TOFIK AHMED - PeerSpot reviewer
Ict User Support Technician at Jju
Real User
Top 10
Not user-friendly, or stable, but is easy to deploy
Pros and Cons
  • "The most valuable feature is endpoint protection."
  • "The solution is complex and can be more user-friendly."

What is our primary use case?

The primary use case of the solution is firewall protection.

What is most valuable?

The most valuable feature is endpoint protection.

What needs improvement?

The security of the solution has room for improvement.

The solution is complex and can be more user-friendly.

The stability and scalability can be improved.

For how long have I used the solution?

I have been using the solution for over one year.

Buyer's Guide
Cisco IOS Security
May 2024
Learn what your peers think about Cisco IOS Security. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
769,630 professionals have used our research since 2012.

What do I think about the stability of the solution?

The solution is not stable.

What do I think about the scalability of the solution?

The solution doesn't have the proper bandwidth source to be scalable.

How was the initial setup?

The initial setup is straightforward.

The deployment takes about two hours.

What other advice do I have?

I give the solution a six out of ten.

We have over 1,000 people using the solution in our organization.

We require around ten people for the deployment and maintenance of the solution.

I do not recommend the solution because it is not secure and is complex.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Director at Cros Elements LLC
Real User
Top 20
Powerful, easy to set up, and nice interface
Pros and Cons
  • "The security is very good."
  • "Sometimes I find it difficult to manage. Some configurations are difficult for new engineers, for example."

What is our primary use case?

We're using it for internet traffic security. It's for protection. 

What is most valuable?

We don't have a problem with the user interface and it is pretty user-friendly.

We don't mind the cost.

The security is very good. 

Cisco is very good, very powerful. 

It's a reliable, stable product in general. It's better than the competition. 

The product is easy to set up. 

It is a stable product.

We find the product to be scalable. 

What needs improvement?

How to improve the solution depends on the usage. 

Sometimes I find it difficult to manage. Some configurations are difficult for new engineers, for example. 

It could be more flexible. 

For how long have I used the solution?

I've been using the solution for the last ten years. 

What do I think about the stability of the solution?

This is a very stable, reliable product. There are no bugs or glitches. It doesn't crash or freeze. 

What do I think about the scalability of the solution?

It's a scalable product. 

We have 500 to 600 people using the solution.

How are customer service and support?

Before, it was very easy to get in touch with support. However, it's become more difficult. It can take a long time to get an answer. We also have to deal with time differences, which can make it harder to get an answer. 

How was the initial setup?

It is very easy for me to implement the solution. It's very good, it's very easy. There are command planning and equations. Cisco is very simple. We don't have issue with Cisco.

The deployment depends on the product you use and the network design. 

You can do it in small batches. It can take some time to refresh. It might take one or two days. 

What's my experience with pricing, setup cost, and licensing?

The cost may be around $5,000 to $10,000 a year. If you want support you have to pay at least this price. 

What other advice do I have?

We are a Cisco customer and end-user. 

We've been using the mid-range version since 2012.

I'd rate the solution around eight out of ten. 

Cisco is great. It's likely number one in the world. I'd recommend the solution as it is a very powerful product. However, it's best to have Cisco experts on staff or available to you to make things easier. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Cisco IOS Security
May 2024
Learn what your peers think about Cisco IOS Security. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
769,630 professionals have used our research since 2012.
Vice President - Network and Infrastructure at NJA LLC
Real User
It covers everything but is especially effective when a lot of the traffic is in layer 7
Pros and Cons
  • "We are able to filter a lot of traffic especially when a lot of the traffic is in layer 7."
  • "It covers everything we need it to without looking to secondary solutions."
  • "The user interface needs to be improved."
  • "Signatures and other critical definitions need to be updated more frequently."

What is our primary use case?

Our primary use is just as a firewall. That is pretty much it.  

How has it helped my organization?

We are able to filter a lot of traffic. The is especially effective when a lot of the traffic is in layer 7 — the internet aspect of security for application services.  

What is most valuable?

I think the multi-layered approach is valuable. Just the fact that it covers everything on the LSA (Local Security Authority) right up to layer 7, in-depth packet analysis, and all that. It covers everything we need it to without looking to secondary solutions.  

What needs improvement?

I think the user interface for IOS Security needs to be improved.  

I think the signature updates and all the other critical definitions need to be updated more frequently.  

For how long have I used the solution?

We have only been using IOS (Internetwork Operating System) Security since about 2016. So we have worked with it for about four years.  

What do I think about the stability of the solution?

The stability of the product is okay. There were not really any bugs or glitches that I can remember.  

What do I think about the scalability of the solution?

The scalability aspect of it is that it is one of those products where you have to incorporate additional hardware. It is a vertical scale, so you add on the boxes you need and bond them together. Of course, it costs more to scale that way than something that would be a software upgrade. You have got to pay to scale and to get more features.  

Our clients are generally small to medium-sized businesses. Cisco IOS is a pretty good fit for that range of clients.  

How are customer service and technical support?

I have used the Cisco technical support and they were okay. Rating them out of ten, I would give them an eight or nine-out-of-ten. They have a pretty good system with decent response time and accuracy. They are good overall and in comparison to other services. They offer 24/7 service, which is a benefit.  

Which solution did I use previously and why did I switch?

I was actually using Cisco products more in the past and use them as a consultant. Right now, Sophos is the only one I have been using. It just came about through one of those situations where we were able to partner up with Sophos. That is really the reason for the change.  

How was the initial setup?

Setup and installation are pretty much straightforward. Comparing the installation to Fortinet or Sophos they are all the same.  

What's my experience with pricing, setup cost, and licensing?

The pricing for IOS Security is okay. It is competitive. It costs more when you have got the need to pay for more features. You have to buy more boxes and tie them together to upgrade to the next level.  

Which other solutions did I evaluate?

I have used Fortinet in the past too as well as Sophos and other Cisco products. They are all similar and if you know how to use them they are virtually all the same.  

What other advice do I have?

The advice that I would give to others looking into implementing this product is that I think they need to do their benchmarking. They should do due diligence beforehand in terms of their traffic.  

On a scale from one to ten (where one is the worst and ten is the best), I would rate this product overall as about an eight-out-of-ten. I do not know how they could realistically improve on that much. You never keep up with the hackers, they are always a step ahead of us when it comes to security.  

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
President at www.virtualtechsolutionsusa.com
Real User
Prevent unauthorized use of network resources and integrate branch offices with reliability
Pros and Cons
  • "Completely integrates branch offices with perimeter security."
  • "The capabilities for scalability with this product are huge"
  • "Cisco is head-and-shoulders above all of the competition when it comes to technical support."
  • "The pricing is the only con for this product."

What is our primary use case?

Some of our uses for this product are on-premise-based and then some are cloud-based. Mostly, we are cloud-based right now because we are getting away from physical architecture moving forward into the cloud as is Cisco. It allows going from considering CapEx (Capital Expenditure) to OpEx (Operating Expense, Operating Expenditure). That is one of the important things that it allows us to do. It is easier to have solutions cloud-based when it makes sense. All the updates and maintenance get taken care of on their side which is a benefit.  

On the cloud, we have both public and private services. It depends on what we are doing. If we have a client that is a hospital, they have got to be HIPAA (Health Insurance Portability and Accountability Act) compliant. We also recommend private cloud services for some huge retailers that have to be PCI (Payment Card Industry) compliant.  

We use it mostly just for prevention. Basically to prevent unauthorized use of network resources. They use it for routing capabilities, threat mitigation, worms, and viruses. A lot of times, it is used for the network application layer threat.  

How has it helped my organization?

The solution does not do anything for us directly as we use it with other clients. We are a large IT company. We hear from clients who tell us what they want. We just find solutions for what they tell us they need. Everyone has a different flavor of what they are looking for and what they are looking to fix.  

The Cisco IOS (Internetwork Operating System) firewalls are mostly set up for branch offices in small to medium business environments or for managed services. Those are the clients we usually use this solution for. It is usually only used for a specific thing to fill a specific need. It might be NAT (Network Address Translation), it might be a guideline or restrictions, it might be that they can have the option to make a solution work on cloud or on-premises. It could be deployed so they have the option to either use CapEx or OpEx. It helps to create options for those types of things.  

What is most valuable?

I would say that the most valuable thing is probably the Application Visibility and Control which is how it controls the application traffic on the network. I like the IPS (Intrusion Prevention System), the IOS content filtering, and the NAT network translation. I like the way it completely integrates branch offices in our perimeter security.  

What needs improvement?

A few things have room for improvement in your opinion. That would start with cost. Cisco products are more expensive than the competition, but the additional cost usually gets absorbed by the name recognition. Most people have Cisco or have familiarity with it, so they go with it. If they want the top quality product, they immediately feel comfortable with the Cisco name brand. That is where we come in as consultants. We bend over backward to make product comparisons and framing for solving the needs posed by an organization. I see something is a better fit for them that they could use. It would reduce their CapEx, their expenses, and it would fit them better all at the same time. The client may still want Cisco despite the recommendation that we make. But usually, that is what it is. Cisco fits, and if they want to spend the money, we make sure that it is within their budget. They feel more comfortable with Cisco, and they have had Cisco in the past, so we go with Cisco then.  

Cisco is great. A lot of the tech companies are doing really well. But Cisco is still in the forefront. They are on top of this category of products. I can not think of anything else they could do because they cover pretty much everything that you would need a firewall for. Then you get Cisco's support behind the products.  

I would think it would be a lot better for us and we could make more money if we try to recommend that clients put drop-in boxes at every location. But we do not choose to do that unless there is a purpose for it. In most cases, we would prefer clients to go the OpEx route. It takes a lot to offset the cost of Cisco so if they are going to do a cloud solution, their costs are metered per month by whatever solution they have. That is a lot better for projecting costs, and then there is the benefit of everything being upgraded in the cloud for them. They do not have to worry about anything. It just works.  

For how long have I used the solution?

We have been using Cisco for as long as Cisco has been around. It is hard to answer the question of when, exactly, we started using this product because they have been upgrading or changing the product as it evolved over the years. It is basically the same foundation and they build upon that over time. I can just say that we have been either using this product or something very similar for a long time.  

What do I think about the stability of the solution?

Cisco IOS Security is stable, very stable.  

What do I think about the scalability of the solution?

The capabilities for scalability with this product are huge. It is very scalable.  

A lot of our clients have a small main office with accounting and human resources that are headquarter-based. Most of them have other remote sites and branch offices. Whether it is a bank or a finance company, it is easy for employees in those particular roles to be able to pull applications down. It takes a lot of stuff off what would have to be handled by the network firewall. They do not have to worry about so many threats when they are bringing up applications to use and if there are compliance or regulating issues that they have to be aligned with. But that is the type of environment where this product can be used to scale effectively.  

How are customer service and technical support?

Cisco's technical support is very good. There are a couple of competing products that I know do not have support that is as good. Palo Alto does not have particularly good technical support, for example, but most of the rest of them do. Even so, Cisco is head-and-shoulders above all of them.  

For tech support, independent of the cost of the product, I would definitely give Cisco a ten-out-of-ten.  

Which solution did I use previously and why did I switch?

We just had a client go with Cisco Meraki and we put a couple of those in. Then we had a Cisco Nexus installation and they topped that by integrating it with perimeter firewalls for their remote locations or branches.  

We currently use really any brand of product in consideration for our consultations. There is not any particular brand we are married to, and we have used them all, pretty much. We do not use all the solutions ourselves. We get feedback from our clients and the companies we do work for. All the clients that we get give us pretty good feedback on the recommendations and the products that they end up using. Otherwise, they would be angry with us. What we recommend has to fit their particular niche and that is what we have to be good at identifying.  

For instance, if a client comes to me and describes how their organization is set up, we react to that. If they say they are a finance company and they have accounting and finance concerns, there are some pain points that they are going to have solved. One of those is application-specific. Then you have to layer that with your regulatory concerns. HIPAA compliance is something I encounter with finance companies, banks, and medical facilities. Those types of companies do very well with CloudGenix because CloudGenix is application-specific. If you put their firewalls in place, those would be a good fit for that type of client. For everything else — manufacturing and all the others and things like that — Cisco would be number one. They outweigh the competition in terms of different companies that they fit niches for better because of the range and flexibility of the solutions.  

If the client's needs are application-based, then we start looking at another way with another solution. But Cisco does great with being PCI and HIPAA compliant and all that, but if you only consider Cisco for every installation, that means you are pulling everything from one pool. You are not looking closely at the specifics.  

How was the initial setup?

I think that the initial setup is very straightforward. Most of the firewalls are straightforward and not too complex. When you are setting up a network with something like Merakis, or if you are looking at working with CloudGenix, then that is where you start to get a separation of difficulty in installation and will notice that it becomes a little bit harder to set up.  

What other advice do I have?

My advice to people and companies considering this solution is to just do the research. Do compatibility research to compare with the other solutions that are out there. Definitely make sure that the firewall you choose is designed for your network architecture, application-layer attacks, and virus and worm protection. If that coverage is what you are looking for and you have an analog phone system. You might not be ready to go to VoIP (Voice over Internet Protocol) yet because you do not want to lose the phones that you have got. Some people add to that base as they scale. We can use something called SIPs (Session Initiation Protocol), for connecting all those analog phones to the VoIP. That is a good indicator that a Cisco firewall will be a good solution for you because it protects the unified communication and guards the SIPs, endpoints, and call-control resources.  

On a scale from one to ten (where one is the worst and ten is the best), I would rate this product overall as a ten, for sure, if you consider its advantages over the competition. If you add in pricing, I would have to lower that to a nine-out-of-ten. Price is the only place that I figure Cisco could do something. Or if they could offset the cost of their boxes using a cloud solution. We had a client do that. They had boxes, but they were trying to figure a better way to scale. I suggested to them that they just move the areas that they were scaling to the cloud. They did it with the new branches they have added, and now they are waiting to phase out their boxes. They will eventually move over to a complete cloud-based firewall solution.  

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Solution Architect at Bilicha Technology
Real User
Supports mobile devices on an enterprise network firewall including iOS and Android
Pros and Cons
  • "We use Cisco IOS Security mostly for routers to route off the firewall. It's a next-generation device."
  • "Most of their features are meant for Cisco. You cannot integrate them with any other vendor."

What is our primary use case?

I use Cisco IOS Security. We install it for people. We have a very small network station. We don't use Cisco IOS Security very often, but we install it for clients. 

We use Cisco IOS Security mostly for routers to route off the firewall. It's a next-generation device. With firewalls, we can connect the solution for the mail cloud. 

We've deployed with Fortinet FortiGate. We don't use it much. We use Cisco IOS Security to manage for enterprise clients.

Our primary use case for this solution is in the insurance industry.

How has it helped my organization?

Cisco IOS Security has not improved my organization. We use it for our clients. It helps their workers to be more secure in operations.

What is most valuable?

We interpret the additional protection to be very important now. Cisco IOS Security is used with client mobile devices on the firewall.

What needs improvement?

We don't love everything about the product. For now, it's what we're using. It's okay. It is difficult to set up. The training is okay. The pricing is standard.

It will be great if they can make it more easy to use the features. The interface is not user-friendly, but a normal IT technician can handle it.

Most of the features only work with Cisco equipment. It's about connectivity. Most of their features are meant for Cisco. You cannot integrate them with any other vendor.

Cisco needs to be more flexible with the integration of other solutions.

For how long have I used the solution?

I've been working on this for let's say three years now.

What do I think about the stability of the solution?

It's not stable if you don't have Cisco gear in your network. If you don't have Cisco equipment within your network, you cannot access powerful pieces of the software.

What do I think about the scalability of the solution?

The scalability of Cisco IOS Security is good. It's very fast. It's not universal because most of the features require you to have Cisco equipment in your network. 

How are customer service and technical support?

If you ask technical support on how to solve some issues, it does help. We do fine with Cisco support. It comes with the equipment.

We provide our clients with six months of in-house support. We pay Cisco for it. The support is okay.

How was the initial setup?

The initial setup is straightforward, but when it comes to complex settings like the firewall, it is not easy. Most of the features that come with it work only with Cisco devices.

You have to have experience before you try to use it. You need to make sure you have it your router by Cisco. Some features only work with Cisco equipment.

What we do is we set up everything. We have to go on-site. It doesn't take time to deploy it. The time required to work on the project can take up to two weeks.

What about the implementation team?

We did the setup mostly with our team. We are consultants. We worked with a reseller. Cisco has an integrator software team too.

What's my experience with pricing, setup cost, and licensing?

Our licensing costs for the solution are on an annual basis. It should be every five years.

What other advice do I have?

On a scale from 1 to 10, I would rate Cisco IOS Security at 9/10.

Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
PeerSpot user
Senior Presale Agent
Real User
Beneficial posturing, scales well, and helpful support
Pros and Cons
  • "The most valuable feature of Cisco IOS Security is posturing."
  • "Cisco IOS Security could improve by having more compatibility with other Cisco solutions."

What is our primary use case?

The main purpose of Cisco IOS Security is for our data center. It connects each node and user to the network.

What is most valuable?

The most valuable feature of Cisco IOS Security is posturing.

What needs improvement?

Cisco IOS Security could improve by having more compatibility with other Cisco solutions.

For how long have I used the solution?

I have been using Cisco IOS Security for approximately three years.

What do I think about the stability of the solution?

Cisco IOS Security is a stable solution.

What do I think about the scalability of the solution?

The scalability of Cisco IOS Security is good. I can increase and decrease elements when needed.

We have approximately 45,000 people that can use the solution. Additionally, We have approximately 1,000 IT managers, technicians, and other users who directly use this solution.

How are customer service and support?

The support from Cisco IOS Security was very helpful.

I rate the support from Cisco IOS Security a four out of ten.

Which solution did I use previously and why did I switch?

I previously used another similar solution.

How was the initial setup?

I can do all the implementation of the solutions through the Cisco DNA Center. I can manage the Cisco IOS Security configuration. The whole process can be complex. Additionally, when we cannot connect to the internet we need to do manual configuration.

The full setup can take a couple of hours. However, initially, it took to use a couple of weeks.

What about the implementation team?

We did the implementation of Cisco IOS Security in-house.

We have two service engineers that are involved in the deployment and maintenance of the solution. They have the appropriate training needed to support the solution.

What other advice do I have?

I rate Cisco IOS Security an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Director Network Engineer at Therap Services
Real User
Offers good security and is easy to use
Pros and Cons
  • "The stability of this solution is excellent."

    What is our primary use case?

    Our primary use case for this solution is internet security at the edge.

    How has it helped my organization?

    Cisco IOS Security gives us a level of trust at the edge as far as being the first line of defense for anything that's trying to get into our network.

    What is most valuable?

    The feature I find most valuable is that the solution doesn't really change from year to year. The basics are there and I have so much experience with it that it's easy to use. I also like the security this solution offers.

    What needs improvement?

    External threats are changing every day, so there are new features coming in. We're more into the command line interface rather.

    For how long have I used the solution?

    Offers good security and is easy to use

    What do I think about the stability of the solution?

    The stability of this solution is excellent. 

    What do I think about the scalability of the solution?

    We are very satisfied with the scalability of this solution.

    How are customer service and technical support?

    The technical support is excellent. We've contacted the tech team a few times and the turnaround time was always almost immediately.

    Which solution did I use previously and why did I switch?

    We've always been using this solution and we haven't seen a need to change from it so we haven't looked at other vendors in quite a while because we are totally satisfied with what we have.

    How was the initial setup?

    The initial setup was straightforward and we did the deployment ourselves. We could go on the internet for any reference that we needed.

    What's my experience with pricing, setup cost, and licensing?

    We have to renew our license every three years.

    What other advice do I have?

    My rating for this solution is a ten out of ten because it does everything I need and it is easy enough to use. My advice to others is to definitely have it on their list of vendors to take a look at. I really recommend this solution.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    SameerBali - PeerSpot reviewer
    Network Architect at Syriatel Mobile Telecom
    Real User
    Top 5
    Secure, cost effective, and easy to install
    Pros and Cons
    • "It is less expensive than alternative firewalls."
    • "While Cisco IOS Security is stable and scalable, I would like to see it improved to be even better."

    What is our primary use case?

    We can use iOS security for a variety of security features. We can use it to run DPM. We run encrypted data and can use it for zone-based firewalls, to a zone-based firewall.

    I use VPN solutions such as site-to-site or user-site VPN, and some do not require a firewall.

    What is most valuable?

    It is less expensive than alternative firewalls.

    What needs improvement?

    While Cisco IOS Security is stable and scalable, I would like to see it improved to be even better.

    For how long have I used the solution?

    I have been working with Cisco IOS Security for three months.

    I use version 12.4 and I use 15 and above for the router.

    What do I think about the stability of the solution?

    Cisco IOS Security is very stable.

    What do I think about the scalability of the solution?

    Cisco IOS Security is a scalable solution.

    We have approximately 50 users.

    How are customer service and support?

    We have not contacted technical support.

    I don't have any critical issues, and I haven't had any open technical tickets with support. Everything is fine, but I work in security with multi-media solutions. We haven't had any problems.

    How was the initial setup?

    The installation is straightforward. It's easy, we didn't have any problems with the installation of Cisco IOS Security.

    I have three or four technical teams to help me work on publishing.

    What's my experience with pricing, setup cost, and licensing?

    Cisco IOS Security requires a license.

    With Cisco, we have a variety of licenses. They have smart licenses that can be provided for one year, two years, three years, five years, and seven years. Alternatively, they have perpetual licenses available. I am working with a perpetual license, but not a smart license.

    What other advice do I have?

    Before we can use any security feature on the Cisco router, we must first purchase an iOS security license.

    Yes, I would recommend this solution. It is more stable and less expensive than other firewalls. In some cases, it saves money for the project or the companies that work with it.

    I would rate Cisco IOS Security an eight out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Buyer's Guide
    Download our free Cisco IOS Security Report and get advice and tips from experienced pros sharing their opinions.
    Updated: May 2024
    Buyer's Guide
    Download our free Cisco IOS Security Report and get advice and tips from experienced pros sharing their opinions.