No more typing reviews! Try our Samantha, our new voice AI agent.
PeerSpot user
Network Technical Security at a tech services company with 501-1,000 employees
Consultant
Feb 18, 2017
Traffic simulation queries identify all firewalls involved in the path between a source and a destination on a given service.
Pros and Cons
  • "We can optimize and produce reports for 744 firewalls from different vendors (Check Point, Juniper, FortiGate, and Cisco) with one application."
  • "AlgoSec doesn’t recognize those loopbacks as a route, so it doesn’t find a route to the destination. This behaviour makes the traffic simulation query feature unusable in our environment."

What is most valuable?

  • Traffic simulation queries allow an engineer to simply find all firewalls involved in the path between a source and a destination on a given service. AlgoSec allows an engineer to issue their own traffic simulation query to be tested against a single device's policy, or against a group of devices. When running a traffic simulation query on a group, AFA finds the devices in the path of the traffic and queries all these devices. Querying the policy or a group of policies produces an AFA report that shows whether traffic of the given service is allowed between the source and destination. If traffic is blocked by the device, you can then find out which rules block it.
  • The change history feature provides detailed information about changes to the device, over the entire history of AFA reports for the device. The information is divided into policy changes and risk profile changes.
  • The optimize policy feature allows an engineer to find out which rules are redundant, unused or already covered by other, more general rules. We can find:
    • Unused rules
    • Covered rules
    • Redundant special case rules
    • Consolidate rules
    • Disabled rules
    • Time-inactive rules
    • Rules without logging
    • Rules with empty comments
    • Duplicate objects
    • Unused objects within rules
    • VPN cleanup
    • VPN analysis report
    • Unused rules
    • Unused objects within rules

How has it helped my organization?

We can optimize and produce reports for 744 firewalls from different vendors (Check Point, Juniper, FortiGate, and Cisco) with one application.

What needs improvement?

We have requested improvement to VRF functionality on Cisco IOS and Nexus L3 devices and to support Juniper routers.

We have discovered that AlgoSec doesn’t work with loopback interfaces. We use OSPF and BGP, which run over multiple Virtual Routing and Forwarding (VRF-Lite) instances and, in some cases, distributors are connected to the core via loopbacks routed by an OSPF instance and a BGP address family. AlgoSec doesn’t recognize those loopbacks as a route, so it doesn’t find a route to the destination. This behaviour makes the “traffic simulation query” feature unusable in our environment.

For how long have I used the solution?

3 years

Buyer's Guide
AlgoSec
September 2026
Learn what your peers think about AlgoSec. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,262 professionals have used our research since 2012.

What do I think about the stability of the solution?

I have not encountered any stability issues.

What do I think about the scalability of the solution?

I have not encountered any scalability issues at all.

How are customer service and support?

Customer Service:

7

Technical Support:

The level of technical support is good.

Which solution did I use previously and why did I switch?

I did not previously use a different solution; we have been using this solution since 2012.

Which other solutions did I evaluate?

I don’t know if they evaluated other options before choosing this product.

What other advice do I have?

This product only supports L3 devices such as Cisco IOS and Cisco Nexus, so if your primary network is based on a different technology, AFA wouldn’t be the best choice.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user494916 - PeerSpot reviewer
Network Security Engineer at a financial services firm with 5,001-10,000 employees
Real User
Feb 1, 2017
The FireFlow feature stops users from overriding policies.
Pros and Cons
  • "It is a good product to use."
  • "Many times, when I try to verify an AlgoSec ticket that has been implemented, the validation has not worked immediately and I have to generate a report to check my work."

What is most valuable?

FireFlow, because you cannot override policies.

How has it helped my organization?

We have been able to add more vendors to support.

What needs improvement?

Validation: Many times I have to generate a report to validate tickets. When I try to verify an AlgoSec ticket that has been implemented, I have an option to validate the work I did. Many times, it has not worked immediately. I have to generate a report based on which I can check my work.

After implementation new rules on firewall algosec is not immediately aware about it. I have to make synchronization between algosec and firewall. In algosec is called analyze firewall. It is possible schedule this analyze more often but it consuming a lot of device resources like CPU, memory etc so I have this analyses one per day. After this analyze I am able make validation of implementation which I did because algosec can see rule which I added.

For how long have I used the solution?

I have been using it for five years.

How is customer service and technical support?

Technical support is quite OK.

AlgoSec provides different types and levels of support. I recommend asking about 24/7 support and being careful when deciding which support to buy.

How was the initial setup?

Initial setup was straightforward because we got support from vendor.

What about the implementation team?

If you are implementing it for the first time, it is good to ask vendor for help.

What other advice do I have?

It is a good product to use.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
AlgoSec
September 2026
Learn what your peers think about AlgoSec. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,262 professionals have used our research since 2012.
PeerSpot user
Cyber Security/ Network Intelligence Professional at EliteVAD
Consultant
Dec 8, 2016
ALGOSEC - Automate Firewall Security Policy Orchestration
Pros and Cons
  • "AlgoSec is a business-driven security management solution, a comprehensive and visionary solution which covers what needs to be covered in firewall security visibility, security change management, and application-security connectivity."
  • "Automated policy push for the Fortinet product family. The Active Change/Automated Policy push feature is already there for all other leading devices such as Cisco, Check Point, Juniper, and Palo Alto, etc."

What is most valuable?

  • Granular visibility
  • Risk rules evaluation
  • Saves with manual processes and dependencies

How has it helped my organization?

  • Saves person-hours
  • Security tightening and optimization in minutes
  • Loophole identification which helps with compliance
  • Effective tracking and automation of change management

What needs improvement?

Automated policy push for the Fortinet product family. The Active Change/Automated Policy push feature is already there for all other leading devices such as Cisco, Check Point, Juniper, and Palo Alto, etc.

For how long have I used the solution?

I've used it for two years.

What was my experience with deployment of the solution?

It's not hard to deploy, and can be run on a virtual environment.

What do I think about the stability of the solution?

It is a robust easy to use platform.

What do I think about the scalability of the solution?

It has highly scalable architecture.

How is customer service and technical support?

Customer Service:

The customer service team is reliable.

Technical Support:

They have time-zone matched technical/SLA support and local response team available.

How was the initial setup?

It is pretty straightforward and a piece of cake for the network engineers.

What about the implementation team?

Initial implementation is highly recommended to be done through a vendor and/or subject matter expert so you can leverage the best of the features.

What's my experience with pricing, setup cost, and licensing?

AlgoSec is a best of class solution with unique value proposition. Licensing has flexibility perpetual and subscription models, and by identifying your own real needs can achieve savings.

Which other solutions did I evaluate?

As a fair evaluation, other solutions are available in the security policy cleanup area. However, AlgoSec stands apart with a visionary business centric approach – not limiting itself to a mere firewall security cleanup tool. With AlgoSec, we also get an automated security change management/compliance solution. It has the unique and powerful application connectivity auto-discovery and then translates these to firewall rules. This is useful to achieve automation during datacenter migration, etc.

What other advice do I have?

AlgoSec is a business-driven security management solution, a comprehensive and visionary solution which covers what needs to be covered in firewall security visibility, security change management, and application-security connectivity. AlgoSec as a platform fills the gaps between the otherwise disconnected teams - Security, Network and Applications - within an organization.

Disclosure: My company has a business relationship with this vendor other than being a customer. We are value added distributors of the solution and are confident that we have the best choice in helping customers manage security at the speed of business.
PeerSpot user
PeerSpot user
Technical Consultant at a tech services company with 10,001+ employees
Real User
Nov 22, 2016
By leveraging BusinessFlow/FireFlow/ActiveChange we have been able to reduce the time from initial requirements gathering to implementation of complex firewall designs.
Pros and Cons
  • "By leveraging BusinessFlow/FireFlow/ActiveChange we have been able to reduce the time from initial requirements gathering to implementation of complex firewall designs by approximately 80% without compromising our security posture."
  • "The initial deployment was unsuccessful as the product had not initially support our use of virtual routing instances on Juniper SRX devices however AlgoSec engineering was quick to deploy fixes to allow us to reach our desired outcome."

What is most valuable?

We were immediately able to leverage the workflow tools in FireFlow with ActiveChange to speed up our deployment of firewall policies.

How has it helped my organization?

By leveraging BusinessFlow/FireFlow/ActiveChange we have been able to reduce the time from initial requirements gathering to implementation of complex firewall designs by approximately 80% without compromising our security posture. 

What needs improvement?

Additional understanding of complex routing in multiple systems.

For how long have I used the solution?

We have had this working in our production environment for about 6 months.

What was my experience with deployment of the solution?

The initial deployment was unsuccessful as the product had not initially support our use of virtual routing instances on Juniper SRX devices however AlgoSec engineering was quick to deploy fixes to allow us to reach our desired outcome. 

What do I think about the stability of the solution?

None.

What do I think about the scalability of the solution?

None.

How is customer service and technical support?

Top notch.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user540387 - PeerSpot reviewer
Information Security Consultant at a tech company with 51-200 employees
Vendor
Nov 21, 2016
It detects dangerous rules that affect security. I would like an architecture diagram that combines intelligence from all integrated firewalls.
Pros and Cons
  • "It has helped to detect all unauthorized changes made on my firewalls."
  • "During the early implementation phase, some stability issues were experienced."

What is most valuable?

The most valuable features are the risky rules analysis and network diagram representation generated from the firewall perspective.

How has it helped my organization?

It has helped to detect all unauthorized changes made on my firewalls. Also, this product can identify if anyone is creating dangerous rules that can severely affect the security of my organization.

What needs improvement?

One scope of improvement is to create an architecture diagram that combines intelligence from all integrated firewalls.

For how long have I used the solution?

I have used this product for three years.

What do I think about the stability of the solution?

During the early implementation phase, some stability issues were experienced. However, that is somewhat stable now.

What do I think about the scalability of the solution?

We have not encountered any scalability issues yet.

How is customer service and technical support?

I manage the reviews aspect, not maintenance.

How was the initial setup?

We were not part of the implementation team.

Which other solutions did I evaluate?

We evaluated the FireMon solution prior to this product.

What other advice do I have?

Prior planning is required for licensing and appliance handling if the company is looking to introduce new firewalls/security devices. This tool even integrates Cisco products to track changes on core switch or primary routers/VPNs.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Security Consultant at Securelink
Consultant
Nov 13, 2016
We took advantage of the the system's ability to add intelligence in all stages of a change.
Pros and Cons
  • "We succeeded in automating the flow in the change process with full traceability and accountability."
  • "The system has a so called roll-back feature, but this is implemented very simply just by a restore of the complete configuration."

Good and bad experience - A case study of the use of AlgoSec FireFlow.

The Good:

·         Cut turnaround time on firewall rule changes from weeks to days.

·         Improved network visibility via policy discovery, map and traffic simulations.

·         Increased accuracy of firewall changes with improved network security.

·         Highly improved traceability and accountability in the firewall change process.

·         It is easy to customise AlgoSec FireFlow to a quality system.

The Bad:

·         Lots of time was used to build and maintain the topology database (the network map). This is the foundation for the magic to happen.  If the topology is wrong, the path discovery and automatic selection of Firewalls in path / in scope for the change can be incorrect. 

·         A decommissioning feature is missing in FireFlow, separate unused rules can be found and decommissioned via the AlgoSec Analyzer, but the FireFlow product does not have a feature for decommissioning of a complete FireFlow ticket.

·         The system has a so called roll-back feature, but this is implemented very simply just by a restore of the complete configuration. In practice, this feature is not useful. If a FireFlow ticket is implemented, and it is discovered that some of the data in the ticket was  wrong, it is not possible to roll-back the mistakenly implemented firewall rules. The cleanup is a manual task that can be time consuming.

Challenges in this case story:

To reach the goal and have the above highlighted business impact, several challenges were faced during the first year of deployment.

One of the best lessons is that the AlgoSec FireFlow system is only accurate if the network topology is complete and accurate. We would have to spend a lot of time tweaking the network topology to make it accurate.

Another challenge was software bugs. AlgoSec technical assistance center was keen to help fix the software defects, but still it was time consuming at times when software defects were disturbing normal operation.

Results

Firewalls need constantly maintained rule changes and security assessment in order to adapt to the ever changing business and threats. We see our decommissioned business applications, new factories or sites that are build, etc.

This altogether brings a heavy workload on the security department.

Now the firewall maintenance tasks scale with existing staff.

 Firewall rule changes take days and not weeks.

The most significant benefits we achieved were:

·         All firewall rules match exactly the planned action

·         All stages of a change are now accountable in the history/audit trail of the change

·         No time spent on already working change requests

·         Full visibility into the network path of traffic

The intelligence provided by the AlgoSec system, and easy accessible security controls are significant, reducing the time spent in the periodic security assessments carried out.

 in the AlgoSec product:

Over the last couple of years we have had several missing features in the product that prevented us from reaching the full extent of automation from a start. However, most of the missing capabilities are today in the product.

Remaining is a better support for decommissioning of firewall rules and applications. This is high on our wish list.

Challenge

As responsible for the network infrastructure and security on more than 95 firewalls. The network infrastructure and security must follow the same strict regulated quality guidelines as the main business area itself.

The most central aspects of strict regulated quality are:

Traceability: the ability to reconstruct the development history of the products.

Accountability: the ability to resolve who has contributed what to the development and when.

Firewall change management in this environment is time consuming and cumbersome.

Each firewall change took several weeks with high cost. Many firewall rules were build unnecessarily wide due to complexity in network.

Many changes were performed for already working traffic. Human errors in creation of firewall rules put the total security at risk. The validation process was cumbersome and error prone.

Solution

We succeeded in automating the flow in the change process with full traceability and accountability. AlgoSec FireFlow was integrated with the surrounding quality system using the great customisation capabilities, and is now used as the main change management system for all infrastructure changes to Switch, Router and Firewalls in the production network.

We took advantage of the AlgoSec system's ability to add intelligence in all stages of a change.

This raised the accuracy of firewall changes.

Disclosure: My company has a business relationship with this vendor other than being a customer. I have been working as a contractor for the Customer for 2 Years building and using the AlgoSec FireFlow My company originally sold the solution to the Customer, however my role has been operation and maintenance at Customer site each day for the last 2 Years
PeerSpot user
it_user541044 - PeerSpot reviewer
Works at a tech company with 51-200 employees
Real User
Nov 2, 2016
Reduces time and costs of firewall change management, risk mitigation, and compliance audits.
Pros and Cons
  • "AlgoSec reduces time and costs of firewall change management, risk mitigation, and compliance audits."
  • "AlgoSec should support these features: Expired time should be one of the components of firewall rules, not only source, destination."

What is most valuable?

  • Intelligent policy tuning helps to reduce risk and improve device performance
  • Traffic simulation query on a specific device

How has it helped my organization?

AlgoSec reduces time and costs of firewall change management, risk mitigation, and compliance audits.

What needs improvement?

AlgoSec should support these features:

  • Expired time should be one of the components of firewall rules, not only source, destination
    For example: Now, in Algosec Fireflow, when creating a change request, there are only 3 component: Source, Destination and Service. I want to have expired date of the traffic
  • Detect duplicate objects in different firewalls
    Now, Algosec can only detect duplicate object within one firewall. I want to detect in different firewalls
    For example: firewall 1 has objet A with IP address 1.1.1.1, firewall 2 has object B with also IP address 1.1.1.1. I want Alogsec to detect this duplication
  • Show IP address of object in a report, query result
    Now, in report, query results, Algosec only displays name of the objects. I want to display IP address of these objects

For how long have I used the solution?

3 years.

What was my experience with deployment of the solution?

No, we haven't encountered any issues.

What do I think about the stability of the solution?

No, AlgoSec is stable.

What do I think about the scalability of the solution?

No, AlgoSec fit our size and is scalable.

How are customer service and technical support?

Customer Service:

Very good.

Technical Support:

Good.

Which solution did I use previously and why did I switch?

No.

How was the initial setup?

The initial setup was simple.

What about the implementation team?

Via a partner, they're very good.

What was our ROI?

We haven't calculated ROI yet, but AlgoSec saves us labor and a lot of time.

Which other solutions did I evaluate?

Tufin, we selected AlgoSec because it provide some useful features that other solution didn't have.

What other advice do I have?

AlgoSec is very helpful for our organization.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user541047 - PeerSpot reviewer
Works at a tech company with 51-200 employees
Real User
Nov 2, 2016
We like the ​rule optimization and risk analysis. It should support IPS devices.
Pros and Cons
  • "Saves time and labor cost in optimizing and operating our firewall system."
  • "It should support IPS devices."

What is most valuable?

  • Rule optimization
  • Risk analysis

How has it helped my organization?

Saves time and labor cost in optimizing and operating our firewall system.

What needs improvement?

Find duplicate objects in different firewalls.

For how long have I used the solution?

3 years

What was my experience with deployment of the solution?

Mainly with log collection.

What do I think about the stability of the solution?

No issues.

What do I think about the scalability of the solution?

None.

How are customer service and technical support?

Customer Service:

Good.

Technical Support:

Good.

Which solution did I use previously and why did I switch?

No.

How was the initial setup?

Simple to setup.

What about the implementation team?

Via a vendor team. They are good.

What was our ROI?

I don't have the details, but it is effective.

Which other solutions did I evaluate?

No.

What other advice do I have?

It should support IPS devices.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user540339 - PeerSpot reviewer
Security Specialist with 1,001-5,000 employees
Vendor
Oct 31, 2016
It has improved the way we handle risky rules on firewalls.
Pros and Cons
  • "I used to use Firemon before but switched to AlgoSec because the AlgoSec product and User Interface are more friendly than Firemon."
  • "The Tighten Permissive Rules Function could be better, we need more specific information about source, destination and service on the rule we will handle."

What is most valuable?

Policy management.

How has it helped my organization?

It has improved the way we handle risky rules on firewalls.

Security Firewall Policy; Firewall Performance; Firewall Hardening.

What needs improvement?

The Tighten Permissive Rules Function could be better, we need more specific information about source, destination and service on the rule we will handle.

For how long have I used the solution?

About 1 year.

What was my experience with deployment of the solution?

Nope.

What do I think about the stability of the solution?

Nope.

What do I think about the scalability of the solution?

Nope.

How are customer service and technical support?

Customer Service:

They have replied fast to all my concerns.

Technical Support:

Excellent.

Which solution did I use previously and why did I switch?

I used to use Firemon before but switched to AlgoSec because the AlgoSec product and User Interface are more friendly than Firemon.

What about the implementation team?

The AlgoSec vendor in Vietnam is Misoft, I rate them excellent in experience and support.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user494103 - PeerSpot reviewer
Information Security Analyst, Team Lead Network Security Assesment at a financial services firm with 1,001-5,000 employees
Vendor
Oct 26, 2016
It has helped us manage PCIDSS compliance.
Pros and Cons
  • "AlgoSec allows me to understand the inside of the firewall and brings simplicity to very complex firewall setups."
  • "It would be nice to allow customers to build their own policy, based on the customer’s own customization and business needs."

Valuable Features

  • Risk management for the rules
  • Policy optimization suggestions

AlgoSec allows me to understand the inside of the firewall and brings simplicity to very complex firewall setups.

Improvements to My Organization

It has helped us manage PCIDSS compliance and also improved the overall network security.

Room for Improvement

The product has several compliance checks built in for PCIDSS, ISO, SOX, etc., and also a baseline security policy. It would be nice to allow customers to build their own policy, based on the customer’s own customization and business needs.

Use of Solution

I have used it for four years.

Deployment Issues

The application is easy to deploy in an hour and can be done via a user guide.

Customer Service and Technical Support

Support needs are rare. I only require support around twice a year. Upgrades are easily done by the user but when support is required, it is great.

Initial Setup

Initial setup is easy because it is a virtual appliance with its own OS.

Implementation Team

I have expertise in implementation and prefer to do it myself rather than invoke the support contract. I believe it helps me stay knowledgeable and besides, AlgoSec implementation is a breeze.

Pricing, Setup Cost and Licensing

The license is perpetual but support is periodic.

Other Solutions Considered

I tried the ManageEngine firewall analyzer. AlgoSec has a superior firewall policy optimization algorithm.

Other Advice

It’s a good buy for simplifying large networks.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user3396 - PeerSpot reviewer
it_user3396Team Lead at a healthcare company with 10,001+ employees
Top 5Real User

Cool review

Buyer's Guide
Download our free AlgoSec Report and get advice and tips from experienced pros sharing their opinions.
Updated: September 2026
Buyer's Guide
Download our free AlgoSec Report and get advice and tips from experienced pros sharing their opinions.