<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Managa All FW centrally in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/managa-all-fw-centrally/m-p/930886#M938678</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tested CSM on a 4x "quad-core" Processors with 32GB RAM Dell Server.  &lt;/P&gt;&lt;P&gt;This is a very fast box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tested version 3.1 last year and it was still slow, especially over&lt;/P&gt;&lt;P&gt;VPN.  Others also experienced the same thing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem I see with CSM is scalability.  I don't know how familiar&lt;/P&gt;&lt;P&gt;you are with Checkpoint Provider-1 or Juniper NetScreen Security Manager,&lt;/P&gt;&lt;P&gt;NSM, is that these things are very scalable.  You can install multiple&lt;/P&gt;&lt;P&gt;Managers &amp;amp; Containers across multiple physical servers and link them&lt;/P&gt;&lt;P&gt;together which allow large environment the ability scale.  Therefore,&lt;/P&gt;&lt;P&gt;as you add more devices to manage and more users, you just add more&lt;/P&gt;&lt;P&gt;hardware to scale the infrastructure.  For both Checkpoint P-1 and&lt;/P&gt;&lt;P&gt;Netscreen NSM, you need a dedicate server just to handle 100+ users,&lt;/P&gt;&lt;P&gt;in case all of them decide to log into the system at the same time,&lt;/P&gt;&lt;P&gt;and that the server has at least 8GB of RAM for this. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can CSM do this?  Is it possible with CSM?  From what I can tell,&lt;/P&gt;&lt;P&gt;CSM is more suited for enterprise environment.  CSM does not scale&lt;/P&gt;&lt;P&gt;well in service provider environment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 26 Apr 2008 02:42:14 GMT</pubDate>
    <dc:creator>cisco24x7</dc:creator>
    <dc:date>2008-04-26T02:42:14Z</dc:date>
    <item>
      <title>Managa All FW centrally</title>
      <link>https://community.cisco.com/t5/network-security/managa-all-fw-centrally/m-p/930879#M938657</link>
      <description>&lt;P&gt;Hi, we want to manage all ASA FW centrally. Please suggest abt any softwrae or tool. Thansk&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:36:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/managa-all-fw-centrally/m-p/930879#M938657</guid>
      <dc:creator>ray_stone</dc:creator>
      <dc:date>2019-03-11T12:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: Managa All FW centrally</title>
      <link>https://community.cisco.com/t5/network-security/managa-all-fw-centrally/m-p/930880#M938658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ray,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco recommends the Cisco Security Manager for all security device management including firewalls.  It supports IPS appliances, and security features on routers too, such as VPN, access-lists, and AAA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a link to the product page:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6498/index.html" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6498/index.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco splits Management and Monitoring.  The above software is used for Management.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For Monitoring, Cisco recommends the CS-MARS appliance.  Especially for networks where there are multiple security devices.  CS-MARS can actually correlate security information (like syslogs and IDS events) into a "big picture".  It presents the information as what is going on in the network as a whole, in addition to any particular device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the product page for CS-MARS:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6241/index.html" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6241/index.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;&lt;P&gt; -Brian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Apr 2008 19:00:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/managa-all-fw-centrally/m-p/930880#M938658</guid>
      <dc:creator>Brian Conklin</dc:creator>
      <dc:date>2008-04-25T19:00:51Z</dc:date>
    </item>
    <item>
      <title>Re: Managa All FW centrally</title>
      <link>https://community.cisco.com/t5/network-security/managa-all-fw-centrally/m-p/930881#M938660</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Is it required any license to use or its free of cost.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Apr 2008 19:13:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/managa-all-fw-centrally/m-p/930881#M938660</guid>
      <dc:creator>ray_stone</dc:creator>
      <dc:date>2008-04-25T19:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: Managa All FW centrally</title>
      <link>https://community.cisco.com/t5/network-security/managa-all-fw-centrally/m-p/930882#M938663</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is mine 2c about Cisco CSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I used to work for a Managed Security Service&lt;/P&gt;&lt;P&gt;Provider, MSSP, and we managed a lot of &lt;/P&gt;&lt;P&gt;Checkpoint firewalls running on Nokia &lt;/P&gt;&lt;P&gt;appliances&lt;/P&gt;&lt;P&gt;and SecurePlatform, over 1000 firewalls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We approached Cisco about two years for a&lt;/P&gt;&lt;P&gt;centralized management tools that will be able&lt;/P&gt;&lt;P&gt;to manage hundreds of Cisco Pix/ASA and FWSM&lt;/P&gt;&lt;P&gt;firewalls.  The requirement is that it is &lt;/P&gt;&lt;P&gt;easy to use, fast and flexible.  In other &lt;/P&gt;&lt;P&gt;words, we want the tool to be as good, if not&lt;/P&gt;&lt;P&gt;better than Checkpoint Provider-1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco recommended CSM 3.0 beta so I went&lt;/P&gt;&lt;P&gt;ahead and tested the product.  It was &lt;/P&gt;&lt;P&gt;absolutely and very slugglish.  It did  not &lt;/P&gt;&lt;P&gt;come close to Checkpoint Provider-1 &lt;/P&gt;&lt;P&gt;centralized management.  Cisco then introduced&lt;/P&gt;&lt;P&gt;me to Solsoft, which is a cisco partner.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Solsoft, on the other hand, is a much better&lt;/P&gt;&lt;P&gt;product than Cisco.  It can run on both &lt;/P&gt;&lt;P&gt;Linux or Windows whereas Cisco CSM can only&lt;/P&gt;&lt;P&gt;run on Windows platform.  Solsoft also has&lt;/P&gt;&lt;P&gt;a lot of limitations as well but if you have&lt;/P&gt;&lt;P&gt;to pick between Solsoft and Cisco CSM, I &lt;/P&gt;&lt;P&gt;definitely pick solsoft over CSM any days.&lt;/P&gt;&lt;P&gt;Even Cisco SEs will admit that to you, off-the&lt;/P&gt;&lt;P&gt;record ofcourse.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Apr 2008 21:19:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/managa-all-fw-centrally/m-p/930882#M938663</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-04-25T21:19:26Z</dc:date>
    </item>
    <item>
      <title>Re: Managa All FW centrally</title>
      <link>https://community.cisco.com/t5/network-security/managa-all-fw-centrally/m-p/930883#M938668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;CSM requires a license.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSM 3.2 (the latest version that came out this month) is far improved from the CSM 3.0 beta.  CSM 3.0 was the first version of CSM and it was built off the remnants of VMS 2.3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The latest CSM 3.2 is better and faster than the 3.0 and worth another try.  I haven't experimented with Solsoft yet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Apr 2008 21:48:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/managa-all-fw-centrally/m-p/930883#M938668</guid>
      <dc:creator>Brian Conklin</dc:creator>
      <dc:date>2008-04-25T21:48:54Z</dc:date>
    </item>
    <item>
      <title>Re: Managa All FW centrally</title>
      <link>https://community.cisco.com/t5/network-security/managa-all-fw-centrally/m-p/930884#M938673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you say faster and better, does it mean &lt;/P&gt;&lt;P&gt;that the CSM can have 100+ users logging into&lt;/P&gt;&lt;P&gt;the CSM at the same time, and making constant&lt;/P&gt;&lt;P&gt;changes at the same time?  I wondered what &lt;/P&gt;&lt;P&gt;the response time will be.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How good is the CSM Java applet works across &lt;/P&gt;&lt;P&gt;the VPN?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Those are the questions that I asked Cisco SEs&lt;/P&gt;&lt;P&gt;about 2 years ago and could not get a &lt;/P&gt;&lt;P&gt;straight answer from them.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Apr 2008 23:51:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/managa-all-fw-centrally/m-p/930884#M938673</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-04-25T23:51:12Z</dc:date>
    </item>
    <item>
      <title>Re: Managa All FW centrally</title>
      <link>https://community.cisco.com/t5/network-security/managa-all-fw-centrally/m-p/930885#M938676</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can't say for sure on the 100+ users.  We're typically at about 10 users here.  But considering the robust workflow mode it has, I wouldn't be surprised if it could handle that.  It would probably depend on the servers hardware specifications.  I have seen deployments of CSM that contain more than 1500 devices.  But yeah, can't say for sure on the number of concurrent users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The CSM Java Applet should have no problem across a VPN tunnel.  To be more accurate, it is a java based application that installs on the client side.  That CSM client application uses https (or http) protocol to communicate with the CSM server, so it is encrypted and lightweight.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The CSM runs for 90 days without a license, you can grab the software here if you have a CCO account:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/cgi-bin/Software/Tablebuild/doftp.pl?ftpfile=cisco/crypto/3DES/ciscosecure/csm-app/fcs-csm-320-w2k-k9.exe&amp;amp;app=Tablebuild&amp;amp;status=showC2A" target="_blank"&gt;http://www.cisco.com/cgi-bin/Software/Tablebuild/doftp.pl?ftpfile=cisco/crypto/3DES/ciscosecure/csm-app/fcs-csm-320-w2k-k9.exe&amp;amp;app=Tablebuild&amp;amp;status=showC2A&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The minimum system requirements are 2 GB of ram.  You can run it on less also, but for 100+ users concurrently you'd probably need more then 2GB ram.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do end up trial running it with 100+ users, let me know what your results are.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; -Brian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Apr 2008 00:29:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/managa-all-fw-centrally/m-p/930885#M938676</guid>
      <dc:creator>Brian Conklin</dc:creator>
      <dc:date>2008-04-26T00:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: Managa All FW centrally</title>
      <link>https://community.cisco.com/t5/network-security/managa-all-fw-centrally/m-p/930886#M938678</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tested CSM on a 4x "quad-core" Processors with 32GB RAM Dell Server.  &lt;/P&gt;&lt;P&gt;This is a very fast box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tested version 3.1 last year and it was still slow, especially over&lt;/P&gt;&lt;P&gt;VPN.  Others also experienced the same thing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem I see with CSM is scalability.  I don't know how familiar&lt;/P&gt;&lt;P&gt;you are with Checkpoint Provider-1 or Juniper NetScreen Security Manager,&lt;/P&gt;&lt;P&gt;NSM, is that these things are very scalable.  You can install multiple&lt;/P&gt;&lt;P&gt;Managers &amp;amp; Containers across multiple physical servers and link them&lt;/P&gt;&lt;P&gt;together which allow large environment the ability scale.  Therefore,&lt;/P&gt;&lt;P&gt;as you add more devices to manage and more users, you just add more&lt;/P&gt;&lt;P&gt;hardware to scale the infrastructure.  For both Checkpoint P-1 and&lt;/P&gt;&lt;P&gt;Netscreen NSM, you need a dedicate server just to handle 100+ users,&lt;/P&gt;&lt;P&gt;in case all of them decide to log into the system at the same time,&lt;/P&gt;&lt;P&gt;and that the server has at least 8GB of RAM for this. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can CSM do this?  Is it possible with CSM?  From what I can tell,&lt;/P&gt;&lt;P&gt;CSM is more suited for enterprise environment.  CSM does not scale&lt;/P&gt;&lt;P&gt;well in service provider environment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Apr 2008 02:42:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/managa-all-fw-centrally/m-p/930886#M938678</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-04-26T02:42:14Z</dc:date>
    </item>
  </channel>
</rss>

