No more typing reviews! Try our Samantha, our new voice AI agent.
Vishal Koovaparambil - PeerSpot reviewer
Server Security Analyst And Solution at Digitaltrack
Real User
Top 5Leaderboard
Jul 9, 2026
Centralized firewall oversight has improved compliance and reduced configuration errors
Pros and Cons
  • "FireMon Security Manager provides a very good return on investment because we are able to save our time and money."

    What is our primary use case?

    FireMon Security Manager is used to centrally manage multiple firewalls, enforce security policies, monitor threats, and simplify day-to-day firewall administration.

    FireMon Security Manager allows us to manage multiple firewalls from a single console, making policy updates and monitoring very easy, and troubleshooting much faster and more consistent.

    FireMon Security Manager is deployed in our organization on-premises within our data center.

    What is most valuable?

    The best features of FireMon Security Manager are centralized policy management and security policy analysis, which is very useful, along with compliance reporting and clear visibility across all the managed firewalls. These features help us to simplify firewall management and improve security.

    FireMon Security Manager has positively impacted our organization by improving our firewall management by increasing visibility, reducing configuration errors, streamlining policy changes, and helping maintain compliance.

    What needs improvement?

    FireMon Security Manager could be improved with a more user-friendly interface. Otherwise, the performance and the deployment are perfect.

    For how long have I used the solution?

    We have not switched solutions; we started with FireMon Security Manager only.

    Buyer's Guide
    FireMon Security Manager
    September 2026
    Learn what your peers think about FireMon Security Manager. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
    914,109 professionals have used our research since 2012.

    What do I think about the stability of the solution?

    FireMon Security Manager is a pretty stable solution.

    What do I think about the scalability of the solution?

    Scalability-wise, FireMon Security Manager is a very good solution that can handle our organization's growth.

    How are customer service and support?

    Customer support for FireMon Security Manager is very supportive, and they are able to provide support and troubleshoot issues at any time.

    Which solution did I use previously and why did I switch?

    We have not evaluated other options before choosing FireMon Security Manager.

    What was our ROI?

    FireMon Security Manager provides a very good return on investment because we are able to save our time and money.

    What other advice do I have?

    FireMon Security Manager helps reduce configuration errors by identifying duplicate, unused, and overly permissive firewall rules before changes are implemented. This reduces the risk of misconfiguration and keeps security policies consistent across all firewalls.

    Regarding FireMon Security Manager's AI capabilities, its governance and security appear very well-designed. They provide controlled access, support compliance, and policy validation, which is very helpful.

    The data that FireMon Security Manager provides is very accurate and reliable, with reliable output.

    I recommend clearly defining your firewall management and compliance requirements before deploying FireMon Security Manager and taking advantage of its policy analysis and compliance features. This will help the organization to achieve a compliance-ready environment and gain proper visibility.

    I rate this product 9 out of 10.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    Last updated: Jul 9, 2026
    Flag as inappropriate
    PeerSpot user
    Cyber Security Consultant at a tech vendor with 10,001+ employees
    MSP
    Top 20
    Aug 31, 2026
    Reporting has strengthened audit readiness but struggles to handle very large rule sets
    Pros and Cons
    • "What I like the most about FireMon Security Manager is the reporting feature; it gives all the rules in one console, so we are able to see all those rules without logging into each firewall."
    • "Regarding the overall scalability of FireMon Security Manager, I would say it is not very scalable. If the rule count goes on increasing, sometimes, for example, if we have a firewall and it's used for all the sites, the device count increases and the rule count increases massively, FireMon sometimes cannot handle it effectively."

    What is our primary use case?

    FireMon Security Manager integrates reasonably well into my security stack. We are able to onboard the devices quite easily, but some advanced features of the firewalls take time to support. Sometimes when a new feature is introduced on the firewall side, FireMon may take some time to incorporate it.

    If I were to speak to someone looking to buy FireMon Security Manager, I would say the biggest win is the reporting feature. If your environment is not very large and if you don't have a massive amount of rule sets, then you can go with FireMon Security Manager. It works well with the reporting, and you can use it for getting the reports and presenting them for audit and compliance. It can be used effectively, but if the rule count is huge, it is not very scalable. If your environment is large, then you may get some issues with getting the reports; sometimes the report won't load if the rule count is very high.

    What is most valuable?

    What I like the most about FireMon Security Manager is the reporting feature; it gives all the rules in one console, so we are able to see all those rules without logging into each firewall. Reporting allows us to fetch the rules, for example, risky rules, and other similar information very easily in one place.

    The reports from FireMon Security Manager for communicating risk reduction, compliance status, or overall security posture to my higher-ups are very good. We are actually using it to get the reports and present them to senior officers.

    What needs improvement?

    FireMon Security Manager should have tested more use cases. Sometimes organizations will have a larger number of devices and a larger number of firewall rules. Sometimes FireMon could not handle such an amount of rule sets, and it will cause some issues with normalizing flows data.

    One thing about FireMon Security Manager is that the releases are quite frequent. We need to upgrade more frequently. They release every quarter, but the frequency is comparatively high when compared to others. For FireMon Security Manager, we don't face many outages, but we need to upgrade it frequently to get the patches and the fixes for the issues.

    For how long have I used the solution?

    In my career, I have been using FireMon Security Manager for five years.

    What do I think about the stability of the solution?

    I have seen lagging, crashing, or downtime; sometimes some service crashed, and I needed to restart those services, identify those services, and restart them. It is not very frequent, but it happened.

    What do I think about the scalability of the solution?

    Regarding the overall scalability of FireMon Security Manager, I would say it is not very scalable. If the rule count goes on increasing, sometimes, for example, if we have a firewall and it's used for all the sites, the device count increases and the rule count increases massively, FireMon sometimes cannot handle it effectively.

    How are customer service and support?

    The speed of support for FireMon Security Manager depends on the severity of the issue. If it is a minor issue, then it will be faster; if it is a major issue, sometimes it will require their development team to get involved. In those cases, it will take a long time; it could sometimes take months to solve the issue.

    For the support of FireMon Security Manager, I would give a six or seven on a scale from one to ten, with ten being the highest.

    Which solution did I use previously and why did I switch?

    Previously, I used AlgoSec in my previous organization, but I didn't use it as extensively as FireMon Security Manager, so I don't have much to compare the two.

    How was the initial setup?

    When I first started using FireMon Security Manager, it was moderate. There were people from FireMon giving us the knowledge articles and how to navigate things, so it was not very hard to learn. It is moderate; someone with two to three years of experience can understand it easily.

    What other advice do I have?

    Overall, I would give FireMon Security Manager a six out of ten for everything.

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    Last updated: Aug 31, 2026
    Flag as inappropriate
    PeerSpot user
    Buyer's Guide
    FireMon Security Manager
    September 2026
    Learn what your peers think about FireMon Security Manager. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
    914,109 professionals have used our research since 2012.
    SE at ATIVASEC
    Real User
    Top 20
    Sep 15, 2026
    Visibility has transformed daily security operations and simplifies multi-vendor policy changes
    Pros and Cons
    • "Since adding FireMon Security Manager inside our environment, our security perspective improves daily, giving us visibility on every change made and allowing us to address any potential security vulnerabilities timely."
    • "I think FireMon Security Manager could improve with a SaaS delivery model for easier connectivity and perhaps provide more regular updates and flexible dashboard options for better usability."

    What is our primary use case?

    My main use case for FireMon Security Manager is bringing visibility throughout the heterogeneous environment that I manage, enabled by the flexibility of the licenses and compatibility with a variety of vendors, including Cisco, Palo Alto, Fortinet, Huawei, and cloud and VMware environments.

    The visibility I gained with FireMon Security Manager became evident when we needed to change our firewall vendors from Cisco to Fortinet, allowing us to perform reusable checks on the rules across all devices while transitioning smoothly to the new vendor.

    FireMon Security Manager helped us further by providing visibility on changes made outside of our scheduled change windows, integrating with an ITSM solution via API to track changes initiated through tickets and ensuring compliance with our internal protocols.

    What is most valuable?

    The best features that FireMon Security Manager offers include license flexibility, vendor compatibility, real-time information, and change checks, which enhances my day-to-day work by consolidating my entire environment into a single pane of glass.

    The visibility, topology, compliance, vulnerability management, and daily filters provided by FireMon Security Manager have made our daily operations much easier, significantly saving us time and enhancing our security practices.

    I can add that we can integrate FireMon Security Manager via API with almost any solution, and its add-on, FireMon Insights, allows for the creation of diverse KPIs and dashboards tailored to our environment's needs.

    Since adding FireMon Security Manager inside our environment, our security perspective improves daily, giving us visibility on every change made and allowing us to address any potential security vulnerabilities timely.

    What needs improvement?

    I think FireMon Security Manager could improve with a SaaS delivery model for easier connectivity and perhaps provide more regular updates and flexible dashboard options for better usability.

    I believe the solution is straightforward, and while it includes many integrations, additional technical information on its internal workings would allow for more flexibility and deeper integrations with our environment.

    For how long have I used the solution?

    I have been working with FireMon Security Manager for the past ten years, as it is the second solution that I started working with here at AtivaSec.

    Which solution did I use previously and why did I switch?

    I previously used AlgoSec and Tufin, switching from AlgoSec to Tufin, and when Tufin lost support in Brazil, I transitioned to FireMon Security Manager, which has proven to be a much better option.

    Which other solutions did I evaluate?

    I did not evaluate other options before choosing FireMon Security Manager, as I had worked with other solutions and found FireMon Security Manager's compatibility with multiple vendors to be a significant differentiator.

    What other advice do I have?

    My advice for those considering FireMon Security Manager is to conduct a POC, share your use cases with the FireMon Security Manager salesperson, and utilize the available templates for assessments.

    I have shared everything about FireMon Security Manager, and I think it is a great solution. I have given this review a rating of ten out of ten.

    Which deployment model are you using for this solution?

    On-premises

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Reseller
    Last updated: Sep 15, 2026
    Flag as inappropriate
    PeerSpot user
    Ganesh-Khutwad - PeerSpot reviewer
    Senior Network Specialist at a tech vendor with 10,001+ employees
    Real User
    Top 5
    Nov 24, 2024
    Rapid policy insights with robust dashboards and cross-vendor automation
    Pros and Cons
    • "Its user-friendly interface allows for easy viewing and searching of network policies, including proxies, all on one console."
    • "FireMon Security Manager is a fast and intelligent device that delivers results in under ten seconds, even with thousands of policies."
    • "The support response time has room for improvement."

    What is our primary use case?

    FireMon Security Manager is a highly intelligent and useful device that consolidates all our security policies, including those for Zscaler proxies, into a single console. This centralized view eliminates gaps and inconsistencies between policies, simplifying policy review and analysis.

    How has it helped my organization?

    FireMon Security Manager is excellent for real-time compliance management. It allows us to quickly retrieve any policy needed for testing and easily analyze it for loopholes. If a loophole exists, FireMon provides comprehensive details within the policy manager.

    It alerts us to firewall rule additions or changes that violate compliance policies. It supports various firewall platforms, including Checkpoint, Zscaler, Fortinet, Cisco, and AWS, and provides centralized management for all configured policies through a single console.

    FireMon Security Manager provides many features, like whether my firewall is compatible with required standards such as NTP and SNMP. Each compliance included in our RFPs is shown in the UI of FireMon. It gives robust and clear dashboards, making it easier to understand risks because the policies have ratings showing usage, and the number of hit attacks.

    It streamlines our compliance reporting processes by providing comprehensive risk and compliance assessments. It offers a range of features, including verification of firewall compatibility with protocols like NTP and SNMP, and detection of signal charges. FireMon effectively addresses all compliance requirements outlined in our RFPs. For instance, it can determine if firewalls or proxies within a stack are configured in Secure Mode or Active-Active mode. FireMon Security Manager enables us to generate reports on all these aspects, ensuring thorough compliance monitoring and documentation.

    FireMon Security Manager is robust and can help automate firewall policy changes across large multi-vendor enterprise environments.

    FireMon Security Manager helps automate firewall policy changes across various environments, including on-premises, cloud, hybrid, SASE, and SD-WAN. It also simplifies cleaning up firewall rules in our environment.

    The time required to accurately create, approve, and deploy firewall policy rules has been reduced. Tasks that took 30 minutes can now be completed in just five minutes using FireMon.

    FireMon provides immediate visibility into our policies through a robust and clear dashboard, making it easy to identify errors or misconfigurations based on the policy rating.

    What is most valuable?

    FireMon Security Manager is a fast and intelligent device that delivers results in under ten seconds, even with thousands of policies. Its user-friendly interface allows for easy viewing and searching of network policies, including proxies, all on one console. By eliminating loopholes between policies, it simplifies review and analysis, while also automating policy changes and supporting multiple vendors. The system provides alerts and notifications for streamlined implementation and features a robust dashboard for clear risk assessment.

    What needs improvement?

    Although configuration is not the most difficult aspect of FireMon, a basic understanding of cloud computing and firewall principles is necessary for successful implementation. Therefore, simplifying the configuration process would be a significant improvement.

    The support response time has room for improvement.

    For how long have I used the solution?

    I have been using FireMon Security Manager in the testing phase for six to seven months.

    What do I think about the stability of the solution?

    I would rate the stability of FireMon Security Manager nine out of ten. It provides a stable environment with excellent scalability.

    What do I think about the scalability of the solution?

    I rate the scalability of FireMon Security Manager a nine out of ten. It offers extensive scalability options, providing more flexibility than other vendors.

    How are customer service and support?

    The technical support is good, but sometimes it takes some time.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?


    How was the initial setup?

    The deployment required some additional knowledge and took eight to nine days, but my team handled it efficiently.

    What about the implementation team?

    My team, consisting of around 20 people, handled the deployment because not everyone had access to the firewall policy manager.

    Which other solutions did I evaluate?

    Other vendors have policy managers, but they are not as fast as FireMon Security Manager.

    What other advice do I have?

    I would rate FireMon Security Manager nine out of ten.

    I recommend FireMon Security Manager because it consolidates all devices into a structured serial and single port.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    MichaelLavin - PeerSpot reviewer
    Digital Workforce Initiatives Leader at Galway
    Real User
    Top 20
    Feb 10, 2025
    Improved compliance monitoring but zone interpretation needs refinement
    Pros and Cons
    • "The most effective feature is the general reporting on compliance."
    • "The issue for me started with Fortinet not being able to see things correctly. It lost its appeal in terms of what it could do for me from a security standpoint, so I do not pay as much attention to it."

    What is our primary use case?

    I use FireMon in my work. I work in security and compliance, so I use it to monitor security and compliance within the firewalls.

    What is most valuable?

    The most effective feature is the general reporting on compliance. It has helped me bring all the firewalls into better alignment with the compliance requirements in my environment. The general long-term compliance monitoring has been the most beneficial aspect to me.

    What needs improvement?

    For one company I work with, I use Fortinet, and FireMon is not able to understand the zones that Fortinet uses. Part of that compliance piece does not provide me with the necessary information. Another company I work with uses Meraki as a firewall system, and in this case, FireMon can see everything much better and provides me with a fuller report.

    For how long have I used the solution?

    I have used the solution for two years.

    What do I think about the stability of the solution?

    In terms of stability, FireMon has been stable. I have not had any problems in that regard.

    What do I think about the scalability of the solution?

    I think the capabilities are good and potentially useful. The issue for me started with Fortinet not being able to see things correctly. It lost its appeal in terms of what it could do for me from a security standpoint, so I do not pay as much attention to it. I use other tools to focus more on the security side of things. If I have the time to look at Meraki, it might handle that better and be much more useful. I understand the concepts behind FireMon and what it does. If it can see and interpret everything correctly, it would do exactly what I want, and it would be very helpful.

    How are customer service and support?

    Their technical support is an eight out of ten. It is not perfect, but I have high standards because I provide so much technical support within my enterprise. An average or no real appeal would be a five. An eight signifies they are doing a good job. They do not always have the answer, but I cannot expect everyone to always have the answer. As long as they eventually provide the answer, I am happy.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The setup was not complicated. It was pretty straightforward.

    What about the implementation team?

    There were not any challenges. It was just straightforward.

    What's my experience with pricing, setup cost, and licensing?

    Comparatively, FireMon has a very good price and is below the general competition in cost. I have not seen any additional fees beyond the general contract fees for the usage I have. So, I have not encountered any hidden costs.

    What other advice do I have?

