Cisco PIX family firewalls and Cisco ASA 5500 Series firewalls integrate next-generation firewall, intrusion defense, and Virtual Private Network technologies in a cost-effective, single-cabinet format. Both of these product lines have been replaced by Cisco's ASA 5500-X line of firewalls with Firepower Services. (See configuration and troubleshooting expertise for Cisco AA 5500-X firewalls with Firepower Services.) Still, both PIX and previous-generation ASA 5500 Series adaptive security appliances are extensively used and continue to deliver small and mid-size organizations a viable firewall solution.

PIX and legacy ASA 5500 firewalls offer robust user and application policy support, mutlivector attack protection, and safe access services. The increased knowledge sharing of consolidated protection features in a single platform provides users implementing these aggregated firewalls the benefits of advanced protection, reduced TCO, and minimal management costs.

Cisco PIX firewalls and the ASA 5500 family combine with Cisco IOS Firewall, the Firewall Services Module (FWSM) for Catalyst 6500 family switches, and 7600 family routers as parts of Cisco's flexible, self-contained firewall line. Based on an expandable, building-block platform, every offering is equipped with a specific feature set to deliver better protection to a variety of network environments. These products can be independently installed to protect specific areas of a connectivity environment, or can be grouped for a layered, protection-in-depth strategy following the architecture best practices described in the Cisco SAFE framework. Completing the modular firewall solutions, Cisco has developed a comprehensive security management portfolio, ranging from Cisco security appliance and IOS Software security features and built-in device managers, to self-contained management utilities, helping to make sure that businesses can productively manage their Cisco protection infrastructure purchases.

PIX Firewall Appliances
PIX firewalls deliver robust policy enforcement, multi-source attack protection, and safe networking services in cost-effective, simple-to-configure solutions. These specialized appliances offer a wealth of integrated security and connectivity services including process-aware firewall features, VoIP and multimedia security, robust multi-site and remote-connectivity IP Security (IPsec) Virtual Private Network networking, fault tolerance, intelligent networking services, and versatile management options. The Cisco PIX firewall Appliance family ranges from small plug-and-play devices for small offices or home offices to modular high-bandwidth products with ROI for enterprise and service-provider customers, Cisco PIX firewalls provide dependable protection, speed, and availability for network environments of any size.

Cisco PIX Security Experts

Based around a hardened, purpose-built operating system that delivers a wealth of protection features, Cisco PIX security appliances offer a high level of security and have earned Common Criteria Evaluation Assurance Level (EAL) 4 status and ICSA Firewall and IP Security (IPsec) certification. PIX security appliances offer security for a broad array of VoIP and additional multimedia standards such as H.323 Version 4, Session Initiation Protocol (SIP), Cisco Skinny Client Control Protocol (SCCP), Real-Time Streaming Protocol (RTSP), and MGCP, enabling businesses to safeguard installations of a broad range of current and upcoming VoIP and multimedia applications.

Cisco PIX firewall appliances feature a variety of setup, tracking, and troubleshooting features, giving businesses the versatility to utilize the methods that best meet their needs. Administrative solutions include common, policy-based administration utilities, integrated web-based administration, and compatibility with remote-tracking standards such as SNMP and syslog. The integrated Adaptive Security Device Manager interface offers a world-class web-accessible control platform that significantly streamlines the deployment, ongoing configuration, and monitoring of a single Cisco PIX firewall appliance without the need of any additional utility beyond a standard web browser and Java applet to be installed on an administrator's computer.

Administrators can furthermore remotely configure, track, and troubleshoot Cisco PIX firewalls using a command-line interface (CLI). Secure command-line interface (CLI) communication is possible using several techniques including Secure Shell (SSHv2) Protocol, Telnet over IP Security (IPsec), and out-of-band via a console port. Cisco PIX security appliances also have dependable automatic-update features, a collection of protected remote-management services that make sure that firewall settings and software images are kept up to date.

Cisco Adaptive Security Appliances (ASA) Firewalls
Cisco Adaptive Security Appliances Firewalls are purpose-built devices that incorporate advanced, best-of-breed security and VPN services plus an adaptive design. The end product is a powerful, multifunction network protection solution better able to defend small and medium business and enterprise networks and, at the same time, reduce the overall deployment and maintenance costs formerly required for this high level of protection.

