FireMon, great tools for managing cyber security devices!
January 22, 2019
FireMon, great tools for managing cyber security devices!

Score 10 out of 10
Vetted Review
Verified User
Modules Used
- Security Manager
- Policy Optimizer
- Policy Planner
Overall Satisfaction with FireMon
We have used FireMon for our MSS clients, including managed firewalls from a different vendor. It's mainly used to manage firewalls, policy review and integrate into the CAB approval process, it went well and provided an easy solution for us and accurate report to clients. Friendly user interfaces are easy to use and system was stable all the time.
- Automate validation of compliance feature saved us time for auditing. It will generate report so we can provide to auditor for further review.
- Traffic flow analysis is one of the feature we used on daily basis, especially when there is a new request for adding policy for a complex environment, this feature provided accurate information on which security device is passing the traffic.
- Firewall cleanup recommendations helped us to improve firewall efficiency and avoid unnecessary changes. We scheduled to using this feature every 6 months to clean up zero hit rules and firewalls performance have been improved since.
- We had an issue when FireMon takes a long time to process the logs from over a dozen chatty firewalls. I understand when there are huge data sending to FireMon it needs time to process it, but FireMon might need to optimize how the data is handled.
- We are managing larger number of client's security devices using FireMon and it reduced our backlog for routine changes.
- By using FireMon's well-designed UI and great features like traffic analysis, removable rules report and compliance auditing etc, we are able to archive our goals in one central console, it saved manpower and reduced human errors.
We using FireMon to provide quarterly compliance reports to our clients. The report can be scheduled and sent to client directly. You can create custom assessments or use the pre-built ones, like PCI and NIST we used on different clients to meet different needs.