Cisco is a perennial leader in developing state-of-the-art firewall appliances for the widest possible range of deployments. Cisco's Firepower Next Generation Firewall (NGFW) security appliances represent an advanced firewall platform that combines dedicated hardware, cloud services, and next-generation intrusion protection system (NGIPS) to anticipate, discover, and respond to cyber attacks automatically. Progent's Cisco-certified CCIE firewall experts can help your organization to plan and execute a smooth upgrade to Cisco Firepower Series firewalls from Cisco's from ASA 5500-X, ASA 5500, or PIX firewalls and show you how to enhance Firepower appliances with Cisco's cloud-based services to build and centrally manage IT ecosystems that encompass local offices, data centers, private clouds and public clouds. Progent can also assist you to maintain and troubleshoot legacy Cisco security appliances. Progent's certified network security consultants can assist you with policy creation based on leading practices in order to build a consistent cybersecurity posture that applies to all your devices at any location.
Cisco's Firepower Next Generation Firewalls
Cisco's line of Firepower Next-Generation Firewalls deliver advanced security and unified management at price points, performance levels, and scale suitable for environments spanning telecommuters and small organizations to global enterprises and service providers. Cisco's Firepower NGFW appliances provide a major performance boost compared to Cisco's older security appliances and offer centralized management of modern cybersecurity capabilities such as application visibility and control, next-generation intrusion protection with intelligent prioritization of risks, advanced malware protection (AMP), DDoS mitigation, and sandboxing.
All Firepower Next-Generation firewalls have a one-pass architecture and permit uninterrupted analysis and retrospective detection, which allows the firewalls to provide outbreak controls and to pinpoint root causes. Firepower NGFW firewalls also offer URL Filtering and sandboxing for detecting evasive and sandbox-aware threats, behavioral indicators of compromise, and malware artifacts. NGIPS rule tuning and network firewall policy creation are performed automatically, requiring no manual intervention by IT security experts. All Firepower Next-Generation firewalls offer the choice of using either Cisco Firepower Threat Defense (FTD) or Adaptive Security Appliance (ASA) software. Unified deployment, logging, system monitoring, and reporting functions can be managed either by Cisco's Management Center or in the cloud with Defense Orchestrator.
Cisco Firepower 1000 Series Next-Generation Firewalls
Cisco Firepower Next-Generation 1000 Series Firewalls are targeted at small businesses, home offices, or branches. Appliances in this family deliver improved value vs. corresponding Cisco ASA models, delivering 4-6X higher firewall speed. Local management can be done with Firepower Device Manager. 1000 Series firewalls include an integrated 10M/100M/1GBASE-T RJ-45 Ethernet interface for management, an RJ-45 console interface, a USB 3.0 Type-A interface, and 200 Gbytes of storage. High availability is supported as well as VPN load balancing.
Cisco's Firepower 1010 model is a desktop or wall-mount, quiet appliance that offers 890 Mbps throughput, AVC, and Next Generation Intrusion Prevention System. The appliance has 8 built-in RJ-45 I/O interfaces, two of them with POE+. IPsec VPN performance is 400 Mbps and the appliance allows 100K concurrent sessions, 6,000 new connections per second, and up to 75 VPN peers. The Firepower 1120 firewall is a 1RU appliance that provides firewall performance of 2.3 Gbps. The appliance features 8 RJ45 integrated I/O interfaces and four SFP ports. IPsec VPN throughput is 1.2 Gbps and the unit allows 200K concurrent sessions, 15,000 new connections/second with AVC, and as many as 150 VPN peers.
The Firepower 1140 firewall is a 1RU appliance that delivers firewall performance of 3.3 Gbps. The firewall comes with eight integrated RJ-45 interfaces and four SFP interfaces. IPsec VPN throughput is 1.4 Gbps and the firewall allows 400K simultaneous sessions, 22K new connections/second with Application Visibility/Control, and a maximum of 400 VPN peers. The Firepower 1150 firewall is a 1RU rackmount device that delivers firewall throughput of 5.3 Gbps. The appliance comes with eight integrated RJ-45 interfaces, two SFP interfaces, and two 10G SFP+ interfaces. IPsec VPN performance is 2.4 Gbps and the firewall can handle 600K concurrent sessions, 28,000 new connections/second, and as many as 800 VPN peers.
Cisco Firepower 2100 Series Next-Generation Firewalls
Cisco's Firepower 2100 Series Next-Generation Firewalls are 1RU rack appliances designed for operation at the data center. Appliances in this family feature a dual multicore CPU architecture that allows them to deliver 3-6X higher performance than Cisco ASA firewalls they are engineered to succeed. Onsite management can be performed with Cisco Firepower Device Manager. All Firepower 2100 Series Next-Generation Firewalls include 12 RJ45 interfaces and four SFP interfaces. These units include one build-in 10M/100M/1GBASE-T RJ-45 Ethernet port for management, an RJ-45 console port, and one USB 2.0 Type-A connection. Active/standby high availability is supported along with VPN load balancing.
Cisco's Firepower 2110 firewall has four built-in 1 Gb SFP Ethernet interface ports and 100 GB of storage. The 2110 delivers 2.6 Gbps firewall performance and 800 Mbps IPsec VPN throughput and allows 1 million concurrent sessions, 18,000 new connections/second, and a maximum of 1,500 VPN peers. Cisco's Firepower 2120 model firewall comes with 12 built-in 10M/100M/1GBASE-T Ethernet RJ-45 interfaces, four integrated 1G SFP Ethernet interfaces, and 100 GB of storage. The 2120 delivers 3.4 Gbps firewall performance and 1 Gbps IPsec VPN performance and allows 1.5 million concurrent sessions, 28,000 new connections per second and as many as 3,500 VPN peers.
Cisco's Firepower 2130 model firewall has 4 integrated 10 Gb SFP+ ports and 200 GB of storage. The 2130 also accepts a network module with eight extra interfaces. The Firepower 2130 delivers 5.4 Gbps firewall throughput and 1.9 Gbps IPsec VPN performance and allows 2 million concurrent sessions, 30,000 new connections per second, and a maximum of 7,500 VPN peers. Cisco's high-end Firepower 2140 model firewall features 4 integrated 10 Gigabit SFP+ interface ports and 200 GB of storage. The unit also accepts a network module with eight additional interface ports for a maximum of 24 Ethernet ports. The 2140 model offers 10.4 Gbps firewall throughput and 3.6 1Gbps IPsec VPN performance and supports 3 million concurrent, 57,000 new connections/second, and a maximum of 10,000 VPN peers. Both the 2130 and 2140 appliances feature dual AC or DC power supplies.
Cisco Secure Firewall 3100 Series
Cisco's 3100 Firewall Series models are modular single-rack units intended for enterprises who require throughput, high port density, and zero-trust cybersecurity at the Internet edge, the corporate data center, or a private cloud. For high uptime, all Secure Firewall 3100 Series models allow 8-device clustering and work in Active/active or Active/standby mode. The units can run Cisco's ASA or Firewall Threat Defense (FTD) software. Built-in I/O for each unit includes 8 10M/100M/1GBASE-T Ethernet interfaces (RJ-45) and eight 1/10 Gigabit Ethernet interface ports. Plug-in network modules offer 1/10/25/40G options and all versions come with 900 GB of storage as well as a spare storage slot.
Cisco's Secure Firewall 3105 device delivers 10 Gbps firewall performance and 5.5 Gbps IPsec VPN performance. The 3105 supports 1.5 million simultaneous sessions, 90,000 new connections/second, and as many as 2,000 VPN peers. Cisco's Secure Firewall 3110 device offers 10 Gbps firewall throughput and 8 Gbps IPsec VPN performance. The 3110 supports 2 million concurrent sessions, 130,000 new connections per second, and as many as 3,000 VPN peers. Cisco's 3120 Firewall model offers 21 Gbps firewall performance and 10 Gbps IPsec VPN throughput. The 3120 firewall allows 4 million simultaneous sessions, 170,000 new connections per second, and as many as 7,000 VPN peers. Cisco's Secure Firewall 3130 model offers 42 Gbps firewall throughput and 14 Gbps IPsec VPN throughput. The 3130 allows 6 million simultaneous sessions, 200K new connections per second, and a maximum of 15,000 VPN peers. The 3130 firewall includes 8 1/10/25G SFP+ interfaces. Cisco's Secure Firewall 3140 appliance delivers 49 Gbps firewall throughput and 17 Gbps IPsec VPN throughput. The 3140 allows 10 million concurrent sessions, 200K new connections per second, and as many as 20K VPN peers. The 3140 features eight 1/10/25G SFP+ ports.
Cisco Firepower 4100 Series Next-Generation Firewalls
Cisco's Firepower 4100 Series Next-Generation Firewalls are single-rack appliances designed for deployment at high-performance data centers. Firewalls in this family offer 5-10X faster performance than the Cisco ASA 5585-X firewall they are engineered to succeed. Local management can be done with Firepower Device Manager. All Firepower 4100 Series NGFW Firewalls include 8 integrated SFP+ interfaces and all can be expanded with a selection of add-in network modules for a maximum of 24 interfaces. All Firepower 4100 Series NGFW Firewalls offer virtual private network load balancing, Active/Standby high availability, and clustering of as many as six chassis. These devices include a built-in 1Gb Ethernet port for management, one RJ-45 console interface, and one USB interface.
Cisco's Firepower 4110 firewall includes 200 GB of storage and offers 13 Gbps firewall throughput and 6 Gbps IPsec VPN performance. The 4110 allows 10 million concurrent sessions, 64K new connections per second, and up to 10K VPN peers. Cisco's Firepower 4112 firewall comes with 400 GB of storage and delivers 19 Gbps firewall throughput and 8.5 Gbps IPsec VPN throughput. The 4112 firewall allows 10 million concurrent sessions, 98K new connections/second, and up to 10,000 VPN peers. Cisco's Firepower 4115 device has 400 GB of storage and offers 33 Gbps firewall throughput and 8 Gbps IPsec VPN throughput. The 4115 firewall supports 15 million concurrent sessions, 210K new connections per second, and up to 15,000 VPN peers. Cisco's Firepower 4120 model comes with 200 GB of storage and delivers 22 Gbps firewall performance and 19 Gbps IPsec VPN throughput. The 4120 firewall supports 15 million concurrent sessions, 118K new connections per second, and as many as 15,000 VPN peers. Cisco's Firepower 4125 firewall features 800 GB of storage and delivers 45 Gbps firewall throughput and 19 Gbps IPsec VPN performance. The 4125 firewall supports 25 million simultaneous sessions, 269K new connections per second, and a maximum of 20K VPN peers.
Cisco's Firepower 4140 model firewall includes 400 GB of storage and delivers 32 Gbps firewall performance and 13 Gbps IPsec VPN performance. The 4140 unit allows 25 million concurrent sessions, 172K new connections/second, and as many as 20K VPN peers. Cisco's more recent Firepower 4145 firewall features 800 GB of storage and offers 53 Gbps firewall throughput and 24 Gbps IPsec VPN throughput. The 4145 firewall supports 30 million simultaneous sessions, 365K new connections/second, and as many as 20K VPN peers. Cisco's Firepower 4150 unit has 400 GB of storage and offers 45 Gbps firewall throughput and 14 Gbps IPsec VPN throughput. The 4150 firewall supports 30 million concurrent sessions, 263K new connections/second, and as many as 20K VPN peers.
Cisco Secure Firewall 4200 Series
Cisco's Secure Firewall 4200 Series appliances are expandable 1RU firewalls designed for deployment at large enterprise campuses and data centers that require high-end performance, manageability, and scale. Cisco's Secure Firewall 4200 Series appliances offer over double the performance of previous generation firewalls and offer high port density. As many as 8 chassis can be clustered for high availability and scale. Crypto accelerator enables SSL and VPN decryption in real time, and zero trust application access permits complete threat inspection for apps. 4200 Series firewalls can be managed locally via the Firewall Management Center or in the cloud using Cisco Defense Orchestrator. Every 4200 device includes 8x 1/10/25 Gigabit Ethernet on-chassis ports and has two module bays for rapid expansion. As many as 24 total Ethernet interfaces are supported. Every 4200 device comes with 1.8 TB x 2 storage.
Cisco's Secure Firewall 4215 product is designed for enterprise campuses with strong growth expectations. The 4215 offers 90 Gbps firewall throughput and 45 Gbps max IPsec VPN performance. The 4215 allows 15 million simultaneous firewall connections, 350 K new connections each second, and as many as 20,000 VPN peers. Cisco's Secure Firewall 4225 device is intended for enterprise data centers. The product offers 95 Gbps firewall throughput and 80 Gbps max IPsec VPN throughput. Cisco's 4225 firewall supports 30 million concurrent firewall connections, 600 K new connections per second, and up to 25,000 VPN peers. Cisco's Secure Firewall 4245 model is built for service providers who support a high volume of traffic. Cisco's 4245 delivers 180 Gbps firewall throughput and 140 Gbps IPsec VPN throughput. The 4245 allows 60 million simultaneous firewall connections, 800 K new connections each second, and up to 30,000 VPN peers.
Cisco Firepower 9300 Series Next-Generation Firewalls
Cisco's Firepower 9300 Series Next-Generation Firewalls are massively scalable and ultra-high performing security appliances. The 3RU chassis of Firepower 9300 Next-Generation Series firewalls can hold two add-in network modules and three security modules. Fully loaded, the Firepower 9300 can hold 24 10-Gigabit SFP+ interfaces or eight 100G interfaces. Intrachassis clustering of up to five chassis delivers a total 1.2 Tbps of firewall performance. The top-of-the-line Cisco Firepower 9300 SM-56 x 3 provides 235 Gbps firewall throughput and 27 Gbps IPsec VPN throughput. The 9300 SM-56 allows 195 million simultaneous sessions, 4.75 M new connections per second, and up to 20,000 VPN peers.
Cisco's ASA 5500-X and Legacy Firewalls
Cisco's ASA 5500-X, ASA 5500 Series, and PIX 500 firewall appliances provide integrated firewall, IPsec VPN, and intrusion prevention system capabilities in single-box devices, delivering a broad range of features to meet the security requirements of organizations from small businesses to enterprises and Internet service providers. Cisco's ASA 5500-X Series, ASA 5500, and PIX firewalls allow network security teams to defend their network perimeter and provide safe offsite and mobile connectivity while using advanced administration tools built on Cisco's world-class firewall products.
Cisco's ASA 5500 and PIX 500 firewalls have arrived at end-of-life (EOL) status but are still widely used in small and mid-size organizations as well as in some larger networks. The ASA 5500-X Next-Generation Firewalls deliver substantially more value and have supplanted the ASA 5500 and PIX 500 families of firewalls for new deployments. Still, Cisco's legacy firewall appliances, if properly maintained, can deliver a high level of security by supplying a variety of security functions including firewall, Virtual Private Network (VPN) connections, and IPS.
Since Cisco's purchase of Sourcefire, the whole family of Cisco ASA 5500-X firewalls can be configured to enable Firepower Services, built on Sourcefire's Snort product, which is the market's most popular intrusion protection system. Firepower services bring powerful new features including advanced malware protection (AMP), URL filtering, dynamic threat analytics, and automation.
Progent's Cisco-certified infrastructure consultants can assist you to support and debug legacy ASA 5500 and PIX 500 firewall appliances and can also assist you to design and carry out an efficient migration to Cisco's ASA 5500-X firewalls with Firepower Services. Progent can also assist you to design, deploy, tune, administer and troubleshoot new firewall ecosystems built on Cisco's current ASA 5500-X models with Firepower. Progent can also assist you to migrate from your Cisco ASA 5500-X solution to Cisco's Firepower NGFWs Firewalls.
Cisco's ASA 5500-X Firewall Product Family
Cisco's comprehensive line of ASA 5500-X security appliances features an improved substitute for every rack-mountable model in the previous ASA 5500 line of devices. Each ASA 5500-X model is suited for the identical market as the corresponding previous models, which offers most plenty of room for selecting a firewall that meets their security needs and budgets. All ASA 5500-X products are based on Cisco's tested stateful-inspection firewall technology and all incorporate purpose-built 64-bit hardware with multicore processors and are capable of running Cisco's powerful security services. All models in Cisco's ASA 5500-X product line deliver consistent protection across any combination of physical, virtual, and cloud deployments.

For additional information about ASA 5500-X firewalls, Firepower services, and Progent's consulting for Cisco ASA 5500-X security appliances, go to Firepower integration and debugging expertise
Cisco's Firepower Services for ASA 5500-X Firewalls
Cisco ASA 5500-X firewalls accept either software or physical modules that enable Firepower Services, which offer layered protection against advanced threats. Firepower Services are based on innovative technology acquired by Cisco from Sourcefire. Major features of Firepower Services for ASA 5500-X security appliances include:

Smaller deployments of Cisco ASA firewalls can be efficiently administered using Cisco's on-device Adaptive Security Device Manager (ASDM) Adaptive Security Device Manager, a web utility which is provided with all ASA 5500-X models. ASDM includes a simple web dashboard for configuring, managing, and troubleshooting ASA 5500-X firewalls and service modules.
For more complex environments, ASA 5500-X firewalls with Firepower Services can be administered using Cisco's Firepower Management Center, available as one or several physical units or virtual appliances. Firepower Management Center offers unified firewall management, Application Visibility and Control (AVC, advanced IPS, URL filtering, and Advanced Malware Protection (AMP). Due to frequent rebranding after Cisco's acquisition of Sourcefire Defense Center, Firepower Management Center has been offered under various names including Defense Center, Cisco Firesight Defense Center, and FireSIGHT Management Center.

Cisco's Firepower Management Center provides capabilities unavailable with Cisco's on-box Adaptive Security Device Manager tool. Extra features include expanded context awareness, Cisco's Advanced Malware Protection (AMP) with remediation for user devices, a console that offers dynamic network infrastructure visualization, automated policy tuning driven by risk assessment of attacks, advanced IPS, custom app discovery for Application Visibility and Control, customized health alerts, improved reporting options, and application interfaces for host input and databases. Hardware-dependent features like clustering, stacking, switching, routing, VPN, and NAT must be handled using the on-box ASDM or the ASA 5500-X CLI.
Cisco ASA 5500 Family of Firewalls
Cisco Adaptive Security Appliances Firewalls leverage technology developed for the PIX 500 Series firewall, the Cisco IPS 4200 family Intrusion Prevention System, and the VPN 3000 family concentrator. These solutions enable the Cisco Adaptive Security Appliances 5500 Series Firewall family to offer a firewall that defends against the widest variety of threats. Cisco Adaptive Security Appliances 5500 Series Firewalls deliver program protection, local containment, and safe VPN functionality throughout Cisco's product line. This broad scope of security allows the guarding of any network area, which includes the most common attack conduits such as remote locations, locally-attached inside users, and remote connected Virtual Private Networks.

Cisco ASA 5500 Series firewalls provide robust application protection through smart, application-sensitive inspection processes that analyze network flows at Layers 4-7. This produces a more secure environment including Web, voice, and mobile wireless access. To protect networks against application-layer assaults and to provide stronger policing of the programs and protocols utilized in their networks, Cisco's inspection engines incorporate broad application and protocol knowledge and employ security enforcement technologies that include anomaly sensing and state monitoring. Also incorporated are assault sensing and mitigation technology including application/protocol command filters and URL deobfuscation. Cisco Adaptive Security Appliances firewall inspection engines also deliver control over IM and tunneling applications, allowing organizations to police usage policies and conserve network bandwidth for important business applications.
For more information about Progent's consulting services for Cisco's ASA 5500 firewalls, see ASA 5500 series firewalls configuration and troubleshooting support.
PIX Firewall Appliances
Built upon a tested, purpose-built operating system that delivers rich protection services, PIX security appliances provide a high level of protection and have earned Common Criteria Evaluation Assurance Level 4 status and ICSA Firewall and IP Security qualification. Cisco PIX security appliances offer protection for a wide range of VoIP and other multimedia standards including H.323 Version 4, Session Initiation Protocol, Cisco Skinny Client Control Protocol (SCCP), Real-Time Streaming Protocol (RTSP), and Media Gateway Control Protocol, helping businesses to protect deployments of a wide range of current and upcoming VoIP and mixed-media applications.

Administrators can furthermore remotely set up, track, and analyze PIX firewalls using a command-line interface. Safe CLI interface communication is possible using several methods including Secure Shell (SSHv2) Protocol, Telnet over IPsec, and out-of-band through a console port. Cisco PIX security appliances also include dependable auto-update features, a collection of advanced protected remote-management options that make sure that security settings and software images are always current.
For more information about Progent's support services for Cisco PIX firewalls, visit Cisco PIX 500 firewalls integration and troubleshooting support.
Progent's Migration Consulting Services for Cisco Firewalls
Because Cisco has stopped offering the PIX 500 and ASA 5500 families of firewalls, many businesses are concerned about relying on a critical infrastructure component that might stop being supported. ASA 5500-X and Firepower NGFW Series security appliances have the benefit of being new devices and also offer a number of technical and economic benefits in comparison to PIX 500 firewalls. These benefits include significantly higher performance, optional Secure Sockets Layer VPN capability, and a modular architecture that guards your investment by enabling you to self-install more security services whenever you require them. Progent's Cisco certified network engineers can help you to assess the business case for migrating from PIX 500 or ASA 5500 security appliances, design a migration plan that allows for a fast and non-disruptive changeover, assist you to set up new ASA 5500-x or Firepower Series firewalls, and offer remote training, consulting, and troubleshooting services.
Other Ways Progent Can Help Your Business with Cisco ASA and PIX Security Appliances
Cisco's Firepower Series, ASA Series, and PIX family firewalls incorporate an array of configuration, monitoring, and analysis features that offer you the ability to set up these firewalls to match your company's needs. Progent's CCIE certified network professionals can show you how to design an efficient infrastructure that includes Cisco security appliances and that offers world-class protection, resilience, throughput, and recoverability. Progent's CISA and CISM-premier information security professionals can assist your business to develop a security strategy that makes sense for your situation and can set up your security appliance to support your security policies. Progent's security assessment experts can assess the effectiveness of your existing firewall solution and audit the overall security of your whole information system network. Progent's Technical Response Center can deliver emergency remote technical support for Cisco products and offer quick access to a Cisco network engineer.
Integration of Cisco and Third-party Firewall Technology
Progent offers expertise in firewall and VPN products from all major vendors and can help you integrate Cisco technology with additional security solutions to help you build a cost-effective network infrastructure that provides a level of security and flexibility appropriate for your business. Third-party firewall and VPN support services available from Progent include:
For more information about Progent's consulting and support services for Cisco technology, call
Ransomware 24x7 Hot Line: Call 800-462-8800
Progent's Ransomware 24x7 Hot Line is designed to help organizations to carry out the time-critical first steps in mitigating a ransomware assault by putting out the fire. Progent's online ransomware expert can assist you to locate and isolate infected servers and endpoints and guard clean resources from being penetrated. If your system has been breached by any strain of ransomware, don't panic. Get immediate help by calling Progent's Ransomware Hot Line at 800-462-8800. For details, visit Progent's Ransomware 24x7 Hot Line.