Cisco ASA 5508

Superior Multilayered Protectio
Cisco ASA with FirePOWER Services brings distinctive threat-focused next-generation security services to the Cisco ASA 5500-X Series Next-Generation Firewalls and Cisco ASA 5585-X Adaptive Security Appliance firewall products. It provides comprehensive protection from known and advanced threats, including protection against targeted and persistent malware attacks (Figure 1). Cisco ASA with FirePOWER Services features these comprehensive capabilities:
- Site-to-site and remote access VPN and advanced clustering provide highly secure, high-performance access and high availability to help ensure business continuity.
- Granular Application Visibility and Control (AVC) supports more than 3,000 application-layer and risk-based controls that can launch tailored intrusion prevention system (IPS) threat detection policies to optimize security effectiveness.
- The industry-leading Cisco ASA with FirePOWER next-generation IPS (NGIPS) provides highly effective threat prevention and full contextual awareness of users, infrastructure, applications, and content to detect multivector threats and automate defense response.
- Reputation- and category-based URL filtering offer comprehensive alerting and control over suspicious web traffic and enforce policies on hundreds of millions of URLs in more than 80 categories.
- AMP provides industry-leading breach detection effectiveness, a low total cost of ownership, and superior protection value that helps you discover, understand, and stop malware and emerging threats missed by other security layers.

Cisco ASA with FirePOWER Services
Unprecedented Network Visibility
Cisco ASA with FirePOWER Services is centrally managed by the Cisco FireSIGHT Management Center. Management Center provides security teams with comprehensive visibility into and control over activity within the network. Such visibility includes users, devices, communication between virtual machines, vulnerabilities, threats, client-side applications, files, and websites. Holistic, actionable indications of compromise (IoCs) correlate detailed network and endpoint event information and provide further visibility into malware infections.
Management Center also provides content awareness with malware file trajectory that aids infection scoping and root cause determination to speed time to remediation.
Cisco Security Manager provides scalable and centralized network operations workflow management. It integrates a powerful suite of capabilities; including policy and object management, event management, reporting, and troubleshooting for Cisco ASA firewall functions. For small-scale and simple deployments, the Cisco Adaptive Security Device Manager (ASDM) is available to provide on-device, GUI-based firewall network operations management.
Cisco’s enterprise-class management tools help administrators reduce complexity with unmatched visibility and control across NGFW deployments.

Cisco FireSIGHT Management Center:
Intuitive High-level and Detailed Drill-Down Dashboards
Reduced Costs and Complexity
Cisco ASA with FirePOWER Services incorporates an integrated approach to threat defense, reducing capital and operating costs and administrative complexity. It smoothly integrates with the existing IT environment, work stream, and network fabric. The purpose-built appliance family is highly scalable, performs at up to multigigabit speeds, and provides consistent and robust security across branch, Internet edge, and data centers in both physical and virtual environments.
With Cisco FireSIGHT Management Center, administrators can streamline operations to correlate threats, assess their impact, automatically tune security policy, and easily attribute user identities to security events. Management Center continually monitors how the network is changing over time. New threats are automatically assessed to determine which can affect your business. Response efforts are then focused on remediation, and network defenses are adapted to changing threat conditions. Critical security activities such as policy tuning are automated, saving time and effort, while protections and countermeasures are maintained in an optimal state.
Cisco FireSIGHT Management Center integrates easily with third-party security solutions through the eStreamer API to streamline operation workflows and fit existing network fabrics.
