Cisco Secure Firewall ASA Virtual - PAYG
Comprehensive security has protected diverse enterprise networks and supports complex deployments
What is our primary use case?
I have been working with firewalls for more than eight years throughout my career, with extensive experience in network architecture and security design.
In my current role as a network architect, I evaluate firewall solutions based on the project RFP, client requirements, technical specifications, and consultant recommendations. My responsibility is to select and size the appropriate solution based on the specific requirements and use case of each project.
We use Cisco Secure Firewall in various network environments to secure WAN and perimeter traffic and to provide next-generation firewall capabilities, including IPS, IDS, URL and web filtering, application control, and SD-WAN for environments with multiple WAN links and high-availability requirements. Depending on the RFP and security architecture, Cisco Secure Firewall can also be deployed as a data center firewall to secure and control data center traffic.
For larger or more complex environments, we may implement a segmented firewall architecture, using dedicated firewalls for different security zones—for example, a WAN firewall, Internet/perimeter firewall, and DMZ firewall. The design depends on the traffic flows, security requirements, performance requirements, and overall architecture of the project.
Although Cisco is one of the firewall platforms we frequently deploy, we also work with other vendors depending on the project requirements. For example, some projects use Cisco for the perimeter firewall and Fortinet, Palo Alto Networks, or Sophos for the data center, while other projects may use Cisco for the data center and another vendor for the perimeter.
Ultimately, the firewall selection is driven by the customer's requirements, RFP specifications, technical use cases, performance and security needs, and the consultant's design. Using different firewall vendors across different security zones is sometimes a deliberate customer requirement or architectural decision.
What is most valuable?
One of the biggest strengths of Cisco Secure Firewall is the integration of multiple next-generation security capabilities into a single platform. For mid-sized deployments, a single firewall appliance can provide comprehensive perimeter security without requiring multiple standalone security solutions.
Key features include next-generation firewall capabilities, IPS/IDS, application control, URL and web filtering, VPN, malware and threat protection, and SD-WAN capabilities. Having these functions integrated into one platform provides centralized policy enforcement and better visibility into network traffic.
I particularly value the combination of firewall and threat-prevention capabilities because it allows organizations to inspect and control traffic at multiple levels rather than relying only on traditional stateful firewall policies. IPS and threat intelligence help identify and block malicious activity, while URL and web filtering provide additional protection against malicious or inappropriate destinations.
Another advantage is the scalability of the platform. Depending on the project requirements, Cisco Secure Firewall can be deployed for Internet and WAN security, perimeter protection, data center segmentation, or other security zones.
Overall, I would say its strongest feature is the ability to combine firewalling, threat prevention, traffic inspection, and secure connectivity into a unified security platform. This can simplify the architecture and operations while providing the security controls required for many enterprise environments.
What needs improvement?
One challenge is that many customers prefer a multi-vendor strategy. Since Cisco is already used for their core and access network, they often prefer Fortinet or Palo Alto Networks for the firewall to reduce vendor dependency and maintain architectural diversity.
The area for improvement is the configuration and deployment experience. Compared with other market vendors, Cisco Secure Firewall has a steeper learning curve and requires more hands-on expertise. FMC provides powerful centralized management, but it can also add complexity, particularly in multi-firewall deployments.
Cost is another consideration. In many projects, Cisco can be around 15 more expensive than competing solutions, depending on the model and licensing.
I would like to see Cisco simplify the management and deployment experience, improve automation, and provide more flexible and cost-effective licensing while maintaining its strong security capabilities.
What do I think about the stability of the solution?
Yes, based on my experience, Cisco Secure Firewall is very stable and reliable. I have deployed it for more than 20 customers across the Middle East and other locations, including hospitals, hotels, airports, and shopping malls.
I have not experienced any major firewall crashes or recurring stability issues in these deployments. The platform has been reliable across different environments and use cases, including high-availability and enterprise deployments.
From my experience, stability and reliability are among the strongest points of Cisco Secure Firewall. With proper sizing, configuration, and maintenance, I have found it to be a dependable platform for critical network environments.
What do I think about the scalability of the solution?
Cisco Secure Firewall is highly scalable when it is properly sized with future growth in mind. In many projects, we recommend sizing the firewall with around 50% capacity reserved for future growth, depending on the customer's requirements and budget.
Cisco's newer firewall models also provide flexibility to upgrade interface and connectivity capabilities, such as moving from 10G to 25G, 40G, or 100G, depending on the specific model and available options.
However, scalability ultimately depends on selecting the right model and configuration from the beginning. If a customer selects a firewall based only on current requirements due to budget constraints, they may face performance or interface limitations as the network grows.
Overall, Cisco Secure Firewall provides good scalability, but proper initial sizing and planning for future capacity are critical.
How are customer service and support?
I would rate Cisco TAC support 9 out of 10 based on my experience.
I regularly work with Cisco TAC, particularly when upgrading Cisco Secure Firewall to a latest stable release. For example, during our airport operations and maintenance projects, we open a TAC case before the upgrade and work with a Cisco engineer throughout the process. After the upgrade, we validate the firewall policies, rules, and overall functionality before closing the case.
Overall, Cisco TAC engineers are knowledgeable and effective, especially when dealing with complex issues. However, my experience over the last two to three years has been that the quality and speed of support can vary depending on the engineer assigned to the case. Sometimes the initial engineer requires multiple rounds of log collection and escalation before the issue reaches a senior engineer who can resolve it quickly.
For this reason, I would give Cisco TAC 9/10. The technical capability is strong, but faster access to experienced engineers and more consistent support quality would make the service even better.
What other advice do I have?
I would rate Cisco Secure Firewall 10 out of 10 overall. I have hands-on experience sizing and configuring Cisco Secure Firewall through CCW based on customer requirements, and I also compare it with solutions from other vendors.
Cisco Secure Firewall is a stable and reliable platform with strong build quality and good hardware support. With the appropriate Smart Net service, hardware replacement can also be very fast when required.
From a sizing perspective, Cisco provides a good range of throughput and interface options, although comparable firewalls from other vendors may offer more interfaces at a similar price point..
My advice to organizations is to consider Cisco Secure Firewall when reliability, enterprise integration, security capabilities, and long-term support are priorities. However, customers should carefully evaluate sizing, licensing, interface requirements, and total cost against competing solutions before making the final decision.
Unified security policies have protected hybrid workloads and support zero trust access
What is our primary use case?
I have been working with Cisco Secure Firewall for almost nine years, and I want to share my experience with this solution.
I have been working with both the on-premises and cloud versions of Cisco Secure Firewall.
The choice between deployment models depends on the use cases. For on-premises use cases, I deploy an on-premises firewall, but for workloads that are based on the cloud, I use the cloud-based firewall.
What is most valuable?
Cisco Secure Firewall has very good IDS and IPS capabilities, as well as excellent threat intelligence features, which are some of the best aspects of the product that I appreciate.
It actually helps with integration by allowing me to integrate different solutions within one platform.
What needs improvement?
I am not currently experiencing many drawbacks with Cisco Secure Firewall. However, since things are migrating to the cloud, the product needs to be more optimized for cloud environments.
Recently, AI-initiated threats have emerged, so Cisco Secure Firewall should have enhanced capabilities to counter AI threats.
For how long have I used the solution?
I have 22 years of overall experience working in the software field.
How was the initial setup?
The deployment for the product was not quite simple, but it was acceptable. I received support from Cisco during the process, so the overall experience was good.
I would rate the technical support from Cisco at an eight out of ten, with ten being the best.
What about the implementation team?
I was assisted by a third party with the deployment.
I handle both the deployment and operations, so I personally participated in the deployment process.
What's my experience with pricing, setup cost, and licensing?
The price for Cisco Secure Firewall is a bit high compared to other vendors.
Which other solutions did I evaluate?
Cisco Secure Firewall helps with a Zero Trust security model, and I am implementing a ZTNA access model. I have already implemented Zero Trust. Other vendors besides Cisco also provide ZTNA solutions. Fortinet and Palo Alto are all working with ZTNA and have moved into the ZTNA platform.
What other advice do I have?
I would assess Cisco Secure Firewall's ability to unify different policies across my environment.
Zero-trust security has protected critical banking applications and supports AI-driven incident response
What is our primary use case?
As a bank, I serve as the Chief Technology Officer at one of the largest banks in Pakistan, UBL, United Bank Limited, and we have Cisco Secure Firewall deployed at the bank in the data center. We apply unified policies across the environment because we have two data center core firewalls running at the production as well as DR site.
What is most valuable?
Cisco Secure Firewall, especially the next generation FTD firewalls, offers application visibility, the intrusion prevention system, advanced malware protection, Snort rules, and threat intelligence feed from Cisco's Talos cloud, which I find very useful.
Cisco Secure Firewall has provided us the ability to go a long way towards zero-trust architecture, which is useful in implementing because zero-trust architecture has many more features such as multi-factor authentication, encryption, and segmentation. We have integrated Cisco's ACI, the Application Centric Infrastructure, the software-defined networks with Cisco Secure Firewall to achieve micro-segmentation and a good, fair bit of zero-trust architecture.
We are using Cisco's XDR platform, which was previously labeled as Cisco SecureX. We have been using the Cisco XDR, Extended Detection and Response platform for the last two years, integrating Cisco Secure Firewall, Cisco Stealthwatch, Cisco Umbrella service for secure DNS, as well as Cisco endpoints with the XDR platform. We have onboarded Cisco's MDR service, Managed Detection and Response service onto the XDR platform.
It has a very useful impact on productivity because when we integrate our ecosystem with the XDR platform, it operates on the AI algorithm, correlating and analyzing incidents for severity level by the AI algorithm, which gives the severity of the incident as well as eliminates false positives and provides it to the SOC level two analyst to contain or remediate the incident. This is a good feature and has automated somewhat the first level of incident response.
What needs improvement?
I am looking forward to Cisco for providing AI detection capability so that we have defenses against AI-assisted cyber attacks.
As I mentioned, I am looking forward to Cisco for providing AI-assisted defenses because nowadays there is a lot of AI-assisted attacks. Traditional or even next-generation firewalls would not go a long way as far as defense is concerned, and I think every other vendor such as Palo Alto, Fortinet, and Sophos are working on improving the firewall with respect to AI-assisted attacks, which is what I expect from Cisco as well.
Presently, I am looking for AI features. I do not see any other feature because we are already using advanced malware protection and IPS and application visibility, threat intelligence feeds, and AI would probably be a good addition to the portfolio.
For how long have I used the solution?
I have been dealing with Cisco Secure Firewall for quite some time.
What do I think about the stability of the solution?
I am satisfied with Cisco Secure Firewall in our organization.
What do I think about the scalability of the solution?
As the organization grows year by year, I believe it is scaling very well concerning the growth of the organization, the number of branches, the number of users increasing, and the applications scaling out. It is scaling out as per the requirement.
How are customer service and support?
I would rate the technical support by Cisco as eight or nine.
Which solution did I use previously and why did I switch?
I included Palo Alto and Fortinet firewalls in our RFP process before opting for Cisco, but I believe for data center firewalling, Cisco is best suited amongst its competitors.
How was the initial setup?
The deployment was very seamless because we have our own team in the bank for deployment, and we also took professional services when we deployed Cisco Secure Firewall. I do not think that we faced any challenges or hiccups during the deployment.
What about the implementation team?
We have a team of ten to twelve people, but they are not only looking after Cisco Secure Firewall; they are looking at the security posture of the bank, including endpoints and file integrity manager, and MDR. I think two people would be the right, appropriate number looking after Cisco Secure Firewall.
What's my experience with pricing, setup cost, and licensing?
The price is reasonable and it is competitive and affordable. It is from Cisco's authorized partners in Pakistan.
What other advice do I have?
The deployment was very seamless because we have our own team in the bank for deployment, and we also took professional services when we deployed Cisco Secure Firewall. I do not think that we faced any challenges or hiccups during the deployment.
Whenever the traffic comes to the server farm and whenever a user accesses the application, we have one hundred twenty-five applications behind Cisco Secure Firewall, and it is almost all the bank which is using Cisco Secure Firewall. If I can give an exact number, probably we have thirty-one thousand employees in the bank, and all their applications are hosted behind Cisco Secure Firewall. I rate this product nine out of ten.
Security policies have supported complex integrations and now manage diverse global access
What is our primary use case?
Regarding the implementation of Cisco Secure Firewall, I imagine that my colleagues from the security department and networking have a lot of complex configurations based on the requirements that we need.
We have an EVID ecosystem, and this implies very different kinds of configurations and rules.
There are general rules, and then there are some specific rules based, for example, on users that are in different geographies, accessing different applications, and with different needs and requirements in terms of security.
There are the back-end applications that must communicate between them and with external partners. There is also another integration complexity that my colleagues must face.
Currently, I am working with some multivendors, for example, with Salesforce, Microsoft Dynamics, EVM DataPower, OpenAI, and Anthropic. I think I could miss other providers, but basically, these are the ones.
What is most valuable?
My organization benefits from utilizing Cisco Secure Firewall. I do not know the details of everything, but I hope my colleagues do a great job and Cisco Systems could help us to identify any of these constraints that could exist.
What needs improvement?
I cannot tell you about any drawbacks, downsides, or weak points of Cisco Secure Firewall which I would eliminate because I cannot respond with clarity.
I know there are known vulnerabilities in every system that we know, but I do not know in particular one that I could specify. If I worked with it on a daily basis, I could be more clear. Right now, I do not know.
For how long have I used the solution?
I have been working in my organization with Cisco Secure Firewall for a long time; I started on this project ten years ago, then I returned in two thousand and twenty-one. It has been Cisco since then.
Which solution did I use previously and why did I switch?
I have not tried or used the solution within the last twelve months period because I use Apache but I'm not using it now.
I have used it for a long time, three or four years, but now I am not using it. Since, I think, three years, four years approximately.
What other advice do I have?
I believe I am not familiar with the product Secure Cloud Protection for Salesforce. I don't know because I am working with the integration and also with the Salesforce component integrations between Salesforce and billing and invoicing platforms.
In terms of security, I must comply with the guidance of the corporation that I am in.
In terms of security, it is another area. We need to only comply and be compliant with the guidance and requirements that they demand.
I would rate this review an eight out of ten.
Central management has unified security policies and supports consistent enterprise protection
What is our primary use case?
I work with both the on-premises and cloud versions of the solution, as well as the SaaS version, for clients.
What is most valuable?
What makes Cisco Secure Firewall appealing to customers is that all the features are the same across all firewalls, but customers appreciate that it is a stable solution and more secure. There are not as many security breaches as with Fortinet, and that is the reason why they often choose Cisco firewalls because of the stability of enterprise-level cybersecurity protection and overall position in the market.
I have used new features recently in Cisco Secure Firewall, including AI support and AI central management, which is the latest feature from Cisco central management that allows me to manage all those appliances and firewalls centrally, also with some AI agents and chats and some additional regression features.
The integration of the SecureX feature has helped my productivity and response time, but I need to ask colleagues about this since they are more involved in this.
I assess the product's ability to unify and consolidate policies across my environment as quite straightforward and easy to do with this central management console.
What needs improvement?
In Cisco Secure Firewall, I have come across some drawbacks, downsides, or weak points, specifically that for some of the solutions or services, the user interface is not as great or lately updated as it should be; it looks old-school.
For how long have I used the solution?
I have known Cisco Secure Firewall for more than five years, but it is not my top product. I am partially working with it.
How are customer service and support?
Regarding Cisco technical support, I have communicated with them, and they are helpful and responsive. I rate them eight out of ten. It is a standard procedure, and I do not have any problems with it.
How was the initial setup?
The implementation of Cisco Secure Firewall is more or less straightforward. I have not encountered any problems lately or at all.
It takes a couple of days, I would estimate, usually to deploy the product. However, this depends on the configuration.
What about the implementation team?
I need more or less one or two people involved in the implementation process, depending on some additional services. When I am talking about the firewalls only, I could do it with one person, but if there are some additional cybersecurity services connected, then I could add some additional specialists.
What other advice do I have?
I am using Cisco SecureX with Cisco Secure Firewall in some cases.
My evaluation of Cisco Secure Firewall in helping my organization implement a Zero Trust security model is that it functions more or less as a marketing abbreviation, but Cisco has all the features and configuration possibilities to implement Zero Trust out of the box. We have seen some cases when we combine it with Cisco Duo to achieve the highest level of Zero Trust access to devices and also to firewalls.
In terms of price, Cisco Secure Firewall is appealing for many in the enterprise segment, though for many customers it is too expensive. However, for customers in enterprises or at large corporations, the price is acceptable, depending on whether the customer is a small-medium business or enterprise. It is positioned more for enterprise customers.
I rate this product eight out of ten overall.
Secure access has protected company data and supports fast VPN work from office and home
What is our primary use case?
My main use case for Cisco Secure Firewall is as a security program, and I am using it to establish VPN connections. We are logging into this system to protect all information.
For a quick specific example of how I use Cisco Secure Firewall in my daily work, we log into this program every day using a specific network. I use my company email and a password to access this program, allowing us to use all the systems and programs in the credit and collections area.
Cisco Secure Firewall serves as the main security tool I use nowadays, primarily to protect information, the systems, and all the facts about the company.
What is most valuable?
In my opinion, the best features Cisco Secure Firewall offers are its speed, as it is one of the quickest and most secure systems I have used during the pandemic period. I have had the opportunity to try different systems to protect or log in at work, and this is one of the quickest and greatest systems available.
Cisco Secure Firewall has positively impacted my organization by providing a quick and easy program to log into the VPN, which is very effective. I do not have troubles or issues with the connection, and I believe that is the most important aspect of this program.
What needs improvement?
I think the system is quick with two steps to log into the security program. I am satisfied with how it works right now, and I have not noticed things that I want to be different with Cisco Secure Firewall.
For how long have I used the solution?
I have been using Cisco Secure Firewall for one full year.
What do I think about the stability of the solution?
I think Cisco Secure Firewall is very stable. I have experienced one or two issues during my usage this year.
What do I think about the scalability of the solution?
Cisco Secure Firewall's scalability is good for my organization right now. We have a hybrid mode to work, and it is a very efficient program for the company.
How are customer service and support?
I have not needed to reach out for help regarding Cisco Secure Firewall. I believe the issues are more about the network or internet connections than Cisco Secure Firewall itself.
Which solution did I use previously and why did I switch?
I did not evaluate other options before choosing Cisco Secure Firewall.
What's my experience with pricing, setup cost, and licensing?
I do not have a clear idea about the pricing, setup cost, or licensing for Cisco Secure Firewall, as I am not an IT employee and do not have information about licensing. I am only a user.
What other advice do I have?
I think the end-to-end visibility from Cisco optimizes the experience in a hybrid setup.
I face specific challenges with hybrid and distributed enterprise networks, particularly feeling a little insecure when working from home. Cisco Secure Firewall is a great option because it provides a quick and secure program, allowing me to confidently access the company's systems.
My advice for others looking into using Cisco Secure Firewall is that it is a quick security program, helping you connect from various places, such as the office, coffee shops, or home. You could try other methods to access the security system, like voice approval or other specific options.
I would rate this product a 9 out of 10.
Firewall has delivered clear visibility and has simplified secure internet protection
What is our primary use case?
Cisco Secure Firewall serves as our primary internet firewall.
What is most valuable?
I appreciate the ease of use most about Cisco Secure Firewall. The end-to-end visibility offered by Cisco Secure Firewall is excellent, and I have no issues with any of the products. I assess the operational efficiency of Cisco Secure Firewall in my IT environment as positive because I value Cisco products and advocate for them whenever I can.
What needs improvement?
The only area that can be improved is related to Cisco Secure Firewall Management Center, as certain versions are not always stable, which has been our only issue.
For how long have I used the solution?
I have been using Cisco Secure Firewall for twenty years.
What do I think about the stability of the solution?
I assess the stability and reliability of Cisco Secure Firewall as good; it is rock solid for me.
What do I think about the scalability of the solution?
I am uncertain about the specific challenges I face with hybrid distribution, especially regarding hybrid and distributed enterprise networks that Cisco Secure Firewall addresses.
How are customer service and support?
I evaluate customer service and technical support at a ten on a scale of one to ten, with ten being the best.
Which solution did I use previously and why did I switch?
I have used Cisco Secure Firewall throughout my career.
How was the initial setup?
I would describe my experience with deploying Cisco Secure Firewall as positive because there is extensive documentation and support available, making the deployment very straightforward.
Which other solutions did I evaluate?
I have never considered anything other than Cisco Secure Firewall; I would never switch.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Security intelligence has protected sensitive workloads and reduced endpoint incident impact
What is our primary use case?
My main use cases for Cisco Secure Firewall vary between branch office, remote connectivity for site-to-site tunnels, partner organizations that we want to connect and share information with, and also protecting internal sensitive workloads and providing secure access to the internet.
What is most valuable?
The features that I appreciate most about Cisco Secure Firewall include the security intelligence that is incorporated into it. Not only can I rely on information coming directly from Cisco from everything they see across all their customers, but I am also able to use many of the same underpinnings they have built out to incorporate information from other sources.
These features have benefited my organization significantly. For example, they certainly reduce the risk impacting endpoints because if something arises where we have a device reaching out to something that presents a risk, that intelligence helps with assessing and blocking that communication. This way, we do not have as high of an impact for a potential incident that we need to clean up.
What needs improvement?
I assess the operational efficiency of Cisco in my IT environment as needing some optimization, but at least some of the tools are incorporating AI to help with finding opportunities for optimization to make the product perform better.
My impression of the end-to-end visibility offered by Cisco is that there are certainly many different options available, and not everyone can afford to have everything in the Cisco portfolio to incorporate all of that to get full visibility. However, from the portfolio suite, there is certainly a lot there to enable customers to have visibility.
My experience with deploying Cisco Secure Firewall has had the biggest challenges in relation to device clustering. Having edge deployment scenarios where you have high connection counts, high user counts, and a need for high availability and load balancing across that has been very complicated to set up correctly. Even when it is set up correctly, there are still times when I have a firewall cluster experiencing issues that require opening a TAC case. This is frustrating considering the solution has been in place for years and suddenly starts to have issues, even when everything looks completely healthy in the health dashboards.
If I could give Cisco Secure Firewall a 12, I would. I rate it as an eight. It still has some growing pains, especially trying to combine two different product lines with Snort and Cisco ASA. Not having feature parity across the entire gamut yet is still a pain. On the software side, you still have to understand the engineering behind it, particularly how the product works at the different layers, because it is not necessarily one cohesive product base yet. It is still multiple components stacked on each other.
For how long have I used the solution?
I have been serving the same customer for 26 years using Cisco Secure Firewall with my latest company.
What do I think about the stability of the solution?
I assess the stability and reliability of Cisco Secure Firewall as having been fairly reliable. When there are issues, it is easy enough for us to engage with TAC and replace hardware quickly.
What do I think about the scalability of the solution?
From my perspective, many of the issues that presented a challenge have already been addressed or will be addressed soon with Cisco Secure Firewall, such as decrypting certain types of traffic like QUIC, which has traditionally been a challenge. With no solution there previously, you were having to outright block that traffic, which does cause an impact. Cisco is taking the right steps to help make those issues less impactful when they do arise. I do not have anything that comes to mind that I would say needs to be addressed urgently.
How are customer service and support?
I evaluate customer support and tech support as excellent, and I would rate it as a very high number on a scale of one to ten. There were a few years, especially following COVID, where it was very challenging even for severity three incidents that we had open where it would take up to a month to have some initial contact, which was very disheartening. However, now with that same level of severity, you are getting a callback within 30 minutes. My most recent case that I had to engage on, the engineer went way above and beyond what I had asked for, and I was very happy with the support that they have given us.
Which solution did I use previously and why did I switch?
Prior to adopting Cisco Secure Firewall, I have always had Cisco firewalls in the environment across my entire tenure. It has never been a complete rip and replace. We did have a point in time where at the edge we had Check Point firewalls. They worked well, but when it came time for replacement, we put Check Point against Cisco and Cisco won out, which I was happy about because I prefer Cisco.
How was the initial setup?
My experience with pricing, setup, and cost licensing is that cost is always an issue for everyone. I think it has gotten easier, especially when it comes to larger customers with enterprise agreements. For example, my organization, while we have 5,000 users and around 18,000 endpoints, there was a time when we were considered not big enough to take advantage of an enterprise agreement. Considering the amount of product that we buy, that was a bit disheartening. But now, with more flexible options for purchasing and enterprise agreements, it has made it easier for us to not only purchase product but also have a clear idea of what we are allowed for growth and have something that is predictable for the cost of that management piece. Cisco has done a really good job with that.
What other advice do I have?
I really do not face any specific challenges with hybrid and distributed enterprise networks that Cisco addresses at the moment, so it does not really apply to us. I rate Cisco Secure Firewall as an eight out of ten.
Firewall has improved internal VM performance and simplified hybrid infrastructure management
What is our primary use case?
My main use for Cisco Secure Firewall is primarily for our internal VMs and similar infrastructure.
What is most valuable?
What I like the most about Cisco Secure Firewall is that it performs better than our previous product. We had a lot of latency issues and general problems with our previous solution, but this firewall functions much better.
Cisco optimizes the experience by providing a single pane of glass for our GUI and firewall management, which is probably the best feature.
I assess the operational efficiency of Cisco in my IT environment as very strong, as it integrates well with most of our existing infrastructure since we are already a Cisco shop.
Cisco does optimize the experience in a hybrid or distributed enterprise setup.
What needs improvement?
I evaluate customer service and technical support as quite good. The documentation could use some improvement overall, as there are some errors in it. However, when we interact with support personnel and the AI agent, the experience is usually very good.
For how long have I used the solution?
I have been using Cisco Secure Firewall for about six months, having received our firewalls during that time.
What do I think about the stability of the solution?
I have not experienced any downtime or crashes.
What do I think about the scalability of the solution?
Cisco Secure Firewall scales well with the growing needs of my organization and certainly scales beyond what we needed.
How are customer service and support?
I evaluate customer service and technical support as quite good. The documentation could use some improvement overall, as there are some errors in it. However, when we interact with support personnel and the AI agent, the experience is usually very good.
Which solution did I use previously and why did I switch?
Prior to Cisco, we were using a few different options, but much of our infrastructure was Grandpea and Upsense.
How was the initial setup?
Deploying Cisco Secure Firewall was as painless as swapping an internal firewall can be.
What was our ROI?
I have seen ROI mainly because our firewall runs our internal infrastructure, and we offer some services behind it, so overall, I would say the ROI is positive.
What's my experience with pricing, setup cost, and licensing?
My experience with price, setup costs, licensing, and related factors was beyond my direct involvement, but I know it came down to a deal that included other products. Overall, we were very happy with the arrangement.
Which other solutions did I evaluate?
What stood out to me during the evaluation process was that choosing Cisco made sense primarily because we are already a Cisco shop and are familiar with their sales representatives, products, and dashboards.
What other advice do I have?
I give Cisco Secure Firewall an overall rating of eight out of ten.
Secure connectivity and custom threat detection have protected hybrid environments and user activity
What is our primary use case?
I have two different perspectives about my use cases for Cisco Secure Firewall. The first one is the device frontier, creating all the connections between on-premise, cloud, on-premise to on-premise, VPNs, NAT and also rules for secure endpoints or user endpoints for downloading malicious files or visiting different websites.
The other use case was threat intelligence, which I mostly used Snort rules or created Snort rules on the firewall to understand or catch early attackers before they started the attack.
What is most valuable?
Snort is one of the features of Cisco Secure Firewall that I know is an open-source rule, but it is really cool that the firewall allows you to create your own rules using this protocol for threat intelligence.
The flow of Cisco Secure Firewall is something that I have a lot of experience creating policies with, but the way the policies work is unusual. For example, they are using every single policy that cascades between each other, and other vendors do not use that kind of flow. Other vendors allow you to create one rule for a specific thing without needing to iterate something from another policy. That is something I do not dislike, but it is hard to work with that kind of flow.
What needs improvement?
As I mentioned, Cisco Secure Firewall's flow is easier with Palo Alto to create things and configure things, also with the policies. But this vendor does not have the possibility for Snort, so I need to work with what the vendor gives to me and it is not really free to use. On the basic configurations and day-to-day tasks that we are having using this tool, it is much easier to use Palo Alto than Cisco Secure Firewall. Cisco has the feature that is Snort, but it is more easy to use Palo Alto in general.
Compared to the license of Cisco Secure Firewall, it was expensive. Right now compared with Palo Alto, Cisco Secure Firewall is kind of expensive. Basically, the license for the VPNs is for all the interfaces, and that is the thing that is really expensive compared with Palo Alto.
For how long have I used the solution?
I am not using Cisco Secure Firewall too much now because I left my previous company, but in previous companies I worked with Cisco Secure Firewall for four to five years.
What do I think about the stability of the solution?
There was basically one downtime with Cisco Secure Firewall that was for a DDoS attack. I think that it was due to a bad configuration from our side. Without those configurations, there were no issues. I would say that the product is pretty much stable and the issue was our fault.
What do I think about the scalability of the solution?
Cisco Secure Firewall is scalable, but if you have the money for the license, then it is scalable.
How are customer service and support?
I have had to contact Cisco technical support two times. One time was to integrate the firewall with the WLC, Wireless LAN controller, for wireless issues, and the other time was for the license that was not activated due to something that happened with the payments.
The first case on the WLC for Cisco Secure Firewall was not very good because it took more than one week with the first call and emails back and forth to resolve the issue. The answers from the technical assistance center gave me the sense that they did not really know what we needed to do or what we needed for escalations. On the other hand, for the payment issues for the license, that team was really clear and resolved the issue in less than 12 hours.
With my experience with those two support cases, I would rate Cisco technical support a seven on a scale from one to ten.
Which solution did I use previously and why did I switch?
I have experience with Cisco in two parts. I worked with Cisco as the SM for one of the companies in Colombia, and I have also worked with other customers that use Cisco. I have been on both sides.
How was the initial setup?
There are two ways for the initial deployment of Cisco Secure Firewall. We have the on-premise device, when I was working in that company, and we also deployed one of the solutions for Threat Defense on Azure. I think that it is easier for on-premise because you have direct connections, and if something happens troubleshooting all the initial IPs is better that way. It is pretty smooth to update it or create that firewall on Azure. On AWS, it is easy. They have some troubles with the Linux instance, but on Azure, it is pretty smooth.
What about the implementation team?
Cisco Secure Firewall is all about taking care for Cisco right now. Previously it was not, but right now it is.
What's my experience with pricing, setup cost, and licensing?
Compared to the license of Cisco Secure Firewall, it was expensive. Right now compared with Palo Alto, Cisco Secure Firewall is kind of expensive. Basically, the license for the VPNs is for all the interfaces, and that is the thing that is really expensive compared with Palo Alto.
Which other solutions did I evaluate?
I have used Fortinet and Palo Alto as alternatives to Cisco Secure Firewall.
It is hard to say, but right now I have been working with Palo Alto. That is currently my best option and I learned a lot from this vendor compared to Cisco Secure Firewall.
What other advice do I have?
I have experience with Cisco in two parts. I worked with Cisco as the SM for one of the companies in Colombia, and I have also worked with other customers that use Cisco. I have been on both sides.
The last time with Cisco I was a partner.
My overall review rating for Cisco Secure Firewall is nine out of ten.