We are using Cisco Secure Firewall on the edge of the network in our enterprise. We use it as a firewall and as an IPS device to protect against threats and malware, URL filtering, phishing, access control, VPN terminator, and site-to-site tunnels. We use all these features provided by Cisco Secure Firewall. I have 1140 FTD Firewalls, specifically the 1140 FTD model.
Team Leader, Information Technology at a financial services firm with 11-50 employees
Advanced threat protection has increased network visibility and kept critical services always available
Pros and Cons
- "Cisco Secure Firewall increased my efficiency by above 90 percent."
What is our primary use case?
What is most valuable?
The most valuable feature I experience in Cisco Secure Firewall is in the IPS, along with the IPsec for IPsec tunneling with outside customers. I consider these specific features valuable to my organization because we have experienced and see the value for protection against malware and URL threats. We see there are a lot of attack attempts and ransomware, and we see how this device is very efficient.
We see the high availability feature in Cisco Secure Firewall. We have clustering nodes and we see how smooth the switching between the nodes is in case an incident occurs from the first node to the second node or the third node. So we see it offers high availability and redundancy to maintain the service up and running. All these features in Cisco Secure Firewall increase the efficiency level because it is very highly available, stable, and secure.
What needs improvement?
I wish to have a single management dashboard for Cisco Secure Firewall. There is no need to switch to the command line and into the management console, and I wish to reach this point to have one consolidated dashboard for all management requirements.
For how long have I used the solution?
I have hands-on experience with Cisco Secure Firewall for more than 20 years.
Buyer's Guide
Cisco Secure Firewall
July 2026
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
907,664 professionals have used our research since 2012.
What do I think about the stability of the solution?
My experience is very good with Cisco technologies in my current field. We have encountered stability and reliability, and we were very satisfied with this solution from the perspective of security and protection against any threats.
What do I think about the scalability of the solution?
Cisco Secure Firewall is scalable. If we make a design or sizing very well with consulting the Cisco engineer, or if we always return to the Cisco teams to provide us with Cisco Validated Designs, we will achieve the scalability part.
How are customer service and support?
I have used Cisco support when deploying Cisco Secure Firewall. Sometimes I need support, and we have a local partner supporting us, along with our own experience and references to the Cisco support cases and open cases with tech engineers. All these factors help us with deployment.
I would evaluate Cisco's customer support for Cisco Secure Firewall as near to 10. My experience with Cisco is above 22 years, and I have opened hundreds of cases with Cisco. The response time and the professionalism of the tech engineers are very helpful and efficient.
Which solution did I use previously and why did I switch?
Before implementing Cisco Secure Firewall, we were using another vendor for firewalls in the data center and on the edge, and we encountered issues with efficiency. Sometimes the dashboard or the datasheet is not accurate about the efficiency or the threshold for the throughput, and the datasheet regarding throughput is not accurate in some vendors. But we see that the datasheet for Cisco is near accurate.
How was the initial setup?
Deploying Cisco Secure Firewall is effective because it is advanced technology. It needs some experience, training, self-study, and support from the tech engineer side.
What was our ROI?
Cisco Secure Firewall increased my efficiency by above 90 percent.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing and licensing of Cisco Secure Firewall is that it is not too expensive. I think it is within the range of the market, and it is acceptable.
Which other solutions did I evaluate?
Before implementing Cisco Secure Firewall, I evaluated other vendors.
What other advice do I have?
I have visibility into the threats that I encounter. I recommend customers who have never experienced a Cisco device to check the POC with Cisco. I think they will be satisfied. I would rate this review as a 9 out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Feb 11, 2026
Flag as inappropriateNetwork Unit Head at a comms service provider with 501-1,000 employees
Edge security has protected critical services with strong intrusion prevention and URL filtering
Pros and Cons
- "Companies are always looking for security; if needing to have a secure firewall with high throughput and heavy-duty devices, we always have to choose Cisco devices because the reality of these devices may be better than any other vendor."
- "The only bad experience is that exporting and importing from one device is problematic."
What is our primary use case?
We are running Cisco Secure Firewall firewalls as edge devices. It is very good to have FTD, a device like FTD and FMC for management of the devices.
What is most valuable?
I am Ahmed from Palestine, working with a service provider company for mobile and landlines. Our company, Jawwal, is a service provider for Palestine with about 3,000 employees serving all people in Palestine. We used to have Cisco devices and also other vendors because our security team always asks to have multiple vendors in our company. We are very happy to have Cisco Secure Firewall devices. Our favorite features are that it is the next-generation firewall, always providing an IPS capability and multi-homing for multiple devices, clustering, and similar functionalities. We also appreciate FMC for management. It is a very good and very strong device to have in our company. We use it as edge firewalls for our company. We have three data centers spread all around the country. We always use Cisco and try to bring Cisco devices to our company because we always have something new.
Cisco Secure Firewall has many features, so the most important thing in the next-generation firewall is an IPS and URL filtering. It is a very good experience to have FTD for IPS and URL filtering.
My favorite feature inside the firewall is an IPS integrated with Threat Defense. I would like to highlight some protection. I would like to mention something about the intelligence for the firewall. We are very much looking forward to having AI included in the firewalls from Cisco, and I am looking to know how I can get benefits from AI inside Cisco Secure Firewall devices. We are always looking for improvement for the devices, and Cisco is always doing that. The most benefit for the firewalls in our company, regarding protection, intrusion prevention, and URL filtering, is a very good feature to have.
What needs improvement?
We faced some issues, though they are not very big issues in the device. When managing these devices from FMC, we have some tricky points for the device flexibility regarding upgrade from one FMC to another FMC and bringing the devices inside to be managed by this FMC. This also applies regarding the flexibility for having the data or the device when upgrading from one hardware to another hardware. To make it more easily to have this configuration from this device to another device would be beneficial.
When upgrading, Cisco always makes something called end of life for the hardware devices. When going from one device to another device, it is very hard to have this configuration exported from this device and put it in another device. This affects our service continuity, potentially causing some interruption for our service provider because we are running in a very critical environment. This may affect our user experience.
The only bad experience is that exporting and importing from one device is problematic. If trying to make a scalable device to increase capability for the device, it is very hard to export the configuration from this device to another device. We have to do it manually. This is a very bad experience, but other things are very good.
For how long have I used the solution?
We have been using this solution for more than seven years.
What do I think about the stability of the solution?
At IT, every time we may have something like this, but it is perhaps not related to the device itself. It depends on very wide other reasons. Sometimes, we have some downtimes because of something unknown, perhaps from the Linux kernel. Cisco engineers are always listening to us and contacting us for any improvement, which is why we love Cisco.
What do I think about the scalability of the solution?
In the network world, there is nothing straightforward. We always have obstacles on our way. Cisco is very good regarding availability and the stability for the device. When something happens in the device, the failover happens very quickly without any interruption. This is our experience with Cisco, and we are looking forward to having more and more. It is not straightforward because of the complexity of the network. As a device, it is straightforward, but because of the complexity of the other things, we can find it not hard, but a little bit complex. It is not related to the device itself.
How are customer service and support?
Cisco technical support is always doing a great job. While supporting us during our maintenance window for downtimes, it is very good. We are trying to have better support, and it is about financial issues because if going up with the support level, it becomes better and better. We need to make it more equitable.
How would you rate customer service and support?
Negative
Which other solutions did I evaluate?
Companies are always looking for security. If needing to have a secure firewall with high throughput and heavy-duty devices, we always have to choose Cisco devices because the reality of these devices may be better than any other vendor. Other vendors are very good also, but sometimes Cisco is more flexible than others.
What other advice do I have?
We have to use solutions such as IPS and IDS also. It is in detection and IPS for prevention also, but it is a different device, so it may have added layers for our network and making problems around that experience we have with it. It is not because of the device or the vendor, but layers in the network making some delays and making some overhead on the network. Cisco is the vendor we use. When comparing devices financially, we can see that other devices have very advanced features and other vendors have very good advantages. Cisco always wins. Maybe it is financially good because we have very high features and there are real advantages and features. Regarding throughput, some other vendors say it is fake throughput, not like Cisco. Cisco, when they say one gig, it is one gig.
We have many models such as 2000, 2003, and 4005. We have about eight devices spread around the company. I would give Cisco Secure Firewall a rating of eight out of ten because we are always looking for improvement. Cisco is very stable. From my experience, Cisco Secure Firewall is very stable. Because of the many integrations with the ICE and SGT, it is very nice to have these features. We always can see improvements on Cisco.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Feb 12, 2026
Flag as inappropriateBuyer's Guide
Cisco Secure Firewall
July 2026
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
907,664 professionals have used our research since 2012.
IT Infrastructure Manager at a real estate/law firm with 51-200 employees
Remote management has improved protection for offices and network segments
Pros and Cons
- "The experience of deployment with Cisco Secure Firewall is very easy."
- "I am uncertain about how the end users go to the network and also to the internet."
What is our primary use case?
My main use cases for Cisco Secure Firewall are ensuring that the offices and the users are protected behind a firewall and that the segments on the network are created.
What is most valuable?
The feature I like the most about Cisco Secure Firewall is the management of it because I can remotely manage everything that I need to do, not only the firewall but also the access points, the switches, and other devices. When they call me, I can fix something remotely without needing to drive over there.
It is typically all in one dashboard, but if I go to Cisco Secure Access and Connect, then it becomes a little bit confusing related to what products I need to use and buy.
What needs improvement?
I think the aspect that can be improved in Cisco Secure Firewall solution is the marketing approach. As I mentioned before, it confuses me related to the umbrella portals for secure access, not the SSE part of it.
I am uncertain about how the end users go to the network and also to the internet. What was previously done in Meraki Secure Connect is now referred to with the marketing term Secure Access, which is confusing to me. I don't know which license I need. I don't know if I'm going to be transitioned or not, or if I'm supposed to migrate myself. This is confusing because I need to be in different portals nowadays still, and I don't know what the future will bring.
Even when I'm at Cisco, I ask around but they say to ask my partner to transition me, but it doesn't seem to be that simple.
For how long have I used the solution?
I have been using Cisco Secure Firewall for two years.
What do I think about the stability of the solution?
I assess the stability and reliability of Cisco Secure Firewall solution as excellent. I don't have any crashes or downtime or anything like that, which is good.
Which solution did I use previously and why did I switch?
I have also used Sophos, specifically Sophos firewalls, before.
How was the initial setup?
The experience of deployment with Cisco Secure Firewall is very easy. I have been using Cisco Secure Firewall in the Meraki dashboard, which means I just need to connect them all and have my licenses ready. Deployment-wise, it is smooth and very straightforward.
What was our ROI?
I can say that it is always difficult to determine if I have seen a return on investment from having Cisco Secure Firewall solution. It is an insurance that I take, something I need to do, but I don't know if it has already prevented me from an attacker or anything like that.
What's my experience with pricing, setup cost, and licensing?
My experience with the pricing, setup cost, and licensing is that it is all good. The initial price is good. The only issue is if I don't renew my licenses after three or five years, my box becomes useless and I can't do anything with it anymore. I need to have an active license to make sure that I can use the product. I understand that if I'm using it in a production environment, I need the support and the licenses.
However, from a sustainable point of view, if I don't have a license, I can't do anything with it anymore, even not on my local home server installation. I think that is a pity. I have never had anything without licenses, but I can imagine if I don't have a license, then it becomes like a brick.
Which other solutions did I evaluate?
Before choosing Cisco Secure Firewall, I considered another solution, specifically Fortinet, and I considered Cato Cloud or Cato Networks, along with other OT vendors as well, such as Moxa or Teltonika.
What other advice do I have?
I chose Cisco first of all for the partner and then second of all for the pricing. The pricing was good enough to convince me to go ahead with Cisco because Cisco is a well-known brand all over the world, which I couldn't say from other OT vendors such as Moxa or Teltonika. That is why I chose Cisco.
I transitioned away from those systems with a hybrid approach. I still have small components on-site, but mostly everything is in the public cloud in Azure. Many SaaS services are also part of this.
In Azure, there is nothing for on-premises. There is nothing that the internal users are using. I have a website in AWS, but I am not using it actively, so it is outsourced.
I would give Cisco Secure Firewall more points if everything were all in one dashboard and they did not confuse me with marketing. Overall, I would rate this review an 8 out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Feb 11, 2026
Flag as inappropriateSenior Manager, Network Engineering at TTi Power Equipment
Unified policies streamline network management but complex licensing requires attention
Pros and Cons
- "Cisco Secure Firewall's ability to unify policies across our environment is pretty good."
- "Cisco Secure Firewall scales incredibly well with our growing needs."
- "Cisco Secure Firewall has some growth opportunities in terms of visibility and control capabilities regarding managing encrypted traffic."
- "My experience with pricing, setup costs, and licensing was a nightmare. It is indeed challenging as Cisco has too many variations of support with no clear explanation of what you are actually getting."
What is our primary use case?
Our main use cases include segmenting different networks for IPS and IDS, using it for basic firewall purposes, controlling ACLs, and monitoring traffic to identify issues within the network.
What is most valuable?
Currently, I find the event viewer feature of Cisco Secure Firewall very useful as it visually displays what is being blocked or allowed by the ACL. I also appreciate the improved visual presentation of the ACL layout.
We have many different opportunities to share incidents with individuals on how traffic flows through the network, and we utilize Cisco Secure Firewall features such as network packet inspection to ensure that policies are applied correctly and to monitor traffic for what is blocked, allowed, or denied.
Cisco Secure Firewall's ability to unify policies across our environment is pretty good.
We can deploy different features and ACLs between various firewalls easily with the FMC, which has improved significantly from the initial deployment time, which was once poor and is now manageable for multiple firewalls.
We use the new AnyConnect or Secure Connect VPNs, which works pretty well. Although we haven't switched to the latest series to utilize the VPNs fully, I appreciate the deployment phase where we can track our deployment progress.
What stands out positively about Cisco is their training and support, which has effectively prepared engineers to work with their products. When hiring, I find it beneficial that most network engineers are familiar with Cisco, whereas I might question the expertise of those trained with Palo Alto or Fortinet.
Performance-wise, Cisco seems to be the best. For instance, my sister company uses Palo Alto and Juniper and reports a high RMA rate. In contrast, we have only RMAed one Cisco Secure Firewall in six years, indicating stability and dependability.
The interface of Cisco Secure Firewall works effectively once you become familiar with its layout, although hiring engineers requires training on the platform, especially as updates occur. They should prioritize adding to the existing product rather than overcomplicating it with new features that may not be necessary.
What needs improvement?
Cisco Secure Firewall has some growth opportunities in terms of visibility and control capabilities regarding managing encrypted traffic. It has the ability to analyze encrypted traffic, and there is potential for more integration with APIs and AI to enhance these capabilities.
Cisco Secure Firewall needs improvement in deployment time and the capability to access the CLI during support calls. I often encounter issues when technical support uses a CLI that is not familiar to me while troubleshooting through the GUI.
My ongoing complaint for the last six years has been the lack of CLI functionality, which hinders my ability to work on the firewall, alongside concerns regarding deployment time.
For the next release, they should look at the features offered by competitors such as Fortinet, including the ability to perform packet capture directly from the interface.
If they enhanced their troubleshooting efficiency related to packet capture for each specific rule, it would simplify the process significantly.
For how long have I used the solution?
I have been using Cisco Secure Firewall for about six years.
What do I think about the stability of the solution?
The process of expanding the usage was fairly smooth. My assessment of the stability and reliability of Cisco Secure Firewall is great from a hardware perspective, yet only okay from a software perspective.
I have experienced downtime crashes and performance issues. Specifically, the FTDs have had High Availability (HA) issues, which I struggle to understand, especially concerning switch connections and HA setups between firewalls.
We have often encountered split-brain scenarios during failover processes and code upgrades, which have been persistent problems for us. It seems that Cisco lacks enough skilled technical support engineers to quickly resolve these issues, often requiring escalation that takes too long.
What do I think about the scalability of the solution?
Cisco Secure Firewall scales incredibly well with our growing needs. We recently transitioned to the new 4100s and we have only just reached the firewall's limitations after five years, indicating that it has been able to build for our future success.
How are customer service and support?
I would rate customer service and technical support about a five out of ten, sometimes dipping to a four depending on the time of day. As in many support models, the quality depends on the region. Some TAC engineers are better in specific areas, such as India or South America. However, they often lack the skills to troubleshoot effectively, leading to repetitive troubleshooting sessions and unresolved issues.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
Prior to adopting Cisco Secure Firewall, I used solutions such as SonicWall and Juniper firewalls. I didn't prefer Juniper and found Cisco Secure Firewall to be the most stable firewall I've worked with.
How was the initial setup?
The deployment time could be improved. The deployment was good, however, it could be sped up. There was a bit of a learning curve as well.
What works well is the interface. It's pretty good as far as knowing where to go and the layout. When hiring engineers, they need to know the platform. In terms of updates, sometimes they bolt on too much.
What was our ROI?
I have not seen ROI with Cisco Secure Firewall initially, however, over time, it has paid for itself as we scale our business.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup costs, and licensing was a nightmare. It is indeed challenging as Cisco has too many variations of support with no clear explanation of what you are actually getting.
Sales representatives try their best but often fall short, making it complicated for users to understand what licenses are included with the product, leading to confusion over various levels of support.
Which other solutions did I evaluate?
Before selecting Cisco Secure Firewall, I considered Fortinet and Palo Alto, and I even thought about sticking with ASAs. We still operate a couple of FTDs alongside ASAs, which creates internal competition. Fortinet, in particular, has remained a competitive option.
What other advice do I have?
We did not purchase this on the AWS Marketplace.
My advice to organizations considering Cisco Secure Firewall would be to recognize the tendency for Cisco to overcomplicate things. However, they are striving for simplification in their firewall products. If someone has experience with ASAs, they can adapt to FTDs as easily. Cisco should focus on learning from competitors to enhance its features and remain competitive in the market.
If you want a stable solution with fewer vulnerabilities, Cisco Secure Firewall is likely to meet your needs as it requires fewer upgrades compared to competitors.
On a scale of one to ten, I rate Cisco Secure Firewall a seven.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Account Manager at a tech vendor with 5,001-10,000 employees
Secure connectivity and custom threat detection have protected hybrid environments and user activity
Pros and Cons
- "I would say that the product is pretty much stable and the issue was our fault."
- "On the basic configurations and day-to-day tasks that we are having using this tool, it is much easier to use Palo Alto than Cisco Secure Firewall."
What is our primary use case?
I have two different perspectives about my use cases for Cisco Secure Firewall. The first one is the device frontier, creating all the connections between on-premise, cloud, on-premise to on-premise, VPNs, NAT and also rules for secure endpoints or user endpoints for downloading malicious files or visiting different websites.
The other use case was threat intelligence, which I mostly used Snort rules or created Snort rules on the firewall to understand or catch early attackers before they started the attack.
What is most valuable?
Snort is one of the features of Cisco Secure Firewall that I know is an open-source rule, but it is really cool that the firewall allows you to create your own rules using this protocol for threat intelligence.
The flow of Cisco Secure Firewall is something that I have a lot of experience creating policies with, but the way the policies work is unusual. For example, they are using every single policy that cascades between each other, and other vendors do not use that kind of flow. Other vendors allow you to create one rule for a specific thing without needing to iterate something from another policy. That is something I do not dislike, but it is hard to work with that kind of flow.
What needs improvement?
As I mentioned, Cisco Secure Firewall's flow is easier with Palo Alto to create things and configure things, also with the policies. But this vendor does not have the possibility for Snort, so I need to work with what the vendor gives to me and it is not really free to use. On the basic configurations and day-to-day tasks that we are having using this tool, it is much easier to use Palo Alto than Cisco Secure Firewall. Cisco has the feature that is Snort, but it is more easy to use Palo Alto in general.
Compared to the license of Cisco Secure Firewall, it was expensive. Right now compared with Palo Alto, Cisco Secure Firewall is kind of expensive. Basically, the license for the VPNs is for all the interfaces, and that is the thing that is really expensive compared with Palo Alto.
For how long have I used the solution?
I am not using Cisco Secure Firewall too much now because I left my previous company, but in previous companies I worked with Cisco Secure Firewall for four to five years.
What do I think about the stability of the solution?
There was basically one downtime with Cisco Secure Firewall that was for a DDoS attack. I think that it was due to a bad configuration from our side. Without those configurations, there were no issues. I would say that the product is pretty much stable and the issue was our fault.
What do I think about the scalability of the solution?
Cisco Secure Firewall is scalable, but if you have the money for the license, then it is scalable.
How are customer service and support?
I have had to contact Cisco technical support two times. One time was to integrate the firewall with the WLC, Wireless LAN controller, for wireless issues, and the other time was for the license that was not activated due to something that happened with the payments.
The first case on the WLC for Cisco Secure Firewall was not very good because it took more than one week with the first call and emails back and forth to resolve the issue. The answers from the technical assistance center gave me the sense that they did not really know what we needed to do or what we needed for escalations. On the other hand, for the payment issues for the license, that team was really clear and resolved the issue in less than 12 hours.
With my experience with those two support cases, I would rate Cisco technical support a seven on a scale from one to ten.
Which solution did I use previously and why did I switch?
I have experience with Cisco in two parts. I worked with Cisco as the SM for one of the companies in Colombia, and I have also worked with other customers that use Cisco. I have been on both sides.
How was the initial setup?
There are two ways for the initial deployment of Cisco Secure Firewall. We have the on-premise device, when I was working in that company, and we also deployed one of the solutions for Threat Defense on Azure. I think that it is easier for on-premise because you have direct connections, and if something happens troubleshooting all the initial IPs is better that way. It is pretty smooth to update it or create that firewall on Azure. On AWS, it is easy. They have some troubles with the Linux instance, but on Azure, it is pretty smooth.
What about the implementation team?
Cisco Secure Firewall is all about taking care for Cisco right now. Previously it was not, but right now it is.
What's my experience with pricing, setup cost, and licensing?
Compared to the license of Cisco Secure Firewall, it was expensive. Right now compared with Palo Alto, Cisco Secure Firewall is kind of expensive. Basically, the license for the VPNs is for all the interfaces, and that is the thing that is really expensive compared with Palo Alto.
Which other solutions did I evaluate?
I have used Fortinet and Palo Alto as alternatives to Cisco Secure Firewall.
It is hard to say, but right now I have been working with Palo Alto. That is currently my best option and I learned a lot from this vendor compared to Cisco Secure Firewall.
What other advice do I have?
I have experience with Cisco in two parts. I worked with Cisco as the SM for one of the companies in Colombia, and I have also worked with other customers that use Cisco. I have been on both sides.
The last time with Cisco I was a partner.
My overall review rating for Cisco Secure Firewall is nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: May 26, 2026
Flag as inappropriateChief Technology Officer at Binary Global Limited
Comprehensive security has unified policy control and supports zero trust across clouds
Pros and Cons
- "From Cisco Secure Firewall's security offering perspective, Cisco has a very comprehensive offering."
- "Every on-premise model has a limit to the throughput it can support, and up to that limit, it scales fine."
What is our primary use case?
Cisco Secure Firewall can be used for perimeter security, IDS, IPS, and VPN purposes. When discussing secure access via Cisco Secure Firewall, it helps any roaming user, whether working from home, an airport, or in the office, to securely access any workload that could be located on a private cloud, public cloud, data center, or at the edge. It bypasses the on-premise firewall, but they offer firewall as a service, which is on the cloud and enables Secure Service Edge. Perimeter security is necessary and is part of their Secure Access offering, which is Firewall as a Service coming out of the cloud.
What is most valuable?
From Cisco Secure Firewall's security offering perspective, Cisco has a very comprehensive offering. Whether it is perimeter security in the form of firewall, user security for remote users for SASE, AI security, endpoint security, network security, or workload security, this fits very well into an overall security architecture proposed by Cisco, which is called a Security Reference Architecture. They have a very comprehensive range of products that integrate very well with their firewall. I do not view Cisco security offerings only from a firewall perspective, but from an overall offering perspective.
Cisco Secure Firewall includes something called Secure Cloud Control, which provides single management for consolidating policy across multiple pieces of equipment, whether it is a SASE policy, firewall policy, or otherwise. Centralized policy management is possible within that firewall, and if you want to orchestrate the same policy across multiple security products, you can use Cisco Secure Cloud Control.
What needs improvement?
Different models exist for Cisco Secure Firewall. Every on-premise model has a limit to the throughput it can support, and up to that limit, it scales fine. After reaching that limit, you are supposed to replace the model. For on-premise solutions, this is the case. However, Firewall as a Service can scale to a very large extent because it is a cloud-based offering that can scale up to a very large number, which is not a problem.
For how long have I used the solution?
Cisco Secure Firewall has been used and sold for at least three to four years.
What do I think about the stability of the solution?
Cisco Secure Firewall is quite stable. If I had to rate stability from zero to ten points for Cisco Secure Firewall, I would give it an eight.
What do I think about the scalability of the solution?
Cloud-delivered firewall provides much better flexibility for an organization via Cisco Secure Firewall. First, you can ensure that any users coming from outside securely access any workload that the organization may be running either in a private cloud or public cloud on a hyperscaler. Second, it provides what is called local internet breakout, where any services not supposed to go through the firewall can do a local internet breakout. With Firewall as a Service, you can consume capacity as you grow, rather than trying to put one firewall for your peak load. This gives tremendous flexibility similar to the flexibility that exists in cloud consumption.
How are customer service and support?
If I had to give points for technical support from Cisco, I would give it an eight. It is pretty good, and we do not face a challenge. The reason is that our own team is pretty capable technically, so we do not go back to Cisco for much support. Whenever we have requested support, they have been pretty responsive.
How would you rate customer service and support?
Positive
What other advice do I have?
I do not view Cisco security offerings only from a firewall perspective, but from an overall offering perspective. Cisco Secure Firewall helps with the Zero Trust Security Model. ZTNA is a concept that has to be implemented at every tier, including the firewall. You cannot implement zero trust without a firewall also supporting it. It is an important piece in building a zero trust architecture. The review rating for this product is an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Last updated: Feb 24, 2026
Flag as inappropriateManager, Information Technology at Cairo Amman Bank
Network protection has controlled web access and prevented threats for sensitive departments
Pros and Cons
- "Cisco Secure Firewall is one of the best and most stable solutions I have encountered, with no crashes and a powerful, stable system that shows no degradation in performance."
