Report | NSS Labs Enterprise Firewalls Report, 2025 | Check Point Software

Report | NSS Labs Enterprise Firewalls Report, 2025

Q4 2025 | EFW TESTED BY Enterprise Firewall COMPARATIVE TEST REPORT

In Q3 2025, NSS Labs conducted independent evaluations of seven leading Enterprise Firewall offerings using the Enterprise Firewall Test Methodology v3.0. The evaluation covered key performance metrics, including how effectively the firewall protected customers from exploits and malware over encrypted traffic, while also avoiding evasions and triggering false positives, all while remaining stable under enterprise workloads. The firewalls were tested using real-world attack scenarios, enterprise-grade workloads, and adversarial evasion techniques to measure their resilience, reliability, and performance.

Table of Contents

Comparative Security Map (CSM)

Enterprise Firewall (EFW) Rating Security Effectiveness False Positive Accuracy
Check Point CP-CGS-9300 Recommended 99.59% 99.35%
Cisco Firepower 2130 Caution 57.34% 79.94%
Forcepoint 2210 Neutral 99.53% 95.22%
Fortinet FortiGate-200G Caution 79.24% 99.41%
Juniper Networks SRX4300 Recommended 99.16% 98.43%
Palo Alto Networks PA-1410 Caution 46.37% 99.66%
Versa Networks CSG5200 Recommended 99.43% 99.63%

Ratings

The NSS Labs Comparative Security Map (CSM) provides a high-level analysis of empirical data gathered during testing. It conveys the relative capabilities of product offerings by mapping a tested product’s security effectiveness on one axis and false positive accuracy as a measurable proxy for operational overhead on the other.

Executive Summary

Key Findings

Recommendations

  1. Regularly test your security products.
  2. Re-evaluate your network firewall requirements.
  3. Hold Vendors accountable for their test results.
  4. Demand transparency from vendors.

Overview

The test focused on real-world attack techniques and enterprise workloads to evaluate both security, potential operational impact, and performance thoroughly.

Inclusion Criteria

This test was conducted at the request of CyberRatings.org and was not sponsored by any vendor. Decisions regarding the inclusion of a product were based on:

How We Tested

To ensure realistic evaluation, we used:

Security Effectiveness

Implementing a firewall can be complex, with multiple factors affecting security effectiveness, including the ability to protect against common evasion techniques and how well the firewall handles false positives.

Routing & Access Control

Access control is a firewall’s primary responsibility. This test validated that the firewalls enforced security policies over various policy environments, from simple to complex.

TLS/SSL Support

Industry-wide research indicates that encryption now dominates web traffic, with over 95% using HTTPS.

Malware

Malware can appear in many forms, and we evaluated the firewall’s ability to block malware at the point of download across multiple operating systems.

Exploits

We verified the firewall’s ability to detect and block exploits targeting known vulnerabilities, ensuring broad coverage across various attack vectors.

Evasions

Attackers use evasions to conceal malicious activity. Each product starts with a baseline of 100% evasion resistance, and the assigned impact for any missed evasion is subtracted.

False Positive Accuracy

False positives can have serious operational consequences. We tested both inbound and outbound traffic to determine the firewall's ability to discern between legitimate and malicious traffic effectively.

Performance

We tested 55 performance use cases for each product to capture performance curves, including transactions per second and latency.

Rated Throughput

NSS Labs measured sustained throughput over time across a range of packet sizes and connection rates.

Theoretical Maximum Capacity

These tests aimed to determine the maximum concurrent TCP connections with no data passing across the connections.

HTTP Capacity

The goal of this test was to stress the HTTP detection engine and determine how the device copes with network loads of varying average packet sizes and connections.

HTTPS Capacity

This test aimed to stress the HTTPS engine and determine how the device copes with network loads of varying average packet sizes and connections per second.