Our primary use case includes basic firewalls, VPNs, NAT, and our connections to customers.
It's used in our data centers to protect the network and customer circuits.
Our primary use case includes basic firewalls, VPNs, NAT, and our connections to customers.
It's used in our data centers to protect the network and customer circuits.
Cisco ASA Firewall has improved our organization by allowing connectivity to the outside world and into different places.
Cybersecurity resilience is very important to our organization. There are always threats from the outside, and the firewall is the first line of defense in protecting the network.
Cisco ASA Firewall is a well-known product. They're always updating it, and you know what they're doing and that it works.
It would be good if Cisco made sure that the solution supports all routing protocols. Sometimes it doesn't.
I've been using it for probably 10 to 15 years.
For the most part, it's stable.
It's a very scalable solution.
The technical support is very good, and I would give them a nine out of ten.
The pricing and licensing are getting more complicated, and I'd like that to be simpler.
We evaluated some Palo Alto and Juniper solutions, but Cisco ASA Firewall is better in terms of ease of use. You could get certified in it.
To leaders who want to build more resilience within their organization, I would say that the ASA, along with its features, is a good product to have as one of the lines of defense.
The solution does require maintenance. We have four network engineers who
are responsible for upgrading code and firewall rules, and for new implementations.
On a scale from one to ten, I would rate Cisco ASA Firewall a nine. Also, it's a very good product, and it compares well to others.
We mainly use it for ICS security.
We definitely feel more secure. We have more control over things going in and out of our network.
Cybersecurity has been our top priority because of the last few attacks on our peers in the oil and gas industry.
The IPS solution helps us to not only navigate north-south traffic, but also east-west traffic.
Third-party integrations could be improved.
Not everything works out-of-the-box. Sometimes, you have to customize it to your needs.
I have been using it for two years.
It is stable for the most part.
There is maintenance needed for software, firmware, and updates. Three or four people keep up with the updates, etc.
It is pretty scalable. We can add as many devices as we want.
The technical support is good. I would rate them as 10 out of 10.
Positive
We previously had a different platform. We wanted to converge multiple platforms into one.
I switched companies. So, I have more experience with Palo Alto.
We saw immediate benefits after deployment from having more control and visibility.
Pretty much everything is included in the price for what we are using.
We looked at Check Point, Palo Alto, Fortinet, and a bunch of others. The management and support for the CIsco product is better.
Listen to your customers and see what their needs are.
The whole stack provided by Cisco is a holistic solution for cybersecurity experts, like myself, and companies who are looking to secure their network.
You should partner up with a good team to view all products available, which cater and are customized to your needs.
We haven't found any gaps where it is lacking.
I would rate this product as eight or nine out of 10.
We use it for remote access VPN. That means the folks at home can work from home using AnyConnect.
For our very specific use case, for remote access for VPN, ASAs are very good.
Cisco also introduces new features and new encryption techniques.
Cisco wasn't first-to-market with NGFWs. That is one of the options now. They did make an acquisition, but other vendors got into that space first. I would tell Cisco to move faster, but everything moves at the speed of light and it's hard to move faster than that. But they should look at what other vendors are doing and try not only to be on the same wavelength but a little bit better. It's hard to be critical of Cisco given that they pave the way a lot, but they should see what their peers are doing and try to emulate that.
In terms of additional features, perhaps there could be some form of integration with the cloud. I don't know how much appetite we would have for that given the principle of keeping a lot of the sensitive data on-prem. But some integration with the cloud might be useful, given that the cloud is everything you see these days. We have our on-premises devices, but maybe they could provide an option where it fails over to a cloud in a worst-case scenario.
I've been using Cisco ASA Firewalls from the time I was in school. I learned it when I was in the academic setting. I joined Cisco and worked there for six years there as a sales engineer before joining my current company.
The stability of the solution is a 10 out of 10.
Scalability is probably a 10 out of 10 for what we're looking at.
Their technical support is very good. Maybe I view them with rose-colored glasses since I was there for six years, but they really do try hard. Cisco cracks the whip on them. They do a lot of work. There's no downtime.
Positive
The challenge we wanted to address was scale. We're growing and we needed something a little more robust, something that could hold a big boy. We've got a lot more employees and we were using an older version of the hardware, so we upgraded to the newest version of the hardware, given that we're familiar with it. It solves our use case of allowing employees to work from home.
I was involved in the design, deployment, and operations. Our team is very special in the fact that we don't delegate to other folks. We're responsible for what we eat and what we design. We actually do the hands-on work and then we maintain it. We tend not to hire out because they come, they wash their hands clean of it, leave, and then there's all this stuff that needs fixing. If we get paged at 3:00 AM it might be our fault, and the lessons are learned.
Our network engineering team consists of about 12 people.
The pricing is fair.
My advice to others would be to design it well and get it validated by the Cisco team or by a consulting company. Don't be afraid of the solution because they have skin in the game. It's been in the market for so long, it's like buying a Corolla, as odd as that sounds. If you have a use case for your car where you're just driving from A to B, then get that Corolla and it will suit you well. It will last you 100 million miles.
Cyber security resilience is super important. We have super important data and we need to secure it. We're regulated and audited by the government and we're audited all the time. I get audited when I breathe. We have to make sure everything is super transparent and make sure that we have all of the fail-safes in place and done well. We have to be very accountable so that there are no "gotchas."
We use it to protect our DMZs and externals, to protect our network from our other city partners who manage their own networks to which we have direct connections, like VPNs, and to manage the security parameters between inside and outside connectivity and vice versa.
Cisco Firepower NGFW Firewall was introduced as a migration of many firewalls into one. Just having one firewall with one place of security and one place to look for your packets has really helped.
The features I've found most valuable are the packet captures and packet traces because they help me debug connections. I like the logs because they help me see what's going on.
The security correlation events and the network map help me to drill down on a host at will.
I really like the flexibility of the policies such as those you can use and the layer three policies with which you can block applications. It's really versatile. I like the security zones.
Cybersecurity resilience is our main focus right now. Because we're a government organization, everybody's really nervous about security and what the ramifications are. My device generates all the logs that our security team goes through and correlates all the events, so it's really important right now.
I think they need to review their whole UI because it feels like it was created by a whole bunch of different teams of developers who didn't fully talk to each other. The net policy screen is just a mess. It should look like the firewall policy screen, and they should both act the same, but they don't. I feel like it's two different buildings or programming, that don't talk to each other, and that really annoys me.
They should either build an application or get away from the web. They need to do something that's uniform and more streamlined.
We have a multi-person firewall team, and I can't look at a policy while somebody else is in it. It'll kick me out. I might be working on something that the other guy has to modify. I know that in the next versions they will be dealing with it with a soft lock, but it should've already been there.
One of Cisco's strengths is the knowledge depth of their staff. The solutions engineer we worked with knew the routing and each protocol. If he didn't know something, he would reach out to someone else at Cisco who did. He would even talk to a developer if he needed to.
I've been using Firepower for about three years.
There are some stability issues. We ran CheckPoint for years and didn't have problems with the firewall itself. However, with Firepower, in the past two years, we've had two major crashes and a software bug switchover.
We were debugging NAT rules. I did a show xlate for the NAT translation, and the firewall rebooted itself.
It has only been three instances in two years, but when I compare the stability to that of CheckPoint, it seems higher. CheckPoint just seemed to run.
We have about 8000 end users. Scalability-wise, it's already handling a large amount of traffic.
I like that Cisco's technical support will help me recover the firewall when everything falls apart. I'd give them a nine out of ten. They've really been consistently good, and they go after the problem.
Positive
We previously used CheckPoint and Fortinet. We switched from CheckPoint because it was unsupported, and we wanted to move to a next-generation firewall.
We went to Fortinet, and when we switched over, it caused a huge network outage. The Cisco engineers helped fish us out of that. Our GM at the time preferred Cisco, and we switched to Cisco Firepower NGFW Firewall.
Setting up the machines was straightforward, but exporting was complex. That is, it wasn't a complex deployment as far as the hardware goes. It was more of a complex deployment as far as transferring all the rules go because of our routing architecture.
Firepower is our main interface out to the outside world. We have about eight DMZs that are interface-based. You can do a logical DMZ or you can have an interface and a logical DMZ. We have about eight that are on interfaces. Then, we have our cloud providers and the firewall. We have rules so that our cloud providers can't ingress into our network.
I've found that Firepower does need a lot of maintenance. It needs a lot more software updates than other solutions. We have three people to maintain the solution.
For the deployment, we had about 18 team members including firewall administrators, Cisco firewall engineers, and techs.
The licensing scheme is completely confusing, and they need to streamline it. They have classic licensing and a new type of licensing now. Also, the licensing for the actual firewall is separate from the one for TAC support.
My advice to leaders who want to build more resilience within their organizations is that they should help make policies. Leaders don't want to make policies; they don't want to put their names on policies or write policy documents. I as a firewall administrator am the one saying what the policy should be. I tell them what should happen, and sometimes, they resist.
Also, because the system is just too big to really manage without TAC, you would need TAC along with Firepower.
My advice would also be to go with HA or a cluster up front and not to be cheap. You really need to go in with a robust solution up front.
I would rate Firepower an eight on a scale from one to ten because the firewall and tech support together make it a very robust solution.
We have the Cisco 5585-X in our data center for perimeter security, internet protection, and for applications behind Cisco ASA DMZs. The challenges we wanted to address were security and segregating the internal networks and the DMZs.
Security-wise, it's given us the protection that we were looking for. Obviously, we're using an in-depth type of design, but the Cisco ASA has been critical in that stack for security.
The Packet Tracer is a really good tool. If someone calls because they're having problems, you can easily create fake traffic without having to do an extended packet capture. You can see, straight away, if there's a firewall rule allowing that traffic in the direction you're trying to troubleshoot. As a troubleshooting tool, Packet Tracer is one of the things that I like. It comes up in all my interviews. When I want to figure out if someone knows how to use the ASA, I ask them about use cases when they use the Packet Tracer.
One of the challenges we've had with the Cisco ASA is the lack of a strong controller or central management console that is dependable and reliable all the time. There was a time I was using what I think was called CMC, a Cisco product that was supposed to manage other Cisco products, although not the ASA. It wasn't very stable.
The controller is probably the biggest differentiator and why people are choosing other products. I don't see any other reason.
I've used the Cisco ASA going back to the 2014 or 2015 timeframe.
The ASA has been very stable for us. Since I deployed the ASA 5585 in our data center, we've not had to resolve anything and I don't even recall ever calling TAC for an issue. I can't complain about its stability as a product.
Our Cisco ASA deployment is an Active-Standby setup. That offers us resilience. We've never had a case where both of them have gone down. In fact, we have never even had the primary go down. We've mainly used that configuration when we're doing code upgrades or maintenance on the network so that we have full network connectivity. When we're working on the primary, we can switch over to the standby unit. That type of resiliency works well for our architecture.
TAC is good, although we've had junior engineers who were not able to figure things out or fix things but, with escalations, we have eventually gotten to the right person. We also have the option to call our sales rep, but we have never used that option. It seems like things are working.
Neutral
In the old days, we used Check Point. We did an evaluation of the Cisco ASA and we liked it and we brought it on board.
At that time, it was easy for our junior operations engineers to learn about it because they were already familiar with Cisco's other products. It was easier to bring it in and fit it in without a lot of training. Also, the security features that we got were very good.
The one we deployed in the data center was pretty straightforward. I also deployed the Cisco ASA for AnyConnect purposes and VPN. I didn't have to call TAC or any professional services. I did it myself.
We used a Cisco reseller called LookingPoint. I would recommend them. We've done a lot of other projects with them as well.
It's a great investment and there's a lot of value for your money if you're a CSO or a C-leader. As an engineer, personally, I have seen it work great wonders for us. When we're doing code upgrades or other maintenance we are able to keep the business going 100 percent of the time. We have definitely seen return on our investment.
I don't look at the pricing side of things, but from what I hear from people, it's a little pricey.
At the time, we looked at Juniper and at Palo Alto. We didn't get a feeling of confidence with Palo Alto. We didn't feel that it offered the visibility into traffic that we were looking for.
