Cisco's PIX family firewalls and ASA 5500 Series firewalls combine comprehensive firewall, intrusion protection, and Virtual Private Network (VPN) functionality in an affordable, single-cabinet package. Both of these product lines have been superseded by Cisco's ASA 5500-X series of firewalls with Firepower Services. (Refer to configuration and debugging help with ASA 5500-X firewalls with Firepower Services.) Still, both PIX and first-generation ASA 5500 Series adaptive security appliances are extensively used and continue to provide small and mid-size organizations a reliable firewall environment.
Cisco PIC and the original ASA 5500 firewalls offer powerful user and program policy support, mutlivector assault protection, and secure connectivity features. The increased knowledge sharing of integrated protection services in a single package provides customers implementing these aggregated solutions the benefits of advanced protection, reduced cost of ownership, and smaller management costs.
Cisco PIX firewalls and Cisco's ASA 5500 family combine with IOS Firewall, the Firewall Services Module (FWSM) for Cisco Catalyst 6500 family switches, and Cisco 7600 routers as components of Cisco's versatile, integrated firewall line. Engineered with a scalable, modular approach, every offering is designed with a specific feature set to provide better protection to a variety of networking environments. These solutions can be individually installed to secure specific areas of a connectivity infrastructure, or can be grouped for a layered, defense-in-depth strategy following the design leading practices described in Cisco's SAFE Blueprint. Completing the integrated firewall solutions, Cisco provides a complete security management catalog, ranging from Cisco security appliance and Cisco IOS security components and built-in device controllers, to standalone management programs, helping to ensure that businesses can productively manage their Cisco security infrastructure investments.
Cisco PIX Firewall Appliances
PIX firewall appliances offer robust user and application policy support, multivector attack protection, and safe connectivity features in cost-effective, simple-to-configure modules. These specialized appliances offer a broad range of integrated protection and connectivity services including application-aware firewall features, Voice over IP and multimedia protection, robust multi-location and remote-access IP Security Virtual Private Network connectivity, excellent resiliency, smart networking features, and versatile administration options. The PIX firewall family spans compact plug-and-go desktop units for small and at home offices to stackable high-bandwidth appliances with ROI for enterprise and ISP customers, Cisco PIX Security Appliance Series deliver high levels of protection, performance, and availability for environments of all sizes.

Based upon a tested, specialized software platform that offers rich protection services, Cisco PIX security appliances provide excellent security and have earned Common Criteria Evaluation Assurance Level (EAL) 4 status and ICSA Firewall and IP Security qualification. PIX security appliances offer security for a broad array of VoIP and additional mixed-media standards including H.323 v. 4, Session Initiation Protocol, Cisco Skinny Client Control Protocol, RTSP, and MGCP, enabling businesses to safeguard installations of a wide range of contemporary and upcoming VoIP and mixed-media applications.
Cisco PIX firewalls offer a variety of setup, monitoring, and analysis features, providing IT managers the flexibility to use the methods that most closely meet their needs. Management options include centralized, policy-based management tools, integrated web-accessible management, and compatibility with remote-tracking standards like SNMP and syslog. The integrated ASDM interface offers a world-class web-based control solution that greatly simplifies the deployment, in-place modification, and monitoring of a specific PIX firewall without the need of any extra utility beyond an ordinary browser and Java plug-in to be installed on a manager's PC.
Administrators can furthermore remotely configure, track, and analyze Cisco PIX firewalls via a command-line interface. Secure command-line interface (CLI) communication is available using several methods such as Secure Shell (SSHv2) Protocol, Telnet over IPsec, and out-of-band via a console port. Cisco PIX firewalls also have robust automatic-update capabilities, a collection of protected remote-management options that ensure firewall settings and software images are always current.
Cisco ASA 5500 Series Firewalls
Cisco Adaptive Security Appliances Firewalls are purpose-built devices that incorporate market-proven, best-of-breed security and Virtual Private Network services with an adaptive architecture. The end product is a powerful, multifunction network protection solution better suited to defend small and midsize company and larger networks and, simultaneously, lower the total deployment and operations costs formerly required for this high degree of protection.

Cisco Adaptive Security Appliances firewalls provide robust application protection via smart, application-sensitive inspection engines that examine network flows at Layers 4-7. This results in a safer environment covering web, voice, and mobile wireless connectivity. To protect networks against application-layer attacks and to give organizations more policing of the applications and protocols used in their environments, Cisco's inspection engines incorporate broad application and protocol knowledge and employ security enforcement technologies such as protocol anomaly sensing and application and protocol state tracking. Also incorporated are attack sensing and remediation techniques including application/protocol command filtering and URL deobfuscation. Cisco Adaptive Security Appliances (ASA) 5500 Series firewall inspection engines also provide control over instant messaging and tunneling applications, allowing organizations to police usage policies and conserve bandwidth for important business applications.
While improving network protection, Cisco Adaptive Security Appliances (ASA) firewalls also decrease deployment and operational costs. By offering extensive VPN and protection functions, the Cisco Adaptive Security Appliances 5500 Series firewall can be used as the single device for many environments, enabling platform standardization. The Cisco ASA firewall can be deployed as a converged attack-protection appliance at the datacenter by taking advantage of its connectivity control, process inspection, and malware mitigation capabilities. The Cisco Adaptive Security Appliances (ASA) firewall can also be used as a dedicated remote access device using its Virtual Private Network capabilities. As another option, the Cisco Adaptive Security Appliances 5500 Series firewall operates capably inside the network for inter-office connectivity control and to defend against malicious assaults inside users may unknowingly introduce into the environment. For small company and branch office networks, the Cisco Adaptive Security Appliances firewall acts as a total solution platform providing complete threat defense and Virtual Private Network functionality while fitting within the cost structure and operational models of these deployments.
This versatile one-device, multiple-use design reduces the total number of appliances that must be deployed and managed while providing a standard operating and administrative system throughout all deployments. This approach streamlines the training of configuration, tracking, troubleshooting, and protection personnel. To further reduce operations costs, Cisco Adaptive Security Appliances 5500 Series firewalls are also highly network conscious, allowing these devices to integrate gracefully into the network without interfering with legitimate data flow and processes.
How Progent's Consultants Can Help You with Cisco PIX and ASA Firewalls
Cisco ASA Series firewalls and PIX security appliances provide a wealth of setup, tracking, and troubleshooting features that give you the ability to set up these security appliances to align optimally with your business requirements. Progent's CCIE authorized network experts can assist you to support your existing network infrastructure that includes Cisco ASA and/or PIX firewalls and that provides security, resilience, throughput, and recoverability. Progent's firewall experts can also assist you to upgrade to ASA 5500-X firewalls with Firepower Services.
Progent's CISA and CISM-certified IS security engineers can help your business to create a security strategy appropriate for your environment and can set up your PIX or ASA firewall to support your security policies. Progent's risk evaluation consultants can evaluate the effectiveness of your current firewall solution and help determine the security of your whole IS environment. Progent's Technical Response Center (TRC) can provide emergency remote troubleshooting for Cisco technology and can give you fast access to a Cisco CCIE expert.
For additional details about Progent's professional expertise for Cisco products, choose a subject: