Try our new research platform with insights from 80,000+ expert users

Cisco Secure Firewall vs Forcepoint Next Generation Firewall comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 16, 2024
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
2nd
Average Rating
8.4
Number of Reviews
316
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st)
Cisco Secure Firewall
Ranking in Firewalls
5th
Average Rating
8.2
Number of Reviews
406
Ranking in other categories
Cisco Security Portfolio (3rd)
Forcepoint Next Generation ...
Ranking in Firewalls
24th
Average Rating
7.6
Number of Reviews
42
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (10th), WAN Edge (12th)
 

Mindshare comparison

As of November 2024, in the Firewalls category, the mindshare of Fortinet FortiGate is 19.8%, up from 17.1% compared to the previous year. The mindshare of Cisco Secure Firewall is 5.7%, down from 6.0% compared to the previous year. The mindshare of Forcepoint Next Generation Firewall is 0.4%, down from 0.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls
 

Featured Reviews

DineshKumar28 - PeerSpot reviewer
Sep 25, 2024
Effective threat prevention with responsive customer support
We are using Fortinet FortiGate as a firewall Fortinet FortiGate has been invaluable. It has helped save costs due to its various features, reliable performance, very good UI, low latency, and stability. The Threat Intel engine in Fortinet FortiGate is highly rated for its effectiveness in…
Daniel Going - PeerSpot reviewer
Jun 26, 2022
Is intuitive in terms of troubleshooting, easy to consume, and stable
We use it for data center security for both the north-south and east-west. With Firepower, you get the next-generation functionality and the next-generation firewall features. Traditionally, when you have a layer three access list, it's really tricky to get the flexibility you need to allow staff…
OusaidAbaz - PeerSpot reviewer
Mar 19, 2024
Provides decent protection for the LAN but complicated interface
We had some licensing issues with its web filtering capabilities. That's why we migrated our web filtering to Cisco Umbrella. Moreover, the interface is complicated. It's difficult to locate all the necessary menus and functions. For example, one of the many issues is with SSH. Even now, we haven't successfully opened the port to connect using SSH mode when we want to change the configuration. It's like a black box—not very open to changes and customization. It's simply not easy to configure. There are other problems, too. For example regarding Forcepoint's Websense component. We had a lot of problems managing the web settings within Websense. That's why we migrated to Cisco Umbrella for cloud-based web filtering. It's not that Forcepoint is inherently bad. The issue is that it's not user-friendly. It is not easy to use. The developers need to redesign the interface (GUI) for better management. It is very difficult to manage. For example, simple actions require too many clicks compared to FortiGate or Palo Alto. That's the main problem.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"FortiGate has a very strong unified threat management system."
"The pricing is excellent. It's much less expensive than Cisco."
"Whenever I need something, Fortinet improves and updates the software for me."
"One of the nice things about FortiGate is that it can be deployed on the cloud or on-premises. You can actually do both. That's the biggest reason why I stick with this solution as opposed to something like Cisco Meraki. Another nice thing is that I can log directly into a FortiGate or get to it through their FortiCloud access products. They're pretty reliable and consistent. One of the reasons why I started using the product was their single pane of management. I can deploy their line of firewalls in conjunction with their switching and access points, and I can manage the entire network from one interface. I don't have to log into one interface for the firewall, another one for the access points, and another one for the switches. These firewalls have access point controller functionality built right into the system, so I don't even have to purchase additional devices to manage them."
"I appreciate FortiGate's flexibility, which allows for centralized management through FortiManager."
"It's an easy solution to set up."
"It is simple to manage, and there are a lot of functionalities in the same box."
"The most valuable features of Fortinet FortiGate are the ease of use and there are several operating systems that can include the hardware capacities. In the newer releases, the resources were more useful because they were included in the operating system."
"Another benefit has been user integration. We try to integrate our policies so that we can create policies based on active users. We can create policies based on who is accessing a resource instead of just IP addresses and ports."
"The grouping of the solutions helps save time. If you have a problem and you have a high-level overview of the system, you can easily dig deeper into the problem. For example, I can check to see why ASA isn't working but the reason for the outage is actually because of Duo. I can spend a lot of time working in the wrong direction because I didn't have an overview."
"The VPN is our most widely used feature for Cisco Secure Firewall. Since we were forced into a hybrid working situation by COVID a few years back, VPN is the widely used feature because everybody is working remotely for our agency. So it came in very handy."
"The most important feature is the intensive way you can troubleshoot Cisco Firepower Firewalls. You can go to the bit level to see why traffic is not handled in the correct way, and the majority of the time it's a networking issue and not a firewall issue. You can solve any problem without Cisco TAC help, because you can go very deeply under the hood to find out how traffic is flowing and whether it is not flowing as expected. That is something I have never seen with other brands."
"The firewall and policy side are easy to use."
"We are mostly using it for remote access, so the remote access feature is the most valuable, but all other features are also needed and required. It is also a very straightforward and reliable solution."
"The most valuable feature is the access control list (ACL)."
"One of the nice things about Firepower is that you can set it to discover the environment. If that is happening, then Firepower is learning about every device, software operating system, and application running inside or across your environment. Then, you can leverage the discovery intelligence to get Firepower to select the most appropriate intrusion prevention rules to use for your environment rather than picking one of the base policies that might have 50,000 IPS rules in it, which can put a lot of overhead on your firewall. If you choose the recommendations, as long as you update them regularly, you might be able to get your rule set down to only 1,000 or 1,500, which is a significant reduction in a base rule set. This means that the firewall will give you better performance because there are less rules being checked unnecessarily. That is really useful."
"The simplicity of the solution is its most valuable asset. It's very user-friendly."
"It is a scalable solution."
"It is a stable solution, and there are no issues so far."
"It provides decent protection for the LAN, especially in run mode."
"I don't have anything bad to say about the product. I absolutely love it."
"The Forcepoint Next Generation Firewall is a scalable product."
"The feature that we like the most about Forcepoint is that we know the technology and have confidence in it. We can have several functionalities to simplify operations and management. We can combine functionalities like log ownership to review the number of devices in the infrastructure."
"I have two offices, and I can route the internet of both offices using the same product. The connectivity is great."
 

Cons

"Fortinet FortiGate is a firewall solution and once it's deployed, you can rest assured that your system is secure."
"Fortinet needs to overhaul its documentation."
"Fortinet already improved FortiGate, but in the current market, many brands of security devices have improved together. Fortinet still needs to catch up with market standards. Fortinet is lacking in features in comparison to competitors."
"The search tool needs improvement. It's very difficult to search for policies right now."
"It could use better throughput on some of the smaller boxes for the branch offices."
"The logs need to be better. They need to be more visible and easier to access."
"The graphical user interface of Fortinet's FortiGate product does not function well with text-based interfaces."
"Security is a continuous process. In every product, there is a requirement for improvement. Its pricing should also be improved according to Indian market requirements. They must also improve on the reporting part. Its reporting can be more precise. If we can get a real-time report in a specific format, it will be helpful for customers to know about the current status of their security."
"The solution needs to have better logging features."
"it is not very user-friendly for the administration."
"The service could use a little more web filtering. If I compare it to Cyberoam, Cyberoam has more the web filtering, so if you want to block a website, it's easier in other solutions than in Cisco."
"Maybe the dashboard could be a bit better."
"Cisco should improve its user interface design. There is a deep learning curve to the product if you are a newcomer."
"It will be nice if they had what you traditionally would use a web application scanner for. If the solution could take a deeper look into HTTP and HTTPS traffic, that would be nice."
"We only have an issue with time sync with Cisco ASA and NTP. If the time is out of sync, it will be a disaster for the failover."
"The stability is not the best."
"My team is looking for more throughput and better integration with our security framework."
"The solution's support could use improvement."
"They should have a local vendor who can provide support. Most of the support is overseas, so the time zones can be a problem."
"The optimization is not really ready. If you want very good optimization, you have to add it to the network."
"Next Generation Firewall's configuration could be improved."
"You do need knowledge of the solution in order to set the product up properly."
"They should provide more details on potential cyber threats."
"The endpoint protection capabilities of the product are an area of concern where improvements are required."
 

Pricing and Cost Advice

"We just pay a flat monthly fee to the vendor for the support."
"We purchased a five-year bundle package, which worked out cheaper than competing solutions."
"In terms of the market, it's not a cheap product, but it's cost-effective."
"The beauty is the price performance ratio is great with FortiGate. It provides all the features we needed and the price is comparable with others' firewalls. The price is quite competitive with the firewalls with similar features."
"The price, in comparison to other products is very cheap."
"These boxes are not that expensive compared to what they can do, their functionality, and the reporting you receive. Fortinet licensing is straightforward and less confusing compared to Cisco."
"The price range is quite acceptable and normal."
"Fortigate's pricing is competitive."
"It is expensive. There is a cost for everything. There is per year license cost and support cost. There is also a cost for any training, any application, and any resource. Things are very costly to do with Cisco. Other brands are cheaper. They are also more flexible in terms of training, subscription, and licensing. They give lots and lots of years free. They provide more than Cisco."
"With the Cisco ASA, you do get what you pay for. What would really be awesome is to see Cisco blow out a real cheap version where you can use the sandbox, but leave it step-wise and go to another product relatively easily, like getting you hooked on candy."
"It's more expensive than Fortinet and Juniper. The price is high compared to other vendors. In general, for the license, it's not that expensive."
"Cisco's pricing is high, at times, for what they provide."
"The licensing features are getting more complicated. These should be simplified."
"Cisco, as we all know, is expensive, but for the money you are paying, you know that you are also getting top-notch documentation as well as support if needed."
"The licensing package is good, but the licensing fee should be decreased."
"I have to admit that the price is high. But I think it's worth it if the stability of your solution counts for you."
"It could be cheaper like Fortinet."
"It is an affordable product. We purchase its yearly license."
"The pricing should be more competitive against other vendors in the market."
"The training that they offer to their end-customers. It's quite expensive, I believe it costs roughly $11,000"
"The solution is expensive."
"We have just a subscription for the cloud, and this license is great. The license is so good."
"It requires a yearly subscription."
"We would love to take other solution from Forcepoint, but unfortunately the price is too high. That's why we are not considering using Forcepoing for our proxy and DLB. They have a very good DLB, but the matter in the end is the cost."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
815,854 professionals have used our research since 2012.
 

Comparison Review

it_user206346 - PeerSpot reviewer
Mar 11, 2015
Cisco ASA vs. Palo Alto Networks
Cisco ASA vs. Palo Alto: Management Goodies You often have comparisons of both firewalls concerning security components. Of course, a firewall must block attacks, scan for viruses, build VPNs, etc. However, in this post I am discussing the advantages and disadvantages from both vendors concerning…
 

Top Industries

By visitors reading reviews
Educational Organization
22%
Computer Software Company
15%
Manufacturing Company
6%
Comms Service Provider
6%
Educational Organization
32%
Computer Software Company
15%
Government
5%
Manufacturing Company
5%
Computer Software Company
18%
Financial Services Firm
9%
Manufacturing Company
9%
Government
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
Which is better - Fortinet FortiGate or Cisco ASA Firewall?
One of our favorite things about Fortinet Fortigate is that you can deploy on the cloud or on premises. Fortinet Fort...
How does Cisco's ASA firewall compare with the Firepower NGFW?
It is easy to integrate Cisco ASA with other Cisco products and also other NAC solutions. When you understand the Cis...
Which is better - Meraki MX or Cisco ASA Firewall?
Cisco Adaptive Security Appliance (ASA) software is the operating software for the Cisco ASA suite. It supports netw...
What is your experience regarding pricing and costs for Forcepoint Next Generation Firewall?
There is a need to make payments towards the licensing charges attached to the product. The product is not expensive.
What needs improvement with Forcepoint Next Generation Firewall?
My experience with this Forcepoint Next Generation Firewall wasn't very pleasant due to its complexity. For example, ...
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate
Cisco ASA Firewall, Cisco Adaptive Security Appliance (ASA) Firewall, Cisco ASA NGFW, Cisco ASA, Adaptive Security Appliance, ASA, Cisco Sourcefire Firewalls, Cisco ASAv, Cisco Firepower NGFW Firewall
Forcepoint NGFW, Stonesoft Next Generation Firewall, McAfee Network Security Platform, Intel Security Network Security Platform
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
There are more than one million Adaptive Security Appliances deployed globally. Top customers include First American Financial Corp., Genzyme, Frankfurt Airport, Hansgrohe SE, Rio Olympics, The French Laundry, Rackspace, and City of Tomorrow.
California Department of Corrections and Rehabilitation (CDCR)
Find out what your peers are saying about Cisco Secure Firewall vs. Forcepoint Next Generation Firewall and other solutions. Updated: October 2024.
815,854 professionals have used our research since 2012.