Security Manager: It effectively manages the complexity and change associated with today’s network security infrastructure and has a good hold in the market.
Network Security Sr. Advisor at a tech services company with 1,001-5,000 employees
It’s helpful during our firewall and network devices audit.
What is most valuable?
How has it helped my organization?
It’s very helpful during our firewall and network devices audit, and also beneficial when backup is required of network security devices.
What needs improvement?
I am desperately looking forward to seeing FireMon considered as a good backup solution for network security devices, which can store up to the last 10 incremental backups. This way, the business can grow with multiple solutions to customer.
For how long have I used the solution?
I have been using it for five years.
Buyer's Guide
FireMon Security Manager
June 2025

Learn what your peers think about FireMon Security Manager. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,632 professionals have used our research since 2012.
What was my experience with deployment of the solution?
I have not really encountered any deployment, stability or scalability issues. Installation and upgrade are quite simple and easy.
How are customer service and support?
Technical support is satisfactory.
Which solution did I use previously and why did I switch?
Previously we were using AlgoSec, but it requires to be updated from time to time. Also, it wasn’t found to be a fruitful solution and has a lot of room for improvement.
How was the initial setup?
We recently installed FireMon on VMware architecture and it was very smooth and without issues.
What about the implementation team?
Implementation was easy and documents are available in FireMon Center, so the in-house support team implemented it without any issues.
What's my experience with pricing, setup cost, and licensing?
Per-device license is little costly, but with such good features it’s understandable.
What other advice do I have?
It is a good solution for audit trails and end-user visibility.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Engineer at a energy/utilities company with 51-200 employees
It helped us identify unused rules, reducing the load on the firewalls.
What is most valuable?
The Configuration Change Management feature was something we were interested in as it helped us to identify who made the change, when and why. Also, the workflow was easy to set up to ease operations.
The second important feature I liked was determining unused rules - rules placed incorrectly in the ACL - this helped us to reduce the load on the firewalls, thus we didn’t have to buy a new firewall due to high CPU or memory consumption. With the help of FireMon, we fine-tuned the rules and were able to save money for buying a new firewall.
How has it helped my organization?
As mentioned, we were able to ease the operations and set up a workflow that allowed the firewall and other network-related requests to go through a formal approval process. This helped to track who, when and why the request was done.
Also, removing redundant rules and placing the rules at the correct place helped lower CPU and memory consumption.
What needs improvement?
I would have preferred fewer updates, as there were quite a few updates made every now and then. Secondly, the Risk Management Module didn’t work well until you have the all of the subnets mapped. This can be improved.
For how long have I used the solution?
I used it for two years.
What was my experience with deployment of the solution?
I didn’t really encounter any deployment issues. However, sometimes the GUI used to crash when it tried to populate the device map; we had a lot of devices. At times, the map displayed fine, even though it took some time to show up; and at other times, the GUI crashed. This should be fixed.
How are customer service and technical support?
Technical support was fine; they have good technical people. However, support can be improved, if they become more responsive.
Which solution did I use previously and why did I switch?
I did not previously use a different solution.
How was the initial setup?
Initial setup was fine; you just need to map certificates between the sensor and the Application Server, which was something different. It can be sorted out through some other methods as well. I don’t exactly remember, but we faced one issue and to resolve it, we had to install the certificates again to get it working.
What about the implementation team?
Implementation was done by the vendor team.
What's my experience with pricing, setup cost, and licensing?
Although I have left the company, I heard that since the license renewal cost was too high, management decided not to renew it. The vendor should reduce the license renewal cost.
Which other solutions did I evaluate?
I personally did not test any other alternative, but I heard management evaluated Skybox as well; they eventually chose FireMon. It was a management decision, so I don’t know why others were rejected.
What other advice do I have?
Check the renewal cost, and determine whether the Risk Management Module is mature enough and whether GUI crash issues have been fixed or not. Maybe for small companies, it comes up fine, but for large environments, it might cause issues.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
FireMon Security Manager
June 2025

Learn what your peers think about FireMon Security Manager. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,632 professionals have used our research since 2012.
Systems Engineer at a tech company with 51-200 employees
It provides clear visibility of our firewall, and clear auditing of each firewall rule and changes.
Valuable Features
We can check the compliance of each firewall, check the KPI of each firewall to determine the security posture of the network, monitor changes done on the firewalls and provide overview of all the rules, either unused, duplicate or risky rules.
Improvements to My Organization
We now have clear visibility of our firewall, clear auditing of each firewall rule and changes, and of course, it helps us comply with governing bodies.
Room for Improvement
They should add SMB firewall support and not only the big players.
Use of Solution
I have used it for one year.
Stability Issues
I did not encounter any stability issues.
Scalability Issues
I did not encounter any scalability issues.
Customer Service and Technical Support
Technical support is 9/10.
Initial Setup
Initial setup was straightforward and it was easy to follow the installation steps.
Pricing, Setup Cost and Licensing
It has great pricing with big discounts.
Other Advice
Prepare the necessary details and make sure you configure the needed firewall according to their guide for a smooth implementation.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Giancarlo,
Thank you for taking the time to write a review of FireMon. I am glad to see you are finding overall satisfaction with the product. We look forward to working with your team more in the future.
Regional Manager Enterprise Data Infrastructure and Information Security at a comms service provider with 51-200 employees
RA excels at identifying risk exposure areas.
Valuable Features
Security Manager (SM) and Risk Analyzer (RA) are the most valuable features to me. SM assesses a network's security posture in terms of deployed policies, redundant policies, duplicate policies, etc. RA takes a snapshot of everything connected to and within the network down to the end points. It recommends security policies that would improve and further secure the network from potential threats etc.
Improvements to My Organization
The product is extremely helpful in policy analysis and improvement. RA was exceptional is identifying risk exposure areas.
Room for Improvement
Although there is nothing 'wrong' in FireMon's support for other vendors, with the advent of SDN, NGFW, etc., I think FireMon will have to cover more layer 3 devices from different vendors. Again, their current database covers almost all of the major vendors: Cisco, Juniper, Fortinet, etc. However, there is always room for growth in this particular area.
Use of Solution
I have used this solution since 2012.
Stability Issues
We have not encountered any issues with stability so far.
Scalability Issues
We have not encountered any issues with scalability so far.
Customer Service and Technical Support
Their technical support is superior.
Pricing, Setup Cost and Licensing
Pricing and licensing is structured well and FireMon was very helpful in meeting the target budget for this project.
Other Solutions Considered
We looked at AlgoSec before choosing FireMon.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Engineer at a insurance company with 1,001-5,000 employees
It allows us to monitor and assess our network and provides proactive security intelligence.
What is most valuable?
It’s provided us with proactive security intelligence so we can act before we have a security breach.
How has it helped my organization?
FireMon allows us to monitor and assess our network, giving continuous visibility into and control over firewall infrastructure, network security policies and underlying IT risk.
What needs improvement?
The reporting needs some improvement to ensure that we are provided with consistent data accross each firewall device on the network.
For how long have I used the solution?
I’ve been using it for two years.
What was my experience with deployment of the solution?
There were no issues with the deployment.
What do I think about the stability of the solution?
We had no issues with the performance.
What do I think about the scalability of the solution?
It's been able to scale for our needs.
How are customer service and technical support?
8/10
Which solution did I use previously and why did I switch?
This is my first time using a solution like this.
How was the initial setup?
It’s quite straightforward.
What about the implementation team?
We had it implemented by a vendor team.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Thank you for taking the time to review our product. I am pleased to hear that Security Manager is bringing you increased visibility into your environment. At FireMon we take pride in our solution and the value that it brings to your environment and look forward to continuing to work with you and your team in the future.
Security Consultant at a tech services company with 501-1,000 employees
Rule comparison and filters are an easy way to check if you policy is concise and clean.
Valuable Features
The instant and complete network graphical view it provides is amazing. Alerts give you complete control of firewall changes, its amazing for compliance and security policy validation. Rule comparison and filters are an easy way to check if you policy is concise and clean, giving your firewall the best performance and readability.
Improvements to My Organization
We managed around 70 different firewalls in more than 25 countries all over the world. The firewalls were from different vendors such as Palo Alto, Checkpoint, Cisco, Juniper, etc. FireMon helped to decrease the workload on risk analysis and also firewall rulebase review time by 50%, at least due to its very elaborate and easy to use filters.
Room for Improvement
It’s been a constant need not only to analyze firewall rules and configurations but also implement them, for which FireMon has no support. Also some of the firewall analysis involve weak password policy, FireMon could implement a way to send firewall hashes, when they exist, to third party cracking softwares.
Use of Solution
I used this solution for about three years in my previous job. I primarily used the Policy Planner and Policy Optimizer modules.
Deployment Issues
The deployment was already easy for v7.0, the upgrade to v8.0 is even easier.
Stability Issues
We had no issues with the performance.
Scalability Issues
It's been able to scale for our needs.
Customer Service and Technical Support
I would rate it 8/10. The only reason I don’t rate it 10/10 is because of the response time which, for us, sometimes took a little bit longer then expected. Customer service and technical support is very good.
Initial Setup
The initial setup was very easy and straightforward and we had no problems implementing it.
Implementation Team
It was initially implemented by a vendor team, but the implementation could easily be done in house.
Pricing, Setup Cost and Licensing
FireMon is not a cheap solution but its price is well balance for what it has to offer.
Other Solutions Considered
We have evaluated FireMon’s competitors like AlgoSec and others, but found FireMon to be the best solution for our needs due to having a complete set of tools.
Other Advice
Be sure you read all the specs, and test the application as deeply as you can to ensure it meets all your requirements.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Felipe, thank you for taking the time to write a review of FireMon. I am glad to see you are finding overall satisfaction with the product. Please feel free to drop us a note at customersuccess@firemon.com with any future questions or concerns.
Senior Network Security Engineer at a local government with 1,001-5,000 employees
In addition to firewall auditing, we use it for rule traffic analysis, traffic flow discovery and hidden/shadow rules.
Pros and Cons
- "Firewall auditing is very important. We also use the solution for rule traffic analysis, traffic flow discovery and hidden/shadow rules within over 100 firewalls spanning five different brands."
- "One area for 7.x customers that needs improvement is the migration. It is an involved process so get ready to spend some time getting your environment back to the way it was."
What is most valuable?
Firewall auditing is very important. We also use the solution for rule traffic analysis, traffic flow discovery and hidden/shadow rules within over 100 firewalls spanning five different brands. These features are valuable as firewall rules are constantly added but its tough to determine what can get cleaned up over time. Knowing how frequently a rule is used, where redundant rules exist and documenting changes are important.
How has it helped my organization?
Since our network is large, someone new like myself has a challenge when we need to make changes to permit certain traffic. Often this traffic will traverse multiple firewalls and FireMon can help demystify where needed rules need to be implemented.
What needs improvement?
We just went from the v7.x to their latest web based v8.x which was a welcome change. One area for 7.x customers that needs improvement is the migration. It is an involved process so get ready to spend some time getting your environment back to the way it was. Another area that could use improvement is the traffic path analysis. FireMon uses learned zone data against interfaces to help determine traffic pathways. The catch here is in v8.x, you now have to specify a source or destination network which may throw off the results sending you to the incorrect firewall. Since we just upgraded last week, there aren't many other items that we can see as improvements as we are just getting familiar with this version.
For how long have I used the solution?
I've used this solution for a little over one year.
What was my experience with deployment of the solution?
The migration from v7 to v8 needs to be improved but we had no issues in the initial deployment.
What do I think about the stability of the solution?
We have a centralized server with data collector appliances placed between two data centers. We were losing change data because one of the collectors had too much load on it but we never knew. Support had to dig deep when we had our 7.x install and help balance out our firewall to collector ratio to ensure we weren't flooding any one collector.
What do I think about the scalability of the solution?
It's been able to scale for our needs.
How are customer service and technical support?
Their support is very good. They are generally responsive and I have needed to escalate only a couple of times.
Which solution did I use previously and why did I switch?
We had no solution in place prior to this. FireMon was the best choice as they really specialize in this niche market.
How was the initial setup?
Like anything new, we needed help from support to get our initial setup moving along. However once you learn the basics, it's not hard moving around the system.
What about the implementation team?
We did get FireMon's assistance during our initial implementation. I encourage this as every environment is different and for me it was worth the investment to get that initial startup help to get things going.
What other advice do I have?
Like any implementation, take time and plan. Engage users and stakeholders letting them know what this system can do and get it integrated within the organizational ecosystem. Like any solution, if it isn't used you simply don't get that potential dividend.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Brendan, thank you for taking the time to write a review of FireMon. I am glad to see you are finding overall satisfaction with the product. Please feel free to drop us a note at customersuccess@firemon.com for any future questions or concerns.
Network Engineer at a tech services company with 501-1,000 employees
It allows you to put expiration dates on ACL's to remove unneeded exceptions, but network maps need more improvement.
What is most valuable?
The reports you can run to look for redundant ACL’s in the firewalls, and the policy trace and review. It also allows you to tie to multiple domains so that the administrators for the FireMon servers do not have to deal with the hassle of making 'view only' accounts. You can also use the Insight function to keep records of the ACL’s. Instead of filling up the firewall with remark statements that could lose their position, you can leave all the information in the FireMon server, and you can tie in ticket information. It also allows you to put an expiration date on that ACL so that you can always remove unneeded exceptions.
How has it helped my organization?
It improved performance of the organization, as instead of going line through line of the firewall, we were able to quickly find IP addresses or services using Firemon.
What needs improvement?
I believe their network maps have a lot of room for improvement. I think they should allow more customization.
For how long have I used the solution?
I have only worked on this product for a year.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
We have not had any issues with stability.
What do I think about the scalability of the solution?
My organization only used FireMon for Cisco ASA products, so I am not sure if it works with other firewalls but it does support other vendors.
How are customer service and technical support?
Customer Service:
Great, they hold free WebEx sessions for additional training on FireMon.
Technical Support:They're extremely responsive and experienced on the product.
Which solution did I use previously and why did I switch?
We did not have a previous solution.
What about the implementation team?
An in-house team did it.
What other advice do I have?
Using this product allows firewall administrators to quickly find a problem with their firewall configurations. It allows the administrators to also look for open services that should not be allowed. One of the most useful features is the ability to use policy trace. If you work in an environment with multiple tiered firewalls you can look at exactly what ACL’s the traffic is going through on each firewall without having to have permission to those firewalls.
It is a smart move to make and makes the administration and troubleshooting of ACL problems clear.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Michael,
Thank you for taking the time to write a review of FireMon. I am glad to see you are finding overall satisfaction with the product.
In regards customization on the map, you can always open a RFE (Request For Enhancement) ticket. This is closely monitored by our Product Management Team, and allow us to understand our customer's needs.
We look forward to working with your team more in the future.

Buyer's Guide
Download our free FireMon Security Manager Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Firewall Security ManagementPopular Comparisons
Tufin Orchestration Suite
Fortinet FortiGate Cloud
Skybox Security Suite
Palo Alto Networks Panorama
AWS Firewall Manager
Azure Firewall Manager
ManageEngine Firewall Analyzer
Cisco Security Cloud Control
Cisco Secure Firewall Management Center
Buyer's Guide
Download our free FireMon Security Manager Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Tasks to Perform on Preventive Maintenance.
- From your experience, what are the technical differences between AlgoSec and FireMon?
- What Is The Biggest Difference Between AlgoSec and FireMon?
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Comparing network security vendors and devices
- When should companies use SSL Inspection?
- When evaluating Firewall Security Management, what aspect do you think is the most important to look for?
- What are the most important features you would be looking for in a firewall?
- How do I estimate the required firewall throughput for my organization?
- What are the pros and cons of Tufin, AlgoSec and RedSeal?
Thank you for providing your detailed feedback on FireMon Security Manager. We truly appreciate the investment of your time to post a review.
In regards to your statement about issues displaying the device map; It is highly recommended to organize devices into device groups. This improves usability for organizations with a large number of devices, and reduces the amount of time taken to display the device map.