C
CyberSecurity Administrator
"Safe, Dependable Remote Access with Quick and Simple Deployment"
Check Point SASE ensures secure and reliable remote access to your IT environment, enhancing the user experience safely. It enables full productivity with ease of use and fast implementation, especially if you're already a Check Point customer. In my experience, I recommend setting up a checkpoint environment to build a full-scale, robust service for your users, providing them a complete and secure way to access your organization's assets. A zero-trust posture that SASE provides enables a new way of working aligned with our security stance, ensuring a secure, reliable, and robust approach to remote work and productivity in my business. It also allows us to boost overall productivity across the company.
"Top-Tier Advanced Threat Prevention with a Cohesive Security Fabric"
Best overall for advanced threat prevention, zero trust architecture, global edge performance, and unified security fabric. It often creates heavy vendor lock-in, high licensing costs, and complex migration phases that disrupt daily operations. Organizations commonly dislike the gaps in "all-in-one" features, where a vendor might excel in security but fall short in network routing tools. Additionally, merging network and security operations forces teams to learn complex new cloud interfaces, leading to misconfigurations and frustration from overly restrictive login policies. Check Point SASE addresses the performance and complexity issues of traditional networks by replacing slow, centralized VPNs with a fast global cloud network that accelerates user connection speeds by up to 10 times. It eliminates fragmented security tools by consolidating firewalls, web filtering, and Zero Trust access into a single, unified dashboard, reducing operational costs by up to 60%. Finally, it stops cyberattacks by limiting remote user access to a strict, application-by-application basis, preventing lateral movement while automatically blocking zero-day phishing and malware at the edge.
M
Mid-Market (51-1000 emp.)
"Robust SASE Security but Complicated Installation"
This solution delivers strong centralized security and access control for remote users and hybrid environments. I especially value the unified approach to secure connectivity, which simplifies managing VPN, web access, and policy enforcement from one platform. It enhances visibility into user traffic and reduces security risks without adding excessive operational complexity once it's set up correctly. While Check Point SASE offers powerful security features, there are areas for improvement. The initial setup and onboarding process can be complicated, especially for teams unfamiliar with the platform. The admin interface can feel crowded, with many features dispersed across different menus, slowing navigation. Troubleshooting connectivity or policy issues isn't always straightforward and may require support assistance. Documentation could also be simpler and clearer for faster adoption. In our environment, we struggled with secure remote access and consistent policy enforcement across distributed users and devices. Managing VPN access and ensuring secure connectivity for remote employees was becoming increasingly complex and time-consuming for IT. With Check Point SASE, we can now centralize access control and security policies for users connecting from anywhere. This has improved visibility into network traffic and reduced the need for manual intervention when addressing connectivity or security issues. Consequently, we've improved operational efficiency, cut troubleshooting time for remote access problems, and strengthened our security posture for remote and hybrid users.
"Secure, Policy-Driven Access with Central Oversight in Check Point SASE"
The best part of Check Point SASE is its ability to deliver secure, policy-driven access while maintaining centralized visibility and control. From an OT security viewpoint, the blend of Zero Trust access, advanced threat prevention, and simplified management supports secure connections for remote users and sites without sacrificing security or operational reliability. One aspect that could be better is the learning curve and administrative complexity relative to some cloud-native SASE alternatives. Initial policy setup and integration across various security services may require more expertise, especially in large enterprise settings. Also, some may find the licensing structure and overall cost higher than other options, particularly for smaller deployments. However, these drawbacks are often overshadowed by its robust security features and comprehensive capabilities. For me, the main benefit is simplified security management and improved risk reduction. It enables secure remote access, enhances threat protection, reduces operational complexity, and aids compliance while offering a better user experience. From an OT/critical infrastructure standpoint, it also supports secure third-party and remote access without unnecessarily exposing critical assets.
N
Network Security Engineer
"Integrated Security and Networking via Check Point SASE"
I value how Check Point SASE consolidates networking and security into a single cloud-delivered service, which is essential for today's hybrid work environments where users connect from many places. It resolves the issue of managing fragmented security tools by bringing together VPN, firewall, CASB, and SD-WAN in one platform. I particularly like the Zero Trust Network Access feature, as it verifies every connection based on user identity, device posture, and application context, offering strong protection against insider threats and compromised accounts. Cloud-native scalability is another standout, making it simple to add users or extend protection to new applications without major infrastructure changes. Additionally, Check Point SASE integrates well with identity and access management platforms like Azure AD, Okta, and Ping Identity, ensuring strong authentication before access is granted. The initial setup can be complex for smaller IT teams without prior Check Point expertise. Check Point SASE combines networking and security elements like VPN, firewall, CASB, and SD-WAN into one platform, simplifying management. Its zero trust network access enhances security by verifying connections, and its cloud-native scalability permits easy addition of users and applications without major infrastructure changes.
S
Senior Site Reliability Engineer
"Speedy Worldwide Connectivity with Some Room for Enhancement"
Check Point SASE offers fast global connectivity and a user-friendly, single-pane dashboard. The direct routing through worldwide cloud points of presence minimizes VPN latency, boosting efficiency. I value the centralized visibility that simplifies management and enables admins to enforce zero trust policies effectively. However, I find setting granular policies and dealing with log latency challenging in Check Point SASE. While initial setup was easy, tailoring configuration to our specific needs proved somewhat difficult. Check Point SASE delivers low latency and zero trust access for remote use. I appreciate the fast global connectivity managed through a single, intuitive dashboard that offers centralized visibility, streamlining management and supporting zero trust policy enforcement.
"Strong Zero Trust Security with Straightforward Central Management"
I'm most impressed by how Check Point SASE unifies networking and security into one platform, greatly simplifying secure connections for remote users, branch offices, and cloud applications without needing multiple disparate products. Centralized management is another plus, as it simplifies policy enforcement and provides comprehensive visibility into the environment. The Zero Trust approach, secure web gateway, and cloud-based security enhance protection while maintaining good user performance. In essence, it boosts operational ease, security, and support for a modern, hybrid workforce. One challenge I've noticed is that implementation and policy creation aren't always straightforward, particularly for organizations new to SASE or Zero Trust. Some advanced features require a learning curve before administrators can use them effectively. Troubleshooting connectivity or policy issues can also be time-consuming due to the multiple security layers. Pricing may be a concern for smaller organizations, especially when needing additional licenses or advanced features. Overall, while powerful and feature-rich, the platform demands planning, training, and ongoing management to maximize value. Check Point SASE has addressed several business challenges for us, including secure remote access, cloud application security, and centralized policy management. We've replaced a range of separate security tools with a single platform, reducing complexity and enhancing visibility. It has reinforced our Zero Trust posture by continuously authenticating users and devices. Consequently, we've improved security for remote and hybrid workers, simplified administration, lowered cyber risk, and provided a consistent user experience with reliable access to business applications.
"Difficult Setup, Disjointed Features, and Cost Issues with Check Point SASE"
The most appealing aspect of Check Point SASE is its integration of network security and secure remote access within a single cloud platform. This ensures consistent security policies across users, devices, and locations without relying heavily on traditional perimeter-based infrastructure, which is crucial for hybrid and distributed work settings. The robust integration of security features such as secure web gateway, zero trust access, threat prevention, and SD-WAN is also commendable. Centralizing these functions improves visibility and simplifies management compared to using multiple standalone security tools. Performance and scalability are additional strengths, enabling users to securely access applications with a smoother experience while maintaining strong threat protection. Overall, it enhances security posture and operational efficiency in modern cloud environments. However, a key drawback is the operational complexity from deployment through policy configuration; the software can be difficult to understand and use daily. Performance can be inconsistent, with issues like latency, unreliable connections, or slower application access due to multiple security layers. Some features feel fragmented, indicating poor integration, which complicates troubleshooting. Furthermore, the cost could be a disadvantage, as licensing and advanced features may incur additional expenses. The reporting and analytics capabilities are also sometimes lacking. Check Point SASE addresses the challenge of securely connecting remote users, cloud applications, and distributed environments without a traditional perimeter. With the shift to hybrid work and cloud computing, managing security with various VPNs, firewalls, and point solutions becomes cumbersome. This solution has benefited us by enhancing visibility and enforcing uniform security policies, enabling secure remote access while reducing the burden of managing separate systems.
"Check Point Harmony SASE: Excellent Local Endpoint Performance"
From an engineering standpoint, the decentralized security model is notable because it provides the security enforcement of a cloud web gateway while also achieving low latency by running a lightweight, granular filtering engine directly on the endpoint. This local processing reduces bandwidth consumption. However, integration with complex on-premises routing that doesn't use BGP is painful, and there are delays in log updates. When a remote user reports a blocked critical application, getting real-time, detailed logs to identify which security layer (ZTNA, CASB, or URL filtering) caused the block can involve noticeable sync lag. Overall, responsiveness, per-user pricing, and feature access remain areas of concern. The vulnerabilities in legacy VPNs, gaps in SaaS and shadow IT visibility, and latency problems were significant pain points for me. This solution helps contain incident blast radius and provides genuine zero trust network access.
"Comprehensive SASE Platform for Contemporary Businesses"
Check Point SASE is appealing because it merges network functions with security into a unified solution, eliminating the need to juggle multiple tools like VPNs, SD-WAN, ZTNA, SWG, and Firewall-as-a-Service. Everything is accessible from a single console, simplifying management and offering full visibility into operations. This approach enhances user safety regardless of location, with centralized control that helps prevent security incidents. As a result, my workload is significantly reduced while maintaining smooth and secure operations. One area that could be improved is the ease of policy setup and configuration, particularly for organizations transitioning from legacy network security setups. Advanced features have a learning curve, and troubleshooting can be challenging due to the integrated security components. For businesses with only networking needs, the solution might be more comprehensive than necessary. We previously relied on traditional VPNs and various security tools, but now Check Point SASE consolidates everything into one platform, providing zero trust access, web security, and optimized network performance from the cloud. This has enhanced our security posture, simplified administration, and delivered a consistent user experience. Policy management has become more straightforward, offering better insights into user activity and ensuring protection for both cloud and on-premise resources.