What is our primary use case?
My main use case for Check Point NGFW is using it as a gateway firewall, since it's an enterprise-grade security device with tons of features such as threat prevention, IPS, app control, URL filtering, antivirus, anti-bot, anti-malware, and sandboxing, to name a few on top of my mind, and recently, as per the last solution I consulted or sold to a customer, they were using NGFW as a gateway firewall.
Apart from using Check Point NGFW as a gateway firewall, we use it as a device for application visibility and control, as Check Point NGFW is designed to detect and block sophisticated threats such as malware and advanced persistent threats (APTs) which can be a critical component for many deployments.
The last solution I worked on involved protecting a company with approximately 200 to 300 in-house employees, where the gateway firewall was installed to protect the network parameter and the gateway points within the organization's infrastructure, acting as a barrier between a trusted internal network and an untrusted external network.
What is most valuable?
The best features Check Point NGFW offers include their tight integration among different products forming a single ecosystem, and the ease of setup is notable, as Check Point is always a leader in security and getting a device with a lot of features managed by a central console, which we call SmartConsole.
The tight integration and ease of setup made a significant difference, as most Check Point NGFW devices come with a default configuration and once powered up, they automatically reach out to the Check Point cloud for an initial configuration download, which is completely autonomous. In my experience, this resulted in an initial setup that took around 3 to 4 hours for more complex configurations.
The combination of zero-touch deployment and SmartConsole allows Check Point NGFW for fast, easy, and scalable fiber deployment, as anyone can get Check Point NGFW up and running with minimal manual intervention, reducing the initial and complex setup, saving time, and alleviating headaches for IT.
Check Point NGFW has impacted our organization positively by reducing time due to zero-touch deployment and SmartConsole, where preconfigured devices automatically connect to Check Point cloud for setup, and this also helps in achieving a complete security posture for the organization.
What needs improvement?
While there are no pain points, the initial learning curve might be steep for those new to Check Point NGFW or the Check Point ecosystem, and it may not be a good solution for budget-conscious organizations given the breadth of services provided.
Documentation and support look great overall, but the initial cost of adopting Check Point technology might be concerning for someone starting their journey with the Check Point software platform, and I find that the lack of a browser-based full-scale GUI might be a limiting factor for users more comfortable with that format.
For how long have I used the solution?
I have been involved with Check Point NGFW for the past 3 years now. Check Point Next Generation Firewalls have been in the market for a long time, and we being one of the premier partners to Check Point, I have been selling them for ages.
What was my experience with deployment of the solution?
During deployment, the initial setup was done within 3 to 4 hours, and although a basic configuration can be installed within 1.5 hours, our configuration was a bit more complex due to the installation in an HQ environment that needed to connect to branches as well, which necessitated the additional time.
What do I think about the stability of the solution?
In my experience, Check Point NGFW has been stable with great support and I have not faced any issues with downtime or reliability.
What do I think about the scalability of the solution?
Check Point NGFW is highly scalable, designed to handle growth and evolving security needs in various environments, and its functionalities such as centralized management with SmartConsole, HA and load balancing mode, scalable licensing, and cloud scalability with CloudGuard makes it suitable for any organization size.
How are customer service and support?
I would rate Check Point's customer support a 9 out of 10, as they are equipped to provide diverse support options, including standard business hours, advanced support, premium support, and hardware replacement, all of which are well-organized in the Check Point support portal.
Which solution did I use previously and why did I switch?
Personally, I didn't use a different solution before Check Point NGFW, but I remember selling Cyberroam, Saro, and WatchGuard solutions.
How was the initial setup?
The initial setup with Check Point NGFW is straightforward, as mentioned previously.
What was our ROI?
While I can't provide specific numbers for ROI since I'm in sales, I haven't seen any complaints and the customer is pleased, having also purchased Check Point Harmony and planning to invest in Check Point CloudGuard services as well as SASE.
What's my experience with pricing, setup cost, and licensing?
Pricing for Check Point NGFW is complex because every product has its own unique selling points. I believe that pricing takes a back seat to how good the relationship is with the customer, how much they trust you as a consultant, and how well you have analyzed their structure to offer a fitting solution, as the installation was a breeze and support from the vendor was amazing.
Which other solutions did I evaluate?
They evaluated Palo Alto before choosing Check Point NGFW.
What other advice do I have?
My advice for others looking into using Check Point NGFW is to assess your network and have a defined security policy ready before choosing a solution, and being familiarized with the platform is crucial, as you should take full advantage of the SmartConsole which offers a breadth of services.
The reason I rate it a 9 out of 10 is primarily due to the lack of a browser-based GUI, and for small to medium-sized segments, Check Point NGFW may not be the best fit for those organizations.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.