Cisco is a perennial leader in delivering cutting-edge firewalls for the widest possible range of environments. Cisco's Firepower Next Generation Firewall (NGFW) appliances provide an advanced cybersecurity platform that marshals dedicated hardware, cloud services, and machine learning to block, identify, and respond to cyberthreats without manual intervention. Progent's Cisco-certified CCIE-certified firewall experts can assist your organization to plan and execute an efficient upgrade to Cisco Firepower firewalls from Cisco's legacy ASA 5500-X, ASA 5500, or PIX firewalls and show you how to enhance Firepower firewalls with Cisco's cloud-based services to build and centrally control IT environments that span branch offices, data centers, and cloud resources. Progent can also assist you to manage and debug older-generation Cisco security appliances. Progent's certified cybersecurity experts can help you with policy creation based on leading practices in order to establish a consistent and effective cybersecurity profile that applies to all your networked endpoints at any location.
Cisco's Firepower NGFW Firewalls
Cisco's portfolio of Firepower Next-Generation Firewalls deliver advanced security and centralized management at prices, speed, and scale to fit deployments ranging from telecommuters and small organizations to major enterprises and Internet service providers. Cisco's Firepower NGFW appliances provide a significant performance improvement compared to Cisco's older firewalls and include centralized management of advanced cybersecurity features like application visibility and control (AVC), next-generation intrusion protection (NGIPS) with intelligent prioritization of risks, advanced malware protection, DDoS mitigation, and sandboxing.
All Firepower NGFW firewalls incorporate a one-pass architecture and support continuous analysis and retrospective detection, which makes it possible to provide outbreak controls and to pinpoint patient zero. Firepower Next-Generation firewalls also offer URL Filtering and sandboxing for finding elusive threats, IoCs, and malware artifacts. Next-Generation IPS rule tuning and network firewall policy creation can be automated, eliminating the need for time-consuming intervention by cybersecurity specialists. All Firepower Next-Generation firewalls give you the choice of running either Firepower Threat Defense or Adaptive Security Appliance (ASA) software. Centralized deployment, logging, monitoring, and reporting functions can be controlled either via Cisco's Management Center or in the cloud with Defense Orchestrator.
Cisco Firepower 1000 Series Next-Generation Firewalls
Cisco Firepower NGFW 1000 Series Firewalls are intended for small businesses, telecommuters, or branches. Appliances in this family offer improved price/performance vs. comparable Cisco ASA 5506-X to ASA 5525-X firewalls, providing 4-6X faster firewall speed. Local management can be done using Cisco Firepower Device Manager. These appliances include a built-in 10M/100M/1GBASE-T RJ-45 Ethernet interface for management, an RJ-45 console port, a USB 3.0 Type-A interface, and 200 Gbytes of storage. High availability is provided as well as VPN load balancing.
Cisco's Firepower 1010 firewall is a desktop, fanless device that offers 890 Mbps performance, AVC, and Next Generation Intrusion Prevention System. The unit features eight built-in RJ-45 I/O interfaces, two of them with POE+. IPsec VPN performance is 400 Mbps and the firewall supports 100K simultaneous sessions, 6,000 new connections/second, and a maximum of 75 VPN peers. The Firepower 1120 firewall is a 1RU appliance that provides firewall throughput of 2.3 Gbps. The firewall comes with eight RJ45 built-in I/O ports and four SFP ports. IPsec VPN throughput is 1.2 Gbps and the device allows 200K simultaneous sessions, 15,000 new connections per second with AVC, and up to 150 VPN peers.
The Firepower 1140 model firewall is a 1RU rackmount device that delivers firewall performance of 3.3 Gbps. The unit features 8 integrated RJ-45 interfaces and 4 SFP interfaces. IPsec VPN performance is 1.4 Gbps and the appliance allows 400K concurrent sessions, 22K new connections/second with AVC, and a maximum of 400 VPN peers. The Firepower 1150 firewall is a 1RU device that delivers firewall performance of 5.3 Gbps. The firewall includes 8 integrated RJ-45 ports, two SFP interfaces, and two 10G SFP+ interface ports. IPsec VPN performance is 2.4 Gbps and the unit can handle 600K concurrent sessions, 28,000 new connections per second, and a maximum of 800 VPN peers.
Cisco Firepower 2100 Series Next-Generation Firewalls
Cisco's Firepower 2100 Series NGFW Firewalls are 1RU units designed for operation at the data center. Appliances in this series feature a dual multicore processor design that enables them to offer 3-6X higher throughput than Cisco ASA models they are engineered to succeed. Local management can be done using Cisco Firepower Device Manager. All Firepower 2100 Series Next-Generation Firewalls incorporate 12 RJ45 interfaces and four SFP interfaces. These appliances include one integrated 10M/100M/1GBASE-T RJ-45 Ethernet port for network management, an RJ-45 console port, and one USB connection. High availability is supported as well as VPN load balancing.
Cisco's Firepower 2110 firewall features four integrated 1 Gb SFP Ethernet interfaces and 100 GB of storage. The 2110 offers 2.6 Gbps firewall performance and 800 Mbps IPsec VPN performance and allows 1 million concurrent sessions, 18,000 new connections/second, and as many as 1,500 VPN peers. Cisco's Firepower 2120 model firewall comes with 12 integrated 10M/100M/1GBASE-T RJ-45 interfaces, four built-in 1G SFP Ethernet ports, and 100 GB of storage. The 2120 delivers 3.4 Gbps firewall performance and 1 Gbps IPsec VPN performance and allows 1.5 million concurrent sessions, 28,000 new connections per second and up to 3,500 VPN peers.
Cisco's Firepower 2130 model firewall includes four integrated 10 Gigabit SFP+ ports and 200 GB of storage. The 2130 also accepts a network module with eight extra interface ports. The Firepower 2130 delivers 5.4 Gbps firewall performance and 1.9 Gbps IPsec VPN throughput and allows 2 million simultaneous sessions, 30,000 new connections per second, and a maximum of 7,500 VPN peers. Cisco's high-end Firepower 2140 firewall comes with four built-in 10G SFP+ interfaces and 200 GB of storage. The unit also accepts a network module with 8 extra interface ports for a total of 24 Ethernet interfaces. The 2140 offers 10.4 Gbps firewall performance and 3.6 1Gbps IPsec VPN throughput and allows three million concurrent, 57,000 new connections/second, and as many as 10,000 VPN peers. Both the 2130 and 2140 units feature dual AC or DC power supplies.
Cisco Secure Firewall 3100 Series
Cisco's 3100 Firewall Series models are modular one-rack devices intended for large companies who require performance, high port density, and zero-trust security at the Internet edge, the corporate data center, or a private cloud. For high uptime, all Secure Firewall 3100 Series appliances allow 8-chassis clustering and work in Active/active or Active/standby mode. The appliances can run Cisco's ASA or Firewall Threat Defense software. Integrated I/O for each device includes eight 10M/100M/1GBASE-T Ethernet interface ports (RJ-45) and 8 1/10 Gigabit Ethernet interfaces. Available network modules support 1/10/25/40G options and all models feature 900 GB of storage plus a spare storage expansion slot.
Cisco's Secure Firewall 3105 model offers 10 Gbps firewall performance and 5.5 Gbps IPsec VPN performance. The 3105 supports 1.5 million concurrent sessions, 90,000 new connections/second, and up to 2,000 VPN peers. Cisco's Secure Firewall 3110 model offers 10 Gbps firewall throughput and 8 Gbps IPsec VPN performance. The 3110 allows two million concurrent sessions, 130,000 new connections/second, and up to 3,000 VPN peers. Cisco's 3120 Firewall model offers 21 Gbps firewall throughput and 10 Gbps IPsec VPN performance. The 3120 allows 4 million simultaneous sessions, 170,000 new connections/second, and up to 7,000 VPN peers. Cisco's Secure Firewall 3130 device delivers 42 Gbps firewall throughput and up to 14 Gbps IPsec VPN throughput. The 3130 firewall supports 6 million concurrent sessions, 200K new connections per second, and up to 15,000 VPN peers. The 3130 firewall features eight 1/10/25G SFP+ interface ports. Cisco's 3140 Firewall appliance offers 49 Gbps firewall performance and up to 17 Gbps IPsec VPN performance. The 3140 allows 10 million concurrent sessions, 200K new connections/second, and a maximum of 20K VPN peers. The 3140 model features 8 1/10/25G SFP+ interface ports.
Cisco Firepower 4100 Series Next-Generation Firewalls
Cisco's Firepower 4100 Series NGFW Firewalls are one-rack appliances designed for use at high-performance data centers. Devices in this series deliver 5-10X higher throughput than the Cisco ASA 5585-X firewall they are designed to succeed. Local management can be done using Cisco Firepower Device Manager. All Firepower 4100 Series Next-Generation Firewalls have 8 built-in SFP+ ports and all can be expanded with a variety of plug-in network modules for a maximum of 24 interfaces. All Firepower 4100 Series Next-Generation Firewalls support VPN load balancing, high availability, and clustering of as many as six chassis. These security appliances feature a built-in 1 Gigabit Ethernet interface for network management, an RJ-45 console port, and one USB connection.
Cisco's Firepower 4110 firewall includes 200 GB of storage and delivers 13 Gbps firewall performance and 6 Gbps IPsec VPN performance. The 4110 model allows 10 million concurrent sessions, 64K new connections per second, and up to 10K VPN peers. Cisco's Firepower 4112 firewall includes 400 GB of storage and offers 19 Gbps firewall throughput and 8.5 Gbps IPsec VPN performance. The 4112 firewall supports 10 million simultaneous sessions, 98K new connections/second, and a maximum of 10,000 VPN peers. Cisco's Firepower 4115 device has 400 GB of storage and delivers 33 Gbps firewall throughput and 8 Gbps IPsec VPN performance. The 4115 unit supports 15 million simultaneous sessions, 210K new connections/second, and as many as 15,000 VPN peers. Cisco's Firepower 4120 model comes with 200 GB of storage and offers 22 Gbps firewall performance and 19 Gbps IPsec VPN performance. The 4120 firewall allows 15 million concurrent sessions, 118K new connections per second, and up to 15,000 VPN peers. Cisco's Firepower 4125 device comes with 800 GB of storage and delivers 45 Gbps firewall performance and 19 Gbps IPsec VPN throughput. The 4125 unit allows 25 million simultaneous sessions, 269K new connections per second, and up to 20K VPN peers.
The Firepower 4140 model firewall comes with 400 GB of storage and offers 32 Gbps firewall throughput and 13 Gbps IPsec VPN performance. The 4140 unit allows 25 million concurrent sessions, 172K new connections/second, and a maximum of 20K VPN peers. Cisco's newer Firepower 4145 model features 800 GB of storage and offers 53 Gbps firewall performance and 24 Gbps IPsec VPN throughput. The 4145 unit supports 30 million simultaneous sessions, 365K new connections per second, and up to 20K VPN peers. The Cisco Firepower 4150 firewall features 400 GB of storage and offers 45 Gbps firewall throughput and 14 Gbps IPsec VPN performance. The 4150 unit allows 30 million simultaneous sessions, 263K new connections per second, and a maximum of 20K VPN peers.
Secure Firewall 4200 Family
Cisco's Secure Firewall 4200 Series appliances are expandable single rack units designed for use at large enterprise campuses and data centers that require best-in-class throughput, manageability, and scalability. Secure Firewall 4200 Series appliances offer more than double the performance of prior generation firewalls from Cisco and feature high port density. As many as 8 chassis can be clustered for fault tolerance and future expansion. Crypto accelerator enables SSL and VPN decryption without performance loss, and zero trust application access (ZTAA) can provide comprehensive threat inspection for applications. 4200 Series appliances can be managed via the Firewall Management Center or in the cloud using Cisco Defense Orchestrator. Every 4200 device includes 8x 1/10/25 Gigabit Ethernet built-in ports and has two interface module bays for rapid expansion. Up to 24 Ethernet interfaces are supported. Every 4200 model comes with 1.8 TB x 2 storage.
Cisco's Secure Firewall 4215 model is built for enterprise campuses with strong growth potential. The device delivers 90 Gbps firewall performance and 45 Gbps IPsec VPN throughput. The Secure Firewall 4215 allows 15 million simultaneous firewall connections, 350 K new connections per second, and as many as 20,000 VPN peers. Cisco's Secure Firewall 4225 device is intended for large enterprise data centers. The device delivers 95 Gbps firewall performance and 80 Gbps IPsec VPN throughput. Cisco's 4225 model supports 30 million simultaneous firewall connections, 600 K new connections each second, and as many as 25,000 VPN peers. The Secure Firewall 4245 product is built for service providers who need to handle a very high volume of traffic. Cisco's 4245 offers 180 Gbps firewall performance and 140 Gbps IPsec VPN performance. The 4245 can support 60 million simultaneous firewall connections, 800 K new connections per second, and as many as 30,000 VPN peers.
Cisco Firepower 9300 Series Next-Generation Firewalls
Cisco's Firepower 9300 Series Next-Generation Firewalls are highly scalable and ultra-high performing firewalls. The 3RU chassis of Firepower 9300 Next-Generation Series firewalls can hold two add-in network modules as well as three security modules. Altogether, the 9300 can hold 24 10G Ethernet Enhanced Small Form-Factor Pluggable network interfaces or eight 100G connections. Clustering of up to five chassis allows up to 1.2 Tbps of firewall performance. The top-of-the-line Cisco Firepower 9300 SM-56 x 3 delivers 235 Gbps firewall throughput and 27 Gbps IPsec VPN performance. The unit allows 195 million simultaneous sessions, 4.75 M new connections per second, and a maximum of 20,000 VPN peers.
Cisco's Firepower Services
Cisco's Firepower Series security appliances accept either software or physical modules that support Firepower Services, which provide layered defense against advanced attacks. Cisco's Firepower Services are based on innovative technology acquired by Cisco from Sourcefire. Major capabilities of Firepower Services include:

Simpler implementations of Cisco's Firepower Series security appliances can be effectively administered using Cisco's on-box Adaptive Security Device Manager (ASDM) Adaptive Security Device Manager, a web tool provided with all NGFW firewall models. ASDM provides an easy-to-use web dashboard for deploying, managing, and troubleshooting NGFW appliances and service modules.
For multi-device and multi-site environments, NGFW firewalls with Firepower Services can be managed with Firepower Management Center, available as one or several physical or virtual appliances. Firepower Management Center offers unified firewall management, Application Visibility and Control (AVC, enhanced IPS, URL filtering, and Advanced Malware Protection (AMP). Due to ongoing rebranding after Cisco's purchase of Sourcefire Defense Center, Cisco's Firepower Management Center has been offered under several names that include Cisco Defense Center, Cisco Firesight Defense Center, and FireSIGHT Management Center.

Cisco's Firepower Management Center appliance provides capabilities unavailable with Cisco's on-box ASDM utility. Additional features include expanded context awareness, Advanced Malware Protection with remediation for client devices, a dashboard that offers real-time infrastructure visualization, automated policy optimization based on risk evaluation of attacks, comprehensive IPS, custom app detectors for Application Visibility and Control, customized health notifications, improved reporting options, and application interfaces for host input and database access. Hardware-dependent capabilities like clustering, stacking, switching, routing, VPN, and NAT must be managed using Cisco's on-device ASDM or the Firepower command line interface.
Progent's Migration Support Services for Cisco Next Generation Firewalls
Since Cisco has discontinued offering the PIX 500 and ASA 5500 product lines, many companies are uncomfortable with depending on a key infrastructure component that may no longer be supported by Cisco. Firepower Series security appliances offer the advantage of being current products and also bring multiple functions and financial benefits in comparison to legacy devices. These benefits include significantly higher throughput, optional Secure Sockets Layer tunneling capability, and a modular architecture that guards your investment by enabling you to add more security services whenever you need them. Progent's Cisco network engineers can assist your company to assess the strategic case for upgrading from PIX or ASA 5500 firewalls, create a migration plan that allows for a quick and seamless upgrade, assist your IT staff to install new Firepower Series firewalls, and provide online, consulting, and troubleshooting services.
Additional Ways Progent Can Support Your Cisco Firewalls
Cisco's Firepower NGFW Series security appliances provide a wealth of configuration, tracking, and troubleshooting options which offer you the flexibility to deploy these security appliances to match your company's requirements. Progent's CCIE authorized network professionals can show you how to build a cost-effective network infrastructure that incorporates Cisco firewalls and that provides advanced protection, resilience, throughput, and recoverability. Progent's GISA and CISM-certified IS security engineers can help you to create a security strategy appropriate for your situation and can set up your security appliance to enforce your security policies. Progent's security assessment professionals can evaluate the effectiveness of your current firewall deployment and help determine the security of your entire IT environment. Progent's Help Desk Call Center can deliver emergency online troubleshooting for Cisco products and offer fast access to a Cisco network engineer.
Progent offers remote or on-premises consulting services and is available for occasional expertise to help your organization resolve a stubborn IT impasse or Progent can provide end-to-end project management and co-management support to ensure your firewall initiative is performed on time and within budget.
For more information about Progent's consulting support for Cisco technology, choose a topic: