Try our new research platform with insights from 80,000+ expert users
PeerSpot user
Senior Presales Engineer at a tech services company with 501-1,000 employees
Consultant
The various NGFW and NGIPS features are valuable, but the option to use ASA to decrypt SSL would be an improvement.

What is most valuable?

NGFW: VPN (IPSec, SSL), NAT (provides great flexibility)

NGIPS: Application visibility, file policies (store files), network discovery, correlation features

What needs improvement?

SSL decryption for modules. Although I think it is better to separate SSL decryption as a service from the software module since it requires additional hardware, but I think it would be great if there is an option to use the ASA (not the software module) to decrypt the SSL.

Ex: Add a license to decrypt SSL traffic on the ASA itself. The ASA already supports SSL VPN. So if SSL decryption can be integrated that would be nice.

For how long have I used the solution?

5 years+

What was my experience with deployment of the solution?

Basic setup is easy, but if you need to do some advanced stuff, it can be intuitive, but some things require some kind of tutorial to understand how it can be done. Good thing is that this device is becoming popular and there are many 3rd party free tutorials and guides that can help.

Buyer's Guide
Cisco Secure Firewall
November 2024
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,562 professionals have used our research since 2012.

What do I think about the stability of the solution?

I heard about defect that were encountered by my colleagues, but not something that cannot be fixed using an upgrade.

What do I think about the scalability of the solution?

Clustering is available for ASA with firepower services.

Also for firepower appliances, there is stacking available for some models.

How are customer service and support?

Customer Service:

Great support. The engineers know what they are doing.

Technical Support:

10/10

Which solution did I use previously and why did I switch?

No

How was the initial setup?

Well, it is straight forward as long as you understand the components available.

ASA can be configured using the CLI or ASDM.

For the Firepower you will need to use a FireSIGHT as a management solution.

Since you will be using two GUIs, I wouldn't call it straight forward.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
PeerSpot user
Sr. Network Engineer at a tech services company with 10,001+ employees
Real User
CLI of the firewall is valuable, but there are IOS related bugs in later versions.

What is most valuable?

  • Stateful inspection
  • CLI of the firewall

How has it helped my organization?

It has increased the security and works best for VPN users.

What needs improvement?

The product has been introduced with UTM i.e. FirePower, and I would like to use it and comment on it.

For how long have I used the solution?

I've used it for three years.

What was my experience with deployment of the solution?

Encountered IOS related bugs in later versions.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

10/10.

Technical Support:

It depends on the support contract that you have.

Which solution did I use previously and why did I switch?

I previously used CheckPoint, and switched because of the UTM features.

How was the initial setup?

It was straightforward.

What about the implementation team?

I implemented it myself.

Which other solutions did I evaluate?

I think evaluated other options with reference to our architecture.

What other advice do I have?

You should analyze the current setup and implement it as per the customers' requirement.

Disclosure: My company has a business relationship with this vendor other than being a customer: Platinum Partner
PeerSpot user
Buyer's Guide
Cisco Secure Firewall
November 2024
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,562 professionals have used our research since 2012.
it_user224271 - PeerSpot reviewer
Senior Network Architect/Owner with 51-200 employees
Vendor
We have the ability to control our VPN users as well as use two-factor authentication if needed, but I would love to see application specific control.

Valuable Features

The features that we use are:

  • The stateful firewall
  • VPN with AnyConnect
  • Site-to-site IPSEC solutions
  • High availability

Improvements to My Organization

The ASA gives us a secure appliance at the perimeter and allows us to provide VPN connectivity to our users. We have the ability to control our VPN users as well as use two-factor authentication if needed (using an outside Radius source).

Room for Improvement

The ASA has room for improvement in the areas of layers four through seven. I would love to see application specific control, e.g.Facebook, Gmail, etc.

Use of Solution

I have used this solution for five years.

Deployment Issues

No issues with the deployment of the ASA as long as you are using it for what it is intended for.

Stability Issues

No issues encountered.

Scalability Issues

As long as you buy the correct model for your company, in regards to throughput, licenses etc., you will be fine.

Customer Service and Technical Support

Customer Service:

8/10.

Technical Support:

8/10.

Initial Setup

I believe it is straightforward, but again it depends on what you are trying to accomplish.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user212700 - PeerSpot reviewer
Senior Network Engineer at a aerospace/defense firm with 51-200 employees
Vendor
Setup can be complex if you don't have previous experience with ASA but it's an excellent product.

What is most valuable?

The multi-context mode.

How has it helped my organization?

Being able to use the multi-context on the firewall to keep costs down.

What needs improvement?

No improvement needed.

For how long have I used the solution?

I've used it for four years.

What was my experience with deployment of the solution?

Yes but I was able to get the support that was needed to resolve any issues.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

9/10.

Technical Support:

8/10.

Which solution did I use previously and why did I switch?

Yes and we switched because we needed a fully redundant solution.

How was the initial setup?

If you have no experience with the device it may be complex but being trained on the device helps drastically.

What about the implementation team?

We used a mix of both - vendor help and in-house.

Which other solutions did I evaluate?

We also evaluated Juniper firewalls.

What other advice do I have?

Excellent product and excellent customer support.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user150300 - PeerSpot reviewer
Senior Network Engineer at a tech services company with 501-1,000 employees
Consultant
The features are quite powerful and it's easy to set-up

Valuable Features

Anyconnect VPN

Improvements to My Organization

The features are quite powerful, easy to set-up and for ease of use end user too is excellent. Moreover, this has been quite stable since the day we installed them.

Use of Solution

More than 5 years

Deployment Issues

No

Stability Issues

No

Scalability Issues

No

Customer Service and Technical Support

Customer Service: Very GoodTechnical Support: Excellent

Initial Setup

Yes, the document repository is pretty robust and easy to understand.

Implementation Team

In-house

Other Solutions Considered

Yes, Checkpoint & Juniper
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user5274 - PeerSpot reviewer
Network Manager at a insurance company with 1,001-5,000 employees
Vendor
Good value compared to Check Point. But I had issues when integrating with Cisco IPS.

Valuable Features:

1. I have found tje Cisco ASA to be less expensive than Check Point firewalls. 2. It is smaller in size than Check Point firewall. 3. It is easy to operate and manage with both GUI and Command Line

Room for Improvement:

1. When I integrate Cisco ASA with Cisco IPS it creates lots of problem such as an increase in CPU utilization - as a result I have to stop the IPS service. 2. Cisco ASA does not provide a flash card for free so I cannot back up the firewall configuration for disaster recovery.

Other Advice:

In my opinion it is a nice firewall product at a low price and good value for medium and large enterprises.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user2871 - PeerSpot reviewer
Network Engineer at a university with 51-200 employees
Vendor
Powerful firewall and VPN device that is highly stable with multiple contexts but has latency and NATing issues

Valuable Features:

-Powerful firewall provides multiple contexts. -Highly stable firewall for campus traffic with no shutdown and zero maintenance compared to the Juniper SRX family which performs like a software firewall after 3 months of operation and did not allow the administrator to login. -Easy to use both GUI and command line. Also it may be more easily used through a management application like Cisco ASDM

Room for Improvement:

-Latency and delay due to configuration and monitoring of multiple VLANS and traffic -Increases the delay as the firewall and IPS polices increase -We faced usually a problem with NATING

Other Advice:

Cisco delivers a powerful firewall -- it’s not just a firewall but also a modular device that can deliver IPS hosting and wireless LAN controller as well. It also provides site to site VPN and remote access VPN services.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Network Engineer at a tech services company with 201-500 employees
Real User
Easy to operate with good technical support, but needs better logging features
Pros and Cons
  • "The command line is the same as it is on the Cisco iOS router."
  • "The solution needs to have better logging features."

What is our primary use case?

We primarily provide implementation and maintenance services to our clients.

What is most valuable?

The software itself is very simple.

The solution is easy to operate. It's not overly complex.

The command line is the same as it is on the Cisco iOS router.

The technical support is very helpful and responsive.

What needs improvement?

The solution needs to have better logging features.

Cisco needs to migrate its ASA Firewall to a management console or to a web console.

For how long have I used the solution?

I've been working with the solution for six years at this point.

What do I think about the stability of the solution?

The solution is largely stable. Once we adopted Cisco services, we found that everything was pretty reliable. There aren't bugs or glitches. It doesn't crash or freeze. It's quite good.

What do I think about the scalability of the solution?

The scalability is a problem as the solution has a low throughput.

How are customer service and technical support?

We've been in touch with technical support and I've always found them easy to reach. They're responsive and helpful. I find their service much better than, for example, Fortinet or Palo Alto. Overall, we're satisfied with Cisco with respect to their technical support.

Which solution did I use previously and why did I switch?

We have some experience working with Palo Alto and Fortinet solutions as well.

What's my experience with pricing, setup cost, and licensing?

While I don't have the exact pricing of the solution, it's my understanding that Cisco is rather costly. It's not the cheapest option on the market. It's expensive. It's more costly, for example than Palo Alto.

What other advice do I have?

We have a gold partnership status with Cisco, however, we are also partners with companies such as Fortinet and Palo Alto.

For a next-generation firewall, I would likely recommend Palo Alto. However, if a company had the budget, I would recommend Fortinet. That said, for a VPN gateway, I would recommend Cisco ASA.

In general, I would rate Cisco's ASA Firewall at seven out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros sharing their opinions.
Updated: November 2024
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros sharing their opinions.