Try our new research platform with insights from 80,000+ expert users
it_user560229 - PeerSpot reviewer
Security Engineer at a healthcare company with 1,001-5,000 employees
Vendor
I especially value Change Management and Compliance. They are most valuable because we are required to comply with regulations - PCI and HIPAA.

What is most valuable?

I especially value Change Management and Compliance. They are most valuable because we are required to comply with regulations regarding credit card processing (PCI) and protecting patient data (HIPAA).

How has it helped my organization?

This product has made visible some areas that were previously hidden.

What needs improvement?

There are many areas for improvement despite the fact that we love the product, but because it is a newer version we’ve been working out lots of issues. Some of those issues are based on our environment.

For how long have I used the solution?

I have used the product for 1.5 years with nearly a year for this version.

Buyer's Guide
Cisco Secure Firewall
June 2025
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.

What do I think about the stability of the solution?

We did not have any problem with the previous (v7) version but when we upgraded to (v8) the new version, we were well aware that there would be some bugs and issues that would require resolution.

What do I think about the scalability of the solution?

We have had no scalability issues.

How are customer service and support?

Tech Support is awesome. I never get someone who has no clue what they are doing. These guys are well trained and know their stuff.

Which solution did I use previously and why did I switch?

We did not use a previous solution. FireMon was implemented as part of a security mandate and we chose this product over its competitors.

How was the initial setup?

Setup was pretty simple, because we implemented the single server model.

What's my experience with pricing, setup cost, and licensing?

We purchased licenses for our High Availability (HA) devices as well but they were not really needed.

Which other solutions did I evaluate?

I was not the researcher and decision maker. I inherited the tool.

What other advice do I have?

To make sure they have the cooperation of the networking team that supports the firewalls. It has been difficult for us to get the tool working to its full potential because our network team is resistant to some of the things we want to monitor.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
PeerSpot user
Manager of Engineering with 1,001-5,000 employees
Vendor
The FirePower IPS, AMP and URL filtering add value to the firewall.

What is most valuable?

Cisco ASA has a well-written command-line interface. Cisco’s AnyConnect SSL VPN is by far the best client VPN technology I’ve ever had to deploy and manage. Upgrades are a breeze. Failovers between units are flawless. FirePower add-ons deepen security with intrusion prevention (IPS), anti-malware protection (AMP), and URL filtering. These particular services can run as a hardware or software module within the ASA. Unlike ASA with CSM, these modules are managed by FireSight, a single pane for all of your FirePower nodes. It’s intuitive and easy to use, but still lacks some automation capabilities (e.g., bulk edits, etc.).

How has it helped my organization?

Cisco is a huge name in the networking world. Having a solution that includes their firewall technology adds value from an operability and support perspective. Cisco, although sometimes considered to be "behind the times" with firewall technology, continues to prove it has momentum in the industry through acquisitions such as Sourcefire and OpenDNS, with rapid integration into their systems. Additionally, ASA is synergistic with other security offerings from Cisco, such as ISE, remote tele-office workers, etc.

What needs improvement?

When running multiple firewalls in your network, you need someone to manage them from a central point. Cisco’s answer is Cisco Security Manager (CSM). Unfortunately, this is a suite of applications that is in much need of an overhaul. It is riddled with bugs and lacks the intuitive experience found in competing vendor offerings. The counter-intuitive interface makes configuration management cumbersome and prone to mistakes. There are software defects within certain modules of the application, resulting in a frustrating experience. Reporting is almost useless. The best part about it is the logging component, but it still is lacking, compared to what you get from other competing vendors.

Aside from management, I think Cisco needs to become more application-focused, something that a few of their competitors shine in.

For how long have I used the solution?

I've deployed and managed Cisco ASA's for over a decade. I've used the X-series models for about three years now.

What do I think about the stability of the solution?

I have not encountered any stability issues; this is a solid firewall platform. Stability is where it shines.

What do I think about the scalability of the solution?

The newer clustering capabilities have introduced some solid scalability design options. From a cost perspective, scalability is quite intimidating.

How are customer service and technical support?

Cisco's TAC engineers are competent, responsive and typically resolve issues in a timely fashion. Do not use them for "best practice"; this is what channel partners are for.

Which solution did I use previously and why did I switch?

I previously used Check Point. Check Point relied on a thick, Windows-based client and, at the time, did not support transparent contexts. However, Check Point has a solid management platform, which is something Cisco should take some pointers from.

How was the initial setup?

Initial setup is complex for a new user, straightforward for a seasoned user. Tons of documentation is available, but you can easily get lost for days if you've never touched one. Cisco offers ASDM, a GUI wizard that can help set up the firewalls. This is nice for newer folks.

What's my experience with pricing, setup cost, and licensing?

Work very closely with your channel partners to verify you have all the licensing you need (VPN, Firepower, etc.). Pricing is always a challenge. Buy closer to Cisco's EOY and you might save a few bucks.

Which other solutions did I evaluate?

Before choosing this product, I also evaluated Palo Alto. I really liked their firewall platform, their Panorama management platform, and wildfire technology. Their SSL VPN was seriously lacking. This is a decent option to consider as well.

What other advice do I have?

Read the Cisco Validated Designs (CVDs) regarding ASAs. Find some decent blogs, discuss topologies and scenarios with a seasoned engineer, and get your final design validated by Cisco. Your Cisco SE should be able to assist with this. If you need assistance implementing, work with your channel partner.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user68991 - PeerSpot reviewer
it_user68991Manager of Engineering with 1,001-5,000 employees
Vendor

Brian, this is one reason I continue to use ASA. Cisco makes a solid, stable and consistent firewall platform. It withstands time and continues to be a widely deployed firewall in the industry.

ASDM is great for a single firewall management, but once you want to manage multiple firewalls at once, you're limited in your offerings from Cisco. I'm hopeful for the future with their plans for FXOS, consolidating these seemingly disparate services (ASA, IPS, VPN) into a single platform.

ASA and IOS teams are definitely separate within Cisco. I don't think these CLIs will ever merge, but we can dream.

See all 5 comments
Buyer's Guide
Cisco Secure Firewall
June 2025
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.
PeerSpot user
Middle-Tier Admin Integrator at a tech services company with 51-200 employees
Real User
Cisco firewalls can be difficult at first but once learned it's fine.

What is most valuable?

Robustness

How has it helped my organization?

Reliability

What needs improvement?

No idea -- I learn a lot from them

For how long have I used the solution?

From 2000 until 2014

What was my experience with deployment of the solution?

Learning at the beginning

What do I think about the stability of the solution?

Nope -- If well planed you should be alright

What do I think about the scalability of the solution?

Price maybe...

How are customer service and technical support?

Customer Service:

Excellent

Technical Support:

Excellent

Which solution did I use previously and why did I switch?

Not reliable for long term -- seem inferior quality

How was the initial setup?

Depends on the product and the knowledge. Cisco firewalls can be difficult at first but once learned it's fine.

What about the implementation team?

Me, I implemented the firewalls, Cisco switches and routers.

What was our ROI?

100% in some installations it exceeded the time predicted to keep up with the work load.

Which other solutions did I evaluate?

Netscreen, Netgear, Checkpoint, others..

What other advice do I have?

Plan well the hardware requirements for future growth and heavy usage.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user4401 - PeerSpot reviewer
it_user4401Developer at a transportation company with 1,001-5,000 employees
Vendor

Can you tell me, please, how does an ASA learn about the MAC address of the host? Thank you.

it_user387540 - PeerSpot reviewer
I.T. Security/Projects Specialist at a tech services company with 501-1,000 employees
Consultant
We wanted a back-end/internal firewall solution, and this provided it for us.

What is most valuable?

Firewalling is the most valuable feature. We wanted a back-end/internal firewall solution, and the Cisco ASA 5525 was great.

How has it helped my organization?

It has taken the pressure off of the IS engineer.

What needs improvement?

  • URL
  • AVC
  • Advanced malware protection

For how long have I used the solution?

We've used it for two years.

What was my experience with deployment of the solution?

There was an issue, but it was rectified promptly after troubleshooting the device's configuration.

What do I think about the stability of the solution?

There were no issues with the scalability.

What do I think about the scalability of the solution?

We've not had any issues scaling yet.

How are customer service and technical support?

Customer Service:

I think it is great but did not use them for this deployment.

Technical Support:

I've not had to use them yet for this deployment.

Which solution did I use previously and why did I switch?

There was no other solution in place.

How was the initial setup?

It was straightforward.

What about the implementation team?

I did the implementation with my colleagues.

What was our ROI?

It's not really quantified, but we have not experienced downtime due to attacks.

Which other solutions did I evaluate?

There were no other solutions looked at.

Disclosure: My company has a business relationship with this vendor other than being a customer. We're a systems integrator and a gold partner.
PeerSpot user
PeerSpot user
Senior Technical Consultant - Network and Security at a tech services company with 51-200 employees
Consultant
It provides our company with security and protection on all our devices, but we had some issues during deployment.

Valuable Features

  • It provides our company with security and protection on all our devices.
  • It's highly available.

Improvements to My Organization

We're able to implement best security practices to secure our company data.

Use of Solution

We've used it for over seven years.

Deployment Issues

We had some issues during deployment.

Stability Issues

No issues encountered.

Scalability Issues

No issues encountered.

Customer Service and Technical Support

Customer Service:

Customer service is excellent.

Technical Support:

Technical support is excellent.

Initial Setup

It was a little complex, but not so much that we couldn't figure it out.

Implementation Team

I was the implementor for a client.

ROI

It's excellent.

Other Solutions Considered

Depends on the customer's budget, but we evaluate all vendors that meet the them. It's a mission-critical product.

Other Advice

I give it a thumbs up.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user341043 - PeerSpot reviewer
System and Network Administrator at a hospitality company with 501-1,000 employees
Vendor
It gives us the ability to do Lan-to-Lan VPN, but it needs support for automation tools, such as Puppet.

What is most valuable?

It gives us the ability to do lan-to-lan VPN.

How has it helped my organization?

So far it has proven to be rock solid and relatively easy to maintain.

What needs improvement?

  • Support for automation tools (Puppet)
  • More granular logging

For how long have I used the solution?

I've used ASA for four years.

What was my experience with deployment of the solution?

No issues encountered.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

8/10

Technical Support:

8/10

Which solution did I use previously and why did I switch?

We moved our VPN termination from a Cisco ASR to an ASA. We switched because the ASR was not scalable and we realized it was a bad idea to use the same device for routing and VPN termination.

How was the initial setup?

The most complex part was figuring out the failover and what NAT mode to implement.

What about the implementation team?

We did it in-house.

What's my experience with pricing, setup cost, and licensing?

Licenses and prices are pretty high. I understand the validity of the product, so I can't complain much.

Which other solutions did I evaluate?

No options were evaluated. We heavily rely on Cisco hardware for our infrastructure

What other advice do I have?

I'd say it would be very beneficial to posses certification such as CCNP Security, at least, to get the most out of it. It's a complex product which requires good knowledge of procedures and best practices. Being a CCIE R&S I know the value of those certifications, and I wish I had a CCNP Security to better handle the task.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
IT Security Engineer at a financial services firm with 501-1,000 employees
Real User
The packet tracer function provides a packet flow through the firewall and shows which rule or policy can cause a drop.

Valuable Features:

Cisco ASA's CLI is very effective and fast to configure the firewall and make changes, but monitoring logs and connections can be eye bothering by reading all the line outputs. ASDM, however, have improved the overall ASA configuration from an GUI standpoint. I really enjoy the log monitor where I can see live logs in a more user friendly interface. The down side of ASDM is that it is build with JAVA and that means a lot vulnerabilities and it does not always work with the latest JAVA version and/or patches.

Improvements to My Organization:

The packet tracer function, which I use the most, have provided me a packet flow through the firewall and see which rule or policy can cause a drop. Also, I can see if my NAT statement is working properly. This has allowed me to quickly troubleshoot potential firewall related issues for my organization.

Room for Improvement:

L7 firewall is a key for the ASA to be competitive in the current and future market place. By integrating with SourceFire, now call FirePower, on the ASA has helped it to get into the next-generation firewall segment.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Network Security Consultant at a tech services company with 51-200 employees
Real User
Reliable product which I'd like to see include a web filtering functionality.

Valuable Features

It blocks all outside to inside traffic and only permits the specific internet traffic from the outside. VPN functionality is very useful, we can create remote access and tunnel VPN in the simplest way.

Improvements to My Organization

It blocked all kinds of internet attacks from outside like DOS or DDOS and avoided any down time. We created a remote tunnel from head office to data center network for easy access of servers that make working fast and they are easily manageable.

Room for Improvement

It would be great if they would add web filtering functionality to this product.

Use of Solution

5 years

Deployment Issues

No

Stability Issues

No

Scalability Issues

No

Customer Service and Technical Support

Customer Service:

Excellent

Technical Support:

Good

Initial Setup

It is a little difficult in newer IOS versions where the use of the NAT command is different. Otherwise its straightforward to configure.

Implementation Team

I deployed it in-house with my team.

ROI

This solution reduces any downtime therefore business continuity is not disturbed - that is ultimately ROI.

Pricing, Setup Cost and Licensing

It is one time cost of about $10,000 and there is no day to day cost.

Other Solutions Considered

Yes, I evaluated Fortigate, SonicWall and Juniper but found Cisco ASA to be the best solution for us above all of the others.

Other Advice

Cisco ASA is a reliable product and it benefits you a lot in your network.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2025
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros sharing their opinions.