Skip to content
Notifications
Clear all

Top firewall for a mid-market manufacturing company with 200 employees

2 Posts
2 Users
0 Reactions
12 Views
(@johndoe82)
Trusted Member
Joined: 3 months ago
Posts: 45
Topic starter   [#13144]

Hey folks, I've been deep in the trenches of a network refresh project for a mid-market manufacturing client (around 200 employees, two sites, a mix of corporate offices, a plant floor with some legacy OT-ish gear, and a growing Azure footprint). We evaluated several next-gen firewall suites over the last few months, and I wanted to share a detailed, hands-on review of Check Point Quantum specifically for this use case.

**Why Check Point Quantum was a strong contender:**
The core appeal was the single, unified management pane (SmartConsole) for everything. We're managing firewalls, site-to-site VPNs (to Azure and to the other plant), and a fairly granular application control policy from one place. For a team with limited dedicated security staff, this consolidation is a huge win. The "Quantum" branding essentially refers to their NGFW platform, and we looked at the 1600 and 3600 appliance models.

**Key strengths we observed:**
* **Granular Security Policies:** Going beyond ports/IPs to application and user-based rules was a project requirement. The policy layer is intuitive once you get the hang of it. We could easily create a rule like: "Allow 'Engineering' group to use 'GitLab' application over HTTPS, but block file uploads to personal cloud storage categories," all in one rule.
* **Centralized Management (SmartConsole):** Managing both firewalls from a single console simplifies life immensely. Pushing policy updates is straightforward.
* **Threat Prevention:** The IPS and antivirus blades are solid. We tested them in a lab with some curated malware samples and C2 traffic, and the catch rate was impressive. The threat hunting and forensics tools in the dashboard are detailed.
* **VPN Reliability:** The site-to-site VPN setup, especially with Azure, was more stable than some competitor solutions we tested. The Mobile Access VPN (for remote engineers) also worked well.

**Configuration Snippet & Gotchas:**
Here's a taste of what a simple application/URL filtering rule looks like in the command line (though we used the GUI 90% of the time). This shows the object-oriented nature of the policy.

```bash
# Creating an application-based rule via CLI (simplified)
add application-site name "Blocked_Cloud_Storage" application-list "Dropbox" "Google-Drive"
add access-rule layer "Network_Policy" position top name "Block_Personal_Storage"
source.negate false source any
destination.negate false destination any
service.negate false service any
application.negate false application "Blocked_Cloud_Storage"
action drop
```

**Pitfalls & Considerations:**
* **Licensing Complexity:** This is the biggest headache. You don't just buy a box. It's a subscription model for software blades (IPS, AV, URL Filtering, etc.). You need to carefully map which blades you need per box. Costs can add up.
* **Initial Learning Curve:** The concepts of "Layers" in the Security Policy and the object database can be confusing for those coming from simpler firewalls. It took us a week or so to feel proficient.
* **Hardware vs. Virtual:** We went with physical appliances (Quantum 3600s) for the main choke points, but their virtual (VE) offering on Azure worked well for our cloud spoke. Just watch the licensing there too.
* **Support Experience:** Our experience was mixed. Some T1 support calls were slow, but once we got to T2/T3, the engineers were excellent.

**Verdict for a 200-person manufacturing co.:**
Check Point Quantum is a powerful, enterprise-grade platform that can absolutely serve a mid-market company well, **if** you have someone (internal or a good MSP) to design and manage it. The centralized management is a major advantage for multi-site setups. The licensing cost and complexity are the main hurdles—ensure you get a clear quote that includes all the software blades you'll need for 3-5 years.

For us, the granular control, single pane of glass, and robust security features outweighed the licensing pain. We ultimately deployed it, and it's been running solidly for 4 months now. Happy to answer specific questions about our rollout or configuration.

—John


Keep it simple.


   
Quote
(@emilyk4)
Reputable Member
Joined: 3 months ago
Posts: 216
 

That's a really interesting point about the unified management for a smaller team. In my previous role, we had separate tools for everything, and just keeping track of what policy was where became a full-time job itself.

When you mention "application and user-based rules" being intuitive, did you find the learning curve for setting those up was steep? I get nervous when a tool's power comes from a complex setup that might be beyond our current team's bandwidth.



   
ReplyQuote