Cisco offers a threat-focused next-generation firewall (NGFW), the ASA 5500-X Series. The ASA 5500 Series platforms can run either the Cisco ASA Firewall or Cisco Firepower Threat Defense (FTD). The series features appliances in a variety of form factors, including standalone options for small and midsize businesses, ruggedized appliances for extreme environments, midsize appliances for security at the Internet edge, and high-performance appliances for enterprise data centers.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. TR verified that a representative sample of customers was invited. More Info
IT Planning in Information Technology at Tigo (1001-5000 employees employees)
Use Cases and Deployment Scope
We actually used to manage all the remote connections from outside the organization. This include internal user VPN and vendors. Also, with these equipment is possible implement a hybrid strategic and combination of remote a local work. Also work to content filter and antivirus check of all the traffic the actually past for it
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Verified User
Engineer in Information Technology (1001-5000 employees employees)
Use Cases and Deployment Scope
We use Cisco ASA 5500-X with FirePOWER Services as the edge for the internet for VPN connections, web sites published to the intenet and apps that needs to be accessible from internet. We also use the outside connection as an alternative path in case the main connection to internet fails.
Pros
Easy GUI administration
VPN remote access and VPN Site to Site are easy to deploy
CLI commands remains the same of IOS
Cons
More options for layer7 filter
Could include IPS and IDS capabilities
More patches to remediate vulnerabilities
Return on Investment
Allow remote connection for home office
Reduce the cost of licencing
Increase performance and network optimization
Alternatives Considered
Palo Alto Networks Next-Generation Firewalls - PA Series and Juniper SRX
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. TR verified that a representative sample of customers was invited. More Info
Senior MS Security Engineer in Information Technology at NTT Ltd. (5001-10,000 employees employees)
Use Cases and Deployment Scope
Cisco ASA 5500-X with FirePOWER Services is being used at edge of the network and inside the network to block and limit the traffic. These devices are very good with NAT and allow the access to the internal servers with the only allowed ports for security. Apart from that the device is handling the VPN, both IPSec and Remote access VPN for the production infrastructure. ASAs are deployed with Anyconnect premium licensing feature to help the remote access or work from home users to connect to the data centre and perform their day to day task with the inhouse applications.
Pros
Traffic handling is fast, i.e. with least latency
VPNs are stable and doesn't creates much issues
Efficiently handles the forwarded and NATed traffic
Management is easy
Packet tracer feature is up to the mark
Cons
Enhance the GUI, i.e. make the device management more user friendly
Troubleshoot part should be more efficient
There should be an option to initiate VPN tunnels without the real traffic
More customised notification options for audit should be available
Resource utilization should be optimized
Return on Investment
Working of remote workforce made easy
Security was enhanced on the data traffic shared with the vendors due to the use of VPNs
Inbound attacks were mostly blocked on the edge and saved a lot of resources (which could had been used in case of attacks getting successful on the application servers)
Alternatives Considered
Palo Alto Networks Next-Generation Firewalls - PA Series, Fortinet FortiGate and Sophos UTM
Other Software Used
Cisco Identity Services Engine (ISE), Fortinet FortiGate, Palo Alto Networks Next-Generation Firewalls - PA Series
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. TR verified that a representative sample of customers was invited. More Info
Network System Administrator in Information Technology at NCM Associates (201-500 employees employees)
Use Cases and Deployment Scope
We utilize the 5500-X with FirePower services for our everyday use to monitor traffic coming in and going out of our network. We set up many network address translations for web pages that need to be reached externally and also have internal resources being accessed that still need protected. We've setup all of our access control lists and constantly keep them up to date so we don't have to worry about being attacked as easily as other companies who don't put forth the additional effort for their security and safety. We also utilize URL filtering and a couple of other security features that allow us to stay notified of issues on our network, so we can take specific actions being to keep our company safe.
Pros
Creating ACLs to grant/restrict specific access
Creating NATs to allow specific access
Creating Objects that can be greatly detailed
Monitor traffic and activity on the network
Cons
URL Filtering feature could be easier to utilize for beginners
I'd like to see a visual of VPN networks setup and show the functioning or malfunctioning status to assist in making troubleshooting easier
Recommendations on ACLs for beginners based on their account creation date
Return on Investment
Saved from the worst of an attacker
Site-to-site VPNs have been a lifesaver
Keeps all of our users and data safe
Alternatives Considered
Cisco Meraki MX
Other Software Used
Veeam ONE, Microsoft SharePoint, HPE Nimble Storage
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
teacher at Chisholm Institute (1001-5000 employees employees)
Use Cases and Deployment Scope
Cisco ASA 5500-X with FirePOWER Services is used to filter students' access to our Racks of Cisco switches and routers. It ensures that only validated students can access the resources.
Pros
Provides us with details of users
Checks and most importantly blocks malignant, malicious software
Allows valid users access to the resources
Cons
Getting updates
Installing updates
Annoying ASDM and ASA image have to be updated separately
Return on Investment
Great ROI, has been in service many years
GUI Bit clunky now compared to single pane products
EOL, so updates are now old
Other Software Used
Azure VMware Solution, NETLAB+
Cisco ASA 5500-X with FirePOWER Services Alternatives
Products similar to Cisco ASA 5500-X with FirePOWER Services that may also meet your needs.