The main use case for Check Point NGFW is providing perimeter security, as the Check Point firewall is deployed at the edge to control all incoming and outgoing north-south traffic, used as a combination of features including URL filtering, application control, IPS, content awareness, identity provider, IPsec tunnel, and SSL VPNs, and was specifically deployed in one of the head office locations as a perimeter firewall to control all in-out traffic.
Performance wise NGFW has handled high volumes of traffic with minimal latency , even during peak times, and the regular updated & support from check point have ensured continue reliability. One of the key improvements we have noticed is better visibility into application usage and user behaviour, allowing us to enforce more granular policies. Check point NGFW has significantly strengthened our organization's network security posture.
The best features offered by Check Point NGFW that stand out are its high detection rate for catching threats, uptime with very low business disruptions even during firmware upgrades, and features such as application control, URL filtering, IPS, and HTTPS inspection, all of which provide granular control over applications with thousands of applications available for policy implementation.
With around 3,000 users working under the organization, the Check Point NGFW safeguards users by protecting their internet browsing experience with features such as antivirus, anti-spoofing, and URL filtering control, ensuring we have control over what users can access and block malicious content from entering the organization's network.
HTTPS inspection for web traffic with Check Point NGFW decrypts and inspects all internet traffic, allowing the firewall to read the content being passed through, and with a threat detection rate around 99%, we have not noticed any breaches or business disruptions.
HTTPS inspection with Check Point NGFW works by decrypting incoming and outgoing HTTPS traffic, allowing the firewall to inspect and detect threats by reading the entire packet in clear plain text.
Check Point NGFW includes SSL VPNs as part of its feature set.
Performance under load : In high traffic environment, we've observed occasional performance bottleneck.
Licensing Flexibility : The licensing model can be rigid and expensive, particularly for small to mid-sized organisations.
I have been using Check Point NGFW for the last two years while working in operations and providing technical support. In our daily use cases, I utilize it as a next-generation firewall for overall features such as application control, URL filtering, IPS, and many other capabilities.
I am Somesh Kadam, a cybersecurity professional with two years of experience in implementation and technical support. I currently work with Softcell Technologies as a Technical Specialist, where I have extensive hands-on experience with firewalls such as Check Point, Fortinet, Palo Alto, and email security. I am currently exploring Zscaler as well.