Try our new research platform with insights from 80,000+ expert users

AWS Firewall Manager vs Skybox Security Suite comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 7, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

AWS Firewall Manager
Ranking in Firewall Security Management
9th
Average Rating
7.8
Reviews Sentiment
6.6
Number of Reviews
9
Ranking in other categories
No ranking in other categories
Skybox Security Suite
Ranking in Firewall Security Management
7th
Average Rating
7.6
Reviews Sentiment
6.8
Number of Reviews
37
Ranking in other categories
Vulnerability Management (46th)
 

Mindshare comparison

As of October 2025, in the Firewall Security Management category, the mindshare of AWS Firewall Manager is 3.7%, down from 5.7% compared to the previous year. The mindshare of Skybox Security Suite is 9.4%, down from 11.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewall Security Management Market Share Distribution
ProductMarket Share (%)
Skybox Security Suite9.4%
AWS Firewall Manager3.7%
Other86.9%
Firewall Security Management
 

Featured Reviews

Karthik Ekambaram - PeerSpot reviewer
Has centralized rule management and improved protection against suspicious traffic but needs better threat intelligence integration and automated policy enforcement
I have not compared AWS WAF with any other WAF solution yet, but whatever WAF you choose, there will always be challenges, and it cannot block all malicious traffic. For AWS WAF, we have seen cases where it allowed suspicious HTTPS headers even if they carried malicious payloads. However, the malicious payloads are not straightforward, and there are assembly scripts that come with the HTTP headers that sometimes AWS WAF misses. In the last four or five years, we have seen a case where WAF was unable to capture a threat. On the other hand, we also see alerts from WAF indicating that it has figured out many DDoS protection alerts and was able to block them, even with rate limiting. Rule-based WAF works perfectly fine, but I don't think any threat intelligence-based WAF solutions can be 100% accurate. The integration with AWS Organizations and enforcement of security policies, particularly SCP, is difficult to deploy in most of my companies due to client environments. When I say difficult, it depends on the client's organization processes, not AWS itself. The SCP feature is excellent in my view and is the best way to reduce the attack surface for organizations structured in a specific manner. While we have used it internally, limited features of SCPs can be utilized by customers. Regarding automating security policy deployment, we have utilized automated security policy features, but it is difficult in some instances. We have identified what has been identified, but enabling automated SCP policies can be restrictive, which is actually good but makes it hard to implement for all organizations. Automating security policy features could understand the customer's environment better. An AI- or ML-enabled automated SCP could be a better option since it can understand the actions of administrators or developers in the customer's organization within the AWS platform, providing more in-depth automated assessments and SCP features. I rate this solution 8 out of 10.
NenadMijatovic - PeerSpot reviewer
Efficient in vulnerability management, stable and easy to use
Vulnerability management is the most valuable feature because it lets you focus on the most critical vulnerabilities. That's the important thing. Here in Serbia, there are not so many companies that have too many firewalls inside one company. So, they usually don't buy this model for Firewall Assurance unless there is some compliance. So you can prove that your firewalls are compliant. So, that model is not so important here in Serbia. It's for bigger companies. So, they usually buy network assurance to build the model of the network and vulnerability management to focus on the most important vulnerabilities. Moreover, Skybox can collect data for many vendors. From the endpoint protection vendors to the network equipment vendors to other security vendors. So, it supports more than one hundred vendors to collect data from them.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Also, the strength of the community is invaluable."
"We work with compliance monitoring in the product, which is helpful for identifying framework-based misconfigurations, as it can tell you where to deploy firewall policies based on the frameworks."
"The most valuable feature is scaling, which allows you to deploy one configuration and scan and deploy it across the network. The automated policy application feature also streamlines security operations."
"The most valuable feature is the centrally managed rule. I also like the central orchestration."
"AWS Firewall Manager isn't a separate solution when you create the virtual private cloud (VPC), so you can control the traffic through that security group."
"The product is highly reliable."
"It has centralized cloud firewall management rules. It provides compliance in tracking and reporting."
"The interface is intuitive and it is easy for the users."
"The initial setup process was easy."
"Skybox Security Suite is cost-effective."
"The most impressive feature is optimization and clean-up."
"The ability to appropriately prioritize vulnerabilities inside the environment, and then to have visibility into the traffic and rule sets of an organization, are two of the top capabilities that I recommend. Skybox is the only one that does both of those in a single platform."
"When you import all the assets that you have, like desktops, servers, networks, devices, routers, and then firewalls, and other products, then Skybox makes like, a model of the network, but with context. So, it is not just a model in VIZIO. Or something like it like that. You get the model with context, and, like, it looks like a real network in a real-time. So you can check your network and the security of your network on that model."
"The most valuable features of Skybox Security Suite are all the modules that are provided, such as vulnerability assessments and network, and firewall assessments."
"It's given us more visibility in terms of what are the kinds of configurations that are on these devices, and how many of these are stale rules. So it's helped greatly in terms of cleaning up of rules, for sure. And it has definitely given us a more secure way of backing up the configuration on these devices."
"The performance could be good because we chose it at the time, but it is too complex for us to appreciate its performance because we lack the necessary skills."
 

Cons

"I would like to see AWS add some UTM features to the firewall. It would also be great if AWS Firewall had native IPS/IDS. They have the separate IPS/IDS, GuardDuty."
"They could consider organizing and enhancing documentation in a more structured and chronological manner"
"The system should be more customizable."
"This solution is suitable for a small-scale enterprise and may not scale up to a very high volume of traffic or a large number of servers."
"Enabling and configuring the logging is not that straightforward."
"The product could benefit from improvements in the user interface and integration capabilities."
"AWS Firewall Manager should be open to manage other third-party appliances as well."
"For AWS WAF, we have seen cases where it allowed suspicious HTTPS headers even if they carried malicious payloads."
"During implementation, we realised approximately 30 devices were not supported by the Skybox platform​."
"Modifications and the deletion of existing policies are currently unavailable."
"The solution needs to add more automation and orchestration capabilities. Those features would make the solution much stronger."
"The solution was quite technical. It would be easier to manage if the solution was more specific about aspects of the solution and provided more advisory around how to use it effectively. It would help users a lot if they were more clear about everything."
"The solution needs improvement in firewall configuration checks. I would also like to see more configuration checks for Forcepoint and for other non-supported firewalls."
"The Network Assurance, which helps to create the network model, is not so rich."
"The primary room for improvement would be to enable a web interface, which is not something which is there in the product. This is supposed to have come a year, a year and a half ago, but still has failed to come out. It still needs a client application to be installed on a workstation to be able to access that server and then run these reports. So I cannot extend that access to anybody. It has to be one administrator all the time. So unlike a web interface, where you can give multiple users simultaneous access and generate the various reports, that isn't a possibility at the moment."
"Skybox should improve their UX features by making them easier to use."
 

Pricing and Cost Advice

"The licensing is on a pay-as-you-go basis and we are billed monthly."
"The AWS Firewall Manager is a little on the costly side."
"It is a cost-efficient product."
"From what I've heard from my colleagues, it appears that the pricing is competitive, which influenced our decision to choose this option."
"The price is not expensive."
"Skybox Security Suite has indeed helped us reduce costs. The prices of AlgoSec and Skybox Security Suite are approximately 50 percent different. The tool may require special vendor support from abroad, resulting in slightly higher costs. Its pricing is in the middle."
"Pricing is on the higher side. In terms of licensing, you should buy the complete suite rather than buying only the Change Manager. I think Change Manager with Vulnerability Control is something that would be interesting to look at."
"The licensing fee is paid yearly and is approximately $100,000."
"The software is expensive. I rate its pricing an eight out of ten."
"I would rate the tool's pricing an eight out of ten."
"The solution is based on a subscription model for annual licenses."
"Fully understand the total cost of ownership. They have gone to a new model where you have to replace the hardware every X amount of years at a very substantial cost and fully understand your intended number of nodes. To operate a firewall, you have to pay two licenses, a firewall node and a network node. If you are a reasonable-sized organization, this gets expensive very quickly."
report
Use our free recommendation engine to learn which Firewall Security Management solutions are best for your needs.
869,089 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
11%
Financial Services Firm
10%
Comms Service Provider
7%
Manufacturing Company
7%
Financial Services Firm
18%
Computer Software Company
12%
Manufacturing Company
10%
Energy/Utilities Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business5
Large Enterprise6
By reviewers
Company SizeCount
Small Business21
Midsize Enterprise4
Large Enterprise20
 

Questions from the Community

What do you like most about AWS Firewall Manager?
It has centralized cloud firewall management rules. It provides compliance in tracking and reporting.
What is your experience regarding pricing and costs for AWS Firewall Manager?
On a scale of one to ten, I would rate the pricing for AWS Firewall Manager as seven, where one is cheap and ten is expensive.
What needs improvement with AWS Firewall Manager?
AWS Firewall Manager should be open to manage other third-party appliances as well.
What do you like most about Skybox Security Suite?
Overall, the tool has helped us reduce risks. If any step is missing, it's easier for my team or engineers to identify it. The tool provides accurate recommendations based on the data. Its integrat...
What is your experience regarding pricing and costs for Skybox Security Suite?
From a commercial perspective, AlgoSec is more expensive compared to Skybox Security Suite. Skybox Security Suite is cost-effective.
What needs improvement with Skybox Security Suite?
The dashboard's UI is not interesting; it is quite normal. It would be better if something more attractive or similar useful information found in AlgoSec was available.
 

Overview

 

Sample Customers

Expedia, Intuit, Royal Dutch Shell, Brooks Brothers
ADP, Blue Cross Blue Shield, BT, USAID, Delta Dental, EDF Energy, EMC, HSBC, Johnson & Johnson
Find out what your peers are saying about AWS Firewall Manager vs. Skybox Security Suite and other solutions. Updated: September 2025.
869,089 professionals have used our research since 2012.