full blade support for all blades that are compatible with the cluster. Especially notable is the lack of support for Identity Awareness in active standby environments for customers. In our setup, transitioning to Connective clusters would be preferable for maintaining connections during failover situations.
View full review »Vendor support might be the weakest point of the CloudGuard solution. You really struggle to find a CloudGuard specialist, even for simple tasks. As mentioned before, you can find better answers to the user community (which is actually a downside of the product).
There are lots of limitations and discrepancies across different Cloud provider deployments.
Documentation might become too complex or too spread out, especially for newcomers.
As in the past, with traditional Check Point firewalls, it sometimes seems to be moving too fast with software releases and upgrade cycles, which are difficult to keep up with.
View full review »Compliance checks on cloud resources against various industry standards and compliance framework templates need to be improved, to ensure that organizations meet regulatory requirements with clear visibility action controls. This can make it difficult to create and manage custom security policies.
Cloud security posture management is a proprietary solution, which means that there is no open-source community to support it. This can make it difficult to get help with troubleshooting and other issues.
View full review »KS
Kuber Shukla
Senior Security Specialist at Tech Mahindra Limited
Their service needs improvement. Their vendor doesn't provide good support. Also, there is no way to escalate it to Check Point so that Check Point can take action against their partner. I don't have direct support with Check Point. We have collaborative support with one of the Check Point partners who do not provide good support. When we reached out to Check Point to escalate; they denied taking any action against the vendor.
View full review »With the incorporation of a lot of AI and machine learning, they can build some sort of a matrix for low-level threats or low-level things that require attention. There can be automation of those tasks so that we don't have to take more time and effort. There should be machine learning to eliminate level-one types of tasks.
View full review »CloudGuard's effective risk management only scans accounts every hour. We have more than 150 AWS accounts and 20 Azure accounts. We sent Check Point a request asking them to increase the frequency to five to fifteen minutes. I want the flexibility to scan it as often as possible based on the account's importance. That part is lacking.
When rules change, it messes up the remediation. They haven't found a fix for that yet. The remediation rule goes into limbo. It's an architectural design flaw within their end compliance engine—a serious bug. We must spend extra time reapplying the rule when they periodically update the compliance presets. Auto-remediation breaks if you're using that particular out-of-the-box rule. I haven't experienced this recently, so maybe they fixed that part. However, that's what it did in the past.
Check Point is slow to respond to bugs. They resolve bugs maybe once every two weeks, and their R&D is slow. They're in Israel, and it's not just the Israeli holidays. I would probably pick a large US company if we did this over again.
They don't give us continuous feedback. I want live feedback when they change something. Stop breaking things. The company should let us know what they're doing when they add new features. They don't have an official beta program, so you can't test the new features.
That's the other bad thing about this product, but I don't know about other Check Point products. They're a firewall company but not a software company. If you put out a beta, customers should have the option to test it and give feedback. I've been putting a lot of work into CloudGuard to fix all the bugs. They should have paid me to fix their bugs for them.
They need to decrease their bug resolution time. Anything longer than two weeks is problematic. It's why we don't jump into the deep end with all these other features they've added. Our primary feature is the CSPM cloud part. The solution is useless if the reporting or remediation breaks, as it has in the past. It requires an SME for CloudGuard to dig in deeper, which takes time away from our SecOps folks.
The version upgrades need improvement. We faced issues while upgrading our CloudGuard Network Gateway. When we tried to use the template that Check Point offers on their site, it was not available for the second to the latest version, so I was forced to upgrade my management server. That was very challenging for us.
View full review »LT
GGNOOB
IT Security Engineer at a healthcare company with 1,001-5,000 employees
Improvements needed include better integration with Azure features to match on-premises capabilities, particularly in areas like identity awareness, to ensure seamless functionality across both environments.
CloudGuard Network Security could be improved in the area of upgrading in place.
AS
AmitSingh14
Security lead at a manufacturing company with 10,001+ employees
There is room for improvement regarding the technical support provided. Having a more refined and advanced feature would offer significant benefits.
CloudGuard Network Security needs to include new features. One specific feature I would like to see is the ability to protect external resources using single sign-on integration with various identity providers, including custom identity providers. Its pricing could also be cheaper.
View full review »The product needs to improve technical support.
Regarding CloudGuard Network Security's integration with various resources like application gateways and application-based security groups, there's room for exploring dynamic access in those areas. A significant concern is the upgrade process. Unlike an in-place upgrade, upgrading the tool in Azure requires deploying a new resource, which can be hectic and less reliable. We have to spend something new to have the tool's latest version.
View full review »The costs are really high if you want the entire capabilities of the platform. However, it is really motivated by the great value of the product. Moreover, you can buy individual licenses for the different modules if you don't need some of them.
View full review »PS
Pushkin Sawhney.
Principle Network and Security Consultant at Vodafone Global Enterprise
Software bugs and OS releases can be very fast to keep up with. Check Point has a history of moving fast with software release and upgrade cycles which are difficult to keep up with at times.
New features should have a single-pane-of-glass view for on-prem DC and cloud environments.
Licensing costs are very high compared to other vendors. Check Point needs to be competitive to keep the cost down for the customers and partners.
The previous Check Point OS model had to support multiple OSs which was difficult and cumbersome (i.e. SPLAT, IPSO, GAIA).
View full review »We have concerns regarding the pricing and would appreciate seeing some improvements.
View full review »The solution’s technical support, DNS security and training could be improved. Check Point CloudGuard Network Security's training and reachability to the customer can be done a bit better. One recommendation from my side is that the handover of the tasks can be a bit better. If an engineer is on a ticket and their shift gets over, the smooth handshake between the two engineers can be a bit better.
View full review »VD
Vijay Devnath
CIFO at Crisp System India Pvt Ltd
Check Point must provide a multi-cloud facility where AWS, Azure, and GCP can seamlessly work together and display posture in an integrated manner. Instead of showing separate AWS, Azure, and GCP environments, the solution should provide a single integrated view. This will make it easier to decide which issues to fix first and will reduce the amount of technical work required.
Check Point is always adding new features. However, we are sometimes confused about how to use the features that are already available. There are so many features and we are unable to use all of them.
The price of the solution could be reduced, it is expensive.
View full review »There are regulatory requirements. I would like to be able to pick the regulation I would like to scheck compliance with and it would tell you where you stand on that regulation and what you are missing to reach compliance. And it shouldn't matter which cloud we're dealing with; we would have these possibilities.
View full review »RN
RonnieNunn
Freelancer at a consultancy with 51-200 employees
Having additional documentation on how to use CloudGuard CNAPP would be advantageous, especially if it were made more user-friendly. The application's structure seems to lead users down one path, then into another, making it difficult to backtrack or navigate seamlessly between different components. Streamlining the user interface would greatly improve the user experience.
View full review »RL
Raimondo Lemma
ICT Security Coordinator at Menarini
In the past year, I noticed that the challenging part, especially in the cloud, is upgrading to the next release of the firewall. Unlike on-premise upgrades, it's not as simple in the cloud. You need to recreate the machine, which makes the process more complex.
View full review »The solution's integration with cloud providers has seen significant development in the past months, but there is room for improvement for better integration.
View full review »People don't know about the tool's features. There's a lack of skill. Users require more knowledge on how to integrate it into the cloud environment and orchestrate routing. So, it's not necessarily a CloudGuard Network Security or Check Point issue but more about integration, knowledge, and understanding.
View full review »The product needs to offer multi-tenancy.
View full review »The solution needs to support more hypervisors.
View full review »There is room for improvement in addressing bugs and support issues. Communication with support, particularly with certain teams, can sometimes be challenging and slow, impacting problem resolution.
View full review »CloudGuard Network Security's pricing is expensive. We have encountered issues with its licensing.
View full review »The product needs to improve support. They don't consider my case the number one priority even though I want a quick resolution.
View full review »The tool should incorporate more use cases like improving security scores. It should also improve documentation.
View full review »Check Point CloudGuard Network Security should give productive reports as per business requirements. It needs to improve support since the time-limit extended beyond a day. It should include more seamless API integrations.
View full review »Check Point CloudGuard is not a feature-centric product because Check Point concentrates on security. For example, if a customer asks for reporting, it might not be available, like a bandwidth report. At most, the reports are given with respect to security, not infrastructure.
View full review »We use the tool as a basic firewall. It's a technical firewall. As a technical firewall, we use SmartConsole or Check Point Firewall.
The deployment phase takes too much time. I would like the deployment to be faster.
The set security features have stable performance and have provided reliable services since we first deployed this product.
The cost is relatively high compared to the cost of other products in the market.
The customization features can be developed further to enable an organization to design the best tools for serving various demands.
The security infrastructure has developed positively and contributed to increased return on investment. We have achieved the set goals and increased profit gains from a stable security environment.
View full review »The tool has several specific characteristics at the Microsoft 365 or Exchange level.
The solution could be improved with a greater analysis of its Microsoft Security score. They should be improving the visualization of data and greater coverage in Sharepoint or Teams. Its posture analysis is currently low. There could be improvement or capacity to be more efficient if we managed to achieve greater integration with Microsoft Security score, improvements in data visualization,, and greater coverage of Microsoft 365 resources.
View full review »We want to optimize the tool in the future. They should allow us to have greater integration with other security solutions and third-party tools so that the organization can take advantage of and improve the protection of all the company infrastructure.
We would like to optimize and improve its high demand for customization, which allows us to adapt to specific necessary security solutions. We want to be able to customize the solution more in order to meet the needs of our company. Currently, the solution is quite rigid and complies only with standards.
View full review »No improvements are needed. The current version has great and powerful features that take care of most sets of demands. The cloud-integrated network system can be upgraded to meet company requirements on intelligence information and for customization purposes. The set features have stable performance capability with the modern threat management network infrastructure.
This system has a capable data orchestration system that can access data from various centers. The customer support channels are reliable, with great services when contacted.
View full review »The networking system updates, when delayed, can lead to misconfigurations and data loss. The cost is high, and many businesses may not be able to support the entire package.
Poor integrations give hackers an opportunity to penetrate and get confidential information access.
Duties should be well categorized, and the right teams should be given an opportunity of handling specific data. Admins and concerned teams should map data rights in the database efficiently to avoid mishandling. The cybersecurity features have to be upgraded on time to meet the modern industrial data protection demands.
View full review »In general, some areas where security solutions could be improved include:
More advanced threat intelligence, including the ability to detect and protect against emerging threats in real time.
Improved scalability to allow the solution to handle larger numbers of users and devices without a significant impact on performance.
Greater automation to reduce the need for manual configuration and management.
Integration with other security tools and services to provide a more comprehensive security solution.
Better reporting and analytics capabilities to provide more detailed visibility into security incidents and events.
View full review »The tool works perfectly and improvements should be made, if any, in various technical and administrative aspects.
I am satisfied with the performance of this platform.
The network security situation in the company has improved since we deployed this application. The next release should be flexible and easier to integrate with other applications.
The overall performance of this application has been efficient, and I totally recommend it to other companies.
The networking process has to be simplified further to enable users to better understand how the system works.
The threat scanning system should categorize the level of threats to enhance reliable data interpretation.
The customer service team sometimes delays their response when there are emergencies that require immediate solutions.
There is a need for timely updates to meet the current technological changes in data security management.
View full review »They can improve their security features to the next advanced level so that their efficiency in catching the malware can become 100%, and there is no scope for any data loss or leakage from the system due to any issue.
The compatibility factor often poses some integration issues and consumes a lot of time for APIs. The business and tech team should be more responsive to our clientele and tech requirements, as it is critical in today's era.
The auto-remediation and risk management segment can be further researched and made more flexible and customizable.
View full review »The entire system is complicated, and the setup process may not cater to the company's demands.
Tiny misconfigurations may not be detected in advance and can easily affect performance from some cloud servers.
When the platform is overloaded with a lot of tasks at the same time, it can delay results and lead to poor security responses.
The cost is high for small businesses that have no stable revenue-generation assets.
Security and compliance posture reports created from the audited results have confirmed that we are doing well and the organization has stable security tools.
View full review »There is no full support for bot management, and the company can work on that to enhance faster service delivery and enhance reliable security checkups.
The reporting dashboard responds slowly, which leads to late report compilation. The next release can be equipped with robust dashboards and highly responsive data models.
The performance was more stable compared to a few challenges we faced, but with new upgrades, it could be even more stable.
The enhancement of cloud servers' security and management of dataflows has been a great achievement, and I highly recommend this solution.
View full review »The biggest thing is the documentation aspect of Dome9 is a little lacking. They were purchased by Check Point about a year and a half to two years ago. When they integrated into Check Point's support system, a lot of the documentation that they had previously got mangled in the transition, e.g., linking to stuff on the Dome9 website that no longer exists. There are still a lot of spaces with incomplete links and stuff that is not as fully explained as it could be. However, the product itself is really easy to use, so there is not too much of an issue with that. Also, it's not too hard to get on with the actual Check Point support to go over this stuff.
The accuracy of its remediation is a 7.5 out of 10. Before, I would have given it a ten but now, to handle remediation for fully qualified domain names, it's not working as it did in the past. We're finding some difficulties there.
Also, as soon as Check Point took over the solution, the feature that identifies and creates security groups based on fully qualified domain names, instead of IP addresses, was degraded.
View full review »The main issue that we found with Dome9 is that we have a default rule set with better recommendations that we want to use. So, you do a clone of that rule set, then you do some tweaks and customizations, but there is a problem. When they activate the default rule set with the recommendations and new security measures, it doesn't apply the new security measures to your clones profile. Therefore, you need to clone the profile again. We are already writing a report to Check Point. I think they have solution to this issue.
View full review »User interface has some latest upgrades and compared to before it is good.
For businesses with varied IT ecosystems, increasing the integration capabilities with additional third-party products and services would also increase flexibility and user-friendliness.
To further reduce the amount of manual work required by security teams, the future release could benefit from more sophisticated automation capabilities, such as automated incident response and remediation workflows.
In order to facilitate better decision-making and strategic planning, improved analytics and reporting capabilities would also be beneficial. These would provide deeper insights into security occurrences and patterns.
View full review »One of the areas that should be improved is the updates of the products. It is somewhat problematic in the area of the cloud. In the case of migration from on-premise to the cloud, it is difficult to replace the licenses. It should be something very transparent and thus save us the time to go to support but in general, the tool is shared very well in security and protection of privacy and if they are lucky they can add more features that help us our security would be great they should always be one step ahead of cyberattacks.
View full review »LD
Leo Diaz
Cloud Support at a tech company with 1-10 employees
There are a few features or improvements that can be mentioned. One of them may be that the Infinity Portal is sometimes slow. A performance improvement could improve the administrator's perspective.
At the cost level, the solution is somewhat expensive. They could have an improvement to be a more feasible solution for everyone.
The support must improve. It is the biggest issue that Check Point currently has. Sometimes it is better to investigate oneself than to wait for a solution from the support department.
View full review »The service is very complete for the functionality that it was created for, however, they can make a couple of improvements such as the validation of policies that must be available before they are implemented in the production environment. It should have some options to activate API calls to the platform in the cloud, another improvement would be that when the rules are colonized and they want to be published. They do not update as they should and the new rules are not applied. They can also try to reduce the false positives generated by the tool.
View full review »The solution's future releases would benefit from incorporating more advanced machine learning capabilities for real-time threat detection and enhanced user interface options for ease of use.
View full review »Sometimes, the solution provides us with false alerts of vulnerabilities that are not present in our cloud environment. The solution should include an auto-remediation feature, which most tools currently provide.
View full review »Every good security product requires a company with many research departments and staff. This ensures that the product is always up to date on the most relevant security threats. An excellent expert team of researchers on vulnerabilities and new cyber threats could exist.
They should start integrating AI more into the product to make it easier to use
View full review »In a general sense, it is a tremendous solution. We have got good use out of it. From what I see, it is also well-positioned in the market. I understand that it is among the best solutions.
MS
Michael Schwatzman1
Azure Specialist at a tech company with 10,001+ employees
CloudGuard CNAPP could be enhanced by increasing the number of components that run natively on Azure. This would allow Check Point to offer a forward-looking security solution that caters to customers who require a purely Azure-based environment. Currently, the mixed architecture involving on-premises and AWS deployments might not meet all compliance and security needs.
It needs to cover additional kinds of infrastructure, like containers and serverless options. It's somewhat limited in that area.
View full review »There is room for improvement, especially concerning the integration with the management center. It would be beneficial if tasks that currently require scripts could be performed directly from the GUI.
View full review »The solution needs to improve the interruptions that happen during gateway upgrades.
View full review »It cost us a little to find some information about CloudGuard Workload Protection. It cost us to find information about the tool and recommendations.
The configuration administration documentation is not very available on the web, or it is not completely updated. They should also improve the support so that we can create a case and they can respond faster. They take time to respond or coordinate a meeting since they maintain a schedule that does not fit Latin America very well. It is sometimes difficult to coordinate support hours.
They do not provide a concrete and rapid solution which causes security implementations to be delayed.
View full review »Check Point tools need to improve the latency in the portal since they take a long time to load.
They also need to improve the support a little or hire more staff since the response time is slow or the solutions take a long time to implement.
Check Point should give added value to all those customers who purchase their product by providing training so that they can certify in the tool. That way, the customer stops depending so much on support and can solve incidents themselves.
View full review »The complexity to deploy should be decreased.
View full review »The SD-WAN could be better.
View full review »The license cost is expensive and has room for improvement.
View full review »The rules are not well-tuned, and many of them generate false positives or nonsensical results. For example, they might flag port 443 as open, even though it is supposed to be open for a public web server. There needs to be a better way to exclude certain hosts that are compliant and are supposed to be open.
Especially with cloud security, there's too much clutter on the screen and too many things going on.
In a future release, we'd like to have the ability to see if there is abnormal data being transferred. We'd like to see more features coming through that allow us to act more proactively and act against vulnerabilities effectively.
View full review »Check Point solutions are not easy to use if you don't have experience. We have some Check Point specialists, so it's not difficult for us. The user experience might suffer if we don't have the time to follow up with our clients and ensure they are using the right options. Clients also want more local support in Portuguese and Spanish during their normal business hours. That's something I hear from my customers and my team, too.
View full review »The solution needs to improve remediation. We need to reduce risk by remediating gaps in security.
You do need to pay extra in order to get better support.
View full review »The security investigation features that are present have been performing excellently since we deployed this application. There are few licensing and network coverage cases, however, the customer service team is always ready to solve any problem.
Timely updates and upgrades to meet modern technological changes could help improve performance and limit the chances of downtime.
The performance has been stable for a long time since we deployed it. The few hitches which we have experienced can be solved without affecting the workflow performance.
The Check Point team has done a great job, and I recommend their products to other companies.
View full review »LD
Leo Diaz
Cloud Support at a tech company with 1-10 employees
Some general improvement characteristics can be made, including the following:
1- Cost improvement. Some tools are quite expensive, and some non-equal manufacturers offer more comfortable capabilities at the cost level.
2- The guidelines to implement or to link with the clouds are not complete. Following them sometimes the task of implementing under the best practices of the manufacturer is not achieved.
3- Many Check Point guides are only available to partners and not to the general public. They can make a better impression by having them public and thereby helping the client.
View full review »LD
Leo Diaz
Cloud Support at a tech company with 1-10 employees
Some possibilities of improvements for Check Point include:
1- Improving or creating best practices that can be generated publicly so that customers can have a package of policies, for example, that the manufacturer provides in addition to easy access to this material.
2- Improvement at the support level for management, handling and solution of cases in a better, faster, and more effective way. Sometimes the cases take a long time to be able to schedule a session and solve together with the client and support.
3- The costs are high. They could provide better costs for the client to make a simpler decision and not be affected by this issue.
View full review »LD
Leo Diaz
Cloud Support at a tech company with 1-10 employees
Some improvements that can be made to Check Point CloudGuard are the following:
1. Cost improvement. Currently, this solution is somewhat expensive. We have not really seen a solution with these characteristics and so complete. However, the cost is high.
2. There is very little Check Point documentation as it is a very new tool. Sometimes we followed the documentation, yet it was not possible to implement it in the tool, for which we had to verify with the executive of our partner to request help.
3. Support is very slow.
View full review »Effects on the network can slow down performance and lead to data leakages that can expose confidential information to cyber attacks.
The UI can be upgraded to be more presentable and solve most challenges that affect users when there are inefficiencies.
It does not support on-premise deployments such as VMware Tanzu, and this has been a major drawback when it comes to integrations with some applications.
The majority of the features have been performing efficiently, and we are happy. The development can keep on updating the platform to meet daily changes and organizational demands.
View full review »The current features have ensured that there are no cloud threats that can affect data in any way.
We have experienced the most advanced data security since we deployed CloudGuard Network Security in the organization.
A threat categorization system can be added to give users the authority to define vulnerable attacks and classify areas that can threaten the workflow system.
Working with this platform is complicated for new users. The cost of management is relatively high for small-scale businesses affecting overall performance.
View full review »We're able to validate in a logical and physical way across layers and can segment data to allow for greater reach in terms of management. In the future, we'd like characteristics to be further simplified. While today we can manage some scopes, there are still some segments in the OSI layer we cannot manage. We'd like visibility on security and perimeter management qualities in order to reach other layers of the OSI model. Right now, we don't have the scope to reach some physical layers.
When it comes to validating the power, security, implementation, and management, I would like to also have the capacity more easily on-premise as well as the cloud. Some problems have been found in analysis at the time of execution, and local install revision agents have generated management incompatibility. It is important to evaluate the applications that are on-site since they are needed in the organization. We're looking for a solution that can incorporate legacy infrastructure for some of our business needs.
View full review »The software configurations theory is complicated, and without proper planning and a well-skilled technical team, it cannot perform its tasks properly. Without effective mapping of critical areas, the platform cannot provide very good results.
The maintenance cost is high after deployment, and it requires close monitoring for effective results.
This version performs effectively when it is channeled to the right network infrastructure. It has created a centralized operation system that can comprehensively monitor and manage security for all connecting systems.
View full review »The operations require skilled manpower with extended experience of working with networking systems for better results.
The cost depends on company size, and licensing terms are not favorable to small-scale businesses.
The good sides are many from my experience, and I could recommend it to any growing company that requires the best-performing network security. From the first deployment, we have experienced improved and secure network infrastructure. We have been working closely with the customer service team, and there is no situation that has led to negative objections.
A combination of on-premises and cloud computing services under one interface could enhance simple and comprehensive monitoring.
They can integrate tools with policy recommendations and notification alerts on when to remove specific objects of the user's choice.
View full review »The product's support team, the UI, and the user interface can be improved.
View full review »Currently, I would like this solution extended to cellular devices or tablets. This will be able to allow us to be more efficient.
The solution is not that flexible when deploying on-prem.
View full review »I would like an interface more adapted to cell phones or tablets. In its web version, it is quite efficient, however, I would like this improvement and the possibility of action to be able to enjoy and manage even the identity and administration under applications optimized in said function - whether they are iOS or Android.
Another feature that I would like is being able to carry out more frequent assessments on the solution with direct Check Point teams.
View full review »I strongly advise that the multi-layered security system of Check Point often undergoes updates and new versions keep coming. It is absolutely fantastic and is worth admiring. Every now and then, we feel that their team's training and orientation process on orienting the clients and partners is low and needs to be strengthened so that every single individual is completely aware and informed of the features and their utilities. They are not clueless in utilizing the services to their maximum. We just need more focused training.
View full review »We really believe in ongoing improvements for emerging business needs. The business and product development team should introduce a high-end feedback collection mechanism and analyze the customer requirements constructively.
The feedback mechanism is best to understand the user and market needs. All kinds and sizes of businesses should be approached to provide feedback so that unanimous decisions and unbiased reviews/feedback can be collected.
Also, more customized strategic pricing can be involved and introduced so that more and more businesses can be attracted for trial and usage of the software.
View full review »Check Point CloudGuard Network Security could improve by making it easier to configure.
In a feature release, the application should be more drag and drop. If I could search it and drag and drop it to the specific rule it would be helpful.
View full review »SB
Schillebeeks Bart
Owner at AD Internet Consulting
The false positives can be annoying at times.
The solution from my experience is very good. What I would like for future updates would be faster updates to apply, and perhaps a greater presence in the local language for the regions of Latin America. These are markets that have been growing, however, the teams need a lot of time and training and in that period a specialized technician in the local language is required to support the constant requests. After that, I accept that Check Point surprises me as it has always done with its excellent work in innovation.
View full review »OP
Oleg Pekar
Senior Network/Security Engineer at Skywind Group
As an administrator, I can say that among all of the Check Point products I have been working with so far, the Virtual Systems solution is one of the most difficult. You need to understand a lot of the underlying concepts to configure it, like the virtual switches and routers it uses underneath. That leads to additional time needed for the initial configuration if you don't have previous experience.
In addition, there is a list of limitations connected specifically with the virtual systems, like the inability to work with the VTI interfaces in a VPN blade, or an unsupported DLP software blade.
In general, we abandoned this solution this year.
Each component of this solution, in my opinion, could be improved.
Integration with ticketing systems, as well as the most important noise and completeness over findings, are definitely in need of improvement. They didn't take into account some additional context.
The UI is very slow.
There is room for improvement. Consider the entire context of the findings and try to avoid making a comparison between the rule and the entity's state. In general, for the product to be successful, they need to improve security, and configuration detection.
View full review »To be honest, we don't have many clients who have taken CloudGuard, as the feedback has not been that great. There are a few clients who have taken the CloudGuard due to the fact that there is a lot of competition in terms of endpoint protection from Trend Micro and other leading vendors.
There are few clients who have CloudGuard and the response is quite positive. However, it comes down to dealing with the challenge of when the client needs both protection for workstations and their physical and virtual servers. With Check Point, we don't have that ability. They have just CloudGuard, which protects the workstations and servers. With other vendors, there's a separation between the endpoint protection for workstations and for the servers and then something else for the virtual environment. The challenge comes in when you're trying to propose this to the client. They'll ask you how they can be sure that this will protect their virtual or physical data centers collectively, and also protect the workstations.
Most clients nowadays tend to move to the cloud and their data security is key. If CloudGuard could be able to give the client that full visibility of how their data is protected on the cloud, then that would be a great selling point for Check Point.
Generally, visibility is the issue. Clients really just need more visibility to know they are protected.
View full review »CloudGuard could be more customizable. It has built-in standards for things like GDPR compliance. But depending on your business lane, you might want to build your own controls based on your own standards.
Almost all features are good, however, they still require improvements to the code security portion on which integration with the major source code repository is required.
Integration with CI/CD is an important aspect as it is needed to secure the environment. Having it will help a lot.
Integration with Docker is also a key feature that needs some improvements.
Integration with other third parties and with SIEM is an important aspect that should be addressed.
Currently, it provides integration with Tenable, but it would be good if it had support other VAPT software as well.
View full review »In the first phase, Cloud Guard Firewalls didn't allow minor and major upgrades. Fortunately, now you can install normal hotfixes and minor upgrades (JHF) on the Cloud firewalls. For major upgrades, it's still necessary to destroy the VMs and re-create them again. Doing that would mean new public IPs as well. We created a script for that. I still hope that major upgrades will be possible in the near future too, otherwise, you still have to script a lot for basic maintenance, instead of using tools like CDT.
View full review »The following things can be improved:
- Reporting should have more options.
- Investigation of security events should be more comprehensive be it for cloud activity or traffic activity.
- The false positives can be annoying at times.
- We do not use remediation at the moment. We do the remediation manually, since we are still using Dome9 in read-only mode. I don't know if we will use the remediation in the future as we prefer to do it ourselves.
- The price of this solution should be reduced so that it is more affordable to scale.
Throughput is impacted drastically once the security modules are enabled on the firewall.
As it is a software-based firewall, there is no dedicated throughput available for each module.
In case the device is inaccessible due to some issue such as CPU or memory, there is no separate port or hardware partition provided for troubleshooting purposes.
Throughput on the virtual firewall is an issue in case the organization wants to migrate a workload to the cloud, and it becomes a bottleneck.
BD
Basil-Dange
Chief Information Security Officer at Abcl
There are several things in need of improvement, including:
- Policy validation should be available before it is deployed in a production environment using a cloud template.
- Auto remediation requires read/write access. As providing read/write access to third-party applications can add risk, it should have some option of triggering API calls to the cloud platform, which in turn makes the required changes.
- A number of security rules need to be added in order to identify more issues.
- Reporting should have more options.
- It should support all container platforms for visibility of complete infrastructure using a single console such as PCF .
BD
Basil-Dange
Chief Information Security Officer at Abcl
System hardening could be improved, as password complexity is not enforced by default on root / command-line passwords.
The documentation provided by Check Point can be rough and needs to have a lot more detail incorporated in order to help the implementor and administrator.
The HA failover time is not as fast as expected and due to this, the convergence time between cluster members is still not perfect. Consequently, there may be an issue in migrating the mission-critical business applications.
Micro-Segmentation functionality for EAST-WEST traffic is not native and requires integration with a third-party OEM.
View full review »The tool has a lot of potential, but today, it lacks a lot of Scripts/Bots for Azure. This is one of the main cloud providers, so it's imperative to make this a priority in order to bring a lot of value to this tool.
The idea is to leverage Dome9 as the main central place for auto-remediation of all cloud environments so that customers don't have to spend a lot of time manually remediating. Manual remediation is very challenging once you have so many cloud accounts to support on a regular basis, and Dome9 can help do part of the job.
View full review »KP
Kirtikumar Patel
Network Engineer at LTTS
In Dome9, there should be a policy validation option where we can validate the policy before we push it into production. This option is very important, as we are working in a critical and complex environment. This option would give us more confidence in our activities or policy pushing.
We could see the option is available for on-premises devices.
Automatic remediation requires read/write access.
Otherwise, overall this product is very good for our cloud environment, and we are satisfied with this.
View full review »The room for improvement wouldn't necessarily be with CloudGuard as much as it would be with the services supported by Check Point. A lot of the documentation that Check Point has in place is largely because of the nature of the cloud. However, it is frequently outdated and riddled with bad links. It has been kind of hard to rely on the documentation. You end up having to work with support engineers on it. Something is either not there or wrong. Some of it is good, but frequently it's a rabbit hole of trying to figure out the good information from the bad.
We use the solution’s native support for AWS Transit Gateway and are integrating it with the Auto Scaling piece now, which is a big portion of it. One of the issues with using the AWS Transit Gateway functionality is that setting up the ingress firewall can be more of a logging type function, as opposed to doing pure, classic firewall functionality. This is with the design that we are using with the Auto Scaling. However, AWS announced about two weeks ago that they have a new feature coming out that will effectively enable us to start blocking on the Check Point side, and with our previous deployment before, we weren't able to do that. While the Check Point side is fine, the functionality that AWS allowed us to use was more of the issue. But now that changes are occurring on the AWS side, those will enable us to get the full use out of the things that we have.
View full review »GF
Genesis Floresta
Senior System Administrator at a tech services company with 501-1,000 employees
We did not use the AWS Transit Gateway, and that's one of the things that we're currently using. I believe we will be working with Check Point again, in the near future, to implement it, once they start having proper support for a single customer with multiple accounts. When we were using them, we had to install Check Point on each and every single account.
I believe they're working on a solution for that. I know they're utilizing Transit Gateway for it, and that is exactly what we're using right now. I'm excited for them to have that ready, and for us to put it in our system.
In general, cloud infrastructure or a cloud-based environment, is very fast when it comes to technology. Things get developed right away. Check Point just needs to adapt to those changes quicker.
View full review »CloudGuard functions just like any other firewall. It functions very well. The only thing that could maybe be improved would be to integrate some tools that are not integrated with the SmartConsole, like the SmartView Monitor that we need to open on a different application to access.
View full review »Clustering has not been perfect from the very beginning. There weren't too many options for redundancy. It was improved in later versions, but that's something which should be available from the very beginning, because the cloud itself offers you a very redundant model with different availability zones, different regions, etc. But the Check Point product was a little bit behind in the past.
The convergence time between cluster members is still not perfect. It's far away from what we get in traditional appliances. If a company wants to move mission-critical applications for an environment to the cloud, it somehow has to accept that it could have downtime of up to 40 seconds, until cluster members switch virtual IP addresses between themselves and start accepting the traffic. That is a little bit too high in my opinion. It's not fully Check Point's fault, because it's a hybrid mechanism with AWS. The blame is 50/50.
View full review »AT
Alex Tremblay
Cyber Security Manager at H2O Power Limited Partnership
The biggest room for improvement is that, for a long time now, they've moved everything over to R80 but they still maintain some of the stuff in the old dashboard. They need to "buy in" and move everything to the modern dashboard so that you don't have to go to one place and to another place, at times, to configure the environment. It's time they just finish what they started and put everything in the new, modern dashboard. I thought they would have done that by now. It has been years. It's always a little disappointing when you get a new version and you see that it's still using the old dashboard for some of the configuration and some of the stuff that you look at.
They just need to make sure they get all their tools into this one place. It would make it a lot easier for the managers.
View full review »BD
BasilDange
Sr Manager IT Security at a financial services firm with 10,001+ employees
- Policy validation should be available before it is deployed in a production environment using a cloud template.
- Automatic remediation requires read/write access. When providing read/write access to third-party applications, this can add risk. It should have some options of triggering API calls to the cloud platform, which in turn, can make the required changes.
- A number of security rules need to be added in order to identify more issues.
- The reporting should have more options. The reports should be more granular.
- It should support all container platforms for visibility of a complete infrastructure single console, such as, PCF.
1) More number of Security Policy to have more number of detection
2) It should capture more information in metadata including communication detail. Also, Internal IP addresses should not be tracked as this might be having some compliance issues.
3) Should have support for VMware Pivotal Cloud Foundry
4) Should maintain configuration information which will help in case forensic need to be performed in term of changes
5) Should allow Policy to be deployed using a template and the same should be getting reviewed before deployment. This will help us to provide secure deployment CI/CD
View full review »Improvements can be made to the user interface, performance and reliability, security and compliance, and customer support.
View full review »CloudGuard CNAPP is a great tool that justifies its investment. Like any other tool, there are opportunities for improvement that can be addressed through a roadmap.
In the next release, including VRF support would be highly beneficial. Many customers have been requesting this feature, as it is currently lacking in Check Point's offerings, which can make architectural designs more cumbersome compared to competitors.
The connection to the on-premises management requires using the CLI. It's not just a click, and you cannot edit in the management to prepare everything. You need to do it online and in real time. After that, you must execute a script, and then you should be happy that it appears in the management.
View full review »We have the product deployed on Azure China. One crucial concern is the version limitation; unfortunately, in Azure China, we are restricted to running version R80. Our architecture has a Load Balancer, VMSS CloudGuard, etc. The duplication in this setup prevents the application from seeing the original client IP. This poses a problem for certain applications that require the original IP for login purposes. Although we managed a workaround with a different architecture involving a WAF, it is not as straightforward as the standard Azure setup.
View full review »When upgrading the firewall, the old VPC containing the firewalls needs to be destroyed. After that, a new firewall is redeployed in the setup. Additionally, there's a need to separate the routing, and the routing from the old VPC has to be recreated in the new one.
Clustering in Azure is a bit different, not using the Check Point cluster but relying on load balancing. It's not as instant as I'm used to; in Azure, it might take around half a minute to a minute, and during this time, services could be down. The delay is attributed to Azure using its load balancing mechanisms instead of the Check Point cluster.
View full review »The product must provide different features like antivirus.
View full review »The dashboard customization has room for improvement.
View full review »There are some usability issues we'd like to see improved.
We're going to be switching to XDR and would like integration with XDR.
View full review »I'd like to see more advanced encryption for local features, which is not present right now. We'd like to have more defined control when implementing intelligent analysis on the cloud. We'd like to extend analysis not just to crowds but to local teams for more granular analysis and advanced searchability.
GD
Gordan Daut-Kaiser
Cloud Security Architect at Kontex
The security of Check Point CloudGuard Posture Management could improve. There are always new security issues coming out.
View full review »CD
ChrisDagal
Enterprise Security Lead at a financial services firm with 501-1,000 employees
The cost is a little high, it doesn't suit every budget. I'd like to see the ability to integrate with other security solutions which is not currently possible. If you need to integrate, you have to buy a Check Point product as well so you're paying for features.
The technical support could be better, but I do not know of any other needed improvements.
View full review »CloudGuard could be improved by including integration with vendors other than AWS, especially Azure, especially in permissions. In the next release, I would like them to include some kind of online scanning on code in the development phase.
View full review »What could be improved in this product is its architecture. Its user interface also needs improvement.
The user experience, particularly in the implementation, management, and operations of this product, also needs to be improved.
Operations management is difficult in Check Point CloudGuard Cloud Network Security.
VK
VinodKumar8
Cybersecurity Architect at a computer software company with 201-500 employees
The solution could improve to have a DLP feature.
View full review »CD
Chris Dagal
Senior Consultant at a tech services company with 11-50 employees
I would be great to have additional features when it comes to vulnerability assessments in terms of how the solution discovers vulnerabilities or compromised workloads and not just on security configurations with customizable reports would be nice.
View full review »
Today, globally, there are many companies of all sizes that do not understand the value of their data, but even with all the existing clouds, they also do not understand what the shared responsibility model is. They only assume that by having a cloud, the provider must ensure security, when the truth is that providers only protect their sites. Everything we do in the cloud and how we configure it is actually our responsibility, in this sense we can evaluate many solutions that help us protect our clouds, however, and after trying 5 different solutions, the checkpoint solution is by far The most complete
View full review »
CheckPoint CloudGuard could be better at solving cases. In many cases, the client should be able to request or obtain a sufficient explanation or to obtain an appropriate answer. Check Point should improve the queue clients need to go through to obtain access to direct support chat. This should be for users with privileged access.
CheckPoint features that should be included in the next release include the possibility to create a cluster on AWS and a Multi-region Cluster. They need to also include the possibility to use a managed web portal.
View full review »I'd like to see improvements with the configuration.
View full review »In terms of what could be improved, we have no support with the current Check Point environment. It ended maybe three or four years ago. Because it's an appliance you have to have support. That's a problem for us because I cannot update it at the moment. We have to have another support. We have to subscribe to another support so I can update it. I think it's a good amount of money and our boss does not want to pay that kind of money for firewall solutions. It's not a hardware solution, which by the way, if it would be up to me, I would migrate it to a hardware FortiGate system because all our customers at the moment are migrating their environments to FortiGate hardware solutions. They say it's a really good improvement from their previous firewall solution because it's easy to manage and they're very happy with it.
