No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco Secure Firewall vs WatchGuard XTM [EOL] comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 30, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
591
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Firewalls (1st), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Cisco Secure Firewall
Average Rating
8.2
Reviews Sentiment
7.0
Number of Reviews
459
Ranking in other categories
Firewalls (5th), Cisco Security Portfolio (3rd)
WatchGuard XTM [EOL]
Average Rating
8.0
Number of Reviews
34
Ranking in other categories
No ranking in other categories
 

Featured Reviews

Abhinandan Yadav - PeerSpot reviewer
Network Security Engineer at Arrow PC Network Pvt Ltd
Unified security and sd-wan have improved uptime and cut wan costs for multi-site branches
Users report stability issues in certain versions, which requires regular updates. Real-world attacks have also highlighted the need for urgent patching of vulnerabilities.Fortinet FortiGate, while a powerful and feature-rich web firewall, could improve in areas like firmware stability, documentation, and ease of use. The learning curve can be steep for some users. For beginners, support quality can vary, and frequent updates with occasional vulnerabilities call for careful patch management. However, once Fortinet FortiGate is configured, it remains highly reliable and efficient. Customer support needs improvement, as I find it very slow, with reports from other users reflecting that customer support is inadequate.
Phil Shiflett - PeerSpot reviewer
Senior Manager, Network Engineering at TTi Power Equipment
Unified policies streamline network management but complex licensing requires attention
Cisco Secure Firewall has some growth opportunities in terms of visibility and control capabilities regarding managing encrypted traffic. It has the ability to analyze encrypted traffic, and there is potential for more integration with APIs and AI to enhance these capabilities. Cisco Secure Firewall needs improvement in deployment time and the capability to access the CLI during support calls. I often encounter issues when technical support uses a CLI that is not familiar to me while troubleshooting through the GUI. My ongoing complaint for the last six years has been the lack of CLI functionality, which hinders my ability to work on the firewall, alongside concerns regarding deployment time. For the next release, they should look at the features offered by competitors such as Fortinet, including the ability to perform packet capture directly from the interface. If they enhanced their troubleshooting efficiency related to packet capture for each specific rule, it would simplify the process significantly.
Generalm4545 - PeerSpot reviewer
General Manager- IT & Automation - Serum at a pharma/biotech company with 1,001-5,000 employees
Protects from attack software and hacking but it doesn't provide the reports in a readable format
In my opinion, image clarity is very important, because I don't get the proper image product on reports. This means that functionality is not there. My engineer does not know how he can replace an order. We attach a log after any kind of keys using a utility instead. For the internet policies that we are implementing, the policy should be based on proper protocols. We use the default policies and there are a number of third-party protocols that appear here. Management with WatchGuard XTM means that out of policy is the problem from our side. In this way, we can not do effective services for people with this one. The policy definition with WatchGuard XTM is not proper for all use case requirements. I've got weekly business reports that I am expecting attachments with from WatchGuard XTM that display data for all kinds of consideration which should be required. Main User Functionality Level Order must adhere to using the admin functionality on the registry, or else our users publish their own name. Maybe these recommendations are irrelevant, but I say that the issue to improve most with WatchGuard XTM is the Main User Function.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Fortinet FortiGate's most valuable features are ease of use, flexibility, and most of the configuration we can be done using the GUI. When we compare Fortinet FortiGate with other solutions the firewall policy are very easy to understand."
"The product has the most valuable configuration, offloading, and security features."
"The most valuable feature of FortiGate is FortiView which provides proactive monitoring."
"The firewalls are valuable for threat prevention."
"It's very easy to configure."
"We were looking for the VPN feature and controlling the inflow and outflow of all the traffic within the site and across the sites. We are also using it for the VPN and VLANs."
"We’ve gone from only selling Fortinet FortiGate as an accessory to creating an entire department in our business dedicated to selling Fortinet products in the span of three years."
"​Easy to implement, and it is also reliable.​"
"Apart from those four things, the Cisco ASA with FirePOWER Services solution works well, provides great insight, applies Advanced Malware Protection strongly, and shuts down a ton of illegitimate connections before they can attack."
"Beats sophisticated cyber attacks with a superior security appliance."
"Cisco Secure Firewall made it easier so that more than one person can handle things. We are able to have a bigger team that can handle simple tasks and have a smaller team focus on the deep-dive needs."
"Connectivity with client Telcos works perfectly and administration is simple."
"The Adversity Malware Protection (AMP) feature is the most valuable. It is also very easy to use. Every technical user can operate this solution without any difficulty. The dashboard of Cisco Firepower has every tool that a security operator needs. You can find every resource that you need to operate through this dashboard."
"I would rate this solution as ten out of ten."
"Some of the most valuable features of the Cisco Secure Firewall are that they are easy to deploy, which is a very important thing to highlight."
"The most valuable feature is the anti-malware protection. It protects the endpoints on my network."
"​Monitoring of network activity is included in the box.​"
"After installing the product, we achieved awareness of our data protection needs and email misuse."
"It costs less than the SO works and others (like SonicWall, Cisco, and Barracuda) without increasing so much CPU use."
"We now have the capability to manage traffic better by putting non-business critical traffic into the small bucket, while business critical traffic gets higher priority."
"The product is easy to use and is the fastest way to learn about firewalls."
"WatchGuard XTM2050A has enterprise class performance with the cost of an SMB class device."
"This product has helped in securing my SQL database and web applications from DDoS attacks and SQL injections, improved my network speed, and helped me to set specific policies for specific applications which I couldn't do with other products."
"Setup and configuration is straightforward with excellent management interface."
 

Cons

"It would be good if they had fewer updates."
"I think they need to improve more in order to be a competitor with the leaders of the field."
"Technical support is good but the response time could be faster."
"The license renewal process, annual renewal price, and the web application firewall features should be improved."
"The initial setup is medium complex and takes between five days and a week."
"Scalability is one of the disadvantages. When it comes to scalability, you have to actually change the box. If you want to upgrade it, you need to actually change the existing box and probably you take the system off to other sites."
"Fortinet needs more memory to save the log files. We need it to save the logs on the hardware and not in the cloud. I know this feature is available in FortiCloud, but if we need this log locally, it is not available."
"Some of the filtering is not robust, you can escape it with a VPN. Some of the users bypass some of the filters."
"I would like it to be easier to work with and have a better user interface. It is not straightforward; you need to know the Cisco command-line interface."
"In the future, I would like to be able to use an IP phone over a VPN connection."
"The artificial intelligence and machine learning (behavioral based threat detection), which I can this will be coming out in another year, these are what we need now."
"This is an older product and has reached end-of-life."
"Cisco is still catching up with its Firepower Next-Generation firewalls."
"Most users do not have awareness of this product's functionality and features."
"Cisco still has a lot of work to do. You can convert an ASA over to a Firepower, but the competitors, like Palo Alto and Juniper, are coming in."
"FlexConfig is there as a bridge for features that are not yet natively integrated into Firepower. It is a way of allowing you to be able to configure things that wouldn't otherwise be possible until the development team can add them into Firepower's native capability. There is still some work that needs to be done around FlexConfig. There are still quite a few complex things, like policy-based routing, that have to be done in FlexConfig, and it doesn't always work perfectly. Sometimes, there are some glitches. It is recommended that you configure FlexConfig policies with Cisco TAC. It would be good to see Cisco accelerate some of those configurations that you can only do in FlexConfig into the platform, so that they are there natively."
"We had some problems of instability with older versions of the software."
"Unfortunately, I could not disable the default Outgoing policy and if I do all clients could not access the internet even if I created another Outgoing Policy to replace the default one."
"Sometimes we have had issues with stability of the product."
"I feel that paying a yearly maintenance fee for firmware updates is not worth it in my opinion."
"I would like them to improve the product's overall protections. This would be good for all product users."
"The initial setup is neither simple nor complex. If you know the base in networking and how the firewall works, you will be able to figure it out.​"
"The initial setup is neither simple nor complex. If you know the base in networking and how the firewall works, you will be able to figure it out."
"Our device was not functioning properly, so we returned the product and as a result, our business was down for two days."
 

Pricing and Cost Advice

"FortiGate Next Generation Firewall is an expensive solution with a yearly subscription."
"The price of Fortinet FortiGate is better than Cisco, Check Point, and Palo Alto. In terms of pricing, it's probably a better-priced firewall solution overall."
"They need to be competitive with other solutions."
"The pricing is reasonable."
"There is a subscription-based model to use Fortinet FortiGate. We pay annually for the solution along with the support. If you want to have all the updates, and security patches you will need to renew your support."
"The tool is a bit pricey for small businesses, but it is still bearable in terms of cost."
"The price for the device and software is high. However, the solution is of good quality and has a lot of features."
"The price is fine."
"The licensing scheme is completely confusing, and they need to streamline it. They have classic licensing and a new type of licensing now. Also, the licensing for the actual firewall is separate from the one for TAC support."
"It is affordable. The hardware is not that expensive anymore. It is a matter of licensing these days."
"The Firepower series of appliances is not cheap. I just got a quote recently for six firewalls that was in the range of over half-a-million dollars. That's what could push us to look to other vendors..."
"Be sure of what features you are ​going to utilize to add/remove some from new bundles."
"If we compare it with FortiGate and the co-existing ASA, FortiGate is better in price."
"The pricing of Cisco's boxes is pretty good."
"Cisco Firepower is a great solution, but it is expensive compared to others that can provide similar benefits for much less."
"There are licensing costs."
"It costs less than the SO works and others (like SonicWall, Cisco, and Barracuda) without increasing so much CPU use."
"Get at least a maintenance contract for the updates and take a larger WatchGuard than you need. A WatchGuard creates new ways to secure your network."
"Like all other manufacturers, there are a lot of features and different pricing. The best is to talk to a representative.​"
"The licensing and renewal is very expensive."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
893,164 professionals have used our research since 2012.
 

Comparison Review

it_user206346 - PeerSpot reviewer
Security Consultant at Webernetz.net - Network Security Consulting
Mar 11, 2015
Cisco ASA vs. Palo Alto Networks
Cisco ASA vs. Palo Alto: Management Goodies You often have comparisons of both firewalls concerning security components. Of course, a firewall must block attacks, scan for viruses, build VPNs, etc. However, in this post I am discussing the advantages and disadvantages from both vendors concerning…
 

Top Industries

By visitors reading reviews
Computer Software Company
10%
Comms Service Provider
10%
Manufacturing Company
9%
Financial Services Firm
7%
Computer Software Company
10%
Manufacturing Company
9%
Financial Services Firm
7%
Comms Service Provider
7%
Marketing Services Firm
14%
Financial Services Firm
14%
Performing Arts
13%
Manufacturing Company
11%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business367
Midsize Enterprise135
Large Enterprise193
By reviewers
Company SizeCount
Small Business190
Midsize Enterprise129
Large Enterprise232
By reviewers
Company SizeCount
Small Business24
Midsize Enterprise7
Large Enterprise3
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
Which is better - Fortinet FortiGate or Cisco ASA Firewall?
One of our favorite things about Fortinet Fortigate is that you can deploy on the cloud or on premises. Fortinet Fort...
How does Cisco's ASA firewall compare with the Firepower NGFW?
It is easy to integrate Cisco ASA with other Cisco products and also other NAC solutions. When you understand the Cis...
Which is better - Meraki MX or Cisco ASA Firewall?
Cisco Adaptive Security Appliance (ASA) software is the operating software for the Cisco ASA suite. It supports netw...
Ask a question
Earn 20 points
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
Cisco Adaptive Security Appliance (ASA) Firewall, Cisco ASA NGFW, Adaptive Security Appliance, Cisco Sourcefire Firewalls, Cisco ASAv, Cisco Firepower NGFW Firewall, Cisco Secure Firewall ASA Virtual - BYOL
No data available
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
There are more than one million Adaptive Security Appliances deployed globally. Top customers include First American Financial Corp., Genzyme, Frankfurt Airport, Hansgrohe SE, Rio Olympics, The French Laundry, Rackspace, and City of Tomorrow.
AVG, Cyren, Kaspersky Lab, Lastline, NCP engineering, Trend Micro, Websense
Find out what your peers are saying about Fortinet, Netgate, Sophos and others in Firewalls. Updated: April 2026.
893,164 professionals have used our research since 2012.