Try our new research platform with insights from 80,000+ expert users

Check Point CloudGuard Network Security vs Prisma SD-WAN comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 16, 2024
 

Categories and Ranking

Check Point CloudGuard Netw...
Ranking in Software Defined WAN (SD-WAN) Solutions
3rd
Ranking in WAN Edge
3rd
Average Rating
8.6
Number of Reviews
126
Ranking in other categories
Firewalls (8th), Managed Security Services (2nd), Cloud and Data Center Security (6th), Unified Threat Management (UTM) (6th)
Prisma SD-WAN
Ranking in Software Defined WAN (SD-WAN) Solutions
4th
Ranking in WAN Edge
4th
Average Rating
8.8
Number of Reviews
18
Ranking in other categories
Secure Access Service Edge (SASE) (7th)
 

Featured Reviews

PRASHANT GARJE - PeerSpot reviewer
May 22, 2024
Cost-effective, supports automation, and provides good security
We have done a lot of automation with the firewall, but sometimes, there are some failures because of some bugs. The fixes for them are still not available. We have daily or weekly communication with the Check Point people giving support in the India region, but we have not seen much improvement or response to our requests for some additional features. We are moving to infra as a code, so we are expecting more advancements in this product. Just installing the patches is not going to help us. They need to focus on this area. I expect Check Point CloudGuard to come up with some AI/ML integration. A firewall is the first L3 security device available to you. It is the single point that manages or processes the traffic for an organization. There is a possibility that the device goes down or gets rebooted for any reason. The integration of artificial intelligence with the devices can help us to know in advance that there might be a surge in traffic. There might be a spike in the traffic, so we can have some additional firewalls integrated. This predictive analysis has to be there. This way, if required, a second, third, or fourth firewall can come into the picture. All the firewalls will process the traffic simultaneously. I am expecting such capability. This sort of feature is available with AWS. We are deploying all the firewalls on AWS, but it would be easy if, in the future, such a feature is available from the OEM or Check Point itself. It will be very helpful for the organization. We have had a couple of outages because of some misconfiguration. They were human errors but there were no prior indications that if we were making these sorts of changes, this would happen. People making the changes on the firewall were not aware of this, and that is the reason why the outage happened. In a financial organization, an outage of even five minutes can cost a lot.
Imran Taiyeb Ali - PeerSpot reviewer
Nov 13, 2023
A stable tool that offers a good uptime and ensures a return on investment
There are some small issues in Prisma SD-WAN's area related to bypass pair or couple ports related to redundancy. Sometimes, during the product's initial setup phase, bypass pair or couple ports don't come up normally, and it requires an hour and a half to troubleshoot to reset the box from Prisma SD-WAN to factory default. Prisma SD-WAN has some minor issues in its physical port, especially in bypass pair or couple ports. Bypass pair or couple ports are not abnormal ports. It is just that the aforementioned ports behave differently. If Prisma SD-WAN can fix bypass pair or couple ports and make them robust enough to work after the initial setup in the first attempt, then it can save a lot of time. The physical device's bypass pair or couple ports generally have issues.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The tool's most valuable features are threat prevention and protection mechanisms."
"The SSL spectrum proved to be the most valuable for our incoming connections."
"What's most valuable to me is that it's a contiguous solution that aligns well with the components that we've relied on and trusted from a traditional hardware, firewall, and unified threat management system. My engineers and analysts don't have to learn another platform. We have already entrusted our security controls to Check Point for perimeter and physical security, and now we can do so at the virtual layer as well, which is key to us."
"It offers remarkable flexibility in how we configure and utilize the resources."
"Check Point CloudGuard is quick to deploy and easy for the customer to use."
"Any kind of cloud environment anywhere can be protected through this effortlessly."
"This solution has good scalability and stability."
"The tool's most valuable features for us are threat prevention, HTTPS inspection, and the Anti-Bot blade. Threat prevention helps to protect our assets from threats. HTTPS inspection ensures secure communication, and the Anti-Bot blade is particularly helpful in detecting C2 servers, enhancing our ability to identify malicious activities and protect our network."
"The solution allows our network to be self-healing in the event of a loss of connectivity between different locations."
"Prisma supports all of the applications we're currently using."
"From the main controller, we can administer the customer's devices, QoS, network, and traffic. We can monitor it and we can change and create policies as well as upgrade the software. We can totally control a customer's network from one site, the Prisma SD-WAN portal."
"Prisma SD-WAN is intuitive. We have a better idea of the different tools we can use and jump between the menus quickly."
"The security offered by the solution is pretty good."
"If the MPLS goes down, there is a really smooth transition for a branch site to take traffic over the Internet. It will advertise the routes of that site in a jiffy."
"The gateway is available on the cloud which allows you access from anywhere and still connects to your home gateway."
"The dynamic routing in Prisma SD-WAN is high-speed and valuable because it quickly adjusts, so users do not realize the link is down."
 

Cons

"The main issue that I have noticed is that for deployment, it still requires a dedicated management server, and the gateway is completely different. That sometimes can cause issues."
"There are some usability issues we'd like to see improved."
"The user experience might suffer if we don't have the time to follow up with our clients and ensure they are using the right options. Clients also want more local support in Portuguese and Spanish during their normal business hours. That's something I hear from my customers and my team, too."
"The convergence time between cluster members is still not perfect. It's far away from what we get in traditional appliances. If a company wants to move mission-critical applications for an environment to the cloud, it somehow has to accept that it could have downtime of up to 40 seconds, until cluster members switch virtual IP addresses between themselves and start accepting the traffic. That is a little bit too high in my opinion. It's not fully Check Point's fault, because it's a hybrid mechanism with AWS. The blame is 50/50."
"We have the product deployed on Azure China. One crucial concern is the version limitation; unfortunately, in Azure China, we are restricted to running version R80. Our architecture has a Load Balancer, VMSS CloudGuard, etc. The duplication in this setup prevents the application from seeing the original client IP. This poses a problem for certain applications that require the original IP for login purposes. Although we managed a workaround with a different architecture involving a WAF, it is not as straightforward as the standard Azure setup."
"There is room for improvement in addressing bugs and support issues."
"We utilize logging systems, and geolocation is crucial for us as some applications must only be accessible from our country. However, there have been occasional issues with this feature."
"Check Point CloudGuard Network Security could improve by making it easier to configure."
"Customer support is our biggest pain point. The quality of support has gone down a little since we initially deployed this product. I don't know if this is due to turnover at Palo Alto or a lack of training. It is now taking one or two days to get an initial response that says, "Hey, we've looked into this, can you pull this data for us?" In the past, we'd immediately get a response."
"The tool needs to work on price and complexity."
"Prisma SD-WAN's technical support should be improved."
"We are incorporating their zone-based firewalls. Prisma SD-WAN has limited documentation on how it manipulates traffic, e.g., how it is interacting with TCP and UDP. We recently had some traffic that was black holing. We literally had to do packet captures to see that the new zone-based firewall, which runs on top of Prisma SD-WAN, was causing issues."
"Prisma could be a little cheaper."
"There are two parallel things that we want Palo Alto to work on. First, customers want a unified appliance that does the work of all firewalls in addition to SD-WAN. Second, the cloud presence should be completely automated. If I purchase the SASE architecture, I shouldn't worry about deployments in Prisma Access or on Prisma SD-WAN. It should be deployed in one go."
"The only con is the pricing because it's more premium."
"The solution should include custom ports and group voice connections."
 

Pricing and Cost Advice

"On average, it is normally on the lower end, being less expensive than Palo Alto or Cisco."
"The product is too expensive."
"The price of Check Point CloudGuard Network Security is very high compared to other solutions, such as Fortinet FortiMail. For the over 2,000 mailboxes we use with the solution it is very expensive."
"Check Point CloudGuard Network Security's pricing is far better than Palo Alto's because Palo Alto is very expensive."
"CloudGuard Network Security is not too cheap."
"It is the most expensive part of the product. There is a lot of room for improvement. Security comes with a price, but it is still a big chunk just for the service."
"We have a pretty good partnership with Check Point. We have a global subscription and agreement. They give us a pretty good corporate discount."
"It's not very expensive. It isn't very cheap either. Its price is okay. It depends on how much money you have. It might be expensive for some companies. Its licensing is on a yearly basis."
"Prisma SD-WAN is a pretty expensive solution."
"If you're already invested in a Palo Alto product, it would be logical to use this solution. If not, there might be some other solutions that are more viable in terms of pricing."
"It is more expensive than Fortinet."
"This solution stood out because it cost considerably less than the other SD-WAN solutions out there from Cisco."
"On a scale from one to ten, where one is cheap and ten is expensive, I rate the solution's pricing an eight out of ten."
report
Use our free recommendation engine to learn which Software Defined WAN (SD-WAN) Solutions solutions are best for your needs.
812,628 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
17%
Financial Services Firm
13%
Manufacturing Company
7%
Retailer
6%
Educational Organization
25%
Computer Software Company
11%
Manufacturing Company
8%
Financial Services Firm
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Check Point CloudGuard Network Security?
The tool's most valuable feature is its management console.
What is your experience regarding pricing and costs for Check Point CloudGuard Network Security?
CloudGuard is pretty expensive. Azure ends up being cheaper. They are fairly priced. It's not cheap. However, you definitely need to spend some dollars on security. While it's rather fair pricing, ...
What needs improvement with Check Point CloudGuard Network Security?
The solution's future releases would benefit from incorporating more advanced machine learning capabilities for real-time threat detection and enhanced user interface options for ease of use.
What do you like most about Prisma SD-WAN?
The product's initial setup phase is straightforward.
What is your experience regarding pricing and costs for Prisma SD-WAN?
Pricing can be an issue. Some customers may find it unaffordable due to their budget constraints.
What needs improvement with Prisma SD-WAN?
The pricing model could be improved to make it more affordable for smaller companies.
 

Also Known As

CloudGuard IaaS, Check Point vSEC, CloudGuard IaaS, Check Point Virtual Systems, Check Point CloudGuard Network Security
CloudGenix
 

Overview

 

Sample Customers

Physicians Choice Laboratory Services, Helvetica Insurance
Open Networking User Group, Columbia Sportswear Company, Coca Cola
Find out what your peers are saying about Check Point CloudGuard Network Security vs. Prisma SD-WAN and other solutions. Updated: August 2024.
812,628 professionals have used our research since 2012.