No more typing reviews! Try our Samantha, our new voice AI agent.
PeerSpot user
Network Engineer at LTTS
Real User
Top 20
Jan 8, 2021
Secure, gives us complete visibility of cloud traffic, and the support is excellent
Pros and Cons
  • "We can monitor each activity from our mobile devices, so there is complete visibility of our cloud traffic flows, with threat intelligence provided by Check Point."
  • "Dome9 is a very good product for us as we are using a hybrid solution."
  • "In Dome9, there should be a policy validation option where we can validate the policy before we push it into production."

What is our primary use case?

CheckPoint Dome9 is a cloud security management solution for our Azure cloud environment, and we have Azure for our cloud services. With this solution, we manage our network security policy management and automation for our cloud environment across providers, accounts, and regions.

Dome9 provides us policy compliance based on our requirements. If we request SOX or HIPPA, based on that we will enable the policy and we will get the reports as well.

We also create users and set policies and we can monitor the logs.

How has it helped my organization?

Dome9 is a very good product for us as we are using a hybrid solution. We have some of the services on-premises and some of the services on the cloud. With Dome9, we very well manage our security policies and also set the compliance policies based on requirements.

Now, we can also support the asset management of our cloud resources, posture management, and many more.

What is most valuable?

IAM is a very good and unique feature of Dome9. IAM gives us complete control of our cloud environment. For example, if someone tries to bypass the policy and attempts to configure or create some users, then it will not allow them to do so. Also, it sends a notification to the concerned person.

We can monitor each activity from our mobile devices, so there is complete visibility of our cloud traffic flows, with threat intelligence provided by Check Point. The IAM provides us complete safety and security.   

What needs improvement?

In Dome9, there should be a policy validation option where we can validate the policy before we push it into production. This option is very important, as we are working in a critical and complex environment. This option would give us more confidence in our activities or policy pushing.

We could see the option is available for on-premises devices. 

Automatic remediation requires read/write access.

Otherwise, overall this product is very good for our cloud environment, and we are satisfied with this.  

Buyer's Guide
Check Point CloudGuard CNAPP
August 2026
Learn what your peers think about Check Point CloudGuard CNAPP. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
908,858 professionals have used our research since 2012.

For how long have I used the solution?

We have been using Dome9 for the past six months.

What do I think about the stability of the solution?

It's a very stable product.

What do I think about the scalability of the solution?

Dome9 is very good in terms of scalability.

How are customer service and support?

The technical support is excellent.

Which solution did I use previously and why did I switch?

We did not use another solution prior to Dome9.

How was the initial setup?

The initial setup is straightforward.

What about the implementation team?

We implemented using a vendor team.

Which other solutions did I evaluate?

We did not evaluate other options.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Senior Network/Security Engineer at Skywind Group
Real User
Aug 26, 2020
Provides good visualization of infrastructure and the compliance engine is powerful
Pros and Cons
  • "This product provides a really nice visualization of the infrastructure, including network topology, firewalls, etc."
  • "The Compliance Engine is powerful."
  • "We were demotivated by the lack of native automation modules for the Terraform and Ansible tools."

What is our primary use case?

We use the Check Point CloudGuard IaaS within our company is for the protection of our cloud assets. It is deployed on Google Cloud Platform with the help of the Firewall, Application Control, and Intrusion Prevention System software blades.

In addition, we rely heavily on the GeoIP module to restrict undesired countries from accessing our services, as for now, you can't achieve it with the GCP firewall.

There are about 30 Google Cloud projects of different sizes ranging from 10 to 250 virtual machines, and they are used for development, staging, production, etc. For every project, there is one dedicated scalable instance group of the Check Point CloudGuard IaaS gateways.

Dome9 is used as an additional compliance tool to improve the security of these environments and avoid any configuration errors.

How has it helped my organization?

Initially, we had purchased the Dome9 solution just for its rich compliance possibilities. We have to provide the compliance reports on a regular basis to our partner companies and the regulators of the gambling and paying card areas, but now, we also rely heavily on the feature that "auto-heals" the configurations of the security groups and the firewall rules.

In addition, the Cloud infrastructure visualization feature is really good, especially for GP with its cumbersome firewall rules based on the instance tags and the service accounts.

What is most valuable?

  1. This product provides a really nice visualization of the infrastructure, including network topology, firewalls, etc. It's cozy to configure stuff, and also to wander around the interface in general.
  2. The Compliance Engine is powerful. We rely heavily on this feature since we must comply with the various security standards to work in the gambling sphere across the globe, and especially in the United States and European Union.
  3. The solution continuously monitors config modifications and may alarm the relevant administrators, or even revert the configs automatically.

What needs improvement?

We were demotivated by the lack of native automation modules for the Terraform and Ansible tools. We think that in the era of the DevOps approach and practices, all the new products need to be released with such support, mandatorily.

In addition, we also hope that the Dome9 will eventually support the other Public Cloud platforms, like Alibaba, since we are planning to expand to the Asian market. Alibaba is the big player in this region due to the fact that Google Cloud and AWS are almost banned.

For how long have I used the solution?

We have been using Dome9 for less than a year.

What do I think about the stability of the solution?

Dome9 is stable and works smoothly.

What do I think about the scalability of the solution?

The solution is scalable. We have it run on about 30 projects without any issues.

How are customer service and technical support?

No cases have been opened regarding Dome9 so far.

Which solution did I use previously and why did I switch?

No, we are unfamiliar with the other solutions of the same kind.

How was the initial setup?

The setup was straightforward, and the configuration was easy and understandable.

What about the implementation team?

Our deployment was completed by our in-house team. We have a Check Point Certified engineer working in the engineering team.

What's my experience with pricing, setup cost, and licensing?

I suggest that you pay attention to the product pricing because while there are no tricks, and the licensing model is transparent, the final numbers may surprise you.

Which other solutions did I evaluate?

No, we did not evaluate other options before adopting Dome9.

What other advice do I have?

Request a free demo directly from Check Point and see whether Dome9 suits you.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Google
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Check Point CloudGuard CNAPP
August 2026
Learn what your peers think about Check Point CloudGuard CNAPP. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
908,858 professionals have used our research since 2012.
reviewer1398609 - PeerSpot reviewer
Senior Manager at a financial services firm with 10,001+ employees
Real User
Aug 4, 2020
Threat intel integration provides us visibility in case any workload is communicating with suspicious or blacklisted IPs
Pros and Cons
  • "Assets Management as it provide complete visibility of our workload inkling EC2 instance or Serverless"
  • "It should capture more information in metadata including communication detail. Also, Internal IP addresses should not be tracked as this might be having some compliance issues."

What is our primary use case?

1) Visibility for Cloud Work Load for Server, Server Less & Container environment 

2) Security configuration review along with auto-remediation

3) Posture management and Compliance for complete Cloud Environment

4) Centralize Visibility for Complete Cloud Environment of Workload hosted on Multiple Cloud Platform (AWS, Azure, and GCP)

5) The baseline for Security Policy as per Workload based on Services such as S3, EC2, etc

6) Visibility of API call within the environment

7) IAM management providing access to cloud network in a control manner

8) Alert and Notification for any Security breach/Changes in Cloud environment

9) Flow Visibility of traffic from and to Cloud Environment

10) Real-time alerting for any incident 

How has it helped my organization?

1) Provides visibility of organization complete cloud infra hosted on different cloud platforms such as AWS & Azure. It also provides visibility of different accounts hosted on multiple tenants on a single dashboard.

2) Provide visibility of workload with an average instance running on a daily basis. As we have few instances that are taken offline during nonworking hours

3) It provides access to complete Cloud environment in control manner, Admin is not allowed to create or add any user or change security Policy directly with an admin account, unless the same has been approved via IAM role

4) Provides compliance and vulnerability detail of our environment. It also provides auto-remediation for few policies.

5) It has helped us to create a baseline while enabling any services.

6) Provides complete detail of any workload trying or getting connected to the Internet or if some workload is getting bypass from Firewall Policy.

7) Provides end to end visibility of source and detail IP address along with communication detail.

8) Reports generated based on metadata and API calls hence it does not impact our billing cycle 

What is most valuable?

1) IAM role is the feature which is widely used as it provides a granular level of control and visibility of any changes happening within our Cloud network

2) Benchmark of our network

3) Complaisance and reporting to understand and mitigate any security issue 

4) Threat intel integration which provides us visibility in case any workload is communicating with Suspicious or blacklisted IP

5) Centralize dashboard for different tenant and account 

6) Assets Management as it provide complete visibility of our workload inkling EC2 instance or Serverless 

What needs improvement?

1) More number of Security Policy to have more number of detection 

2) It should capture more information in metadata including communication detail. Also, Internal IP addresses should not be tracked as this might be having some compliance issues. 

3) Should have support for VMware Pivotal Cloud Foundry

4) Should maintain  configuration information which will help in case forensic need to be performed in term of changes

5) Should allow Policy to be deployed using a template and the same should be getting reviewed before deployment. This will help us to provide secure deployment CI/CD

For how long have I used the solution?

We have been using Dome9 for three months.

What do I think about the stability of the solution?

we have workout for SaaS offering from Dome9 hence entire setup is managed and maintained by Dome9. We have enrolled our account and using it as a service and till not we have not observed any outages 

What do I think about the scalability of the solution?

As it's available as SaaS and subscription offering it can be scalable deepening upon the number of workloads for which support is required.

How are customer service and technical support?

Overall its excellent both support and presales team.

Which solution did I use previously and why did I switch?

We used a Cloud-native solution to identify security issues but it did not provide any detailed visibility. Also, multiple console access where required in order to identify and security flaw.

How was the initial setup?

It was straightforward there was template provided by Dome9 (Checkpoint) and that need to be imported in our account which create ID and provide access to Dome9 on our cloud infra to monitor and collect metadata logs

What about the implementation team?

Our cloud team has helped us in terms of implementation. Also, it's not complicated the complete step by step guide is provided by Dome9 (CheckPoint) for enrolling Cloud to Dome9.

What's my experience with pricing, setup cost, and licensing?

Cost is based on number or Workload in case of Prisma & Dome9 

For Aquasec it's based on a number of application workloads

For Conformity it's based on the number of accounts 

Which other solutions did I evaluate?

Redlock from Prisma 

Conformity from Trend Micro

Auquasec 

What other advice do I have?

Licensing should be based on workload and should have some option for smaller brackets its should not in starting from 100,200 etc.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Evans Vs - PeerSpot reviewer
Security Engineer at Digitaltrack
Real User
Jul 30, 2024
Excellent efficiency and accuracy with very good cost-effectiveness
Pros and Cons
  • "The valuable features of Checkpoint CloudGuard CNAPP include its automation capabilities."
  • "Improvements can be made to the user interface."

What is our primary use case?

Check Point CloudGuard CNAPP is primarily designed to protect cloud-native applications and their underlying infrastructure from cyber threats. The primary use cases of this solution are comprehensive cloud security, workload protection, cloud security posture management, DevSecOps integration, threat detection and response, compliance and risk management.

How has it helped my organization?

Checkpoint CloudGuard Cnapp has improved efficiency, accuracy, cost-effectiveness, data-driven decision making and customer satisfaction.

What is most valuable?

The valuable features of Checkpoint CloudGuard CNAPP are automation capabilities, integration with existing systems, real-time analytics and reporting, customization and flexibility, security and compliance, scalability and growth support and a user-friendly interface.

What needs improvement?

Improvements can be made to the user interface, performance and reliability, security and compliance, and customer support.

For how long have I used the solution?

I've used the solution for the past year.

What do I think about the stability of the solution?

The stability is good.

What do I think about the scalability of the solution?

The scalability is nice.

How are customer service and support?

Technical support is good.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

No, I did not previously use a different solution. 

What about the implementation team?

The solution was set up via our in-house team.

What was our ROI?

The ROI is okay.

What's my experience with pricing, setup cost, and licensing?

The pricing and licensing can be improved.

Which other solutions did I evaluate?

No, I did not evaluate another solution. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
CEO at a tech vendor with 11-50 employees
Real User
Mar 26, 2024
Has amazing coverage and a very sophisticated way of building new queries
Pros and Cons
  • "The most valuable features of CloudGuard CNAPP are its compliance engine and auto-remediation features."
  • "There are opportunities for improvement that can be addressed through a roadmap."

What is our primary use case?

I use it for cloud visibility detection and remediation. I also use it for reporting and dashboarding.

What is most valuable?

The most valuable features of CloudGuard CNAPP are its compliance engine and auto-remediation features.

What needs improvement?

CloudGuard CNAPP is a great tool that justifies its investment. Like any other tool, there are opportunities for improvement that can be addressed through a roadmap.

For how long have I used the solution?

I have been using Check Point CloudGuard CNAPP for six years.

What do I think about the scalability of the solution?

I would rate the scalability of the solution as a ten out of ten.

How are customer service and support?

I would rate the technical support as seven out of ten. It is good when we get attention, but sometimes it is a bit difficult to get the attention we need.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We opted for CloudGuard CNAPP over other solutions mostly due to its flexibility.

How was the initial setup?

The implementation of the solution was easy.

What was our ROI?

There has been a significant ROI for me because now I can reduce risks effectively, and every risk I mitigate is a return on investment for the platform.

What other advice do I have?

CloudGuard CNAPP has been crucial in giving us visibility into our cloud setup and has significantly lowered our risks by enabling better control over our cloud security.

I find that CloudGuard CNAPP 's cloud security posture management is exceptional for addressing both physical and digital security concerns. It offers extensive coverage and provides a straightforward yet sophisticated method for creating and implementing new security queries.

My advice would be to define your use cases very well when considering this solution.

Overall, I would rate CloudGuard CNAPP as an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Myrian  Medina - PeerSpot reviewer
Head of Technology and Systems at Simed
Real User
Aug 29, 2023
A product that performs well and enables users to control the information that goes out of their company
Pros and Cons
  • "The product enables us to check the information that goes out of the company."
  • "The product must provide different features like antivirus."

What is our primary use case?

We use the solution to control all the emails that go out from the company. We also use it to protect our network by stopping unauthorized people from accessing it.

What is most valuable?

The product enables us to check the information that goes out of the company. We get to know if someone sends our sales emails to our competitors. We control the information that goes out of the company. It’s a good product.

What needs improvement?

The product must provide different features like antivirus.

For how long have I used the solution?

I am currently using the solution.

What do I think about the scalability of the solution?

The tool always performs very well. All the upgrades happen automatically. We haven't had a problem with it.

How are customer service and support?

We haven’t needed much support.

How would you rate customer service and support?

Positive

What's my experience with pricing, setup cost, and licensing?

The solution’s pricing is a little bit high. I rate the product’s pricing a seven out of ten on a scale of one to ten, where one is the lowest price, and ten is the highest price.

What other advice do I have?

I would like to implement all the security solutions from Check Point in our company. Overall, I rate the product an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
LucianoMiguel - PeerSpot reviewer
Security Consultant at a consultancy with 501-1,000 employees
Real User
Jul 10, 2023
Easy to manage, great visibility, all from a single dashboard
Pros and Cons
  • "The most valuable feature is the single dashboard that enables us to manage the entire cloud environment from one place."
  • "The dashboard customization has room for improvement."

What is our primary use case?

We utilize Check Point CloudGuard Posture Management to gain visibility into our cloud environments and their configurations. The cloud services we employ include AWS, Azure, and GCP.

How has it helped my organization?

A while back, we deployed Kubernetes, and it was exposed to the internet, resulting in the environment being affected by malware. Check Point CloudGuard Posture Management has helped our organization prevent such attacks from occurring in our environment.

What is most valuable?

The most valuable feature is the single dashboard that enables us to manage the entire cloud environment from one place.

What needs improvement?

The dashboard customization has room for improvement.

For how long have I used the solution?

I have been using Check Point CloudGuard Posture Management for four years.

What do I think about the stability of the solution?

Check Point CloudGuard Posture Management is highly stable. There was only one instance when the solution experienced downtime.

How are customer service and support?

The technical support is good.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is straightforward.

What's my experience with pricing, setup cost, and licensing?

Check Point CloudGuard Posture Management is expensive.

What other advice do I have?

I give Check Point CloudGuard Posture Management a ten out of ten.

Check Point CloudGuard Posture Management is an important component of a cloud environment that enables us to gain visibility across all areas and configure easily. I highly recommend this solution.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Hazel Zuñiga Rojas - PeerSpot reviewer
Administrative Assistant at Tecapro
Real User
Top 20
Nov 21, 2022
Great machine learning, good analysis, and efficient responses to threats
Pros and Cons
  • "The solution learns day by day, learning from behavior, attacks, management, detections, capturing packets, and performing real-time analysis while generating knowledge from a variety of sources for an excellent analysis, which allows us to move faster and have more efficient responses to incidents."
  • "I'd like to see more advanced encryption for local features, which is not present right now."

What is our primary use case?

