Differences between the ISA500 Series Integrated Security Appliance and the SA500 Series Security Appliance
Objective
The ISA500 Series Integrated Security Appliances is designed to have improved deployment flexibility, expanded security protection coverage, more tools to monitor and maintain security protection and services, and enhanced security performance over the older SA500 Series Security Appliances. This article explains the differences between ISA500 Series Integrated Security Appliances and SA500 Series Security Appliances.
Applicable Devices
• ISA500 Series Integrated Security Appliances
• SA500 Series Security Appliances
Specifically provide control settings and policies to a specific zone like VPN, WAN, or DMZ
Specifically provide control settings and Policies to a specific zone like VPN, WAN, or DMZ
Web URL Filtering
System based
System based
Profile & User (IP) based
Profile & User (IP) based
Gateway Anti-Virus
No
No
Yes
Yes
Intrusion Prevention Systems(IPS)
Limited
Limited
Configure zones and provide better security for WAN, LAN, and VPN
Configure zones and provide better security for WAN, LAN, and VPN
Network Reputation
No
No
Yes
Yes
802.1x
No
No
Yes
Yes
Rouge AP Detection
No
No
Yes
Yes
Cisco AnyConnect SSL
No
No
Yes
Yes
Security Reporting with ViewMaster
No
No
Yes
Yes
Syslog
Fundamental
Fundamental
Configure the logs based on the severity
Configure the logs based on the severity
System Status & Monitoring, Alert
Limited
Limited
Have Email, Remote, and Local log alerts for all features
Have Email, Remote, and Local log alerts for all features
Tech Zip File
No
No
Yes
Yes
Wizards
No
No
Yes
Yes
VPN (IPSec)
85 Mbps
65 Mbps
150 Mbps
75 Mbps
IPS
30 Mbps
20 Mbps
150 Mbps
80 Mbps
UTM
<30 Mbps
<20 Mbps
120 Mbps
45 Mbps
With more configurable interfaces, advanced firewall features, improved WAN failover and load balancing, more IPsec VPN options, enhanced application control, and the addition of profile and user based web URL filtering, the ISA500 Series Integrated Security Appliance can be deployed in more ways than previously available on the SA500 Series Security Appliance.
The ISA500 Series also offers gateway anti-virus, network reputation, 802.1x, rogue Access Point (AP) detection, Cisco AnyConnect Secure Socket Layer (SSL), and enhanced Intrusion Prevention System (IPS) which is not available in the SA500 Series. These features expand security protection coverage for your network.
Security Reporting with ViewMaster, enhanced Syslog, improved system status monitoring and alerts, tech zip files, and wizards, not available in the SA500 Series, give the ISA500 Series more tools to view and monitor the network for security issues and to ease network support.
The improvement in IPsec VPN, IPS, and UTM speeds of the ISA500 Series over the SA500 Series presents a boost to security performance which means that the ISA500 Series is not only more secure but also faster than the SA500 Series.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: