Cisco Virtual Security Appliance Installation Guide

11/14
88

Cisco Virtual Security Appliance Installation Guide

Posted in:

Cisco Virtual Security Appliance Installation Guide Rating: 4,6/5 5067reviews

Iv. Syslog Support. Integration with Cisco WCCP. This data sheet describes the benefits, specifications, and ordering information for the Cisco Adaptive Security Virtual Appliance ASAv Data Sheet. The Adaptive Security Appliance is a network firewall made by Cisco. It was introduced in 2005 to replace the Cisco PIX line. Along with stateful firewall. Screen-Shot-2013-09-03-at-4.09.56-PM.png' alt='Cisco Virtual Security Appliance Installation Guide' title='Cisco Virtual Security Appliance Installation Guide' />Cisco Adaptive Security Virtual Appliance ASAv Data Sheet. Meet the latest step in the evolution of Cisco Adaptive Security Appliances the Cisco Adaptive Security Virtual Appliance ASAv. This appliance brings the power of ASA to the virtual domain and cloud environments. It runs the same software as the physical appliance to deliver proven security functionality. You can use it to protect virtual workloads within your data center. Cisco Adaptive Security Virtual Appliance ASAv Some links below may open a new browser window to display the document you selected. Later, you can expand, contract, or shift the location of these workloads over time and span physical, virtual, and Public Cloud infrastructures. In the past, computing infrastructure elements were implemented with specialized hardware built for that purpose. With the advent of x. Cisco Virtual Security Appliance Installation Guide' title='Cisco Virtual Security Appliance Installation Guide' />Businesses are deploying their computing, storage, and network infrastructure with virtual devices because of benefits they gain. These include deployment flexibility, increased server utilization, and ease of management. Product Overview. The Adaptive Security Virtual Appliance runs as a virtual machine inside a hypervisor in a virtual host Figure 1. Most of the features that are supported on a physical ASA by Cisco software are supported on the virtual appliance as well, except for clustering and multiple contexts. The virtual appliance supports site to site VPN, remote access VPN, and clientless VPN functionalities as supported by physical ASA devices. Figure 1.       ASAv Architecture. The Adaptive Security Virtual Appliance uses Cisco Smart Software Licensing to validate its entitlements. Smart Software Licensing makes it easier to deploy, manage, and track virtual instances of the appliance running on customer premises. Benefits. The Adaptive Security Virtual Appliance offers multiple customer benefits, including the following Uniform Security across Deployment Domains. You gain uniform security across physical and virtual deployment domains with multiple hypervisors. Increasingly, customers are deploying some parts of an application on physical infrastructure and other parts on virtual infrastructure. Even on a virtual infrastructure, customers use multiple hypervisors to deploy their applications. ASAv, along with ASA, normalizes the deployment options. One security policy can be deployed for both physical and virtual appliances. Ease of Management. The Adaptive Security Virtual Appliance offers the representational state transfer REST API, an HTTP based interface. With it, you can change your security policies and monitoring status and otherwise manage the device. An ASA can be introduced into software defined networking SDN environments and easily used with custom policy orchestration systems. Ease of Provisioning. You can provision the virtual appliance within a matter of minutes with a predetermined configuration. You can quickly deploy security services to match the speed of application deployment. With Smart Software Licensing, the virtual appliance can automatically obtain the entitlements while giving you a single, holistic view of the resources being consumed within your enterprise. The Virtual Appliance Family. The virtual appliance is available in multiple models to provide a suitable fit for customer needs    Cisco ASAv. GB of memory and delivers up to 1. Mbps of throughput   Cisco ASAv. GB of memory and delivers up to 1 Gbps of throughput   Cisco ASAv. GB of memory and delivers up to 2 Gbps of throughput   Cisco ASAv. GB of memory and delivers up to 1. Gbps of throughput. Smart Software Licensing. Cisco Smart Software Licensing makes it easier to buy, deploy, track, and renew Cisco licenses. We have moved away from product activation key PAK based licensing to a model that supports more flexibility and visibility. You will enjoy    Simpler purchase and activation of the virtual appliance, as outlined in Figure 2   Easier license management and reporting of virtual appliances due to license pooling   Automatic license activation when the virtual appliance is provisioned. Customers, their chosen partners, and Cisco can view product entitlements and services in the Cisco Smart Software Manager. Configuration and activation are done with a single token. The Adaptive Security Virtual Appliance will self register with a Cisco server in the cloud, removing the need of going to a website and registering products with PAKs. Instead of using PAKs or license files, Smart Software Licensing establishes a pool of software licenses or entitlements that can be used across your business. When a virtual appliance is instantiated on a customers premises, an entitlement is subtracted from the pool. When a virtual appliance is decommissioned, or when it is deinstantiated within the Smart Software Manager, an entitlement is added to the pool. With the Smart Software Manager, you can self manage license deployments throughout your company easily and quickly. You can also manage multiple products from Cisco that support Smart Software Licensing. The Adaptive Security Virtual Appliance uses Smart Software Licensing exclusively. Older forms of licensing are not supported. Figure 2.       Smart Software Licensing. Table 1 lists the specifications for all three virtual appliance models. Table 2 provides ordering information. Table 1.        Specifications. Feature. ASAv. 5ASAv. ASAv. 30. ASAv. 50. Stateful inspection throughput maximum1. Mbps. 1 Gbps. 2 Gbps. Gbps. Stateful inspection throughput multiprotocol2. Mbps. 50. 0 Mbps. Gbps. 5 Gbps. Advanced Encryption Standard AES VPN throughput. Mbps. 12. 5 Mbps. Gbps. 3 Gbps. Connections per second. Concurrent sessions. VLANs. 25. 50. 20. Bridge groups. 12. IPsec VPN peers. 50. Cisco Any. Connect or clientless VPN user sessions. Cisco Unified Communications phone proxy. Not tested. Cisco Cloud Web Security users. Not tested. High availability. Activestandby. VMware ESXESXi 5. KVMHyper V Windows Server 2. R2 Not supported for ASAv. Hypervisor support. Public Cloud Support. AWS c. 3. large, c. Azure d. 3, d. 3v. Azure Government CloudCurrently not supported on Public Cloud Modes. Routed and transparent. Virtual CPUs. 11. Memory. 1 GB minimum. GB maximum. 2 GB8 GB1. GBMinimum disk storage. GB8 GB1. 6 GB1. 6 GBNote    This data is from testing on the Cisco Unified Computing System Cisco UCS C series M4 server with the Intel Xeon CPU E5 2. Deep Ze 7. SR IOV on Intel X5. X5. 40. Each performance number above was obtained while running only the associated test. Maximum throughput measured with User Datagram Protocol UDP traffic under ideal conditions. Multiprotocol refers to a traffic profile consisting primarily of TCP based protocols or applications like HTTP, SMTP, FTP, IMAPv. Bit. Torrent, and DNS. The VPN throughput and the number of sessions depend on the ASA device configuration and VPN traffic patterns. Datasheet numbers based on IKEv. Throughput 4. 50. B UDP NGE tested numbers. These elements should be taken into consideration as part of your capacity planning. Thin provisioning is supported. Table 2.        Ordering Information In Cisco Commerce Workspace CCW Order the Base Selection Denoted by K9 in the Part Number, Followed by the Desired License Type. Part Number. Description. L ASAV1. 0S K9Cisco ASAv. Gbps selection. L ASAV1. S STDCisco ASAv. Gbps with all firewall features licensed. L ASAV1. 0S STD 1. Cisco ASAv. 10 1 Gbps with all firewall features licensed. L ASAV3. 0S K9Cisco ASAv. Gbps selection. L ASAV3. S STDCisco ASAv. Gbps with all firewall features licensed. L ASAV3. 0S STD 4.