CISCO
PIX 525 Security Appliance - Datasheet
The Cisco® PIX® 525 Security Appliance delivers enterprise-class
security for medium-to-large enterprise networks, in a reliable,
purpose-built appliance. Its modular two-rack unit (2RU) design
incorporates two 10/100 Fast Ethernet interfaces and supports a
combination of up to six additional 10/100 Fast Ethernet interfaces or
three additional Gigabit Ethernet interfaces, making it an ideal choice
for businesses requiring a high performance, Gigabit Ethernet-ready
solution that provides solid investment protection. Part of the
market-leading Cisco PIX Security Appliance Series, the Cisco PIX 525
Security Appliance provides a wide range of rich, integrated security
services, hardware VPN acceleration, and powerful remote management
capabilities in a cost-effective, highly-resilient solution.
Rich Network Integration Improves Network Resiliency And Simplifies
Deployment
Cisco PIX Security Appliances include a variety of advanced networking
features for smooth integration into today's diverse enterprise network
environments. Administrators can easily integrate Cisco PIX Security
Appliances into switched network environments by taking advantage of
native support of 802.1q-based VLAN support. Cisco IP phones can benefit
from the "zero-touch provisioning" services provided by Cisco
PIX Security Appliances, which help the phones automatically register with
the appropriate Cisco CallManager and download any additional
configuration information and software images. Companies can also improve
their overall network resiliency by taking advantage of the robust Open
Shortest Path First (OSPF) dynamic routing services provided by Cisco PIX
Security Appliances, which can detect network outages within seconds and
route around them
Robust Remote-Management Solutions Lower Total Cost Of Ownership
The Cisco PIX 525 Security Appliance is a reliable, easy-to-maintain
platform that provides a wide variety of configuration, monitoring, and
troubleshooting methods. Management solutions range from centralized,
policy-based management tools to integrated, Web-based management to
support for remote monitoring standards such as Simple Network Management
Protocol (SNMP) and syslog.
Administrators can easily manage large numbers of remote Cisco PIX
Security Appliances using CiscoWorks VPN/Security Management Solution
(VMS).
This suite consists of several integrated software modules including
Management Center for Firewalls, Auto Update Server Software, and Security
Monitor. This powerful combination provides a highly scalable,
next-generation, three-tier management solution that includes the
following features:
-
Comprehensive configuration and software image management
-
Device hierarchy with configuration inheritance based on
"Smart Rules"
-
Customizable administrative roles and access privileges
-
Comprehensive enterprise change management and auditing
-
"Touchless" software image management for remote Cisco
PIX Security Appliances
-
Support for dynamically addressed appliances
|
CISCO
PIX 535 Security Appliance - Datasheet
The Cisco® PIX® 535 Security Appliance delivers enterprise-class
security for large enterprise and service provider networks, in a high
performance, purpose-built appliance. Its highly modular three-rack unit
(3RU) design supports a combination of up to 10 10/100 Fast Ethernet
interfaces or nine Gigabit Ethernet interfaces as well as redundant power
supplies, making it an ideal choice for businesses requiring the highest
levels of performance, port density, reliability, and investment
protection. Part of the market-leading Cisco PIX Security Appliance
Series, the Cisco PIX 535 Security Appliance provides a wide range of
rich, integrated security services, hardware VPN acceleration, and
powerful remote management capabilities in a highly scalable,
high-performance solution.
Enterprise-Class Security For Large Enterprise And Service Provider
Networks
The Cisco PIX 535 Security Appliance delivers a multilayered defense
for large enterprise and service provider networks through rich,
integrated security services, including stateful inspection firewall
services, advanced application and protocol inspection, site-to-site and
remote access VPN, inline intrusion prevention, and robust multimedia and
voice security-all in a single, integrated solution.
Cisco PIX Security Appliances incorporate the state-of-the-art Cisco
Adaptive Security Algorithm, which provides stateful inspection firewall
services by tracking the state of all authorized network communications
and by preventing unauthorized network access. As an additional layer of
security, Cisco PIX Security Appliances integrate more than 24
purpose-built inspection engines that perform in-depth Layers 4-7
inspection of network traffic flows for many of today's popular
applications and protocols. To defend networks from application layer
attacks and to give businesses more control over applications and
protocols in their environment, these inspection engines incorporate
extensive application and protocol knowledge and employ security
enforcement technologies that range from protocol conformance checking,
application and protocol state tracking, Network Address Translation (NAT)
services, and attack detection and mitigation techniques such as protocol
field length checking and URL length checking.Administrators can easily
create custom security policies using the many flexible access control
technologies provided by Cisco PIX Security Appliances including network
and service object groups, turbo access control lists (ACLs), user and
group-based policies, and more than 100 predefined applications and
protocols. By combining these flexible access control technologies with
the powerful stateful inspection firewall services and advanced
application and protocol inspection services that Cisco PIX Security
Appliances provide, businesses can easily enforce their network security
policies and protect their networks from attack.
Flexible VPN Services Extend Networks Economically To Remote
Offices And Mobile Users
Using the full-featured VPN capabilities of the Cisco PIX 535 Security
Appliance, businesses can securely extend their networks across low-cost
Internet connections to mobile users, business partners, and remote
offices worldwide. Solutions supported range from standards-based
site-to-site VPN using the Internet Key Exchange (IKE) and IP Security (IPSec)
VPN standards, to the innovative Cisco Easy VPN capabilities found in
Cisco PIX Security Appliances and other Cisco Systems® security
solutions-such as Cisco IOS® routers and Cisco VPN 3000 Series
Concentrators. Cisco Easy VPN delivers a uniquely scalable,
cost-effective, and easy-to-manage remote-access VPN architecture that
eliminates the operational costs associated with maintaining the
remote-device configurations that are typically required by traditional
VPN solutions. Cisco PIX Security Appliances encrypt data using 56-bit
Data Encryption Standard (DES), 168-bit Triple DES (3DES), or up to
256-bit Advanced Encryption Standard (AES) encryption. Certain Cisco PIX
535 Security Appliance models have integrated hardware VPN acceleration
capabilities, delivering highly scalable, high-performance VPN services.
Integrated Intrusion Prevention Guards Against Popular Internet
Threats
The integrated inline intrusion prevention capabilities of the Cisco
PIX 535 Security Appliance can protect large enterprise and service
provider networks from many popular forms of attacks, including
denial-of-service (DoS) attacks and malformed packet attacks. Using a
wealth of advanced intrusion-prevention features, including DNSGuard,
FloodGuard, FragGuard, MailGuard, IPVerify, and TCP intercept, in addition
to looking for more than 55 different attack "signatures," Cisco
PIX Security Appliances keep a vigilant watch for attacks, can optionally
block them, and can provide real-time notification to administrators.
Award-Winning Resiliency Provides Maximum Business Uptime
Select models of Cisco PIX 535 Security Appliances provide stateful
failover capabilities that help to ensure resilient network protection for
enterprise network environments. Employing a cost-effective,
active-standby, high-availability architecture, Cisco PIX Security
Appliances that are configured as a failover pair continuously synchronize
their connection state and device configuration data. Synchronization can
take place over a high-speed LAN connection, providing another layer of
protection through the ability to geographically separate the failover
pair. In the event of a system or network failure, network sessions are
automatically transitioned between appliances, with complete transparency
to users.
|