12-16-2022 10:13 AM
I have a question about FP sizing.
For a site that has approximately 2000 active connections through an ASA5506x (not running any firepower just classic ASA, output of "show conn") would a FP1010 be powerful enough to run all three FTD licenses?
Solved! Go to Solution.
12-16-2022 10:30 AM - edited 12-16-2022 10:38 AM
@lcaruso yes the 1010 hardware should be sufficent, datasheet included for reference (and comparison with the other models).
You may want to check other limitations of each hardware model depending on your future requirements, network bandwidth etc.
12-18-2022 07:35 PM
With IPS, URL Filtering and Malware all enabled, the Firepower 1010 can handle about 160 Mbps (Snort 2) to 220 Mbps (Snort 3). Under those conditions you should be at or below the recommended 80% CPU utilization according to the tool.
12-20-2022 05:39 AM
@lcaruso the Firepower 1120 (or anything higher) can handle that speed with all three features. For the 1120, the expected CPU is 57% with Snort 3 and FTD 7.2
12-16-2022 10:30 AM - edited 12-16-2022 10:38 AM
@lcaruso yes the 1010 hardware should be sufficent, datasheet included for reference (and comparison with the other models).
You may want to check other limitations of each hardware model depending on your future requirements, network bandwidth etc.
12-16-2022 04:03 PM
Have you access to and tried this site?
12-17-2022 01:02 AM
@lcaruso sorry I don't have access, only partners or cisco employees can use this tool. I believe @Marvin Rhoads works for a partner would have access to run this tool.
12-18-2022 03:54 AM
Concurrent connections are not a parameter used in the NGFWPE tool. For that you can refere to the data sheet that @Rob Ingram linked earlier.
The tool takes into account throughput, average packet size and enabled features (Base, URL Filtering, Malware analysis and SSL decryption (where used)).
12-18-2022 10:20 AM
Yes, that is exactly what I noticed after seeing a demo video of this tool noting throughput as the critical parameter and why I wanted to access it.
12-18-2022 07:35 PM
With IPS, URL Filtering and Malware all enabled, the Firepower 1010 can handle about 160 Mbps (Snort 2) to 220 Mbps (Snort 3). Under those conditions you should be at or below the recommended 80% CPU utilization according to the tool.
12-19-2022 11:00 AM
Would it be too much to ask to provide the correct FTD model for a 600Mbps ISP connection for all three licenses? I always try to ensure the edge device is not throttling down.
12-20-2022 05:39 AM
@lcaruso the Firepower 1120 (or anything higher) can handle that speed with all three features. For the 1120, the expected CPU is 57% with Snort 3 and FTD 7.2
12-20-2022 08:00 AM
Marvin, thanks kindly once again for this help. I finally got in touch with our account team and they requested access to the tool while I was on the phone with them, so it would seem to be no small favor for you to not only take the time but also arrange this. I really appreciate you helping us get a favorable client outcome. Best Regards, sir!
12-19-2022 07:02 AM
Thank you kindly for running that scenario.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide