Try our new research platform with insights from 80,000+ expert users

Cisco Secure Firewall vs Stormshield Network Security comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
357
Ranking in other categories
Firewalls (2nd), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st)
Cisco Secure Firewall
Average Rating
8.2
Reviews Sentiment
7.3
Number of Reviews
428
Ranking in other categories
Firewalls (6th), Cisco Security Portfolio (4th)
Stormshield Network Security
Average Rating
7.8
Reviews Sentiment
6.0
Number of Reviews
17
Ranking in other categories
Unified Threat Management (UTM) (12th)
 

Featured Reviews

Jorge Martínez - PeerSpot reviewer
Offers good SD-WAN capabilities and integrates easily with Fortinet devices
I am not part of the initial setup or deployment process since I work in presales. The setup or deployment is quite easy, as you can do a one-touch deployment that automatically connects to the FortiManager cloud when you connect it to a broadband or dynamic IP, allowing you to start the configuration from that point. We usually sell it for on-premises setups. It's on the cloud only when the client has virtual machines or their own service. Sometimes they have a service on the cloud like AWS, but it's more difficult to sell now because AWS has an e-commerce option where you can buy FortiGate directly. The only thing you need is someone to manage and configure.
Carlos Reis - PeerSpot reviewer
Proven reliability and strong support spark trust but system updates slow and complex
The Cisco Secure Firewall product in general has room for improvement. I had a problem this weekend working with one of them, and I think it's very specific, though I'm going to be more general with my answer. Cisco has the FMC as a centralized tool, but sometimes they have too many dependencies. I faced a problem this weekend because while trying to solve an issue with one of the company's firewall management centers, I couldn't update or install an update on the platform due to a remote site being down. The device got stuck in my queue. I had to cancel my maintenance because of that. Everyone was expecting me to fix many bugs, but because of one device, I had to cancel everything. Sometimes the ID is nice around Cisco, but another area they need to improve is the capability to manage multiple devices. The FMC manages many devices, but if I put too many, around 300 devices, it becomes very slow, and the system becomes heavy. When you compare that with solutions such as Palo Alto, Palo Alto can manage many more devices on the same type of platform. Cisco is better at managing things such as RMAs. They do that exceptionally, even with the support. However, when we're talking about the FMC itself, sometimes they have some small issues; the platform is very slow and has too many bugs in the versions. We constantly need to update the platform to maintain stability.
Benjamin - PeerSpot reviewer
The intrusion detection system helps our organization by automatically detecting and responding to potential threats
The tool's most valuable feature is its dashboard, which helps you manage different aspects of a single page. The intrusion detection system helps our organization by automatically detecting and responding to potential threats. It operates similarly to Darktrace, which detects and responds automatically based on the security rules you apply. Initially, you configure everything to block, and then you can whitelist specific items as needed.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It's user-friendly and easy to operate."
"Stateful packet inspection is valuable. It also does SSL packet inspection. It is able to provide a VPN for remote users with secure connectivity."
"It has improved our organization with control data."
"The most valuable features are the enterprise modeling and the simple interface."
"The notable features that I have found most valuable are that it includes the antivirus, and also IPS, and even SD-WAN."
"FortiGate is on the cheaper end, and it offers good value."
"Fortinet FortiGate provides excellent security against ransomware attacks."
"The simplicity of the configuration and the stability of the product are most valuable. The VPN concentrator is very useful."
"It just works for us."
"Cisco Secure Firewall's ability to unify policies across our environment is pretty good."
"Cisco Firepower NGFW is really easy to use right now to determine when my file requires a shift from primary to secondary status, and it can be done with automation. Earlier we used to do this with patching."
"I would say the Firepower module is most valuable. I'm trying more to transition to this kind firewall. I had to study a little on Palo Alto Networks equipment. There is a lot I have to learn about the difference."
"Cisco ASA works very nicely from an administration perspective. The management of the device is very nice. The ASDM (Adaptive Security Device Manager) is the software that we use and it is very easy to configure using the GUI."
"The main thing that I love the most is its policy and objects. Whenever I try to give access to a user, I can create an object via group creation in the object fields. This way, I am not able to enter a user in the policy repeatedly."
"The features I have found most valuable are the ASA firewalls. I like to have features like most integrated systems in ACI."
"Cisco Secure Firewall is reliable, which is why we opted for it during the pandemic for our remote users."
"The scalability of the solution is good."
"I like that it works fine. Stormshield is a very good solution."
"Easily manageable in a variety of environments."
"The most valuable features are the IPS, the firewall function, and the price."
"I can see what traffic is going on. I can easily block any programs from attacks."
"This solution is quick and easy to configure."
"The solution has improved my organization because I can see what traffic is happening and I can use it to block and prevent attacks."
"The tool's most valuable feature is its dashboard, which helps you manage different aspects of a single page. The intrusion detection system helps our organization by automatically detecting and responding to potential threats. It operates similarly to Darktrace, which detects and responds automatically based on the security rules you apply. Initially, you configure everything to block, and then you can whitelist specific items as needed."
 

Cons

"I would like Fortinet to add more automation to FortiGate."
"There are just some services that aren't available. For example, the Ethernet or point-to-point protocols. They could add these services to their product offering - especially services for ISPs."
"The WAF is extremely limited."
"My only complaint about FortiGate is a lack of QinQ VLAN tunneling. I haven't found this feature in any Fortinet product. You can do this on all Cisco routers, including the smaller models. However, QinQ isn't available on the biggest, most expensive Fortinet units. They still don't have that. I think now we're on software version 6.0, and they still haven't found a solution for QinQ. It isn't a dealbreaker, but that's my main complaint."
"At the moment, if you don't integrate any third-party solution with a simple Fortinet FortiGate box, the box would not function as expected for superb protection."
"The renewal price and the availability could be improved."
"The command line is complicated, and the interface could be better."
"Areas of improvement for Fortinet FortiGate include the need for more training and certification, especially when dealing with distributors globally, which presents challenges in product availability and delivery timelines."
"Technical support is unsatisfactory for me. There might be restructuring within Cisco India or with the partner's capability."
"We had an event recently where we had inbound traffic for SIP and we experienced an attack against our SIP endpoint, such that they were able to successfully make calls out... Both CTR, which is gathering data from multiple solutions that the vendor provides, as well as the FMC events connection, did not show any of those connections because there was not a NAT inbound which said either allow it or deny it."
"The management of the firewalls could be improved because there are a lot of bugs."
"I think they need to review their whole UI because it feels like it was created by a whole bunch of different teams of developers who didn't fully talk to each other. The net policy screen is just a mess. It should look like the firewall policy screen, and they should both act the same, but they don't. I feel like it's two different buildings or programming, who don't talk to each other, and that really annoys me."
"The operation of the ASA is good but the problem is that whenever you require an upgrade, there are multiple pieces of software that you have to upgrade. Extensive planning is required, because if you upgrade one piece of the software it has to be compatible with the others as well. You always need to check the compatibility metrics."
"I was just trying to learn how this product actually operates and one thing that I see from internal processing is it does fire-walling and then sends it to the IPS model and any other model that needs to be performed. For example, content checking or filtering will be done in a field processing manner. That is something that causes delays in the network, from a security perspective. That is something that can be improved upon. Palo Alto already has implemented this as a pilot passed processing. So they put the same stream of data across multiple modules at the same time and see if it is giving a positive result by using an XR function. So, something similar can be done in the Cisco Firepower. Instead of single processing or in a sequential manner, they can do something similar to pile processing. Internal function that is something that they can improve upon."
"It would be good if Cisco made sure that the solution supports all routing protocols. Sometimes it doesn't."
"There could be some improvement in the way FMC displays the policy."
"With Stormshield, there are difficulties joining things, and it can be complex depending on the architecture."
"This is not a next-generation firewall."
"Stormshield Network Security is quite expensive."
"A more user-friendly interface would be helpful."
"Not all the fields are activated yet and we were informed that it will take at least one month."
"The biggest issue was their support department was not able to help us, then everything stops. This is a no-go area for me."
"The product must improve its pricing."
"The filtering configuration could be better. We have some difficulties with the filtering configuration and the filter extension. It's not that easy. It's not that straightforward. In the next release, I would like to see a reporting system. Stormshield doesn't have any tutorials on how to do the configuration and things like that. They just have documentation on the website. If you want to configure, for example, Cisco or Fortinet, you can find tutorials on YouTube. They show you how to configure the features, and so on. In Stormshield, there is nothing on social media or the internet on how to configure different things. The lack of documentation or the lack of material makes it difficult for others to adopt this solution."
 

Pricing and Cost Advice

"It is more affordable than Check Point and Palo Alto. Another thing is that all the features and the OS remain the same irrespective of the size of the device. Pricing-wise, Fortinet typically provides one-year support with the firewall appliance. There is also an option for three years which is how their licensing works."
"The pricing is fair."
"For medium and enterprise organizations, FortiGate is more affordable."
"We purchased a five-year bundle package, which worked out cheaper than competing solutions."
"We find the most valuable aspect of this solution is the price. It is affordable, and cheaper than other firewalls."
"Fortinet Secure SD-WAN delivered the lowest total cost of ownership (TCO) per Mbps among all other vendors."
"Fortinet bundles FortiGate with other products and because of this, the price is a little expensive to some SMB enterprises."
"It's an expensive solution."
"Their pricing is very aggressive and good. Even a small company can afford it. I am happy with its pricing. Its licensing is on a yearly basis."
"The licensing features are getting more complicated. These should be simplified."
"This is an expensive product, although when you buy this solution, you can do many things so it provides good value for the investment."
"​Price point is too high for features and throughput available.​"
"It has a great performance-to-price value, compared to competitive solutions."
"Pricing varies on the model and the features we are using. It could be anywhere from $600 to $1000 to up to $7,000 per year, depending on what model and what feature sets are available to us."
"The price of Firepower is not bad compared to other products."
"The pricing could always be cheaper."
"The pricing could be better."
"The price of this solution and the price of support are ok."
"We chose Stormshield for its price, as the Azure firewall was too expensive."
"I think the price is good."
"For mid-sized companies, they sell their appliances for good prices."
"The SN200 series costs between $500 USD and $600 USD per year, whereas the SN700 series costs approximately $1,000 annually."
"We bought a three-year license, and we renew it whenever it expires. The price could be better. It's always very expensive."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
857,028 professionals have used our research since 2012.
 

Comparison Review

it_user206346 - PeerSpot reviewer
Mar 11, 2015
Cisco ASA vs. Palo Alto Networks
Cisco ASA vs. Palo Alto: Management Goodies You often have comparisons of both firewalls concerning security components. Of course, a firewall must block attacks, scan for viruses, build VPNs, etc. However, in this post I am discussing the advantages and disadvantages from both vendors concerning…
 

Top Industries

By visitors reading reviews
Educational Organization
15%
Computer Software Company
15%
Comms Service Provider
7%
Manufacturing Company
6%
Educational Organization
41%
Computer Software Company
14%
University
5%
Manufacturing Company
4%
Computer Software Company
22%
Comms Service Provider
16%
Government
9%
Financial Services Firm
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
Which is better - Fortinet FortiGate or Cisco ASA Firewall?
One of our favorite things about Fortinet Fortigate is that you can deploy on the cloud or on premises. Fortinet Fort...
How does Cisco's ASA firewall compare with the Firepower NGFW?
It is easy to integrate Cisco ASA with other Cisco products and also other NAC solutions. When you understand the Cis...
Which is better - Meraki MX or Cisco ASA Firewall?
Cisco Adaptive Security Appliance (ASA) software is the operating software for the Cisco ASA suite. It supports netw...
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate, Fortinet Firewall
Cisco Adaptive Security Appliance (ASA) Firewall, Cisco ASA NGFW, Adaptive Security Appliance, Cisco Sourcefire Firewalls, Cisco ASAv, Cisco Firepower NGFW Firewall
NETASQ Firewalls
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
There are more than one million Adaptive Security Appliances deployed globally. Top customers include First American Financial Corp., Genzyme, Frankfurt Airport, Hansgrohe SE, Rio Olympics, The French Laundry, Rackspace, and City of Tomorrow.
ACESUR group, Ministry of Education Oman, Anios Laboratories, Zain, DLM Location
Find out what your peers are saying about Cisco Secure Firewall vs. Stormshield Network Security and other solutions. Updated: June 2025.
857,028 professionals have used our research since 2012.