Business use. It has performed well.
Information Systems Manager at a manufacturing company with 201-500 employees
Its most valuable feature is its ability to work with the traffic
Pros and Cons
- "Its ability to work with the traffic."
- "I would like it to be easier to work with and have a better user interface. It is not straightforward. You need to know the Cisco command-line interface."
- "Initial setup was fairly complex."
What is our primary use case?
What is most valuable?
Its ability to work with the traffic.
What needs improvement?
I would like it to be easier to work with and have a better user interface. It is not straightforward. You need to know the Cisco command-line interface.
What do I think about the stability of the solution?
Stability has been fine.
Buyer's Guide
Cisco Secure Firewall
November 2024
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,636 professionals have used our research since 2012.
What do I think about the scalability of the solution?
It is good.
How are customer service and support?
I have not used technical support.
Which solution did I use previously and why did I switch?
We have always been with Cisco.
How was the initial setup?
Initial setup was fairly complex. Just having to know the command prompt rather than having a better user interface.
What's my experience with pricing, setup cost, and licensing?
We looking for a possible new solution because of the licensing and VPN.
Which other solutions did I evaluate?
We evaluated Cisco and Meraki.
What other advice do I have?
Look through what your needs are.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
ESS Security with 201-500 employees
Allows us to implement active/backup HA with ASAv (Adaptive Security Virtual Appliance)
Pros and Cons
- "In v9.8 you are able to do active/backup HA with ASAv (Adaptive Security Virtual Appliance) deployed on MS Azure."
- "The relatively new Firepower Threat Defense image (mix of ASA and Sourcefire network security) fills a lot of gaps and features that were missing on ASA."
What is most valuable?
Starting in version 9.7 you could track a login history for audit purposes and, in 9.8, you are able to do active/backup HA with ASAv (Adaptive Security Virtual Appliance) deployed on MS Azure.
What needs improvement?
There is always room for improvement in virtually anything. However, the relatively new Firepower Threat Defense image (mix of ASA and Sourcefire network security) fills a lot of gaps and features that were missing on ASA. Moreover, with FMC (Firepower Management Console) you can complement it with even more admin and reporting capabilities for the entire platform.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
No stability issues.
What do I think about the scalability of the solution?
No scalability issues.
How is customer service and technical support?
Excellent.
How was the initial setup?
New version comes with initial setup tutorial, with very nice security policies baseline, set up by default.
What's my experience with pricing, setup cost, and licensing?
Be sure of what features you are going to utilize to add/remove some from new bundles.
What other advice do I have?
Best value will always be delivered by adding FMC (Firepower Management Console); at least their virtual edition.
Disclosure: My company has a business relationship with this vendor other than being a customer: Distributor.
Buyer's Guide
Cisco Secure Firewall
November 2024
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,636 professionals have used our research since 2012.
Consultant
Management Console and user profiling to define activities are key features
Pros and Cons
- "Management Console and user profiling to define activities."
- "As it’s a GenX firewall, expertise for both implementation and troubleshooting the pain points can be a challenge. This could be a concern when companies are thinking about buying this product."
How has it helped my organization?
It’s too early to say anything about this, as it’s still under implementation.
What is most valuable?
Management Console and user profiling to define activities.
What needs improvement?
As it’s a GenX firewall, expertise for both implementation and troubleshooting the pain points can be a challenge. This could be a concern when companies are thinking about buying this product.
For how long have I used the solution?
Still implementing.
What do I think about the stability of the solution?
Yes, unexpected failure and no RCA provided by the OEM.
What do I think about the scalability of the solution?
Still working on this.
How are customer service and technical support?
Technical support from OEM is a six out 10, as RCA report has still not been shared to date.
Which solution did I use previously and why did I switch?
Check Point. We moved to Firepower as an internal firewall to manage internal access and other network load.
How was the initial setup?
Straightforward, two-tire setup.
What's my experience with pricing, setup cost, and licensing?
All our requirements which we need performed by the firewall (e.g. VPN, URL white-listing, or IP based white-listing, etc.) have separate licenses and costs.
Which other solutions did I evaluate?
Yes, a couple of other of OEMs: Fortinet, Barracuda, etc.
What other advice do I have?
I rate it an eight out of 10, as it’s a new platform. Compared to Cisco ASA, it’s far better, per my usage to date.
Make sure you have an expert resource or subscribe to OEM technical support.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
President and CTO with 51-200 employees
Very good as a stateful inspection firewall, but weak in all other areas
Pros and Cons
- "Strong in NAT and access-lists."
- "Very good as a stateful inspection firewall."
- "VPNs are weak as this product still does not support route-based VPNs."
What is our primary use case?
Firewall only - no advanced services.
How has it helped my organization?
In the early days, before UTM and NGFW, this product was awesome. Cisco tried to add Firepower, but it requires a different management interface and is still too expensive.
What is most valuable?
- Strong in NAT and access-lists
- Very good as a stateful inspection firewall, but weak in all other areas.
What needs improvement?
- Integrated threat management
- Route-based VPNs: VPNs are weak as this product still does not support route-based VPNs.
- Single management interface
- Better throughput for price point
For how long have I used the solution?
More than five years.
What's my experience with pricing, setup cost, and licensing?
Price point is too high for features and throughput available.
What other advice do I have?
Overall, this is a legacy product.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
I.T. Security/Projects Specialist at a tech services company with 501-1,000 employees
We wanted a back-end/internal firewall solution, and this provided it for us.
What is most valuable?
Firewalling is the most valuable feature. We wanted a back-end/internal firewall solution, and the Cisco ASA 5525 was great.
How has it helped my organization?
It has taken the pressure off of the IS engineer.
What needs improvement?
- URL
- AVC
- Advanced malware protection
For how long have I used the solution?
We've used it for two years.
What was my experience with deployment of the solution?
There was an issue, but it was rectified promptly after troubleshooting the device's configuration.
What do I think about the stability of the solution?
There were no issues with the scalability.
What do I think about the scalability of the solution?
We've not had any issues scaling yet.
How are customer service and technical support?
Customer Service:
I think it is great but did not use them for this deployment.
Technical Support:I've not had to use them yet for this deployment.
Which solution did I use previously and why did I switch?
There was no other solution in place.
How was the initial setup?
It was straightforward.
What about the implementation team?
I did the implementation with my colleagues.
What was our ROI?
It's not really quantified, but we have not experienced downtime due to attacks.
Which other solutions did I evaluate?
There were no other solutions looked at.
Disclosure: My company has a business relationship with this vendor other than being a customer: We're a systems integrator and a gold partner.
Security Engineer at a tech services company with 501-1,000 employees
FirePOWER mobile is good, but they should make the device accesible from the web.
Valuable Features
- Firewall
- VPN
- FirePOWER mobile
Room for Improvement
They should make the ASA accessible via the web instead of ASDM. Also, a big improvement is needed on the transparent mode.
Use of Solution
I've used it for over six months.
Deployment Issues
There were some issues.
Stability Issues
There have been some issues with Java.
Scalability Issues
There were some issues.
Customer Service and Technical Support
Customer Service:
8/10.
Technical Support:8/10.
Initial Setup
It was straightforward.
Other Advice
Make sure to plan your network carefully.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
System Engineer at a tech services company with 501-1,000 employees
Stable, scalable, and flexible, with good support
Pros and Cons
- "It's a flexible solution."
- "The configuration is an area that needs improvement."
What is our primary use case?
We use Cisco ASA for traffic control.
What is most valuable?
It's a flexible solution.
What needs improvement?
The configuration is an area that needs improvement.
In the next release, I would like to see the UI include or provide web access, and more integration.
For how long have I used the solution?
I have been using Cisco ASA Firewall for five years.
We are not using the latest version, as it is not available.
What do I think about the stability of the solution?
It's a stable solution and we have not had any issues.
What do I think about the scalability of the solution?
It's a scalable product. We have approximately 2,000 users in our organization.
We have plans to continue to use it.
How are customer service and technical support?
Technical support provides us with good service.
How was the initial setup?
The initial setup was straightforward. It was easy for us because we have experience.
It was already deployed when I arrived.
We have two or three guys for deployment and maintenance.
What other advice do I have?
This is a product that I would recommend to others.
I would rate Cisco ASA Firewall a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Solutions Architect at a tech services company with 10,001+ employees
Allowed us to consolidating multiple security devices into a single appliance
Pros and Cons
- "It allowed us to consolidating multiple security devices into a single appliance."
- "We are looking for software taxi capabilities."
What is our primary use case?
- High-performance intrusion prevention
- Malware protection
- Multiple firewalls to control departments on a business by business level (security policies per department).
- Allowed us to consolidating multiple security devices into a single appliance.
How has it helped my organization?
- Intrusion protection
- We were able to determine when we are being attacked.
- We determine that our inspections were causing latency.
We needed a way to monitor threat protection and not cause latency.
What is most valuable?
It allowed us to consolidating multiple security devices into a single appliance. It consolidated and helped us eliminate firmware upgrade issues across multiple devices. The "Keep It Simple" method.
What needs improvement?
We are looking for software taxi capabilities.
For how long have I used the solution?
One to three years.
Which other solutions did I evaluate?
Going forward, we are evaluating Anomali. The founder of ArcSight founded Anomali. The product has the ability to be a consumer of threat intelligence, and be a contributor showing the maturity in threat protection posture.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Updated: November 2024
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
Sophos XG
Palo Alto Networks NG Firewalls
Azure Firewall
Check Point NGFW
WatchGuard Firebox
SonicWall TZ
Juniper SRX Series Firewall
Untangle NG Firewall
Fortinet FortiGate-VM
SonicWall NSa
Sophos XGS
Fortinet FortiOS
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Is The Biggest Difference Between Cisco ASA And Fortinet FortiGate?
- Cisco Firepower vs. FortiGate
- How do I convince a client that the most expensive firewall is not necessarily the best?
- What are the biggest differences between Cisco Firepower NGFW and Fortinet FortiGate?
- What Is The Biggest Difference Between Cisco Firepower and Palo Alto?
- Would you recommend replacing Cisco ASA Firewall with Fortinet FortiGate FG 100F due to cost reasons?
- What are the main differences between Palo Alto and Cisco firewalls ?
- A recent reviewer wrote "Cisco firewalls can be difficult at first but once learned it's fine." Is that your experience?
- Which is the best IPS - Cisco Firepower or Palo Alto?
- Which product do you recommend and why: Palo Alto Networks VM-Series vs Cisco Firepower Threat Defense Virtual (FTDv)?