Cisco Secure Firewall vs. FireMon

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Cisco Secure Firewall
Score 8.5 out of 10
N/A
Cisco Secure Firewall delivers comprehensive threat protection for modern, distributed networks. Built to support hybrid workforces and multicloud environments, it enables Zero Trust access, application visibility, and secure remote connectivity. With integration across the Cisco Secure portfolio, including SecureX and Talos threat intelligence, the firewall powers organizations to detect and stop more sophisticated threats. Centralized management simplifies policy enforcement, orchestration,…N/A
FireMon
Score 7.9 out of 10
Enterprise companies (1,001+ employees)
FireMon is a real-time security policy management solution built for today’s complex multi-vendor, enterprise environments. Supporting the latest firewall and policy enforcement technologies spanning on-premises networks to the cloud, FireMon delivers visibility and control across the entire IT landscape to automate policy changes, meet compliance standards, to minimize policy-related risk. Since creating their policy management solution in 2004, FireMon states they've helped…N/A
Pricing
Cisco Secure FirewallFireMon
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
Cisco Secure FirewallFireMon
Free Trial
YesYes
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeOptional
Additional Details
More Pricing Information
Community Pulse
Cisco Secure FirewallFireMon
Considered Both Products
Cisco Secure Firewall
Chose Cisco Secure Firewall
I would say both are great piece of hardware and I'm not selecting one over another, as I have used both for different purposes and would like to do same for my clients.
Chose Cisco Secure Firewall
Cisco Umbrella and Cisco Secure Firewall serve complementary purposes rather than competing ones. Umbrella provides cloud-based protection for internet usage, while Cisco Secure Firewall delivers deeper network control, VPN capabilities, and segmentation. Cisco Secure Firewall …
Chose Cisco Secure Firewall
it has good features, working stable, well known configuration logic, well designed HA features
Chose Cisco Secure Firewall
Cisco was easier to manage and had fewer day-to-day issues with the product.
Chose Cisco Secure Firewall
Cisco Secure Firewall is worse than all of those in every way except for the Cisco Secure Client VPN software itself
Chose Cisco Secure Firewall
We are a Cisco shop, so it was easier to integrate.
Chose Cisco Secure Firewall
Palo Alto Networks Advanced Threat Prevention, Fortinet FortiGate and Juniper Advanced Threat Prevention
Chose Cisco Secure Firewall
functionality is very similar however I think Palo is simpler to use and troubleshoot logs.
Chose Cisco Secure Firewall
Cisco provides a far superior product based on our evaluations. Along with the integrations of or other Cisco products that are not available from other vendors
Chose Cisco Secure Firewall
Cisco Firepower 2100 Series
Chose Cisco Secure Firewall
Was made by upper management
Chose Cisco Secure Firewall
Fortinet is a great competitor but it has had a lot of vulnerabilities and fair share of issues. We chose Cisco Secure Firewall solely because we are a CIsco environment that uses a lot of the Cisco products. We use the Catalyst switches, the Meraki switches and access points …
Chose Cisco Secure Firewall
Cisco Secure Firewall is worth all the money spent. it allows you to create and manage your configuration in a very easy way, furthermore, with the analytics you can see what is happening in your network in real time, and this is very important with all the threats nowadays. …
Chose Cisco Secure Firewall
Fortinet and Palo both offer strong firewall capabilites but integrating them with the rest of our Cisco infra required additionnal efforts and multiple management consoles (so less visibility).
With Cisco Secure Firewall, everyting operates in a complementary and unified way …
Chose Cisco Secure Firewall
I have used from other vendors like Palo Alto, Fortinet, Ubiquiti. This product is the whole thing. I mean, when you're buying a product from Cisco, you're buying a support function, you buy a whole case for products. And with all that other products Cisco have, like the SNR, …
Chose Cisco Secure Firewall
Fairly similar in throughput.
Chose Cisco Secure Firewall
No problems with compatibility.
All the protocols are standards, so the implementation is natural (Vlans, TCP, routing protocols, etc ..)
Chose Cisco Secure Firewall
Software Stability: While the hardware is legendary for its reliability (low RMA rates), the software (FTD) has historically been prone to bugs during major version jumps.
FireMon
Chose FireMon
FireMon gives us more flexibility when deploying the solution. Integrates with cutting-edge security solutions
Chose FireMon
We have only used firemon and there hasn't been a need to consider other products as we are satisfied with what Firemon can do.
Chose FireMon
Firewall Rule analyzer was used before I joined the company, but I have no experience with it.
Chose FireMon
OSSEC is open source and FM is much better from GUI and supportability stand points. Tufin and FireMon are very comparable
Chose FireMon
Best Compliance and Auditing tool to to identify the traffic that is hitting this rule.
Chose FireMon
I was not involved on the decision but having multiple brands in the company make sense to use a tool such as Firemon because it integrates easily with multiple vendors.
Chose FireMon
Infoblox DDI (BloxOne), Palo Alto Networks Prisma Cloud, Palo Alto Panorama, Palo Alto Networks Threat Protection, Palo Alto Networks WildFire, Palo Alto Networks Next-Generation Firewalls - PA Series and Fortinet FortiGate
Chose FireMon
Algosec and Tufin both are good tools but the cost involved for what they offer as services led us to go with Firemon.
Chose FireMon
i was not involved in the selection however i am quite happy with FireMon as the replacement of our aging product.
Chose FireMon
We have stuck with FireMon, and there is no reason to leave.
Chose FireMon
The Dell product ran on its own hardware, which failed often. The reports were not available to us in real-time, we had to request them. Many false detections of issues.
Chose FireMon
Both perform admirably with regards to providing that single pane of glass and visibility in a normalized view. They both provide great insight into where your organization stands in terms of compliance controls. In terms of upgrading and scalability, I would have to give the …
Chose FireMon
I has worked with Algosec and while they are very similar product, I find the FireMon is easier to understand and get rolling with. While both require some learning, FireMon is by far the easier one. Once you have an understanding of how things are arranged and labeled you can …
Chose FireMon
FireMon has the most supported devices.
The UI is easy to use and intuitive.
There is a comprehensive list of built in compliance controls that are missing in the competition.
Chose FireMon
To be blunt, at the time of purchase most of these products appeared to do the same things in the same ways. What really brought us to the table with FireMon six years ago was their willingness to earn our business, and to this day they remain just as committed to keeping our …
Chose FireMon
FireMon is way more flexible and the interface is tremendously better than any existing ones.
Chose FireMon
Algosec is a great tool, lower in cost as well.

FireMon has alot of capabilites, but our organization is not ready or have a use case yet for those features.
Chose FireMon
Tufin works much better with CheckPoint.
Chose FireMon
They are two very well done tools, FireMon is better suited for firewall rules evaluation, configuration and review, Tenable.io is better suited for CIS benchmarking. We ended up using both of them in the end, it really depends of your needs and what you are looking for, the …
Chose FireMon
Nothing like FireMon. We have other tools but 99% of them are looking at specific areas and not the enterprise security on a dashboard.
Chose FireMon
We performed a head-to-head PoC between FireMon and AlgoSec several years ago. Both platforms were well developed, but FireMon had the upper hand in three areas:
  1. Its UI was more unified and intuitive across the different components and products
  2. The reporting was better suited …
Chose FireMon
AlgoSec and Tufin both have initial issues during the POC stage, and FireMon even though with the changes they have made still works better and is more user friendly.
Features
Cisco Secure FirewallFireMon
Firewall
Comparison of Firewall features of Product A and Product B
Cisco Secure Firewall
8.2
Ratings
5% below category average
FireMon
-
Ratings
Identification Technologies8.10 Ratings00 Ratings
Visualization Tools7.80 Ratings00 Ratings
Content Inspection8.30 Ratings00 Ratings
Policy-based Controls8.50 Ratings00 Ratings
Active Directory and LDAP7.90 Ratings00 Ratings
Firewall Management Console8.00 Ratings00 Ratings
Reporting and Logging7.70 Ratings00 Ratings
VPN8.80 Ratings00 Ratings
High Availability8.90 Ratings00 Ratings
Stateful Inspection8.80 Ratings00 Ratings
Proxy Server7.80 Ratings00 Ratings
Best Alternatives
Cisco Secure FirewallFireMon
Small Businesses
pfSense
pfSense
Score 8.5 out of 10
NinjaOne
NinjaOne
Score 9.0 out of 10
Medium-sized Companies
Quantum Firewalls and Security Gateways
Quantum Firewalls and Security Gateways
Score 9.1 out of 10
Cisco Meraki MX
Cisco Meraki MX
Score 9.0 out of 10
Enterprises
Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series
Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series
Score 9.1 out of 10
Cisco Meraki MX
Cisco Meraki MX
Score 9.0 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
Cisco Secure FirewallFireMon
Likelihood to Recommend
8.4
(0 ratings)
7.9
(0 ratings)
Likelihood to Renew
9.5
(0 ratings)
6.8
(0 ratings)
Usability
7.3
(0 ratings)
7.3
(0 ratings)
Availability
9.5
(0 ratings)
7.3
(0 ratings)
Performance
9.9
(0 ratings)
9.1
(0 ratings)
Support Rating
7.8
(0 ratings)
7.7
(0 ratings)
In-Person Training
10.0
(0 ratings)
-
(0 ratings)
Implementation Rating
8.7
(0 ratings)
9.1
(0 ratings)
Configurability
10.0
(0 ratings)
-
(0 ratings)
Ease of integration
8.4
(0 ratings)
-
(0 ratings)
Product Scalability
9.5
(0 ratings)
7.9
(0 ratings)
Vendor post-sale
10.0
(0 ratings)
-
(0 ratings)
Vendor pre-sale
10.0
(0 ratings)
-
(0 ratings)
User Testimonials
Cisco Secure FirewallFireMon
Likelihood to Recommend
I can't think of scenarios where it is less appropriate, unless we are talking about real tiny businesses. More businesses will find Cisco Secure Firewall an outstanding tool to use, love, and trust from a reputable Network giant vendor. It is a must for businesses that want to focus on what they are doing, and leaving the network security for the pros.
Read full review
FireMon is best used in a large environment (for example, I have >100
firewalls in my environment). It's best used when trying to improve
security posture and showing changes in firewall security over time. It
might not be the best choice for smaller environments or those that aren't concerned about security management.
Read full review
Pros
  • Cisco's firewall actually does its job of blocking what it is supposed to block. We had an old Firewall that led to slippages. Cisco catches 97% of malware and vulnerabilities during testing. For Coitiar, that means an engineer who clicks a link with malware is handled quickly.
  • We actually tested if failovers would affect running sessions. We pulled our primary unit during a certification submission period. The firewall just switched, and the connection kept running.
  • The AI assistant in policy management is excellent, and for our lean team, it makes the whole process easy and efficient. I don't have to audit 200 policies manually; the AI steps in and does its thing.
Read full review
  • PCI Reporting - After identifying which firewalls and rulesets are in scope, producing a report artifact to satisfy PCI requirements on Firewall reviews is literally a two-click operation.
  • Storing Rule Metadata - FireMon stores metadata (prefilled fields, standard fields, and custom fields) for each rule in each policy which is valuable for context during firewall reviews in particular
  • API - FireMon exposes most if not all of its functionality via REST API
Read full review
Cons
  • I wish that the deployment of the updates to the sensors from the FMC was faster.
  • Cisco ASA firewall did a great job of authentication and authorization on the local firewall. FTD does not authorize users well in terms that an AAA must be setup to provide the granular tools that the ASA did.
  • Cisco's method of licensing the firewall can be improved. The FMC and the FTD are licensed through the Cisco software manager and there are instances where the devices are licensed but the firewall still displays and error due to licensing.
Read full review
  • Some features could be added to the existing functionality which include NAT rules usage
  • Rule expiration normalization from firewalls rather than entering them in rule documentation
  • .csv exports of the files from the firewall pane only gives usage for 30 days by default and that should be increased
Read full review
Likelihood to Renew
It works really well. We can do most anything we want or need to with it, and you don’t have to have a doctorate or multiple certs to necessarily figure it out. The thing that would probably have to happen to make us switch would be if we just got priced out - Cisco’s more powerful and higher bandwidth models cost a pretty penny.
Read full review
Once all the customization has been completed, the business is starting to see the return on investment. The visibility it provides into the network gear that is owned by other IT groups is immeasurable and has allowed us to apply standards across the board. The only thing I have concern with is their support documentation.
Read full review
Usability
i think overall after ALOT of tac cases it works allright now. But still have alot of issues if you use cloud based mangement. fx, if you open 2 windows of access policys, both of the pages, rules starte to jump form side to side. if you then open one more list, its start to jump even faster. if you close the 2 of them, its back to normal. ALSO the extended access lists for VPN, SUCKS. Its the tiniest window when opening the editor, and you are not able to give the rules names, Which means finding and editing rules SUCKS, its a horrible experience, and eveytime we have to we want to yell :P
Read full review
It save me time and I'm able to have the review - review the rule independently with using my time.
Read full review
Reliability and Availability
Rationale:


Strengths:


High availability (HA) and failover configurations ensure continuous operation during hardware or network issues.


Minimal unplanned outages reported; system remains responsive under full inspection load.


Centralized monitoring and proactive alerts help prevent downtime.




Minor Considerations:


Occasional maintenance windows or updates may require brief service interruptions.


Complex integrations with other systems may sometimes require extra attention to maintain uptime.




Overall, Cisco Secure Firewall is highly available and dependable, supporting business continuity and operational resilience.
Read full review
FireMon has been relatively stable overall. However, there have been a handful of times where we had issues with the console. For example, we couldn't update which devices to include in a security assessment. The initial suggestion from support was to just reboot it. It seems like there weren't many other options available such as to restart services before going to the extreme of a complete reboot.
Read full review
Performance
We have not had any performance issues with Cisco Secure Firewall, even with DPI and IPS enabled, we have not seen a performance hit. Emoployes have not complained about any slow network speeds that could have been attributed to the secure firewall it has always been something else within the office network.
Read full review
I'm not sure we have the largest implementation of FireMon out there but we do have a few 1000 devices being probed by FireMon. Overall, the system's performance has been rock solid. The console refreshes quickly and reports are generated within an expected timeframe.
Read full review
Support Rating
Our experience with Cisco TAC support for Cisco Secure Firewall has been very good. The support engineers are knowledgeable about the product and have many tools available to them to work "under the hood" of the firewalls or management center. When we've had equipment failures, the RMA process has been simple and straightforward.
Read full review
FireMon technical support is awesome! They respond quickly to our requests and they are well trained and very knowledgeable about the tool. Some issues have to be referred to the development team, but technical support largely provides solutions for any issues that we may have.
Read full review
In-Person Training
great center and Instructors
Read full review
No answers on this topic
Online Training
was a good training but questions was answered not so good. Training was "Fundamentals of Cisco Firewall Threat Defense and Intrusion Prevention (SFWIPF)".
Read full review
No answers on this topic
Implementation Rating
In the beginning transition from Adaptive Security Appliance to Cisco Secure Firewall did not look like the best choice. Solution was new, there were a lot of bugs and unsupported features and the actual execution in the form of configuration via Firepower Management Center was extremely slow. Compare configuring a feature via CLI on ASA in a manner of seconds (copy/paste) to deployment via FMC to Secure Firewall which took approx. 10 mins (no exaggeration). Today, situation is a bit different, overall solution looks much more stable and faster then it was but there's still room for improvement.
Read full review
Implementation is fairly simple. Most issues can be resolved by referencing manuals.
Read full review
Alternatives Considered
Cisco Secure Firewall works better with the Cisco ecosystem when we can utilize it and feels beefy enough when we utilize it in the data center. The Fortinet we have found are great, small cost boxes for remote offices with a better UI then Cisco Secure Firewalls. The feature set included with the firewalls feels similar from a security point of view.
Read full review
I has worked with AlgoSec and while they are very similar product, I find the FireMon is easier to understand and get rolling with. While both require some learning, FireMon is by far the easier one. Once you have an understanding of how things are arranged and labeled you can easily import firewalls and begin to work on them to improve them
Read full review
Scalability
Cisco Secure Firewall has never given us any trouble, it has stayed up at all times, upgrading the appliance has also become much simpler. We operate the appliance in a HA pair, so 0% downtime within our organisation. During switchover while upgrading, not a single packet seems to get lost, so this has been a very valuable asset to our company.
Read full review
Firemon Is easily scalable and maintainable with any size team. Although it requires some tech debt, it is well worth the time to invest to ensure compliance is visible and reports are accurate. Although our environment is very large we do not fully utilize the scalability of the Firemon product.
Read full review
Return on Investment
  • Given we are an higher Ed. organization, our reselling leveraged that and got us a significant discount on the appliances. We have our licensing rolled into an EA. I would say we save over $100k in adoption costs, and at least that much per year on licensing.
  • We combine event data from our Cisco Secure Firewall Firepowers with ISE, Umbrella, Catalyst Center and other utilities to assist us with troubleshooting and security issues. The event logs are a bit difficult to use, and don't always provide us with useful information, but we do use the to correlate events across the tools.
Read full review
  • It helps us save us time in determining what change was made and by whom.
  • Real time alerting is a great convenience in helping us know if something went wrong, we can immediately review the last report to determine what has changed.
  • Allows us to determine what rules are not used and if said rules are still required.
Read full review
ScreenShots

Cisco Secure Firewall Screenshots

Screenshot of Cisco Secure 1200 Series Firewall FamilyScreenshot of Cisco Secure 4200 SeriesScreenshot of Cisco Secure 4200 SeriesScreenshot of Cisco Secure Firewall 1200 Stack FamilyScreenshot of Cisco Secure Firewall 200 SeriesScreenshot of Cisco Secure Firewall 200 Series