We use it to provide security in our organization. Check Point Next Generation Firewalls are designed to support large networks, like a telco environment.
Network Security Administrator at a computer software company with 201-500 employees
User-friendly with IPS already configured in the box, and the dashboard is good and easy to use
Pros and Cons
- "Check Point has a lot of features. The ones I love are the antivirus, intrusion prevention, and data loss prevention. Apart from that, there is central management through which we can integrate all the firewalls and support them. It makes it easy to manage all the firewalls."
- "The antivirus is less effective than its competitors' antivirus. The antivirus is good, but in other firewalls, such as Palo Alto, it's quite effective. Check Point should provide more output. Sometimes it provides comprehensive information and sometimes it doesn't."
What is our primary use case?
What is most valuable?
Check Point has a lot of features. The ones I love are the
- antivirus
- intrusion prevention
- data loss prevention.
Apart from that, there is central management through which we can integrate all the firewalls and support them. It makes it easy to manage all the firewalls.
It's also user-friendly and not very complex. Anyone can use it and the dashboard is quite good.
What needs improvement?
Check Point has notably fewer tutorials on Google. If I'm facing any kind of issue and I Google it, less stuff is available.
Apart from that, the antivirus is less effective than its competitors' antivirus. The antivirus is good, but in other firewalls, such as Palo Alto, it's quite effective. Check Point should provide more output. Sometimes it provides comprehensive information and sometimes it doesn't.
For how long have I used the solution?
I have been using this firewall for more than one year.
Buyer's Guide
Check Point NGFW
April 2025

Learn what your peers think about Check Point NGFW. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
851,604 professionals have used our research since 2012.
What do I think about the stability of the solution?
The stability is good. We've never seen any kind of issue with the Check Point firewalls. In very rare cases we go to their TAC, but we normally try to resolve the situation from our side.
What do I think about the scalability of the solution?
They are quite scalable. They are designed to extend in large data centers and tech environments. They are designed to support the needs of large networks, and offer reliability and performance.
How are customer service and support?
Check Point's technical support is quite good. It's quite helpful. We have never faced any kind of issue with them. Whenever we have an issue with the firewalls, we just raise it with them and they are quite supportive and quite technical as well. They provide a resolution on time and effectively.
Which solution did I use previously and why did I switch?
Previously, I worked on Cisco ASA firewalls and they have a lot of disadvantages. They have a lot fewer features compared to the Check Point firewalls. We just started using Check Point as a firewall in our organization and they give us new features which are better than the Cisco ASA. With Check Point, the IPS is already configured in the box, unlike the Cisco ASA, and there are a lot of features which help us to provide more security for our customers. In our case, the customers are all employees of our organization.
All of these are reasons we switched to Check Point.
How was the initial setup?
The setup is straightforward.
Deployment depends on the customer's architecture or network.
In terms of a deployment plan, we have different teams in our organization that support different business cases. After an implementation ticket is raised by the requester it goes to the planning stage, then it goes to the implementation stage and then it goes to the validation stage. The planning stage is done by the network security admins. The approval stage that is done by our managers and the validation stage is done by us, the network security admins. This is the process that we follow in our organization. Everything is documented.
What about the implementation team?
We do the deployment ourselves, but if we face any kind of issue, we just raise an issue with their TAC.
What's my experience with pricing, setup cost, and licensing?
The pricing is good. It's not so expensive. You can deploy it and it will do a lot of jobs in one package. It's a good choice compared to the other firewalls.
Which other solutions did I evaluate?
We looked at Palo Alto and the Cisco FTD Next-Generation Firewall.
What other advice do I have?
Check Point Next Generation firewalls are very good. They have a lot of features in one box and they're not that expensive. They support a lot of features, including antivirus, data loss prevention, and the central management is very good. We can configure all the firewalls through the central management. They have many things in a small package. I would recommend them.
The biggest lesson I have learned from the solution is that it has a lot of features that I was not aware of. The dashboard is quite simple and it's not complex to use.
We make changes on this Checkpoint Firewall as per customer demand. If they want to add a rule on the firewall we do that, and if they want to remove something we remove it for them. If they want to change the position of some rules or to allow or deny any kind of traffic, we do that for them.
In our organization we have a team of 20 - 25 network security admins. Sometimes the network team will also implement changes and they are about 25 people. Sometimes we get the help of our managers to approve the changes or validate whether the change has been implemented correctly or not. If I sum it up, it's a team of about 100 people who directly use the solution, and they also take care of deployment and maintenance.
Which deployment model are you using for this solution?
On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.

The product is highly scalable and flexible, but the cost of add-on features is too high
Pros and Cons
- "The product is flexible."
- "The cost of add-on features is too high."
What is our primary use case?
We use the tool as a data center firewall. Some of our customers use it as a perimeter firewall. We are only using the security gateway.
