Cisco FirePOWER SSL2000 Network Security/Firewall Appliance

Manufacturer: Cisco Systems, Inc
Mfr. Part: FP-SSL2000-K9

RSA, AES, DES, 3DES, RC4, MD5, SHA-1 - 3 Total Expansion Slots - 1U - Rack-mountable

Cisco FirePOWER SSL2000 Network Security/Firewall Appliance

About This Product

Overview

Strengthen Security with SSL Inspection

Cisco SSL Appliances decrypt secure socket layer (SSL) traffic and send it to existing security and network appliances to transparently enable encrypted traffic inspection. This allows existing intrusion prevention system (IPS) appliances to identify risks normally hidden by SSL, such as regulatory compliance violations, viruses, malware, data loss, and intrusion attempts.

Features and Capabilities

An Easy Vehicle for Cybersecurity Attacks

SSL-encrypted traffic is exploding, due to the enterprise-wide usage of cloud computing, secure e-commerce, Web 2.0 applications, email, and VPN. However, SSL-encrypted communications are an easy vehicle to hide many types of cybersecurity threats, including:

  • Intrusion attacks
  • Advanced malware
  • Phishing attacks
  • Viruses and worms
  • Data loss

If not managed properly, SSL can leave a hole in any enterprise security architecture. Existing approaches to SSL-encrypted traffic often involve passing everything through or blocking all SSL traffic. Or they may combine the SSL decryption on the same device as threat protection functions, such as an IPS.

Cisco SSL Appliance Capabilities

Unlike on-box SSL decryption solutions that use shared hardware resources for SSL decryption and IPS inspection, the Cisco SSL architecture permits the SSL and IPS processes to run on separate systems. This offloads all decryption and encryption requirements from the IPS to provide greater IPS performance and scalability.

Cisco SSL Appliances are also versatile enough to inspect SSL traffic in both inbound and outbound configurations and are available with a range of interface options. All include a programmable fail-open capability, traffic bypass filters, and configurable link state monitoring and mirroring. Fine-grained policy control provides the ability to control which SSL flows are inspected, passed through, or blocked.

The following unique capabilities of Cisco SSL Appliances remove risk arising from lack of visibility into SSL traffic while also maintaining the performance of security and network appliances:

  • Decryption of traffic up to 3.5 Gbps with over five million simultaneous flows
  • Transparent proxy - no configuration, addressing, or topology changes
  • Support for both passive and inline configurations
  • Detection of SSL sessions on all ports, not just the traditional port 443
  • Logging the details of all SSL flows to detect suspicious trends or patterns
  • Supports network security and firewall appliance deployment by centralizing traffic inspection, policy enforcement, and access control
  • Supports policy?based inspection and controlled management of network traffic flows through intrusion prevention firewall protection
  • Uses RSA encryption standard to support asymmetric cryptographic operations commonly used for key exchange and authentication mechanisms
  • Rack?mountable form factor allows organized installation within standard equipment racks for structured cabling layouts

Quick Specifications

Product Line
FirePOWER
Product Model
SSL2000
Product Type
Network Security/Firewall Appliance
Firewall Protection Supported
Intrusion Prevention Antivirus Malware Protection Anti-phishing Worm Scanning
Encryption Standard
RSA AES DES 3DES RC4 MD5 SHA-1
Total Number of Expansion Slots
3
Manageable
Yes
Compatible Rack Unit
1U