SlideShare a Scribd company logo
1 of 22
• A firewall is a software or hardware-based network security system that
controls the incoming and outgoing network traffic by analyzing the data
packets and determining whether they should be allowed through or not,
based on a rule set.
• A firewall establishes a barrier between a trusted, secure internal network
and another network (e.g., the Internet) that is not assumed to be secure
and trusted.
What is a FIREWALL?
STATEFUL INSPECTION
 Introduced in 1994 by Gill Schwed in the FireWall-1
product and changed the way traffic inspection occurs.
 Check Layer 3/Layer 4 information within an IP packet
and stores the information in a separate table referred
to as the “STATE TABLE” of the firewall.
 All traffic flows through the firewall will be
compared/inspected against “STATE TABLE” entries.
History of Cisco’s ASA
 Private Internet eXchange (PIX) was developed in 1994 and was renamed
as the ASA (Adaptive Security Appliance) when Cisco acquired it in 2005
and declared PIX EoL in 2008.
 The disadvantages for PIX are that VPN cannot be terminated on a PIX
and we could not add an external modules. Needed to rely on a
separate external device called a Concentrator which has also reached
its End of Life. PIX version 8.0 supports VPN termination without
concentrators.
 Ran a proprietary OS called Finese OS (Fast InterNEt Server Executive).
 The ASA runs an OS version of 8.0/8.2/8.3/8.4/8.5/8.6/8.7/9.0/9.1
etc. It runs on the Adaptive Security Algorithm and hence is named so.
Cisco’s ASA Product Line
 Dedicated Hardware appliances- 1st generation-ASA
5505/ASA 5510/ASA 5520/5540/5550/5580
 2nd generation Appliances-5500-X series appliances-Cisco
ASA 5512-X,5515-X,Cisco ASA 5525-X, Cisco ASA 5545-
X,5585-X
 Cisco Catalyst 6500 Series Switches FWSM blade
 Cisco ASA 1000v Cloud Firewall- VM
ASA 5505
ASA 5510
ASA 5520
ASA 5540
ASA 5550
ASA 5580
 The ASA 5510, 5520, and 5540 chassis have one SSM slot that can be
populated with one of the following:
1. Four-port Gigabit Ethernet SSM: This module adds four additional
physical firewall interfaces, as either 101100/1000 RJ45 or small form-
factor pluggable (SFP) based ports.
2. Advanced Inspection and Prevention (AlP) SSM: This module adds inline
network IPS capabilities to the ASAs security suite.
3. Content Security and Control (CSC) SSM: This module adds
comprehensive content control and antivirus services to the ASAs
security suite.
 AIP SSM
 Advanced inspection and prevention security service module //for IPS
feature
 Provides protection against viruses, spyware, spam and other unwanted
traffic by scanning the FTP, HTTP and SMTP packets
CSC SSM
 Content security and control security service module //for Content
security feature
 Inspection for HTTP and SMTP viruses and worms using Trend micro
based software.
 Provides Anti-X Features.
ASA OS Versions:
Older Version::
 Version 7.0,Version 7.1,Version 7.2
 Version 8.0,Version 8.1,Version 8.2
Newer Version::
 Version 8.3,Version 8.4,Version 8.5,Version 8.6,Version
8.7
 Version 9.0,Version 9.1,Version 9.2
Security Licenses
 BASE License
 Security PLUS License
 Feature-Specific License
 A license key, which is partly based on the serial number of the appliance, is used
to unlock features of the operating system. Since the serial number of the
appliance is used for the license key, you cannot take a key from one appliance
and use it on a different appliance. License keys can be used to unlock the following
features on some of the appliances:
 ■ Number of connections allowed in the state table
 ■ Number of interfaces that can be used
 ■ Amount of RAM that can be used
 ■ Encryption algorithms that can be used: DES, 3DES, and/or AES
 ■ Number of IPSec/L2TP VPN sessions supported
 ■ Number of SSL VPN sessions supported
 ■ Number of users that the appliance supports
 ■ Number of VLANs that can be used
 ■ Whether failover is supported
 ■ Number of contexts supported
Thank you

More Related Content

Similar to ASA day 1.pptx

Ten new topics on security+ 2011 (sy0 301) (domain 1.0 network security)
Ten new topics on security+ 2011 (sy0 301) (domain 1.0 network security)Ten new topics on security+ 2011 (sy0 301) (domain 1.0 network security)
Ten new topics on security+ 2011 (sy0 301) (domain 1.0 network security)
chhoup
 
Top 5 reasons to purchase cisco asa 5500 series
Top 5 reasons to purchase cisco asa 5500 seriesTop 5 reasons to purchase cisco asa 5500 series
Top 5 reasons to purchase cisco asa 5500 series
IT Tech
 
Cisco asa firewall
Cisco asa firewallCisco asa firewall
Cisco asa firewall
IT Tech
 

Similar to ASA day 1.pptx (20)

Cisco identity services engine (ise) ordering steps & guide
Cisco identity services engine (ise) ordering steps & guideCisco identity services engine (ise) ordering steps & guide
Cisco identity services engine (ise) ordering steps & guide
 
Ten new topics on security+ 2011 (sy0 301) (domain 1.0 network security)
Ten new topics on security+ 2011 (sy0 301) (domain 1.0 network security)Ten new topics on security+ 2011 (sy0 301) (domain 1.0 network security)
Ten new topics on security+ 2011 (sy0 301) (domain 1.0 network security)
 
Resilient IoT Security: The end of flat security models
Resilient IoT Security: The end of flat security modelsResilient IoT Security: The end of flat security models
Resilient IoT Security: The end of flat security models
 
ASA Firepower NGFW Update and Deployment Scenarios
ASA Firepower NGFW Update and Deployment ScenariosASA Firepower NGFW Update and Deployment Scenarios
ASA Firepower NGFW Update and Deployment Scenarios
 
C1111-8P Datasheet
C1111-8P DatasheetC1111-8P Datasheet
C1111-8P Datasheet
 
CCNP Security-Firewall
CCNP Security-FirewallCCNP Security-Firewall
CCNP Security-Firewall
 
Fortinet FortiGate 100D
Fortinet FortiGate 100DFortinet FortiGate 100D
Fortinet FortiGate 100D
 
Intel_IoT_gateway.pdf
Intel_IoT_gateway.pdfIntel_IoT_gateway.pdf
Intel_IoT_gateway.pdf
 
Ce hv6 module 60 firewall technologies
Ce hv6 module 60 firewall technologiesCe hv6 module 60 firewall technologies
Ce hv6 module 60 firewall technologies
 
What is Firewall?
What is Firewall?What is Firewall?
What is Firewall?
 
Network & security startup
Network & security startupNetwork & security startup
Network & security startup
 
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
 
Top 5 reasons to purchase cisco asa 5500 series
Top 5 reasons to purchase cisco asa 5500 seriesTop 5 reasons to purchase cisco asa 5500 series
Top 5 reasons to purchase cisco asa 5500 series
 
RA TechED 2019 - SS08 - What's New and Coming Soon in Safety Automation Archi...
RA TechED 2019 - SS08 - What's New and Coming Soon in Safety Automation Archi...RA TechED 2019 - SS08 - What's New and Coming Soon in Safety Automation Archi...
RA TechED 2019 - SS08 - What's New and Coming Soon in Safety Automation Archi...
 
Cisco asa firewall
Cisco asa firewallCisco asa firewall
Cisco asa firewall
 
How to configure cisco asa virtual firewall
How to configure cisco asa virtual firewallHow to configure cisco asa virtual firewall
How to configure cisco asa virtual firewall
 
Quickassist adapter-8960-8970-brief
Quickassist adapter-8960-8970-briefQuickassist adapter-8960-8970-brief
Quickassist adapter-8960-8970-brief
 
IPLOOK IKEPC 500 Series Product Information
IPLOOK IKEPC 500 Series Product InformationIPLOOK IKEPC 500 Series Product Information
IPLOOK IKEPC 500 Series Product Information
 
Ibm spectrum scale fundamentals workshop for americas part 1 components archi...
Ibm spectrum scale fundamentals workshop for americas part 1 components archi...Ibm spectrum scale fundamentals workshop for americas part 1 components archi...
Ibm spectrum scale fundamentals workshop for americas part 1 components archi...
 
siemens relays catalog - geetech group.pdf
siemens relays catalog - geetech group.pdfsiemens relays catalog - geetech group.pdf
siemens relays catalog - geetech group.pdf
 

Recently uploaded

會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文
會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文
會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文
中 央社
 
Transparency, Recognition and the role of eSealing - Ildiko Mazar and Koen No...
Transparency, Recognition and the role of eSealing - Ildiko Mazar and Koen No...Transparency, Recognition and the role of eSealing - Ildiko Mazar and Koen No...
Transparency, Recognition and the role of eSealing - Ildiko Mazar and Koen No...
EADTU
 

Recently uploaded (20)

TỔNG HỢP HƠN 100 ĐỀ THI THỬ TỐT NGHIỆP THPT TOÁN 2024 - TỪ CÁC TRƯỜNG, TRƯỜNG...
TỔNG HỢP HƠN 100 ĐỀ THI THỬ TỐT NGHIỆP THPT TOÁN 2024 - TỪ CÁC TRƯỜNG, TRƯỜNG...TỔNG HỢP HƠN 100 ĐỀ THI THỬ TỐT NGHIỆP THPT TOÁN 2024 - TỪ CÁC TRƯỜNG, TRƯỜNG...
TỔNG HỢP HƠN 100 ĐỀ THI THỬ TỐT NGHIỆP THPT TOÁN 2024 - TỪ CÁC TRƯỜNG, TRƯỜNG...
 
An overview of the various scriptures in Hinduism
An overview of the various scriptures in HinduismAn overview of the various scriptures in Hinduism
An overview of the various scriptures in Hinduism
 
TỔNG HỢP HƠN 100 ĐỀ THI THỬ TỐT NGHIỆP THPT TOÁN 2024 - TỪ CÁC TRƯỜNG, TRƯỜNG...
TỔNG HỢP HƠN 100 ĐỀ THI THỬ TỐT NGHIỆP THPT TOÁN 2024 - TỪ CÁC TRƯỜNG, TRƯỜNG...TỔNG HỢP HƠN 100 ĐỀ THI THỬ TỐT NGHIỆP THPT TOÁN 2024 - TỪ CÁC TRƯỜNG, TRƯỜNG...
TỔNG HỢP HƠN 100 ĐỀ THI THỬ TỐT NGHIỆP THPT TOÁN 2024 - TỪ CÁC TRƯỜNG, TRƯỜNG...
 
ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH FORM 50 CÂU TRẮC NGHI...
ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH FORM 50 CÂU TRẮC NGHI...ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH FORM 50 CÂU TRẮC NGHI...
ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH FORM 50 CÂU TRẮC NGHI...
 
How to Send Pro Forma Invoice to Your Customers in Odoo 17
How to Send Pro Forma Invoice to Your Customers in Odoo 17How to Send Pro Forma Invoice to Your Customers in Odoo 17
How to Send Pro Forma Invoice to Your Customers in Odoo 17
 
FICTIONAL SALESMAN/SALESMAN SNSW 2024.pdf
FICTIONAL SALESMAN/SALESMAN SNSW 2024.pdfFICTIONAL SALESMAN/SALESMAN SNSW 2024.pdf
FICTIONAL SALESMAN/SALESMAN SNSW 2024.pdf
 
ESSENTIAL of (CS/IT/IS) class 07 (Networks)
ESSENTIAL of (CS/IT/IS) class 07 (Networks)ESSENTIAL of (CS/IT/IS) class 07 (Networks)
ESSENTIAL of (CS/IT/IS) class 07 (Networks)
 
Supporting Newcomer Multilingual Learners
Supporting Newcomer  Multilingual LearnersSupporting Newcomer  Multilingual Learners
Supporting Newcomer Multilingual Learners
 
Major project report on Tata Motors and its marketing strategies
Major project report on Tata Motors and its marketing strategiesMajor project report on Tata Motors and its marketing strategies
Major project report on Tata Motors and its marketing strategies
 
Analyzing and resolving a communication crisis in Dhaka textiles LTD.pptx
Analyzing and resolving a communication crisis in Dhaka textiles LTD.pptxAnalyzing and resolving a communication crisis in Dhaka textiles LTD.pptx
Analyzing and resolving a communication crisis in Dhaka textiles LTD.pptx
 
OSCM Unit 2_Operations Processes & Systems
OSCM Unit 2_Operations Processes & SystemsOSCM Unit 2_Operations Processes & Systems
OSCM Unit 2_Operations Processes & Systems
 
Book Review of Run For Your Life Powerpoint
Book Review of Run For Your Life PowerpointBook Review of Run For Your Life Powerpoint
Book Review of Run For Your Life Powerpoint
 
會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文
會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文
會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文會考英文
 
OS-operating systems- ch05 (CPU Scheduling) ...
OS-operating systems- ch05 (CPU Scheduling) ...OS-operating systems- ch05 (CPU Scheduling) ...
OS-operating systems- ch05 (CPU Scheduling) ...
 
male presentation...pdf.................
male presentation...pdf.................male presentation...pdf.................
male presentation...pdf.................
 
Đề tieng anh thpt 2024 danh cho cac ban hoc sinh
Đề tieng anh thpt 2024 danh cho cac ban hoc sinhĐề tieng anh thpt 2024 danh cho cac ban hoc sinh
Đề tieng anh thpt 2024 danh cho cac ban hoc sinh
 
UChicago CMSC 23320 - The Best Commit Messages of 2024
UChicago CMSC 23320 - The Best Commit Messages of 2024UChicago CMSC 23320 - The Best Commit Messages of 2024
UChicago CMSC 23320 - The Best Commit Messages of 2024
 
Transparency, Recognition and the role of eSealing - Ildiko Mazar and Koen No...
Transparency, Recognition and the role of eSealing - Ildiko Mazar and Koen No...Transparency, Recognition and the role of eSealing - Ildiko Mazar and Koen No...
Transparency, Recognition and the role of eSealing - Ildiko Mazar and Koen No...
 
diagnosting testing bsc 2nd sem.pptx....
diagnosting testing bsc 2nd sem.pptx....diagnosting testing bsc 2nd sem.pptx....
diagnosting testing bsc 2nd sem.pptx....
 
Stl Algorithms in C++ jjjjjjjjjjjjjjjjjj
Stl Algorithms in C++ jjjjjjjjjjjjjjjjjjStl Algorithms in C++ jjjjjjjjjjjjjjjjjj
Stl Algorithms in C++ jjjjjjjjjjjjjjjjjj
 

ASA day 1.pptx

  • 1. • A firewall is a software or hardware-based network security system that controls the incoming and outgoing network traffic by analyzing the data packets and determining whether they should be allowed through or not, based on a rule set. • A firewall establishes a barrier between a trusted, secure internal network and another network (e.g., the Internet) that is not assumed to be secure and trusted. What is a FIREWALL?
  • 2. STATEFUL INSPECTION  Introduced in 1994 by Gill Schwed in the FireWall-1 product and changed the way traffic inspection occurs.  Check Layer 3/Layer 4 information within an IP packet and stores the information in a separate table referred to as the “STATE TABLE” of the firewall.  All traffic flows through the firewall will be compared/inspected against “STATE TABLE” entries.
  • 3.
  • 4. History of Cisco’s ASA  Private Internet eXchange (PIX) was developed in 1994 and was renamed as the ASA (Adaptive Security Appliance) when Cisco acquired it in 2005 and declared PIX EoL in 2008.  The disadvantages for PIX are that VPN cannot be terminated on a PIX and we could not add an external modules. Needed to rely on a separate external device called a Concentrator which has also reached its End of Life. PIX version 8.0 supports VPN termination without concentrators.  Ran a proprietary OS called Finese OS (Fast InterNEt Server Executive).  The ASA runs an OS version of 8.0/8.2/8.3/8.4/8.5/8.6/8.7/9.0/9.1 etc. It runs on the Adaptive Security Algorithm and hence is named so.
  • 5. Cisco’s ASA Product Line  Dedicated Hardware appliances- 1st generation-ASA 5505/ASA 5510/ASA 5520/5540/5550/5580  2nd generation Appliances-5500-X series appliances-Cisco ASA 5512-X,5515-X,Cisco ASA 5525-X, Cisco ASA 5545- X,5585-X  Cisco Catalyst 6500 Series Switches FWSM blade  Cisco ASA 1000v Cloud Firewall- VM
  • 6.
  • 7.
  • 14.  The ASA 5510, 5520, and 5540 chassis have one SSM slot that can be populated with one of the following: 1. Four-port Gigabit Ethernet SSM: This module adds four additional physical firewall interfaces, as either 101100/1000 RJ45 or small form- factor pluggable (SFP) based ports. 2. Advanced Inspection and Prevention (AlP) SSM: This module adds inline network IPS capabilities to the ASAs security suite. 3. Content Security and Control (CSC) SSM: This module adds comprehensive content control and antivirus services to the ASAs security suite.
  • 15.  AIP SSM  Advanced inspection and prevention security service module //for IPS feature  Provides protection against viruses, spyware, spam and other unwanted traffic by scanning the FTP, HTTP and SMTP packets
  • 16. CSC SSM  Content security and control security service module //for Content security feature  Inspection for HTTP and SMTP viruses and worms using Trend micro based software.  Provides Anti-X Features.
  • 17.
  • 18.
  • 19. ASA OS Versions: Older Version::  Version 7.0,Version 7.1,Version 7.2  Version 8.0,Version 8.1,Version 8.2 Newer Version::  Version 8.3,Version 8.4,Version 8.5,Version 8.6,Version 8.7  Version 9.0,Version 9.1,Version 9.2
  • 20. Security Licenses  BASE License  Security PLUS License  Feature-Specific License
  • 21.  A license key, which is partly based on the serial number of the appliance, is used to unlock features of the operating system. Since the serial number of the appliance is used for the license key, you cannot take a key from one appliance and use it on a different appliance. License keys can be used to unlock the following features on some of the appliances:  ■ Number of connections allowed in the state table  ■ Number of interfaces that can be used  ■ Amount of RAM that can be used  ■ Encryption algorithms that can be used: DES, 3DES, and/or AES  ■ Number of IPSec/L2TP VPN sessions supported  ■ Number of SSL VPN sessions supported  ■ Number of users that the appliance supports  ■ Number of VLANs that can be used  ■ Whether failover is supported  ■ Number of contexts supported