Try our new research platform with insights from 80,000+ expert users
PeerSpot user
IT Security Engineer at a financial services firm with 501-1,000 employees
Real User
The packet tracer function provides a packet flow through the firewall and shows which rule or policy can cause a drop.

What is most valuable?

Cisco ASA's CLI is very effective and fast to configure the firewall and make changes, but monitoring logs and connections can be eye bothering by reading all the line outputs. ASDM, however, have improved the overall ASA configuration from an GUI standpoint. I really enjoy the log monitor where I can see live logs in a more user friendly interface. The down side of ASDM is that it is build with JAVA and that means a lot vulnerabilities and it does not always work with the latest JAVA version and/or patches.

How has it helped my organization?

The packet tracer function, which I use the most, have provided me a packet flow through the firewall and see which rule or policy can cause a drop. Also, I can see if my NAT statement is working properly. This has allowed me to quickly troubleshoot potential firewall related issues for my organization.

What needs improvement?

L7 firewall is a key for the ASA to be competitive in the current and future market place. By integrating with SourceFire, now call FirePower, on the ASA has helped it to get into the next-generation firewall segment.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Network Security Consultant at a tech services company with 51-200 employees
Real User
Top 20
Reliable product which I'd like to see include a web filtering functionality.

Valuable Features

It blocks all outside to inside traffic and only permits the specific internet traffic from the outside. VPN functionality is very useful, we can create remote access and tunnel VPN in the simplest way.

Improvements to My Organization

It blocked all kinds of internet attacks from outside like DOS or DDOS and avoided any down time. We created a remote tunnel from head office to data center network for easy access of servers that make working fast and they are easily manageable.

Room for Improvement

It would be great if they would add web filtering functionality to this product.

Use of Solution

5 years

Deployment Issues

No

Stability Issues

No

Scalability Issues

No

Customer Service and Technical Support

Customer Service:

Excellent

Technical Support:

Good

Initial Setup

It is a little difficult in newer IOS versions where the use of the NAT command is different. Otherwise its straightforward to configure.

Implementation Team

I deployed it in-house with my team.

ROI

This solution reduces any downtime therefore business continuity is not disturbed - that is ultimately ROI.

Pricing, Setup Cost and Licensing

It is one time cost of about $10,000 and there is no day to day cost.

Other Solutions Considered

Yes, I evaluated Fortigate, SonicWall and Juniper but found Cisco ASA to be the best solution for us above all of the others.

Other Advice

Cisco ASA is a reliable product and it benefits you a lot in your network.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Cisco Secure Firewall
September 2025
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,787 professionals have used our research since 2012.
it_user293883 - PeerSpot reviewer
System/Network administrator at a computer software company with 501-1,000 employees
Vendor
We have issues with some versions of Java, but it does amalgamate the firewall and VPN.

What is most valuable?

It's a great solution that amalgamates a firewall and VPN into one device. It also has a well organized GUI- ASDM.

How has it helped my organization?

  • Easy to setup VPNs
  • Firewall ACL
  • Easy to modify
  • Easy to perform maintenance

What needs improvement?

The ADSM is incompatible with different versions of Java.

For how long have I used the solution?

I've used it for six years.

What do I think about the stability of the solution?

I have issues with some versions of Java and ASDM.

How are customer service and technical support?

Customer Service:

It's high.

Technical Support:

It's high.

Which solution did I use previously and why did I switch?

I used a Cisco 881 router as a firewall and VPN solution. ASA allows conformity and various amounts of functionality in work.

How was the initial setup?

It can be complex, since a lot of CLI commands are different with respect to the CLI of IOS routers.

What about the implementation team?

We implemented ASA without vendor support. For first time implementation, it is good to have someone with ASA experience involved.

What's my experience with pricing, setup cost, and licensing?

Prices could be a little bit lower to make the product more accessible.

Disclosure: My company has a business relationship with this vendor other than being a customer. We're a Cisco Partner.
PeerSpot user
PeerSpot user
Senior Presales Engineer at a tech services company with 501-1,000 employees
Real User
The various NGFW and NGIPS features are valuable, but the option to use ASA to decrypt SSL would be an improvement.

What is most valuable?

NGFW: VPN (IPSec, SSL), NAT (provides great flexibility)

NGIPS: Application visibility, file policies (store files), network discovery, correlation features

What needs improvement?

SSL decryption for modules. Although I think it is better to separate SSL decryption as a service from the software module since it requires additional hardware, but I think it would be great if there is an option to use the ASA (not the software module) to decrypt the SSL.

Ex: Add a license to decrypt SSL traffic on the ASA itself. The ASA already supports SSL VPN. So if SSL decryption can be integrated that would be nice.

For how long have I used the solution?

5 years+

What was my experience with deployment of the solution?

Basic setup is easy, but if you need to do some advanced stuff, it can be intuitive, but some things require some kind of tutorial to understand how it can be done. Good thing is that this device is becoming popular and there are many 3rd party free tutorials and guides that can help.

What do I think about the stability of the solution?

I heard about defect that were encountered by my colleagues, but not something that cannot be fixed using an upgrade.

What do I think about the scalability of the solution?

Clustering is available for ASA with firepower services.

Also for firepower appliances, there is stacking available for some models.

How are customer service and technical support?

Customer Service:

Great support. The engineers know what they are doing.

Technical Support:

10/10

Which solution did I use previously and why did I switch?

No

How was the initial setup?

Well, it is straight forward as long as you understand the components available.

ASA can be configured using the CLI or ASDM.

For the Firepower you will need to use a FireSIGHT as a management solution.

Since you will be using two GUIs, I wouldn't call it straight forward.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
PeerSpot user
Business Development Director with 51-200 employees
Vendor
UTM features need to be improved, but it's a full inspection firewall.

What is most valuable?

The fact that it's a full inspection firewall.

How has it helped my organization?

In fact there is no relevant improvement, but this is the kind of device that every company must have.

What needs improvement?

  • Recognition of appliances
  • UTM features

For how long have I used the solution?

I've used it for five years.

What was my experience with deployment of the solution?

It was mainly issues regarding the management and VPN setup.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

8/10.

Technical Support:

8/10.

Which solution did I use previously and why did I switch?

We previously used IPtables, and switched because there was a lack of technical support, RMA, etc.

How was the initial setup?

It was an easy initial set-up.

What about the implementation team?

We did it in-house.

Which other solutions did I evaluate?

No other options were looked at.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user264462 - PeerSpot reviewer
Technolgy Analyst/Lead at a tech services company with 10,001+ employees
Real User
It currently does not support VPN, but I like the documentation, reliability, and support.

What is most valuable?

  • Site-to-site IPsec VPN
  • Remote IPsec VPN
  • Reverse route injection

How has it helped my organization?

Cisco Context gave us the feature of creating a virtual firewall, which is good. It provides us with maximum network isolation. Also impressive is the ISP redundancy.

What needs improvement?

WCCP, and URLs, in the Cisco ASA Context both need work. When changing from single mode to multiple mode or back, the commands must be done from the command line (CLI) and cannot be done via the ASDM GUI interface. ASA context should be able to support site-to-site VPN, but the current Cisco Context does not support VPN

For how long have I used the solution?

I've used them for six years.

What was my experience with deployment of the solution?

During the deployment of WCCP, we noted some loopholes like it only supports ports 80 & 443. Application which is running on multiple ports doesn't work with WCCP and to make it work we need to allow respective traffic outside the firewall.

What do I think about the stability of the solution?

Sometimes there is an issue with the site-to-site VPN.

What do I think about the scalability of the solution?

In certain cases, like an any access-list, if we add a URL the Cisco ASA access-list does not resolve that URL while this can be done in Juniper, and Fortinet.

How are customer service and technical support?

Customer Service:

9/10.

Technical Support:

9/10,

Which solution did I use previously and why did I switch?

I have migrated some set-ups from Cisco to Juniper, but not from Juniper to Cisco.

How was the initial setup?

We have multiple ASA firewalls for different clients now we migrated to Cisco Context.

What about the implementation team?

It was done in-house.

What was our ROI?

It's 8/10.

What other advice do I have?

If it is for a banking domain, your organisation should use Cisco which can assure better security than any other vendors' products. Also, they have the best documentation, reliability and support.

Disclosure: My company has a business relationship with this vendor other than being a customer. Channel partner
PeerSpot user
it_user246819 - PeerSpot reviewer
Global Security Architect/Perimeter Systems Administration/Active Directory and System Administrator at a retailer with 1,001-5,000 employees
Vendor
The solution has worked very well for us, but the configuration/management interface is complex.

What is most valuable?

  • Firewall mode
  • AnyConnect gateway
  • Client-less SSL VPN

How has it helped my organization?

The versatility of the product has allowed us to solve a number of perimeter requirements without having to seek out different products or companies for solutions. It has allowed for a single management mechanism, and by having a single platform solution, it has allowed for simpler training.

What needs improvement?

The configuration/management interface is complex and can be confusing. Technical documentation is often sparse and can be incomplete when covering specific implementations.

For how long have I used the solution?

I've used Cisco PIX and ASA firewalls since 2003.

What was my experience with deployment of the solution?

Not with the ASAs, with some early version PIX products.

What do I think about the stability of the solution?

Not with the ASAs, with some early version PIX products.

What do I think about the scalability of the solution?

The ASAs offer several different technologies for HA and we have used all of them successfully.

How are customer service and technical support?

Customer Service:

It's excellent.

Technical Support:

Excellent, we have always been able to get the specific expertise needed to solve our challenges with the products.

Which solution did I use previously and why did I switch?

Checkpoint Firewalls - the primary reason we switched was cost and limited support options.

How was the initial setup?

It's pretty straightforward. I came at these products already having considerable firewall experience.

What about the implementation team?

It was all in-house, as we all had 10 years plus experience when we moved to PIX firewalls and then a few years later we brought in the ASAs.

Which other solutions did I evaluate?

  • Watchguard
  • Sonicwall
  • Checkpoint

What other advice do I have?

The product line offers tremendous capability. Please look into all of the solutions it can provide for you to maximize your investment.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Constructor of the computer systems at a security firm with 51-200 employees
Vendor
It can be controlled through different methods but the online regional support needs improving.

What is most valuable?

  • Reliability
  • Security
  • Flexibility
  • Functionality
  • Availability - controllability anywhere and with different methods

How has it helped my organization?

I can tell that when we have started using the Cisco AnyConnect for remote access to business apps it makes the work for remote staff much simpler. It's also easier to provide remote IT support. Aside from this, the security officers can sleep better now.

What needs improvement?

The ASA is an almost perfect device.

For how long have I used the solution?

I've used it for two years.

What was my experience with deployment of the solution?

I have had no problems deploying it.

What do I think about the stability of the solution?

Occasionally, the packet rate falls unexpectedly.

What do I think about the scalability of the solution?

I currently do not need to scale on my network.

How are customer service and technical support?

Customer Service:

9/10 - the regional online support could be better.

Technical Support:

10/10.

Which solution did I use previously and why did I switch?

We use MySQL and Nagios devices alongside the ASA as our network infrastructure needs expanding and required more serious hardware solutions.

How was the initial setup?

When Cisco was installed, it did not go as expected.

What was our ROI?

It is not simple to calculate for IT hardware. To calculate the ROI for using the ASA, I would need to have a lot of statistics on the quality of services, both before and after.

What's my experience with pricing, setup cost, and licensing?

Cisco ASA 5512-X was bought for $3,000, and a further $1,000 was needed for installation and pre-configuration.

Which other solutions did I evaluate?

  • Fortinet
  • Juniper

What other advice do I have?

As a rule, any device upon delivery is obsolete. Pick up the solution for your business, based on your specific needs.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros sharing their opinions.
Updated: September 2025
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros sharing their opinions.