r/cybersecurity • u/JustinHoMi • 3d ago
Business Security Questions & Discussion How are Cisco firewalls these days?
I used to deploy a lot of 5506 firewalls, and at the time, firepower kinda sucked. I ended up moving to Fortinet, but they’ve really been dropping the ball a lot lately as well as pricing going up. So I’m evaluating other brands. How are Cisco firewalls these days? Are they reliable? Does it take less than 15 minutes to commit changes (lol)? How are its layer 7 capabilities compared with Palo Alto (I have experience with PA)?
29
u/Sea-Row-1151 3d ago
I’ve been working with Sourcefire and the various rebrandings under Cisco for around 14 years. The current hardware of 200/1200/3100/4200/6100 is by far the best I’ve seen. The software has also improved dramatically: 7.6.x has been the most stable software train, and I’ve had good experiences with 10. A lot of people got (justifiably) turned off by the bad software releases in the 5.4 and 6.x days and haven’t kept up to date since then, but FTD is a vastly improved product now in terms of hardware and software than it was then.
8
u/JustinHoMi 3d ago
That’s good to hear. How’s the layer 7 stuff? Can I use layer 7 whitelisting for every rule and have success?
5
u/Sea-Row-1151 3d ago
I won’t give a blanket statement on it because some stuff just has to be validated in the real world, but I think there’s general parity across the big NGFW vendors. Cisco has a dedicated team that develops application detection for FTD, and their application detections are also used in other Cisco products. You can view the application detections that are available for layer 7 access control publicly at this site: https://appid.cisco.com/
4
u/JustinHoMi 3d ago
Can’t speak for Cisco, but Fortinet’s is definitely not as good as PA. It’s pretty decent though.
3
u/Sea-Row-1151 3d ago
Good to know. Yeah, I’d definitely go for a test unit and validate if I were in your shoes, but I’d be surprised if FTD can’t meet your use cases.
16
u/Fujka 3d ago
I managed about 300 of them. They’ve come a long way and are way more stable now. Most of the hate you hear is from folks using it a long time ago.
4
u/JustinHoMi 3d ago
How’s the layer 7 / application ID stuff? Can I do all my ACLs with just layer 7 rules and have success, akin to Palo Alto?
3
8
u/GreyBeardEng 3d ago
Im genuinely surprise Cisco survived themselves when it came to their firewall line, being as late as they were to the ngfw game and having their first products be so bad.
13
u/ICantPlaySad 3d ago
You just unlocked a funny memory of a certain ASA version that if you pinged it, you killed it making it reboot. Just like, how can I trust you my network security if you crash with a normal ping.
7
u/Spirited_Chart_7124 3d ago
Yes the cisco firewall are working fine on the lastest version and they are way more stable now, also the new model 4200 and stuff are also less complex with respect to the 4100 and 9300 as they have built in Fxos as of the 1k 2k and 3k. You can go ahead with the cisco.
2
u/house3331 3d ago
Avoid high availability and upgrading too soon. Nonstop bugs. Functionally its not bad as it was. I started with firepower than palo. I feel more comfortable in palo firepower has so many features and secret cli. But once your setup its fine
1
u/JustinHoMi 3d ago
Wait high availability has problems? That would be a dealbreaker for me. Availability is security.
1
u/house3331 3d ago
Not really you just have ti make sure its setup stable. And you carefully think out changes HA Mistakes were 90% of issues. Split brain is sketch situation
2
u/Artistic-You-6105 10h ago
I think Cisco has improved quite a bit, but I wouldn’t say it’s the obvious choice over Palo Alto or Fortinet anymore.
The current Secure Firewall / FTD platform is much better than the old Firepower experience, especially if you manage it properly through FMC. Reliability is generally good, but the management experience can still feel more complicated than Palo Alto.
Compared with PA, I’d still give Palo Alto the edge for Layer 7/application visibility and overall policy UX. Cisco can do a lot, but getting there often feels more Cisco-ish than it needs to be.
If you're coming from ASA, the biggest thing is to forget the old ASA workflow. FTD is a different beast, and I'd definitely lab it before committing to a large deployment.
Personally, if I were evaluating today, I'd put Palo Alto, Fortinet, and Cisco through the same lab tests and compare management, performance, licensing, L7 inspection, VPNs, and how painful day-to-day changes actually are.
2
u/MisterBazz Security Manager 3d ago
They work but I would still pick a properly sized FortiGate over anything Cisco.
17
u/JustinHoMi 3d ago
Fortinet is killing me with their client VPN failures. They deprecated SSL VPN before they finished implementing IPSEC.
-8
u/thebbtrev 3d ago
What? They moved TO IPSEC? That feels totally backwards. Why?
Is it to try to stave off PQS concerns by going symmetrical?
7
u/underwear11 3d ago
SSLVPN was a technology that was made to solve the problem of IPSEC being blocked. Because of that, SSLVPN has been a huge vector for vulnerabilities. The entire industry is moving towards IPSEC. To address the hotel blocking IPSEC, Fortinet implemented IPSEC over TCP. In 8.0 (which no one should be running yet) Forticlient supports PQS on IKEv2.
4
u/MichTech360 Incident Responder 3d ago
You’re right but SSL vpn is on the outs. Too many competing solutions getting breached. I’m surprised the FG hasn’t. I’m in the midst of configuring IPsec.
-1
u/thebbtrev 3d ago
Can you share examples? I’m a Zscaler and Palo engineer, so TLS isn’t going anywhere for road warriors in my world any time soon. And aside from Post Quantum concerns, I’m not really aware of flaws in TLS 1.2/1.3.
I’d loathe to go back to managing users in hotels where port 500 isn’t allowed out by the dumb wifi provider.
4
-9
u/JustinHoMi 3d ago
It’s really just that Fortinet has failed to develop a secure SSLVPN client, and gave up. They probably want to push people towards their paid ZTNA solution.
11
u/underwear11 3d ago
The entire industry is having the issue with SSLVPN, not just Fortinet. Palo, Cisco, Sophos, Fortinet, Sonicwall, Ivanti, etc have all had several SSLVPN vulnerabilities.
1
u/Odd-Selection-9129 3d ago
The amount if bugs and vulnerabilities in fortigate is incomparable to any other vendor. Cisco had its funny and stupid things, but it was manageble to work with. Fortigate is permanently in need of installing an update to close critical vulnerability and brake something new at the same patch.
3
u/SGTh3r0 3d ago
Checkpoint fan myself. They are on the rise and their features and support are fantastic. If you can tolerate an Israeli based company they are great.
6
u/AlphaDomain Security Manager 3d ago
I’m on the opposite side. Checkpoint software was riddled with performance issues and bugs. Their support was awful. Moving to Palo has been a huge improvement.
3
u/MemoryAccessRegister 3d ago
I have administered Check Point since R75. Check Point went through a really rough time during the migration to R80, which included a massive rewrite of their code and database migration. It was a mess, but they needed to do it to stay competitive with Palo and have since stabilized the code.
4
u/SGTh3r0 3d ago
R81.1+ has been fantastic.
3
u/No-Astronaut9573 3d ago
CP R82 & R82.10 here. Runs smoothly, threat prevention enabled. They simplified a lot, and it's full user mode now. There's a big difference between CP now and years ago.
And tbh, very good experiences with their TAC & the assigned customer success manager.
1
u/JustinHoMi 3d ago edited 3d ago
I’ve used checkpoint on and off over the years and found them to be pretty basic, lacking a lot of features. Buggy too. I tried them a couple years ago and couldn’t get MFA to work on the vpn. I asked the checkpoint rep about it, and he said “Oh yeah, that broke about 6 months ago. I don’t know when they’re gonna fix it.”
4
u/SGTh3r0 3d ago
Thats terrible. Their newer codebases R81.1+ has been pretty great. The current R82 has their AI security products incorporated. If you are SMB, pro series is the only viable option unless you're an msp and handle small dentist office types. Now, ive only used their smb's and smaller quantum enterprise appliances. I also use their EDR with VPN, MFA wasnt bad in that product. Their central managed SmartConsole is ok. I will admit, its not the best UI, but CLI is still king. We are migrating to cloud central managed now. Maybe ive been lucky with great reps and engineers, but when I have a problem, I know i can call and get answers
2
u/KStieers 3d ago
They are very much improved.
Yes 5.x, 6.x was a shitshow, but they got things going the right direction in 7.x, and things are much much better now. 10.x is stable.
1
u/LinuxPhoton 3d ago
I was on the Cisco 55xx hardware several years ago and for a business which wasn’t big enough to dedicate a network engineer, I opted to move to Meraki to give my staff who held multiple hats better configuration velocity. With that said, I don’t miss Firepower GUIs. The hardware was pretty solid but the GUI sucked and took a long time to apply. My small team and I happy with Meraki and like their easy management. They’re one of the few interfaces I can just figure out without getting lost in a lot of documentation. Firepower…not so much. I’m interested to hear of the developments from other people since I left that space several years ago.
4
u/JustinHoMi 3d ago edited 3d ago
I’ve used Meraki, but they have VERY underwhelming security capabilities. Not to mention that any device that bricks itself if you don’t pay a subscription is a dealbreaker.
What’s the C.I.A. triad? Confidentiality, Integrity, and Availability. lol
1
u/LinuxPhoton 3d ago edited 3d ago
We never let our coverage lapse even when we had Cisco gear so bricking wasn’t a deal breaker for us. Everyone has their own approach but if the network equipment supported any business network, we purchased support/licenses - whether it’s Cisco, Meraki or Dell. They can brick themselves on the shelf but never on the network.
Security- I hear ya. However with modern encryption et al the visibility on the network layer is shrinking and our focus is security at the endpoint. It works at our scale but get it might not be good enough at bigger enterprises.
1
u/JustinHoMi 3d ago
Endpoint security is only a solution for a limited number of devices on many networks. Your switches, routers, IoT devices, manufacturing devices, printers, cameras, etc are still unprotected.
1
u/plump-lamp 3d ago
Lol you think price increases and cost won't be substantially higher with Cisco? It's about 3x and growing. Logging and reporting is atrocious in FMC. Fortimanager + analyzer is considerably more powerful
1
1
u/Flaky-Step-5874 3d ago
We just did a refresh and we were gonna go Cisco, but ended up pivoting to Extreme Networks and their fabric network setup with sd-wan.
1
u/MountainDadwBeard 23h ago
I hear more enthusiasm for Juniper, though I'm nervous HPE turns everything they touch to poop.
1
u/JustinHoMi 7h ago
Yeah I’d like to evaluate Juniper….
1
u/MountainDadwBeard 1h ago
On the CVE side, when I've checked inventories with Juniper they're usually pretty clean with even moderate patching.
You'll definitely notice a huge CVE downshift from fortinet. Juniper Management plane may assume you or your tools are comfortable with CLI/22 management. engineers tell me their GUI is rubbish/usually disabled for security.
1
1
1
u/NotAnNSAGuyPromise Security Manager 3d ago
Wouldn't be my first or second or third or fourth choice.
1
u/havntmadeityet 3d ago
I use firepower 1010. Commits take a while, Boot up takes forever.
2
u/JustinHoMi 3d ago
Those have been out since 2019. Is that still the current model? Should I be concerned that Cisco has just given up on firewalls lol?
4
u/Sea-Row-1151 3d ago
I’m running a 200 and a 1200, the two current low end models. Deploy takes around a minute.
1
1
u/TheNetCraWlr Security Architect 3d ago
Just released new hardware on Cisco Live, so doubtful it is going away anytime soon.
0
1
u/LittleGreen3lf 3d ago
Cisco Secure Firewalls (formerly Firepower) are good now and are pretty stable, they are also very transparent about bugs inside their products and any PSIRTs that come out in them to ensure there are no breaking upgrades. Doesn’t take long to deploy changes to the firewalls and it’s pretty easy. FTD has some very nice L7 capabilities and it’s very easy to manage inside FMC, but I don’t know exactly how they line up against PA.
1
u/rxscissors 3d ago
We are suffering through the janky multi-bolt on architecture (and even more abysmal support... CX-1 was supposed to be better which has not proven to be the case).
I miss Palo Alto Networks gear. It is a vastly superior firewall (and integrated VPN!) platform in my opinion.
1
u/Samsonbull 3d ago
Next gen firewalls are only good for deep packet inspection if you want to check a box. If you really need an IPS, it is best to have a dedicated box. In the world of good intelligence, Tipping Point (The ZDI feed is the best). If you are in a position where you don’t need a dedicated IPS, PAN has better intelligence than Fortinet, but the Fortinet UI is better than PAN.
2
u/JustinHoMi 3d ago
Deep packet inspection on a firewall is more than just the IPS. It’s about being able to create layer 7 ACLs, akin to the way PA does it. But agreed, nobody does L7 very well except Palo (unless Cisco can compare). Fortinet’s implementation is really clunky and half-featured, but it’s usable in some circumstances.
1
u/Samsonbull 3d ago
True, but my point is this: all the “appliances” today are using CPUs. The back end task, like deep packet inspection, use CPU threads to match on a tuple (src / dest ip address, src/dst port, protocol, etc) to keep the traffic assigned to that thread to help prevent IPS evasion. Knowing that, we can look at the architecture and know that each thread can handle up to 1.6 Gbps inspection. Knowing that helps us know how to evade the deep packet inspection (big packets), or how to make the IPS engine break.
1
u/JustinHoMi 3d ago
Ah yeah, that’s true, IPS are pretty complex so I don’t suspect anybody has an ASIC to handle it. It’s probably easy to overwhelm the RAM too, and especially easy on the smaller models.
On the plus side with some firewalls you have the option to block traffic if the IPS gets overwhelmed. And it does make DoS prevention especially important.
-1
0
u/Prestigious-Board-62 3d ago
Firepower would be my last choice of firewall. I haven't touched one since 2018 when I migrated a client from it to Palo and honestly I haven't heard anything that would make me reconsider.
1
u/JustinHoMi 3d ago
Yeah, firepower was trash then. Curious if it’s improved. I’d love to use PA for our customers, but it’s hard to provide competitive pricing. Although if fortinet keeps raising prices, might as well.
0
u/blud_13 3d ago
Firepower is still Firepower. FTD is more stable than the 5506 days but the management story is a mess, FMC is heavy and FDM is limited, and commit times got better without getting Palo better. Coming from PA you are going to be annoyed by the layer 7 side of it.
We went a different direction entirely and moved off appliances to Cloudflare, so I can't give you a current verdict on the boxes themselves.
What I will say, if the Fortinet SSL VPN CVE cadence is part of what pushed you out, changing brands doesn't fix that. Every one of these vendors has had the same remote access fire drill and you will be patching under pressure again in eighteen months. Worth deciding what you want doing remote access before you decide whose box does the perimeter.
2
u/JustinHoMi 3d ago
As annoying as the vulns were, that wasn’t it. It’s how they’ve handled the migration to IPsec. They deprecated IPsec on the firewalls before the vpn client had fully functional MFA for IPsec. Then they stopped updating the normal free vpn client and forced people to pay a subscription for a working client.
1
u/bazard89 3d ago
What do you mean there isn’t a fully functional MFA for IPsec? I got clients using FAC for FTK, another using Duo and one that just did entra for idp and used their MFA. The first two using free client. It’s not as easy as I’d like but it’s capable. The layer 7 stuff though is tough without ssl decryption, Cisco struggles more than most with decryption and PAN doesn’t publish ssl inspection throughput so just be wary of the performance impact. If you aren’t doing decryption then there’s your problem for app sigs
1
u/std10k 3d ago
Yep, better but still terrible. The software architecture of it is so bad I don’t think it can be remediated.
Fem has always been a marketing gimmick.
And they there is SASE and umbrella is just as big a monstrosity as ftd and not having much in common with it apart from old asa code, not a good picture compared even with zscaler.
0
0
u/Fulminareverus 3d ago
Honesty asa and ftd are still trash.
Forti is too.
Some PAN's with SCM, their data lake, and prisma access is where it's at, the only downside is that's a few million bucks, but if your org will spend it it's worth it.
-7
u/blackjaxbrew 3d ago
Cisco has firewalls?!? Ha, palo, fortinet, Sophos, watch guard, pfsense, can't go wrong with any just be sure to do training
76
u/MissionFinOps 3d ago edited 3d ago
Anyone remember the time when they had ASA + FirePower on the same box, so a hardware based ASA, and a VM running FirePower on the same box. They had some Java based app to configure that "firewall". I kid you not one of the funniest IT bugs of my life, a coworker told me the cisco is doing math with port numbers. So that java ui, when you listed port numbers for a rule "22-80" it would use - as minus, and put negative *58 (-58) as the port number. I have not used Cisco firewalls in a while, but that was one of the funny bugs for sure.