Cisco PIX family firewalls and Cisco ASA 5500 Series firewalls combine comprehensive firewall, intrusion protection, and Virtual Private Network functionality in a cost-effective, one-cabinet package. Both of these product families have been superseded by Cisco's ASA 5500-X series of firewalls with Firepower Services. (See integration and troubleshooting expertise for Cisco AA 5500-X firewalls with Firepower Services.) Still, both PIX and previous-generation ASA 5500 Series firewalls are widely used and continue to provide small and mid-size companies a viable security environment.
PIX and legacy ASA 5500 firewalls deliver powerful user and application policy enforcement, mutlivector assault defense, and safe access services. The increased intelligence sharing of integrated protection features in a single package offers customers deploying these integrated firewalls the advantages of advanced security, reduced cost of ownership, and smaller management expense.
PIX security appliances and Cisco's ASA 5500 product line join Cisco IOS Firewall, the Firewall Services Module (FWSM) for Cisco Catalyst 6500 Series switches, and Cisco 7600 routers as components of Cisco's flexible, integrated firewall line. Engineered with a scalable, building-block platform, each offering is equipped with a specific array of options to deliver more efficient protection to different network situations. These solutions can be independently deployed to protect specific areas of the connectivity infrastructure, or can be combined for a layered, defense-in-depth strategy following the design best practices outlined in the Cisco SAFE framework. Completing the modular firewall product line, Cisco provides a complete security management portfolio, ranging from Cisco security appliance and Cisco IOS security components and embedded appliance controllers, to self-contained management applications, moving to ensure that customers can effectively use their Cisco security infrastructure investments.
Cisco PIX Firewall Appliances
Cisco PIX Security Appliance Series offer reliable user and application policy enforcement, multivector invasion defense, and safe connectivity services in cost-effective, out-of-the-box modules. These purpose-built devices provide a broad range of built-in security and networking services such as process-aware firewall features, VoIP and multimedia security, robust multi-site and remote-access IPcec Virtual Private Network networking, high availability, smart networking features, and flexible administration options. The Cisco PIX firewall Appliance product line spans small plug-and-play devices for small and at home offices to stackable high-bandwidth products with ROI for enterprise and service-provider environments, Cisco PIX firewall appliances provide dependable protection, speed, and reliability for network environments of all sizes.

Based upon a tested, purpose-built software platform that offers rich security features, PIX security appliances provide a high level of security and have received Common Criteria Evaluation Assurance Level (EAL) 4 status and ICSA Firewall and IP Security qualification. Cisco PIX firewall appliances offer protection for a wide range of VoIP and additional mixed-media standards such as H.323 Version 4, SIP, SCCP, Real-Time Streaming Protocol (RTSP), and Media Gateway Control Protocol, helping businesses to safeguard deployments of a broad range of current and next-generation VoIP and video applications.
PIX security appliances offer a variety of configuration, tracking, and analysis options, providing businesses the versatility to utilize the techniques that best match their needs. Administrative solutions include common, policy-based management tools, integrated web-based administration, and support for remote-tracking standards such as Simple Network Management Protocol and syslog. The integrated Adaptive Security Device Manager system offers a powerful web-based management platform that greatly streamlines the deployment, in-place configuration, and monitoring of a single Cisco PIX firewall without requiring any additional utility other than a standard web browser and Java applet to be installed on a manager's PC.
IT managers can furthermore remotely configure, track, and troubleshoot Cisco PIX firewalls using a CLI interface. Secure command-line interface (CLI) communication is possible through a number of methods including Secure Shell (SSHv2) Protocol, Telnet over IP Security, and out-of-band through a console port. Cisco PIX firewall appliances also include robust automatic-update features, a set of protected remote-administration options that ensure firewall settings and software images are always current.
Cisco Adaptive Security Appliances (ASA) 5500 Series Firewalls
Cisco ASA Firewalls are purpose-built devices that bring together market-proven, best-of-breed security and VPN services with an adaptive design. The result is a robust, multifunction network protection appliance better suited to protect small and midsize business (SMB) and enterprise networks and, simultaneously, lower the total installation and operations expenses formerly required for this high degree of security.

Cisco Adaptive Security Appliances (ASA) 5500 Series firewalls provide a high-level of application protection through smart, application-sensitive inspection processes that analyze network flows at Layers 4-7. The result is a better protected environment including web, voice, and mobile wireless access. To defend networks from application-layer attacks and to give organizations more control over the programs and protocols used in their environments, Cisco's inspection engines integrate broad application and protocol knowledge and employ security enforcement technologies that include protocol anomaly detection and state monitoring. Also included are assault sensing and remediation technology including application and protocol command filtering and URL deobfuscation. Cisco ASA 5500 Series firewall inspection engines also deliver control over IM and tunneling applications, enabling organizations to enforce usage policies and preserve network bandwidth for important business applications.
At the same time as increasing security, Cisco ASA firewalls also decrease deployment and support expenses. By offering extensive VPN and security functions, the Cisco Adaptive Security Appliances firewall can be a single device for many environments, allowing platform commonality. The Cisco ASA firewall can be used as a consolidated threat-protection appliance at a central location by leveraging its access control, application inspection, and malicious assault remediation technologies. The Cisco Adaptive Security Appliances (ASA) firewall can also be deployed as a specialized remote access solution utilizing its Virtual Private Network capabilities. As an alternative, the Cisco Adaptive Security Appliances (ASA) firewall serves capably in the network interior for interdepartmental connectivity control and to defend against malware inside workers may inadvertently introduce into the environment. In small company and branch office environments, the Cisco ASA firewall acts as an all-in-one platform providing complete intrusion defense and Virtual Private Network functionality while fitting within the budgets and performance models of such deployments.
This versatile one-device, many-solution approach reduces the number of devices that must be deployed and managed while providing a common functional and administrative environment across all deployments. This architecture simplifies the education of configuration, monitoring, support, and protection staff. To further minimize maintenance costs, Cisco Adaptive Security Appliances (ASA) 5500 Series firewalls are also highly network aware, enabling them to insert seamlessly into the network without interfering with legitimate data flow and processes.
How Progent's Cisco Certified Experts Can Help You with Cisco PIX and ASA Firewalls
Cisco ASA Series firewalls and PIX security appliances incorporate a wealth of setup, monitoring, and troubleshooting options that give you the ability to set up these security appliances to align optimally with your business requirements. Progent's CCIE authorized network consultants can help you to maintain your existing network infrastructure that incorporates Cisco ASA or PIX security appliances and that provides protection, resilience, throughput, and recoverability. Progent can also assist you to migrate to Cisco ASA 5500-X firewalls with Firepower Services.
Progent's GISA and CISSP-ISSP-certified IS security consultants can assist your business to create a security policy appropriate for your environment and can configure your security appliance to enforce your security policies. Progent's risk evaluation engineers can assess the effectiveness of your current firewall deployment and audit the security of your entire IS environment. Progent's Help Desk support team can deliver urgent online technical support for Cisco technology and offer fast access to a Cisco network engineer.
Integration of Cisco and Third-party Firewall Technology
Progent offers expertise in firewall and VPN products from all major vendors and can help you integrate Cisco technology with additional security solutions to help you build a cost-effective network infrastructure that provides a level of security and flexibility appropriate for your business. Third-party firewall and VPN support services available from Progent include: