Cisco is a long-time leader in developing state-of-the-art firewall appliances for the widest possible variety of environments. Cisco's Firepower Next Generation Firewalls represent a modern cybersecurity platform that marshals dedicated hardware, cloud services, and machine learning to anticipate, discover, and mitigate threats without manual intervention. Progent's Cisco-certified CCIE-certified firewall experts can help you to plan and execute a smooth upgrade to Firepower Series firewalls from Cisco's from ASA 5500-X, ASA 5500, or PIX firewalls and help you integrate Firepower firewalls with Cisco's cloud-based services to build and centrally control network environments that include local offices, data centers, private clouds and public clouds. Progent's firewall consultants can also help you to manage and debug legacy Cisco firewalls. Progent's certified network security consultants can assist you with policy creation and tuning based on industry best practices so you can establish a consistent security profile across all your endpoints at any location.

Cisco's Firepower Next Generation Firewalls
Cisco's Firepower Next Generation Firewalls provide a significant performance boost over Cisco's popular ASA 5500-X firewalls and include centralized control of advanced security features like application visibility and control, next-generation intrusion protection with intelligent prioritization of risks, advanced malware protection (AMP), URL filtering, and sandboxing. For details about Cisco's Firepower line of NGFWs Firewalls, visit Firepower firewalls consulting experts.

Cisco Firepower 4100 Series Firewalls Consulting

Cisco's ASA 5500-X Series and Legacy Firewalls
Cisco's ASA 5500-X Series, ASA 5500 Series, and PIX firewalls provide integrated firewall, IPsec VPN, and intrusion prevention system (IPS) services in compact single-box packages, delivering a broad array of features to meet the security requirements of organizations ranging from small and mid-size businesses to enterprises and Internet service providers. Cisco's ASA 5500-X Series, ASA 5500, and PIX 500 firewalls allow IT security teams to protect their network perimeter and provide safe remote connectivity while using advanced administration tools built on Cisco's industry-leading firewall products.

Cisco's ASA 5500 Series and PIX firewalls have arrived at end-of-life (EOL) but remain widely used in small and mid-size businesses and in some enterprise data centers. Cisco's ASA 5500-X Next-Generation Firewalls represent substantially more value and have supplanted the ASA 5500 and PIX lines of firewalls for new installations. Still, Cisco's legacy firewalls, if properly maintained, can offer a high degree of security by supplying a variety of services including stateful firewall, VPN, and IPS.

Following Cisco's purchase of Sourcefire, the whole line of ASA 5500-X devices can be provisioned to enable Firepower Services, based on Sourcefire's Snort product, which is the market's most popular intrusion protection system (IPS). Firepower services provide enhanced features including advanced malware protection (AMP), URL filtering, dynamic threat analytics, and automation.

Progent's Cisco CCIE-certified infrastructure consultants can help your organization to maintain and debug older ASA 5500 and PIX firewall appliances and can also help you to design and carry out an efficient upgrade to Cisco's ASA 5500-X Series firewalls with Firepower Services. Progent can also help you to plan, deploy, optimize, manage and troubleshoot new firewall ecosystems built on Cisco's latest ASA 5500-X models with Firepower Services. Progent can also assist your organization to upgrade from your Cisco ASA 5500-X deployment to Cisco's latest Firepower NGFWs Firewalls.

Cisco's ASA 5500-X Firewall Product Family
Cisco's extensive line of ASA 5500-X security appliances features an improved substitute for every rack-mountable model in the older ASA 5500 series of devices. Each ASA 5500-X model is suited for the identical market as the corresponding previous models, which gives small and midsize businesses ample choice for selecting a firewall that meets their security needs and IT budgets. All ASA 5500-X firewalls are based on Cisco's tested stateful-inspection firewall technology and all include purpose-built 64-bit hardware with multicore processors and are capable of running Cisco's advanced protection services. All models in Cisco's ASA 5500-X product line provide consistent security across any combination of physical, virtual, and cloud environments.

Cisco ASA 5500-X Firepower Consultants

For additional details about Cisco's ASA 5500-X firewalls, Firepower services, and Progent's consulting for ASA 5500-X security appliances, visit Cisco Firepower integration and troubleshooting expertise

Firepower Services for ASA 5500-X Security Appliances
Cisco ASA 5500-X security appliances work with either software or physical modules that enable Cisco's Firepower Services, which offer layered defense against multi-vector attacks. Cisco's Firepower Services are powered by innovative technology adopted by Cisco from Sourcefire. Major capabilities of Firepower Services for ASA 5500-X firewalls include:

  • Multi-layer defense against both familiar and new attacks
  • Advanced Malware Protection that uses big data techniques to find and mitigate security breaches
  • Cisco's Next-Generation Intrusion Prevention System (NGIPS) that performs contextual analysis that covers clients, network infrastructure, software applications, and content to detect threats that incorporate multiple vectors
  • High-resolution Application Visibility and Control that is aware of thousands of applications and can automatically launch standard and customized IPS policies depending on the severity of threats
Cisco Firepower Configuration Expertise

Firepower Services for Cisco ASA firewalls offer advanced multi-layered threat protection

Smaller deployments of Cisco ASA 5500-X firewalls can be effectively managed using Cisco's on-box Adaptive Security Device Manager (ASDM) Adaptive Security Device Manager, a web tool included with all ASA 5500-X versions. ASDM provides a simple web dashboard for deploying, administering, and debugging ASA 5500-X appliances and service modules.

For multi-device and multi-site deployments, ASA 5500-X appliances with Firepower can be administered with Cisco's Firepower Management Center, available as one or several physical units or virtual devices. Cisco's Firepower Management Center provides unified firewall management, Application Visibility and Control, advanced IPS, URL filtering, and Advanced Malware Protection (AMP). Due to frequent rebranding since Cisco's purchase of Sourcefire Defense Center, Cisco's Firepower Management Center has been delivered under various names including Defense Center, FireSIGHT Defense Center, and FireSIGHT Management Center.

Cisco Firepower Management Center Consulting

Firepower Management Center unifies event and policy management for Firepower firewalls

Cisco's Firepower Management Center offers features unavailable with Cisco's on-device ASDM tool. Additional features include expanded context awareness, Advanced Malware Protection with mitigation for user devices, a dashboard that provides dynamic infrastructure visualization, automated policy tuning based on impact evaluation of attacks, advanced IPS, custom application detectors for Application Visibility and Control, customized health notifications, improved reporting options, and APIs for host input and databases. Hardware-dependent capabilities like clustering, stacking, switching, routing, VPN, and NAT must be handled using Cisco's ASA 5500-X on-device ASDM or the ASA command line interface.

Cisco ASA 5500 Family of Firewalls
Cisco ASA Firewalls build on engineering behind the Cisco PIX 500 family firewall, the IPS 4200 family Intrusion Prevention System, and the Cisco VPN 3000 family concentrator. These solutions converge on the Cisco Adaptive Security Appliances (ASA) Firewall family to deliver a firewall that stops the broadest range of threats. Cisco Adaptive Security Appliances (ASA) 5500 Series Firewalls deliver program protection, network containment, and clean Virtual Private Network connectivity throughout the entire product line. This broad scope of protection allows defense of any network section, including the most typical threat conduits such as remote sites, LAN-connected inside users, and off-site connected Virtual Private Networks.

Cisco ASA 5500 Consulting Services and Troubleshooting
The expandable architecture of the ASA 5500 family allows you to add security services by installing service modules and security service cards (SSCs). These easy-to-install options provide the ability to add IPS and content protection services like filtering virus, worms, and phishing attacks and performing file and web filtering. Beside enabling your IT staff to respond quickly to the latest threat environments, the expandable architecture of the ASA 5500 family also leverages your hardware investment by increasing the life of your security appliances. The ASA 5500 family also leverages your investment in IT team training by utilizing the rich library of PIX management utilities and protocols such as the Cisco ASDM platform, protected command-line interface (CLI) access, verbose syslog, and Simple Network Management Protocol (SNMP).

Cisco Adaptive Security Appliances firewalls provide robust application security through smart, application-aware inspection processes that examine traffic at Layers 4-7. This produces a more secure environment covering Web, voice, and mobile wireless services. To protect against application-layer attacks and to offer stronger policing of the programs and protocols utilized in their networks, these inspection engines integrate extensive application and protocol knowledge and employ security enforcement technologies such as anomaly detection and state monitoring. Also included are assault detection and mitigation techniques including application and protocol command filters and content verification. Cisco Adaptive Security Appliances 5500 Series firewall inspection engines also provide management of instant messaging and tunneling applications, allowing organizations to enforce usage policies and recover network bandwidth for critical business processes.

For more details about Progent's support services for ASA 5500 firewalls, go to Cisco ASA 5500 firewalls configuration and debugging support.

Cisco PIX Firewalls
Based around a hardened, purpose-built operating system that delivers a wealth of protection features, Cisco PIX firewall appliances provide excellent protection and have been awarded Common Criteria Evaluation Assurance Level 4 status and ICSA Firewall and IP Security qualification. Cisco PIX firewalls offer security for a broad range of Voice over IP and other mixed-media standards including H.323 v. 4, Session Initiation Protocol (SIP), SCCP, Real-Time Streaming Protocol (RTSP), and Media Gateway Control Protocol (MGCP), enabling businesses to protect deployments of a wide range of current and next-generation Voice over IP and video applications.

Cisco PIX Firewalls Support
PIX firewalls feature a variety of setup, monitoring, and troubleshooting features, providing IT managers the versatility to utilize the methods that most closely meet their requirements. Administrative solutions include centralized, policy-based administration tools, integrated web-based management, and compatibility with remote-monitoring standards such as Simple Network Management Protocol and syslog. The integrated Adaptive Security Device Manager interface provides a world-class Web-accessible control solution that greatly simplifies the installation, ongoing configuration, and tracking of a single PIX firewall appliance without requiring any extra software other than an ordinary browser and Java applet to be running on an administrator's computer.

IT managers can also remotely set up, monitor, and analyze PIX security appliances via a command-line interface (CLI). Safe command-line interface (CLI) communication is possible through a number of methods including Secure Shell (SSHv2) Protocol, Telnet over IP Security (IPsec), and out-of-band through a console port. PIX firewall appliances also include robust auto-update features, a collection of revolutionary secure remote-administration options that ensure firewall settings and software images are kept current.

For additional details about Progent's consulting services for Cisco PIX firewalls, see Cisco PIX firewalls integration and troubleshooting consulting.

Progent's Migration Support for Cisco Firewalls
Because Cisco has stopped offering the PIX 500 and ASA 5500 product lines, many companies are concerned about relying on a key infrastructure component that might no longer be supported. Cisco ASA 5500-X and Firepower Series firewalls have the benefit of being current devices and also bring several technical and financial advantages in comparison to PIX firewalls. These benefits include substantially better throughput, optional SSL VPN support, and a modular design that protects your investment by enabling you to add more security features when and if you require them. Progent's CCIE-certified experts can help you to assess the business value of for migrating from PIX 500 or Cisco ASA 5500 security appliances, create a migration process that permits a quick and non-disruptive changeover, assist you to install new ASA 5500-x Series or Firepower Series appliances, and offer online, consulting, and troubleshooting services.

Additional Ways Progent Can Help You with Cisco ASA and PIX Firewalls
Cisco's Firepower Series, ASA Series, and PIX security appliances provide a wealth of configuration, tracking, and analysis features which give you the ability to configure these security appliances to match your company's requirements. Progent's CCIE certified network professionals can help you to configure and support a cost-effective network infrastructure that includes Cisco firewalls and that provides advanced security, fault tolerance, throughput, and manageability. Progent's GISA and CISSP-ISSP-certified information security professionals can assist you to develop a security strategy appropriate for your business and can configure your security appliance to enforce your security policies. Progent's security assessment consultants can evaluate the effectiveness of your current firewall deployment and audit the overall security of your whole IT environment. Progent's Technical Response Center can deliver emergency remote troubleshooting for Cisco technology and offer fast access to a Cisco expert.

To see additional information concerning Progent's consulting assistance for Cisco technology, choose a topic:

Integration of Cisco and Third-party Firewall Technology
Progent offers expertise in firewall and VPN products from all major vendors and can help you integrate Cisco technology with additional security solutions to help you build a cost-effective network infrastructure that provides a level of security and flexibility appropriate for your business. Third-party firewall and VPN support services available from Progent include:

To contact Progent about consulting assistance for Cisco networking, phone 1-800-993-9400 or visit Contact Progent.



An index of content::







  • © 2002-2026 Progent Corporation. All rights reserved.