Enterprise Firewall Next Generation Firewall - Cisco

Transcription

Data SheetCisco ASA 5500 SeriesEnterprise FirewallNext Generation Firewall 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information.Page 1 of 10

ContentsCisco ASA 5500 Series appliances3Model overview3Detailed performance specifications and feature highlights3Hardware specifications6Cisco Capital 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information.10Page 2 of 10

Cisco ASA 5500 Series appliancesThe Cisco Firepower 5500 Series is a family of six threat-focused NGFW security platforms that deliverbusiness resiliency through superior threat defense. It offers exceptional sustained performance whenadvanced threat functions are enabled. The ASA 5500 series’ throughput range addresses use cases from theSOHO/ROBO to the internet edge. The ASA 5500 Series platforms can run either the Cisco ASA Firewall orCisco Firepower Threat Defense (FTD).Model overviewCisco ASA 5500 Series 0 Mbps125 Mbps125 Mbps8 x RJ45ASA-55081 Gbps250 Mbps250 Mbps8 x RJ45ASA-55161.8 Gbps450 Mbps450 Mbps8 x RJ45ASA-55252 Gbps650 Mbps650 Mbps8 x RJ45, optional 6 x GEASA-55453 Gbps1 Gbps1 Gbps8 x RJ45, optional 6 x GEASA-55554 Gbps1.2 Gbps1.2 Gbps8 x RJ45, optional 6 x GEDetailed performance specifications and feature highlightsTable 1.Performance specifications and feature highlights for ASA 5500 with the Cisco Firepower Threat defense imageFeatures*550655085516552555455555Throughput: FW AVC(1024B)250 Mbps450 Mbps850 Mbps1.1 Gbps1.5 Gbps1.7 GbpsThroughput: FW AVC IPS (1024B)125 Mbps250 Mbps450 Mbps650 Mbps1 Gbps1.2 GbpsThroughput: FW AVC(450B)100 Mbps175 Mbps275 Mbps350 Mbps500 Mbps600 MbpsThroughput: FW AVC IPS (450B)75 Mbps125 Mbps200 Mbps250 Mbps350 Mbps420 Mbps 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information.Page 3 of 10

Features*550655085516552555455555Maximum concurrentsessions, with AVC50K100K250K500K750K1 Million7.5K11 K11.5K19K22K250 Mbps285 Mbps270 Mbps290 Mbps370 Mbps250 Mbps450 Mbps650 Mbps1 Gbps1.2 GbpsMaximum new connections 3Kper second, with AVCTLS-Throughput: NGIPS (1024B) 125 MbpsThroughput: NGIPS (450B)75 Mbps125 Mbps200 Mbps250 Mbps350 Mbps420 MbpsIPSec VPN Throughput(1024B TCP w/Fastpath)100 Mbps175 Mbps250 Mbps300 Mbps400 Mbps700 MbpsCisco Firepower DeviceManager (localmanagement)YesYesYesYesYesYesCentralized managementCentralized configuration, logging, monitoring, and reporting are performed by theManagement Center or alternatively in the cloud with Cisco Defense OrchestratorApplication Visibility andControl (AVC)Standard, supporting more than 4000 applications, as well as geolocations, users, andwebsitesAVC: OpenAppID supportfor custom, open source,application detectorsStandardCisco Security IntelligenceStandard, with IP, URL, and DNS threat intelligenceCisco Firepower NGIPSAvailable; can passively detect endpoints and infrastructure for threat correlation andIndicators of Compromise (IoC) intelligenceCisco AMP for NetworksAvailable; enables detection, blocking, tracking, analysis, and containment of targeted andpersistent malware, addressing the attack continuum both during and after attacks.Integrated threat correlation with Cisco AMP for Endpoints is also optionally availableCisco AMP Threat GridsandboxingAvailableURL Filtering: number ofcategoriesMore than 80URL Filtering: number ofURLs categorizedMore than 280 millionAutomated threat feed andIPS signature updatesYes: class-leading Collective Security Intelligence (CSI) from the Cisco Talos ity/talos.html)Third-party and opensource ecosystemOpen API for integrations with third-party products; Snort and OpenAppID communityresources for new and specific threats 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information.Page 4 of 10

Features*550655085516552555455555High availability andclusteringActive/standbyCisco Trust AnchorTechnologiesASA 5500 Series platforms include Trust Anchor Technologies for supply chain and softwareimage assurance. Please see the section below for additional detailsNOTE: Performance will vary depending on features activated, and network traffic protocol mix, and packet sizecharacteristics. Performance is subject to change with new software releases. Consult your Ciscorepresentative for detailed sizing guidance.*ASA-5506 tested with FTD version 6.2.3.Table 2.ASA Performance and capabilities on ASA 5500 appliancesFeatures5506Stateful inspection 750 Mbpsfirewall throughput1550855165525554555551 Gbps1.8 Gbps2 Gbps3Gbps4 GbpsStateful inspectionfirewall throughput(multiprotocol)2300 Mbps500 Mbps900 Mbps1 Gbps1.5 Gbps2 GbpsConcurrent firewallconnections50K100K250K500K750K1 millionNew connectionsper second5K10K20K20K30K50KIPsec VPNthroughput (450BUDP L2L test)100 Mbps175 Mbps250 Mbps300 Mbps400 Mbps700 MbpsSecurity contexts(included;maximum)N/A2; 52; 52; 202; 502; 100High ve/activeandactive/standbyScalabilityVPN Load BalancingCentralizedmanagementCentralized configuration, logging, monitoring, and reporting are performed by Cisco SecurityManager or alternatively in the cloud with Cisco Defense OrchestratorAdaptive SecurityDevice ManagerWeb-based, local management for small-scale deployments1Throughput measured with 1500B User Datagram Protocol (UDP) traffic measured under ideal test conditions.2“Multiprotocol” refers to a traffic profile consisting primarily of TCP-based protocols and applications like HTTP, SMTP, FTP, IMAPv4,BitTorrent, and DNS.3In unclustered configuration.Performance testing methodologies LINK 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information.Page 5 of 10

Hardware specificationsTable 3.Cisco ASA 5500-X series next-generation firewallsFeatureCisco ASA5506-XCisco ASA5506H-XCisco ASA5508-XCisco ASA5516-XCisco ASA5525-XCisco ASA5545-XCisco ASA5555-XForm factorDesktop, IN-Rail1 rack unit(RU), 19-in.rackmountable1 rack unit(RU), 19-in.rackmountable1RU, 19-in.rackmountable1RU, 19-in.rackmountable1RU, 19in. rackmountableDimensions1.72 x 7.871 x 2.72 x 9.059.23 in.x 9.05 in.1.72 x 17.2 x11.288 in.1.72 x 17.2 1.75 x 17.5 xx 11.288 in. 14.25 in.1.67 x 16.7 x19.1 in.1.67 x 16.7 x19.1 in.(H x W x D)(4.369 x19.992 x23.444 cm)(6.9 x23.0 x 23.0cm)(4.369 x43.688 x28.672 cm)(4.369 x43.688 x28.672 cm)(4.45 x 20.04x 36.20 cm)(4.24 x 42.9 x (4.24 x 42.948.4 cm)x 48.4 cm)Integrated I/O8 x 1GE4 x 1GE8 x 1GE8 x 1GE8 x 1GE8 x 1GE8 x 1GEExpansion I/ON/AN/AN/AN/A6 GE copperor 6 GE SFP6 GE copperor 6 GE SFP6 GE copperor 6 GE SFPExpansion slotN/AN/AN/AN/A1 interfacecard1 interfacecard1 interfacecardDedicatedmanagementportYes (Shared)Yes(Shared)Yes (Shared)Yes(Shared)Yes (1 GE)Yes (1 GE)Yes (1 GE)Serial ports1 RJ-45 andMini USBconsole1 RJ-45and MiniUSBconsole1 RJ-45 andMini USBconsole1 RJ-45and MiniUSBconsole1 RJ-45console1 RJ-45console1 RJ-45consoleSolid-statedrive50 GB mSata650 GBmSatatested forheat80 GB mSata6 100 GBmSata6USB 2.0 portsUSB port type‘A’, HighSpeed 2.0USB portUSB port typetype ‘A’,‘A’, HighHigh Speed Speed 2.02.0USB porttype ‘A’,High Speed2.01 slot, 120 GB 2 slots, RAIDMLC SED1, 120 GBMLC SED2 slots, RAID1, 120 GBMLC SED222Operating parametersTemperature32 to 104 F(0 to 40 C)-4 to 140 F 32 to 104 F(-20 to 60(0 to 40 C) C)32 to 104 F 23 to 104 F(0 to 40 C) (-5 to 40 C)23 to 104 F(-5 to 40 C)23 to 104 F(-5 to 40 C)Relativehumidity90 percentnoncondensing95 percent 10 to 90nonpercent noncondensing condensing10 to 90percentnoncondensing10 to 90percent noncondensing10 to 90percent noncondensingAltitudeDesigned and Designedtested for 0 to and testedDesigned and Designedtested for 0 to and tested 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information.10 to 90percent noncondensingDesigned and Designed and Designedtested for 0 to tested for 0 to and testedPage 6 of 10

FeatureAcoustic noiseCisco ASA5506-XCisco ASA5506H-XCisco ASA5508-XCisco ASA5516-XCisco ASA5525-XCisco ASA5545-XCisco ASA5555-X10,000 ft(3048 m)for 0 to10,000 ft(3050 m)10,000 ft(3048 m)for 0 to10,000 ft(3048 m)10,000 ft(3050 m)10,000 ft(3050 m)for 0 to10,000 ft(3050 m)Fanless0 dBAFanless0 dBA41.6 Aweighteddecibels(dBA) type.67.2 dBA max41.6dBA type64.2dBA max67.9dBA max67.9dBA max67.2 dBAmaxNon-operating parametersTemperature1-13 to 158ºF(-25 to 70ºC)-40 to185ºF (-40to 85ºC)-13 to 158ºF -13 to(-25 to 70ºC) 158ºF (-25to 70ºC)-13 to 158 F(-25 to 70 C)-13 to 158 F -13 to 158 F(-25 to 70 C) (-25 to70 C)Relativehumidity10 to 90percent noncondensing10 to 95percentnoncondensing10 to 90percent noncondensing10 to 90percentnoncondensing10 to 90percent10 to 90percent10 to 90percentAltitudeDesigned andtested for 0 to15,000 ft(4572 m)Designedand testedfor 0 to15,000 ft(4572 m)Designed andtested for 0to 15,000 ft(4572 m)Designedand testedfor 0 to15,000 ft(4572 m)Designed andtested for 0 to15,000 ft(4572 m)Designed andtested for 0 to15,000 ft(4572 m)Designedand testedfor 0 to15,000 ft(4572 m)Power input (per power supply)AC range linevoltageExternal, 90 to240 voltsalternatingcurrent (VAC)External, 90to 240 voltsalternatingcurrent(VAC)External, 90to 240 voltsalternatingcurrent (VAC)External, 90to 240 voltsalternatingcurrent(VAC)100 to 240VAC100 to 240VAC100 to 240VACAC normal linevoltage90 to 240VAC90 to 240VAC91 to 240VAC92 to 240VAC100 to 240VAC100 to 240VAC100 to 240VACAC currentN/AN/A0.25AC amps 0.25ACamps4.85A5A, 100 to120V5A, 100 to120V2.5A, 200 to240V2.5A, 200 to240VAC frequency50/60 Hz50/60 Hz50/60 Hz50/60 Hz50/60 Hz50/60 Hz50/60 HzDual-powersuppliesNoneNoneNoneNoneNoneYesYesDC domesticline voltageN/AN/AN/AN/A-40.5 to 56VDC(-48 VDCnominal)-40.5 to 56VDC-40.5 to 56VDC(-48 VDCnominal)(-48 VDCnominal)-55 to -72VDC-55 to -72VDC-55 to -72VDC(-60 VDC(-60 VDC(-60 VDCDC international N/Aline voltageN/AN/AN/A 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information.Page 7 of 10

FeatureDC currentCisco ASA5506-XN/ACisco ASA5506H-XN/ACisco ASA5508-XN/ACisco ASA5516-XN/A 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information.Cisco ASA5525-XCisco ASA5545-XCisco 15A(maximuminput)15A(maximuminput)Page 8 of 10

FeatureCisco ASA5506-XCisco ASA5506H-XCisco ASA5508-XSteady state12V @2.5A5V @3.6A12V @ 3.0AMaximum peak12V @ 5A5V @4.4AMaximum heatdissipation205 Btu/hrCisco ASA5516-XCisco ASA5525-XCisco ASA5545-XCisco ASA5555-X12V @ 3.0A 75W86W90W12V @ 5.0A12V @ 5.0A 108W125W134W75 Btu/hr205 Btu/hr205 Btu/hr369 Btu/hr427 Btu/hr458 Btu/hr7 lb(3.18 kg)8 lb(3 kg)8 lb(3 kg)22.0 lb(10 kg)16.82 lb (7.63kg) withsingle powersupplyOutputWeight (with AC 4 lb (1.82 kg)power supply)116.82 lb(7.63 kg)with singlepower18.86 lb (8.61 supplykg) with dual 18.86 lbpower supply (8.61 kg)with dualpowersupplyDerate the maximum operating temperature 1.5 C per 1000 ft above sea level.Table 4.Cisco ASA 5500 Series regulatory, safety, and EMC complianceSpecificationDescriptionRegulatory complianceProducts comply with CE markings per directives 2004/108/EC and 2006/108/ECSafety UL 60950-1 CAN/CSA-C22.2 No. 60950-1 EN 60950-1 IEC 60950-1 AS/NZS 60950-1 GB4943EMC: Emissions 47CFR Part 15 (CFR 47) Class A (FCC Class A) AS/NZS CISPR22 Class A CISPR22 CLASS A EN55022 Class A ICES003 Class A VCCI Class A EN61000-3-2 EN61000-3-3 KN22 Class A CNS13438 Class A EN300386 TCVN7189EMC: Immunity EN55024 CISPR24 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information.Page 9 of 10

SpecificationDescription EN300386 KN24 TVCN 7317 EN-61000-4-2, EN-61000-4-3, EN-61000-4-4, EN-61000-4-5, EN-61000-4-6,EN-61000-4-8, EN61000-4-11Cisco CapitalFlexible payment solutions to help you achieve your objectivesCisco Capital makes it easier to get the right technology to achieve your objectives, enable businesstransformation and help you stay competitive. We can help you reduce the total cost of ownership,conserve capital, and accelerate growth. In more than 100 countries, our flexible payment solutions can helpyou acquire hardware, software, services and complementary third-party equipment in easy, predictablepayments. Learn more.Printed in USAs 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information.C78-742475-01 03/20Page 10 of 10

Cisco ASA 5500-X series next-generation firewalls Feature Cisco ASA 5506-X Cisco ASA 5506H-X Cisco ASA 5508-X Cisco ASA 5516-X Cisco ASA 5525-X Cisco ASA 5545-X Cisco ASA 5555-X Form factor Desktop, rack mountable Desktop, rack mountable, wall mountable, DIN-Rail 1 rack unit (RU), 19 -in. rack-mountable 1 rack unit (RU), 19 -in. rack-mountable