Try our new research platform with insights from 80,000+ expert users
PeerSpot user
Information Technologies Consultant at a tech services company
Consultant
Jun 20, 2018
Everything is based on high securities standards
Pros and Cons
  • "It joins all branches and permits employees to work outside their offices, but everything is based on high securities standards (PCI compliance)."
  • "It joins all branches and permits employees to work outside their offices, but everything is based on high securities standards (PCI compliance)."
  • "Multiple WAN connections: Even though you can implement more than one interface to outside connections, it is lacking on load balances, etc."
  • "Multiple WAN connections: Even though you can implement more than one interface to outside connections, it is lacking on load balances, etc."

What is our primary use case?

Some branches are joint through Cisco ASA 5500-X VPNs. Executives or employees are connected via AnyConnect.

How has it helped my organization?

It joins all branches and permits employees to work outside their offices, but everything is based on high securities standards (PCI compliance).

What is most valuable?

  • Reliability
  • Robustness
  • Security features
  • High encryption, hashing, and integrity support
  • Support
  • High performance

What needs improvement?

Multiple WAN connections: Even though you can implement more than one interface to outside connections, it is lacking on load balances, etc.

Buyer's Guide
Cisco Secure Firewall
March 2026
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,286 professionals have used our research since 2012.

For how long have I used the solution?

Three to five years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer820269 - PeerSpot reviewer
IT Manager with 51-200 employees
User
Jun 14, 2018
Once configured to suit your needs, these firewalls are rock solid appliances
Pros and Cons
  • "Once configured to suit your needs, these firewalls are rock solid appliances."
  • "These firewalls are not for beginners."

These firewalls are used in enterprise level environments, which require granular control and customization to meet security and compliance guidelines for an organization. Once configured to suit your needs, they are rock solid appliances. 

These firewalls are not for beginners. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Cisco Secure Firewall
March 2026
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,286 professionals have used our research since 2012.
it_user886188 - PeerSpot reviewer
Presales Engineer
Real User
Jun 13, 2018
Monitoring via the dashboard enables customers to see what is happening in the system
Pros and Cons
  • "According to them, it's working perfectly."
  • "It's lacking one feature: VPN. Also, the 2100 Series lacks a DDoS feature. If they could add that to those platforms, that would be good."
  • "In terms of scalability, it is really expensive. It is scalable, but when it comes to pricing, the upgrading is a bit high."

What is our primary use case?

The use case has been for the banking sector, for one of our banking customers. According to them, it's working perfectly.

What is most valuable?

Monitoring, of course - the dashboard. It enables you to see what is happening.

What needs improvement?

It's lacking one feature: VPN. That is a feature we're looking for. Otherwise, the new devices have very good support, and the performance is quite good.

Also, the 2100 Series lacks a DDoS feature. If they could add that to those platforms, that would be good.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

So far, since we installed it, there have been no issues.

What do I think about the scalability of the solution?

In terms of scalability, it is really expensive. It is scalable, but when it comes to pricing, the upgrading is a bit high.

How was the initial setup?

It's not straightforward. You need to know what you're doing, you need to be trained. I don't know for other vendors whether it's the same issue, but for Cisco you have to be trained on the system.

Which other solutions did I evaluate?

Check Point and Fortigate. Generally, our customers choose Firepower because they've seen the system work somewhere before, and they see it is stable and working perfectly. Those are the reasons they opt for Firepower.

What other advice do I have?

There are other solutions, like Fortigate, which are very good solutions, and cheaper for the customer. Even the support via subscription is favorable, in terms of pricing. I would really advise the customer to do some research first and come up with the best solution for their needs

I rate Firepower as an eight out of 10. It is a good solution but it is expensive compared to other products, like Fortigate. Still, some of our customers do prefer Firepower over the others.

Disclosure: My company has a business relationship with this vendor other than being a customer. Solutions provider/integrator.
PeerSpot user
it_user806910 - PeerSpot reviewer
Manager at SAP
Real User
Jun 11, 2018
A nice GUI, but poor performance
Pros and Cons
  • "Cisco ASA has an okay CLI with a nice GUI."
  • "It has poor performance."

Cisco ASA has an okay CLI with a nice GUI, but has poor performance.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
IT Infrastructure Engineer at Atlas
Real User
Top 5
Jun 10, 2018
My confidence continues to build upon using Cisco firewalls
Pros and Cons
  • "My confidence continues to build upon using Cisco firewalls."
  • "My confidence continues to build upon using Cisco firewalls."
  • "Antivirus features must be integrated for end user security."
  • "Security must be increased when a new user connects over the LAN and an alarm must be generated."
  • "Antivirus features must be integrated for end user security."

How has it helped my organization?

My confidence continues to build upon using Cisco firewalls. I prefer to use Cisco firewalls to any others. 

What needs improvement?

Antivirus features must be integrated for end user security. They must be increased in the next version along with audit and restriction for the incoming user. Security must be increased when a new user connects over the LAN and an alarm must be generated.

For how long have I used the solution?

Three to five years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Supervisor of Computer Operations at Neil McFadyen
User
May 31, 2018
Setting up rules for HTTPS and SSH access to the management interface are straightforward
Pros and Cons
  • "I am used to the ASA syntax, therefore it is quite easy to make up new rules. I have found that DNS doctoring rules are useful."
  • "I found that setting up rules for HTTPS and SSH access to the management interface are straightforward, including setting the cypher type."
  • "Most of same old ASA 5520 config could be used for the new 5516-X model."
  • "10Gb interfaces should be available on more models."
  • "It is surprising that you need to have a virtual appliance for the Firepower Management Center. It is not good if you have to setup a VMware server just for it."
  • "It is confusing to have two management interfaces, e.g., ASDM and Firepower Management Center."
  • "It is surprising that you need to have a virtual appliance for the Firepower Management Center. It is not good if you have to setup a VMware server just for it."

What is our primary use case?

We use it for our university department firewall. It replaced our 12-year-old Cisco ASA 5520, which used to protect web servers, mail servers, SVN repositories, office computers, research computers, and computer labs. It was used for blocking the internet for exams. It was not used for IPS, so we did not buy the new threat protection or malware license. We connected it to a Layer 3 switch for faster Inter-VLAN routing.

How has it helped my organization?

It works better through specs than our old ASA 5520. It seems to perform the same functionality unless you buy the additional threat protection licenses, so this is a disappointment. I found a bug where the ASDM could not be used with Windows 2016, but it did work with Windows 10.  

What is most valuable?

  • Most of same old ASA 5520 config could be used for the new 5516-X model. The ASDM interface is improved and can also be configured to the Firepower settings. 
  • I am used to the ASA syntax, therefore it is quite easy to make up new rules. I have found that DNS doctoring rules are useful, and I am not sure how other firewalls handle the issue of internal versus external DNS, so this was a reason to keep the same type of firewall.
  • Customizing logging event of syslog to feed into Splunk is very useful for management and monitoring just for the importance events instead of a huge stream of thousands of unneeded events.
  • I found it quite easy to block computers from the internet, e.g, in a computer lab with students doing an exam using software for the course when needed.
  • I use access to a list to block IPs which have attacked our web servers on the outside interface, since I do not have IPS.
  • I found that setting up rules for HTTPS and SSH access to the management interface are straightforward, including setting the cypher type.
  • It is very useful to use the command line interface for modifying or adding to the config because sometimes the ASDM interface is hard to find when the setting is more complicated.
  • The text config file is great to have, to know what is in the config, instead of having to check every setting in the GUI.
  • While the CLI is used the most, sometimes the ASDM is faster and easier to use to set some settings.

What needs improvement?

  • It is confusing to have two management interfaces, e.g., ASDM and Firepower Management Center. It would be nice to have a Windows program instead of a virtual appliance for the Firepower Management Center.  The ASA and Firepower module seem redundant, not sure which one to set the rules in, but maybe that was for backward compatibility. I am not sure that is very useful.
  • It is surprising that you need to have a virtual appliance for the Firepower Management Center. It is not good if you have to setup a VMware server just for it.
  • 10Gb interfaces should be available on more models. 

For how long have I used the solution?

Still implementing.

What's my experience with pricing, setup cost, and licensing?

ASA pricing seems high compared to other firewalls, such as the Sophos XG models. 

The licensing features are getting more complicated. These should be simplified. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Bob Wholley - PeerSpot reviewer
Bob WholleyTitleSr. Systems Engineer at a tech company with 5,001-10,000 employees
Real User

Have you checked out Fortinet's Fortigate UTM appliances and Security Fabric? They wiill save you money and provide more security.

PeerSpot user
Sales Manager at Entiresoft Technologies Pvt Ltd
Real User
Top 20
May 30, 2018
VPN load balancing has been essential for my connections to integrate via multiple time zones
Pros and Cons
  • "VPN load balancing has been particularly essential for my connections to integrate via multiple time zones."
  • "Our content, which is the main asset for our firm, is pretty elusive behind the firewall of Cisco ASA."
  • "I needed to be well-versed with all the command lines for Cisco ASA in order to fully utilize it. I missed this info and wasted some operational costs."
  • "I needed to be well-versed with all the command lines for Cisco ASA in order to fully utilize it. I missed this info and wasted some operational costs."

What is our primary use case?

I am using Cisco ASA as the firewall for my business to guard the boundary of my business. It has been very helpful in my sector of media with my clients, essentially focusing on how secure their data is, especially when we are working on a few projects which involve multiple citations across Europe. 

Our content, which is the main asset for our firm, is pretty elusive behind the firewall of Cisco ASA.

How has it helped my organization?

It has improved my client's trust. 

What is most valuable?

VPN load balancing: This has been particularly essential for my connections to integrate via multiple time zones.

What needs improvement?

I needed to be well-versed with all the command lines for Cisco ASA in order to fully utilize it. I missed this info and wasted some operational costs. I would like to advise others to please be wary from the start.

For how long have I used the solution?

Less than one year.

What was our ROI?

It was initially heavy on my pocket, but it soon actualised its worth.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
‎Senior Vice President at a transportation company with 51-200 employees
Real User
May 27, 2018
Enables securing of various network segments based on use, but there are integration issues
Pros and Cons
  • "Valuable features include DMZ segmentation, and IDS and IPS."
  • "Tech support has been good."
  • "Cisco suffers from some integration issues with other products... There is a problem with the Cisco Catalyst Switches in terms of assembling bursts and having them interact properly with the Cisco Firepower."
  • "Some of the tools are still a little bit difficult to use."

What is our primary use case?

We use it as a firewall and it has performed adequately.

How has it helped my organization?

It allows the securing of various network segments, based on use.

What is most valuable?

DMZ segmentation, and IDS and IPS.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

It is fairly stable. However, Cisco suffers from some integration issues with other products, but this product, as a standalone, is fine. There is a problem with the Cisco Catalyst Switches in terms of assembling bursts and having them interact properly with the Cisco Firepower.

What do I think about the scalability of the solution?

The scalability is good.

How are customer service and technical support?

Tech support has been good.

Which solution did I use previously and why did I switch?

We've been using Cisco. Prior to this it was Cisco ASA. This was the next evolution.

When selecting a vendor it is important that they have positive industry feedback, that they are a visionary leader.

How was the initial setup?

I was involved in the initial set up and it was complex.

What other advice do I have?

I give this solution a seven out of 10. Some of the tools are still a little bit difficult to use.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2026
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros sharing their opinions.