Cisco is a perennial front-runner in delivering cutting-edge firewalls for the widest possible variety of environments. Cisco's Firepower Next Generation Firewall (NGFW) appliances provide a modern cybersecurity solution that marshals dedicated hardware, cloud services, and next-generation intrusion protection system (NGIPS) to block, discover, and mitigate cyber attacks automatically. Progent's Cisco-certified CCIE-certified firewall experts can assist you to plan and execute an efficient upgrade to Cisco Firepower Series firewalls from Cisco's legacy ASA 5500-X, ASA 5500, or PIX appliances and show you how to enhance Firepower appliances with Cisco's subscription-based security services to create and centrally control network environments that span local offices, data centers, private clouds and public clouds. Progent's firewall consultants can also help you to maintain and debug legacy Cisco firewalls. Progent's certified network security experts can help you with policy creation based on leading practices so you can establish a consistent and effective security posture across all your endpoints anywhere.
Cisco's Firepower Next Generation Firewalls
Cisco's family of Firepower Next-Generation Firewalls offer modern protection and unified control at prices, performance levels, and scale to fit environments ranging from telecommuters and small businesses to major enterprises and Internet service providers. Cisco's Firepower NGFW appliances provide a major performance improvement over Cisco's older security appliances and offer unified control of modern cybersecurity features such as application visibility, next-generation intrusion protection (NGIPS) with risk prioritization, advanced malware protection, DDoS mitigation, and multi-node sandboxing.
All Firepower NGFW firewalls have a one-pass design and support continuous analysis and retrospective detection, which makes it possible to provide outbreak management and to pinpoint root causes. Firepower NGFW firewalls also have the option of URL Filtering and subscription-free sandboxing for finding elusive threats, behavioral indicators of compromise, and malware artifacts. Next-Generation IPS rule tuning and firewall policy are automated, requiring no manual intervention by cybersecurity specialists. All Firepower NGFW firewalls give you the choice of using either Cisco Firepower Threat Defense (FTD) or Adaptive Security Appliance (ASA) software. Unified deployment, logging, monitoring, and reporting functions can be controlled either by Management Center or in the cloud with Defense Orchestrator.
Cisco Firepower 1000 Series Next-Generation Firewalls
Cisco Firepower Next-Generation 1000 Series Firewalls are targeted at small organizations, telecommuters, or branch offices. Devices in this series deliver improved price/performance vs. comparable Cisco ASA 5506-X to ASA 5525-X firewalls, delivering 4-6X faster firewall speed. Onsite management can be done with Firepower Device Manager. 1000 Series firewalls feature a built-in 10M/100M/1GBASE-T Ethernet port for network management, an RJ-45 console port, a USB 3.0 Type-A interface, and 200 Gbytes of storage. High availability is supported as well as VPN load balancing.
Cisco's Firepower 1010 firewall is a desktop or wall-mount, fanless appliance that offers 890 Mbps throughput, AVC, and NGIPS. The unit features eight integrated RJ-45 I/O interfaces, two of them POE+ capable. IPsec VPN throughput is 400 Mbps and the firewall supports 100K simultaneous sessions, 6,000 new connections/second, and up to 75 VPN peers. The Firepower 1120 firewall is a 1RU appliance that delivers firewall performance of 2.3 Gbps. The firewall includes eight RJ45 built-in I/O interfaces and four SFP interfaces. IPsec VPN throughput is 1.2 Gbps and the device supports 200K concurrent sessions, 15,000 new connections per second with Application Visibility/Control (AVC), and a maximum of 150 VPN peers.
The Firepower 1140 model firewall is a 1RU device that delivers firewall throughput of 3.3 Gbps. The unit features 8 integrated RJ-45 interface ports and four SFP interfaces. IPsec VPN throughput is 1.4 Gbps and the firewall supports 400K simultaneous sessions, 22K new connections/second with Application Visibility/Control, and up to 400 VPN peers. The Firepower 1150 model firewall is a 1RU device that offers firewall performance of 5.3 Gbps. The unit has eight built-in RJ-45 interface ports, two SFP interface ports, and two 10G SFP+ interface ports. IPsec VPN throughput is 2.4 Gbps and the unit allows 600K concurrent sessions, 28,000 new connections per second, and up to 800 VPN peers.
Cisco Firepower 2100 Series NGFW Firewalls
Cisco's Firepower 2100 Series Next-Generation Firewalls are single-rack appliances intended for deployment at the data center. Devices in this line feature a dual multicore CPU design that enables them to offer 3-6X faster throughput than Cisco ASA 5545-X to ASA 5555-X models they are designed to succeed. Onsite management can be done using Firepower Device Manager. All Firepower 2100 Series NGFW Firewalls incorporate 12 RJ45 ports and four SFP interfaces. These firewalls include one integrated 10M/100M/1GBASE-T RJ-45 Ethernet interface for management, an RJ-45 console interface, and one USB 2.0 Type-A interface. Active/standby high availability is supported along with VPN load balancing.
Cisco's Firepower 2110 firewall has 4 built-in 1 Gigabit SFP Ethernet ports and 100 GB of storage. The 2110 delivers 2.6 Gbps firewall performance and 800 Mbps IPsec VPN performance and supports 1 million simultaneous sessions, 18,000 new connections per second, and as many as 1,500 VPN peers. Cisco's Firepower 2120 model firewall comes with 12 built-in 10M/100M/1GBASE-T Ethernet RJ-45 interfaces, four built-in 1G SFP Ethernet interfaces, and 100 GB of storage. The 2120 delivers 3.4 Gbps firewall throughput and 1 Gbps IPsec VPN throughput and allows 1.5 million concurrent sessions, 28,000 new connections/second and a maximum of 3,500 VPN peers.
Cisco's Firepower 2130 firewall comes with 4 built-in 10 Gigabit SFP+ ports and 200 GB of storage. The unit also accepts a network module with eight additional interface ports. The Firepower 2130 offers 5.4 Gbps firewall performance and 1.9 Gbps IPsec VPN throughput and supports two million concurrent sessions, 30,000 new connections per second, and a maximum of 7,500 VPN peers. Cisco's top-of-the-line Firepower 2140 model firewall has four integrated 10 Gigabit SFP+ ports and 200 GB of storage. The 2140 also scales via a network module with eight additional interface ports for a maximum of 24 Ethernet interface ports. The 2140 offers 10.4 Gbps firewall throughput and 3.6 1Gbps IPsec VPN throughput and allows 3 million simultaneous, 57,000 new connections per second, and as many as 10,000 VPN peers. Both the 2130 and 2140 appliances have the option of dual AC or DC power supplies.
Cisco 3100 Firewall Series
Cisco's Secure Firewall 3100 Series appliances are modular 1RU rack units designed for enterprises who require throughput, high port density, and zero-trust cybersecurity at the Internet edge, the data center, or a private cloud. For maximum availability, all Secure Firewall 3100 Series appliances support 8-device clustering and work in either Active/active or Active/standby mode. The devices can run Cisco's ASA or Firewall Threat Defense (FTD) software. Built-in I/O for each model includes eight 10M/100M/1GBASE-T interfaces (RJ-45) and 8 1/10 Gigabit (SFP) Ethernet interface ports. Plug-in network modules offer 1/10/25/40G options and all versions feature 900 GB of storage as well as an additional storage expansion slot.
Cisco's Secure Firewall 3105 device offers 10 Gbps firewall performance and 5.5 Gbps IPsec VPN performance. The 3105 allows 1.5 million concurrent sessions, 90,000 new connections/second, and up to 2,000 VPN peers. Cisco's 3110 Firewall model delivers 10 Gbps firewall throughput and 8 Gbps IPsec VPN throughput. The 3110 supports two million concurrent sessions, 130,000 new connections/second, and up to 3,000 VPN peers. Cisco's 3120 Firewall model delivers 21 Gbps firewall throughput and up to 10 Gbps IPsec VPN throughput. The 3120 firewall supports 4 million simultaneous sessions, 170,000 new connections/second, and a maximum of 7,000 VPN peers. Cisco's Secure Firewall 3130 device offers 42 Gbps firewall throughput and 14 Gbps IPsec VPN performance. The 3130 firewall allows 6 million simultaneous sessions, 200K new connections per second, and up to 15,000 VPN peers. The 3130 firewall includes 8 1/10/25G SFP+ interface ports. Cisco's 3140 Firewall appliance offers 49 Gbps firewall throughput and 17 Gbps IPsec VPN throughput. The 3140 supports 10 million concurrent sessions, 200K new connections per second, and as many as 20K VPN peers. The 3140 has eight 1/10/25G SFP+ interface ports.
