Cisco ASA 5506 X Datasheet: 750 Mbps Firewall, 8 RJ45 Ports

Scope and Engineering Basis

This guide covers the Cisco ASA 5506-X and the related ASA 5500-X appliances listed in datasheet C78-742475-01, dated March 2020. The source contains six performance columns and seven hardware models, including the ASA 5506H-X.

The principal engineering distinction is between operation with the Cisco ASA Firewall image and Cisco Firepower Threat Defense (FTD). Their throughput figures, connection rates, management tools, and high-availability capabilities must not be combined into a single specification.

Except for the explicitly identified lifecycle guidance, specifications below come from the supplied text. Missing ordering codes, MTBF figures, warranty terms, and licensing details are not inferred.

Lifecycle & End-of-Life

These are discontinued platforms. New deployment proposals should evaluate replacement hardware rather than treat the 2020 datasheet as evidence of current availability or software support.

The following lifecycle information is external to the supplied datasheet and is based on retained product-lifecycle knowledge, not a live check of Cisco notices. Exact applicability must be confirmed against the installed or quoted product ID before contractual use.

Platform group End-of-sale date Last date of support
ASA 5506-X and ASA 5506H-X August 2, 2021 August 31, 2026
ASA 5508-X and ASA 5516-X August 2, 2021 August 31, 2026
ASA 5525-X, ASA 5545-X, and ASA 5555-X September 16, 2020 September 30, 2025

“End-of-life” describes a process with several milestones. End of sale is not the same as the last date of support. Software maintenance, vulnerability support, service attachment, and renewal deadlines can differ from the dates above.

Replacement evaluation candidates include:

  • ASA 5506-X: Cisco Secure Firewall 1010.
  • ASA 5508-X and ASA 5516-X: Cisco Secure Firewall 1120 or 1140, subject to workload sizing.
  • ASA 5525-X, ASA 5545-X, and ASA 5555-X: Cisco Secure Firewall 2100 or 3100 Series, with the specific model selected from current performance and lifecycle information.
  • ASA 5506H-X: A separately qualified rugged firewall solution. A desktop replacement must not be assumed to reproduce its temperature range or DIN-rail installation capability.

These are migration candidates, not claims of equivalent performance or official one-to-one substitution. Confirm current replacement availability, image support, interfaces, environmental ratings, subscriptions, and migration requirements.

Complete Model and Expansion Matrix

The source supplies model identifiers, not complete orderable SKUs. It contains no license-bundle suffixes, spare part numbers, power-supply ordering codes, or interface-card product IDs.

Hardware model Summary identifier Format Integrated interfaces Expansion
ASA 5506-X ASA-5506 Compact desktop; rack mountable 8 x 1GE None
ASA 5506H-X Not separately listed Desktop; rack, wall, and DIN-rail mountable 4 x 1GE None
ASA 5508-X ASA-5508 Fixed 1RU; 19-inch rack 8 x 1GE None
ASA 5516-X ASA-5516 Fixed 1RU; 19-inch rack 8 x 1GE None
ASA 5525-X ASA-5525 Expandable 1RU; 19-inch rack 8 x 1GE One interface-card slot
ASA 5545-X ASA-5545 Expandable 1RU; 19-inch rack 8 x 1GE One interface-card slot
ASA 5555-X ASA-5555 Expandable 1RU; 19-inch rack 8 x 1GE One interface-card slot
Six-port GE copper option No SKU provided Interface module for 5525-X/5545-X/5555-X 6 x GE copper Occupies expansion slot
Six-port GE SFP option No SKU provided Interface module for 5525-X/5545-X/5555-X 6 x GE SFP Occupies expansion slot

The larger appliances are fixed appliances with interface expansion, not modular chassis systems. The six-port alternatives must not be interpreted as two simultaneously available expansion cards.

The overview identifies RJ45 interfaces for the six summary models. No separate performance column exists for the ASA 5506H-X; assigning the ASA 5506-X results to it would exceed the source.

ASA Firewall Performance

All throughput values in this table are Mbps. Connection counts are absolute values.

ASA metric 5506 5508 5516 5525 5545 5555
Stateful firewall, ideal test 750 1,000 1,800 2,000 3,000 4,000
Stateful firewall, multiprotocol 300 500 900 1,000 1,500 2,000
Concurrent connections 50,000 100,000 250,000 500,000 750,000 1,000,000
New connections/second 5,000 10,000 20,000 20,000 30,000 50,000
IPsec VPN 100 175 250 300 400 700
Contexts: included / maximum N/A 2 / 5 2 / 5 2 / 20 2 / 50 2 / 100

The ideal firewall test uses 1500-byte UDP traffic. The multiprotocol profile primarily contains TCP-based protocols and applications, including HTTP, SMTP, FTP, IMAPv4, BitTorrent, and DNS.

Presales rule: Use the multiprotocol result as the more relevant initial reference for mixed application traffic. Do not describe the ASA 5506-X as a guaranteed 750 Mbps production firewall.

The ASA VPN result uses a 450-byte UDP LAN-to-LAN test. It does not establish remote-access user capacity, supported cryptographic combinations, or performance under simultaneous inspection and encryption.

ASA high availability is active/standby on the 5506. The other five performance models list active/active and active/standby. VPN load balancing is also listed, but no scaling multiplier is provided.

FTD Performance and Inspection Sizing

All throughput values below are Mbps. AVC means Application Visibility and Control.

FTD metric 5506 5508 5516 5525 5545 5555
FW + AVC, 1024B 250 450 850 1,100 1,500 1,700
FW + AVC + IPS, 1024B 125 250 450 650 1,000 1,200
FW + AVC, 450B 100 175 275 350 500 600
FW + AVC + IPS, 450B 75 125 200 250 350 420
TLS Not stated 250 285 270 290 370
IPsec VPN, 1024B TCP with Fastpath 100 175 250 300 400 700
Concurrent sessions with AVC 50,000 100,000 250,000 500,000 750,000 1,000,000
New connections/second with AVC 3,000 7,500 11,000 11,500 19,000 22,000

Standalone NGIPS throughput equals the corresponding FW + AVC + IPS figure at both packet sizes.

The ASA 5506 test used FTD 6.2.3. This is a historical test condition, not evidence of compatibility with later FTD releases.

Practical sizing rules

  1. Select the security profile before selecting the appliance. Firewall-only, AVC, IPS, TLS, and VPN figures represent different conditions.
  2. Account for packet size. The ASA 5506 moves from 125 Mbps at 1024B to 75 Mbps at 450B with FW + AVC + IPS.
  3. Check session count and connection establishment independently. An application with frequent short connections may encounter connection-rate constraints before reaching a bandwidth figure.
  4. Do not add throughput rows. TLS and IPS results are not additive capacity.
  5. Do not infer missing TLS performance. The dash for the 5506 is neither a measured zero nor proof of a specified capability.
  6. Size active/standby designs for one appliance carrying the required load. The FTD table lists active/standby, not aggregate forwarding capacity across both units.
  7. Reserve workload-specific headroom. The source provides no universal utilization percentage.

For example, a 100 Mbps requirement with IPS and traffic resembling the 450B test exceeds the ASA 5506’s published 75 Mbps result. A requirement of 125 Mbps exactly matches its 1024B result and leaves no margin against that benchmark.

The datasheet explicitly states that activated features, protocol mix, packet size, and software releases affect performance. A representative acceptance test is therefore required for a firm capacity commitment.

Security Services, Management, and Availability

The FTD feature table identifies the following as standard:

  • AVC covering more than 4,000 applications, plus geolocations, users, and websites.
  • OpenAppID support for custom, open-source application detectors.
  • Security Intelligence for IP, URL, and DNS threat intelligence.

Available capabilities include NGIPS, AMP for Networks, AMP Threat Grid sandboxing, and optional integration with AMP for Endpoints. URL filtering lists more than 80 categories and more than 280 million categorized URLs.

Automated threat-feed and IPS-signature updates are identified with Cisco Talos. Integration facilities include an open API and Snort/OpenAppID community resources. Trust Anchor Technologies are described as supporting supply-chain and software-image assurance.

“Available” does not establish that a service is included in a base purchase. The supplied text lacks entitlement and subscription ordering details.

Software image Local management Centralized management
FTD Firepower Device Manager Management Center or Cisco Defense Orchestrator
ASA Adaptive Security Device Manager Cisco Security Manager or Cisco Defense Orchestrator

These are the management options documented in 2020. Current support and version interoperability require separate verification.

Interfaces, Storage, and Installation Details

The management-port row says “Yes (Shared)” for the 5506-X, 5506H-X, 5508-X, and 5516-X. That wording does not clearly establish independently usable management-interface capacity. The 5525-X, 5545-X, and 5555-X explicitly list a 1GE management port.

The first four models provide RJ45 and Mini USB console connections. The larger three list an RJ45 console.

Model SSD arrangement
5506-X 50 GB mSATA
5506H-X 50 GB mSATA, tested for heat
5508-X 80 GB mSATA
5516-X 100 GB mSATA
5525-X One slot; 120 GB MLC SED
5545-X Two slots; RAID 1; 120 GB MLC SED
5555-X Two slots; RAID 1; 120 GB MLC SED

The trailing “6” in several extracted mSATA entries is unresolved; it is not treated as a storage-interface specification. RAID 1 does not justify doubling the stated usable capacity.

