No more typing reviews! Try our Samantha, our new voice AI agent.
ITEnginec8d2 - PeerSpot reviewer
IT Engineer at a tech services company with 11-50 employees
MSP
Jul 15, 2019
A scalable solution with good support and a straightforward setup
Pros and Cons
  • "The initial setup wasn't complex or complicated."
  • "Cisco NGIPS dropped network Troyans and web application attac almost every day."
  • "More flexibility with the dashboards is needed because some of them are not fully developed."
  • "The main problem with Firepower is the time between deployment and configuration."

What is our primary use case?

We use this solution for integration, installing, and supporting.

How has it helped my organization?

Cisco NGIPS dropped network Troyans and web application attac almost every day. That helps up to feel more secure.

What is most valuable?

I find the IPS feature the most valuable.

What needs improvement?

The main problem with Firepower is the time between deployment and configuration. Now, it's approximately six minutes, so If I configure something during deployment, I understand that maybe if I write up a small mistake, I need to wait twelve minutes before I can fix the configuration. So I think the main problem is the time of deployment.

The solution could add DLT, but it's already full enough of features.

The interface could be simpler and more user-friendly. More flexibility with the dashboards is needed because some of them are not fully developed. We could use more flexible base boards.

Buyer's Guide
Cisco Secure IPS (NGIPS)
June 2026
Learn what your peers think about Cisco Secure IPS (NGIPS). Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,838 professionals have used our research since 2012.

For how long have I used the solution?

I've been using this solution for one year.

What do I think about the stability of the solution?

For the years we've been using Firepower we have only one or two cases of instability. There were only one or two unpredictable things.

One case was fasten with Active/standby switchover. After switchover some networks has been lost. After rebooting the standby FP next switchover was without problem.

Another case was associated with setting up of NAT. It was a FirePower nuance. Only the second TAC engineer helped us with it.

What do I think about the scalability of the solution?

I find the solution really scalable.

How are customer service and support?

I'd give technical support a five out of five. When things need to get solved, they get solved.

Which solution did I use previously and why did I switch?

We used to have ASA 5520. But in time we needed more security features to secure our services and users.

How was the initial setup?

The initial setup wasn't complex or complicated. Everything was clear. The initial configuration took a day, but the company that we support has a very complicated topology. During the deployment, they had a different idea about how the configuration should be. Because the customer didn't know what they wanted, the files and the deployment took approximately three or four months. 

For deployment, it depends on the company. It depends on the company's complicated topology. If it's too complicated, then maybe you need two engineers to support Firepower. For employees, you need only one, with a second as a standby in case something goes wrong with the primary engineer, so I'd say you need two engineers to maintain the solution.

What about the implementation team?

I handled the implementation myself.

Which other solutions did I evaluate?

The company is Cisco oriented and Cisco is a leader in security Gartner Quadrant for Enterprise Network Firewalls.

What other advice do I have?

My advice for anybody implementing this solution is to follow the instructions carefully.

I would rate this solution an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller.
PeerSpot user
Senior Consultant at Wevioo
Consultant
Jul 14, 2019
Offers valuable web filtering and JPS features and their technical support responds quickly
Pros and Cons
  • "The solution is stable. This is one of the good things in Firepower. Especially if we use ESE with it."
  • "If someone wants to use Cisco Firepower, the solution is easy."
  • "There are some features not found in Firepower, like data loss prevention, and SSO, to have a connection between Cisco and Active Directory, which was introduced on other products."

What is most valuable?

I've found the web filter and JPS the most valuable features.

What needs improvement?

There are some features not found in Firepower, like data loss prevention, and SSO, to have a connection between Cisco and Active Directory, which was introduced on other products.

In the future, I'd like the same solution in other UTM solutions. I know it has an application filter, but it's not really improving. Also, DLP needs to prevent data loss. Those two features are really important now for firewalls and for the security. The data loss prevention really is the most asked for feature from the customer. Often they ask about how we can prevent loss of emails, of data, files. It's really important.

For how long have I used the solution?

I've been using the solution since 2014.

What do I think about the stability of the solution?

The solution is stable. This is one of the good things about Firepower. Especially if we use ESE with it. That would make it the complete solution for Cisco for security. If it is the complete solution, it's stable and there are no issues with the product. If the user isn't connected all the time, for example, if we look at some sites or some users, sometimes the connection for the user gets disconnected with each session. Sometimes the filter doesn't work. 

What do I think about the scalability of the solution?

The solution is good to scale.

