We use this solution as a firewall and for the segregation of our servers from the rest of the environment.
A flexible and easy to manage solution for segregating our servers from the rest of the environment
Pros and Cons
- "The most valuable features are the flexibility and level of security that this solution provides."
- "There was an error in the configuration, related to our uplink switches, that caused us to contact technical support, and it took a very long time to resolve the issue."
What is our primary use case?
How has it helped my organization?
Instead of using multiple firewalls, we only need to rely on this solution. It has a small footprint.
What is most valuable?
The most valuable features are the flexibility and level of security that this solution provides.
What needs improvement?
There was an error in the configuration, related to our uplink switches, that caused us to contact technical support, and it took a very long time to resolve the issue.
Some of the features should be baked-in by default.
Buyer's Guide
Cisco Secure Firewall
July 2026
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
907,731 professionals have used our research since 2012.
What do I think about the stability of the solution?
Stability has been pretty good, so far.
What do I think about the scalability of the solution?
This solution is very scalable.
How are customer service and support?
We have contacted technical support about an issue that we were having, and it took a very long time for them to figure it out. We were on the phone for six or seven hours with them.
Which solution did I use previously and why did I switch?
We previously used an ASA 5500, and it was simply time to upgrade it. We used this solution as a direct replacement.
How was the initial setup?
The initial setup of this solution is pretty straightforward.
Which other solutions did I evaluate?
We are not restricted to any one vendor, but this solution worked well as a direct replacement for our previous one. We considered both Juniper and FortiGate.
What other advice do I have?
This is a very straightforward firewall. There is a management platform with its own operating system. Just make sure that everything is set up properly for your uplink switches because that is an issue that we ran into.
I would rate this solution a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Information Security Engineer at a financial services firm with 501-1,000 employees
Enables admins to be able to troubleshoot easily and has good traffic analytics features
Pros and Cons
- "For business purposes, it's a very detailed solution, which is it's greatest benefit, as you can get almost any piece of information you need from the solution. It allows for admins to be able to troubleshoot pretty easily."
- "I'm working on a slightly older version, but what it needs is a better alert management. It's pretty standard, but there's no real advanced features involved around it."
- "If you're going to get the latest and greatest of this solution, it's very expensive and it's actually the reason my organization is moving away from it."
What is our primary use case?
We use it as a network firewall.
How has it helped my organization?
For business purposes, it's a very detailed solution, which is it's greatest benefit, as you can get almost any piece of information you need from the solution. It allows for admins to be able to troubleshoot pretty easily.
What is most valuable?
The solution is part of a suite. If you pay for it, it has basically a view that's called Firepower, and it's really good at being able to analyze exact bits of a pack, at the packet level, and has the ability to allow you to examine that traffic. It is really good. That's probably my favorite part of the suite.
What needs improvement?
I would definitely say the pricing could be improved. If you're going to get the latest and greatest of this solution, it's very expensive and it's actually the reason my organization is moving away from it.
I'm working on a slightly older version, but what it needs is better alert management. It's pretty standard, but there are no real advanced features involved around it.
For how long have I used the solution?
I've been using the solution for around one year.
What do I think about the stability of the solution?
We haven't had any major issues in regards to stability. In general, there are best practices in the industry to use. It's never really mattered because generally, with firewalls, you have two in any given location or service. They seem to be redundant of each other. So there's never been a problem where we lost functionality because of the firewall.
What do I think about the scalability of the solution?
It's pretty scalable. Cisco is a large enterprise solution and it's designed to be able to serve large enterprise, so, it's fairly scalable. We're using the solution minimally at this point, and we're decreasing usage because it's too expensive to upgrade.
How are customer service and technical support?
They have pretty good customer support. The solution's technical support is great.
Which solution did I use previously and why did I switch?
I had not previously used another solution.
How was the initial setup?
I was not with the organization when they originally rolled it out, so I can't speak to how straightforward or complex the initial setup was. There are about six people who manage the solution. We have security engineers and network engineers. If someone is trying to get an idea of how many people are required, it varies because a lot of organizations will have multiple firewalls in different locations. Six for one organization may be way more than somebody needs or way fewer than somebody needs.
What about the implementation team?
We didn't use any other group for the deployment. We did all the work in-house.
What's my experience with pricing, setup cost, and licensing?
My company is moving away from the solution because it is quite expensive.
Which other solutions did I evaluate?
We've looked at the Fortinet solution. The Fortinet FortiGate.
What other advice do I have?
I would just say that it's expensive. The product is fine on its own, it's high end. It's got a high brand name attached to it. I would recommend the product, however. The product works great. It does everything it's supposed to do. There's no issues with it, no real concerns. It's just expensive.
I would rate it an eight out of 10 because it does everything it's designed to do, but it is not any better than other industry-leading solution, and it's far more expensive.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Cisco Secure Firewall
July 2026
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
907,731 professionals have used our research since 2012.
Network Engineer at a comms service provider with 1,001-5,000 employees
Protects from external threats to our network as a firewall and VPN solution
Pros and Cons
- "A stable and solid solution for protection from external threats and for VPN connections."
- "For simple purposes, it's the best in my opinion."
- "It is not the newest, cutting-edge technology"
- "For a next-generation firewall, Cisco's product — a combination of ASA and Firepower — is not the best solution."
What is our primary use case?
The primary use of Cisco ASA (Adaptive Security Appliances) for us it to protect from external threats to our network as a firewall and VPN solution.
How has it helped my organization?
Cisco ASA serves a purpose more than it improves us. It is good at what it does. We are using other vendors and splitting the traffic to different devices based on what they do best. Even though we use other products the trend at our company is that we will increase the traffic through Cisco ASA.
What is most valuable?
It's difficult to say what features are most valuable because ASA is not a cutting-edge device. It's rather more stable and proven than modern. It's difficult to suggest adding features because with new features we are adding something new, and that means it could be less stable and. New features are not the reason we use the solution — it is almost the opposite. The most valuable part of the solution is dependability.
It's already a mature and stable product. I prefer to not to use the newest software — even if Cisco suggests using the newest — because this is a critical security device.
What needs improvement?
My opinion is that the new direction Cisco is taking to improve its product is not correct. They want to make the old ASA firewall into a next-generation firewall. FirePower is a next-generation firewall and they want to combine the two solutions into one device. I think that this combination — and I know that even my colleagues who work with ASA and have more experience than me agree — everybody says that it's not a good combination.
They shouldn't try to upgrade the older ASA solution from the older type Layer 4 firewall. It was not designed to be a next-generation firewall. As it is, it is good for simple purposes and it has a place in the market. If Cisco wants to offer a more sophisticated Layer 7 next-generation firewall, they should build it from scratch and not try to extend the capabilities of ASA.
Several versions ago they added support for BGP (Border Gateway Protocol). Many engineers' thought that their networks needed to have BGP on ASA. It was a very good move from Cisco to add support for that option because it was desired on the market. Right now, I don't think there are other features needed and desired for ASA.
I would prefer that they do not add new features but just continue to make stable software for this equipment. For me, and for this solution, it's enough.
For how long have I used the solution?
We have been using the solution for about five years.
What do I think about the stability of the solution?
It is a stable solution. It is predictable when using different protocol and mechanics.
What do I think about the scalability of the solution?
We've used several models of the product, from the smallest to the biggest. I think that this family of the ASAs is scalable enough for everything up to an enterprise environment. I think the family of products is able to handle small and large company needs.
How are customer service and technical support?
Cisco is a well-known vendor and its support is good. In my previous company, we sometimes used a vendor rather than direct Cisco support, but sometimes we used Cisco. For ASA in my current company, we have additional support from the local vendor. If we have a problem we can also initiate a ticket directly on the Cisco support site.
Which solution did I use previously and why did I switch?
About one-and-a-half years ago we implemented a different solution to handle certain situations like BGP. But when we upgraded our Cisco devices just few months ago, we could have BGP on ASA. Now our devices from Cisco have enhanced capability, not just something new and maybe less dependable. Implementing BGP on ASA was a late addition. It had been tested, the bugs were worked out and engineers wanted the solution. The stability of ASA as an older solution is what is important.
How was the initial setup?
I think it is not the simplest solution to set up because it is sophisticated equipment. For engineers to work with vendors and incorporate totally different solutions, it could be difficult. It is also different from the other Cisco devices like Cisco Router IOS. It differs in a strange way, I would say, because the syntax or CRI differs. If you are used to other OSs, it is not easy to switch to ASA because you have to learn the syntax differences.
It's common for there to be differences in syntax between vendors. But, I would say that this is more complex. The learning curve for start-up and configuration of ASA is at mid-level when it comes to the difficulty of implementation.
What about the implementation team?
I did the implementation myself. ASA is not the newest solution for Cisco or the newest equipment. You can use the vendor and ask for help if you need it during the installation and for support. Because it was an older solution, it was already somewhat familiar to me.
Which other solutions did I evaluate?
My current company has been using ASA for quite a long time, so I was not involved in the choices.
I have been participating in choosing a new vendor and new equipment for some specific purposes as we go forward. For a next-generation firewall, Cisco's product — a combination of ASA and Firepower — is not the best solution. We are choosing a different vendor and going with Palo Alto for next-generation solutions because we feel it is better.
What other advice do I have?
I think I can rate this product as an eight out of ten. A strong eight. The newest version of software and solutions often have bugs and functional problems because they have not been rigorously tested in a production environment. It is not the modern, next-generation firewall, but it solidly serves simple purposes. For simple purposes, it's the best in my opinion. I am used to its CRI (Container Runtime Interface) and its environment, so for me, familiarity and stability are the most important advantages.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Ingénieur technico-commercial at ICBM
Good for building a solid security solution for a company
Pros and Cons
- "The best solutions for our company are those we have yet to implement so it will be even better in the future for us than it already is."
- "If people want to build a solid security solution for their company, I think this solution is the best but it would depend on the configuration of your company."
- "The user interface is too complex for people who are not trained to or certified to engage with the product. The interface should be easier to use."
What is most valuable?
We haven't deployed all the possible services from Cisco yet, but I started to research more of the ones that are available and I think Firepower will end up being the best, most valuable solution for us.
What needs improvement?
I think the visibility of the network can be improved, at least from our current setup. I do not know everything about the solution and exactly how it can be modified.
Another way they can improve is their pricing. One thing I notice is about the price is that it would be good if they could adapt the price to the area where a company is. West Africa is not the same as in India or in the USA and it is much more difficult to afford. If Cisco can manage this for our people it would help us implement better solutions.
To upgrade to some Cisco solutions or features you have to invest resources to create the solution or pay the difference for that functionality to upgrade services or license. It is not really an all-in-one solution. So if Cisco could manage to build an all-in-one solution with most or all of the features we would be looking for in one solution, it would be better for us.
For example, if you want faithful service from the company and equipment, you have to pay more just to get the solutions. If it's included it would be easier for us to deploy.
For how long have I used the solution?
I've been using the solution with my newest employer for over three years.
What do I think about the stability of the solution?
For me it is stable. It is amongst the best products in that way.
What do I think about the scalability of the solution?
It is a scalable solution. It may cost money and resources to scale.
How are customer service and technical support?
I have not had direct experience with technical support for the firewall. I contacted support for the switching. For the firewall, I have not had to contact them at all.
Which solution did I use previously and why did I switch?
Before I used Fortinet FortiGate. But when I moved from the previous company to this company they had a different solution. That is why I switched.
How was the initial setup?
The initial setup was a little complex for me because I had been using a different solution. But how complex something is will depend on the mind of that person. For me, it was a little complex for me. However, it really only took one day to set it up.
Step by step, when I work with the product for a longer period of time and gain experience, it will be very easy for me.
What about the implementation team?
I did the implementation by myself.
What other advice do I have?
If people want to build a solid security solution for their company, I think this solution is the best but it would depend on the configuration of your company. For a good company to have a good solution for security, you can choose the Cisco firewall for that and be confident.
I think I can give that product an eight out of ten. It comes down to the user interface. It needs to be easier so that more people can quickly develop the skills to manage the product. It would be better for us right now for more people to have certification or to just develop the skills to use the product. But if Cisco made it easier and took away the need for certification, it would be easier for us to use company-wide and have more people involved.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller.
Team leader at J.B. Hunt Transport Services, Inc.
Provides security and visibility for our network, and it is easy to integrate
Pros and Cons
- "The most valuable feature of this solution is its ability to integrate vertically."
- "This product has increased the visibility in our network."
- "There used to be information displayed about the packets in a module called Packet Flow, but it is no longer there."
What is our primary use case?
We primarily use this solution for network security.
How has it helped my organization?
This product has increased the visibility in our network.
What is most valuable?
The most valuable feature of this solution is its ability to integrate vertically.
What needs improvement?
There used to be information displayed about the packets in a module called Packet Flow, but it is no longer there. In order to accomplish the same thing you now have to wade through lots of information in the Syslogs.
What do I think about the stability of the solution?
This is a highly stable solution.
What do I think about the scalability of the solution?
This solution is very scalable.
How are customer service and technical support?
Technical support for this solution is good. The response times meet our expectations and we have not had any issues.
Which solution did I use previously and why did I switch?
We have always been using this same solution, but previous versions. We update them in trying to keep up with the amount of data coming through, such as more streaming.
How was the initial setup?
The initial setup of this solution was straightforward. We had the proper documentation to reference.
What about the implementation team?
We deployed this solution in-house.
What was our ROI?
I don't work with the numbers, but I can say that it's great for security and has improved our effectiveness at the office.
What's my experience with pricing, setup cost, and licensing?
The cost of this solution is high.
Which other solutions did I evaluate?
We did evaluate another option, but we stayed with the Cisco solution because it's trustworthy.
What other advice do I have?
This is a good product from a trustworthy vendor, but it is not perfect.
I would rate this solution an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Manager at Vegol
A stable solution with good monitoring and VPN capabilities
Pros and Cons
- "The stability is good. Very simple. Upgrades are great."
- "The VPN and monitoring are the most valuable features."
- "They really need support for deployment."
- "The pricing is quite high."
What is most valuable?
The VPN and monitoring are the most valuable features.
What needs improvement?
I tried to buy licenses, but I had trouble. Their licensing is too expensive.
If they can get the reporting to go into deeper detail, it would really be helpful because in order to get the reports in Cisco you have to go to look at the information that you don't necessarily need.
Also, the pricing is quite high.
For how long have I used the solution?
I've been using the solution for six years.
What do I think about the stability of the solution?
The stability is good. Very simple. Upgrades are great. But when we upgrade it, things break. You have to upgrade about three things before you get something stable.
What do I think about the scalability of the solution?
I haven't had to scale, so I can't speak to this aspect of the solution.
How are customer service and technical support?
I haven't had to deal with technical support, so I don't have much to say.
Which solution did I use previously and why did I switch?
We didn't previously use a different solution.
How was the initial setup?
The initial setup was straightforward.
What about the implementation team?
I did the setup myself. The budget I had didn't allow me to get support. I would use Google a lot. The first implementation took me about three weeks because I did not know what I was doing. So it took me a while. It took me about three weeks, but everything else took about two days, maybe three days and I was done.
Which other solutions did I evaluate?
We did look at Barracuda.
What other advice do I have?
They really need support for deployment.
I would rate this solution nine out of 10 because I think if you have the budget and you plan it properly I think you won't have the initial deployment problems I faced.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Network Administrator at a financial services firm with 1,001-5,000 employees
The granularity keeps users seeing what they are supposed to and enables the security not to become compromised
Pros and Cons
- "An efficient, easy to deploy and dependable firewall solution."
- "Our organization has been improved by the solution because we can be assured that the firewall is secure."
- "The interface for monitoring could be improved to allow better views to make troubleshooting easier."
- "One way the product could be improved is if you could monitor more than one rule at a time."
What is our primary use case?
Our primary use for the solution is for checking on and verifying the security of our customer data.
How has it helped my organization?
Our organization has been improved by the solution because we can be assured that the firewall is secure. It gives us more flexibility to monitor other things. Because we have safe firewalls, we don't have to worry about that and can direct resources elsewhere. If our internet goes down in one location we can bring it back up pretty easily.
What is most valuable?
The thing we've found most valuable is the efficiency. The firewalls are easy to configure and deploy. Overall it is an easy system to manage.
Another valuable feature is just how granular we can get with it so we can keep users seeing what they are supposed to and don't compromise security.
What needs improvement?
One way the product could be improved is if you could monitor more than one rule at a time. We only have the option to have one monitor window up at a time if you're trying to troubleshoot something you end up switching back-and-forth and don't get the bigger picture all at once.
It's reliable and it does its job. It gives you the freedom to do other things while you get indications of any issues. The multi-monitor would be a huge improvement.
I'd definitely recommend the product. Even when you set it up for the first night, it definitely will tell you the status of the network. The important part in the setup is following the instructions to get it going.
What do I think about the stability of the solution?
The solution itself is good as far as stability.
How are customer service and technical support?
The technical support is good and the response time quick. We had some firewalls down and gave them a call. They helped resolve the issue and it was all positive.
Which solution did I use previously and why did I switch?
Previous to this we had just a normal firewall that I didn't like. It didn't provide enough.
How was the initial setup?
The setup was straightforward, even without initially having all the information we needed. It was very intuitive. When I went in to get help, help was there.
What about the implementation team?
We got the product from a reseller and we did the installation ourselves.
What was our ROI?
We certainly have seen a return on investment at the very least from being able to reallocate human resources.
Which other solutions did I evaluate?
Before selecting this as a solution we really didn't evaluate other options at all.
What other advice do I have?
As far as rating this product, I would give it a nine out of ten. The only real drawbacks are the lack of multi-monitoring and not really having clear instructions prior to jumping in and implementing it.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Solutions Architect at a manufacturing company with 10,001+ employees
Increases efficiency of servicing our customers by joining our networks
Pros and Cons
- "This solution is easy to use if you know how to set it up."
- "Firewalls are difficult, and this solution gives us outside access to connect with the customer's network and service them better."
- "The inclusion of an autofill feature would improve the ease of commands."
- "This solution would benefit from being more cost-effective."
What is our primary use case?
We use this solution to join our private network to the customer's network.
In our business, we don't have to be on the customer's network, so a lot of people will install cheap equipment. We're trying to push it to where we can standardize the equipment, although the cost of Cisco products would have to come down a little bit in order for us to be more competitive.
How has it helped my organization?
Firewalls are difficult, and this solution gives us outside access to connect with the customer's network and service them better. It makes us more efficient.
What is most valuable?
This solution is easy to use if you know how to set it up.
The most valuable features are on the routing side, with the control between the two networks and the rules that are in there.
What needs improvement?
The inclusion of an autofill feature would improve the ease of commands.
This solution would benefit from being more cost-effective.
What do I think about the stability of the solution?
This solution is very stable, and I haven't seen any issues with it.
What do I think about the scalability of the solution?
Scalability doesn't really apply to us, as it is just a firewall client.
How are customer service and technical support?
Technical support for this solution is really good. We had an issue with a firewall and it was a good turnaround that was quick.
Which solution did I use previously and why did I switch?
Our implementation of this solution was driven by the customer.
How was the initial setup?
The initial setup of this solution is pretty straightforward. We did have some rules that somebody had put on it that didn't match up, but we got it all worked out.
What about the implementation team?
We implemented this solution in-house.
What's my experience with pricing, setup cost, and licensing?
With respect to the routers and switches, or the core stacks that we get, they seem to be pretty comparable so I don't have any issues with the licensing.
Some of our customers would be more likely to standardize on Cisco equipment if the cost was lower because a lot of people install cheap equipment.
Which other solutions did I evaluate?
While we have a partnership with Cisco, there are other products that have been used within the company. After evaluating other products such as those by Barracuda, it just happened that this solution worked out better for us. I like the Cisco reputation.
What other advice do I have?
With this solution, we have everything that we need. I don't know about other people's use cases, but ours is pretty straightforward.
My advice to anybody researching this type of solution is to stick with Cisco products, no matter which one it is. We've had pretty good luck with everything from Cisco.
I don't have any issues with this solution, so I would rate it a ten out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner.
IT Manager with 10,001+ employees
Simplified VPN Interconnection, easy to manage, and scales well for SMB
Pros and Cons
- "The feature I find most valuable is the Cisco VPN Interconnection."
- "They should allow customers to talk to them directly instead of having to go through the reseller."
- "I would say the pricing could be improved. It's quite expensive, especially for the economy."
What is most valuable?
The feature I find most valuable is the Cisco VPN Interconnection.
The file features are useful as well. They're good at packet tracing. They are very straightforward. I would say that the Cisco ASA ASDM makes it very easy to manage the firewall.
What needs improvement?
I would say the pricing could be improved. It's quite expensive, especially for the economy.
I'd like to see them more integration so that I don't need other parties for protecting my network. If I could just have ASA firewalls for perimeter protection and LAN protection, then I'm good. I don't need so many devices.
I would like to see improvements for client protection.
For how long have I used the solution?
I've been using the solution for four years.
What do I think about the stability of the solution?
My impression is it's a stable solution. I could sound biased, but if you have a device working for four years and it's still working and people are using it, then it's stable.
What do I think about the scalability of the solution?
Scalability depends on which device you have.
It's quite scalable if you have either the ASA, even if you had the new ASA firewall services, even if you had the one with the capacity of about 500 MDP. It isn't scalable for three hundred people connecting to it. I would say it is good for medium branch offices.
I'm not sure if we have plans to extend the service.
How are customer service and technical support?
Technical support is good. The only thing is that Cisco cannot support you unless you have a contract with them. You have to go through the reseller in Africa. I don't see why Cisco cannot communicate directly with the customer, especially when I can prove that I have the device. They should allow customers to talk to them directly instead of having to go through the reseller.
Which solution did I use previously and why did I switch?
I previously used SonicWall. I'm not the one who decided to switch, I just know that previously we used SonicWall.
How was the initial setup?
The initial setup was straightforward. Within in an hour you're done, including with your basic training. For implementation, you need one to two people. You should have one senior network administrator. Two people can maintain it if they have the skill.
What about the implementation team?
I did the implementation by myself. If you decide to do it by yourself, you need basic knowledge. If you don't have that you would need a contractor.
What's my experience with pricing, setup cost, and licensing?
This solution might be expensive, but it is economical in the long run.
What other advice do I have?
The functionality is fine.
When they prove to me they cannot be hacked then I can give them a ten.
I would rate this solution as eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Manager at a comms service provider with 501-1,000 employees
Offers good security and stability
Pros and Cons
- "What I like about Cisco is the security zone. By default when you configure it, it gives you a security zone, which other firewalls don't have."
- "The Cisco ASAv is really stable, especially if you compare it to Check Point."
- "I wish the Cisco interface was not so granular. Check Point was easier to create specific rules than with ASAv."
What is most valuable?
One of the important aspect when deploying Ciso ASA firewall, it’s oblige you at the beginning to define your security level, which will make it easier when making your security policy ( traffic allow From Source to Destination)
A security level will define how trusted is an interface in relation to another interface on the Cisco ASA.
The Higher is the security level, is the more trusted is the interface.
The highest security level is , “ Security Level 100” .
Nowadays other Firewall manufacturer try to adopt the same deployment principle as the Cisco ASA with security level, however the Cisco ASA do have other interesting features which I think are very useful:
- Firepower services
- Security context
- Firepower management
What needs improvement?
Normally in terms of design, the user prefers to use Cisco ASAv as a border router or a border firewall, because you have two different kinds of firewalls. You have a firewall when the data communication enters the network, and then you have a firewall, for when you've been inside the network. So, for the inside network firewall, Check Point is better because it can make a better notation of your network infrastructure. But, for the incoming data, or border firewall, ASAv is better. In terms of improving the interface, if you compared to the Check Point file, then I think that ASAv should be better. They should improve the interface so that it's similar to the Check Point firewall.
For how long have I used the solution?
I've been using the solution for the past three years.
What do I think about the stability of the solution?
The Cisco ASAv is really stable, especially if you compare it to Check Point. Not long ago Check Point did release one virtual firewall, and the virtual firewall of Check Point is not stable.
The hardware version of the firewall is more stable than the virtual one. In terms of the data center, many companies have a virtual data center in a group environment. Many companies want to have a virtual firewall, but the one from Check Point, in comparison to Cisco, is not stable at the moment.
What do I think about the scalability of the solution?
The solution is really scalable.
How are customer service and technical support?
I haven't dealt with technical support. We just check online, and if we have to contact Cisco about major issues, it's an internal department dealing with that. I don't know how technical support is, because our technical support team is located in Sofia, and I am in the Netherlands, so I don't have any view on that.
How was the initial setup?
The setup is always different. If you have a small company, the setup is quite easy, but if you have a bigger company the setups are quite complex. Cisco is pretty good in routing. So in bigger situations, configuring the ASAv file is pretty straightforward.
The deployment also depends on the customer's site. So, the time changes because most of the time we have to do a migration. For example, some customers have an old firewall, and you have to migrate things to a new one. And sometimes, it's just copy/paste, but in some situations, we cannot migrate all firewall configurations to a new one.
In terms of how many people you need for deployment and maintenance, again, it's dependent on the company strategy around the help desk. You should have a maintenance engineer who should be part of a team. The deployment will be done in a team. You can have one person to do the deployment but usually, you always have a backup, so it would be two. And then, for the maintenance, it can be one person or two. The maintenance can be done on the site desk, operating after office hours, so it depends.
What other advice do I have?
It's difficult to give specific advice on the solution because it always depends on the design solution and the strategy. So what I would recommend is to use different firewalls and to use Cisco ASAv as a border firewall.
I would rate this solution as 7.5 out of 10. I wish the Cisco interface was not so granular. Check Point was easier to create specific rules than on ASAv, so that's why I say this. If you want to make things easier for an engineer, you always have to work on the interface. But the product, in and of itself, there's nothing wrong with it.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Updated: July 2026
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
Sophos Firewall
Cisco Umbrella
Palo Alto Networks NG Firewalls
WatchGuard Firebox
Cisco Identity Services Engine (ISE)
Check Point Harmony SASE (formerly Perimeter 81)
Check Point Quantum Force (NGFW)
Cisco Meraki MX
Check Point Cloud Firewall (formerly CloudGuard Network Security)
Azure Firewall
Cisco Secure Email
Cisco Duo
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Is The Biggest Difference Between Cisco ASA And Fortinet FortiGate?
- Cisco Firepower vs. FortiGate
- How do I convince a client that the most expensive firewall is not necessarily the best?
- What are the biggest differences between Cisco Firepower NGFW and Fortinet FortiGate?
- What Is The Biggest Difference Between Cisco Firepower and Palo Alto?
- Would you recommend replacing Cisco ASA Firewall with Fortinet FortiGate FG 100F due to cost reasons?
- What are the main differences between Palo Alto and Cisco firewalls ?
- A recent reviewer wrote "Cisco firewalls can be difficult at first but once learned it's fine." Is that your experience?
- Which Cisco firewall model is the latest: ASA or NGFW?
- Which is better - Fortinet FortiGate or Cisco ASA Firewall?












