IT Manager at a financial services firm with 10,001+ employees
Real User
Helps us meet our compliance mandates and has excellent visibility
Pros and Cons
  • "It has helped us to meet our compliance mandates. We have some requirements that we need to provide more visibility on the risk levels of our firewall base and Tufin helped us with that requirement."
  • "I would like to see an improved reporting model that can be flexible for us to generate our own reports. The data's already there."

What is our primary use case?

Our primary use case if for risk compliance. 

How has it helped my organization?

The change workflow process is flexible and customizable. 

It has helped us to meet our compliance mandates. We have some requirements that we need to provide more visibility on the risk levels of our firewall base, and Tufin helped us with that requirement. 

What is most valuable?

The USB is the most valuable feature for us. Inside of Tufin, we are planning to leverage the USB solution.

The visibility is excellent. We have a better view of our compliance status. 

What needs improvement?

I would like to see an improved reporting model that can be flexible for us to generate our own reports. The data is already there. 

Buyer's Guide
Tufin Orchestration Suite
April 2024
Learn what your peers think about Tufin Orchestration Suite. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
771,212 professionals have used our research since 2012.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

It has been very stable since 2017. We haven't had any power problems. As far as hardware goes, it's been very stable. In the software, we found some bugs, but we're working with support to fix them.

What do I think about the scalability of the solution?

Scalability is very good. We are planning to add more entities this year. 

How are customer service and support?

Technical support is satisfactory at the moment. 

How was the initial setup?

The initial setup was very straightforward. 

What about the implementation team?

We did most of the onboarding ourselves. 

Which other solutions did I evaluate?

We also looked at AlgoSec. 

I was part of the decision-making process.

What other advice do I have?

I would rate it an eight out of ten. It's very easy to use and you can get good results very quickly. 

We don't use the cloud native security features yet.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Manager at a manufacturing company with 10,001+ employees
Real User
Enables us to automatically check if a change request will violate any security policy rules but they should get rid of the REST APIs
Pros and Cons
  • "The change workflow process is flexible and customizable. We have one guy who has never logged into Tufin ever in his life. He sits down and in 30 minutes had written an automation routine, then went back and changed it. He did that with no training. For me, that is a major benefit."
  • "I would like to see them get rid of the REST APIs and use something more modern."
  • "I would also like to see them do more cloud integration within the Tufin Orchestration Suite, not within a SaaS solution."

What is our primary use case?

Our primary use case is for automation and orchestration.

How has it helped my organization?

We use Tufin to automatically check if a change request will violate any security policy rules. One of the things we want to do is to have a blacklist/whitelist policy. A blacklist of things that can never be allowed and a whitelist of things which are always allowed. I want this tool to block or report ports that should not be used, putting somebody in a change. In addition to that, I want it to be able to block people from mapping IP addresses in North Korea, Iran, or whatever is on the blacklist.

Our corporate policy mandates that we can only make changes to our firewalls daily. Once we get ServiceNow integrated with our whitelist policy, Tufin should be able to initiate the change and get us to reduce time.

It should help us meet our compliance mandates going forward. It is replacing AlgoSec.

What is most valuable?

The ease of use is the most valuable feature. 

The change workflow process is flexible and customizable. We have one guy who has never logged into Tufin ever in his life. He sits down and in 30 minutes had written an automation routine, then went back and changed it. He did that with no training. For me, that is a major benefit.

The two reasons that we wanted Tufin

  1. The single pane of glass, so our Tier 1 and Tier 2 could make changes.
  2. The network mapping which is something that we have never had before.

What needs improvement?

  • I would like to see them get rid of the REST APIs and use something more modern. 
  • I would also like to see them do more cloud integration within the Tufin Orchestration Suite, not within a SaaS solution. 
  • I would like them to move their community support off of Google and onto something more long-term.

For how long have I used the solution?

Less than one year.

What do I think about the stability of the solution?

So far, stability has been good. 

What do I think about the scalability of the solution?

It has already pulled in all our Layer 3 switches and routers across the company.

I don't know if I can expand on the cloud yet.

How are customer service and technical support?

We bought premium support. I have heard from my team that they are great. 

Which solution did I use previously and why did I switch?

We switched from AlgoSec because they had horrible customer support, and difficult change management and processes. 

How was the initial setup?

The initial setup was very straightforward. It was done in five days, which is pretty cool.  

What about the implementation team?

We used Tufin for the deployment. We had a positive experience with them. 

Which other solutions did I evaluate?

We compared AlgoSec, Tufin, and Skybox side-by-side. Originally, the team chose Skybox. They threw in what a lot of other groups had wanted, like the network team, security team, and DevOps team. When I sat them down (because I voted Tufin), I asked them why and they gave me all of the explanations that were all somebody else's reasons, not ours. I told them that this tool is for us and we needed a true orchestration automation tool. Not one that supports everyone else's automation, and we need one for firewalls.

What other advice do I have?

I would rate it a seven out of ten. 

I would advise someone considering this type of solution to not listen to the sales teams among the competitors. They all throw each other under the bus and a lot of it is not true. Tufin's competitors will tell you how bad of a company that Tufin is and how you can't trust them, and how their stuff doesn't work. Then, Tufin doesn't say anything bad about their competitors. So, don't trust everything that you hear. 

Do your own research. Do a proof of concept. Get all of the vendors in. Give it a month to test drive. Set it up and let them prove it out. In the end, the correct tool, not the better salesman, will win.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Tufin Orchestration Suite
April 2024
Learn what your peers think about Tufin Orchestration Suite. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
771,212 professionals have used our research since 2012.
Security Engineer at Allegiant Air
Real User
The revision reports are phenomenal, as they really help us to see what was changed and when
Pros and Cons
  • "Tufin is our audit trail for all changes. We have to be PCI compliant, and it's the tool we go to for enforcing PCI on the network side."
  • "I would like to see more expansion into the cloud and documentation needs improvement. When I try to do something new in the product, the documentation is no help. Something's written there, but it's not enough to help you do what you want to do."
  • "The policy browser has had trouble working. We have experienced bugs."

What is our primary use case?

We use Tufin for two purposes: 

  1. To track all changes on our network equipment, our Cisco gear, F5s, and Check Point. 
  2. We use SecureChange. So, we submit any firewall change through SecureChange, then we use that for the approval process. We are trying to have it end-to-end, where it provisions the device, but we're not there yet. 

How has it helped my organization?

Tufin is our audit trail for all changes. We have to be PCI compliant, and it is the tool that we go to for enforcing PCI on the network side.

The change workflow process has customizable and functional for us.

It has helped us meet our compliance mandates.

What is most valuable?

The revision reports are phenomenal. They really help us out to see what changed, when, and who, most importantly. Some of the other reporting that we audit and clean up have been really valuable for us. 

The visibility is great. We have found the policy browser to be very useful. It is a fairly new feature. 

What needs improvement?

I would like to see more expansion into the cloud and documentation needs improvement. When I try to do something new in the product, the documentation is no help. Something's written there, but it's not enough to help you do what you want to do. We would like more examples and use cases.

The cloud is fairly new to Tufin. We have AWS. Their first steps into providing audits on the cloud have been really helpful, but we ourselves don't know how we're going to manage the cloud. One of the features that we didn't like is the controlling of the security groups. We can read them but there's no way to change them or to really control them through Tufin. That would be a nice addition.

We are currently working on a bunch of automation to include Tufin. We need security group management (security group modification for Cisco devices). That is what we need from Tufin going forward. We can't go live with the total automation because there are pieces missing, e.g., you cannot update the service group.

What do I think about the stability of the solution?

It has been very stable. Though, the policy browser has had trouble working. We have experienced bugs.

What do I think about the scalability of the solution?

We have a lot of devices on it now.

How are customer service and technical support?

The technical support is hit or miss. More miss than hit. It takes them awhile to understand what the issue is. They don't know where to go in the product right away. A lot of stuff gets escalated to R&D, and even that is a very slow process. When it goes to R&D, it's really slow. We've had the same issue for months. They say it'll be fixed in the next release, then we'll get the next release, and it's even worse.

What about the implementation team?

We deployed it ourselves.

What other advice do I have?

We are really interested in the Tufin Orca product.

  • For visibility in the network, I would rate the product as a nine out of ten. 
  • For usability, I would rate the product as a seven out of ten. 
  • For liability, I would rate the product as a nine out of ten. 
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Network Security at a tech services company with 5,001-10,000 employees
Real User
We can have automated reports, even with security and compliance
Pros and Cons
  • "We can get reports with Tufin at anytime. We can have automated reports, even with security and compliance."
  • "I would like to simplify the reports, and maybe have another view besides the charts. Possibly they could be more graphical."

What is our primary use case?

The primary case is to get more compliance and security with good performance. We use Tufin to use some Check Point products. The product is for the way we manage our security, performance, and boxes.

How has it helped my organization?

The change impact analysis has been very good. We continue to improve. 

The change workflow process is flexible and customizable. Right now, we are using SecureChange, which is improving the rules that get applied to Check Point.

We use the solution to automatically check if a change request will violate any security policy rules by generating a Sunday email report in these type of situations.

Using the Tufin reports, for internal and external audits, is a way we can demonstrate how we made compliance. After any of the observation that we get from the audits, we just run the reports one more time to see if our changes are being successfully applied and everything is working according to the requirements.

Tufin has been very helpful to get a lot of groups changed and getting all the information inputted on a tool, then later to applied on the device. 

What is most valuable?

We can get reports with Tufin at anytime. We can have automated reports, even with security and compliance.

The visibility is very good, as it incorporates graphics with some charts and comparisons. So, we have very good visibility for the entire tool.

What needs improvement?

I would like to simplify the reports, and maybe have another view besides the charts. Possibly they could be more graphical.

I would like to see them continue improving the versions.

For how long have I used the solution?

Three to five years.

What do I think about the stability of the solution?

The stability has been improved, even person by person. It is even stronger in a way.

What do I think about the scalability of the solution?

The scalability is according to performance that we are experience. Therefore, we are getting more devices on this tool, so it has been very helpful for us.

How are customer service and technical support?

I haven't used their technical support.

How was the initial setup?

The initial setup was very simple. We could obtain deep knowledge information from Tufin's knowledge base (KB).

What was our ROI?

The solution has helped us to reduce the time it takes to make changes. With Tufin, it takes ten to 15 minutes. Before, it was 30 minutes or more.

What other advice do I have?

I would recommend Tufin. They are very helpful for IT organizations, as they continue improving SecureChange.

With our security plan, we can see how Tufin meets the basic requirements. Then, we can go and customize if there is any risk, which might be interfering with ports or external networks.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Security Engineer at BCBSMA
Real User
Enables us to perform self-audits and use rule-based accountability
Pros and Cons
  • "The most valuable features are the Security Risks and Best Practices reporting/Rule base cleanup."
  • "I feel that the user interface is a bit dated."

What is our primary use case?

Our primary use case for this solution is for audit and firewall rule base management. 

How has it helped my organization?

Tufin allows us to perform self-audits and use rule-based accountability. 

What is most valuable?

The most valuable features are the Security Risks and Best Practices reporting/Rule base cleanup.

What needs improvement?

I feel that the user interface is a bit dated. The product version updates should be automated, and the reports could be a bit cleaner.

For how long have I used the solution?

More than five years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior Information Security Architect at First Citizens Bank
Real User
Provides a single pane of glass to see what all our different policies are doing
Pros and Cons
  • "One of the main things is to look at what policies haven't been hit, so we can remove those remnant policies when people come in, use it, and it's still left on the Check Point. So when a couple of users say, "This is not needed anymore." We'll remove it."
  • "We like the change impact analysis capabilities quite a bit. The only weakness is that the reporting is a bit clunky. We would like to have the reporting be better."

What is our primary use case?

We use it to manage our policies, consolidate them, and if we see anything missing, we can use it to track that, as well.

Right now, we're mainly on-premise. S,o the cloud piece is not being used right now. However, in the future, we will use it. I think it will help tremendously to get a good picture across the board.

How has it helped my organization?

One of the main things is to look at what policies haven't been hit, so we can remove those remnant policies when people come in, use it, and it's still left on the Check Point. So when a couple of users say, "This is not needed anymore." We'll remove it.

What is most valuable?

The capability to manage: We have different domains, so we want to have a single pane of glass to see what all the different policies are doing.

What needs improvement?

We like the change impact analysis capabilities quite a bit. The only weakness is that the reporting is a bit clunky. We would like to have the reporting be better.

Right now, it is being used retroactively. There was talk with the rep this morning that they can do this proactively. In other words, we see the policy, and if it's not needed, then it can be removed, or add new policies, as needed.

What do I think about the stability of the solution?

We feel that it is a very good solution. So, we'll probably use it going forward.

What do I think about the scalability of the solution?

This is one of the things that we do like about the solution, which is why we went with it.

How are customer service and technical support?

The technical support has been very good. I would like it to be a little faster, but it's good.

How was the initial setup?

There were some hiccups in the initial setup. In using the new features, there was a learning curve. However, for the most part, it was fairly straightforward.

What about the implementation team?

We hired people that have done the deployment in the past. So, we did it all ourselves.

What was our ROI?

Manually looking at the policies is very time-consuming. With this product, I think we've streamlined the process tremendously.

Which other solutions did I evaluate?

We like the visibility. That's why we went with this solution over other competitors.

What other advice do I have?

It does what it needs to do for our needs.

We are in the process of doing a PoC for the new changes.

Currently, it's all reactive. We do the changes, then we review it at a later time.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user489246 - PeerSpot reviewer
Network Engineer at a financial services firm with 10,001+ employees
Vendor
Helps us with troubleshooting to find out what changed. Patching and speed are issues.

Valuable Features

The governance feature is handy in the process flow. Tufin is easy for an average user to be able to put in their request and have it automatically assigned to other firewalls.

We are able to review changes from the previous day to be able to compare if there's a change that goes in from one day to the next, if there's an issue, we can see what change has occurred. You can see that through the reporting. It's quick to go and pull up what changed between the two days. It works great for the users to be able to put it in. And then troubleshooting afterward if something happened to find out what had changed.

Improvements to My Organization

It has come a long way. Compared to where we were, it's significantly better. We were using an internal process that was intensive. This is clearly better.

Room for Improvement

From my limited use of it directly as a user, I don't think it's efficiently comparing. We were looking for a 2 of 3 match that haven’t used the same rule, and it's not working as well. It's adding additional rules into our policy at times. It could be more effective than that. I’d like it to add fewer rules but still keep the same security posture.

We’ve also had issues with speed, and it needs to be a bit more reliable. It's definitely slows up. Sometimes, just when I log in, it didn't connect me to the system or we've had to do some emergency patches on it and it would take 10 or 15 minutes to get logged in. That was kind of weird and that's happened a couple times. I think it is user-friendly, outside of the things our own internal people have added and made it a little confusing.

I think the app could be a little bit improved in the way that it selects objects.

Stability Issues

From my user perspective, I think patching is an issue. I haven't done it, but I know they had to. It got slow, and there were issues getting connected in to it. Everything was running slow a few different times. We’ve had to contact support. There's been times we've lost a day and a half of usage.

Customer Service and Technical Support

I have not had to use technical support.

Implementation Team

I was not part of the implementation.

Other Advice

It works well. It’s something you would send a colleague to use. It gives a nice process flow as far as the end user putting something in, having governance check, and being able to have multiple work screens because we have different areas of the company and different processes. They have to have different work flows. We use multiple work flows. That's handy. You can build those in, you select from the beginning and then you're off and running.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user489336 - PeerSpot reviewer
Network Security Engineer at a hospitality company with 1,001-5,000 employees
Vendor
The most valuable feature that I've found is rule optimization. Another benefit is the complete set of all rules.

Valuable Features

The most valuable feature that I've found is rule optimization. If the rule has massive hits and if I want to remove that rule, I can put that rule into the SecureTrack change. After a few weeks, it will tell me that these are all the IP addresses that it is hitting, and this is all the traffic that it is hitting. It provides all sorts of other information too. That's one of the features that I like in Tufin.

Having total compliance is a benefit. When our compliance department tells that there is a rule that says IP such-and-such, and that we have to remove that rule, it’s never easy for us to directly remove a rule until and unless we have some traffic analysis and so on.

Another benefit is the complete set of all rules. If I have to find a particular object, Tufin provides a search feature. That's one of the good features in Tufin. If you have more than 100 or 200 firewalls and 100 or 200 policies, and each and every policy has a humungous amount of rule numbers, it can give you detailed reports, as well as the search feature.

Room for Improvement

I would like to see improvements in historic views of rules - stating that this rule hasn't been used for the past one year, that this rule hasn't had much hits, these are all of the shadowed rules and these are all of the unshadowed rules - so we can narrow down the rule base. That's probably one of the aspects that I would like. If Tufin can help me out with that, that would be nice too.

It needs improvement with rule optimization and compliance.

Tufin product is good, but it requires a lot of CPU overhead. It might be because of the rule base we have. It might be due to other factors, but it's kind of slow for us. I would like to see an improvement in speed, as well.

Stability Issues

It's been stable. No complaints yet, except for the upgrade. The upgrade takes a little long, but that's fine. I believe that’s because of the vastness of our environment.

Scalability Issues

We probably have more than 2,000 rules for each and every policy. It depends, 1,000 rules, 2,000 rules, somewhere in between. We have a pretty massive rule base, and it's giving good reports.

Customer Service and Technical Support

Involvement with the technical support team went well. They are cooperative.

Other Solutions Considered

We also use AlgoSec for analysis.

Other Advice

It all depends upon the environment that you’re using. Compare it to other vendors, like FireMon and AlgoSec, and then you can rate the products and decide what to use and what not to use.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Tufin Orchestration Suite Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2024
Buyer's Guide
Download our free Tufin Orchestration Suite Report and get advice and tips from experienced pros sharing their opinions.