Cisco is a perennial front-runner in developing cutting-edge firewall appliances for the widest possible variety of deployments. Cisco's Firepower Next Generation Firewalls (NGFWs) provide a modern cybersecurity solution that marshals sophisticated hardware, cloud-based services, and machine learning to anticipate, identify, and mitigate cyber attacks without manual intervention. Progent's Cisco-certified CCIE-certified firewall experts can help you to design and execute a smooth upgrade to Cisco Firepower firewalls from Cisco's legacy ASA 5500-X, ASA 5500, or PIX appliances and help you integrate Firepower firewalls with Cisco's security services to build and centrally control network environments that span local offices, data centers, and cloud resources. Progent can also help you to maintain and debug older-generation Cisco firewalls. Progent's certified network security experts can help you with policy creation and tuning based on industry best practices in order to build a consistent and effective security profile across all your endpoints at any location.
Cisco's Firepower Next Generation Firewalls
Cisco's Firepower Next Generation Firewalls (NGFWs) deliver a significant performance improvement over Cisco's popular ASA 5500-X firewalls and offer unified management of modern security capabilities such as application visibility and control (AVC), next-generation intrusion protection with intelligent prioritization of risks, advanced malware protection, DDoS mitigation, and sandboxing. For details about Cisco's Firepower portfolio of Next Generation Firewalls, refer to Firepower firewalls integration experts.

Cisco's ASA 5500-X and Legacy Firewalls
Cisco's ASA 5500-X, ASA 5500, and PIX 500 firewall appliances offer combined firewall, IPsec VPN, and IPS services in compact single-box devices, delivering a wide range of features to meet the security and compliance needs of organizations ranging from small and mid-size businesses to enterprises and Internet service providers. Cisco's ASA 5500-X Series, ASA 5500 Series, and PIX firewall appliances enable IT security staffs to protect their network edge and provide safe remote connectivity while using advanced administration tools built on Cisco's world-class firewall products.
Cisco's ASA 5500 and PIX firewall appliances have arrived at end-of-life (EOL) but are still commonly deployed in smaller organizations and in some larger data centers. Cisco's ASA 5500-X Series Next-Generation Firewalls deliver significantly more value and have supplanted Cisco's ASA 5500 and PIX lines of firewalls for new installations. However, Cisco's older model firewall appliances, if properly managed, continue to deliver a high degree of security by providing multiple services such as stateful firewall, VPN, and IPS.
After Cisco's acquisition of Sourcefire, the whole family of Cisco ASA 5500-X firewalls can be configured to support Firepower Services, based on Sourcefire's Snort technology, which is the market's most popular intrusion protection system (IPS). Firepower services provide enhanced features such as advanced malware protection (AMP), URL filtering, real-time threat analytics, and security automation.
Progent's Cisco CCIE-premier infrastructure consultants can assist your organization to maintain and debug older ASA 5500 and PIX 500 firewall appliances and can also assist you to plan and implement a smooth migration to Cisco's ASA 5500-X firewalls with Firepower. Progent can also assist you to plan, configure, optimize, manage and troubleshoot new firewall ecosystems built on Cisco's current ASA 5500-X firewalls with Firepower. Progent's firewall consultants can also help you to upgrade from your Cisco ASA 5500-X Series deployment to Cisco's Firepower Next Generation Firewalls (NGFWs).
Cisco's ASA 5500-X Firewall Product Family
Cisco's extensive line of ASA 5500-X security appliances features an enhanced replacement for each rack-mountable unit in the older ASA 5500 line of firewalls. Each ASA 5500-X firewall is suited for the identical environment as the corresponding earlier models, which offers most plenty of room for selecting a firewall that aligns with their security needs and budgets. All ASA 5500-X firewalls build on Cisco's proven stateful-inspection firewall technology and all include purpose-built 64-bit hardware with multicore CPUs and support Cisco's powerful security services. All devices in Cisco's ASA 5500-X family deliver dependable protection across any mix of physical, virtual, and cloud environments.

For more information about Cisco's ASA 5500-X security appliances, Firepower services, and Progent's support for Cisco ASA security appliances, go to Cisco Firepower configuration and troubleshooting consulting
Cisco's Firepower Services for ASA 5500-X Firewalls
Cisco ASA 5500-X security appliances work with software or physical modules that support Firepower Services, which provide layered protection against advanced attacks. Firepower Services are based on innovative technology acquired by Cisco from Sourcefire. Major features of Firepower Services for ASA security appliances include:

Smaller deployments of Cisco ASA 5500-X firewalls can be effectively managed using Cisco's on-box Adaptive Security Device Manager (ASDM) Adaptive Security Device Manager, a web utility included with all ASA 5500-X versions. ASDM provides a simple web dashboard for deploying, administering, and troubleshooting ASA 5500-X firewalls and service modules.
For multi-device and multi-site deployments, ASA 5500-X firewalls with Firepower can be administered using Cisco's Firepower Management Center, implemented as one or more physical units or virtual appliances. Cisco's Firepower Management Center provides centralized firewall management, Application Visibility and Control, enhanced IPS, URL filtering, and Cisco's Advanced Malware Protection (AMP). Due to ongoing rebranding since Cisco's purchase of Sourcefire Defense Center, Cisco's Firepower Management Center has been offered under several names including Cisco Defense Center, Cisco Firesight Defense Center, and FireSIGHT Management Center.

Cisco's Firepower Management Center offers capabilities beyond those available with Cisco's on-box ASDM utility. Additional features include greater context awareness, Cisco's Advanced Malware Protection with mitigation for client devices, a dashboard that offers real-time network visualization, automated policy tuning based on risk assessment of threats, advanced IPS, custom app discovery for Application Visibility and Control (AVC), customized health notifications, enhanced reporting features, and application interfaces for host input and databases. Hardware-dependent features like clustering, stacking, switching, routing, VPN, and NAT must be managed using Cisco's ASA 5500-X on-device ASDM or the ASA CLI.
Cisco ASA 5500 Series Firewalls
Cisco Adaptive Security Appliances Firewalls build on technology behind the Cisco PIX 500 firewall, the Cisco IPS 4200 family sensor, and the Cisco VPN 3000 model concentrator. These solutions enable the Cisco Adaptive Security Appliances (ASA) 5500 Series Firewall family to deliver a platform that defends against the broadest variety of threats. Cisco Adaptive Security Appliances Firewalls deliver application protection, network containment and control, and clean Virtual Private Network functionality across the entire product line. This breadth of security allows the guarding of any network area, including the most typical threat vectors such as remote locations, LAN-connected internal users, and off-site access VPNs.

Cisco Adaptive Security Appliances firewalls provide a high-level of application security via intelligent, application-sensitive inspection processes that analyze network flows at Layers 4-7. The result is a better protected network covering Web, voice, and 3G-mobile wireless services. To protect networks against application-layer attacks and to offer stronger control over the applications and protocols used in their networks, these inspection engines integrate extensive application and protocol knowledgebases and employ protection enforcement technologies that include protocol anomaly sensing and application and protocol state monitoring. Also included are attack sensing and mitigation technology such as application and protocol command filtering and content verification. Cisco Adaptive Security Appliances 5500 Series firewall inspection engines also provide control over IM and tunneling applications, enabling businesses to enforce usage policies and preserve bandwidth for important business processes.
For more details about Progent's consulting services for ASA 5500 security appliances, visit ASA 5500 firewalls configuration and troubleshooting services.
Cisco PIX Firewall Appliances
Built around a tested, purpose-built OS that delivers rich security services, PIX security appliances offer excellent security and have received EAL 4 status and ICSA Labs Firewall and IPsec qualification. Cisco PIX security appliances provide protection for a broad range of VoIP and other mixed-media conventions such as H.323 v. 4, Session Initiation Protocol, SCCP, Real-Time Streaming Protocol, and MGCP, enabling organizations to protect installations of a wide array of current and upcoming Voice over IP and video applications.

Administrators can furthermore remotely set up, track, and analyze Cisco PIX firewall appliances using a command-line interface (CLI). Safe command-line interface communication is available through a number of techniques including SSHv2 Protocol, Telnet through IP Security, and out-of-band via a console port. PIX firewall appliances also have dependable auto-update capabilities, a collection of revolutionary protected remote-administration services that ensure firewall configurations and software images are always up to date.
For additional details about Progent's consulting services for PIX 500 security appliances, go to Cisco PIX firewalls integration and debugging support.
Progent's Migration Support for Cisco Firewalls
Because Cisco has ceased selling the PIX and ASA 5500 families of firewalls, many companies are concerned about relying on a critical infrastructure component that may stop being supported by Cisco. ASA 5500-X and Firepower NGFW Series firewalls offer the advantage of being current products and also bring several functions and financial advantages in comparison to PIX devices. These benefits include substantially higher performance, optional Secure Sockets Layer VPN support, and a modular design that guards your investment by enabling you to self-install more security features whenever you require them. Progent's Cisco certified experts can assist your company to determine the strategic case for moving from PIX or ASA 5500 security appliances, design a migration plan that permits a quick and seamless upgrade, assist your IT staff to set up new ASA 5500-x Series or Firepower Series appliances, and provide online, consulting, and troubleshooting services.
Other Ways Progent Can Assist Your Business with Cisco ASA and PIX Firewalls
Cisco Firepower NGFW Series, ASA Series, and PIX family firewalls incorporate a wealth of setup, tracking, and analysis options which offer you the ability to set up these firewalls to align optimally with your business requirements. Progent's CCIE certified network consultants can show you how to build a cost-effective network infrastructure that includes Cisco firewalls and that provides world-class security, fault tolerance, performance, and manageability. Progent's GISA and CISM-premier information security consultants can help your business to create a security policy appropriate for your environment and can configure your security appliance to enforce your security strategy. Progent's risk assessment professionals can evaluate the strength of your current firewall solution and validate the overall security of your entire IT environment. Progent's Help Desk Call Center can deliver urgent online troubleshooting for Cisco technology and offer fast access to a Cisco CCIE expert.
To find out more information about Progent's engineering assistance for Cisco products, select a topic:
Integration of Cisco and Third-party Firewall Technology
Progent offers expertise in firewall and VPN products from all major vendors and can help you integrate Cisco technology with additional security solutions to help you build a cost-effective network infrastructure that provides a level of security and flexibility appropriate for your business. Third-party firewall and VPN support services available from Progent include:
To contact Progent about consulting assistance for Cisco products, phone