No more typing reviews! Try our Samantha, our new voice AI agent.
Voice and data infrastructure specialist at a tech services company with 1,001-5,000 employees
User
Oct 17, 2021
Easy to configure and setup with good scalability
Pros and Cons
  • "Check Point Intrusion Prevention System has great profiles, and we can continuously create, modify, activate, deactivate or configure any specific setting to allow the profile to focus on just one thing or for certain attacks."
  • "Now that the Check Point Intrusion Prevention System has improved our environment, we feel that we are more protected in our network."
  • "The cost is a bit high but it is worth it."

What is our primary use case?

The Check Point Intrusion Prevention System can block traffic from any source workstation inside our local network and facilitates the analysis of outbound traffic to check if there is any risk in the internal network in order to protect our clients and servers. With this product, we're creating a secure zone. We currently are using this blade in our hybrid environment and it's integrated with our secure gateway. Most of the time, our NOC team continuously monitors traffic in order to find any suspicious activity.

How has it helped my organization?

Now that the Check Point Intrusion Prevention System has improved our environment, we feel that we are more protected in our network. By implementing the recommendations that Check Point has given us, we have an optimal security environment now that provides almost real-time detection and prevention. We are protected by the Intrusion Prevention System and can go back and select any period or severity in order to display the latest statistics.

What is most valuable?

Check Point Intrusion Prevention System has great profiles, and we can continuously create, modify, activate, deactivate or configure any specific setting to allow the profile to focus on just one thing or for certain attacks. I also like that profiles can be applied to groups of workstations that need to be more protected from possible attacks. Each profile that we create has activated protections and some instructions of what the IPS should do with the traffic.

What needs improvement?

At the moment, I do not see what else can be added to this service. In my experience, I've seen that it has what we need without something additional being required. 

It is easy to use, easy to configure, and practically updates itself without the need to intervene as an administrator of the appliance. We are happy with this platform since it allows us to have security and control over the connections almost in real-time. There are many different services that Check Point Intrusion Prevention System has that are quite useful.

Buyer's Guide
Check Point IPS
September 2026
Learn what your peers think about Check Point IPS. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,322 professionals have used our research since 2012.

For how long have I used the solution?

I've been using the solution for about four years.

What do I think about the stability of the solution?

I've found the stability to be good.

What do I think about the scalability of the solution?

The scalability is great.

How are customer service and support?

Technical support has been great,

Which solution did I use previously and why did I switch?

I did not previously use a different solution.

How was the initial setup?

The initial setup was not complex. 

What about the implementation team?

We handled the implementation process in-house.

What was our ROI?

I've witnessed a 40% ROI.

What's my experience with pricing, setup cost, and licensing?

The cost is a bit high but it is worth it.

Which other solutions did I evaluate?

I did evaluate other options before choosing Check Point.

What other advice do I have?

So far, I have no regrets about choosing this solution.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
User
Oct 14, 2021
Easy to use, stable, and allows flagging if patterns are detected
Pros and Cons
  • "IPS easily allows follow-up flags on recently updated patterns. If, in rare cases, a false positive does occur, it is quickly detected and an exception can be easily created."
  • "Basically, it is easy to use and offers a wide variety of protections through all kinds of software, services, appliances, and IoT-Devices."
  • "I am not aware of a preview channel or some repository to have a preview on upcoming signatures, however, this would be nice to have."
  • "In some cases, I would have liked the updates to be faster."

What is our primary use case?

IPS is part of our Check Point Firewall Solution and a key function in securing our infrastructure. It is good to have an instance already on the gateway that protects specific services from attacks.

Very often, patch installations and downtimes cannot be implemented immediately in the case of critical security vulnerabilities.

IPS helps to secure short-term security vulnerabilities with its regular signature updates. The variety of products being covered is always impressive.

IPS is a key instance to secure services behind our Gateway.

How has it helped my organization?

Online attacks and malware have been evolving, using sophisticated and even evasive attack methods. Check Point addresses the changing threat landscape while meeting several key operational requirements for Intrusion Prevention Systems. Check Point IPS protections include checks for protocol and behavioral anomalies which means they detect vulnerabilities in well-known protocols such as HTTP, SMTP, POP, and IMAP before an exploit is found.

If you have any doubt if an update might interfere with any of your services, you can just mark it as "detect only" and observe how it behaves.

What is most valuable?

IPS easily allows follow-up flags on recently updated patterns. If, in rare cases, a false positive does occur, it is quickly detected and an exception can be easily created.

Basically, it is easy to use and offers a wide variety of protections through all kinds of software, services, appliances, and IoT-Devices. Updates are available regularly and can be easily downloaded and deployed through all the infrastructure. Rollback is easy to perform if ever something happens. It is a must-have on each gateway.

What needs improvement?

Usually, new signatures for known vulnerabilities come very quickly. In some cases, I would have liked the updates to be faster.

I am not aware of a preview channel or some repository to have a preview on upcoming signatures, however, this would be nice to have.

There is not too much else I am missing on Check Point Intrusion Prevention.

For how long have I used the solution?

We've used the solution for years now.

What do I think about the stability of the solution?

We have no concerns at all when it comes to stability. 

What do I think about the scalability of the solution?

We've never reached a performance limit.

How are customer service and support?

Technical support is responsive and helpful.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I've worked with Check Point for years now.

How was the initial setup?

The setup process is straightforward. I'd recommend others join a CCSA training to cover the required knowledge.

What about the implementation team?

We implemented through our vendor and they were very experienced.

Which other solutions did I evaluate?

I've worked with other vendors before - however, of those that I've used, I found they didn't offer the whole package under one admin console.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Check Point IPS
September 2026
Learn what your peers think about Check Point IPS. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,322 professionals have used our research since 2012.
it_user1670154 - PeerSpot reviewer
Firewall Engineer at a logistics company with 1,001-5,000 employees
User
Oct 4, 2021
Scalable with convenient pre-defined profiles and an easy setup
Pros and Cons
  • "IPS signatures can be set quite granularly depending on your environment. You can filter on performance impact, severity, and confidence which makes sizing and adapting easier."
  • "Check Point's IPS simply works and is continuously kept up-to-date on all gateways."
  • "Threat Prevention policies are not very easily manageable as there are several profiles/policies/etc. Therefore, there are several ways to add exceptions and check the configuration."

What is our primary use case?

We have a hybrid infrastructure with an on-premise data center, cloud data center, and multiple branch offices. All of these firewalls are managed via Check Point Multi Domain Management as well as Smart Event to see security events across our environment.

IPS is set primarily to prevent and only some signatures are set to detect (only after some false positives) so we still see them and get notifications via the Smart Event reports.

IPS is updated automatically and pushed to all gateways every two hours. 

How has it helped my organization?

Check Point's IPS simply works and is continuously kept up-to-date on all gateways. Via the management, it's possible to let the gateway update the IPS signatures itself, instead of letting the management update itself and then push the updates to the gateways.

If there's a new data center or branch office and everything is still in the test phase, it's possible to set the IPS policy to detect only so you can gather data and create a baseline without completely disabling IPS. That way, you can still see log entries.

What is most valuable?

Automatic updates can be done either via management or the Gateway itself, without any user interaction. The gateway is up-to-date with the newest signatures.

If you're unsure which profile to use, Check Point has some pre-defined profiles according to its best practices. Each one adds a different load to the relevant gateway, so you have to first check the current load and then decide on the right profile.

IPS signatures can be set quite granularly depending on your environment. You can filter on performance impact, severity, and confidence which makes sizing and adapting easier.

What needs improvement?

You can't turn off IPS completely as there are some signatures that are set even without activated IPS. If you know that, you can act accordingly. But sometimes you have to do a general exception instead of a granular one.

There are always some false positives with non-RFC traffic. This is good for security, however, it will cause some effort in day-to-day business as there will have to be exceptions for certain applications.

Threat Prevention policies are not very easily manageable as there are several profiles/policies/etc. Therefore, there are several ways to add exceptions and check the configuration.

For how long have I used the solution?

I've used the solution for over ten years.

What do I think about the stability of the solution?

The solution is very stable.

What do I think about the scalability of the solution?

The scalability is quite good, depending on which IPS profile you're using.

How was the initial setup?

The solution is easy to set up.

Disclosure: My company has a business relationship with this vendor other than being a customer. We're a Check Point partner and use their products as well for our own environment.
PeerSpot user
PeerSpot user
Associate Consult at Atos
Vendor
Sep 5, 2021
Great updates, good out-of-the-box configuration and very good reporting
Pros and Cons
  • "There's an automatic update after every 2 hours which makes sure that the database is up to date and providing zero-day vulnerability protection."
  • "Intrusion prevention and detection are the most valuable pillars in the security system, which detects and prevents exploits or weaknesses in vulnerable systems or in applications and protect against threats not only based on signatures but also based on anomalies, behavioral analysis, etc."
  • "After the R80 release, there are almost all feature sets available under IPS Configuration. However, further to this, adding a direct vulnerability scan based on ports and protocol for every zone (LAN, DMZ, or Outside) will make Check Point very different compared to other vendors on the market."

What is our primary use case?

Intrusion prevention and detection are the most valuable pillars in the security system, which detects and prevents exploits or weaknesses in vulnerable systems or in applications and protect against threats not only based on signatures but also based on anomalies, behavioral analysis, etc.

IPS is already integrated and comes as a security license in Check Point NG Firewalls and NGTX Firewalls.

Every defense system must have a feature set that provides complete security for Network IPS and Check Point has very powerful high throughput - almost at terabyte speed - with the help of a hyper-scale approach.

How has it helped my organization?

Organizations can scan for vulnerabilities know as VAPT, which many prefer as one-step closure for maximum security for the entire network. Check Point IPS plays a leading role in patching those vulnerabilities based on CVE IDS.

Based on updates received from the Check Point Threat Cloud, CVE IDs get updated or we can manually add those signatures.

It helps organizations to get a complete report for vulnerabilities in applications, the host running in the network (which helps to fixed to vulnerabilities based on CVE IDs), and gives reports for the compromised host, C&C host, DNS tunneling attempts, and protects against vulnerability in SNMTP HTTP POP, etc.

What is most valuable?

There's a good out-of-the-box configuration for recommended security based on severity levels, confidence levels, and network impact - also known as an IPS Profile.

For better security, we can edit options based on requirements and we can keep actions as detect-only which gives us alerts but allows traffic to flow without stopping anything.

There's an automatic update after every 2 hours which makes sure that the database is up to date and providing zero-day vulnerability protection.

Check Point IPS provides reports for running vulnerabilities which help enable SOC teams to respond to the highest-priority events first to patch them.

What needs improvement?

After the R80 release, there are almost all feature sets available under IPS Configuration. However, further to this, adding a direct vulnerability scan based on ports and protocol for every zone (LAN, DMZ, or Outside) will make Check Point very different compared to other vendors on the market.

Most customers take an IPS license but they don't take a SmartEvent license and when this happens, they will not be aware of the report parts such as current threats in the network open ports/protocol, vulnerabilities in a system, or detected/prevented attacks. For such cases, Check Point should provide a bundled license with IPS. 

For how long have I used the solution?

I've been using the solution for more than four years.

What do I think about the stability of the solution?

The solution is highly stable for this particular blade.

What do I think about the scalability of the solution?

Scalability can depend on throughput and if we use Maestro Hyperscale, we can distribute load across multiple Check Point Firewalls to get the maximum (in TPS) throughput.

How are customer service and technical support?

Most of the time there is no need to take support for this,  but the CVE closure technical support team helps lot.

Which solution did I use previously and why did I switch?

Customers may have had different NGFW solutions, however, after, they migrated over to Check Point NGFW.

How was the initial setup?

The installation was straightforward in terms of configuration and onboarding.

What about the implementation team?

We are service providers and provide services to customers.

What was our ROI?

Attacks are getting prevented and detected based on severity which helps our organization to get rid of compromising attacks.

What's my experience with pricing, setup cost, and licensing?

Check Point IPS license is a must-have, and users need to make sure the database gets updated on daily basis after every 2 hours as per the defined configuration (which helps to get maximum protection).

The configuration is very simple and effective if you refer to the configuration guide properly.

Which other solutions did I evaluate?

We did not look at any other solution.

What other advice do I have?

The solution is best in class.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Chief Information Security Officer at Abcl
Real User
Top 10
May 11, 2021
Good visibility and reporting, helpful support, but it can lead to performance degradation
Pros and Cons
  • "It protects against specific known exploits but also, with SandBlast integration, it is able to protect against unknown or zero-day attacks at the perimeter level."
  • "There is a performance impact on the NGFW post-enabling the IPS blade/Module, which can even lead to downtime if IPS starts to monitor or block high-volume traffic."

What is our primary use case?

We use this solution to secure the organization against any attack coming into the network via the internet, a third party, or any other connected network. It is used to detect and prevent identified threats at the perimeter level so attacks do not penetrate the network.

With so many access points present on a typical business network, it is essential that we have a way to monitor for signs of potential violations, incidents, and imminent threats.

We also use it to provide flexibility for the SOC admin to identify any suspicious activity and either detect and allow (IDS) or prevent (IPS) the threat. It logs and reports any such incident to the centralized logger so the required action can be taken by the SOC team.

How has it helped my organization?

This IPS device is protecting the organization's assets from any know vulnerability or threats that are coming from the network and vice versa.

It protects against specific known exploits but also, with SandBlast integration, it is able to protect against unknown or zero-day attacks at the perimeter level. An example of this is C&C communication, which is getting trigger by compromised systems.

It's able to detect and prevent any tunneling attempt that is happening via compromised systems, thereby avoiding data leakage.

It provides the capability to enable security policy based on templates, which can be enabled by the organization, depending upon their need. For example, enabling the highest security with the lowest performance impact is a matter of selecting templates accordingly.

What is most valuable?

IPS can be enabled on the same security gateway and does not require any additional hardware purchase or additional network connectivity.

It provides complete visibility and reporting on a single dashboard for the entire NG firewall, including the IPS blade on the Smart Console.

Signatures are constantly updated and it also provides virtual patching protection up to a certain extent. 

It provides a detect-only mode for IPS Security policy that the admin can enable on a required segment for monitoring, giving an opportunity to observe prior to blocking.

What needs improvement?

There is a performance impact on the NGFW post-enabling the IPS blade/Module, which can even lead to downtime if IPS starts to monitor or block high-volume traffic. 

There is no separate, dedicated appliance for IPS.

In the case of the IPS blade enabled on the NG firewall, it does not provide flexibility to monitor specific segments as easily as the IPS policies that are applied on the security gateway. There is lots of configuration and exclusion policy that need to be configured to bypass traffic from IPS Policy. 

IPS gets bypass in case performance goes above certain limit. This is the default setting that is provided.

For how long have I used the solution?

I have been using Check Point IPS for more than six years.

What do I think about the stability of the solution?

This is a stable product.

What do I think about the scalability of the solution?

Most of the organization is deployed on the NGFW and it has scaled accordingly, with most devices in HA mode.

How are customer service and technical support?

Technical support is excellent.

Which solution did I use previously and why did I switch?

We did not use another solution prior to this one.

How was the initial setup?

This is a blade/module that needs to be enabled, selected, and applied across the security gateway.

What about the implementation team?

Our in-house team was responsible for deployment.

What's my experience with pricing, setup cost, and licensing?

Enabling IPS does not require any additional license purchase from OEM, as it comes by default with the NGFW bundle. This blade/module can be enabled based on the requirement and can be pushed to the security gateway.

Which other solutions did I evaluate?

