Cisco PIX security appliances and Cisco ASA Series adaptive security appliances integrate comprehensive firewall, intrusion protection, and VPN functionality in a cost-effective, single-cabinet package. Both product families have been replaced by Cisco's ASA 5500-X series of firewalls with Firepower. (See integration and debugging help with ASA 5500-X firewalls with Firepower Services.) Nevertheless, PIX and previous-generation ASA 5500 Series firewalls are extensively deployed and continue to deliver small and mid-size companies a reliable security solution.
Cisco PIC and the original ASA 5500 firewalls offer powerful client and program policy support, mutlivector attack protection, and safe connectivity services. The increased intelligence sharing of integrated protection services in a stand-alone package offers customers deploying these aggregated firewalls the advantages of enhanced security, reduced TCO, and smaller management expense.
PIX firewalls and the ASA 5500 Series combine with IOS Firewall, the FWSM for Cisco Catalyst 6500 switches, and Cisco 7600 family routers as components of Cisco's versatile, self-contained firewall product. Based on a scalable, modular platform, every offering is designed with a specific array of options to provide better security to a variety of network environments. These solutions can be individually installed to secure specific areas of a network infrastructure, or can be grouped for a layered, defense-in-depth strategy following the architecture best practices described in Cisco's SAFE Blueprint. Completing the modular firewall product line, Cisco has developed a complete security management portfolio, spanning Cisco security device and IOS Software security components and embedded device managers, to standalone management programs, helping to make sure that businesses can effectively use their Cisco security solution purchases.
Cisco PIX Firewalls
PIX firewalls offer robust user and application policy support, multi-source attack protection, and safe connectivity services in affordable, out-of-the-box modules. These purpose-built devices offer a wealth of built-in protection and networking services such as process-aware firewall services, Voice over IP (VoIP) and multimedia protection, reliable multi-location and remote-connectivity IPcec Virtual Private Network (VPN) networking, high availability, smart networking services, and versatile management options. The Cisco PIX Security Appliance Series family spans compact plug-and-go desktop units for small or home offices to modular high-bandwidth products with ROI for large business and ISP environments, Cisco PIX firewalls provide dependable security, speed, and availability for network environments of all sizes.
Built around a tested, purpose-built OS that delivers rich security features, Cisco PIX firewall appliances provide a high level of protection and have been awarded EAL 4 status and ICSA Firewall and IP Security qualification. Cisco PIX firewalls provide protection for a wide range of Voice over IP and additional mixed-media standards such as H.323 Version 4, Session Initiation Protocol (SIP), Cisco Skinny Client Control Protocol, Real-Time Streaming Protocol, and MGCP, helping organizations to protect deployments of a broad range of current and upcoming IP voice and multimedia applications.
PIX firewall appliances feature a wealth of setup, tracking, and analysis features, providing businesses the flexibility to utilize the methods that most closely meet their needs. Management options include centralized, policy-based administration tools, integrated web-accessible management, and compatibility with remote-tracking standards like Simple Network Management Protocol (SNMP) and syslog. The integrated Adaptive Security Device Manager system offers a powerful web-based management solution that greatly streamlines the deployment, ongoing configuration, and monitoring of a single PIX firewall without requiring any extra utility other than an ordinary web browser and Java plug-in to be installed on a manager's PC.
IT managers can also remotely configure, monitor, and analyze PIX firewall appliances using a CLI interface. Safe command-line interface (CLI) communication is possible through a number of methods including Secure Shell Protocol, Telnet through IPsec, and out-of-band via a console port. PIX firewalls also include dependable automatic-update capabilities, a collection of protected remote-management options that make sure that firewall settings and software images are always up to date.
Cisco Adaptive Security Appliances (ASA) Firewalls
Cisco ASA 5500 Series Firewalls are purpose-built solutions that bring together market-proven, best-of-breed protection and VPN support plus a flexible architecture. The result is a powerful, multifunction network security solution better able to defend small and midsize business and larger networks and, simultaneously, lower the total deployment and operations expenses formerly required for this high degree of protection.
Cisco Adaptive Security Appliances 5500 Series firewalls deliver a high-level of application security via smart, application-aware inspection processes that analyze network flows at Layers 4-7. This results in a safer network covering web, voice, and mobile wireless access. To defend networks against application-layer assaults and to offer organizations more policing of the applications and protocols utilized in their environments, these inspection engines integrate extensive application and protocol knowledgebases and rely on protection enforcement technologies that include anomaly detection and state monitoring. Also incorporated are assault detection and mitigation techniques including application/protocol command filters and URL deobfuscation. Cisco Adaptive Security Appliances firewall inspection engines also provide control over instant messaging and tunneling applications, allowing organizations to enforce usage policies and recover network bandwidth for vital business processes.
At the same time as increasing network protection, Cisco Adaptive Security Appliances firewalls also decrease deployment and operational expenses. By offering extensive Virtual Private Network and security functions, the Cisco Adaptive Security Appliances (ASA) 5500 Series firewall can be a the only platform for many environments, enabling platform standardization. The Cisco Adaptive Security Appliances (ASA) 5500 Series firewall can be used as a consolidated threat-protection device at the datacenter by taking advantage of its access control, application inspection, and malicious assault remediation technologies. The Cisco Adaptive Security Appliances (ASA) firewall can also be deployed as a specialized remote access device using its VPN capabilities. Alternatively, the Cisco ASA 5500 Series firewall performs capably in the network interior for inter-office connectivity control and to guard against malicious assaults inside workers may unwittingly introduce into the network. In small business and branch office environments, the Cisco Adaptive Security Appliances firewall acts as a total solution platform providing comprehensive intrusion prevention and VPN functionality while suiting the cost structure and operational demands of these deployments.
This versatile one-device, multiple-use approach reduces the total number of devices that must be installed and maintained while providing a standard functional and management system across all installations. This approach streamlines the education of configuration, monitoring, troubleshooting, and security staff. To further minimize operations expenses, Cisco Adaptive Security Appliances firewalls are also highly network conscious, enabling them to insert seamlessly into the network without disrupting authorized traffic and processes.
How Progent Can Assist You with Cisco PIX and ASA Security Appliances
Cisco ASA Series adaptive security appliances and PIX firewalls provide a wealth of setup, tracking, and troubleshooting features which give you the flexibility to set up these firewalls to align optimally with your company's needs. Progent's CCIE certified network experts can help you to support your existing infrastructure that incorporates Cisco ASA and/or PIX firewall technology and that provides protection, fault tolerance, throughput, and recoverability. Progent's firewall experts can also help your organization to upgrade to Cisco ASA 5500-X firewalls with Firepower Services.
Progent's GISA and CISSP-ISSP-certified information security engineers can help your business to develop a security strategy appropriate for your environment and can configure your PIX or ASA firewall to support your security strategy. Progent's security assessment consultants can assess the strength of your current firewall deployment and audit the security of your entire IT network. Progent's Technical Response Center can provide emergency online technical support for Cisco technology and can give you quick access to a Cisco CCIE network engineer.
To see more information about Progent's consulting assistance for Cisco technology, select a subject: