We use this solution to connect branch offices and keep the security on each one.
Senior Pre Sales Engineer at IKUSI
Gives us better efficiency and is a secure option for platforms and gateways
Pros and Cons
- "Cisco IOS allows us to keep the same security features as our principal offices."
- "I think setup could be one area for improvement, because sometimes we don't have people inside so we have to move to the place."
What is our primary use case?
How has it helped my organization?
Cisco IOS allows us to keep the same security features as our principal offices.
What is most valuable?
We can access control lists and VPN tunneling.
It gives us better efficiency.
What needs improvement?
I think setup could be one area for improvement.
I would also like to see them add integration with cloud solutions like Umbrella, as well as some monitoring improvements. This would let us connect a new platform and cloud solution for a site.
Buyer's Guide
Cisco IOS Security
January 2025
Learn what your peers think about Cisco IOS Security. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
What do I think about the stability of the solution?
Cisco's high stability is a well known feature.
What do I think about the scalability of the solution?
It is scalable. We can go to another platform and keep the same functionality.
How are customer service and support?
I think we have great support from Cisco for this. I haven't used it personally, but I have heard good things.
Which solution did I use previously and why did I switch?
I think we used Firepower. We work specifically with Cisco.
What about the implementation team?
I think the initial setup was simple. We have a lot of documentation and a guide that we can follow.
What was our ROI?
Thinking about the ease of managing these platforms and the technical support that we have, we can avoid extra costs and investments. We've saved time allowing our staff to work on other things that have saved money overall.
What other advice do I have?
My advice is that this is a very secure option for platforms and gateways using the Cisco IOS security feature.
I would rate Cisco IOS as ten out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
Pre-Sales at a computer software company with 501-1,000 employees
User-friendly and straightforward, with responsive technical support, but performance and integration could be improved
Pros and Cons
- "Cisco IOS Security has many good features, but compared to other solutions, it has a more user-friendly interface with steps to apply and manage rules. Another good part of the solution is that it's more straightforward."
- "An area for improvement in Cisco IOS Security is the performance because it's not as stable sometimes. There's also some latency in the solution, which could be improved. Cisco IOS Security integrates with other solutions, but you'll encounter many errors after integration, so this is another area for improvement. I'd like to see enhanced performance and a simplified setup in the next version of Cisco IOS Security."
What is most valuable?
Cisco IOS Security has many good features, but compared to other solutions, it has a more user-friendly interface with steps to apply and manage rules. Another good part of the solution is that it's more straightforward.
What needs improvement?
An area for improvement in Cisco IOS Security is the performance because it's not as stable sometimes. There's also some latency in the solution, which could be improved. Cisco IOS Security integrates with other solutions, but you'll encounter many errors after integration, so this is another area for improvement.
I'd like to see enhanced performance and a simplified setup in the next version of Cisco IOS Security.
For how long have I used the solution?
I've been working with Cisco IOS Security for more than five years.
What do I think about the stability of the solution?
Cisco IOS Security isn't as stable.
What do I think about the scalability of the solution?
Cisco IOS Security isn't as scalable, but it's okay. It's suitable for enterprise companies.
How are customer service and support?
The technical support for Cisco IOS Security is very good. The support team responds every time.
How was the initial setup?
Setting up Cisco IOS Security wasn't very easy because it's not a standalone solution. The setup requires merging rules and integration with other solutions, which could take some time.
What's my experience with pricing, setup cost, and licensing?
The pricing for Cisco IOS Security is reasonable compared to other Cisco products.
What other advice do I have?
I'm working with Cisco products such as firewalls, ISE, routers, data centers, FTD, and most of the Cisco technologies. I have experience with Cisco IOS Security as well.
My company is a partner and reseller of Cisco products.
My customers, particularly enterprise customers, use Cisco IOS Security.
My advice to others looking into implementing Cisco IOS Security is to do a POC first. It would help to be careful about performance, latency, and management issues with Cisco IOS Security.
I'd rate Cisco IOS Security as seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Buyer's Guide
Cisco IOS Security
January 2025
Learn what your peers think about Cisco IOS Security. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
Technical Lead at a tech services company with 10,001+ employees
Easy to use, easy to set up, and offers excellent technical support
Pros and Cons
- "The solution is very user-friendly and easy to deal with."
- "It would be ideal if the solution had more capacity."
What is our primary use case?
We primarily use the solution as a VPN concentrator. It's the main VPN concentrator for all remote connections.
What is most valuable?
The compatibility is high with many open protocols. We use it for Radiant. We use it for any kind of network access protocols as well.
The solution is very user-friendly and easy to deal with. We find working with both the Command-Line and the Viewer very, very straightforward.
It's quite stable. We find it more stable than other options.
What needs improvement?
It would be ideal if the solution had more capacity. Right now, we are almost hitting the maximum capacity of the product. If they could provide more capacity for the same product, that would be great.
For how long have I used the solution?
I've been using the solution for over ten years. At more than a decade, it's been a long time.
What do I think about the stability of the solution?
The solution is extremely stable. We find it much more stable than other options. It doesn't crash or freeze. There aren't issues with glitches. It is completely reliable.
What do I think about the scalability of the solution?
Currently, we have over 7,000 users that utilize this solution.
We do plan to increase usage in the future.
How are customer service and technical support?
Technical support is very, very good under Cisco. It's one of the other advantages of using their product. They are very helpful, responsive, and knowledgeable. We've very satisfied with the level of service they provide to us.
Which solution did I use previously and why did I switch?
We previously used Juniper. Juniper has improved a lot over the last little while, however, we still prefer Cisco.
How was the initial setup?
I was not part of the installation process. That was handled by another team entirely. That said, they didn't take a lot of time to get everything up and running. It was, if I recall correctly, less than one week to put it up and test it and make all the configuration adjustments. Deployment was fast and it's my understanding that the whole process from beginning to end was straightforward.
We only needed two people and they were able to handle both deployment and maintenance. They are engineers.
What's my experience with pricing, setup cost, and licensing?
I don't know the exact licensing costs. It's not something I deal with directly, and therefore I don't have any access to the information in regards to pricing and payments.
What other advice do I have?
We're just a customer and end-user. We don't have a business relationship with Cisco.
We're using the latest version of the solution in our organization right now.
We use both cloud and on-premises deployments, however, currently, we tend to use more on-premises deployments.
I would recommend the solution. Overall, I would rate it at an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Network Engineer at PART
Has good routing features and is easy to use
Pros and Cons
- "I've found their network routing to be very good."
- "I wish it would be more like the next generation firewall technology. There should be more selection between the application and filtering."
What is our primary use case?
We use Cisco IOS for security prevention. It enables us to check the network.
How has it helped my organization?
I didn't think that they would put servers in the DMZ. It also protects us from hackers; we haven't had any issues with them.
What is most valuable?
I've found their network routing to be very good.
It is also stable, has good scalability and is easy to use.
What needs improvement?
I wish it would be more like the next generation firewall technology. There should be more selection between the application and filtering.
I would appreciate updates to reporting, in terms of data entry.
For how long have I used the solution?
We have been using Cisco IOS for more than eight years.
What do I think about the stability of the solution?
We don't have any issues with stability. Cisco is always stable.
What do I think about the scalability of the solution?
Scalability is easy.
How are customer service and technical support?
We have a contract with the representative of DEO support, not just Cisco. So we have local support. If we have any issue, they respond to us directly by phone.
How was the initial setup?
The initial setup was easy. There are step-by-step instructions, like many of their other products.
What was our ROI?
The solution is definitely valuable for us.
What's my experience with pricing, setup cost, and licensing?
The licensing is on a subscription basis, and it is fairly costly. I would prefer a one-time payment.
What other advice do I have?
My advice is to take this firewall. It is really good. I would rate Cisco IOS as eight out of ten.
The next-generation firewalls, like UTM, have paper-thin single boxes. They should follow the same projects, like the next-generation firewall. They have everything like 40GBs in a single box, along with filtering applications, like VPN and SSN. They also have reporting features.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Networks Lead Engineer at a mining and metals company with 1,001-5,000 employees
Increased endpoint security but is overall a very complicated product
Pros and Cons
- "Previously, anyone in the organization would see any data point in the wall. They could just go and connect their machine with that data point and could access the network. But now, even if someone came and tried that, they will not be given access."
- "We have a very bad experience on the support. They take too much time requesting logs, and they are not coming directly online to resolve the issues."
What is our primary use case?
We use it for endpoint security, to control access to our edge level. Basically, Cisco IOS checks the identity of each endpoint (printers, etc.). There's a specific group allowing the printer to immediately connect to the network. Also, if there is a laptop, for example, then the IOS will tell you, okay this is a laptop, please add the user name and password to access the network. Once it gets authenticated with IOS, they will still do something like posturing, checking the compliance list. For example, if a laptop doesn't have an updated antivirus or updated patches - if it's non-compliant with any one of those things, the system will reject it and isolate it in a special network, so it cannot access our network.
How has it helped my organization?
Previously, anyone in the organization would see any data point in the wall. They could just go and connect their machine with that data point and could access the network. But now, even if someone came and tried that, they will not be given access. Because Cisco IOS will ask for the identity. So, you will now need to give your identity. If you are not part of the organization, you will not be given access.
What needs improvement?
I think it's a complicated product. It is very complicated, especially in the design. If in some way you mess up the logic and design, you can really mess up and you will hate your life. The dashboard is actually very complicated. There's a lot of options. They don't need to do this. They need to make it more simple. Going to the direct point, showing what to do, where to configure, how to make the policy. They need to simplify the dashboard management more. Also, they need to improve the dashboard statistics. We need to see the statistics in a more organized way and clear. Reporting features, I think are also missing. It should be there.
Maybe they need to add in posturing. Cisco is able to check if a device is updated or not. Taking action to isolate it outside the network, and then requesting automatically for the updates to that system would be helpful. It's something in automation they can improve.
For how long have I used the solution?
I have been using the solution for 1 year.
What do I think about the stability of the solution?
Initially, we faced some stability problems with the wifi systems. And sometimes it authenticates, sometimes it doesn't. But, overall, it's 90% stable. It's not causing many problems, because, no one is touching that. No one is touching that box.
How are customer service and technical support?
Their support was very bad. We have a very bad experience on the support. They take too much time requesting logs, and they are not coming directly online to resolve the issues. They keep asking about a lot of things. And they know that we are not expert in the system. So, we are wasting our time. And it takes time to respond. Sometimes one single issue will stay on the stack for three weeks, just to resolve it. The last ticket for me reached six weeks, not three weeks even. They are not like that in all products. Just this product.
How was the initial setup?
The initial setup was very complicated. For the initial setup, you need to configure the TAC servers and assigning the password, user name and the group for authenticating, etc. The deployment took more than three months.
What about the implementation team?
We used a vendor. We are not doing anything ourselves except for the basic things. We are using the vendors to do this. Not everything is handled by vendors; only, again, for the complicated products. We try to approach the integrators to do it.
Which other solutions did I evaluate?
I did not evaluate other options. I was thinking maybe Aruba might be a good option, but I did not switch over to it actually because Cisco's a big company and known in the market.
What other advice do I have?
Even now, we are not fully utilizing the features because it'll add complicated things. I would rate this solution 7 out of 10 because of both support and interface. After this experience, next time in any project we are going to go more secure.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Network Engineer at Transportation
EEM is a valuable feature for turning a Cisco device into a programmable device.
What is most valuable?
EEM (Embedded Event Manager) is a software component of Cisco IOS.
I found that EEM is a handy feature [but it is an underdog for the end user] if fine tuning of monitoring is required or if you would like to turn a Cisco device (switch or router) into a programmable device (without fancy words like ACI or Python, etc.). It is low level but efficient and money saving. It is available by default (but check the IOS feature support first). For curious minds, it could be used in combination with IP SLA and tracking features, a network engineer Swiss army knife.
How has it helped my organization?
- Increased monitoring level for KPIs normally not tracked by network management systems.
- Ability to correlate events and report back in a predefined format/customized message on the switch.
- Making a Cisco switch act as a network event sensor is enhancing visibility on the network.
What needs improvement?
- Tailored monitoring/notifications and some sort of added intelligence moved now to the edge of the network. (Actually, it could be done at any point of network: core, distribution, or access.)
What do I think about the scalability of the solution?
As it is a tailored solution, it is not very scalable, but this is a trade off; you need a hammer or a scalpel. And EEM is a scalpel.
What's my experience with pricing, setup cost, and licensing?
No licenses but what comes with the features of IOS.
Which other solutions did I evaluate?
Before choosing this product, we evaluated other options. I looked for a tailored solution.
What other advice do I have?
The competition (like Juniper) do offer similar approaches (scripting capabilities, but I did not look into the details). The question is that in many cases, users are not extending their expertise to adopt these money/time-saving features that vendors provide with their OSs.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Commercial Manager at Natco Information technology
Excellent technical support, stable, and straightforward installation
Pros and Cons
- "The technical is excellent."
What is our primary use case?
We are using Cisco IOS Security for endpoint security. For example, spyware, firewall, database and application protection.
For how long have I used the solution?
I have been using the solution for approximately 10 years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
We have found the solution to be scalable.
We have approximately 20 customers using this solution.
How are customer service and technical support?
The technical is excellent.
How was the initial setup?
The installation is straightforward.
What about the implementation team?
We have two engineers that do the implementation and maintenance of the solution.
What's my experience with pricing, setup cost, and licensing?
The price of the solution should be cheaper, and the license is purchase annually.
What other advice do I have?
I recommend this solution to others and advise them to use the latest version.
I rate Cisco IOS Security an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Network Manager at a insurance company with 1,001-5,000 employees
Good features. But when I converted it into a zone-based firewall, CPU utilization shot up and network performance slowed down.
Valuable Features:
1. Cisco IOS Security feature provides key features such as AAA, VPN, IPsec, content filtering, IPS, etc in all IOS based Cisco devices.
2. I like it because they include powerful security features that come with all Cisco Router and Switch from low to higher end.
3. It helped me to convert my Cisco router into a zone-based policy firewall.
4. It helped me to implement port security at my switch end.
5. I have implemented AAA in all Cisco routers and switch easily.
6. I have configured VPN server in a Cisco router with ease compare to OPENVPN configuration in a Linux OS environment.
Room for Improvement:
1. IOS security related IPS facility is not as strong as Cisco ASA and the signature file of IPS does not update automatically like Cisco ASA.
2. When I converted the Cisco router into a zone-based firewall, CPU utilization shot up and slowed down network performance.
Other Advice:
Cisco IOS security feature is the most robust and simple security facility which nice and small to implement. It helped me protect my network from external and internal attack.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Cisco IOS Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
OPNsense
Cisco Secure Firewall
Palo Alto Networks NG Firewalls
Juniper SRX Series Firewall
Untangle NG Firewall
Fortinet FortiOS
KerioControl
Buyer's Guide
Download our free Cisco IOS Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What do you recommend for a corporate firewall implementation?
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Which is the best network firewall for a small retailer?
- When evaluating Firewalls, what aspect do you think is the most important to look for?
- Cyberoam or Fortinet?
- Fortinet, Palo Alto or Check Point?
- If you could go back, would you change your decision to buy that firewall and why?
- Sophos XG vs Fortigate UTM
- Can you recommend a solution to replace Cyberoam 200ing Firewall?