But as I said before, my boss does not want to pay a lot of money for a firewall solution since we don't have much data to protect and the data is not very important. It's not a big use for us. So we will just probably try pfSense or OPNsense. I can patch it to an up-to-date version, like the 2021 patch. We have the open source solution because my boss does not want to pay for it. It's my approach to migrate the firewall, actually. If it was up to me, I'd probably migrate it to a FortiGate system.
I'm not very experienced with Check Point. But what I would like to see is a step-by-step initial installation of the firewall. That would be really helpful. Like in Oracle appliances, when you start it asks you, what's your current IP address? An initial setup should be a step by step and intuitive process. You click on "begin," it asks you some simple questions. You fill in the blanks - your current IP address, what you want to do, if you want to set up a site to site VPN, for example, that kind of thing. That would be the smartest thing to have.
View full review »The initial setup is complex and could be made simpler.
The console could use some improvement.
View full review »PD
PRAPHULLA DESHPANDE
Associate Consult at Atos
I would like this product to provide functionality like a web application firewall, where we can fully monitor all traffic passing both to and from the cloud.
The latency should be minimized by having multiple entry points all across the world. Nearby requests will have lower latency access to cloud applications.
It would be useful to have AD integration with an on-premises server.
The API integration is complex, which is an area that should be improved.
Onboarding this product takes some expertise because it is complex compared to other services that Check Point provides.
View full review »The clustering and HE from the scaling availability could be improved.
The documentation could be much better as well.
View full review »AG
AnkG
Team Leader - Security at a tech services company with 10,001+ employees
Easier optimization techniques can definitely help with better performance of the OS, as using the vanilla software doesn't actually showcase the real capability of the software.
While there is a lot of documentation available on Support Center to understand how the solution works, it can become quite confusing. Some free training videos by Check Point would really help the engineers who don't have full access due to restrictions/unseen reasons.
A step-by-step guide for leading CSPs would really help.
Auto Scaling should be given as an option during a first-time installation, as it would be really beneficial and some users might not be aware of it.
View full review »We're looking forward to the next Check Point with the solution and CloudGuard and everything on the same single cloud. Right now, that's not yet the case.
We're expecting more new features in the next release, however, I'm not sure precisely what is being added.
Check Point support, beyond CloudGuard, does need some improvement.
View full review »OP
Oswald Polo
Electronic Engineer at eBTel Cia. Ltda.
The capability and the response, in terms of the time of response of the transactions, is very important for my customers. It's something they need to continuously work on to make it better.
The memory and hard disk capability could be strengthened.
The product should integrate next-generation firewall features such as anti-spam and anti-spoofing.
View full review »Check Point Virtual Systems is a complete solution, but pricing can be better.
View full review »The solution lacks the capability to scale effectively.
View full review »This application can be more integrated with web application firewalls. Better integrations would provide more granularity, which would be helpful for focusing on the application itself and preventing attacks.
It would be good to include the cross-domain search. If you have multiple firewalls that are managed on the same platform and you want to check who is using some particular objects or where a specific ID is being used, it should provide an option for this kind of search instead of having to check one by one on each firewall.
View full review »OP
Oleg Pekar
Senior Network/Security Engineer at Skywind Group
We were demotivated by the lack of native automation modules for the Terraform and Ansible tools. We think that in the era of the DevOps approach and practices, all the new products need to be released with such support, mandatorily.
In addition, we also hope that the Dome9 will eventually support the other Public Cloud platforms, like Alibaba, since we are planning to expand to the Asian market. Alibaba is the big player in this region due to the fact that Google Cloud and AWS are almost banned.
OP
Oleg Pekar
Senior Network/Security Engineer at Skywind Group
As with other solutions of this kind, you still have to manage basic cloud firewalls and routes for VPC outside of CloudGuard IaaS. There's no 100% integration.
I hope that Check Point continues to improve its technical documentation regarding the Check Point CloudGuard IaaS gateway and management system. For example, the questions on how to scale the instances in the relevant cloud should be covered, and all the High Availability options and switchover scenarios. Without that, users have to open numerous consulting cases to the support team to get it right.
RT
RajivT
Senior System Engineer at a energy/utilities company with 201-500 employees
I think they have pretty much mastered what can be done. There are some nuances like when you fail over from one cluster member to the other, the external IP address takes about two minutes to fail over. During this time there is an outage of service. On digging into this further I found that this is more on the cloud fabric and provider side than the actual Checkpoint CloudGuard side. The Cloud provider is taking that long to actually detach the Virtual IP Address (VIP) from one machine and fail it over to the other
View full review »MP
M Poczobut
CISO and Senior Director Technical Operations at a insurance company with 201-500 employees
It's meeting our needs at this time. If I could make it better, it would be by making it more standalone. That would be beneficial to us. I say that because our current platform for virtualization is VMware. The issue isn't any fault of Check Point, it's more how the virtualization platform partners allow for that partnership and integration. There has to be close ties and partnerships between the vendors to ensure interoperability and sup-portability. There is only so far that Check Point, or any security vendor technology can go without the partnership and enablement of the virtualization platform vendor as it relies on "Service Insertion" to maintain optimal performance.
We are frequently in contact with Check Point's Diamond Support, Product Development Managers as well as their sales team, as we look to keep apprised of where the product ius and should be going. Most of our requests have been around our physical assets, the physical UTM devices — Check Point Maestro, as an example — as well as their endpoint systems. There has not been anything at this time where we've said, "We wish CloudGuard did X differently." CloudGuard, in my opinion, having recently talked with them, is continously improving and is incorporating some of their recently acquired capabilities, such as Dome9 cloud compliance. Those are areas I have been evaluating and looking to add to my environment. My preference would be that it be included in my CloudGuard subscription licensing, and not an add-on; But that's the only thing that I could say that would be beneficial to us as an enhancement to the system.
View full review »There is definitely some improvement required. We currently use a deployment template provided by AWS each time. If I want to clean up the IaaS I have to use the IaaS template which should not be necessary. Secondly, because it's zero touch, I cannot write up any rules in the firewall. I understand these features might have been built particularly for zero-touch but from the perspective of a network and firewall engineer, some independence to configure something on the firewall would be appreciated.
An additional feature that could improve the solution would be to enable both automatic and manual control that would allow the engineer complete control over the firewall.
NG
Naveen Govindappa
Solution Architect Cloud Security at a tech vendor with 10,001+ employees
Dome9 should also support deployments that are on-premises and in a hybrid cloud.
This solution needs DLP support.
View full review »We would like to be able to scale out such that we can increase performance within a cluster with more active nodes.
