Try our new research platform with insights from 80,000+ expert users
PeerSpot user
Security Consultant at a tech services company with 501-1,000 employees
Reseller
Detection engine and historical file analysis ease threat investigations
Pros and Cons
  • "The Firepower IPS, based on Snort technology, has an amazing detection engine and historical analysis capability of files that eases threat investigations a lot."
  • "I would like to see more integration with third-party devices in general. There is great integration with Cisco devices, but there's not much integration with third-party devices."

What is our primary use case?

Cisco next-generation firewalls are mainly used either for data center protection - north-south traffic - or internet traffic.

How has it helped my organization?

The application and user-visibility and control, along with very powerful IPS and malware protection, enables our clients to secure their data centers and internet perimeter in a much better way. It provides them with traffic visibility and reporting as well.

The main advantage is when you put it between users and servers internally or between different VLANs in the network. You have full visibility over the traffic, over all the internal applications. Usually, there's a lot of traffic that is not very clear and no one knows what is on their network. So, once deploy it internally, you have full visibility over the internal traffic, who's accessing what, which protocol. It can directly detect all kinds of malicious traffic, traffic that abuses bandwidth. 

It makes different kinds of internal behavior that is useful to a network admin. And for security of course: Any kind of file infection, any kind of internal scanning, internal attacks; it gives you full visibility.

Finally, you have communication of VLANs, internally, in the network, of course. So you have a granular access control based on user and application, instead of IP and port as you would have with a traditional firewall.

What is most valuable?

During the first phase of use, it was an extra module on standard Cisco ASA firewalls. It then became a standalone solution known as FTD, Firepower Threat Defense.

The Firepower IPS, based on Snort technology, has an amazing detection engine and historical analysis capability of files that eases threat investigations a lot.

I value the integration with other products (Cisco ISE, Cisco Endpoint AMP) which increases the protection intelligence within the enterprise by sharing security info between different products, which function on different layers. It furnishes fully connected security.

It also provides detection of the client operating system, which gives very good reporting and correlation with the signatures. It can relay the signature IP to the client operating system, to give a better correlation decision.

What needs improvement?

Some ASA known features are still missing, but are being added bit by bit in each new version release, such as:

  • Remote Access VPN (the last release only supported the 2100 series): The next firewall model version is expected to support Remote Access VPN in the next software release in July 2017.
  • Virtualization of the appliance (multiple contexts) is still missing.
  • You always need an external management system, the onboard one is not very good. You have to use FMC, FirePOWER Management Center, as external software. There's always an add-on, whereas all the competition has an onboard management interface.

I would like to see more integration with third-party devices in general. There is great integration with Cisco devices, but there's not much integration with third-party devices.

Buyer's Guide
Cisco Secure Firewall
September 2025
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,787 professionals have used our research since 2012.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

We did not encounter any issues with stability. Cisco Firepower FW is very stable in all of the deployments we have made.

What do I think about the scalability of the solution?

The scalability is very good. They have a clustering mechanism, so you can start with an appliance and then cluster, adding more bandwidth and nodes into your cluster. If you don't have a big budget you can start with a medium appliance and then cluster appliances. Or if you want to buy it all in one shot, there is a big range.

Although it allows scaling by adding multiple firewalls together (clustering), we have never used that, as all new hardware supports high-performance throughput and connections at a reasonable price.

How are customer service and support?

Technical support is perfect. Cisco is always known for its good technical support. We have never had any issues with them.

Which solution did I use previously and why did I switch?

As a Cisco Gold Partner, we always proposed Cisco firewalls for our clients.

How was the initial setup?

The setup was straightforward. A new Cisco FTD can be set up and running in a couple of hours. If you're used to firewalls you can quickly get along with it. There is nothing complicated.

The time deploy is short. But the time to tune and create the policies involves a learning phase. Traffic changes over time, so the tuning for firewall rules has to be as granular as possible takes a bit of time. But to deploy you can go live is fast.

The strategy is to start with high-level security policies and then monitor the traffic and the applications affected. Then on the detection logs, create more granular rules.

What's my experience with pricing, setup cost, and licensing?

It has a great performance-to-price value, compared to competitive solutions. Subscriptions are annual. The licensing fee and standard support are the only costs we pay for.

Which other solutions did I evaluate?

We did not evaluate any alternative solutions.

What other advice do I have?

Make sure you tune your rules very well, as some clients just leave the firewall as it is and don't maintain the access rules or tighten them to be more granular and efficient.

In terms of maintenance, you need one person for security analysis and one to create rules and for daily support.

Disclosure: My company has a business relationship with this vendor other than being a customer. We are a Cisco Gold Partner.
PeerSpot user
it_user654645 - PeerSpot reviewer
Senior Network Specialist
Vendor
It has an important role as a firewall and it improves our access control.

What is most valuable?

The security features are valuable because it is easy to use and it has an important role as a firewall.

How has it helped my organization?

It has improved our access control.

What needs improvement?

It would be useful to gather all security features in one box. For example, certain features like URL filtering and application control licenses need to be purchased separately and it depends on the hardware spec, as not all models are supporting these two features. This causes the user to be highly dependent on the pre-sales person.

For how long have I used the solution?

We have been using the solution for six years.

What do I think about the stability of the solution?

We did not encounter any issues with stability.

What do I think about the scalability of the solution?

We had a scalability issue, as each feature is based on license or hardware support.

How are customer service and technical support?

I would rate the technical support at 8/10.

Which solution did I use previously and why did I switch?

We did not use a previous solution.

How was the initial setup?

The setup was straightforward with two layers of firewall.

What's my experience with pricing, setup cost, and licensing?

It is too pricey if you want to activate more features in a box, which necessitates you to purchase a license.

Which other solutions did I evaluate?

We evaluated Palo Alto and CheckPoint.

What other advice do I have?

Know what features are needed, and then purchase the necessary hardware and license.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Cisco Secure Firewall
September 2025
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,787 professionals have used our research since 2012.
it_user430797 - PeerSpot reviewer
Network Engineer at a mining and metals company with 1,001-5,000 employees
Vendor
The simple access rule, Internet NAT and routing are valuable features.

What is most valuable?

The simple access rule, Internet NAT and routing are valuable features. It is very simple and the most reliable perimeter firewall.

How has it helped my organization?

We were using Cisco Security Manager (CSM) to control and configure all of our Cisco products. ASA worked very well on the CSM.

What needs improvement?

The next-generation firewall could improve. Still, they have NGFW 5525 but I haven’t tried it yet.

For how long have I used the solution?

We have been using this solution for seven years.

What do I think about the stability of the solution?

We have never faced any stability issues.

What do I think about the scalability of the solution?

Sometimes, the throughput and CPU counter issues were faced, maybe because we started to use it a long time ago.

How are customer service and technical support?

Technical support is great. They are very responsible, know the bugs and workaround.

Which solution did I use previously and why did I switch?

We have used it from the beginning.

How was the initial setup?

The initial setup is not simple and straightforward, because it is Cisco and you need to configure it by CLI.

What's my experience with pricing, setup cost, and licensing?

Obviously, Cisco products are not cheap.

What other advice do I have?

If you are looking for a stable run and it is easy to find someone to configure the service, then better go for Cisco; their support is very professional.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user3396 - PeerSpot reviewer
it_user3396Team Lead at Tata Consultancy Services
Top 5Real User

Cool Review

it_user674844 - PeerSpot reviewer
Executive Manager with 11-50 employees
Real User
The solution's reliability, performance, and security are most valuable.

What is most valuable?

The solution's reliability, performance, and security are most valuable.

What needs improvement?

The price and compatibility with other vendors' products can be improved.

For how long have I used the solution?

I have used this solution for three years.

What do I think about the stability of the solution?

I have not encountered any issue with stability.

What do I think about the scalability of the solution?

I have not encountered any issues with scalability.

How are customer service and technical support?

I would give technical support a rating of 9/10.

Which solution did I use previously and why did I switch?

I used Juniper Networks and I switched due to the lack of technical and sales support in Romania.

How was the initial setup?

The initial setup was complex because of its outdoor position. We had to solve this problem with outdoor protection.

What's my experience with pricing, setup cost, and licensing?

Negotiate the quote.

Which other solutions did I evaluate?

Before choosing, I evaluated Juniper Networks SRX.

What other advice do I have?

Be careful with temperature control in the rack area, since Cisco ASA 5585-X with SSP-10 heats up a lot.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
IT Operation Manager at a retailer with 11-50 employees
Real User
Provides software updates for known bugs and vulnerabilities.

What is most valuable?

  • Hardware reliability
  • Software stability
  • Quick software updates for known bugs/vulnerabilities

These are very important in an enterprise environment.

How has it helped my organization?

It is small. Nobody knows where it is or what it is. It works silently. As there ar no issues, it is good for businesses and organizations.

What needs improvement?

  • License politics
  • License price
  • Precise vendor roadmap for this product

For how long have I used the solution?

I have used Cisco ASA for five years.

What do I think about the stability of the solution?

We have not had stability issues.

How are customer service and technical support?

I would give them a high rating.

Which solution did I use previously and why did I switch?

We were using TippingPoint as an IPS and ZyXEL ZyWALL as a VPN server.
Cisco has good documentation and it is easy for Cisco certified engineers.

How was the initial setup?

The initial setup was straightforward.

What's my experience with pricing, setup cost, and licensing?

Our experience last year showed us that there is no full security, so why should we pay more? Any security vendor with a user-friendly interface, with good support, on-time updates for known vulnerabilities, and reliable hardware, is acceptable for an organization.

Which other solutions did I evaluate?

We did not evaluate any alternatives.

What other advice do I have?

The Cisco ASA product line will be replaced by Cisco FTD. Cisco FTD software is not ready for production, due to a lack of many basic NGFW features. Maybe only the high-performance Firepower 41xx/21xx/90xx Series is good as an IPS, because it is using a stable Sourcefire engine.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user477366 - PeerSpot reviewer
Security Technical Architect at a tech services company with 10,001+ employees
Consultant
It provides detection of zero day infections. The feature sets are great when there are no software bugs.

What is most valuable?

The feature sets are great when there are no software bugs. With FirePOWER, you can enhance security, have effective management, and a good reporting engine.

How has it helped my organization?

It provides detection of zero day infections through FirePOWER AMP.

What needs improvement?

Well tested software releases. We have had a number of bugs on the FirePOWER software across several clients which have been very inconsistent and have affected our ability to deliver.

For how long have I used the solution?

I have used the ASA portion for over eight years and the FirePOWER portion for about three years.

What do I think about the stability of the solution?

We did have stability issues with the FirePOWER software.

What do I think about the scalability of the solution?

We did not have scalability issues with the high end devices.

How are customer service and technical support?

I give technical support a rating of 5/10.

Which solution did I use previously and why did I switch?

We are part of the integrator space. When we changed products, it was to displace a product that no longer met the client’s requirements.

How was the initial setup?

The setup was reasonably straightforward.

What's my experience with pricing, setup cost, and licensing?

Get a clear understanding of what the licensing entails before committing.

Which other solutions did I evaluate?

We checked out Check Point and FortiGate.

What other advice do I have?

Plan very well in order to have a seamless project implementation and transition.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
IT Operation Manager at a retailer with 11-50 employees
Real User
​NGFW features software stability, quick software updates for known bugs/vulnerabilities.

What is most valuable?

NGFW features software stability, quick software updates for known bugs/vulnerabilities. Why no hardware reliability (see Clock Signal Component Issue -Cisco)? Because without NGFW features it is basically like a home router.

How has it helped my organization?

It is small, nobody knows where it is, nobody knows what it is, it works silently. So, as there is no issue, it is good for business and organization.

What needs improvement?

License politics, license price, precise vendor roadmap for this product.

For how long have I used the solution?

Two years.

What do I think about the stability of the solution?

Yes, FirePower is not stable, because every new software version comes with many features that cause problems. Cisco has to do it because other vendors have already added these features.

What do I think about the scalability of the solution?

No.

How are customer service and technical support?

High.

Which solution did I use previously and why did I switch?

3Com TippingPoint as IPS, Zyxel ZyWALL ZyXEL ZyWALLas VPN server. Cisco has good documentation and it is easy for Cisco certificated engineers.

How was the initial setup?

Complex, because of non-ready Firepower service software setup.

What's my experience with pricing, setup cost, and licensing?

The last years' experience showed that there is no full security, so why pay more. Any security vendor with a user-friendly interface, with good support, on-time updates for known vulnerabilities and reliable hardware, is acceptable for an organization.

Which other solutions did I evaluate?

No.

What other advice do I have?

Cisco's ASA product line will be replaced by Cisco FTD. And Cisco FTD software is not ready for production (lack of many basic NGFW features). So, maybe only high-performance Firepower 41xx/21xx/90xx Series is good as IPS.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Security Consultant at Accenture
Real User
Cisco doesn't have many features but only basic firewalls. Technical support and documentation is great.

What is most valuable?

Cisco doesn't have many features but only basic firewalls.

How has it helped my organization?

No improvement. My clients have been using this product and moving to other products.

What needs improvement?

This product should have moved towards making UTMs.

For how long have I used the solution?

Eight years.

What do I think about the stability of the solution?

No.

What do I think about the scalability of the solution?

No.

How are customer service and technical support?

Technical support and documentation is great.

Which solution did I use previously and why did I switch?

No, I worked with this product by working for a client.

How was the initial setup?

It is easy to set up and implement.

What's my experience with pricing, setup cost, and licensing?

Never worked on pricing and licensing.

Which other solutions did I evaluate?

I would always prefer to evaluate other products when I have been asked for advice on firewall solutions.

What other advice do I have?

Evaluate other product before using this product.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros sharing their opinions.
Updated: September 2025
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros sharing their opinions.