What is our primary use case?
We use the product as our main and only Firewall/Gateway/VPN Gateway. we are in the finance sector, and we need a very reliable and robust system.
We rely heavily on the VPN system, as most of our employees are working outside the office at this time.
We also have two appliances to improve reliability, we have internet access through two ISPs configured to work simultaneously.
Our internal LAN is with duplicated network nodes that are double connected to our Check Point cluster. That way, we have full High Availability.
How has it helped my organization?
Before our purchase of Check Point products, we used an open-source product that lacked good integration between products and setting up to work was very tricky.
We use the Check Point mobile VPN, which is very stable and easy to use. It allows our employees to change their internal domain password when it becomes old, even when they are outside of the office for a long time. The VPN client can connect to our internal network even before the user is logged into his laptop. This allows users to receive GPO policy updates.
What is most valuable?
The solution offers very good central management, which saves time and is hassle-free.
One of the most useful new feature is dynamic definitions. For example, if you need to allow all of the Microsoft Azure IP addresses, you can insert them dynamically and Check Point will update them for you. Without it, to find all IP addresses would be almost impossible.
You can create additional layers for the firewall rules. This allows better organization and performance of the product by skipping to the rules that are responsible for this group of protected devices.
What needs improvement?
There are some GUI features in Check Point's SmartConsole that are still from the old versions and are in separate/duplicated interfaces; it would be most useful if it is integrated and not on different menus.
We would like to have a better search engine on the checkpoint.com site. Right now, it is difficult to find, for example, a newer version of the Check Point VPN Mobile client. The search engine shows most visited sites and the newer version won't be the most recently viewed site page. As it is right now, you have to find the general VPN page form, and from there you have to look at what version of the product you need and then go to the page of the latest version.
For how long have I used the solution?
We have been using this product for five years.
What do I think about the stability of the solution?
Check Point is very stable.
What do I think about the scalability of the solution?
We haven't needed to expand our throughput capacity.
However, based on the Check Point documentation, it is hyperscale ready capable of up to 475 Gbps of Threat Prevention.
How are customer service and support?
It is very good. Our local representatives are very helpful.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We moved from a previous solution to Check Point as it is more reliable and easy to manage, and our old solution wasn't able to provide the level of security we desired.
How was the initial setup?
We have had some problems understanding how to set up HA, however, we managed to do it. This was mainly due to the fact that we didn't have experience with Check Point products in the past.
What about the implementation team?
We did everything in-house.
What's my experience with pricing, setup cost, and licensing?
New users should know that the first year of support is included in the equipment. After that, you have to buy it.
Which other solutions did I evaluate?
We choose between Palo Alto and Checkpoint.
What other advice do I have?
We like it. It works well.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.