| Throughput: FW + AVC (1024B) | 13Gbps |
|---|---|
| Throughput: FW + AVC + IPS (1024B) | 11Gbps |
| Maximum concurrent sessions, with AVC | 10Million |
| Maximum new connections per second, with AVC | 64K |
| TLS (Hardware Decryption) | 4.5Gbps |
| Throughput: NGIPS (1024B) | 15Gbps |
| IPSec VPN Throughput (1024B TCP w/Fastpath) | 6Gbps |
| Multi-Instance Capable | Yes |
| Application Visibility and Control (AVC) | Standard, supporting more than 4000 applications, as well as geolocations, users, and websites |
| AVC: OpenAppID support for custom, open source, application detectors | Standard |
| Cisco Security Intelligence | Standard, with IP, URL, and DNS threat intelligence |
| Cisco Firepower NGIPS | Available; can passively detect endpoints and infrastructure for threat correlation and Indicators of Compromise (IoC) intelligence |
| Cisco AMP for Networks | Available; enables detection, blocking, tracking, analysis, and containment of targeted and persistent malware, addressing the attack continuum both during and after attacks. |
| Cisco AMP Threat Grid sandboxing | Available |
| URL Filtering: number of categories | More than 80 |
| URL Filtering: number of URLs categorized | More than 280 Million |
| Automated threat feed and IPS signature updates | Yes: class-leading Collective Security Intelligence (CSI) from the Cisco Talos Group |
| Third-party and opensource ecosystem | Open API for integrations with third-party products; Snort® and OpenAppID community resources for new and specific threats |
| High availability and clustering | Active/standby. Cisco Firepower 4100 Series allows clustering of up to 6 chassis |
| Cisco Trust Anchor Technologies | Firepower 4100 Series platforms include Trust Anchor Technologies for supply chain and software image assurance |
| Stateful inspection firewall throughput | 35Gbps |
| Stateful inspection firewall throughput (multiprotocol) | 15Gbps |
| Concurrent firewall connections | 10Million |
| Firewall latency (UDP 64B microseconds) | 3.5 |
| New connections per second | 150,000 |
| IPsec VPN throughput (450B UDP L2L test) | 8Gbps |
| Maximum VPN Peers | 10,000 |
| Security contexts (included; maximum) | 10; 250 |
| High availability | Active/active and active/standby |
| Clustering | Up to 16 appliances |
| Scalability | VPN Load Balancing, Firewall Clustering |
| Centralized management | Centralized configuration, logging, monitoring, and reporting are performed by Cisco Security Manager or alternatively in the cloud with Cisco Defense Orchestrator |
| Adaptive Security Device Manager | Web-based, local management for small-scale deployments |
