About the Author

author photo

Joe Harris, CCIE No. 6200 (R&S, Security & SP) is a Systems Engineer with Cisco Systems® specializing in Security. In addition to authoring Cisco Network Security Little Black Book, Joe has also been a technical reviewer for several Cisco Press publications and written articles, white papers, and presentations on various security technologies. He also assists various Certification Partners by beta testing their newest CCIE certification workbooks and has been recognized by Cisco as an SE Wall of Fame award winner.

See All Posts by This Author

Cisco ASA/PIX Software v7.2.3 and ASDM v5.2.3 Released

Cisco has announced the availability of v7.2.3 software (and ASDM v5.2.3) for the Cisco ASA 5500 Series and Cisco PIX Security Appliances. This release unlocks two ports of Gigabit Ethernet on any Cisco ASA 5510 appliance with a Security Plus license, in addition to introducing Cisco WAAS support, ESMTP over TLS support, increased VLAN range support on Cisco ASA 5505, and resolving a variety of customer-found and internally found defects in previous software releases. Gigabit Ethernet Support Unlocked on 2 Embedded Ports in Cisco ASA 5510s with Security Plus License This release brings Gigabit Ethernet support on two of the embedded I/O ports in any Cisco ASA 5510 that has a Security Plus license. After upgrading to Cisco ASA Software v7.2.3, ports 0/0 and 0/1 will become Gigabit Ethernet enabled on Cisco ASA 5510s with a Security Plus license. This gives customers greater flexibility, and enables them to achieve the maximum Cisco ASA 5510 firewall throughput (300 Mbps) through a single interface, if required. Below is a table that summarizes the number and types of interfaces that are included with Cisco ASA 5510s, depending on software release and license installed. 

Platform

Running v7.2.2 Running v7.2.3
Cisco ASA 5510, Base Platform 5 Fast Ethernet No Change
Cisco ASA 5510, Security Plus 5 Fast Ethernet 2 Gigabit Ethernet, 3 Faster Ethernet

The Cisco ASA 5510 Security Plus license is an excellent upgrade option for customers, with a list price of $1000 as an option and $1200 as a spare (ASA5510-SEC-PL and ASA5510-SEC-PL= respectively).  It adds the following key capabilities to this popular platform:

  • Active/Active and Active/Standby stateful failover support
  • Clustering and load balancing support for SSL and IPsec remote access VPNs (requires Cisco ASA 5500 Software v8.0)
  • More than doubles the number of maximum firewall connections (130,000 with Security Plus vs. 50,000 on base platform)
  • Adds support for up to 5 virtual firewalls/security contexts, with 2 security contexts included with Security Plus license
  • Unlocks two embedded ports for Gigabit Ethernet, bringing I/O profile to 2 Gigabit Ethernet and 3 Fast Ethernet ports

Cisco WAAS Support
This release also introduces support for enabling secure WAN optimization in conjunction with Cisco Wide Area Application Services (WAAS) solutions. This solution provides full stateful inspection firewall services, facilitates Payment Card Industry (PCI) compliance, transparently protects WAN accelerated traffic, and provides transparent integration for networks using Cisco WAAS.ESMTP over TLS Support
Cisco ASA/PIX Software v7.2.3 introduces support for TLS-encrypted SMTP email transfer connections.  Using the powerful Modular Policy Framework (MPF) that Cisco ASA/PIX solutions offers, customers can permit/deny the usage of this service on a per-flow basis.  Thus enabling customers to have encrypted SMTP communications with trusted business partners, and blocking encrypted SMTP connections from untrusted sites.

 Increased VLAN Range Support on Cisco ASA 5505
This release also expands the number of VLAN IDs the Cisco ASA 5505 can use to 1 - 4090 (previously Cisco ASA 5505 was limited to VLAN IDs 1 - 1001).  This gives customers greater flexibility, and allows them to use the expanded VLAN ID range found in most network environments.

There Is 1 Response So Far. »

  1. Gravatar

    Glad to hear they finally released new code for the 7.2.x rev. It was painful before. Lots of bugs. We were keep our customers on 7.0.x because of the bugs.

    Justin Lofton
    Systems Engineer
    Tredent Data Systems, Inc.
    justinl@tredent.com
    http://www.tredent.com

Post a Response