Its security features are the most valuable aspect. It has the ability to detect and prevent intrusions.
IT Support Engineer
Its security features are the most valuable aspect. The equipment is too expensive.
What is most valuable?
How has it helped my organization?
The product has helped organizations secure their infrastructure and data. Most organizations are happy to adopt the technology.
What needs improvement?
The equipment is too expensive compared with other firewall products.
For how long have I used the solution?
I have used ASA for about three months. I just bought and configured it for a client.
Buyer's Guide
Cisco Secure Firewall
September 2025

Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
867,676 professionals have used our research since 2012.
What do I think about the stability of the solution?
Since I installed and configured it, the client has never called with complaints.
What do I think about the scalability of the solution?
I have not had scalability issues at all. Maybe it is because I have not used it quite extensively.
How are customer service and support?
I haven't had a chance to interact with the support team.
Which solution did I use previously and why did I switch?
The previous product was limited in throughput and security.
How was the initial setup?
The initial setup was quite complex.
What's my experience with pricing, setup cost, and licensing?
As much as there is value for money, there is a need to make it affordable.
Which other solutions did I evaluate?
I tried Sophos.
What other advice do I have?
It is a very good device to use for those who value their network security.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Member of the Board of Directors at a tech services company with 1,001-5,000 employees
Class-based policing is the most important part of the ASA, and was its differentiator.
What is most valuable?
Class-based policing is the most important part of the ASA, and was its differentiator.
How has it helped my organization?
It gave us more organized DMZs and logical segments.
What needs improvement?
I’m not a fan of the new modular licensing model. Cisco moved from a base license to an a la carte SaaS model a couple of years back, wherein the customer is required to pay for feature sets on a case-by-case basis. This makes it difficult for people who want to study and trial new technologies and features.
For how long have I used the solution?
I’ve been using ASA technology since it was PIX, so since 1999.
What do I think about the stability of the solution?
We have not had stability issues.
What do I think about the scalability of the solution?
We have not had scalability issues.
How are customer service and technical support?
Support with Cisco TAC, or with VARs like WWT and Trace3 is usually pretty good.
Which solution did I use previously and why did I switch?
I have used both ASA and PAN. Different strokes for different folks.
How was the initial setup?
Initial setup is straightforward. You can get as granular and complex as you want, but out of the box, ASAs provide a secure FW solution.
Which other solutions did I evaluate?
We evaluate all other options.
What other advice do I have?
ASAs are a solid solution. Cisco provides more training and learning materials than any other vendor, which is critical if an organization wants to take true ownership of a technological solution. Documentation and use cases alone tend to make me a fan of Cisco's way of engineering, and they have come a long way over the last few years when it comes to integrating their solutions into comprehensive security communications platforms using tools like PRIME and ISE. FirePOWER and AMP make Cisco an even better overall contender for top FW status.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Cisco Secure Firewall
September 2025

Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
867,676 professionals have used our research since 2012.
Networking Specialist at a insurance company with 1,001-5,000 employees
Provides management with the adaptive security device manager.
What is most valuable?
It is good for firewalls, management with the adaptive security device manager (ASDM), and tools such as packet tracers for troubleshooting.
It’s a really good firewall which is easy to manage, but it is not a Next Gen firewall.
Firewall functionality is the main issue when buying this product. We use it to segment our DMZs, it is stateful firewalling, is highly reliable with zero outages, and impeccable failovers during upgrades.
The ASDM is the management tool to administer the ASAs via the GUI. It has an easy to use interface with very nice troubleshooting tools, such as Packet Tracer. This tool lets you simulate a traffic flow so you can see why flows don’t work.
How has it helped my organization?
It is a very reliable border firewall which makes it easy for us to organize and secure our DMZs.
What needs improvement?
- The SSL VPN portal could be better.
- The ASAs support both IPSEC as an SSL VPN.
- For IPSEC you need a Cisco VPN client.
- You can only have two SSL VPN sessions.
- For more SSL sessions you have to pay (750 IPSEC sessions are included with an ASA).
- With SSL, you connect through a browser, so it is clientless. The SSL portal offers a few functionalities which you can offer a user. Configuring this portal is not an easy task.
For how long have I used the solution?
We have been using the solution for almost five years.
What do I think about the stability of the solution?
We didn't encounter any issues with stability.
What do I think about the scalability of the solution?
Scalability is limited depending on the chosen model.
How are customer service and technical support?
I would give technical support a rating of 9/10. Cisco is one of the best, if not the best, in support.
Which solution did I use previously and why did I switch?
We chose FortiGate from Fortinet as our Next Gen Firewall solution because of the higher value for our money.
How was the initial setup?
The setup was easy with lots of documentation and configuration examples provided.
What's my experience with pricing, setup cost, and licensing?
You have to negotiate well.
Which other solutions did I evaluate?
We did not evaluate any alternative options for stateful firewalling.
What other advice do I have?
You will want to have Next Generation functionality, so choose FortiGate or Cisco Firepower.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Project Manager with 11-50 employees
It is very robust, trustworthy and highly customizable.
What is most valuable?
It is very robust, trustworthy and highly customizable.
How has it helped my organization?
Solutions using NAT, VPNs, internet and MPLS, are more customizable than other solutions.
What needs improvement?
It could have more functions for load balance on the internet.
For how long have I used the solution?
We have been using the solution for two years.
What do I think about the stability of the solution?
We never had any stability issues. It is the most stable platform that I have used, and I have used several including Fortinet, Sophos, Hillstone, Cisco and D-Link.
What do I think about the scalability of the solution?
We did not encounter any issues with scalability.
How are customer service and technical support?
I would rate the technical support at 10/10. It is the best.
Which solution did I use previously and why did I switch?
I implement solutions on several clients, Redneet is a technology integration company and I prefer Cisco ASA for my security solutions.
How was the initial setup?
The setup is a little more complex than other solutions.
What's my experience with pricing, setup cost, and licensing?
It is a bit more expensive than other solutions, but offers more customization and security than other solutions.
Which other solutions did I evaluate?
We evaluated Fortinet, Sophos, Palo Alto.
What other advice do I have?
Use the best practice guides and online documentation. Cisco has more information online free that any other brand, so use it!!!
Disclosure: My company has a business relationship with this vendor other than being a customer. We are a Cisco Partner.
Senior Network Designer at ODI
You can extend your visibility in network infrastructure for monitoring.
What is most valuable?
The Advanced Malware Protection and Security Group Tag (SGT) are valuable features. You are able to integrate all the networks by using SGT with the pxGrid service. This is built-in technology in Cisco devices and services.
How has it helped my organization?
You can extend your visibility in network infrastructure for monitoring. You can absolutely give your users a better experience. When you use .1X for user authentication:
- Users login just one time
- You can control all user access to the internet, data center resources, and across the network.
What needs improvement?
After Firepower V6.1, Cisco added bandwidth shaping on the FTD product. This feature is a little bit weak. You cannot have customized shaping in different projects.
For how long have I used the solution?
I have used this product, as well as Cisco Firepower Threat Defense, for about two years.
What do I think about the stability of the solution?
I have heard about some bugs, but I have never encountered any.
What do I think about the scalability of the solution?
This product is very scalable in our experience.
How was the initial setup?
It is easy to initialize. For advanced configurations, it is sometimes complicated.
What's my experience with pricing, setup cost, and licensing?
The base license is delivered with the device. This license includes IPS and user authentication. You should buy a license for an IPS update. You should also buy another license for AMP and URL filtering.
These are the important licenses: BASE, IPS, AMP, and URL filtering. Apart from the base license, the other licenses are subscription based for one, three, or five years.
Which other solutions did I evaluate?
I evaluated many products, such as CheckPoint, Palo Alto, Fortinet Firewall, Sophos, and Cyberoam Firewall.
What other advice do I have?
This product is very usable when you need integrity in your network. This product is very functional when you use a Cisco Identity Services engine.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Corporate Information Security Officer
A standard rule based firewall that has solved many remote access problems.
What is most valuable?
It's a standard rule based firewall for us. The AnyConnect VPN has solved a lot of remote access problems. High availability is good. It will fall back to the other ASA without any disruptions.
How has it helped my organization?
It has secured our DMZ.
What needs improvement?
I would like to see the following made easier:
- Objects
- Removing objects
- Correlating access rules and AnyConnect ACLs
Sometimes we suffer from older versions, such as objects, object groups, and aliases (name).
For how long have I used the solution?
We have been using the solution for nine years.
What do I think about the stability of the solution?
We did not encounter any stability issues.
What do I think about the scalability of the solution?
We did not encounter any scalability issues.
How are customer service and technical support?
The technical support is good.
Which solution did I use previously and why did I switch?
We used Cisco PIX.
How was the initial setup?
I can't really remember the setup. It was too long ago.
What's my experience with pricing, setup cost, and licensing?
We bought the solution, so there were no real recurring costs at that time.
Which other solutions did I evaluate?
We didn't evaluate any alternative products.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Security Consultant at a tech services company with 51-200 employees
It allows us to filter incoming traffic to our network and provide a secure access to office network from outside through remote access VPN.
What is most valuable?
Cisco ASA is a stateful firewall which means they are the fastest and more secure, because they maintain state tables. Cisco ASA is very efficient not only in Firewalling but in VPNs, IPS and content filtering. It also has option of failover and redundancy.
How has it helped my organization?
It allows us to filter incoming traffic to our network and provide a secure access to office network from outside through remote access VPN. We also connected our branch office through IPSEC site-to-site VPN tunnel which is very secure and reliable.
What needs improvement?
Some improvements required on GUI interface called ASDM. It should include health check parameters like temperature, memory used.
For how long have I used the solution?
I am using it more than five years.
What was my experience with deployment of the solution?
No issues, very easy to deploy.
What do I think about the stability of the solution?
No.
What do I think about the scalability of the solution?
Migration to new version is very easy, therefore no issue.
How are customer service and technical support?
Customer Service:
9/10.
Technical Support:9/10.
Which solution did I use previously and why did I switch?
Cisco ASA firewall is most reliable to protect the network, therefore I switched.
How was the initial setup?
Yes, straightforward and simple.
What about the implementation team?
I am also vendor.
What was our ROI?
100%.
What's my experience with pricing, setup cost, and licensing?
Price is bit high as compared to other vendors, but Cisco ASA has reputation and most reliable product. Always go with minimum security plus license.
Which other solutions did I evaluate?
Yes, Fortinet and Palo Alto.
What other advice do I have?
No.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller.
Simplified the complexity of our security architecture.
What is most valuable?
Provides advanced malware capabilities.
How has it helped my organization?
Simplified the complexity of our security architecture.
What needs improvement?
Integration of advanced malware services with the firewall through Firepower services.
For how long have I used the solution?
We have been using this solution for six months.
What was my experience with deployment of the solution?
There were no issues with deployment.
What do I think about the stability of the solution?
There were no issues with stability.
What do I think about the scalability of the solution?
There were no issues with scalability.
How are customer service and technical support?
Customer Service:
I would give customer service a rating of 10/10.
Technical Support:I would give technical support a rating of 10/10.
Which solution did I use previously and why did I switch?
We were looking to upgrade to a comprehensive firewall solution that integrated Next Generation Prevention System (NGIPS).
How was the initial setup?
There were no issues with setup.
What about the implementation team?
We implemented in-house.
What was our ROI?
We calculated for the entire year, but the ROI seemed very decent from the first six months.
What's my experience with pricing, setup cost, and licensing?
Pricing: Negotiate
Licensing: Buy the advanced Malware Protection license subscription for one year. It is worth the investment.
Which other solutions did I evaluate?
We evaluated Juniper, Fortinet, and Huawei.
Disclosure: My company has a business relationship with this vendor other than being a customer. We are a CISCO Security Business partner

Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2025
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
Sophos XG
Cisco Umbrella
Cisco Identity Services Engine (ISE)
Palo Alto Networks NG Firewalls
Cisco Meraki MX
WatchGuard Firebox
Check Point Quantum Force (NGFW)
Azure Firewall
SonicWall TZ
Sophos XGS
Cisco Secure Network Analytics
Fortinet FortiGate-VM
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Is The Biggest Difference Between Cisco ASA And Fortinet FortiGate?
- Cisco Firepower vs. FortiGate
- How do I convince a client that the most expensive firewall is not necessarily the best?
- What are the biggest differences between Cisco Firepower NGFW and Fortinet FortiGate?
- What Is The Biggest Difference Between Cisco Firepower and Palo Alto?
- Would you recommend replacing Cisco ASA Firewall with Fortinet FortiGate FG 100F due to cost reasons?
- What are the main differences between Palo Alto and Cisco firewalls ?
- A recent reviewer wrote "Cisco firewalls can be difficult at first but once learned it's fine." Is that your experience?
- Which is the best IPS - Cisco Firepower or Palo Alto?
- Which product do you recommend and why: Palo Alto Networks VM-Series vs Cisco Firepower Threat Defense Virtual (FTDv)?