Try our new research platform with insights from 80,000+ expert users
PeerSpot user
Asst.Manager IT at a manufacturing company with 501-1,000 employees
Real User
Blocks threats from the application layer
Pros and Cons
  • "The GUI is among the most valuable features,"
  • "It could use a web-based portal for VPN. Earlier they had it in the ASA model, but currently they don't have it."

What is our primary use case?

The primary use is to block incoming threats from the internet, at the edge of the network.

It's performing well. We check the report of blocked pages, blocked attacks, etc.

How has it helped my organization?

Previously, we only had a normal firewall, it was not next generation. It was not blocking many of the threats from Layer 7, the application layer. Now, this solution has IP, an intrusion prevention system, and because of the URL filtering, it can block other malware. It seems with the cloud database and the signatures, it compares the receiving files, then it blocks the URLs, making us more secure.

What is most valuable?

All the features are good. The GUI is among the most valuable.

What needs improvement?

It is on multiple boxes so ISP load balancing, multiple network load balancing would be helpful.

Also a web-based portal for VPN. Earlier they had it in the ASA model, but currently, they don't have it. The user needs to just click on the link so he can work.

Buyer's Guide
Cisco Secure Firewall
November 2024
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,562 professionals have used our research since 2012.

What do I think about the stability of the solution?

It is quite stable, it is able to detect. But the malware part should probably be upgraded. Performance-wise it is good and it has a long life.

What do I think about the scalability of the solution?

It has limits. If your network is going beyond it, then you'll have to replace it with higher model.

How are customer service and support?

Technical support is good.

Which solution did I use previously and why did I switch?

We have been using Cisco for a long time, various models. We had PIX, then ASA. We were quite comfortable with the performance, it never failed. But our old solution was coming to end-of-life. Also, this is able to more block more threats from the application layer, etc.

The most important criteria when selecting a vendor are 

  • reputation
  • technology
  • features
  • cost.

How was the initial setup?

The initial setup was a bit complex.

What other advice do I have?

My advice would depend on what your comfort level is. If you have already used Cisco, I would recommend this, to evaluate it at least. Evaluate it and learn how useful it is.

It gives good performance, the technology is quite good, sufficient for our objectives, protecting our network, etc. The missing two points are because they have to do make more improvements.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Network Engineer at a tech vendor with 10,001+ employees
Vendor
Some of the valuable features are detecting malware and blocking blacklisted URLs.

What is most valuable?

Some of the valuable features are detecting malware and blocking blacklisted URLs.

How has it helped my organization?

It has enhanced the security in every network over time.

What needs improvement?

As of now, I can't find any flaws with the device or any improvement that I can suggest.

For how long have I used the solution?

I have been working with the device for the past two years.

What was my experience with deployment of the solution?

The upgrade is a bit of a pain in the neck.

What do I think about the stability of the solution?

There were no issues with the stability

What do I think about the scalability of the solution?

Scalability has been all-star perfect.

How are customer service and technical support?

Customer Service:

I would give customer service a rating of 10/10.

Technical Support:

I would give technical support a rating of 10/10.

Which solution did I use previously and why did I switch?

We have only used Cisco security devices.

How was the initial setup?

The setup was smooth and simple.

What about the implementation team?

We implemented it by ourselves and with some support from the Cisco TAC.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Cisco Secure Firewall
November 2024
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,562 professionals have used our research since 2012.
it_user477366 - PeerSpot reviewer
Security Technical Architect at a tech services company with 10,001+ employees
Consultant
It provides detection of zero day infections. The feature sets are great when there are no software bugs.

What is most valuable?

The feature sets are great when there are no software bugs. With FirePOWER, you can enhance security, have effective management, and a good reporting engine.

How has it helped my organization?

It provides detection of zero day infections through FirePOWER AMP.

What needs improvement?

Well tested software releases. We have had a number of bugs on the FirePOWER software across several clients which have been very inconsistent and have affected our ability to deliver.

For how long have I used the solution?

I have used the ASA portion for over eight years and the FirePOWER portion for about three years.

What do I think about the stability of the solution?

We did have stability issues with the FirePOWER software.

What do I think about the scalability of the solution?

We did not have scalability issues with the high end devices.

How are customer service and technical support?

I give technical support a rating of 5/10.

Which solution did I use previously and why did I switch?

We are part of the integrator space. When we changed products, it was to displace a product that no longer met the client’s requirements.

How was the initial setup?

The setup was reasonably straightforward.

What's my experience with pricing, setup cost, and licensing?

Get a clear understanding of what the licensing entails before committing.

Which other solutions did I evaluate?

We checked out Check Point and FortiGate.

What other advice do I have?

Plan very well in order to have a seamless project implementation and transition.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Middle-Tier Admin Integrator at a tech services company with 51-200 employees
Real User
Cisco firewalls can be difficult at first but once learned it's fine.

What is most valuable?

Robustness

How has it helped my organization?

Reliability

What needs improvement?

No idea -- I learn a lot from them

For how long have I used the solution?

From 2000 until 2014

What was my experience with deployment of the solution?

Learning at the beginning

What do I think about the stability of the solution?

Nope -- If well planed you should be alright

What do I think about the scalability of the solution?

Price maybe...

How are customer service and technical support?

Customer Service:

Excellent

Technical Support:

Excellent

Which solution did I use previously and why did I switch?

Not reliable for long term -- seem inferior quality

How was the initial setup?

Depends on the product and the knowledge. Cisco firewalls can be difficult at first but once learned it's fine.

What about the implementation team?

Me, I implemented the firewalls, Cisco switches and routers.

What was our ROI?

100% in some installations it exceeded the time predicted to keep up with the work load.

Which other solutions did I evaluate?

Netscreen, Netgear, Checkpoint, others..

What other advice do I have?

Plan well the hardware requirements for future growth and heavy usage.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user4401 - PeerSpot reviewer
it_user4401Developer at a transportation company with 1,001-5,000 employees
Vendor

Can you tell me, please, how does an ASA learn about the MAC address of the host? Thank you.

it_user243897 - PeerSpot reviewer
Cisco Systems Engineer at a tech services company with 1,001-5,000 employees
Consultant
Review about Cisco ASA

What is most valuable?

  • Network firewall
  • FirePOWER services (URL filtering, IPS)

How has it helped my organization?

With the new FirePOWER services, Cisco has given the ASA new valuable features like URL filtering and a more simple and efficient IPS. With FirePOWER services, we have been able to have more insight of our network, something that we never had before, now we can see all the applications that our users are using the most and we can see if there is malware on our network.

What needs improvement?

The FirePOWER defense system has no integration with the firewall management of the ASA, I mean you can’t create ACLS, rules, VPNS NAT, and so on. All of this has to be done with the ASDM which, from my point of view, is very complex if you are not used to it, you should be able to manage the entire solution from one central software like Defense system, but right now you can’t. This is one of the biggest problems I see right now

For how long have I used the solution?

I've used it for two years.

What was my experience with deployment of the solution?

The FirePOWER deployment has to be done from the management port of the ASA. This port has to be dedicated because all the communication from the defense system to the appliance goes by that port, so you need to have different networks (inside and management port) to be able to implement this feature. It would be nice again if you can just configure this from one single point and not two (defense system and ASDM).

What do I think about the stability of the solution?

No, I have never had any problems with Cisco equipment regarding stability.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

8/10.

Technical Support:

6/10 - I mean you need luck when you open a case with Cisco to have someone with expertise on the product. I’ve had great TAC experiences and the worst ones too, if you have a loss of service they put you with people that know what they are doing, but if you want to configure something extra and you just ask the TAC how to do it, sometimes you get someone that appears to be learning the solution. Many times, I´ve been able to solve it by myself sooner than the TAC.

Which solution did I use previously and why did I switch?

We previously used Microsoft ISA and switched because it's no longer supported.

How was the initial setup?

In our case straightforward, because we do not have many rules on our firewall, but I’ve seen cases where the migration from one firewall to another can be very tedious.

What about the implementation team?

We did it in-house.

What other advice do I have?

If you are using Cisco, then you will be very familiar with the product, and maybe you won't encounter any problems at all. However, if Cisco is a new solution, you should ask for a demo to see the interface of the ASDM and the defense system in action, and then decide if this is the kind of insight you need of your network.

Disclosure: My company has a business relationship with this vendor other than being a customer: Premier partner.
PeerSpot user
reviewer1895523 - PeerSpot reviewer
Network Systems Manager at a computer software company with 5,001-10,000 employees
Vendor
VPN enables staff to work from home, and our response times to events has been reduced
Pros and Cons
  • "The VPN feature is the most valuable to us because it accomplishes the task well. We're able to do everything we need to do."
  • "I would like to see them update the GUI so that it doesn't look like it was made in 1995."

What is our primary use case?

We use it for our VPN requirements. We wanted to allow people to work from home and we used the ASA to create VPNs through AnyConnect at the endpoints.

How has it helped my organization?

It has 

  • allowed people to work from home when they otherwise couldn't
  • improved response times when there are fires that need to be put out when people are not onsite.

What is most valuable?

The VPN feature is the most valuable to us because it accomplishes the task well. We're able to do everything we need to do.

What needs improvement?

I would like to see them update the GUI so that it doesn't look like it was made in 1995.

For how long have I used the solution?

I've been using the Cisco ASA Firewall for between one and two years.

What do I think about the stability of the solution?

It's been very stable. I don't think we've ever had an issue with it failing entirely.

What do I think about the scalability of the solution?

It scales well. We've had no issues ramping things up.

We're going to expand our usage of it. We rolled it out to about 200 users and now we're going to expand that to about 1,000 users out of our 3,000-user base. It has been really good.

How are customer service and support?

The tech support is excellent. I've always gotten really good tech support from Cisco.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We did not have a previous solution.

What's my experience with pricing, setup cost, and licensing?

The pricing could always be cheaper.

What other advice do I have?

The solution always requires maintenance. I have about two people who are the "experts" and they help maintain it pretty well.

Cyber security resilience has been extremely important for our organization because of our customers' demands for security. The ASA has really helped to accomplish that with the VPN. My advice to leaders who are looking to build resilience is don't go cheap, and make sure you have backup solutions and high availability.

It's a good, robust firewall and VPN solution, with lots of knobs to turn. It is effective at what it does.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1473525 - PeerSpot reviewer
Enterprise Integration Architect at a insurance company with 10,001+ employees
Real User
Reliable and mature with good support but the content filtering needs improvement
Pros and Cons
  • "It's very stable and mature."
  • "The content filtering on an application level is not as good as other solutions such as Palo Alto."

What is most valuable?

It's very stable and mature.

What needs improvement?

The content filtering on an application level is not as good as other solutions such as Palo Alto.

While the price is fair with all of the features that it has, it should be cheaper.

For how long have I used the solution?

I have been using the Cisco ASA Firewall for seven years.

What do I think about the stability of the solution?

It's a stable solution.

We have plans to continue using this solution in the future.

What do I think about the scalability of the solution?

It's a scalable product. We have 200,000 users in our organization.

How are customer service and technical support?

Cisco technical support is good.

Which solution did I use previously and why did I switch?

Previously, we used other products. We used Fortinet and CheckPoint.

How was the initial setup?

We have a team of 50 or 60 Network Engineers to maintain this solution.

What's my experience with pricing, setup cost, and licensing?

The price is fair. It's not the cheapest, but it's not bad.

What other advice do I have?

Cisco ASA Firewall is a good product. I would recommend it to others who are interested in using it.

I would rate it a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Executive Director at ict training and development center
Real User
Good at blocking threats and pretty reliable but needs a better user interface such as web interface for easier create policy
Pros and Cons
  • "It's pretty reliable and allows for isolation capabilities within the network."
  • "The user interface isn't as good as it could be. They should work to improve it. It would make it easier for customer management if it was easier to use."

What is our primary use case?

We primarily use the solution for basic firewall configurations such as NAT, FORWARD PORT and Block TCP-UDP Port.

   

How has it helped my organization?

My company is very small just built last year, i now am using cisco asa 5510 for NAT and Port Forward and limit users access directly from internet only via Remote-VPN.

What is most valuable?

The ability to block threats is its most valuable aspect.

Most clients in Laos use the basic setup, which works quite well. It ensures that nothing can get onto the local network.

It's pretty reliable and allows for isolation capabilities within the network.

The ADSM is very good.

I like that I can use the command line. I use a lot of Cisco and often work with this. If you are comfortable with the command line, it's quite good.

What needs improvement?

The user interface isn't as good as it could be. They should work to improve it. It would make it easier for customer management if it was easier to use.

Cisco does not have a lot of web management. We have to use ASTM server management to make up for it.

For how long have I used the solution?

I've been using the solution, give or take, for around five years at this point.

What do I think about the scalability of the solution?


How are customer service and technical support?

When we need assistance from technical support, we typically deal with the team in China. They've been very good. Whenever I have a problem, they can resolve it. They are knowledgeable and responsive. We're satisfied with the level of support we get.

Which solution did I use previously and why did I switch?

We typically offer clients a few different solutions. For example, we may recommend Fortinet.

How was the initial setup?

For a new user, the initial setup may be a bit difficult. For me, since I am comfortable with Cisco, it's pretty straightforward. A new connection has its own complexities. It may be a different thing on Java SDK. There may be some programs that may not be able to access it.

What's my experience with pricing, setup cost, and licensing?

In Laos, clients don't have much wiggle room when it comes to cost. The economy right now isn't very good. Most just choose the basic solution in order to avoid pricey licensing fees.

Which other solutions did I evaluate?

subscription payment  

What other advice do I have?

We're just customers. We use it in our office and suggest it to clients. However, we don't have a business relationship with Cisco.

We try to adhere to our client's needs, and therefore, if they specify hardware they want to use, like Fortinet, we tend to accommodate them.

That said, if they ask my opinion, I usually recommend Cisco ASA.

I know a lot about the product and I'm good at controlling everything. I have a lot of knowledge and understanding after working with it so closely. That's why I tend to favor it when my customers ask for advice.

Overall, I would rate the solution seven out of ten. If the user interface were a bit better, I'd rate it higher.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros sharing their opinions.
Updated: November 2024
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros sharing their opinions.