Listing Thumbnail

    Cisco Secure Firewall ASA Virtual - PAYG

     Info
    Deployed on AWS
    Free Trial
    Ideal for remote worker and multi-tenant environments, Secure Firewall ASA Virtual provides scalable VPN options including remote access, site-to-site, clientless, and more. Experience Cisco's industry-leading firewall to protect your cloud resources.
    4

    Overview

    Experience Cisco's industry leading Layer 3 and Layer 4 firewall in a virtualized form factor to protect your cloud environment. You can now take advantage of:

    High performance security:

    • Dynamically scale resilient remote access to meet demand with AWS Route 53
    • Leverage site-to-site VPN, clientless remote access, and remote access VPN
    • Integrate with AWS Transit Gateway for scalable inter-VPC traffic

    Protection for your dynamic environments:

    • Ingress and egress traffic protection across your cloud environments
    • Advanced inspection, including voice and video protocols
    • Micro-segmentation capabilities for east-west traffic

    Cloud-delivered management:

    • Consistently manage policies with our cloud-delivered management solution, Cisco Defense Orchestrator (CDO)
    • Increase efficiency with low-touch provisioning for faster firewall deployments
    • Supports REST API, an HTTP-based interface for appliance management, security policies, status monitoring, and enables multiple cloud management solutions

    For supported AWS instances, please see the data sheet.

    Highlights

    • Deploy remote access in as little as 20 minutes with Cisco ASAv RA-VPN on AWS Quick Start guide.
    • Ideal for remote worker and multi-tenant environments that require secure, scalable, and resilient remote access options.
    • Consistent policy management in the cloud with Cisco Defense Orchestrator.

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    OtherLinux 9.24.1

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Free trial

    Try this product free for 30 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.

    Cisco Secure Firewall ASA Virtual - PAYG

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (52)

     Info
    Dimension
    Cost/hour
    c5.xlarge
    Recommended
    $0.92
    c5n.large
    $0.35
    m5zn.large
    $0.35
    m5.xlarge
    $0.92
    m4.xlarge
    $0.92
    m5n.xlarge
    $0.92
    m5n.2xlarge
    $1.93
    m4.2xlarge
    $1.93
    m5.2xlarge
    $1.93
    m5n.4xlarge
    $3.12

    AI Insights

     Info

    Dimensions summary

    You pay by the hour for the software running on your chosen AWS instance type. Each dimension maps to a specific instance size, from large through 4xlarge, across families like c5, c6i, c6in, c6a, m4, m5, m5n, and m5zn. Larger instances hold more virtual CPU and memory, which supports higher firewall throughput and more VPN sessions. Pricing scales with the instance you select rather than a fixed license tier. You can start small and move to a bigger instance if you need more capacity. Billing is usage-based, so you pay only for running hours.

    Top-of-mind questions for buyers

    One unit is a single running instance of the software on your chosen AWS instance type. The instance size sets the virtual CPUs and memory available. Larger sizes support higher stateful inspection throughput, more concurrent sessions, and more VPN peers. You pick the instance that matches your throughput needs.
    Software charges meter running hours only. A fully stopped instance stops accruing software charges. Stopped instances may still incur underlying AWS storage fees for attached volumes, but the firewall software bills only for time the instance is actually running.
    Yes. Because pricing follows the AWS instance you select, you can spin up a larger instance size when demand grows. The datasheet notes that higher-performance models can be deployed to add bandwidth or protection. Your hourly rate then reflects the new instance size.
    www.cisco.com
    Helpful?

    Vendor refund policy

    The Cisco ASAv instance can be terminated at any time to stop incurring charges.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Support

    Vendor support

    For all support queries, only Community Support is available for this product listing. Please visit the Cisco Security - Firewalling community using the link above and include "ASA-AWS" in the title of your community discussion for the fastest response. https://supportforums.cisco.com/community/firewalling  For all support queries, only Community Support is available for this product listing. Please visit the Cisco Security - Firewalling community using the link above and include "ASA-AWS" in the

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    25
    In Network Infrastructure
    Top
    10
    In Migration
    Top
    10
    In Device Connectivity

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    VPN Connectivity Options
    Supports site-to-site VPN, remote access VPN, and clientless remote access capabilities for secure connectivity
    Traffic Inspection and Segmentation
    Provides Layer 3 and Layer 4 firewall inspection with advanced protocol analysis including voice and video, plus micro-segmentation for east-west traffic protection
    Cloud Infrastructure Integration
    Integrates with AWS Transit Gateway for scalable inter-VPC traffic management and AWS Route 53 for dynamic scaling of remote access
    API-Based Management
    Exposes REST API HTTP-based interface for appliance management, security policy configuration, and status monitoring across multiple cloud management solutions
    Cloud-Delivered Policy Management
    Centralized policy management through Cisco Defense Orchestrator with low-touch provisioning for rapid firewall deployment
    Intrusion Detection and Prevention
    Intrusion detection and prevention (IPS) capabilities for threat detection and mitigation
    Application Security and Visibility
    Application visibility and control through AppSecure with L4-L7 security services
    VPN and Secure Connectivity
    IPsec and full mesh VPN termination services for secure connectivity across on-premises data centers, campuses, branches, and geographically dispersed VPCs
    Cloud-Native Integration
    Integration with AWS services including Elastic Load Balancer, Auto-Scaling Groups, CloudWatch, Security Hub, Key Management Service, and Gateway Load Balancer (GWLB) with L3 gateway and L4 load balancer capabilities
    Advanced Routing and Network Services
    Cloud-grade routing capabilities with NAT, firewall, and network address translation services
    Software-Defined WAN (SD-WAN) Engine
    Built-in SD-WAN engine combining multiple remote access and WAN optimization technologies for secure access to cloud resources across office and mobile users.
    Intrusion Prevention System (IPS)
    Integrated IPS engine providing real-time network protection against a broad range of network threats.
    Application-Based Traffic Control
    Enterprise-grade firewalling with application-aware segmentation and traffic control based on application identity, ports, and user identity.
    Network Access Control
    Network access control enforcement capabilities for enforcing security policies across dispersed network environments.
    VPN and Secure Connectivity
    VPN technologies enabling secure remote access, secure office-to-cloud connectivity, and cloud network segmentation with support for branch office direct internet schemes.

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4
    121 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    40%
    48%
    5%
    1%
    6%
    33 AWS reviews
    |
    88 external reviews
    External reviews are from G2  and PeerSpot .
    Muhammad Awais Afzal

    Comprehensive security has protected diverse enterprise networks and supports complex deployments

    Reviewed on Aug 07, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I have been using a firewall for more than eight years throughout my career overall.

    I am working as a network architect in my current field for a long time. I need to evaluate the solution based on the RFP and size the right solution for the right project based on the client's specification, client requirement, and the requirement of the consultant.

    We are using Cisco Secure Firewall on the network parameters to secure the WAN traffic, enabling all the features of the next-generation firewall, which includes the IPS, IDS, web filtering, URL filtering, and we are enabling the SD-WAN feature for the multi-WAN links for high availability of the WAN. Based on the RFP and client demand, we are also using it as a data center firewall to protect the data center traffic. In some use cases, we are using separate firewalls on the WAN, such as a WAN firewall, then an internet firewall, and the DMZ firewall based on the different use cases. We are using Cisco firewall on almost all the zones to secure our network.

    For some RFP and projects, we are using the perimeter firewall from Cisco and data center firewall from competitor vendors. It can be FortiNet, Palo Alto, or Sophos, depending on the use cases. Sometimes, the data center firewall is Cisco and the perimeter firewall is from another vendor. It is the customer's choice to keep different firewalls on different zones and from different vendors.

    What is most valuable?

    There is a lot to appreciate about Cisco Secure Firewall and its next-generation features. One firewall can, if it's a mid-scale project, serve as a perimeter firewall that is more than enough to protect you from all of the outsourced bad actors, which includes the web filtering, URL filtering, and also the VPN, which includes the antivirus, IPS, and IDS. All of the features of the next-generation firewall in one box are more than enough to protect you from all of the bad actors from outside your organization.

    What needs improvement?

    One thing I dislike about Cisco Secure Firewall is that most customers do not want to go with one vendor. Cisco also provides the network devices, which includes the core switch and switches, and other equipment, so customers dislike going with the same vendor for the firewall. They prefer that the firewall vendor should be different from their network backbone. If one side is exploited, such as there is a vulnerability on the switch ISO, there is a possibility your firewall can also be disrupted by the same vulnerability. Customers do not want to go with the same vendor across all their network. They want to change the firewall vendor to another, such as FortiNet and Palo Alto to keep some modularity in the network.

    Another thing I do not appreciate in Cisco Secure Firewall specifically is that the configuration aspect is a bit difficult compared to other vendors such as FortiNet and Palo Alto. You need a good hands-on engineer who can configure Cisco Secure Firewall as compared to the other vendors. The learning curve is more complex in Cisco compared to other market vendors. Additionally, the cost difference is almost fifteen to twenty percent more than other vendors.

    The deployment process is a bit difficult, especially on Cisco, because first you need to deploy Cisco Secure Firewall and if you have multiple firewalls from Cisco, you need FMC. Without FMC, you cannot deploy most of the Cisco Secure Firewall features; you need FMC as mandatory. In the case of other vendors, you do not need their central management, and if you want to manage the firewall from a central location, it is acceptable, but you can configure the full features of the firewall from the firewall interface. Cisco does not provide this ease. You have to have FMC to enable a certain set of features on Cisco Secure Firewall. Additionally, the learning curve is a bit difficult; you should have good hands-on experience with their solution to make all the configuration required as per the customer requirement.

    What do I think about the stability of the solution?

    I have not faced any crashing of Cisco Secure Firewall in any of my clients. I have deployments around twenty plus customers in Saudi Arabia and different countries and cities, in different use cases. I have Cisco Secure Firewall in hospitals, hotels, airports, and shopping malls, and I have never faced complaints of a Cisco Secure Firewall crash or anything similar. They are very stable.

    What do I think about the scalability of the solution?

    When you are selecting the firewall and choosing one with a future perspective for growth, taking into consideration fifty percent or more than fifty percent, Cisco Secure Firewall is scalable. However, when selecting a firewall without considering future growth due to budget constraints, you may encounter bottlenecks later. In some cases, customers specifically ask to size Cisco Secure Firewall based on fifty percent occupancy and fifty percent for future growth. Cisco Secure Firewall is scalable. Cisco's new models allow you to upgrade their network card from ten gigabit to twenty-five gigabit and from twenty-five gigabit to forty gigabit and forty gigabit to one hundred gigabit based on different models. Their new models are highly scalable, but it ultimately depends on how much the customer wants to pay.

    How are customer service and support?

    I have contacted Cisco's technical support regarding the firewall when needed. On most of the clients, especially when we need to upgrade Cisco Secure Firewall to the latest firmware, we have the project Airport and we have the operation and maintenance at the ICAD Group company. Whenever we need to upgrade Cisco Secure Firewall to the latest stable release, we first open the TAC case with Cisco. We take a Cisco engineer on board with us, and he is involved until the end of the update cycle. Once Cisco Secure Firewall is fully upgraded, we confirm that all the policies and firewall rules are running efficiently without any issues before we close the TAC case with Cisco.

    For support, I would give ten out of ten, but I have faced issues over the past two or three years. When we open the TAC case and the TAC case goes to America or a European country, the support engineer is very good, and he guides us and is with us, solving all issues effectively. However, when the TAC case goes to an Indian engineer, I am really surprised. There is a big gap in the learning curve. The engineers assigned from the European or American side and the engineers assigned from India to the TAC case are completely different experiences. This is my personal experience. When I have received TAC cases from India, I have been totally disappointed. In contrast, the engineers assigned from America or European countries are very good; they solve issues smartly and quickly. The engineers assigned from India typically keep asking for logs and other details, then escalate the case to a further level, and finally someone will be assigned from America or North America who will solve the issue.

    For the support case, I would give nine out of ten to Cisco TAC support. They are very good and efficient, but over the past two or three years, I would deduct one mark for the TAC support due to the engineers assigned from India.

    What other advice do I have?

    I am the one configuring CCW on the Cisco portal. I am customizing Cisco Secure Firewall based on the customer requirement and also other vendors, which include FortiNet, Palo Alto, and Sophos, while I configure the firewall on the portal. Cisco Secure Firewall price is a bit higher, and the subscription cost is also a bit higher compared to other vendors. The interface, number of availability of ten gigabit, one gigabit, or twenty-five, forty gigabit interface, if I compare to other vendors for the same series of model, if I compare Cisco 3105 with the FortiNet 401F, they almost have the same features and throughput, but the number of interfaces is more on the other vendor firewall compared to Cisco Secure Firewall. Cisco Secure Firewall is nearly ten to fifteen percent more than other market vendors.

    Maintenance is required, of course. You can say that almost every year and based on the customer requirement. For example, in one site, we are using a firewall that has a ten gigabit interface, and the customer demanded that we upgrade the throughput to twenty-five gigabit or forty gigabit, but the firewall supports twenty-five gigabit. We removed the ten gigabit card and we added the available twenty-five gigabit card from Cisco Secure Firewall. In terms of hardware maintenance, I do not see any hardware maintenance needed due to a firewall failure; it is a very stable firewall with good build quality. Also, if you have Cisco Smart Net and if there is any chance of firewall failure, they will replace it on the next business day. If you have twenty-four seven support, they will replace it in four hours, which varies based on the use cases and which Smart Net service you have on the client side.

    In some projects, we faced a small use case with Cisco during the tendering stage. When we need to size the correct solution, especially for hybrid deployment on some projects, we did not have a well-trained or good engineer from Cisco who could guide us and size the solution based on the customer need. On some projects, time is very limited; we have a small window of one week or ten days to submit our proposal to the customer. We need to size the solution based on the customer need, but sometimes the representative provided by a Cisco account manager does not understand the solution or size it correctly, particularly for hybrid deployments, causing us to lose the RFP. Overall, I have given this review a rating of ten out of ten.

    Vijai-Cyriac

    Unified security policies have protected hybrid workloads and support zero trust access

    Reviewed on Jul 30, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I have been working with Cisco Secure Firewall for almost nine years, and I want to share my experience with this solution.

    I have been working with both the on-premises and cloud versions of Cisco Secure Firewall.

    The choice between deployment models depends on the use cases. For on-premises use cases, I deploy an on-premises firewall, but for workloads that are based on the cloud, I use the cloud-based firewall.

    What is most valuable?

    Cisco Secure Firewall has very good IDS and IPS capabilities, as well as excellent threat intelligence features, which are some of the best aspects of the product that I appreciate.

    It actually helps with integration by allowing me to integrate different solutions within one platform.

    What needs improvement?

    I am not currently experiencing many drawbacks with Cisco Secure Firewall. However, since things are migrating to the cloud, the product needs to be more optimized for cloud environments.

    Recently, AI-initiated threats have emerged, so Cisco Secure Firewall should have enhanced capabilities to counter AI threats.

    For how long have I used the solution?

    I have 22 years of overall experience working in the software field.

    How was the initial setup?

    The deployment for the product was not quite simple, but it was acceptable. I received support from Cisco during the process, so the overall experience was good.

    I would rate the technical support from Cisco at an eight out of ten, with ten being the best.

    What about the implementation team?

    I was assisted by a third party with the deployment.

    I handle both the deployment and operations, so I personally participated in the deployment process.

    What's my experience with pricing, setup cost, and licensing?

    The price for Cisco Secure Firewall is a bit high compared to other vendors.

    Which other solutions did I evaluate?

    Cisco Secure Firewall helps with a Zero Trust security model, and I am implementing a ZTNA access model. I have already implemented Zero Trust. Other vendors besides Cisco also provide ZTNA solutions. Fortinet and Palo Alto are all working with ZTNA and have moved into the ZTNA platform.

    What other advice do I have?

    I would assess Cisco Secure Firewall's ability to unify different policies across my environment.

    AwaisEjaz

    Zero-trust security has protected critical banking applications and supports AI-driven incident response

    Reviewed on Jul 29, 2026
    Review provided by PeerSpot

    What is our primary use case?

    As a bank, I serve as the Chief Technology Officer at one of the largest banks in Pakistan, UBL, United Bank Limited, and we have Cisco Secure Firewall deployed at the bank in the data center. We apply unified policies across the environment because we have two data center core firewalls running at the production as well as DR site.

    What is most valuable?

    Cisco Secure Firewall, especially the next generation FTD firewalls, offers application visibility, the intrusion prevention system, advanced malware protection, Snort rules, and threat intelligence feed from Cisco's Talos cloud, which I find very useful.

    Cisco Secure Firewall has provided us the ability to go a long way towards zero-trust architecture, which is useful in implementing because zero-trust architecture has many more features such as multi-factor authentication, encryption, and segmentation. We have integrated Cisco's ACI, the Application Centric Infrastructure, the software-defined networks with Cisco Secure Firewall to achieve micro-segmentation and a good, fair bit of zero-trust architecture.

    We are using Cisco's XDR platform, which was previously labeled as Cisco SecureX. We have been using the Cisco XDR, Extended Detection and Response platform for the last two years, integrating Cisco Secure Firewall, Cisco Stealthwatch, Cisco Umbrella service for secure DNS, as well as Cisco endpoints with the XDR platform. We have onboarded Cisco's MDR service, Managed Detection and Response service onto the XDR platform.

    It has a very useful impact on productivity because when we integrate our ecosystem with the XDR platform, it operates on the AI algorithm, correlating and analyzing incidents for severity level by the AI algorithm, which gives the severity of the incident as well as eliminates false positives and provides it to the SOC level two analyst to contain or remediate the incident. This is a good feature and has automated somewhat the first level of incident response.

    What needs improvement?

    I am looking forward to Cisco for providing AI detection capability so that we have defenses against AI-assisted cyber attacks.

    As I mentioned, I am looking forward to Cisco for providing AI-assisted defenses because nowadays there is a lot of AI-assisted attacks. Traditional or even next-generation firewalls would not go a long way as far as defense is concerned, and I think every other vendor such as Palo Alto, Fortinet, and Sophos are working on improving the firewall with respect to AI-assisted attacks, which is what I expect from Cisco as well.

    Presently, I am looking for AI features. I do not see any other feature because we are already using advanced malware protection and IPS and application visibility, threat intelligence feeds, and AI would probably be a good addition to the portfolio.

    For how long have I used the solution?

    I have been dealing with Cisco Secure Firewall for quite some time.

    What do I think about the stability of the solution?

    I am satisfied with Cisco Secure Firewall in our organization.

    What do I think about the scalability of the solution?

    As the organization grows year by year, I believe it is scaling very well concerning the growth of the organization, the number of branches, the number of users increasing, and the applications scaling out. It is scaling out as per the requirement.

    How are customer service and support?

    I would rate the technical support by Cisco as eight or nine.

    Which solution did I use previously and why did I switch?

    I included Palo Alto and Fortinet firewalls in our RFP process before opting for Cisco, but I believe for data center firewalling, Cisco is best suited amongst its competitors.

    How was the initial setup?

    The deployment was very seamless because we have our own team in the bank for deployment, and we also took professional services when we deployed Cisco Secure Firewall. I do not think that we faced any challenges or hiccups during the deployment.

    What about the implementation team?

    We have a team of ten to twelve people, but they are not only looking after Cisco Secure Firewall; they are looking at the security posture of the bank, including endpoints and file integrity manager, and MDR. I think two people would be the right, appropriate number looking after Cisco Secure Firewall.

    What's my experience with pricing, setup cost, and licensing?

    The price is reasonable and it is competitive and affordable. It is from Cisco's authorized partners in Pakistan.

    What other advice do I have?

    The deployment was very seamless because we have our own team in the bank for deployment, and we also took professional services when we deployed Cisco Secure Firewall. I do not think that we faced any challenges or hiccups during the deployment.

    Whenever the traffic comes to the server farm and whenever a user accesses the application, we have one hundred twenty-five applications behind Cisco Secure Firewall, and it is almost all the bank which is using Cisco Secure Firewall. If I can give an exact number, probably we have thirty-one thousand employees in the bank, and all their applications are hosted behind Cisco Secure Firewall. I rate this product nine out of ten.

    Bruno da Silva

    Security policies have supported complex integrations and now manage diverse global access

    Reviewed on Jul 28, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Regarding the implementation of Cisco Secure Firewall, I imagine that my colleagues from the security department and networking have a lot of complex configurations based on the requirements that we need.

    We have an EVID ecosystem, and this implies very different kinds of configurations and rules.

    There are general rules, and then there are some specific rules based, for example, on users that are in different geographies, accessing different applications, and with different needs and requirements in terms of security.

    There are the back-end applications that must communicate between them and with external partners. There is also another integration complexity that my colleagues must face.

    Currently, I am working with some multivendors, for example, with Salesforce, Microsoft Dynamics, EVM DataPower, OpenAI, and Anthropic. I think I could miss other providers, but basically, these are the ones.

    What is most valuable?

    My organization benefits from utilizing Cisco Secure Firewall. I do not know the details of everything, but I hope my colleagues do a great job and Cisco Systems could help us to identify any of these constraints that could exist.

    What needs improvement?

    I cannot tell you about any drawbacks, downsides, or weak points of Cisco Secure Firewall which I would eliminate because I cannot respond with clarity.

    I know there are known vulnerabilities in every system that we know, but I do not know in particular one that I could specify. If I worked with it on a daily basis, I could be more clear. Right now, I do not know.

    For how long have I used the solution?

    I have been working in my organization with Cisco Secure Firewall for a long time; I started on this project ten years ago, then I returned in two thousand and twenty-one. It has been Cisco since then.

    Which solution did I use previously and why did I switch?

    I have not tried or used the solution within the last twelve months period because I use Apache but I'm not using it now.

    I have used it for a long time, three or four years, but now I am not using it. Since, I think, three years, four years approximately.

    What other advice do I have?

    I believe I am not familiar with the product Secure Cloud Protection for Salesforce. I don't know because I am working with the integration and also with the Salesforce component integrations between Salesforce and billing and invoicing platforms.

    In terms of security, I must comply with the guidance of the corporation that I am in.

    In terms of security, it is another area. We need to only comply and be compliant with the guidance and requirements that they demand.

    I would rate this review an eight out of ten.

    MartinsZipp

    Central management has unified security policies and supports consistent enterprise protection

    Reviewed on Jul 28, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I work with both the on-premises and cloud versions of the solution, as well as the SaaS version, for clients.

    What is most valuable?

    What makes Cisco Secure Firewall appealing to customers is that all the features are the same across all firewalls, but customers appreciate that it is a stable solution and more secure. There are not as many security breaches as with Fortinet, and that is the reason why they often choose Cisco firewalls because of the stability of enterprise-level cybersecurity protection and overall position in the market.

    I have used new features recently in Cisco Secure Firewall, including AI support and AI central management, which is the latest feature from Cisco central management that allows me to manage all those appliances and firewalls centrally, also with some AI agents and chats and some additional regression features.

    The integration of the SecureX feature has helped my productivity and response time, but I need to ask colleagues about this since they are more involved in this.

    I assess the product's ability to unify and consolidate policies across my environment as quite straightforward and easy to do with this central management console.

    What needs improvement?

    In Cisco Secure Firewall, I have come across some drawbacks, downsides, or weak points, specifically that for some of the solutions or services, the user interface is not as great or lately updated as it should be; it looks old-school.

    For how long have I used the solution?

    I have known Cisco Secure Firewall for more than five years, but it is not my top product. I am partially working with it.

    How are customer service and support?

    Regarding Cisco technical support, I have communicated with them, and they are helpful and responsive. I rate them eight out of ten. It is a standard procedure, and I do not have any problems with it.

    How was the initial setup?

    The implementation of Cisco Secure Firewall is more or less straightforward. I have not encountered any problems lately or at all.

    It takes a couple of days, I would estimate, usually to deploy the product. However, this depends on the configuration.

    What about the implementation team?

    I need more or less one or two people involved in the implementation process, depending on some additional services. When I am talking about the firewalls only, I could do it with one person, but if there are some additional cybersecurity services connected, then I could add some additional specialists.

    What other advice do I have?

    I am using Cisco SecureX with Cisco Secure Firewall in some cases.

    My evaluation of Cisco Secure Firewall in helping my organization implement a Zero Trust security model is that it functions more or less as a marketing abbreviation, but Cisco has all the features and configuration possibilities to implement Zero Trust out of the box. We have seen some cases when we combine it with Cisco Duo to achieve the highest level of Zero Trust access to devices and also to firewalls.

    In terms of price, Cisco Secure Firewall is appealing for many in the enterprise segment, though for many customers it is too expensive. However, for customers in enterprises or at large corporations, the price is acceptable, depending on whether the customer is a small-medium business or enterprise. It is positioned more for enterprise customers.

    I rate this product eight out of ten overall.

    View all reviews