Cisco's PIX family firewalls and ASA 5500 Series adaptive security appliances combine next-generation firewall, intrusion protection, and Virtual Private Network technologies in an economical, single-box package. Both of these product lines have been replaced by the ASA 5500-X series of security appliances with Firepower Services. (See integration and troubleshooting help with Cisco AA 5500-X firewalls with Firepower Services.) Nevertheless, both PIX and previous-generation Cisco ASA 5500 model firewalls are extensively used and continue to provide small and mid-size companies a viable security solution.
PIX and legacy ASA 5500 firewalls offer powerful user and application policy enforcement, mutlivector attack defense, and safe connectivity services. The enhanced intelligence sharing of consolidated protection services in a single platform provides users implementing these aggregated solutions the advantages of enhanced protection, reduced cost of ownership, and smaller management expense.
PIX security appliances and the ASA 5500 family join Cisco IOS Firewall, the FWSM for Catalyst 6500 family switches, and Cisco 7600 Series routers as components of Cisco's flexible, self-contained firewall line. Engineered with a scalable, modular approach, each device is designed with a particular feature set to provide more efficient security to a variety of network environments. These products can be individually deployed to protect specific facets of the network environment, or can be combined for a systematic, protection-in-depth strategy based on the design best practices outlined in the Cisco SAFE Blueprint. Rounding out the modular firewall solutions, Cisco has developed a complete security management portfolio, spanning Cisco security appliance and IOS Software security components and embedded appliance controllers, to standalone management utilities, moving to make sure that businesses can productively manage their Cisco security solution investments.
PIX Firewall Appliances
PIX firewall appliances offer robust policy enforcement, multivector attack defense, and safe connectivity services in economical, simple-to-configure solutions. These purpose-built appliances provide a wealth of integrated protection and networking services including application-aware firewall services, Voice over IP and multimedia protection, robust site-to-site and remote-access IPcec Virtual Private Network (VPN) networking, fault tolerance, smart networking services, and versatile administration solutions. The PIX Security Appliance Series product line ranges from small plug-and-go devices for small offices or home offices to stackable high-bandwidth appliances with ROI for large business and ISP environments, PIX Security Appliance Series provide high levels of security, speed, and reliability for network environments of all sizes.

Based around a tested, specialized OS that delivers a wealth of security services, Cisco PIX security appliances offer excellent protection and have earned EAL 4 status and ICSA Labs Firewall and IP Security qualification. PIX firewall appliances provide security for a broad array of VoIP and additional mixed-media standards including H.323 v. 4, Session Initiation Protocol, Cisco Skinny Client Control Protocol (SCCP), RTSP, and Media Gateway Control Protocol, enabling businesses to protect installations of a wide range of contemporary and next-generation IP voice and mixed-media applications.
Cisco PIX firewall appliances offer a wealth of setup, monitoring, and troubleshooting features, providing businesses the flexibility to utilize the methods that best meet their needs. Administrative solutions include centralized, policy-based management utilities, integrated web-accessible management, and support for remote-tracking protocols like SNMP and syslog. The integrated Adaptive Security Device Manager system offers a world-class web-based control solution that significantly simplifies the installation, ongoing modification, and tracking of a specific Cisco PIX firewall without requiring any extra utility beyond an ordinary web browser and Java applet to be running on an administrator's computer.
IT managers can also remotely configure, track, and troubleshoot Cisco PIX firewall appliances via a command-line interface (CLI). Safe command-line interface (CLI) access is possible through a number of methods including Secure Shell (SSHv2) Protocol, Telnet over IP Security, and out-of-band through a console port. Cisco PIX firewall appliances also include dependable automatic-update capabilities, a collection of secure remote-management services that ensure firewall settings and software images are kept current.
Cisco Adaptive Security Appliances (ASA) 5500 Series Firewalls
Cisco ASA 5500 Series Firewalls are specially engineered solutions that bring together market-proven, industry-leading protection and Virtual Private Network services with an adaptive design. The end product is a robust, multifunction network security appliance better suited to defend small and medium company and larger networks and, at the same time, reduce the overall deployment and operations costs formerly associated with this high level of protection.

Cisco Adaptive Security Appliances 5500 Series firewalls provide strong application protection via intelligent, application-sensitive inspection processes that analyze network flows at Layers 4-7. This results in a better protected network covering web, voice, and mobile wireless connectivity. To protect environments against application-layer attacks and to give organizations greater policing of the programs and protocols used in their networks, these inspection engines integrate extensive application and protocol knowledgebases and employ security enforcement technologies that include protocol anomaly detection and state tracking. Also incorporated are assault detection and remediation technology such as application and protocol command filtering and content verification. Cisco Adaptive Security Appliances 5500 Series firewall inspection engines also provide management of IM and peer-to-peer file sharing, enabling businesses to police usage policies and recover bandwidth for important business processes.
At the same time as increasing security, Cisco Adaptive Security Appliances (ASA) 5500 Series firewalls also decrease deployment and support expenses. By offering broad Virtual Private Network and security functions, the Cisco Adaptive Security Appliances (ASA) 5500 Series firewall can be used as the single device for many environments, allowing platform standardization. The Cisco Adaptive Security Appliances 5500 Series firewall can be used as a consolidated threat-protection device at the datacenter by leveraging its access control, process inspection, and malware mitigation capabilities. The Cisco Adaptive Security Appliances firewall can also be deployed as a dedicated remote access solution using its Virtual Private Network features. As an alternative, the Cisco ASA firewall operates capably inside the network for interdepartmental access management and to defend against malicious assaults internal workers might inadvertently release into the network. For small company and satellite office networks, the Cisco Adaptive Security Appliances (ASA) 5500 Series firewall acts as an all-in-one platform offering complete intrusion defense and Virtual Private Network services while suiting the cost structure and performance demands of these situations.
This versatile one-device, many-solution design reduces the total number of appliances that must be installed and managed while offering a common operating and management system throughout all those installations. This architecture streamlines the education of configuration, tracking, troubleshooting, and security staff. To further minimize maintenance expenses, Cisco Adaptive Security Appliances (ASA) 5500 Series firewalls are also exceptionally network aware, allowing these devices to integrate gracefully into the environment without disrupting legitimate data flow and processes.
How Progent Can Help Your Business with Cisco Firewalls
Cisco ASA 5500 Series firewalls and PIX family security appliances provide an array of setup, monitoring, and troubleshooting features which offer you the ability to deploy these firewalls to match your company's needs. Progent's CCIE certified network professionals can show you how to support your existing infrastructure that includes Cisco ASA or PIX firewall technology and that provides security, resilience, throughput, and recoverability. Progent's firewall experts can also assist your organization to migrate to ASA 5500-X firewalls with Firepower Services.
Progent's GISA and CISSP-ISSP-premier information security professionals can help your business to create a security policy that makes sense for your situation and can set up your firewall to support your security policies. Progent's risk evaluation consultants can assess the effectiveness of your current firewall solution and validate the overall security of your entire information system network. Progent's Technical Response Center can deliver emergency remote technical support for Cisco technology and offer quick access to a Cisco expert.
To see additional details about Progent's consulting support for Cisco technology, choose a subject: