My use case for Cisco Secure Firewall includes secure access into the network, remote access VPN, site-to-site VPN, NAT, and access control.
Senior Network Engineer at a legal firm with 11-50 employees
Centralized management has simplified secure access and still needs clearer log navigation
Pros and Cons
- "Cisco Secure Firewall helps organizations improve by making networking easier, as they have provided a graphical user interface for much of the functionality."
- "If I could improve Cisco Secure Firewall, I feel that even with my experience, I have difficulty navigating some of the logs and trying to find specific flows, whether it is the source address or the pre-NAT address."
What is our primary use case?
What is most valuable?
I believe the most valuable feature of having the FTD in Cisco Secure Firewall is that it is typically managed through FMC, which is a tool that allows you to manage multiple devices. The ability to manage, view, and push templates across multiple devices at one time is beneficial versus having to manually do it.
Cisco Secure Firewall helps organizations improve by making networking easier, as they have provided a graphical user interface for much of the functionality. I think people prefer the GUI and find it easier to navigate versus having to remember commands, making it excellent for both novice and senior engineers.
What needs improvement?
If I could improve Cisco Secure Firewall, I feel that even with my experience, I have difficulty navigating some of the logs and trying to find specific flows, whether it is the source address or the pre-NAT address. I find the filtering very difficult to navigate and determine exactly what field I have to put the criteria in, as there are too many fields.
For how long have I used the solution?
I probably started using Cisco Secure Firewall at the beginning of the pandemic, around 2021, while I was using ASAs before that, which had been for approximately 10 years. I have used FTD and Firepower for approximately five years and ASA for approximately 10 years.
Buyer's Guide
Cisco Secure Firewall
June 2026
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
899,645 professionals have used our research since 2012.
What do I think about the stability of the solution?
I believe Cisco Secure Firewall is stable because I have never seen it crash and I have never seen it fail to forward packets.
How are customer service and support?
My experience with customer support for Cisco Secure Firewall is positive, as they are helpful. On a scale of one to ten, I would rate Cisco Secure Firewall customer support as a nine, with ten being best.
Which solution did I use previously and why did I switch?
I have briefly looked at some marketing materials for other firewall solutions such as Palo Alto, Fortinet, and FortiGate to understand where they are in the market, but I have never really managed or configured those platforms.
How was the initial setup?
The complexity of deploying Cisco Secure Firewall varies depending on how many you have deployed. When I first deployed it, I still had to refer to documentation and conduct some trial and error, as we had to reconfigure some elements because of the interesting environment where we had to port-channel separately instead of as one bundled channel in an HA cluster. The complexity really depends on the environment.
What about the implementation team?
I have deployed Cisco Secure Firewall with some customers.
Which other solutions did I evaluate?
I believe the market space for firewall solutions is crowded, and these vendors need to be competitive. I find that they are all quite similar.
What other advice do I have?
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Feb 12, 2026
Flag as inappropriateNetwork Operations at a healthcare company with 5,001-10,000 employees
Effectively unifies policies but bugs have been problematic
Pros and Cons
- "I appreciate the uniformity of being able to push the policies out with Cisco Secure Firewall. That was one of the reasons we acquired it, so we could push the policies out everywhere."
- "I appreciate Cisco's support and have been very happy with it."
- "Downtime due to bugs requiring code upgrades has been problematic. That's the reason why we are moving away from Cisco Secure Firewalls."
What is our primary use case?
Our main use cases for Cisco Secure Firewall are segmentation and VPNs. My involvement is more at the remote sites, setting up those firewalls for VPN, and we have centralized management for handling all the policies.
What is most valuable?
I appreciate the uniformity of being able to push the policies out with Cisco Secure Firewall. That was one of the reasons we acquired it, so we could push the policies out everywhere.
What needs improvement?
Downtime due to bugs requiring code upgrades has been problematic. That's the reason why we are moving away from Cisco Secure Firewalls.
For how long have I used the solution?
I have been using Cisco Secure Firewall for approximately four years.
What do I think about the stability of the solution?
It has been problematic, primarily due to bugs in the code rather than crashes.
What do I think about the scalability of the solution?
We're looking at Palo Alto, and we will probably be cutting over to Palo Alto, which will likely be a many-year project.
How are customer service and support?
I appreciate Cisco's support and have been very happy with it. I imagine the support is the same for the firewall. I typically handle break-fix issues at the firewall level and turn them over to engineering, who then contact tech support. With switching, I call tech support directly.
The support has improved significantly over the years, and the escalation process is very straightforward now. Even if the first engineer isn't highly knowledgeable, we get additional support and can escalate the issue.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We have been using a Meraki solution.
What's my experience with pricing, setup cost, and licensing?
Licensing with Cisco Secure Firewall isn't too difficult. However, pricing seems high. We had been using a Meraki solution, and Cisco Secure Firewall seems more expensive than Meraki, even though Meraki is also cloud-based.
Which other solutions did I evaluate?
We're going to cut over to Palo Alto, which will probably be a many-year project, because the amount of downtime is substantial. While it doesn't affect the whole company, there is downtime in certain areas, usually due to bugs that require code upgrades to fix. That has been problematic.
We had planned to deploy Meraki more extensively as our Cisco ASAs aged out. However, we're also deploying SDA fabric, and Meraki is currently not compatible with that solution. I recently spoke with an engineer about SDA, and his answer indicated they will be supported, but with some variance. That's why we're moving away from Meraki, but we're still not ready for Palo Alto since it has a big learning curve and is totally different. We still have deployment and upgrade needs, so we're continuing to get Cisco Firepower firewalls while implementing Palo Alto more internally. This could be a multi-year process, depending on how it progresses.
What other advice do I have?
It's difficult to predict how other organizations will deploy Cisco Secure Firewall, but my advice is to ensure the code being installed is the code recommended by Cisco. My recommendation wouldn't be extremely high, as deciding to discard millions of dollars in investment makes a significant statement. I would have difficulty recommending it based on our management's decisions, especially considering we're willing to replace our core firewalls and perimeter firewalls. The Palo Alto transition entails substantial training and design work. If we're willing to get rid of Cisco Secure Firewall in favor of a different product, it says a lot.
I would rate Cisco Secure Firewall a seven out of ten. It performs necessary firewall functions, but there are issues related to bugs.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Cisco Secure Firewall
June 2026
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
899,645 professionals have used our research since 2012.
Assistant Director IT at Punjab Education Foundation
Strong threat protection improves server reliability and needs better management
Pros and Cons
- "The most valuable features of Cisco Secure Firewall include the next-generation firewall and its strong anti-malware capabilities."
- "Cisco Secure Firewall could improve in areas like user-friendliness and cost-effectiveness, as it is very costly and difficult to manage. I would rate it seven out of ten, but I would recommend other firewalls due to its high cost and complexity."
What is our primary use case?
We use Cisco Secure Firewall for our servers, protecting data centers, and limiting the ports and threats. We have various web servers hosted in our data center, and to protect them from external threats, we use the firewall.
What is most valuable?
The most valuable features of Cisco Secure Firewall include the next-generation firewall and its strong anti-malware capabilities. These features protect internal servers from external threats, such as denial of service threats, viruses, and malware. Additionally, Cisco checks and stops traffic containing new threats, taking steps to mitigate them. When our servers are secure, their speed is very good using Cisco Secure Firewall. We do not face any kind of delay or issues, allowing more users to connect seamlessly.
What needs improvement?
Cisco Secure Firewall is difficult to manage as it lacks a web interface for management, requiring installation of management center software on a dedicated computer or server. Should the management software be removed, it needs to be reinstalled, consuming time and resources. Moreover, the configuration commands are not user-friendly, especially when compared to Fortinet's interface. The process of licensing is complicated, involving many steps to obtain and enter the license key. This process should be simplified.
For how long have I used the solution?
We have been working with Cisco Secure Firewall for about five to six years.
How are customer service and support?
The technical support is not very good because when support is requested, assistance often takes a few days to arrive as they are quite busy.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We previously used software firewalls running on Linux. We switched because they were not next-generation firewalls and did not provide antivirus and malware protection.
What's my experience with pricing, setup cost, and licensing?
The licensing process for Cisco Secure Firewall is convoluted, involving many steps to request and enter a license key. In contrast, Fortinet or other firewalls offer a simpler process where you just need to enter the key quickly.
What other advice do I have?
Cisco Secure Firewall could improve in areas like user-friendliness and cost-effectiveness, as it is very costly and difficult to manage. I would rate it seven out of ten, but I would recommend other firewalls due to its high cost and complexity.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
VSO at a computer software company with 501-1,000 employees
Enhances security with precise access control but has integration challenges
Pros and Cons
- "Most firewalls have a challenge of identifying keywords and providing restricted access, which I encountered. However, Cisco Firewall has very good features, like trusted applications and restricted access for users based on keywords."
- "The integration, especially for APIs or with other firewall products, is a challenge for me."
- "Technical support is unsatisfactory for me. There might be restructuring within Cisco India or with the partner's capability."
What is our primary use case?
I implemented the product which provides end-to-end networking and security features. It starts with secure tunneling, and I performed micro-segmentation in the firewall specific to a particular customer environment. It offers comprehensive security as well as networking features that I have enabled.
What is most valuable?
The software was mainly the highlight. Most firewalls have a challenge of identifying keywords and providing restricted access, which I encountered. However, Cisco Firewall has very good features, like trusted applications and restricted access for users based on keywords. I could access it appropriately, unlike some firewalls where this is a challenge. Essentially, the restricted access to websites has been exceptional. I was in the life science industry, focusing heavily on compliance. This product meets compliance requirements, and the security process has improved. Stability and consistent performance are critical components of Cisco's product.
What needs improvement?
The integration, especially for APIs or with other firewall products, is a challenge for me. In some satellite sites where large firewalls are not involved, I used Cisco Meraki. The integration between Cisco products themselves presents difficulties, such as SD-WAN configuration. Managing centralized networking with Cisco is challenging for me in terms of integration with other firewall products.
For how long have I used the solution?
I have used the solution for almost four years.
What do I think about the stability of the solution?
The solution is stable and performs well.
What do I think about the scalability of the solution?
Scalability presents a challenge. There is commercial involvement and several factors, making it complex for me. I would rate scalability seven out of ten.
How are customer service and support?
Technical support is unsatisfactory for me. There might be restructuring within Cisco India or with the partner's capability. Whenever I encounter a technical support challenge, it is not an easy process. Even with premium support, it is a struggle. I have to provide many logs, yet problems remain unresolved, often requiring workarounds rather than solutions.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial setup is not simple as it is all based on my requirements. If the requirement or site is predominantly complex, specialist involvement is necessary. However, for a vanilla installation, it is fine - just not easy.
Which other solutions did I evaluate?
I have assessed and decided to move on to Sophos. Sophos's support is excellent compared to Cisco and other products, with their technical support team based in South India. I have received a lot of good feedback about it.
What other advice do I have?
Overall, I would rate the product six out of ten. Because of the support and cost, I moved away from Cisco, but otherwise, it is a good product. Recommendation depends on the requirement. If lacking a proper team and being dependent on the OEM and partner, Cisco is not suitable.
However, if the team is qualified with Cisco-certified people and the requirement is a big network, it can be considered. In today's hybrid work world, having an expanded gateway is more typical than having a single one. Thus, Cisco is unlikely to be recommended for a hybrid requirement unless in-house skills align. Otherwise, depending on partners and Cisco, it can be a risk.
I rate the overall solution six out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Network Administrator at iib
Delivers strong threat prevention and good VPN but has configuration complexity
Pros and Cons
- "The VPN functionality is consistent, and the performance is good."
- "Their hardware can handle substantial amounts of data without causing latency."
- "Cisco Firewall is not user-friendly."
- "Cisco Firewall is not user-friendly. They complicate simple configurations, requiring multiple steps."
What is our primary use case?
The solution is used in a normal enterprise-level configuration. It has effectively worked as a perimeter firewall. Our VPN was also configured on it.
What is most valuable?
The threat prevention is better than FortiGate, but it is less effective than Palo Alto. The VPN functionality is consistent, and the performance is good.
What needs improvement?
Cisco Firewall is not user-friendly. They complicate simple configurations, requiring multiple steps. Compared to Palo Alto and FortiGate, it is not as effective. Cisco Firewalls require FMC for management.
If you have a small to medium-sized office with only a few firewalls, you can deploy and manage them without FMC. However, without FMC, it is not fully functional, limiting the features available. You cannot use the asterisk value in address objects in Cisco.
In other firewalls, hovering over an object displays details like the IP address. With Cisco, you need to access the object to see inside details. Cisco should improve this aspect. The NAT process is handled differently, which I do not like. Obtaining support is challenging compared to FortiGate and Palo Alto.
Although knowledge-wise they are good, obtaining technical support and involving an engineer in a troubleshooting call is a challenge.
For how long have I used the solution?
I have used the solution for almost two years.
What do I think about the scalability of the solution?
The scalable performance is good, however, the voice communication is not effective. Compared to FortiGate and Palo Alto, it lags in configuration and other aspects.
How are customer service and support?
Knowledge-wise, they are good, however, obtaining technical support and involving an engineer in a troubleshooting call is a challenge.
How would you rate customer service and support?
Negative
How was the initial setup?
The deployment was a normal activity, similar to how enterprises operate. It worked as a perimeter firewall, and our VPN was configured on it. The installation took approximately half a day.
What other advice do I have?
For mid-sized organizations, I do not recommend it. For ISPs or data centers, I would recommend it due to its good performance and hardware capabilities. Their hardware can handle substantial amounts of data without causing latency. I recommend it for ISP or data center. For enterprise purposes, I do not recommend it.
I rate the overall solution seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Engineer
Offers high flexibility, solid security, and unified policy management
Pros and Cons
- "What I appreciate the most about Cisco Secure Firewall is that it can be very elastic, as it can be configured with all the flexibility of my network needs and complexity."
- "Cisco Secure Firewall can be improved by simplifying the GUI, as it shouldn't be so complex."
What is our primary use case?
My main use cases for Cisco Secure Firewall are to safeguard our network, including the IPS and all the traffic, and to control the traffic.
How has it helped my organization?
The visibility and control capabilities of Cisco Secure Firewall in managing encrypted traffic are very good. I can implement all my certificates, so I can open the traffic and see everything.
Cisco Secure Firewall’s ability to unify policies across our environment is at a high level. This unification of policies into one system is important for my company. We are able to consolidate all the policies instead of spreading them across many security systems.
What is most valuable?
What I appreciate the most about Cisco Secure Firewall is that it can be very elastic, as it can be configured with all the flexibility of my network needs and complexity. The service I receive from the Cisco engineer helps me implement all my needs.
Cisco Secure Firewall allows me to safeguard Layer 7 or Layer 3 and manage the security rules with the business needs of my organization. The firewall has benefited my company overall because it safeguards and finds and stops all the malicious traffic.
What needs improvement?
Cisco Secure Firewall can be improved by simplifying the GUI, as it shouldn't be so complex.
For how long have I used the solution?
I have been using Cisco Secure Firewall for ten years.
What do I think about the stability of the solution?
It's very robust. We don't have any downtime or anything. We work with a cluster with high availability, so if something goes wrong, we have it functioning.
What do I think about the scalability of the solution?
Cisco Secure Firewall helps with the growing needs of our company as it's scalable.
How are customer service and support?
Customer service and technical support for Cisco Secure Firewall are very good. I would rate them a nine out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
It was a little bit difficult.
What about the implementation team?
We needed a good integrator to help us, and we contacted Cisco for some help with technical issues.
What was our ROI?
We are able to safeguard our assets.
What's my experience with pricing, setup cost, and licensing?
It's acceptable and comparable to other products.
Which other solutions did I evaluate?
We did consider other solutions before choosing Cisco Secure Firewall. We considered all the big vendors such as Palo Alto, Check Point, Fortinet, and others. Cisco won because it has the best IPS model on it, and that's the reason why we chose this firewall.
What other advice do I have?
I would rate Cisco Secure Firewall an eight out of ten. To make it a ten, the complexity of the configuration compared to other vendors needs to be addressed. Overall, we're very happy with the product.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Principal Consultant at Epitome Infotech Solutions (P) Ltd
Exceptional performance and purpose-built architecture enable threat prevention with great support
Pros and Cons
- "Customer service and support are excellent. I would rate their support 10 out of 10."
- "The configuration might be slightly difficult compared to other players in the market like Fortinet or WatchGuard."
What is our primary use case?
Our primary use case for Cisco Secure Firewall is for enterprise customers. We primarily work on Cisco Meraki switching and wireless. We also engage with Cisco Secure Firewall for threat prevention and information security.
What is most valuable?
The Cisco Secure Firewall appliances are primarily ASIC-based, which makes them fast and purpose-built. They stand out because they are not Intel-based systems, and in terms of performance and stability, they are among the best. Scalability is another strong point, as I have not encountered any issues in terms of scalability. Everything is in a cluster and can operate in active standby, active-active, or active-passive mode. Additionally, Cisco's support is excellent, which adds further value to their solutions.
What needs improvement?
The configuration might be slightly difficult compared to other players in the market like Fortinet or WatchGuard. It can be challenging for someone who is not used to using an application to configure the firewall, but with experience, it becomes manageable.
For how long have I used the solution?
