Cisco ASA 5506-X with FirePOWER Services Security Appliance / Firewall

MX58853 ASA 5506-X with FirePOWER Services Security Appliance / Firewall
MX58853 ASA 5506-X with FirePOWER Services Security Appliance / Firewall

Product Info

Stop more threats with the threat-focused 5500-X NGFW

Meet the industry’s first adaptive, threat-focused next-generation firewall (NGFW) designed for a new era of threat and advanced malware protection. Cisco® ASA with FirePOWER Services delivers integrated threat defense for the entire attack continuum - before, during, and after an attack. How? By combining the proven security capabilities of the Cisco ASA firewall with the industry-leading Sourcefire® threat and Advanced Malware Protection (AMP) features together in a single device. The solution uniquely extends the capabilities of the Cisco ASA 5500-X Series Next-Generation Firewalls beyond what today’s NGFW solutions are capable of. Whether you need protection for a small or midsized business, a distributed enterprise, or a single data center, Cisco ASA with FirePOWER Services provides the needed scale and context in a NGFW solution.

Superior Multilayered Protection

Cisco ASA with FirePOWER Services brings distinctive threat-focused next-generation security services to the Cisco ASA 5500-X Series Next-Generation Firewalls. It provides comprehensive protection from known and advanced threats, including protection against targeted and persistent malware attacks (Figure 1). Cisco ASA is the world’s most widely deployed, enterprise-class stateful firewall. Cisco ASA with FirePOWER Services features these comprehensive capabilities:

  • Site-to-site and remote access VPN and advanced clustering provide highly secure, high-performance access and high availability to help ensure business continuity.
  • Granular Application Visibility and Control (AVC) supports more than 4,000 application-layer and risk-based controls that can launch tailored intrusion prevention system (IPS) threat detection policies to optimize security effectiveness.
  • The industry-leading Cisco ASA with FirePOWER next-generation IPS (NGIPS) provides highly effective threat prevention and full contextual awareness of users, infrastructure, applications, and content to detect multivector threats and automate defense response.
  • Reputation- and category-based URL filtering offer comprehensive alerting and control over suspicious web traffic and enforce policies on hundreds of millions of URLs in more than 80 categories.
  • AMP provides industry-leading breach detection effectiveness, sandboxing, a low total cost of ownership, and superior protection value that helps you discover, understand, and stop malware and emerging threats missed by other security layers.

Unprecedented Network Visibility

Cisco ASA with FirePOWER Services is centrally managed by the Cisco Firepower Management Center (formerly known as Cisco FireSIGHT Management Center), which provides security teams with comprehensive visibility into and control over activity within the network. Such visibility includes users, devices, communication between virtual machines, vulnerabilities, threats, client-side applications, files, and web sites. Holistic, actionable indications of compromise (IoCs) correlate detailed network and endpoint event information and provide further visibility into malware infections. Cisco’s enterprise-class management tools help administrators reduce complexity with unmatched visibility and control across NGFW deployments. Cisco Firepower Management Center also provides content awareness with malware file trajectory that aids infection scoping and root cause determination to speed time to remediation.

Cisco Security Manager provides scalable and centralized network operations workflow management. It integrates a powerful suite of capabilities; including policy and object management, event management, reporting, and troubleshooting for Cisco ASA firewall functions when utilizing Cisco Firepower Management Center.

For local, on-device management including deployments for small and midsized businesses, Cisco Adaptive Security Device Manager (ASDM) 7.3.x provides, access control and advanced threat defense management. ASDM V 7.3.x provides an enhanced user interface that provides quick views on trends and the ability to drill down for further analysis.

Reduced Costs and Complexity

Cisco ASA with FirePOWER Services incorporates an integrated approach to threat defense, reducing capital and operating costs and administrative complexity. It smoothly integrates with the existing IT environment, work stream, and network fabric. The appliance family is highly scalable, performs at up to multigigabit speeds, and provides consistent and robust security across branch, Internet edge, and data centers in both physical and virtual environments.

With Cisco Firepower Management Center, administrators can streamline operations to correlate threats, assess their impact, automatically tune security policy, and easily attribute user identities to security events. Cisco Firepower Management Center continually monitors how the network is changing over time. New threats are automatically assessed to determine which ones can affect your business. Responses are then focused on remediation and network defenses are adapted to changing threat conditions. Critical security activities such as policy tuning are automated, saving time and effort, while protections and countermeasures are maintained in an optimal state.

Cisco Firepower Management Center integrates easily with third-party security solutions through the eStreamer API to streamline operation workflows and fit existing network fabrics.


  • Next-generation firewall
    Industry’s first threat-focused NGFW; provides ASA firewall functionality, advanced threat protection, and advanced breach detection and remediation combined in a single device
  • Proven ASA firewall
    Rich routing, stateful firewall, Network Address Translation, and dynamic clustering for high-performance, highly secure, and reliable access with Cisco AnyConnect® VPN
  • Market-leading NGIPS
    Superior threat prevention and mitigation for both known and unknown threats
  • Advanced malware protection
    Detection, blocking, tracking, analysis, and remediation to protect the enterprise against targeted and persistent malware attacks
  • Full contextual awareness
    Policy enforcement based on complete visibility of users, mobile devices, client-side applications, communication between virtual machines, vulnerabilities, threats, and URLs
  • Application control and URL filtering
    Application-layer control (over applications, geolocations, users, websites) and ability to enforce usage and tailor detection policies based on custom applications and URLs
  • Enterprise-class management
    Dashboards and drill-down reports of discovered hosts, applications, threats, and indications of compromise for comprehensive visibility
  • Streamlined operations automation
    Lower operating cost and administrative complexity with threat correlation, impact assessment, automated security policy tuning, and user identification
  • Purpose-built, scalable
    Highly scalable security appliance architecture that performs at up to multigigabit speeds; consistent and robust security across small office, branch offices, Internet edge, and data centers in either physical and virtual environments
  • On-device management
    Simplifies advanced threat defense management for small and medium sized business with small scale deployments
  • Remote Access VPN
    Extends secure corporate network access beyond corporate laptops to personal mobile devices, regardless of physical location; support for Cisco AnyConnect Secure Mobility Solution, with granular, application-level VPN capability, as well as native Apple iOS and Android VPN clients
  • Site-to-site VPN
    Protect traffic, including VoIP and client-server application data, across the distributed enterprise and branch offices
  • Third-party technology ecosystem
    Open API that enables the third-party technology ecosystem to integrate with existing customer work streams
  • Integration with Snort and OpenAppID
    Open source security integration with Snort and OpenAppID for access to community resources and ability to easily customize security to address new and specific threats and applications quickly
  • Collective Security intelligence (CSI)
    Unmatched security and web reputation intelligence provides real-time threat intelligence and security protection


Model Number ASA5506-K9
Appliance Type Next-Generation Firewall (NGFW)
Number of Ports 8 x 1 Gigabit Ethernet (GE)
Dedicated management port Yes (To be shared with FirePOWER Services), 10/100/1000
Serial port 1 RJ-45 and Mini USB console
Integrated Wireless Access Point N/A
Expansion slot N/A
User-accessible Flash slot No
USB ports USB port type ‘A’, High Speed 2.0
Storage 50 GB mSata Solid-state Drive
Memory 4 GB
System flash 8 GB
System bus Multibus architecture
Throughput: Application Control (AVC) 250 Mbps
Throughput: Application Control (AVC) and IPS 125 Mbps
Maximum concurrent sessions 20,000; 50000¹

1 Higher specifications are associated with the Security Plus license.

Maximum New Connections per second 5,000
Supported applications More than 3,000
URL categories 80+
Number of URLs categorized More than 280 million
Centralized configuration, logging, monitoring, and reporting Multi-device Cisco Security Manager (CSM) and Cisco Firepower Management Center
On-Device Management ASDM (version 7.3 or higher required)
Stateful inspection throughput (maximum) 750 Mbps
Stateful inspection throughput (multiprotocol) 300 Mbps
Triple Data Encryption Standard/Advanced Encryption Standard (3DES/AES) VPN throughput 100 Mbps
Users/nodes Unlimited
IPsec site-to-site VPN peers 10; 50¹

1 Higher specifications are associated with the Security Plus license.

Cisco Cloud Web Security users For detailed sizing guidance see the CWS Connector Sizing for ASA 5500 and ASA 5500-X
Cisco AnyConnect Plus/Apex VPN maximum simultaneous connections 50

Separately licensed feature. For AnyConnect, licenses are purchased based on feature tier (Plus/Apex), term and authorized user license.

Virtual interfaces (VLANs) 5; 30¹

1 Higher specifications are associated with the Security Plus license.

Security contexts (included; maximum) N/A
High availability Requires Security Plus License; Active/Standby
AC range line voltage External, 90 to 240 volts alternating current (VAC)
AC normal line voltage 90 to 240V AC
AC maximum input current N/A
AC frequency 50 / 60 Hz
Dual-power supplies None
Fans None
Noise 0 dBA
Temperature Operating: 0 to 40° C (32 to 104° F)
Nonoperating: -25 to 70° C (-13 to 158° F)
Operating Humidity Operating: 90% Noncondensing
Nonoperating: 10 - 90% Noncondensing
Altitude Operating: 3048 m / 10,000 ft (max)
Nonoperating: 15,000 ft (max)
Form Factor Desktop, rack mountable
Rack mountable Yes. Separate kit must be ordered.
Dimensions 1.72 x 7.871 x 9.23 in.
Weight 4 lb (1.82 kg)