Cisco PIX family firewalls and ASA Series adaptive security appliances combine comprehensive firewall, intrusion protection, and Virtual Private Network (VPN) functionality in an affordable, one-cabinet package. Both of these product lines have been superseded by Cisco's ASA 5500-X line of firewalls with Firepower Services. (See configuration and debugging expertise for ASA 5500-X firewalls with Firepower Services.) Still, both PIX and first-generation ASA 5500 Series adaptive security appliances are widely used and continue to offer small and mid-size organizations a reliable security environment.
Cisco PIC and the original ASA 5500 firewalls offer powerful user and application policy enforcement, mutlivector assault defense, and safe connectivity services. The increased knowledge sharing of consolidated protection services in a stand-alone package provides customers implementing these integrated solutions the benefits of enhanced protection, reduced cost of ownership, and smaller maintenance expense.
Cisco PIX firewalls and Cisco's ASA 5500 Series join IOS Firewall, the Firewall Services Module for Catalyst 6500 Series switches, and Cisco 7600 Series routers as parts of Cisco's versatile, integrated firewall solutions. Based on an expandable, building-block platform, each device is designed with a particular feature set to provide more efficient security to different networking environments. These solutions can be individually installed to protect specific facets of the connectivity infrastructure, or can be grouped for a layered, protection-in-depth approach following the design leading practices outlined in the Cisco SAFE framework. Completing the modular firewall solutions, Cisco has developed a comprehensive security management portfolio, ranging from Cisco security device and Cisco IOS security components and built-in appliance controllers, to standalone management programs, helping to ensure that customers can effectively use their Cisco security infrastructure investments.
Cisco PIX Security Appliance Series
Cisco PIX Security Appliance Series deliver reliable policy support, multi-source attack defense, and safe networking features in economical, easy-to-deploy solutions. These specialized devices offer a broad range of integrated protection and networking capabilities such as process-aware firewall services, Voice over IP and multimedia security, robust site-to-site and remote-connectivity IPcec VPN networking, high availability, smart networking services, and versatile administration solutions. The Cisco PIX firewall product line ranges from small plug-and-play appliances for small or at home offices to stackable gigabit products with investment protection for large business and ISP environments, Cisco PIX firewalls provide high levels of security, performance, and reliability for networks of all sizes.

Built upon a tested, purpose-built OS that offers a wealth of protection services, PIX security appliances provide a high level of security and have earned Common Criteria Evaluation Assurance Level (EAL) 4 status and ICSA Labs Firewall and IPsec certification. Cisco PIX security appliances provide protection for a broad range of Voice over IP and additional mixed-media standards including H.323 Version 4, Session Initiation Protocol (SIP), Cisco Skinny Client Control Protocol, Real-Time Streaming Protocol, and MGCP, enabling organizations to safeguard deployments of a wide array of contemporary and upcoming Voice over IP and mixed-media applications.
PIX firewalls offer a variety of configuration, tracking, and troubleshooting options, giving businesses the versatility to use the techniques that most closely meet their requirements. Management options include common, policy-based administration tools, integrated web-based administration, and support for remote-tracking protocols such as Simple Network Management Protocol and syslog. The integrated Adaptive Security Device Manager interface provides a world-class web-accessible control platform that greatly simplifies the deployment, ongoing modification, and monitoring of a single Cisco PIX security appliance without requiring any additional software other than an ordinary web browser and Java plug-in to be running on an administrator's computer.
IT managers can also remotely configure, monitor, and troubleshoot PIX firewalls via a command-line interface. Secure CLI interface communication is available using a number of methods such as Secure Shell (SSHv2) Protocol, Telnet through IPsec, and out-of-band via a console port. Cisco PIX firewalls also include dependable auto-update capabilities, a set advanced protected remote-management services that make sure that firewall configurations and software images are kept current.
Cisco Adaptive Security Appliances Firewalls
Cisco Adaptive Security Appliances (ASA) 5500 Series Firewalls are purpose-built devices that incorporate market-proven, best-of-breed security and VPN support with an adaptive architecture. The result is a robust, versatile network security solution better suited to defend small and medium company and larger networks and, simultaneously, lower the overall installation and operations expenses previously associated with this enhanced level of security.

Cisco ASA firewalls provide strong application security through smart, application-aware inspection processes that analyze traffic at Layers 4-7. This results in a more secure environment including web, voice, and mobile wireless access. To protect environments from application-layer attacks and to give organizations more control over the applications and protocols utilized in their networks, Cisco's inspection engines incorporate extensive application and protocol knowledge and employ protection enforcement technologies such as protocol anomaly detection and state monitoring. Also included are attack detection and remediation techniques including application and protocol command filtering and URL deobfuscation. Cisco Adaptive Security Appliances 5500 Series firewall inspection engines also deliver control over IM and tunneling applications, enabling businesses to police usage policies and recover network bandwidth for critical business applications.
At the same time as increasing network security, Cisco ASA firewalls also lower installation and support costs. By providing extensive VPN and protection services, the Cisco ASA 5500 Series firewall can be used as the single device for many uses, allowing product standardization. The Cisco Adaptive Security Appliances 5500 Series firewall can be deployed as a consolidated threat-protection appliance at the datacenter by leveraging its connectivity control, process inspection, and malicious assault remediation capabilities. The Cisco Adaptive Security Appliances (ASA) firewall can also be deployed as a specialized remote connectivity device using its VPN features. Alternatively, the Cisco Adaptive Security Appliances (ASA) firewall performs equally well in the network interior for inter-office access control and to guard against malware inside users might unwittingly release into the network. In small company and satellite office networks, the Cisco Adaptive Security Appliances firewall serves as a total solution platform offering complete intrusion defense and VPN services while suiting the cost structure and operational demands of these deployments.
This versatile single-platform, many-use design reduces the number of devices that must be deployed and managed while providing a standard operating and management environment throughout all those installations. This approach streamlines the education of setup, tracking, support, and security personnel. To further reduce maintenance expenses, Cisco ASA 5500 Series firewalls are also highly network aware, allowing these devices to integrate gracefully into the environment without interfering with legitimate data flow and applications.
How Progent's Consultants Can Help Your Business with Cisco Firewalls
Cisco's ASA Series firewalls and PIX firewalls provide a wealth of setup, monitoring, and analysis options that give you the ability to set up these security appliances to align optimally with your company's requirements. Progent's CCIE certified network experts can help you to maintain your current network infrastructure that incorporates Cisco ASA and/or PIX security appliances and that offers security, resilience, throughput, and manageability. Progent's firewall experts can also help you to migrate to Cisco ASA 5500-X firewalls with Firepower Services.
Progent's CISA and CISSP-ISSP-certified information security professionals can help your business to create a security policy that makes sense for your environment and can configure your firewall to support your security strategy. Progent's risk assessment engineers can evaluate the strength of your existing firewall deployment and help determine the overall security of your whole IS environment. Progent's Help Desk support team can deliver emergency online technical support for Cisco products and can give you fast access to a Cisco CCIE network engineer.
To see additional information concerning Progent's engineering support for Cisco products, pick a topic: