Cisco Adaptive Security Appliance (ASA) Software vs. Forcepoint NGFW

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Cisco Adaptive Security Appliance (ASA) Software
Score 9.0 out of 10
N/A
Cisco Adaptive Security Appliance (ASA) software is the core OS for the ASA suite. It provides firewall functionality, as well as integration with context-specific Cisco security modules. It is scaled for enterprise-level traffic and connections.N/A
Forcepoint NGFW
Score 10.0 out of 10
N/A
Forcepoint Next-Generation Firewall delivers network security at scale. They can be deployed from anywhere through the Secure Management Console (SMC) and unify policy management, incident response and reporting.
$900
one-time fee (approx)
Pricing
Cisco Adaptive Security Appliance (ASA) SoftwareForcepoint NGFW
Editions & Modules
No answers on this topic
Forcepoint NGFW N60
$900
one-time fee (approx)
Forcepoint NGFW N120
$1314
one-time fee (approx)
Forcepoint NGFW N350
$7850
one-time fee (approx)
Forcepoint NGFW N1200
$13600
one-time fee (approx)
Forcepoint NGFW N2200
$36000
one-time fee (approx)
Forcepoint NGFW N3400 & N3500
varies
one-time fee
Offerings
Pricing Offerings
Cisco Adaptive Security Appliance (ASA) SoftwareForcepoint NGFW
Free Trial
NoYes
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional DetailsFirewalls are bought predominately through partners and third-party VARs. Pricing for purchase and lease and support options vary by reseller.
More Pricing Information
Community Pulse
Cisco Adaptive Security Appliance (ASA) SoftwareForcepoint NGFW
Features
Cisco Adaptive Security Appliance (ASA) SoftwareForcepoint NGFW
Firewall
Comparison of Firewall features of Product A and Product B
Cisco Adaptive Security Appliance (ASA) Software
7.8
Ratings
10% below category average
Forcepoint NGFW
8.1
Ratings
6% below category average
Identification Technologies6.50 Ratings5.00 Ratings
Visualization Tools6.50 Ratings5.00 Ratings
Content Inspection8.00 Ratings10.00 Ratings
Policy-based Controls9.00 Ratings10.00 Ratings
Active Directory and LDAP7.50 Ratings8.00 Ratings
Firewall Management Console7.50 Ratings10.00 Ratings
Reporting and Logging5.90 Ratings8.00 Ratings
VPN9.00 Ratings9.00 Ratings
High Availability9.00 Ratings9.00 Ratings
Stateful Inspection9.00 Ratings7.00 Ratings
Proxy Server8.00 Ratings00 Ratings
Best Alternatives
Cisco Adaptive Security Appliance (ASA) SoftwareForcepoint NGFW
Small Businesses
pfSense
pfSense
Score 9.9 out of 10
pfSense
pfSense
Score 9.9 out of 10
Medium-sized Companies
Quantum Firewalls and Security Gateways
Quantum Firewalls and Security Gateways
Score 9.6 out of 10
Quantum Firewalls and Security Gateways
Quantum Firewalls and Security Gateways
Score 9.6 out of 10
Enterprises
Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series
Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series
Score 10.0 out of 10
Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series
Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series
Score 10.0 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
Cisco Adaptive Security Appliance (ASA) SoftwareForcepoint NGFW
Likelihood to Recommend
9.0
(0 ratings)
9.0
(0 ratings)
Likelihood to Renew
7.1
(0 ratings)
-
(0 ratings)
Usability
-
(0 ratings)
10.0
(0 ratings)
Availability
7.5
(0 ratings)
-
(0 ratings)
Support Rating
8.7
(0 ratings)
6.0
(0 ratings)
Implementation Rating
8.0
(0 ratings)
-
(0 ratings)
Ease of integration
6.5
(0 ratings)
-
(0 ratings)
User Testimonials
Cisco Adaptive Security Appliance (ASA) SoftwareForcepoint NGFW
Likelihood to Recommend
We moved our operations entirely to the cloud a few years ago. We loved the stability and scalability of the ASA and wanted to, somehow, keep using it. We discovered that ASA was available in the cloud as well and it was branded ASAv. We tested it and noticed that it was equally robust and a perfect fit for us. During the entire migration period, we used ASAv for cloud operations and put a lot of load on it. ASAv performed very well and gave us an easy transition from on-prem to the cloud.
Read full review
If you are looking for a smaller network/security team, the ease and low complexity create an easy to manage environment. One engineer can easily manage 100 nodes/locations. If you are just starting to get security conscious and predict regular adjustments to policy, routing, and access, this is a very good system for making easy to understand and low impact changes on a regular basis without operations interruption.
Read full review
Pros
  • How we can manage: ASDM the GUI is so much easier to manage it even for a new guy also.
  • Traffic handling capacity
  • More secure and the different features it gives.
  • Support from the TAC team or from the community manages to handle issues very efficiently.
Read full review
  • Easy to manage and make changes on - ACL's are done with ease.
  • Easy USB initial configuration - The easy initial setup of a new location and firewall saves massive time. Settings are automatically pushed to new nodes upon contact with the controller.
  • Low Complexity - This system does not have a lot of complexity requiring extra hours, training, or personnel to manage.
Read full review
Cons
  • The Java based ASDM can botch commands and isn't compatible on some more locked down systems.
  • Monitoring. Really the same complaint as above, the monitoring available through the ASDM is crappy at best. A much better solution is to send the logs and mirror packets to a SEIM, but that can create issues of its own when looking for realtime analysis.
  • Compatibility across other ASA models. ASA 5520s don't play well with 5525X which don't play well with older 5510s. Each is great on it's own, but it's next to impossible to logically stack them or have them as layers of firewalls in an infrastructure.
  • Lack of cloud based management. The Cisco Meraki security devices do this well, but the ASAs are still behind in this regard.
Read full review
  • Poor Reporting - It exists but even when calling in to support for assistance, they have no idea how to tackle customizing reports or searching for specific data.
Read full review
Likelihood to Renew
To be honest there has been now great products out in the market compared to Cisco ASA. I beleieve Cisco has to do a lot of improvement in this area. The other defeiniete factors is the cost when it comes to renewals which is always a premium on Cisco products
Read full review
No answers on this topic
Usability
No answers on this topic
The Graphical User Interface is very easy to read, understand and work with. The usability of this product is very high.
Read full review
Reliability and Availability
I generally have not noticed the outages, however since it's a machine it can malfunction, we need to implement the firewall infrastructure in such a way that it is highly available with device failure, region failure etc. Else any solution will be having the issues if they are not build with resiliency.
Read full review
No answers on this topic
Support Rating
The support is usually very good and gets back to you very quickly. However I had some instances of when two engineers will give me wildly different answers to what I thought was a simple question. Overall however I do rate the support highly and they are generally always very good.
Read full review
Support has varied over the history of the company. Terro is a name that comes up often with the best of service from this company.
Read full review
Implementation Rating
It was quite a good one, how ever requires an expertise to deploy hence the SMB segment would be finding it difficult to implement this product. The one good reason is that there are lot of ASA certified engineers in compared to the other certified engineers. Hence this resembles positively on the deployment as you have quite a lot of experienced engineer on your deployment
Read full review
No answers on this topic
Alternatives Considered
Cisco has made it easy to buy, set up, and manage all of our firewalls with the central FirePower Management Center. All licensing is done via one license portal too. Tech support is standardized for all ASA devices and like support engineers who know the different models to provide timely help for any issues. Cisco Talos is a premier could platform which scours the internet looking for threats and develops protections for the ASA's and as such provides zero second coverage when it best can detect global issues.
Read full review
There are similar hardware and license costs between the two products. The Forcepoint NGFW product is by far easier to use and manage.
Read full review
Return on Investment
  • I know a customer who is still using a Pix[.]
  • The 5510 is still being used in one of our setups, and still doing its job this is a lot of Return on Investment.
  • We have managed to turn around projects quickly because most of our engineers understand this firewall very well. We deploy them in a matter of minutes[.]
Read full review
  • Efficiency/Productivity increase. The company moved from Cisco firewall and routing hardware to Forcepoint NGFW. It now takes fewer people and fewer hours to manage the new product. This has allowed the company to put the man-hours to use on other projects and tasks.
  • Long term viability. This has been a concern in the past when the company started as Stonegate, merged to become Stonesoft then got purchased by McAfee, then McAfee got purchased by Intel. However, with Forcepoint the product seems to have found a stable home.
  • Low complexity. The Web GUI based system for management has reduced the cost of personnel and training required. There is no longer a need for the company to have higher trained and higher salary cost employees to manage the system. Mid-level admins at lower salaries are capable of managing the GUI based system with ease.
Read full review
ScreenShots