cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
548
Views
0
Helpful
2
Replies

PIX & IDS/IDP

ilogic-il
Level 1
Level 1

Folks,

I need advice.

I am running PIX 515 (R) 6.3 version. I am planning to upgrade it to 7.01 – are there any improvements regarding IDS/IDP stuff?

What options do I have if I'd like to run proper IDS/IDP system?

Cheers,

Daniel.

2 Replies 2

gabelar
Level 1
Level 1

Daniel - a few things

- 7.01 should have at least 128 meg memory.

- the IDS functionality is basically the same but application inspection has been added to the core firewall code its self, so protocol compliance is now part of the release. Andf it works very very well mitigating attacks that violate HTTP, FTP, SNMP

- I don't think 7.01 is officially supported on any 515 platforms except the 515E. But... I have been running it on my 515 and 128 meg with no problem

- ASDM is awesome.

- but that all being said if you want to run a "proper IPS" the best option may be to buy a small ASA box with an SSM card which runs the complete PIX code set along with a complete version of IPS 5.0. Check www.cisco.com/go/asa..

- if you don't have SmartNet you will need to buy and upgrade license for PIX 7.

I think that's it - good luck.

one question - If i want to replace PIX515E with ASA5510 to have both firewall and IRS features, is there any migration tool/path to translate PIX configuration to ASA configuration for Firwall and VPN portion?

thanks

regards

Rakesh

======

Review Cisco Networking for a $25 gift card