We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
"Web filtering is a big improvement for us. The previous version we used, the AC520, did not have that feature included. It was not very easy for us, especially because the environment had to be isolated and we needed to get updates from outside, such as Windows patches. That feature has really helped us when we are going outside to pull those patches."
"You do not have to do everything through a command line which makes it a lot easier to apply rules."
"The Firepower+ISE+AMP for endpoint integration is something that really stands it out with other vendor solutions. They have something called pxGrid and i think it is already endorsed by IETF. This allows all devices on the network to communicate."
"The most valuable features of this solution are advanced malware protection, IPS, and IDS."
"I have experience with URL filtering, and it is very good for URL filtering. You can filter URLs based on the categories, and it does a good job. It can also do deep packet inspection."
"Firepower NGFW has improved my organization in several ways. Before, we were trying to stamp out security threats and issues, it was a one-off type of way to attack it. I spent a lot of manpower trying to track down the individual issues or flare-ups that we would see. With Cisco's Firepower Management, we're able to have that push up to basically one monitor and one UI and be able to track that and stop threats immediately. It also gives us a little more granularity on what those threats might be."
"It is one of the fastest solutions, if not the fastest, in the security technology space. This gives us peace of mind knowing that as soon as a new attack comes online that we will be protected in short order. From that perspective, no one really comes close now to Firepower, which is hugely valuable to us from an upcoming new attack prevention perspective."
"There are no issues that we are aware of. It does its job silently in the background."
"This kind of strategic technology makes it much easier to remove malware and address vulnerabilities quickly."
"Each user has the ability to manage the solution."
"The valuable features of this solution are the VPN, load balancer, and the QoS for splitting the ISP band."
"I have found the solution easy to use and fully integrated."
"It is simple to use."
"The solution was able to be integrated well with exciting hardware and software and in multiple business sectors."
"The most valuable feature I have found to be the reporting function."
"We found the initial setup to be straightforward."
"All features are useful. We are using premium features such as bandwidth sharing, failover, web filters, SSL controls, antivirus, and VPN. We use these features to the fullest. These features are available in the paid firewall license, not the free one."
"Its detection, antivirus, and filtering features are the most valuable. The facility to connect by using the VPN connection is also a very valuable feature. It is very strong, secure, and reliable. We have implemented the Untangle solution in all hardware. It is also a user-friendly solution. It is easy to learn and easy to configure."
"They have a command center that makes it easy to log into and see all of your appliances nationwide."
"Easy to set up and easy to integrate."
"The most valuable features are IPS, MAPI, NAT, and VPN."
"Implementations require the use of a console. It would help if the console was embedded."
"One feature I would like to see, that Firepower doesn't have, is email security. Perhaps in the future, Cisco will integrate Cisco Umbrella with Firepower. I don't see why we should have to pay for two separate products when both could be integrated in one box."
"The initial setup could be simplified, as it can be complex for new users."
"The product line does not address the SMB market as it is supposed to do. Cisco already has an on-premises sandbox solution."
"My team tells me that other solutions such as Fortinet and Palo Alto are easier to implement."
"I would like to see improvement when you create policies on Snort 3 IPS on Cisco Firepower. On Snort 2, it was more like a UI page where you had some multiple choices where you could tweak your config. On Snort 3, the idea is more to build some rules on the text file or JSON file, then push it. So, I would like to see a lot of improvements here."
"FlexConfig is there as a bridge for features that are not yet natively integrated into Firepower. It is a way of allowing you to be able to configure things that wouldn't otherwise be possible until the development team can add them into Firepower's native capability. There is still some work that needs to be done around FlexConfig. There are still quite a few complex things, like policy-based routing, that have to be done in FlexConfig, and it doesn't always work perfectly. Sometimes, there are some glitches. It is recommended that you configure FlexConfig policies with Cisco TAC. It would be good to see Cisco accelerate some of those configurations that you can only do in FlexConfig into the platform, so that they are there natively."
"Deploying configurations takes longer than it should."
"The logging side of it could definitely be better. Some of the logging lacks, and the information that they provide you, especially in the spam filtering section, could be better."
"They should improve the hardware. If they can do that, it will be a very good product."
"There is an area that is very specific to our setup, where working tools you cannot easily establish a VPN between two internal networks."
"The MTR feature needs enhancing."
"Sophos needs improvements made to the console, such as host entry or defining rules directly from it."
"They need to improve the SD-WAN feature."
"In feature releases of the solution, I would like there to be an increase in the detection capability."
"The reaction time of the GUI is terrible when compared to other manufacturers."
"The common center facility that Untangle provides should be available on-premises. There are great corporations here in Mexico that like the Untangle solution, but they don't like the fact that the monitoring and access to the appliance are in the cloud. They request for the common center facility to be available and installed on-premises."
"Web-filtering policies could be improved."
"The pricing should be reduced because it is expensive."
"We seek the availability of the hardware in our region. The hardware-based firewall from Untangle is currently not available in our region. It should have threat protection on a real-time basis. This feature, available in Check Point and Sandstorm kind of scenario, is currently missing in Untangle NG Firewall."
"They don't have any feature that allows you to drop the session."
"The price of Firepower is not bad compared to other products."
"The solution was chosen because of its price compared to other similar solutions."
"When we are fighting against other competitors for customers, whether it is a small or big business, we feel very comfortable with the price that Firepower has today."
"I know that licensing for some of the advanced solutions, like Intrusion Prevention and Secure Malware Analytics, are nominal costs."
"I am happy with the product in general, including the pricing."
"There are additional implementation and validation costs."
"Cisco pricing is premium. However, they gave us a 50 to 60 percent discount."
"When we purchased the firewall, we had to take the security license for IPS, malware protection, and VPN. If we are using high availability, we have to take a license for that. We also have to pay for hardware support and technical support. Its licensing is on a yearly basis."
"We prepaid in advance to get the max discount."
"There is no license required to use this solution."
"The solution is priced well."
"Sophos allows for its product to be evaluated without any financial commitment."
"Because we're in education, Sophos gives us a very competitive price for it."
"The price is reasonable"
"The price is reasonable but it would be great if it was reduced to half the price."
"Its price should be better. Initially, the clients have to pay for the appliance. Then, they have to pay for the software that is installed on the appliance. Depending on whether they have a one-year, two-year, or three-year license, they just have to renew the license of the software after it expires. They don't have to renew the appliance license. So, they have to pay for the appliance only once, and after that, they just renew the software license. That's all."
"It is not expensive. The best part is that it is based on the pay-per-use kind of scenario. An increase or decrease in the number of people doesn't make any difference. We are really happy about using this particular scenario."
"The pricing model is better than with SonicWall."
"It is not expensive. It is cheaper than Fortinet."
Cisco NGFW firewalls deliver advanced threat defense capabilities to meet diverse needs, from
small/branch offices to high performance data centers and service providers. Available in a wide
range of models, Cisco NGFW can be deployed as a physical or virtual appliance. Advanced threat
defense capabilities include Next-generation IPS (NGIPS), Security Intelligence (SI), Advanced
Malware Protection (AMP), URL filtering, Application Visibility and Control (AVC), and flexible VPN
features. Inspect encrypted traffic and enjoy automated risk ranking and impact flags to reduce event
volume so you can quickly prioritize threats. Cisco NGFW firewalls are also available with clustering
for increased performance, high availability configurations, and more.
Cisco Firepower NGFWv is the virtualized version of Cisco's Firepower NGFW firewall. Widely
deployed in leading private and public clouds, Cisco NGFWv automatically scales up/down to meet
the needs of dynamic cloud environments and high availability provides resilience. Also, Cisco NGFWv
can deliver micro-segmentation to protect east-west network traffic.
Cisco firewalls provide consistent security policies, enforcement, and protection across all your
environments. Unified management for Cisco ASA and FTD/NGFW physical and virtual firewalls is
delivered by Cisco Defense Orchestrator (CDO), with cloud logging also available. And with Cisco
SecureX included with every Cisco firewall, you gain a cloud-native platform experience that enables
greater simplicity, visibility, and efficiency.
Learn more about Cisco’s firewall solutions, including virtual appliances for public and private cloud.
Sophos XG Firewall is next gen firewall that is optimized for today’s business, delivering all the protection and insights you need in a single, powerful appliance that’s easy to manage.
Untangle NG Firewall takes the complexity out of network security—saving you time, money and frustration. Get everything you need in a single, modular platform that fits the evolving needs of your organization without the headaches of multiple point solutions.
Enjoy the flexibility to deploy Untangle’s award-winning NG Firewall software on third party hardware, as a virtual machine, or as a turnkey appliance.
Rest assured that the browser-based, responsive and intuitive interface will enable you to create policies quickly and easily. Then, drill down into database-driven reports—the most comprehensive and detailed in the industry—to get visibility into exactly what’s happening on your network.
Sophos XG is ranked 6th in Firewalls with 116 reviews while Untangle NG Firewall is ranked 21st in Firewalls with 5 reviews. Sophos XG is rated 8.2, while Untangle NG Firewall is rated 9.4. The top reviewer of Sophos XG writes "Light and stable with excellent real-time control ". On the other hand, the top reviewer of Untangle NG Firewall writes "Good VPN features, helpful reporting and alerting, built-in content filtering, and excellent support". Sophos XG is most compared with Fortinet FortiGate, pfSense, Sophos UTM, Meraki MX and Sophos Cyberoam UTM, whereas Untangle NG Firewall is most compared with OPNsense, pfSense, Sophos UTM and Fortinet FortiGate. See our Sophos XG vs. Untangle NG Firewall report.
See our list of best Firewalls vendors.
We monitor all Firewalls reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.