PeerSpot user
Network Security Specialist at a financial services firm with 501-1,000 employees
Real User
It is easy to create interfaces and routing, but the product needs real-time logs
Pros and Cons
  • "It is easy to create interfaces and routing, which all can be done at the GUI level."
  • "The product needs real-time logs to be able to monitor our services, so we can know if any our services have been blocked via the firewall or on the application side."

What is our primary use case?

Currently used for at our disaster recovery site as our internal firewall, not a lot of services are running through it. We are still going around learning how to use it.

How has it helped my organization?

Since we have used Firepower firewall, we are facing issues of getting real-time logs, as they are not available with the latest version.

What is most valuable?

It is easy to create interfaces and routing, which all can be done at the GUI level. For now, we are still going around the services and will add more in the future.

What needs improvement?

The product needs real-time logs to be able to monitor our services, so we can know if any our services have been blocked via the firewall or on the application side.

Buyer's Guide
Cisco Secure Firewall
May 2024
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
769,976 professionals have used our research since 2012.

For how long have I used the solution?

Less than one year.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user511224 - PeerSpot reviewer
IT Support Engineer
Vendor
Its security features are the most valuable aspect. The equipment is too expensive.

What is most valuable?

Its security features are the most valuable aspect. It has the ability to detect and prevent intrusions.

How has it helped my organization?

The product has helped organizations secure their infrastructure and data. Most organizations are happy to adopt the technology.

What needs improvement?

The equipment is too expensive compared with other firewall products.

For how long have I used the solution?

I have used ASA for about three months. I just bought and configured it for a client.

What do I think about the stability of the solution?

Since I installed and configured it, the client has never called with complaints.

What do I think about the scalability of the solution?

I have not had scalability issues at all. Maybe it is because I have not used it quite extensively.

How are customer service and technical support?

I haven't had a chance to interact with the support team.

Which solution did I use previously and why did I switch?

The previous product was limited in throughput and security.

How was the initial setup?

The initial setup was quite complex.

What's my experience with pricing, setup cost, and licensing?

As much as there is value for money, there is a need to make it affordable.

Which other solutions did I evaluate?

I tried Sophos.

What other advice do I have?

It is a very good device to use for those who value their network security.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Cisco Secure Firewall
May 2024
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
769,976 professionals have used our research since 2012.
PeerSpot user
Founder, CEO, & President at Krystal Sekurity
Consultant
Simplified the complexity of our security architecture.

What is most valuable?

Provides advanced malware capabilities.

How has it helped my organization?

Simplified the complexity of our security architecture.

What needs improvement?

Integration of advanced malware services with the firewall through Firepower services.

For how long have I used the solution?

We have been using this solution for six months.

What was my experience with deployment of the solution?

There were no issues with deployment.

What do I think about the stability of the solution?

There were no issues with stability.

What do I think about the scalability of the solution?

There were no issues with scalability.

How are customer service and technical support?

Customer Service:

I would give customer service a rating of 10/10.

Technical Support:

I would give technical support a rating of 10/10.

Which solution did I use previously and why did I switch?

We were looking to upgrade to a comprehensive firewall solution that integrated Next Generation Prevention System (NGIPS).

How was the initial setup?

There were no issues with setup.

What about the implementation team?

We implemented in-house.

What was our ROI?

We calculated for the entire year, but the ROI seemed very decent from the first six months.

What's my experience with pricing, setup cost, and licensing?

Pricing: Negotiate

Licensing: Buy the advanced Malware Protection license subscription for one year. It is worth the investment.

Which other solutions did I evaluate?

We evaluated Juniper, Fortinet, and Huawei.

Disclosure: My company has a business relationship with this vendor other than being a customer: We are a CISCO Security Business partner
PeerSpot user
PeerSpot user
IT Security Engineer at a financial services firm with 501-1,000 employees
Real User
The packet tracer function provides a packet flow through the firewall and shows which rule or policy can cause a drop.

Valuable Features:

Cisco ASA's CLI is very effective and fast to configure the firewall and make changes, but monitoring logs and connections can be eye bothering by reading all the line outputs. ASDM, however, have improved the overall ASA configuration from an GUI standpoint. I really enjoy the log monitor where I can see live logs in a more user friendly interface. The down side of ASDM is that it is build with JAVA and that means a lot vulnerabilities and it does not always work with the latest JAVA version and/or patches.

Improvements to My Organization:

The packet tracer function, which I use the most, have provided me a packet flow through the firewall and see which rule or policy can cause a drop. Also, I can see if my NAT statement is working properly. This has allowed me to quickly troubleshoot potential firewall related issues for my organization.

Room for Improvement:

L7 firewall is a key for the ASA to be competitive in the current and future market place. By integrating with SourceFire, now call FirePower, on the ASA has helped it to get into the next-generation firewall segment.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Network Security Engineer at a tech services company with 51-200 employees
Real User
A proactive threat defense solution with a good Inline Mode configuration
Pros and Cons
  • "The Inline Mode configuration works really well, and ASA works very impressively."
  • "I think the ASA layer is thin. It's always Layer 3 or Layer 4 source controller and doesn't control the Layer 7 traffic. It's important, and you'll need an additional firewall."

What is our primary use case?

I use it for VPNs, remote-access VPNs, environment issues, and failover issues. I also use the
content mode, NAT, and PAT in this firewall. We always use ASA for VPN sites and firewall sites. We use the edge for internet access for data center servers or company customers' internet access.

How has it helped my organization?

We always use ASA for integration another companies  and branches easily. 

What is most valuable?

The Inline Mode configuration works really well, and ASA works very impressively.

What needs improvement?

I think the ASA layer is thin. It's always Layer 3 or Layer 4 source controller and doesn't control the Layer 7 traffic at all. It's important, and you'll need an additional firewall. 

All next-generation firewalls don't have much control over Layer 7, but there's a little bit of control for inspection. ASA never controlled Layer 7, and it's a bad point.

 I don't like to use ASDM, a graphical interface, and other solutions for ASA. I wouldn't say I like this, and it's not good(ASDM).

For how long have I used the solution?

I have over seven years of experience with Cisco ASA Firewall.

What do I think about the stability of the solution?

It's stable. ASA works very well, and it's impressive. I use only ASA and only the Inline Mode. 

What do I think about the scalability of the solution?

It's a scalable, high availability solution. It's an active/standby model for VPN. But if you don't use VPN in these devices, it works as an active/active high availability model.

How was the initial setup?

If you're a Cisco Administrator or Cisco certified, the initial setup isn't a problem. But if you don't know Cisco devices and how they work, it can get a little complicated.

What other advice do I have?

I would advise new users to look at next-generation firewalls like FTD or other models from Cisco. It's better than Cisco ASA. Cisco ASA Firewall isn't a next-generation firewall.

On a scale from one to ten, I would give Cisco ASA Firewall an eight.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Lead Network Engineer at a tech services company with 51-200 employees
Real User
A recommended firewall solution that is straightforward, stable, and reliable
Pros and Cons
  • "We are mostly using it for remote access, so the remote access feature is the most valuable, but all other features are also needed and required. It is also a very straightforward and reliable solution."
  • "We don't have any serious problems. The firewall models that we have are quite legacy, and they have slower performance. We are currently investigating the possibility of migrating to next-generation firewalls."

What is our primary use case?

We mostly use it for remote access. We also use this firewall between different segments of our enterprise network.

We have legacy models of this solution. We are using models 5510 and 5520.

What is most valuable?

We are mostly using it for remote access, so the remote access feature is the most valuable, but all other features are also needed and required. It is also a very straightforward and reliable solution.

What needs improvement?

We don't have any serious problems. The firewall models that we have are quite legacy, and they have slower performance. We are currently investigating the possibility of migrating to next-generation firewalls.

For how long have I used the solution?

We have been using Cisco ASA Firewall for around one hour and a half years.

What do I think about the stability of the solution?

It is quite stable. We didn't have any issues or crashes, so we find it to be a solid solution.

How are customer service and technical support?

We don't have Cisco support because these models are excellent.

How was the initial setup?

It has moderate complexity. I didn't have any prior experience in configuring these firewalls. That's why I found its initial setup to be of moderate complexity, but now, I have got used to using and maintaining these devices.

What's my experience with pricing, setup cost, and licensing?

We're using the smart license for this firewall. The models that we have require licensing for remote access.

What other advice do I have?

I would absolutely recommend this solution. It is a very straightforward and reliable solution. I would definitely like to propose and offer this solution to other colleagues.

Cisco doesn't have any plans to develop this kind of solution more. Cisco ASA Firewall will not be developed in the future. The next-generation firewall is the next step in the development of the Cisco firewall. For this reason, we are investigating the possibility of migrating to another product.

I would rate Cisco ASA Firewall a nine out of ten. We are very happy with this solution. It is very straightforward and reliable, but it is quite a legacy solution and lacks performance. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
IT Administration at a healthcare company with 11-50 employees
Real User
A stable solution for protecting our edge network, with good technical support
Pros and Cons
  • "The most valuable feature is the access control list (ACL)."
  • "This is an older product and has reached end-of-life."

What is our primary use case?

It provides the firewall and security for our edge network.

We are using a really old ASA device that is at end-of-life, so we're replacing it.

What is most valuable?

The most valuable feature is the access control list (ACL). 

What needs improvement?

This is an older product and has reached end-of-life.

For how long have I used the solution?

We have been using Cisco ASA for probably ten years.

What do I think about the stability of the solution?

This is a very stable product.

What do I think about the scalability of the solution?

We're just a small company, so we have not had to scale it.

How are customer service and technical support?

The technical support is definitely very good.

How was the initial setup?

The initial setup was very straightforward.

What about the implementation team?

Just one person is required for maintenance.

What other advice do I have?

My advice for anybody who is implementing Cisco ASA is that it is not very difficult to deploy and not very difficult to understand how to continue adding more rules to it.

I would rate this solution an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
Coordinator Network Support at a manufacturing company with 501-1,000 employees
Real User
It provides security for our company and users
Pros and Cons
  • "It provides security for our company and users."
  • "The initial setup was complex."

What is our primary use case?

It is our firewall solution. We connect to other locations, as well as use programs in-house.

What is most valuable?

The most valuable feature is the security that it provides our company and users.

Furthermore, our company uses it for making rules for the bank to connect to our server in the DMZ, which is a security challenge.

What needs improvement?

It needs improvement as a "Next-Generation" firewall solution. In addition, it needs to be more user-friendly. 

For how long have I used the solution?

More than five years.

What do I think about the stability of the solution?

There is no downtime, and it is working great. 

What do I think about the scalability of the solution?

It is scalable. We have had no issues. 

What's my experience with pricing, setup cost, and licensing?

The initial setup was complex. But, after that, to maintain and keep creating rules it was easy.

Which other solutions did I evaluate?

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2024
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros sharing their opinions.