Secure Firewall 3100 Series Datasheet: Up to 45 Gbps IPS
Platform Scope and Deployment Architecture
The Cisco Secure Firewall 3100 Series comprises five 1RU security appliances: 3105, 3110, 3120, 3130, and 3140. Deployment use cases include the Internet edge, data center, and private cloud. Each model can run either ASA or Firewall Threat Defense (FTD) software and supports deployment in firewall or dedicated IPS mode.
The architecture combines a modern CPU design with purpose-built hardware for firewall processing, cryptography, and threat inspection. Software selection determines the relevant performance benchmarks, management tools, and security capabilities; ASA throughput must not be substituted for FTD inspection capacity.
For inline sets and passive interfaces, the series supports Q-in-Q encapsulation with up to two 802.1Q headers per packet. Trust Anchor Technologies provide supply chain and software image assurance.
Model, Interface, and SKU Matrix
All five models combine fixed integrated interfaces with optional network-module expansion. No separate compact appliance models are identified. Complete orderable appliance, module, power-supply, and accessory SKU strings are not specified; FPR-3120 is explicitly identified for the NEBS-related platform description.
Appliance Matrix
All models include eight 10M/100M/1GBASE-T RJ-45 Ethernet interfaces.
| Model designation | Form factor | Additional fixed Ethernet interfaces | Optional network module | Maximum Ethernet ports | Standard AC configuration |
|---|---|---|---|---|---|
| 3105 | 1RU | 8 x 1/10G SFP interfaces | 8 x 1/10G | Up to 24 | Single 400W |
| 3110 | 1RU | 8 x 1/10G SFP interfaces | 8 x 1/10G | Up to 24 | Single 400W |
| 3120; also identified as FPR-3120 | 1RU | 8 x 1/10G SFP interfaces | 8 x 1/10G | Up to 24 | Single 400W |
| 3130 | 1RU | 8 x 1/10/25G SFP interfaces | 8 x 1/10/25G or 4 x 40G | Up to 24 | Dual 400W |
| 3140 | 1RU | 8 x 1/10/25G SFP interfaces | 8 x 1/10/25G or 4 x 40G | Up to 24 | Dual 400W |
The 24-port maximum depends on module selection. A four-port 40G module must not be treated as an eight-port expansion option.
Modular Components and Accessories
| Component or option | Applicable models | Configuration details | Orderable SKU |
|---|---|---|---|
| 8-port 1/10G network module | 3105, 3110, 3120 | Ethernet expansion | Not specified |
| 8-port 1/10/25G network module | 3130, 3140 | Ethernet expansion | Not specified |
| 4-port 40G network module | 3130, 3140 | Ethernet expansion | Not specified |
| 400W AC supply | All | Optional dual AC on 3105-3120; dual AC standard on 3130-3140 | Not specified |
| 400W DC supply | All | Optional single or dual DC | Not specified |
| Fan modules | All | Two hot-swappable modules, two fans each | Not specified |
| Storage | All | One 900 GB drive and one spare slot | Not specified |
| Four-post mounting rails | All | Included; EIA-310-D rack | Not specified |
| Two-post fixed mounting brackets | All | Optional | Not specified |
Presales rule: Select the chassis for both processing capacity and interface requirements. The 3130 and 3140 provide integrated 25G connectivity and optional 40G modules; the 3105, 3110, and 3120 have integrated optical interface speeds up to 10G.
FTD Performance and Capacity
Throughput values below are in Gbps. FW means firewall; AVC means Application Visibility and Control.
| FTD metric | 3105 | 3110 | 3120 | 3130 | 3140 |
|---|---|---|---|---|---|
| FW + AVC, 1024B | 10.0 | 17.0 | 21.0 | 38.0 | 45.0 |
| FW + AVC + IPS, 1024B | 10.0 | 17.0 | 21.0 | 38.0 | 45.0 |
| NGIPS, 1024B | 10.0 | 17.0 | 21.0 | 38.0 | 45.0 |
| Maximum concurrent sessions with AVC | 1.5 million | 2 million | 4 million | 6 million | 10 million |
| Maximum new connections/second with AVC | 90,000 | 130,000 | 170,000 | 240,000 | 300,000 |
| TLS benchmark | 3.2 | 4.8 | 6.7 | 9.1 | 11.5 |
| IPsec VPN, 1024B TCP with Fastpath | 5.5 | 8.0 | 10.0 | 17.8 | 22.4 |
| Projected IPsec with VPN offload, FTD 7.2 | N/A | 11.0 | 13.5 | 33.0 | 39.4 |
| Maximum VPN peers | 2,000 | 3,000 | 7,000 | 15,000 | 20,000 |
The TLS benchmark uses 50% TLS 1.2 traffic with AES256-SHA and RSA 2048B keys. It is not a universal throughput guarantee for arbitrary encrypted traffic.
FW + AVC and FW + AVC + IPS have identical listed throughput values. This does not establish that every additional security function has no processing cost. Performance varies with enabled features, protocol mix, packet sizes, and software release.
FTD Sizing Rules
- Size inspection separately from basic forwarding. Use FW + AVC + IPS capacity when those functions are required.
- Evaluate TLS as an independent constraint. A firewall selected only for aggregate inspected throughput can be undersized for its encrypted workload.
- Check session count and connection establishment independently. Long-lived sessions and short-lived transaction bursts stress different capacity limits.
- Retain the projected designation for VPN offload. Do not present the FTD 7.2 projections as unconditional measured results.
- Check VPN peers as well as bandwidth. Tunnel population can determine model selection before throughput does.
- Allow project-specific headroom. No fixed sizing margin or performance derating percentage is specified.
ASA Performance and Capacity
ASA stateful inspection throughput uses 1500B UDP traffic under ideal test conditions. The multiprotocol profile primarily comprises TCP-based protocols and applications, including HTTP, SMTP, FTP, IMAPv4, BitTorrent, and DNS.
| ASA metric | 3105 | 3110 | 3120 | 3130 | 3140 |
|---|---|---|---|---|---|
| Stateful firewall throughput, Gbps | 10.0 | 18.0 | 22.0 | 42.0 | 49.0 |
| Multiprotocol firewall throughput, Gbps | 9.0 | 15.0 | 17.0 | 39.0 | 43.0 |
| Concurrent firewall connections | 1.5 million | 2 million | 4 million | 6 million | 10 million |
| New connections/second | 150,000 | 300,000 | 500,000 | 875,000 | 1,100,000 |
| IPsec VPN, 450B UDP L2L, Gbps | 5.5 | 8.0 | 10.0 | 14.0 | 17.0 |
| Projected IPsec with VPN offload, ASA 9.18, Gbps | 7.0 | 12.0 | 15.4 | 28.0 | 33.0 |
| Maximum VPN peers | 2,000 | 3,000 | 7,000 | 15,000 | 20,000 |
| Security contexts, included/maximum | 2/100 | 2/100 | 2/100 | 2/100 | 2/100 |
ASA supports VPN load balancing. Every model includes two security contexts and supports a maximum of 100; the maximum must not be represented as the included entitlement.
Presales rule: Use the multiprotocol benchmark when discussing mixed application traffic, while retaining its test-profile qualification. ASA and FTD VPN results use different packet sizes and traffic types and are not directly interchangeable.
Security Functions and Management
FTD Capabilities
AVC is standard and supports more than 4,000 applications, together with geolocations, users, and websites. OpenAppID support for custom, open-source application detectors is also standard.
Cisco Security Intelligence is standard and provides IP, URL, and DNS threat intelligence. Additional available capabilities include:
- Cisco Secure IPS: Passive endpoint and infrastructure detection for threat correlation and Indicators of Compromise intelligence.
- Cisco Malware Defense: Detection, blocking, tracking, analysis, and containment of targeted and persistent malware, including activity during and after attacks.
- Cisco Secure Endpoint correlation: Optional integrated threat correlation.
- Cisco Secure Malware Analytics: Available.
- URL filtering: More than 80 categories and more than 280 million categorized URLs.
Automated threat feeds and IPS signature updates use Collective Security Intelligence from Cisco Talos. An open API supports third-party integration, while Snort and OpenAppID community resources support additional threat and application detection requirements.
Local on-device management is available on every model. Centralized configuration, logging, monitoring, and reporting use Firewall Management Center or cloud-based Cisco Defense Orchestrator.
ASA Management
ASA centralized configuration, logging, monitoring, and reporting use Cisco Security Manager or Cisco Defense Orchestrator. Adaptive Security Device Manager provides web-based local management for small-scale deployments.
Commercial rule: Distinguish features identified as standard from features identified as available or optional. Subscription identifiers, term lengths, and feature-specific license prices are not specified.
High Availability and Scaling
The series lists active/active and active/standby high availability. Clustering supports up to eight chassis on the 3110, 3120, 3130, and 3140. The 3105 does not support clustering.
Availability planning should separate appliance failure, power-supply failure, and fan failure. These are addressed by different mechanisms and should appear separately in the engineering design.
For active/standby deployments, size the surviving appliance for the required failover workload rather than adding both appliances’ throughput. For clustered deployments, do not assume an eight-chassis cluster provides exactly eight times single-appliance capacity; no cluster scaling efficiency is specified.
The 3105 remains an option for non-clustered deployments but should be excluded when chassis clustering is a mandatory requirement.
Physical, Environmental, and Reliability Specifications
Common Chassis Specifications
| Parameter | Specification |
|---|---|
| Rack height | 1RU |
| Dimensions, H x W x D | 1.75 x 17 x 20 in. |
| Metric dimensions, H x W x D | 4.4 x 43.3 x 50.8 cm |
| Dedicated network management | 1 x 1/10G SFP |
| Serial console | 1 x RJ-45 |
| USB | 1 x USB 3.0 Type-A, 900mA |
| Storage | 1 x 900 GB; 1 spare slot |
| Operating temperature | 32 to 104 degrees F; 0 to 40 degrees C |
| Nonoperating temperature | -4 to 149 degrees F; -20 to 65 degrees C |
| Operating humidity | 10% to 85%, noncondensing |
| Nonoperating humidity | 5% to 95%, noncondensing |
| Maximum standard operating altitude | 10,000 ft |
| Maximum nonoperating altitude | 40,000 ft |
| Acoustic noise at 25 degrees C | 65 dBA |
| Maximum acoustic noise | 74 dBA |
| MTBF | Not specified |
The 3105, 3110, and 3120 weigh 23 lb, or 10.5 kg, in the listed configuration with one power supply, one network module, fan module, and one SSD. The 3130 and 3140 weigh 25 lb, or 11.4 kg, with two power supplies, one network module, fan module, and one SSD.
Four-post EIA-310-D mounting rails are included. Two-post fixed mounting brackets are optional. Rack planning should account for chassis depth, cabling, service access, and the selected mounting arrangement. The acoustic ratings should be included in site suitability reviews.
FPR-3120 NEBS Operating Conditions
FPR-3120 is designed to be NEBS ready; NEBS certification availability is pending.
| Condition | FPR-3120 limit |
|---|---|
| Operating altitude | 0 to 13,000 ft |
| Long-term temperature, up to 6,000 ft | 0 to 45 degrees C |
| Long-term temperature, 6,000 to 13,000 ft | 0 to 35 degrees C |
| Short-term temperature, up to 6,000 ft | -5 to 55 degrees C |
These conditions apply specifically to FPR-3120. Do not extend them to other models or represent NEBS readiness as completed certification.
Electrical Design and Field-Serviceable Hardware
| Electrical parameter | AC supply | DC supply |
|---|---|---|
| Input voltage | 100 to 240V AC | -48V to -60V DC |
| Maximum input current | Less than 6A at 100V | Less than 12.5A at -48V |
| Maximum output power | 400W | 400W |
| Input frequency | 50 to 60 Hz | Not specified |
| Efficiency at 50% load | Greater than 89% | Greater than 88% |
| Dual-supply redundancy | 1+1 | 1+1 |
Dual supplies are hot-swappable. The 3105, 3110, and 3120 require the optional second AC supply when redundant AC power is required. The 3130 and 3140 include dual AC supplies. Single or dual DC configurations are optional across the series.
Each appliance has two hot-swappable fan modules containing two fans each. Fans operate in a 3+1 redundant configuration: the system continues functioning with three operational fans, and the remaining fans run at full speed.
Facilities rule: A 400W supply rating is not a stated appliance power-consumption figure or PoE budget. Typical consumption, heat dissipation, and PoE capability or budget are not specified. Do not derive cooling requirements by treating redundant supply ratings as measured consumption.
Regulatory, Safety, and EMC Requirements
Regulatory compliance includes CE markings under directives 2004/108/EC and 2006/108/EC.
Safety standards include UL 62368-1, CAN/CSA-C22.2 No. 62368-1, EN 62368-1, IEC 62368-1, IEC 60950-1, AS/NZS 62368-1, and GB4943.
EMC emissions listings include FCC 47CFR15 Class A, AS/NZS CISPR 32 Class A, EN55032/CISPR 32 Class A, ICES-003 Class A, VCCI Class A, KS C 9832 Class A, and CNS-13438 Class A. Power-line requirements include EN61000-3-2 and EN61000-3-3.
Immunity listings cover IEC/EN61000-4-2, -4-3, -4-4, -4-5, -4-6, and -4-11, plus KS C 9835. ETSI/EN listings include EN 300 386, EN55032/CISPR 35, EN55024/CISPR 24, EN55035/CISPR 35, and EN61000-6-1.
Procurement compliance reviews should distinguish these regulatory listings from the separate, pending NEBS certification status.
Warranty, Service, and Commercial Planning
Warranty duration, hardware replacement turnaround, return procedures, technical support coverage, software-update entitlement, and service-contract SKUs are not specified. MTBF is also unspecified; component redundancy must not be presented as a quantitative reliability guarantee.
The service specification should explicitly establish:
- Hardware warranty term and covered components.
- Support hours and escalation arrangements.
- Replacement delivery targets and geographic coverage.
- Software maintenance and security-update entitlements.
- Responsibility for replacing supplies, fans, and storage.
- Spare-parts quantities and service-contract identifiers.
Hot-swappable power supplies and fan modules support hardware maintenance, but do not define contractual replacement times.
Cisco Capital offers payment solutions in more than 100 countries for hardware, software, services, and complementary third-party equipment. Financing should be evaluated separately from support coverage and security subscriptions.
Presales Acceptance Checklist
Before finalizing a configuration:
- Select ASA or FTD and retain the corresponding benchmark conditions.
- Validate inspection throughput, TLS demand, sessions, connection rate, VPN bandwidth, and peer count.
- Confirm fixed ports, expansion modules, and required interface speeds.
- Exclude the 3105 if clustering is mandatory.
- Size for the required failure scenario.
- Specify redundant supplies and appropriate rack hardware.
- Check temperature, altitude, humidity, acoustics, and compliance requirements.
- Complete orderable SKU, licensing, warranty, and service details before commercial approval.