Its security features are the most valuable aspect. It has the ability to detect and prevent intrusions.
IT Support Engineer
Its security features are the most valuable aspect. The equipment is too expensive.
What is most valuable?
How has it helped my organization?
The product has helped organizations secure their infrastructure and data. Most organizations are happy to adopt the technology.
What needs improvement?
The equipment is too expensive compared with other firewall products.
For how long have I used the solution?
I have used ASA for about three months. I just bought and configured it for a client.
Buyer's Guide
Cisco Secure Firewall
January 2025
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
825,609 professionals have used our research since 2012.
What do I think about the stability of the solution?
Since I installed and configured it, the client has never called with complaints.
What do I think about the scalability of the solution?
I have not had scalability issues at all. Maybe it is because I have not used it quite extensively.
How are customer service and support?
I haven't had a chance to interact with the support team.
Which solution did I use previously and why did I switch?
The previous product was limited in throughput and security.
How was the initial setup?
The initial setup was quite complex.
What's my experience with pricing, setup cost, and licensing?
As much as there is value for money, there is a need to make it affordable.
Which other solutions did I evaluate?
I tried Sophos.
What other advice do I have?
It is a very good device to use for those who value their network security.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Simplified the complexity of our security architecture.
What is most valuable?
Provides advanced malware capabilities.
How has it helped my organization?
Simplified the complexity of our security architecture.
What needs improvement?
Integration of advanced malware services with the firewall through Firepower services.
For how long have I used the solution?
We have been using this solution for six months.
What was my experience with deployment of the solution?
There were no issues with deployment.
What do I think about the stability of the solution?
There were no issues with stability.
What do I think about the scalability of the solution?
There were no issues with scalability.
How are customer service and technical support?
Customer Service:
I would give customer service a rating of 10/10.
Technical Support:I would give technical support a rating of 10/10.
Which solution did I use previously and why did I switch?
We were looking to upgrade to a comprehensive firewall solution that integrated Next Generation Prevention System (NGIPS).
How was the initial setup?
There were no issues with setup.
What about the implementation team?
We implemented in-house.
What was our ROI?
We calculated for the entire year, but the ROI seemed very decent from the first six months.
What's my experience with pricing, setup cost, and licensing?
Pricing: Negotiate
Licensing: Buy the advanced Malware Protection license subscription for one year. It is worth the investment.
Which other solutions did I evaluate?
We evaluated Juniper, Fortinet, and Huawei.
Disclosure: My company has a business relationship with this vendor other than being a customer: We are a CISCO Security Business partner
Buyer's Guide
Cisco Secure Firewall
January 2025
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
825,609 professionals have used our research since 2012.
IT Security Engineer at a financial services firm with 501-1,000 employees
The packet tracer function provides a packet flow through the firewall and shows which rule or policy can cause a drop.
Valuable Features:
Cisco ASA's CLI is very effective and fast to configure the firewall and make changes, but monitoring logs and connections can be eye bothering by reading all the line outputs. ASDM, however, have improved the overall ASA configuration from an GUI standpoint. I really enjoy the log monitor where I can see live logs in a more user friendly interface. The down side of ASDM is that it is build with JAVA and that means a lot vulnerabilities and it does not always work with the latest JAVA version and/or patches.
Improvements to My Organization:
The packet tracer function, which I use the most, have provided me a packet flow through the firewall and see which rule or policy can cause a drop. Also, I can see if my NAT statement is working properly. This has allowed me to quickly troubleshoot potential firewall related issues for my organization.
Room for Improvement:
L7 firewall is a key for the ASA to be competitive in the current and future market place. By integrating with SourceFire, now call FirePower, on the ASA has helped it to get into the next-generation firewall segment.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Network Architect at a tech vendor with 10,001+ employees
Security solution that offers a broad range of protection and has given us better control over securing our organization
Pros and Cons
- "This solution made our organization more secure and gave us better control."
- "This solution could be more granular and user-friendly."
What is our primary use case?
We use this solution for company security and to define access and connection between different devices.
How has it helped my organization?
This solution made our organization more secure and gave us better control.
What is most valuable?
The access list is the most valuable feature of this solution.
What needs improvement?
This solution could be more granular and user-friendly.
For how long have I used the solution?
I have been using this solution for 12 years.
What do I think about the stability of the solution?
This is a stable solution.
What do I think about the scalability of the solution?
This is a scalable solution.
How are customer service and support?
The technical support for this solution is good. I would rate it a seven out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We use this solution together with Palo Alto, depending on the use case.
How was the initial setup?
The initial setup is straightforward and the deployment only takes a few hours. Our deployment strategy was to keep it simple. A large deployment of this solution can require up to 10 resources.
The solution does require maintenance and we use an external service provider for this maintenance.
What other advice do I have?
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Network Security Engineer at a tech services company with 51-200 employees
A proactive threat defense solution with a good Inline Mode configuration
Pros and Cons
- "The Inline Mode configuration works really well, and ASA works very impressively."
- "I think the ASA layer is thin. It's always Layer 3 or Layer 4 source controller and doesn't control the Layer 7 traffic. It's important, and you'll need an additional firewall."
What is our primary use case?
I use it for VPNs, remote-access VPNs, environment issues, and failover issues. I also use the
content mode, NAT, and PAT in this firewall. We always use ASA for VPN sites and firewall sites. We use the edge for internet access for data center servers or company customers' internet access.
How has it helped my organization?
We always use ASA for integration another companies and branches easily.
What is most valuable?
The Inline Mode configuration works really well, and ASA works very impressively.
What needs improvement?
I think the ASA layer is thin. It's always Layer 3 or Layer 4 source controller and doesn't control the Layer 7 traffic at all. It's important, and you'll need an additional firewall.
All next-generation firewalls don't have much control over Layer 7, but there's a little bit of control for inspection. ASA never controlled Layer 7, and it's a bad point.
I don't like to use ASDM, a graphical interface, and other solutions for ASA. I wouldn't say I like this, and it's not good(ASDM).
For how long have I used the solution?
I have over seven years of experience with Cisco ASA Firewall.
What do I think about the stability of the solution?
It's stable. ASA works very well, and it's impressive. I use only ASA and only the Inline Mode.
What do I think about the scalability of the solution?
It's a scalable, high availability solution. It's an active/standby model for VPN. But if you don't use VPN in these devices, it works as an active/active high availability model.
How was the initial setup?
If you're a Cisco Administrator or Cisco certified, the initial setup isn't a problem. But if you don't know Cisco devices and how they work, it can get a little complicated.
What other advice do I have?
I would advise new users to look at next-generation firewalls like FTD or other models from Cisco. It's better than Cisco ASA. Cisco ASA Firewall isn't a next-generation firewall.
On a scale from one to ten, I would give Cisco ASA Firewall an eight.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Lead Network Engineer at a tech services company with 51-200 employees
A recommended firewall solution that is straightforward, stable, and reliable
Pros and Cons
- "We are mostly using it for remote access, so the remote access feature is the most valuable, but all other features are also needed and required. It is also a very straightforward and reliable solution."
- "We don't have any serious problems. The firewall models that we have are quite legacy, and they have slower performance. We are currently investigating the possibility of migrating to next-generation firewalls."
What is our primary use case?
We mostly use it for remote access. We also use this firewall between different segments of our enterprise network.
We have legacy models of this solution. We are using models 5510 and 5520.
What is most valuable?
We are mostly using it for remote access, so the remote access feature is the most valuable, but all other features are also needed and required. It is also a very straightforward and reliable solution.
What needs improvement?
We don't have any serious problems. The firewall models that we have are quite legacy, and they have slower performance. We are currently investigating the possibility of migrating to next-generation firewalls.
For how long have I used the solution?
We have been using Cisco ASA Firewall for around one hour and a half years.
What do I think about the stability of the solution?
It is quite stable. We didn't have any issues or crashes, so we find it to be a solid solution.
How are customer service and technical support?
We don't have Cisco support because these models are excellent.
How was the initial setup?
It has moderate complexity. I didn't have any prior experience in configuring these firewalls. That's why I found its initial setup to be of moderate complexity, but now, I have got used to using and maintaining these devices.
What's my experience with pricing, setup cost, and licensing?
We're using the smart license for this firewall. The models that we have require licensing for remote access.
What other advice do I have?
I would absolutely recommend this solution. It is a very straightforward and reliable solution. I would definitely like to propose and offer this solution to other colleagues.
Cisco doesn't have any plans to develop this kind of solution more. Cisco ASA Firewall will not be developed in the future. The next-generation firewall is the next step in the development of the Cisco firewall. For this reason, we are investigating the possibility of migrating to another product.
I would rate Cisco ASA Firewall a nine out of ten. We are very happy with this solution. It is very straightforward and reliable, but it is quite a legacy solution and lacks performance.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
IT Administration at a healthcare company with 11-50 employees
A stable solution for protecting our edge network, with good technical support
Pros and Cons
- "The most valuable feature is the access control list (ACL)."
- "This is an older product and has reached end-of-life."
What is our primary use case?
It provides the firewall and security for our edge network.
We are using a really old ASA device that is at end-of-life, so we're replacing it.
What is most valuable?
The most valuable feature is the access control list (ACL).
What needs improvement?
This is an older product and has reached end-of-life.
For how long have I used the solution?
We have been using Cisco ASA for probably ten years.
What do I think about the stability of the solution?
This is a very stable product.
What do I think about the scalability of the solution?
We're just a small company, so we have not had to scale it.
How are customer service and technical support?
The technical support is definitely very good.
How was the initial setup?
The initial setup was very straightforward.
What about the implementation team?
Just one person is required for maintenance.
What other advice do I have?
My advice for anybody who is implementing Cisco ASA is that it is not very difficult to deploy and not very difficult to understand how to continue adding more rules to it.
I would rate this solution an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Coordinator Network Support at a manufacturing company with 501-1,000 employees
It provides security for our company and users
Pros and Cons
- "It provides security for our company and users."
- "The initial setup was complex."
What is our primary use case?
It is our firewall solution. We connect to other locations, as well as use programs in-house.
What is most valuable?
The most valuable feature is the security that it provides our company and users.
Furthermore, our company uses it for making rules for the bank to connect to our server in the DMZ, which is a security challenge.
What needs improvement?
It needs improvement as a "Next-Generation" firewall solution. In addition, it needs to be more user-friendly.
For how long have I used the solution?
More than five years.
What do I think about the stability of the solution?
There is no downtime, and it is working great.
What do I think about the scalability of the solution?
It is scalable. We have had no issues.
What's my experience with pricing, setup cost, and licensing?
The initial setup was complex. But, after that, to maintain and keep creating rules it was easy.
Which other solutions did I evaluate?
We evalutated Cisco ASA vs Fortinet FortiGate VM.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
Sophos XG
Palo Alto Networks NG Firewalls
Azure Firewall
Check Point NGFW
WatchGuard Firebox
SonicWall TZ
Juniper SRX Series Firewall
Untangle NG Firewall
Fortinet FortiGate-VM
SonicWall NSa
Sophos XGS
Fortinet FortiOS
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Is The Biggest Difference Between Cisco ASA And Fortinet FortiGate?
- Cisco Firepower vs. FortiGate
- How do I convince a client that the most expensive firewall is not necessarily the best?
- What are the biggest differences between Cisco Firepower NGFW and Fortinet FortiGate?
- What Is The Biggest Difference Between Cisco Firepower and Palo Alto?
- Would you recommend replacing Cisco ASA Firewall with Fortinet FortiGate FG 100F due to cost reasons?
- What are the main differences between Palo Alto and Cisco firewalls ?
- A recent reviewer wrote "Cisco firewalls can be difficult at first but once learned it's fine." Is that your experience?
- Which is the best IPS - Cisco Firepower or Palo Alto?
- Which product do you recommend and why: Palo Alto Networks VM-Series vs Cisco Firepower Threat Defense Virtual (FTDv)?