| Model |
FPR1140-FTD-HA-BUN |
| Hardware specifications |
| Form factor |
Rack mount, 1U |
| Network interfaces |
8 x RJ-45, 4 x SFP |
| Power over Ethernet |
N/A |
| Management interfaces |
1x 1000BASE-T, 1x Serial console (RJ-45) |
| USB |
1 x USB 3.0 Type-A (500mA) |
| Storage |
1 x 200 GB |
| Dimensions (H x W x D) |
1.72 x 17.2 x 10.58 in. |
| Power supply configuration |
Integrated, single AC input |
| AC input voltage |
100 to 240V AC |
| AC maximum current draw |
< 2A at 100V, < 1A at 240V |
| AC maximum power draw |
100W |
| AC frequency |
50 to 60 Hz |
| AC efficiency |
>85% at 50% load |
| Fans |
1 integrated fan |
| Noise |
34.2 dBA @ 25C, 56.8 dBA at highest system performance |
| Rack mounting |
2-post mounting Brackets included. |
| Weight |
8 lb (3.6 kg) |
| Temperature: operating |
32 to 104°F (0 to 40°C) |
| Temperature: nonoperating |
-13 to 158°F (-25 to 70°C |
| Humidity: operating |
90% noncondensing |
| Humidity: nonoperating |
10 to 90% noncondensing |
| Altitude: operating |
9,843 ft (max), 3,000 m (max) |
| Altitude: nonoperating |
15,000 ft (max) |
| Performance for Cisco Firepower 1040 with the Threat Defense (FTD) software |
| Throughput: Firewall (FW) + Application Visibility and Control (AVC) (1024B) |
3.3 Gbps |
| Throughput: FW + AVC + Intrusion Prevention System (IPS) (1024B) |
3.3 Gbps |
| Maximum concurrent sessions, with AVC |
400K |
| Maximum new connections per second, with AVC |
22K |
| Transport Layer Security (TLS) |
1.2 Gbps |
| Throughput: NGIPS (1024B) |
3.5 Gbps |
| IPSec VPN throughput(1024B TCP w/Fastpath) |
1.4 Gbps |
| Maximum VPN Peers |
400 |
| Cisco Device Manager (local聽management) |
Yes |
| Centralized management |
Centralized configuration, logging, monitoring, and reporting are performed by the Threat Defense Manager (FMC) or, alternatively, from the cloud with Cisco Defense Orchestrator |
| AVC |
Standard, supporting more than 4000 applications, as well as geolocations, users, and websites |
| AVC: OpenAppID support for custom, open-source application detectors |
Standard |
| Cisco Security Intelligence |
Standard, with IP, URL, and DNS threat intelligence |
| Cisco IPS |
Available; can passively detect endpoints and infrastructure for threat correlation and Indicators of Compromise (IoC) intelligence |
| Cisco Malware Defense for Networks |
Available; enables detection, blocking, tracking, analysis, and containment of targeted and persistent malware, addressing the attack continuum both during and after attacks. Integrated threat correlation with Cisco AMP for Endpoints is also optionally available |
| Cisco Malware Analytics sandboxing |
Available |
| URL filtering: number of categories |
More than 80 |
| URL filtering: number of URLs categorized |
More than 280 million |
| Automated threat feed and IPS signature updates |
class-leading Collective Security Intelligence (CSI) from the Cisco Talos® group (https://www.cisco.com/c/en/us/products/security/talos.html) |
| Third-party and open- source ecosystem |
Open API for integrations with third-party products; Snort® and OpenAppID community resources for new and specific threats |
| High availability and clustering |
Active/standby |
| Cisco Trust Anchor Technologies |
Cisco Firepower 1000 Series platforms include Trust Anchor Technologies for supply chain and software image assurance. Please see the section below for additional details |
| Regulatory, safety, and EMC compliance on Cisco Firepower 1000 Series |
| Regulatory compliance |
Products comply with CE markings per directives 2004/108/EC and 2006/108/EC |
| Safety |
UL 60950-1 |
| CAN/CSA-C22.2 No. 60950-1 |
| EN 60950-1 |
| IEC 60950-1 |
| AS/NZS 60950-1 |
| GB4943 |
| EMC: emissions |
47CFR Part 15 (CFR 47) Class A (FCC Class A) |
| AS/NZS CISPR22 Class A |
| CISPR22 CLASS A |
| EN55022 Class A |
| ICES003 Class A |
| VCCI Class A |
| EN61000-3-2 |
| EN61000-3-3 |
| KN22 Class A |
| CNS13438 Class A |
| EN300386 |
| CISPR24 |
| EMC: immunity |
EN55024 |
| CISPR24 |
| EN300386 |
| KN24 |
| TVCN 7317 |
| EN-61000-4-2, EN-61000-4-3, EN-61000-4-4, EN-61000-4-5, EN-61000-4-6,EN-61000-4-8, EN61000-4-11 |
Cisco FPR1140-FTD-HA-BUN hỗ trợ những công nghệ nào để phát hiện các mối đe dọa chưa từng biết đến?
Ngoài IPS và Security Intelligence, FPR1140-FTD-HA-BUN còn hỗ trợ Cisco Malware Defense for Networks, Malware Analytics Sandboxing, OpenAppID và Snort. Các công nghệ này giúp phân tích hành vi của tệp tin và lưu lượng mạng, nhận diện mã độc mới hoặc các kỹ thuật tấn công chưa có chữ ký, từ đó nâng cao khả năng phát hiện và ứng phó với các mối đe dọa nâng cao (Advanced Threats).
Khả năng quản lý tập trung của Cisco FPR1140-FTD-HA-BUN mang lại lợi ích gì khi doanh nghiệp có nhiều chi nhánh?
Thiết bị FPR1140-FTD-HA-BUN hỗ trợ quản lý tập trung thông qua Cisco Firepower Management Center (FMC) hoặc nền tảng đám mây Cisco Defense Orchestrator (CDO). Quản trị viên có thể triển khai chính sách bảo mật, theo dõi nhật ký, giám sát sự kiện và cập nhật cấu hình cho nhiều firewall từ một giao diện duy nhất, giúp giảm thời gian vận hành và đảm bảo chính sách bảo mật được áp dụng đồng nhất trên toàn hệ thống.
Cisco FPR1140-FTD-HA-BUN sử dụng nền tảng tình báo mối đe dọa Cisco Talos như thế nào để bảo vệ hệ thống?
FPR1140-FTD-HA-BUN tích hợp Cisco Talos Security Intelligence, cho phép tự động cập nhật cơ sở dữ liệu về IP, URL, DNS độc hại và chữ ký IPS mới nhất. Nhờ đó, firewall có thể nhận diện và ngăn chặn các mối đe dọa mới xuất hiện mà không cần chờ quản trị viên cấu hình thủ công, giúp doanh nghiệp luôn được bảo vệ trước các cuộc tấn công đang diễn ra.