Most Helpful Review
We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
Integration with all the other Cisco tools is valuable.
We moved from a legacy firewall to the ASA with FirePOWER, increasing our Internet Edge defense dramatically.
Cisco ASA NGFW significantly improves our bank. It protects any high-value products that we use from hackers, viruses, malware, and script-bots. It gives us metrics on network traffic as well as what kind of attacks we are getting from the outside.
Right now, Cisco ASA NGFW has given us a lot of improvement. We are planning to move to a new facility and will be a much larger organization.
The feature that I found most valuable is the overall stability of the product.
The stability of Cisco ASA is excellent compared to other products on the market. Because of our customer experience as an integrator company, our clients never report any performance problems. We have a good performance reputation with Cisco ASA.
I would say the Firepower module is most valuable. I'm trying more to transition to this kind firewall. I had to study a little on Palo Alto Networks equipment. There is a lot I have to learn about the difference.
We have multiple secure internal networks linked with our plants. We are from a oil company, so we have multiple plant areas which need to have restricted network access. Therefore, we are using it for restricting access to the plant area.
The UTM platform has been the most valuable.
The solution is very robust.
The most valuable feature for us was to implement negligent functionality, to direct functionality to viewer control and application control so we could disconnect, and at the same time, we installed checkpoints. We disconnected our proxy.
We can create a domain to separate and segregate some functions, some services.
The databases and its signatures are its most important features.
It provides visibility and drives organizational security.
It safeguards against cyber attacks.
If we are receiving spam emails, or other types of malicious email coming from a particular email ID, then we are able to block them using this solution.
The product has helped improve our organization by being easy to use and integrate. This saves time, trouble and money.
The most valuable network security feature is the network sandbox solution. This sandbox feature works on traffic flow.
Initially, we didn't have much visibility around what is occurring at our applications lower level. For instance, if we are exposed to any malicious attacks or SQL injections. But now we've integrated FireEye with Splunk, so now we get lots of triggers based on policy content associated with FireEye. The solution has allowed for growth and improvement in our information security and security operations teams.
The most valuable feature is the view into the application.
Application categorization is the most valuable feature for us. Application filtering is very interesting because other products don't give you full application filtering capabilities.
It allows us to be more hands off in checking on emails and networking traffic. We can set up a bunch of different alerts and have it alert us.
The scalability has not been a problem. We have deployed the product in very high bandwidth networks. We have never had a problem with the FireEye product causing latency issues within our networks.
With regards to stability, we had a critical bug come out during our evaluation... not good.
The product would be improved if the GUI could be brought into the 21st Century.
Cisco should improve its user interface design. There is a deep learning curve to the product if you are a newcomer.
There is no support here in Georgia. If something goes wrong, support is not always very helpful with the other firewalls or other products.
One of my main concerns, an area that could use improvement is in adjusting the need to buy a license to enable features.
Usually, the customers are satisfied, but I am going to recommend that all clients upgrade to FirePOWER management. I want Cisco to improve the feature called anti-spam. We use a Cisco only email solution, that's why we need the anti-spam on email facility.
The installation and integration of Cisco ASA with FirePOWER can be improved. The management with Fortigate is easier than Cisco ASA on FirePOWER. The management side of Cisco ASA can be improved so it can be more easily configured and used.
Most of the time, when I try to run Java, it is not compatible with ASA's current operating systems.
Specifically on the user experience, sometimes the set up of things, such as the VPN SSL, takes a lot of time to load and a lot of time to get up and running on every session.
The solution should be more user-friendly.
The solution could be improved if there was a better way to report. The reporting functionality is not really good. Even though it's not the major function. Maybe adding a way to make a custom report.
As we don't have a representative of Check Point in Mozambique, this makes it very difficult when we have some issues to resolve.
While the technical support is good, the Indian level technical support could use an upgrade.
I am not able to see a demo.
The interface needs improvement.
It would be a good idea if we could get an option to block based upon the content of an email, or the content of a file attachment.
As far as future inclusions, it would be useful to display more threat intelligence, such as the actual area of the threat and the origin of the web crawling (Tor and Dark Web).
They could also increase or improve the scalability because to my knowledge the biggest bandwidth can only support up to 10 gigs of input.
Improvements could be achieved through greater integration capabilities with different firewall solutions. Integrating with the dashboard itself for different firewalls so users can also pull tags into their firewall dashboard.
A better depth of view, being able to see deeper into the management process, is what I'd like to see.
Based on what we deployed, they should emphasize the application filtering and the web center. We need to look deeper into the SSM inspection. If we get the full solution with that module, we don't need to get the SSM database from another supplier.
I would love to see better reporting. Because you can't export some of the reports in proper formats, it is hard to extract the data from reports.
The initial setup was complex because of the nature of our environment. When it comes to the type of applications and functions which we were looking at in terms of identifying malicious threats, there would be some level of complexity, if we were doing it right.
Pricing and Cost Advice
Watch out for hidden licensing and incredibly high annual maintenance costs.
We paid about $7,000 for the Cisco firewall, plus another small Cisco router and the lead switch. It was under the combined license. It's a final agreement.
The cost is a big factor for us. This is why we are using it only in our restricted area. They are very much higher than their competitors in the market.
Licensing is expensive compared to other solutions.
Pricing is high, but it is essentially a corporate decision.
The cost is a bit high compared to other solutions in the market.
Cisco recently has become very expensive.
The cost is a bit higher than other competitive solutions on the market.
This cost is between 3,000 and 5,000 euros per year, so some other solutions are cheaper and the pricing should be improved.
The pricing is too high.
When I compare this solution to its competitors in the market, I find that it is a little expensive.
FireEye is comparable to other products, such as HX, but seems expensive. It may cause us to look at other products in the market.
The current pricing is much better than before because they now offer product-related promotions along with some changes in product licensing. The new pricing model is better than before.
We're partners with Cisco so we get a reasonable price. It's cheaper than Palo Alto in terms of licensing.
Because of what the FireEye product does, it has significantly decreased our mean time in being able to identify and detect malicious threats. The company that I work with is a very mature organization, and we have seen the meantime to analysis decrease by at least tenfold.
There are some additional services that I understand the vendor provides, but our approach was to package all of the features that we were looking to use into the product.
The pricing is a little high.
Pricing and licensing are reasonable compared to competitors.
Compared 37% of the time.
Compared 11% of the time.
Compared 9% of the time.
Compared 37% of the time.
Compared 21% of the time.
Compared 9% of the time.
Compared 17% of the time.
Compared 13% of the time.
Compared 12% of the time.
Also Known As
|Cisco ASA, Adaptive Security Appliance, ASA||FireEye|
Adaptive Security Appliance (ASA) is Cisco's end-to-end software solution and core operating system that powers the Cisco ASA product series. This software solution provides enterprise-level firewall capabilities for all types of ASA products, including blades, standalone appliances and virtual devices. Adaptive Security Appliance provides protection to organizations of all sizes, and allows end-users to access information securely anywhere, at any time, and through any device.
Adaptive Security Appliance is also fully compatible with other key security technologies, and so provides organizations with an all-encompassing security solution.
Block more threats and quickly mitigate those that do breach your defenses with the industry’s first threat-focused NGFW.
|Check Point UTM-1 delivers proven, best-in-class security ideal for use in industrial Ethernet and SCADA environments. Robust performance and central management provide unmatched value in a simple, all-in-one solution.|
FireEye Network Security is an advanced threat protection and breach detection platform that provides industry leading threat visibility and protection against the world’s most sophisticated and damaging attacks. By leveraging FireEye’s unique technologies and threat intelligence, FireEye Network Security detects what other security solutions miss, providing holistic security from the perimeter to the network core.
Start your two week free trial.
Learn more about Check Point UTM-1 [EOL]
Learn more about FireEye Network Security
|There are more than one million Adaptive Security Appliances deployed globally. Top customers include First American Financial Corp., Genzyme, Frankfurt Airport, Hansgrohe SE, Rio Olympics, The French Laundry, Rackspace, and City of Tomorrow.||AccessIT Group Inc., Accuvant, Cadre Computer Resources Inc., Compuquip Technologies Inc, Dimension Data North America Inc., Forsythe Solutions Group, Gotham Technology Group LLC, GuidePoint Security LLC, Iovations, IPS||FFRDC, Finansbank, Japan Advanced Institute of Science and Technology, Investis, Kelsey-Seybold Clinic, Bank of Thailand, City of Miramar, Citizens National Bank, D-Wave Systems|
Financial Services Firm19%
Comms Service Provider10%
Comms Service Provider21%
Financial Services Firm14%
Financial Services Firm36%