Report | NSS Labs Enterprise Firewalls Report, 2025 | Check Point Software
Report | NSS Labs Enterprise Firewalls Report, 2025
Q4 2025 | EFW TESTED BY Enterprise Firewall COMPARATIVE TEST REPORT
In Q3 2025, NSS Labs conducted independent evaluations of seven leading Enterprise Firewall offerings using the Enterprise Firewall Test Methodology v3.0. The evaluation covered key performance metrics, including how effectively the firewall protected customers from exploits and malware over encrypted traffic, while also avoiding evasions and triggering false positives, all while remaining stable under enterprise workloads. The firewalls were tested using real-world attack scenarios, enterprise-grade workloads, and adversarial evasion techniques to measure their resilience, reliability, and performance.
Table of Contents
- Comparative Security Map (CSM) 3
- Ratings 4
- SVM vs. CSM: Price, Operational Overhead, and False Positive Accuracy 4
- Executive Summary 5
- Key Findings 5
- Recommendations 5
- Overview 6
- Inclusion Criteria 6
- How We Tested 7
- Security Effectiveness 8
- Routing & Access Control 9
- TLS/SSL Support 10
- Malware 12
- Exploits 13
- Evasions 16
- False Positive Accuracy 18
- Performance 20
Comparative Security Map (CSM)
| Enterprise Firewall (EFW) | Rating | Security Effectiveness | False Positive Accuracy |
|---|---|---|---|
| Check Point CP-CGS-9300 | Recommended | 99.59% | 99.35% |
| Cisco Firepower 2130 | Caution | 57.34% | 79.94% |
| Forcepoint 2210 | Neutral | 99.53% | 95.22% |
| Fortinet FortiGate-200G | Caution | 79.24% | 99.41% |
| Juniper Networks SRX4300 | Recommended | 99.16% | 98.43% |
| Palo Alto Networks PA-1410 | Caution | 46.37% | 99.66% |
| Versa Networks CSG5200 | Recommended | 99.43% | 99.63% |
Ratings
The NSS Labs Comparative Security Map (CSM) provides a high-level analysis of empirical data gathered during testing. It conveys the relative capabilities of product offerings by mapping a tested product’s security effectiveness on one axis and false positive accuracy as a measurable proxy for operational overhead on the other.
Executive Summary
Key Findings
- Test Results point to how attackers are bypassing defenses. While average exploit and malware block rates exceeded 96%, three widely deployed vendors failed critical evasion tests that significantly reduced their effectiveness. Only three of seven products earned a Recommended rating.
- Evasion test results are alarming. The fact that well-known transport and network layer evasions were able to bypass some of the most widely held security products should be concerning. Attackers use evasion techniques to bypass security defenses.
- Encrypted traffic contains attacks. Protecting against attacks within encrypted traffic is the true test of firewall performance, as more than 95% of global web traffic is now encrypted.
- High accuracy is essential to avoid wasted resources, user disruption, and reduced trust in security. One product recorded a below-average 80% false positive accuracy rate.
Recommendations
- Regularly test your security products.
- Re-evaluate your network firewall requirements.
- Hold Vendors accountable for their test results.
- Demand transparency from vendors.
Overview
The test focused on real-world attack techniques and enterprise workloads to evaluate both security, potential operational impact, and performance thoroughly.
Inclusion Criteria
This test was conducted at the request of CyberRatings.org and was not sponsored by any vendor. Decisions regarding the inclusion of a product were based on:
- Market presence
- Identification by industry analysts covering the specific technology area
- Consumer requests
- Innovative technology/offering or marketing claims that receive significant market attention
How We Tested
To ensure realistic evaluation, we used:
- False Positives: 6,481 samples from business-critical files.
- Exploits: 3,326 attack samples from widely exploited vulnerabilities.
- Malware: 11,311 samples sourced from active malware campaigns.
- Evasion Techniques: 5,752 attack variations spanning multiple evasion categories.
Security Effectiveness
Implementing a firewall can be complex, with multiple factors affecting security effectiveness, including the ability to protect against common evasion techniques and how well the firewall handles false positives.
Routing & Access Control
Access control is a firewall’s primary responsibility. This test validated that the firewalls enforced security policies over various policy environments, from simple to complex.
TLS/SSL Support
Industry-wide research indicates that encryption now dominates web traffic, with over 95% using HTTPS.
Malware
Malware can appear in many forms, and we evaluated the firewall’s ability to block malware at the point of download across multiple operating systems.
Exploits
We verified the firewall’s ability to detect and block exploits targeting known vulnerabilities, ensuring broad coverage across various attack vectors.
Evasions
Attackers use evasions to conceal malicious activity. Each product starts with a baseline of 100% evasion resistance, and the assigned impact for any missed evasion is subtracted.
False Positive Accuracy
False positives can have serious operational consequences. We tested both inbound and outbound traffic to determine the firewall's ability to discern between legitimate and malicious traffic effectively.
Performance
We tested 55 performance use cases for each product to capture performance curves, including transactions per second and latency.
Rated Throughput
NSS Labs measured sustained throughput over time across a range of packet sizes and connection rates.
Theoretical Maximum Capacity
These tests aimed to determine the maximum concurrent TCP connections with no data passing across the connections.
HTTP Capacity
The goal of this test was to stress the HTTP detection engine and determine how the device copes with network loads of varying average packet sizes and connections.
HTTPS Capacity
This test aimed to stress the HTTPS engine and determine how the device copes with network loads of varying average packet sizes and connections per second.