Protect your network with Cisco ASA
Use Cases and Deployment Scope
Cisco ASA is an excelent solution for protecting your network and allowing traffic from internet to your internal services. The performance is very good, you can administrate the device via CLI and via GUI (ASDM), the deploy via ASDM can take a little longer than CLI but is simplier. We have used Cisco ASA for publishing service to internet and as a gateway to the internet for the internal traffic.
Pros
- Robust device
- CLI commands from Cisco
- You can virtuallize the ASA
- It can work in HA Failover
Cons
- There's a bug where you can't have more than 200 host IP allowed in a VPN remote access
- Sometimes ASDM take a long time to save the changes
- It can improve the layer 7 filters for internet traffic
Likelihood to Recommend
It is a very good product for having as your perimeter for your network to internet, it works very good with NAT for publish services, but if you want to have a deep packet inspection on the traffic from your internal network to internet it is not the best solution, you can make IP filter, port filter, but you can't perform IPS functions or full packet inspection.
