No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco Sourcefire SNORT vs KerioControl comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 19, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco Sourcefire SNORT
Ranking in Intrusion Detection and Prevention Software (IDPS)
12th
Average Rating
7.8
Reviews Sentiment
6.8
Number of Reviews
20
Ranking in other categories
No ranking in other categories
KerioControl
Ranking in Intrusion Detection and Prevention Software (IDPS)
13th
Average Rating
8.2
Reviews Sentiment
6.9
Number of Reviews
58
Ranking in other categories
Firewalls (27th), Unified Threat Management (UTM) (8th)
 

Mindshare comparison

As of August 2026, in the Intrusion Detection and Prevention Software (IDPS) category, the mindshare of Cisco Sourcefire SNORT is 3.0%, up from 2.6% compared to the previous year. The mindshare of KerioControl is 3.0%, down from 3.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Intrusion Detection and Prevention Software (IDPS) Mindshare Distribution
ProductMindshare (%)
Cisco Sourcefire SNORT3.0%
KerioControl3.0%
Other94.0%
Intrusion Detection and Prevention Software (IDPS)
 

Featured Reviews

reviewer2772102 - PeerSpot reviewer
Cloud Architect at a consultancy with 1-10 employees
Logging and customizable rules have helped improve threat monitoring and detection
The logging is mainly what I consider one of the best features with Cisco Sourcefire SNORT. Being able to log and store it in a file allows you to push it to a centralized repository. The logging and reporting help improve incident response. You should always be logging threats, any sort of misconfiguration, and anything that could be an issue. It's important to at least log and monitor it. The basic rules provide a good baseline in assessing Cisco Sourcefire SNORT's ability in providing real-time analytics for threat detection, but as a professional, you should look to constantly modify that baseline. They provide extensive customizability so you can define your own rules. The customizability allows it to be adaptable in protecting against diverse network threats to the constant change.
Constantnos Achilleos - PeerSpot reviewer
Product manger at Asbis Mediteranean
Leveraging geo-tagging and web filtering for enhanced network security
The solution is used for site-to-site VPN connections and it is valued for its cost efficiency and easy connectivity. It is especially beneficial for multi-site VPNs and is used in about fifteen different components KerioControl has provided a financial benefit as it allows purchasing one license…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I would recommend this solution; it's reliable and scalable, with easy installation and integration."
"The solution is rather easy to use."
"The logging is mainly what I consider one of the best features with Cisco Sourcefire SNORT; being able to log and store it in a file allows you to push it to a centralized repository."
"I like most of Cisco's features, like malware detection and URL filtering."
"With Cisco Sourcefire SNORT, we've been able to prevent and detect intrusion in our network and actually decrease our SLA (Service Level Agreement)."
"The solution can be integrated with some network electors like Cisco Stealthwatch, Cisco ISE, and Active Directory to provide the client with authentication certificates."
"We primarily use this solution as an intrusion prevention system for external firewalls and deploy the solution on-premises."
"If you compare it to other vendors, the technical support from Cisco is excellent."
"The user interface and the ease of use are pretty good. Everything fits together so nicely."
"One thing we always tell our customers is that we have never had a client using Kerio Control and the antivirus tools that we suggest who has been infected with any type of ransomware."
"The most valuable features of KerioControl are ease of configuration, user-friendliness, and comfortable to use. It is an all-in-one solution, it comes with many features, such as a firewall, antivirus software, and network protection."
"The most valuable feature is the reliability of VPN capabilities. The VPN has been very reliable and secure. The security has been very good and the VPN connections are reliable in that they stay up. We don't have a lot of problems with downtime and that type of thing."
"When one of the employees of my customers is using the VPN Client, I have created for them that they will always get a message. When the VPN Client connects to Kerio Control from the outside, they will get an email so they know when they are connected and when they are disconnected what is happening to their network."
"The interface control manager where we can allocate LAN connections to certain VLANs is the most valuable feature. The other feature that's important for us is because obviously everything is remote with MyKerio, as long as the boat has an internet connection, we can log onto the Kerio and get statistics, as well as provide support."
"The most valuable feature is to provide users with the ability to log in to the portal page, keep track of their data usage and perform bandwidth management."
"Kerio is a lot clearer to set up to do particular things, whereas when I do it on a Cisco or a FortiGate I have to go fight with it per week sometimes to do something I can do in 20 minutes on Kerio."
 

Cons

"The main dashboard of Cisco Sourcefire SNORT could improve."
"While the alerts they offer are good, it could improve it in the sense that they should be more detailed to make the alerts more useful to us in general. Sometimes the solution will offer up false positives. Due to the fact that the alerts aren't detailed, we have to go dig around to see why is it being blocked. The solution would be infinitely better if there was just a bit more detail in the alert information and logging we receive."
"Integration with other components — even Cisco's own products — can be enhanced to improve administrative experience."
"Performance needs improvement."
"The utopia is to see everything from one dashboard, but sometimes that's not very possible."
"Cisco Sourcefire SNORT can scale, but if you have too much, you could fill up your log files, which I consider when discussing scalability."
"The solution's approach to managing traffic blocking is confusing and impractical."
"To be frank, the product is not really stable, although they're working on that."
"I would like to see them develop a bit more flexibility creating VLANs."
"The denial of service could also be improved. There recently was a big issue with denial of service attacks and it was a bit laborious."
"Because of all the security features within Kerio Control, e.g., it can do a deep packet inspection, this can slow down the traffic."
"The upgrades make the network slower."
"I would like the customer statistics to be more user-friendly. It should explain more what users have been doing throughout the day. Sometimes, it'll just say they downloaded a big file. Meanwhile, they were connected through a VPN."
"Support responses need improvement."
"If you have to dive deeper into the firewall or any other features, then you really have to read up a bit about how to set it up properly. Some of my colleagues, in the beginning, jumped in and made a bunch of rules but then it got really messy. If Kerio had a template or guidelines for best practices, at the beginning, that would really help. With Kerio Control it's basically 'find out for yourself.'"
"I would like to see a little improvement in their technical support when you have a problem."
 

Pricing and Cost Advice

"Licensing for this solution is paid on a yearly basis."
"We have a three-year license for this solution."
"I don't know the exact amount, but most of the time when I go to a company with a proposition, they will say, "This thing that you are selling is good, but it's expensive. Why don't you propose something like FortiGate, Check Point, or Palo Alto?" Cisco device are expensive compared to other devices."
"The cost is per port and can be expensive but it does include training and support for three years."
"If one is an extremely expensive product, and ten is cheap, I rate the tool's price as a five."
"Its price is fair. There are no additional costs."
"It gets expensive pretty quickly if you need to purchase license packs."
"The price is inexpensive."
"It's pretty expensive in licensing costs, especially if you use the product longer than one or two years. The licensing costs are still high, which I don't think is reasonable for a product like this."
"Pricing is good, but the licensing took a lot of time."
"It gives us a lot. It does prove to be a very robust product for the cost."
"Our clients see ROI with Kerio Control, as they are saving bandwidth costs."
"The pricing is in-line with our expectations in terms of the quality that we get for it."
report
Use our free recommendation engine to learn which Intrusion Detection and Prevention Software (IDPS) solutions are best for your needs.
908,800 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
13%
Financial Services Firm
8%
Comms Service Provider
8%
Outsourcing Company
6%
Construction Company
12%
Computer Software Company
11%
Comms Service Provider
11%
Outsourcing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise9
Large Enterprise7
By reviewers
Company SizeCount
Small Business44
Midsize Enterprise9
Large Enterprise3
 

Questions from the Community

What is your experience regarding pricing and costs for Cisco Sourcefire SNORT?
If one is an extremely expensive product, and ten is cheap, I rate the tool's price as a five. There are some other tools in the market that are more expensive than Cisco. There are no additional c...
What needs improvement with Cisco Sourcefire SNORT?
I have not had much experience with the community-driven rule set while utilizing Cisco Sourcefire SNORT. I don't have experience with recognizing zero-day vulnerabilities, but based on my knowledg...
What is your primary use case for Cisco Sourcefire SNORT?
Endpoint protection is the main use case. The main aspect involves specifying different rules, and when network traffic hits these rules, it will try to block the traffic or at least log the traffi...
What is your experience regarding pricing and costs for KerioControl?
KerioControl offers good pricing as one license covers all features needed without extra payment. The price for the product is rated as ten out of ten.
What needs improvement with KerioControl?
Regarding KerioControl's application awareness and control feature, I have not used it much.
What is your primary use case for KerioControl?
With KerioControl, we usually use them for site-to-site VPNs for most of our clients. With multiple offices, we use KerioControl as our solution.
 

Also Known As

Sourcefire SNORT
No data available
 

Overview

 

Sample Customers

CareCore, City of Biel, Dimension Data, LightEdge, Lone Star College System, National Rugby League, Port Aventura, Smart City Networks, Telecom Italia, The Department of Education in Western Australia
Triton Technical, McDonald's
Find out what your peers are saying about Cisco Sourcefire SNORT vs. KerioControl and other solutions. Updated: August 2026.
908,800 professionals have used our research since 2012.