Try our new research platform with insights from 80,000+ expert users

AWS Firewall Manager vs Tufin Orchestration Suite comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Nov 4, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

AWS Firewall Manager
Ranking in Firewall Security Management
9th
Average Rating
8.0
Reviews Sentiment
6.6
Number of Reviews
10
Ranking in other categories
No ranking in other categories
Tufin Orchestration Suite
Ranking in Firewall Security Management
2nd
Average Rating
8.0
Reviews Sentiment
7.2
Number of Reviews
182
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of November 2025, in the Firewall Security Management category, the mindshare of AWS Firewall Manager is 3.6%, down from 5.4% compared to the previous year. The mindshare of Tufin Orchestration Suite is 22.5%, up from 21.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewall Security Management Market Share Distribution
ProductMarket Share (%)
Tufin Orchestration Suite22.5%
AWS Firewall Manager3.6%
Other73.9%
Firewall Security Management
 

Featured Reviews

Karthik Ekambaram - PeerSpot reviewer
Has centralized rule management and improved protection against suspicious traffic but needs better threat intelligence integration and automated policy enforcement
I have not compared AWS WAF with any other WAF solution yet, but whatever WAF you choose, there will always be challenges, and it cannot block all malicious traffic. For AWS WAF, we have seen cases where it allowed suspicious HTTPS headers even if they carried malicious payloads. However, the malicious payloads are not straightforward, and there are assembly scripts that come with the HTTP headers that sometimes AWS WAF misses. In the last four or five years, we have seen a case where WAF was unable to capture a threat. On the other hand, we also see alerts from WAF indicating that it has figured out many DDoS protection alerts and was able to block them, even with rate limiting. Rule-based WAF works perfectly fine, but I don't think any threat intelligence-based WAF solutions can be 100% accurate. The integration with AWS Organizations and enforcement of security policies, particularly SCP, is difficult to deploy in most of my companies due to client environments. When I say difficult, it depends on the client's organization processes, not AWS itself. The SCP feature is excellent in my view and is the best way to reduce the attack surface for organizations structured in a specific manner. While we have used it internally, limited features of SCPs can be utilized by customers. Regarding automating security policy deployment, we have utilized automated security policy features, but it is difficult in some instances. We have identified what has been identified, but enabling automated SCP policies can be restrictive, which is actually good but makes it hard to implement for all organizations. Automating security policy features could understand the customer's environment better. An AI- or ML-enabled automated SCP could be a better option since it can understand the actions of administrators or developers in the customer's organization within the AWS platform, providing more in-depth automated assessments and SCP features. I rate this solution 8 out of 10.
MithatBulut - PeerSpot reviewer
New employees can quickly grasp the various IPs, devices, and the network's logical and physical
Tufin is primarily used to orchestrate and manage network traffic and firewall devices. It is specifically useful for implementing firewall policies and handling requests from clients that require policy updates or changes Tufin simplifies understanding network topology. New employees can quickly…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Once this solution is set up, we hardly have to touch it."
"We work with compliance monitoring in the product, which is helpful for identifying framework-based misconfigurations, as it can tell you where to deploy firewall policies based on the frameworks."
"The most valuable feature is the centrally managed rule. I also like the central orchestration."
"Also, the strength of the community is invaluable."
"AWS Firewall Manager isn't a separate solution when you create the virtual private cloud (VPC), so you can control the traffic through that security group."
"It is helpful for our compliance, as the compliance manager manages compliance with leading industry standards such as FedRAMP, which my company complies with, GDPR laws, and ISO 27001."
"The product is highly reliable."
"It has centralized cloud firewall management rules. It provides compliance in tracking and reporting."
"We can check and analyze the current status of our firewall rules."
"Tufin Orchestration Suite is a good tool that makes firewall policies faster to implement from a central point, and its support is good."
"The most valuable feature of Tufin is we have better visibility and management of our file infrastructure."
"Tufin simplifies understanding network topology."
"The automation because it is saving a lot of work, time, and effort required to do all of our manual work. The change impact analysis is pretty good, and with the automation, it takes care of a lot of things which we would be doing manually."
"We use this product to sharpen our change cycle. A request used to take quite a while as we did manual assessments. A lot of that is now done through SecureTrack."
"The policy overview is valuable."
"The stability is bulletproof."
 

Cons

"The product could benefit from improvements in the user interface and integration capabilities."
"They could consider organizing and enhancing documentation in a more structured and chronological manner"
"This solution is suitable for a small-scale enterprise and may not scale up to a very high volume of traffic or a large number of servers."
"Enabling and configuring the logging is not that straightforward."
"The areas of improvement are definitely platform resiliency, as we have seen outages on the AWS backbone, and whenever there is an outage on the AWS backbone, it impacts all the services hosted on that region, so we expect regional resiliency."
"It needs to be more employee-friendly, and the security management could be more efficient."
"AWS Firewall Manager should be open to manage other third-party appliances as well."
"For AWS WAF, we have seen cases where it allowed suspicious HTTPS headers even if they carried malicious payloads."
"We use a lot of inline rules, and it would be beneficial to see those from within Tufin."
"The initial setup can be tough."
"The product should integrate with the UTM features."
"The network part of the solution could be improved. It's too hard because of the Tufin licensing model for the routing devices."
"The metrics need improvement. They need more consistency or understanding of automation, along lines of customization of automation."
"My worry with Tufin is that it cannot connect to Fortinet, which is what I want to do."
"While Tufin is suitable for small businesses, issues can arise in larger enterprises, particularly concerning policy-based forwarding and NAT traffic."
"We found some bugs on the software, but we're working with tech support to fix them."
 

Pricing and Cost Advice

"It is a cost-efficient product."
"The AWS Firewall Manager is a little on the costly side."
"The licensing is on a pay-as-you-go basis and we are billed monthly."
"From what I've heard from my colleagues, it appears that the pricing is competitive, which influenced our decision to choose this option."
"The solution has helped us to reduce the time it takes to make changes. With Tufin, it takes ten to 15 minutes. Before, it was 30 minutes or more."
"Our engineers are spending less time on manual processes: 20 to 30 hour plus."
"We did look at less expensive solutions than Tufin, but being a corporation, this solution made sense."
"Our licensing costs are pretty low. We were grandfathered in, so we are at about $35,000 per year."
"We have seen ROI in operational aspects, in terms of how long it takes to resolve incidences which arise."
"Licensing is on a customer by customer basis."
"I had a bad experience with the financial department, and the price is too high. The software does work and does the job. The solution is worth the money. If I had a different partner to implement the solution, it would have been worth the price."
"We are seeing ROI in terms of having SecureApp."
report
Use our free recommendation engine to learn which Firewall Security Management solutions are best for your needs.
873,085 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
10%
Computer Software Company
10%
Comms Service Provider
7%
Retailer
7%
Financial Services Firm
16%
Computer Software Company
12%
Manufacturing Company
11%
Retailer
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business5
Large Enterprise7
By reviewers
Company SizeCount
Small Business29
Midsize Enterprise13
Large Enterprise152
 

Questions from the Community

What is your experience regarding pricing and costs for AWS Firewall Manager?
Microsoft Firewall costs depend on region-based pricing. I don't recall the exact costs because we usually don't get the costing for the firewall alone but rather for the entire product we use, so ...
What needs improvement with AWS Firewall Manager?
I don't see any specific problems with AWS Firewall Manager, but the area of improvement could be in threat intelligence integration. For instance, while I'm not specifically saying Mandiant, which...
What is your primary use case for AWS Firewall Manager?
The major use case for AWS Firewall Manager is to deploy firewalls in front of the products we expose to the internet in our Kubernetes clusters and AKS clusters, ensuring we block DDoS attacks and...
What needs improvement with Tufin SecureCloud?
Tufin Orchestration Suite ( /products/tufin-orchestration-suite-reviews ) is not commonly used in Thailand due to a lack of local support, and many customers are switching to AlgoSec or other vendo...
What is your primary use case for Tufin SecureCloud?
I have primarily used Skybox and AlgoSec ( /products/algosec-reviews ). I have also interacted with FireMon for compiling. However, I am not currently working with ACA, and I don't have any project...
What advice do you have for others considering Tufin SecureCloud?
There is potential for improvement in explaining the analytics in the dashboard for Tufin Orchestration Suite. Tufin Orchestration Suite does provide good monitoring; however, interpreting the grap...
 

Also Known As

No data available
Tufin SecureCloud
 

Overview

 

Sample Customers

Expedia, Intuit, Royal Dutch Shell, Brooks Brothers
3M, AT&T, Blue Cross Blue Shield, BNP Parabas, ConocoPhillips, Deutsche Bank, GE, IBM, Pfizer, United States Postal Service 
Find out what your peers are saying about AWS Firewall Manager vs. Tufin Orchestration Suite and other solutions. Updated: September 2025.
873,085 professionals have used our research since 2012.