We performed a comparison between Cisco Secure Firewall and Zscaler Internet Access based on real PeerSpot user reviews.
Find out in this report how the two Firewalls solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."It's great for capturing the traffic and troubleshooting it."
"The CLI is robust and powerful, enabling rapid, consistent changes via SSH."
"The flexibility and ease of configuration are the most valuable features."
"Fortinet has a very good solution for Secure SD-WAN. One very good feature is that they have robust and simple FortiOS through which they provide all solutions. That's their strength. There's not much complexity involved with the Secure SD-WAN solution of Fortinet as compared to Cisco's solution, which has a lot of flexibility but complexity also comes with that flexibility."
"Advanced routing (RIP, OSPF, BGP, PBR). It gives you a seamless and simple integration into a large network."
"The most valuable feature is the policy routing and application control."
"The pipe filter application is an outstanding feature."
"It's very fast and easy to configure."
"The most valuable Cisco Secure Firewall features are options, features, and ease of deployment because it's an appliance."
"The firepower sensors have been great; they do a good job of dropping unwanted traffic."
"The most important feature is the intensive way you can troubleshoot Cisco Firepower Firewalls. You can go to the bit level to see why traffic is not handled in the correct way, and the majority of the time it's a networking issue and not a firewall issue. You can solve any problem without Cisco TAC help, because you can go very deeply under the hood to find out how traffic is flowing and whether it is not flowing as expected. That is something I have never seen with other brands."
"I love the ASDM (Adaptive Security Device Manager) which is the management suite. It's a GUI and you're able to see everything at a glance without using the command line. There are those who love the CLI, but with ASDM it is easier to see where everything is going and where the problems are."
"The most valuable feature would be the IP blocking. It gets rid of things that you don't need in your environment."
"We moved from a legacy firewall to the ASA with FirePOWER, increasing our Internet Edge defense dramatically."
"It protects our network."
"If configured, Firepower provides us with application visibility and control."
"Zscaler covers all the features needed to replace a VPN or proxy solution. They are good. They've been on the market for 15 years now, so they are mature enough."
"The solution is scalable and stable."
"The solution offers a distributed organization to master and to control all of the endpoints."
"The scanning feature is impressive, because they do not introduce a big latency to the traffic."
"Overall, we're very happy with our product."
"The VPN is valuable, as the whole technology is very different from a traditional VPN."
"It is easy to set up the solution."
"We use ZIA for outbound internet connectivity. The internet traffic of on-prem users will be directed to the ZIA cloud for security checks and web filtering."
"Reporting is limited to providing an external appliance for improving the reporting capabilities of the FortiAnalyzer. It does not offer a central management and is also sold separably as an appliance."
"One area for improvement is the performance on bandwidth demands for smaller devices, as well as better web filtering."
"Monitoring and reporting could be better."
"It is stable, but its stability can be improved."
"Technical support needs to be improved."
"The stability could be a bit better."
"The main aspect of FortiGate that could be improved is load balancing. Our management team does not want to buy another appliance for only load balancing."
"Currently, FortiGate is providing SSL VPN. But they're missing some features that are available in Palo Alto's SSL VPN."
"In a future release, it would be ideal if they could offer an open interface to other security products so that we could easily connect to our own open industry standard."
"Cisco wasn't first-to-market with NGFWs... they should look at what other vendors are doing and try not only to be on the same wavelength but a little bit better."
"Security generally requires integration with many devices, and the management side of that process could be enhanced somewhat. It would help if there was a clear view of the integrations and what the easiest way to do them is."
"The main problem we have is that things work okay until we upgrade the firmware, at which point, everything changes, and the net stops working."
"It integrates with other security products from Cisco, but sometimes, there can be glitches or errors."
"Report generation is an area that should be improved."
"Some of the features, like the stability, need to be improved."
"The stability and the product features have to really be worked on."
"What could be improved in Zscaler Internet Access is its price. It could be cheaper."
"Zscaler Internet Access needs to integrate more ISPs. It is good to have more than three ISPs."
"The reporting functionality could be a bit easier to use. There is a reporting function, but it's quite hard to do any good reporting, from a user-management perspective. For example, if a department manager wants to know how his department is using the web, there is a way to get the data, but it's quite cumbersome to get it and show it well. And that's true for comparing between departments."
"The solution is expensive. They recently revised the pricing and packaging. Some of our existing customers have been asking for alternate solutions for a lower price."
"One thing that needs to be improved is their presence in China. I'm not sure if that's a Zscaler thing or if it's a problem with all vendors in this space, but it would be nice to have better coverage in China. This concern is a common one for vendors across the board when dealing with the Chinese market."
"The performance needs improvement. Some areas create performance issues and, depending on the use cases, require reconfiguration to perform again."
"They should enhance the audit reporting feature."
"There are some performance issues when we add on additional controls."
Cisco Secure Firewall is ranked 4th in Firewalls with 404 reviews while Zscaler Internet Access is ranked 2nd in Secure Web Gateways (SWG) with 46 reviews. Cisco Secure Firewall is rated 8.2, while Zscaler Internet Access is rated 8.2. The top reviewer of Cisco Secure Firewall writes "Highlights and helps us catch Zero-day vulnerabilities traveling across our network". On the other hand, the top reviewer of Zscaler Internet Access writes "Provides integrated CASB and file sandboxing but could be less expensive ". Cisco Secure Firewall is most compared with Palo Alto Networks WildFire, Netgate pfSense, Meraki MX, Sophos XG and Palo Alto Networks NG Firewalls, whereas Zscaler Internet Access is most compared with Cisco Umbrella, Microsoft Defender for Cloud Apps, Netskope , Prisma Access by Palo Alto Networks and Appgate SDP. See our Cisco Secure Firewall vs. Zscaler Internet Access report.
We monitor all Firewalls reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.