We were looking for a solution to simplify our hybrid cloud infrastructure. We wanted something that could manage both our on-premises and cloud environments seamlessly. Nutanix offered that unified management plane. We also needed to improve our disaster recovery capabilities.
Senior Cyber Security Engineer at a computer software company with 501-1,000 employees
Unified management streamlines hybrid cloud operations and boosts disaster recovery, while initial setup complexity poses challenges
Pros and Cons
- "We've tested failover scenarios, and they worked flawlessly."
- "Licensing can be a bit complicated."
What is our primary use case?
How has it helped my organization?
It's been really good. It simplified our operations significantly. We're able to manage everything from a single pane of glass, which has been a huge time saver.
What is most valuable?
The Prism Central management console is excellent. It gives us a centralized view of our entire infrastructure. Also, the built-in disaster recovery capabilities have been essential. We've tested failover scenarios, and they worked flawlessly. It simplified our operations significantly. We're able to manage everything from a single pane of glass, which has been a huge time saver.
What needs improvement?
The initial setup was a little complex, but Nutanix support helped us through the process. Also, licensing can be a bit complicated.
Buyer's Guide
Check Point Quantum Force (NGFW)
September 2026
Learn what your peers think about Check Point Quantum Force (NGFW). Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,109 professionals have used our research since 2012.
For how long have I used the solution?
We've been using it for about two and a half years now.
How are customer service and support?
Nutanix support helped us through the process when the initial setup was complex.
How was the initial setup?
The initial setup was a little complex, but Nutanix support helped us through the process.
What's my experience with pricing, setup cost, and licensing?
Licensing can be a bit complicated.
What other advice do I have?
Absolutely. Especially for companies looking to simplify hybrid cloud management and improve disaster recovery.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Administrator at POET, LLC
Efficiently manages large-scale firewall deployments and improves threat detection
Pros and Cons
- "I would rate the overall solution ten out of ten."
- "Pricing is high, but it's worth it."
What is our primary use case?
We use Check Point NGFW for edge firewalls as well as internal segregation firewalls. It easily allows us to separate critical traffic from non-critical office traffic.
What is most valuable?
We use Check Point NGFW for edge firewalls as well as internal segregation firewalls. It easily allows us to separate critical traffic from non-critical office traffic. Check Point ThreatCloud is excellent. Their central management console makes managing hundreds of firewalls very easy, and their antivirus that's part of the ThreatCloud is very good. Since implementing it, we have noticed a lot less getting through that maybe other antivirus within firewalls had failed to catch.
What needs improvement?
Pricing is high, but it's worth it. That's the main one.
For how long have I used the solution?
I have been using Check Point NGFW for over ten years.
What do I think about the stability of the solution?
Check Point NGFW is stable.
What do I think about the scalability of the solution?
Check Point NGFW has excellent scalability.
How are customer service and support?
Customer support is excellent.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We did previously use several solutions from SonicWall and other vendors, and Check Point was just a better overall solution for our environment.
What about the implementation team?
Make sure to get a good third-party consultant or something to assist you, as the learning curve is steep at first.
What was our ROI?
We have seen a good return on investment. However, I do not have any metrics I can easily share.
What's my experience with pricing, setup cost, and licensing?
All good. No issues.
Which other solutions did I evaluate?
We evaluated a few other companies. The main one, or the biggest competitor, was Palo Alto.
What other advice do I have?
Make sure, if you do not have any experience with Check Point, to get a good third-party consultant or something to assist, as the learning curve is steep at first, but well worth the end benefit. Reliability, customer support, and just overall excellence. I would rate the overall solution ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Check Point Quantum Force (NGFW)
September 2026
Learn what your peers think about Check Point Quantum Force (NGFW). Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,109 professionals have used our research since 2012.
Sr. Cyber Security and Solutions Architect at a consultancy with 201-500 employees
Robust security and seamless integration enhance classified application management
Pros and Cons
- "One of the most valuable features is the ability to whitelist and blacklist sources to control access to our ecosystem, ensuring secured SaaS application access."
- "I would absolutely recommend this solution to others for its robust security and scalability."
- "The graphical user interface (GUI) could benefit from some updates."
What is our primary use case?
