Cisco ASA 5506 X Datasheet: 750 Mbps Firewall, 8 RJ45 Ports
Scope and Engineering Basis
This guide covers the Cisco ASA 5506-X and the related ASA 5500-X appliances listed in datasheet C78-742475-01, dated March 2020. The source contains six performance columns and seven hardware models, including the ASA 5506H-X.
The principal engineering distinction is between operation with the Cisco ASA Firewall image and Cisco Firepower Threat Defense (FTD). Their throughput figures, connection rates, management tools, and high-availability capabilities must not be combined into a single specification.
Except for the explicitly identified lifecycle guidance, specifications below come from the supplied text. Missing ordering codes, MTBF figures, warranty terms, and licensing details are not inferred.
Lifecycle & End-of-Life
These are discontinued platforms. New deployment proposals should evaluate replacement hardware rather than treat the 2020 datasheet as evidence of current availability or software support.
The following lifecycle information is external to the supplied datasheet and is based on retained product-lifecycle knowledge, not a live check of Cisco notices. Exact applicability must be confirmed against the installed or quoted product ID before contractual use.
| Platform group | End-of-sale date | Last date of support |
|---|---|---|
| ASA 5506-X and ASA 5506H-X | August 2, 2021 | August 31, 2026 |
| ASA 5508-X and ASA 5516-X | August 2, 2021 | August 31, 2026 |
| ASA 5525-X, ASA 5545-X, and ASA 5555-X | September 16, 2020 | September 30, 2025 |
“End-of-life” describes a process with several milestones. End of sale is not the same as the last date of support. Software maintenance, vulnerability support, service attachment, and renewal deadlines can differ from the dates above.
Replacement evaluation candidates include:
- ASA 5506-X: Cisco Secure Firewall 1010.
- ASA 5508-X and ASA 5516-X: Cisco Secure Firewall 1120 or 1140, subject to workload sizing.
- ASA 5525-X, ASA 5545-X, and ASA 5555-X: Cisco Secure Firewall 2100 or 3100 Series, with the specific model selected from current performance and lifecycle information.
- ASA 5506H-X: A separately qualified rugged firewall solution. A desktop replacement must not be assumed to reproduce its temperature range or DIN-rail installation capability.
These are migration candidates, not claims of equivalent performance or official one-to-one substitution. Confirm current replacement availability, image support, interfaces, environmental ratings, subscriptions, and migration requirements.
Complete Model and Expansion Matrix
The source supplies model identifiers, not complete orderable SKUs. It contains no license-bundle suffixes, spare part numbers, power-supply ordering codes, or interface-card product IDs.
| Hardware model | Summary identifier | Format | Integrated interfaces | Expansion |
|---|---|---|---|---|
| ASA 5506-X | ASA-5506 | Compact desktop; rack mountable | 8 x 1GE | None |
| ASA 5506H-X | Not separately listed | Desktop; rack, wall, and DIN-rail mountable | 4 x 1GE | None |
| ASA 5508-X | ASA-5508 | Fixed 1RU; 19-inch rack | 8 x 1GE | None |
| ASA 5516-X | ASA-5516 | Fixed 1RU; 19-inch rack | 8 x 1GE | None |
| ASA 5525-X | ASA-5525 | Expandable 1RU; 19-inch rack | 8 x 1GE | One interface-card slot |
| ASA 5545-X | ASA-5545 | Expandable 1RU; 19-inch rack | 8 x 1GE | One interface-card slot |
| ASA 5555-X | ASA-5555 | Expandable 1RU; 19-inch rack | 8 x 1GE | One interface-card slot |
| Six-port GE copper option | No SKU provided | Interface module for 5525-X/5545-X/5555-X | 6 x GE copper | Occupies expansion slot |
| Six-port GE SFP option | No SKU provided | Interface module for 5525-X/5545-X/5555-X | 6 x GE SFP | Occupies expansion slot |
The larger appliances are fixed appliances with interface expansion, not modular chassis systems. The six-port alternatives must not be interpreted as two simultaneously available expansion cards.
