Whatever you have that’s potentially public-facing, you need to protect it. As our technology moves to the cloud, so our need for security transfers from physical appliances to virtual ones. This is the classic Cisco ASA device, virtualised.
Info Sec Consultant at Size 41 Digital
Keeps costs low and provides granular control using appliances familiar to the team
Pros and Cons
- "Among the top features are integrated threat defence and the fact that each virtual appliance is separate so you get great granular control."
- "There are always vulnerabilities that come up and there was one in early 2018 but this was patched with software updates."
What is our primary use case?
How has it helped my organization?
Ease of spinning one up: The hourly charge has made demos and testing better because it’s a truer representation of a real-life situation.
It has allowed us to reduce costs and to make sure we provide rounded, secure products to customers.
What is most valuable?
Top features:
- Easy to deploy for staff to use VPNs
- Ease of setup
- Integrated threat defence
- Great flow-based inspection device
- Easy ACLs
- Failover support
- Each virtual appliance is separate so you get great granular control
- Has own memory allocation
- Multiple types of devices: 100 Mbps, 1 Gbps, 2 Gbps
- License control
- SSH or RESTful API
What needs improvement?
We didn’t find any huge issues. Obviously, there are always vulnerabilities that come up and there was one in early 2018 but this was patched with software updates.
Admin rights need to be given out carefully as they give overarching control to all devices - but that’s the same for everything.
Buyer's Guide
Cisco Secure Firewall
March 2025

Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
839,422 professionals have used our research since 2012.
How was the initial setup?
We went with this solution via the AWS Marketplace because it’s been made so easy to use an ASAv on AWS with simple drop downs to set it up. Our demo machines were also in AWS so we wanted a one-stop shop where we could spin them up or down as needed and configure the ASAv before it was launched.
What other advice do I have?
Almost all IT staff have used, or can easily learn how to use, the Cisco ASA appliance because it’s been around for years and is so popular (with good reason). For us, we stuck with what we know. It was an easy sell to get it signed off by higher-ups as they’d also heard of the ASA device from their time in IT.
This solution gets an eight out of ten because it is easy, has the features we need, keeps costs low, and provides granular control using appliances that are already familiar to the team.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Partner - Consulting & Advisory at Wipro Technologies
It provides the transparency of a single UI to ensure security
Pros and Cons
- "The transparency of the single UI to ensure security. A product has to be simple so that an administrator can use it."
- "The artificial intelligence and machine learning (behavioral based threat detection), which I can this will be coming out in another year, these are what we need now."
What is our primary use case?
Our primary use case is security.
How has it helped my organization?
From a security perspective, we are getting assurance with the respect to the the infrastructure which is getting built or the threats which are emanating from the Internet. With these, we can obtain the visibility that we need to know where we need to improve.
What is most valuable?
The transparency of the single UI to ensure security. A product has to be simple so that an administrator can use it.
What needs improvement?
The artificial intelligence and machine learning (behavioral based threat detection), which I can this will be coming out in another year, these are what we need now.
For how long have I used the solution?
Three to five years.
What do I think about the stability of the solution?
The stability is alright.
What do I think about the scalability of the solution?
Scalability is not an issue.
How is customer service and technical support?
Its technical support is the main reason why we selected the product.
How was the initial setup?
The integration and configuration are transparent and easy.
What's my experience with pricing, setup cost, and licensing?
We are partners with Cisco. They are always one call away, which is good. They know how to keep their customers happy.
Which other solutions did I evaluate?
We evaluated VMware Virtual Networking and Check Point.
We chose Cisco because of the support and their roadmap for the changing technology landscape is good. Therefore, it is always better to be partnered with them.
What other advice do I have?
When you are going to select a product, don't look at the cost, but at the functionality. Also, look at the stability. These days, the startups will show a new function or functionality, but when looking for a partner, make sure the company is sustainability for the new four years? Do they have the funding?
We have a large ecosystem system: Symantec, McAfee, Splunk, Check Point firewalls, Cisco firewalls and IPS IDS from Cisco. They integrate and work well together. Cisco has been security leader for the last 20 years, so the products are quite stable working in sync.
We are using every version of the product: On-premise, Azure, and AWS, which is a new offering.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
Buyer's Guide
Cisco Secure Firewall
March 2025

Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
839,422 professionals have used our research since 2012.
Network Consulting Engineer at a energy/utilities company with 10,001+ employees
It is very stable. Setting it up is not as intuitive as other more modern NGFWs.
Pros and Cons
- "If only a Layer 4 FW is needed, this is a good solution."
- "It is very stable."
- "Setting it up is not as intuitive as other more modern NGFWs."
What is our primary use case?
Solid datacenter firewall, but the ASA software is old with no application recognition. If only a Layer 4 FW is needed, this is a good solution.
How has it helped my organization?
Do not use it in cluster mode. It is not worth it. These firewalls can do 10G, so just design the rest of the network around this.
Do not do cluster to add more bandwidth.
What is most valuable?
Nothing fancy about ASA capabilities, it does its job and does it well as long as you only care about filtering ports and protocols.
What needs improvement?
The needed features are already being done on Firepower, but this software is still in flux.
For how long have I used the solution?
Three to five years.
What do I think about the stability of the solution?
It is very stable.
How was the initial setup?
Setting it up is not as intuitive as other more modern NGFWs.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Cloud Engineer at a tech services company with 1,001-5,000 employees
It's a straightforward setup with easy to follow instructions, however, some IDS/IPS appliances can be too complicated and too time consuming to properly deploy.
What is most valuable?
The ease of use and ease of deployment were the most important features. As a signature based appliance, SourceFire hits it on the head at detection and capturing traffic, but quite a few of the other IDS/IPS appliances are way too complicated and too time consuming to properly deploy. This will lead to improper deployments and often missing important spots in your network.
How has it helped my organization?
Being able to detect intrusions is very valuable, and this can be anything from reconnaissance attacks to malware beaconing from inside our network.
What needs improvement?
Being able to incorporate third party rules as the SourceFire rules often lag behind current threats. When the latest zero day or other threats hit the market and are high value threats, most departments want to have these signatures available and able to deploy automatically. SourceFire makes this a manual process with third party rules.
For how long have I used the solution?
I've used it for two years.
What was my experience with deployment of the solution?
No, it was quite easy.
What do I think about the stability of the solution?
No issues with stability.
What do I think about the scalability of the solution?
The only issue I have is with the price, as SourceFire is VERY expensive.
How are customer service and technical support?
Customer Service:
Customer service is very helpful and there are some extremely knowledgeable people on board.
Technical Support:Very technical! The men and women know what they are doing and are very helpful.
Which solution did I use previously and why did I switch?
No previous solution was used.
How was the initial setup?
It's straightforward with easy to follow instructions. You just plug-in and go.
What about the implementation team?
I implemented it myself.
What was our ROI?
Lousy! $250K/year just for maintenance and licensing costs for a defense center and five sensors? This is insane! There is a better way.
What's my experience with pricing, setup cost, and licensing?
The original setup cost was very high, not sure of the exact numbers because this product was purchased prior to me joining, but it was expensive Tack on the recurring charge and this really racks up, but luckily the day to day operational costs aren't bad at all, unless you break out the recurring charge daily!
Which other solutions did I evaluate?
Other IDS/IPS products were looked at.
What other advice do I have?
The same level of protection can be had at a much lower cost! Look at rolling your own with commodity hardware, Suricata (Or SNORT if you choose, but look at the differences please!), Aanval for the central management and the emerging threats rules.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Engineer at a tech services company with 501-1,000 employees
Saves us time and offers good security
Pros and Cons
- "The security features are the most valuable. My customers find the security products very useful because nowadays there are many threats from the internet and other malicious users. The security products really help."
- "It should be easier for the IT management or the admin to configure products. For example, the firewall products are not very straightforward for many users. They should be easier to configure and should be more straightforward."
What is our primary use case?
We deploy the firewall on the customer end and the customer can facilitate the VPN for their clients. We use Cisco Umbrella to secure their network and their endpoints.
How has it helped my organization?
We only work with Cisco products. We have been working with Cisco products for many years. In that way, we save time and we don't want to change to other vendors.
What is most valuable?
The security features are the most valuable. My customers find the security products very useful because nowadays there are many threats from the internet and other malicious users. The security products really help.
So far, Cisco Secure for securing infrastructure from end-to-end so that we can detect and remediate threats is good enough.
What needs improvement?
It should be easier for the IT management or the admin to configure products. For example, the firewall products are not very straightforward for many users. They should be easier to configure and should be more straightforward.
Some competitors are very easy to configure, you don't need to spend a lot of time reading the documents and learning them.
For how long have I used the solution?
I have been using Cisco products for ten years.
How are customer service and support?
The support is good. Sometimes it has a long waiting time. The waiting time depends on the products. For some products, for example, the Data Center solutions, you have to wait for an hour, even though they said that they escalated the case.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial deployment should be more straightforward. It's not that straightforward at the moment.
What's my experience with pricing, setup cost, and licensing?
The licensing is not good, it's confusing. I'm an engineer so I don't care about the actual price that much but the licensing part is confusing.
Which other solutions did I evaluate?
We've evaluated other solutions. We've been consulted to use competitors' products. There are things that are good with those competitors, but everything has two sides.
We choose Cisco because we are a Cisco partner, so we only recommend Cisco products. They believe in us, so we have a good relationship with them.
What other advice do I have?
I would rate Cisco Secure products an eight out of ten.
My advice would be to use them.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Solutions Consultant at a comms service provider with 10,001+ employees
A capable box for UTM
Pros and Cons
- "It's quite a capable box for UTM."
- "Sometimes my customers say that Cisco Firewalls are a bit more difficult compared to Fortigate or Palo Alto. There is complexity in the configuration and the GUI could be improved."
What is our primary use case?
We use it as a firewall or for UTM at the data center.
What is most valuable?
We like the standard firewall features. It's quite a capable box for UTM.
What needs improvement?
Sometimes my customers say that Cisco firewalls are a bit more difficult compared to Fortigate or Palo Alto. There is complexity in the configuration and the GUI could be improved.
For how long have I used the solution?
I have been using Cisco ASA Firewalls for as long as I have been working here, which is seven years.
What do I think about the stability of the solution?
Once installed, it's quite stable. We don't have many issues after it's deployed. Both the hardware and software are quite stable.
What do I think about the scalability of the solution?
As a firewall, it's in use all the time. Whether there will be increased usage depends on how security risks increase. But at the moment, there's no expectation for an increase in use.
How are customer service and support?
Cisco's technical support is usually quite satisfactory, and we get a reasonable response in a reasonable time to any inquiry we make.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is not that simple. I don't do the installation myself, but from what I hear it's more complicated than some of the other firewall products.
We usually do our installation in two or three hours. Our customers usually have between 10 and 50 users and they are generally IT admins.
We have three people who work in the field and manage deployments, and another five to 10 to manage the solution.
What was our ROI?
If you use the full functionality of Cisco ASA, it's worth the cost. But I don't think our company product is using the full capacity of the Cisco ASA.
What's my experience with pricing, setup cost, and licensing?
Licensing, recently, has been getting more complicated. In particular, the Smart Licensing that came out is quite complicated. I don't know what's going on. Our sales team asks us questions about Smart accounts, but I don't know what it is and Cisco is making it so complicated. They call it Smart, but it's complicated. I prefer the traditional license where you buy it once.
What other advice do I have?
When talking with our customers, I would not recommend our company's Cisco products for their security. It depends on their requirements, but if they want full security, I wouldn't say that Cisco ASA is the one choice.
My advice would be to do a PoC first.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Network Systems Manager at a computer software company with 5,001-10,000 employees
VPN enables staff to work from home, and our response times to events has been reduced
Pros and Cons
- "The VPN feature is the most valuable to us because it accomplishes the task well. We're able to do everything we need to do."
- "I would like to see them update the GUI so that it doesn't look like it was made in 1995."
What is our primary use case?
We use it for our VPN requirements. We wanted to allow people to work from home and we used the ASA to create VPNs through AnyConnect at the endpoints.
How has it helped my organization?
It has
- allowed people to work from home when they otherwise couldn't
- improved response times when there are fires that need to be put out when people are not onsite.
What is most valuable?
The VPN feature is the most valuable to us because it accomplishes the task well. We're able to do everything we need to do.
What needs improvement?
I would like to see them update the GUI so that it doesn't look like it was made in 1995.
For how long have I used the solution?
I've been using the Cisco ASA Firewall for between one and two years.
What do I think about the stability of the solution?
It's been very stable. I don't think we've ever had an issue with it failing entirely.
What do I think about the scalability of the solution?
It scales well. We've had no issues ramping things up.
We're going to expand our usage of it. We rolled it out to about 200 users and now we're going to expand that to about 1,000 users out of our 3,000-user base. It has been really good.
How are customer service and support?
The tech support is excellent. I've always gotten really good tech support from Cisco.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We did not have a previous solution.
What's my experience with pricing, setup cost, and licensing?
The pricing could always be cheaper.
What other advice do I have?
The solution always requires maintenance. I have about two people who are the "experts" and they help maintain it pretty well.
Cyber security resilience has been extremely important for our organization because of our customers' demands for security. The ASA has really helped to accomplish that with the VPN. My advice to leaders who are looking to build resilience is don't go cheap, and make sure you have backup solutions and high availability.
It's a good, robust firewall and VPN solution, with lots of knobs to turn. It is effective at what it does.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Consultant at IKUSI
Good integration with helpful technical support and very good administration capabilities
Pros and Cons
- "The solution offers very easy configurations."
- "The initial setup can be a bit complex for those unfamiliar with the solution."
What is our primary use case?
I often work with financial sector companies such as banks as well as retail organizations.
What is most valuable?
The solution offers very easy configurations.
The administration of the solution is very good.
The product integrates well with other products.
What needs improvement?
The initial setup can be a bit complex for those unfamiliar with the solution.
There are better solutions in terms of border security. Palo Alto, for example, seems to be a bit more advanced.
The cost of the solution is very high. Fortinet, as an example, has good pricing, whereas Cisco has very high costs in comparison.
For how long have I used the solution?
We've used the solution recently. We've used it at least over the last 12 months or so.
What do I think about the stability of the solution?
The stability of the solution is pretty good. I don't recall having issues with this aspect of the solution.
What do I think about the scalability of the solution?
This particular product does not have high availability and therefore scalability is limited.
You need a pretty sizable solution for a center.
We have about 300 clients using this solution, and therefore the amount of people on the solution is very high, however, I don't have the exact number of users across all clients. For solutions providers, we have IT solutions for maybe around 5,000 users.
How are customer service and technical support?
I have experience working with technical support from Cisco. It's very easy to contact them and talk with them. There were times we worked using email, for example, for communication. We also worked with Cisco engineers in Mexico directly. We're very satisfied with the level of service so far.
Which solution did I use previously and why did I switch?
We also work with Fortinet and Palo Alto, for example. As a reseller, we work with many solutions.
How was the initial setup?
I did not directly implement the solution. I don't have the right type of expertise. You need to know a bit about what you are doing, otherwise, the initial setup is a bit complex.
You may need, for example, a separate management device for this kind of solution. It's quite difficult to handle if you don't have in-depth knowledge.
What's my experience with pricing, setup cost, and licensing?
The cost of the solution is quite high. It's very expensive compared to other options. For example, Fortinet is much more reasonably priced.
What other advice do I have?
I am working for a Cisco seller in Mexico, and we have a relationship with Cisco. We are a gold partner. We ensure that the development is of the proper sizing for our clients.
I would rate the solution at a nine out of ten. We've had a very good experience so far. The only downside is that it's not as advanced as, for example, Palo Alto. That said, if you have the right skills to manipulate the configuration capabilities, Cisco is quite good.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2025
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
Sophos XG
Palo Alto Networks NG Firewalls
Check Point NGFW
Azure Firewall
WatchGuard Firebox
SonicWall TZ
Juniper SRX Series Firewall
SonicWall NSa
Fortinet FortiGate-VM
Untangle NG Firewall
Sophos XGS
Fortinet FortiOS
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Is The Biggest Difference Between Cisco ASA And Fortinet FortiGate?
- Cisco Firepower vs. FortiGate
- How do I convince a client that the most expensive firewall is not necessarily the best?
- What are the biggest differences between Cisco Firepower NGFW and Fortinet FortiGate?
- What Is The Biggest Difference Between Cisco Firepower and Palo Alto?
- Would you recommend replacing Cisco ASA Firewall with Fortinet FortiGate FG 100F due to cost reasons?
- What are the main differences between Palo Alto and Cisco firewalls ?
- A recent reviewer wrote "Cisco firewalls can be difficult at first but once learned it's fine." Is that your experience?
- Which is the best IPS - Cisco Firepower or Palo Alto?
- Which product do you recommend and why: Palo Alto Networks VM-Series vs Cisco Firepower Threat Defense Virtual (FTDv)?
I use pfSense at home and HIGHLY recommend this over anything else. But for a very distributed environment, checkout Aanval and Suricata combo with rules from Emerging Threats. At my old employer, I developed a plan to replace their $250K/year SourceFire deployment with a $80K/year custom solution that scales much better.
But again, each their own. For small/medium business, I would recommend pfSense, but for larger enterprise, I would recommend a custom solution based around Aanval/Suricata/ETPro with Firewall/VPN as separate devices.