We use the Check Point Next Generation Firewall for whitelisting and blacklisting of addresses. It's part of our identity management solution and is utilized for inbound and outbound traffic services.
Additionally, it is integrated with our DMZ, managing traffic from an IP addressing scheme. We also use it for monitoring different types of classified and nonclassified applications.
How has it helped my organization?
Check Point has improved our organization's ability to manage both classified and nonclassified applications securely, ensuring they pass through multiple layers of security within our firewall infrastructure.
What is most valuable?
One of the most valuable features is the ability to whitelist and blacklist sources to control access to our ecosystem, ensuring secured SaaS application access. It provides robust security across classified and nonclassified applications and integrates well with our existing infrastructure.
What needs improvement?
The graphical user interface (GUI) could benefit from some updates, although it is generally satisfactory in its current form.
What do I think about the stability of the solution?
The solution is stable, and I have the utmost confidence in its software stability.
What do I think about the scalability of the solution?
The application is very scalable, allowing us to manage security across different network layers and support various applications and activities.
How are customer service and support?
Customer support quality depends on the person you interact with. However, the support team we engaged was knowledgeable and well-versed with the application, allowing us to resolve any potential issues effectively.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We switched to Check Point due to cost and maintenance benefits. The previous solutions required significant resources to handle network and communication alignment during upgrades.
How was the initial setup?
The initial setup is straightforward, with no significant issues arising from the box configuration.
What about the implementation team?
Our implementation team comprised about thirty individuals, including supervisors for each stage, to manage testing, validation, staging, and production.
What was our ROI?
We conducted a detailed analysis and determined a high return on investment. Maintenance and stability were key factors contributing to a favorable ROI.
What's my experience with pricing, setup cost, and licensing?
We found the pricing reasonable, ensuring the product was not overpriced. However, I am not familiar with the exact cost details.
What other advice do I have?
I would absolutely recommend this solution to others for its robust security and scalability.
I'd rate the solution ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Associate Vice President at Novac Technology Solutions
Real-time prevention is there to protect against zero-day malware
Pros and Cons
- "The CPU-based emulation is a better feature than any technologies not having that."
- "The drawback is that I want to push the policy from my management console itself instead of on the Check Point device."
What is our primary use case?
I use it for UTM [Unified Threat Management]. I use a gateway firewall at the office.
What is most valuable?
Next Generation Firewall, along with Threat Emulation and Threat Extraction, is what I use. Real-time prevention is there to protect against zero-day malware and Check Point Sandbox.
And then, the CPU-based emulation is a better feature than any technologies not having that. Check Point has a CPU-based emulation. Normally, Fortinet and others, they do it differently. But these people work on a technology called CPU-based emulation.
This CPU-based emulation is a unique CPU-level technology that catches malware before it has an opportunity to deploy or evade detection. They call it SandBlast. Check Point SandBlast Threat Emulation. That is a great feature, which they are using. It controls attempts to bypass OS security controls also. And then it avoids deep security.
I use our Check Point firewall for all the NATing of my applications. I use it for external traffic monitoring where my Internet links are connected, and I use it as a gateway.
What needs improvement?
The drawback is that I want to push the policy from my management console itself instead of on the Check Point device. For example, if I have two different firewalls, I want to push the policy to the gateway, and then it will take 10 to 20 minutes to roll back the policies. It should be applied faster.
For how long have I used the solution?
I have been using it for more than a year.
What do I think about the stability of the solution?
It is a stable product 99.4% of the time.
What do I think about the scalability of the solution?
Check Point NGFW has a feature where it can top two of the firewalls, and then we can integrate the performance.
It's a cluster kind of solution where they can integrate.
How are customer service and support?
For the firewall, the support is good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I also use CloudGuard Security Posture Management. I also used Fortinet.
The major difference, I feel, is the threat emulation. It's zero-day protection. The supply chain attack is very, very low compared to all firewall vendors.
For example, being parallel to Palo Alto Networks or FortiGate and NFT OS or Check Point, that supply chain attack was very, very low in our Check Point firewall. And then the maintenance was very, very low compared to all.
That is my takeaway. My one of my takeaways before proceeding with my procurement decision was that there are two things: one is the security point. Another one is performance. The last one is very, very important. That is for the supply chain attack because we need to concentrate more on other products also.