Technical Specifications:
Cisco ASA 5500-X Series Low-End Appliances with FirePOWER Services |
Maximum application control (AVC) throughput |
250 Mbps |
250 Mbps |
250 Mbps |
450 Mbps |
850 Mbps |
Maximum application control (AVC) and IPS throughput |
125 Mbps |
125 Mbps |
125 Mbps |
250 Mbps |
600 Mbps |
Maximum concurrent sessions |
20,000; 50000 |
20,000; 50000 |
50,000 |
100,000 |
250,000 |
Maximum New Connections per second |
5,000 |
5,000 |
5,000 |
10,000 |
20,000 |
Application control (AVC) or IPS sizing throughput [440 byte HTTP]* |
90 Mbps |
90 Mbps |
90 Mbps |
200 Mbps |
500 Mbps |
Supported applications |
More than 3,000 |
URL categories |
80+ |
Number of URLs categorized |
More than 280 million |
Centralized configuration, logging, monitoring, and reporting |
Multi-device Cisco Security Manager and Cisco FireSIGHT Management Center |
On-Device Management |
ASDM 7.3.x |
Cisco ASA 5500-X Series Next-Generation Firewalls Hardware |
Stateful inspection throughput (maximum1) |
750 Mbps |
750 Mbps |
750 Mbps |
1 Gbps |
1.8 Gbps |
Stateful inspection throughput (multiprotocol2) |
300 Mbps |
300 Mbps |
300 Mbps |
500 Mbps |
900 Mbps |
Triple Data Encryption Standard/Advanced Encryption Standard (3DES/AES) VPN throughput3 |
100 Mbps |
100 Mbps |
100 Mbps |
175 Mbps |
250 Mbps |
Users/nodes |
Unlimited |
Unlimited |
Unlimited |
Unlimited |
Unlimited |
IPsec VPN peers |
10; 504 |
10; 504 |
50 |
100 |
300 |
Cisco Cloud Web Security users |
275 |
275 |
275 |
565 |
2000 |
Cisco AnyConnect Premium/Apex VPN peers (included; maximum) |
2; 504 |
2; 504 |
50 |
100 |
300 |
Virtual interfaces (VLANs) |
5; 304 |
5; 304 |
30 |
50 |
100 |
Security contexts5 (included; maximum) |
N/A |
N/A |
N/A |
2; 5 |
2; 5 |
High availability4 |
Requires Security Plus License; Active/Standby |
Requires Security Plus License; Active/Standby |
Requires Security Plus License; Active/Standby |
Active/Active and Active/Standby |
Active/Active and Active/Standby |
Integrated Wireless Access Point |
N/A |
Wireless Bands a/b/g/n; Max n wifi throughput 54 Mbps; internal antenna only; local management or centralized via Cisco WLC |
N/A |
N/A |
N/A |
Expansion slot |
N/A |
N/A |
N/A |
N/A |
N/A |
User-accessible Flash slot |
No |
No |
No |
No |
No |
USB 2.0 ports |
USB port type ‘A’, High Speed 2.0 |
USB port type ‘A’, High Speed 2.0 |
USB port type ‘A’, High Speed 2.0 |
USB port type ‘A’, High Speed 2.0 |
USB port type ‘A’, High Speed 2.0 |
Integrated I/O |
8 x 1GE |
8 x 1GE |
4 x 1GE |
8 x 1GE |
8 x 1GE |
Expansion I/O |
N/A |
N/A |
N/A |
N/A |
N/A |
Dedicated management port |
Yes (To be shared with Firepower services), 10/100/1000 |
Yes (To be shared with FirePOWER Services), 10/100/1000 |
Yes (To be shared with FirePOWER Services), 10/100/1000 Base-T, 100Base-FX, 1000Base-X |
Yes (To be shared with FirePOWER Services), 10/100/1000 |
Yes (To be shared with FirePOWER Services), 10/100/1000 |
Serial ports |
1 RJ-45 and Mini USB console |
1 RJ-45 and Mini USB console |
1 RJ-45 and Mini USB console |
1 RJ-45 and Mini USB console |
1 RJ-45 and Mini USB console |
Solid-state drive |
50 GB mSata6 |
50 GB mSata6 |
50 GB mSata tested for heat |
80 GB mSata6 |
100 GB mSata6 |
Memory |
4 GB |
4 GB |
4 GB |
8 GB |
12 GB |
Minimum system flash |
8 GB |
4 GB |
8 GB |
8 GB |
8 GB |
System bus |
Multibus architecture |
Multibus architecture |
Multibus architecture |
Multibus architecture |
Multibus architecture |
Operating Temperature |
32 to 104°F (0 to 40 °C) |
Operating Relative Humidity |
90 percent noncondensing |
10 to 90 percent noncondensing |
Operating Altitude |
Designed and tested for 0 to 10,000 ft (3050 m) |
Acoustic noise |
Fanless 0 dBA |
Fanless 0 dBA |
Fanless 0 dBA |
41.6 A-weighted decibels (dBA) type 67.2 dBA max |
41.6 dBA type 67.2 dBA max |
Nonoperating Temperature |
-13 to 158ºF (-25 to 70ºC) |
-40 to 185ºF (-40 to 85ºC) |
-13 to 158ºF (-25 to 70ºC) |
Nonoperating Relative Humidity |
10 to 95 percent noncondensing |
10 to 95 percent noncondensing |
10 to 90 percent |
Nonoperating Altitude |
Designed and tested for 0 to 15,000 ft (4572 m) |
AC range line voltage |
External, 90 to 240 volts alternating current (VAC) |
AC normal line voltage |
90 to 240 VAC |
100 to 240 VAC |
100 to 240 VAC |
100 to 240 VAC |
100 to 240 VAC |
AC current |
N/A |
N/A |
N/A |
0.25AC amps |
0.25AC amps |
AC frequency |
50/60 Hz |
50/60 Hz |
50/60 Hz |
50/60 Hz |
50/60 Hz |
Dual-power supplies |
None |
None |
None |
None |
Yes |
DC domestic line voltage |
N/A |
N/A |
N/A |
N/A |
N/A |
DC international line voltage |
N/A |
N/A |
N/A |
N/A |
N/A |
DC current |
N/A |
N/A |
N/A |
N/A |
N/A |
Steady state |
12V @2.5A |
12V @2.5A |
5V @3.6A |
12V @ 3.0A |
12V @ 3.0A |
Maximum peak |
12V @ 5A |
12V @ 5A |
5V @4.4A |
12V @ 5.0A |
12V @ 5.0A |
Maximum heat dissipation |
103 Btu/hr |
103 Btu/hr |
103 Btu/hr |
123 Btu/hr |
123 Btu/hr |
Form Factor |
Desktop |
Desktop |
Desktop, rack mountable, wall mountable, DIN-Rail |
1 rack unit (RU), 19-in. rack-mountable |
Dimensions (H x W x D) |
7.871 x 9.23 x 1.72 in. (19.992 x 23.444 x 4.369 cm) |
9.05 x 9.05 x 2.72 in. (23.0 x 23.0 x 6.9 cm) |
17.2 x 11.288 x 1.72 in. (43.688 x 28.672 x 4.369 cm) |
Weight (with AC power supply) |
4 lb (1.82 kg) |
4 lb (1.82 kg) |
7 lb (3.18 kg) |
8 lb (3 kg) |
8 lb (3 kg) |
Safety |
UL 60950 CAN/CSA-C22.2 No. 60950 EN 60950 IEC 60950 AS/NZS 60950 |
UL 60951 CAN/CSA-C22.2 No. 60951 EN 60951 IEC 60951 AS/NZS 60951 |
UL 60950 CAN/CSA-C22.2 No. 60950 EN 60950 IEC 60950 AS/NZS 60950 |
UL 60952 CAN/CSA-C22.2 No. 60952 EN 60952 IEC 60952 AS/NZS 60952 |
UL 60953 CAN/CSA-C22.2 No. 60953 EN 60953 IEC 60953 AS/NZS 60953 |
Electromagnetic compatibility (EMC) |
47 CFR Part 15 CISPR22: Edition 6.0 CNS13438 EN 300 386 V1.6.1 EN 55022 EN61000-3-2 EN61000-3-3 ICES-003 Issue 5 QCVN 54: BTTTT TCVN 7189 VCCI: V-3 CISPR24 EN 300 386 V1.6.1 EN301 489-1 v1.9.2 EN301 489-17 v2.1.1 EN301 489-24 v1.5.1 EN301 489-4 V1.4.1 EN301 489-7 v1.3.1 EN55024 QCVN 18: BTTTT TCVN 7317 |