We wanted to protect, analyze, and detect issues within the infrastructure that we have taken to the cloud. We were looking for ways that we can analyze and introduce a more complete internal forensic analysis so that if an intrusion did not happen, we could have a visualization in which we could be constantly learning how to detect and ee anomalies and provide analysis for detection in real-time. 

How has it helped my organization?

We needed a solution that could handle analysis and offer automated detection with process intelligence. We were interested in threat prevention in real-time to help us detect anomalies, attempts, and atypical actions in any of the activities of the teams or users. The goal was to take advantage of that learning and detection. Machine learning supervises and analyzes in an advanced way everything that is happening in the cloud. It works within any type of cloud and can be integrated more so if we want to migrate or scale tomorrow, we can carry out this detection automatically.

What is most valuable?

The solution learns day by day. It learns from behavior, attacks, management, detections, captures packets, real-time analysis, et cetera. It's generating knowledge from a variety of sources for an excellent analysis. 

This allows us to move faster and have more efficient responses to incidents. It provides alerts for all these types of activities, achieving more objective management for packet capture and a combination of activities within the cloud environment.

What needs improvement?

I'd like to see more advanced encryption for local features, which is not present right now. We'd like to have more defined control when implementing intelligent analysis on the cloud. We'd like to extend analysis not just to crowds but to local teams for more granular analysis and advanced searchability.

For how long have I used the solution?

I've used the solution for about a year and a bit.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Cloud Security Architect at Kontex
Real User
Jul 12, 2022
Useful training, good support, and reliable
Pros and Cons
  • "The most valuable feature of Check Point CloudGuard Posture Management is the training."
  • "When you're using Cisco, Check Point, or Palo Alto, you know that you will pay more, but you know that it will work."
  • "The security of Check Point CloudGuard Posture Management could improve. There are always new security issues coming out."

What is most valuable?

The most valuable feature of Check Point CloudGuard Posture Management is the training.

What needs improvement?

The security of Check Point CloudGuard Posture Management could improve. There are always new security issues coming out.

For how long have I used the solution?

I have been using Check Point CloudGuard Posture Management for a few months.

What do I think about the stability of the solution?

Check Point CloudGuard Posture Management is a reliable solution.

What do I think about the scalability of the solution?

The scalability of Check Point CloudGuard Posture Management is good.

How are customer service and support?

The support from Check Point CloudGuard Posture Management is very good.

How was the initial setup?

The initial setup of Check Point CloudGuard Posture Management difficulty depends on how you want to set it up. There are always some problems when you have to connect it to your cloud systems. However, this will only add time to the process.

What's my experience with pricing, setup cost, and licensing?

Check Point CloudGuard Posture Management is always known as a good solution but an expensive one. When you're using Cisco, Check Point, or Palo Alto, you know that you will pay more, but you know that it will work.

What other advice do I have?

I rate Check Point CloudGuard Posture Management an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
HariOmKanth MS - PeerSpot reviewer
DevSecOps Engineer at a tech services company with 11-50 employees
Reseller
Jun 1, 2022
Stable, scalable container security that's great for a developer-focused environment
Pros and Cons
  • "The way they offer container security is a big highlight that I have noticed, and the solution is also agentless, so the scanning, runtime, really everything is offered directly by CloudGuard."
  • "The technical support could be better, but I do not know of any other needed improvements."

What is our primary use case?

We resell the CloudGuard Workload Protection product. If a customer comes to us looking for a CSM tool, for example, we evaluate their needs and suggest a good option, like this solution.

What is most valuable?

The way they offer container security is a big highlight that I have noticed. The solution is also agentless, so the scanning, runtime, really everything is offered directly by CloudGuard.

What needs improvement?

The technical support could be better, but I do not know of any other needed improvements.

For how long have I used the solution?

My company has been involved with this solution for almost one year.

What do I think about the stability of the solution?

This is a stable product. 

What do I think about the scalability of the solution?

The solution is scalable.

How are customer service and support?

I would rate technical support as an eight out of ten. It has some room for improvement. 

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is really easy. On a scale of one to five, I would rate it as a five.

What other advice do I have?

If your company's environment is more developer-focused, meaning it has more containers and is running on Kubernetes, I would certainly recommend choosing Checkpoint.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
PeerSpot user
Buyer's Guide
Download our free Check Point CloudGuard CNAPP Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2026
Buyer's Guide
Download our free Check Point CloudGuard CNAPP Report and get advice and tips from experienced pros sharing their opinions.