ASA 5500 Series

http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/product_data_sheet0900aecd802930c5.html

Table 1. Cisco ASA 5505 Adaptive Security Appliance Platform Capabilities and Capacities

Feature

Description

Firewall Throughput

Up to 150 Mbps

Maximum Firewall and IPS Throughput

Up to 75 Mbps with AIP SSC-5

VPN Throughput

Up to 100 Mbps

Concurrent Sessions

10,000/25,000*

IPsec VPN Peers

10; 25*

Premium AnyConnect VPN Peer License Levels**

2, 10, or 25

Interfaces

8-port Fast Ethernet switch with dynamic port grouping (including 2 PoE ports)

Virtual Interfaces (VLANs)

3 (no trunking support)/20 (with trunking support)*

High Availability

Not supported; stateless Active/Standby and redundant ISP support*

* Upgrade available with Cisco ASA 5505 Security Plus license

** Separately licensed feature; includes two with the base system

Performance numbers tested and validated with Cisco ASA Software Release 7.2.

Cisco ASA 5510 Adaptive Security Appliance

The Cisco ASA 5510 Adaptive Security Appliance delivers advanced security and networking services for small and medium-sized businesses and enterprise remote/branch offices in an easy-to-deploy, cost-effective appliance. These services can be easily managed and monitored by the integrated Cisco ASDM application, thus reducing the overall deployment and operations costs associated with providing this high level of security. The Cisco ASA 5510 Adaptive Security Appliance provides high-performance firewall and VPN services and five integrated 10/100 Fast Ethernet interfaces. It optionally provides high-performance intrusion prevention and worm mitigation services through the AIP SSM, or comprehensive malware protection services through the CSC SSM. This unique combination of services on a single platform makes the Cisco ASA 5510 an excellent choice for businesses requiring a cost-effective, extensible, DMZ-enabled security solution.

As business needs grow, customers can install a Security Plus license, upgrading two of the Cisco ASA 5510 Adaptive Security Appliance interfaces to Gigabit Ethernet and enabling integration into switched network environments through VLAN support. This upgrade license maximizes business continuity by enabling Active/Active and Active/Standby high-availability services. Using the optional security context capabilities of the Cisco ASA 5510 Adaptive Security Appliance, businesses can deploy up to five virtual firewalls within an appliance to enable compartmentalized control of security policies on a departmental level. This virtualization strengthens security and reduces overall management and support costs while consolidating multiple security devices into a single appliance.

Businesses can extend their SSL and IPsec VPN capacity to support a larger number of mobile workers, remote sites, and business partners. Up to 250 AnyConnect and/or clientless VPN peers can be supported on each Cisco ASA 5510 by installing an Essential or a Premium AnyConnect VPN license; up to 250 IPsec VPN peers are supported on the base platform.

VPN capacity and resiliency can also be increased by taking advantage of the Cisco ASA 5510's integrated VPN clustering and load-balancing capabilities (available with a Security Plus license). The Cisco ASA 5510 supports up to 10 appliances in a cluster, offering a maximum of 2500 AnyConnect and/or clientless VPN peers or 2500 IPsec VPN peers per cluster. For business continuity and event planning, the Cisco ASA 5510 can also benefit from the Cisco VPN FLEX licenses, which enable administrators to react to or plan for short-term bursts of concurrent Premium VPN remote-access users, for up to a 2-month period.

Table 2 lists features of the Cisco ASA 5510.

Table 2. Cisco ASA 5510 Adaptive Security Appliance Platform Capabilities and Capacities

Feature

Description

Firewall Throughput

Up to 300 Mbps

Maximum Firewall and IPS Throughput

• Up to 150 Mbps with AIP SSM-10
• Up to 300 Mbps with AIP SSM-20

VPN Throughput

Up to 170 Mbps

Concurrent Sessions

50,000; 130,000*

IPsec VPN Peers

250

Premium AnyConnect VPN Peer License Levels**

2,10, 25, 50, 100, or 250

Security Contexts

Up to 5***

Interfaces*

5 Fast Ethernet ports; 2 Gigabit Ethernet + 3 Fast Ethernet*

Virtual Interfaces (VLANs)

50; 100*

Scalability*

VPN clustering and load balancing

High Availability

Not supported; Active/Active****, Active/Standby*

* Upgrade available with Cisco ASA 5510 Security Plus license

** Separately licensed feature; includes two with the base system

*** Separately licensed feature; includes two with the Cisco ASA 5510 Security Plus license

**** Available for the firewall feature set

Performance numbers tested and validated with Cisco ASA Software Release 7.2.

Cisco ASA 5520 Adaptive Security Appliance

The Cisco ASA 5520 Adaptive Security Appliance delivers security services with Active/Active high availability and Gigabit Ethernet connectivity for medium-sized enterprise networks in a modular, high-performance appliance. With four Gigabit Ethernet interfaces and support for up to 100 VLANs, businesses can easily deploy the Cisco ASA 5520 into multiple zones within their network. The Cisco ASA 5520 Adaptive Security Appliance scales with businesses as their network security requirements grow, delivering solid investment protection.

Businesses can extend their SSL and IPsec VPN capacity to support a larger number of mobile workers, remote sites, and business partners. Up to 750 AnyConnect and/or clientless VPN peers can be supported on each Cisco ASA 5520 by installing an Essential or a Premium AnyConnect VPN license; 750 IPsec VPN peers are supported on the base platform. VPN capacity and resiliency can be increased by taking advantage of the Cisco ASA 5520's integrated VPN clustering and load-balancing capabilities. The Cisco ASA 5520 supports up to 10 appliances in a cluster, offering a maximum of 7500 AnyConnect and/or clientless VPN peers or 7500 IPsec VPN peers per cluster. For business continuity and event planning, the Cisco ASA 5520 can also benefit from the Cisco VPN FLEX licenses, which enable administrators to react to or plan for short-term bursts of concurrent Premium VPN remote-access users, for up to a 2-month period.

The advanced application-layer security and content security defenses provided by the Cisco ASA 5520 can be extended by deploying the high-performance intrusion prevention and worm mitigation capabilities of the AIP SSM, or the comprehensive malware protection of the CSC SSM. Using the optional security context capabilities of the Cisco ASA 5520 Adaptive Security Appliance, businesses can deploy up to 20 virtual firewalls within an appliance to enable compartmentalized control of security policies on a departmental level. This virtualization strengthens security and reduces overall management and support costs while consolidating multiple security devices into a single appliance.

Table 3 lists features of the Cisco ASA 5520.

Table 3. Cisco ASA 5520 Adaptive Security Appliance Platform Capabilities and Capacities

Feature

Description

Firewall Throughput

Up to 450 Mbps

Maximum Firewall and IPS Throughput

• Up to 225 Mbps with AIP SSM-10
• Up to 375 Mbps with AIP SSM-20
• Up to 450 Mbps with AIP SSM-40

VPN Throughput

Up to 225 Mbps

Concurrent Sessions

280,000

IPsec VPN Peers

750

Premium AnyConnect VPN Peer License Levels*

2,10, 25, 50, 100, 250, 500, or 750

Security Contexts*

Up to 20

Interfaces

4 Gigabit Ethernet ports and 1 Fast Ethernet port

Virtual Interfaces (VLANs)

150

Scalability

VPN clustering and load balancing

High Availability

Active/Active**, Active/Standby

* Separately licensed feature; includes two with base system

** Available for the firewall feature set

Performance numbers tested and validated with Cisco ASA Software Release 7.2.

Cisco ASA 5540 Adaptive Security Appliance

The Cisco ASA 5540 Adaptive Security Appliance delivers high-performance, high-density security services with Active/Active high availability and Gigabit Ethernet connectivity for medium-sized and large enterprise and service-provider networks, in a reliable, modular appliance. With four Gigabit Ethernet interfaces and support for up to 100 VLANs, businesses can use the Cisco ASA 5540 to segment their network into numerous zones for improved security. The Cisco ASA 5540 Adaptive Security Appliance scales with businesses as their network security requirements grow, delivering exceptional investment protection and services scalability. The advanced network and application-layer security services and content security defenses provided by the Cisco ASA 5540 Adaptive Security Appliance can be extended by deploying the AIP SSM for high-performance intrusion prevention and worm mitigation.

Businesses can scale their SSL and IPsec VPN capacity to support a larger number of mobile workers, remote sites, and business partners. Up to 2500 AnyConnect and/or clientless VPN peers can be supported on each Cisco ASA 5540 by installing an Essential or a Premium AnyConnect VPN license; 5000 IPsec VPN peers are supported on the base platform. VPN capacity and resiliency can also be increased by taking advantage of the integrated VPN clustering and load-balancing capabilities of the Cisco ASA 5540. The Cisco ASA 5540 supports up to 10 appliances in a cluster, supporting a maximum of 25,000 AnyConnect and/or clientless VPN peers or 50,000 IPsec VPN peers per cluster. For business continuity and event planning, the ASA 5540 can also benefit from the Cisco VPN FLEX licenses, which enable administrators to react to or plan for short-term bursts of concurrent Premium VPN remote-access users, for up to a 2-month period.

Using the optional security context capabilities of the Cisco ASA 5540 Adaptive Security Appliance, businesses can deploy up to 50 virtual firewalls within an appliance to enable compartmentalized control of security policies on a per-department or per-customer basis, and deliver reduced overall management and support costs.

Table 4 lists features of the Cisco ASA 5540.

Table 4. Cisco ASA 5540 Adaptive Security Appliance Platform Capabilities and Capacities

Feature

Description

Firewall Throughput

Up to 650 Mbps

Maximum Firewall and IPS Throughput

• Up to 500 Mbps with AIP SSM-20
• Up to 650 Mbps with AIP SSM-40

VPN Throughput

Up to 325 Mbps

Concurrent Sessions

400,000

IPsec VPN Peers

5000

Premium AnyConnect VPN Peer License Levels*

2, 10, 25, 50, 100, 250, 500, 750, 1000, and 2500

Security Contexts

Up to 50*

Interfaces

4 Gigabit Ethernet ports and 1 Fast Ethernet port

Virtual Interfaces (VLANs)

200

Scalability

VPN clustering and load balancing

High Availability

Active/Active**, Active/Standby

* Separately licensed feature; includes two with base system

** Available for the firewall feature set

Performance numbers tested and validated with Cisco ASA Software Release 7.2.

No comments: