Cisco Adaptive Security Appliance (ASA) Software vs. pfSense

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Cisco Adaptive Security Appliance (ASA) Software
Score 9.0 out of 10
N/A
Cisco Adaptive Security Appliance (ASA) software is the core OS for the ASA suite. It provides firewall functionality, as well as integration with context-specific Cisco security modules. It is scaled for enterprise-level traffic and connections.N/A
pfSense
Score 9.9 out of 10
N/A
pfSense is a firewall and load management product available through the open source pfSense Community Edition, as well as a the licensed edition, pfSense Plus (formerly known as pfSense Enterprise). The solution provides combined firewall, VPN, and router functionality, and can be deployed through the cloud (AWS or Azure), or on-premises with a Netgate appliance. It as scalable capacities, with functionality for SMBs. As a firewall, pfSense offers Stateful packet inspection, concurrent…
$179
per appliance
Pricing
Cisco Adaptive Security Appliance (ASA) SoftwarepfSense
Editions & Modules
No answers on this topic
SG-1100
$179
per appliance
SG-2100
$229
per appliance
SG-3100
$399
per appliance
SG-5100
$699
per appliance
XG-7100-DT
$899
per appliance
XG-7100-1U
$999
per appliance
XG-1537
$1,949
per appliance
XG-1541
$2,649
per appliance
Offerings
Pricing Offerings
Cisco Adaptive Security Appliance (ASA) SoftwarepfSense
Free Trial
NoNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
Cisco Adaptive Security Appliance (ASA) SoftwarepfSense
Considered Both Products
Cisco Adaptive Security Appliance (ASA) Software
Chose Cisco Adaptive Security Appliance (ASA) Software
We were using pfsence before [the] Cisco ASA firewall and we were not happy with pfsense features. Lots of features are missing in pfSence so we decided to install the [Cisco] ASA 5525 and we are very happy with the features. There are lots of options in nat and you can easy to …
Chose Cisco Adaptive Security Appliance (ASA) Software
The company has been using Cisco Adaptive Security Appliance (ASA) Software for more than 10 years, for the support team its operation is simple, so even though Palo Alto has more functions, we would have a certain cost of investment and time in training the entire team, or we …
Chose Cisco Adaptive Security Appliance (ASA) Software
Integration with Cisco Ecosystem, Cisco Adaptive Security Appliance (ASA) Software integrates smoothly with other Cisco security products and networking solutions. We have already invested in Cisco networking equipment and infrastructure which is why we chose Cisco Adaptive …
Chose Cisco Adaptive Security Appliance (ASA) Software
I've used the Firepower to a small extent. It's way better. It does up to layer seven. It does a lot more inspection. It does URL filter. It does IPS, it does antibody, it does all the things that the ASA doesn't do.
Chose Cisco Adaptive Security Appliance (ASA) Software
Cisco has made it easy to buy, set up, and manage all of our firewalls with the central FirePower Management Center. All licensing is done via one license portal too. Tech support is standardized for all ASA devices and like support engineers who know the different models to …
Chose Cisco Adaptive Security Appliance (ASA) Software
The ASA led the pack for our use case since we were familiar with it and the ASA (and ASAv) was able to integrated with our environment very easily. We were also able to apply MFA to the ASA with very little effort, further improving our posture. In comparison, other tools were …
Chose Cisco Adaptive Security Appliance (ASA) Software
This was selected due to our organization standard and our branch office is using ASA. Integration with the same product is really a good option with ASA.
Chose Cisco Adaptive Security Appliance (ASA) Software
We moved from older ASAs to Firepower and were excited to see the new features and higher reliability. Throughput is faster and as our old ASAs were breaking down intermittently it was time for the upgrade. The newer GUI has a better dashboard and is easy to maneuver in, easier …
Chose Cisco Adaptive Security Appliance (ASA) Software
We will be moving to firepower in the next update
Chose Cisco Adaptive Security Appliance (ASA) Software
I am a CCNP and will always go with Cisco because they are more affordable than Palo Altos and yet they do the same job and easy to deploy.
Chose Cisco Adaptive Security Appliance (ASA) Software
Configuration and management of Cisco's ASA are straightforward. We chose Cisco ASA for many reasons, as well as Cisco's threat response reports. We previously had issues with Sophos UTM due to its poor performance. We no longer have to be concerned about performance issues …
Chose Cisco Adaptive Security Appliance (ASA) Software
Palo Altos blow Cisco ASAs away in terms of form and function. They are next-generation firewalls that have very advanced rule sets and AI to help protect your cooperation; however, they are also about 20 times more than a comparable Cisco ASA firewall.
Chose Cisco Adaptive Security Appliance (ASA) Software
Palo Alto Networks Next-Generation Firewalls - PA Series, Palo Alto Networks Prisma Access, Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series, Palo Alto Panorama, Sophos SG Firewall Appliances, Sophos UTM, Sophos XG Firewall, Cyberoam, SonicWall NSA Series …
Chose Cisco Adaptive Security Appliance (ASA) Software
Fortinet and SonicWall firewalls are not without their own unique merits, but Cisco ASA devices are our go-to devices for all of our clients' firewall needs. We have found creating and keeping VPN tunnels established is much easier on a Cisco ASA device.
Chose Cisco Adaptive Security Appliance (ASA) Software
Cisco ASA is doing well, has [a] lot of documents available, [and easy] implementation, however, other vendors are also very easy to deploy. Cisco ASA has [a] great support team. Cisco ASA is truly [a] next-generation product. Now it is cloud-managed, along with zero-touch …
Chose Cisco Adaptive Security Appliance (ASA) Software
We have never used any other firewall. This is the first firewall in our organization and we are very happy with its features and technical support. [Cisco ASA] is easy to configure and we never face any downtime with it.
Chose Cisco Adaptive Security Appliance (ASA) Software
We have a small network so we were using clearos for security but this firewall is just a basic functionality so we decided to change and installed the Cisco ASA firewall. Cisco ASA provides us lots of features like NAT, routing, as well as security features for protecting our …
Chose Cisco Adaptive Security Appliance (ASA) Software
We were not using any firewall before this, so we searched and purchased the Cisco ASA 5525 Series Firewall. It provides us [a] firewall with router features. The performance of this firewall is very good.
Chose Cisco Adaptive Security Appliance (ASA) Software
We were using the Sophos firewall but this firewall is very complicated and lots of bugs [are] in this firewall. Lots of [times] we faced the policy misbehave [as well as] downtime. Technical support is also not good so we purchased the Cisco ASA series and after Cisco ASA, we …
Chose Cisco Adaptive Security Appliance (ASA) Software
We have a startup and this is our first organization. We researched lots of firewalls but the price was very high so we decided to purchase the Cisco ASA. It provides us [a lot] of features at a low cost. Cisco ASA provides us router functionality [as well] so it is easy for us …
Chose Cisco Adaptive Security Appliance (ASA) Software
We were not using any firewall before this. I checked the reviews and directly purchased.
Chose Cisco Adaptive Security Appliance (ASA) Software
We were using Pfsense in our environment before for remote VPN but we were facing continuous configuration misbehave issues. After using Cisco ASA is have resolved our remote VPN & security issues. It has also GUI Based control access so that we can easily check & manage things …
Chose Cisco Adaptive Security Appliance (ASA) Software
We were using the PFSense but we were not happy with the services. We were facing lots of downtime and bugs during the production hours. That's why we selected Cisco ASA. It is a really very good firewall and we haveb't faced any downtime in the last 3 years.
Chose Cisco Adaptive Security Appliance (ASA) Software
We were using PfSense before in our environment but we were facing continuous issues in configuration management & policy-based management. After the implementation of Cisco ASA, it has resolved both the previous problems & also provided us a reliable solution with High …
Chose Cisco Adaptive Security Appliance (ASA) Software
We were using [pfSense] before in our environment but we regularly facing difficulties over it due to software bugs & downtime. After implementing Cisco ASA, it resolved our availability issue & provides us a reliable solution with the best security features & easy to …
pfSense
Chose pfSense
PFSense is not a fully featured and supported enterprise-grade solution; however, it does offer a lot of similar functionality at a fraction of the cost for more minor requirements.
Chose pfSense
Fortigate offers an extensive set of features including the Unified Threat Management and a lot of FortiGuard services . pfSense is extremely modular, probably because of its open source "flavour"m but relies on community support. Fortinet ROI depends on the reduced …
Chose pfSense
PfSense beats all other solutions at its price point, hands-down. You can get more features with far less performance, or same performance for much higher cost.
Chose pfSense
pfSense does almost all what the other brands do and the CE Edition is free even if complete.
Chose pfSense
Meraki has a unified management login for all devices, which is nice. It also has decent content filtering, both areas where pfSense is weaker.

Where pfSense far ouclasses Meraki is in the ease of use and the other width of features. These include features such as better VPN …
Chose pfSense
Overall, pfSense is the most complete solution in terms of features included even though it currently lack of a centralised management interface.The Ubiquiti firewall offering is often appealing being well integrated within the Ubiquiti dashboard and it is often a solution of …
Chose pfSense
We were using Sophos XG Firewall in our environment before but we need a product that is customizable & provides low cost high security features. pfSense provided us high security features with customizable options as it's kernel is based on freeBSD.
Chose pfSense
We were using Sophos XG firewall in our environment but when it comes to cost it's more expensive with limited features. After using [pfSense] we are getting more security features at less cost. After pfSense provides a bundle of security features such as anti-spamming, …
Chose pfSense
pfSense offers more options and scales very easily.
Chose pfSense
pfSense is just a more flexible, lower-cost solution—it can be installed (if you wish) on just about any x86 hardware or even virtual machines - the community edition is free and so enables rapid prototyping and low-cost prototyping and lab build out—something that isn't …
Chose pfSense
pfSense is a lot cheaper and has higher firewall throughput per dollar than "enterprise" network appliances. It's also significantly easier to configure and learn. It may not have some of the "enterprise" features or the support level that someone like Cisco has, but for small …
Chose pfSense
pfSense itself is free and can be installed on just about any hardware so from a hardware cost perspective it can beat out anybody. In terms of features it's above many pro-sumer/small business solutions like Ubiquiti. It can't really stand against high-end gear like Cisco but …
Chose pfSense
First of all, I don't need to be a Cisco professional to manage VPN, load balance, multiple WAN/LAN, Firewall and etc. pfSense has an easy-to-use web interface and I can do everything and add packaged add-on services. Moreover, for Small & Medium Enterprise, IT budget is …
Chose pfSense
Pfsense seemed to always be cheaper and just as good as its competitors.
Chose pfSense
I have not seen a single thing that these other products do that pfSense does not. In fact, the performance/throughput of pfSense is better in my opinion.
Chose pfSense
While you can get the performance out of other products, pfSense offers the unique ability to put other services on the same device. Products such as Untagle's NG Firewall and SonicWall's TZ series offer cost effective options for firewall and VPN services, having incoming load …
Chose pfSense
pfSense is a new and innovative platform that has learned from the errors of older systems, which helps it cover the needs that aren't covered by Smoothwall.

Chose pfSense
Before pfSense we were using consumer and small business rated network appliances from Linksys, Cisco, Buffalo and Netgear. We were replacing them on average of every 6-12 months because they'd fail or would offer poor wifi availability.

Switching to pfSense allowed us to use …
Chose pfSense
It's an open source solution can support from 50 to 700 user without sweating and with the half of the standard bundle investment that will take to deploy a Fortigate UTM, or a Cisco ASA, also a Sophos UTM that are quite remarkable units but to pFSense saves you money and will …
Chose pfSense
Real competition was between Pfsense and OpnSense that integrates first the bootstrap Twitter framework. But with OpSense there are configurations that create some problems with a specific client (we've experienced that by creating an IPSec tunnel both with OpSense and …
Chose pfSense
I've used a number of routers like Cisco, Sonicwall, Juniper, Home based routers, etc. pfSense is like most routers but with the benefit of load balancing and multi-wan. Well many support multi-wan but load balancing is usually a separate device like an BIGiP F5 or Cisco CSS.
Chose pfSense
Both products listed above, are very great solutions, but payed ones. If you are looking for open source firewall solution, pfSense is the one. Based on FreeBSD, it has strong security features and is very easy to deploy, configure and manage. pfSense also plays network simple …
Features
Cisco Adaptive Security Appliance (ASA) SoftwarepfSense
Firewall
Comparison of Firewall features of Product A and Product B
Cisco Adaptive Security Appliance (ASA) Software
7.8
Ratings
10% below category average
pfSense
7.6
Ratings
13% below category average
Identification Technologies6.50 Ratings5.00 Ratings
Visualization Tools6.50 Ratings7.00 Ratings
Content Inspection8.00 Ratings4.00 Ratings
Policy-based Controls9.00 Ratings10.00 Ratings
Active Directory and LDAP7.50 Ratings7.00 Ratings
Firewall Management Console7.50 Ratings9.50 Ratings
Reporting and Logging5.90 Ratings8.00 Ratings
VPN9.00 Ratings10.00 Ratings
High Availability9.00 Ratings10.00 Ratings
Stateful Inspection9.00 Ratings7.00 Ratings
Proxy Server8.00 Ratings6.10 Ratings
Best Alternatives
Cisco Adaptive Security Appliance (ASA) SoftwarepfSense
Small Businesses
pfSense
pfSense
Score 9.9 out of 10
Sophos UTM
Sophos UTM
Score 8.1 out of 10
Medium-sized Companies
Quantum Firewalls and Security Gateways
Quantum Firewalls and Security Gateways
Score 9.6 out of 10
Quantum Firewalls and Security Gateways
Quantum Firewalls and Security Gateways
Score 9.6 out of 10
Enterprises
Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series
Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series
Score 10.0 out of 10
Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series
Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series
Score 10.0 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
Cisco Adaptive Security Appliance (ASA) SoftwarepfSense
Likelihood to Recommend
9.0
(0 ratings)
9.6
(0 ratings)
Likelihood to Renew
7.1
(0 ratings)
-
(0 ratings)
Usability
-
(0 ratings)
10.0
(0 ratings)
Availability
7.5
(0 ratings)
-
(0 ratings)
Support Rating
8.7
(0 ratings)
-
(0 ratings)
Implementation Rating
8.0
(0 ratings)
-
(0 ratings)
Ease of integration
6.5
(0 ratings)
-
(0 ratings)
User Testimonials
Cisco Adaptive Security Appliance (ASA) SoftwarepfSense
Likelihood to Recommend
We moved our operations entirely to the cloud a few years ago. We loved the stability and scalability of the ASA and wanted to, somehow, keep using it. We discovered that ASA was available in the cloud as well and it was branded ASAv. We tested it and noticed that it was equally robust and a perfect fit for us. During the entire migration period, we used ASAv for cloud operations and put a lot of load on it. ASAv performed very well and gave us an easy transition from on-prem to the cloud.
Read full review
pfSense is incredibly budget friendly and capable for organizations of all sizes. My specific scenario, working for a non-profit organization, requires budget consciences decisions without compromising security and function. pfSense has helped tremendously in accomplishing this. It specifically tackles advanced routing, static routing, remote access, intrusion prevention, in a single platform, mostly available for free.
Read full review
Pros
  • How we can manage: ASDM the GUI is so much easier to manage it even for a new guy also.
  • Traffic handling capacity
  • More secure and the different features it gives.
  • Support from the TAC team or from the community manages to handle issues very efficiently.
Read full review
  • Easy to use. Good user interface design! Easy to understand and easy to set up.
  • Lower hardware requirement. 3 years ago, we used an old PC to run it. Now, we have changed to a router device with Celeron CPU and 8GB RAM. It runs smoothly with a 1000G commercial broadband.
Read full review
Cons
  • The Java based ASDM can botch commands and isn't compatible on some more locked down systems.
  • Monitoring. Really the same complaint as above, the monitoring available through the ASDM is crappy at best. A much better solution is to send the logs and mirror packets to a SEIM, but that can create issues of its own when looking for realtime analysis.
  • Compatibility across other ASA models. ASA 5520s don't play well with 5525X which don't play well with older 5510s. Each is great on it's own, but it's next to impossible to logically stack them or have them as layers of firewalls in an infrastructure.
  • Lack of cloud based management. The Cisco Meraki security devices do this well, but the ASAs are still behind in this regard.
Read full review
  • There is no API for making changes. This can be a hindrance in environments where auto-deploying something needs firewall rules or HAProxy configs updated. Since all settings are stored in an XML file and then configs are generated from that, even manually updating config files cannot be done.
  • Beware that some network cards can have issues. pfSense is based on FreeBSD, so it's best to look on their compatibility list before deploying.
Read full review
Likelihood to Renew
To be honest there has been now great products out in the market compared to Cisco ASA. I beleieve Cisco has to do a lot of improvement in this area. The other defeiniete factors is the cost when it comes to renewals which is always a premium on Cisco products
Read full review
No answers on this topic
Usability
No answers on this topic
pfSense can be a very elementary firewall but can also be as comples as you want, according your needs. I'd always reccomend a HA solution when used in a company and, for bigger companies, commercial license is recommended. It's also very adptable to everyone's needs.
Read full review
Reliability and Availability
I generally have not noticed the outages, however since it's a machine it can malfunction, we need to implement the firewall infrastructure in such a way that it is highly available with device failure, region failure etc. Else any solution will be having the issues if they are not build with resiliency.
Read full review
No answers on this topic
Support Rating
The support is usually very good and gets back to you very quickly. However I had some instances of when two engineers will give me wildly different answers to what I thought was a simple question. Overall however I do rate the support highly and they are generally always very good.
Read full review
pfSense+ basic provides "As Available" email support. pfSense+ Pro offers 24 hr turn around email support. pfSense+ Enterprise offers 24/7 phone support.
Read full review
Implementation Rating
It was quite a good one, how ever requires an expertise to deploy hence the SMB segment would be finding it difficult to implement this product. The one good reason is that there are lot of ASA certified engineers in compared to the other certified engineers. Hence this resembles positively on the deployment as you have quite a lot of experienced engineer on your deployment
Read full review
No answers on this topic
Alternatives Considered
Cisco has made it easy to buy, set up, and manage all of our firewalls with the central FirePower Management Center. All licensing is done via one license portal too. Tech support is standardized for all ASA devices and like support engineers who know the different models to provide timely help for any issues. Cisco Talos is a premier could platform which scours the internet looking for threats and develops protections for the ASA's and as such provides zero second coverage when it best can detect global issues.
Read full review
PFSense is not a fully featured and supported enterprise-grade solution; however, it does offer a lot of similar functionality at a fraction of the cost for more minor requirements.
Read full review
Return on Investment
  • I know a customer who is still using a Pix[.]
  • The 5510 is still being used in one of our setups, and still doing its job this is a lot of Return on Investment.
  • We have managed to turn around projects quickly because most of our engineers understand this firewall very well. We deploy them in a matter of minutes[.]
Read full review
  • pfSense has only had positive impacts on our company. We are not a huge company so not having to buy licenses to get all these features have been excellent.
  • I was not around when our current sysadmin decided to use pfSense, but I am assuming from day one it was probably a 100% return on investment since it does everything we need it to and it was open source software.
Read full review
ScreenShots