Secure Firewall 3100 Series Datasheet: Up to 45 Gbps IPS

Platform Scope and Deployment Architecture

The Cisco Secure Firewall 3100 Series comprises five 1RU security appliances: 3105, 3110, 3120, 3130, and 3140. Deployment use cases include the Internet edge, data center, and private cloud. Each model can run either ASA or Firewall Threat Defense (FTD) software and supports deployment in firewall or dedicated IPS mode.

The architecture combines a modern CPU design with purpose-built hardware for firewall processing, cryptography, and threat inspection. Software selection determines the relevant performance benchmarks, management tools, and security capabilities; ASA throughput must not be substituted for FTD inspection capacity.

For inline sets and passive interfaces, the series supports Q-in-Q encapsulation with up to two 802.1Q headers per packet. Trust Anchor Technologies provide supply chain and software image assurance.

Model, Interface, and SKU Matrix

All five models combine fixed integrated interfaces with optional network-module expansion. No separate compact appliance models are identified. Complete orderable appliance, module, power-supply, and accessory SKU strings are not specified; FPR-3120 is explicitly identified for the NEBS-related platform description.

Appliance Matrix

All models include eight 10M/100M/1GBASE-T RJ-45 Ethernet interfaces.

Model designation Form factor Additional fixed Ethernet interfaces Optional network module Maximum Ethernet ports Standard AC configuration
3105 1RU 8 x 1/10G SFP interfaces 8 x 1/10G Up to 24 Single 400W
3110 1RU 8 x 1/10G SFP interfaces 8 x 1/10G Up to 24 Single 400W
3120; also identified as FPR-3120 1RU 8 x 1/10G SFP interfaces 8 x 1/10G Up to 24 Single 400W
3130 1RU 8 x 1/10/25G SFP interfaces 8 x 1/10/25G or 4 x 40G Up to 24 Dual 400W
3140 1RU 8 x 1/10/25G SFP interfaces 8 x 1/10/25G or 4 x 40G Up to 24 Dual 400W

The 24-port maximum depends on module selection. A four-port 40G module must not be treated as an eight-port expansion option.

Modular Components and Accessories

Component or option Applicable models Configuration details Orderable SKU
8-port 1/10G network module 3105, 3110, 3120 Ethernet expansion Not specified
8-port 1/10/25G network module 3130, 3140 Ethernet expansion Not specified
4-port 40G network module 3130, 3140 Ethernet expansion Not specified
400W AC supply All Optional dual AC on 3105-3120; dual AC standard on 3130-3140 Not specified
400W DC supply All Optional single or dual DC Not specified
Fan modules All Two hot-swappable modules, two fans each Not specified
Storage All One 900 GB drive and one spare slot Not specified
Four-post mounting rails All Included; EIA-310-D rack Not specified
Two-post fixed mounting brackets All Optional Not specified

Presales rule: Select the chassis for both processing capacity and interface requirements. The 3130 and 3140 provide integrated 25G connectivity and optional 40G modules; the 3105, 3110, and 3120 have integrated optical interface speeds up to 10G.

FTD Performance and Capacity

Throughput values below are in Gbps. FW means firewall; AVC means Application Visibility and Control.

FTD metric 3105 3110 3120 3130 3140
FW + AVC, 1024B 10.0 17.0 21.0 38.0 45.0
FW + AVC + IPS, 1024B 10.0 17.0 21.0 38.0 45.0
NGIPS, 1024B 10.0 17.0 21.0 38.0 45.0
Maximum concurrent sessions with AVC 1.5 million 2 million 4 million 6 million 10 million
Maximum new connections/second with AVC 90,000 130,000 170,000 240,000 300,000
TLS benchmark 3.2 4.8 6.7 9.1 11.5
IPsec VPN, 1024B TCP with Fastpath 5.5 8.0 10.0 17.8 22.4
Projected IPsec with VPN offload, FTD 7.2 N/A 11.0 13.5 33.0 39.4
Maximum VPN peers 2,000 3,000 7,000 15,000 20,000

The TLS benchmark uses 50% TLS 1.2 traffic with AES256-SHA and RSA 2048B keys. It is not a universal throughput guarantee for arbitrary encrypted traffic.

FW + AVC and FW + AVC + IPS have identical listed throughput values. This does not establish that every additional security function has no processing cost. Performance varies with enabled features, protocol mix, packet sizes, and software release.

FTD Sizing Rules

  • Size inspection separately from basic forwarding. Use FW + AVC + IPS capacity when those functions are required.
  • Evaluate TLS as an independent constraint. A firewall selected only for aggregate inspected throughput can be undersized for its encrypted workload.
  • Check session count and connection establishment independently. Long-lived sessions and short-lived transaction bursts stress different capacity limits.
  • Retain the projected designation for VPN offload. Do not present the FTD 7.2 projections as unconditional measured results.
  • Check VPN peers as well as bandwidth. Tunnel population can determine model selection before throughput does.
  • Allow project-specific headroom. No fixed sizing margin or performance derating percentage is specified.

ASA Performance and Capacity

ASA stateful inspection throughput uses 1500B UDP traffic under ideal test conditions. The multiprotocol profile primarily comprises TCP-based protocols and applications, including HTTP, SMTP, FTP, IMAPv4, BitTorrent, and DNS.

ASA metric 3105 3110 3120 3130 3140
Stateful firewall throughput, Gbps 10.0 18.0 22.0 42.0 49.0
Multiprotocol firewall throughput, Gbps 9.0 15.0 17.0 39.0 43.0
Concurrent firewall connections 1.5 million 2 million 4 million 6 million 10 million
New connections/second 150,000 300,000 500,000 875,000 1,100,000
IPsec VPN, 450B UDP L2L, Gbps 5.5 8.0 10.0 14.0 17.0
Projected IPsec with VPN offload, ASA 9.18, Gbps 7.0 12.0 15.4 28.0 33.0
Maximum VPN peers 2,000 3,000 7,000 15,000 20,000
Security contexts, included/maximum 2/100 2/100 2/100 2/100 2/100

ASA supports VPN load balancing. Every model includes two security contexts and supports a maximum of 100; the maximum must not be represented as the included entitlement.

Presales rule: Use the multiprotocol benchmark when discussing mixed application traffic, while retaining its test-profile qualification. ASA and FTD VPN results use different packet sizes and traffic types and are not directly interchangeable.

Security Functions and Management

FTD Capabilities

AVC is standard and supports more than 4,000 applications, together with geolocations, users, and websites. OpenAppID support for custom, open-source application detectors is also standard.

Cisco Security Intelligence is standard and provides IP, URL, and DNS threat intelligence. Additional available capabilities include:

  • Cisco Secure IPS: Passive endpoint and infrastructure detection for threat correlation and Indicators of Compromise intelligence.
  • Cisco Malware Defense: Detection, blocking, tracking, analysis, and containment of targeted and persistent malware, including activity during and after attacks.
  • Cisco Secure Endpoint correlation: Optional integrated threat correlation.
  • Cisco Secure Malware Analytics: Available.
  • URL filtering: More than 80 categories and more than 280 million categorized URLs.

Automated threat feeds and IPS signature updates use Collective Security Intelligence from Cisco Talos. An open API supports third-party integration, while Snort and OpenAppID community resources support additional threat and application detection requirements.

Local on-device management is available on every model. Centralized configuration, logging, monitoring, and reporting use Firewall Management Center or cloud-based Cisco Defense Orchestrator.

ASA Management

ASA centralized configuration, logging, monitoring, and reporting use Cisco Security Manager or Cisco Defense Orchestrator. Adaptive Security Device Manager provides web-based local management for small-scale deployments.

Commercial rule: Distinguish features identified as standard from features identified as available or optional. Subscription identifiers, term lengths, and feature-specific license prices are not specified.

High Availability and Scaling

The series lists active/active and active/standby high availability. Clustering supports up to eight chassis on the 3110, 3120, 3130, and 3140. The 3105 does not support clustering.

Availability planning should separate appliance failure, power-supply failure, and fan failure. These are addressed by different mechanisms and should appear separately in the engineering design.

For active/standby deployments, size the surviving appliance for the required failover workload rather than adding both appliances’ throughput. For clustered deployments, do not assume an eight-chassis cluster provides exactly eight times single-appliance capacity; no cluster scaling efficiency is specified.

The 3105 remains an option for non-clustered deployments but should be excluded when chassis clustering is a mandatory requirement.

Physical, Environmental, and Reliability Specifications

Common Chassis Specifications

Parameter Specification
Rack height 1RU
Dimensions, H x W x D 1.75 x 17 x 20 in.
Metric dimensions, H x W x D 4.4 x 43.3 x 50.8 cm
Dedicated network management 1 x 1/10G SFP
Serial console 1 x RJ-45
USB 1 x USB 3.0 Type-A, 900mA
Storage 1 x 900 GB; 1 spare slot
Operating temperature 32 to 104 degrees F; 0 to 40 degrees C
Nonoperating temperature -4 to 149 degrees F; -20 to 65 degrees C
Operating humidity 10% to 85%, noncondensing
Nonoperating humidity 5% to 95%, noncondensing
Maximum standard operating altitude 10,000 ft
Maximum nonoperating altitude 40,000 ft
Acoustic noise at 25 degrees C 65 dBA
Maximum acoustic noise 74 dBA
MTBF Not specified

The 3105, 3110, and 3120 weigh 23 lb, or 10.5 kg, in the listed configuration with one power supply, one network module, fan module, and one SSD. The 3130 and 3140 weigh 25 lb, or 11.4 kg, with two power supplies, one network module, fan module, and one SSD.

Four-post EIA-310-D mounting rails are included. Two-post fixed mounting brackets are optional. Rack planning should account for chassis depth, cabling, service access, and the selected mounting arrangement. The acoustic ratings should be included in site suitability reviews.

FPR-3120 NEBS Operating Conditions

FPR-3120 is designed to be NEBS ready; NEBS certification availability is pending.

Condition FPR-3120 limit
Operating altitude 0 to 13,000 ft
Long-term temperature, up to 6,000 ft 0 to 45 degrees C
Long-term temperature, 6,000 to 13,000 ft 0 to 35 degrees C
Short-term temperature, up to 6,000 ft -5 to 55 degrees C

These conditions apply specifically to FPR-3120. Do not extend them to other models or represent NEBS readiness as completed certification.

Electrical Design and Field-Serviceable Hardware

Electrical parameter AC supply DC supply
Input voltage 100 to 240V AC -48V to -60V DC
Maximum input current Less than 6A at 100V Less than 12.5A at -48V
Maximum output power 400W 400W
Input frequency 50 to 60 Hz Not specified
Efficiency at 50% load Greater than 89% Greater than 88%
Dual-supply redundancy 1+1 1+1

Dual supplies are hot-swappable. The 3105, 3110, and 3120 require the optional second AC supply when redundant AC power is required. The 3130 and 3140 include dual AC supplies. Single or dual DC configurations are optional across the series.

Each appliance has two hot-swappable fan modules containing two fans each. Fans operate in a 3+1 redundant configuration: the system continues functioning with three operational fans, and the remaining fans run at full speed.

Facilities rule: A 400W supply rating is not a stated appliance power-consumption figure or PoE budget. Typical consumption, heat dissipation, and PoE capability or budget are not specified. Do not derive cooling requirements by treating redundant supply ratings as measured consumption.

Regulatory, Safety, and EMC Requirements

Regulatory compliance includes CE markings under directives 2004/108/EC and 2006/108/EC.

Safety standards include UL 62368-1, CAN/CSA-C22.2 No. 62368-1, EN 62368-1, IEC 62368-1, IEC 60950-1, AS/NZS 62368-1, and GB4943.

EMC emissions listings include FCC 47CFR15 Class A, AS/NZS CISPR 32 Class A, EN55032/CISPR 32 Class A, ICES-003 Class A, VCCI Class A, KS C 9832 Class A, and CNS-13438 Class A. Power-line requirements include EN61000-3-2 and EN61000-3-3.

Immunity listings cover IEC/EN61000-4-2, -4-3, -4-4, -4-5, -4-6, and -4-11, plus KS C 9835. ETSI/EN listings include EN 300 386, EN55032/CISPR 35, EN55024/CISPR 24, EN55035/CISPR 35, and EN61000-6-1.

Procurement compliance reviews should distinguish these regulatory listings from the separate, pending NEBS certification status.

Warranty, Service, and Commercial Planning

Warranty duration, hardware replacement turnaround, return procedures, technical support coverage, software-update entitlement, and service-contract SKUs are not specified. MTBF is also unspecified; component redundancy must not be presented as a quantitative reliability guarantee.

The service specification should explicitly establish:

  • Hardware warranty term and covered components.
  • Support hours and escalation arrangements.
  • Replacement delivery targets and geographic coverage.
  • Software maintenance and security-update entitlements.
  • Responsibility for replacing supplies, fans, and storage.
  • Spare-parts quantities and service-contract identifiers.

Hot-swappable power supplies and fan modules support hardware maintenance, but do not define contractual replacement times.

Cisco Capital offers payment solutions in more than 100 countries for hardware, software, services, and complementary third-party equipment. Financing should be evaluated separately from support coverage and security subscriptions.

Presales Acceptance Checklist

Before finalizing a configuration:

  1. Select ASA or FTD and retain the corresponding benchmark conditions.
  2. Validate inspection throughput, TLS demand, sessions, connection rate, VPN bandwidth, and peer count.
  3. Confirm fixed ports, expansion modules, and required interface speeds.
  4. Exclude the 3105 if clustering is mandatory.
  5. Size for the required failure scenario.
  6. Specify redundant supplies and appropriate rack hardware.
  7. Check temperature, altitude, humidity, acoustics, and compliance requirements.
  8. Complete orderable SKU, licensing, warranty, and service details before commercial approval.