All Topics  
Cisco PIX

 

   Email Print
   Bookmark   Link






 

Cisco PIX



 
 
Cisco PIX (Private Internet eXchange) is a popular IP
Internet protocol suite

The Internet Protocol Suite is the set of communications protocols used for the Internet and other similar networks. It is named from two of the most important protocols in it: the Transmission Control Protocol and the Internet Protocol , which were the first two networking protocols defined in this standard....
 firewall
Firewall (networking)

A firewall is an integrated collection of security measures designed to prevent unauthorized electronic access to a networked computer system....
 and network address translation
Network address translation

In computer networking, network address translation is the process of modifying network address information in datagram packet headers while in transit across a traffic router for the purpose of remapping a given address space into another....
 (NAT) appliance
Computer appliance

A computer appliance is generally a separate and discrete hardware component specifically designed to provide a specific compute resource, and which often resides on a dedicated computing platform....
. It was one of the first products in this market segment.

In 2005, Cisco introduced the newer Adaptive Security Appliance
Cisco ASA

In computer networking, Cisco Adaptive Security Appliance 5500 Series, or simply Cisco ASA, is Cisco's line of network security devices introduced in 2005, that succeeded three existing lines of popular Cisco products:...
 (ASA), that inherited much of PIX features, and in 2008 announced PIX end-of-sale.

The PIX technology is still sold in a blade, the FireWall Services Module (FWSM), for the Cisco Catalyst 6500
Catalyst 6500

The Catalyst 6500 is a modular chassis Network Switch manufactured by Cisco Systems since 1999, capable of delivering speeds of up to "400 million packet s per second" ....
 switch series and the 7600 Router series.

was originally conceived in early 1994 by John Mayes of Redwood City, California and coded by Brantley Coile
Coraid

of Athens, GA designs and manufactures Etherdrive networked storage appliances. Coraid's developers created and maintain the Linux kernel's aoe driver....
 of Athens, Georgia.






Discussion
Ask a question about 'Cisco PIX'
Start a new discussion about 'Cisco PIX'
Answer questions from other users
Full Discussion Forum



Encyclopedia


Cisco PIX (Private Internet eXchange) is a popular IP
Internet protocol suite

The Internet Protocol Suite is the set of communications protocols used for the Internet and other similar networks. It is named from two of the most important protocols in it: the Transmission Control Protocol and the Internet Protocol , which were the first two networking protocols defined in this standard....
 firewall
Firewall (networking)

A firewall is an integrated collection of security measures designed to prevent unauthorized electronic access to a networked computer system....
 and network address translation
Network address translation

In computer networking, network address translation is the process of modifying network address information in datagram packet headers while in transit across a traffic router for the purpose of remapping a given address space into another....
 (NAT) appliance
Computer appliance

A computer appliance is generally a separate and discrete hardware component specifically designed to provide a specific compute resource, and which often resides on a dedicated computing platform....
. It was one of the first products in this market segment.

In 2005, Cisco introduced the newer Adaptive Security Appliance
Cisco ASA

In computer networking, Cisco Adaptive Security Appliance 5500 Series, or simply Cisco ASA, is Cisco's line of network security devices introduced in 2005, that succeeded three existing lines of popular Cisco products:...
 (ASA), that inherited much of PIX features, and in 2008 announced PIX end-of-sale.

The PIX technology is still sold in a blade, the FireWall Services Module (FWSM), for the Cisco Catalyst 6500
Catalyst 6500

The Catalyst 6500 is a modular chassis Network Switch manufactured by Cisco Systems since 1999, capable of delivering speeds of up to "400 million packet s per second" ....
 switch series and the 7600 Router series.

History

PIX was originally conceived in early 1994 by John Mayes of Redwood City, California and coded by Brantley Coile
Coraid

of Athens, GA designs and manufactures Etherdrive networked storage appliances. Coraid's developers created and maintain the Linux kernel's aoe driver....
 of Athens, Georgia. The PIX name is derived from its creators' aim of creating the functional equivalent of an IP PBX
Private branch exchange

A private branch exchange is a telephone exchange that serves a particular business or office, as opposed to one that a common carrier or telephone company operates for many businesses or for the general public....
 to solve the then-emerging registered IP address
IP address

An Internet Protocol address is a numerical identification that is assigned to devices participating in a computer network utilizing the Internet Protocol for communication between its nodes....
 shortage. At a time when NAT was just being investigated as a viable approach, they wanted to conceal a block or blocks of IP addresses behind a single or multiple registered IP addresses, much like PBX's do for internal phone extensions. When they began, RFC 1597 and RFC 1631 were being discussed, but the now-familiar RFC 1918
Private network

In Internet terminology, a private network is typically a network that uses private IP address space, following the standards set by RFC 1918 and RFC 4193....
 had not yet been submitted.

The design, and testing were carried out in 1994 by John Mayes, Brantley Coile and Johnson Wu of Network Translation, Inc., with Brantley Coile being the sole software developer. Beta testing of PIX serial number 000000 was completed and first customer acceptance was on December 21 1994 at KLA Instruments in San Jose, California. The PIX quickly became one of the leading enterprise firewall products and was awarded the Data Communications Magazine "Hot Product of the Year" award in January of 1995.

After Cisco
Cisco

Cisco may refer to:Companies:* Cisco Systems, a computer networking company* Certis CISCO, corporatised entity of the former Commercial and Industrial Security Corporation in Singapore....
 acquired Network Translation in November 1995, Mayes and Coile hired four long time associates: Jim Jordan, Tom Bohannon, and Richard Howes and Pete Tenereillo (both who worked for NTI prior to the acquisition). Together they continued development on Finesse OS and the original version of the Cisco PIX Firewall, now known as the PIX "Classic". During this time, the PIX shared most of its code with another Cisco product, the LocalDirector
Cisco LocalDirector

Cisco LocalDirector is a server load balancing appliance, discontinued in 2003, based on the Network Address Translation technology Cisco Systems acquired when they bought Network Translation, Inc....
.

End-of-Life

On January 28, 2008, Cisco announced the end-of-sale and end-of-life dates for all Cisco PIX Security Appliances, software, accessories, and licenses. The last day for purchasing Cisco PIX Security Appliance platforms and bundles was July 28, 2008. The last day to purchase accessories and licenses was January 27, 2009. It is important to note that Cisco will continue to support Cisco PIX Security Appliance customers through July 27, 2013.

Adaptive Security Appliance (ASA)

In May 2005, Cisco introduced the Adaptive Security Appliance (ASA) which combines functionality from the PIX, VPN 3000 series and IDS
Intrusion-detection system

An Intrusion detection system is software and/or hardware designed to detect unwanted attempts at accessing, manipulating, and/or disabling of computer, mainly through a network, such as the Internet....
 product lines. The ASA series of devices run PIX code 7.0 and later. Through PIX OS release 7.x the PIX and the ASA use the same software images. Beginning with PIX OS version 8.x, the operating system code diverges, with the ASA using a Linux kernel and PIX continuing to use the traditional Finesse/PIX OS combination.

Description of operation

The PIX runs a custom-written proprietary operating system
Operating system

An operating system is an interface between hardware and applications; it is responsible for the management and coordination of activities and the sharing of the limited resources of the computer....
 originally called Finesse (Fast InterNEt Server Executive), but now the software is known simply as PIX OS. It is classified as a network layer firewall with stateful inspection
Stateful firewall

In computing, a stateful firewall is a Firewall that keeps track of the state of network connections traveling across it. The firewall is programmed to distinguish legitimate packets for different types of connections....
, although technically the PIX would more precisely be called a Layer 4, or Transport Layer Firewall, as its access is not restricted to Network Layer routing, but socket based connections (a port and an IP Address - Port communications occur at Layer 4). By design it allows internal connections out (outbound traffic), and only allows inbound traffic that is a response to a valid request or is allowed by an Access Control List
Access control list

With respect to a computer filesystem, an access control list is a list of permissions attached to an object. The list specifies who or what is allowed to access the object and what operations are allowed to be performed on the object....
 (ACL) or a conduit. The PIX can be configured to perform many functions including network address translation
Network address translation

In computer networking, network address translation is the process of modifying network address information in datagram packet headers while in transit across a traffic router for the purpose of remapping a given address space into another....
 (NAT) and port address translation
Port address translation

Port Address Translation is a feature of a Computer network device that translates Transmission Control Protocol or User Datagram Protocol communications made between hosts on a private network and hosts on a public network....
 (PAT), as well as being a virtual private network
Virtual private network

VPN which stands for Virtual Private Networks are used as secure extranets and Internets . It protects its network by using encryption, firewalls and other security strategies....
 (VPN) endpoint appliance.

The PIX was the first commercially available firewall product to introduce protocol specific filtering with the introduction of the "fixup" command. The PIX "fixup" capability allows the Firewall to apply additional security policies to connections identified as using specific protocols. Two protocols for which specific fixup behaviors were developed are DNS and SMTP. The DNS fixup originally implemented a very simple but effective security policy; it allowed just one DNS response from a DNS server on the Internet (known as outside interface) for each DNS request from a client on the protected (known as inside) interface. "Fixup" has been superseded by "Inspect" on later versions of PIX OS.

The Cisco PIX was also one of the first commercially available security appliances to incorporate IPSec
IPsec

Internet Protocol Security is a Protocol suite for securing Internet Protocol communications by authentication and encryption each packet #Example: IP packets of a data stream....
 VPN gateway functionality.

The PIX can be managed by a command line interface
Command line interface

A command-line interface is a mechanism for interacting with a computer operating system or software by typing commands to perform specific tasks....
 (CLI) or a graphical user interface
Graphical user interface

A graphical user interface is a type of user interface which allows people to human-computer interaction such as computers; hand-held devices such as MP3 Players, Portable Media Players or Gaming devices; household appliances and office equipment....
 (GUI). The CLI is accessible from the serial console, telnet and SSH
Secure Shell

Secure Shell or SSH is a network protocol that allows data to be exchanged using a secure channel between two networked devices. Used primarily on Linux and Unix based systems to access shell accounts, SSH was designed as a replacement for TELNET and other Computer security remote Shell s, which send information, notably passwords, in...
. GUI administration was introduced with version 4.1, and it has been through several incarnations: PIX Firewall Manager (PFM) for PIX OS versions 4.x and 5.x, which runs locally on a Windows NT client; PIX Device Manager (PDM) for PIX OS version 6.x, which runs over https
Https

Hypertext Transfer Protocol Secure is a combination of the Hypertext Transfer Protocol and a secure communication protocol.HTTP operates at the highest layer of the TCP/IP model, the Application layer; but the security protocol operates at lower sublayer, encrypting an HTTP message prior to transmission and decrypting a message upon arriva...
 and requires Java
Java (programming language)

Java is a programming language originally developed by James Gosling at Sun Microsystems and released in 1995 as a core component of Sun Microsystems' Java ....
; and Adaptive Security Device Manager (ASDM) for PIX OS version 7 and greater, which can run locally on a client or in reduced-functionality mode over HTTPS.

As the PIX is an acquired product, the CLI was originally not aligned with the Cisco IOS
Cisco IOS

Cisco IOS is the software used on the vast majority of Cisco Systems routers and all current Cisco network switches. . IOS is a package of routing, switching, internetworking and telecommunications functions tightly integrated with a computer multitasking operating system....
 syntax. Starting with version 7.0, the configuration is much more IOS-like. As the PIX only supports IP traffic (as opposed to IPX
IPX

Internetwork Packet Exchange is the OSI model Network layer Protocol_ in the IPX/SPX protocol stack.The IPX/SPX protocol stack is supported by Novell, Inc.'s NetWare network operating system....
, DECNet
DECnet

DECnet is a suite of network protocols created by Digital Equipment Corporation, originally released in 1975 in order to connect two PDP-11 minicomputers....
, etc.), in most configuration commands 'ip' is omitted. The configuration is upwards compatible, but not downwards. When a 5.x or 6.x configuration is loaded on a 7.x platform, the configuration is automatically converted to 7.x formatting. This allows for an easy migration from PIX to ASA. PIX OS v7.0 is only supported on models 515, 515(E), 525 and 535. Although the 501 and 506E are relatively recent models, the flash memory
Flash memory

Flash memory is a non-volatile memory computer storage that can be electrically erased and reprogrammed. It is a technology that is primarily used in memory cards and USB flash drives for general storage and transfer of data between computers and other digital products....
 size of only 8 MB prevents support of version 7.x, although rumors suggest that 7.0 can be installed on a 506E (see external links). For the PIX 515(E), a doubling of the memory size is required (32->64 MB for restricted and 64->128MB for Unrestricted/Failover licenses). A 515(E) can run 7.0 with 64 MB memory installed, but that is not recommended as larger configuration and session/xlate tables can exceed the available memory.

Specifications of past and present models


Current models

Model501506e515e525535FWSM
Introduced 2001 2002 2002 2000 2000 2003
Discontinued 2008 2008 2008 2008 2008 
CPU
Central processing unit

A central processing unit is an electronic circuit that can execute computer programs. This broad definition can easily be applied to many early computers that existed long before the term "CPU" ever came into widespread usage....
 type
AMD
SC520 5x86
AMD 5x86

The Am5x86 processor is an x86-compatible Central processing unit introduced in 1995 by AMD for use in 80486-class computer systems. It was one of the fastest, and most universally-compatible upgrade paths for users of 486 systems....
 
Intel
Celeron
Celeron

The Celeron brand is a range of x86 CPUs from Intel targeted at budget/value personal computers?with the motto, "delivering great quality at an exceptional value"....

(Mendocino SL36A)
Intel
Celeron
Celeron

The Celeron brand is a range of x86 CPUs from Intel targeted at budget/value personal computers?with the motto, "delivering great quality at an exceptional value"....

(Mendocino SL3BA)
Intel
Pentium III
Pentium III

The Pentium III brand refers to Intel's 32-bit x86 desktop and mobile microprocessors based on the sixth-generation Intel P6 microarchitecture introduced on February 26, 1999....

(Coppermine)
Intel
Pentium III
Pentium III

The Pentium III brand refers to Intel's 32-bit x86 desktop and mobile microprocessors based on the sixth-generation Intel P6 microarchitecture introduced on February 26, 1999....

(Coppermine)
Intel Pentium III, IBM
IBM

International Business Machines Corporation, abbreviated IBM and nicknamed "Big Blue" , is a multinational corporation computer technology and consulting corporation headquartered in Armonk, New York, New York, United States....
 4GS3 PowerNP network processor
Network processor

A network processor is an integrated circuit which has a feature set specifically targeted at the Computer networking application domain.Network processors are typically software programmable devices and would have generic characteristics similar to general purpose Central Processing Units that are commonly used in many different types of e...
s
CPU speed 133 MHz 300 MHz 433 MHz 600 MHz 1 GHz 1 GHz
Chipset AMD
SC520
Intel
440BX
Intel 440BX

The Intel 440BX, also known as the i440BX, is a chipset from Intel, supporting Pentium II, Pentium III, and Celeron processors. It was released on April 1998....

Seattle
Intel
440BX
Intel 440BX

The Intel 440BX, also known as the i440BX, is a chipset from Intel, supporting Pentium II, Pentium III, and Celeron processors. It was released on April 1998....

Seattle
Intel
440BX
Intel 440BX

The Intel 440BX, also known as the i440BX, is a chipset from Intel, supporting Pentium II, Pentium III, and Celeron processors. It was released on April 1998....

Seattle
Broadcom
Broadcom

Broadcom Corporation is an United States supplier of integrated circuits for broadband communications. Founded in 1991 by Henry Samueli and Henry T....

Serverworks
RCC
?
Default RAM 32 MB 1 GB
Boot flash device Onboard Onboard Onboard OnboardOnboard Onboard
Default flash 16 MB 128 MB
Boot flash chips 1 x 28F640 1 x 28F640 1 x E28F128J3 1 x EF28F128J3 2 x i28F640J5 ATA CompactFlash
PIX BIOS flash chips 28F640 AM29F400B AM29F400BE28F400B5T 
Minimum PIX OS version 6.1(1) 5.1(x) 5.1(x) 5.2(x) 5.3(x) 
Maximum PIX OS version officially supported Latest 6.3(x) Latest 6.3(x) 8.x 8.x 8.x 
Max interfaces 2 
Fixed internal interface 10
10BASE-T

Ethernet over twisted pair refers to the use of a pair of copper cables, twisted around each other, for the physical layer of an Ethernet network ....
/100baseT
10/100baseT 10/100baseT No No
Fixed external interface 10/100baseT 10/100baseT 10/100baseT No No
PCI slots 0 0 2 3 9 1
Expansion cards supported No No4 port FE,
1 port 1000baseSX
1 port FE,
4 port FE,
1 port 1000baseSX
1 port FE,
4 port FE,
1 port 1000baseSX
Supports SSL VPN No No No No No No
VPN accelerator supported No No Yes Yes Yes
Floppy drive No No No No No No
Failover
Failover

Failover is the capability to switch over automatically to a redundancy or standby computer Server , system, or computer network upon the failure or abnormal end of the previously active server, system, or network....
 supported
No No Yes Yes Yes Yes
Model501506e515e525535FWSM


Discontinued models

ModelNTI PIXClassic
47-3158-01
10000506510515520
Introduced 1994 1995 1996 2000 1997 1999 1999
Discontinued 1995 1998 1998 2002 1999 2002 2001
CPU
Central processing unit

A central processing unit is an electronic circuit that can execute computer programs. This broad definition can easily be applied to many early computers that existed long before the term "CPU" ever came into widespread usage....
 type
Intel 486DX2
Intel 80486DX2

The Intel's i486DX2 is a central processing unit produced by Intel that was introduced in 1992. The i486DX2 was nearly identical to the Intel 80486DX but for the addition of clock multiplier circuitry....
/
Intel Pentium
Pentium

Introduced on March 22, 1993, the original Pentium was the first superscalar x86 architecture microprocessor. Its fifth-generation x86 microarchitecture was a direct extension of the 80486 architecture with dual integer pipeline s, a faster FPU unit, wider data bus, and features for further reduced address calculation latency....
Intel Pentium Intel
Pentium Pro
Pentium Pro

The Pentium Pro is a sixth-generation x86-based microprocessor developed and manufactured by Intel introduced in November 1995. It introduced the Intel P6 and was originally intended to replace the original Pentium in a full range of applications....
Intel
Pentium MMX
Intel
Pentium
Intel
Pentium MMX
Intel
Pentium II
Pentium II

The Pentium II brand refers to Intel's sixth-generation microarchitecture and x86 architecture-compatible microprocessors introduced on May 7, 1997....

(Deschutes)
CPU speed 66 / 90 MHz 100~133 MHz 200 MHz 200 MHz 166 MHz 200 MHz
Chipset  Intel
430FX/TX
Intel
440FX
Natoma
Intel
430TX
Intel
430TX
Intel
430TX
440LX/BX
Balboa/
Seattle
Default RAM 4 MB
Megabyte

Megabyte is a SI prefix-multiple of the unit byte for digital information computer storage or transmission and is equal to 106 bytes....
8 MB 16 MB 32 MB 16 MB 128 MB
Boot flash device ISA card ISA card ISA card Onboard ISA card Onboard ISA card
Default flash 512KB 2 MB 2 MB 2 MB
Boot flash chips 2 x i28f0204 x 29C040
1 x i28F640J5 4 x 29C040 2 x i28F640J52 x i28F640J5
PIX BIOS flash chips AM28F256 AT29C257 AM28F256 AT29C257AT29C257
Minimum PIX OS version 1.x 2.x 4.4(x) 4.4(x) 4.4(x) 5.1(x) 4.4(x)
Maximum PIX OS version5.1(x) Latest 8.x
Max interfaces    2 
Fixed internal interface No No No 10baseT No 10/100baseT No
Fixed external interface No No No 10baseT No 10/100baseT No
PCI slots ? 4 4 0 2
Expansion cards supported ? 1 port FE,
1 port Token Ring
IBM token ring

Token ring local area network technology is a local area network network protocol which resides at the data link layer of the OSI model. It uses a special three-byte frame called a token that travels around the ring....
,
1 port FDDI
1 port FE,
1 port Token Ring,
1 port FDDI
No 1 port FE,
1 port Token Ring,
1 port FDDI
1 port FE,
4 port FE,
1 port 1000baseSX
1 port FE,
4 port FE,
1 port 1000baseSX
VPN accelerator supported Yes Yes Yes No Yes Yes Yes
Floppy drive Yes Yes Yes No Yes No Yes
Failover
Failover

Failover is the capability to switch over automatically to a redundancy or standby computer Server , system, or computer network upon the failure or abnormal end of the previously active server, system, or network....
 supported
No Yes No Yes Yes Yes
ModelNTI PIXClassic10000506510515520
---Information on models supported as of 6/27/2005 verified from (page 2) and the specific

Performance specifications

ModelPIX ClassicPIX 10000PIX 501PIX 506PIX 506ePIX 510PIX 515PIX 515ePIX 525PIX 535ASA 5520FWSM
Cleartext
Cleartext

In data communications, cleartext is the form of a message or data which is in a form that is immediately comprehensible to a human being without additional processing....
 throughput
Throughput

In communication networks, such as Ethernet or packet radio, throughput is the average rate of successful message delivery over a communication channel....
, Mbit/s
  90 60 20 100  147 190 240 330 1655 450 5500
56-bit DES
Data Encryption Standard

The Data Encryption Standard is a block cipher that was selected by National Bureau of Standards as an official Federal Information Processing Standard for the United States in 1976 and which has subsequently enjoyed widespread use internationally....
 throughput, Mbit/s
   6  20  n/a n/a  n/a n/a ? n/a
168-bit Triple DES
Triple DES

In cryptography, Triple DES is a block cipher formed from the Data Encryption Standard cipher by using it three times....
 throughput, Mbit/s
   3 6 16  225 n/a
AES
Advanced Encryption Standard

In cryptography, the Advanced Encryption Standard is an encryption standard adopted by the Federal government of the United States. The standard comprises three block ciphers, AES-128, AES-192 and AES-256, adopted from a larger collection originally published as Rijndael. Each AES cipher has a 128 bit block size, with key sizes of 128...
-128 throughput, Mbit/s
   4.5  30    225 n/a
AES
Advanced Encryption Standard

In cryptography, the Advanced Encryption Standard is an encryption standard adopted by the Federal government of the United States. The standard comprises three block ciphers, AES-128, AES-192 and AES-256, adopted from a larger collection originally published as Rijndael. Each AES cipher has a 128 bit block size, with key sizes of 128...
-256 throughput, Mbit/s
   3.4  25    225 n/a
Max simultaneous connections  16,000 7,500 10,000 25,000  256,000 280,000 999,900 total / 100,000 per second
Max simultaneous hosts (users)    Unlimited   Unlimited Unlimited Unlimited ? 256,000
Max number of ACL
Access control list

With respect to a computer filesystem, an access control list is a list of permissions attached to an object. The list specifies who or what is allowed to access the object and what operations are allowed to be performed on the object....
's
            ? 80,000
Max simultaneous VPN peers   10 25 25    750 IPSec, 750 SSL n/a
ModelPIX ClassicPIX 10000PIX 501PIX 506PIX 506ePIX 510PIX 515PIX 515ePIX 520PIX 525PIX 535ASA 5520FWSM
---Information on models supported as of 6/27/2005 verified from (page 2) and the specific

List of part numbers for PCI
Peripheral Component Interconnect

The PCI Local Bus , or Conventional PCI, is a computer bus for attaching computer hardware in a computer. These devices can take either the form of an integrated circuit fitted onto the motherboard itself, called a planar device in the PCI specification or an expansion card that fits into a socket....
, ISA, and EISA expansion cards

  • Flash cards
    • ??? - 512 kB ISA flash card used in the original NTI PIX, PIX Classic and 10000. It is manufactured by Productivity Enhancement Products. Aside from progressive manufacturing refinements, the 512KB and 2MB flash cards were identical aside from the chips that populated it. Both booted from a 28F256 chip, but the 512KB card only populated two of the flash sockets with 28F020 chips, while the 2MB card populated all four sockets with 29C040 chips
    • ??? - 2 MB ISA flash card used in the PIX Classic, 10000, 510, and 520, as well as the SSG-6510 and many LocalDirectors. It is manufactured by Productivity Enhancement Products.
    • PIX-FLASH-16MB - 16 MB ISA flash card for the PIX 510, 520, and 535. It is manufactured by Productivity Enhancement Products.
  • Ethernet cards
    • PIX-1GE-66 - 64 bit/66 MHz PCI 1000baseSX card for PIX 53x. Based on the Intel Pro/1000-F fiber network card using the Intel TL82543GC (Intel code name "Livengood") ASIC (PWLA8490sx). The 1000baseT variant of this card, the Intel Pro/1000-t Server adapter (PWLA8490t), is not supported by PIX OS, due to Carrier Extension interoperability problems with early 1000baseT switch products .
    • PIX-1GE - 32 bit/33 MHz PCI 1000baseSX card for PIX 52x. Based on the Intel PWLA8490 Pro/1000 fiber network card with the 82542 (Intel code name "Wiseman") chipset. The ASIC used on this card is the LSI L2A1157/695314-003. . There is no 1000baseT variant of this card. In the release notes for PIX OS 6.02, Cisco advises against installing this card in the 525 and 535 , referencing caveat CSCdu00850, although this caveat actually only lists the PIX 535, which is the only model with a 66 MHz PCI bus.
    • PIX-4FE-66 - 64 bit/66 MHz PCI Four port 10/100 Fast Ethernet card. Based on the Intel 82559 chipset. Uses a DEC
      Digital Equipment Corporation

      Digital Equipment Corporation was a pioneering United States company in the computer industry. It is often referred to within the computing industry as DEC ....
       21154BE bridge chip.
    • PIX-4FE - 32 bit/33 MHz PCI Four port 10/100 Fast Ethernet card. Based on the Intel 82558b chipset. Uses an Intel 21154AC or DEC 21154AB bridge chip.
    • PIX-1FE - 32 bit/33 MHz PCI Single-port 10/100 Fast Ethernet card. Based on the Intel Pro/100+ family with the 82557, 82558 and 82559 chipsets.
    • ??? - 3COM
      3Com

      3Com is a manufacturer best known for its computer network infrastructure products. The company was co-founded in 1979 by Robert Metcalfe, Bruce Borden, and Greg Shaw, and is headquartered in Marlborough, Massachusetts, Massachusetts....
       3c590 and 3c595 PCI NIC's occasionally found in NTI PIX, PIX Classic, 10000, 510, 515, and 520. Mentioned in version 4.4.1 install guide and supported through at least PIX OS 5.1.5 . Since these are off-the-shelf PC components predating the creation of the PIX, there may not be PIX-specific part numbers for these at all.
  • VPN/Encryption acceleration cards
    • PIX-VAC-PLUS - 64 bit/66 MHz PCI IPSec
      IPsec

      Internet Protocol Security is a Protocol suite for securing Internet Protocol communications by authentication and encryption each packet #Example: IP packets of a data stream....
       Hardware VPN Accelerator Card, identified by PIX OS as a PIX-VAC+. Supported by the 515, 515e, 520, 525, and 535 running PIX OS 6.3(1) or higher. Accelerates DES, 3DES, and AES. Part number 74-3176-01. Uses the Broadcom
      Broadcom

      Broadcom Corporation is an United States supplier of integrated circuits for broadband communications. Founded in 1991 by Henry Samueli and Henry T....
       BCM5823KPB-5 chip.
    • PIX-VPN-ACCEL - 32 bit/33 MHz PCI IPSec
      IPsec

      Internet Protocol Security is a Protocol suite for securing Internet Protocol communications by authentication and encryption each packet #Example: IP packets of a data stream....
       Hardware VPN Accelerator Card, identified by PIX OS as a PIX-VAC. Accelerates DES and 3DES. This is a repackaged IRE SafeNet CryptPCI 413-10004 rev 2.3 card. It uses the Analog Devices
      Analog Devices

      Analog Devices is an United States Multinational corporation producer of semiconductor devices. Analog specializes in analog-to-digital converter, digital-to-analog converter, MEMS, and digital signal processing chips for consumer and industrial goods....
       ADSP-2141L chip. Its part number is 74-1908-01.
    • PIX-PL2 - 32 bit/33 MHz PCI proprietary DES
      Data Encryption Standard

      The Data Encryption Standard is a block cipher that was selected by National Bureau of Standards as an official Federal Information Processing Standard for the United States in 1976 and which has subsequently enjoyed widespread use internationally....
       encryption
      Encryption

      In cryptography, encryption is the process of transforming information using an algorithm to make it unreadable to anyone except those possessing special knowledge, usually referred to as a key ....
       card (discontinued and unsupported from PIX OS 6.0.1 on). It is manufactured by Productivity Enhancement Products.
    • PIX-PL - 32 bit/8 MHz EISA
      Extended Industry Standard Architecture

      The Extended Industry Standard Architecture is a bus standard for IBM compatible computers. It was announced in late 1988 by IBM PC compatible vendors as a counter to IBM's use of its Proprietary software MicroChannel Architecture in its IBM Personal System/2 series....
       encryption card found in some early PIXes. It is manufactured by Productivity Enhancement Products.
  • FDDI and Token Ring cards
    • PIX-1TR - 32 bit/33 MHz 4/16 Mbit/s PCI Token Ring
      IBM token ring

      Token ring local area network technology is a local area network network protocol which resides at the data link layer of the OSI model. It uses a special three-byte frame called a token that travels around the ring....
       card based on the Olicom OC-3137/PE-67597 (discontinued and unsupported from PIX OS 6.0.1 on).
    • PIX-FDDI - 32 bit/33 MHz 100 Mbit/s SC duplex PCI FDDI card based on the Interphase 5511 FDDI card (PB05511-002). It was discontinued and unsupported from PIX OS 6.0.1 on.


Footnotes

Only the first few NTI PIXes came with the 486 processor; the rest came with a Pentium processor.
The "inside" port is connected to an internal, unmanaged, auto-polarity 4 port switch
Network switch

A network switch is a computer networking device that connects computer network Network segment.The term commonly refers to a Network bridge that processes and routes data at the Data link layer of the OSI model....
.
Restricted package / Unrestricted package limits (referred to by Cisco as R and UR/FO/FO-AA, respectively). For PIX-525, RAM configurations above 384MB are not supported by Cisco however up to 3x 256MB work for a maximum of 768MB.
According to Cisco, the 1000baseSX card is not officially supported by the 515/515e, but it will work.
VAC acceleration vs VAC+ (in parenthesis) acceleration (Implies Unrestricted package).
Older 520's made before February 2000 and with a serial number less than 18025677 shipped with a 2 MB flash card. Newer 520's shipped with a 16 MB flash card .
The WS-SVC-FWM-1-K9 blade has no fixed ports or internal expansion; it makes use of either VLAN interfaces (being used by physical interfaces on a remote switch) or the physical interfaces on the switch/router it is installed in.
PIX Classic firewalls with a serial number of 06002015 or lower came with a 512KB flash card. Newer models came with a 2MB flash card .
The WS-SVC-FWM-1-K9 blade only supports IPSec VPN for management. It doesn't have the ability to terminate a VPN connection for remote users.
The PIX 520 received updated PII processors as they became available, starting with the PII 233 and ending with the PII 350. The Intel-manufactured ATX
ATX

The ATX Motherboard form factor was created by Intel in 1995. It was the first big change in computer case and motherboard design in many years....
 motherboard in the 520 can support any Slot1
Slot 1

Slot 1 refers to the physical and electrical specification for the connector used by some of Intel's microprocessors, including the Celeron, Pentium II and the Pentium III....
 processor from the Celeron
Celeron

The Celeron brand is a range of x86 CPUs from Intel targeted at budget/value personal computers?with the motto, "delivering great quality at an exceptional value"....
 Covington, Celeron Mendocino, Pentium II
Pentium II

The Pentium II brand refers to Intel's sixth-generation microarchitecture and x86 architecture-compatible microprocessors introduced on May 7, 1997....
 Klamath, Pentium II Deschutes, and the Pentium III
Pentium III

The Pentium III brand refers to Intel's 32-bit x86 desktop and mobile microprocessors based on the sixth-generation Intel P6 microarchitecture introduced on February 26, 1999....
 Katmai families, as long as the cpu uses 2.0v core voltage and can run on a 66 or 100 MHz fsb
Front side bus

In personal computers, the Front Side Bus is the bus that carries data between the central processing unit and the Northbridge .Depending on the processor used, some computers may also have a back side bus that connects the CPU to the CPU cache....
. One may also use 133 MHz FSB cpu's, but they will run at slower speeds, for example a 933 MHz cpu for 133 MHz FSB will only run at 700 MHz. A slotket
Slotket

In computer hardware terminology, slotkets, also known as slockets, are adapter s that allow socket-based microprocessors to be used on slot-based motherboards....
 can also be used to install the newer 500 MHz - 1.1 GHz Socket 370 Pentium III Coppermine cpus, as long as the slotket provides a voltage regulator and manual bus speed selector. Using the PowerLeap PL-iP3 converter, Tualatin processors can be used. A BIOS upgrade to the latest level of the SE440-BX2 is required. Using the bus-speed settings on the Powerleap, speeds of 1.6 GHz are possible.
The PIX 520 rev A firewalls may use the Intel motherboard instead of the SE440BX-2. The AL440LX may be replaced by a SE440BX-2 motherboard, which is found in the 520 rev B.
Cannot be easily upgraded, due to clearance issues with the top cover.
In early 2005, Cisco indicated that PIX OS 7.x would only support the 515, 515e, 525, and 535, while a "stripped-down" version would eventually be released for the 501 and 506e. While not officially supported, it is actually possible to update the 506E to 7.x code by removing all GUI management software.
The maximum OS version one can run with a 512KB card is 4.2(2). The maximum OS version one can run with a 2MB card is 5.1(x). The maximum OS version with a 16MB card is 6.3(5), unless one is using a PIX 535. OS version 5.2(4) and higher explicitly does not support the Intel 440FX chipset.
Shows flash chips on the 2 MB flash card versus the chips on the 16 MB flash card.
Various models of the 525 use different flash chips, probably due to differing production runs.
Shows flash chips on the 512KB flash card versus the chips on the 2 MB flash card.
While the PIX 535 boots off of the same ISA flash card as some PIX 510's and 520's (the PIX-FLASH-16MB) its newer on-board PIX BIOS (version 4.x) overrides the PIX BIOS on the flash card (version 3.6) at boot.
Since both the 510 and 520 have standard ATX motherboards, the PCI slot count can be higher or lower than the default if the motherboard is replaced with a different one.
The performance figures cited here are highly changeable, as one can upgrade the CPU in the PIX 520 to a 1 GHz Pentium III, which will considerably increase its throughput in all of the below categories, putting it on a level with the 525 and 535.
According to a 2000 field notice, due to a "procedural error", PIX 525's with serial numbers 44480380055 through 44480480044 were manufactured with erroneous or omitted EEPROM
EEPROM

EEPROM stands for Electrically Erasable Programmable Read-Only Memory and is a type of non-volatile memory used in computers and other electronic devices to store small amounts of data that must be saved when power is removed, e.g., calibration tables or device configuration....
 programming in their 82559 chips that caused the onboard FastEthernet ports to behave erratically when set to full-duplex. Starting with PIX OS 5.3.1, the "eeprom update" command will reprogram the defective data and restore normal operation permanently. Viewing the field notice requires registration . Most, if not all, 525's in use today within that range have likely been corrected, but an unused or unopened unit within that range would still need the corrective action to be taken.
It is theoretically possible to upgrade the Socket 8
Socket 8

Socket 8 CPU socket was used exclusively with the Intel Pentium Pro and Pentium OverDrive#Pentium Pro sockets computer central processing unit....
 Pentium Pro
Pentium Pro

The Pentium Pro is a sixth-generation x86-based microprocessor developed and manufactured by Intel introduced in November 1995. It introduced the Intel P6 and was originally intended to replace the original Pentium in a full range of applications....
 processor in the PIX Classic and 10000 with either an Intel Pentium II Overdrive (300 or 333 MHz depending on the system bus speed) or a Powerleap PL-Pro/II Celeron
Celeron

The Celeron brand is a range of x86 CPUs from Intel targeted at budget/value personal computers?with the motto, "delivering great quality at an exceptional value"....
 adapter, both of which are long out of production. The Powerleap adapter natively can allow use of a 300 - 533 MHz Mendocino Celeron PPGA processor. Coupled with the Powerleap Neo S370 FC-to-PPG adapter, one can use a 533 - 766 MHz FC-PGA Coppermine-128 Celeron processor. However, the 60 or 66 MHz bus (no 100 MHz bus) and 72-pin SIMM
SIMM

A SIMM, or single in-line memory module, is a type of memory module containing random access memory used in computers from the early 1980s to the late 1990s....
 memory limitations of the workstation-style 440FX board used limit the potential gains in performance to be had from such upgrades. Upgrading the motherboard to a compatible server-style 440FX board with DIMM
DIMM

A DIMM, or dual in-line memory module, comprises a series of dynamic random access memory integrated circuits. These modules are mounted on a printed circuit board and designed for use in personal computers, workstations and Server s....
 slots may allow for the use of the 440FX chipset's theoretical limit of 1 GB of RAM, although if the motherboard is to be replaced, it may arguably be more cost-efficient to upgrade to a SE440BX-2 motherboard with a slocket and Tualatin Celeron CPU. It is also worthwhile to note that PIX OS later than 5.3.4 explicitly does not support the 440FX chipset.
The PIX 525 is known to come with a variety of processors including 1.65V 600MHz (SL3VH) and 1.75V 600MHz (SL5BT). It would appear that all 1.65V to 1.75V 100MHz FSB CPUs would work, this has been substantiated to 1000MHz with a SL5QV 1.75V CPU.
The first PIX Classics did not support failover. Only after this feature debuted with the LocalDirector did it come to be included in the later PIX Classics.
At least one person has successfully replaced the 506E's Celeron 300Mhz/66Mhz FSB with a Pentium III 600Mhz/133Mhz FSB CPU; Giving close to 525 specifications.

Citations


See also

  • Cisco LocalDirector
    Cisco LocalDirector

    Cisco LocalDirector is a server load balancing appliance, discontinued in 2003, based on the Network Address Translation technology Cisco Systems acquired when they bought Network Translation, Inc....
  • Cisco SSG6510
    Cisco SSG-6510

    The Cisco SSG-6510 was a device introduced by Cisco in 1998 that allows dynamic direction of IP traffic to various services. It was typically deployed at the edge of a service provider's network where users would connect, log in, and be directed to whatever service they were paying for....


External links



The following links may require a free registration at Cisco's website to view.