What is our primary use case?
My primary use case is twofold: as a centralized VPN concentrator —terminating site-to-site IPsec tunnels to remote offices and providing secure remote access via SSL VPN— and as a perimeter firewall for the edge of my virtualized workloads.
CloudEdge inspects north-south traffic toward my virtual instances by applying intrusion prevention (IPS) and inline antivirus, complemented by application identification and policy-based control.
With this, I protect the data of my main systems against intrusions, malware, and malicious traffic, while maintaining visibility and granular control over inbound and outbound connections.
How has it helped my organization?
CloudEdge consolidated VPN, IPS, and antivirus into a single virtual appliance, reducing operational complexity and cost compared to tier-one solutions.
We gained full visibility into north-south traffic toward our virtual instances and granular policy-based control, which strengthened our perimeter security posture.
Inline inspection reduced the exposure surface of our critical systems against intrusions and malware, while the centralized termination of IPsec and SSL VPN tunnels simplified secure connectivity with remote offices and remote-access users.
In addition, CloudEdge has helped us apply consistent security controls across both our AWS workloads and our on-premises workloads.
It provides an additional security layer beyond basic security groups and network ACLs, allowing us to inspect traffic more closely and enforce more detailed and specific policies.
What is most valuable?
The most valuable features for us have been:
Intrusion prevention (IPS) and inline antivirus: real-time threat inspection on north-south traffic allows us to block intrusions and malware before they reach our critical systems, without relying on external controls or a second inspection layer.
VPN termination (IPsec and SSL): consolidating site-to-site tunnels to remote offices and secure remote access on the same appliance simplified our connectivity architecture and reduced administration points.
Behavioral analysis and anomaly detection: this is one of Hillstone's key differentiators; anomalous-traffic detection gives us visibility depth beyond traditional signatures, helping us identify suspicious patterns that a conventional firewall would miss.
Traffic visibility and logging: granular logs and full connection visibility let us audit, correlate events, and tune policies based on concrete data, which is essential for daily operations and compliance.
Deployment flexibility: being able to deploy the same virtual appliance both in public cloud and on our own hypervisor lets us apply consistent security controls across hybrid environments, without fragmenting our security policy between platforms.
What needs improvement?
Cloud-native automation and IaC: Terraform support, auto-scaling templates, and API maturity lag behind Palo Alto VM-Series and FortiGate-VM.
Dynamically scaling in public cloud requires more manual effort.
Third-party integrations and ecosystem: fewer native connectors with SIEM/SOAR platforms, CSPM, and third-party tools compared to market leaders.
Documentation and training material: technical documentation and community resources (forums, tutorials, KB) are more limited, which lengthens the learning curve for new teams.
SASE/SSE capabilities: the integrated SASE/ZTNA offering is less mature compared to the convergence already provided by Fortinet or Palo Alto.
Centralized multi-instance management: managing large fleets of virtual appliances could be smoother; centralized management (HSM) works, but some users would like more granularity and automation.
For how long have I used the solution?
I have used it for 5 years.
Which solution did I use previously and why did I switch?
We previously used Fortinet (FortiGate) and migrated to Hillstone CloudEdge.
The decision was primarily driven by the cost/performance ratio: Hillstone offered us a comparable feature set —NGFW firewall, IPS, antivirus, and VPN termination— at a lower total cost of ownership, with a more flexible licensing model for virtualized and cloud environments.
Additionally, we valued the depth of Hillstone's behavioral analysis and anomaly detection capabilities, which aligned well with our visibility requirements.
The migration allowed us to maintain our existing security posture while optimizing the investment, without sacrificing inspection or secure-connectivity capabilities.
What's my experience with pricing, setup cost, and licensing?
My main recommendation is to evaluate the total cost of ownership (TCO) over a three-year horizon, not just the initial acquisition or licensing price.
That is where Hillstone CloudEdge shows its greatest advantage: when comparing the accumulated cost of licenses, security subscriptions, support, and renewals against alternatives like Palo Alto or Check Point, the differential is usually significant in Hillstone's favor, while maintaining a comparable feature set.
I advise building the analysis around the full lifecycle including subscription renewals and projected instance growth to properly size the real savings.
When evaluated from that perspective, the cost/performance ratio becomes a compelling argument.
Which other solutions did I evaluate?
Before making our decision, we evaluated other NGFW alternatives, primarily Palo Alto Networks (VM-Series) and Check Point (CloudGuard).
Both are strong, well-recognized solutions in the market, but in our cost-benefit analysis Hillstone CloudEdge offered the best balance: a comparable feature set NGFW, IPS, antivirus, VPN, and behavioral analysis at a significantly lower total cost of ownership, with a more flexible licensing model for virtualized and cloud environments.
Palo Alto and Check Point stand out in ecosystem maturity and integrations, but for our operational requirements, the price differential did not justify the additional investment, especially given our in-house expertise with the Hillstone platform.
That combination of capabilities, flexibility, and cost was what tipped the decision.
What other advice do I have?
On balance, Hillstone CloudEdge is a solid and highly competitive solution within the virtual NGFW firewall segment.
Its greatest strength is the cost/performance ratio: it delivers a feature set comparable to that of the market leaders NGFW, IPS, antivirus, VPN, and behavioral analysis at a considerably lower total cost of ownership, which makes it an especially attractive option for hybrid environments and organizations looking to optimize their security investment without sacrificing inspection capabilities.