What is most valuable?
The product is flexible. I like the product’s performance and throughput.
What needs improvement?
The cost of add-on features is too high.
For how long have I used the solution?
I have been using the solution for five to six years.
What do I think about the stability of the solution?
The tool is stable. We haven’t faced any issues after configuring and putting it in production.
What do I think about the scalability of the solution?
We have roughly 7000 appliances. The tool is scalable. I like the scalability of the solution. We have 10 to 20 customers.
How are customer service and support?
The technical support is good.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is easy.
What's my experience with pricing, setup cost, and licensing?
The pricing is moderate. The license cost is good. However, some features like VPN are costly.
What other advice do I have?
We use the solution for our clients. My recommendation depends upon the requirements. I do not recommend the product for an SMB. I recommend it for enterprises. It has good performance and throughput. Overall, I rate the solution a seven or eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: customer/partner
Buyer's Guide
Check Point NGFW
April 2025

Learn what your peers think about Check Point NGFW. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
851,604 professionals have used our research since 2012.
IT Security Administrator at a tech services company with 51-200 employees
Easy to manage with good features but there are security bugs that are annoying
Pros and Cons
- "We have all the features we want or need in this appliance. It's been good so far."
- "Sometimes there are security bugs, which is frustrating."
What is our primary use case?
We primarily use it for internet security. We use it for firewalling, ePass, and threat detection including anti-malware protection, bug protection, and social inspection. We can also use it for DLP.
What is most valuable?
The solution helps out in our security goals. It acts as a primary source of protection for threats from the internet and is great for data leakage protection.
Most of the time, it's pretty stable.
We have all the features we want or need in this appliance. It's been good so far.
What needs improvement?
Sometimes there are security bugs, which is frustrating.
Right now, we have a problem with DLP and this problem has become very big. Check Point, our firewall, is not handling data properly. There seems to be some sort of security bug.
For how long have I used the solution?
I've used the solution for ten years or so. It's been a decade at least.
What do I think about the stability of the solution?
The solution, for the most part, is very stable. We find it to be quite reliable. There are bugs, however, which have caused some issues.
What do I think about the scalability of the solution?
The solution is not scalable per se. There is only one way to upgrade and that is to buy new appliances.
Currently, we have around 7,000 people using this solution.
Likely, we won't be increasing usage. We are building new releases and we are considering changing this solution to another vendor. We might switch from Check Point to maybe Palo Alto or Cisco. We don't know which yet.
How are customer service and support?
We haven't really dealt with technical support. We typically go through our partners.
Which solution did I use previously and why did I switch?
We also use Cisco as well. We use Cisco ASA. Check Point, right now, is our primary firewall.
Check Point offers very good management. For an administrator, it's easy to manage this appliance, this firewall. Cisco, historically, has a big problem with this, specifically with FTD firewalls. There also tend to be some bugs you have to contend with.
How was the initial setup?
I can't speak to the initial setup process. Our partner handled it and therefore I wasn't really part of the process. That said, for me. the process is pretty simple.
My understanding is that the deployment took a few days.
I'd rate the experience of the initial setup at a four out of five.
About two people were able to handle the implementation process. Typically, they are architects and engineers.
What about the implementation team?
We had a partner set up the solution for us.
What was our ROI?
We have seen a decent ROI. I'd rate it at a four out of five.
What's my experience with pricing, setup cost, and licensing?
I can't speak to the cost of the solution. We deal with it through a partner, and I'm not involved in any of the pricing aspects.
Which other solutions did I evaluate?
We are considering switching to Palo Alto or maybe Cisco in the near future.
What other advice do I have?
We are a customer and an end-user.
Some blades, some function blades on Check Point, are very good, however, it's not all of them. Right now, I know DLP and social inspection are a problem. New users should be aware of this.
Overall, I would rate the solution at a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
A next generation firewall solution with a useful SmartEvent feature
Pros and Cons
- "I like the SmartEvent feature. When we see a threat, SmartEvent can create a rule for that. SmartEvent works with the SmartCenter to block a threat attack with a block monitor. The SmartCenter has the management for all the firewalls and data centers in a single dashboard."
- "It could be more stable and scalable. Check Point price and support could be better."
What is our primary use case?
I use CheckPoint in our data center to control the internet and to enable threat prevention. I then integrate it into my center and to my events.
What is most valuable?
I like the SmartEvent feature. When we see a threat, SmartEvent can create a rule for that. SmartEvent works with the SmartCenter to block a threat attack with a block monitor. The SmartCenter has the management for all the firewalls and data centers in a single dashboard.
What needs improvement?
It could be more stable and scalable. Check Point price and support could be better.
For how long have I used the solution?
I have ten years of experience using Check Point NGFW.
What do I think about the stability of the solution?
Check Point NGFW could be more stable. I think the problem is that the kernel sometimes won't play ball and isn't stable. Sometimes, they have a block, and we have to spend a lot of time fixing it. In contrast, I think Palo Alto and Fortinet are more stable.
What do I think about the scalability of the solution?
Check Point NGFW could be more scalable. I think Palo Alto has more plugins and features, and Check Point needs more features. However, Check Point integration is very complex.
How are customer service and technical support?
Check Point support could be better. I think Palo Alto has a very clear pricing model. When we have an issue, we create a ticket and receive fast service from Palo Alto. It's good.
How was the initial setup?
The initial setup, in my experience, isn't simple as Fortinet and Palo Alto. It would be better if the person doing it has experience.
What about the implementation team?
I implemented this solution by myself.
What's my experience with pricing, setup cost, and licensing?
The price could be better. I think Palo Alto pricing is high, and Check Point isn't much better. FortiGate is cheaper. I think when I implemented this solution, I recommended buying a yearly subscription.
Which other solutions did I evaluate?
When I choose a solution for a customer, I must verify the features, current specifications and make recommendations. When we use an all-in-one firewall solution, we usually recommend using a Palo Alto external firewall. This is because Fortinet has an SD-WAN solution and firewalls, and Palo Alto is the same. But I don't think Check Point has one. When a customer doesn't want to implement many solutions, we recommend using Fortinet or Palo Alto.
What other advice do I have?
On a scale from one to ten, I would give Check Point NGFW an eight.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Security product manager at RRC
An easy-to-use and easy-to-manage protection solution at a reasonable price
Pros and Cons
- "It is easy to use, and its management is the best. Check Point has a great unified management solution for firewalls and security products."
- "Their technical support can be better. In addition, when we need to use it in a government environment, we face a lot of legal issues related to different types of certifications. It would be better to improve it for these issues. Check Point doesn't have a SOAR system. They work with Siemplify, but it is an integration with another vendor. It would be great if Check Point has an integrated SOAR system."
What is our primary use case?
We use Check Point NGFW for perimeter protection of our network from the internet. We also use it for threat protection at the network level and the endpoint level.
We provide implementation, installation, and support services. We know about all types of firewalls, and we work with all types of installations. We usually use appliances, but in test environments, we use virtual appliances.
What is most valuable?
It is easy to use, and its management is the best. Check Point has a great unified management solution for firewalls and security products.
What needs improvement?
Their technical support can be better. In addition, when we need to use it in a government environment, we face a lot of legal issues related to different types of certifications. It would be better to improve it for these issues.
Check Point doesn't have a SOAR system. They work with Siemplify, but it is an integration with another vendor. It would be great if Check Point has an integrated SOAR system.
For how long have I used the solution?
We have been dealing with Check Point firewalls in our company for more than 20 years.
What do I think about the stability of the solution?
It is quite stable, but it can vary based on the version.
What do I think about the scalability of the solution?
It is scalable. We can use the Maestro solution from Check Point for scalability. We can add new appliances as the company grows. If we need more performance and throughput, we can add additional appliances and have more performance. Check Point Maestro is the best solution for scalability.
How are customer service and technical support?
Their technical support can be better.
How was the initial setup?
Its initial setup is easy for me. The deployment duration varies. A simple deployment takes two or three days. A complex deployment that involves a cluster configuration or appliance replacement can take up to five days.
What's my experience with pricing, setup cost, and licensing?
Its price is reasonable. If we compare its TCO for three years, it is more reasonable than some of the other vendors such as Fortinet, Palo Alto, etc.
What other advice do I have?
I would recommend this solution. It is a great solution for endpoint protection and threat prevention. I have been working with Check Point products for a very long time. Check Point is one of our best vendors, and they make great products.
I would advise others to learn about firewalls and other Check Point solutions. They have a lot of different solutions. If you choose their firewall, it would be useful to know more about other solutions. It would be one of the ways to improve the protection of your network with Check Point.
I would rate Check Point NGFW a ten out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Distributor
IT-Infrastruktur at Synthesa Chemie Ges.m.b.H
Provides centralized management, good logging capabilities, and granular application control
Pros and Cons
- "The most valuable feature is the centralized management, which gives us control over all of the Check Point gateways."
- "Without any training, it is very hard to administrate the whole Check Point NGFW."
What is our primary use case?
Check Point protects our environment from external threats. In particular, we use:
- Application Control for Internet access
- HTTPS Inspection for outgoing connections into the internet
- Separate the OT network from the normal data LANs
- SSL VPN for End Users - Check Point Mobile VPN Client is used on the end-user clients
- Site-to-Site VPN for connecting other companies to our environment
We are using two Check Point boxes in a ClusterXL Setup so that one appliance can die and the environment is not affected. We also use a cloud gateway for internet security on users, which are only connected to the internet (outside the office).
How has it helped my organization?
Check Point has improved our organization in the following ways:
- Provides for central management over all of the Check Point gateways
- Maintains a changelog that shows which users have made changes
- Version control allows us to roll back a ruleset after, for example, a misconfiguration
- Offers very granular application control
- Allows for various internet permissions for various users
- Gives us very good logging, which is nice for troubleshooting because you can instantly which rule is affected for each action
- The cloud gateway (Check Point Capsule Cloud) ensures that users are getting the same internet permissions as they would if inside the company, no matter which internet connection they are using
What is most valuable?
The most valuable feature is the centralized management, which gives us control over all of the Check Point gateways. This means that you do not need to connect to each gateway and make the necessary changes.
Cluster functionality, "ClusterXL", works like a charm. A rollover to the standby gateway does work with no noticeable delay in the network.
You can buy a Check Point appliance or install the Check Point NGFW as a VM on your own hardware.
The extremely wide function horizon covers almost every possible scenario.
What needs improvement?
The Performance on a policy install takes too long for my taste. This might be because, at each policy install, the management pushes the whole policy on the affected gateways.
Without any training, it is very hard to administrate the whole Check Point NGFW.
In our case, the main Check Point gateways are in a cluster configuration. Sadly, the management always shows the standby box as failed. This may be because it is set to STANDBY and not ACTIVE. It would be better to show the standby box as good.
For how long have I used the solution?
I have been using Check Point NGFW for about five years.
How are customer service and technical support?
Support is very customer-oriented and you are always in good hands.(customer wishes are often implemented in the next hotfix)
Most Support engineers are located in Israel. (Very good spoken english)
Very fast response from R&D Team
Which solution did I use previously and why did I switch?
We were using SonicWall and switched because of EOL.
What's my experience with pricing, setup cost, and licensing?
The pricing for Check Point depends on your environment.
Which other solutions did I evaluate?
Before choosing Check Point we evaluated Fortinet and a newer version of SonicWall.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Network Administrator at Türkiye İş Bankası
Easy to use, configure, and manage and offers good security
Pros and Cons
- "SmartCenter and SmartLog are the best platforms to manage firewall rules. SandBlast Zero-Day is very useful when encountering any security leaks."
- "Check Point needs to work on hardware problems also."
I have been working with Check Point for almost three years in my career and 8+ years on my company.
We are using Check Point as a perimeter firewall in our data center and we are using all NGFW specs on our firewalls like IPS, identity awareness, Anti-Bot, application firewall antivirus and SandBlast solutions in our environment.
It is generally easy to configure and manage using SmartCenter. Also, SmartLog really helps troubleshoot any problems that we encounter. SandBlast Zero-Day security helps our organization become safer. SmartConsole is the best GUI when compared to other companies. It is very easy to use and it is much more secure when compared to a web GUI.
SmartCenter and SmartLog are the best platforms to manage firewall rules. SandBlast Zero-Day is very useful when encountering any security leaks.
Maestro looks very sophisticated and it is the most important feature. We have to see how it works and if it's stable or not.
Check Point needs to work on hardware problems also. There are some hardware problems on NIC cards and hard disks. Lately, we have encountered some problems with it. There needs to be an RMA on some devices. Also, management and data plane separation need to be done as soon as possible because if you encounter a problem with gateways, you can't reach the management which will create more problematic situations.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Supervisor of Network and Datacentre Operations at Manitoba eHealth
Consolidated many of our DMZ services into one appliance
What is our primary use case?
- Perimeter and datacentre firewalls
- URL filtering
- Anti-bot
- Anti-malware
- Application awareness.
How has it helped my organization?
Consolidated many of our DMZ services into one appliance, and it's easy to add IPS functionality on firewalls.
What is most valuable?
All of the above mentioned.
What needs improvement?
Simplify licensing.
For how long have I used the solution?
Three to five years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Check Point NGFW Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2025
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
OPNsense
Sophos XG
Cisco Secure Firewall
Meraki MX
Palo Alto Networks NG Firewalls
Azure Firewall
WatchGuard Firebox
SonicWall TZ
Sophos UTM
Juniper SRX Series Firewall
Fortinet FortiGate-VM
SonicWall NSa
Sophos XGS
Buyer's Guide
Download our free Check Point NGFW Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- How does Check Point NGFW compare with Fortinet Fortigate?
- Is Palo Alto Networks NG Firewalls better than Check Point NGFW?
- Which would you recommend - Azure Firewall or Check Point NGFW?
- Is Check Point's software compatible with other products?
- What do you recommend for a corporate firewall implementation?
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Which is the best network firewall for a small retailer?
- When evaluating Firewalls, what aspect do you think is the most important to look for?
- Cyberoam or Fortinet?