Cisco ASA 5500 Model Comparison
| Cisco ASA 5500 Series Model/License | Cisco ASA 5580-20
| Cisco ASA 5580-40
| Cisco ASA 5585-X with SSP-10
|
| Network Location |
Data Center, Campus |
Data Center, Campus |
Internet Edge, Campus |
| Performance Summary | |
| Firewall Throughput1 |
5 Gbps (real-world HTTP), 10 Gbps (max) |
10 Gbps (real-world HTTP), 20 Gbps (max) |
2 Gbps (multi-protocol), 4 Gbps (max) |
| Maximum Firewall Connections |
1,000,000 |
2,000,000 |
750,000 |
| Maximum Firewall Connections/Second |
90,000 |
150,000 |
50,000 |
| Packets per second (64 byte) |
2,500,000 |
4,000,000 |
1,500,000 |
| Maximum 3DES/AES VPN Throughput2 |
1 Gbps |
1 Gbps |
1 Gbps |
| Maximum Site-to-Site and Remote Access VPN Sessions |
10,000 |
10,000 |
5,000 |
| Maximum SSL VPN User Sessions |
10,000 |
10,000 |
5,000 |
| Bundled SSL VPN User Sessions |
2 |
2 |
2 |
| Technical Summary | |
| Memory |
8 GB |
12 GB |
6 GB (SSP-10) 12 GB (SSP-10 and IPS SSP-10) |
| Minimum System Flash |
1 GB |
1 GB |
2 GB |
| Integrated Ports |
2-10/100/1000 management +4-10/100/1000 (with ASA5580-4 GE-CU) +4 GE SR (with ASA5580-4 GE-FI) +2 10 GE SR (with ASA5580-2X10 GE-SR) |
2-10/100/1000 management +4-10/100/1000 (with ASA5580-4 GE-CU) +4 GE SR (with ASA5580-4 GE-FI) +2 10 GE SR (with ASA5580-2X10 GE-SR) |
8-10/100/1000, 2-10 GE SFP+ (with ASA5585-Sec-Pl license), 2-10/100/1000 management + 8-10/100/1000, 2-10 GE SFP+, 2-10/100/1000 management (with IPS SSP-10) |
| Maximum Virtual Interfaces (VLANs) |
250 |
250 |
250 |
| Expansion Capabilities | |
| SSP Expansion |
Not available |
Not available |
1- IPS SSP |
| SSP Supported |
Not available |
Not available |
IPS SSP-10 |
| Intrusion Prevention |
Not available |
Not available |
Yes (with IPS SSP) |
| Concurrent Threat Mitigation Throughput (Mbps) (Firewall + IPS Services) |
Not available |
Not available |
2 Gbps |
| Features | |
| Cisco Adaptive Security Appliance Software Version (latest) |
8.3 |
8.3 |
8.2.3 |
| Application-Layer Firewall Services |
Yes |
Yes |
Yes |
| Layer 2 Transparent Firewalling |
Yes |
Yes |
Yes |
| Security Contexts (included/maximum3) |
2/50 |
2/50 |
2/50 |
| GTP/GPRS Inspection3 |
Yes |
Yes |
Yes |
| High-Availability Support4 |
A/A and A/S |
A/A and A/S |
A/A and A/S |
| SSL and IPsec VPN Services |
Yes |
Yes |
Yes |
| VPN Clustering and Load Balancing |
Yes |
Yes |
Yes |
| Advanced Endpoint Assessment3 |
Yes |
Yes |
Yes |
|
1 Maximum throughput measured under ideal test conditions 2 VPN throughput and sessions count depend on the ASA device configuration and VPN traffic patterns. These elements should be taken in to consideration as part of your capacity planning. 3 Licensed features 4 A/S = Active/Standby; A/A = Active/Active
|
Cont..
| Cisco ASA 5500 Series Model/License | Cisco ASA 5585-X with SSP-20
| Cisco ASA 5585-X with SSP-40
| Cisco ASA 5585-X with SSP-60
|
| Network Location |
Data Center, Campus |
Data Center, Campus |
Data Center, Campus |
| Performance Summary | |
| Firewall Throughput1 |
5 Gbps (multi-protocol), 10 Gbps (max) |
10 Gbps (multi-protocol), 20 Gbps (max) |
20 Gbps (multi-protocol), 35 Gbps (max) |
| Maximum Firewall Connections |
1,000,000 |
2,000,000 |
2,000,000 |
| Maximum Firewall Connections/Second |
125,000 |
200,000 |
350,000 |
| Packets per second (64 byte) |
3,000,000 |
5,000,000 |
9,000,000 |
| Maximum 3DES/AES VPN Throughput2 |
2 Gbps |
3 Gbps |
5 Gbps |
| Maximum Site-to-Site and Remote Access VPN Sessions |
10,000 |
10,000 |
10,000 |
| Maximum SSL VPN User Sessions |
10,000 |
10,000 |
10,000 |
| Bundled SSL VPN User Sessions |
2 |
2 |
2 |
| Technical Summary | |
| Memory |
12 GB (SSP-20) 24 GB (SSP-20 and IPS SSP-20) |
12 GB (SSP-40) 36 GB (SSP-40 and IPS SSP-40) |
24 GB (SSP-60) 72 GB (SSP-60 and IPS SSP-60) |
| Minimum System Flash |
2 GB |
2 GB |
2 GB |
| Integrated Ports |
8-10/100/1000, 2-10 GE SFP+ (with ASA5585-Sec-Pl license), 2-10/100/1000 management + 8-10/100/1000, 2-10 GE SFP+, 2-10/100/1000 management (with IPS SSP-20) |
6-10/100/1000, 4-10 GE SFP+, 2-10/100/1000 management + 6-10/100/1000, 4-10 GE SFP+, 2-10/100/1000 management (with IPS SSP-40) |
6-10/100/1000, 4-10 GE SFP+, 2-10/100/1000 management + 6-10/100/1000, 4-10 GE SFP+, 2-10/100/1000 management (with IPS SSP-60) |
| Maximum Virtual Interfaces (VLANs) |
250 |
250 |
250 |
| Expansion Capabilities | |
| SSP Expansion |
1- IPS SSP |
1-IPS SSP |
1-IPS SSP |
| SSP Supported |
IPS SSP-20 |
IPS SSP-40 |
IPS SSP-60 |
| Intrusion Prevention |
Yes (with IPS SSP) |
Yes (with IPS SSP) |
Yes (with IPS SSP) |
| Concurrent Threat Mitigation Throughput (Mbps) (Firewall + IPS Services) |
3 Gbps |
5 Gbps |
10 Gbps |
| Features | |
| Cisco Adaptive Security Appliance Software Version (latest) |
8.2.3 |
8.2.3 |
8.2.3 |
| Application-Layer Firewall Services |
Yes |
Yes |
Yes |
| Layer 2 Transparent Firewalling |
Yes |
Yes |
Yes |
| Security Contexts (included/maximum3) |
2/50 |
2/50 |
2/50 |
| GTP/GPRS Inspection3 |
Yes |
Yes |
Yes |
| High-Availability Support4 |
A/A and A/S |
A/A and A/S |
A/A and A/S |
| SSL and IPsec VPN Services |
Yes |
Yes |
Yes |
| VPN Clustering and Load Balancing |
Yes |
Yes |
Yes |
| Advanced Endpoint Assessment3 |
Yes |
Yes |
Yes |
|
1 Maximum throughput measured under ideal test conditions 2 VPN throughput and sessions count depend on the ASA device configuration and VPN traffic patterns. These elements should be taken in to consideration as part of your capacity planning. 3 Licensed features 4 A/S = Active/Standby; A/A = Active/Active
|
|