We use Cisco IOS Security for security functions like firewalls and IPS in specific remote branches.
Senior Network Security Engineer at a tech services company with 10,001+ employees
A scalable solution that can be used for security functions like firewalls and IPS
Pros and Cons
- "Cisco IOS Security increases the overall security of our network, performs authentication, and provides level 15 access and privileges."
- "Cisco IOS Security should improve its functionalities."
What is our primary use case?
How has it helped my organization?
Cisco IOS Security enables communication between our network nodes. The solution provides authentication like policy enforcement, QOS, and intelligent routing. We use Cisco IOS Security for administration purposes.
What is most valuable?
Cisco IOS Security increases the overall security of our network, performs authentication, and provides level 15 access and privileges.
What needs improvement?
Cisco IOS Security should improve its functionalities.
Buyer's Guide
Cisco IOS Security
January 2025
Learn what your peers think about Cisco IOS Security. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
For how long have I used the solution?
I have been using Cisco IOS Security for more than four years.
What do I think about the scalability of the solution?
I rate Cisco IOS Security a nine out of ten for scalability.
How are customer service and support?
The solution's technical support is good. I rate the solution's technical support eight and a half out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
The solution's initial setup is straightforward.
What was our ROI?
We have seen a return on investment with Cisco IOS Security.
What's my experience with pricing, setup cost, and licensing?
The solution's pricing is very good.
What other advice do I have?
Overall, I rate Cisco IOS Security a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Solution Architect at Zak Solution
Scalable solution with good technical support services
Pros and Cons
- "The solution is stable."
- "The solution’s setup process could be better."
What is our primary use case?
We use the solution to secure data centres for clients.
What is most valuable?
The solution has the best features for routers embedded with firewall capabilities. It helps us protect the network.
What needs improvement?
The solution’s setup process could be better. It is complex regarding troubleshooting, and only highly skilled engineers can resolve it.
For how long have I used the solution?
We have been using the solution for 15 years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
It is a scalable solution. We have more than 100 clients using the solution.
How are customer service and support?
The solution's technical support is excellent. The team includes certified engineers.
How was the initial setup?
The solution's initial setup process is easy if you are highly skilled in handling the troubleshooting part. The deployment takes around two to three weeks, depending on the requirements.
What's my experience with pricing, setup cost, and licensing?
We can purchase the solution's licenses as per specific business requirements.
What other advice do I have?
The solution provides a robust system. I advise others to understand the technology to use the system with ease.
I rate it a ten out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Cisco IOS Security
January 2025
Learn what your peers think about Cisco IOS Security. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
Senior Sales Engineer at Ingram Micro
A stable and scalable firewall solution
Pros and Cons
- "We use the product for firewalls."
- "We cannot directly upgrade the system. The tool's deployment is also very difficult in legacy environments. The tool needs to have bigger ports as well."
What is our primary use case?
We use the product for firewalls.
What needs improvement?
We cannot directly upgrade the system. The tool's deployment is also very difficult in legacy environments. The tool needs to have bigger ports as well.
For how long have I used the solution?
I have been working with the product for four years.
What do I think about the stability of the solution?
The product is stable.
What do I think about the scalability of the solution?
The tool is scalable.
How was the initial setup?
The tool's deployment takes around thirty minutes to complete.
What's my experience with pricing, setup cost, and licensing?
The tool could be priced lower. If you want advanced services, then you need to purchase them.
What other advice do I have?
Most of our customers are from the banking and financial domain. I have chosen the product after a thorough comparison and reading through whitepapers.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Business Development Manager at Odxs
Very highly scalable and an effective Umbrella integration for tech analysis
Pros and Cons
- "The solution effectively integrates with Umbrella."
- "The solution is not user friendly and it is hard to manage the GUI interface."
What is our primary use case?
Our company uses the solution as intrusion protection for customers. It fully integrates with the BMA and ISE. We manage all traffic in data centers to protect them from internal users and outside traffic.
What is most valuable?
The solution effectively integrates with Umbrella which has an intelligent background and is very helpful in tech analysis or discovery.
What needs improvement?
The solution is not user friendly and it is hard to manage the GUI interface. This is an ongoing CISCO problem.
The solution needs Active/Active firewalls to have good load balance with high availability. The firewalls should work simultaneously, not just as failovers.
For how long have I used the solution?
I have been using the solution for ten years.
What do I think about the stability of the solution?
The solution is very stable if configured properly. I rate stability a nine out of ten.
What do I think about the scalability of the solution?
The solution is very highly scalable and other products really don't compete with its scalability. The solution can easily be used for small companies or big enterprises with thousands of users. I rate scalability an eight out of ten.
How are customer service and support?
Technical support does not have a broad knowledge base, so I rate them a six out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
The setup is better than before but still not easy or clear like Palo Alto. If you want to configure the solution, then you need to study how to do it.
The setup is difficult so I rate it a six out of ten.
What about the implementation team?
We implement the solution for customers on our own unless we have an issue or bug. It takes one expert staff person for deployment. Depending on the customer's policies and the network's complexity, deployment might take from three to seven days.
Our process includes verifying the license and setting up the firewall, hardware, FMC, and the failover when there is more than one firewall. We then define or set up the configurable interfaces and the IP addresses. Finally, we define the VLAN of the customer and policies for each VLAN.
The solution does not require ongoing maintenance if it is configured properly.
What was our ROI?
Our ROI is that the solution saves time because it reduces attacks and helps with ongoing protection. The subscription model is also very helpful for ROI.
I rate ROI at 1800%.
What's my experience with pricing, setup cost, and licensing?
The pricing is average and includes all features with support. I rate pricing a six out of ten.
Which other solutions did I evaluate?
Palo Alto has a better GUI interface for handling all features and is easier to configure.
What other advice do I have?
I recommend the solution and rate it an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Network Administrator at MP Tech
Has good scalability, but its technical support services need improvement
Pros and Cons
- "The product has valuable features for business intelligence."
- "The product's technical support services need improvement."
How has it helped my organization?
Cisco IOS Security helps us with splitting the DNS between a specific perimeter.
What is most valuable?
The product has valuable features for business intelligence. It enables intrusion detection for the network.
What needs improvement?
The product's technical support services need improvement.
For how long have I used the solution?
We have been using Cisco IOS Security for more than ten years.
What do I think about the stability of the solution?
Cisco releases new patches and updates, whenever required. I rate its stability a nine out of ten.
What do I think about the scalability of the solution?
I rate the product’s scalability a ten out of ten. We have three users for it in our organization. We might increase the usage depending on the business requirements.
How are customer service and support?
Cisco has a lot of support partners. However, it takes a long time to replace some equipment.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have used Cisco Adaptive Security Appliance (ASA) before.
How was the initial setup?
The initial setup requires specific training. I rate the process an eight out of ten. The deployment involves setting up a bot for Buffalo with the management IP address. After that, I deploy the data center and access it remotely to complete the process.
What's my experience with pricing, setup cost, and licensing?
I rate Cisco IOS Security's pricing a ten out of ten.
Which other solutions did I evaluate?
We evaluated a few products. Later, we opted for Cisco as we already have experience working with it.
What other advice do I have?
It is a good product. It is valuable in terms of availability. Once configured and installed, the equipment runs for years. I rate it a seven out of ten as its support cost is high.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Network Architect at Syriatel Mobile Telecom
Secure, cost effective, and easy to install
Pros and Cons
- "It is less expensive than alternative firewalls."
- "While Cisco IOS Security is stable and scalable, I would like to see it improved to be even better."
What is our primary use case?
We can use iOS security for a variety of security features. We can use it to run DPM. We run encrypted data and can use it for zone-based firewalls, to a zone-based firewall.
I use VPN solutions such as site-to-site or user-site VPN, and some do not require a firewall.
What is most valuable?
It is less expensive than alternative firewalls.
What needs improvement?
While Cisco IOS Security is stable and scalable, I would like to see it improved to be even better.
For how long have I used the solution?
I have been working with Cisco IOS Security for three months.
I use version 12.4 and I use 15 and above for the router.
What do I think about the stability of the solution?
Cisco IOS Security is very stable.
What do I think about the scalability of the solution?
Cisco IOS Security is a scalable solution.
We have approximately 50 users.
How are customer service and support?
We have not contacted technical support.
I don't have any critical issues, and I haven't had any open technical tickets with support. Everything is fine, but I work in security with multi-media solutions. We haven't had any problems.
How was the initial setup?
The installation is straightforward. It's easy, we didn't have any problems with the installation of Cisco IOS Security.
I have three or four technical teams to help me work on publishing.
What's my experience with pricing, setup cost, and licensing?
Cisco IOS Security requires a license.
With Cisco, we have a variety of licenses. They have smart licenses that can be provided for one year, two years, three years, five years, and seven years. Alternatively, they have perpetual licenses available. I am working with a perpetual license, but not a smart license.
What other advice do I have?
Before we can use any security feature on the Cisco router, we must first purchase an iOS security license.
Yes, I would recommend this solution. It is more stable and less expensive than other firewalls. In some cases, it saves money for the project or the companies that work with it.
I would rate Cisco IOS Security an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Presale Agent
Beneficial posturing, scales well, and helpful support
Pros and Cons
- "The most valuable feature of Cisco IOS Security is posturing."
- "Cisco IOS Security could improve by having more compatibility with other Cisco solutions."
What is our primary use case?
The main purpose of Cisco IOS Security is for our data center. It connects each node and user to the network.
What is most valuable?
The most valuable feature of Cisco IOS Security is posturing.
What needs improvement?
Cisco IOS Security could improve by having more compatibility with other Cisco solutions.
For how long have I used the solution?
I have been using Cisco IOS Security for approximately three years.
What do I think about the stability of the solution?
Cisco IOS Security is a stable solution.
What do I think about the scalability of the solution?
The scalability of Cisco IOS Security is good. I can increase and decrease elements when needed.
We have approximately 45,000 people that can use the solution. Additionally, We have approximately 1,000 IT managers, technicians, and other users who directly use this solution.
How are customer service and support?
The support from Cisco IOS Security was very helpful.
I rate the support from Cisco IOS Security a four out of ten.
Which solution did I use previously and why did I switch?
I previously used another similar solution.
How was the initial setup?
I can do all the implementation of the solutions through the Cisco DNA Center. I can manage the Cisco IOS Security configuration. The whole process can be complex. Additionally, when we cannot connect to the internet we need to do manual configuration.
The full setup can take a couple of hours. However, initially, it took to use a couple of weeks.
What about the implementation team?
We did the implementation of Cisco IOS Security in-house.
We have two service engineers that are involved in the deployment and maintenance of the solution. They have the appropriate training needed to support the solution.
What other advice do I have?
I rate Cisco IOS Security an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Field Solutions Engineer at a computer software company with 1,001-5,000 employees
IPsec technology allows our clients to be more agile in their connectivity, but the technical support response times should be better
Pros and Cons
- "What I have used the most and received the most benefit from is the IPsec technology."
- "With respect to user-friendliness, it is a command-line interface and those with such experience will get along just fine, whereas others may struggle."
What is our primary use case?
We are a reseller and Cisco IOS Security is one of the network security products that we offer to our clients. The primary use case is securing connectivity between sites. Examples of this are between a site and a data center, or a site and a cloud provider.
How has it helped my organization?
DMVPN as a technology, not necessarily for security, has allowed my customers to be more agile in their connectivity, without having to rely on a hub-and-spoke topology. Rather, they can leverage a full mesh topology, which is essentially SD-WAN.
IPsec allows us to overlay that, which means we can obfuscate the underlying infrastructure, whatever the transports are. Whether it is a secure private transport like MPLS or just public internet, we can commoditize the underlying transports and trust that everything is secured from prying eyes.
What is most valuable?
What I have used the most and received the most benefit from is the IPsec technology. It overlays on DMVPN tunnels and being able to secure these object-based tunnels is good because they perform significantly better than traditional IPsec tunnels.
What needs improvement?
With respect to user-friendliness, it is a command-line interface and those with such experience will get along just fine, whereas others may struggle. My expectation is that it will remain a primarily command-line-based technology.
The biggest annoyance is probably the quality control of the code. They have to make sure that they are better at vetting bugs and software issues before they release code to the general public.
For how long have I used the solution?
I have been working with this product for the past ten years.
What do I think about the stability of the solution?
It is not the most stable system that I have worked with.
What do I think about the scalability of the solution?
I don't think that scalability is much of an issue.
Our clients are small enterprise-level organizations, typically between 1,000 and 5,000 knowledge workers.
How are customer service and technical support?
The technical support is pretty good and I would rate them an eight out of ten. If anything, they should work on their response times for critical cases.
Which solution did I use previously and why did I switch?
I would say that 80% of my experience is with Cisco products.
How was the initial setup?
The initial setup is fairly complex, although it depends on the feature sets that you're looking for. Cisco IOM is probably the most complex part of it because it involves setting up all of the QoS policies, performance-routing policies, and performance-routing domains.
From a DMVPN over IPsec perspective, it is pretty straightforward.
What's my experience with pricing, setup cost, and licensing?
Price is certainly something that the IOS technology has fallen behind the competition on.
What other advice do I have?
My advice for anybody who is implementing this product is to ensure that they don't overlook the technical overhead that is required to get it set up and keep it running. From an SD-WAN perspective, there are more user-friendly options out there, so they are going to have their own shortcomings. However, if you're going down the route of a Cisco command-line-based solution then make sure that you're prepared to have the staff on hand to manage it or instead, have a trusted partner that you work with and has the expertise to manage it.
From a feature-set perspective, as long as Cisco continues down the path of combining features from its products onto the unified platform, it will have all the features you need.
It's a good product and it does exactly what it's intended to do, but there and stability issues and the price is expensive.
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Download our free Cisco IOS Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
OPNsense
Cisco Secure Firewall
Palo Alto Networks NG Firewalls
Juniper SRX Series Firewall
Untangle NG Firewall
Fortinet FortiOS
KerioControl
Buyer's Guide
Download our free Cisco IOS Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What do you recommend for a corporate firewall implementation?
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Which is the best network firewall for a small retailer?
- When evaluating Firewalls, what aspect do you think is the most important to look for?
- Cyberoam or Fortinet?
- Fortinet, Palo Alto or Check Point?
- If you could go back, would you change your decision to buy that firewall and why?
- Sophos XG vs Fortigate UTM
- Can you recommend a solution to replace Cyberoam 200ing Firewall?