We did not evaluate other options.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Cloud Support at a tech company with 1-10 employees
Real User
Top 5Leaderboard
Oct 29, 2025
Proactive Security Made Simple - IPS
Pros and Cons
  • "Check Point is one of the best security brands worldwide."
  • "It would be good to update the public documentation of Check Point so that we can generate improvements and best practices based on the documentation."

What is our primary use case?

The opportunity to use this tool was provided due to its ease of implementation within our NGFW security environment. The solution has been very good and the tool has a low rate of false positives, which makes it safer and more accurate.                                                                                                                                                                                                                                                                                               

How has it helped my organization?

                                                                                                  

This IPS tool is integrated with our gateways and is managed from our management environment. It has been very useful. It has given us protection to find any vulnerability, detect it, and improve it. It also validates threats reliably through its monitoring panel. The reports and logs help us to deal with decision-making to improve security conditions.

The option of security patches has been better protected to manage the servers' updates in a reliable way.

What is most valuable?

Its monitoring and reports generate extra help to be able to fight against
vulnerabilities.

We have really liked practically all the product's features - from the easy implementation through Check Point's gateway to its reduction in licensing costs. That especially really positively impacts the company's finances.

The low number of false positives for vulnerabilities builds additional confidence in the brand.

The constant updating of vulnerability signatures gives the tool protection against new and old threats.

What needs improvement?

One area that could benefit from improvement at the vendor level is the responsiveness of the support team. In our experience, resolution times tend to be slower than expected, even when the issue involves newly released tools or features.

Additionally, implementation processes can occasionally be complex, requiring more guidance than what’s currently available.

It would be highly valuable to see updates to Check Point’s public documentation. Enhanced and more detailed resources would help teams adopt best practices more efficiently and drive continuous improvement across deployments.

For how long have I used the solution?

This is a great security application. We've used it in our Check Point gateways and management environment for more than three years. We've enjoyed excellent performance.

What do I think about the stability of the solution?

yes

What do I think about the scalability of the solution?

yes

How are customer service and support?

great.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Previously we did not have a tool that would solve our security problems.

How was the initial setup?

excellent

What about the implementation team?

yes, excellent deploy.

What's my experience with pricing, setup cost, and licensing?

It is essential to validate the costs before implementation and also to test before setting up the environment in production.

Which other solutions did I evaluate?

We value some tools. However, nevertheless, Check Point met the conditions to implement it correctly and comply with what was necessary.

What other advice do I have?

its a excellent solution by my company

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Ajenthan Aiyathurai - PeerSpot reviewer
Manager - IT at NVCL Group
Real User
Top 20
Mar 15, 2023
Good notification, stable, and scalable
Pros and Cons
  • "The notifications are the most valuable feature of the solution."
  • "The installation documentation has room for improvement."

What is our primary use case?

We use the solution as a firewall to monitor and prevent intrusion into our system.

What is most valuable?

The notifications are the most valuable feature of the solution.

What needs improvement?

The solution is expensive and the cost has room for improvement.

The installation documentation has room for improvement. We can use more detailed information because sometimes it is difficult to understand.

For how long have I used the solution?

I have been using the solution for two years.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

The solution is highly scalable.

We have 100 people using the solution in our organization.

How are customer service and support?

I have had issues with the technical support not contacting me back.

How would you rate customer service and support?

Neutral

How was the initial setup?

The initial setup is straightforward. The configuration is completed with a few clicks. After the configuration, we can access the portal and start using the firewall. 

What about the implementation team?

We used a vendor for the implementation.

What other advice do I have?

I give the solution a nine out of ten.

The maintenance is easy.

Check Point IPS has zero-day detection and next-generation servers which make it a good solution and I recommend it.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
System Engineer/IT Support at Starlabs Limited
Reseller
Nov 27, 2022
Great functionality, user-friendly and easy to implement
Pros and Cons
  • "User-friendly and easy to implement."
  • "The solution helps our clients because once IPS is implemented, they don't have to worry about the security of their most critical infrastructure, and they can focus on their core business rather than the IT side of things."
  • "This is an expensive solution, higher than other products on the market."

What is our primary use case?

Most of our clients have the majority of their critical resources on prem to protect their DMZ, so we use IPS for that. We are resellers, implementing and providing support to our clients. I'm a system engineer IT support.

How has it helped my organization?

The solution helps our clients because once IPS is implemented, they don't have to worry about the security of their most critical infrastructure, and they can focus on their core business rather than the IT side of things. They know that once the solution is in place, they can have full trust in it.

What is most valuable?

The product is user-friendly and easy to implement. We receive training on how to onboard and when we are onboarding clients, we have the option of engaging Check Point to assist. It's a good provision to have. In terms of functionality, it's one of the best solutions on the market. 

What needs improvement?

Most complaints for Check Point relate to licensing fees. You need to be prepared to pay extra for implementing this product. 

For how long have I used the solution?

I've been dealing with this solution for over a year. 

What do I think about the stability of the solution?

The solution is stable and robust. 

What do I think about the scalability of the solution?

The solution is easily scalable. 

How was the initial setup?

The initial setup is quite straightforward and they provide documentation that is of good quality. Deployment takes around 30 minutes and maintenance is easy.  

What other advice do I have?

This is not a difficult tool to use as long as you understand the basics of networking and security. I rate this solution nine out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
Orlando Dos Santos Junior - PeerSpot reviewer
Consultant at Tempest Security Intelligence
Consultant
Aug 15, 2022
Great and easy to work with firewall, and prevents important attacks
Pros and Cons
  • "The Check Point IPS feature I find the most valuable is the firewall, as it is great and easy to work with."
  • "What I would like to improve in IPS would be the capacity of the hardware. I would also like to be able to sort signatures by severity. This would greatly impact how well I can manage my environment."
  • "So I don't think Check Point IPS is a great solution."

What is our primary use case?

My primary use case for Check Point IPS is very simple: I first identify some signature behaviors and secure levels and then I apply some signatures. I usually do not deploy IPS from CheckPoint. Overall, I manage signatures.

What is most valuable?

The Check Point IPS feature I find the most valuable is the firewall. It is great and easy to work with. 

What needs improvement?

I'm not sure what I really like in IPS because it's automated. You read the permit and you try to apply the signature and read the behavior of the solution and find how to fix it. So I don't think Check Point IPS is a great solution. 

I don't I like working with it very much because there's other stuff you can do to have more information. However, Check Point IPS does prevent important attacks easily.

What I would like to improve in IPS would be the capacity of the hardware. I would also like to be able to sort signatures by severity. This would greatly impact how well I can manage my environment. 

In the next release, I would like to see automatic signature deployment. 

For how long have I used the solution?

I have been using Check Point IPS for nearly a year now. 

What's my experience with pricing, setup cost, and licensing?

On a scale of one to ten, with one being the worst and ten being the best, I would rate Check Point IPS an eight. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1854018 - PeerSpot reviewer
Implementer at a tech services company with 51-200 employees
Real User
May 20, 2022
Autonomous threat prevention, APIs, and SmartConsole features work well and are easy to use
Pros and Cons
  • "The autonomous threat prevention is very easy to use. The APIs and SmartConsole tool also work well."
  • "There are a lot of false positives. I would like to see integration with some kind of network detection and response in order to make some automation on IPS configuration."

What is our primary use case?

I implement this solution for customers.

What is most valuable?

The autonomous threat prevention is very easy to use. The APIs and SmartConsole tool also work well.

What needs improvement?

There are a lot of false positives. I would like to see integration with some kind of network detection and response in order to make some automation on IPS configuration.

For how long have I used the solution?

I have been using this solution for about 12 years.

What other advice do I have?

I would rate this solution 10 out of 10.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Check Point IPS Report and get advice and tips from experienced pros sharing their opinions.
Updated: September 2026
Buyer's Guide
Download our free Check Point IPS Report and get advice and tips from experienced pros sharing their opinions.