The primary use case is to enhance security by safeguarding the internet connection for both servers and users.
Technical Engineer at a tech services company with 11-50 employees
Robust network security with advanced features, user-friendly management, and good scalability
Pros and Cons
- "Its greatest asset lies in its user-friendly interface, making it exceptionally suitable and reliable for managing gateways."
- "When it comes to Check Point's small business gateway series, there might be a need for hardware upgrades, as configuring them can sometimes be a bit challenging."
What is our primary use case?
What is most valuable?
Its greatest asset lies in its user-friendly interface, making it exceptionally suitable and reliable for managing gateways.
What needs improvement?
When it comes to Check Point's small business gateway series, there might be a need for hardware upgrades, as configuring them can sometimes be a bit challenging.
For how long have I used the solution?
I have been working with it for two years.
Buyer's Guide
Check Point NGFW
April 2025

Learn what your peers think about Check Point NGFW. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
850,028 professionals have used our research since 2012.
What do I think about the stability of the solution?
I would rate its stability capabilities eight out of ten.
What do I think about the scalability of the solution?
I would rate its scalability abilities eight out of ten.
How are customer service and support?
Seeking solutions from them can be quite challenging and often takes a while, which then impacts our workload. I would rate it seven out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I have some experience with Juniper, WatchGuard, Cisco, and Fortinet.
How was the initial setup?
The initial setup is relatively complex.
What about the implementation team?
Deployment duration varies based on the customer's specific conditions. On average, an installation might take around twenty minutes.
What's my experience with pricing, setup cost, and licensing?
The best solutions tend to come with a higher price tag. If something is inexpensive, it often implies a compromise in quality. The solution is indeed costly. I would rate it eight out of ten.
What other advice do I have?
Overall, I would rate it eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner

RESIDENT ENGINEER at NetAssist (M) Sdn Bhd
A stable tool that offers high performance and requires an easy and straightforward maintenance process
Pros and Cons
- "The most valuable feature of the solution is the Quantum Intrusion Prevention System (IPS). I also like the solution's functionality, like autonomous threat prevention."
- "The complexity involved in the solution's initial setup phase and deployment process is an area of concern where improvement is required."
What is our primary use case?
I use the solution in my company since the solution serves as a firewall and functions on a DMZ network while also providing public-facing services. I serve my company's customers as a firewall administrator.
How has it helped my organization?
My company's customers have benefited from the solution's performance, especially when dealing with a huge amount of traffic. Check Point is a well-known name in the security industry that opts for functionalities like signature-based detection and beyond.
What is most valuable?
The most valuable feature of the solution is the Quantum Intrusion Prevention System (IPS). I also like the solution's functionality, like autonomous threat prevention.
What needs improvement?
The complexity involved in the solution's initial setup phase and deployment process is an area of concern where improvement is required.
For how long have I used the solution?
I have been using Check Point NGFW for two years. I work as the solution's integrator. Speaking about the version, I use Check Point Quantum 6400 Next Generation Firewalls.
What do I think about the stability of the solution?
So far, I haven't faced any issues related to the solution's stability.
What do I think about the scalability of the solution?
Scalability-wise, I rate the solution a nine out of ten.
If I take into consideration my company's customers who use the solution, then I would have to say that there are around 300 to 400 users.
How are customer service and support?
I have availed the services provided by the solution's technical support. My company engages with the solution's local partner to avail the services provided by Check Point's technical support team.
Which solution did I use previously and why did I switch?
Compared to Palo Alto and Fortinet, Check Point provides good internal performance, especially for big-scale enterprises and entities, making it a tool that is not just suitable for SMEs or mid-sized companies. Check Point is, however, pricier than other solutions.
How was the initial setup?
The initial setup of Check Point NGFW is quite complex. When it comes to the product's setup phase, the engineer should understand the product, and instead of understanding the firewall, it is important to know how to manage or be an admin.
The solution is deployed on an on-premises model.
The solution's deployment is complex.
What was our ROI?
My company's customers have seen a return on investment from the use of Check Point NGFW.
What's my experience with pricing, setup cost, and licensing?
I rate the pricing of Check Point NGFW a five on a scale of one to ten, where one is high price, and ten is low price.
