We are using Firewall Analyzer (AFA) to compare configurations from multiple firewalls, such as Cisco ASA, Palo Alto, Check Point, and so on. It helps us to streamline our firewall rules, identify risks, and provide better visibility. This product has significantly saved the time and human efforts in creating and deploying firewall rules. It is now easier for our cybersecurity team to analyze firewalls rules and ACLs, using them in a more efficient manner. Other features are also very important for us.
Consultant at HCL Technologies
During extreme load in business hours, it works well without any issues
Pros and Cons
- "It helps us to streamline our firewall rules, identify risks, and provide better visibility. This product has significantly saved the time and human efforts in creating and deploying firewall rules. It is now easier for our cybersecurity team to analyze firewalls rules and ACLs, using them in a more efficient manner."
- "This product has significantly saved the time and human efforts in creating and deploying firewall rules."
- "We are running multiple hybrid cloud solutions, working with cloud providers, and looking for API integrations with cloud and related interoperability. Sometimes, when we are trying to delete or disable any rule, it takes more time than expected."
- "Sometimes, when we are trying to delete or disable any rule, it takes more time than expected."
What is our primary use case?
How has it helped my organization?
With the help of this product, we can manage all the network security equipment in a centralized way. We are also able to make requests to our security team about quick and valid changes requests, helping to minimize the workload in documentation, troubleshooting and so on. This helps to identify any wrong or unnecessary changes in the network security perimeter, making sure that all security policies and best practices are followed in our network domain. During change implementation, and especially after completion, we can validate, make sure that everything is working fine, and is up-to-date per our expectations.
What is most valuable?
It’s capability to build and present entire network topology via map makes team members to easily investigate the entire domain. Whenever new applications and services get on boarded and traffic rules and policies being created it automatically discovered those Apps and services and makes life easy. Each and every performance report can be fully automated using this and saves time in audit and compliance requirement.It also helps us to clean old and obsolete rules or those rules which are not in use otherwise it could be very difficult without this product as team have to log into each firewall and remove rules and policies
What needs improvement?
We are running multiple hybrid cloud solutions, working with cloud providers, and looking for API integrations with cloud and related interoperability. Sometimes, when we are trying to delete or disable any rule, it takes more time than expected.
Sometimes, the web browser has issues with slowness. It can be worked out with a click or two.
Buyer's Guide
AlgoSec
May 2026
Learn what your peers think about AlgoSec. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
893,438 professionals have used our research since 2012.
For how long have I used the solution?
We are using Algosec Firewall Analyzer referred to as (AFA) since 2018.
What do I think about the stability of the solution?
This is very stable, robust product. During extreme load in business hours, it works well without any issues.
What do I think about the scalability of the solution?
It provides interoperability with all vendor firewalls and the scalability is much easier.
How are customer service and support?
Technical support is always good whenever we contact the support team. We always get an immediate response and a solution within defined timelines.
Which solution did I use previously and why did I switch?
Earlier we are not using any solution but always planning to procure solution that have ability to integrate multi vendor firewalls into single platform and after assessments and evaluations with OEM products we finally select Algosec as approved solution.
How was the initial setup?
Initial setup was very simple. Using Quickstart help, any member can take part in deployment and administration from basic to advanced level.
Only the firewall integration could take time due to some complex interactions.
What about the implementation team?
We implemented using our own internal team and with the help of AlgoSec technical support team. AlgoSec technical support was excellent and prompt.
What was our ROI?
It provides an improvement in the firewall process load. It also helps with increasing CPU and memory utilization.
What's my experience with pricing, setup cost, and licensing?
When it comes to the cost of support and licensing, it is much cheaper than other competing products.
Which other solutions did I evaluate?
We have tried FireMon and Tufin under a non-production environment, but the overall features of AlgoSec were best. Therefore, we choose this product for our production environment.
What other advice do I have?
Excellent product to use and has tremendous support from OEM.
We have not faced many problems or issues using this product.
We also have not tested AI or ML capabilities and are very keen to start working with it now.
Overall, it is well-maintained, robust platform tool for firewall management.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Resp. Area de Segurança at REN
AlgoBot checks if rules already exist or finds out easily where they need to be configured
Pros and Cons
- "AlgoBot is a brilliantly, simple idea that lets us give our IT internal customers a way to check if rules are already in place before asking for more."
- "AlgoSec has saved us a lot of time in managing our rule base which has become increasingly large."
- "The license rekeying needed for when you need to change a firewall usually takes a bit of time."
- "The only complaint is about the license rekeying needed for when you need to change a firewall. That usually takes a bit of time."
What is our primary use case?
Our main use cases for this solution are:
- Firewall Rule optimization
- Topology mapping of various firewalls
- Automating the implementation of rules.
- Reports warning before time based rules expire.
We also implemented the AlgoBot, which is extremely useful when checking if rules already exist or finding out easily where they need to be configured.
We have 20-plus firewalls from multi-vendors in several sites, both IT and OT. Therefore, an automated way to manage firewalls is a must, especially since staff is always on the short side.
How has it helped my organization?
AlgoSec has saved us a lot of time in managing our rule base which has become increasingly large. With 20-plus multi-vendor firewalls, it gets really hard to manage without a solution like AlgoSec. This has helped us to fulfill our internal SLAs for change implementation.
The fine tuning of the policies is a lot faster and repeatable.
The compliance factor has also helped us a lot where we can show auditing that we have a repository for all the changes made in the firewalls, who made them, and at what time.
Gone are the days where time-based rules expire without anyone noticing. We have now automated reports sent to the team. This allows us to ask the involved asset owners if rules can be disabled or need to be extended.
What is most valuable?
Most valuable features are the firewall rule optimization, topology mapping, and automating the deployment of new rules in several multi-vendor devices.
AlgoBot is a brilliantly, simple idea that lets us give our IT internal customers a way to check if rules are already in place before asking for more.
With firewall rule optimization, you cannot only tune most used rules higher in the rule base, but also check for unused objects or rules to clean up.
The automatic implementation of rules in several firewalls simultaneously is also a great feature, especially in large environments or on short staffed teams.
What needs improvement?
AlgoBot should be more developed by adding more features to the chat.
We will be integrating with Cisco ACI soon. Hopefully, new features with this integration will be developed as well in terms of automation.
I came across a difficulty recently with a BGP enabled firewall that had a large number of routes. This wasn't directly supported due to a 3000 rule per firewall limit.
For how long have I used the solution?
We've been using AlgoSec for over six years.
What do I think about the stability of the solution?
It has been running flawlessly since installation. Even upgrades are pretty straightforward and have never given us problems.
What do I think about the scalability of the solution?
We have added 10 more firewalls to our 14 existing and have had no performance or scalability issues.
How are customer service and technical support?
We have had several tickets opened and the responses were fast. This enabled us to solve our problems quickly. The only complaint is about the license rekeying needed for when you need to change a firewall. That usually takes a bit of time.
Which solution did I use previously and why did I switch?
We did use a different solution for several years. The features and usability made us switch.
How was the initial setup?
If you are knowledgeable about the firewalls that you intend to manage, the initial setup is really easy. The most difficult steps are configuring checkpoints for LEA integration where you need to create the object in each firewall, establish connectivity, install the database, install the policy, etc.
What about the implementation team?
It was initially implemented through a vendor. Their level of expertise was good enough to implement the solution effortlessly.
What's my experience with pricing, setup cost, and licensing?
Cost is based on firewall. There are bundles, e.g., virtual firewalls might make the solution cheaper.
The licensing scheme should be done in a simpler way. For example, if we delete a firewall and want to add a new one, then the license doesn't get freed up automatically. You have to request a new license to customer support and install it. If you are testing new implementations, this can be cumbersome.
Which other solutions did I evaluate?
We evaluated the main competitor, Tufin, because we were using it!
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
AlgoSec
May 2026
Learn what your peers think about AlgoSec. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
893,438 professionals have used our research since 2012.
MITP-2 at State of Nevada Department of Administration Message
Traffic queries help when troubleshooting a problem, especially if the traffic goes through two or more firewalls
Pros and Cons
- "Traffic queries are a great help when troubleshooting a problem, especially if the traffic is going through two or more firewalls."
- "Technical support is the best that I have ever dealt with."
- "The initial cost was high for us, but we have always been behind the tech curve and cost has always been the limiting factor."
- "The initial cost was high for us, but we have always been behind the tech curve and cost has always been the limiting factor."
What is our primary use case?
I am the senior network security engineer in an environment of more than 80 firewalls ranging from ASA 5506-X to ASA 5585-X and now to FortiGate 3960E. As part of this position, I need to be able to audit firewalls and ensure that they are compliant to a number of policies. Before AlgoSec, this was done in a very long, slow manual process, and it took days to audit even the smallest firewall. With AlgoSec, I can run a compliance report and see exactly where that firewall falls short.
How has it helped my organization?
AlgoSec has freed up my time to look into new solutions and complete other jobs that I have to get done. I have been able to shepherd the migration from Cisco ASA to FortiGate and using AlgoSec made that process much easier. Now, when I get a request for audit information, that information is available at a click. A PCI audit is no sweat. I know which firewalls fall under PCI, and I can provide the needed answers in minutes instead of days. This has improved my use of time.
What is most valuable?
Policy optimization, compliance, and change reports are the most valuable. I can clean up firewall rules quickly, optimizing the rule set and moving on in hours. Before, I was looking at days. Compliance is a breeze. The change reports are helpful to see changes over time and also be a "second set of eyes" when looking into issues.
The mapping tool is helpful.
Traffic queries are a great help when troubleshooting a problem, especially if the traffic is going through two or more firewalls.
What needs improvement?
I can't think of specific improvements. If anything, the product has been improving in usefulness constantly.
For how long have I used the solution?
I have been using AlgoSec Firewall Analyzer for approximately two and a half years now.
What do I think about the stability of the solution?
Product hotfixes are released regularly and are a breeze to install. I have dealt with other products that always promising to fix bugs, but it takes months or longer for the next patch to appear. AlgoSec is on top of this and in my opinion is a real leader with bug fixes.
How are customer service and technical support?
Technical support is the best that I have ever dealt with. I have yet to have a support engineer tell me that they couldn't fix a problem or that it was sunspots (Cisco TAC). They have gone above and beyond multiple times. I never hesitated to call as they have never made me feel that the problem is the user, even though I am sure that there were times it has been.
I have never had a problem that the technical support wasn't willing to dig into and get resolved.
Which solution did I use previously and why did I switch?
Not really. We used a homegrown VBScript that would parse the configurations on our firewalls for auditing. This didn't help at all with compliance.
How was the initial setup?
The setup is not difficult. The professional services were outstanding in installation and knowledge transfer.
What about the implementation team?
We implemented through a vendor team. Their expertise was outstanding. They made sure to spend a lot time doing knowledge transfer.
What's my experience with pricing, setup cost, and licensing?
The initial cost was high for us, but we have always been behind the tech curve and cost has always been the limiting factor. That attitude has changed. Now, we look for the best, not simply the cheapest.
Which other solutions did I evaluate?
We did look at a couple of other solutions. FireMon and Qualsys are the only two I remember.
What other advice do I have?
It has saved my bacon a number of times and is a great arrow to have in your quiver of tools.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Security Engineer at Chubb
Risky rules reports help to reduce manual work
Pros and Cons
- "We need less time to identify any risks in our firewalls, as we can detect changes in real-time."
- "It is a great tool that makes work easier each day."
- "A vulnerability management module might be interesting, though not integrated with a third-party vendor. It should be an AlgoSec VM module."
- "Some PDF reports are not so good. E.g., the graphics and reports are not so good."
How has it helped my organization?
We need less time to identify any risks in our firewalls, as we can detect changes in real-time.
We have obtained in easy way to do compliance reports for audit purposes. With this optimization reports, we can clean up unused rules, consolidate covered or redundant rules. We can also define trusted rules that apply.
Risky rules reports help to reduce manual work and identify the main risky configurations to remove. This give us some recommendations on how remediate and their importance.
What is most valuable?
- Identifying and removing risky rules
- Firewall rules cleanup (unused rules)
- Security compliance reports
- Security baseline settings
What needs improvement?
A vulnerability management module might be interesting, though not integrated with a third-party vendor. It should be an AlgoSec VM module.
I would like some server integration for vulnerability management.
Some PDF reports are not so good. E.g., the graphics and reports are not so good. Sometimes, we need to create graphics and reports to compare security ratings across months and groups.
For how long have I used the solution?
I have been using AlgoSec for two years.
What do I think about the stability of the solution?
Awesome.
What do I think about the scalability of the solution?
Great.
How are customer service and technical support?
Excellent and very kind technical support.
Which solution did I use previously and why did I switch?
No.
What's my experience with pricing, setup cost, and licensing?
Licensing is very easy to set up. The pricing is relative to how you want to expand and harden your network security.
Which other solutions did I evaluate?
I did not evaluate another solution.
What other advice do I have?
It is a great tool that makes work easier each day. I can't imagine working without AlgoSec and using it for my daily activities.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Network Engineer at a energy/utilities company with 1,001-5,000 employees
Automatically optimizes existing rule sets to comply with our security policy
Pros and Cons
- "This has helped to restrict rules, delete rules that are too permissive, and create a configuration that complies with our security policy."
- "This solution has improved our Security in our Firewalls."
- "There are sometimes issues with the Risky Rules reports where the number of hits is registering zero, but we know that this is incorrect because we have checked the rules and see that they are indeed registering traffic."
- "There are sometimes issues with the Risky Rules reports where the number of hits is registering zero, but we know that this is incorrect because we have checked the rules and see that they are indeed registering traffic."
What is our primary use case?
The primary use of this solution is to extract Risky Rules reports obtained from our Firewalls, check the rules, and proceed with changes on the Firewall as needed. In these reports, we also see the traffic being applied for different rules.
The traffic used for different Firewall rules can be obtained and then, we have a clear idea of the use for different rules. If some service or protocol is more often used or not, we can see.
We use the FireFlow tool to create the rule to be validated and applied in the appropriate Firewall. FireFlow can install the rule automatically.
How has it helped my organization?
This solution has improved our Security in our Firewalls. This has helped to restrict rules, delete rules that are too permissive, and create a configuration that complies with our security policy.
The reports are very useful for determining whether our Firewalls are compliant with our security rules and directives.
What is most valuable?
The feature that I've found most valuable is the risk classifications for different rules. The number of different risky rules that we have for each Firewall is determined automatically.
The traffic used or not for every service is very useful to check if some service is needed or not. In cases where it is not used, we can delete or disable it.
The FireFlow tool is very useful with the automatic installation of rules into Firewalls. It detects the router and applies the new rules, which saves us time in manual configuration.
What needs improvement?
There are sometimes issues with the Risky Rules reports where the number of hits is registering zero, but we know that this is incorrect because we have checked the rules and see that they are indeed registering traffic.
Sometimes the Trust setting on Firewall rules is changing to trusted by itself.
For how long have I used the solution?
I have been using AlgoSec for more than one year.
What do I think about the stability of the solution?
I have very good impressions of AlgoSec stability.
What do I think about the scalability of the solution?
The scalability is very good.
Which solution did I use previously and why did I switch?
I did not use another solution prior to this one.
Which other solutions did I evaluate?
I did not evaluate other options before choosing AlgoSec.
What other advice do I have?
Overall, I think this tool is very useful and we think that it's difficult to improve.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Networking Engineer at Schneider Electric
Reduces IT workload and improves efficiency using powerful API integration
Pros and Cons
- "It has reduced the workload for the firewall team thanks to the API integration with our ticketing system, handling the standard types of requests automatically."
- "It has reduced the workload for the firewall team thanks to the API integration with our ticketing system, handling the standard types of requests automatically."
- "It would be nice to have a good tool for network map discovery in the GUI to make it more user-friendly."
- "It would be nice to have a good tool for network map discovery in the GUI to make it more user-friendly."
What is our primary use case?
Our primary use for AlgoSec is to automate our firewall configuration. We use the AlgoSec system to remotely configure the firewalls, making our life easier.
We are in a multisite environment with plenty of firewalls for perimeter security and LAN segregation for specific proposes. This solution helped us to make the process more dynamic.
How has it helped my organization?
It has reduced the workload for the firewall team thanks to the API integration with our ticketing system, handling the standard types of requests automatically. Before having it, we had to create a lot of standard rules that now can now be just pushed from the AlgoSec system.
It has also helped in terms of firewall monitoring. Automatic alerts are sent to the security team so we can react quicker in case something goes wrong or a thread is detected going through the firewall. This is made possible using the simple reports.
What is most valuable?
The most valuable feature of this solution from an operations perspective is the automation of the firewall rule deployment, working together with our ticketing system.
Any new needs are requested by a user using the internal webpage request. This request is automatically validated against a set of standard rules. If the request is compliant, the new rule sets are automatically configured in the specified firewalls without any human action. This reduces the firewall team's workload and improves efficiency.
What needs improvement?
It would be nice to have a good tool for network map discovery in the GUI to make it more user-friendly. I would also like to be able to check and modify network maps in a graphical and more intuitive way. This will improve our network overview for new deployments and troubleshooting.
An API to connect to Palo Alto Prisma and Zscaler to be used after SD-WAN deployment would be a helpful feature. We have discussed this with AlgoSec and are hoping to see it in the near future.
For how long have I used the solution?
We have been using the AlgoSec solution for four years.
Which solution did I use previously and why did I switch?
We did not use a solution like this one previously. This is the first time.
What's my experience with pricing, setup cost, and licensing?
I'm part of the team that uses the AlgoSec solution, not on the finance IT team.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Cyber Security Specialist at Richemont
Improves visibility, automatically creates and optimized firewall rules
Pros and Cons
- "We met our goal by gaining visibility and automating rule creation."
- "We met our goal by gaining visibility and automating rule creation."
- "This solution would be improved if it were able to compare configurations and provide recommendations."
- "This solution would be improved if it were able to compare configurations and provide recommendations."
What is our primary use case?
Our primary uses for AlgoSec are to gain visibility and automate rule creation.
How has it helped my organization?
We met our goal by gaining visibility and automating rule creation. We are on a very good track.
What is most valuable?
The most valuable feature is the help of cleaning the firewall rules and object databases.
What needs improvement?
This solution would be improved if it were able to compare configurations and provide recommendations. For example, suggest cluster members.
For how long have I used the solution?
I have been using AlgoSec for four years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Technical and Integration Designer / Center of Excellence / Europe & Indonesia at Ahold Delhaize
Good reporting, improves efficiency, and simplifies troubleshooting
Pros and Cons
- "We now process FCRs much faster, which helps us to deliver faster and implement reworks at a quicker rate."
- "AlgoSec provided a much easier way to process FCRs and get visibility into traffic."
- "Creating more intuitive menus could be helpful, especially for first-time users."
- "Creating more intuitive menus could be helpful, especially for the first-time users."
What is our primary use case?
Firewall rule base management and FCR processing is the main reason we use AlgoSec.
We also use it for troubleshooting purposes and reporting. In that sense, there are three instances that are the main consumers of it. Our infrastructure management uses reporting to get insights, our Network and Security team does all of the FCR processing and troubleshooting of network problems, and our security department that also uses reporting and is part of the approval process for FCRs that are placed in AlgoSec.
How has it helped my organization?
AlgoSec provided a much easier way to process FCRs and get visibility into traffic. With previous vendors, we had to guess what was going on with our traffic and we were not able to act accordingly.
By automating some parts of the work, business pressure is also reduced since we now deliver much faster. I received feedback from our security department that their FCR approval process is also now much easier. The network team is also now able to process FCRs much faster and with more accuracy.
What is most valuable?
Most of all, Technical Reviews are now top-notch and AlgoSec does part of the job automatically that had been done manually with our previous vendor.
We now process FCRs much faster, which helps us to deliver faster and implement reworks at a quicker rate.
With Business Flow and Firewall Analyzer, it provides much better visibility into traffic and process flows. Visibility into traffic was our main problem in the past since we had no clue what was going on but now, we have all sorts of analyses and reports. This makes our decision process, firewall clean up, and troubleshooting much easier.
What needs improvement?
All of the search options needed are there but the search menu could be a bit more intuitive. In other words, I can perform any search I want without any problems but combining different search parameters can sometimes be a problem.
Creating more intuitive menus could be helpful, especially for the first-time users.
For example, it would be useful to be able to save searches with complex structure so they can be easily reused with simple change of parameter. Also, "contain" criteria sometimes misses just like ability to search using any value in basic search box, instead of reaching out to Advanced search (it would be great if simple typing IP address, or Project ID in basic search box lists all rules containing such a value).
For how long have I used the solution?
We have been using AlgoSec in production for about one year. Before that, we used it as a PoC for around six months.
What do I think about the stability of the solution?
We have had no issues in the past year.
What do I think about the scalability of the solution?
This solution is very scalable.
Which solution did I use previously and why did I switch?
We used another vendor prior to AlgoSec but we were not satisfied with the "intelligence" of the product when it came to the processing of FCRs.
Which other solutions did I evaluate?
We also evaluated Skybox.
What other advice do I have?
I have not seen any major issues with AlgoSec and it is better than the previous product we used. I am glad to have it now.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free AlgoSec Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2026
Product Categories
Firewall Security ManagementPopular Comparisons
Tufin Orchestration Suite
Fortinet FortiGate Cloud
Skybox Security Suite
FireMon Security Manager
Palo Alto Networks Panorama
Azure Firewall Manager
AWS Firewall Manager
ManageEngine Firewall Analyzer
Cisco Security Cloud Control
Fortinet FortiPortal
Opinnate
Cisco Secure Firewall Management Center
Buyer's Guide
Download our free AlgoSec Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- From your experience, what are the technical differences between AlgoSec and FireMon?
- What Is The Biggest Difference Between AlgoSec and FireMon?
- What are the differences between Palo Alto Networks Panorama and AlgoSec?
- What is the biggest difference between AlgoSec and Tufin?
- What is your opinion on Fortinet FortiManager vs AlgoSec? Are they complementary?
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Comparing network security vendors and devices
- When should companies use SSL Inspection?
- When evaluating Firewall Security Management, what aspect do you think is the most important to look for?
- What are the most important features you would be looking for in a firewall?










