<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I believe starting at version in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5585x-vs-palo-alto-3020-differences-help-needed/m-p/2544860#M237188</link>
    <description>&lt;P&gt;I believe starting at version 12.4(6)&amp;nbsp;and version 15.x Cisco does support zone based firewalls&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(82, 82, 82); font-family: arial, helvetica, 'Helvetica Neue', HelveticaNeue, 'Lucida Grande', sans-serif; font-size: 13px; line-height: 16.25px;"&gt;Cisco IOS® Software Release 12.4(6)T introduced Zone-Based Policy Firewall&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/ios-firewall/98628-zone-design-guide.html&lt;/P&gt;</description>
    <pubDate>Mon, 05 Oct 2015 17:54:11 GMT</pubDate>
    <dc:creator>tabique22</dc:creator>
    <dc:date>2015-10-05T17:54:11Z</dc:date>
    <item>
      <title>ASA 5585X vs Palo Alto 3020 - differences - help needed understanding</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585x-vs-palo-alto-3020-differences-help-needed/m-p/2544854#M237179</link>
      <description>&lt;P&gt;I was hoping to get some clarifications on the ASA technology vs the Palo Alto 3020. Below are the specs from the website for the 3020.&lt;/P&gt;&lt;P&gt;Questions&lt;/P&gt;&lt;P&gt;1) I believe the ASA 5585X would be right choice/equivalent: ASA5585-S10C10-K9.&amp;nbsp; Correct?&lt;/P&gt;&lt;P&gt;2) The ASA doesn't have zones, only Security Contexts, right?&lt;/P&gt;&lt;P&gt;3) The Palo Alto box lists "Virtual routers, virtual systems and zones. What are the ASA equivalents? I imagine Virtual Systems is the equivalent of a Security Context but I'm not sure. Any explanations here would be very helpful.&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(31, 73, 125);"&gt;&lt;FONT face="Calibri"&gt;Palo Alto PA-3020 Hardware Firewalls&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: rgb(31, 73, 125);"&gt;&lt;FONT face="Calibri"&gt;•&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 Gbps firewall throughput (App-ID enabled1)&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: rgb(31, 73, 125);"&gt;&lt;FONT face="Calibri"&gt;•&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 Gbps threat prevention throughput&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: rgb(31, 73, 125);"&gt;&lt;FONT face="Calibri"&gt;•&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 500 Mbps IPSec VPN throughput&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: rgb(31, 73, 125);"&gt;&lt;FONT face="Calibri"&gt;•&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 250,000 max sessions per second&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: rgb(31, 73, 125);"&gt;&lt;FONT face="Calibri"&gt;•&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 50,000 new sessions per second&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: rgb(31, 73, 125);"&gt;&lt;FONT face="Calibri"&gt;•&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1,000 IPSec VPN Users&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: rgb(31, 73, 125);"&gt;&lt;FONT face="Calibri"&gt;•&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 Virtual routers&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: rgb(31, 73, 125);"&gt;&lt;FONT face="Calibri"&gt;•&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1/6 virtual systems (base/max2)&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: rgb(31, 73, 125);"&gt;&lt;FONT face="Calibri"&gt;•&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 40 security zones&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: rgb(31, 73, 125);"&gt;&lt;FONT face="Calibri"&gt;•&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2,500 max number of policies&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:23:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585x-vs-palo-alto-3020-differences-help-needed/m-p/2544854#M237179</guid>
      <dc:creator>jacob6000</dc:creator>
      <dc:date>2019-03-12T04:23:02Z</dc:date>
    </item>
    <item>
      <title>1) I believe the ASA 5585X</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585x-vs-palo-alto-3020-differences-help-needed/m-p/2544855#M237183</link>
      <description>&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;1) I believe the ASA 5585X would be right choice/equivalent: ASA5585-S10C10-K9.&amp;nbsp; Correct?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;No, the 5525X with a 10 context license would be a more accurate match for the Palo Alto settings you posted.&amp;nbsp; The only difference would be the new sessions per second is 20,000 on the ASA...all other stats match.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;2) The ASA doesn't have zones, only Security Contexts, right?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Correct, the ASA contexts are virtual firewalls.&amp;nbsp; Though secure zone and non-secure zone would either be defined by a security context or security-levels on the interfaces (accompanied with ACLs)&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;3) The Palo Alto box lists "Virtual routers, virtual systems and zones. What are the ASA equivalents? I imagine Virtual Systems is the equivalent of a Security Context but I'm not sure. Any explanations here would be very helpful.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;This I am not sure of, as I am not very familiar with Palo Alto...yet &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp; But for a little explanation, the ASA is a firewall, with some routing capabilities and each context has its own routing table.&amp;nbsp; So I would assume that virtual routers and virtual systems could be combined into what the ASA defines as a security context.&amp;nbsp; Cisco routers have zones defined when using the zone based firewall, however the ASA does not define security zones in the same way.&amp;nbsp; Zones on the ASA would be the administrator defining a interface security level, or a context and defining the network connected to the interface or context as being a highly sensitive subnet, regular user subnet, internet...etc.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2014 08:52:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585x-vs-palo-alto-3020-differences-help-needed/m-p/2544855#M237183</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-06-26T08:52:47Z</dc:date>
    </item>
    <item>
      <title>I use Palo Alto firewalls</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585x-vs-palo-alto-3020-differences-help-needed/m-p/2544856#M237184</link>
      <description>&lt;P&gt;I use Palo Alto firewalls extensively in the past and also have used ASA's since inception.&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;Questions&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;&lt;STRONG&gt;1) I believe the ASA 5585X would be right choice/equivalent: ASA5585-S10C10-K9.&amp;nbsp; Correct?&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;The correct firewall to size against the PA-3020 would be the ASA 5585-X SSP-20 w/ FirePOWER Services. An important thing to note is sizing needs to be with full Application/IPS detection. Here is a great reference: &amp;nbsp;http://www.cisco.com/c/en/us/products/collateral/security/asa-5500-series-next-generation-firewalls/datasheet-c78-732253.html&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;&lt;STRONG&gt;2) The ASA doesn't have zones, only Security Contexts, right?&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;Both the ASA and Palo Alto have similar zones and virtual firewalls you can bring up. The wording is a little different but function similarly.&amp;nbsp;&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;&lt;STRONG&gt;3) The Palo Alto box lists "Virtual routers, virtual systems and zones. What are the ASA equivalents? I imagine Virtual Systems is the equivalent of a Security Context but I'm not sure. Any explanations here would be very helpful.&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;Cisco leverages 'contexts' while Palo Alto leverages 'VSYS'. Here is a reference for ASA:&amp;nbsp;http://www.cisco.com/c/en/us/td/docs/security/asa/asa72/configuration/guide/conf_gd/contexts.html#wp1002608&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;Here is the reference for Palo Alto:&amp;nbsp;https://live.paloaltonetworks.com/docs/DOC-3892&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;I hope this helps.&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;Ricky Boyd&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;CCIE&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;Please rate if helpful&lt;/P&gt;</description>
      <pubDate>Tue, 25 Nov 2014 06:26:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585x-vs-palo-alto-3020-differences-help-needed/m-p/2544856#M237184</guid>
      <dc:creator>rdboyd</dc:creator>
      <dc:date>2014-11-25T06:26:46Z</dc:date>
    </item>
    <item>
      <title>Hi ,I believe that asa 5585-x</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585x-vs-palo-alto-3020-differences-help-needed/m-p/2544857#M237185</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;I believe that asa 5585-x does not support trafficfic shaping the way palo alto is doing .?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2015 00:27:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585x-vs-palo-alto-3020-differences-help-needed/m-p/2544857#M237185</guid>
      <dc:creator>susim</dc:creator>
      <dc:date>2015-07-02T00:27:31Z</dc:date>
    </item>
    <item>
      <title>Both the ASA and PA support</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585x-vs-palo-alto-3020-differences-help-needed/m-p/2544858#M237186</link>
      <description>&lt;P&gt;Both the ASA and PA support traffic shaping. This is actually a great feature to limit unwanted traffic too - if designed correctly.&lt;/P&gt;&lt;P&gt;As with Cisco and Palo Alto, the higher end hardware will obtain better results for traffic shaping.&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;Ricky Boyd&lt;/P&gt;&lt;P&gt;CCIE 2901&lt;/P&gt;&lt;P&gt;Security and Data Center Consultant&lt;/P&gt;&lt;P&gt;Dimension Data&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2015 06:38:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585x-vs-palo-alto-3020-differences-help-needed/m-p/2544858#M237186</guid>
      <dc:creator>rdboyd</dc:creator>
      <dc:date>2015-07-02T06:38:11Z</dc:date>
    </item>
    <item>
      <title>Hi,In palo alto we can create</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585x-vs-palo-alto-3020-differences-help-needed/m-p/2544859#M237187</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;In palo alto we can create 8 classes where we can give priority (high ,low..)&lt;BR /&gt;and Egress Max and Egress Guaranteed . Is it possible in the same way&amp;nbsp;&lt;/P&gt;&lt;P&gt;Moreover that&amp;nbsp;&lt;/P&gt;&lt;P&gt;based on the appication &amp;nbsp;(for example skype , windows update ) we can limit the traffic&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2015 08:43:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585x-vs-palo-alto-3020-differences-help-needed/m-p/2544859#M237187</guid>
      <dc:creator>susim</dc:creator>
      <dc:date>2015-07-02T08:43:46Z</dc:date>
    </item>
    <item>
      <title>I believe starting at version</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585x-vs-palo-alto-3020-differences-help-needed/m-p/2544860#M237188</link>
      <description>&lt;P&gt;I believe starting at version 12.4(6)&amp;nbsp;and version 15.x Cisco does support zone based firewalls&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(82, 82, 82); font-family: arial, helvetica, 'Helvetica Neue', HelveticaNeue, 'Lucida Grande', sans-serif; font-size: 13px; line-height: 16.25px;"&gt;Cisco IOS® Software Release 12.4(6)T introduced Zone-Based Policy Firewall&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/ios-firewall/98628-zone-design-guide.html&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2015 17:54:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585x-vs-palo-alto-3020-differences-help-needed/m-p/2544860#M237188</guid>
      <dc:creator>tabique22</dc:creator>
      <dc:date>2015-10-05T17:54:11Z</dc:date>
    </item>
    <item>
      <title>I don't think the Palo Alto</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585x-vs-palo-alto-3020-differences-help-needed/m-p/2544861#M237189</link>
      <description>&lt;P&gt;I don't think the Palo Alto chassis setup is&amp;nbsp;redundant. You have to buy 2.&lt;/P&gt;&lt;P&gt;With the 6500, 2 sups, 2 ASA-SM, 2 Line cards, 2 power supplies in one box!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, the Palo Alto only supports 64k prefixes.&lt;/P&gt;&lt;P&gt;My .02 worth&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2015 19:42:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585x-vs-palo-alto-3020-differences-help-needed/m-p/2544861#M237189</guid>
      <dc:creator>fsebera</dc:creator>
      <dc:date>2015-10-05T19:42:56Z</dc:date>
    </item>
  </channel>
</rss>

