The Cisco Firepower 4100 Series’ 1-rack-unit size is presented by the vendodr as ideal at the Internet edge and in high-performance environments. They further state that it shows what’s happening on your network, detects attacks earlier so you can act faster, and reduces management complexity.
N/A
SonicWall TZ
Score 7.2 out of 10
N/A
SonicWall TZ is an entry to mid-tier NGFW for small to mid-sized companies. It is a Unified Threat Management solution, with additional native decryption and deep-packet inspection capabilities.
When we are asked by local partners which security equipment we use we always recommend our Cisco security products. The Firepower firewall is no exception and we can easily recommend this to others who need a fast, secure, and well built system that integrates well with all your existing hardware and software.
Good price for scope of functionality Challenge for those that are not highly technical Many options within Firewall Setting that need to understood to maximize use of the device. Would be nice to see some sort of configuration wizard to assist in configuring unit.
Policy management in the GUI. I'm old-school, and still create ACLs in the CLI, but using the GUI for this is very nice.
Event monitoring and reporting is great, and you can get very granular when it comes to what information you are viewing.
I really like the troubleshooting features that are built in, especially the packet tracer and the ability to generate and download a troubleshooting package to review or send to TAC.
management is confusing has many items that could be improved to facilitate the work to the network administrator
in the diagnostic tool I would improve the response times, that is, if a ping test is required, it should be quick, since in cases of failures it is sought to minimize the impact as much as possible.
each function has a different license item, I would place a single license package for all team functions
It not easy to understand the different features it offers. Sometimes you need to spend a couple of minutes to implement a change or even open a ticket with cisco tac to figure it out. Once support is on the phone with you they know how to resolve problems. But it's not an intuitive tool
Overall the new interface is very logical and easy to navigate. We did struggle at first coming from the older interface and finding our way around the new. But our new users found it very simple to find what they were looking for. One negative we do all struggle with is packet cpature not always being clear how its set/what is being monitored. this could do with more information on teh intial page instead of having to look for it
Once you get to a competent technician the support experience is better. But I have found that the lower tiers of support are very slow to respond (like 1 email per day) and you typically have to re-explain yourself a couple times before they get it. I have not used Phone support, and that may be a better experience.
We switch to Palo Alto due the amount of tickets open with Cisco Firepower 4100 Series. It was taking a great amount of time for our engineers to fix problems. But it was a great tool when it was working as we were expecting. The fact it has a lot of instability on the releases was the deciding factor.
SonicWall and WatchGuard are both fine appliances, but I am accustomed to the Barracuda NG. The Barracuda Control Center is so powerful and useful that it beats out the other two. SonicWall does a great job of dividing up firewall rules and NAT policies, but this is a preference among engineers.