We primarily use the solution for perimeter security - including DMZ and as an internet firewall. We use Check Point Firewalls as the first line of defense from the internet and they are also used to segregate the internet, DMZ, and internal networks. Check Point VSX technology is used to split the hardware into multiple virtual firewalls to cater to different environments so they are well segregated. We have BGP running on the firewalls, such as all of our network devices in our environment, to learn and advertise routes. Check Point does a decent job with BGP and does an excellent job as a perimeter firewall.
Senior Infrastructure Technical Lead at a financial services firm with 10,001+ employees
Great management console and operations support but they need to focus on its overall robustness
Pros and Cons
- "The ability to split single hardware into multiple virtuals along with support for dynamic routing using BGP is very useful for our environment."
- "The Check Point smart dashboard has made things easier for administration and we've been able to manage all the Check Point devices from one place which is very useful."
- "I would like less CPU-intensive features to be introduced to replace the existing heavy-duty processes."
- "Check Point, being our perimeter firewall, has failed quite a few times mainly when handling BGP."
What is our primary use case?
How has it helped my organization?
Check Point was brought into our environment as a perimeter security device to replace the Juniper NetScreen which was originally used as the perimeter firewall. When Juniper announced the end of life of NetScreen devices, we decided to go with Check Point mainly because of the ease of management and also because Check Point was an Industry leader and Juniper was still in the initial stages of building their own firewalls using JunOS. With the introduction of Check Point with the VSX features, we could use BGP instead of the tedious static routes that we had in place with the old NetScreen.
What is most valuable?
The VSX has been great. The ability to split single hardware into multiple virtuals along with support for dynamic routing using BGP is very useful for our environment.
We like the management console. The Check Point smart dashboard has made things easier for administration and we've been able to manage all the Check Point devices from one place which is very useful.
The operations support is great. There is a smart log system that is very good for troubleshooting and reporting. We also use the CLI for troubleshooting purposes (for the likes of FWMonitor and tcpdump) while the FW rules are managed via the smart console which does wonders for operations support.
What needs improvement?
It is common for any network device to compromise on stability when more and more features are packed into it. It may work for small organizations when they want a single device to do everything for security. However, it is a big issue for us as a large financial institution when even a small outage costs dearly. Check Point, being our perimeter firewall, has failed quite a few times mainly when handling BGP. I would like less CPU-intensive features to be introduced to replace the existing heavy-duty processes. They may already have a lot of features, so the enhancement of existing features could focus on robustness rather than introducing new features.
Buyer's Guide
Check Point Quantum Force (NGFW)
June 2026
Learn what your peers think about Check Point Quantum Force (NGFW). Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,747 professionals have used our research since 2012.
For how long have I used the solution?
I've been using the solution for three years.
What do I think about the stability of the solution?
With the upgrade to R80, the solution has become more stable. We have had outages because of the gateways failure while running BGP with older versions. After the upgrade, we havent had such outages.
What do I think about the scalability of the solution?
With the latest upgrades of R80, Check Point has bettered its performance, and hence, scalability has improved a lot. Also, there are multiple NG features that can be utilized that makes it more suitable for multiple solutions.
How are customer service and support?
They offer very good customer support; they're always available and capable.
Which solution did I use previously and why did I switch?
We previously used NetScreen and they were at their end of life.
How was the initial setup?
Check Point has its own design that is a little complex compared to other products. This has a 3-tier architecture and we need management servers and gateways separate. I would still say its not much of a hassle building it.
What about the implementation team?
We handled everything through Check Point PS. They were very good.
What was our ROI?
I can't really comment, as I do not have much idea about this space.
What's my experience with pricing, setup cost, and licensing?
The solution is priced well in the market in order to compete with the other products.
Which other solutions did I evaluate?
I wasn't in the organization when the evaluation happened. However, I know Juniper SRX was one of the solutions looked at as we are using them for our internal firewalls.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Manager IT & Security at mCarbon Tech Innovations Pvt., Ltd.
Scalable, easy to install, and quick to deploy
Pros and Cons
- "It's quite a stable solution."
- "As a next-generation firewall, this product is capable of handling all kinds of threats that might try to attack the network, including events such as DDoS attacks."
- "The pricing could always be more competitive."
- "We also use Cisco, and, in comparison, Cisco's support is way better in terms of how helpful and responsive they are."
What is our primary use case?
As a next-generation firewall, this product is capable of handling all kinds of threats that might try to attack the network, including events such as DDoS attacks.
How has it helped my organization?
The compliance part of the product has been very useful to our organization. There are many useful reports from this firewall device. For example, it can tell us how much of our network has compliance with the guidelines that are in place.
What is most valuable?
The product is very easy to use.
It's quite a stable solution.
The scalability is very good.
The solution is easy to install and deploy.
What needs improvement?
The product could always be even more stable and secure, as it would improve protection.
As we aren't using the very latest iteration, it's hard to say which features are lacking, as some might have been added in the latest releases we haven't yet migrated over to.
The pricing could always be more competitive.
Technical support needs to be more helpful.
For how long have I used the solution?
I've been using the solution for the last six months or so. It's been less than a year, and therefore, it hasn't been that long.
What do I think about the stability of the solution?
The stability is good. There are no bugs and glitches. It doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
The solution offers good scalability. If a company needs to expand it, it can do so. It's not hard.
We have 50 users on the solution right now.
How are customer service and technical support?
I would say that technical support could be better. We also use Cisco, and, in comparison, Cisco's support is way better in terms of how helpful and responsive they are. We aren't as satisfied with Check Point. They need to be faster, friendlier, and much more knowledgeable.
Which solution did I use previously and why did I switch?
Right now I am using Check Point and Cisco ASA.
How was the initial setup?
The initial setup is not overly complex or difficult. It's pretty straightforward.
The deployment doesn't take long either. It's a fast process.
You only really need two people for deployment and maintenance for most setups.
What about the implementation team?
I handled the implementation myself. I did not need the assistance of an integrator or consultant.
What's my experience with pricing, setup cost, and licensing?
The solution could work to make the pricing a bit lower. It's similar in cost to Palo Alto, however, if it was lower, it would make them more competitive.
What other advice do I have?
We are a customer and an end-user. We don't have a business relationship with Check Point.
We are not using the latest version of the solution, however, I cannot speak to the actual version number. We might be a version or two behind the latest update.
I'd rate the solution at an eight out of ten. We've largely been quite pleased with its capabilities.
I would recommend the solution to other users and companies.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Check Point Quantum Force (NGFW)
June 2026
Learn what your peers think about Check Point Quantum Force (NGFW). Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,747 professionals have used our research since 2012.
Project Manager at a financial services firm with 10,001+ employees
Good centralized management and VSX with great scalability potential
Pros and Cons
- "There is a lot of legacy traffic from other vendors that has been migrated to Check Point which has resulted in a lot of stability in our environment."
- "Using these features provides enhanced security with reduced cost across different domains and tenants with complete segregation from the policies database and a user traffic perspective."
- "The product or services can be improved from the cost and the pricing perspective."
What is our primary use case?
The next-generation firewalls are used on the perimeter within a couple of data centers. There are lots of firewalls and we are trying to consolidate everything in the final solution. The MDS and VSX are real solutions that are easing the consolidation across different domains to make management easier. It also improves the overall solution from the operations perspective where BAU teams can leverage different Check Point product lines, like Smart Log, to support customers on a daily basis.
How has it helped my organization?
There is a lot of legacy traffic from other vendors that has been migrated to Check Point which has resulted in a lot of stability in our environment. Moreover, consolidation happening across different legacy environments is being enhanced by the usage of MDS and VSX solutions offered by Check Point. This is making things easier from both a migration and implementation perspective. It offers easy management architecture, and, with Smart Log, makes life easier for the operations engineers and different teams working with Check Point products.
What is most valuable?
The most valuable feature of Check Point is the Centralized Management (MDS) and Virtualization (VSX) for the firewalls. Using these features provides enhanced security with reduced cost across different domains and tenants with complete segregation from the policies database and a user traffic perspective. Using these features is proving to be scalable as things are virtualized and the resources can be increased or decreased as per the demand or usage from a project perspective.
What needs improvement?
The product or services can be improved from the cost and the pricing perspective. There are a lot of other competitors in the market providing similar solutions with more low-cost options. There is no doubt that the great three-tier architecture of Check Point is great, however, when the cost is considered, it proves to be a bit expensive as compared to other products in the market. Also, the licensing and maintenance costs are quite high. Maintaining these solutions proves to be a bit costly to organizations from a day-to-day perspective.
For how long have I used the solution?
I've used the solution for five years.
What do I think about the stability of the solution?
The stability is excellent.
What do I think about the scalability of the solution?
The scalability is really good.
How are customer service and technical support?
We are satisfied with the level of support.
Which solution did I use previously and why did I switch?
Yes, we have used a different solution previously and have switched because of the great performance that Check Point offers.
How was the initial setup?
The initial setup is pretty straightforward.
What about the implementation team?
Yes, and we had a good experience.
What was our ROI?
The ROI meets our expectations.
What's my experience with pricing, setup cost, and licensing?
The cost is quite high for Check Point products.
Which other solutions did I evaluate?
Yes, however, I prefer not to say which.
What other advice do I have?
Overall, the solution and product line are good but more competitive pricing can be offered.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
Subgerente de Tecnologías de la Información at ETAPA EP
Good VPN and access control features, and it's stable,
Pros and Cons
- "The configuration is one of the best features of this product."
- "The product has been working very well."
- "The only reasons we are looking at other solutions are price and integration."
- "We are looking for a cheaper product that is more integrated than our Cisco Network appliance."
What is our primary use case?
We use Check Point for VPN access for all employees, as a rule. We also used it as a filter, a firewall, and it's the front line of our access to the Internet.
It has VPN access for our employees and it controls access, barring intrusion for non-authorized access.
What is most valuable?
The URL filter is activated to filter access to our employees. We use filtering for VPN access.
The configuration is one of the best features of this product.
When this product was purchased approximately 12 years ago it was the top of the line.
The product has been working very well.
I don't have any issues with the software of this solution. It works as is expected.
What needs improvement?
I would like to see more integration with other infrastructures. We are considering Cisco because it is more integrated, and the network limits of the solution are better.
Recently, we experience a problem with the hardware because it was too old, it was blocked. The hardware failed, but the software did not. With older hardware, it is a problem because our network is growing every year. The solution is not at maximum performance.
It does not have the performance that we require. The network is not the same as it was 12 years ago. There are several logs.
We are looking for a cheaper product that is more integrated than our Cisco Network appliance.
It may also need to support other types of architecture.
The only reasons we are looking at other solutions are price and integration.
For how long have I used the solution?
Check Point was installed in the company approximately 12 years ago.
What do I think about the stability of the solution?
The stability is good.
What do I think about the scalability of the solution?
We are a company with 1,200 employees, and approximately 700 are using this solution.
How was the initial setup?
We have five HP Servers, and we have a cluster in different geographic locations.
Check Point has been installed in an HP-certified server. It is not an appliance, it is an HP Server.
We have one or two professionals who work on the platform.
What's my experience with pricing, setup cost, and licensing?
It is not a cheap solution, which is why we are looking for another one.
Which other solutions did I evaluate?
We are currently evaluating new firewall solutions because the Check Point that we have was installed approximately 12 years ago, and wanted to change to a next-generation firewall.
What other advice do I have?
The HP Server works fine without any maintenance, but it needs to be taken care of. We did not, which caused a disk to fail. We have one or maybe two that are working. I don't have any complaints about the HP Server. It was sized for that network load at that time.
I would rate Check Point a ten out of ten. It works as expected.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Manager at a comms service provider with 51-200 employees
Great mobile access with good security and excellent stability
Pros and Cons
- "The AntiSpam/Mail blade was also one of the main reasons we went with this product since we hosted our email server locally. This was an extra layer of protection on top of the existing solution."
- "Stability and security are the best way to describe this solution."
- "It would be ideal to manage everything from one central place."
- "I do prefer to manage everything from only one point of entry/one application."
What is our primary use case?
It's our main firewall and the first line of protection from the outside! We use it to interconnect our remote locations (that use different vendors and equipment) and let the employees work remotely.
We're a small site with 300 users and this equipment is more than enough for us. We use almost all the blades and the equipment has run smoothly for years.
This NGFW monitors all the traffic outside of the main network, prevents malicious activities, and lets us easily manage network policies to shape our connections.
How has it helped my organization?
Stability and security are the best way to describe this solution. The attacks from the outside still exist, but now we're better protected. We can view everything that goes in and out of our network with all the information in one place. The drill-down is very helpful and easy to use. Currently, we can troubleshoot connection problems live and solve them in a couple of minutes. This is an improvement on the 1-2 hours with the old solution.
In 4 years we've only had one problem with the equipment (due to a malfunctioning UPS). That corrupted the boot of the equipment, but was easily solved with an fsck.
What is most valuable?
We basically use almost all the blades, since the IPS, Threat Emulation, Spam, etc., are essential for our work. However, currently, Mobile Access is the most valuable. The stability of the solution and the security it gives when working remotely is great. It lets our employees work from everywhere, anytime!
The AntiSpam/Mail blade was also one of the main reasons we went with this product since we hosted our email server locally. This was an extra layer of protection on top of the existing solution.
Threat and Application control are also very important to us.
What needs improvement?
I do prefer to manage everything from only one point of entry/one application. Some things can only be configured from the smart console and others from the smart dashboard. This is the only handicap in this solution. It would be ideal to manage everything from one central place.
Instead of using a windows application to manage the equipment, it would be better to use a web app to configure the solution from a browser. I know that it's not as powerful (you can't do everything from there), but then we could manage the solution and troubleshoot from any device.
It's faster to see the event logs on a webpage than it is to see them in the smart console.
For how long have I used the solution?
I've used the solution for 4 years.
What do I think about the stability of the solution?
It's very stable. It's also the main reason I love the solution.
During this time i never had to manually restart the equipment because of connectivity problems or because of CPU/memory degradation performance. Sometimes these values get high, but i never lose Throughtput, the equipment continues to run smoothly. We used to restart our older firewall at least 2 times per month.
In the beginning, because we use the spam blade, the memory usage was always high, and the administration was a little bit slow. But Checkpoint provided us an extra memory upgrade and after that we never had administration problems. If we don't have internet connection it's allways the ISP, it was never because of the firewall.What do I think about the scalability of the solution?
Although I only have one unit, I know that it scales perfectly.
How are customer service and technical support?
We only had one problem with this equipment. That was because it couldn't boot properly due to disk corruption (malfunction UPS), however, searching the technical Check Point forums it was easy to find a solution to the problem at hand.
We managed to solve the problem without contacting customer service at all.
Which solution did I use previously and why did I switch?
We used to have Zyxel products, but they were aging and couldn't let us connect at faster speeds.
How was the initial setup?
The setup was easy. It didn't take long to have it up and running.
The only concern for us was the remote sites - since it was different vendors. However, we had everything documented and prepared and due to that, it went flawlessly.
It was also easy to create access policies.
What about the implementation team?
The implementation was through a vendor, and the installation went really well. The consultant was Check Point certified and explained everything in detail.
Later on, we added new remote sites to the configuration (in-house) without any problem. We didn't need to check with the vendor.
What was our ROI?
It's not easy to calculate, however, given the stability and security of the solution, it's elevated. There are no bulletproof solutions. That said, now we can rest a bit more because our assets are more protected than they were a couple of years ago.
What's my experience with pricing, setup cost, and licensing?
The setup cost, pricing, and licensing can be a bit expensive, but, I promise, it's completely worth the cost.
Which other solutions did I evaluate?
I evaluated Fortinet and Check Point.
What other advice do I have?
It simply works like a charm. The stability and trust in the vendor are also very important to us.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
TitleManager - Datacenter IT at a manufacturing company with 10,001+ employees
Reliable with a great re-designed interface with excellent policy management
Pros and Cons
- "I love the redesigned interface starting with R80 as well as the ability for multiple engineers to work on the policy simultaneously."
- "We love the reliability and strong feature set of the firewall appliances and software blades."
- "Check Point solutions have always been more complex to deploy than their competitors."
What is our primary use case?
The primary use of the solution is as an enterprise perimeter firewall in our data centers. We also use software blades for IPS/IDS functions as well. We have a combination of enterprise-grade firewalls like the 15000 and16000 series as well as mid-size versions like the 5000 and 6000 series which are for specific segment isolation or other purposes. The software blades are running on HP servers. Management is done via 5150 appliances. 5000 and 6000 series appliances are primarily used for segment isolation while the larger appliances are used for perimeter security.
How has it helped my organization?
We have been using Check Point firewalls as our main security devices for many years and thus have a strong level of expertise within the organization on implementing various features. We love the reliability and strong feature set of the firewall appliances and software blades. Managing policies with v80 and above is also much more streamlined. Troubleshooting events via logs makes identifying issues straightforward. We have multiple engineers working on policies at the same time, so the newer versions help simplify this tasks for us.
What is most valuable?
I love the redesigned interface starting with R80 as well as the ability for multiple engineers to work on the policy simultaneously. Policy management is simplified and the virtualization options help us to plan for future deployments in a much easier way. While we haven't tried out all the features available - like Sandblast, AntiBot, URL filtering, etc. - the fact that these are available to use is definitely a plus. We were able to use the IPS features, negating the deployment of an expensive standalone IPS solution.
What needs improvement?
Check Point solutions have always been more complex to deploy than their competitors. There may be multiple scenarios where we may need to engage support, however, the customer support is very good. There are certain features that are only possible from the command line (e.g. packet captures) and it would be good to integrate everything into the GUI to reduce the learning curve for newer engineers. Finally, it can be a costlier solution - especially for the smaller firewalls as compared to the competition. It would be beneficial to have more training options or documentation as well.
For how long have I used the solution?
I've been using the solution for over 15 years.
What do I think about the stability of the solution?
The solution is extremely stable. There have been a few software bugs that have caused some unwanted glitches but these were fixed with updates.
What do I think about the scalability of the solution?
If the product is sized correctly in terms of appliances, then it is easy to scale.
How are customer service and technical support?
The support is excellent and knowledgeable. The service offered sets them apart from the competition.
Which solution did I use previously and why did I switch?
We have used Juniper SSG firewalls in the past and moved to Check Point due to the learning curve on the new JunOS deployments with the SRX firewalls.
How was the initial setup?
The setup required some planning and was slightly complex. The process requires good expertise on the product before deployment.
What about the implementation team?
We had an in-house team for deployment with active support from Check Point.
What was our ROI?
I don't have much detail on this.
Which other solutions did I evaluate?
We evaluated Cisco ASA firewalls and Palo Alto devices as well as Juniper SRXs.
What other advice do I have?
Setup can be complex and it is very helpful to first plan the deployment before rushing into it. Use the support available to find out the best options to use.
We would love to have more training materials and/or courses available so that I can onboard engineers in a faster way.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network security engineer at Fidelity Bank
Cisco dominated the African market until Check Point came along
Pros and Cons
- "Check Point has a really cool GUI."
- "The NGFW has helped our compliance to regulations authorities such as PCIDSS and has helped the bank create secure connections to vendors and third party service providers as well as remain protected from attacks and intrusion attempts."
- "The end-user VPN could be improved. It could benefit from some modification."
- "Check Point has actually failed twice within the last year."
What is our primary use case?
We use this solution for permissions regarding access ports and services. We also use Check Point Remote Access VPN as an endpoint VPN. We use it for site-to-site configuration.
All of the traffic that comes through our sites passes through our firewall. Basically, everyone, including our staff and clients, passes through our firewall. In other words, we have thousands of users using this solution.
How has it helped my organization?
The NGFW has helped our compliance to regulations authorities such as PCIDSS. It has has helped the bank create secure connections to vendors and third party service providers as well as remain stay protected from attacks and intrusion attempts.
What is most valuable?
The management of services, including forming access lists with the services we have, connecting servers to servers, permissions between servers and users — this is all great. In addition, Check Point has a really cool GUI.
What needs improvement?
The end-user VPN could be improved. It could benefit from some modification.
The VPN timeout feature needs to be improved. When we try to connect to the VPN, it times out before we can even enter our user name and password. If you can't prove you are who you say you are within seven to ten seconds, it just kicks you out.
For how long have I used the solution?
1 year +
What do I think about the stability of the solution?
Check Point has actually failed twice within the last year. The first failure was a disk failure. Check Point offers a software solution, they don't actually offer hardware. They will only provide you with the software and licenses. Because of this, when our disk failed, we had to wait for them to ship in some new hardware for us to fix the issue.
Aside from the disk failure issue, a month ago, our Check Point device froze. We don't exactly know what caused it to happen. It caused the entire organization to go down for about two to three hours until we found out that Check Point was not allowing anything to pass through. Our Check Point is clustered, so primarily it's supposed to have a failover feature. For some reason, the failover feature didn't work. When the primary gateway went down, it affected everyone.
What do I think about the scalability of the solution?
We've not tried to expand Check Point. We have two sites. We have a primary site and a secondary site that is off-prem. For this reason, we planned big. We planned for a high amount of availability for our two sites. We use clusters of four gateways: two gateways are in one cluster, and another two gateways are in another cluster. If one goes down, it switches to the other. If the second goes down, it switches to the other DR site. We've got backups of everything.
How are customer service and technical support?
The technical support is very responsive. We have a vendor that acts as a buffer between us and Check Point. In our country, these companies all have a local vendor that pushes their product.
When we contacted our vendor, our vendor called Check Point and as they were talking, Check Point shipped the hard disk, to fix the issue I mentioned earlier. They just placed the order immediately, while we were still talking. We think that they knew that delivery was going to take about five days — it was actually very fast.
How was the initial setup?
The initial setup and deployment were straightforward. We deployed it with RADIUS servers; it was not complex at all.
What about the implementation team?
From scratch to finish, deployment took about a month. It took this long because we had to convert all of our existing configurations from Cisco Firewall to Check Point. We had to get help from our vendor to do this. He had to manually convert each and every command from our existing Cisco device to Check Point — that took a while. This was the main reason that deployment took so much time.
The end-user VPN didn't take much time to deploy. Neither did the site-connecting with the VPN — that took a day or two to deploy.
What's my experience with pricing, setup cost, and licensing?
I think our licensing is on a yearly basis, but it could be every three years. Either way, it's not more than three years — that I am certain of.
The pricing was actually what made us go for Check Point. Palo Alto was much more expensive. Check Point offers the same applications and features as Palo Alto for roughly a third of the price.
Which other solutions did I evaluate?
We evaluated Palo Alto, Cisco (which we were using), and we also evaluated Check Point — which we ended up with.
What other advice do I have?
I would recommend Check Point to others. We are still learning as we're just about a year into using it, but so far, the support and the solution in general has been good. I'd recommend Check Point, especially to users that are looking for an affordable solution.
Check Point also has a great community. They have this community where users can go to share ideas. They also have great networks.
Overall, on a scale from one to ten, I would give this solution a rating of eight. Cisco dominated the African market until Check Point came along.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
AGM Cyber Security CoE at Bata Group
Flexible, provides good visibility, and it's easy to manage with a centralized dashboard
Pros and Cons
- "It creates granular security policies based on users or groups to identify, block or limit the usage of web applications."
- "In summary, this is an excellent product and featured consistently in Gartner for the last 10 years."
- "Although Check Point provides annual updates to the Gaia platform, integration with other OEMs is difficult."
- "Technical Support needs improvement, especially the L1 engineers."
What is our primary use case?
We use this solution for complete protection against advanced zero-day threats with Threat Emulation and Threat Extraction. We also use:
- NSS Recommended IPS to proactively prevent intrusions
- Antivirus to identify and block malware
- Anti-bot to detect and prevent bot damage
- Anti-Spam to protect an organization's messaging infrastructure
- Application Control to prevent high-risk application use
- URL Filtering to prevent access to websites hosting malware
- Identity Awareness to define policies for user and groups
- Unified Policy that covers all web, applications, users, and machines
- Logging and Status for proactive data analysis
How has it helped my organization?
The solution has improved the organization with respect to the following:
- Simple implementation and operation
- Central dashboard for managing branch firewalls
- Easy measurement of security effectiveness and value to the organization
- Proactive protection with the help of many inbuilt blades
- SandBlast Threat Emulation and Extraction provides us zero-day protection from known and unknown threats in real-time
- Great visibility on the number of threats being blocked at the dashboard
- Helps to clean traffic, both egress and ingress
- A simplified URL filtering option is available for users with detailed granularity to map user/departments with respect to specific access
- It does deep packet inspection for checking HTTPS traffic. There is a shift towards more use of HTTPS, SSL, and TLS encryption to increase Internet security. At the same time, files delivered into the organization over SSL and TLS represent a stealthy attack vector that bypasses traditional security implementations. Check Point Threat Prevention looks inside encrypted SSL and TLS tunnels to detect threats, ensuring users remain in compliance with company policies while surfing the Internet and using corporate data
- It helps in the identification of C&C via Anti-Bot
- It provides geolocation restrictions that may be imposed via IPS
- Excellent Application Control for the administrator to manage the access for users
- Secure remote access is configured with mobile access connectivity for up to five users, using the Mobile Access Blade. This license provides secure remote access to corporate resources from a wide variety of devices including smartphones, tablets, PCs, Mac, and Linux
What is most valuable?
We are using the Check Point Next-Generation Firewall to maximize protection through unified management, monitoring, and reporting. It has the following features:-
- Antivirus: This stops incoming malicious files at the gateway, before the user is affected, with real-time virus signatures and anomaly-based protections.
- IPS: The IPS software blade further secures your network by inspecting packets. It offers full-featured IPS with geo-protections and is constantly updated with new defenses against emerging threats.
- AntiBot: It detects bot-infected machines, prevents bot damage by blocking both cyber-criminals Command and Control center communications, and is continually updated.
- Application Control: It creates granular security policies based on users or groups to identify, block or limit the usage of web applications.
- URL Filtering: The network admin can block access to entire websites or just pages within, set enforcements by time allocation or bandwidth limitations, and maintain a list of accepted and unaccepted website URLs.
- Identity Awareness: This feature provides granular visibility of users, groups, and machines, enabling unmatched application and access control through the creation of accurate, identity-based policies.
What needs improvement?
I would like to see the provision of an industry-wide and global benchmark scorecard on leading standards such as ISO 27001, SOX 404, etc., so as to provide assurance to the board, and confidence with the IT team, on where we are and how much to improve and strive for the best.
Although Check Point provides annual updates to the Gaia platform, integration with other OEMs is difficult. This integration would be helpful in providing a full security picture across the organization. I am looking forward to the go-ahead of R81 with MITRE framework adoption in the future.
For how long have I used the solution?
We have been using the Check Point NGFW for the last four years.
What do I think about the stability of the solution?
This is a very stable product.
What do I think about the scalability of the solution?
It is highly scalable on cloud and does provide customers with lot of flexibility while performing the sizing of the appliance.
How are customer service and technical support?
Technical Support needs improvement, especially the L1 engineers.
Which solution did I use previously and why did I switch?
Prior to this solution, we were using GajShield. However, due to limited visibility and support, we opted for a technical refresh and upgrade of products.
How was the initial setup?
Yes initial setup was complex as migration of policies from one OEM to another is a challenge. however we meticulously planned and completed the implementation in phases.
What about the implementation team?
Yes we took help of the Certified Vendor. Vendor support was good.
What was our ROI?
We did not calculate our ROI; however, it provides good visibility to us.
What's my experience with pricing, setup cost, and licensing?
Check Point is competitively priced; however, there is an additional charge for the Annual Maintenance Contract (AMC) and it is easy to understand.
My advice is to negotiate upfront with a support contract of between three and five years.
Which other solutions did I evaluate?
We evaluated Palo Alto, Barracuda, and Fortinet.
What other advice do I have?
In summary, this is an excellent product and featured consistently in Gartner for the last 10 years. They have good R&D and support services across the globe.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Manager at Kotak Mahindra Bank
Good traffic visibility, integrates well with third-party solutions, and it's easy to implement
Pros and Cons
- "The threat emulation blade and user identity awareness feature has helped us a lot in terms of perimeter security and have given us granular visibility of user access."
- "Right now, with a larger user database and a high number of rules, it takes a bit of time for policy installation."
What is our primary use case?
The role NGFW plays is to protect the organization against Layer 7 network attacks.
The solution has helped us to guard our perimeter security on a wider level. This is not like plain vanilla firewall. We have got a wider visibility with the help of this next-generation firewall; it shows us the traffic flowing across the network and based upon that, we have made the modifications required to restrict access.
Also, the active cluster module has helped us to balance the load during peak hours. Since moving to the active-active module, we have got the much-needed breathing space.
How has it helped my organization?
It has helped us to inspect traffic, not only with a limited protocol base but on the application/service level inspection too.
The service base access policy has provided us with a next-level restriction, which wasn't there on old school firewalls.
The integrated threat & anti-bot blade gives us protection from zero-day attacks and these can be blocked using analysis & signature matching.
The integrated intrusion prevention blade not only gives an additional level of security but also cuts down the load to manage an extra device.
What is most valuable?
The threat emulation blade and user identity awareness feature has helped us a lot in terms of perimeter security and have given us granular visibility of user access.
The integration with third-party vendors is quite easy and well defined, which really helps you with the automation.
The integration of gateways with a centralized managed server gives you full control in a single place.
The setup and implementation are quite easy and the logs and reports are elaborative and effective for securing the network.
What needs improvement?
The one area that I would like to see a change in is policy installation. Right now, with a larger user database and a high number of rules, it takes a bit of time for policy installation. There is definitely some improvement in the R80 version; however, I believe that it should not take more than one minute to refresh the database. Also, there is a significant spike in gateway resource utilization during policy installation.
The additional blades have an impact on resource utilization, hence scope of improvement is needed here too.
For how long have I used the solution?
I am using Check Point NGFW for the past five to six years for perimeter & internal security.
What do I think about the stability of the solution?
The solution is quite stable, however some issues also observed in new version release & same is fixed through hotfix/portfix once it is highlighted to the TAC
What do I think about the scalability of the solution?
The new hyperscale module gives you the much-needed breathing space, which the industry was looking at for quite a long time.
How are customer service and technical support?
When it comes to technical support, Check Point is on another level. The support engineers are very well versed with the solution they are managing.
How was the initial setup?
The initial setup & integration was quite easy, and the support during migration was outstanding.
What about the implementation team?
It was a collaborative effort of our in-house and vendor teams. The support was good & quite appreciable.
What was our ROI?
It's good & the same as expected.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Works at Johnson Controls, Inc.
Easy to manage and use, affordable, with support that is knowledgeable and helpful
Pros and Cons
- "The uncomplicated configuration ensures that mistakes are avoided and rules are easily audited."
- "Check Point's solution is both affordable and easy to manage for the small business applications that we utilize them for."
- "The one thing I have been continually asking for is a more robust certification process including self-paced study material similar to Cisco's Security certification track."
What is our primary use case?
Our branch offices and customer sites require Internet access for the on-site staff and remote access capabilities for after-hours and remote support.
The Check Point firewalls allow us to provide site-to-site VPN, client VPN, web/app filtering, and IPS functionalities.
Client VPN is leveraged by site staff due to the majority of our sites requiring 24-hour support and also allows centralized teams to remotely assist with multiple sites globally.
We also use these at locations to provide security when our stand-alone network requires connectivity to the customer's network.
How has it helped my organization?
Check Point's solution is both affordable and easy to manage for the small business applications that we utilize them for. Due to the great pricing and support, we can afford to deploy the firewalls in a high-availability solution providing greater uptime and less worry.
The price point of their equipment also means that we can often purchase a more robust solution compared to some competitors and Check Point's inclusion of more advanced features, such as IPS, by default, is a great selling point.
What is most valuable?
We greatly appreciate the ease of configuring firewall policy ACL rules and how the seamless integration with VPN users and user groups provides the ability to granularly restrict access. The uncomplicated configuration ensures that mistakes are avoided and rules are easily audited.
Having the ability to set an expiration date for remote access VPN users simplifies the process and increases security by ensuring that stale accounts and not forgotten.
In general, we find that CheckPoint offers a great balance between ease of use and configurability.
What needs improvement?
The one thing I have been continually asking for is a more robust certification process including self-paced study material similar to Cisco's Security certification track. Not everyone can afford the time and money to attend the official in-person classes offered by Check Point. Even if someone was not interested in fully pursuing a certification, offering certification guides is often a method that IT professionals follow in order to learn about a specific topic and keep for reference.
An area that I sometimes find lacking is the information provided by the system when performing troubleshooting issues such as site-to-site VPN tunnels. The logs provide general information regarding what is happening but often, it leaves you wanting additional details. This also ties back into the lack of training and knowledge required to utilize the more advanced features of the command line.
For how long have I used the solution?
We have been using Check Point NGFW for more than five years.
What do I think about the stability of the solution?
We have never had a device or software failure in the more than five years that we have been using Check Point devices. To date, we are extremely happy with the performance.
How are customer service and technical support?
The few times that we required customer service, they have been extremely helpful and knowledgeable. I would rate them on par with the other top-tier companies.
Which solution did I use previously and why did I switch?
We previously utilized Cisco firewalls but the cost structure of the hardware, licensing, and support became prohibitive. Check Point offered a more robust solution at an affordable price point.
How was the initial setup?
The initial setup was extremely quick and easy, and the deployment time for a new site is often under a day.
What's my experience with pricing, setup cost, and licensing?
The price point and licensing was the main factor in moving away from Cisco and migrating all of our sites to Check Point. They offered more features for a lower cost than competitors, and the licensing model was easy to understand.
Which other solutions did I evaluate?
We evaluated NGFWs from Cisco, Palo Alto, and Fortinet in addition to the Check Point.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Check Point Quantum Force (NGFW) Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2026
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
Sophos Firewall
Cisco Secure Firewall
Palo Alto Networks NG Firewalls
WatchGuard Firebox
Cisco Meraki MX
Check Point Cloud Firewall (formerly CloudGuard Network Security)
Azure Firewall
Palo Alto Networks VM-Series
Fortinet FortiGate-VM
SonicWall TZ
Juniper SRX Series Firewall
Buyer's Guide
Download our free Check Point Quantum Force (NGFW) Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- How does Check Point NGFW compare with Fortinet Fortigate?
- Is Palo Alto Networks NG Firewalls better than Check Point NGFW?
- Which would you recommend - Azure Firewall or Check Point NGFW?
- Is Check Point's software compatible with other products?
- What do you recommend for a corporate firewall implementation?
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Which is the best network firewall for a small retailer?
- When evaluating Firewalls, what aspect do you think is the most important to look for?
- Cyberoam or Fortinet?













