Likelihood to Recommend I strongly recommend using it in networks where many machines enter, it is essential to have a capture of all ids, mac etc to prevent and detect unauthorized machines.We are in the technological era and there is a lot of technological robotization looking for weak systems to enter.Invest in greater security and that does not happen to you.
Read full review Trellix (FireEye + McAfee)
It’s a dedicated Network Advanced Threat Detection and Prevention solution. Easy maintenance and low operating costs fit perfectly for SMEs. Variety of appliance selection makes NX the perfect choice for large enterprises. As it’s a dedicated solution with its own appliance, price is higher compared to NGTP add on solutions. FireEye is an ecosystem therefore when you’ve the EX or HX vice versa, you should be looking to NX. Otherwise, you’re missing the threat intel exchange on the network side reverse is the true. Sizing is important before the purchase, if you select a low end model for a busy network you lose your initial investment. For multiple NX deployments I highly recommend CMS. Without CMS you’ll lose the threat intel exchange and this will negatively reduce the risk scores.
Read full review Pros Network Access Control does a great job of identifying unmanaged devices on the network and "quarantining" them. The inventory feature of CounterAct is a handy place to see what version of applications are running on which machines on our network. Policies can be very intricate. Read full review Trellix (FireEye + McAfee)
Advanced detection of targeted attacks. Mandiant team effort is a big plus. Inline mitigation capabilities particularly well. Different deployment models for specific needs. License and information sharing selection 1 way or 2 way mode. Frequent updates. Low false positive rates. FireEye sandboxing is immune to sandboxing attacks. Central management (CMS) capabilities for managing several NX's. Extra IPS/IDS functionality in the product. Smartvision specific to lateral movement detection. Upgrades and updates with zero down time. Local FireEye support is superb. Multiple deployment scenarios (span, inline) in the same NX for different interface pairs. SSL inspection support. No need to maintain, build or updates the images. It's highly automatic. Read full review Cons They should have more training for the versions of applications they update. It would be great if the GUI would be more aesthetic in appearance. Nothing else as the application is amazing. Read full review Trellix (FireEye + McAfee)
Very first detected APT sample can pass the NX even it's inline blocking mode. Performance optimization for busy networks is cumbersome. CMS does not provide all the management capabilities, CLI or local config. Should be done for advanced customization. Constant limitations of tcpdump/ packet capture for 10G interfaces. IPS functionality is a bit cumbersome, not a full feature IPS, lack of signatures and customization of IPS signatures. It's not a full NDR solution or a UBA solution. Lack of device or user mapping. Forensics is based on the specific APT. May not provide the whole story and need some additional tools. You cannot make manual submission to NX (needs AX). You cannot access the kernel directly for deep analy[sis] or troubleshooting (assist from FireEye Support should be taken). Read full review Support Rating They are prompt in their response with a complete resolution once they have identified the problem. Other OEM's generally give stop-gap arrangements and then later come with new upgrade versions. This gives downtime tasks to customers often, which isn't appreciated. Given the criticality of this software, their support is prompt.
Read full review Trellix (FireEye + McAfee)
Alternatives Considered Better intergration with patch management tools. Forescount Platfform (CounterAct) is easily compatible with diverse network infrastructure to offer better service and efficiently ensure seamless operations. Its automation capabilities have also enabled us to depend less on the operations teams hence saving time as it's faster and also saving the operational cost of having people around in case of threats.
Read full review Trellix (FireEye + McAfee)
FireEye NX is a solid product. It gives you sustainable security throughout the organization. NX detection engines are more capable compared to others. Its catch rate is higher, FP rate is lower, [and] speed is awesome. NX can work for highly regulated environments with 1 way solution. Operation costs are much lower. Software quality is very good. It may have bugs, but these bugs do not compromise the security in general. SOC team loves the FireEye NX for its pinpoint detection capabilities. Local and partner support is exceptional.
Read full review Return on Investment We've managed to automate our cybersecurity to impressive extents, now the IT security team puts focus on more important things. We've attained successful assets risk mitigation for our clients. Read full review Trellix (FireEye + McAfee)
As [a] financial company on the digital markets, we need to be safeguard for 0days and targeted attacks. FireEye NX provides the best updated protection with its enhanced capabilities. Security score based on detection/prevention metrics [is] very high ensuring the highest level of security. APTs in our region successfully detected and mitigated by the NX. For the ROI, in a six month period FireEye is paying off its [investment]. One negative thing, especially with increasing network bandwidths, [is that] you need to make [the] investment every two or three years. Read full review ScreenShots Trellix Network Security Screenshots