Cisco Sourcefire SNORT vs Fortra's Tripwire Enterprise comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Cisco Sourcefire SNORT
Ranking in Intrusion Detection and Prevention Software (IDPS)
11th
Average Rating
7.6
Number of Reviews
18
Ranking in other categories
No ranking in other categories
Fortra's Tripwire Enterprise
Ranking in Intrusion Detection and Prevention Software (IDPS)
19th
Average Rating
8.0
Number of Reviews
8
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2024, in the Intrusion Detection and Prevention Software (IDPS) category, the mindshare of Cisco Sourcefire SNORT is 3.0%, down from 3.6% compared to the previous year. The mindshare of Fortra's Tripwire Enterprise is 0.6%, down from 1.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Intrusion Detection and Prevention Software (IDPS)
Unique Categories:
No other categories found
No other categories found
 

Featured Reviews

Carlos Reis - PeerSpot reviewer
Feb 27, 2024
Offer a convenient and effective way to implement strong security measures
It provides a centralized platform using Cisco. SNORT is integral to the database. The primary function is expanding the database. As nodes transition, adjustments are made to SNORT, further enhancing its capabilities. It plays a crucial role in managing various protocols. Cisco Sourcefire SNORT is expected to offer improved management capabilities within the ACP. However, navigating the ACP settings can be challenging, particularly when dealing with default configurations. Additionally, upgrading devices may receive unfamiliar database updates from the FMC, such as ETB. This can lead to confusion and necessitate careful handling to ensure proper integration and functionality. Changes in Cisco Sourcefire SNORT, particularly in application settings, can have significant impacts. For instance, transitioning from one application setting to another, such as from a large-scale deployment to a maximum setting, can disrupt operations. This disruption is particularly challenging because it affects various rules and configurations for different applications. It's essential for Cisco to streamline the process of managing these changes, possibly by providing more user-friendly interfaces or tools, as relying solely on technical support can be cumbersome. Specifically, when discussing SmartOps, the complexity of managing configurations and settings becomes apparent, highlighting the need for simpler, more intuitive solutions. When working with Cisco Sourcefire SNORT, creating your profile files and meticulously tracking your activities is essential. When starting out with SNORT and adjusting migration rules, it's crucial to exercise caution and understand the potential impact on the business. Sometimes, you need to put your network into 'inline mode' to observe the traffic and understand what's happening on your network. Enabling this mode allows you to see what's passing through your network. There are some tools we use to analyze specialized traffic. We recently encountered a situation in which Cisco SQL traffic was blocked because of SNORT. It provides good analysis and outputs. You can see everything if you're attached to intrusion testing in the FMC; its database is good. The strength of SNORT, coupled with its integration with the firewall, works well. The database from SNORT contains a lot of data, and it's not just a single tool requirement. Dealing with all this data can be challenging. Firepower had some options like that that couldn't be blocked. Then, you can start to see improvement. We encountered an issue where certain features were blocked after migrating from SNORT version two to three. Despite our efforts to ensure progress, some problems arose, particularly related to the network analysis policy. This occurred even before transitioning to Sourcefire; within the engine, some traffic passing through SNORT faced issues. When migrating to version three, Cisco had to release a patch to address this problem and give you an idea. Overall, I rate this solution an eight out of ten.
RS
Apr 3, 2023
Good baseline features and mapping but the GUI is dated
I primarily use the solution for many use cases.  We've delivered many clients' compliance solutions. It's helped with suggesting compliance, including HIPAA, ISO, et cetera. It suggested what we need to do at the device level, whether endpoint or network. It also helps manage and monitor changes,…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It has a huge rate of protection. It's has a low level of positives and a huge rate of threat protection. It's easy to deploy and easy to implement. It has an incredible price rate compared to similar solutions."
"The most valuable feature is the visibility that we have across the virtual environment."
"I like most of Cisco's features, like malware detection and URL filtering."
"The product is inexpensive compared to leading brands such as Palo Alto or Fortinet."
"The URL filtering is very good and you can create a group for customized URLs."
"The most valuable feature of this solution is the filtering."
"The most valuable feature is the ability to automatically learn the traffic in our environment, and change the merit recommendations based on that."
"The whole solution is very good, and stable."
"The most valuable feature is integrity management. I had some discussions with service providers, and they also agreed."
"We use Tripwire Enterprise as a tool to test the vulnerability of a network. That is the most valuable feature of the product for us."
"File monitoring is the most valuable feature of the solution."
"Even if you change a single word in Notepad, it will let you know whether it was added, removed, or modified."
"What's most valuable in Tripwire Enterprise is the ability to execute custom COCR rules that lets me fine-tune how I monitor Linux and Windows agents."
"Its reporting features are great. It gives you an in-depth report. Its customization is also great, and it is working fine."
"The product supports different platforms."
"The most valuable feature is the integrity."
 

Cons

"With the next release, I would like to see some PBR, so that you can do the configuration with the features."
"The solution's approach to managing traffic blocking is confusing and impractical."
"The customization of the rules can be simplified."
"Integration with other components — even Cisco's own products — can be enhanced to improve administrative experience."
"We are unhappy with technical support for this solution, and it is not as professional as what we typically expect from Cisco."
"Performance needs improvement."
"I would like to have analytics included in the suite."
"There are problems setting up VPNs for some regions."
"The Windows online integration license needs to be improved."
"The initial setup is complex."
"A lot of network devices need a custom integration."
"It needs more local support from the OEM side. It would be great if this can be improved."
"The main way that it can be improved is through better reporting."
"An area for improvement in Tripwire Enterprise is stability, as my company had stability issues with the last few versions of the solution. Tripwire Enterprise has been a bit buggy."
"Cloud monitoring could be better. It would also be better if the company followed a pay-as-you-use model."
"The deployment with certain systems can be difficult and it needs to be simplified."
 

Pricing and Cost Advice

"The cost is per port and can be expensive but it does include training and support for three years."
"We have a three-year license for this solution."
"Licensing for this solution is paid on a yearly basis."
"I don't know the exact amount, but most of the time when I go to a company with a proposition, they will say, "This thing that you are selling is good, but it's expensive. Why don't you propose something like FortiGate, Check Point, or Palo Alto?" Cisco device are expensive compared to other devices."
"The licensing depends on the equipment, how many devices and the types of devices."
"Cloud monitoring could be better. It could also be cheaper. It would be better if the company followed a pay-as-you-use model."
"Tripwire is more expensive than Netwrix."
report
Use our free recommendation engine to learn which Intrusion Detection and Prevention Software (IDPS) solutions are best for your needs.
787,817 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
20%
Government
8%
Financial Services Firm
8%
Comms Service Provider
7%
Financial Services Firm
14%
University
10%
Government
10%
Educational Organization
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Cisco Sourcefire SNORT?
The product is inexpensive compared to leading brands such as Palo Alto or Fortinet.
What is your experience regarding pricing and costs for Cisco Sourcefire SNORT?
The product is inexpensive compared to leading brands such as Palo Alto or Fortinet. It is cheaper than Palo Alto and comparable to Fortinet. It also depends on Cisco’s discount. Sometimes it's che...
What needs improvement with Cisco Sourcefire SNORT?
The solution has some stability issues. Also, it's complicated compared to other products like FortiGate.
What do you like most about Tripwire Enterprise?
The product supports different platforms.
What needs improvement with Tripwire Enterprise?
The solution has some limitations in OT, IoT, and AIX. The product must provide whitelisting services.
 

Also Known As

Sourcefire SNORT
No data available
 

Learn More

 

Overview

 

Sample Customers

CareCore, City of Biel, Dimension Data, LightEdge, Lone Star College System, National Rugby League, Port Aventura, Smart City Networks, Telecom Italia, The Department of Education in Western Australia
1. Aetna 2. Adobe 3. ADP 4. Airbus 5. Amazon 6. American Express 7. Aon 8. ATT 9. Bank of America 10. Barclays 11. Baxter International 12. Bechtel 13. Boeing 14. Cisco Systems 15. CocaCola 16. Comcast 17. Dell 18. ETRADE 19. ExxonMobil 20. Ford Motor Company 21. General Electric 22. General Motors 23. Google 24. JPMorgan Chase 25. Kraft Foods 26. Lockheed Martin 27. McDonald's 28. Merck 29. Microsoft 30. Morgan Stanley 31. Nike 32. Oracle
Find out what your peers are saying about Cisco Sourcefire SNORT vs. Fortra's Tripwire Enterprise and other solutions. Updated: May 2024.
787,817 professionals have used our research since 2012.