Scope and Source Limitations
This guide interprets the supplied Cisco ASA 5500 Series datasheet, document C78-742475-01, dated 03/20. It separates ASA firewall performance from Firepower Threat Defense (FTD) performance and identifies installation and procurement constraints.
The source describes six performance tiers and seven hardware models, including the ASA 5506H-X. It does not provide orderable bundle part numbers, interface-card SKUs, license ordering codes, MTBF figures, or warranty terms. Those omissions must remain open qualification items rather than assumed specifications.
The platforms are described as supporting either Cisco ASA Firewall or FTD. The ASA 5506 FTD measurements specifically use version 6.2.3. No separate performance measurements are supplied for the 5506H-X.
Complete Model and Expansion Matrix
The following matrix includes every appliance designation in the supplied text. “Compact,” “fixed,” and “expandable” describe the documented hardware arrangement, not separate ordering categories.
| Hardware model | Summary designation | Hardware category | Integrated data I/O | Expansion | Mounting |
|---|---|---|---|---|---|
| ASA 5506-X | ASA-5506 | Compact, fixed I/O | 8 x 1GE | None | Desktop, rack mountable |
| ASA 5506H-X | Not separately listed | Compact, fixed I/O | 4 x 1GE | None | Desktop, rack, wall, DIN-Rail |
| ASA 5508-X | ASA-5508 | Fixed I/O | 8 x 1GE | None | 1RU, 19-inch rack |
| ASA 5516-X | ASA-5516 | Fixed I/O | 8 x 1GE | None | 1RU, 19-inch rack |
| ASA 5525-X | ASA-5525 | Expandable appliance | 8 x 1GE | One card: 6 GE copper or 6 GE SFP | 1RU, 19-inch rack |
| ASA 5545-X | ASA-5545 | Expandable appliance | 8 x 1GE | One card: 6 GE copper or 6 GE SFP | 1RU, 19-inch rack |
| ASA 5555-X | ASA-5555 | Expandable appliance | 8 x 1GE | One card: 6 GE copper or 6 GE SFP | 1RU, 19-inch rack |
The six-model summary identifies integrated interfaces as RJ45. The optional six-port copper and SFP cards have no part numbers in the source.
Presales rule: A requirement for additional interfaces or SFP expansion directs evaluation toward the 5525-X, 5545-X, or 5555-X. Do not specify an expansion card or transceiver ordering code from this datasheet alone.
ASA Firewall Performance and Sizing
ASA throughput figures describe two different test profiles. The higher figures use 1500-byte UDP under ideal conditions. Multiprotocol results use primarily TCP-based applications, including HTTP, SMTP, FTP, IMAPv4, BitTorrent, and DNS.
| ASA model tier | Ideal stateful throughput | Multiprotocol throughput | Concurrent connections | New connections/sec | IPsec throughput |
|---|---|---|---|---|---|
| 5506 | 750 Mbps | 300 Mbps | 50,000 | 5,000 | 100 Mbps |
| 5508 | 1 Gbps | 500 Mbps | 100,000 | 10,000 | 175 Mbps |
| 5516 | 1.8 Gbps | 900 Mbps | 250,000 | 20,000 | 250 Mbps |
| 5525 | 2 Gbps | 1 Gbps | 500,000 | 20,000 | 300 Mbps |
| 5545 | 3 Gbps | 1.5 Gbps | 750,000 | 30,000 | 400 Mbps |
| 5555 | 4 Gbps | 2 Gbps | 1 million | 50,000 | 700 Mbps |
ASA IPsec measurements use a 450-byte UDP LAN-to-LAN test.
Use multiprotocol performance as the more relevant published comparison for mixed application traffic. It is still a test result, not a guaranteed production capacity.
Connection establishment and concurrent connection capacity require separate checks. For example, the 5516 and 5525 both list 20,000 new connections per second, although the 5525 doubles concurrent connection capacity from 250,000 to 500,000.
Presales rule: Moving to the next model does not necessarily improve every limiting metric. Select against throughput, connection population, connection churn, and VPN demand independently.
FTD Inspection Performance
FTD performance must be sized against the enabled inspection functions and packet profile. FW denotes firewall inspection; AVC denotes Application Visibility and Control.
| FTD model tier | FW + AVC, 1024B | FW + AVC + IPS, 1024B | FW + AVC, 450B | FW + AVC + IPS, 450B |
|---|---|---|---|---|
| 5506 | 250 Mbps | 125 Mbps | 100 Mbps | 75 Mbps |
| 5508 | 450 Mbps | 250 Mbps | 175 Mbps | 125 Mbps |
| 5516 | 850 Mbps | 450 Mbps | 275 Mbps | 200 Mbps |
| 5525 | 1.1 Gbps | 650 Mbps | 350 Mbps | 250 Mbps |
| 5545 | 1.5 Gbps | 1 Gbps | 500 Mbps | 350 Mbps |
| 5555 | 1.7 Gbps | 1.2 Gbps | 600 Mbps | 420 Mbps |
Standalone NGIPS throughput matches the corresponding FW + AVC + IPS figures at both published packet sizes.
| FTD model tier | Concurrent sessions with AVC | New connections/sec with AVC | TLS | IPsec VPN |
|---|---|---|---|---|
| 5506 | 50,000 | 3,000 | Not specified | 100 Mbps |
| 5508 | 100,000 | 7,500 | 250 Mbps | 175 Mbps |
| 5516 | 250,000 | 11,000 | 285 Mbps | 250 Mbps |
| 5525 | 500,000 | 11,500 | 270 Mbps | 300 Mbps |
| 5545 | 750,000 | 19,000 | 290 Mbps | 400 Mbps |
| 5555 | 1 million | 22,000 | 370 Mbps | 700 Mbps |
FTD IPsec testing uses 1024-byte TCP with Fastpath. Although its numerical results match the ASA table, the methodologies differ.
The TLS row lacks test-method detail. Its figures are not strictly increasing by model: the 5525 lists 270 Mbps versus 285 Mbps for the 5516. The dash for the 5506 is not sufficient evidence to declare TLS unsupported.
Inspection Sizing Rules
- For a 400 Mbps FW + AVC + IPS requirement using the published 1024-byte profile, the 5516 is the first listed tier exceeding that rate, at 450 Mbps.
- For the same requirement using the 450-byte profile, only the 5555 exceeds it, at 420 Mbps. That leaves little separation from the published test ceiling and requires further validation.
- A 1 Gbps inspected requirement matches the 5545’s 1024-byte result but exceeds every listed 450-byte result.
- Do not add TLS, VPN, and firewall figures together or assume simultaneous delivery of their individual maxima.
- Establish project-specific operating margin; the source provides no standard headroom percentage.
The datasheet explicitly warns that activated features, protocol mix, packet sizes, and software releases affect performance.
Security Functions and Management
FTD includes standard AVC covering more than 4,000 applications, plus geolocations, users, and websites. OpenAppID support for custom open-source application detectors is standard.
Cisco Security Intelligence is listed as standard, with IP, URL, and DNS threat intelligence. Additional listed capabilities include:
- Available NGIPS, including passive endpoint and infrastructure detection for threat correlation and Indicators of Compromise intelligence.
- Available AMP for Networks for malware detection, blocking, tracking, analysis, and containment.
- Optional integrated correlation with AMP for Endpoints.
- Available AMP Threat Grid sandboxing.
- URL filtering covering more than 80 categories and more than 280 million categorized URLs.
- Automated threat-feed and IPS-signature updates from Cisco Talos.
- An open integration API and Snort and OpenAppID community resources.
“Available” does not establish that a feature is included in a base purchase. The source does not provide subscription terms or license SKUs.
FTD supports local Firepower Device Manager across all six performance tiers. Centralized configuration, logging, monitoring, and reporting use Management Center or cloud-based Cisco Defense Orchestrator.
