Try our new research platform with insights from 80,000+ expert users
Chief Technology Officer at a tech services company
Real User
A modular and easily managed solution, but throughput capacity is expensive and requires upgrading of hardware
Pros and Cons
  • "The most valuable feature of this solution is its modularity, so whenever you need to upgrade or add another service, you don't need to buy another box."
  • "If there was a software-based solution for scaling up then it would be much better."

What is our primary use case?

We are a system integrator, and we resell this solution to our customers.

This solution is for intrusion prevention, and the majority of deployments are on-premises.

What is most valuable?

The most valuable feature of this solution is its modularity, so whenever you need to upgrade or add another service, you don't need to buy another box. You can activate these services on the same box, which saves a lot in terms of cost because you don't need additional hardware. Moreover, it makes manageability easier because you don't have to use several different devices.

Cisco operates on an open operating system platform so it gives you the flexibility to add other things. Cisco itself is using different manufacturers, or OEM vendors to integrate with their product. For example, Radware is providing a DDoS solution for the NGIPS box.

What needs improvement?

We would like to see support for DDoS protection.

The cost of adding additional throughput is very high and is an area of concern. Competing products such as FortiGate and TippingPoint have a much larger throughput at a smaller cost.

The devices have certain limitations and to go beyond them, I need to change the hardware. For example, if I exceed the throughput on the 2000 series then I have to switch to the 4000 series. This one then has a limitation of perhaps fifty gigabytes, and if I exceed that, then I need to move to the 9000 series. By comparison, TippingPoint and FortiGate have no limit. If there was a software-based solution for scaling up then it would be much better.

For how long have I used the solution?

I have been using this solution for between two and three years.
Buyer's Guide
Cisco Secure IPS (NGIPS)
May 2025
Learn what your peers think about Cisco Secure IPS (NGIPS). Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,604 professionals have used our research since 2012.

What do I think about the stability of the solution?

This is a very stable solution. We have not heard any complaints from customers, and we have not experienced any trouble ourselves.

What do I think about the scalability of the solution?

When it comes to scalability, there is a limitation that is set by the hardware. If you're looking for higher throughput then you have to change boxes. The 2000 series is pretty small when it comes to bandwidth, so scalability is a concern.

How are customer service and support?

Technical support from Cisco is perfectly fine, and they are doing a great job.

Which solution did I use previously and why did I switch?

Prior to this solution, we used TippingPoint. Although it is a very good solution, there was a problem with the product having too many acquisitions. Every time there was a new acquisition, support was a concern. For example, at one point it was taken over by HP, and then, again, HP disowned it. Support was hampered by this, and if you're not getting support on a critical security appliance then you need to look for other options. This is what led us to adopt Cisco.

How was the initial setup?

The initial setup of this solution is not complex. They have a graphical user interface for managing all of these things, which helps make it easy to deploy.

What's my experience with pricing, setup cost, and licensing?

The price for additional throughput is the highest in the industry.

What other advice do I have?

This is a solution that I recommend for IPS.

I would rate this solution a seven out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1083318 - PeerSpot reviewer
Network Infrastructure Program Manager at a non-profit with 1,001-5,000 employees
Real User
Offers valuable SSL decryption, URL filtering, and ITSM inspection features
Pros and Cons
  • "Cisco is number one in the technical support. It's good technical support and this is actually a problem when we do the recruitment for some other products. Other products you are on hold forever and the support might be not the best compared to Cisco."
  • "The file trajectory, the trace in contamination files, could be improved."

What is most valuable?

In the previous version, some features were not enabled. For example, you could not access the VPN. So that was one of the downsides of the product. In this latest version, after enabling these features in the previous version and using them, it's been good. Inspection, application, and inspection in the cloud, the detail in the cloud for an indication of compromise and the malicious activity re-hashing are all valuable features. It's more of the cloud and the malicious activities aspects that define this application.

What needs improvement?

The file trajectory could be improved.

We still have a web proxy but I think at some point we should not have two products. We should have only one product. Most of the features of the web proxy already exist in the UTM appliances. We have a debate as to whether it's the Cisco Firepower and UTM Appliance of next-generation firewall. But I consider both of them the same. So I would say if we have the caching and the other features which are unique features to the Web Proxy, I think Cisco will be number one if they are able to include such features in the future.

For how long have I used the solution?

I have been using the solution for three years.

What do I think about the stability of the solution?

It's a really good product but I have had a really good experience with Palo Alto UTM Appliances. Which I would give a higher mark than the Firepower. It's just a little bit more expensive than the Cisco Firepower.

What do I think about the scalability of the solution?

Scalability I would say, it has some limitations in the large deployment. I think Cisco is working to improve it.

How are customer service and technical support?

The technical support is the most valuable part of the solution. Cisco is number one in technical support. It's good technical support and this is actually a problem when we do the recruitment for some other products. Other products you are on hold forever and the support is not as good compared to Cisco. 

Which solution did I use previously and why did I switch?

I started with Juniper and the Palo Alto UTM Appliances, and many other vendors. But we do have a policy to use multiple vendors.

How was the initial setup?

Three years ago the setup was very complex. We had two different cables or software. It's like two appliances and one appliance. We had to set up ASA first and then set up Firepower and do the redirect from the old HTTP traffic, from the ASA for a detailed inspection by Firepower. Initially, it was complex. That was a few years back, but now with the newer version, it's just a piece of cake. Deployment took about 40 minutes. I also handle the maintenance myself.

What about the implementation team?

I do the implementation myself but in certain situations, because we have a risk assessment, it's a sort of risk transfer, so we have a contract with a certain integrator. We do have a contract, but I personally do the setup.

What was our ROI?

We have definitely experienced ROI. Because we have had many incidents where Cisco Firepower has caught malicious activities and triggered an alarm, a true positive alarm. Which is really good in our case.

What other advice do I have?

The solution is extensively used. We have a policy, from a permission security perspective, that you need to have diversity in the vendors and diversity in the products. We have some areas which are using these products and other areas which is using different products.

It's a really good product, but you need to give it some time to form a sort of baseline, before enabling all the features. You need to study the product well because the product will decrease to around 35-40% of the actual product when you start to enable features. Like the application and inspection, the SSL decryption, the URL filtering, and the ITSM inspection. If you enable more features, you will decrease a little bit of the property. Whoever selects the device initially needs to plan which features they are going to use and they might have to shift the sizing of the product. They might need a high-end appliance or a smaller low-end appliance based on the features they are going to use.

I would give the solution 9 out of 10. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Cisco Secure IPS (NGIPS)
May 2025
Learn what your peers think about Cisco Secure IPS (NGIPS). Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,604 professionals have used our research since 2012.
Carlos Reis - PeerSpot reviewer
Network Security Engineer at New Era Technology
Real User
Top 10
Has great security intelligence features
Pros and Cons
  • "I like the security solutions from Cisco."
  • "There are certain limitations that need to be addressed."

What is our primary use case?

People still aggregate these functions. We have files that only serve the purpose of NextGen NGIPS.  They have no rules that just allow pure source running and execution. We need regular firewall protection with NetGen. It's nice because we can lease both firewall and IPS system functions. We have both running on the network.

What is most valuable?

Apex IPaaS functions itself. You can create an intrusion rule that can be used for blocking purposes.

I like the security solutions from Cisco. They don't only give you the IPS itself, but you also have another database and other applications. 

They also have the security intelligence feature. This is one of the first software lines. This brings you the URLs, IPs, etc. This is even before the access control.

What needs improvement?

There are certain limitations that need to be addressed. 

For how long have I used the solution?

I have been using the Cisco NGIPS for two years. 

How are customer service and support?

Cisco support is very good. 

How would you rate customer service and support?

Positive

What other advice do I have?

For the time being, I never received a complaint about a policy, but this may happen in the future. This can be due to consistent integration. 

They filter even between different companies and stuff and cloud providers and I've never received any complaints about the speed.

Overall, I rate the solution an eight out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior Network Security Consultant at a tech vendor with 10,001+ employees
Real User
Top 10
Makes data more secure with separate IPSec tunnels
Pros and Cons
  • "NGIPS' best feature is the separate IPSec tunnels, which makes the user's data more secure if they want to access it privately."
  • "NGIPS' GUI interface could be improved and made more user-friendly."

What is our primary use case?

I primarily use NGIPS as perimeter security firewall devices to filter traffic.

What is most valuable?

NGIPS' best feature is the separate IPSec tunnels, which makes the user's data more secure if they want to access it privately.

What needs improvement?

NGIPS' GUI interface could be improved and made more user-friendly, especially in comparison to Palo Alto's Next-Generation Firewall.

For how long have I used the solution?

I've been using NGIPS for around five years.

How was the initial setup?

The initial setup is complex and requires someone with a background in firewalls to set it up. Inexperienced users will find it very difficult to set up. For experienced users, deployment will take around forty-five minutes. I would rate the setup process five out of ten.

What's my experience with pricing, setup cost, and licensing?

NGIPS is expensive.

What other advice do I have?

I would recommend NGIPS to other users, but only as a second choice behind Palo Alto. I would give NGIPS a rating of eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
reviewer1776513 - PeerSpot reviewer
Solutions Architect at a outsourcing company with 1,001-5,000 employees
Real User
Beneficial documentation, overall good design, and responsive support
Pros and Cons
  • "Among all the different solutions I have worked with, such as Palo Alto many other firewalls. Cisco has the support, documentation, and design. The documentation is widely available and it can help you a lot with implementation. It makes the implementation much easier."
  • "What I don't like about Cisco recently is they keep changing the names, which makes it hard for customers and sometimes even us as engineers to know what is the solution they are speaking about. For example, with AMP, now they call it Secure Endpoint and I don't know if in the next couple of years they're going to change it to something else. They should keep the names the same."

What is our primary use case?

The Cisco NGIPS and IGS are used as network firewalls for IPS and IGS protection. I have both the Cisco Firepower and Cisco Meraki solutions in different customers' locations. They have the capability of the NGIPS built into it. We have different customers that they are using it. For example, on Edge, data centers, and campus networks.

What is most valuable?

Among all the different solutions I have worked with, such as Palo Alto many other firewalls. Cisco has the support, documentation, and design. The documentation is widely available and it can help you a lot with implementation. It makes the implementation much easier.

What needs improvement?

What I don't like about Cisco recently is they keep changing the names, which makes it hard for customers and sometimes even us as engineers to know what is the solution they are speaking about. For example, with AMP, now they call it Secure Endpoint and I don't know if in the next couple of years they're going to change it to something else. They should keep the names the same.

For how long have I used the solution?

I have been using Cisco NGIPS for approximately 10 years.

What do I think about the stability of the solution?

Cisco NGIPS is stable, however, it is nothing special.

What do I think about the scalability of the solution?

The scalability of Cisco NGIPS I am not too familiar with. The solution can do clustering and other operations. With the Orchestrator, I haven't worked with it yet but I hope that will help to make standard policies all run better. The most important part about scalability is how do you want to apply the same policy all around and across the different locations that you have. This is something that is not easy with any firewall unless you have a Secure Orchestrator. I don't see any issues with the scalability at this time.

How are customer service and support?

The support from Cisco NGIPS is very good.

Which solution did I use previously and why did I switch?

I have used many other solutions, such as Palo Alto.

What's my experience with pricing, setup cost, and licensing?

I would rate the price of Cisco NGIPS a three out of five.

They are very expensive in some places and not reasonable at times for many customers. I have had customers choose another solution because of the high price.

What other advice do I have?

When speaking about the features of Cisco NGIPS, what makes the feature good is dependent on what the customer likes and the skillset that they have. I cannot say what is the best feature because it depends on the use case.

There are times I see customers spend a lot of money on something which they really don't use. Whether this solution is good or not depends on what exactly the customer wants to implement and protect. They should pick the right solution with the skillset that they have.

I rate Cisco NGIPS nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Distribution officer at Wilshirelabs
Real User
Provides very good IPS and VirtualBox features
Pros and Cons
  • "Good IPS and VirtualBox features."
  • "Should include additional security features."

What is our primary use case?

At present, we are using different policies against which we gather logs. Logs that have been deleted on a first in, first out basis. The logs are only available for three to four hours max. I work in the IT department of a pharmaceutical company and we are customers of Cisco. 

What is most valuable?

We are looking for cybersecurity threats, like Pinterest and this solution has a good IPS feature as well as it's VirtualBox which helps us to time and for the QD, our daily routine tasks or issues. The solution provides a clear picture of what a user is doing at a specified time.

What needs improvement?

Because of cybersecurity threats, other security features should be available in Cisco devices. Sangfor IAM is good because this provides the logging IAM feature which you can retain for up to 12 months. But Cisco does not provide this type of logging because no third-party logging server is supported with the Cisco firewall.

For how long have I used the solution?

I've been using this solution for three years. 

What do I think about the stability of the solution?

The stability is fine. We manage to resolve general bugs by updating the software or VirtualBox as well as in the hardware. That is not a big deal for us.

What do I think about the scalability of the solution?

The scalability is fine for us, we currently have 50 users. 

How are customer service and technical support?

Their technical support is good. We have SLA with Cisco, which will be renewed next year.

How was the initial setup?

We have a somewhat complicated environment over here. We have also implemented SSG Juniper, SSG140, so basically their firewall is working as a router.

What's my experience with pricing, setup cost, and licensing?

The price is a little high in comparison to other similar solutions. If we talk about Sophos Firewall with IBM software, it's cheaper in comparison to Cisco and their VirtualBox.

What other advice do I have?

I recommend this latest model of Cisco firewall. In terms of the wide logging, it gives us as much as we need. We have implemented 30 to 35 policies in which loggings are gathered. 

I would rate this solution an eight out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Carlos Bracamonte - PeerSpot reviewer
Senior Network Support Engineer at Amadeus
MSP
Good protection, reliable and responsive support
Pros and Cons
  • "The URL filtering feature and the new locations feature are both valuable additions to the solution."
  • "While the Management GUI and FMC could be improved, the devices themselves function well."

What is our primary use case?

Some of our customers are having DDOS attacks and ransomware attacks.

How has it helped my organization?

Earlier in July 2019, I noted that there was an attack. To mitigate future attacks from the ransomware in Columbia Bank and other similar situations, we at Cisco Talent, which is responsible for security intelligence, provided updated security rules. We offered intrusion policies and codes through signatures to help overcome such situations.

What is most valuable?

It's a good solution.

The solution is not that bad. Next-generation firewalls work from my experience, they work. 

The URL filtering feature and the new locations feature are both valuable additions to the solution.

What needs improvement?

While the Management GUI and FMC could be improved, the devices themselves function well.

For how long have I used the solution?

I have been using Cisco NGIPS for more than five years.

I provided support for version 6.4, but in our company, we do have Firepower version 7.0.

What do I think about the stability of the solution?

Cisco NGIPS is a stable solution.

How are customer service and support?

Cisco has great support.

What other advice do I have?

I would rate Cisco NGIPS an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PauloRio - PeerSpot reviewer
Senior Consultant at a tech services company with 5,001-10,000 employees
Real User
Top 10
Stable environment, excellent technical support, and with good training you can go the distance
Pros and Cons
  • "It is more or less stable. Sometimes I have some issues normally when we need to upgrade it to newer versions. I think it does the job."
  • "I think the part of IPS and everything else needs to be better equated to the real needs or current needs of the business compared to the other manufacturer, because it is not straightforward, a way to configure it compared to the other competitors."

What is our primary use case?

Our primary use case is as a firewall segregating networks and defending the perimeter.

How has it helped my organization?

I would consider this to be a medium product in its field across the board.

What needs improvement?

Some features, for instance, are a way for the management console to be able to manage each specific firewall, for instance. Because if we have more than one firewall configured in the management center, we cannot delegate administration, just one of the equipment. I think the part of IPS and everything else needs to be better equated to the real needs or current needs of the business compared to the other manufacturer, because it is not straightforward, a way to configure it compared to the other competitors.

For how long have I used the solution?

I have been using Cisco NGIPS for one year.

What do I think about the stability of the solution?

It is more or less stable. Sometimes I have some issues normally when we need to upgrade it to newer versions. I think it does the job. The hardware does the job, and the current models do the job.

What do I think about the scalability of the solution?

We have around four thousand users and that would be an example of its scalability.

How are customer service and support?

Technical support is good. If you open a case about the support, it is good. Compared to the other manufacturer, it is very good.

How was the initial setup?

The initial setup was complex and the upgrade took a lot of time with a very big image to download and everything else. We had many versions and patches that had to be installed. The deployment took between two and three hours.

What about the implementation team?

In this case, we did it in-house and I was the integrator.

What other advice do I have?

I think we have to have a good knowledge of the product. It is not easy to set up from the beginning. And I am also using the comparison with the other manufacturer. You need to have very good training before managing the product. I would rate Cisco NGIPS a seven on a scale of one to ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Buyer's Guide
Download our free Cisco Secure IPS (NGIPS) Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2025
Buyer's Guide
Download our free Cisco Secure IPS (NGIPS) Report and get advice and tips from experienced pros sharing their opinions.