Cisco Cisco ASA 5540 Adaptive Security Appliance Hoja De Datos
Product Bulletin
© 2009 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information.
Page 2 of 5
●
Transparent firewall mode support for IPv6 addressing: Cisco ASA Software Release
8.2 flexibly extends the support of IPv6 addressing in transparent firewall mode to enable
quick ASA deployments into existing IPv6 networks without requiring IP readdressing.
●
250 VLANs on the Cisco ASA 5580: The number of virtual interfaces available on the
Cisco ASA 5580 has increased from 50 to 250.
●
TCP state bypass: With Cisco ASA Software Release 8.2, business can selectively disable
firewall TCP inspection on ASA appliances. This is useful for allowing certain traffic to flow
through in asymmetric routing scenarios when two ASA appliances are in different locations
that are not adjacent to Layer 2.
●
IPv6 support for AIP SSM modules: The Cisco ASA now supports IPv6 capabilities on the
Cisco ASA AIP SSM modules. Customers can send IPv6 packets from the ASA to the AIP
SSM modules for both IPv6 and IPv4 IPS inspection. Minimum IPS software required is
Cisco IPS software version 6.2.
Remote-access VPN features:
●
Cisco AnyConnect Essentials: This feature offers basic AnyConnect tunneling support for
customers who require VPN remote access but do not need Cisco Secure Desktop features
or clientless SSL VPN capabilities. AnyConnect Essentials supports mobile connectivity
options with the AnyConnect Mobile license. Upgrade to the full-featured AnyConnect
Premium license (traditional AnyConnect) is available by applying a traditional AnyConnect
license or shared license to the ASA appliance.
●
Shared license support for SSL VPN: The shared license server device (holding the
shared license) and participant devices must be able to communicate with one another on
an internal network either directly or through a VPN connection. Each participating device
must have a license that enables the shared licensing capability. Shared licenses support
the full AnyConnect feature set, including Cisco Secure Desktop and clientless SSL VPN.
●
Cisco AnyConnect Mobile: AnyConnect Mobile provides Windows Mobile 5.0, 6.0, and
6.1 full client support for touch-screen Windows Mobile devices. AnyConnect Mobile is
compatible with AnyConnect Essentials and Premium (traditional AnyConnect) licenses, as
well as with shared licenses.
●
Pre-fill username from certificate: This security feature facilitates user login by pre-filling
the username in username/password authentication from a field of the user’s certificate.
●
Double authentication: This feature enables the validation of two separate sets of
credentials at login. For example, one-time password (OTP) can be used as the primary
authentication and an Active Directory domain credential can be used for the secondary
authentication method.
●
Per-group certificate authentication enable: This feature allows administrators to
configure whether to require a certificate on a per-URL or per-FQDN basis. This setting is
global on all Cisco ASA Software releases.
●
Per-group Cisco Secure Desktop enable: This feature allows administrators to configure
Cisco Secure Desktop functions on a per-URL or per-FQDN basis. This setting is global on
all Cisco ASA Software releases.
●
Microsoft SharePoint 2007 support: Cisco ASA Software Release 8.2 provides official
Microsoft SharePoint 2007 support for clientless SSL VPN connections.
●
EKU tunnel group: Cisco ASA Software Release 8.2 provides an extended key usage
(EKU) extension in the tunnel-group map.