TrustRadius: an HG Insights company

Check Point Quantum Firewalls and Security Gateways

Score9.2 out of 10

39 Reviews and Ratings

What is Check Point Quantum Firewalls and Security Gateways?

The Check Point Quantum Security Gateway Next Generation Firewall is a tiered firewall product. The base model includes the core firewall services, and can be upgraded to include anti-bot/virus/spam and sandboxing capabilities.

Top Performing Features

  • Stateful Inspection

    Stateful inspection analyzes packet headers and contents of packets

    Category average: 8.6

  • Content Inspection

    Inspecting permitted application traffic by means of threat prevention, URL filtering and data filtering

    Category average: 8.4

  • Visualization Tools

    Visualization tools present administrators with data on applications traversing the network, who is using them, and the potential security impact.

    Category average: 7.7

Areas for Improvement

  • Firewall Management Console

    Either command-line or web-based interface for centralized control and management

    Category average: 8.4

  • Reporting and Logging

    Custom and summary reports, and log files enabling analysis of security incidents, application usage and traffic patterns

    Category average: 7.8

  • Proxy Server

    A proxy server changes your IP address and masks the origin of your network traffic

    Category average: 8.3

Robust firewall and zero-day protection on network

Use Cases and Deployment Scope

We are using Check Point Quantum Firewalls for Web filtering, IPS/IDS functionality along with gateway

Pros

  • WEBFILTER
  • IPS
  • IDS
  • GATEWAY

Cons

  • While using management console, sometimes we are getting duplicate policies and dashboard often hangs
  • customization on reporting will be difficult to create

Return on Investment

  • Check Point Quantum Firewalls gives very less vulnerability(Supply chain attack) compared to other peers. Hence, firmware activity is very minimal
  • Zero phishing feature helps to detect the web threat and gives more visibility to the security operations

Usability

Alternatives Considered

Palo Alto Networks Advanced Threat Prevention and Palo Alto Networks Advanced URL Filtering

Other Software Used

Palo Alto Networks Next-Generation Firewalls - PA Series, Fortinet FortiGate

Check Point advance security gateway.

Use Cases and Deployment Scope

Check Point Quantum firewalls and Security Gateways provide prime-level security at the perimeter level with Multiple blades and features like VPN, Content Filter, Application filter, etc. All this is managed by a smart console, and we can add firewalls in HA. With Distribution deployment, we can add firewalls at different locations or at a single location.

Pros

  • Provides prime level security at perimeter with 99% Accuracy.
  • NGTP blade can provide features with maximum benefit.
  • Check Point all in one evaluation blade provide access to evaluate the features.

Cons

  • In the smart console, all options should be visible as new, so that Check Point can find the option very easily.

Return on Investment

  • I was not involved in financial decision.

Usability

Other Software Used

Palo Alto Networks Next-Generation Firewalls - PA Series, Cisco Firepower 4100 Series

Acing Cyber Threats detection for our clients - CheckPoint is the way to go!

Pros

  • Stopping and detecting Day 0 attacks
  • Easy troubleshooting/ GUI
  • Scalability and speed
  • After sales support, NGFW capabilities

Cons

  • Modular capabilities
  • Integration with VMware and NSX products per client requirement
  • 3rd Party support product

Most Important Features

  • Application-aware boxes
  • Threat detection capabilities
  • Hyperscaling

Return on Investment

  • We saved an approx USD $ 750k minimum in a span of only 3 months due to long term planning and migrating from old /legacy platform to Newer CheckPoint Quantum Security Gateways
  • Long term plan - To purchase licenses for next 2-3 years planning = expected Savings = 500k - 1000k USD min
  • Super easy after sales support / Diamond level equivalent

Alternatives Considered

Check Point CloudGuard Posture Management (formerly Dome9)

Other Software Used

Check Point CloudGuard Posture Management (formerly Dome9), Stonesoft Next Generation Firewall (Discontinued), Trend Micro Cloud One - Application Security, Forcepoint Data Guard

Checkpoint firewall with nice VPN and NGFW features with tricky configuration

Pros

  • Internal Network Protection from outside network
  • VPN connectivity for secure data transmission across multiple vendors
  • File download antivirus security
  • URL Filtering
  • Malicious domains blocking

Cons

  • Fine tune required in the malicious domains blocking
  • Antivirus signatures should be updated in real time
  • Network latency can be reduced during high utilization time window

Most Important Features

  • Perimeter security
  • URL Filtering
  • Virtual Private Network

Return on Investment

  • Reduced attacks on DMZ servers
  • Blocked access of malicious destinations hit by internal users
  • Complete visibility about what is going and what is coming via internet

Alternatives Considered

Cisco ASA 5500-X with FirePOWER Services and Palo Alto Networks Next-Generation Firewalls - PA Series

Other Software Used

Cisco ASA 5500-X with FirePOWER Services, Palo Alto Networks Next-Generation Firewalls - PA Series, Fortinet FortiGate

Check Point's robust and unique feature set proves why it's the industry leader

Pros

  • SSL inspection provides more effective mitigation of threat and data leakage with the ability to inspect and analyze encrypted traffic.
  • Threat emulation and extraction provides protection against zero-day threats without compromising the data of infected files.
  • 'Office mode' VPN provides a seamless connected experience for remotely connected individuals.
  • Application control features provide granular restrictions to the type of application traffic than can pass through the network.

Cons

  • Pricing is not as competitive as the alternatives.
  • Perimeter antivirus is not as effective as its competitors
  • Steep learning curve and expensive certification paths may impair training paths

Return on Investment

  • Lower maintenance and information security management efforts thanks to the centralized console and dashboards
  • Improved mitigation of data loss/data leakage thanks to dedicated DLP blades
  • Improved productivity thanks to VPN/remote work capabilities
  • Improved internet access speeds and prioritization of services through the implementation of the application control blade
  • Improved employee productivity thanks to stringent URL filtering controls

Alternatives Considered

Palo Alto Networks Next-Generation Firewalls - PA Series

Other Software Used

Microsoft SQL Server, MySQL, NGINX, Apache Web Server, Microsoft Power BI