We use Cisco AnyConnect and we've not had any issues with it. During COVID we had to scale up and buy licenses that supported the number of users we had, and we didn't have any problems with it.
We pretty much use it as our edge firewall and data center firewall.
We have a colocation that is the center for all our campuses. That is where our edge firewall is. We use that for VPN as well, and it was a great thing during the pandemic because we were already ready to go with VPN. We didn't have to do anything extra on that part.
The solution has really enabled us to ensure our university is secure.
Cybersecurity resilience has been paramount. Because there is a threat of losing everything if ransomware or another sort of attack were to happen, the cybersecurity resilience has been top-notch.
The multi-context feature is the most valuable, especially in our data center. Having different needs for different departments is part of our organization. We can have five firewalls in one.
I would like it if they made the newer generation a bit simpler. You can do ASA code and FXOS. It is just a bit confusing with the newer generational equipment on what it can do.
I have been using this solution for five years.
I would rate the stability as 10 out of 10.
We do maintenance for software updates, etc. I don't think we have had any major hardware failures.
We haven't had to really scale up too much.
The technical support is excellent. Every time that we have ever had an issue, we got a result very quickly. I would rate them as nine out of 10.
Positive
We have always had ASA since I have been at the company. The ASAs were in place and we have upgraded to newer ASA Next-Generation Firewalls.
I am not a huge fan of Cisco licensing in general. However, I wasn't really involved with the pricing. That decision was made a little higher than me.
We are in the middle of an upgrade to the newer Firepowers.
We have used Palo Alto for another solution and they have a better firewall. It is a whole new GUI to learn. With Palo Alto, you simply get one code, then that is your firewall. With the newer Firepowers, there are two or three different ways that you can run it. So, we currently have our data center running in ASA code, then we are doing it a different way with our edge ASA. My supervisor has complained about all the different ways that the new hardware can be configured and installed.
Stay more up-to-date with equipment. The old equipment is what will get you, e.g., leaving Windows 7 machines on your network or 15-year-old switches.
Heavily research what can do cluster mode, HA pairs, etc. That is where we ran into the "gotchas". You have to run it in certain ways to have it clustered and run it another way to have it as an HA pair.
I would rate ASA Firewall as nine out of 10.
We are using it for border firewalls, VPN access, and site-to-site VPN tunnels.
It is deployed at a single location with about 2,500 users.
So far, the remote VPN access has been a perfect solution for our company.
The user interface is a little clunky and difficult to work with. Some things aren't as easy as they should be.
I have been using it for five years.
So far, it has been very stable.
It does require maintenance. There is a team of two who manage it.
We haven't scaled it much at this point.
The technical support has been good so far. I would rate them as eight out of 10.
Positive
The VPN solution works much better than our previous solutions.
We previously used Palo Alto. The switch was driven by Cisco's pitch.
It was fairly straightforward. We stood it up side by side with our nesting firewalls. We did some testing during an outage window, then migrated it over.
We used a partner, CDW, to help us with the deployment. Our experience with CDW was good.
Internally, it was just me for the deployment.
The pricing seems fair. It is above average.
Take the time to really learn it, then it becomes a lot easier to use.
I would rate the solution as eight out of 10.
We are using it for security on everything from small customers to big data centers.
It is stable. We saw benefit from this in just a few days.
Cisco AnyConnect is my favorite. It is awesome. It also exists on Firepower and newer things.
Cisco ASA is starting to get old and Firepower is taking over. All the good things happening are with Firepower. Everything that I could wish for is in Firepower. We will probably not be doing too many new installations of ASAs since Firepower is mostly taking over.
I have been using it for 15 to 20 years.
It is stable and secure. There are a few bugs, etc. Overall, we are very happy with it. We have never looked at anything else because it works so well. I would rate the stability as 10 out of 10. It is very good.
There is maintenance. We have to keep an eye out for software upgrades and forced changes to the configuration. We have a network operations team of 15 people who take care of these things from day to day.
The solution's scalability is very good.
We use it on customers who have two employees up to customers with 5,000 employees. It is also used for customers who have one site or several sites. It is all over the place
Cisco tech is always good and helpful. I would rate them as 10 out of 10.
Positive
I didn't use another solution previously.
All our deployments have been different. Some have been really easy and others have been really complex. It could go either way: some are complex and some are easy. The complex solutions could take days or a couple of weeks to deploy. Easy solutions take a day.
If it was a big project, there would be a pre-project identifying what we were going to do and making a plan for it, then we would realize that plan. If it was a smaller thing, we would just jump into it.
It was deployed in-house. Depending on the solution and its complexity, it could take a single person to a team of 20 people to deploy it.
Our return on investment is having a network that we don't need to think too much about. It works, and that is it.
Cisco is always expensive, but you get what you pay for. It is expensive for a reason. It is a good solution, and good solutions cost money.
AnyConnect is an extra license. If you want the IDS/IPS things, those are usually extra too.
I evaluated Check Point, Palo Alto, and Fortinet, but Cisco won the race. Since we were already running most of our other networking with Cisco, it felt natural to land on Cisco.
I would rate the solution as 10 out of 10.
It is for our VPNs and filters out websites.
It helped us a lot with our VPNs for the home office during COVID. There has been more security and flexibility for VPNs and other applications.
Its security is easy to use.
I would like more features in conjunction with other solutions, like Fortinet.
I have been using it for five years.
It has very good stability.
It has really good scalability.
The customer service and technical support are good. I would rate them as nine out of 10.
Positive
We were previously using Fortinet. We switched to ASA and Firepower when our contract with Fortinet ended. Now, we are only using ASA.
The deployment was simple.
The ROI is good. Using ASA, we have saved 10% to 20% on our costs.
The pricing is fine. It is not too bad.
We had it integrated with the Umbrella solution a few years ago.
I would rate this solution as nine out of 10.
We use it for basic firewalling, building VPN tunnels, and for some remote VPN connections.
We have two ASAs servicing external remote connectivity sessions for about 300 users.
It has definitely improved our organization. It gives us remote connectivity, helps workers connect remotely, and also gives us good connectivity to our other branches.
It would be nice if it had the client to actually access the firewall. Though, web-based access over HTTPS is actually a lot nicer than having to put on a client just to access the device.
For Firepower Threat Defense and ASAs, I would like it if there was a centralized way to manage policies, then sticking with the network functions on the actual devices. That is probably the thing that frustrates me the most. I want a way that you can manage multiple policies at several different locations, all at one site. You then don't have to worry about the connectivity piece, in case you are troubleshooting because connectivity is down.
I have been using ASA for about three years.
It is stable.
We just run updates on them. I don't know if we have had to do any hardware maintenance, which is good.
We have been just using ASAs for a smaller environment.
I don't know if I have ever worked with ASA in a highly scalable environment.
I haven't really gotten involved with the technical support for ASAs.
I work with a lot of different companies and a number of different firewalls. A lot of times it is really about the price point and their specific needs.
This solution was present when I showed up.
The pricing is pretty standard.
I wish there was an easier way to license the product in closed environments. I have worked in a number of closed environments, then it is a lot of head scratching. I know that we could put servers in these networks and that would help with the licensing. I have never been in a situation where we connected multiple networks, i.e., having an external network as well as an internal network, as those kinds of solutions are not always the best. I think licensing is always a headache for everyone, and I don't know if there is a simple solution.
We can build GRE tunnels. Whereas, Firepower can't route traffic nor do a bit more traffic engineering within the VPN tunnels. This is what I like about using ASAs over Firepower.
Firepower Threat Defense has a mode where you can manage multiple firewalls through a single device.
I really like how Palo Alto does a much better job separating the network functions from the firewalling functions.
I would consider if there is a need to centralize all the configurations. If you have many locations and want to centrally manage it, I would use the ASA to connect to a small number of occasions. As that grew, I would look for a solution where I could centrally manage the policies, then have a little more autonomous control over the networking piece of it.
Know specifically what you want out of the firewall. If you are looking for something that will build the GRE tunnel so you can route between different sites, I would go with ASA over Firepower Threat Defense.
I like the ASA. I would probably rate it as eight or nine out of 10, as far as the firewalls that I have worked with.