What other advice do I have?
I take care of the solution's maintenance part, and I feel that it is a straightforward process.
Check Point NGFW is good for big companies.
I rate the overall solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
Buyer's Guide
Check Point NGFW
April 2025

Learn what your peers think about Check Point NGFW. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
850,028 professionals have used our research since 2012.
Senior Security Specialist at Tech Mahindra Limited
Great URL filtering, Data Loss Prevention, and mobile device connectivity
Pros and Cons
- "Its auditing features are good for checking who did what changes and when."
- "The URL objects take significant time in processing compared to other products like Cisco FTD; it would be better if they could improve it."
What is our primary use case?
Check Point NGFW is great in terms of functionality. We use it to control the infra outbound/inbound traffic and with it and we can block suspicious IPs directly on our SAM database instead of creating or adding in firewall rules. This not only saves time but also provides immediate protection from malicious traffic without deploying the changes in firewall gateways.
We used to check who is doing what changes and when. We can now check logs to find why any traffic is blocked, and, if blocked, it gives good details of each error. We can easily organize all firewalls through one smart console.
How has it helped my organization?
Its GUI platform is very good. It helps us to divide up the rule base which made it easier to recognize the rules. Its SAM database gives us the amazing ability to block suspicious activity without waiting for the next change window to push the changes. In packet flows, it first checks the SAM database beforehand in order to process the packet further.
The logs give us plenty of detail as to why any packet was blocked or allowed. It really proves the purpose of getting a stateful firewall, showing the context of every packet.
What is most valuable?
The SAM database, URL/application filtering and IPS, Data Loss prevention, VPN and mobile device connectivity, stateful packet inspection, and unified management console are all useful features.
It allows us to avoid having to go and log in to each firewall device for creating the rules as it can be done from its central console. We can manage all the firewalls and create rules and deploy them through the smart console which is really good. It helps us avoid creating the same object in each firewall.
Its auditing features are also good for checking who did what changes and when.
What needs improvement?
The URL objects take significant time in processing compared to other products like Cisco FTD; it would be better if they could improve it.
We have seen that whenever we configured URL objects, the CPU percentage went higher. Therefore, we started using IKP-based objects, however, in today's cloud world where every application is in the cloud and they change IPs on a random basis, whenever each new IP change happens, it's too risky to allow the whole cloud subnet (like Google or Azure). They need to therefore fix URL processing times.
For how long have I used the solution?
I've used the solution for four years.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Infrastructure Manager at trt18
Very good security especially where high bandwidth is needed
Pros and Cons
- "I use it as well as a VM. We use it a lot because we have all fiber optic connections, so we could use almost all of that. The federation is beautiful because I can transfer all traffic to my main site where I can use just one link to the internet, and I can use it as a proxy as well. It is good to keep control and security."
- "In terms of what could be improved, we have a cluster with two nodes and usually we have some problems when process gets really high and it has to choose which services it keeps going. I would like to have a better solution here, like if instead of just one we could use both at the same time. It would be good if it could work together. Then when one has a failure or something like that, the other one is there to transfer, to take all the services and keep working."
What is our primary use case?
I use the solution for VPN mostly, for the IDS and prevention and detection. I use it for security exploits, like HTTPS exploits.
I also use Check Point NGFW as a federation. I use it to connect to my other sites. We have five of them, mostly in cities where we need a high bandwidth.
What is most valuable?
I use it as well as a VM. We use it a lot because we have all fiber optic connections, so we could use almost all of that. The federation is beautiful because I can transfer all traffic to my main site where I can use just one link to the internet, and I can use it as a proxy as well. It is good to keep control and security.
What needs improvement?
In terms of what could be improved, we have a cluster with two nodes and usually we have some problems when process gets really high and it has to choose which services it keeps going. I would like to have a better solution here, like if instead of just one we could use both at the same time. It would be good if it could work together. Then when one has a failure or something like that, the other one is there to transfer, to take all the services and keep working. They have an integration between the nodes but I would like to use both of them working together. In the solution they could both be active, instead of active and passive. I would like them to add backup features to Check Point Firewall.
Many companies are going to the cloud. In future releases, it would be nice to have a cloud integration so we could work in a hybrid form for some years, like some services in the cloud and others on-premises. So it would be nice to have some features in this sense.
For how long have I used the solution?
I've been using Check Point NGFW since 2018. For two years now.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
I couldn't tell you about the scalability. I don't know. I know that we can use a federation, but I think it is scalable because we can buy additional licenses. As I mentioned, right now we have five working together, but we can buy until 50 or a 100, so I guess that it is scalable because you can keep increasing.
How was the initial setup?
The initial setup is hard. We came from another Cisco solution and even then it is hard, especially talking about the traffic. So we had to inspect the traffic and sometimes we had to do a lot of configurations. It would be nice if it was easier.
It took about three months to deploy.
It would be nice if it was easier to set up and to maintain.
What's my experience with pricing, setup cost, and licensing?
Right now we keep a contract with a company in Brazil, so we hardly talk to Check Point itself and we don't like it very much. In most cases we have to search and look into the database to really find the solution, so it could be better.
What other advice do I have?
I'd say that Check Point NGFW is a good product but it's hard to set up and keep it going, so we had to invest in some training and we have to keep at least two employees just to keep it working.
On a scale of one to ten, I would give Check Point NGFW an eight.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Director at TechPlayr
Centralized architecture, with good support, but the scalability could be improved
Pros and Cons
- "We have not had any issues with the firewall."
- "Check Point can scale but at times we have experienced some issues."
What is our primary use case?
We deploy solutions for customers. We don't engage in buying.
We are both consultants and implementers.
What is most valuable?
We have not had any issues with the firewall.
Support is good and it's centralized architecture.
What needs improvement?
We are also working on load balancers. We don't have the option to work more with load balancers, we would like to see what else can come out of this in terms of security.
Technical support and scalability both require improvement.
For how long have I used the solution?
I have been working with Check Point NGFW for the last ten years.
What do I think about the scalability of the solution?
Check Point can scale but at times we have experienced some issues.
How are customer service and support?
Palo Alto is better compared to Check Point. I would rate Palo Alto as superior support to Fortinet or Check Point.
Which solution did I use previously and why did I switch?
We used to work with Fortinet for approximately five years, and the Palo Alto Appliances was some time back.
I believe the Palo Alto support is excellent, and it has more features than Fortinet. Many businesses, in my opinion, are choosing Palo Alto.
Palo Alto support is very good.
Fortinet's main issue is the support. We can't take it to the enterprise level because the Fortinet support is not very good.
What's my experience with pricing, setup cost, and licensing?
Check Point has previously held a large market share, but perhaps not recently. I think that the price point in India is a bit different. Check Point offers options. I don't see that Check Point is very high, but it is geared more towards enterprises.
Which other solutions did I evaluate?
We have evaluated Palo Alto Networks VM-Series to see what was available, and recently, I researched the Azure VM series to know how it worked.
What other advice do I have?
I'm leaning toward the now cloud. The appliance base has now been removed. We are now concentrating our efforts on the Azure Cloud, AWS, and other similar platforms. I believe that people must mature in order to work on it. That's where things stand. As a result, we must learn how this is implemented on cloud platforms.
I would rate Check Point a seven out of ten but NGFW a six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IT Director at Facultad de Ciencias Actuariales, Universidad Anáhuac México
The best enterprise solution for cybersecurity protection
Pros and Cons
- "A stable solution with multiple interfaces"
- "Complex and not very easy to use."
What is our primary use case?
I'm at a university in Queretaro, Mexico and it's used to protect our infrastructure: wireless, LAN, PCs. Since the solution prevents attacks, we have the checkpoint in all our equipment, from the critical infrastructure to the directors' and employees' cell phones.
How has it helped my organization?
This is the best enterprise solution. Almost every university in Mexico has Fortinet or VXN, but our mission is to have the best cybersecurity protection for our information and our users. We're a private university and our clients and information are the priority. This is the reason why I chose Check Point NGFW.
What is most valuable?
The solution interface is good. It has three different ones: the NGFW, the Endpoint, and Harmony Mobile.
For how long have I used the solution?
I've been using this solution for five years.
What do I think about the stability of the solution?
It is very stable.
