Try our new research platform with insights from 80,000+ expert users
Solutions Architect at Clockwork Solutions
Real User
Geo-blocking enables us to know where our traffic needs to come from but the antivirus is a bit laggy
Pros and Cons
  • "The top features are ones that we're not using yet but we soon will be because we've just had broadband upgraded in Australia. We've got something called the National Broadband Network, which is forced onto you, so you have to take it when it arrives. We'll be trying the high availability out soon. We tried that with some load balancing, it didn't quite work as we expected, but I think that was more of a configuration thing rather than a product thing."
  • "The antivirus seemed to be a bit laggy on the connection so I disconnected that. It's definitely good. The only issue we've had with any sort of cyber attack seemed to be coming from a couple of distinct locations, people trying to get into known ports on remote desktops and stuff like that. The fact that we can block all that traffic is just great. It simplifies it."

What is our primary use case?

It's the Edge firewall for my business. I'm a small business IT consultancy and I'm subcontracted out to a larger organization. It's really just me working from home, which is a bit more permanent now, but we do have a couple of other side projects I work on with a couple of other partners. One of them is a financial trading solution, so we want Kerio to beef up the edge security to make sure that the solution itself was secured nicely because it meant building out a rack of a couple of rack-mounted servers and beefing up the solution. 

Being an SMB, we do find that Kerio fits our needs. It fits nicely in that space because any time that I've been to an enterprise it's pretty much dominated by Cisco products. A product like this probably wouldn't get much air time to get in the door of a really big organization, whereas a small to medium-size enterprise where they're big enough to have some sort of IT presence, it would probably fit in nicely. With an enterprise that's my size that doesn't have an IT presence, then they'll probably use some sort of managed service solution.

We wanted to beef up the firewall and not just run off some sort of IoT style firewall that's built into a modem. It didn't seem to be adequate for our needs. So that's where we went into Kerio because at the time, we had some remote desktop services running and we were getting a lot of attempted cyber attacks coming out of China and a few other places. Kerio was one of the few that could actually geo-block, which was really quite handy.

How has it helped my organization?

Its primary job is to protect us and give us a degree of comfort. We're putting a lot of effort into creating a financial trading system. We want some comfort that it's secure behind the quality firewall and that's really what beckoned its purchase. The fact that we've not had any issue indicates that it must be doing that job reasonably well, and the fact that we don't get any of those attempted attacks from the block in China, because of geo-blocking, is probably the strongest feature for us. I wouldn't say it improves what we do because it doesn't affect what we do. It's really just security.  It's a tool to improve our security profile for what we do.

We don't expose our remote desktop connected servers to the internet anymore. But when we did have that, because the security log is a really easy thing to set up, it would show you all the attempted, brute force attacks. That's now down to zero. We don't get any brute force attacks, but at the same time, we don't expose the Port 3389 out to the internet. We could achieve the same result with a domestic firewall in a domestic router. However, this gives us a degree of comfort that we can actually analyze any traffic that looks a bit suspicious, inbound, or outbound. That's a definite step change compared to what we'd have in an out-of-the-box type of router.

Security is there to slow things down and make things a bit tricky. That's its bottom line. If security is easy, it's probably being done wrong.

Certainly in the first few months of using it, it was quite time-consuming to get a configuration working that was reliable. Because I work from home, I originally had it protecting everything coming in and out of the home which didn't work well at all. It's protecting the home office and the server environment. Everything else just goes straight out of the domestic router out to the internet because we've got IPTV, with kids on devices. They don't need such a high level of protection. It would be nice to give them that because if you've got this perimeter that's protected by a really good quality product, you want to protect everything.  But when we tried that, it seemed to struggle with the high volume of traffic that was being generated by the IP cameras, the IPTV service, and the myriad of devices and iPads that we have in the house. So we stopped using it for that purpose.

What is most valuable?

The top features are ones that we're not using yet but we soon will be because we've just had broadband upgraded in Australia. We've got something called the National Broadband Network, which is forced onto you, so you have to take it when it arrives. We'll be trying the high availability out soon. We tried that with some load balancing, it didn't quite work as we expected, but I think that was more of a configuration thing rather than a product thing.

The geo-blocking is essential because the partners we deal with are typically either in the US or Australia. We know where our traffic needs to come from and we don't post anything publicly that the general world needs to see. It's just a few discreet services that need to be hosted on this financial trading stuff.

The integration of Active Directory is very good as well. We don't use the VPN service. We use VNC. We get mixed results from the QoS, but that's another good feature. Really, dashboarding, track, and monitoring are the most important features for us as well.

We are about to test the high availability and failover protection because one of the issues we have is the device or the Hyper-V host seems to need a regular rebooting, which isn't an issue directly in itself, but it would be nice if it could do that on its own. We can't find a feature to do that. That's the complaint I'd have of that and the HA might solve that problem for us. So we'll give that a go.

Out-of-the-box, the overall comprehensiveness of the security features is pretty good. It's not just a firewall, it's kind of a firewall proxy, reverse proxy, everything out-of-the-box sort of solution. It's pretty comprehensive. I can't imagine wanting anything else, because for me as a consultant, it's not just about protecting the environment. It's also about having something that's commercial-grade because when you go in as a consultant, you need to be exposed to these tools and you need a lab environment to test these tools out. This is as close to a good commercial tool that you could possibly ask for.

In terms of the availability issue, I've considered that there are hardware options as well, which is nice. We're not sure if that will be an improvement over using Hyper-V, but that's to be decided.

What needs improvement?

The antivirus seemed to be a bit laggy on the connection so I disconnected that. It's definitely good. The only issue we've had with any sort of cyber attack seemed to be coming from a couple of distinct locations, people trying to get into known ports on remote desktops and stuff like that. The fact that we can block all that traffic is just great. It simplifies it.

The last time we used the antivirus, it seemed to slow down some of the connections. I didn't dig too deep into it, we just turned it off and it seemed to rectify the problems. It's hard to say whether it was that directly but it seemed to be creating a bit of overhead on the connections.

The reliability is its biggest downfall. I don't expect to be rebooting a product like this every couple of days. In fact, it's become a start of day thing just to reboot so it doesn't let me down in the middle of a team's call or something like that. It's quite slow as well. I could be on a team call and it would drop the connection. Then we'll get a warning that we've got poor call quality and as soon as you restart the device all the problems go away. There's clearly maybe some sort of memory leak problem or something in there that's affecting its reliability.

We've just had our national broadband network connection today, which is a high throughput connection. We will be reconnecting the entire household through the device, to see how it copes and we'll see if it improves anything.

Buyer's Guide
KerioControl
July 2025
Learn what your peers think about KerioControl. Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
864,155 professionals have used our research since 2012.

For how long have I used the solution?

I have been using Kerio Control for two and a half years. 

What do I think about the stability of the solution?

If I came across a client that was a small to medium enterprise, I'd probably recommend it, but a lot of them have a solution in place now anyway. It's hard to get those opportunities for new business in that regard, but I reckon it would probably scale quite well. I'm at 25 licenses, but that's only because we have so many devices in this house. It looks like it probably would scale. As I said, with that level of reliability, that probably would be an issue if you wanted to scale 100 to 200 licenses.

We did try the proxy feature, but once again, that failed miserably. It ran well for a few weeks and then it died on us, and it was really quite hard to diagnose what had gone wrong. We turned it off and went back to a previous configuration which was a bit disappointing. It comes back to that reliability, whatever it is that makes it conk out is clearly a problem.

How are customer service and support?

I used support once or twice when I hit the first license ceiling. I did log a support ticket in. They were fine. There were no complaints from that. They offer 24/7 support, via email. I don't think I actually phoned them up. It's pretty good. There are no real issues there.

Which solution did I use previously and why did I switch?

We tried a few different Windows-based products. That's how we found Kerio because it offered a Hyper-V solution and it also offered a hardware solution if you wanted. I'll try the software one first and see where we go. There were a couple of other products we used before. Originally, we used to use Microsoft, the ISA server back in the day because that got swallowed up by Fortinet and we didn't touch that. 

There was another Windows product, WinGate. That has a really bad reliability problem. It would stay up but the connections were very slow going through that thing. Maybe it was poorly configured on my part, but it just seemed to be incredibly slow at managing the connections. We'd notice a very latent response from web pages and it never, even though it had a massive caching there for caching pages, it just seemed to never be as quick as bypassing the WinGate software. That wasn't virtualized. That was running on a native Windows server at the time so that was really quite poor in terms of performance.

How was the initial setup?

Given that it's a Linux deployment, the support it offered, like giving you a Hyper-V client out-of-the-box, is fantastic. It's a really clever idea because you're not then left with a painful configuration of spinning up some sort of Linux host and then trying to do an installation. The fact that it comes pre-packaged with Hyper-V images was a very smart and clever move because that made it a lot easier to get it going if you like. Getting that up and running was quick, it was just a configuration, and finding the right configuration was the hardest part.

The deployment was less than half an hour. It was very quick to get it up and running and get it operational. It was just fine-tuning that configuration to suit my environment that took the time, which I would expect of any device, no device is going to come out-of-the-box and just work like magic unless you've got a really simple environment. Whereas I've got a home environment, where it's just me as a small business, but I've got that many servers and hosts running.

Our strategy was to take it out-of-the-box and get it working.

The setup was pretty easy. The external remote control was really good and simple. It gave extra manageability on the road which was good. It was pretty straightforward.

In terms of maintenance, it's just me. In terms of my time, it doesn't take much time at all. I'll hardly make any changes to it. Now it's running fine. The only next thing I'll be doing is trying out the HOA.

What was our ROI?

With security, I don't think you can calculate ROI. It's not easy to call a return on investment with security products because anything security that's done properly is going to be a cost overhead. That's by its very nature. If security is quick or cheap it's probably wrong. I don't look at it as a return on investment, I see it as security. A bit like saying if I bought a new car and they said, "I can save you $500 if you say no to the airbags." For 99.9% of the time, you'd be saving $500, until one day it costs you lots of money and maybe your life. I see it the same way.

It's not an optional extra, it is an overhead that you have to pay if you want to secure an important asset. You've got to weigh up how important that asset is against how well you want to secure it, and that's where you say, "Well, it's going to cost you the price of a Kerio license, the price of a VNC license, sort of remote management. And that's what it costs to manage and secure properly those services." I'd say we've achieved that. It's hard to really put a return on investment with security.

What's my experience with pricing, setup cost, and licensing?

I think it is a bit on the pricey side, but it's okay. I've got 50 licenses which I think is $250 a year or something like that. It's not terrible. It's actually cheaper than what we pay for VNC. We probably could save money thereby utilizing the Kerio VPN and not VNC. For a firewall proxy solution, it's probably a bit on the higher side price-wise.

We have to provide our own Hyper-V host to spin it up or buy the Kerio hardware, but otherwise, there are no other costs.

What other advice do I have?

I'm experienced in networking, but I'm not a network engineer per se, I'm more software development. The fact that I was able to get it set up and going with minimal fuss was definitely a plus for the product. I've seen products before where you can get them running, you make the slightest configuration change, and the whole thing comes crashing down. It's quite a stable product in that respect and it does look after itself quite well. For example, risk proxying solution and buying a GoDaddy certificate to secure a couple of APIs was a piece of cake. It really didn't hurt us at all. I think the important lesson there is, if we had tried to do the same thing with a NETGEAR sort of a firewall with a built-in firewall product, I think we would have had a hard time. Kerio definitely has made it easier.

I'd say give it a look for sure. I'd totally recommend it.

I would rate Kerio Control a seven out of ten. If I didn't have to reboot it so often, then it would probably score a nine.

It's not a cheap product and it's not a particularly reliable product at the same time which tends not to be a good mix. Something like this should be able to cope with my entire household, every device I throw at it, and it should be able to cope with that fine. It clearly didn't two years ago. We'll try it again in about 24 hours and we have to hook up this high-speed connection to it and we'll see how well it performs there. Reliability is about the only qualm I have with the product.

Which deployment model are you using for this solution?

On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
IT Support at Rural Computer Consultants, Inc
Real User
Content filtering and VPN simplicity are second to none
Pros and Cons
  • "The ease of use in the GUI itself is the most valuable feature. The GUI is really the best part of it. We like the traffic rules so we can control who can get to what. It's easy to determine the flow of the traffic itself so we aren't having to guess through command lines and reading out basically command-driven output. It's just a very easy-to-use interface. The interface is the best part of the product."
  • "The security part of the software, like virus scanning, website, traffic monitoring, things like that, can take a beating on the appliance. And when there's a lot of things going on, the system can get bogged down. The actual security functionality of it needs a little bit more work, which I believe they are remedying or attempting to remedy at this time, but that's the downfall at this time."

What is our primary use case?

We have over 50 office staff that we use Kerio Control to protect, monitor web traffic, and cloud-host environments. We have a VPN tunnel from outside vendors that we keep connected to our environment and we use it as a switching device between some of our hardware in the hosting environment. We also use it for the security function. 

Our primary use case is for intrusion prevention from attackers, from wherever they may be. And also for doing the quality of service because we have a lot of remote users, especially during this pandemic. We can control the quality of service with phones and network devices, as well as the antivirus scanning. We use the whole gamut of pretty much everything that Kerio has to offer.

We're still a small company but we are pushing what the software is currently able to handle, while it seems to be geared towards small-medium business.

How has it helped my organization?

Content filtering used to be that you had to block specific websites that you didn't want somebody to access, or you had to write a specific rule to say that something is accessible or not accessible. We can apply Kerio-provided categories and rules without having to define large scopes of protocols or malicious websites. That part of it has come a long way in the last five to ten years.

The GUI is the best part of the product. If another team member needs to get in there to do something, it's a really quick click and it's done. There's no learning through command-line tools.

On an annual basis, we save not just hundreds of hours but also labor costs. Over the life of the product, I'm sure it's in the tens of thousands of hours because we don't need an inhouse specialist in Kerio technology.


What is most valuable?

The ease of use in the GUI itself is the most valuable feature. We like the traffic rules so we can control who has access. It's easy to determine the flow of the traffic itself so we don't have to educate on command lines and reading out command-driven output. It's a very easy-to-use interface.

The comprehensiveness of the security features is fairly good. There have been some suggestions that we've made to the GFI team that we would like to see for performance. As our company grows, we need Kerio to grow with us, and so we've suggested some ideas on making the Kerio Control appliance perform better for more users because it can become sluggish under heavy loads.

In terms of security features, Kerio gives us most of what we need. There are some granular items that we would find more useful when we want to stop a particular region from access. 

The firewall and intrusion detection features are really good, it just needs a little bit more fine-tuning.

The content filtering and VPN features are great. The vpn client is ssl based, so no key cipher matching is required when setting up without information in front of you.

What needs improvement?

The security part of the software, like virus scanning, website, traffic monitoring, things like that, can take a toll on performance. The actual security functionality of it needs a little bit more work, which I believe they are remedying or attempting to remedy at this time, but that's the downfall at this time; it is currently running on an end of life linux kernel.

For how long have I used the solution?

I personally have been using Kerio Control for 13 years but it's been at my company for close to 20 years.

What do I think about the stability of the solution?

The stability has actually improved quite a bit. There were some bugs found in previous versions up until about last spring, and then they concentrated on fixing some of the issues causing us some problems. As of the last update, it's very stable.

What do I think about the scalability of the solution?

It's not very scalable when you start to get into the hundreds to thousands of users because the performance of all of the functionality isn't quite there yet. We're hoping that's remedied with some updates coming down the line.

Kerio is pretty much the backbone of everything that we do. Keeping all of our customers connected to us, keeping our staff safe online, and getting our staff into our cloud environment.

How are customer service and technical support?

The GFI technical support can be very time-consuming to get down to the root of the problem, but they are very helpful when you do have an issue. It just takes some time to get to it. It sometimes can be communication that's the issue. Sometimes it can be the complexity of the problem.

It doesn't seem to be a lack of knowledge on the technical support side of things. Some of it comes down to whether the product can currently do what we needed to do or not. We were trying to determine if there was something that we could do to get better performance out of the appliance, and the response from the GFI support team was that it wasn't able to do some of the things that we wanted it to do, but it was something that they were looking at with rewriting some of the functionality. There is the possibility that some of those can be overcome easier.

Which solution did I use previously and why did I switch?

I did not have any experience with another similar solution. In fact, I had never heard of Kerio until I started at my company, primarily because Kerio was fairly small at the time. They were based out of California at the time. They were a small company and generally fit into the 100-users-or-less environment. When you would hear about other vendors, they generally ran in the thousands to tens of thousands of users and you just didn't hear about Kerio in that product line.

We take other solutions into consideration based on the growth needs that we have. As our cloud environment gets larger, if the Kerio technology is not able to keep up, that's always under consideration.

How was the initial setup?

The process was pretty straightforward. Something that I expected to take days to weeks took about two or three hours.

What was our ROI?

Network security should not be planned around providing a return on your dollar in terms of a payback in the administration of the process. It should be planned around providing a level of comfort to management that intruders are being kept out of the network, errors and omissions are being kept to an acceptable level of risk.

What's my experience with pricing, setup cost, and licensing?

Price-wise, it's very affordable. Whether you're a smaller or larger business, whether you're five users or a couple of hundred users, the pricing is very fair. The performance of it is what determines how you want to license it because you can purchase a Kerio appliance. We try to make use out of everything because we like to keep it in one place. It has fit our business size and needs.

Which other solutions did I evaluate?

Some of the main differences between the other solutions and Kerio is that Kerio has made their subscription service fairly universal. You get pretty much everything with one subscription. With some of the other vendors, you have to subscribe to each module that you want to use. On the other side of it, other firewall vendors tend to be able to handle in the millions of connections, hundreds of thousands to millions. And we see some of those limitations with the Kerio appliance because of some of the aging architecture of it.

What other advice do I have?

My advice would be to follow the hardware requirements of Kerio and make sure the equipment that you have can run the connections for the number of users that you intend to run and are being planned out to be successful. Working with the Kerio team to determine your needs works out very well. 

Not all firewalls have to be difficult to learn. Kerio has made it a really easy-to-use product.

Which deployment model are you using for this solution?

On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
KerioControl
July 2025
Learn what your peers think about KerioControl. Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
864,155 professionals have used our research since 2012.
General Manager at Gays Hops-n-Schnapps
Real User
Using the VPN it's like I'm sitting in our store; provides seamless connectivity
Pros and Cons
  • "I love the VPN that we set up. A few of us have it on our computers so that if we leave, we can still access the stores. And we can work from home if needed. When I sign into that Kerio VPN, it links me like I'm sitting in the store. It puts me in our secure network so that I can sign on to each individual store and I can run numbers... If I have to work from home, it's so much faster than the way we used to do it."
  • "When we did our last update, we had some trouble with the initial syncing process to get our messaging to go through. But we were also moving a store and a lot was changing during that process. I don't think it was on Kerio's end. It just coincided with the update. Once we got our third-party IT guy involved it was resolved very quickly."

What is our primary use case?

We mainly use Kerio Control for the phone systems. We use it like a VPN network so that I and a couple other guys can take our computers home and work from home. That's a great feature. We love that because you can sign in at home and be like you're in the store.

What is most valuable?

We have five locations and, for the person who controls it we have it set up in our main office. The ease of access, of being able to change a voice message, it links to that. The person who controls it can approve it and then she just plays it. That's great for when we have to do a holiday message or special events are happening. We love that feature. 

I love the VPN that we set up. A few of us have it on our computers so that if we leave, we can still access the stores. And we can work from home if needed. When I sign into that Kerio VPN, it links me like I'm sitting in the store. It puts me in our secure network so that I can sign on to each individual store and I can run numbers. We work through ICS Vision for our stores. We have a corporate plus five stores and it lets me link to all that. If I have to work from home, it's so much faster than the way we used to do it. It saves me a couple hours of each time I use it from home. It also saves me from having to drive in.

It's the overall ease of everything. It seems to have pretty seamless connectivity for linking our stores.

Also, the firewall and intrusion detection features seem to keep people out of our servers. I know it's a little bit of a process to try to link something new into it because the firewall is very secure, but we haven't had any issues with malware attacks on our end so it must be stopping them.

What needs improvement?

We haven't really had any major issues. But when we did our last update, we had some trouble with the initial syncing process to get our messaging to go through. But we were also moving a store and a lot was changing during that process. I don't think it was on Kerio's end. It just coincided with the update. Once we got our third-party IT guy involved it was resolved very quickly.

For how long have I used the solution?

We have been using Kerio Control for about six years.

What do I think about the stability of the solution?

The stability has been fine. We have no concerns or complaints.

What do I think about the scalability of the solution?

In terms of increasing usage, that's going to end up being discussed in a meeting with our IT guy to see what capabilities it has, how we could expand it, how we could grow with it, and how it could help out day-to-day business.

How was the initial setup?

I've been with the company a little over three years now, but when I came in as general manager it was already in use. The upgrade is the closest that I've been to a deployment.

From start to finish, when doing the upgrade, we were back up in an hour, including the issue we had. Our IT guy let us know what was going on and that there was a series of events he had to do and he did them and we were good to go.

What was our ROI?

From the old way we used to do things, it's night and day. Before the company brought this on, it was pretty old-school in how it did its phone systems and messaging. The efficiency has doubled, but the company also used to use answering machines way back when.

What's my experience with pricing, setup cost, and licensing?

I've never seen any additional costs incurred or involved, other than the initial.

What other advice do I have?

The biggest lesson from using Kerio Control is the untapped potential there is to link to everything and streamline our business. That's really what it's about for us. Obviously, there's more out there for us to do with it.

As an SMB, Kerio Control is a good fit for our environment. It serves what we need done. I would recommend it for a smaller business because the ease of use and the access it allows us are great.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Owner at Multi Level Software
Real User
Gives me the ability to map which ports to allow in and out of the VPN
Pros and Cons
  • "I want to have access to my computer from the outside and Kerio Control plays a role because it has a VPN... It is more reliable because it's a smaller group of computers to target for hackers and the like. The VPN works very well. I use it to work remotely very easily and exchange information, both to and from the location where it's deployed, and there have been no problems there."
  • "I would like to be able to automatically send email from Kerio Control and have it tell me what my external IPs are, because on one of my lines I have a fixed IP address and on the other it is variable. If there were a permanent way for me to figure out, "Okay, my current external VPN and my firm IP is this," it would help. I need to know the IP address to connect with the VPN and, at the moment, one of the lines sometimes changes its IP address without me knowing it. It's a hassle to figure out what it is."

What is our primary use case?

I use Kerio Control because it is one of the few firewalls which allows easy failover from two separate internet providers. It also has virus protection built-in. I use it to have reliable access to the internet, which is virus-free and which fails over if one of my internet providers drops — and they do sometimes when it rains. Those were the reasons I wanted Kerio Control. And it just works; provides internet.

We are a very small company, and started with two users. We have now four users who use it on and off. There are nine or 10 computers. I, myself have three or four computers working at the same time. I'm not really dependent on cloud, but I use internet very much in a lot of situations.

It's deployed onsite but as a virtual machine in a Windows server.

How has it helped my organization?

Being an SMB, Kerio Control is nice-to-have. It fulfills my needs completely. 

It allows the users I have to use email without any problem, without their having to know anything about the fact that there is a firewall which protects them in different ways. I might spend an hour per month on maintenance of the Kerio system. So it's very transparent and very hidden. The best thing is the fact that nobody notices it.

It has helped me save time. It allows me to get on with my main work, without spending any time on security or worrying about threats to the data I have. Without it, I would have lost a lot of time. A long time ago, I spent a lot of time cleaning computers, removing viruses, etc. That has all gone away since I have had this set up, as part of a three-layer defense.

The failover has no effect on security. It only affects the availability. There used to be a situation where I had two internet providers with different speeds. If my main provider was down, it would be backed up by the other and I wouldn't notice that it was a little slower, and I wouldn't notice that one of my internet providers was unavailable. This guarantees that I always have internet availability. We had some technical problems with one of the lines which was very sensitive to rain — which sounds weird, but okay. And this setup allowed me to not think about it anymore. Since then, internet speeds have grown and at the moment it's not a big issue, but I'm sure that both of the providers drop once a year for a day. But I don't notice it, and that's very important for me.

What is most valuable?

The most valuable features include 

  • being able to attach to two different internet providers
  • the ability to map which ports you will allow in and out of the VPN, which is built-in 
  • the fact that it reliably works without any attention.

I want to have access to my computer from the outside and Kerio Control plays a role because it has a VPN. This VPN is different from most other VPNs, although they have used a standard version. It is more reliable because it's a smaller group of computers to target for hackers and the like. The VPN works very well. I use it to work remotely very easily and exchange information, both to and from the location where it's deployed, and there have been no problems there.

I have one or two VPN clients, at most, that are active at one time, so it's there if needed when I'm not working at this location. It helps me a lot to have a reliable VPN client. I have no performance issues when working through VPN.

Kerio Control also has some authorizations so I am able to block internet access for certain hours for certain people.

Overall, the security features are adequate. They do what I need. I don't have much experience with anything else, so I can't compare, but they completely solved my problems.

The firewall and intrusion detection features don't hinder me, and I haven't had any attacks, as far as I can see. I want a firewall to be unobtrusive. I don't want to notice it's there. It should just do its work and protect me and not hinder me when doing real work, and that's what it does. It's very good because it shouldn't be noticed, and it's good at not being noticed and doing its work.

Overall, I don't have any problem using Kerio Control. For me, it's very easy, but I've been working in software for some 50 years.

What needs improvement?

I would like to be able to automatically send email from Kerio Control and have it tell me what my external IPs are, because on one of my lines I have a fixed IP address and on the other it is variable. If there were a permanent way for me to figure out, "Okay, my current external VPN and my firm IP is this," it would help. I need to know the IP address to connect with the VPN and, at the moment, one of the lines sometimes changes its IP address without me knowing it. It's a hassle to figure out what it is.

It might also be interesting to have a GFI-approved, Docker-containerized version of the Kerio Control system.

For how long have I used the solution?

I have been using Kerio Control for more than 10 years.

What do I think about the stability of the solution?

I don't remember any glitches. I haven't had problems with it for a very long time. But I use it very specifically for a certain purpose and that works fine.

What do I think about the scalability of the solution?

It's very hard for me to give a correct estimate of the scalability, since a lot of overhead in my situation is caused by the fact that I run it in a virtual machine. That means the bandwidth which it can process, which would be scalable, is downgraded because it's in a virtual machine. That's not Kerio's fault.

I have no plans to increase the usage in the future. For me, it's adequate because I have a lot of leeway. I have enough bandwidth available to fulfill my needs.

How are customer service and technical support?

The problems I've had with Kerio, when I wanted to change something, have always been solved by consulting the Knowledge Base.

We are located in Holland and there is supposed to be Dutch tech support, and there is an American tech support, as far as I know. The bad thing about the American tech support is that reaching them by phone is difficult and by mail there's a certain turnaround. So, I'd rather rely on the Knowledge Base so that I'm not really dependent on the person on the other side.

They have an extensive Knowledge Base and, if you can't find something there, you can check the internet and there's enough available.

Which solution did I use previously and why did I switch?

I switched because I wanted something which had the possibility to handle two different internet providers, two network cards, and do load switching and load balancing. The other solution I used didn't have that.

How was the initial setup?

The initial setup is easy. I know what I want to configure so it's easy, no problem at all. 

The biggest problem I have is using it as a container on a virtual machine. You have to connect your hardware network cards to the internal virtual machine. That's a problem that Kerio won't be able to solve because it's the environment I have to create to let Kerio work in the way I work, and that is probably different than most users. But if you use it on a simple PC, it's no problem at all.

I reinstalled it recently and it took me about half an hour, and part of that was getting backups right, etc.

As for an implementation strategy, I changed the system my Kerio was installed on, so I first did a trial-install to figure out if everything worked. After that, when I did the actual production install, it was done very fast because I had tried it out before.

What was our ROI?

It does its job. Converted into hours, it doesn't cost more than five hours per year to pay the price for the 10 users I have. That's a good deal for me.

Having good internet access is a very large requirement for me to do my work. Internet is one of the basic tools I have and I need a firewall. Your internet provider will give you a box that has a simple firewall in it, but that doesn't suffice for me. I need something like this and it's not an option for me not to buy a product like this. I'm really not even thinking of return on investment. If I don't have something like this, I just can't work. It's a basic necessity.

What's my experience with pricing, setup cost, and licensing?

I don't think it's expensive. I'd recommend it to others.

Which other solutions did I evaluate?

I haven't evaluated any other options. I started using Kerio Control and it was sufficient. I haven't spent any time looking at alternatives. I've seen constant improvements in Kerio; they actively enhance the product. That's a good sign for me. I also use the GFI mail server and I prefer to use one company for my tools.

What other advice do I have?

My general advice is always: Read the manual, check your hardware and see if you have everything you need, and if it will suit your needs.

It's hard for me to assess its malware and antivirus protection because Kerio is one part of a three-part defense against malware and antivirus. I'm not sure which part picks up which problem. My philosophy is that no single protocol picks up all the problems, so if you have several of them, you'll fight the virus or malware at some point. That's why I have three different tools with different focus points, and together they keep me safe. Malwarebytes specializes more in malware, ESET is a normal desktop antivirus system, and this system is a general anti-malware and antivirus system of another type. They compliment each other.

I have an internet speed of 200 megabits per second, and 15 might be enough. So the only point I don't know about Kerio is whether it takes a lot of performance out of the maximum you could get if you didn't have a firewall.

Overall, I would give it a nine out of ten, but with the comment that I haven't compared it with anything else. On my scale, 10s are very rare. They're for things that go beyond my expectations and Kerio does exactly what I expect and it does it well.

It's just an essential which does it's work. I don't think about it normally. It's just there and it works.

Which deployment model are you using for this solution?

On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Owner at Fr@nkonnections
Real User
Very easy to view how things are working and protects you from hackers
Pros and Cons
  • "When one of the employees of my customers is using the VPN Client, I have created for them that they will always get a message. When the VPN Client connects to Kerio Control from the outside, they will get an email so they know when they are connected and when they are disconnected what is happening to their network."
  • "After the takeover by GFI, one of the things that Kerio built was MyKerio environment. This has not been very reliable because I get many messages that MyKerio is not functioning. For some reason, there are things that they changed and it is not very reliable at this moment, instead I have to connect to the firewall to see what is happening."

What is our primary use case?

I use it as a service for my customers. My primary target is to help my customers in the best way to protect them from the dangerous things from the Internet. As a solution, it's easy to maintain. The product is a good solver that also depends on good support and its availability of engineers.

I am using the latest version of Kerio Control. It is an old type of configuration with VPN connections. I still like the product very much.

It is mostly installed on the Linux software appliance. That's what I mostly use for my customers.

How has it helped my organization?

Most customers are not able to understand the technology behind it. I am always trying to explain it to my customers. When I show my customers the interface of Kerio Control and all the reporting features along with the security features within the logging, they're very impressed. I have a very good relationship with my customers because this is mostly based on trust. I show them, and if they have doubts, I always say, "Just hire somebody to check my work." For example, a year and half ago in the travel industry, there were new rules for travel agencies who give out credit cards that they must comply with PCI DSS standards. There were some things that had to be adjusted and Kerio was able to adjust for that. So, it met the demands of PCI DSS standards.

When one of the employees of my customers was using a VPN Client, I created it so they will always get a message. When the VPN Client connects to Kerio Control from the outside, they will get an email so they know when they are connected and when they are disconnected what is happening to their network. I can, as an administrator, look in the logging and see what's happening. If I really wanted to manage what is happening over a month, then I could go deeply within Kerio Control and make a text file of the logging. I could then order an export to Excel to give the customer an impression of what is happening.

Our customers don't want to worry about their IP. If it's implemented well, Kerio Control is very good product for this.

What is most valuable?

  • Security
  • Ease of use
  • Ease of install
  • Ease to recover
  • The load balancing is very easy to maintain.

The login appearances are very strong. In case of problems, you're able to find anything you want. I am always able to help my customers. I really love this product. It's very good. With its many features, there is no comparison. Over the years, I have seen other types of firewalls but they don't have these functionalities within them. 

You can create your users, groups, IP addresses, IP groups, and make rules. It can do protocol inspection and load balancing. You can have a backup line where all kinds of scenarios are possible. 

It has security features, like an open source Internet protection system. This is well-known and a good solution to protect you from guys who try to hack systems. They have also integrated a fire scanner, a protocol inspection, and web content filter. You can adjust things depending on the types of organizations who are using it. Over the years, it has been very easy to maintain. 

I haven't seen anything else that compares to the comprehensiveness of its security features because I'm working mostly with small to mid-range offices. Manageability is very important, and that is possible with it.

Kerio Control's firewall and intrusion detection system, Snort, uses tables that are available on the Internet and loads them automatically. Over the years, I never had problems with my customers. The stability is very important for the product. I use Kerio Control as a central security system for my customers. On the workstation, I mostly use a virus scan. There are also multiple virus detections through your firewall. 

The VPN Client for users is a strong feature within Kerio Control. An important thing within the VPN Client is it also has the possibility for two-factor authentication, which I really like. For some customers, this is very important.

I like its malware features.

This is a very robust the product.

What needs improvement?

With Kerio Connect, they blew it. They were not able to pace up with the competition. I am working with a variety of customers: lawyer offices, travel agencies, big shopping mall accounts, and small accountancy offices. They have all kinds of needs. Kerio Connect did a new launch in the Netherlands for the ACG and GDPR, which are very strict for some companies, like lawyer offices. It is important within the mail server product that you're able to encrypt your attachments and have two-factor authentication. All these type of things are not within Kerio Connect. Therefore, this product is not interesting anymore for my customers since the Dutch law is that strict. For example, there was a judgment from a judge this year when a company was hacked. There was a guy who maintained this network gave some advice to the customer, but the customer would not pay for that solution. He was held responsible for about 60 percent loss of this business, because there was a ransomware within in the organization. These are the things we have to deal with in the Netherlands and in Europe. Within the Netherlands, this is a very important thing, so you can probably understand how important it is that the product is okay with the market demands.

After the takeover by GFI, one of the things that Kerio built was MyKerio environment. This is a cloud solution to have an overview of the statuses of all the firewalls that you maintain. When a firewall or primary interface goes down, then you get messages. It also has an app for iPhone or Android. You can then have a quick view about the status of the firewalls for your customers. If there is a problem with the Internet connection, whether it is down or there is an update, then you get a message. So, I can proactively help my customers. However, after the takeover, this has not been very reliable because I get many messages that MyKerio is not functioning. For some reason, there are things that they changed and it is not very reliable at this moment, instead I have to connect to the firewall to see what is happening.

MyKerio is a cloud thing where you can easily see all the firewalls that you maintain for your customers along with the statuses behind them, providing a way to securely connect to your firewall appliances. This is a very strong feature of MyKerio. However, nowadays, I'm not really impressed about things they do with it. That needs improvement in my opinion.

Another thing is that you must be a specialist, like me, when you want to have more specific information, e.g., when there are incidents or things that are happening that need investigation, then you need to go to the shell prompts and logging, where you can perform anything. You can edit anything out of your log files. However, this is not possible within the Kerio Control admin interface. You can only search for one thing, but not for many things.

Kerio Control has a very good future, but it needs good marketing and knowledge around it.

For how long have I used the solution?

I have been working with it since the beginning (1997). When it started, it was called WinRoute. Now, the name is Kerio Control.

What do I think about the stability of the solution?

It is a very stable product, which over the years has been very good. 

What do I think about the scalability of the solution?

The scalability is good. The VPN connections may need improvement. Because of all the security features within Kerio Control, e.g., it can do a deep packet inspection, this can slow down the traffic. Sometimes that creates a problem. For example, Kerio Control offers protocol inspection for the services that are available, and sometimes that gives problems because people are complaining that it is slow. The VPN connections from remote are not always very fast, so I think the throughputs of the VPN need improvement.

How are customer service and technical support?

In every software, sometimes there are problems. One of the strong things about Kerio was the support knowledge and the involvement of the employees within the support department. I used to have the impression that the people working there were part of the products. It was almost a pleasure to have contact with people who were really involved with the products. After the take over of Kerio Control and Kerio Connect by GFI, it was really disastrous because a lot of the people involved were gone. When I had a problem and I asked for support, then they are asking me questions that I think help, but they don't understand the product. This is logical, of course, because there was a takeover.

The GFI product support for Kerio Connect has been unacceptable for my customers and me because I had major businesses that were running with this software and very satisfied because of the user-friendliness. Error and problems cannot be cured, but they must be solved. For example, when I perform an update, the next thing will be a ruined email system, but nobody will be available for support. This is also when they know that an update is coming and I am calling after updating it. They promise to support us, but there is no support, which is terrible. This is the thing that I feel is very important when you use business-critical software, and they need to improve on. I want to be able to call their support and reach someone who has knowledge about the product. 

It has a very sophisticated logging system. I need to be able to connect to the engineers behind it, who develop it, and tell them, "Okay, that's wrong." If I'm not able to connect to first level engineers and make them understand that they're not able to help me or they need deeper knowledge of the product, then there is a problem. While this is not an issue with Kerio Control because they have proven with the product that they are able to maintain it, the major problem for me with Kerio Connect was they ruined things in the past and I was unable to go back. So, I'm very interested in how they are improving the support to make things work again with MyKerio, as it is very good feature.

Which solution did I use previously and why did I switch?

I have worked with all the firewall systems, like Cisco. I see how people struggle of with it and also how much effort it takes to maintain it and implement rules. Kerio did a very good job with that. You can also, in a quick way, see inbound and outbound traffic and make your own filters.

How was the initial setup?

A basic initial setup is very simple and straightforward. They offer a straightforward set of rules to make it work, then you can create all the rules you need for the customer depending on their demands. It can do almost anything.

The deployment time frame varies. For example, if I am deploying to a shopping mall, that shopping mall has all kinds of offices. Every office has its own demands regarding the IP system that they use. Every shop has its own software supply and concepts. Sometimes things get complex, then I start from scratch to make sure everything is maintainable, but this is very easy in Kerio Control if you know how to do your job.

Because of the coronavirus, for people who want to work at home, it is very easy to set up VPN Clients because that is a piece of cake.

What about the implementation team?

When you look at Kerio Control, they are able to maintain it in a way that I had no problems because I was always careful with updates. I first test them on-premise before I roll it out to my customers. That's also no guarantee, but we are able to maintain it in a good way.

Implementation strategy changes per customer. Some customers have very strict policies about the sites that they can access via the Internet. Others have limited bandwidth. For example, I had a customer who could not visit some Internet sites because most of my customers have two Internet connections. I found out that connecting through the other interface wasn't a problem. It had to do this with the networks between them. It's very easy in Kerio Control to make another path where another Internet connection is used for that website.

I built a large network of freelancers over the years in the Netherlands and foreign countries to get the best solution for each customers. I am working with all types of people who are trustworthy and have good knowledge of the product. I tell my customers, "The IT world is the same as the medical world. You don't go to a heart specialist for an eye operation, and you don't go to your normal doctor for a heart operation. They're all specialists on their specific terrain." That is the way I operate for my customers.

I handle the deployment and maintenance of Kerio Control myself.

What was our ROI?

I have seen ROI over the years. It is part of the complete solution that I offer to my customers. Over the years, it has offered me a reliable platform for my customer and allowing me to build trust with my customers. That's the most important thing of Kerio Control.

If the support is not good, then I have a problem with my customers and it will cost me money. That's one of the things that GFI did after the takeover: It cost me a lot of money. Because there were a lot of problems, not with Kerio Control, but with Kerio Connect. It really cost me with unsatisfied customers.

What's my experience with pricing, setup cost, and licensing?

It's not a very expensive solution from my point of view. Because it is not only about buying a product, but how much time does it cost to implement the features that the product offers? I haven't found another product that is able to do the things that Kerio Control can do for the money. 

It is a good fit for SMBs because of its maintainability. When you want to keep your costs low, then Kerio Control is a very good solution. It's not an expensive product that is well integrated. It has a complete set of features within it that make it a very strong product.

GFI has made a stupid decision regarding small office licensing. For offices where there are only three to five employees and had five years towards a five user product, they now force these customers to a 10-year user license. I really don't understand it. It's a stupid decision for the small offices who want a good solution for security because they'll probably decide to go to another product. Why should they buy something that they don't use?

I don't use the Kerio hardware because they're too expensive and difficult to maintain.

Kerio Control has the ability if you buy it (it's a separate option) to know malware sites. Then, they will be blocked and the user is informed.

Which other solutions did I evaluate?

I have used Cisco, FortiGate, pfSense, and then more simple router things that have integrated software. However, mostly in business, I don't want to use just a router with integrated software. I don't believe in that concept. My customers are of a size that the stability of the product and the way it is maintained are very important to me. That's one of the strongest things about Kerio Control. It has proven to me over the years, and with my customers as well, that it's a very stable product. I haven't seen another product that compares to it within its price range. However, I also have to help my customers when they are having problems when connecting to a site or when they are having problems in general. When I contact their IT to find out what's happening on their side, it is difficult to get an answer why things are going wrong.

I can't find a comparable product to Kerio Control that offers the same set of features for the same money.

I found another product that can do a lot more than Kerio Connect, and that's IceWarp. IceWarp is a very strong product. IceWarp is a really strong competitor within this market. I was impressed with the software's ease of use because it's completely web-based. It's not only a mail server product, which offers secure attachments with out-of-the-box Office, but offers two-factor authentication. It also has a web-based text editor and Excel sheet, where you can make a basic presentation. With the same interface, there is the possibility to do OneDrive or Google Drive. They built it with the same depth that you need to log in to your IceWarp environment as a user. You can store your documents and sync them with a Mac or Windows PC. However, there is not much to find about this product.

What other advice do I have?

Kerio Control is very good. The way that you can maintain it, it's very easy. I had an employee who built a copy of the product, which was a very basic interface for the open source community. You can find it on the Internet. He was impressed by the way Kerio built this firewall solver, because most firewalls are very difficult to maintain due to their complexity. If you are working in complex environments, it is not easy to maintain firewalls, because things are always changing. This is the part of Kerio that is very good.

Every IT guy that I show the interface of Kerio Control is impressed with the product because it's very easy to view how things are working (when you know what you're doing).

Ransomware is protected only when the system is able to detect, "Okay, this is coming from a link and that link is known, and it is within the protection."

I don't use the solution’s high-availability/failover protection because the hardware is needed as well and I wasn't able to test it. I want to test it first, because it's not only the testing, but what are the costs of ownership for the customer? Over the years, the Internet connections in the Netherlands are very stable. I always tell my customers that if they have an Internet connection that they should have a backup connection. The hardware that I use is mostly recent, stable hardware. So, it's not for my type of customers. This is not a very important feature because the hardware is well-maintained. However, that's a thing that I take care of since most hardware fails because there is not a good cooling environment or a lot of dust is in hardware. I make sure that things are running well as part of my services.

I'm still surprised that sometimes I need something which I thought was not within Kerio Control, and it was within Kerio Control. That's mostly the case.

Biggest lesson learnt: Stick with suppliers for software products who are able to give very good support.

I would rate the product as a nine (out of 10). It is very good.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
reviewer1380816 - PeerSpot reviewer
System Administrator Team Lead | Developer at a tech services company with 11-50 employees
Real User
Makes it easy to manage and add settings to the firewall, and gives us a single point to manage global rule sets
Pros and Cons
  • "The traffic insight page or the administrative portal is really helpful because you can see all the internet usage down to the point where you can see if it's big files or streams. It gives us a good view of what the internet usage is of users who are coupled to an IP address. That way, if there are problems with, for example, a lot of data usage or problems with the connection, we can narrow it down to a single user or server and address the problem. It's really helpful for diagnostic data."
  • "If you have to dive deeper into the firewall or any other features, then you really have to read up a bit about how to set it up properly. Some of my colleagues, in the beginning, jumped in and made a bunch of rules but then it got really messy. If Kerio had a template or guidelines for best practices, at the beginning, that would really help. With Kerio Control it's basically 'find out for yourself.'"

What is our primary use case?

We mostly use Kerio Control as a virtual firewall solution, and the user accounts let people have access to the internet through the firewall. We also have a few cases where we use the VPN. But it's mostly a firewall solution with multiple VLANs and the network behind it.

It's deployed on-premises, both virtual and hardware solutions. The NG100 is the smallest solution for smaller businesses, but we mostly use the virtual appliance.

Most of our customers are small to medium companies, where there are between five and 40 work spaces. Everyone has a PC and they have a VoIP phone and their own phones, and they have tablets. Most of the time, it's one to four devices per user. The biggest client we have is around 30 users.

How has it helped my organization?

It has made it easier for us and our employees to manage and add settings to the firewall, as opposed to another brand where you have to use command-line or really complicated layouts. The ease of use is a big plus.

The solution has also saved us a lot of time in managing security. We have to adjust the content rules and now we have one place where we can enter them. We have a customer with about 20 Kerio Controls and we don't have to set all the rules on each firewall. When we have to add some rules to each of the firewalls, it can be done within one minute. Normally, it would take 20 to 30 minutes, depending on if they're all online — and we would have to check them manually. Now, we just have to enter them and, when they come online, they sync with the global rule sets.

What is most valuable?

The traffic insight page or the administrative portal is really helpful because you can see all the internet usage down to the point where you can see if it's big files or streams. It gives us a good view of what the internet usage is of users who are coupled to an IP address. That way, if there are problems with, for example, a lot of data usage or problems with the connection, we can narrow it down to a single user or server and address the problem. It's really helpful for diagnostic data.

The content filtering is pretty good for our needs, especially with the global rules you can define. We can define global rules and use them on multiple Kerio Control installations. So we have one place to set all the rules for different customers. That's very good. The rules that it auto-updates and that are automatically available — for example, spam or indecent websites, or whatever else is in the firewall by default — are good.

The VPN works pretty well, especially with the Kerio Control VPN software. Some products don't have their own VPN software and, with Windows, sometimes it's just better to have a piece of software. That's especially true for some of our customers because they only have to open the software and press "Connect." Windows can be a little bit weird when it comes to that, and it breaks connections. You really don't see when Windows loses a connection or if you have to reconnect. The Kerio Control VPN client is pretty good at that.

What needs improvement?

The antivirus is either on or off, but we can't really see or measure how well it is doing. Sometimes we get the feeling that some files get past it and then they get caught on the antivirus of the client PC. We would like to have more control with the antivirus.

Also, we have multiple employees working on firewalls and if one employee changes a rule and traffic that shouldn't be there suddenly comes through the firewall, it's hard to pinpoint which rule is affecting that traffic because there is some overlap. It's not clear if it's getting past it because it's not decrypted. It needs more logging or more in-depth diagnostics about which traffic is hitting which rule on the firewall. Sometimes we have 20 or 30 rules and it becomes a whole job to figure that out.

When it comes to QOS, the quality of service, you have to set a fixed bandwidth. But sometimes, when we have multiple connections in front of it, it's a fallback line. For example, when we use Kerio aboard a ship, there is the satellite connection but there is also a 3G or 4G connection. We always have to set a fixed limit for the connection. If we set the fixed limit to 4G and it switches to navigation, one user can use up all the bandwidth for the entire ship. It would be better if there were something more dynamic, where it could sense the total and we could use percentages. For example, we could say a user has always 5 percent of the connection. But now we have 5 percent of a fixed connection number. The fixed limit on a line for QOS is a problem because we don't always know which connection is in front of it.

Also, if you have to dive deeper into the firewall or any other features, then you really have to read up a bit about how to set it up properly. Some of my colleagues, in the beginning, jumped in and made a bunch of rules but then it got really messy. If Kerio had a template or guidelines for best practices, at the beginning, that would really help. With Kerio Control it's basically "find out for yourself."

We've also had some problems with how to set the rules, but that's when more than one rule is overlapping and cancels out all the other rules. However, that's more our fault.

For how long have I used the solution?

I have been using Kerio Control for around six years.

What do I think about the stability of the solution?

It's pretty stable. We had some problems with Kerio Control virtual appliances. If it was running more than 20 days, it would become really slow and sometimes it would just stop working. When we rebooted the solution it would come back up. But that was something that was happening a year-and-a-half ago. Since then, we haven't had any more problems with it. 

We had a few solutions that just went corrupt. We're not sure if that was the disk or Kerio itself. We always have an installation of the virtual appliance on the server, so we can set up a new one, load the backup back in, and be up and running again in 15 minutes.

How are customer service and technical support?

It's been a while since we contacted support, but back when we did it was pretty hard to get a hold of someone. We didn't get a lot of feedback. Most of the time, it was, "Look at the documentation." It was hard to get someone to look over our shoulder and help us with the problem. I think that was before GFI took over.

Which solution did I use previously and why did I switch?

We did not have a previous solution. 

How was the initial setup?

As I said, if there were best practices or a template, the setup would be a lot easier because you start and then you change the setup according to what you think is right. But later on, when you encounter problems and look in the documentation, you see that another way is better. That was a bit of a problem when setting up. It all works, but in managing or adding rules, for example, or we just didn't do it properly. It was a bit of trial and error and that was a problem. It's too much trial and error when you start.

Deployment time, for some customers, is fairly quick. A basic setup can be up and running in 15 or 30 minutes. With other customers that have a lot of rules we do testing so it could take three or four hours.

For our implementation strategy, we just look at what the client wants. For some clients, we have a basic template now, where we always use a backup from an existing Kerio. If it's a new customer, we check if we have an existing Kerio that's pretty much the same, or we just do it from scratch if there aren't too many rules or networking behind it.

What was our ROI?

We see ROI because the ease of use is a lot better, so we spend less time on maintenance, administrating, changing rules, and checking usage.

What's my experience with pricing, setup cost, and licensing?

If you have a lot of users, the licensing can be a bit of a problem because we have a lot of customers who don't use the user feature, but we have five devices per user, and we have to extend the license every time. The fixed model of users and devices is a bit of a problem for us. We want to be able to expand it fast and not have to contact our supplier first to get a license. That takes another one or two days and the customer is waiting.

It might be better if they offered a fixed monthly or yearly price instead of the user-based price. That's really keeping us from deploying with some of our smaller customers or customers that have a more dynamic user base. If they had a larger fixed price with unlimited users or devices, that would help. Now, it's five users each time. A pack of 100 or 200 users for a certain price would make it more dynamic and user-scalable.

Which other solutions did I evaluate?

We looked at pfSense and some paid firewall solutions, but in terms of how user-friendly it is for our employees and my colleagues, and how well we could manage it from a remote portal, Kerio Control was better, in our opinion.

What other advice do I have?

Kerio Control is a nice-to-have for a small business like ours.

My advice would be to look at best practices or get someone to show you how to properly set it up before you try anything and it gets too messy. The biggest lesson I have learned from using this solution is to look out when it comes to firewall rules. Don't use too many firewall rules or content rules because it can get really messy, really quickly, if you don't have a decent strategy for that.

We always try to use auto-update, so most of the time we're on the most recent version. We have some examples where we use Kerio Control aboard ships where the bandwidth is really limited. In those cases we use our own timeframe to update Kerio Control, but it's normally done within a month or two, so most of them are up to date.

We haven't seen anything yet in the antivirus and we haven't had any problems with malware with our systems. I don't know if malware is being detected that well, because sometimes the clients still have some malware. I don't know if it's because it's an HTTPS site or something else.

In our company, most of the work with Kerio is done by about 10 people. Everyone does the same tasks: administrating, changing rules, and installing new Kerios. I work on it in my role as a system admin team lead and developer. As of late, I've been more of a developer than administrator. The others are system administrators, business consultants, and there are two other developers.

Which deployment model are you using for this solution?

On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
reviewer1388148 - PeerSpot reviewer
CEO at a computer software company with 1-10 employees
Real User
The security has been very good and the VPN connections are reliable in that they stay up
Pros and Cons
  • "The most valuable feature is the reliability of VPN capabilities. The VPN has been very reliable and secure. The security has been very good and the VPN connections are reliable in that they stay up. We don't have a lot of problems with downtime and that type of thing."
  • "One of the problems we do have causes problems with the VPN. The software slows the throughput down too much. You could have a one-gigabit connection from the internet, and it slows it down to the area of upload and download is extremely slow. There's too much content filtering at that point."

What is our primary use case?

We have our server in our head office, so we have offices that log into it from various other cities and run their accounting software on it.

How has it helped my organization?

We have several offices in different provinces across Canada and because of that, the connection has been very secure and reliable. We haven't had any downtime with it other than when we had the NG100 fail. Other than that, it's made the connection to our websites, our office, and our eCommerce sites all very reliable. That's been very important.

What is most valuable?

The most valuable feature is the reliability of VPN capabilities. The VPN has been very reliable and secure. The security has been very good and the VPN connections are reliable in that they stay up. We don't have a lot of problems with downtime and that type of thing.

The comprehensiveness of the security features is extremely good. 

Kerio offers everything I need in one product. 

The firewall and intrusion detection features are good. We've had some intrusion attempts that were stopped. The firewall has been doing extremely well for attempted hacks, as well as working well with the intrusion protection.

The VPN features are good They have a solid VPN client, which we found to be extremely good and reliable on various operating systems. Other than that, the VPN has been good. 

Kerio is extremely easy to use. They're easy to install and pre-configure. If you have to do any maintenance it's well handled through the system. Remote connection, logging in, and doing changes on the system is extremely well handled.

We do use the failover in our head office. The failover is working extremely well. The last test on that was May of 2000 and 2020. The failover seems to be working well and the security has been good, so they've felt very confident in having it up and working as it's supposed to be. It's configured as per the instructions and it's working really well.

Kerio has enabled us to double the number of VPN clients extended to those outside of our environment. It started a little bit before the pandemic but just because some of the companies started to work more from home to cut down on costs. But since COVID that's where it shows it's doubled.

What needs improvement?

One of the problems we do have causes problems with the VPN. The software slows the throughput down too much. You could have a one-gigabit connection from the internet, and it slows it down to where the area of upload and download is extremely slow. There's too much content filtering at that point.

Quality control is another problem that needs to be handled better, particularly in the NG100 series. We have had to replace a couple of those. Other than that, the throttling down of the speed is too much. It is too heavy.

Other than that, I think they're good. 

For how long have I used the solution?

We first started with Kerio back in 2003.

We have an NG300, NG100, NG300W, and we still have a couple of 1120s.

What do I think about the stability of the solution?

Other than the quality of the NG100, stability has been extremely good.

What do I think about the scalability of the solution?

The scalability has been extremely well handled. We can very quickly figure out what size of a machine a customer needs and put it into position.

We have four people that do them, but usually, when we're shipping out, one person sets it up and then they deploy it remotely and have the customer follow their instructions remotely.

We don't have plans to increase usage because of the problems we have encountered with the company and the follow-up. We would have. We had quite a few of them, I don't know an exact count anymore because it's changed over but even now we've still got about 32 of them in use right now. But we've switched over probably triple that away from it.

How are customer service and technical support?

GFI's technical support is improving but at the very beginning, it was very bad. There was no way to contact them. When you did call, you didn't get returned messages. It is improving, but it's still not at a level where we're happy with it.

Which solution did I use previously and why did I switch?

We previously used SonicWall. We were looking for something that was really rock solid. We had a very bad experience with SonicWall and their support was very bad. We had a client that was down and they couldn't and didn't help us. We had to find something else in a hurry. 

One of our technicians had been reading up on Kerio so we brought one of their machines in and configured it. That's one of the first ones he did and he said that the setup was really good. He installed it and got the client back up and running, and then we started looking into it and found it was much better. Strangely enough, shortly after that, the sales rep we were dealing with at SonicWall left and he went to Kerio also.

Something that really bothers us about GFI, is that as a partner or a reseller, they believe that the customers belong to them. As a reseller, we take a lot of time building trust and confidence with our clients. We've been in business 30 odd years, and we still have clients with us that we took on back 30, 32, 37 years ago. They're still our clients, they deal with us, and they trust us. SonicWall did it and now GFI does it. They insist on all of the contact information for our customers if we sell them a machine. Then they start direct emailing them and our clients start saying, "I hired you to take care of this, why are these people sending me all this junk?"

Plus, we're in Canada and they send out this information and emails and it has U.S. pricing on it. They make a big deal about that it's only $100 or something, and then by the time we convert it to Canadian, we're looking at $135 and the clients forget that very quickly. It's very misleading to clients. Our customers don't like it. That's one of the other reasons that we're moving everybody from Kerio, because of what GFI's policy is of insisting on having all of our customer's names, addresses, phone numbers, emails, and everything else.

How was the initial setup?

The initial setup is pretty good. The guys are used to it now. They've done a fair number of machines and they're very used to it.

It has become familiar and they're consistent from one model to another. The instructions are straightforward and a good tech should have no problem with it at all. The thing is that they're not a home machine, they're for business. If it has a tech working on it is no problem at all. It's quite simple.

An average deployment takes two and a half hours. 

Network engineers set it up. Even one of our web developers has set up some of them. They have been very happy with training other people to do them. They don't have any problems. It's quite simple. The engineer was the first one to start working with Kerio back when we took them on, and he found that even in the beginning, from learning on his own, it only took him about four to eight machines to feel confident that he could do it without having to follow the instructions every time.

The size of the companies we work with vary. We call them medium-size, but some of them are only one location with 5 to 20 employees. We host a lot of our e-commerce systems and clients have those on their machines so that when the e-commerce inquiries come in, they go through that router. They become a medium-sized business very quickly because of the amount of business they're doing.

Kerio is a good solution for companies of this size. It comes down to the same thing, reliable, cost-effective, the VPN connections are good for the security between the e-commerce sites. Our eCommerce site is dynamic, so it's connected between the customers' inventory, warehousing, shipping, and billing system, directly to the e-commerce site. It makes it a lot tighter and more security is required because they are connecting directly to the customers' business machines, as well as just e-commerce hosted sites. Reliability and security are very highly needed because it does run their e-commerce sites. 

What was our ROI?

We see ROI through the ease of setup. We have a flat fee for configuring one, we charge for one before we ship it out for installation or go and install it. A customer pays the retail price, converted to Canadian at the current exchange rate, and that's what we charge the customer for the machine based on Kerio's MSRP. Then we charge them a flat rate for configuring it, which is two hours and we charge them for two hours labor. Then we charge them for whatever time it takes to do it remotely on-site, or if we're going on-site and having to install it, we charge for that time. If you charge for your time and the value, then you're going to make a good return on it.

But if you go in undercutting prices, something has to suffer. We have never had a customer say to us that they're upset because we haven't taken care of them if they have a problem with one of the Kerio devices. There have been issues, they're machines, they're going to break down. But we've never had a customer say that it wasn't taken care of properly by us. When we had SonicWall that was a problem, we took care of the customer, we couldn't get the machine that he should have had properly under warranty, so we just went and got him a different machine, put it in and got him up and going.

That's where we have to charge for it. We did charge the customer for that, but he felt that we provided the service he needed. It just gave him a very bad taste in his mouth because he couldn't get it under warranty. Undercutting prices, either in your services or your pricing of the hardware is what's happening now on the internet, we see that people are buying Kerio cheaper. We say to them "If you insist on buying it and want us to install it, we're going to charge you to install it, and if there's a problem with DOA or anything like that, dead on arrival, that's up to you." We hand it back to them and say this machine's got a problem, you have to get it fixed.

What's my experience with pricing, setup cost, and licensing?

The pricing is good. Our businesses have been around a long time and we've done that by not being the cheapest, but trying to be the best or one of the best. There's a lot of very good software and hardware companies out there, but a lot of them try to just undercut pricing and try to get the deal. We do not do that. We have a feeling we know what the value of our product is, if it's our own product. In a case where we have a router system, we know the value of it, we know what the value of the software licensing is for renewal and for the initial startup. We look at those things at the beginning, and we felt that Kerio was well in line. The price seems to be going up now, it hasn't gone up as bad as some of its competitors yet, but we'll keep an eye on that. Right now the pricing is valid for the product and the service they get.

Which other solutions did I evaluate?

We did look at and we're also an authorized Cisco reseller, but they're doing the same thing as SonicWall now. These big companies forget who puts all the work in. What they're trying to do, in my opinion, is get the little reseller to go out and hire the right people and go out and move their product, get them installed, and then they want to start going to them directly. I understand that smaller companies come and go but we've been here 37 years in total. They shouldn't go to our customers and start trying to direct sell to them and that type of thing. 

We were also a Dell reseller and we quit because we had to register every sale with them, and then they were going direct to the customers. It's not fair to the company that's gone out and done all the work.

What other advice do I have?

The machine is a good value for the price and the software is extremely good value for the price. It's proven out to be good, but we're just disappointed in the company that now owns it and took over from it. They're improving, but it took too long to improve and it cost us a lot of money in that way. But I can't blame it on Kerio, I have to blame it on GFS.

I would rate Kerio Control a nine out of ten. 

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
reviewer1363695 - PeerSpot reviewer
IT and Operations Manager at a financial services firm with 1-10 employees
Real User
Scalable with an easy initial setup but technical support is terrible
Pros and Cons
  • "The initial setup is a breeze."
  • "When it comes to dealing with updates, there are often bugs on the solution. They should do a lot more testing before they release new versions."

What is our primary use case?

We primarily use the solution on the VPN for protection purposes. We utilize its antivirus capabilities as well.

What is most valuable?

I really like their general IT.

I like how it's possible for me to block other countries immediately if I see the need to do so.

The initial setup is a breeze.

What needs improvement?

The support the solution offers needs a lot of improvement. GFI took over the product and since the takeover, the support, the backups, the after-sales support, etc., has basically dropped off quite a bit.

When it comes to dealing with updates, there are often bugs on the solution. They should do a lot more testing before they release new versions.

For how long have I used the solution?

I've been using the solution for about five years now.

What do I think about the stability of the solution?

The solution is very stable. Organizations won't have to worry about the solution crashing. I consider it to be very reliable. We have only had one firewall go down in the five years we've been using it, and I can't recall any other problems.

That said, when it comes to major updates, they need to do a lot more testing before they release things. Last year there had been a lot of bugs in major releases. It may have been because of the takeover. GFI has since taken over the brand.

What do I think about the scalability of the solution?

The solution is pretty scalable. I updated it about two years ago and I didn't have trouble scaling. A company shouldn't have any problems expanding it.

How are customer service and technical support?

Technical support is not the best. As an example, this past weekend I had an issue. It took me four days to get a hold of their support team. I'm a premium client. I tried everybody: America, Germany, UK, Africa. Everybody. That's unacceptable. There is no reason that their response should be that slow. In the past, I had managed to resolve issues quickly. That's not the case anymore. We're very dissatisfied with the level of service they are providing their clients.

Which solution did I use previously and why did I switch?

I've previously come across Barracuda. I've spoken to the team there. In terms of meeting our needs, I've found that, with a lot of other products, it's very modular. Kerio tends to keep everything in-house. Due to that, there are certain functionalities that I prefer to have with Kerio as opposed to other solutions.

How was the initial setup?

The fact that the setup is so easy is one of the solution's great selling points. It's straightforward. It's not complex at all.

It only takes one person to deploy and maintain the solution. The deployment itself only takes about an hour or two. Looking at the branches, it may just be 10-15 minutes of work for them. It's pretty quick. Of course, it depends on how many walls. A super basic setup is 10-15 minutes, however, if you have to put in a lot of rules, it will take longer because that process takes time.

What about the implementation team?

I handled the implementation myself.

What other advice do I have?

We're using the latest version of the solution.

I would recommend the solution. It doesn't take too many people to set it up or maintain it, like, for example, Cisco, which is a bit more complex and difficult.

I would rate the solution seven out of ten, and that's mostly due to the fact that their support is so awful right now. If their support was better and more reliable, I would rate them much higher.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free KerioControl Report and get advice and tips from experienced pros sharing their opinions.
Updated: July 2025
Buyer's Guide
Download our free KerioControl Report and get advice and tips from experienced pros sharing their opinions.