The overview identifies RJ45 interfaces for the six summary models. No separate performance column exists for the ASA 5506H-X; assigning the ASA 5506-X results to it would exceed the source.
ASA Firewall Performance
All throughput values in this table are Mbps. Connection counts are absolute values.
| ASA metric | 5506 | 5508 | 5516 | 5525 | 5545 | 5555 |
|---|---|---|---|---|---|---|
| Stateful firewall, ideal test | 750 | 1,000 | 1,800 | 2,000 | 3,000 | 4,000 |
| Stateful firewall, multiprotocol | 300 | 500 | 900 | 1,000 | 1,500 | 2,000 |
| Concurrent connections | 50,000 | 100,000 | 250,000 | 500,000 | 750,000 | 1,000,000 |
| New connections/second | 5,000 | 10,000 | 20,000 | 20,000 | 30,000 | 50,000 |
| IPsec VPN | 100 | 175 | 250 | 300 | 400 | 700 |
| Contexts: included / maximum | N/A | 2 / 5 | 2 / 5 | 2 / 20 | 2 / 50 | 2 / 100 |
The ideal firewall test uses 1500-byte UDP traffic. The multiprotocol profile primarily contains TCP-based protocols and applications, including HTTP, SMTP, FTP, IMAPv4, BitTorrent, and DNS.
Presales rule: Use the multiprotocol result as the more relevant initial reference for mixed application traffic. Do not describe the ASA 5506-X as a guaranteed 750 Mbps production firewall.
The ASA VPN result uses a 450-byte UDP LAN-to-LAN test. It does not establish remote-access user capacity, supported cryptographic combinations, or performance under simultaneous inspection and encryption.
ASA high availability is active/standby on the 5506. The other five performance models list active/active and active/standby. VPN load balancing is also listed, but no scaling multiplier is provided.
FTD Performance and Inspection Sizing
All throughput values below are Mbps. AVC means Application Visibility and Control.
| FTD metric | 5506 | 5508 | 5516 | 5525 | 5545 | 5555 |
|---|---|---|---|---|---|---|
| FW + AVC, 1024B | 250 | 450 | 850 | 1,100 | 1,500 | 1,700 |
| FW + AVC + IPS, 1024B | 125 | 250 | 450 | 650 | 1,000 | 1,200 |
| FW + AVC, 450B | 100 | 175 | 275 | 350 | 500 | 600 |
| FW + AVC + IPS, 450B | 75 | 125 | 200 | 250 | 350 | 420 |
| TLS | Not stated | 250 | 285 | 270 | 290 | 370 |
| IPsec VPN, 1024B TCP with Fastpath | 100 | 175 | 250 | 300 | 400 | 700 |
| Concurrent sessions with AVC | 50,000 | 100,000 | 250,000 | 500,000 | 750,000 | 1,000,000 |
| New connections/second with AVC | 3,000 | 7,500 | 11,000 | 11,500 | 19,000 | 22,000 |
Standalone NGIPS throughput equals the corresponding FW + AVC + IPS figure at both packet sizes.
The ASA 5506 test used FTD 6.2.3. This is a historical test condition, not evidence of compatibility with later FTD releases.
Practical sizing rules
- Select the security profile before selecting the appliance. Firewall-only, AVC, IPS, TLS, and VPN figures represent different conditions.
- Account for packet size. The ASA 5506 moves from 125 Mbps at 1024B to 75 Mbps at 450B with FW + AVC + IPS.
- Check session count and connection establishment independently. An application with frequent short connections may encounter connection-rate constraints before reaching a bandwidth figure.
- Do not add throughput rows. TLS and IPS results are not additive capacity.
- Do not infer missing TLS performance. The dash for the 5506 is neither a measured zero nor proof of a specified capability.
- Size active/standby designs for one appliance carrying the required load. The FTD table lists active/standby, not aggregate forwarding capacity across both units.
- Reserve workload-specific headroom. The source provides no universal utilization percentage.
For example, a 100 Mbps requirement with IPS and traffic resembling the 450B test exceeds the ASA 5506’s published 75 Mbps result. A requirement of 125 Mbps exactly matches its 1024B result and leaves no margin against that benchmark.
The datasheet explicitly states that activated features, protocol mix, packet size, and software releases affect performance. A representative acceptance test is therefore required for a firm capacity commitment.
Security Services, Management, and Availability
The FTD feature table identifies the following as standard:
- AVC covering more than 4,000 applications, plus geolocations, users, and websites.
- OpenAppID support for custom, open-source application detectors.
- Security Intelligence for IP, URL, and DNS threat intelligence.
Available capabilities include NGIPS, AMP for Networks, AMP Threat Grid sandboxing, and optional integration with AMP for Endpoints. URL filtering lists more than 80 categories and more than 280 million categorized URLs.
Automated threat-feed and IPS-signature updates are identified with Cisco Talos. Integration facilities include an open API and Snort/OpenAppID community resources. Trust Anchor Technologies are described as supporting supply-chain and software-image assurance.
“Available” does not establish that a service is included in a base purchase. The supplied text lacks entitlement and subscription ordering details.
| Software image | Local management | Centralized management |
|---|---|---|
| FTD | Firepower Device Manager | Management Center or Cisco Defense Orchestrator |
| ASA | Adaptive Security Device Manager | Cisco Security Manager or Cisco Defense Orchestrator |
These are the management options documented in 2020. Current support and version interoperability require separate verification.
Interfaces, Storage, and Installation Details
The management-port row says “Yes (Shared)” for the 5506-X, 5506H-X, 5508-X, and 5516-X. That wording does not clearly establish independently usable management-interface capacity. The 5525-X, 5545-X, and 5555-X explicitly list a 1GE management port.
The first four models provide RJ45 and Mini USB console connections. The larger three list an RJ45 console.
| Model | SSD arrangement |
|---|---|
| 5506-X | 50 GB mSATA |
| 5506H-X | 50 GB mSATA, tested for heat |
| 5508-X | 80 GB mSATA |
| 5516-X | 100 GB mSATA |
| 5525-X | One slot; 120 GB MLC SED |
| 5545-X | Two slots; RAID 1; 120 GB MLC SED |
| 5555-X | Two slots; RAID 1; 120 GB MLC SED |
The trailing “6” in several extracted mSATA entries is unresolved; it is not treated as a storage-interface specification. RAID 1 does not justify doubling the stated usable capacity.
The first four models list Type A High Speed USB 2.0 without an explicit count. The larger three list two USB 2.0 ports.
Environmental, Physical, Acoustic, and Reliability Specifications
Dimensions below preserve the source’s inch values and use H x W x D.
| Model | Dimensions, inches | Weight with AC supply | Operating temperature | Acoustic noise |
|---|---|---|---|---|
| 5506-X | 1.72 x 7.871 x 9.23 | 4 lb | 0 to 40 C | Fanless; 0 dBA |
| 5506H-X | 2.72 x 9.05 x 9.05 | 7 lb | -20 to 60 C | Fanless; 0 dBA |
| 5508-X | 1.72 x 17.2 x 11.288 | 8 lb | 0 to 40 C | 41.6 dBA typical; 67.2 maximum |
| 5516-X | 1.72 x 17.2 x 11.288 | 8 lb | 0 to 40 C | 41.6 dBA typical; 67.2 maximum |
| 5525-X | 1.75 x 17.5 x 14.25 | 22 lb | -5 to 40 C | 64.2 dBA maximum |
| 5545-X | 1.67 x 16.7 x 19.1 | 16.82 lb single supply; 18.86 lb dual | -5 to 40 C | 67.9 dBA maximum |
| 5555-X | 1.67 x 16.7 x 19.1 | 16.82 lb single supply; 18.86 lb dual | -5 to 40 C | 67.9 dBA maximum |
Operating humidity is 90 percent non-condensing for the 5506-X and 95 percent non-condensing for the 5506H-X; lower limits are not given. The remaining models specify 10 to 90 percent non-condensing.
