Overview
As you migrate your workloads from physical appliance to public cloud infrastructure, you need the same kind of secure web as offered by physical appliances.
With Cisco's Secure Web Appliance (aka Web Security Appliance) on AWS, you can safeguard your business through broad threat intelligence, multiple layers of malware defense, and vital data loss prevention (DLP) capabilities across the attack continuum.
Secure Web Appliance plays an important role in overall Cisco security solution architecture.
With existing integrations with Advanced Malware Protection, SecureX, Identity Service Engine, Umbrella it eases out the tasks for network and security admins to deploy and operate these solutions in the network.
Highlights
- With Secure Web Appliance, you can assess files using the latest threat information from Cisco Talos. Cisco Secure Web captures a fingerprint of each file as it traverses the gateway and sends it to Cisco's cloud based threat intelligence network for a reputation verdict.
- You can identify malware and breaches as they affect your system. When malware is detected, AMP gets precise details about a file's behavior and combines that data with detailed human and machine analysis to determine the file's threat level in a sandbox
- Centralized management and reporting is also available via SMA. You can deploy SMA along with WSA on the AWS environment. There is no additional license for SMA or WSA on AWS. You can use the existing licenses from your physical appliances and deploy any number of instances
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
Please contact your Cisco Sales Team for refund or cancellation policy information
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Additional details
Usage instructions
It is recommended to deploy 'Async OS 15.5.1' with c5 instance type.
Resources
Vendor resources
Support
Vendor support
https://www.cisco.com/c/en/us/support/index.html BYOL: Cisco TAC provides support based on purchased licenses and support contract from Cisco or an authorized Cisco Reseller
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products

Customer reviews
Advanced protection features offer robust security while integration process presents challenges
What is our primary use case?
The user interface that I usually provide for the web app includes malware protection, URL filtering, data loss prevention (DLP ), and advanced threat analytics. This is how I typically implement user cases for my client with the codec.
What is most valuable?
The features I like most are the DLP functionality for web security and malware protection. The malware protection is especially impressive when it is integrated with other Cisco products like Cisco I and the firewall FTP. When I integrate these three products, it efficiently prevents malware, showing which endpoint is affected and providing a comprehensive view of the endpoint connections.
What needs improvement?
With the WebAssign integration, it is not easy when I am integrating policies within the company, especially with NAND and wireless policies. The challenge arises when traffic is blocked from either wireless or wired connections. Although implementing it as a standalone is quicker, integrating BYOD with Cisco I and FTB can be tiring. Once it is done correctly, the functionality and reports become valuable, although the implementation part can still be challenging.
For how long have I used the solution?
I have used the solution for about ten years now.
What do I think about the stability of the solution?
It is very stable, a product that I put on the network, and it will run for a very long time. I would rate it nine out of ten.
What do I think about the scalability of the solution?
It is very stable. I would rate it nine out of ten.
How are customer service and support?
I think I will give them a seven out of ten for WSA. The support is good but slow. Generally, the response time for resolving issues is getting slower. This applies to all products, including firewalls and next solutions. It is not what it used to be.
How would you rate customer service and support?
Neutral
How was the initial setup?
The setup is simple and quick. The web is already an appliance on standby. The only challenge is when I bring policies to the appliance and integrate it with my next solution and FTD. It can be tricky initially, but as I become more familiar, it becomes easier. However, it depends on the environment. Simpler environments make the setup very straightforward.
What's my experience with pricing, setup cost, and licensing?
Comparing with other products, Cisco has more functionality, but pricing is a challenge. Cisco is not a product for small companies due to its pricing. Cisco has been in business for a long time, requiring a significant investment.
Which other solutions did I evaluate?
I can provide it with BlueCards. BlueCards is where ReliVista plays a role. In terms of functionality, BlueCards is slightly off, however, I've heard good things about WSA. While comparing it with FTP and the firewall, it is improving and becoming more competitive in the market.
What other advice do I have?
I will give it a seven out of ten as the overall product rating. It is a good product, and as a Cisco partner, we sell many Cisco products.
Subscription-based with enhanced content control and filtering
What is our primary use case?
