The AnyConnect remote access VPN gives us an easy way to deploy remote working for our users.
Senior Network Security Engineer at a university
Spec the right hardware model and choose the right license for your needs.
Pros and Cons
- "The AnyConnect remote access VPN gives us an easy way to deploy remote working for our users."
- "The SSL VPN is, and always has been, painful to configure and the Java plugin does not guarantee a uniform deployment."
How has it helped my organization?
What is most valuable?
It all depends on the deployment scenario, as I have used ASA for specific purposes. In general, the stateful firewall feature, site to site VPN, and AnyConnect remote access VPN are always useful.
What needs improvement?
It's not perfect, and does have room for improvement with certain features.
The SSL VPN is, and always has been, painful to configure and the Java plugin does not guarantee a uniform deployment.
Certain documentation on the newer models of ASA (specifically, ASA 5500-X with FirePower services) is a little out of date and in some cases incorrect, although this may have been corrected since my last deployment.
What do I think about the stability of the solution?
I've never seen a firewall that didn't need an RMA at some point! And that is true of the ASA, however, the failure rate (in my experience) has always been very low with ASA's (and Cisco equipment in general).
Buyer's Guide
Cisco Secure Firewall
September 2026
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,889 professionals have used our research since 2012.
What do I think about the scalability of the solution?
Nope.
How are customer service and support?
With Cisco TAC, you can always get an answer to technical issues, and with the thriving Cisco support forum, you can always get answers to questions even if you don't have TAC.
Which solution did I use previously and why did I switch?
Not in my current organization.
How was the initial setup?
I would say it's only complex if you're not familiar with either the CLI or ASDM.
So for me, it was easy, for those without Cisco CLI (or ASDM) experience, deployment can be a little daunting.
That being said, there are plenty of configuration documents available on the Cisco website that will "hold your hand" through any deployment.
What's my experience with pricing, setup cost, and licensing?
Hardware and licensing can be expensive, and licensing can be a complicated affair. I would strongly recommend you speak with your distributor to ensure you choose the right license for your needs, and read the hardware comparison guide to make sure you spec the correct hardware for your specific needs.
Which other solutions did I evaluate?
It's great buying the latest and greatest equipment, but no so great if your engineers don't know how to operate it!
From experience, hardware purchasing is normally dependent on the technical expertise of engineers, so if all your engineers are Cisco trained, it makes no sense to buy another vendor firewall.
What other advice do I have?
Spec the right hardware model and choose the right license for your needs.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior IT Networking and Security Manager at a tech services company with 10,001+ employees
It is supported on many platforms and helps us gain access to the network.
Pros and Cons
- "This is definitely not a cheap solution, but I think it is worth the investment."
- "The next generations part of these products need a better approach."
What is most valuable?
There are a lot of features which are good and can be implemented, especially in the latest IOS version of the product.
They saved me a lot of time thinking how to solve different scenarios with other solutions.
Cisco AnyConnect for remote access is one of them. It is supported on most of the platforms, which business users use. They can gain access to the network, via functions like PBR, Security groups, contexts, and DNS doctoring. This gives a lot of flexibility to the product.
How has it helped my organization?
It gave us a more secure environment and a lot of flexibility to the business.
What needs improvement?
The next generations part of these products need a better approach. A lot of vendors are definitely a step or two in front of them.
For how long have I used the solution?
I have worked with these types of firewalls for more than 10 years.
What do I think about the stability of the solution?
I can say that this product is one of the most stable products I have ever worked with.
What do I think about the scalability of the solution?
In terms of scalability, this always depends on how the product was chosen and what purpose it will work for. I haven't experienced any issues with the scalability of the product.
How are customer service and technical support?
In terms of technical support, it depends on the different cases. I would surely give Cisco technical support a rating of 9/10.
Which solution did I use previously and why did I switch?
I used to work with open source solutions, but the support and complication behind them was definitely not OK. If you want to have flexibility and stability, you have to move on to something that receives more development in that specific area.
How was the initial setup?
The initial setup was straightforward and there was a lot of documentation that can help out with specific cases.
What's my experience with pricing, setup cost, and licensing?
