Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Look for a specific application-identification count and a described classification methodology for unknown traffic, not just 'Layer 7 visibility.'
Throughput often drops significantly with full threat-prevention features enabled — look for a real-world figure distinct from the marketing maximum.
Strong answers state a specific performance impact figure for decryption enabled versus disabled, since this is a common gap between marketing throughput and real deployed performance.
Look for genuinely unified policy management across environments, not separate consoles per deployment location requiring manual reconciliation.
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
Look for a real customer-referenced figure for scale and policy-push latency, not a theoretical maximum.
Native SD-WAN integration avoids policy fragmentation between the security and networking layers; a bolted-on separate SD-WAN product often creates gaps.
Look for a real customer-tested failover time and session-persistence confirmation, not just an architecture diagram claim.
Look for a stated update frequency and confirmation that third-party/custom feeds can be ingested, not just a closed proprietary feed.
Look for transparent, explicit disclosure of what's bundled versus a paid add-on; threat-prevention features gated behind a separate subscription is a common way buyers underestimate real total cost.
IoT/unmanaged-device-aware policy is a materially more advanced capability than treating all network traffic uniformly — ask for a concrete example of differentiated policy in production.
Look for an explicit answer on feature parity — virtual form factors sometimes lag behind hardware appliances in capability, which matters for a customer building a hybrid or cloud-first architecture.
Ask for the specific certification level and scope — a vague 'certified' claim without a level and validation number is not sufficient evidence for regulated buyers.
Cross-tool automated response (not just traffic blocking) is a materially stronger security outcome — ask for a concrete integration example, not just a generic 'integrates with your stack' claim.
Strong answers describe real migration tooling and a concrete, customer-validated timeline; a vendor with no migration story is asking the customer to manually rebuild potentially years of accumulated firewall policy from scratch.
Look for a coherent single-platform story across headquarters, branch, and remote workforce; a fragmented answer requiring multiple disconnected products for different populations is a real operational complexity cost.
A false positive on an inline blocking firewall directly breaks legitimate business traffic — ask for a real customer-validated false-positive figure and rollout-tuning process, not just a detection-accuracy claim.