| Model |
CSF6170-A-TD-K9 |
| Hardware specifications |
| Form factor |
2 RU for 19" Rack |
| Fixed ports |
12 x 1/10/25/50 Gigabit Ethernet SFP56 Ports |
| 4 x 40/100/200 Gigabit Ethernet QSFP56 Ports |
| Management Ethernet |
2 x 1/10/25 Gigabit Ethernet SFP28 Ports |
| Network Modules |
Standard Ethernet Modules |
| ● 8 x 1/10 Gigabit Ethernet SFP+ Network Module |
| ● 8 x 1/10/25 Gigabit Ethernet SFP28 Network Module |
| ● 4 x 40 Gigabit Ethernet QSFP+ Network Module |
| ● 4 x 40/100/200 Gigabit Ethernet QSFP56 Network Module |
| ● 2 x 40/100 Gigabit Ethernet QSFP28 Network Module |
| ● 2 x 200/400 Gigabit Ethernet QSFP-DD Network Module |
| Fail-to-Wire (FTW) Modules |
| ● 8 x 1 Gigabit Ethernet Copper Fail-to-Wire (FTW) Network Module |
| ● 6 x 1 Gigabit Ethernet SX Fiber Fail-to-Wire (FTW) Network Module |
| ● 6 x 10 Gigabit Ethernet SR Fiber Fail-to-Wire (FTW) Network Module |
| ● 6 x 10 Gigabit Ethernet LR Fiber Fail-to-Wire (FTW) Network Module |
| ● 6 x 25 Gigabit Ethernet SR Fiber Fail-to-Wire (FTW) Network Module |
| ● 6 x 25 Gigabit Ethernet LR Fiber Fail-to-Wire (FTW) Network Module |
| Maximum number of interfaces |
| Expansion (2 Slots) |
Total Maximum Ports |
| + 16 (via 2x 8-port modules, SFP28) |
28 Ports |
| + 8 (via 2x 4-port modules, QSFP56) |
12 Ports |
| + 4 (via 2x 2-port modules, QSFP-DD) |
4 Ports |
| N/A |
2 Ports |
| Note: 50G Support: Only the 12 Fixed SFP56 ports support native 50G speeds (Modules listed are SFP28 maxing at 25G). |
| FTW (Fail-to-Wire): If using Fail-to-Wire modules (6-ports each), the total 1/10/25G count would be 24 ports (12 Fixed + 12 Module). |
| The above port counts do not factor in the breakout capability supported by different interfaces. |
| Console port |
1 x RJ-45 console |
| USB port |
1 USB 3.0 |
| Storage |
2 x 7.2 TB |
| Power over Ethernet |
NA |
| Transceiver support |
Refer to Cisco Secure Firewall (CSF) 6100 Hardware Installation Guide |
| Mean Time Between Failure (MTBF) |
Chassis: 206,000 Hours (8.89 cm x 42.93 cm x 82.55 cm) |
| Chassis dimensions (HxWxD) |
3.5” H x 16.9” W x 32.5” D |
| Weight |
66lbs (29.94kg), fully loaded |
| Cooling |
4 Field Replaceable Fan module; every module has 2 fans |
| Rack mountable |
Yes, mount rails included (4-post EIA-310-D rack) |
| Power Supply Details |
| Configuration |
Dual high-voltage AC/DC power supplies. |
| ● High Line AC: Up to 3000W per power supply, hot-swappable, load-sharing redundancy. |
| ● Low Line AC: Up to 1500W per power supply, load sharing with no redundancy. |
| Dual low-voltage DC power supplies offered. |
| ● Both Inputs Connected: Up to 3000W per power supply, hot-swappable, load-sharing redundancy. |
| ● One Input Connected: Up to 1500W per power supply, load sharing with no redundancy. |
| AC input voltage |
100 to 120 VAC (HVAC low line); 200 to 277 VAC (HVAC high line) |
| AC input frequency |
50—60 Hz |
| HVDC input voltage |
240 to 380 VDC |
| LVDC input voltage |
—48VDC to —60VDC |
| AC current draw, maximum |
14 Amperes (high line AC) |
| System HVDC current draw, maximum |
12 Amperes |
| System LVDC current draw, maximum |
33 Amperes |
| Power consumption, typical |
2010 Watts |
| Power consumption, maximum |
2760 Watts |
| Redundancy |
1+1 Redundancy |
| ● Redundant only with dual HVAC, HVDC, or dual-input LVDC. |
| ● LVAC and single-input DC do not support redundancy. |
| Operating Range |
| Temperature: operating |
32°F to 104°F (0°C to 40°C) |
| Humidity: operating |
5% to 90% (non-condensing) |
| Altitude: operating |
0 to 10,000 ft. |
| De-rate the maximum operating temperature 1°C/1K-ft. above 6000 ft. |
| Acoustic noise |
Sound Pressure: <=74 dBA (typical), <= 90 dBA (maximum) |
| Sound Power: <=81 dB (typical), <=98 dB (maximum) |
| Non-operating/storage environment |
| Temperature: nonoperating |
–40°F to 158°F (–40°C to 70°C) |
| Humidity: nonoperating |
5% to 95% (non-condensing) |
| Altitude: nonoperating |
40,000 ft. |
| Performance : Cisco Secure Firewall 6170 Series with FTD software |
| Throughput: Firewall + Application Visibility and Control (AVC) (1024B) |
700 Gbps |
| Throughput: AVC + Intrusion Prevention System (IPS) (1024B) |
600 Gbps |
| NGFW Throughput: FW + AVC + IPS (1024B) |
600 Gbps |
| IPSec VPN Throughput (1024B TCP w/Fastpath) |
550 Gbps |
| TLS Decryption[1] |
150 Gbps |
| Application Visibility and Control (AVC) |
Standard, supporting more than 8100 applications, as well as geolocations, users, and websites |
| Scalability : Cisco Secure Firewall 6170 Series FTD software |
| Maximum concurrent sessions, with AVC |
105 Million |
| Maximum new connections per second, with AVC |
2.7 Million |
| Maximum VPN peers |
60 K |
| Maximum virtual router instances (VRF) |
250 |
| High availability |
Active/Standby, Active/Active (with clustering) |
| Instances (Multi-Instance) |
Available in future release |
| Clustering |
Up to 16 |
| Compliance: Cisco 6100 Series regulatory, safety, and EMC compliance |
| Regulatory compliance |
Products comply with CE markings per directives 2014/30/EU and 2006/108/EC |
| Safety |
● UL 62368-1 |
| ● UL 60950-1 |
| ● CAN/CSA-C22.2 No. 62368-1 |
| ● CAN CSA C22.2 60950-1 |
| ● EN 62368-1 |
| ● IEC 62368-1 |
| ● AS/NZS 62368.1 |
| ● GB4943.1 |
| EMC: Emissions |
● FCC 47CFR15 Class A |
| ● AS/NZS CISPR 32 Class A |
| ● EN55032/CISPR 32 Class A |
| ● ICES-003 Class A |
| ● VCCI Class A |
| ● KS C 9832 Class A |
| ● CNS-15936 Class A |
| ● EN61000-3-2 Power Line Harmonics |
| ● EN61000-3-3 Voltage Changes, Fluctuations, and Flicker |
| EMC: Immunity |
● IEC/EN61000-4-2 Electrostatic Discharge Immunity |
| ● IEC/EN61000-4-3 Radiated Immunity |
| ● IEC/EN61000-4-4 EFT-B Immunity |
| ● IEC/EN61000-4-5 Surge |
| ● IEC/EN61000-4-6 Immunity to Conducted Disturbances |
| ● IEC/EN61000-4-11 Voltage Dips, Short Interruptions, and Voltage Variations |
| ● KS C 9835 |
| EMC: ETSI/EN |
● EN 300 386 Telecommunications Network Equipment (EMC) |
| ● EN55032/CISPR32 Multimedia Equipment (Emissions) |
| ● EN55035/CISPR 35 Multimedia Equipment (Immunity) |
| ● EN61000-6-1, EN61000-6-2 Generic Immunity Standards |
| License for Cisco Secure Firewall 6170 with FTD software (option) |
|
| L-CSF6170T-T= |
Cisco Secure Firewall 6170 Threat Defense License |
| L-CSF6170T-AMP= |
Cisco Secure Firewall 6170 Adv Malware Protection License |
| L-CSF6170T-URL= |
Cisco Secure Firewall 6170 URL Filtering License |
| L-CSF6170T-TC= |
Cisco Secure Firewall 6170 Threat Defense and URL License |
| L-CSF6170T-TM= |
Cisco Secure Firewall 6170 Threat Defense, Malware License |
| L-CSF6170T-TMC= |
Cisco Secure Firewall 6170 TD, Malware and URL License |
Khả năng mở rộng cổng mạng của Cisco Secure Firewall CSF6170-A-TD-K9 có ưu điểm gì?
CSF6170-A-TD-K9 được trang bị sẵn 12 cổng SFP56 1/10/25/50GbE và 4 cổng QSFP56 40/100/200GbE, đồng thời hỗ trợ nhiều Network Module như SFP28, QSFP56 và QSFP-DD. Thiết bị có thể mở rộng lên 28 cổng 1/10/25GbE, đồng thời hỗ trợ kết nối tốc độ 200G và 400G, giúp dễ dàng nâng cấp hạ tầng mạng khi nhu cầu băng thông tăng lên.
Cisco Secure Firewall CSF6170-A-TD-K9 phù hợp với những môi trường triển khai nào?
CSF6170-A-TD-K9 được thiết kế cho các trung tâm dữ liệu, nhà cung cấp dịch vụ (ISP) và doanh nghiệp quy mô lớn có yêu cầu xử lý lưu lượng cực cao. Thiết bị cung cấp 700 Gbps Firewall + AVC, 600 Gbps NGFW, 550 Gbps IPSec VPN, hỗ trợ 105 triệu phiên đồng thời và 2,7 triệu kết nối mới/giây, đáp ứng tốt các hệ thống có mật độ người dùng và ứng dụng lớn.
Điểm khác biệt lớn nhất giữa Cisco Secure Firewall CSF6160-A-TD-K9 và CSF6170-A-TD-K9 là gì?
CSF6170-A-TD-K9 có hiệu năng vượt trội so với CSF6160-A-TD-K9, với 700 Gbps Firewall + AVC, 600 Gbps NGFW, 150 Gbps TLS Decryption, 105 triệu phiên đồng thời và 2 × 7,2 TB SSD, trong khi CSF6160-A-TD-K9 đạt 600 Gbps Firewall + AVC, 550 Gbps NGFW, 100 Gbps TLS Decryption, 75 triệu phiên đồng thời và 2 × 3,6 TB SSD. Vì vậy, CSF6170-A-TD-K9 phù hợp hơn với các hệ thống có lưu lượng và yêu cầu xử lý rất lớn.