Firepower 2100 - slowly dying but still usable
Use Cases and Deployment Scope
Cisco Firepower 2100 series - specifically Cisco Firepower 2130 in my organization is used as a main VPN concentrator. Main business problems the product addresses are connecting remote access users to our data center and out of band networks where services usually seat. The platform is suitable directly for deployments in bigger data centers or DMZs.
Pros
- Advanced threat protection
- Secure VPN connectivity
- Visibility and control (if connected to FMC)
- Regulatory compliacnce with ISO 27001, NIS2, etc.
Cons
- performance and scalability
- slow policy deployment times
- not all configurations are supported via FMC - you have to use flexconfigs
- when using flexconfigs, it is little bit confusing
Likelihood to Recommend
The Firepower 2100 sersies are suited well if you need next generation firewall for very specific usage, with one or two "roles" - for example use it as VPN concentrator, or for network segmentation. But it is not that suitable in environment, where you need lots of new functions, because it is on its end of live way - and so you have to think about changing it soon.