Cisco is a perennial leader in developing cutting-edge firewalls for the broadest possible range of deployments. Cisco's Firepower NGFWs Firewalls provide a modern firewall platform that marshals dedicated hardware, cloud services, and machine learning to block, identify, and mitigate cyber attacks automatically. Progent's Cisco-certified CCIE firewall consultants can help you to plan and carry out a smooth upgrade to Cisco Firepower firewalls from Cisco's from ASA 5500-X, ASA 5500, or PIX appliances and show you how to enhance Firepower firewalls with Cisco's security services to build and centrally manage network ecosystems that span local offices, data centers, private clouds and public clouds. Progent's firewall consultants can also assist you to maintain and troubleshoot legacy Cisco firewalls. Progent's certified network security experts can assist you with policy creation based on industry best practices in order to establish a consistent and effective cybersecurity profile across all your networked devices at any location.
Cisco's Firepower Next Generation Firewall Appliances
Cisco's Firepower Next Generation Firewalls deliver a significant performance improvement compared to Cisco's previous-generation ASA 5500-X security appliances and offer centralized control of advanced security capabilities such as application visibility and control, next-generation intrusion protection (NGIPS) with intelligent prioritization of risks, advanced malware protection, DDoS mitigation, and sandboxing. For more information about Cisco's Firepower family of Next Generation Firewalls (NGFWs), refer to Cisco Firepower firewalls consulting expertise.

Cisco's ASA 5500-X and Legacy Firewalls
Cisco's ASA 5500-X Series, ASA 5500, and PIX firewalls offer combined firewall, IPsec VPN, and IPS capabilities in single-box packages, delivering a wide array of features to match the security needs of organizations from small and mid-size businesses to enterprises and Internet service providers. Cisco's ASA 5500-X Series, ASA 5500 Series, and PIX 500 firewalls allow network security staffs to protect their network edge and provide safe offsite and mobile connectivity while utilizing powerful administration tools built on Cisco's world-class firewall products.
Cisco's ASA 5500 and PIX firewall appliances have arrived at end-of-life (EOL) but are still widely deployed in small and mid-size businesses and in a few enterprise data centers. The ASA 5500-X Next-Generation Firewalls deliver substantially more bang for the buck and have superseded Cisco's ASA 5500 and PIX families of firewalls for new deployments. Still, Cisco's legacy firewalls, if carefully maintained, can offer a high degree of protection by supplying multiple services including firewall, VPN, and IPS.
After Cisco's acquisition of Sourcefire, the whole family of Cisco ASA 5500-X devices can be configured to enable Firepower Services, based on Sourcefire's Snort technology, which is the world's most popular network intrusion protection system. Firepower services bring enhanced features such as advanced malware protection (AMP), URL filtering, dynamic threat analytics, and security automation.
Progent's Cisco-certified network engineers can assist you to support and troubleshoot older ASA 5500 Series and PIX 500 firewalls and can also help you to plan and carry out an efficient upgrade to Cisco's ASA 5500-X firewalls with Firepower. Progent can also assist you to plan, deploy, tune, administer and debug new firewall ecosystems based on Cisco's latest ASA 5500-X models with Firepower. Progent can also help you to migrate from your Cisco ASA 5500-X deployment to Cisco's Firepower NGFWs Firewalls.
Cisco's ASA 5500-X Firewall Product Family
Cisco's extensive family of ASA 5500-X firewalls features an improved substitute for every rack-mountable model in the older ASA 5500 line of firewalls. Each ASA 5500-X firewall targets the identical market as the corresponding earlier models, which offers small and midsize businesses plenty of room for picking a solution that meets their security requirements and budgets. All ASA 5500-X products build on Cisco's proven stateful-inspection firewall technology and all incorporate purpose-built 64-bit hardware with multicore CPUs and support Cisco's powerful security services. All models in Cisco's ASA 5500-X family provide dependable protection across any mix of physical, virtual, and cloud deployments.

For more details about ASA 5500-X security appliances, Firepower services, and Progent's support for Cisco ASA firewalls, go to Firepower configuration and debugging expertise
Cisco's Firepower Services for ASA 5500-X Security Appliances
Cisco ASA 5500-X security appliances accept software or physical modules that enable Firepower Services, which provide layered defense against multi-vector threats. Firepower Services are based on technology acquired by Cisco from Sourcefire. Major features of Firepower Services for ASA 5500-X firewalls include:

Simpler deployments of Cisco ASA firewalls can be efficiently administered via Cisco's on-device Adaptive Security Device Manager (ASDM) Adaptive Security Device Manager, a web utility which is provided with all ASA 5500-X models. ASDM includes a simple web console for configuring, managing, and troubleshooting ASA 5500-X appliances and service modules.
For multi-device and multi-site deployments, ASA 5500-X appliances with Firepower can be administered using Cisco's Firepower Management Center, available as one or more physical or virtual appliances. Firepower Management Center provides unified firewall management, Application Visibility and Control (AVC, enhanced IPS, URL filtering, and Advanced Malware Protection. Because of ongoing rebranding since Cisco's acquisition of Sourcefire Defense Center, Firepower Management Center has been offered under various names including Cisco Defense Center, FireSIGHT Defense Center, and FireSIGHT Management Center.

Cisco's Firepower Management Center provides capabilities beyond those available with Cisco's on-box ASDM utility. Additional features include greater context awareness, Cisco's Advanced Malware Protection with remediation for client devices, a console that provides real-time network infrastructure visualization, automated policy tuning based on risk assessment of attacks, advanced IPS, custom application discovery for Application Visibility and Control (AVC), customized health notifications, improved reporting options, and APIs for host input and databases. Hardware-dependent options like clustering, stacking, switching, routing, VPN, and NAT must be handled using either the on-box ASDM or the ASA command line interface.
Cisco ASA 5500 Family of Firewalls
Cisco ASA Firewalls leverage engineering developed for the PIX 500 Series Security Appliance, the Cisco IPS 4200 Series sensor, and Cisco's VPN 3000 model concentrator. These technologies enable the Cisco Adaptive Security Appliances (ASA) 5500 Series Firewall product line to deliver a platform that stops the widest variety of attacks. Cisco ASA Firewalls deliver program protection, network containment, and safe Virtual Private Network connectivity across the entire product portfolio. This broad scope of security enables the guarding of any network segment, which includes the most typical threat vectors such as remote sites, locally-connected inside users, and off-site access VPNs.

Cisco Adaptive Security Appliances (ASA) firewalls provide robust application security through smart, application-aware inspection processes that examine network flows at Layers 4-7. The result is a better protected network covering Web, voice, and mobile wireless access. To defend against application-layer assaults and to provide stronger control over the applications and protocols utilized in their environments, these inspection engines integrate extensive application and protocol knowledgebases and employ security enforcement solutions such as anomaly detection and application and protocol state monitoring. Also incorporated are attack detection and mitigation technology including application/protocol command filters and URL deobfuscation. Cisco Adaptive Security Appliances firewall inspection engines also provide management of instant messaging and tunneling applications, allowing businesses to enforce usage policies and recover bandwidth for vital business processes.
For more information about Progent's support services for Cisco's ASA 5500 security appliances, go to ASA 5500 series firewalls integration and debugging support.
Cisco PIX Firewalls
Built around a tested, purpose-built operating system that delivers rich security services, PIX security appliances offer a high level of protection and have received EAL 4 status and ICSA Labs Firewall and IP Security certification. Cisco PIX security appliances offer protection for a wide array of VoIP and additional mixed-media standards such as H.323 v. 4, SIP, Cisco Skinny Client Control Protocol (SCCP), Real-Time Streaming Protocol, and Media Gateway Control Protocol, enabling businesses to protect installations of a broad range of current and next-generation Voice over IP and video applications.

IT managers can also remotely configure, track, and analyze PIX security appliances using a CLI interface. Safe command-line interface access is available using several methods such as Secure Shell Protocol, Telnet through IP Security (IPsec), and out-of-band via a console port. PIX security appliances also have robust automatic-update capabilities, a collection of revolutionary secure remote-administration options that make sure that firewall configurations and software images are always up to date.
For additional information about Progent's consulting services for Cisco PIX 500 firewalls, go to Cisco PIX firewalls configuration and debugging support.
Progent's Migration Consulting for Cisco Firewalls
Since Cisco has discontinued offering the PIX 500 and ASA 5500 families of firewalls, many businesses are concerned about relying on a key security component that may stop being supported. ASA 5500-X and Firepower NGFW Series firewalls have the advantage of being current products and also bring several functions and financial benefits in comparison to PIX firewalls. These benefits include significantly better throughput, optional SSL tunneling capability, and an expandable design that protects your investment by allowing you to self-install new security features whenever you need them. Progent's CCIE-certified experts can help you to determine the strategic value of for migrating from PIX or ASA 5500 firewalls, create a migration plan that permits a fast and non-disruptive changeover, assist your IT staff to deploy new ASA 5500-x Series or Firepower Series appliances, and provide online, consulting, and troubleshooting services.
Other Ways Progent Can Assist You with Cisco ASA and PIX Firewalls
Cisco's Firepower NGFW Series, ASA 5500 Series, and PIX family security appliances provide a wealth of setup, monitoring, and analysis options which offer you the flexibility to deploy these firewalls to align optimally with your company's needs. Progent's CCIE authorized network consultants can assist you to build a cost-effective network infrastructure that incorporates Cisco firewall technology and that offers world-class security, fault tolerance, throughput, and recoverability. Progent's GISA and CISSP-ISSP-premier IS security consultants can help your business to develop a security strategy appropriate for your business and can set up your PIX or ASA firewall to support your security policies. Progent's security evaluation experts can evaluate the strength of your current firewall solution and help determine the security of your whole IS environment. Progent's Help Desk support team can provide urgent online troubleshooting for Cisco technology and offer fast access to a Cisco CCIE expert.
For additional details about Progent's consulting support for Cisco technology, select a subject:
Integration of Cisco and Third-party Firewall Technology
Progent offers expertise in firewall and VPN products from all major vendors and can help you integrate Cisco technology with additional security solutions to help you build a cost-effective network infrastructure that provides a level of security and flexibility appropriate for your business. Third-party firewall and VPN support services available from Progent include:
In order to ask Progent about engineering expertise for Cisco networking, call