cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
12530
Views
27
Helpful
17
Comments
Dennis Perto
Level 5
Level 5

Cisco recently announced two high-end next generation firewalls primarily for service providers and data centers.
Based on data released from Cisco I have filled out the voids with my own tentative data.
If you find any data that is proved incorrect, please contact me and I will edit it.

Firepower 4100

In the front is two network module bays and two SSD bays. Only one SSD bay is used by default. Six hot-swappable fans and two power supply’s in the back.

Applications:

ASA

Firepower Threat Defense

Decorations:

For 4120, 4140 and 4150 - Radware DefensePro DDoS Mitigation

Supervisor

8x 10GE SFP+ ports

Management processor: Gladden 2.0GHz (Pentium B925C 2 physical cores/4 logical cores)

Management memory: 8GB DDR3 1600MHz RDIMM

Management SSD: Unknown

Backplane: Broadcom StrataXGS® Trident II

Backplane model: BCM56854A0IFSBG 720Gbit/s

4110

12 physical cores (24 logical cores) Single 12 core Xeon E5-2658v3 2.2GHz

64GB DDR4 2133MHz RAM

One disk 200GB SSD storage + one optional for AMP

One Smart NIC - Cruz custom Cisco FPGA

One Crypto Accelerator - Cavium Nitrox III CNN53550-500-C20

4120

24 physical cores (48 logical cores) Dual 12 core Xeon E5-2658v3 2.2GHz

128GB DDR4 2133MHz RAM

One disk 200GB SSD storage + one optional for AMP

Two Smart NIC - Cruz custom Cisco FPGA

Two Crypto Accelerator - Cavium Nitrox III CNN3550-500-C20

4140

36 physical cores (72 logical cores) Dual 18 core Xeon E5-2699v3 2.3GHz

256GB DDR4 2133MHz RAM

One disk 400GB SSD storage + one optional for AMP

Two Smart NIC - Cruz custom Cisco FPGA

Two Crypto Accelerator - Cavium Nitrox III CNN3550-500-C20

4150

44 physical cores (88 logical cores) Dual 22 core Xeon E5-2699v4 2.2GHz

256GB DDR4 2400MHz RAM

One disk 400GB SSD storage + one optional for AMP

Two Smart NIC - Cruz custom Cisco FPGA

Two Crypto Accelerator - Cavium Nitrox III CNN3550-500-C20

 

Firepower 9300

Can contain one supervisor with up to two network modules, three security modules (blades) of one kind (either SM24, SM36 or SM44) and two power supply’s in the front.

In the back there is 4 hot-swappable fans.

Applications:

ASA

Firepower Threat Defense

Decorations:

Radware DefensePro DDoS Mitigation

- Up to 10GBps per module on 6 dedicated x86 CPU cores

- Impact on ASA throughput is 10-15%

Supervisor

8x 10GE SFP+ ports

Management processor: Unknown

Management memory: 32GB DDR4 2133MHz

Management SSD: Micron M500 mSATA 120GB

Backplane: Broadcom StrataXGS® Trident II

Backplane model: BCM56852A0KFSBG  960Gbit/s

9300 Security Module 24 - Enterprise

24 physical cores (48 logical cores) Dual 12 core Xeon E5-2658v3 2.2GHz (2.9GHz turbo)

256GB DDR4 RAM 2133MHz RDIMM

Two 800GB SSDs in RAID1

Two Smart NIC – Cruz custom Cisco FPGA

Two Crypto Accelerator - Cavium Nitrox III CNN3550-500-C20

9300 Security Module 36 - Extreme

36 physical cores (72 logical cores) Dual 18 core Xeon E5-2699v3 2.3GHz (3.6GHz turbo)

256GB DDR4 RAM 2133MHz RDIMM

Two 800GB SSDs in RAID1

Two Smart NIC – Cruz custom Cisco FPGA

Two Crypto Accelerator - Cavium Nitrox III CNN3550-500-C20

9300 Security Module 44

44 physical cores (88 logical cores) Dual 22 core Xeon E5-2699v4 2.2GHz (3.6GHz turbo)

256GB DDR4 RAM 2400MHz RDIMM

Two 800GB SSDs in RAID1

Two Smart NIC – Cruz custom Cisco FPGA

Two Crypto Accelerator - Cavium Nitrox III CNN3550-500-C20

Notes

  1. Cisco announced that the security modules running ASA will use the processors turbo mode when 25% of the cores hit 80% CPU load. This will be disabled again when all ASA cores drop below 60% load.
  2. I am unable to find any information about the management processor on the Firepower 9300 chassis and the management SSD on the 4100.
17 Comments
priced
Level 5
Level 5

Are there any 3rd party test results for throughput on the 4100 series?

