Our primary use case for Cisco Secure Firewall is segregation between different environments. We put Cisco Secure Firewall between each of those environments to create this segregation.
Network Lead at a tech company with 10,001+ employees
Simple deployment and is easy to manage but the GUI, functionality and flexibility should improve
Pros and Cons
- "Cisco Secure Firewall improved our organization. We have it in every one of our French offices."
- "One thing that Cisco could improve is the GUI. The graphic user interface should be more user-friendly."
What is our primary use case?
How has it helped my organization?
Cisco Secure Firewall improved our organization. We have it in every one of our French offices.
What is most valuable?
What I like about Cisco Secure Firewall is that you get to integrate it into one box. For example, you can have one big switch with a model inside of it. This makes it easy to manage.
What needs improvement?
One thing that Cisco could improve is the GUI. The graphic user interface should be more user-friendly. If you compare it with some of its competitor's GUIs, Cisco falls short in terms of how rules are pushed.
We have also run into issues with functionality and flexibility. Cisco does fall behind its competitors in this regard. It's our opinion that Cisco is not a leader in security devices.
Buyer's Guide
Cisco Secure Firewall
September 2026
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
913,924 professionals have used our research since 2012.
For how long have I used the solution?
I have been using Cisco Secure Firewall for two decades.
How are customer service and support?
We are satisfied with the level of support we get from Cisco. Getting support is quite easy. When we have a problem, our engineer just opens up a case and we get a reply quickly. The support usually has deep knowledge of the solution.
How was the initial setup?
I was involved in the initial deployment. It was quite simple, not complex at all.
What was our ROI?
We have seen a return on investment in terms of price because we have a partnership with our provider.
Which other solutions did I evaluate?
We chose Cisco Secure Firewall because we were already using Cisco switch routers and other products, so we wanted everything to be from one provider. However, we do use other products as an additional security measure.
What other advice do I have?
The solution does help us save time because it enables us to do a good job of filtering from the get-go. This ensures we have fewer potential threats to look through.
Cisco Secure Firewall has not helped us consolidate tools because part of our security strategy is having multiple firewalls from different providers. Our company policy is that it is better to have different technology, so we do have some overlap.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Founder CCIE
Adds value and helps organizations avoid problems and mistakes
Pros and Cons
- "What I found the most valuable about Cisco Secure Firewall is that if a client is educated about the solution, it can help him or her avoid many problems and mistakes."
- "Cisco's inspection visibility could be better."
What is our primary use case?
Our primary use case for this solution is to use it as a firewall. This product secures the internet from internal and public users.
How has it helped my organization?
Cisco Secure Firewall helped add to my organization's value. It is a selling product for us here. They have great support and documentation, which makes the solution easy to sell to customers. The Cisco name has a lot of value and high brand awareness.
We are selected partners now but are looking to grow to become a primary partner for Egypt.
Cisco Secure Firewall definitely saved us time. However, security is never 100% with any product, even Cisco. So, you will have to spend some time securing your IT regardless of which solution you use.
I would say that it helped my company cut time by 50%.
The solution cautions us against threats via email notifications and internally in the web interface of the product itself on the dashboard.
What is most valuable?
What I found the most valuable about Cisco Secure Firewall is that if a client is educated about the solution, it can help him or her avoid many problems and mistakes.
What needs improvement?
I think Cisco would benefit from comparing its solutions to other products. There is a lot to learn from solutions like Palo Alto or FortiGate. These are top security products. For example, Palo Alto has better inspection visibility than Cisco. When we ask customers about Palo Alto, they say "I like Palo Alto. It helps me see problems on time. I can audit everything through it." Cisco could improve in this regard. Cisco's inspection visibility could be better.
For how long have I used the solution?
I have been using this solution for a long time; since the PIX version in 2003. This adds up to almost 20 years now. I have had a plethora of experiences with this solution as both just an employee using it and also as the owner of a company. We also have a range of customers using the solution.
Which solution did I use previously and why did I switch?
We did not use any other solutions. Our strategy from the beginning has been to grow with Cisco. However, our customers have the final say in which solutions they choose and sometimes that's not Cisco. That has much to do with their previous beliefs and brand loyalty and trust. The customer's opinion matters and if the customer is loyal to Palo Alto, we are going to have a hard time getting them to make the switch.
How was the initial setup?
I am not involved in the deployment of the product. I have a sub that deploys Cisco Secure Firewall. I'm involved in guiding the deployment on the management side and making sure it's done in line with the customer's wishes.
Which other solutions did I evaluate?
I did evaluate other options but ultimately went with Cisco because of the support they offer. You can reach their tech support engineers at any time. That's important. Their documentation is great as well. Their site is wonderful.
What other advice do I have?
I rate the solution a seven out of ten.
Cisco Secure Firewall should be consolidated with routers, switches, or VOIP.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Cisco Secure Firewall
September 2026
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
913,924 professionals have used our research since 2012.
System Administrator at a healthcare company with 501-1,000 employees
Robust, integrates well, and offers effective protection against internal risks
Pros and Cons
- "Collaboration with other Cisco products such as ISE and others is the most valuable feature."
- "While this applies to all vendors, pricing can be always lower. In my opinion, Cisco is the most expensive. The pricing can be reduced."
What is our primary use case?
The Cisco Secure Firewall is placed between the separate VLANs. It's a common and effective method of protecting VLANs against internal risks such as Checkpoints and external parameters.
How has it helped my organization?
It certainly saves time. You can detect anything if you have nothing. This is why, in the end, it saves time.
What is most valuable?
Collaboration with other Cisco products such as ISE and others is the most valuable feature.
What needs improvement?
it is difficult to say what it needs in terms of what needs to be improved. I don't work with it on a daily basis.
I haven't heard anything negative about it.
While this applies to all vendors, pricing can be always lower. In my opinion, Cisco is the most expensive.
The pricing can be reduced.
For how long have I used the solution?
Our organization has been working with Cisco Secure Firewall for three to five years.
What do I think about the stability of the solution?
There are no complaints about performance or stability.
What do I think about the scalability of the solution?
There are no issues with the scalability. It works fine.
It is simple to upgrade.
We only need one person to maintain the product.
How are customer service and support?
My colleague has experience with technical support. I'm not sure if it was with Cisco's technical support directly or through Conscia in between.
Which solution did I use previously and why did I switch?
This was the first solution we were using.
We are primarily Cisco housed, and I believe that practically everything is Cisco.
It might be part of the contract for a small fee. I don't think there's any particular reason.
I am familiar with CheckPoint, as well as Microsoft ISA.
How was the initial setup?
We have an implementation partner.
It's a hands-on job with a colleague of mine.
I don't know if it is particularly easy or not.
There was also some learning involved, such as knowing the traffic. This took some time. It took six months to deploy.
With the implementation partner, everything was written out. It was the best-case scenario for us.
We did not use the Cisco Firewall Migration tool.
What about the implementation team?
Conscia assisted us with implementation.
They are one of the best in the Netherlands.
What's my experience with pricing, setup cost, and licensing?
I am not aware of the pricing.
It's an all-in-one contract.
What other advice do I have?
I would rate Cisco Secure Firewall an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
UC Solutions Engineer at Diversified
Video Review
Enabled my client to have thousands of remote users connect seamlessly through VPN
Pros and Cons
- "You can also put everything into a nice, neat, little package, as far as configuration goes. I was formerly a command-line guy with the ASA, and I was a little nervous about dealing with a GUI interface versus a command line, but after I did my first deployment, I got a lot more comfortable with doing it GUI based."
- "It enabled my clients to have remote users, thousands of them, and they're able to connect seamlessly."
- "I'm not a big fan of the FDM (Firepower Device Manager) that comes with Firepower. I found out that you need to use the Firepower Management Center, the FMC, to manage the firewalls a lot better. You can get a lot more granular with the configuration in the FMC, versus the FDM that comes out-of-the-box with it. FDM is like Firepower for dummies."
- "Because I don't like the management tool that comes out-of-the-box with it, the FDM, I'll give the Firepower an eight out of 10. That was a real pain dealing with, until they said, "Okay, let's get him an FMC.""
What is our primary use case?
I typically deploy firewalls to set up VPNs for remote users, and, in general, for security. I have a number of use cases.
With theUI basedpandemic, the customer really didn't have a VPN solution for their remote users, so we had to go in and deploy a high-availability cluster with Firepower. And I set up single sign-on with SAML authentication and multi-factor authentication.
How has it helped my organization?
We deploy for other organizations. I don't work on our own corporate firewalls, but I do believe we have some. But it definitely improved things. It enabled my clients to have remote users, thousands of them, and they're able to connect seamlessly. They don't have to come into the office. They can go home, connect to the VPN, log on, and do what they need to do.
What is most valuable?
I like that you can get really granular, as far as your access lists and access control go.
You can also put everything into a nice, neat, little package, as far as configuration goes. I was formerly a command-line guy with the ASA, and I was a little nervous about dealing with a GUI interface versus a command line, but after I did my first deployment, I got a lot more comfortable with doing it GUI-based.
What needs improvement?
I'm not a big fan of the FDM (Firepower Device Manager) that comes with Firepower. I found out that you need to use the Firepower Management Center, the FMC, to manage the firewalls a lot better. You can get a lot more granular with the configuration in the FMC, versus the FDM that comes out-of-the-box with it.
FDM is like Firepower for dummies. I found myself to be limited in what I can do configuration-wise, versus what I can do in the FMC. FMC is more when you have 100 firewalls to manage. They need to come out with something better to manage the firewall, versus the FDM that comes out-of-the-box with it, because that set me back about two weeks fooling around with it.
For how long have I used the solution?
I have been using Cisco Firepower NGFW Firewall for two or three years now.
What do I think about the stability of the solution?
It's good. It's stable. I haven't heard anything [from my customer]. No news is good news.
What do I think about the scalability of the solution?
It scales because you can deploy a cluster. You could have up to 16 Firepowers in a cluster, from the class I [was learning] in yesterday. I only had two in that particular cluster. It scales up to 16. If you have a multi-tenant situation, or if you're offering SaaS, or cloud-based firewall services, it's great that it can scale up to 16.
How are customer service and support?
They're always great to me. They're responsive, they're very knowledgeable. They offer suggestions, tell you what you need to do going forward, [and give you] a lot of helpful hints. It was good because I had to work with them a lot on this past deployment.
Now I can probably do it by myself, without TAC's help.
How would you rate customer service and support?
Positive
How was the initial setup?
The deployment was complex because that was my first time doing a Firepower. I did ASAs prior, no problem. I had to get used to the GUI and the different order of deploying things. I had to reset it to factory defaults several times because I messed something up. And then I had to get with Cisco TAC, for them to help me, and they said, "Okay, you need to default it and start over again".
But now, going forward, I know I need to deploy the FMC first, and then you deploy the Firepowers, and tell them where the FMC is, and then they connect, and then you can go in and configure it. I had it backward and it was a big thing. I had to keep resetting it. It was a good learning experience, though, and thankfully, I had a patient customer.
[In terms of maintenance] I've not heard anything back from my customer, so I'm assuming once it's in, it's in. It's not going to break. It's an HA pair. My customer doesn't really know too much about it. I don't know that they would know if one of them went down, because it fails over to the other one. I demonstrated to them, "Look, this is how it fails over. If I turn one off, it fails over." VPN doesn't disconnect, everything's good. Users don't know that the firewall failed over unless they're actually sitting there looking at AnyConnect. I don't think they know. So, I'll wait for them to call me and see if they know if something's broken or not.
What was our ROI?
As far as return on investment [goes], I would imagine there is some. For the users, as far as saving on commuting costs, they don't have to come into the office. They can stay home and work, and connect to the enterprise from anywhere in the world, essentially.
Which other solutions did I evaluate?
I've done a Palo Alto before, and a Juniper once, but mostly ASAs and Firepowers.
Naturally, I prefer Cisco stuff. [For the Palo Alto deployment] they just said, "Oh, you know, firewalls", and that's why the customer wanted Palos, so that's what I had to do. I had to figure it out. I learned something new, but my preference is Cisco firewalls.
I just like the granularity of the configuration [with Cisco]. I've never had any customers complain after I put it in, "Hey, we got hacked," or "There are some holes in the firewall," or any type of security vulnerabilities, malware, ransomware, or anything like that. You can tighten up the enterprise really well, security-wise.
Everything is GUI-based now, so to me, that's not really a difference. The Palos and the Junipers, I don't know what improvements they have made because [I worked on] those over five or six years ago. I can't even really speak to that.
What other advice do I have?
Because I don't like the management tool that comes out-of-the-box with it, the FDM, I'll give the Firepower an eight out of 10. That was a real pain dealing with, until they said, "Okay, let's get him an FMC." That was TAC's suggestion, actually. They said, "You really need FMC. The FDM is really trash."
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Technical Solutions Architect at NIL Data Communications
Video Review
Provides perimeter security, allowing/blocking of traffic, IPS, and port scans
Pros and Cons
- "The return on investment is not going to be restricted to just the box... Now, these genres have been expanded to cyber, to third-party integrations, having integrated logging, having integrated micro and macro segmentations. The scope has been widened, so the ROI, eventually, has multiplied."
- "The return on investment is not going to be restricted to just the box, because nowadays, if you look at the integrated security that Cisco has been heavily investing into, it's not just about ASA doing the firewalling functions."
- "The only improvement that we could make is maybe [regarding] the roadmap, to have better visibility as to what we are targeting ahead in the next few quarters."
What is our primary use case?
With [my company], NIL, it's cross-domain. It's just not ASA, but in particular we work with customers where we talk about the physical boxes or even the virtual appliances that we're deploying. The use cases can be multiple, but mostly what we have seen is perimeter security, looking at blocking [and] allowing of traffic before accessing the internet.
The majority of the challenges that we see across customers and partners is looking at the data, the integrity, security, [and] looking at various areas where they need to put in boxes or solutions which could secure their environments. It's not just about the data, but even looking at the endpoints, be it physical or virtual. That, in itself, makes the use case for putting in a box like ASA.
And, of course, with the integrations nowadays that we have from a firewall, looking at multiple identity solutions or logging solutions you could integrate with, that in itself becomes a use case of expanding the genres of integrated security.
What is most valuable?
The best features would obviously be the ones that are most used: the perimeter security, allowing/blocking of traffic, NAT-ing, and routing, or making it easy as compared to a router. If you were to do the similar features on a router, it would be way more extensive and difficult as compared to a firewall. These are the majority of the features that anyone would begin with.
But of course, they expanded to other features like IPS or cyber security or looking at vulnerabilities or scanning, port scans. Those are the advanced things.
[In terms of overall performance] in the last decade or so, especially in the last three or four years, the scale of where the architecture has been—all the numbers, the stats, everything—has gone up exponentially. It's all because of the innovations that are always happening, and not just at the hardware level, but particularly at the software level. Of course, we can always look at the data sheets and talk about the numbers, but all I can say, in my experience, is that the numbers have really gone up, and the speed at which the numbers have gone up in the last couple of years or so, is really progressive. That's really good to see.
What needs improvement?
We're reaching [the point] where we want it to be. If you go 10 years back, we did miss the bus on bringing in the virtual versus the physical appliance, but now that we have had it, the ASAv, for a few years, I think we are doing the right things at the right place.
The only improvement that we could make is maybe [regarding] the roadmap, to have better visibility as to what we are targeting ahead in the next few quarters. That is where we, as partners, can also leverage our repos with our customers and making them aware that there might be some major changes that we may have to introduce in their networks in the near future.
For how long have I used the solution?
I started back in the days with ASA when I was [with] Cisco. I was [with] Cisco for 12 years. I started as a TAC engineer, and one of the teams I was leading was the ASA team, firewall, and across VPN, AAA. it became like a cross-border team or cross-architecture, and it's been long enough. I've been working with ASAs for about 12 or more years now.
What do I think about the stability of the solution?
From the stability standpoint, it's way better. Is there a scope for improvement? Of course. There always is. But I can just speak from my experience. What it was and what it is today, it is way better.
What do I think about the scalability of the solution?
We look at scalability for any product of Cisco. I cannot be confined to the ASAs. We have physical, virtual, and cloud deployments. Everything is possible, so scalability is no issue.
How are customer service and support?
Support, when you look at any product from Cisco, has been top-notch. I was a TAC guy myself for 10 years and I can vouch for it like anyone would do from TAC.
Support has always been extensive. There is great detail in root cause analysis. Going back into my Cisco TAC experience, it's always the story that if you know the product well, you know the things that you need to collect for TAC or for any other junior SME to work with you collectively, to get down to the solutions sooner. Otherwise, they have to let you know what you need to collect. It's better to know the product, get the right knowledge transfer, work towards those goals, and then, collectively, we can work as a great team.
How was the initial setup?
I have mostly been involved in the pre-sales stage, and then eventually the post-sales as well. But we do the groundwork of making sure that we have set the stage for the customer to get the initial onboarding. And at times, I do it with other engineers or other colleagues who take it over from there. In my experience, it has been pretty straightforward.
It's not just the implementation, but [it's] also managing or maintaining [the ASA]. It would depend on how complex a configuration is, a one-box versus cluster versus clusters at different sites. Depending on the amount of configuration complexity and the amount of nodes that you have, you would need to look at staff from there. It's hard to put a number [on it and] just say you need a couple of guys. It could be different for different use cases and environments.
[In terms of maintenance] it's about a journey: the journey from having the right knowledge transfer, knowing how to configure a product, knowing how to deploy it, and then how to manage it. Now, of course, from the manageability standpoint, there are some basic checks that you have to do, like firmware upgrades, or backup restores, or looking at the sizing—how much your customer needs: a single node versus multiple nodes, physical versus virtual, cloud versus on-prem. But once you are done with that, it also depends on how much the engineers or SMEs know about configuring the product, because if they know about configuring the product, that's when they would know if something has been configured incorrectly. That also comes in [regarding] maintenance [of] or troubleshooting the product. Knowledge transfer is the key, and making sure that you're up to date and you have your basic checks done. Then, [the] manageability is like any other product, it's going to be easy.
What was our ROI?
The return on investment is not going to be restricted to just the box, because nowadays, if you look at the integrated security that Cisco has been heavily investing into, it's not just about ASA doing the firewalling functions. Now, these genres have been expanded to cyber, to third-party integrations, having integrated logging, having integrated micro and macro segmentations. The scope has been widened, so the ROI, eventually, has multiplied.
What other advice do I have?
Being a partner, we work with customers who already have different vendor solutions as well. At times, there are a mix of small SMB sites, which could be, let's say, a grocery. There are smaller stores and there are bigger stores, and at times, they do local DIAs or local internet breakouts. [That's where] you do see some cloud-based or very small firewalls as well, but when you look at the headquarters or bigger enterprises, that is where we would probably position Cisco.
[My advice] would depend [on] if they are comfortable with a particular product, if they've been working with a particular vendor. If it's a Cisco shop, or if they've been working on Cisco, or the customers are quite comfortable with Cisco, I would say this is the way to go. Unless they have a mixed environment. It will still depend on the SME's expertise, how comfortable they are, and then looking at the use cases and which products would nullify or solve them. That is where we should position it.
My lessons are endless with ASA, but my lessons are mostly toward product knowledge. When you look at the deployment side of things, or for me, personally, when I was TAC, to know how things work internally within ASA—like an A to Z story, and there are 100 gaps between and you need to know those gaps—and then, eventually, you will get to the problem and solve it in minutes rather than hours.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Network Support Engineer at a manufacturing company with 51-200 employees
Poor upgrade process can result in network failure, but the threat defense works well and it is scalable
Pros and Cons
- "Cisco's technical support is the best and that's why everybody implements their products."
- "The main problem we have is that things work okay until we upgrade the firmware, at which point, everything changes, and the net stops working."
- "From the perspective of return on investment, implementing the Firepower 2100 series is a bad decision."
What is our primary use case?
We primarily use this firewall for IPS, IAM, threat defense, and NAT.
I am from the networking department.
How has it helped my organization?
We are using the Firepower Management Center (FMS) and the management capabilities are okay. I would not say that they are good. The current version is okay but the earlier versions had many issues. The deployment also takes a long time. It takes us hours and in some cases, it took us days. The latest version 6.6.1, is okay and the deployment was quick.
I have tried to compare application visibility and control against Fortinet FortiGate, but so far, I don't see much difference. As I try to determine what is good and what is bad, I am seeking third-party opinions.
What is most valuable?
The most valuable feature is the threat defense. This product works well for threat defense but for everything else, we use Cisco ASA.
What needs improvement?
This product has a lot of issues with it. We are using it in a limited capacity, where it protects our DR site only. It is not used in full production.
The main problem we have is that things work okay until we upgrade the firmware, at which point, everything changes, and the net stops working. As a financial company, we have a lot of transactions and when the net suddenly stops working, it means that we lose transactions and it results in a huge loss.
We cannot research or test changes in advance because we don't have a spare firewall. If we had a spare then we would install the new firmware and test to see if it works, or not. The bottom line is that we shouldn't have to lose the network. If we upgrade the firmware then it should work but if you do upgrade it, some of the networks stop working.
For how long have I used the solution?
We have been using the Cisco Firepower NGFW Firewall for three years.
How are customer service and support?
Cisco's technical support is the best and that's why everybody implements their products. But, when it comes to Firepower, we have had many delays with their support. For all of the other Cisco products, things are solved immediately.
Nowadays, they're doing well for Firepower also, but initially, there was no answer for some time and they used to tell us that things would be fixed in the next version. That said, when comparing with other vendors, the support from Cisco is good.
Which solution did I use previously and why did I switch?
We use a variety of tools in the organization. There is a separate department for corporate security and they use tools such as RedSeal.
In the networking department, we use tools to analyze and report the details of the network. We also create dashboards that display things such as the UP/DOWN status.
We have also worked with Cisco ASA, and it is much better. Firepower has a lot of issues with it but ASA is a rock-solid platform. The reason we switched was that we needed to move to a next-generation firewall.
How was the initial setup?
The initial setup was not easy and we were struggling with it.
In 2017, we bought the Firepower 2100 Series firewalls, but for a year, there was nothing that we could do with them. In 2018, we were able to deploy something and we had a lot of difficulties with it.
Finally, we converted to Cisco ASA. When we loaded ASA, there was a great difference and we put it into production. At the time, we left Firepower in the testing phase. In December 2018, we were able to deploy Firepower Threat Defense in production, and it was used only in our DR site.
What about the implementation team?
We do our own maintenance and there are three or four of us that are responsible for it. I am one of the network administrators. We can also call Cisco if we need support.
What was our ROI?
From the perspective of return on investment, implementing the Firepower 2100 series is a bad decision.
What's my experience with pricing, setup cost, and licensing?
Firepower has a very high cost and you have to pay for the standby as well, meaning that the cost is doubled. When you compare Fortinet, it is a single cost only, so Fortinet is cheaper.
Which other solutions did I evaluate?
Prior to Firepower, we were Cisco customers and did not look to other vendors.
Given the problems that we have had with Cisco, we are moving away from them. We are now trying to implement FortiGate and have started working with it. One thing that we have found is that the Fortinet technical support is very bad.
What other advice do I have?
I would rate this solution a five out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Engineer at Teracai Corporation
One box gives us inbound/outbound access, as well as site-to-site and incoming client VPN
Pros and Cons
- "It's very scalable. You can go to different models of the ASAs and they scale up to as big as you want to go."
- "In terms of resilience, in general, if we have any box failure, being able to fail over to another box or to fail over to another site helps measurably."
- "They should work on making it a little more intuitive for users and not quite as complex. Still, it's a good product."
What is our primary use case?
Our use cases include inbound access, outbound access, as well as VPN solutions, both site-to-site and for an incoming client. We wanted something that would do all those things at one time, as opposed to having separate boxes.
Our deployment is on-premises. We're looking at going into cloud-based with some of it. Meraki is the cloud-based version of the ASAs.
How has it helped my organization?
If we have a power failure at one building, traffic can be routed to our other building. We also have backup data stores. I live in the Northeast, so in the event of ice storms that cause power outages, it really enables us to keep functioning as a company rather than going dark for the amount of time it takes to get the power back.
What is most valuable?
The GUI makes configuring it much simpler than the command line.
What needs improvement?
They should work on making it a little more intuitive for users and not quite as complex. Still, it's a good product.
For how long have I used the solution?
What do I think about the stability of the solution?
It's very stable. We've had no hardware issues at all and only very infrequent software configuration issues.
What do I think about the scalability of the solution?
It's very scalable. You can go to different models of the ASAs and they scale up to as big as you want to go.
How are customer service and support?
The technical support is very good. Whenever we call up Cisco, we get a rapid response. They help us in troubleshooting issues we have and we implement the solutions and go on.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
For me, there wasn't a previous solution here. I inherited the solution when I came in.
What was our ROI?
From a security standpoint, the return on investment is hard to quantify. You've stopped something that was going to cost you money, but how do you quantify that? How many times did it stop something from coming in that would have cost you a bunch of money? You don't know.
What's my experience with pricing, setup cost, and licensing?
We've compared it to other solutions, like WatchGuard and other types of firewalls in that same realm. Cisco ASAs are fairly priced and very competitive with them.
Some of the solutions we looked at had different GUI interfaces that might be a little bit easier to get around in, but they might not have had as many features. Cisco had the feature edge.
What other advice do I have?
Look at the features and consider what your migration path may be. Some other vendors offer firewalls with great bells and whistles, but when you look beneath the surface, they don't do exactly what they say. Do your due diligence and make sure you see everything.
In terms of resilience, in general, if we have any box failure, being able to fail over to another box or to fail over to another site helps measurably. Cyber security resilience is important for all organizations. The number of attacks going on just increases every day. There's a cost-benefit to building cyber security resilience. You have to get past that and build as much resiliency as you can. If you worry more about cost than you do about your product or your productivity, something else is going to fail.
Maintenance of the ASA is just the security updates that we watch for and updating the client software.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security admin at a wholesaler/distributor with 10,001+ employees
Used to protect systems against various methods of intrusion
Pros and Cons
- "This solution helped us to identify the key areas where we need to focus to block traffic that is malicious to our organization."
- "This tool offers great value with regard to cyber security due to its integration with different tools like Splunk and other cloud-based solutions."
- "The application detection feature of this solution could be improved as well as its integration with other solutions."
- "There is room for improvement when it comes to stability. We have encountered a lot of bugs using this solution."
What is our primary use case?
This solution is a next-generation firewall. We use it to inspect our traffic going through the internet edges. This solution blocks Tor nodes or botnets that try to invade the system using various methods for intrusion.
How has it helped my organization?
This solution helped us to identify the key areas where we need to focus to block traffic that is malicious to our organization. We can complete a layer 7 inspection and take a deep dive into the packets and block the traffic accordingly.
It took approximately six months to a year to realize the benefits of deploying this solution. It's an arduous process that is still ongoing.
What is most valuable?
This tool offers great value with regard to cyber security due to its integration with different tools like Splunk and other cloud-based solutions.
Within an application, you can block traffic at a granular level instead of relying on HTTPS traffic.
What needs improvement?
The application detection feature of this solution could be improved as well as its integration with other solutions.
For how long have I used the solution?
I have been using this solution for five years.
What do I think about the stability of the solution?
There is room for improvement when it comes to stability. We have encountered a lot of bugs using this solution.
What do I think about the scalability of the solution?
This is a scalable solution.
How are customer service and support?
I would rate the customer support for this solution an eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We previously used Check Point. We had an option to connect all of our security products from the endpoint to the firewalls to SASE-based solutions. This is why we changed solutions.
How was the initial setup?
The initial setup is straightforward because it is supported by good documentation. We did not experience many issues and deployment took a couple of months.
We first deployed the solution in monitoring mode before moving into protection mode. We required four or five engineers for this. It takes a lot of time to do any maintenance or upgrades. This is one of my key pain points for this product.
Maintenance requires two people; one to focus on the upgrade and one to monitor the traffic.
What was our ROI?
We have experienced a return on investment in terms of security that has added value.
What's my experience with pricing, setup cost, and licensing?
This solution offers smart licensing that is comparable to other solutions on the market.
What other advice do I have?
I would rate this solution a seven out of ten.
There are multiple data planes that run within this solution. My advice is to unify those data planes into a single data plane, so that traffic is sectioned and can be handled effectively. If you need a next-generation firewall, this is a good product.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Architecture Design Engineer at a comms service provider with 10,001+ employees
The stability is better than competitors and offers easy deployment
Pros and Cons
- "The IP filter configuration for specific political and Static NAT has been most valuable."
- "Cisco is more stable and offers easy deployment for the platform."
- "The access layer of this solution could be improved in terms of the way the devices interconnect with our network. We need to be able to analyze the traffic between the different interconnection in these areas."
What is our primary use case?
We started using this solution due to challenges with throughput. We needed devices with more quantity of throughput and bandwidth. We use this solution in different locations and different departments and we have around 2000 internal customers.
How has it helped my organization?
Cyber security resilience is really important for our organization. It is necessary for all the points for interconnections between LAN networks and WAN networks as we receive daily attacks.
What is most valuable?
The IP filter configuration for specific political and Static NAT has been most valuable.
What needs improvement?
The access layer of this solution could be improved in terms of the way the devices interconnect with our network. We need to be able to analyze the traffic between the different interconnections in these areas.
In a future release, we would like to have an IP analyzer to try to identify the specific comportment of the customers.
For how long have I used the solution?
I have been using this solution for seven years.
What do I think about the stability of the solution?
This is a very stable solution.
What do I think about the scalability of the solution?
This solution would need an adjustment to be scalable.
How are customer service and support?
Our engineers usually fix the issues we have, depending on the issue. When we reached out to the technical support team, they were attentive and helped us.
Which solution did I use previously and why did I switch?
We previously used Palo Alto, Fortinet, and Cisco Firepower. We switched because Cisco is more stable and offers easy deployment for the platform.
How was the initial setup?
This solution requires regular maintenance and I have 10 engineers that manage it.
What other advice do I have?
I would rate this solution a nine out of ten because it is a good product that is more stable than others on the market.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security engineer at a energy/utilities company with 10,001+ employees
We have more control over things going in and out of our network
Pros and Cons
- "We definitely feel more secure. We have more control over things going in and out of our network."
- "Third-party integrations could be improved. Not everything works out-of-the-box."
What is our primary use case?
We mainly use it for ICS security.
How has it helped my organization?
We definitely feel more secure. We have more control over things going in and out of our network.
Cybersecurity has been our top priority because of the last few attacks on our peers in the oil and gas industry.
What is most valuable?
The IPS solution helps us to not only navigate north-south traffic, but also east-west traffic.
What needs improvement?
Third-party integrations could be improved.
Not everything works out-of-the-box. Sometimes, you have to customize it to your needs.
For how long have I used the solution?
I have been using it for two years.
What do I think about the stability of the solution?
It is stable for the most part.
There is maintenance needed for software, firmware, and updates. Three or four people keep up with the updates, etc.
What do I think about the scalability of the solution?
It is pretty scalable. We can add as many devices as we want.
How are customer service and support?
The technical support is good. I would rate them as 10 out of 10.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We previously had a different platform. We wanted to converge multiple platforms into one.
I switched companies. So, I have more experience with Palo Alto.
What was our ROI?
We saw immediate benefits after deployment from having more control and visibility.
What's my experience with pricing, setup cost, and licensing?
Pretty much everything is included in the price for what we are using.
Which other solutions did I evaluate?
We looked at Check Point, Palo Alto, Fortinet, and a bunch of others. The management and support for the CIsco product is better.
What other advice do I have?
Listen to your customers and see what their needs are.
The whole stack provided by Cisco is a holistic solution for cybersecurity experts, like myself, and companies who are looking to secure their network.
You should partner up with a good team to view all products available, which cater and are customized to your needs.
We haven't found any gaps where it is lacking.
I would rate this product as eight or nine out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
Sophos Firewall
Check Point Cloud Firewall (formerly CloudGuard Network Security)
Cisco Umbrella
Palo Alto Networks NG Firewalls
WatchGuard Firebox
Cisco Identity Services Engine (ISE)
Check Point Harmony SASE (formerly Perimeter 81)
Cisco Meraki MX
Check Point Quantum Force (NGFW)
Cisco Secure Email
Azure Firewall
Cisco Duo
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Is The Biggest Difference Between Cisco ASA And Fortinet FortiGate?
- Cisco Firepower vs. FortiGate
- How do I convince a client that the most expensive firewall is not necessarily the best?
- What are the biggest differences between Cisco Firepower NGFW and Fortinet FortiGate?
- What Is The Biggest Difference Between Cisco Firepower and Palo Alto?
- Would you recommend replacing Cisco ASA Firewall with Fortinet FortiGate FG 100F due to cost reasons?
- What are the main differences between Palo Alto and Cisco firewalls ?
- A recent reviewer wrote "Cisco firewalls can be difficult at first but once learned it's fine." Is that your experience?
- Which Cisco firewall model is the latest: ASA or NGFW?
- Which is better - Fortinet FortiGate or Cisco ASA Firewall?














