What is our primary use case?
My main use case for Check Point NGFW is that it was deployed at the network edge to protect and manage incoming and outgoing traffic from the corporate network, which is controlled by Check Point firewall. We have implemented application control, URL filtering, content filtering, and similar features. This enables us to manage the traffic by creating granular policies, IP space, or user-based policies. The main use case is to control the inward traffic and stop cyber threats at the network edge only.
What is most valuable?
Check Point NGFW offers excellent features such as implementation of content awareness, application filtering, URL filtering, HTTPS inspection, IPS, and identity-based integration with LDAP, which we were able to implement. The user-based policies we have configured help us avoid unwanted malicious sites and ensure there is no malware being downloaded into the network, meaning there are no disruptions in network production. All users are focusing on their desired tasks, which has a positive impact by avoiding business disruptions. That's the main impact I can say, as it indirectly helps the organization keep their users focused and stay away from any kind of cyber threats.
Check Point NGFW has positively impacted my organization as the incidents have reduced, resulting in no disruptions in the network. Everything is running smoothly and the organization is protected by Check Point firewall. The users are doing their desired tasks very efficiently, and everything is live in the network or applications, providing excellent security. Therefore, there is no business disruption so far.
What needs improvement?
To improve Check Point NGFW, I would suggest that AI features, such as Auto AI autopilot, would be greatly appreciated because they can automate most of the tedious tasks that take a lot of time. Having features such as AI can make the process easier.
A specific task I'd like to automate with AI in Check Point NGFW is adding multiple users, users and address group configuration of address groups and addresses, along with exporting firewall addresses in a certain format. That kind of feature should be there, or if we try to export the data from the Check Point firewall, we get only group address group names without seeing whatever members of the address are included.
Check Point should provide the feature of exporting group data with address groups, so when I export address books, only the group name is visible in the Excel file. Instead, it should show the actual members of the groups getting exported. That kind of feature would be appreciated.
For how long have I used the solution?
I've been using Check Point NGFW for more than one and a half years as an admin.
What do I think about the stability of the solution?
In my experience, Check Point NGFW is stable.
What do I think about the scalability of the solution?
The scalability of Check Point NGFW is good, and we can integrate it with third-party solutions, such as Nexus 2FA. I have seen this kind of setup in one of the client environments.
How are customer service and support?
Customer support for Check Point NGFW is quite good. I would rate the customer support an eight on a scale of one to ten.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
I did not previously use a different solution before Check Point NGFW.
How was the initial setup?
The initial setup with Check Point NGFW is straightforward.
What was our ROI?
I have seen a return on investment with Check Point NGFW as it helps reduce business disruptions, indirectly allowing the organization to focus on their desired tasks and get things done properly while saving time and avoiding unexpected disruptions. This time savings has contributed to company growth happening at the backend.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for Check Point NGFW indicates that the pricing is comparatively higher compared to other vendors, but it is worth it when considering the features. It is justifiable.
Which other solutions did I evaluate?
I don't have knowledge about evaluating other options before choosing Check Point NGFW.
What other advice do I have?
When using application control and URL filtering, I would share my experience where the organization used these features to block unwanted applications and allow only legitimate specific applications such as LinkedIn, Dropbox, and OneDrive, which should be accessible to all employees. Rest applications such as Facebook, YouTube, WhatsApp, WeChat, and other file-sharing applications should be blocked in the networks, and no one should access those applications. For web filtering, users can only visit legitimate websites; they should not visit any hacking or malicious websites, only financial, government websites, and internal applications should be accessible to users. We have configured these types of policies for the organization.
My advice for others looking into using Check Point NGFW is to utilize multiple features of the Check Point firewall. There is a huge list of features in the SmartConsole, so implementing most of the features such as application control and HTTPS inspection can be beneficial.
I would rate Check Point NGFW a nine out of ten because I am expecting a few features that are missing in the Check Point firewall, which I already mentioned.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner