Cisco Secure Firewall vs KerioControl comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
2nd
Average Rating
8.4
Number of Reviews
314
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (2nd), WAN Edge (1st)
Cisco Secure Firewall
Ranking in Firewalls
4th
Average Rating
8.2
Number of Reviews
405
Ranking in other categories
Cisco Security Portfolio (4th)
KerioControl
Ranking in Firewalls
29th
Average Rating
8.2
Number of Reviews
56
Ranking in other categories
Intrusion Detection and Prevention Software (IDPS) (16th), Unified Threat Management (UTM) (11th)
 

Mindshare comparison

As of July 2024, in the Firewalls category, the mindshare of Fortinet FortiGate is 22.6%, up from 18.8% compared to the previous year. The mindshare of Cisco Secure Firewall is 6.2%, down from 6.3% compared to the previous year. The mindshare of KerioControl is 2.5%, up from 0.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls
Unique Categories:
Software Defined WAN (SD-WAN) Solutions
19.7%
WAN Edge
21.4%
Cisco Security Portfolio
8.2%
Intrusion Detection and Prevention Software (IDPS)
1.9%
Unified Threat Management (UTM)
8.2%
 

Featured Reviews

AV
May 10, 2023
Feature-rich, affordable, and has good performance
It is deployed on-premises. Our customers prefer to deploy not only Fortinet devices but all security devices on-premises. They rarely use cloud licenses. Some customers only buy it from us, and for some customers, we also set it up. Its setup is easy for us, but not every company wants to use our service for setting it up because of the cost. They prefer to install it themselves. In some cases, it could be hard for them. In terms of the implementation strategy, we first try to understand what problem a customer wants to solve by using FortiGate. We collect a lot of information about a customer's network, such as protocols and devices being used. We try to prepare this device in our local lab. We preload the device and send it to the customer, and then we finalize the installation in the customer's building. We have very technical staff, and we do not have difficulties with installations. We have had situations where customers do not have much experience with it, and then we recommend them to go for certain features such as IPS, antivirus, etc. The deployment duration depends on the size of the environment, but generally, it does not take more than one or two months.
CW
Jun 15, 2023
Helped us consolidate tools and applications and provides excellent documentation and support
The solution has improved our organization. I think my company was using Check Point back in the day. My company has 12 Cisco products. We used Palo Alto in my old organization. It’s what I'm most familiar with. The application visibility and control with Secure Firewall are not bad. The product’s alerting is pretty good. There were a couple of things that surprised me about the solution. It works really well because we use it with Secure Client and Secure Endpoint. Sometimes the solutions can cross-enrich each other, which we wouldn’t get with a dedicated, standalone firewall. The solution has helped free up our IT staff for other projects. We don't even have a dedicated firewall person. I sometimes do some stuff. Mostly the dedicated network admins run it, and they have time to do the rest of their job. Our whole network infrastructure team's only five to six people, and they can manage multiple sites across all different firewalls. It's not unreasonable to demand at all. The product has helped us consolidate tools and applications. If we were using another solution, we would have had their firewall, management plane, and other appliances to back that up. Having a product in the Cisco universe definitely does help. It's all right there when we're using Secure Client and Umbrella. I want more of what Cisco Identity Services Engine and DNA do. I don't like switching tabs in my browser. We use a relatively basic subset of Cisco Talos for general threat intel. It's definitely helpful. It's mostly about just getting the Talos definitions into the firewall so it can do all the heavy lifting so we don't have to. Now that Cisco has the XDR product, it will probably make it even more useful because then we can combine the network side, the security operations, and the threat intelligence into one thing to work harder for us. Cisco Secure Firewall has definitely helped our organization improve its cybersecurity resilience. I like the IDS a lot. The definitions work really well. Making custom ones is pretty trivial. We don't have to do complicated packet captures or anything of that kind. My advice would be to lean really hard on your sales engineer to explain the stack to you. There's definitely a learning curve to it. Cisco does things in a very particular way that's maybe a little bit different than other firewall vendors. Generally, it's pretty helpful talking to post-sales about what you need because you're probably not going to be able to figure it out. It's definitely a pretty top-shelf tool. If an organization already uses Cisco, they probably want to invest in the solution. Overall, I rate the solution an eight out of ten.
RB
Jun 25, 2020
VPN enables us to do remote work and we can better manage security
It is scalable up to a point that then you might have to use a user faster, bigger one, but on the whole, it is scalable. It's because based most installations I have are over 300. Whereas if they start to get really big, you'll need to increase the model to the next model up. In my company, it's me that manages and installs them all. We install, manage, and offer basic management and support. The environments we've installed for can go from three to 50 users. We've never had any problems with it not being able to manage the traffic.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Allows for firewall rules to be programmed and named in a way that makes it “readable”"
"We purchased Fortinet because of the pricing, its functionality, because it met our requirements, and the total cost of ownership over five years was quite reasonable. In the market, Fortinet is rated quite well."
"The signature database and zero-day detection are Fortinet FortiGate's most valuable features."
"There are lots of features and most of them are deployed for internet security. Users are protected if they accidentally go to some malicious sites."
"Layer-3 firewall and routing are the most valuable features."
"The most valuable features are that it is very simple to configure and to manage."
"The most valuable features of Fortinet FortiGate are the ease of use and there are several operating systems that can include the hardware capacities. In the newer releases, the resources were more useful because they were included in the operating system."
"Fortinet FortiGate meets all the security demands of my industry. It covers endpoint security, including web interface, DNS security, and ELP. I'm currently using the latest version. The features that have most improved our network security are Web Control, filtering, application control, IDS, IPS policies, and Deep SSL inspection."
"The most valuable feature is stability."
"It's the VPN side of things that has been most useful for us. It allows us to secure our users even when they're working from home. They are able to access all of our resources, no matter where they are in the world."
"The most valuable feature is the access control list (ACL)."
"Sourcefire has been a great addition. The visibility and control have been nice."
"We found the initial setup to be easy."
"The most valuable feature of this solution is its ability to integrate vertically."
"We use the solution for deep packet inspection, Internet Edge functionality, IDS, and IDP."
"I like that it is easy to change the settings."
"The most valuable feature is the reliability of VPN capabilities. The VPN has been very reliable and secure. The security has been very good and the VPN connections are reliable in that they stay up. We don't have a lot of problems with downtime and that type of thing."
"It prevents people from visiting undesirable sites and ensures that they use the internet for their designated jobs."
"The solution provides feasibility regarding cyber privacy."
"The most valuable features of KerioControl are ease of configuration, user-friendliness, and comfortable to use. It is an all-in-one solution, it comes with many features, such as a firewall, antivirus software, and network protection."
"I have found the most valuable features of Kerio Control to be the IPS and firewall."
"What I like the most about Kerio is that I can use the software appliance as a solution, so if the hardware fails for any reason then I can quickly replace it with hardware that I have in stock."
"The top features are ones that we're not using yet but we soon will be because we've just had broadband upgraded in Australia. We've got something called the National Broadband Network, which is forced onto you, so you have to take it when it arrives. We'll be trying the high availability out soon. We tried that with some load balancing, it didn't quite work as we expected, but I think that was more of a configuration thing rather than a product thing."
"The solution is easy to manage. Kerio Control is unique compared to other firewalls because it has been around since 2000 when we switched and the name it started with was WinRoute, and then later became Kerio Control. It evolved over time and it is more of a proprietary firewall on its own and has been developed through open source."
 

Cons

"It can be a little bit more user-friendly in terms of policy definition and implementation. It seems a little bit complicated, and it could be simplified."
"Scalability is one of the disadvantages. When it comes to scalability, you have to actually change the box. If you want to upgrade it, you need to actually change the existing box and probably you take the system off to other sites."
"Technical support needs to be improved."
"The updates Fortinet provides are sometimes unstable."
"It is very expensive, and their support is not very good. I hope that their technical support will be better in the future."
"The initial setup is complex."
"It would be ideal if they had some sort of GUI interface for troubleshooting and diagnostics."
"The solution could be more user friendly."
"Comparing Cisco solution to others, it is expensive, it would be better for it to be cheaper."
"While this applies to all vendors, pricing can be always lower. In my opinion, Cisco is the most expensive. The pricing can be reduced."
"We have seen some bugs come up with Cisco Secure Firewall in terms of high availability. The solution should be improved to avoid these bugs."
"The IPS module is combined with the main operating system."
"There was an error in the configuration, related to our uplink switches, that caused us to contact technical support, and it took a very long time to resolve the issue."
"It needs to provide the next-generation firewall features that other vendors provide, like data analytics, telemetry, and deep packet inspection."
"The Cisco ASA device needs overall improvement, as configurations alone do not completely secure my network."
"It is not easy to configure."
"Filtering of pages and greater personalization in services need improvement."
"The Kerio hardware devices look cheap and could be improved. Some of our clients are switching to Sophos because their hardware has a more sleek design."
"I would like the customer statistics to be more user-friendly. It should explain more what users have been doing throughout the day. Sometimes, it'll just say they downloaded a big file. Meanwhile, they were connected through a VPN."
"The product's technical support is not good as it used to be."
"The improvement that we are looking for is for when decide to move some part of our application to the cloud."
"Kerio Control could improve content filtering."
"My experience with the solutions technical support is fine but they could be faster in responding."
"The trial duration of the product should be extended."
 

Pricing and Cost Advice

"The price is fair for what we get with FortiGate."
"Compared to Palo Alto, which we have used in the past, pricing and licensing are okay."
"Setup costs and pricing depends on many variables, but it's mostly affordable."
"The price of FortiGate support is too expensive."
"The cost is too high... They have to focus on more features with less cost for the customer. If you see the market, where it's going, there are a lot of players offering more features for less cost."
"Fortinet FortiGate's price can be reduced."
"In terms of the market, it's not a cheap product, but it's cost-effective."
"If the customer is looking for SD-WAN, it comes free with FortiGate."
"It has a great performance-to-price value, compared to competitive solutions."
"The pricing seems fair. It is above average."
"I like the Smart Licensing, because it is more dynamic and easier to keep track of where you are at. If we have a high availability firewall pair and they are deployed in active/standby rather than active/active, I would expect that we would only pay for one set of licenses because you are using only one firewall at any one time. The other is there just for resiliency. The licensing, from a Firepower perspective, still requires you to have two licenses, even if the firewalls are in active/standby, which means that you pay for the two licenses, even though you might only be using one firewall any one time. This is probably not the best way to do it and doesn't represent the best value for money. This could be looked at to see if it could be done in a fairer way."
"That'd be more for my leadership, but I give them the quotes, and if they approve, they're happy. They've never wavered, so I wouldn't say it's out of the realm where they're considering another product. It must be in the direct price range for our leadership to not blink an eye when we give it to them."
"When we purchased the firewall, we had to take the security license for IPS, malware protection, and VPN. If we are using high availability, we have to take a license for that. We also have to pay for hardware support and technical support. Its licensing is on a yearly basis."
"With AnyConnect, it depends on your license. It depends on the number of concurrent users you want to connect."
"It is extremely expensive compared to its competitors and I would rate it 2 out of 10."
"The pricing and licensing are getting more complicated, and I'd like that to be simpler."
"The pricing is in-line with our expectations in terms of the quality that we get for it."
"My advice is to use your own hardware, and do not use theirs."
"Search and compare."
"The price of the solution is reasonable. For additional costs, you can add on more features such as antivirus."
"It's very affordable."
"I am living in Iran and we cannot buy the product from Kerio because of sanctions."
"The price of Kerio Control could be better, it is a bit overpriced compared to other solutions."
"Its initial cost is less as compared to other products. It becomes a bit costly when you pay for the products that you don't use. We paid for almost all the products through subscription, but we are using only a few products. We use EndPointSecurity, Kerio Connect, WebMonitor, and LanGuard. We don't use the rest of the products."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
793,295 professionals have used our research since 2012.
 

Comparison Review

it_user206346 - PeerSpot reviewer
Mar 11, 2015
Cisco ASA vs. Palo Alto Networks
Cisco ASA vs. Palo Alto: Management Goodies You often have comparisons of both firewalls concerning security components. Of course, a firewall must block attacks, scan for viruses, build VPNs, etc. However, in this post I am discussing the advantages and disadvantages from both vendors concerning…
 

Top Industries

By visitors reading reviews
Educational Organization
21%
Computer Software Company
15%
Manufacturing Company
6%
Comms Service Provider
6%
Educational Organization
25%
Computer Software Company
16%
Government
6%
Manufacturing Company
5%
Computer Software Company
24%
Media Company
8%
Financial Services Firm
8%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
Which is better - Fortinet FortiGate or Cisco ASA Firewall?
One of our favorite things about Fortinet Fortigate is that you can deploy on the cloud or on premises. Fortinet Fort...
How does Cisco's ASA firewall compare with the Firepower NGFW?
It is easy to integrate Cisco ASA with other Cisco products and also other NAC solutions. When you understand the Cis...
Which is better - Meraki MX or Cisco ASA Firewall?
Cisco Adaptive Security Appliance (ASA) software is the operating software for the Cisco ASA suite. It supports netw...
What do you like most about KerioControl?
The solution provides feasibility regarding cyber privacy.
What is your experience regarding pricing and costs for KerioControl?
KerioControl's pricing is reasonable. The license for KerioControl is annual. It's difficult to specify an exact cost...
What needs improvement with KerioControl?
I would like to see geo-IP filtering added to the filtering rules. Incorporating these rules would be very beneficial...
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate
Cisco ASA Firewall, Cisco Adaptive Security Appliance (ASA) Firewall, Cisco ASA NGFW, Cisco ASA, Adaptive Security Appliance, ASA, Cisco Sourcefire Firewalls, Cisco ASAv, Cisco Firepower NGFW Firewall
No data available
 

Learn More

 

Overview

 

Sample Customers

1. Amazon Web Services 2. Microsoft 3. IBM 4. Cisco 5. Dell 6. HP 7. Oracle 8. Verizon 9. AT&T 10. T-Mobile 11. Sprint 12. Vodafone 13. Orange 14. BT Group 15. Telstra 16. Deutsche Telekom 17. Comcast 18. Time Warner Cable 19. CenturyLink 20. NTT Communications 21. Tata Communications 22. SoftBank 23. China Mobile 24. Singtel 25. Telus 26. Rogers Communications 27. Bell Canada 28. Telkom Indonesia 29. Telkom South Africa 30. Telmex 31. Telia Company 32. Telkom Kenya
There are more than one million Adaptive Security Appliances deployed globally. Top customers include First American Financial Corp., Genzyme, Frankfurt Airport, Hansgrohe SE, Rio Olympics, The French Laundry, Rackspace, and City of Tomorrow.
Triton Technical, McDonald's
Find out what your peers are saying about Cisco Secure Firewall vs. KerioControl and other solutions. Updated: July 2024.
793,295 professionals have used our research since 2012.