Cisco ASA is a stateful firewall which means they are the fastest and more secure, because they maintain state tables. Cisco ASA is very efficient not only in Firewalling but in VPNs, IPS and content filtering. It also has option of failover and redundancy.
Network Security Consultant at a tech services company with 51-200 employees
It allows us to filter incoming traffic to our network and provide a secure access to office network from outside through remote access VPN.
What is most valuable?
How has it helped my organization?
It allows us to filter incoming traffic to our network and provide a secure access to office network from outside through remote access VPN. We also connected our branch office through IPSEC site-to-site VPN tunnel which is very secure and reliable.
What needs improvement?
Some improvements required on GUI interface called ASDM. It should include health check parameters like temperature, memory used.
For how long have I used the solution?
I am using it more than five years.
Buyer's Guide
Cisco Secure Firewall
March 2025

Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
839,422 professionals have used our research since 2012.
What was my experience with deployment of the solution?
No issues, very easy to deploy.
What do I think about the stability of the solution?
No.
What do I think about the scalability of the solution?
Migration to new version is very easy, therefore no issue.
How are customer service and support?
Customer Service:
9/10.
Technical Support:9/10.
Which solution did I use previously and why did I switch?
Cisco ASA firewall is most reliable to protect the network, therefore I switched.
How was the initial setup?
Yes, straightforward and simple.
What about the implementation team?
I am also vendor.
What was our ROI?
100%.
What's my experience with pricing, setup cost, and licensing?
Price is bit high as compared to other vendors, but Cisco ASA has reputation and most reliable product. Always go with minimum security plus license.
Which other solutions did I evaluate?
Yes, Fortinet and Palo Alto.
What other advice do I have?
No.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
Principal Network Engineer at a tech services company with 51-200 employees
Provides the capability of the higher end firewall products to handle most network tasks without issues.
Pros and Cons
- "It makes it very easy to have delineated roles and responsibilities between network engineering and network security."
- "In my experience, a number of engineers get tunnel vision with devices. This is exacerbated by vendors fostering a silo mentality in disciplines."
How has it helped my organization?
It makes it very easy to have delineated roles and responsibilities between network engineering and network security.
What is most valuable?
I find the overall capability of the higher end firewall products to handle most network tasks without any issues. In addition, it is easy to train lower level help desk personnel on the GUI management.
What needs improvement?
People tend to think of firewalls as firewalls and routers as routers. Going by the book, I had to create a number of static routes in the firewall so it could reach the various subnets in my client's internal network. I decided to turn on OSPF routing to simplify my deployment. This resolved a lot of issues with remote VPN and site-to-site VPN tunnels.
In my experience, a number of engineers get tunnel vision with devices. This is exacerbated by vendors fostering a silo mentality in disciplines.
I cannot name the organization, but a large national non-profit in the medical field had too many network configuration problems because of the silo mentality.
Large Cisco ASA units have the capability to act as routers. This particular non-profit would not enable routing on the ASA until I explained that it resolve a number of issues that they were experiencing and resolving by static routes, a second Cisco ASA, and a proxy server.
What do I think about the stability of the solution?
Stability issues did not occur in my experience, as long as we stayed with the correct image builds.
What do I think about the scalability of the solution?
There were no scalability issues.
How is customer service and technical support?
Customer Service:
Generally, we do not need customer support, so it is hard to rate.
Technical Support:
Generally we do not need technical support, so it is hard to rate.
How was the initial setup?
The initial setup at many clients' sites was straightforward. Very complicated networks take a lot of planning.
What about the implementation team?
We implemented the solution in-house.
What was our ROI?
We cannot determine ROI just yet.
What's my experience with pricing, setup cost, and licensing?
Always plan ahead for three years. In other words, do not buy a firewall on what your needs are today, but try to predict where you will be three years from now in terms of bandwidth, security requirements, and changes in organizational design. This applies to any vendor, not just this product. I find that I always need to buy a higher level product than the specifications request in order to be safe.
Which other solutions did I evaluate?
In locations where I have used Cisco ASA firewalls, I have compared FortiGate and SonicWall.
What other advice do I have?
I utilize different brands of firewalls depending on the needs of a client, i.e., in-house IT versus outsourced. I am vendor agnostic as much as possible.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Cisco Secure Firewall
March 2025

Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
839,422 professionals have used our research since 2012.
Network security engineer at a tech services company with 1,001-5,000 employees
Good IPS/IDS functionality, straightforward to set up, and simple to deploy
Pros and Cons
- "The most valuable features of this solution are advanced malware protection, IPS, and IDS."
- "Web filtering needs improvement because sometimes the URL is miscategorized."
What is our primary use case?
We use this solution for advanced IPS, IDS, advanced malware protection, and web filtering.
What is most valuable?
The most valuable features of this solution are advanced malware protection, IPS, and IDS.
What needs improvement?
web filtering needs to improve because cisco firepower sync with bright cloud website for the website category. sometimes your URL is falling in the wrong category because of the bright cloud. so if you want to change the category you will have to drop the mail to the bright cloud and they will take action and it's a very long procedure.
For how long have I used the solution?
more than 2 years
What do I think about the stability of the solution?
This is a very reliable solution.
What do I think about the scalability of the solution?
I have extended my Cisco solution and did not have any trouble.
We have more than 400 users and we plan to increase usage.
How was the initial setup?
The initial setup is very simple to deploy in the Egyptian network. It takes two to three days to deploy but if you are implementing AMP then it will take an extra one or two days.
What's my experience with pricing, setup cost, and licensing?
I am happy with the product in general, including the pricing.
Which other solutions did I evaluate?
We evaluated a Sophos firewall but when I checked the reviews, I found that Sophos did not rate as well in terms of IPS, IDS, and malware protection.
What other advice do I have?
Cisco utilizes BrightCloud for URL filtering. Web filtering is the main problem with this product.
My advice to anybody who is considering this product is that if they want good security, compared to other offerings such as those by Check Point and Palo Alto, then they should implement Cisco Firepower.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
System Administrator at a non-profit with 1-10 employees
User-friendly UI, blocking by category, has plenty of features
Pros and Cons
- "You do not have to do everything through a command line which makes it a lot easier to apply rules."
- "The solution could offer better control that would allow the ability to restrictions certain features from a website."
What is our primary use case?
We use the solution to monitor the connections as part of our parameter protection for our network. We restrict what kind of traffic comes in and out, we use it basically for traffic management.
What is most valuable?
Cisco used to be all command-line operations and now Firepower is in a way modelled from FortiGate. Firepower has integrated a UI into it now.
You do not have to do everything through a command line which makes it a lot easier to apply rules.
You are able to see the traffic of what sites users are visiting.
There are warnings if you are about to go to sites that could be malicious.
It also allows you to block within categories, such as, by URL.
The solution always had these capabilities, but it did not have a user interface that was user-friendly.
What needs improvement?
The solution could offer better control that would allow the ability to restrictions certain features from a website. For example, If we want to allow YouTube but not allow uploads or we want to allow Facebook but not allow the chat or to playing of videos. This ability to customize restrictions would be great.
For how long have I used the solution?
We have been using the solution for three months now. We have always used Cisco but before we were using the ASA and now we use the new version with the threat defence.
What do I think about the stability of the solution?
The stability is good so far. My opinion could change in another couple of months once we get more deeply involved with the solution.
What do I think about the scalability of the solution?
We currently are protection approximately 220 users.
How are customer service and technical support?
We just deployed it a couple of months ago, we have not used the tech support with the Firepower yet. We have not had an issue that we have had to raise with them.
Generally, the tech support for Cisco takes too long to go through the different tiers of support agents to get to someone that can resolve the issue. You end up speaking to someone that is not qualified to solve the issue, then you have to be escalated upwards over and over. This system could be better.
I rate the tech support service generally from Cisco a seven out of ten.
How was the initial setup?
The installation is not hard and not easy either, it falls in between.
What about the implementation team?
The time of implementation took us two to three days. This was in part because we were migrating from another Cisco firewall. The config files were already there, we just had to bring them over. While having the config files we just had to set up the hardware to have us up and running. The install could have taken longer if this was not the case.
What other advice do I have?
Currently, I would give this solution high marks because I have not had a problem. However, keeping in mind, my evaluation period has been short. I would not give the solution a ten, nothing is perfect.
I rate Cisco Firepower NGFW Firewall a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Jr. Engineer at a computer software company with 5,001-10,000 employees
User-friendly, easy to install with updates available online, and good support
Pros and Cons
- "The interface is user-friendly."
- "The cost is very high. Most organizations cannot afford it."
What is our primary use case?
In our organization, we are using it as an internal firewall.
What is most valuable?
It is already improved because all of the computer updates are available online. So, you can update, and I think that the ASA 5585 is already updated.
All of the licensing features can be upgrades.
The interface is user-friendly.
What needs improvement?
The cost is very high. Most organizations cannot afford it.
For how long have I used the solution?
We have been using the latest version of this solution for the last five years.
What do I think about the stability of the solution?
It's a stable product.
What do I think about the scalability of the solution?
It's a scalable solution. We have more than 2000 users in our organization.
How are customer service and technical support?
Technical support is fine, we have no issues.
How was the initial setup?
The initial setup was very easy. Cisco documentation is online, so it was no problem at all.
It took approximately 30 minutes to install.
What's my experience with pricing, setup cost, and licensing?
If we compare it with FortiGate and the co-existing ASA, FortiGate is better in terms of price.
What other advice do I have?
This is a product that I can recommend to others.
I would rate this solution a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
ICT Systems Engineer at a insurance company with 11-50 employees
Pretty stable, but it needs better reporting tools and improvements to the user interface
Pros and Cons
- "This product is pretty stable."
- "I would like the ability to drill down into certain reports because currently, that cannot be done."
What is our primary use case?
The number one use for this product is security.
What needs improvement?
The management of the application can be improved with enhancements to the user interface.
I would like the ability to drill down into certain reports because currently, that cannot be done. In fact, this is one of the reasons that we want to move away from Cisco. Better reporting tools would be an improvement.
For how long have I used the solution?
We have been using Cisco ASA for approximately seven years.
What do I think about the stability of the solution?
This product is pretty stable.
What do I think about the scalability of the solution?
Our current model is reaching its end of life, so it's not very scalable at the moment. We don't plan to increase usage.
It is currently providing protection for about 30 users.
How are customer service and technical support?
The technical support is with our solution provider. I would say that it's average, rather than very good.
How was the initial setup?
The initial setup is complex. I would say that it took a maximum of a week to deploy.
What about the implementation team?
We had a service provider who took care of the installation for us.
What's my experience with pricing, setup cost, and licensing?
This is an expensive product. We pay about €2,000 ($2,400 USD) per year for licensing.
Technical support is in addition to the standard licensing fees.
What other advice do I have?
At this point, Cisco ASA is not a product that I recommend. My advice is that people should look at other solutions because there are other products available on the market that are just as good, if not even better.
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Ingénieur technico-commercial at ICBM
Good for building a solid security solution for a company
Pros and Cons
- "The best solutions for our company are those we have yet to implement so it will be even better in the future for us than it already is."
- "The user interface is too complex for people who are not trained to or certified to engage with the product. The interface should be easier to use."
What is most valuable?
We haven't deployed all the possible services from Cisco yet, but I started to research more of the ones that are available and I think Firepower will end up being the best, most valuable solution for us.
What needs improvement?
I think the visibility of the network can be improved, at least from our current setup. I do not know everything about the solution and exactly how it can be modified.
Another way they can improve is their pricing. One thing I notice is about the price is that it would be good if they could adapt the price to the area where a company is. West Africa is not the same as in India or in the USA and it is much more difficult to afford. If Cisco can manage this for our people it would help us implement better solutions.
To upgrade to some Cisco solutions or features you have to invest resources to create the solution or pay the difference for that functionality to upgrade services or license. It is not really an all-in-one solution. So if Cisco could manage to build an all-in-one solution with most or all of the features we would be looking for in one solution, it would be better for us.
For example, if you want faithful service from the company and equipment, you have to pay more just to get the solutions. If it's included it would be easier for us to deploy.
For how long have I used the solution?
I've been using the solution with my newest employer for over three years.
What do I think about the stability of the solution?
For me it is stable. It is amongst the best products in that way.
What do I think about the scalability of the solution?
It is a scalable solution. It may cost money and resources to scale.
How are customer service and technical support?
I have not had direct experience with technical support for the firewall. I contacted support for the switching. For the firewall, I have not had to contact them at all.
Which solution did I use previously and why did I switch?
Before I used Fortinet FortiGate. But when I moved from the previous company to this company they had a different solution. That is why I switched.
How was the initial setup?
The initial setup was a little complex for me because I had been using a different solution. But how complex something is will depend on the mind of that person. For me, it was a little complex for me. However, it really only took one day to set it up.
Step by step, when I work with the product for a longer period of time and gain experience, it will be very easy for me.
What about the implementation team?
I did the implementation by myself.
What other advice do I have?
If people want to build a solid security solution for their company, I think this solution is the best but it would depend on the configuration of your company. For a good company to have a good solution for security, you can choose the Cisco firewall for that and be confident.
I think I can give that product an eight out of ten. It comes down to the user interface. It needs to be easier so that more people can quickly develop the skills to manage the product. It would be better for us right now for more people to have certification or to just develop the skills to use the product. But if Cisco made it easier and took away the need for certification, it would be easier for us to use company-wide and have more people involved.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
Data Center Architect at Fronius International
Has the full package that we're looking for but the features aren't stable enough for us to use
Pros and Cons
- "We chose Cisco because it had the full package that we were looking for."
- "The stability and the product features have to really be worked on."
What is our primary use case?
Our primary use case of this solution is for firewalling.
How has it helped my organization?
We have been using Cisco for a long time, and we use Firepower to replace other systems. It hasn't really been an improvement, but there are many features we want to use in the future. We haven't seen much improvement because we only installed it a short while ago.
What is most valuable?
It has many features but not all of them work. The features aren't stable enough for us to use them. The most valuable features are the firewalling and the deep inspection.
What needs improvement?
The stability and the product features have to really be worked on.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
The stability is getting better but we had some firmware issues.
What do I think about the scalability of the solution?
The scalability is good. We have scaled it but at a normal gross so it's not very high. We have designed it for our use case and we have the option to scale but we don't use it at the moment.
Which solution did I use previously and why did I switch?
We chose Cisco because it had the full package that we were looking for.
How was the initial setup?
The initial setup was of normal complexity. It's not straightforward, and because we started so early, the migration tools were not so good at the beginning.
What about the implementation team?
We implemented through our partner and had a good experience with them.
What other advice do I have?
Customers should take note that the migrations steps are not easy. The tools cannot solve all configurations and handle all configurations directly so you will have to do some coding by yourself. The solution is not complete at the moment but it will get better.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2025
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
Sophos XG
Palo Alto Networks NG Firewalls
Check Point NGFW
Azure Firewall
WatchGuard Firebox
SonicWall TZ
Juniper SRX Series Firewall
SonicWall NSa
Fortinet FortiGate-VM
Untangle NG Firewall
Sophos XGS
Fortinet FortiOS
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Is The Biggest Difference Between Cisco ASA And Fortinet FortiGate?
- Cisco Firepower vs. FortiGate
- How do I convince a client that the most expensive firewall is not necessarily the best?
- What are the biggest differences between Cisco Firepower NGFW and Fortinet FortiGate?
- What Is The Biggest Difference Between Cisco Firepower and Palo Alto?
- Would you recommend replacing Cisco ASA Firewall with Fortinet FortiGate FG 100F due to cost reasons?
- What are the main differences between Palo Alto and Cisco firewalls ?
- A recent reviewer wrote "Cisco firewalls can be difficult at first but once learned it's fine." Is that your experience?
- Which is the best IPS - Cisco Firepower or Palo Alto?
- Which product do you recommend and why: Palo Alto Networks VM-Series vs Cisco Firepower Threat Defense Virtual (FTDv)?
hello
respectfully, you are right about routing, Cisco ASA is a best firewall that support routing. however, in best practices offer: do not use firewall as router and also is better to use firewall as transparent mode. because technically firewall designed for access control or something like that, so in high routing environment, sometime firewall cannot handle routing as router.