Cisco's PIX security appliances and Cisco ASA Series adaptive security appliances combine comprehensive firewall, intrusion protection, and Virtual Private Network functionality in an affordable, one-cabinet format. Both product lines have been replaced by Cisco's ASA 5500-X family of security appliances with Firepower. (Refer to integration and debugging help with Cisco AA 5500-X firewalls with Firepower Services.) Still, PIX and previous-generation ASA 5500 Series adaptive security appliances are widely deployed and continue to deliver small and mid-size organizations a viable security solution.

Cisco PIC and legacy ASA 5500 firewalls offer powerful client and application policy enforcement, mutlivector assault defense, and secure access services. The increased intelligence sharing of integrated security services in a single platform offers customers deploying these aggregated firewalls the advantages of enhanced security, lower TCO, and minimal management expense. Cisco PIX security appliances and Cisco's ASA 5500 Series combine with Cisco IOS Firewall, the FWSM for Cisco Catalyst 6500 family switches, and 7600 family routers as components of Cisco's flexible, integrated firewall product. Based on a scalable, modular approach, each device is equipped with a particular feature set to deliver better security to a variety of network situations. These products can be independently deployed to protect specific areas of the network environment, or can be combined for a layered, defense-in-depth approach based on the design leading practices described in the Cisco SAFE framework. Rounding out the modular firewall solutions, Cisco has developed a comprehensive security management product portfolio, spanning Cisco security device and Cisco IOS security components and built-in appliance controllers, to self-contained management utilities, moving to make sure that customers can productively use their Cisco protection infrastructure investments. PIX Firewall Appliances
Cisco PIX Security Appliance Series offer reliable policy enforcement, multi-source attack defense, and secure networking services in affordable, easy-to-deploy solutions. These specialized devices provide a broad range of integrated security and networking services including process-aware firewall features, Voice over IP (VoIP) and multimedia protection, reliable multi-location and remote-access IP Security (IPsec) VPN connectivity, high availability, smart networking services, and versatile administration solutions. The PIX firewall Appliance product line ranges from compact plug-and-go desktop units for small or at home offices to modular gigabit products with investment protection for enterprise and service-provider customers, PIX firewalls deliver dependable security, speed, and availability for network environments of any size.

Cisco PIX Security Consulting
Built upon a hardened, purpose-built software platform that delivers a wealth of protection services, PIX firewalls offer a high level of security and have received Common Criteria Evaluation Assurance Level (EAL) 4 status and ICSA Labs Firewall and IP Security qualification. Cisco PIX security appliances provide security for a broad range of VoIP and additional multimedia standards including H.323 Version 4, SIP, SCCP, RTSP, and MGCP, enabling businesses to safeguard installations of a broad array of current and upcoming Voice over IP and video applications. PIX firewalls offer a variety of setup, monitoring, and troubleshooting features, giving businesses the versatility to utilize the methods that best match their needs. Administrative options include common, policy-based administration utilities, integrated web-accessible administration, and support for remote-tracking standards such as SNMP and syslog. The integrated Adaptive Security Device Manager interface provides a powerful web-based control solution that significantly simplifies the deployment, in-place configuration, and monitoring of a single PIX security appliance without the need of any additional utility other than an ordinary browser and Java plug-in to be running on a manager's PC.

Administrators can also remotely configure, track, and analyze PIX firewalls via a CLI interface. Secure CLI interface access is possible through several techniques such as SSHv2 Protocol, Telnet over IP Security (IPsec), and out-of-band via a console port. PIX firewalls also have robust auto-update capabilities, a collection advanced secure remote-administration options that ensure security settings and software images are kept current. Cisco Adaptive Security Appliances (ASA) Firewalls
Cisco ASA 5500 Series Firewalls are purpose-built solutions that incorporate advanced, industry-leading protection and Virtual Private Network support with an adaptive architecture. The result is a robust, versatile network security appliance better able to defend small and midsize company and enterprise networks and, at the same time, lower the total installation and operations costs formerly associated with this enhanced degree of security.

Cisco Adaptive Security Appliances Firewalls Professional Services
Cisco ASA Firewalls build on technology behind the Cisco PIX 500 family Security Appliance, the IPS 4200 Series sensor, and the VPN 3000 Series concentrator. These solutions converge on the Cisco ASA Firewall product line to deliver a platform that stops a wide range of attacks. Cisco Adaptive Security Appliances 5500 Series Firewalls deliver application protection, network containment and control, and clean Virtual Private Network connectivity across Cisco's product line. This broad scope of security allows the guarding of any network section, which includes the most common threat conduits such as remote locations, locally-connected inside users, and remote connected VPNs. Cisco Adaptive Security Appliances firewalls provide robust application protection through intelligent, application-aware inspection processes that analyze network flows at Layers 4-7. This produces a more secure environment covering web, voice, and mobile wireless connectivity. To defend environments from application-layer assaults and to offer organizations more control over the applications and protocols utilized in their networks, these inspection engines incorporate broad application and protocol knowledge and rely on security enforcement solutions such as protocol anomaly detection and application and protocol state monitoring. Also included are assault sensing and remediation techniques including application and protocol command filtering and content verification. Cisco Adaptive Security Appliances firewall inspection engines also deliver management of instant messaging and peer-to-peer file sharing, enabling organizations to police usage policies and recover network bandwidth for vital business processes. At the same time as improving network security, Cisco Adaptive Security Appliances firewalls also decrease installation and operational expenses. By providing extensive VPN and security functions, the Cisco ASA firewall can be used as the single device for many uses, enabling platform standardization. The Cisco Adaptive Security Appliances (ASA) 5500 Series firewall can be used as a consolidated attack-prevention appliance at the datacenter by leveraging its connectivity control, application inspection, and malware mitigation technologies. The Cisco Adaptive Security Appliances 5500 Series firewall can also be deployed as a specialized remote access solution using its Virtual Private Network capabilities. As an alternative, the Cisco Adaptive Security Appliances (ASA) firewall serves equally well inside the network for inter-office connectivity management and to defend against malware internal users may unwittingly release into the network. For small company and satellite office networks, the Cisco Adaptive Security Appliances (ASA) 5500 Series firewall serves as a total solution device providing complete threat prevention and Virtual Private Network services while suiting the cost structure and performance models of such situations.

This adaptive single-platform, many-solution approach minimizes the number of devices that must be deployed and managed while offering a common functional and management environment throughout all deployments. This approach simplifies the training of configuration, monitoring, troubleshooting, and protection personnel. To further minimize operations costs, Cisco ASA 5500 Series firewalls are also highly network aware, allowing them to integrate seamlessly into the environment without disrupting legitimate traffic and applications. How Progent's Cisco Certified Experts Can Help Your Business with Cisco Firewalls
Cisco ASA Series adaptive security appliances and PIX family security appliances provide an array of configuration, tracking, and analysis options that give you the flexibility to set up these security appliances to match your company's needs. Progent's CCIE authorized network consultants can help you to support your existing network infrastructure that incorporates Cisco ASA and/or PIX security appliances and that provides protection, fault tolerance, performance, and recoverability. Progent can also assist you to migrate to Cisco ASA 5500-X firewalls with Firepower Services.

Progent's GISA and CISSP-ISSP-certified information security consultants can assist your business to develop a security strategy that makes sense for your business and can configure your security appliance to support your security strategy. Progent's risk assessment professionals can assess the effectiveness of your existing firewall solution and validate the overall security of your entire IT environment. Progent's Help Desk Call Center can provide urgent online troubleshooting for Cisco technology and can give you quick access to a Cisco network engineer. To learn additional information about Progent's consulting help for Cisco products, choose a topic:

If you wish to get in touch with Progent about technical support for Cisco networking, call 1-800-993-9400 or go to Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.