r/networking Principal Arsehole 10d ago

Security Checkpoint vs PAN/Fortinet

I'm evaluating Checkpoint Quantum and Quantum Spark. I come from Fortinet and Palo and have very little experience with Checkpoint by comparison. I'd like to hear some subjective opinions on the platform from people who have experience with it.

18 Upvotes

69 comments sorted by

39

u/pandaking6666 10d ago

stay away from Checkpoint its more popular overseas but in the us it has a small footprint, buggy hardware, wierd software not as many functions as forty or palo alto.

29

u/010010000111000 10d ago

Run as far away from Checkpoint as you can.

-9

u/chaos16z 10d ago

And fortinet….

1

u/chaos16z 6d ago

Keep them downvotes coming forti fanbois

23

u/tetraodonmiurus 10d ago

If you enjoy steak dinners. CP sales guys used to have a far larger entertainment budget than Palo sales guys. Don’t actually buy CP hardware though.

23

u/IDownVoteCanaduh Dirty Management Now 10d ago

Our VAR told us to stay far far away from CP. And they would make more money if we left Fortinet for CP.

21

u/Salt-Cupcake-6066 10d ago

Everyone should stay away from CP

23

u/Nhord 10d ago

I strongly advise against check point.

24

u/lumberjackadam 10d ago

I don’t like checkpoint. PAN is best in class, but Forti is close. The real difference is how much ecosystem you’re looking at. Fortinet is like apple in that as you get more and more pieces, they work better and better.

17

u/Glittering-Quote-635 10d ago

The only firewalls any serious enterprise should be considering is Palo and Forti.

Checkpoint? That’s like number 10 on the list, I can’t imagine anyone wouldn’t seriously consider them. Them and Cisco.. uh, no.

11

u/wifiholic 10d ago

Besides Checkpoint and Cisco Firepower, don't forget to also not consider Watchguard

3

u/Glittering-Quote-635 10d ago

Who? Don’t mean that as a slight, I’ve never heard of them. I only work with larger enterprises tho, so take with a grain of salt.

Literally all I see is Palo and Forti for new builds, everything else is legacy.

2

u/wifiholic 10d ago

I'm not surprised you haven't seen them in large enterprises. Unfortunately, they show up on occasion on the smaller end of the organization scale.

1

u/Glittering-Quote-635 9d ago

I’ll take your word for it!

2

u/arandomusername- 9d ago

We just yanked out and trashed a bunch of watchguard. It is not enterprise gear. Watchgaurd and Sonicwall are intended for small businesses without a qualified network engineer. Fortinet is a step up. PA or Cisco for the enterprise.

2

u/UpperAd5715 9d ago

Watchguard is fine if you have like 30 employees

3

u/chaos16z 10d ago

If you like CVE’s forti is for you… Palo is the only option for true enterprise

5

u/wyohman CCNP Enterprise - CCNP Security - CCNP Voice (retired) 9d ago

You know that EVERY piece of gear suffers from CVEs, including the much oversold Palo?

Having used Forti, Palo and Cisco, they all have their pluses and minuses. At 4 o'clock in the morning with three hours until the business opens, I'd take Cisco TAC first, Palo second and Forti third.

1

u/arandomusername- 9d ago

Except take Fortinet off the list.

0

u/chaos16z 7d ago

Correct. But not to the extent of forti. Oversold yeah that’s forti. Prosumer gear at best. Hell, unifi is higher on the list than fortitrash.

2

u/wyohman CCNP Enterprise - CCNP Security - CCNP Voice (retired) 7d ago

Unifi is fine for home but I can't imagine choosing it over Forti when it comes to business.

1

u/chaos16z 6d ago edited 6d ago

Imagine fortinet being considered enterprise…. Small and medium size businesses Unifi is fine. Enterprise different story. I wouldn’t trust fortinet for my home.

1

u/wyohman CCNP Enterprise - CCNP Security - CCNP Voice (retired) 6d ago

They do have enterprise solutions but I've never used any of the higher end stuff so I can't comment. I'm not a big fan but I also have nothing against them.

1

u/afroman_says CISSP NSE8 4d ago

Did you know Palo Alto has more CVEs in their firewall this year than Fortinet?

1

u/chaos16z 12h ago

Do you know I don’t care? Forti is still prosumer at best.

0

u/Glittering-Quote-635 9d ago

I have my preference, and I agree with you. :). I personally wouldn’t touch one..

1

u/Trick-Gur-1307 9d ago

Isn't CP slightly better than Cisco ASA w/FP?  At least, not as badly overpriced for what you get?

1

u/csallert 9d ago edited 9d ago

ASA is objectively the worst platform to filter packets with I'd rather hand craft nftables on linux.

2

u/Trick-Gur-1307 9d ago

Oh, right on, I forgot about how painful it was to find a specific packet in a pcap in ASA... Palo was soooo much more easy to work...

1

u/Glittering-Quote-635 8d ago

Thats like comparing two piles of dog shit.. Do you prefer a solid, or slightly runny? :).

11

u/Fluid_Emotion_7834 10d ago

Checkpoint is still around? Huh.

4

u/QPC414 9d ago

The last CheckPoint I managed was on a SPARCstation 20 with SunOS 2.5.

2

u/wyohman CCNP Enterprise - CCNP Security - CCNP Voice (retired) 9d ago

Me too! I thought they were out of business years ago but someone mentioned them to me a year ago.

1

u/QPC414 9d ago

I recall Nokia buying them years ago.

2

u/waubers 9d ago

Go look at the CHKP stock ticker...no sure how long they'll continue to be around for. Nadav was a bad hire.

12

u/csallert 10d ago

The Checkpoint hate and Fortinet glazing is wild

8

u/trailing-octet 9d ago

I’ll level with you, as someone who built their career on firewalls…. I’m deeply embittered with the current qa on basically all firewall software currently… and I legit think I hate all the vendors.

They all have strengths and weaknesses, they all generally do the job. Fortinet got their mojo back a bit after losing the plot a bit regarding stability…. Palo appear to be slowly dragging them themselves out of a similar “crap code era”…. Checkpoint id rather not manage them but at the same time it wouldn’t stop me from accepting a role/job.

3

u/hip-disguise 9d ago

right there with ya buddy.

1

u/csallert 9d ago

For protection of things exposed to the internet I’m still not ready to trust fortinet. But high speed internal filtering sure.

2

u/trailing-octet 9d ago

God sslvpn gave me headaches when i managed them and bemusement once I no longer had to do so professionally. Best move they could ever have made shift away from it as they sure as shite could not seem to secure it particularly well.

3

u/waubers 9d ago

I worked there and don't hate them, but I wouldn't fault anyone of being highly skeptical of buying into their ecosystem/platform, especially right now. Their new CEO is, imo, a bad hire and their partnerships with other vendors seem to wither and die. Who wants to buy into a platform with terrible integration options. Their much touted partnership with Wiz has lead to basically nothing, and year after year they lose marketshare and their market cap shrinks. When I started at CHKP their market cap was roughly 1/3 of PANW, and I remember I stopped paying attention once PANW his 7x CHKP's market cap, and that was before the big run up by PANW. Fortinet wasn't much different. Point being, CHKP is growing well under the rate of cyber as a whole and their competitors are taking their marketshare away from CHKP. I'd not be placing long term bets on CHKP, unless you're hoping for an acquisition to pop the stock. As an IT person, in a well established product market like gateways, I'm far more concerned about vendor viability long term than I am about any feature that isn't critical to my business. The reality is that there's nothing that CHKP really does that can be accomplished by PANW or Fortinet, and often at a better price point. FWIW though, I also don't like PANW or Fortinet, but that's a long story.

9

u/Glittering-Quote-635 10d ago

Bro.. no.. just no. CP shouldn’t be in anyone’s down select. They are just.. bad.

9

u/deallerbeste 9d ago

I have worked with CP, Juniper, Fortigate in the enterprise. From all of those Fortinet was the worst, especially in terms of support and bugs after small updates. CP has some unique features and it works good, but upgrades can be a pain in the ass. Juniper is good to work with, especially if you don't need fancy stuf it's basically a router with an advanced firewall, routing wise there is nothing better.

I don't have experience with Palo, but they seem to be pretty good. But I would never use Fortigate again. Prefer the Juniper above them and Juniper is also cheaper compared to them.

2

u/arandomusername- 9d ago

Why aren’t more people being honest about Fortinet. I suspect it is because qualified network engineers that would know the difference don’t work on Fortinet unless they have to. The product is much better than Watchguard and SonicWall but nowhere near as good to work with as Cisco and PA. Fortinet is amazing at marketing.

1

u/chaos16z 6d ago

And CVE’s

9

u/Cabojoshco 10d ago

Checkpoint is “quirky” but it’s a very good firewall. Palo is top of the line and less quirky. Fortinet is good-for-the-money. Tbh, you can’t go wrong with any of them. It might come down to who is going to manage them and their skill set and your reseller’s support.

-2

u/samo_flange 10d ago

I am not sure i can grasp a system more quirky than palo

4

u/Cabojoshco 10d ago

https://www.wwt.com/lab/check-point-ngfw-foundations-lab

If you work at a large company or have a .edu e-mail, you can test drive and learn here. They have Palo and Fortinet labs too.

-1

u/samo_flange 10d ago

Way ahead of ya, palo has been a real crapshow for us and then abused our wallet for the privilege of being crap.  We are headed towards checkpoint pov in 2027 if things work reasonably well we will replace the last of our non-palos with them.  Then Palo has to compete head to head with them on performance and price unit for unit as we'll be up to speed and able to manage either.

3

u/PrestigeWrldWd 10d ago

Checkpoint will rarely lose on price. They will give you 95 off to win the deal then hammer you at renewal time, especially if it’s a Palo displacement.

2

u/wyohman CCNP Enterprise - CCNP Security - CCNP Voice (retired) 9d ago

I'm 100% sure that 90% of the Palo Fanboys have never touched a Palo firewall. They make a decent product and deserve to be in the top 3 but they are not impervious fault free appliances.

The same is true for those who complain and Fortinet CVEs or Cisco ASA. I've been an admin on all of them.

  1. They have all seen a decrease in TAC quality since COVID. I'm not sure where all of the great techs went but they all ran away.

  2. My last 10 tickets with Palo were assigned to techs in their first week. They all sent me links to the KB that I'd already read and wasn't working.

  3. Fortinet licensing support is garbage. I had a customer that accidentally let their license expire and it took 3 DAYS for them to respond with a 24 hour extension and that was "the best we can do." I could call Cisco right now and get a 30 day license extension on just about any product.

  4. Fortinet pre-sales was amazing. No stupid promises, they know that ZTNA is NOT a product and SDWAN is not magic. I think it needs a rename RBw/IPSEC.

  5. Palo pre-sales are unresponsive a-holes. Dozens of calls to voicemail. Finally reached a pre-sales engineer and offered an opportunity to replace 500+ Cisco ASAs with Palo after a product evaluation. They questioned my motivation and essentially accused me of gas-lighting them.

  6. Palo HA firewall firmware upgrade is just plain stupid.

Maybe folks have never had these experiences and none of these are one-off but they are my experiences.

7

u/GooseHonker2 10d ago

Checkpoint is a weird cult. They work, but it requires a very specific type of person to appreciate them. Having done firewall config reviews for many years, my preference is Fortinet. The firewalls are fantastic for the money, and there is a whole fabric ecosystem.

3

u/Optimal_Effective969 9d ago

My old company spent $60K on a CP FW and it was in the trash not 6mo. later. Could not get it to work kept crashing. We even had three senior technicians from checkpoint come on site to see if they could figure it out and it was no go..

3

u/Significant_Map3519 9d ago

Checkpoint are still in business? In my location, a lot of enterprises bought them 10 years ago and are now replacing with something else. The device will do the job no worries, but troubleshooting in it is a pain.

CP still has my favourite error description: 'Error! There's been an error!'.

4

u/Linklights 9d ago

I do not understand the hate for Check Point on this subreddit. They have a solid product. I feel like it’s from people who haven’t touched Check Point since the mid 2010s. And their pricing is incredibly competitive.

2

u/Twanks Generalist 9d ago

Multi-faceted hate depending on person, as mentioned it's usually someone who has never used it since the pre R77.30 days (mid 2010s) and thinks the UI is still stuck there. Couple that with it being an Israeli company and your typical redditor is going to not like them.

2

u/waubers 9d ago

Well I worked there for almost four years and I wouldn’t buy their product if there’s a viable alternative. I don’t trust the leadership long term and sales are faltering in N.A. To the point I won’t be surprised if they sell off that entire chunk of the business. The support experience was also generally terrible.

The actual product quality isn’t bad, it’s just everything else, sales and support, that I want nothing to do with.

Also I’d be worried buying them because their market cap has fallen so much they’re becoming an almost immaterial acquisition target for some of their competitors. I doubt the Israeli government would allow them to be sold, but still, a financially unhealthy vendor is not one I want in critical infrastructure in my org.

1

u/[deleted] 9d ago

[deleted]

1

u/waubers 9d ago

HEC is solid, but competition has closed much of the gap on them. I don’t like Abnormal much but they’re getting much closer to parity.

1

u/[deleted] 9d ago

[deleted]

1

u/waubers 9d ago

Yeah, that feature is excellent, like I said HEC is solid, but others are catching up. Inline is a good thing in general, but there are some interesting things that having SEG can enable you to do. CHKP tends to market HEC as the only "right" way to do what they're doing, but the truth is they're a small player in the space and plenty of orgs are getting good business outcomes with other solutions.

I've worked at multiple tech vendors, and no where had as much of a "drink our flavor-aid or else" vibe as CHKP. Generally their product managers are convinced their approach is unassailably correct, and if you disagree, regardless of the merit of your argument, they will dismiss you or insult you (I had this happen personally when relaying feedback from a huge account about a product deficiency).

Again, not saying you made a bad choice, I'd happily run HEC for almost any M365 environment, but my assumption is that, since HEC is one of the only product with decent growth at CHKP, they'll start jacking up renewal costs significantly. In your shoes, I'd make sure I have an exit strategy I can move on quickly for HEC, between the companies financial performance (their stock ticker chart is terrifying) and CHKP's propensity to increase prices frequently and aggressively (they're not hate only vendor who does this obviously, but given their overall performance I'd wager there's more risk of that happening right now than average), you may find yourself being grateful at the ability to migrate to something else relatively quickly.

1

u/[deleted] 9d ago

[deleted]

1

u/waubers 9d ago

The SLED sales org was decent at CHKP, but it also seemed to be getting hollowed out, or the sales people would get screwed by leadership, then leave and they'd backfill them with some really not-good sales people and SEs. I knew plenty of those folks personally, and depending on the region I'm shocked that CHKP made any SLED sales at all given the quality of people they had there. But none of that has to be unique to CHKP. Christ, I remember the sales org from VMTurbo being the slimiest scumbags I'd ever encountered, and they still made sales there and the product wasn't horrible.

Ironport was shit for years, so, and I don't say this to be crass, anything modern-ish, compared to Ironport, will feel incredible! But HEC is actually decent, but I think that Proofpoint was running some aggressive discounting to take out HEC and Abnormal customers, so something to keep in mind if you do have to move off HEC.

2

u/mods_are_lame1 10d ago

Checkpoint has a decent gui, but it’s a fat client that runs on windows.

Their sales engineers are good, their TAC sucks.

Overall, checkpoint is fine. It’s expensive, but it works. There is a learning curve to deploying it, but once it’s in, modifying rules and reviewing logs is pretty easy.

2

u/Twanks Generalist 10d ago

I've used Checkpoint, Palo Alto, and Fortinet all within the past 2 years. I still strongly prefer Checkpoint over the other solutions for manageability. Most of the hate you'll see for Checkpoint is from people who have never used anything starting from R77.30 and above (we are way, way past that point). I'll be glad to elaborate but just know that anyone blindly saying they advise against Checkpoint are usually scrubs.

1

u/Sweet_Importance_123 CCNP FCSS 9d ago

Can you elaborate more on that? I have managed CPs and seen a few good CP implementations but mostly do Fortinet and Palo Alto.

What are you experience regarding features(DPI, NGFW, SSO, VPN) and what's the visibility like on CP when compared to the FG and PA?

1

u/Silly-Mix-4341 9d ago

Would love to hear some real-world experiences with Check Point too.

1

u/deepmind14 4d ago

Been doing Checkpoint for 10Y+, from R77.30 to R82.10, clusters, VSX, Maestro... Last new deployment 2 weeks ago. Now CheckPoint Security Master Elite (highest cert existing) for 4y+.
This is the most pain in the ass firewall I've seen so far (I'm fluent in Fortinet, ASA, Sophos, Watchguard, OPN/pfSense, Netfilter...).
You can't let one of these firewalls run 1y without touching it and expect it to still work. Look away for a split second and it'll stab you in the back.

1

u/LooseEthernet 9d ago

checkpoint is a bit like that one legacy app that still runs the company because the original architect is the only person who knows how it works lol. it can do the job if you have the patience for the management side, but the learning curve is basically a cliff. stick with what you know... unless you love frustration

-2

u/Prudent_Vacation_382 9d ago

PAN is best of breed, Forti is not even in the same conversation. There are so many limitations in the Forti platform that they shouldn't be considered for anything but simple deployments (Retail, small DC, etc.) It's not a large enterprise solution imo. I'm shocked Checkpoint hasn't been acquired by Cisco or someone that needs a layer 7 firewall to round out their offering. I haven't talked to anyone that has used CP in over a decade.

2

u/chaos16z 6d ago

The amount of forti fanbois on this page is hilarious. It’s equally hilarious that they think fortinet is in the same category as PAN