IT Central Station is now PeerSpot: Here's why

Cisco ASA Firewall vs Cisco Firepower NGFW Firewall comparison

Cancel
You must select at least 2 products to compare!
Executive Summary
Updated on March 16, 2022

We performed a comparison between Cisco ASA Firewall and Cisco Firepower NGFW Firewall based on our users’ reviews in four categories. After reading all of the collected data, you can find our conclusion below.

  • Ease of Deployment: Users of Cisco ASA Firewall say if you are familiar with Cisco products, the deployment is easy. However, if you do not have experience using their products, it can be complex. In contrast, almost all user reviews of Cisco Firepower NGFW Firewall mentioned that the initial setup was easy and straightforward.
  • Features: Valuable features of Cisco ASA Firewall include intrusion prevention, intrusion detection, application control, URL filtering, stability, command-line interface, good reports, great visibility, remote VPN, ACL, and role-based access. Some of the features that users mention are lacking include better encryption, a less overwhelming user interface, stronger policy-based routing, and better configuration.

    Valuable features of Cisco Firepower NGFW Firewall include Unified Event Viewer, a fantastic UI, backup VTI tunnel, Dynamic Access Policies, Dynamic Objects, AnyConnect, Next-Generation Intrusion Prevention System, its stability, its speed, and ease of use. Features that users feel are lacking include its limited data storage, the fact that it is missing some older ASA firewall codes, the slower speed at which policies are deployed, and slow load times.
  • Pricing: Users of both Cisco ASA Firewall and Cisco Firepower NGFW Firewall say the pricing is expensive.
  • Service and Support: Users of Cisco ASA Firewall mention that service and support is excellent, noting that you have access to it 24/7. Likewise, users of Cisco Firepower NGFW Firewall say that technical support is brilliant, and that they do everything they can to help you.
  • ROI: Cisco ASA Firewall users confirm that they have seen an ROI by avoiding attacks and protecting their network. Comparably, Cisco Firepower NGFW Firewall users say they have seen a lot of value from the product, not just a monetary value.

Comparison Results: Based on the parameters we compared, Cisco ASA Firewall and Cisco Firepower NGFW Firewall are similarly well-thought of. Cisco Firepower NGFW Firewall seems to be slightly more popular than Cisco ASA Firewall. The major differentiation between the two is that Cisco Firepower NGFW Firewall seems to have a smoother deployment process.

To learn more, read our detailed Cisco ASA Firewall vs. Cisco Firepower NGFW Firewall report (Updated: July 2022).
Buyer's Guide
Cisco ASA Firewall vs. Cisco Firepower NGFW Firewall
July 2022
Find out what your peers are saying about Cisco ASA Firewall vs. Cisco Firepower NGFW Firewall and other solutions. Updated: July 2022.
622,358 professionals have used our research since 2012.
Q&A Highlights
Question: How does Cisco's ASA firewall compare with the Firepower NGFW?
Answer: It is easy to integrate Cisco ASA with other Cisco products and also other NAC solutions. When you understand the Cisco ecosystem, it is very simple to handle. This solution has traffic inspection and the Firepower engine which provides good application visibility and control. Cisco ASA gives you full details, traffic monitoring, and threat monitoring. Cisco ASA has very solid encryption and multi-factor authentication. This solution is a great option to enable work-from-home options seamlessly. The front-end configuration with Cisco ASA can be tough, though - there are too many steps in this process. It would also be better if there was a clear view of the integrations and the easiest way to complete them. In inexperienced hands, the Cisco ASA interface can be pretty daunting. An improved GUI would make this product much more user-friendly and competitive with other products. This solution can also be very expensive. In the security technology space, Cisco Firepower NGFW Firewall is one of the fastest, if not the fastest. This gives us confidence in knowing that the moment an attack comes online, we will be protected immediately. We also like the intrusion policy that Cisco Firepower NGFW Firewall provides. We are able to see active users vs. inactive users, which has helped increase productivity through visibility. We get proactive notifications if there are issues with our throughput. If you know your way around the Cisco ecosystem, things can be pretty simple to set up and manage. Deployment with Cisco Firepower NGFW Firewall takes too long, though. Other products are much faster. Additionally, when you have too many IPS rules, it slows down and impacts overall performance. Cisco Firepower NGFW Firewall does not have email security, and this is an important function we would like to see added with future upgrades. Conclusion These are both amazing products and in some situations, we have these two solutions working together. Overall, we found Cisco Firepower NGFW Firewall to have better flexibility and more granular access control. Cisco Firepower NGFW Firewall has some great micro-segmentations functionalities with regard to east-west and north-south traffic control, which is exactly what we wanted.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"This solution made our organization more secure and gave us better control.""The initial setup is easy.""The best features are stability and scalability.""The technical support is excellent. I would rate it as 10 out of 10. When there has been an issue, we have had a good response from them.""I love the ASDM (Adaptive Security Device Manager) which is the management suite. It's a GUI and you're able to see everything at a glance without using the command line. There are those who love the CLI, but with ASDM it is easier to see where everything is going and where the problems are.""ASA integrates with FirePOWER, IPS functionality, malware filtering, etc. This functionality wasn't there in the past. With its cloud architecture, Cisco can filter traffic at the engine layer. Evasive encryptions can be entered into the application, like BitTorrent or Skype. This wasn't possible to control through a traditional firewall.""Cisco ASA Firewall is a well known product. They're always updating it, and you know what they're doing and that it works.""The most valuable feature is that it's secure."

More Cisco ASA Firewall Pros →

"We have not had to deal with stability issues.""Another benefit has been user integration. We try to integrate our policies so that we can create policies based on active users. We can create policies based on who is accessing a resource instead of just IP addresses and ports.""The customer service/technical support is very good with this solution.""The solution offers very easy configurations.""The most important features are the intrusion prevention engine and the application visibility and control. The Snort feature in Firepower is also valuable.""This solution helped us to identify the key areas where we need to focus to block traffic that is malicious to our organization.""I have experience with URL filtering, and it is very good for URL filtering. You can filter URLs based on the categories, and it does a good job. It can also do deep packet inspection.""It is one of the fastest solutions, if not the fastest, in the security technology space. This gives us peace of mind knowing that as soon as a new attack comes online that we will be protected in short order. From that perspective, no one really comes close now to Firepower, which is hugely valuable to us from an upcoming new attack prevention perspective."

More Cisco Firepower NGFW Firewall Pros →

Cons
"You shouldn't have to use the ASDM to help manage the client.""The user interface is a little clunky and difficult to work with. Some things aren't as easy as they should be.""The solution needs to have better logging features.""Its user interface is good, but it could be better. Currently, you have to know what to do before you can manage a device. If you don't know what to do, you can mess things up. There are some devices that are easier, such as FortiGate. The user interface of FortiGate is more intuitive. It is very easy to log in and configure things.""Some individuals find the setup and configuration challenging.""On firewall features, Fortinet is better. Cisco needs to become more competitive and add more features or meet Fortinet's offering.""The price can be better.""Comparing Cisco solution to others, it is expensive, it would be better for it to be cheaper."

More Cisco ASA Firewall Cons →

"Cisco Firepower is not completely integrated with Active Directory. We are trying to use Active Directory to restrict users by using some security groups that are not integrated within the Cisco Firepower module. This is the main issue that we are facing.""On the VPN side, Firepower could be better. It needs more monitoring on VPNs. Right now, it's not that good. You can set up a VPN in Firepower, but you can't monitor it.""In a future release, it would be ideal if they could offer an open interface to other security products so that we could easily connect to our own open industry standard.""One of the few things that are brought up is that for the overall management, it would be great to have a cloud instance of that. And not only just a cloud instance, but one of the areas that we've looked at is using an HA type of cloud. To have the ability to have a device file within a cloud. If we had an issue with one, the other one would pick up automatically.""The ability to better integrate with other tools would be an improvement.""Licensing is complex, and I'd like it to be simplified. This is an area for improvement.""FirePOWER does a good job when it comes to providing us with visibility into threats, but I would like to see a more proactive stance to it.""Implementations require the use of a console. It would help if the console was embedded."

More Cisco Firepower NGFW Firewall Cons →

Pricing and Cost Advice
  • "Cisco is considered to be an expensive solution."
  • "It's very competitive with other products."
  • "We pay about $200 yearly and we have two firewalls."
  • "I'd say it's probably well-priced."
  • "The product cost is a little high. It is a little bit on the high side, and it should be a little bit cost-friendly."
  • "We pay about €2,000 ($2,400 USD) per year for licensing."
  • "If we compare it with FortiGate and the co-existing ASA, FortiGate is better in price."
  • "They seem to be at the top end in terms of pricing, but they are worth the price. They are probably a little bit lower than Palo Alto. If the customers are relying on Cisco products and they are thinking more in terms of scaling to another layer in a year, it is pretty much in a good price range."
  • More Cisco ASA Firewall Pricing and Cost Advice →

  • "Cisco, as we all know, is expensive, but for the money you are paying, you know that you are also getting top-notch documentation as well as support if needed."
  • "This product requires licenses for advanced features including Snort, IPS, and malware detection."
  • "This product is expensive."
  • "For me, personally, as an individual, Cisco Firepower NGFW Firewall is expensive."
  • "The price of Firepower is not bad compared to other products."
  • "The solution was chosen because of its price compared to other similar solutions."
  • "The price is comparable."
  • "It definitely competes with the other vendors in the market."
  • More Cisco Firepower NGFW Firewall Pricing and Cost Advice →

    report
    Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
    622,358 professionals have used our research since 2012.
    Questions from the Community
    Top Answer: When you compare these firewalls you can identify them with different features, advantages, practices and usage at large. In my opinion, Fortinet would be the best option and l use… more »
    Top Answer:One of our favorite things about Fortinet Fortigate is that you can deploy on the cloud or on premises. Fortinet Fortigate is very stable, reliable, and consistent. We like that we can manage the… more »
    Top Answer:It is easy to integrate Cisco ASA with other Cisco products and also other NAC solutions. When you understand the Cisco ecosystem, it is very simple to handle. This solution has traffic inspection and… more »
    Top Answer: The Cisco Firepower NGFW Firewall is a very powerful and very complex piece of anti-viral software. When one considers that fact, it is all the more impressive that the setup is a fairly… more »
    Top Answer:If you need a performance appliance, Cisco is not the one. Once you start adding policies, IPS and others, it chokes.  Fortinet has customs semiconductors that can handle hardware with a tremendous… more »
    Top Answer:Pick a product model for both vendors: Cisco & Palo Alto (refer to technical data sheets and whitepapers --)  See the key differences on your target or specific needs). Practical evaluation by a… more »
    Ranking
    4th
    out of 48 in Firewalls
    Views
    58,827
    Comparisons
    43,916
    Reviews
    82
    Average Words per Review
    543
    Rating
    8.4
    5th
    out of 48 in Firewalls
    Views
    45,810
    Comparisons
    30,188
    Reviews
    46
    Average Words per Review
    957
    Rating
    8.2
    Comparisons
    Also Known As
    Cisco Adaptive Security Appliance (ASA) Firewall, Cisco ASA NGFW, Cisco ASA, Adaptive Security Appliance, ASA, Cisco Sourcefire Firewalls, Cisco ASAv
    Cisco Firepower NGFW, Cisco Firepower Next-Generation Firewall, FirePOWER, Cisco NGFWv
    Learn More
    Cisco
    Video Not Available
    Overview

    Cisco ASA Firewall is a security device that combines firewall, intrusion prevention, virtual private network (VPN), and antivirus capabilities. Its main purpose is to provide proactive threat defense to stop attacks before they spread through the network.

    Cisco ASA Firewall Features

    Cisco ASA Firewall has many valuable key features, including:

    • Intrusion prevention system (IPS): Cisco ASA Firewall’s IPS provides contextual awareness.
    • Advanced threat protection: Gain protection against zero day threats (based on using global threat intelligence) .
    • Rapid threat containment: With Cisco ASA Firewall, you can proactively mitigate risks. If a threat is detected, additional security policies are applied to other network devices for increased protection.
    • High availability: Cisco ASA Firewall offers high availability for high resiliency applications
    • Integrated IPS, VPN, and unified communications capabilities
    • Multi-node clustering
    • Multi-site
    • High performance

    Cisco ASA Firewall Benefits

    Some of the benefits of using Cisco ASA Firewall include:

    • Superior protection from threats through CSC, IPS, and the like.
    • Better pricing means that TCO is reduced. 
    • High performance levels that can be scaled to achieve 10+ Gbps.
    • You can deploy new applications easily over secured layers.
    • Identity-based access helps you access business resources.
    • Identity-based access can be integrated with other services, such as LDAP and Microsoft Active Directory.
    • By implementing Cisco ASA Firewall, IT resources are freed up.
    • Because Cisco ASA Firewall offers effective prevention, your spyware cleanup costs decrease.

    Reviews from Real Users

    Below are some reviews and helpful feedback written by Cisco ASA Firewall users.

    A Cisco Security Specialist at a tech services company says, “All the features are very valuable. Among them is the integration for remote users, with AnyConnect, to the infrastructure. All the security through that is wonderful and it's very easy. You connect and you are inside your company network via VPN. Everything is encrypted and it's a very good solution.” He goes on to add, “The intrusion prevention system, the intrusion detection, is perfect. But you can also integrate Cisco with an IPS solution from another vendor, and just use the ASA with AnyConnect and as a firewall. Cisco ASA also provides application control. You can block or prevent people from going to certain applications or certain content.”

    Jonathan M., Head of Information Communication Technology at National Building Society, comments, "The benefits we see from the ASA are connected to teleworking as well as, of course, having the basic functionality of a firewall in place and the prevention of attacks. The standard reports allow us to constantly monitor our environment and take corrective steps.

    Eric H., CEO at NPI Technology Management, explains, “The command-line interface is really useful for us. We script basic installations and modifications through the command-line, which is considered sort of old school, and yet it allows us to fully document the changes that we're making due to the fact that we can save the exact script that was applied and say, "Here are the changes that we made."

    Cisco Firepower Next-Generation Firewall (NGFW) is a firewall that provides capabilities beyond those of a standard firewall and delivers comprehensive, unified policy management of firewall functions, application control, threat prevention, and advanced malware protection from the network to the endpoint.

    Cisco NGFW Firewalls include advanced threat defense capabilities to meet diverse needs, from small offices to high-performance data centers and service providers, and are deployed in leading private and public clouds. Available in a wide range of models, Cisco NGFW can be deployed as a physical or virtual appliance. Cisco NGFW firewalls are also available with clustering for increased performance, high availability configurations, and more.

    Key Features of Cisco NGFW Firewalls

    • Breach prevention and advanced security: Prevent attacks before they get inside. Cisco provides its firewalls with the latest intelligence to stop emerging threats and employs filtering to enforce policies on hundreds of millions of URLs. Cisco NGFW offers built-in sandboxing and advanced malware protection that continuously analyzes file behavior to quickly detect and eliminate threats.

    • Comprehensive network visibility: Constantly monitor your network so you can rapidly spot and stop bad behavior. Cisco NGFW provides a holistic view of all activity and provides a clear picture of threat activity across users, hosts, networks, and devices, as well as information on threats and website, application, and VM activities.

    • Flexible management and deployment options: Centrally deploy, customize, and manage all your appliances.

    • Fast detection: Detect threats in seconds and detect the presence of a successful breach within hours or minutes. Cisco NGFW allows you to deploy consistent policy that's easy to maintain, with automatic enforcement across all the different parts of your organization.

    • Automation and product integrations: Seamlessly integrate with Cisco tools and automatically share threat information, event data, policy, and contextual information with email, web, endpoint, and network security tools. Cisco NGFW automates security tasks like impact assessment, policy management and tuning, and user identification.

    Reviews from Real Users

    Cisco NGFW stands out among its competitors for a number of reasons. Two major ones are its extensive discovery abilities that enable you to constantly see what is happening on your network and take action when necessary, and the high level of protection it provides.

    Mike B., a director of IT security at a wellness & fitness company, writes, "It is one of the fastest solutions, if not the fastest, in the security technology space. This gives us peace of mind knowing that as soon as a new attack comes online that we will be protected in short order. From that perspective, no one really comes close now to Firepower, which is hugely valuable to us from an upcoming new attack prevention perspective."

    Zhulien K., the lead network security engineer at TechnoCore LTD, notes, " The most valuable feature that Cisco Firepower NGFW provides for us is the Intrusion policy. Again, with that being said, I cannot shy away from giving kudos to all of the other features such as AVC (Application Visibility and Control), SSL Decryption, Identity policy, Correlation policy, REST API, and more. All of the features that are incorporated in the Cisco Firepower NGFW are awesome and easy to configure if you know what you are doing. Things almost always work, unless you hit a bug, which is fixed with a simple software update. "

    Offer
    Learn more about Cisco ASA Firewall
    Learn more about Cisco Firepower NGFW Firewall
    Sample Customers
    There are more than one million Adaptive Security Appliances deployed globally. Top customers include First American Financial Corp., Genzyme, Frankfurt Airport, Hansgrohe SE, Rio Olympics, The French Laundry, Rackspace, and City of Tomorrow.
    Rackspace, The French Laundry, Downer Group, Lewisville School District, Shawnee Mission School District, Lower Austria Firefighters Administration, Oxford Hospital, SugarCreek, Westfield
    Top Industries
    REVIEWERS
    Financial Services Firm15%
    Comms Service Provider12%
    Computer Software Company9%
    Manufacturing Company8%
    VISITORS READING REVIEWS
    Comms Service Provider35%
    Computer Software Company19%
    Government6%
    Manufacturing Company4%
    REVIEWERS
    Comms Service Provider19%
    Financial Services Firm17%
    Government13%
    Manufacturing Company6%
    VISITORS READING REVIEWS
    Comms Service Provider29%
    Computer Software Company20%
    Government7%
    Manufacturing Company4%
    Company Size
    REVIEWERS
    Small Business35%
    Midsize Enterprise23%
    Large Enterprise42%
    VISITORS READING REVIEWS
    Small Business26%
    Midsize Enterprise22%
    Large Enterprise51%
    REVIEWERS
    Small Business40%
    Midsize Enterprise25%
    Large Enterprise35%
    VISITORS READING REVIEWS
    Small Business26%
    Midsize Enterprise20%
    Large Enterprise55%
    Buyer's Guide
    Cisco ASA Firewall vs. Cisco Firepower NGFW Firewall
    July 2022
    Find out what your peers are saying about Cisco ASA Firewall vs. Cisco Firepower NGFW Firewall and other solutions. Updated: July 2022.
    622,358 professionals have used our research since 2012.

    Cisco ASA Firewall is ranked 4th in Firewalls with 91 reviews while Cisco Firepower NGFW Firewall is ranked 5th in Firewalls with 53 reviews. Cisco ASA Firewall is rated 8.4, while Cisco Firepower NGFW Firewall is rated 8.2. The top reviewer of Cisco ASA Firewall writes "Includes multiple tools that help manage and troubleshoot, but needs SD-WAN for load balancing". On the other hand, the top reviewer of Cisco Firepower NGFW Firewall writes "The ability to implement dynamic policies for dynamic environments is important, given the fluidity in the world of security". Cisco ASA Firewall is most compared with Fortinet FortiGate, Palo Alto Networks WildFire, Meraki MX, pfSense and Juniper SRX, whereas Cisco Firepower NGFW Firewall is most compared with Fortinet FortiGate, Meraki MX, Palo Alto Networks WildFire, Check Point NGFW and pfSense. See our Cisco ASA Firewall vs. Cisco Firepower NGFW Firewall report.

    See our list of best Firewalls vendors.

    We monitor all Firewalls reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.