Cisco Adaptive Security Appliance (ASA) software is the core OS for the ASA suite. It provides firewall functionality, as well as integration with context-specific Cisco security modules. It is scaled for enterprise-level traffic and connections.
N/A
Cisco Secure Firewall
Score 8.0 out of 10
N/A
Cisco Secure Firewall delivers comprehensive threat protection for modern, distributed networks. Built to support hybrid workforces and multicloud environments, it enables Zero Trust access, application visibility, and secure remote connectivity. With integration across the Cisco Secure portfolio, including SecureX and Talos threat intelligence, the firewall powers organizations to detect and stop more sophisticated threats. Centralized management simplifies policy enforcement, orchestration,…
Cisco Secure Firewall aka Firepower has a more visibility than the ASA, specially with use of FMC. The Secure Firewall also adds a lot of security features, with IPS, IDS, AVC, Security Intelligence, Identity Mapping and so on.
We moved our operations entirely to the cloud a few years ago. We loved the stability and scalability of the ASA and wanted to, somehow, keep using it. We discovered that ASA was available in the cloud as well and it was branded ASAv. We tested it and noticed that it was equally robust and a perfect fit for us. During the entire migration period, we used ASAv for cloud operations and put a lot of load on it. ASAv performed very well and gave us an easy transition from on-prem to the cloud.
The software offers advanced firewall solutions from Web threats management to behavioural analytics and comprehensive application security. Cisco Secure firewall software is incredibly easy to deploy and implement. Customer support services providers are concise and very responsive. Integration and customization of the software are exceptional. The product boasts impressive capabilities, enabling it to stop threats and manage all security flaws in real time.
It's good at segregating networks and ensuring that you only give the access that you need to give. Especially with medical devices, you want to only give the access that they need and keep them in their own separate areas so that they can't just communicate with the rest of the network. It's also good at the border for keeping attackers out of the network.
The Java based ASDM can botch commands and isn't compatible on some more locked down systems.
Monitoring. Really the same complaint as above, the monitoring available through the ASDM is crappy at best. A much better solution is to send the logs and mirror packets to a SEIM, but that can create issues of its own when looking for realtime analysis.
Compatibility across other ASA models. ASA 5520s don't play well with 5525X which don't play well with older 5510s. Each is great on it's own, but it's next to impossible to logically stack them or have them as layers of firewalls in an infrastructure.
Lack of cloud based management. The Cisco Meraki security devices do this well, but the ASAs are still behind in this regard.
I have one argument, failover scenario. It's not quite easy. Failover scenario of firewalls. It's sometimes not quite easy to know the issue. But if we open a tech case, a technical case to Cisco, Cisco will help us, it's a little bit con, but we are happy with this product.
To be honest there has been now great products out in the market compared to Cisco ASA. I beleieve Cisco has to do a lot of improvement in this area. The other defeiniete factors is the cost when it comes to renewals which is always a premium on Cisco products
It works really well. We can do most anything we want or need to with it, and you don’t have to have a doctorate or multiple certs to necessarily figure it out. The thing that would probably have to happen to make us switch would be if we just got priced out - Cisco’s more powerful and higher bandwidth models cost a pretty penny.
The platform is powerful and feature-rich, especially when paired with tools like Firepower Management Center (FMC) and SecureX. The policy structure is logical, and the visibility into traffic flows, threat activity, and rule hits is quite strong once you're familiar with the interface
I generally have not noticed the outages, however since it's a machine it can malfunction, we need to implement the firewall infrastructure in such a way that it is highly available with device failure, region failure etc. Else any solution will be having the issues if they are not build with resiliency.
As for the availability, in general we did not experience any issues with it, neither in situations where there's only one physical device implemented nor when there's and High Availability pair. Failover works like a charm, no complaints here, it works as it should and so far it has been highly reliable.
The support is usually very good and gets back to you very quickly. However I had some instances of when two engineers will give me wildly different answers to what I thought was a simple question. Overall however I do rate the support highly and they are generally always very good.
Our experience with Cisco TAC support for Cisco Secure Firewall has been very good. The support engineers are knowledgeable about the product and have many tools available to them to work "under the hood" of the firewalls or management center. When we've had equipment failures, the RMA process has been simple and straightforward.
was a good training but questions was answered not so good. Training was "Fundamentals of Cisco Firewall Threat Defense and Intrusion Prevention (SFWIPF)".
It was quite a good one, how ever requires an expertise to deploy hence the SMB segment would be finding it difficult to implement this product. The one good reason is that there are lot of ASA certified engineers in compared to the other certified engineers. Hence this resembles positively on the deployment as you have quite a lot of experienced engineer on your deployment
Our initial implementation was aided by Cisco's professional services and was excellent. The engineer was very knowledgeable and helped us work through issues while building out our new internet security edge Part of this involved tools to migrate the firewall configuration from old to new.
Cisco has made it easy to buy, set up, and manage all of our firewalls with the central FirePower Management Center. All licensing is done via one license portal too. Tech support is standardized for all ASA devices and like support engineers who know the different models to provide timely help for any issues. Cisco Talos is a premier could platform which scours the internet looking for threats and develops protections for the ASA's and as such provides zero second coverage when it best can detect global issues.
Cisco Secure Firewall works better with the Cisco ecosystem when we can utilize it and feels beefy enough when we utilize it in the data center. The Fortinet we have found are great, small cost boxes for remote offices with a better UI then Cisco Secure Firewalls. The feature set included with the firewalls feels similar from a security point of view.
The 5510 is still being used in one of our setups, and still doing its job this is a lot of Return on Investment.
We have managed to turn around projects quickly because most of our engineers understand this firewall very well. We deploy them in a matter of minutes[.]
Cisco Secure Firewall gives details on the possible intrusions attempts that are occurring on the network, which gives stakeholders confidence that the network is being protected.
Cisco's reputation as a longstanding network leader provides the trust that is needed in keeping networks secure.
The wide variety of tools and features that Cisco Secure Firewall provides allows business owners to plan for changes that can occur in the network as Cisco is able to adapt to the different needs.