We currently use the security manager modules to clean and fine-tune our set of policies centrally. We additionally use a policy planner to automate our process of routine operations in policy sets.
Pros
Cleaning policy sets.
Policy set automation.
Detailed analysis of the policies to be implemented.
Cons
Keep up with new features implemented by security vendors.
Likelihood to Recommend
Environments where it is required to automate firewall security operations activities. Where it is required to have detailed change audit controls.
VU
Verified User
Manager in Information Technology (Computer & Network Security company, 1001-5000 employees)
We use FireMon to validate rules, test traffic pathing and to do TFAs for minimizing overly permissive rules.
Pros
TFA and TFA output is fantastic
Finding misconfigured rules is very easy
We arent leveraging very much from FireMon
Cons
The support site isnt the best
Likelihood to Recommend
The ability to find an overly permissive rule and then leverage TFA to monitor the rule's traffic with the output being easily consumable is incredibly valuable.
We used FireMon as a firewall analyzer of internal and external perimeters. We were able to gather relevant tcpdumps instead of looking directly in the firewall. This is very useful for executive managements, we can just provide them read only access and if someone in our organization asked them they can directly check for any network traffic on their own.
Pros
Straightforward firewall analyzer, executive management people can understand what's going on.
Provides risk rating for any allowed firewall policies
Easy dashboard management
Can connect to our SIEM
Cons
Had an issue integrating Checkpoint firewall, need to improve integration with it.
Likelihood to Recommend
1. We used FireMon mainly on reviewing firewall policies that are high risk or that are not being used in the network anymore. We are able to configure several thresholds wherein once there are no hit counts for atleast 60 days (2 months) there will be an alert to us administrators. 2. We also use several dashboards that are shared to executive personnel for them to see what is going on in our internal and external perimeters.
VU
Verified User
Administrator in Information Technology (Information Technology & Services company, 501-1000 employees)
We use FireMon for compliance purposes. We use it to generate reports whenever a change is made to the Firewall. We can see who pushed policy in Checkpoint, what Change# it is associated with, and what was actually done compared to what the change ticket stated.
Pros
When working correctly, it generates reports for each firewall when a change is made.
It is a great tool to audit Firewall rules, redundant rules, and changes made
Cons
It doesn't always provide reports for when changes are made.
It only shows who pushed policy in the reports, not who made the actual changes to the firewall.
You can no longer drill down into reports at a granular level which back in Version 7 you were able to, which provided a great deal of information.
Seems to have some issues communicating with Checkpoint retrieving all reports that are split between two data centers.
Likelihood to Recommend
When working correctly, it is great for audit purposes when you need to show when changes were made, what was made, who made them, and with what change. When the reports aren't working, you have to dig up all this information manually. Back in version 7, you were able to drill down in the reports that provided a very granular detailed information, now the newer version doesn't allow for this.
VU
Verified User
Analyst in Information Technology (Information Technology & Services company, 501-1000 employees)
We are a product distributor of Firemon, we were able to sell Firemon to some of our customers, from telecoms, banks and call centers. I am the one providing the walkthrough and guide the customers on how to integrate the FireMon security manager to the Firewall devices. FireMon addresses a lot of difficulties that the firewall administrator faces, a lot of firewall devices are not optimized. FireMon can help a lot on this department. Though FireMon has other add on modules from the security manager. I did not see an aggressive positioning of the other modules.
Pros
Configuration changes, it can monitor and alerts any change on the firewall through email alerts.
Traffic Flow Analysis help a lot to further discover, tightening rules such as ANY rules configured on the firewall.
Cons
Needs more supported devices and firewall supported vendors.
Needs to push other add on modules to show the full capability of the FireMon Security Manager. eg policy planner, policy optimiser, risk analysis.
Needs aggressive marketing in the Philippine Market. A lot of customers are not aware that there is a solution for firewall optimization and management.
A lot of add on features are not introduced or not being used by the customer.
We have used FireMon for our MSS clients, including managed firewalls from a different vendor. It's mainly used to manage firewalls, policy review and integrate into the CAB approval process, it went well and provided an easy solution for us and accurate report to clients. Friendly user interfaces are easy to use and system was stable all the time.
Pros
Automate validation of compliance feature saved us time for auditing. It will generate report so we can provide to auditor for further review.
Traffic flow analysis is one of the feature we used on daily basis, especially when there is a new request for adding policy for a complex environment, this feature provided accurate information on which security device is passing the traffic.
Firewall cleanup recommendations helped us to improve firewall efficiency and avoid unnecessary changes. We scheduled to using this feature every 6 months to clean up zero hit rules and firewalls performance have been improved since.
Cons
We had an issue when FireMon takes a long time to process the logs from over a dozen chatty firewalls. I understand when there are huge data sending to FireMon it needs time to process it, but FireMon might need to optimize how the data is handled.
Likelihood to Recommend
Friendly user interfaces, supports API. Plus, FireMon provided best technical support for any issue we had. We also benefitted from training by FireMon which helped us fully using the feature it provided to better manage our clients.
VU
Verified User
Consultant in Information Technology (Computer & Network Security company, 1001-5000 employees)
We have customers that have this product and we help them with the installation. For one of them we have a managed service, and it means we manage the tool with tasks like doing firmware upgrades, adding/deleting devices and helping them with reports and other configurations. It is also used for training the customer’s users to and understand the reports and other features FireMon Security Manager has.
Pros
Custom compliance assessments. Even [though] FireMon Security Manager has a complete suite of compliance assessments, it's a strength that we are able to build custom compliance assessments to review the status of the network based on our internal policies.
Rule Search. Is an awesome tool because we can verify before creating a new firewall policy in the network if there is any other policy that is already created that fulfills the request. It lets you keep your firewalls clean.
Cons
Building the maps is still a complex task to complete. It requires a lot of time to do it and it's not too intuitive.
Likelihood to Recommend
Appropriate: - Within complex networks with devices from different vendors - Companies merging with other companies
VU
Verified User
Engineer in Engineering (Information Technology and Services company, 11-50 employees)
I am a network security engineer for a large ISP and we recently implemented FireMon in our network to help manage our firewalls. We are a growing company and this product helps us consolidate our firewalls to give us a better understanding of how they are being used and how often.
Pros
FireMon gives a great overview of all firewalls on the network.
FireMon tells us what rules are and aren't being used to help us keep our policies manageable.
FireMon gives us a better understanding of what areas might need more security.
Cons
It's great that it can tell us what rules are redundant but it doesn't lay out the rules side by side.
Could provide more online training like videos and documentation, to maximize our use of FireMon.
Likelihood to Recommend
We were getting to migrate from one firewall to another and so we went in and removed all the unused rules and redundant rules. By doing this, it made the migration period much shorter and we knew that the rules that we migrating were accurate.
VU
Verified User
Engineer (Information Technology and Services company, 1001-5000 employees)
FireMon Security Manager is being used within my organization for several purposes. I specifically utilize FireMon 8 in order to gain long-term information about the traffic hitting the firewalls within the network. The reports that I'm able to run using FireMon 8 give allow me to better analyze the firewalls in order to remediate rules within the firewalls.
Pros
Provides well organized, easy to read reports such as rule usage and object usage.
Provides ability to quickly run a query to identify where particular objects are being used.
Logging of firewalls over time gives long-term status on rule use on the firewalls.
Cons
Learning how to write syntax to query information was difficult.
Difficult to rely solely on the results from queries run in FireMon. I have seen different results from FireMon and what is on the firewall using another tool and FireMon was inaccurate.
Logging stops or malfunctions on FireMon.
Likelihood to Recommend
FireMon Security Manager is well suited for anyone who is working within security, remediation, or architecture for their company's network. FireMon's report library enables the user to run reports in order to analyse, change, check compliance and health check, and usage for environment. It quickly identifies rules that can be/need to be cleaned up within the environment, particularly rules that are disabled or need description.