We just raised a $30M Series A: Read our story

Cisco Sourcefire SNORT OverviewUNIXBusinessApplication

Cisco Sourcefire SNORT is the #7 ranked solution in our list of top Intrusion Detection and Prevention Software. It is most often compared to Cisco Stealthwatch: Cisco Sourcefire SNORT vs Cisco Stealthwatch

What is Cisco Sourcefire SNORT?

Snort is an open-source, rule-based, intrusion detection and prevention system. It combines the benefits of signature-, protocol-, and anomaly-based inspection methods to deliver flexible protection from malware attacks. Snort gained notoriety for being able to accurately detect threats at high speeds.

Cisco Sourcefire SNORT is also known as Sourcefire SNORT.

Cisco Sourcefire SNORT Buyer's Guide

Download the Cisco Sourcefire SNORT Buyer's Guide including reviews and more. Updated: October 2021

Cisco Sourcefire SNORT Customers

CareCore, City of Biel, Dimension Data, LightEdge, Lone Star College System, National Rugby League, Port Aventura, Smart City Networks, Telecom Italia, The Department of Education in Western Australia

Cisco Sourcefire SNORT Video

Archived Cisco Sourcefire SNORT Reviews (more than two years old)

Filter by:
Filter Reviews
Industry
Loading...
Filter Unavailable
Company Size
Loading...
Filter Unavailable
Job Level
Loading...
Filter Unavailable
Rating
Loading...
Filter Unavailable
Considered
Loading...
Filter Unavailable
Order by:
Loading...
  • Date
  • Highest Rating
  • Lowest Rating
  • Review Length
Search:
Showingreviews based on the current filters. Reset all filters
NAWAF-TAWAKOL
Pre-Sales Engineer at a tech services company with 51-200 employees
Real User
User friendly GUI, good filtering capability, and good technical support

What is our primary use case?

We are a system integrator and this is one of the solutions that we provide to our customers. This solution is for inspecting traffic. It works with the firewall, email, etc. This is for an on-premises deployment.

How has it helped my organization?

This is a solution that we trust for protection.

What is most valuable?

The most valuable feature of this solution is the filtering. It does well for eliminating email spam. The GUI is user-friendly.

What needs improvement?

The price of this solution could be improved. If the price is brought down then everybody will be happy. I would like to see a cloud-based version of this solution.

For how long have I used the solution?

I have been familiar with this solution for five years.

What do I

What is our primary use case?

We are a system integrator and this is one of the solutions that we provide to our customers.

This solution is for inspecting traffic. It works with the firewall, email, etc.

This is for an on-premises deployment.

How has it helped my organization?

This is a solution that we trust for protection.

What is most valuable?

The most valuable feature of this solution is the filtering.

It does well for eliminating email spam.

The GUI is user-friendly.

What needs improvement?

The price of this solution could be improved. If the price is brought down then everybody will be happy.

I would like to see a cloud-based version of this solution.

For how long have I used the solution?

I have been familiar with this solution for five years.

What do I think about the stability of the solution?

This is a stable solution.

What do I think about the scalability of the solution?

Scalability is something that Cisco has always cared about. There is no problem with it. For example, if you have one branch and you want to expand to two or three then it will work without any problems.

How are customer service and technical support?

The technical support is very good. I deal with several Cisco departments, and they have a good team. The team around the world is large and their support is very good.

We had a customer who had a problem with their server, and Cisco sent an entirely new one as a replacement. 

How was the initial setup?

The initial setup of this solution is a little bit complex compared to other solutions.

The average deployment takes approximately half a day. It depends on the environment. If we are connecting braches versus only connecting the head office, the length of time to deploy can change.

What's my experience with pricing, setup cost, and licensing?

Licensing for this solution is paid on a yearly basis.

What other advice do I have?

This solution has improved a lot in the past few years.

I would rate this solution an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
OS
Senior Engineer at a tech services company with 51-200 employees
Real User
User-friendly and provides important insights into SSL traffic

Pros and Cons

  • "The solution can be integrated with some network electors like Cisco Stealthwatch, Cisco ISE, and Active Directory to provide the client with authentication certificates."
  • "With the next release, I would like to see some PBR, so that you can do the configuration with the features."

What is our primary use case?

The main features of the Cisco Sourcefire are that it's a next-generation firewall with new features. It has application security, advanced malware protection, URL filterings, encryption, and decryption.

It is also used for email filtration and web application cyber protection.

The deployment model we used was on-premises.

How has it helped my organization?

This solution has improved our security level for our organization. It's a more intellectual system with many features that can help us with decryption. 

At this time, we have more than eighty-six percent of the traffic is SSL. We must decrypt this, and these devices provide us with tools for encrypted traffic inspection.

What is most valuable?

 It's user-friendly for engineers and works well for configuration and debugging.

The solution can be integrated with some network electors like Cisco Stealthwatch, Cisco ISE, and Active Directory to provide the client with authentication certificates.

What needs improvement?

This is a good solution, but some others may have some advantages. For example, Palo Alto has more useful and suitable application abilities. This solution has a better Firepower but the functionalities are not as good.

With the next release, I would like to see some PBR, so that you can do the configuration with the features.

For how long have I used the solution?

I have been using this solution for six years.

What do I think about the stability of the solution?

This solution is stable if we talk about boxes, and usually, it is a strong system, but with some software versions, we have had some trouble. I think that it depends on the manufacturers. 

What do I think about the scalability of the solution?

This solution is scalable and reliable.

You can use it in a cluster for one PC or a cluster for two different data centers.

How are customer service and technical support?

The support is good.

For customers, there are many features and we try to resolve as many issues as we can, but we only have access to some of the core elements. They can only be resolved by contacting technical support.

How was the initial setup?

The initial setup and configuration are easy.

You can create panels with deeper functionalities, but you need a bit more experience with the technology. 

What other advice do I have?

Providing videos and materials are useful, but really what you need is the experience in analyzing logs. Without that, you wouldn't be able to problem-solve on your own, even with the assistance of videos.

I would recommend this solution. It's reliable and scalable, with easy installation and integration.

I would rate this solution an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Learn what your peers think about Cisco Sourcefire SNORT. Get advice and tips from experienced pros sharing their opinions. Updated: October 2021.
541,708 professionals have used our research since 2012.
OH
Network Engineer at a financial services firm with 201-500 employees
Real User
A straightforward setup, and flexible enough to activate based on any rule that I want

Pros and Cons

  • "The whole solution is very good, and stable."
  • "The customization of the rules can be simplified."

What is our primary use case?

We use this solution, in conjunction with the Cisco Firepower 4000 series, for security in our data center. We also use it with a Cisco Firepower 2000 series for our VPN and internet access firewall.

What is most valuable?

The most valuable feature of this solution is support for everything in the same box, including IPS, High Availability, etc.

What needs improvement?

This solution needs to be more customizable.

The customization of the rules can be simplified.

For how long have I used the solution?

We have been using this solution for about five months.

What do I think about the stability of the solution?

This is a stable solution.

What do I think about the scalability of the solution?

This is a scalable solution that I can apply to any rule I want.

We have approximately five hundred and fifty employees who are protected by this solution.

How are customer service and technical support?

We contacted technical support many times during our deployment, but none of them were directly related to Sourcefire SNORT.

Which solution did I use previously and why did I switch?

Prior to this solution, we used McAfee. We switched because we replace our firewalls every five or six years.

How was the initial setup?

The initial setup of this solution is straightforward.

The deployment took approximately two days, which included applying the IPS rules in the Sourcefire policy.

One person is suitable for deployment and maintenance.

What about the implementation team?

A support company assisted us with the deployment.

What's my experience with pricing, setup cost, and licensing?

We have a three-year license for this solution.

Which other solutions did I evaluate?

We evaluated Fortinet FortiGate and Palo Alto before choosing this solution.

What other advice do I have?

We are satisfied with this solution. The whole solution is very good, and stable.

There are three modes that can be configured. The first is collectivity over security, the second is security over collectivity, and the third is a balanced mode. We have implemented a balanced mode, and it works just fine.

I would rate this solution an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
SA
Chief technology officer at Next Generation Systems Nigeria Limited
Real User
A great firewall with advanced malware protection and URL filtering

Pros and Cons

  • "Cisco technical support is unbeatable. It offers a premium service every time."
  • "The pricing needs to be improved. We have lots of low-budget clients around us. Budget constraints are always a deterrent in our market."

What is our primary use case?

We primarily use the solution as security on either side of the VPN.

What is most valuable?

The ability to roll out the services is an excellent aspect of the solution. They have advanced malware protection for URL filtering. I like working with both of these features.

What needs improvement?

The pricing needs to be improved. We have lots of low-budget clients around us. Budget constraints are always a deterrent in our market.

For how long have I used the solution?

I've been using the solution for eight years.

What do I think about the stability of the solution?

The solution has a considerable amount of stability.

What do I think about the scalability of the solution?

The solution is very scalable.

How are customer service and technical support?

Cisco technical support is unbeatable. It offers a premium service every time.

What other advice do I have?

We typically work with the on-premises deployment model.

Cisco Sourcefire is a great solution when it was packaged into the AMP giving it the ability to do URL filtering. However, Meraki seems to be going in the cloud direction. If the cloud is not interesting, then Cisco's firewall, Sourcefire, is great a great on-premises solution when it comes to advanced malware protection, URL filtering, etc. It's a great product.

I would rate the solution nine out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
BT
Network Engineer at a individual & family service with 10,001+ employees
Real User
Enables us to prevent and detect intrusion in our network and actually decrease our SLA

Pros and Cons

  • "Solid intrusion detection and prevention that scales easily in very large environments."
  • "Integration with other components — even Cisco's own products — can be enhanced to improve administrative experience."

What is our primary use case?

Our primary use for the solution is security, mostly in intrusion prevention.

How has it helped my organization?

With Cisco Sourcefire SNORT, we've been able to prevent and detect intrusion in our network and actually decrease our SLA (Service Level Agreement).

What is most valuable?

For us, the scalability of the solution is really useful. We were able to rebuild our network recently and we plan to add another 500 nodes throughout South America.

What needs improvement?

One addition to the current product that I think would be helpful is if it was integrated into the Cisco DNA Center. Between their security side, their routing, and the wireless side, they kind of have a gap. If they could bridge the gap and integrate all those in the DNA Center, I think that would be a good goal and something useful to users.

What do I think about the stability of the solution?

We haven't had any problem with the stability of the solution so far. It's been a solid platform and considering how quickly we scaled without any major issues, the stability really speaks for itself.

What do I think about the scalability of the solution?

When we recently upgraded our network the scalability of the product became obvious. We're planning to add about 500 extra nodes throughout South America and we're able to scale the platform to be able to utilize the solutions.

How are customer service and technical support?

I honestly haven't had to use technical support that much because we haven't had that many issues. I guess that says something about the quality of the product when you don't need to use tech support in an installation as large as ours.

Which solution did I use previously and why did I switch?

The main reason why we switched to this solution had to do with growth. We were growing at a very high rate at the time so we needed a solution that could handle a much larger architecture reliably. This was just one of the options that we were looking at and we really thought we'd benefit from the top-notch solution that the platform was.

How was the initial setup?

The initial setup was fairly simple. We did it a couple of years ago but I remember it went well. It was, I think, a three-month project and rolled over pretty easily into our expansion.

What about the implementation team?

The initial implementation was done with the assistance of a consultant. I don't remember the name of the group but it was a good experience. We enjoyed their experience and assistance very much.

Which other solutions did I evaluate?

There were a couple of other products that we considered at the time. None of them made it very far in the process because they just didn't have a lot of the capabilities that we were looking for. Cisco came out on top.

What other advice do I have?

I'd give the product a nine out of ten because it is excellent in scalability, ease of management, and ease of use.

The only reason it isn't a ten out of ten is some of the gaps in integration. I think if they could improve integration with other platforms to make it more fluid to connect between the different platforms and platform management, that would make it a much better solution. The integration issues are probably the only knock off I have on the product so far.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Cisco Sourcefire SNORT Report and get advice and tips from experienced pros sharing their opinions.