Cisco Secure Firewall vs Juniper vSRX comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
2nd
Average Rating
8.4
Number of Reviews
314
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (2nd), WAN Edge (1st)
Cisco Secure Firewall
Ranking in Firewalls
4th
Average Rating
8.2
Number of Reviews
405
Ranking in other categories
Cisco Security Portfolio (4th)
Juniper vSRX
Ranking in Firewalls
23rd
Average Rating
7.8
Number of Reviews
34
Ranking in other categories
Virtualization Security (3rd), Unified Threat Management (UTM) (8th)
 

Mindshare comparison

As of July 2024, in the Firewalls category, the mindshare of Fortinet FortiGate is 22.6%, up from 18.8% compared to the previous year. The mindshare of Cisco Secure Firewall is 6.2%, down from 6.3% compared to the previous year. The mindshare of Juniper vSRX is 0.3%, up from 0.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls
Unique Categories:
Software Defined WAN (SD-WAN) Solutions
19.7%
WAN Edge
21.4%
Cisco Security Portfolio
8.2%
Virtualization Security
7.1%
Unified Threat Management (UTM)
6.0%
 

Featured Reviews

Javed Hashmi - PeerSpot reviewer
May 24, 2023
Easy to configure, has a robust OS, and offers a lot of features at a very good price
Fortinet has a very strong OS. They have a single OS through which they integrate all the networks and security operations. Our experience has been very good. Fortinet gives us a single fabric for the security and network teams. This unification has helped us a lot in providing Secure SD-WAN and other solutions, such as network switches, wireless controllers, FortiNAC, FortiAuthenticator, etc. They have a single pane of glass for all these from the monitoring and visibility aspect. The integrated application protection provided by Secure SD-WAN is very good. Fortinet is a security-focused company. The features related to application recognition and how to enhance the performance and security of applications are pretty good. The customers for whom we deployed FortiGate have become long-term customers of Fortinet. Even when they compare the solution with some of the other vendors, they're more comfortable with going with Fortinet and upgrading and refreshing the hardware and the software. It's a very good product, and the customer satisfaction is pretty good. It impacts operational efficiency because we can quickly make the changes. For example, Cisco has some limitations in terms of the time it takes for any change to take effect, which impacts the operational efficiency, whereas in the case of Fortinet, they've got a very quick way of doing the changes and reverting them, which eliminates any downtimes because of the configurations. Their method for configuring and applying policies is very simple and easy. Because of that, it's very easy to do complex changes, and in the case of misconfiguration, revert those changes without much of an impact. Overall, Fortinet FortiGate brings a lot of operational improvements because of the strength of FortiOS. Secure SD-WAN has helped us remediate threats more quickly. Normally, with the WAN solutions or the simple SD-WAN solutions, security is done on the hub side. With the Secure SD-WAN solution, we can apply security at the branch level, so unnecessary or malicious traffic doesn't reach the data centers or the hub site, which helps in improving the overall security posture. Also, we can tighten and apply a single security policy across all the branches or different segments of the WAN, which improves overall security. Fortinet offers different security measures for blocking malicious traffic and having a uniform policy across the entire organization. Secure SD-WAN has helped reduce our mean time to detect (MTTD) and mean time to resolve (MTTR). Applying a central security policy at the branch level immediately helps us to detect any malicious traffic and block it there, so the chances of anything reaching the hub or the data center side are less. It improves MTTD and MTTR because it has a very good interface where we can easily respond to all the attacks and manipulate things. Applying security with the help of Secure SD-WAN helps to mitigate attacks from where they are originating, which improves MTTD and MTTR. Secure SD-WAN has helped reduce help desk tickets. Because of the operational efficiency and security, there are not many issues that impact the number of tickets. With the help of Secure SD-WAN, we can provide operational efficiency because we can apply policies on an application-level basis. With Secure SD-WAN, we can apply a security policy per application. The central security application structure helps to apply all the measures from one central place and from the cloud. Because it's connected to many intelligence centers, it future-proofs a business and improves it overall.
James-Buchanan - PeerSpot reviewer
Apr 2, 2023
Has excellent support and good licensing, and with the VPN feature, secures our users even when they're working from home
We use them for some of our border firewalls in our data centers and also as our VPN concentrator.  It's the VPN side of things that has been most useful for us. It allows us to secure our users even when they're working from home. They are able to access all of our resources, no matter where they…
JonathanHowell - PeerSpot reviewer
Apr 12, 2024
Provides access to route traffic with virtualization allowing you to leverage computing resources
The key dependency lies in the hardware. If you're hosting it in a virtual environment, it relies on the underlying hardware supporting that environment. Physically, you rely on the circuitry, chips, power, and other components. Therefore, using a virtualized platform introduces an additional layer of abstraction. You'll end up wasting money if you don't know what you're doing and use cases. It's not about buying a virtualized firewall. You're getting a virtualized router and a switch combined into one unit capable of performing telco-grade routing at a layer two level. It's a very complex piece of equipment used for threat management. It is capable of much more. We use it for its versatility; it can serve multiple purposes effectively. You can monitor the hypervisor for key performance indicators and understand how it's running and functioning. It integrates well with the most well-known operational toolsets. Overall, I rate the solution a nine out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The web filtering feature and the intrusion protection system are the most valuable. It is a resilient appliance. I never had an issue with it in terms of any security breaches."
"Initial setup is straightforward. There weren't too many issues with setting it up. It takes one hour or so."
"FortiGate is flexible and easy to use."
"Fortinet FortiGate is a security device. It can optimize security on the networks of a company. It actually protects the company from attacks from outside. With FortiGate, you can categorize the users. You can create a group of users that can access all of the websites for their work. You can limit other users' access."
"Fortinet FortiGate is scalable for our users. Right now, we have almost 70 users. We do not have any plan to increase our usage of FortiGate. For maintaining the firewall solution, one staff member is enough."
"User-friendly and affordable security solution that's recommended for SMB customers. This solution has good technical support."
"Its administrative panel is very intuitive and simple. It is simpler than the other solutions that we had. As an administrator, we are always looking for the easiest solution to manage network policies. We are able to filter everything on our network and also use the VPN feature, which is important these days when people are working remotely during COVID."
"Provides good firewall security and has great VPN features."
"The feature my customers find the most valuable is the exportability."
"VPN, firewall, and IDS/IPS allow us to deliver services to meet client needs across various industry verticals."
"The most important feature is the intensive way you can troubleshoot Cisco Firepower Firewalls. You can go to the bit level to see why traffic is not handled in the correct way, and the majority of the time it's a networking issue and not a firewall issue. You can solve any problem without Cisco TAC help, because you can go very deeply under the hood to find out how traffic is flowing and whether it is not flowing as expected. That is something I have never seen with other brands."
"This solution helped us to identify the key areas where we need to focus to block traffic that is malicious to our organization."
"Easy to deploy in a working environment between servers and users."
"I like that Cisco Firepower NGFW Firewall is reliable. Support is also good."
"All the rules are secure and we haven't had a significant malware attack in the five years that we've been using ASA Firewall. It has been a tremendous improvement for our network. However, I can't quantify the benefits in monetary terms."
"The stability is good. Very simple. Upgrades are great."
"It's basic functionality is probably the most valuable feature."
"The authentication part is seamless and easy for people."
"The product’s quality and performance are better than other vendors."
"The most valuable features are application filtering, content filtering, the intrusion prevention system (IPS), and definitely the application firewall."
"It's a very powerful solution and the firewalls offer high performance"
"The technical support has been good."
"It's much faster to deploy a power source. If you need to deploy a firewall in the cloud of software, it's much easier and much faster than deploying the office firewall in a rush."
"There are a few valuable features that offer very good quality on the solution. Especially NetScreen. We used to use NetScreen for the the product line. It was a very mature solution, very robust, easy to configure, easy to manage, etc. It made it easy to do everything."
 