ASA uses web-based Adaptive Security Device Manager locally, with Cisco Security Manager or Cisco Defense Orchestrator for centralized management.
Trust Anchor Technologies are identified for supply-chain and software-image assurance. Implementation details are not included in the supplied text.
Availability, Contexts, and Platform Selection
| Model tier | ASA contexts included / maximum | ASA high availability | FTD high availability |
|---|---|---|---|
| 5506 | N/A | Active/standby | Active/standby |
| 5508 | 2 / 5 | Active/active and active/standby | Active/standby |
| 5516 | 2 / 5 | Active/active and active/standby | Active/standby |
| 5525 | 2 / 20 | Active/active and active/standby | Active/standby |
| 5545 | 2 / 50 | Active/active and active/standby | Active/standby |
| 5555 | 2 / 100 | Active/active and active/standby | Active/standby |
ASA scalability includes VPN load balancing. The FTD row is titled “High availability and clustering,” but specifies only active/standby. It does not establish additional clustering modes.
Engineering rule: Size an active/standby deployment so the surviving appliance can support the required workload. Do not treat the pair as twice the listed forwarding capacity.
Context maxima do not establish included entitlement beyond the stated two contexts. Licensing and deployment prerequisites require confirmation.
Storage, Console, and Management Interfaces
| Model | Storage | Console | Management entry |
|---|---|---|---|
| 5506-X | 50 GB mSATA | RJ-45 and Mini USB | Yes, shared |
| 5506H-X | 50 GB mSATA, heat tested | RJ-45 and Mini USB | Yes, shared |
| 5508-X | 80 GB mSATA | RJ-45 and Mini USB | Yes, shared |
| 5516-X | 100 GB mSATA | RJ-45 and Mini USB | Yes, shared |
| 5525-X | One slot, 120 GB MLC SED | RJ-45 | Yes, 1GE |
| 5545-X | Two slots, RAID 1, 120 GB MLC SED | RJ-45 | Yes, 1GE |
| 5555-X | Two slots, RAID 1, 120 GB MLC SED | RJ-45 | Yes, 1GE |
The first four models list Type A High Speed USB 2.0 without an explicit count. The remaining models list two USB 2.0 ports.
The shared-management wording does not describe the sharing mechanism. Confirm the intended management topology before finalizing port assignments.
Physical, Environmental, and Reliability Specifications
Dimensions, Weight, and Acoustics
Dimensions below use the source’s inch values in H x W x D order.
| Model | Dimensions, inches | Weight with AC supply | Acoustic noise |
|---|---|---|---|
| 5506-X | 1.72 x 7.871 x 9.23 | 4 lb | Fanless, 0 dBA |
| 5506H-X | 2.72 x 9.05 x 9.05 | 7 lb | Fanless, 0 dBA |
| 5508-X | 1.72 x 17.2 x 11.288 | 8 lb | 41.6 dBA typical; 67.2 maximum |
| 5516-X | 1.72 x 17.2 x 11.288 | 8 lb | 41.6 dBA typical; 67.2 maximum |
| 5525-X | 1.75 x 17.5 x 14.25 | 22.0 lb | 64.2 dBA maximum |
| 5545-X | 1.67 x 16.7 x 19.1 | 16.82 lb single supply; 18.86 lb dual | 67.9 dBA maximum |
| 5555-X | 1.67 x 16.7 x 19.1 | 16.82 lb single supply; 18.86 lb dual | 67.9 dBA maximum |
Source inconsistencies require attention: the 5525-X width is also printed as 20.04 cm, inconsistent with 17.5 inches. The 5508-X and 5516-X weights are printed as both 8 lb and 3 kg. Verify mechanical requirements before installation.
