I usually use it for GRE channels and VPNs. Is very stable and is a good solution. It has been stable.
Network Engineer at Banque des Mascareignes
Enables us to securely transfer data over the internet network but I would like the ability to automatically load balance
Pros and Cons
- "I'm able to transfer data over internet network security. With the GRE I'm able to transfer data within one bunch to another bunch in a public way, like the internet. The communication is encrypted and is private. It gives me added privacy."
- "There's a technology called SD-WAN that we would like to see. We are unable to handle multiple connections or to automatically load balance. I would like to have a feature that enables us to automatically prepare for load balancing."
What is our primary use case?
How has it helped my organization?
I'm able to securely transfer data over the internet network. With the GRE I'm able to transfer data within one site to another sites in a public way, like the internet. The communication is encrypted and is private. It gives me added privacy.
What is most valuable?
The GRE kernels and IPSEC security are the most valuable features.
What needs improvement?
There's a technology called SD-WAN that we would like to see. We are unable to handle multiple connections or to automatically load balance. I would like to have a feature that enables us to automatically prepare for load balancing.
Buyer's Guide
Cisco IOS Security
June 2025

Learn what your peers think about Cisco IOS Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.
For how long have I used the solution?
More than five years.
What do I think about the stability of the solution?
It is stable but is missing functionalities. For example, everyone is bound to one single router.
This product is being used on a daily basis, 24/7. We are a bank, so it is always running. We have no downtime and our customers don't have any downtime.
What do I think about the scalability of the solution?
You can do a lot in terms of the scalability. In my department, I have 11 branches that are using it and everything works flawlessly for them.
How are customer service and support?
Cisco's technical support is the best.
Which solution did I use previously and why did I switch?
I have previously used FortiGate and I didn't switch solution, I switched companies. Cisco is stable once it is up and running. You can forget about it, it's going to work unless the hardware fails. As your centers deploy, make sure it's configured and up and running. You just have to put it there and forget it.
How was the initial setup?
The complexity of the initial setup will depend on your level of expertise and your experience with the product. It was simple for me but I have seen others struggle with it.
Usually, when I did deploy I do it on a lap setup. The time it takes depends mostly on how we are going to plan the deployment. It can be done within a day or a week.
What about the implementation team?
Sometimes we will use an integrator for the deployment and sometimes we will do it ourselves.
What was our ROI?
The return on investment has already been achieved and it is great.
What's my experience with pricing, setup cost, and licensing?
The solution is a one-off fee once, it's just a matter of whether we are using IOS security you want to use the IT functionality, you need to have the security licenses.
What other advice do I have?
It's a good product you just have to have someone that really knows how to configure it otherwise it's going to be a nightmare.
I would rate it a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Operational Risk Manager at a financial services firm with 1,001-5,000 employees
Scalability and some enhancement to our security posture have been key for us
Pros and Cons
- "The most valuable feature is the scalability. The nice thing with the bigger vendors is that they're very good at scale."
- "I would like to see much more embedded security that works and that isn't a bolt-on."
What is our primary use case?
We use it for routing and switching, VPNs, connectivity to some degree, and firewalls.
How has it helped my organization?
In certain spots it has improved our security program's maturity, for example around virtualization and network segmentation.
What is most valuable?
The most valuable feature is the scalability. The nice thing with the bigger vendors is that they're very good at scale.
What needs improvement?
I would like to see much more embedded security that works and that isn't a bolt-on.
What do I think about the stability of the solution?
It's pretty stable. The stability has been good.
How are customer service and technical support?
I would rate the technical support at eight out of ten. We've had a lot of good feedback.
Which solution did I use previously and why did I switch?
Different products come and go but we've been using Cisco for 20 years.
What about the implementation team?
We use every consulting firm and probably most integrators, depending on the project. On any day it could be Deloitte, Accenture, etc.
What was our ROI?
I'm sure we've seen ROI. Routing is better than picking up a file, carrying it to you and handing it to you. But it's been in place for quite a long time.
What other advice do I have?
Look at this solution and figure out what you're trying to accomplish. You should probably augment it with some other vendors as well. I'm not a big single-vendor type of person. I don't think anyone does it perfectly well. With Cisco, you bring them in for their core competencies which are routing, switching, and virtual networking. Then you augment it with some security vendors that have been doing security the entire time.
I would rate it at eight out of ten. It's not a ten because of the criticisms around security.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Cisco IOS Security
June 2025

Learn what your peers think about Cisco IOS Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.
Network Engineer at Transportation
EEM is a valuable feature for turning a Cisco device into a programmable device.
What is most valuable?
