cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
504
Views
0
Helpful
2
Replies

firewall service module vs ASA

ohassairi
Level 5
Level 5

Hi

Someone told me that the cisco firewall service module of 6500 has poor performances compared to ASA

What do you recommend as a core firewall (to protect internal servers): ASA or firewall service module ?

thanks

2 Accepted Solutions

Accepted Solutions

Jouni Forss
VIP Alumni
VIP Alumni

Hi,

We are using 5 FWSMs at the moment but are moving away from them to ASA5585-X models.

I wouldnt suggest going to FWSMs anymore at this point if you have any plan on having support for new features.

End Of Life and End of Sale Notice

http://www.cisco.com/en/US/prod/collateral/modules/ps2706/eol_c51-699134.html

The follower for the FWSM is the ASA Service Module which supports the newer softwares (while the FWSM doesnt). Heres a link to a document about the ASASM

http://www.cisco.com/en/US/prod/collateral/modules/ps2706/ps11621/data_sheet_c78-672507.html

Also you could always consider a separate ASA models. Here are links to both the orignal ASA 5500 series and new ASA 5500-X series

ASA 5500 Series

http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/prod_brochure0900aecd80285492.pdf

ASA 5500-X Series

http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/at_a_glance_c45-701635.pdf

I guess the question for you is what are the requirements for the device regarding performance. All of the above documentation should give you a clue about which model might be the best for you.

- Jouni

View solution in original post

Andrew Phirsov
Level 7
Level 7

FWSM is a legacy module for 6500. The new one is ASA service module wich has performance characteristics greater then most of the  biggest standalone ASA appliances, like 5585-x. So it should be your choise.

View solution in original post

2 Replies 2

Jouni Forss
VIP Alumni
VIP Alumni

Hi,

We are using 5 FWSMs at the moment but are moving away from them to ASA5585-X models.

I wouldnt suggest going to FWSMs anymore at this point if you have any plan on having support for new features.

End Of Life and End of Sale Notice

http://www.cisco.com/en/US/prod/collateral/modules/ps2706/eol_c51-699134.html

The follower for the FWSM is the ASA Service Module which supports the newer softwares (while the FWSM doesnt). Heres a link to a document about the ASASM

http://www.cisco.com/en/US/prod/collateral/modules/ps2706/ps11621/data_sheet_c78-672507.html

Also you could always consider a separate ASA models. Here are links to both the orignal ASA 5500 series and new ASA 5500-X series

ASA 5500 Series

http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/prod_brochure0900aecd80285492.pdf

ASA 5500-X Series

http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/at_a_glance_c45-701635.pdf

I guess the question for you is what are the requirements for the device regarding performance. All of the above documentation should give you a clue about which model might be the best for you.

- Jouni

Andrew Phirsov
Level 7
Level 7

FWSM is a legacy module for 6500. The new one is ASA service module wich has performance characteristics greater then most of the  biggest standalone ASA appliances, like 5585-x. So it should be your choise.

Review Cisco Networking for a $25 gift card