We mostly use Cisco Secure Firewall as a VPN concentrator and for its firewall features.
Cisco Secure Firewall ASA Virtual - PAYG
Cisco Systems, Inc.External reviews
External reviews are not included in the AWS star rating for the product.
An easy to configure solution that can act as a VPN concentrator
What is our primary use case?
How has it helped my organization?
Using Cisco Secure Firewall has helped grow our familiarity with people that know Cisco.
What is most valuable?
The most valuable feature of Cisco Secure Firewall is its ease of configuration and that it's scalable for firewalls and VPNs.
What needs improvement?
Changes you make in the GUI sometimes do not reflect in the command line and vice versa.
For how long have I used the solution?
We have been using the solution since its inception, so, for many years now.
What do I think about the stability of the solution?
We did not have any stability issues with Cisco Secure Firewall.
What do I think about the scalability of the solution?
We did not see any limitations with Cisco Secure Firewall’s scalability.
Which solution did I use previously and why did I switch?
We also use Aruba in our organization. We never have to factor in extra development time when we go to a new major version of Cisco. With Aruba, we have a pretty drawn-out development timeline for any upgrades or software improvements. Aruba and Cisco Secure Firewall are very different in their implementation and development.
How was the initial setup?
The initial setup of the Cisco Secure Firewall is very straightforward. The average time it took to deploy the solution was very short. Deploying the VM and automating our configurations took a couple of minutes.
What's my experience with pricing, setup cost, and licensing?
Cisco smart licensing is a hassle for a disconnected environment. However, I haven't licensed anything in a while. There have been many changes, making it easier to license disconnected devices connected to the internet.
What other advice do I have?
ASAv uses the solution as a VPN concentrator and a firewall because it could be used for both. It can be used for landing AnyConnect clients on ASAv and as a firewall.
What sets Cisco Firewall apart from other products is that when we do an update, we know we're not going to break a lot of things, and there are not a lot of bugs. The integration on the Cisco side is pretty good.
Most of our team is familiar with Cisco, and everyone knows what to expect when they log in. So it's easy in that way.
I like the application visibility and control with Cisco Secure Firewall. My only complaint is that the changes made in the GUI sometimes do not reflect in the command line.
I haven't had any problems with Cisco Secure Firewall. It's very straightforward and reliable. Also, it's trustworthy because it has the Cisco name.
Cisco Secure Firewall has helped free up our IT staff for other projects. The product is quite heavy into automation. So with it being Cisco, it is very scalable in generating configs. The solution saves a week or two for implementation and integration.
Cisco Secure Firewall has helped our organization improve its cybersecurity resilience through the reliability aspect.
You know what you're getting when you use an ASAv from Cisco. Cisco Secure Firewall is a great product in terms of reliability and scalability.
Overall, I rate Cisco Secure Firewall ten out of ten.
Secures our infrastructure from end to end
What is our primary use case?
We have some in our DMZ. We have some located in several locations throughout our state. Then we have our local Egress and VPN firewalls that we use.
What is most valuable?
The VPN is our most widely used feature for Cisco Secure Firewall. Since we were forced into a hybrid working situation by COVID a few years back, VPN is the widely used feature because everybody is working remotely for our agency. So it came in very handy.
What needs improvement?
Cisco Secure Firewall’s customer support could be improved.
For how long have I used the solution?
I have been using Cisco Secure Firewall for 20 years.
What do I think about the stability of the solution?
Cisco Secure Firewall is a very stable solution.
What do I think about the scalability of the solution?
We bought scalable products, and we're in a good position.
How are customer service and support?
With Cisco Secure Firewall's technical support, it's always hard to get somebody that knows what they're doing on the line. However, when you finally get somebody on the line, it's pretty good. Having to deal with the licensing and be able to open a TAT case based on the serial numbers was very difficult. The individuals we get support from are pretty good, but the solution's support is two out of ten because of the process of having to get to that point to get support.
How would you rate customer service and support?
Negative
Which solution did I use previously and why did I switch?
I have previously used Juniper. Our company decided to go with Cisco Secure Firewall because of the cost and ease of use. Also, the people in our team knew Cisco versus other solutions.
How was the initial setup?
Cisco Secure Firewall's initial setup was pretty straightforward. They have a wizard, which helped in some instances, but there's also a lot of documentation online that helps a lot.
What about the implementation team?
We have a reseller that we go through, and they helped implement Cisco Secure Firewall for us.
What other advice do I have?
The application visibility and control with Cisco Secure Firewall is pretty great. We have the FTD, the firewall threat defense, and FMC, the management console we use, and we have great visibility using that product.
Cisco Secure Firewall's ability to secure our infrastructure from end to end is really good. We always find things and or block things before they even happen. So it's great, especially with Talos.
Cisco Secure Firewall has helped free up our IT staff for other projects to a certain degree. We still have to review logs in the firewall, and hopefully, someday, we'll have AI to help do that for us too. The solution has probably saved our organization about ten hours a week.
We use Talos, among other threat advice tools, and it's very good. Talos automatically updates us on the threats out there, and we can deploy those to our devices if we deem it fit to deploy them.
Cisco Secure Firewall has helped our organization improve its cybersecurity resilience. We've used Cisco for so long, and we've never had a data breach up to this point.
Overall, I rate Cisco Secure Firewall ten out of ten.
Cisco Adaptative
We need help to upgrade to the version of the ASA OS that currently is on version 7.16 and an upgrade to version 9.14(2)8 is required
We request your important support to review the causistry of updating the VPN services found in AWS, we have 6 C5xlarge with images of Cisco Secure Firewall ASA Virtual - PAYG which we require to upgrade to the version of the ASA OS that currently is on version 7.16 and an upgrade to version 9.14(2)8 is required
i-0521966302cb81d67
i-06f377eef48968e71
i-0e2a22338ca7e533a
i-0141f49bb48f8c3b5
i-010e4caa4fe7a687b
i-0c5cd8239b2233718
i-082c7850b684ac26c
ASA 55xx
great experience
Good Firewall and VPN solution
- Posture requirements
- Dynamic configurations
default password - read the directions
Folks the inquiries about the default password... Sigh- read the directions. https://www.cisco.com/c/en/us/td/docs/security/asa/asa99/asav/quick-start/asav-quick/asav-aws.html
Here is how to make it work... BEFORE you launch the AMI you must click advanced details and ADD a zero day configuration via text entry. Once you do connect via SSH and the username is admin. That said I was a victim too on the first try.
VPN Security
Really close to the physical rackmount version
Using these for work for most of the year now with a site-to-site tunnel from an asa-v in us-east-1 to an asa-v in us-west-2 as well as several incoming site-to-site tunnels and remote access VPN on both 9.5.2.204 and 9.5.2.207. Make sure you know what you're doing...you're comfortable with Cisco config via user data (and later ASDM if needed), you have compared what ASA-v doesn't provide, etc. otherwise you'll give undeserved 1-star reviews like those before. Only issue seen so far is Syslog can die with lots of traffic around a month in (204) or several months in (207) which requires a restart of the appliance. I'm hoping 9.6.2.1 fixes that. Other than that a ChangeLog for each AMI version would be nice to see.