Playing off of Cisco CEO John Chambers’ security-themed keynote address at Interop Tuesday, Cisco this week introduced a security appliance that rolls multiple services into a single box, with the aim of making it easier for businesses to secure network borders.
Unveiled at the Interop 2005 conference in Las Vegas, the Adaptive Security Appliance (ASA) 5500 is designed to collapse VPN, firewall, intrusion prevention system (IPS), and other services into a single box. The device could help users deploy less security gear and make it easier to manage the detection and prevention of blocking worms, viruses, spyware and other unwanted network traffic.
The ASA 5500 series combines the functions of PIX firewalls, Cisco VPN 3000 Concentrators, Cisco IPS 4200 series appliances, and anti-virus and network quarantine technology based on Cisco’s Network Admission Control (NAC) multi-vendor effort.
The devices come in three models: the ASA 5510, 5520 and 5540, which support 300M bit/sec, 450M bit/sec and 650M bit/sec of security processing bandwidth, respectively. Cisco claims each device can move traffic at its maximum throughput rate with all services turned on — stateful firewall traffic inspection, SSL VPN and IPSec encryption and tunnel termination, as well as IPS functions.
The device runs a management application that allows users to administer multiple network security services from a single interface. Policies can more easily be pushed across VPN, firewall and IPS services running on the box. Users can also use this tool to configure anti-spyware, anti-virus and denial-of-service attack detection services, as well as singling out and controlling specific applications (such as Kazaa or other peer-to-peer applications).
The boxes are meant to sit at the edge of a corporate network, securing incoming and outgoing packet flows, as well as remote access VPN traffic. The devices could also reside in a corporate data center, or on segments of a LAN, allowing administrators to restrict access to certain network assets, or to monitor internal traffic for malicious software.
Cisco said it plans to integrate the ASA technology into its Catalyst 6500 switch platform, as well as a service blade in its access routers. But the company did not give a road map for when this would happen.
To build the new multi-function box, Cisco technologists said that pieces of code from various security product operating systems were combined under a new real-time operating system based on a “Linux-like” kernel, designed specifically for security.
“There are elements of IOS (Cisco’s main device operating system), and there are elements of legacy systems, such a PIX firewall, VPN Concentrator,” and IPS appliances, says Jason Nolet, director of engineering at Cisco. “We leveraged parts of IOS where it made sense, and parts of other operating systems that had the best capabilities we were looking for.”
Nolet said that each function of the ASA 5500 — VPN, firewall, IPS — can integrate into a current Cisco VPN, PIX firewall or IDS deployment. VPN 3000 devices, for example, would recognize the ASA 5500 as a peer device, as would PIX firewalls or IDS appliances deployed across an enterprise. Security services running on the ASA 5500 could be managed via existing security management tools, such as Cisco’s VPN/Security Management Solutions (VMS). But ultimately, the goal is to have users migrate off of legacy security management to the ASA 5500 platform, Cisco executives adds.
“The benefit of this is obvious,” says Jayshree Ullal, senior vice president of Cisco’s Security and Technology Group. “You don’t have to log in and out of firewalls and IDS devices,” and VPN gear. “You’re dealing with just one device.”
Cisco says it plans to announce more securty services for the ASA 5500 relating to its Network Admission Control program later this year, along with anti-virus and other security vendor partners.
The Cisco ASA 5510 costs $3,500, while the ASA 5520 costs $8,000 and the ASA 5540 costs $17,000. All products are available now.