All models list operating altitude from 0 to 10,000 ft and non-operating altitude from 0 to 15,000 ft. A footnote requires reducing maximum operating temperature by 1.5 C per 1,000 ft above sea level, despite its placement alongside the non-operating temperature row.
Non-operating temperature is -25 to 70 C except for the 5506H-X, which specifies -40 to 85 C. Non-operating humidity is 10 to 95 percent for the 5506H-X and 10 to 90 percent for the others. The larger three do not repeat the non-condensing qualifier in that row.
MTBF: No MTBF, failure-rate model, or reliability test conditions are supplied. Fanless construction, RAID, and dual supplies must not be converted into an unsupported MTBF estimate.
The metric dimensions and weights contain inconsistencies, including the 5525-X width and the 5508-X/5516-X pound-to-kilogram entries. Rack drawings, transport loads, and installation clearances require verification rather than silent correction.
Power, Cooling, and Redundancy
| Model | Listed steady-state output | Listed maximum peak output | Maximum heat | Dual supplies |
|---|---|---|---|---|
| 5506-X | 12 V at 2.5 A | 12 V at 5 A | 205 Btu/hr | No |
| 5506H-X | 5 V at 3.6 A | 5 V at 4.4 A | 75 Btu/hr | No |
| 5508-X | 12 V at 3 A | 12 V at 5 A | 205 Btu/hr | No |
| 5516-X | 12 V at 3 A | 12 V at 5 A | 205 Btu/hr | No |
| 5525-X | 75 W | 108 W | 369 Btu/hr | No |
| 5545-X | 86 W | 125 W | 427 Btu/hr | Yes |
| 5555-X | 90 W | 134 W | 458 Btu/hr | Yes |
These values appear under “Output”; they must not automatically be represented as measured AC wall consumption.
The AC-range row lists external 90 to 240 VAC supplies for the first four models and 100 to 240 VAC for the larger three. All specify 50/60 Hz. The separate normal-voltage row gives unusual 91 V and 92 V lower bounds for the 5508-X and 5516-X, respectively; confirm supply labels before electrical design.
The larger three list DC options, 15 A maximum DC input, and -48 V or -60 V nominal systems. The domestic range is printed as “-40.5 to 56 VDC”; its polarity ambiguity requires verification.
No PoE capability or PoE budget is specified. Power-output figures are not Ethernet endpoint power budgets.
Warranty, Service, and Procurement Controls
The supplied datasheet does not state:
- Hardware warranty duration or exclusions.
- Advance-replacement or return-to-factory terms.
- TAC access or response commitments.
- Software-update entitlement.
- Onsite service availability.
- Service contract SKUs or subscription prices.
A proposal must identify these as unresolved commercial requirements, not substitute assumed standard terms.
For an installed or secondary-market appliance, procurement should verify the exact product ID and serial number, ownership and entitlement status, service eligibility, software access, security-update availability, and replacement-hardware arrangements. A service contract must not be assumed to extend support beyond the applicable lifecycle deadline.
Cisco Capital financing is described as available in more than 100 countries for hardware, software, services, and complementary third-party equipment. Financing does not establish warranty coverage or technical support entitlement.
The source also lists safety approvals from the 60950-1 family and Class A emissions standards, including FCC Class A. These historical declarations do not replace current jurisdiction-specific compliance checks.
Before approval, the engineering record should contain the selected software image, measured traffic profile, inspection requirements, connection demand, VPN workload, failover capacity, installation conditions, verified bill of materials, support position, and migration plan.