TrustRadius: an HG Insights company

Cisco Secure Firewall

Score8.5 out of 10

300 Reviews and Ratings

What is Cisco Secure Firewall?

Cisco Secure Firewall delivers comprehensive threat protection for modern, distributed networks. Built to support hybrid workforces and multicloud environments, it enables Zero Trust access, application visibility, and secure remote connectivity. With integration across the Cisco Secure portfolio, including SecureX and Talos threat intelligence, the firewall powers organizations to detect and stop more sophisticated threats. Centralized management simplifies policy enforcement, orchestration, and automated response — reducing complexity while strengthening security across physical, virtual, and cloud-based deployments.

Categories & Use Cases

Media

Screenshot of Cisco Secure 1200 Series Firewall Family
Screenshot of Cisco Secure 4200 Series
Screenshot of Cisco Secure 4200 Series
Screenshot of Cisco Secure Firewall 1200 Stack Family
Screenshot of Cisco Secure Firewall 200 Series
Screenshot of Cisco Secure Firewall 200 Series
Screenshot of Cisco Secure Firewall 200 Series
Screenshot of Secure Firewall 1200 Series
Screenshot of Secure Firewall 1200 Series
Screenshot of Firewall Management - Network Discovery
Screenshot of Secure Firewall 3100 Series
Screenshot of Secure Firewall 3100 Series
Screenshot of Secure Firewall 3100 Series
Screenshot of Secure Firewall 3100 Series
Screenshot of Secure Firewall 3100 Series
Screenshot of Secure Firewall 3100 Series
Screenshot of Secure Firewall 3100 Series
Screenshot of Secure Firewall 3100 Series
Screenshot of Secure Firewall 3100 Series
Screenshot of Secure Firewall 6100 Series
Screenshot of Secure Firewall 6100 Series

1 / 21

Screenshot of Cisco Secure 1200 Series Firewall Family

Top Performing Features

  • High Availability

    Built-in capacity to prevent exposure if primary firewall stops working

    Category average: 8.7

  • VPN

    VPN's implement encryption and anonymize IP addresses

    Category average: 8.9

  • Stateful Inspection

    Stateful inspection analyzes packet headers and contents of packets

    Category average: 8.4

Areas for Improvement

  • Visualization Tools

    Visualization tools present administrators with data on applications traversing the network, who is using them, and the potential security impact.

    Category average: 7.6

  • Proxy Server

    A proxy server changes your IP address and masks the origin of your network traffic

    Category average: 7.9

  • Reporting and Logging

    Custom and summary reports, and log files enabling analysis of security incidents, application usage and traffic patterns

    Category average: 7.4

Who Buys & Uses Cisco Secure Firewall

Pros

  • Robust threat protection and detection capabilities against cyber threats.
  • Comprehensive VPN functionalities for secure remote access and site-to-site connectivity.
  • Centralized management and control via Firepower Management Center (FMC).

Cons

  • Slow deployment and application of configuration changes.
  • Management interface can be complex, slow, or not intuitive for users.
  • Complex and expensive licensing model and overall pricing structure.

Cisco Secure Firewall 3130

Use Cases and Deployment Scope

In my work, we heavily depend on Firepower Threat Defense (FTD) for both Internet and internal security, and manage them using Firewall Management Console (FMC) for crafting security rules and policies. A day hardly passes without touching those appliances. VPN needs are also carried out with these headends, both on the RA and S-2-S sides.

Pros

  • Taking care of access control rules governing traffic movement throughout both, the network and out to the internet
  • Terminating RA and S-2-S VPN sessions is carried out by Cisco Secure Firewall
  • Addressing network address translation (NAT) is also sourced from them

Cons

  • More documentation is always very useful on the numerous security aspects these appliances are capable of doing
  • FMC GUI and visualization tools can take more TLC
  • Integration with ISE and AD is not intuitive and needs more detailed instructions to be laid out in the GUI

Return on Investment

  • ROI is NLT 90%
  • 100% protection and access control achieved
  • 75% of Cyber Security endeavors are fulfilled by Cisco Secure Firewall

Cisco Secure Firewall

Use Cases and Deployment Scope

We currently have 2 Cisco Secure Firewall Firepower 4215 FTD appliances, running in HA, and managed by a virtual FMC. This addresses our need for a redundant firewall solution with next-gen features like Snort, IDS/IPS, etc. We have over 8000 users, and approximately 20k devices on our network, with 100+ VLANs and 30 security zones.

