Top Microsegmentation Software Insights
Top Microsegmentation Software Insights
Microsegmentation Software
Contents
Focus On Solutions . . . . . . . . . . . . . . . . . . . . . . . . . . . 7 ‐ 94
Vendor Directory . . . . . . . . . . . . . . . . . . . . . . . . . . . . 95 ‐ 97
About PeerSpot . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 98 ‐ 99
Microsegmentation
Software Recap
• Fine‐grained Policies: Enables precise access control based on roles and needs.
• Real‐time Monitoring: Provides visibility into network traffic for quick threat detection.
• Automated Responses: Implements pre‐set actions in response to suspicious activities.
• Scalability: Adapts to the growing demands of large and complex networks.
Organizations find this software category beneficial for enforcing strict security measures
without compromising network performance. It supports modern infrastructure needs,
helping businesses manage risk effectively.
Microsegmentatio
n Software
Top Solutions
VMware NSX
Illumio
Appgate SDP
Zero Networks
Focus on solutions
VMware NSX
Executive summary
VMware NSX is widely implemented across industries such as finance, healthcare, and manufacturing. Organizations
in these sectors utilize it to bolster security, enhance network efficiency, and support cloud‐native applications. By
extending on‐premise networks into provider spaces and managing virtual access networks, VMware NSX
significantly optimizes infrastructure operations.
Sample customers
Compared 19% of the time Compared 18% of the time Compared 16% of the time
Learn more Learn more Learn more
Energy/Utilities Company 8%
Manufacturing Company 8%
Manufacturing Company 9%
Government 9%
Company size
Valuable features
MagdyRaafat
Services Presales Solutions Architecture ‐ UAE & Gulf at a tech vendor with
10,001+ employees
Tomas Barcik
Senior VMware Administrator at Johnson Controls, Inc.
Verified user
Sr . IT Infrastructure Manager at a computer software company with 201‐500
employees
“I value the ability to dynamically configure our network on the fly using
VMware NSX.”
DanielBass
Senior IT Strategy Consultant at a financial services firm with 1,001‐5,000
employees
Efthymios Bliatis
Joint Staff Officer at Hellenic National Defence General Staff
“The micro-segmentation and security for the product itself and the ease of usage
from the administration point of view are the most valuable features of VMware
NSX.
“Security policies across different environments, such as private and public cloud,
are very helpful because security is crucial. When moving to the cloud, all
customers are asking for security. When you have a solid secure solution between
your on-premises and cloud solution, you are in a safe place..”
“VMware NSX has the ability to create networks in software. This feature eases life
by enabling management with one team. It's robust, stable, and easy to use, but we
don't fully utilize its capabilities..”
“I value the ability to dynamically configure our network on the fly using VMware
NSX. This flexibility is a huge advantage because it allows us to avoid static
configurations that come with traditional hardware setups.
“The most valuable features are its security aspects, especially the IPS and IDS for
intrusion detection and protection. We've found these features beneficial in
enhancing our network security..”
“Firewall security is one of VMware NSX's vital features. Using the tags and the
solution's security policy is incredibly simple. For instance, I can create a sketch
on paper and redesign it with the tags present on the network segment using
VMware NSX. .”
Pain Points
MagdyRaafat
Services Presales Solutions Architecture ‐ UAE & Gulf at a tech vendor with
10,001+ employees
Tomas Barcik
Senior VMware Administrator at Johnson Controls, Inc.
“The initial setup for VMware NSX is a bit complex; it's not as simple as it
could be.”
Verified user
Sr . IT Infrastructure Manager at a computer software company with 201‐500
employees
DanielBass
Senior IT Strategy Consultant at a financial services firm with 1,001‐5,000
employees
Efthymios Bliatis
Joint Staff Officer at Hellenic National Defence General Staff
“The licensing model has become expensive since Broadcom bought VMware,
making it costly with no other options to select specific components from the
license itself. Customers must buy the whole package even if they do not need all
components..”
“The reporting functionality could be better, and there could be an easier way of
forwarding events. There's room for improvement in the product. We don't use it
to its full capabilities and much more could be done with it. The pricing for the
product is another area for improvement as I'm not satisfied nowadays..”
“Function-wise, VMware NSX is performing well, and I don't see any major areas
for improvement since most of the functions meet my expectations.
“The initial configuration and integration within our existing environment were
not easy. The configuration process was a bit complex, specifically during the
initial setup..”
“I cannot think of something specific that needs improvement since our needs are
currently covered by VMware NSX. I have no complaints regarding the user
interface or any technical issues..”
“If you had asked when it was NSX V, which was dedicated only for Hyper-V and
VMware, I would have said they could open the door for all partners. At the
moment, NSX T is complete. Migrating from V to T is very tricky, complicated, and
there are a lot of parameters to account for. The pricing is also an issue; it's very
expensive and changes all the time. VMware is not easy to negotiate with..”
Pricing
“The product pricing ranges from medium to expensive. I rate the pricing a seven
out of ten.”
“The price is significantly high and it can be a hurdle for many potential users.”
Illumio
Executive summary
Illumio Zero Trust Segmentation is a cloud and data center security solution that helps stop
breaches from spreading across hybrid and multi cloud IT environments. The solution is
designed to stop ransomware, contain cyber attacks, and reduce risk. With Illumio Zero Trust
Segmentation, users can understand relationships and communications to map exposure risk
of systems and data, identify the right security posture and secure applications through least‐
privilege policies, and ensure a Zero Trust security posture.
Illumio Zero Trust Segmentation has many valuable key features. Some of the most useful
ones include:
• Single pane of visibility: The solution’s single pane of visibility improves your security
posture and ability to prevent and respond rapidly to cyberattacks.
• Simplicity: With Illumio Zero Trust Segmentation, setting up groups and tags is simple.
The solution is easy to integrate with next‐generation firewalls and can also integrate
with IT service management tools to import workload tags to provide more context to
workloads.
There are many benefits to implementing Illumio Zero Trust Segmentation. Some of the
biggest advantages the solution offers include:
Visibility everywhere: The Illumio Zero Trust Segmentation solution helps ensure that every
interaction on your network is accounted for.
• Proactive posture: Using the solution enables your organization to always be on the
lookout for an attack.
• Improve breach containment: With the solution, you can prevent unauthorized lateral
movement and reduce your blast radius. Creating micro‐perimeters around specific
assets breaks up your attack surface and gives you the granular control needed to
contain breaches.
Illumio Zero Trust Segmentation is a solution that stands out when compared to many of its
competitors. Some of its major advantages are that it has a good auto policy writing feature,
great mapping, and useful monitoring.
Shashi, Technical Consultant at a financial services firm, explains which features she really
likes. “The auto policy writing is great. The feature will give you the option of inbound‐
outbound traffic. The Explorer allows you to know the traffic between source and destination.
The illumination definitely stands out. Mapping is great. The application group mapping is
useful.”
The solution has “helpful support, useful monitoring, and high availability,” according to Edwin
L., Security Architect at MGM.
Sample customers
Plantronics, NTT Innovation Institute Inc.
Akamai Guardicore
VMware NSX Cisco Secure
Segmentation
Workload
Compared 41% of the time Compared 12% of the time Compared 8% of the time
Learn more Learn more Learn more
University 13%
Manufacturing Company 8%
Government 7%
Company size
Valuable features
Verified user
Technical Associate at a healthcare company with 11‐50 employees
“The strongest aspect of Illumio is the visual traffic interface, which allows
us to see all traffic that communicates with our servers and allied
companies.”
Alark Singh
Senior Technical Analyst at Allianz
Vincent TOH
Assistant Manager at KPMG S.A.
“The features that I have found most useful is the ability to centralize all the
rules and then distribute them across various locations. However, I've
encountered challenges related to tagging policies, which can be complex to
devise. It's a matter that requires careful consideration and stakeholder
involvement before implementing such policies.”
MICHEL RACT‐MUGNEROT
Personal business manager at La Mairic
Verified user
Executive Director of Cloud Networking at a financial services firm with 10,001+
employees
“The strongest aspect of Illumio is the visual traffic interface, which allows us to
see all traffic that communicates with our servers and allied companies. We can
write rules that can be embedded into the IP table, making it easy to handle.
Illumio enables us to see network flows, traffic sources, and destinations. The
policy generation and enforcement capabilities are valuable, allowing for selective
enforcement. Illumio helps in audit purposes by saving data and showing blocked
traffic, ensuring no outside traffic is allowed..”
“Visibility is the most valuable feature of the solution. The product provides
visibility into how the applications communicate and how the network protocols
are being used. We can also block protocols such as RDP, NetBIOS, and
ransomware attacks..”
“The solution helps to maintain logs and monitor activities. It also helps us with
access management. The tool helps us to secure organizational data that include
files. .”
The auto policy writing is great. The feature will give you the option of the
inbound-outbound traffic.
The Explorer allows you to know the traffic between source and destination.
We have a feature called parallel coordinates. There, we can see what application is
talking to which application and where a single application is talking to many
applications.
The illumination definitely stands out. Mapping is great. The application group
mapping is useful.
The ability to operate inside the real technology has been excellent.
Pain Points
Verified user
Technical Associate at a healthcare company with 11‐50 employees
“There should be an option to upgrade from the console to the latest version
instead of performing manual upgrades.”
Alark Singh
Senior Technical Analyst at Allianz
“We need more details on areas where there is an error or a traffic blockage. I
would like the tool to offer a more detailed view.”
Vincent TOH
Assistant Manager at KPMG S.A.
MICHEL RACT‐MUGNEROT
Personal business manager at La Mairic
“The solution is very basic and doesn't do anything other than the
orchestration of layer four endpoint firewall rules.”
Verified user
Executive Director of Cloud Networking at a financial services firm with 10,001+
employees
“There should be an option to upgrade from the console to the latest version
instead of performing manual upgrades. This would be more helpful to streamline
processes..”
“The log collection part needs improvement, and the tool should offer more details
about the logs. We need more details on areas where there is an error or a traffic
blockage. I would like the tool to offer a more detailed view..”
“The product’s agents don't work very well in OT environments. It could include
environments with manufacturing sensors or other devices where installing the
agent may not be possible. We don't have the same visibility and flexibility that we
have on our computer or server..”
“Every month, we're getting new features. It's always improving. I don't see a
place where it is weak or lacking in development.
“The interaction we've had with the support team hasn't been ideal. Technical
support should be improved.
The solution needs to better integrate before we are able to deploy. It would be
helpful if we could deploy the solution even if there are difficulties with
integrations or other conflicts..”
Pricing
Executive summary
Sample customers
Santander, Frontier Airlines, OpenLink, Intermountain Healthcare, Cellcom,
BancoBASE
University 18%
Manufacturing Company 8%
Insurance Company 7%
Company size
Valuable features
“Guardicore makes its own rule set automatically, so we can work fast when
creating a rule set.”
Verified user
Information Security Consultant at a comms service provider with 11‐50
employees
Uday Varma
Solution Architecht at Inspira Enterprise
“The most valuable features of the solution are the maps and ring fencing
that help monitor events.”
Ofira Cohen
Analyser at Shaare Zedek Medical Centre
Matthias Kropf
Senior Expert Enterprise Architecture at a manufacturing company with 10,001+
employees
KlavsThaarup
Senior Security Consultant at Orange Cyberdefense
And Guardicore makes its own rule set automatically, so we can work fast when
creating a rule set. We don’t have a long phase of monitoring or whatever, so we
can go straight to rules where we drop unwanted data traffic.
We can also give this view not only to the administrator of the Guardicore
components but also to the application owner, so they can see where their
application is placed in the ring-fencing and what communication is there. This
makes incident management easier because we get incidents in a more
authenticated way from the application owner. That’s also a big benefit from the
visibility of the Guardicore solution.
In the firewall, only the administrator has a deep look into the architecture, the
logs, and the segmentation. In the Guardicore solution, we can give more visibility
to the application owner on their own application. This makes it easier to manage
incidents and the overall management of the application and network. The
application owner has a view of the actions happening on the network with their
assets or applications..”
“Initially, I liked the telemetry part. But later, we used the micro-segmentation
features that we were able to deploy and found that they really stood out from
other vendors.
“The tool is easy to use and simple to deploy to achieve segmentation objectives. It
offers a graphical view of real-time workflows and traffic patterns into server-to-
server communications. Also, the amount of process, service level visibility the
agents deployed on the servers provide via network logs is very informative..”
The query insight module is something that our customers found very beneficial.
“The limitation of security groups, in terms of the number of services you can open
that you can cover by using these tools, is great.
If you treat your network as a flat, and then you start creating all your, let's say,
network security zones using this tool, it makes life easy. For example, you have
always flexibility in having different production and management interfaces.
I have not compared the range of operating systems that it supports to its
competitors because of our use case. We are most interested in LAN segmentation,
in particular between the data center and the users' network, so I compared it with
other solutions in that context.
It is a benefit that Guardicore supports legacy operating systems, and I have used it
with such servers. However, in the long term, it is more important that I have
something protecting my data center and having the visibility of what endpoint is
initiating connections.
We use the AI-powered segmentation functionality and it affects the time required
to design by a lot. It gives us a large number of views and without that, you
cannot design the system properly. The AI helps because it shows you what you
need to do. Without the AI, either you will not be able to implement the system, or
it will take a long time and be very difficult. For us, using this feature saved us a
couple of months in implementation time..”
Pain Points
“I would rate the stability a six out of ten, where one is low and ten is high
stability.”
Verified user
Information Security Consultant at a comms service provider with 11‐50
employees
Uday Varma
Solution Architecht at Inspira Enterprise
“It would be very helpful for beginners if the solution had more windows to
help with the terms inside instead of going to the documentation.”
Ofira Cohen
Analyser at Shaare Zedek Medical Centre
Matthias Kropf
Senior Expert Enterprise Architecture at a manufacturing company with 10,001+
employees
KlavsThaarup
Senior Security Consultant at Orange Cyberdefense
“When we have more than one interface, we can only have one policy for both
interfaces. Normally, you have assets with a production interface and a server
interface that are only for management.
But in the Guardicore architecture, you cannot give the production interface its
own rule set and the management interface another rule set. You have to combine
these rule sets into one. It’s a lack because security standards suggest a different
way to secure management interfaces.
So, I would like to have two separate rule sets for the basis of the device..”
“It's not easy to learn to use this program. It would be very helpful for beginners if
the solution had more windows to help with the terms inside instead of going to
the documentation..”
“There are always areas for improvement. It doesn't support a PAAC solution
(Platforma as a service) in the cloud. So that could be improved.
In future releases, I would like to see more integration with other products. .”
“Supports become difficult when it's for a big organization. For a small
organization, medium organization, it still makes sense, however, for a big
organization, it makes life difficult.
I'd like support for all types of Kubernetes and service mesh. They say, "Ah, we
support this, we support that." This is not the case. .”
Pricing
“The price is the same as other products in the market. There's no price argument
to choose one or the other product, it will cost the customer approximately the
same.”
“The solution is reasonably priced and I would rate it a six out of ten. The tool's
licensing costs are yearly.”
Executive summary
Cisco Secure Workload is a cloud and data security solution that offers a zero‐trust policy of
keeping an organization’s application workloads safe and secure throughout the entire on‐
premise and cloud data center ecosystems.
Cisco Secure Workload will consistently provide protection by discovering workload process
anomalies, stopping threats immediately, minimizing the risk threat surface, and aborting any
lateral movement.
Today’s ecosystems are very elastic, and in the application‐focused dynamic of today’s
aggressive marketplace, Cisco Secure Workload delivers a robust security solution that works
effectively with today’s most popular applications. The solution uniquely surrounds each and
every workload to ensure organizations are able to keep their data, network, and applications
safe and secure at all times. Cisco Secure Workload ensures that enterprise organizations can
maintain secure applications by consistently building firewalls around every workload level
throughout the entire ecosystem. The solution can manage applications that are deployed on
containers, virtual machines, or bare‐metal servers.
Cisco Secure workload is able to meet an organization's busy needs and offers flexible options
such as Software‐as‐a‐Service (SaaS) and on‐premises options. Using the Secure Workload
SaaS options, users receive all the benefits of Cisco Secure Workload protection without the
hassle of having to deploy and maintain the platform on premises. Users are responsible for
acquiring the necessary software licensing and deploying software agents. Using SaaS, Secure
Workload runs in the cloud and is operated and maintained by Cisco. This option offers the
ability to scale easily and is a popular choice for SaaS‐first and SaaS‐only clients. Many
organizations find they get the best TCO and achieve the best productivity and profitability
using the SaaS options.
When choosing on‐premises options, organizations choose between hardware‐based appliance models (large or small
form factors). Platform selection is dependent on scalability goals, the desired fidelity level of flow telemetry, and the
actual number of workloads. When a user chooses to configure Cisco Secure Workload for a conversation‐only flow
telemetry for all workloads, each platform has the capability to scale up vertically twice the default platform scale.
Additionally, with Secure Workload, it is possible for the platform to be scaled horizontally in order to satisfy the
demands of extra large widely distributed enterprise environments using federation capabilities.
Cisco Secure Workload also provides a robust disaster recovery (DR) tool, which helps to make it a complete,
comprehensive solution. The DR allows for continuous restore and backup capabilities that enable users to quickly
remediate operations and data to a standby cluster in the event of a drastic failure or disaster.
“
The solution offers 100% telemetry coverage.
The telemetry you collect is not sampled, it's not intermittent. It's complete. You see everything in it, including full
visibility of all activities on your endpoints and in your network. Other valuable features include vast support for
annotations, flexible user applications, machine learning, automatic classification, and hierarchical policies.” ‐ CTO at a
tech vendor
Sample customers
ADP, University of North Carolina Charlotte (UNCC)
Akamai Guardicore
Cisco Hypershield Illumio
Segmentation
Compared 22% of the time Compared 17% of the time Compared 16% of the time
Learn more Learn more Learn more
Government 8%
Company size
Valuable features
“The only use case I can see that makes sense is micro-segmentation. I think
there are other use cases for it. The main purpose of the product is to do
micro-segmentation by collecting IP. That could be done by installing an
agent, and then you have all the communication coming in and out. You
could also use some flow sensors installed in the network that receive a copy
of the traffic and then report that back to the system.”
Sanjay Gaiswal
Post Sales Manager at Vcom Teachnologies
Verified user
Partner at a consultancy with 1‐10 employees
Muhammad Marakkoottathil
Regional Presales Consultant (INS Division) at GBM
“It's stable.”
Boris REYES
Sales Manager at Compuequip DOS
“The most valuable feature of Cisco Secure Workload is its ability to streamline
policy discovery. Once you create the workspace, it automatically identifies
policies at various levels, whether you need finely-tuned micro-level or broader
group policies. As data is gathered from all the agents, the system presents these
policies, significantly reducing the need for multiple engineers who typically take
much longer to create them. My IT risk colleagues utilize a process we call ADM,
where they discover policies over a three to six-month period and present them to
application owners. Once the application owners approve the policies, they can
switch to enforcement mode in Cisco Tetration. This automation in policy
presentation and access is incredibly valuable, as it minimizes manual
intervention and the time required for policy discovery.
“The only use case I can see that makes sense is micro-segmentation. I think there
are other use cases for it. The main purpose of the product is to do micro-
segmentation by collecting IP. That could be done by installing an agent, and then
you have all the communication coming in and out. You could also use some flow
sensors installed in the network that receive a copy of the traffic and then report
that back to the system.
No matter where you're getting the flow from, the system calculates all those
flows. You know what the front end, the middleware, the back end, the database,
and so on are so that you can group them. The system's strength is actually in
proposing the policy. So, all web servers need to have HTTPS access to it.
Then, you can start building the policy for your application. When you have a
policy, you can push that situation for self-service, which means you're trying out
the policies you created in a real environment. Then, you can spend time trying to
see if you have any escaped traffic, which means you have traffic that does not
match the policy. If you were in enforcement mode, that traffic would be dropped.
So you have a period where you can monitor if you have done the correct mode,
seen all the traffic, and so on. That could be for a couple of weeks, that could be a
month, or it could be half a year, depending on the criticality and how important
your system actually is.
From my point of view, the strength is the policy proposal you're receiving. It's
really good. That's the biggest challenge for everybody - creating a policy you
could use in Cisco Secure Workload itself. You could also export it and use it in your
firewall if you want to do that if you have a Cisco firewall setup. But you could also
use it in every other enforcement part. I'm seeing what people are struggling with
in companies - to actually restructure your CMDB data correctly, then get a policy
that you can use in your network. I think that the tool is good at that..”
“I used to be a big fan of Cisco Secure Workload and Cisco Tetration Platform. I
used to really like it. However, the product has undergone significant
modifications since then. Certain pieces of it have been moved into Cisco SD-
Access, and the original DVR of the network functionality has been moved. As a
result, the product has changed a lot since I was most familiar with it.
It's stable.
“The solution offers 100% telemetry coverage. The telemetry you collect is not
sampled, it's not intermittent. It's complete. You see everything in it, including
full visibility of all activities on your endpoints and in your network.
Pain Points
Sanjay Gaiswal
Post Sales Manager at Vcom Teachnologies
“There was a controversy when Cisco reduced the amount of data they kept,
and the solution became quite cost-intensive, which made its adoption
challenging….Although they have modified it now, I preferred the previous
version, and I wish all the functionality were back under the same product.”
Verified user
Partner at a consultancy with 1‐10 employees
Muhammad Marakkoottathil
Regional Presales Consultant (INS Division) at GBM
Boris REYES
Sales Manager at Compuequip DOS
“We actively seek improvements in integrating the Infoblox DDI platform with
Cisco Secure Workload. This integration allows Cisco Secure Workload to learn
about our networks and network tags, providing valuable insights into
vulnerabilities related to the operating system and various applications installed
on our servers.
Cisco Secure Workload offers automatic policy enforcement but cannot adjust
policies dynamically as the application needs to change. Having used the platform
for the past five years, the recent announcement has been reassuring. Cisco has
confirmed that our investment in the platform will not go to waste. They will
honor our existing licenses, providing a natural migration path to the new solution
without any disruption.”
“There's room for improvement when it comes to Cisco Secure Workload. A couple
of internal areas could be refined a little bit. They are trying to solve it, depending
on where you suppose the agent is. Suppose you have the agent on both the server
and the client, which could be the front-end server or web server connecting to
the. In that case, if those two are communicating on RPC, the server can look into
its configuration. It could go down and find the configuration file on the FTP server
and then set the policies to it. But there are a lot of different FTP servers out there.
It's also a complex case for the tool to support all FTP servers.
Some things are related to Windows, Unix, Linux, and IBM AIX. We have been
working on all platforms, but the support for IBM AIX isn't that good compared to
normal operating systems. Support is much better for Windows compared to IBM
AIX..”
“On the client side, Cisco Secure Workload orchestrates host firewalls for micro-
segmentation, which is crucial for zero trust security for whitelisting in
networking. Before speaking of areas for improvement, I would like to say that I
have always been fond of Cisco Tetration Platform and Cisco Secure Workload.
There was a controversy when Cisco reduced the amount of data they kept, and the
solution became quite cost-intensive, which made its adoption challenging.
Although they have modified it now, I preferred the previous version, and I wish all
the functionality were back under the same product. Currently, it is integrated into
Cisco SD-Access, but not all customers want access to this product..”
“There is some overlap between Cisco Tetration and AppDynamics and there are
few DC tools, It would be great to have a single pane of glass, rather than have to
jump between different tools..”
Pricing
“Regarding price, Cisco Secure Workload can be expensive if you don't have a
budget. If you're not doing micro-segmentation, every extra security measure or
enforcement you're putting on top of your existing environment will be an extra
cost. It's not a cheap solution at all. But from my point of view, if you need to do
micro-segmentation, this is one of the best tools I've seen for it. I can't compare
that to Microsoft's solution because I haven't looked into it. I've looked into
VMware and Cisco. Those are the only two that I know of. I didn't know that
Microsoft could do micro-segmentation at all. Maybe they can, but I haven't heard
anything about it.”
“The price is based on how many computers you're going to install it on.”
“Pricing depends on the scope of the application and the features. Larger
installations save more.”
Executive summary
Sample customers
JetBlue, International Speedway Corporation, Volkswagen SAIC, Brighton and Hove
City Council, Foresters Financial, Janus International Group, Cloud Comrade, Serco
Akamai Guardicore
VMware NSX Illumio
Segmentation
Compared 78% of the time Compared 10% of the time Compared 9% of the time
Learn more Learn more Learn more
Healthcare Company 8%
Manufacturing Company 8%
Company size
Valuable features
“They also introduced that they develop API first and the rest follows.”
Verified user
Systems Engineer at a tech services company with 11‐50 employees
“It is a very stable solution. Stability-wise, I rate the solution a ten out of
ten.”
Gus Thompson
IT Principal Analyst at Pima Community College
Lipaz Hessel
Integration Manager at Gilat Satellite Networks
“The network view was excellent as it allowed us to expand the server view
and visualize all connections it made within the environment. This was
particularly useful in identifying the path of our data and not just its location
within the data center.”
Jason‐Taylor
Senior Systems Engineer at a tech vendor with 1,001‐5,000 employees
SuchitPatel
Technical Solutions Architect for Cloud and Data Center Group at Hitachi Systems,
Ltd.
“Nutanix Flow solution has updated the ability to control everything through API.
They also introduced that they develop API first and the rest follows.
I don't use it very often because the implementation isn't huge enough to
necessitate automating things. But I think it could be very solid since the API of
Nutanix and the rest of the components is very good. So, I think it can be quite
useful and helpful.
It has a lot of features. There is probably some confusion with the name or with the
product because there is Flow micro-segmentation and also Flow networking. It's
both network-related, but it's not the same product. What I know and speak about
is micro-segmentation, and I think it's quite nice. It's easy, and it does what it
needs to do..”
“Nutanix Flow has a lot of data protection features. It's also valuable
for operations and management. It's a big solution that works well with different
solutions and is suitable for most business cases..”
Pain Points
“Last time I used it, it was not handy to see or to analyze traffic logs.”
Verified user
Systems Engineer at a tech services company with 11‐50 employees
Gus Thompson
IT Principal Analyst at Pima Community College
Lipaz Hessel
Integration Manager at Gilat Satellite Networks
“While the graphical interface of Nutanix Flow Network Security could have
been improved, and some of the reporting features needed extra work, the
product's features were similar to VMware's NSX. The difference lay more in
the presentation and user interface.”
Jason‐Taylor
Senior Systems Engineer at a tech vendor with 1,001‐5,000 employees
“I would rate Flow Network Security's stability seven out of ten - it could be
improved.”
SuchitPatel
Technical Solutions Architect for Cloud and Data Center Group at Hitachi Systems,
Ltd.
“Last time I used it, it was not handy to see or to analyze traffic logs. As a Check
Point partner as well, we have some more expectations to log in. Probably, it's
possible to forward all the traffic logs to a log system, but I'm not very into it. It is
not very intuitive. A lot of manual tasks are needed to achieve that. But it's
possible, and it would be nice to maybe have better examples in the guides or to
have another integrated log system to analyze the traffic logs..”
“While the graphical interface of Nutanix Flow Network Security could have been
improved, and some of the reporting features needed extra work, the product's
features were similar to VMware's NSX. The difference lay more in the
presentation and user interface.
I am not able to recall the specifics, but I vaguely remember encountering a minor
issue with the product's graphical interface.
My sales engineer was helpful in identifying that I was using a different approach
than what was anticipated when expanding the object to view the communication
protocols. However, I don't have any further information about the issue..”
“For customers who are running Nutanix Flow and AHV, the largest area for
improvement is in the disaster recovery environments. To automate the populate
of rules from one side to the other side in case of disaster you report everything on
the disaster recovery site, and you have all the rules automatically applied. This
was something that was being built when I left Nutanix. It might already be
available. Additionally, the usability of the rules editor could improve..”
“Nutanix Flow's networking features could use some improvement. Also, I don't
know if it's currently supporting load balancing or not. Lately, we've been
working a bit more with Nutanix Calm. We're trying to invest more in Calm and
deliver solutions based on that platform. But it is still a new software. It's a new
solution for automation and helping customers develop a private cloud. We are
still facing a lot of challenges in Calm, but in the future, we will focus on Calm and
Era our customers benefit a lot from these products. Era is a database-as-a-service
(DBaaS) solution that we plan to promote to the customer along with Calm because
Calm minimizes the time and operations efforts of the customer..”
Pricing
“On a scale from one to ten, where one is cheap and ten is expensive, I rate the
solution's pricing a seven out of ten.”
“In comparison to other options available in the market, I would rate their pricing
as very competitive, probably a two or three out of ten for cost.”
Appgate SDP
Executive summary
Appgate SDP is a network access control tool for local and remote access, multifactor
authentication, and micro‐segmentation. It is a flexible, robust, and configurable tool with
good documentation, interface improvements, and ease of deployment.
It helps organizations prevent lateral movement across networks and servers and provides a
more granular access control structure than traditional VPNs. Appgate SDP's valuable
features include the ability to hide servers, good support, stability, scalability, and stopping
lateral movement. It is currently being used as the main VPN solution for many companies.
Sample customers
United States Air Force
FINRA
Weight Watchers
Rackspace
DataDog
SageNet
Verdant
Norwegian Cruise Line
VoiceBase
The Third Floor
Government 8%
Company size
Valuable features
IgnitiusMolepo
Senior IP Network Defense at MTN
Verified user
Country Manager at a tech services company with 1‐10 employees
Abubakar Babah
Payment Officer at Central Bank of Nigeria
Haricharan Gokul
Software engineer at a tech vendor with 10,001+ employees
Omar_Jaimes
Cybersecurity Architecture Manager at Data Warden
“Firstly, the granularity feature of the solution allows it to build granular rules to
access different applications. Secondly, the capacity to view the connection is
another valuable feature of the solution. .”
You can hide the servers, and you can avoid lateral movement if you pick up any
ransomware, for example.
It is pretty stable.
“The flexibility of the tool is valuable. It is very robust. It has a very robust
configuration capability.
Pain Points
“They could provide a single-box solution to manage tools for 4000 users.
Additionally, they could add extra features to enhance remote micro
connection.”
IgnitiusMolepo
Senior IP Network Defense at MTN
“The user interface should be improved as it is not very easy to work with the
updates.”
Verified user
Country Manager at a tech services company with 1‐10 employees
Abubakar Babah
Payment Officer at Central Bank of Nigeria
Haricharan Gokul
Software engineer at a tech vendor with 10,001+ employees
“On the cloud, when you make some changes, it may be difficult.”
Omar_Jaimes
Cybersecurity Architecture Manager at Data Warden
“They could provide a single-box solution to manage tools for 4000 users.
Additionally, they could add extra features to enhance remote micro connection..”
“One limitation is that it's harder to provide access to multiple applications in the
company with Appgate, but that's probably because of poor management.
The solution is fine as it is, but it would be better if it could help us access general
public sites. It would be better to not create a separate policy for that..”
“On the cloud, when you make some changes, it may be difficult. However, on-
premises is very good, and I like it.
We'd like to be able to change the VPN connection for different areas. For example,
if finance wants to connect to SAP, you could grant access to certain people for
that, on a specific server..”
One thing that kind of sticks out to me is the ability to do a proper non-split
tunnel. VPN tunnel-wise, it is not really a true unsplit tunnel, but I think that's
just because of the way it's designed. A split VPN basically allows your system to
talk to other systems without being forced down the tunnel. A VPN running in a
non-split tunnel mode forces all the traffic down the tunnel to wherever you're
VPNing to. It forces the traffic down so that the traffic is subject to the firewall and
rules that you have in your corporate environment and such. It helps to prevent
remote malicious folks that may be talking directly to that box from piggybacking
into the corporate environment through it. They do it partially, but it would be nice
to see more of an enterprise-level solution there..”
Pricing
“The pricing is according to the market price. It is not a very cheap solution. They
have some very aggressive promotions to sell the product in the market.”
“We pay $100 per user per month. One license for the site is around $17.”
“It is a pretty expensive tool. It is maybe about $20,000 per year for a hundred
users or so.”
Executive summary
Airgap Zero Trust Enterprise is a comprehensive security solution designed for various
applications, including secure remote access, protection against unauthorized data breaches,
and enforcement of least‐privilege access controls. It features a Ransomware Kill Switch, easy
deployment, granular control over network access, and strong support for remote work
environments. Users appreciate its enhancement of operational efficiency, streamlined
workflows, and improved productivity, alongside cost‐saving benefits. Its user‐friendly
interface facilitates quick integration, making it a valuable asset for optimizing organizational
performance.
Akamai Guardicore
Illumio
Segmentation
Valuable features
Atul‐Yadav
Enterprise Cloud and AI Security Architect at a security firm with 10,001+
employees
“The most valuable feature is the runtime protection and dynamic Zero Trust
monitoring, which helps me catch threats in real time, especially in production
environments. Airgap Zero Trust Enterprise effectively reduces false positives and
distinguishes between genuine and false attacks, providing automated guidance
for remediation and minimizing production impact..”
Pain Points
Atul‐Yadav
Enterprise Cloud and AI Security Architect at a security firm with 10,001+
employees
Zero Networks
Executive summary
Zero Networks leverages machine learning and behavioral analytics to create and enforce
adaptive security policies that automatically adjust to changing network conditions and user
behaviors. The solution continuously monitors network traffic and user activities, creating a
dynamic and secure environment where access is strictly controlled based on real‐time risk
assessments. By automating the zero‐trust model, Zero Networks eliminates the need for
manual configuration and reduces the complexity of network security management.
What benefits should users look for in reviews when evaluating Zero Networks?
• Improved Security Posture: Enhanced protection against unauthorized access and lateral
movement within the network.
• Reduced Complexity: Simplifies network security management by automating policy
creation and enforcement.
• Operational Efficiency: Saves time and resources with automated processes and real‐
time adjustments.
• Scalability: Easily adapts to changing network conditions and growing organizational
needs.
• Cost Savings: Potential reduction in security‐related costs due to automation and
efficient threat management.
Zero Networks is implemented across various industries, including finance, healthcare, and
manufacturing, providing tailored security solutions to meet specific regulatory and
operational requirements. Its automated and adaptive approach is particularly beneficial in
sectors with complex and dynamic network environments.
Pricing for Zero Networks solutions typically involves a subscription model based on the
number of users and devices. The company offers robust customer support, including
deployment assistance, training, and ongoing technical support to ensure optimal
performance and security.
In summary, Zero Networks provides an automated, adaptive zero‐trust security solution that
enhances network protection, simplifies management, and reduces costs.
Sample customers
Sani Marc, Great Clips, MIO Partners, ACT Commodities, Evercore, Atlantic
Constructors
Akamai Guardicore
Illumio Elisity
Segmentation
Compared 59% of the time Compared 30% of the time Compared 11% of the time
Learn more Learn more Learn more
Manufacturing Company 8%
Healthcare Company 6%
Vendor Directory
ColorTokens Xshield
Elisity Elisity
Fortinet ShieldX
Illumio Illumio
SideChannel Enclave
TrueFort Truefort
The summaries, overviews and recaps in this report are all based on real user feedback and
reviews collected by PeerSpot’s team. Every reviewer on PeerSpot has been authenticated
with our triple authentication process. This is done to ensure that every review provided is an
unbiased review from a real user.
The customized report will include recommendations for you based on what other people like
you are using and researching.
Answer a few questions in our short wizard to get your customized report.
Get your personalized report here
About PeerSpot
PeerSpot is the leading review site for software running on AWS and other platforms. We
created PeerSpot to provide a trusted platform to share information about software,
applications, and services. Since 2012, over 22 million people have used PeerSpot to choose
the right software for their business.
PeerSpot
244 5th Avenue, Suite R‐230 • New York, NY 10001
reports@[Link]
+1 646.328.1944