cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2442
Views
15
Helpful
8
Replies

Throughput

elite2010
Level 3
Level 3

Hi,

How the ips ,ngfw and threat protection throughput related to Firewall throughput 

And what is the  difference between the   ips ,ngfw and threat protection throughput

Thanks

8 Replies 8

balaji.bandi
Hall of Fame
Hall of Fame

Depends on Design and network.

 

here is the information cisco point of view. :

 

https://www.cisco.com/c/dam/m/sl_si/events/2017/cisco-connect/pdf/ConnectSLO_Cisco-Next-Generation-Firewall-and-IPS.pdf

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi,

Depends on Design and network.

Can you give an example .?

In normal case how these throughput  influence each other 

Thanks

 

 

Hi,

Firewall Throughput (ASA) is 3 gbps and FW + AVC  throughput is1750 Mbps .

Does it mean it reduces th throughput if we enable FW+AVC 

Thanks

Yes, enabling more features generally requires the appliance to do more work (consume CPU etc.) thus it slows down.

Imagine you can run a distance at whatever speed. Now imagine running the same distance carrying a heavy load. your speed will be slower.

Only on some of the newest appliances (i.e. Firepower 4100 and 9300 series) does speed remain close to uniform despite turning on additional features. That is because they have purpose built hardware (custom ASICs, network interface cards etc.) that is designed to offload those features which might otherwise be done with additional software processing and a general purpose CPU.

Hi,

If I am buying a ASA5545 With FTD image , which datasheet I shoud refer ?

https://www.cisco.com/c/en/us/products/collateral/security/asa-5500-series-next-generation-firewalls/datasheet-c78-733916.html

 

https://www.cisco.com/c/en/us/products/collateral/security/asa-5500-series-next-generation-firewalls/datasheet-c78-733916.html

 

Why cisco says just IPS  in some datasheets and some place says . NGIPS

what is the differnece between IPS and NGIPS

?

Thanks

 

Yes you add more advance features, the performance go down - since it required to process all the rules and intercept the traffic.

 

To be honestly - bewcuase organically grown this documents, Cisco have many cosmotic errors in the documentation

 

5545-X  with FTD you can use ( if you buying new Device) suggest to go with firepower appliance directly rather ASA

like 2100/4XXX /9XXX  depends on requirement.

 

Again all the models not going to support FTD check version and model before buying ASA.

 

IPS is traditional Cisco one

NGIPS - is the next generation IPS with Firrepower

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi,

you said "5545-X  with FTD you can use ( if you buying new Device) suggest to go with firepower appliance directly rather ASA"

 

You recommending asa 5545-x  FTD  or firepower appliances?

If firepower appliance which one you suggest ? 

 

Thanks

Firepower Diretion 2100 / 4100 (for medium) - to replace 5545X

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Review Cisco Networking for a $25 gift card