Cisco Secure Firewall vs Cisco Vulnerability Management (formerly Kenna.VM) comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Cisco Secure Firewall
Ranking in Cisco Security Portfolio
4th
Average Rating
8.2
Number of Reviews
405
Ranking in other categories
Firewalls (4th)
Cisco Vulnerability Managem...
Ranking in Cisco Security Portfolio
12th
Average Rating
8.0
Number of Reviews
1
Ranking in other categories
Risk-Based Vulnerability Management (15th)
 

Mindshare comparison

As of July 2024, in the Cisco Security Portfolio category, the mindshare of Cisco Secure Firewall is 8.2%, up from 5.9% compared to the previous year. The mindshare of Cisco Vulnerability Management (formerly Kenna.VM) is 1.0%, down from 2.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Cisco Security Portfolio
Unique Categories:
Firewalls
6.2%
Risk-Based Vulnerability Management
3.4%
 

Featured Reviews

NH
Jun 15, 2023
Fantastic reliability, easy to understand, and works very well for policy-based VPN
We can automate the VPN. The build process and how we've standardized it makes it very easy for us to focus on other tasks. We know that an end user can push a button, and the VPN will get built. They only bring us in for troubleshooting or higher-level issues with the other vendor. Because of that program, the ability to use Cisco ASA every time, in the same way, makes our job easy. Once we started standardizing and using the same solution, we've been able to correlate that so we know what we are doing. We can train even less experienced and newer guys to do the tasks that in turn frees up the higher-level engineers. It has cut out the VPN work for higher-level engineers. They may have been spending ten hours a week previously, and now they may spend ten hours in the quarter. It has improved our cybersecurity resilience. It has allowed us to see some differences with partners using weaker ciphers, which allows us to validate what we're using and reevaluate it. We put exceptions in cases where we have to. The security risk team is as well aware of those, and they can essentially go back on a buy-in or see if the vendor has upgraded to plug in a security hole. It has given us that visibility to see where we are weak with our vendors.
AshishPaliwal - PeerSpot reviewer
May 19, 2022
Offers contextual prioritization and risk-based remediation of vulnerability
An improvement would be some sort of an integration with any GRC suite. There are a lot of GRC suites available, like Archer, MetricStream, Rsam, Protiviti, for example. So how would a solution like this work if my company has already invested thousands or maybe millions in a GRC solution? Do I still need it and how does it fit into an existing SAP environment? There could be interoperability, having more data sources, integrating Splunk, Qualys, FireEye, Rapid7, Carbon Black. I'm sure all that can be done to an extent, with a little more insight and a little more accuracy on the industry numbers and trends. I'd like the solution to offer any sort of assistance in any way with the remediation part, not just identification of vulnerability risk, and that is second.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Cisco ASA has an okay CLI with a nice GUI."
"The Packet Tracer is a really good tool. If someone calls because they're having problems, you can easily create fake traffic without having to do an extended packet capture. You can see, straight away, if there's a firewall rule allowing that traffic in the direction you're trying to troubleshoot."
"With the pandemic, people began working from home. That was a pretty big move, having all our users working from a home. More capacity needed to be added to our remote VPN. ASA did this very well."
"I'm a big fan of SecureX, Cisco's platform for tying together all the different security tools. It has a lot of flexibility and even a lot of third-party or non-Cisco integration. I feel like that's a really valuable tool."
"ASA 5505 and ASA 5506 are very powerful tools to use in a business environment, and provide a lot of security."
"We can shift traffic, block certain content, or redirect policies."
"The most valuable features of this solution are advanced malware protection, IPS, and IDS."
"The main thing that I love the most is its policy and objects. Whenever I try to give access to a user, I can create an object via group creation in the object fields. This way, I am not able to enter a user in the policy repeatedly."
"The risk context of any vulnerability is a valuable feature."
 

