Skip Links

Network World

Brad Reese

Quiet Cisco PIX end-of-sale (EOS) notice kindles PIX trade-in offer from Astaro

By Brad Reese on Sun, 02/03/08 - 9:50am.
Newsletter Signup

Upgrade Your PIX Trade-in Program

Twelve years after its 1995 acquisition of PIX (Private Internet EXchange) creator - Network Translation, Inc., Cisco has quietly released:

End-of-Sale (EOS) Notice for Cisco PIX Products

The Cisco EOS notice covers all PIX security appliances, software, accessories and licenses for:

PIX 501
PIX 506E
PIX 515E
PIX 525
PIX 535 systems and spares
Cisco PIX Software Releases 6.2, 6.3, 7.0, 7.1, 7.2, and 8.0
All accessory items such as power supplies, I/O cards, memory upgrade kits, VPN Accelerator Card Plus (VAC+) cards and software licenses.

Cisco PIX EOS Dates

Milestone
Explanation
Date
External announcement
The date when the end of sale and end of life of a product is announced to the general public.
January 28, 2008
End-of-sale date for platforms/bundles
The last date to order the platform and bundles.
July 28, 2008
End-of-sale date for accessories
The last date to order the accessories.
January 27, 2009
End of software maintenance releases
The last date that Cisco Engineering may release any final software maintenance releases or bug fixes. After this date, Cisco Engineering will no longer develop, repair, maintain, or test the product software.
July 28, 2009
End of new service attachment date
For equipment and software that is not covered by a service-and-support contract, this is the last date to order a new service-and-support contract or add the equipment and/or software to an existing service-and-support contract.
July 28, 2009
End of service contract renewals
The last date to extend or renew a service contract for the product. The extension or renewal period cannot extend beyond the last date of support.
October 23, 2012
End of support/end of life
The last date to receive service and support for the product. After this date, all support services for the product are unavailable, and the product becomes obsolete.
July 27, 2013


So far, the Linux platform based Unified Threat Management (UTM) solution vendor Astaro, has been the only competitor to address the Cisco PIX end-of-sale notice by announcing its Upgrade Your Cisco PIX trade-in program.

Over 100,000 IT administrators entrust their network with security appliances from Astaro.

The Astaro trade-in program offers Cisco PIX users 20% off the list price on all Astaro hardware, software and maintenance for 3 or 5 year agreements, with the return of a Cisco PIX firewall appliance.

Jan Hichert"Astaro’s ease of use and robust feature set has always made us an effective platform that Cisco Pix users upgraded to," said Jan Hichert - Astaro CEO.

"When companies announce the end-of-life of an appliance line it essentially means that the product and the technology is now obsolete."

"Now with users forced to choose a migration path, we want to make sure that PIX users know there is an option available that can increase their protection and save them money vs. the ASA path being offered by Cisco."

Astaro vs. Cisco PIX

Astaro Security Gateway
Cisco PIX
Astaro WebAdmin is intuitive, so even basic users can build rules and make changes without special training. Proprietary command line IOS interface is realistically usable by certified personnel only. All configuration done with included WebAdmin GUI.
Rudimentary GUI supported offered via the Cisco Device Manager only.
Offers over 7000 IDS patterns standard, in addition to firewall, VPN, routing, NAT, and more. Acts as a firewall/vpn/router only. IPS has a poor amount of patterns/attacks base. VPN Performance from 50-600+ Mbps using AES or 3DES technology in various configurations. Low VPN Performance, even on high-end models (under 100 Mbps). ASG base model 120 offers 512MB RAM, with up to 4GB on higher models. Uses latest processors from Intel. Low hardware specifications yield poor throughput. (32MB RAM, 16 MB flash RAM). SSL VPN Support comes Standard /w Unlimited clients included free of charge. No SSL Roadwarrior VPN support.


Astaro vs. Cisco Adaptive Security Appliances (ASA)

Astaro Security Gateway
Cisco ASA 5510/5520/5540
Full SSL VPN /w Unlimited Clients included. 2 SSL VPN Licenses included for demo/evaluation. Additional purchase required. Base functionality includes Firewall, Roadwarrior VPN, Site-Site VPN, Intrusion Detection & Prevention, and Basic Web & Email Filtering. Only Firewall and VPN included in base functionality. No add-in slots required to enable all UTM features on the same platform. 1 Add-in slot for expanding functionality to include IPS, more ports, or Filtering. Intrusion Prevention & Detection included standard with over 7000 patterns. IPS only available with AIP SSM add-in card at extra charge. Dual AV Engines, Anti-Spyware, Anti-Phishing, Content Filtering, and Malware blocking available with just a software license. AV/Anti-Spyware/File Blocking only available with CSC SSM add-in card. 8 x 10/100/1000 Ethernet ports based on model selected. 5 Ethernet ports in various 10/100/1000 configurations depending on model. 7th Generation WebAdmin GUI uses immersive technology tools like AJAX and Javascript to produce a clean, fast, and effective management platform. 1st Generation GUI is kludgy and dated. Offers true UTM functionality by including all features on a single box. Not possible to outfit ASA with all offerings due to expansion port limitations. Web Filtering offers access to more than 39 million categorized sites and over 2.5 billion URL’s and objects. Profile creation allows selection of sites in over 50 categories. The ASA Anti-X option includes some basic web filtering capabilities only. To get advance web filtering comparable to Astaro's you have use external subscription services from 3rd party URL partners.


Astaro vs. Competitors

 
                 
Choice of hardware or software solution
Intuitive web-based GUI for complete system management
One-click VPN for easy SSL remote access (free of charge)
IPsec, SSL, PPTP and L2TP VPN support on all appliances

Dual, independent anti virus engines

Clientless email encryption (TLS, S/MIME, OpenPGP)

Virus scanning for encrypted emails (S/MIME & OpenPGP)

Extensive set of multiple spam detection capabilities

Quarantine for spam mails on local hard drive

Time, user and group based URL filtering policies

Prevent spyware infection and hidden "phone home" communication

Automatic system software updates

End user self servicing portal for spam and VPN management

Active/Active cluster with integrated load balancing

VMWare support



Curious to know what method Astaro will deploy to jettison returned Cisco PIX trade-in units?


Related Story:

Network World Cisco sets last sale date for PIX firewall


Contact Brad Reese
http://www.BradReese.Com

What will Astaro do with PIX?

0

With support being such a bear, I doubt if Astaro will do much with returned PIX boxes other than to use them as glorified paper weights. To the recycle bin they will go.

antiquated technology was tops in its heyday

0

PIX is an antiquated technology that enjoyed a great run but truth be told, its annual service contract cost more than buying a new device from a competitor. The point is to get these obsolete appliances out of peoples' networks and into places like the Smithsonian.

Cisco vs. Astaro Confusion

0

Received the following private email message:

---------------------------

Brad/Reggie—

Thought the chart comparing Cisco vs. Astaro to be interesting, but I was confused.

I teach Cisco firewalls as part of my job, and in the class I taught last week, I gave lessons on:

Cisco GUI management (ASDM, which is actually second-generation at least after PDM, even if you don’t count the PDM and SDM revisions);

One-click VPNs via wizards;

Time, User and group-based URL filtering and traffic filtering

Active/Active clustering

I don’t mind looking at competitive products in the marketplace, but I do find it odd to misstate the capabilities of any competitor simply to make Astaro look better.

I was ready to forward your email out to my customers, but the misstatements in the email make me reluctant to give them information about your product with the incorrect information about other products included.

Did I miss something?


Official response from Astaro

The chart you used in the story was actually made by Astaro marketing, which of course usually assumes the best case using challenge words, something that Astaro competitors do as well.

It is also quite old, and needs updating.

