Networks Training

  • About
  • My Books
  • IP Tools
  • HOME
  • Cisco Networking
    • Cisco General
    • Cisco IOS
    • Cisco VPN
    • Cisco Wireless
  • Cisco ASA
    • Cisco ASA General
    • Cisco ASA Firewall Configuration
  • Certifications Training
    • CCNA Training
    • Cisco Certifications
    • I.T Training
  • General
    • Tech News
    • General Networking
    • IP Telephony
    • Network Security
    • Product Reviews
    • Software
  • Cisco Routers
  • Cisco Switches
You are here: Home / Cisco ASA Firewall Configuration / Cisco ASA CX Security Module on new 5500-X Firewalls

Cisco ASA CX Security Module on new 5500-X Firewalls

Edited By Harris Andrea

The new series of Cisco ASA devices (ASA 5500-X models which include 5512-X, 5515-X, 5525-X, 5545-X, 5555-X and 5585-X) have the capabilities to support Next Generation Firewall Security Services.

They support these security services as cloud-based services (such as Cloud Web Security and Web Security Essentials) or as software based modules which do not need additional hardware (only a license to use the module).

One of the prevalent security services modules is the ASA CX. This module has the following characteristics and compatibilities:

  • It comes as a separate Hardware Module SSP on 5585-X firewall.
  • It comes as a Software Module on ASA 5512-X through ASA 5555-X and is supported only on ASA version 9.1 and later.
  • If you purchase a Cisco ASA 5512-X through ASA 5555-X with the ASA CX software module included, then you will get a device with a pre-installed SSD (Solid State Drive) which will have the ASA CX software ready to go.If you want to add the ASA CX to an existing ASA, or need to replace the SSD, you need to install the ASA CX boot software and partition the SSD with a special procedure.
MORE READING:  Cisco ASA Master PassPhrase (How to Show Encrypted Password)

The ASA CX security module receives traffic from the ASA hardware firewall and performs some advanced and extensive application inspection and control over this traffic.

For example, with the ASA CX module, you can extract the full context of a traffic flow and enforce granular policies such as permitting access to Facebook but denying access to certain other functionalities of Facebook (such as playing Facebook games for example).  

Also, you can permit finance employees access to a sensitive enterprise database but denying the same to other employees.

This Context-Aware security offered by ASA CX is based on identity of a user (who), the application or website that the user is trying to access (what), the origin of the access attempt (where), the time of the attempted access (when), and the properties of the device used for the access (how).

The ASA CX has its own GUI environment (different from the ASDM which manages the actual ASA firewall) and is managed with a Web Browser (for single installations) or using the Cisco Prime Security Manager (PRSM) which is a management tool for multiple ASA CX installations.

MORE READING:  Configure Cisco ASA 5505 to allow Remote Desktop access from Internet

Taking advantage of the ASA CX is one of the differences between the older ASA5500 appliances and the new ASA5500-X series. ASA CX is supported only on the new 5500-X devices.

NOTE:

If you don’t want to have these Next Generation Security services (which cost money to have) and you just want a plain firewall solution, then there are no major feature differences between the new ASA5500-X and the regular ASA5500 series (as far as core firewall services are concerned).

However, you should keep in mind that the new 5500-X models are running on 64-bit processors and have much higher performance and throughput specs than the regular 5500 series.

Spread the love

Related Posts

  • Prevent Spoofing Attacks on Cisco ASA using RPF
  • Configuring Connection Limits on Cisco ASA Firewalls – Protect from DoS
  • Configuring AAA Authentication-Authorization-Accounting on Cisco ASA Firewall (TACACS+, RADIUS)
  • Cisco ASA Firewall Management Interface Configuration (with Example)
  • How to Configure Access Control Lists on a Cisco ASA 5500/5500-X Firewall (with Examples)

Filed Under: Cisco ASA Firewall Configuration

Download Free Cisco Commands Cheat Sheets

Enter your Email below to Download our Free Cisco Commands Cheat Sheets for Routers, Switches and ASA Firewalls.

By subscribing to our email list you will be receiving technical tutorials and industry news from time-to-time. You can unsubscribe at any time.

About Harris Andrea

Harris Andrea is an Engineer with more than two decades of professional experience in the fields of TCP/IP Networks, Information Security and I.T. Over the years he has acquired several professional certifications such as CCNA, CCNP, CEH, ECSA etc.

He is a self-published author of two books ("Cisco ASA Firewall Fundamentals" and "Cisco VPN Configuration Guide") which are available at Amazon and on this website as well.

Comments

  1. Edwin says

    April 19, 2013 at 2:43 pm

    Awesome. Your my one stop firewall shop! You should also come with a document, tutorial, or pdf on the FWSM and ASA 1000v.

  2. Blog Admin says

    April 19, 2013 at 4:54 pm

    Edwin,

    I’m glad you liked my post.

    Take care…

    Harris

  3. marwan says

    April 24, 2013 at 8:21 pm

    thanks for your post
    it has a good information
    q
    what do you mean by “Next Generation Security services”
    Regards

  4. Saeed says

    April 25, 2013 at 6:30 am

    Hi Harris,

    Thanks for such nice information and really your website and article educating us on few lines.

    Also, i wish you have to post for DDOS mitigation steps on firewall/router and educate us how to identify first these type of attacks.

    Keep it up and once again thanks.

    Regards,

    Saeed

  5. Blog Admin says

    April 25, 2013 at 4:39 pm

    Next Generation Security Services refer mainly to advanced inspection and granular traffic control based on “Context”. The firewall must have knowledge who the user is, what he/she is trying to access, from where etc, so the firewall can enforce policies based on the context of every connection. Also, with Next Generation Security you can enforce restrictions on what sites the users can access and what applications etc. e.g users can access Facebook but restricted to play games on Facebook.

  6. René Huysmans says

    April 29, 2013 at 4:10 am

    Hi Harris,

    thanks for your updates. They are informative and most helpful. Regarding the ASA-CX security service, how does that stack up to the PaloAlto firewall? I’ve worked with the Cisco PIX/ASA firewall since it was invented but having recently been forced onto a PaloAlto training course I’m wondering if the ASA-CX can really match what the PaloAlto can do?

  7. Blog Admin says

    April 29, 2013 at 5:34 am

    Rene,

    Unfortunately I don’t have experience with other firewall vendors except Cisco, so I don’t know exactly what the PaloAlto can do. What I know however is that the “next generation firewall” concept is more mature in other vendors compared with Cisco, so I guess PaloAlto might have features that Cisco is still behind. However, Cisco has the capability and knowhow to always catch up with other vendors pretty quickly.

  8. hp says

    May 6, 2013 at 1:14 pm

    Harris,You have been a great knowledge source.
    Appreciate it, n thanks alot for being a reliable guide to all learners.

  9. Blog Admin says

    May 6, 2013 at 4:11 pm

    Thanks a lot

  10. hp says

    May 19, 2013 at 5:07 am

    >

    My co-learning frnds,

    Here’s an interesting news from Cisco recent release notes :

    When configuring for IKEv2, for security reasons you should use groups 21, 20, 19, 24, 14, and 5. We do not recommend Diffie Hellman Group1 or Group2. For example, use

    crypto ikev2 policy 10
    group 21 20 19 24 14 5

    Regards,
    Hp Gedda

  11. Blog Admin says

    May 19, 2013 at 6:22 am

    Gedda,

    Thanks for bringing this info up. Indeed the purpose of IKEv2 is to make IPSEC even stronger, that’s the reason for suggesting these high-number DH groups.

  12. Arvind says

    February 14, 2015 at 4:02 am

    Harris,

    Can we ASA CX module can be configured via CLI ?. If yes then waiting for a pdf doc written by you for this topic.

  13. Harris Andrea says

    February 14, 2015 at 6:25 am

    Hi,
    Yes the ASA CX can be configured via CLI. Once you connect on the parent ASA device, run the command “session cxsc console” which will take you to the CX CLI configuration mode.

  14. Arvind says

    February 16, 2015 at 5:44 am

    Thank you Harris.. .. Waiting for your book on ASA CX module CLI configuration.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Search this site

About Networks Training

We Provide Technical Tutorials and Configuration Examples about TCP/IP Networks with focus on Cisco Products and Technologies. This blog entails my own thoughts and ideas, which may not represent the thoughts of Cisco Systems Inc. This blog is NOT affiliated or endorsed by Cisco Systems Inc. All product names, logos and artwork are copyrights/trademarks of their respective owners.

Amazon Disclosure

As an Amazon Associate I earn from qualifying purchases.
Amazon and the Amazon logo are trademarks of Amazon.com, Inc. or its affiliates.

Search

BLOGROLL

Tech21Century
Firewall.cx

Copyright © 2026 | Privacy Policy | Terms and Conditions | Contact | Amazon Disclaimer | Delivery Policy