need help selecting a PIX 515e

Posted on 2006-10-23
Medium Priority
Last Modified: 2010-04-11
I am looking at purchasing a PIX 515e.
I'm a little awash in the available options. Perhaps someone can help with some advice or informative links. I am looking at Cisco's website so i know what the abbreviations stand for but i'm not sure which ones i need.

I have a small business with a static ip, a DSL Netopia router, a SBS server and a standard 2003 server.
I need a firewall with VPN capability.
Also DMZ capability would be nice. Not sure if this is only available with DMZ option.
Not sure how licensing and Smartnet support works and if it is necessary.
I would like to host my own website, FTP, and mail server.

Thanks in advance.

Question by:ArkAdmin
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2

Expert Comment

ID: 17790588
The environment you describe doesn't need more than a pix 506. It will save you some money, and  even though it only has an outside and inside interface you can still do dmz because it supports 2 vlans on the inside interface:
Off course it supports vpn as well and any everything you need for your above described setup.
Ebay has some great deals. I have 2 of those running for the past 2 yrs without any issues.

If you insist on the higher end 515.

You will require DMZ, because it will include an additional interface for that purpous. You don't require FO unless you want to have a active/failover setup, where you need to buy an additioanl failover pix firewall.  Same thing you don't require AA unless you want to have a active/active setup, requiring a second pix as well for load balancing and failover. You might want the UR unrestricted license, but you can probably do without.

Although a restricted PIX typically supports fewer concurrent connections through the firewall, it is not a problem in most cases because even the lower-end restricted PIX 515 will support 50,000 concurrent users.
A restricted PIX typically comes with about half of the RAM of an unrestricted PIX.

DES/3DES option. Depends what type of encryption you need. Most new PIXes are sold with DES encryption only and you can then submit a request to upgrade to 3DES free of charge upon signing their encryption license agreement. This can be done online at www.cisco.com


Author Comment

ID: 17791052
It looks like the 506 will work for me.

How is the 506E different?

How do I know if i need the unrestricted license?

Does the 506 require VPN client licenses? I am looking at a couple new/nearly new and/or refurbed 506's on ebay. Is there anything I need to watch out for regarding licensing, unlocking, etc?


Accepted Solution

instillmotion earned 2000 total points
ID: 17791345
In terms of standalone functionality, you will find the 506E can support pretty much all the same features that a 515 would support. It actually runs the same software, so software functionality is there.
However the 506 is limited to 2 interfaces, you cannot set it up in a failover scenario, the chassis is smaller, though rack mountable, the power supply outlet is less (heavy duty).
On a pix 501 0r 506 the license is always considered restricted however what you want to look for is the DES/3DES encryption:
"Software Licenses
3DES/AES and DES Encryption Licenses
The Cisco PIX 506E Security Appliance has two optional encryption licenses-one license (PIX-506-SW-3DES) enables 168-bit 3DES and up to 256-bit AES encryption, the other license (PIX-VPN-DES) enables 56-bit DES encryption. Both are available either at the time of ordering the Cisco PIX 506E Security Appliance, or can be obtained subsequently through Cisco.com. Note that an encryption license must be installed to activate encryption services which are required before using certain features including VPN and secure remote management."

I would go for the 3DES license as the encryption is a lot more secure than DES.

A good example of a 506 I would purchase is:

In terms of client license, by virtue of owning a pix you are entitled to use the client software to my knowledge.
However if you don't already have access to the software you will not be able to download it from the cisco website without a support contract.
However a quick search on google will find several locations where you can download the latest version: ie: http://www1.umn.edu/adcs/help/vpn/

Author Comment

ID: 17791454
thx for the 101 on 506e.
i also found the modified rack shelf for the 506 form factor.

Expert Comment

ID: 17791505
You're welcome, thx for the points.

Featured Post

Manage your data center from practically anywhere

The KN8164V features HD resolution of 1920 x 1200, FIPS 140-2 with level 1 security standards and virtual media transmissions at twice the speed. Built for reliability, the KN series provides local console and remote over IP access, ensuring 24/7 availability to all servers.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Short answer to this question: there is no effective WiFi manager in iOS devices as seen in Windows WiFi or Macbook OSx WiFi management, but this article will try and provide some amicable solutions to better suite your needs.
For many of us, the  holiday season kindles the natural urge to give back to our friends, family members and communities. While it's easy for friends to notice the impact of such deeds, understanding the contributions of businesses and enterprises i…
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses
Course of the Month10 days, 12 hours left to enroll

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question