06-02-2017 10:15 AM - edited 03-12-2019 02:27 AM
We have purchased and configured some asa 5506's. We have installed basic firepower on each(only ips . No amp licenses for extra features). Will the 5506 be strong enough resource wise to run firepower on the basic ips/ids?
06-04-2017 08:29 AM
Sure. As long as you keep the throughput below the rated maximum (125 Mbps with AVC and IPS as shown in the data sheet here: http://www.cisco.com/c/en/us/products/collateral/security/asa-5500-series-next-generation-firewalls/datasheet-c78-733916.html) you should be just fine.
These are pretty widely deployed in just this way.
06-05-2017 06:53 AM
We have a sizing chart(a spreadsheet) from our reseller which states that the 5506 with ips will reduce throughput to 68mb which is why i was asking. Does this sound accurate?
06-05-2017 08:45 AM
As with most performance engineering answers, "it depends". If you measure with the data sheet metric of 1024 byte packet size and all http traffic then the answer is as specified in the data sheet.
If you drop the packet size to 450 byes then you will see performance closer to your cited number.
If you are in the grey area in between, your reseller can pull some metrics from your actual network and request Cisco partner help desk to run the actual numbers through an internal sizing tool and give you a precise estimate based on your environment.
06-08-2017 02:19 PM
It's just sort of a matter of who to believe. Leaning on believing cisco but i was just wondering what throughput's people are actually getting in production. Main features we'd be running on this level of unit would be ips/ids and anyconnect or site ipsec vpn.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide