Cisco Firepower 2100 Series Datasheet: Dual Multicore CPU

Platform Architecture and Deployment Scope

The Cisco Firepower 2100 Series comprises four 1RU security appliances: FPR-2110, FPR-2120, FPR-2130, and FPR-2140. Each uses a dual multicore CPU architecture for firewall, cryptographic, and threat inspection functions. Deployment roles include Internet-edge security, data center firewalling, and dedicated IPS operation.

The appliances run either Cisco Secure Firewall ASA or Threat Defense software. Software selection determines the applicable performance figures, management tools, and high-availability capabilities. ASA stateful firewall throughput must not be used as the sizing value for Threat Defense deployments with application control and IPS.

The principal hardware division is between the fixed-interface FPR-2110/FPR-2120 and the expansion-capable FPR-2130/FPR-2140. The latter provide integrated 10 Gigabit interfaces, optional network modules, and redundant power configurations.

Appliance SKU and Interface Matrix

The complete set of named appliance identifiers is shown below. Network module, power supply, rail, and transceiver ordering SKUs are not specified. No compact appliance SKU is identified.

Appliance SKU Interface configuration Integrated copper interfaces Integrated optical interfaces Optional network modules Maximum Ethernet ports
FPR-2110 Fixed 12 x 10M/100M/1GBASE-T RJ-45 4 x 1 Gigabit SFP None 16
FPR-2120 Fixed 12 x 10M/100M/1GBASE-T RJ-45 4 x 1 Gigabit SFP None 16
FPR-2130 Integrated ports plus modular expansion 12 x 10M/100M/1GBASE-T RJ-45 4 x 10 Gigabit SFP+ 10G SFP+; 1/10G fail-to-wire Up to 24
FPR-2140 Integrated ports plus modular expansion 12 x 10M/100M/1GBASE-T RJ-45 4 x 10 Gigabit SFP+ 10G SFP+; 1/10G fail-to-wire Up to 24

All four models additionally provide:

  • One dedicated 10M/100M/1GBASE-T RJ-45 management port.
  • One RJ-45 serial console port.
  • One USB 2.0 Type-A port rated at 500 mA.

Presales rule: Select FPR-2130 or FPR-2140 when integrated 10 Gigabit connectivity, interface expansion, or fail-to-wire modules are required. FPR-2110 and FPR-2120 have no network module option.

Fail-to-wire modules support dedicated threat sensor deployments. Module selection must follow the required link speed and deployment topology; the available descriptions do not establish individual module port counts or ordering identifiers.

Threat Defense Performance and Capacity

Metric FPR-2110 FPR-2120 FPR-2130 FPR-2140
Firewall + AVC, 1024-byte traffic 2.6 Gbps 3.4 Gbps 5.4 Gbps 10.4 Gbps
Firewall + AVC + IPS, 1024-byte traffic 2.6 Gbps 3.4 Gbps 5.4 Gbps 10.4 Gbps
Dedicated IPS, 1024-byte traffic 2.6 Gbps 3.5 Gbps 5.4 Gbps 10.5 Gbps
Maximum concurrent sessions with AVC 1 million 1.5 million 2 million 3 million
Maximum new connections/second with AVC 14,000 18,000 30,000 57,000
TLS throughput 365 Mbps 475 Mbps 760 Mbps 1.4 Gbps
IPsec VPN, 1024-byte TCP with Fastpath 950 Mbps 1.2 Gbps 1.9 Gbps 3.6 Gbps
Maximum VPN peers 1,500 3,500 7,500 10,000

AVC means Application Visibility and Control.

The firewall-plus-AVC and firewall-plus-AVC-plus-IPS figures are identical for each model under the stated test conditions. This does not establish equivalent performance for every combination of security services. Performance varies with enabled features, protocol mix, packet sizes, and software releases.

TLS throughput is a separate sizing constraint. An FPR-2140 has a 10.4 Gbps firewall-plus-AVC-plus-IPS rating, but its listed TLS throughput is 1.4 Gbps. Encrypted traffic inspection requirements therefore require an independent capacity check.

Dedicated IPS ratings also require careful interpretation. The FPR-2120 provides 3.5 Gbps for IPS versus 3.4 Gbps for firewall plus AVC plus IPS. The corresponding FPR-2140 figures are 10.5 Gbps and 10.4 Gbps.

ASA Performance and Virtualization

Metric FPR-2110 FPR-2120 FPR-2130 FPR-2140
Stateful inspection firewall throughput 3 Gbps 6 Gbps 10 Gbps 20 Gbps
Multiprotocol firewall throughput 1.5 Gbps 3 Gbps 5 Gbps 10 Gbps
Concurrent firewall connections 1 million 1.5 million 2 million 3 million
New connections/second 18,000 28,000 40,000 75,000
IPsec VPN, 450-byte UDP L2L test 500 Mbps 700 Mbps 1 Gbps 2 Gbps
Maximum VPN peers 1,500 3,500 7,500 10,000
Security contexts included 2 2 2 2
Maximum security contexts 25 25 30 40

The headline stateful inspection figures use 1500-byte UDP traffic under ideal test conditions. Multiprotocol testing uses a traffic profile consisting primarily of TCP-based protocols and applications, including HTTP, SMTP, FTP, IMAPv4, BitTorrent, and DNS.

Presales rule: Use the multiprotocol rating as the more relevant initial comparison for mixed-application ASA requirements, rather than treating the ideal-condition UDP figure as an assured production rate.

ASA and Threat Defense VPN figures use different test methods. The ASA 450-byte UDP LAN-to-LAN results and Threat Defense 1024-byte TCP Fastpath results are not equivalent benchmarks.

Firewall latency values are not specified. No numeric latency commitment should be attached to these throughput tables.

Security Services and Management

Threat Defense includes standard AVC support for more than 4,000 applications, together with geolocation, user, and website visibility and control. OpenAppID support enables custom, open-source application detectors.

Cisco Security Intelligence is standard and supplies IP, URL, and DNS threat intelligence. Additional available capabilities include:

  • Firepower NGIPS: Passive endpoint and infrastructure detection for threat correlation and Indicators of Compromise intelligence.
  • AMP for Networks: Malware detection, blocking, tracking, analysis, and containment during and after attacks.
  • Secure Endpoint correlation: Optional integrated threat correlation with Cisco Secure Endpoint.
  • AMP Threat Grid: Available sandboxing.
  • URL filtering: More than 80 categories and more than 280 million categorized URLs.

Automated threat feeds and IPS signature updates use Collective Security Intelligence from Cisco Talos. An open API supports third-party integrations, while Snort and OpenAppID provide community resources.

Trust Anchor Technologies provide supply chain and software image assurance.

Software Local management Centralized management
Threat Defense Firepower Device Manager on all four models Management Center or cloud-based Cisco Defense Orchestrator
ASA Web-based Adaptive Security Device Manager Cisco Security Manager or cloud-based Cisco Defense Orchestrator

Centralized management covers configuration, logging, monitoring, and reporting. Available security capabilities should be distinguished from standard capabilities during commercial scoping; subscription SKUs and entitlement terms are not specified.

Availability and Presales Sizing Rules

Threat Defense lists active/standby high availability. ASA supports active/active and active/standby operation, with VPN Load Balancing identified as a scalability capability. No clustering capacity or cluster size is specified.

A sizing exercise should evaluate each requirement independently:

  1. Choose the software first. Apply ASA or Threat Defense measurements consistently.
  2. Match the inspection role. Distinguish stateful firewalling, application-aware firewalling, combined IPS inspection, and dedicated IPS.
  3. Check encrypted traffic separately. Compare TLS and VPN requirements against their own ratings.
  4. Check session scale and connection rate. Aggregate bandwidth alone does not address connection-heavy workloads.
  5. Check VPN peers independently of throughput. Peer count and encrypted traffic volume are separate limits.
  6. Check interfaces before finalizing capacity. Port speed, media, expansion, and fail-to-wire requirements can determine the model.
  7. Size for failover operation. Do not treat an active/standby pair as twice the listed forwarding capacity.
  8. Reserve deployment-specific headroom. Select headroom through workload evaluation rather than inventing a universal derating percentage.

For example, a Threat Defense requirement exceeding 475 Mbps of TLS throughput eliminates FPR-2110 and FPR-2120 on the listed TLS ratings alone. A requirement for more than 25 ASA security contexts similarly directs evaluation toward FPR-2130 or FPR-2140.

Power, Storage, and Cooling

Specification FPR-2110 FPR-2120 FPR-2130 FPR-2140
Installed storage 1 x 100 GB 1 x 100 GB 1 x 200 GB 1 x 200 GB
Spare storage slot 1, for MSP 1, for MSP 1, for MSP 1, for MSP
AC supply configuration Single integrated 250 W Single integrated 250 W Single 400 W; dual optional Dual 400 W
DC supply option Not listed Not listed Single/dual 350 W Single/dual 350 W
Power redundancy None None 1+1 AC or DC with dual supplies 1+1 AC or DC with dual supplies
AC maximum input current <2.7 A at 100 V <2.7 A at 100 V <6 A at 100 V <6 A at 100 V
AC efficiency at 50% load >88% >88% >89% >89%

All models accept 100 to 240 V AC at 50 to 60 Hz. FPR-2130 and FPR-2140 DC options accept -48 to -60 V DC, with maximum input current below 12.5 A at -48 V and efficiency above 88% at 50% load. Dual power supplies are hot-swappable.

Power supply output ratings are not measured appliance power consumption. No PoE capability or PoE budget is specified.

FPR-2110 and FPR-2120 contain four integrated fans: two internal and two exhaust. FPR-2130 and FPR-2140 use one hot-swappable module containing four fans.

Fans operate in a 3+1 redundant configuration. The appliance continues operating with three functional fans, which then run at full speed. Power redundancy and fan redundancy should be evaluated separately.

Environmental and Physical Specifications

All models measure 1.73 x 16.90 x 19.76 inches, or 4.4 x 42.9 x 50.2 cm, in height x width x depth. Each occupies 1RU.

Specification FPR-2110 FPR-2120 FPR-2130 FPR-2140
Listed weight 16.1 lb / 7.3 kg 16.1 lb / 7.3 kg 19.4 lb / 8.8 kg 21 lb / 9.53 kg
Noise at 25 C 56 dBA 56 dBA 56 dBA 56 dBA
Noise at highest system performance 74 dBA 74 dBA 77 dBA 77 dBA
Included mounting hardware Two-post fixed brackets Two-post fixed brackets Four-post rails Four-post rails
Optional mounting hardware Four-post rails Four-post rails Not specified Not specified

Four-post rails support EIA-310-D racks. FPR-2110 and FPR-2120 weights include two SSDs. FPR-2130 weight includes one power supply, one network module, one fan module, and two SSDs. FPR-2140 weight includes two power supplies, one network module, one fan module, and two SSDs.

Common environmental limits are:

Parameter Limit
Operating temperature 32 to 104 F / 0 to 40 C
Nonoperating temperature -4 to 149 F / -20 to 65 C
Operating humidity 10% to 85%, noncondensing
Nonoperating humidity 5% to 95%, noncondensing
Maximum operating altitude 10,000 ft, except the FPR-2130 NEBS operating envelope
Maximum nonoperating altitude 40,000 ft
MTBF Not specified

Acoustic planning should account for the highest-performance values, not only the 25 C measurements. MTBF must not be inferred from redundant fans or power supplies.

FPR-2130 NEBS Operating Envelope

FPR-2130 is designed to be NEBS ready; NEBS certification availability is identified as pending.

Its listed NEBS operating envelope includes:

  • Operating altitude from 0 to 13,000 ft.
  • Long-term temperature of 0 to 45 C up to 6,000 ft.
  • Long-term temperature of 0 to 35 C from 6,000 to 13,000 ft.
  • Short-term temperature of -5 to 55 C up to 6,000 ft.

These conditions apply only to FPR-2130 and must not be extended to other models. NEBS readiness must not be represented as completed certification.

Regulatory, Safety, and EMC Requirements

CE compliance lists directives 2004/108/EC and 2006/108/EC.

Safety standards include UL 60950-1, CAN/CSA-C22.2 No. 60950-1, EN 60950-1, IEC 60950-1, AS/NZS 60950-1, and GB4943.

Emissions coverage includes FCC Class A under 47CFR Part 15; AS/NZS CISPR22, CISPR22, EN55022, ICES003, VCCI, KN22, and CNS13438 Class A; plus EN61000-3-2, EN61000-3-3, EN300386, and TCVN7189.

Immunity standards include EN55024, CISPR24, EN300386, KN24, TVCN 7317, EN-61000-4-2, EN-61000-4-3, EN-61000-4-4, EN-61000-4-5, EN-61000-4-6, EN-61000-4-8, and EN61000-4-11.

Warranty, Service, and Commercial Planning

Warranty duration, hardware replacement commitments, return procedures, support hours, software maintenance entitlements, and service contract SKUs are not specified. Procurement requirements should identify these items explicitly rather than treating hardware redundancy as a service commitment.

Service planning should distinguish integrated components from replaceable assemblies. FPR-2110 and FPR-2120 have integrated power supplies and fans. FPR-2130 and FPR-2140 offer dual hot-swappable supplies and a hot-swappable fan module. These differences affect maintenance planning but do not establish replacement delivery times or support coverage.

A complete commercial scope should identify appliance model, operating software, management platform, optional security capabilities, required modules, power configuration, mounting hardware, and support terms.

Cisco Capital offers financing in more than 100 countries for hardware, software, services, and complementary third-party equipment. Financing is separate from warranty coverage and technical support entitlements.