1. For the GUI, Cisco uses the word intuitive, which of course is open to debate depending on whom is using the GUI.

A person who is Cisco expert and heavily familiar with the Cisco GUI, probably can move through it quite quickly.

The point Astaro is trying to make is that its WebAdmin is considered easier and more intuitive to use, not that Cisco has no GUI at all.

Suggest that Astaro marketing reword this.

---------------------------

2. In regards to One-Click VPN, Astaro's focus is more on the Free of Charge statement, since ASA does have SSL vpn, (Astaro is not web portal based but rather a full IP ssl vpn) however Cisco offers only a 2 client sampler free of charge, not unlimited clients for multi-OS’s as part of the base price.

Being a marketing chart, Astaro once again is shining the light in the best possible way for Astaro.

---------------------------

3. For the URL filter, this is incorrect as ASA does this, optionally, however this statement was supposed to have the Edirectory SSO and AD SSO in it, thus making the checkboxes correct.

---------------------------

4. Active/Active clustering should read as Zero Configuration One Click Active-Active Clustering indicating Astaro’s feature requires no setup at all, simply plug in a new Astaro and the first one will assimilate it and build the cluster automatically.

It appears Astaro marketing took a few liberties here on this chart.


Sincerely,

Brad Reese
http://www.BradReese.Com

I find the argument that the

0

I find the argument that the PIX is realistically usable only by Cisco certified staff to be a bit of a feature, when compared to allowing basic users to configure a firewall, as Astaro would have you believe.

Does the argument carry then that if you were replacing your PIX in the data center, you would also no longer need those certified staff's knowledge of proper security techniques and best practices? Or does Astaro GUI provide that also? Maybe they have their version of MS's 'Clippy' to help you along?

Sounds to me that Juniper's Netscreens will be getting a close look when it comes time to replace the PIX's in places where security really matters.

some truth

0

I maintain a cisco pix for my employer. I have a very good understanding of and ability to implement best security practices. I sure as hell can't do it on a Pix. They us a very specific command structure that is different from any other Cisco equipment, classes are difficult to find, and even consultants who understand the PIX are difficult to find. I do minimal maintanence and use the pay and pray method (pay someone to do it and hope they understand what I want).

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.
Welcome, visitor. Register Log in
Advertisement:
About Brad Reese on Cisco

Brad Reese cofounded BradReese.Com Cisco Refurbished which offers one year warranties on Cisco Refurbished and Cisco Repair.

