Listing Thumbnail

    Cisco Secure Firewall Threat Defense Virtual - PAYG

     Info
    Deployed on AWS
    Free Trial
    Protect your dynamic cloud environments with consistent security, superior visibility, and advanced threat defense such as application visibility and control, deep packet inspection, IPS, malware defense, and URL filtering - powered by Cisco Talos® Threat Intelligence. Achieve deeper visibility into QUIC and TLS 1.3 traffic without breaking Layer 7 policies.
    4.2

    Overview

    Cisco Secure Firewall Threat Defense Virtual delivers consistent security, deep visibility, and advanced threat defense options to help you maintain business continuity amidst unpredictable threats and change. Take advantage of capabilities such as application visibility and control, Snort 3 IPS, malware defense, URL filtering, and Cisco Talos® Threat Intelligence to protect against known and unknown threats across your environments. Maintain Layer 7 policies on encrypted QUIC and TLS 1.3 traffic with our Encrypted Visibility Engine.

    Realize a payback period of 10 months over a three-year investment*.

    Secure your dynamic environments consistently: Gain consistent security policy enforcement, deep packet inspection, and ingress and egress traffic protection across your cloud environments.

    • Deeper visibility into QUIC and TLS 1.3 encrypted traffic without breaking Layer 7 policies
    • Dynamic attribute support for AWS tags for situations where static IP addresses are not available
    • Firewall clustering for highly-available threat defense

    Achieve greater efficiency with unified firewall management: Cisco Secure Firewall Management Center gives you the freedom and choice to administer firewalls, correlate and prioritize threats, as well as quickly act on them in a single pane of glass.

    • Reduce up to 95%* of network operation work streams by managing your firewall stack with Secure Firewall Management Center
    • Management offered in a cloud-delivered, virtual, and on-premises form factors
    • Supports REST API - a HTTP-based interface for management, policies, and monitoring

    Accelerate response with Cisco SecureX: Every Secure Firewall includes entitlement for Cisco SecureX to accelerate threat detection and remediation.

    • Speed up incident response with the new SecureX ribbon in Firewall Management Center, enabling SecOps to instantly pivot to the SecureX open platform
    • Configure AWS VPCs manually or automatically from SecureX in response to events from Cisco Secure products
    • Monitor your AWS accounts and workloads for malicious activity by integrating with Amazon GuardDuty

    Introduce AWS services for added benefits:

    • Combine with Amazon Gateway Load Balancer to dynamically insert scalable security into your AWS environment and reduce complexity
    • Leverage Amazon Route 53 for remote access VPN
    • Integrate with AWS Transit Gateway for scalable inter-VPC traffic

    For supported AWS instances, please see the data sheet. To get started, see our Getting Started Guide.

    *Forrester Total Economic Impact of Cisco Secure Firewall, 2022. <www.cisco.com/go/firewallTEI >

    Highlights

    • An AWS Security Competency approved solution providing real-time, unified, network security to protect your most critical infrastructure and data across dynamic environments.
    • Delivers the most advanced threat defense options with Snort 3 IPS, visibility into encrypted QUIC and TLS 1.3 traffic, malware defense, URL filtering, deep packet inspection, and application visibility and control.
    • Cisco Talos® Threat Intelligence is included, protecting against known and unknown threats from one of the world's largest commercial threat intelligence teams.

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    OtherLinux 10.0.0-140

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Free trial

    Try this product free for 30 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.

    Cisco Secure Firewall Threat Defense Virtual - PAYG

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (31)

     Info
    Dimension
    Cost/hour
    c5.xlarge
    Recommended
    $1.00
    c4.xlarge
    $1.00
    c6in.4xlarge
    $3.50
    c3.xlarge
    $1.00
    c5a.xlarge
    $1.00
    c5n.2xlarge
    $1.80
    c6a.xlarge
    $1.00
    m5zn.2xlarge
    $1.80
    c5n.4xlarge
    $3.50
    m5n.xlarge
    $1.00

    Vendor refund policy

    The Cisco NGFWv instance can be terminated at any time to stop incurring charges.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Support

    Vendor support

    For Community Support, please visit the Cisco Security Firepower community using the link below and include NGFWv-AWS in the title of your discussion for the fastest response. The below listed partners can also sell support contracts. https://supportforums.cisco.com/community/12249536/firepower-firesight-system  http://WWW.TRACE3.COM  http://WWW.SHI.COM  http://WWW.SYCOMP.COM  http://WWW.COMPUTACENTER.COM  (EMEAR) http://WWW.VELOCIS.IN  (APJ)

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    25
    In Network Infrastructure
    Top
    10
    In Migration
    Top
    10
    In Device Connectivity

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Intrusion Prevention System
    Snort 3 IPS engine for detecting and preventing network-based attacks and intrusions
    Encrypted Traffic Visibility
    Encrypted Visibility Engine providing Layer 7 policy enforcement and deep visibility into QUIC and TLS 1.3 encrypted traffic without decryption
    Threat Intelligence Integration
    Cisco Talos Threat Intelligence integration for protection against known and unknown threats
    Deep Packet Inspection
    Deep packet inspection capability combined with application visibility and control for comprehensive traffic analysis
    Firewall Clustering
    Firewall clustering support for high availability and distributed threat defense across cloud environments
    Intrusion Detection and Prevention
    Intrusion detection and prevention (IPS) capabilities for threat detection and mitigation
    Application Security and Visibility
    Application visibility and control through AppSecure with L4-L7 security services
    VPN and Secure Connectivity
    IPsec and full mesh VPN termination services for secure connectivity across on-premises data centers, campuses, branches, and geographically dispersed VPCs
    Cloud-Native Integration
    Integration with AWS services including Elastic Load Balancer, Auto-Scaling Groups, CloudWatch, Security Hub, Key Management Service, and Gateway Load Balancer (GWLB) with L3 gateway and L4 load balancer capabilities
    Advanced Routing and Network Services
    Cloud-grade routing capabilities with NAT, firewall, and network address translation services
    Software-Defined WAN (SD-WAN) Engine
    Built-in SD-WAN engine combining multiple remote access and WAN optimization technologies for secure access to cloud resources across office and mobile users.
    Intrusion Prevention System (IPS)
    Integrated IPS engine providing real-time network protection against a broad range of network threats.
    Application-Based Traffic Control
    Enterprise-grade firewalling with application-aware segmentation and traffic control based on application identity, ports, and user identity.
    Network Access Control
    Network access control enforcement capabilities for enforcing security policies across dispersed network environments.
    VPN and Secure Connectivity
    VPN technologies enabling secure remote access, secure office-to-cloud connectivity, and cloud network segmentation with support for branch office direct internet schemes.

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.2
    172 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    48%
    43%
    8%
    1%
    0%
    16 AWS reviews
    |
    156 external reviews
    External reviews are from G2  and PeerSpot .
    AwaisEjaz

    Zero-trust security has protected critical banking applications and supports AI-driven incident response

    Reviewed on Jul 29, 2026
    Review provided by PeerSpot

    What is our primary use case?

    As a bank, I serve as the Chief Technology Officer at one of the largest banks in Pakistan, UBL, United Bank Limited, and we have Cisco Secure Firewall  deployed at the bank in the data center. We apply unified policies across the environment because we have two data center core firewalls running at the production as well as DR site.

    What is most valuable?

    Cisco Secure Firewall , especially the next generation FTD firewalls, offers application visibility, the intrusion prevention system, advanced malware protection, Snort rules, and threat intelligence feed from Cisco's Talos cloud, which I find very useful.

    Cisco Secure Firewall has provided us the ability to go a long way towards zero-trust architecture, which is useful in implementing because zero-trust architecture has many more features such as multi-factor authentication, encryption, and segmentation. We have integrated Cisco's ACI, the Application Centric Infrastructure, the software-defined networks with Cisco Secure Firewall to achieve micro-segmentation and a good, fair bit of zero-trust architecture.

    We are using Cisco's XDR  platform, which was previously labeled as Cisco SecureX. We have been using the Cisco XDR , Extended Detection and Response platform for the last two years, integrating Cisco Secure Firewall, Cisco Stealthwatch , Cisco Umbrella  service for secure DNS, as well as Cisco endpoints with the XDR  platform. We have onboarded Cisco's MDR service, Managed Detection and Response  service onto the XDR platform.

    It has a very useful impact on productivity because when we integrate our ecosystem with the XDR platform, it operates on the AI algorithm, correlating and analyzing incidents for severity level by the AI algorithm, which gives the severity of the incident as well as eliminates false positives and provides it to the SOC level two analyst to contain or remediate the incident. This is a good feature and has automated somewhat the first level of incident response.

    What needs improvement?

    I am looking forward to Cisco for providing AI detection capability so that we have defenses against AI-assisted cyber attacks.

    As I mentioned, I am looking forward to Cisco for providing AI-assisted defenses because nowadays there is a lot of AI-assisted attacks. Traditional or even next-generation firewalls would not go a long way as far as defense is concerned, and I think every other vendor such as Palo Alto, Fortinet, and Sophos are working on improving the firewall with respect to AI-assisted attacks, which is what I expect from Cisco as well.

    Presently, I am looking for AI features. I do not see any other feature because we are already using advanced malware protection and IPS and application visibility, threat intelligence feeds, and AI would probably be a good addition to the portfolio.

    For how long have I used the solution?

    I have been dealing with Cisco Secure Firewall for quite some time.

    What do I think about the stability of the solution?

    I am satisfied with Cisco Secure Firewall in our organization.

    What do I think about the scalability of the solution?

    As the organization grows year by year, I believe it is scaling very well concerning the growth of the organization, the number of branches, the number of users increasing, and the applications scaling out. It is scaling out as per the requirement.

    How are customer service and support?

    I would rate the technical support by Cisco as eight or nine.

    Which solution did I use previously and why did I switch?

    I included Palo Alto and Fortinet firewalls in our RFP process before opting for Cisco, but I believe for data center firewalling, Cisco is best suited amongst its competitors.

    How was the initial setup?

    The deployment was very seamless because we have our own team in the bank for deployment, and we also took professional services when we deployed Cisco Secure Firewall. I do not think that we faced any challenges or hiccups during the deployment.

    What about the implementation team?

    We have a team of ten to twelve people, but they are not only looking after Cisco Secure Firewall; they are looking at the security posture of the bank, including endpoints and file integrity manager, and MDR. I think two people would be the right, appropriate number looking after Cisco Secure Firewall.

    What's my experience with pricing, setup cost, and licensing?

    The price is reasonable and it is competitive and affordable. It is from Cisco's authorized partners in Pakistan.

    What other advice do I have?

    The deployment was very seamless because we have our own team in the bank for deployment, and we also took professional services when we deployed Cisco Secure Firewall. I do not think that we faced any challenges or hiccups during the deployment.

    Whenever the traffic comes to the server farm and whenever a user accesses the application, we have one hundred twenty-five applications behind Cisco Secure Firewall, and it is almost all the bank which is using Cisco Secure Firewall. If I can give an exact number, probably we have thirty-one thousand employees in the bank, and all their applications are hosted behind Cisco Secure Firewall. I rate this product nine out of ten.

    Bruno da Silva

    Security policies have supported complex integrations and now manage diverse global access

    Reviewed on Jul 28, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Regarding the implementation of Cisco Secure Firewall, I imagine that my colleagues from the security department and networking have a lot of complex configurations based on the requirements that we need.

    We have an EVID ecosystem, and this implies very different kinds of configurations and rules.

    There are general rules, and then there are some specific rules based, for example, on users that are in different geographies, accessing different applications, and with different needs and requirements in terms of security.

    There are the back-end applications that must communicate between them and with external partners. There is also another integration complexity that my colleagues must face.

    Currently, I am working with some multivendors, for example, with Salesforce, Microsoft Dynamics, EVM DataPower, OpenAI, and Anthropic. I think I could miss other providers, but basically, these are the ones.

    What is most valuable?

    My organization benefits from utilizing Cisco Secure Firewall. I do not know the details of everything, but I hope my colleagues do a great job and Cisco Systems could help us to identify any of these constraints that could exist.

    What needs improvement?

    I cannot tell you about any drawbacks, downsides, or weak points of Cisco Secure Firewall which I would eliminate because I cannot respond with clarity.

    I know there are known vulnerabilities in every system that we know, but I do not know in particular one that I could specify. If I worked with it on a daily basis, I could be more clear. Right now, I do not know.

    For how long have I used the solution?

    I have been working in my organization with Cisco Secure Firewall for a long time; I started on this project ten years ago, then I returned in two thousand and twenty-one. It has been Cisco since then.

    Which solution did I use previously and why did I switch?

    I have not tried or used the solution within the last twelve months period because I use Apache but I'm not using it now.

    I have used it for a long time, three or four years, but now I am not using it. Since, I think, three years, four years approximately.

    What other advice do I have?

    I believe I am not familiar with the product Secure Cloud Protection for Salesforce. I don't know because I am working with the integration and also with the Salesforce component integrations between Salesforce and billing and invoicing platforms.

    In terms of security, I must comply with the guidance of the corporation that I am in.

    In terms of security, it is another area. We need to only comply and be compliant with the guidance and requirements that they demand.

    I would rate this review an eight out of ten.

    MartinsZipp

    Central management has unified security policies and supports consistent enterprise protection

    Reviewed on Jul 28, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I work with both the on-premises and cloud versions of the solution, as well as the SaaS version, for clients.

    What is most valuable?

    What makes Cisco Secure Firewall  appealing to customers is that all the features are the same across all firewalls, but customers appreciate that it is a stable solution and more secure. There are not as many security breaches as with Fortinet, and that is the reason why they often choose Cisco firewalls because of the stability of enterprise-level cybersecurity protection and overall position in the market.

    I have used new features recently in Cisco Secure Firewall , including AI support and AI central management, which is the latest feature from Cisco central management that allows me to manage all those appliances and firewalls centrally, also with some AI agents and chats and some additional regression features.

    The integration of the SecureX feature has helped my productivity and response time, but I need to ask colleagues about this since they are more involved in this.

    I assess the product's ability to unify and consolidate policies across my environment as quite straightforward and easy to do with this central management console.

    What needs improvement?

    In Cisco Secure Firewall, I have come across some drawbacks, downsides, or weak points, specifically that for some of the solutions or services, the user interface is not as great or lately updated as it should be; it looks old-school.

    For how long have I used the solution?

    I have known Cisco Secure Firewall for more than five years, but it is not my top product. I am partially working with it.

    How are customer service and support?

    Regarding Cisco technical support, I have communicated with them, and they are helpful and responsive. I rate them eight out of ten. It is a standard procedure, and I do not have any problems with it.

    How was the initial setup?

    The implementation of Cisco Secure Firewall is more or less straightforward. I have not encountered any problems lately or at all.

    It takes a couple of days, I would estimate, usually to deploy the product. However, this depends on the configuration.

    What about the implementation team?

    I need more or less one or two people involved in the implementation process, depending on some additional services. When I am talking about the firewalls only, I could do it with one person, but if there are some additional cybersecurity services connected, then I could add some additional specialists.

    What other advice do I have?

    I am using Cisco SecureX with Cisco Secure Firewall in some cases.

    My evaluation of Cisco Secure Firewall in helping my organization implement a Zero Trust security model is that it functions more or less as a marketing abbreviation, but Cisco has all the features and configuration possibilities to implement Zero Trust out of the box. We have seen some cases when we combine it with Cisco Duo  to achieve the highest level of Zero Trust access to devices and also to firewalls.

    In terms of price, Cisco Secure Firewall is appealing for many in the enterprise segment, though for many customers it is too expensive. However, for customers in enterprises or at large corporations, the price is acceptable, depending on whether the customer is a small-medium business or enterprise. It is positioned more for enterprise customers.

    I rate this product eight out of ten overall.

    reviewer2865999

    Secure access has protected company data and supports fast VPN work from office and home

    Reviewed on Jul 11, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Cisco Secure Firewall  is as a security program, and I am using it to establish VPN connections. We are logging into this system to protect all information.

    For a quick specific example of how I use Cisco Secure Firewall  in my daily work, we log into this program every day using a specific network. I use my company email and a password to access this program, allowing us to use all the systems and programs in the credit and collections area.

    Cisco Secure Firewall serves as the main security tool I use nowadays, primarily to protect information, the systems, and all the facts about the company.

    What is most valuable?

    In my opinion, the best features Cisco Secure Firewall offers are its speed, as it is one of the quickest and most secure systems I have used during the pandemic period. I have had the opportunity to try different systems to protect or log in at work, and this is one of the quickest and greatest systems available.

    Cisco Secure Firewall has positively impacted my organization by providing a quick and easy program to log into the VPN, which is very effective. I do not have troubles or issues with the connection, and I believe that is the most important aspect of this program.

    What needs improvement?

    I think the system is quick with two steps to log into the security program. I am satisfied with how it works right now, and I have not noticed things that I want to be different with Cisco Secure Firewall.

    For how long have I used the solution?

    I have been using Cisco Secure Firewall for one full year.

    What do I think about the stability of the solution?

    I think Cisco Secure Firewall is very stable. I have experienced one or two issues during my usage this year.

    What do I think about the scalability of the solution?

    Cisco Secure Firewall's scalability is good for my organization right now. We have a hybrid mode to work, and it is a very efficient program for the company.

    How are customer service and support?

    I have not needed to reach out for help regarding Cisco Secure Firewall. I believe the issues are more about the network or internet connections than Cisco Secure Firewall itself.

    Which solution did I use previously and why did I switch?

    I did not evaluate other options before choosing Cisco Secure Firewall.

    What's my experience with pricing, setup cost, and licensing?

    I do not have a clear idea about the pricing, setup cost, or licensing for Cisco Secure Firewall, as I am not an IT employee and do not have information about licensing. I am only a user.

    What other advice do I have?

    I think the end-to-end visibility from Cisco optimizes the experience in a hybrid setup.

    I face specific challenges with hybrid and distributed enterprise networks, particularly feeling a little insecure when working from home. Cisco Secure Firewall is a great option because it provides a quick and secure program, allowing me to confidently access the company's systems.

    My advice for others looking into using Cisco Secure Firewall is that it is a quick security program, helping you connect from various places, such as the office, coffee shops, or home. You could try other methods to access the security system, like voice approval or other specific options.

    I would rate this product a 9 out of 10.

    Jeff Nagel

    Firewall has delivered clear visibility and has simplified secure internet protection

    Reviewed on Jun 01, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Cisco Secure Firewall  serves as our primary internet firewall.

    What is most valuable?

    I appreciate the ease of use most about Cisco Secure Firewall . The end-to-end visibility offered by Cisco Secure Firewall is excellent, and I have no issues with any of the products. I assess the operational efficiency of Cisco Secure Firewall in my IT environment as positive because I value Cisco products and advocate for them whenever I can.

    What needs improvement?

    The only area that can be improved is related to Cisco Secure Firewall Management Center , as certain versions are not always stable, which has been our only issue.

    For how long have I used the solution?

    I have been using Cisco Secure Firewall for twenty years.

    What do I think about the stability of the solution?

    I assess the stability and reliability of Cisco Secure Firewall as good; it is rock solid for me.

    What do I think about the scalability of the solution?

    I am uncertain about the specific challenges I face with hybrid distribution, especially regarding hybrid and distributed enterprise networks that Cisco Secure Firewall addresses.

    How are customer service and support?

    I evaluate customer service and technical support at a ten on a scale of one to ten, with ten being the best.

    Which solution did I use previously and why did I switch?

    I have used Cisco Secure Firewall throughout my career.

    How was the initial setup?

    I would describe my experience with deploying Cisco Secure Firewall as positive because there is extensive documentation and support available, making the deployment very straightforward.

    Which other solutions did I evaluate?

    I have never considered anything other than Cisco Secure Firewall; I would never switch.

    Which deployment model are you using for this solution?

    On-premises

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    View all reviews