Yuvanesan  V.
YV
Yuvanesan V.
Software Developer Intern
"Generation Firewalls"
4/5
What do you like best about Check Point Next Generation Firewalls (NGFWs)?

From what I've learned, the best aspects of Check Point Next Generation Firewalls (NGFWs) are their comprehensive security features, including intrusion prevention, application control, threat prevention, and secure VPN capabilities. They also have a centralised management console that makes it easier to configure and monitor network security across an organisation. Review collected by and hosted on G2.com.

What do you dislike about Check Point Next Generation Firewalls (NGFWs)?

Based on what I've read and learned, some users mention that the initial setup can be complex for beginners, and the large number of security features may require time to learn. Some organisations also feel that licensing and advanced features can be expensive compared with other firewall solutions. Review collected by and hosted on G2.com.

Nijat I.
NI
Nijat I.
Full-stack Developer
Information Technology and Services
Small-Business (50 or fewer emp.)
"Extensive Network Traffic Visibility That Simplifies Log Analysis and Policy Updates"
4.5/5
What do you like best about Check Point Next Generation Firewalls (NGFWs)?

Most of my work with the Check Point Next Generation Firewalls involved analyzing firewall logs, verifying security policies following infrastructure changes, and examining traffic within, outside, and across the network.

One feature that came in particularly handy was having detailed information for any connection that was blocked. Rather than just getting information about the source and destination, I was able to examine the traffic at the application level to see which services and protocols were causing the traffic. In the context of policy changes or adding new apps, this allowed me to make sure that there wasn't any unnecessary exposure while retaining necessary business traffic.

Checking hit counts and ensuring that traffic was behaving as expected after making policy changes was also an important task. Review collected by and hosted on G2.com.

What do you dislike about Check Point Next Generation Firewalls (NGFWs)?

The more that firewall policies increase in number, the more difficult their management will become. It is necessary to perform careful validations when making changes to such rules since their order and inspection modes will determine whether or not traffic will be treated correctly by firewalls.

Finally, I recall dealing with issues involving legitimate traffic whose treatment changed upon modifications made to the policies. It is hard to predict how such policies will interact if they are managed by several people from various departments.

Additionally, it can be problematic to maintain clean policies in the long run if their regular checks are neglected. Review collected by and hosted on G2.com.

Arkajit D.
AD
Arkajit D.
Chief Technology Officer
Information Technology and Services
Mid-Market (51-1000 emp.)
"Strong All-in-One Security and SmartConsole Management, but Setup and Scaling Take Care"
3.5/5
What do you like best about Check Point Next Generation Firewalls (NGFWs)?

The main advantage of Check Point NGFWs is the security strategy itself, which includes a combination of firewall, intrusion prevention, threat prevention, and application control capabilities all in one package. With it, users can effectively protect their infrastructure from various types of modern cyber-attacks with no need to install any additional software.

In addition, the centralized management via SmartConsole is another feature worth mentioning, since it significantly simplifies policy creation and allows users to easily monitor and control network traffic from one location.

In general, it's an efficient and reliable product which provides both solid protection capabilities and convenient management options. Review collected by and hosted on G2.com.

What do you dislike about Check Point Next Generation Firewalls (NGFWs)?

First, the product may be considered difficult to set up and operate because its advanced policy and rule configuration settings may not be easy for beginners who have no experience working with Check Point products. In addition, it is rather expensive because of licensing fees required for various security blades, although it costs less than competing solutions.

However, performance issues may occur when many security blades operate simultaneously, especially when a large amount of data is processed at once.

Therefore, special attention should be paid to system scaling. Review collected by and hosted on G2.com.

Verified User in Animation
CA
Verified User in Animation
Mid-Market (51-1000 emp.)
"Powerful Check Point NGFW Security, but Setup and Licensing Can Be Challenging"
3.5/5
What do you like best about Check Point Next Generation Firewalls (NGFWs)?

I like Check Point NGFWs because of their strong security capabilities, centralized management, and advanced threat prevention features. The integration of features like IPS, application control, URL filtering, anti-malware, sandboxing, and threat intelligence helps provide layered protection against modern cyber threats. The SmartConsole management platform also makes it easier to monitor, configure, and maintain multiple firewalls from a single interface. Review collected by and hosted on G2.com.

What do you dislike about Check Point Next Generation Firewalls (NGFWs)?

One downside of Check Point NGFWs is that the initial setup and configuration can be complex, especially for new administrators. The licensing model can also be expensive compared to some alternatives, and major upgrades or policy changes may require careful planning to avoid disruptions. The platform is powerful, but it has a steeper learning curve compared to simpler firewall

solutions. Review collected by and hosted on G2.com.

Erick Vincent Steve G.
EG
Erick Vincent Steve G.
IT Support I
Enterprise (> 1000 emp.)
"The Ultimate Tool for Threat Prevention"
4.5/5
What do you like best about Check Point Next Generation Firewalls (NGFWs)?

What I appreciate most about Check Point NGFWs is the unparalleled visibility provided through the SmartConsole. Having a single pane of glass to manage complex security policies across different environments is a massive time-saver. The granular logging and 'Policy Layers' make auditing and troubleshooting much more intuitive compared to other vendors. Review collected by and hosted on G2.com.

What do you dislike about Check Point Next Generation Firewalls (NGFWs)?

The primary drawback of Check Point NGFWs is the steep learning curve associated with the SmartConsole. While the unified management is powerful, it can be overwhelming for junior admins or those accustomed to more intuitive, web-based interfaces. The complexity of policy layers and object management requires specialized training to master, which can lead to a slower onboarding process. Additionally, the initial configuration and the resource-heavy nature of the management server itself can be a significant hurdle for smaller environments with limited hardware budgets. Review collected by and hosted on G2.com.

xandr P.
XP
xandr P.
Legend: Legacy of Dragons"
Mid-Market (51-1000 emp.)
"Excellent orchestration and management, but complex setup"
3.5/5
What do you like best about Check Point Next Generation Firewalls (NGFWs)?

I use Check Point Next Generation Firewalls (NGFWs) for application control and I like the unified management through Smart Console, it's one of the best solutions on the market. I am impressed by the prevention vs detection philosophy. The Maestro orchestration technology allows for excellent scalability, providing predictability and speed in deploying a new gateway. Review collected by and hosted on G2.com.

What do you dislike about Check Point Next Generation Firewalls (NGFWs)?

If some kind of mystery starts within the cluster, for example, an asymmetric route, unraveling it is hellishly difficult, you have to use separate utilities to understand which of the 28 physical gateways is dropping the packet, and the entry threshold into Maestro requires skills. Configuration will not be easy for any level. Review collected by and hosted on G2.com.

Verified User
G
Verified User
Mid-Market (51-1000 emp.)
"Strong Security, Centralized Management, but Complex Licensing"
4/5
What do you like best about Check Point Next Generation Firewalls (NGFWs)?

I appreciate Check Point Next Generation Firewalls for their strong security features and centralized management through SmartConsole. I find the integration of threat prevention technologies like IPS, Anti-Bot, and Threat Emulation to be valuable, providing multiple layers of protection. I like how the unified security approach simplifies managing policies, monitoring network activity, and maintaining a strong security posture. I also enjoy its ability to block any shady site, which adds a layer of safety against scammers. Review collected by and hosted on G2.com.

What do you dislike about Check Point Next Generation Firewalls (NGFWs)?

Check Point NGFWs offer excellent security, but the learning curve can be steep. The licensing model can be complex, and managing large rule bases may become challenging over time. Simplifying deployment, licensing, and policy management would make the platform even more user-friendly. The initial setup of Check Point NGFWs was moderately challenging. The deployment process is well-documented, but it still requires a solid understanding of networking and security concepts. Configuring the initial policies, routing, and security blades took some time, especially to align with our existing infrastructure. Review collected by and hosted on G2.com.

ZM
Zeeshan M.
Mid-Market (51-1000 emp.)
"Reliable Security with Scope for UI Improvements"
4/5
What do you like best about Check Point Next Generation Firewalls (NGFWs)?

I like the reliability and threat-prevention accuracy of Check Point Next Generation Firewalls (NGFWs). It's stable, and the security blades work consistently. The visibility into traffic makes troubleshooting straightforward. I also prefer Check Point for its stronger threat prevention, better stability, and more mature management features compared to our previous firewall vendor. The initial setup was fairly straightforward, with the wizard helping with the basics, and once the core configuration was done, the rest was manageable. Review collected by and hosted on G2.com.

What do you dislike about Check Point Next Generation Firewalls (NGFWs)?

The management interface can feel dated, and policy pushes take longer than they should. Logging can also lag during peak times, and upgrades sometimes require more planning than other vendors. Review collected by and hosted on G2.com.

Ahmad A.
AA
Ahmad A.
Flutter Developer
Information Technology and Services
Small-Business (50 or fewer emp.)
"Strong Multi-Layered Security and Centralized SmartConsole Management"
4/5
What do you like best about Check Point Next Generation Firewalls (NGFWs)?

Check Point NGFWs stand out for their strong, multi-layered security and ability to prevent advanced threats before they impact the network. The centralized management through SmartConsole makes it much easier to control policies, monitor traffic, and maintain visibility across different environments from a single place. I also like how the platform integrates multiple security features—like IPS, sandboxing, and threat intelligence into one solution, which reduces the need for separate tools. Overall, it delivers reliable performance and scalability, making it suitable for both enterprise environments and growing infrastructures. Review collected by and hosted on G2.com.

What do you dislike about Check Point Next Generation Firewalls (NGFWs)?

The main downside is the complexity, especially during the initial setup and policy configuration. It’s not very beginner-friendly and often requires experienced engineers to deploy and manage properly. Licensing can also be confusing, with multiple bundles and add-ons that are not always clearly structured. Additionally, the cost is relatively high compared to competitors, and in some cases, support response times or update processes can be slower than expected. Review collected by and hosted on G2.com.

Verified User in Consulting
UC
Verified User in Consulting
Small-Business (50 or fewer emp.)
"Powerful NGFW, but complexity, licensing headaches, and performance hits create friction"
2/5
What do you like best about Check Point Next Generation Firewalls (NGFWs)?

Here is a structured deep dive across those six key pillars for Check Point Next Generation Firewalls (NGFWs):

1. UI / UX

SmartConsole: The centralized management interface is highly regarded for its object-oriented architecture. Once you define a network object, you can reuse it across any policy or rule base seamlessly.

Complexity: The sheer depth of configuration options means it has a steeper learning curve compared to more minimalist competitors. It is powerful but requires dedicated expertise to navigate efficiently.

2. Integrations

Extensive API Support: Check Point provides robust REST APIs, making it highly compatible with CI/CD pipelines, orchestration tools (like Ansible or Terraform), and SIEM/SOAR platforms.

Cloud & Hybrid Environments: It integrates smoothly across AWS, Azure, and Google Cloud, allowing unified policy enforcement across on-premise and cloud workloads.

3. Performance

Maestro Hyperscale: Check Point's clustering technology allows you to scale performance dynamically by distributing traffic across multiple firewalls, avoiding traditional active-passive bottlenecks.

Inspection Overhead: Enabling deep packet inspection, TLS 1.3 decryption, and advanced sandboxing simultaneously will impact throughput, requiring precise sizing during deployment.

4. Pricing / ROI

Premium Cost: It sits at the higher end of the enterprise market. Hardware, software licensing (blades), and ongoing support require significant capital.

Long-Term Value: The ROI comes from risk mitigation. Preventing a single major breach or downtime event often justifies the upfront licensing costs for enterprise environments.

5. Support / Onboarding

User Community & TAC: The Check Point Technical Assistance Center (TAC) is generally responsive for critical issues, and the "CheckMates" user community is an excellent resource for real-world troubleshooting.

Onboarding Curve: Due to the complexity of blade architectures (e.g., separating Application Control, URL Filtering, and Threat Prevention), initial deployment usually requires certified professional services or experienced in-house engineers.

6. AI / Intelligence

ThreatCloud AI: This is the backbone of their security effectiveness. It aggregates real-time threat intelligence globally, using machine learning models to block zero-day exploits and phishing attempts before they hit the internal network.

Autonomous Security: Recent updates lean heavily into automated policy adjustments, minimizing human error in rule creation. Review collected by and hosted on G2.com.

What do you dislike about Check Point Next Generation Firewalls (NGFWs)?

While Check Point is a powerhouse in security effectiveness, it has several well-documented pain points that engineers and administrators frequently run into.

Here is the flip side of the coin across those same six pillars:

1. UI / UX (The "Heavy" Client & Complexity)

SmartConsole Resource Drag: The primary management tool, SmartConsole, has historically been a fat Windows client. It can feel slow to load, resource-intensive, and clunky if you are managing it over a high-latency VPN connection.

Policy Fragmentation: Because features are broken into separate "Software Blades" (e.g., Firewall, URL Filtering, Threat Prevention), managing and auditing rules can feel fragmented. You often have to bounce between different tabs, layers, and policy packages to see the full picture of what is happening to a single packet.

2. Integrations (Legacy Friction)

Cloud-Native vs. Lift-and-Shift: While cloud integration has improved significantly with CloudGuard, Check Point's architecture can still feel like a traditional on-premise firewall adapted for the cloud, rather than a truly cloud-native, lightweight microservice solution.

Third-Party Ecosystem: While standard APIs are robust, setting up seamless orchestration with niche or non-standard third-party vendors often requires more manual scripting and custom API work than its main competitors.

3. Performance (The "Blade" Tax)

Throughput Degradation: The moment you turn on deep packet inspection, HTTPS inspection, and advanced threat emulation (sandboxing) simultaneously, performance takes a visible hit. If you don't over-provision your hardware sizing from day one, enabling full security features can severely bottleneck your network throughput.

Slow Policy Compilation: Pushing a policy change isn't instant. When you hit "Install Policy," the system has to compile the changes and push them to the gateways, which can take anywhere from a couple of minutes to significantly longer in massive environments with complex rule bases.

4. Pricing / ROI (Convoluted Licensing)

The "A La Carte" Software Blade Model: Check Point's licensing can be an absolute nightmare to navigate. Because features are split into individual software blades, it is easy to find yourself getting nickeled-and-dimed for extra capabilities (like advanced bot prevention or specific mobile access licenses) that you assumed were included.

High Renewal Costs: Support and subscription renewals for ThreatCloud AI and hardware maintenance are among the steepest in the industry, making the total cost of ownership (TCO) incredibly high over a 3- to 5-year lifecycle.

5. Support / Onboarding (The Upgrades Scares)

Complex Upgrade Paths: Upgrading Check Point Gaia OS via CPUSE (Check Point Upgrade Service Engine) has historically given network admins gray hairs. Minor version mismatches, dependency issues, or hotfix conflicts can cause upgrades to fail midway, requiring lengthy rollbacks.

Brutal Learning Curve: This is not a "set-it-and-forget-it" firewall. Onboarding a junior engineer to manage a Check Point environment safely takes a long time due to the complexity of the architecture, meaning high operational overhead for training.

6. AI / Intelligence (False Positive Tuning)

Aggressive Default Stances: Because ThreatCloud AI is highly sensitive to zero-day signatures, shifting threat prevention into "Prevent" mode out of the box can cause a spike in false positives. It requires significant, ongoing manual tuning by an administrator to ensure legitimate business traffic isn't accidentally blocked by automated machine-learning heuristics. Review collected by and hosted on G2.com.