Even a PIX 501 can be used (ok with very few VPN tunnels -5 max). However i realized that i needed ACS to use extended authentication (userid/password) for the VPN clients. Otherwise VPN client logs on just by configuring the vpngroup name and vpngroup password