We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
"Web filtering is a big improvement for us. The previous version we used, the AC520, did not have that feature included. It was not very easy for us, especially because the environment had to be isolated and we needed to get updates from outside, such as Windows patches. That feature has really helped us when we are going outside to pull those patches."
"One of the most valuable features of Firepower 7.0 is the "live log" type feature called Unified Event Viewer. That view has been really good in helping me get to data faster, decreasing the amount of time it takes to find information, and allowing me to fix problems faster. I've found that to be incredibly valuable because it's a lot easier to get to some points of data now."
"The most important feature is the intensive way you can troubleshoot Cisco Firepower Firewalls. You can go to the bit level to see why traffic is not handled in the correct way, and the majority of the time it's a networking issue and not a firewall issue. You can solve any problem without Cisco TAC help, because you can go very deeply under the hood to find out how traffic is flowing and whether it is not flowing as expected. That is something I have never seen with other brands."
"I have integrated it for incidence response. If there is a security event, the Cisco firewall will automatically block the traffic, which is valuable."
"One of the most valuable features is the AMP. It's very good and very reliable when it comes to malicious activities, websites, and viruses."
"The most important features are the intrusion prevention engine and the application visibility and control. The Snort feature in Firepower is also valuable."
"The most valuable features of this solution are advanced malware protection, IPS, and IDS."
"The most valuable feature that Cisco Firepower NGFW provides for us is the Intrusion policy."
"Its ability to block incoming attacks is valuable. Its logging, traffic monitoring, and VPN capabilities are also valuable."
"Scalability is good; the company wants to be able to handle large customers."
"Their GPS possibilities and the security that it has, especially the SD-WAN functionality, is very good."
"The interface is very user-friendly and it is quite easy to use."
"What I like best about this product are the support and the features."
"Ability to manage multiple firewalls."
"Good identity fire walling, malware protection and application control features."
"Its stability and SD-WAN features are the most valuable."
"The stability is better than other products."
"The most valuable feature is the Global Management System."
"User friendly and intuitive."
"The solution has many useful features, such as content management, user management, user filtering, and domain controller connectivity mapping."
"The filtering is excellent."
"The most valuable features are the VPN, SSL VPN, and IPSec VPN."
"SonicWall NSA is easy to deploy, easy to maintain, and easy to configure."
"The antivirus and items of that nature were quite helpful to have."
"Web filtering needs improvement because sometimes the URL is miscategorized."
"It's mainly the UI and the management parts that need improvement. The most impactful feature when you're using it is the user interface and the user experience."
"The product line does not address the SMB market as it is supposed to do. Cisco already has an on-premises sandbox solution."
"This product is managed using the Firepower Management Center (FMC), but it would be better if it also supported the command-line interface (CLI)."
"Deploying configurations takes longer than it should."
"They need a VTI. I know it's going to be available in the next software version, which is the 6.7 version. However, the problem with that is that the 6.7 is going to deprecate all the older IKEv1 deployment tunnels. Therefore, the problem is that we have a lot of customers which are using older encryptions. If I do that, update it, it's not going to work for me."
"On the VPN side, Firepower could be better. It needs more monitoring on VPNs. Right now, it's not that good. You can set up a VPN in Firepower, but you can't monitor it."
"The Firepower FTD code is missing some old ASA firewalls codes. It's a small thing. But Firepower software isn't missing things that are essential, anymore."
"If you have another brand of VPN where you have to put an SSL VPN between two devices, Barracuda doesn't support that at a certain point. You can't actually build the VPN between Barracuda and a different device of a different brand."
"Command line could be more user friendly."
"The biggest issue that I have with this solution is that it is not super intuitive. Once you know what to do, things make sense, but you can't just open the program and start doing things. It would be great if there was a little bit more guided usage inside the program."
"The analytics are weak."
"Technical support used to be at a very high level but it is now a bit less so."
"If you experience an attack it can take a very long time to find a solution."
"The interface should be more user-friendly and it should be easier to configure."
"The administration UI could be better. It should also have better application detection policies."
"We still get phishing emails that manage to come through from time to time."
"The reporting feature could be better because most of the companies want to have the analytics included, which is something that you have to buy separately."
"The filter settings are confusing and overly complicated. The user interface can be improved."
"Vendor support needs improvement. The frequency of time and support should be increased."
"Do not even consider NetExtender - probably one of the most horrific, nightmare grade Java-based VPN clients. We have but all given up trying to make it work reliably."
"The anti-spam requires a specific Java version on the server side (do not update it, otherwise it will break)."
"It doesn't require much improvement. The only improvement area is that cloud reporting, assessment reporting, and other reporting features should be available with the subscription. They should provide reporting features with the subscription base, which is currently not there. We bought the reporting tool, but there are some complications. They have made some changes to the application, and now the reporting management is completely on the cloud."
"We're not particularly fond of the way it generally performs. We are finding ourselves rebooting often. There are freeze-ups and that kind of thing. The stability needs to improve exponentially."
"For me, personally, as an individual, Cisco Firepower NGFW Firewall is expensive."
"When we purchased the firewall, we had to take the security license for IPS, malware protection, and VPN. If we are using high availability, we have to take a license for that. We also have to pay for hardware support and technical support. Its licensing is on a yearly basis."
"It definitely competes with the other vendors in the market."
"This product is expensive."
"I know that licensing for some of the advanced solutions, like Intrusion Prevention and Secure Malware Analytics, are nominal costs."
"Cisco pricing is premium. However, they gave us a 50 to 60 percent discount."
"Its pricing is good and competitive. There is a maintenance cost. It includes SecureX that makes it cost-effective as compared to the other solutions where you have to pay for XDR and SOAR capabilities."
"I am happy with the product in general, including the pricing."
"The solution costs more than 800 Euros to purchase an F18, which is an entry model, and then another 500 Euros for instant replacement, and 500 Euros for energized updates. The total package would be around 1,900 Euros for five years license and all updates for an entry model."
"The 600 series is about USD $10,000 a year and the 80 is USD $400 a year."
"Its licensing is on a yearly basis. There is an upfront purchase price, and there is also an annual maintenance fee. There are no additional fees."
"Normally, when we buy any product, we buy it with a five-year service built into it. Later on, depending on the growth of the organization, we go for a new one or an upgrade."
"The pricing is good and we are satisfied with the cost of this solution."
"They do have the option to purchase yearly, or two years, and three years renewal."
"The price is reasonable for what it does."
"You need their analyzer to properly generate reports. This is an expensive, licensed feature, with a complex application or appliance back-end."
"Its price is okay."
"SonicWall is a one-time purchase and there is no renewal license."
"If you want to connect more than five concurrent users by VPN then you have to pay an additional fee."
Cisco NGFW firewalls deliver advanced threat defense capabilities to meet diverse needs, from
small/branch offices to high performance data centers and service providers. Available in a wide
range of models, Cisco NGFW can be deployed as a physical or virtual appliance. Advanced threat
defense capabilities include Next-generation IPS (NGIPS), Security Intelligence (SI), Advanced
Malware Protection (AMP), URL filtering, Application Visibility and Control (AVC), and flexible VPN
features. Inspect encrypted traffic and enjoy automated risk ranking and impact flags to reduce event
volume so you can quickly prioritize threats. Cisco NGFW firewalls are also available with clustering
for increased performance, high availability configurations, and more.
Cisco Firepower NGFWv is the virtualized version of Cisco's Firepower NGFW firewall. Widely
deployed in leading private and public clouds, Cisco NGFWv automatically scales up/down to meet
the needs of dynamic cloud environments and high availability provides resilience. Also, Cisco NGFWv
can deliver micro-segmentation to protect east-west network traffic.
Cisco firewalls provide consistent security policies, enforcement, and protection across all your
environments. Unified management for Cisco ASA and FTD/NGFW physical and virtual firewalls is
delivered by Cisco Defense Orchestrator (CDO), with cloud logging also available. And with Cisco
SecureX included with every Cisco firewall, you gain a cloud-native platform experience that enables
greater simplicity, visibility, and efficiency.
Learn more about Cisco’s firewall solutions, including virtual appliances for public and private cloud.
Barracuda's Cloud Generation Firewalls redefine the role of the Firewall from a perimeter security solution to a distributed network optimization solution that scales across any number of locations and applications, connects on-premises and cloud infrastructures, and helps organizations transform their business.
Barracuda CloudGen Firewall is ranked 24th in Firewalls with 8 reviews while SonicWall NSa is ranked 16th in Firewalls with 35 reviews. Barracuda CloudGen Firewall is rated 7.8, while SonicWall NSa is rated 7.6. The top reviewer of Barracuda CloudGen Firewall writes "Good SIEM and a dynamic VPN with good scalability". On the other hand, the top reviewer of SonicWall NSa writes "A rugged solution capable of defeating advanced threats". Barracuda CloudGen Firewall is most compared with Fortinet FortiGate, Sophos XG, Cisco ASA Firewall, SonicWall TZ and Meraki SD-WAN, whereas SonicWall NSa is most compared with Meraki MX, Fortinet FortiGate, WatchGuard Firebox and SonicWall TZ. See our Barracuda CloudGen Firewall vs. SonicWall NSa report.
See our list of best Firewalls vendors.
We monitor all Firewalls reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.