EEM (Embedded Event Manager) is a software component of Cisco IOS.
I found that EEM is a handy feature [but it is an underdog for the end user] if fine tuning of monitoring is required or if you would like to turn a Cisco device (switch or router) into a programmable device (without fancy words like ACI or Python, etc.). It is low level but efficient and money saving. It is available by default (but check the IOS feature support first). For curious minds, it could be used in combination with IP SLA and tracking features, a network engineer Swiss army knife.
How has it helped my organization?
- Increased monitoring level for KPIs normally not tracked by network management systems.
- Ability to correlate events and report back in a predefined format/customized message on the switch.
- Making a Cisco switch act as a network event sensor is enhancing visibility on the network.
What needs improvement?
- Tailored monitoring/notifications and some sort of added intelligence moved now to the edge of the network. (Actually, it could be done at any point of network: core, distribution, or access.)
What do I think about the scalability of the solution?
As it is a tailored solution, it is not very scalable, but this is a trade off; you need a hammer or a scalpel. And EEM is a scalpel.
What's my experience with pricing, setup cost, and licensing?
No licenses but what comes with the features of IOS.
Which other solutions did I evaluate?
Before choosing this product, we evaluated other options. I looked for a tailored solution.
What other advice do I have?
The competition (like Juniper) do offer similar approaches (scripting capabilities, but I did not look into the details). The question is that in many cases, users are not extending their expertise to adopt these money/time-saving features that vendors provide with their OSs.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Manager at a insurance company with 1,001-5,000 employees
Good features. But when I converted it into a zone-based firewall, CPU utilization shot up and network performance slowed down.
Valuable Features:
1. Cisco IOS Security feature provides key features such as AAA, VPN, IPsec, content filtering, IPS, etc in all IOS based Cisco devices.
2. I like it because they include powerful security features that come with all Cisco Router and Switch from low to higher end.
3. It helped me to convert my Cisco router into a zone-based policy firewall.
4. It helped me to implement port security at my switch end.
5. I have implemented AAA in all Cisco routers and switch easily.
6. I have configured VPN server in a Cisco router with ease compare to OPENVPN configuration in a Linux OS environment.
Room for Improvement:
1. IOS security related IPS facility is not as strong as Cisco ASA and the signature file of IPS does not update automatically like Cisco ASA.
2. When I converted the Cisco router into a zone-based firewall, CPU utilization shot up and slowed down network performance.
Other Advice:
Cisco IOS security feature is the most robust and simple security facility which nice and small to implement. It helped me protect my network from external and internal attack.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Infrastructure Expert at a tech company with 51-200 employees
The Best network security OS
Valuable Features:
Cisco IOS is the best OS for Cisco routers and switches.
There are a lot of plus points of using Cisco IOS. A brief introduction about them are as follows.AAA- Cisco IOS has a lot advantages while using AAA. It can use various encryption services which also includes EAP with Radius.Firewall- You can use Cisco IOS Advance IP Services for creating Zone based firewalls on Cisco Routers.TCP Intercept- It prevents DDOS attacks quite effectively.PKI- You can use RSA keys in PKI. Also lets you use Certificates in PKI.VPN- Almost any type of VPN can be configured using IOS security. Site to site or remote. 802.1X- This facility has helped a lot of organizations and ISPs to maintain authentication for their users.
Room for Improvement:
It is very hard to find any limitations of this OS
Still when you use this as Zone based firewall you can see its limitations.
You need to restrict traffic with ACL, which is fine but you need to create too many ACLs.
Hence management of ACLs is a tedious task.
Works better with TACACS+ which is Cisco proprietary.
WAN connectivity is difficult on a router which is running IOS Security.
Other Advice:
The best OS from my point of view in Cisco IOS is Advanced IP Services.
This OS has changed the definition of network security by using the router.
The use of VPN concentrator is coming to an end because this OS can handle any kind of VPN using the router, so no need of VPN concentrators.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Director at Nam Truong Son
Plenty of functionality, reliable, and good interface
Pros and Cons
- "The most valuable features of Cisco IOS Security are the plenty of functionality it provides, many people are IT certified the usage, and the user interface is good."
- "Cisco IOS Security could improve its security features. There are competitors that have some additional security features, such as Fortinet FortiGate. Additionally, there should be better synchronization with Cisco IOS Security and other vendors, and improved AI features would be beneficial."
What is most valuable?
The most valuable features of Cisco IOS Security are the plenty of functionality it provides, many people are IT certified the usage, and the user interface is good.
What needs improvement?
