Cisco's PIX family firewalls and Cisco ASA 5500 Series adaptive security appliances combine comprehensive firewall, intrusion protection, and Virtual Private Network functionality in an economical, single-cabinet package. Both product families have been superseded by the ASA 5500-X family of security appliances with Firepower. (See integration and debugging support for ASA 5500-X firewalls with Firepower Services.) Still, PIX and first-generation Cisco ASA 5500 model adaptive security appliances are extensively used and continue to deliver small and mid-size companies a viable security solution.
PIX and the original ASA 5500 firewalls deliver powerful client and application policy enforcement, mutlivector attack defense, and secure access services. The enhanced intelligence sharing of integrated security features in a single platform provides customers deploying these integrated firewalls the benefits of enhanced protection, lower cost of ownership, and minimal maintenance costs.
PIX security appliances and Cisco's ASA 5500 Series join IOS Firewall, the Firewall Services Module (FWSM) for Catalyst 6500 switches, and 7600 routers as parts of Cisco's flexible, integrated firewall line. Based on a scalable, building-block platform, each offering is designed with a particular array of options to provide better protection to different network situations. These products can be individually installed to protect specific facets of the connectivity infrastructure, or can be grouped for a layered, protection-in-depth approach based on the architecture leading practices outlined in the Cisco SAFE Blueprint. Completing the modular firewall product line, Cisco has developed a complete security management portfolio, spanning Cisco security device and IOS security features and built-in appliance controllers, to self-contained management utilities, helping to ensure that customers can productively use their Cisco security infrastructure purchases.
PIX Firewalls
Cisco PIX firewall appliances deliver reliable user and application policy support, multivector attack protection, and safe connectivity features in economical, simple-to-configure solutions. These specialized appliances provide a wealth of built-in protection and connectivity capabilities such as application-aware firewall features, VoIP and multimedia security, reliable multi-location and remote-connectivity IPcec VPN networking, high availability, smart networking features, and flexible administration options. The Cisco PIX firewall product line ranges from small plug-and-go desktop units for small offices and home offices to modular gigabit products with investment protection for large business and ISP customers, Cisco PIX firewalls provide dependable protection, speed, and reliability for network environments of all sizes.

Based upon a tested, purpose-built operating system that delivers rich security features, Cisco PIX firewalls provide excellent security and have earned Common Criteria Evaluation Assurance Level 4 status and ICSA Labs Firewall and IP Security certification. PIX firewall appliances provide protection for a broad range of VoIP and additional multimedia standards such as H.323 v. 4, SIP, Cisco Skinny Client Control Protocol (SCCP), Real-Time Streaming Protocol, and MGCP, helping businesses to protect installations of a wide array of current and upcoming IP voice and mixed-media applications.
PIX security appliances offer a wealth of setup, tracking, and analysis options, providing businesses the versatility to use the methods that most closely meet their needs. Management solutions include centralized, policy-based management utilities, integrated web-accessible management, and compatibility with remote-monitoring protocols such as Simple Network Management Protocol (SNMP) and syslog. The integrated ASDM system provides a world-class web-accessible control solution that greatly simplifies the installation, in-place configuration, and tracking of a specific PIX firewall without requiring any extra utility beyond an ordinary browser and Java applet to be installed on a manager's computer.
IT managers can furthermore remotely set up, monitor, and analyze Cisco PIX security appliances via a command-line interface (CLI). Safe command-line interface (CLI) access is possible through a number of methods including SSHv2 Protocol, Telnet over IP Security (IPsec), and out-of-band via a console port. PIX firewall appliances also have dependable auto-update features, a collection advanced protected remote-management options that ensure firewall configurations and software images are always up to date.
Cisco Adaptive Security Appliances (ASA) Firewalls
Cisco Adaptive Security Appliances 5500 Series Firewalls are purpose-built devices that incorporate market-proven, industry-leading security and VPN services plus an adaptive architecture. The result is a robust, multifunction network protection solution better suited to protect small and medium company and larger networks and, simultaneously, lower the total deployment and operations costs previously associated with this enhanced level of security.

Cisco Adaptive Security Appliances firewalls provide strong application protection via intelligent, application-sensitive inspection processes that examine traffic at Layers 4-7. This results in a more secure network covering web, voice, and mobile wireless access. To defend networks against application-layer attacks and to offer businesses more policing of the programs and protocols utilized in their environments, these inspection engines incorporate broad application and protocol knowledgebases and rely on security enforcement solutions such as anomaly sensing and state monitoring. Also incorporated are attack sensing and mitigation techniques such as application/protocol command filters and content verification. Cisco Adaptive Security Appliances (ASA) 5500 Series firewall inspection engines also deliver control over IM and peer-to-peer file sharing, enabling organizations to enforce usage policies and free up bandwidth for critical business processes.
While increasing security, Cisco Adaptive Security Appliances (ASA) firewalls also lower installation and operational expenses. By offering broad VPN and protection functions, the Cisco Adaptive Security Appliances 5500 Series firewall can be a the only platform for a multitude of environments, enabling platform standardization. The Cisco Adaptive Security Appliances firewall can be deployed as a converged attack-prevention appliance at the datacenter by leveraging its access control, application inspection, and malware remediation capabilities. The Cisco Adaptive Security Appliances (ASA) 5500 Series firewall can also be used as a dedicated remote connectivity solution utilizing its Virtual Private Network capabilities. Alternatively, the Cisco Adaptive Security Appliances 5500 Series firewall operates equally well inside the network for interdepartmental access control and to guard against malware internal workers might unwittingly introduce into the network. For small business and satellite office networks, the Cisco ASA 5500 Series firewall serves as an all-in-one platform offering complete intrusion defense and Virtual Private Network services while fitting within the budgets and operational demands of such situations.
This adaptive one-device, multiple-solution design minimizes the total number of appliances that must be installed and managed while offering a common functional and administrative system across all those installations. This approach streamlines the education of setup, tracking, support, and protection staff. To further minimize maintenance costs, Cisco Adaptive Security Appliances firewalls are also exceptionally network conscious, enabling them to integrate gracefully into the network without interfering with authorized traffic and applications.
How Progent Can Help You with Cisco PIX and ASA Firewalls
Cisco's ASA Series firewalls and PIX firewalls provide a wealth of setup, tracking, and troubleshooting features that give you the flexibility to deploy these firewalls to align optimally with your business requirements. Progent's CCIE authorized network consultants can help you to maintain your current network infrastructure that incorporates Cisco ASA and/or PIX security appliances and that offers security, fault tolerance, performance, and manageability. Progent's firewall experts can also assist your organization to migrate to ASA 5500-X firewalls with Firepower Services.
Progent's CISA and CISSP-ISSP-premier IS security experts can help your business to develop a security strategy appropriate for your situation and can configure your firewall to enforce your security policies. Progent's risk assessment experts can assess the effectiveness of your current firewall deployment and validate the overall security of your whole IT network. Progent's Help Desk Call Center can provide urgent online troubleshooting for Cisco technology and can give you fast access to a Cisco CCIE expert.
To learn more information concerning Progent's consulting help for Cisco products, select a topic: