In our organization, we are using it as an internal firewall.
Jr. Engineer at a computer software company with 5,001-10,000 employees
User-friendly, easy to install with updates available online, and good support
Pros and Cons
- "The interface is user-friendly."
- "The cost is very high. Most organizations cannot afford it."
What is our primary use case?
What is most valuable?
It is already improved because all of the computer updates are available online. So, you can update, and I think that the ASA 5585 is already updated.
All of the licensing features can be upgrades.
The interface is user-friendly.
What needs improvement?
The cost is very high. Most organizations cannot afford it.
For how long have I used the solution?
We have been using the latest version of this solution for the last five years.
Buyer's Guide
Cisco Secure Firewall
December 2025
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,422 professionals have used our research since 2012.
What do I think about the stability of the solution?
It's a stable product.
What do I think about the scalability of the solution?
It's a scalable solution. We have more than 2000 users in our organization.
How are customer service and support?
Technical support is fine, we have no issues.
How was the initial setup?
The initial setup was very easy. Cisco documentation is online, so it was no problem at all.
It took approximately 30 minutes to install.
What's my experience with pricing, setup cost, and licensing?
If we compare it with FortiGate and the co-existing ASA, FortiGate is better in terms of price.
What other advice do I have?
This is a product that I can recommend to others.
I would rate this solution a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Group Information Technology Manager at a mining and metals company with 201-500 employees
Provides great VPN and firewall features; very stable
Pros and Cons
- "VPN and firewall are good features."
- "Lacks a good graphical user interface."
What is our primary use case?
I'm the group information technology manager and we are customers of Cisco.
What is most valuable?
The best feature for me is the VPN and I also like the firewall.
What needs improvement?
In terms of improvement, we'd like to see a good graphical user interface. I'd also like to see the initial setup simplified. In comparison, if I were to implement the Fortigate firewall from scratch, it's a fairly simple set up. That is not the case with the ASA firewall, where you really need to have the skill and know what you're doing.
For how long have I used the solution?
I've been using this solution for 18 years.
What do I think about the stability of the solution?
The solution is stable, we haven't had any issues. If we need something, we go to a consultant. In terms of product stability, it works very well.
What do I think about the scalability of the solution?
We haven't made any changes since implementing and we haven't tried scaling.
How are customer service and technical support?
We get our support from the resellers, not from Cisco.
What other advice do I have?
For those who have the technical know-how with Cisco products, I would recommend going with the ASA firewall, but if you're new to the field and running a smaller business, deployment will be complicated.
I would rate this solution a nine out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Cisco Secure Firewall
December 2025
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,422 professionals have used our research since 2012.
Network Security Presales Engineer at a tech services company with 51-200 employees
Good throughput, with one-of-a-kind support, that is scalable
Pros and Cons
- "The most valuable features of this solution are the integrations and IPS throughput."
- "The price and SD-WAN capabilities are the areas that need improvement."
What is our primary use case?
I am a pre-sales engineer, and I do comparisons based on my customer's requests.
What is most valuable?
The most valuable features of this solution are the integrations and IPS throughput.
What needs improvement?
The price and SD-WAN capabilities are the areas that need improvement.
In the next release, I would like to see more of the FortiGate features added. FortiGate is compatible with Cisco ACI, but I can't see Firepower with Security Fabric. For example, if I had Fortinet activated, could I integrate with it?
For how long have I used the solution?
I have familiar with the Next Generation firewalls for two years, and six years with firewalls in general.
What do I think about the stability of the solution?
It's a stable product.
What do I think about the scalability of the solution?
It's scalable indeed.
Our clients are SMB Enterprise.
How are customer service and technical support?
It's just a fact, nothing is better than Cisco technical support.
Which solution did I use previously and why did I switch?
Previously, I was working with Fortinet. I would most likely recommend Fortinet, because of the price and the security fabric integration with other products. It's scalable as well, and all of the FortiGate features are useful.
It's very easy to implement and it's very easy to administrate.
How was the initial setup?
The initial setup was straightforward. With other vendors, it is easier, but it was straightforward.
What's my experience with pricing, setup cost, and licensing?
This product is expensive.
What other advice do I have?
I would rate this solution an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer.
ICT Systems Engineer at a insurance company with 11-50 employees
Pretty stable, but it needs better reporting tools and improvements to the user interface
Pros and Cons
- "This product is pretty stable."
- "I would like the ability to drill down into certain reports because currently, that cannot be done."
What is our primary use case?
The number one use for this product is security.
What needs improvement?
The management of the application can be improved with enhancements to the user interface.
I would like the ability to drill down into certain reports because currently, that cannot be done. In fact, this is one of the reasons that we want to move away from Cisco. Better reporting tools would be an improvement.
For how long have I used the solution?
We have been using Cisco ASA for approximately seven years.
What do I think about the stability of the solution?
This product is pretty stable.
What do I think about the scalability of the solution?
Our current model is reaching its end of life, so it's not very scalable at the moment. We don't plan to increase usage.
It is currently providing protection for about 30 users.
How are customer service and technical support?
The technical support is with our solution provider. I would say that it's average, rather than very good.
How was the initial setup?
The initial setup is complex. I would say that it took a maximum of a week to deploy.
What about the implementation team?
We had a service provider who took care of the installation for us.
What's my experience with pricing, setup cost, and licensing?
This is an expensive product. We pay about €2,000 ($2,400 USD) per year for licensing.
Technical support is in addition to the standard licensing fees.
What other advice do I have?
At this point, Cisco ASA is not a product that I recommend. My advice is that people should look at other solutions because there are other products available on the market that are just as good, if not even better.
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Executive Director at a tech services company with 51-200 employees
Good at blocking threats and pretty reliable but needs a better user interface such as web interface for easier create policy
Pros and Cons
- "It's pretty reliable and allows for isolation capabilities within the network."
- "The user interface isn't as good as it could be. They should work to improve it. It would make it easier for customer management if it was easier to use."
What is our primary use case?
We primarily use the solution for basic firewall configurations such as NAT, FORWARD PORT and Block TCP-UDP Port.
How has it helped my organization?
My company is very small just built last year, i now am using cisco asa 5510 for NAT and Port Forward and limit users access directly from internet only via Remote-VPN.
What is most valuable?
The ability to block threats is its most valuable aspect.
Most clients in Laos use the basic setup, which works quite well. It ensures that nothing can get onto the local network.
It's pretty reliable and allows for isolation capabilities within the network.
The ADSM is very good.
I like that I can use the command line. I use a lot of Cisco and often work with this. If you are comfortable with the command line, it's quite good.
What needs improvement?
The user interface isn't as good as it could be. They should work to improve it. It would make it easier for customer management if it was easier to use.
Cisco does not have a lot of web management. We have to use ASTM server management to make up for it.
For how long have I used the solution?
I've been using the solution, give or take, for around five years at this point.
What do I think about the scalability of the solution?
How are customer service and technical support?
When we need assistance from technical support, we typically deal with the team in China. They've been very good. Whenever I have a problem, they can resolve it. They are knowledgeable and responsive. We're satisfied with the level of support we get.
Which solution did I use previously and why did I switch?
We typically offer clients a few different solutions. For example, we may recommend Fortinet.
How was the initial setup?
For a new user, the initial setup may be a bit difficult. For me, since I am comfortable with Cisco, it's pretty straightforward. A new connection has its own complexities. It may be a different thing on Java SDK. There may be some programs that may not be able to access it.
What's my experience with pricing, setup cost, and licensing?
In Laos, clients don't have much wiggle room when it comes to cost. The economy right now isn't very good. Most just choose the basic solution in order to avoid pricey licensing fees.
Which other solutions did I evaluate?
subscription payment
What other advice do I have?
We're just customers. We use it in our office and suggest it to clients. However, we don't have a business relationship with Cisco.
We try to adhere to our client's needs, and therefore, if they specify hardware they want to use, like Fortinet, we tend to accommodate them.
That said, if they ask my opinion, I usually recommend Cisco ASA.
I know a lot about the product and I'm good at controlling everything. I have a lot of knowledge and understanding after working with it so closely. That's why I tend to favor it when my customers ask for advice.
Overall, I would rate the solution seven out of ten. If the user interface were a bit better, I'd rate it higher.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Security Engineer at a financial services firm with 1,001-5,000 employees
Great for blocking attacks, best support, and very easy to use
Pros and Cons
- "The Adversity Malware Protection (AMP) feature is the most valuable. It is also very easy to use. Every technical user can operate this solution without any difficulty. The dashboard of Cisco Firepower has every tool that a security operator needs. You can find every resource that you need to operate through this dashboard."
- "Its interface is sometimes is a little bit slow, and it can be improved. When you need to put your appliance in failover mode, it is a little difficult to do it remotely because you need to turn off the appliance in Cisco mode. In terms of new features, it would be good to have AnyConnect VPN with Firepower. I am not sure if it is available at the moment."
What is our primary use case?
I use it to protect my DMZ from external attacks.
How has it helped my organization?
Last year, we received a lot of linear service attacks in our environment during the Black Friday season. Cisco Firepower blocked every attack.
What is most valuable?
The Adversity Malware Protection (AMP) feature is the most valuable.
It is also very easy to use. Every technical user can operate this solution without any difficulty. The dashboard of Cisco Firepower has every tool that a security operator needs. You can find every resource that you need to operate through this dashboard.
What needs improvement?
Its interface is sometimes is a little bit slow, and it can be improved.
When you need to put your appliance in failover mode, it is a little difficult to do it remotely because you need to turn off the appliance in Cisco mode.
In terms of new features, it would be good to have AnyConnect VPN with Firepower. I am not sure if it is available at the moment.
For how long have I used the solution?
I have been using Cisco Firepower for two years.
What do I think about the scalability of the solution?
We use it specifically for DMZ, so we don't need it to scale it up. Because we are using this solution for a specific environment, we don't plan to increase its usage.
We have a few teams who use this solution. We have the information security team for reading the logs and policies. We have administrators, and we also have contractors for the network operation center to analyze some logs and reports.
How are customer service and technical support?
We have used their technical support. They are amazing. Cisco's technical support is the best.
Which solution did I use previously and why did I switch?
We have used Check Point and one more solution. The main difference is in the IPS signatures. Cisco Firepower has precise and most updated IPS signatures.
How was the initial setup?
The initial setup is easy. The deployment took two months because we didn't have Firepower previously, and it took us some time to plan and implement.
What about the implementation team?
We used our reseller and contractor to deploy Cisco Firepower. They were good.
What other advice do I have?
I would recommend this solution. I would rate Cisco Firepower a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Solution Architect at a tech services company with 11-50 employees
Powerful features include Snort and IPS, it is easy to deploy, and the technical support is good
Pros and Cons
- "I like the firewall features, Snort, and the Intrusion Prevention System (IPS)."
- "This product is managed using the Firepower Management Center (FMC), but it would be better if it also supported the command-line interface (CLI)."
What is our primary use case?
We are a solution provider and Cisco NGFW is one of the products that we implement for our clients. My clients use it for internet access within the enterprise.
What is most valuable?
I like the firewall features, Snort, and the Intrusion Prevention System (IPS).
What needs improvement?
This product is managed using the Firepower Management Center (FMC), but it would be better if it also supported the command-line interface (CLI). Cisco's FTD devices don't support the command-line interface and can only be configured using FMC.
For how long have I used the solution?
We have been using this product for the past four years.
What do I think about the stability of the solution?
This is a stable product and we plan to continue implementing it for clients in the future.
What do I think about the scalability of the solution?
Cisco NGFW is a scalable firewall. My client has more than 100 users.
How are customer service and technical support?
We have support from Cisco's TAC, the Technical Assistance Center, and they support this product well. We haven't had any issues with them.
Which solution did I use previously and why did I switch?
Prior to the Next Generation firewall, my clients were using Cisco ASA for more than 10 years.
How was the initial setup?
The initial setup is easy, with the installation and configuration taking about two hours.
What about the implementation team?
I did the deployment myself.
What's my experience with pricing, setup cost, and licensing?
This product requires licenses for advanced features including Snort, IPS, and malware detection.
What other advice do I have?
In summary, this is a good product and I recommend it.
I would rate this solution a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Implementer
Chief Technology Officer at a tech services company with 51-200 employees
Provides excellent integrations and reporting
Pros and Cons
- "Provides good integrations and reporting."
- "Deploying configurations takes longer than it should."
What is our primary use case?
Our primary use case is as a data center firewall for internet firewalls and also as a VPN concentrator. I'm the chief technology officer and we are partners of Cisco.
What is most valuable?
In terms of features there hasn't been much improvement but it's a very stable solution and a very good firewall with almost all of the features required for next generation firewall purposes. Almost all the firewalls on the market have the same features available, but if you take into account the integrations and reporting of Cisco, it's a little better than the others. In particular, the briefing reporting is better. With Fortinet we would probably have to use FortiAnalyzer as a separate reporting module for Fortinet, but here the reporting is good.
What needs improvement?
There needs to be an improvement in the time it takes to deploy the configurations. It normally takes two to four minutes and they need to reduce this. The deployment for any configuration should be minimal. It's possibly improved on the very latest version.
An additional feature I would like to have in Firepower would be for them to give us the data from the firewall - Cisco is probably working on that.
For how long have I used the solution?
I've been using this solution for close to five years.
What do I think about the scalability of the solution?
The scalability is very good.
How are customer service and technical support?
We generally provide support but if we're not able to resolve an issue, we escalate it to Cisco and they're great. They are one of the best support services I've used and it's one of the reasons Cisco is doing so well in the market.
Which solution did I use previously and why did I switch?
I also work with Fortinet and Palo Alto. Fortinet is also a really good product but Cisco is a leader in next generation firewalls and now that they are catching up to Fortinet, they have provided a lot of features and flexibility. I personally see Cisco as being good for large enterprise companies and Fortinet is better for families as well as small and medium size businesses. When it comes to Palo Alto, the high price point is one thing that is an issue, some companies are unable to afford it. Palo Alto is good but Cisco is catching up to them and I believe in a year or two, Cisco will probably match Palo Alto as well and be much better.
How was the initial setup?
The initial setup is not too complex, but as with Fortinet, they have some detailed steps required which adds to the flexibility also. With flexibility comes a bit of complexity, but it's not too bad. Deployment time takes a few minutes. I am responsible for implementation and maintenance for our clients. We were previously deploying only for medium or large enterprise companies but Cisco has come up with the 1000 and 1100 series firewalls for smaller companies which is pretty good. They're a cost-effective solution and competitive in the market.
What's my experience with pricing, setup cost, and licensing?
Cisco falls somewhere in the middle in terms of pricing, it's not very expensive and it's not very cheap. There is an additional accessory fee associated with Cisco but normally they have a separate subscription cost for different types of security to protect the firewall. There are separate bundles available inside the pricing and that's probably true for all of the firewalls.
What other advice do I have?
Cisco is a large, good and reliable firewall. They are working on advanced features and catching up with the leaders in the market. I believe that's a score for them. A yearly subscription is cheaper than Palo Alto and Fortinet offer. They provide good support and once it's loaded, it doesn't give a lot of problems, that's very important.
I would rate this solution an eight out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2025
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
Sophos XG
Cisco Umbrella
Cisco Identity Services Engine (ISE)
Palo Alto Networks NG Firewalls
WatchGuard Firebox
Cisco Meraki MX
Check Point Quantum Force (NGFW)
Azure Firewall
SonicWall TZ
Cisco Secure Network Analytics
Sophos XGS
Fortinet FortiGate-VM
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Is The Biggest Difference Between Cisco ASA And Fortinet FortiGate?
- Cisco Firepower vs. FortiGate
- How do I convince a client that the most expensive firewall is not necessarily the best?
- What are the biggest differences between Cisco Firepower NGFW and Fortinet FortiGate?
- What Is The Biggest Difference Between Cisco Firepower and Palo Alto?
- Would you recommend replacing Cisco ASA Firewall with Fortinet FortiGate FG 100F due to cost reasons?
- What are the main differences between Palo Alto and Cisco firewalls ?
- A recent reviewer wrote "Cisco firewalls can be difficult at first but once learned it's fine." Is that your experience?
- Which is the best IPS - Cisco Firepower or Palo Alto?
- Which product do you recommend and why: Palo Alto Networks VM-Series vs Cisco Firepower Threat Defense Virtual (FTDv)?













