C
Core Team Member (Cybersecurity)
"Potent Security with Intricate Setup"
I utilize Check Point WAF to protect our public-facing web app and APIs from web threats like SQL injection and cross-domain issues. The solution provides advanced threat prevention and automated policy cleaning. I value the traffic inspection and reverse migration capabilities that ensure application uptime and security compliance, with support for both community and hybrid environments. We integrate it with our broader security setup, improving monitoring and threat detection visibility. Cloud integration has eased development, offering better visibility into application networks and stronger protection against top vulnerabilities. Despite its robust security and configuration options, some areas need improvement. The initial policy tuning can be complex for new admins, requiring a solid grasp of web traffic patterns. The interface could be more user-friendly, and reporting and dashboard customization could offer better insights. Licensing may also be challenging for smaller organizations, I think. Faster deployment templates for cloud-native apps would simplify implementation. I use Check Point WAF to protect our web app and APIs from threats like SQL injection and ensure compliance. It provides advanced threat prevention, automated policy cleaning, and hybrid environment support, though initial setup demands expertise.
"Simple and Secure Firewall Solution"
I find Check Point WAF extremely easy to use. Even those new to firewalls can manage it effectively with some guidance on its GUI. Setup is straightforward; you can have it running in five to ten minutes using the interface, which is user-friendly for beginners. Having tried many firewalls, I think Check Point's interface is good but could see minor improvements. Compared to Fortinet, their GUI is slightly better. That's the only area I'd highlight for improvement, as Check Point offers superior features when compared to Palo Alto and FortiGate. I use Check Point WAF to safeguard our environment from vulnerabilities, performing effective URL and application-level filtering.
"Excellent ML Protection, but Pricing, Setup, and Docs Fall Short"
It can easily tell apart attacks from legitimate traffic without requiring much manual rule creation or policy setup. Machine learning and AI are used for protection, preventing most attacks effectively. I'm not fond of the pricing or the complicated initial setup. Log retention is restricted, making troubleshooting more difficult, and the documentation lacks real-world examples. Customization is also limited compared to traditional firewalls. Being cloud-based, it depends on ISP reachability and connectivity. It blocks SQL injection and XSS attacks that often go unnoticed, and it reduces false positives, easing the workload for the network security team. It also helps stop automated botnets, overall strengthening our network security.
C
Cyber Security Trainee Network Security Trainee Self Learning – Cyber & Network Security
"Robust Protection with Onboarding Enhancements Needed"
I rely on Check Point WAF to defend web applications and APIs against a variety of cyber threats, including SQL injection and XSS. What I appreciate most is its strong, automated protection that remains easy to manage daily. The platform effectively detects and blocks harmful traffic. The initial setup was fairly simple, thanks to available documentation and guided configuration options. It offers solid defense against modern threats and good visibility via a centralized management interface. The onboarding and policy tuning process poses a challenge, though. For complex or highly customized web apps, balancing strong security with minimal false positives may require extra time and expertise. I use Check Point WAF to protect web apps and APIs from threats like SQL injection and XSS. It provides strong, automated protection while being easy to manage day-to-day. It effectively identifies and blocks malicious traffic, solving security issues by guarding against both common and complex attacks.
"Excellent Web Traffic Insight, but Challenging to Learn"
The best aspect of Check Point WAF is its transparent visibility into web traffic and blocked requests. It simplifies identifying suspicious activity and refining security policies. Once set up, it delivers reliable protection with little daily effort. The main downside is the learning curve, especially for beginners. The interface can feel cluttered, and fine-tuning policies to minimize false positives takes time. Some configuration tasks could be more straightforward. This WAF helps protect our web apps from common attacks while reducing the need for constant manual monitoring. It gives us greater clarity on suspicious traffic, enabling quicker responses and more efficient security management.
M
Machine Learning & Software Engineer
"Reliable Protection and Simple Web Security Management"
I appreciate that Check Point WAF is user-friendly and offers solid protection without demanding constant manual intervention. It effectively blocks common web attacks and provides clear insights into ongoing activities. The managed rules are handy, and we still have the flexibility to adjust things when necessary. A downside is that setup and tuning can sometimes be a bit tricky, particularly at the beginning. Some alerts or rules require extra scrutiny to avoid false positives, and understanding why certain actions were blocked can take time. The interface is decent, but certain parts could be simpler and more intuitive. Check Point WAF addresses the issue of defending web applications against common threats like malicious bots, injection attempts, and other unwanted traffic. It blocks many threats before they reach the app, so we don't have to inspect everything manually. It also offers better visibility into incoming requests and blocked items. The benefit is that security management becomes easier and time is saved for the team.
C
Cybersecurity Home Lab & Security Projects
"Powerful, User-Friendly Web App Security with Smart Automation"
Check Point WAF offers robust defense against web app attacks while being simple to deploy and manage. The automated policy generation, AI-driven threat detection, and low false positive rate cut down administrative work without sacrificing security. I also value its cloud environment support, API protection, and centralized management, making it a dependable choice for modern web apps. One area for improvement is making the platform more intuitive for new users, especially when setting up advanced security policies. Still, the existing documentation and automation features ease the learning curve, and overall, the solution delivers strong security and flexibility. This WAF addresses the challenge of protecting web apps from threats while minimizing the effort needed to monitor and manage protective rules. The automated threat detection, clear traffic visibility, and ability to spot and stop malicious activity are major benefits. It boosts my confidence that applications are well-protected and makes security management more streamlined.
"Effective WAF Protection With a Steep Learning Curve"
The contextual AI engine is the highlight, detecting threats without constant signature updates. It has significantly lowered false positives compared to our previous signature-based WAF, saving us time on rule tuning and reducing noise. Deploying across cloud environments was simple, and the automatic learning of app behavior means new applications are protected without extensive manual setup. The unified Infinity portal is another significant advantage, allowing us to view everything in one place. However, initial setup and configuration were more complex than anticipated, and mastering rule tuning to minimize false positives took time. Documentation could be more detailed in spots, and support response times weren't always prompt during urgent situations. Pricing is also on the higher end relative to alternatives, especially with increased traffic. Better dashboards and more intuitive policy management would be beneficial. We rely on Check Point WAF to secure our web apps and APIs from threats like SQL injection, XSS, and bot traffic. Previously, we had to manually manage security rules and keep up with emerging attacks. Now, we enjoy more consistent protection across cloud environments and spend less time on alert triage. The automated threat detection allows us to prioritize other tasks while trusting that our applications are well-protected.
"Difficult Setup, Yet Robust Security Features"
In my view, Check Point WAF is quite basic but fulfills its role well in safeguarding the company. It's definitely useful when an employee clicks on a questionable link, like stopping phishing attempts. I value that it records everything so the SOC team remains informed. My favorite feature is managing firewall policies and reviewing logs through the smart console. I frequently analyze logs to investigate problems and confirm security alerts. Additionally, I leverage threat prevention features such as IPS and antivirus to grasp patterns and adjust rules. The setup is quite complicated and time-consuming. It's also costly, and performance suffers somewhat, increasing latency and reducing throughput, so proper sizing and tuning are essential. I hope the Check Point team can streamline the process. I utilize Check Point WAF to safeguard my organization, identify endpoint activities, and avert security breaches. It logs all events, keeping our SOC team alert to potential phishing threats and ensuring we avoid dangerous links.
"Robust Security, Unified Visibility, and Smooth Check Point Integration"
The standout feature of Check Point WAF is its excellent mix of security, visibility, and user-friendly administration. It shields web applications from typical threats while offering security teams a centralized view and control. Its smooth integration with the rest of the Check Point ecosystem is another plus, streamlining monitoring and policy management for existing users. The downside is that configuration and management can be somewhat daunting, especially for newcomers. Developing precise security policies and rules may demand time and know-how, and the price point might be steep for smaller businesses. The UI and documentation could be more straightforward in certain areas, easing troubleshooting and daily tasks. This WAF has been instrumental in defending our web apps and APIs against SQL injection, XSS, and other malicious traffic. It lowers the chance of application-level breaches while providing insight into traffic and security occurrences. Consequently, our security posture has improved, less manual monitoring is needed, and our team feels more assured that our public-facing applications are protected without harming user experience.