We use it for rule re-certification and rule review. Twice a week, we use the Tufin report to see what changes or adds were done to the policies. Finally, we also use it for rule automation. We have it integrated with ServiceNow for rule requests.
Senior Network Engineer at a financial services firm with 10,001+ employees
Helps with auditing by proving what changes were done, when, and by whom
Pros and Cons
- "The best feature for me is being able to look up objects within all of our policies, because we have a little over 12,000 rules and over 30,000 objects. When one person says, 'Hey, where's my server?' I can just go to Tufin and say, 'Hey, where is that server?' and very quickly it tells you where it is, what policy it's on. That is a life saver."
- "Tufin is a convenient way for us to show and prove what changes were done, when they were done, and by whom they were done."
- "For me, there are two things that can make Tufin a bit better... [It needs] a better focus on automation - automating a lot of the processes; and automating rule re-certification, or at least finding a way to simplify it."
- "The cost is too much. For us it's around $40,000."
What is our primary use case?
How has it helped my organization?
It has improved our organization through the beginning of automation. It has also helped in terms of auditing. Tufin is a convenient way for us to show and prove what changes were done, when they were done, and by whom they were done.
Tufin also helps ensure that security policies are followed across our entire hybrid network. We use the USP, Universal Security Profile, which is governed by our cyber team. That team sets up the parameters and then, through the automation, when a request comes in, the first thing it does is check if it meets or violates. If it violates, it sends it right back to the requester. Another way we do it is that when somebody puts a request in, it goes through the USP. Then the cyber team combs through it to make sure that whatever service they're asking for can happen. For example, if someone wants Dev going to the internet, of course that's not going to happen. They'll filter all that out before it comes to us. Once it comes to us, we'll implement it, and then we comb through all the reports and make sure that nobody missed anything.
It also helps expedite changes.
What is most valuable?
The reports are very valuable. In terms of cleaning up firewall policies, we use Tufin to gather information in the reports. However, we don't automate Tufin to do the work. It's still done by a firewall engineer.
But the best feature for me is being able to look up objects within all of our policies, because we have a little over 12,000 rules and over 30,000 objects. When one person says, "Hey, where's my server?" I can just go to Tufin and say, "Hey, where is that server?" and very quickly it tells me where it is, what policy it's on. That is a life saver. Without that, I'd be a janitor.
The visibility it provides is also very good.
The change workload process is flexible and customizable. For example, we have it working with ServiceNow. When somebody requests to have a rule in place or requests a firewall, they will first go to ServiceNow and put all their information in. ServiceNow then sends that over to Tufin and Tufin does its magic - verifies the USPs and does the design. That part is simplified. However, there are little mechanics in between that could be a lot better.
We use the solution to automatically check if a change request would violate any security policies or rules. Our cyber team is on it as well. We comb through all the changes done for that rule and verify. Before we do a push, we verify that there was no compromise to our security posture.
What needs improvement?
For me, there are two things that can make Tufin a bit better. This could be something on my end that I don't understand or maybe it can already be done and I don't know, but the two things that I am hoping to get out of this couple of days here at Tufinnovate 2019 are: have a better focus on automation - automating a lot of the processes; and automating rule re-certification, or at least finding a way to simplify it.
In my industry, the banking industry, we're heavily regulated. Auditors are everywhere and they want everything accounted for. When I do a rule re-certification, I have to justify why that rule still there, who is using the rule, what's going on. Or if it hasn't been used, I want to get rid of it. But I don't want the onus to be on the firewall team. I want that onus to be on the person who requested the rule. I'm trying to figure out a way that I can have Tufin say, "Hey, look, John or Joan, your rules haven't been used in a year," or "Do you still require these rules or these servers?" and it would give them buttons to click, either "yes" or "no".
If they hit "no," Tufin would say, "Thanks very much," and disable them for 30 days, in case they made a mistake, and after 30 days, it would remove them. That type of automation would save us so much time. Right now, there are three people doing that job.
As an example with rules, when I look at a rule it will tell me how many days it was hit, when the last hit was, when it was last modified, but I can't get a creation date. What date was it created? It must know when it was created because it created an OUI for the rule. I asked support and they said, "Well, go here, go there, do this, spin your head and tap three times, and if you're lucky..." And I'm thinking, "Can you not just tell me the date it was created?" Then I could filter on those as well. Right now, I can't filter on rules that are over five years old, for example. Even when they're in use, I still want to see old rules. Maybe they've got old services that shouldn't be working anymore.
I would also like to see better logging.
SecureChange could be a bit better, at least with integration with ServiceNow or some of the other ticketing tools.
Buyer's Guide
Tufin Orchestration Suite
July 2026
Learn what your peers think about Tufin Orchestration Suite. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,877 professionals have used our research since 2012.
What do I think about the scalability of the solution?
The scalability is amazing. We have it in two data centers. We have full redundancy with it. I have no qualms about its scalability, whatsoever.
How are customer service and support?
Technical support has been very good. I've dealt with Professional Services and I dealt with a programmer when we did our ServiceNow with Tufin. They were really good; two of the best guys. Top-notch. My Professional Services guy is awesome. He's my go-to guy. The other gentleman, whose name is Neil, was really good. He was very kind, very accommodating, top-notch.
Which solution did I use previously and why did I switch?
The switch to Tufin was done before I got to this company, but if I had to guess, I imagine somebody tried to jump out of the window or thought, "I'm going to go nuts if I have to look up one object in a pool of 30,000 and 8,000 rules." It's over 80 firewalls.
How was the initial setup?
The initial setup was complex because we had to integrate with ServiceNow. That's what made it complex. Tufin would say, "Hey, we can do this," and ServiceNow would say, "Yeah, we can't do that." Or ServiceNow would say, "We do it this way," and Tufin would reply, "Yeah, that's not going to happen."
If it was just a stand-up and write some custom workflows, that would have been a lot easier.
What about the implementation team?
We had a vendor or reseller with us, but they didn't have much experience with the size of network we have, so they were more listening in and trying to get experience while things were going on. I'm okay with that. At the end of the day, it was the Tufin guys who actually brought it all together.
What was our ROI?
If we look at the cost of a firewall engineer and the time saved as return on investment, we have seen a return. If we didn't have Tufin at all and the work that I'm doing now had to be done manually, those hours are about a four-to-one ratio. So that is a return on investment.
What's my experience with pricing, setup cost, and licensing?
The cost is too much. For us it's around $40,000.
What other advice do I have?
I've already recommended Tufin to other people, absolutely. There was another company that has Check Point, I'd meet with them at Check Point expos and we'd talk. I would tell them I'm doing the rule re-cert with the bank and tell them, "Get Tufin." The first thing you want to do is get SecureTrack. Get it set up, get it working. Then you can grow from there. If you don't know what's going on with all the policies, you're blowing your brains out. I always recommend Tufin.
We're working on getting the solution to help us meet our compliance mandates. That's one of my projects, starting this year.
In my opinion, the solution’s cloud-native security features are good. I just don't have anything to compare them to. I can't say I have worked with AlgoSec or FireMon so I can't compare Tufin and say, "Oh, you guys are much better than that guy." Tufin is the only product I've worked with in policy management.
Tufin is better than the way we're using it. I firmly believe that we're not using it to its full capability. It's like having a Ferrari in the garage but using it to go get groceries. Someone might look at it and say, "Oh my God, we could be on the Autobahn, flying." And I say, "Yeah, I know, but I need groceries." I don't think we're using it to its full potential. However, from what I'm seeing now, and in future developments based on this conference, it's going in the right direction.
I would rate it at eight out of ten. We are strictly a Check Point shop for firewalls. We don't have other vendors. I can see where, if I had Palo Altos and Fortinets and Ciscos, Tufin would be Godsend. I wouldn't have to go combing through every vendor. Whereas for us, it's already together. That may be why I don't rate higher.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Consultant at Critical Design Analytics
The change workflow process is very easy to customize
Pros and Cons
- "The change workflow process is very easy to customize. You can do a workflow however you want, so you can have an approval every single step. Or, you can remove approvals on certain steps, automating some steps."
- "The preconfigured PCI compliance USPs are the best part for me."
- "We have had a couple issues with the VMs, but I think it was just because they were starving for resources. A recommendation on what the virtual appliances should have for resources would be appreciated."
What is our primary use case?
We implement Tufin for other customers and help set it up.
I'm not the end user. I just set it up for the end user.
We are using the latest version from 2018.
How has it helped my organization?
We use Tufin to clean up our firewall policies. They already have the compliance policies sort of prepopulated in there to point out violations.
Most customers will go through and check the USP to see if it violated with the designer tool.
We are in the process of working with a customer right now to set up the Unified Security Policy (USP). We got all the violations from the first phase and will go through to do the mediations, then run the scan again to show the progression of the clients.
What is most valuable?
The preconfigured PCI compliance USPs are the best part for me. These make things a lot easier.
The visualizer for the Network Topology is really good. You can see all the routes throughout your entire environment.
The change workflow process is very easy to customize. You can do a workflow however you want, so you can have an approval every single step. Or, you can remove approvals on certain steps, automating some steps.
It capabilities are very good.
What needs improvement?
Sometimes, the user interface is a little cumbersome, trying to navigate between them. In the new version, it looks like they resolved those issues.
What do I think about the stability of the solution?
We have had a couple issues with the VMs, but I think it was just because they were starving for resources. A recommendation on what the virtual appliances should have for resources would be appreciated.
What do I think about the scalability of the solution?
We have done PR strategies and added Tufin appliances. It is super easy to just back up and restore to a new one. You can get a new appliance up and running in 20 minutes.
How are customer service and technical support?
We worked with their professional support before, but we have not worked with their Professional services.
How was the initial setup?
The initial setup is straightforward.
What about the implementation team?
We are a reseller.
What was our ROI?
We've install it to make money.
Tufin does make the process faster for customers, depending on if they use SecureChange to automate their process. Everything is all in one then.
What's my experience with pricing, setup cost, and licensing?
Licensing is on a customer by customer basis.
What other advice do I have?
Try Tufin out. Make a PoC of it. That is how we sell most of our products because it works well.
Our customers do not have a hybrid network.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller.
Buyer's Guide
Tufin Orchestration Suite
July 2026
Learn what your peers think about Tufin Orchestration Suite. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,877 professionals have used our research since 2012.
Head of IT Security at Banco Privado
A powerful tool for a security team to optimize time
Pros and Cons
- "We use Tufin to clean up our firewall policies because it is so fast, as a report about compliance and the clean-up process used to take about one month before, but with Tufin it takes only one day."
- "I would like to see more about the cloud in the next release. They need a large plan to deploy the cloud into the solution and a way to implement it."
What is our primary use case?
The primary use case is for compliance with PCI regulation for local and country regulations.
We are using the latest version of the product.
How has it helped my organization?
We use Tufin to clean up our firewall policies because it is so fast. A report about compliance and the clean-up process used to take about one month up before. With Tufin, it takes only one day.
Implementing roles in the firewall used to take two days, but now, it takes two hours.
The audit and policy relation reports have helped me show compliance to managers.
The product helps my cybersecurity team. Now, my cybersecurity team spends their time creating new controls for new technologies.
What is most valuable?
The workflow is the most valuable feature.
The visibility that the solution provides is amazing.
The change workflow process is flexible and customizable. I can send one request to an IT Manager and another one to a Development Manager, making them customized.
What needs improvement?
I would like to see more about the cloud in the next release. They need a large plan to deploy the cloud into the solution and a way to implement it.
The web service for integration with other solutions needs improvement.
What do I think about the stability of the solution?
The stability is okay.
What do I think about the scalability of the solution?
At this moment, it is not necessary to expand the solution.
How are customer service and technical support?
I don't really use the technical support.
Which solution did I use previously and why did I switch?
We did not have a previous solution. I was looking for a solution to optimize time in security policy management. Then, I found the Tufin and contacted a reseller.
How was the initial setup?
The initial setup was super easy. It was fast to implement the firewall. The Check Point was very fast.
What about the implementation team?
We used a reseller for the implementation. It was the first time for the reseller to do this implementation.
What was our ROI?
It saves us a lot of time. People can devote their time to other more important tasks.
What's my experience with pricing, setup cost, and licensing?
The seller of Tufin, when I wanted the solution, was very flexible because the cost on the lease was very high in Latin America. So, he was able to reduce the cost.
Which other solutions did I evaluate?
We considered Algosec and Firemon, but Tufin was the best.
What other advice do I have?
A powerful tool for a security team to optimize time.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Network Security Engineer at a retailer with 10,001+ employees
Comparing the rules and policy browser is valuable, but having to enter the password each time for each firewall is annoying
Pros and Cons
- "Comparing the rules and policy browser is valuable to me. It gives me the ability to pull running configs and be able to analyze them without having to go directly into the firewall."
- "If you want to be able to manage your firewalls efficiently and securely, then use Tufin."
- "They are sort of at the pilot stage on some of their products. I saw the Orca and Iris products yesterday. My initial impression of these products were that they were good products, but I felt like some of their features overlapped with SecureTrack and SecureChange, which they are already doing. So, I just wondered what direction they're going in? I understand that they are cloud products, but are these security products going to overlap each other's features at some point? This is my initial concern."
- "They are sort of at the pilot stage on some of their products. I saw the Orca and Iris products yesterday."
What is our primary use case?
The primary use case is firewall analysis.
We use SecureTrack, which is great.
How has it helped my organization?
The solution has helped us to meet our compliance mandates. We have to be PCI and SOX compliant. Some of these rules and systems might meet those requirements. Knowing which system can talk with which system is definitely helpful in that sense.
This solution has helped us reduce the time it takes to make changes.
What is most valuable?
Comparing the rules and policy browser is valuable to me. It gives me the ability to pull running configs and be able to analyze them without having to go directly into the firewall.
The visibility is great.
What needs improvement?
When you make changes, you have to enter the password each time for each firewall. This is sort of annoying.
They are sort of at the pilot stage on some of their products. I saw the Orca and Iris products yesterday. My initial impression of these products were that they were good products, but I felt like some of their features overlapped with SecureTrack and SecureChange, which they are already doing. So, I just wondered what direction they're going in? I understand that they are cloud products, but are these security products going to overlap each other's features at some point? This is my initial concern.
For how long have I used the solution?
I just opened the tool about four weeks ago.
What do I think about the stability of the solution?
It is very stable.
What do I think about the scalability of the solution?
It seems pretty scalable. From what I have seen in the training, you can use it on multiple firewalls. It seems like a solution which was built for very large enterprise level networks.
How are customer service and technical support?
I haven't dealt with the technical support yet.
What other advice do I have?
If you want to be able to manage your firewalls efficiently and securely, then use Tufin.
It is a pretty solid solution. As with any security solution, I think is it is growing. It seems like it is at a good point. It could still use some work, but it's growing, and that's good.
We saw in the training yesterday the changes for part of SecureTrack 2.0, which isn't out yet. Those changes, that they will be implementing, look very good from what I can see.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Associate Director Program Management at a pharma/biotech company with 10,001+ employees
Helps us meet our compliance mandates by providing visibility into firewall rules
Pros and Cons
- "We were hit by the NotPetya attack. Therefore, our whole company and all its sites were down for several months. So, you don't have an attack like that and not need something like Tufin. Other companies can prevent these attacks, or at least slow them down, by having this type of a tool. We will never go back."
- "Tufin seems like a high quality product from a company that cares."
- "We actually had a key issue, which was a bug, that the development team didn't want to fix. We escalated it, then it got fixed. So, the management level seems very responsive at least, but at a support level, they are just regular support people and not outstanding."
- "We actually had a key issue, which was a bug, that the development team didn't want to fix."
What is our primary use case?
The primary use case is locking down the firewalls to Zero Trust and automating the risk assessments.
How has it helped my organization?
We use Tufin to clean up our firewall policies. It very easily shows us what is not used, so we can take it out. It shows us head counts as well, so if something is used once or twice a year, that might not be something we want to keep. Thus, we can have the conversation. We also like how it has a business owner of the firewall policy, so we'll be filling that in. So, those people will be involved ongoing with the approvals.
This solution has helped us meet our compliance mandates by providing visibility into firewall rules.
Today, we can check to see how our lockdowns have gone and what unusuals are still there. We have a long way to go, but we've done a lot already.
We were hit by the NotPetya attack. Therefore, our whole company and all its sites were down for several months. So, you don't have an attack like that and not need something like Tufin. Other companies can prevent these attacks, or at least slow them down, by having this type of a tool. We will never go back.
In the future, we will be using this solution to automatically check if a change request will violate any security policy rules.
What is most valuable?
- Being able to see all the firewall rules in one place.
- Being able to query them.
- SecureChange will automate and put the rules into Remedy.
The visibility is incredible. It has never been there before.
What needs improvement?
The UI was a little clunky at the first. It was confusing. They are working on that. The new one is better.
What do I think about the stability of the solution?
We haven't really overburdened it yet. What we have has been very stable. There have been no issues that I have seen.
What do I think about the scalability of the solution?
It seems very scalable.
We have 40 consultants and too many people.
How are customer service and technical support?
The regular technical people seem okay when you put in a help call, and they do get back to you. We actually had a key issue, which was a bug, that the development team didn't want to fix. We escalated it, then it got fixed. So, the management level seems very responsive at least, but at a support level, they are just regular support people and not outstanding.
Which solution did I use previously and why did I switch?
I asked our firewall team if they had the tools that they needed to do their job, and they said, "No."
We did not have a previous solution.
How was the initial setup?
The initial setup was pretty straightforward. The problem was getting people to pay attention to it.
It is a lot of work to implement.
What about the implementation team?
We used Tufin for the deployment.
What was our ROI?
We have not seen ROI yet. What we are going to see is fewer cyberattacks. When you have a multimillion dollar cyberattack, you don't care about three million dollars in a one time cost.
Engineers are spending less time on manual processes by weeks. Huge amounts of time have been saved.
What's my experience with pricing, setup cost, and licensing?
Our licensing costs are three million total and then we pay for maintenance, which is an additional cost for three years.
Which other solutions did I evaluate?
We did a comparison of three products and Tufin was recommended at the time. We got quotes from Tufin and another product, and Tufin came in under.
I just talked to two people who switched to Tufin from another product. It seems to be the leader of the pack.
What other advice do I have?
Tufin seems like a high quality product from a company that cares. It focuses on exactly what we need.
We would like to get to having Tufin make changes on firewall rules, but we are going to need help convincing our management of that we should be using Tufin to do that. It looks very promising, but we can't use it for that yet.
We haven't implemented the change workflow process yet.
While we didn't buy it for the solution’s cloud-native security features. I'm interested in that, but it is not in my mandate right now.
The product has been fabulous.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Security Operations at a insurance company with 10,001+ employees
We use this product to sharpen our change cycle
Pros and Cons
- "We use this product to sharpen our change cycle. A request used to take quite a while as we did manual assessments. A lot of that is now done through SecureTrack."
- "In the past, we would do certain things because of private knowledge of people's own understanding of the network. We don't have to rely on just that piece of it, because of the topology. We now know which firewalls come into play."
- "The solution has helped us reduce the time it takes us to make changes from weeks to days, and engineers are spending less time on manual processes by about 15 to 20 percent."
- "The product that we have deployed for our main process gets bogged down in terms of its response. Maybe, we need to deploy a slightly smaller box. Eventually, we need to discuss this with Tufin is to see if we can move over to some sort of VM environment where we can add more processing power to it."
- "Our initial setup was complex from two dimensions, because we were deploying it globally and had to have a centralized view, but a distributed approach. We had it in Asia and North America, causing a slightly complicated approach."
- "We do have an ongoing issue with capacity. If one of our resources is working on it, nobody else can do anything."
What is our primary use case?
The primary use case of Tufin is firewall management, firewall reviews, and eventually, to do rule deployment.
It was more to start standardizing our prior work changes. The initial first step is to understand and make sure that whatever change goes in is complying to our policies and standardized. The eventual goal is to get everything automated.
We are using SecureTrack at the moment, but we do have licenses for SecureChange as well.
How has it helped my organization?
We use this product to sharpen our change cycle. A request used to take quite a while as we did manual assessments. A lot of that is now done through SecureTrack.
At this stage, we are doing only manual checks. We are only using SecureTrack to verify the flows through Tufin. At a later stage, when we will also automate certain types of rules to be done through SecureChange, this will tremendously help us. We are not there yet, but this will help us in terms of time and resource costs.
In the past, we would do certain things because of private knowledge of people's own understanding of the network. We don't have to rely on just that piece of it, because of the topology. We now know which firewalls come into play.
We use Tufin to help us clean up the firewall policies. It provides very easy reporting. We get all the aged or unused rules listed very quickly, as soon we run the report. It's a quite easy way of doing it. However, we have not automated our process. We are hoping that at some point that we will be in a position to automate that process.
We use the solution to automatically check if a change request will violate any security policy rules. If a request comes in, and it is from an Internet zone going straight out to an inside secure zone, then we definitely flag it. There are other policies that we find in our USP, which we flag. These are the type of things that we check.
We definitely use the compliance reports, which has simplified things. However, we haven't fully integrated it into the GRC process with Tufin yet. The desire is to make sure our GRC resources are fully aware and engaged in our Tufin deployment.
We are leveraging some components to provide reports for our GRC process, but there is no plan to integrate those processes. Those are run by different teams. We were planning to integrate our ticketing system (ServiceNow) with Tufin, which is ongoing. We are working on that now.
What is most valuable?
The central repository of information provides a consistent way of doing things, eventually shortening the time period to make changes. This is the most valuable thing at this point in time.
I'm very happy with the visibility component. It gives us a reasonable insight into the most of the application flows. Obviously, most east-west application flows are missing from what we have. That is a component which we will need to eventually fill in the gaps.
Between the cloud and physical data centers, we definitely share Tufin policies. That definitely gives us visibility into both.
What needs improvement?
I would like to drive value from is to getting to a point where we are almost like a DevOps operation for security changes.
We have put in a lot of requests. Some of them are high level related to cloud. Others relate to some of the reporting structures that we have. E.g., some of the automated reporting capabilities for specifics on certain regulations. Certain countries have certain regulations, and with GRC, if we can associate that on certain regulations, then we can spit out reports from that.
We would like to see integration of the different versions of this product, e.g., SecureChange and SecureTrack. They eventually need to start amalgamating all these into an end-to-end product for visibility.
What do I think about the stability of the solution?
We do have an ongoing issue with capacity. If one of our resources is working on it, nobody else can do anything. If a particular report is being run on the server, nothing else seems to work. We haven't done anything about it as of yet. Maybe some of my team members have opened tickets to Tufin for it.
What do I think about the scalability of the solution?
I am not sure about the scalability. The product that we have deployed for our main process gets bogged down in terms of its response. Maybe, we need to deploy a slightly smaller box. Eventually, we need to discuss this with Tufin is to see if we can move over to some sort of VM environment where we can add more processing power to it.
We have a global implementation.
How are customer service and technical support?
Whenever we have had a problem, some of my engineers contact Tufin and they have been very easy to get a hold of. From my team, they have not had any problems with the technical support.
Which solution did I use previously and why did I switch?
We were using Tufin before, as well, but it was not the same. It was separated into localized instances and regions.
We sort of saw that the volume of changes were coming in high. The patience from the business side was getting low to invest the time that it used to take to make firewall changes. Therefore, it was inevitable that we need to purchase a solution.
How was the initial setup?
Our initial setup was complex from two dimensions, because we were deploying it globally and had to have a centralized view, but a distributed approach. We had it in Asia and North America (US and Canada), causing a slightly complicated approach. Prior to Tufin, we had three instances which were separately managed, so we did not have end-to-end visibility. Therefore, we rearchitected the Tufin environment and created one global Tufin instance. The retail instances became local collectors, which reported back to the single environment.
From the start of the project to the end of the project, the deployment took us a while, at least five to six months. Most of the time involved was not because of Tufin. It was primarily for us to handle all of our separate service providers and outsourcers globally, so they could all provide us with read-only access to the firewalls that they manage.
What about the implementation team?
We deployed the solution in-house. It was pretty straightforward to deploy.
What was our ROI?
The solution has helped us reduce the time it takes us to make changes from weeks to days.
Engineers are spending less time on manual processes by about 15 to 20 percent. I would like to get a bigger number.
We didn't buy this based on ROI, so we didn't measure ROI. Overall, from a time savings perspective though, it is definitely there.
What's my experience with pricing, setup cost, and licensing?
The licensing costs are around $250,000 to $300,000.
There are ways to deploy the license to different types of firewall. However, if we decide to change the physical brand of the firewall, we need to go back to Tufin and modify the licensing. This is a hassle.
Which other solutions did I evaluate?
We did not consider anyone else, because we already had an unused, unimplemented Tufin license. We eventually thought to start consolidating everything into one place.
We decided on Tufin because:
- It was an existing tool.
- It served our purposes. It provided us the essential components for managing a varied environment of different types of firewalls.
- We felt that there was enough potential in the organization to grow with us and provide capabilities, like cloud, VM environments, etc., under the same umbrella.
What other advice do I have?
It gives us visibility and the ability to make changes automatically with less mistakes. Overall, it's a decent product.
Tufin is definitely a good contender to come as a winner. It has the potential to look not only at firewalls, but also network devices and other cloud-native solutions. It is a pretty broad base product, which will eventually be a good future tool to have in a toolkit.
We haven't used the workflow from Tufin. We use our own ticketing system for that. We are busy integrating our ticketing system with Tufin right now using an API. We are just in the process of doing that.
Tufin helps us understand and ensure that security is being applied. Tufin is not a security tool. It just gives us all the information about security, firewalls, etc., and that they are doing their work. From that perspective, it would be a long stretch to say that Tufin provides us security. However, Tufin provides us the information that we have security across hybrid environments.
All of our cloud-native security features are directly taken from cloud management tools. We don't have anything deployed yet from Tufin for cloud-native security features, but there is a desire for that.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Engineer at a healthcare company with 10,001+ employees
Provides a holistic view of the infrastructure, as well as automation workflows
Pros and Cons
- "One of the biggest quick wins that we had with Tufin was cleaning up our firewall policies and rules, and we cleaned out a lot of rules which helped our devices, longevity-wise, as well as speed-wise."
- "We would like Tufin to have interoperability with Juniper products, along with official support."
What is our primary use case?
We use it with SecureTrack, mainly for auditing purposes. We also use SecureChange for workflows on temporary firewalls.
How has it helped my organization?
We use Tufin to clean up our firewall policies. From an auditing perspective, it is centrally managed in one place for all of our firewall vendors.
One of the biggest quick wins that we had with Tufin was cleaning up our firewall policies and rules. We cleaned out a lot of rules which helped our devices, longevity-wise, as well as speed-wise.
What is most valuable?
- Easability
- Audit features
- SecureTrack
- Change of work allowance
- It is very open to changing it and making it do what we need it do.
- We get a holistic view of the infrastructure, as well as automation workflows.
The visibility is great, so far. We are still building it out because we have a lot of firewalls from different vendors. Overall, it's a good product in the way it works.
The change workflow process is flexible and customizable. We use this process a lot. We have developers do custom integrations with different vendors, especially ones that are technically supported, as well as doing some custom integrations with our Juniper products, which are not officially supported.
The solution’s cloud-native security feature is definitely welcome. We are starting to embrace the cloud. We are a little more legacy and timid in our approach, considering the amount of data that we have and the way that we want it to be accessed. However, the cloud-native applications are going to be big, so I definitely think that's a welcome feature that they're working on.
What needs improvement?
We would like Tufin to have interoperability with Juniper products, along with official support.
They could maybe update the interface. However, I know there is an interface update coming, I just haven't seen it yet.
There is room for improvement, as far as making the product easy to use and having training available.
In my training with the workflow, it always kicks me back every time that I do a step backwards. I think that automatically it should take you to the next step in the workflow, that would be appreciated.
What do I think about the stability of the solution?
So far, the stability has been great. One of my colleagues just did an upgrade from the previous version to 19.1, which had a bit of database issues. Those have now been resolved.
What do I think about the scalability of the solution?
The scalability seems good. We have a distributed system right now, and it seems like it can scale up or scale out, as needed.
How are customer service and technical support?
So far, the technical support has been good. I haven't had to deal with support a lot yet. We have weekly check-ins with our account manager where we go through what we can do with it. Overall, I think it's adequate.
Which solution did I use previously and why did I switch?
We didn't have a previous solution.
It is nice to see the capabilities that Tufin has, and we look forward to building it out.
How was the initial setup?
I wasn't there for the initial setup, but from what I've seen, it was pretty straightforward for the engineers who set it up.
What was our ROI?
The solution has helped us reduce the time it takes us to make changes. From the auditing perspective, it definitely saves a lot of time. Once we get our USP built out with the automatic calculations, as well as having validation and seeing where the roles need to go in place, this solution will be very helpful.
It is helping engineers spend less time on manual processes.
Which other solutions did I evaluate?
We did look at a few other vendors.
The power that Tufin has behind it is the reason they chose it. They saw that it had a lot of capability compared to its competition.
What other advice do I have?
Check out this product and see what it can do for you. Talk with the marketing team and account reps and see what direct benefit the platform gives you. Then, see what strengths it has compared to the competition, as well as its value proposition.
We are not to the point of using the solution to automatically check if a change request will violate any security policy rules, but it is coming.
We are building the security policy part of it out across out hybrid network, especially with the USP.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Analyst at a retailer with 10,001+ employees
Helpful with making sure all parts of our organization are following change management
Pros and Cons
- "It provides a comprehensive overview of what our network looks like in terms of what is allowed and what is not, then how the traffic' is flowing with the Network Topology Map."
- "The solution helps us ensure that security policy is followed across our entire hybrid network."
- "I wish there was a read-only admin option. I don't like that you have to be a full admin just to see the Network Topology Map. That option is great out there if you are a user, multi-domain user, etc. However, that piece is very helpful for us, but I also don't want to be handing out admin access to every single person so they can see that network tab."
- "Sometimes, it'll freak out and cause everything else to stay and be unable to get configed, then our Palo Alto products will sort of cease, usually a good majority of them, which is not ideal."
What is our primary use case?
The primary use case is monitoring routers, switches, firewalls, but mostly routers and firewalls.
We are just using SecureTrack, either version 18-2 or 18.3.
How has it helped my organization?
We use it to aid with firewall reviews. We don't have SecureChange active, but we can take the info and use it to help. We have found a lot to work with.
Tufin has been helpful with making sure all parts of our organization are following change management:
- If you are changing rules, then you have tickets, and there is the approval process associated with it.
- Seeing people are sticking with those temp rules, if they end up staying there for awhile.
- Sometimes, there are just bad rules where something that should've been "deny" and should not be allowed.
Those are more direct examples without getting too far into the weeds.
It is greatly aided in helping us meet our compliance mandates. There used to be manual reviews for certain compliance requirements. Now, this solution helps automate a lot of that, and even the parts which are still manual. It's a lot more comprehensive than trying to read raw text files of the configs and making sense of those.
The solution helps us ensure that security policy is followed across our entire hybrid network. It is like a centralized single pane of glass where comprehensively shows things, especially coupled with the Network Topology piece that they have. You can say, "Here's where the DMZ is, and here's that. These are the amount of firewalls crosses this through." Whereas before, it was this big spreadsheet of all the firewalls and zones. Except for like two or three legacy knowledge people, no one really understood how it flowed before Tufin.
It has helped us troubleshoot, e.g., why isn't this still working? "Oh, they put it on the wrong firewall or they typoed it." The solution has helped with that.
The firewall reviews for compliance used to be a more labor intensive process. It used to take a few months, and now, it's down to just a couple of weeks.
What is most valuable?
It provides a comprehensive overview of what our network looks like in terms of what is allowed and what is not, then how the traffic' is flowing with the Network Topology Map.
With the Unified Security Policy, the more you improve it, the more you will get out of it.
For the things that Tufin is able to work with, it is really great. It sort of provides a comprehensive view. It is easier to explain to people who don't really work with firewalls everyday:
- Why this is an issue.
- Why certain things are an issue.
- Why some things are the way they are.
What needs improvement?
I wish they had a credentials vault or something. Right now, you have to manually add a username and password per device, and if they are using something like in a centralized, like an AD account, that password rotates eventually. Now, I have to go back and change information for all these hundreds of devices. Whereas, if they just had some credentials vault for credential one, two, and three, then you could just reference them per device and change it in one place. It would make our lives a lot easier.
I wish there was a read-only admin option. I don't like that you have to be a full admin just to see the Network Topology Map. That option is great out there if you are a user, multi-domain user, etc. However, that piece is very helpful for us, but I also don't want to be handing out admin access to every single person so they can see that network tab.
Tufin covers a lot of vendors, but there are still some that they don't, like Radware. Some of these vendors that they don't cover are at critical points in our company, as far as explaining the full picture of our routing. Since it can't show the full picture, it can't support that.
What do I think about the stability of the solution?
The stability is pretty good. We have run into repeat issues with Palo Alto Panorama, where it doesn't seem to play nice if we change the vice group names in Palo Alto or if one of the Palo Alto servers is down, but it is in Panorama, because we're pulling everything through Panorama. Sometimes, it'll freak out and cause everything else to stay and be unable to get configed. Then, our Palo Alto products will sort of cease, usually a good majority of them, which is not ideal.
What do I think about the scalability of the solution?
So far, scalability has been doing well.
How are customer service and technical support?
The technical support is very good. They respond pretty fast. They are always available whenever I need it. It is usually my fault when there are delays because I just don't respond to an email. I forget, then a few days go by and email again like, "Oh, shoot." The technical support has always been on top of things.
How was the initial setup?
Someone before me had stood up the actual server on the network. They had one device, and it was monitoring. Then, I took it over. I've expanded it out to over 400 devices.
They made getting new monitoring devices in pretty easy. From the monitoring devices tab, it was pretty straightforward. You pick the vendor, then under there, this is a drop-down. I struggled a bit under the Cisco tab where they have a router, then a Nexus router. They have a lot of different vendors, and figuring out which category it falls under was confusing. The help docs don't exactly specify between the two or what commands it will be running. This is usually more for our older devices.
What about the implementation team?
We had Professional Services hours. However, as far as getting the actual devices and scaling it out, that was all just me.
What other advice do I have?
Understand your DNS or network segment. What all these different subments and how they will fit into what categories, because you are going to directly take that info when you build out your USP. If it's too messy, your USP is not really going to do anything. You need to have a good dictionary for the USP to follow.
We aren't really using the cloud-native security features in our current environment.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Firewall Architect at a financial services firm with 10,001+ employees
Helps us tighten up our firewall policy, but reporting should include automation metrics
Pros and Cons
- "The automation piece is the most valuable feature: having SecureChange make the change on the firewalls, instead of my having to go manually make the changes on the vendor product."
- "When it comes to the turnaround of firewall rule requests, it used to take about a week to implement and have the customer test for firewall access, now it can take just one day."
- "We would like to see automation metrics, from a reporting standpoint. We would also like to see automation of site-to-site VPN tunnels. We would like to see automation of Check Point application-based firewall rules."
What is our primary use case?
Our primary use case is firewall automation. We use SecureTrack and SecureChange. We have distribution serves, Remote Collectors, but what we primarily use is SecureChange integrated with ServiceNow for users to submit firewall requests. They then go to SecureChange which designs the rules and implements them.
How has it helped my organization?
When it comes to the turnaround of firewall rule requests, it used to take about a week to implement and have the customer test for firewall access. Now, it can take just one day. The implementation itself takes a minute or two. For the customer, it may take the rest of the day, by the time that the policy is installed and the customer tests, either that evening or the next day.
While I'm not involved in the leadership, I believe the solution has helped us to meet our compliance mandates: from a firewall perspective, as well as an audit perspective, as well as review of the rules and source and destination port requests.
As for ensuring that security policy is followed across the entire hybrid network, we're getting there. That's part of why we implemented Tufin. We are implementing that across our multiple offices. Once we get to that state, it will ensure that security policy is followed.
Finally, using the solution, our engineers are spending less time on manual processors.
What is most valuable?
In general, the automation piece is the most valuable feature: having SecureChange make the change on the firewalls, instead of my having to go manually make the changes on the vendor product.
In terms of cleanup of our firewall policies, we don't officially use Tufin, but I, as an architect, do use the Automatic Policy Generator to review existing rules: high hit-count rules and open rules which aren't very secure. We use that to then build firewall rules which tighten up our firewall policy.
The change workflow process is flexible and customizable. We have had to edit and alter some of our workflow and it's pretty easy, pretty simple, pretty straightforward. We use Tufin support, their helpdesk, for that because we're a very new customer.
What needs improvement?
In terms of the visibility the solution provides, we have hits and misses with it. Overall, we think it works. We would like to get more automated, but that could be an issue internally with services and ports that we allow between different zones and our USP matrix. We're working with Tufin representatives to help solidify that and clean that up a little bit. That's one of the headaches and hiccups that we have right now: the full automation piece. We have automation to an extent, but we still have requesters who submit requests that still require approval, whether it be firewall leadership approval or cyber leadership approval. We want to determine what ports are allowed between the zones, as I mentioned, so that we can have full automation and there's no human interaction at all.
We would like to see automation metrics, from a reporting standpoint. We would also like to see automation of site-to-site VPN tunnels. We would like to see automation of Check Point application-based firewall rules. That's available on the Palo Alto side, but we are primarily a Check Point site on-prem. We have Palo Alto on the cloud but most of our on-prem stuff is from Check Point, so we're waiting for that. Those are some of the key things we're waiting for.
For how long have I used the solution?
We've been using Tufin for about four months.
What do I think about the stability of the solution?
My impression of the stability is positive. We haven't had any issues. We even went through an upgrade about a month ago and it was a smooth process.
What do I think about the scalability of the solution?
As for scalability, we're finding that out right now. We're building out two new Remote Collectors for our global deployment of an additional 150 to 180 firewalls, plus additional Layer 3 appliances. We're working through that right now. Hopefully, it will be a smooth transition but I can't say for sure because we haven't actually implemented it yet.
How are customer service and technical support?
I would rate tech support as "fair." Response time is a little slow, but when they do respond, and when time is available for them, we work through things pretty quickly to resolution.
How was the initial setup?
I wasn't involved in the initial setup, but from what I've heard from others from whom I took it over, it was very straightforward.
Which other solutions did I evaluate?
I know they reviewed other solutions but I don't know which, for sure, since I inherited the project. I would assume AlgoSec and FireMon were reviewed as well.
What other advice do I have?
Be as detailed as you can within your introductory meetings, and your planning and implementation phases, because if you don't mention something and it comes back later, you're going to have to work through it. That could take time, it could take extra money. You want to make sure, upfront, that you know everything you want to do so that it's all included in the cost for the Professional Services implementation.
We do use it on the cloud; we're having some trouble right now defining the network policy on our cloud. We're working through that; it's part of being a new client.
I would rate Tufin a seven out of ten. We're a very large, complex organization, so we're still working through some stuff that we focus on, things that, perhaps, other customers don't, or that Tufin doesn't have integrated in the TOS software.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Manager of Security Engineering at Global Payments Inc.
Increases your productivity and simplifies your workflow
Pros and Cons
- "It is a great solution. If you have all the devices and firewalls in place, the amount of details that you get along with the network topology is very good."
- "It is a great tool; it will help you increase your productivity and simplifies your workflow."
- "I haven't seen the cloud integration yet, and I would like to see if we could audit the cloud firewalls, like the cloud-native, Azure, and Amazon. That would be nice. You want one tool to do everything. I don't want to use another tool, or manually go and audit the cloud firewalls."
- "I have seen some issues with the stability. One of the things that we noticed was when R18 was released about one or two years back, it couldn't discover the newer versions of firewalls, then we had to upgrade it."
What is our primary use case?
Right now, we are just using it for SecureTrack. Next year, we have plans to buy the license for SecureChange as well.
I think we're using version 18, and we are in the process of upgrading it to 19-2
How has it helped my organization?
We got Tufin from a company that we acquired, so its helping us do mitigations there. Now, we are extending the scope and implementing it in our HQ, as well. It has helped for PCI and compliance.
The solution helps us ensure that security policy is followed across our entire network. It is important to configure and define all the networks right.
One of the primary reasons why we want to use Tufin is currently we are having issues with companies from overseas who manage our firewalls. It is very inefficient where they say that they have implemented the rules, then later on we find out the implementation has not been done properly and they are missing firewalls. Hopefully, once we fully implement this tool, it should be able to tell us if firewall rules are missing. It should be able to tell them before they communicate with us. After the implementation, we can verify and make sure that everything is working and do all the validations.
What is most valuable?
It is a great solution. If you have all the devices and firewalls in place, the amount of details that you get along with the network topology is very good.
If we had the budget and money, the SecureChange is really great. What you can do and where you can push everything from one console. You can create a change and do the whole automation: create the change, implement the change, and close the change. Right now, I have to go to two, three, or four different consoles. Whereas if I had SecureChange, I could do everything in one place. From an auditing perspective, it becomes easy. Right now, I have to give a change ticket number, then show the auditor and tell them to search for that change ticket number in a different place. If everything is in one place, that makes your life easier.
The change workflow process is flexible and customizable.
What needs improvement?
I would like more API integration, API integration with the cloud, and API integration with other chain management solutions. I would also like more scripts, which would help us not have to write scripts. If you give me all this, I can use the scripts to automate stuff, making my life easier.
I haven't seen the cloud integration yet, and I would like to see if we could audit the cloud firewalls, like the cloud-native, Azure, and Amazon. That would be nice. You want one tool to do everything. I don't want to use another tool, or manually go and audit the cloud firewalls.
What do I think about the stability of the solution?
I have seen some issues with the stability. One of the things that we noticed was when R18 was released about one or two years back, it couldn't discover the newer versions of firewalls, then we had to upgrade it. After the upgrade we ran into some other issues. However, it looks like with the patches it is getting there.
What do I think about the scalability of the solution?
With the scalability, you have to use different components: the reporting server and distribution server. When we implemented it earlier, we didn't design it properly, which I feel is our issue. Once we design it properly, the way that we are implementing it now, I feel the scalability should be there.
Which solution did I use previously and why did I switch?
I have used auditing tools in the past, so I was already aware of Tufin. When I saw the processes in my company where I worked were manual, I recommended a solution, saying, "We need to expand the solution from our other company to here, as well. It will simplify our processes."
How was the initial setup?
The initial implementation was done at an acquired company, so it was already installed. However, we are doing upgrades now.
What about the implementation team?
I think we will be using Tufin for the upgrades.
What was our ROI?
We have seen ROI:
- The productivity has increased. The team is more productive.
- It will decrease the time of firewall implementation, which will increase the productivity in the sense that now other teams don't have to wait for their projects.
- This helps us simplify our processes.
Our engineers are spending less time doing manual processing. Their productivity has at least increased by 50 percent.
What's my experience with pricing, setup cost, and licensing?
We haven't purchased the license yet for SecureChange. We do have plans to buy it next year.
The additional piece, which we are buying and doesn't include our other solution, is close to 300,000.
Which other solutions did I evaluate?
We did not have have time to evaluate other solutions. Also, we already had Tufin in place in our other company.
This seems to be a better solution than AlgoSec, which I have used in the past. I have also seen FireMon, and Tufin gave us what we needed. I didn't see a reason to explore other solutions.
What other advice do I have?
It is a great tool. It will help you increase your productivity and simplifies your workflow.
We should use it to clean up our firewall policies since the tool is there.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Tufin Orchestration Suite Report and get advice and tips from experienced pros
sharing their opinions.
Updated: July 2026
Product Categories
Firewall Security ManagementPopular Comparisons
Fortinet FortiGate Cloud
Skybox Security Suite
FireMon Security Manager
Palo Alto Networks Panorama
Azure Firewall Manager
AWS Firewall Manager
ManageEngine Firewall Analyzer
Cisco Security Cloud Control
FortiGate Cloud-Native Firewall (FortiGate CNF)
Cisco Secure Firewall Management Center
Buyer's Guide
Download our free Tufin Orchestration Suite Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between AlgoSec and Tufin?
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Comparing network security vendors and devices
- When should companies use SSL Inspection?
- When evaluating Firewall Security Management, what aspect do you think is the most important to look for?
- What are the most important features you would be looking for in a firewall?
- How do I estimate the required firewall throughput for my organization?
- What are the pros and cons of Tufin, AlgoSec and RedSeal?
- Tasks to Perform on Preventive Maintenance.
- Why is network segmentation important?











