No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer2701569 - PeerSpot reviewer
Enterprise Network Engineer at a outsourcing company with 201-500 employees
Real User
Top 5Leaderboard
Jul 31, 2025
Network security gains peace of mind and efficient threat management
Pros and Cons
  • "Check Point NGFW has positively impacted my organization by providing confidence that it's managing all the threats out there for us, even though at any one point in time, threats are coming in all over the place."
  • "I find that the licenses are a bit expensive compared to other vendors, and while the price is justified, at times, renewing them becomes a bit painful, so if it could become a bit more budget-friendly, that would work for me."

What is our primary use case?

My main use case for Check Point NGFW is using it as our data center firewall, which basically keeps the resources behind the data center safe from all the different cybersecurity threats.

Check Point NGFW has made a difference for our data center, especially when some people at some point tried to spoof their IPs within the organization, and upon checking the logs, we found a couple of IPs that had been blocked because they were trying to get in from a different network where we don't expect those IPs, so the traffic was denied because of the IP spoofing setup.

What is most valuable?

The best features Check Point NGFW offers include unified threat management, web filter engines, and intrusion prevention, which I find valuable because it's important for us to have the security behind the data center down to the dot, and because of the granular policies we set, we can manage every bit of security when it comes to the data center network.

One standout feature relates to a user feature that puts users into sessions every time they are configuring, meaning one person is not going to configure the same thing that another does, and it locks the configuration to avoid confusion where one changes one thing and another person changes something differently on the other side, and when you're done, the session is committed, and you can still roll back in case the commit has an issue, which I find quite beneficial.

Check Point NGFW has positively impacted my organization by providing confidence that it's managing all the threats out there for us, even though at any one point in time, threats are coming in all over the place. The sense of confidence and peace of mind is the biggest positive impact, as cybersecurity is a bit fragile, so a product that gives you peace of mind goes a long way.

What needs improvement?

I find that the licenses are a bit expensive compared to other vendors, and while the price is justified, at times, renewing them becomes a bit painful, so if it could become a bit more budget-friendly, that would work for me.

That licensing issue would be the main area regarding needed improvements.

For how long have I used the solution?

I have been working in my current field for three years.

Buyer's Guide
Check Point Quantum Force (NGFW)
August 2026
Learn what your peers think about Check Point Quantum Force (NGFW). Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
908,858 professionals have used our research since 2012.

What was my experience with deployment of the solution?

The pricing, setup cost, and licensing process were smooth without any challenges.

What do I think about the scalability of the solution?

Check Point NGFW is reliable, and in terms of scalability, I'd say it's quite okay, considering we're using data center grade, but also there are options for some of the remote branches that we have at a lower cost, so you don't have to buy the bigger devices for the smaller branches, making the scalability suitable, and I rate customer support highly because whenever you log a case with the right level of urgency, they deal with it promptly as required.

How are customer service and support?

I would rate customer support a 10.

Which solution did I use previously and why did I switch?

I'm not sure of that information, but I think a different solution was used before I arrived.

What was our ROI?

Regarding return on investment, it might not really be that kind of metric, but since we've deployed Check Point NGFW, we've not had any incident, which speaks for itself because that is basically what it's about. The fact that we've not had any breach toward the data center side is plenty enough.

What other advice do I have?

My advice to others looking into using Check Point NGFW is that it's quite strong and reliable with cutting-edge threat prevention and unified management, making it a solid foundation for a profitable business. I rate Check Point NGFW a 10 out of 10.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Network and Security engineer at a tech services company with 11-50 employees
Real User
Top 20
May 16, 2025
User identity awareness improves security
Pros and Cons
  • "Check Point NGFW is a fantastic product, and it is also easy to integrate with third-party devices."
  • "My experience with pricing, setup cost, and licensing for Check Point NGFW is that the high subscription fees aren't easy to afford, and it's not recommended for mid-sized companies or businesses."

What is our primary use case?

My main use case for Check Point NGFW is to filter the whole infrastructure traffic, and we use it as the perimeter firewall for our data center.

Check Point NGFW helps me in my daily operations by managing traffic across almost 30 branches, and we utilize its SD-WAN features to communicate with other third-party companies through a VPN.

For branch communication, we use the SD-WAN feature of Check Point NGFW, and through the VPN, we establish a connection between our company and the third-party companies. Currently, we filter our traffic between the branch sites and third-parties, and access the internet through that exchange firewall.

What is most valuable?

The best features Check Point NGFW offers in my experience are its application identification and control capabilities, which stand out as we use them beyond Layer 3 communications.

The application identification and control feature of Check Point NGFW helps my organization by allowing quick responses to make decisions and segregate applications that need more attention.

Check Point NGFW positively impacts my organization as it has improved our security posture and made us less vulnerable to attacks compared to our previous status; we can easily filter URLs and enhance web security.

While we don't have specific numbers, we measure increased security through our ability to block malicious attacks, including phishing attacks, easily.

What needs improvement?

Check Point NGFW has a steep learning curve for starters; it's not easy to learn and is a bit complex to start from scratch.

Check Point NGFW sometimes has limitations on third-party integrations, requiring more specifics rather than being straightforward.

For how long have I used the solution?

I have been using Check Point NGFW for almost two years.

What do I think about the stability of the solution?

Check Point NGFW is stable.

What do I think about the scalability of the solution?

We scaled up Check Point NGFW about six months ago, and it handled that scalability fantastically.

How are customer service and support?

Customer support for Check Point NGFW has been stable, even while we faced some issues.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I did not previously use a different solution; it was similar to Cisco ASA.

How was the initial setup?

The initial setup with Check Point NGFW was a bit complex.

What was our ROI?

We have seen a return on investment with Check Point NGFW as we have reduced incidents from the previous setup.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing for Check Point NGFW is that the high subscription fees aren't easy to afford, and it's not recommended for mid-sized companies or businesses. The cost is a little bit high compared to other competitors.

Which other solutions did I evaluate?

Before choosing Check Point NGFW, I evaluated Cisco, but I didn't look into other options on PeerSpot.

What other advice do I have?

I recommend Check Point NGFW to others looking into it because it's a good protective device.

From the vendor, I was not offered a gift card or incentive for this review.

Check Point NGFW is a fantastic product, and it is also easy to integrate with third-party devices.

On a scale of one to ten, I rate Check Point NGFW a nine.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Check Point Quantum Force (NGFW)
August 2026
Learn what your peers think about Check Point Quantum Force (NGFW). Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
908,858 professionals have used our research since 2012.
reviewer1088037 - PeerSpot reviewer
Senior Client Executive at a tech vendor with 10,001+ employees
MSP
Top 10
Oct 30, 2024
Powerful firewall for advanced security with robust support
Pros and Cons
  • "Check Point's support is probably the best of the major players in that space."
  • "Check Point's capabilities are limited from a firewall perspective."

What is our primary use case?

I do not use them, I just sell them, but customers are using them to protect on the edge and at the core.

What is most valuable?

It brings value to their clients as everybody is concerned with security. Firewalls are the first line of defense. Check Point's support is probably the best of the major players in that space. Check Point is more complex than the other players, but it is also more powerful.

What needs improvement?

A lot of the other players have a more robust best-of-suite offering versus the best-of-breed offering. Check Point's capabilities are limited from a firewall perspective. Other players are acquiring companies and offering add-ons like CASB or VPN-type capabilities.

For how long have I used the solution?

I have had experience with Check Point Next Generation Firewall for seven or eight years.

What do I think about the stability of the solution?

Their code is a little bit finicky as of late, but that's just because they just released this product line.

What do I think about the scalability of the solution?

It depends on what you're deploying. Maestro is more scalable than standalone firewalls.

How are customer service and support?

The support depends on what support model you buy. Customers that have dedicated support teams get more attention than the traditional support, however, a lot of other companies are offshoring their support.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Cisco is not a true security company, but Check Point is where they grew up, so I think they are a little more mature.

How was the initial setup?

The initial setup depends on the environment and can take weeks. It is not different than the rest of the players in terms of maintenance.

What about the implementation team?

It's basic engineers, usually one to two people.

What was our ROI?

It is pretty difficult to determine ROI with firewalls because they are more of an insurance policy. However, it helps with security. The cost of a breach versus having some of these measures in place is the real comparison.

What's my experience with pricing, setup cost, and licensing?

There is a lot of price parity between all the players. Everybody is within plus or minus ten percent. Check Point is probably more expensive than some of the other players out there, but it is incremental.

Which other solutions did I evaluate?

I evaluated Palo Alto and Fortinet.

What other advice do I have?

I would recommend Check Point Next Generation Firewall to others. I would put them in the upper echelon.

I'd rate the solution nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Genwhisper - PeerSpot reviewer
Director at a tech vendor with 5,001-10,000 employees
Real User
Top 20
Sep 11, 2024
Offers a lot of integration capabilities but lacks to offer flexibility during deployment
Pros and Cons
  • "The solution's technical support is fine."
  • "If you check each and every point from this part, you will find some flow in an area, or you will discover another flow in another area."

What is our primary use case?

Generally speaking, it's like any other NGFW. It's quite a versatile solution for many aspects. It's not like a separate solution for firewalling, but a separate solution for web access. It's just very convenient to have everything in one box. On the other hand, when you need something, like a very top-rank solution for very specific things, like network intrusion prevention or network intrusion detection as a component of NGFW, I would say it looks weaker compared to the well-designed solution for its purpose. It has the same issue as many other versatile or unified solutions, so it's really convenient.

What is most valuable?

From our point of view, including me and my colleagues, I would say it's really good that they have a lot of integrations with third-party companies. Integrations with third-party companies are really convenient. API offers many convenient ways to integrate with open-source solutions. It's very, very good when you have everything in one package and one bundle.

What needs improvement?

If you check each and every point from this part, you will find some flow in an area, or you will discover another flow in another area. It's unfortunate, and not a usual situation and it is not just for NGFW but for any other tool, making it a disadvantage where improvements are required.

For the next release, I would prefer the tool to be more flexible in terms of general deployments because some additional companies must be deployed as a basic one. For those who have been working with their solutions for a relatively short amount of time, it would be better for the tool to offer an adequate knowledge base, not just very superficial information, or maybe not too much in that spot, something like average stuff. The tool should be more flexible in terms of deployment, and a more adequate knowledge base should be available.

About the UI, it is hard to comment because it has been more or less the same for many years. Professionals have already been using the tool's interface for many years. From a contemporary angle, the tool's interface looks a bit outdated from a UI point of view. The UI has been more or less static in terms of changes for the last couple of years. People can get to the UI and work with it in a couple of months, but compared to any other solutions on the market, which are more flexible and more rapidly evolving, I would say that UI should be considered for improvement.

For how long have I used the solution?

I have been using Check Point NGFW for two to two and a half years. My company is a partner and reseller of the solution.

What do I think about the stability of the solution?

For stability in high-load networks, I rate the solution a six to seven out of ten.

What do I think about the scalability of the solution?

Scalability-wise, I rate the tool an eight to nine out of ten.

There could be some performance issues under the heavy deployments and heavy load, but generally, if you are talking about the general scalability, it is quite good.

The tool is suitable for large and very large enterprise businesses. From our company's practice, I would say it is meant for banks and financial institutions. It is also quite popular in heavy industries. I would say it has a more or less wide list. It is more or less very popular in banking.

The tool can be scaled up, but even despite high scalability, it requires a lot of extra companies to bear a high-load environment and high-load networks, making it a bit unfair, especially when comparing some of the numbers with the real-world statistics it likes too far from reality.

How are customer service and support?

The solution's technical support is fine. I rate the technical support a nine to ten out of ten.

How would you rate customer service and support?

Positive

How was the initial setup?

If ten means easy, I rate the product's initial setup phase a six to seven out of ten. It is not a plug-and-play solution. It requires much more skill and effort for the specialist to set it up properly. Even if there are any PoCs, you can easily discover the difference between the easy setup process and the more difficult setup phases, and I would say that Check Point falls under the latter category as it takes much more time and effort. Sometimes, it could be buggy, and you just need to fix some other firmware or software update.

The solution is deployed on an on-premises model for large and very large enterprises.

The time to deploy the solution depends on the stage because you can talk about the initial deployment or you can talk about the deployment, including the integrations. I would say that the integrations would be really time-consuming. For the initial deployment, I would say it is a couple of days if it is not really a large installation and a couple of weeks are needed for the initial deployment.

What was our ROI?

ROI is like an artificial point in connection to a solution like Check Point NGFW, and its numbers are quite questionable.

Suppose the company has too many different solutions from different vendors. In that case, it becomes a greater burden in terms of support and everything, especially in terms of management of these solutions. I would say that Check Point would be a good choice if they are planning to migrate. If it is something like a choice between one NGFW from a vendor and you want to move into the Check Point NGFW, it becomes a bit more tricky. It becomes really hard to say about the ROI because it is just like a different approach. If you are moving between a lot of different solutions from different companies, then ROI will be really good and attractive.

What's my experience with pricing, setup cost, and licensing?

The tool's price is reasonable in case you are not using it in a high-load environment. If you are not expecting significant increases or peak increases in loading, it should be fine. If it is a really highly loaded VLE environment, and if you try to rely on the tool's official numbers, I would say you can put your environment and network in jeopardy because it becomes really unstable. For the last couple of years, the situation has changed, and it has become really tricky to understand why the tool's official numbers aren't aligned with real-world numbers, which is a big problem for the VLE customers because when they are just trying to consider their official stats and official scalability numbers, it might be tricky. VLE customers should have, like, a 20 to 30 percent extra, or else, at this point, it becomes much more expensive.

The tool's prices don't make any sense because we are not talking about MSRP prices for VLE. We are talking about the discounted prices, which could be a really, really huge gap between the MSRP and the discounted price. I don't think these numbers will highlight any beneficial aspect of the price for you.

What other advice do I have?

There needs to be accuracy in terms of scalability. It should be well-designed, and if the customer does not have enough resources or their own resources, it is better to involve an adequate number of SIs. The system integrator will do the trick, and if a person is experienced, then everything can be really good in terms of the certifications, the statistics, and everything else. The system integrator should do everything properly, but it will be quite expensive, especially if we are talking about large and very large enterprises. For mid-sized businesses, it should be fine because it is less tricky, and even the normal specialized person on the customer side should be fine with using it, as it can be quite easy. In any case, scalability is a bottleneck here.

I rate the tool a seven out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Senior Implementation Security Engineer at Orange España
Real User
Top 20
Aug 29, 2024
Serves as a perimeter firewall at a cheaper rate but doesn't have a friendly GUI
Pros and Cons
  • "Google has a premium partnership with Check Point, involving extensive verification processes for major customers. This strong partnership indicates a significant level of collaboration between the two companies."
  • "The GUI is not very user-friendly, and configuring it can be challenging."

What is our primary use case?

I used Check Point NGFW to secure the data centers of medium to large enterprise companies. In many cases, it serves as a perimeter firewall, though its use can vary based on specific needs. Primarily, it functions as a defensive firewall.

What is most valuable?


What needs improvement?

The GUI is not very user-friendly, and configuring it can be challenging. The management console often has issues, sometimes requiring high CPU usage on your FTP or Windows system to open or manage sessions. It can be resource-intensive. Additionally, when viewing or monitoring logs, they sometimes do not appear immediately and may be outdated or missing.

For how long have I used the solution?

I have been using Check Point NGFW for two years.

What do I think about the stability of the solution?

It is a stable device.

What do I think about the scalability of the solution?

They support a range of enterprises, from small to large. Their solutions can accommodate environments with as few as 50 users to those with thousands or more. So, handling a large number of users is not an issue.

How are customer service and support?

Support is very good.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is not straightforward and can be more complex than that of other devices like Palo Alto or Fortinet firewalls. The setup for the CMA and management center requires careful implementation. Additionally, integrating components such as MDM and other security devices, including sandboxes, can be challenging to achieve a cohesive and secure environment.

The time required for deployment depends on the amount of configuration needed. Typically, it might take a full day, but with sufficient time, a basic configuration can often be completed in about eight to ten hours.

I have worked with both on-premises and VM versions. The CMA is typically deployed as a VM on a server, while the firewall is a physical device. 

What about the implementation team?

I have already deployed many times by myself, so there is no need for many people.

What's my experience with pricing, setup cost, and licensing?

It is a cheaper device than what other vendors offe.

What other advice do I have?

For security features, I typically use the templates or standards provided by the vendor. Based on my experience over the past three years, I haven’t encountered any significant complaints from customers about attacks or major issues while using the firewall to protect their data centers.

Google has a premium partnership with Check Point, involving extensive verification processes for major customers. This strong partnership indicates a significant level of collaboration between the two companies.

I haven’t handled any maintenance, but the support center has been very helpful. They provided excellent support and demonstrated strong knowledge whenever I reached out for assistance. They are proficient in various languages and have a good grasp of Linux, which is essential for effective support.

They provide good step-by-step implementation guides, similar to what is available for Fortinet's FortiGate. However, I find the implementation process for other vendors to be easier. Pricing varies among the three vendors, so there are differences in cost. Palo Alto offers the best options for sizing, though I haven’t worked operationally.

I recommend it, but you should know Linux and its commands to work effectively with this device.

Overall, I rate the solution a six out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
VinothS - PeerSpot reviewer
Solution Architecht at airtel
Real User
Feb 9, 2024
Ensures comprehensive security features, including URL filtering, content filtering, and global threat intelligence, while also providing scalability and ease of deployment
Pros and Cons
  • "Some of the most valuable features are URL filtering, web filtering, and content filtering."
  • "It would be beneficial if Check Point included more licenses bundled with the base model, reducing the need for additional subscription charges for essential functionalities."

What is our primary use case?

Our customers find that the Check Point NGFW highly effective for data center deployments. Additionally, smaller models are well-suited for branch locations where local internet breakout is necessary. These smaller models streamline internet access at remote sites, eliminating the need for third-party service providers and reducing costs. The 26000 and 28000 series excel in securing DMZs, while the lower-end versions are ideal for branch-level internet breakout, allowing direct cloud connectivity without intermediary networks. It offers cost savings and efficient security solutions tailored to various deployment scenarios.

What is most valuable?

Some of the most valuable features are URL filtering, web filtering, and content filtering. Typically, customers would need to invest in cloud web security solutions for local internet breakout. However, by deploying Check Point firewalls, which include these functionalities built-in at each site, the need for separate cloud-based solutions is eliminated. This consolidation reduces costs significantly, as one product serves multiple purposes: routing, switching, and next-generation security features such as timeboxing and malware filtering.

What needs improvement?

Check Point could enhance its capabilities further by focusing on global threat intelligence, particularly in addressing zero-day attacks and other unknown threats. If I were to suggest improvements for this firewall, it would involve enhancing its core features. Currently, there are many additional licenses available for purchase, such as DDoS protection, URL filtering, and global threat intelligence. These additional licenses increase the overall cost significantly, as they are add-ons to the base model. It would be beneficial if Check Point included more licenses bundled with the base model, reducing the need for additional subscription charges for essential functionalities.

For how long have I used the solution?

I have been working with it for one year.

What do I think about the stability of the solution?

I would rate its stability capabilities eight out of ten. I'm uncertain about its performance in large enterprises, where stability is paramount. It's crucial that the firewall can handle high throughput, accommodating multiple gigabytes of bandwidth, alongside additional firewall features like web filtering, content filtering, and sandboxing. In my experience with capacities ranging from one hundred to two hundred megabytes, focusing solely on web and content filtering, the product has proven to be stable.

What do I think about the scalability of the solution?

There is room for improvement in scalability. Adding more firewall features can impact the performance of the device, particularly in terms of processor capacity. I would rate it six out of ten. Our customers typically fall within the medium-sized business category.

How are customer service and support?

All manuals are accessible on the website, ensuring comprehensive documentation is readily available. The publicly available documentation is satisfactory, covering a wide range of information. However, certain documents not accessible to the public are provided to partners through a partner sign-in portal. This access ensures that all necessary documentation is available within our organization.

How was the initial setup?

The initial setup was quite straightforward. It involved basic configuration, which I would rate as an eight out of ten in terms of simplicity.

What about the implementation team?

The deployment took approximately five hours. The process can be executed in various methods. I typically perform a remote login from the console. The deployment involves three main steps: IP configuration, security configuration, and DNS setup, including any necessary DNS protection configurations.

What's my experience with pricing, setup cost, and licensing?

It falls in a moderate price range, not as inexpensive as some alternatives but not as costly as Palo Alto. I would rate it seven out of ten. There are numerous additional licenses required for advanced security features, leading to additional costs.

What other advice do I have?

Check Point has introduced several SD-WAN and IoT features, among others. I would suggest exploring the zero-trust features offered by Check Point. Additionally, if interested in incorporating SD-WAN or IoT capabilities, these features are readily available within the product. It's important to note that in today's landscape, Check Point offers more than just a traditional firewall; it's a comprehensive and advanced solution. Overall, I would rate it eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
PeerSpot user
Tempreviewercb Ba - PeerSpot reviewer
Network Specialist at CCV Deutschland GmbH
User
Oct 19, 2023
Robust, efficient, and very easy to implement
Pros and Cons
  • "We have found the central management (Smart Console) to be very helpful in managing all the firewalls and keeping the software/hotfix versions up to date."
  • "We have run into an interface expansion limitation, and thus it would be helpful if products lower in the stack would offer more interface expansion options."

What is our primary use case?

We use Check Point Quantum Network Gateways for all our on-site firewalls. It protects the network edge, network core, data center, and our AWS direct connect. 

We are a payment facilitator and security is one of our core requirements. 

We have implemented VSX which enabled us to reduce the hardware footprint. 

We have implemented 6700NGFW, 6600NGFW, and 6400NGFW in different network segments. We have enabled basic firewall, ClusterXL, and IPS licensing. 

Due to the nature of the traffic, we do not use Application Control or URL Filtering.

How has it helped my organization?

With our previous firewall solution, we had no automated compliance tools. Now, with the Check Point Quantum Network Gateways, we have the ability to automate compliance reports for both GDPR and PCI3.2, and by using VSX (Virtual System Extension) we have reduced our data center footprint. This will lead us to become a more sustainable organization. 

We have found the central management (Smart Console) to be very helpful in managing all the firewalls and keeping the software/hotfix versions up to date.

What is most valuable?

By implementing VSX (Virtual System Extension), we were able to reduce our hardware footprint, reducing both direct and indirect costs. This also enables us to quickly scale up or down to meet business needs.

We have also found that the Intrusion Prevention System implemented on Check Point Quantum Network Gateways is robust, efficient, and very easy to implement. Being able to add it later as a software feature is a real boon. The customization options enabled us to zero in on our specific use case.

What needs improvement?

Due to our unique environment, we have to implement BGP on our firewalls, and the way that BGP is implemented on Check Point Quantum Network Gateways is not intuitive and requires additional custom configuration. This caused a significant delay in our migration. The way that NAT is implemented was also not intuitive and required additional custom configuration.

We have also run into an interface expansion limitation, and thus it would be helpful if products lower in the stack would offer more interface expansion options.

For how long have I used the solution?

The solution has been in use for one year.

What do I think about the stability of the solution?

During the first year of operation, we have seen 100% up-time.

What do I think about the scalability of the solution?

Due to the VSX implementation, I would conclude that it is highly scalable.

How are customer service and support?

Customer service and support from the vendor have been excellent. They have assisted in communicating issues back to Check Point and the subsequent response from Check Point has been very good.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We used Cisco ASA 5500 series firewalls, but these have reached the end of life and needed to be replaced.

How was the initial setup?

The initial setup and migration was complex and we had a vendor team assisting.

What about the implementation team?

The expertise of the vendor team is excellent; I'd rate their services nine out of ten.

What's my experience with pricing, setup cost, and licensing?

It is important to carefully consider your needs. Additional features can be activated easily - for additional licensing costs. However, opting for extended licensing can provide cost savings through discounts.

Which other solutions did I evaluate?

In looking at replacing the existing firewalls we considered Cisco, Palo Alto, and Check Point. 

Check Point Quantum Network Gateways offered us a more favorable price point without compromising on functionality.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Tempreviewera A - PeerSpot reviewer
Infrastructure Developer at Holmen Iggesund
Real User
Nov 16, 2023
User-friendly interface, intuitive console, and helpful support
Pros and Cons
  • "We can define security policies based on a variety of criteria, including user identity, application, and content type."
  • "It would be nice to have comprehensive documentation and training resources that can help users and administrators to better understand and utilize the full range of Check Point's capabilities."

What is our primary use case?

Historically, the primary uses for these gateways were perimeter security and internet filtering. However, we now push all our internal traffic through the gateways for LAN segregation and to isolate obsolete operating systems.

Our isolated operating systems and LANs only allow specific traffic from a specific source to access them, making these critical production/business systems more secure. It's not a simple case of just replacing these legacy operating systems but replacing the industrial machinery that they control - which would require an investment of tens of millions of pounds.

How has it helped my organization?

Isolating obsolete operating systems wasn't in the scope when implementing the gateways originally. However, it has enabled us to secure Windows XP/Windows 7/2003/2008 machines which are end of support yet are still required to run industrial software and interface with large machines, which are not easy to replace.

Isolating machines and networks, along with SSL inspection, wasn't in scope when the gateways were spec'd. That said, five years later, they are still rock solid, and along with the Threat Cloud intelligence service, this ensures that our firewall is equipped with up-to-date threat intelligence, enhancing its ability to detect and mitigate emerging threats.

What is most valuable?

One of the strengths of Check Point Firewall lies in its granular policy management capabilities. We can define security policies based on a variety of criteria, including user identity, application, and content type. This level of granularity allows us to enforce security policies that align with our specific needs and compliance requirements.

One of the standout features of our Check Point Gateways is the user-friendly interface. Smart Console (management console) is well-designed and intuitive and provides administrators with a centralized hub for monitoring and configuring security policies. The web version isn't quite there yet, so to get the most out of it, the console needs to be installed, but it allows users to tailor it to their specific needs, and the menu structure is logical, making navigation a breeze for both novices and experienced administrators.

What needs improvement?

2FA on login would assist us with compliance however at the moment, it's not a major factor for us - yet may be in the future.

It would be nice to have comprehensive documentation and training resources that can help users and administrators better understand and utilize the full range of Check Point's capabilities. We ended up having to travel to London to sit through lots of training as we didn't find the information readily available.

Finding the costs associated with a particular blade can be challenging. This isn't specific to Check Point, but sometimes we need a ballpark cost quickly and don't have the time to speak to a reseller.

For how long have I used the solution?

The company has been using Check Point gateways for around five years, myself about two years.

What do I think about the stability of the solution?

Hardware has been 100%; software has been slightly less as we had an issue where the gateways would failover. 

What do I think about the scalability of the solution?

We run a pair of Gateways in HA mode, this solution has worked for us, and there have been no cases of downtime. Adding additional gateways should in theory be quite simple however for us there is no need.

How are customer service and support?

Support has been quick to respond to any questions or issues.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

The company used to sue Cisco Firepower. I wasn't with the company when switching.

How was the initial setup?

The setup was straightforward; the implementation team went on the CCSA and CCSE courses.

What about the implementation team?

We handled the setup initially in-house.

What was our ROI?

We ran these gateways for five years and will look to do the same with the replacements.

What's my experience with pricing, setup cost, and licensing?

Work with Check Point's presale team and complete the scoping document. If you are an existing customer, use the CPSizeME. 

Which other solutions did I evaluate?

The company also evaluated Palo Alto.

What other advice do I have?

We have run Check Point Security Gateways for five years and have had very few issues; they have been rock solid, and the hardware has been 100%.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer02975255 - PeerSpot reviewer
Senior Manager at BDO Unibank
User
Nov 1, 2023
Great IPS and anti-malware security blades with responsive technical support
Pros and Cons
  • "The successful performance of the security blades has shown the value of the investment along with the comparable success of leveraging the NGFW over a separate specialized security solution."
  • "The current reporting capability needs to be parsed and edited to be appreciated by leadership."

What is our primary use case?

Our company undertook a network transformation and instead of implementing a separate IPS solution, we've opted for the NGFW of Check Point. We've leveraged the different security blades available in the Check Point NGFW. Besides the IPS blade, we've also leveraged the anti-malware threat intelligence blades for our gateways, especially for the perimeter. 

We've also enabled the IPS blade for our remote offices as part of the additional security layer for our smaller international offices and used both the IPS and anti-malware for our bigger offices. 

How has it helped my organization?

We've managed to reduce the CAPEX cost of the network transformation when we leveraged the versatility of the Check Point NGFW solution. 

Instead of purchasing separate solutions for the IPS, anti-malware, and threat intelligence, the security blades of the Check Point NGFW were just enabled. 

The software subscription cost is already included in the annual software and hardware maintenance cost which made the solution more cost-effective than having separate solutions wherein we need to maintain a separate subscription for each. 

What is most valuable?

Besides the basic firewall feature of the Check Point NGFW, we find the IPS and anti-malware security blades to be most valuable for our current implementation.

The IPS and anti-malware solutions have successfully identified and blocked potential threats from our perimeter. 

Though we are also using threat intelligence, we see more validation of the successful use of the IPS an anti-malware. 

The successful performance of the security blades has shown the value of the investment along with the comparable success of leveraging the NGFW over a separate specialized security solution. 

What needs improvement?

Overall, we are satisfied with the performance of the NGFW both from the functional and operational perspective. The solution has been proven effective in detecting and blocking potential and intentional threats to the company's internal network without impacting the performance of the appliance. 

What can be improved though is the capability of providing an executive summary report that can highlight the performance and operational effectiveness of the implemented security solution. The current reporting capability needs to be parsed and edited to be appreciated by leadership.

For how long have I used the solution?

We've been using Check Point NGFW for more than 4 four years.

What do I think about the stability of the solution?

Check Point NGFW has been very stable and very rarely do we encounter any performance issues due to hardware or software issues. 

What do I think about the scalability of the solution?

The solution is very scalable and easy to manage.

How are customer service and support?

Customer service and support are very responsive, and we get quick and fairly consistent turnaround times for the resolution. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We previously used Cisco Firepower, however, we were not satisfied with its performance both functional and operational. 

How was the initial setup?

The initial setup was straightforward since the deployment is just the typical high-availability active standby implementation. 

What about the implementation team?

We implement through a vendor team. The vendor team is very competent and has consistently displayed their expertise in the technology. 

What was our ROI?

Unfortunately, our team does not have visibility on the ROI.

What's my experience with pricing, setup cost, and licensing?

If the implementation would require multiple gateways, consider leveraging the Infinity Total Protection. 

Which other solutions did I evaluate?

We no longer evaluated other options. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer98265120 - PeerSpot reviewer
Senior Technical Consultant at CDW
MSP
Nov 1, 2023
Improves environments, has helpful support, and offer great compute power
Pros and Cons
  • "The Check Point appliances are considered NGFW devices and can process both the ASA and FTD requirements on a single instance, removing the requirement for an expansion SSD module and/or additional hardware."
  • "We'd like an option that can convert other vendors' NGFW configurations to supported Check Point NGFW config for ease of migration."

What is our primary use case?

The customer purchased Check Point 6200 Firewalls to replace their aging Cisco ASA firewalls on the perimeter of their sites. The Cisco Firewalls must be replaced due to insufficient capacity.

It is envisioned that the initial migration will be a direct replica of the ASA configuration, with the client expanding the solution post-migration, with Check Point NGFW features.

This project consisted of the following deliverables:
• Rule base is migrated like for like, in which ASA Firewall zone-based rules will be converted to Check Point Parent/Child layered rules.
• Firewall zones to be imported and reviewed post migration by client.
• NAT rules will be migrated “as-is”.
• Geo-location rules from FTD will be honored and mapped into Check Point.
• Client-based blacklisting will be migrated into the solution, using external feeds via URL.
• A single IPS profile consisting of a clone of the vendor's “out-of-box” balanced profile (optimized).
• 1X site-to-site VPN.
• Integration into Client’s Cisco ISE solution for RADIUS-based admin authentication.
• NGFW licensing and blades to be installed on firewall devices, to allow features to be enabled in the future and expand the solution.

How has it helped my organization?

The Client wishes for the ASA firewalls to be replaced with a Check Point systems solution, which consists of 6200 Plus Appliances. 

The initial requirement was to migrate the configuration in an “as-is” state, with the necessary licensing purchased and installed to enable expansion of the solution with next-generation feature sets in the future.

The solution was able to meet and exceed the client's requirements thereby improving the client's environment.

The management server is software-based.

Firewalls and licensing include:
• FW
• IPS

The solution provides a single pane of glass management of rules/logging.

The solution supports IPsec tunnels FOR 1X IPsec VPNs.

The solution integrates with the client’s Cisco ISE RADIUS solution for administrative access.

What is most valuable?

The compute power of the appliance is great. The Check Point appliances are considered NGFW devices and can process both the ASA and FTD requirements on a single instance, removing the requirement for an expansion SSD module and/or additional hardware.

What needs improvement?

We'd like an option that can convert other vendors' NGFW configurations to supported Check Point NGFW config for ease of migration.

Check Point configuration options can be very enormous and overwhelming.
Check Point comes with a very lean learning curve even though they offer a robust knowledge base. 

A lot of configuration cannot be accomplished via the web interface or the smart dashboard software and must be done manually via the command line interface.

I'd like to see some built-in automation for the firewall alerts/events to trigger an automated response or recovery.

For how long have I used the solution?

I've used the solution for three years.

What do I think about the stability of the solution?

The solution is stable with frequent version and management updates.

What do I think about the scalability of the solution?

The solution is highly scalable and expandable.

How are customer service and support?

The solution offers great customer support.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We used a different solution and needed more processing power and functionality which this had compared to industry competitors.

How was the initial setup?

The setup was straightforward yet third-party device migration contained a lot of manual configuration conversions.

What about the implementation team?

I implemented this myself.

What's my experience with pricing, setup cost, and licensing?

Pricing can be relatively more expensive when compared to industry peers, however, the functionality makes up for the price difference.

Which other solutions did I evaluate?

We also evaluated:

What other advice do I have?

This is a great overall solution.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Check point Partner
PeerSpot user
Buyer's Guide
Download our free Check Point Quantum Force (NGFW) Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2026
Buyer's Guide
Download our free Check Point Quantum Force (NGFW) Report and get advice and tips from experienced pros sharing their opinions.