Cisco Firepower 1000 Series Datasheet: Up to 6.1 Gbps IPS
Platform Scope and Selection Criteria
The Cisco Firepower 1000 Series consists of compact and 1U firewall appliances for small offices and remote branches. Platforms run either Cisco Secure Firewall Threat Defense (FTD) or Cisco Secure Firewall ASA software. The family includes the 1010, 1010E, 1120, 1140, and 1150.
Software selection is a primary sizing decision. FTD performance figures cover Application Visibility and Control (AVC), intrusion prevention, TLS processing, and IPsec VPN. ASA figures describe stateful firewall and VPN performance under different test conditions. These figures are not interchangeable.
Presales qualification should establish:
- Required software image and security functions.
- Inspected traffic volume, including traffic requiring TLS processing.
- Concurrent sessions and peak new connections per second.
- VPN throughput and peer count.
- Copper, SFP, and SFP+ interface requirements.
- High-availability and management architecture.
- Physical installation, power, acoustics, and environmental constraints.
Performance varies with enabled features, protocol mix, packet sizes, and software releases. Published throughput is a test result, not a guaranteed production forwarding rate.
Appliance and SKU Matrix
The following matrix covers every appliance identifier named in the product tables. Full ordering bundle identifiers, software subscription SKUs, transceiver SKUs, and accessory part numbers are not specified.
| Model identifier | Named SKU where stated | Physical category | Fixed network interfaces | PoE capability | Mounting |
|---|---|---|---|---|---|
| 1010 | FPR-1010 | Compact | 8 x 1000BASE-T | 2 x PoE+ ports, IEEE 802.3at | Desktop, wall-mount, optional rack kit |
| 1010E | Not specified | Compact | 8 x 1000BASE-T | None | Desktop, wall-mount, optional rack kit |
| 1120 | FPR-1120 | Fixed 1U appliance | 8 x 1000BASE-T, 4 x SFP | None | 2-post brackets included |
| 1140 | FPR-1140 | Fixed 1U appliance | 8 x RJ-45, 4 x SFP | None | 2-post brackets included |
| 1150 | FPR-1150 | Fixed 1U appliance | 8 x RJ-45, 2 x SFP, 2 x 10G SFP+ | None | 2-post brackets included |
No modular chassis, expansion-module SKU, or field-expandable interface configuration is specified. SFP and SFP+ connectivity should not be interpreted as a modular chassis architecture.
The 1010 and 1010E share the published performance ratings. Their explicit hardware differences are PoE support and maximum AC power draw: 115 W for the 1010 versus 55 W for the 1010E.
FTD Performance and Capacity
FTD firewall, combined inspection, and NGIPS throughput figures use 1024-byte traffic. IPsec throughput uses 1024-byte TCP with Fastpath.
| FTD metric | 1010 / 1010E | 1120 | 1140 | 1150 |
|---|---|---|---|---|
| Firewall + AVC | 890 Mbps | 2.3 Gbps | 3.3 Gbps | 5.3 Gbps |
| Firewall + AVC + IPS | 880 Mbps | 2.3 Gbps | 3.3 Gbps | 4.9 Gbps |
| NGIPS | 900 Mbps | 2.6 Gbps | 3.5 Gbps | 6.1 Gbps |
| TLS | 195 Mbps | 850 Mbps | 1.2 Gbps | 1.4 Gbps |
| Maximum concurrent sessions with AVC | 100,000 | 200,000 | 400,000 | 600,000 |
| Maximum new connections/s with AVC | 6,000 | 15,000 | 22,000 | 28,000 |
| IPsec VPN | 400 Mbps | 1.2 Gbps | 1.4 Gbps | 2.4 Gbps |
| Maximum VPN peers | 75 | 150 | 400 | 800 |
FTD Sizing Rules
Use the combined inspection row for IPS-enabled firewall designs. The 1150 supports 5.3 Gbps for firewall plus AVC, but 4.9 Gbps with IPS included. Its 6.1 Gbps NGIPS figure is not the equivalent of combined firewall, AVC, and IPS throughput.
Treat TLS as a separate sizing constraint. The 1010’s 890 Mbps firewall-plus-AVC rating does not establish comparable encrypted-traffic inspection capacity; its TLS rating is 195 Mbps. The same distinction applies throughout the family.
Check connection rate independently of bandwidth. Session-heavy or short-lived traffic can stress connection establishment before reaching a throughput limit. Under FTD with AVC, the 1120 supports 15,000 new connections/s versus 22,000 for the 1140.
Check concurrent sessions independently of connection rate. Long-lived connections consume session capacity even when bandwidth is modest. Capacity increases from 100,000 sessions on the compact models to 600,000 on the 1150.
Do not equate port speed with inspection capacity. The 1150 provides 10G SFP+ interfaces, but its published combined firewall, AVC, and IPS throughput is 4.9 Gbps.
Do not add feature throughput figures together. TLS, VPN, and firewall ratings are separate measurements. They do not define a combined simultaneous workload guarantee.
ASA Performance and Capabilities
ASA stateful firewall throughput uses 1500-byte UDP under ideal test conditions. The multiprotocol profile consists primarily of TCP applications and protocols, including HTTP, SMTP, FTP, IMAPv4, BitTorrent, and DNS.
ASA IPsec results use a 450-byte UDP LAN-to-LAN test, unlike the FTD VPN methodology.
| ASA metric | 1010 / 1010E | 1120 | 1140 | 1150 |
|---|---|---|---|---|
| Stateful firewall throughput | 2 Gbps | 4.5 Gbps | 6 Gbps | 7.5 Gbps |
| Multiprotocol firewall throughput | 1.4 Gbps | 2.5 Gbps | 3.5 Gbps | 4.5 Gbps |
| Concurrent firewall connections | 100,000 | 200,000 | 400,000 | 600,000 |
| New connections/s | 25,000 | 75,000 | 100,000 | 150,000 |
| IPsec VPN throughput | 500 Mbps | 1 Gbps | 1.2 Gbps | 1.7 Gbps |
| Maximum VPN peers | 75 | 150 | 400 | 800 |
| Security contexts, included / maximum | N/A | 2 / 5 | 2 / 5 | 2 / 25 |
| High availability | Active/standby | Active/active or active/standby | Active/active or active/standby | Active/active or active/standby |
VPN load balancing is listed as an ASA scalability capability. Clustering and 64-byte UDP firewall latency have no numerical or affirmative specification.
For mixed application traffic, the multiprotocol result is the more relevant published comparison than the ideal UDP figure. Neither should be treated as a guaranteed site-specific result.
The 1150 is the only listed appliance with a maximum of 25 ASA security contexts. The 1120 and 1140 each include two contexts and support a maximum of five. Compact-model contexts are marked N/A.
Security Functions and Management
FTD Security Functions
AVC is standard and supports more than 4,000 applications, together with geolocations, users, and websites. OpenAppID support for custom, open-source application detectors is also standard.
Cisco Security Intelligence is standard and includes IP, URL, and DNS threat intelligence.
Available security functions include:
- Cisco IPS: Passive detection of endpoints and infrastructure for threat correlation and Indicators of Compromise intelligence.
- Cisco Malware Defense for Networks: Detection, blocking, tracking, analysis, and containment of targeted and persistent malware.
- Endpoint correlation: Optional integrated threat correlation with Cisco AMP for Endpoints.
- Cisco Malware Analytics: Sandboxing.
- URL filtering: More than 80 categories and more than 280 million categorized URLs.
Automated threat feeds and IPS signature updates use Cisco Talos Collective Security Intelligence. Third-party integration is supported through an open API. Snort and OpenAppID community resources support additional threat coverage and application detection.
Features described as available should be explicitly qualified in the commercial design. Subscription part numbers, entitlement terms, and feature bundle pricing are not specified.
Management Options
| Software | Local management | Centralized management |
|---|---|---|
| FTD | Cisco Device Manager | Threat Defense Manager (FMC) or Cisco Defense Orchestrator |
| ASA | Adaptive Security Device Manager | Cisco Security Manager or Cisco Defense Orchestrator |
Centralized management covers configuration, logging, monitoring, and reporting. ASA local management is described as web-based and intended for small-scale deployments.
The platforms include Cisco Trust Anchor Technologies for supply-chain and software-image assurance. Specific implementation details are not enumerated.
High Availability and Architecture Rules
FTD supports active/standby high availability across the listed models. ASA supports active/standby on the compact models and active/active or active/standby on the rack appliances.
Apply these design rules:
- Size an active/standby deployment for one appliance carrying the required workload. Do not add the two appliances’ throughput ratings.
- Do not transfer ASA HA capabilities to FTD. Active/active is listed for ASA on the rack models, not for FTD.
- Do not specify clustering from the HA entries. No clustering capability is affirmatively listed.
- Separate appliance availability from power architecture. Rack models have an integrated supply with a single AC input; compact models use an external AC supply.
- Validate interface allocation before ordering. The fixed interface inventory must accommodate the planned network topology.
Physical, Power, and Environmental Specifications
Dimensions and Installation
| Specification | 1010 / 1010E | 1120 | 1140 | 1150 |
|---|---|---|---|---|
| Dimensions, H x W x D | 1.82 x 7.85 x 8.07 in. | 1.72 x 17.2 x 10.58 in. | 1.72 x 17.2 x 10.58 in. | 1.72 x 17.2 x 10.58 in. |
| Weight | 3 lb / 1.4 kg | 8 lb / 3.6 kg | 8 lb / 3.6 kg | 8 lb / 3.6 kg |
| Form factor | Compact desktop/wall-mount | 1U rack | 1U rack | 1U rack |
| Fans | None | 1 integrated | 1 integrated | 1 integrated |
| Rack hardware | Optional kit | 2-post brackets included | 2-post brackets included | 2-post brackets included |
Every model has one 1000BASE-T management interface, one RJ-45 serial console, one USB 3.0 Type-A port rated at 500 mA, and one 200 GB storage device. The storage medium type is not specified.
Electrical Characteristics
| Specification | 1010 | 1010E | 1120 / 1140 / 1150 |
|---|---|---|---|
| Supply arrangement | External AC supply | External AC supply | Integrated, single AC input |
| Input voltage | 100-240 V AC | 100-240 V AC | 100-240 V AC |
| Maximum AC power draw | 115 W | 55 W | 100 W each |
| AC frequency | 50-60 Hz | 50-60 Hz | 50-60 Hz |
| Efficiency at 50% load | >88% | >88% | >85% |
Maximum current draw is less than 2 A at 100 V and less than 1 A at 240 V across the family.
Only the 1010 provides PoE: two IEEE 802.3at PoE+ ports. An aggregate PoE budget and per-port deliverable power are not specified. The 115 W maximum AC draw must not be represented as a PoE budget.
Acoustics
| Model | Noise at 25 C | Noise at highest system performance |
|---|---|---|
| 1010 / 1010E | 0 dBA specified | No separate value specified |
| 1120 | 31.7 dBA | 56.8 dBA |
| 1140 | 34.2 dBA | 56.8 dBA |
| 1150 | 34.2 dBA | 56.8 dBA |
The fanless compact units are the appropriate candidates when the installation requires the listed 0 dBA acoustic characteristic. Rack-unit placement should account for the higher published maximum noise level.
Environmental Limits and Reliability
All models share these limits:
| Parameter | Limit |
|---|---|
| Operating temperature | 32-104 F / 0-40 C |
| Nonoperating temperature | -13 to 158 F / -25 to 70 C |
| Operating humidity | 90%, noncondensing |
| Nonoperating humidity | 10-90%, noncondensing |
| Maximum operating altitude | 9,843 ft / 3,000 m |
| Maximum nonoperating altitude | 15,000 ft |
| MTBF | Not specified |
Site acceptance should check the appliance’s installation environment, not merely general room conditions. No MTBF-based availability calculation or component replacement interval is established by these specifications.
Regulatory, Safety, and EMC
Regulatory compliance includes CE markings under directives 2004/108/EC and 2006/108/EC.
Safety standards are UL 60950-1, CAN/CSA-C22.2 No. 60950-1, EN 60950-1, IEC 60950-1, AS/NZS 60950-1, and GB4943.
Emissions listings include FCC Class A under 47CFR Part 15, AS/NZS CISPR22 Class A, CISPR22 Class A, EN55022 Class A, ICES003 Class A, VCCI Class A, KN22 Class A, CNS13438 Class A, EN61000-3-2, EN61000-3-3, EN300386, and TCVN7189.
Immunity listings include EN55024, CISPR24, EN300386, KN24, TVCN 7317, and EN-61000-4-2, -4-3, -4-4, -4-5, -4-6, -4-8, and EN61000-4-11.
Warranty, Service, and Commercial Planning
Warranty duration, return-to-factory coverage, advance replacement, service response times, support hours, and software maintenance entitlements are not specified. No warranty or support SKU is listed.
The bill of materials and service proposal should separately establish:
- Appliance ordering identifiers and software image.
- Required security subscriptions and management components.
- Hardware replacement coverage and delivery commitments.
- Technical support access and response objectives.
- Software update and maintenance entitlements.
- Optional compact rack mounting and required interface accessories.
Available security functionality does not establish an included service entitlement. Likewise, automated threat updates should not be interpreted as a defined warranty or maintenance term.
Cisco Capital payment solutions cover hardware, software, services, and complementary third-party equipment in more than 100 countries. Financing availability does not define support coverage.
Presales Model Selection Rules
- 1010: Evaluate for compact installations needing two PoE+ ports. Validate the 195 Mbps TLS rating, 400 Mbps FTD VPN rating, and 75-peer limit.
- 1010E: Evaluate where compact, fanless operation is required without PoE. Performance matches the 1010, while maximum AC draw is 55 W.
- 1120: Evaluate for 1U deployments requiring four SFP interfaces, 2.3 Gbps combined FTD inspection, and up to 200,000 sessions.
- 1140: Evaluate when the 1120 interface arrangement is suitable but higher inspection, session, or connection-establishment capacity is required.
- 1150: Evaluate for 10G SFP+ connectivity, 600,000 sessions, 800 VPN peers, or the highest listed inspection capacity. Its 1.4 Gbps TLS rating remains a separate constraint.
Final engineering acceptance should validate the intended software release, enabled security functions, representative packet sizes, connection behavior, VPN demand, and failover workload. Select against the limiting requirement rather than the largest headline throughput.