• Advanced Application-Aware Firewall Services
• Market-Leading Voice-Over-IP and Multimedia Security
• Robust Site-to-Site and Remote Access IPSec VPN Connectivity
• Award-Winning Resiliency
• Intelligent Networking Services
• Flexible Management Solutions
F
Advanced Firewall Services Deliver Strong Business Protection and Rich Application Control
Robust Stateful Inspection and Application Layer Security
Multi-Vector Attack Protection
Market-Leading VoIP Security Services Protect Next-Generation Converged Networks
Robust IPsec VPN Services Cost Effectively Connect Networks and Mobile Users
Award-Winning Resilient Architecture Provides Maximum Business Uptime
Intelligent Networking Services Enable Simplified Deployment and Seamless Network Integration
Flexible Management Solutions Lower Operational Costs
Next-Generation Centralized Management Solutions
• Comprehensive configuration and software image management
• Device hierarchy with "Smart Rules"-based configuration inheritance
• Customizable administrative roles and access privileges
• Comprehensive enterprise change management and auditing
• Intelligent discovery and optimization of security policies and object groups
• "Touchless" software image management for remote Cisco PIX Security Appliances
• Support for dynamically addressed appliances
Attack Mitigation and Event Monitoring Solutions
World-Class Device Management Solutions
Table 1. Product Features and Benefits
| Features | Benefit |
| Reliable and Expandable Security Appliance | |
| Purpose-Built Security Appliance |
• Uses a
proprietary,
hardened operating
system that
eliminates the
security risks
associated with
general-purpose
operating systems
• Combines Cisco
product quality with
no moving parts to
provide a highly
reliable security
platform
|
| Fast Ethernet Expansion Options |
• Supports easy
installation of
additional network
interfaces two PCI
expansion slots
• Supports expansion
cards including
single-port Fast
Ethernet and
four-port Fast
Ethernet cards
|
| Hardware VPN Acceleration |
• Delivers high
speed VPN services
through the addition
of either a VPN
Accelerator Card
(VAC) or a VPN
Accelerator Card+
(VAC+)-Unrestricted
(UR), Failover (FO)
and
Failover-Active/Active
(FO-AA) models have
integrated hardware
VPN acceleration
services
|
| Integration with Leading Third-Party Solutions |
• Supports the broad
range of Cisco
Technology Developer
partner solutions
that provide URL
filtering, content
filtering, virus
protection, scalable
remote management,
and more
|
| Industry Certifications and Evaluations |
• Earned numerous
leading industry
certifications and
evaluations,
including:
• Common Criteria
Evaluated Assurance
Level 4 (EAL4)
• Corporate RSSP
Category
• Network Equipment
Building Standards
(NEBS) Level-3
Compliant
|
| Advanced Firewall Services | |
| Stateful Inspection Firewall |
• Provides
wide-range of
perimeter network
security services to
prevent unauthorized
network access
• Delivers robust
stateful inspection
firewall services
which track the
state of all network
communications
• Provides flexible
access-control
capabilities for
more than 100
predefined
applications,
services, and
protocols, with the
ability to define
custom applications
and services
• Supports
inbound/outbound
ACLs for interfaces,
time-based ACLs, and
per-user/per-group
policies for
improved control
over network and
application usage
• Simplifies
management of
security policies by
giving
administrators the
ability to create
re-usable network
and service object
groups that can be
referenced by
multiple security
policies,
simplifying initial
policy definition
and ongoing policy
maintenance
|
| Advanced Application and Protocol Inspection |
• Integrates 30
specialized
inspection engines
that provide rich
application control
and security
services for
protocols such as
Hypertext Transfer
Protocol (HTTP),
File Transfer
Protocol (FTP),
Extended Simple Mail
Transfer Protocol
(ESMTP), Domain Name
System (DNS), Simple
Network Management
Protocol (SNMP),
Internet Control
Message Protocol
(ICMP), SQL*Net,
Network File System
(NFS), H.323
Versions 1-4,
Session Initiation
Protocol (SIP),
Cisco Skinny Client
Control Protocol
(SCCP), Real-Time
Streaming Protocol
(RTSP), GPRS
Tunneling Protocol
(GTP), Internet
Locator Service
(ILS), Sun Remote
Procedure Call
(RPC), and many more
|
| Modular Policy Framework |
• Provides a
powerful, highly
flexible framework
for defining flow-
or class-based
policies, enabling
administrators to
identify a network
flow or class based
on a variety of
conditions, and then
apply a set of
customizable
services to each
flow/class
• Improves control
over applications by
introducing ability
to have flow- or
class-specific
firewall/inspection
policies, QoS
policies, connection
limits, connection
timers, and more
|
| Security Contexts |
• Enables creation
of multiple security
contexts (virtual
firewalls) within a
single Cisco PIX
Security Appliance,
with each context
having its own set
of security
policies, logical
interfaces, and
administrative
domain
• Supports one
licensed level of
security contexts: 5
(maximum number of
security contexts
supported based on
model of Cisco PIX
Security Appliance)
• Provides
businesses a
convenient way of
consolidating
multiple firewalls
into a single
physical appliance
or failover pair,
yet retaining the
ability to manage
each of these
virtual instances
separately
• Enables service
providers to deliver
resilient
multi-tenant
firewall services
with a pair of
redundant appliances
|
| Layer 2 Transparent Firewall |
• Supports
deployment of a
Cisco PIX Security
Appliance in a
secure Layer 2
bridging mode,
providing rich Layer
2-7 firewall
security services
for the protected
network while
remaining
"invisible" to
devices on each side
of it
• Simplifies Cisco
PIX Security
Appliance
deployments in
existing network
environments by not
requiring businesses
to re-address the
protected networks
• Supports creation
of Layer 2 security
perimeters by
enforcing
administrator
defined
Ethertype-based
access control
policies for Layer 2
network traffic
|
| Multi-Vector Attack Protection |
• Provides wealth of
advanced attack
protection services
to defend businesses
from many popular
forms of attacks,
including
denial-of-service
(DoS) attacks,
fragmented attacks,
replay attacks, and
malformed packet
attacks
• Delivers advanced
TCP stream
reassembly and
traffic
normalization
services to assist
in detecting hidden
application and
protocol layer
attacks
• Integrates with
Cisco Network
Intrusion Prevention
System (IPS)
solutions to
identify and
dynamically block or
shun hostile network
nodes
|
| Authentication, Authorization, and Accounting (AAA) Support |
• Integrates with
popular AAA services
via TACACS+ and
RADIUS, with support
for redundant
servers for
increased AAA
services resiliency
• Provides highly
flexible user and
administrator
authentication
services, dynamic
per-user/per-group
policies, and
administrator
privilege control
through tight
integration with
Cisco Secure Access
Control Server (ACS)
|
| Robust IPSec VPN Services | |
| Cisco Easy VPN Server |
• Delivers
feature-rich remote
access VPN
concentrator
services for up to
2000 remote
software- or
hardware-based VPN
clients
• Pushes VPN policy
dynamically to Cisco
Easy VPN
Remote-enabled
solutions (such as
the Cisco VPN
Client) upon
connection, helping
to ensure that the
latest corporate VPN
security policies
are used
• Performs VPN
client security
posture checks when
a VPN connection
attempt is received,
including enforcing
usage of authorized
host-based security
products (such as
the Cisco Security
Agent) and verifying
its version number
and status prior to
letting the remote
user access the
corporate network
• Provides
administrators
precise control over
what different types
of VPN clients
(software client,
router, VPN 3002,
and PIX) are allowed
to connect based on
type of client,
operating system
installed, and
version of VPN
client software
• Supports automatic
software updates of
Cisco VPN Clients
and Cisco 3002
Hardware VPN
Clients, with the
ability to trigger
updates when VPN
connections are
established, or
on-demand for
currently connected
VPN clients
• Extends VPN reach
into environments
using NAT or Port
Address Translation
(PAT), via support
of a variety of TCP
and UDP-based NAT
traversal methods
including the
Internet Engineering
Task Force (IETF)
draft standard
|
| Cisco VPN Client |
• Includes a free
unlimited license
for the highly
acclaimed,
industry-leading
Cisco VPN Client
• Available on
wide-range of
platforms including
Microsoft Windows
98, ME, NT, 2000,
XP; Sun Solaris;
Intel-based Linux
distributions; and
Apple Macintosh OS X
• Provides many
innovative features
including dynamic
security policy
downloading from
Cisco Easy VPN
Server-enabled
products, automatic
failover to backup
Easy VPN Servers,
administrator
customizable
distributions, and
more
• Integrates with
the award-winning
Cisco Security Agent
(CSA) for
comprehensive
endpoint security
|
| Site-to-Site VPN |
• Supports IKE and
IPSec VPN standards
• Extends networks
securely over the
Internet by helping
to ensure data
privacy, data
integrity, and
strong
authentication with
remote networks and
remote users
• Improves network
reliability and
performance through
support of OSPF
dynamic routing and
reverse-route
injection over
site-to-site VPN
tunnels
• Supports 56-bit
DES, 168-bit 3DES,
and up to 256-bit
AES data encryption
|
| Native Integration with Popular User Authentication Services |
• Provides
convenient method
for authenticating
VPN users through
native integration
with popular
authentication
services including
Microsoft Active
Directory, Microsoft
Windows Domains,
Kerberos, LDAP, and
RSA SecurID (without
requiring a separate
RADIUS/TACACS+
server to act as an
intermediary)
|
| X.509 Certificate and CRL Support |
• Supports Simple
Certificate
Enrollment Protocol
(SCEP)-based
enrollment and
manual enrollment
with leading X.509
solutions from
Baltimore, Cisco,
Entrust,
iPlanet/Netscape,
Microsoft, RSA, and
VeriSign
• Interoperates with
large-scale Public
Key Infrastructure
(PKI) deployments
through n-tiered
certificate
hierarchy support
|
| Resilient Architecture | |
| Active/Active and Active/Standby Stateful Failover |
• Ensures resilient
network protection
for businesses
through the
award-winning high
availability
services provided by
certain models of
Cisco PIX 515E
Security Appliances
• Supports
Active/Standby
failover services as
a cost-effective
high availability
solution, where one
failover pair member
operates in
hot-standby mode
acting as a complete
redundant system
that maintains
current session
state information
for the active unit
• Delivers advanced
Active/Active
failover services
where both Cisco PIX
Security Appliances
in a failover pair
actively pass
network traffic
simultaneously and
share state
information
bi-directionally,
enabling support for
asymmetric routing
environments and
effectively doubling
the throughput of
the failover pair
for bursty network
traffic conditions
• Supports
long-distance
failover enabling
geographic
separation of
failover pair
members, providing
another layer of
protection
|
| VPN Stateful Failover |
• Maximizes VPN
connection uptime
with new
Active/Standby
stateful failover
for VPN connections
• Synchronizes all
security association
(SA) state
information and
session key material
between failover
pair members,
providing a highly
resilient VPN
solution
• This feature is
available on
Unrestricted (UR),
Failover (FO), and
Failover-Active/Active
(FO-AA) models only.
|
| Zero-Downtime Software Upgrades |
• Enables businesses
to perform software
maintenance release
upgrades on Cisco
PIX Security
Appliance failover
pairs without
impacting network
uptime or
connections through
the support of
state-sharing
between mixed Cisco
PIX Security
Appliance Software
versions (running
version 7.0(1) or
higher)
|
| Intelligent Networking Services | |
| VLAN-Based Virtual Interfaces |
• Provides increased
flexibility when
defining security
policies and eases
overall integration
into switched
network environments
by supporting the
creation of logical
interfaces based on
IEEE 802.1q VLAN
tags, and the
creation of security
policies based on
these virtual
interfaces
• Supports multiple
virtual interfaces
on a single physical
interface through
VLAN trunking, with
support for multiple
VLAN trunks per
Cisco PIX Security
Appliance
• Supports up to 25
total VLANs on Cisco
PIX 515E Security
Appliances
|
| QoS Services |
• Delivers per-flow,
policy-based QoS
services, with
support for LLQ and
traffic policing for
prioritizing
latency-sensitive
network traffic and
limiting bandwidth
usage of
administrator-specified
applications
• Enables businesses
to have end-to-end
QoS policies for
their extended
network
|
| OSPF Dynamic Routing |
• Provides
comprehensive OSPF
dynamic routing
services using
technology based on
world-renowned Cisco
IOS Software
• Offers improved
network reliability
through fast route
convergence and
secure, efficient
route distribution
• Delivers a secure
routing solution in
environments using
NAT through tight
integration with
Cisco PIX Security
Appliance NAT
services
• Supports MD5-based
OSPF authentication,
in addition to
plaintext OSPF
authentication, to
prevent route
spoofing and various
routing-based DoS
attacks
• Provides route
redistribution
between OSPF
processes, including
OSPF, static, and
connected routes
• Supports load
balancing across
equal-cost multipath
routes
|
| PIM Multicast Routing |
• Streamlines the
delivery of
multimedia traffic
in
video-conferencing,
collaborative
computing, and
mission critical
real-time enterprise
applications through
full PIM-Sparse Mode
v2 and
Bidirectional-PIM
routing support
(based on
world-class Cisco
IOS multicast
technology)
|
| IPv6 Networking |
• Provides access
control and deep
inspection firewall
services for native
IPv6 network
environments and
mixed IPv4/IPv6
network environments
through dual-stack
support
• Delivers
IPv6-enabled
inspection services
for HTTP, FTP, SMTP,
ICMP, TCP, and
UDP-based
applications
• Supports SSHv2,
telnet, HTTP/HTTPS,
and ICMP-based
management over IPv6
|
| Dynamic Host Control Protocol (DHCP) Client and Server |
• Obtains IP address
for outside
interface of
appliance
automatically from
service provider
• Provides DHCP
server services on
one or more
interfaces, allowing
devices to obtain IP
addresses
dynamically
• Includes
extensions for
automated
provisioning of
Cisco IP phones and
Cisco SoftPhone IP
telephony solutions
|
| DHCP Relay |
• Forwards DHCP
requests from
internal devices to
an
administrator-specified
DHCP server,
enabling centralized
distribution,
tracking and
maintenance of IP
addresses
|
| NAT/PAT Support |
• Provides rich
dynamic, static, and
policy-based NAT,
and PAT services
|
| Flexible Management Solutions | |
| CiscoWorks VPN/Security Management Solution (VMS) |
• Provides a
comprehensive
management suite for
large scale Cisco
security product
deployments
• Integrates policy
management, software
maintenance and
security monitoring
in a single
management console
|
| Cisco Adaptive Security Device Manager (ASDM) |
• World-class
Web-based GUI
enables simple,
secure remote
management of Cisco
PIX Security
Appliances
• Provides a wide
range of
informative,
real-time, and
historical reports
which give critical
insight into usage
trends, performance
baselines, and
security events
|
| Auto Update |
• Provides
"touchless" secure
remote management of
Cisco PIX Security
Appliance
configuration
and software images
via a unique
"push/pull"
management model
• Next-generation
secure Extensible
Markup Language
(XML) over HTTPS
management interface
can be used by Cisco
and third-party
management
applications for
remote Cisco PIX
Security Appliance
configuration
management,
inventory, software
image
management/deployment
and monitoring
• Integrates with
CiscoWorks
Management Center
for Firewalls and
Auto Update Server
for robust, scalable
remote management of
up to 1000 Cisco PIX
Security Appliances
(per management
server)
|
| Cisco PIX Command Line Interface (CLI) |
• Allows customers
to use existing
Cisco IOS Software
CLI knowledge for
easy installation
and management
without additional
training
• Supports improved
ease-of-use with
services such as
command completion,
context-sensitive
help, and command
aliasing
• Accessible through
variety of methods
including console
port, Telnet, and
SSHv2
|
| Command-Level Authorization |
• Gives businesses
the ability to
create up to 16
customizable
administrative
roles/profiles for
managing a Cisco PIX
Security Appliance
(monitoring only,
read-only access to
configuration,
VPN administrator,
firewall/NAT
administrator, etc.)
• Uses either the
internal
administrator
database or outside
sources via TACACS+,
such as Cisco Secure
ACS
|
| SNMP and Syslog Support |
• Provide remote
monitoring and
logging
capabilities, with
integration into
Cisco and
third-party
management
applications
• Supports Cisco
IPSec Flow
Monitoring SNMP MIB,
providing a wealth
of VPN flow
statistics including
tunnel uptime,
bytes/packets
transferred, and
more
|
Table 2. Product Specifications
| Feature | Specifications |
| License Options | |
| The Cisco PIX 515E Security Appliance is available in four primary models that provide different levels of interface density, failover capabilities, and VPN throughput. Optional licenses support enabling features including security contexts, GTP inspection, and various strengths of encryption technology. | |
| Platform Licenses |
• Restricted
Software License
• The Cisco PIX 515E
Restricted (PIX
515E-R) model
provides an
excellent value for
organizations
looking for robust
Cisco PIX Security
Appliance services
with minimal
interface density
and VPN throughput
requirements. It
includes 64 MB of
RAM, two 10/100 Fast
Ethernet interfaces,
and support for one
additional 10/100
Fast Ethernet
interface.
• Unrestricted
Software License
• The PIX 515E
Unrestricted (PIX
515E-UR) model
extends the
capabilities of the
family with support
for stateful
failover, additional
LAN interfaces, and
increased VPN
throughput via
integrated
hardware-based VPN
acceleration. It
includes an
integrated VAC or
VAC+ hardware VPN
accelerator, 128 MB
of RAM, two 10/100
Fast Ethernet
interfaces, and
support for up to
four additional
10/100 Fast Ethernet
interfaces. The
Cisco PIX 515E-UR
also adds the
ability to share
state information
with a secondary
Cisco PIX Security
Appliance (either in
an Active/Active or
Active/Standby
deployment model)
for resilient
network protection.
• Failover
Active/Standby
Software License
• The Cisco PIX 515E
"Failover" (PIX
515E-FO) model is
designed for use in
conjunction with a
PIX 515E-UR,
providing a
cost-effective,
Active/Standby
high-availability
solution. It
operates in
hot-standby mode
acting as a complete
redundant system
that maintains
current session
state information.
With the same
hardware
configuration as the
Cisco PIX 515E-UR,
it delivers the
ultimate in high
availability for a
fraction of the
price.
• Failover
Active/Active
Software License
• The Cisco PIX 515E
Failover
Active/Active (PIX
515E-FO-AA) model is
designed for use in
conjunction with a
PIX 515E-UR,
providing a scalable
Active/Active
high-availability
solution. Advanced
network topologies,
such as those with
asymmetric routing,
are supported
through the
Active/Active
architecture where
both Cisco PIX
Security Appliances
pass network traffic
and exchange
bi-directional state
sharing updates with
one another. This
license is supported
by Cisco PIX
Security Appliance
Software v7.0 and
higher. License
upgrades are
available for
existing PIX 515E-FO
units to convert
from Active/Standby
to Active/Active
failover.
|
| Feature Licenses |
• Security Context
Licenses
• The Cisco PIX 515E
Security Appliance
can support up to 5
security contexts,
with each context
having its own
separate security
policies and
administrative
domain. One tier of
security context
licensing is
available for Cisco
PIX 515E Security
Appliances-5
security contexts.
This license is
supported by Cisco
PIX Security
Appliance Software
v7.0 and higher, and
requires an
Unrestricted (UR),
Failover (FO), or
Failover
Active/Active
(FO-AA)
license-security
contexts are not
supported on
Restricted (R)
models.
• GTP Inspection
License
• The Cisco PIX 515E
Security Appliance
can provide advanced
security services
for GTP/GPRS 3G
Mobile Wireless
environments upon
installation of the
GTP Inspection
License. This
license is supported
by Cisco PIX
Security Appliance
Software v7.0 and
higher, and requires
either an
Unrestricted (UR),
Failover (FO), or
Failover
Active/Active
(FO-AA) license-GTP
inspection is not
supported on
Restricted (R)
models.
|
| Encryption License |
• 3DES/AES and DES
Encryption Licenses
• The Cisco PIX 515E
Security Appliance
has two optional
encryption
licenses-one license
(PIX-VPN-3DES)
enables 168-bit 3DES
and up to 256-bit
AES encryption, the
other license
(PIX-VPN-DES)
enables 56-bit DES
encryption. Both are
available either at
the time of ordering
the Cisco PIX 515E
Security Appliance,
or can be obtained
subsequently through
Cisco.com. Note that
an encryption
license must be
installed to
activate encryption
services which are
required before
using certain
features including
VPN and secure
remote management.
|
| Performance Summary |
• Cleartext
throughput: Up to
190 Mbps
• Concurrent
connections: 130,000
• 168-bit 3DES IPSec
VPN throughput: Up
to 135 Mbps with
VAC+ or 63 Mbps with
VAC
• 128-bit AES IPSec
VPN throughput: Up
to 130 Mbps with
VAC+
• 256-bit AES IPSec
VPN throughput: Up
to 130 Mbps with
VAC+
• Simultaneous VPN
tunnels: 2000
|
| Technical Specifications |
• Processor: 433-MHz
Intel Celeron
Processor
• Random access
memory: 64 MB or 128
MB of SDRAM
• Flash memory: 16
MB
• Cache: 128 KB
level 2 at 433 MHz
• System bus: Single
32-bit, 33-MHz PCI
|
| Environmental Operating Ranges |
• Operating
• Temperature: -25º
to 131ºF (-5º to
55ºC)
• Relative Humidity:
5% to 95%
noncondensing
• Altitude: 0 to
9843 ft (3000 m)
• Shock: 1.14 m/sec
(45 in./sec) 1/2
sine input
• Vibration: 0.41
Grms2 (3-500 Hz)
random input
• Acoustic Noise: 45
dBa maximum
• Nonoperating
• Temperature: -13º
to 158ºF (-25º to
70ºC)
• Relative Humidity:
5% to 95%
noncondensing
• Altitude: 0 to
15,000 ft (4570 m)
• Shock: 30 G
• Vibration: 0.41
Grms2 (3-500 Hz)
random input
|
| Power |
• Input (Per Power
Supply)
• Range Line
Voltage: 100V to
240V AC or 48V DC
• Nominal Line
Voltage: 100V to
240V AC or 48V DC
• Current: 1.5 Amps
• Frequency: 50 to
60 Hz, single phase
• Output
• Steady State: 50W
• Maximum Peak: 65W
• Maximum Heat
Dissipation: 410
BTU/hr, full power
usage (65W)
|
| Physical Specifications |
• Dimensions and
Weight
Specifications
• Form factor: 1 RU,
standard 19-in. rack
mountable
• Dimensions (H x W
x D): 1.72 x 16.82 x
11.8 in (4.37 x
42.72 x 29.97 cm)
• Weight (one power
supply): 11 lb (4.11
kg)
• Expansion
• Two 32-bit/33-MHz
PCI slots
• Two 168-pin DIMM
RAM slots,
supporting up to 64
MB memory maximum
• Interfaces
• Console Port:
RS-232, 9600 bps,
RJ45
• Failover Port:
RS-232, 115 Kbps,
DB-15 (special PIX
failover cable
required)
• Two integrated
10/100 Fast Ethernet
interfaces,
auto-negotiate
(half/full duplex),
RJ45
|
| Regulatory and Standards Compliance |
• Safety
• UL 1950, CSA C22.2
No. 950, EN 60950,
IEC 60950,
AS/NZS3260, TS001,
IEC60825, EN 60825,
21CFR1040
• Electro Magnetic
Compatibility (EMC)
• FCC Part 15 (CFR
47) Class A,
ICES-003 Class A
with UTP, EN55022
Class A with UTP,
CISPR 22 Class A
with UTP, AS/NZ 3548
Class A with UTP,
VCCI Class A with
UTP, EN55024,
EN50082-1 (1997), CE
marking, EN55022
Class B with FTP,
Cispr 22 Class B
with FTP, AS/NZ 3548
Class B with FTP,
VCCI Class B with
FTP
|


