Cisco Secure Web Appliance (formerly Cisco Web Security Appliance [WSA]), powered by Cisco Talos, protects by automatically blocking risky sites and testing unknown sites before allowing users to link to them, helping with compliance. It is available models S690, S390, and S190.
N/A
Zscaler Internet Access
Score 8.8 out of 10
N/A
Zscaler Internet Access™ (ZIA) is a secure web gateway (SWG), delivering cloud native cyberthreat protection and zero trust access to the internet and SaaS apps.
McAfee Web Gateway can be much more expensive, we tested it and it really is excellent in the usefulness it offers; however, the team did not adapt very well to how expensive the tool can be. On the other hand, Cisco Secure Web Appliance offers much more comfortable payment …
At home I have a McAfee service that does similar tasks and helps manage the users of my internet. McAfee seems more user friendly and easier to set exceptions.
Cisco Web Security Appliance (WSA) is a potent tool. When it comes to handling emails and links from blacklisted IP, Cisco Web Security Appliance (WSA) does a better job. However, considering the price to performance ratio, Mimecast is way ahead of Cisco Web Security Appliance …
Considering we're with Cisco IronPort Web Security Appliances for the last 9 years, as I stated, we don't have too much experience with other producs. What I can say is that in the past, we evaluated Websense before it became Forcepoint and we also used MS ISA Server for …
We previously used BlueCoat ProxySG appliances. The system worked well overall, but the hardware, licensing, and support costs were just too high to continue using the product. The hardware costs, in particular, were unacceptable. It was relatively easy to convert our …
Websense has more resources devoted to categorizing the internet. The product is one of the best and most expensive. The Cisco WSA isn't as experienced, but is also significantly cheaper. Its an active product line getting investment and improvements. It is worth a look. …
Cisco IronPort was the most flexible and easy to deploy. The use of a central manager even simplifies the process even further. Maintenance is seemeless and upgrades go well without having to install constant hotfixes.
We used several other products (evaluation and production) in the past and are testing some of them now. According to my experience I can say that Cisco IronPort Web Security Appliance has a lot of positive moments. It doesn't mean that other products worse or do not have such …
Netskope was good however did not have all the features Zscaler had. Zscaler provides the same type of protection as Netskope but more. We also found the netskope agent used a lot of resoures on devices. ZCC was very light-weight and did not consume a lot of resources on laptops.
Palo support has been a large enough negative experience on multiple occasions that we have been looking to move away from the platform and Zscaler Internet Access looks to be a suitable replacement
Zscaler Internet Access is most akin to ZPA - we bought both at the same time to handle all traffic internally and externally. In terms of quality - I would make the statement that Zscaler Internet Access is a simpler product but that's also cause there are no App Connectors …
Zscaler Internet Access has significantly more configurability and capability in the platform, and can scale much better with large organizations. It is also much more affordable for our environment and gives us greater flexibility to grow into the Zscaler Platform.
Based on the platforms I have evaluated, I think the WSA is a great fit for any organization that needs a proxy server that provides control over what web sites are accessed or when they can be accessed. I think it is probably overkill if you simply need a proxy server for bandwidth savings or because you need to proxy general Internet access without extensive filtering needs.
Zscaler Internet Access has extremely powerful category selection and it is very easy to create your own destinations for inspection and policy exceptions (SSL exception specifically). It is also very affordable and just as powerful (if not more) than some of the other solutions I have used in the past to achieve internet security.
It does a great job of filtering emails based on IP reputation. This feature works particularly very well. Cisco has a vast database of IP reputation scores and therefore offers very few false positives and negatives.
It checks each email thoroughly without any compromise of privacy. Any malicious link present in the body of the email makes its way to the quarantine. The IP reputation scores also help in this case.
The depth that Cloud App control policies can go into. Being able to control individual actions within an application, more than just all or nothing access.
The UX/UI design makes it really easy to navigate the portal.
Understanding how cloud app/url control policy gets evaluated and creating/editing existing policy is extremely straightforward.
While Zscaler Internet Access (ZIA) delivers critical value in cloud security and RBI compliance, I rate renewal likelihood 7/10 due to evolving needs versus platform limitations. Below is my rationale:
Because it's one of those products you almost don't realize it exists from the end user. From the administrator perspective, you can do everything on its web interface and it's very intuitive to manage, once you know the concepts behind identities, acls, etc. Also, once you build the control structure, I mean, you link 'local' groups with your own Active Directory groups, as we did here, you don't need to be managing those things on the appliance itself.
The application is easy to install and configure on all Windows devices. To troubleshoot any internet issue, we can easily collect all the relevant logs from Zscaler and check the exact issue. The only problem is with the uninstall, as a dedicated crew needs to provide the password.
Our experience with Cisco's support was terrible. Other than the fact that they don't respond to service-related emails with urgency, they also keep on changing the policies that affected us. Recently, they came up with a new look for the same software, which was insanely slow. Renewal of keys for the old interface took months. Overall, the support was not very friendly from the users' point of view.
Zscaler's ZIA support is quick and knowledgable. They respond within 1-2 hours of you submitting your ticket. They are very thorough and are typically ready to jump on a live troubleshooting session. Our ZIA platform and how we use is it unique so at times tickets can be open for weeks but we alway get quality support compared to other unrelated product support in our enterprise
Considering we're with Cisco IronPort Web Security Appliances for the last 9 years, as I stated, we don't have too much experience with other producs. What I can say is that in the past, we evaluated Websense before it became Forcepoint and we also used MS ISA Server for webfilter. As you may imagine, IronPort is a very very superior product.
Zscaler Internet Access is most akin to ZPA - we bought both at the same time to handle all traffic internally and externally. In terms of quality - I would make the statement that Zscaler Internet Access is a simpler product but that's also cause there are no App Connectors involved in that process.
Having a much safer work system has given us the guarantee and security of always staying out of danger.
The prevention system is important for us and always keeping our devices, web and emails free of any malicious agent has allowed us an excellent workflow, without distractions or inconvenience in the development of projects.
Thanks to the fact that we have kept our work system safe, we have saved ourselves a lot of inconvenience, time spent, avoiding equipment damage, payments to solve problems, among many other problems that thanks to Cisco Secure Web Appliance we have been able to solve.
Has allowed us to remove other products that were suboptimal
Saved us money overall by stacking it with other Zscaler products
Created a more secure work environment for our users through intelligent internet policies that are not needlessly restrictive while still maintaining security best practices