What do I think about the scalability of the solution?
The scalability of this solution is good.
How are customer service and support?
Because my employees work in other departments, we used the deployment consultant. The service was very good.
How was the initial setup?
The setup was simple because we had the checkpoint expert support. The time it took was standard and once the installation was complete, there was no problem at all.
What's my experience with pricing, setup cost, and licensing?
The setup was simple because we had our partner and checkpoint expert support. The time it took was standard and once the installation was complete, there was no problem at all.
What other advice do I have?
I would rate this solution a nine out of ten. This is a very good solution. It's complex because it's not too easy to use, but the brand and our partner help us with NG Firewall configuration issues or other solutions like Harmony.
The university is growing every year and with that, I purchase more endpoint licenses and Harmony Endpoint because the firewall works well on the dimension and capacity. Next year, we plan to integrate Harmony Email and Office. The solution also prevents threats to Office 365.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Integration engineer at S21sec
Great technical support, adapts well to any environment, and works well with Linux
Pros and Cons
- "The technical services always replied in a very fast and effective way."
- "One thing to improve is the VSX gateway. It is quite complex to work with VSX and they are quite easy to break if you aren't familiar with them."
What is our primary use case?
We use the product to secure our network, using all Check Point has to offer, including multi-domain servers, centralized log servers, gateways on-premise, and VSX. It has improved a lot with the last versions making day-to-day operations very user-friendly.
I have used almost all the blades Check Point has and it's incredible what a Next-Generation firewall is capable of, including VPN, IPS, monitoring, mobile access, compliance, and more. The reports of the Smart Event console are also very useful. It's good to have a view of what's going on in our network.
Since Check Point has Linux working on them, it gives us plenty of tools to adapt to any specific need we have.
How has it helped my organization?
In actuality, Firewalls are a must in any organization. Check Point's ability to adapt to any environment is their strength. The interface is very easy to understand, and the Smart Console can be configured to fit almost anything you need to.
When an issue appears, the logs are very easy to read, and that helps to identify the reason for the problem and solves it faster. The issues are not so annoying.
What is most valuable?
The support Check Point gives is key. As the Firewall vendor, I recommend them. It's always great to work with them. For this reason, I am very satisfied with Check Point. Every doubt I had they were pleased to help with and we ab;e to provide a resolution. The technical services always replied in a very fast and effective way. The live chat is great as well. There is always someone willing to help. This makes working with Check Point a good experience.
Check Point expert mode is basically Linux, so working with that allows us to implement a variety of scripts.
What needs improvement?
In earlier versions, it was a bit hard to do migrations of Multi-Domain Servers/CMAs, nowadays, with +R80.30 it has gotten much easier. I cannot really think of many things to improve.
One thing that could be useful is to have a website to analyze CP Infos. This way, it would be much faster to debug problems or check configurations.
Another thing not very annoying but enough to comment on is when preparing a bootable UBS with the ISOMorphic (Check Point's bootable USB tool), it gives the option to attach a Hotfix. However, this usually causes corrupted ISO installations.
One thing to improve is the VSX gateway. It is quite complex to work with VSX and they are quite easy to break if you aren't familiar with them.
For how long have I used the solution?
I've used the solution for three years.
What do I think about the stability of the solution?
With other products, I have used quite a lot of RMAs, usually for not the most important component, however, enough to need an RMA, such as FANs or PSUs.
With Check Point it's quite easy, if it's needed, to replace. You just install the correct version and hotfix and load a backup from the old device. After that, the new device is ready to go.
What do I think about the scalability of the solution?
The scalability of Check Point is great. With the usage of Multi-Domain Servers, you can integrate all the devices into one console. You also always have the chance to expand creating new domains. Also, this distribution helps to have a very structured and organized management. It is always a very good thing when things don't go as expected and you need to solve any problem. Finding where the issue is in your organization is key.
How are customer service and support?
The technical cases are replied to in a very fast and effective way. The live chat means there is always someone willing to help. This makes working with Check Point a good experience.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
The most I have used are Forcepoint, Cisco, F5, FortiGate, and Palo Alto.
How was the initial setup?
The initial setup is very straightforward and very guided.
What was our ROI?
