Cisco PIX Firewall Series



Similar documents
Cisco PIX Firewall Series

Cisco Secure PIX Firewall Series

Cisco PIX Firewall 500 Series

- Introduction to PIX/ASA Firewalls -

Cisco MCS 7825-H3 Unified Communications Manager Appliance

Cisco ACE 4710 Application Control Engine

Cisco MCS 7825-H2 Unified CallManager Appliance

Security Threats VPNs and IPSec AAA and Security Servers PIX and IOS Router Firewalls. Intrusion Detection Systems

TABLE OF CONTENTS NETWORK SECURITY 2...1

Cisco VPN 3000 Concentrator Series

Cisco IPS 4200 Series Sensors

Nokia IP Security Platforms Technical Specifications Guide Nokia Enterprise Solutions

Cisco 2600 Series Modular Access Routers

INTRODUCTION TO FIREWALL SECURITY

Cisco SR 520-T1 Secure Router

Cisco ASA 5500 Series Firewall Edition for the Enterprise

Check Point taps the power of virtualization to simplify security for private clouds

Cisco ASA 5500 Series Firewall Edition for the Enterprise

Benefits. Product Overview. There is nothing more important than our customers. DATASHEET

Cisco ASA 5500 Series IPS Solution

Cisco MCS 7816-I3 Unified Communications Manager Appliance

Cisco Adaptive Security Device Manager Version 5.2F for Cisco Firewall Services Module Software Version 3.2

CISCO PIX SECURITY APPLIANCE LICENSING

WATCHGUARD FIREBOX SOHO 6TC AND SOHO 6

Cisco PIX vs. Checkpoint Firewall

Application Server V240 Platform

TABLE OF CONTENTS NETWORK SECURITY 1...1

Benefits. Product Overview. There is nothing more important than our customers. DATASHEET

Appliance Comparison Chart

APV9650. Application Delivery Controller

How To Use The Cisco Wide Area Application Services (Waas) Network Module

SonicWALL Advantages Over WatchGuard

Cisco 7816-I5 Media Convergence Server

Cisco Redundant Power System 2300

Sophos SG Series Appliances

Cisco ASA 5500-X Series Next-Generation Firewalls

Cisco ASA 5585-X Next-Generation Firewall

Cisco ASA 5500-X Series Next-Generation Firewalls

Cisco Intrusion Prevention System Advanced Integration Module for Cisco 1841 and Cisco 2800 and 3800 Series Integrated Services Routers

How Cisco IT Uses Firewalls to Protect Cisco Internet Access Locations

QuickSpecs. Models. Features and benefits Configuration. HP VCX x3250m2 IP Telecommuting Module. HP VCX x3250m2 IP Telecommuting Module Overview

Considerations In Developing Firewall Selection Criteria. Adeptech Systems, Inc.

Load Balance Router R258V

Securing Networks with PIX and ASA

Benefits. Product Overview. There is nothing more important than our customers. DATASHEET

Enhanced Performance, Versatility, High Availability, and Reliability at the Provider Edge

Cisco RV082 Dual WAN VPN Router Cisco Small Business Routers

Cisco ASA 5500-X Series Next-Generation Firewalls

Cisco IPS 4200 Series Sensors

Centralized Orchestration and Performance Monitoring

Cisco 1600 Series Modular Desktop Access Routers

Cisco RV 120W Wireless-N VPN Firewall

Chapter 1 Introduction

Cisco TelePresence Video Communication Server Starter Pack Express Bundle

Security Information & Event Manager (SIEM)

Network Security Firewall

Cisco Application Networking Manager Version 2.0

Delivers fast, accurate data about security threats:

Cisco Nexus 7000 Series.

Cisco Small Business Managed Switches

QuickSpecs. Models HP MSR Open Application Platform (OAP) with VMware vsphere MIM Module

Deliver More Applications for More Users

Cisco WAE Deployed with Cisco ACNS: Product Function Matrix. Two 10/100/1000BASE-T. Two 10/100/1000BASE- T

Licenses are not interchangeable between the ISRs and NGX Series ISRs.

Enhanced Performance, Versatility, High Availability, and Reliability at the Provider Edge

Cisco Nexus 7000 Series Supervisor Module

Cisco ASA 5500 Series Adaptive Security Appliances for the Internet Edge

How To Build A Network Security Firewall

ZEN LOAD BALANCER EE v3.04 DATASHEET The Load Balancing made easy

Cisco IPS AIM and IPS NME for Cisco 1841 and Cisco 2800, 2900, 3800 and 3900 Series Integrated Services Routers

Cisco ASA, PIX, and FWSM Firewall Handbook

SOHOware Long Reach Ethernet (LRE) Solution

Cisco Secure PIX Firewall Frequently Asked Questions

Datasheet. Advanced Network Routers. Models: ERPro-8, ER-8, ERPoe-5, ERLite-3. Sophisticated Routing Features

Job Aid Pre-Installation Information S8500 Media Server

ROSA Server MKVI. A Complete, Powerful Solution

Cisco IOS Advanced Firewall

Cisco Secure Control Access System 5.8

Adit 3000 Series Part Guide

Cisco Network Planning Solution 2.0 Cisco Network Planning Solution Service Provider 2.0

Cisco SA 500 Series Security Appliances

Cisco Communication Media Module

Firewall Introduction Several Types of Firewall. Cisco PIX Firewall

Ixia xstream TM 10. Aggregation, Filtering, and Load Balancing for qgbe/10gbe Networks. Aggregation and Filtering DATA SHEET

Scalable. Reliable. Flexible. High Performance Architecture. Fault Tolerant System Design. Expansion Options for Unique Business Needs

Content Switching Module for the Catalyst 6500 and Cisco 7600 Internet Router

Cisco Unity PBX and T1 IP Media Gateways

Scalable. Reliable. Flexible. High Performance Architecture. Fault Tolerant System Design. Expansion Options for Unique Business Needs

Cisco VPN Internal Service Module for Cisco ISR G2

CT LANforge-FIRE VoIP Call Generator

ProCurve Switch 8000m (J4110A) and Switch 8000m

48 GE PoE-Plus + 2 GE SFP L2 Managed Switch, 375W

Cisco Intrusion Detection System Services Module (IDSM-2)

Overview. Alarm console supports simultaneous viewing of both live and recorded video when alarm events are selected

Security Information & Event Manager (SIEM)

TechGuard Firewall Products Specs/Parts/Competitive Analysis

Transcription:

Cisco PIX Firewall Series Product Overview The Cisco PIX Firewall series delivers strong security in an easy-to-install, integrated hardware/software firewall appliance that offers outstanding performance. Cisco s world-leading PIX Firewall family spans the entire user application spectrum, from compact, plug-n-play desktop firewalls for small/home offices to carrier-class gigabit firewalls for the most demanding enterprise and service provider environments. Cisco PIX Firewalls deliver superior performance of up to 500,000 simultaneous connections and nearly 1.7 Gigabits per second (Gbps) aggregate throughput while providing Cisco customers world-class security, reliability and customer service. Key Features and Benefits Security Cisco PIX Firewalls are purpose-built firewall appliances that utilize a proprietary, hardened operating system which eliminates security risks associated with general purpose operating systems. PIX firewalls also provide the latest in security technology ranging from stateful inspection firewalling, IPsec and L2TP/PPTP-based VPNs, content filtering capabilities, and integrated intrusion detection to help secure your network environment from next-generation attacks. At the heart of the PIX Firewall family is the adaptive security algorithm (ASA), which maintains the secure perimeters between the networks controlled by the firewall. The stateful, connection-oriented ASA design creates session flows based on source and destination addresses, TCP sequence numbers (which are non-predictable), port numbers, and additional TCP flags. All inbound and outbound traffic is controlled by applying security policies to each connection table entry. Performance Cisco PIX firewall s highly scalable, yet very secure architecture based upon stateful inspection technology and application-aware fixups provides state-of-the-art performance and robust security. With support for up to 10 Gigabit Ethernet interfaces and 1.7 Gbps of throughput, PIX Firewalls can scale to meet the needs of the most demanding network environments. Reliability Cisco PIX Firewalls provide resilient security services for mission-critical network environments by leveraging the integrated stateful failover capabilities within PIX. Network traffic can be automatically sent to a hot standby unit in the event of a failure, while maintaining concurrent connections via automated state synchronization between the primary and standby units. Virtual Private Networking (VPN) Cisco PIX Firewalls support both standards-based IPsec and L2TP/PPTP-based VPN services, which are suitable for site-to-site and remote access VPN deployments. Tripe DES (3DES) based VPN throughput can be scaled to nearly 100 Mbps using the PIX VPN Accelerator Card (VAC), which offloads computeintensive encryption/decryption processes to specialized cryptographic coprocessors. Network Address Translation (NAT) and Port Address Translation (PAT) Cisco PIX Firewalls provide robust NAT and PAT services to conceal IP addresses of internal networks and to expand network address space for internal networks. Denial-of-Service (DoS) Attack Prevention Cisco PIX Firewalls protect the firewall and networks behind them from disruptive network hacking attempts that could otherwise bring a network to a halt. Simple, Web-Based Management with PIX Device Manager (PDM) Cisco PIX Firewalls provide a simple, easy-touse web-based interface for centrally managing the configuration of PIX firewalls. Furthermore, PDM provides a wide range of informative, real-time, and historical reports which give critical insight into usage trends, performance baselines, and security events. PDM provides all the tools necessary to manage a firewall, all from the convenience of any web browser. Platform Extensibility Cisco PIX Firewalls provide an extensible platform that can easily grow with your networking needs. With support from two 10/100 Ethernet interfaces all the way up to ten Gigabit Ethernet interfaces in a single firewall appliance solution, PIX Firewalls can fit your budget and your networking environment. Low Cost of Ownership Simple installation and configuration minimizes time investment required for administrators to get PIX firewalls up and running. Minimal time investment combined with an impressive price/performance ratio enable Cisco PIX Firewalls to provide low total cost of ownership (TCO). Visit Cisco Connection Online at www.cisco.com 1

Specifications Hardware Table 19-21: Technical Specifications for Cisco PIX Firewalll Description PIX 501 Firewall PIX 506 Firewall PIX 515 Firewall PIX 525 Firewall PIX 535 Firewall Processor 133 MHz 200 MHz 200 MHz 350 MHz 1 GHz RAM 16 MB 32 MB 32 MB or 64 MB 128 MB or 256 MB 512 MB or 1 GB Flash Memory 8 MB 8 MB 16 MB 16 MB 16 MB PCI Slots None None 2 3 9 Fixed Interfaces 1 10BaseT Ethernet (outside) 4 port 10/100 switch (inside) 2 10BaseT Ethernet 2 10/100 Fast Ethernet 2 10/100 Fast Ethernet None Maximum Interfaces 1 10BaseT Ethernet (outside) 2 10BaseT Ethernet 6 10/100 Fast Ethernet 8 10/100 Fast Ethernet or Gigabit Ethernet 10 10/100 Fast Ethernet or Gigabit Ethernet 4 port 10/100 switch (inside) VPN Accelerator Card (VAC) Support No No Yes Yes Yes Failover Support No No Yes, UR only Yes, UR only Yes, UR only Rack Mountable No No Yes Yes Yes Size Desktop Desktop 1 RU 2 RU 3 RU 1. Rack-mountable products come with rack-mount hardware 2. Failover requires a special Cisco cable, included with failover capable systems Table 19-22: Power Requirements for Cisco PIX Firewall Description PIX 501 Firewall PIX 506 Firewall PIX 515 Firewall PIX 525 Firewall PIX 535 Firewall Autoswitching 100-240 VAC 100-240 VAC 100-240 VAC 100-240 VAC 100-240 VAC Frequency 50-60 Hz 50-60 Hz 50-60 Hz 50-60 Hz 50-60 Hz, single phase Current 0.051 Amps 1.5-0.75 Amps 1.5-0.75 Amps 5-2.5 Amps 4-2 Amps Table 19-23: Physical and Environmental Specifications for Cisco PIX Firewall Description PIX 501 Firewall PIX 506 Firewall PIX 515 Firewall PIX 525 Firewall PIX 535 Firewall Dimensions (HxWxD) 1.0 x 6.25 x 5.5 in. (2.54 x 15.875 x 13.97 cm) 1.72 x 8.5 x 11.8 in. (4.4 x 21.7 x 29.9 cm) 1.72 x 16.82 x 11.8 in., 1 RU (4.4 x 42.7 x 29.9 cm) 3.5 x 17.5 x 18.25 in., 2 RU (8.89 x 44.45 x 46.36 cm) 5.25 x 17.5 x 18.25 in., 3 RU (8.89x 44.45 x 46.36 cm) Weight 0.75 lb. (0.34 kg) 6 lb. 11 lb. (4.9 kg) 32 lb. (14.5 kg) 32 lb. (14.5 kg) Operating Temperature 32 to 104 F (0 to 40 C) -25 to 113 F (-5 to +45 C) -25 to 113 F (-5 to +45 C) -25 to 131 F (-5 to +55 C) -25 to 113 F (-5 to +45 C) Storage Temperature -4 to 149 F (-20 to 65 C) -13 to 158 F (-25 to +70 C) -13 to 158 F (-25 to +70 C) -13 to 158 F (-25 to +70 C) -13 to 158 F (-25 to +70 C) Operational Humidity 90% relative humidity (RH) 95% relative humidity (RH) 95% relative humidity (RH) 95% relative humidity (RH) 95% relative humidity (RH) Operational Altitude 6500 ft (2000m) 9843 ft (3000m), 77 F (25 C) 9843 ft (3000m), 77 F (25 C) 9843 ft (3000m), 104 F (40 C) 9843 ft (3000m) 2 Cisco Product Catalog, February, 2002

Description PIX 501 Firewall PIX 506 Firewall PIX 515 Firewall PIX 525 Firewall PIX 535 Firewall Heat Dissipation (Worst Case with Full Power Usage) 17.0 BTU/hr 102.4 BTU/hr 160.37 BTU/hr 410 BTU/hr 750 BTU/hr Software For additional specifications, see the Cisco PIX Firewall datasheet on the Cisco Web at http://www.cisco.com/go/pix. For software options for the Cisco PIX Firewall Series, see PIX Firewall Software in the tables below. Cisco PIX Firewall Software Features State-of-the-art Adaptive Security Algorithm (ASA) and stateful inspection firewalling Cut-through proxy authenticates and authorizes connections, meanwhile enhancing performance Easy-to-use Web-based interface for managing PIX firewalls remotely Support for up to 10 ethernet interfaces ranging from 10-BaseT, 10/100 Fast Ethernet to Gigabit Ethernet Stateful firewall failover capability with synchronized connection information and product configurations True Network Address Translation (NAT) as specified in RFC 1631 Port Address Translation (PAT) further expands a company s address pool-one IP address supports more than 64,000 hosts Support for IPsec and L2TP/PPTP-based VPNs Support for high performance URL filtering via integration with Websense-based URL filtering solutions Mail Guard removes need for external mail relay server in perimeter network Support for broad range of authentication methods via TACACS+, Radius and Cisco ACS integration DNS Guard transparently protects outbound name and address lookups Flood Guard and Fragmentation Guard protect against denial of service attacks Support for advanced Voice over IP (VoIP) standards including SIP, H.323 and others Java blocking eliminates potentially dangerous Java applets (not compressed or archived) Cisco IOS-style command-line interface Extended authentication, authorization, and accounting capabilities Net Aliasing transparently merges overlapping networks with the same IP address space Ability to customize protocol port numbers Integration with Cisco Intrusion Detection Systems for shunning connections of known malicious IP addresses Enhanced customization of syslog messages Simple Network Management Protocol (SNMP) and syslog for remote management Reliable syslogging using either TCP or UDP Extended transparent application support (both with and without NAT enabled) includes: Sun remote procedure call (RPC) Microsoft Networking client and server communication (NetBIOS over IP) using NAT Multimedia, including RealNetworks RealAudio, Xing Technologies Streamworks, White Pines CuSeeMe, Vocal Tec s Internet Phone, VDOnet s VDOLive, Microsoft s NetShow, VXtreme Web Theatre 2; and Intel s Internet Video Phone and Microsoft s NetMeeting (based on H.323 standards) Visit Cisco Connection Online at www.cisco.com 3

Oracle SQL*Net client and server communication Table 19-24: PIX Firewall Manager Specifications Operating Systems Windows 2000 (Service Pack 1) Windows NT 4.0 (Service Pack 6a) Windows 98 (original or 2 nd addition) Sun Solaris 2.6 or 2.8 running CDE or OpenWindows window manager Redhat Linux 6.2 or 7.0 running GNOME or KDE 2.0 desktop environment Browsers MS Internet Explorer 5.01 (Service Pack1) or higher (5.5 recommended) Netscape Communicator 4.51 or higher (4.76 recommended) MS Internet Explorer 5.0 or higher (5.5 recommended) Netscape Communicator 4.51 or higher (4.76 recommended) Netscape Communicator 4.76 For additional specifications, see the Cisco PIX Firewall datasheet on the Cisco Web at http://www.cisco.com/go/pix. For software options for the Cisco PIX Firewall Series, see PIX Firewall Software in the tables below. 4 Cisco Product Catalog, February, 2002

Ordering Information Where to buy Cisco products Visit http://www.cisco.com/public/ordering_info.shtml Product and Part Numbers Part Numbers for the Cisco PIX Firewall Part Description PIX Firewall Solutions ONE 10/100 Mbps ETHERNET INTERFACES, RJ45 ONE 10/100 Mbps ETHERNET INTERFACES, RJ45 Single Gigabit Ethernet Interface for PIX Firewall Single Gigabit Ethernet Interface for PIX Firewall Single 66MHz Gigabit Ethernet Interface Single 66MHz Gigabit Ethernet Interface PIX Four-port 10/100 Ethernet interface PIX Four-port 10/100 Ethernet interface FAILOVER UPGRADE KIT - SW V3.0 OR LATER PIX 501 (Chassis, software, 10 user license, integrated 4 port 10/100 switch and 10BaseT port) 10-user license for PIX 501 50-user license for PIX 501 10-to-50 user upgrade license for PIX 501 10-to-50 user upgrade license for PIX 501 168-bit 3DES software license for PIX 501 168-bit 3DES software license for PIX 501 Spare AC power supply for PIX 501 PIX 506 (Chassis, software, two 10BaseT ports) 3DES Software Licence for PIX 506 3DES Software Licence for PIX 506 PIX 506 spare AC power supply 515 R to UR License Upgrade (includes 32 MB RAM) Software upgrade from Failover to UnRestricted for PIX 515 Software upgrade from Failover to Restricted for PIX 515 Blank to fill unused option slot on PIX 515 PIX 515 Chassis only Part Number PIX-1FE PIX-1FE= PIX-1GE PIX-1GE= PIX-1GE-66 PIX-1GE-66= PIX-4FE PIX-4FE= PIX-FO= PIX-501 PIX-501-SW-10 PIX-501-SW-50 PIX-501-SW-10-50= PIX-501-SW-10-50= PIX-501-VPN-3DES PIX-501-VPN-3DES= PIX-501-PWR-AC= PIX-506 PIX-506-SW-3DES PIX-506-SW-3DES= PIX-506-PWR-AC= PIX-515-SW-UPG= PIX-515-SW-FO-UR= PIX-515-SW-FO-R= PIX-BLANK-SLOT PIX-515 Visit Cisco Connection Online at www.cisco.com 5

Part Description PIX 515 DC Powered Firewall Appliance PIX 515 Unrestricted Function software license PIX 515 spare AC power supply PIX Firewall 525 Chassis PIX 525 DC Chassis PIX Firewall 535 Chassis PIX 535 512MB RAM Upgrade (2-256MB DIMM, UR Only) Redundant AC power supply for PIX 535 PIX 535 spare AC power supply Redundant DC power supply for PIX 535 PIX 535 spare DC power supply Blank to fill unused power supply slot on PIX 535 PIX Classic, 10K, 510, 520 Failover to entry license upgrade PIX Classic, 10K, 510, 520 failover to mid license upgrade PIX Classic, 10K, 510, 520 failover to UR license upgrade PIX Classic, 10K, 510, 520 Entry to midrange license upgrade PIX Classic, 10K, 510, 520 entry to UR license upgrade PIX Classic, 10K, 510, 520 midrange to UR license upgrade PIX Software Upgrade for Non-Support Customers 128 MB Memory Upgrade for PIX Firewall Models 510 and 520 PIX Firewall IPSec Accelerator PIX Firewall IPSec Accelerator PIX Firewall Bundles PIX 501 10-user/DES Bundle (chassis, latest PIX software, 10-user and DES licenses, integrated 4-port 10/100 switch and 10BaseT port) PIX 501 10-user/3DES Bundle (chassis, latest PIX software, 10-user and 3DES licenses, integrated 4-port 10/100 switch and 10BaseT port) PIX 501 50-user/DES Bundle (chassis, latest PIX software, 50-user and DES licenses, integrated 4-port 10/100 switch and 10BaseT port) PIX 501 50-user/3DES Bundle (chassis, latest PIX software, 50-user and 3DES licenses, integrated 4-port 10/100 switch and 10BaseT port) PIX 506 (Chassis, software, two 10BaseT ports) Part Number PIX-515-DC PIX-515UR-SW PIX-515-PWR-AC= PIX-525 PIX-525-DC PIX-535 PIX-535-MEM-512 PIX-535-PWR-AC PIX-535-PWR-AC= PIX-535-PWR-DC PIX-535-PWR-DC= PIX-535-PWR-BLANK PIX-CONN-FO-128= PIX-CONN-FO-1K= PIX-CONN-FO-UR= PIX-CONN-128-1K= PIX-CONN-128-UR= PIX-CONN-1K-UR= PIX-CONN-VER= PIX-MEM-5XX-128= PIX-VPN-ACCEL PIX-VPN-ACCEL= PIX-501-BUN-K8 PIX-501-BUN-K9 PIX-501-50-BUN-K8 PIX-501-50-BUN-K9 PIX-506 6 Cisco Product Catalog, February, 2002

Part Description PIX 515FO Bundle (Chassis, failover SW, PIX 515R Bundle (Chassis, restricted SW, PIX 515UR Bundle (Chassis, unrestricted SW, PIX 515-R DC Bundle (Chassis, R software, two 10/100 ports) PIX 515-UR DC Bundle(Chassis, UR software, two 10/100 ports) PIX 525FO Bundle (Chassis, failover SW, PIX 525R Bundle (Chassis, restricted SW, PIX 525UR Bundle (Chassis, unrestricted SW, PIX 535FO Bundle (Chassis, failover SW, PIX 535UR Bundle (Chassis, unrestricted SW, PIX 535R Bundle (Chassis, restricted SW, PIX Firewall Flash Cards PIX 16MB ISA Flash card PIX Firewall Crypto PIX 3DES Software License Without Client Software PIX 3DES Software License Without Client Software Part Number PIX-515-FO-BUN PIX-515-R-BUN PIX-515-UR-BUN PIX-515-DC-R-BUN PIX-515-DC-UR-BUN PIX-525-FO-BUN PIX-525-R-BUN PIX-525-UR-BUN PIX-535-FO-BUN PIX-535-UR-BUN PIX-535-R-BUN PIX-FLASH-16MB= PIX-VPN-3DES PIX-VPN-3DES= Minimum Software Versions Cisco PIX 501 Firewall: Minimum Software Version: 6.1(1) Table 19-25: Cisco PIX 501 Firewall Software Licenses Product Description PIX-501-SW-10 10-user license for PIX 501 PIX-501-SW-50 50-user license for PIX 501 PIX-501-SW-10-50= 10-to-50 user upgrade license for PIX 501 PIX-VPN-DES 56-bit DES IPSec software license for Cisco PIX 501 Firewall PIX-501-VPN-3DES 168-bit 3DES IPSec software license for Cisco PIX 501 Firewall Cisco PIX 506 Firewall: Minimum Software Version: 5.1(2) The Cisco PIX 506 Firewall is provided in a single, unlimited mode. Visit Cisco Connection Online at www.cisco.com 7

Table 19-26: Cisco PIX 506 Firewall Software Licenses PIX-VPN-DES PIX-506-SW-3DES Product Description 56-bit DES IPSec software license for Cisco PIX 506 Firewall 168-bit 3DES IPSec software license for Cisco PIX 506 Firewall Cisco PIX 515 Firewall: Minimum Software Version: 4.4(1) Starting with Cisco PIX version 5.1(2) the Cisco PIX 515-R Firewall supports a maximum of three interfaces. Customers must purchase the third interface. This is a free software upgrade for customers with SMARTnet contracts and is available on Cisco.com. Customers who upgrade from an earlier version must obtain a new activation key from licensing@cisco.com. Customers who purchase a new Cisco PIX 515-R Firewall with software version 5.1(2) preinstalled will not be affected. Software version 5.2 or later does not require a new activation key for third-party interface support. Table 19-27: Cisco PIX 515 Firewall Software Licenses Requirements/Comments Restricted PIX-515-SW-R Cisco PIX 515 Firewall Restricted software license. Failover is not supported. Unrestricted PIX-515-SW-UR Cisco PIX 515 Firewall Unrestricted software license. Requires PIX-515-MEM-32 to upgrade base chassis from 32 MB to 64 MB Failover PIX-515-FO-SW Cisco PIX 515 Firewall Failover software license. Restricted to Unrestricted PIX-515-SW-UPG= Cisco PIX 515 Firewall Restricted to Unrestricted software license upgrade. Includes PIX-515-MEM-32 to upgrade base chassis from 32MB to 64MB. Failover to Restricted PIX-515-SW-FO-R Cisco PIX 515 Firewall Failover to Restricted software license upgrade. Failover to Unrestricted PIX-515-SW-FO-UR Cisco PIX 515 Firewall Failover to Unrestricted software license upgrade. 56-bit DES IPSec PIX-VPN-DES Zero cost option required to enable DES support. 168-bit 3DES IPSec PIX-VPN-3DES 168-bit 3DES IPSec software license for Cisco PIX Firewall. Cisco PIX 525 Firewall: Minimum Software Version: 5.2(1) Table 19-28: Cisco PIX 525 Firewall5 Software Licenses Requirements/Comments Restricted PIX-525-SW-R Cisco PIX 525 Firewall Restricted software license. Failover not supported. Unrestricted PIX-525-SW-UR Cisco PIX 525 Firewall Unrestricted software license. Fail-Over PIX-525-FO-SW Cisco PIX 525 Firewall Failover software license. Restricted to Unrestricted PIX-525-SW-R-UR Cisco PIX 525 Firewall Restricted to Unrestricted software license upgrade. Includes 128 MB RAM. Fail-Over to Restricted PIX-525-SW-FO-R Cisco PIX 525 Firewall Failover to Restricted software license upgrade. Fail-Over to Unrestricted PIX-525-SW-FO-UR Cisco PIX 525 Firewall Failover to Unrestricted software license upgrade. 56-bit DES IPSec PIX-VPN-DES Zero cost option required to enable DES support. 168-bit 3DES IPSec PIX-VPN-3DES 168-bit 3DES IPSec software license for PIX Firewall. Cisco PIX 535 Firewall: Minimum Software Version: 5.3(1) Table 19-29: Cisco PIX 535 Firewall Software Licenses Requirements/Comments Restricted PIX-535-SW-R Cisco PIX 535 Firewall Restricted software license. Failover not supported. 8 Cisco Product Catalog, February, 2002

Unrestricted PIX-535-SW-UR Cisco PIX 535 Firewall Unrestricted software license. Fail-Over PIX-535-FO-SW Cisco PIX 535 Firewall Failover software license. Restricted to Unrestricted PIX-535-SW-R-UR Requirements/Comments Cisco PIX 535 Firewall Restricted to Unrestricted software license upgrade. Includes 512MB RAM. Fail-Over to Restricted PIX-535-SW-FO-R Cisco PIX 535 Firewall Failover to Restricted software license upgrade. Fail-Over to Unrestricted PIX-535-SW-FO-UR Cisco PIX 535 Firewall Failover to Unrestricted software license upgrade. 56-bit DES IPSec PIX-VPN-DES Zero cost option required to enable DES support 168-bit 3DES IPSec PIX-VPN-3DES 168-bit 3DES IPSec software license for PIX Firewall. Documentation For part numbers for product specific documentation, visit http://www.cisco.com/univercd/cc/td/doc/pcat/swdo d1.htm Services and Support Table 19-30: Available Support Contracts for the Cisco PIX Firewall Family Description PIX SMARTnet maintenance all versions PIX SMARTnet maintenance all versions (two-tier products) Part Number CON-SNT-PIX CON-SNT-PKG12 Visit Cisco Connection Online at www.cisco.com 9

10 Cisco Product Catalog, February, 2002