So I don't want to spend too much time on the maintenance part. So this supply chain attack was very, very less compared to other providers since we are using multiple firewalls. This particular firmware was very stable, and there was no need to update until unless it is necessary and shared by Check Point team. So my takeaway is that the supply chain attack was very less compared to all.
How was the initial setup?
If the person knows the technology and the basic functionalities of a firewall, they can integrate it very fast.
We took three days to deploy.
What about the implementation team?
Three people were involved: my IT security manager, myself, and one L3 engineer who deployed the product.
The architecture and functionalities are managed by me, and then the deployment is taken care of by our team members.
What's my experience with pricing, setup cost, and licensing?
Compared to Fortinet and Check Point, both are the same.
What other advice do I have?
Check Point is coming up withsome AI integration and some AI features. They are using threat emulation on the AI front, but they are also discussing the quantum processor, where they have integrated many new features.
Overall, I would rate it a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Enterprise Security Architect at Cyqurex Systems Ltd
A reliable and robust security solution with a wide range of capabilities
Pros and Cons
- "Its simplified management, enhanced remote support capabilities, and the ability to facilitate secure VPN connectivity for numerous offices and employees are highly beneficial."
- "The current model is predominantly hardware appliance-based, which can incur substantial costs"
What is our primary use case?
The primary objective was to replace the Cisco ASA firewalls with Check Point NGFWs. In addition to their firewall functions, these NGFWs also provide features like Web Application Firewall and Network Data Security. We used this approach to consolidate security measures into a single, comprehensive solution, much like having a master key at the main entrance rather than separate keys for each window and door. This streamlines security management and ensures a more efficient and robust overall security strategy.
What is most valuable?
There are several crucial advantages to using Check Point NGFW including its ease of use, as it provides a unified interface for managing multiple security functions. It offers impressive scalability to meet the demands of a large organization and can handle substantial traffic. Its simplified management, enhanced remote support capabilities, and the ability to facilitate secure VPN connectivity for numerous offices and employees are highly beneficial.
What needs improvement?
The current model is predominantly hardware appliance-based, which can incur substantial costs. These appliances must be purchased separately, contributing to a significant investment.
For how long have I used the solution?
Our most recent engagement with Check Point NGFW was a year ago when we implemented it for one of your financial sector clients.
What do I think about the stability of the solution?
The stability of the firewall has been exceptional, with very minimal disruptions. There was only one instance of downtime, and it wasn't attributed to any fault in the firewall itself or the hardware, but due to a configuration issue. I would rate it eight out of ten.
What do I think about the scalability of the solution?
The scalability of Check Point firewalls is a notable strength. These firewalls can handle a substantial number of connections. For instance, they can manage up to one million connections on the NDSW server. Regarding its VPN capacity, it can support around 5,000 to 8,000 users per box, which is quite impressive. This scalability makes Check Point firewalls well-suited for organizations with high connection and user requirements. I would rate it eight out of ten.
How are customer service and support?
Their support team has demonstrated an approximately 24-hour turnaround time, which is considered quite good. We have rarely needed to engage with Check Point support because most issues are resolved internally. Typically, we turn to OEM support only when we encounter challenges that are beyond our capabilities.
Which solution did I use previously and why did I switch?
I also have experience with Fortinet and Cisco, both of which have made significant developments recently. They have introduced software-based firewall and system solutions, which have garnered attention from customers. This shift in the competitive landscape has led to changes in customer preferences, with more organizations considering Fortinet as a viable option for their security needs.
How was the initial setup?
This process can be a bit complex at times, mainly because it depends on the specific client architecture and how they want to set it up.
What about the implementation team?
The deployment process can be rated at about six in terms of complexity. Several factors influence this complexity, but getting the infrastructure ready is often the most challenging aspect. To successfully deploy, you need to account for downtime, ensure proper backups are in place, and ideally test it in a sandbox environment before going live. After deployment, thorough checks and adjustments are necessary. It typically requires at least two days of parallel operation, where both the new and old equipment run simultaneously. In an environment with no existing infrastructure to replace, the process is generally smoother. Deployment typically involves a team of 2 or 3 people working full-time for 4 to 5 days, equivalent to nine hours a day. Maintenance is handled by a networking team, which includes a Network Operations Center. The team consists of approximately eleven people managing various network components, including L1, L2, and L3 devices.
What other advice do I have?
When considering a POC for a security solution, it's essential to assess the various use cases and functionalities it offers, such as NDSW which is particularly useful for protecting sensitive data. Check Point NGFW is not solely a firewall; it's a comprehensive security solution with various capabilities. It can address a wide range of security requirements, making it a valuable and versatile asset for organizations looking to enhance their security posture. I would rate it eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
Security Support Engineer at a tech vendor with 51-200 employees
Effective security with room for performance reliability improvements
Pros and Cons
- "What I found very valuable in Check Point Quantum Force (NGFW) is the possibility to share everything with the ThreatCloud; for example, when a customer encounters a new virus, malware, or signature, it gets uploaded into the ThreatCloud and shared among all other customers."
- "The issues with Check Point Quantum Force (NGFW) are mainly related to reliability. It depends significantly on the hotfix version of the gateway."
What is our primary use case?
In our customer environment, Check Point Quantum Force (NGFW) is used for edge security and internal security, both for data center and edge side.
We don't have Check Point Quantum Force (NGFW) personally. We install it for our customers and then take care of it.
What is most valuable?
What I found very valuable in Check Point Quantum Force (NGFW) is the possibility to share everything with the ThreatCloud. For example, when a customer encounters a new virus, malware, or signature, it gets uploaded into the ThreatCloud and shared among all other customers.
What needs improvement?
The issues with Check Point Quantum Force (NGFW) are mainly related to reliability. It depends significantly on the hotfix version of the gateway. You could end up with a version that's stable or unstable, or for example, stable for one scenario, but then in certain specific scenarios, it becomes unstable and creates an issue. This requires contacting support, discussing with R&D, and verifying if there is a new version or custom fix to install.
For how long have I used the solution?
I have been using Check Point Quantum Force (NGFW) for around two years, slightly more.
What do I think about the stability of the solution?
Check Point Quantum Force (NGFW) is stable overall and behaves the way it should. There are specific issues that are not just limited to the version, but they include processes and blades. When I mention specific issues, it involves different components that make up the security gateway.
Stability concerns are the main reason I chose a seven rating. It's very important for customers because they rely heavily on the security gateway to operate in order to maintain connections.
What do I think about the scalability of the solution?
Based on the documentation, Check Point Quantum Force (NGFW) should handle scalability effectively, since it's based on AI, making the throughput significantly bigger than its predecessor.
How are customer service and support?
Customer support for Check Point Quantum Force (NGFW) is a bit of a hit and miss. Sometimes they have tunnel vision, so they only see the initial request and don't evaluate the whole scenario.
How would you rate customer service and support?
Neutral
How was the initial setup?
My experience with the pricing, setup cost, and licensing of Check Point Quantum Force (NGFW) is that it is straightforward but still expensive. It's quite pricey.
What was our ROI?
The return on investment for Check Point Quantum Force (NGFW) depends on the customer. Some customers didn't see the value and changed from Check Point to a different product.
Which other solutions did I evaluate?
Before choosing Check Point Quantum Force (NGFW), we evaluated Palo Alto Networks.
What other advice do I have?
You can add blades in the gateway of Check Point Quantum Force (NGFW). Blades are modules such as antivirus, anti-bot, or filtering, and they help prevent attacks or improve your security and perimeter.
The performance of Check Point Quantum Force (NGFW) varies based on whether it's a VM or a security appliance. The Quantum version, which is fairly new, focuses on the AI trend. It should have better throughput, better performance, and faster processing overall.
I rate Check Point Quantum Force (NGFW) a seven out of ten because it's stable enough, works very well, and doesn't have many CVE vulnerabilities. However, it's sometimes unreliable in terms of stability, depending on the version. Many customers have a positive impact, while others have a worse experience.
I would recommend evaluating your needs for Check Point Quantum Force (NGFW). If you are a small company, this product might be too extensive for your necessities. It depends on the throughput, gigabyte requirements, and pure performance needs. You can always use a VM or SMB Quantum Spark.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Enterprise Network Engineer at a outsourcing company with 201-500 employees
Network security gains peace of mind and efficient threat management
Pros and Cons
- "Check Point NGFW has positively impacted my organization by providing confidence that it's managing all the threats out there for us, even though at any one point in time, threats are coming in all over the place."
- "I find that the licenses are a bit expensive compared to other vendors, and while the price is justified, at times, renewing them becomes a bit painful, so if it could become a bit more budget-friendly, that would work for me."
What is our primary use case?
My main use case for Check Point NGFW is using it as our data center firewall, which basically keeps the resources behind the data center safe from all the different cybersecurity threats.
Check Point NGFW has made a difference for our data center, especially when some people at some point tried to spoof their IPs within the organization, and upon checking the logs, we found a couple of IPs that had been blocked because they were trying to get in from a different network where we don't expect those IPs, so the traffic was denied because of the IP spoofing setup.
What is most valuable?
The best features Check Point NGFW offers include unified threat management, web filter engines, and intrusion prevention, which I find valuable because it's important for us to have the security behind the data center down to the dot, and because of the granular policies we set, we can manage every bit of security when it comes to the data center network.
One standout feature relates to a user feature that puts users into sessions every time they are configuring, meaning one person is not going to configure the same thing that another does, and it locks the configuration to avoid confusion where one changes one thing and another person changes something differently on the other side, and when you're done, the session is committed, and you can still roll back in case the commit has an issue, which I find quite beneficial.
Check Point NGFW has positively impacted my organization by providing confidence that it's managing all the threats out there for us, even though at any one point in time, threats are coming in all over the place. The sense of confidence and peace of mind is the biggest positive impact, as cybersecurity is a bit fragile, so a product that gives you peace of mind goes a long way.
What needs improvement?
I find that the licenses are a bit expensive compared to other vendors, and while the price is justified, at times, renewing them becomes a bit painful, so if it could become a bit more budget-friendly, that would work for me.
That licensing issue would be the main area regarding needed improvements.
For how long have I used the solution?
I have been working in my current field for three years.
What was my experience with deployment of the solution?
The pricing, setup cost, and licensing process were smooth without any challenges.
What do I think about the scalability of the solution?
Check Point NGFW is reliable, and in terms of scalability, I'd say it's quite okay, considering we're using data center grade, but also there are options for some of the remote branches that we have at a lower cost, so you don't have to buy the bigger devices for the smaller branches, making the scalability suitable, and I rate customer support highly because whenever you log a case with the right level of urgency, they deal with it promptly as required.
How are customer service and support?
I would rate customer support a 10.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I'm not sure of that information, but I think a different solution was used before I arrived.
What was our ROI?
Regarding return on investment, it might not really be that kind of metric, but since we've deployed Check Point NGFW, we've not had any incident, which speaks for itself because that is basically what it's about. The fact that we've not had any breach toward the data center side is plenty enough.
What other advice do I have?
My advice to others looking into using Check Point NGFW is that it's quite strong and reliable with cutting-edge threat prevention and unified management, making it a solid foundation for a profitable business. I rate Check Point NGFW a 10 out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network and Security engineer at a tech services company with 11-50 employees
User identity awareness improves security
Pros and Cons
- "Check Point NGFW is a fantastic product, and it is also easy to integrate with third-party devices."
- "My experience with pricing, setup cost, and licensing for Check Point NGFW is that the high subscription fees aren't easy to afford, and it's not recommended for mid-sized companies or businesses."
What is our primary use case?
My main use case for Check Point NGFW is to filter the whole infrastructure traffic, and we use it as the perimeter firewall for our data center.
Check Point NGFW helps me in my daily operations by managing traffic across almost 30 branches, and we utilize its SD-WAN features to communicate with other third-party companies through a VPN.
For branch communication, we use the SD-WAN feature of Check Point NGFW, and through the VPN, we establish a connection between our company and the third-party companies. Currently, we filter our traffic between the branch sites and third-parties, and access the internet through that exchange firewall.
What is most valuable?
The best features Check Point NGFW offers in my experience are its application identification and control capabilities, which stand out as we use them beyond Layer 3 communications.
The application identification and control feature of Check Point NGFW helps my organization by allowing quick responses to make decisions and segregate applications that need more attention.
Check Point NGFW positively impacts my organization as it has improved our security posture and made us less vulnerable to attacks compared to our previous status; we can easily filter URLs and enhance web security.
While we don't have specific numbers, we measure increased security through our ability to block malicious attacks, including phishing attacks, easily.
What needs improvement?
Check Point NGFW has a steep learning curve for starters; it's not easy to learn and is a bit complex to start from scratch.
Check Point NGFW sometimes has limitations on third-party integrations, requiring more specifics rather than being straightforward.
For how long have I used the solution?
I have been using Check Point NGFW for almost two years.
What do I think about the stability of the solution?
Check Point NGFW is stable.
What do I think about the scalability of the solution?
We scaled up Check Point NGFW about six months ago, and it handled that scalability fantastically.
How are customer service and support?
Customer support for Check Point NGFW has been stable, even while we faced some issues.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I did not previously use a different solution; it was similar to Cisco ASA.
How was the initial setup?
The initial setup with Check Point NGFW was a bit complex.
What was our ROI?
We have seen a return on investment with Check Point NGFW as we have reduced incidents from the previous setup.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for Check Point NGFW is that the high subscription fees aren't easy to afford, and it's not recommended for mid-sized companies or businesses. The cost is a little bit high compared to other competitors.
Which other solutions did I evaluate?
Before choosing Check Point NGFW, I evaluated Cisco, but I didn't look into other options on PeerSpot.
What other advice do I have?
I recommend Check Point NGFW to others looking into it because it's a good protective device.
From the vendor, I was not offered a gift card or incentive for this review.
Check Point NGFW is a fantastic product, and it is also easy to integrate with third-party devices.
On a scale of one to ten, I rate Check Point NGFW a nine.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Client Executive at a tech vendor with 10,001+ employees
Powerful firewall for advanced security with robust support
Pros and Cons
- "Check Point's support is probably the best of the major players in that space."
- "Check Point's capabilities are limited from a firewall perspective."
What is our primary use case?
I do not use them, I just sell them, but customers are using them to protect on the edge and at the core.
What is most valuable?
It brings value to their clients as everybody is concerned with security. Firewalls are the first line of defense. Check Point's support is probably the best of the major players in that space. Check Point is more complex than the other players, but it is also more powerful.
What needs improvement?
A lot of the other players have a more robust best-of-suite offering versus the best-of-breed offering. Check Point's capabilities are limited from a firewall perspective. Other players are acquiring companies and offering add-ons like CASB or VPN-type capabilities.
For how long have I used the solution?
I have had experience with Check Point Next Generation Firewall for seven or eight years.
What do I think about the stability of the solution?
Their code is a little bit finicky as of late, but that's just because they just released this product line.
What do I think about the scalability of the solution?
It depends on what you're deploying. Maestro is more scalable than standalone firewalls.
How are customer service and support?
The support depends on what support model you buy. Customers that have dedicated support teams get more attention than the traditional support, however, a lot of other companies are offshoring their support.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Cisco is not a true security company, but Check Point is where they grew up, so I think they are a little more mature.
How was the initial setup?
The initial setup depends on the environment and can take weeks. It is not different than the rest of the players in terms of maintenance.
What about the implementation team?
It's basic engineers, usually one to two people.
What was our ROI?
It is pretty difficult to determine ROI with firewalls because they are more of an insurance policy. However, it helps with security. The cost of a breach versus having some of these measures in place is the real comparison.
What's my experience with pricing, setup cost, and licensing?
There is a lot of price parity between all the players. Everybody is within plus or minus ten percent. Check Point is probably more expensive than some of the other players out there, but it is incremental.
Which other solutions did I evaluate?
I evaluated Palo Alto and Fortinet.
What other advice do I have?
I would recommend Check Point Next Generation Firewall to others. I would put them in the upper echelon.
I'd rate the solution nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Ensures comprehensive security features, including URL filtering, content filtering, and global threat intelligence, while also providing scalability and ease of deployment
Pros and Cons
- "Some of the most valuable features are URL filtering, web filtering, and content filtering."
- "It would be beneficial if Check Point included more licenses bundled with the base model, reducing the need for additional subscription charges for essential functionalities."
What is our primary use case?
Our customers find that the Check Point NGFW highly effective for data center deployments. Additionally, smaller models are well-suited for branch locations where local internet breakout is necessary. These smaller models streamline internet access at remote sites, eliminating the need for third-party service providers and reducing costs. The 26000 and 28000 series excel in securing DMZs, while the lower-end versions are ideal for branch-level internet breakout, allowing direct cloud connectivity without intermediary networks. It offers cost savings and efficient security solutions tailored to various deployment scenarios.
What is most valuable?
Some of the most valuable features are URL filtering, web filtering, and content filtering. Typically, customers would need to invest in cloud web security solutions for local internet breakout. However, by deploying Check Point firewalls, which include these functionalities built-in at each site, the need for separate cloud-based solutions is eliminated. This consolidation reduces costs significantly, as one product serves multiple purposes: routing, switching, and next-generation security features such as timeboxing and malware filtering.
What needs improvement?
Check Point could enhance its capabilities further by focusing on global threat intelligence, particularly in addressing zero-day attacks and other unknown threats. If I were to suggest improvements for this firewall, it would involve enhancing its core features. Currently, there are many additional licenses available for purchase, such as DDoS protection, URL filtering, and global threat intelligence. These additional licenses increase the overall cost significantly, as they are add-ons to the base model. It would be beneficial if Check Point included more licenses bundled with the base model, reducing the need for additional subscription charges for essential functionalities.
For how long have I used the solution?
I have been working with it for one year.
What do I think about the stability of the solution?
I would rate its stability capabilities eight out of ten. I'm uncertain about its performance in large enterprises, where stability is paramount. It's crucial that the firewall can handle high throughput, accommodating multiple gigabytes of bandwidth, alongside additional firewall features like web filtering, content filtering, and sandboxing. In my experience with capacities ranging from one hundred to two hundred megabytes, focusing solely on web and content filtering, the product has proven to be stable.
What do I think about the scalability of the solution?
There is room for improvement in scalability. Adding more firewall features can impact the performance of the device, particularly in terms of processor capacity. I would rate it six out of ten. Our customers typically fall within the medium-sized business category.
How are customer service and support?
All manuals are accessible on the website, ensuring comprehensive documentation is readily available. The publicly available documentation is satisfactory, covering a wide range of information. However, certain documents not accessible to the public are provided to partners through a partner sign-in portal. This access ensures that all necessary documentation is available within our organization.
How was the initial setup?
The initial setup was quite straightforward. It involved basic configuration, which I would rate as an eight out of ten in terms of simplicity.
What about the implementation team?
The deployment took approximately five hours. The process can be executed in various methods. I typically perform a remote login from the console. The deployment involves three main steps: IP configuration, security configuration, and DNS setup, including any necessary DNS protection configurations.
What's my experience with pricing, setup cost, and licensing?
It falls in a moderate price range, not as inexpensive as some alternatives but not as costly as Palo Alto. I would rate it seven out of ten. There are numerous additional licenses required for advanced security features, leading to additional costs.
What other advice do I have?
Check Point has introduced several SD-WAN and IoT features, among others. I would suggest exploring the zero-trust features offered by Check Point. Additionally, if interested in incorporating SD-WAN or IoT capabilities, these features are readily available within the product. It's important to note that in today's landscape, Check Point offers more than just a traditional firewall; it's a comprehensive and advanced solution. Overall, I would rate it eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
Buyer's Guide
Download our free Check Point Quantum Force (NGFW) Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Popular Comparisons
Fortinet FortiGate
Cisco Secure Firewall
Netgate pfSense
Sophos Firewall
Check Point Cloud Firewall (formerly CloudGuard Network Security)
Palo Alto Networks NG Firewalls
WatchGuard Firebox
Check Point Harmony SASE (formerly Perimeter 81)
Cisco Meraki MX
Azure Firewall
Palo Alto Networks VM-Series
Fortinet FortiGate-VM
Juniper SRX Series Firewall
Buyer's Guide
Download our free Check Point Quantum Force (NGFW) Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- How does Check Point NGFW compare with Fortinet Fortigate?
- Is Palo Alto Networks NG Firewalls better than Check Point NGFW?
- Which would you recommend - Azure Firewall or Check Point NGFW?
- Is Check Point's software compatible with other products?
- What do you recommend for a corporate firewall implementation?
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Which is the best network firewall for a small retailer?
- When evaluating Firewalls, what aspect do you think is the most important to look for?
- Cyberoam or Fortinet?














