Members

Blog Posts

Firewall CISCO ASA5585-S10-K8 ASA 5585-X Chassis with SSP10, 8GE, 2GE Mgt, 1 AC, DES

Modern corporate networks are trying to keep up with mobile users.

Mobile device performance levels increase, applications become more complex, and users expect network resources to be accessed from their many devices. Despite this, safety remains a priority. Cisco ASA 5585-X Next-Generation Firewall, a compact yet high-density firewall that provides high scalability, performance, and security in a 2RU device.

Using a single firewall, the Cisco ASA 5585-X meets the growing needs of dynamic organizations with eight times the performance density, very high VPN sessions, twice the connections per second, and four times the bandwidth of any competitive firewall.

Firewall capabilities
Support for Layer 3 and Layer 4 firewall health checks, including access control and network address translation, enables organizations to maintain existing health check policies that are required to comply with regulatory requirements. Cisco Intrusion Prevention System (IPS) context-sensitive services provide the ability to act smarter and more aggressively against threats that pose significant risk to organizations.

In addition to comprehensive health checking capabilities, Layer 7 policies act intelligently on contextual information. Cisco AnyConnect technology provides information about the type and location of a mobile device before it accesses the network so that administrators can maintain a high level of network security and control. Threat defenses from Cisco Collective Security Intelligence (CSI) leverage Cisco's global security deployment capabilities to analyze approximately one-third of the world's Internet traffic to provide near-constant protection against zero-day threats.

Flexible deployment options
The Cisco ASA 5585-X supports two hardware blades in a single 2RU chassis. The bottom slot (slot 0) houses the firewall module for checking the status of the ASA, while the top slot (slot 1) can be used to add a dedicated Cisco IPS, Cisco ASA with FirePOWER Services, or a second firewall module for checking the state. Multiple integrated security services within a single chassis provide broad deployment flexibility and investment protection. The ability to add a second stateful firewall engine improves firewall efficiency, providing superior scalability, performance, and security for use in data centers. Moreover,

Clustering
Using Cisco ASA Software Release 9.0 and later, customers can aggregate up to 16 Cisco ASA 5585-X Firewalls in a single cluster with up to 640 Gbps throughput, 2M connections per second, and over 100M concurrent connections. This pay-as-you-grow model allows organizations to buy what they need today and dynamically add more as their productivity grows. To protect high-performance data centers from internal and external threats, the cluster can be supplemented by the addition of IPS modules.

Cisco ASA Software Clustering provides a consistent scaling factor, regardless of the number of blocks in the cluster, for linear and predictable performance gains. Complexity is reduced as no changes are required for existing Layer 2 and Layer 3 networks. Support for data center designs based on the Cisco Catalyst 6500 Virtual Switching System (VSS) and Cisco Virtual PortChannel (vPC) and Link Aggregation Control Protocol (LACP) provides high availability (HA) with better network integration.

For operational efficiency, Cisco ASA clusters are easy to manage and troubleshoot. Policies that are moved to the master are replicated across all blocks in the cluster. Health, performance, and capacity statistics for the entire cluster, as well as individual organizational units within the cluster, can be viewed from a single management console. Automatic software updates are supported to simplify device upgrades.

Clustering supports HA in active / active and active / passive modes. All OUs in the cluster are actively forwarding traffic, and all connection information is replicated to at least one other unit in the cluster to support N + 1 HA. In addition, single and multiple contexts are supported, as well as routed and transparent modes. One configuration is supported across all modules in the cluster using automatic configuration synchronization. Cluster statistics are provided to track resource usage.

Cisco TrustSec Integration
Using Cisco ASA Software Release 9.0 and later, the Cisco ASA 5585-X provides contextual awareness by integrating firewall security based on Cisco TrustSec security group identities and tags for improved visibility and control. Identity-based firewall security provides more flexible access control to enforce policies based on user and group ID and access point. Administrators can create policies that conform to business rules, a process that improves security, enhances usability, and requires fewer policies to manage. Likewise, the Cisco TrustSec integration allows security group tags to be embedded in the network,

Reduce costs while increasing productivity and safety
The Cisco ASA 5585-X Next-Generation Firewall provides superior scalability, performance, and security for processing large amounts of data without sacrificing performance. Most firewalls require up to 16RU and 5100 watts to achieve the level of performance that the Cisco ASA 5585-X provides at only 2RU and 785 watts. This performance helps enterprises meet growing network connectivity requirements without having to invest in additional data center space and incur associated maintenance costs.

Based on tests conducted by Cisco, the Cisco ASA 5585-X significantly reduces initial procurement costs by 80 percent, energy costs by 85 percent, and rack space requirements by 88 percent, while significantly reducing overall integration and management complexity and costs. ... In addition, you can install up to two firewall modules in a single Cisco ASA 5585-X chassis for scalability up to 80 Gbps.

For more information about: firewall definition

Views: 3

Comment

You need to be a member of On Feet Nation to add comments!

Join On Feet Nation

© 2024   Created by PH the vintage.   Powered by

Badges  |  Report an Issue  |  Terms of Service