| Model |
FPR3110-NGFW-K9 |
| Hardware specifications |
| Network modules |
8 x 1/10G Options |
| Integrated I/O |
8 x 10M/100M/1G BASE-T Ethernet interfaces (RJ-45)
8 x 1/10 Gigabit (SFP) Ethernet interfaces |
| Integrated network management ports |
1 x 1/10G SFP |
| Storage |
1 x 900 GB, 1 spare slot |
| Serial port |
1 x RJ-45 console |
| USB |
1 x USB 3.0 Type-A (900mA) |
| Dimensions (H x W x D) |
4.4 x 43.3 x 50.8 cm |
| Form factor (rack units) |
1RU |
| Power Supplies |
| Configuration |
Single 400W AC, Dual 400W AC optional
Single/Dual 400W DC optional |
| AC input voltage |
100 to 240V AC |
| AC maximum input current |
< 6A at 100V |
| AC maximum output power |
400W |
| AC frequency |
50/60 Hz (nominal) |
| AC efficiency |
> 89% at 50% load |
| DC input voltage |
-48V to -60VDC |
| DC maximum input current |
< 12.5A at -48V |
| DC maximum output power |
400W |
| DC efficiency |
>88% at 50% load |
| Redundancy |
1 + 1 AC or DC with dual supplies |
| Fans |
2 hot-swappable fan modules (with 2 fans each) |
| Noise |
65 dBA @ 25C; 74 dBA maximum |
| Rack mountable |
Yes. Fixed mount brackets optional. (2-post). Mount rails included (4-post EIA-310-D rack) |
| Weight |
23 lbs (10.5kg) 1 x power supplies, 1 x NM, fan module, 1 x SSD |
| Temperature: operating |
32 to 104 ℉ (0 to 40℃) |
| Temperature: non-operating |
-4 to 149℉ (-20 to 65℃) |
| Humidity: operating |
10 to 85% non-condensing |
| Humidity:non-operating |
5 to 95% non-condensing |
| Altitude: operating |
10,000 ft (max) |
| Altitude: non-operating |
40,000 ft (max) |
| Fans |
3 Duals fan modules (FRU). Each module has two fans |
| Noise |
Sound Pressure: <=78 dBA (typical), <=84 dBA (maximum) |
| Rack mountable |
Yes, mount rails included (4-post EIA-310-D rack) |
| Weight |
46 lbs (19.5 kgs); 2 x power supplies; 2 x NMs, 3 x fan-modules; 36 lbs (16.3 kgs): no power supplies, no NMs, no fans |
| Temperature: operating |
32 to 102 ℉ (0 to 40℃), at sea level |
| Temperature: non-operating |
-40 to 149℉ (-40 to 65℃) |
| Humidity: operating |
5 to 95% non-condensing |
| Humidity:non-operating |
5 to 95% non-condensing |
| Altitude: operating |
10,000 ft (max) |
| Altitude: non-operating |
40,000 ft (max) |
| Performance specifications and feature highlights with the Cisco Secure Firewall Threat Defense (TD) image |
| Throughput: FW + AVC (1024B) |
17.0 Gbps |
| Throughput: FW + AVC + IPS (1024B) |
17.0 Gbps |
| Maximum concurrent sessions, with AVC |
2 Million |
| New connections Per Second with, AVC |
130,000 |
| TLS |
4.8 Gbps |
| Throughput: NGIPS (1024B) |
17.0 Gbps |
| IPSec VPN Throughput (1024B TCP w/Fastpath) |
8 Gbps |
| Projected IPSec VPN throughput (1024B TCP w/Fastpath) with VPN Offload (FTP 7.2) |
11.0 Gbps |
| Maximum VPN Peers |
3,000 |
| Local On-device Management |
Yes |
| Centralized Management |
Centralized configuration, logging, monitoring, and reporting are performed by the Firewall Management Center or alternatively in the cloud with Cisco Defense Orchestrator |
| Application Visibility and Control (AVC) |
Standard, Supporting more than 4000 applications, as well as gelocation, users, and websites |
| AVC: OpenAppID Support for custom, open source application detectors |
Standard |
| Cisco Security Intelligence |
Standard with IP, URL, and DNS Threat intelligence |
| Cisco Secure IPS |
Available: can passively detect endpoints and infrastructure for threat correlation an indicators of Compromise (IOC) intelligence |
| Cisco Malware Defense |
Available: enables detection, blocking, tracking, analysis, and containment of targeted and persistent malware, addressing the attack continuum both during and after attacks, integrated threat correlation with CISCO Secure Endpoint is also optionally available |
| Cisco Secure Malware Analytics |
Available |
| URL Filtering: Number of Categories |
More than 80 |
| URL Filtering: Number of URL categorized |
More than 280 million |
| Automated Threat Feed and IPS signature updates |
Yes: class-ending Collective Security Intelligence (CSI) from the Cisco Talos Group |
| Third-party and open-source ecosystem |
Open API for integrations with third-party products; Snort and OpenAppID community resources for new and specific threats |
| High Availability & Clustering |
Active/active, Active/standby. |
| Cisco Secure Firewall 3100 Series allows clustering of up 8 chassis (no clustering on 3105) |
| Cisco Trust Anchor Technologies |
Secure Firewall 3100 Series platforms include Trust Anchor Technologies for supply chain and software image assurance. Please see the section below for additional details |
Cisco Secure Firewall FPR3110-NGFW-K9 có đảm bảo tính sẵn sàng cao cho hệ thống mạng không?
Có. FPR3110-NGFW-K9 hỗ trợ High Availability với chế độ Active/Active và Active/Standby, đồng thời hỗ trợ Firewall Clustering lên đến 8 chassis. Thiết bị còn được trang bị nguồn dự phòng 1+1 (AC hoặc DC) và quạt hot-swappable, giúp duy trì hoạt động liên tục và giảm thiểu thời gian gián đoạn khi xảy ra sự cố.
FPR3110-NGFW-K9 có hỗ trợ các công nghệ bảo mật hiện đại để phát hiện và ngăn chặn mối đe dọa không?
Có. Thiết bị tích hợp Cisco Secure IPS, Cisco Security Intelligence, Cisco Malware Defense, Cisco Secure Malware Analytics, URL Filtering và cập nhật chữ ký bảo mật tự động từ Cisco Talos. Ngoài ra còn hỗ trợ OpenAppID và Snort, giúp tăng khả năng nhận diện và ngăn chặn các mối đe dọa mới.
FPR3110-NGFW-K9 có khả năng xử lý đồng thời nhiều kết nối và lưu lượng lớn như thế nào?
FPR3110-NGFW-K9 hỗ trợ 2 triệu phiên kết nối đồng thời và 130.000 kết nối mới mỗi giây, cùng thông lượng NGFW và IPS đạt 17 Gbps. Nhờ đó, thiết bị đáp ứng tốt các hệ thống có lưu lượng truy cập lớn, nhiều người dùng và nhiều ứng dụng hoạt động cùng lúc.