Whatelse it can do expect open and close ports and VPN? what kind of firewall features does it have? does it provide any DOS/DDOS protection?
The PIX 506 only has 10/100 ports, so it's really only going to be good for protecting small DoS attempts that wouldn't overwhelm your server anyway. Generally it should have some type of content based access controls, so it should be able to dynamically open ports as required for FTP and similar protocols. Otherwise it's just going to do what firewalls do best: block or allow traffic and log the connection for either case.
Originally Posted by LowAsYou
also it said "Intrusion prevention".. so what kind of?
Generally intrusion prevention just covers basic signatures and blocking IPs that initiate port scans or brute force port connections. It should pretty much cover the same things BFD would do running on a Linux box.
Enterprise Network Engineer :: Hosting Hobbyist :: Master of Procrastination
"The really cool thing about facts is they remain true regardless of who states them."
For most setups is it overkill however there is no problem with using one if you would like it. It can help eliminate some of the load on the servers. If you only have a few users with ssh access you can also place ssh behind the VPN which will stop all of the brute force attacks very quickly and will also help reduce the load.
Note that things like BFD and any other similar script that bans users after guessing a password will not ban them in the PIX firewall, only in a local firewall which you would still need to be running if you wanted that functionality.
As others have said it can help some in a DDOS but at only 100Mbps many, not all types, of DDos can be stopped by the server itself. It is not going to be able to mitigate a DDoS as well as some of the systems a large datacenter has so do not think it is the solution to all DDoS issues.
John W, CISSP, C|EH
MS Information Security and Assurance ITEagleEye.com - Server Administration and Security Yawig.com - Managed VPS and Dedicated Servers with VIP Service