Operating and Storage Conditions
| Model | Operating temperature | Operating relative humidity | Non-operating temperature |
|---|---|---|---|
| 5506-X | 0 to 40 C | 90%, non-condensing | -25 to 70 C |
| 5506H-X | -20 to 60 C | 95%, non-condensing | -40 to 85 C |
| 5508-X / 5516-X | 0 to 40 C | 10 to 90%, non-condensing | -25 to 70 C |
| 5525-X / 5545-X / 5555-X | -5 to 40 C | 10 to 90%, non-condensing | -25 to 70 C |
All models are designed and tested for operating altitude from 0 to 10,000 ft and non-operating altitude from 0 to 15,000 ft. A footnote requires derating maximum operating temperature by 1.5 C per 1,000 ft above sea level.
Non-operating humidity is 10 to 95% non-condensing for the 5506H-X. It is 10 to 90% non-condensing for the 5506-X, 5508-X, and 5516-X. The three larger models list 10 to 90% without explicitly repeating “non-condensing.”
The 5506H-X has the widest listed temperature envelope and additional mounting options, but only four integrated GE interfaces.
MTBF
No MTBF, reliability calculation conditions, or component failure-rate data are supplied. Fanless construction, RAID 1, and dual supplies must not be converted into unsupported reliability figures. Obtain separate evidence where reliability targets are contractual.
Electrical and Cooling Planning
| Model | Source-listed steady-state output | Maximum peak output | Maximum heat dissipation | Dual supplies |
|---|---|---|---|---|
| 5506-X | 12 V at 2.5 A | 12 V at 5 A | 205 Btu/hr | No |
| 5506H-X | 5 V at 3.6 A | 5 V at 4.4 A | 75 Btu/hr | No |
| 5508-X | 12 V at 3 A | 12 V at 5 A | 205 Btu/hr | No |
| 5516-X | 12 V at 3 A | 12 V at 5 A | 205 Btu/hr | No |
| 5525-X | 75 W | 108 W | 369 Btu/hr | No |
| 5545-X | 86 W | 125 W | 427 Btu/hr | Yes |
| 5555-X | 90 W | 134 W | 458 Btu/hr | Yes |
The source labels these figures “Output”; they should not be relabeled as measured AC input consumption.
AC range is external 90 to 240 VAC for the first four models and 100 to 240 VAC for the larger three. All list 50/60 Hz. Separate nominal-voltage entries unusually show 91 to 240 VAC for the 5508-X and 92 to 240 VAC for the 5516-X.
The larger three list 15 A maximum DC input. Domestic DC range is printed as “-40.5 to 56 VDC” with -48 VDC nominal; international range is -55 to -72 VDC with -60 VDC nominal. Confirm the domestic polarity notation before electrical design.
No PoE capability or budget is specified.
Compliance, Warranty, and Service
The source lists CE compliance under directives 2004/108/EC and 2006/108/EC; safety references include UL, CAN/CSA, EN, IEC, and AS/NZS 60950-1, plus GB4943.
EMC entries include FCC Class A, CISPR22, EN55022, ICES003, VCCI, KN22, CNS13438, EN300386, EN55024, CISPR24, and specified EN61000 immunity tests. These are source-listed references, not evidence of current project-specific certification.
No warranty duration, hardware replacement commitment, RMA procedure, technical-support coverage, software-update entitlement, or service SKU appears in the supplied text.
Before quotation approval, obtain written confirmation of:
- Warranty scope and commencement date.
- Support hours, response targets, and replacement delivery terms.
- Software maintenance and security subscription entitlements.
- Coverage for supplies, storage, interface cards, and optics.
- Current orderability, software compatibility, and lifecycle status.
Cisco Capital is described as offering financing in more than 100 countries for hardware, software, services, and complementary third-party equipment. Financing availability does not establish warranty or support coverage.
Final Engineering Qualification
A defensible selection records the software image, inspection profile, packet-size assumptions, TLS and VPN demand, session scale, connection rate, HA behavior, interfaces, environmental limits, and power arrangement. Any requirement not documented here, especially warranty, MTBF, exact ordering SKUs, and simultaneous-feature capacity, remains an explicit validation item rather than an assumed capability.