Cisco Adaptive Security Appliance (ASA) software is the core OS for the ASA suite. It provides firewall functionality, as well as integration with context-specific Cisco security modules. It is scaled for enterprise-level traffic and connections.
N/A
pfSense
Score 9.9 out of 10
N/A
pfSense is a firewall and load management product available through the open source pfSense Community Edition, as well as a the licensed edition, pfSense Plus (formerly known as pfSense Enterprise). The solution provides combined firewall, VPN, and router functionality, and can be deployed through the cloud (AWS or Azure), or on-premises with a Netgate appliance. It as scalable capacities, with functionality for SMBs. As a firewall, pfSense offers Stateful packet inspection, concurrent…
We were using pfsence before [the] Cisco ASA firewall and we were not happy with pfsense features. Lots of features are missing in pfSence so we decided to install the [Cisco] ASA 5525 and we are very happy with the features. There are lots of options in nat and you can easy to …
The company has been using Cisco Adaptive Security Appliance (ASA) Software for more than 10 years, for the support team its operation is simple, so even though Palo Alto has more functions, we would have a certain cost of investment and time in training the entire team, or we …
Integration with Cisco Ecosystem, Cisco Adaptive Security Appliance (ASA) Software integrates smoothly with other Cisco security products and networking solutions. We have already invested in Cisco networking equipment and infrastructure which is why we chose Cisco Adaptive …
I've used the Firepower to a small extent. It's way better. It does up to layer seven. It does a lot more inspection. It does URL filter. It does IPS, it does antibody, it does all the things that the ASA doesn't do.
Cisco has made it easy to buy, set up, and manage all of our firewalls with the central FirePower Management Center. All licensing is done via one license portal too. Tech support is standardized for all ASA devices and like support engineers who know the different models to …
The ASA led the pack for our use case since we were familiar with it and the ASA (and ASAv) was able to integrated with our environment very easily. We were also able to apply MFA to the ASA with very little effort, further improving our posture. In comparison, other tools were …
This was selected due to our organization standard and our branch office is using ASA. Integration with the same product is really a good option with ASA.
We moved from older ASAs to Firepower and were excited to see the new features and higher reliability. Throughput is faster and as our old ASAs were breaking down intermittently it was time for the upgrade. The newer GUI has a better dashboard and is easy to maneuver in, easier …
Configuration and management of Cisco's ASA are straightforward. We chose Cisco ASA for many reasons, as well as Cisco's threat response reports. We previously had issues with Sophos UTM due to its poor performance. We no longer have to be concerned about performance issues …
Palo Altos blow Cisco ASAs away in terms of form and function. They are next-generation firewalls that have very advanced rule sets and AI to help protect your cooperation; however, they are also about 20 times more than a comparable Cisco ASA firewall.
Fortinet and SonicWall firewalls are not without their own unique merits, but Cisco ASA devices are our go-to devices for all of our clients' firewall needs. We have found creating and keeping VPN tunnels established is much easier on a Cisco ASA device.
Cisco ASA is doing well, has [a] lot of documents available, [and easy] implementation, however, other vendors are also very easy to deploy. Cisco ASA has [a] great support team. Cisco ASA is truly [a] next-generation product. Now it is cloud-managed, along with zero-touch …
We have never used any other firewall. This is the first firewall in our organization and we are very happy with its features and technical support. [Cisco ASA] is easy to configure and we never face any downtime with it.
We have a small network so we were using clearos for security but this firewall is just a basic functionality so we decided to change and installed the Cisco ASA firewall. Cisco ASA provides us lots of features like NAT, routing, as well as security features for protecting our …
We were not using any firewall before this, so we searched and purchased the Cisco ASA 5525 Series Firewall. It provides us [a] firewall with router features. The performance of this firewall is very good.
We were using the Sophos firewall but this firewall is very complicated and lots of bugs [are] in this firewall. Lots of [times] we faced the policy misbehave [as well as] downtime. Technical support is also not good so we purchased the Cisco ASA series and after Cisco ASA, we …
We have a startup and this is our first organization. We researched lots of firewalls but the price was very high so we decided to purchase the Cisco ASA. It provides us [a lot] of features at a low cost. Cisco ASA provides us router functionality [as well] so it is easy for us …
We were using Pfsense in our environment before for remote VPN but we were facing continuous configuration misbehave issues. After using Cisco ASA is have resolved our remote VPN & security issues. It has also GUI Based control access so that we can easily check & manage things …
We were using the PFSense but we were not happy with the services. We were facing lots of downtime and bugs during the production hours. That's why we selected Cisco ASA. It is a really very good firewall and we haveb't faced any downtime in the last 3 years.
We were using PfSense before in our environment but we were facing continuous issues in configuration management & policy-based management. After the implementation of Cisco ASA, it has resolved both the previous problems & also provided us a reliable solution with High …
We were using [pfSense] before in our environment but we regularly facing difficulties over it due to software bugs & downtime. After implementing Cisco ASA, it resolved our availability issue & provides us a reliable solution with the best security features & easy to …
PFSense is not a fully featured and supported enterprise-grade solution; however, it does offer a lot of similar functionality at a fraction of the cost for more minor requirements.
Fortigate offers an extensive set of features including the Unified Threat Management and a lot of FortiGuard services . pfSense is extremely modular, probably because of its open source "flavour"m but relies on community support. Fortinet ROI depends on the reduced …
PfSense beats all other solutions at its price point, hands-down. You can get more features with far less performance, or same performance for much higher cost.
Overall, pfSense is the most complete solution in terms of features included even though it currently lack of a centralised management interface.The Ubiquiti firewall offering is often appealing being well integrated within the Ubiquiti dashboard and it is often a solution of …
We were using Sophos XG Firewall in our environment before but we need a product that is customizable & provides low cost high security features. pfSense provided us high security features with customizable options as it's kernel is based on freeBSD.
We were using Sophos XG firewall in our environment but when it comes to cost it's more expensive with limited features. After using [pfSense] we are getting more security features at less cost. After pfSense provides a bundle of security features such as anti-spamming, …
pfSense is just a more flexible, lower-cost solution—it can be installed (if you wish) on just about any x86 hardware or even virtual machines - the community edition is free and so enables rapid prototyping and low-cost prototyping and lab build out—something that isn't …
pfSense is a lot cheaper and has higher firewall throughput per dollar than "enterprise" network appliances. It's also significantly easier to configure and learn. It may not have some of the "enterprise" features or the support level that someone like Cisco has, but for small …
pfSense itself is free and can be installed on just about any hardware so from a hardware cost perspective it can beat out anybody. In terms of features it's above many pro-sumer/small business solutions like Ubiquiti. It can't really stand against high-end gear like Cisco but …
First of all, I don't need to be a Cisco professional to manage VPN, load balance, multiple WAN/LAN, Firewall and etc. pfSense has an easy-to-use web interface and I can do everything and add packaged add-on services. Moreover, for Small & Medium Enterprise, IT budget is …
I have not seen a single thing that these other products do that pfSense does not. In fact, the performance/throughput of pfSense is better in my opinion.
While you can get the performance out of other products, pfSense offers the unique ability to put other services on the same device. Products such as Untagle's NG Firewall and SonicWall's TZ series offer cost effective options for firewall and VPN services, having incoming load …
pfSense is a new and innovative platform that has learned from the errors of older systems, which helps it cover the needs that aren't covered by Smoothwall.
Before pfSense we were using consumer and small business rated network appliances from Linksys, Cisco, Buffalo and Netgear. We were replacing them on average of every 6-12 months because they'd fail or would offer poor wifi availability.
It's an open source solution can support from 50 to 700 user without sweating and with the half of the standard bundle investment that will take to deploy a Fortigate UTM, or a Cisco ASA, also a Sophos UTM that are quite remarkable units but to pFSense saves you money and will …
Real competition was between Pfsense and OpnSense that integrates first the bootstrap Twitter framework. But with OpSense there are configurations that create some problems with a specific client (we've experienced that by creating an IPSec tunnel both with OpSense and …
I've used a number of routers like Cisco, Sonicwall, Juniper, Home based routers, etc. pfSense is like most routers but with the benefit of load balancing and multi-wan. Well many support multi-wan but load balancing is usually a separate device like an BIGiP F5 or Cisco CSS.
Both products listed above, are very great solutions, but payed ones. If you are looking for open source firewall solution, pfSense is the one. Based on FreeBSD, it has strong security features and is very easy to deploy, configure and manage. pfSense also plays network simple …
We moved our operations entirely to the cloud a few years ago. We loved the stability and scalability of the ASA and wanted to, somehow, keep using it. We discovered that ASA was available in the cloud as well and it was branded ASAv. We tested it and noticed that it was equally robust and a perfect fit for us. During the entire migration period, we used ASAv for cloud operations and put a lot of load on it. ASAv performed very well and gave us an easy transition from on-prem to the cloud.
pfSense is incredibly budget friendly and capable for organizations of all sizes. My specific scenario, working for a non-profit organization, requires budget consciences decisions without compromising security and function. pfSense has helped tremendously in accomplishing this. It specifically tackles advanced routing, static routing, remote access, intrusion prevention, in a single platform, mostly available for free.
Easy to use. Good user interface design! Easy to understand and easy to set up.
Lower hardware requirement. 3 years ago, we used an old PC to run it. Now, we have changed to a router device with Celeron CPU and 8GB RAM. It runs smoothly with a 1000G commercial broadband.
The Java based ASDM can botch commands and isn't compatible on some more locked down systems.
Monitoring. Really the same complaint as above, the monitoring available through the ASDM is crappy at best. A much better solution is to send the logs and mirror packets to a SEIM, but that can create issues of its own when looking for realtime analysis.
Compatibility across other ASA models. ASA 5520s don't play well with 5525X which don't play well with older 5510s. Each is great on it's own, but it's next to impossible to logically stack them or have them as layers of firewalls in an infrastructure.
Lack of cloud based management. The Cisco Meraki security devices do this well, but the ASAs are still behind in this regard.
There is no API for making changes. This can be a hindrance in environments where auto-deploying something needs firewall rules or HAProxy configs updated. Since all settings are stored in an XML file and then configs are generated from that, even manually updating config files cannot be done.
Beware that some network cards can have issues. pfSense is based on FreeBSD, so it's best to look on their compatibility list before deploying.
To be honest there has been now great products out in the market compared to Cisco ASA. I beleieve Cisco has to do a lot of improvement in this area. The other defeiniete factors is the cost when it comes to renewals which is always a premium on Cisco products
pfSense can be a very elementary firewall but can also be as comples as you want, according your needs. I'd always reccomend a HA solution when used in a company and, for bigger companies, commercial license is recommended. It's also very adptable to everyone's needs.
I generally have not noticed the outages, however since it's a machine it can malfunction, we need to implement the firewall infrastructure in such a way that it is highly available with device failure, region failure etc. Else any solution will be having the issues if they are not build with resiliency.
The support is usually very good and gets back to you very quickly. However I had some instances of when two engineers will give me wildly different answers to what I thought was a simple question. Overall however I do rate the support highly and they are generally always very good.
It was quite a good one, how ever requires an expertise to deploy hence the SMB segment would be finding it difficult to implement this product. The one good reason is that there are lot of ASA certified engineers in compared to the other certified engineers. Hence this resembles positively on the deployment as you have quite a lot of experienced engineer on your deployment
Cisco has made it easy to buy, set up, and manage all of our firewalls with the central FirePower Management Center. All licensing is done via one license portal too. Tech support is standardized for all ASA devices and like support engineers who know the different models to provide timely help for any issues. Cisco Talos is a premier could platform which scours the internet looking for threats and develops protections for the ASA's and as such provides zero second coverage when it best can detect global issues.
PFSense is not a fully featured and supported enterprise-grade solution; however, it does offer a lot of similar functionality at a fraction of the cost for more minor requirements.
The 5510 is still being used in one of our setups, and still doing its job this is a lot of Return on Investment.
We have managed to turn around projects quickly because most of our engineers understand this firewall very well. We deploy them in a matter of minutes[.]
pfSense has only had positive impacts on our company. We are not a huge company so not having to buy licenses to get all these features have been excellent.
I was not around when our current sysadmin decided to use pfSense, but I am assuming from day one it was probably a 100% return on investment since it does everything we need it to and it was open source software.