How are customer service and technical support?

The technical support is really good. Not only for this solution. The support of Cisco is always good. From the first call, the response is quick and there is no problem with the support.

How was the initial setup?

The initial setup is not complex. There is a wizard so it's not complex. There is a difference in the complexity of the deployment. Depending on customers and infrastructure, sometimes it takes one day or two days if we're talking about a little infrastructure. Sometimes it can take eight days or more to couple the firewall with ASA, and to do some more complex architecture. If we have a complex architecture, we need 2 people to implement, but if we have an implementation that is not so complex, one person can do it.

What about the implementation team?

I do the implementation myself.

What was our ROI?

Most of the time the ROI good. The customer, most of the time, is happy and is convinced of the usefulness of the solution.

What other advice do I have?

If someone wants to use Cisco Firepower, the solution is easy. The complete solution is the best for having the full security of a Cisco infrastructure. If I could advise someone with the deployment, I would advise taking the complete solution, in order to have a really scalable and stable solution. Or, if you can't take the complete solution, I'd advise taking a cluster of Firepower to have the scalability and stability.

I would rate this solution a 7 or 8 out of 10. If they could add a few of the mentioned features or do something more with the application filter it would be a 9 or a 10 out of 10.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner.
PeerSpot user
Buyer's Guide
Cisco Secure IPS (NGIPS)
June 2026
Learn what your peers think about Cisco Secure IPS (NGIPS). Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,838 professionals have used our research since 2012.
reviewer1083318 - PeerSpot reviewer
Network Infrastructure Program Manager at a non-profit with 1,001-5,000 employees
Real User
Jul 14, 2019
Offers valuable SSL decryption, URL filtering, and ITSM inspection features
Pros and Cons
  • "Cisco is number one in the technical support. It's good technical support and this is actually a problem when we do the recruitment for some other products. Other products you are on hold forever and the support might be not the best compared to Cisco."
  • "The file trajectory, the trace in contamination files, could be improved."
  • "Scalability I would say, it has some limitations in the large deployment."

What is most valuable?

In the previous version, some features were not enabled. For example, you could not access the VPN. So that was one of the downsides of the product. In this latest version, after enabling these features in the previous version and using them, it's been good. Inspection, application, and inspection in the cloud, the detail in the cloud for an indication of compromise and the malicious activity re-hashing are all valuable features. It's more of the cloud and the malicious activities aspects that define this application.

What needs improvement?

The file trajectory could be improved.

We still have a web proxy but I think at some point we should not have two products. We should have only one product. Most of the features of the web proxy already exist in the UTM appliances. We have a debate as to whether it's the Cisco Firepower and UTM Appliance of next-generation firewall. But I consider both of them the same. So I would say if we have the caching and the other features which are unique features to the Web Proxy, I think Cisco will be number one if they are able to include such features in the future.

For how long have I used the solution?

I have been using the solution for three years.

What do I think about the stability of the solution?

It's a really good product but I have had a really good experience with Palo Alto UTM Appliances. Which I would give a higher mark than the Firepower. It's just a little bit more expensive than the Cisco Firepower.

What do I think about the scalability of the solution?

Scalability I would say, it has some limitations in the large deployment. I think Cisco is working to improve it.

How are customer service and technical support?

The technical support is the most valuable part of the solution. Cisco is number one in technical support. It's good technical support and this is actually a problem when we do the recruitment for some other products. Other products you are on hold forever and the support is not as good compared to Cisco. 

Which solution did I use previously and why did I switch?

I started with Juniper and the Palo Alto UTM Appliances, and many other vendors. But we do have a policy to use multiple vendors.

How was the initial setup?

Three years ago the setup was very complex. We had two different cables or software. It's like two appliances and one appliance. We had to set up ASA first and then set up Firepower and do the redirect from the old HTTP traffic, from the ASA for a detailed inspection by Firepower. Initially, it was complex. That was a few years back, but now with the newer version, it's just a piece of cake. Deployment took about 40 minutes. I also handle the maintenance myself.

What about the implementation team?

I do the implementation myself but in certain situations, because we have a risk assessment, it's a sort of risk transfer, so we have a contract with a certain integrator. We do have a contract, but I personally do the setup.

What was our ROI?

We have definitely experienced ROI. Because we have had many incidents where Cisco Firepower has caught malicious activities and triggered an alarm, a true positive alarm. Which is really good in our case.

What other advice do I have?

The solution is extensively used. We have a policy, from a permission security perspective, that you need to have diversity in the vendors and diversity in the products. We have some areas which are using these products and other areas which is using different products.

It's a really good product, but you need to give it some time to form a sort of baseline, before enabling all the features. You need to study the product well because the product will decrease to around 35-40% of the actual product when you start to enable features. Like the application and inspection, the SSL decryption, the URL filtering, and the ITSM inspection. If you enable more features, you will decrease a little bit of the property. Whoever selects the device initially needs to plan which features they are going to use and they might have to shift the sizing of the product. They might need a high-end appliance or a smaller low-end appliance based on the features they are going to use.

I would give the solution 9 out of 10. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
CyberEng8ecc - PeerSpot reviewer
Cyber Engineer at a aerospace/defense firm with 10,001+ employees
Real User
Mar 24, 2019
This solution has helped improve productivity and detect attacks before they happen
Pros and Cons
  • "This solution has helped improve productivity and detect attacks before they happen."
  • "I would like to see better integration with SIEMs."
  • "Rating the technical support from one to five (where five is high), I would rate them as a two. I find them to be very bad."

What is our primary use case?

It detects attacks from malicious intrusions and malicious activity before they happen.

How has it helped my organization?

This solution has helped improve productivity and detect attacks before they happen.

What is most valuable?

Signature rules from the Snort community around the world.

What needs improvement?

  • I would like to see better integration with SIEMs. 
  • Better rule building using other tools, like LuaH and Python.
  • Better performance.
  • Better intelligence gathering in domains, the main URLs, and endpoint solutions.

What do I think about the stability of the solution?

It's very reliable. We really like the product and will be staying with the product a while.

What do I think about the scalability of the solution?

At this point in time, it's making it a little bit difficult to scale due to the company, as the vendor is making some changes. We are waiting to see if the product is scalable or not. 

How are customer service and technical support?

Rating the technical support from one to five (where five is high), I would rate them as a two. I find them to be very bad.

Which solution did I use previously and why did I switch?

This was originally a Snort product, which was open source. So, there is a community for it worldwide.

We used ISS from IBM in the past, but it was causing many issues and was dropping packets. It was not an ideal solution, so we moved to Sourcefire FirePower NGIPS.

How was the initial setup?

The initial setup is easy because I am very familiar with the product.

What's my experience with pricing, setup cost, and licensing?

We buy the licensing on a yearly basis, when we renew our contract. It is around $14,000.

Which other solutions did I evaluate?

McAfee and Palo Alto were on our shortlist.

What other advice do I have?

The product is a ten because it is the only product in the market like this.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Security8085 - PeerSpot reviewer
Security at a government with 1,001-5,000 employees
Real User
Mar 24, 2019
Does a great job of detecting and stopping threats
Pros and Cons
  • "It has good intelligence. It does a great job at stopping threats."
  • "It has increased our security posture and has contributed substantially to our security maturity by stopping threats."
  • "In the next release I would like to see better reporting. I also find it's hard to act on the data it gives you."

What is our primary use case?

We use it for threat prevention.

How has it helped my organization?

It has increased our security posture and has contributed substantially to our security maturity by stopping threats.

What is most valuable?

  • It has good intelligence.
  • It does a great job at stopping threats.

What needs improvement?

In the next release I would like to see better reporting. I also find it's hard to act on the data it gives you.

What do I think about the stability of the solution?

The stability is excellent.

What do I think about the scalability of the solution?

The scalability is excellent.

How are customer service and technical support?

Technical support has been excellent.

How was the initial setup?

The initial setup is complex. That's just the nature of that product. It's a really advanced product so it takes a lot of technical knowledge to implement it.

What about the implementation team?

We used a reseller. 

What was our ROI?

We have definitely seen ROI, but I can't quantify it.

What other advice do I have?

Get a good demo to test it out or do a proof of concept to see if it it's what you're looking for.

I rate it an eight out of ten. Eight because it's good at detecting and stopping threats. Those other two points that would make it a ten are better usability and reporting.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Carlos Reis - PeerSpot reviewer
Network Security Engineer at a computer software company with 501-1,000 employees
Real User
Top 20
May 16, 2024
Has great security intelligence features
Pros and Cons
  • "I like the security solutions from Cisco."
  • "There are certain limitations that need to be addressed."

What is our primary use case?

People still aggregate these functions. We have files that only serve the purpose of NextGen NGIPS.  They have no rules that just allow pure source running and execution. We need regular firewall protection with NetGen. It's nice because we can lease both firewall and IPS system functions. We have both running on the network.

