06-08-2005 06:21 AM - edited 03-10-2019 01:29 AM
Folks,
I need advice.
I am running PIX 515 (R) 6.3 version. I am planning to upgrade it to 7.01 are there any improvements regarding IDS/IDP stuff?
What options do I have if I'd like to run proper IDS/IDP system?
Cheers,
Daniel.
06-08-2005 09:22 AM
Daniel - a few things
- 7.01 should have at least 128 meg memory.
- the IDS functionality is basically the same but application inspection has been added to the core firewall code its self, so protocol compliance is now part of the release. Andf it works very very well mitigating attacks that violate HTTP, FTP, SNMP
- I don't think 7.01 is officially supported on any 515 platforms except the 515E. But... I have been running it on my 515 and 128 meg with no problem
- ASDM is awesome.
- but that all being said if you want to run a "proper IPS" the best option may be to buy a small ASA box with an SSM card which runs the complete PIX code set along with a complete version of IPS 5.0. Check www.cisco.com/go/asa..
- if you don't have SmartNet you will need to buy and upgrade license for PIX 7.
I think that's it - good luck.
06-22-2005 11:54 AM
one question - If i want to replace PIX515E with ASA5510 to have both firewall and IRS features, is there any migration tool/path to translate PIX configuration to ASA configuration for Firwall and VPN portion?
thanks
regards
Rakesh
======
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide