it_user874149 - PeerSpot reviewer
Tehcnician at Belize Telemedia Limited
User
ASDM has made configuring ASA easy. No need to memorize CLI commands.
Pros and Cons
  • "ASDM provides GUI for configurations. The ASDM has made configuring ASA easy. No need to memorize CLI commands."
  • "Ease of configuration: It has gotten a lot easier to configure compared to the original Cisco Pix."
  • "The ASA has become a bit old and needs updating."
  • "UTM features would be nice or some NextGen features."

What is our primary use case?

Remote network access: We primarily use ASA for VPN, NAT, PAT routing, SLA, and multiple ISP providers.

How has it helped my organization?

Ease of configuration: It has gotten a lot easier to configure compared to the original Cisco Pix.

What is most valuable?

ASDM provides GUI for configurations. ASDM has made configuring ASA easy. No need to memorize CLI commands.

What needs improvement?

  • UTM features would be nice or some NextGen features. 
  • The ASA has become a bit old and needs updating.
Buyer's Guide
Cisco Secure Firewall
May 2024
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
770,141 professionals have used our research since 2012.

For how long have I used the solution?

One to three years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user413292 - PeerSpot reviewer
Regional Manager - Pre Sales at a tech services company with 51-200 employees
Consultant
Helps us to identify key, persistent threats so we can set policies accordingly
Pros and Cons
  • "Its in-depth monitoring and analysis help us to make better decisions and policies."
  • "Integration aspects and traffic shaping need improvement."
  • "Initial setup can be complex. It is complex. We have to set up ASA, SFR module, and FMC separately, which sometimes requires extensive troubleshooting, even for smaller issues."

How has it helped my organization?

It helps us to identify key, persistent threats so we can set policies accordingly.

What is most valuable?

In-depth monitoring and analysis. It helps us to make better decisions and policies.

What needs improvement?

  • Integration aspects
  • Traffic shaping

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

Initially there were some stability issues, but in the long-run no.

What do I think about the scalability of the solution?

It requires additional licensing to enable 10G ports.

How is customer service and technical support?

Technical support is very good.

How was the initial setup?

It is complex. We have to set up ASA, SFR module, and FMC separately, which sometimes requires extensive troubleshooting, even for smaller issues.

Which other solutions did I evaluate?

We evaluated Huawei, briefly.

What other advice do I have?

It is a good datacenter firewall, as they have now overcome integration issues with latest versions.

Disclosure: My company has a business relationship with this vendor other than being a customer: Cisco Premier Partner.
PeerSpot user
Buyer's Guide
Cisco Secure Firewall
May 2024
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
770,141 professionals have used our research since 2012.
it_user682167 - PeerSpot reviewer
Network and System Engineer at a non-tech company with 201-500 employees
Vendor
IPS features can be accessed from a separate interface

What is most valuable?

I enjoy the interface of Cisco products, especially the CLI version. I think the IPS feature in the product is best compared to products of other vendors. All the IPS features can be accessed from a separate interface, e.g., Cisco IDM.

How has it helped my organization?

We are an educational institute, and we are required to block many websites that are not suitable for students and teachers. Most of the sites, like YouTube uses an https version, thus blocking with IP address was becoming problematic. Moreover, certificate domains for Gmail and YouTube are the same. But the IPS feature in this product helps us to overcome this limitation.

What needs improvement?

Pricing of this product needs improvement.

For how long have I used the solution?

I have used this solution for two years.

What do I think about the stability of the solution?

I did not encounter any issues with stability.

What do I think about the scalability of the solution?

I did not encounter any issues with scalability.

How are customer service and technical support?

I would give technical support a rating of a nine out of 10.

Which solution did I use previously and why did I switch?

I worked with Cyberoam and Fortinet UTM at my previous job. When I joined my present company, they were already using the Cisco ASA solution. But my present company may switch to other vendors, especially Fortinet, because of the license renewal price.

How was the initial setup?

As I enjoy working on CLI, I would say that the initial setup was not complex.

What's my experience with pricing, setup cost, and licensing?

License and appliance costs are more expensive as compared to other vendors on the market.

What other advice do I have?

If your company is small or mid-range, it is better to go with other vendors, because of the pricing.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user470943 - PeerSpot reviewer
ICT Manager - Network Operations at a healthcare company
Vendor
​Pricing is competitive and licensing cost is on the higher side for non-profit organizations​.

What is most valuable?

Firewall, VPN and Single Sign On.

How has it helped my organization?

Remote Access and SSO Authentication.

For how long have I used the solution?

One year.

What do I think about the stability of the solution?

No.

What do I think about the scalability of the solution?

Not yet.

How are customer service and technical support?

Good.

Which solution did I use previously and why did I switch?

Watchguard Firewall. Switched due to license cost.

How was the initial setup?

A bit complex compared to Watchguard Firewall.

What's my experience with pricing, setup cost, and licensing?

Pricing is competitive but licensing cost is on the higher side for non-profit organizations.

Which other solutions did I evaluate?

If so, which ones? Yes, Checkpoint, Juniper, Cyberoam.

What other advice do I have?

Cisco is good. Look at your requirements and create a matrix to figure out the best option.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user400626 - PeerSpot reviewer
Senior Network & Data Communication Engineer at a tech services company with 201-500 employees
Consultant
​Most valuable features are Security, Routing and NAT.

What is most valuable?

Security, Routing and NAT.

How has it helped my organization?

Gives flexibility and several deployment options.

What needs improvement?

Some default inspection rules need better tuning. Focus development on CLI version.

For how long have I used the solution?

11 years.

What do I think about the stability of the solution?

Rarely.

What do I think about the scalability of the solution?

Yes, before Clustering was introduced.

How are customer service and technical support?

Nine out of 10.

Which solution did I use previously and why did I switch?

Yes. We changed for no special reason, just to mix things up.

How was the initial setup?

Yes, but you need to read and understand how the device functions before deployment.

What's my experience with pricing, setup cost, and licensing?

Like with all vendors, know what options you require and request the proper license accordingly. Prices are on the same level as competitors.

Which other solutions did I evaluate?

Not really, as all firewalls do most of what enterprises look for. What matters most is the after sales support.

What other advice do I have?

Read, read, read and understand your requirements beforehand.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user349320 - PeerSpot reviewer
Corporate Information Security Officer
Vendor
A standard rule based firewall that has solved many remote access problems.

What is most valuable?

It's a standard rule based firewall for us. The AnyConnect VPN has solved a lot of remote access problems. High availability is good. It will fall back to the other ASA without any disruptions.

How has it helped my organization?

It has secured our DMZ.

What needs improvement?

I would like to see the following made easier:

  • Objects
  • Removing objects
  • Correlating access rules and AnyConnect ACLs

Sometimes we suffer from older versions, such as objects, object groups, and aliases (name).

For how long have I used the solution?

We have been using the solution for nine years.

What do I think about the stability of the solution?

We did not encounter any stability issues.

What do I think about the scalability of the solution?

We did not encounter any scalability issues.

How are customer service and technical support?

The technical support is good.

Which solution did I use previously and why did I switch?

We used Cisco PIX.

How was the initial setup?

I can't really remember the setup. It was too long ago.

What's my experience with pricing, setup cost, and licensing?

We bought the solution, so there were no real recurring costs at that time.

Which other solutions did I evaluate?

We didn't evaluate any alternative products.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Senior Technical Consultant - Network and Security at a tech services company with 51-200 employees
Consultant
It provides our company with security and protection on all our devices, but we had some issues during deployment.

Valuable Features

  • It provides our company with security and protection on all our devices.
  • It's highly available.

Improvements to My Organization

We're able to implement best security practices to secure our company data.

Use of Solution

We've used it for over seven years.

Deployment Issues

We had some issues during deployment.

Stability Issues

No issues encountered.

Scalability Issues

No issues encountered.

Customer Service and Technical Support

Customer Service:

Customer service is excellent.

Technical Support:

Technical support is excellent.

Initial Setup

It was a little complex, but not so much that we couldn't figure it out.

Implementation Team

I was the implementor for a client.

ROI

It's excellent.

Other Solutions Considered

Depends on the customer's budget, but we evaluate all vendors that meet the them. It's a mission-critical product.

Other Advice

I give it a thumbs up.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Senior Presales Engineer at a tech services company with 501-1,000 employees
Consultant
The various NGFW and NGIPS features are valuable, but the option to use ASA to decrypt SSL would be an improvement.

What is most valuable?

NGFW: VPN (IPSec, SSL), NAT (provides great flexibility)

NGIPS: Application visibility, file policies (store files), network discovery, correlation features

What needs improvement?

SSL decryption for modules. Although I think it is better to separate SSL decryption as a service from the software module since it requires additional hardware, but I think it would be great if there is an option to use the ASA (not the software module) to decrypt the SSL.

Ex: Add a license to decrypt SSL traffic on the ASA itself. The ASA already supports SSL VPN. So if SSL decryption can be integrated that would be nice.

For how long have I used the solution?

5 years+

What was my experience with deployment of the solution?

Basic setup is easy, but if you need to do some advanced stuff, it can be intuitive, but some things require some kind of tutorial to understand how it can be done. Good thing is that this device is becoming popular and there are many 3rd party free tutorials and guides that can help.

What do I think about the stability of the solution?

I heard about defect that were encountered by my colleagues, but not something that cannot be fixed using an upgrade.

What do I think about the scalability of the solution?

Clustering is available for ASA with firepower services.

Also for firepower appliances, there is stacking available for some models.

How are customer service and technical support?

Customer Service:

Great support. The engineers know what they are doing.

Technical Support:

10/10

Which solution did I use previously and why did I switch?

No

How was the initial setup?

Well, it is straight forward as long as you understand the components available.

ASA can be configured using the CLI or ASDM.

For the Firepower you will need to use a FireSIGHT as a management solution.

Since you will be using two GUIs, I wouldn't call it straight forward.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2024
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros sharing their opinions.