Try our new research platform with insights from 80,000+ expert users
Technolo63ef - PeerSpot reviewer
Technology Engineer at a financial services firm with 501-1,000 employees
Real User
With the change control functionality, we can track firewall rule changes made outside of change windows.

What is most valuable?

Currently, the change management controls for monitoring the firewall configuration changes is the only feature that we really use, at this time.

How has it helped my organization?

With the change control functionality, if somebody was to go in and make a rule change on the firewall, it's configured to send a notification as soon as those changes have been made. If this happens outside of a change window, we can track those and go to that person/individual, and find out why they made the change without going through proper change control procedure.

What needs improvement?

We just updated to the latest version, so I haven't had a chance to play with the enhancements from what we were previously using. What I was looking for in the previous version was better capability of adding change control numbers manually for rule changes that don't allow me to put in a descriptor into the change on the actual device. That will automatically get pulled into FireMon for reporting purposes. Some features don't have a description field that I can populate, and so I need to go back into FireMon later and document those. Even though the field is available as an option in properties, there's no way for me to fill that because of the type of the category of the change. It may not be a security change. It could be just a documentation process that I'm not able to do. That was in a previous version. I haven't validated that in this latest version.

For how long have I used the solution?

I've only been using it for about a year. My employeer has used it for two to three years.

Buyer's Guide
FireMon Security Manager
May 2025
Learn what your peers think about FireMon Security Manager. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,823 professionals have used our research since 2012.

What do I think about the stability of the solution?

The product itself has been solid, stable. I haven't had any issues with stability issues at all, now.

What do I think about the scalability of the solution?

The scalability seems to only be limited based on licensing we have installed. It appears to be fairly robust. It does offer a very large variety of devices that it can monitor but it's only limited based on the licenses that we have installed. For example, when I started here over a year ago, the device was licensed just for Cisco ASA5520s, and now we're using it to also monitor 5545s, which is a different tier. Until we licensed it for that different tier, we weren't able to ingest the configurations or monitor those newer devices. It truly comes down just to licensing. So, making sure we have the proper licensing is key. From what I've seen, it can monitor many devices, from routers, switches, up to the firewalls, from across many vendors.

How are customer service and support?

We have asked for help a couple times, mainly about minor questions. There were questions about how to use documentation better, and they helped with that, but most of the questions that we've had have been around upgrading the product. We needed to know what is in the next version.

Which solution did I use previously and why did I switch?

Based on what I know, there were no previous products. My understanding was they brought this in because they did not have that capability, and so this was an enhancement to the organization overall. Previously, there wasn't any monitoring being done.

How was the initial setup?

Initial setup was done prior to me being here.

What other advice do I have?

From what I've seen of the product, it's fairly robust. Making sure to know everything that you want monitored, to get the proper licensing upfront, is probably the biggest thing. If you're only strictly wanting to do firewalls, make sure you get the right licensing that will match your firewall capabilities. If you want to match a more cross-spectrum of your devices, get licensing to support that. The biggest key is making sure to get all the licensing you need for the devices you want upfront.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user631122 - PeerSpot reviewer
it_user631122Customer Success Manager at a tech vendor with 201-500 employees
Real User

Technolo63ef,

Thank you for taking the time to write a review of FireMon. I am glad to see you are finding overall satisfaction with the product.

IT Security Assistant Manager at Octopus Cards Limited
Real User
Compliant, stable, scalable, with good support
Pros and Cons
  • "The most valuable feature is the Firewall reviews for our company compliance."
  • "The advanced features are complex in setting up the rules."

What is most valuable?

The most valuable feature is the Firewall reviews for our company compliance.

What needs improvement?

The review process is an area that needs improvement. We would like to review the rules and be able to make comments.

The advanced features are complex in setting up the rules.

I would like to see level mapping available with other products improved, to allow other products to build the level mapping. It does not have an export in Visio.

For how long have I used the solution?

I have been working with FireMon for half a year.

We are using version 8.

What do I think about the stability of the solution?

This solution is stable.

What do I think about the scalability of the solution?

It's a scalable product. We have five to eight people who are using this solution in our company.

How are customer service and technical support?

Technical support is fine. I don't have any other issues.

Which solution did I use previously and why did I switch?

I have not worked with any product that is similar previously.

How was the initial setup?

Most of the setup was easy for us, but the advanced features are more complex.

What's my experience with pricing, setup cost, and licensing?

Pricing is reasonable.

Licensing fees are paid every year.

What other advice do I have?

It's a good solution that is stable, I would recommend this solution to others.

I would rate FireMon an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
FireMon Security Manager
May 2025
Learn what your peers think about FireMon Security Manager. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,823 professionals have used our research since 2012.
it_user642174 - PeerSpot reviewer
Information Security Officer at a university with 10,001+ employees
Vendor
The ability to audit our firewall rule base allows us to determine which rules can be removed.

What is most valuable?

The ability to audit our firewall rule base is my favorite feature. It allows us to determine which rules can be removed and it helps us reduce our security footprint.

How has it helped my organization?

Over the past two years, we have been able to identify a bunch of rules that were orphaned and no longer have any need.

These rules were exposing our organization to undue risk associated with devices being exposed to the internet that shouldn’t have been exposed.

We use the feature to identify some rules that were no longer needed. That helps us reduce our overall, organizational risk profile.

What needs improvement?

What's funny is that if I had been asked eight months ago about areas with room for improvement, I would have said the product in general needed to be improved. It wasn't web-based. It was client-based and it was just kind of clunky.

In the last eight months since we upgraded to the web version, there isn't a lot of need for improvement. I feel like it is pretty good. Things have been a lot better for us since we upgraded to the web version. I'm happy with it right now and I don't have any complaints.

For how long have I used the solution?

We’ve been using this solution for just over two years.

What do I think about the stability of the solution?

We haven’t had any stability problems. I had one or two minor issues since the upgrade, such as upgrade failures. I couldn’t get the system to accept a maintenance release. Those issues were resolved pretty quickly. There have been no stability issues, nor long-term outage issues.

What do I think about the scalability of the solution?

We have a fairly limited amount of systems that are monitored by FireMon. Our box can support up to 20-25 devices. We only have eight devices to monitor. We still have a lot of overhead. We haven’t noticed any slowdown issues or any problems of a scalable nature on the device.

How was the initial setup?

Back then, it was client-based and the setup was not so straightforward. Most things worked well right out of the box.

Although I haven’t done an actual setup after it became web-based, I can see that it is much easier. You don’t have to download a client. You just have a website. There is no need for a command-line configuration to get it up and running. It was fine for overall level of difficultly before and I can assume it is easier now.

Which other solutions did I evaluate?

We did not evaluate other options. This was the first of its kind. I saw it at a vendor/expo demo and I was interested in it.

Our vendor that we work with threw it into a deal. We paid for support and they were trying to increase the overall install base footprint. They made a couple deals with us for a next generation firewall. I wasn’t budgeted to purchase it, but it was part of a deal, and it fell into our lap for next generation firewall monitoring.

What other advice do I have?

FireMon is a very good product; is a slippery slope in terms of deployment. It can monitor all of your network devices and firewalls. I would imagine a lot of people probably use it for that.

We are a small organization. From a cost and work standpoint, we only wanted the ability to audit and manage our firewall rule sets. It’s been good for us in that way.

People need to think about what’s important to them based on a monitoring point of view, which is regulation-based. That wasn’t an issue for us. I recommend that people considered the best-sized solution for them. Give it a try. It’s worked well for us.

I would rate it as the best firewall monitoring platform that I’ve used, but I’ve only used FireMon.

We are a Palo Alto customer and this is a great tool to augment the Palo Alto tool set. It’s a very beneficial product. It fills the gap of things you can’t get with standard Palo Alto management, such as long-term analysis and knowing what’s really going on with objects and rules in the firewall rule base.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user560244 - PeerSpot reviewer
Clinical Systems Engineer So Cal Regional Office at a healthcare company with 1,001-5,000 employees
Real User
Easy setup, where a non-IT person can install the tool
Pros and Cons
  • "Vendor agnostic when it comes to integrating with other product."
  • "A phone app would be nice. This is the reason why it is not perfect yet."

What is most valuable?

  • Vendor agnostic when it comes to integrating with other product.
  • Reliable
  • Excellent customer support

How has it helped my organization?

This product has enabled Kaiser Permanente Clinical Technology technicians with proactive/remote monitoring of highly critical systems.

What needs improvement?

A phone app would be nice. This is the reason why it is not perfect yet.

For how long have I used the solution?

12 months.

What do I think about the stability of the solution?

No problems.

What do I think about the scalability of the solution?

No problems.

How are customer service and technical support?

A 10 out of 10.

Which solution did I use previously and why did I switch?

No previous solutions were used.

How was the initial setup?

Since a non-IT person like me was able to setup the system from scratch, I would say that it is not complex at all.

What's my experience with pricing, setup cost, and licensing?

Relative to what it offers, the price is fair.

Which other solutions did I evaluate?

FireMon Immediate Insight was the only product that would work for us, due to the limitations that the Clinical Technology Department has at KP.

What other advice do I have?

It is a very versatile and sustainable product.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
reviewer1740165 - PeerSpot reviewer
GISA at a tech vendor with 201-500 employees
Real User
Top 20
Provides us with very good real-time compliance management
Pros and Cons
  • "For the cleanup of firewall rules, it performs really well for us. We utilize it in our regular rule cleanup tasks, several times a year. FireMon is our primary tool when doing that, either by going through its out-of-the-box compliance rules or using it to search for certain things in our rules that we want to prune from our firewalls."
  • "When it comes to real-time compliance management, something that is missing is alerting on certain, predefined controls. It would be good to have a predefined set of controls which, if not complied with in a newly set up rule, would create an alert for us. That is something that is missing, out-of-the-box."

What is our primary use case?

Our main use case is the monitoring of changes on our firewalls. Another of our use cases is keeping firewall rules in good shape by doing regular rule reviews, using FireMon's built-in categories for rules and even deploying our own. Additionally, we used FireMon when we did internal firewall migration, meaning we were switching to a new generation of firewalls.

How has it helped my organization?

The solution has decreased errors and misconfigurations that would otherwise increase risk in our environment.

In addition, when we migrated to a new generation of firewalls, FireMon was of help when doing a first benchmark of the new solution and the initial setup.

It also identifies risks in our environment and helps prioritize fixes for them. The compliance module in Security Manager does that by watching overall rules and any changes, and benchmarking them against a pre-setup set of controls. It notifies us if any control has failed. That's how we monitor whether our firewall rules are compliant with a pre-set benchmark.

Firewall policy rule cleanup doesn't need to be a priority for a company to justify using FireMon, given that it makes that job much easier and faster. That means you don't need to allocate as many resources to do that work. It's now incomparably easier to do things like a rule review.

Overall, our monitoring and compliance are on much higher levels. The visibility we have into our firewall rules is much better now than it was prior to having FireMon.

What is most valuable?

One of the most valuable features is the compliance feature, which is something that we really utilize in Security Manager. It has a set of controls that we tuned a little bit from the way they came out-of-the-box, and created a custom set of rules that we are monitoring and that we want to have inline in our environment. It's a very good solution for real-time compliance management.

And for the cleanup of firewall rules, it performs really well for us. We utilize it in our regular rule cleanup tasks, several times a year. FireMon is our primary tool when doing that, either by going through its out-of-the-box compliance rules or using it to search for certain things in our rules that we want to prune from our firewalls.

What needs improvement?

When it comes to real-time compliance management, something that is missing is alerting on certain, predefined controls. It would be good to have a predefined set of controls which, if not complied with in a newly set up rule, would create an alert for us. That is something that is missing, out-of-the-box. We have tried to work around it by setting up email notifications, but it would be nice if it came with the product. That would really turn it into real-time monitoring for us. 

The workaround works for us, and the out-of-the-box setup is also good, but it expects you to be constantly watching and monitoring the solution itself. That's a bit hard when you have more than one solution to work on. You cannot just watch one and keep an eye on it for something that's non-compliant. Having an alert would be much easier for us. Still, it's a good tool for that kind of monitoring, for us.

For how long have I used the solution?

I have been using FireMon for about two years.

What do I think about the stability of the solution?

FireMon is quite stable. We haven't had any stability issues with it so far.

What do I think about the scalability of the solution?

It's quite scalable. The process of adding modules has gone quite well. Anytime we have needed to increase it, there hasn't been a problem.

We use it extensively; if not on a daily basis then on a weekly basis. There are periods when we use it even more intensely when doing reviews.

How are customer service and support?

They really give us great support. When thinking of the level of support that we get from some other vendors, FireMon's support is really good. They have a good, knowledgeable support team around the world. We have offices in Europe and California. Whenever we have had any type of issue and have needed their support, whether the issue is in Europe or California, we have had really great support from them.

Which solution did I use previously and why did I switch?

We did not have a previous solution.

How was the initial setup?

We had a FireMon support engineer for the initial setup and it looked fairly straightforward, but it definitely needed some FireMon knowledge. Since then, we have onboarded a number of new devices in FireMon on our own, and that part is quite straightforward. But setting up the system itself is something that requires the knowledge of a FireMon engineer.

For the deployment, there was a month of weekly sessions with the engineer to get it working.

We have three people, within our security staff, who are using FireMon regularly. The three of us were involved in deploying and we work on maintaining it. It's a shared effort. None of us is working full-time on FireMon.

What's my experience with pricing, setup cost, and licensing?

There are no costs in addition to the standard licensing fees.

Which other solutions did I evaluate?

We talked about other solutions with different partners, and based on that we decided to go with FireMon. We did have a proof of concept with them before going live, and we liked it and the options it had, so we decided to go forward.

Which deployment model are you using for this solution?

On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
reviewer1489200 - PeerSpot reviewer
Network Solution Architect at a manufacturing company with 10,001+ employees
Real User
An agile network security policy platform that provides 360-degree views, but comes with limited functionality
Pros and Cons
  • "FireMon is nice and provides 360-degree user views."
  • "I don't like that it comes with bugs, constant issues, and limited functionality."

What is most valuable?

FireMon is nice and provides 360-degree user views. You can also find the information you're looking for pretty easily.

What needs improvement?

I don't like that it comes with bugs, constant issues, and limited functionality. I would like to have enhanced change management reporting support for UTM features in the next release.

For how long have I used the solution?

I have been using FireMon for six months.

What other advice do I have?

On a scale from one to ten, I would give FireMon a five.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user494268 - PeerSpot reviewer
Information Security Analyst at a financial services firm with 1,001-5,000 employees
Vendor
It was valuable for auditing purposes.

What is most valuable?

It was used for firewall change review. For our company, it became an invaluable tool for auditing purposes.

How has it helped my organization?

It allowed us to track every change made to the firewall. We were able to see who made the changes, when the changes were made, and exactly what was modified.

What needs improvement?

We monitored multiple firewalls. In the version we used, we had to check the changes made on each firewall individually. We didn’t see a condensed list of changes across our environment.

For how long have I used the solution?

I used it for 1.5 yrs.

What was my experience with deployment of the solution?

We encountered minor issues with FireMon and its collection of data from Palo Alto firewalls. It required a small amount of additional time with system engineers on our side and on FireMon’s side to complete the deployment.

How are customer service and technical support?

Customer Service:

The customer service was excellent.

Technical Support:

At the time we were using the product, it did seem like the tech support staff was very limited in size. I am sure they have grown more since we used this product.

Which solution did I use previously and why did I switch?

We used another product (Tufin). For us, we needed to make a change because they lacked the ability to support Palo Alto (at that time). FireMon was a better fit with that firewall.

How was the initial setup?

The initial setup was straightforward. Minimal support was required to complete it.

What about the implementation team?

We implemented it through an in-house team. We required minimal assistance from the vendor.

What other advice do I have?

There are very few products that can do what FireMon can. I would definitely recommend it if there is a need to review firewall changes.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Joao Manso - PeerSpot reviewer
CEO at REDSHIFT CONSULTING
Reseller
Top 10
Improved our network security
Pros and Cons
  • "The firewall assessment feature is great."
  • "FireMon could be easier to use and flexibility regarding reporting could be improved."

What is our primary use case?

We are resellers. All of our clients are enterprise companies. 

What is most valuable?

The firewall assessment feature is great.

What needs improvement?

FireMon could be easier to use and flexibility regarding reporting could be improved. 

For how long have I used the solution?

I have been using FireMon for six months.

What do I think about the scalability of the solution?

FireMon is both scalable and stable. 

How are customer service and technical support?

I've never had to contact technical support. 

Which solution did I use previously and why did I switch?

I used to work with AlgoSec. They are both very good products but they target different customers in our market. One is more expensive than the other. One is more simple than the other to use. For this reason, we decided to go with FireMon. The profile of our customers is more related to FireMon than AlgoSec.

How was the initial setup?

The initial setup was very easy.

What's my experience with pricing, setup cost, and licensing?

FireMon is cheaper than AlgoSec.

What other advice do I have?

My advice is to make sure you choose the right reseller because it's not a product you should use by itself.

Overall, on a scale from one to ten, I would give FireMon a rating of eight. 

Disclosure: My company has a business relationship with this vendor other than being a customer: reseller
PeerSpot user
Buyer's Guide
Download our free FireMon Security Manager Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2025
Buyer's Guide
Download our free FireMon Security Manager Report and get advice and tips from experienced pros sharing their opinions.