Features | 1010 | 1120 | 1140 |
Throughput: Firewall (FW) + Application Visibility and Control
(AVC) (1024B) | 650 Mbps | 1.5 Gbps | 2.2 Gbps |
Throughput: FW + AVC + Intrusion Prevention System (IPS) (1024B) | 650 Mbps | 1.5 Gbps | 2.2 Gbps |
Maximum concurrent sessions, with AVC | 100K | 200K | 400K |
Maximum new connections per second, with AVC | 6K | 15K | 22K |
Transport Layer Security (TLS) | 150 Mbps | 700 Mbps | 1 Gbps |
Throughput: NGIPS (1024B) | 650 Mbps | 1.5 Gbps | 2.2 Gbps |
IPSec VPN throughput (1024B TCP w/Fastpath) | 300 Mbps | 1 Gbps | 1.2 Gbps |
Maximum VPN Peers | 75 | 150 | 400 |
Cisco Firepower Device Manager (local management) | Yes | Yes | Yes |
Centralized management | Centralized configuration, logging, monitoring, and reporting are
performed by the Management Center or alternatively in the cloud
with Cisco Defense Orchestrator |
AVC | Standard, supporting more than 4000 applications, as well as
geolocations, users, and websites |
AVC: OpenAppID support for custom, open-source application
detectors | Standard |
Cisco Security Intelligence | Standard, with IP, URL, and DNS threat intelligence |
Cisco Firepower NGIPS | Available; can passively detect endpoints and infrastructure for
threat correlation and Indicators of Compromise (IoC) intelligence |
Cisco Advanced Malware Protection (AMP) for Networks | Available; enables detection, blocking, tracking, analysis, and
containment of targeted and persistent malware, addressing the
attack continuum both during and after attacks. Integrated threat
correlation with Cisco AMP for Endpoints is also optionally
available. |
Cisco AMP Threat Grid sandboxing | Available |
URL filtering: number of categories | More than 80 |
URL filtering: number of URLs categorized | More than 280 million |
Automated threat feed and IPS signature updates | Yes: class-leading Collective Security Intelligence (CSI) from the
Cisco Talos® group |
Third-party and open-source ecosystem | Open API for integrations with third-party products; Snort® and
OpenAppID community resources for new and specific threats |
High availability and clustering | Active/standby |
Cisco Trust Anchor Technologies | Cisco Firepower 1000 Series platforms include Trust Anchor
Technologies for supply chain and software image assurance. Please
see the section below for additional details. |
NOTE: Performance will vary depending on features activated, and
network traffic protocol mix, and packet size characteristics.
Performance is subject to change with new software releases.
Consult your Cisco representative for detailed sizing guidance. |