We're working usually for the public sector and government organizations mostly. Also we work with some private sector organizations and private banks.
Cisco Secure IPS (NGIPS) provides intrusion prevention, malware detection, and DDoS protection with modularity, third-party integration, and cloud capabilities, focusing on flexibility, automation, and real-time threat detection, while offering centralized management and ease of upgrading.

| Product | Mindshare (%) |
|---|---|
| Cisco Secure IPS (NGIPS) | 3.4% |
| Darktrace | 10.1% |
| Fortinet FortiGate | 8.5% |
| Other | 78.0% |
| Company Size | Count |
|---|---|
| Small Business | 25 |
| Midsize Enterprise | 15 |
| Large Enterprise | 23 |
| Company Size | Count |
|---|---|
| Small Business | 153 |
| Midsize Enterprise | 47 |
| Large Enterprise | 125 |
Cisco Secure IPS (NGIPS) is designed to support network security through an open platform, delivering features such as anomaly detection and security intelligence. Users benefit from robust technical support, making it a reliable choice for enterprises seeking to protect their network infrastructures. However, improvements are needed in user-friendliness, interface complexity, and integration with third-party tools. There is a demand for better reporting, sandboxing capabilities, and enhanced AI-driven threat detection and response times, especially for zero-day attacks. Pricing remains a concern due to high costs and licensing complexity.
What are the key features of Cisco Secure IPS?Businesses deploy Cisco Secure IPS (NGIPS) in both on-premises and cloud environments, addressing needs like compliance audits and integration with platforms such as Cisco Talos and Umbrella. Its implementation strengthens perimeter security, enhances cybersecurity in enterprise and banking sectors, and ensures effective threat management for network defense.
Cisco Secure IPS (NGIPS) was previously known as Sourcefire NGIPS, Firepower NGIPS.
American Electric Power, Huntington Bank, Keycorp, Nationwide, Transunion, Marriott, Inova Health, Ford, Thomson Reuters, Dow Chemical, Equifax, Chevron, Walmart, Coca Cola
| Author info | Rating | Review Summary |
|---|---|---|
| System Engineer at a tech services company with 11-50 employees | 3.5 | I've used Cisco Secure IPS for years, but its lack of CLI, slow commit times, and unstable updates hurt usability. While their support varies, I still value Cisco’s switches and may recommend them cautiously depending on client needs. |
| IT Infrastructure Manager at TMLI | 3.0 | I use Cisco Secure IPS (NGIPS) to block unwanted software and suspicious behaviors. It excels in threat and botnet detection, is easy to integrate but could improve with automation and AI features for enhanced functionality. |
| Senior Network Security Expert & Instructor at a tech services company with 51-200 employees | 3.5 | I've used Cisco Secure IPS (NGIPS) for in-line traffic control and value its visibility, Snort engine, and real-time threat detection, though its stability, support, and high cost leave room for improvement, especially compared to Fortinet IPS. |
| IT Infrastructure Manager at TMLI | 3.5 | We deploy Cisco Secure IPS to prevent and detect network threats. It integrates well with other Cisco products and effectively captures logs. However, the dashboard needs updating. We see no clear ROI, and Cisco Firepower was our first choice. |
| Head Of Technical Operations at ITE | 3.0 | As a system integrator using Cisco Secure IPS, I find its features comparable to other NGFW solutions, but it faces competitive challenges due to limited educational investment and branding. I prioritize Palo Alto and Fortinet for their pricing and higher ratings. |
| Solutions Expert Engineer at Orange Moldova | 3.5 | I use Cisco Secure IPS for regulatory intrusion prevention, valuing its threat detection and single-vendor management. However, customer support and regional management are poor, making me consider other vendors, especially for Moldova projects. |
| Lead Sevice Engineer at Emerson | 4.0 | I use Cisco NGIPS as a stable DMZ firewall, though it has many bugs and Cisco's support is slow. Despite the high price, I am generally satisfied with the product, rating it 8/10. |
| Soc at a financial services firm with 5,001-10,000 employees | 4.0 | We deployed Cisco Secure IPS (NGIPS) to protect our financial sector servers, particularly in the DMZ zone. It excels in Trojan detection and integrates well with third-party tools. However, enhancing its AI for better intrusion prevention would be beneficial. |
| Solution Director - CTO at Huawei | 3.0 | I use Cisco Secure IPS in our bank's server center for traffic analysis and policy customization. It's effective for malware protection and anomaly detection. Recent OS and firewall improvements are notable, though detection for zero-day attacks could improve. |
| Networking and Security Engineer at IE Network Solutions PLC | 3.5 | I appreciate Cisco NGIPS's easy licensing and capable tech support. However, its complex deployment, instability, and scalability issues, especially with the Next-Generation product, make me hesitant to recommend it unless these problems are resolved. |
We're working usually for the public sector and government organizations mostly. Also we work with some private sector organizations and private banks.
This may not be the latest data, but the number of installations we secured with Cisco solutions was enormous, reaching tens of thousands of users. And it must be admitted that we didn't experience a serious security incident. This proves that the threat information and vaccines provided by the manufacturer were doing their job.
The best thing about Cisco is their good marketing force. We appreciate doing business with Cisco all the time, and I'd love to sell and install Cisco switches and other things.
Regarding security, my opinion is that the real value of a security solution lies in these information databases and is more important than, for example, ease of use or other features.
Cisco's got Talos security, and there are many people working there analysing security incidents and preparing new singnatures fast, so we are immune to new versions of malware.
There are numerous things that could be improved about Cisco Secure IPS (NGIPS) to get it back on track.
Sollution for small branches: when we have to connect a lot very small branches (or sometimes only an ATM) we need something small, with LTE and with reasonable price. Cisco response is SDWAN but it is not always the case. Recently Cisco released some small firewalls but I have not tried them yet.
Central management with FMC is a very good idea, but sometimes local management or monitoring is helpfull. With Cisco You have to decide: central or local. You cannot have both.
Regarding usability, when you commit configuration on Cisco, it sometimes takes very long. Commits also take some time for the competition, but Cisco is definitely lagging behind the rest in this respect.
Last but not least, for me as a professional is lack of CLI. With CLI, I can configure every firewall on the market except Cisco. CLI is very important in professional working, and IMHO it was an unwise decision by Cisco to remove it. Graphical interfaces are very nice, but when you've got thousands of objects in a big installation and have to configure many things, CLI is a much faster way to do it.
I have been using Cisco Secure IPS (NGIPS) for a long time. I'm CCIE for over 25 years and I installed a alot of ASAs and and many IPS sensors. At the beginning, it was PIX, ASA, IPS4500, IDSM Sensors, and then it was Firepower. Now, I don't really work very often with Cisco IPS. It's mostly with other vendors, but I still provide support to customers wich using FirePower.
We had some problems where after an upgrade, simple things stopped working. It was unfortunate that after upgrading to recommended software, some things stopped working, and these weren't just minor details but very important functions. And there are frequent problems with FMC. It's software so you can't fix it yourself, the only option is to open the case with TAC.
This happens with other manufacturers as well, but it occurs very frequently with Cisco. They are now in a position where they have to surprise us with good quality and ensure everything works properly.
However, the switches, router and other stuf are working very well, and we don't complain about and our customers are very pleased with them.
The technical support by Cisco used to be one of the best in the world. Sometimes it is very good, but i think they try to optimize business by lowering costs and buying support from other companies. When I open a Cisco ticket, I sometimes get a response from people from IBM. I believe IBM is a subcontractor of Cisco, and they employ people from other companies who sometimes knew very little. Usually, the first person in contact is incompetent most of the time.
When I get firs 10 initial questions, somme of them are irrelevant. I usually don't answer and ask for someone more competent, and then the next day I get someone qualified.
But the average level of Cisco's technical support is still very good especially when compared to other manufacturers.
Positive
My job is to secure customers networks. And it is not that I have switched, but I had to addapt to customer needs. At the end they decided what they want.
When people lose trust in the solution, they stop buying it and regaining the trust is very hard and time consuming. I have experience with all best security products on the market, and they all have advantages and some flaws. The future will show who will dominate this market.
Long time ago (times of ASAs, IPS Sensors) Cisco had probably 60-70% of the security market, but they made many mistakes and missed their chance with NGFWs. Many people who had ASA were very pleased with it. They wanted another firewall from Cisco, but they couldn't buy it because Firepower didn't work at the beginning or was at least problematic.They lost people's confidence. Now, the product is quite good, but the milk has been spilled.
The competition isn't without errors as well, but it seems that Cisco lost a lot of trust. They still have significant influence on the market in switching, routing, and other things and they are still able to rebuild trust.
They could regain some market share, but it takes time. Security is a matter of trust.
On a scale of 1-10, this solution receives a rating of 6.

Neutral
Our main use case for Cisco Secure IPS (NGIPS) is in-line traffic control, and we are using IPS in an in-line mode.
The features I really appreciate in Cisco Secure IPS (NGIPS) are the discovery features, Snort engine features, user mapping, visibility, and the IDS feature.
We are using real-time contextual data for threat detection, which is a valuable capability.
Cisco Secure IPS (NGIPS) helps me with the visibility component, providing visibility across more than 3,000 applications using Firepower IPS.
The main benefits Cisco Secure IPS (NGIPS) provides for us are security, visibility, and cost savings.
I am aware that we are not measuring some metrics or tracking access through Cisco Secure IPS (NGIPS).
In my opinion, Cisco could improve the Web GUI for Cisco Secure IPS (NGIPS).
I have been working with Cisco partner solutions for ten years.
I would rate the stability of Cisco Secure IPS (NGIPS) as middling.
I recommend it to other users, but I am concerned about stability, as the stability is not adequate.
I would rate scalability as between seven and eight.
I would rate Cisco technical support as not the best, especially compared to previous years.
The initial setup is straightforward.
We completed ten setups with our team for Cisco Secure IPS (NGIPS).
I would rate the price for Cisco Secure IPS (NGIPS) as high.
I can compare Cisco Secure IPS (NGIPS) with Fortinet IPS.

We use Cisco Secure IPS to prevent and detect any suspicious activities or network detections to prevent unwanted applications.
IPS decreases the risk for management.
Cisco has many products that are easily integrated with other services. The capability to capture logs and prevent unauthorized activities is beneficial.
The dashboard is quite old compared to today's technology. We would like to see improvements in the dashboard features.
We have been working with Secure IPS from Cisco for around ten years.
The solution is stable.
For IPS, it cannot be scalable. From our perspective, it is already fixed.
We have no issue with Cisco tech support. They resolve issues faster than expected.
Positive
We don't use any other solution.
There was no complexity in the initial setup.
We used a third party for the implementation.
We cannot calculate the ROI for a security product.
The pricing is standard and there is no issue.
Cisco Firepower was the first choice for us.
Cisco has a strong brand and the tech support is always available. It's a good fit for our company.
I'd rate the solution seven out of ten.

We are working as a system integrator, dealing with various network security products. Currently, I am dealing with Cisco products, including Cisco Secure IPS (NGIPS), for different facets of our networking setup. These include UCS servers, NGIPS firewall, Firepower, switching, routing, and AP controllers.
Cisco Secure IPS (NGIPS) is deployed on a very limited part of networks due to Cisco's historical lack of investment in education for Firepower. As a result, the market in Pakistan has been captured by Fortinet. All NGFW solutions, including Cisco Secure IPS, are largely similar in most respects. The choice is often dependent on the significance of the brand's name rather than their performance advantage in the security domain.
There are no specific additional features needed in Cisco Secure IPS (NGIPS) as most features are similar across all NGFWs. Any improvements would target marketing strategies and how they communicate with users because, technologically, all major firewalls are on par.
I am satisfied with Cisco's technical support, but I would rate it six out of ten. Fortinet, on the other hand, offers quicker response times and same-day RMAs, which gives them an edge in customer service.
Neutral
I have used Sophos, Fortinet, and Palo Alto. My choice for firewalls usually starts with Palo Alto, followed by Fortinet, and then Cisco because Palo Alto and Fortinet offer better pricing and are rated higher in Gartner.
The initial setup of Cisco Secure IPS (NGIPS) can be complex compared to Fortinet or Palo Alto. I had to spend several days with support to handle the licensing via a YouTube tutorial.
Cisco Secure IPS (NGIPS) has a higher cost compared to Fortinet, making it a less favorable option in terms of pricing.
In our country, most SD-WANs are based on Fortinet because it does not require a license, unlike Palo Alto. Also, Fortinet integrates multiple functionalities in a single firewall.
I don't recommend Cisco Secure IPS (NGIPS) unless the network infrastructure is predominantly Cisco. It is less commonly found in higher enterprise networks for security. My overall rating for Cisco Secure IPS (NGIPS) is six out of ten.

Our primary use case is for regulatory purposes. We use Cisco Secure IPS for intrusion prevention to manage all features from a single dashboard.
The solution is valuable since it is a single vendor option, which makes it easier to manage all features from one dashboard. The threat detection and prevention feature is particularly important for us.
Customer support needs improvement. The regional manager and the Romanian representative are not adequate. They should change their approach and policy since they currently do not allocate enough resources for smaller projects, like those in Moldova. This is not acceptable for a vendor of Cisco's stature. We are considering a change in vendors due to this issue.
We have been using the solution for about one year.
I would rate the stability of the solution as seven to nine out of ten.
The scalability of Cisco Secure IPS is strong, supporting our organizational growth with a rating of nine out of ten.
Customer service is lacking, and I would rate it as three out of ten. There is significant room for improvement.
Negative
We also use Zscaler. Unlike Cisco, Zscaler is more flexible in terms of vendor and regional management.
The initial setup was somewhat difficult. It took about a week to deploy.
On a scale from one to ten, Cisco Secure IPS pricing is relatively economical with a rating of four out of ten.
We have evaluated Zscaler as another solution.
I would not recommend Cisco Secure IPS to other users in Moldova because of the regional managerial approach and inadequate resources. They need to change their policy and position in the market.
I would rate the overall solution as seven out of ten.

I use Cisco NGIPS as a firewall for the DMZ zone.
Cisco NGIPS is not secured, and we did not use it in our company for VPN-related purposes. Cisco NGIPS is just to protect data. We use Cisco ASA, which has reached its end-of-sale cycle, and install Cisco NGIPS simply in our environment, which emulates features similar to Cisco ASA.
From an improvement perspective, Cisco's technical support team should work on their speed of response.
If there is a delay in the response time from Cisco's technical support team, it causes a problem since for our company, we don't have access to Cisco's site since it is a restricted zone. If we have some project in our company and we want to set up some remote access, then we need to enter some commands and tests. Some problems exist on my company's side when it comes to the product, but a better speed of response from the technical support team of Cisco would be good.
Cisco NGIPS should work on its shortcomings related to the issues that stem from bugs and performance.
I have been using Cisco NGIPS for a year or two. My company operates as an integrator for Cisco.
Though Cisco NGIPS is a stable tool that offers performance, there are a lot of bugs in the product. At the moment, my company has an open ticket with the support team of Cisco in relation to IGMP snooping, where there are some bugs causing issues.
The technical support provided by Cisco NGIPS is okay. I rate the technical support an eight out of ten.
Positive
I have some past experience with Cisco ASA and PIX.
It is difficult for me to speak about the price of the product since I am unable to compare it with other products in the market that may be its competitors. In our company, we know that the price of Cisco products is high, especially for its switches, routers and IOS. The price of Cisco products may be twice its original price if you plan to extend some of its features.
I am not responsible for the development part of my company, and it is our headquarters in the US that decided to opt for Cisco NGIPS. Initially, in our company, we used Cisco ASA and then Cisco NGIPS.
In my company, we operate the solution we use in our internal environment owing to cybersecurity reasons. In general, my company uses simple solutions and routers for protection that are not complicated, which means we don't use anything considered high-tech. For my company, the most important part when it comes to a solution is in terms of OT.
I am satisfied with Cisco NGIPS as a product. I rate the overall product an eight out of ten.
We have deployed Cisco Secure IPS (NGIPS) for intrusion detection and prevention in our financial sector. It protects our public-facing systems, especially in the DMZ zone, ensuring high security for servers involved in public transactions.
Cisco Secure IPS (NGIPS) performs exceptionally in Trojan detection, especially at the network level. We used a Next Generation Firewall on that aspect, which is amazing. Cisco products are also very good at integration with third-party tools.
It's better to strengthen the AI feature of the IPS. Considering different attack vectors, using AI to understand the behavior or features of network-level intrusions and protecting against zero-day attacks would be beneficial.
I have been working with Cisco Secure IPS (NGIPS) for about two to three years.
I find Cisco Secure IPS (NGIPS) stable.
The solution is good at scaling.
Before Cisco, we did not work with any other solutions for the IDPS.
I was not involved in the initial deployment or setup.
The pricing for Cisco Secure IPS (NGIPS) is quite high. They should consider revising the pricing strategies since there are other vendors in the market offering competitive pricing.
I would recommend Cisco Secure IPS (NGIPS) to others, although the pricing is high.
I'd rate the solution eight out of ten.

Our company uses the solution for data functions in banking. It is a backend solution in the server center.
We analyze traffic and adapt configurations or customize policies to the environment of the IPS itself.
The solution very effectively provides malware protection and signature-based anomaly detection. We don't need to use any separate tools.
The end delay layer was recently improved so it is much faster for service functions, training, and workflows.
Recent improvements to the OS and firewalling are good.
The solution could always enhance detection for zero-day attacks, SQL injection, and signature-based anomalies.
I have been using the solution for 15 years.
The stability needs improvement so is rated a four out of ten.
Technical support is rated a six out of ten.
Neutral
The setup is pretty normal but might be slightly more complicated than Fortinet. If you are familiar with the interface or have a technical background, then you won't have issues with the setup. New engineers might find the setup a bit complicated until they get used to it.
We implement the solution in-house. Deployment time depends on the environment itself. You also have to consider migrations and preparing the environment. In the learning phase, you determine any impact on protection or policy and adapt accordingly.
A large network will take longer to implement than a small one. Integrations can take some hours to many days, can take minutes to a month.
The solution is a good product so I rate it a six out of ten.
My company is a system integrator and we deploy Cisco NGIPS in various contexts, typically in the banking environment and in other high-level security scenarios, depending on our customer requirements.
We normally work with the most current models of Cisco products such as the Catalyst 9000 Series switches and 1000 Series routers.
The top features of Cisco NGIPS, which have been working very well, include stateful inspection and the access list-based security configuration. But from my perspective, the best part of Cisco NGIPS is the licensing process, which is very easy and straightforward. It's essentially copy-paste licensing.
The other aspect that I like is the technical support, who are highly capable. They were very good to us during the times that we used them and they tend to reply immediately to queries, even though you might not get the right engineer to help you right away. Tickets are usually assigned to junior staff at first but they do have escalation procedures, so if the support member can't solve the issue then they will immediately escalate it to higher management.
The feedback from some of our customers is that they weren't interested in Cisco because it was too complicated to deploy, especially in cloud-related areas.
Something else that our customers have commented on is that, in the current release of Cisco NGIPS that we are using, there have been some issues when they have tried to synchronize Cisco's hardware products with Cisco's management software.
If I recall correctly, the problems came from Cisco's Firepower Management software after we had proposed to our customers to use virtual machines as a cost-saving measure. After setting up the VMs, the software would start crashing, and it greatly disturbed the customers. It is possible that this was related to power issues because most of the time it would crash on power-on or power-off, but at other times it would crash due to incoming firewall traffic. I hope that in future releases, these problems will be solved.
In general, the ASA level features are working very well in Cisco products, but when it comes to the Next-Generation product, it has been somewhat unstable. To remedy this situation, Cisco needs to make the software more stable, easier to manage, and easier to update (possibly with an auto-updating mechanism). The small intricacies of the software product make the system more complicated than it needs to be for our engineers and our customers.
I have used Cisco NGIPS for four years.
Cisco's stability issues have caused several of our customers to complain directly to the vendor, and if these issues persist into the future I will not be able to continue recommending Cisco NGIPS to our customers. In terms of cost, security, compatibility, and flexibility, there are a lot of products doing better than Cisco, so why would customers keep buying Cisco if they can get better products with more stability? Cisco has to think of their global market first and foremost and fix their issues based on their findings. In our country, Cisco has a good name because they got here first, but a lot of customers have shifted, in terms of security, to other products such as Fortinet and Palo Alto, which have their own Next-Generation firewalls.
Cisco NGIPS is not that easy to scale, in my opinion. However, it can be upgraded, depending on the design. When you propose a design to customers, you have to check their expansion capability in terms of various factors such as how much time and how much employees would have to be involved.
When it comes to the VM products, some of them might not be scalable unless you upgrade your product to the latest version, in which case you have to upgrade the versions one by one. For example, your current version might 5.1 and you are aiming to upgrade to version 10.1. In this case, you would have to upgrade each intermediate version until you reach 10.1.
Cisco's tech support is very good and it was a pleasant experience whenever we used them. They tend to reply immediately, although when it comes to the technical capability of the support you might not get an appropriately skilled engineer to help you right away. However, they do have escalation procedures such that the junior staff will escalate any unsolved issues to higher management.
The ease of installation depends on the engineer. If they aren't trained in Cisco NGIPS or they aren't skilled enough, it's not easy to implement. You have to implement with a highly skilled engineer because it's not simple to deploy Cisco products.
We had one project where we implemented Cisco NGIPS along with a few other products and it took perhaps a week to fully deploy.
The annual licensing tends to be expensive, but in terms of implementing the licenses, it's a very uncomplicated process and as easy as copy-paste in its straightforwardness.
Regarding the affordability of the licensing, if you buy licenses on a yearly or quarterly basis, you might not find much return on investment, but at the same time you will have a better product with regular upgrades and less network interruptions, so this has to be weighed against the costs.
I have decided not to update our use of Cisco NGIPS unless they can solve their issues related to software stability, and thus I cannot fully recommend Cisco NGIPS to other customers at this time.
I would rate Cisco NGIPS a seven out of ten.