We use it to protect our DMZs and externals, to protect our network from our other city partners who manage their own networks to which we have direct connections, like VPNs, and to manage the security parameters between inside and outside connectivity and vice versa.
System programmer 2 at a government with 10,001+ employees
Has versatile, flexible policies and packet captures that help debug connections
Pros and Cons
- "The features I've found most valuable are the packet captures and packet traces because they help me debug connections. I like the logs because they help me see what's going on."
- "Cisco Firepower NGFW Firewall was introduced as a migration of many firewalls into one."
- "I think they need to review their whole UI because it feels like it was created by a whole bunch of different teams of developers who didn't fully talk to each other. The net policy screen is just a mess. It should look like the firewall policy screen, and they should both act the same, but they don't. I feel like it's two different buildings or programming, who don't talk to each other, and that really annoys me."
What is our primary use case?
How has it helped my organization?
Cisco Firepower NGFW Firewall was introduced as a migration of many firewalls into one. Just having one firewall with one place of security and one place to look for your packets has really helped.
What is most valuable?
The features I've found most valuable are the packet captures and packet traces because they help me debug connections. I like the logs because they help me see what's going on.
The security correlation events and the network map help me to drill down on a host at will.
I really like the flexibility of the policies such as those you can use and the layer three policies with which you can block applications. It's really versatile. I like the security zones.
Cybersecurity resilience is our main focus right now. Because we're a government organization, everybody's really nervous about security and what the ramifications are. My device generates all the logs that our security team goes through and correlates all the events, so it's really important right now.
What needs improvement?
I think they need to review their whole UI because it feels like it was created by a whole bunch of different teams of developers who didn't fully talk to each other. The net policy screen is just a mess. It should look like the firewall policy screen, and they should both act the same, but they don't. I feel like it's two different buildings or programming, that don't talk to each other, and that really annoys me.
They should either build an application or get away from the web. They need to do something that's uniform and more streamlined.
We have a multi-person firewall team, and I can't look at a policy while somebody else is in it. It'll kick me out. I might be working on something that the other guy has to modify. I know that in the next versions they will be dealing with it with a soft lock, but it should've already been there.
One of Cisco's strengths is the knowledge depth of their staff. The solutions engineer we worked with knew the routing and each protocol. If he didn't know something, he would reach out to someone else at Cisco who did. He would even talk to a developer if he needed to.
Buyer's Guide
Cisco Secure Firewall
July 2026
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
905,526 professionals have used our research since 2012.
For how long have I used the solution?
I've been using Firepower for about three years.
What do I think about the stability of the solution?
There are some stability issues. We ran CheckPoint for years and didn't have problems with the firewall itself. However, with Firepower, in the past two years, we've had two major crashes and a software bug switchover.
We were debugging NAT rules. I did a show xlate for the NAT translation, and the firewall rebooted itself.
It has only been three instances in two years, but when I compare the stability to that of CheckPoint, it seems higher. CheckPoint just seemed to run.
What do I think about the scalability of the solution?
We have about 8000 end users. Scalability-wise, it's already handling a large amount of traffic.
How are customer service and support?
I like that Cisco's technical support will help me recover the firewall when everything falls apart. I'd give them a nine out of ten. They've really been consistently good, and they go after the problem.
Which solution did I use previously and why did I switch?
We previously used CheckPoint and Fortinet. We switched from CheckPoint because it was unsupported, and we wanted to move to a next-generation firewall.
We went to Fortinet, and when we switched over, it caused a huge network outage. The Cisco engineers helped fish us out of that. Our GM at the time preferred Cisco, and we switched to Cisco Firepower NGFW Firewall.
How was the initial setup?
Setting up the machines was straightforward, but exporting was complex. That is, it wasn't a complex deployment as far as the hardware goes. It was more of a complex deployment as far as transferring all the rules go because of our routing architecture.
Firepower is our main interface out to the outside world. We have about eight DMZs that are interface-based. You can do a logical DMZ or you can have an interface and a logical DMZ. We have about eight that are on interfaces. Then, we have our cloud providers and the firewall. We have rules so that our cloud providers can't ingress into our network.
I've found that Firepower does need a lot of maintenance. It needs a lot more software updates than other solutions. We have three people to maintain the solution.
What about the implementation team?
