
Overview
Hyper Scale Security for your Hyper Scalable Clouds Whether your data and applications are stored on premises, in the data center, or public clouds (or a combination of all three), organizations still need to meet their requirements of security, control, compliance, and governance by themselves. The on-demand nature of public clouds such as AWS naturally means that workloads move and regroup, where maintaining continuous visibility and control over the rapid changes calls for expert intervention. Common security challenges include: Centralized visibility and threat management for your hybrid environment Deploy applications and workloads securely Manage access & control privileges to cloud and on-premises workloads Secure data transfer, data migrations Accomplish all of the security deployments at the pace and scale demanded by cloud architectures
Highlights
- FireMon can easily create, maintain, and distribute policies in highly dynamic networks, as well as scope the impact of proposed changes to your security. By automating & orchestrating, Security Manager ensures your ability to operate at scale across cloud, virtual and hybrid environments.
- Through traffic flow analysis, FireMon tracks behavior across your network to identify which applications are being used. You can correlate vulnerability scans with access path analysis to trace every available path across the network to reduce your attack surface with a defined remediation.
- Automated compliance assessments help you validate your configuration requirements and alert you to violations. Security Manager out-of-the-box audit ready and customizable reports saves time and gives you the confidence to meet your regulatory and internal security demands.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
Please see seller website for refund details.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Additional details
Usage instructions
Before launch, in the AMI configuration settings, you must add additional volume to prevent launch failure.
Add Storage tab, click Add New Volume and in the Size field enter at least 600. Do not change the Root Volume Type.
Complete FMOS Initial Setup after launch:
- Open a web browser.
- Navigate to https://<hostname>:55555/setup, replacing <hostname> of the SIP instance running in AWS with the IP or the hostname.
- In the Authentication dialog box-Username is fmosadmin- Password is the EC2 Instance ID- Click Submit
- After authenticating, complete the required fields in the FMOS Initial Setup form. The username is read-only and cannot be changed, but you can update the password.
- After submitting the FMOS Initial Setup form, FMOS will begin the deployment process.Log in to SIP after deployment:
- Open a web browser tab.
- Enter the IP address of your SIP/AWS instance.
- Enter your username and password.
- Username is firemon (case-sensitive)
- Password is the MAC address for the instance
- Click Log in. For details, see: https://www.firemon.com/wp-content/uploads/AWS-AMI-Launch-and-FMOS-Install.pdf
CF template Usage Instruction: 1.Go to AWS marketplace subscription and Launch cloud formation teamplate. 2.Choose Action 'Launch Cloud formation' and click on Launch 3.Enter Stack Name. 4.Enter all mandatory fields in Parameters. VPC ID Subnet ID Instance Type Key Pair Name IP address Volume Size FMOS username 5.Specify Ecosystem in "Machine Configuration". 6.Add Organization Name. 7.Click Next. 8.Review: Review all sections entered and click Next. 9.A new stack with above Stack Name is created with status "CREATE_COMPLETE". 10.Go to EC2 Dashboard, a new instance is created. 11.After the deployment process completes, you can log in to Security Intelligence Platform to continue setting up your network, such as adding users and devices. a. Open another browser tab. b. Enter the IP address of your AWS instance, For example, https://<hostname_or_IPaddress>;. c. Enter your username and password: Username is firemon (case-sensitive) Password is the MAC address for the instance with colons removed and lowercase letters instead of uppercase letters. For example, a MAC address of 00:05:95:A1:2B:CC would be 000595a12bcc. This is a one-time password to use at first installation and will need to be reset after initial login. Click Log In
Resources
Support
Vendor support
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products



Customer reviews
Compliance checks have improved visibility and now provide clear guidance on blocking risky rules
What is our primary use case?
I use FireMon Security Manager as a compliance tool to check rule compliance and firewall rule compliance.
What is most valuable?
I use FireMon Security Manager as a compliance tool to check rule compliance and firewall rule compliance. Overall, it is good and working fine. As soon as we deployed it for that purpose, we could see the benefits immediately. We could see what rules should be blocked and everything.
What needs improvement?
The only feedback I would like to give is that we were requesting them to move to SaaS so that the upgradation and everything would be a little more automatic or maybe just easier.
For how long have I used the solution?
I have been using FireMon Security Manager for around four years.
What do I think about the stability of the solution?
I have not observed any lagging, crashing, downtime, or instability with FireMon Security Manager recently. Previously, we used to have some issues with respect to upgrades two years back; it was failing, but now it seems pretty smooth since the last two years.
What do I think about the scalability of the solution?
FireMon Security Manager is good in terms of scalability. We are requesting a few things now, and we have requested new features. I have gotten an update from the TAM that the engineering team is working on that, and it may be coming soon. With respect to scalability, FireMon Security Manager is fine and good.
How are customer service and support?
I think FireMon Security Manager is pretty good. I have a support manager, Gary, who helps us. He is a TAM for us, and he supports us very well.
I have contacted the technical support or customer support of FireMon Security Manager regularly. The TAM with whom I am connected supports us, and his support is really good. He gives us proper support; whenever there is a query or any issue, we send an email to him, and he gives us support whenever required. We are completely satisfied with that.
Out of 10, I would give the support of FireMon Security Manager a score of 10. It is really good.
Which solution did I use previously and why did I switch?
I cannot say that MFNA, Micro Focus Network Analyzer, is exactly similar to FireMon Security Manager because as of now, we have that tool, but it is strictly for configuration. There, we check the configuration part, not the rule of the firewalls. It strictly checks the configuration, so it is not really similar. FireMon Security Manager is better. I think we are exploring to check configuration from FireMon as well, but we are not checking it yet.
How was the initial setup?
The initial deployment of FireMon Security Manager when I first started using the product was fine. It was easy and not so difficult.
What was our ROI?
Definitely, some time had to pass before I saw the benefits of FireMon Security Manager.
What other advice do I have?
I do not have much idea with respect to pricing of FireMon Security Manager.
FireMon Security Manager does not really require any maintenance on my end to continue working. There are just regular updates whenever a new OS comes up, but apart from that, I do not see any maintenance that is required.
I think FireMon Security Manager's reporting is good. In our case, we do not use the report from FireMon Security Manager. We fetch the data from the API, and we have different dashboards, so we do not use reports directly from FireMon.
I do not have any idea about partnerships; I think I am just a customer of FireMon Security Manager.
I would rate this review an 8 out of 10.
Reporting has strengthened audit readiness but struggles to handle very large rule sets
What is our primary use case?
FireMon Security Manager integrates reasonably well into my security stack. We are able to onboard the devices quite easily, but some advanced features of the firewalls take time to support. Sometimes when a new feature is introduced on the firewall side, FireMon may take some time to incorporate it.
If I were to speak to someone looking to buy FireMon Security Manager, I would say the biggest win is the reporting feature. If your environment is not very large and if you don't have a massive amount of rule sets, then you can go with FireMon Security Manager. It works well with the reporting, and you can use it for getting the reports and presenting them for audit and compliance. It can be used effectively, but if the rule count is huge, it is not very scalable. If your environment is large, then you may get some issues with getting the reports; sometimes the report won't load if the rule count is very high.
What is most valuable?
What I like the most about FireMon Security Manager is the reporting feature; it gives all the rules in one console, so we are able to see all those rules without logging into each firewall. Reporting allows us to fetch the rules, for example, risky rules, and other similar information very easily in one place.
The reports from FireMon Security Manager for communicating risk reduction, compliance status, or overall security posture to my higher-ups are very good. We are actually using it to get the reports and present them to senior officers.
What needs improvement?
FireMon Security Manager should have tested more use cases. Sometimes organizations will have a larger number of devices and a larger number of firewall rules. Sometimes FireMon could not handle such an amount of rule sets, and it will cause some issues with normalizing flows data.
One thing about FireMon Security Manager is that the releases are quite frequent. We need to upgrade more frequently. They release every quarter, but the frequency is comparatively high when compared to others. For FireMon Security Manager, we don't face many outages, but we need to upgrade it frequently to get the patches and the fixes for the issues.
For how long have I used the solution?
In my career, I have been using FireMon Security Manager for five years.
What do I think about the stability of the solution?
I have seen lagging, crashing, or downtime; sometimes some service crashed, and I needed to restart those services, identify those services, and restart them. It is not very frequent, but it happened.
What do I think about the scalability of the solution?
Regarding the overall scalability of FireMon Security Manager, I would say it is not very scalable. If the rule count goes on increasing, sometimes, for example, if we have a firewall and it's used for all the sites, the device count increases and the rule count increases massively, FireMon sometimes cannot handle it effectively.
How are customer service and support?
The speed of support for FireMon Security Manager depends on the severity of the issue. If it is a minor issue, then it will be faster; if it is a major issue, sometimes it will require their development team to get involved. In those cases, it will take a long time; it could sometimes take months to solve the issue.
For the support of FireMon Security Manager, I would give a six or seven on a scale from one to ten, with ten being the highest.
Which solution did I use previously and why did I switch?
Previously, I used AlgoSec in my previous organization, but I didn't use it as extensively as FireMon Security Manager, so I don't have much to compare the two.
How was the initial setup?
When I first started using FireMon Security Manager, it was moderate. There were people from FireMon giving us the knowledge articles and how to navigate things, so it was not very hard to learn. It is moderate; someone with two to three years of experience can understand it easily.
What other advice do I have?
Overall, I would give FireMon Security Manager a six out of ten for everything.
Real-Time Visibility That Delivers
Centralized policy visibility has transformed how I manage compliance and firewall rule changes
What is our primary use case?
Our customers have different use cases with FireMon, and I won't disclose names. They want a tool that offers a single pane of glass for rule set visibility, understanding policy compliance, and how compliant they are with various policies such as HIPAA, PCI DSS, or NIST. Another use case involves Security Manager rather than Policy Planner and Policy Optimizer, as these are designed for change automation.
Regarding centralized visibility of firewall rules across multiple vendors for a customer, they sometimes want to know who owns a particular rule, its function, and its deployment location. For risk and compliance, the focus is on identifying risky firewall rules and assessing them against organizational standards. Additionally, they use network path analysis to understand connections between applications, which aids network security teams in troubleshooting.
What is most valuable?
FireMon Security Manager acts as a network security policy management layer above core infrastructures, offering centralized policy visibility across platforms including Palo Alto, Fortinet, and Check Point. It interfaces with ITSM tools, facilitating workflow automation. However, it complements rather than replaces existing security technologies.
Transitioning from a manual and time-consuming process to one utilizing Policy Planner and Optimizer has improved visibility and confidence in policy changes, reducing manual efforts, and enhancing governance and auditability.
What needs improvement?
The console GUI disappoints me because it lacks customization. I cannot remove or add widgets, similar to how iPhone locks app placements. The non-customizable dashboard annoys me as it shows unwanted information. However, Insights with AI integration offers customizable dashboard visibility once opted in, which addresses this limitation.
For how long have I used the solution?
I have been with the company for twenty-two years, and with FireMon Security Manager, I have been using it for around two years now.
What do I think about the stability of the solution?
A specific collector issue affected traffic log collection and config retrieval. It was not a total crash, but a process issue. This is the first occurrence in two years, and we are working on pinpointing the problem. Overall, I rate the stability at nine out of ten.
What do I think about the scalability of the solution?
FireMon Security Manager uniquely supports Strata Cloud Manager for Prisma Palo Alto devices and facilitates Azure firewall configurations and Illumio integrations. It integrates with various solutions such as ServiceNow, SIEM, or SOAR, showcasing superior integration and scalability among vendors.
How are customer service and support?
As a user for two years, I recently opened my first case with FireMon's technical support, which was handled promptly. Unlike other vendors with long response times, FireMon's support quickly engaged, offering screen sharing sessions to resolve issues efficiently. I have found their support exemplary.
Which solution did I use previously and why did I switch?
I have experience working with several network security policy management solutions, including Tufin, AlgoSec, and previously Skybox. Skybox offered a high degree of dashboard customisation, but the company subsequently went into liquidation in February 2025. Tufin and AlgoSec both have their own strengths, and my experience with FireMon has led me to favour it for my current requirements, particularly around centralised policy visibility, compliance, policy management, and integration capabilities.
How was the initial setup?
Initial deployment is extremely easy. If a connector issue arises, FireMon sends a device pack to address specific issues, avoiding full software upgrades. This expedites resolutions, such as with Check Point or Fortinet firewalls. Furthermore, bulk uploading capabilities streamline implementation without management stations.
What's my experience with pricing, setup cost, and licensing?
What other advice do I have?
I regularly design, deploy, and support FireMon Security Manager instances, receiving daily reports. These reports are valuable for customers, particularly for C-level presentations, offering insights into compliance, security, and change activities. I give FireMon Security Manager a rating of ten out of ten. I have worked with many solutions, including Skybox, Tufin, AlgoSec, Check Point, and Palo Alto, but FireMon Security Manager truly stands out for its willingness to assist quickly.
Centralized rule analysis has streamlined multi-vendor firewall audits and risk reporting
What is our primary use case?
We use FireMon Security Manager for managing the rule base on our various multi-vendor firewalls.
We did not use the policy manager, but with FireMon Security Manager, we checked for logging disabled. We used overly permissive features and ran SQL queries to find the overly permissive rules and conducted remediation based on those findings. We ran FQDN queries to find out which rules were using FQDN instead of URL filtering. Without FireMon Security Manager, the vendor did not have any such features, so FireMon Security Manager was the only tool we could use to get our retrievals. We use CLI scripts and GUI, both of which are doing something that no other tool can do as far as we have seen.
What is most valuable?
What I like the most about FireMon Security Manager is that it can go across a whole rule base and get the items we need, like rules that have a specific characteristic, such as logging disabled, and we can find which rules are there that match that criteria for any vendor. It can do this very quickly. Whereas, if we have to log into all the vendor websites and try to get access to all the infrastructure for every single vendor separately, it is a very time-consuming task. We can export results in CSV, and there are some good features that we can use right away.
What needs improvement?
What I dislike about FireMon Security Manager is that I use the Insights add-on option, which does add a visual dashboard. I would prefer more of a visual dashboard that I can customize. Right now, we have the visual dashboard in Security Manager, but it is not customizable, and the same applies to Insights. The AI feature is very useful in Insights, but the visual dashboard which can be customized is not there to track our progress if we are trying to mitigate any security blind spots.
I mention more customizable visual dashboards because every organization has different priorities. Sometimes our management asks us to prioritize and look for different items, and suddenly they change the direction. If you have a tool that does not customize a dashboard, then you cannot make graphs or visually represent over the past three months or six months how we have progressed. Have we gotten worse or better?
I think the pricing for FireMon Security Manager is fair. However, it could be better if you could have more customization options, such as medium and large firewalls. You could have different categories; small firewalls exist, but medium is no longer in the licensing. That would help save money.
FireMon Security Manager requires maintenance on my end. We have to pull retrievals, and the retrievals fail many times, and sometimes they succeed. Sometimes we have to investigate, troubleshoot, and do packet captures. There is a lot of work that management does not understand, and it is very difficult to convince them that we are actually working. They do not realize that we are actually working on many tasks just to keep things running and pulling reports. We need fresh retrievals, and sometimes things break. We have to remove devices and add devices. It is very difficult to portray to management that we are actually working, and it takes a lot of effort to manage the database server and keep things running smoothly and update licenses. A lot of background effort is involved, though it does not appear that way to management. It is very difficult to convey the efforts involved at performance evaluation time.
I have just used Panorama with FireMon Security Manager. However, my colleagues have used other tools, and they said there are advantages and disadvantages in every tool. FireMon Security Manager is a very good tool to do what we want to do, but it can be improved, as can every other tool.
For how long have I used the solution?
I have been using FireMon Security Manager in my career overall for about four years.
What do I think about the stability of the solution?
I think stability is very good. FireMon Security Manager is pretty stable. Sometimes we had issues, but we resolved those issues and restarted the server. That part is good.
What do I think about the scalability of the solution?
I think scalability with FireMon Security Manager is pretty easy.
How are customer service and support?
Our TAM helped us a lot and was very useful to have. He customized many features that were not customizable. He wrote custom scripts and did a great job customizing everything and keeping our management happy. We had very customized requests, and since we could not customize anything, our TAM helped us maneuver around the rigid dashboard display limitations. He wrote custom Python scripts and did a lot of effort behind the scenes. I am not even aware of how much effort he took to do all that work.
Which solution did I use previously and why did I switch?
I have just used Panorama with FireMon Security Manager. My colleagues have used other tools, and they said there are advantages and disadvantages in every tool. FireMon Security Manager is a very good tool to do what we want to do, but it can be improved, as can every other tool.
How was the initial setup?
I was not there when they did the initial deployment of FireMon Security Manager, but I was involved in an upgrade, and the upgrade went smoothly.
What about the implementation team?
I was not there when they did the initial deployment of FireMon Security Manager, but I was involved in an upgrade, and the upgrade went smoothly. Our TAM helped us a lot and was very useful to have.
Which other solutions did I evaluate?
I have just used Panorama with FireMon Security Manager. My colleagues have used other tools, and they said there are advantages and disadvantages in every tool. FireMon Security Manager is a very good tool to do what we want to do, but it can be improved, as can every other tool.
What other advice do I have?
Overall, I would say FireMon Security Manager is hard to beat, except the AI features have been recently introduced in Insights. I would rate FireMon Security Manager 9 out of 10. There are hardly any tools that can do better, from what I have known. Perhaps there are some other tools, but I have not had experience with any of them. FireMon Security Manager is one of the best that I have seen so far. However, everyone has their own opinion, and management has their own expectations. They expect a miracle, so I cannot speak for management. We have told them that this tool does a lot of good work and it is very difficult to beat. The reporting features are very stable and reliable. It may not present the appearance of the latest or a shiny tool, as some tools are flashy. This is not the flashy tool, but it does a lot of basic reporting work and allows you to do all the queries. I think FireMon Security Manager is a well-rounded tool.
I have used the reporting capabilities of FireMon Security Manager to communicate risk reduction, compliance status, and the overall security posture to my higher-ups. We use it on a regular basis.