
Overview
Hyper Scale Security for your Hyper Scalable Clouds Whether your data and applications are stored on premises, in the data center, or public clouds (or a combination of all three), organizations still need to meet their requirements of security, control, compliance, and governance by themselves. The on-demand nature of public clouds such as AWS naturally means that workloads move and regroup, where maintaining continuous visibility and control over the rapid changes calls for expert intervention. Common security challenges include: Centralized visibility and threat management for your hybrid environment Deploy applications and workloads securely Manage access & control privileges to cloud and on-premises workloads Secure data transfer, data migrations Accomplish all of the security deployments at the pace and scale demanded by cloud architectures
Highlights
- FireMon can easily create, maintain, and distribute policies in highly dynamic networks, as well as scope the impact of proposed changes to your security. By automating & orchestrating, Security Manager ensures your ability to operate at scale across cloud, virtual and hybrid environments.
- Through traffic flow analysis, FireMon tracks behavior across your network to identify which applications are being used. You can correlate vulnerability scans with access path analysis to trace every available path across the network to reduce your attack surface with a defined remediation.
- Automated compliance assessments help you validate your configuration requirements and alert you to violations. Security Manager out-of-the-box audit ready and customizable reports saves time and gives you the confidence to meet your regulatory and internal security demands.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
Please see seller website for refund details.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Additional details
Usage instructions
Before launch, in the AMI configuration settings, you must add additional volume to prevent launch failure.
Add Storage tab, click Add New Volume and in the Size field enter at least 600. Do not change the Root Volume Type.
Complete FMOS Initial Setup after launch:
- Open a web browser.
- Navigate to https://<hostname>:55555/setup, replacing <hostname> of the SIP instance running in AWS with the IP or the hostname.
- In the Authentication dialog box-Username is fmosadmin- Password is the EC2 Instance ID- Click Submit
- After authenticating, complete the required fields in the FMOS Initial Setup form. The username is read-only and cannot be changed, but you can update the password.
- After submitting the FMOS Initial Setup form, FMOS will begin the deployment process.Log in to SIP after deployment:
- Open a web browser tab.
- Enter the IP address of your SIP/AWS instance.
- Enter your username and password.
- Username is firemon (case-sensitive)
- Password is the MAC address for the instance
- Click Log in. For details, see: https://www.firemon.com/wp-content/uploads/AWS-AMI-Launch-and-FMOS-Install.pdf
CF template Usage Instruction: 1.Go to AWS marketplace subscription and Launch cloud formation teamplate. 2.Choose Action 'Launch Cloud formation' and click on Launch 3.Enter Stack Name. 4.Enter all mandatory fields in Parameters. VPC ID Subnet ID Instance Type Key Pair Name IP address Volume Size FMOS username 5.Specify Ecosystem in "Machine Configuration". 6.Add Organization Name. 7.Click Next. 8.Review: Review all sections entered and click Next. 9.A new stack with above Stack Name is created with status "CREATE_COMPLETE". 10.Go to EC2 Dashboard, a new instance is created. 11.After the deployment process completes, you can log in to Security Intelligence Platform to continue setting up your network, such as adding users and devices. a. Open another browser tab. b. Enter the IP address of your AWS instance, For example, https://<hostname_or_IPaddress>;. c. Enter your username and password: Username is firemon (case-sensitive) Password is the MAC address for the instance with colons removed and lowercase letters instead of uppercase letters. For example, a MAC address of 00:05:95:A1:2B:CC would be 000595a12bcc. This is a one-time password to use at first installation and will need to be reset after initial login. Click Log In
Resources
Support
Vendor support
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products
Customer reviews
Centralized policy visibility has transformed how I manage compliance and firewall rule changes
What is our primary use case?
Our customers have different use cases with FireMon, and I won't disclose names. They want a tool that offers a single pane of glass for rule set visibility, understanding policy compliance, and how compliant they are with various policies such as HIPAA, PCI DSS, or NIST. Another use case involves Security Manager rather than Policy Planner and Policy Optimizer, as these are designed for change automation.
Regarding centralized visibility of firewall rules across multiple vendors for a customer, they sometimes want to know who owns a particular rule, its function, and its deployment location. For risk and compliance, the focus is on identifying risky firewall rules and assessing them against organizational standards. Additionally, they use network path analysis to understand connections between applications, which aids network security teams in troubleshooting.
What is most valuable?
FireMon Security Manager acts as a network security policy management layer above core infrastructures, offering centralized policy visibility across platforms including Palo Alto, Fortinet, and Check Point. It interfaces with ITSM tools, facilitating workflow automation. However, it complements rather than replaces existing security technologies.
Transitioning from a manual and time-consuming process to one utilizing Policy Planner and Optimizer has improved visibility and confidence in policy changes, reducing manual efforts, and enhancing governance and auditability.
What needs improvement?
The console GUI disappoints me because it lacks customization. I cannot remove or add widgets, similar to how iPhone locks app placements. The non-customizable dashboard annoys me as it shows unwanted information. However, Insights with AI integration offers customizable dashboard visibility once opted in, which addresses this limitation.
For how long have I used the solution?
I have been with the company for twenty-two years, and with FireMon Security Manager, I have been using it for around two years now.
What do I think about the stability of the solution?
A specific collector issue affected traffic log collection and config retrieval. It was not a total crash, but a process issue. This is the first occurrence in two years, and we are working on pinpointing the problem. Overall, I rate the stability at nine out of ten.
What do I think about the scalability of the solution?
FireMon Security Manager uniquely supports Strata Cloud Manager for Prisma Palo Alto devices and facilitates Azure firewall configurations and Illumio integrations. It integrates with various solutions such as ServiceNow, SIEM, or SOAR, showcasing superior integration and scalability among vendors.
How are customer service and support?
As a user for two years, I recently opened my first case with FireMon's technical support, which was handled promptly. Unlike other vendors with long response times, FireMon's support quickly engaged, offering screen sharing sessions to resolve issues efficiently. I have found their support exemplary.
Which solution did I use previously and why did I switch?
I have experience working with several network security policy management solutions, including Tufin, AlgoSec, and previously Skybox. Skybox offered a high degree of dashboard customisation, but the company subsequently went into liquidation in February 2025. Tufin and AlgoSec both have their own strengths, and my experience with FireMon has led me to favour it for my current requirements, particularly around centralised policy visibility, compliance, policy management, and integration capabilities.
How was the initial setup?
Initial deployment is extremely easy. If a connector issue arises, FireMon sends a device pack to address specific issues, avoiding full software upgrades. This expedites resolutions, such as with Check Point or Fortinet firewalls. Furthermore, bulk uploading capabilities streamline implementation without management stations.
What's my experience with pricing, setup cost, and licensing?
What other advice do I have?
I regularly design, deploy, and support FireMon Security Manager instances, receiving daily reports. These reports are valuable for customers, particularly for C-level presentations, offering insights into compliance, security, and change activities. I give FireMon Security Manager a rating of ten out of ten. I have worked with many solutions, including Skybox, Tufin, AlgoSec, Check Point, and Palo Alto, but FireMon Security Manager truly stands out for its willingness to assist quickly.
Centralized rule analysis has streamlined multi-vendor firewall audits and risk reporting
What is our primary use case?
We use FireMon Security Manager for managing the rule base on our various multi-vendor firewalls.
We did not use the policy manager, but with FireMon Security Manager, we checked for logging disabled. We used overly permissive features and ran SQL queries to find the overly permissive rules and conducted remediation based on those findings. We ran FQDN queries to find out which rules were using FQDN instead of URL filtering. Without FireMon Security Manager, the vendor did not have any such features, so FireMon Security Manager was the only tool we could use to get our retrievals. We use CLI scripts and GUI, both of which are doing something that no other tool can do as far as we have seen.
What is most valuable?
What I like the most about FireMon Security Manager is that it can go across a whole rule base and get the items we need, like rules that have a specific characteristic, such as logging disabled, and we can find which rules are there that match that criteria for any vendor. It can do this very quickly. Whereas, if we have to log into all the vendor websites and try to get access to all the infrastructure for every single vendor separately, it is a very time-consuming task. We can export results in CSV, and there are some good features that we can use right away.
What needs improvement?
What I dislike about FireMon Security Manager is that I use the Insights add-on option, which does add a visual dashboard. I would prefer more of a visual dashboard that I can customize. Right now, we have the visual dashboard in Security Manager, but it is not customizable, and the same applies to Insights. The AI feature is very useful in Insights, but the visual dashboard which can be customized is not there to track our progress if we are trying to mitigate any security blind spots.
I mention more customizable visual dashboards because every organization has different priorities. Sometimes our management asks us to prioritize and look for different items, and suddenly they change the direction. If you have a tool that does not customize a dashboard, then you cannot make graphs or visually represent over the past three months or six months how we have progressed. Have we gotten worse or better?
I think the pricing for FireMon Security Manager is fair. However, it could be better if you could have more customization options, such as medium and large firewalls. You could have different categories; small firewalls exist, but medium is no longer in the licensing. That would help save money.
FireMon Security Manager requires maintenance on my end. We have to pull retrievals, and the retrievals fail many times, and sometimes they succeed. Sometimes we have to investigate, troubleshoot, and do packet captures. There is a lot of work that management does not understand, and it is very difficult to convince them that we are actually working. They do not realize that we are actually working on many tasks just to keep things running and pulling reports. We need fresh retrievals, and sometimes things break. We have to remove devices and add devices. It is very difficult to portray to management that we are actually working, and it takes a lot of effort to manage the database server and keep things running smoothly and update licenses. A lot of background effort is involved, though it does not appear that way to management. It is very difficult to convey the efforts involved at performance evaluation time.
I have just used Panorama with FireMon Security Manager. However, my colleagues have used other tools, and they said there are advantages and disadvantages in every tool. FireMon Security Manager is a very good tool to do what we want to do, but it can be improved, as can every other tool.
For how long have I used the solution?
I have been using FireMon Security Manager in my career overall for about four years.
What do I think about the stability of the solution?
I think stability is very good. FireMon Security Manager is pretty stable. Sometimes we had issues, but we resolved those issues and restarted the server. That part is good.
What do I think about the scalability of the solution?
I think scalability with FireMon Security Manager is pretty easy.
How are customer service and support?
Our TAM helped us a lot and was very useful to have. He customized many features that were not customizable. He wrote custom scripts and did a great job customizing everything and keeping our management happy. We had very customized requests, and since we could not customize anything, our TAM helped us maneuver around the rigid dashboard display limitations. He wrote custom Python scripts and did a lot of effort behind the scenes. I am not even aware of how much effort he took to do all that work.
Which solution did I use previously and why did I switch?
I have just used Panorama with FireMon Security Manager. My colleagues have used other tools, and they said there are advantages and disadvantages in every tool. FireMon Security Manager is a very good tool to do what we want to do, but it can be improved, as can every other tool.
How was the initial setup?
I was not there when they did the initial deployment of FireMon Security Manager, but I was involved in an upgrade, and the upgrade went smoothly.
What about the implementation team?
I was not there when they did the initial deployment of FireMon Security Manager, but I was involved in an upgrade, and the upgrade went smoothly. Our TAM helped us a lot and was very useful to have.
Which other solutions did I evaluate?
I have just used Panorama with FireMon Security Manager. My colleagues have used other tools, and they said there are advantages and disadvantages in every tool. FireMon Security Manager is a very good tool to do what we want to do, but it can be improved, as can every other tool.
What other advice do I have?
Overall, I would say FireMon Security Manager is hard to beat, except the AI features have been recently introduced in Insights. I would rate FireMon Security Manager 9 out of 10. There are hardly any tools that can do better, from what I have known. Perhaps there are some other tools, but I have not had experience with any of them. FireMon Security Manager is one of the best that I have seen so far. However, everyone has their own opinion, and management has their own expectations. They expect a miracle, so I cannot speak for management. We have told them that this tool does a lot of good work and it is very difficult to beat. The reporting features are very stable and reliable. It may not present the appearance of the latest or a shiny tool, as some tools are flashy. This is not the flashy tool, but it does a lot of basic reporting work and allows you to do all the queries. I think FireMon Security Manager is a well-rounded tool.
I have used the reporting capabilities of FireMon Security Manager to communicate risk reduction, compliance status, and the overall security posture to my higher-ups. We use it on a regular basis.
Automation for firewall changes has improved, but integration delays still limit daily use
What is our primary use case?
The intended use case is to have every firewall opening ticket processed through FireMon Security Manager. To accomplish this, we need to integrate it with ITSM, a ServiceNow tool, which is currently not implemented on our side. We have been waiting for this integration for a very long time and are awaiting support from FireMon Security Manager team to work with us and integrate it into our ITSM system. Currently, the way we would use it would be to manually enter all the data into FireMon Security Manager and then run it over, but this does not save us any time, so we are not currently doing that.
We have the topology built and are using FireMon Security Manager from time to time, but not for every use case. We sometimes use it for topology checks and rule verification, so we are using the secondary functions rather than the main function. The ideal scenario would be to have users enter information into ServiceNow that would be automatically populated to FireMon Security Manager, and then FireMon Security Manager would push the changes.
We are currently in the middle of changing our infrastructure. Previously, when we purchased FireMon Security Manager, we were using Cisco ASAs. Now we are migrating to FTD and next-generation firewalls from Cisco, and those devices are not yet integrated. Our engineer is working with the system, and we are seeking help from FireMon Security Manager in order to assist us with this transition.
What is most valuable?
AlgoSec is another tool we considered, as Tufin is a popular comparison. However, FireMon Security Manager is cheaper and fits well with our needs. The logic of these tools is mostly the same, with differences coming down to specific extra features available with each one.
What needs improvement?
Waiting one year to get help is unacceptable, particularly regarding the new setup and integration with ServiceNow. We need to pay extra for it, and it is frustrating to wait for an engineer from FireMon Security Manager to assist us.
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
From their side, there was one person, and if he had some issues, he was reaching out to the developers to solve the problems we faced. This implies a level of dependency on their internal team which can cause delays.
Better support is needed as waiting a year for assistance is way too long. We have known we wanted this setup from the start, but it has not integrated as expected.
Which solution did I use previously and why did I switch?
We were also considering AlgoSec, which has similar logic to FireMon Security Manager and Tufin. However, slight differences exist in potential extra features or what they support, but nothing was significant enough to impact our decision.
How was the initial setup?
I remember the timeframe for fully implementing it from start to finish was three to six months.
What about the implementation team?
What was our ROI?
What's my experience with pricing, setup cost, and licensing?
AlgoSec and Tufin were also evaluated by us along with their pricing.
Which other solutions did I evaluate?
If comparing them, depending on the use case and device compatibility, all three could potentially meet our needs.
What other advice do I have?
I do not want to blame FireMon Security Manager for this because our failure to use it is partially their fault. They are not giving us the engineer support we need.
We view this as a new setup issue requiring financial support. This is not directly a support problem for an existing issue, but more about expected availability to facilitate implementation.
My overall review rating for FireMon Security Manager is seven.