Pros

  • Provides a very functional GUI
  • Usually integrates well with our other service, like ISE, Umbrella, wireless.
  • Provides timely patches and upgrades.
  • Policy configuration is intuitive.
  • Providing an AI assistant to evaluate configurations and recommend changes.

Cons

  • I think the flexconfig process is very confusing.
  • The passive ID integration with ISE doesn't work as designed, and TAC has not been able to figure it out.
  • I would like TAC to provide better support, particularly when it is a tier 1 problem.

Return on Investment

  • Given we are an higher Ed. organization, our reselling leveraged that and got us a significant discount on the appliances. We have our licensing rolled into an EA. I would say we save over $100k in adoption costs, and at least that much per year on licensing.
  • We combine event data from our Cisco Secure Firewall Firepowers with ISE, Umbrella, Catalyst Center and other utilities to assist us with troubleshooting and security issues. The event logs are a bit difficult to use, and don't always provide us with useful information, but we do use the to correlate events across the tools.

Alternatives Considered

Palo Alto Networks Advanced Threat Prevention, Fortinet FortiGate and Juniper Advanced Threat Prevention

Other Software Used

Cisco Identity Services Engine (ISE), Cisco Umbrella, Cisco Catalyst Center

In a League of Its Own.

Use Cases and Deployment Scope

For malware defense and URL filtering. Essential for detecting and blocking threats while keeping our network and all users safe.

Pros

  • Powerful protection for our network.
  • Safe remote access and secure connection for multiple office locations.
  • Great for controlling access.
  • Easy integration with other Cisco tools.

Cons

  • Some integrated with 3rd party tools require a complex setup.

Return on Investment

  • Keep our network secure and helps to detect potential threats effectively.
  • Enable remote employees to have a safe connection.

Other Software Used

Cisco Duo

Cisco Secure Firewall

Use Cases and Deployment Scope

Cisco Secure Firewalls are used as our edge security platform for network traffic as well as VPN access/connections.We have Cisco Secure Firewalls also in our Azure Environments aswell as to help secure our DMZ.

One issue we have is sometimes missing unified events for traffic. There will be time ranges set say for a month or a week and then it will only display information from the day or a couple hours

Another issue we're having currently is NAt reservations are failing to be un reserved for certain components of our network..

Pros

  • SSL Decrypt
  • Intrusion Blocks
  • VPN

Cons

  • Better THI interface
  • Better Upgrade process
  • Deeper file inspection and Malware feature

Return on Investment

  • Better seucirty
  • Better inspection
  • Better security insights

Alternatives Considered

Palo Alto Networks Advanced Threat Prevention

Other Software Used

Cisco Meraki Dashboard, Anthropic Claude, ChatGPT

[...] from [...]

Use Cases and Deployment Scope

Edge and data center firewalls protect our campus and on-prem assets as well as our connectivity to our cloud presence in AWS

Pros

  • Excellent management via the FMC
  • Smooth upgrade process for the Cisco Secure Firewall FTD firewalls
  • Good visibility into the traffic flows and IPS blocks via the FMC

Cons

  • EVE is a little buggy, and forced us to disable this due to causing random reboots of the active FTD

Return on Investment

  • FMC and FTD's are not cheap, but the value is in the security and performance
  • Talos Security intelligence feeds are a big win, and we block on all categories

Alternatives Considered

Palo Alto Networks Advanced Threat Prevention

Other Software Used

Cisco Identity Services Engine (ISE), Cisco Catalyst Center