I have deployed Cisco ASA as a terminator firewall. Normally, I would have preferred to have a sandwich configuration for firewalls: One possible firewall that would make an internal firewall and another for an external firewall.
Network Engineer at Banque des Mascareignes
Its VPN and ASN features are very stable. They are behind the market leaders for next-generation capabilities.
Pros and Cons
- "Its VPN and ASN features are very stable."
- "The setup was straightforward. I was happy with the configuration and deployment of the solution, as it was quick."
- "In terms of next-generation capabilities, Cisco is a little behind, and it is way behind the market leaders."
What is our primary use case?
How has it helped my organization?
Cisco ASA is best suited for our external firewall protection.
What is most valuable?
- Its VPN and ASN features are very stable.
- It is easy to configure.
What needs improvement?
In terms of next-generation capabilities, Cisco is a little behind. It is way behind leaders like Palo Alto, Check Point and Fortinet. While Cisco is headed in the right direction, it will take several years for it to get there.
Buyer's Guide
Cisco Secure Firewall
March 2025

Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
839,319 professionals have used our research since 2012.
For how long have I used the solution?
More than five years.
How are customer service and support?
When I need support, Cisco has provided quality support. I like working with them because of their support system.
How was the initial setup?
The setup was straightforward. I was happy with the configuration and deployment of the solution, as it was quick.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Coordinator Network Support at a manufacturing company with 501-1,000 employees
It provides security for our company and users
Pros and Cons
- "It provides security for our company and users."
- "The initial setup was complex."
What is our primary use case?
It is our firewall solution. We connect to other locations, as well as use programs in-house.
What is most valuable?
The most valuable feature is the security that it provides our company and users.
Furthermore, our company uses it for making rules for the bank to connect to our server in the DMZ, which is a security challenge.
What needs improvement?
It needs improvement as a "Next-Generation" firewall solution. In addition, it needs to be more user-friendly.
For how long have I used the solution?
More than five years.
What do I think about the stability of the solution?
There is no downtime, and it is working great.
What do I think about the scalability of the solution?
It is scalable. We have had no issues.
What's my experience with pricing, setup cost, and licensing?
The initial setup was complex. But, after that, to maintain and keep creating rules it was easy.
Which other solutions did I evaluate?
We evalutated Cisco ASA vs Fortinet FortiGate VM.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Cisco Secure Firewall
March 2025

Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
839,319 professionals have used our research since 2012.
Tehcnician at Belize Telemedia Limited
ASDM has made configuring ASA easy. No need to memorize CLI commands.
Pros and Cons
- "ASDM provides GUI for configurations. The ASDM has made configuring ASA easy. No need to memorize CLI commands."
- "Ease of configuration: It has gotten a lot easier to configure compared to the original Cisco Pix."
- "The ASA has become a bit old and needs updating."
- "UTM features would be nice or some NextGen features."
What is our primary use case?
Remote network access: We primarily use ASA for VPN, NAT, PAT routing, SLA, and multiple ISP providers.
How has it helped my organization?
Ease of configuration: It has gotten a lot easier to configure compared to the original Cisco Pix.
What is most valuable?
ASDM provides GUI for configurations. ASDM has made configuring ASA easy. No need to memorize CLI commands.
What needs improvement?
- UTM features would be nice or some NextGen features.
- The ASA has become a bit old and needs updating.
For how long have I used the solution?
One to three years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Information Technology at Giumarra
It is worth every penny that we have invested in it
Pros and Cons
- "It is much better than most of the other firewalls that I have worked with."
- "It needs more tunneling capabilities."
What is our primary use case?
I have been using the 5510 a lot, and have been working with it for many years. I have also used the 5505 and other firewalls.
How has it helped my organization?
It is much better than most of the other firewalls that I have worked with.
What needs improvement?
It needs more tunneling capabilities.
For how long have I used the solution?
More than five years.
What was our ROI?
It is worth every penny that we have invested in it.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
ESS Security with 201-500 employees
Allows us to implement active/backup HA with ASAv (Adaptive Security Virtual Appliance)
Pros and Cons
- "In v9.8 you are able to do active/backup HA with ASAv (Adaptive Security Virtual Appliance) deployed on MS Azure."
- "The relatively new Firepower Threat Defense image (mix of ASA and Sourcefire network security) fills a lot of gaps and features that were missing on ASA."
What is most valuable?
Starting in version 9.7 you could track a login history for audit purposes and, in 9.8, you are able to do active/backup HA with ASAv (Adaptive Security Virtual Appliance) deployed on MS Azure.
What needs improvement?
There is always room for improvement in virtually anything. However, the relatively new Firepower Threat Defense image (mix of ASA and Sourcefire network security) fills a lot of gaps and features that were missing on ASA. Moreover, with FMC (Firepower Management Console) you can complement it with even more admin and reporting capabilities for the entire platform.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
No stability issues.
What do I think about the scalability of the solution?
No scalability issues.
How is customer service and technical support?
Excellent.
How was the initial setup?
New version comes with initial setup tutorial, with very nice security policies baseline, set up by default.
What's my experience with pricing, setup cost, and licensing?
Be sure of what features you are going to utilize to add/remove some from new bundles.
What other advice do I have?
Best value will always be delivered by adding FMC (Firepower Management Console); at least their virtual edition.
Disclosure: My company has a business relationship with this vendor other than being a customer: Distributor.
IT Security Engineer at a financial services firm with 501-1,000 employees
The packet tracer function provides a packet flow through the firewall and shows which rule or policy can cause a drop.
Valuable Features:
Cisco ASA's CLI is very effective and fast to configure the firewall and make changes, but monitoring logs and connections can be eye bothering by reading all the line outputs. ASDM, however, have improved the overall ASA configuration from an GUI standpoint. I really enjoy the log monitor where I can see live logs in a more user friendly interface. The down side of ASDM is that it is build with JAVA and that means a lot vulnerabilities and it does not always work with the latest JAVA version and/or patches.
Improvements to My Organization:
The packet tracer function, which I use the most, have provided me a packet flow through the firewall and see which rule or policy can cause a drop. Also, I can see if my NAT statement is working properly. This has allowed me to quickly troubleshoot potential firewall related issues for my organization.
Room for Improvement:
L7 firewall is a key for the ASA to be competitive in the current and future market place. By integrating with SourceFire, now call FirePower, on the ASA has helped it to get into the next-generation firewall segment.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Network Security Consultant at a tech services company with 51-200 employees
Reliable product which I'd like to see include a web filtering functionality.
Valuable Features
It blocks all outside to inside traffic and only permits the specific internet traffic from the outside. VPN functionality is very useful, we can create remote access and tunnel VPN in the simplest way.
Improvements to My Organization
It blocked all kinds of internet attacks from outside like DOS or DDOS and avoided any down time. We created a remote tunnel from head office to data center network for easy access of servers that make working fast and they are easily manageable.
Room for Improvement
It would be great if they would add web filtering functionality to this product.
Use of Solution
5 years
Deployment Issues
No
Stability Issues
No
Scalability Issues
No
Customer Service and Technical Support
Customer Service:
Excellent
Technical Support:Good
Initial Setup
It is a little difficult in newer IOS versions where the use of the NAT command is different. Otherwise its straightforward to configure.
Implementation Team
I deployed it in-house with my team.
ROI
This solution reduces any downtime therefore business continuity is not disturbed - that is ultimately ROI.
Pricing, Setup Cost and Licensing
It is one time cost of about $10,000 and there is no day to day cost.
Other Solutions Considered
Yes, I evaluated Fortigate, SonicWall and Juniper but found Cisco ASA to be the best solution for us above all of the others.
Other Advice
Cisco ASA is a reliable product and it benefits you a lot in your network.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Chief Technical Officer at a comms service provider with 501-1,000 employees
It has given us a very robust and well firewalled LAN.
What is most valuable?
- Content filtering
- VPN features
- User interface is also very friendly
How has it helped my organization?
Users can VPN into the network from remote locations. It has given us a very robust and well firewalled LAN, that we use for authentication as well for our core network infrastructure.
For how long have I used the solution?
I've used it for seven years.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
It's a very stable product.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
It's good.
Technical Support:It's good.
Which solution did I use previously and why did I switch?
No previous solution was used.
How was the initial setup?
It was a straightforward setup.
What about the implementation team?
Implementation was in-house as we have Cisco experts.
What's my experience with pricing, setup cost, and licensing?
The initial cost was approximately $6,000.
Which other solutions did I evaluate?
No other products were evaluated.
What other advice do I have?
ASA is a very reliable product and I have been using it since I cam across it. I strongly recommend the use of the product
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2025
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
Sophos XG
Palo Alto Networks NG Firewalls
Check Point NGFW
Azure Firewall
WatchGuard Firebox
SonicWall TZ
Juniper SRX Series Firewall
SonicWall NSa
Fortinet FortiGate-VM
Untangle NG Firewall
Sophos XGS
Fortinet FortiOS
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Is The Biggest Difference Between Cisco ASA And Fortinet FortiGate?
- Cisco Firepower vs. FortiGate
- How do I convince a client that the most expensive firewall is not necessarily the best?
- What are the biggest differences between Cisco Firepower NGFW and Fortinet FortiGate?
- What Is The Biggest Difference Between Cisco Firepower and Palo Alto?
- Would you recommend replacing Cisco ASA Firewall with Fortinet FortiGate FG 100F due to cost reasons?
- What are the main differences between Palo Alto and Cisco firewalls ?
- A recent reviewer wrote "Cisco firewalls can be difficult at first but once learned it's fine." Is that your experience?
- Which is the best IPS - Cisco Firepower or Palo Alto?
- Which product do you recommend and why: Palo Alto Networks VM-Series vs Cisco Firepower Threat Defense Virtual (FTDv)?