Cisco ASA 5506 X Datasheet: 750 Mbps Firewall, 8 RJ45 Ports
Platform Scope and Selection Priorities
The Cisco ASA 5500 Series covers small-office, remote-office, branch, and internet-edge firewall deployments. The six performance tiers are ASA-5506, ASA-5508, ASA-5516, ASA-5525, ASA-5545, and ASA-5555. Hardware configurations additionally include the ASA 5506H-X, which has different interfaces, mounting options, and environmental limits from the ASA 5506-X.
The platforms can run Cisco ASA Firewall or Cisco Firepower Threat Defense (FTD). These software choices have separate performance figures, management systems, and high-availability capabilities. Hardware selection must therefore start with the intended software image and inspection policy, not the headline firewall throughput.
For ASA 5506-X sizing, the principal distinction is between 750 Mbps of ideal-condition stateful firewall throughput, 300 Mbps of multiprotocol firewall throughput, and 125 Mbps of FTD firewall, Application Visibility and Control (AVC), and IPS throughput at 1024-byte packet size. These are different test cases, not interchangeable capacity ratings.
Model and Expansion Matrix
The following matrix covers every appliance model identifier and interface expansion configuration listed. Ordering part numbers for appliance bundles, interface cards, power supplies, subscriptions, and mounting accessories are not specified.
| Appliance model | Summary identifier | Format | Integrated interfaces | Expansion |
|---|---|---|---|---|
| ASA 5506-X | ASA-5506 | Compact desktop; rack mountable | 8 x 1GE | None |
| ASA 5506H-X | Not separately listed | Compact desktop; rack, wall, and DIN-Rail mounting | 4 x 1GE | None |
| ASA 5508-X | ASA-5508 | Fixed 1RU, 19-inch rack | 8 x 1GE | None |
| ASA 5516-X | ASA-5516 | Fixed 1RU, 19-inch rack | 8 x 1GE | None |
| ASA 5525-X | ASA-5525 | Expansion-capable 1RU, 19-inch rack | 8 x 1GE | One interface-card slot |
| ASA 5545-X | ASA-5545 | Expansion-capable 1RU, 19-inch rack | 8 x 1GE | One interface-card slot |
| ASA 5555-X | ASA-5555 | Expansion-capable 1RU, 19-inch rack | 8 x 1GE | One interface-card slot |
| 6 GE copper interface option | Part number not specified | Modular interface option | 6 GE copper | For 5525-X, 5545-X, and 5555-X |
| 6 GE SFP interface option | Part number not specified | Modular interface option | 6 GE SFP | For 5525-X, 5545-X, and 5555-X |
The six summary models have eight RJ45 interfaces. The ASA 5506H-X hardware configuration instead has four integrated 1GE interfaces. Separate 5506H-X performance figures are not specified.
Presales rule: Requirements for interface expansion narrow selection to the 5525-X, 5545-X, and 5555-X. Do not assume that the compact or fixed-interface models can accept additional interface cards.
ASA Firewall Performance and Capacity
All throughput values below are Mbps. Connection figures are individual connections, not thousands.
| ASA metric | 5506 | 5508 | 5516 | 5525 | 5545 | 5555 |
|---|---|---|---|---|---|---|
| Stateful firewall, ideal conditions | 750 | 1,000 | 1,800 | 2,000 | 3,000 | 4,000 |
| Stateful firewall, multiprotocol | 300 | 500 | 900 | 1,000 | 1,500 | 2,000 |
| Concurrent firewall connections | 50,000 | 100,000 | 250,000 | 500,000 | 750,000 | 1,000,000 |
| New connections per second | 5,000 | 10,000 | 20,000 | 20,000 | 30,000 | 50,000 |
| IPsec VPN, 450-byte UDP L2L | 100 | 175 | 250 | 300 | 400 | 700 |
| Security contexts, included / maximum | N/A | 2 / 5 | 2 / 5 | 2 / 20 | 2 / 50 | 2 / 100 |
The ideal-condition firewall test uses 1500-byte UDP traffic. The multiprotocol profile consists primarily of TCP-based protocols and applications, including HTTP, SMTP, FTP, IMAPv4, BitTorrent, and DNS.
For mixed application traffic, the multiprotocol result is the more relevant starting point than the ideal UDP result. Connection establishment must also be checked independently: the 5516 and 5525 both list 20,000 new connections per second despite different throughput and concurrent-connection capacities.
ASA 5506 supports active/standby high availability. The other five performance tiers list active/active and active/standby operation. VPN load balancing is also listed as a scalability capability.
FTD Inspection Performance
All throughput figures are Mbps. FW means firewall; AVC means Application Visibility and Control.
| FTD metric | 5506 | 5508 | 5516 | 5525 | 5545 | 5555 |
|---|---|---|---|---|---|---|
| FW + AVC, 1024 bytes | 250 | 450 | 850 | 1,100 | 1,500 | 1,700 |
| FW + AVC + IPS, 1024 bytes | 125 | 250 | 450 | 650 | 1,000 | 1,200 |
| FW + AVC, 450 bytes | 100 | 175 | 275 | 350 | 500 | 600 |
| FW + AVC + IPS, 450 bytes | 75 | 125 | 200 | 250 | 350 | 420 |
| NGIPS, 1024 bytes | 125 | 250 | 450 | 650 | 1,000 | 1,200 |
| NGIPS, 450 bytes | 75 | 125 | 200 | 250 | 350 | 420 |
| TLS | Not specified | 250 | 285 | 270 | 290 | 370 |
| IPsec VPN, 1024-byte TCP with Fastpath | 100 | 175 | 250 | 300 | 400 | 700 |
| Concurrent sessions with AVC | 50,000 | 100,000 | 250,000 | 500,000 | 750,000 | 1,000,000 |
| New connections/second with AVC | 3,000 | 7,500 | 11,000 | 11,500 | 19,000 | 22,000 |
The ASA-5506 FTD benchmark uses version 6.2.3. Performance varies with enabled features, protocol mix, packet sizes, and software releases.
The 450-byte results are materially lower than the 1024-byte results. For example, ASA 5506 FW + AVC + IPS throughput is 75 Mbps at 450 bytes versus 125 Mbps at 1024 bytes. A design carrying predominantly smaller packets should not use the larger-packet figure as its sole sizing criterion.
TLS performance does not increase uniformly between adjacent models: the 5516 lists 285 Mbps, while the 5525 lists 270 Mbps. Select encrypted-traffic capacity from the TLS row rather than extrapolating from firewall throughput. No TLS throughput value is specified for the 5506.
Presales Sizing Rules
- Choose the software image first. ASA connection-rate and firewall results do not represent FTD inspection performance.
- Match the enabled inspection chain. IPS-enabled designs require the FW + AVC + IPS benchmark.
- Check packet-size sensitivity. Use both listed packet-size results when assessing workload risk.
- Size sessions and connection rate separately. A throughput match alone does not establish suitability.
- Keep VPN test methods distinct. ASA uses a 450-byte UDP LAN-to-LAN test; FTD uses 1024-byte TCP with Fastpath.
- Do not add benchmark rows. Firewall, TLS, IPS, and VPN ratings are not an aggregate simultaneous-performance commitment.
- Validate the surviving HA unit. An active/standby pair should be sized around the unit carrying traffic after failover.
- Validate representative traffic before acceptance. Include the intended software release, policy, protocol mix, and inspection features.
Security Functions and Management
FTD includes standard AVC support for more than 4,000 applications, with additional visibility involving geolocations, users, and websites. OpenAppID support for custom, open-source application detectors is standard.
Cisco Security Intelligence provides IP, URL, and DNS threat intelligence. Available security functions include:
- Firepower NGIPS, including passive endpoint and infrastructure detection for threat correlation and Indicators of Compromise intelligence.
- AMP for Networks, supporting malware detection, blocking, tracking, analysis, and containment.
- Optional integrated threat correlation with AMP for Endpoints.
- AMP Threat Grid sandboxing.
- URL filtering covering more than 80 categories and more than 280 million categorized URLs.
Automated threat feeds and IPS signature updates use Cisco Talos Collective Security Intelligence. Integration facilities include an open API and Snort and OpenAppID community resources.
FTD supports local Firepower Device Manager across all six performance tiers. Centralized configuration, logging, monitoring, and reporting use Management Center or cloud-based Cisco Defense Orchestrator. FTD high availability is active/standby.
ASA uses Adaptive Security Device Manager for web-based local management. Centralized management uses Cisco Security Manager or Cisco Defense Orchestrator.
Trust Anchor Technologies provide supply-chain and software-image assurance. Features identified as available should be separated from standard capabilities in the commercial configuration; subscription part numbers and entitlement terms are not specified.
Interfaces, Console Access, and Storage
The 5506-X, 5506H-X, 5508-X, and 5516-X management-port entries are designated “Shared.” The 5525-X, 5545-X, and 5555-X list a dedicated 1GE management port. Management connectivity should therefore be checked explicitly when preparing the interface allocation.
| Model | Console access | SSD configuration | USB |
|---|---|---|---|
| 5506-X | RJ45 and Mini USB | 50 GB mSATA | Type A, High Speed USB 2.0 |
| 5506H-X | RJ45 and Mini USB | 50 GB mSATA, heat tested | Type A, High Speed USB 2.0 |
| 5508-X | RJ45 and Mini USB | 80 GB mSATA | Type A, High Speed USB 2.0 |
| 5516-X | RJ45 and Mini USB | 100 GB mSATA | Type A, High Speed USB 2.0 |
| 5525-X | RJ45 | One slot, 120 GB MLC SED | Two USB 2.0 ports |
| 5545-X | RJ45 | Two slots, RAID 1, 120 GB MLC SED | Two USB 2.0 ports |
| 5555-X | RJ45 | Two slots, RAID 1, 120 GB MLC SED | Two USB 2.0 ports |
Environmental and Physical Specifications
Dimensions below use inches and the order height x width x depth. Weights use pounds.
| Model | Dimensions | Weight with AC supply | Operating temperature | Acoustic noise |
|---|---|---|---|---|
| 5506-X | 1.72 x 7.871 x 9.23 | 4 | 0 to 40 C | Fanless, 0 dBA |
| 5506H-X | 2.72 x 9.05 x 9.05 | 7 | -20 to 60 C | Fanless, 0 dBA |
| 5508-X | 1.72 x 17.2 x 11.288 | 8 | 0 to 40 C | 41.6 dBA typical; 67.2 maximum |
| 5516-X | 1.72 x 17.2 x 11.288 | 8 | 0 to 40 C | 41.6 dBA typical; 67.2 maximum |
| 5525-X | 1.75 x 17.5 x 14.25 | 22.0 | -5 to 40 C | 64.2 dBA maximum |
| 5545-X | 1.67 x 16.7 x 19.1 | 16.82 single supply; 18.86 dual | -5 to 40 C | 67.9 dBA maximum |
| 5555-X | 1.67 x 16.7 x 19.1 | 16.82 single supply; 18.86 dual | -5 to 40 C | 67.9 dBA maximum |
Operating relative humidity is 90% non-condensing for 5506-X and 95% non-condensing for 5506H-X. The remaining models specify 10% to 90% non-condensing.
All models are designed and tested for operating altitudes from 0 to 10,000 feet. Maximum operating temperature must be derated by 1.5 C per 1,000 feet above sea level.
Non-operating temperature is -25 to 70 C except for 5506H-X, which supports -40 to 85 C. Non-operating humidity is 10% to 95% for 5506H-X and 10% to 90% for the others. Non-condensing storage conditions are explicitly listed for 5506-X, 5506H-X, 5508-X, and 5516-X. All models list non-operating altitude from 0 to 15,000 feet.
MTBF: No mean time between failures rating is specified. Reliability calculations should not substitute warranty duration, temperature range, or redundant-power capability for an MTBF value.
Deployment rule: The fanless compact models are relevant where acoustic output matters. The 5506H-X additionally provides wider temperature tolerance and wall or DIN-Rail mounting, but only four integrated interfaces.
Power, Redundancy, and Cooling
| Model | AC input range | Dual supplies | Steady-state output | Maximum peak output | Maximum heat |
|---|---|---|---|---|---|
| 5506-X | External, 90-240 VAC | No | 12 V at 2.5 A | 12 V at 5 A | 205 Btu/hr |
| 5506H-X | External, 90-240 VAC | No | 5 V at 3.6 A | 5 V at 4.4 A | 75 Btu/hr |
| 5508-X | External, 90-240 VAC | No | 12 V at 3 A | 12 V at 5 A | 205 Btu/hr |
| 5516-X | External, 90-240 VAC | No | 12 V at 3 A | 12 V at 5 A | 205 Btu/hr |
| 5525-X | 100-240 VAC | No | 75 W | 108 W | 369 Btu/hr |
| 5545-X | 100-240 VAC | Yes | 86 W | 125 W | 427 Btu/hr |
| 5555-X | 100-240 VAC | Yes | 90 W | 134 W | 458 Btu/hr |
All models use 50/60 Hz AC. Separate normal-line entries list 91-240 VAC for 5508-X and 92-240 VAC for 5516-X.
AC current is 0.25 A for 5508-X and 5516-X, and 4.85 A for 5525-X. The 5545-X and 5555-X list 5 A at 100-120 V or 2.5 A at 200-240 V.
The three expansion-capable models list DC supply parameters and 15 A maximum DC input. International DC voltage is -55 to -72 VDC, with -60 VDC nominal. The domestic entry is printed as -40.5 to 56 VDC with -48 VDC nominal; installation requires resolution of that polarity inconsistency before connection.
No PoE capability or PoE budget is specified. Power-supply output ratings must not be treated as endpoint power budgets.
Warranty, Service, and Procurement
Warranty duration, hardware replacement turnaround, technical-support hours, software-update entitlement, and service-level commitments are not specified. No support-contract SKUs are listed.
The procurement schedule should explicitly identify:
- Hardware warranty term and covered components.
- Replacement logistics and required restoration time.
- Technical-support coverage and escalation arrangements.
- Software maintenance and security-update entitlements.
- Subscriptions for the selected inspection functions.
- Coverage for interface cards, storage, and power supplies.
- Mounting accessories and the required AC or DC configuration.
Cisco Capital payment solutions cover hardware, software, services, and complementary third-party equipment in more than 100 countries. Financing availability does not define support coverage or warranty terms.
Compliance and Engineering Acceptance
Safety listings include UL 60950-1, CAN/CSA-C22.2 No. 60950-1, EN 60950-1, IEC 60950-1, AS/NZS 60950-1, and GB4943. Emissions listings include FCC Class A, CISPR22 Class A, EN55022 Class A, ICES003 Class A, and VCCI Class A. Immunity listings include EN55024, CISPR24, EN300386, and the listed EN61000-4 test standards.
Engineering acceptance should require a documented software image, inspection profile, traffic assumptions, interface allocation, HA mode, rack or desktop arrangement, altitude-adjusted temperature limit, power configuration, and service schedule. This prevents a headline throughput figure from becoming an unsupported commitment for the complete deployment.