Several enterprises, from financial institutions to hospitals, use this product mainly as edge solution. In most cases, the setup was based on a redundant configuration. Other cases which have been rolled out are based on smaller devices in office locations and larger devices in the central datacenter of the customer. As an MSSP we trust the reliability of the solutions, since we cannot risk having our reputation being harmed. Our team is perfectly able to manage the devices on a day by day basis using the central management solution.
Innovation Consultant at KPN IT Solutions - Trusted Services
Stable with reliable threat intelligence and offers very good updates
Pros and Cons
- "The different hardware models focus on a wide spectrum of the market, so any company can choose a model that makes sense for them from the range."
- "Pricing needs to be lowered from start, this would be more effective than lowering it during negotiations."
What is our primary use case?
How has it helped my organization?
The tension of being well protected from the outside world has decreased due to the sturdiness and reliability of the solution.
Results are predictable and managing everything is easy with the right tooling. The management solutions are easy to use and make it possible for our administrators to manage numerous amounts of devices in one console.
Software updates/upgrades contain valuable additions and it is clear that Check Point has the right focus on the requirements of what should be added as functionality.
What is most valuable?
Trustworthiness and stability are the key aspects when looking at these products.
The up to date-ness of the threat intelligence and the underlying network of devices adding value to it is good.
With many of their own investigators adding their findings to the threat database, Check Point has become a leader in having their product in the higher ranks of the spectrum of efficiency.
The different hardware models focus on a wide spectrum of the market, so any company can choose a model that makes sense for them from the range.
What needs improvement?
The world is changing rapidly, and even though Check Point is delivering security solutions on many levels such as endpoints, cloud, and on-premise.
A more centric solution would be preferable. They should take all existing products and make them a part of a suite that is easily manageable from one platform. This would leverage the use of the different products since no administrator wants many interfaces to manage the complete environment.
Pricing needs to be lowered from start, this would be more effective than lowering it during negotiations.
Buyer's Guide
Check Point NGFW
June 2025

Learn what your peers think about Check Point NGFW. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
For how long have I used the solution?
We've used the solution for more than 10 years products and have been delivering the solution to our customers.
What do I think about the stability of the solution?
The product is very stable.
What do I think about the scalability of the solution?
The solution is less scalable when using hardware-based solutions. Especially the smaller models have limited possibilities to expand on port / performance level. Both issues can be resolved using the Maestro solution, but that is limited to specific models.
How are customer service and support?
Technical support is very good and easily accessible.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We previously used Cisco and Fortinet. Check Point is a long-lasting vendor that we use, based on trust.
How was the initial setup?
The initial setup is pretty straightforward, especially when working with preset best practice profiles.
What about the implementation team?
We handled it on our own.
What was our ROI?
In the end, the ROI is good once a company knows the protection level on offer.
What's my experience with pricing, setup cost, and licensing?
Pricing and licensing are not the best within the market. That said when you get to know the products they offer you will be happy to pay a bit more.
Which other solutions did I evaluate?
We also looked at Palo Alto previously.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer: My company acts as an MSSP, and delivers devices and managed services based on the Checkpoint solutions.

Service Manager Datacenter LAN at a manufacturing company with 10,001+ employees
Great Anti-Bot and application control features but administration of routing should be on the central dashboard
Pros and Cons
- "The QoS blade is very good for controlling traffic such as Windows patches, mail traffic and other stuff."
- "The client for the central tools is very big - maybe using web access in future releases, similar to other vendors should be possible."
What is our primary use case?
We primarily use the solution for central administration and management of a lot of locations worldwide. That's the main task for this solution for our Central IT Team. Central logging and troubleshooting are 2nd level topics that are great to handle with the SmartDashboard and other tools.
We started in the past with base features and checked the NGFW features. Application Control gives us the option to permit applications and not just some IP address lists. Before we had so much manual work for dealing with firewall rules.
For some topics, we've given the Service Desk permissions and it's working great.
How has it helped my organization?
We have so many standalone firewalls. The central management of Check Point with different sessions/permissions is great. We can administrate all topics smoothly. The Application Control brings us to the next level of controlling cloud apps and other stuff.
Anti-Bot and the IPS are good features to check/defend our servers and company. We can prevent servers easily for vulnerabilities from/to the public internet and we can see what traffic/actions is active on our lines.
Our Security Operation Center is very happy about the solutions too due to the fact that they have so much transparency.
What is most valuable?
QoS, Anti-Bot, IPS, and Application Control are the main features we're using.
The QoS blade is very good for controlling traffic such as Windows patches, mail traffic and other stuff. In the past, sometimes we had no control and couldn't help when too much traffic had occurred.
Anti-Bot is great at preventing our clients and corporate network from calling the central control.
IPS is good in protecting our systems in DMZ zones when patching of servers sometimes can't be done.
Application control for controlling Cloud Apps like MS Teams, M365 Apps, or others, is perfect. Previously, we had only IP Lists for stuff like this.
What needs improvement?
Administration of the routing and system settings should be moved to the central dashboard. It's not good to go to all GAIA Interfaces to change settings there.
The client for the central tools is very big - maybe using web access in future releases, similar to other vendors should be possible.
The firmware for the Check Point Firewalls is very big. It takes a long time when we are using small lines for data transfers. Other vendors have updates lower than 100MB. For Check Point often we need a minimum of 2GB.
For how long have I used the solution?
I've used the solution for nine years.
What do I think about the scalability of the solution?
The scalability is great.
Which solution did I use previously and why did I switch?
We previously used Watchguard. It was not so good with different vendors for some features.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Check Point NGFW
June 2025

Learn what your peers think about Check Point NGFW. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
PLM Consultant
Great URL filtering, Application Control, and Intrusion Prevention
Pros and Cons
- "Check Point NGFW generates very helpful reports based on the logs of the activated features."
- "There have been a few requests/issues about the Identity Awareness feature."
What is our primary use case?
We first deployed Check Point for our clients. Our first client wanted to deploy the security appliances in a cluster solution for their network infrastructure solution. The NGTW chosen was the 5800 series and it was deployed as a software solution on clients' servers. Everything is going smoothly and the client seems happy with our proposal.
How has it helped my organization?
For our client, it is extremely important to protect the internal network infrastructure from any malicious attempt to break into their critical data. The NFGW cluster has been a step towards greater visibility in regards to their internal operations. The logs give a very detailed panorama of risks.
What is most valuable?
URL filtering, Application Control, and the Intrusion Prevention System are the features that almost every client wants to be guaranteed by their security appliances.
Check Point NGFW also generates very helpful reports based on the logs of the activated features, including the features mentioned (URL filtering, Application Control, and the Intrusion Prevention System, as well as anti-bot and anti-spam).
Sandblast is also a great feature, soon to be added to this solution through endpoints.
What needs improvement?
The appliances are quite intuitive and easy to be used. The hotfixes are useful and often released with notifications sent to the client.
There have been a few requests/issues about the Identity Awareness feature. The connection to AD, which was a request from the user, required the TAC team's support.
For how long have I used the solution?
I've been using the solution for more than 3 years.
What do I think about the stability of the solution?
This solution is stable and its replacement will not be needed for some time. Security is a need, and as such, it should be a permanent investment.
What do I think about the scalability of the solution?
It seems pretty scalable. Scalability is one of the features that make Check Point different from other vendors. Most of the Quantum series are usable with the Maestro solution, where the client can practically add up other appliances on top of the previous one, without replacing it.
How are customer service and support?
Cases don't always get a resolution immediately, however, the TAC team is supportive and through continuous interactions and suggestions, all cases have been resolved (within 1-2 weeks when they are not urgent).
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
For our own infrastructure, Check Point was the first vendor chosen.
How was the initial setup?
The implementation is straightforward. The setup is clear and simple, much like any other software nowadays.
What about the implementation team?
We did an in-house implementation.
What was our ROI?
The biggest investment is the initial one when you purchase the solution. It needs very little maintenance, and the automation it offers makes it easy to maintain.
What's my experience with pricing, setup cost, and licensing?
The setup is easy and intuitive, and licensing has good coverage to meet the needs for most of the clients. Price is the least favorite element regarding Check Point. Its products aren't the cheapest ones in the market, however, the ratio of value to money is fair.
Which other solutions did I evaluate?
Fortinet was considered as an option as well.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer: We are users of Checkpoint for our own infrastructure, as well as Checkpoint Resellers
Senior infrastructure technical lead at Westpac Bank
Super technical support, scalable, and has very useful dashboards
Pros and Cons
- "Objects search and tracker logs are useful."
- "The pricing could be better."
What is our primary use case?
The solution is primarily used for firewall protection for an enterprise environment, The Check Point firewalls are implemented on the perimeter (DMZ) and Secure Access Domain (SAD) environments.
We use physical VSLS clusters but have many virtual systems (Vsys) configured for different sub purposes. The Entire management domain is protected by Check Point firewall virtuals running on multiple physical boxes.
We have multiple virtual routers configured on the physical firewalls which connect L3 connectivity to other domains. The Perimeter DMZ firewall protects the boundary zone Environments
How has it helped my organization?
Check Point firewalls have helped our organization to securely promote the traffic flow in a secure way that is fast and swift.
There's faster identification of customer traffic issues identifies via a smart view tracker and centralized management of rules. It has an ease of access policy and a human-readable format.
We have multiple virtual routers configured on the physical firewalls which connect with L3 connectivity to other domains. The Perimeter DMZ firewall protects the boundary zone environments.
What is most valuable?
Dashboards for rules management and trackers for firewall logs capture are useful.
Traffic flow in Check Point is very structured so that it is easy to understand the path it checks to understand which elements come first and which elements come later.
The smart log compiles from multiple CMAs is an important feature that is very attractive.
The MDM dashboard is very organized compared to other vendors. The use of CLI tools like TCPDUMP and FW monitor are very useful in verifying the traffic logs.
Objects search and tracker logs are useful.
What needs improvement?
To combine CLI routing and GUI application in a way that both interact together would be ideal.
The pricing could be better. In general, the Check Point solutions are not cheap, however, you could try to negotiate on the overall contract, especially if you are purchasing a lot of hardware.
In the CLI, while viewing configs, there is no easy way to snapshot configs.
For how long have I used the solution?
I've used the solution for more than 15 years.
What do I think about the stability of the solution?
The product is very stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
Technical support is super.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We switched from Cisco to Check Point. Cisco was CLI-based and cumbersome with rulesets.
How was the initial setup?
The setup is straightforward as there are many videos available on the net to practice with.
What about the implementation team?
We had vendor involvement.
What was our ROI?
It serves the purpose and primarly gets the best output.
What's my experience with pricing, setup cost, and licensing?
The pricing is high. In general, the Check Point solutions are not cheap, however, you could try to negotiate on the overall contract, especially if you are purchasing a lot of hardware.
Which other solutions did I evaluate?
Yes, the vendor ran through the options and based their decision on the company security standards.
What other advice do I have?
We are satisfied with the product and support.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Checkpoint firewall has helped organisation to securely promote the traffic flow in secure way that is fast and swift.
Systems Architect at PHARMPIX CORP
Excellent support, great remote access, and very good reporting capabilities
Pros and Cons
- "The support offers the best services I have experienced. It's better than any other IT vendor."
- "Internet load balancing provides either active/passive or active/active load balancing, however, I would like to see more options that provide SD-WAN capabilities while also allowing for more than two links."
What is our primary use case?
Currently, I'm working as a Lead Security Architect in the healthcare industry. We have two data centers, multiple branch offices, multiple cloud subscriptions, and over 200 employees. Our operation is mission-critical and requires it to be up and running 24/7. We need to protect multiple applications that are developed in-house, sensitive data including PHI, Financial, intellectual property, et cetera.
Check Point NGFW and its security modules have been our security solution for the past six years to protect all of our assets, including our cloud subscriptions.
How has it helped my organization?
Check Point Next Generation Firewalls are key components in protecting our assets and information. Their security modules are very easy to use and understand. Also, it's one of the most user-friendly interfaces I’ve had the opportunity to use and I’ve had the chance to work with more than four firewall solutions.
Their reporting and logs modules are amazing. It provides a level of detail and visibility that we haven't had before. It’s useful to understand what is happening on our network and has been very successful in blocking attacks and providing options for executive summaries.
Being able to manage all the security gateways for our multiple sites in a single management console and share policies has been very beneficial.
What is most valuable?
The Remote Access VPN has been crucial to us, especially during this pandemic. We had to be on lockdown for a couple of months and being able to deploy a remote workforce with Check Point VPN was a crucial part of our business continuity strategy.
The logs and reporting are very easy to use and manage. Also, the IPS and IDS are critical components to keeping our network secure. They are very easy to configure and there are multiple templates that can be used out of the box that provides maximum protection to our network.
The support offers the best services I have experienced. It's better than any other IT vendor.
What needs improvement?
Check Point Firewalls haven't failed me during the past six years that I have been using them.
If I had to mention anything that I would like to see some improvement on, it’s on the internet load balancing options. Internet load balancing provides either active/passive or active/active load balancing, however, I would like to see more options that provide SD-WAN capabilities while also allowing for more than two links. I know this can be performed with other network devices, however, adding the option as part of the NGFW would be awesome.
For how long have I used the solution?
I have been using Check Point for 6 years now.
What do I think about the stability of the solution?
I've never had a single issue on any of my security gateways.
What do I think about the scalability of the solution?
I haven't had the opportunity to scale, however, I have seen many demos of maestro architecture, and it looks awesome.
How are customer service and technical support?
As I mentioned before, Check Point support is one of the best services from any IT vendor I have experienced. They answer very quickly and also provide solutions most of the time within the first call.
Which solution did I use previously and why did I switch?
I have used multiple solutions in the past. We migrated from Cisco ASA to Check Point six years ago and have never looked back. Our old ASA required additional hardware components for additional security services.
How was the initial setup?
The product is very easy to set up.
What about the implementation team?
The implementation was performed by a vendor team in combination with our in-house security team.
What was our ROI?
My peace of mind is the ROI.
What's my experience with pricing, setup cost, and licensing?
Check Point is not the cheapest firewall solution, but you get what you pay for. It's super reliable and their service is great.
Which other solutions did I evaluate?
I had the opportunity to review Palo Alto and Fortinet.
What other advice do I have?
I'd advise other users to give it a try.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Project Manager at Junta de Andalucia
A complete security solution that prevents attacks against data center servers and viruses
Pros and Cons
- "Check Point has a centralized console that makes it possible to manage all the deployed equipment. It also has a built-in VPN service that lets users connect through VPN to our organization, which facilitates teleworking while cutting off unauthorized access to the organization's internal network."
- "The predefined reports are limited and should provide more information. Check Point should provide a greater number of defined reports and produce reports for each division of the organization."
What is our primary use case?
We use Check Point firewalls to prevent attacks against the data center servers by adding more layers of security, such as IPS, Data Leak Prevention. We have also used Check Point to implement security policies in layer 7 and applications as well as to configure the VPN for internal users of the organization.
How has it helped my organization?
Check Point's firewall security solution is a complete solution that allows you to prevent attacks against your data center servers and avoid the transmission of viruses to end-users via ransomware, phishing, or forgery of URLs.
What is most valuable?
Check Point has a centralized console that makes it possible to manage all the deployed equipment. It also has a built-in VPN service that lets users connect through VPN to our organization, which facilitates teleworking while cutting off unauthorized access to the organization's internal network.
What needs improvement?
The predefined reports are limited and should provide more information. Check Point should provide a greater number of defined reports and produce reports for each division of the organization. Also, historical statistics cannot be obtained from the central console, the data or logs must be exported to another machine and processed from there to obtain this historical information. The number of available physical ports could be increased and Check Point could add support for higher speeds.
For how long have I used the solution?
We have been using Check Point firewalls for more than 10 years.
What do I think about the stability of the solution?
Check Point is a company that has been producing firewalls for many years. It is a leader in today's market, and its products are very stable. They are always updating and improving their products to stay at the top of the market.
What do I think about the scalability of the solution?
Check Point NGFW allows easy and fast scalability.
How are customer service and technical support?
Our experience with Check Point technical support was very positive. They always resolved questions or incidents quickly and professionally.
Which solution did I use previously and why did I switch?
We have always had Check Point solutions.
How was the initial setup?
The initial configuration was simple. The previous team was also using Check Point, we only had to export and update the rules. Only a couple of things had to be corrected and changed.
What about the implementation team?
It was implemented through a CheckPoint partner who demonstrated great experience in migration.
What's my experience with pricing, setup cost, and licensing?
When implementing, I would suggest you define in a real way what you want to allow —applications, content, destinations, etc. — and drop the rest of the traffic. It is important to review the groups, objects, and networks created to efficiently define the security policies that you finally want to implement.
Which other solutions did I evaluate?
Before making the last purchase, we evaluated other solutions, such as Palo Alto or Fortinet.
What other advice do I have?
I would rate Check Point NGFW 10 out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Security Administrator at a financial services firm with 10,001+ employees
Great protection, very stable, and offers excellent management
Pros and Cons
- "The firewall rule writing and object creation are the best and simplest I've seen on a firewall."
- "When we hit a bug, the support team recommends some hotfix, and if we upgrade to that, we have to uninstall it before we apply some newer jumbo hotfix."
What is our primary use case?
We are a financial institution and we use Check Point as a firewall that is positioned for external connections, like the Internet, leased lines, and site-to-site VPNs for other companies. Check Point protects our mobile applications connected to the internet, as well as the main company website. Some firewalls are positioned on some of our HQs.
We're on version R80.40 (some minor firewalls are on R80.30) and we use 13000, 23000, and 26000 series appliances. We use Application Control, Identity Awareness, IPS, URL Filtering, Anti-bot, Antivirus, Threat extraction, and Threat emulation blades.
How has it helped my organization?
I've been in the same company for 11 years, and Check Point has been running in a stable manner for our company's main internet connection (and 7 years before that).
It has protected our main applications successfully without any performance drops, and with its flawless logging capabilities, we were able to pinpoint any issues every time.
The management is also the best among any other firewall, with the convenience to create the objects and rules on the same page. This has helped us save time on operations. We can use APIs to create objects and rules to easily finish some projects.
What is most valuable?
The best features are the stability and the performance of the firewall and its software blades, simplicity to write the firewall rules on its GUI, and its logging capabilities.
The firewalls are working stably, without any interruptions. As we planned our capacity well, we've never had any performance issues.
The firewall rule writing and object creation are the best and simplest I've seen on a firewall (I've looked at 6 different vendors). I often wonder why the other vendors don't do it Check Point's way.
To see the logs, we can search like a search engine, and we can combine different search strings to pinpoint the interesting traffic.
What needs improvement?
The product can be improved with fewer hotfixes, and if more generally available jumbo hotfixes were used.
We don't often hit bugs. It's perfectly normal for an NGFW device as other vendors are always fixing bugs too. However, when we hit a bug, the support team recommends some hotfix, and if we upgrade to that, we have to uninstall it before we apply some newer jumbo hotfix. If those fixes were included in a fast manner in the jumbo hotfix (as jumbo hotfixes are tested thoroughly for general availability), it would be ideal.
For how long have I used the solution?
I've used the solution for 11 years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Solutions Architect Infrastructure and Security Manager at Jumbo Electronics Co. Ltd. LLC.
Stable and secure, but not user-friendly in terms of implementation
Pros and Cons
- "Check Point is awesome from a security standpoint. Based on our experience and also the experience of the other customers, it is a very stable appliance."
- "It should be user-friendly from an implementation point of view. Its setup is a little bit difficult."
What is our primary use case?
We use a remote access VPN, and this is a perimeter firewall for our data center to secure our servers and internal applications. We are using model G-6600.
What is most valuable?
Check Point is awesome from a security standpoint. Based on our experience and also the experience of the other customers, it is a very stable appliance.
What needs improvement?
It should be user-friendly from an implementation point of view. Its setup is a little bit difficult.
For how long have I used the solution?
I have been using this solution for four years.
What do I think about the stability of the solution?
From a security standpoint, it is very stable, and I would rate it a nine out of 10. I don't have any issues with it.
What do I think about the scalability of the solution?
At present, we have 30 for our distribution. So, it is pretty scalable.
How are customer service and technical support?
Their support is good. Their L1 and L2 support across the globe is great. L3 support is with the Israel team, and they have the right competency to troubleshoot it. Sometimes, when something needs to be done in the software in detail, we need to wait for people to come online from Israel. I would rate their L3 support a six out of 10 because we need to wait for the team from Israel to come online.
How was the initial setup?
It is a little difficult to set up. We need a really skillful engineer to manage it. After we have onboarded it correctly, it is very easy to manage, and it is very secure. Initially, we had some challenges and issues, and when we got the right resource and support from the vendor, they all got resolved. It took four or five days.
It should be user-friendly from an implementation point of view. I would rate it a six out of 10 in terms of implementation.
What other advice do I have?
I would recommend this solution. From a security standpoint, Check Point is the best product, but a customer should have the right skillsets to onboard and manage this.
I've been working with multiple customers in India, and I don't see any specific features that they need. It has covered pretty much everything.
Overall, I would rate it a seven out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Check Point NGFW Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
OPNsense
Sophos XG
Cisco Secure Firewall
Meraki MX
Palo Alto Networks NG Firewalls
Azure Firewall
WatchGuard Firebox
SonicWall TZ
Sophos UTM
Juniper SRX Series Firewall
Fortinet FortiGate-VM
Sophos XGS
SonicWall NSa
Buyer's Guide
Download our free Check Point NGFW Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- How does Check Point NGFW compare with Fortinet Fortigate?
- Is Palo Alto Networks NG Firewalls better than Check Point NGFW?
- Which would you recommend - Azure Firewall or Check Point NGFW?
- Is Check Point's software compatible with other products?
- What do you recommend for a corporate firewall implementation?
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Which is the best network firewall for a small retailer?
- When evaluating Firewalls, what aspect do you think is the most important to look for?
- Cyberoam or Fortinet?