Cisco Firewall Models and Performance

This article is about Cisco Firewalls. It aggregates available information from datasheets published by Cisco.

Cisco ASA

ASA or Adaptive Security Appliance is one of the most commonly deployed firewalls and successor of Cisco PIX, which was Cisco’s first firewall available with acquisition of Network Translation in 1995.

Original ASA line consisted of 6 models with the following parameters, as published on Cisco website. All of the models below are well past End-Of-Sale date.

IPS performance numbers can be achieved only using Advanced Inspection and Prevention or AIP hardware module.

ModelForm-factorFirewall
Mbps
FW + IPS
Mbps
VPN AES
Mbps
Sessions
5505Desktop1507510025,000
55101RU300300170130,000
55201RU450450225280,000
55401RU650650325400,000
55501RU1,200N/A425650,000
5580-204RU5,000N/A1,0001,000,000
5580-404RU10,000N/A1,0002,000,000

Table 1. Legacy ASA Performance

More information is available on official Cisco website.

The next generation of Cisco ASA line introduced Next-Gen Features, such as antivirus, file blocking, antispam, URL blocking and content control with new hardware security module called Content Security and Control or CSC Module for ASA 5520/40/80. New ASA 5525-X, 5545-X and 5555-X models had these features available without any additional hardware.

New X models also had significantly higher throughput. Below are published specs for the newer models:

ModelFirewall (UDP-based)
Mbps
Firewall (Multi-protocol)
Mbps
FW+IPS

Mbps
Next-Gen Throughput
Mbps
VPN AES
Mbps
Sessions
5520450*450**225280,000
5525-X2,0001,000600650300500,000
5540650*650**325400,000
5545-X3,0001,5009001,000400750,000
55501,200*N/A**425650,000
5555-X4,0002,0001,3001,4007001,000,000

Table 2. ASA Gen2 Performance

* – Performance data is not published

** – CSC module is responsible for Next-Gen features on these models. Performance data is not published

Cisco also made available multi-protocol firewall throughput numbers for the new platforms based on multiple TCP-based applications, such as HTTP, SMTP and FTP. The table above shows values for both maximum achievable and closer to real life multi-protocol performance.

The second generation models data sheet is available here.

Current product line includes Next-Gen features, such as Sourcefire Threat and Advance Malware Protection. These technologies became available with Cisco’s acquisition of Sourcefire in 2013. Firewalls model name has “with FirePOWER Services” added to the 55xx series as per table below.

ModelForm-factorFirewall (Multi-protocol)
Mbps
FW + AVC

Mbps
FW + AVC + NGIPS

Mbps
FW + AVC + NGIPS
440 byte
Mbps
VPN AES

Mbps
Sessions
5506-X
5506W-X
5506H-X
Desk
W - is for wireless
H - is ruggedized
3002501259010050,000
5508-X1RU500450250180175100,000
5516-X1RU900850450300250250,000
5525-X1RU1,0001,000650375300500,000
5545-X1RU1,5001,5001,000575400750,000
5555-X1RU2,0001,7501,2507257001,000,000

Table 3. ASA Current Gen Performance

The current models can either run:

  • ASA software with FirePOWER services as a software module managed by FirePOWER Management Center.
  • FTD or unified image with the single control plane. Traditional ASA configuration with CLI will not be available to perform changes.

The screenshot of the software download page shows options for ASA5506-X as an example with the options marked with red dot are required to image ASA with FirePOWER services. Blue dot option is the unified image.

Cisco Firepower Series

Firepower devices include 4 series of the products:

All Firepower devices can run FTD image and either support or will support ASA image.

Firepower 1000 series is the most recent addition to the family and has impressive performance numbers, especially with NGIPS and AVC features enabled. At the time of writing Firepower 1000 supports only FTD image. Local management via Firepower Device Manager or centralized via Management Center options are available.

