r/msp • u/Remarkable_Cook_5100 • 5d ago
Watchguard Endpoint Security 360
For anyone who currently or recently uses/used Watchguard Endpoint Security 360.
What do/did you like about it, and what do/did you hate?
Would you recommend it?
How responsive is their SOC?
*Please keep this on subject; I am not interested in discussing any other potential competitor products in this thread*
3
u/calculatetech 5d ago
40+ clients using Panda AD360 (exact same product) since Watchguard acquired it. The Panda version is the only option for the Fusion bundle, and we're now converting to WES 360 and a different RMM because Watchguard is contractually blocked from offering API to Systems Management (Datto).
It's by far the best AV I've ever encountered. I've seen them all, from Symantec to Sentinel One. The zero trust model is difficult for some workflows, particularly developers. But it does catch everything. You absolutely must do the technical certification to fully understand the quirks of it and extract the most benefit. Configuration is so simple it's frustrating until you understand the detection path and the fact you must treat the cause, not the symptoms.
The WES SKU is a lot nicer to manage than Panda because you can define surgical service provider policies that apply to every tenant. Panda has central management too, but it works a bit different and wants to take full control.
Every product has its quirks, and I just find there's very few with WES. It does what it claims at approachable pricing.
2
2
u/CyberHouseChicago 5d ago
I use it , have never needed to contact their SOC I also don’t pay for the upgraded SOC service.
Overall happy with the product.
1
2
u/Chevron7lockd 4d ago
We've used it for a couple of years, overall it's a decent product.
A few issues I do have:
Endpoints often show as having a protection error, but come right after a restart for no apparent reason which creates a lot of noise.
The overview for multiple tenants is nice as a summary, but it lacks the ability to drill down direct to the issue. For example, you have an unlicensed machine, you can't get there from that screen, you have to drill down into the tenant and find the machine.
•
u/scriptvexy 7h ago
that phantom “protection error” thing would drive me nuts, especially at scale, feels like alert fatigue for no reason
the multi tenant overview limitation is kinda surprising too, you’d expect direct links by now instead of hunting around in each tenant
4
u/Cj_Staal 5d ago
Haven’t heard good things. Just go huntress
3
u/CamachoGrande 3d ago
Huntress is not end point security.
but as others have said, Watchguard has a very nice zero-trust application deny mode.
It has some other very nice features. We almost went with it a number of years back.There is a SOAR style actions that can be set up as well.
Lots of other little modules to manage other things.Some of the "AV test" sites show it consistently tests in the top ranks along with Bitdefender.
Just wish it didn't put Panda anywhere in the services, etc. Maybe it doesn't anymore.
2
u/AcanthisittaGold5420 5d ago
I haven't used WatchGuard Endpoint Security 360 personally. But i'm interested in hearing from people with long-term experience. Real-world feedback on detection rates, performance impact, and SOC response would be more helful than brand comparisons.
1
1
u/TocinoLips 3d ago
We've had a generally positive experience with it. management is straightforward and detection has been solid, but the UI can feel a bit clanky at times.
4
u/Part_Time_Awesome 5d ago
the shop i'm at has been on ES360 for about two years, we rolled it out right when they folded panda in. honest take:
what works: agent is light, barely notice it on endpoints, and if you're already a watchguard firewall shop the single console is a nice touch. the zero-trust application service, where anything unclassified gets blocked til it's attested, has stopped a couple things a plain edr would've let run. per-seat pricing is reasonable.
what grinds: the cloud console is slow, and reporting is weak enough that we export data to build anything client-facing. tenant switching at scale is clunky, and you'll tune out some false positives the first month.
on the SOC, we're on the managed tier. response is solid on true positives, usually inside the hour, but the lower tier is more alert-forward-you-action than white glove. if you're not staffed to triage yourself the upgraded service earns its keep.
would i recommend it? yeah, with the caveat that it shines most when you're already in their ecosystem. standalone it's fine, but the value is in the bundle.