We performed a comparison between Cisco Secure Firewall, Fortinet FortiGate, and Netgate pfSense based on real PeerSpot user reviews.
Find out what your peers are saying about Netgate, Fortinet, OPNsense and others in Firewalls."I haven't had any major problems so I haven't had to open a ticket with technical support."
"The most beneficial aspect of the Cisco Secure Firewall is the AnyConnect component within the firewall package, which we selected specifically for VPN usage due to its exceptional integration with various third-party devices and applications."
"One of the most valuable features of Firepower 7.0 is the "live log" type feature called Unified Event Viewer. That view has been really good in helping me get to data faster, decreasing the amount of time it takes to find information, and allowing me to fix problems faster. I've found that to be incredibly valuable because it's a lot easier to get to some points of data now."
"It is a very user-friendly product."
"The most valuable features are the IPsec VPN and web filtering."
"The product is easy to manage and simple. It works with the rest of our Cisco products. You can drop in new ones if you need more performance. The training and documentation provided are good."
"The implementation is pretty straightforward."
"This solution has good security, and it's a good product. You can trust Cisco, and there's support as well, which is really good."
"It is a good source for firewall protection."
"The flexibility and ease of configuration are the most valuable features."
"UTM/NGFW features and FortiCloud for logs and backups are awesome."
"The solution has very good threat and content filtering switches."
"The most valuable feature of this solution is the analytics."
"FortiGate has a very strong unified threat management system."
"It's an easy solution to set up."
"We use a southern institution that's audited for IT security and the reporting that automatically comes off the unit makes it much easier to meet compliance standards and makes it easier as far as the amount of time that has to be spent to compile that information. If you get your reporting set up correctly when you initially set it up, you just select the one you want and hit print. The auditing trail on it is the best feature."
"It has a good web cache. I used to use a DHCP server and DNS server. For my company, I use pfSense as a load balancing application."
"The features I have found best are ease of use, GUI, and performance."
"Easy to deploy and easy to use."
"Is good at blocking IP addresses."
"Centralized administration with multiple services, which allows for execution in several important functionalities of information security."
"The most valuable feature, for instance, is the ease of migrating configurations between different Netgate devices housed in the same box."
"The firewall sensor is highly effective, and it's easy to deploy. You can deploy pfSense with limited hardware resources. It's not necessary to have an appliance with much RAM to make it work. It's cost-effective and performs well."
"It is a stable solution. It is also easy to install and can be deployed and maintained by one team member."
"The solution’s GUI could be better."
"With regards to stability, we had a critical bug come out during our evaluation... not good."
"The annual subscription cost is a bit high. They should try to make it comparable to other offerings. We have a number of Chinese products here in Pakistan, which are already, very cheap and have less annual maintenance costs compared to Cisco."
"They could improve by having more skilled, high-level engineers that are available around the clock. I know that's an easy thing to say and a hard thing to do."
"Lacks a good graphical user interface."
"I'm working on a slightly older version, but what it needs is a better alert management. It's pretty standard, but there's no real advanced features involved around it."
"We are still running the original ASAs. The software that you are running for the ASDM software and Java application has never been a lot of fun to operate. It would have been nice to see that change update be redesigned with modern systems, which don't play nicely with Java sometimes. Cybersecurity doesn't seem to love how that operates. For us, a fresher application, taking advantage of the hardware, would have been a better approach."
"Comparing Cisco solution to others, it is expensive, it would be better for it to be cheaper."
"They are doing good, but they can improve the distributor assignment. The availability of the product and the timeline of delivery are the main things. The distribution should be swift, and the distributor should not reach out to end customers directly. They should work as a distributor. There should also be one more local distributor. Currently, there is only one distributor in Pakistan, and the rest of them are in UAE. It is difficult to work with only one distributor. Sometimes, you don't get along with the same distributor, and that's why they should have one more distributor. Their licensing should also be improved. The activation or renewal of the product should be done from the date of renewal, not from the date on which the license expired."
"With the reports, you can see it, and you can get good feelings so upper management can go, "Oh, wow. That looks pretty." However, it's very basic."
"One issue that I have had is that sometimes I need to monitor the traffic, so I need to filter it according to the user and which user is using it the most. I experience a bottleneck most of the time, particularly at the peak time when the number of contracts and users are at maximum."
"The feedback that I have received is that the performance could be better, and the user experience is not as good compared to a previous solution we used. It could be more user-friendly. Of course, it still works fine for our operations."
"If I had any criticism that I would give FortiGate, it would be that they need to stop changing their logging format. Every time we do a firmware upgrade, it is a massive issue on the SIM. Parsers have to be rebuilt. Even the FortiGate guys came in and said that they don't play well in the sandbox."
"The routing capability on the FortiGate devices has room for improvement."
"WAN load-balancing could be a lot better at detecting when a link is poor or inconsistent, and not just flat out dead."
"The initial setup and configuration are not intuitive and require training."
"Their support could be better in terms of the response time."
"The VPN feature of the solution could improve by adding better functionality and providing easier configure ability."
"Also, simplifying the rules for the GeoIP. Making it simpler to understand would be an improvement."
"Reporting and real-time monitoring, since I'm used to Watchguard's reporting features, it would be nice to have an embedded solution for reporting."
"Needs services on additional features, such as managing inventory and generating reports."
"I would like to see pfSense integrate WireGuard. Currently, pfSense uses OpenVPN, and there's nothing wrong with it, but WireGuard is a lot leaner and meaner."
"It's just not listed as FIPS compliant for where we're at now in government, which is an issue."
"The solution requires a lot of administration."