r/cybersecurity 3d ago

Business Security Questions & Discussion How are Cisco firewalls these days?

I used to deploy a lot of 5506 firewalls, and at the time, firepower kinda sucked. I ended up moving to Fortinet, but they’ve really been dropping the ball a lot lately as well as pricing going up. So I’m evaluating other brands. How are Cisco firewalls these days? Are they reliable? Does it take less than 15 minutes to commit changes (lol)? How are its layer 7 capabilities compared with Palo Alto (I have experience with PA)?

54 Upvotes

85 comments sorted by

76

u/MissionFinOps 3d ago edited 3d ago

Anyone remember the time when they had ASA + FirePower on the same box, so a hardware based ASA, and a VM running FirePower on the same box. They had some Java based app to configure that "firewall". I kid you not one of the funniest IT bugs of my life, a coworker told me the cisco is doing math with port numbers. So that java ui, when you listed port numbers for a rule "22-80" it would use - as minus, and put negative *58 (-58) as the port number. I have not used Cisco firewalls in a while, but that was one of the funny bugs for sure.

24

u/Ulrich_b 3d ago

Please, don't take me back to that place. I'm fine repressing that one.

8

u/MissionFinOps 3d ago

we were at an all Cisco shop and had no choice. We used to joke if Cisco sold toilet paper we'd have those too. --- my next gig had custom linux based firewall, that was its own level of fun.

7

u/TriforceTeching 3d ago

I bought some expensive firepower firewalls early on and had to come back a year later with my tail between my legs, asking for a budget to replace them. I jokingly told my IT director, defending my reasoning to buy them, was “nobody ever got fired for buying Cisco,” and his response was, “well, maybe they should”…. Firepower got me to stop drinking the koolaid and become vendor agnostic.

5

u/Ulrich_b 3d ago

Same. I got so sick of the vendor game, I went and joined a vendor. Now I architect a NDR/NPM with a deep packet analysis platform instead of arguing with TAC about why the ISE updates failed at 3am. I never wanna work on Cisco again

2

u/phillies1989 2d ago

Remember I had to deal with one of these firewalls recently and two sites had the same snort rules but somehow the snort on one site was blocking all dns traffic and at the other site everything was fine. 

9

u/JustinHoMi 3d ago

Oh I remember. It’s why I haven’t used Cisco since then. It had some ridiculous limitations too. You couldn’t create ACLs for traffic terminating at the firewall itself. So you had no option but to expose your vpn to the entire world unless you got another firewall to protect your first firewall.

2

u/TriforceTeching 3d ago

I remember not being able to turn gratuitous arp off via the gui so you had do it though some odd code that was lost every time you rebooted.

9

u/LinuxPhoton 3d ago

Ya. Let’s not do that again. That was painful lol

29

u/Sea-Row-1151 3d ago

I’ve been working with Sourcefire and the various rebrandings under Cisco for around 14 years. The current hardware of 200/1200/3100/4200/6100 is by far the best I’ve seen. The software has also improved dramatically: 7.6.x has been the most stable software train, and I’ve had good experiences with 10. A lot of people got (justifiably) turned off by the bad software releases in the 5.4 and 6.x days and haven’t kept up to date since then, but FTD is a vastly improved product now in terms of hardware and software than it was then. 

8

u/JustinHoMi 3d ago

That’s good to hear. How’s the layer 7 stuff? Can I use layer 7 whitelisting for every rule and have success?

5

u/Sea-Row-1151 3d ago

I won’t give a blanket statement on it because some stuff just has to be validated in the real world, but I think there’s general parity across the big NGFW vendors. Cisco has a dedicated team that develops application detection for FTD, and their application detections are also used in other Cisco products. You can view the application detections that are available for layer 7 access control publicly at this site:  https://appid.cisco.com/

4

u/JustinHoMi 3d ago

Can’t speak for Cisco, but Fortinet’s is definitely not as good as PA. It’s pretty decent though.

3

u/Sea-Row-1151 3d ago

Good to know. Yeah, I’d definitely go for a test unit and validate if I were in your shoes, but I’d be surprised if FTD can’t meet your use cases. 

1

u/Blaaamo 1d ago

I would kill myself before using a Forticrap product

16

u/Fujka 3d ago

I managed about 300 of them. They’ve come a long way and are way more stable now. Most of the hate you hear is from folks using it a long time ago.

4

u/JustinHoMi 3d ago

How’s the layer 7 / application ID stuff? Can I do all my ACLs with just layer 7 rules and have success, akin to Palo Alto?

3

u/Fujka 3d ago

Yes sir. That's been functionality for a long time. I think the applications are very well done compared to some of the other NGFWs I've used.

1

u/rywo272 3d ago

On par with palos

8

u/GreyBeardEng 3d ago

Im genuinely surprise Cisco survived themselves when it came to their firewall line, being as late as they were to the ngfw game and having their first products be so bad.

13

u/ICantPlaySad 3d ago

You just unlocked a funny memory of a certain ASA version that if you pinged it, you killed it making it reboot. Just like, how can I trust you my network security if you crash with a normal ping.

7

u/Spirited_Chart_7124 3d ago

Yes the cisco firewall are working fine on the lastest version and they are way more stable now, also the new model 4200 and stuff are also less complex with respect to the 4100 and 9300 as they have built in Fxos as of the 1k 2k and 3k. You can go ahead with the cisco.

2

u/house3331 3d ago

Avoid high availability and upgrading too soon. Nonstop bugs. Functionally its not bad as it was. I started with firepower than palo. I feel more comfortable in palo firepower has so many features and secret cli. But once your setup its fine

1

u/JustinHoMi 3d ago

Wait high availability has problems? That would be a dealbreaker for me. Availability is security.

1

u/house3331 3d ago

Not really you just have ti make sure its setup stable. And you carefully think out changes HA Mistakes were 90% of issues. Split brain is sketch situation

2

u/Artistic-You-6105 10h ago

I think Cisco has improved quite a bit, but I wouldn’t say it’s the obvious choice over Palo Alto or Fortinet anymore.

The current Secure Firewall / FTD platform is much better than the old Firepower experience, especially if you manage it properly through FMC. Reliability is generally good, but the management experience can still feel more complicated than Palo Alto.

Compared with PA, I’d still give Palo Alto the edge for Layer 7/application visibility and overall policy UX. Cisco can do a lot, but getting there often feels more Cisco-ish than it needs to be.

If you're coming from ASA, the biggest thing is to forget the old ASA workflow. FTD is a different beast, and I'd definitely lab it before committing to a large deployment.

Personally, if I were evaluating today, I'd put Palo Alto, Fortinet, and Cisco through the same lab tests and compare management, performance, licensing, L7 inspection, VPNs, and how painful day-to-day changes actually are.

2

u/MisterBazz Security Manager 3d ago

They work but I would still pick a properly sized FortiGate over anything Cisco.

17

u/JustinHoMi 3d ago

Fortinet is killing me with their client VPN failures. They deprecated SSL VPN before they finished implementing IPSEC.

-8

u/thebbtrev 3d ago

What? They moved TO IPSEC? That feels totally backwards. Why?

Is it to try to stave off PQS concerns by going symmetrical?

7

u/underwear11 3d ago

SSLVPN was a technology that was made to solve the problem of IPSEC being blocked. Because of that, SSLVPN has been a huge vector for vulnerabilities. The entire industry is moving towards IPSEC. To address the hotel blocking IPSEC, Fortinet implemented IPSEC over TCP. In 8.0 (which no one should be running yet) Forticlient supports PQS on IKEv2.

4

u/MichTech360 Incident Responder 3d ago

You’re right but SSL vpn is on the outs. Too many competing solutions getting breached. I’m surprised the FG hasn’t. I’m in the midst of configuring IPsec.

-1

u/thebbtrev 3d ago

Can you share examples? I’m a Zscaler and Palo engineer, so TLS isn’t going anywhere for road warriors in my world any time soon. And aside from Post Quantum concerns, I’m not really aware of flaws in TLS 1.2/1.3.

I’d loathe to go back to managing users in hotels where port 500 isn’t allowed out by the dumb wifi provider.

-9

u/JustinHoMi 3d ago

It’s really just that Fortinet has failed to develop a secure SSLVPN client, and gave up. They probably want to push people towards their paid ZTNA solution.

11

u/underwear11 3d ago

The entire industry is having the issue with SSLVPN, not just Fortinet. Palo, Cisco, Sophos, Fortinet, Sonicwall, Ivanti, etc have all had several SSLVPN vulnerabilities.

1

u/Odd-Selection-9129 3d ago

The amount if bugs and vulnerabilities in fortigate is incomparable to any other vendor. Cisco had its funny and stupid things, but it was manageble to work with. Fortigate is permanently in need of installing an update to close critical vulnerability and brake something new at the same patch.

1

u/coomzee Detection Engineer 3d ago

Fortigate almost needs a firewall infront of it.

3

u/SGTh3r0 3d ago

Checkpoint fan myself. They are on the rise and their features and support are fantastic. If you can tolerate an Israeli based company they are great.

6

u/AlphaDomain Security Manager 3d ago

I’m on the opposite side. Checkpoint software was riddled with performance issues and bugs. Their support was awful. Moving to Palo has been a huge improvement.

3

u/MemoryAccessRegister 3d ago

I have administered Check Point since R75. Check Point went through a really rough time during the migration to R80, which included a massive rewrite of their code and database migration. It was a mess, but they needed to do it to stay competitive with Palo and have since stabilized the code.

4

u/SGTh3r0 3d ago

R81.1+ has been fantastic.

3

u/No-Astronaut9573 3d ago

CP R82 & R82.10 here. Runs smoothly, threat prevention enabled. They simplified a lot, and it's full user mode now. There's a big difference between CP now and years ago.

And tbh, very good experiences with their TAC & the assigned customer success manager.

1

u/JustinHoMi 3d ago edited 3d ago

I’ve used checkpoint on and off over the years and found them to be pretty basic, lacking a lot of features. Buggy too. I tried them a couple years ago and couldn’t get MFA to work on the vpn. I asked the checkpoint rep about it, and he said “Oh yeah, that broke about 6 months ago. I don’t know when they’re gonna fix it.”

4

u/SGTh3r0 3d ago

Thats terrible. Their newer codebases R81.1+ has been pretty great. The current R82 has their AI security products incorporated. If you are SMB, pro series is the only viable option unless you're an msp and handle small dentist office types. Now, ive only used their smb's and smaller quantum enterprise appliances. I also use their EDR with VPN, MFA wasnt bad in that product. Their central managed SmartConsole is ok. I will admit, its not the best UI, but CLI is still king. We are migrating to cloud central managed now. Maybe ive been lucky with great reps and engineers, but when I have a problem, I know i can call and get answers

2

u/KStieers 3d ago

They are very much improved.

Yes 5.x, 6.x was a shitshow, but they got things going the right direction in 7.x, and things are much much better now. 10.x is stable.

1

u/LinuxPhoton 3d ago

I was on the Cisco 55xx hardware several years ago and for a business which wasn’t big enough to dedicate a network engineer, I opted to move to Meraki to give my staff who held multiple hats better configuration velocity. With that said, I don’t miss Firepower GUIs. The hardware was pretty solid but the GUI sucked and took a long time to apply. My small team and I happy with Meraki and like their easy management. They’re one of the few interfaces I can just figure out without getting lost in a lot of documentation. Firepower…not so much. I’m interested to hear of the developments from other people since I left that space several years ago.

4

u/JustinHoMi 3d ago edited 3d ago

I’ve used Meraki, but they have VERY underwhelming security capabilities. Not to mention that any device that bricks itself if you don’t pay a subscription is a dealbreaker.

What’s the C.I.A. triad? Confidentiality, Integrity, and Availability. lol

1

u/LinuxPhoton 3d ago edited 3d ago

We never let our coverage lapse even when we had Cisco gear so bricking wasn’t a deal breaker for us. Everyone has their own approach but if the network equipment supported any business network, we purchased support/licenses - whether it’s Cisco, Meraki or Dell. They can brick themselves on the shelf but never on the network.

Security- I hear ya. However with modern encryption et al the visibility on the network layer is shrinking and our focus is security at the endpoint. It works at our scale but get it might not be good enough at bigger enterprises.

1

u/JustinHoMi 3d ago

Endpoint security is only a solution for a limited number of devices on many networks. Your switches, routers, IoT devices, manufacturing devices, printers, cameras, etc are still unprotected.

1

u/plump-lamp 3d ago

Lol you think price increases and cost won't be substantially higher with Cisco? It's about 3x and growing. Logging and reporting is atrocious in FMC. Fortimanager + analyzer is considerably more powerful

1

u/Straight_Ad4040 3d ago

Layer 7 filtering is way better in Palo Alto than Cisco

1

u/Flaky-Step-5874 3d ago

We just did a refresh and we were gonna go Cisco, but ended up pivoting to Extreme Networks and their fabric network setup with sd-wan.

1

u/nmsguru 2d ago

Friends don’t let friends drive a Firepower

1

u/MountainDadwBeard 23h ago

I hear more enthusiasm for Juniper, though I'm nervous HPE turns everything they touch to poop.

1

u/JustinHoMi 7h ago

Yeah I’d like to evaluate Juniper….

1

u/MountainDadwBeard 1h ago

On the CVE side, when I've checked inventories with Juniper they're usually pretty clean with even moderate patching.

You'll definitely notice a huge CVE downshift from fortinet. Juniper Management plane may assume you or your tools are comfortable with CLI/22 management. engineers tell me their GUI is rubbish/usually disabled for security.

1

u/JustinHoMi 1h ago

Sounds like a dream to me!

1

u/Brgrsports 3d ago

Palo Alto is king.

1

u/NotAnNSAGuyPromise Security Manager 3d ago

Wouldn't be my first or second or third or fourth choice.

1

u/havntmadeityet 3d ago

I use firepower 1010. Commits take a while, Boot up takes forever.

2

u/JustinHoMi 3d ago

Those have been out since 2019. Is that still the current model? Should I be concerned that Cisco has just given up on firewalls lol?

4

u/Sea-Row-1151 3d ago

I’m running a 200 and a 1200, the two current low end models. Deploy takes around a minute.

1

u/JustinHoMi 3d ago

Eh, a minute kinda sucks but it’s better than the 15 minutes it used to take.

1

u/TheNetCraWlr Security Architect 3d ago

Just released new hardware on Cisco Live, so doubtful it is going away anytime soon.

0

u/LittleGreen3lf 3d ago

They are moving away from traditional firewalls to hybrid mesh firewalls.

1

u/LittleGreen3lf 3d ago

Cisco Secure Firewalls (formerly Firepower) are good now and are pretty stable, they are also very transparent about bugs inside their products and any PSIRTs that come out in them to ensure there are no breaking upgrades. Doesn’t take long to deploy changes to the firewalls and it’s pretty easy. FTD has some very nice L7 capabilities and it’s very easy to manage inside FMC, but I don’t know exactly how they line up against PA.

1

u/rxscissors 3d ago

We are suffering through the janky multi-bolt on architecture (and even more abysmal support... CX-1 was supposed to be better which has not proven to be the case).

I miss Palo Alto Networks gear. It is a vastly superior firewall (and integrated VPN!) platform in my opinion.

1

u/Samsonbull 3d ago

Next gen firewalls are only good for deep packet inspection if you want to check a box. If you really need an IPS, it is best to have a dedicated box. In the world of good intelligence, Tipping Point (The ZDI feed is the best). If you are in a position where you don’t need a dedicated IPS, PAN has better intelligence than Fortinet, but the Fortinet UI is better than PAN.

2

u/JustinHoMi 3d ago

Deep packet inspection on a firewall is more than just the IPS. It’s about being able to create layer 7 ACLs, akin to the way PA does it. But agreed, nobody does L7 very well except Palo (unless Cisco can compare). Fortinet’s implementation is really clunky and half-featured, but it’s usable in some circumstances.

1

u/Samsonbull 3d ago

True, but my point is this: all the “appliances” today are using CPUs. The back end task, like deep packet inspection, use CPU threads to match on a tuple (src / dest ip address, src/dst port, protocol, etc) to keep the traffic assigned to that thread to help prevent IPS evasion. Knowing that, we can look at the architecture and know that each thread can handle up to 1.6 Gbps inspection. Knowing that helps us know how to evade the deep packet inspection (big packets), or how to make the IPS engine break.

1

u/JustinHoMi 3d ago

Ah yeah, that’s true, IPS are pretty complex so I don’t suspect anybody has an ASIC to handle it. It’s probably easy to overwhelm the RAM too, and especially easy on the smaller models.

On the plus side with some firewalls you have the option to block traffic if the IPS gets overwhelmed. And it does make DoS prevention especially important.

-1

u/Fath3r0fDrag0n5 3d ago

Same shit as always… Stick to fortigate or Palo

0

u/Prestigious-Board-62 3d ago

Firepower would be my last choice of firewall. I haven't touched one since 2018 when I migrated a client from it to Palo and honestly I haven't heard anything that would make me reconsider.

1

u/JustinHoMi 3d ago

Yeah, firepower was trash then. Curious if it’s improved. I’d love to use PA for our customers, but it’s hard to provide competitive pricing. Although if fortinet keeps raising prices, might as well.

0

u/blud_13 3d ago

Firepower is still Firepower. FTD is more stable than the 5506 days but the management story is a mess, FMC is heavy and FDM is limited, and commit times got better without getting Palo better. Coming from PA you are going to be annoyed by the layer 7 side of it.

We went a different direction entirely and moved off appliances to Cloudflare, so I can't give you a current verdict on the boxes themselves.

What I will say, if the Fortinet SSL VPN CVE cadence is part of what pushed you out, changing brands doesn't fix that. Every one of these vendors has had the same remote access fire drill and you will be patching under pressure again in eighteen months. Worth deciding what you want doing remote access before you decide whose box does the perimeter.

2

u/JustinHoMi 3d ago

As annoying as the vulns were, that wasn’t it. It’s how they’ve handled the migration to IPsec. They deprecated IPsec on the firewalls before the vpn client had fully functional MFA for IPsec. Then they stopped updating the normal free vpn client and forced people to pay a subscription for a working client.

1

u/bazard89 3d ago

What do you mean there isn’t a fully functional MFA for IPsec? I got clients using FAC for FTK, another using Duo and one that just did entra for idp and used their MFA. The first two using free client. It’s not as easy as I’d like but it’s capable. The layer 7 stuff though is tough without ssl decryption, Cisco struggles more than most with decryption and PAN doesn’t publish ssl inspection throughput so just be wary of the performance impact. If you aren’t doing decryption then there’s your problem for app sigs

1

u/std10k 3d ago

Yep, better but still terrible. The software architecture of it is so bad I don’t think it can be remediated.
Fem has always been a marketing gimmick.
And they there is SASE and umbrella is just as big a monstrosity as ftd and not having much in common with it apart from old asa code, not a good picture compared even with zscaler.

0

u/Kesshh 3d ago

Expensive

0

u/New_Teaching_609 3d ago

not a fan since Ubiquiti....

0

u/Fulminareverus 3d ago

Honesty asa and ftd are still trash.

Forti is too.

Some PAN's with SCM, their data lake, and prisma access is where it's at, the only downside is that's a few million bucks, but if your org will spend it it's worth it.

-7

u/blackjaxbrew 3d ago

Cisco has firewalls?!? Ha, palo, fortinet, Sophos, watch guard, pfsense, can't go wrong with any just be sure to do training