Try our new research platform with insights from 80,000+ expert users
it_user850275 - PeerSpot reviewer
Pre-sales engineer with 51-200 employees
Real User
Provides visibility as well as management and administration capabilities

What is our primary use case?

We use it as a perimiter firewall and do VPNs and filtering.

How has it helped my organization?

As a reseller, because Cisco includes different companies like Sourcefire, Meraki, and Talos, I think Cisco has a good portfolio for the security business, with their own devices too. For example, we have our firewall, we have a Web security appliance, things like OpenDNS with Umbrella. I think Cisco can cover with all the platforms.

What is most valuable?

All the visibility the device gives us as well as management and administration facilities.

What needs improvement?

It needs better documentation for when we present solutions to non-technical people. They need to bring together all the information, across the various firewalls, so that we can more clearly explain them.

Also, pricing could be better.

Buyer's Guide
Cisco Secure Firewall
June 2025
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.

What do I think about the stability of the solution?

It's very stable. 

What do I think about the scalability of the solution?

When we implement a firewall we need to be aware of whether it is growing over a short time period or a long time period. I think the scalability, from our implementation, is good because you can use the same configuration for another platform. If you implement on a small platform, it It is easy to implement the same configuration to another, bigger device.

How are customer service and support?

I think tech support is a large part of Cisco. It's good, it provides support around the clock, answers problems. I would rate it nine out of 10.

Which solution did I use previously and why did I switch?

SonicWall.

How was the initial setup?

For some things it is very easy, but configuring other things is a little complex. It depends on the use case.

What's my experience with pricing, setup cost, and licensing?

Cisco may be a little expensive but it has everything, and they support very well.

Which other solutions did I evaluate?

Juniper, Fortinet.

What other advice do I have?

I think Cisco has all the solutions: switching, routing, security, they have wireless. You can cover all the devices with Cisco. They have all the network and engineered tools to help resolve the issues that we have. They are really very good devices.

In terms of advice, I would say Cisco is the best company. They're very stable, there aren't too many issues. And when there is an issue they have many engineers who can solve the problem.

Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller.
PeerSpot user
reviewer847167 - PeerSpot reviewer
Network and Securirty Engineer at a tech vendor with 501-1,000 employees
User
Filtering is the best feature
Pros and Cons
  • "Filtering is the best feature."
  • "The IPS and GUI are outdated."
  • "It is slowly not supported and other vendors are a few years ahead of Cisco in development."

What is our primary use case?

We use it for security of branch offices and data centers. 

How has it helped my organization?

It works like a firewall for security reasons. 

What is most valuable?

Filtering is the best feature, as I have gotten used to using it.                               .

What needs improvement?

The IPS and GUI are outdated. It is finally getting IPS inside, which will be a big improvement. The GUI is outdated, and they are slowly improving it. We will see if they go in the correct direction. Unfortunately, they usually just follow other vendors.

It is slowly not supported and other vendors are a few years ahead of Cisco in development.  

For how long have I used the solution?

More than five years.

What other advice do I have?

Configuration on Firepower is currently madness as you have to redeploy it again with all its configurations if you use it as a module.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Cisco Secure Firewall
June 2025
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.
it_user821520 - PeerSpot reviewer
Information Systems Manager at a manufacturing company with 201-500 employees
Real User
Its most valuable feature is its ability to work with the traffic
Pros and Cons
  • "Its ability to work with the traffic.​"
  • "​I would like it to be easier to work with and have a better user interface.​ It is not straightforward. You need to know the Cisco command-line interface."
  • "​Initial setup was fairly complex."

What is our primary use case?

Business use. It has performed well.

What is most valuable?

Its ability to work with the traffic.

What needs improvement?

I would like it to be easier to work with and have a better user interface. It is not straightforward. You need to know the Cisco command-line interface.

What do I think about the stability of the solution?

Stability has been fine.

What do I think about the scalability of the solution?

It is good.

How are customer service and technical support?

I have not used technical support.

Which solution did I use previously and why did I switch?

We have always been with Cisco.

How was the initial setup?

Initial setup was fairly complex. Just having to know the command prompt rather than having a better user interface.

What's my experience with pricing, setup cost, and licensing?

We looking for a possible new solution because of the licensing and VPN.

Which other solutions did I evaluate?

We evaluated Cisco and Meraki.

What other advice do I have?

Look through what your needs are.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Network Consulting Engineer at a energy/utilities company with 10,001+ employees
Real User
It is very stable. Setting it up is not as intuitive as other more modern NGFWs.
Pros and Cons
  • "If only a Layer 4 FW is needed, this is a good solution."
  • "It is very stable."
  • "Setting it up is not as intuitive as other more modern NGFWs."

What is our primary use case?

Solid datacenter firewall, but the ASA software is old with no application recognition. If only a Layer 4 FW is needed, this is a good solution.

How has it helped my organization?

Do not use it in cluster mode. It is not worth it. These firewalls can do 10G, so just design the rest of the network around this.

Do not do cluster to add more bandwidth.

What is most valuable?

Nothing fancy about ASA capabilities, it does its job and does it well as long as you only care about filtering ports and protocols.

What needs improvement?

The needed features are already being done on Firepower, but this software is still in flux. 

For how long have I used the solution?

Three to five years.

What do I think about the stability of the solution?

It is very stable.

How was the initial setup?

Setting it up is not as intuitive as other more modern NGFWs.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user824748 - PeerSpot reviewer
Works at a comms service provider with 1,001-5,000 employees
User
Clustering architecture which offers zero downtime upgrades, keeping uptime close to 99.999%
Pros and Cons
  • "Clustering architecture which offers zero downtime upgrades, keeping uptime close to 99.999%."
  • "REST API offering with rich capabilities which makes the product very robust."
  • "ASDM needs to be able to customize applets.​"
  • "​REST API stability needs improvement in order for customizing resource allocation available to the user rather than just being there transparently. This way users can customize REST API and tailor it to their needs​."

What is our primary use case?

Service Provider Operations manipulating thousands of firewall rules deploying Network Access Translations (NAT) for various multiservice networks.

How has it helped my organization?

  • Easy and fast to deploy.
  • User-friendly GUI
  • REST API offering with rich capabilities which makes the product very robust.

What is most valuable?

Clustering architecture which offers zero downtime upgrades, keeping uptime close to 99.999%. This creates less stress on operations and network stability throughout the various maintenance tasks.

What needs improvement?

ASDM needs to be able to customize applets.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

REST API stability needs improvement in order for customizing resource allocation available to the user rather than just being there transparently. This way users can customize REST API and tailor it to their needs.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Network Security Specialist at a financial services firm with 501-1,000 employees
Real User
It is easy to create interfaces and routing, but the product needs real-time logs
Pros and Cons
  • "It is easy to create interfaces and routing, which all can be done at the GUI level."
  • "The product needs real-time logs to be able to monitor our services, so we can know if any our services have been blocked via the firewall or on the application side."

What is our primary use case?

Currently used for at our disaster recovery site as our internal firewall, not a lot of services are running through it. We are still going around learning how to use it.

How has it helped my organization?

Since we have used Firepower firewall, we are facing issues of getting real-time logs, as they are not available with the latest version.

What is most valuable?

It is easy to create interfaces and routing, which all can be done at the GUI level. For now, we are still going around the services and will add more in the future.

What needs improvement?

The product needs real-time logs to be able to monitor our services, so we can know if any our services have been blocked via the firewall or on the application side.

For how long have I used the solution?

Less than one year.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user814596 - PeerSpot reviewer
Senior Network Manager with 51-200 employees
Vendor
Easy to deploy in a working environment between servers and users
Pros and Cons
  • "Logging is great. It will show when it reaches its capacity before it is too late, unless you have bursts of traffic."
  • "Easy to deploy in a working environment between servers and users."
  • "HTTPs inspection and higher throughput/spec would be good."

What is our primary use case?

  • Datacenter and edge firewalls
  • Used in central and remote sites.
  • Used in datacenter production sites.

How has it helped my organization?

  • Deployed between users and servers transparently.
  • Easy to deploy in a working environment between servers and users.
  • Improved security and visibility.

What is most valuable?

  • Failover
  • Transparent firewall
  • Multi-context
  • Logging is great. It will show when it reaches its capacity before it is too late, unless you have bursts of traffic.

What needs improvement?

HTTPs inspection and higher throughput/spec would be good. Now, it has been replace by Firepower, which is a lot faster. 

For how long have I used the solution?

More than five years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Security Governance at a comms service provider with 1,001-5,000 employees
Real User
It brought our network down several times due to a memory leakage bug. Protects 3G/4G Internet customers and the Private APN.
Pros and Cons
  • "We have been using a 5520 for seven years in our datacenter and we are satisfied by this version."
  • "The solution is used for the protection of the mobile data network. It is protecting 3G/4G Internet customers and the Private APN."
  • "The throughput highlighted on the datasheet (10Gbps) should be reviewed. This throughput is only for a UDP running environment, which you will never find in the real world. Rather consider a multiprotocol throughput."
  • "A memory leakage issue which literally freeze the nodes (we have an HA environment). The issue is still not solved and the only recommendation from Cisco is to reboot the node."

What is our primary use case?

ASA5585-SSP-60 was deployed after a migration from Juniper SRX5600. The solution is used for the protection of the mobile data network. It is protecting 3G/4G Internet customers and the Private APN.

How has it helped my organization?

So far, we are not satisfied by the move. The precedent solution is much more adapted to the Telco environment, although Cisco recommended this platform. Cisco ASA also brought our network down several times due to a memory leakage bug, which is still not resolved.

What is most valuable?

All features provided by the platform are quite the same for all other platforms. We rather missed some features we were used to, such as virtual routers

What needs improvement?

  • VPN creation with Cisco is quite difficult: Some DH groups are not supported (compared to Juniper).
  • Expected to see the enablement of virtual routing, which is key in a Telco environment. We need to provide this in LAN to LAN services with shared platforms (DNS, proxies, etc.).
  • Application visibility 

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

Yes, a memory leakage issue which literally freeze the nodes (we have an HA environment). The issue is still not solved and the only recommendation from Cisco is to reboot the node.

What do I think about the scalability of the solution?

Yes, the throughput highlighted on the datasheet (10Gbps) should be reviewed. This throughput is only for a UDP running environment, which you will never find in the real world. Rather consider a multiprotocol throughput.

How are customer service and technical support?

Experience with technical support was mitigated. 

Technically, they denied any issues on the node and call the memory leak issue, "A cosmetic issue." They were stating that memory disappearance reported by SNMP was an error and will have no impact on the traffic. They have reviewed this since we have recorded several blackouts during the year.

Which solution did I use previously and why did I switch?

We were using Juniper SRX5600. The switch was more a strategic decision than a technical one.

We are also using a 5520 for seven years in our datacenter and we are satisfied by this version.

How was the initial setup?

The initial setup was very complex. Migration from Juniper (with wide usage of VR) to Cisco is complex and you should make sure to master all the flows on the node. Also, Juniper is more permissive on asymmetric traffic, which Cisco will deny by default. 

What about the implementation team?

Implementation was performed by a Cisco recommended local partner. 

We were not satisfied at all (from the pre to post implementation). Their level of expertise was zero.

What was our ROI?

I do not know.

What's my experience with pricing, setup cost, and licensing?

Nothing to highlight at this level. 

Which other solutions did I evaluate?

We did an evaluation with Check Point.

What other advice do I have?

It is definitely not for Telco.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2025
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros sharing their opinions.