With the few replacements we need to do, there is very little downtime. It is worth the investment. The great support team behind Check Point is also worth the cost.
What's my experience with pricing, setup cost, and licensing?
Check Point is not the cheapest manufacturer, however, it's worth the price.
Which other solutions did I evaluate?
I have been always on the side of Check Point, however, Palo Alto was another option we considered.
What other advice do I have?
Having the option to use a UNIX-based shell instead of being forced to use GAIA, in this case, is great. It makes Check Point very customizable.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Technical Specialist at NTT Security
Stable with flexible licensing and good centralized management
Pros and Cons
- "It improves user productivity and frees up system resources."
- "The firewall should be easily deployable and scalable in any major cloud environment and enable an organization’s security team to manage all of its security settings from a single console."
What is our primary use case?
Check Point Security Gateway GAIA R80.30 is used as our secure gateway firewall. We have configured two gateways as active-passive in cluster mode.
We also use R80.30 as our security management server to configure the policies on the firewall. We use it primarily to control traffic and secure our network perimeter against unknown attacks. The rules and policies for the SSL VPN connections are configured on the mobile access blade. We use the policies to segregate and filter the traffic flow.
This is for a bank environment.
How has it helped my organization?
A traditional firewall provides a stable inspection of network traffic. It allows or blocks traffic based on state, port, and protocol, and filters traffic based on administrator-defined rules.
A next-generation firewall (NGFW) does this, and so much more. In addition to access control, NGFWs can block modern threats such as advanced malware and application-layer attacks. According to Gartner's definition, a next-generation firewall must include:
- Standard firewall capabilities like stateful inspection
- Integrated intrusion prevention
- Application awareness and control to see and block risky apps
- Threat intelligence sources
- Techniques to address evolving security threats
What is most valuable?
Check Point Endpoint anti-malware benefits include:
- Improves user productivity and frees up system resources
- The industry’s fastest malware and anti-virus scan and boot time
- The smallest memory and disk footprints
- A single-console centralized management
- Prevention of malware from accessing endpoints with a single scan
- Malware identified using signatures, behavior blockers, heuristic analysis
- Protection automatically updated with optional Program Advisor Service
- A knowledge base of more than one million trusted or suspicious programs
- Integrated into Check Point Software Blade Architecture
- Flexible licensing options—annual or perpetual
- Centrally managed and deployed
- Activate anti-malware and application control on any Check Point security gateway
What needs improvement?
Almost all organizations are using cloud computing, and the vast majority are using a hybrid cloud deployment. Private and public cloud deployments have different security requirements, and it is necessary for an organization to be able to enforce consistent security policies across cloud-based environments hosted by multiple vendors.
The firewall should be easily deployable and scalable in any major cloud environment and enable an organization’s security team to manage all of its security settings from a single console.
For how long have I used the solution?
I've used the solution for five years.
What do I think about the stability of the solution?
Check Point is a very stable solution.
What do I think about the scalability of the solution?
It is good in terms of scalability.
Which solution did I use previously and why did I switch?
From the start, we have been using Check Point.
What's my experience with pricing, setup cost, and licensing?
We would adivse users to install Check Point NGFW. The setup cost is simple and it is not too much. The license fits most budgets.
Which other solutions did I evaluate?
We also evaluated Cisco and Fortinet.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer:

Buyer's Guide
Download our free Check Point NGFW Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2025
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
OPNsense
Sophos XG
Cisco Secure Firewall
Palo Alto Networks NG Firewalls
Azure Firewall
WatchGuard Firebox
SonicWall TZ
Juniper SRX Series Firewall
Fortinet FortiGate-VM
SonicWall NSa
Sophos XGS
Untangle NG Firewall
KerioControl
Buyer's Guide
Download our free Check Point NGFW Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- How does Check Point NGFW compare with Fortinet Fortigate?
- Is Palo Alto Networks NG Firewalls better than Check Point NGFW?
- Which would you recommend - Azure Firewall or Check Point NGFW?
- Is Check Point's software compatible with other products?
- What do you recommend for a corporate firewall implementation?
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Which is the best network firewall for a small retailer?
- When evaluating Firewalls, what aspect do you think is the most important to look for?
- Cyberoam or Fortinet?