Our biggest complaint concerns the high resource usage for IDS/IPS, as we cannot turn on all of the features even with a recent hardware upgrade.
A great enhancement for this solution would be an active-active or multi-active scalability.
As we need to fulfill higher bandwidth demands due to increased cloud usage and research-driven data exchange, we might need to look for other vendors with more competitive pricing.
View full review »If you compare the GUI with the Palo Alto and Cisco, they're very easy. Check Point, due to its design, is a little bit complex. They should make the GUI easy to use so that anyone can understand it, like Fortinet's GUI. Many companies end up using Fortinet because the GUI is very easy, and there's no need for training. They just deploy the box and do the configuration.
Also, we have to inform customers that with Check Point there's no need to purchase any routing device. Check Point can do that routing as well as the Firewall and the IPS. The marketing should be stronger, to show that customers only need one box to handle all the features. It will be cost-effective and enhance the performance and value, but because of their poor marketing, customers don't realize this.
In the future, a color string would be powerful. Sandboxing should also be offered. Many people want the Trend Sandbox but not on the cloud. In the Middle East, there is a policy for Sandboxing that states it should be on Trend as per the government law. They have Sandboxing solutions on the cloud, but they have to bring the solution onto Trend also. Palo Alto has Wildfire, Cisco has Talos, and Forcepoint has one available as well.
In the future, routing protocols should be more supported like OSPF and BGP. There needs to be integration with the SDN. I don't know if SDN is there or not in Check Point, but SDN is one of the major requirements nowadays.
View full review »SS
Siju Siju
Assistant Manager IT Projects at Mustafa Sultan Office Technology Co. LLC
The knowledge base that is available is limited and it is on a closed network where only a customer or certified engineer will know about it. A beginner who wants to learn about the product actually has to enroll in training or get certified and have a valid license or certification to access information. That is something I find strange as most users would like to know about it. The new users would like to be able to see those areas and what type of concerns or any configuration issues they may have before deciding to work with the product. To me, that is a simple open-mindedness. In terms of the availability of the system and functionality of the product, there's no concern. But the problem is that efficient VSX (Virtual System Extension) deployment is complicated. Most of our customers are afraid to deploy any configuration changes because they are afraid something will happen.
It's not the same situation as with other products. I guess the reason behind it is the kind of architecture which they are using. There are more possibilities to crash than other products. That is the feedback I normally get from end-users, but even so, for us, I would say it's one of the best product.
View full review »Reporting needs improvement. It's difficult to utilize properly. Currently, I'm in a situation whereby a client of ours is looking for reporting on their organizational unit. Check Point has failed to do that. We've been trying to do it for the past month and we haven't been able to. We've also gotten techs from Check Point to call us to help and we just can't get the solution to do what we need it to do.
Sometimes, if you aren't familiar with the solution, it can be a bit complex, but it does become easier to use with time. However, every time they launch a new version, it becomes more complex and you need to take time to get familiar with all the changes. For every version that they upgrade, you need to upskill yourself.
View full review »The stability of the solution could be improved, but this is the problem of all the solutions in the market. This isn't just a problem specific to Check Point.
View full review »I would like to see an improvement on the zero-day threat detection. It is also not very user-friendly, so it would be great if it could be less complicated and easier to operate. The dashboard needs to be easier to use.
Also, if the solution could be cheaper, it would really help, because it is very expensive.
I would like to see sand boxing added to the new version.
View full review »The management console can be simplified because at the moment, it is a bit of a challenge to use.
I would like to see support for software-defined wirings in the next release of this solution.
View full review »Integration with other security tools would be of benefit.
I would like to see some AI on the back-end, just to assist with doing analysis and making recommendations.
View full review »YY
Yasdy Yasin
Cloud Infrastructure Architect at Maxis Berhad
I would like to see Test B functions at the application access level.
The product can still grow.
View full review »I would like to see more focus on east-west traffic inspection and AWS.
Things are changing very quickly in the cloud. There is a lot more maturing that needs to happen as far as CloudGuard goes, specifically more around some cloud native type situations where everything is being shoehorned through one or multiple VMs is not optimal.
View full review »RR
Rakesh Rawat
Network Engineer at Acliv Technologies Pvt Ltd
I would like for them to develop guides. If you compare it with Cisco, you can just type out any problem you're having regarding Cisco and you will easily get a solution. With Check Point, it's not easy to get a solution.
View full review »Having a web UI in the VSX (or something similar) would be nice. However, you can do everything in the CLI.
View full review »EI
ElieIfrah
Cloud & DevOps Team Leader at a tech company with 501-1,000 employees
I’d like to see more integration with third-party tools. For example, it would be helpful to have an integration between Dome9 and ServiceNow to manage security incidents and security changes.
View full review »Dome9 continues to enrich its features at a blazingly fast pace. I would like to see tighter integration with other compliance tools, like Chef Compliance, in addition to Inspector. Also, I would love to add more richness to the Splunk add-on for Dome9.
We have Microsoft CASB cloud app security and it's one of the least compatible firewalls. They really need to look at this, as both Check Point and Microsoft are major players. Why aren't they compatible? If we had Palo Alto then we wouldn't have this problem.
View full review »It is somewhat difficult to upgrade the entire hardware without downtime.
View full review »The governance and compliance areas are becoming very useful, and continue to expand in very user-friendly ways. Addressing the large amount of compliance information and benchmarks we need to observe, the tools are becoming our goto dashboards.
View full review »VS
VikasSharma
Senior Security Engineer at a financial services firm with 1,001-5,000 employees
Each new version does offer a new set of features plus also incorporates bug fixes identified during the life cycle of the previous product. Hence, this product keeps on maturing as newer versions are released.
View full review »
At the beginning the design can be overwhelming, where to start
Getting used to the CLI syntax but do-able
View full review »
Areas for improvement include other Security Features like AntiVirus, AntiSpam, DLP etc.
View full review »
The challenge mainly revolves around the slower functionality of virtual IP switching in Azure Virtual Network compared to on-premise solutions. On-premise, switching between clusters is faster, taking only a few seconds, while in Azure, it can extend up to five minutes. The downtime is a concern for us.
View full review »Buyer's Guide
Check Point Cloud Firewall (formerly CloudGuard Network Security)
September 2026
Learn what your peers think about Check Point Cloud Firewall (formerly CloudGuard Network Security). Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,322 professionals have used our research since 2012.








































































