Cons

"The graphical interface could be improved. From what I have seen, Fortinet, for example, has a nicer GUI."
"In terms of what could be improved, I would say the UTM part should be more integrated for one price, because if you buy ASA from Cisco, you need to buy another contract service from Cisco as a filter for the dictionary of attacks. In Fortinet, you buy a firewall and you have it all."
"Cisco ASA is not a next-generation firewall product."
"One area that could be improved is its logging functionality. Your logs are usually displayed on the screen, but if you want to go back one or two days, then you need another solution in place because those logs are overwritten within minutes."
"There are always vulnerabilities that come up and there was one in early 2018 but this was patched with software updates."
"This product is managed using the Firepower Management Center (FMC), but it would be better if it also supported the command-line interface (CLI)."
"They could improve by having more skilled, high-level engineers that are available around the clock. I know that's an easy thing to say and a hard thing to do."
"It is a good firewall, though not NextGen."
"An improvement would be some sort of an integration with any GRC suite."
 

Pricing and Cost Advice

"The pricing and licensing structure of the firewall is fair and reasonable."
"In the past, I encountered several difficulties and misunderstandings with Cisco licensing, but now the situation has improved. The Cisco Smart Software portal is an excellent resource for keeping track of, upgrading, and researching information related to Smart Licensing and other relevant topics. It is extremely helpful. Unfortunately, since it is not my money and there is only one vendor, I am unable to provide any comments on the prices. Nevertheless, the system, along with its provision through the Cisco Smart Software portal, as well as the traditional license and subscription models, are excellent and highly beneficial."
"The solution was chosen because of its price compared to other similar solutions."
"In terms of costs, other solutions are more expensive than Cisco. Palo Alto is more expensive than Cisco."
"It is pay-as-you-go, so it much cheaper than buying in the plants."
"I just bought it off the shelf, and I'm using it with my previous one, so I have not spent that much."
"Cisco pricing is premium. However, they gave us a 50 to 60 percent discount."
"The licensing is a bit off because the physical firewall is cheaper than the virtual one. We only have the physical ones as they are cheaper than the virtual ones. We only use the physical firewalls because of the price difference."
"I think the pricing is based on the number of endpoints, so it's more subscription-based."
report
Use our free recommendation engine to learn which Cisco Security Portfolio solutions are best for your needs.
793,295 professionals have used our research since 2012.
 

Comparison Review

it_user206346 - PeerSpot reviewer
Mar 11, 2015
Cisco ASA vs. Palo Alto Networks
Cisco ASA vs. Palo Alto: Management Goodies You often have comparisons of both firewalls concerning security components. Of course, a firewall must block attacks, scan for viruses, build VPNs, etc. However, in this post I am discussing the advantages and disadvantages from both vendors concerning…
 

Top Industries

By visitors reading reviews
Educational Organization
25%
Computer Software Company
16%
Government
6%
Manufacturing Company
5%
Computer Software Company
23%
Financial Services Firm
13%
Retailer
7%
Insurance Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage at large. In my opinion, Fortinet would be the best option and l use Fortinet too...
Which is better - Fortinet FortiGate or Cisco ASA Firewall?
One of our favorite things about Fortinet Fortigate is that you can deploy on the cloud or on premises. Fortinet Fortigate is very stable, reliable, and consistent. We like that we can manage the e...
How does Cisco's ASA firewall compare with the Firepower NGFW?
It is easy to integrate Cisco ASA with other Cisco products and also other NAC solutions. When you understand the Cisco ecosystem, it is very simple to handle. This solution has traffic inspection ...
Ask a question
Earn 20 points
 

Also Known As

Cisco ASA Firewall, Cisco Adaptive Security Appliance (ASA) Firewall, Cisco ASA NGFW, Cisco ASA, Adaptive Security Appliance, ASA, Cisco Sourcefire Firewalls, Cisco ASAv, Cisco Firepower NGFW Firewall
Kenna.VM, Kenna Security, Kenna, Kenna Security Platform
 

Learn More

 

Overview

 

Sample Customers

There are more than one million Adaptive Security Appliances deployed globally. Top customers include First American Financial Corp., Genzyme, Frankfurt Airport, Hansgrohe SE, Rio Olympics, The French Laundry, Rackspace, and City of Tomorrow.
TransUnion
Find out what your peers are saying about Cisco and others in Cisco Security Portfolio. Updated: July 2024.
793,295 professionals have used our research since 2012.