Cisco PIX firewalls and Cisco ASA 5500 Series firewalls combine next-generation firewall, intrusion protection, and VPN features in an affordable, single-box package. Both product lines have been replaced by Cisco's ASA 5500-X line of security appliances with Firepower. (Refer to integration and troubleshooting expertise for Cisco AA 5500-X firewalls with Firepower Services.) Still, PIX and earlier-generation Cisco ASA 5500 model firewalls are extensively used and continue to provide small and mid-size companies a viable firewall environment.
PIX and legacy ASA 5500 firewalls offer robust client and application policy enforcement, mutlivector assault defense, and secure connectivity features. The increased knowledge sharing of consolidated protection features in a single package offers users implementing these integrated firewalls the advantages of enhanced protection, reduced cost of ownership, and minimal management expense.
Cisco PIX firewalls and Cisco's ASA 5500 Series combine with Cisco IOS Firewall, the Firewall Services Module for Catalyst 6500 family switches, and Cisco 7600 Series routers as parts of Cisco's flexible, self-contained firewall line. Based on an expandable, modular platform, each offering is designed with a specific feature set to provide more efficient security to different networking situations. These products can be individually deployed to protect certain facets of a connectivity infrastructure, or can be combined for a layered, protection-in-depth strategy based on the design leading practices described in the Cisco SAFE Blueprint. Completing the integrated firewall product line, Cisco provides a comprehensive security management offering, spanning Cisco security appliance and Cisco IOS Software security components and built-in appliance controllers, to standalone management utilities, helping to ensure that businesses can effectively manage their Cisco protection infrastructure investments.
PIX Firewall Appliances
PIX firewalls deliver robust policy support, multivector invasion protection, and secure connectivity services in economical, simple-to-configure modules. These specialized devices provide a wealth of built-in protection and networking capabilities such as process-aware firewall services, VoIP and multimedia security, reliable multi-site and remote-access IPcec Virtual Private Network (VPN) networking, excellent resiliency, intelligent networking features, and flexible management options. The PIX firewall product line spans small plug-and-play desktop units for small offices or home offices to stackable gigabit appliances with ROI for enterprise and service-provider customers, Cisco PIX Security Appliance Series provide high levels of protection, speed, and availability for network environments of all sizes.

Based around a hardened, specialized software platform that offers a wealth of security features, Cisco PIX security appliances provide excellent protection and have received EAL 4 status and ICSA Labs Firewall and IP Security (IPsec) certification. PIX security appliances offer security for a broad range of Voice over IP and other mixed-media conventions including H.323 Version 4, Session Initiation Protocol, SCCP, RTSP, and MGCP, enabling businesses to safeguard installations of a wide array of contemporary and next-generation IP voice and multimedia applications.
Cisco PIX firewalls offer a variety of setup, monitoring, and troubleshooting options, giving businesses the flexibility to use the methods that best match their needs. Administrative solutions include common, policy-based management tools, integrated web-based management, and compatibility with remote-tracking protocols such as Simple Network Management Protocol and syslog. The integrated ASDM system offers a powerful web-accessible management solution that greatly simplifies the deployment, ongoing configuration, and tracking of a specific PIX firewall appliance without the need of any additional software beyond a standard browser and Java plug-in to be installed on an administrator's computer.
Administrators can also remotely set up, monitor, and troubleshoot Cisco PIX firewall appliances via a command-line interface. Safe command-line interface communication is possible using several techniques including SSHv2 Protocol, Telnet through IP Security (IPsec), and out-of-band via a console port. PIX security appliances also include robust auto-update features, a set of secure remote-management options that ensure firewall configurations and software images are always up to date.
Cisco Adaptive Security Appliances 5500 Series Firewalls
Cisco ASA Firewalls are purpose-built devices that incorporate advanced, industry-leading security and VPN support with an adaptive architecture. The result is a powerful, multifunction network security appliance better suited to defend small and midsize company and larger networks and, at the same time, reduce the total installation and maintenance expenses previously required for this enhanced level of security.

Cisco Adaptive Security Appliances (ASA) 5500 Series firewalls deliver a high-level of application protection via intelligent, application-aware inspection processes that analyze traffic at Layers 4-7. This results in a safer network covering web, voice, and mobile wireless access. To defend networks from application-layer attacks and to offer businesses greater policing of the applications and protocols utilized in their networks, these inspection engines incorporate extensive application and protocol knowledge and employ protection enforcement solutions such as anomaly detection and state tracking. Also included are assault sensing and mitigation techniques including application and protocol command filtering and URL deobfuscation. Cisco Adaptive Security Appliances (ASA) 5500 Series firewall inspection engines also deliver control over IM and tunneling applications, allowing organizations to police usage policies and preserve bandwidth for critical business processes.
At the same time as improving network security, Cisco Adaptive Security Appliances 5500 Series firewalls also decrease installation and support expenses. By providing broad Virtual Private Network and protection services, the Cisco ASA 5500 Series firewall can be a single device for a multitude of uses, allowing platform commonality. The Cisco ASA 5500 Series firewall can be used as a converged threat-protection appliance at the datacenter by taking advantage of its connectivity control, application inspection, and malicious assault mitigation capabilities. The Cisco Adaptive Security Appliances (ASA) firewall can also be used as a specialized remote connectivity device using its Virtual Private Network capabilities. As another option, the Cisco ASA firewall operates equally well inside the network for interdepartmental connectivity control and to guard against malicious assaults inside users might inadvertently introduce into the environment. For small business and branch office environments, the Cisco Adaptive Security Appliances firewall serves as a total solution platform providing complete intrusion defense and Virtual Private Network services while fitting within the cost structure and operational demands of such deployments.
This adaptive one-device, multiple-solution approach reduces the number of appliances that need to be installed and managed while offering a standard operating and administrative system throughout all deployments. This architecture streamlines the education of configuration, tracking, troubleshooting, and protection staff. To further reduce maintenance costs, Cisco ASA firewalls are also highly network conscious, enabling them to insert gracefully into the environment without disrupting legitimate data flow and applications.
How Progent's Cisco Certified Experts Can Help You with Cisco PIX and ASA Security Appliances
Cisco's ASA 5500 Series firewalls and PIX family security appliances incorporate a wealth of configuration, tracking, and troubleshooting options which give you the ability to configure these security appliances to align optimally with your company's requirements. Progent's CCIE certified network professionals can show you how to maintain your existing network infrastructure that includes Cisco ASA or PIX security appliances and that offers protection, fault tolerance, throughput, and recoverability. Progent can also help you to upgrade to ASA 5500-X firewalls with Firepower Services.
Progent's CISA and CISM-certified information security experts can assist you to develop a security policy that makes sense for your environment and can configure your PIX or ASA firewall to support your security policies. Progent's risk assessment engineers can evaluate the effectiveness of your existing firewall deployment and validate the security of your entire IT network. Progent's Technical Response Center can provide urgent remote troubleshooting for Cisco technology and can give you fast access to a Cisco network engineer.
To see additional details about Progent's engineering support for Cisco products, choose a topic: