Try our new research platform with insights from 80,000+ expert users
it_user579180 - PeerSpot reviewer
Networking Specialist at a insurance company with 1,001-5,000 employees
Vendor
Provides management with the adaptive security device manager.

What is most valuable?

It is good for firewalls, management with the adaptive security device manager (ASDM), and tools such as packet tracers for troubleshooting.

It’s a really good firewall which is easy to manage, but it is not a Next Gen firewall.

Firewall functionality is the main issue when buying this product. We use it to segment our DMZs, it is stateful firewalling, is highly reliable with zero outages, and impeccable failovers during upgrades.

The ASDM is the management tool to administer the ASAs via the GUI. It has an easy to use interface with very nice troubleshooting tools, such as Packet Tracer. This tool lets you simulate a traffic flow so you can see why flows don’t work.

How has it helped my organization?

It is a very reliable border firewall which makes it easy for us to organize and secure our DMZs.

What needs improvement?

  • The SSL VPN portal could be better.
  • The ASAs support both IPSEC as an SSL VPN.
  • For IPSEC you need a Cisco VPN client.
  • You can only have two SSL VPN sessions.
  • For more SSL sessions you have to pay (750 IPSEC sessions are included with an ASA).
  • With SSL, you connect through a browser, so it is clientless. The SSL portal offers a few functionalities which you can offer a user. Configuring this portal is not an easy task.

For how long have I used the solution?

We have been using the solution for almost five years.

Buyer's Guide
Cisco Secure Firewall
June 2025
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.

What do I think about the stability of the solution?

We didn't encounter any issues with stability.

What do I think about the scalability of the solution?

Scalability is limited depending on the chosen model.

How are customer service and support?

I would give technical support a rating of 9/10. Cisco is one of the best, if not the best, in support.

Which solution did I use previously and why did I switch?

We chose FortiGate from Fortinet as our Next Gen Firewall solution because of the higher value for our money.

How was the initial setup?

The setup was easy with lots of documentation and configuration examples provided.

What's my experience with pricing, setup cost, and licensing?

You have to negotiate well.

Which other solutions did I evaluate?

We did not evaluate any alternative options for stateful firewalling.

What other advice do I have?

You will want to have Next Generation functionality, so choose FortiGate or Cisco Firepower.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user456837 - PeerSpot reviewer
Project Manager with 11-50 employees
Real User
It is very robust, trustworthy and highly customizable.

What is most valuable?

It is very robust, trustworthy and highly customizable.

How has it helped my organization?

Solutions using NAT, VPNs, internet and MPLS, are more customizable than other solutions.

What needs improvement?

It could have more functions for load balance on the internet.

For how long have I used the solution?

We have been using the solution for two years.

What do I think about the stability of the solution?

We never had any stability issues. It is the most stable platform that I have used, and I have used several including Fortinet, Sophos, Hillstone, Cisco and D-Link.

What do I think about the scalability of the solution?

We did not encounter any issues with scalability.

How are customer service and technical support?

I would rate the technical support at 10/10. It is the best.

Which solution did I use previously and why did I switch?

I implement solutions on several clients, Redneet is a technology integration company and I prefer Cisco ASA for my security solutions.

How was the initial setup?

The setup is a little more complex than other solutions.

What's my experience with pricing, setup cost, and licensing?

It is a bit more expensive than other solutions, but offers more customization and security than other solutions.

Which other solutions did I evaluate?

We evaluated Fortinet, Sophos, Palo Alto.

What other advice do I have?

Use the best practice guides and online documentation. Cisco has more information online free that any other brand, so use it!!!

Disclosure: My company has a business relationship with this vendor other than being a customer. We are a Cisco Partner.
PeerSpot user
Buyer's Guide
Cisco Secure Firewall
June 2025
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.
Senior Network Designer at ODI
Real User
You can extend your visibility in network infrastructure for monitoring.

What is most valuable?

The Advanced Malware Protection and Security Group Tag (SGT) are valuable features. You are able to integrate all the networks by using SGT with the pxGrid service. This is built-in technology in Cisco devices and services.

How has it helped my organization?

You can extend your visibility in network infrastructure for monitoring. You can absolutely give your users a better experience. When you use .1X for user authentication:

  • Users login just one time
  • You can control all user access to the internet, data center resources, and across the network.

What needs improvement?

After Firepower V6.1, Cisco added bandwidth shaping on the FTD product. This feature is a little bit weak. You cannot have customized shaping in different projects.

For how long have I used the solution?

I have used this product, as well as Cisco Firepower Threat Defense, for about two years.

What do I think about the stability of the solution?

I have heard about some bugs, but I have never encountered any.

What do I think about the scalability of the solution?

This product is very scalable in our experience.

How was the initial setup?

It is easy to initialize. For advanced configurations, it is sometimes complicated.

What's my experience with pricing, setup cost, and licensing?

The base license is delivered with the device. This license includes IPS and user authentication. You should buy a license for an IPS update. You should also buy another license for AMP and URL filtering.

These are the important licenses: BASE, IPS, AMP, and URL filtering. Apart from the base license, the other licenses are subscription based for one, three, or five years.

Which other solutions did I evaluate?

I evaluated many products, such as CheckPoint, Palo Alto, Fortinet Firewall, Sophos, and Cyberoam Firewall.

What other advice do I have?

This product is very usable when you need integrity in your network. This product is very functional when you use a Cisco Identity Services engine.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user349320 - PeerSpot reviewer
Corporate Information Security Officer
Vendor
A standard rule based firewall that has solved many remote access problems.

What is most valuable?

It's a standard rule based firewall for us. The AnyConnect VPN has solved a lot of remote access problems. High availability is good. It will fall back to the other ASA without any disruptions.

How has it helped my organization?

It has secured our DMZ.

What needs improvement?

I would like to see the following made easier:

  • Objects
  • Removing objects
  • Correlating access rules and AnyConnect ACLs

Sometimes we suffer from older versions, such as objects, object groups, and aliases (name).

For how long have I used the solution?

We have been using the solution for nine years.

What do I think about the stability of the solution?

We did not encounter any stability issues.

What do I think about the scalability of the solution?

We did not encounter any scalability issues.

How are customer service and technical support?

The technical support is good.

Which solution did I use previously and why did I switch?

We used Cisco PIX.

How was the initial setup?

I can't really remember the setup. It was too long ago.

What's my experience with pricing, setup cost, and licensing?

We bought the solution, so there were no real recurring costs at that time.

Which other solutions did I evaluate?

We didn't evaluate any alternative products.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Network Security Consultant at a tech services company with 51-200 employees
Real User
It allows us to filter incoming traffic to our network and provide a secure access to office network from outside through remote access VPN.

What is most valuable?

Cisco ASA is a stateful firewall which means they are the fastest and more secure, because they maintain state tables. Cisco ASA is very efficient not only in Firewalling but in VPNs, IPS and content filtering. It also has option of failover and redundancy.

How has it helped my organization?

It allows us to filter incoming traffic to our network and provide a secure access to office network from outside through remote access VPN. We also connected our branch office through IPSEC site-to-site VPN tunnel which is very secure and reliable.

What needs improvement?

Some improvements required on GUI interface called ASDM. It should include health check parameters like temperature, memory used.

For how long have I used the solution?

I am using it more than five years.

What was my experience with deployment of the solution?

No issues, very easy to deploy.

What do I think about the stability of the solution?

No.

What do I think about the scalability of the solution?

Migration to new version is very easy, therefore no issue.

How are customer service and technical support?

Customer Service:

9/10.

Technical Support:

9/10.

Which solution did I use previously and why did I switch?

Cisco ASA firewall is most reliable to protect the network, therefore I switched.

How was the initial setup?

Yes, straightforward and simple.

What about the implementation team?

I am also vendor.

What was our ROI?

100%.

What's my experience with pricing, setup cost, and licensing?

Price is bit high as compared to other vendors, but Cisco ASA has reputation and most reliable product. Always go with minimum security plus license.

Which other solutions did I evaluate?

Yes, Fortinet and Palo Alto.

What other advice do I have?

No.

Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller.
PeerSpot user
PeerSpot user
Founder, CEO, & President at Krystal Sekurity
Consultant
Simplified the complexity of our security architecture.

What is most valuable?

Provides advanced malware capabilities.

How has it helped my organization?

Simplified the complexity of our security architecture.

What needs improvement?

Integration of advanced malware services with the firewall through Firepower services.

For how long have I used the solution?

We have been using this solution for six months.

What was my experience with deployment of the solution?

There were no issues with deployment.

What do I think about the stability of the solution?

There were no issues with stability.

What do I think about the scalability of the solution?

There were no issues with scalability.

How are customer service and technical support?

Customer Service:

I would give customer service a rating of 10/10.

Technical Support:

I would give technical support a rating of 10/10.

Which solution did I use previously and why did I switch?

We were looking to upgrade to a comprehensive firewall solution that integrated Next Generation Prevention System (NGIPS).

How was the initial setup?

There were no issues with setup.

What about the implementation team?

We implemented in-house.

What was our ROI?

We calculated for the entire year, but the ROI seemed very decent from the first six months.

What's my experience with pricing, setup cost, and licensing?

Pricing: Negotiate

Licensing: Buy the advanced Malware Protection license subscription for one year. It is worth the investment.

Which other solutions did I evaluate?

We evaluated Juniper, Fortinet, and Huawei.

Disclosure: My company has a business relationship with this vendor other than being a customer. We are a CISCO Security Business partner
PeerSpot user
PeerSpot user
Principal Network Engineer at a tech services company with 51-200 employees
Consultant
Provides the capability of the higher end firewall products to handle most network tasks without issues.
Pros and Cons
  • "It makes it very easy to have delineated roles and responsibilities between network engineering and network security."
  • "In my experience, a number of engineers get tunnel vision with devices. This is exacerbated by vendors fostering a silo mentality in disciplines."

How has it helped my organization?

It makes it very easy to have delineated roles and responsibilities between network engineering and network security.

What is most valuable?

I find the overall capability of the higher end firewall products to handle most network tasks without any issues. In addition, it is easy to train lower level help desk personnel on the GUI management.

What needs improvement?

People tend to think of firewalls as firewalls and routers as routers. Going by the book, I had to create a number of static routes in the firewall so it could reach the various subnets in my client's internal network. I decided to turn on OSPF routing to simplify my deployment. This resolved a lot of issues with remote VPN and site-to-site VPN tunnels.

In my experience, a number of engineers get tunnel vision with devices. This is exacerbated by vendors fostering a silo mentality in disciplines.

I cannot name the organization, but a large national non-profit in the medical field had too many network configuration problems because of the silo mentality.

Large Cisco ASA units have the capability to act as routers. This particular non-profit would not enable routing on the ASA until I explained that it resolve a number of issues that they were experiencing and resolving by static routes, a second Cisco ASA, and a proxy server.

What do I think about the stability of the solution?

Stability issues did not occur in my experience, as long as we stayed with the correct image builds.

What do I think about the scalability of the solution?

There were no scalability issues.

How is customer service and technical support?

Customer Service:

Generally, we do not need customer support, so it is hard to rate.

Technical Support:

Generally we do not need technical support, so it is hard to rate.

How was the initial setup?

The initial setup at many clients' sites was straightforward. Very complicated networks take a lot of planning.

What about the implementation team?

We implemented the solution in-house.

What was our ROI?

We cannot determine ROI just yet.

What's my experience with pricing, setup cost, and licensing?

Always plan ahead for three years. In other words, do not buy a firewall on what your needs are today, but try to predict where you will be three years from now in terms of bandwidth, security requirements, and changes in organizational design. This applies to any vendor, not just this product. I find that I always need to buy a higher level product than the specifications request in order to be safe.

Which other solutions did I evaluate?

In locations where I have used Cisco ASA firewalls, I have compared FortiGate and SonicWall.

What other advice do I have?

I utilize different brands of firewalls depending on the needs of a client, i.e., in-house IT versus outsourced. I am vendor agnostic as much as possible.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Kiarash Barzoodeh - PeerSpot reviewer
Kiarash BarzoodehSenior Network Designer at ODI
Real User

hello
respectfully, you are right about routing, Cisco ASA is a best firewall that support routing. however, in best practices offer: do not use firewall as router and also is better to use firewall as transparent mode. because technically firewall designed for access control or something like that, so in high routing environment, sometime firewall cannot handle routing as router.

PeerSpot user
Network Security Coordinator at a energy/utilities company with 1,001-5,000 employees
Real User
We decided to go with Cisco because stability and reliability were major concerns for us.

What is most valuable?

Outstanding NGFW capabilities, Site to site VPNs and High Availability. Also the integration of FirePOWER services (Web Filtering/IPS/Malware Protection) are a huge step forwards for an already great platform.

How has it helped my organization?

We purchased a pair of ASAs to handle all perimeter traffic in and out of our network. This devices enabled us to secure all our perimeter traffic, WAN connections, Internet connectivity and Internet facing services. FirePOWER services enabled better control and visibility over the traffic traversing our perimeter. High Avalability helped us greatly improve the availability of the services by reducing downtime caused by both Incidents and planned maintenance operations.

What needs improvement?

Only problem in my opinion is ease of use. You really need to know your way around the CLI and complex feature set to get things working. The ASDM GUI is good for some things but for the most part you'll need to stick to the CLI which is a bit difficult specially if you don't have a lot of experience around Cisco equipment.

For how long have I used the solution?

We've operated this firewalls for around 2 years now.

What was my experience with deployment of the solution?

ASAs are as complex as they are powerful. Configuration and administration are not as straightforward as other solutions and will take some time and studying to get used to them.

What do I think about the stability of the solution?

In my experience with various Firewall solutions, the stability and reliability of Cisco ASAs is unparalleled.

What do I think about the scalability of the solution?

No

How are customer service and technical support?

Customer Service:

Cisco offers great customer service.

Technical Support:

The best I have worked with.

Which solution did I use previously and why did I switch?

We used to have a SonicWall and an older ASA 5510 platform. Both were replaced by a Cisco ASA cluster using a pair of 5525x.

What's my experience with pricing, setup cost, and licensing?

ASAs are expensive. The initial cost is high compared to other similar solutions, and chances are the personnel that will operate them will require some training. But if you're aiming for stability and reliability, this is the best solution you will find.

Which other solutions did I evaluate?

We evaluated Fortinet and SonicWall, both great UTM vendors. Although those platforms are cheaper, we decided to go with Cisco because stability and reliability were mayor concerns for us, also the support is much better in my experience.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user326337 - PeerSpot reviewer
it_user326337Customer Success Manager at PeerSpot
Real User

Great to know, sounds like you've really had a great experience with ASA. How do you expect these enhancements to help your productivity and/or security in the long term?

See all 3 comments
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2025
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros sharing their opinions.