Experiences with gateways?

4 views
Skip to first unread message

Kurt Buff

unread,
Nov 2, 2023, 12:05:54 PM11/2/23
to ntexc...@googlegroups.com
We're coming up the expiration of our Mimecast subscription - we're not happy with it and looking to move on.

We've done PoCs for Proofpoint and Check Point (Avanon).

Anyone have comments on either of the ones we're considering?

I like that PP has phishing campaigns and security training that can be bundled, and I like that CP seems to have good integration with their other products and a better approach to investigations and analysis.

Any pitfalls you've run across with either product?

Kurt

Philip Elder

unread,
Nov 2, 2023, 1:36:39 PM11/2/23
to ntexc...@googlegroups.com

We’ve been using Proofpoint for years now. It works really well and when it doesn’t support has been on the ball.

 

Philip Elder MCTS

Senior Technical Architect

Microsoft High Availability MVP

E-mail: Phili...@mpecsinc.ca

Phone: +1 (780) 458-2028

Web: www.mpecsinc.com

Blog: blog.mpecsinc.com

Twitter: Twitter.com/MPECSInc

Skype: MPECSInc.

 

Please note: Although we may sometimes respond to email, text and phone calls instantly at all hours of the day, our regular business hours are 8:00 AM - 5:00 PM, Monday thru Friday.

--
You received this message because you are subscribed to the Google Groups "ntexchange" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ntexchange+...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntexchange/CADy1Ce7L5SzeMXd8mAocMei_-v5j%3DUn5dCT40mQVxJ_L9uOTAw%40mail.gmail.com.

Kurt Buff

unread,
Nov 2, 2023, 2:34:15 PM11/2/23
to ntexc...@googlegroups.com
Thanks. I remember your mentions of appreciation from earlier discussions.

Kurt

Michael B. Smith

unread,
Nov 2, 2023, 5:23:23 PM11/2/23
to ntexc...@googlegroups.com
I switched to proofpoint for smithcons at the beginning of September. I also use mimecast, proofpoint, and barracuda daily for clients.

IMHO, proofpoint wins, hands down, for ease of configuration and value delivered.

However, if you've got complex configurations I think mimecast makes those slightly easier.

For end users, I think that mimecast slightly wins because of the Outlook plugin. But I also don't see it as a big deal. 

Functionality-wise, mimecast and proofpoint are darn close.

Personally, I am not a fan of barracuda and unfortunately I have no experience with avanon.

All IMHO.


From: ntexc...@googlegroups.com <ntexc...@googlegroups.com> on behalf of Kurt Buff <kurt...@gmail.com>
Sent: Thursday, November 2, 2023 12:05:15 PM
To: ntexc...@googlegroups.com <ntexc...@googlegroups.com>

Subject: [ntexchange] Experiences with gateways?

Kurt Buff

unread,
Nov 2, 2023, 5:40:47 PM11/2/23
to ntexc...@googlegroups.com
Apparently they switched from PP to mimecast a couple of years before I got here because PP wanted to increase prices.

Since we're using a couple of other Check Point products, licensing their newly-acquired Avanon would give us a significant price break across all of their products, and I must say their demo/PoC was very nice.

Gartner has a comparison, FWIW.

Michael B. Smith

unread,
Nov 2, 2023, 6:32:04 PM11/2/23
to ntexc...@googlegroups.com

Looks like either would work for you.

 

Kurt Buff

unread,
Nov 2, 2023, 6:47:36 PM11/2/23
to ntexc...@googlegroups.com
That's my thought, which is why I was looking for experiences and opinions to see if real life is different from Gartner opinions and our PoCs.

Right now, we're leaning toward Check Point because of the integrations, and the lower pricing available as we stack their products.

We'll be making our decision before the end of next week.

Kurt

Bonnie Pohlschneider

unread,
Nov 3, 2023, 7:01:14 AM11/3/23
to ntexc...@googlegroups.com

The only thing we're not happy with ProofPoint is their price. They are expensive, but we haven't found a product yet that will do everything PP can. My team's sanity and my company's security are worth the price tag. Would be happy to chat if you want more info Kurt.

 

Bonnie Pohlschneider
Information Technology Director, CRSI
Phone 937-653-1317Fax 937-653-1321
www.crsi-oh.com

From: ntexc...@googlegroups.com <ntexc...@googlegroups.com> On Behalf Of Kurt Buff
Sent: Thursday, November 2, 2023 6:47 PM
To: ntexc...@googlegroups.com
Subject: Re: [ntexchange] Experiences with gateways?

 

That's my thought, which is why I was looking for experiences and opinions to see if real life is different from Gartner opinions and our PoCs. Right now, we're leaning toward Check Point because of the integrations, and the lower pricing

Kurt Buff

unread,
Nov 3, 2023, 10:56:33 AM11/3/23
to ntexc...@googlegroups.com
Thanks for the offer - if our team has questions, I'll send you a message.

Thanks,
Kurt

Philip Elder

unread,
Nov 6, 2023, 12:28:07 AM11/6/23
to ntexc...@googlegroups.com

I don’t see the Outlook plug-in as being any more useful than the daily quarantine report that comes in to the user’s Inbox. IMO of course.

 

Philip Elder MCTS

Senior Technical Architect

Microsoft High Availability MVP

E-mail: Phili...@mpecsinc.ca

Phone: +1 (780) 458-2028

Web: www.mpecsinc.com

Blog: blog.mpecsinc.com

Twitter: Twitter.com/MPECSInc

Skype: MPECSInc.

 

Please note: Although we may sometimes respond to email, text and phone calls instantly at all hours of the day, our regular business hours are 8:00 AM - 5:00 PM, Monday thru Friday.

 

Michael B. Smith

unread,
Nov 6, 2023, 7:50:02 AM11/6/23
to ntexc...@googlegroups.com

I agree with you. I got a bunch of lawyers that disagree. And they pay the invoice…. 😊

Kurt Buff

unread,
Nov 6, 2023, 7:59:43 AM11/6/23
to ntexc...@googlegroups.com
The plugin is for items that made it io the inbox - the quarantine report is for items that didn't make it to the inbox..

But, aside from that, this place has had a button since before I got here, and it would cause some unhappiness if there weren't one.

Kurt

Miller, Jon

unread,
Nov 6, 2023, 9:13:05 AM11/6/23
to ntexc...@googlegroups.com

We are a Mimecast shop and I have been wondering if it’s time to drop Mimecast and just use the built-in Microsoft online protections.  Has anyone on the list taken that plunge?



This message and any attachments may contain legally privileged or confidential information, and are intended only for the individual or entity identified above as the addressee. If you are not the addressee, or if this message has been addressed to you in error, you are not authorized to read, copy, or distribute this message and any attachments, and we ask that you please delete this message and attachments (including all copies) and notify the sender. Delivery of this message and any attachments to any person other than the intended recipient(s) is not intended in any way to waive confidentiality or a privilege. All personal messages express views only of the individual sender, and may not be copied or distributed without this statement.

Kurt Buff

unread,
Nov 6, 2023, 9:17:51 AM11/6/23
to ntexc...@googlegroups.com
I can't tell you that.

We went through a full Proof of Concept with both Proofpoint and Check Point (they took different approaches, but neither interfered with the way we had Mimecast set up.

What I can tell you is that we couldn't get anything like a PoC with MSFT EOP. We got a few minutes with a talking head.

Also, we don't have much in the way of Azure licensing - no P1/P2, and to make EOP work we'd need to spend lots more money.

Might be the best thing in the world, but you couldn't prove it by me.

Kurt

Jim Kennedy

unread,
Nov 6, 2023, 11:13:22 AM11/6/23
to ntexc...@googlegroups.com

We used MS’s online protections, they were not good. In fact they were really bad. We bought Proofpoint to replace it.

 

From: 'Miller, Jon' via ntexchange <ntexc...@googlegroups.com>
Sent: Monday, November 6, 2023 9:13 AM
To: ntexc...@googlegroups.com

To view this discussion on the web visit https://groups.google.com/d/msgid/ntexchange/DS0PR20MB56618185D12A12B5E22D4FA0ADAAA%40DS0PR20MB5661.namprd20.prod.outlook.com.

CAUTION: This email originated from outside of the organization. Do not click any links or open any attachments unless you trust the sender and know the content is safe.

Philip Elder

unread,
Nov 6, 2023, 1:24:37 PM11/6/23
to ntexc...@googlegroups.com

Never argue with the money. ;0)

 

Ever …

 

Philip Elder MCTS

Senior Technical Architect

Microsoft High Availability MVP

E-mail: Phili...@mpecsinc.ca

Phone: +1 (780) 458-2028

Web: www.mpecsinc.com

Blog: blog.mpecsinc.com

Twitter: Twitter.com/MPECSInc

Skype: MPECSInc.

 

Please note: Although we may sometimes respond to email, text and phone calls instantly at all hours of the day, our regular business hours are 8:00 AM - 5:00 PM, Monday thru Friday.

 

Philip Elder

unread,
Nov 6, 2023, 1:34:37 PM11/6/23
to ntexc...@googlegroups.com

🤮

 

I can’t count the number of times we’ve hit vapourware with their SPAM service.

 

Send it and POOF it’s gone. When that happens I check the MX for the domain and sure enough there’s O365.

 

No NDR, no reply, and no way for the recipient to figure out where it is.

 

Proofpoint, and others mentioned, give us full control over incoming mail.

 

We’ve put Proofpoint in front of O365/M365 and turned their services off because it’s so bad.

 

Philip Elder MCTS

Senior Technical Architect

Microsoft High Availability MVP

E-mail: Phili...@mpecsinc.ca

Phone: +1 (780) 458-2028

Web: www.mpecsinc.com

Blog: blog.mpecsinc.com

Twitter: Twitter.com/MPECSInc

Skype: MPECSInc.

 

Please note: Although we may sometimes respond to email, text and phone calls instantly at all hours of the day, our regular business hours are 8:00 AM - 5:00 PM, Monday thru Friday.

 

Michael B. Smith

unread,
Nov 6, 2023, 3:02:44 PM11/6/23
to ntexc...@googlegroups.com

You can disable the “IP reputation service”, similar to what you can do with PP and Mimecast, to remove that behavior.

 

(I’m not promoting EOP – it’s probably the cheapest thing out there and you get what you pay for – I just wanted to address this specific issue.)

 

I’ve got quite a few clients using EOP, but I don’t recommend it.

Philip Elder

unread,
Nov 6, 2023, 3:08:52 PM11/6/23
to ntexc...@googlegroups.com

Most of the folks that this happens with have no clue how to manage their own subscription.

 

Philip Elder MCTS

Senior Technical Architect

Microsoft High Availability MVP

E-mail: Phili...@mpecsinc.ca

Phone: +1 (780) 458-2028

Web: www.mpecsinc.com

Blog: blog.mpecsinc.com

Twitter: Twitter.com/MPECSInc

Skype: MPECSInc.

 

Please note: Although we may sometimes respond to email, text and phone calls instantly at all hours of the day, our regular business hours are 8:00 AM - 5:00 PM, Monday thru Friday.

 

Kurt Buff

unread,
Nov 9, 2023, 1:13:28 PM11/9/23
to ntexc...@googlegroups.com
All,

We've finished our review process, and as I expected the Check Point product has won.

Proof Point scored marginally higher on the technical grounds on which we scored, but was nearly double for cost.

One thing that CP recommends is to turn up EOP in front of their product (they use an API integration at the back end).

We've not turned up EOP while using Mimecast (with the exception of some DLP notifications), and there looks to be a lot of config that can be done with it.

Can anyone speak to what in your experience should, and perhaps more importantly what shouldn't, be configured with EOP?

We haven't found an actual spreadsheet of the settings in EOP, so one of our guys is generating one from an HTML list to be shared internally, and we'll be scoring based on that.

Thanks,
Kurt

Michael B. Smith

unread,
Nov 10, 2023, 7:29:50 PM11/10/23
to ntexc...@googlegroups.com

All of it?

 

What exactly does CP do? I think that’s really the question and defines the limit of what you configure in EOP.

 

--

You received this message because you are subscribed to the Google Groups "ntexchange" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ntexchange+...@googlegroups.com.

Kurt Buff

unread,
Nov 10, 2023, 9:48:23 PM11/10/23
to ntexc...@googlegroups.com
the theory is that EOP catches the easy stuff, and CP catches the more difficult stuff.

Kurt

Michael B. Smith

unread,
Nov 11, 2023, 8:47:31 AM11/11/23
to ntexc...@googlegroups.com
I look forward to you telling us about this in a couple of months 😀

But based on that, my "all of it" seems like the right answer.
Sent: Friday, November 10, 2023 9:48:07 PM
To: ntexc...@googlegroups.com <ntexc...@googlegroups.com>
Subject: Re: [ntexchange] Re: Experiences with gateways?
 

Kurt Buff

unread,
Nov 11, 2023, 12:13:32 PM11/11/23
to ntexc...@googlegroups.com
Turning on all of the EOP settings only makes sense if it has a very
good False Positive/False Negative rate, and from comments I've seen
here and elsewhere, that might not be the case.

What's your experience with it?

OTOH, Check Point hass introduced an enhancement that allows them to
retrieve quarantined emails from EOP as well as their own quarantine,
which should prove useful.

Regardless, yes, I intend to provide some detail about our experience
- our Mimecast contract ends mid-January, so by April I should have
more to say.

Kurt
> To view this discussion on the web visit https://groups.google.com/d/msgid/ntexchange/SJ0PR05MB73432F2921CECA344381CF72FFADA%40SJ0PR05MB7343.namprd05.prod.outlook.com.
Reply all
Reply to author
Forward
0 new messages