TrustRadius: an HG Insights company

Cisco Firepower 1000 Series

Score8.2 out of 10

92 Reviews and Ratings

What is Cisco Firepower 1000 Series?

The Cisco Firepower® 1000 Series for small to medium-size businesses and branch offices is a family of four threat-focused Next-Generation Firewall (NGFW) security platforms designed to deliver business resiliency through superior threat defense. The vendor provides that they offers exceptional sustained performance when advanced threat functions are enabled. The 1000 Series’ throughput range addresses use cases from the small office, home office, remote branch office to the Internet edge. The 1000 Series platforms run Cisco Firepower Threat Defense (FTD) and Cisco® Adaptive Security Appliance (ASA) software.

Read more details.

Categories & Use Cases

Videos

Top Performing Features

  • High Availability

    Built-in capacity to prevent exposure if primary firewall stops working

    Category average: 8.7

  • Content Inspection

    Inspecting permitted application traffic by means of threat prevention, URL filtering and data filtering

    Category average: 8.3

  • Stateful Inspection

    Stateful inspection analyzes packet headers and contents of packets

    Category average: 8.4

Areas for Improvement

  • VPN

    VPN's implement encryption and anonymize IP addresses

    Category average: 8.9

  • Policy-based Controls

    Firewall policy controls enable administrators to create firewall policies controlling what data is allowed to traverse the firewall

    Category average: 8.6

  • Visualization Tools

    Visualization tools present administrators with data on applications traversing the network, who is using them, and the potential security impact.

    Category average: 7.6

Who Buys & Uses Cisco Firepower 1000 Series

Nice value for money

Use Cases and Deployment Scope

We are using Cisco Firepower 1000 Series in our customers networks, primarily as a Virtual Private Networks Remote Access concentrator, but also as a perimeter and DMZ FW. We are addressing problems as a segment separations, geo location blocking and Intrusion Prevention System that can block threats from very beginning.

Pros

  • Perimeter firewalling
  • Intrusion Prevention System threat blocking
  • Remote Access Connections
  • Site to Site VPN tunnels

Cons

  • VPN geolocation blocking exceptions
  • number of VLAN supported
  • Time of deployments

Return on Investment

  • Upgrade process is very straight forward for newer releases
  • No downtime for upgrades when in HA
  • Full IPS performance about 1G in 1120 platform

Alternatives Considered

Cisco Firepower 2100 Series, Cisco ASA 5500-X with FirePOWER Services and Cisco Firepower 4100 Series

Other Software Used

Microsoft Entra ID, Cisco Identity Services Engine (ISE), Cisco Application Centric Infrastructure (Cisco ACI)

Cisco Firepower 1000

Use Cases and Deployment Scope

Cisco Firepower 1000 series are used in remote branches where sensitive data needs to be secured but not at a large band with scale. It provides URL filtering Geo blocking and access control policies. Without being too high of a price point Firepower 1000 series can lock down a local network effectively.

Pros

  • Easy installation and lightweight
  • Can mass deploy with reproduce configurations

Cons

  • Could have a faster upgrade time
  • Could have configurations stored on a flat file to be able to backup and restore quickly
  • Could have AI leveraged to clean up rules

Return on Investment

  • Streamlined hardware replacement and quick deployment
  • Bulk orders and quick turn around times
  • Geoblocking and url filtering even at small sites

Alternatives Considered

Infoblox DDI (BloxOne), Trellix Intrusion Prevention System and Cisco ThousandEyes

Other Software Used

Netskope CASB, AWS Firewall Manager, Forescout Platform

Cisco Firepower 1000

Use Cases and Deployment Scope

Cisco Firepower 1000 is used at remote sites where there is a limited number of connections. They are compact and can fit easily in security cabinets without building out a larger telecommunication room and are robust without incurring any long periods of downtime. They are more budget-friendly than the 3000 series for straightforward cookie-cutter jobs.

Pros

  • Rugged and robust
  • Useful for simpler firewall requirements
  • Can be managaged by FMC after version 6

Cons

  • They can have ports with larger bandwidth
  • Wish their config files could be saved as a flat file
  • Wish upgrade speeds would be faster

Return on Investment

  • Firepower 1000 was successful in replacing the majority of our ASA devices
  • Firepower 1000 can implement geoblocking
  • Firepower 1000 can send logs to our SIEM

Alternatives Considered

Palo Alto Networks Advanced URL Filtering, ExtraHop Performance Platform and MixMode

Other Software Used

SDWAN|Link, Palo Alto Panorama, Juniper Mist Wi-Fi Assurance

Evaluating Cisco Firepower 1000 for mid-sized business

Use Cases and Deployment Scope

These are the main business problems...
1. Implement policies for Internet navigation: restrict sites directly from the firewall, eliminate our proxy
2. Protection against cyber attacks hacking, viruses, and malware.
3. Control of network traffic
4. Protection of confidential information:protect sensitive or confidential information from being accessed by unauthorized users or external threats.

Pros

  • Advanced threat protection
  • Network visibility
  • provides a robust and flexible set of security capabilities
  • Security automation

Cons

  • Price: The Cisco Firepower 1000 Series comes with a significant price tag
  • User interface: The Firepower Management Center (FMC) interface can be complex and overwhelming for some users
  • Performance impact especially when running multiple security modules

Return on Investment

  • Better security
  • optimization of network
  • Better network performance

Alternatives Considered

Cisco Meraki MX

Other Software Used

Cisco Meraki MX, Cisco Meraki MR

Stores protection

Use Cases and Deployment Scope

It implements the firewall cluster in a customer of ours' stores. It implements the perimeter-based security and VPN

Pros

  • VPN
  • Perimeter-based security
  • L7 application visibility

Cons

  • Configuration tools and portability
  • Capacity
  • ACL configuration

Return on Investment

  • Acceptable initial investment
  • Good for service costs in opex
  • Multi site management allows costs reduction

Alternatives Considered

Fortinet FortiGate and Cisco Meraki MX

Other Software Used

Fortinet FortiGate, Cisco Meraki MX, Check Point DDoS Protector