Cisco PIX security appliances and Cisco ASA Series firewalls integrate comprehensive firewall, intrusion protection, and Virtual Private Network functionality in an economical, one-cabinet format. Both of these product lines have been replaced by Cisco's ASA 5500-X line of security appliances with Firepower Services. (Refer to integration and debugging help with Cisco AA 5500-X firewalls with Firepower Services.) Still, both PIX and previous-generation ASA 5500 model adaptive security appliances are extensively used and continue to deliver small and mid-size companies a viable firewall solution.
Cisco PIC and the original ASA 5500 firewalls offer powerful client and application policy enforcement, mutlivector attack protection, and safe connectivity features. The increased knowledge sharing of consolidated security services in a single platform offers customers implementing these integrated firewalls the benefits of advanced protection, lower TCO, and smaller maintenance costs.
PIX firewalls and Cisco's ASA 5500 Series join Cisco IOS Firewall, the Firewall Services Module for Catalyst 6500 Series switches, and Cisco 7600 Series routers as components of Cisco's flexible, integrated firewall line. Based on a scalable, modular approach, each device is designed with a particular feature set to deliver more efficient security to different network environments. These products can be independently deployed to secure certain facets of a connectivity environment, or can be combined for a layered, protection-in-depth approach based on the architecture leading practices described in the Cisco SAFE framework. Rounding out the modular firewall product line, Cisco provides a comprehensive security management catalog, spanning Cisco security appliance and IOS Software security features and built-in device managers, to self-contained management applications, moving to make sure that customers can effectively use their Cisco protection solution purchases.
PIX Security Appliance Series
PIX firewalls deliver robust policy enforcement, multivector attack defense, and safe connectivity features in affordable, out-of-the-box solutions. These specialized appliances offer a wealth of integrated protection and networking services including application-aware firewall services, VoIP and multimedia protection, reliable site-to-site and remote-access IPcec Virtual Private Network networking, fault tolerance, intelligent networking features, and versatile administration options. The PIX Security Appliance Series family ranges from small plug-and-play appliances for small or at home offices to stackable gigabit appliances with investment protection for large business and ISP customers, PIX firewalls provide dependable security, speed, and availability for environments of all sizes.

Built upon a tested, purpose-built operating system that offers rich security services, PIX firewall appliances provide excellent protection and have earned EAL 4 status and ICSA Labs Firewall and IP Security qualification. PIX firewall appliances offer protection for a broad array of VoIP and additional mixed-media conventions such as H.323 Version 4, Session Initiation Protocol (SIP), Cisco Skinny Client Control Protocol (SCCP), RTSP, and Media Gateway Control Protocol, enabling businesses to safeguard deployments of a wide range of contemporary and next-generation Voice over IP and multimedia applications.
PIX firewall appliances feature a wealth of configuration, tracking, and analysis features, giving businesses the flexibility to utilize the methods that most closely match their requirements. Administrative options include centralized, policy-based administration utilities, integrated web-based administration, and support for remote-tracking standards such as Simple Network Management Protocol (SNMP) and syslog. The integrated ASDM interface offers a world-class web-based control solution that significantly streamlines the deployment, in-place configuration, and monitoring of a specific PIX security appliance without requiring any additional utility other than a standard browser and Java applet to be running on a manager's computer.
Administrators can also remotely configure, monitor, and troubleshoot PIX firewalls via a command-line interface (CLI). Secure CLI interface access is possible using several methods including SSHv2 Protocol, Telnet over IP Security, and out-of-band through a console port. Cisco PIX firewall appliances also have dependable automatic-update capabilities, a collection of protected remote-management options that ensure security settings and software images are always current.
Cisco Adaptive Security Appliances 5500 Series Firewalls
Cisco Adaptive Security Appliances (ASA) 5500 Series Firewalls are specially engineered solutions that incorporate advanced, best-of-breed protection and VPN services with an adaptive design. The result is a robust, multifunction network security solution better suited to protect small and medium business (SMB) and larger networks and, at the same time, reduce the total deployment and operations costs formerly associated with this high degree of protection.

Cisco ASA firewalls provide strong application protection via intelligent, application-sensitive inspection processes that examine traffic at Layers 4-7. This results in a better protected network covering web, voice, and mobile wireless connectivity. To protect environments from application-layer attacks and to give organizations more control over the programs and protocols utilized in their networks, these inspection engines integrate extensive application and protocol knowledgebases and rely on protection enforcement solutions that include protocol anomaly detection and state monitoring. Also incorporated are assault detection and mitigation techniques such as application/protocol command filtering and URL deobfuscation. Cisco Adaptive Security Appliances 5500 Series firewall inspection engines also provide control over instant messaging and tunneling applications, enabling businesses to police usage policies and conserve network bandwidth for important business applications.
While improving network protection, Cisco ASA firewalls also decrease deployment and operational costs. By providing extensive VPN and protection services, the Cisco Adaptive Security Appliances 5500 Series firewall can be a single device for many uses, allowing product commonality. The Cisco Adaptive Security Appliances firewall can be used as a converged threat-prevention appliance at a central location by leveraging its access control, process inspection, and worm, virus, and other malware remediation technologies. The Cisco Adaptive Security Appliances (ASA) firewall can also be deployed as a dedicated remote access device using its Virtual Private Network features. As another option, the Cisco Adaptive Security Appliances firewall performs equally well in the network interior for interdepartmental access management and to guard against malicious assaults inside users may unwittingly introduce into the environment. For small company and satellite office networks, the Cisco ASA firewall acts as an all-in-one device offering comprehensive intrusion prevention and Virtual Private Network functionality while suiting the budgets and performance demands of such deployments.
This adaptive one-device, many-use design reduces the number of devices that must be deployed and managed while offering a common operating and administrative system across all those deployments. This approach streamlines the education of configuration, monitoring, support, and security personnel. To further reduce maintenance costs, Cisco Adaptive Security Appliances (ASA) 5500 Series firewalls are also highly network conscious, allowing them to insert gracefully into the environment without disrupting legitimate traffic and processes.
How Progent Can Assist You with Cisco Firewalls
Cisco ASA Series firewalls and PIX security appliances provide an array of setup, tracking, and troubleshooting features which give you the flexibility to set up these security appliances to match your company's requirements. Progent's CCIE authorized network experts can assist you to maintain your existing network infrastructure that includes Cisco ASA or PIX firewall technology and that offers security, resilience, throughput, and manageability. Progent's firewall experts can also help your organization to migrate to ASA 5500-X firewalls with Firepower Services.
Progent's CISA and CISM-premier IS security professionals can help your business to create a security strategy appropriate for your environment and can set up your firewall to support your security policies. Progent's risk evaluation professionals can evaluate the strength of your current firewall deployment and audit the security of your entire information system network. Progent's Help Desk support team can deliver emergency remote troubleshooting for Cisco products and can give you fast access to a Cisco expert.
To learn additional details concerning Progent's consulting support for Cisco technology, choose a subject: