<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX 520 Replacement in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-520-replacement/m-p/1030380#M919543</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are number of tools out there, pdm has a built-in monitoring tool tab which you can use to monitor pix cpu usage, xlate , regular connections, Ipsec connections etc.. you could setup graphical monitoring and let it run for a week to sort of get you overall pix utilization baseline.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could also use PRGT  to monitor the physical ports ethernet utilization, example would be the inside interface connecting to a switchport , monitor switchport through PRTG.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.paessler.com/" target="_blank"&gt;http://www.paessler.com/&lt;/A&gt; , prtg is not free but they have demo allowing to monitor two or three physical ports free.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or if you have an internal snmp server you could also configure snmp to pool pix stats &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094a13.shtml#intro" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094a13.shtml#intro&lt;/A&gt;&lt;/P&gt;&lt;P&gt;   &lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;-Jorge&lt;/P&gt;&lt;P&gt;&lt;I&gt;PLS rate any helpful post if it helped&lt;/I&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 27 May 2008 04:39:10 GMT</pubDate>
    <dc:creator>JORGE RODRIGUEZ</dc:creator>
    <dc:date>2008-05-27T04:39:10Z</dc:date>
    <item>
      <title>PIX 520 Replacement</title>
      <link>https://community.cisco.com/t5/network-security/pix-520-replacement/m-p/1030377#M919540</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have PIX 520 that I want to replace, I assume the new replacement is ASA. My question is which model. I use the PIX simply as a firewall. I do not want to under-engieenr the solution. So I will probably will require min three interfaces inside, outside and DMZ.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:50:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-520-replacement/m-p/1030377#M919540</guid>
      <dc:creator>nyousif</dc:creator>
      <dc:date>2019-03-11T12:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 520 Replacement</title>
      <link>https://community.cisco.com/t5/network-security/pix-520-replacement/m-p/1030378#M919541</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nabeel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bellow pdf provides migration guide from PIX 500 series to ASA5500 series.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX520 equivalent upgrade to asa is asa5520 but from what you have indicated needing only  inside,outside and DMZ you probably are looking at the ASA5510, you still need to conduct thourough assesment and baseline of your currently PIX520 such Ipsec vpns tunnels currentl utilization if any, look at bellow comparison table and total ASA firewall Mbps throughput.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX/ASA upgrade path chart&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/prod_brochure0900aecd8053258b.pdf" target="_blank"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/prod_brochure0900aecd8053258b.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lastly you may want to check models performance throughput.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;ASA comparison chart &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/prod_models_comparison.html" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/prod_models_comparison.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;-Jorge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 May 2008 00:05:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-520-replacement/m-p/1030378#M919541</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-05-27T00:05:02Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 520 Replacement</title>
      <link>https://community.cisco.com/t5/network-security/pix-520-replacement/m-p/1030379#M919542</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jorge,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the info, what is the best way to baseline my connection and firewall uitilazation. again thanks in advance for your help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 May 2008 02:59:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-520-replacement/m-p/1030379#M919542</guid>
      <dc:creator>nyousif</dc:creator>
      <dc:date>2008-05-27T02:59:35Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 520 Replacement</title>
      <link>https://community.cisco.com/t5/network-security/pix-520-replacement/m-p/1030380#M919543</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are number of tools out there, pdm has a built-in monitoring tool tab which you can use to monitor pix cpu usage, xlate , regular connections, Ipsec connections etc.. you could setup graphical monitoring and let it run for a week to sort of get you overall pix utilization baseline.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could also use PRGT  to monitor the physical ports ethernet utilization, example would be the inside interface connecting to a switchport , monitor switchport through PRTG.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.paessler.com/" target="_blank"&gt;http://www.paessler.com/&lt;/A&gt; , prtg is not free but they have demo allowing to monitor two or three physical ports free.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or if you have an internal snmp server you could also configure snmp to pool pix stats &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094a13.shtml#intro" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094a13.shtml#intro&lt;/A&gt;&lt;/P&gt;&lt;P&gt;   &lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;-Jorge&lt;/P&gt;&lt;P&gt;&lt;I&gt;PLS rate any helpful post if it helped&lt;/I&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 May 2008 04:39:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-520-replacement/m-p/1030380#M919543</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-05-27T04:39:10Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 520 Replacement</title>
      <link>https://community.cisco.com/t5/network-security/pix-520-replacement/m-p/1030381#M919544</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jorge,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all your help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 May 2008 12:49:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-520-replacement/m-p/1030381#M919544</guid>
      <dc:creator>nyousif</dc:creator>
      <dc:date>2008-05-27T12:49:48Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 520 Replacement</title>
      <link>https://community.cisco.com/t5/network-security/pix-520-replacement/m-p/1030382#M919545</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Don't forget about a failover interface since the ASA uses an Ethernet interface not the serial cable..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TJM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pls rate if post was helpful..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 May 2008 19:53:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-520-replacement/m-p/1030382#M919545</guid>
      <dc:creator>tj.mitchell</dc:creator>
      <dc:date>2008-05-27T19:53:26Z</dc:date>
    </item>
  </channel>
</rss>