Contact Brad Reese

Archives
July 2009
June 2009
May 2009
April 2009
March 2009
February 2009
January 2009
December 2008
November 2008
October 2008
September 2008
August 2008
July 2008
June 2008
May 2008
April 2008
March 2008
February 2008
January 2008
December 2007
November 2007
October 2007
September 2007
August 2007
July 2007
June 2007
May 2007
April 2007
March 2007
February 2007
January 2007
Categories
1811 expands to 384Mbps of DRAM and 128Mbps of Flash
A UBS analyst is reporting that Cisco's losing market share across the board
A company's monthly network communications cost will be reduced
A government official in possession of a large corporate stockholding while that corporation is subject to administrative rulings by that same government official
Agito adds that its enterprise fixed mobile convergence (eFMC) platform enables low-cost in-building voice coverage
Agito introduced Agito for BlackBerry
Agito's BlackBerry smart phone functionality for Cisco VoIP
Agito's RIM BlackBerry support announcement
An assortment of communications companies
Apple iPhone 3G S
Apple will begin selling its new iPhone 3G S
Applying a Mask of 11111111.11111111.11111111.0000
Back in April the CCIE Security track changed
Before Cisco CTO Padmasree Warrior was hired by Cisco
Below are two addresses broken out from dotted decimal to binary and then redisplayed with dots separating octet boundaries
Bill Alderson - NetQoS Technology Consulting Officer
Black Hat attack on Cisco's network admission control (NAC)
Boas also led an educational session at the Gartner Security Summit
Boas shares his insight on the most prevalent threats to the enterprise network
Brings enterprise VoIP over WiFi for dual-mode BlackBerry smartphones
Careers
Certified by Cisco-Linksys technicians via Linksys ISO certification procedures
Chairman and CEO of Cisco China - Jim Sherriff
Cisco
Cisco 1811 IOS 12.4 with SDM is the standard for Cisco CCNA – Security Labs
Cisco 1811 is now standard on the Cisco CCIE Security Lab with IOS 12.4T
Cisco Flip Video Camera
Cisco NAC design flaws that the folks at Black Hat so alarmingly described
Cisco has produced a new CCIE count
Cisco has successfully made the market transition to selling refurbished Linksys directly to end users
Cisco is also offering its new home media ensemble
Cisco is celebrating its 25th anniversary this year
Cisco merged the Linksys channel partner program into Cisco's registered partner tier
Cisco only counts your CCIE number once
Cisco registered the shoplinksys.com domain name to sell refurbished Linksys
Cisco released its new worldwide CCIE count
Cisco sales plummeted $1.6 billion (Page 4) and operating income nose-dived $1 billion
Cisco shouldn’t until it works out the kinks
Cisco's executive biographies web page
Compromised the Cisco agent installed on the end system
Confirmation testimony before the U.S. Senate noteworthy
Customer-proven best practices of network access control (NAC)
DSL/Cable with the Cisco 1811 makes sense
Data Center
Desai previously served as Chief Operating Officer of Radware (NASDAQ: RDWR)
Didn’t RIM already support voice over WiFi?
Doesn’t RIM’s Ascendent acquisition give them this?
Dotted decimal addresses that end up falling under a non-octet boundary subnet mask
Dual CCIE #18532 Routing and Switching/Security - George Morton
Dual Cisco CCIE #18532 Security/R&S - George Morton
Dual-mode BlackBerry smartphones
During the first 9 months of Cisco's 2009 fiscal year under Warrior's leadership as CTO
Each eight bits being converted to decimal
Enables BlackBerry to be integrated into corporate PBXs and Unified Communications systems
Enterasys NAC is agent-less assessment based on a network scan
Enterasys security expert Dennis Boas
Enterasys uses multiple criteria beyond end system health assessment to assign and limit access granted to an end system
Enterprise concerns about the financial and management aspects of NAC
Enterprises that have standardized on the BlackBerry platform
FCC requires the old Bell System to report its T1 outage and that the repair needs to be under 4 hours for 95% of all T1 outages
Famous networking industry journalist
Feature allowing entry of a real address mask of your own to test if it is on the same or remote network
Flexible options with Enterasys NAC
HP and Liquid Computing
Half the smartphones in use in the US today are BlackBerry devices
How Cisco was working overtime AGAINST the Buy America provisions of the $7.2B broadband stimulus fund
How LiquidIQ Works
How useful do you find this subnet calculator?
I developed the Subnet Calculator to make learning more demonstrative and fun
I have worked for a handful of telecommunications companies of varying sizes
I voted for President Obama seeking change
In the subnet calculator the binary and the n
Interesting CCIE news from around the world
Internet access at the branch would run faster than traditional T1 services
Is Cisco getting ready to sell its refurbished gear directly to end users too?
Is George Morton on to something here?
It will kill the Cisco Flip video camera
Its been proven that a government official can be bribed with free dinners
Joel Bion - Senior Vice President of Cisco's Product Resiliency Research
LANs / WANs
Larry Strickling is confirmed as the new Administrator of the National Telecommunications and Information Administration (NTIA)
Last month Cisco missed the multiple CCIE numbers
Leaving Warrior with absolutely no future as the CTO of Motorola
Linksys by Cisco Certified Refurbished Product
Linksys by Cisco Wireless Home Audio System
Liquid Computing's definition of unified computing (LiquidIQ) is a flexible
LiquidIQ Business Continuity - Disaster Recovery Made Simple
LiquidIQ Technical Specifications
LiquidIQ Total Software Control - LiquidView Management
LiquidIQ can consolidate functions including web
LiquidIQ is the only UCS system that's listed by VMware to support VSphere
LiquidIQ is the only standards-based unified computing solution that’s in production today with paying customers
LiquidIQ was designed with built-in security
Made by Strickling during his March 19
Manny Rivelo - Senior Vice President of Cisco's Development Organization
Market failures for business class DSL/Cable is unacceptable
May 2009 vs. June 2009 Worldwide CCIE Count Comparison
Mobile features integrated into the BlackBerry
Morton believes with DSL/Cable services having up to 18Mbps of download availability
Morton's design would route all requests over the DMVPN-mGRE
Motorola operating earnings dropped $3.8 billion to a loss of $534 million
Motorola sales had collapsed by more than $4 billion (Page 1)
Multiple pipes with QoS for voice dedicated to one uplink and data services on the second link
My previous government service at the FCC provide me a unique background for the position of Assistant Secretary
NetQoS Subnet Calculator offers a view of every bit in the IP address to help network engineers understand how IP subnetting works
Network Management
Network World's Data Center Derby story acknowledged Liquid's first-mover advantage with its unified data center concept
Network performance management vendor NetQos
Network security vendor Enterasys
Nortel had purchased Alteon for $7.8 billion
Not too many senior executives are around from Cisco's early days
Omitted the years of Cisco service for both John Morgridge and Richard Justice because they are no longer full-time Cisco executives
Only 66% of all applicants who passed were for the CCIE Router and Switch track
Only one CCIE is a member of Cisco's 59 strong senior executive team
Pacific Rim CCIE numbers didn't change over the last 39 days
Pejman Roshan - Chief Marketing Officer of enterprise fixed mobile convergence (eFMC) vendor Agito Networks
Ponemon Institute reported
R & S + Security this year as the most popular dual CCIE track
R & S + Service Provider was 49% of the successful attempts for dual CCIE
RIM offers only data services over WiFi on their dual-mode smartphones
Radware recently purchased Nortel's application delivery business (Alteon) for the cut-rate price of $18 million
Refurbished product are mostly customer returns that meet original factory specifications
Refurbished product sold in the United States
Responsible for Cisco's IOS Software
SMB
Screenshot of the NetQoS Subnet Calculator
Security
Security mechanisms are used to validate the integrity and authenticity of the Enterasys agent for all server/agent communications
She was the CTO of Motorola and dismissed in her blog the introduction of the Apple iPhone
Showed that Stickling owned a large Cisco stock position
So we had 251 new CCIEs
Start by entering your address and mask in the calculator
Subject of Cisco's senior executive team came up
The Federal Reserve has moved from complex Cisco routers with T1 service to Cisco low end routers (ISR 1811) with DSL
The IOS 12.4 track with ISR routers is slowing down the Security CCIE track
The National Telecommunications and Information Administration (NTIA) granted Cisco its coveted Buy American Exception
The average tenure would be of the 61 executives listed on Cisco's Mount Rushmore
The change in the CCIE Security track has had a major impact on new security CCIEs
Until one takes some real addresses and experiments with how the mask affects the address bits
View Cisco's flash promotion for its home media ensemble
View more Cisco Tools
Vik Desai - President and Chief Executive Officer of unified computing infrastructure vendor - Liquid Computing
VoIP / Convergence
Warrior is now repeating her Motorola failure at Cisco
We're also now starting to see the CCIE Wireless track
We've experienced a new low for CCIE Security track
What exactly has Agito Networks announced this week?
What's your take on the implications of the new worldwide Cisco CCIE count?
Why is cellular-only PBX and UC integration incomplete?
Why the Enterasys NAC solution is doing so well
Why the Enterasys NAC solution is in such high demand
Wireless / Mobile
Within 9 months of the Apple iPhone introduction
On The Web
Twitter