- "I find deploying Cisco Secure Firewall to be a little bit challenging, but once it is implemented on our network, it is stable with no problems or issues."
What is our primary use case?
Cisco Secure Firewall is used to protect our edge network. We use site-to-site VPNs, VPN clients, and benefit from Next-Generation Firewall features including threat prevention, URL filtering, and application control.
What is most valuable?
I appreciate all of the features of Cisco Secure Firewall, but the most important ones are the URL filtering feature that gives control over what users try to browse or reach on the internet, along with the threat prevention that inspects all traffic going out of and incoming to our network, making them very powerful features.
For example, I want to restrict a group of employees from my area in a very secure department that is not allowed to reach the internet or browse any websites that might be malicious or harmful to our network. By applying URL filtering, I can restrict their access to only the allowed websites according to our policy, allowing them to use certain websites related to their work while restricting them from reaching other harmful websites.
What needs improvement?
With everyone discussing AI and threat intelligence, security is advancing further. In addition to the features we have, we might consider threat intelligence that uses AI for more investigation and analytics on malicious codes or access. If Cisco integrates Cisco Secure Firewall with the cloud using AI, which I am sure they are working on, that would be beneficial for customers.
For how long have I used the solution?
The first Cisco firewall I used was the ASA back in 2008, which was a long time ago.
What do I think about the stability of the solution?
Cisco Secure Firewall is one of the best and most stable solutions I have encountered, with no crashes and a powerful, stable system that shows no degradation in performance.
What do I think about the scalability of the solution?
So far, we have not had other sites to expand, but I am confident that with the current design and features from Cisco, it will be easily expandable. If I decide to put another firewall in a DR site or any HA site, it is simply an HA configuration that will integrate smoothly with the current firewall we have.
How are customer service and support?
The Cisco team is a wonderful team, always helpful and ready to assist us anytime. Our local vendors and the Cisco TAC team provide support wherever we are and whenever we need it. I would rate the Cisco team a ten because they are very responsive and solve our issues. I have never been stuck on any cases, although some may take time depending on their complexity, but they are wonderful.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have used firewalls including the Forcepoint firewall, which I found to be good, but it was complex in terms of user management, and my team suffered from the complexity of managing this firewall. I have also used FortiGate firewalls and Palo Alto firewalls.
All the mentioned products are Next-Generation Firewalls with similar features, but the main difference lies in how we use these features. The simplicity of using these features is the key point. The URL filtering and threat prevention features in Cisco Secure Firewall are very nice, simple, and easy to configure and apply to our network.
How was the initial setup?
I find deploying Cisco Secure Firewall to be a little bit challenging, but once it is implemented on our network, it is stable with no problems or issues. It is not that complex, and if we know our network, the Cisco team is helpful in guiding us to achieve the best design and implementation.
What's my experience with pricing, setup cost, and licensing?
Cisco is not a cheap product, but when discussing an excellent product, we should not expect it to be that cheap. We normally have agreements and get discounts because we have been a Cisco customer for a long time, so the prices are reasonable.
What other advice do I have?
My advice to other companies considering Cisco Secure Firewall is to assess your network thoroughly and understand your security needs very well. I am confident that if you choose Cisco Secure Firewall from a technical point of view, it will meet all your requirements, and I highly recommend using it. I rate Cisco Secure Firewall a nine out of ten because I am expecting more from Cisco, and I am sure next time they will reach a ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Feb 12, 2026
Flag as inappropriateManager, Network & Security at a financial services firm with 10,001+ employees
Firewall has streamlined policy cleanup and supports strict financial security audits
Pros and Cons
- "Cisco Secure Firewall helps our company overall because the firewall provides substantial capability when it comes to throughput, the number of policies, and the number of records."
- "Whenever we open a case, for example a P1 (severity one) case, an L2 engineer initially takes time to understand the requirement, then the engineer mentions that their shift is going to finish and hands over to a new engineer, who takes additional time to get up to speed."
What is our primary use case?
Cisco Secure Firewall's use case in our organization is justified because we operate in the financial industry where security best practices require multi-vendor products. We are running other vendors' solutions as well, and since Cisco is a prominent and one of the best vendors in the market, we opted for Cisco Secure Firewall. Both solutions serve our security requirements effectively.
What is most valuable?
The most valuable feature of Cisco Secure Firewall is the policy cleanup functionality. In the firewall, we have hundreds of policies deployed, and we often face a challenge regarding what to do with unused policies and how to remove them without impacting required access. Cisco Secure Firewall helps us identify the unused policies efficiently, and we are confident to remove them without any negative impact.
Cisco Secure Firewall helps our company overall because the firewall provides substantial capability when it comes to throughput, the number of policies, and the number of records. However, whenever traffic comes into the network, it must pass through all the policies and match the required ones, which takes considerable time. This solution helps us streamline our processes, streamline our information security requirements, and streamline our audit requirements to achieve our goals.
What needs improvement?
From the improvement perspective, I would identify automation as a key area. Whenever a requirement comes and needs to be deployed, there are individual rules to configure. When it comes to CLI, it was easy to create a script and copy-paste, but the GUI approach takes considerable time. Built-in automation would help significantly. Although there are options in the market such as Terraform or Ansible Tower with possible integration, having something built directly into Cisco Secure Firewall would be more beneficial.
For how long have I used the solution?
I have been using Cisco Secure Firewall for a couple of years.
What do I think about the stability of the solution?
Cisco Secure Firewall is quite stable. While I experienced some issues when it was new in the market, the solution is stable now.
We are running other solutions as well, but being in the financial industry, we run multiple vendors and multiple firewalls. When I compare this solution with others, Cisco Secure Firewall is quite stable.
What do I think about the scalability of the solution?
Cisco Secure Firewall is scalable and provides the required functionality and scalability from a throughput perspective and from a bandwidth perspective.
How are customer service and support?
Regarding my experience with Cisco support for firewalls, we are using TAC support and partner support from Cisco. The experience is generally fine, but there is one area where we consistently face problems. Whenever we open a case, for example a P1 (severity one) case, an L2 engineer initially takes time to understand the requirement. Then the engineer mentions that their shift is going to finish and hands over to a new engineer, who takes additional time to get up to speed. This approach is not workable in our environment, especially in banking, where uptime is critical. This area requires improvement.
How would you rate customer service and support?
What other advice do I have?
From the pricing and licensing perspective for Cisco Secure Firewall, we have multiple licenses covering threat intelligence, antivirus, and other security functionalities, and these come within the offering. This is satisfactory from that perspective. My overall review rating for Cisco Secure Firewall is 8 out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Feb 11, 2026
Flag as inappropriateHead Of Information Security Section at Bank of Palestine PLC
Edge protection has provided strong layered defense and secure tunneling with flexible addressing
Pros and Cons
- "They bring great value for the price because they provide excellent support, have stability, and we trust this product."
- "My experience with deploying Cisco Secure Firewall is that it is complicated, but if you have the experience, you can deploy it smoothly."
What is our primary use case?
Cisco Secure Firewall's main use case is the edge firewall, which has great IPS and IDS capabilities, providing a solid defense layer for the organization.
What is most valuable?
I really appreciate the NAT-ting feature of Cisco Secure Firewall the most.
The main benefit of the NAT-ting feature in Cisco Secure Firewall is that when I establish a site-to-site tunnel with another endpoint from another company, I can provide them with a fake IP instead of the real IP.
Cisco Secure Firewall benefits our organization by serving as the first defense layer, which is the edge firewall as I mentioned before, helping to prevent DDoS attacks and similar threats.
What needs improvement?
I think Cisco Secure Firewall could become even better overall, but as of now, it is already in a stable status, and I do not see any significant features that need immediate attention. Perhaps something will come up in the future.
What do I think about the stability of the solution?
Cisco Secure Firewall is a stable and reliable product.
Cisco Secure Firewall remains stable because even if there are bugs, Cisco TAC engineers are consistently working to find solutions on the spot.
I am not experiencing any downtime with Cisco Secure Firewall.
There are bugs in Cisco Secure Firewall, but as I mentioned, the TAC engineers are actively working to resolve issues as quickly as possible, so the downtime is only for a short period.
I have experienced bugs with Cisco Secure Firewall, such as a sudden reboot, for example, but they resolved it on the spot.
What do I think about the scalability of the solution?
Cisco Secure Firewall scales with the growing needs of an organization and has scalability.
Cisco Secure Firewall definitely demonstrates scalability, though I cannot explain it exactly.
How are customer service and support?
I find that customer support from Cisco is good, as the TAC engineers are available all the time.
If I could rate Cisco Secure Firewall's support on a scale from one to ten, I would give it a ten.
How would you rate customer service and support?
Positive
How was the initial setup?
The deployment model for Cisco Secure Firewall is on-premises.
My experience with deploying Cisco Secure Firewall is that it is complicated, but if you have the experience, you can deploy it smoothly.
There is a high learning curve for the deployment of Cisco Secure Firewall.
What was our ROI?
I have seen ROI with Cisco Secure Firewall, as they definitely save time and provide peace of mind.
Cisco Secure Firewall saves time and also saves money, definitely providing peace of mind.
What other advice do I have?
My impression of the pricing and licensing of Cisco Secure Firewall is that it is not the normal pricing; it is high, but they deserve it.
They bring great value for the price because they provide excellent support, have stability, and we trust this product.
I would rate Cisco Secure Firewall a nine on a scale from one to ten. I rate it a nine because there is one point regarding the bugs that the versions of Cisco in general have.
My advice to other organizations considering Cisco Secure Firewall is to ensure that customers receive guidance from TAC engineers regarding bugs and workarounds when they are published. It is crucial to expedite the process of finding bugs before deploying new versions.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Feb 12, 2026
Flag as inappropriateNetwork Architect And Security at a tech vendor with 10,001+ employees
Centralized security has unified governance across campuses and data centers while simplifying rules
Pros and Cons
- "I think in general, Cisco Secure Firewall is a really great product, and we will just go with the flow."
- "To improve Cisco Secure Firewall product, we have a TAC case open for that, but I would prioritize responsiveness for sure, as UX/UI is always something to work on."
What is our primary use case?
The use case at my company is to secure our campus and our different data centers.
What is most valuable?
My most valuable feature of Cisco Secure Firewall is that I can see what is where, which rules are applied where, and create templates. In general, it's a good feature for us.
Having Cisco Secure Firewall has definitely helped our organization because we are a German company that follows rules, so we have governance. We need to deploy the same type of governance everywhere, and it's much easier to deploy this way, even with some country-to-country differences.
What needs improvement?
To improve Cisco Secure Firewall product, we have a TAC case open for that, but I would prioritize responsiveness for sure, as UX/UI is always something to work on. We have complaints from our NOC people, but they are always complaining.
For how long have I used the solution?
I have been using Cisco Secure Firewall at my company for a year.
What do I think about the stability of the solution?
When it comes to reliability with Cisco Secure Firewall, it's not necessarily about downtime; it's about reliability in updates. We want something that can be updated easily and reliably. When we push an update, we don't want it to crash, of course, and we want to be sure that we are up in the security game. This is one of the main reasons I'm here, as everything security-related is quite important to us. We mostly have on-premises devices and our own data centers, so it's crucial that the tools we buy are reliable.
What do I think about the scalability of the solution?
I find Cisco Secure Firewall to be pretty easy to scale, and I was in a meeting this week with Cisco insiders who said it's going to be even easier in the future.
They're going to provide us with AI now for Cisco Secure Firewall, and we will just be able to chat while everything does itself.
How are customer service and support?
Regarding customer support, I had a meeting yesterday with them for Cisco Secure Firewall. We are a very large company, so we open TAC cases quite often because we have more than 200 people working in security at my company. We find problems all the time, and most of the time it's quite responsive. However, one of the reasons we come to Cisco Live is to meet face-to-face with the engineers and their managers to ask why a particular TAC case hasn't moved for the last couple of months, and we want answers. We're not afraid to say when it's bad, but we also recognize when it's good. We want answers. If you don't want to tell us why, tell us why you don't want to tell us why. Generally, we have a very good relationship with Cisco.
On a scale of one to ten, I would rate the support for Cisco Secure Firewall a nine, even if sometimes we have some bumps. I understand the effort all the support team needs to provide to reach this level. Living in Warsaw, I have seen the Krakow office grow, and I believe it's a fantastic development for Poland to have so many people there. I hope Cisco continues investing there.
Which solution did I use previously and why did I switch?
I believe we were using another product before Cisco Secure Firewall, but I don't have the detailed answer. I work at digital department, where we provide all IT and IT infrastructure for the company, so it's quite a large environment with 2,000 people in the networking team globally. I don't know what everyone is doing, even if I should probably know.
Which other solutions did I evaluate?
Evaluating other solutions is becoming my job now, and I'm focusing on three main topics: creating the lab for the networkers at my company, evaluating the monitoring capabilities for the networkers, and looking into AI tools for our networking team. I know some of my colleagues in architecture are also evaluating tools more in detail, ranging from SD-WAN to firewall to switching. We have many solutions here in Cisco, and we are all communicating to share opinions, even if it's not our core role to have answers. It's a good thing.
What other advice do I have?
This new AI functionality will definitely help our company operate more efficiently for the SOC team, especially concerning deploying different rules and rule sets. This year, when we faced problems with the geopolitical environment, our company decided to enforce policies on some countries, and instead of reviewing hundreds of thousands of IP addresses manually, we could just do five clicks to shut off a whole part of Ukraine very easily. It's a life-saver sometimes.
I think in general, Cisco Secure Firewall is a really great product, and we will just go with the flow. AI is probably something that we need to go with, but let's not implement AI everywhere for the sake of it. Let's ensure it's useful, and I believe it has its utility there as well.
I don't think there is anything competing on the market at the moment. There is nothing competing on the market, so I have given Cisco Secure Firewall an overall rating of ten. I appreciate your understanding; when I mention integers, I know that engineers will understand exactly what I'm talking about.
Concerning the pricing and licensing of Cisco Secure Firewall, that's not really my part. My focus is on the product itself — how good it is, how it competes, and how well it fits our needs. I do ask about pricing, but that ultimately goes to board management for negotiating directly with Cisco. I have an overview of the pricing, of course, and I can share with my management what the pricing is versus competitors. We often see significant disparities, but most of the time there are valid reasons with Cisco.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Feb 16, 2026
Flag as inappropriateBuyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Updated: July 2026
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
Sophos Firewall
Cisco Umbrella
Palo Alto Networks NG Firewalls
WatchGuard Firebox
Cisco Identity Services Engine (ISE)
Check Point Harmony SASE (formerly Perimeter 81)
Check Point Quantum Force (NGFW)
Cisco Meraki MX
Check Point Cloud Firewall (formerly CloudGuard Network Security)
Azure Firewall
Cisco Secure Email
Cisco Duo
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Is The Biggest Difference Between Cisco ASA And Fortinet FortiGate?
- Cisco Firepower vs. FortiGate
- How do I convince a client that the most expensive firewall is not necessarily the best?
- What are the biggest differences between Cisco Firepower NGFW and Fortinet FortiGate?
- What Is The Biggest Difference Between Cisco Firepower and Palo Alto?
- Would you recommend replacing Cisco ASA Firewall with Fortinet FortiGate FG 100F due to cost reasons?
- What are the main differences between Palo Alto and Cisco firewalls ?
- A recent reviewer wrote "Cisco firewalls can be difficult at first but once learned it's fine." Is that your experience?
- Which Cisco firewall model is the latest: ASA or NGFW?
- Which is better - Fortinet FortiGate or Cisco ASA Firewall?