Dennis Perto
Level 5
Level 5

Not to my knowledge.

4120 vs. 9300 Security Module 24 - Enterprise

Stateful inspection firewall throughput: 40Gbps vs. 75 Gbps

Concurrent firewall connections: 15 million vs. 55 million

IPSEC VPN throughput: 10 Gbps vs. 15Gbps

4140 vs. 9300 Security Module 36 - Extreme

Stateful inspection firewall throughput: 60Gbps vs. 80 Gbps

Concurrent firewall connections: 25 million vs. 60 million

IPSEC VPN throughput: 14 Gbps vs. 18Gbps

# of Cores, etc. is the same between the two 4100 and 9300 Boxes, why such big differences in performance?


Thanks for the explanation.

Dennis Perto
Level 5
Level 5

Looking at your numbers I figure that you are comparing ASA software specs.

I guess that the only substantial difference is the amount of RAM, so Cisco must have made some improvements in the usage of memory.

If you look at Firepower instead you go from 5Gbit in a 4120 to 6Gbit in a SM24.

Hi Dennis,

thanks for your reply. But does it matter if i compare ASA Images or FTD Images, Stateful firewall throughput or Sizing Throughput (AVC+IPS)? (As long as i compare the same throughput values.)

Cisco: "Same hardware and software architecture as 9300"  ...same RAM, same CPU, same Core-#...

The differences in throughput are huge in my opinion.

regards

Wladimir

Dennis Perto
Level 5
Level 5

I Agree with you, it is a huge difference, but only with the ASA software.

Think of it it this way. You have two raspberry PI. The one with double the amount of RAM.

You installed Nginx on both. Which one can handle the most concurrent connections?

And Apache is like Firepower. You get less out of the ekstra RAM.

Remember that it is two completely different operating systems.

Dennis Perto
Level 5
Level 5

Keep in mind that in this case Apache will have to serve websites, while Nginx only is looking at the senders IP address to filter and proxy. Two different use cases as well.

Christopher Heffner
Cisco Employee
Cisco Employee

Dennis - probably just a difference in language for spelling but if not then can you please fix "Firepower Threat Defence" under the Applications sections for the FP4100 and FP9300 so it is spelled "Defense".

Great work on getting all this information together for the FTD community.

I will work on getting the management process for the FP9300 supervisor for your collection here.

Cheers,

Christopher

Dennis Perto
Level 5
Level 5

It is done. Thank you for telling me.
Apparently I keep switching those letters around. Silly me.

That would be great as it is the only piece of information I cannot see anywhere. Not even on the firepowerngfw.com site.

Christopher Heffner
Cisco Employee
Cisco Employee

Thanks Dennis for the typo corrections.

Also a BIG “THANK YOU” for the link to the firepowerngfw.com website. I work for Cisco and did not even know about that website.

I have already added the link to a presentation I have to give in the AM.

Thanks again!

Christopher M. Heffner, CCIE #8211, CCSI #98760, CICSS

Technical Solutions Architect

GET Security

Cisco Systems

“ISE Champion”

https://new-webex.webex.com/meet/chheffne

--

Dennis Perto
Level 5
Level 5

Hi Christopher

Please keep in mind that the SSDs shown on that website is all 120GB. This can not be true as the FP4100 is not sold with less than 400GB SSDs.
The same for 5506, 5508 and 5516.

And is is just me, or did they switch the labels for the Cavium and the CPU?

Christopher Heffner
Cisco Employee
Cisco Employee

I will have to check into the labels on the website and see if they are incorrect about getting them fixed.

I have to figure out “who” the owner of the website content is FIRST!

Cheers,

Christopher

Qamar Islam
Level 1
Level 1

Hi,

I have a 4120 Appliance and i tried to factory reset it. I tried from the ROMMON mode but it doesn't show me the Switch # mode. Your kind support is needed ?

Thanks

Dennis Perto
Level 5
Level 5

Did you load the kickstart image?

Qamar Islam
Level 1
Level 1

Thanks for your reply.

Yes, I load the kickstart image but after that it will goes me to Firepower CLI mode FP4120#.

Can you provide me the step by step reseting document or any other option for reseting it.?

Thanks

Qamar

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: