Cisco Secure Firewall ASA Virtual is a virtualized firewall platform for private data centers, branch environments, and public clouds. It provides stateful inspection, site-to-site VPN, remote-access VPN, and clientless VPN capabilities while maintaining policy consistency with physical Secure Firewall ASA deployments. The platform is available through bandwidth-based entitlements from 100 Mbps to 20 Gbps, with an ASAv-U option for higher-performance KVM and ESXi deployments.

Product role and deployment model

Secure Firewall ASA Virtual is designed for organizations that need firewall functionality without deploying a dedicated physical appliance. It can be instantiated as a virtual machine on VMware ESXi, KVM, Hyper-V, OpenStack, AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud Infrastructure, and government or regional cloud marketplaces identified in the platform support information.

Common deployment roles include:

  • Internet edge firewall for a virtual data center
  • VPN head-end for remote-access users
  • Site-to-site VPN termination between data centers, branches, and cloud networks
  • Firewall for branch or office relocation projects
  • Temporary capacity for seasonal application demand
  • Security control point for workloads distributed across private and public clouds
  • Consistent firewall platform alongside physical Secure Firewall ASA appliances

The platform supports routed and transparent modes on VMware ESXi. Public cloud deployments and the other listed virtualization environments use routed mode. VMware ESXi supports stateful active/standby high availability. Azure supports stateless active/standby. High availability is listed as unsupported for AWS, GCP, and OCI in the supplied platform matrix.

Security and VPN functions

The firewall provides stateful inspection and VPN services. Supported VPN functions include:

  • Site-to-site IPsec VPN
  • Remote-access VPN
  • Clientless VPN
  • Cisco AnyConnect user sessions
  • VPN peer termination
  • Routed firewall deployments
  • Transparent firewall deployments on VMware ESXi

The maximum number of VPN peers and remote-access or clientless VPN sessions depends on the selected entitlement and deployment environment. VPN throughput also varies by platform and test profile. The published VPN figures use an AES 450-byte UDP test. They should not be treated as equivalent to application throughput for mixed production traffic.

The same Smart Software Licensing entitlement can be used across supported virtual CPU and memory configurations. This permits an organization to move an entitlement between supported private-cloud and public-cloud instances, subject to the supported platform and resource limits.

Performance tiers for VMware, KVM, and OpenStack

The following figures apply to the primary virtual deployment table for VMware ESXi, KVM, and OpenStack. The ASAv-U values apply to KVM and ESXi.

License type Stateful inspection maximum Multiprotocol throughput IPsec VPN throughput Connections per second Concurrent sessions VPN peers AnyConnect or clientless sessions vCPU Memory Best For
100M ASAv5 100 Mbps 100 Mbps 100 Mbps 12,500 50,000 50 50 1 2 GB Small branch, lab, or low-bandwidth VPN edge
1G ASAv10 1 Gbps 1 Gbps 1 Gbps 40,000 100,000 250 250 1 2 GB Small to medium virtual perimeter
2G ASAv30 2 Gbps 2 Gbps 2 Gbps 160,000 500,000 750 750 4 8 GB Medium data center or cloud edge
10G ASAv50 10 Gbps 10 Gbps 6 Gbps 270,000 2,000,000 10,000 10,000 8 16 GB High-volume application and VPN edge
20G ASAv100 20 Gbps 20 Gbps 12 Gbps 600,000 4,000,000 20,000 20,000 16 32 GB Large enterprise or service-provider virtual edge
ASAv-U 90 Gbps 60 Gbps 30 Gbps 1,000,000 8,000,000 30,000 30,000 16+ 32+ GB Very high-throughput KVM or ESXi deployments

All standard tiers provide 8 GB of disk storage. VLAN support ranges from 25 on ASAv5 to 1,024 on ASAv50, ASAv100, and ASAv-U. Bridge-group capacity ranges from 12 on ASAv5 to 250 on ASAv50, ASAv100, and ASAv-U.

The published resource allocations are the allocations required to achieve the documented performance figures. Lower allocations are supported, but performance will be lower. Thin provisioning is supported.

The throughput values were measured using 1500-byte UDP traffic under ideal test conditions. Multiprotocol results represent a traffic profile consisting primarily of TCP-based protocols or applications such as HTTP, SMTP, FTP, IMAPv4, BitTorrent, and DNS. Each performance value was obtained while running only the associated test.

Public-cloud sizing

Public-cloud performance is not interchangeable between providers. The same entitlement can produce different multiprotocol, VPN, and connection-rate results depending on the instance or shape type.

AWS

License Instance type Maximum inspection Multiprotocol IPsec VPN Connections per second Sessions Best For
ASAv5 c5n.large 100 Mbps 100 Mbps 100 Mbps 12,500 50,000 Small cloud perimeter
ASAv10 c5n.large 1 Gbps 1 Gbps 1 Gbps 60,000 100,000 Low-cost 1 Gbps cloud edge
ASAv30 c5n.xlarge 2 Gbps 2 Gbps 2 Gbps 80,000 500,000 Medium cloud deployment
ASAv50 c5n.2xlarge 10 Gbps 4.5 Gbps 4.5 Gbps 120,000 2,000,000 High-throughput cloud firewall
ASAv100 c5n.4xlarge 20 Gbps 7 Gbps 8 Gbps 200,000 4,000,000 Large AWS security edge

AWS supports 50, 250, 750, 10,000, and 20,000 VPN peers and AnyConnect or clientless sessions across the same entitlement sequence.

Azure

License VM type Maximum inspection Multiprotocol IPsec VPN Connections per second Sessions Best For
ASAv5 D3_v2 100 Mbps 100 Mbps 100 Mbps 4,000 50,000 Small Azure perimeter
ASAv10 D3_v2 1 Gbps 1 Gbps 1 Gbps 4,000 100,000 Low-volume 1 Gbps deployment
ASAv30 D3_v2 2 Gbps 2 Gbps 2 Gbps 4,000 500,000 Medium Azure edge
ASAv50 D4_v2 5.5 Gbps 4.6 Gbps 4 Gbps 8,000 2,000,000 Higher-throughput Azure firewall
ASAv100 D5_v2 11 Gbps 6 Gbps 8 Gbps 14,000 4,000,000 Large Azure perimeter

Azure performance figures were measured with Accelerated Networking enabled. Azure supports the same VPN peer and remote-access session limits as AWS for each corresponding entitlement.

GCP

License Machine type Maximum inspection Multiprotocol IPsec VPN Connections per second Sessions Best For
ASAv5 c2-standard-4 100 Mbps 100 Mbps 100 Mbps 12,500 50,000 Small GCP edge
ASAv10 c2-standard-4 1 Gbps 1 Gbps 1 Gbps 48,000 100,000 Low to moderate cloud firewall
ASAv30 c2-standard-4 2 Gbps 2 Gbps 2 Gbps 48,000 500,000 Medium GCP deployment
ASAv50 c2-standard-8 7.6 Gbps 6 Gbps 5 Gbps 82,000 2,000,000 High-volume GCP edge
ASAv100 c2-standard-16 16 Gbps 10 Gbps 9.5 Gbps 160,000 4,000,000 Large GCP perimeter

GCP supports up to 20,000 VPN peers and AnyConnect or clientless sessions on ASAv100.

OCI

License Shape type Maximum inspection Multiprotocol IPsec VPN Connections per second Sessions Best For
ASAv5 VM.Standard3.4 100 Mbps 100 Mbps 100 Mbps 12,500 50,000 Small OCI perimeter
ASAv10 VM.Standard3.4 1 Gbps 1 Gbps 1 Gbps 120,000 100,000 High connection-rate 1 Gbps edge
ASAv30 VM.Standard3.4 2 Gbps 2 Gbps 2 Gbps 250,000 500,000 Medium OCI deployment
ASAv50 VM.Standard3.8 8 Gbps 8 Gbps 7.5 Gbps 450,000 2,000,000 High-volume OCI edge
ASAv100 VM.Standard3.8 8 Gbps 8 Gbps 7.5 Gbps 450,000 4,000,000 Large-session OCI deployment

OCI figures were measured with SR-IOV interfaces. The ASAv50 and ASAv100 entries have the same published throughput and connection-rate figures, but ASAv100 provides the higher session, VPN peer, and remote-access session limits.

ASAc container deployments

The extracted performance tables also define ASAc deployments on Catalyst 9300 and Catalyst 9300X App Hosting, as well as standalone ASAc deployments on Kubernetes and Docker.

Deployment License CPU and memory Maximum inspection Firewall throughput at 450 bytes IPsec VPN Connections per second Sessions Best For
Catalyst 9300 ASAc5 1 vCPU, 2 GB 100 Mbps 100 Mbps 100 Mbps 1,400 50,000 Small branch or embedded firewall
Catalyst 9300 ASAc10 2 vCPU, 2 GB 1 Gbps 500 Mbps 250 Mbps 6,000 100,000 Integrated campus security
Catalyst 9300X ASAc10 2 vCPU, 4 GB 1 Gbps 700 Mbps 450 Mbps 8,000 100,000 Higher-performance campus edge
Catalyst 9300X ASAc10 4 vCPU, 8 GB 1 Gbps 900 Mbps 600 Mbps 8,000 100,000 Maximum listed Catalyst ASAc profile
Standalone Kubernetes or Docker ASAc5 1 vCPU, 2 GB 100 Mbps 100 Mbps 100 Mbps 1,400 50,000 Small containerized firewall
Standalone Kubernetes or Docker ASAc10 1 vCPU, 2 GB 1 Gbps 500 Mbps 250 Mbps 6,000 100,000 Basic containerized 1 Gbps entitlement

Standalone ASAc5 supports 25 VLANs, 12 bridge groups, 50 VPN peers, and 50 AnyConnect or clientless sessions. ASAc10 supports 50 VLANs, 25 bridge groups, 250 VPN peers, and 250 AnyConnect or clientless sessions.

Performance on Catalyst App Hosting can be affected when multiple applications are running on the switch at the same time, depending on available compute resources.

Presales sizing rules

Sizing should use the most restrictive requirement, not only the nominal firewall throughput.

  1. Select the deployment platform first. AWS, Azure, GCP, OCI, ESXi, KVM, and Catalyst App Hosting have different performance profiles.
  2. Compare both maximum inspection and multiprotocol throughput. Application traffic should be sized against the multiprotocol figure when traffic is primarily TCP-based.
  3. Size VPN capacity independently from firewall throughput. VPN throughput depends on device configuration and traffic patterns.
  4. Check connections per second for environments with high churn, short-lived sessions, web transactions, or scanning activity.
  5. Check concurrent sessions for large application estates, NAT-heavy environments, and shared cloud edges.
  6. Check VPN peer count for hub-and-spoke designs and remote-access session count for workforce access.
  7. Allocate the documented vCPU and memory values when the target is the published performance level.
  8. On public clouds, select the instance or shape type shown for the required entitlement rather than assuming a generic instance with similar memory is equivalent.
  9. For Azure, enable Accelerated Networking where the performance figures require it.
  10. For OCI, use SR-IOV interfaces for the published performance profile.
  11. Treat ASAv-U as a KVM or ESXi option only within the scope identified in the performance table.
  12. Include growth capacity for application expansion, VPN onboarding, and connection-rate increases rather than sizing only for average traffic.

The platform supports a maximum of 16 vCPUs and 128 GB of memory for the Secure Firewall ASA Virtual VM configuration. Public-cloud instance support lists include AWS instances from 2 to 16 vCPUs, Azure instances from 4 to 16 vCPUs, GCP machine profiles up to 16 OCPUs and 128 GB, and OCI shapes with 4 or 8 vCPUs and 60 or 120 GB.

Smart Software Licensing

Secure Firewall ASA Virtual uses Smart Software Licensing exclusively. Older licensing forms are not supported.

Smart Software Licensing provides:

  • Simplified purchase and activation
  • License pooling across the organization
  • Centralized entitlement tracking and reporting
  • Automatic activation when a virtual appliance is provisioned
  • A single token for configuration and activation
  • Return of an entitlement to the license pool when an appliance is decommissioned or deinstantiated in Smart Software Manager

The entitlement is associated with the organization rather than permanently tied to one supported VM footprint. This supports relocation between private-cloud and public-cloud environments, subject to platform compatibility and resource limits.

Ordering matrix

The base selection is followed by the required license type in Cisco Commerce Workspace.

Part number License type Entitlement Best For
L-ASAV5S-K9= Perpetual selection 100 Mbps ASAv5 Small virtual firewall or branch
L-ASA-V-5S-K9= Subscription 100 Mbps ASAv5 Operational expense licensing for small deployment
L-ASAV10S-K9= Perpetual selection 1 Gbps ASAv10 Small or medium virtual perimeter
L-ASA-V-10S-K9= Subscription 1 Gbps ASAv10 Flexible 1 Gbps cloud or data center deployment
L-ASAV30S-K9= Perpetual selection 2 Gbps ASAv30 Medium firewall and VPN edge
L-ASA-V-30S-K9= Subscription 2 Gbps ASAv30 Medium cloud or data center deployment
L-ASAV50S-K9= Perpetual selection 10 Gbps ASAv50 High-throughput enterprise edge
L-ASA-V-50S-K9= Subscription 10 Gbps ASAv50 High-throughput cloud or data center edge
L-ASA-V-100S-K9= Subscription 20 Gbps ASAv100 Large-scale virtual firewall deployment

There is no perpetual license option listed for ASAv100.

Environmental and physical considerations

Secure Firewall ASA Virtual is software deployed on customer-selected compute infrastructure rather than a fixed physical appliance. Consequently, the extracted product information does not specify appliance MTBF, chassis dimensions, rack dimensions, weight, fan configuration, acoustic noise, power draw, operating temperature, storage temperature, humidity range, or altitude limits.

Those characteristics must be evaluated against the selected host server, hypervisor, cloud instance, Catalyst switch, or container platform. The relevant infrastructure owner is responsible for host environmental conditions, physical redundancy, cooling, power, and hardware maintenance.

The supplied data specifies virtual resource requirements instead:

  • Standard ASAv disk storage: 8 GB
  • ASAv5 and ASAv10: 1 vCPU and 2 GB memory
  • ASAv30: 4 vCPUs and 8 GB memory
  • ASAv50: 8 vCPUs and 16 GB memory
  • ASAv100: 16 vCPUs and 32 GB memory
  • ASAv-U: 16 or more vCPUs and 32 GB or more memory
  • Maximum supported ASAv VM configuration: 16 vCPUs and 128 GB RAM

Warranty and service considerations

The supplied product information does not define warranty duration, hardware replacement coverage, software support duration, response targets, service-level commitments, technical support entitlement, or renewal terms for the virtual appliance.

The commercial information identifies Smart Software Licensing as the licensing and entitlement mechanism. It also identifies Cisco Capital as a financing option for hardware, software, services, and complementary third-party equipment. Financing availability and payment terms are not specified in the technical data.

For a complete proposal, the bill of materials should separately identify the required ASAv entitlement, subscription or perpetual selection, support services, cloud marketplace charges, host infrastructure, and any VPN client or associated software requirements.