Try our new research platform with insights from 80,000+ expert users

FireMon Security Manager vs ManageEngine Firewall Analyzer vs RedSeal comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

Firewall Security Management Market Share Distribution
ProductMarket Share (%)
FireMon Security Manager17.8%
Tufin Orchestration Suite22.6%
AlgoSec22.5%
Other37.099999999999994%
Firewall Security Management
Firewall Security Management Market Share Distribution
ProductMarket Share (%)
ManageEngine Firewall Analyzer3.3%
Tufin Orchestration Suite22.6%
AlgoSec22.5%
Other51.599999999999994%
Firewall Security Management
Risk-Based Vulnerability Management Market Share Distribution
ProductMarket Share (%)
RedSeal0.5%
Qualys VMDR16.1%
Rapid7 InsightVM14.2%
Other69.2%
Risk-Based Vulnerability Management
 

Featured Reviews

Ganesh-Khutwad - PeerSpot reviewer
Rapid policy insights with robust dashboards and cross-vendor automation
FireMon Security Manager is excellent for real-time compliance management. It allows us to quickly retrieve any policy needed for testing and easily analyze it for loopholes. If a loophole exists, FireMon provides comprehensive details within the policy manager. It alerts us to firewall rule additions or changes that violate compliance policies. It supports various firewall platforms, including Checkpoint, Zscaler, Fortinet, Cisco, and AWS, and provides centralized management for all configured policies through a single console. FireMon Security Manager provides many features, like whether my firewall is compatible with required standards such as NTP and SNMP. Each compliance included in our RFPs is shown in the UI of FireMon. It gives robust and clear dashboards, making it easier to understand risks because the policies have ratings showing usage, and the number of hit attacks. It streamlines our compliance reporting processes by providing comprehensive risk and compliance assessments. It offers a range of features, including verification of firewall compatibility with protocols like NTP and SNMP, and detection of signal charges. FireMon effectively addresses all compliance requirements outlined in our RFPs. For instance, it can determine if firewalls or proxies within a stack are configured in Secure Mode or Active-Active mode. FireMon Security Manager enables us to generate reports on all these aspects, ensuring thorough compliance monitoring and documentation. FireMon Security Manager is robust and can help automate firewall policy changes across large multi-vendor enterprise environments. FireMon Security Manager helps automate firewall policy changes across various environments, including on-premises, cloud, hybrid, SASE, and SD-WAN. It also simplifies cleaning up firewall rules in our environment. The time required to accurately create, approve, and deploy firewall policy rules has been reduced. Tasks that took 30 minutes can now be completed in just five minutes using FireMon. FireMon provides immediate visibility into our policies through a robust and clear dashboard, making it easy to identify errors or misconfigurations based on the policy rating.
Hoa-Nguyen - PeerSpot reviewer
Implementation supports efficient network management but requires improvement in device handling capacity
The strong points of ManageEngine Firewall Analyzer are many, but I think my favorite feature focuses on the VPN traffic. If I want to manage my policy and optimize it, I find that ManageEngine Firewall Analyzer supports many vendors after Firewall. One aspect I want to improve in ManageEngine Firewall Analyzer is the maximum number of firewalls that can be managed. I learned from the internal support team that one prop server only supports three to five firewalls. I think one prop server can manage a maximum of five because if I have many devices here, the performance of the prop would be very high, considering CPU and RAM usage.
Sajid Mukhtar - PeerSpot reviewer
Provides a graphical overview of our network and is easy to deploy, but needs a user-friendly interface and a feature for compliance audit policy
Sometimes, it required us to refresh the configuration. When we integrated any of the configurations into the device, sometimes, it could not detect the exact picture of that device. So, we had to reset the device to see that if it was giving true-positive results or false-positive results. In some cases, we were not able to get true-positive results. There was some kind of bug in that version. Its interface is not user-friendly and needs to be improved. It takes time to understand the interface and various options. Skybox has quite a user-friendly interface. They could provide a feature for compliance audit policy if it is already not there. A compliance audit policy ensures that all configurations are based on the best practices standards, such as CIS benchmarks standard or other similar standards. It provides visibility about whether your device configuration is based on best practices or not. Usually, such a feature is provided by other solutions such as Meteor or Tenable Nessus.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"For the cleanup of firewall rules, it performs really well for us. We utilize it in our regular rule cleanup tasks, several times a year. FireMon is our primary tool when doing that, either by going through its out-of-the-box compliance rules or using it to search for certain things in our rules that we want to prune from our firewalls."
"Its user-friendly interface allows for easy viewing and searching of network policies, including proxies, all on one console."
"The most valuable feature for me is its capability for cleanup and managing the complexity of security products."
"Vendor agnostic when it comes to integrating with other product."
"The most valuable feature is the reporting capability because everything that we do is a result of our being able to query a report, based on our environment and our PCI compliance efforts."
"The firewall assessment feature is great."
"In one report, FireMon tells us there are, say, 1,000 rules that can be taken out and it gives us the ability to disable those for a year and to track when we made our changes. After a year, we can go back and eliminate the rules, to bring the configuration down to an almost human-readable level."
"Firewall auditing is very important. We also use the solution for rule traffic analysis, traffic flow discovery and hidden/shadow rules within over 100 firewalls spanning five different brands."
"Firewall Analyzer helps our organization to fulfill the compliance requirement as per ISO 27001, managing the network security effectively."
"The strong points of ManageEngine Firewall Analyzer are many, but I think my favorite feature focuses on the VPN traffic."
"The most valuable features of the ManageEngine Firewall Analyzer are the monitoring of the full management of the network elements and the inventory of the infrastructure."
"The most valuable feature of the solution is that it is a very user-friendly tool compared to other solutions."
"Firewall Analyzer is easy to work with."
"Overall the solution does a good job."
"I found the reporting to be useful because not only can I go back months, but it lists the individual URLs and the time that a particular person visited."
"RedSeal integrates the network and gives us a visual or graphical overview of our network. If an organization is geographically dispersed, for instance, with one office in Canada and one office in the Philippines, the whole network, including all devices, is integrated into RedSeal, and you can see from where the traffic is going in and out."
"This is the only solution in the world that gives you a digital resilience score."
"The most valuable features are network mapping and configuration."
"RedSeal has different modules, such as the Analyzer module, which can be leveraged."
 

Cons

"To my knowledge, there's no cloud component to FireMon whatsoever. We're on the hook for any updates to versioning of the operating system or the application that runs on the operating system. It would be nice if it was a little bit more automated."
"The AWS integration is still not mature for us to use. It is just not ready for our use case for AWS connectivity. Therefore, it does not provide us with a single pane of glass for our cloud environments, because we can't manage our cloud environment with the tool."
"Some of the core functionality in our environment doesn't seem to work. We will get buggy code releases. They need to work on their Q&A of every code release."
"The cost of the solution is pretty expensive. It would be ideal if they could work on their pricing."
"A feature that could be improved is support for more devices, not just the firewall."
"The training for configuring new users or operators is confusing because the UI is not user-friendly and has room for improvement."
"When it comes to identifying risk in our environment and prioritizing fixes, it is really about the different priorities within the organization. FireMon is not so smart that it can tell what's important to us. It's up to us to figure that out."
"We've had recurring issues managing FireMon's internal backups. Sometimes, the space allocated for the backup is full, and there is no process where it deletes files that are older than I certain date. It's just waiting for the storage to get full and then it's cleaned up. It isn't something that creates serious issues for us."
"It would be awesome if the product could monitor services for applications."
"The solution lacks a lot of features that other products have in the marketplace."
"One aspect I want to improve in ManageEngine Firewall Analyzer is the maximum number of firewalls that can be managed. I learned from the internal support team that one prop server only supports three to five firewalls."
"If there is a need to get some customized report or anything, ManageEngine Firewall Analyzer takes some time."
"The stability is so-so. There are always memory issues, but the solution is working great apart from that."
"ManageEngine Firewall Analyzer can improve by having better monitoring of all features from firewalls. We are using Kibana in order to monitor parts that this solution does not record. For example, having more correlation and proactive monitoring in some activity or scenario."
"There is room for improvement in integrating the OT security part and the private 5G security part in RedSeal."
"One of the areas of concern is the GUI. It is important to our customers that the GUI looks beautiful. It's a Java Client, so you have a Java dependency."
"The dashboard should be improved to make correlating data easier to do."
"Sometimes, it required us to refresh the configuration. When we integrated any of the configurations into the device, sometimes, it could not detect the exact picture of that device. So, we had to reset the device to see that if it was giving true-positive results or false-positive results. In some cases, we were not able to get true-positive results. There was some kind of bug in that version. Its interface is not user-friendly and needs to be improved. It takes time to understand the interface and various options. Skybox has quite a user-friendly interface. They could provide a feature for compliance audit policy if it is already not there. A compliance audit policy ensures that all configurations are based on the best practices standards, such as CIS benchmarks standard or other similar standards. It provides visibility about whether your device configuration is based on best practices or not. Usually, such a feature is provided by other solutions such as Meteor or Tenable Nessus."
 

