|
Cisco PIX OS version 7.0新特性一直以来,Cisco在PIX OS上的开发力度大概只能用“慢工出细活”来形容,在竞争对手如Netscreen, Fortinet等等大大小小的厂商不断推出New Features的同时,Cisco似乎只是将精力放在了PIX OS version 6.0的捉虫上,不用说那些封堵BT下载之类的新特性,即便是Transparent Firewall这种已是大路货的东西,Cisco也只是在Catalyst6500的Firewall Service Module提供支持。我想,一方面可能缘于Cisco的软件工程体系,另一个可能的方面是因为PIX OS属于专有OS,而Fortinet一类的厂商实际上是以Linux为基础进行开发,如我般浅薄者觉得通用操作系统的扩展性可能还是要强于专有的操作系统。
不过,一切似乎都很快要有所改观,Cisco已经在CCO上释出PIX OS 7.0的release notes,transparent firewall, virtual firewalls, IPv6, SSHv2, p2p blocking, etc,看起来该有的都有了,并且Cisco仍然保留了在CLI界面上的特点。
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/
Release Highlights
ADVANCED FIREWALL SERVICES
• Deep inspection firewall services for HTTP, FTP, ESMTP, and more
• Instant messaging, peer-to-peer, and tunneling application blocking
• Cisco Modular Policy Framework with flow-based security policies
• Virtual firewall services
• Layer 2 transparent firewall
• 3G Mobile Wireless security services
ROBUST IPSEC VPN SERVICES
• VPN client security posture enforcement
• Automatic VPN client software updating
• OSPF dynamic routing over VPN tunnels
HIGH AVAILABILITY SERVICES
• Active/Active failover with asymmetric routing support
• Remote-access and site-to-site VPN stateful failover
• Zero-downtime software upgrades
INTELLIGENT NETWORK SERVICES
• PIM multicast routing
• Quality of service (QoS)
• IPv6 networking
FLEXIBLE MANAGEMENT SOLUTIONS
• SSHv2 and SNMPv2c
• Configuration rollback
• Usability enhancements |
|