I used Check Point NGFW to secure the data centers of medium to large enterprise companies. In many cases, it serves as a perimeter firewall, though its use can vary based on specific needs. Primarily, it functions as a defensive firewall.
Senior Implementation Security Engineer at Orange España
Serves as a perimeter firewall at a cheaper rate but doesn't have a friendly GUI
Pros and Cons
- "Google has a premium partnership with Check Point, involving extensive verification processes for major customers. This strong partnership indicates a significant level of collaboration between the two companies."
- "The GUI is not very user-friendly, and configuring it can be challenging."
What is our primary use case?
What is most valuable?
What needs improvement?
The GUI is not very user-friendly, and configuring it can be challenging. The management console often has issues, sometimes requiring high CPU usage on your FTP or Windows system to open or manage sessions. It can be resource-intensive. Additionally, when viewing or monitoring logs, they sometimes do not appear immediately and may be outdated or missing.
For how long have I used the solution?
I have been using Check Point NGFW for two years.
Buyer's Guide
Check Point Quantum Force (NGFW)
September 2025

Learn what your peers think about Check Point Quantum Force (NGFW). Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,787 professionals have used our research since 2012.
What do I think about the stability of the solution?
It is a stable device.
What do I think about the scalability of the solution?
They support a range of enterprises, from small to large. Their solutions can accommodate environments with as few as 50 users to those with thousands or more. So, handling a large number of users is not an issue.
How are customer service and support?
Support is very good.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is not straightforward and can be more complex than that of other devices like Palo Alto or Fortinet firewalls. The setup for the CMA and management center requires careful implementation. Additionally, integrating components such as MDM and other security devices, including sandboxes, can be challenging to achieve a cohesive and secure environment.
The time required for deployment depends on the amount of configuration needed. Typically, it might take a full day, but with sufficient time, a basic configuration can often be completed in about eight to ten hours.
I have worked with both on-premises and VM versions. The CMA is typically deployed as a VM on a server, while the firewall is a physical device.
What about the implementation team?
I have already deployed many times by myself, so there is no need for many people.
What's my experience with pricing, setup cost, and licensing?
It is a cheaper device than what other vendors offe.
What other advice do I have?
For security features, I typically use the templates or standards provided by the vendor. Based on my experience over the past three years, I haven’t encountered any significant complaints from customers about attacks or major issues while using the firewall to protect their data centers.
Google has a premium partnership with Check Point, involving extensive verification processes for major customers. This strong partnership indicates a significant level of collaboration between the two companies.
I haven’t handled any maintenance, but the support center has been very helpful. They provided excellent support and demonstrated strong knowledge whenever I reached out for assistance. They are proficient in various languages and have a good grasp of Linux, which is essential for effective support.
They provide good step-by-step implementation guides, similar to what is available for Fortinet's FortiGate. However, I find the implementation process for other vendors to be easier. Pricing varies among the three vendors, so there are differences in cost. Palo Alto offers the best options for sizing, though I haven’t worked operationally.
I recommend it, but you should know Linux and its commands to work effectively with this device.
Overall, I rate the solution a six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner

Ensures comprehensive security features, including URL filtering, content filtering, and global threat intelligence, while also providing scalability and ease of deployment
Pros and Cons
- "Some of the most valuable features are URL filtering, web filtering, and content filtering."
- "It would be beneficial if Check Point included more licenses bundled with the base model, reducing the need for additional subscription charges for essential functionalities."
What is our primary use case?
Our customers find that the Check Point NGFW highly effective for data center deployments. Additionally, smaller models are well-suited for branch locations where local internet breakout is necessary. These smaller models streamline internet access at remote sites, eliminating the need for third-party service providers and reducing costs. The 26000 and 28000 series excel in securing DMZs, while the lower-end versions are ideal for branch-level internet breakout, allowing direct cloud connectivity without intermediary networks. It offers cost savings and efficient security solutions tailored to various deployment scenarios.
