Try our new research platform with insights from 80,000+ expert users
IT Administrator at a retailer with 51-200 employees
Real User
A stable solution with excellent IPS detection functionality
Pros and Cons
  • "We have found the IPS detection to be a very valuable feature of this solution. It is easy to use to stop policy violations."
  • "We would like an option to search through the logs to be added to this solution."

What is our primary use case?

We use this product for IPS detection and reporting purposes.

What is most valuable?

We have found the IPS detection to be a very valuable feature of this solution. It is easy to use to stop policy violations.

What needs improvement?

We would like an option to search through the logs to be added to this solution.

For how long have I used the solution?

We have been working with this solution for three years.

Buyer's Guide
Cisco Secure IPS (NGIPS)
September 2024
Learn what your peers think about Cisco Secure IPS (NGIPS). Get advice and tips from experienced pros sharing their opinions. Updated: September 2024.
802,829 professionals have used our research since 2012.

What do I think about the stability of the solution?

The current version of this solution is proving to be very stable.

What do I think about the scalability of the solution?

We believe this to be a scalable solution.

How are customer service and support?

The technical support for this product is good. They respond to tickets quickly when they are raised, and they generally respond within 24 hours.

How was the initial setup?

The initial setup and configuration of this solution was straightforward.

What's my experience with pricing, setup cost, and licensing?

Licenses for this product are available for either one, or three year terms.

What other advice do I have?

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Network engineer at a manufacturing company with 201-500 employees
Real User
IPS ability enables you to balance security and connectivity
Pros and Cons
  • "The most valuable feature is its IPS ability. You are able to balance security and connectivity."
  • "The CLI, the console line interface, of the FTD could be improved. It's very complex, so without a GUI, it doesn't work well. I would like it to be more simple."

What is our primary use case?

Our primary use case is securing the network. It has a deep learning intelligence ability to filter packages and traffic coming to networks and to different workstations in networks. 

This solution is deployed on-premises. 

What is most valuable?

The most valuable feature is its IPS ability. You are able to balance security and connectivity. 

What needs improvement?

The CLI, the console line interface, of the FTD could be improved. It's very complex, so without a GUI, it doesn't work well. I would like it to be more simple. 

As far as additional features or next releases, I think the price could be cheaper. 

For how long have I used the solution?

We have been using this solution for more than eight years. 

What do I think about the stability of the solution?

This product is stable. 

What do I think about the scalability of the solution?

This product is very scalable. 

How are customer service and support?

Cisco's technical support is very, very fast. 

Which solution did I use previously and why did I switch?

Before implementing Cisco, we used Fortigate and Check Point. 

How was the initial setup?

The installation is straightforward. You have to install the device, but if you want to actually manage it, you need a GUI for it. For deployment, you will need two engineers, maximum. 

What about the implementation team?

We implemented this solution through an in-house team and deployed it ourselves. 

What's my experience with pricing, setup cost, and licensing?

We pay for the IPS license to use this solution. 

What other advice do I have?

I rate this product a nine out of ten, and would recommend this product to others who are considering using it. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Cisco Secure IPS (NGIPS)
September 2024
Learn what your peers think about Cisco Secure IPS (NGIPS). Get advice and tips from experienced pros sharing their opinions. Updated: September 2024.
802,829 professionals have used our research since 2012.
Network Support Engineer at Nigeria LNG Limited
Real User
Top 20
Stable, scalable, and has good support
Pros and Cons
  • "We are satisfied with the technical support."
  • "It is no longer scalable because it has gone end of life."

What is our primary use case?

We use this solution for traffic inspection and searching.

What needs improvement?

It's coming to its end of life. We will be considering another solution because it is no longer scalable.

While it is stable, I would like it to be even more stable.

For how long have I used the solution?

I have been using this solution for 10 years.

What do I think about the stability of the solution?

Cisco NGIPS is a stable solution. We have not had any issues since we have been using it.

What do I think about the scalability of the solution?

It is no longer scalable because it has gone end of life.

We have approximately six locations. We have close to 2,000 users.

How are customer service and technical support?

We are satisfied with the technical support.

How was the initial setup?

I was not involved in the installation.

We have a team of four of five, including four engineers, and one supervisor to maintain this solution.

What's my experience with pricing, setup cost, and licensing?

It could be less expensive.

We do pay for licensing yearly, but since it is at its end of life, there are no license implications until we purchase a new solution.

What other advice do I have?

I would recommend this solution to others.

I would rate Cisco NGIPS an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Infrastructure and Security Officer at a tech services company with 201-500 employees
Real User
Top 10
The console has everything you need in one place
Pros and Cons
  • "I like how NGIPS has everything in one console."
  • "The look and feel of the console could be updated."

What is our primary use case?

We use NGIPS for monitoring and firewall purposes. We have about 3,000 users. 

What is most valuable?

I like how NGIPS has everything in one console.  

What needs improvement?

The look and feel of the console could be updated. 

For how long have I used the solution?

I have used NGIPS for about five years.

What do I think about the stability of the solution?

NGIPS is stable.

How was the initial setup?

Setting up NGIPS was complex. We needed help from a Cisco specialist. 

What other advice do I have?

I rate Cisco NGIPS eight out of 10 overall.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Networking Security Consultant at a comms service provider with 51-200 employees
Real User
Good support, stable, and has a lot of advanced security features
Pros and Cons
  • "The integration with the Cisco portfolio is very helpful."
  • "Multi-internet line load balancing should be supported."

What is our primary use case?

I work for a system integrator and Cisco NGIPS is one of the products that we implement for our clients. This is a solution for enterprise networks and it has a lot of advanced features including security intelligence feeds and DNS security.

What is most valuable?

This product can be integrated with other solutions from the Cisco portfolio including Cisco ISE and SecureX. The integration with the Cisco portfolio is very helpful. Cisco ISE will give full control in any network and it can be used to isolate any infected or misbehaving users automatically.

What needs improvement?

Multi-internet line load balancing should be supported. It is available from other vendors and should be included with this product.

What do I think about the stability of the solution?

This is one of the most stable solutions in the firewall world. 

What do I think about the scalability of the solution?

Cisco takes scalability into consideration. My clients vary in size from small and medium-sized businesses to enterprises.

How are customer service and technical support?

The best support that I have ever dealt with is from Cisco. I am very satisfied with their service.

Which solution did I use previously and why did I switch?

I have experience with a lot of network security products. These include solutions by Cisco, Palo Alto, Fortinet, and Forcepoint.

How was the initial setup?

The initial setup is very simple and in one or two hours, it can be up and running.

What's my experience with pricing, setup cost, and licensing?

The licensing can be billed annually or in multi-year contracts such as three, four, or five years.

What other advice do I have?

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner, integrator
PeerSpot user
System Engineer at a tech services company with 11-50 employees
Real User
A solution with a lot of complexity but with excellent customer service
Pros and Cons
  • "Technical support is quite good. With firewalls, the last cases I had with Cisco were professionally handled quite quickly and it was great."
  • "Overall, it lacks user-friendliness. It could be easier to manage. I can train any customer using FortiGate or Palo Alto in a few days, but with Cisco, it takes much more time because the systems aren't easy to use."

What is our primary use case?

We use the solution to secure our client's networks.

What needs improvement?

Overall, it lacks user-friendliness. It could be easier to manage. I can train any customer using FortiGate or Palo Alto in a few days, but with Cisco, it takes much more time because the systems aren't easy to use.

It would be very nice to get rid of FlexConfig. It's a very unhelpful element of the solution.

One feature that is lacking is full interoperability with CLI.

You can configure Palo Alto and FortiGate with a graphical interface, and you can configure it with the command line. This is not so in Cisco. For professionals, this is important because the command line allows us to configure a lot of things and copy configurations and it's much easier.

For how long have I used the solution?

I've been using the solution for 10 to 15 years.

How are customer service and technical support?

Technical support is quite good. With firewalls, the last cases I had with Cisco were professionally handled quite quickly and it was great. I can compare with some other manufacturers. FortiGate is awful, for example. I'm generally pleased with Cisco.

How was the initial setup?

The solution has a moderate amount of difficulty. You need to go over and use the documentation.

Cisco has a device manager now but this device manager is not like all device managers from ASA. It lacks a lot of features, and some of these features are very important. It makes it a challenge to configure because of the graphical interface. You have to install the management center and that itself takes time and it's not so simple.

What other advice do I have?

We use the on-premises deployment model.

Ten years ago, when you sold Cisco to clients, customers complained about the price but they knew they were buying the best product in the market. It is totally different now. If they want to buy the best product in the market, they buy Palo Alto or Check Point. Cisco is trying to catch up to the competition.

When we talk about just the IPS manufacturers, I would rate the solution around six or seven out of ten. If we're talking about Cisco as a whole, I would rate them eight out of ten.  

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
PeerSpot user
Senior Consultant at Wevioo
Consultant
Offers valuable web filtering and JPS features and their technical support responds quickly
Pros and Cons
  • "The solution is stable. This is one of the good things in Firepower. Especially if we use ESE with it."
  • "There are some features not found in Firepower, like data loss prevention, and SSO, to have a connection between Cisco and Active Directory which was introduced on other products."

What is most valuable?

I've found the web filter and JPS the most valuable features.

What needs improvement?

There are some features not found in Firepower, like data loss prevention, and SSO, to have a connection between Cisco and Active Directory, which was introduced on other products.

In the future, I'd like the same solution in other UTM solutions. I know it has an application filter, but it's not really improving. Also, DLP needs to prevent data loss. Those two features are really important now for firewalls and for the security. The data loss prevention really is the most asked for feature from the customer. Often they ask about how we can prevent loss of emails, of data, files. It's really important.

For how long have I used the solution?

I've been using the solution since 2014.

What do I think about the stability of the solution?

The solution is stable. This is one of the good things about Firepower. Especially if we use ESE with it. That would make it the complete solution for Cisco for security. If it is the complete solution, it's stable and there are no issues with the product. If the user isn't connected all the time, for example, if we look at some sites or some users, sometimes the connection for the user gets disconnected with each session. Sometimes the filter doesn't work. 

What do I think about the scalability of the solution?

The solution is good to scale.

How are customer service and technical support?

The technical support is really good. Not only for this solution. The support of Cisco is always good. From the first call, the response is quick and there is no problem with the support.

How was the initial setup?

The initial setup is not complex. There is a wizard so it's not complex. There is a difference in the complexity of the deployment. Depending on customers and infrastructure, sometimes it takes one day or two days if we're talking about a little infrastructure. Sometimes it can take eight days or more to couple the firewall with ASA, and to do some more complex architecture. If we have a complex architecture, we need 2 people to implement, but if we have an implementation that is not so complex, one person can do it.

What about the implementation team?

I do the implementation myself.

What was our ROI?

Most of the time the ROI good. The customer, most of the time, is happy and is convinced of the usefulness of the solution.

What other advice do I have?

If someone wants to use Cisco Firepower, the solution is easy. The complete solution is the best for having the full security of a Cisco infrastructure. If I could advise someone with the deployment, I would advise taking the complete solution, in order to have a really scalable and stable solution. Or, if you can't take the complete solution, I'd advise taking a cluster of Firepower to have the scalability and stability.

I would rate this solution a 7 or 8 out of 10. If they could add a few of the mentioned features or do something more with the application filter it would be a 9 or a 10 out of 10.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
PeerSpot user
IT Engineer at a tech services company with 11-50 employees
Real User
A scalable solution with good support and a straightforward setup
Pros and Cons
  • "The initial setup wasn't complex or complicated."
  • "More flexibility with the dashboards is needed because some of them are not fully developed."

What is our primary use case?

We use this solution for integration, installing, and supporting.

How has it helped my organization?

Cisco NGIPS dropped network Troyans and web application attac almost every day. That helps up to feel more secure.

What is most valuable?

I find the IPS feature the most valuable.

What needs improvement?

The main problem with Firepower is the time between deployment and configuration. Now, it's approximately six minutes, so If I configure something during deployment, I understand that maybe if I write up a small mistake, I need to wait twelve minutes before I can fix the configuration. So I think the main problem is the time of deployment.

The solution could add DLT, but it's already full enough of features.

The interface could be simpler and more user-friendly. More flexibility with the dashboards is needed because some of them are not fully developed. We could use more flexible base boards.

For how long have I used the solution?

I've been using this solution for one year.

What do I think about the stability of the solution?

For the years we've been using Firepower we have only one or two cases of instability. There were only one or two unpredictable things.

One case was fasten with Active/standby switchover. After switchover some networks has been lost. After rebooting the standby FP next switchover was without problem.

Another case was associated with setting up of NAT. It was a FirePower nuance. Only the second TAC engineer helped us with it.

What do I think about the scalability of the solution?

I find the solution really scalable.

How are customer service and technical support?

I'd give technical support a five out of five. When things need to get solved, they get solved.

Which solution did I use previously and why did I switch?

We used to have ASA 5520. But in time we needed more security features to secure our services and users.

How was the initial setup?

The initial setup wasn't complex or complicated. Everything was clear. The initial configuration took a day, but the company that we support has a very complicated topology. During the deployment, they had a different idea about how the configuration should be. Because the customer didn't know what they wanted, the files and the deployment took approximately three or four months. 

For deployment, it depends on the company. It depends on the company's complicated topology. If it's too complicated, then maybe you need two engineers to support Firepower. For employees, you need only one, with a second as a standby in case something goes wrong with the primary engineer, so I'd say you need two engineers to maintain the solution.

What about the implementation team?

I handled the implementation myself.

Which other solutions did I evaluate?

The company is Cisco oriented and Cisco is a leader in security Gartner Quadrant for Enterprise Network Firewalls.

What other advice do I have?

My advice for anybody implementing this solution is to follow the instructions carefully.

I would rate this solution an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
PeerSpot user
Buyer's Guide
Download our free Cisco Secure IPS (NGIPS) Report and get advice and tips from experienced pros sharing their opinions.
Updated: September 2024
Buyer's Guide
Download our free Cisco Secure IPS (NGIPS) Report and get advice and tips from experienced pros sharing their opinions.