Cisco PIX firewalls

Heya Guys,
       I like to think im slowy becomeing a Cisco Router buff but I know little about the PIX firewall. I would like to know when a PIX firewall would be used? over say a Cisco Router running an IOS CBAC firewall, can it completely replace the function of a router? Also, can you impliment a DMZ on a router or would you need to use a PIX device? thanks ! :-)
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

PIX: Full firewall
Router: has some SPI capabilities.

More and more the IOS feature set of Cisco is adding the features of a pix, so it's getting harder to tell the diference.

If you have a Cisco router with multiple interfaces you could actually set up a DMZ.  

The PIX Software is kinda like the Cisco IOS that time forgot.  The command that you use, like write mem, are the same commmands that you used pre 11.2 IOS.  I have heard the reason that the do not innovate with simple commands is they feel the code is very secure and they do not like to make changes if not needed. (who knows if that's true.)

The Pix also has Fixup commands, which allow it to do extended analazyis of certin protocals, that  the router IOS would not be able to do.

In short, a router is not as secure as a PIX, because a PIX is built for security.  On the other hand, the throughput of a router is much better than a pix, because it is built for speed first.  They both overlap however.


Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
mattacukAuthor Commented:
I am glad the blur between the two is not just me! :-) My Cisco 857 router has 1 wan adsl o/pots interface and 1vlan with 4 ethernet switch ports. Is it possible to have a DMZ  on this? or  do you need a router with a built i DMZ functionality? also, can you add additional vlans or are you stuck with what your get out the box?

It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Software Firewalls

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.