Try our new research platform with insights from 80,000+ expert users

AlgoSec vs FireMon Security Manager vs Tufin Orchestration Suite comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

As of October 2025, in the Firewall Security Management category, the mindshare of AlgoSec is 22.8%, up from 21.0% compared to the previous year. The mindshare of FireMon Security Manager is 17.8%, up from 15.9% compared to the previous year. The mindshare of Tufin Orchestration Suite is 22.6%, up from 21.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewall Security Management Market Share Distribution
ProductMarket Share (%)
AlgoSec22.8%
Tufin Orchestration Suite22.6%
FireMon Security Manager17.8%
Other36.8%
Firewall Security Management
 

Featured Reviews

SAURABH JAMBHULKAR - PeerSpot reviewer
Empowers organizations to reduce change management time by 80% and improve audit efficiency
AlgoSec offers essential features such as risk management, policy optimization, change management, traffic simulation, and compliance auditing. Risk management is crucial for security, enabling deep analysis and threat prioritization, while traffic simulation allows interactive diagnostics for operational traffic management. Change management includes tools for monitoring policy changes and ensuring compliance with security standards, making these features significant for any organization. AlgoSec positively impacts my organization by reducing operation burden, enhancing time efficiency, and saving costs associated with security management. AlgoSec firewall analyzer helps with policy complexity by identifying unused or redundant rules and objects, recommending optimizations such as merging similar rules and removing unnecessary allows. Over time, firewalls can accumulate risky configurations, leading to increased overhead and troubleshooting time, but with AlgoSec, we simplify our rule sets, improve firewall performance, and facilitate faster change implementations.
Ganesh-Khutwad - PeerSpot reviewer
Rapid policy insights with robust dashboards and cross-vendor automation
FireMon Security Manager is excellent for real-time compliance management. It allows us to quickly retrieve any policy needed for testing and easily analyze it for loopholes. If a loophole exists, FireMon provides comprehensive details within the policy manager. It alerts us to firewall rule additions or changes that violate compliance policies. It supports various firewall platforms, including Checkpoint, Zscaler, Fortinet, Cisco, and AWS, and provides centralized management for all configured policies through a single console. FireMon Security Manager provides many features, like whether my firewall is compatible with required standards such as NTP and SNMP. Each compliance included in our RFPs is shown in the UI of FireMon. It gives robust and clear dashboards, making it easier to understand risks because the policies have ratings showing usage, and the number of hit attacks. It streamlines our compliance reporting processes by providing comprehensive risk and compliance assessments. It offers a range of features, including verification of firewall compatibility with protocols like NTP and SNMP, and detection of signal charges. FireMon effectively addresses all compliance requirements outlined in our RFPs. For instance, it can determine if firewalls or proxies within a stack are configured in Secure Mode or Active-Active mode. FireMon Security Manager enables us to generate reports on all these aspects, ensuring thorough compliance monitoring and documentation. FireMon Security Manager is robust and can help automate firewall policy changes across large multi-vendor enterprise environments. FireMon Security Manager helps automate firewall policy changes across various environments, including on-premises, cloud, hybrid, SASE, and SD-WAN. It also simplifies cleaning up firewall rules in our environment. The time required to accurately create, approve, and deploy firewall policy rules has been reduced. Tasks that took 30 minutes can now be completed in just five minutes using FireMon. FireMon provides immediate visibility into our policies through a robust and clear dashboard, making it easy to identify errors or misconfigurations based on the policy rating.
MithatBulut - PeerSpot reviewer
New employees can quickly grasp the various IPs, devices, and the network's logical and physical
Tufin is primarily used to orchestrate and manage network traffic and firewall devices. It is specifically useful for implementing firewall policies and handling requests from clients that require policy updates or changes Tufin simplifies understanding network topology. New employees can quickly…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"AFA provides project teams with a simplified way to obtain the status on their current rule set."
"Implementing firewall rules within our organization has been significantly expedited thanks to AlgoSec."
"We have not seen many faults reported from our customers."
"We see the value of BusinessFlow for organisations involved in digital transformation projects migrating to public/private/hybrid cloud models."
"AlgoSec has reduced the need for additional manpower and we can now use the time to tackle other security-related issues."
"It helps us to streamline our firewall rules, identify risks, and provide better visibility. This product has significantly saved the time and human efforts in creating and deploying firewall rules. It is now easier for our cybersecurity team to analyze firewalls rules and ACLs, using them in a more efficient manner."
"Users utilize this tool to make their change requests."
"We have all of the information about the firewall devices that we have at risk, either because there is a firewall policy with some open protocol that can give us security problems later, or because long-unused rules present a security hole."
"In one report, FireMon tells us there are, say, 1,000 rules that can be taken out and it gives us the ability to disable those for a year and to track when we made our changes. After a year, we can go back and eliminate the rules, to bring the configuration down to an almost human-readable level."
"I've been using the reports to see what is going on, and that is a helpful feature. We can track down unused rules, which helps with compliance. We can see rules that have not been used or that are duplicates or overly permissive."
"FireMon Security Manager is a fast and intelligent device that delivers results in under ten seconds, even with thousands of policies."
"Firewall auditing is very important. We also use the solution for rule traffic analysis, traffic flow discovery and hidden/shadow rules within over 100 firewalls spanning five different brands."
"We also use the solution’s SASE integration capabilities to extend security policy management for cloud firewall management. It helps in creating one consistent rule across multiple platforms and it improves accuracy."
"When it comes to real-time compliance management, it is very good because it is able to compare changes in the configuration as well as giving us a timestamp. It also sends email alerts to our environment so we know if someone has made a change on the network. It gives us the whole picture of that change. Whether it is a configuration change or just a small comment, it gives us the before and after snapshot."
"It gives us the ability to go to one place to look for potential firewall rules that are inappropriate, or which don't meet compliance. Instead of manually searching hundreds of firewalls for a policy, we can go to this one location and find the rules which are now out of compliance."
"The firewall assessment feature is great."
"The visibility is very good. We have managers who are overseeing it, and they are approving things through it."
"We find it to be flexible. If we have a change that needs to be done, it will go ahead and do it for all our devices, regardless of the manufacturer that we have associated with it."
"The Topology Map, which feeds into our SecureChange - the latter being an automation platform - there's a lot of synergy between the two."
"The designer gives the ability to know where to add a rule, or if the rule is already in place."
"We just got done with major audits. Tufin was able to provide information to give back to people, and say, "Hey, this is what I need to do, and what we're doing.""
"This has helped us to better clean up and audit changes to the firewall policy."
"The most valuable function is the SecureChange where it is able to automate everything from the validation of the rules to the pushing of the rules."
"Its ability to detect changes within our firewall."
 

Cons

"We needs object level permissions and application level recertifications."
"Fireflow needs to be a little more user-friendly."
"It gives you the capability to make changes to hundreds of your firewalls at the same time, but big enterprises have change management policies. Change managers will never allow you to make changes to more than 10 devices at the same time, which is a feature in AlgoSec. Because, what if something goes wrong, then you have to roll back and figure out what caused the impact, e.g., which firewall did not work well. Doing that post-mortem becomes a difficult thing. So, change automation on a firewall is actually defeating the purpose of the change management policies in any organization. If you run a bank, you will not allow anyone to make changes at the same time from a single click for 10 firewalls. The bank will never allow this."
"The graphical user interface in AlgoSec needs improvement. Sometimes it gets stuck, requiring multiple refreshes."
"Certain firewalls don't integrate with AlgoSec, and it would be great if this bug could be fixed."
"In our environment, we add rules in the files based on user logins, but currently, we can't do that with AlgoSec. AlgoSec can't create rules based on user logins. For example, generally, when we create a rule, we put IP Address, Destination IP Address, and Service Port. However, in our environment, we put IP Address, User Login, Destination IP Address, and Service Port, but AlgoSec doesn't support a rule in this format. We opened a ticket regarding this with their support two months ago, and they said that they will be able to add it in the future, but they don't know the timeframe."
"We faced internal challenges with our services and the process. If we had a closer approach from AlgoSec with instructions on how to build or change the management process, how to improve our environment, it would have been better. The big problem was more about the approval and request roles, and bureaucratic side of things."
"It would be nice to have a good tool for network map discovery in the GUI to make it more user-friendly."
"I ran a report and FireMon suggested that certain tools were not used. When I removed them, while it didn't bring our environment down completely, a lot of our environment started malfunctioning. Our backup system did not work, nor did other things that involve internal and external communication. We are not comfortable with what it did."
"Our firewalls have multiple paths through them and FireMon falls short a little bit because it's not Palo Alto-centric. I don't think FireMon has kept up with where Palo Alto is at. They started out being Check Point-centric for years and they've never really fully embraced the nuances others, like Palo Alto or Fortinet, have. They don't handle a lot of the capabilities and attributes that Palo Alto does yet. They're working on it. They're getting there."
"The support response time has room for improvement."
"The initial setup can take some time, including connecting it and configuring it. It's not something that is easy for anybody to do. There is time and energy required because of the number of systems you have to configure to get it to work properly."
"We're working on implementing FireMon with our ticketing system service now. Having that would be an improvement."
"The advanced features are complex in setting up the rules."
"It comes as a Linux appliance on a server and we're not a Linux shop, we're more of a Windows shop. It would be great if they could automate or integrate the backups into it and other things through their GUI interface, just to make the management of Linux a little more transparent."
"While I like the reporting, I think that has the biggest room for improvement. Right now, as a user of FireMon, if I create a report, I am the only one who can see it inside FireMon. If someone on my team creates a report, they are the only person who can see that report on FireMon. It doesn't matter if you're admin in FireMon or not. The way we have to do it now is that we have created a service account user and that service account user runs all the reports. This way, all the reports, which are running, are just run under a single user so we can always access them. This definitely needs to change so users can see other users' reports or we can share reports within FireMon."
"The biggest area where I see a need for improvement is some of the documentation and training stuff. It does a really good job of hitting the big concepts, but it needs like another layer deeper of actually getting into some of the details of how to do some of the things. Conceptually, I understand how the product works, but now how do I start building stuff and integrating it into my environment."
"The product should integrate with the UTM features."
"It could be a little more intuitive."
"We had a discussion in the Customer Advisory Board yesterday around use of SecureChange. We would like to have an opportunity for an engineer to choose if you want to make or take the policy which has been suggested by the designer functionality, making it more human readable or less human readable (more or less granular). This would be huge for the customers who are using SecureChange. They said this was one of their issues with it, especially for anything that was going into a regulator's or auditor's hands. The more human readable, the better that it would be, and this would definitely be applicable to our industry. It sounds like they are working on this issue, or they took the feedback, but that would be a big one for us in being able to make the jump to SecureChange."
"Tufin has come a long way when it comes to visibility. What we would like to see is a little bit more on the discovery level, network discovery, which Tufin does not have today."
"I would also like to see them do more cloud integration within the Tufin Orchestration Suite, not within a SaaS solution."
"We need to implement micro-segmentation in our infrastructure, and we are using Cisco ACI. However, we are facing an issue with Tufin, as it does not currently support integration with ACI for micro-segmentation, even though it is advertised as such."
"My worry with Tufin is that it cannot connect to Fortinet, which is what I want to do."
 

Pricing and Cost Advice

"The pricing is flexible with a low cost setup."
"Pricing is easy to grasp."
"The licensing scheme should be done in a simpler way. For example, if we delete a firewall and want to add a new one, then the license doesn't get freed up automatically. You have to request a new license to customer support and install it. If you are testing new implementations, this can be cumbersome."
"Price is not my concern. If a tool does its job, it is not my concern to obtain a good price for it. If a tool is needed, we are going to buy it."
"Licensing is very easy to set up. The pricing is relative to how you want to expand and harden your network security."
"The initial cost was high for us."
"Setup cost and pricing were reasonable and the licensing was straightforward."
"We are working with our finance department right now to be able to purchase it. The AlgoSec team is doing everything that they can in their power to get the costs down to where our budget is. They have worked a lot on it. They have cut the cost in half for us so far by questioning, "This is in the quote. Is this something that is actually needed?" They have pulled some stuff out and cut our costs down by 50% for the product itself."
"Pricing model seems fair."
"Relative to what it offers, the price is fair."
"This is an expensive solution. The cost of three modules for three years was approximately one million."
"The pricing was very good during our initial year, but they increased it this year a little bit. The price is okay. It is not cheap, but it is still average."
"The pricing is very good, very straightforward. It also came in cheaper than AlgoSec and Tufin."
"We don't license all of the devices in our network, so it does not provide us with a comprehensive visibility of all devices in a hybrid network at this time."
"Regarding additional costs, if you want things like Policy Optimizer, extra features, that's extra."
"FireMon is cheaper than AlgoSec."
"We have seen ROI from the side of operations, and we'll probably get to more of that as time goes on. However it took a while to get to that point."
"Pricing is quite high. We did compare it with AlgoSec but the pricing is not much different between the two."
"The seller of Tufin, when I wanted the solution, was very flexible because the cost on the lease was very high in Latin America. So, he was able to reduce the cost."
"The solution is more reasonably priced than its competitors."
"The price of Tufin could be lower."
"Our licensing fees are more than $100,000 USD per year."
"It's not that expensive, except for Security Groups. For us, just the Security Groups were about half of the total price. The total was about €500,000 a year, of which €200,000 was for Security Groups."
"Our licensing costs are pretty low. We were grandfathered in, so we are at about $35,000 per year."
report
Use our free recommendation engine to learn which Firewall Security Management solutions are best for your needs.
869,513 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Financial Services Firm
16%
Manufacturing Company
8%
Healthcare Company
6%
Computer Software Company
14%
Financial Services Firm
14%
Manufacturing Company
11%
Comms Service Provider
7%
Financial Services Firm
17%
Computer Software Company
13%
Manufacturing Company
11%
Retailer
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business57
Midsize Enterprise31
Large Enterprise175
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise9
Large Enterprise44
By reviewers
Company SizeCount
Small Business29
Midsize Enterprise13
Large Enterprise152
 

Questions from the Community

What do you like most about AlgoSec?
AlgoSec's ability to integrate with various security and networking solutions enhances its overall value.
What is your experience regarding pricing and costs for AlgoSec?
Pricing and licensing for AlgoSec depend entirely on custom quotes based on the organization's specific needs. My exp...
What needs improvement with AlgoSec?
One improvement I see for AlgoSec is implementing an optimized rule cleanup and recertification process to address th...
What do you like most about FireMon?
I like the Security Manager console where we can see any changes that have been made or pull the results of an assess...
What is your experience regarding pricing and costs for FireMon?
Comparatively, FireMon has a very good price and is below the general competition in cost. I have not seen any additi...
What needs improvement with FireMon?
For one company I work with, I use Fortinet, and FireMon is not able to understand the zones that Fortinet uses. Part...
What needs improvement with Tufin SecureCloud?
Tufin Orchestration Suite ( /products/tufin-orchestration-suite-reviews ) is not commonly used in Thailand due to a l...
What is your primary use case for Tufin SecureCloud?
I have primarily used Skybox and AlgoSec ( /products/algosec-reviews ). I have also interacted with FireMon for compi...
What advice do you have for others considering Tufin SecureCloud?
There is potential for improvement in explaining the analytics in the dashboard for Tufin Orchestration Suite. Tufin ...
 

Also Known As

No data available
No data available
Tufin SecureCloud
 

Overview

 

Sample Customers

Maersk, Delta Airlines, Chevron, General Motors, T-Mobile, Chevron, AT&T, BP, Bell Canada, HCA Healthcare, Morgan Stanley, Unilever, Nationwide Insurance Enterprise, US Bank, Microsoft 
Convey, MGM Resorts International, Southwest Airlines, Alkami, Costco, Aetna, IBM, Verizon, Wells Fargo
3M, AT&T, Blue Cross Blue Shield, BNP Parabas, ConocoPhillips, Deutsche Bank, GE, IBM, Pfizer, United States Postal Service 
Find out what your peers are saying about AlgoSec, Tufin, Palo Alto Networks and others in Firewall Security Management. Updated: September 2025.
869,513 professionals have used our research since 2012.