Scope and Source Limitations

This guide interprets the supplied Cisco ASA 5500 Series datasheet, document C78-742475-01, dated 03/20. It separates ASA firewall performance from Firepower Threat Defense (FTD) performance and identifies installation and procurement constraints.

The source describes six performance tiers and seven hardware models, including the ASA 5506H-X. It does not provide orderable bundle part numbers, interface-card SKUs, license ordering codes, MTBF figures, or warranty terms. Those omissions must remain open qualification items rather than assumed specifications.

The platforms are described as supporting either Cisco ASA Firewall or FTD. The ASA 5506 FTD measurements specifically use version 6.2.3. No separate performance measurements are supplied for the 5506H-X.

Complete Model and Expansion Matrix

The following matrix includes every appliance designation in the supplied text. “Compact,” “fixed,” and “expandable” describe the documented hardware arrangement, not separate ordering categories.

Hardware model Summary designation Hardware category Integrated data I/O Expansion Mounting
ASA 5506-X ASA-5506 Compact, fixed I/O 8 x 1GE None Desktop, rack mountable
ASA 5506H-X Not separately listed Compact, fixed I/O 4 x 1GE None Desktop, rack, wall, DIN-Rail
ASA 5508-X ASA-5508 Fixed I/O 8 x 1GE None 1RU, 19-inch rack
ASA 5516-X ASA-5516 Fixed I/O 8 x 1GE None 1RU, 19-inch rack
ASA 5525-X ASA-5525 Expandable appliance 8 x 1GE One card: 6 GE copper or 6 GE SFP 1RU, 19-inch rack
ASA 5545-X ASA-5545 Expandable appliance 8 x 1GE One card: 6 GE copper or 6 GE SFP 1RU, 19-inch rack
ASA 5555-X ASA-5555 Expandable appliance 8 x 1GE One card: 6 GE copper or 6 GE SFP 1RU, 19-inch rack

The six-model summary identifies integrated interfaces as RJ45. The optional six-port copper and SFP cards have no part numbers in the source.

Presales rule: A requirement for additional interfaces or SFP expansion directs evaluation toward the 5525-X, 5545-X, or 5555-X. Do not specify an expansion card or transceiver ordering code from this datasheet alone.

ASA Firewall Performance and Sizing

ASA throughput figures describe two different test profiles. The higher figures use 1500-byte UDP under ideal conditions. Multiprotocol results use primarily TCP-based applications, including HTTP, SMTP, FTP, IMAPv4, BitTorrent, and DNS.

ASA model tier Ideal stateful throughput Multiprotocol throughput Concurrent connections New connections/sec IPsec throughput
5506 750 Mbps 300 Mbps 50,000 5,000 100 Mbps
5508 1 Gbps 500 Mbps 100,000 10,000 175 Mbps
5516 1.8 Gbps 900 Mbps 250,000 20,000 250 Mbps
5525 2 Gbps 1 Gbps 500,000 20,000 300 Mbps
5545 3 Gbps 1.5 Gbps 750,000 30,000 400 Mbps
5555 4 Gbps 2 Gbps 1 million 50,000 700 Mbps

ASA IPsec measurements use a 450-byte UDP LAN-to-LAN test.

Use multiprotocol performance as the more relevant published comparison for mixed application traffic. It is still a test result, not a guaranteed production capacity.

Connection establishment and concurrent connection capacity require separate checks. For example, the 5516 and 5525 both list 20,000 new connections per second, although the 5525 doubles concurrent connection capacity from 250,000 to 500,000.

Presales rule: Moving to the next model does not necessarily improve every limiting metric. Select against throughput, connection population, connection churn, and VPN demand independently.

FTD Inspection Performance

FTD performance must be sized against the enabled inspection functions and packet profile. FW denotes firewall inspection; AVC denotes Application Visibility and Control.

FTD model tier FW + AVC, 1024B FW + AVC + IPS, 1024B FW + AVC, 450B FW + AVC + IPS, 450B
5506 250 Mbps 125 Mbps 100 Mbps 75 Mbps
5508 450 Mbps 250 Mbps 175 Mbps 125 Mbps
5516 850 Mbps 450 Mbps 275 Mbps 200 Mbps
5525 1.1 Gbps 650 Mbps 350 Mbps 250 Mbps
5545 1.5 Gbps 1 Gbps 500 Mbps 350 Mbps
5555 1.7 Gbps 1.2 Gbps 600 Mbps 420 Mbps

Standalone NGIPS throughput matches the corresponding FW + AVC + IPS figures at both published packet sizes.

FTD model tier Concurrent sessions with AVC New connections/sec with AVC TLS IPsec VPN
5506 50,000 3,000 Not specified 100 Mbps
5508 100,000 7,500 250 Mbps 175 Mbps
5516 250,000 11,000 285 Mbps 250 Mbps
5525 500,000 11,500 270 Mbps 300 Mbps
5545 750,000 19,000 290 Mbps 400 Mbps
5555 1 million 22,000 370 Mbps 700 Mbps

FTD IPsec testing uses 1024-byte TCP with Fastpath. Although its numerical results match the ASA table, the methodologies differ.

The TLS row lacks test-method detail. Its figures are not strictly increasing by model: the 5525 lists 270 Mbps versus 285 Mbps for the 5516. The dash for the 5506 is not sufficient evidence to declare TLS unsupported.

Inspection Sizing Rules

  • For a 400 Mbps FW + AVC + IPS requirement using the published 1024-byte profile, the 5516 is the first listed tier exceeding that rate, at 450 Mbps.
  • For the same requirement using the 450-byte profile, only the 5555 exceeds it, at 420 Mbps. That leaves little separation from the published test ceiling and requires further validation.
  • A 1 Gbps inspected requirement matches the 5545’s 1024-byte result but exceeds every listed 450-byte result.
  • Do not add TLS, VPN, and firewall figures together or assume simultaneous delivery of their individual maxima.
  • Establish project-specific operating margin; the source provides no standard headroom percentage.

The datasheet explicitly warns that activated features, protocol mix, packet sizes, and software releases affect performance.

Security Functions and Management

FTD includes standard AVC covering more than 4,000 applications, plus geolocations, users, and websites. OpenAppID support for custom open-source application detectors is standard.

Cisco Security Intelligence is listed as standard, with IP, URL, and DNS threat intelligence. Additional listed capabilities include:

  • Available NGIPS, including passive endpoint and infrastructure detection for threat correlation and Indicators of Compromise intelligence.
  • Available AMP for Networks for malware detection, blocking, tracking, analysis, and containment.
  • Optional integrated correlation with AMP for Endpoints.
  • Available AMP Threat Grid sandboxing.
  • URL filtering covering more than 80 categories and more than 280 million categorized URLs.
  • Automated threat-feed and IPS-signature updates from Cisco Talos.
  • An open integration API and Snort and OpenAppID community resources.

“Available” does not establish that a feature is included in a base purchase. The source does not provide subscription terms or license SKUs.

FTD supports local Firepower Device Manager across all six performance tiers. Centralized configuration, logging, monitoring, and reporting use Management Center or cloud-based Cisco Defense Orchestrator.

ASA uses web-based Adaptive Security Device Manager locally, with Cisco Security Manager or Cisco Defense Orchestrator for centralized management.

Trust Anchor Technologies are identified for supply-chain and software-image assurance. Implementation details are not included in the supplied text.

Availability, Contexts, and Platform Selection

Model tier ASA contexts included / maximum ASA high availability FTD high availability
5506 N/A Active/standby Active/standby
5508 2 / 5 Active/active and active/standby Active/standby
5516 2 / 5 Active/active and active/standby Active/standby
5525 2 / 20 Active/active and active/standby Active/standby
5545 2 / 50 Active/active and active/standby Active/standby
5555 2 / 100 Active/active and active/standby Active/standby

ASA scalability includes VPN load balancing. The FTD row is titled “High availability and clustering,” but specifies only active/standby. It does not establish additional clustering modes.

Engineering rule: Size an active/standby deployment so the surviving appliance can support the required workload. Do not treat the pair as twice the listed forwarding capacity.

Context maxima do not establish included entitlement beyond the stated two contexts. Licensing and deployment prerequisites require confirmation.

Storage, Console, and Management Interfaces

Model Storage Console Management entry
5506-X 50 GB mSATA RJ-45 and Mini USB Yes, shared
5506H-X 50 GB mSATA, heat tested RJ-45 and Mini USB Yes, shared
5508-X 80 GB mSATA RJ-45 and Mini USB Yes, shared
5516-X 100 GB mSATA RJ-45 and Mini USB Yes, shared
5525-X One slot, 120 GB MLC SED RJ-45 Yes, 1GE
5545-X Two slots, RAID 1, 120 GB MLC SED RJ-45 Yes, 1GE
5555-X Two slots, RAID 1, 120 GB MLC SED RJ-45 Yes, 1GE

The first four models list Type A High Speed USB 2.0 without an explicit count. The remaining models list two USB 2.0 ports.

The shared-management wording does not describe the sharing mechanism. Confirm the intended management topology before finalizing port assignments.

Physical, Environmental, and Reliability Specifications

Dimensions, Weight, and Acoustics

Dimensions below use the source’s inch values in H x W x D order.

Model Dimensions, inches Weight with AC supply Acoustic noise
5506-X 1.72 x 7.871 x 9.23 4 lb Fanless, 0 dBA
5506H-X 2.72 x 9.05 x 9.05 7 lb Fanless, 0 dBA
5508-X 1.72 x 17.2 x 11.288 8 lb 41.6 dBA typical; 67.2 maximum
5516-X 1.72 x 17.2 x 11.288 8 lb 41.6 dBA typical; 67.2 maximum
5525-X 1.75 x 17.5 x 14.25 22.0 lb 64.2 dBA maximum
5545-X 1.67 x 16.7 x 19.1 16.82 lb single supply; 18.86 lb dual 67.9 dBA maximum
5555-X 1.67 x 16.7 x 19.1 16.82 lb single supply; 18.86 lb dual 67.9 dBA maximum

Source inconsistencies require attention: the 5525-X width is also printed as 20.04 cm, inconsistent with 17.5 inches. The 5508-X and 5516-X weights are printed as both 8 lb and 3 kg. Verify mechanical requirements before installation.

Operating and Storage Conditions

Model Operating temperature Operating relative humidity Non-operating temperature
5506-X 0 to 40 C 90%, non-condensing -25 to 70 C
5506H-X -20 to 60 C 95%, non-condensing -40 to 85 C
5508-X / 5516-X 0 to 40 C 10 to 90%, non-condensing -25 to 70 C
5525-X / 5545-X / 5555-X -5 to 40 C 10 to 90%, non-condensing -25 to 70 C

All models are designed and tested for operating altitude from 0 to 10,000 ft and non-operating altitude from 0 to 15,000 ft. A footnote requires derating maximum operating temperature by 1.5 C per 1,000 ft above sea level.

Non-operating humidity is 10 to 95% non-condensing for the 5506H-X. It is 10 to 90% non-condensing for the 5506-X, 5508-X, and 5516-X. The three larger models list 10 to 90% without explicitly repeating “non-condensing.”

The 5506H-X has the widest listed temperature envelope and additional mounting options, but only four integrated GE interfaces.

MTBF

No MTBF, reliability calculation conditions, or component failure-rate data are supplied. Fanless construction, RAID 1, and dual supplies must not be converted into unsupported reliability figures. Obtain separate evidence where reliability targets are contractual.

Electrical and Cooling Planning

Model Source-listed steady-state output Maximum peak output Maximum heat dissipation Dual supplies
5506-X 12 V at 2.5 A 12 V at 5 A 205 Btu/hr No
5506H-X 5 V at 3.6 A 5 V at 4.4 A 75 Btu/hr No
5508-X 12 V at 3 A 12 V at 5 A 205 Btu/hr No
5516-X 12 V at 3 A 12 V at 5 A 205 Btu/hr No
5525-X 75 W 108 W 369 Btu/hr No
5545-X 86 W 125 W 427 Btu/hr Yes
5555-X 90 W 134 W 458 Btu/hr Yes

The source labels these figures “Output”; they should not be relabeled as measured AC input consumption.

AC range is external 90 to 240 VAC for the first four models and 100 to 240 VAC for the larger three. All list 50/60 Hz. Separate nominal-voltage entries unusually show 91 to 240 VAC for the 5508-X and 92 to 240 VAC for the 5516-X.

The larger three list 15 A maximum DC input. Domestic DC range is printed as “-40.5 to 56 VDC” with -48 VDC nominal; international range is -55 to -72 VDC with -60 VDC nominal. Confirm the domestic polarity notation before electrical design.

No PoE capability or budget is specified.

Compliance, Warranty, and Service

The source lists CE compliance under directives 2004/108/EC and 2006/108/EC; safety references include UL, CAN/CSA, EN, IEC, and AS/NZS 60950-1, plus GB4943.

EMC entries include FCC Class A, CISPR22, EN55022, ICES003, VCCI, KN22, CNS13438, EN300386, EN55024, CISPR24, and specified EN61000 immunity tests. These are source-listed references, not evidence of current project-specific certification.

No warranty duration, hardware replacement commitment, RMA procedure, technical-support coverage, software-update entitlement, or service SKU appears in the supplied text.

Before quotation approval, obtain written confirmation of:

  • Warranty scope and commencement date.
  • Support hours, response targets, and replacement delivery terms.
  • Software maintenance and security subscription entitlements.
  • Coverage for supplies, storage, interface cards, and optics.
  • Current orderability, software compatibility, and lifecycle status.

Cisco Capital is described as offering financing in more than 100 countries for hardware, software, services, and complementary third-party equipment. Financing availability does not establish warranty or support coverage.

Final Engineering Qualification

A defensible selection records the software image, inspection profile, packet-size assumptions, TLS and VPN demand, session scale, connection rate, HA behavior, interfaces, environmental limits, and power arrangement. Any requirement not documented here, especially warranty, MTBF, exact ordering SKUs, and simultaneous-feature capacity, remains an explicit validation item rather than an assumed capability.