I have been working with Cisco Secure Firewall for four, five, six years or more.
What was my experience with deployment of the solution?
There have been no issues with deployment.
What do I think about the stability of the solution?
Cisco Secure Firewall offers exceptional performance and stability. They are among the best in terms of stability.
What do I think about the scalability of the solution?
I have not come across any issues with scalability. Everything scales very well.
How are customer service and support?
Customer service and support are excellent. I would rate their support 10 out of 10. I have been working with them on firewalls, wireless, switching, and routing, and the support is the best.
How would you rate customer service and support?
Positive
How was the initial setup?
For someone like me who has been working on firewalls for quite some time, I do not see any problems with the initial setup. However, for someone trying to configure it for the first time with little experience, it may present a challenge.
What was our ROI?
Return on investment depends on the customer. While some may see it as an expense, others view it as an investment based on their understanding of Cisco.
What's my experience with pricing, setup cost, and licensing?
The pricing is slightly more expensive than other products in the market. It's considered a premium, but people pay that price for Cisco.
Which other solutions did I evaluate?
I have been working with Palo Alto, Fortinet, SonicWALL, and WatchGuard.
What other advice do I have?
I would definitely recommend Cisco Secure Firewall for its architecture, performance, stability, and exceptional support. When choosing a product, consider features delivery, stability, scalability, and customer support. On a scale of one to ten, I rate their firewalls eight to eight and a half.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Team Lead at WM Group
Great performance with advanced features yet management system needs updating
Pros and Cons
- "There is a good relationship between real throughput, meaning the root performance, and the data sheet performance."
- "The SLA is great, and the escalation process is also great."
- "The management usability and security of Cisco Firewall are based on Firepower Management Center, which is quite out of date compared to other vendors."
What is our primary use case?
I am a system engineer, and I've been looking for some details and competitive information regarding the standards of this firewall and similar technologies.
What is most valuable?
There is a good relationship between real throughput, meaning the root performance, and the data sheet performance. When comparing it to other vendors, the data sheet performance is often more than expected and more than the real performance. It includes features like IPS, malware protection, and other security features.
What needs improvement?
The management usability and security of Cisco Firewall are based on Firepower Management Center, which is quite out of date compared to other vendors.
For how long have I used the solution?
I have used this solution for more than ten years.
How are customer service and support?
The SLA is great, and the escalation process is also great. For example, if I have a priority one case, I am able to call the manager to raise the severity, etc. So the SLA is very good.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
When compared with other competitors like Palo Alto or Fortinet, Cisco stands in a good position regarding the firewall environment. Compared to Fortinet, Cisco is a bit higher. When comparing with Palata and Juniper, Cisco has the same price level.
How was the initial setup?
I am well prepared, and it is quite easy. Cisco has really great documentation, like a deployment guide and a quick start guide, etc.
Which other solutions did I evaluate?
What other advice do I have?
If engineers are well prepared, it is good to note that Cisco has really great documentation. I have been working with AI features in the Cisco environment with Cisco Firewall, etc. I have been hearing and reading a lot about the integration of AI capabilities into Cisco devices, but I have not worked with that yet.
Overall, I would rate this an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2026
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
Sophos Firewall
Cisco Umbrella
Palo Alto Networks NG Firewalls
Cisco Identity Services Engine (ISE)
WatchGuard Firebox
Check Point Quantum Force (NGFW)
Check Point Harmony SASE (formerly Perimeter 81)
Cisco Meraki MX
Check Point Cloud Firewall (formerly CloudGuard Network Security)
Azure Firewall
Cisco Secure Network Analytics
Cisco Duo
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Is The Biggest Difference Between Cisco ASA And Fortinet FortiGate?
- Cisco Firepower vs. FortiGate
- How do I convince a client that the most expensive firewall is not necessarily the best?
- What are the biggest differences between Cisco Firepower NGFW and Fortinet FortiGate?
- What Is The Biggest Difference Between Cisco Firepower and Palo Alto?
- Would you recommend replacing Cisco ASA Firewall with Fortinet FortiGate FG 100F due to cost reasons?
- What are the main differences between Palo Alto and Cisco firewalls ?
- A recent reviewer wrote "Cisco firewalls can be difficult at first but once learned it's fine." Is that your experience?
- Which Cisco firewall model is the latest: ASA or NGFW?
- Which is better - Fortinet FortiGate or Cisco ASA Firewall?














