Try our new research platform with insights from 80,000+ expert users
PeerSpot user
Senior Consultant at Unify Square
Real User
Dec 11, 2017
An excellent firewall, and one of the best available choices for big size companies. As usual excellence requires money.
Pros and Cons
  • "ASA is stable and with a low level of work required on the maintenance side."
  • "You have to know the ASA command line very well because not all operations are available in the graphical interface"

What is our primary use case?

Cisco ASA is born as an hardware firewall. The user case is security check on company's external connections (Internet and VPN access).

Most recent versions include antivirus and intrusion prevention to add security layers (including the above scenarios and the internal network) 

How has it helped my organization?

Cisco ASA have been the main security device for many years, slowly replaced with Check Point on the main datacentre.

What is most valuable?

ASA is stable and with a low level of work required on the maintenance side. It is a dedicated firewall, so you do not have to manage additional topics like spam, web sites filtering and so on.The routing part is high level as usual with Cisco products.  

What needs improvement?

You have to know the ASA command line very well because not all operations are available in the graphical interface (or let's say that sometimes it is better to operate with the ASA CLI).If you are searching for an "all in one product" it is not for you

Buyer's Guide
Cisco Secure Firewall
March 2026
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
884,873 professionals have used our research since 2012.

What do I think about the stability of the solution?

No, stability is a really strong point with ASA.

What do I think about the scalability of the solution?

No, an assessment about the workload is important to select the right device.

How are customer service and support?

Over many year, the only kind of support we needed directly from Cisco was (really seldom) for parts replacement

Which solution did I use previously and why did I switch?

The previous solution was based on software firewalls that where not able to perform as the Cisco ASA

How was the initial setup?

Setup of a firewall, on a medium / large deployment is always a complex work.

Cisco ASA (more than other vendors' solutions) require a lot of know-how and real world expertise to be configured properly.

What about the implementation team?

More than one external team (Cisco partners) has been involved over time.

All of them were outstanding in their work.

What was our ROI?

Positive. The devices serves thousands of users for many years, outliving other vendors solutions.

What's my experience with pricing, setup cost, and licensing?

Cisco devices are for sure costly and budget could be an important constrain on selecting them as our security solution. 

Which other solutions did I evaluate?

When the choice was made, some comparison was made with other market leaders but integration with the existing Cisco network was a really important positive side in the final decision.

What other advice do I have?

ASA is one of the the state-of-the-art firewall devices for security.
It is affordable and not too complicated to use if you are doing standard operations (modifying ACLs, natting and so on) on an existing deployment.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user487374 - PeerSpot reviewer
it_user487374VP Product Management at a tech services company with 51-200 employees
Top 20Real User

Did it replace a different product you had? Did you consider other products before choosing to go with this one?

PeerSpot user
Owner at David Strom Inc.
Writer
Top 20Leaderboard
Aug 20, 2017
Cisco has done a superior job at its next generation of firewall technology.

What is most valuable?

The user interface of the Prime Security Manager is, well, prime and one of the best pieces of software I have seen from them, and the features are on par if not better than what their competitors offer.

How has it helped my organization?

Cisco has done a nice job of integrating global IP reputation management into the firewall with its Security Intelligence and Operations module for insights and malware collection.

What needs improvement?

Prime manager is just for the CX line for now. CX features also add about a 30% overhead on throughput.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Cisco Secure Firewall
March 2026
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
884,873 professionals have used our research since 2012.
it_user682167 - PeerSpot reviewer
Network and System Engineer at a non-tech company with 201-500 employees
Real User
Jul 31, 2017
IPS features can be accessed from a separate interface

What is most valuable?

I enjoy the interface of Cisco products, especially the CLI version. I think the IPS feature in the product is best compared to products of other vendors. All the IPS features can be accessed from a separate interface, e.g., Cisco IDM.

How has it helped my organization?

We are an educational institute, and we are required to block many websites that are not suitable for students and teachers. Most of the sites, like YouTube uses an https version, thus blocking with IP address was becoming problematic. Moreover, certificate domains for Gmail and YouTube are the same. But the IPS feature in this product helps us to overcome this limitation.

What needs improvement?

Pricing of this product needs improvement.

For how long have I used the solution?

I have used this solution for two years.

What do I think about the stability of the solution?

I did not encounter any issues with stability.

What do I think about the scalability of the solution?

I did not encounter any issues with scalability.

How are customer service and technical support?

I would give technical support a rating of a nine out of 10.

Which solution did I use previously and why did I switch?

I worked with Cyberoam and Fortinet UTM at my previous job. When I joined my present company, they were already using the Cisco ASA solution. But my present company may switch to other vendors, especially Fortinet, because of the license renewal price.

How was the initial setup?

As I enjoy working on CLI, I would say that the initial setup was not complex.

What's my experience with pricing, setup cost, and licensing?

License and appliance costs are more expensive as compared to other vendors on the market.

What other advice do I have?

If your company is small or mid-range, it is better to go with other vendors, because of the pricing.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
IT Adviser/Manager with 51-200 employees
Real User
Jul 24, 2017
The Cisco ASDM management tool was helpful. I would like to see good reporting options.
Pros and Cons
  • "The ASA 55-x range is a solid and reliable firewall. It secures the traffic for normal purposes."
  • "Firewalls, in general, were not really designed for normal IT personnel, but for firewall and network experts. Therefore, they missed a lot of options and did not provide any good reporting or improvement options."

How has it helped my organization?

The ASA 55-x range is a solid and reliable firewall. It secures the traffic for normal purposes.

If you ask how a firewall can improve our business: It can’t. It is securing our business IT network.

But if you want to know what the ASA5520 can do to secure our network:
Not much more than any firewall. It is a solid port firewall, nothing more, nothing less.

What is most valuable?

The Cisco ASDM management tool was helpful.

What needs improvement?

Firewalls, in general, were not really designed for normal IT personnel, but for firewall and network experts. Therefore, they missed a lot of options and did not provide any good reporting or improvement options.

For example, to update or add a feature, you end up buying new support and licenses. The process is complex and changes so rapidly that you won't find a salesperson who will offer you the right products.

New generation firewalls are cloud managed or provide a good interface. They integrate into the environment. They are application aware and come with security features that are especially designed for the purpose.

What do I think about the stability of the solution?

There were no stability issues.

What do I think about the scalability of the solution?

You need to buy a new product if you want to scale. I once tried to put in another network card and ended up in a support nightmare. I had to buy more support, licenses, and it was more expensive than buying a new one.

How are customer service and technical support?

Customer Service:

Customer service is non-existent. You need to go through a very complex and annoying approval system before you can get any help. The support then gets asked a question and you get one word answers. It takes you hours to find out what version of an update you need to install, and then another day to find out how to install it.

Technical Support:

I would give technical support a rating of zero out of 10. It is clear that Cisco is not for the end-customer, but rather for resellers and providers. They might have better contracts and get more technical support.

Which solution did I use previously and why did I switch?

I usually have to take what is there. If I had a choice, I would now take something newer.

How was the initial setup?

You can start very easy and set up the network cards, but it also has many traps to find out the right setting for your environment.

For example, you need fixed network settings on your switch to connect with full duplex 100Mb/s. There is no autonegotiation nor other settings. This is the same problem with the WAN connection. You need to know exactly what to configure to match the WAN, or it will not work.

What about the implementation team?

I once had support from a reseller and once from a provider. Both depended on the level of the person you speak with. Most have some knowledge.

What was our ROI?

Once installed, they last a long time. I would recommend replacing them after some years to get better security features.

What's my experience with pricing, setup cost, and licensing?

If you look for user internet access, many new products can help with filtering and rules or procedures, like Meraki. This replaces the purpose of proxy servers.

If you have to secure web servers from the internet, you need a decent firewall with web features to process the requests and redirect traffic to web servers.

Cisco is no longer the only vendor offering these features. With Microsoft TMG out of the race, others have to push in. But firewalls are also no longer the first frontier of security. Cloud services are in there as well.

Which other solutions did I evaluate?

I had no choice.

What other advice do I have?

Get someone to help you plan and set up the firewall concept, as well as the initial setup and testing. Waiting for later is not the time to test or change anything without an outage.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Presales Consultant at a tech services company with 51-200 employees
Consultant
Jul 23, 2017
One of the most valuable features is the correlation of events -- including the path that a file is taking in the network and its integration with the endpoint protection.

What is most valuable?

Classic ASA features such as NAT, Stateful Firewall, and VPN are basic functions for average organizations, but next generation features such as the granular control of port hopping applications, IPs, and malware protection are mandatory, considering current advanced security threats.

One of the most valuable features is the correlation of events, including the path that a file takes in the network and its integration with the endpoint protection. This gives you the chance to take some actions in the case a breach happens.

How has it helped my organization?

Visibility in the network traffic.

What needs improvement?

Management console – Firesight Management Center.

When deploying Cisco FMC versions 6.0 and 6.1, some issues may appear when trying to register ASA sensors. The problem needs Cisco TAC involvement, adding more effort and time. I guess this will be fixed in version 6.2.

For how long have I used the solution?

I've used this solution for three to five years.

What do I think about the stability of the solution?

Some releases of the unified image (FTD – Firepower Threat Defense – Cisco ASA + Sourcefire IPS) are not very stable, but things are getting improved.

What do I think about the scalability of the solution?

Some clustering functions are not available in the unified image.

How are customer service and technical support?

Excellent.

Which solution did I use previously and why did I switch?

Old ASA 5500. Natural upgrade to next generation functions.

How was the initial setup?

Initial setup is pretty straightforward.

What's my experience with pricing, setup cost, and licensing?

The licensing model has been simplified and is easy to understand. The price is higher compared to UTM solutions, such as Fortinet, but in the same range as Checkpoint and Palo Alto.

Which other solutions did I evaluate?

We also work with Palo Alto Networks, Fortinet, FireEye, and some other vendors.

What other advice do I have?

Take a look at the features included in the unified image. Some classic ASA functionality has not been integrated yet, go for non-unified image if the deployment requires something that is not available – classic ASA iOS plus Sourcefire code.

Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Sergei Chernooki - PeerSpot reviewer
IT SecOps Manager at a computer software company with 1,001-5,000 employees
Vendor
Jul 19, 2017
The best features are NAT, transport-layer inspections, and VPN

What is most valuable?

Cisco ASAs are great network firewalls and they can work for years after being configured. The best features are NAT, transport-layer inspections, and VPN.

How has it helped my organization?

With ASAs, we can keep operational expenses as low as possible. Disaster risks should be observed as usual, but this is definitely not the weak point.

What needs improvement?

I would like to see new SW versions being more stable and HW performance increase. However, the new 2000 series has high performance, but it is not shipped widely so far.

For how long have I used the solution?

I started using Cisco firewalls when old PIX models were produced. I then observed all model changes. This makes about 10 years of continuous experience.

What do I think about the stability of the solution?

There are no real stability issues, if upgrades are done carefully.

What do I think about the scalability of the solution?

I believe scalability issues are caused by poor design.

How are customer service and technical support?

Cisco technical support makes a good impression most of the time.

Which solution did I use previously and why did I switch?

Some of my customers switched from ZyXel to Cisco and this is an obvious decision for me. It will be much harder to imagine a customer replacing Check Point or Fortinet with Cisco.

How was the initial setup?

The initial setup should not be left to the customer. The best way to do this is to make a basic setup and integration along with cabling and power-up, then verifying requirements and adjusting the configuration.

What's my experience with pricing, setup cost, and licensing?

Basic features and IPs can work without subscriptions. All next-generation features require per-year payments. Enterprise customers usually agree with price and license fees, so I don't see any painful issues with pricing and licensing.

Which other solutions did I evaluate?

I compared Cisco with Fortinet, Checkpoint, and DIY solutions.

What other advice do I have?

All you need to succeed is careful design, professional setup, and a support contract.

Disclosure: My company has a business relationship with this vendor other than being a customer. We have been Cisco channel partners for over 15 years.
PeerSpot user
PeerSpot user
Technical Specialist with 5,001-10,000 employees
Real User
Jul 18, 2017
The throughput and reliability of the product improve the network stability of our organization.

What is most valuable?

VPN (site to site VPN and remote access ), NAT policies, modular policy framework, detailed troubleshooting methods.

How has it helped my organization?

The throughput and reliability of the product improve the network stability of our organization.

What needs improvement?

Area : URL filtering and content filtering.

When Cisco ASA is presented as an enterprise firewall, that should be capable doing IPS/IDS, firewalling, VPN concentrator, application filtering, URL filtering and content filtering.

Of course, the last three technologies can do by a proxy. But nowadays, all next generation firewalls like Fortinet, Check Point, and Palo Alto are each bundling the UTM features into a single box with multiple separate content processors (hardware) to do these jobs.

This would enable single pane glass for management. No need to look at different devices for change management and troubleshooting.

I would say Cisco ASA is the best except for its URL and content filtering module. And these modules in ASA are not straightforward, rather complex in managing the device.

What was my experience with deployment of the solution?

I've been using this solution since 2007.

What do I think about the stability of the solution?

No.

What do I think about the scalability of the solution?

All product-based firewalls will encounter scalability issues. The firewall sizing is important during the sizing.

How are customer service and technical support?

Good.

Which solution did I use previously and why did I switch?

I used to work with most of the hardware firewalls, Cisco ASA is reliable and few technologies are good enough to compete for the market (VPN, Modular policy framework, NAT, etc.).

How was the initial setup?

Straightforward -- console or via the interface.

What's my experience with pricing, setup cost, and licensing?

Expensive when compared to other products.

Which other solutions did I evaluate?

Yes, all.

What other advice do I have?

If you are looking into implementing VPN or advanced features, I recommend using this product. URL or content filtering is not good as much as the NGFWs are.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Computer Networking Consultant and Contractor at a tech services company with 51-200 employees
Consultant
Jul 17, 2017
Initial setup was very straightforward because the training and certification provided by the vendor helped us to solve rapidly any configuration issues.​
Pros and Cons
  • "Stability, high availability of services, and very high MTBU were the most valuable features for me."
  • "The ability to integrate (as options) all-in-one features -- like anti-spam, anti-virus, etc."

How has it helped my organization?

I have 15 years’ experience with Cisco products and I've had very, very little problems with them. Also, for resolving appeared issues Cisco was a good partner.

Crescendo (www.crescendo.ro) is an IT&C integrator and this product (based on Cisco Partnership) helped us to grow our business, and Cisco ASA was one of most sold product in our solutions portfolio.

What is most valuable?

Stability, high availability of services, and very high MTBU were the most valuable features for me -- because in my work as network and security consultant, it is very important to guarantee to my customer the security of his business.

What needs improvement?

The ability to integrate (as options) all-in-one features -- like anti-spam, anti-virus, etc.

What do I think about the stability of the solution?

With Cisco ASA firewall, no.

What do I think about the scalability of the solution?

No. Based on their recent acquisition of Firepower, Cisco added "multi 10Gbps" NGFW performance in their solutions portfolio, which can be used by us, as a Gold Partner with Advance Security Architecture Specialization, in our network architecture proposals.

How are customer service and technical support?

Very satisfied.

Which solution did I use previously and why did I switch?

I haven' t used another solution.

How was the initial setup?

Initial setup was very straightforward because the training and certification provided by the vendor helped us to solve rapidly any configuration issues.

What's my experience with pricing, setup cost, and licensing?

To discuss with Cisco Systems or their partners to gain the optimal price and to not consider, without verifying, the false information that Cisco ASA is very expensive.

Which other solutions did I evaluate?

We evaluated other solutions, like Fortinet, HPE, Juniper, Check Point, but Cisco ASA was what we need.

What other advice do I have?

To test the product in their network and to evaluate other products. I am sure that the Cisco ASA Firewall will be the winner.

Our complete relationship is based on the following partner competencies:
Certifications:

• Gold Certified Partner
Specializations:
• Advanced Collaboration Architecture Specialization
• Advanced Data Center Architecture Specialization
• Advanced Enterprise Networks Architecture Specialization
• Advanced Security Architecture Specialization


Cloud Partners:
• Storage: EMC
• Virtualization: VMware
• Cloud Management: VMware
• Cloud Professional Services
• SaaS Simple Resale


Other Authorizations:
• Registered Partner
• Cisco Certified Refurbished Equipment
• Cisco Developer Network Cisco Products Marketplace
• Cisco Meeting Server formerly Acano
• PSPP Defense
• Smart Care Registered Partner
• ATP - Unified Contact Center Enterprise

Partner since:

• More than 10 years

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2026
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros sharing their opinions.