We just raised a $30M Series A: Read our story

Compare Cisco ASA Firewall vs. Cisco IOS Security

Cancel
You must select at least 2 products to compare!
Featured Review
Find out what your peers are saying about Cisco ASA Firewall vs. Cisco IOS Security and other solutions. Updated: November 2021.
552,136 professionals have used our research since 2012.
Quotes From Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:

Pros
"The most important features are the intrusion prevention engine and the application visibility and control. The Snort feature in Firepower is also valuable.""The Firepower+ISE+AMP for endpoint integration is something that really stands it out with other vendor solutions. They have something called pxGrid and i think it is already endorsed by IETF. This allows all devices on the network to communicate.""Feature-wise, we mostly use IPS because it is a security requirement to protect against attacks from outside and inside. This is where IPS helps us out a bunch.""Another benefit has been user integration. We try to integrate our policies so that we can create policies based on active users. We can create policies based on who is accessing a resource instead of just IP addresses and ports.""The most valuable features of this solution are the integrations and IPS throughput.""The integration of network and workload micro-segmentation helps a lot to provide unified segmentation policies across east-west and north-south traffic. One concrete example is with Cisco ACI for the data center. Not only are we doing what is called a service graph on the ACI to make sure that we can filter traffic east-west between two endpoints in the same network, but when we go north-south or east-west, we can then leverage what we have on the network with SGTs on Cisco ISE. Once you build your matrix, it is very easy to filter in and out on east-west or north-south traffic.""The most valuable feature is stability.""One of the most valuable features is the AMP. It's very good and very reliable when it comes to malicious activities, websites, and viruses."

More Cisco Firepower NGFW Firewall Pros »

"Cisco has the best documentation. You can easily find multiple documents by searching the web. Even a child can go online and find the required information.""The configuration support is very good. You can find a lot of configuration samples and troubleshooting tips on the internet, which is very good.""I have found the most valuable feature to be the access control and IPsec VPN.""If you have a solution that is creating a script and you need to deploy many implementations, you can create a script in the device and it will be the same for all. After that, you just have to do the fine tuning.""It is a very stable product. I've not had any issues with it. It is a super product, and I won't need to change it anytime soon.""The management aspect of the product is very straightforward.""The traffic inspection and the Firepower engine are the most valuable features. It gives you full details, application details, traffic monitoring, and the threats. It gives you all the containers the user is using, especially at the application level. The solution also provides application visibility and control.""We are mostly using it for remote access, so the remote access feature is the most valuable, but all other features are also needed and required. It is also a very straightforward and reliable solution."

More Cisco ASA Firewall Pros »

"The technical is excellent.""Cisco is head-and-shoulders above all of the competition when it comes to technical support.""The hardware is pretty stable. It's also a very good product performance-wise. Initially, it wasn't mature like a firewall and there were other leaders, but now they have included almost all the features of next-generation security. Basically, it's a good product to work with.""The capabilities for scalability with this product are huge""The product is easy to use.""We are able to filter a lot of traffic especially when a lot of the traffic is in layer 7.""Cisco has always been a premium product. There's a lot of other entry-level solutions. This is more robust.""Completely integrates branch offices with perimeter security."

More Cisco IOS Security Pros »

Cons
"One feature I would like to see, that Firepower doesn't have, is email security. Perhaps in the future, Cisco will integrate Cisco Umbrella with Firepower. I don't see why we should have to pay for two separate products when both could be integrated in one box.""I believe that the current feature set of the device is very good and the only thing that Cisco should work on is improving the user experience with the device.""On the VPN side, Firepower could be better. It needs more monitoring on VPNs. Right now, it's not that good. You can set up a VPN in Firepower, but you can't monitor it.""The initial setup could be simplified, as it can be complex for new users.""The product line does not address the SMB market as it is supposed to do. Cisco already has an on-premises sandbox solution.""My team tells me that other solutions such as Fortinet and Palo Alto are easier to implement.""The Firepower FTD code is missing some old ASA firewalls codes. It's a small thing. But Firepower software isn't missing things that are essential, anymore.""It's mainly the UI and the management parts that need improvement. The most impactful feature when you're using it is the user interface and the user experience."

More Cisco Firepower NGFW Firewall Cons »

"The stability is not the best.""They need a user-friendly interface that we could easily configure.""I think the ASA layer is thin. It's always Layer 3 or Layer 4 source controller and doesn't control the Layer 7 traffic. It's important, and you'll need an additional firewall.""The cost is very high. Most organizations cannot afford it.""Some individuals find the setup and configuration challenging.""The annual subscription cost is a bit high. They should try to make it comparable to other offerings. We have a number of Chinese products here in Pakistan, which are already, very cheap and have less annual maintenance costs compared to Cisco.""If the implementation was easier, it would be a lot better for us.""On firewall features, Fortinet is better. Cisco needs to become more competitive and add more features or meet Fortinet's offering."

More Cisco ASA Firewall Cons »

"The user interface needs to be improved.""With respect to user-friendliness, it is a command-line interface and those with such experience will get along just fine, whereas others may struggle.""It would be ideal if the solution had more capacity.""Signatures and other critical definitions need to be updated more frequently.""The configuration should be easier in the solution.""I think they should bring back remote VPN for users.""The company needs to make its solution more affordable to make it more accessible to larger markets. Otherwise, it's seen as an enterprise-level solution that small or medium-sized organizations can't afford and therefore they won't even look at it.""The pricing is the only con for this product."

More Cisco IOS Security Cons »

Pricing and Cost Advice
"There are additional implementation and validation costs.""Cisco, as we all know, is expensive, but for the money you are paying, you know that you are also getting top-notch documentation as well as support if needed.""This product is expensive.""I know that licensing for some of the advanced solutions, like Intrusion Prevention and Secure Malware Analytics, are nominal costs.""It definitely competes with the other vendors in the market.""This solution is expensive and other solutions, such as FortiGate, are cheaper.""Cisco is not for a small mom-and-pop shop because of the cost, but if you're in a regulated industry where a breach could cost you a million dollars, it's a bargain.""Its pricing is good and competitive. There is a maintenance cost. It includes SecureX that makes it cost-effective as compared to the other solutions where you have to pay for XDR and SOAR capabilities."

More Cisco Firepower NGFW Firewall Pricing and Cost Advice »

"Their pricing is very aggressive and good. Even a small company can afford it. I am happy with its pricing. Its licensing is on a yearly basis.""We're using the smart license for this firewall. The models that we have require licensing for remote access.""The licensing is a bit off because the physical firewall is cheaper than the virtual one. We only have the physical ones as they are cheaper than the virtual ones. We only use the physical firewalls because of the price difference.""Its price is moderate. It is not too expensive.""The product is very expensive.""They have a lot of different models but most of them are really expensive.""Cisco ASA Firewall should be cheaper.""I just bought it off the shelf, and I'm using it with my previous one, so I have not spent that much."

More Cisco ASA Firewall Pricing and Cost Advice »

"Price is certainly something that the IOS technology has fallen behind the competition on.""Palo Alto networks are more expensive than this solution and this is why you will see more products like this one in Mexico.""It is necessary to pay for a license in order to use the solution. It is on a yearly basis and the price is high.""The price of the solution should be cheaper, and the license is purchase annually.""The pricing is okay. It is competitive. It costs more when you need get more features.""It is an expensive solution."

More Cisco IOS Security Pricing and Cost Advice »

report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
552,136 professionals have used our research since 2012.
Questions from the Community
Top Answer:  When you compare these firewalls you can identify them with different features, advantages, practices and… more »
Top Answer:  The Cisco Firepower NGFW Firewall is a very powerful and very complex piece of anti-viral software. When one considers… more »
Top Answer: It is easy to integrate Cisco ASA with other Cisco products and also other NAC solutions. When you understand the Cisco… more »
Top Answer: One of our favorite things about Fortinet Fortigate is that you can deploy on the cloud or on premises. Fortinet… more »
Top Answer:  Cisco Adaptive Security Appliance (ASA) software is the operating software for the Cisco ASA suite. It supports… more »
Top Answer: When looking to change our ASA Firewall, we looked into Palo Alto’s WildFire. It works especially in preventing advanced… more »
Top Answer: One of the main features is that the hardware is extremely reliable.
Top Answer: Palo Alto networks are more expensive than this solution and this is why you will see more products like this one in… more »
Top Answer: I think they should bring back remote VPN for users. However, I understand the attempt is to have these functions inside… more »
Comparisons
Also Known As
Cisco Firepower NGFW, Cisco Firepower Next-Generation Firewall, FirePOWER, Cisco NGFWv
Cisco Adaptive Security Appliance (ASA) Firewall, Cisco ASA NGFW, Cisco ASA, Adaptive Security Appliance, ASA, Cisco Sourcefire Firewalls, Cisco ASAv
IOS Security
Learn More
Overview

Cisco NGFW firewalls deliver advanced threat defense capabilities to meet diverse needs, from
small/branch offices to high performance data centers and service providers. Available in a wide
range of models, Cisco NGFW can be deployed as a physical or virtual appliance. Advanced threat
defense capabilities include Next-generation IPS (NGIPS), Security Intelligence (SI), Advanced
Malware Protection (AMP), URL filtering, Application Visibility and Control (AVC), and flexible VPN
features. Inspect encrypted traffic and enjoy automated risk ranking and impact flags to reduce event
volume so you can quickly prioritize threats. Cisco NGFW firewalls are also available with clustering
for increased performance, high availability configurations, and more.
Cisco Firepower NGFWv is the virtualized version of Cisco's Firepower NGFW firewall. Widely
deployed in leading private and public clouds, Cisco NGFWv automatically scales up/down to meet
the needs of dynamic cloud environments and high availability provides resilience. Also, Cisco NGFWv
can deliver micro-segmentation to protect east-west network traffic.
Cisco firewalls provide consistent security policies, enforcement, and protection across all your
environments. Unified management for Cisco ASA and FTD/NGFW physical and virtual firewalls is
delivered by Cisco Defense Orchestrator (CDO), with cloud logging also available. And with Cisco
SecureX included with every Cisco firewall, you gain a cloud-native platform experience that enables
greater simplicity, visibility, and efficiency.
Learn more about Cisco’s firewall solutions, including virtual appliances for public and private cloud.

Cisco ASA firewalls deliver enterprise-class firewall functionality with highly scalable and flexible VPN capabilities to meet diverse needs, from small/branch offices to high performance data centers and service providers. Available in a wide range of models, Cisco ASA can be deployed as a physical or virtual appliance. Flexible VPN capabilities include support for remote access, site-to-site, and clientless VPN. Also, select appliances support clustering for increased performance, VPN load balancing to optimize available resources, advanced high availability configurations, and more.

Cisco ASAv is the virtualized version of the Cisco ASA firewall. Widely deployed in leading private and public clouds, Cisco ASAv is ideal for remote worker and multi-tenant environments. The solution scales up/down to meet performance requirements and high availability provides resilience. Also, Cisco ASAv can deliver micro-segmentation to protect east-west network traffic.

Cisco firewalls provide consistent security policies, enforcement, and protection across all your environments. Unified management for Cisco ASA and FTD/NGFW physical and virtual firewalls is delivered by Cisco Defense Orchestrator (CDO), with cloud logging also available. And with Cisco SecureX included with every Cisco firewall, you gain a cloud-native platform experience that enables greater simplicity, visibility, and efficiency.

Learn more about Cisco’s firewall solutions, including virtual appliances for public and private cloud.

Cisco IOS Software delivers a sophisticated set of security capabilities for a comprehensive, layered security approach throughout your network infrastructure. Cisco IOS security technologies help to defend critical business processes against attack and disruption, protect privacy, and support policy and regulatory compliance controls.
Offer
Learn more about Cisco Firepower NGFW Firewall
Learn more about Cisco ASA Firewall
Learn more about Cisco IOS Security
Sample Customers
Rackspace, The French Laundry, Downer Group, Lewisville School District, Shawnee Mission School District, Lower Austria Firefighters Administration, Oxford Hospital, SugarCreek, Westfield
There are more than one million Adaptive Security Appliances deployed globally. Top customers include First American Financial Corp., Genzyme, Frankfurt Airport, Hansgrohe SE, Rio Olympics, The French Laundry, Rackspace, and City of Tomorrow.
Arup Group, Brunel University London, City of Biel, Gobierno de Castilla-La Mancha, K&L Gates , New South Wales Rural Fire Service, Offshore Northern Seas, Transplace
Top Industries
REVIEWERS
Comms Service Provider22%
Financial Services Firm16%
Manufacturing Company8%
Non Profit8%
VISITORS READING REVIEWS
Comms Service Provider32%
Computer Software Company21%
Government7%
Manufacturing Company4%
REVIEWERS
Financial Services Firm17%
Comms Service Provider13%
Manufacturing Company10%
University6%
VISITORS READING REVIEWS
Comms Service Provider35%
Computer Software Company21%
Government5%
Educational Organization4%
REVIEWERS
Financial Services Firm17%
Comms Service Provider17%
University8%
Security Firm8%
VISITORS READING REVIEWS
Comms Service Provider29%
Computer Software Company28%
Government5%
Financial Services Firm4%
Company Size
REVIEWERS
Small Business43%
Midsize Enterprise28%
Large Enterprise29%
VISITORS READING REVIEWS
Small Business21%
Midsize Enterprise13%
Large Enterprise66%
REVIEWERS
Small Business35%
Midsize Enterprise26%
Large Enterprise39%
VISITORS READING REVIEWS
Small Business28%
Midsize Enterprise16%
Large Enterprise56%
REVIEWERS
Small Business29%
Midsize Enterprise42%
Large Enterprise29%
Find out what your peers are saying about Cisco ASA Firewall vs. Cisco IOS Security and other solutions. Updated: November 2021.
552,136 professionals have used our research since 2012.

Cisco ASA Firewall is ranked 5th in Firewalls with 62 reviews while Cisco IOS Security is ranked 17th in Firewalls with 10 reviews. Cisco ASA Firewall is rated 8.0, while Cisco IOS Security is rated 7.8. The top reviewer of Cisco ASA Firewall writes "Robust solution that integrates well with both Cisco products and products from other vendors". On the other hand, the top reviewer of Cisco IOS Security writes "Prevent unauthorized use of network resources and integrate branch offices with reliability". Cisco ASA Firewall is most compared with Fortinet FortiGate, Palo Alto Networks WildFire, Meraki MX, Juniper SRX and SonicWall TZ, whereas Cisco IOS Security is most compared with Zyxel Unified Security Gateway, Fortinet FortiGate, pfSense, Kerio Control and Juniper SRX. See our Cisco ASA Firewall vs. Cisco IOS Security report.

See our list of best Firewalls vendors.

We monitor all Firewalls reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.