PeerSpot user
Network Security Administrator at a tech company with 5,001-10,000 employees
Vendor
There were some issues with the ASDM client during deployment but high availability is a valuable feature.

What is most valuable?

  • Modular scalability
  • High availability
  • VPN services

How has it helped my organization?

It provided more secure access to the resources of my organization and created a more stable environment for the business activities between us and our partners.

What needs improvement?

Security through integrated cloud and software based services.

For how long have I used the solution?

I've used it for two years.

Buyer's Guide
Cisco Secure Firewall
April 2024
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,857 professionals have used our research since 2012.

What was my experience with deployment of the solution?

There were a few problems with the interaction between the ASDM client and ASA device.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and support?

Customer Service:

10/10.

Technical Support:

9/10.

Which solution did I use previously and why did I switch?

I previously used a Fortinet solution. I switched to Cisco because Fortinet lacked
stability and robust troubleshooting features.

How was the initial setup?

It was complex because I had to put the ASA directly into the production environment.

What about the implementation team?

I implemented the solution in-house.

Which other solutions did I evaluate?

I also evaluated Juniper and CheckPoint solutions.

What other advice do I have?

You should try it without restraints, and it is worth every penny.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Network Security Presales Engineer at a tech services company with 51-200 employees
MSP
Good throughput, with one-of-a-kind support, that is scalable
Pros and Cons
  • "The most valuable features of this solution are the integrations and IPS throughput."
  • "The price and SD-WAN capabilities are the areas that need improvement."

What is our primary use case?

I am a pre-sales engineer, and I do comparisons based on my customer's requests.

What is most valuable?

The most valuable features of this solution are the integrations and IPS throughput.

What needs improvement?

The price and SD-WAN capabilities are the areas that need improvement.

In the next release, I would like to see more of the FortiGate features added. FortiGate is compatible with Cisco ACI, but I can't see Firepower with Security Fabric. For example, if I had Fortinet activated, could I integrate with it?

For how long have I used the solution?

I have familiar with the Next Generation firewalls for two years, and six years with firewalls in general.

What do I think about the stability of the solution?

It's a stable product.

What do I think about the scalability of the solution?

It's scalable indeed.

Our clients are SMB Enterprise.

How are customer service and technical support?

It's just a fact, nothing is better than Cisco technical support.

Which solution did I use previously and why did I switch?

Previously, I was working with Fortinet. I would most likely recommend Fortinet, because of the price and the security fabric integration with other products. It's scalable as well, and all of the FortiGate features are useful.

It's very easy to implement and it's very easy to administrate.

How was the initial setup?

The initial setup was straightforward. With other vendors, it is easier, but it was straightforward.

What's my experience with pricing, setup cost, and licensing?

This product is expensive.

What other advice do I have?

I would rate this solution an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer:
PeerSpot user
Buyer's Guide
Cisco Secure Firewall
April 2024
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,857 professionals have used our research since 2012.
it_user857937 - PeerSpot reviewer
ICT Manager with 1-10 employees
Real User
A stable, reliable solution used to protect the network's perimeter
Pros and Cons
  • "A stable, reliable solution used to protect the network's perimeter."
  • "it is not very user-friendly for the administration."

What is our primary use case?

We use it to protect the perimeter of the network.

How has it helped my organization?

It is reliable, and does the job that it is supposed to be doing.

What is most valuable?

  • IPS
  • Antivirus
  • IP filtering

What needs improvement?

it is not very user-friendly for the administration.

What do I think about the stability of the solution?

The Cisco solution that we have now is very stable. That is why we are interested in continuing with the Cisco solution and upgrading to the next generation.

What do I think about the scalability of the solution?

It can be used by multiple users.

How are customer service and technical support?

We use the technical support of Cisco through a partner, so I do not have direct access to the Cisco IT technical support.

Which solution did I use previously and why did I switch?

We just shortlisted Cisco and Fortinet.

What about the implementation team?

We needed a Cisco technician to do the initial setup. We had to outsource the implementation.

What other advice do I have?

We need to upgrade our security requirements due to the new security requirement applicable in Europe (from GDPR) and the cyber security guidelines for our vessel (we are a US shipping company). 

Most important criteria when selecting a vendor: familiarity, reliability, and price.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user814596 - PeerSpot reviewer
Senior Network Manager with 51-200 employees
Vendor
Easy to deploy in a working environment between servers and users
Pros and Cons
  • "Logging is great. It will show when it reaches its capacity before it is too late, unless you have bursts of traffic."
  • "Easy to deploy in a working environment between servers and users."
  • "HTTPs inspection and higher throughput/spec would be good."

What is our primary use case?

  • Datacenter and edge firewalls
  • Used in central and remote sites.
  • Used in datacenter production sites.

How has it helped my organization?

  • Deployed between users and servers transparently.
  • Easy to deploy in a working environment between servers and users.
  • Improved security and visibility.

What is most valuable?

  • Failover
  • Transparent firewall
  • Multi-context
  • Logging is great. It will show when it reaches its capacity before it is too late, unless you have bursts of traffic.

What needs improvement?

HTTPs inspection and higher throughput/spec would be good. Now, it has been replace by Firepower, which is a lot faster. 

For how long have I used the solution?

More than five years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user674844 - PeerSpot reviewer
Executive Manager with 11-50 employees
Vendor
The solution's reliability, performance, and security are most valuable.

What is most valuable?

The solution's reliability, performance, and security are most valuable.

What needs improvement?

The price and compatibility with other vendors' products can be improved.

For how long have I used the solution?

I have used this solution for three years.

What do I think about the stability of the solution?

I have not encountered any issue with stability.

What do I think about the scalability of the solution?

I have not encountered any issues with scalability.

How are customer service and technical support?

I would give technical support a rating of 9/10.

Which solution did I use previously and why did I switch?

I used Juniper Networks and I switched due to the lack of technical and sales support in Romania.

How was the initial setup?

The initial setup was complex because of its outdoor position. We had to solve this problem with outdoor protection.

What's my experience with pricing, setup cost, and licensing?

Negotiate the quote.

Which other solutions did I evaluate?

Before choosing, I evaluated Juniper Networks SRX.

What other advice do I have?

Be careful with temperature control in the rack area, since Cisco ASA 5585-X with SSP-10 heats up a lot.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user240570 - PeerSpot reviewer
Network, Unix and Security Engineer at a tech services company with 501-1,000 employees
Consultant
It's easy to deploy, but the routing needs to be improved.

What is most valuable?

  • NAT
  • IPSec
  • ACL

How has it helped my organization?

It solved an IPSec issue we had with a customer. We have moved from Linux IPSec to Cisco.

What needs improvement?

  • Routing
  • It needs GRE supports
  • Application visibility
  • Context

For how long have I used the solution?

I have used Cisco ASA products since 2010.

What was my experience with deployment of the solution?

No, it's very easy to deploy.

What do I think about the stability of the solution?

With versions 8.4.4 and version 8.4.6, they had a lot of bugs. Also, after I moved to 8.4.5, route lookup changed to NAT divert and that kicked me.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

No service.

Technical Support:

No service.

Which solution did I use previously and why did I switch?

Yes we previously used Linux and we moved because Cisco is great.

How was the initial setup?

It was straightforward as Cisco Asia integrated it into OSPF, another router on the stack, and for NAT IPSec.

What about the implementation team?

I implemented it by myself.

What was our ROI?

It's good.

Which other solutions did I evaluate?

No other options were evaluated.

What other advice do I have?

It's a great product.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user1998 - PeerSpot reviewer
Infrastructure Expert at a tech company with 51-200 employees
Vendor
The most powerful and expensive firewall

Valuable Features:

There are a lot of companies who create firewalls but there is not a single one which can compete with ASA. It can have access control from layer 3 to layer 7. The ASA 5510 is more than enough for small to medium business. It has dedicated GUI interface which is known as ASDM, a beautiful tool to manage ASA. You can use ASA to route traffic. AAA service supports plenty of Authentication server types. You can configure advanced NAT in this device. It uses Modular Policy Framework (MPF) to inspect traffic. You can inspect traffic at different layers separately. You can use this as a transparent firewall & fail over is instant. The virtualization works beautifully for this device. VPN is another added advantage.All the types of VPNs are managed through ASA.

Room for Improvement:

The 5505 does not support multiple mode. While running this device on multiple mode you cannot use dynamic routing protocols or multicast routing. Also the IPSEC and SSL VPNs are not supported while running in multiple mode. sometimes analysis might take too long while performing DPI in real-time traffic. The product is expensive. A 5580 series costs more than $50000.

Other Advice:

Its very difficult to write something about this product as it has so many options. I have studied 1000 pages about this product and most of the organizations use this firewall as it is the best in the world. I have never seen such a powerful device which can handle 2 million connections at 20Gbps speed. It can also inspect 4 million packets per second.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user2895 - PeerSpot reviewer
it_user2895Senior InfoSec Engineer at a tech services company with 10,001+ employees
Consultant

There are companies that can compete with Cisco. Gartner has provided a report from 2012 showing that the new leader in firewalls with a new behavioral approach to firewalls is Palo Alto Networks. Not saying that Gartner has the right reports all the time but this one was correct. So remember that Checkpoint also exists and have been giving Cisco a run for their money. The caveat with Checkpoint is that some ports like X11 have to be hard coded into the top of the ACL in both directions in order to allow the traffic.

Anyone on any given day can beat the number one provider. The shift is now towards behavioral firewalling against unapproved applications and provide protection to the user no matter where they are based on user and not where they are coming from. Stay tuned as more developments come in the security field.

See all 2 comments
PeerSpot user
Solutions Architect at a tech services company with 51-200 employees
Consultant
A multitude of valuable features but a little pricey
Pros and Cons
  • "Signature-based detection; user-defined signatures with regular expressions; integrated URL and content filtering; custom URL categories filtering."

    How has it helped my organization?

    Secured our network from outside and inside intruders.

    What is most valuable?

    • Network attack detection
    • DoS and DDoS attack prevention
    • Signature-based detection
    • User-defined signatures with regular expressions
    • Integrated URL and content filtering
    • Custom URL categories filtering
    • Integarted antrivirus
    • Protocols scanning

    What needs improvement?

    License capacity needs to be extended and the vendor needs to work on the pricing.

    For how long have I used the solution?

    Three to five years.

    What do I think about the stability of the solution?

    No stability issues.

    What do I think about the scalability of the solution?

    No scalability issues.

    How are customer service and technical support?

    10 out of 10.

    Which solution did I use previously and why did I switch?

    No, Cisco was part of our solution from the start.

    How was the initial setup?

    Straightforward.

    What's my experience with pricing, setup cost, and licensing?

    Value for your money, but bit a costly.

    What other advice do I have?

    Good product, give it a chance.

    Disclosure: My company has a business relationship with this vendor other than being a customer: Solution Partner.
    PeerSpot user
    Buyer's Guide
    Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros sharing their opinions.
    Updated: April 2024
    Buyer's Guide
    Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros sharing their opinions.