"Automated Firewall Workflows That Save a Great Deal of Time"
I appreciate that you can automate firewall workflows—that's mainly what I've used it for, and it has saved a significant amount of time. Our network team relies on it completely. There's nothing negative to mention—it works as designed and has been very easy to configure. The main purpose is to automate policy change requests and streamline firewall processes.
"AppViz Makes Network Rules Easy to Understand"
I enjoy using AppViz. It's excellent for viewing applications and gaining a better understanding of the network rules behind them. The price was on the higher side for us, but once it was deployed, we saw the value. Previously, when we had application issues, we couldn't see the flow. Now we can clearly see the flow and the rules, and we're able to identify the problem.
"Algosec for ACI"
Fantastic product and customer service—the tool significantly improved usability on ACI clusters and helps clients understand the correct ACI format. I haven't encountered anything I dislike, but the user interface could be simpler, as it can be confusing at times. It assists clients in transitioning from network-centric design on ACI to a more structured approach for ACI microsegmentation.
"Effective Firewall Cleanup with Algosec, but Needs Better Stability"
Algosec has proven very effective for firewall cleanup tasks, which I've been using it for over the past two years. It offers a good range of options and statistics, though I've noticed they aren't always completely accurate. The monitoring features are comprehensive, and I find the user interface particularly user-friendly. Additionally, deployment is straightforward, which adds to its convenience.
My main concerns are occasional malfunctions and times when statistics aren't visible. There are also communication issues with Checkpoint firewalls—some changes either don't appear in the tool or take a long time to show up. Even when our firewalls are configured identically, the tool still struggles to communicate with one of them. Moreover, there's a significant issue with integrating Microsoft Exchange Cloud relay, which we depend on for sending weekly firewall reports. This compatibility problem is a major drawback.
TAC support is not up to par, as they lack proper knowledge of the tool and have very few senior support members. The primary advantage we get from Algosec is its support for firewall cleanup activities. Over the past two years, I've regularly performed these cleanups, and they've generally been successful without major issues. Another benefit is how Algosec documents each activity, which is useful for future reference and verification.
"Streamlined Firewall Setup with a Clear, Standardized Procedure"
We appreciate that there's a defined process and we don't have to set up each firewall individually. Having them all mapped to applications makes it much easier for our business stakeholders to submit requests in terms they understand. With our complex network design, sometimes it struggles to understand traffic flows. We're under pressure to implement firewall rules quickly—and this allows us to have rules enabled fast based on what the business needs, in a way they can comprehend.
"Centralized Firewall Assurance Made Simple"
AlgoSec Firewall Analyzer is a top-notch tool for ensuring firewall assurance against defined standards and compliance requirements. It offers a comprehensive, single-pane view of the entire network, making it easy to understand policy structures and the potential impact of changes before implementation. This visibility is extremely valuable for maintaining a secure and organized firewall environment.
Additionally, the training provided by AlgoSec is very insightful and well-structured, particularly helpful for first-time users. It gives a solid foundation for understanding the products and their capabilities, allowing teams to quickly become proficient in managing and analyzing firewall policies.
Overall, AlgoSec Firewall Analyzer is a powerful solution for improving network security posture and streamlining firewall management. The initial configuration can be a bit complex and time-consuming, especially in environments with multiple vendors and large, distributed networks. Managing complex firewall environments across multiple vendors can be challenging, especially when aiming to maintain compliance, optimize policies, and prevent misconfigurations. Without clear visibility, predicting the impact of policy changes is difficult, which can lead to outages, compliance gaps, and security risks. AlgoSec solves this by providing a centralized view of all firewall policies, automating compliance checks, and continuously monitoring for risky or overly permissive rules. It simplifies audits by generating detailed, ready-to-use compliance reports and helps teams quickly identify and remediate violations, ensuring standards are consistently met.
AlgoSec's policy impact simulation is especially valuable, showing exactly what will be affected before changes are made, reducing human error and avoiding downtime. This not only strengthens the organization's security posture but also improves operational efficiency, saving time on troubleshooting and change management. With AlgoSec, firewall management becomes smarter, more secure, and more efficient, while giving teams confidence that every change is compliant and low-risk.
"AlgoSec Horizon Delivers Strong Cloud Visibility and Actionable Security Insights"
AlgoSec Horizon provides robust cloud visibility, automated risk detection, compliance support, and actionable insights via intuitive dashboards, which helps teams improve security and simplify operations efficiently. In my view, there's nothing negative to say about AlgoSec. AlgoSec Horizon helps close cloud visibility gaps while addressing risk management and compliance challenges. It makes it easier to spot misconfigurations, automate security checks, and prioritize risks, which supports better decision-making and a stronger security posture. Consequently, it reduces manual effort and helps teams deploy applications faster and more safely across multi-cloud environments.
C
Consultant-Cyber and Risk
"Reliable Firewall Management with Excellent Visibility"
I value AlgoSec Horizon for its outstanding visibility and control over firewall rules throughout our environment. Its automated risk analysis, rule optimization, and compliance reporting capabilities have notably strengthened our security posture and cut down operational workload. I appreciate its end-to-end visibility and centralized management of network security across complex multicloud and on-prem environments. The platform consolidates firewall analysis, application connectivity, and risk insights into a single unified view, greatly enhancing security governance and decision-making. Additionally, the initial setup was quite straightforward, following the steps provided by the team. Reporting customization and performance for very large rulebases could be improved. AlgoSec Horizon offers excellent visibility and control over firewall rules with automated risk analysis and compliance reporting, improving our security posture and reducing effort. Its end-to-end visibility unifies firewall analysis, connectivity, and risk insights, enhancing security governance and decision-making.
N
Network Security Engineer
"AlgoSec Horizon: Great Visibility, Automation, and Application-Centric Security Insights"
AlgoSec Horizon is an extremely effective solution that simplifies management across complex environments, providing excellent visibility into network security policies. One of the platform's best features is its application-centric approach—rather than only showing technical details like IP addresses and ports, Horizon helps us understand the actual business impact behind connectivity and security policies, making troubleshooting faster.
The dashboard is user-friendly and well-organized, allowing teams to quickly monitor compliance status, identify risks, and review application flows. The protective risk insights are also highly valuable, helping detect misconfigurations and overly permissive rules before they become security issues.
Another major advantage is the automation capability—AlgoSec Horizon streamlines firewall policy management and cloud security changes, reducing manual effort, minimizing human errors, and accelerating approval processes. The compliance reporting features are equally impressive, especially for organizations working with standards like PCI-DSS, HIPAA, and GDPR, as they significantly cut down preparation time.
Overall, AlgoSec Horizon is not just a firewall management solution; it's a powerful security visibility and risk management tool that helps organizations improve operational efficiency, strengthen security posture, and better align security with business applications. One area that could use more effort is the initial deployment and onboarding process, especially in large or highly complex infrastructures. Since AlgoSec Horizon performs deep traffic flow analysis and application dependency mapping, organizations need to ensure their network information and configurations are well-organized to get the best results. However, this process ultimately helps uncover hidden network dependencies and improves overall visibility.
We previously faced many challenges in monitoring network traffic. AlgoSec Horizon has simplified firewall and security policy management by providing clear visibility into network traffic, application connectivity, and risky or unused rules. After buying this solution, our team feels more confident when making changes, reducing the risk of unexpected production issues.
It has also made compliance management much easier, offering continuous monitoring and ready-to-use audit reports that save significant time during PC and SOC2 assessments. Another major benefit is the unified visibility across both cloud and on-premises environments in a single view.
"Rule Analysis and App Mapping That Speed Up Firewall Migrations"
As someone who performs ASA-to-FTD and Palo Alto migrations daily, Horizon won me over with AFA's rule analysis that happens before touching any device. It identifies which rules are actually in use, which are obsolete, and which pose risks, backed by actual traffic data. On a migration involving hundreds of legacy ASA rules, this alone saves days of manual effort in comparing rules.
FireFlow handles the change management side effectively. Each request comes with a status, an owner, and a complete audit trail, so there's no confusion later about who approved a particular NAT rule.
AppViz is the feature that transforms how we communicate with other teams. Instead of sharing spreadsheets full of IPs and ports, we can show them the actual application flow and highlight the specific policy causing a block. This eliminates most of the back-and-forth with development teams.
Other notable aspects include:
- Clean interface that avoids overwhelming menus, making it quick to access compliance status or specific rules.
- Change automation through FireFlow reduces errors like selecting the wrong object-group compared to manual changes.
- Compliance reports, particularly PCI-DSS and similar, are nearly ready to export, which is crucial during audits.
- Handles large-scale hybrid environments without performance issues.
Don't view this as just a firewall dashboard. The application mapping is truly valuable when explaining security decisions to non-technical stakeholders. However, the onboarding phase demands significant effort. This isn't so much a Horizon issue but rather the tool uncovering every undocumented device and forgotten network segment, so if your topology documentation is outdated, you'll spend initial weeks fixing collectors instead of focusing on meaningful work.
The custom reporting functionality could also be improved. While the built-in compliance templates suffice, creating custom branded reports for executive presentations takes longer than expected. A proper drag-and-drop report builder would be helpful.
The greatest benefit is achieving visibility across a hybrid infrastructure that previously lived in the heads of three different people—ours, the client's, and whoever built the original ASA rulebase years ago. Horizon consolidates everything into one place, so when a migration starts, we're not wasting the first two weeks just figuring out what's actually running.
It has also greatly reduced interactions with application owners. Previously, a 'why is my app broken' ticket meant pulling logs from three devices and guessing. Now we can reference the AppViz map and pinpoint the exact rule or path causing the issue, allowing tickets to close in minutes instead of days.
On the compliance front, it has saved extensive manual preparation before audits. Reports that once took a day to compile by hand now export within minutes.
Regarding integrations, it works seamlessly with the Cisco ASA/FTD and Palo Alto stacks we mostly handle, and the API access makes it easy to pull data into our own tracking without staying in the Horizon UI all day.
Cost-wise, it's not inexpensive, and licensing scales with device count, so for smaller organizations, it might be a tough sell upfront. But for anyone running a genuinely hybrid, multi-vendor environment, the time saved on rule cleanup and audit preparation tends to justify the expense within a few migrations.