Cisco Adaptive Security Appliances 5500 Series Firewalls Professional Services
Cisco Adaptive Security Appliances (ASA) Firewalls leverage engineering behind Cisco's PIX 500 Security Appliance, the IPS 4200 family sensor, and the Cisco VPN 3000 Series concentrator. These solutions converge on the Cisco ASA Firewall product line to deliver a platform that stops a wide range of threats. Cisco ASA 5500 Series Firewalls provide application security, network containment, and safe Virtual Private Network functionality throughout Cisco's product line. This broad scope of protection enables defense of any network area, including the most typical attack vectors such as remote locations, LAN-connected inside users, and remote connected VPNs.

Cisco ASA firewalls provide strong application protection via intelligent, application-sensitive inspection processes that examine network flows at Layers 4-7. This results in a safer environment covering web, voice, and mobile wireless services. To protect networks against application-layer attacks and to give organizations greater policing of the programs and protocols used in their environments, these inspection engines incorporate broad application and protocol knowledgebases and rely on protection enforcement technologies that include anomaly detection and application and protocol state tracking. Also incorporated are attack detection and mitigation technology such as application/protocol command filtering and URL deobfuscation. Cisco Adaptive Security Appliances (ASA) 5500 Series firewall inspection engines also deliver control over instant messaging and tunneling applications, allowing businesses to police usage policies and conserve network bandwidth for critical business processes.

While increasing network protection, Cisco Adaptive Security Appliances firewalls also decrease deployment and support expenses. By providing broad VPN and protection functions, the Cisco Adaptive Security Appliances firewall can be a single device for a multitude of uses, allowing platform commonality. The Cisco ASA 5500 Series firewall can be deployed as a consolidated attack-prevention device at the datacenter by taking advantage of its connectivity control, application inspection, and worm, virus, and other malware remediation technologies. The Cisco Adaptive Security Appliances (ASA) firewall can also be used as a specialized remote access device using its Virtual Private Network features. As another option, the Cisco Adaptive Security Appliances 5500 Series firewall serves capably in the network interior for interdepartmental connectivity management and to guard against malware internal users may inadvertently introduce into the network. In small company and satellite office networks, the Cisco Adaptive Security Appliances firewall acts as a total solution platform offering comprehensive threat defense and VPN functionality while suiting the cost structure and performance models of such situations.

This adaptive single-platform, many-solution approach minimizes the number of devices that need to be installed and managed while providing a standard operating and management system across all those installations. This approach streamlines the education of setup, tracking, troubleshooting, and protection personnel. To further reduce maintenance expenses, Cisco ASA 5500 Series firewalls are also exceptionally network conscious, enabling them to insert gracefully into the network without disrupting authorized traffic and applications.

How Progent's Consultants Can Assist You with Cisco Firewalls
Cisco's ASA 5500 Series adaptive security appliances and PIX firewalls provide a wealth of setup, tracking, and troubleshooting features which offer you the ability to configure these security appliances to match your business needs. Progent's CCIE authorized network consultants can assist you to support your current network infrastructure that includes Cisco ASA or PIX firewall technology and that provides protection, resilience, performance, and recoverability. Progent's firewall experts can also help your organization to migrate to Cisco ASA 5500-X firewalls with Firepower Services.

Progent's GISA and CISM-certified IS security consultants can assist you to develop a security policy appropriate for your business and can set up your firewall to support your security policies. Progent's security evaluation consultants can assess the effectiveness of your current firewall deployment and audit the overall security of your whole IS network. Progent's Help Desk support team can deliver urgent remote technical support for Cisco technology and offer fast access to a Cisco CCIE expert.

To see additional details concerning Progent's professional help for Cisco networking products, choose a subject:

Integration of Cisco and Third-party Firewall Technology
Progent offers expertise in firewall and VPN products from all major vendors and can help you integrate Cisco technology with additional security solutions to help you build a cost-effective network infrastructure that provides a level of security and flexibility appropriate for your business. Third-party firewall and VPN support services available from Progent include: To get in touch with Progent about engineering help for Cisco products, phone 1-800-993-9400 or see Contact Progent.



An index of content::







  • © 2002-2026 Progent Corporation. All rights reserved.