Cons

"There were quite a few problems with the stability of the system."
"I have to say that the initial setup was complex. The deployment took a few days to get set up. Initially, we were using an IPVanish. We switched to this tool since we thought it would be easier. But it turns out it wasn't easier to set up and run."
"We were not able to build a full-mesh VPN; however, I am not sure if this was the fault of Fortinet FortiGate."
"It claims it does DLP, but the degree and level of controls are very basic."
"For the migration, everyone has a firewall in use and I am selling Fortinet. Typically, I am replacing another firewall. Previously, there was a tool available to convert configurations from one firewall, such as Palo Alto, to Fortinet, but this tool is no longer free. If it could be made free again, it would be very beneficial."
"Fortinet needs more memory to save the log files. We need it to save the logs on the hardware and not in the cloud. I know this feature is available in FortiCloud, but if we need this log locally, it is not available."
"It could use more templates for third-party site-to-site VPN setups other than FortiGate and Cisco."
"The stability of Fortinet FortiGate could improve."
"UTM features would be nice or some NextGen features."
"FlexConfig is there as a bridge for features that are not yet natively integrated into Firepower. It is a way of allowing you to be able to configure things that wouldn't otherwise be possible until the development team can add them into Firepower's native capability. There is still some work that needs to be done around FlexConfig. There are still quite a few complex things, like policy-based routing, that have to be done in FlexConfig, and it doesn't always work perfectly. Sometimes, there are some glitches. It is recommended that you configure FlexConfig policies with Cisco TAC. It would be good to see Cisco accelerate some of those configurations that you can only do in FlexConfig into the platform, so that they are there natively."
"There is limited data storage on the appliance itself. So, you need to ship it out elsewhere in order for you to store it. The only point of consideration is around that area, basically limited storage on the machine and appliance. Consider logging it elsewhere or pushing it out to a SIEM to get better controls and manipulation over the data to generate additional metrics and visibility."
"I'm working on a slightly older version, but what it needs is a better alert management. It's pretty standard, but there's no real advanced features involved around it."
"I think the ASA layer is thin. It's always Layer 3 or Layer 4 source controller and doesn't control the Layer 7 traffic. It's important, and you'll need an additional firewall."
"The Firepower FTD code is missing some old ASA firewalls codes. It's a small thing. But Firepower software isn't missing things that are essential, anymore."
"Cisco Secure Firewall should be easier to handle. It uses ASDM, which is not easy to understand. It would be better if there was direct access via HTTPS."
"I would like the ability to drill down into certain reports because currently, that cannot be done."
"We experienced some technical issues during implementation"
"We have some weird errors and some weird behavior on the solution occasionally. The device gets buggy without anyone touching it. It would work and then suddenly stop. Sometimes you need to just move the cards out and restart it again, and it will work. The solution itself, the hardware and the software, there must be some bugs that need to be dealt with."
"The GUI interface needs improvement."
"The solution should consider improving its licensing policies."
"The solution's GUI needs improvement."
"It is pretty complex to manage and could be easier."
"Juniper vSRX is expensive."
"The user interface could always be better. They could make it simpler and more intuitive."
 

Pricing and Cost Advice

"Compared to Palo Alto, which we have used in the past, pricing and licensing are okay."
"For medium and enterprise organizations, FortiGate is more affordable."
"When you look at these end security systems and firewalls, these firewalls even five years ago were $50,000 or perhaps $25,000 to implement in some types of customer sites. Now we're talking about tools that are $1,000. In this case, it might have been $500 or something like that."
"The product pricing is reasonable."
"They need to be competitive with other solutions."
"The price of the license and warranty can be better because it is very expensive."
"I give the pricing a nine out of ten."
"Fortigate's pricing is competitive."
"The cost is a big factor for us. This is why we are using it only in our restricted area. They are very much higher than their competitors in the market."
"​Price point is too high for features and throughput available.​"
"Cisco devices are for sure costly and budget could be an important constrain on selecting them as our security solution."
"Watch out for hidden licensing and incredibly high annual maintenance costs."
"It definitely competes with the other vendors in the market."
"License capacity needs to be extended and the vendor needs to work on the pricing."
"We've gone to all smart licensing, so that works well."
"Cisco's pricing is high, at times, for what they provide."
"We like pricing through the AWS Marketplace."
"Our experience purchasing the solution through the AWS Marketplace was good."
"As a customer, the pricing is good for us."
"The ongoing licensing cost seems to be pretty standard. There are no additional costs."
"I rate the tool's pricing a five out of ten."
"It is not that costly."
"The solution could have been cheaper."
"The pricing is reasonable."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
793,295 professionals have used our research since 2012.
 

Comparison Review

it_user206346 - PeerSpot reviewer
Mar 11, 2015
Cisco ASA vs. Palo Alto Networks
Cisco ASA vs. Palo Alto: Management Goodies You often have comparisons of both firewalls concerning security components. Of course, a firewall must block attacks, scan for viruses, build VPNs, etc. However, in this post I am discussing the advantages and disadvantages from both vendors concerning…
 

Top Industries

By visitors reading reviews
Educational Organization
21%
Computer Software Company
15%
Manufacturing Company
6%
Comms Service Provider
6%
Educational Organization
25%
Computer Software Company
16%
Government
6%
Manufacturing Company
5%
Educational Organization
82%
Computer Software Company
3%
Financial Services Firm
2%
Government
1%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
Which is better - Fortinet FortiGate or Cisco ASA Firewall?
One of our favorite things about Fortinet Fortigate is that you can deploy on the cloud or on premises. Fortinet Fort...
How does Cisco's ASA firewall compare with the Firepower NGFW?
It is easy to integrate Cisco ASA with other Cisco products and also other NAC solutions. When you understand the Cis...
Which is better - Meraki MX or Cisco ASA Firewall?
Cisco Adaptive Security Appliance (ASA) software is the operating software for the Cisco ASA suite. It supports netw...
What do you like most about Juniper vSRX?
One of Juniper vSRX's most valuable features is its integration with safety applications. It keeps the software secur...
What is your experience regarding pricing and costs for Juniper vSRX?
I rate the product’s pricing a three out of ten, where one is cheap, and ten is expensive.
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate
Cisco ASA Firewall, Cisco Adaptive Security Appliance (ASA) Firewall, Cisco ASA NGFW, Cisco ASA, Adaptive Security Appliance, ASA, Cisco Sourcefire Firewalls, Cisco ASAv, Cisco Firepower NGFW Firewall
No data available
 

Overview

 

Sample Customers

1. Amazon Web Services 2. Microsoft 3. IBM 4. Cisco 5. Dell 6. HP 7. Oracle 8. Verizon 9. AT&T 10. T-Mobile 11. Sprint 12. Vodafone 13. Orange 14. BT Group 15. Telstra 16. Deutsche Telekom 17. Comcast 18. Time Warner Cable 19. CenturyLink 20. NTT Communications 21. Tata Communications 22. SoftBank 23. China Mobile 24. Singtel 25. Telus 26. Rogers Communications 27. Bell Canada 28. Telkom Indonesia 29. Telkom South Africa 30. Telmex 31. Telia Company 32. Telkom Kenya
There are more than one million Adaptive Security Appliances deployed globally. Top customers include First American Financial Corp., Genzyme, Frankfurt Airport, Hansgrohe SE, Rio Olympics, The French Laundry, Rackspace, and City of Tomorrow.
Expedient Data Centers
Find out what your peers are saying about Cisco Secure Firewall vs. Juniper vSRX and other solutions. Updated: July 2024.
793,295 professionals have used our research since 2012.