Cisco IOS Security could improve its security features. There are competitors that have some additional security features, such as Fortinet FortiGate. Additionally, there should be better synchronization with Cisco IOS Security and other vendors, and improved AI features would be beneficial.
For how long have I used the solution?
I have been using Cisco IOS Security for over 20 years.
What do I think about the stability of the solution?
Cisco IOS Security is stable.
What do I think about the scalability of the solution?
The scalability of Cisco IOS Security is good.
How are customer service and support?
The technical support from Cisco IOS Security is of an average level. They had some difficulties.
I rate the support from Cisco IOS Security a four out of five.
What's my experience with pricing, setup cost, and licensing?
Cisco IOS Security price could be reduced, it is more expensive than many of the other solutions, such as Sophos and Fortinet FortiGate.
What other advice do I have?
This solution has some advantages over competitors, but it has weaknesses too.
I rate Cisco IOS Security an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Cyber Security Engineer at a tech company
Easy to install and good technical support on offer but could be easier to use
Pros and Cons
- "The product is easy to use."
- "There could be a bit more functions on offer that could make it easier to use."
What is our primary use case?
We primarily use the product as a security solution within our company.
What is most valuable?
Overall, the devices are very good and reliable.
The product is easy to use.
It's quite a stable solution.
The installation process is easy.
Technical support has always been very good.
What needs improvement?
It's a good device yet it's not a market leader. There are better options for customers to choose from.
There could be a bit more functions on offer that could make it easier to use.
For how long have I used the solution?
We have used the solution for four years. It's been a while. We have a bit of experience with it at this point.
What do I think about the stability of the solution?
The stability is great and the performance is good. It's reliable. There are no bugs or glitches. it doesn't crash or freeze.
What do I think about the scalability of the solution?
We have about 2,000 users on the product currently.
How are customer service and technical support?
Cisco technical support is the best in the world. They are very helpful and responsive and we are always satisfied with the amount of assistance we get.
Which solution did I use previously and why did I switch?
Previous to this solution, we did not use anything else.
How was the initial setup?
It's straightforward to set up. The product isn't too complex in terms of implementation. It takes about two days to deploy everything.
You only need two people for installation. We have two technicians for the installation of the product and two engineers for managing the product.
What about the implementation team?
We handle the implementation ourselves in-house. We don't need outside consultants or integrators.
What's my experience with pricing, setup cost, and licensing?
We pay a yearly subscription for signatures and stuff for the filtering, debugging inspection.
Which other solutions did I evaluate?
We did not evaluate anything before we started using Cisco. We didn't evaluate other options.
What other advice do I have?
We always use two versions behind the latest version. We do not use the latest version typically.
I'd rate the solution at a six out of ten.
I wouldn't recommend the solution to other users or organizations at this time.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
System Administrator at a tech services company with 11-50 employees
A highly scalable solution that is used for security
Pros and Cons
- "The Intrusion Firewall is a valuable feature."
- "Cisco is an expensive firewall, so the pricing can be improved."
What is our primary use case?
The solution is used for security purposes.
What is most valuable?
The Intrusion Firewall is a valuable feature.
What needs improvement?
Cisco is an expensive firewall, so the pricing can be improved.
For how long have I used the solution?
I have been using Cisco IOS Security for more than five years.
What do I think about the stability of the solution?
The stability can be improved. I rate the stability an eight out of ten.
What do I think about the scalability of the solution?
It is a scalable solution. Presently, two hundred users are using the solution.
How are customer service and support?
The technical support team is good.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is not very difficult.
What's my experience with pricing, setup cost, and licensing?
The pricing is expensive.
What other advice do I have?
I will recommend it if your entire infrastructure is Cisco-based, because the compatibility is good.
I rate the overall solution an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Cisco IOS Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
OPNsense
Cisco Secure Firewall
Palo Alto Networks NG Firewalls
Juniper SRX Series Firewall
Fortinet FortiGate-VM
KerioControl
Fortinet FortiOS
Palo Alto Networks Advanced Threat Prevention
Check Point IPS
Palo Alto Networks URL Filtering with PAN-DB
Juniper vSRX
Fortra's Tripwire Enterprise
Buyer's Guide
Download our free Cisco IOS Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What do you recommend for a corporate firewall implementation?
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Which is the best network firewall for a small retailer?
- When evaluating Firewalls, what aspect do you think is the most important to look for?
- Cyberoam or Fortinet?
- Fortinet, Palo Alto or Check Point?
- If you could go back, would you change your decision to buy that firewall and why?
- Sophos XG vs Fortigate UTM
- Can you recommend a solution to replace Cyberoam 200ing Firewall?