Cisco is a long-time leader in delivering cutting-edge firewall appliances for the broadest possible range of deployments. Cisco's Firepower Next Generation Firewall (NGFW) security appliances provide an advanced firewall platform that combines dedicated hardware, cloud-based services, and machine learning to anticipate, discover, and respond to cyberthreats without manual intervention. Progent's Cisco-certified CCIE-certified firewall consultants can assist you to plan and carry out a smooth migration to Firepower Series firewalls from Cisco's from ASA 5500-X, ASA 5500, or PIX appliances and show you how to enhance Firepower appliances with Cisco's subscription-based security services to create and centrally control network environments that span branch offices, data centers, private clouds and public clouds. Progent can also assist you to maintain and debug legacy Cisco firewalls. Progent's certified cybersecurity consultants can help you with policy creation and tuning based on leading practices so you can establish a consistent and effective security profile across all your devices at any location.

Cisco's Firepower NGFW Firewalls
Cisco's line of Firepower Next-Generation Firewalls offer advanced security and centralized management at prices, performance levels, and scale to fit environments ranging from home offices and small businesses to global enterprises and Internet service providers. Cisco's Firepower NGFW appliances deliver a significant performance improvement compared to Cisco's older firewalls and include centralized management of modern cybersecurity features such as application visibility, next-generation intrusion protection (NGIPS) with risk prioritization, advanced malware protection (AMP), DDoS mitigation, and multi-node sandboxing.

All Firepower Next-Generation firewalls have a single-pass architecture and permit continuous analysis and retrospective detection, which makes it possible to initiate outbreak controls and to uncover patient zero. Firepower NGFW firewalls also have the option of URL Filtering and sandboxing for finding evasive and sandbox-aware threats, behavioral indicators of compromise, and malware artifacts. NGIPS rule tuning and firewall policy are automated, requiring no manual intervention by cybersecurity specialists. All Firepower NGFW security appliances give you the option of using either Cisco Firepower Threat Defense (FTD) or Adaptive Security Appliance (ASA) software. Unified deployment, logging, monitoring, and reporting capabilities can be controlled either by Management Center or in the cloud with Cisco Defense Orchestrator.

Cisco Firepower 1000 Series NGFW Firewalls
Cisco Firepower Next-Generation 1000 Series Firewalls ExpertsCisco Firepower Next-Generation 1000 Series Firewalls are intended for small businesses, home offices, or branches. Firewalls in this series deliver improved price/performance vs. comparable Cisco ASA 5506-X to ASA 5525-X models, providing 4-6X higher firewall speed. Local management can be performed using Firepower Device Manager. These firewalls feature a built-in 10/100/1000 Ethernet interface for management, an RJ-45 console port, a USB interface, and 200 Gbytes of storage. Active/active and Active/standby high availability is supported as well as virtual private network load balancing.

Cisco's Firepower 1010 model is a desktop or wall-mount, quiet appliance that offers 890 Mbps performance, Application Visibility/Control, and Next Generation Intrusion Prevention System. The unit has 8 built-in RJ-45 I/O interfaces, two of them POE+ capable. IPsec VPN performance is 400 Mbps and the firewall supports 100K simultaneous sessions, 6,000 new connections/second, and up to 75 VPN peers. The Firepower 1120 firewall is a 1RU rack device that provides firewall throughput of 2.3 Gbps. The unit includes 8 RJ45 integrated I/O ports and four SFP interface ports. IPsec VPN throughput is 1.2 Gbps and the unit allows 200K concurrent sessions, 15,000 new connections/second with AVC, and up to 150 VPN peers.

The Firepower 1140 model firewall is a 1RU rackmount device that delivers firewall performance of 3.3 Gbps. The unit includes 8 built-in RJ-45 interface ports and 4 SFP interfaces. IPsec VPN performance is 1.4 Gbps and the appliance supports 400K simultaneous sessions, 22K new connections/second with AVC, and up to 400 VPN peers. The Firepower 1150 model firewall is a 1RU rackmount appliance that delivers firewall throughput of 5.3 Gbps. The appliance has 8 integrated RJ-45 ports, two SFP interface ports, and two 10G SFP+ interface ports. IPsec VPN throughput is 2.4 Gbps and the appliance allows 600K concurrent sessions, 28,000 new connections per second, and a maximum of 800 VPN peers.

Cisco Firepower 2100 Series Next-Generation Firewalls
Cisco Firepower 2100 Series Next-Generation Firewalls ConsultantsCisco's Firepower 2100 Series Next-Generation Firewalls are 1RU rack appliances intended for operation at the Internet edge. Appliances in this line feature a dual multicore CPU architecture that allows them to offer 3-6X faster throughput than Cisco ASA 5545-X to ASA 5555-X models they are designed to succeed. Local management can be done using Cisco Firepower Device Manager. All Firepower 2100 Series NGFW Firewalls include 12 RJ45 ports and four SFP ports. These appliances include one build-in 10M/100M/1GBASE-T Ethernet interface for network management, an RJ-45 console interface, and one USB port. Active/standby high availability is supported along with virtual private network load balancing.

Cisco's Firepower 2110 model firewall comes with four integrated 1 Gigabit SFP Ethernet ports and 100 GB of storage. The 2110 delivers 2.6 Gbps firewall performance and 800 Mbps IPsec VPN throughput and allows 1 million concurrent sessions, 18,000 new connections per second, and as many as 1,500 VPN peers. Cisco's Firepower 2120 model firewall comes with 12 built-in 10M/100M/1GBASE-T Ethernet RJ-45 interface ports, four built-in 1G SFP Ethernet interface ports, and 100 GB of storage. The 2120 delivers 3.4 Gbps firewall performance and 1 Gbps IPsec VPN throughput and permits 1.5 million simultaneous sessions, 28,000 new connections/second and as many as 3,500 VPN peers.

Cisco's Firepower 2130 firewall includes 4 integrated 10 G SFP+ interfaces and 200 GB of storage. The unit also scales via a network module with eight additional interface ports. The Firepower 2130 delivers 5.4 Gbps firewall throughput and 1.9 Gbps IPsec VPN throughput and allows 2 million concurrent sessions, 30,000 new connections/second, and a maximum of 7,500 VPN peers. Cisco's top-of-the-line Firepower 2140 model firewall features 4 integrated 10 Gigabit SFP+ interface ports and 200 GB of storage. The 2140 also accepts a network module with 8 extra ports for a maximum of 24 Ethernet ports. The 2140 delivers 10.4 Gbps firewall throughput and 3.6 1Gbps IPsec VPN throughput and allows 3 million simultaneous, 57,000 new connections/second, and a maximum of 10,000 VPN peers. Both the 2130 and 2140 units feature redundant AC or DC power supplies.

Cisco 3100 Firewall Series
Cisco Secure Firewall 3100 Series ConsultantsCisco's Secure Firewall 3100 Series models are modular 1RU rack devices targeted at large companies who need performance, high port density, and zero-trust security at the Internet edge, the corporate data center, or a private cloud. For high uptime, all Secure Firewall 3100 Series models allow 8-device clustering and work in either Active/active or Active/standby mode. The units can run Cisco's ASA or Firewall Threat Defense (FTD) software. Integrated I/O for each model includes eight 10M/100M/1GBASE-T ports (RJ-45) and eight 1/10 Gigabit (SFP) Ethernet ports. Available network modules support 1/10/25/40G options and all versions include 900 GB of storage as well as an additional storage expansion slot.

Cisco's 3105 Firewall device offers 10 Gbps firewall throughput and 5.5 Gbps IPsec VPN throughput. The 3105 supports 1.5 million concurrent sessions, 90,000 new connections per second, and a maximum of 2,000 VPN peers. Cisco's 3110 Firewall device delivers 10 Gbps firewall performance and 8 Gbps IPsec VPN throughput. The 3110 allows two million concurrent sessions, 130,000 new connections per second, and as many as 3,000 VPN peers. Cisco's 3120 Firewall model offers 21 Gbps firewall throughput and 10 Gbps IPsec VPN performance. The 3120 supports 4 million simultaneous sessions, 170,000 new connections per second, and a maximum of 7,000 VPN peers. Cisco's Secure Firewall 3130 model delivers 42 Gbps firewall throughput and 14 Gbps IPsec VPN performance. The 3130 firewall allows 6 million concurrent sessions, 200K new connections/second, and up to 15,000 VPN peers. The 3130 firewall has 8 1/10/25G SFP+ interface ports. Cisco's Secure Firewall 3140 appliance offers 49 Gbps firewall throughput and up to 17 Gbps IPsec VPN performance. The 3140 firewall allows 10 million simultaneous sessions, 200K new connections/second, and a maximum of 20K VPN peers. The 3140 firewall has 8 1/10/25G SFP+ ports.

Cisco Firepower 4100 Series NGFW Firewalls
Cisco Firepower 4100 Series NGFW Firewalls ConsultingCisco's Firepower 4100 Series NGFW Firewalls are one-rack units intended for deployment at high-performance data centers. Appliances in this line offer 5-10X faster performance than the Cisco ASA 5585-X device they are designed to succeed. Local management can be done using Cisco Firepower Device Manager. All Firepower 4100 Series NGFW Firewalls include 8 integrated SFP+ ports and all can be expanded with a selection of add-in network modules for a maximum of 24 interfaces. All Firepower 4100 Series Next-Generation Firewalls offer VPN load balancing, Active/Standby high availability, and clustering of up to six chassis. These security appliances feature an integrated 1 Gigabit Ethernet port for network management, one RJ-45 console port, and one USB connection.

Cisco's Firepower 4110 firewall features 200 GB of storage and offers 13 Gbps firewall throughput and 6 Gbps IPsec VPN performance. The 4110 supports 10 million concurrent sessions, 64K new connections per second, and a maximum of 10K VPN peers. Cisco's Firepower 4112 firewall has 400 GB of storage and delivers 19 Gbps firewall throughput and 8.5 Gbps IPsec VPN throughput. The 4112 appliance allows 10 million simultaneous sessions, 98K new connections/second, and a maximum of 10,000 VPN peers. Cisco's Firepower 4115 model firewall includes 400 GB of storage and offers 33 Gbps firewall throughput and 8 Gbps IPsec VPN throughput. The 4115 unit supports 15 million concurrent sessions, 210K new connections/second, and as many as 15,000 VPN peers. Cisco's Firepower 4120 device has 200 GB of storage and delivers 22 Gbps firewall throughput and 19 Gbps IPsec VPN throughput. The 4120 unit allows 15 million concurrent sessions, 118K new connections/second, and as many as 15,000 VPN peers. Cisco's Firepower 4125 appliance includes 800 GB of storage and delivers 45 Gbps firewall throughput and 19 Gbps IPsec VPN performance. The 4125 firewall allows 25 million concurrent sessions, 269K new connections/second, and up to 20K VPN peers.

The Firepower 4140 firewall includes 400 GB of storage and offers 32 Gbps firewall performance and 13 Gbps IPsec VPN throughput. The 4140 firewall allows 25 million concurrent sessions, 172K new connections per second, and up to 20K VPN peers. Cisco's more recent Firepower 4145 appliance includes 800 GB of storage and offers 53 Gbps firewall throughput and 24 Gbps IPsec VPN performance. The 4145 unit allows 30 million concurrent sessions, 365K new connections per second, and up to 20K VPN peers. The Cisco Firepower 4150 unit has 400 GB of storage and offers 45 Gbps firewall throughput and 14 Gbps IPsec VPN throughput. The 4150 unit supports 30 million concurrent sessions, 263K new connections/second, and up to 20K VPN peers.

Cisco Secure Firewall 4200 Family
Cisco Secure Firewall 4200 ExpertsCisco's Secure Firewall 4200 appliances are modular single rack units designed for use at large enterprise campuses and data centers that need best-in-class throughput, manageability, and scale. Secure Firewall 4200 Series devices deliver over twice the throughput of previous generation firewalls and offer high port density. As many as 8 chassis can be clustered for fault tolerance and future expansion. Crypto accelerator allows SSL and VPN decryption without performance loss, and zero trust application access (ZTAA) can provide comprehensive threat inspection for applications. 4200 Series firewalls can be managed by the Firewall Management Center or in the cloud using Cisco Defense Orchestrator. Every 4200 device comes with 8x 1/10/25 Gigabit Ethernet on-chassis interfaces and features two module slots for rapid expansion. Up to 24 Ethernet connections are supported. Every 4200 unit includes 1.8 TB x 2 storage.

Cisco's Secure Firewall 4215 model is designed for large enterprise campuses with high growth expectations. The 4215 offers 90 Gbps firewall throughput and 45 Gbps IPsec VPN performance. The Secure Firewall 4215 supports 15 million simultaneous firewall connections, 350 K new connections each second, and as many as 20,000 VPN peers. The Secure Firewall 4225 appliance is designed for large enterprise data centers. The appliance offers 95 Gbps firewall throughput and 80 Gbps max IPsec VPN throughput. The 4225 model allows 30 million simultaneous firewall connections, 600 K new connections each second, and up to 25,000 VPN peers. The Secure Firewall 4245 model is designed for service providers who support a high volume of traffic. Cisco's 4245 delivers 180 Gbps firewall throughput and 140 Gbps IPsec VPN throughput. The 4245 allows 60 million simultaneous firewall connections, 800 K new connections per second, and up to 30,000 VPN peers.

Cisco Firepower 9300 Series NGFW Firewalls
Cisco Firepower 9300 Series NGFW Firewalls ConsultantsCisco's Firepower 9300 Series Next-Generation Firewalls are highly scalable and ultra-high performing security appliances. The 3 Rack Units enclosure of Firepower 9300 NGFW Series firewalls can hold two network modules and three security modules. Fully loaded, the Firepower 9300 can hold 24 10-Gigabit SFP+ network interfaces or eight 100 Gigabit Ethernet interfaces. Clustering of up to 5 9300 chassis delivers a total 1.2 Tbps of firewall throughput. The high-end Cisco Firepower 9300 SM-56 x 3 delivers 235 Gbps firewall performance and 27 Gbps IPsec VPN throughput. The unit allows 195 million simultaneous sessions, 4.75 M new connections per second, and a maximum of 20,000 VPN peers.

Firepower Services
Firepower NGFW security appliances accept software or hardware modules that support Cisco's Firepower Services, which provide layered defense against multi-vector attacks. Firepower Services are powered by innovative technology acquired by Cisco from Sourcefire. Major features of Firepower Services include:

  • Layered defense against both familiar and new threats
  • Advanced Malware Protection (AMP) that uses big data techniques to find and mitigate intrusions
  • Cisco's Next-Generation Intrusion Prevention System (NGIPS) that performs contextual analysis that covers clients, network infrastructure, software applications, and content to detect threats that use multiple approaches
  • Fine-grained Application Visibility and Control (AVC that is aware of thousands of apps and can automatically launch both standard and customized IPS policies depending on the degree of threats
Cisco Firepower Integration Expertise

Firepower Services for NGFW firewalls offer advanced multi-layered security

Simpler deployments of Firepower Series firewalls can be effectively managed using Cisco's on-device Adaptive Security Device Manager (ASDM) Adaptive Security Device Manager, a web utility included with all NGFW firewall versions. ASDM includes a simple web console for configuring, administering, and debugging Firepower appliances and modules.

For more complex environments, Cisco's Next Gerneration appliances with Firepower Services can be managed using Firepower Management Center, available as one or more physical or virtual devices. Cisco's Firepower Management Center provides centralized firewall management, Application Visibility and Control (AVC, advanced IPS, URL filtering, and Cisco's Advanced Malware Protection. Due to ongoing rebranding after Cisco's purchase of Sourcefire Defense Center, Firepower Management Center has been delivered under various names including Defense Center, Cisco Firesight Defense Center, and Cisco Firesight Management Center.

Cisco Firepower Management Center Experts

Firepower Management Center centralizes event and policy control for Firepower firewalls

Firepower Management Center appliance offers features unavailable with Cisco's on-box Adaptive Security Device Manager utility. Additional features include greater context awareness, Cisco's Advanced Malware Protection (AMP) with mitigation for user devices, a console that provides real-time infrastructure visualization, automated policy tuning based on risk evaluation of threats, comprehensive IPS, custom app detectors for Application Visibility and Control, customized health alerts, improved reporting features, and APIs for host input and database access. Hardware-dependent features like clustering, stacking, switching, routing, VPN, and NAT must be handled using either the on-box ASDM or the Firepower command line interface.

Progent's Migration Consulting Support for Cisco Next Generation Firewalls
Since Cisco has discontinued offering the PIX and ASA 5500 product lines, many businesses are concerned about depending on a key infrastructure mechanism that may stop being supported. Firepower NGFW Series security appliances offer the benefit of being new products and also bring important technical and budgetary benefits in comparison to legacy devices. These benefits include significantly better throughput, optional Secure Sockets Layer VPN support, and a modular design that protects your investment by allowing you to self-install new security features whenever you need them. Progent's Cisco certified network engineers can assist your company to assess the business case for upgrading from PIX or ASA 5500 security appliances, design a migration process that allows for a quick and non-disruptive changeover, assist you to install new Firepower NGFW Series firewalls, and offer online, consulting, and technical support services.

Other Ways Progent Can Support Your Cisco Firewalls
Cisco Firepower Series firewalls provide an array of setup, tracking, and troubleshooting features which offer you the flexibility to deploy these firewalls to match your business requirements. Progent's CCIE authorized network experts can show you how to design an efficient network infrastructure that includes Cisco firewall technology and that provides world-class security, resilience, performance, and recoverability. Progent's GISA and CISSP-ISSP-certified IS security professionals can help you to create a security strategy that makes sense for your business and can set up your firewall to enforce your security strategy. Progent's security assessment professionals can evaluate the effectiveness of your current firewall solution and help determine the overall security of your entire IS environment. Progent's Help Desk Call Center can deliver emergency online technical support for Cisco products and can give you fast access to a Cisco expert.

Progent can provide remote or on-premises support and is available for as-needed guidance to help your organization with a stubborn IT bottleneck or Progent offers comprehensive project management support to ensure your firewall initiative is completed on time and within budget.

For more details concerning Progent's professional support for Cisco networking products, choose a subject:

Contact Progent for Cisco Firewall Solutions
To ask Progent about consulting help with Cisco Firepower NGFW firewalls, call 1-800-993-9400 or visit Contact Progent.



An index of content::







  • © 2002-2026 Progent Corporation. All rights reserved.