TrustRadius: an HG Insights company

Cisco ASA 5500-X with FirePOWER Services

Score7.3 out of 10

87 Reviews and Ratings

What is Cisco ASA 5500-X with FirePOWER Services?

Cisco offers a threat-focused next-generation firewall (NGFW), the ASA 5500-X Series. The ASA 5500 Series platforms can run either the Cisco ASA Firewall or Cisco Firepower Threat Defense (FTD). The series features appliances in a variety of form factors, including standalone options for small and midsize businesses, ruggedized appliances for extreme environments, midsize appliances for security at the Internet edge, and high-performance appliances for enterprise data centers.

Read more details.

Categories & Use Cases

Top Performing Features

  • Policy-based Controls

    Firewall policy controls enable administrators to create firewall policies controlling what data is allowed to traverse the firewall

    Category average: 8.9

  • Active Directory and LDAP

    Integration with Active Directory and LDAP directories

    Category average: 8.6

  • VPN

    VPN's implement encryption and anonymize IP addresses

    Category average: 9.1

Areas for Improvement

  • Stateful Inspection

    Stateful inspection analyzes packet headers and contents of packets

    Category average: 8.9

  • Reporting and Logging

    Custom and summary reports, and log files enabling analysis of security incidents, application usage and traffic patterns

    Category average: 8.3

  • Proxy Server

    A proxy server changes your IP address and masks the origin of your network traffic

    Category average: 8.6

Who Buys & Uses Cisco ASA 5500-X with FirePOWER Services

Excellent to manage VPN connections

Use Cases and Deployment Scope

We actually used to manage all the remote connections from outside the organization. This include internal user VPN and vendors. Also, with these equipment is possible implement a hybrid strategic and combination of remote a local work. Also work to content filter and antivirus check of all the traffic the actually past for it

Pros

  • VPN connection and management
  • Antivirus filtering
  • Traffic filtering

Cons

  • IA filtering
  • Sandbox
  • Scabilit

Return on Investment

  • We could implement hybrid work strategy
  • The uptime is excellent with 0 downtimes

Excellent performance and Security with Cisco ASA 5500-X with FirePOWER Services

Use Cases and Deployment Scope

We use Cisco ASA 5500-X with FirePOWER Services as the edge for the internet for VPN connections, web sites published to the intenet and apps that needs to be accessible from internet. We also use the outside connection as an alternative path in case the main connection to internet fails.

Pros

  • Easy GUI administration
  • VPN remote access and VPN Site to Site are easy to deploy
  • CLI commands remains the same of IOS

Cons

  • More options for layer7 filter
  • Could include IPS and IDS capabilities
  • More patches to remediate vulnerabilities

Return on Investment

  • Allow remote connection for home office
  • Reduce the cost of licencing
  • Increase performance and network optimization

Alternatives Considered

Palo Alto Networks Next-Generation Firewalls - PA Series and Juniper SRX

Other Software Used

Cisco Meraki Dashboard, Cisco Umbrella, Fortinet FortiGate

Cisco ASA 5500-X with FirePOWER Services review with 1 year of usages

Use Cases and Deployment Scope

Cisco ASA 5500-X with FirePOWER Services is being used at edge of the network and inside the network to block and limit the traffic. These devices are very good with NAT and allow the access to the internal servers with the only allowed ports for security. Apart from that the device is handling the VPN, both IPSec and Remote access VPN for the production infrastructure. ASAs are deployed with Anyconnect premium licensing feature to help the remote access or work from home users to connect to the data centre and perform their day to day task with the inhouse applications.

Pros

  • Traffic handling is fast, i.e. with least latency
  • VPNs are stable and doesn't creates much issues
  • Efficiently handles the forwarded and NATed traffic
  • Management is easy
  • Packet tracer feature is up to the mark

Cons

  • Enhance the GUI, i.e. make the device management more user friendly
  • Troubleshoot part should be more efficient
  • There should be an option to initiate VPN tunnels without the real traffic
  • More customised notification options for audit should be available
  • Resource utilization should be optimized

Return on Investment

  • Working of remote workforce made easy
  • Security was enhanced on the data traffic shared with the vendors due to the use of VPNs
  • Inbound attacks were mostly blocked on the edge and saved a lot of resources (which could had been used in case of attacks getting successful on the application servers)

Alternatives Considered

Palo Alto Networks Next-Generation Firewalls - PA Series, Fortinet FortiGate and Sophos UTM

Other Software Used

Cisco Identity Services Engine (ISE), Fortinet FortiGate, Palo Alto Networks Next-Generation Firewalls - PA Series

Cisco Firewall Will Keep Your Data Safe

Use Cases and Deployment Scope

We utilize the 5500-X with FirePower services for our everyday use to monitor traffic coming in and going out of our network. We set up many network address translations for web pages that need to be reached externally and also have internal resources being accessed that still need protected. We've setup all of our access control lists and constantly keep them up to date so we don't have to worry about being attacked as easily as other companies who don't put forth the additional effort for their security and safety. We also utilize URL filtering and a couple of other security features that allow us to stay notified of issues on our network, so we can take specific actions being to keep our company safe.

Pros

  • Creating ACLs to grant/restrict specific access
  • Creating NATs to allow specific access
  • Creating Objects that can be greatly detailed
  • Monitor traffic and activity on the network

Cons

  • URL Filtering feature could be easier to utilize for beginners
  • I'd like to see a visual of VPN networks setup and show the functioning or malfunctioning status to assist in making troubleshooting easier
  • Recommendations on ACLs for beginners based on their account creation date

Return on Investment

  • Saved from the worst of an attacker
  • Site-to-site VPNs have been a lifesaver
  • Keeps all of our users and data safe

Alternatives Considered

Cisco Meraki MX

Other Software Used

Veeam ONE, Microsoft SharePoint, HPE Nimble Storage

Grand OLD lady past its Prime

Use Cases and Deployment Scope

Cisco ASA 5500-X with FirePOWER Services is used to filter students' access to our Racks of Cisco switches and routers. It ensures that only validated students can access the resources.

Pros

  • Provides us with details of users
  • Checks and most importantly blocks malignant, malicious software
  • Allows valid users access to the resources

Cons

  • Getting updates
  • Installing updates
  • Annoying ASDM and ASA image have to be updated separately

Return on Investment

  • Great ROI, has been in service many years
  • GUI Bit clunky now compared to single pane products
  • EOL, so updates are now old

Other Software Used

Azure VMware Solution, NETLAB+