What is most valuable?
Some of the most valuable features are URL filtering, web filtering, and content filtering. Typically, customers would need to invest in cloud web security solutions for local internet breakout. However, by deploying Check Point firewalls, which include these functionalities built-in at each site, the need for separate cloud-based solutions is eliminated. This consolidation reduces costs significantly, as one product serves multiple purposes: routing, switching, and next-generation security features such as timeboxing and malware filtering.
What needs improvement?
Check Point could enhance its capabilities further by focusing on global threat intelligence, particularly in addressing zero-day attacks and other unknown threats. If I were to suggest improvements for this firewall, it would involve enhancing its core features. Currently, there are many additional licenses available for purchase, such as DDoS protection, URL filtering, and global threat intelligence. These additional licenses increase the overall cost significantly, as they are add-ons to the base model. It would be beneficial if Check Point included more licenses bundled with the base model, reducing the need for additional subscription charges for essential functionalities.
For how long have I used the solution?
I have been working with it for one year.
What do I think about the stability of the solution?
I would rate its stability capabilities eight out of ten. I'm uncertain about its performance in large enterprises, where stability is paramount. It's crucial that the firewall can handle high throughput, accommodating multiple gigabytes of bandwidth, alongside additional firewall features like web filtering, content filtering, and sandboxing. In my experience with capacities ranging from one hundred to two hundred megabytes, focusing solely on web and content filtering, the product has proven to be stable.
What do I think about the scalability of the solution?
There is room for improvement in scalability. Adding more firewall features can impact the performance of the device, particularly in terms of processor capacity. I would rate it six out of ten. Our customers typically fall within the medium-sized business category.
How are customer service and support?
All manuals are accessible on the website, ensuring comprehensive documentation is readily available. The publicly available documentation is satisfactory, covering a wide range of information. However, certain documents not accessible to the public are provided to partners through a partner sign-in portal. This access ensures that all necessary documentation is available within our organization.
How was the initial setup?
The initial setup was quite straightforward. It involved basic configuration, which I would rate as an eight out of ten in terms of simplicity.
What about the implementation team?
The deployment took approximately five hours. The process can be executed in various methods. I typically perform a remote login from the console. The deployment involves three main steps: IP configuration, security configuration, and DNS setup, including any necessary DNS protection configurations.
What's my experience with pricing, setup cost, and licensing?
It falls in a moderate price range, not as inexpensive as some alternatives but not as costly as Palo Alto. I would rate it seven out of ten. There are numerous additional licenses required for advanced security features, leading to additional costs.
What other advice do I have?
Check Point has introduced several SD-WAN and IoT features, among others. I would suggest exploring the zero-trust features offered by Check Point. Additionally, if interested in incorporating SD-WAN or IoT capabilities, these features are readily available within the product. It's important to note that in today's landscape, Check Point offers more than just a traditional firewall; it's a comprehensive and advanced solution. Overall, I would rate it eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
Buyer's Guide
Check Point Quantum Force (NGFW)
September 2025

Learn what your peers think about Check Point Quantum Force (NGFW). Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,787 professionals have used our research since 2012.
Network Engineer at Upstream
Easy to use and free of bugs with a good Smart Console
Pros and Cons
- "mart Console simplifies the management of current policies and objects, making it effortless to track an object's usage or identify unused objects, thus ensuring a tidy configuration."
- "In the past year, we faced severe downtime that lasted many days due to a misconfiguration."
What is our primary use case?
We use the solution for our data center firewall on-premises. We have deployed a VSX Cluster that currently holds three virtual firewalls. We have several site-to-site VPNs established with our partners and hundreds of policies applied.
We had a custom configuration in our previous policy for which we were passing traffic from one VPN tunnel to another transparently. With Check Point we had to create a new virtual firewall in order to keep it working, so from one firewall we ended up with two rerouting traffic from one firewall to another and changing NAT in order to keep this solution running.
Finally, we created another (third) virtual firewall and configured it to be only a remote access SSL VPN firewall and to be used as a backup if our primary in our HQ fails while the other two firewalls handle production traffic.
How has it helped my organization?
We selected this solution in order to replace the Cisco ASA we used to have.
The features the CP firewall has combined with a very attractive price led us to this decision. The migration was smooth and all the features we needed have been configured easily and worked as expected. Additionally, the SmartConsole and the Log Event viewer made our every day to day tasks easier.
Also, we were provided with a trial license for the compliance blade and the IPS which are truly amazing. I believe that the compliance blade will be used soon by our company in order to assist with the ISO certificate we are trying to get.
Since we have already deployed an AWAF on our premises we didn't use the IPS but the features presented definitely would increase the security level.
Although we use it as our data center firewall, it would be ideal for our HQ Office with all the security features it provides.
What is most valuable?
I appreciate the Smart Console for its ease of use and clarity in managing configurations. It's user-friendly and free of software bugs. Smart Console simplifies the management of current policies and objects, making it effortless to track an object's usage or identify unused objects, thus ensuring a tidy configuration.
Additionally, the hit count feature proves highly valuable, enabling policy prioritization based on usage frequency and facilitating verification of traffic alignment with newly created policies. Furthermore, implementing 2FA for SSL VPN users was a straightforward process, notably without the need for additional costs, unlike the FortiTokens required for our primary SSL VPN.
Additionally, the quick and seamless option to revert to a previous configuration revision is highly valuable. The logs tab serves as a helpful tool for troubleshooting.
It's worth noting that we've experienced no CPU or memory issues, and the system is highly responsive.
What needs improvement?
The only downside is that we are not able to have redundant VPN tunnels with our cloud environments. We tried many guides suggested by the CheckMates community and have not been able to easily capture packets in a PCAP file as we used to do with the ASDM Packet Capture Wizard.
Finally, in the past year, we faced severe downtime that lasted many days due to a misconfiguration. Support wasn't able to detect it. We are allowed to add an automatic NAT in an object and install it in all three virtual firewalls that we have. I cannot imagine a real case that needs this option. This option should be totally removed.
The destination MAC address for this object was flapping between the three virtual MAC addresses of the FW leading to a packet loss in our service up to 30%. Our manager found the root cause at the end.
For how long have I used the solution?
I've used the solution for three to four years.
What do I think about the stability of the solution?
In the past four years that we have had Check Point, we haven't faced any stability issues. It is a stable solution.
What do I think about the scalability of the solution?
Our cluster is oversized for our needs so we haven't reached any system limits in order to face an issue or at least observe its behavior. Our solution covers our current needs and can easily handle any additional load.
How are customer service and support?
Technical support is average. From my last experience, it was my manager who found the root cause of the downtime.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
As noted earlier, our transition to this solution marked a shift from our previous Cisco ASA Cluster setup. Check Point's prominent position in the network industry and the compelling price point offered made it too appealing to overlook.
How was the initial setup?
The initial setup and the configuration migration were done by an integrator who specializes in such migrations. It was complex enough yet very well-planned and organized.
What about the implementation team?
The implementation was done by a very qualified vendor team.
What was our ROI?
Since I am in the engineering department, I can't evaluate the actual income or costs of handling our production traffic with this solution.
What's my experience with pricing, setup cost, and licensing?
I'm not sure what was evaluated. It depends on the company's unique existing infrastructure and needs.
Which other solutions did I evaluate?
We evaluated offers for Cisco, Fortinet, and Palo Alto solutions.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Independent Information Technology and Services Professional at a non-profit with 1-10 employees
Enhanced firewall management with cost-effective feature integration and competitive pricing
Pros and Cons
- "The price point is good."
- "The operating system and platform could be more tightly integrated."
What is our primary use case?
We use Check Point Next Generation Firewall both as a perimeter firewall and as an internal firewall.
For customers, we recommend using the open platform, which is the software installed on your own server. We usually find that you get a lot more performance out of the software that way. Also, a lot of energy companies use it as well.
How has it helped my organization?
Check Point Next Generation Firewall helps us with routing failover, setting up a web dashboard for better management of the platform, and ensuring the stability and availability of our firewalls with its backup features.
What is most valuable?
The price point is good. You get a lot more features for the cost. How it's bundled and packaged is very simple to order. All the features are bundled with the product, and it's just a matter of checking a box to turn it on or off.
Performance is usually better on OpenServers, where we provide the server on the Check Point platform.
What needs improvement?
The operating system and platform could be more tightly integrated. Some features are better done on the OS side of the platform. Integrating all features into one dashboard should avoid switching between the new and old dashboards.
What do I think about the stability of the solution?
Check Point Next Generation Firewall is quite stable. For features like backup and data, I would rate it highly.
What do I think about the scalability of the solution?
Check Point Next Generation Firewall offers excellent scalability. With OpenServer, it's just a matter of purchasing licenses that enable more CPUs to be used. We can increase the RAM on the box and allow for more network traffic and customers onto our platform.
How are customer service and support?
The support is great. I usually get it online and it meets our needs effectively.
How would you rate customer service and support?
Positive
How was the initial setup?
Setup is easy. I would give it an eight out of ten.
What's my experience with pricing, setup cost, and licensing?
The pricing is fair and more competitive than many competitors. On a scale of one to ten, with ten being the most expensive, I would rate it around a three in its category.
Which other solutions did I evaluate?
Cisco does not support SSL inspection, and its detection capabilities are limited. I would say Check Point is comparable with Palo Alto in terms of features and detection capabilities.
What other advice do I have?
I would recommend Check Point Next Generation Firewall because of its detection capabilities, which ensure protection by identifying malicious files and suspicious activities. The price point is also lower compared to Palo Alto for the same features.
I'd rate the solution nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Senior Manager at BDO Unibank
Great IPS and anti-malware security blades with responsive technical support
Pros and Cons
- "The successful performance of the security blades has shown the value of the investment along with the comparable success of leveraging the NGFW over a separate specialized security solution."
- "The current reporting capability needs to be parsed and edited to be appreciated by leadership."
What is our primary use case?
Our company undertook a network transformation and instead of implementing a separate IPS solution, we've opted for the NGFW of Check Point. We've leveraged the different security blades available in the Check Point NGFW. Besides the IPS blade, we've also leveraged the anti-malware threat intelligence blades for our gateways, especially for the perimeter.
We've also enabled the IPS blade for our remote offices as part of the additional security layer for our smaller international offices and used both the IPS and anti-malware for our bigger offices.
How has it helped my organization?
We've managed to reduce the CAPEX cost of the network transformation when we leveraged the versatility of the Check Point NGFW solution.
Instead of purchasing separate solutions for the IPS, anti-malware, and threat intelligence, the security blades of the Check Point NGFW were just enabled.
The software subscription cost is already included in the annual software and hardware maintenance cost which made the solution more cost-effective than having separate solutions wherein we need to maintain a separate subscription for each.
What is most valuable?
Besides the basic firewall feature of the Check Point NGFW, we find the IPS and anti-malware security blades to be most valuable for our current implementation.
The IPS and anti-malware solutions have successfully identified and blocked potential threats from our perimeter.
Though we are also using threat intelligence, we see more validation of the successful use of the IPS an anti-malware.
The successful performance of the security blades has shown the value of the investment along with the comparable success of leveraging the NGFW over a separate specialized security solution.
What needs improvement?
Overall, we are satisfied with the performance of the NGFW both from the functional and operational perspective. The solution has been proven effective in detecting and blocking potential and intentional threats to the company's internal network without impacting the performance of the appliance.
What can be improved though is the capability of providing an executive summary report that can highlight the performance and operational effectiveness of the implemented security solution. The current reporting capability needs to be parsed and edited to be appreciated by leadership.
For how long have I used the solution?
We've been using Check Point NGFW for more than 4 four years.
What do I think about the stability of the solution?
Check Point NGFW has been very stable and very rarely do we encounter any performance issues due to hardware or software issues.
What do I think about the scalability of the solution?
The solution is very scalable and easy to manage.
How are customer service and support?
Customer service and support are very responsive, and we get quick and fairly consistent turnaround times for the resolution.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We previously used Cisco Firepower, however, we were not satisfied with its performance both functional and operational.
How was the initial setup?
The initial setup was straightforward since the deployment is just the typical high-availability active standby implementation.
What about the implementation team?
We implement through a vendor team. The vendor team is very competent and has consistently displayed their expertise in the technology.
What was our ROI?
Unfortunately, our team does not have visibility on the ROI.
What's my experience with pricing, setup cost, and licensing?
If the implementation would require multiple gateways, consider leveraging the Infinity Total Protection.
Which other solutions did I evaluate?
We no longer evaluated other options.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Specialist at CCV Deutschland GmbH
Robust, efficient, and very easy to implement
Pros and Cons
- "We have found the central management (Smart Console) to be very helpful in managing all the firewalls and keeping the software/hotfix versions up to date."
- "We have run into an interface expansion limitation, and thus it would be helpful if products lower in the stack would offer more interface expansion options."
What is our primary use case?
We use Check Point Quantum Network Gateways for all our on-site firewalls. It protects the network edge, network core, data center, and our AWS direct connect.
We are a payment facilitator and security is one of our core requirements.
We have implemented VSX which enabled us to reduce the hardware footprint.
We have implemented 6700NGFW, 6600NGFW, and 6400NGFW in different network segments. We have enabled basic firewall, ClusterXL, and IPS licensing.
Due to the nature of the traffic, we do not use Application Control or URL Filtering.
How has it helped my organization?
With our previous firewall solution, we had no automated compliance tools. Now, with the Check Point Quantum Network Gateways, we have the ability to automate compliance reports for both GDPR and PCI3.2, and by using VSX (Virtual System Extension) we have reduced our data center footprint. This will lead us to become a more sustainable organization.
We have found the central management (Smart Console) to be very helpful in managing all the firewalls and keeping the software/hotfix versions up to date.
What is most valuable?
By implementing VSX (Virtual System Extension), we were able to reduce our hardware footprint, reducing both direct and indirect costs. This also enables us to quickly scale up or down to meet business needs.
We have also found that the Intrusion Prevention System implemented on Check Point Quantum Network Gateways is robust, efficient, and very easy to implement. Being able to add it later as a software feature is a real boon. The customization options enabled us to zero in on our specific use case.
What needs improvement?
Due to our unique environment, we have to implement BGP on our firewalls, and the way that BGP is implemented on Check Point Quantum Network Gateways is not intuitive and requires additional custom configuration. This caused a significant delay in our migration. The way that NAT is implemented was also not intuitive and required additional custom configuration.
We have also run into an interface expansion limitation, and thus it would be helpful if products lower in the stack would offer more interface expansion options.
For how long have I used the solution?
The solution has been in use for one year.
What do I think about the stability of the solution?
During the first year of operation, we have seen 100% up-time.
What do I think about the scalability of the solution?
Due to the VSX implementation, I would conclude that it is highly scalable.
How are customer service and support?
Customer service and support from the vendor have been excellent. They have assisted in communicating issues back to Check Point and the subsequent response from Check Point has been very good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We used Cisco ASA 5500 series firewalls, but these have reached the end of life and needed to be replaced.
How was the initial setup?
The initial setup and migration was complex and we had a vendor team assisting.
What about the implementation team?
The expertise of the vendor team is excellent; I'd rate their services nine out of ten.
What's my experience with pricing, setup cost, and licensing?
It is important to carefully consider your needs. Additional features can be activated easily - for additional licensing costs. However, opting for extended licensing can provide cost savings through discounts.
Which other solutions did I evaluate?
In looking at replacing the existing firewalls we considered Cisco, Palo Alto, and Check Point.
Check Point Quantum Network Gateways offered us a more favorable price point without compromising on functionality.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Administrator at POET
Great support, central management, and logging capabilities
Pros and Cons
- "The central management and logging are frankly one of the top selling points."
- "Lately, Check Point seems to be pushing new products too early."
What is our primary use case?
The solution is used for edge and interior firewalls. We use large-scale Check Points for our edge and have them set up in an active/passive cluster. For our internal firewalls at the remote sites, we use a virtual firewall for the OT DMZ, and then behind this virtual firewall, we have a physical appliance for the actual OT network. This allows us to fully secure the critical network yet still allow access via jump hosts or other remote management that we have approved. It also gives us excellent control over any north/south traffic.
How has it helped my organization?
Check Points is probably not the easiest or cheapest solution to use, however, we have never had any issues with their security and the technical issues we have had with them are few and far between.
Most support calls for us are centered around how to best deploy a feature or why something is being blocked by a certain blade. This is one of the main reasons we continue to use them as they provide proven security for my company and the built-in blades generally always provide a benefit for us.
What is most valuable?
The central management and logging are frankly one of the top selling points.
The actual management is perhaps a little confusing for a newcomer to Check Point - however, does not take very long to learn the basic ins and outs of.
The logging capability of Check Point is excellent and very rarely have we wanted more. The logging is very fast and easy to use, and this makes finding items across all 80+ firewalls very easy.
It is also easy to export all logs to our MSP since it is from a central point. The other built-in features are also helpful as it eliminates the need for some extra security appliances.
What needs improvement?
Lately, Check Point seems to be pushing new products too early. We have evaluated a few we thought may be useful to us yet were just not ready for enterprise use. Every company goes through this so hopefully, they will slow down and get the products up to speed and working better before trying to bring them to market.
The current products that have been around for more than a few years generally do not suffer from this issue, however, their documentation does lag severely when a command changes or says the way to configure it changes. Support generally is up to date, but the KB articles are not always this way.
For how long have I used the solution?
I've used the solution for 18 years at my current company, and another four at my previous company.
What do I think about the stability of the solution?
The stability is excellent.
What do I think about the scalability of the solution?
Scalability is excellent, especially the newer products.
How are customer service and support?
The technical support is mostly good. Their Tier 2 and higher engineers are excellent. Like any call center, however, their Tier 1 can be hit or miss. We use a third party for front line support so mostly never encounter anything less than Tier 3 since the only issues that get directed to actual Check Point support are already vetted out.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We used SonicWall. We switched due to wanting a more enterprise-quality product and previous experience.
How was the initial setup?
The setup is complex, however, we knew this from the start so it was not unexpected.
What about the implementation team?
We set up the solution mostly in-house. However, we were experienced with Check Point installs.
What was our ROI?
I have no visibility on ROI.
What's my experience with pricing, setup cost, and licensing?
If new to Check Point, get pro services to help deploy it - especially if it is an advanced config. This will save huge amounts of time and grief. Once you have experience, pro services are generally not needed unless, again, you have no experience in that area.
Which other solutions did I evaluate?
We did not evaluate other options.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Architect and consultant at VirginAustralia
Enhances network security and ensures robust scalability capabilities
Pros and Cons
- "It offers a range of models to enhance network security and it can be customized to secure endpoint client machines or user devices by deploying features like malware detection, antivirus, and mail security blades."
- "There is a strong demand for security services that can be effortlessly integrated which would ensure that security measures can seamlessly adapt to the cloud infrastructure."
What is our primary use case?
It offers a range of models to enhance network security and it can be customized to secure endpoint client machines or user devices by deploying features like malware detection, antivirus, and mail security blades. Its integration with a web application firewall provides added protection.
What is most valuable?
Check Point's architecture is three-fold, comprising the firewall, management server, and dashboard. The dashboard provides a comprehensive view of the network and security status, enabling identification and isolation of problematic devices, performing tasks like patch updates, and monitoring logs. It provides configured automated alerts via email or notifications on mobile devices, ensuring you're informed of any threats, even during non-business hours. Another vital function is the ability to offer VPN services. This enables end users and mobile or remote workers to securely access the network from anywhere globally.
What needs improvement?
There is a strong demand for security services that can be effortlessly integrated which would ensure that security measures can seamlessly adapt to the cloud infrastructure.
For how long have I used the solution?
I have been working with it for eight years.
What do I think about the stability of the solution?
It is a highly reliable tool. I would rate its stability capabilities nine out of ten.
What do I think about the scalability of the solution?
Check Point NGFW is a highly scalable solution that can be tailored to the unique needs and infrastructure of each customer. For instance, if a customer needs to secure multiple zones, they can opt for multiple firewalls. They can consolidate their network onto a single firewall by creating virtual interfaces based on VLANs. The firewall's capability to handle network traffic becomes a crucial consideration, especially when dealing with larger user bases and higher traffic volumes. In such cases, deploying multiple firewalls in a high-availability configuration becomes essential.
How was the initial setup?
The initial setup was easy. I would rate it nine out of ten.
What about the implementation team?
I have hands-on experience working in various environments, including on-premises, private clouds, hybrid setups that combine both private and public clouds (e.g., AWS, Google Cloud, Oracle Cloud), and purely public cloud deployments. While the technical interfaces and options may differ slightly between these environments, the core concepts, such as Security Event and Management (SEM), remain consistent. For instance, the Virtual Private Cloud (VPC) configurations in Google Cloud are similar to those in AWS. Network components like instances and Access Control Lists (ACLs) share common principles across platforms. The key to successfully implementing it lies in understanding the specific needs of each client's business and aligning our solutions accordingly. We can leverage technology and services to meet their requirements effectively. It's worth emphasizing that the adaptability of our approach is central to achieving our clients' objectives. When starting a project, we typically initiate a POC and conduct thorough pre-checks to assess the network's specific needs. In cases where clients want to transition from legacy firewalls like Cisco ASA or Palo Alto to modern Next-Generation Firewalls like Check Point Firewall, we carefully examine their existing configurations. This allows us to manipulate and adapt the configurations to suit Check Point's requirements. The timeline for these processes can vary. For entirely new environments, which involve documentation, design, and diagram creation, it may take anywhere from 15 days to one month at most.
What's my experience with pricing, setup cost, and licensing?
The pricing falls in the middle, meaning it's neither cheap nor expensive. I would rate it five out of ten.
What other advice do I have?
Before opting for this solution, it is crucial to assess the customer's existing environment, including the number of users, traffic patterns, applications in use, and bandwidth utilization. It is an excellent choice and I would encourage others to consider using it for their security needs. I would rate it nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner, Post and pre services

Buyer's Guide
Download our free Check Point Quantum Force (NGFW) Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2025
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
Cisco Secure Firewall
Palo Alto Networks NG Firewalls
WatchGuard Firebox
Cisco Meraki MX
Azure Firewall
SonicWall TZ
Fortinet FortiGate-VM
Juniper SRX Series Firewall
SonicWall NSa
Buyer's Guide
Download our free Check Point Quantum Force (NGFW) Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- How does Check Point NGFW compare with Fortinet Fortigate?
- Is Palo Alto Networks NG Firewalls better than Check Point NGFW?
- Which would you recommend - Azure Firewall or Check Point NGFW?
- Is Check Point's software compatible with other products?
- What do you recommend for a corporate firewall implementation?
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Which is the best network firewall for a small retailer?
- When evaluating Firewalls, what aspect do you think is the most important to look for?
- Cyberoam or Fortinet?