Cisco offers the Firepower 2100 Series NGFW, designed to allow businesses to gain resiliency through superior security with sustained performance. The Firepower 2100 Series has a dual multicore CPU architecture that optimizes firewall, cryptographic, and threat inspection functions simultaneously, to achieve security doesn’t come at the expense of network performance.
Technician in Information Technology (201-500 employees)
Use Cases and Deployment Scope
Cisco Firepower 2100 series - specifically Cisco Firepower 2130 in my organization is used as a main VPN concentrator. Main business problems the product addresses are connecting remote access users to our data center and out of band networks where services usually seat. The platform is suitable directly for deployments in bigger data centers or DMZs.
Pros
Advanced threat protection
Secure VPN connectivity
Visibility and control (if connected to FMC)
Regulatory compliacnce with ISO 27001, NIS2, etc.
Cons
performance and scalability
slow policy deployment times
not all configurations are supported via FMC - you have to use flexconfigs
when using flexconfigs, it is little bit confusing
Return on Investment
positive impact when used as replacement from old ASA firewalls, and migrated 200-300 vpn users with anyconnect image upgrade
negative impact because very early EoL so we need to consider replacement for another platform - it would be expencive
positive imact - reduced incident response time and security breaches - management is happy because of lower operational risk and cost of downtime.
Usability
Alternatives Considered
Cisco Firepower 1000 Series, Cisco Firepower 4100 Series and Cisco ASA 5500-X with FirePOWER Services
Other Software Used
Cisco Firepower 1000 Series, Palo Alto Networks Next-Generation Firewalls - PA Series, Cisco Firepower 4100 Series
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Verified User
Engineer in Information Technology (1001-5000 employees)
Use Cases and Deployment Scope
A firewall. So ultimately it's just preventing and allowing access as needed.
Pros
For us, to power the whole system does scaling quite a bit. So we can definitely have a lot of room to grow if needed. The device can support a lot of way more than we need right now, but in the future, if we need more it seems to be a big pro of that. Also the support of Cisco, knowing that it's backed by Cisco definitely is good. You guys are the largest players in the market
Cons
Career-wise very familiar with the ASAs, you know, the previous gen firewalls, Pyxis, ASAs, the CHA. As far as being intuitive, those seem to be far more intuitive to learn and figure out what the features and changes and config management, all that stuff is. With Firepower, it's a learning curve and I feel like I have quite a bit of experience with it, and so does my team, but feels like it's not as intuitive, and trying to make changes just always seems harder for some reason. We've gone to some Cisco security training and all that, but even then it's just harder to work with. The other big thing is, and this is a big gripe of mine, I suppose, that on any other firewall, when we have various different manufacturers, if you make a change, you know, a simple change object, object name gets changed or object is deleted or whatever the simplest of change is, it gets implemented instantly.
With the Firepower system, you have to deploy the change and it'll take about six or seven minutes for the change to actually take, which is insanely different than any other platform where that change is instantaneous. So let's say if I'm making seven different changes for a troubleshooting job I don't know which one of the seven is gonna fix it, I do one by one by one. I'm like, oh, let me try one change, one second, change, third change, four changes. It's going to take seven deploys. And seven deploys mean it's gonna take an hour of just deploy time. So that is a big, big gripe
Return on Investment
It's keeping threats out like a firewall should. Definitely cost wise it is at a higher cost center than other alternatives. Especially when it comes to licensing. Cisco is generally the higher, for perhaps, definitely for good reason, right? I mean, definitely positive impact as far as working as it should that's at cost.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Verified User
Engineer in Information Technology (501-1000 employees)
Pros
Nice HTML5 web interface instead of the old java client
Many added features over the ASA
Firepower built in and faster than before
Cons
Cisco patches bugs quickly but patches are slow to install and reboot
Smart licensing is getting better but still can be troublesome
Some weird visual interface glitches that require clicking the same options a few extra times
Return on Investment
Simplifying our lives by reducing our time spent in a console
Being comfortable knowing the full might of Cisco is safeguarding your network
A good excuse to bump up the IT budget in the next fiscal year!
Other Software Used
Cisco SD-WAN, Cisco 1000 Series Integrated Services Routers (ISR 1000), Cisco Wireless LAN Controllers