Cisco Firepower 4100 Series Datasheet: Up to 53 Gbps NGFW

Platform Scope and Deployment Architecture

The Cisco Secure Firewall 4100 Series comprises four 1RU security appliances: FPR-4112, FPR-4115, FPR-4125, and FPR-4145. Deployment use cases include internet edge, data center, and service provider security.

Each platform runs either Cisco Secure Firewall ASA or Cisco Secure Firewall Threat Defense (FTD) software. Software selection determines inspection capabilities, performance limits, management options, and high-availability behavior. ASA firewall ratings must not be used to size FTD inspection deployments.

The family supports flow offloading, programmatic orchestration, and security-service management through RESTful APIs. Trust Anchor Technologies provide supply-chain and software-image assurance. NEBS compliance is supported specifically by the FPR-4125.

Appliance SKU and Configuration Matrix

All four named appliances combine fixed on-chassis interfaces with modular expansion. No separate fixed-only or compact appliance SKUs are identified.

Appliance SKU Form factor Fixed data interfaces Expansion Storage Power configuration
FPR-4112 1RU 8 x 10 Gigabit Ethernet SFP+ 2 network-module slots 400 GB Single 1100W AC; dual AC optional; single or dual 950W DC optional
FPR-4115 1RU 8 x 10 Gigabit Ethernet SFP+ 2 network-module slots 400 GB Single 1100W AC; dual AC optional; single or dual 950W DC optional
FPR-4125 1RU 8 x 10 Gigabit Ethernet SFP+ 2 network-module slots 800 GB Dual 1100W AC
FPR-4145 1RU 8 x 10 Gigabit Ethernet SFP+ 2 network-module slots 800 GB Dual 1100W AC

The supervisor is the Cisco Secure Firewall 4000 Supervisor, incorporating eight 10 Gigabit Ethernet ports and two network-module slots.

Network-Module and Fixed-Interface Matrix

Module descriptions are available, but individual orderable module part numbers are not specified. These descriptions should remain distinct from validated procurement SKUs.

Component or module description Port configuration Engineering distinction
Fixed supervisor data interfaces 8 x 10 Gigabit Ethernet SFP+ Included on chassis
100 Gigabit Ethernet QSFP28 network module 2 x 100 Gigabit Ethernet High-speed modular connectivity
10 Gigabit Ethernet SFP+ network module 8 x 10 Gigabit Ethernet Modular interface expansion
1 Gigabit Ethernet SFP option 8 x 1 Gbps fiber or 4 x 1 Gbps copper Listed under the SFP+ module description
40 Gigabit Ethernet QSFP+ network module 4 x 40 Gigabit Ethernet Modular interface expansion
Copper FTW network module 8 x 1 Gbps copper Ports not configured for fail-to-wire can operate as regular copper ports
SX fiber FTW network module 6 x 1 Gbps Fiber fail-to-wire option
SR fiber FTW network module 6 x 10 Gbps Fiber fail-to-wire option
LR fiber FTW network module 6 x 10 Gbps Fiber fail-to-wire option
SR FTW network module 2 x 40 Gbps Fail-to-wire option
Additional 100Gbps network-module listing 2 x 100 Gbps No separate identifying part number specified
Integrated management interface 1 x 1 Gigabit Ethernet SFP Supports fiber or copper modules
Console 1 x RJ-45 Serial management
USB 1 x USB 2.0 Local USB connectivity

Maximum interface configurations include:

  • Up to 4 x 100 Gigabit Ethernet QSFP28 interfaces.
  • Up to 24 x 10 Gigabit Ethernet SFP+ interfaces.
  • Up to 8 x 40 Gigabit Ethernet QSFP+ interfaces using two modules.
  • Up to 24 x 1 Gigabit Ethernet SFP ports using fixed ports and modules.

These are configuration-specific maxima, not simultaneous additive port counts. Interface speed also does not establish inspection throughput.

FTD Performance and Sizing

FTD metric FPR-4112 FPR-4115 FPR-4125 FPR-4145
Firewall + AVC, 1024-byte traffic 19 Gbps 33 Gbps 45 Gbps 53 Gbps
Firewall + AVC + IPS, 1024-byte traffic 19 Gbps 33 Gbps 45 Gbps 53 Gbps
NGIPS, 1024-byte traffic 19 Gbps 33 Gbps 45 Gbps 55 Gbps
Concurrent sessions with AVC 10 million 15 million 25 million 30 million
New connections/second with AVC 98,000 210,000 269,000 365,000
TLS hardware decryption 4.5 Gbps 6.5 Gbps 8.5 Gbps 10 Gbps
IPsec VPN, 1024-byte TCP with Fastpath 8.5 Gbps 12.5 Gbps 19 Gbps 24 Gbps
Maximum VPN peers 10,000 15,000 20,000 20,000

AVC denotes Application Visibility and Control. The TLS measurement uses 50% TLS 1.2 traffic with AES256-SHA and RSA 2048B keys.

Performance varies with activated features, protocol mix, packet sizes, and software release. Identical firewall-plus-AVC and firewall-plus-AVC-plus-IPS figures do not establish that inspection has no performance cost under every workload.

Presales Selection Rules

  1. Size against the enabled inspection stack. Use the firewall-plus-AVC-plus-IPS row for that feature combination, rather than ASA stateful throughput.
  2. Evaluate TLS independently. Encrypted-traffic inspection requirements must be checked against the decryption rating and its specific test profile.
  3. Check session capacity and connection rate separately. A deployment can fit within its bandwidth limit while exceeding session or connection-establishment capacity.
  4. Separate NGIPS from NGFW sizing. The FPR-4145 provides 55 Gbps NGIPS but 53 Gbps firewall plus AVC plus IPS.
  5. Check both VPN dimensions. Tunnel traffic and peer count impose separate limits.
  6. Do not assume proportional gains across models. FPR-4125 and FPR-4145 both support 20,000 VPN peers despite different throughput ratings.

For an FTD requirement above 33 Gbps and no greater than 45 Gbps under the stated inspection test conditions, FPR-4125 is the first model whose rating covers the requirement. That comparison does not establish spare capacity for traffic growth or a different packet profile.

ASA Performance and Sizing

ASA metric FPR-4112 FPR-4115 FPR-4125 FPR-4145
Stateful firewall throughput 40 Gbps 80 Gbps 80 Gbps 80 Gbps
Multiprotocol firewall throughput 30 Gbps 40 Gbps 45 Gbps 50 Gbps
Concurrent firewall connections 10 million 15 million 25 million 40 million
New connections/second 400,000 848,000 1.1 million 1.5 million
Firewall latency, 64-byte UDP 3.5 microseconds 3.5 microseconds 3.5 microseconds 3.5 microseconds
IPsec VPN, 450-byte UDP L2L 9 Gbps 15 Gbps 19 Gbps 23 Gbps
Maximum VPN peers 10,000 15,000 20,000 20,000
Security contexts, included / maximum 10 / 250 10 / 250 10 / 250 10 / 250

The peak stateful firewall test uses 1500-byte UDP traffic under ideal conditions. The multiprotocol profile consists primarily of TCP-based protocols and applications, including HTTP, SMTP, FTP, IMAPv4, BitTorrent, and DNS.

For mixed application environments, the multiprotocol rating provides a more relevant comparison than the ideal UDP result. FPR-4115, FPR-4125, and FPR-4145 share an 80 Gbps peak rating, but differ in multiprotocol throughput, connection capacity, and connection establishment rate.

ASA and FTD VPN results use different packet sizes and traffic profiles. Their numerical differences should not be interpreted as a controlled software comparison.

Security Features, Licensing, and Management

FTD includes AVC for more than 6,000 applications, with visibility and control covering geolocations, users, and websites. OpenAppID support for custom, open-source application detectors is standard.

Cisco Security Intelligence is standard and supplies IP, URL, and DNS threat intelligence. Additional capabilities include:

Capability Availability and function
Cisco Secure IPS license Available; passive endpoint and infrastructure detection for threat correlation and Indicators of Compromise intelligence
Cisco Malware Defense for Networks Available; malware detection, blocking, tracking, analysis, and containment
Cisco Secure Endpoint correlation Optional integration with malware threat correlation
Cisco Malware Analytics Sandboxing available
URL filtering More than 120 categories and more than 280 million categorized URLs
Automated threat updates Threat feeds and IPS signature updates from Cisco Talos Collective Security Intelligence
Ecosystem integration Open API integration, plus Snort and OpenAppID community resources

A bill of materials should distinguish standard functions from capabilities marked available or optional. Feature availability alone does not establish inclusion in an appliance purchase.

FTD centralized configuration, logging, monitoring, and reporting use Management Center or cloud-based Cisco Defense Orchestrator. ASA uses Cisco Security Manager or Cisco Defense Orchestrator. Adaptive Security Device Manager provides web-based local ASA management for small-scale deployments.

High Availability, Clustering, and Multi-Instance Design

FTD supports active/standby high availability at the appliance level or between logical instances on two different appliances. All four models are multi-instance capable.

FTD clustering supports up to 16 appliances, or up to 16 instances across different appliances using Multi Instance. ASA supports clustering of up to 16 appliances and provides VPN load balancing and firewall clustering.

ASA high availability supports active/standby and active/active configurations. Active/active requires multiple contexts.

Engineering rules for resilient designs are:

  • Size an active/standby design for the surviving active appliance to handle the required workload.
  • Do not equate ASA active/active operation with FTD high availability.
  • Do not treat 16-node clustering as a guaranteed 16-fold throughput multiplier.
  • Validate topology and configuration against the applicable high-availability and clustering configuration guides.
  • Treat ASA security contexts and FTD logical instances as separate software constructs.

Electrical Power and Field Serviceability

Electrical specification AC DC
Input voltage 100 to 240V AC -40V to -60V DC
Maximum input current 13A 27A
Maximum output power 1100W 950W
Frequency 50 to 60 Hz Not applicable
Efficiency at 50% load Greater than 92% Greater than 92.5%

Power-supply redundancy is 1+1. Dual power supplies are hot-swappable. Each chassis contains six hot-swappable fans.

FPR-4112 and FPR-4115 require selection of the optional second supply when redundant power is required. FPR-4125 and FPR-4145 list dual AC supplies.

Power-supply output ratings are not typical appliance consumption figures. Typical chassis consumption, heat dissipation, and PoE budgets are not specified. Electrical planning should not substitute the 1100W supply rating for measured operating demand.

Environmental, Physical, Acoustic, and Reliability Specifications

Parameter Specification
Dimensions, H x W x D 1.75 x 16.89 x 29.7 inches
Metric dimensions 4.4 x 42.9 x 75.4 cm
Rack height 1RU
Mounting Included rails for a 4-post EIA-310-D rack
Equipped weight 39.4 lb / 17.87 kg with two supplies, two network modules, and six fans
Weight without supplies, modules, or fans 31.4 lb / 14.24 kg
Typical acoustic noise 63 dBA
Maximum acoustic noise 74 dBA
Standard operating temperature 32 to 104 degrees F / 0 to 40 degrees C
Nonoperating temperature -40 to 149 degrees F / -40 to 65 degrees C
Operating humidity 5% to 95%, noncondensing
Nonoperating humidity 5% to 95%, noncondensing
Standard maximum operating altitude 10,000 ft
Maximum nonoperating altitude 40,000 ft
MTBF Not specified

The FPR-4145 operating-temperature range is explicitly qualified at sea level. Temperature and altitude maxima should not be combined into an unsupported operating envelope.

Rack planning must account for the 29.7-inch chassis depth, rail installation, cable routing, and service access. The 63 dBA typical and 74 dBA maximum acoustic ratings warrant assessment before installation near occupied work areas.

MTBF is not assigned a numerical value. Hot-swappable components and redundant power describe serviceability features, not a quantified failure rate or availability guarantee.

FPR-4125 NEBS Operating Envelope

NEBS operating conditions apply only to FPR-4125.

Condition Temperature Altitude
Long-term operation 0 to 45 degrees C Up to 6,000 ft
Long-term operation 0 to 35 degrees C 6,000 to 13,000 ft
Short-term operation -5 to 50 degrees C Up to 6,000 ft

The NEBS operating-altitude range is 0 to 13,000 ft. Short-term temperature allowances should not be used as continuous facility design limits.

Regulatory and Compliance Requirements

CE compliance is listed under directives 2004/108/EC and 2006/108/EC.

Safety standards include UL 60950-1, CAN/CSA-C22.2 No. 60950-1, EN 60950-1, IEC 60950-1, AS/NZS 60950-1, and GB4943.

EMC emissions listings include FCC Class A under 47CFR Part 15, AS/NZS CISPR22 Class A, CISPR22 Class A, EN55022 Class A, ICES003 Class A, VCCI Class A, EN61000-3-2, EN61000-3-3, KN22 Class A, CNS13438 Class A, EN300386, and TCVN7189.

Immunity listings include EN55024, CISPR24, EN300386, KN24, TVCN 7317, and EN61000-4 series tests covering -2, -3, -4, -5, -6, -8, and -11.

Warranty, Service, and Procurement Controls

Warranty duration, hardware replacement turnaround, technical-support entitlement, software-update entitlement, and service-contract SKUs are not specified. Procurement acceptance criteria should establish these terms explicitly rather than assume a standard coverage package.

The service schedule should identify:

  • Warranty term and covered components.
  • Hardware replacement service level.
  • Technical-support coverage hours and response commitments.
  • Software maintenance and security-update entitlements.
  • Coverage for power supplies, fans, modules, and optics.
  • Responsibilities for hardware replacement and configuration restoration.

Hot-swappable fans and dual supplies support component replacement, but do not establish an onsite service commitment.

Cisco Capital offers payment solutions in more than 100 countries for hardware, software, services, and complementary third-party equipment. Financing should be evaluated separately from support coverage.

Before quotation release, the engineering package should record the software image, inspection requirements, session and connection-rate targets, VPN requirements, failover capacity, module allocation, power configuration, environmental limits, security entitlements, and service terms. This prevents an interface-complete hardware proposal from being mistaken for a fully sized and supported security deployment.