Pricing and Cost Advice

"FireMon is cheaper than AlgoSec."
"Its pricing is good. Compared to others, it is not so expensive."
"The pricing was very good during our initial year, but they increased it this year a little bit. The price is okay. It is not cheap, but it is still average."
"We pay for it yearly."
"Pricing model seems fair."
"It's a good value. From a licensing standpoint... it's very simple to understand, and gives us a good bang for the buck."
"Relative to what it offers, the price is fair."
"FireMon is very expensive. I think that they charge a premium. In general, they are very pricey. Compared to their competitors, they cost a little more than the other solutions that we evaluated."
"I know that the price of the products is flexible. There have been different types of products, like professional and enterprise-based ones, and depending on the requirements, customers can choose their products."
"Needs to work on pricing."
"ManageEngine Firewall Analyzer is less expensive than some of their competitors, such as Cisco. The price is one of the reasons why we use ManageEngine Firewall Analyzer."
"The pricing is based on the number of endpoints and devices, and we have seen it range from mid-five figures to low six figures."
report
Use our free recommendation engine to learn which Firewall Security Management solutions are best for your needs.
867,821 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
14%
Manufacturing Company
11%
Comms Service Provider
7%
Computer Software Company
18%
Healthcare Company
10%
Comms Service Provider
10%
Energy/Utilities Company
8%
Government
22%
Energy/Utilities Company
7%
Manufacturing Company
7%
Retailer
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise9
Large Enterprise44
By reviewers
Company SizeCount
Small Business3
Midsize Enterprise1
Large Enterprise10
By reviewers
Company SizeCount
Small Business1
Midsize Enterprise1
Large Enterprise7
 

Questions from the Community

What do you like most about FireMon?
I like the Security Manager console where we can see any changes that have been made or pull the results of an assess...
What is your experience regarding pricing and costs for FireMon?
Comparatively, FireMon has a very good price and is below the general competition in cost. I have not seen any additi...
What needs improvement with FireMon?
For one company I work with, I use Fortinet, and FireMon is not able to understand the zones that Fortinet uses. Part...
What do you like most about ManageEngine Firewall Analyzer?
The most valuable feature of the solution is that it is a very user-friendly tool compared to other solutions.
What is your experience regarding pricing and costs for ManageEngine Firewall Analyzer?
The pricing and overall licensing cost of ManageEngine Firewall Analyzer is very cost-effective compared to global co...
What needs improvement with ManageEngine Firewall Analyzer?
To improve ManageEngine Firewall Analyzer, they need to implement Zero Touch Provisioning (ZTP) support for firewalls...
What needs improvement with RedSeal?
There is room for improvement in integrating the OT security part and the private 5G security part in RedSeal.
What is your primary use case for RedSeal?
The primary use cases for RedSeal are lifecycle management, vulnerabilities, and change management. Customers might l...
 

Overview

 

Sample Customers

Convey, MGM Resorts International, Southwest Airlines, Alkami, Costco, Aetna, IBM, Verizon, Wells Fargo
WFP, NYC.gov, Sony Pictures, Franklin Security Bank, ITC INFOTECH
United States Postal Service, Pacific Gas and Electric Co., Interval International
Find out what your peers are saying about AlgoSec, Tufin, Palo Alto Networks and others in Firewall Security Management. Updated: August 2025.
867,821 professionals have used our research since 2012.