What is our primary use case?
The primary use case for these firewalls is to protect our perimeter from unwanted traffic in and out of our network as well as to control the flow of data to comply with our company security policies.
It also plays an integral part in restricting or granting access at a granular level for certain users or vendors allowing us to monitor and protect end-customer data as well as protecting our users and network from malware, bots, ransomware and other bad actors that could disrupt our business operations.
How has it helped my organization?
Check Point NGFW products have improved the operation of our organization by allowing us to secure our perimeter from attacks, probes, malware, DDoS, bots and general bad actors. It also allows us to secure outbound traffic from our users.
It allows us to fine tune how we allow users to access resources both in our DMZ and externally. This helps us to secure customer and user data in order to prevent privacy issues, prevent loss of operations or downtime which we cannot accept.
Being able to use the products in redundant pairs has also allowed us to provide a more stable network.
What is most valuable?
There are several useful features that we utilize that are now valuable assets in terms of protecting the network. These would include user identification (ID Collector), IPS, antibot, antivirus, application, and URL filtering as well as the standard firewall security rules. They all work together to provide layers of security to protect both inbound and outbound traffic in order to minimize loss of private data as well as to ensure our network is free of bad actors attempting to use malware or ransomware against us.
What needs improvement?
Check Point could improve its products by working on stability. Overall, it is a stable platform, however, at times we have issues with 'quirks' and bugs that cause issues for our end users and typically are not straightforward to fix.
Another issue that presents itself is upgrading. Small hot fixes are not problematic. That said, updating to a new version of the OS has been an absolute nightmare and caused significant downtime and a number of issues - not to mention wasted engineering time. Simplify the upgrade process and they may regain confidence in this area!
I'd like to see more use of applications and URLs in security policies moving forwards.
For how long have I used the solution?
I've worked with the solution for seven years across two different companies.
What do I think about the stability of the solution?
The stability is good, yet it could use some improvement.
What do I think about the scalability of the solution?
The scalability is very good.
How are customer service and support?
It has always been slow and difficult to use technical support. It depends on a case-by-case basis, however, you have to chase and manage the case yourself or it will go nowhere. This likely comes down to a lack of experienced agents.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We previously used Cisco ASA. We switched due to the fact that Cisco's product was very hard to manage and lacked any real intelligence.
How was the initial setup?
The initial setup is complex. A very large and multifaceted environment will always be complex to configure.
What about the implementation team?
We used vendor support and account teams and in-house technical engineering.
What's my experience with pricing, setup cost, and licensing?
It's expensive, however, compared to the cost of not protecting the network properly, it's worth the cost.
Which other solutions did I evaluate?
We looked at Palo Alto, Fortinet, and Cisco.
What other advice do I have?
Carefully consider the vendor before making a leap. It's very difficult and costly to change vendors at a later date.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.