What is our primary use case?
We primarily use the solution for network firewalling and intrusion prevention.
How has it helped my organization?
We get a bit of visibility into network threats and we can successfully mitigate those threats by using the product.
What is most valuable?
The most valuable feature would be the intrusion prevention for us for security reasons.
The setup is pretty straightforward.
The solution gives us a lot of visibility into our security.
The product is quite stable.
There are pretty good capabilities for scaling.
What needs improvement?
Currently, this product is difficult to manage. It needs to be more user-friendly.
A lot of improvements can be made into the overall architecture of the firewall. It's lacking right now. It's something they need to work hard to improve.
The reason for the lack of cohesion in the architecture is due to the fact that Cisco acquired this company and then they merged two products, the Cisco ASA and the Firepower product, into a single product. As a result, the product is not as mature as some of the other comparable products out in the industry.
The price is in the high end of the spectrum, again, comparing to other players in the industry.
The solution requires better management. When it comes to central management capabilities, improvements can be made.
Better reporting in terms of analytics and dashboards would be very useful in future versions.
For how long have I used the solution?
We've been using the solution for about five years now.
What do I think about the stability of the solution?
The stability overall has been good once we get it up and running. We've not seen any issues once we've launched everything. It isn't buggy or glitchy. It doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
The scalability on the solution is good overall. They have a central management console that can assist with the process. The only issue there is we feel like there's room for improvement on the administration side of things.
When it comes to a user installing the networks, all the users essentially traverse this firewall, but when it comes to the administrators of the product, we've got five administrators in networking, they pretty much use it on a daily basis.
How are customer service and support?
The technical support has been good. We're satisfied with the level of service we get. They know what they are talking about. They respond promptly. Overall, they are above-average. I'd rate them eight out of ten.
Of course, there's always a little bit of room for improvement from any technical support service. In general, it's always about the speed of resolving an issue, responsiveness, et cetera. These are common industry wide. We always want everything resolved faster.
Which solution did I use previously and why did I switch?
We previously used FortiGate. We switched as we wanted something that had easy management capabilities, so we moved to Cisco. We thought that Cisco would be a bit more mature.
How was the initial setup?
The initial setup is a little bit difficult. It's pretty straightforward, although if we look at it relative to other products on the market, we feel that the other products are easier to set up compared to this one.
What's my experience with pricing, setup cost, and licensing?
The pricing is actually pretty high, especially if you compare it to other solutions that are out there. They are comparable but cost less.
What other advice do I have?
The advice we would give to other organizations is to look at the administrative overhead, and also to pay close attention to when the company is deploying it. We feel that there are certain feature functionalities that might not be mature depending on a company's use case. Everything depends on use cases. A company needs to evaluate its own unique use case, and look at the product feature functionality. A company also needs to look at some of the administrative overhead before they choose the product to make sure that it is suitable for their environment.
This solution overall I would rate at seven out of ten. I would say it's a good product if you look at the primary functionality, which is intrusion prevention. It's is one of the best out there, however, the issue is it's been wrapped around an administrative layer which is quite difficult compared to other products. They've got a really good engine as far as IPSs go, and that's the most important thing.
Which deployment model are you using for this solution?
On-premises
*Disclosure: My company has a business relationship with this vendor other than being a customer: Partner