PeerSpot user
Team Lead at a tech services company with 201-500 employees
Real User
Offers good protection and a huge rate of threat protection
Pros and Cons
  • "It has a huge rate of protection. It's has a low level of positives and a huge rate of threat protection. It's easy to deploy and easy to implement. It has an incredible price rate compared to similar solutions."
  • "Performance needs improvement."

What is most valuable?

It has a huge rate of protection. It has a low level of positives and a huge rate of threat protection. It's easy to deploy and easy to implement. It has an incredible price rate compared to similar solutions. It has a good support channel, technical assistance. It's good. 

It's really good to sell as far as a Cisco firewall. It's really good to sell in the complex Cisco project because Cisco's really good for networking and routing. When we are networking, it's easier to sell a security-based firewall. It's a complex product. It's really good. There is syndication between different security products, and in Cisco's case, it's with integration.

What needs improvement?

Performance needs improvement. If you compare Cisco Sourcefire with other products, it performs at the same level of compliance. For Cisco Sourcefire, it's not really horrible and it's not really the market and price-performance rate. The performance can be improved. 

For how long have I used the solution?

We have been using Sourcefire since 2011.

What do I think about the scalability of the solution?

It's scalable. Sourcefire has a classic deployment model and you can scale up through the appliance if you need the same deployment so it's quite simple. It's quite scalable. We mostly work with mid-sized companies. 

Sourcefire Snort is the kind of software that is constantly running like 24/7,

Buyer's Guide
Cisco Sourcefire SNORT
May 2024
Learn what your peers think about Cisco Sourcefire SNORT. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
770,428 professionals have used our research since 2012.

How are customer service and support?

In general, Cisco provides really good and reliable support. Overall it's good but sometimes, around 1% of the time, it doesn't work so well. 

Which solution did I use previously and why did I switch?

We also use IBM and Palo Alto and from the technical perspective, it's probably equal. It's equal by the features, by the functionality, by the performance. But again, for the pricing, it's really bumpy.  For Palo Alto for example, the pricing is almost equal. But for the performance and the features, they are on the next level.

How was the initial setup?

It is easy to setup. For a basic deployment, it can take up to three or four days to deploy in a minimal setup. If it's a huge project with a huge data center, a lot of configuration, a lot of work, and a lot of integration, it will take two or three weeks up to one month. 

You only need one person for a basic deployment. 

What other advice do I have?

Make sure to have good sizing because it matters for the performance of the features. Also make sure to have a good design. Before starting with the deployment and installation for Sourcefire. Have a technical session with the local Cisco office or the local department to provide a good design. 

I would rate it an eight out of ten. 

We have some architecture concerns. I'm not really sure that Cisco can quickly solve this concern. Palo Alto has a user-friendly interface for the management. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Senior Engineer at a tech services company with 51-200 employees
Real User
User-friendly and provides important insights into SSL traffic
Pros and Cons
  • "The solution can be integrated with some network electors like Cisco Stealthwatch, Cisco ISE, and Active Directory to provide the client with authentication certificates."
  • "With the next release, I would like to see some PBR, so that you can do the configuration with the features."

What is our primary use case?

The main features of the Cisco Sourcefire are that it's a next-generation firewall with new features. It has application security, advanced malware protection, URL filterings, encryption, and decryption.

It is also used for email filtration and web application cyber protection.

The deployment model we used was on-premises.

How has it helped my organization?

This solution has improved our security level for our organization. It's a more intellectual system with many features that can help us with decryption. 

At this time, we have more than eighty-six percent of the traffic is SSL. We must decrypt this, and these devices provide us with tools for encrypted traffic inspection.

What is most valuable?

 It's user-friendly for engineers and works well for configuration and debugging.

The solution can be integrated with some network electors like Cisco Stealthwatch, Cisco ISE, and Active Directory to provide the client with authentication certificates.

What needs improvement?

This is a good solution, but some others may have some advantages. For example, Palo Alto has more useful and suitable application abilities. This solution has a better Firepower but the functionalities are not as good.

With the next release, I would like to see some PBR, so that you can do the configuration with the features.

For how long have I used the solution?

I have been using this solution for six years.

What do I think about the stability of the solution?

This solution is stable if we talk about boxes, and usually, it is a strong system, but with some software versions, we have had some trouble. I think that it depends on the manufacturers. 

What do I think about the scalability of the solution?

This solution is scalable and reliable.

You can use it in a cluster for one PC or a cluster for two different data centers.

How are customer service and technical support?

The support is good.

For customers, there are many features and we try to resolve as many issues as we can, but we only have access to some of the core elements. They can only be resolved by contacting technical support.

How was the initial setup?

The initial setup and configuration are easy.

You can create panels with deeper functionalities, but you need a bit more experience with the technology. 

What other advice do I have?

Providing videos and materials are useful, but really what you need is the experience in analyzing logs. Without that, you wouldn't be able to problem-solve on your own, even with the assistance of videos.

I would recommend this solution. It's reliable and scalable, with easy installation and integration.

I would rate this solution an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Cisco Sourcefire SNORT Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2024
Buyer's Guide
Download our free Cisco Sourcefire SNORT Report and get advice and tips from experienced pros sharing their opinions.