Robustness
Middle-Tier Admin Integrator at a tech services company with 51-200 employees
Cisco firewalls can be difficult at first but once learned it's fine.
Pros and Cons
- "Customer Service: Excellent Technical Support: Excellent"
- "Price maybe..."
What is most valuable?
How has it helped my organization?
Reliability
What needs improvement?
No idea -- I learn a lot from them
For how long have I used the solution?
From 2000 until 2014
Buyer's Guide
Cisco Secure Firewall
March 2026
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
884,976 professionals have used our research since 2012.
What was my experience with deployment of the solution?
Learning at the beginning
What do I think about the stability of the solution?
Nope -- If well planed you should be alright
What do I think about the scalability of the solution?
Price maybe...
How are customer service and support?
Customer Service:
Excellent
Technical Support:Excellent
Which solution did I use previously and why did I switch?
Not reliable for long term -- seem inferior quality
How was the initial setup?
Depends on the product and the knowledge. Cisco firewalls can be difficult at first but once learned it's fine.
What about the implementation team?
Me, I implemented the firewalls, Cisco switches and routers.
What was our ROI?
100% in some installations it exceeded the time predicted to keep up with the work load.
Which other solutions did I evaluate?
Netscreen, Netgear, Checkpoint, others..
What other advice do I have?
Plan well the hardware requirements for future growth and heavy usage.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
I.T. Security/Projects Specialist at a tech services company with 501-1,000 employees
We wanted a back-end/internal firewall solution, and this provided it for us.
Pros and Cons
- "Firewalling is the most valuable feature."
- "URL AVC Advanced malware protection"
What is most valuable?
Firewalling is the most valuable feature. We wanted a back-end/internal firewall solution, and the Cisco ASA 5525 was great.
How has it helped my organization?
It has taken the pressure off of the IS engineer.
What needs improvement?
- URL
- AVC
- Advanced malware protection
For how long have I used the solution?
We've used it for two years.
What was my experience with deployment of the solution?
There was an issue, but it was rectified promptly after troubleshooting the device's configuration.
What do I think about the stability of the solution?
There were no issues with the scalability.
What do I think about the scalability of the solution?
We've not had any issues scaling yet.
How are customer service and technical support?
Customer Service:
I think it is great but did not use them for this deployment.
Technical Support:I've not had to use them yet for this deployment.
Which solution did I use previously and why did I switch?
There was no other solution in place.
How was the initial setup?
It was straightforward.
What about the implementation team?
I did the implementation with my colleagues.
What was our ROI?
It's not really quantified, but we have not experienced downtime due to attacks.
Which other solutions did I evaluate?
There were no other solutions looked at.
Disclosure: My company has a business relationship with this vendor other than being a customer. We're a systems integrator and a gold partner.
Buyer's Guide
Cisco Secure Firewall
March 2026
Learn what your peers think about Cisco Secure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
884,976 professionals have used our research since 2012.
Senior Technical Consultant - Network and Security at a tech services company with 51-200 employees
It provides our company with security and protection on all our devices, but we had some issues during deployment.
Pros and Cons
- "It provides our company with security and protection on all our devices."
- "We had some issues during deployment."
Valuable Features
- It provides our company with security and protection on all our devices.
- It's highly available.
Improvements to My Organization
We're able to implement best security practices to secure our company data.
Use of Solution
We've used it for over seven years.
Deployment Issues
We had some issues during deployment.
Stability Issues
No issues encountered.
Scalability Issues
No issues encountered.
Customer Service and Technical Support
Customer Service:
Customer service is excellent.
Technical Support:Technical support is excellent.
Initial Setup
It was a little complex, but not so much that we couldn't figure it out.
Implementation Team
I was the implementor for a client.
ROI
It's excellent.
Other Solutions Considered
Depends on the customer's budget, but we evaluate all vendors that meet the them. It's a mission-critical product.
Other Advice
I give it a thumbs up.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
System and Network Administrator at a hospitality company with 501-1,000 employees
It gives us the ability to do Lan-to-Lan VPN, but it needs support for automation tools, such as Puppet.
Pros and Cons
- "So far it has proven to be rock solid and relatively easy to maintain."
- "Licenses and prices are pretty high."
What is most valuable?
It gives us the ability to do lan-to-lan VPN.
How has it helped my organization?
So far it has proven to be rock solid and relatively easy to maintain.
What needs improvement?
- Support for automation tools (Puppet)
- More granular logging
For how long have I used the solution?
I've used ASA for four years.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
No issues encountered.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
8/10
Technical Support:8/10
Which solution did I use previously and why did I switch?
We moved our VPN termination from a Cisco ASR to an ASA. We switched because the ASR was not scalable and we realized it was a bad idea to use the same device for routing and VPN termination.
How was the initial setup?
The most complex part was figuring out the failover and what NAT mode to implement.
What about the implementation team?
We did it in-house.
What's my experience with pricing, setup cost, and licensing?
Licenses and prices are pretty high. I understand the validity of the product, so I can't complain much.
Which other solutions did I evaluate?
No options were evaluated. We heavily rely on Cisco hardware for our infrastructure
What other advice do I have?
I'd say it would be very beneficial to posses certification such as CCNP Security, at least, to get the most out of it. It's a complex product which requires good knowledge of procedures and best practices. Being a CCIE R&S I know the value of those certifications, and I wish I had a CCNP Security to better handle the task.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Security Engineer at a financial services firm with 501-1,000 employees
The packet tracer function provides a packet flow through the firewall and shows which rule or policy can cause a drop.
Pros and Cons
- "The packet tracer function, which I use the most, has provided me a packet flow through the firewall and shows which rule or policy can cause a drop, and it has allowed me to quickly troubleshoot potential firewall-related issues for my organization."
- "The down side of ASDM is that it is build with JAVA and that means a lot vulnerabilities and it does not always work with the latest JAVA version and/or patches."
Valuable Features:
Cisco ASA's CLI is very effective and fast to configure the firewall and make changes, but monitoring logs and connections can be eye bothering by reading all the line outputs. ASDM, however, have improved the overall ASA configuration from an GUI standpoint. I really enjoy the log monitor where I can see live logs in a more user friendly interface. The down side of ASDM is that it is build with JAVA and that means a lot vulnerabilities and it does not always work with the latest JAVA version and/or patches.
Improvements to My Organization:
The packet tracer function, which I use the most, have provided me a packet flow through the firewall and see which rule or policy can cause a drop. Also, I can see if my NAT statement is working properly. This has allowed me to quickly troubleshoot potential firewall related issues for my organization.
Room for Improvement:
L7 firewall is a key for the ASA to be competitive in the current and future market place. By integrating with SourceFire, now call FirePower, on the ASA has helped it to get into the next-generation firewall segment.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Security Consultant at a tech services company with 51-200 employees
Reliable product which I'd like to see include a web filtering functionality.
Pros and Cons
- "Cisco ASA is a reliable product and it benefits you a lot in your network."
- "It would be great if they would add web filtering functionality to this product."
Valuable Features
It blocks all outside to inside traffic and only permits the specific internet traffic from the outside. VPN functionality is very useful, we can create remote access and tunnel VPN in the simplest way.
Improvements to My Organization
It blocked all kinds of internet attacks from outside like DOS or DDOS and avoided any down time. We created a remote tunnel from head office to data center network for easy access of servers that make working fast and they are easily manageable.
Room for Improvement
It would be great if they would add web filtering functionality to this product.
Use of Solution
5 years
Deployment Issues
No
Stability Issues
No
Scalability Issues
No
Customer Service and Technical Support
Customer Service:
Excellent
Technical Support:Good
Initial Setup
It is a little difficult in newer IOS versions where the use of the NAT command is different. Otherwise its straightforward to configure.
Implementation Team
I deployed it in-house with my team.
ROI
This solution reduces any downtime therefore business continuity is not disturbed - that is ultimately ROI.
Pricing, Setup Cost and Licensing
It is one time cost of about $10,000 and there is no day to day cost.
Other Solutions Considered
Yes, I evaluated Fortigate, SonicWall and Juniper but found Cisco ASA to be the best solution for us above all of the others.
Other Advice
Cisco ASA is a reliable product and it benefits you a lot in your network.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
System/Network administrator at a computer software company with 501-1,000 employees
We have issues with some versions of Java, but it does amalgamate the firewall and VPN.
Pros and Cons
- "It's a great solution that amalgamates a firewall and VPN into one device and also has a well organized GUI-ASDM."
- "The ADSM is incompatible with different versions of Java."
What is most valuable?
It's a great solution that amalgamates a firewall and VPN into one device. It also has a well organized GUI- ASDM.
How has it helped my organization?
- Easy to setup VPNs
- Firewall ACL
- Easy to modify
- Easy to perform maintenance
What needs improvement?
The ADSM is incompatible with different versions of Java.
For how long have I used the solution?
I've used it for six years.
What do I think about the stability of the solution?
I have issues with some versions of Java and ASDM.
How are customer service and technical support?
Customer Service:
It's high.
Technical Support:It's high.
Which solution did I use previously and why did I switch?
I used a Cisco 881 router as a firewall and VPN solution. ASA allows conformity and various amounts of functionality in work.
How was the initial setup?
It can be complex, since a lot of CLI commands are different with respect to the CLI of IOS routers.
What about the implementation team?
We implemented ASA without vendor support. For first time implementation, it is good to have someone with ASA experience involved.
What's my experience with pricing, setup cost, and licensing?
Prices could be a little bit lower to make the product more accessible.
Disclosure: My company has a business relationship with this vendor other than being a customer. We're a Cisco Partner.
Senior Presales Engineer at a tech services company with 501-1,000 employees
The various NGFW and NGIPS features are valuable, but the option to use ASA to decrypt SSL would be an improvement.
Pros and Cons
- "Customer Service: Great support."
- "Basic setup is easy, but if you need to do some advanced stuff, it can be intuitive, but some things require some kind of tutorial to understand how it can be done."
What is most valuable?
NGFW: VPN (IPSec, SSL), NAT (provides great flexibility)
NGIPS: Application visibility, file policies (store files), network discovery, correlation features
What needs improvement?
SSL decryption for modules. Although I think it is better to separate SSL decryption as a service from the software module since it requires additional hardware, but I think it would be great if there is an option to use the ASA (not the software module) to decrypt the SSL.
Ex: Add a license to decrypt SSL traffic on the ASA itself. The ASA already supports SSL VPN. So if SSL decryption can be integrated that would be nice.
For how long have I used the solution?
5 years+
What was my experience with deployment of the solution?
Basic setup is easy, but if you need to do some advanced stuff, it can be intuitive, but some things require some kind of tutorial to understand how it can be done. Good thing is that this device is becoming popular and there are many 3rd party free tutorials and guides that can help.
What do I think about the stability of the solution?
I heard about defect that were encountered by my colleagues, but not something that cannot be fixed using an upgrade.
What do I think about the scalability of the solution?
Clustering is available for ASA with firepower services.
Also for firepower appliances, there is stacking available for some models.
How are customer service and technical support?
Customer Service:
Great support. The engineers know what they are doing.
Technical Support:10/10
Which solution did I use previously and why did I switch?
No
How was the initial setup?
Well, it is straight forward as long as you understand the components available.
ASA can be configured using the CLI or ASDM.
For the Firepower you will need to use a FireSIGHT as a management solution.
Since you will be using two GUIs, I wouldn't call it straight forward.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2026
Popular Comparisons
Fortinet FortiGate
Netgate pfSense
Sophos Firewall
Cisco Umbrella
Cisco Identity Services Engine (ISE)
Palo Alto Networks NG Firewalls
WatchGuard Firebox
Check Point Quantum Force (NGFW)
Cisco Meraki MX
Azure Firewall
Check Point Harmony SASE (formerly Perimeter 81)
Cisco Secure Email
SonicWall TZ
Cisco Secure Network Analytics
Buyer's Guide
Download our free Cisco Secure Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Is The Biggest Difference Between Cisco ASA And Fortinet FortiGate?
- Cisco Firepower vs. FortiGate
- How do I convince a client that the most expensive firewall is not necessarily the best?
- What are the biggest differences between Cisco Firepower NGFW and Fortinet FortiGate?
- What Is The Biggest Difference Between Cisco Firepower and Palo Alto?
- Would you recommend replacing Cisco ASA Firewall with Fortinet FortiGate FG 100F due to cost reasons?
- What are the main differences between Palo Alto and Cisco firewalls ?
- A recent reviewer wrote "Cisco firewalls can be difficult at first but once learned it's fine." Is that your experience?
- Which Cisco firewall model is the latest: ASA or NGFW?
- Which is better - Fortinet FortiGate or Cisco ASA Firewall?












Can you tell me, please, how does an ASA learn about the MAC address of the host? Thank you.