PIX/ASA Features
Số trang: 2
Loại file: pdf
Dung lượng: 35.46 KB
Lượt xem: 4
Lượt tải: 0
Xem trước 2 trang đầu tiên của tài liệu này:
Thông tin tài liệu:
The PIX/ASA is a powerful stateful packet-inspection firewall with some basic application-inspection capabilities.
Nội dung trích xuất từ tài liệu:
PIX/ASA FeaturesPIX/ASA FeaturesThe PIX/ASA is a powerful stateful packet-inspection firewall with some basicapplication-inspection capabilities. One of the nice things about the PIX/ASA firewall isthat fundamentally all hardware models run pretty much the same software (with thenotable exception being the PIX 501 and PIX 506E, which will not run the newest PIX7.x software, as discussed in the section Cisco PIX Firewall and ASA Models). For thePIX firewall, these features include the following: • Failover functionality whereby two PIXs can provide high-availability services to a network. This functionality is only supported in PIX 515E or larger firewalls and is supported in both active/passive or active/active (for PIX software 7.x or newer) modes of operation. • Zero-downtime software upgrades. • DHCP server. The PIX now has a built-in DHCP server to provide address allocations for remote office or branch offices. • Object grouping. Administrators can now group network objects (such as devices, networks, and services) into logical groups to simplify access control list (ACL) definition and maintenance. • ACLs for controlling traffic access both inbound and outbound. The PIX can also precompile the ACLs using turbo ACLs, which provides for enhanced performance. • Command-level authorization for role-based access control. • Network Address Translation (NAT)both unidirectional as well as bidirectional to support overlapping private address ranges. • Network Time Protocol (NTP) support for clock synchronization to a time server. • Simple Network Management Protocol (SNMP) monitoring with CPU monitoring using SNMPv2. • Virtual firewall services (PIX software 7.x). • Layer 2 transparent firewall (PIX software 7.x). • Software and configuration updates via HTTP and HTTPS. • HTTPS-based command-line interface (CLI) access. • VPN services providing both LAN-to-LAN and remote-access VPN services. • PPP over Ethernet (PPPoE) support for users connecting the PIX to an xDSL interface (not supported in PIX software 7.x). • Quality of service (QoS) (PIX software 7.x). • Tunneling application control to block and prevent applications that tunnel through web application ports such as instant messaging, peer-to-peer file share, and other applications such as GoToMyPC. • IPv6 networking. • Secure Shell Version 2 (SSHv2) and SNMPv2C (PIX software 7.x). • Multicast support for multimedia applications. • Port Address Translation (PAT) for H.323 and Session Initiation Protocol (SIP) for voice applications. • Deep packet inspection for services such as HTTP, FTP, Extended Simple Mail Transfer Protocol (ESMTP), and more. • Intrusion detection signatures for packet inspection. • VLAN support.These are just some of the features available in the PIX firewall. For a complete listing offeatures, refer to http://www.cisco.com/go/pix andhttp://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_data_sheet0900aecd80225ae1.html.The ASA Security Appliance shares many of the same features as the PIX firewall, aswell as a few additional ASA-specific features, including the following: • IPS • Network antivirus, antispam, and antiphishing capabilities • Dedicated out-of-band management interfacesFor a complete listing of features, refer to http://www.cisco.com/go/asa andhttp://www.cisco.com/en/US/products/ps6120/prod_models_comparison.html
Nội dung trích xuất từ tài liệu:
PIX/ASA FeaturesPIX/ASA FeaturesThe PIX/ASA is a powerful stateful packet-inspection firewall with some basicapplication-inspection capabilities. One of the nice things about the PIX/ASA firewall isthat fundamentally all hardware models run pretty much the same software (with thenotable exception being the PIX 501 and PIX 506E, which will not run the newest PIX7.x software, as discussed in the section Cisco PIX Firewall and ASA Models). For thePIX firewall, these features include the following: • Failover functionality whereby two PIXs can provide high-availability services to a network. This functionality is only supported in PIX 515E or larger firewalls and is supported in both active/passive or active/active (for PIX software 7.x or newer) modes of operation. • Zero-downtime software upgrades. • DHCP server. The PIX now has a built-in DHCP server to provide address allocations for remote office or branch offices. • Object grouping. Administrators can now group network objects (such as devices, networks, and services) into logical groups to simplify access control list (ACL) definition and maintenance. • ACLs for controlling traffic access both inbound and outbound. The PIX can also precompile the ACLs using turbo ACLs, which provides for enhanced performance. • Command-level authorization for role-based access control. • Network Address Translation (NAT)both unidirectional as well as bidirectional to support overlapping private address ranges. • Network Time Protocol (NTP) support for clock synchronization to a time server. • Simple Network Management Protocol (SNMP) monitoring with CPU monitoring using SNMPv2. • Virtual firewall services (PIX software 7.x). • Layer 2 transparent firewall (PIX software 7.x). • Software and configuration updates via HTTP and HTTPS. • HTTPS-based command-line interface (CLI) access. • VPN services providing both LAN-to-LAN and remote-access VPN services. • PPP over Ethernet (PPPoE) support for users connecting the PIX to an xDSL interface (not supported in PIX software 7.x). • Quality of service (QoS) (PIX software 7.x). • Tunneling application control to block and prevent applications that tunnel through web application ports such as instant messaging, peer-to-peer file share, and other applications such as GoToMyPC. • IPv6 networking. • Secure Shell Version 2 (SSHv2) and SNMPv2C (PIX software 7.x). • Multicast support for multimedia applications. • Port Address Translation (PAT) for H.323 and Session Initiation Protocol (SIP) for voice applications. • Deep packet inspection for services such as HTTP, FTP, Extended Simple Mail Transfer Protocol (ESMTP), and more. • Intrusion detection signatures for packet inspection. • VLAN support.These are just some of the features available in the PIX firewall. For a complete listing offeatures, refer to http://www.cisco.com/go/pix andhttp://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_data_sheet0900aecd80225ae1.html.The ASA Security Appliance shares many of the same features as the PIX firewall, aswell as a few additional ASA-specific features, including the following: • IPS • Network antivirus, antispam, and antiphishing capabilities • Dedicated out-of-band management interfacesFor a complete listing of features, refer to http://www.cisco.com/go/asa andhttp://www.cisco.com/en/US/products/ps6120/prod_models_comparison.html
Tìm kiếm theo từ khóa liên quan:
công nghệ thông tin an ninh bảo mật fire wall tường lửa Fire wall fundamentals PIX/ASA FeaturesGợi ý tài liệu liên quan:
-
52 trang 431 1 0
-
Top 10 mẹo 'đơn giản nhưng hữu ích' trong nhiếp ảnh
11 trang 316 0 0 -
74 trang 302 0 0
-
96 trang 293 0 0
-
Báo cáo thực tập thực tế: Nghiên cứu và xây dựng website bằng Wordpress
24 trang 289 0 0 -
Đồ án tốt nghiệp: Xây dựng ứng dụng di động android quản lý khách hàng cắt tóc
81 trang 281 0 0 -
EBay - Internet và câu chuyện thần kỳ: Phần 1
143 trang 275 0 0 -
Tài liệu dạy học môn Tin học trong chương trình đào tạo trình độ cao đẳng
348 trang 269 1 0 -
Tài liệu hướng dẫn sử dụng thư điện tử tài nguyên và môi trường
72 trang 265 0 0 -
64 trang 263 0 0