Try our new research platform with insights from 80,000+ expert users
PeerSpot user
IT System Administrator at PFW HAVACILIK
Real User
Aug 20, 2018
Creates a unified strategy for event logging and correlation
Pros and Cons
  • "Beats sophisticated cyber attacks with a superior security appliance."
  • "Beats sophisticated cyber attacks with a superior security appliance."
  • "The Cisco ASA device needs overall improvement, as configurations alone do not completely secure my network."
  • "The Cisco ASA device needs overall improvement, as configurations alone do not completely secure my network."

What is our primary use case?

IT landscape is dynamic, requiring security policy, controls, and visibility to be better than ever. 

  • 1Gbps
  • Multi-service
  • Beats sophisticated cyber attacks with a superior security appliance.
  • IT landscape is dynamic.
  • Requires security policy, controls, and visibility to be better than ever. 

This applies to all ASA-related Management/to-the-box traffic, like SNMP, SSH, etc., with Firepower services combined with our proven network firewall along with the industry’s most effective next-generation IPS and advanced malware protection. Therefore, you can get more visibility, be more flexible, save more, and protect better.

How has it helped my organization?

Historic events related to security incidents. My organization must have a unified strategy for event logging and correlation.

What is most valuable?

The Cisco Product Security Incident Response creates and maintains publications, commonly referred to as PSIRT Advisories, for security-related issues in Cisco ASA.

What needs improvement?

The Cisco ASA device needs overall improvement, as configurations alone do not completely secure my network. The operational procedures in use on the network contribute as much to security as the configuration on devices.

Buyer's Guide
Cisco Secure Firewall
March 2026
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
884,976 professionals have used our research since 2012.

For how long have I used the solution?

Still implementing.

How are customer service and support?

There is 24/7 support anytime, anywhere.

Which solution did I use previously and why did I switch?

Before, I did not manage my private network well (or professionally). For this reason, I have been updating products.

What's my experience with pricing, setup cost, and licensing?

Commercial leasing is the best option.         

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Technology Associate at a financial services firm with 1-10 employees
Real User
Aug 19, 2018
The most valuable features are the IPsec VPN and web filtering. It seems very clunky and slow.
Pros and Cons
  • "The most valuable features are the IPsec VPN and web filtering."
  • "The most valuable features are the IPsec VPN and web filtering."
  • "It seems very clunky and slow. I would like to be able to tune it to be a more efficient product."
  • "I would like the ability to pick and choose different features of it to run in a packaged infrastructure or modules, therefore I would like to have more customizability over it."
  • "The use of it has really bogged down our response time for certain problems, given we have to go through AT&T for everything."
  • "It seems very clunky and slow. I would like to be able to tune it to be a more efficient product."

What is our primary use case?

Our primary use case is as a firewall and using it for web filtering. We use IPsec VPN services on it, as well as the router.

I have been using the product for only a few months, but the company has been using it for a couple of years.

How has it helped my organization?

The use of it has really bogged down our response time for certain problems, given we have to go through AT&T for everything. I don't think really highly of it, though.

What is most valuable?

The IPsec VPN and web filtering.

What needs improvement?

I would like the ability to pick and choose different features of it to run in a packaged infrastructure or modules, therefore I would like to have more customizability over it. 

It seems very clunky and slow. I would like to be able to tune it to be a more efficient product.

For how long have I used the solution?

Less than one year.

What do I think about the stability of the solution?

It has generally been okay in terms of stability. We haven't had it go down, but we do have some interruptions. I don't know if it is the ISP or the firewall. We have more frequent network disruptions, and other branches call in telling us that they are unable to use their services to do their job. Unfortunately, we can't really do anything about it. It just clears up in about five or six minutes. In terms of stability, I would give it a seven and a half out of 10.

What do I think about the scalability of the solution?

I don't see it being very scalable. I don't have access to the actual interface on it. However, it is an older product, so it probably doesn't have high availability features. So, it's scalability is probably limited. I know that we kind of put it through the ringer with our fewer than a hundred connections into it.

How is customer service and technical support?

AT&T handles our technical support, since it's leased through them.

How was the initial setup?

I was not involved with the initial setup.

What's my experience with pricing, setup cost, and licensing?

We pay a lot of money for it.

For big organizations who are used to throwing around a lot of money for absolutely surety, this would probably be a good fit for them. For the average SME, this particular firewall system, as well as Cisco in general, this product would not be a good fit for them.

Which other solutions did I evaluate?

We are currently looking at WatchGuard, pfSense, and Fortinet FortiGate. Netgate would provide the hardware.

We have still got nine months left on our contract with AT&T before we can actually do anything. We are just trying to do as much research and ask as many questions as we can before we get to that point.

What other advice do I have?

We just don't have a lot of the control or customizability that we would like to have over the system. A lot of this has to do with how AT&T is handling the access to it. Also, the hardware is outdated. We would like to go with a product in which everything is very transparent, clear, organized, all in the same place, and we can monitor clearly. The reason that we are looking to change is price: We pay a lot for it. If we had more control over it, we would be better able to control the quality and performance of the network and services, as well as the budget.

The most important criteria when selecting a vendor:

  • IPsec VPN
  • Good stable connection
  • Failover support: We need to have dual-WAN, so we can get two WAN connections in there and have failover. 
  • Load balancing would be good, especially for those rough patches. 
  • Internal web filtering and blocking: We need to be able to control what our end users are looking at.
  • Monitoring: As much monitoring as we can get.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Cisco Secure Firewall
March 2026
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
884,976 professionals have used our research since 2012.
it_user916539 - PeerSpot reviewer
Solutions Architect at a tech services company with 10,001+ employees
Real User
Aug 16, 2018
Allowed us to consolidating multiple security devices into a single appliance
Pros and Cons
  • "It allowed us to consolidating multiple security devices into a single appliance."
  • "It allowed us to consolidating multiple security devices into a single appliance."
  • "We are looking for software taxi capabilities."
  • "We are looking for software taxi capabilities."

What is our primary use case?

  • High-performance intrusion prevention
  • Malware protection
  • Multiple firewalls to control departments on a business by business level (security policies per department).
  • Allowed us to consolidating multiple security devices into a single appliance.

How has it helped my organization?

  • Intrusion protection
  • We were able to determine when we are being attacked.
  • We determine that our inspections were causing latency.

We needed a way to monitor threat protection and not cause latency.

What is most valuable?

It allowed us to consolidating multiple security devices into a single appliance. It consolidated and helped us eliminate firmware upgrade issues across multiple devices. The "Keep It Simple" method.

What needs improvement?

We are looking for software taxi capabilities.   

For how long have I used the solution?

One to three years.

Which other solutions did I evaluate?

Going forward, we are evaluating Anomali. The founder of ArcSight founded Anomali. The product has the ability to be a consumer of threat intelligence, and be a contributor showing the maturity in threat protection posture.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user900396 - PeerSpot reviewer
Support Engineer at a tech services company with 51-200 employees
Reseller
Aug 7, 2018
We can shift traffic, block certain content, or redirect policies
Pros and Cons
  • "We can shift traffic, block certain content, or redirect policies."
  • "It's primarily for managing our employees; so far, it has been working great and we don't have many problems."
  • "We would like to see MS Word BPM as a feature."
  • "It is a great solution for medium or big enterprises, not so much for small businesses, mainly due to the financial costs."

What is our primary use case?

It's primarily for managing our employees. So far, it has been working great. We don't have many problems.

How has it helped my organization?

It gives us all the features that we need.

What is most valuable?

We can shift traffic, block certain content, or redirect policies.

What needs improvement?

We would like to see MS Word BPM as a feature. 

For how long have I used the solution?

Three to five years.

How are customer service and technical support?

We don't use the technical support too much. It is not good, especially for Latin America. Therefore, we employ people who have skills or certifications, using them for technical support.

Which solution did I use previously and why did I switch?

We started with Cisco Firepower.

How was the initial setup?

It was a bit complex to set up. However, after some practice, it was not too difficult.

What's my experience with pricing, setup cost, and licensing?

It is a great solution for medium or big enterprises, not so much for small businesses, mainly due to the financial costs. Cisco Firepower is a great solution, but it is expensive compared to others that can provide similar benefits for much less.

What other advice do I have?

Most important criteria when selecting a vendor:

  • Quality of the product
  • Cost.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
IT Manager at a construction company with 11-50 employees
Real User
Aug 7, 2018
User-based firewall rules are helpful but the solution needs to be more reliable
Pros and Cons
  • "I have used technical support once, and they were superb."
  • "The product crashes. We have a cluster of firewalls and we regularly get failovers."
  • "The product crashes. We have a cluster of firewalls and we regularly get failovers."

What is our primary use case?

Firewall and VPN.

How has it helped my organization?

I can't really say how it has improved our organization, but the benefits are that we have a necessary firewall with which we can create VPNs.

What is most valuable?

Pro user-based firewall rules.

What needs improvement?

The solution that we have right now doesn't do what I want it to do. We don't have a ratified solution for all the things that I wanted to right across our business. We're doing similar functions using different technology and I want ratification. I want to be able to do more than what we are currently able to do with the existing service, all under the umbrella of improving security.

What do I think about the stability of the solution?

The product crashes. We have a cluster of firewalls and we regularly get failovers.

How are customer service and technical support?

I have used technical support once, and they were superb.

Which solution did I use previously and why did I switch?

When selecting a vendor, the most important criteria include:

  • Security - the ability of the technology from a security perspective.
  • The ability of the company to support the technology - knowledge of the product by the company. It may sound really silly to say that, but you'd be surprised how poor some companies' technical support is.
  • The financial stability of the company.

How was the initial setup?

I was involved in the initial setup. It was complex. 

What other advice do I have?

Do your research, know what you want to achieve.

Cisco ASA needs to be more reliable. Because of the nature of the product, it has to be rock solid and, unfortunately, it's not.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Asst.Manager IT at a manufacturing company with 501-1,000 employees
Real User
Jul 26, 2018
Blocks threats from the application layer
Pros and Cons
  • "The GUI is among the most valuable features,"
  • "It gives good performance, the technology is quite good, sufficient for our objectives, protecting our network, etc."
  • "It could use a web-based portal for VPN. Earlier they had it in the ASA model, but currently they don't have it."
  • "It is on multiple boxes so ISP load balancing, multiple network load balancing would be helpful. Also a web-based portal for VPN would be helpful because earlier they had it in the ASA model, but currently they don't have it."

What is our primary use case?

The primary use is to block incoming threats from the internet, at the edge of the network.

It's performing well. We check the report of blocked pages, blocked attacks, etc.

How has it helped my organization?

Previously, we only had a normal firewall, it was not next generation. It was not blocking many of the threats from Layer 7, the application layer. Now, this solution has IP, an intrusion prevention system, and because of the URL filtering, it can block other malware. It seems with the cloud database and the signatures, it compares the receiving files, then it blocks the URLs, making us more secure.

What is most valuable?

All the features are good. The GUI is among the most valuable.

What needs improvement?

It is on multiple boxes so ISP load balancing, multiple network load balancing would be helpful.

Also a web-based portal for VPN. Earlier they had it in the ASA model, but currently, they don't have it. The user needs to just click on the link so he can work.

What do I think about the stability of the solution?

It is quite stable, it is able to detect. But the malware part should probably be upgraded. Performance-wise it is good and it has a long life.

What do I think about the scalability of the solution?

It has limits. If your network is going beyond it, then you'll have to replace it with higher model.

How are customer service and technical support?

Technical support is good.

Which solution did I use previously and why did I switch?

We have been using Cisco for a long time, various models. We had PIX, then ASA. We were quite comfortable with the performance, it never failed. But our old solution was coming to end-of-life. Also, this is able to more block more threats from the application layer, etc.

The most important criteria when selecting a vendor are 

  • reputation
  • technology
  • features
  • cost.

How was the initial setup?

The initial setup was a bit complex.

What other advice do I have?

My advice would depend on what your comfort level is. If you have already used Cisco, I would recommend this, to evaluate it at least. Evaluate it and learn how useful it is.

It gives good performance, the technology is quite good, sufficient for our objectives, protecting our network, etc. The missing two points are because they have to do make more improvements.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Works at IDF technology
User
Jul 17, 2018
Valuable features include AnyConnect, double translations, and an independent IPS module
Pros and Cons
  • "Valuable features include AnyConnect, double translations, and an independent IPS module."
  • "Valuable features include AnyConnect, double translations, and an independent IPS module."
  • "The licensing needs simplification."
  • "The IPS module is combined with the main operating system."
  • "The licensing needs simplification."

What is our primary use case?

This solution is involved in the protection of the network perimeter and the VPN gateway.

How has it helped my organization?

It allows you to fine-tune and create flexible circuits, as well as unites a large number of different types of connections.

What is most valuable?

  • AnyConnect
  • Double translations
  • Independent IPS module
  • High performance
  • Various methods of organizing a VPN

What needs improvement?

  • Simplify licensing
  • Do not combine the IPS module with the main operating system.
  • In new products, leave the CLI.

For how long have I used the solution?

More than five years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
student at MC
User
Jul 16, 2018
Manual deep bracket inspection is required to use web filtering. ASA 5505 and ASA 5506 are very powerful tools to use in a business environment, and provide a lot of security
Pros and Cons
  • "ASA 5505 and ASA 5506 are very powerful tools to use in a business environment, and provide a lot of security."
  • "ASA 5505 and ASA 5506 are very powerful tools to use in a business environment, and provide a lot of security."
  • "Intrusion prevention, we currently need to apply deep bracket inspection manually to use web filtering."
  • "Intrusion prevention, we currently need to apply deep bracket inspection manually to use web filtering."

What is our primary use case?

We offer publishing services. It depends on our business, but we use this solution for security.

What is most valuable?

ASA 5505 and ASA 5506 are very powerful tools to use in a business environment, and provide a lot of security.

What needs improvement?

Intrusion prevention, we currently need to apply deep bracket inspection manually to use web filtering.

For how long have I used the solution?

Three to five years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2026
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros sharing their opinions.