What is our primary use case?
We use the Check Point IPS module on various firewall gateways. Specifically, we use the IPS on our DMZ firewall gateway to protect our DMZ servers from the inbound Internet traffic.
For our user outbound Internet traffic, we use the IPS and the anti-virus anti-bot modules, in addition to the base IPS module to protect the network traffic.
We also apply the product to our guest firewall gateway to monitor outbound internet traffic, with a focus to avoid any malicious guest users using our guest internet services to launch attacks.
How has it helped my organization?
The Check Point IPS module offers protection against malicious inbound Internet traffic to our DMZ network and inspects and blocks outbound Internet traffic to sites that could be a danger to our internal users.
We have configured the Check Point IPS modules so all the downloaded updates would turn to monitor-only mode. Once the updates have been in use for a couple of weeks, then we would review the IPS signature, and turn them into prevent mode based on factors such as the severity of the vulnerability, the performance hit to the firewall gateway, the chance of false positives, and the relevance to our environment. This allows us to easily maintain up-to-date network protection with a lower chance of unexpected business interruption.
What is most valuable?
The mechanism where you can let the system automatically turn the IPS signature to a different mode (prevent / monitor / inactive) is a nice feature that allows us to easily adjust the balance between security protection and the risk of business impact.
It is also worth noting that many IPS signature comes with detailed background about the vulnerability, and potentially how the vulnerability would affect the network security.
Also, you can easily search through thousands of IPS signatures using various keywords is another feature worth noting.
What needs improvement?
Out of the box, the number of built-in reporting and dashboards related to the IPS logs and events has room for improvement. The dashboard reports can be easier to generate and customize.
It would also be nice if the system would allow some form of alerting when specific signatures have been triggered X number of times within Y amount of time. This would allow us to be better notified when there is a security attack going on, without too much of false-positive alerts.
Another would-be-nice request is to have more details information about how the signatures would detect the specific security vulnerability. This allows us to make a judgment about how useful a particular signature is in our specific environment.
For how long have I used the solution?
I've used the product for over ten years.
What do I think about the stability of the solution?
The stability should be high as we don't have many issues with the IPS solution. In the last couple of years; we only had one issue due to a bad signature.
What do I think about the scalability of the solution?
We have not observed any major performance hit to the firewall gateway by enabling the IPS module. Of course, some signatures did indicate a high-performance hit to the gateway, in which we typically won't turn on those signatures unless there is a strong need.
How are customer service and support?
Good technical support is by chance/luck. Sometimes you run into good tech support. Other times you may run into someone that doesn't know much more than yourself.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We also have extensive experience with the Cisco Firepower solution. We actually use both solutions in our environment.
How was the initial setup?
The initial setup is pretty simple so long you just follow the default steps, without too much worry about going through the thousands of signatures manually.
What about the implementation team?
What's my experience with pricing, setup cost, and licensing?
With Check Point, the IPS license could be bundled with the firewall product and so the license cost is not huge.
It does take time to get familiar with the UI and understand the "workflow" that Check Point has in mind when designing the solution. A good understanding of this would allow an easier adoption.
Which other solutions did I evaluate?
We use both Check Point's and Firepower's solutions in our data center.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.