CCIE SEC Cisco Security Appliances and Applications
Firewall
Cisco Secure PIX Firewall
This product is no longer being sold and might not be supported
Service Provided
Firewall
VPN
IPSEC
Cisco Adaptive Security Appliance (ASA) Firewall
5505 Base /Security Plus
150 Mbps
8 port 10/100 switch with 2 Power over Ethernet ports
5510 Base /Security Plus
300 Mbps
5-10/100 /
2-10/100/1000, 3-10/100
+4-10/100/1000, 4 SFP (with 4GE SSM)
5520
450 Mbps
4-10/100/1000,
1-10/100
+4-10/100/1000, 4 SFP (with 4GE SSM)
5540
650 Mbps
4-10/100/1000,
1-10/100
+4-10/100/1000, 4 SFP (with 4GE SSM)
5550
1.2 Gbps
8-10/100/1000,
4-SFP, 1-10/100
5580-20
5 Gbps (real-world HTTP), 10 Gbps (jumbo frames)
2-10/100/1000 Management
+4-10/100/1000 (with ASA5580-4GE-CU)
+ 4 GE SR LC (with ASA5580-4GE-FI)
+2 10GE SR LC (with ASA5580-2X10GE-SR)
5580-40
10 Gbps (real-world HTTP), 20 Gbps (jumbo frames)
2-10/100/1000 Management
+4-10/100/1000 (with ASA5580-4GE-CU)
+ 4 GE SR LC (with ASA5580-4GE-FI)
+2 10GE SR LC (with ASA5580-2X10GE-SR)
Services Provided
Firewall
Context (Virtual) Firewalling
Transparent (Layer2) Firewalling
Unified Communications Security
IPS
VPN
IPSEC
SSL
Content Filtering
CSC10
CSC20
antivirus/anti-spyware
PLUS
URL filtering
anti-phishing
anti-spam
Powered by TREND
Modular Policy
Cisco IOS Firewall
CBAC
Context Based Access List
IP Inspect Commands
Show ip inspect sessions
IP inspect name FIREWALL tcp
Effectively Dynamic Access lists
6500 FWSM
5-Gbps throughput, 100,000 CPS, and 1M concurrent connections
scalability to 20 Gbps per chassis.
Based on Cisco PIX Firewall technology
Cisco Intrusion Prevention System (IPS)
IPS AIM for ISR
IPS AIM
up to 45 Mbps
IPS NME
upto 75 Mbps
4200 Series
Cisco IPS 4270 Sensor
up to 4 Gbps performance and is suitable for large enterprises and data centers
up to 16 Gigabit Ethernet interfaces
Cisco IPS 4260 Sensor
1 Gbps of intrusion prevention performance
optional fiber or copper NIC cards
Cisco IPS 4255 Sensor
Upto 600 Mbps
10/100/1000 interfaces
Cisco IPS 4240 Sensor
Upto 250 Mbps
10/100/1000 interfaces
Cisco IDS 4215 Sensor
Upto 80 Mbps
supports up to five sniffing interfaces
ASA AIP-SSM
AIP SSM-10
• 150 Mbps with Cisco ASA 5510
• 225 Mbps with Cisco ASA 5520
AIP SSM-20
• 375 Mbps with Cisco ASA 5520
• 500 Mbps with Cisco ASA 5540
AIP SSM-40
• 450 Mbps with Cisco ASA 5520
• 650 Mbps with Cisco ASA 5540
6500 IDSM2
passive
• 600 Mbps
• 6,000 new TCP connections per second
• 6,000 HTTP transactions per second
• 60,000 concurrent connections
inline
• 500 Mbps
• 5,000 new TCP connections per second
• 5,000 HTTP transactions per second
• 50,000 concurrent connections
• Supports up to 500,000 concurrent connections
With no slot restriction on Cisco Catalyst 6500/7600 Series chassis, the 1-RU IDSM-2 can scale to up to 8 modules per chassis, providing up to 4 Gbps of inline prevention
Cisco IOS Intrusion Prevention System
Getting Started
Signature List
Pre-Tuned Signature Definition Files (.SDF) Files
IP Audit Commands
Cisco Security Monitoring, Analysis and Response System (MARS)
Provides security monitoring for network devices and host applications supporting both Cisco and other vendors.
* "Learns" the topology, configuration and behavior of your environment
* Automatically updates knowledge of new Cisco IPS signatures, for up to the minute reporting on your environment
* Promotes awareness of environmental anomalies with network behavior analysis using NetFlow and syslog
* Provides simple access to audit compliance reports with more than 150 ready-to-use customizable reports
* Makes precise recommendations for threat mitigation, including the ability to visualize the attack path and identify the source of the threat with detailed topological graphs that simplify security response at Layer 2 and Layer 3
* Integrates with the Cisco Security Manager to correlate security events with the configured firewall rules and intrusion prevention system (IPS) signatures that can affect the security event.
Cisco Traffic Anomaly Detectors
powerful family of solutions for detecting and defeating today's most complex and sophisticated distributed-denial-of-service (DDoS) attacks.
Working in concert with Cisco Guard DDoS mitigation appliances and service modules, Cisco Traffic Anomaly Detectors detect the presence of a potential DDoS attack
Detection is based on sophisticated anomaly detection capabilities that compare current activity to profiles of known "normal" behavior,
Cisco Traffic Anomaly Detector XT
XT 5600
10/100/1000BASE-T Ethernet ports
XT 5700
1000BASE-SX multimode fiber optic ports with LC connectors
Cisco Guard DDoS Mitigation Appliance
Working in concert with Cisco Traffic Anomaly Detectors, Cisco Guards detect the presence of a potential DDoS attack, and block malicious traffic in real time,
Guard XT diverts traffic destined for a targeted device under attack (and only that traffic)
Diverted Traffic is subjected to a unique Multi-Verification Process (MVP) architecture
Two versions of the Cisco Guard XT 5650 are available. One provides 10/100/1000BASE-T Ethernet ports, while the other offers 1000BASE-SX multimode fiber optic ports with LC connectors
Cisco Catalyst 6500 Series Security Modules
FWSM
IDSM
VPNSM
This product is no longer being sold and might not be supported.
WebVPN
The Cisco® WebVPN Services Module is a high-speed, integrated Secure Sockets Layer (SSL) VPN services module for Cisco Catalyst® 6500 Series switches and Cisco 7600 Series routers
Supporting up to 32,000 SSL VPN users and 128,000 connections per chassis,
Cisco Traffic Anomaly Detector Module
Cisco Guard Service Module
SSL modules
CSM-S
The Catalyst 6500 Series Content Switching Module with SSL (CSM-S) combines high-performance server load balancing (SLB) with Secure Socket Layer (SSL) offload
VPN
Cisco IOS IPSec VPN
Cisco EzVPN Software and Hardware Clients
Cisco VPN 3000 Series Concentrators
DMVPM
Dynamic Multipoint VPN
IPSEC / GRE
Identity
Cisco IOS Trust and Identity
Cisco Secure Access Control Server
Cisco Secure ACS Solution Engine
Cisco Secure ACS for Windows
Network Access Profiles
802.1x
IBNS
Identity Based Network Services
CCIE SEC Cisco Security Appliances and Applications
Added: 2009-01-23 03:37:08
From: (Joined 2008-12-15 05:32:23)
246 views |3 downloads
CCIE SEC Cisco Security Appliances and Applications