Try our new research platform with insights from 80,000+ expert users

AlgoSec vs FireMon Security Manager vs Tufin Orchestration Suite comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

As of July 2025, in the Firewall Security Management category, the mindshare of AlgoSec is 22.8%, up from 20.4% compared to the previous year. The mindshare of FireMon Security Manager is 17.5%, up from 15.8% compared to the previous year. The mindshare of Tufin Orchestration Suite is 22.5%, up from 20.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewall Security Management
 

Featured Reviews

SAURABH JAMBHULKAR - PeerSpot reviewer
Empowers organizations to reduce change management time by 80% and improve audit efficiency
AlgoSec offers essential features such as risk management, policy optimization, change management, traffic simulation, and compliance auditing. Risk management is crucial for security, enabling deep analysis and threat prioritization, while traffic simulation allows interactive diagnostics for operational traffic management. Change management includes tools for monitoring policy changes and ensuring compliance with security standards, making these features significant for any organization. AlgoSec positively impacts my organization by reducing operation burden, enhancing time efficiency, and saving costs associated with security management. AlgoSec firewall analyzer helps with policy complexity by identifying unused or redundant rules and objects, recommending optimizations such as merging similar rules and removing unnecessary allows. Over time, firewalls can accumulate risky configurations, leading to increased overhead and troubleshooting time, but with AlgoSec, we simplify our rule sets, improve firewall performance, and facilitate faster change implementations.
Ganesh-Khutwad - PeerSpot reviewer
Rapid policy insights with robust dashboards and cross-vendor automation
FireMon Security Manager is excellent for real-time compliance management. It allows us to quickly retrieve any policy needed for testing and easily analyze it for loopholes. If a loophole exists, FireMon provides comprehensive details within the policy manager. It alerts us to firewall rule additions or changes that violate compliance policies. It supports various firewall platforms, including Checkpoint, Zscaler, Fortinet, Cisco, and AWS, and provides centralized management for all configured policies through a single console. FireMon Security Manager provides many features, like whether my firewall is compatible with required standards such as NTP and SNMP. Each compliance included in our RFPs is shown in the UI of FireMon. It gives robust and clear dashboards, making it easier to understand risks because the policies have ratings showing usage, and the number of hit attacks. It streamlines our compliance reporting processes by providing comprehensive risk and compliance assessments. It offers a range of features, including verification of firewall compatibility with protocols like NTP and SNMP, and detection of signal charges. FireMon effectively addresses all compliance requirements outlined in our RFPs. For instance, it can determine if firewalls or proxies within a stack are configured in Secure Mode or Active-Active mode. FireMon Security Manager enables us to generate reports on all these aspects, ensuring thorough compliance monitoring and documentation. FireMon Security Manager is robust and can help automate firewall policy changes across large multi-vendor enterprise environments. FireMon Security Manager helps automate firewall policy changes across various environments, including on-premises, cloud, hybrid, SASE, and SD-WAN. It also simplifies cleaning up firewall rules in our environment. The time required to accurately create, approve, and deploy firewall policy rules has been reduced. Tasks that took 30 minutes can now be completed in just five minutes using FireMon. FireMon provides immediate visibility into our policies through a robust and clear dashboard, making it easy to identify errors or misconfigurations based on the policy rating.
MithatBulut - PeerSpot reviewer
New employees can quickly grasp the various IPs, devices, and the network's logical and physical
Tufin is primarily used to orchestrate and manage network traffic and firewall devices. It is specifically useful for implementing firewall policies and handling requests from clients that require policy updates or changes Tufin simplifies understanding network topology. New employees can quickly…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"This has helped to restrict rules, delete rules that are too permissive, and create a configuration that complies with our security policy."
"I like the auto-mapping features and configuration overview. We use this for many things, but primarily for quick reactions to security events, audit, project management, and quick operational efficiencies."
"We need less time to identify any risks in our firewalls, as we can detect changes in real-time."
"Rather than logging in on separate firewalls, AlgoSec enables you to make changes on all firewalls from one pane of glass."
"It is helpful in improving the security and compliance of our environment. We can optimize our environment by improving the rules that are not used or are duplicated. FireFlow is useful in creating and implementing new rules. It allows us to automate rules implementation and have more control over the rules."
"I found that for policy optimization it does a great job."
"It assists us in network security reviews and audits."
"AlgoSec has helped us save time by having one central location to view firewall policies, especially when crossing multiple vendors."
"It gives us the ability to go to one place to look for potential firewall rules that are inappropriate, or which don't meet compliance. Instead of manually searching hundreds of firewalls for a policy, we can go to this one location and find the rules which are now out of compliance."
"It is the single place where we go to review all of our firewall changes. The solution makes it easier for us to track all the changes made. It is a central place where we can look at all the firewall rules, because we have three different firewall vendors. It save us time and creates efficiencies by looking at the general picture."
"The automation that the platform provides to create tickets reduces human error and more generally, reduces the operational overhead."
"The unused objects is another nice feature, where it digs a little bit deeper into comparing the logs that it sees versus the configurations that it sees... The unused objects feature will go through in a pretty detailed way and show us which ones aren't being used. Or, if they are used, it will show us how often they're used."
"FireMon is nice and provides 360-degree user views."
"Compared to other applications, it is user-friendly. The appearance of the menus and titles is clear and they are easy to follow. Of course, it requires some experience through using it, to go through everything, but it is not very difficult. It is an easy application to use."
"In one report, FireMon tells us there are, say, 1,000 rules that can be taken out and it gives us the ability to disable those for a year and to track when we made our changes. After a year, we can go back and eliminate the rules, to bring the configuration down to an almost human-readable level."
"Its user-friendly interface allows for easy viewing and searching of network policies, including proxies, all on one console."
"It's hard to pick the most valuable feature. All of them are valuable, they're all critical for us... ChangeTrack obviously has a lot of very good features, like the risk analysis, the USP, and the Policy Browser."
"We use this product to sharpen our change cycle. A request used to take quite a while as we did manual assessments. A lot of that is now done through SecureTrack."
"We use Tufin to clean up our firewall policies. This makes it a lot easier to find out the things that are wrong."
"We are able to stay compliant with many of the regulations."
"Tufin is our audit trail for all changes. We have to be PCI compliant, and it's the tool we go to for enforcing PCI on the network side."
"It made us look at security policies more holistically."
"This solution provides a more organized manner for us to track towards compliance for our PCI audits."
"Comparing the rules and policy browser is valuable to me. It gives me the ability to pull running configs and be able to analyze them without having to go directly into the firewall."
 

Cons

"It would be nice if it was more variable when checking virtual domain baseline in the same way as Fortigate's firewalls do."
"We see a very high demand for using containers and Dockers and therefore there is a need for managing access control to these platforms. I checked AlgoSec’s roadmap and, for now, there are no plans for developing these features."
"In our environment, we add rules in the files based on user logins, but currently, we can't do that with AlgoSec. AlgoSec can't create rules based on user logins. For example, generally, when we create a rule, we put IP Address, Destination IP Address, and Service Port. However, in our environment, we put IP Address, User Login, Destination IP Address, and Service Port, but AlgoSec doesn't support a rule in this format. We opened a ticket regarding this with their support two months ago, and they said that they will be able to add it in the future, but they don't know the timeframe."
"The HA solution is not good."
"Automate the change documentation in MS Word format. Therefore, we can customize it, if needed."
"All our firewalls were renamed, and AlgoSec saw these devices as new devices. As a result, all the reports from the same device but with the old hostname were no longer connected. AlgoSec did not clean up the old reports as well. After a few days, it depleted its own storage, and then, the server became inaccessible."
"Priority should be to improve the user interface for the risk and compliance part, making it more responsive and user-friendly."
"I like the training available as it is very informative, but, I wish it was just available from YouTube and I could easily play it from my cell phone without additional logins."
"To my knowledge, there's no cloud component to FireMon whatsoever. We're on the hook for any updates to versioning of the operating system or the application that runs on the operating system. It would be nice if it was a little bit more automated."
"One area for 7.x customers that needs improvement is the migration. It is an involved process so get ready to spend some time getting your environment back to the way it was."
"The stability has been fairly decent, but there have been a few issues. My coworker has had some issues in the past where he has had to work with support."
"While I like the reporting, I think that has the biggest room for improvement. Right now, as a user of FireMon, if I create a report, I am the only one who can see it inside FireMon. If someone on my team creates a report, they are the only person who can see that report on FireMon. It doesn't matter if you're admin in FireMon or not. The way we have to do it now is that we have created a service account user and that service account user runs all the reports. This way, all the reports, which are running, are just run under a single user so we can always access them. This definitely needs to change so users can see other users' reports or we can share reports within FireMon."
"We're working on implementing FireMon with our ticketing system service now. Having that would be an improvement."
"FireMon could improve its end-user practices. As an end user, I am just trying to catch up on all the alerts. There are so many, and you still have to go through them and document what was found."
"It comes as a Linux appliance on a server and we're not a Linux shop, we're more of a Windows shop. It would be great if they could automate or integrate the backups into it and other things through their GUI interface, just to make the management of Linux a little more transparent."
"The AWS integration is still not mature for us to use. It is just not ready for our use case for AWS connectivity. Therefore, it does not provide us with a single pane of glass for our cloud environments, because we can't manage our cloud environment with the tool."
"For me, there are two things that can make Tufin a bit better... [It needs] a better focus on automation - automating a lot of the processes; and automating rule re-certification, or at least finding a way to simplify it."
"I would like something that addresses security in the cloud."
"I would like more enforcement. Right now. it's a lot of alerting. You see it in Tufin, but you have to go to Check Point or whatever device to make the actual action."
"I would like to see them get rid of the REST APIs and use something more modern."
"I needed more help getting the product to work in the lab."
"We would like better communication on tickets, a better way to do metrics, and better communication to the customer. The biggest change that my team would like right now is communication on the process of the ticket, so the customer knows where their ticket is while their waiting."
"More API integration with third-party platforms is something that we would definitely like to see in upcoming releases."
"I would like to see visibility into the FW features like IPS/Content Filter policies, the same way it does for FW rules/policies."
 

Pricing and Cost Advice

"AlgoSec may be little pricier with its licenses, but it is probably better than any of other competitors."
"Setup cost and pricing were reasonable and the licensing was straightforward."
"The solution has a high cost, but the reduction in operation pays the investment."
"The initial cost was high for us."
"The pricing could be better."
"The licensing is very easy to set up, with flexible licensing methods such as subscription and perpetual."
"The pricing of AlgoSec is fair."
"Cost is based on firewall. There are bundles, e.g., virtual firewalls might make the solution cheaper."
"The pricing is very good, very straightforward. It also came in cheaper than AlgoSec and Tufin."
"We pay for it yearly."
"FireMon is very expensive. I think that they charge a premium. In general, they are very pricey. Compared to their competitors, they cost a little more than the other solutions that we evaluated."
"Its pricing is good. Compared to others, it is not so expensive."
"The pricing was very good during our initial year, but they increased it this year a little bit. The price is okay. It is not cheap, but it is still average."
"Regarding additional costs, if you want things like Policy Optimizer, extra features, that's extra."
"We don't license all of the devices in our network, so it does not provide us with a comprehensive visibility of all devices in a hybrid network at this time."
"Pricing model seems fair."
"Pricing played a big part here... The customer had evaluated other products but, due to price as well as support, they chose Tufin."
"It's not that expensive, except for Security Groups. For us, just the Security Groups were about half of the total price. The total was about €500,000 a year, of which €200,000 was for Security Groups."
"The solution has helped us to reduce the time it takes to make changes. With Tufin, it takes ten to 15 minutes. Before, it was 30 minutes or more."
"There is no issue with the pricing because we used a VM. That kept the cost low, as compared to an appliance."
"We have seen ROI from the side of operations, and we'll probably get to more of that as time goes on. However it took a while to get to that point."
"The licensing costs are around $250,000 to $300,000."
"I suggest talking with Tufin about the flexibility of the pricing structure."
"There are ways to deploy the license to different types of firewall. However, if we decide to change the physical brand of the firewall, we need to go back to Tufin and modify the licensing. This is a hassle."
report
Use our free recommendation engine to learn which Firewall Security Management solutions are best for your needs.
859,687 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
18%
Financial Services Firm
17%
Manufacturing Company
8%
Healthcare Company
6%
Computer Software Company
18%
Financial Services Firm
15%
Manufacturing Company
10%
Healthcare Company
6%
Financial Services Firm
17%
Computer Software Company
14%
Manufacturing Company
10%
Healthcare Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about AlgoSec?
AlgoSec's ability to integrate with various security and networking solutions enhances its overall value.
What is your experience regarding pricing and costs for AlgoSec?
Pricing for AlgoSec is fairly competitive. Rating the pricing on a scale from one being high to ten being low, the pr...
What needs improvement with AlgoSec?
The user interface for AlgoSec has remained unchanged for the last ten years and could benefit from being more intera...
What do you like most about FireMon?
I like the Security Manager console where we can see any changes that have been made or pull the results of an assess...
What is your experience regarding pricing and costs for FireMon?
Comparatively, FireMon has a very good price and is below the general competition in cost. I have not seen any additi...
What needs improvement with FireMon?
For one company I work with, I use Fortinet, and FireMon is not able to understand the zones that Fortinet uses. Part...
What needs improvement with Tufin SecureCloud?
Tufin Orchestration Suite ( /products/tufin-orchestration-suite-reviews ) is not commonly used in Thailand due to a l...
What is your primary use case for Tufin SecureCloud?
I have primarily used Skybox and AlgoSec ( /products/algosec-reviews ). I have also interacted with FireMon for compi...
What advice do you have for others considering Tufin SecureCloud?
There is potential for improvement in explaining the analytics in the dashboard for Tufin Orchestration Suite. Tufin ...
 

Also Known As

No data available
No data available
Tufin SecureCloud
 

Overview

 

Sample Customers

Maersk, Delta Airlines, Chevron, General Motors, T-Mobile, Chevron, AT&T, BP, Bell Canada, HCA Healthcare, Morgan Stanley, Unilever, Nationwide Insurance Enterprise, US Bank, Microsoft 
Convey, MGM Resorts International, Southwest Airlines, Alkami, Costco, Aetna, IBM, Verizon, Wells Fargo
3M, AT&T, Blue Cross Blue Shield, BNP Parabas, ConocoPhillips, Deutsche Bank, GE, IBM, Pfizer, United States Postal Service 
Find out what your peers are saying about AlgoSec, Tufin, FireMon and others in Firewall Security Management. Updated: June 2025.
859,687 professionals have used our research since 2012.