Cisco PIX family firewalls and ASA Series firewalls combine comprehensive firewall, intrusion protection, and VPN technologies in an economical, single-cabinet format. Both product lines have been superseded by Cisco's ASA 5500-X series of security appliances with Firepower. (See integration and troubleshooting support for ASA 5500-X firewalls with Firepower Services.) Nevertheless, both PIX and first-generation Cisco ASA 5500 model firewalls are extensively used and continue to provide small and mid-size companies a reliable security solution.
Cisco PIC and legacy ASA 5500 firewalls offer powerful client and application policy enforcement, mutlivector assault defense, and safe connectivity services. The increased intelligence sharing of integrated security services in a single package provides customers deploying these aggregated firewalls the advantages of advanced security, reduced cost of ownership, and smaller management costs.
Cisco PIX security appliances and the ASA 5500 family join Cisco IOS Firewall, the FWSM for Catalyst 6500 Series switches, and 7600 routers as components of Cisco's versatile, self-contained firewall line. Based on a scalable, modular approach, every offering is designed with a particular array of options to provide better protection to a variety of networking environments. These products can be independently deployed to protect certain facets of the connectivity environment, or can be combined for a systematic, protection-in-depth strategy based on the design leading practices described in Cisco's SAFE framework. Completing the integrated firewall product line, Cisco provides a comprehensive security management catalog, ranging from Cisco security device and Cisco IOS security features and embedded appliance managers, to self-contained management utilities, moving to ensure that businesses can productively manage their Cisco security solution purchases.
Cisco PIX Security Appliance Series
PIX firewalls deliver robust user and application policy enforcement, multivector attack defense, and safe networking features in economical, out-of-the-box solutions. These specialized devices provide a wealth of integrated protection and networking services such as process-aware firewall features, Voice over IP (VoIP) and multimedia protection, robust multi-site and remote-connectivity IP Security (IPsec) Virtual Private Network connectivity, high availability, intelligent networking services, and flexible management options. The Cisco PIX Security Appliance Series product line spans compact plug-and-play devices for small offices or home offices to modular gigabit appliances with investment protection for large business and ISP environments, PIX firewalls provide dependable security, performance, and reliability for network environments of any size.
Built upon a tested, purpose-built operating system that delivers rich security features, PIX security appliances provide a high level of security and have earned Common Criteria Evaluation Assurance Level (EAL) 4 status and ICSA Labs Firewall and IP Security certification. Cisco PIX security appliances provide protection for a wide array of VoIP and additional mixed-media conventions such as H.323 v. 4, Session Initiation Protocol (SIP), SCCP, RTSP, and MGCP, enabling organizations to protect deployments of a wide range of contemporary and upcoming Voice over IP and mixed-media applications.
PIX firewall appliances offer a variety of setup, tracking, and troubleshooting features, giving IT managers the versatility to utilize the methods that best meet their needs. Administrative options include common, policy-based management tools, integrated web-accessible management, and compatibility with remote-monitoring protocols such as SNMP and syslog. The integrated Cisco Adaptive Security Device Manager (ASDM) system offers a powerful web-accessible management platform that significantly simplifies the installation, ongoing modification, and tracking of a specific PIX security appliance without the need of any extra software beyond a standard browser and Java applet to be installed on an administrator's PC.
Administrators can furthermore remotely set up, track, and analyze Cisco PIX firewalls via a CLI interface. Secure command-line interface access is available through a number of methods such as Secure Shell Protocol, Telnet through IPsec, and out-of-band via a console port. PIX firewall appliances also have robust auto-update features, a collection of protected remote-administration options that ensure security configurations and software images are always up to date.
Cisco Adaptive Security Appliances (ASA) Firewalls
Cisco ASA 5500 Series Firewalls are purpose-built solutions that bring together advanced, best-of-breed security and VPN services with a flexible architecture. The end product is a robust, versatile network security appliance better suited to defend small and midsize business and larger networks and, simultaneously, lower the overall deployment and maintenance expenses previously required for this high degree of security.
Cisco ASA firewalls deliver robust application protection through smart, application-aware inspection engines that analyze traffic at Layers 4-7. The result is a more secure network covering web, voice, and mobile wireless access. To protect environments from application-layer attacks and to give organizations greater policing of the programs and protocols used in their networks, Cisco's inspection engines integrate broad application and protocol knowledgebases and employ security enforcement solutions that include anomaly sensing and state tracking. Also included are assault sensing and mitigation technology such as application and protocol command filtering and content verification. Cisco Adaptive Security Appliances firewall inspection engines also deliver management of instant messaging and tunneling applications, enabling organizations to enforce usage policies and recover bandwidth for important business processes.
While increasing network protection, Cisco Adaptive Security Appliances firewalls also lower deployment and operational costs. By providing broad VPN and security functions, the Cisco Adaptive Security Appliances (ASA) firewall can be a single device for a multitude of uses, enabling product standardization. The Cisco Adaptive Security Appliances firewall can be deployed as a converged attack-protection appliance at a central location by leveraging its access control, process inspection, and malicious assault mitigation capabilities. The Cisco Adaptive Security Appliances firewall can also be deployed as a specialized remote connectivity solution using its VPN features. As another option, the Cisco Adaptive Security Appliances firewall serves equally well in the network interior for inter-office connectivity management and to guard against malware internal users might unknowingly release into the environment. For small business and satellite office networks, the Cisco ASA 5500 Series firewall acts as a total solution device offering complete intrusion defense and Virtual Private Network functionality while suiting the budgets and performance demands of such deployments.
This versatile one-device, multiple-use approach minimizes the number of devices that need to be deployed and maintained while offering a standard functional and administrative environment throughout all deployments. This approach streamlines the training of setup, monitoring, troubleshooting, and security personnel. To further minimize operations costs, Cisco ASA 5500 Series firewalls are also exceptionally network aware, allowing them to integrate gracefully into the network without disrupting authorized traffic and applications.
How Progent's Cisco Certified Experts Can Help You with Cisco PIX and ASA Firewalls
Cisco ASA 5500 Series firewalls and PIX family firewalls incorporate a wealth of configuration, monitoring, and analysis options which offer you the ability to configure these firewalls to align optimally with your business requirements. Progent's CCIE certified network consultants can assist you to maintain your current infrastructure that includes Cisco ASA or PIX security appliances and that provides protection, fault tolerance, performance, and manageability. Progent's firewall experts can also assist your organization to migrate to Cisco ASA 5500-X firewalls with Firepower Services.
Progent's GISA and CISM-premier IS security experts can help you to develop a security policy that makes sense for your environment and can set up your firewall to enforce your security strategy. Progent's risk assessment consultants can assess the effectiveness of your current firewall deployment and help determine the overall security of your whole information system environment. Progent's Help Desk Call Center can provide emergency remote technical support for Cisco technology and can give you fast access to a Cisco expert.
For additional information about Progent's professional help for Cisco products, choose a subject: