Cisco Adaptive Security Appliance (ASA) software is the core OS for the ASA suite. It provides firewall functionality, as well as integration with context-specific Cisco security modules. It is scaled for enterprise-level traffic and connections.
N/A
GFI KerioControl
Score 8.5 out of 10
N/A
Kerio Control is a next-gen firewall for SMBs, from Aurea SMB Solutions (formerly GFI Software).
N/A
Pricing
Cisco Adaptive Security Appliance (ASA) Software
GFI KerioControl
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
Cisco Adaptive Security Appliance (ASA) Software
GFI KerioControl
Free Trial
No
No
Free/Freemium Version
No
No
Premium Consulting/Integration Services
No
No
Entry-level Setup Fee
No setup fee
No setup fee
Additional Details
—
—
More Pricing Information
Community Pulse
Cisco Adaptive Security Appliance (ASA) Software
GFI KerioControl
Features
Cisco Adaptive Security Appliance (ASA) Software
GFI KerioControl
Firewall
Comparison of Firewall features of Product A and Product B
Cisco Adaptive Security Appliance (ASA) Software
7.8
Ratings
10% below category average
GFI KerioControl
8.6
Ratings
0% below category average
Identification Technologies
6.50 Ratings
8.00 Ratings
Visualization Tools
6.50 Ratings
7.00 Ratings
Content Inspection
8.00 Ratings
10.00 Ratings
Policy-based Controls
9.00 Ratings
8.00 Ratings
Active Directory and LDAP
7.50 Ratings
9.00 Ratings
Firewall Management Console
7.50 Ratings
10.00 Ratings
Reporting and Logging
5.90 Ratings
7.00 Ratings
VPN
9.00 Ratings
9.00 Ratings
High Availability
9.00 Ratings
8.00 Ratings
Stateful Inspection
9.00 Ratings
10.00 Ratings
Proxy Server
8.00 Ratings
9.00 Ratings
Best Alternatives
Cisco Adaptive Security Appliance (ASA) Software
GFI KerioControl
Small Businesses
pfSense
Score 9.9 out of 10
pfSense
Score 9.9 out of 10
Medium-sized Companies
Quantum Firewalls and Security Gateways
Score 9.6 out of 10
Quantum Firewalls and Security Gateways
Score 9.6 out of 10
Enterprises
Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series
Score 10.0 out of 10
Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series
We moved our operations entirely to the cloud a few years ago. We loved the stability and scalability of the ASA and wanted to, somehow, keep using it. We discovered that ASA was available in the cloud as well and it was branded ASAv. We tested it and noticed that it was equally robust and a perfect fit for us. During the entire migration period, we used ASAv for cloud operations and put a lot of load on it. ASAv performed very well and gave us an easy transition from on-prem to the cloud.
IT works very well in the non-profit and small business space when there is a need for remote access or connecting several sites in a point to point VPN, user management and rule creation are very easy. The use of the MyKerio website for remote management also makes it easy to troubleshoot problems and make changes if technical staff are not onsite.
The Java based ASDM can botch commands and isn't compatible on some more locked down systems.
Monitoring. Really the same complaint as above, the monitoring available through the ASDM is crappy at best. A much better solution is to send the logs and mirror packets to a SEIM, but that can create issues of its own when looking for realtime analysis.
Compatibility across other ASA models. ASA 5520s don't play well with 5525X which don't play well with older 5510s. Each is great on it's own, but it's next to impossible to logically stack them or have them as layers of firewalls in an infrastructure.
Lack of cloud based management. The Cisco Meraki security devices do this well, but the ASAs are still behind in this regard.
To be honest there has been now great products out in the market compared to Cisco ASA. I beleieve Cisco has to do a lot of improvement in this area. The other defeiniete factors is the cost when it comes to renewals which is always a premium on Cisco products
Very easy to use and manage, user training takes less then 10 minutes. Technicians can perform basic tasks with less then an hour of training and can master it in under a year.
I generally have not noticed the outages, however since it's a machine it can malfunction, we need to implement the firewall infrastructure in such a way that it is highly available with device failure, region failure etc. Else any solution will be having the issues if they are not build with resiliency.
The support is usually very good and gets back to you very quickly. However I had some instances of when two engineers will give me wildly different answers to what I thought was a simple question. Overall however I do rate the support highly and they are generally always very good.
Support is very slow to respond and it takes a long time to convince level 1 techs that you need to be moved up to someone more senior. I believe support is outsourced and they are graded on how few tickets they need to escalate to higher tiers so they will try to figure out a solution even if it is detrimental to the overall support experience.
It was quite a good one, how ever requires an expertise to deploy hence the SMB segment would be finding it difficult to implement this product. The one good reason is that there are lot of ASA certified engineers in compared to the other certified engineers. Hence this resembles positively on the deployment as you have quite a lot of experienced engineer on your deployment
Cisco has made it easy to buy, set up, and manage all of our firewalls with the central FirePower Management Center. All licensing is done via one license portal too. Tech support is standardized for all ASA devices and like support engineers who know the different models to provide timely help for any issues. Cisco Talos is a premier could platform which scours the internet looking for threats and develops protections for the ASA's and as such provides zero second coverage when it best can detect global issues.
We found Kerio Control to provide the most features and easiest management of all the solutions we looked at, while cost was not the lowest the value was by far the best when you considered all the factors, costs, and manhours involved in deployment and management.
The 5510 is still being used in one of our setups, and still doing its job this is a lot of Return on Investment.
We have managed to turn around projects quickly because most of our engineers understand this firewall very well. We deploy them in a matter of minutes[.]