Throughput: FW + AVC (1024B) |
14Gbps |
---|---|
Throughput: FW + AVC + IPS (1024B) |
12.5Gbps |
Maximum concurrent sessions, with AVC |
10Million |
Maximum new connections per second, with AVC |
85K |
TLS (Hardware Decryption) |
4.5Gbps |
Throughput: NGIPS (1024B) |
15Gbps |
IPSec VPN Throughput (1024B TCP w/Fastpath) |
6Gbps |
Multi-Instance Capable |
Yes |
Application Visibility and Control (AVC) |
Standard, supporting more than 4000 applications, as well as geolocations, users, and websites |
AVC: OpenAppID support for custom, open source, application detectors |
Standard |
Cisco Security Intelligence |
Standard, with IP, URL, and DNS threat intelligence |
Cisco Firepower NGIPS |
Available; can passively detect endpoints and infrastructure for threat correlation and Indicators of Compromise (IoC) intelligence |
Cisco AMP for Networks |
Available; enables detection, blocking, tracking, analysis, and containment of targeted and persistent malware, addressing the attack continuum both during and after attacks. |
Cisco AMP Threat Grid sandboxing |
Available |
URL Filtering: number of categories |
More than 80 |
URL Filtering: number of URLs categorized |
More than 80 Million |
Automated threat feed and IPS signature updates |
Yes: class-leading Collective Security Intelligence (CSI) from the Cisco Talos Group |
Third-party and opensource ecosystem |
Open API for integrations with third-party products; Snort® and OpenAppID community resources for new and specific threats |
High availability and clustering |
Active/standby. Cisco Firepower 4100 Series allows clustering of up to 6 chassis |
Cisco Trust Anchor Technologies |
Firepower 4100 Series platforms include Trust Anchor Technologies for supply chain and software image assurance |
Stateful inspection firewall throughput |
40Gbps |
Stateful inspection firewall throughput (multiprotocol) |
30Gbps |
Concurrent firewall connections |
10Million |
Firewall latency (UDP 64B microseconds) |
3.5 |
New connections per second |
400,000 |
IPsec VPN throughput (450B UDP L2L test) |
9Gbps |
Maximum VPN Peers |
10,000 |
Security contexts (included; maximum) |
10; 250 |
High availability |
Active/active and active/standby |
Clustering |
Up to 16 appliances |
Scalability |
VPN Load Balancing, Firewall Clustering |
Centralized management |
Centralized configuration, logging, monitoring, and reporting are performed by Cisco Security Manager or alternatively in the cloud with Cisco Defense Orchestrator |
Adaptive Security Device Manager |
Web-based, local management for small-scale deployments |