| Model |
FPR1120-FTD-HA-BUN |
| Hardware specifications |
| Form factor |
Rack mount, 1U |
| Network interfaces |
8 x 1000BASE-T, 4 x SFP |
| Power over Ethernet |
NA |
| Management interfaces |
1x 1000BASE-T, 1x Serial console (RJ-45) |
| USB |
1 x USB 3.0 Type-A (500mA) |
| Storage |
1 x 200 GB |
| Dimensions (H x W x D) |
1.72 x 17.2 x 10.58 in. |
| Power supply configuration |
Integrated, single AC input |
| AC input voltage |
100 to 240V AC |
| AC maximum current draw |
< 2A at 100V, < 1A at 240V |
| AC maximum power draw |
100W |
| AC frequency |
50 to 60 Hz |
| AC efficiency |
>85% at 50% load |
| Fans |
1 integrated fan |
| Noise |
31.7 dBA @ 25C, 56.8 dBA at highest system performance |
| Rack mounting |
2-post mounting Brackets included. |
| Weight |
8 lb (3.6 kg) |
| Temperature: operating |
32 to 104°F (0 to 40°C) |
| Temperature: nonoperating |
-13 to 158°F (-25 to 70°C |
| Humidity: operating |
90% noncondensing |
| Humidity: nonoperating |
10 to 90% noncondensing |
| Altitude: operating |
9,843 ft (max), 3,000 m (max) |
| Altitude: nonoperating |
15,000 ft (max) |
| Performance for Cisco Firepower 1020 with the Threat Defense (FTD) software |
| Throughput: Firewall (FW) + Application Visibility and Control (AVC) (1024B) |
2.3 Gbps |
| Throughput: FW + AVC + Intrusion Prevention System (IPS) (1024B) |
2.3 Gbps |
| Maximum concurrent sessions, with AVC |
200K |
| Maximum new connections per second, with AVC |
15K |
| Transport Layer Security (TLS) |
850 Mbps |
| Throughput: NGIPS (1024B) |
2.6 Gbps |
| IPSec VPN throughput(1024B TCP w/Fastpath) |
1.2 Gbps |
| Maximum VPN Peers |
150 |
| Cisco Device Manager (local management) |
Yes |
| Centralized management |
Centralized configuration, logging, monitoring, and reporting are performed by the Threat Defense Manager (FMC) or, alternatively, from the cloud with Cisco Defense Orchestrator |
| AVC |
Standard, supporting more than 4000 applications, as well as geolocations, users, and websites |
| AVC: OpenAppID support for custom, open-source application detectors |
Standard |
| Cisco Security Intelligence |
Standard, with IP, URL, and DNS threat intelligence |
| Cisco IPS |
Available; can passively detect endpoints and infrastructure for threat correlation and Indicators of Compromise (IoC) intelligence |
| Cisco Malware Defense for Networks |
Available; enables detection, blocking, tracking, analysis, and containment of targeted and persistent malware, addressing the attack continuum both during and after attacks. Integrated threat correlation with Cisco AMP for Endpoints is also optionally available |
| Cisco Malware Analytics sandboxing |
Available |
| URL filtering: number of categories |
More than 80 |
| URL filtering: number of URLs categorized |
More than 280 million |
| Automated threat feed and IPS signature updates |
class-leading Collective Security Intelligence (CSI) from the Cisco Talos® group (https://www.cisco.com/c/en/us/products/security/talos.html) |
| Third-party and open- source ecosystem |
Open API for integrations with third-party products; Snort® and OpenAppID community resources for new and specific threats |
| High availability and clustering |
Active/standby |
| Cisco Trust Anchor Technologies |
Cisco Firepower 1000 Series platforms include Trust Anchor Technologies for supply chain and software image assurance. Please see the section below for additional details |
| Regulatory, safety, and EMC compliance on Cisco Firepower 1000 Series |
| Regulatory compliance |
Products comply with CE markings per directives 2004/108/EC and 2006/108/EC |
| Safety |
UL 60950-1 |
| CAN/CSA-C22.2 No. 60950-1 |
| EN 60950-1 |
| IEC 60950-1 |
| AS/NZS 60950-1 |
| GB4943 |
| EMC: emissions |
47CFR Part 15 (CFR 47) Class A (FCC Class A) |
| AS/NZS CISPR22 Class A |
| CISPR22 CLASS A |
| EN55022 Class A |
| ICES003 Class A |
| VCCI Class A |
| EN61000-3-2 |
| EN61000-3-3 |
| KN22 Class A |
| CNS13438 Class A |
| EN300386 |
| CISPR24 |
| EMC: immunity |
EN55024 |
| CISPR24 |
| EN300386 |
| KN24 |
| TVCN 7317 |
| EN-61000-4-2, EN-61000-4-3, EN-61000-4-4, EN-61000-4-5, EN-61000-4-6,EN-61000-4-8, EN61000-4-11 |
Cisco FPR1120-FTD-HA-BUN có thể phát hiện và ngăn chặn các mối đe dọa hiện đại bằng những công nghệ nào?
Cisco FPR1120-FTD-HA-BUN có chức năng firewall truyền thống, ngoài ra thiết bị còn tích hợp Cisco Talos Security Intelligence, Intrusion Prevention System (IPS), Malware Defense, Malware Analytics Sandbox và URL Filtering. Sự kết hợp này cho phép phát hiện các cuộc tấn công theo thời gian thực, chặn truy cập đến các website độc hại, phân tích mã độc và hỗ trợ ứng phó hiệu quả với các mối đe dọa mới phát sinh trước khi chúng ảnh hưởng đến hệ thống.
Khi nào doanh nghiệp nên đầu tư phiên bản High Availability (HA) thay vì chỉ sử dụng một thiết bị firewall?
Phiên bản HA là lựa chọn phù hợp khi hệ thống không được phép gián đoạn, chẳng hạn như trung tâm dữ liệu, hệ thống ERP, dịch vụ VPN hoặc các ứng dụng kinh doanh hoạt động 24/7. Với cơ chế Active/Standby, thiết bị dự phòng sẽ tự động tiếp quản khi firewall chính gặp sự cố, giúp duy trì kết nối và giảm thiểu rủi ro ngừng dịch vụ.
Vì sao Cisco FPR1120-FTD-HA-BUN là lựa chọn phù hợp cho doanh nghiệp cần vừa bảo mật vừa đảm bảo hiệu suất mạng?
FPR1120-FTD-HA-BUN được thiết kế để duy trì hiệu năng ngay cả khi đồng thời kích hoạt các tính năng bảo mật như Firewall, IPS và Application Visibility and Control (AVC). Điều này giúp doanh nghiệp tăng cường khả năng phòng chống tấn công mà không làm ảnh hưởng đáng kể đến tốc độ xử lý lưu lượng, phù hợp cho văn phòng nhiều người dùng hoặc chi nhánh có lưu lượng truy cập lớn.