The first four models list Type A High Speed USB 2.0 without an explicit count. The larger three list two USB 2.0 ports.

Environmental, Physical, Acoustic, and Reliability Specifications

Dimensions below preserve the source’s inch values and use H x W x D.

Model Dimensions, inches Weight with AC supply Operating temperature Acoustic noise
5506-X 1.72 x 7.871 x 9.23 4 lb 0 to 40 C Fanless; 0 dBA
5506H-X 2.72 x 9.05 x 9.05 7 lb -20 to 60 C Fanless; 0 dBA
5508-X 1.72 x 17.2 x 11.288 8 lb 0 to 40 C 41.6 dBA typical; 67.2 maximum
5516-X 1.72 x 17.2 x 11.288 8 lb 0 to 40 C 41.6 dBA typical; 67.2 maximum
5525-X 1.75 x 17.5 x 14.25 22 lb -5 to 40 C 64.2 dBA maximum
5545-X 1.67 x 16.7 x 19.1 16.82 lb single supply; 18.86 lb dual -5 to 40 C 67.9 dBA maximum
5555-X 1.67 x 16.7 x 19.1 16.82 lb single supply; 18.86 lb dual -5 to 40 C 67.9 dBA maximum

Operating humidity is 90 percent non-condensing for the 5506-X and 95 percent non-condensing for the 5506H-X; lower limits are not given. The remaining models specify 10 to 90 percent non-condensing.

All models list operating altitude from 0 to 10,000 ft and non-operating altitude from 0 to 15,000 ft. A footnote requires reducing maximum operating temperature by 1.5 C per 1,000 ft above sea level, despite its placement alongside the non-operating temperature row.

Non-operating temperature is -25 to 70 C except for the 5506H-X, which specifies -40 to 85 C. Non-operating humidity is 10 to 95 percent for the 5506H-X and 10 to 90 percent for the others. The larger three do not repeat the non-condensing qualifier in that row.

MTBF: No MTBF, failure-rate model, or reliability test conditions are supplied. Fanless construction, RAID, and dual supplies must not be converted into an unsupported MTBF estimate.

The metric dimensions and weights contain inconsistencies, including the 5525-X width and the 5508-X/5516-X pound-to-kilogram entries. Rack drawings, transport loads, and installation clearances require verification rather than silent correction.

Power, Cooling, and Redundancy

Model Listed steady-state output Listed maximum peak output Maximum heat Dual supplies
5506-X 12 V at 2.5 A 12 V at 5 A 205 Btu/hr No
5506H-X 5 V at 3.6 A 5 V at 4.4 A 75 Btu/hr No
5508-X 12 V at 3 A 12 V at 5 A 205 Btu/hr No
5516-X 12 V at 3 A 12 V at 5 A 205 Btu/hr No
5525-X 75 W 108 W 369 Btu/hr No
5545-X 86 W 125 W 427 Btu/hr Yes
5555-X 90 W 134 W 458 Btu/hr Yes

These values appear under “Output”; they must not automatically be represented as measured AC wall consumption.

The AC-range row lists external 90 to 240 VAC supplies for the first four models and 100 to 240 VAC for the larger three. All specify 50/60 Hz. The separate normal-voltage row gives unusual 91 V and 92 V lower bounds for the 5508-X and 5516-X, respectively; confirm supply labels before electrical design.

The larger three list DC options, 15 A maximum DC input, and -48 V or -60 V nominal systems. The domestic range is printed as “-40.5 to 56 VDC”; its polarity ambiguity requires verification.

No PoE capability or PoE budget is specified. Power-output figures are not Ethernet endpoint power budgets.

Warranty, Service, and Procurement Controls

The supplied datasheet does not state:

  • Hardware warranty duration or exclusions.
  • Advance-replacement or return-to-factory terms.
  • TAC access or response commitments.
  • Software-update entitlement.
  • Onsite service availability.
  • Service contract SKUs or subscription prices.

A proposal must identify these as unresolved commercial requirements, not substitute assumed standard terms.

For an installed or secondary-market appliance, procurement should verify the exact product ID and serial number, ownership and entitlement status, service eligibility, software access, security-update availability, and replacement-hardware arrangements. A service contract must not be assumed to extend support beyond the applicable lifecycle deadline.

Cisco Capital financing is described as available in more than 100 countries for hardware, software, services, and complementary third-party equipment. Financing does not establish warranty coverage or technical support entitlement.

The source also lists safety approvals from the 60950-1 family and Class A emissions standards, including FCC Class A. These historical declarations do not replace current jurisdiction-specific compliance checks.

Before approval, the engineering record should contain the selected software image, measured traffic profile, inspection requirements, connection demand, VPN workload, failover capacity, installation conditions, verified bill of materials, support position, and migration plan.