This is definitely not a cheap solution, but I think it is worth the investment.
Which other solutions did I evaluate?
We evaluated other solutions like Juniper, but we chose Cisco, since our network was becoming more and more Cisco oriented.
What other advice do I have?
I would recommend that you understand the needs of the business case before choosing the product and start implementing it. It is very important to choose the right licenses from the beginning.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Cisco Secure Firewall
September 2026
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,889 professionals have used our research since 2012.
Network Engineer at a tech vendor with 10,001+ employees
Some of the valuable features are detecting malware and blocking blacklisted URLs.
Pros and Cons
- "It has enhanced the security in every network over time."
- "The upgrade is a bit of a pain in the neck."
What is most valuable?
Some of the valuable features are detecting malware and blocking blacklisted URLs.
How has it helped my organization?
It has enhanced the security in every network over time.
What needs improvement?
As of now, I can't find any flaws with the device or any improvement that I can suggest.
For how long have I used the solution?
I have been working with the device for the past two years.
What was my experience with deployment of the solution?
The upgrade is a bit of a pain in the neck.
What do I think about the stability of the solution?
There were no issues with the stability
What do I think about the scalability of the solution?
Scalability has been all-star perfect.
How are customer service and technical support?
Customer Service:
I would give customer service a rating of 10/10.
Technical Support:I would give technical support a rating of 10/10.
Which solution did I use previously and why did I switch?
We have only used Cisco security devices.
How was the initial setup?
The setup was smooth and simple.
What about the implementation team?
We implemented it by ourselves and with some support from the Cisco TAC.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Consultant at a tech services company with 501-1,000 employees
Detection engine and historical file analysis ease threat investigations
Pros and Cons
- "The Firepower IPS, based on Snort technology, has an amazing detection engine and historical analysis capability of files that eases threat investigations a lot."
- "The application and user-visibility and control, along with very powerful IPS and malware protection, enables our clients to secure their data centers and internet perimeter in a much better way."
- "I would like to see more integration with third-party devices in general. There is great integration with Cisco devices, but there's not much integration with third-party devices."
- "You always need an external management system, the onboard one is not very good."
What is our primary use case?
Cisco next-generation firewalls are mainly used either for data center protection - north-south traffic - or internet traffic.
How has it helped my organization?
The application and user-visibility and control, along with very powerful IPS and malware protection, enables our clients to secure their data centers and internet perimeter in a much better way. It provides them with traffic visibility and reporting as well.
The main advantage is when you put it between users and servers internally or between different VLANs in the network. You have full visibility over the traffic, over all the internal applications. Usually, there's a lot of traffic that is not very clear and no one knows what is on their network. So, once deploy it internally, you have full visibility over the internal traffic, who's accessing what, which protocol. It can directly detect all kinds of malicious traffic, traffic that abuses bandwidth.
It makes different kinds of internal behavior that is useful to a network admin. And for security of course: Any kind of file infection, any kind of internal scanning, internal attacks; it gives you full visibility.
Finally, you have communication of VLANs, internally, in the network, of course. So you have a granular access control based on user and application, instead of IP and port as you would have with a traditional firewall.
What is most valuable?
During the first phase of use, it was an extra module on standard Cisco ASA firewalls. It then became a standalone solution known as FTD, Firepower Threat Defense.
The Firepower IPS, based on Snort technology, has an amazing detection engine and historical analysis capability of files that eases threat investigations a lot.
I value the integration with other products (Cisco ISE, Cisco Endpoint AMP) which increases the protection intelligence within the enterprise by sharing security info between different products, which function on different layers. It furnishes fully connected security.
It also provides detection of the client operating system, which gives very good reporting and correlation with the signatures. It can relay the signature IP to the client operating system, to give a better correlation decision.
What needs improvement?
Some ASA known features are still missing, but are being added bit by bit in each new version release, such as:
- Remote Access VPN (the last release only supported the 2100 series): The next firewall model version is expected to support Remote Access VPN in the next software release in July 2017.
- Virtualization of the appliance (multiple contexts) is still missing.
- You always need an external management system, the onboard one is not very good. You have to use FMC, FirePOWER Management Center, as external software. There's always an add-on, whereas all the competition has an onboard management interface.
I would like to see more integration with third-party devices in general. There is great integration with Cisco devices, but there's not much integration with third-party devices.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
We did not encounter any issues with stability. Cisco Firepower FW is very stable in all of the deployments we have made.
What do I think about the scalability of the solution?
The scalability is very good. They have a clustering mechanism, so you can start with an appliance and then cluster, adding more bandwidth and nodes into your cluster. If you don't have a big budget you can start with a medium appliance and then cluster appliances. Or if you want to buy it all in one shot, there is a big range.
Although it allows scaling by adding multiple firewalls together (clustering), we have never used that, as all new hardware supports high-performance throughput and connections at a reasonable price.
How are customer service and technical support?
Technical support is perfect. Cisco is always known for its good technical support. We have never had any issues with them.
Which solution did I use previously and why did I switch?
As a Cisco Gold Partner, we always proposed Cisco firewalls for our clients.
How was the initial setup?
The setup was straightforward. A new Cisco FTD can be set up and running in a couple of hours. If you're used to firewalls you can quickly get along with it. There is nothing complicated.
The time deploy is short. But the time to tune and create the policies involves a learning phase. Traffic changes over time, so the tuning for firewall rules has to be as granular as possible takes a bit of time. But to deploy you can go live is fast.
The strategy is to start with high-level security policies and then monitor the traffic and the applications affected. Then on the detection logs, create more granular rules.
What's my experience with pricing, setup cost, and licensing?
It has a great performance-to-price value, compared to competitive solutions. Subscriptions are annual. The licensing fee and standard support are the only costs we pay for.
Which other solutions did I evaluate?
We did not evaluate any alternative solutions.
What other advice do I have?
Make sure you tune your rules very well, as some clients just leave the firewall as it is and don't maintain the access rules or tighten them to be more granular and efficient.
In terms of maintenance, you need one person for security analysis and one to create rules and for daily support.
Disclosure: My company has a business relationship with this vendor other than being a customer. We are a Cisco Gold Partner.
Senior Network Specialist
It has an important role as a firewall and it improves our access control.
Pros and Cons
- "The security features are valuable because it is easy to use and it has an important role as a firewall."
- "It would be useful to gather all security features in one box. For example, certain features like URL filtering and application control licenses need to be purchased separately and it depends on the hardware spec, as not all models are supporting these two features."
What is most valuable?
The security features are valuable because it is easy to use and it has an important role as a firewall.
How has it helped my organization?
It has improved our access control.
What needs improvement?
It would be useful to gather all security features in one box. For example, certain features like URL filtering and application control licenses need to be purchased separately and it depends on the hardware spec, as not all models are supporting these two features. This causes the user to be highly dependent on the pre-sales person.
For how long have I used the solution?
We have been using the solution for six years.
What do I think about the stability of the solution?
We did not encounter any issues with stability.
What do I think about the scalability of the solution?
We had a scalability issue, as each feature is based on license or hardware support.
How are customer service and technical support?
I would rate the technical support at 8/10.
Which solution did I use previously and why did I switch?
We did not use a previous solution.
How was the initial setup?
The setup was straightforward with two layers of firewall.
What's my experience with pricing, setup cost, and licensing?
It is too pricey if you want to activate more features in a box, which necessitates you to purchase a license.
Which other solutions did I evaluate?
We evaluated Palo Alto and CheckPoint.
What other advice do I have?
Know what features are needed, and then purchase the necessary hardware and license.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Engineer at a mining and metals company with 1,001-5,000 employees
The simple access rule, Internet NAT and routing are valuable features.
Pros and Cons
- "If you are looking for a stable run and it is easy to find someone to configure the service, then better go for Cisco; their support is very professional."
- "Sometimes, the throughput and CPU counter issues were faced, maybe because we started to use it a long time ago."
What is most valuable?
The simple access rule, Internet NAT and routing are valuable features. It is very simple and the most reliable perimeter firewall.
How has it helped my organization?
We were using Cisco Security Manager (CSM) to control and configure all of our Cisco products. ASA worked very well on the CSM.
What needs improvement?
The next-generation firewall could improve. Still, they have NGFW 5525 but I haven’t tried it yet.
For how long have I used the solution?
We have been using this solution for seven years.
What do I think about the stability of the solution?
We have never faced any stability issues.
What do I think about the scalability of the solution?
Sometimes, the throughput and CPU counter issues were faced, maybe because we started to use it a long time ago.
How are customer service and technical support?
Technical support is great. They are very responsible, know the bugs and workaround.
Which solution did I use previously and why did I switch?
We have used it from the beginning.
How was the initial setup?
The initial setup is not simple and straightforward, because it is Cisco and you need to configure it by CLI.
What's my experience with pricing, setup cost, and licensing?
Obviously, Cisco products are not cheap.
What other advice do I have?
If you are looking for a stable run and it is easy to find someone to configure the service, then better go for Cisco; their support is very professional.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Executive Manager with 11-50 employees
The solution's reliability, performance, and security are most valuable.
Pros and Cons
- "The solution's reliability, performance, and security are most valuable."
- "The price and compatibility with other vendors' products can be improved."
What is most valuable?
The solution's reliability, performance, and security are most valuable.
What needs improvement?
The price and compatibility with other vendors' products can be improved.
For how long have I used the solution?
I have used this solution for three years.
What do I think about the stability of the solution?
I have not encountered any issue with stability.
What do I think about the scalability of the solution?
I have not encountered any issues with scalability.
How are customer service and technical support?
I would give technical support a rating of 9/10.
Which solution did I use previously and why did I switch?
I used Juniper Networks and I switched due to the lack of technical and sales support in Romania.
How was the initial setup?
The initial setup was complex because of its outdoor position. We had to solve this problem with outdoor protection.
What's my experience with pricing, setup cost, and licensing?
Negotiate the quote.
Which other solutions did I evaluate?
Before choosing, I evaluated Juniper Networks SRX.
What other advice do I have?
Be careful with temperature control in the rack area, since Cisco ASA 5585-X with SSP-10 heats up a lot.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Operation Manager at a retailer with 11-50 employees
Provides software updates for known bugs and vulnerabilities.
Pros and Cons
- "Any security vendor with a user-friendly interface, with good support, on-time updates for known vulnerabilities, and reliable hardware, is acceptable for an organization."
- "Cisco FTD software is not ready for production, due to a lack of many basic NGFW features."
What is most valuable?
- Hardware reliability
- Software stability
- Quick software updates for known bugs/vulnerabilities
These are very important in an enterprise environment.
How has it helped my organization?
It is small. Nobody knows where it is or what it is. It works silently. As there ar no issues, it is good for businesses and organizations.
What needs improvement?
- License politics
- License price
- Precise vendor roadmap for this product
For how long have I used the solution?
I have used Cisco ASA for five years.
What do I think about the stability of the solution?
We have not had stability issues.
How are customer service and technical support?
I would give them a high rating.
Which solution did I use previously and why did I switch?
We were using TippingPoint as an IPS and ZyXEL ZyWALL as a VPN server.
Cisco has good documentation and it is easy for Cisco certified engineers.
How was the initial setup?
The initial setup was straightforward.
What's my experience with pricing, setup cost, and licensing?
Our experience last year showed us that there is no full security, so why should we pay more? Any security vendor with a user-friendly interface, with good support, on-time updates for known vulnerabilities, and reliable hardware, is acceptable for an organization.
Which other solutions did I evaluate?
We did not evaluate any alternatives.
What other advice do I have?
The Cisco ASA product line will be replaced by Cisco FTD. Cisco FTD software is not ready for production, due to a lack of many basic NGFW features. Maybe only the high-performance Firepower 41xx/21xx/90xx Series is good as an IPS, because it is using a stable Sourcefire engine.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Technical Architect at a tech services company with 10,001+ employees
It provides detection of zero day infections. The feature sets are great when there are no software bugs.
Pros and Cons
- "With FirePOWER, you can enhance security, have effective management, and a good reporting engine."
- "We have had a number of bugs on the FirePOWER software across several clients which have been very inconsistent and have affected our ability to deliver."
What is most valuable?
The feature sets are great when there are no software bugs. With FirePOWER, you can enhance security, have effective management, and a good reporting engine.
How has it helped my organization?
It provides detection of zero day infections through FirePOWER AMP.
What needs improvement?
Well tested software releases. We have had a number of bugs on the FirePOWER software across several clients which have been very inconsistent and have affected our ability to deliver.
For how long have I used the solution?
I have used the ASA portion for over eight years and the FirePOWER portion for about three years.
What do I think about the stability of the solution?
We did have stability issues with the FirePOWER software.
What do I think about the scalability of the solution?
We did not have scalability issues with the high end devices.
How are customer service and technical support?
I give technical support a rating of 5/10.
Which solution did I use previously and why did I switch?
We are part of the integrator space. When we changed products, it was to displace a product that no longer met the client’s requirements.
How was the initial setup?
The setup was reasonably straightforward.
What's my experience with pricing, setup cost, and licensing?
Get a clear understanding of what the licensing entails before committing.
Which other solutions did I evaluate?
We checked out Check Point and FortiGate.
What other advice do I have?
Plan very well in order to have a seamless project implementation and transition.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Operation Manager at a retailer with 11-50 employees
NGFW features software stability, quick software updates for known bugs/vulnerabilities.
Pros and Cons
- "It is small, nobody knows where it is, nobody knows what it is, it works silently."
- "Yes, FirePower is not stable, because every new software version comes with many features that cause problems."
What is most valuable?
NGFW features software stability, quick software updates for known bugs/vulnerabilities. Why no hardware reliability (see Clock Signal Component Issue -Cisco)? Because without NGFW features it is basically like a home router.
How has it helped my organization?
It is small, nobody knows where it is, nobody knows what it is, it works silently. So, as there is no issue, it is good for business and organization.
What needs improvement?
License politics, license price, precise vendor roadmap for this product.
For how long have I used the solution?
Two years.
What do I think about the stability of the solution?
Yes, FirePower is not stable, because every new software version comes with many features that cause problems. Cisco has to do it because other vendors have already added these features.
What do I think about the scalability of the solution?
No.
How are customer service and technical support?
High.
Which solution did I use previously and why did I switch?
3Com TippingPoint as IPS, Zyxel ZyWALL ZyXEL ZyWALLas VPN server. Cisco has good documentation and it is easy for Cisco certificated engineers.
How was the initial setup?
Complex, because of non-ready Firepower service software setup.
What's my experience with pricing, setup cost, and licensing?
The last years' experience showed that there is no full security, so why pay more. Any security vendor with a user-friendly interface, with good support, on-time updates for known vulnerabilities and reliable hardware, is acceptable for an organization.
Which other solutions did I evaluate?
No.
What other advice do I have?
Cisco's ASA product line will be replaced by Cisco FTD. And Cisco FTD software is not ready for production (lack of many basic NGFW features). So, maybe only high-performance Firepower 41xx/21xx/90xx Series is good as IPS.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
Sophos Firewall
Check Point Cloud Firewall (formerly CloudGuard Network Security)
Cisco Umbrella
Palo Alto Networks NG Firewalls
WatchGuard Firebox
Cisco Identity Services Engine (ISE)
Check Point Harmony SASE (formerly Perimeter 81)
Cisco Meraki MX
Check Point Quantum Force (NGFW)
Cisco Secure Email
Azure Firewall
Cisco Duo
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Is The Biggest Difference Between Cisco ASA And Fortinet FortiGate?
- Cisco Firepower vs. FortiGate
- How do I convince a client that the most expensive firewall is not necessarily the best?
- What are the biggest differences between Cisco Firepower NGFW and Fortinet FortiGate?
- What Is The Biggest Difference Between Cisco Firepower and Palo Alto?
- Would you recommend replacing Cisco ASA Firewall with Fortinet FortiGate FG 100F due to cost reasons?
- What are the main differences between Palo Alto and Cisco firewalls ?
- A recent reviewer wrote "Cisco firewalls can be difficult at first but once learned it's fine." Is that your experience?
- Which Cisco firewall model is the latest: ASA or NGFW?
- Which is better - Fortinet FortiGate or Cisco ASA Firewall?












Cool Review