Cisco is a perennial leader in developing state-of-the-art firewall appliances for the widest possible range of environments. Cisco's Firepower Next Generation Firewall (NGFW) security appliances provide an advanced cybersecurity solution that combines dedicated hardware, cloud services, and machine learning to block, discover, and mitigate threats automatically. Progent's Cisco-certified CCIE firewall consultants can help your organization to plan and execute an efficient upgrade to Cisco Firepower Series firewalls from Cisco's legacy ASA 5500-X, ASA 5500, or PIX firewalls and help you integrate Firepower appliances with Cisco's security services to create and centrally manage network ecosystems that encompass local offices, data centers, private clouds and public clouds. Progent can also help you to maintain and debug legacy Cisco firewalls. Progent's certified network security consultants can help you with policy creation and tuning driven by leading practices in order to establish a consistent and effective cybersecurity profile that applies to all your endpoints anywhere.
Cisco's Firepower NGFW Firewalls
Cisco's line of Firepower Next-Generation Firewalls deliver advanced security and centralized control at prices, speed, and expandability suitable for deployments spanning home offices and small businesses to global enterprises and service providers. Cisco's Firepower NGFW appliances deliver a major performance boost compared to Cisco's previous-generation security appliances and offer centralized management and automation of modern cybersecurity capabilities such as application visibility and control (AVC), next-generation intrusion protection with intelligent prioritization of risks, advanced malware protection, URL filtering, and sandboxing.
All Firepower NGFW firewalls incorporate a single-pass design and permit continuous inspection and retrospective detection, which makes it possible to initiate outbreak controls and to pinpoint root causes. Firepower NGFW firewalls also have the option of URL Filtering and subscription-free sandboxing for detecting evasive and sandbox-aware malware, actionable event correlations, and malware artifacts. Next-Generation IPS rule tuning and network firewall policy creation are automated, eliminating the need for time-consuming intervention by IT security experts. All Firepower NGFW firewalls offer the choice of running either Firepower Threat Defense or Cisco Adaptive Security Appliance software. Centralized configuration, logging, monitoring, and reporting functions can be managed either via Management Center or in the cloud with Defense Orchestrator.
Cisco Firepower 1000 Series NGFW Firewalls
Firepower Next-Generation 1000 Series Firewalls are targeted at small businesses, telecommuters, or branches. Firewalls in this family offer improved price/performance vs. comparable Cisco ASA 5506-X to ASA 5525-X firewalls, delivering 4-6X higher firewall speed. Local management can be done with Cisco Firepower Device Manager. These appliances feature a built-in 10/100/1000 RJ-45 Ethernet port for network management, an RJ-45 console port, a USB interface, and 200 Gbytes of storage. High availability is supported as well as virtual private network load balancing.
Cisco's Firepower 1010 model is a desktop, fanless appliance that delivers 890 Mbps throughput, AVC, and NGIPS. The appliance has 8 built-in RJ-45 I/O interfaces, two of them with POE+. IPsec VPN performance is 500 Mbps and the appliance allows 100K concurrent sessions, 6,000 new connections/second, and a maximum of 75 VPN peers. The Firepower 1120 firewall is a 1RU device that delivers firewall throughput of 2.3 Gbps. The firewall includes 8 RJ45 built-in I/O interfaces and four SFP interfaces. IPsec VPN performance is 1.2 Gbps and the unit allows 200K concurrent sessions, 15,000 new connections/second with Application Visibility/Control, and up to 150 VPN peers.
The Firepower 1140 firewall is a 1RU rackmount appliance that delivers firewall throughput of 3.3 Gbps. The appliance comes with 8 built-in RJ-45 ports and 4 SFP interfaces. IPsec VPN performance is 1.4 Gbps and the firewall allows 400K concurrent sessions, 22K new connections/second with AVC, and a maximum of 400 VPN peers. The Firepower 1150 firewall is a 1RU appliance that offers firewall performance of 5.3 Gbps. The firewall comes with eight integrated RJ-45 interface ports, two SFP ports, and two 10G SFP+ ports. IPsec VPN performance is 2.4 Gbps and the unit can handle 600K concurrent sessions, 28,000 new connections/second, and up to 800 VPN peers.
Cisco Firepower 2100 Series NGFW Firewalls
Cisco's Firepower 2100 Series NGFW Firewalls are single-rack appliances intended for operation at the data center. Firewalls in this family have a dual multicore processor design that allows them to offer 3-6X higher throughput than Cisco ASA models they are engineered to replace. Onsite management can be performed using Firepower Device Manager. All Firepower 2100 Series NGFW Firewalls include 12 RJ45 ports and four SFP ports. These appliances include one build-in 10M/100M/1GBASE-T Ethernet port for network management, an RJ-45 console interface, and one USB 2.0 Type-A connection. Active/standby high availability is supported along with VPN load balancing.
The Firepower 2110 firewall comes with four integrated 1 Gigabit SFP Ethernet interfaces and 100 GB of storage. The 2110 offers 2.6 Gbps firewall performance and 800 Mbps IPsec VPN performance and supports 1 million simultaneous sessions, 18,000 new connections per second, and a maximum of 1,500 VPN peers. Cisco's Firepower 2120 model firewall has 12 integrated 10M/100M/1GBASE-T Ethernet RJ-45 ports, four built-in 1G SFP Ethernet interfaces, and 100 GB of storage. The 2120 offers 3.4 Gbps firewall performance and 1 Gbps IPsec VPN throughput and allows 1.5 million concurrent sessions, 28,000 new connections/second and as many as 3,500 VPN peers.
Cisco's Firepower 2130 firewall features four built-in 10 Gigabit SFP+ interfaces and 200 GB of storage. The unit also scales via a network module with 8 additional interface ports. The Firepower 2130 offers 5.4 Gbps firewall throughput and 1.9 Gbps IPsec VPN performance and supports two million concurrent sessions, 30,000 new connections per second, and a maximum of 7,500 VPN peers. Cisco's high-end Firepower 2140 model firewall comes with 4 integrated 10G SFP+ ports and 200 GB of storage. The 2140 also accepts a network module with eight additional ports for a total of 24 Ethernet interface ports. The 2140 model delivers 10.4 Gbps firewall performance and 3.6 1Gbps IPsec VPN throughput and supports three million simultaneous, 57,000 new connections per second, and up to 10,000 VPN peers. Both the 2130 and 2140 units have the option of dual AC or DC power supplies.
Cisco 3100 Firewall Series
Cisco's Secure Firewall 3100 Series appliances are modular 1RU devices intended for large companies who require performance, high port count, and zero-trust cybersecurity at the Internet edge, the data center, or a private cloud. For high availability, all Secure Firewall 3100 Series appliances support 8-chassis clustering and work in Active/active or Active/standby mode. The devices can run Cisco's ASA or Firewall Threat Defense software. Integrated I/O for each model includes eight 10M/100M/1GBASE-T interface ports (RJ-45) and 8 1/10 Gigabit Ethernet interfaces. Available network modules offer 1/10/25/40G options and all versions have 900 GB of storage as well as an additional storage expansion slot.
Cisco's Secure Firewall 3110 device delivers 18 Gbps firewall performance and 8 Gbps IPsec VPN performance. The 3110 supports two million concurrent sessions, 64,000 new connections/second, and as many as 3,000 VPN peers. Cisco's 3120 Firewall model offers 22 Gbps firewall throughput and up to 10 Gbps IPsec VPN throughput. The 3120 allows 4 million concurrent sessions, 98K new connections per second, and a maximum of 7,000 VPN peers. Cisco's Secure Firewall 3130 device offers 42 Gbps firewall throughput and up to 14 Gbps IPsec VPN performance. The 3130 supports 6 million concurrent sessions, 200K new connections per second, and as many as 15,000 VPN peers. Cisco's Secure Firewall 3140 device delivers 49 Gbps firewall performance and 17 Gbps IPsec VPN throughput. The 3140 allows 10 million concurrent sessions, 200K new connections/second, and a maximum of 20K VPN peers.
Cisco Firepower 4100 Series Next-Generation Firewalls
Cisco's Firepower 4100 Series Next-Generation Firewalls are 1RU rack units designed for use at the Internet edge. Appliances in this series offer 5-10X faster performance than the Cisco ASA 5585-X device they are designed to replace. Onsite management can be performed using Cisco Firepower Device Manager. All Firepower 4100 Series NGFW Firewalls include 8 integrated SFP+ interfaces and all accept a variety of add-in network modules for a maximum of 24 interfaces. All Firepower 4100 Series NGFW Firewalls support VPN load balancing, high availability, and clustering of as many as six chassis. These security appliances feature a built-in 1 Gigabit Ethernet port for network management, one RJ-45 console interface, and one USB 2.0 interface.
Cisco's Firepower 4110 firewall includes 200 GB of storage and delivers 13 Gbps firewall throughput and 6 Gbps IPsec VPN performance. The 4110 model supports 10 million simultaneous sessions, 64K new connections per second, and a maximum of 10K VPN peers. Cisco's Firepower 4112 firewall has 400 GB of storage and delivers 19 Gbps firewall performance and 8.5 Gbps IPsec VPN throughput. The 4112 firewall supports 10 million concurrent sessions, 98K new connections per second, and as many as 10,000 VPN peers. Cisco's more recent Firepower 4115 model firewall features 400 GB of storage and offers 27 Gbps firewall performance and 8 Gbps IPsec VPN performance. The 4115 unit allows 15 million simultaneous sessions, 200K new connections/second, and a maximum of 15,000 VPN peers. Cisco's Firepower 4120 model has 200 GB of storage and offers 22 Gbps firewall performance and 19 Gbps IPsec VPN throughput. The 4120 firewall allows 15 million simultaneous sessions, 118K new connections per second, and up to 15,000 VPN peers. Cisco's newer Firepower 4125 firewall comes with 800 GB of storage and offers 40 Gbps firewall throughput and 14 Gbps IPsec VPN throughput. The 4125 unit supports 25 million simultaneous sessions, 265K new connections/second, and up to 20K VPN peers.
The Firepower 4140 model firewall includes 400 GB of storage and delivers 32 Gbps firewall performance and 13 Gbps IPsec VPN throughput. The 4140 firewall allows 25 million concurrent sessions, 172K new connections/second, and up to 20K VPN peers. Cisco's newer Firepower 4145 model features 800 GB of storage and delivers 53 Gbps firewall performance and 18 Gbps IPsec VPN throughput. The 4145 firewall allows 30 million simultaneous sessions, 350K new connections per second, and a maximum of 20K VPN peers. Cisco's Firepower 4150 firewall has 400 GB of storage and offers 45 Gbps firewall performance and 14 Gbps IPsec VPN throughput. The 4150 firewall supports 30 million concurrent sessions, 263K new connections per second, and a maximum of 20K VPN peers.
Cisco Secure Firewall 4200 Family
Cisco's Secure Firewall 4200 Series appliances are expandable 1RU firewalls designed for deployment at enterprise campuses and data centers that need best-in-class throughput, manageability, and scalability. Secure Firewall 4200 Series devices deliver more than double the throughput of prior generation firewalls from Cisco and offer high port density. As many as 8 units can be clustered for fault tolerance and future expansion. Crypto accelerator enables SSL and VPN decryption without performance loss, and zero trust application access (ZTAA) can provide deep threat inspection for applications. 4200 Series firewalls can be managed locally via the Firewall Management Center or in the cloud using Cisco Defense Orchestrator. Each 4200 model comes with 8x 1/10/25 Gigabit Ethernet built-in ports and has two interface module slots for rapid expansion. Up to 24 Ethernet interfaces are supported. Each firewall model includes 1.8 TB x 2 storage.
Cisco's Secure Firewall 4215 product is designed for large enterprise campuses with high growth potential. The device delivers 90 Gbps firewall throughput and 50 Gbps max IPsec VPN throughput. The 4215 supports 15 million concurrent firewall connections, 1.4 M new connections each second, and as many as 20,000 VPN peers. The Secure Firewall 4225 product is designed for enterprise data centers. The device offers 95 Gbps firewall performance and 60 Gbps max IPsec VPN throughput. Cisco's 4225 model supports 30 million simultaneous firewall connections, 1.7 M new connections per second, and up to 25,000 VPN peers. The Secure Firewall 4245 product is designed for service providers who need to handle a very high volume of traffic. Cisco's 4245 offers 180 Gbps firewall throughput and 70 Gbps IPsec VPN throughput. The 4245 can support 60 million simultaneous firewall connections, 2.0 M new connections each second, and as many as 30,000 VPN peers.
Cisco Firepower 9300 Series Next-Generation Firewalls
Cisco's Firepower 9300 Series NGFW Firewalls are highly scalable and carrier-grade security appliances. The 3 Rack Units (3RU) chassis of Firepower 9300 Next-Generation Series firewalls accepts two network modules and three security modules. Fully loaded, the 9300 can hold 24 10-Gigabit SFP+ ports or eight 100G connections. Intrachassis clustering of up to 5 chassis delivers up to 1.2 Tbps of firewall throughput. The top-of-the-line Cisco Firepower 9300 SM-56 provides 70 Gbps firewall throughput and 27 Gbps IPsec VPN performance. The unit allows 35 million simultaneous sessions, 490K new connections per second, and a maximum of 20,000 VPN peers.
Cisco's Firepower Services
Firepower NGFW security appliances accept either software or hardware modules that enable Cisco's Firepower Services, which provide layered defense against sophisticated attacks. Firepower Services are powered by technology adopted by Cisco from Sourcefire. Major features of Firepower Services include:
Simpler implementations of Firepower Next Generation security appliances can be efficiently administered using Cisco's on-box Adaptive Security Device Manager (ASDM) Adaptive Security Device Manager, a web-based utility which is provided with all NGFW firewall versions. ASDM provides a simple web dashboard for deploying, managing, and troubleshooting Firepower devices and service modules.
For multi-device and multi-site deployments, NGFW firewalls with Firepower Services can be administered with Cisco's Firepower Management Center, available as one or several physical units or virtual devices. Firepower Management Center provides centralized firewall management, Application Visibility and Control, enhanced IPS, URL filtering, and Advanced Malware Protection. Because of frequent rebranding after Cisco's purchase of Sourcefire Defense Center, Cisco's Firepower Management Center has been delivered under several names that include Cisco Defense Center, Cisco Firesight Defense Center, and Cisco Firesight Management Center.
Firepower Management Center appliance offers features unavailable with Cisco's on-device ASDM tool. Additional capabilities include expanded context awareness, Advanced Malware Protection with mitigation for user devices, a dashboard that provides real-time network visualization, automated policy tuning driven by impact evaluation of attacks, comprehensive IPS, custom application discovery for Application Visibility and Control (AVC), customized health alerts, enhanced reporting features, and APIs for host input and databases. Hardware-dependent capabilities such as clustering, stacking, switching, routing, VPN, and NAT must be handled using Cisco's on-box ASDM or the Firepower CLI.
Progent's Migration Consulting Services for Cisco Firepower Firewalls
Since Cisco has ceased offering the PIX and ASA 5500 product lines, many businesses are concerned about relying on a critical infrastructure component that might stop being supported by Cisco. Firepower NGFW Series firewalls offer the advantage of being new products and also bring important functions and budgetary benefits in comparison to legacy firewalls. These advantages include substantially better throughput, optional SSL VPN support, and an expandable design that protects your investment by allowing you to add more security features when and if you require them. Progent's Cisco network engineers can help your company to determine the business value of for upgrading from PIX or ASA 5500 firewalls, create a migration plan that permits a quick and non-disruptive upgrade, help your IT staff to set up new Firepower NGFW Series appliances, and provide online, consulting, and troubleshooting services.
Additional Ways Progent Can Support Your Cisco Firewalls
Cisco Firepower NGFW Series firewalls incorporate a wealth of configuration, monitoring, and analysis options that give you the ability to set up these firewalls to match your business requirements. Progent's CCIE certified network consultants can help you to build a cost-effective infrastructure that includes Cisco security appliances and that provides world-class security, fault tolerance, performance, and manageability. Progent's CISA and CISM-certified information security consultants can help your business to develop a security policy that makes sense for your business and can configure your security appliance to support your security policies. Progent's risk assessment experts can evaluate the effectiveness of your current firewall solution and help determine the overall security of your whole IT network. Progent's Help Desk support team can deliver emergency online troubleshooting for Cisco technology and can give you fast access to a Cisco CCIE expert.
Progent offers remote or on-premises support and can deliver occasional expertise to help your organization resolve a challenging technical impasse or Progent offers comprehensive project management and co-management services to ensure your firewall initiative is performed on time and within budget.
To find out additional information concerning Progent's consulting support for Cisco technology, pick a subject: