The primary use of the solution is as an enterprise perimeter firewall in our data centers. We also use software blades for IPS/IDS functions as well. We have a combination of enterprise-grade firewalls like the 15000 and16000 series as well as mid-size versions like the 5000 and 6000 series which are for specific segment isolation or other purposes. The software blades are running on HP servers. Management is done via 5150 appliances. 5000 and 6000 series appliances are primarily used for segment isolation while the larger appliances are used for perimeter security.
TitleManager - Datacenter IT at a manufacturing company with 10,001+ employees
Reliable with a great re-designed interface with excellent policy management
Pros and Cons
- "I love the redesigned interface starting with R80 as well as the ability for multiple engineers to work on the policy simultaneously."
- "We love the reliability and strong feature set of the firewall appliances and software blades."
- "Check Point solutions have always been more complex to deploy than their competitors."
What is our primary use case?
How has it helped my organization?
We have been using Check Point firewalls as our main security devices for many years and thus have a strong level of expertise within the organization on implementing various features. We love the reliability and strong feature set of the firewall appliances and software blades. Managing policies with v80 and above is also much more streamlined. Troubleshooting events via logs makes identifying issues straightforward. We have multiple engineers working on policies at the same time, so the newer versions help simplify this tasks for us.
What is most valuable?
I love the redesigned interface starting with R80 as well as the ability for multiple engineers to work on the policy simultaneously. Policy management is simplified and the virtualization options help us to plan for future deployments in a much easier way. While we haven't tried out all the features available - like Sandblast, AntiBot, URL filtering, etc. - the fact that these are available to use is definitely a plus. We were able to use the IPS features, negating the deployment of an expensive standalone IPS solution.
What needs improvement?
Check Point solutions have always been more complex to deploy than their competitors. There may be multiple scenarios where we may need to engage support, however, the customer support is very good. There are certain features that are only possible from the command line (e.g. packet captures) and it would be good to integrate everything into the GUI to reduce the learning curve for newer engineers. Finally, it can be a costlier solution - especially for the smaller firewalls as compared to the competition. It would be beneficial to have more training options or documentation as well.
Buyer's Guide
Check Point Quantum Force (NGFW)
August 2026
Learn what your peers think about Check Point Quantum Force (NGFW). Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
908,858 professionals have used our research since 2012.
For how long have I used the solution?
I've been using the solution for over 15 years.
What do I think about the stability of the solution?
The solution is extremely stable. There have been a few software bugs that have caused some unwanted glitches but these were fixed with updates.
What do I think about the scalability of the solution?
If the product is sized correctly in terms of appliances, then it is easy to scale.
How are customer service and support?
The support is excellent and knowledgeable. The service offered sets them apart from the competition.
Which solution did I use previously and why did I switch?
We have used Juniper SSG firewalls in the past and moved to Check Point due to the learning curve on the new JunOS deployments with the SRX firewalls.
How was the initial setup?
The setup required some planning and was slightly complex. The process requires good expertise on the product before deployment.
What about the implementation team?
We had an in-house team for deployment with active support from Check Point.
What was our ROI?
I don't have much detail on this.
Which other solutions did I evaluate?
We evaluated Cisco ASA firewalls and Palo Alto devices as well as Juniper SRXs.
What other advice do I have?
Setup can be complex and it is very helpful to first plan the deployment before rushing into it. Use the support available to find out the best options to use.
We would love to have more training materials and/or courses available so that I can onboard engineers in a faster way.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Founder at DedSec
Cisco dominated the African market until Check Point came along
Pros and Cons
- "Check Point has a really cool GUI."
- "The NGFW has helped our compliance to regulations authorities such as PCIDSS and has helped the bank create secure connections to vendors and third party service providers as well as remain protected from attacks and intrusion attempts."
- "The end-user VPN could be improved. It could benefit from some modification."
- "Check Point has actually failed twice within the last year."
What is our primary use case?
We use this solution for permissions regarding access ports and services. We also use Check Point Remote Access VPN as an endpoint VPN. We use it for site-to-site configuration.
All of the traffic that comes through our sites passes through our firewall. Basically, everyone, including our staff and clients, passes through our firewall. In other words, we have thousands of users using this solution.
How has it helped my organization?
The NGFW has helped our compliance to regulations authorities such as PCIDSS. It has has helped the bank create secure connections to vendors and third party service providers as well as remain stay protected from attacks and intrusion attempts.
What is most valuable?
The management of services, including forming access lists with the services we have, connecting servers to servers, permissions between servers and users — this is all great. In addition, Check Point has a really cool GUI.
What needs improvement?
The end-user VPN could be improved. It could benefit from some modification.
The VPN timeout feature needs to be improved. When we try to connect to the VPN, it times out before we can even enter our user name and password. If you can't prove you are who you say you are within seven to ten seconds, it just kicks you out.
For how long have I used the solution?
1 year +
What do I think about the stability of the solution?
Check Point has actually failed twice within the last year. The first failure was a disk failure. Check Point offers a software solution, they don't actually offer hardware. They will only provide you with the software and licenses. Because of this, when our disk failed, we had to wait for them to ship in some new hardware for us to fix the issue.
Aside from the disk failure issue, a month ago, our Check Point device froze. We don't exactly know what caused it to happen. It caused the entire organization to go down for about two to three hours until we found out that Check Point was not allowing anything to pass through. Our Check Point is clustered, so primarily it's supposed to have a failover feature. For some reason, the failover feature didn't work. When the primary gateway went down, it affected everyone.
What do I think about the scalability of the solution?
We've not tried to expand Check Point. We have two sites. We have a primary site and a secondary site that is off-prem. For this reason, we planned big. We planned for a high amount of availability for our two sites. We use clusters of four gateways: two gateways are in one cluster, and another two gateways are in another cluster. If one goes down, it switches to the other. If the second goes down, it switches to the other DR site. We've got backups of everything.
How are customer service and technical support?
The technical support is very responsive. We have a vendor that acts as a buffer between us and Check Point. In our country, these companies all have a local vendor that pushes their product.
When we contacted our vendor, our vendor called Check Point and as they were talking, Check Point shipped the hard disk, to fix the issue I mentioned earlier. They just placed the order immediately, while we were still talking. We think that they knew that delivery was going to take about five days — it was actually very fast.
How was the initial setup?
The initial setup and deployment were straightforward. We deployed it with RADIUS servers; it was not complex at all.
What about the implementation team?
From scratch to finish, deployment took about a month. It took this long because we had to convert all of our existing configurations from Cisco Firewall to Check Point. We had to get help from our vendor to do this. He had to manually convert each and every command from our existing Cisco device to Check Point — that took a while. This was the main reason that deployment took so much time.
The end-user VPN didn't take much time to deploy. Neither did the site-connecting with the VPN — that took a day or two to deploy.
What's my experience with pricing, setup cost, and licensing?
I think our licensing is on a yearly basis, but it could be every three years. Either way, it's not more than three years — that I am certain of.
The pricing was actually what made us go for Check Point. Palo Alto was much more expensive. Check Point offers the same applications and features as Palo Alto for roughly a third of the price.
Which other solutions did I evaluate?
We evaluated Palo Alto, Cisco (which we were using), and we also evaluated Check Point — which we ended up with.
What other advice do I have?
I would recommend Check Point to others. We are still learning as we're just about a year into using it, but so far, the support and the solution in general has been good. I'd recommend Check Point, especially to users that are looking for an affordable solution.
Check Point also has a great community. They have this community where users can go to share ideas. They also have great networks.
Overall, on a scale from one to ten, I would give this solution a rating of eight. Cisco dominated the African market until Check Point came along.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Check Point Quantum Force (NGFW)
August 2026
Learn what your peers think about Check Point Quantum Force (NGFW). Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
908,858 professionals have used our research since 2012.
AGM Cyber Security CoE at Bata Group
Flexible, provides good visibility, and it's easy to manage with a centralized dashboard
Pros and Cons
- "It creates granular security policies based on users or groups to identify, block or limit the usage of web applications."
- "In summary, this is an excellent product and featured consistently in Gartner for the last 10 years."
- "Although Check Point provides annual updates to the Gaia platform, integration with other OEMs is difficult."
- "Technical Support needs improvement, especially the L1 engineers."
What is our primary use case?
We use this solution for complete protection against advanced zero-day threats with Threat Emulation and Threat Extraction. We also use:
- NSS Recommended IPS to proactively prevent intrusions
- Antivirus to identify and block malware
- Anti-bot to detect and prevent bot damage
- Anti-Spam to protect an organization's messaging infrastructure
- Application Control to prevent high-risk application use
- URL Filtering to prevent access to websites hosting malware
- Identity Awareness to define policies for user and groups
- Unified Policy that covers all web, applications, users, and machines
- Logging and Status for proactive data analysis
How has it helped my organization?
The solution has improved the organization with respect to the following:
- Simple implementation and operation
- Central dashboard for managing branch firewalls
- Easy measurement of security effectiveness and value to the organization
- Proactive protection with the help of many inbuilt blades
- SandBlast Threat Emulation and Extraction provides us zero-day protection from known and unknown threats in real-time
- Great visibility on the number of threats being blocked at the dashboard
- Helps to clean traffic, both egress and ingress
- A simplified URL filtering option is available for users with detailed granularity to map user/departments with respect to specific access
- It does deep packet inspection for checking HTTPS traffic. There is a shift towards more use of HTTPS, SSL, and TLS encryption to increase Internet security. At the same time, files delivered into the organization over SSL and TLS represent a stealthy attack vector that bypasses traditional security implementations. Check Point Threat Prevention looks inside encrypted SSL and TLS tunnels to detect threats, ensuring users remain in compliance with company policies while surfing the Internet and using corporate data
- It helps in the identification of C&C via Anti-Bot
- It provides geolocation restrictions that may be imposed via IPS
- Excellent Application Control for the administrator to manage the access for users
- Secure remote access is configured with mobile access connectivity for up to five users, using the Mobile Access Blade. This license provides secure remote access to corporate resources from a wide variety of devices including smartphones, tablets, PCs, Mac, and Linux
What is most valuable?
We are using the Check Point Next-Generation Firewall to maximize protection through unified management, monitoring, and reporting. It has the following features:-
- Antivirus: This stops incoming malicious files at the gateway, before the user is affected, with real-time virus signatures and anomaly-based protections.
- IPS: The IPS software blade further secures your network by inspecting packets. It offers full-featured IPS with geo-protections and is constantly updated with new defenses against emerging threats.
- AntiBot: It detects bot-infected machines, prevents bot damage by blocking both cyber-criminals Command and Control center communications, and is continually updated.
- Application Control: It creates granular security policies based on users or groups to identify, block or limit the usage of web applications.
- URL Filtering: The network admin can block access to entire websites or just pages within, set enforcements by time allocation or bandwidth limitations, and maintain a list of accepted and unaccepted website URLs.
- Identity Awareness: This feature provides granular visibility of users, groups, and machines, enabling unmatched application and access control through the creation of accurate, identity-based policies.
What needs improvement?
I would like to see the provision of an industry-wide and global benchmark scorecard on leading standards such as ISO 27001, SOX 404, etc., so as to provide assurance to the board, and confidence with the IT team, on where we are and how much to improve and strive for the best.
Although Check Point provides annual updates to the Gaia platform, integration with other OEMs is difficult. This integration would be helpful in providing a full security picture across the organization. I am looking forward to the go-ahead of R81 with MITRE framework adoption in the future.
For how long have I used the solution?
We have been using the Check Point NGFW for the last four years.
What do I think about the stability of the solution?
This is a very stable product.
What do I think about the scalability of the solution?
It is highly scalable on cloud and does provide customers with lot of flexibility while performing the sizing of the appliance.
How are customer service and technical support?
Technical Support needs improvement, especially the L1 engineers.
Which solution did I use previously and why did I switch?
Prior to this solution, we were using GajShield. However, due to limited visibility and support, we opted for a technical refresh and upgrade of products.
How was the initial setup?
Yes initial setup was complex as migration of policies from one OEM to another is a challenge. however we meticulously planned and completed the implementation in phases.
What about the implementation team?
Yes we took help of the Certified Vendor. Vendor support was good.
What was our ROI?
We did not calculate our ROI; however, it provides good visibility to us.
What's my experience with pricing, setup cost, and licensing?
Check Point is competitively priced; however, there is an additional charge for the Annual Maintenance Contract (AMC) and it is easy to understand.
My advice is to negotiate upfront with a support contract of between three and five years.
Which other solutions did I evaluate?
We evaluated Palo Alto, Barracuda, and Fortinet.
What other advice do I have?
In summary, this is an excellent product and featured consistently in Gartner for the last 10 years. They have good R&D and support services across the globe.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Manager at Kotak Mahindra Bank
Good traffic visibility, integrates well with third-party solutions, and it's easy to implement
Pros and Cons
- "The threat emulation blade and user identity awareness feature has helped us a lot in terms of perimeter security and have given us granular visibility of user access."
- "Right now, with a larger user database and a high number of rules, it takes a bit of time for policy installation."
What is our primary use case?
The role NGFW plays is to protect the organization against Layer 7 network attacks.
The solution has helped us to guard our perimeter security on a wider level. This is not like plain vanilla firewall. We have got a wider visibility with the help of this next-generation firewall; it shows us the traffic flowing across the network and based upon that, we have made the modifications required to restrict access.
Also, the active cluster module has helped us to balance the load during peak hours. Since moving to the active-active module, we have got the much-needed breathing space.
How has it helped my organization?
It has helped us to inspect traffic, not only with a limited protocol base but on the application/service level inspection too.
The service base access policy has provided us with a next-level restriction, which wasn't there on old school firewalls.
The integrated threat & anti-bot blade gives us protection from zero-day attacks and these can be blocked using analysis & signature matching.
The integrated intrusion prevention blade not only gives an additional level of security but also cuts down the load to manage an extra device.
What is most valuable?
The threat emulation blade and user identity awareness feature has helped us a lot in terms of perimeter security and have given us granular visibility of user access.
The integration with third-party vendors is quite easy and well defined, which really helps you with the automation.
The integration of gateways with a centralized managed server gives you full control in a single place.
The setup and implementation are quite easy and the logs and reports are elaborative and effective for securing the network.
What needs improvement?
The one area that I would like to see a change in is policy installation. Right now, with a larger user database and a high number of rules, it takes a bit of time for policy installation. There is definitely some improvement in the R80 version; however, I believe that it should not take more than one minute to refresh the database. Also, there is a significant spike in gateway resource utilization during policy installation.
The additional blades have an impact on resource utilization, hence scope of improvement is needed here too.
For how long have I used the solution?
I am using Check Point NGFW for the past five to six years for perimeter & internal security.
What do I think about the stability of the solution?
The solution is quite stable, however some issues also observed in new version release & same is fixed through hotfix/portfix once it is highlighted to the TAC
What do I think about the scalability of the solution?
The new hyperscale module gives you the much-needed breathing space, which the industry was looking at for quite a long time.
How are customer service and technical support?
When it comes to technical support, Check Point is on another level. The support engineers are very well versed with the solution they are managing.
How was the initial setup?
The initial setup & integration was quite easy, and the support during migration was outstanding.
What about the implementation team?
It was a collaborative effort of our in-house and vendor teams. The support was good & quite appreciable.
What was our ROI?
It's good & the same as expected.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Works at Johnson Controls, Inc.
Easy to manage and use, affordable, with support that is knowledgeable and helpful
Pros and Cons
- "The uncomplicated configuration ensures that mistakes are avoided and rules are easily audited."
- "Check Point's solution is both affordable and easy to manage for the small business applications that we utilize them for."
- "The one thing I have been continually asking for is a more robust certification process including self-paced study material similar to Cisco's Security certification track."
What is our primary use case?
Our branch offices and customer sites require Internet access for the on-site staff and remote access capabilities for after-hours and remote support.
The Check Point firewalls allow us to provide site-to-site VPN, client VPN, web/app filtering, and IPS functionalities.
Client VPN is leveraged by site staff due to the majority of our sites requiring 24-hour support and also allows centralized teams to remotely assist with multiple sites globally.
We also use these at locations to provide security when our stand-alone network requires connectivity to the customer's network.
How has it helped my organization?
Check Point's solution is both affordable and easy to manage for the small business applications that we utilize them for. Due to the great pricing and support, we can afford to deploy the firewalls in a high-availability solution providing greater uptime and less worry.
The price point of their equipment also means that we can often purchase a more robust solution compared to some competitors and Check Point's inclusion of more advanced features, such as IPS, by default, is a great selling point.
What is most valuable?
We greatly appreciate the ease of configuring firewall policy ACL rules and how the seamless integration with VPN users and user groups provides the ability to granularly restrict access. The uncomplicated configuration ensures that mistakes are avoided and rules are easily audited.
Having the ability to set an expiration date for remote access VPN users simplifies the process and increases security by ensuring that stale accounts and not forgotten.
In general, we find that CheckPoint offers a great balance between ease of use and configurability.
What needs improvement?
The one thing I have been continually asking for is a more robust certification process including self-paced study material similar to Cisco's Security certification track. Not everyone can afford the time and money to attend the official in-person classes offered by Check Point. Even if someone was not interested in fully pursuing a certification, offering certification guides is often a method that IT professionals follow in order to learn about a specific topic and keep for reference.
An area that I sometimes find lacking is the information provided by the system when performing troubleshooting issues such as site-to-site VPN tunnels. The logs provide general information regarding what is happening but often, it leaves you wanting additional details. This also ties back into the lack of training and knowledge required to utilize the more advanced features of the command line.
For how long have I used the solution?
We have been using Check Point NGFW for more than five years.
What do I think about the stability of the solution?
We have never had a device or software failure in the more than five years that we have been using Check Point devices. To date, we are extremely happy with the performance.
How are customer service and technical support?
The few times that we required customer service, they have been extremely helpful and knowledgeable. I would rate them on par with the other top-tier companies.
Which solution did I use previously and why did I switch?
We previously utilized Cisco firewalls but the cost structure of the hardware, licensing, and support became prohibitive. Check Point offered a more robust solution at an affordable price point.
How was the initial setup?
The initial setup was extremely quick and easy, and the deployment time for a new site is often under a day.
What's my experience with pricing, setup cost, and licensing?
The price point and licensing was the main factor in moving away from Cisco and migrating all of our sites to Check Point. They offered more features for a lower cost than competitors, and the licensing model was easy to understand.
Which other solutions did I evaluate?
We evaluated NGFWs from Cisco, Palo Alto, and Fortinet in addition to the Check Point.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network, Systems and Security Engineer at SOLTEL Group
Good support, provides deep packet inspection, and offers sandbox capabilities
Pros and Cons
- "I think that the most valuable feature is the prevention of known and zero-day threats because they are constantly trying to access your company and compromise its data."
- "Previously, I used Fortinet but Check Point provides us with more features."
- "Check Point products have many places that need to be improved, but they are constantly upgrading."
What is our primary use case?
Nowadays, there are many threats and it's necessary to have an automatic process to defend your organization. The Check Point NGFW is a good solution for this use case.
How has it helped my organization?
For my organization, CheckPoint NGFW helped us with enforcing threat prevention.
Threat prevention capabilities are a natural extension of next-generation firewalls' deep packet inspection capabilities. As the traffic passes through the device, they also inspect the traffic for known exploits of existing vulnerabilities (IPS).
Files can be sent off-device to be emulated in a virtual sandbox to detect malicious behavior, named sandbox security.
I think that the main benefit of an NGFW is the ability to safely enable the use of Internet applications that empower users to be more productive while blocking less desirable applications.
What is most valuable?
I think that the most valuable feature is the prevention of known and zero-day threats because they are constantly trying to access your company and compromise its data. It is very important to have your solution always update for this.
I think that another important feature is that it is a cloud solution. More and more companies have all of their systems in the cloud and the threats are pointing here.
The features that a next-generation firewall includes are application and user control, integrated intrusion prevention, advanced malware detection such as sandboxing, and leverages threat intelligence feeds.
What needs improvement?
Check Point products have many places that need to be improved, but they are constantly upgrading.
For how long have I used the solution?
I have been using Check Point NGFW since 2015.
How are customer service and technical support?
Check Point has a good support department and they are always ready to help you.
Which solution did I use previously and why did I switch?
Previously, I used Fortinet but Check Point provides us with more features.
I used this solution for the first time in 2015 when I worked for a local Internet Service Provider. At that point, I used the R77.30 console and I saw all of the good features that it provided.
Now, I use R80.30 in my current company and these products are the best in the market. This company is going to be at the forefront and you can complete your solution with other products in their portfolio.
How was the initial setup?
Today’s next-generation network firewall can be found deployed on-premises at the edge of enterprises and branch offices, on-premises at internal segment boundaries, in public clouds such as Amazon (AWS), Microsoft Azure, and the Google Cloud Platform. They are also deployed in private clouds.
What's my experience with pricing, setup cost, and licensing?
The licensing includes the cost of support.
Which other solutions did I evaluate?
We evaluated many others options including solutions by Fortinet, Palo Alto, SonicWall, etc.
We think that Check Point is the best because they are at the forefront.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Chief Information Security Officer at Abcl
Good support, flexible, scales well, and provides centralized policy management
Pros and Cons
- "It provides access to the Internet for corporate resources in a secure manner."
- "The firewall throughput or performance reduces drastically after enabling each module/blade."
What is our primary use case?
The primary use is to protect the organization from any kind of attack. It is able to isolate, secure, and control every device on the network at all times. Solutions should have the ability to block infected devices from accessing corporate data and assets.
It provides access to the Internet for corporate resources in a secure manner. Our resources are used to host applications and services that are accessible to end-users over the Internet.
It is used to provide required/limited access for third parties who want to connect to our corporate network. Access is granted based on application type and should be independent of port or protocol.
It provides next-generation protection including IPS/Web Filtering/SSL decryption and more.
It offers centralized policy management capabilities for all firewalls.
How has it helped my organization?
This solution was able to provide access to our internet-based resources using our application/FQDN.
The license offers different modules for NGTP and SNBT. It provides multiple functionality or blades, which can be enabled on the firewall depending upon organizational requirements.
Other than stateful packet filtering with the NGTP license, it provides blades such as IPS/URL/VPN/Application Control/content awareness/Anti-Bot/Anti-Virus/Anti-Spam. With SNBT, it provides additional security using the SandBlast Threat Emulation and SandBlast Threat Extraction for Zero-day attacks in real-time.
Any file, before it reaches an endpoint, is executed in a virtual environment for analysis. Based on the verdict and configured policy, a decision will be made as to whether it should be delivered to the endpoint or not.
What is most valuable?
It provides the flexibility to use any module with the NGTP and SNBT license. Depending upon the requirements, the blades/module can be enabled on the firewall security gateway and it can be deployed easily.
In case SSL decryption or IPS need to be enabled on any security gateway, it is simple to do. We can go ahead and enable the module/blade and then create a policy, deploy it, and it will start to work.
It has a default five-user license for Mobile/SSL VPN, so the organization can check the solution any time or can even provide access to critical users on an as-needed basis, without getting the OEM involved, all on the same box.
For smaller organizations with the correct sizing of the appliance, they can use the full security solution on a single box. It will provide financial benefits along with reducing the cost of purchasing additional solutions or appliances.
For example:
- URL Filtering Module: It can replace the proxy solution for on-premises users with integration of application control and the Identity module. Active Directory access can be provided based on the User ID and the website or application.
- SSL VPN or SSL decryptor, and more.
- Core assignment for each interface, which can be done using the CLI. If the administrator determines that a particular interface requires more compute, he can manually assign additional cores accordingly. This is done by enabling hyperthreading on the firewall.
- The policy can be copied from any security gateway and pasted onto another one.
What needs improvement?
This is a zone-based firewall, which differs from other firewall solutions available on the market. It changes the way the admin manages firewall policy. The administrator has to be careful while defining policy because it can lead to configuration errors, allowing unwanted access.
For example, if a user needs to access the internet on the HTTPS port, then the administrator has to create a policy as below, rather than using NAT for assigning the user's machine to a public IP.
Source: User machine
Destination: any
Port: HTTPS
Action: allow (for allowing the user's machine access)
This has to be done along with the below policy:
Source: User machine
Destination: Other Zone created on Firewall
Port: HTTPS
Action: block
The two policies, together, mean that the user's machine will not be able to communicate with any other L3 Network created on the firewall.
The firewall throughput or performance reduces drastically after enabling each module/blade.
It does not provide for standalone configuration on the security gateway. Instead, you need to have a management server/smart console for managing it. This can be deployed on a dedicated server or can be deployed on the security gateway itself.
For how long have I used the solution?
I have been using the Check Point NGFW for more than eight years.
What do I think about the stability of the solution?
This solution is very much stable and does not require frequent changes in architecture. The patch frequency is limited and it does not require frequent maintenance windows in terms of downtime.
What do I think about the scalability of the solution?
This firewall is very much scalable. The introduction of Maestro has changed the concept of hyperscaling.
How are customer service and technical support?
The technical support is excellent. The center is located in major cities in India along with the Check Point presales team.
Which solution did I use previously and why did I switch?
We did not use another solution prior to this one. We have been using Check Point for a long time.
How was the initial setup?
During the initial setup, support is excellent. It is a well-known OEM and they have people ready to resolve any issue that should arise.
What about the implementation team?
Our in-house team deployed it with support from the OEM.
What's my experience with pricing, setup cost, and licensing?
Cost-wise, it cheaper than industry leaders such as Palo Alto. The licensing is straightforward; there are only three types of licenses that include NGFW, NGTP, and SNBT, so the organization can choose its license according to their requirements.
Which other solutions did I evaluate?
We have evaluated solutions by Juniper, Cisco, and Palo Alto.
What other advice do I have?
Before implementing the security gateway, you need to be sure about the license and modules that you are going to enable. This includes determining the proper size, as it can affect throughput drastically after enabling each module. This is especially true for SSL decryption.
The architecture needs to be studied before finalizing, as the configuration is done remotely using the centralized smart console. All of the security gateways need to be connected to the management server for any policy configuration, and they should be available at all times.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Network Engineer at LTI - Larsen & Toubro Infotech
Centralized management, good VPN functionality, provides valuable insights into our traffic
Pros and Cons
- "The SmartView monitor and SmartReporter help us to monitor and report on traffic."
- "Managing all of our user VPNs, customer VPNs, and Cloud VPN tunnels' endpoint encryption from a single management portal is helping us."
- "Integration with a third-party authentication mechanism is tricky and needs to be planned well."
- "Support might take a long time to resolve issues in rare scenarios."
What is our primary use case?
We have deployed Check Point firewalls for perimeter security and also for filtering East-West traffic.
Check Point helps in improving perimeter security along with giving insights into different kinds of traffic and attacks.
Isolation between different tiers of APPs is critical for us and Check Point is utilized for handling high traffic volumes of East-West traffic.
We are leveraging the VPN module on the perimeter firewall for users to access the VPNs. VPN authentication is integrated with RSA for multi-factor authentication.
How has it helped my organization?
We have reduced the number of firewalls using the VSX cluster from Check Point. This reduced management overhead to a great extent. Also, the stability of clustered firewall helps us in meeting SLAs with clients.
Check Point firewalls can be tuned for one-off cases like allowing out-of-sync packets for a source-destination pair, which is a feature that helped us tackle application issues.
We have deployed VPN firewalls in multiple data centers, which help with load sharing and redundancy for the VPN traffic.
Managing all of our user VPNs, customer VPNs, and Cloud VPN tunnels' endpoint encryption from a single management portal is helping us.
What is most valuable?
VSX helps to reduce the physical footprint on datacenter racks.
The SmartView monitor and SmartReporter help us to monitor and report on traffic.
Centralized management and management high availability give the ability to manage firewalls in a DR scenario.
Features such as the ability to simultaneously edit the rule base by multiple admins and revert to a previous rule base revision are very useful.
Having a separate appliance for logging helps us in meeting the security audit requirements, without having an overhead on management.
What needs improvement?
Configurations can be complex in some situations and need experienced engineers for managing the solution.
Integration with a third-party authentication mechanism is tricky and needs to be planned well.
SmartView monitor can be enhanced to display granular details of gateways with a single click. Also, having the ability to generate alerts from the Smart Monitor would be a nice feature.
For how long have I used the solution?
We have been using Check Point firewalls for the last eight years.
How are customer service and technical support?
Support might take a long time to resolve issues in rare scenarios.
What other advice do I have?
My advice for anybody who is implementing this solution is to always keep an identical configuration, even interface statuses, in a VSX cluster before an upgrade to minimize upgrade failures.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IP LAN and Integrity Specialist at Chevron
Skilled support engineers, provides good control with central management
Pros and Cons
- "The packet inspection capabilities are great."
- "This product has provided us the total control of our connections in our very bandwidth and session-intensive environment."
- "The virtual infrastructure of the central management requires a huge amount of resources to work properly and manage all the logs without problems."
What is our primary use case?
We use this solution as a layer 3/4 firewall deploying access rules in our DMZ. We have more than six different centers with different service layers, a core of up to 500Gb per site, and other service centers providing security for all inbound and outbound connections.
VSX gives us the capacity to consolidate hardware in fewer devices, reducing the OPEX, and creating different VFWs to provide service to different environments or services.
Layer 7 features allow us to upgrade our security services. Activating the required features only requires upgrading the license.
How has it helped my organization?
This product has provided us the total control of our connections in our very bandwidth and session-intensive environment. It offers high capacity on NAT tables that, with other vendors, needed to use really huge devices to support.
We can control all of our international connections in a central point with a distributed cluster in a very easy way and with good performance.
The layer 7 features (AV, IPS, Web filtering, etc) and integrations with AWS provide us a clear point of management for future deployments on the cloud.
What is most valuable?
The packet inspection capabilities are great.
ARP protections based on interface works better than it does with other vendors.
There are new improvements related to the upgrade of the solution, making for the easiest upgrade/update procedures.
New features allow for concurrent use of the console in write mode between different users.
The exposed API allows us to automate a lot of actions in a very easy way.
The central console and log collector are basically the best central management consoles, and each day provides new useful features like counts, etc.
What needs improvement?
There are issues with stability in some specific versions.
The VPN is a little difficult to configure, and sometimes you need help from Check Point professional services.
There are some performance problems with the IPS when the FW is in a high load, but in general, it is working better than in previous versions.
The routing is configured on the gateway, so, you need to remember for migration purposes.
The virtual infrastructure of the central management requires a huge amount of resources to work properly and manage all the logs without problems.
For how long have I used the solution?
I have been using Check Point NGFW for more than 10 years.
What do I think about the stability of the solution?
In general, this is a very stable solution. We have had only one incident in the last few years that was with the size or the route tables in memory that finally it was discovered that was a bug in a specific version and was solved upgrading the devices to new firmware that solved the bug
What do I think about the scalability of the solution?
This product is very scalable. There are a lot of different virtual and physical devices to cover any requirement in terms of sessions, performance, etc.
How are customer service and technical support?
We are very happy with the support. They are very skilled engineers and always fast at analyzing and solving issues.
Which solution did I use previously and why did I switch?
We did you another solution, but we switched due to prices and solution stability.
How was the initial setup?
The initial setup is not more complex than other solutions.
What about the implementation team?
Was implemented using a third-party vendor.
What was our ROI?
Our ROI with this firewall is high.
What's my experience with pricing, setup cost, and licensing?
The vendor has a very flexible licensing approach.
Cost per Gb reduced and reduced OPEX compared with other vendors.
Which other solutions did I evaluate?
We evaluated Fortinet, Juniper, and Palo Alto.
What other advice do I have?
This is a complex solution and there are other vendors that are easier to manage, but it is perhaps the best solution regardless.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Security Engineer at a tech services company with 10,001+ employees
Good support, granular policy configuration options, and a good VPN that facilitates remote working
Pros and Cons
- "There are many useful features including the Office VPN, which provides us with a seamless connection for users who are working remotely."
- "This solution has improved the way our organization functions in multiple ways."
- "There are two major areas that need to be improved. The study material for Check Point needs to be improved, as well as the cost for certification."
What is our primary use case?
The purpose of using the firewall is to protect the users from the external network, internet. Apart from that, we have set up IPsec tunnels between two different sites, and for internal usage, between two different zones, we use these firewalls as well.
Our environment consists of a 3-tier architecture, which is recommended by Check Point. We use the central management system to manage our 3-tier architecture, and we use the Smart Console as well.
How has it helped my organization?
This solution has improved the way our organization functions in multiple ways. For example, during the pandemic situation, things completely shifted. People who are working from the office are now working from home, and it is our responsibility, as network security engineers, to monitor the home users. We do not want them to access any blacklisted sites and we want to make sure that they are protected from threats and risks from the internet.
With the Office Mode VPN, it would not be possible to manage work from home because the security would not be in place. We have more granular security options with this firewall.
What is most valuable?
There are many useful features including the Office VPN, which provides us with a seamless connection for users who are working remotely. This is helpful for our employees that are working from home, as they get the same office environment as if they were on-premises. It is also helpful for us as an organization because we have good control and visibility over their data, including network traffic packets.
What needs improvement?
There are two major areas that need to be improved.
The study material for Check Point needs to be improved, as well as the cost for certification. One of my friends recently completed the certification and it was costlier than other firewall security certificates.
The reports are generally good but there is not much control. We would like to have more filters. Essentially, we want more granular reporting.
For how long have I used the solution?
I have been using Check Point NGFW since 2018.
What do I think about the stability of the solution?
There are no issues with stability that we have found. It is a good brand, and it is one of the oldest and finest firewalls on the market right now.
What do I think about the scalability of the solution?
Scalability is not a problem. It has both UI and CLI-based options to configure it, and it is not difficult to extend or scale. We have between four and six deployments and we plan to continue using it in the future. As we are growing, we will continue to expand its usage.
We have about 12 people working directly with Check Point NGFW. There are approximately 4,000 users who are indirectly using it, as their traffic passes through the firewall. It is used by the entire organization.
How are customer service and technical support?
We have support available from the Check Point TAC team. Our experience with them has been pretty good. We haven't had any issues or problems communicating with them or getting a solution from them.
Which solution did I use previously and why did I switch?
Prior to Check Point, we were using Cisco ASA.
The problem with Cisco ASA is that it is a purely CLl-based firewall. Check Point is not only UI and CLI-based, but it is also a next-generation firewall. It has many different and more advanced features, compared to Cisco ASA.
For example, in Cisco ASA, we can use only two gateways in active-active mode, but with this product, we can use five gateways at a time. Another difference is that the Cisco ASA policy configuration options are not as granular as Check Point.
How was the initial setup?
The initial setup process was very straightforward.
Our deployment took between seven and eight months, which included replacing our Cisco ASA firewall. It began with the planning, then implementation, followed by validation, and then we replaced the existing firewall. It would have been a little complex for us, but we did it all in a very straightforward manner.
What about the implementation team?
We have a very good in-house engineering team that does the setup and configuration. We did not require any third-party assistance because we have had full training on it.
Our deployment included seven or eight people who were working in different shifts. Similarly, we have three to four network security engineers working in shifts who maintain it. This includes things like dealing with tickets for updating policies.
What was our ROI?
We are happy with the return that we are getting from this firewall.
Rather than money, this product is saving the security of our organization. This is the first thing that we were looking for, before deploying this firewall in our organization. We know that ASA is cheaper than Check Point, but our concentration was making the environment more secure.
Cost-wise, it is more expensive than Cisco ASA, but the returns include better security and more granular options. We are happy with that. We were not looking to save money but rather, providing a safer environment for our users.
What's my experience with pricing, setup cost, and licensing?
The price of this product is not too costly and you do not need to pay for all of the features. It is more expensive than Cisco ASA, yet cheaper than a similar product by Palo Alto. The cost varies, depending on the service. For example, we have opted for Geo Protection, which is something that costs extra, but we wanted that feature.
Which other solutions did I evaluate?
We did not evaluate other options. We only compared the differences between our existing Cisco ASA implementation and Check Point.
What other advice do I have?
The biggest lesson that I have learned from using this product is that the TAC team is very knowledgeable and supportive. If I want to understand something or if I have doubts, then usually clear it up and make sure that I understand the logic. I have learned a lot from them.
This is a product that is rich in features and my advice for anybody who is deploying it for the first time is to learn about them in advance. It is a little bit different than a CLI-based firewall and I recommend learning about all of the features before deploying it.
At this point, we are happy with the results that we are getting from Check Point, and are not looking to replace it. It works as we were expecting before it was deployed.
I would rate this solution a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
Download our free Check Point Quantum Force (NGFW) Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2026
Popular Comparisons
Fortinet FortiGate
Cisco Secure Firewall
Netgate pfSense
Sophos Firewall
Palo Alto Networks NG Firewalls
WatchGuard Firebox
Cisco Meraki MX
Check Point Cloud Firewall (formerly CloudGuard Network Security)
Azure Firewall
Palo Alto Networks VM-Series
Fortinet FortiGate-VM
Juniper SRX Series Firewall
SonicWall TZ
Buyer's Guide
Download our free Check Point Quantum Force (NGFW) Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- How does Check Point NGFW compare with Fortinet Fortigate?
- Is Palo Alto Networks NG Firewalls better than Check Point NGFW?
- Which would you recommend - Azure Firewall or Check Point NGFW?
- Is Check Point's software compatible with other products?
- What do you recommend for a corporate firewall implementation?
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Which is the best network firewall for a small retailer?
- When evaluating Firewalls, what aspect do you think is the most important to look for?
- Cyberoam or Fortinet?












