What users are saying about
Top Rated
186 Ratings
42 Ratings
Top Rated
186 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow noopener noreferrer'>trScore algorithm: Learn more.</a>
Score 8.3 out of 100
42 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow noopener noreferrer'>trScore algorithm: Learn more.</a>
Score 9.3 out of 100

Likelihood to Recommend

Cisco ASA

CISCO ASA is suitable for every organization from MID range to HIGH RANGE. However, for small customers, they can buy Cisco product but support cost will be the challenge. However nowadays one tool is never enough, but Cisco gives us a unified way of managing infra with there different solutions. I agree they are more stable products comparing any products which are available in the Market.
Jitu Mani Das | TrustRadius Reviewer

pfSense

For fast-growing or SME companies, pfSense is quite suitable because pfSense already had many advanced features such as VPN and multiple WAN / LAN. As a result, we just need to pay for expensive router frequently to upgrade our infrastructure.
Allan Leung | TrustRadius Reviewer

Feature Rating Comparison

Firewall

Cisco ASA
8.3
pfSense
7.2
Identification Technologies
Cisco ASA
7.7
pfSense
3.0
Visualization Tools
Cisco ASA
6.9
pfSense
6.0
Content Inspection
Cisco ASA
8.1
pfSense
8.0
Policy-based Controls
Cisco ASA
8.9
pfSense
7.0
Active Directory and LDAP
Cisco ASA
9.1
pfSense
4.0
Firewall Management Console
Cisco ASA
7.3
pfSense
8.0
Reporting and Logging
Cisco ASA
7.7
pfSense
6.0
VPN
Cisco ASA
8.8
pfSense
10.0
High Availability
Cisco ASA
9.4
pfSense
9.0
Stateful Inspection
Cisco ASA
9.3
pfSense
9.0
Proxy Server
Cisco ASA
7.9
pfSense
9.0

Pros

Cisco ASA

  • Consistent commands. A lot of the general commands used on other Cisco switches and routers also work here, making it easy script common tasks and changes across multiple devices without having to switch command structure.
  • Processing power. The ASA is incredibly fast and doesn't introduce much if any latency.
Brian Taylor | TrustRadius Reviewer

pfSense

  • pfSense is an excellent firewall - It logs all of your traffic. It has packages you can install to snort bad traffic.
  • pfSense has a tool called "p0f" which allows you to see what type of OS is trying to connect to you. You can filter these results and you can also block a specific OS from connecting to you.
  • pfSense is an excellent load-balancer: (Multi-WAN and Server Load Balancing) The fail-over/aggregation works very well. This is perfect if your business uses multiple ISP's to ensure your customers are always able to access their data. Also helps with bandwidth distribution as well.
  • VPN's - I am not entirely sure if this package was free with pfSense, but it does offer the ability to use OpenVPN which is what I am familiar with.
  • They also have IPsec in the settings as well, but I am not familiar with that enough to go into any detail with it.
  • As I mentioned I do use OpenVPN the only thing I don't care for with it is I can create OpenVPN configs for each user I want to be able to VPN into the network and I assumed each one would be "unique" but this does not seem to be the case. I could be doing it wrong, but if I create a config for a specific employee I would expect only that employee should be able to use that config, but I have been able to login to everyone that I made using my credentials.
  • I mentioned earlier that pfSense had a GUI.
  • I personally really think it is cool because it has a bunch of reporting graphs for monitoring your networks. I think when I become the full-time admin at the company I am going to try to talk them into getting me a TV I can mount on the wall and display all the graphs and real-time info pfSense shows so I can monitor what is going on with the network(s) at all times. Plus I think it would look rad.
Charles R. Coggins III | TrustRadius Reviewer

Cons

Cisco ASA

  • The gui interface is good, but often lacks the ability to perform full tasks without command line.
  • Integration with other products can be complicated and you may need to find the custom commands from the 3rd party or support to make it work.
  • A lot of their advanced features are present, but aren't fully integrated yet.
Anonymous | TrustRadius Reviewer

pfSense

  • There is no API for making changes. This can be a hindrance in environments where auto-deploying something needs firewall rules or HAProxy configs updated. Since all settings are stored in an XML file and then configs are generated from that, even manually updating config files cannot be done.
  • Beware that some network cards can have issues. pfSense is based on FreeBSD, so it's best to look on their compatibility list before deploying.
Aaron Smith | TrustRadius Reviewer

Likelihood to Renew

Cisco ASA

Cisco ASA 9.0
Based on 1 answer
I am committed to low-OpEx usage model, know most (nearly all) hw and sw features and have a good customer base to continue to use Cisco ASA.
Sergei Chernooki | TrustRadius Reviewer

pfSense

No score
No answers yet
No answers on this topic

Support Rating

Cisco ASA

Cisco ASA 8.4
Based on 12 answers
The support is usually very good and gets back to you very quickly. However I had some instances of when two engineers will give me wildly different answers to what I thought was a simple question. Overall however I do rate the support highly and they are generally always very good.
Fraser Clark | TrustRadius Reviewer

pfSense

No score
No answers yet
No answers on this topic

Alternatives Considered

Cisco ASA

Cisco made sense from the standpoint that my engineers already knew it and there was little learning curve. Personally, I prefer a purpose-built hardware solution. Untangle is not ready for the enterprise as a whole but works great to do web/application filtering . Checkpoint and Palo are VERY high cost and have few support options
Larry Chisholm | TrustRadius Reviewer

pfSense

Before pfSense we were using consumer and small business rated network appliances from Linksys, Cisco, Buffalo and Netgear. We were replacing them on average of every 6-12 months because they'd fail or would offer poor wifi availability.Switching to pfSense allowed us to use professional grade switches and wifi access points, offloading all of the services that the consumer grade products took care of, onto pfSense (DHCP, DNS, routing, firewall, VPN, etc).
Jim Rubenstein | TrustRadius Reviewer

Return on Investment

Cisco ASA

  • We've gotten every penny's worth of use with our Cisco ASA firewalls - they were a few thousand dollars to purchase, even in HA, and have been in production for over 5 years
  • I'm glad that when the Cisco ASA IKE buffer overflow vulnerability was released, Cisco provided a code update, even though the 8.2-series code was EOL. This saved us and many companies from scrambling and spending big $ and time to put a workaround in.
Anonymous | TrustRadius Reviewer

pfSense

  • Moving to a FWaaS solution installed on a decent computer the initial investment was moderate to cover 50 to 250 users, but still being cheaper that a Fortinet, Cisco ASA, or a Sophos UTM.
  • Paying only for support can be a double edge knife, cause you need to identify what's the goal of the request, or your drown into a an endless list of requirements.
  • To stay in the top with the half of a regular investment pFSense gives a wide variety of plugins that will give you a deep knowledge of your security flaws and strong points.
Victor Arana | TrustRadius Reviewer

Pricing Details

Cisco ASA

General

Free Trial
Free/Freemium Version
Premium Consulting/Integration Services
Entry-level set up fee?
No

Cisco ASA Editions & Modules

Additional Pricing Details

pfSense

General

Free Trial
Free/Freemium Version
Premium Consulting/Integration Services
Entry-level set up fee?
No

pfSense Editions & Modules

Edition
SG-1100$1791
SG-2100$2291
SG-3100$3991
SG-5100$6991
XG-7100-DT$8991
XG-7100-1U$9991
XG-1537$1,9491
XG-1541$2,6491
  1. per appliance
Additional Pricing Details

Rating Summary

Add comparison