Vinay-Singh - PeerSpot reviewer
Manager IT & Security at mCarbon Tech Innovations Pvt., Ltd.
Real User
Top 10
Beneficial reports, good protection, and straightforward setup
Pros and Cons
  • "The most valuable features of Cisco NGIPS are protection and reporting."
  • "We have a separate management controller for Cisco NGIPS. If they have not done it already they should integrate Cisco NGIPS with the Cloud Portal."

What is our primary use case?

I use Cisco NGIPS as a firewall.

What is most valuable?

The most valuable features of Cisco NGIPS are protection and reporting.

What needs improvement?

We have a separate management controller for Cisco NGIPS. If they have not done it already they should integrate Cisco NGIPS with the Cloud Portal.

The solution has some bugs that sometimes take time to resolve.

For how long have I used the solution?

I have been using Cisco NGIPS for approximately two years.

Buyer's Guide
Cisco NGIPS
April 2024
Learn what your peers think about Cisco NGIPS. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
767,847 professionals have used our research since 2012.

What do I think about the stability of the solution?

The stability of Cisco NGIPS has been good since we have been using it.

What do I think about the scalability of the solution?

The scalability of Cisco NGIPS is good.

How are customer service and support?

Cisco has better technical support than other competitors, such as Check Point IPS or Palo Alto. Cisco has very good support, they are always ready to help their customer if there are any production issues.

Cisco NGIPS should add a technical person to the chat support. They correctly do not have a specialist. The knowledge base of the chat agent should be better.

Which solution did I use previously and why did I switch?

I have used Check Point IPS solutions.

How was the initial setup?

The implementation of Cisco NGIPS is straightforward.

What about the implementation team?

You have to do your own implementation of the Cisco NGIPS hardware, but for the configuration, Cisco support can be involved from day one. That's what I have experienced. There was some exception but I have involved the Cisco support team from day one when I started configuring my firewall.

What was our ROI?

We have seen a return on investment by using Cisco NGIPS.

What's my experience with pricing, setup cost, and licensing?

There is a license required to use Cisco NGIPS and it can be a one or three-year license.

What other advice do I have?

I would advise others to use the support from Cisco, they are helpful.

I rate Cisco NGIPS an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Student at a educational organization with 201-500 employees
Real User
Top 5
Easy to deploy, good intrusion prevention, but the documentation needs improvement.
Pros and Cons
  • "The most valuable features are the intrusion detection ones."
  • "There is room for improvement in the policy documentation."

What is our primary use case?

The primary use case is for intrusion prevention. We install the solution between the firewall and the call switches.

What is most valuable?

The most valuable features are the intrusion detection ones. We channel the intrusion engine to create a policy of prevention. We only use this solution for intrusion prevention, not as a firewall.

What needs improvement?

There is room for improvement in the policy documentation. It gets confusing trying to understand what all of the policies mean. We need clear documentation explaining what each policy does.

For the Cisco STD, if we lose the connection with the SMC and STD, we can only assist with the STD via the CLI, so we can only do some troubleshooting. I think this is an area that needs improvement. In terms of the architecture, it needs to be more comfortable to change our own managed STD via the UI even if SMC is not available.

The technical support has room for improvement.

For how long have I used the solution?

I have been using the solution for six years.

How are customer service and support?

Some of the engineers within Cisco's tech support are knowledgeable and others are not. Sometimes we have to go back and forth for a week to get an answer.

How would you rate customer service and support?

Neutral

How was the initial setup?

The initial setup is not complex; we only need to define the IP address and add the SMC IP. Both STD and SMC have the capability of SDM. Also if we don't have SMC, we mainly require the anti-SDM in UI. However, after we enroll the Cisco file from the SMC, we can no longer manage the STD from there. Therefore, it is very difficult to roll back if there is a connection loss between the STD and SMC, as SMC cannot manage the STD via the UI. In comparison, if there is a connection loss between Palo Alto Panorama, we can simply lock it with Palo Alto following the file and do some configuration. 

What other advice do I have?

I give the solution a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Cisco NGIPS
April 2024
Learn what your peers think about Cisco NGIPS. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
767,847 professionals have used our research since 2012.
ChrisWanyoike - PeerSpot reviewer
Network Infrastructure Specialist at Central-Bank-Kenya
Real User
Top 5Leaderboard
Offers defense mechanism and helps with intrusion prevention but performance needs improvement
Pros and Cons
  • "I like the way the tool pushes the packets from the node level."
  • "Cisco NGIPS' performance could be better."

What is our primary use case?

Cisco NGIPS offers defense mechanism and intrusion prevention for your environment. 

What is most valuable?

I like the way the tool pushes the packets from the node level. 

What needs improvement?

Cisco NGIPS' performance could be better. 

For how long have I used the solution?

I have been working with the product for 24 years. 

What do I think about the stability of the solution?

Cisco NGIPS is stable. 

What do I think about the scalability of the solution?

The tool is scalable. My company has over 2000  users for the product. 

How was the initial setup?

The tool's deployment is not straightforward. You need a technical and competent person to do it. A four to five-member technical team can handle its deployment and maintenance. 

What was our ROI?

The tool's ROI is good. 

What's my experience with pricing, setup cost, and licensing?

The tool's licensing costs are yearly. 

What other advice do I have?

I rate Cisco NGIPS a ten out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Senior Network Security Engineer at a wellness & fitness company with 10,001+ employees
Real User
Auto-scaling, powerful software fingerprint identification, and good technical support
Pros and Cons
  • "I think their fingerprints are good in terms of how they whitelist and blacklist."
  • "The only thing I think they may need to improve on a little bit is identifying software more correctly when you do network discovery."

What is our primary use case?

The NGIPS handles all of the IPS functionality for our security.

What is most valuable?

The most valuable feature for our cloud-based deployment is the autoscaling.

For our on-premises deployment, clustering is the most valuable.

I think their fingerprints are good in terms of how they whitelist and blacklist. This is because of Talos, which is really awesome. We use that a lot.

The anomaly detection capabilities are awesome.

What needs improvement?

The only thing I think they may need to improve on a little bit is identifying software more correctly when you do network discovery. You need that to really handle finding anomalies properly. In the past, I've noticed that some applications are not identified correctly, based on the OS and the fingerprints that they're pulling from the host.

In the future, we would like to see more involvement with the on-premises hybrid cloud. We want to see Cisco do more in the cloud space, and basically improving the connection between on-premises and the cloud. This including things such as automation.

For how long have I used the solution?

I have been using Cisco NGIPS for almost seven years.

What do I think about the stability of the solution?

The code is well-stabled right now and we've never had issues upgrading from one version to another. We've had it since version 2.0 and for every time we upgrade, it gets better. We're currently on version 6.6 and we're expecting that when 6.7 comes out, it will get better.

What do I think about the scalability of the solution?

This is a very scalable product. You can add multiple devices to the same policy and then push that out.

In the cloud space, scaling is done automatically based on the amount of traffic and the amount of bandwidth that's generated. It scales up and down, back and forth, as needed. For example, if there is not much traffic then it drops, whereas if there is a lot of traffic then it creates another FTD, and then it just shares the load with load balancing.

Everything is scaled properly both in the cloud and on-premises.

How are customer service and technical support?

Cisco's technical support is really good. I would say that they are number one. They follow up on their calls and tags, as well.

Which solution did I use previously and why did I switch?

I also have experience with Check Point and I find that the pricing is better with Cisco.

How was the initial setup?

The initial setup is straightforward. With the Firepower Threat Defense (FTD), everything is in one box. You can do everything from firewalls to IPS and more. It also includes the next-generation firewall.

It is an easy upgrade process that is easy to understand. I would say that from version 3.0, it has improved.

What's my experience with pricing, setup cost, and licensing?

The cost of the license depends on the level of support that you have with Cisco. 

What other advice do I have?

My advice for anybody who is implementing Cisco NGIPS is to read and understand all of the documentation before you start. Whatever it is that you might need help with, reach out to Cisco support and let them help you. The documentation is available and it is very understandable so you may not need their help. I would say that if you take your time to read it then you shouldn't have any problems in deploying.

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Carlos Bracamonte - PeerSpot reviewer
Senior Network Support Engineer at Amadeus
MSP
Top 5
Good protection, reliable and responsive support
Pros and Cons
  • "The URL filtering feature and the new locations feature are both valuable additions to the solution."
  • "While the Management GUI and FMC could be improved, the devices themselves function well."

What is our primary use case?

Some of our customers are having DDOS attacks and ransomware attacks.

How has it helped my organization?

Earlier in July 2019, I noted that there was an attack. To mitigate future attacks from the ransomware in Columbia Bank and other similar situations, we at Cisco Talent, which is responsible for security intelligence, provided updated security rules. We offered intrusion policies and codes through signatures to help overcome such situations.

What is most valuable?

It's a good solution.

The solution is not that bad. Next-generation firewalls work from my experience, they work. 

The URL filtering feature and the new locations feature are both valuable additions to the solution.

What needs improvement?

While the Management GUI and FMC could be improved, the devices themselves function well.

For how long have I used the solution?

I have been using Cisco NGIPS for more than five years.

I provided support for version 6.4, but in our company, we do have Firepower version 7.0.

What do I think about the stability of the solution?

Cisco NGIPS is a stable solution.

How are customer service and support?

Cisco has great support.

What other advice do I have?

I would rate Cisco NGIPS an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Diego Munoz - PeerSpot reviewer
Information Technology Manager at AGRI-CORP
Real User
Has good malware detection, threat defense, sandboxing, VPN, and mail security features
Pros and Cons
  • "The Malware Detection, threat defense, sandboxing, VPN and mail security have all been valuable features of Cisco NGIPS."
  • "I would like to see Cisco NGIPS to include home office support in one single product."

What is our primary use case?

We use Cisco as a firewall. It is an intrusion detection and prevention solution.

What is most valuable?

The malware detection, threat defense, sandboxing, VPN, and mail security have all been valuable features of Cisco NGIPS.

What needs improvement?

The performance of CISCO Firepower could be improved. 

We moved from Sophos to Cisco before the pandemic. During the pandemic, there was an increase in VPN connections. We had a layer of security within CISCO Umbrella, and now with Cloud. The firewall protects the internal system, but we needed to add another layer of security for the endpoints that are outside the local area network. We needed another product to cover this lack of security.

We prefer to have integration with the points that are outside our local area networks using the same brand using one single console. Because the firewall only protects the people inside the network, we required another solution.

I would like to see Cisco NGIPS include home office support in one single product.

For how long have I used the solution?

Our organization has been using Cisco NGIPS for two years.

What do I think about the stability of the solution?

Cisco NGIPS is stable most of the time.

What do I think about the scalability of the solution?

This solution is not easily scaled. I would like Cisco NGIPS to be easier to scale. With the increase in work from home, we needed to add another layer of security to ensure we can meet the demand of stability, high availability, and connection.

How are customer service and support?

Our company has two layers of support with Cisco. One is the local support, which is very good. The second support is directly from Cisco. They are quick to respond and have quick solutions to the problems.

Which solution did I use previously and why did I switch?

We moved from Sophos to Cisco Firewall because we were looking for better integration between all the appliances and data center. All of our core switches, our wireless system, and other tools are the Cisco brand, meaning that all our monitoring options are integrated under Cisco.

What about the implementation team?

We hired a professional service to install this solution.

What other advice do I have?

With the increase in work from home, companies may need more than just a firewall. I recommend anyone considering Cisco NGIPS evaluate all the demands from their in-home offices and determine if their solution needs to be bigger, or wider, for security and performance.

I would rate this product a 9 out of 10, particularly if you work in a LAN environment.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
IT Manager at a financial services firm with 51-200 employees
Real User
Useful filters, reliable, and customer support helpful
Pros and Cons
  • "I have found the filter and the antivirus to be most valuable."
  • "The user interface needs some improvement, it is a little rudimentary and not very intuitive."

What is our primary use case?

We use the solution for traffic filtering, security, and antivirus capabilities.

What is most valuable?

I have found the filter and the antivirus to be most valuable.

What needs improvement?

The user interface needs some improvement, it is a little rudimentary and not very intuitive. If you are not very technical inclined you may need to be assisted or might struggle to set it up.

The newer version tends to use a lot of system resources. For example, your processor and RAM.

For how long have I used the solution?

I have been using the solution for approximately four years.

What do I think about the stability of the solution?

The solution is stable and reliable, it does the job well.

What do I think about the scalability of the solution?

The scalability is excellent, they can support a large environment. However, a large size organization will need its own dedicated appliance.

How are customer service and technical support?

The customer support is very good.

Which solution did I use previously and why did I switch?

We have used and still use Darktrace. We do not use it to replace Cisco's NGIPS solution but we use it predominantly as an in-network snooper.

How was the initial setup?

The installation is complex.

What about the implementation team?

We used an in-house team to do the deployment and it takes roughly a day and a half depending on the size of your organization and the configuration. Setting up the rules, all the features, and the licensing takes time.

To do the maintenance you need somebody familiar with Cisco and networking technologies.

What was our ROI?

By using this solution we have received a return on our investment. 

What's my experience with pricing, setup cost, and licensing?

Cisco products are not cheap and this solution is no different. However, the price of all of the Firepower is part of a bundle when you buy the actual firewall, the Cisco firewall. It is part of the whole bundle package, but Firepower IPS itself has its own costs.

We are on a yearly license and the price depends on the environment, we pay approximately $33,000. The solution has additional components, and each one of the components cost extra.

What other advice do I have?

For those wanting to implement this solution, I was advice before deploying the solution, understand exactly what you want it to do for you. The product has a couple of different capabilities, do you want to expand, or you may not want to expand. These are scenarios that you have to take into account. I would not recommend the solution for small organizations, it would be too time-consuming for that.

I rate Cisco NGIPS an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PauloRio - PeerSpot reviewer
Senior Consultant at Axians
Consultant
Top 20
Stable environment, excellent technical support, and with good training you can go the distance
Pros and Cons
  • "It is more or less stable. Sometimes I have some issues normally when we need to upgrade it to newer versions. I think it does the job."
  • "I think the part of IPS and everything else needs to be better equated to the real needs or current needs of the business compared to the other manufacturer, because it is not straightforward, a way to configure it compared to the other competitors."

What is our primary use case?

Our primary use case is as a firewall segregating networks and defending the perimeter.

How has it helped my organization?

I would consider this to be a medium product in its field across the board.

What needs improvement?

Some features, for instance, are a way for the management console to be able to manage each specific firewall, for instance. Because if we have more than one firewall configured in the management center, we cannot delegate administration, just one of the equipment. I think the part of IPS and everything else needs to be better equated to the real needs or current needs of the business compared to the other manufacturer, because it is not straightforward, a way to configure it compared to the other competitors.

For how long have I used the solution?

I have been using Cisco NGIPS for one year.

What do I think about the stability of the solution?

It is more or less stable. Sometimes I have some issues normally when we need to upgrade it to newer versions. I think it does the job. The hardware does the job, and the current models do the job.

What do I think about the scalability of the solution?

We have around four thousand users and that would be an example of its scalability.

How are customer service and support?

Technical support is good. If you open a case about the support, it is good. Compared to the other manufacturer, it is very good.

How was the initial setup?

The initial setup was complex and the upgrade took a lot of time with a very big image to download and everything else. We had many versions and patches that had to be installed. The deployment took between two and three hours.

What about the implementation team?

In this case, we did it in-house and I was the integrator.

What other advice do I have?

I think we have to have a good knowledge of the product. It is not easy to set up from the beginning. And I am also using the comparison with the other manufacturer. You need to have very good training before managing the product. I would rate Cisco NGIPS a seven on a scale of one to ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Buyer's Guide
Download our free Cisco NGIPS Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2024
Buyer's Guide
Download our free Cisco NGIPS Report and get advice and tips from experienced pros sharing their opinions.