We are using SecureChange to start orchestrating a lot of our changes. Our users can then request changes instead of having to go directly to us. We are trying to automate some of those pieces.
Network Security at a transportation company with 10,001+ employees
The change impact analysis capabilities of this solution are good
Pros and Cons
- "The visibility is very good. We have managers who are overseeing it, and they are approving things through it."
- "The hardest piece is getting the matrix built."
What is our primary use case?
How has it helped my organization?
The visibility is very good. We have managers who are overseeing it, and they are approving things through it.
The whole process is flexible and customizable. We are building the matrix, then we're putting in exceptions. We have to add manual exceptions into it, and they have to come to us first before they can get it approved, which is good.
We use this solution to automatically check if a change request will violate any security policy rules. Similar to what we are doing with Azure, where they request a change, and if it violates policies, it gets kicked back. Then, we have to review it and figure out what they're doing. We can then move forward with it, if it's approved.
What is most valuable?
- The Orchestration
- The way that users can access it directly.
- The change impact analysis capabilities of this solution are good.
What needs improvement?
- The hardest piece is getting the matrix built.
- Room for improvement includes how we are pulling the routing cables and getting SNMP enabled.
- Tufin could provide a train for running its reports and showing people how to use them.
Buyer's Guide
Tufin Orchestration Suite
April 2025

Learn what your peers think about Tufin Orchestration Suite. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
849,963 professionals have used our research since 2012.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
The solution is very stable. We've upgraded several times and not had any issues. For stability, it's perfect.
What do I think about the scalability of the solution?
We're in the process of scaling it. We started off small, and now, we're enlarging it to cover more of the enterprise. The scalability is good.
How are customer service and support?
I haven't used technical support. My colleague has, and they are very good. They work through solutions.
How was the initial setup?
The initial setup was pretty straightforward. It communicating with the firewalls and management server were the big pieces.
What about the implementation team?
Well when we first started, it was through a reseller. Then, as we're bringing in SecureChange, we have been doing it all that ourselves.
The reseller was Structured Communications, who is in Portland. It was part of a package deal that we built with them. Our experience with them was good. We used them a lot.
What was our ROI?
We don't have to go through our firewall group, who actually does the rules. They don't have to create tickets to send to us, then take a couple of days to get all that stuff built and put in place. Now, it is usually the same day, or within a day.
This solution helped us to reduce the time it takes to make changes. We used to spend up to an hour to do a change, and now, it's around five minutes.
Engineers are spending less time on manual processes. They are now spending half their time on manually processes, 20 to 30 minutes, because we don't have to go out and touch things anymore.
We're still in the process of implementing things, so we haven't really seen a lot of return yet, but we're hoping.
What other advice do I have?
It is a good solution, somewhat easy to implement, and gives you a lot of information. It takes time to learn all the little nuances of it.
I don't think we're using cloud native security quite yet.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Consultant at Critical Design Analytics
The change workflow process is very easy to customize
Pros and Cons
- "The change workflow process is very easy to customize. You can do a workflow however you want, so you can have an approval every single step. Or, you can remove approvals on certain steps, automating some steps."
- "We have had a couple issues with the VMs, but I think it was just because they were starving for resources. A recommendation on what the virtual appliances should have for resources would be appreciated."
What is our primary use case?
We implement Tufin for other customers and help set it up.
I'm not the end user. I just set it up for the end user.
We are using the latest version from 2018.
How has it helped my organization?
We use Tufin to clean up our firewall policies. They already have the compliance policies sort of prepopulated in there to point out violations.
Most customers will go through and check the USP to see if it violated with the designer tool.
We are in the process of working with a customer right now to set up the Unified Security Policy (USP). We got all the violations from the first phase and will go through to do the mediations, then run the scan again to show the progression of the clients.
What is most valuable?
The preconfigured PCI compliance USPs are the best part for me. These make things a lot easier.
The visualizer for the Network Topology is really good. You can see all the routes throughout your entire environment.
The change workflow process is very easy to customize. You can do a workflow however you want, so you can have an approval every single step. Or, you can remove approvals on certain steps, automating some steps.
It capabilities are very good.
What needs improvement?
Sometimes, the user interface is a little cumbersome, trying to navigate between them. In the new version, it looks like they resolved those issues.
What do I think about the stability of the solution?
We have had a couple issues with the VMs, but I think it was just because they were starving for resources. A recommendation on what the virtual appliances should have for resources would be appreciated.
What do I think about the scalability of the solution?
We have done PR strategies and added Tufin appliances. It is super easy to just back up and restore to a new one. You can get a new appliance up and running in 20 minutes.
How are customer service and technical support?
We worked with their professional support before, but we have not worked with their Professional services.
How was the initial setup?
The initial setup is straightforward.
What about the implementation team?
We are a reseller.
What was our ROI?
We've install it to make money.
Tufin does make the process faster for customers, depending on if they use SecureChange to automate their process. Everything is all in one then.
What's my experience with pricing, setup cost, and licensing?
Licensing is on a customer by customer basis.
What other advice do I have?
Try Tufin out. Make a PoC of it. That is how we sell most of our products because it works well.
Our customers do not have a hybrid network.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
Buyer's Guide
Tufin Orchestration Suite
April 2025

Learn what your peers think about Tufin Orchestration Suite. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
849,963 professionals have used our research since 2012.
Firewall Architect at a financial services firm with 10,001+ employees
Helps us tighten up our firewall policy, but reporting should include automation metrics
Pros and Cons
- "The automation piece is the most valuable feature: having SecureChange make the change on the firewalls, instead of my having to go manually make the changes on the vendor product."
- "We would like to see automation metrics, from a reporting standpoint. We would also like to see automation of site-to-site VPN tunnels. We would like to see automation of Check Point application-based firewall rules."
What is our primary use case?
Our primary use case is firewall automation. We use SecureTrack and SecureChange. We have distribution serves, Remote Collectors, but what we primarily use is SecureChange integrated with ServiceNow for users to submit firewall requests. They then go to SecureChange which designs the rules and implements them.
How has it helped my organization?
When it comes to the turnaround of firewall rule requests, it used to take about a week to implement and have the customer test for firewall access. Now, it can take just one day. The implementation itself takes a minute or two. For the customer, it may take the rest of the day, by the time that the policy is installed and the customer tests, either that evening or the next day.
While I'm not involved in the leadership, I believe the solution has helped us to meet our compliance mandates: from a firewall perspective, as well as an audit perspective, as well as review of the rules and source and destination port requests.
As for ensuring that security policy is followed across the entire hybrid network, we're getting there. That's part of why we implemented Tufin. We are implementing that across our multiple offices. Once we get to that state, it will ensure that security policy is followed.
Finally, using the solution, our engineers are spending less time on manual processors.
What is most valuable?
In general, the automation piece is the most valuable feature: having SecureChange make the change on the firewalls, instead of my having to go manually make the changes on the vendor product.
In terms of cleanup of our firewall policies, we don't officially use Tufin, but I, as an architect, do use the Automatic Policy Generator to review existing rules: high hit-count rules and open rules which aren't very secure. We use that to then build firewall rules which tighten up our firewall policy.
The change workflow process is flexible and customizable. We have had to edit and alter some of our workflow and it's pretty easy, pretty simple, pretty straightforward. We use Tufin support, their helpdesk, for that because we're a very new customer.
What needs improvement?
In terms of the visibility the solution provides, we have hits and misses with it. Overall, we think it works. We would like to get more automated, but that could be an issue internally with services and ports that we allow between different zones and our USP matrix. We're working with Tufin representatives to help solidify that and clean that up a little bit. That's one of the headaches and hiccups that we have right now: the full automation piece. We have automation to an extent, but we still have requesters who submit requests that still require approval, whether it be firewall leadership approval or cyber leadership approval. We want to determine what ports are allowed between the zones, as I mentioned, so that we can have full automation and there's no human interaction at all.
We would like to see automation metrics, from a reporting standpoint. We would also like to see automation of site-to-site VPN tunnels. We would like to see automation of Check Point application-based firewall rules. That's available on the Palo Alto side, but we are primarily a Check Point site on-prem. We have Palo Alto on the cloud but most of our on-prem stuff is from Check Point, so we're waiting for that. Those are some of the key things we're waiting for.
For how long have I used the solution?
We've been using Tufin for about four months.
What do I think about the stability of the solution?
My impression of the stability is positive. We haven't had any issues. We even went through an upgrade about a month ago and it was a smooth process.
What do I think about the scalability of the solution?
As for scalability, we're finding that out right now. We're building out two new Remote Collectors for our global deployment of an additional 150 to 180 firewalls, plus additional Layer 3 appliances. We're working through that right now. Hopefully, it will be a smooth transition but I can't say for sure because we haven't actually implemented it yet.
How are customer service and technical support?
I would rate tech support as "fair." Response time is a little slow, but when they do respond, and when time is available for them, we work through things pretty quickly to resolution.
How was the initial setup?
I wasn't involved in the initial setup, but from what I've heard from others from whom I took it over, it was very straightforward.
Which other solutions did I evaluate?
I know they reviewed other solutions but I don't know which, for sure, since I inherited the project. I would assume AlgoSec and FireMon were reviewed as well.
What other advice do I have?
Be as detailed as you can within your introductory meetings, and your planning and implementation phases, because if you don't mention something and it comes back later, you're going to have to work through it. That could take time, it could take extra money. You want to make sure, upfront, that you know everything you want to do so that it's all included in the cost for the Professional Services implementation.
We do use it on the cloud; we're having some trouble right now defining the network policy on our cloud. We're working through that; it's part of being a new client.
I would rate Tufin a seven out of ten. We're a very large, complex organization, so we're still working through some stuff that we focus on, things that, perhaps, other customers don't, or that Tufin doesn't have integrated in the TOS software.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Senior Specialist at Cigna
Allows non-technical people to keep track of firewall rules, but the API needs to be improved
Pros and Cons
- "Tufin is the only multi-vendor firewall tool that is available, and it helps to bring everything together and report on what all of the rules are."
- "I would like to see API access into every aspect of Tufin."
What is our primary use case?
My company primarily uses this solution for reporting and enforcing policy. My role has to do with developing applications to allow integration with our other tools.
How has it helped my organization?
When I was using Tufin for analysis, there was a tool that would tell me which rules could be consolidated. It was amazing and helped me to clean up the firewall policies.
We use this solution to automatically check to see if change requests will violate any security policy rules, but I do not have any specific details or examples.
Tufin is the only multi-vendor firewall tool that is available, and it helps to bring everything together and report on what all of the rules are.
This solution helps to ensure that security policy is followed across the network because it is the main tool that non-technical security people use to keep track of firewall rules. Without it, they wouldn't even know where to begin.
What is most valuable?
In my current role, the most valuable features are the API and the accessing. In my previous job, the analysis was my favorite.
What needs improvement?
I would like to see API access into every aspect of Tufin. For example, every feature and everything that's in the database, I would like to have programmatic access to. This would give me the ability to do anything that the product can do but from a script. This way, we are not beholden to the GUI in any way. If an operation requires that somebody click somewhere into the interface, manually, especially if it's just part of many other things that they have to do, then we want to fully automate that.
Some of the manual processes are taking longer because, without the proper API access, there are a lot of tickets coming in. These are from people who need to perform a task, but only a handful of them have access to it. This is because we're too afraid to give access to all of the people who actually need it.
What do I think about the stability of the solution?
In every instance that I've ever worked with it, it was stable.
How are customer service and technical support?
I have not dealt with technical support.
What about the implementation team?
In my previous company, I handled the deployment of this solution myself.
What's my experience with pricing, setup cost, and licensing?
Turning on certain options in the solution comes at an additional cost.
What other advice do I have?
My advice for anybody who is researching this solution is that if they are a larger company with a lot of money to spend, and they have a heterogeneous network with more than three different firewall vendors, then they absolutely need it. There is no competitor or really anybody who is even close.
For what this product does, it does well. There are, however, things that are missing.
Overall, I would rate this solution a seven out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Analyst at Equifax Inc.
Provides important visibility and saves us considerable time when making changes
Pros and Cons
- "The most valuable feature is that it extends security entries in the firewall policies."
- "I would like the ability to export information in other formats including PDF, HTML, or Excel."
What is our primary use case?
We use this solution for auditing our security and system access entries, then alerting us to problems.
How has it helped my organization?
The auditing reports generated by this solution help us to find issues.
This solution has helped us to meet our compliance mandates. We have very strict standards and security policies that we must follow. This tool is very flexible for the management team. It also helps us to ensure that our security policy is followed across our entire hybrid network, but we have a lack of security in some points.
What is most valuable?
The most valuable feature is that it extends security entries in the firewall policies. Given the number of entries in the access control, this would take a lot of time, so this feature is very valuable for us.
The visibility this solution provides us is great. At the moment, we are in the process of continuous improvement, and we need to include these new features.
The change workflow process is okay.
What needs improvement?
I would like the ability to export information in other formats including PDF, HTML, or Excel.
For how long have I used the solution?
We are still implementing.
What do I think about the stability of the solution?
The stability is very good. It's better than the other tools that we have in the company.
What do I think about the scalability of the solution?
To this point, we have only used the basic functionality. We have several teams working with the tools.
How are customer service and technical support?
Technical support for this solution is excellent. At the moment, we have very good communication with support.
How was the initial setup?
The initial setup was good and we had no trouble with it.
What about the implementation team?
We handled the deployment of this solution internally.
Which other solutions did I evaluate?
We did not evaluate other solutions before choosing this one.
What other advice do I have?
This tool is excellent in the specific areas where it is applied. We are spending less time on manual processes and at some point, we will be stopping them.
This solution definitely helps to reduce the time it takes to make changes. With other tools, I have spent five or six hours or even days, but with this solution, it takes me thirty minutes. It can take even less, depending on the complexity of the firewall.
My only complaint is that I would like to be able to export data to different formats.
I would rate this solution a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IT Manager at a financial services firm with 10,001+ employees
Valuable reporting helps us to satisfy our audit requirements
Pros and Cons
- "The most valuable feature is the reporting of our risk poster in our firewall."
- "I would like to see improved role-based access."
What is our primary use case?
Our primary use case for this solution is risk visibility.
How has it helped my organization?
We use this solution to clean up our firewall policies.
Prior to using this solution, and according to our best practices, we didn't have a baseline of the security poster that we have with our rule sets. Now, with this reporting, we're able to provide that to our management.
It has helped us meet your compliance mandates. We are getting this from the data and reports. This was one of our requirements.
What is most valuable?
The most valuable feature is the reporting of our risk poster in our firewall. We clean up our firewall rules using this solution. The reporting helps us carry this out quickly.
This visibility is good and I would say that the change workflow process is average to good.
We expect that SecureChange will help us to reduce the time it takes to make changes. It is on our roadmap.
What needs improvement?
The reporting still has a lot of improvements to be made.
I would like to see improved role-based access.
For how long have I used the solution?
We are still implementing.
What do I think about the stability of the solution?
For us, this product has been very stable. We don't have any trouble with it.
What do I think about the scalability of the solution?
Our deployment is quite small, so I cannot speak to the scalability yet.
How are customer service and technical support?
Technical support for this solution needs improvement. We usually get a callback from an engineer, but the escalation of support should be faster.
Our account manager at Tufin is very engaged and has been super helpful.
Which solution did I use previously and why did I switch?
Adopting this solution was an easy decision for us because it is an audit requirement.
How was the initial setup?
The initial setup of this solution is straightforward. Installing SecureTrack was not difficult, after browsing through the knowledge base. With the documentation that is available, it is easy to deploy.
What about the implementation team?
We implemented this solution ourselves.
What was our ROI?
We have not yet seen ROI, but when we go with the SecureChange model, we will automate and reduce overtime hours. At this point, we will see a very valuable return on investment. For the time being, it is on our roadmap.
Which other solutions did I evaluate?
We did evaluate other solutions before choosing Tufin. This solution is used by many large companies, which is one of the reasons that we selected it.
What other advice do I have?
There is always room for improvement, but with the performance and the day to day stability that we have, I think that it's a very good product. Overall, I am very happy and satisfied with the product, and I am looking forward to a lot of new features.
I would rate this solution an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Manager at a manufacturing company with 10,001+ employees
Enables us to automatically check if a change request will violate any security policy rules but they should get rid of the REST APIs
Pros and Cons
- "The change workflow process is flexible and customizable. We have one guy who has never logged into Tufin ever in his life. He sits down and in 30 minutes had written an automation routine, then went back and changed it. He did that with no training. For me, that is a major benefit."
- "I would like to see them get rid of the REST APIs and use something more modern."
- "I would also like to see them do more cloud integration within the Tufin Orchestration Suite, not within a SaaS solution."
What is our primary use case?
Our primary use case is for automation and orchestration.
How has it helped my organization?
We use Tufin to automatically check if a change request will violate any security policy rules. One of the things we want to do is to have a blacklist/whitelist policy. A blacklist of things that can never be allowed and a whitelist of things which are always allowed. I want this tool to block or report ports that should not be used, putting somebody in a change. In addition to that, I want it to be able to block people from mapping IP addresses in North Korea, Iran, or whatever is on the blacklist.
Our corporate policy mandates that we can only make changes to our firewalls daily. Once we get ServiceNow integrated with our whitelist policy, Tufin should be able to initiate the change and get us to reduce time.
It should help us meet our compliance mandates going forward. It is replacing AlgoSec.
What is most valuable?
The ease of use is the most valuable feature.
The change workflow process is flexible and customizable. We have one guy who has never logged into Tufin ever in his life. He sits down and in 30 minutes had written an automation routine, then went back and changed it. He did that with no training. For me, that is a major benefit.
The two reasons that we wanted Tufin
- The single pane of glass, so our Tier 1 and Tier 2 could make changes.
- The network mapping which is something that we have never had before.
What needs improvement?
- I would like to see them get rid of the REST APIs and use something more modern.
- I would also like to see them do more cloud integration within the Tufin Orchestration Suite, not within a SaaS solution.
- I would like them to move their community support off of Google and onto something more long-term.
For how long have I used the solution?
Less than one year.
What do I think about the stability of the solution?
So far, stability has been good.
What do I think about the scalability of the solution?
It has already pulled in all our Layer 3 switches and routers across the company.
I don't know if I can expand on the cloud yet.
How are customer service and technical support?
We bought premium support. I have heard from my team that they are great.
Which solution did I use previously and why did I switch?
We switched from AlgoSec because they had horrible customer support, and difficult change management and processes.
How was the initial setup?
The initial setup was very straightforward. It was done in five days, which is pretty cool.
What about the implementation team?
We used Tufin for the deployment. We had a positive experience with them.
Which other solutions did I evaluate?
We compared AlgoSec, Tufin, and Skybox side-by-side. Originally, the team chose Skybox. They threw in what a lot of other groups had wanted, like the network team, security team, and DevOps team. When I sat them down (because I voted Tufin), I asked them why and they gave me all of the explanations that were all somebody else's reasons, not ours. I told them that this tool is for us and we needed a true orchestration automation tool. Not one that supports everyone else's automation, and we need one for firewalls.
What other advice do I have?
I would rate it a seven out of ten.
I would advise someone considering this type of solution to not listen to the sales teams among the competitors. They all throw each other under the bus and a lot of it is not true. Tufin's competitors will tell you how bad of a company that Tufin is and how you can't trust them, and how their stuff doesn't work. Then, Tufin doesn't say anything bad about their competitors. So, don't trust everything that you hear.
Do your own research. Do a proof of concept. Get all of the vendors in. Give it a month to test drive. Set it up and let them prove it out. In the end, the correct tool, not the better salesman, will win.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Sr. Security Administrator at a consultancy with 1,001-5,000 employees
Most of the valuable features have to do with the reporting and the cleanup of policy.
Valuable Features
A lot of the most valuable features have to do with the reporting and the cleanup of policy. With our day-to-day busy lives, we just want to get the change in and implement it, and that just increases rule base exponentially. From time to time you need to go back and find duplicate services, objects, rules, and cleanup. With a lot of the cleanup effort, I think the product helps out a lot.
Tracking changes is beneficial. We get alerted immediately who made the change, what change was made, and things like that. That's probably the most valuable.
Room for Improvement
It is important to keep up to date with the vendors you support. For example, Palo Alto, CheckPoint, Cisco, F5, and so on. They should make sure that Tufin supports the latest version of those products.
We upgraded to R80 two months ago, and our Tufin product hasn't been working. It's because there's no support for R80. We're hoping that Tufin supports R80 soon so we can start getting all the changes. If a vendor upgrades to a certain version, Tufin needs to provide support fairly quickly.
Also, our 20/20 vision is to be in the cloud wherever we can. Cloud first. If Tufin had any kind of management in the cloud, that's one less piece of hardware to manage in-house. Being in the cloud would definitely provide that extra missing feature.
Use of Solution
We've had it for about 3 or 4 years now.
Stability Issues
We have not had any stability issues at all. Upgrading has been simple, no issues at all.
Scalability Issues
It is scalable. We manage about 150 firewalls. There are no issues at all.
Customer Service and Technical Support
The support portal has been quick. I actually emailed them about R80 support, and they were really fast at letting me know that it's coming in mid-2016.
Other Solutions Considered
Along with a colleague of mine, I was involved in the decision to start using Tufin a few years ago. We compared it to AlgoSec and a couple other vendors. Tufin seemed to meet our requirements at the time. Before our renewal, we are looking to re-evaluate what all the vendors have to make sure we are getting the most out of the product.
Other Advice
It's a great product. It's pretty straightforward to use. It meets our needs and great support overall.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Tufin Orchestration Suite Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2025
Product Categories
Firewall Security ManagementPopular Comparisons
FireMon Security Manager
Skybox Security Suite
Palo Alto Networks Panorama
AWS Firewall Manager
Azure Firewall Manager
ManageEngine Firewall Analyzer
Cisco Security Cloud Control
Buyer's Guide
Download our free Tufin Orchestration Suite Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between AlgoSec and Tufin?
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Comparing network security vendors and devices
- When should companies use SSL Inspection?
- When evaluating Firewall Security Management, what aspect do you think is the most important to look for?
- What are the most important features you would be looking for in a firewall?
- How do I estimate the required firewall throughput for my organization?
- What are the pros and cons of Tufin, AlgoSec and RedSeal?
- Tasks to Perform on Preventive Maintenance.
- Why is network segmentation important?