Cisco Secure Firewall is a next-generation firewall that can be used for various security applications.
Security Network Architect at novonordisc
Has an easy installation process, but the integration capabilities with various applications need improvement
Pros and Cons
- "The advantage of using Cisco is its integration within the Cisco fabric, which allows for effective threat detection and mitigation."
- "Cisco could improve its score by developing more features that integrate seamlessly with various applications and investing in hardware acceleration to enhance performance."
What is our primary use case?
What is most valuable?
The advantage of using Cisco is its integration within the Cisco fabric, which allows for effective threat detection and mitigation.
What needs improvement?
Cisco could improve its score by developing more features that integrate seamlessly with various applications and investing in hardware acceleration to enhance performance.
What do I think about the stability of the solution?
The product is stable with minimal glitches or latency issues.
Buyer's Guide
Cisco Secure Firewall
May 2026
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
896,387 professionals have used our research since 2012.
How was the initial setup?
The solution is easy to install, requiring minimal expertise. Deployment time varies, but it can take about two days for a medium-sized company with 200-300 users to configure and install.
What was our ROI?
After five years of product usage, the high return on investment and low total cost of ownership can be observed.
What's my experience with pricing, setup cost, and licensing?
Pricing depends on partnerships and certifications. The engineering team's certifications can qualify it for seven to eight percent discounts.
What other advice do I have?
The platform's integration capabilities depend on the project context. In some cases, integrating Palo Alto may provide better performance, but Cisco can still be effective.
However, its classification in industry comparisons, such as those from Gartner, is lower than that of competitors like FortiGate and Palo Alto.
Overall, I rate it seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Security Engineer at a financial services firm with 501-1,000 employees
Provides IPS intrusion prevention, anti-malware, and anti-spam
Pros and Cons
- "The important features are IPS intrusion prevention, anti-malware, and anti-spam."
How has it helped my organization?
Cisco Secure Firewall has impacted our cybersecurity cost efficiency.
What is most valuable?
The important features are IPS intrusion prevention, anti-malware, and anti-spam.
What needs improvement?
Cisco firewall needs experience with hardware. They should also enhance security antivirus, application detection, user detection, and ID detection.
For how long have I used the solution?
I have been using Cisco Secure Firewall for three years.
What do I think about the scalability of the solution?
300 users are using this solution.
How are customer service and support?
The support is good.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is easy, but it takes some time to push the configurations. Also, it's a little complicated and not friendly to use. It is good only for IT and experienced people.
The deployment took two months and a team of two to three people.
What's my experience with pricing, setup cost, and licensing?
The pricing is average.
What other advice do I have?
I recommend the solution to medium and enterprise customers since it is expensive.
Overall, I rate the solution an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Cisco Secure Firewall
May 2026
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
896,387 professionals have used our research since 2012.
System Engineer at a computer software company with 201-500 employees
The grouping of the solutions helps save time
Pros and Cons
- "The grouping of the solutions helps save time. If you have a problem and you have a high-level overview of the system, you can easily dig deeper into the problem. For example, I can check to see why ASA isn't working but the reason for the outage is actually because of Duo. I can spend a lot of time working in the wrong direction because I didn't have an overview."
- "It would be great to have all the data correlated to have an overview and one point of administration."
What is our primary use case?
We use Cisco IronPort, Firepower, Secure Firewall, Email, and Secure Connect.
As with most products, integration could be better where needed. Sometimes, for example, the Cisco Secure Firewall and IronPort are in a class of their own. When it comes to management and logging, there's room for improvement.
Most of the products aren't configured on their own, but they are related together. There should be some sort of management. We would need a supervisor to manage it before using all of the solutions together.
How has it helped my organization?
They address services that belong together. For example, the Secure Client provides remote access. Authentication and multiple-factor authentication are two different products that belong together. There should be a link between both products and between both management interfaces to see, for example, troubleshooting or reporting so that you have both sources together.
It would be great to have all the data correlated to have an overview and one point of administration.
The grouping of the solutions helps save time. If you have a problem and you have a high-level overview of the system, you can easily dig deeper into the problem. For example, I can check to see why ASA isn't working but the reason for the outage is actually because of Duo. I can spend a lot of time working in the wrong direction because I didn't have an overview.
IronPort stuff looks at first a little bit outdated. It's not a fancy-colored view, but it does its job and is extremely helpful. Debugging on this platform is very easy.
What needs improvement?
Firepower's implementation and reliability need room for improvement.
How are customer service and support?
We address our problems with the relevant people. Some of the quality of their support has dropped. If your problem gets escalated, there are many skilled people who are absolute pleasures to work with. They are brilliant at what they do.
If you talk to someone who solves the problem within five minutes you can't do any better. But on the other hand, the other end of the range needs improvement.
You can have a case that lasts 15 months in which you have to talk to 20 people to resolve.
How would you rate customer service and support?
Neutral
How was the initial setup?
The complexity of the installation depends. It's not so easy to install. Each topic needs one management interface. So you end up with 20 to 40 different management platforms. All of them use a tremendous amount of resources. If you're willing to install it, you need a huge pile of hardware. It is not clear what everything does. Some consolidation there would be helpful. Other vendors face the same problem.
What was our ROI?
We have seen ROI from using Cisco.
What other advice do I have?
I chose Cisco because I've been working with them for 23 years. I choose it for its stability and because they have the right range of products. Most of our IT staff is happy with it.
I would rate it a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Head of Information Security Division at Prime Bank Ltd.
Easy setup, stable, and affordably priced
Pros and Cons
- "URL filtering is valuable."
- "The scalability has room for improvement."
What is our primary use case?
We use the solution to secure our external software application and user access through different ports.
What is most valuable?
URL filtering is valuable.
What needs improvement?
The virtualization aspect has room for improvement.
The scalability has room for improvement.
For how long have I used the solution?
I have been using the solution for three and a half years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
I give the scalability a one out of ten.
How was the initial setup?
The initial setup is straightforward.
What's my experience with pricing, setup cost, and licensing?
The price is good.
What other advice do I have?
I give the solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Engineer at a computer software company with 51-200 employees
Integrates easily and has VPN capabilities, but the ASDM interface is a bit buggy and the CLI isn't always intuitive
Pros and Cons
- "I like its integration with the AnyConnect client. I also like how modular it is. For example, I can easily integrate the Umbrella add-on into it. We are planning on adding Umbrella. We haven't added it yet, but we have researched."
- "One big pain point I have is the ASDM interface because it's Java, and sometimes, it's a bit buggy and has low performance. That's something that probably won't be improved because of backward compatibility."
What is our primary use case?
We are mainly using it as a VPN gateway and edge firewall.
How has it helped my organization?
It helped us with the transition to working from home and hybrid working. Because of its VPN capabilities, it enabled us to keep working while everyone had to stay home because of COVID.
It integrates well with other systems within our environment.
What is most valuable?
I like its integration with the AnyConnect client. I also like how modular it is. For example, I can easily integrate the Umbrella add-on into it. We are planning on adding Umbrella. We haven't added it yet, but we have researched it.
What needs improvement?
One big pain point I have is the ASDM interface because it's Java, and sometimes, it's a bit buggy and has low performance. That's something that probably won't be improved because of backward compatibility.
The CLI is not always clear. It's not always intuitive.
Some of the things, such as site-to-site VPN, are complicated to set up. The settings you have are all hidden away in crypto maps, and you can't have a setting per tunnel. When you want to change one particular tunnel, you automatically change them all. That's a drawback.
For how long have I used the solution?
We've been using the Cisco ASA firewall for about two years.
What do I think about the stability of the solution?
It's reliable.
How are customer service and support?
I haven't had much contact with their tech support. We have a partner called Fundamentals for support. They're good. I'd recommend them.
Which solution did I use previously and why did I switch?
We have a Palo Alto core firewall, and we handle threat detection and intrusion prevention on that device. We don't use Cisco ASA for detecting or remediating threats.
Compared to other systems that I have used in the past, Cisco ASA is reliable, and it's not a very big hassle to set up. It's very good, and it just does its job.
How was the initial setup?
It's not a very big hassle to set up. It's a bit complex when you go into different topics that aren't the basic capabilities, such as when you go above VPN and basic ACL configuration, but all in all, it does the job.
What other advice do I have?
I'd rate it a seven out of ten because of the ASDM, non-intuitive CLI, and complication of setting some of the things.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
System Engineer
Saves us a lot of time and has a stable VPN
Pros and Cons
- "I think that the firewall feature is the most valuable to me as it is one of the oldest features for this solution. We also appreciate how stable the VPN is."
- "I have a lot of difficulties with the solution's Firewall Management Center (FMC) and the GUI. Neither is responsive enough and should be improved."
What is our primary use case?
Our primary use cases for this solution are as a traditional firewall, VPN system, IPS, and for URL filtering.
What is most valuable?
I think that the firewall feature is the most valuable to me as it is one of the oldest features for this solution. We also appreciate how stable the VPN is.
What needs improvement?
I have a lot of difficulties with the solution's Firewall Management Center (FMC) and the GUI. Neither is responsive enough and should be improved.
For how long have I used the solution?
My organization has been using Cisco Secure Firewall for more than 10 years.
What do I think about the stability of the solution?
My opinion is that this solution is quite stable.
How are customer service and support?
We encounter tech issues often. Sometimes it's really good to work with the tech engineer, but sometimes it can be really frustrating that it's slow to go through the email chat and everything. It depends on the engineer you get.
How would you rate customer service and support?
Positive
How was the initial setup?
I have had difficulties with the implementation of this solution. When I first encountered this solution, I had difficulties bringing it up and configuring it, but this was maybe due to the fact that back then it was a new technology. It is possible that I would have an easier time with it right now.
What other advice do I have?
I would say that this solution did help free up staff. Today, and even during COVID, a lot of customers are interested in VPN solutions and this demand will only keep increasing. I work from home mostly and the solution saves me two hours per day.
I do want to stress that this solution saves our organization time. We have 13 engineers in our company and even more staff in other departments and they also have the opportunity to work from home and with this, they save a lot of time. We plan on buying a smaller office thanks to this and this too will save a lot of money for the company.
The reason we chose Cisco is that some of my colleagues partnered with the provider when they came to Hungary, so they have been working with these solutions for a long time.
I do not have experience with the Cisco migration tool, but my colleagues do and they are really happy with it and its ease of use.
I would rate this solution a nine, on a scale from one to 10, with one being the worst and 10 being the best.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Network Engineer at EURODESIGN
Is stable and has the best support
Pros and Cons
- "I work with Cisco and other partners, but the Cisco team is the best team in our country. When I call them, they always help us."
- "We are Cisco partners, and when we recommend Cisco FirePower to customers, they always think that FirePower is bad. For a single installation of FirePower, if I have to write about 18 tickets to Cisco, it's a big problem. There was an issue was related to Azure. We had Active Directory in Azure. The clients had to connect to FirePower through Azure. We had a lot of group policies. After two group policies, we had to make groups in Azure, and they had to sign in and sign back. It was a triple-layer authentication, and there was a big problem, so we didn't use it."
What is our primary use case?
We have a lot of use cases of FirePower. In one of the use cases, we have two offices, and we use FirePower on our two sites. One of them works through the site-to-site VPN, and we have a controller on this site.
What is most valuable?
I work with Cisco and other partners, but the Cisco team is the best team in our country. When I call them, they always help us.
What needs improvement?
I started to configure the device with version 7.2. After that, I had a problem. It was not a physical problem. It was a software problem. They advised me to install 7.0. I uninstalled and reinstalled everything. It took time, but it started to work normally.
I am not a programmer, but on the business side, they should fix all such issues in the future. We are Cisco partners, and when we recommend Cisco FirePower to customers, they always think that FirePower is bad. For a single installation of FirePower, if I have to write about 18 tickets to Cisco, it's a big problem. There was an issue related to Azure. We had Active Directory in Azure. The clients had to connect to FirePower through Azure. We had a lot of group policies. After two group policies, we had to make groups in Azure, and they had to sign in and sign back. It was a triple-layer authentication, and there was a big problem, so we didn't use it.
For how long have I used the solution?
We have been using this solution for about two years.
What do I think about the stability of the solution?
It's very stable now. Everything is fine for me.
What do I think about the scalability of the solution?
I use just two devices. I've not tested anything else.
How are customer service and support?
Their customer support is very good. We also work with other vendors, but Cisco's support is still the best. I'd rate them a 10 out of 10.
How would you rate customer service and support?
Positive
How was the initial setup?
For me, it was very easy because I solved all problems, but I had to install it two times.
What other advice do I have?
We are a reseller, and for us, it's a 10 out of 10 because if we sell it, we will earn money, but customers have to agree with us.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Network Engineer at a financial services firm with 10,001+ employees
Helped to secure our infrastructure from end to end so that we can detect and remediate threats
Pros and Cons
- "All the features except IPS are valuable. IPS is not a part of my job."
- "In terms of functionality, there isn't much to improve. There could be more bandwidth and better interface speed."
What is our primary use case?
We mainly use it in the data center. We are obliged to use a firewall. It's a necessity.
How has it helped my organization?
It has helped in securing our infrastructure from end to end so that we can detect and remediate threats. There is another office in my company that does threat detection, but it has been helpful.
It hasn't freed up any time. We still have to manage the firewall. It's something we have to do.
What is most valuable?
All the features except IPS are valuable. IPS is not a part of my job.
What needs improvement?
It's already pretty good. In terms of functionality, there isn't much to improve. There could be more bandwidth and better interface speed.
For how long have I used the solution?
I've been using Cisco firewalls for 20 years.
What do I think about the stability of the solution?
Its stability is very good.
What do I think about the scalability of the solution?
It's better to have a higher speed. I'd rate it an eight out of ten in terms of scalability.
We have multiple locations and multiple departments. We are a big company, and we have a lot of remote sites. We have about 6,000 of them.
How are customer service and support?
They are very good. From time to time, Cisco employees come to us and provide information about the latest features and new products. I'd rate them a ten out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We have other firewalls, and it hasn't helped to consolidate other solutions. We have to use the Cisco firewall and other vendors because of internal law. We have to use two firewalls, one from vendor A and the other one from vendor B.
We went for Cisco because it's affordable. It's something you can trust. It's something you know. It's a valued product.
How was the initial setup?
I've been involved in configuring it and assessing and ensuring that the configuration is up to date and there are no bugs, etc.
Its initial setup is not at all complex. I've been working with Cisco firewalls for 20 years, so I know them very well. It's not complicated for me.
We have all deployment models. We have on-premises and cloud deployments. We have everything. I belong to a big organization.
What about the implementation team?
We had a consultant for integrating the product. Our experience with the consultant was good.
The number of people required for deployment varies, but one person can deploy the solution. It's quite easy to implement. It doesn't require a lot of staff.
It requires normal maintenance.
What's my experience with pricing, setup cost, and licensing?
It's affordable.
What other advice do I have?
Try it. You will be happy.
I'd rate Cisco Secure Firewall a ten out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2026
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
Sophos Firewall
Cisco Umbrella
Cisco Identity Services Engine (ISE)
Palo Alto Networks NG Firewalls
WatchGuard Firebox
Check Point Quantum Force (NGFW)
Cisco Meraki MX
Check Point Harmony SASE (formerly Perimeter 81)
Check Point Cloud Firewall (formerly CloudGuard Network Security)
Azure Firewall
Cisco Secure Network Analytics
Cisco Duo
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Is The Biggest Difference Between Cisco ASA And Fortinet FortiGate?
- Cisco Firepower vs. FortiGate
- How do I convince a client that the most expensive firewall is not necessarily the best?
- What are the biggest differences between Cisco Firepower NGFW and Fortinet FortiGate?
- What Is The Biggest Difference Between Cisco Firepower and Palo Alto?
- Would you recommend replacing Cisco ASA Firewall with Fortinet FortiGate FG 100F due to cost reasons?
- What are the main differences between Palo Alto and Cisco firewalls ?
- A recent reviewer wrote "Cisco firewalls can be difficult at first but once learned it's fine." Is that your experience?
- Which Cisco firewall model is the latest: ASA or NGFW?
- Which is better - Fortinet FortiGate or Cisco ASA Firewall?