ModelForm-factorFirewall
(Multi-protocol)
Mbps
FW+AVC
1024 byte
Mbps
FW + AVC + NGIPS
1024 byte
Mbps
VPN AES

Mbps
TLS


Mbps
Sessions
1010Desk650650650300150100,000
11201RU1,5001,5001,5001,000700200,000
11401RU2,2002,2002,2001,2001,000400,000

Table 4. FTD 1000 Series Performance

Firepower 2100 series consists of 4 models and has dual multi-core CPU architecture. FTD performance is as per the table below. All devices are 1RU.

ModelFirewall Max
(UDP)
Mbps
FW+AVC
1024 byte
Mbps
FW + AVC + NGIPS
1024 byte
Mbps
VPN AES

Mbps
TLS

Mbps
Sessions
21103,0002,3002,3008003651,000,000
21206,0003,0003,0001,0004751,500,000
213010,0005,0005,0001,6007352,000,000
214020,0009,0009,0003,2001,4003,000,000

Table 5. Firepower 2100 Series Performance - FTD Image

Cisco also publishes performance number when Firepower 2100 is running ASA image captured in the next table.

ModelFirewall Max
(UDP)
Mbps
Firewall
(Multi-protocol)
Mbps
VPN AES

Mbps
Sessions
21103,0001,5005001,000,000
21206,0003,0007001,500,000
213010,0005,0001,0002,000,000
214020,00010,0002,0003,000,000

Table 6. Firepower 2100 Series Performance - ASA Image

Firepower 4100 Series consists of 7 models. Original models are 41×0 and 41×5 are more recent addition. All devices are 1RU. This series can operate at much higher speed and is positioned for data center use. It can also run multiple instances of FTDs using Docker container packaging.

The device has 2 x86 CPUs with internal hardware optimization with programmable Smart NICs and Crypto Accelerators.

450-byte packet size numbers are published and shown in the table below for FTD image.

ModelFirewall Max
(UDP)
Mbps
FW+AVC
1024 byte
Mbps
FW+AVC
450 byte
Mbps
FW+AVC + NGIPS
1024 byte
Mbps
FW+AVC + NGIPS
450 byte
Mbps
VPN AES

Mbps
TLS


Mbps
Sessions
411035,00013,0003,50011,0002,5006,0004,50010,000,000
411580,00027,00010,00026,0007,0008,0006,50015,000,000
412060,00022,0006,50019,0004,50010,0007,10015,000,000
412580,00040,00013,00035,0009,00014,0008,00025,000,000
414070,00032,0009,50027,0006,50013,0007,30025,000,000
414580,00053,00017,00045,00012,00018,00010,00030,000,000
415075,00045,00014,50039,00010,00014,0007,50030,000,000

Table 7. Firepower 4100 Series Performance - FTD Image

4100 ASA image performance is as per table below.

ModelFirewall Max
(UDP)
Mbps
Firewall
(Multi-protocol)
Mbps
VPN AES

Mbps
Sessions
411035,00015,0008,00010,000,000
411580,00040,00015,00015,000,000
412060,00030,00010,00015,000,000
412580,00045,00019,00025,000,000
414070,00040,00014,00025,000,000
414580,00050,00023,00040,000,000
415075,00050,00015,00035,000,000

Table 8. Firepower 4100 Series Performance - ASA Image

Firepower 9300 is carrier-grade modular firewall in 3RU form factor. Each firewall can have up to 3 security modules installed of the same type, which are internally clustered. Security modules have the same architecture as Firepower 4100 with 2 x86 CPUs, Smart NIC and Crypto Accelerator.

Model number and naming is based on number of CPU cores per socket. Performance is published for single security module and for 3x clustered modules to show how throughput scales.

ModelFirewall Max
(UDP)
Mbps
FW+AVC
1024 byte
Mbps
FW+AVC
450 byte
Mbps
FW+AVC + NGIPS
1024 byte
Mbps
FW+AVC + NGIPS
450 byte
Mbps
VPN AES

Mbps
TLS


Mbps
Sessions
SM-2475,00025,0007,50021,0005,00013,5007,50030,000,000
SM-3680,00034,0009,50029,0007,00016,0008,50030,000,000
SM-4480,00050,00016,00043,00011,50017,00010,00030,000,000
3x SM-44234,000148,00048,000132,00032,50051,00025,00063,000,000
SM-4080,00054,00019,00048,00013,00020,00010,00035,000,000
SM-4880,00064,00022,00055,00015,00025,00011,00035,000,000
SM-5680,00070,00025,00064,00018,00027,00012,00035,000,000
3x SM-56235,000168,00060,000153,00043,00081,00028,00060,000,000

Table 9. Firepower 9300 Series Performance - FTD Image

9300 ASA image performance is as per table below.

ModelFirewall Max
(UDP)
Mbps
Firewall
(Multi-protocol)
Mbps
VPN AES

Mbps
Sessions
SM-2475,00050,00015,00055,000,000
SM-3680,00060,00018,00060,000,000
SM-4480,00060,00020,00060,000,000
3x SM-44234,000130,00060,00070,000,000
SM-4080,00055,00025,00055,000,000
SM-4880,00060,00027,00060,000,000
SM-5680,00064,00030,00060,000,000
3x SM-56235,000172,00074,000195,000,000

Table 10. Firepower 9300 Series Performance - ASA Image

Cisco ASAv

ASAv is virtualized Cisco ASA that can be deployed on all popular virtualization platforms, including VMware ESXi, KVM and Hyper-V. Use cases for virtualized platforms data center deployments with Cisco ACI where firewall provisioning and insertion can be automated. ASAv is also supported in Azure and AWS.

There are 4 models available with the parameters and performance numbers as per table below. Measurement was performed on Xeon E5-2690v4 with SR-IOV.

ModelvCPUsRAM

GB
Firewall Max
(UDP)
Mbps
Firewall
(Multi-protocol)
Mbps
VPN AES

Mbps
Sessions
ASAv511.5100505050,000
ASAv10121,000500250100,000
ASAv30482,0001,000750500,000
ASAv5081610,0005,00010,0002,000,000

Table 11. Cisco ASAv Performance

Cisco NGFWv

NGFWv can be deployed on VMware ESXi and KVM. Hyper-V is not supported. Both Azure and AWS can host NGFWv. Use case for virtual NGFWv are the same as with Cisco ASAv.

There are 3 supported CPU/RAM configurations listed below.

vCPUsRAM

GB
FW+AVC
1024 byte
Mbps
482,000
8164,000
12248,000

Table 12. Cisco NGFWv Performance

Meraki MX

Cisco acquired Meraki in 2012. Meraki products are cloud-controlled and target customers looking for simpler management and rapid provisioning. There are unique features, such as Auto VPN which provides very quick and simple way to establish full mesh VPN site-to-site connectivity. This is possible due to centralized cloud control plane which performs automatic security parameters management.

There are some drawbacks in configuration flexibility and feature set. For example, Application Layer Gateway (ALG) functionality is not supported with MX firewalls which can affect VoIP support. See the following URL for details.

Base license includes stateful firewall and Auto VPN features. Advanced security services license unlocks IPS, Advanced Malware Protection and Content Filtering.

Meraki MX firewalls for small branches include the following models:

  • MX64, MX64W
  • MX65, MX65W (similar to MX64, but with extra ports)
  • MX67, MX67W, MX67C
  • MX68, MX68W, MX68CW (similar to MX67, but with extra ports)

W in the model number is wireless support and C is built-in 3G/4G. All models support 3G/4G USB modems for failover connectivity.

Medium branch:

  • MX84
  • MX100

Large branch/campus:

  • MX250
  • MX450

Public cloud support is possible with vMX. It can be deployed on AWS and Azure to provide VPN concentrator functionality.

ModelStateful Firewall

Mbps
VPN Throughput

Mbps
Recommended
number of users
MX64, MX64W,
MX65, MX65W
25010050
MX67, MX67W, MX67C,
MX68, MX68W, MX68CW
45020050
MX84500250200
MX100750500500
MX2504,0001,0002,000
MX4506,0002,00010,000
vMX100500500N/A

Table 13. Meraki MX Performance