Advanced Intelligence Module for Cloud
What do you like best about the product?
It provides more features to secure and monitor our application networks, like VPV logs monitoring, User Account Activity monitoring, Pod to Pod communication on kubernetes clusters,etc. I like the feature of Graphical presentation of Captured logs.
What do you dislike about the product?
This features only supported on VPC & Account Activity logs.
The Graphical presentation will be supported on limited number of traffics only.
What problems is the product solving and how is that benefiting you?
The network security solution help us to continuously monitor our application networks and prevent any anomaly behaviour happens on our networks.
Thread Intelligence for Cloud Network logs
What do you like best about the product?
It having the anomaly Threat Intelligence Engine to detect our network inbound and outbound traffics effectively.
The engine having some predefined rulesets to address the runtime protection of our cloud environments.
It has supported the cluster pod to pod network communication as well.
What do you dislike about the product?
The module will be supported on Network VPC and user activity logs.
The engine will not supported to run the specific rulesets to assess.
What problems is the product solving and how is that benefiting you?
With the help of CloudGuard Network Security we continuously monitoring network and user activity logs on our cloud environments.
We have configured custom usecases to find malicious activity.
Amazing Threat Intel module for Cloud Application logs
What do you like best about the product?
The network module covers completely on console user activity logs and Vpc network logs. The additional features of gsl query will help us to easily identify and we can able to find the customized details of events.
What do you dislike about the product?
It will supports only on activity and vpc logs.
Log retention period is very low
What problems is the product solving and how is that benefiting you?
From the help of this module we reducing the malicious traffics from attackers. We can able to monitor the live traffics on continuously
probably one of the best cloud network security tool.
What do you like best about the product?
These are the points that i find best from my daily use of cloud gaurd
The User Interface is clean and easy to understand
the threat engine works so good
it has built in predefined log query (filters) that can save lot of manual work
traffic explorer is really helpful interms providing a breife understanding of the network traffic
ability to set up custom notifications is very useful
It supports custom rules
easy to integrate
easy to implement
great customer support
What do you dislike about the product?
the logs are limited to cloud trial and VPC logs
although traffic graph is great it is limited we cannot get end to end traffic view.
What problems is the product solving and how is that benefiting you?
since we have multiple cloud service providers and 7 different accounts for various applications, it is challenging to keep track of the security compliance of the cloud environment and any security breach starts at network level and is by far the most important part and cloud gaurd greatly helps us to keep track of the security standards.
Robust features in a cloud native world
What do you like best about the product?
Using CloudGuard network security allows for a familiar implementation with all the features of an onprem appliance. The deployment can be completely codified using Terrafrom, allowing for reapeatable deployments for each region. Using the AWS GWLB and endpoint service, inspecition can be extended to any / all member accounts for ingress / egress inspection. The GWLB deployment also allows for right sizing of EC2s that can increase/decrease with autoscaling. The policy can also be codified using Terraform, allowing for teams to inner-source access requests, but ensuring the proper security teams can still approve the access before it is rolled out.
What do you dislike about the product?
When using Terraform to manage the security policy, the object creation layout needs to be well thought through to ensure objects are created as disired. Also, publishing changes needs to be accounted for on Terraform apply success and failures so Terraform state and the Check Point database stay in sync.
What problems is the product solving and how is that benefiting you?
CloudGuard Network Security provides inspection throughout many parts of the cloud network.
1. Inspection of traffic from the internet inbound to a VPC.
2. Inspection of traffic from a VPC to the internet. Internet categories and applications can be used instead of having to know each exact FQDN, which would be a major pain and struggle for engineering teams.
3. Inspection between VPCs
4. Inspeciton between VPCs and on-prem
5. IPS
6. Detailed traffic logging
7. Identity based access
Since this deployment is EC2 based, traffic mirroing is also possible to enable external IDS systems.
Cloud Guard Network Security - Best Network Threat Analyser for Cloud
What do you like best about the product?
It will help us to reduce malicious attack traffic s on our cloud applications. It will monitor all our network and user level traffics and events.
I like the option of GSL module to provide us on filter the traffic events more deeply.
What do you dislike about the product?
Currently it will supports network and user activity to integrate.
What problems is the product solving and how is that benefiting you?
We reducing the risk of malicious traffics and it will help us to monitor our application traffics on 24/7
Offers straightforward licensing and excellent technical support
What is our primary use case?
My main use cases for CloudGuard Network Security are to scale the technology for protecting and filtering traffic within AWS and Azure environments.
The main challenge I was looking to address by implementing CloudGuard Network Security was the need to establish a firewall on our cloud perimeter for enhanced security.
How has it helped my organization?
The flexibility to rebuild the firewall in CloudGuard Network Security has helped our organization eliminate downtime.
CloudGuard Network Security has improved our organization by allowing us to easily deploy firewalls from the cloud wherever we might need them.
What is most valuable?
The most valuable feature I have found in CloudGuard Network Security is the flexibility to rebuild the firewall as needed.
What needs improvement?
CloudGuard Network Security could be improved in the area of upgrading in place.
For how long have I used the solution?
I have been working with CloudGuard Network Security for five years.
What do I think about the scalability of the solution?
The scalability of CloudGuard Network Security is very good and we can scale it as needed.
How are customer service and support?
Check Point's service and tech support are very good, especially since we have access to their Diamond-level support. I would rate the support as a ten out of ten.
How would you rate customer service and support?
What's my experience with pricing, setup cost, and licensing?
I find the pricing and licensing of CloudGuard Network Security to be pretty straightforward.
What other advice do I have?
The main benefit we have seen from using CloudGuard Network Security is the ability to filter traffic by URL. We realized these benefits approximately six months after deployment.
Unified management of the firewall has positively affected our security operations by making it easy to manage from one place.
My advice for those evaluating CloudGuard Network Security is to remember that licensing is critical, so ensure that central licensing is configured properly.
Overall, I would rate CloudGuard Network Security as a ten out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Gives a lot of visibility and we can manage all cloud environments from a central place
What is our primary use case?
We are primarily using it for access control for our various cloud environments from our on-prem resources.
By implementing CloudGuard Network Security, we wanted granularity and control of the traffic going through our different BDCs within AWS. We use one there. We also wanted identity awareness for going into cloud resources.
How has it helped my organization?
CloudGuard Network Security gives us access and visibility into what is going on in our cloud environments. Previously, we did not have any cloud instances. We were just managing the on-prem and then letting it go. It gives a lot of visibility. We could realize its benefits instantly.
CloudGuard Network Security provides us with unified security management across hybrid-clouds as well as on-prem. We were able to manage all of our cloud environments from one central place. We have got CloudGuard in Azure and AWS restricting traffic between those hybrid cloud environments.
We feel very confident in our cloud network security by using CloudGuard Network Security. We get what we would expect with an on-prem firewall. We get all of the functionality and security that we would expect from an on-prem firewall in the cloud. We did not go with our cloud vendor's cloud firewall because they were not able to meet a lot of the security standards that we needed.
What is most valuable?
The ease of deployment has been nice. It is like managing any of our on-prem firewalls.
What needs improvement?
The only pain points we have had with it were when we did major version upgrades. Rather than being able to do incremental upgrades on those, we had to completely redeploy. I know that has changed recently, but we had some hiccups when we did the upgrades. This is the only issue we have had.
For how long have I used the solution?
We have been using CloudGuard Network Security for over four years.
What do I think about the stability of the solution?
It is very stable. I would rate it a ten out of ten for stability.
What do I think about the scalability of the solution?
It scales pretty easily. At this time, I am not aware of any plans to increase its usage.
How are customer service and support?
Their support is great. I would rate them a ten out of ten.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We did not use a similar solution previously.
How was the initial setup?
It is a private cloud. We have it in both our private Azure and private AWS restricting access between the individual BDCs and on-prem environment and between the two different cloud environments as well.
It is primarily deployed by one team, but multiple clients use the cloud services.
What was our ROI?
I believe we have seen an ROI. We are able to manage it from an already existing management server that we are using for on-prem. Not having to have another product that we are managing outside of Check Point is a big plus.
Which other solutions did I evaluate?
We looked at cloud-native firewalls. They were not able to meet the security standards that we were able to get by using CloudGuard.
We looked at their IPS solutions with the cloud-native firewalls, but we could not go as granular. With CloudGuard Network Security, we could see the individual protection and fine-tune it.
CloudGuard Network Security is also easier to use than other solutions.
What other advice do I have?
I would rate CloudGuard Network Security a ten out of ten.
Offers seamless deployment, rapid scalability, and user-friendly management, providing robust protection against threats with ease
What is our primary use case?
We utilize CloudGuard Network Security as virtual appliances deployed within virtual machines, acting as firewalls at the perimeter of our data center in QSaver. These virtual appliances safeguard all internet access originating from the virtual machines at our factory in Curitiba, Brazil.
How has it helped my organization?
The challenges we sought to tackle through the implementation of CloudGuard Network Security were to ensure the protection of our servers against threats and attempts to breach them via internet-facing avenues.
We found it advantageous due to its ease of implementation and use. There were no delays in receiving customer devices, which enhances security within the environment.
We enjoy all the benefits typically associated with physical appliances, even while utilizing virtual machines. Although it took some time for customers to fully grasp the benefits, as they weren't immediately clear, over time, they began to recognize the value it brings to their security infrastructure.
It offers us unified security management across hybrid CloudGuard deployments, as well as on-premises. The option to manage it bridges physical devices onto the data center. With consolidated logs accessible on the same management interface, it becomes highly convenient and straightforward to operate.
Comparing CloudGuard's network security to other solutions in terms of ease of use is challenging. Additionally, since we're already utilizing Check Point solutions, integrating it with hardware network security proves to be very straightforward and user-friendly.
We have a high level of confidence in the effectiveness of CloudGuard Network Security.
What is most valuable?
The SSL spectrum proved to be the most valuable for our incoming connections. This feature enabled us, for instance, to successfully prevent Log4J attack attempts.
What needs improvement?
New features have been introduced recently, but they have not yet been integrated into CloudGuard Vsec. It would be advantageous to have them implemented as they would improve the performance.
For how long have I used the solution?
I have been using it for three years.
What do I think about the stability of the solution?
It provides excellent stability capabilities.
What do I think about the scalability of the solution?
It offers good scalability abilities. We have a plan to increase the utilization of CloudGuard Network Security and its services in the future.
How are customer service and support?
I am satisfied with the customer service and support provided. I would rate it eight out of ten.
How would you rate customer service and support?
What about the implementation team?
In our deployment environment, each instance is strategically positioned at the forefront of the web servers within the data center, effectively serving its purpose. Specifically, it functions to regulate internet access for the servers and manage inbound connections from internet customers to the servers.
It's remarkably easy to deploy, by far the simplest. For instance, it only took us a few minutes to transition to production. This capability is incredibly beneficial, as it allows us to swiftly assist customers during emergencies by deploying a firewall and addressing any threats they may encounter.
What was our ROI?
Determining the return on investment can be challenging; however, we've observed other companies operating in the same sector with similar approaches. Despite encountering attacks, we have yet to experience any incidents. This absence of incidents serves as a metric for us, indicating the reliability of our alternative solution.
What's my experience with pricing, setup cost, and licensing?
The pricing is highly competitive and advantageous, offering great value.
What other advice do I have?
I recommend others to give it a try because of its simplicity in deployment, scalability, and usability. Overall, I would rate it ten out of ten.
Makes policy management easy and helps to improve security score and uptime
What is our primary use case?
We use it to analyze all the traffic in our network. It is the main tool for security services and networking in our company.
How has it helped my organization?
We increased our security score by introducing the tool. We are continuing to grow and improve. In terms of policies, we have a lot of benefits in terms of the security cluster and how it works.
CloudGuard Network Security provides unified security management across hybrid-clouds as well as on-prem. We have a hybrid scenario in the company. We have 3% of services in the cloud, and we can use the same clusters and the same policies that we have on the on-premise side for our cloud services. We have the same benefits for both.
We are pretty confident in our cloud network security using CloudGuard Network Security. We are not exactly an Internet-exposure company, but we have a cloud setup. We are pretty confident with its configuration assessment. With Check Point as our partners, we are protected, and we can be confident in our security.
What is most valuable?
Microsegmentation is very useful for us because we minimize the surface attack. The easy management of the policies is great for us because we are a small team and having easy management is great and useful for us.
What needs improvement?
At this point, we are very happy with what is happening with their horizon. At CPX, we heard that we can see all the things on the same platform. That is what we have been asking for, and hopefully, we are going to start seeing it this year.
For how long have I used the solution?
I have been using CloudGuard Network Security since 2020.
What do I think about the stability of the solution?
It is stable. I cannot remember a time when we had any issues with it. Our operations are 24/7.
What do I think about the scalability of the solution?
It is scalable. We do not have any problems with it.
How are customer service and support?
We have had a good experience with the support and customer service, and we are happy with them.
I would rate them a nine out of ten. A unique issue that we have is related to the language. When the first level of support cannot resolve an issue and the issue needs to be escalated, we have a language challenge because the team is based in India. There are some limitations on both ends.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We used our cloud vendor's security but did not get as many details when we had any issues. We immediately moved to Check Point, and we are more confident of Check Point.
At first, we used Azure and Defender, and before we changed to CheckPoint, we used ESET. So, we had ESET and then we started rolling out Check Point. We had a mix with the cloud vendor solution, and then we went for Check Point.
How was the initial setup?
We have a mix of on-premises and cloud. We use the Infinity services.
My team deployed it. I have three security engineers on the team, and with the help of Check Point, we deployed it. We upgraded very recently in December, and it was a good experience. It has been running well.
What about the implementation team?
We used the services of a company based in Panama. With the Infinity contract, we had some professional time with Check Point, and they helped us set up some of the things. They reviewed some of the things that we deployed, so we have all the best practices.
What was our ROI?
I do not have a lot of details on that, but our uptime is pretty high.
What's my experience with pricing, setup cost, and licensing?
It is an expensive product, but when you realize that you need it, it does not feel so expensive.
We have had a good experience with them as partners. They have helped us with designing and having good architecture and the best equipment at the best prices. We find it a good deal.
Which other solutions did I evaluate?
We evaluated Microsoft's security suite. The thing that made us decide on Check Point was that Check Point had the least zero-day attack score. We have a lot of solutions from Check Point, and we stayed with Check Point.
We are now not evaluating other solutions because, since 2020, we have chosen Check Point as our partner. It continues to be the best solution for us to improve our score. We are not looking for software solutions from other vendors.
We always keep track of the service and the score, and with Check Point, there has always been the highest score.
What other advice do I have?
I would rate CloudGuard Network Security a ten out of ten. We are happy with the uptime and management. It is a good tool, and it provides a lot of value for us. We are happy.