| Model |
CSF6170-A-ASA-K9 |
| Hardware specifications |
| Form factor |
2 RU for 19" Rack |
| Fixed ports |
12 x 1/10/25/50 Gigabit Ethernet SFP56 Ports |
| 4 x 40/100/200 Gigabit Ethernet QSFP56 Ports |
| Management Ethernet |
2 x 1/10/25 Gigabit Ethernet SFP28 Ports |
| Network Modules |
Standard Ethernet Modules |
| ● 8 x 1/10 Gigabit Ethernet SFP+ Network Module |
| ● 8 x 1/10/25 Gigabit Ethernet SFP28 Network Module |
| ● 4 x 40 Gigabit Ethernet QSFP+ Network Module |
| ● 4 x 40/100/200 Gigabit Ethernet QSFP56 Network Module |
| ● 2 x 40/100 Gigabit Ethernet QSFP28 Network Module |
| ● 2 x 200/400 Gigabit Ethernet QSFP-DD Network Module |
| Fail-to-Wire (FTW) Modules |
| ● 8 x 1 Gigabit Ethernet Copper Fail-to-Wire (FTW) Network Module |
| ● 6 x 1 Gigabit Ethernet SX Fiber Fail-to-Wire (FTW) Network Module |
| ● 6 x 10 Gigabit Ethernet SR Fiber Fail-to-Wire (FTW) Network Module |
| ● 6 x 10 Gigabit Ethernet LR Fiber Fail-to-Wire (FTW) Network Module |
| ● 6 x 25 Gigabit Ethernet SR Fiber Fail-to-Wire (FTW) Network Module |
| ● 6 x 25 Gigabit Ethernet LR Fiber Fail-to-Wire (FTW) Network Module |
| Maximum number of interfaces |
| Expansion (2 Slots) |
Total Maximum Ports |
| + 16 (via 2x 8-port modules, SFP28) |
28 Ports |
| + 8 (via 2x 4-port modules, QSFP56) |
12 Ports |
| + 4 (via 2x 2-port modules, QSFP-DD) |
4 Ports |
| N/A |
2 Ports |
| Note: 50G Support: Only the 12 Fixed SFP56 ports support native 50G speeds (Modules listed are SFP28 maxing at 25G). |
| FTW (Fail-to-Wire): If using Fail-to-Wire modules (6-ports each), the total 1/10/25G count would be 24 ports (12 Fixed + 12 Module). |
| The above port counts do not factor in the breakout capability supported by different interfaces. |
| Console port |
1 x RJ-45 console |
| USB port |
1 USB 3.0 |
| Storage |
2 x 7.2 TB |
| Power over Ethernet |
NA |
| Transceiver support |
Refer to Cisco Secure Firewall (CSF) 6100 Hardware Installation Guide |
| Mean Time Between Failure (MTBF) |
Chassis: 206,000 Hours |
| Chassis dimensions (HxWxD) |
3.5” H x 16.9” W x 32.5” D (8.89 cm x 42.93 cm x 82.55 cm) |
| Weight |
66lbs (29.94kg), fully loaded |
| Cooling |
4 Field Replaceable Fan module; every module has 2 fans |
| Rack mountable |
Yes, mount rails included (4-post EIA-310-D rack) |
| Power Supply Details |
| Configuration |
Dual high-voltage AC/DC power supplies. |
| ● High Line AC: Up to 3000W per power supply, hot-swappable, load-sharing redundancy. |
| ● Low Line AC: Up to 1500W per power supply, load sharing with no redundancy. |
| Dual low-voltage DC power supplies offered. |
| ● Both Inputs Connected: Up to 3000W per power supply, hot-swappable, load-sharing redundancy. |
| ● One Input Connected: Up to 1500W per power supply, load sharing with no redundancy. |
| AC input voltage |
100 to 120 VAC (HVAC low line); 200 to 277 VAC (HVAC high line) |
| AC input frequency |
50—60 Hz |
| HVDC input voltage |
240 to 380 VDC |
| LVDC input voltage |
—48VDC to —60VDC |
| AC current draw, maximum |
14 Amperes (high line AC) |
| System HVDC current draw, maximum |
12 Amperes |
| System LVDC current draw, maximum |
33 Amperes |
| Power consumption, typical |
2010 Watts |
| Power consumption, maximum |
2760 Watts |
| Redundancy |
1+1 Redundancy |
| ● Redundant only with dual HVAC, HVDC, or dual-input LVDC. |
| ● LVAC and single-input DC do not support redundancy. |
| Operating Range |
| Temperature: operating |
32°F to 104°F (0°C to 40°C) |
| Humidity: operating |
5% to 90% (non-condensing) |
| Altitude: operating |
0 to 10,000 ft. |
| De-rate the maximum operating temperature 1°C/1K-ft. above 6000 ft. |
| Acoustic noise |
Sound Pressure: <=74 dBA (typical), <= 90 dBA (maximum) |
| Sound Power: <=81 dB (typical), <=98 dB (maximum) |
| Non-operating/storage environment |
| Temperature: nonoperating |
–40°F to 158°F (–40°C to 70°C) |
| Humidity: nonoperating |
5% to 95% (non-condensing) |
| Altitude: nonoperating |
40,000 ft. |
| Performance : Cisco Secure Firewall 6170 Series with ASA software |
| Stateful inspection firewall throughput (1500 B UDP)[2] |
750 Gbps |
| Stateful inspection firewall throughput (HTTP 1024 Byte) |
750 Gbps |
| IPsec VPN throughput (450B UDP L2L test) |
370 Gbps |
| Scalability : Cisco Secure Firewall 6170 Series with ASA software |
| New connections per second |
5.5 Million |
| Concurrent firewall connections |
180 Million |
| Maximum VPN Peers |
60 K |
| High availability |
Active/Active and Active/Standby |
| Security contexts |
Included 10, maximum 250 |
| Clustering |
Up to 16 |
| Compliance: Cisco 6100 Series regulatory, safety, and EMC compliance |
| Regulatory compliance |
Products comply with CE markings per directives 2014/30/EU and 2006/108/EC |
| Safety |
● UL 62368-1 |
| ● UL 60950-1 |
| ● CAN/CSA-C22.2 No. 62368-1 |
| ● CAN CSA C22.2 60950-1 |
| ● EN 62368-1 |
| ● IEC 62368-1 |
| ● AS/NZS 62368.1 |
| ● GB4943.1 |
| EMC: Emissions |
● FCC 47CFR15 Class A |
| ● AS/NZS CISPR 32 Class A |
| ● EN55032/CISPR 32 Class A |
| ● ICES-003 Class A |
| ● VCCI Class A |
| ● KS C 9832 Class A |
| ● CNS-15936 Class A |
| ● EN61000-3-2 Power Line Harmonics |
| ● EN61000-3-3 Voltage Changes, Fluctuations, and Flicker |
| EMC: Immunity |
● IEC/EN61000-4-2 Electrostatic Discharge Immunity |
| ● IEC/EN61000-4-3 Radiated Immunity |
| ● IEC/EN61000-4-4 EFT-B Immunity |
| ● IEC/EN61000-4-5 Surge |
| ● IEC/EN61000-4-6 Immunity to Conducted Disturbances |
| ● IEC/EN61000-4-11 Voltage Dips, Short Interruptions, and Voltage Variations |
| ● KS C 9835 |
| EMC: ETSI/EN |
● EN 300 386 Telecommunications Network Equipment (EMC) |
| ● EN55032/CISPR32 Multimedia Equipment (Emissions) |
| ● EN55035/CISPR 35 Multimedia Equipment (Immunity) |
| ● EN61000-6-1, EN61000-6-2 Generic Immunity Standards |
| License for Cisco Secure Firewall 6170 with ASA software (option) |
| L-CSF6170-BSE |
Cisco Secure Firewall 6170 Base License (available default) |
| L-CSF6100-ENC-K9 |
Cisco Secure Firewall 6100 Strong Encryption (3DES/AES) (available) |
| L-CSF6100-ASASC-10 |
Cisco Secure Firewall 6100 - Add 10 Security Context License |
| L-CSF6100-ASA-CAR |
Cisco Secure Firewall 6100 ASA Carrier License |
Những yếu tố nào giúp Cisco Secure Firewall CSF6170-A-ASA-K9 đảm bảo tính sẵn sàng và độ tin cậy cho hệ thống?
Cisco Secure Firewall CSF6170-A-ASA-K9 được thiết kế cho môi trường hoạt động liên tục với nguồn điện kép 1+1 Redundancy, 4 mô-đun quạt có thể thay thế nóng (Hot-Swappable) và hỗ trợ High Availability ở cả hai chế độ Active/Active và Active/Standby. Thiết bị còn hỗ trợ Cluster tối đa 16 firewall, 250 Security Context và 60.000 VPN Peers, giúp duy trì hoạt động ổn định ngay cả khi có sự cố phần cứng hoặc khi hệ thống cần mở rộng, đảm bảo tính liên tục và độ sẵn sàng cao cho các ứng dụng quan trọng của doanh nghiệp.
Vì sao Cisco Secure Firewall CSF6170-A-ASA-K9 có khả năng mở rộng và đáp ứng tốt nhu cầu phát triển trong tương lai?
Cisco Secure Firewall CSF6170-A-ASA-K9 hỗ trợ nhiều loại Network Module từ 1G, 10G, 25G, 40G, 100G, 200G đến 400G, cho phép doanh nghiệp mở rộng hệ thống mà không cần thay thế thiết bị. Ngoài 12 cổng SFP56 và 4 cổng QSFP56 tích hợp sẵn, thiết bị còn có 2 khe mở rộng để bổ sung thêm nhiều cổng mạng tốc độ cao hoặc các Fail-to-Wire Module, giúp tăng tính linh hoạt trong triển khai và dễ dàng đáp ứng nhu cầu mở rộng hạ tầng trong tương lai.
Cisco Secure Firewall CSF6170-A-ASA-K9 có những cải tiến gì về hiệu năng so với các firewall thế hệ thấp hơn?
Cisco Secure Firewall CSF6170-A-ASA-K9 được tối ưu cho các hệ thống mạng có lưu lượng cực lớn với 750 Gbps Stateful Firewall Throughput, 370 Gbps IPsec VPN Throughput, hỗ trợ 5,5 triệu kết nối mới mỗi giây và 180 triệu kết nối đồng thời. So với các firewall hiệu năng thấp hơn trong cùng dòng, thiết bị xử lý được nhiều phiên kết nối hơn trong thời gian ngắn, đáp ứng tốt các trung tâm dữ liệu, nhà cung cấp dịch vụ và doanh nghiệp quy mô lớn có yêu cầu bảo mật và hiệu năng rất cao.