| Model |
FPR3120-NGFW-K9 |
| Hardware specifications |
| Maximum number of interface |
Up to 24 total Ethernet ports (8 x 1G RJ-45, 8 x 1/10G SFP, and network module) |
| Network modules |
8 x 1/10G Options |
| Integrated I/O |
8 x 10M/100M/1G BASE-T Ethernet interfaces (RJ-45)
8 x 1/10 Gigabit (SFP) Ethernet interfaces |
| Integrated network management ports |
1 x 1/10G SFP |
| Storage |
1 x 900 GB, 1 spare slot |
| Serial port |
1 x RJ-45 console |
| USB |
1 x USB 3.0 Type-A (900mA) |
| Dimensions (H x W x D) |
4.4 x 43.3 x 50.8 cm |
| Form factor (rack units) |
1RU |
| Power Supplies |
| Configuration |
Single 400W AC, Dual 400W AC optional
Single/Dual 400W DC optional |
| AC input voltage |
100 to 240V AC |
| AC maximum input current |
< 6A at 100V |
| AC maximum output power |
400W |
| AC frequency |
50/60 Hz (nominal) |
| AC efficiency |
> 89% at 50% load |
| DC input voltage |
-48V to -60VDC |
| DC maximum input current |
< 12.5A at -48V |
| DC maximum output power |
400W |
| DC efficiency |
>88% at 50% load |
| Redundancy |
1 + 1 AC or DC with dual supplies |
| Fans |
2 hot-swappable fan modules (with 2 fans each) |
| Noise |
65 dBA @ 25C; 74 dBA maximum |
| Rack mountable |
Yes. Fixed mount brackets optional. (2-post). Mount rails included (4-post EIA-310-D rack) |
| Weight |
23 lbs (10.5kg) 1 x power supplies, 1 x NM, fan module, 1 x SSD |
| Temperature: operating |
32 to 104 ℉ (0 to 40℃) |
| Temperature: non-operating |
-4 to 149℉ (-20 to 65℃) |
| Humidity: operating |
10 to 85% non-condensing |
| Humidity:non-operating |
5 to 95% non-condensing |
| Altitude: operating |
10,000 ft (max) or NEBS operation (see below) |
| Altitude: non-operating |
40,000 ft (max) |
| NEBS operation (FPR-3120 only) |
Operating altitude: 0 to 13,000ft (3962 m)
Operating temperature:
Long term: 0 to 45℃, up to 6,000ft (1829 m)
Long term: 0 to 35℃, 6,000 ft to 13,000 ft(1829 m to 3962 m)
Short term: -5 to 55℃, up to 6,000 ft (1829 m) |
| Performance specifications and feature highlights with the Cisco Secure Firewall Threat Defense (TD) image |
| Throughput: FW + AVC (1024B) |
21.0 Gbps |
| Throughput: FW + AVC + IPS (1024B) |
21.0 Gbps |
| Maximum concurrent sessions, with AVC |
4 Million |
| New connections Per Second with, AVC |
170,000 |
| TLS |
6.7 Gbps |
| Throughput: NGIPS (1024B) |
21.0 Gbps |
| IPSec VPN Throughput (1024B TCP w/Fastpath) |
10 Gbps |
| Projected IPSec VPN throughput (1024B TCP w/Fastpath) with VPN Offload (FTP 7.2) |
13.5 Gbps |
| Maximum VPN Peers |
7,000 |
| Local On-device Management |
Yes |
| Centralized Management |
Centralized configuration, logging, monitoring, and reporting are performed by the Firewall Management Center or alternatively in the cloud with Cisco Defense Orchestrator |
| Application Visibility and Control (AVC) |
Standard, Supporting more than 4000 applications, as well as gelocation, users, and websites |
| AVC: OpenAppID Support for custom, open source application detectors |
Standard |
| Cisco Security Intelligence |
Standard with IP, URL, and DNS Threat intelligence |
| Cisco Secure IPS |
Available: can passively detect endpoints and infrastructure for threat correlation an indicators of Compromise (IOC) intelligence |
| Cisco Malware Defense |
Available: enables detection, blocking, tracking, analysis, and containment of targeted and persistent malware, addressing the attack continuum both during and after attacks, integrated threat correlation with CISCO Secure Endpoint is also optionally available |
| Cisco Secure Malware Analytics |
Available |
| URL Filtering: Number of Categories |
More than 80 |
| URL Filtering: Number of URL categorized |
More than 280 million |
| Automated Threat Feed and IPS signature updates |
Yes: class-ending Collective Security Intelligence (CSI) from the Cisco Talos Group |
| Third-party and open-source ecosystem |
Open API for integrations with third-party products; Snort and OpenAppID community resources for new and specific threats |
| High Availability & Clustering |
Active/active, Active/standby. |
| Cisco Secure Firewall 3100 Series allows clustering of up 8 chassis (no clustering on 3105) |
| Cisco Trust Anchor Technologies |
Secure Firewall 3100 Series platforms include Trust Anchor Technologies for supply chain and software image assurance. Please see the section below for additional details |
FPR3120-NGFW-K9 có đáp ứng được các hệ thống mạng nhiều người dùng và ứng dụng không?
Có. FPR3120-NGFW-K9 hỗ trợ 4 triệu phiên kết nối đồng thời, 170.000 kết nối mới mỗi giây và thông lượng NGFW/IPS đạt 21 Gbps. Nhờ đó, thiết bị phù hợp với doanh nghiệp lớn, trung tâm dữ liệu và các hệ thống có mật độ người dùng, ứng dụng và lưu lượng truy cập cao.
Điểm nổi bật của Cisco Secure Firewall FPR3120-NGFW-K9 về khả năng mở rộng cổng kết nối là gì?
FPR3120-NGFW-K9 hỗ trợ tối đa 24 cổng Ethernet, bao gồm 8 cổng Gigabit RJ-45, 8 cổng SFP 1/10G và Network Module mở rộng 8 cổng 1/10G. Thiết kế này giúp doanh nghiệp dễ dàng mở rộng hạ tầng mạng tốc độ cao mà không cần thay thế thiết bị khi nhu cầu kết nối tăng lên.
Cisco Secure Firewall FPR3120-NGFW-K9 có khả năng xử lý lưu lượng VPN và SSL/TLS như thế nào?
Thiết bị cung cấp IPSec VPN Throughput lên đến 10 Gbps và có thể đạt 13.5 Gbps khi sử dụng VPN Offload trên FTD 7.2. Đồng thời, TLS Throughput đạt 6.7 Gbps, giúp xử lý hiệu quả lưu lượng VPN và SSL/TLS được mã hóa mà vẫn duy trì hiệu năng cao.