security consultant at a tech vendor with 10,001+ employees
Real User
Top 5
Aug 26, 2026
There should be more tutorials and documentation about the usage of Check Point WAF (formerly CloudGuard WAF) online so more users and tenants can use these security services daily, as it is not as well-documented as other tools, such as the F5 WAF.
System And Network Administrator at a tech services company with 51-200 employees
Real User
Top 10
Jul 29, 2026
Currently, I have no suggestions for Cisco Secure Firewall. I am not working on the next-generation firewall of Cisco. As I already mentioned, I have no suggestions regarding the features and improvements. I am not working on Cisco firewall currently.
Senior Technical Engineer at a outsourcing company with 1,001-5,000 employees
Real User
Top 20
Jul 22, 2026
I face issues with the UI part of Check Point WAF (formerly CloudGuard WAF), as it malfunctions sometimes. Sometimes I do not see the icons in Check Point WAF (formerly CloudGuard WAF), and whenever I refresh the page, the icons remain invisible. Additional features I have considered with Check Point WAF (formerly CloudGuard WAF) include the ability to add an exception rule. Since we have multiple projects, I want to add an exception rule to all projects as a shared exception, but when adding it, I am unable to add it individually.
The false positive rate is a concern, but I could recommend improvements where false positives have to be minimized better. This all depends on how the rules are customized and configured, and it can also improve with planning during the initial configuration, including threat intelligence and APIs, so it could enhance how it defends against attacks and prompts injections. It can find the threat actors behind it, and I find that strategically and technically it is effective, although the AI-related features could improve, especially as global AI capabilities evolve, which are advancing more than what Check Point WAF (formerly CloudGuard WAF) provides compared to competitors. There are no glitches; I believe improvement could be made primarily in API Gateway and API security, especially by enabling enhanced AI-related features for better fine-tuning.
For Check Point WAF (formerly CloudGuard WAF), the negative aspects include the very high price, complex licensing, and the need for specialized trained people to configure it, which is comparatively more complicated than other firewalls like Palo Alto and FortiGate. The two areas for improvement are the price and the complexity of configuration.
Check Point WAF (formerly CloudGuard WAF) needs to offer more competitive pricing. There are many other cloud WAF products available, and when comparing costs, other vendors have a significant cost advantage. Check Point WAF (formerly CloudGuard WAF) pricing is not as competitive as other original equipment manufacturers like Cloudflare or Array WAF. I feel the pricing is on the higher side compared to these alternatives. Application Delivery Controller (ADC) features are limited in Check Point WAF (formerly CloudGuard WAF). While we can integrate with ADC, not all inputs from the forest can be uploaded to Check Point WAF (formerly CloudGuard WAF), which is a practical issue we have encountered in customer use cases.
Learn what your peers think about Check Point WAF (formerly CloudGuard WAF). Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
As a reseller, the most difficult part is the lack of awareness. Check Point does not provide any kind of awareness programs to the customers, requiring partners to educate customers. There are indeed some features missing, particularly connected with integration or with artificial intelligence. Check Point WAF (formerly CloudGuard WAF) faces certain issues with dual ISP tagging on entry-level devices since SD-WAN features were added.
Security Consultant at a computer software company with 501-1,000 employees
Consultant
Top 10
May 27, 2026
A gap for improvement for Check Point WAF (formerly CloudGuard WAF) is the learning curve, as better training modules could help end customers, and pricing and reporting functionality could also be improved.
The interface and deployment require qualified skills and a qualified engineer who knows this product very well. In general, Check Point products load the system somewhat and require more performance and better performance equipment on the customer side. When compared to solutions specialized only on WAF, such as Imperva or Cloudflare, Check Point WAF (formerly CloudGuard WAF) is a lighter version and does not have as well-performed a load balancer or anti-DDoS option.
The negative aspect is that Check Point WAF (formerly CloudGuard WAF) uses Check Point Harmony in its management console, which sometimes creates latency when connecting to or opening the platform. This is one function they are lagging in. The reporting functions need improvement. For example, I want to calculate traffic metrics, but I cannot see them in the current Check Point WAF (formerly CloudGuard WAF). To know the overall traffic for today on the application, I have to check multiple dashboards instead of one single dashboard.
Check Point CloudGuard WAF can be improved in several ways. We have faced slowness issues in our network after onboarding it on any application. The cost can be higher than traditional WAF solutions, and its heavy reliance on AI also means we have less manual control. Maximum work is done via AI, so that can be reduced. The cost can be decreased, and regarding manual controls, I just wanted to say that relying directly on AI is not good for our environment because AI is copying our data. According to other traditional OEMs, we experience a few issues with pricing. The pricing is high compared to other vendors, and I have already mentioned the high reliance on AI, which can be a concern. Customer support can be improved because we have to reach out to the distributors for support. That could be directly controlled by the OEM.
While Check Point CloudGuard WAF is a strong solution, it could be improved in a few areas such as simplifying and customizing the user interface and reporting database. Improving API security depth is also necessary.
The negative side I see is that while most things about Check Point CloudGuard WAF are really good, there is some latency and performance issues, as it can be slow to log in, especially from different regions. The pricing is another concern, as it is on the higher side and more suitable for mid-level or large enterprises rather than small organizations. The quality of the technical support team could be better; I rate them as okay, not excellent. To improve support, response time needs attention, as it can be hard to connect with the team. First, one must speak to the level one team, then the case must be transferred to levels two or three, leading to delays due to multiple teams managing different issues. This process means the customer can face delays in getting the right assistance. Latency and performance issues, friendlier pricing, and support are major concerns for improvement.
There are some API gateway and API securities I mentioned. If these are incorporated with AI-related features, particularly those seven key vulnerabilities I mentioned—token theft and tool poisoning—that would be beneficial. AI-related features are not included yet in Check Point CloudGuard WAF. However, they are present in FortiGate. That is the advantage of FortiGate now. FortiGate is stopping all AI-related vulnerabilities now. FortiGate has this capability. It is unfortunate that even Palo Alto also lacks one or two of these features. Check Point Quantum is very good, without a doubt. However, their capabilities are not in comparison with Palo Alto. There are some features, but there are some gaps in comparison with Palo Alto.
IT Security & Networks Administrator at a financial services firm with 1,001-5,000 employees
Real User
Top 5
Feb 4, 2026
Check Point could improve or add more flexibility when it comes to migrating to different sites. Multi-tenancy is an area where Check Point has room for improvement.
I see areas for improvement primarily on the reporting functionality front, as there are very limited functions in the reporting section. For example, I want to run a consolidated dashboard for the last six months, but it is not available. Reporting functions alone have limitations, and sometimes this portal has latency issues when loading pages. Since I am using it as a SaaS platform, sometimes the loading pages take more time. Regarding the Breach Reduction feature, I had a discussion with the Check Point account manager and pre-sale representative, but they have not yet provided a proof of concept demo. We are still in discussion.
Sr. VP of Creative & Development at a non-tech company with 51-200 employees
Real User
Top 5
Nov 22, 2025
Check Point CloudGuard WAF's support is only available in English. I gave Check Point CloudGuard WAF a rating of 9 out of 10 because the language limitation of support keeps it from being a perfect score, as I prefer support in different languages.
IT Support at a security firm with 51-200 employees
Real User
Top 5
Nov 9, 2025
Check Point CloudGuard WAF is a strong solution, but there are a few areas where it could be improved, particularly the user interface for managing custom rules and exceptions, which could be more intuitive and streamlined to reduce the learning curve for new users, especially when deploying for the first time. I think the documentation could be better. People need more intuitive documentation and easier steps for the first deployment.
Areas where Check Point CloudGuard WAF can improve include simple policy tuning, as the protection seems strong, though initial rule tuning can be complex. More guided workflows or templates would help speed up deployment, along with deeper integration with the DevOps pipeline, and while it handles API well, more dedicated API security would add value. In addition, it could be improved with better integration with the DevOps pipeline, more granular reporting, as the dashboards provide good high-level visibility, but sometimes digging into specific attack patterns or trends requires manual effort, and simple tuning of the ML models would be beneficial.
Check Point CloudGuard WAF could be improved by simplifying the initial setup for a faster deployment, making the dashboard and reporting more customizable, and offering a more accessible pricing model.
Security Engineer at a tech vendor with 51-200 employees
Real User
Top 5
Aug 22, 2025
Check Point CloudGuard WAF can be improved; initially, the setup is very complicated, and there's not a lot of documentation available, plus it didn't have something for anti-bot, but other than that, it is fine. The documentation issue means that I can't find it online very easily, and while I can always ask support, it's a bit limited. As for anti-bot, I refer to a feature that I can find a better option for on Cloudflare. I don't have anything more to add about the needed improvements or anything regarding the onboarding.
There are still areas for improvement with Check Point CloudGuard Code Security. All the features we have on the firewall on the on-premises side, we also have under CloudGuard such as IPS, Anti-Bot, and all these blades are set up in our CloudGuard.
Senior Cyber Security Engineer at a computer software company with 501-1,000 employees
Real User
Top 5
Apr 30, 2025
CloudGuard WAF could improve UI simplicity, reduce false positives, and enhance policy management. Future releases should include better bot mitigation, behavioral anomaly detection, compliance templates, advanced threat intel integration, and streamlined multi-cloud support to boost protection and usability.
The solution should improve vulnerability in-depth, false-positive reduction, integration with other tools, performance optimization, and the user interface.
Director of Security EngineerIng at a financial services firm with 5,001-10,000 employees
Real User
Mar 15, 2024
There are a lot of opportunities for how they can use their technology to do more. That would be more like sensitive data discovery and other things besides Git Repos, but then you are expanding the scope of what necessarily their product is. If we talk about what problem we are trying to solve, which is secrets disclosure, perhaps even validation of configuration management inside of Git environments, it is a very comprehensive solution. It is what it is, and it does a great job.
The enhancements are needed in the logging system and log management processes. Additionally, we encounter issues with geolocation functionality, which is crucial for enforcing access restrictions based on location. While we heavily rely on this feature, it occasionally fails to function correctly, posing challenges to our security measures.
Perimeter Security Administrator at a security firm with 51-200 employees
Real User
Top 20
Feb 24, 2023
This is a highly technical solution for users who do not have security experience. It requires specialized knowledge of configurations to use it correctly. This is a disadvantage since we must generate investment in training for the users. It takes a while to achieve adequate knowledge and we need to provide training and support resources for users before attempting the implementation of the solution for the first time. In addition, they need to additionally provide you with constantly evolving material due to its constant state of updating. It is important that we have these technical skills and requisite documentation in order to have greater confidence when using the tool.
We need to have many of the baselines or development guides providing less complex writing or development. We need to be able to add in the different languages in Latin America. It needs to be multilingual and include languages from our region. One of the agencies promotes, for example, Latino development. Other than that, the solution is quite fast. It is scalable and does not need a lot of equipment. Based on the SAS trends, it is seen as important to understand and adopt these types of solutions.
The tool is complying with what was requested and as described. The only thing that they can improve, is to make the reports more didactic in order to have more functionalities. They should build a broader and more orderly knowledge base since it is difficult to find guides on the tool. This is not good since it takes a long time to look for information. They should improve the quality of technical support they offer. We have had setbacks in case resolutions and this has harmed our business. They should also extend the hours of support a little more to accommodate time differences.
The application configuration process is simple, and it cannot be affected by external factors. Poor data interpretation during the scanning process can lead to poor decision-making and affect lead to insecurity. This platform has advanced data security and enhanced compliance. There is progressive growth and few cases of attacks across the enterprise. This software has safeguarded assets and built secure and reliable infrastructure. We have managed to uphold the company and set standard policies during the entire software development lifecycle. I am satisfied with the performance and results enhanced by this product since we deployed it.
I would like this solution to be extended to cellular devices or tablets. In a way, this will be able to support ourselves in order to be more efficient.
Being such a new tool in the Check Point security portfolio, it has become a challenge to obtain information on security implementation improvements, for which it would be very good to create more documentation for this tool. It is difficult to solve problems via support. With very new tools, the service hours are sometimes different from our country, so finding sessions is sometimes hard. The costs are not transparent. You need a provider so that they can give you more details. It is a non-centralized environment in Infinity Portal.
At the moment, Spectral Check Point is well-formed. It would be important to check later if they require improvements. At the Check Point support level, it has always been regular, however, they can improve the attention time and different languages to be able to serve customers better. Sometimes for simple cases, it takes a long time for support representatives to respond. Sometimes we have had to review or investigate by ourselves to solve problems more quickly. In general, these would be my comments for improvements.
Check Point WAF offers a robust security framework with AI-driven threat detection and seamless integration, protecting applications and APIs in multi-cloud environments.Effective in preemptively blocking threats through AI and machine learning, Check Point WAF reduces false positives and operational workload. Its integration capabilities and threat intelligence provide comprehensive protection against zero-day attacks, while centralized management facilitates cost-effective and insightful...
There should be more tutorials and documentation about the usage of Check Point WAF (formerly CloudGuard WAF) online so more users and tenants can use these security services daily, as it is not as well-documented as other tools, such as the F5 WAF.
Currently, I have no suggestions for Cisco Secure Firewall. I am not working on the next-generation firewall of Cisco. As I already mentioned, I have no suggestions regarding the features and improvements. I am not working on Cisco firewall currently.
I face issues with the UI part of Check Point WAF (formerly CloudGuard WAF), as it malfunctions sometimes. Sometimes I do not see the icons in Check Point WAF (formerly CloudGuard WAF), and whenever I refresh the page, the icons remain invisible. Additional features I have considered with Check Point WAF (formerly CloudGuard WAF) include the ability to add an exception rule. Since we have multiple projects, I want to add an exception rule to all projects as a shared exception, but when adding it, I am unable to add it individually.
The false positive rate is a concern, but I could recommend improvements where false positives have to be minimized better. This all depends on how the rules are customized and configured, and it can also improve with planning during the initial configuration, including threat intelligence and APIs, so it could enhance how it defends against attacks and prompts injections. It can find the threat actors behind it, and I find that strategically and technically it is effective, although the AI-related features could improve, especially as global AI capabilities evolve, which are advancing more than what Check Point WAF (formerly CloudGuard WAF) provides compared to competitors. There are no glitches; I believe improvement could be made primarily in API Gateway and API security, especially by enabling enhanced AI-related features for better fine-tuning.
For Check Point WAF (formerly CloudGuard WAF), the negative aspects include the very high price, complex licensing, and the need for specialized trained people to configure it, which is comparatively more complicated than other firewalls like Palo Alto and FortiGate. The two areas for improvement are the price and the complexity of configuration.
Check Point WAF (formerly CloudGuard WAF) needs to offer more competitive pricing. There are many other cloud WAF products available, and when comparing costs, other vendors have a significant cost advantage. Check Point WAF (formerly CloudGuard WAF) pricing is not as competitive as other original equipment manufacturers like Cloudflare or Array WAF. I feel the pricing is on the higher side compared to these alternatives. Application Delivery Controller (ADC) features are limited in Check Point WAF (formerly CloudGuard WAF). While we can integrate with ADC, not all inputs from the forest can be uploaded to Check Point WAF (formerly CloudGuard WAF), which is a practical issue we have encountered in customer use cases.
As a reseller, the most difficult part is the lack of awareness. Check Point does not provide any kind of awareness programs to the customers, requiring partners to educate customers. There are indeed some features missing, particularly connected with integration or with artificial intelligence. Check Point WAF (formerly CloudGuard WAF) faces certain issues with dual ISP tagging on entry-level devices since SD-WAN features were added.
A gap for improvement for Check Point WAF (formerly CloudGuard WAF) is the learning curve, as better training modules could help end customers, and pricing and reporting functionality could also be improved.
The interface and deployment require qualified skills and a qualified engineer who knows this product very well. In general, Check Point products load the system somewhat and require more performance and better performance equipment on the customer side. When compared to solutions specialized only on WAF, such as Imperva or Cloudflare, Check Point WAF (formerly CloudGuard WAF) is a lighter version and does not have as well-performed a load balancer or anti-DDoS option.
The negative aspect is that Check Point WAF (formerly CloudGuard WAF) uses Check Point Harmony in its management console, which sometimes creates latency when connecting to or opening the platform. This is one function they are lagging in. The reporting functions need improvement. For example, I want to calculate traffic metrics, but I cannot see them in the current Check Point WAF (formerly CloudGuard WAF). To know the overall traffic for today on the application, I have to check multiple dashboards instead of one single dashboard.
In my opinion, there is some room for improvement regarding pricing, which we require, and much of it relates to the license base and support.
Check Point CloudGuard WAF can be improved in several ways. We have faced slowness issues in our network after onboarding it on any application. The cost can be higher than traditional WAF solutions, and its heavy reliance on AI also means we have less manual control. Maximum work is done via AI, so that can be reduced. The cost can be decreased, and regarding manual controls, I just wanted to say that relying directly on AI is not good for our environment because AI is copying our data. According to other traditional OEMs, we experience a few issues with pricing. The pricing is high compared to other vendors, and I have already mentioned the high reliance on AI, which can be a concern. Customer support can be improved because we have to reach out to the distributors for support. That could be directly controlled by the OEM.
While Check Point CloudGuard WAF is a strong solution, it could be improved in a few areas such as simplifying and customizing the user interface and reporting database. Improving API security depth is also necessary.
The negative side I see is that while most things about Check Point CloudGuard WAF are really good, there is some latency and performance issues, as it can be slow to log in, especially from different regions. The pricing is another concern, as it is on the higher side and more suitable for mid-level or large enterprises rather than small organizations. The quality of the technical support team could be better; I rate them as okay, not excellent. To improve support, response time needs attention, as it can be hard to connect with the team. First, one must speak to the level one team, then the case must be transferred to levels two or three, leading to delays due to multiple teams managing different issues. This process means the customer can face delays in getting the right assistance. Latency and performance issues, friendlier pricing, and support are major concerns for improvement.
There are some API gateway and API securities I mentioned. If these are incorporated with AI-related features, particularly those seven key vulnerabilities I mentioned—token theft and tool poisoning—that would be beneficial. AI-related features are not included yet in Check Point CloudGuard WAF. However, they are present in FortiGate. That is the advantage of FortiGate now. FortiGate is stopping all AI-related vulnerabilities now. FortiGate has this capability. It is unfortunate that even Palo Alto also lacks one or two of these features. Check Point Quantum is very good, without a doubt. However, their capabilities are not in comparison with Palo Alto. There are some features, but there are some gaps in comparison with Palo Alto.
Check Point could improve or add more flexibility when it comes to migrating to different sites. Multi-tenancy is an area where Check Point has room for improvement.
I see areas for improvement primarily on the reporting functionality front, as there are very limited functions in the reporting section. For example, I want to run a consolidated dashboard for the last six months, but it is not available. Reporting functions alone have limitations, and sometimes this portal has latency issues when loading pages. Since I am using it as a SaaS platform, sometimes the loading pages take more time. Regarding the Breach Reduction feature, I had a discussion with the Check Point account manager and pre-sale representative, but they have not yet provided a proof of concept demo. We are still in discussion.
Check Point CloudGuard WAF's support is only available in English. I gave Check Point CloudGuard WAF a rating of 9 out of 10 because the language limitation of support keeps it from being a perfect score, as I prefer support in different languages.
Check Point CloudGuard WAF is a strong solution, but there are a few areas where it could be improved, particularly the user interface for managing custom rules and exceptions, which could be more intuitive and streamlined to reduce the learning curve for new users, especially when deploying for the first time. I think the documentation could be better. People need more intuitive documentation and easier steps for the first deployment.
Areas where Check Point CloudGuard WAF can improve include simple policy tuning, as the protection seems strong, though initial rule tuning can be complex. More guided workflows or templates would help speed up deployment, along with deeper integration with the DevOps pipeline, and while it handles API well, more dedicated API security would add value. In addition, it could be improved with better integration with the DevOps pipeline, more granular reporting, as the dashboards provide good high-level visibility, but sometimes digging into specific attack patterns or trends requires manual effort, and simple tuning of the ML models would be beneficial.
Check Point CloudGuard WAF could be improved by simplifying the initial setup for a faster deployment, making the dashboard and reporting more customizable, and offering a more accessible pricing model.
Check Point CloudGuard WAF can be improved; initially, the setup is very complicated, and there's not a lot of documentation available, plus it didn't have something for anti-bot, but other than that, it is fine. The documentation issue means that I can't find it online very easily, and while I can always ask support, it's a bit limited. As for anti-bot, I refer to a feature that I can find a better option for on Cloudflare. I don't have anything more to add about the needed improvements or anything regarding the onboarding.
There are still areas for improvement with Check Point CloudGuard Code Security. All the features we have on the firewall on the on-premises side, we also have under CloudGuard such as IPS, Anti-Bot, and all these blades are set up in our CloudGuard.
CloudGuard WAF could improve UI simplicity, reduce false positives, and enhance policy management. Future releases should include better bot mitigation, behavioral anomaly detection, compliance templates, advanced threat intel integration, and streamlined multi-cloud support to boost protection and usability.
The solution should improve vulnerability in-depth, false-positive reduction, integration with other tools, performance optimization, and the user interface.
There are a lot of opportunities for how they can use their technology to do more. That would be more like sensitive data discovery and other things besides Git Repos, but then you are expanding the scope of what necessarily their product is. If we talk about what problem we are trying to solve, which is secrets disclosure, perhaps even validation of configuration management inside of Git environments, it is a very comprehensive solution. It is what it is, and it does a great job.
The enhancements are needed in the logging system and log management processes. Additionally, we encounter issues with geolocation functionality, which is crucial for enforcing access restrictions based on location. While we heavily rely on this feature, it occasionally fails to function correctly, posing challenges to our security measures.
There needs to be better security around API integration.
The ease of use could be better. There is a bit of a learning curve. I'd rate the ease of use six out of ten. There is room to improve.
This is a highly technical solution for users who do not have security experience. It requires specialized knowledge of configurations to use it correctly. This is a disadvantage since we must generate investment in training for the users. It takes a while to achieve adequate knowledge and we need to provide training and support resources for users before attempting the implementation of the solution for the first time. In addition, they need to additionally provide you with constantly evolving material due to its constant state of updating. It is important that we have these technical skills and requisite documentation in order to have greater confidence when using the tool.
We need to have many of the baselines or development guides providing less complex writing or development. We need to be able to add in the different languages in Latin America. It needs to be multilingual and include languages from our region. One of the agencies promotes, for example, Latino development. Other than that, the solution is quite fast. It is scalable and does not need a lot of equipment. Based on the SAS trends, it is seen as important to understand and adopt these types of solutions.
The tool is complying with what was requested and as described. The only thing that they can improve, is to make the reports more didactic in order to have more functionalities. They should build a broader and more orderly knowledge base since it is difficult to find guides on the tool. This is not good since it takes a long time to look for information. They should improve the quality of technical support they offer. We have had setbacks in case resolutions and this has harmed our business. They should also extend the hours of support a little more to accommodate time differences.
The application configuration process is simple, and it cannot be affected by external factors. Poor data interpretation during the scanning process can lead to poor decision-making and affect lead to insecurity. This platform has advanced data security and enhanced compliance. There is progressive growth and few cases of attacks across the enterprise. This software has safeguarded assets and built secure and reliable infrastructure. We have managed to uphold the company and set standard policies during the entire software development lifecycle. I am satisfied with the performance and results enhanced by this product since we deployed it.
I would like this solution to be extended to cellular devices or tablets. In a way, this will be able to support ourselves in order to be more efficient.
Being such a new tool in the Check Point security portfolio, it has become a challenge to obtain information on security implementation improvements, for which it would be very good to create more documentation for this tool. It is difficult to solve problems via support. With very new tools, the service hours are sometimes different from our country, so finding sessions is sometimes hard. The costs are not transparent. You need a provider so that they can give you more details. It is a non-centralized environment in Infinity Portal.
At the moment, Spectral Check Point is well-formed. It would be important to check later if they require improvements. At the Check Point support level, it has always been regular, however, they can improve the attention time and different languages to be able to serve customers better. Sometimes for simple cases, it takes a long time for support representatives to respond. Sometimes we have had to review or investigate by ourselves to solve problems more quickly. In general, these would be my comments for improvements.