    I rate FireMon a seven out of ten. It is good, but I have not found it as useful as I hoped when I first evaluated it. This is generally because it does not interpret the Fortinet zones correctly, which diminishes its appeal. That is why I rate it a seven. However, looking at the Meraki side, it may do exactly what I expected initially.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer1915401 - PeerSpot reviewer
    Network security consultant at a comms service provider with 10,001+ employees
    Real User
    Top 20
    Feb 19, 2025
    Streamlines firewall cleanup and helps with tracking
    Pros and Cons
    • "The most valuable feature for me is its capability for cleanup and managing the complexity of security products."
    • "Overall, I would rate this solution a nine out of ten."
    • "A feature that could be improved is support for more devices, not just the firewall."
    • "Sometimes, there is a problem related to the sizing itself. If we have many devices added or if the firewall complexity is huge, we might experience some lag in processing. It may relate to the hardware specifications."

    What is our primary use case?

    Whenever I have a project or implementation, I use FireMon Security Manager for firewall cleanup or reporting. When I have an assessment project, I need to ensure the complexity of the firewall rules and identify unused rules from my side. It helps me to generate these reports and clean up the firewall itself.

    How has it helped my organization?

    It automatically warns us when new firewall rules, and changes to existing ones, violate compliance policies before they are deployed. This is important because I need to know who made the changes or when a change was made. It helps with tracking.

    It has helped with the compliance reporting processes in an effective way.

    It has helped to clean up firewall rules to some extent. It is not 100% percent but meets the needs.

    It has decreased errors and misconfigurations that increase risk in an environment. There has been about a 90% reduction.

    What is most valuable?

    The most valuable feature for me is its capability for cleanup and managing the complexity of security products. It provides me with performance indicators like the complexity of the device itself and also identifies unused rules. In time, it helps in an effective way.

    What needs improvement?

    A feature that could be improved is support for more devices, not just the firewall. It would be beneficial if they expanded to other devices like switches, routers, and other security devices, perhaps including proxies. Although I know it supports F5 LTM, supporting more products would be advantageous.

    For how long have I used the solution?

    I have been working with it since 2015, but I do not use it frequently. I sometimes implement it for a customer and use it when needed.

    What do I think about the stability of the solution?

    Sometimes, there is a problem related to the sizing itself. If we have many devices added or if the firewall complexity is huge, we might experience some lag in processing. It may relate to the hardware specifications.

    What do I think about the scalability of the solution?

    If we need to add more devices or more FireMon instances, I believe scalability is good from their side.

    How are customer service and support?

    I have contacted customer service, but it was a long time ago.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    I have worked with alternatives such as AlgoSec. FireMon is more user-friendly and has better reporting.

    How was the initial setup?

    The setup is easy. I do not remember the exact details, but it does not take too much time, one or two days maximum.

    What's my experience with pricing, setup cost, and licensing?

    Its pricing is good. Compared to others, it is not so expensive.

    What other advice do I have?

    For those looking to buy this solution, it is important to study the devices to be added to ensure correct specifications or hardware. This will satisfy their needs and expectations from FireMon. If there are many devices to be added, they should consider the appropriate hardware specs and VM.

    Overall, I would rate this solution a nine out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Jaimin Mehta - PeerSpot reviewer
    Senior Server and Cloud Engineer at Ertech
    Real User
    Aug 31, 2023
    Has an excellent dashboard, and performs comprehensive risk analysis, but can be more user-friendly
    Pros and Cons
    • "What I like about FireMon is the ability to track changes made by network engineers on the network."
    • "FireMon could be made more user-friendly when it comes to creating filters or conducting traffic analysis."

    What is our primary use case?

    We have a two-server system for web applications, and we utilize FireMon to manage our Palo Alto firewalls. We log in to FireMon for reporting and creating rules. Currently, I am working on a project that involves using FireMon to clean up some of our open rules.

    FireMon is deployed on-premises.

    How has it helped my organization?

    The real-time compliance management is excellent. It's something we prioritize in our efforts to comply in real-time. We have established some rules following the PCI guidelines as we are currently working towards achieving PCI compliance. These rules serve as metrics for us to assess our progress. We believe that real-time capabilities are essential and exciting for our organization.

    FireMon alerts us whenever there are new rules or changes to existing ones. I have set up some reports that arrive in my inbox daily, providing me with a summary. So, if there are any changes within the environment, I am notified. I believe that FireMon can also notify us before a change is made in our environment.

    The compliance reporting process does not require much time or effort, as long as we know what we are doing.

    FireMon helps automate firewall policy changes across large and multi-vendor enterprise environments.

    FireMon provides us with a dashboard view that shows an overhead view of all our redundant rules, along with our own user rules. With this information, we can generate reports and focus on specific criteria we are interested in. By doing so, we can easily identify rules that are actively in use, while also being able to spot duplicates and other elements that aid in cleanup efforts.

    FireMon helps us save time when creating, approving, and deploying firewall policies. For instance, when we deployed certain rules, they resembled penetration testing scenarios. The reports provided us with the capability to monitor activities in our network and effectively save time. Consequently, we could easily share these reports with the networking team, enabling them to promptly remove the identified rules, rather than having to conduct extensive and time-consuming investigations.

    FireMon helps to reduce misconfiguration, which can increase risks in our environment by at least ten percent. For example, it achieves this by not deploying specific rules that are overly permissive.

    FireMon assists in identifying risks within our environment and prioritizing fixes for those risks. This is an essential feature of our organization.

    What is most valuable?

    What I like about FireMon is the ability to track changes made by network engineers on the network. This allows us to run reports based on those changes. We can also track new rules to see if they comply with our standards. Additionally, we can identify rules that haven't been used or those that duplicate others excessively. FireMon enables us to create reports that provide valuable information for making changes within the system.

    The dashboard in FireMon is excellent, offering an overview of our network's compliance and security index database, among other things. I have also used FireMon for risk analysis of policies, exploring the possibilities and findings. While primarily focused on cleaning up files for a project, I have utilized many features for removing redundant and unused rules.

    However, I am aware that FireMon has even more to offer, such as understanding our network topology and conducting a comprehensive risk analysis. My current work mostly revolves around compliance, change management, and reviewing the alterations made.

    What needs improvement?

    FireMon could be made more user-friendly when it comes to creating filters or conducting traffic analysis.

    For how long have I used the solution?

    I have been using FireMon for eight months. 

    What do I think about the stability of the solution?

    FireMon is quite stable overall. However, there is one issue I encounter when attempting to run reports. Occasionally, it indicates that I do not have to report the web services. I'm uncertain if this problem is unique to our system or not, as it seems to be an ongoing concern. I have submitted several tickets, with five more related to this particular issue. Aside from that, FireMon remains stable and does not experience frequent downtimes. The only inconvenience arises when running reports, as it occasionally prompts an error, leading to a need for a web server restart.

    How are customer service and support?

    The technical support is generally good, but they can sometimes be slow in responding.

    How would you rate customer service and support?

    Positive

    What other advice do I have?

    I would rate FireMon a seven out of ten. There's a lot more I can gain from FireMon, as opposed to just running reports. I am particularly interested in automation and similar functionalities, but I haven't dedicated enough time to fully take advantage of all the features it offers.

    There are ten of us using FireMon within our organization.

    The maintenance we undergo for FireMon primarily involves upgrades. We have dedicated networking personnel and a development manager who oversees the maintenance.

    I suggest spending a significant amount of time watching the videos; there are some beneficial training videos available. Additionally, it would be beneficial to arrange some sessions with their contact. I have an account and have been having sessions with my contact for five months.

    Firewall policy clean-up management is undoubtedly a priority. If we have rules that are not correctly configured or overly encrypted, we expose our environment to numerous serious compromises, making it imperative to address this promptly.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    reviewer2244066 - PeerSpot reviewer
    Security Engineer at a healthcare company with 10,001+ employees
    Real User
    Jul 28, 2023
    Reporting helps us remove rules rather having to dig deep to do so, but some functions are tricky to use
    Pros and Cons
    • "I've been using the reports to see what is going on, and that is a helpful feature. We can track down unused rules, which helps with compliance. We can see rules that have not been used or that are duplicates or overly permissive."
    • "Some of the things that you want to do in FireMon are not exactly straightforward, like creating certain reports or controls. Some of the functions could be a little more user-friendly, such as creating certain filters."

    What is our primary use case?

    We have a two-server system, application and web, and we're using FireMon for our Palo Alto firewalls and their logs, to help us create rules. 

    We're working on cleaning up our rules using FireMon as well, because we have a lot of live, open rules.

    How has it helped my organization?

    FireMon really helps save time with the reports that give you visibility into what's going on with your network. We were able to pull a report and give it to the networking team and they were able to remove those rules, as opposed to having to dig deep and spend hours on that.

    It has also definitely helped decrease errors and misconfigurations. For example, we had certain rules that were overly permissive. We were able to redress those rules and make them more specific. We have seen at least a 10 percent reduction in misconfigurations.

    What is most valuable?

    I've been using the reports to see what is going on, and that is a helpful feature. We can track down unused rules, which helps with compliance. We can see rules that have not been used or that are duplicates or overly permissive. We can use FireMon to create reports and use that information to make changes within FireMon. I also like that we can track the kinds of changes that the network engineers are performing on the networks. We can run reports on that.

    We have also set up alerts and reports that come into my inbox daily. That gives me a rundown of any changes that have occurred within the environment.

    The solution has a good dashboard that gives you an overview of what's going on within your network in terms of compliance and the security index. The dashboard also gives you an outline of redundant and unused rules. You can run reports and make them a bit more targeted in terms of what you're looking for. That can help with the cleanup.

    I've also dabbled in the Policy Analyzer to see what information I can get from that.

    What needs improvement?

    Some of the things that you want to do in FireMon are not exactly straightforward, like creating certain reports or controls. Some of the functions could be a little more user-friendly, such as creating certain filters.

    For example, I was trying to do a traffic analysis and it can be a little tricky trying to change your firewalls on that profile. You almost have to create the entire thing over again. So there could be some enhancements in the user-friendliness.

    For how long have I used the solution?

    I have been using FireMon for eight months.

    What do I think about the stability of the solution?

    FireMon is pretty stable. 

    There has been one issue when I try to run reports. Sometimes it gives me an error and I have to reboot the web services. I'm not sure if that's unique to us or an ongoing issue. I've opened quite a few tickets with FireMon on that. 

    Apart from that, it's pretty stable. It doesn't go down.

    How are customer service and support?

    The support has been good. They have been slow to respond sometimes, but overall, it has been good.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    Networking-wise, I used a number of different solutions, but I didn't use anything similar to FireMon before.

    What other advice do I have?

    My advice would be to spend a good amount of time on the training videos. And if you can set up some sessions with your FireMon contact, that would also help. I do so many different things that I don't get enough time to spend on FireMon. I do use it pretty often, but maybe in terms of training, especially, there's a lot more I could gain from it, as opposed to just running reports. I could get into automation, for example.

    In addition to what I've been using it for, I know there's a lot more within FireMon, like getting an understanding of your network topology, bringing many different points together, and analyzing the risk factors. FireMon also helps automate firewall policy changes across large, enterprise environments, but we don't have it set up to that yet.

    Real-time compliance management is great. That's something that we are looking into and we have created some PCI rules. It's just a matter of learning how to make the reports. It's not very difficult at all.

    The maintenance that we go through with FireMon is mainly upgrades. I'm the point of contact and we have a couple of networking guys who are hands-on as well.

    Firewall policy cleanup is definitely a priority. If you have rules that are not properly configured or overly permissive, you open your environment to a lot of serious compromises.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    reviewer1954185 - PeerSpot reviewer
    Solution Architect at a transportation company with 51-200 employees
    Real User
    Sep 14, 2022
    Gives us an elegant, efficient way to clean up firewall rules, and better real-time capabilities for PCI compliance
    Pros and Cons
    • "The unused objects is another nice feature, where it digs a little bit deeper into comparing the logs that it sees versus the configurations that it sees... The unused objects feature will go through in a pretty detailed way and show us which ones aren't being used. Or, if they are used, it will show us how often they're used."
    • "It's been extremely helpful for that."
    • "To my knowledge, there's no cloud component to FireMon whatsoever. We're on the hook for any updates to versioning of the operating system or the application that runs on the operating system. It would be nice if it was a little bit more automated."

    What is our primary use case?

    We use it to capture logs and events from our enterprise firewalls, and we also collect configurations from those firewalls. Our main use case is for cleanup and hygiene of those firewalls, to make sure that all the rules that allow our systems to talk to each other are current and being used. And if they're not, then we clean those rules up.

    We use it more on the reporting and logging side, rather than for actually making changes to our firewalls.

    How has it helped my organization?

    For our PCI compliance audit this year, it was a better tool for us, with better real-time capabilities and better formatting for the reports that we needed. It has definitely made things more efficient by having a single console. We can run all of our reports from it, whether it's for the PCI environment or things that extend beyond that environment. It's very simple to use and it saves us time.

    The "wheelhouse" of FireMon, and why we bought it is the effect it has on the cleanup of firewall rules in a large environment. We've had rules out there that needed to be cleaned up for a couple of years and we just didn't have an elegant way to do that. The solution has really helped make things more efficient and easy for the implementing teams to consume. It's been great for that.

    While we didn't buy some of the additional tools that allow us to implement changes, it saves us time in accurately creating, approving, and deploying firewall policy rules. We get more value out of being able to compare what was done versus what the team said they were going to do or what was approved.

    It has also decreased errors and misconfigurations that increased risk. It's hard to quantify by how much, but we'll catch something that wasn't done quite right or as optimally as possible in 10 to 15 percent of the things that are implemented.

    What is most valuable?

    There are some built-in cleanup reports, out-of-the-box, and we like those. 

    Also, the unused objects is another nice feature, where it digs a little bit deeper into comparing the logs that it sees versus the configurations that it sees. As an example, a firewall rule deck could be very complex and might have hundreds of objects. The unused objects feature will go through in a pretty detailed way and show us which ones aren't being used. Or, if they are used, it will show us how often they're used. 

    Both those are geared toward cleanup and hygiene of the environment.

    It's also good when it comes to real-time compliance management. We used it for our PCI audit this year. It's a situation where we have to prove to our auditors that all the communications that are coming in and out of particular systems, and that process cardholder data, are current, and that we have the documentation, descriptions, and the rules. It's been extremely helpful for that. We used some other tools in the past, but this one is far superior.

    In addition, in terms of when new firewall rules and changes to existing ones violate compliance, the way we have it set up, FireMon automatically warns us when they're deployed. We look at those and we compare them with what we have approved for changes to the environment and it's very helpful for us.

    What needs improvement?

    To my knowledge, there's no cloud component to FireMon whatsoever. We're on the hook for any updates to versioning of the operating system or the application that runs on the operating system. It would be nice if it was a little bit more automated. We've got a small team and every time a new version is released, we have to go back and relearn the commands and how to verify that things were done correctly. That's the one pain point for me: It takes quite a bit of hand-holding, in terms of system administration from our server and infrastructure teams.

    For how long have I used the solution?

    We implemented FireMon about six months ago.  

    What do I think about the stability of the solution?

    We haven't had any problems since the deployment. Things have been running fast and efficiently.

    What do I think about the scalability of the solution?

    We're a pretty small shop, so I don't know how it would scale for a Fortune 100-sized company. Based on the feedback I've had, it's been great. We haven't had any problems with capacity or what we have needed to do.

    We have 10 people using it who are system admins, network admins, and security analysts. I wouldn't say we use it extensively. It's something that any given person probably uses once a week.

    It's possible that we would purchase some other modules that could give us a little bit more insight into the implementation and the planning side of things. But we like what we have for now. We don't have any direct plans to purchase more.

    How are customer service and support?

    Initially, we had contact with their technical support, but things have been smooth for the last few months. We haven't had to reach out lately.

    I don't remember the specific issue that we had, but it seems that they were on the ball. They responded right away and got us what we needed. My overall impression of their support organization is good. We've had limited involvement with them, but from my experience, it's been great.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    We used Tufin. When we looked at FireMon we liked it from a price standpoint; it was better. We asked some peers about it through the reseller that we bought it through and got very good feedback. Those were the two main factors.

    How was the initial setup?

    The initial setup was pretty straightforward for the most part. We had some hiccups and some bumps with some of the more detailed configurations, but overall, it was pretty simple to set up, get it running, and collecting logs and configurations. It took us about four hours over the span of two weeks.

    What about the implementation team?

    We used FireMon paid services to help us implement it. They were great.

    What was our ROI?

    It's hard to quantify ROI with FireMon, but it's definitely valuable. How do you quantify a missed cyber security incident?

    What's my experience with pricing, setup cost, and licensing?

    It's a good value. 

    From a licensing standpoint, our only limitation is the number of devices that we manage. Our environment is small. We have fewer than 20 enterprise firewalls, meaning it's hard to say what it would look like at a company that has thousands and thousands of enterprise firewalls. But from our standpoint, it's very simple to understand, and gives us a good bang for the buck.

    There are some hardware components involved in the cost, but in general, it's pretty straightforward. There are no hidden fees or adjacent costs that we weren't aware of going in.

    Which other solutions did I evaluate?

    We looked at Tufin's comparable product. We were using an older platform of theirs so we looked at their new platform and we looked at FireMon's and we decided on FireMon.

    What other advice do I have?

    Make sure that you've got somebody from your non-cyber-security teams, somebody from one of the other IT teams, such as infrastructure, servers, or networks, who understands and who does really good documentation around the initial setup. Our cyber security or information security team is the one that uses it mostly, but we do need assistance from the other team. Make sure that you have stakeholders from other groups, even though they're not going to be the primary users.

    The idea that firewall policy rule cleanup and management is important, but it's just not a priority compared to other more urgent items, is a pretty tough statement to make, especially in a regulated environment or if any sort of compliance is needed. It's just not really a valid statement. If someone said that, I would ask them to go back and make sure that they're following all the rules of the road.

    It comes down to what your priorities are and what's important. Most regulations have some sort of a component around zoning and limiting communications between different systems. It's of utmost importance if you think about it from a compliance standpoint.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    JeffReese - PeerSpot reviewer
    Senior Security Engineer at a financial services firm with 1,001-5,000 employees
    Real User
    Top 20
    Jul 26, 2022
    Makes compliance much easier compared to doing it manually, and automates policy changes across environments
    Pros and Cons
    • "In one report, FireMon tells us there are, say, 1,000 rules that can be taken out and it gives us the ability to disable those for a year and to track when we made our changes. After a year, we can go back and eliminate the rules, to bring the configuration down to an almost human-readable level."
    • "Within one day, we can do what we used to do in two weeks."
    • "When it comes to documentation, they need to start putting together a basic command manual. With Cisco, you can look up a command and it gives you examples of three or four different ways that command can be used. It tells you how to put it into the GUI and the CLI. FireMon does need to start doing that."
    • "When it comes to documentation, they need to start putting together a basic command manual."

    What is our primary use case?

    We're an MSSP, so we put FireMon on our customer sites to monitor their security devices.

    How has it helped my organization?

    It's so quick at finding redundant and shadowed rules. I used to have to do that and I would have to yell at people to stop bothering me because I needed my complete concentration to do it. And there was still human error. FireMon saves all that time and eliminates that human error.

    Also, in terms of our compliance reporting process, they would give us a week and we'd pull all the configurations of all the firewalls and send them off to someone like me who would go through them and say, "Hey, this is not good. Take a close look at this. Why is it any-any?" People would have to go back and look at the firewalls to see if that was a business risk or not and, if it was, have the company sign off on it as a business risk. That would actually take up to about six months of going back and forth, giving people weeks at a time to respond.

    With FireMon Security Manager, I can create a report and send it off to the customer and say, "Here are the 98 rules that put you at high risk. Are these needed?" They look at them and say, "Oh no, that application is gone, you can get rid of that." Or they say, "Yep, this is an acceptable risk." I then say, "Okay, I'm going to be back in a year," and I mark it as "acceptable risk, by so and so." A year later I can go back and say, "Is this still an acceptable risk to you?" It makes our compliance so much easier when compared to having to do it manually. I would recommend everybody get this tool just for that aspect.

    A module that we have to pay for, because we're using FireMon Security Manager, helps automate firewall policy changes across large, multi-vendor enterprise environments, and it's the only solution that does that. The rest of them are so labor-intensive that this would probably save 70 percent of that work time. It enables us to make changes company-wide. Suppose one of our clients has 60 firewalls. We can do a company-wide firewall update within about two hours if they have multiple brands of firewalls. We can do it in about 30 minutes if they only have one brand. When we had a person logging in to manually do it, it would take them at least a day for 60 firewalls. Now, if it's Palo Alto, we can do it in half an hour. If it's Fortinet, it can take us an hour and a half.

    We have about 20 customers and we're saving at least a day of time for each one of those customers. Within one day, we can do what we used to do in two weeks. That's very significant because we were looking at hiring more people. FireMon has reduced the need for that. As our people become more and more efficient, we can actually have more and more customers without having to increase our labor force.

    The solution can also talk across on-premises, cloud, hybrid, SASE, and SD-WAN environments. You need the path. Once you have the path, which most of the time is going to be a VPN tunnel if it's over an untrusted area, you can do anything. That makes it one pane of glass. For example, in the past, if it was on-prem and in the cloud, I would have to do an on-prem pane of glass and a cloud pane of glass. Now I can do it in one pane of glass and it's less labor-intensive and much faster.

    You can even automate the cleanup of firewall rules in a large, enterprise environment. That's the nice part about it. You can say, "Here are 100 rules I want you to disable," put in the IP addresses, hit enter, and it pushes that out to the 60 firewalls. It takes time, but you walk away. You've saved tons of time while it's doing the process for you through automation. I can't see working on more than one firewall without having this tool.

    If you make a mistake on one IP address, and you push it out to 60 firewalls, instead of bringing one down, you could bring them all down. You measure twice and cut once. You verify, you make sure you have the stuff in there. Then you have a second person to look at it and, when you both agree, you hit enter and you know you're not going to bring the system down. That actually takes a little bit more time because it's a two-person activity where it used to be just one. We used to bring down a firewall once a month and now we don't do that. We're saving at least one outage day and then another day of apologizing.

    What is most valuable?

    People have a tendency to just add rules to firewalls, but they don't go back and take rules away. Some of our customers have thousands of unused rules that have been sitting out there for over a year. In one report, FireMon tells us there are, say, 1,000 rules that can be taken out and it gives us the ability to disable those for a year and to track when we made our changes. After a year, we can go back and eliminate the rules, to bring the configuration down to an almost human-readable level.

    It also identifies risks in your environment and helps to prioritize fixes. It actually rates the risk level, meaning you look for the red and try to bring everything to green.

    What needs improvement?

    When it comes to documentation, they need to start putting together a basic command manual. With Cisco, you can look up a command and it gives you examples of three or four different ways that command can be used. It tells you how to put it into the GUI and the CLI. FireMon does need to start doing that. Right now, I use their tech support for that. They give me a command and I create my own book.

    For how long have I used the solution?

    I have been using FireMon for four years.

    What do I think about the stability of the solution?

    I have use cases where it's been running for two and a half years, and I've never had a problem with it. They're smaller companies where there aren't a lot of changes going on, but FireMon is just clicking away the whole time. It's stable.

    Once it's put in, you pretty much walk away from it. You come back every morning to see if anything is going on and, if not, keep moving. It has made life a whole lot easier for us.

    What do I think about the scalability of the solution?

    It's very easy to scale up or down.

    Every time we get a new customer, we put it in. The customer has to have a VM set up for the hardware requirements of FireMon, or we won't monitor their systems.

    How are customer service and support?

    They're very quick. They usually have the answer in a short period of time, and the maximum is no more than a day. Most of the time I just need a command and I can put it in on my side to verify, and that's it. I need to see what's going on. I'm a hands-on person. I don't like to sit back and watch other people do things.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    We started with another solution called ManageEngine Firewall Analyzer, and we had that throughout our customers' sites. We recently started moving things over to FireMon for our old customers. If you run into Firewall Analyzer, run, don't walk, to the nearest exit.

    Firewall Analyzer was so labor intensive just to do a report. You would tell it to look up an IP address and create the report, it would create a 20-page report, but you'd end up having to do that 20 times until you got the entire report. It could take six to eight hours to do a report. With FireMon, I hit "report," walk away, and it says, "Hey, your report's ready."

    How was the initial setup?

    The initial setup is pretty easy. I have three engineers who work on setups, and it took about 20 minutes, walking through it twice in the sandbox. It's pretty easy to set up.

    There are two aspects to the setup. There's the basic setup of getting the application working, and there is the advanced setup of putting firewalls into the application. The basic is so basic that it's ridiculous. I could probably answer all the questions a customer might have and send it off to them and they could do it by themselves the first time. The advanced is a little bit more hairy because you have to make sure everything is in place.

    At each of our customers, we assign at least two people to do the reports.

    The maintenance is lightweight. The only trouble is in the upgrades. They take a little bit of effort, but they only come out once or twice a year. Sometimes, you don't need to do the upgrade because the change isn't applied to whatever site you're working on. Sometimes an upgrade is easy, and sometimes it's reformatting a database and that takes a little bit more effort. But you don't do it. FireMon has a script all set up. It's just that it takes a little bit longer to watch it do the upgrades, as compared to doing it ourselves.

    What was our ROI?

    Our ROI is the FTEs a year that we're saving. The solution is not even close to the cost of an employee. It might cost that employee's health benefits. We're saving double the amount of money we would pay a person.

    What's my experience with pricing, setup cost, and licensing?

    There is sticker shock on Firemon's pricing because it is done per device, but I'll guarantee you that it's well worth it. For each of our customers, we save at least one FTE a year. We would have needed 20 more people in our organization without the FireMon application.

    Which other solutions did I evaluate?

    When it comes to real-time compliance management, FireMon is much better. I've looked at Tufin and one other competitor, but FireMon has the most accurate best-practice reports. Tufin was our least favorite of the three. The other one was pretty good, but it looked a little bit immature. You had to create all the stuff you needed to do, while FireMon had everything already created, so it was the logical choice.

    What other advice do I have?

    My advice would be to get familiar with UNIX commands and the VI. Those two are very helpful when you're working on the CLI. Otherwise, the GUI is so easy.

    Security Manager, which is what we're using, doesn't automatically warn you when new firewall rules and changes to existing ones violate compliance policies, before they are deployed. However, there is another licensed aspect to Security Manager that does have that ability. What I have will tell me that somebody has made a change, what it was, and when it was made, but for the solution to make it a judgment call, I'd have to license another portion of Security Manager. It will even tell you where to put something. You put the entire enterprise in, with 60 firewalls, and you say, "I want to do this." It will say, "Okay, put it over here on this firewall, on this interface." You don't even have to think about the design. It does all the work for you.

    If a colleague at another company said that firewall policy cleanup and management is important, but it's just not a priority, I would tell them that's a misconception. Any rule out there that hasn't been looked at, at least yearly, can become a security problem. Leaving that open, someone else can put another server in its place and now have open ports because you didn't remove a rule that's no longer in use. That's a very big security hazard. You do not want to leave rules in that aren't being used.

    I've seen that happen in many companies that I've worked in, where a server had a lot of ports open because it needed to have them open for that application. The server then went away and then someone put another server in there and it automatically had all those rights. You didn't even know that it was changed. All you saw was a name change, and didn't realize that all those open ports are now a security violation because they applied to the old server and not the new one.

    Having used it for so long, I'm so inundated with it that I can't see much that needs to be improved without a major redesign, and I can't even see that. When we're putting in automated changes it takes effort, but you realize that if it was too easy you could mess things up pretty quickly. I prefer it the way it is. I really don't want it changing.

    It's the only tool we use for our security area that is worth anything.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
    PeerSpot user
    Buyer's Guide
    Download our free FireMon Security Manager Report and get advice and tips from experienced pros sharing their opinions.
    Updated: September 2026
    Buyer's Guide
    Download our free FireMon Security Manager Report and get advice and tips from experienced pros sharing their opinions.