What is most valuable?

Apex IPaaS functions itself. You can create an intrusion rule that can be used for blocking purposes.

I like the security solutions from Cisco. They don't only give you the IPS itself, but you also have another database and other applications. 

They also have the security intelligence feature. This is one of the first software lines. This brings you the URLs, IPs, etc. This is even before the access control.

What needs improvement?

There are certain limitations that need to be addressed. 

For how long have I used the solution?

I have been using the Cisco NGIPS for two years. 

How are customer service and support?

Cisco support is very good. 

How would you rate customer service and support?

Positive

What other advice do I have?

For the time being, I never received a complaint about a policy, but this may happen in the future. This can be due to consistent integration. 

They filter even between different companies and stuff and cloud providers and I've never received any complaints about the speed.

Overall, I rate the solution an eight out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Infrastructure and Security Officer at a tech services company with 201-500 employees
Real User
Mar 16, 2023
The console has everything you need in one place
Pros and Cons
  • "I like how NGIPS has everything in one console."
  • "The look and feel of the console could be updated."

What is our primary use case?

We use NGIPS for monitoring and firewall purposes. We have about 3,000 users. 

What is most valuable?

I like how NGIPS has everything in one console.  

What needs improvement?

The look and feel of the console could be updated. 

For how long have I used the solution?

I have used NGIPS for about five years.

What do I think about the stability of the solution?

NGIPS is stable.

How was the initial setup?

Setting up NGIPS was complex. We needed help from a Cisco specialist. 

What other advice do I have?

I rate Cisco NGIPS eight out of 10 overall.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Senior Network Engineer at Dejpaad
Real User
Jan 14, 2023
The best in the world, high value features, with long term reliability
Pros and Cons
  • "The most valuable feature would be the IPS is very important in Cisco Firepower because I can configure deep configuration in IPS and tuning."
  • "I would like to see the sanctions lifted so we could use the full solution and have the speed increased."

What is our primary use case?

Our primary use case is for the firewall and other security-related features.

How has it helped my organization?

I think the Cisco Firepower is the best firewall in the world and the other security features like AMP, IPS, and deep inspection packets.

What is most valuable?

The most valuable feature would be the IPS is very important in Cisco Firepower because I can configure deep configuration in IPS and tuning.

What needs improvement?

I would like to see the sanctions lifted so we could use the full solution and have the speed increased.

For how long have I used the solution?

I have been using Cisco NGIPS for the past eight years.

What do I think about the stability of the solution?

The stability is evident and without issues.

What do I think about the scalability of the solution?

The scalability is excellent. We have around one thousand two hundred users.

How are customer service and support?

There is a very good community with CISCO.

How was the initial setup?

The initial setup is straightforward.

What about the implementation team?

The implementation can take anywhere from one day to a month for advanced tuning and firewall protection.

What was our ROI?

There is definitely a return on investment and is worth the money

What's my experience with pricing, setup cost, and licensing?

When it comes to pricing you pay for a permanent licensing structure. One, three, and five-year options. There are no extra costs.

What other advice do I have?

I would rate Cisco NGIPS a ten on a scale of one to ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer1664133 - PeerSpot reviewer
System Administrator at a tech services company with 201-500 employees
Real User
Sep 14, 2021
Impressive tech support with good interface and documentation
Pros and Cons
  • "The technical support is impressive."
  • "The solution is pricey, but worth it."
  • "The solution should contain the sandbox features which we find in Check Point."

What is our primary use case?

I cannot state which version we are currently using. 

What is most valuable?

The interface and documentation are fine. 

What needs improvement?

The solution should contain the sandbox features which we find in Check Point. 

For how long have I used the solution?

We have been using Cisco NGIPS for five years.

What do I think about the stability of the solution?

The solution is stable. 

What do I think about the scalability of the solution?

I suppose the scalability is fine. 

How are customer service and technical support?

The technical support is impressive.

How was the initial setup?

The initial setup is fine. 

What's my experience with pricing, setup cost, and licensing?

The solution is pricey, but worth it.

What other advice do I have?

I rate Cisco NGIPS as an eight out of ten. 

Disclosure: My company has a business relationship with this vendor other than being a customer. partner
PeerSpot user
Buyer's Guide
Download our free Cisco Secure IPS (NGIPS) Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2026
Buyer's Guide
Download our free Cisco Secure IPS (NGIPS) Report and get advice and tips from experienced pros sharing their opinions.