cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5040
Views
5
Helpful
4
Replies

ASA 5506X

nelson-rick
Level 1
Level 1

Does anyone know how many clients I can have with this setup?  Any objections to my setup or other suggestions?  I want to protect users from downloading malware and accessing unauthorized sites.

ASA 5506 W/FIREPOWER SVC MFG Part#:ASA5506-FPWR-BUN

ASA with FirePOWER Services IPS and Advanced Malware Protection license - sub MFG Part#:L-ASA5506-TAM-3Y

ASA with FirePOWER Services URL Filtering - subscription license  MFG Part#:L-ASA5506-URL-3Y

1 Accepted Solution

Accepted Solutions

bejiening
Level 1
Level 1

Cisco ASA 5500-X Next Generation ASA5506-K9 FirePower firewall overview:

8 * 1 Gigabit Ethernet interface,1 management port

Firepower service, Firesight management Center, ASDM 7.3X

Up to 750 Mbps stateful inspection, 100 Mbps 3DES/AES VPN throughput

Cloud- and Software-based Firewall services, 2 SSL VPN peers

unlimited users supports, 50 IPsec VPN peer, Active/Standby support

up to 30 vlans support, 5,000 new connections per second

4GB memory, 8 Flash memory, 64Gb Solid-state drive

View solution in original post

4 Replies 4

brremmel
Cisco Employee
Cisco Employee

There is no hard limitation on the # of clients that can run through the ASA 5506.

bejiening
Level 1
Level 1

Cisco ASA 5500-X Next Generation ASA5506-K9 FirePower firewall overview:

8 * 1 Gigabit Ethernet interface,1 management port

Firepower service, Firesight management Center, ASDM 7.3X

Up to 750 Mbps stateful inspection, 100 Mbps 3DES/AES VPN throughput

Cloud- and Software-based Firewall services, 2 SSL VPN peers

unlimited users supports, 50 IPsec VPN peer, Active/Standby support

up to 30 vlans support, 5,000 new connections per second

4GB memory, 8 Flash memory, 64Gb Solid-state drive

alexandersoliz
Level 1
Level 1

First of all I recommend you to use the L-ASA5512-TAMC-3Y license insted of those two so you can do some savings, and the next thing you should analazy besides of the number of users is the amount of traffic analized, and the features you will enable. If we focus only in the requirement of deep packet inspection with features of URL Filtering and AMP (which uses the IPS engine)  the 5506-X can analize about 58 Mbps of REAL traffic (Please keep in mind that the datasheet numbers usually reflects a result of the test with ideal traffic so they can show bigger numbers).

The 750 Mbps of stateful inspection is just for the traffic without the features of URL Filtering and AMP, and also uses a ideal traffic.

Review Cisco Networking for a $25 gift card