Basic IPS functionality for intrusion prevention. We have two kinds of deployment. The one that is Inline and the one that is not Inline, where it's just listening. We have like a tap to which its monitoring traffic. For the one that is kind of offline deployment but for the Inline deployment, all traffic goes through it, like for North-South traffic, towards internet to provide some real-time intrusion prevention.
Manager IT Security at UnitedHealth Group
The anomaly baseline formation links the network, then anything that goes away from the norm is also flagged
Pros and Cons
- "Ir's signature-based. We are also using the anomaly baseline formation, where it links the network, then anything that goes away from the norm is also flagged. Those are the two most valuable features."
- "You can trust it because of the originality score and with what we've used so far too, I see the difference in the old version and this new one."
- "It has room for improvement when it comes to integrating machine learning and AI into it where even if you don't have a baseline that is of length for anomaly detection, it could do more like an AI style machine learning. It learns on its own."
What is our primary use case?
What is most valuable?
Ir's signature-based. We are also using the anomaly baseline formation, where it links the network, then anything that goes away from the norm is also flagged. Those are the two most valuable features.
What needs improvement?
It has room for improvement when it comes to integrating machine learning and AI into it where even if you don't have a baseline that is of length for anomaly detection, it could do more like an AI style machine learning. It learns on its own. It learns patterns, learns what good traffic looks like then is able to stop bad traffic, not just based on behavior but based on every other thing. I think other next-generation IPS solutions are turning towards integration of ML and AI. I need machine learning and the ability to share intelligence.
For how long have I used the solution?
I have been using Cisco NGIPS for seven years.
Buyer's Guide
Cisco Secure IPS (NGIPS)
July 2026
Learn what your peers think about Cisco Secure IPS (NGIPS). Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
906,781 professionals have used our research since 2012.
What do I think about the stability of the solution?
It is pretty stable and has good throughput.
What do I think about the scalability of the solution?
It's scalable. You can add more to it as traffic requires, one cluster can do HA, so it's pretty scalable. In fact, you can cluster up to six chassis on the 4100.
If it's host-based IPS, we can count a number of users and say we have 45,0000 users but for network-based IPS, where it's just picking traffic from different connections when you're trying to go to the internet or when you're trying to come back to the internet it can support up to 10 million concurrent sessions. We have around 200,000 users but it can support 10 million concurrent sessions.
For maintenance, once you configure it, depending on what you call maintenance if it's software upgrade it doesn't take a lot to upgrade it. If it's active/standby you can upgrade the active. The standby becomes the active. Then when the active comes back on, you can upgrade the standby. So usually, at least you have an active/standby scenario, but if you have a cluster, you can take each out of production in codes. We start while others are in production.
If you're talking about maintenance in terms of log collections and shipping of the logs, it's also easy to deploy from that perspective.
How are customer service and support?
Cisco has very good support. We get good support from Cisco.
Which solution did I use previously and why did I switch?
We've been using Cisco for a while. Going from the IPS module on ASA or the IPS appliance, we've transitioned from different Cisco IPS solutions to this Cisco Next Generation IPS.
It's been Cisco all along, it's just that this one has more visibility and it's next-generation style compared to the older IPS.
How was the initial setup?
The initial setup was straightforward and easy to deploy. It was very quick.
Which other solutions did I evaluate?
We also looked at Sourcefire.
They bought this particular one from Sourcefire and Sourcefire was the world leader in next-generation IPS before Cisco bought it and I know it wasn't just in terms of visibility and how much it can do but in terms of cost too because it was an open-source project that was going on before Cisco bought it. Cisco bought the enterprise version so I feel it's not expensive, but I've not really checked the licensing cost.
What other advice do I have?
Sourcefire wasn't originally Cisco and it was already a world leader and if I'm not mistaken or quoting wrongly, I think it's from the Snort project. I know the open-source community is still contributing to what Cisco is presenting with FirePower or FireSIGHT IPS. It's an open-source project. You can trust it because of the originality score and with what we've used so far too, I see the difference in the old version and this new one. You get better security compared to these other next-generation IPS out there.
In the next release, I would like to see AI machine learning capabilities built into it.
I would rate it a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Director, Security and Compliance at a tech services company with 1-10 employees
Offers protection to internal networks from malware
Pros and Cons
- "The product's initial setup phase was easy."
- "The product's high price is an area of concern where improvements are required."
What is our primary use case?
In my company, the solution is used as a platform for cybersecurity. The product offers protection from malware. In general, the solution offers protection to our company's internal network.
How has it helped my organization?
The product's benefits experienced by the company stem from the fact that the solution provides keep abilities that help users see what is happening in their network. The solution also provides alerts.
What needs improvement?
My company does not use the URL filtering capabilities offered by Cisco NGIPS. My company prefers to use the URL filtering feature offered by a brand other than Cisco since other tools provide an easier way to use the functionality.
I wanted to look into the other products offered in the market because Cisco NGIPS is expensive. The product's high price is an area of concern where improvements are required.
For how long have I used the solution?
I have been using Cisco NGIPS for eight years. My company has a partnership with Cisco. I am also a user of the product. My company operates as a reseller of Cisco products.
What do I think about the stability of the solution?
I don't remember seeing any crashes when using the solution. The product has been very stable in our company.
What do I think about the scalability of the solution?
The scalability offered by the product is fine. My company has not faced any problems with the scalability feature. The solution is deployed in three of our company's data centers.
How are customer service and support?
The first call that I had with the product's technical team was not good since it took time to provide an explanation to get the right engineer to help us with our problems. Once the user gets connected with the right engineer, the support offered is very good.
I rate the technical support a seven out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I have experience with Fortinet. I don't remember the name of one of the solutions that I had used in the past.
How was the initial setup?
The product's initial setup phase was easy.
I rate the product's initial setup phase a nine on a scale of one to ten, where one means a difficult process, and ten means that it is an easy process.
The solution is deployed on an on-premises model.
The solution can be deployed in a couple of weeks. We take care of the testing phase in our company before installing the solution only when the signatures are updated in our environment, which takes around a time frame of less than two weeks.
Around three or four engineers take care of the product's installation phase.
What about the implementation team?
My company purchases professional services from Cisco's partner to take care of the installation phase.
What's my experience with pricing, setup cost, and licensing?
Cisco NGIPS is an expensive product.
Which other solutions did I evaluate?
I have compared Fortinet FortiGate IPS against Cisco NGIPS.
What other advice do I have?
With Cisco NGIPS, the rate of false positives is very low.
I would tell those who plan to use Cisco NGIPS that it is a good solution, but if they have budget constraints, they should explore the other brands in the market.
I rate the tool an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Buyer's Guide
Cisco Secure IPS (NGIPS)
July 2026
Learn what your peers think about Cisco Secure IPS (NGIPS). Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
906,781 professionals have used our research since 2012.
Tecnical manager at Watronix Information Technology Ltd
An efficient cyber security solution with good integration features
Pros and Cons
- "The solution is very stable."
- "They could provide one solution to fit all the use cases."
What is our primary use case?
We use the solution as an intrusion prevention system to detect malicious attacks on the network.
What is most valuable?
The solution updates at regular intervals. It has the most recent definition of the attacks, including zero-day attacks.
What needs improvement?
They could provide one solution to fit all the use cases. Presently, we have purchased different solutions for total security. It has become expensive for us.
What do I think about the stability of the solution?
The solution is very stable. I rate its stability a nine out of ten.
What do I think about the scalability of the solution?
The solution is scalable. It integrates with different XDR solutions. Thus, we can manage all the devices on a single pane. It is suitable for SMEs and large enterprises as well.
I rate its scalability an eight out of ten.
How are customer service and support?
The solution's technical support is quite good. Although, it needs to be cohesive in terms of communication.
How would you rate customer service and support?
Positive
How was the initial setup?
The solution's initial setup process is complicated. But we can manage it with the right team for installation and technical support from Cisco.
What's my experience with pricing, setup cost, and licensing?
The solution is good value for money. It is highly-priced but competitive in terms of features and support services.
What other advice do I have?
It is an efficient cyber security solution. I highly recommend it to others and rate it a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer.
CIO at a legal firm with 11-50 employees
Easy to use and the technical support is great
Pros and Cons
- "The thing about this solution that I like the most is that it's intuitive."
- "My opinion is that this solution should improve the pricing."
What is most valuable?
The thing about this solution that I like the most is that it's intuitive. The other features I like are the good support chain and ease of use.
What needs improvement?
My opinion is that this solution should improve the pricing.
For how long have I used the solution?
I have been using this solution for about two years.
How are customer service and support?
I would rate the technical support of this solution a nine, on a scale from one to 10, with one being the worst and 10 being the best.
How would you rate customer service and support?
Positive
What's my experience with pricing, setup cost, and licensing?
I would rate the pricing of this solution a seven, on a scale from one to 10, with one being the worst and 10 being the best.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Specialist at Wattum
Beneficial protection but expensive
Pros and Cons
- "The most valuable feature of Cisco NGIPS is its protection."
- "The price of Cisco NGIPS could improve."
What is our primary use case?
We are using Cisco NGIPS for our company network. We are comparing how it works with the other companies.
What is most valuable?
The most valuable feature of Cisco NGIPS is its protection.
What needs improvement?
The price of Cisco NGIPS could improve.
For how long have I used the solution?
I have been using Cisco NGIPS for approximately four years.
What do I think about the stability of the solution?
Cisco NGIPS is stable.
What do I think about the scalability of the solution?
The scalability of Cisco NGIPS is good.
We have approximately 100 people using this solution in my company.
How are customer service and support?
I did not use the support.
Which solution did I use previously and why did I switch?
We previously used a Russian-based solution that was not popular.
How was the initial setup?
The initial setup of Cisco NGIPS was straightforward.
What about the implementation team?
We used a consultant for the implementation of the solution.
What was our ROI?
I have not seen a return on investment.
What's my experience with pricing, setup cost, and licensing?
The price of Cisco NGIPS could be reduced. It is more expensive than other solutions.
What other advice do I have?
The solution only requires one person for maintenance.
I would recommend this solution to others but it depends on their budget. It is expensive.
I rate Cisco NGIPS a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Manager at a consultancy with 11-50 employees
A good IPS solution with strong traffic filtering functionality, but is complicated to configure
Pros and Cons
- "The traffic filter of this solution is very valuable to us, and to our clients."
- "The traffic filter feature of this solution has improved our organization as it not only provides ransomware protection, but saves us time in dealing with unnecessary traffic."
- "We would like to see some improvement in the configuration process for this solution, as it is currently quite complex."
What is our primary use case?
We use this solution as an intrusion prevention system, as well as UI filtering, application control, and anti-malware protection.
How has it helped my organization?
The traffic filter feature of this solution has improved our organization. It not only provides ransomware protection, but saves us time in dealing with unnecessary traffic.
What is most valuable?
The traffic filter of this solution is very valuable to us, and to our clients.
What needs improvement?
We would like to see some improvement in the configuration process for this solution, as it is currently quite complex.
For how long have I used the solution?
We have been working with this solution for around a year.
What do I think about the stability of the solution?
We have found this to be a stable solution in our experience.
What do I think about the scalability of the solution?
This is a scalable product.
How was the initial setup?
The initial setup of this solution is straightforward if it is only the standard package being installed. However, configuring this product is complex and requires a lot of time commitment.
Deployment of the solution usually only takes a few hours, but if it is being implemented in a more complicated environment it can take up to three days.
What other advice do I have?
We would recommend this solution to other organizations as it is very easy to use.
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
Ceo & Creative Director at Redstout
Scalable expectations, clear and easy implementation, and meeting our current needs
Pros and Cons
- "Cisco NGIPS is working well overall with our current needs."
- "The stability of the user console and some features could be easier to access."
What is our primary use case?
We are using the WAF models to monitor the IDS and IPS also, and it is integrated with Cisco Umbrella.
What is most valuable?
Cisco NGIPS is working well overall with our current needs.
What needs improvement?
The stability of the user console and some features could be easier to access.
For how long have I used the solution?
I have been using Cisco NGIPS for the past one and half years.
What do I think about the stability of the solution?
The stability can be better. The Cisco console is unstable.
What do I think about the scalability of the solution?
The scalability is fine. I believe it covers the expectations that we have.
How are customer service and support?
Technical support is very good, but you must have the expertise and technical people with Cisco NGIPS.
How would you rate customer service and support?
Positive
How was the initial setup?
It is very straightforward, clear, and easy.
What's my experience with pricing, setup cost, and licensing?
I usually work with Fortinet and FortiGate which is a lower cost in comparison with Cisco NGIPS.
What other advice do I have?
I would rate Cisco NGIPS a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Network Security Engineer at a tech services company with 51-200 employees
Useful VPN, beneficial access policy management, and centrally managed
Pros and Cons
- "The most valuable features of Cisco NGIPS are the VPN, IPS, access policy management, EIM, and the ASA model as part of Firepower."
- "Cisco NGIPS is highly stable."
- "I would recommend this solution to others for medium, large, and enterprise businesses only."
- "The price of the solution is expensive to a degree it cannot be used by small businesses."
What is most valuable?
The most valuable features of Cisco NGIPS are the VPN, IPS, access policy management, EIM, and the ASA model as part of Firepower.
For how long have I used the solution?
I have been using Cisco NGIPS for approximately three years.
What do I think about the stability of the solution?
Cisco NGIPS is highly stable.
What do I think about the scalability of the solution?
Cisco NGIPS is scalable. The scalability is easy to do because if the Firepower threat defense works in the cluster mode, someone can scale up the system using two and three Firepower threat defenses at the same time in one system.
We use this solution in different companies and provide them with support. We have some clients that have 3,000 users whereas others have 700.
What about the implementation team?
In our company process some team, we have three or four people and the solution can be easily maintained because it is managed in one place in the Firepower management center. In one company we have approximately 24 Firepower models and these devices are controlled by one system, the Firepower management system (FMC). It's very easy to control and maintain the solution.
What's my experience with pricing, setup cost, and licensing?
The price of the solution is expensive to a degree it cannot be used by small businesses. It is best suited for medium and enterprise businesses.
What other advice do I have?
I would recommend this solution to others for medium, large, and enterprise businesses only.
I rate Cisco NGIPS a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Implementer
IT Administrator at a retailer with 51-200 employees
A stable solution with excellent IPS detection functionality
Pros and Cons
- "We have found the IPS detection to be a very valuable feature of this solution, and it is easy to use to stop policy violations."
- "We would like an option to search through the logs to be added to this solution."
What is our primary use case?
We use this product for IPS detection and reporting purposes.
What is most valuable?
We have found the IPS detection to be a very valuable feature of this solution. It is easy to use to stop policy violations.
What needs improvement?
We would like an option to search through the logs to be added to this solution.
For how long have I used the solution?
We have been working with this solution for three years.
What do I think about the stability of the solution?
The current version of this solution is proving to be very stable.
What do I think about the scalability of the solution?
We believe this to be a scalable solution.
How are customer service and support?
The technical support for this product is good. They respond to tickets quickly when they are raised, and they generally respond within 24 hours.
How was the initial setup?
The initial setup and configuration of this solution was straightforward.
What's my experience with pricing, setup cost, and licensing?
Licenses for this product are available for either one, or three year terms.
What other advice do I have?
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Network / ITOps Engineer at a leisure / travel company with 201-500 employees
Easy to set up with helpful technical support and good integration capabilities
Pros and Cons
- "You can do zero-day prevention and detection. It's quite useful."
- "Cisco technical support is great; they are helpful and responsive, and we are very happy with their capabilities."
- "I'd like to see some cloud management. Cisco maybe already has it, however, my company doesn't use it as cloud management."
- "I'd like to see some cloud management."
What is our primary use case?
The way we use it in my company is just for a basic firewall.
It's a next-generation firewall. You can integrate it with external systems, like Cisco Talos, Cisco Umbrella, all these things. You can do threat detection, threat prevention. You can integrate with your active directory. It can block traffic based on the user or user group.
What is most valuable?
I use the product mainly for follow-up. I would say the most important is the integration with our directory services, the user directory services. We can block or allow traffic based on the specific users or specific user groups.
There are other features such as the connection with the intelligence systems such as Talos on Cisco. You can do zero-day prevention and detection. It's quite useful.
The solution is stable and the performance is good.
My understanding is that the initial setup is simple.
What needs improvement?
I'd like to see some cloud management. Cisco maybe already has it, however, my company doesn't use it as cloud management. That said, it would be great to manage your device through the cloud instead of managing through a server on-premise.
For how long have I used the solution?
I've only used the solution for two months. It hasn't been that long just yet.
What do I think about the stability of the solution?
The product has been stable. Cisco is quite stable as a product. It doesn't crash or freeze. It's reliable. There are no bugs or glitches.
What do I think about the scalability of the solution?
I can't really speak to the scalability of the solution as I haven't used it for long enough.
Due to the fact that all the traffic passes through the firewalls, I would say 500 people or maybe more use the solution in our organization.
How are customer service and support?
Cisco technical support is great. They are helpful and responsive. We are very happy with their capabilities.
Which solution did I use previously and why did I switch?
I'm also aware of Palo Alto, which in many ways is a more solid product. We used it in my previous company as it was more mature and much simpler to use in comparison to Cisco.
How was the initial setup?
While I didn't set it up, my understanding is the implementation is straightforward. You read the documentation. It's this continuation from the old Cisco ASAs. People have used it for many years. Cisco's quite easy to set it up and keep up and running. You just need to add things on top of it, however, it's all quite easy. I have done an installation of the previous Cisco firewall. It's really straightforward. The upgrade is quite simple as well.
We have three technical personnel that can handle deployment and maintenance. We have to cover the whole globe, so we have three people on to handle everything 24/7.
What's my experience with pricing, setup cost, and licensing?
You do need to pay a licensing fee. If you want the additional features, like prevention or integration with extended intelligence systems, you need to pay additional licenses.
What other advice do I have?
I'm not sure which version of the solution we're using. It might be 6.4. It's likely whatever that latest version is.
I would recommend Cisco, however, I do find Palo Alto to be a good product as well, and in some ways more solid.
I'd rate the solution at a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Cisco Secure IPS (NGIPS) Report and get advice and tips from experienced pros
sharing their opinions.
Updated: July 2026
Product Categories
Intrusion Detection and Prevention Software (IDPS)Popular Comparisons
Fortinet FortiGate
WatchGuard Firebox
KerioControl
Splunk User Behavior Analytics
TrendAI Tipping Point
Palo Alto Networks Advanced Threat Prevention
ExtraHop Reveal(x) 360
Cisco IOS Security
Check Point IPS
Hillstone I-Series Server Breach Detection System
Cisco Sourcefire SNORT
Trellix Intrusion Prevention System
Buyer's Guide
Download our free Cisco Secure IPS (NGIPS) Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- When evaluating Intrusion Detection, what aspect do you think is the most important to look for?
- What is your recommended cost-effective solution to detect and prevent APT attacks?
- What product do you recommend for a Campus IPS appliance implementation?
- How do you use the MITRE ATT&CK framework for improving enterprise security?
- What are the pros and cons of Darktrace vs CrowdStrike Falcon vs alternative EPP solutions?
- Which alternative solutions (other than Darktrace) do you recommend for an SMB?
- Which is the best intrusion detection and prevention solution?
- What is the best IDPS security tool and why?
- What is Cognitive Cybersecurity and what is it used for?

