For the deployment, we had about 18 team members including firewall administrators, Cisco firewall engineers, and techs.
What's my experience with pricing, setup cost, and licensing?
The licensing scheme is completely confusing, and they need to streamline it. They have classic licensing and a new type of licensing now. Also, the licensing for the actual firewall is separate from the one for TAC support.
What other advice do I have?
My advice to leaders who want to build more resilience within their organizations is that they should help make policies. Leaders don't want to make policies; they don't want to put their names on policies or write policy documents. I as a firewall administrator am the one saying what the policy should be. I tell them what should happen, and sometimes, they resist.
Also, because the system is just too big to really manage without TAC, you would need TAC along with Firepower.
My advice would also be to go with HA or a cluster up front and not to be cheap. You really need to go in with a robust solution up front.
I would rate Firepower an eight on a scale from one to ten because the firewall and tech support together make it a very robust solution.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Engineer at a tech vendor with 5,001-10,000 employees
Provides us with a critical piece of our in-depth security stack
Pros and Cons
- "The Packet Tracer is a really good tool. If someone calls because they're having problems, you can easily create fake traffic without having to do an extended packet capture. You can see, straight away, if there's a firewall rule allowing that traffic in the direction you're trying to troubleshoot."
- "It's a great investment and there's a lot of value for your money if you're a CSO or a C-leader."
- "One of the challenges we've had with the Cisco ASA is the lack of a strong controller or central management console that is dependable and reliable all the time."
What is our primary use case?
We have the Cisco 5585-X in our data center for perimeter security, internet protection, and for applications behind Cisco ASA DMZs. The challenges we wanted to address were security and segregating the internal networks and the DMZs.
How has it helped my organization?
Security-wise, it's given us the protection that we were looking for. Obviously, we're using an in-depth type of design, but the Cisco ASA has been critical in that stack for security.
What is most valuable?
The Packet Tracer is a really good tool. If someone calls because they're having problems, you can easily create fake traffic without having to do an extended packet capture. You can see, straight away, if there's a firewall rule allowing that traffic in the direction you're trying to troubleshoot. As a troubleshooting tool, Packet Tracer is one of the things that I like. It comes up in all my interviews. When I want to figure out if someone knows how to use the ASA, I ask them about use cases when they use the Packet Tracer.
What needs improvement?
One of the challenges we've had with the Cisco ASA is the lack of a strong controller or central management console that is dependable and reliable all the time. There was a time I was using what I think was called CMC, a Cisco product that was supposed to manage other Cisco products, although not the ASA. It wasn't very stable.
The controller is probably the biggest differentiator and why people are choosing other products. I don't see any other reason.
For how long have I used the solution?
I've used the Cisco ASA going back to the 2014 or 2015 timeframe.
What do I think about the stability of the solution?
The ASA has been very stable for us. Since I deployed the ASA 5585 in our data center, we've not had to resolve anything and I don't even recall ever calling TAC for an issue. I can't complain about its stability as a product.
Our Cisco ASA deployment is an Active-Standby setup. That offers us resilience. We've never had a case where both of them have gone down. In fact, we have never even had the primary go down. We've mainly used that configuration when we're doing code upgrades or maintenance on the network so that we have full network connectivity. When we're working on the primary, we can switch over to the standby unit. That type of resiliency works well for our architecture.
How are customer service and support?
TAC is good, although we've had junior engineers who were not able to figure things out or fix things but, with escalations, we have eventually gotten to the right person. We also have the option to call our sales rep, but we have never used that option. It seems like things are working.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
In the old days, we used Check Point. We did an evaluation of the Cisco ASA and we liked it and we brought it on board.
At that time, it was easy for our junior operations engineers to learn about it because they were already familiar with Cisco's other products. It was easier to bring it in and fit it in without a lot of training. Also, the security features that we got were very good.
How was the initial setup?
The one we deployed in the data center was pretty straightforward. I also deployed the Cisco ASA for AnyConnect purposes and VPN. I didn't have to call TAC or any professional services. I did it myself.
What about the implementation team?
We used a Cisco reseller called LookingPoint. I would recommend them. We've done a lot of other projects with them as well.
What was our ROI?
It's a great investment and there's a lot of value for your money if you're a CSO or a C-leader. As an engineer, personally, I have seen it work great wonders for us. When we're doing code upgrades or other maintenance we are able to keep the business going 100 percent of the time. We have definitely seen return on our investment.
What's my experience with pricing, setup cost, and licensing?
I don't look at the pricing side of things, but from what I hear from people, it's a little pricey.
Which other solutions did I evaluate?
At the time, we looked at Juniper and at Palo Alto. We didn't get a feeling of confidence with Palo Alto. We didn't feel that it offered the visibility into traffic that we were looking for.
What other advice do I have?
We use Cisco AnyConnect and we've not had any issues with it. During COVID we had to scale up and buy licenses that supported the number of users we had, and we didn't have any problems with it.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Cisco Secure Firewall
July 2026
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
905,526 professionals have used our research since 2012.
Senior Network Engineer at a manufacturing company with 1,001-5,000 employees
The VPN solution works much better than our previous solutions
Pros and Cons
- "So far, it has been very stable."
- "So far, the remote VPN access has been a perfect solution for our company."
- "The user interface is a little clunky and difficult to work with. Some things aren't as easy as they should be."
What is our primary use case?
We are using it for border firewalls, VPN access, and site-to-site VPN tunnels.
It is deployed at a single location with about 2,500 users.
What is most valuable?
So far, the remote VPN access has been a perfect solution for our company.
What needs improvement?
The user interface is a little clunky and difficult to work with. Some things aren't as easy as they should be.
For how long have I used the solution?
I have been using it for five years.
What do I think about the stability of the solution?
So far, it has been very stable.
It does require maintenance. There is a team of two who manage it.
What do I think about the scalability of the solution?
We haven't scaled it much at this point.
How are customer service and support?
The technical support has been good so far. I would rate them as eight out of 10.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
The VPN solution works much better than our previous solutions.
We previously used Palo Alto. The switch was driven by Cisco's pitch.
How was the initial setup?
It was fairly straightforward. We stood it up side by side with our nesting firewalls. We did some testing during an outage window, then migrated it over.
What about the implementation team?
We used a partner, CDW, to help us with the deployment. Our experience with CDW was good.
Internally, it was just me for the deployment.
What's my experience with pricing, setup cost, and licensing?
The pricing seems fair. It is above average.
What other advice do I have?
Take the time to really learn it, then it becomes a lot easier to use.
I would rate the solution as eight out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior network security, engineer and architect at a computer software company with 5,001-10,000 employees
Decreased our downtime and enables us to get users connected faster and more easily
Pros and Cons
- "AnyConnect has been very helpful, along with the ability to use LDAP for authentication."
- "It has improved things greatly by giving us easier and better access, easier configuration, and allowing users to gain the access they need."
- "The ASAs are being replaced with the new Firepowers and they have a different type of structure in the configuration to be able to migrate from one to the other."
What is our primary use case?
We use it for VPN access for our two-factor authentication. We were looking to get access through AnyConnect, to gain access to devices behind boundaries and firewalls.
How has it helped my organization?
It has improved things greatly by giving us easier and better access, easier configuration, and allowing users to gain the access they need. We have also had less downtime using these firewalls.
What is most valuable?
AnyConnect has been very helpful, along with the ability to use LDAP for authentication. It's very robust and we are able to do many different things that we were looking to do.
What needs improvement?
The ASAs are being replaced with the new Firepowers and they have a different type of structure in the configuration to be able to migrate from one to the other.
For how long have I used the solution?
I have been using Cisco ASA Firewalls for 20 years.
What do I think about the stability of the solution?
The stability is very good. It has been a very stable environment. Since the new AnyConnect came out, it's been very easy to use and very much self-sufficient.
What do I think about the scalability of the solution?
You can vary scalability from very few users to thousands of users.
How are customer service and support?
Technical support has been very helpful at times, helping us to know what bugs and what things are getting fixed in the next releases.
How would you rate customer service and support?
Positive
How was the initial setup?
As an architecture team, we had a pretty good idea of what we wanted to do and how we wanted to do it, so it was pretty straightforward and easy. We have each one across many different avenues and many different boundaries, so each one took about a day to deploy.
We needed two to three people to deploy them and another one to go over some things to make sure everything was good to go.
There is routine maintenance, keeping it up to date and making sure the licensing versions are all good to go. We have a four-man team for maintenance and they work a regular shift of eight hours.
What about the implementation team?
We used a reseller, FedData. Our experience with them was good.
What was our ROI?
It took us about six months to see benefits from our ASA Firewalls. We've seen return on our investment in terms of the timeframe of downtime, and the ability to get users connected faster and more easily has been a big benefit.
What's my experience with pricing, setup cost, and licensing?
The pricing of the products isn't terrible. They're not too expensive. They're a little more expensive than other products, but you are getting the name, the company, and the support.
It's also nice that you can buy different avenues of licensing, depending on how you want to go about using them.
We buy a support license to get support if we have any issues or problems or need help on how we want to implement things.
Which other solutions did I evaluate?
We evaluated other options, but that was a long time ago. We went with Cisco because it is so robust as well as because they have been able to integrate their solutions into many different architectures. That makes their products easier to use.
What other advice do I have?
Each use case is different and things depend upon your cost analysis and how much you need. We have these firewalls in different avenues over about 30 different sites.
The biggest lesson from using the solution is being agile which has included learning to understand how to use the ASDM and figuring out how to configure everything—the little nuances—and what can and can't be done on the CLI.
These firewalls, along with the upcoming Firepower that they're being replaced by, are going to be very good assets for two-factor authentication and VPN access.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Network Architect at a tech services company with 10,001+ employees
A stable and secure solution that works well
Pros and Cons
- "Cisco tech is always good and helpful. I would rate them as 10 out of 10."
- "Our return on investment is having a network that we don't need to think too much about."
- "Cisco ASA is starting to get old and Firepower is taking over. All the good things happening are with Firepower."
What is our primary use case?
We are using it for security on everything from small customers to big data centers.
How has it helped my organization?
It is stable. We saw benefit from this in just a few days.
What is most valuable?
Cisco AnyConnect is my favorite. It is awesome. It also exists on Firepower and newer things.
What needs improvement?
Cisco ASA is starting to get old and Firepower is taking over. All the good things happening are with Firepower. Everything that I could wish for is in Firepower. We will probably not be doing too many new installations of ASAs since Firepower is mostly taking over.
For how long have I used the solution?
I have been using it for 15 to 20 years.
What do I think about the stability of the solution?
It is stable and secure. There are a few bugs, etc. Overall, we are very happy with it. We have never looked at anything else because it works so well. I would rate the stability as 10 out of 10. It is very good.
There is maintenance. We have to keep an eye out for software upgrades and forced changes to the configuration. We have a network operations team of 15 people who take care of these things from day to day.
What do I think about the scalability of the solution?
The solution's scalability is very good.
We use it on customers who have two employees up to customers with 5,000 employees. It is also used for customers who have one site or several sites. It is all over the place
How are customer service and support?
Cisco tech is always good and helpful. I would rate them as 10 out of 10.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I didn't use another solution previously.
How was the initial setup?
All our deployments have been different. Some have been really easy and others have been really complex. It could go either way: some are complex and some are easy. The complex solutions could take days or a couple of weeks to deploy. Easy solutions take a day.
If it was a big project, there would be a pre-project identifying what we were going to do and making a plan for it, then we would realize that plan. If it was a smaller thing, we would just jump into it.
What about the implementation team?
It was deployed in-house. Depending on the solution and its complexity, it could take a single person to a team of 20 people to deploy it.
What was our ROI?
Our return on investment is having a network that we don't need to think too much about. It works, and that is it.
What's my experience with pricing, setup cost, and licensing?
Cisco is always expensive, but you get what you pay for. It is expensive for a reason. It is a good solution, and good solutions cost money.
AnyConnect is an extra license. If you want the IDS/IPS things, those are usually extra too.
Which other solutions did I evaluate?
I evaluated Check Point, Palo Alto, and Fortinet, but Cisco won the race. Since we were already running most of our other networking with Cisco, it felt natural to land on Cisco.
What other advice do I have?
I would rate the solution as 10 out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Admin Network Engineer at Xcaret
Offers more security and flexibility for VPNs
Pros and Cons
- "It helped us a lot with our VPNs for the home office during COVID, and there has been more security and flexibility for VPNs and other applications."
- "I would like more features in conjunction with other solutions, like Fortinet."
What is our primary use case?
It is for our VPNs and filters out websites.
How has it helped my organization?
It helped us a lot with our VPNs for the home office during COVID. There has been more security and flexibility for VPNs and other applications.
What is most valuable?
Its security is easy to use.
What needs improvement?
I would like more features in conjunction with other solutions, like Fortinet.
For how long have I used the solution?
I have been using it for five years.
What do I think about the stability of the solution?
It has very good stability.
What do I think about the scalability of the solution?
It has really good scalability.
How are customer service and support?
The customer service and technical support are good. I would rate them as nine out of 10.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We were previously using Fortinet. We switched to ASA and Firepower when our contract with Fortinet ended. Now, we are only using ASA.
How was the initial setup?
The deployment was simple.
What was our ROI?
The ROI is good. Using ASA, we have saved 10% to 20% on our costs.
What's my experience with pricing, setup cost, and licensing?
The pricing is fine. It is not too bad.
What other advice do I have?
We had it integrated with the Umbrella solution a few years ago.
I would rate this solution as nine out of 10.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Engineer at a computer software company with 201-500 employees
Gives us remote connectivity and helps workers connect remotely
Pros and Cons
- "It has definitely improved our organization. It gives us remote connectivity, helps workers connect remotely, and also gives us good connectivity to our other branches."
- "I would like it if there was a centralized way to manage policies, then sticking with the network functions on the actual devices. That is probably the thing that frustrates me the most. I want a way that you can manage multiple policies at several different locations, all at one site. You then don't have to worry about the connectivity piece, in case you are troubleshooting because connectivity is down."
- "I would like it if there was a centralized way to manage policies, then sticking with the network functions on the actual devices."
What is our primary use case?
We use it for basic firewalling, building VPN tunnels, and for some remote VPN connections.
We have two ASAs servicing external remote connectivity sessions for about 300 users.
How has it helped my organization?
It has definitely improved our organization. It gives us remote connectivity, helps workers connect remotely, and also gives us good connectivity to our other branches.
What needs improvement?
It would be nice if it had the client to actually access the firewall. Though, web-based access over HTTPS is actually a lot nicer than having to put on a client just to access the device.
For Firepower Threat Defense and ASAs, I would like it if there was a centralized way to manage policies, then sticking with the network functions on the actual devices. That is probably the thing that frustrates me the most. I want a way that you can manage multiple policies at several different locations, all at one site. You then don't have to worry about the connectivity piece, in case you are troubleshooting because connectivity is down.
For how long have I used the solution?
I have been using ASA for about three years.
What do I think about the stability of the solution?
It is stable.
We just run updates on them. I don't know if we have had to do any hardware maintenance, which is good.
What do I think about the scalability of the solution?
We have been just using ASAs for a smaller environment.
I don't know if I have ever worked with ASA in a highly scalable environment.
How are customer service and support?
I haven't really gotten involved with the technical support for ASAs.
Which solution did I use previously and why did I switch?
I work with a lot of different companies and a number of different firewalls. A lot of times it is really about the price point and their specific needs.
This solution was present when I showed up.
What's my experience with pricing, setup cost, and licensing?
The pricing is pretty standard.
I wish there was an easier way to license the product in closed environments. I have worked in a number of closed environments, then it is a lot of head scratching. I know that we could put servers in these networks and that would help with the licensing. I have never been in a situation where we connected multiple networks, i.e., having an external network as well as an internal network, as those kinds of solutions are not always the best. I think licensing is always a headache for everyone, and I don't know if there is a simple solution.
Which other solutions did I evaluate?
We can build GRE tunnels. Whereas, Firepower can't route traffic nor do a bit more traffic engineering within the VPN tunnels. This is what I like about using ASAs over Firepower.
Firepower Threat Defense has a mode where you can manage multiple firewalls through a single device.
I really like how Palo Alto does a much better job separating the network functions from the firewalling functions.
I would consider if there is a need to centralize all the configurations. If you have many locations and want to centrally manage it, I would use the ASA to connect to a small number of occasions. As that grew, I would look for a solution where I could centrally manage the policies, then have a little more autonomous control over the networking piece of it.
What other advice do I have?
Know specifically what you want out of the firewall. If you are looking for something that will build the GRE tunnel so you can route between different sites, I would go with ASA over Firepower Threat Defense.
I like the ASA. I would probably rate it as eight or nine out of 10, as far as the firewalls that I have worked with.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Analytical Engineer at a pharma/biotech company with 10,001+ employees
Keeps away threats trying to come into my organization
Pros and Cons
- "With the pandemic, people began working from home. That was a pretty big move, having all our users working from a home. More capacity needed to be added to our remote VPN. ASA did this very well."
- "It did help my organization; the firewall pretty much covers most stuff, and with the pandemic and everyone working from home, ASA handled the increased remote VPN capacity very well."
- "It can be improved when it comes to monitoring. Today, the logs from the firewalls could be improved a bit more without integrating with other devices."
What is our primary use case?
We are using it for our VPN. We have a remote VPN and then a VPLS connection. Overall, it is a pretty big design.
We were looking for an opportunity to integrate our Firepower with Cisco ASA.
We mainly have these appliances on the data center side and in our headquarters.
How has it helped my organization?
It did help my organization. The firewall pretty much covers most stuff. They have next-gen firewalls as well, which have more threat analysis and stuff like that.
The firewall solution is really important, not just for our company, but for every organization. It keeps away threats trying to come into my organization.
With the pandemic, people began working from home. That was a pretty big move, having all our users working from a home. More capacity needed to be added to our remote VPN. ASA did this very well.
What is most valuable?
The most valuable features are the remote VPN and site-to-site VPN tunnels.
I use the solution to write policies and analyze the data coming in via the firewalls.
What needs improvement?
It can be improved when it comes to monitoring. Today, the logs from the firewalls could be improved a bit more without integrating with other devices.
I would like to see more identity awareness.
For how long have I used the solution?
I have been using it for over six years.
What do I think about the stability of the solution?
The stability is pretty good. They are keeping up the good work and making updates to the current platform.
How are customer service and support?
The support is good. They have been there every time that we need them. I would rate them as nine out of 10.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We have used Check Point and Palo Alto. We are still using those but for more internal stuff. For external use, we are using the Cisco client.
How was the initial setup?
The initial deployment was straightforward. We have worldwide data centers. For one data center, it took three days from design to implementation.
What about the implementation team?
It was a self-deployment. It took eight people to deploy.
What's my experience with pricing, setup cost, and licensing?
It was pretty good and not expensive on the subscription side. Cisco is doing a good job on this.
Which other solutions did I evaluate?
We also evaluated Zscaler, which is more cloud-based. It was pretty new and has a lack of support on the system side.
What other advice do I have?
They have been keeping up by adding more features to the next-gen and cooperating with other vendors.
I would rate this solution as nine out of 10. It is pretty good compared to its competitors. Cisco is doing well. They have kept up their old traditional routing and fiber policies while bringing on new next-gen features.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Engineer at Utah broadband
It is secure and very reliable
Pros and Cons
- "The TAC is always very helpful. We pay for Tier 1 support, so we get whatever we need from them. They always give us a solution. If they can't give us an answer that day, they get back to us within at least 24 hours with a solution or fix. I have never had a problem with the TAC. I would rate them as 10 out of 10."
- "We wanted to integrate Firepower with our solution, but it didn't have the capability to accommodate our bandwidth since they only had two 10 gig interfaces on the box. We run way more than that through our network because we are a service provider, providing Internet to our customers."
What is our primary use case?
We use it as a security solution. It is our firewall.
We run three data centers and have three ASAs at each data center.
What is most valuable?
It is pretty user-friendly and straightforward to use.
It is secure and very reliable.
I like the heartbeat between the two devices that we have. Because if something fails, it immediately fails over.
For how long have I used the solution?
I have been using ASAs for 15 years at two different companies.
What do I think about the stability of the solution?
Cybersecurity resilience has been outstanding because it is very stable. There are not a whole lot of upgrades that we need to do for the firmware.
Four engineers support it. From time to time, there are firmware upgrades that we need to keep up to date with. Sometimes, we need to run debugs to figure out what's going on with it, and if it needs a patch, then we will figure it out. Usually, Cisco has been really good about getting us that.
What do I think about the scalability of the solution?
Scalability is actually pretty exponential. In the grand scheme of things, we are a small network. We only have 15,000 subscribers. However, if we need to expand, it is reasonable.
How are customer service and support?
The TAC is always very helpful. We pay for Tier 1 support, so we get whatever we need from them. They always give us a solution. If they can't give us an answer that day, they get back to us within at least 24 hours with a solution or fix. I have never had a problem with the TAC. I would rate them as 10 out of 10.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We haven't really used anything different. The only thing that we run inline with Cisco ASAs is Barracuda Networks. We kind of run that in tandem with this firewall, and it works really well.
Which other solutions did I evaluate?
We wanted to integrate Firepower with our solution, but it didn't have the capability to accommodate our bandwidth since they only had two 10 gig interfaces on the box. We run way more than that through our network because we are a service provider, providing Internet to our customers.
What other advice do I have?
Do your homework and know what you are doing. Know how to use your product, stay current, and hire smart people.
I would rate the solution as eight out of 10.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cybersecurity Architect at a financial services firm with 5,001-10,000 employees
Provides our organization with a sense of security, reliability, and trustworthiness
Pros and Cons
- "The most valuable feature would be the IP blocking. It gets rid of things that you don't need in your environment."
- "Cybersecurity resilience has helped us be able to react and respond in a quick fashion to anything that may be happening or any anomalies within the environment."
- "The solution is overcomplicated in some senses. Simplifying it would be an improvement."
What is our primary use case?
It has been great for blocking incoming bad actors. The new Firepower modules have been a welcome additive to that.
How has it helped my organization?
Cybersecurity resilience has helped us be able to react and respond in a quick fashion to anything that may be happening or any anomalies within the environment.
The solution has provided us a sense of security, reliability, and trustworthiness.
What is most valuable?
The most valuable feature would be the IP blocking. It gets rid of things that you don't need in your environment.
Its resilience helps offer being able to react and self-heal.
What needs improvement?
The solution is overcomplicated in some senses. Simplifying it would be an improvement.
For how long have I used the solution?
I have used the ASA solutions for a better part of 10 years.
What do I think about the stability of the solution?
The stability is unparalleled.
All solutions require maintenance, and we do that routinely. Anywhere from three to four people from the network teams to application owners are involved in the maintenance. This is a firewall in production, so we need to do maintenances after hours, but it would be nice if we didn't need to do it after hours
What do I think about the scalability of the solution?
Scalability is unparalleled. It is easy to scale.
We don't have plans to increase our usage at this time.
How are customer service and support?
In previous years, Cisco's tech support has been great. Although, I have seen it declining. I would rate their support as seven out of 10.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We have used the Check Point firewalls as well as several different vendors.
What was our ROI?
It secures the network. The ROI is really incalculable at this point as keeping our data secure is keeping the company's assets secure.
Which other solutions did I evaluate?
We did evaluate other vendors.
What other advice do I have?
You need to be always looking ahead and proactively developing to build resilience.
I would rate the solution as eight out of 10. It is a world-class firewall.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Updated: July 2026
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
Sophos Firewall
Cisco Umbrella
Palo Alto Networks NG Firewalls
Cisco Identity Services Engine (ISE)
WatchGuard Firebox
Check Point Harmony SASE (formerly Perimeter 81)
Check Point Quantum Force (NGFW)
Cisco Meraki MX
Check Point Cloud Firewall (formerly CloudGuard Network Security)
Azure Firewall
Cisco Secure Network Analytics
Cisco Duo
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Is The Biggest Difference Between Cisco ASA And Fortinet FortiGate?
- Cisco Firepower vs. FortiGate
- How do I convince a client that the most expensive firewall is not necessarily the best?
- What are the biggest differences between Cisco Firepower NGFW and Fortinet FortiGate?
- What Is The Biggest Difference Between Cisco Firepower and Palo Alto?
- Would you recommend replacing Cisco ASA Firewall with Fortinet FortiGate FG 100F due to cost reasons?
- What are the main differences between Palo Alto and Cisco firewalls ?
- A recent reviewer wrote "Cisco firewalls can be difficult at first but once learned it's fine." Is that your experience?
- Which Cisco firewall model is the latest: ASA or NGFW?
- Which is better - Fortinet FortiGate or Cisco ASA Firewall?













