We use it for VSX virtualization and we use it for normal firewall functions as well as NAT. And we use it for VPN. We don't use a mobile client, we just use the VPN for mobile users.
Founder at DedSec
Enabled us to virtualize multiple firewalls on one machine
Pros and Cons
- "The most valuable feature for us is the VSX, the virtualization."
- "We have surely seen ROI compared to the other vendors I mentioned, in terms of costs, and we tested all the firewall features to see if it is doing what it says it can do, and so far so good, it's excellent."
- "The VPN part was actually one of the most complex parts for us. It was not easy for us to switch from Cisco, because of one particular part of the integration: connecting the Check Point device to an Entrust server. Entrust is a solution that provides two-factor authentication. We got around it by using another server, a solution called RADIUS."
- "The VPN part was actually one of the most complex parts for us."
What is our primary use case?
How has it helped my organization?
We are able to virtualize about four firewalls on one machine. Before, we needed to have four firewall hardware devices, physical devices, from Cisco. We had four appliances, but now, with Check Point, we just have one. We can manage them, we can integrate them, and we can increase connections using one and the other. It has broken down connection complexities into just a GUI.
Also, previously we had downtime due to memory saturation with our old firewalls. We were using Cisco ASA before. During peak periods, CPU utilization was high. Immediately, when we switched to Check Point, that was the first thing we started monitoring. What is the CPU utilization on the device? We observed that CPU utilization stayed around 30 percent, as compared to 70 percent with the Cisco we had before, although it was an old-generation Cisco. Now, at worst, CPU utilization goes to 35 percent. That gives us confidence in the device.
In addition, the way Check Point built their solution, there is a Management Server that you do your administration on. You have the main security gateway, so it's like they broke them down into two devices. Previously, on the Cisco, everything was in one box: both the management and the gateway were in one box. With Check Point breaking it into two boxes, if there's a failure point, you know it's either in the management or the security gateway. The management is segmented from the main security gateway. If the security gateway is not functioning properly, we know that we have to isolate the security gateway and find out what the problem is. Or if the management is not coming up or is not sending the rules to the security gateway, we know there's something wrong with it so we isolate it and treat it differently. Just that ability to break them down into different parts, isolating them and isolating problems, is a really nice concept.
And with the security gateway there are two devices, so there's also a failover.
What is most valuable?
- The most valuable feature for us is the VSX, the virtualization.
- The GUI is also better than what we had previously.
- The third feature is basic IP rules, which are more straightforward.
- And let's not forget the VPN.
The way we use the VPN is usually for partners to connect with. We want a secure connection between our bank and other enterprises so we use the VPN for them. Also, when we want to secure a connection to our staff workstations, when employees want to work from home, we use a VPN. That has been a very crucial feature because of COVID-19. A lot of our people needed to work remotely.
What needs improvement?
The VPN part was actually one of the most complex parts for us. It was not easy for us to switch from Cisco, because of one particular part of the integration: connecting the Check Point device to an Entrust server. Entrust is a solution that provides two-factor authentication. We got around it by using another server, a solution called RADIUS.
It was very difficult to integrate the VPN. Until now, we still don't know why it didn't work. With our previous environment, Cisco, it worked seamlessly. We could connect an Active Directory server to a two-factor authentication server, and that to the firewall. But when we came onboard with Check Point, the point-of-sale said it's possible for you to use what you have on your old infrastructure. We tried with the same configurations, and we even invited the vendor that provided the stuff for us, but we were not able to go about it. At the end of day they had to use a different two-FA solution. I don't if Check Point has a limitation in connecting with other two-FAs. Maybe it only connects with Microsoft two-FA or Google two-FA or some proprietary two-FA. They could work on this issue to make it easier.
Apart from that, we are coming from something that was not so good to something that is much better.
Buyer's Guide
Check Point Quantum Force (NGFW)
September 2026
Learn what your peers think about Check Point Quantum Force (NGFW). Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,109 professionals have used our research since 2012.
For how long have I used the solution?
I have been using the Check Point Next Generation Firewall for 10 months.
What do I think about the stability of the solution?
The stability of Check Point's firewall, for what we use it for now, is pretty good. Especially, with the licensing of blades and the way they script it down into different managers. You have a part that manages blades, you have the part that manages NAT, and you have the part that manages identity. The VSX is another one on its own. So it is very stable for us.
When we add more load to it, when we go full-blown with what we want to use the device for, that will be a really good test of strength for the device. But for now the stability is top-notch.
What do I think about the scalability of the solution?
They scale well.
All information passes through the firewall. We have about 8,000-plus users, including communicating with third-party or the networks of other enterprises that we do business with.
How are customer service and support?
We've not used technical support. We asked our questions of the vendor that deployed and he was quite free and open in providing solutions. Anytime we call him we can ask. He was like our own local support.
There is also a Check Point community, although we've not really been active there, but you can go and ask questions there too, apart from support.
How was the initial setup?
The initial setup was pretty straightforward.
It took a while about a month, but it was not because of the complexity. It was because we gave them what we already have on the ground. We were on Cisco before and they had to come up with a replica of the configurations for Check Point. When they got back to us we had to make some corrections, and there was some back-and-forth before everything finally stabilized.
Four our day-to-day administrative work, we have about four people involved.
What about the implementation team?
We used a Check Point partner for the installation. I was involved in the deployment, meaning that while they were deploying I was there. They even took us through some training.
What was our ROI?
We have surely seen ROI compared to the other vendors I mentioned, in terms of costs. And we tested all the firewall features to see if it is doing what it says can do. And so far so good, it's excellent. It's a good return.
What's my experience with pricing, setup cost, and licensing?
Check Point offers good solutions, but it won't kill your budget.
Going into Next-Generation firewalls, you should know what the different blades are for, and when you want to buy a solution, know what you want to use that solution for. If it's for your normal IP rule set, for identity awareness, content awareness, for VPN, or for NAT, know the blades you want. Every solution or every feature of the firewall has license blades. If you want to activate a feature to see how that feature handles the kind of work you give, and it handles it pretty well, you can then move to other features.
Which other solutions did I evaluate?
We evaluated Palo Alto, Fortinet FortiGate, and Cisco FirePOWER.
Check Point was new to the market so we had to ask questions among other users. "How is this solution? Is it fine?" We got some top users, some top enterprises, that said, "Yes, we've been using it for a while and it's not bad. It's actually great." So we said, "Okay, let's go ahead."
What other advice do I have?
I would recommend going into Check Point solutions. Although Check Point has the option of implementing your firewall on a server, I would advise implementing it on a perimeter device because servers have latency. So deploy it on a dedicated device. Carry out a survey to find out if the device can handle the kind of workload you need to put through it.
Also, make it a redundant solution, apart from the Management Server, which can be just one device. Although I should note that up until now, we have not had anything like that.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
High-capability devices help us to integrate with cloud infrastructure and internet applications
Pros and Cons
- "It also gives us a single console for everything. Rather than having one device for URL filtering and a different device as a firewall, this gives us everything in one place."
- "Once we got the Check Point, we could use the same device for multiple roles, which reduced the cost a lot."
- "It would help if they were easier to deploy, without needing more technical people. It would be nice if we could just give basic information, how to connect, and that would be all, while the rest of the setup could be done remotely."
- "Check Point's technical support is a seven out of 10. Sometimes it takes a lot of time to get the right people on TAC issues."
What is our primary use case?
We work with these firewalls for overall security, including content filtering.
How has it helped my organization?
High-capacity and high-capability devices help us to integrate with the cloud infrastructure as well as internet applications.
What is most valuable?
The most valuable feature is the URL filtering.
It also gives us a single console for everything. Rather than having one device for URL filtering and a different device as a firewall, this gives us everything in one place.
What needs improvement?
It would help if they were easier to deploy, without needing more technical people. It would be nice if we could just give basic information, how to connect, and that would be all, while the rest of the setup could be done remotely.
For how long have I used the solution?
I have been using Check Point NGFWs for six years.
What do I think about the stability of the solution?
They're pretty stable. I don't see any issues there.
What do I think about the scalability of the solution?
Scalability means upgrading to newer, better hardware.
From an end-user perspective, everyone in our organization is using it, as it's a perimeter device. If they have to access the internet, they use this firewall to allow that access. We have about 4,000 end-users and about 200,000 concurrent connections.
How are customer service and technical support?
Check Point's technical support is a seven out of 10. Sometimes it takes a lot of time to get the right people on TAC issues. And to buy time, they just use generic questions, which is really time-consuming and doesn't relate to the problem at all.
Which solution did I use previously and why did I switch?
For the infrastructure in question, we have always used Check Point firewalls.
I have worked with Cisco ASA. Cisco is more CLI oriented, whereas Check Point is more GUI oriented. With the GUI, it's easier to manage and administrate it. If the configuration becomes bigger and bigger, it is really easy to see things in the GUI versus a CLI.
The advantage of the CLI is that you can create scripts and execute them. But the disadvantage is that they become so lengthy that it becomes very difficult to manage.
How was the initial setup?
The initial setup is straightforward because it's a GUI interface. Even when it was upgraded, things didn't change in terms of the look and feel. It was still the same. There was no need to learn new things. It's easy for any administrator to learn new features.
On average, deployment takes one to two hours, including mounting and everything, from the physical work to moving the traffic there.
The issue is that we still need people to be onsite to do this because some tasks have to be done on the day. That means a technical person is required to do that work. We can't give it to any other person to do this because, until those particular steps are completed, things can't go any further.
We have six people, network admins, for deployment and maintenance because we have about 30 of firewalls.
What about the implementation team?
We do it ourselves.
What was our ROI?
When we first started using them, we were just using them for basic functionality. Then we started using more features and introducing other components. For example, we had a different proxy server which we depended on. Once we got the Check Point, we could use the same device for multiple roles, which reduced the cost a lot. I would estimate our costs have been reduced by 30 percent.
What's my experience with pricing, setup cost, and licensing?
If you use the features then it's cost-effective. Otherwise, it's expensive.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
Check Point Quantum Force (NGFW)
September 2026
Learn what your peers think about Check Point Quantum Force (NGFW). Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,109 professionals have used our research since 2012.
Security Engineer at Hitachi Systems
Using the IPS, we can easily identify if there is any malicious activity
Pros and Cons
- "In R80.10 and above, you can view logs in SmartConsole. You don't have to open another smart tracker to view logs. That is the improvement Check Point has done which makes it better because it is much easier to find logs. This saves time, approximately 40 to 50 a day in one shift."
- "They are completely stable, and I haven't faced any issue with stability."
- "For R80.10 and above, if you want to install a hotfix, then you can't install it through the GUI. I don't know why. In the earlier days, I was able to do the installation of hotfixes through the GUI. Now, Check Point said that you have to install hotfixes through the CLI. If that issue could be resolved, then it would be great because the GUI is more handy than the CLI."
What is our primary use case?
We are mainly using it for policy installation and access purposes. We have a bank project where we are using mobile access, Antivirus, and IPS. These are all are configured on the Check Point Firewall, where we are using it on a daily basis.
I have worked on the following firewall series and models:
- 15000
- 23900
- 41000
- 44000.
I have worked on the following versions:
- R77.30
- R80.10
- R80.20.
I am currently working on the R80.20 version and the hardware version is from the 23000 series.
How has it helped my organization?
We installed this firewall in our organization one year ago, and it is completely fine. There are other deployment also going on for other customers. Most of those deployments are handled by our project teams.
What is most valuable?
What I like most about Check Point Firewall is that it is easy to use.
The most valuable feature is the IPS. For our bank project, we are using it as an external firewall. All the traffic is going through the Check Point Firewall. Then, using the IPS, we can easily identify if there is any malicious activity or anything else. We also have to update signatures on a regular basis.
What needs improvement?
We are facing some problems with the management on our Check Point Management Server. There are some issues with R80.20, so Check Point suggested to upgrade. However, we are in lockdown, so we will upgrade after the lockdown. We are coordinating this issue with the Check Point guys. After upgrading, I think these issues will get resolved.
For R80.10 and above, if you want to install a hotfix, then you can't install it through the GUI. I don't know why. In the earlier days, I was able to do the installation of hotfixes through the GUI. Now, Check Point said that you have to install hotfixes through the CLI. If that issue could be resolved, then it would be great because the GUI is more handy than the CLI.
For how long have I used the solution?
Two and a half years.
What do I think about the stability of the solution?
They are completely stable. I haven't faced any issue with stability.
What do I think about the scalability of the solution?
There are no issues with scalability.
In Hitachi Systems in Mumbai, there are around 10 to 12 clients who are using Check Point Firewall. There are around 40 network security engineers who support Check Point Firewall in our organization for the Mumbai location, and there are multiple locations.
How are customer service and technical support?
The technical support is very good. The Check Point guys are very humble and quick. They are always ready to support us if we call them.
How was the initial setup?
I have done four to five initial setups and configurations of firewalls, which have been completely fine and proper. There are no improvements needed.
For one firewall, it will take around two and a half hours to configure the interface and everything else. For the deployment of one firewall, it will take around two and a half hours. If you want to make any clusters, then it is around five to six hours.
What about the implementation team?
We support companies locally and remotely. Since the lockdown, we have been supporting companies only in a remote fashion.
We have to first make a plan of action, then verify that it meets Check Point's requirements. Then, we will raise a case with the Check Point desk. We verify with them if there are any changes that they need us to do. After that, we will go for deployment. Check Point engineering will also help if there are issues with the deployment.
What was our ROI?
They have made domain improvements to SmartConsole. If you check older versions, such as R77.30, you have to open a separate, smart tracker to view logs. However, in R80.10 and above, you can view logs in SmartConsole. You don't have to open another smart tracker to view logs. That is the improvement Check Point has done which makes it better because it is much easier to find logs. This saves time, approximately 40 to 50 a day in one shift.
What's my experience with pricing, setup cost, and licensing?
For the firewall, there is a limitation on the license. We are facing some problems with mobile access. We have a license for 450 licenses of VPN users. We would like Check Point to have more than that, e.g., if the organization gets bigger and there are more users, then that will be a problem.
I have done licensing and contracts for multiple firewalls. The license and contract configuration is completely fine, but if it is possible to make them cost a bit less, then this would be better.
Which other solutions did I evaluate?
Palo Alto is a zone-based firewall and Check Point is an interface-based firewall. With Palo Alto, we are using Panorama to install policy, and in Check Point, we are using their Management Server to install policy. The Palo Alto Panorama console has more options than Check Point.
On the Check Point Firewall, you can install policy. With the Palo Alto firewall, you can install policy on multiple gateways. You cannot install policy on multiple gateways with the Check Point Firewall.
What other advice do I have?
If you are making a plan of action for the installation of firewalls, clarify with the Check Point tech engineers that all is proper and good. We always arrange a Check Point standby engineer for this activity, because if anything goes wrong, then they can help on the call.
I would rate this solution as an eight out of 10.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner.
Security team leader at a aerospace/defense firm with 10,001+ employees
Management platform and GUI are intuitive and user-friendly, but QA on releases needs improvement
Pros and Cons
- "The management platform and the dashboard, the graphical user interface, is one of the best, if not the best, in the business. It's the most intuitive and it's really user-friendly in day-to-day operations."
- "One of my issues with Check Point is the stability. There have been too many bugs, over the years, when I compare them with other vendors. Their QA team should do better work before releasing their GA versions."
What is our primary use case?
The reason we have the Check Point Next Generation Firewall is that it's our main perimeter firewall in all our branches around the world. It secures the IT infrastructure in all of our environments and our subsidiaries. We also use it to set up tunnels between all our sites.
We have multiple versions from the legacy R77 to the latest R80.40.
How has it helped my organization?
In today's world, there are a lot of risks related to infrastructure security, malware and more. The Check Point has multiple blades in the same product, which improve security in IPS, application control, and URL filtering. You don't need to buy multiple, separate products to achieve the best security.
What is most valuable?
The basic most valuable feature is the firewall itself.
The management platform, dashboard, graphical user interface, are one of the best, if not the best, in the business. It's the most intuitive and it's really user-friendly in day-to-day operations.
The VPN means you can communicate in an encrypted manner between sites.
The application control and URL filtering are also very beneficial. They enable you to tighten security and decide which applications or websites you want to grant access to. In our company, we don't allow anyone to freely access the internet to surf all websites. Some sites may be sensitive and some of them may be inappropriate. It allows us to control the traffic.
What needs improvement?
Their management features are the best, from one point of view, but they are too heavy. For example, if you are looking at a configuration file, you can't just browse through it and see all the configurations like you can with other vendors, like Cisco and Fortigate. With those solutions you can just go over the configuration file and read all the objects and the policies, etc.
Because of the Check Point architecture, the data file itself is huge if you're comparing it to the data files of other vendors. The difference is something like 3 Mb to 1 Gb. It's not so straightforward.
The data process is also not so simple. You don't just load a text file which has all the configuration. It's a more complex process to restore it from a backup, when it comes to Check Point.
For how long have I used the solution?
I have been using Check Point's NGFW for approximately 10 years.
What do I think about the stability of the solution?
One of my issues with Check Point is the stability. There have been too many bugs, over the years, when I compare them with other vendors. Their QA team should do better work before releasing their GA versions.
What do I think about the scalability of the solution?
If you're looking for scalability and you need to add more power and performance and to scale up, they have a new solution, but I haven't used it yet.
In terms of the extent of our use, it's our main firewall. Everything flows through it.
We currently have four direct users and all of them are security engineers. I'm doing most of the deployment and the others are responsible for the day-to-day operations. In the overall company there are more than 10,000 users, and the traffic throughput is around 10 Gb.
How are customer service and technical support?
They have a very extensive Knowledge Base on their website, which is very helpful. But if you contact their technical support, not all of them have all the skills. If you open a ticket it may take a while to be resolved. It can take more than a month until they finally escalate it several times internally and then, finally, find a solution. But the first tier is not too technical.
Which solution did I use previously and why did I switch?
The previous solution, Contivity, was before my time in this company and I don't think it even exists anymore. The Contivity was only a firewall and our company wanted more features and benefits. It didn't have next-generation firewall options, like URL filtering, user identity, and IPS. As risks evolved in the data security field, our company needed to adapt.
How was the initial setup?
The complexity of the setup depends on which branch we're setting it up for. If it's a new branch, we can spin up a new firewall in less than an hour or so, do all the configuration, and it's ready for production. But if we're replacing an existing solution, the migration process may take some time and the people involved need more extensive knowledge, compared to spinning up a new firewall.
If it's a complex environment and you're migrating from one solution to another one, or even from an older version to a new version within the Check Point platform, I would recommend not to do it by yourself. In those cases you should use a third-party partner or Check Point Professional Services.
What about the implementation team?
I did most of my deployments by myself, but in our headquarters, where there was an older version of a Check Point version, and they wanted to migrate to a new one, I used a partner. The partner I used was SafeWay, a company in Israel. They have quite extensive knowledge and they are very professional.
What was our ROI?
It's hard to measure ROI in financial terms, but our productivity has gone up with the new version of the R80 because we don't need to wait for one administrator to log out of the management system for another to be able to log in. Multiple administrators can now work simultaneously on the platform. That productivity increase can be seen as a form of ROI.
What's my experience with pricing, setup cost, and licensing?
Use the basic sizing tool to do the correct sizing so you don't waste too much money, because it's not a very cheap solution when compared to other vendors. There are other vendors that are more affordable.
There are no costs in addition to the standard licensing fees, except maintenance.
Which other solutions did I evaluate?
We have not evaluated any other options.
What other advice do I have?
My best advice would be, if you are not as skilled, that while you don't really need to use the Check Point Professional Services, you should use a partner that has good knowledge of the device. If it's just a straightforward deployment without all the features, it may look simple but there are too many options. Eventually, you may use 30 percent of them. I don't think you will use 100 percent of all the features that are available.
Overall, I'm a little bit disappointed because of the numerous bugs that there are.
I would rate it at seven out of ten because their management platform and the dashboard. It's the most intuitive and user-friendly in day-to-day operations, as long as you're not dealing with the bugs.
Which deployment model are you using for this solution?
On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Sr. Security Engineer at a financial services firm with 10,001+ employees
Everything can be managed from a single dashboard
Pros and Cons
- "Everything can be managed from a single dashboard nowadays."
- "The most valuable feature is the Check Point Management Server, especially version R.80 onward, where we can manage endpoint security, cloud security, and email security from a single management server, making this a very unique and easy solution to use in the market now."
- "The main thing for a normal operations guy who is creating tools and firewalls, it is quite difficult to manage. It requires an expert level of knowledge in Check Point products to manage these scalable platform appliances and the virtual firewall that comes with it. We have to educate our guys and give them training on a regular basis to work on these products."
- "The main thing for a normal operations guy who is creating tools and firewalls, it is quite difficult to manage."
What is our primary use case?
It is a typical firewall that has been implemented in most of our regions. We use it for normal firewall policies and VPNs.
We are mainly using Check Point firewalls. We also have a few Check Point cloud security programs.
How has it helped my organization?
Everything can be managed from a single dashboard nowadays.
Since we upgraded to R.80 from our previous R.77 version, the activity of my team has improved a lot. We don't have to open multiple consoles or go to multiple nodes. Even though we are managing multiple solutions of Check Point, they feel similar to us now.
What is most valuable?
The most valuable feature is the Check Point Management Server, especially version R.80 onward. We can manage everything. We have endpoint security, cloud security, and email security. Everything can be managed from a single management server, making this a very unique and easy solution to use in the market now.
From a technical perspective, it is an easy solution to use. Everything seems perfect. We are not using all of its features, like sandboxing.
What needs improvement?
The main thing for a normal operations guy who is creating tools and firewalls, it is quite difficult to manage. It requires an expert level of knowledge in Check Point products to manage these scalable platform appliances and the virtual firewall that comes with it. We have to educate our guys and give them training on a regular basis to work on these products. Otherwise, it's fine.
For how long have I used the solution?
About five years.
What do I think about the stability of the solution?
It is pretty stable. It hasn't caused many issues over the years, unlike normal network issues. They do release bug fixes at least once a month. We keep very good track of that and update the patches regularly, but we haven't run into bigger issues so far. So, I'd say it is quite stable.
The firewall is very easy to use and hasn't caused much trouble for us over the years.
What do I think about the scalability of the solution?
From a scalability perspective, they have a solutions like Check Point Maestro. Therefore, it is easy to upscale nowadays.
We have over 200,000 end users.
How are customer service and technical support?
They should improve the support a bit. Though they have expert engineers in tech, sometimes the amount of time to get back a solution for an issue is more than what is acceptable, even though it is a high priority.
During a scheduled activity or an implementation, they find their highest level of support. During an implementation, I never faced an issue with the support. I would rate them a nine out of ten for this.
Which solution did I use previously and why did I switch?
The company has been using Check Point firewalls for the past 10 years. Before that, they used Cisco ASA.
How was the initial setup?
Mostly, I have worked on Check Point products. Therefore, the initial setup was straightforward. It was not that complicated.
I can spin up a firewall and put it in production within an hour. If it's a migration from a different solution or upgrading an existing management solution, it might take some time because of the planning. There are a lot of things that have to be a part of the implementation or migration activities.
What about the implementation team?
We do it ourselves most of the time. We only take help when it comes to scalable platforms, like big chassis firewalls, which are little complicated. Then, we get outside help.
I manage the operations team and have also been involved as a consultant.
We have some best practices in place that we follow.
There are four security engineers who deploy and maintain this solution.
What's my experience with pricing, setup cost, and licensing?
Comparatively, Check Point pricing is a little high. However, if you have that budget, I would recommend anybody to go with Check Point.
Which other solutions did I evaluate?
For cloud security purposes, we looked at FortiGate. In the end, we decided to go with Check Point. Primarily, we went with Check Point because of the fee. We also already had expertise on Check Point and the team is comfortable around it. We like that Check Point has a single dashboard. Feedback from peers suggests that the support in India for NGFWs is not as good with other vendors as it is at Check Point.
What other advice do I have?