Cisco Firepower 4100 Series NGFW Firewalls
Cisco's Firepower 4100 Series Next-Generation Firewalls are 1RU units designed for operation at high-performance data centers. Devices in this line offer 5-10X faster performance than the Cisco ASA 5585-X device they are designed to replace. Onsite management can be performed using Firepower Device Manager. All Firepower 4100 Series Next-Generation Firewalls have 8 integrated SFP+ ports and all can be expanded with a variety of add-in network modules for up to 24 ports. All Firepower 4100 Series NGFW Firewalls offer VPN load balancing, Active/Standby high availability, and clustering of as many as six chassis. These security appliances include an integrated 1Gb Ethernet interface for management, one RJ-45 console interface, and one USB connection.
Cisco's Firepower 4110 firewall has 200 GB of storage and delivers 13 Gbps firewall performance and 6 Gbps IPsec VPN performance. The 4110 allows 10 million concurrent sessions, 64K new connections per second, and as many as 10K VPN peers. Cisco's Firepower 4112 firewall includes 400 GB of storage and offers 19 Gbps firewall performance and 8.5 Gbps IPsec VPN throughput. The 4112 firewall supports 10 million simultaneous sessions, 98K new connections per second, and as many as 10,000 VPN peers. Cisco's Firepower 4115 appliance comes with 400 GB of storage and delivers 33 Gbps firewall throughput and 8 Gbps IPsec VPN performance. The 4115 unit supports 15 million simultaneous sessions, 210K new connections/second, and up to 15,000 VPN peers. Cisco's Firepower 4120 model features 200 GB of storage and delivers 22 Gbps firewall throughput and 19 Gbps IPsec VPN performance. The 4120 unit allows 15 million simultaneous sessions, 118K new connections per second, and up to 15,000 VPN peers. Cisco's Firepower 4125 device features 800 GB of storage and offers 45 Gbps firewall throughput and 19 Gbps IPsec VPN throughput. The 4125 firewall allows 25 million simultaneous sessions, 269K new connections/second, and up to 20K VPN peers.
The Firepower 4140 model firewall features 400 GB of storage and offers 32 Gbps firewall throughput and 13 Gbps IPsec VPN throughput. The 4140 unit allows 25 million simultaneous sessions, 172K new connections per second, and as many as 20K VPN peers. Cisco's more recent Firepower 4145 firewall comes with 800 GB of storage and offers 53 Gbps firewall throughput and 24 Gbps IPsec VPN throughput. The 4145 unit supports 30 million simultaneous sessions, 365K new connections per second, and up to 20K VPN peers. The Cisco Firepower 4150 unit includes 400 GB of storage and offers 45 Gbps firewall throughput and 14 Gbps IPsec VPN performance. The 4150 unit supports 30 million concurrent sessions, 263K new connections/second, and up to 20K VPN peers.
Cisco Secure Firewall 4200 Series
Cisco's Secure Firewall 4200 appliances are expandable 1RU firewalls intended for use at enterprise campuses and data centers that require best-in-class performance, manageability, and scale. Cisco's Secure Firewall 4200 Series devices deliver more than double the performance of previous generation firewalls from Cisco and feature high port density. Up to 8 units can be clustered for fault tolerance and future expansion. Crypto accelerator allows SSL and VPN decryption without performance loss, and zero trust application access can provide deep threat inspection for applications. 4200 Series appliances can be managed locally by the Firewall Management Center or in the cloud using Cisco Defense Orchestrator. Every 4200 firewall includes 8x 1/10/25 Gigabit Ethernet integrated ports and features two interface module bays for rapid expansion. Up to 24 total Ethernet connections are possible. Every 4200 device includes 1.8 TB x 2 storage.
Cisco's Secure Firewall 4215 model is designed for enterprise campuses with strong growth expectations. The 4215 offers 90 Gbps firewall throughput and 45 Gbps IPsec VPN throughput. The Secure Firewall 4215 supports 15 million simultaneous firewall connections, 350 K new connections each second, and as many as 20,000 VPN peers. The Secure Firewall 4225 product is intended for enterprise data centers. The model delivers 95 Gbps firewall performance and 80 Gbps max IPsec VPN performance. The 4225 model can handle 30 million concurrent firewall connections, 600 K new connections each second, and up to 25,000 VPN peers. Cisco's Secure Firewall 4245 model is designed for service providers who support a high volume of traffic. The 4245 delivers 180 Gbps firewall performance and 140 Gbps IPsec VPN throughput. The 4245 allows 60 million simultaneous firewall connections, 800 K new connections per second, and up to 30,000 VPN peers.
Cisco Firepower 9300 Series Next-Generation Firewalls
Cisco's Firepower 9300 Series Next-Generation Firewalls are highly scalable and carrier-grade security appliances. The 3 Rack Units chassis of Firepower 9300 NGFW Series firewalls can hold two network modules and three security modules. Altogether, the 9300 can support 24 10G SFP+ network interfaces or eight 100G ports. Clustering of up to five 9300 chassis allows a total 1.2 Tbps of firewall throughput. The top-of-the-line Cisco Firepower 9300 SM-56 x 3 provides 235 Gbps firewall performance and 27 Gbps IPsec VPN performance. The 9300 SM-56 allows 195 million simultaneous sessions, 4.75 M new connections per second, and a maximum of 20,000 VPN peers.
Firepower Services
Firepower Series security appliances accept either software or hardware modules that enable Cisco's Firepower Services, which offer layered defense against sophisticated attacks. Cisco's Firepower Services are powered by innovative technology adopted by Cisco from Sourcefire. Major capabilities of Firepower Services include:
Simpler deployments of Firepower Next Generation firewalls can be efficiently administered via Cisco's on-device Adaptive Security Device Manager (ASDM) Adaptive Security Device Manager, a web-based utility provided with all firewall versions. ASDM includes a convenient web console for configuring, administering, and troubleshooting NGFW appliances and modules.
For more complex deployments, Cisco's Next Gerneration appliances with Firepower Services can be administered with Firepower Management Center, implemented as one or several physical units or virtual devices. Cisco's Firepower Management Center provides unified firewall management, Application Visibility and Control, enhanced IPS, URL filtering, and Cisco's Advanced Malware Protection. Because of frequent rebranding after Cisco's purchase of Sourcefire Defense Center, Firepower Management Center has been offered under several names including Defense Center, FireSIGHT Defense Center, and FireSIGHT Management Center.
Firepower Management Center appliance offers capabilities unavailable with Cisco's on-device Adaptive Security Device Manager tool. Additional capabilities include greater context awareness, Advanced Malware Protection with remediation for user devices, a console that provides dynamic network infrastructure visualization, automated policy tuning driven by impact assessment of attacks, advanced IPS, custom application detectors for Application Visibility and Control (AVC), customized health notifications, improved reporting options, and application interfaces for host input and databases. Hardware-dependent options such as clustering, stacking, switching, routing, VPN, and NAT must be managed via Cisco's on-box ASDM or the Firepower command line interface.
Progent's Migration Consulting Services for Cisco Next Generation Firewalls
Because Cisco has stopped selling the PIX 500 and ASA 5500 families of firewalls, many companies are uncomfortable with relying on a critical infrastructure mechanism that may stop being supported by Cisco. Firepower NGFW Series security appliances have the benefit of being current products and also offer important technical and economic advantages in comparison to legacy firewalls. These benefits include substantially better performance, optional Secure Sockets Layer tunneling capability, and an expandable design that guards your investment by allowing you to add new security features when and if you need them. Progent's Cisco network engineers can assist you to assess the strategic case for moving from PIX 500 or Cisco ASA 5500 firewalls, design a migration plan that allows for a quick and seamless upgrade, assist your IT staff to install new Firepower Series appliances, and offer remote training, consulting, and troubleshooting services.
Other Ways Progent Can Support Your Cisco Firewalls
Cisco Firepower NGFW Series firewalls incorporate an array of configuration, tracking, and analysis options which give you the ability to set up these security appliances to match your business needs. Progent's CCIE authorized network professionals can help you to design an efficient infrastructure that includes Cisco security appliances and that offers advanced protection, resilience, throughput, and manageability. Progent's CISA and CISSP-ISSP-premier information security consultants can help your business to create a security policy that makes sense for your environment and can set up your security appliance to enforce your security policies. Progent's risk assessment engineers can assess the effectiveness of your current firewall solution and help determine the security of your whole information system environment. Progent's Help Desk support team can provide urgent online troubleshooting for Cisco technology and offer fast access to a Cisco CCIE expert.
Progent can provide online or onsite consulting services and is available for as-needed expertise to help your organization with a challenging IT bottleneck or Progent offers end-to-end project management and co-management support to ensure your firewall initiative is performed on time and within budget.
To learn additional information about Progent's consulting expertise for Cisco solutions, select a topic: