Enterprise-Class Security for Small Office Environments
Market-Leading VoIP Security Services Protect Next-Generation Converged Networks
Flexible VPN Services Extend Networks Economically to Remote Networks and Mobile Users
Integrated Intrusion Prevention Guards Against Popular Internet Threats
Simple, High-Speed Small Office Networking
Robust Remote-Management Solutions Lower Total Cost of Ownership
• Comprehensive configuration and software image management
• Device hierarchy with configuration inheritance based on "Smart Rules"
• Customizable administrative roles and access privileges
• Comprehensive enterprise change management and auditing
• "Touchless" software image management for remote Cisco PIX Security Appliances
• Support for dynamically addressed appliances
Table 1. Product Features and Benefits
| Feature | Benefit |
| Enterprise-Class Security | |
| Reliable, purpose-built security appliance |
• Uses a
proprietary,
hardened operating
system that
eliminates security
risks associated
with general purpose
operating systems
• Combines Cisco
product quality with
no moving parts to
provide a highly
reliable security
platform
|
| Stateful inspection firewall |
• Provides perimeter
network security to
prevent unauthorized
network access
• Uses
state-of-the-art
Cisco Adaptive
Security Algorithm
for robust stateful
inspection firewall
services
• Provides flexible
access-control
capabilities for
over 100 predefined
applications,
services and
protocols, with the
ability to define
custom applications
and services
• Simplifies
management of
security policies by
giving
administrators the
ability to create
re-usable network
and service object
groups which can be
referenced by
multiple security
policies, thus
simplifying initial
policy definition
and on-going policy
maintenance
|
| Advanced application and protocol inspection |
• Integrates over
two dozen
specialized
inspection engines
for protocols such
as Hypertext
Transfer Protocol
(HTTP), File
Transfer Protocol
(FTP), Simple Mail
Transfer Protocol
(SMTP), Domain Name
System (DNS), Simple
Network Management
Protocol (SNMP),
SQL*Net, Network
File System (NFS),
H.323 Versions 1-4,
Session Initiation
Protocol (SIP),
Cisco Skinny Client
Control Protocol
(SCCP), Real-Time
Streaming Protocol
(RTSP), Internet
Locator Service
(ILS), and many more
|
| Cisco Easy VPN Remote (hardware VPN client) |
• Enables
dramatically
simplified VPN
rollouts to small
office/teleworker
environments by
eliminating the
provisioning
complexities of
traditional
site-to-site VPN
deployments
• Downloads VPN
policy dynamically
from a Cisco Easy
VPN Server upon
connection, ensuring
the latest corporate
security policies
are enforced
• Provides robust
client-side VPN
resiliency with
support for up to 10
Cisco Easy VPN
Servers with
automatic failover,
in addition to Dead
Peer Detection (DPD)
support
• Supports optional
authentication of
individual users
behind a Cisco PIX
Security Appliance
through an
easy-to-use,
Web-based interface
with support for
standard and
one-time passwords
(including
authentication
tokens)
• Extends VPN reach
into environments
using NAT or PAT,
via support of
Internet Engineering
Task Force (IETF)
UDP-based draft
standard for NAT
traversal
• Supports both
split and non-split
tunneling
environments
• Provides
intelligent,
transparent DNS
proxy capabilities
for access to both
corporate and public
DNS servers
|
| Cisco Easy VPN Server |
• Provides remote
access VPN
concentrator
services for up to
10 remote software
or hardware-based
VPN clients
• Pushes VPN policy
dynamically to Cisco
Easy VPN
Remote-enabled
solutions (such as
the Cisco VPN
Client) upon
connection, ensuring
the latest corporate
security policies
are enforced
• Supports
award-winning Cisco
VPN Client on
multiple platforms
including Microsoft
Windows
98/ME/NT/2000XP, Sun
Solaris, Intel-based
Linux distributions,
and Apple Macintosh
OS X (available
separately)
|
| Site-to-site VPN |
• Supports IKE and
IPSec VPN industry
standards
• Extends networks
securely over the
Internet by ensuring
data
privacy/integrity
and strong
authentication with
remote networks
• Supports 56-bit
DES, 168-bit 3DES,
and up to 256-bit
AES data encryption
to ensure data
privacy
|
| Intrusion prevention |
• Provides
protection from over
55 different types
of popular
network-based
attacks ranging from
malformed packet
attacks to
denial-of-service
(DoS) attacks
• Integrates with
Cisco Network
Intrusion Detection
System (IDS) sensors
to identify and
dynamically
block/shun hostile
network nodes
|
| Authentication, authorization, and accounting (AAA) support |
• Integrates with
popular AAA services
via TACACS+ and
RADIUS
• Provides tight
integration with
Cisco Secure Access
Control Server (ACS)
for
user/administrator
authentication,
dynamic
per-user/group
policies, and
administrator access
privileges
|
| X.509 certificate and CRL support |
• Supports
SCEP-based
enrollment with
leading X.509
solutions from
Baltimore, Entrust,
Microsoft, and
VeriSign
|
| Integration with leading third-party solutions |
• Supports the broad
range of Cisco AVVID
(Architecture for
Voice, Video and
Integrated Data)
partner solutions
that provide URL
filtering, content
filtering, virus
protection, scalable
remote management,
and more
|
| Integrated security lock slot |
• Provides ability
to physically secure
the Cisco PIX 501
Security Appliance
using a standard
notebook security
cable lock (lock not
included)
|
| Industry certifications and evaluations |
• Earned numerous
leading industry
certifications and
evaluations,
including:
• Common Criteria
Evaluated Assurance
Level 4 (EAL4)
• FIPS 140-2, Level
2 Validation
|
| Robust Small Office Networking | |
| Integrated 4-port 10/100 switch |
• Provides
convenient,
high-speed
networking
environment for
small office
environments in a
single compact
platform
• Auto-MDIX support
eliminates the need
to use crossover
cables with devices
connected to the
switch
|
| DHCP client/server |
• Obtains IP address
for outside
interface of
appliance
automatically from
service provider
• Provides IP
addresses to devices
on inside network of
the appliance
• Delivers "zero
touch provisioning"
of Cisco IP Phones
via automated
bootstrapping of
CallManager contact
information through
DHCP server
extensions
|
| DHCP relay |
• Forwards DHCP
requests from
internal devices to
an
administrator-specified
DHCP server,
enabling centralized
distribution,
tracking and
maintenance of IP
addresses
|
| NAT/PAT support |
• Provides dynamic,
static, and
policy-based NAT, as
well as PAT services
• Allows multiple
users to share a
single broadband
connection using a
single public IP
address
|
| PAT for IPSec |
• Supports IPSec
passthrough
services, enabling a
single device behind
the Cisco PIX
Security Appliance
to establish a VPN
tunnel through the
firewall to a VPN
peer
|
| PPPoE support |
• Ensures
compatibility with
networks that
require PPP over
Ethernet (PPPoE)
support
|
| Rich Management Capabilities | |
| CiscoWorks VMS |
• Provides a
comprehensive
management suite for
large scale Cisco
security product
deployments
• Integrates policy
management, software
maintenance, and
security monitoring
in a single
management console
|
| Cisco PIX Device Manager (PDM) |
• Intuitive,
Web-based GUI
enables simple,
secure remote
management of Cisco
PIX Security
Appliances
• Provides wide
range of
informative,
real-time, and
historical reports
which give critical
insight into usage
trends, performance
baselines, and
security events
|
| Auto Update |
• Provides
"touchless" secure
remote management of
Cisco PIX Security
Appliance
configuration and
software images via
a unique push/pull
management model
• Next-generation
secure XML/HTTPS
management interface
can be leveraged by
Cisco and third
party management
applications for
remote Cisco PIX
Security Appliance
configuration
management,
inventory, software
image
management/deployment,
and monitoring
• Supports
dynamically
addressed appliances
in addition to
firewalls with
static IP addresses
• Integrates
seamlessly with
Management Center
for Firewalls and
Auto Update Server
for robust, scalable
remote management of
up to 1000 Cisco PIX
Security Appliances
(per management
server)
|
| Cisco PIX command-line interface |
• Allows customers
to use existing
Cisco IOS CLI
knowledge for easy
installation and
management with
little additional
training needed
• Accessible through
variety of methods
including console
port, Telnet, and
SSH
|
| Command-level authorization |
• Gives businesses
the ability to
create up to 16
customizable
administrative
roles/profiles for
managing a Cisco PIX
Security Appliance
(for example,
monitoring only,
read-only access to
configuration, VPN
administrator,
firewall/NAT
administrator, etc.)
• Leverages either
the internal
administrator
database or outside
sources via TACACS+,
such as Cisco Secure
Access Control
Server (ACS)
|
| SNMP and syslog support |
• Provide remote
monitoring and
logging
capabilities, with
integration into
Cisco and
third-party
management
applications
|
Table 2. Product Specifications
| Feature | Specifications |
| Software Licenses |
• 10-User License
• The Cisco PIX 501
10-user license
supports up to 10
concurrent source IP
addresses from your
internal network to
traverse through the
Cisco PIX 501. The
integrated DHCP
server supports up
to 32 DHCP leases.
As your needs grow,
both 50 user and
unlimited user
upgrade licenses are
available, allowing
you to extend your
investment in Cisco
PIX 501 equipment.
• 50-User License
• The Cisco PIX 501
50-user license
supports up to 50
concurrent source IP
addresses from your
internal network to
traverse through the
Cisco PIX 501. The
integrated DHCP
server supports up
to 128 DHCP leases.
As your needs grow,
a 50-to-unlimited
user upgrade license
is also available,
allowing you to
further extend your
investment in Cisco
PIX 501 equipment.
• Unlimited User
License
• The PIX 501
unlimited user
license supports an
unlimited number of
devices from your
internal network to
traverse through the
Cisco PIX 501. The
integrated DHCP
server supports up
to 256 DHCP leases.
• 3DES/AES and DES
Encryption Licenses
• The Cisco PIX 501
Security Appliance
has two optional
encryption
licenses-one license
(PIX-501-VPN-3DES)
enables 168-bit 3DES
and up to 256-bit
AES encryption, the
other license
(PIX-VPN-DES)
enables 56-bit DES
encryption. Both are
available either at
the time of ordering
the Cisco PIX 501
Security Appliance,
or can be obtained
subsequently through
Cisco.com. Note that
an encryption
license must be
installed to
activate encryption
services which are
required before
using certain
features including
VPN and secure
remote management.
|
| Performance Summary |
• Cleartext
throughput: Up to 60
Mbps
• Concurrent
connections: 7,500
• 56-bit DES IPsec
VPN throughput: Up
to 6 Mbps
• 168-bit 3DES IPsec
VPN throughput: Up
to 3 Mbps
• 128-bit AES IPsec
VPN throughput: Up
to 4.5 Mbps
• Simultaneous VPN
peers: 10*
* Maximum number of simultaneous site-to-site or remote access IKE Security Association (SAs) supported |
| Technical Specifications |
• Processor: 133-MHz
AMD SC520 Processor
• Random access
memory: 16 MB of
SDRAM
• Flash memory: 8 MB
• System bus: Single
32-bit, 33-MHz PCI
|
| Environmental Operating Ranges |
• Operating
• Temperature: 32 to
104<F (0 to 40<C)
• Relative humidity:
10 to 90 percent,
noncondensing
• Altitude: 0 to
6500 feet (2000 m)
• Shock: 250 G, < 2
ms
• Vibration: 0.41
Grms2 (3-500 Hz)
random input
• Nonoperating
• Temperature: -4 to
149<F (-20 to 65<C)
• Relative humidity:
10 to 90 percent,
noncondensing
• Altitude: 0 to
15000 feet (4570 m)
• Shock: 65 G, 8 ms
• Vibration: 1.12
Grms2 (3-500 Hz)
random input
|
| Power |
• Input
• Range Line
Voltage: 100V to
240V AC
• Nominal Line
Voltage: 100V to
240V AC
• Current: 0.051A
(at 115V)
• Frequency: 50-60
Hz, single phase
• Power: 5.9W
• Output
• Nominal Line
Voltage: 3.3V DC
• Current: 1.5A
• Steady State: 5W
• Maximum Peak: 5W
• Maximum Heat
Dissipation: 17.0
BTU/hr, full power
usage (5W)
|
| Physical Specifications |
• Dimensions and
Weight
Specifications
• Dimensions (H x W
x D): 1.0 x 6.25 x
5.5 in. (2.54 x
15.875 x 13.97 cm)
• Weight: 0.75 lb
(0.34 kg)
• Interfaces
• Console Port:
RS-232, 9600 bps,
RJ-45
• Outside:
Integrated 10/100
Fast Ethernet port,
auto-negotiate
(half/full duplex),
RJ-45
• Inside: Integrated
auto-sensing,
auto-MDIX 4-port
10/100 Fast Ethernet
switch, RJ-45
|
| Regulatory and Standards Compliance |
• Regulatory
Compliance
• Products bear CE
Marking indicating
compliance with the
89/366/EEC and
73/23/EEC
directives, which
includes the
following safety and
Electro Magnetic
Compatibility (EMC)
standards.
• Safety
• UL1950,
CAN/CSA-C22.2 No.
60950-00, IEC60950,
EN60950
• Electromagnetic
Compatibility (EMC)
• EN55022 Class B,
CISPR22 Class B,
AS/NZS 3548 Class B,
VCCI Class B,
EN55024, EN50082-1,
EN61000-3-2,
EN61000-3-3
|
Product Ordering Information
Table 3. Ordering Information
| Product Number | Product Description |
| PIX-501 | Cisco PIX 501 chassis, software, 10-user license, integrated 4-port 10/100 switch and 10/100 port |
| PIX-501-BUN-K9 | Cisco PIX 501 10-user bundle (chassis, latest PIX software, 10-user and 3DES licenses, integrated 4-port 10/100 switch and 10/100 port) |
| PIX-501-50-BUN-K9 | Cisco PIX 501 50-user bundle (chassis, latest PIX software, 50-user and 3DES licenses, integrated 4-port 10/100 switch and 10/100 port) |
| PIX-501-UL-BUN-K9 | Cisco PIX 501 unlimited user bundle (chassis, latest PIX software, unlimited user and 3DES licenses, integrated 4-port 10/100 switch and 10/100 port) |
| PIX-501-SW-10 | 10-user license for Cisco PIX 501 |
| PIX-501-SW-50 | 50-user license for Cisco PIX 501 |
| PIX-501-SW-UL | Unlimited user license for Cisco PIX 501 |
| PIX-501-SW-10-50= | 10-to-50 user upgrade license for Cisco PIX 501 |
| PIX-501-SW-10-UL= | 10-to-unlimited user upgrade license for Cisco PIX 501 (requires Cisco PIX Security Appliance Software Version 6.3) |
| PIX-501-SW-50-UL= | 50-to-unlimited user upgrade license for Cisco PIX 501 (requires Cisco PIX Security Appliance Software Version 6.3) |
| PIX-501-PWR-AC= | Spare AC power supply for Cisco PIX 501 |
| PIX-VPN-DES | Cisco PIX DES VPN/SSH/SSL encryption license |
| PIX-501-VPN-3DES | Cisco PIX 501 3DES/AES VPN/SSH/SSL encryption license |