Get a team who has expertise on this product and educate your team. Give them training. If Check Point is using a new version, make sure your team is aware of that. If there are any changes, let them know and make them comfortable working around this product because we have had some issues due to lack of expertise.
If you don't have an expert in-house team for implementation, I would strongly recommend getting help of the Check Point professional services team. There are a few third-party operational services, but I would go with Check Point professional services.
We are planning to increase our usage of the solution. Every project that we take on has Check Point security products as part of the solution.
I would give this solution an eight out of 10 because of the support. They take too much time when they should give you a result.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Network Security Consultant at Atos Syntel
Easy to manage, deploy, and upgrade
Pros and Cons
- "It is easy to deploy or upgrade. There is no need to do this manually with commands. This solution can be set up online."
- "It is a good firewall and has returned good performance, and we are happy with the product."
- "In a VPN setup, we have Internet connection via Check Point. The connectivity is not turnkey like competing devices. We have not yet terminated our site-to-site VPN because things are fluctuating right now and Check Point needs to be upgraded. Also, their troubleshooting needs to be improved for this."
What is our primary use case?
We have around 500 firewalls all around the world with a global team to manage them. We are using Check Point NGFW for Internet traffic, IPS, and UTM devices.
Atos provides this solution, including network design and advice.
What is most valuable?
- Antivirus
- IPS
- They got the logs into one site, which is wonderful.
- There is a secure action line code that you can announce your products in.
- If you have a number of sites, like a hundred sites around the world, you can deploy multiple VSX testing.
- All over the world, you can have DMZs in data centers, e.g., in the USA, Dubai, and London.
- It is easy to deploy and upgrade.
- Easy to manage, e.g., if there is a new engineer onsite, they can easily manage it.
What needs improvement?
In a VPN setup, we have Internet connection via Check Point. The connectivity is not turnkey like competing devices. We have not yet terminated our site-to-site VPN because things are fluctuating right now and Check Point needs to be upgraded. Also, their troubleshooting needs to be improved for this.
For how long have I used the solution?
I have been using it for five years.
What do I think about the stability of the solution?
I haven't seen any stability issues, though I have seen some issues with the management of the gateway. Stability-wise, it is good (a nine out of 10).
What do I think about the scalability of the solution?
We have 74 locations. We can have 10,000 users maximum via an Internet gateway. We have four data center across the world: two in USA, one in London, and one in Dubai. Passing through Check Point per location: in the USA - 5000 users, in London - 2000 users, and in Dubai - 10,000 users.
There are 12 network security engineers/consultants managing Check Point and the legacy firewall, SonicWall.
How are customer service and technical support?
Right now, we cannot go directly to Check Point because of vendor dependency. We have to first initiate with our vendor.
Which solution did I use previously and why did I switch?
We migrated SonicWall to Check Point about two years back. That took one year to set up in our organization.
We switched away from SonicWall because it is a legacy firewall at end of life. SonicWall was missing features that Check Point has, like UTM, IDS, IPS, antivirus, etc. Check Point is better for protection and performance-wise.
How was the initial setup?
It is easy to deploy or upgrade. There is no need to do this manually with commands. This solution can be set up online.
We have two devices. Right now, we are deploying and upgrading a new setup, where you can do management, management plus gateway on the device, or virtually you can install your management device on VMware or Hyper-V. With the Hyper-V and the Management Server, you can access all the gateways. For the Management Server and gateways, we have an activation key.
What about the implementation team?
We are an IBM OEM company who received installation support from that vendor. They provided all the network connectivity.
For our implementation, we:
- Started with an initial diagram of the configurations and what we want to see after the installation.
- Segregated the SonicWall and Check Point tools for the migration since we used automation.
- Checked the mode of installation. We went with transparent mode.
- Collected the IPs for the firewall. It required multiple IPs because with we have cluster nodes.
- Assessed the feasibility of Check Point in our environment.
For our strategy, we looked at:
- How many users are in all our offices? For example, is it a small office, mid-size office, or data center?
- Using high-end versus lower-end devices, e.g., lower-end devices means a smaller price tag.
A smaller office of less than 500 people would get a 4000 Series. Whereas, a larger office would get a 5600 or 7000 Series. We have to be focused on the natural topology.
What's my experience with pricing, setup cost, and licensing?
We have had some vulnerabilities when we upgraded the R80.30 Management Server. We have some gateways right now in our R77.30 version, and this means if we go without license in R80.30, then it will prompt a bad connection and terminate. We have had some license difficulties with the connection going from R70 to R80. However, these don't largely impact performance.
Which other solutions did I evaluate?
We looked at Fortinet and Palo Alto. We did not feel FortiGate was capable of what we required. Palo Alto is somehow not as good as Check Point, budget-wise and performance-wise. Palo Alto is more costly than Check Point.
If you need a good support or something that is good budget-wise, then I recommend going with Check Point compared to Cisco or Palo Alto.
What other advice do I have?
It is a good firewall. It has returned good performance. We are happy with the product. I would rate the product as a nine out of 10.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Reseller.
IT SecOps Manager at a tech services company with 11-50 employees
Reliable product with good technical support services
Pros and Cons
- "The product's primary benefits include effective intrusion blocking and improved network management."
- "I recommend developing a management console that can more efficiently handle multiple Check Point devices, as we have multiple appliances across different sites."
What is our primary use case?
We primarily use the product to block traffic at the application layer, limiting access to YouTube and social media during busy periods while allowing it during lunchtime or office hours.
What is most valuable?
The product's primary benefits include effective intrusion blocking and improved network management.
I appreciate the support provided as well. It is highly reliable and has a prompt response time.
What needs improvement?
The system's operation could be enhanced. I recommend developing a management console that can more efficiently handle multiple Check Point devices, as we have multiple appliances across different sites.
For how long have I used the solution?
We have been using Check Point NGFW since 2016 for approximately eight years.
What do I think about the stability of the solution?
There are occasional issues, but they are typically resolved with subsequent updates. I rate the stability a six out of ten.
What do I think about the scalability of the solution?
We have three sites where we use Check Point NGFW. The first site has about 1000 users, the second site has between 800 and 900 users, and the third site has approximately 100 to 200 users.
I rate the product scalability as two out of ten. Improvement is needed as it could be more convergent, particularly for on-premises solutions.
Which solution did I use previously and why did I switch?
We are currently using Check Point, Palo Alto, and Cisco.
Check Point's advantages include its lower cost than Palo Alto. However, it requires maintenance of many parts, as it is only partially GUI-based. In contrast, Palo Alto is mostly GUI-based, simplifying operations for our IT security team.
How was the initial setup?
The setup process was straightforward. Some aspects in terms of maintenance are easier due to the GUI-based interface.
What about the implementation team?
We took help from a consultant for implementation.
What other advice do I have?
I recommend Check Point Firewalls. It is a solid product with reliable support and frequent updates.
I rate it an eight.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cybersecurity Engineer at a tech services company with 11-50 employees
Good functionality and access control policies while helping limit access to third parties
Pros and Cons
- "Its management web interface is very easy and user-friendly."
- "Finding support is a little bit hard."
What is our primary use case?
We are resellers, and our customers need a robust and well-performing NGFW. The Check Point NGFW tool was acquired since they needed collaborators to have secure access to the company's resources and applications. This tool provides us with the alerts and corrections that must be made when finding a security breach in their environment.
Check Point NGFW also provides a great capacity of features and helps us apply them to the organization. It has web filtering limited to third parties and SSL encryption. The application's administration is very simple and centralized since it helps them a lot in reporting and generating alerts.
How has it helped my organization?
The organization needed a tool that would provide various security functionalities in the organization, and so far, Check Point NGFW has helped them a lot.
It has helped the company by applying access control policies and limiting access to third parties and only those who must enter the organization to use resources and applications.
The application behaved very well with the current resources in the company network; it helped us to prevent several security holes found with web filtering and internal DDoS attacks.
Check Point NGFW can quickly identify where the attacks are coming from, provide detailed and complete information on the attacks, and provide zero-day attacks in real-time.
What is most valuable?
One of the valuable characteristics of Check Point NGFW is that it presents very centralized management. Due to this, their security throughout and outside of the organization has improved.
Many collaborators work from their homes or different places and help them filter and limit access to packet inspection with flexibility and speed that was not previously possible.
The records that it shows and generates (depending on its configuration) make everything very visible to be able to adjust and correct in time. When superiors ask for administrative information, it provides great value.
Its management web interface is very easy and user-friendly.
What needs improvement?
The tool provides what is expected in its security functionality. However, some points must be improved, such as the latency in the GUI entry. It takes a while to register and allow access to the administrative panel.
Customer service should be improved, both in the administrative and technical fields. Support cases have been generated several times, and it takes time to resolve the case. Finding support is a little bit hard. This needs to be improved.
For how long have I used the solution?
I've used the solution for one and a half years.
Disclosure: My company has a business relationship with this vendor other than being a customer. My company is partnered with checkpoint as a reseller.
Chief Information Security Officer at a consultancy with 1-10 employees
Safeguards networks against a wide range of cyber threats with its robust security features, advanced threat prevention and centralized management
Pros and Cons
- "Extracting data from the logs and utilizing the log analyzer tool provides valuable insights and enhances the product's overall effectiveness."
- "Scalability should be improved."
What is our primary use case?
It can function as either a standalone appliance or as part of a clustered solution, offering flexibility to suit the needs of various customers, ranging from small businesses to large enterprises. We have experience working with a diverse clientele across different industries, leveraging Check Point's solutions to provide comprehensive network security tailored to each organization's requirements.
What is most valuable?
Extracting data from the logs and utilizing the log analyzer tool provides valuable insights and enhances the product's overall effectiveness.
What needs improvement?
Managing a smaller number of firewalls is straightforward, but as the scale increases, especially with numerous firewall instances, the complexity grows significantly. Scalability should be improved.
For how long have I used the solution?
I have been working with it for twenty years.
What do I think about the stability of the solution?
It offers good stability capabilities.
What do I think about the scalability of the solution?
We've encountered challenges related to scalability, particularly with its performance slowing down as the volume of objects in the network grows.
How are customer service and support?
While most engineers are typically responsive, there may be variations in their availability and response times. I would rate its customer service and support eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I also work with Fortinet, and I find it preferable because it offers a wider range of options. Additionally, its integrated package functions exceptionally well, with seamless coordination between services.
How was the initial setup?
The initial setup process is typically straightforward for most customers. However, when comparing Check Point with other solutions like FortiGate, there's a notable difference in how policy rules are implemented. With Check Point, you need to install the entire policy each time you want to make changes, whereas FortiGate allows for more streamlined updates by simply accepting the modifications. This can sometimes add complexity to installing a new policy with Check Point.
What about the implementation team?
The deployment time varies depending on the scale of the project. For small cases, it may only take a couple of minutes, while larger-scale deployments can span up to a month. Having a skilled engineer is crucial; one proficient engineer can handle the job effectively. Maintenance is relatively straightforward.
What's my experience with pricing, setup cost, and licensing?
While it may be slightly more expensive, when compared with competition it is reasonable. Licenses are renewed annually.
What other advice do I have?
Overall, I would rate it nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Consultant
Technical Specialist at Tech Hat Pvt Ltd
Great security management, packet filtering, and built-in high availability
Pros and Cons
- "In a single bundle we have the all solutions we need - like application/URL filtering, and threat emulation/extraction."
- "They could improve by lowering prices."
What is our primary use case?
We use the solution for full-scale integration and end-to-end management at the organization in a distributed deployment. The deployment/installation is quite easy.
Check Point NGFW is the best in terms of comprehensive protection against network threats and security against malware and phishing attacks. It smoothly restricts these via anti-phishing algorithms.
Check Point NGFW source package covers all the bases - application control, NAT, DLP, routing, content awareness, VPN, desktop security, and much more.
It is scalable, provides end-to-end resolution and customized productive services like providing a complete solution for perimeter protection that blocks the traffic based on an IP address or on applications and content. This makes Check Point NGFW a highly promising and more or less a complete solution.
How has it helped my organization?
Check Point NGFW proved to be highly scalable, secure, and stable, among other alternatives to multiple firewalls present in the market.
Before we used Check Point, we faced many issues such as latency, business interruptions, etc. In a single bundle we have the all solutions we need - like application/URL filtering, and threat emulation/extraction. In one single platform, we can manage everything with no need for a separate console to check/manage the features and behaviors. It has improved the performance and has minimal latency.
What is most valuable?
The most valuable aspects include:
Security Management. In a single console, we can manage the policies. It includes all the included bundles, features, and monitoring of logs.
Packet Filtering. This is used to examine every packet of data passing through your network.
Built-in High Availability. A standard backup feature should be included if you cannot risk losing your firewall.
Bandwidth control and monitoring. It's important to control the use of the bandwidth you have available.
Policy verification/validation. Check Point provides a convenient abstraction for bundling the validation of data against an expectation suite.
What needs improvement?
They could improve by lowering prices. The source package is a bit more expensive than its competitors. We've had some downtime issues
Improvements in the time and attention given to solutions for generated cases. Licensing that is more comfortable and affordable.
Check Point NGFW Firewall requires frequent updates to build more user-friendly dashboards.
A few services of Check Point NGFW require immediate improvements, like the customer support portal and the ads management on the platform.
Sometimes the KB article does not include all the steps. There is a chance for improvement in the content of global KB articles.
For how long have I used the solution?
I've used the solution for eight or more years.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Check Point Quantum Force (NGFW) Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Popular Comparisons
Fortinet FortiGate
Cisco Secure Firewall
Netgate pfSense
Sophos Firewall
Check Point Cloud Firewall (formerly CloudGuard Network Security)
Palo Alto Networks NG Firewalls
WatchGuard Firebox
Check Point Harmony SASE (formerly Perimeter 81)
Cisco Meraki MX
Azure Firewall
Palo Alto Networks VM-Series
Fortinet FortiGate-VM
Juniper SRX Series Firewall
Buyer's Guide
Download our free Check Point Quantum Force (NGFW) Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- How does Check Point NGFW compare with Fortinet Fortigate?
- Is Palo Alto Networks NG Firewalls better than Check Point NGFW?
- Which would you recommend - Azure Firewall or Check Point NGFW?
- Is Check Point's software compatible with other products?
- What do you recommend for a corporate firewall implementation?
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Which is the best network firewall for a small retailer?
- When evaluating Firewalls, what aspect do you think is the most important to look for?
- Cyberoam or Fortinet?












