What We do
Security Solutions Experienced Security Engineers provide expert services to facilitate Installation Configuration and Technical Support of the Cisco AIP-SSM module ensure business continuity and operational stability after the device placement in the network .Being a service module that device cannot exist on its own thus the installation of the AIP is closely linked to the installation of the Cisco ASA appliances .Security Solutions provides that extra expertise to manage monitor and install that device module .For more information on the Cisco IPS solutions offered please go to the products section here
Product Overview
As mobile devices and applications become more popular, it becomes harder to secure corporate perimeters. Traditional firewall and intrusion prevention system (IPS) solutions are not enough to keep up with the fast-changing threat landscape. The Cisco® ASA 5500 Series IPS Solution provides superior real-time protection for your critical information assets, using innovative IPS with Global Correlation, firewall, and VPN technology. The Cisco ASA 5500 Series IPS Solution delivers intrusion prevention capabilities using a range of hardware-accelerated IPS modules, cards, and security services processors.
IPS technology extends firewall protection by blocking threats such as worms, Trojans, viruses, distributed denial of service attacks, reconnaissance attacks, and attacks against operating system and application vulnerabilities. Cisco IPS with Global Correlation increases the efficacy of traditional IPS. With updates every five minutes, Cisco IPS with Global Correlation provides the fastest and most accurate threat protection with real-time global intelligence from Cisco IPS, firewall, email, and web appliances because the nature of the technology.
In addition to securing your network, the Cisco ASA 5500 Series IPS Solution also helps you meet compliance objectives. Whether your mandate is the Payment Card Industry (PCI) standard in retail, the Federal Financial Institutions Examination Council (FFIEC) in banking, or the Health Insurance Portability and Accountability Act (HIPAA) in healthcare, the Cisco ASA 5500 Series IPS Solution helps ensure that your network is safe and your compliance requirements are met.
Features and Benefits
The Cisco ASA 5500 Series IPS Solution delivers high performance and powerful security protection in a single easy-to-deploy platform (Figure 1).
Superior Security Protection
The Cisco ASA 5500 Series IPS Solution counteracts threats before they enter your network. Whether you have an IPv6 network, IPv4 network, or hybrid IPv6 and IPv4 network, the solution provides:
• Wide-ranging IPS capabilities: The Cisco ASA 5500 Series IPS Solution delivers all the IPS capabilities available on Cisco IPS 4200 Series Sensors. The ASA 5500 Series IPS Solution technology can be deployed inline in the traffic path or in promiscuous mode, in which a copy of the traffic is sent to the IPS for inspection. The Cisco ASA 5500 Series IPS Solution provides protection against tens of thousands of known attacks. And with Cisco anomaly detection and Global Correlation, your network can be protected against day-zero threats before signature updates are available.
• Global Correlation: Cisco Global Correlation provides real-time updates on the global threat environment beyond your perimeter by adding reputation analysis, reducing the window of threat exposure, and providing continuous feedback. With these new capabilities, Cisco IPS sensors can detect more threats, detect them earlier and more accurately, and protect critical assets from malicious attacks.
• Comprehensive and timely attack protection: The Cisco ASA 5500 Series IPS Solution delivers protection against tens of thousands of known exploits and millions more potential unknown exploit variants using specialized IPS detection engines and thousands of signatures. Cisco Services for IPS provides signature updates through a global intelligence team working 24 hours a day to help ensure that you are protected against the latest threats.
• Zero-day attack protection: The Cisco ASA 5500 Series IPS Solution provides powerful protection against zero-day attacks. Cisco anomaly detection learns the normal behavior on your network and alerts you when it sees anomalous activities in your network. Cisco anomaly protection helps protect you against new threats even before signatures are available.
• Application inspection and control: The application inspection engines in the Cisco ASA 5500 Series IPS Solution provide granular control of who and what can enter the network. You can prevent access to potentially dangerous URLs, block rogue callers, and use blacklists to stop infected file attachments from entering your network.
• Wireless protection: The Cisco ASA 5500 Series IPS Solution is tightly integrated with the Cisco Wireless LAN Controller to help keep intruders out of your wireless network. The Cisco Wireless LAN Controller blocks intruders based on real-time threat intelligence from the Cisco ASA 5500 Series IPS Solution.
• Unified Communications protection: Strong protection of voice-over-IP (VoIP) protocols, and Cisco Unified Communications Manager helps ensure the constant uptime of your critical voice network. The Cisco ASA 5500 Series IPS Solution uses dedicated voice engines and comprehensive voice signatures to protect your voice network from intruders and attacks.
High Performance
The Cisco ASA 5500 Series IPS Solution is hardware-accelerated to provide the highest level of performance without negatively affecting firewall or VPN throughput. With the Cisco IPS Security Services Processors, the Cisco ASA 5500 Series IPS Solution can achieve up to 10 Gbps of IPS throughput.
Today, almost every important application uses the Internet. VoIP, e-commerce, streaming video, and Web 2.0 applications enable higher productivity and employee collaboration. These networked applications pose different and varying demands on resources such as connection rates, concurrent connections, flow length, and transaction size. From a performance perspective, the spectrum of application types ranges from media-rich environments that feature converged content to highly transactional environments populated by rapid-fire, lightweight connections. The Cisco ASA 5500 Series IPS Solution is optimized for both media-rich and transactional environments.
Advanced Policy Provisioning
Policy provisioning simplifies management, reduces chances of mistakes, and allows you to focus on important tasks at hand. With the Cisco ASA 5500 Series IPS Solution, you can apply unified policies with the Cisco Modular Policy Framework (MPF) and assign IPS policies within the Cisco IPS technology:
• Cisco Modular Policy Framework: The Cisco MPF provides a powerful mechanism to assign Cisco ASA firewall, VPN, and IPS policies in one place. With the Cisco MPF, the Cisco ASA firewall passes traffic to the IPS for inspection on a flow-by-flow, as-needed basis.
• Cisco IPS policy provisioning: For IPS policy provisioning, Cisco IPS technologies are the only products that provide Risk Rating-based policy provisioning. Instead of tuning individual signatures, you assign IPS policies based on risk. All events are assigned a Risk Rating number between 0 and 100 based on the risk level of the event. Based on the Risk Rating, different policy actions can be assigned, such as drop packet, alarm, and log.
Flexible Management
Cisco can provide the right management solutions for you, whether you have five Cisco ASA 5500 Series IPS devices or thousands.
• Cisco Security Management Suite: The Cisco Security Management Suite is a powerful management application suite that scales up to thousands of devices and helps you manage the IPS, firewall, and VPN capabilities of your Cisco ASA 5500 Series IPS Solution. The suite includes Cisco Security Manager and the Cisco Security Monitoring, Analysis, and Response System (Cisco Security MARS). With Cisco Security Manager, you can, at one click, apply security policies or perform software updates to hundreds or thousands of Cisco ASA appliances. Cisco Security MARS can collect and correlate data from the Cisco ASA 5500 Series IPS Solution and other security devices to identify problems and recommend corrective actions.
• Cisco IPS Manager Express: An all-in-one IPS management and reporting application for small deployments, Cisco IPS Manager Express enables you to provision, monitor, troubleshoot, and provide reports on up to five Cisco IPS devices. A customizable dashboard with more than 10 drag-and-drop gadgets allows you to personalize it to your needs
Table 1. Cisco ASA 5500 Series IPS Solution Specifications
Feature |
Cisco ASA 5505 IPS Solution (base license/security plus license) |
Cisco ASA 5510 IPS Solution (base license/security plus license) |
||
225 Mbps with AIP-SSM-10 |
||||
Maximum Triple Data Encryption Standard/Advanced Encryption Standard (3DES/AES) VPN throughput (Mbps) |
||||
Maximum SSL VPN user sessions1 |
||||
1Beginning with Cisco ASA Software Release 7.1, SSL VPN (Web VPN) capability requires a license. Systems include 2 SSL VPN users by default for evaluation and remote management purposes |
Table 2 provides Cisco ASA 5500 Series IPS Solution specifications for Cisco 5585 appliances.
Table 2. IPS Solution Specifications for Cisco 5585 Appliances
Feature |
||||
Table 3 provides Cisco AIP SSM specifications.
Table 3. Cisco AIP SSM Specifications
Table 4 provides Cisco IPS SSP specifications.
Table 4. Cisco IPS SSP Specifications
Ordering Information
To place an order, visit the Cisco Ordering homepage. See Table 5 for ordering information.
Table 5. Ordering Information
The above information has been sourced from Cisco's Wbsite more specifically over here