Cisco ASA5500-SC-5= - ASA 5500 Security Context Datasheet

Adaptive security appliances asa software version 7.0

Advertisement

Quick Links

DATA SHEET
CISCO ASA SOFTWARE VERSION 7.0
®
Cisco
ASA 5500 Series adaptive security appliances deliver numerous market-leading, high-performance security and
VPN services for small and medium-sized businesses (SMBs), enterprises, and service providers—in addition to providing
unprecedented services flexibility and extensibility and lower deployment and operations costs.
PRODUCT OVERVIEW
®
Cisco
ASA 5500 Series adaptive security appliances are purpose-built solutions that combine best-of-breed security and VPN services with the
innovative Cisco Adaptive Identification and Mitigation (AIM) architecture. Designed as a key component of the Cisco Self-Defending Network,
the Cisco ASA 5500 Series provides proactive threat defense that stops attacks before they spread through the network, controls network activity and
application traffic, and delivers flexible VPN connectivity. The result is a powerful multifunction network security appliance family that provides the
security breadth and depth for protecting SMBs and enterprise networks while reducing the overall deployment and operations costs and
complexities associated with providing this new level of security.
The Cisco ASA 5500 Series delivers a powerful combination of multiple market-proven technologies in a single platform, making it operationally
and economically feasible to deploy comprehensive security services to more locations. And its multifunction security profile virtually eliminates the
difficult—and risky—decision of making trade-offs between robust security protection and the operational costs associated with multiple devices in
numerous locations.
The Cisco ASA 5500 Series helps businesses more effectively and efficiently protect their networks while delivering exceptional investment
protection through the following key elements:
Market-proven security and VPN capabilities—Full-featured, high-performance firewall, intrusion prevention system (IPS), network antivirus,
and IP Security/Secure Sockets Layer (IPSec/SSL) VPN technologies deliver robust application security, user- and application-based access
control, worm and virus mitigation, malware protection, and remote user and site connectivity.
Extensible Adaptive Identification and Mitigation services architecture—Taking advantage of a modular services processing and policy
framework, the Cisco Adaptive Identification and Mitigation architecture enables the application of specific security or network services on
a per traffic flow basis, delivering highly granular policy controls and anti-x protection with streamlined traffic processing. The efficiencies
of the Cisco ASA 5500 Series AIM architecture, as well as software and hardware extensibility through user-installable security services
modules (SSMs), advance the evolution of existing services as well as deployment of new services without requiring a platform replacement
or performance compromise. As the architectural foundation of the Cisco ASA 5500 Series, AIM enables highly customizable security policies
and unprecedented services extensibility to help protect against the fast-evolving threat environment.
Reduced deployment and operations costs—These multifunction appliances allow for platform, configuration, and management standardization,
helping decrease the costs of deployment and ongoing operations.
MARKET-PROVEN SECURITY AND VPN CAPABILITIES
The Cisco ASA 5500 Series leverages Cisco's expertise in developing industry-leading and award-winning security and VPN solutions, and
integrates the latest technologies from Cisco PIX
Cisco VPN 3000 Series Concentrators. By combining these technologies, the Cisco ASA 5500 Series delivers an unmatched, best-of-breed solution
that stops the broadest range of threats and provides businesses with flexible, secure connectivity options. The breadth and depth of security and
networking services provided by the Cisco ASA 5500 Series enable it to protect any area of the network, including the most common threat vectors
such as mobile users, remote sites, and unmanaged desktops and servers. As a key component of the Cisco Adaptive Threat Defense and flexible
All contents are Copyright © 1992–2005 Cisco Systems, Inc. All rights reserved. Important Notices and Privacy Statement.
®
500 Series Security Appliances, Cisco IPS 4200 Series Intrusion Prevention Systems, and
Page 1 of 19

Advertisement

Table of Contents
loading

Summary of Contents for Cisco ASA5500-SC-5= - ASA 5500 Security Context

  • Page 1 The breadth and depth of security and networking services provided by the Cisco ASA 5500 Series enable it to protect any area of the network, including the most common threat vectors such as mobile users, remote sites, and unmanaged desktops and servers.
  • Page 2: Application Security

    Advanced Detection Techniques To help ensure that threats do not go unnoticed, the Cisco ASA 5500 Series offers numerous methods to identify policy violations, anomalous activity, and vulnerability exploitation. They include stateful pattern recognition for stopping attacks hidden inside a data stream; protocol analysis to validate network traffic;...
  • Page 3 Internet, without compromising the integrity of the corporate security policy. By integrating VPN services with the wide range of security services offered by the Cisco ASA 5500 Series, businesses benefit from a stronger, more secure VPN connectivity.
  • Page 4 Intelligent Network Integration The Cisco ASA 5500 Series takes advantage of more than 20 years of Cisco networking leadership and innovation, and delivers a wide range of intelligent networking services for seamless integration into today’s diverse network environments. Key network integration services include: Layer 2 transparent firewall—Provides the ability to rapidly deploy Cisco ASA 5500 Series appliances into existing networks without requiring...
  • Page 5 In small business and branch office environments, the Cisco ASA 5500 Series serves as an “all-in-one”...
  • Page 6 Next-Generation Centralized Management Solutions Cisco ASA 5500 Series appliances running Cisco ASA Software Version 7.0 can be centrally managed using the upcoming follow-on software release to CiscoWorks VPN/Security Management Solution (VMS) 2.3. This highly scalable, next-generation, three-tier management solution will...
  • Page 7 FEATURES AND BENEFITS OF CISCO ASA SOFTWARE VERSION 7.0 Cisco ASA Software Version 7.0 for Cisco ASA 5500 Series adaptive security appliances provides a wealth of features, including those detailed in Table 1. A complete list of features is available in the release notes.
  • Page 8 Microsoft Windows Messenger, while delivering advanced services such as call forwarding, call transfers, and more • SCCP Security Services Provides secure integration of Cisco SCCP-based IP telephony services with Cisco CallManager Version 4.1 while successfully connecting calls over multiprotocol VoIP environments across NAT and PAT boundaries MGCP Security Services •...
  • Page 9 Uses auto-update capability to download the latest threat information from Cisco.com (refer to Cisco Services for IPS for more information) These features are available only when an AIP SSM is installed in a Cisco ASA 5500 Series appliance. • Multi-Vector Threat...
  • Page 10 NAT and PAT boundaries as well as Cisco TCP and UDP NAT traversal methods • Allows administrators to require that all traffic from a remote VPN client be sent up to the Cisco ASA 5500 Series appliance, allowing Internet-destined traffic from remote-access user VPN tunnels to leave through the same...
  • Page 11 • Cisco ASA 5500 Series appliances that are configured as a failover pair continuously synchronize their connection state and device configuration data. In the event of a system or network failure, network sessions are...
  • Page 12 Cisco ASA 5500 Series appliance • Supports up to 10 VLANs on Cisco ASA 5510 appliances (with the Security Plus license), 25 VLANs on Cisco ASA 5520 appliances, and 100 VLANs on Cisco ASA 5540 appliances OSPF Dynamic Routing •...
  • Page 13 Provides a wide range of informative, real-time, and historical reports that give critical insight into usage trends, performance baselines, and security events • Command Line Interface Allows customers to use existing Cisco PIX Security Appliance and Cisco IOS Software CLI knowledge for easy (CLI) installation and management without additional training •...
  • Page 14: Product Licensing

    Security Context Licenses The Cisco ASA 5520 and 5540 can support up to 10 and 50 security contexts, respectively, where each context has its own separate security policies and administrative domain. These appliances include two contexts by default, and those contexts can be used for either Active/Active high ©...
  • Page 15: Product Specifications

    Cisco ASA 5520 Adaptive Security Appliance VPN Plus License Businesses can extend the IPSec and SSL VPN capacity of their Cisco ASA 5520 with a VPN Plus license, which more than doubles the platform VPN capacity to support up to 750 concurrent VPN connections from mobile users, remote sites, and business partners.
  • Page 16 Cisco PIX Security Appliance Software versions 6.2 and 6.3 Cisco Site-to-Site VPN Compatibility In addition to providing interoperability for many third-party VPN products, Cisco ASA 5500 Series appliances interoperate with the Cisco VPN products listed in Table 3 for site-to-site VPN connectivity: Table 3.
  • Page 17: System Requirements

    X.509 Certificate Enrollment Methods • Simple Certificate Enrollment Protocol (SCEP) • Manual (PKCS #7 and #10) SYSTEM REQUIREMENTS Table 5 lists system requirements for Cisco ASA 5500 Series appliances running Cisco ASA Software Version 7.0. Table 5. System Requirements System Requirement Description •...
  • Page 18: To Download The Software

    SERVICE AND SUPPORT Cisco offers a wide range of services programs to accelerate customer success. These innovative service programs are delivered through a unique combination of people, processes, tools, and partners, resulting in high levels of customer satisfaction. Cisco services help you protect your network investment, optimize network operations, and prepare your network for new applications to extend network intelligence and the power of your business.
  • Page 19 2005 Cisco Systems, Inc. All rights reserved. CCSP, CCVP, the Cisco Square Bridge logo, Follow Me Browsing, and StackWise are trademarks of Cisco Systems, Inc.; Changing the Way We Work, Live, Play, and Learn, and iQuick Study are service marks of Cisco Systems, Inc.; and Access Registrar, Aironet, ASIST, BPX, Catalyst, CCDA, CCDP,...
  • Page 20 © 2005 Cisco Systems, Inc. All rights reserved. Important notices, privacy statements, and trademarks of Cisco Systems, Inc. can be found on cisco.com. Page 20 of 20...

This manual is also suitable for:

Asa 5500 series

Table of Contents