Cisco Web Security Appliance is used to secure users from malicious threats across the internet and applications they access on different cloud platforms. It is a dedicated solution for protecting users from various internet threats and provides a centralized dashboard for visibility and control over accessed apps.
What is most valuable?
The solution offers content filtering and micro-content controls, such as regulating the types of images and their resolution. It provides granular controls over media being accessed on social platforms, ensuring that content not in the company's interest is restricted.
What needs improvement?
The product is great, however, incorporating features offered by competitors would be beneficial. Competitors sometimes highlight features that Cisco products lack. Additional features like improved whitelisting and blacklisting of malicious websites could enhance the product.
For how long have I used the solution?
I have been using Cisco Web Security Appliance for several years, more than seven or eight, approximately eight or nine years.
What do I think about the scalability of the solution?
The solution is subscription-based, making scaling possible.
How are customer service and support?
Cisco offers intense and comprehensive technical support services, making it a strong selling point.
How would you rate customer service and support?
Positive
How was the initial setup?
The installation requires a skilled resource who understands the product technology and its features. Deployment is not straightforward due to the complexity of the functions and considerations involved.
What about the implementation team?
Cisco provides Mentored Installation Services through specialized service delivery partners to ensure proper deployment.
What's my experience with pricing, setup cost, and licensing?
Pricing is competitive and varies across sectors. Public sector clients receive good pricing, whereas enterprise or commercial clients might not find the pricing as favorable.
What other advice do I have?
I'd rate the solution eight out of ten.
Ensures security for remote workers
What is our primary use case?
We use the solution for web security. We have Netskope for DLP. We opted for the Cisco solution for its cost-effectiveness. We use all its features effectively to prevent unnecessary expenses.
We implemented Cisco Web Security Appliance to address the challenge of ensuring security for remote workers. Employees working from home operate outside the company's network, potentially exposing the organization to various risks as they access the internet directly. Without enforcing company policies, there's a heightened vulnerability to data breaches. We can extend protection to remote users by deploying Cisco Web Security Appliance, even when not connected to the company's network. This ensures that corporate data remains secure regardless of the user's location.
How has it helped my organization?
Cisco Web Security Appliance restricts access to illegitimate websites, including those containing pornography and categories like social media platforms like Facebook. Policies must be installed on endpoints to enforce these restrictions and assist users in accessing appropriate content.
What is most valuable?
The solution offers a range of security features, including Cloud-based policies and Key Security Bundles. It includes DNS certificate functionality. These features streamline security processes and provide comprehensive solutions within a single platform.
The DNS security feature is the most effective when users transition to remote work, as we are currently in a hybrid mode due to the COVID-19 pandemic. This hybrid mode involves working from home and occasionally reporting to the office.
What needs improvement?
The solution could provide seamless integration with other technologies. Cisco's strength lies in its reliable managed services, which address any issues promptly. It is not able to integrate with existing technologies.
The ISB component of KSB is weak, but its firewall capabilities and DNS are strong.
For how long have I used the solution?
I have been using Cisco Web Security Appliance for one year.
What do I think about the stability of the solution?
It is scalable and is a very effective solution in that regard. You can size it differently according to your needs, as there are various models available. When it comes to scalability, we address five key factors.
What do I think about the scalability of the solution?
The Cisco Web Security Appliance is indeed stable. While there have been occasional instances of instability, particularly during the August period, overall, its stability is commendable. The solution itself is robust and reliable.
How are customer service and support?
Customer support is very effective. They follow up to resolve any issues. They continuously inquire if there are any outstanding concerns. Their comprehensive approach, covering many solutions, including a 360-degree block-wise strategy, is excellent.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We tried using Cisco but faced issues, especially with DDoS attacks. There were delays, and our website started to crash because of the overload on their servers.
How was the initial setup?
Cisco manages the solution's setup. We purchased their managed services, so they continue to handle its management.
The complexity arises when deploying various web security solutions, such as Kaspersky, with Cisco Web Security Appliance. Sometimes, transitioning from one solution to another, like Kaspersky to Cisco, can bring certificate installation complexities.
If we opt for the Cloud version, implementation takes two months. On the other hand, deploying the on-premises solution usually takes three to four months.
What was our ROI?
The general investment in Cisco Web Security Appliance is relatively minimal. When considering its utility, the primary purpose is to enhance the layers of protection. If our endpoints are already secured, the justification for investment may seem less apparent. However, the significance of Web Security Appliance becomes evident in scenarios where breaches occur or security threats escalate. In such instances, the importance of investing in additional security measures becomes clear.
What's my experience with pricing, setup cost, and licensing?
What other advice do I have?
The Cisco Web Security Appliance provides DLP to organizations. It helps prevent the unauthorized transmission of sensitive information by blocking such attempts. Additionally, it safeguards against malware attacks, particularly on websites not authorized by our company. Its role in protecting us from malware is pivotal.
The organization itself handles the configuration and management of Cisco Web Security Appliance. Cisco assists in deploying and configuring the appliance and managing all associated services.
Integrating the Cisco Web Security Appliance with other solutions is quite challenging. For instance, when we tried to integrate Netscape KSP, we encountered difficulties retrieving logs. Additionally, our solution failed to interact with the Web Security Appliance. Overall, the integration process remains problematic, hindering the effectiveness of our security infrastructure.
We have both the cloud version and the on-premises version. For clients who require data sovereignty, we offer the on-premises version, which includes a data sovereignty tool. This allows them to enforce policies that prevent the transfer of logs to third-party data centres, ensuring compliance with their country's regulations.
Overall, I rate the solution a nine out of ten.
Though the product ensures a high ROI, the management capabilities require improvement
What is our primary use case?
I use Cisco Web Security Appliance in my company for proxy-related purposes.
What is most valuable?
The most valuable features of the solution are the functions of proxy for the users who use the internet and the security it offers against the not-so-secure web pages.
What needs improvement?
There are certain shortcomings related to the product's management capabilities, where improvements are required. The solution needs to provide better management of the category of web pages.
For how long have I used the solution?
I have three years of experience with Cisco Web Security Appliance . My company is a customer of the solution. I use the solution's previous or the previous to previous version.
What do I think about the stability of the solution?
Stability-wise, I rate the solution an eight out of ten.
What do I think about the scalability of the solution?
Scalability-wise, I rate the solution a seven out of ten.
Around 300 people in my company use the solution.
I use the solution every day in my company.
How are customer service and support?
At times, the product's technical support takes a long time to provide solutions.
I rate the technical support a six out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I have experience with GFI KerioControl . I also have experience with other devices from Cisco. I have done some integration of the Cisco Web Security Appliance with other systems.
How was the initial setup?
I rate the product's initial setup phase a seven on a scale of one to ten, where one is a difficult setup phase, and ten is an easy setup phase.
The solution is deployed on an on-premises model.
It took quite a long time to implement the solution, maybe seven to eight months. The deployment phase took a few weeks.
Two or three specialists who are network administrators in my company were involved in the deployment and maintenance phases of the product.
What about the implementation team?
The product's reseller helped my company with the product's implementation phase.
What was our ROI?
From an ROI perspective, I rate the product a nine out of ten.
What's my experience with pricing, setup cost, and licensing?
I rate the product price a ten on a scale of one to ten, where one is low price and ten is high price.
Which other solutions did I evaluate?
During the evaluation phase, my company considered GFI KerioControl and Fortinet FortiProxy against Cisco Web Security Appliance.
What other advice do I have?
I rate the overall product a seven out of ten.
An user-friendly solution that offers environment protection
What is most valuable?
Cisco Web Security Appliance is user-friendly and easy to manage. It protects your environment while accessing the internet.
What needs improvement?
The tool needs to improve cloud-based decryption.
What do I think about the stability of the solution?
Cisco Web Security Appliance's stability is good.
What do I think about the scalability of the solution?
The product is scalable. We have 1500 to 2000 users.
How was the initial setup?
The tool's deployment is very straightforward. The only process that can take time is aligning the policies as per your use case.
What about the implementation team?
Getting a partner from Cisco to help with the deployment is good.
What was our ROI?
You can get a good ROI in the long run.
What's my experience with pricing, setup cost, and licensing?
The tool's licensing is yearly.
What other advice do I have?
I rate the product a ten out of ten.