Cisco Adaptive Security Appliance (ASA) software is the core OS for the ASA suite. It provides firewall functionality, as well as integration with context-specific Cisco security modules. It is scaled for enterprise-level traffic and connections.
N/A
Cisco Firepower 4100 Series
Score 8.2 out of 10
N/A
The Cisco Firepower 4100 Series’ 1-rack-unit size is presented by the vendodr as ideal at the Internet edge and in high-performance environments. They further state that it shows what’s happening on your network, detects attacks earlier so you can act faster, and reduces management complexity.
Cisco ASA's are great for internal network connected access between a firewall and the central management server. And, for complex networks where high security requirements with overly strict compliance are necessary. For networks with limited connectivity to the core or for poor network connectivity these are not the best solution. There are other more stand-alone firewall's that do this better. These firewall's are a little more complex to set up to start with so significant knowledge of these devices is required to set them up and ensure they are best practice installed.
When we are asked by local partners which security equipment we use we always recommend our Cisco security products. The Firepower firewall is no exception and we can easily recommend this to others who need a fast, secure, and well built system that integrates well with all your existing hardware and software.
The failover process is clunky. When out Fortigate firewalls failed over, we lost 1 ping. When our Firepowers failover, whether it is on purpose or not, we experience a 2.5 minute complete outage.
Cisco could stand to improve their support documentation. I have found it difficult to find good directions for configuring these, especially when it comes to NAT and IPSEC tunnels.
To be honest there has been now great products out in the market compared to Cisco ASA. I beleieve Cisco has to do a lot of improvement in this area. The other defeiniete factors is the cost when it comes to renewals which is always a premium on Cisco products
In general, the Cisco Firepower 4100 Series works well, great performance, support a high volume of traffic, configuration, users, the device is powerful and once you have something configured you can be sure that it will rarely fail but for day to day troubleshooting or modifications needed can be a little complicated due to you have to deploy every change you make in the device and is not as fast as other devices, in general a deploy takes 5 minutes.
I generally have not noticed the outages, however since it's a machine it can malfunction, we need to implement the firewall infrastructure in such a way that it is highly available with device failure, region failure etc. Else any solution will be having the issues if they are not build with resiliency.
The support is usually very good and gets back to you very quickly. However I had some instances of when two engineers will give me wildly different answers to what I thought was a simple question. Overall however I do rate the support highly and they are generally always very good.
It was quite a good one, how ever requires an expertise to deploy hence the SMB segment would be finding it difficult to implement this product. The one good reason is that there are lot of ASA certified engineers in compared to the other certified engineers. Hence this resembles positively on the deployment as you have quite a lot of experienced engineer on your deployment
We were using [pfSense] before in our environment but we regularly facing difficulties over it due to software bugs & downtime. After implementing Cisco ASA, it resolved our availability issue & provides us a reliable solution with the best security features & easy to understand GUI.
Cisco Firepower 4100 Series deployment is straightforward and easy to implement. It is also can support high availability and able to achieve redundancy. Besides, firmware upgrade is quite simple and the process does not take much effort as the upgrade will be automatically done by itself. Cisco Firepower 4100 Series is also very cost effective compared with other similar ranges of firewalls.