Cisco Secure Firewall ASA Virtual is a virtualized firewall platform for private data centers, branch environments, and public clouds. It provides stateful inspection, site-to-site VPN, remote-access VPN, and clientless VPN capabilities while maintaining policy consistency with physical Secure Firewall ASA deployments. The platform is available through bandwidth-based entitlements from 100 Mbps to 20 Gbps, with an ASAv-U option for higher-performance KVM and ESXi deployments.
Product role and deployment model
Secure Firewall ASA Virtual is designed for organizations that need firewall functionality without deploying a dedicated physical appliance. It can be instantiated as a virtual machine on VMware ESXi, KVM, Hyper-V, OpenStack, AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud Infrastructure, and government or regional cloud marketplaces identified in the platform support information.
Common deployment roles include:
- Internet edge firewall for a virtual data center
- VPN head-end for remote-access users
- Site-to-site VPN termination between data centers, branches, and cloud networks
- Firewall for branch or office relocation projects
- Temporary capacity for seasonal application demand
- Security control point for workloads distributed across private and public clouds
- Consistent firewall platform alongside physical Secure Firewall ASA appliances
The platform supports routed and transparent modes on VMware ESXi. Public cloud deployments and the other listed virtualization environments use routed mode. VMware ESXi supports stateful active/standby high availability. Azure supports stateless active/standby. High availability is listed as unsupported for AWS, GCP, and OCI in the supplied platform matrix.
Security and VPN functions
The firewall provides stateful inspection and VPN services. Supported VPN functions include:
- Site-to-site IPsec VPN
- Remote-access VPN
- Clientless VPN
- Cisco AnyConnect user sessions
- VPN peer termination
- Routed firewall deployments
- Transparent firewall deployments on VMware ESXi
The maximum number of VPN peers and remote-access or clientless VPN sessions depends on the selected entitlement and deployment environment. VPN throughput also varies by platform and test profile. The published VPN figures use an AES 450-byte UDP test. They should not be treated as equivalent to application throughput for mixed production traffic.
The same Smart Software Licensing entitlement can be used across supported virtual CPU and memory configurations. This permits an organization to move an entitlement between supported private-cloud and public-cloud instances, subject to the supported platform and resource limits.
Performance tiers for VMware, KVM, and OpenStack
The following figures apply to the primary virtual deployment table for VMware ESXi, KVM, and OpenStack. The ASAv-U values apply to KVM and ESXi.
| License type | Stateful inspection maximum | Multiprotocol throughput | IPsec VPN throughput | Connections per second | Concurrent sessions | VPN peers | AnyConnect or clientless sessions | vCPU | Memory | Best For |
|---|---|---|---|---|---|---|---|---|---|---|
| 100M ASAv5 | 100 Mbps | 100 Mbps | 100 Mbps | 12,500 | 50,000 | 50 | 50 | 1 | 2 GB | Small branch, lab, or low-bandwidth VPN edge |
| 1G ASAv10 | 1 Gbps | 1 Gbps | 1 Gbps | 40,000 | 100,000 | 250 | 250 | 1 | 2 GB | Small to medium virtual perimeter |
| 2G ASAv30 | 2 Gbps | 2 Gbps | 2 Gbps | 160,000 | 500,000 | 750 | 750 | 4 | 8 GB | Medium data center or cloud edge |
| 10G ASAv50 | 10 Gbps | 10 Gbps | 6 Gbps | 270,000 | 2,000,000 | 10,000 | 10,000 | 8 | 16 GB | High-volume application and VPN edge |
| 20G ASAv100 | 20 Gbps | 20 Gbps | 12 Gbps | 600,000 | 4,000,000 | 20,000 | 20,000 | 16 | 32 GB | Large enterprise or service-provider virtual edge |
| ASAv-U | 90 Gbps | 60 Gbps | 30 Gbps | 1,000,000 | 8,000,000 | 30,000 | 30,000 | 16+ | 32+ GB | Very high-throughput KVM or ESXi deployments |
All standard tiers provide 8 GB of disk storage. VLAN support ranges from 25 on ASAv5 to 1,024 on ASAv50, ASAv100, and ASAv-U. Bridge-group capacity ranges from 12 on ASAv5 to 250 on ASAv50, ASAv100, and ASAv-U.
The published resource allocations are the allocations required to achieve the documented performance figures. Lower allocations are supported, but performance will be lower. Thin provisioning is supported.
The throughput values were measured using 1500-byte UDP traffic under ideal test conditions. Multiprotocol results represent a traffic profile consisting primarily of TCP-based protocols or applications such as HTTP, SMTP, FTP, IMAPv4, BitTorrent, and DNS. Each performance value was obtained while running only the associated test.
Public-cloud sizing
Public-cloud performance is not interchangeable between providers. The same entitlement can produce different multiprotocol, VPN, and connection-rate results depending on the instance or shape type.
AWS
| License | Instance type | Maximum inspection | Multiprotocol | IPsec VPN | Connections per second | Sessions | Best For |
|---|---|---|---|---|---|---|---|
| ASAv5 | c5n.large | 100 Mbps | 100 Mbps | 100 Mbps | 12,500 | 50,000 | Small cloud perimeter |
| ASAv10 | c5n.large | 1 Gbps | 1 Gbps | 1 Gbps | 60,000 | 100,000 | Low-cost 1 Gbps cloud edge |
| ASAv30 | c5n.xlarge | 2 Gbps | 2 Gbps | 2 Gbps | 80,000 | 500,000 | Medium cloud deployment |
| ASAv50 | c5n.2xlarge | 10 Gbps | 4.5 Gbps | 4.5 Gbps | 120,000 | 2,000,000 | High-throughput cloud firewall |
| ASAv100 | c5n.4xlarge | 20 Gbps | 7 Gbps | 8 Gbps | 200,000 | 4,000,000 | Large AWS security edge |
AWS supports 50, 250, 750, 10,000, and 20,000 VPN peers and AnyConnect or clientless sessions across the same entitlement sequence.
Azure
| License | VM type | Maximum inspection | Multiprotocol | IPsec VPN | Connections per second | Sessions | Best For |
|---|---|---|---|---|---|---|---|
| ASAv5 | D3_v2 | 100 Mbps | 100 Mbps | 100 Mbps | 4,000 | 50,000 | Small Azure perimeter |
| ASAv10 | D3_v2 | 1 Gbps | 1 Gbps | 1 Gbps | 4,000 | 100,000 | Low-volume 1 Gbps deployment |
| ASAv30 | D3_v2 | 2 Gbps | 2 Gbps | 2 Gbps | 4,000 | 500,000 | Medium Azure edge |
| ASAv50 | D4_v2 | 5.5 Gbps | 4.6 Gbps | 4 Gbps | 8,000 | 2,000,000 | Higher-throughput Azure firewall |
| ASAv100 | D5_v2 | 11 Gbps | 6 Gbps | 8 Gbps | 14,000 | 4,000,000 | Large Azure perimeter |
Azure performance figures were measured with Accelerated Networking enabled. Azure supports the same VPN peer and remote-access session limits as AWS for each corresponding entitlement.
GCP
| License | Machine type | Maximum inspection | Multiprotocol | IPsec VPN | Connections per second | Sessions | Best For |
|---|---|---|---|---|---|---|---|
| ASAv5 | c2-standard-4 | 100 Mbps | 100 Mbps | 100 Mbps | 12,500 | 50,000 | Small GCP edge |
| ASAv10 | c2-standard-4 | 1 Gbps | 1 Gbps | 1 Gbps | 48,000 | 100,000 | Low to moderate cloud firewall |
| ASAv30 | c2-standard-4 | 2 Gbps | 2 Gbps | 2 Gbps | 48,000 | 500,000 | Medium GCP deployment |
| ASAv50 | c2-standard-8 | 7.6 Gbps | 6 Gbps | 5 Gbps | 82,000 | 2,000,000 | High-volume GCP edge |
| ASAv100 | c2-standard-16 | 16 Gbps | 10 Gbps | 9.5 Gbps | 160,000 | 4,000,000 | Large GCP perimeter |
GCP supports up to 20,000 VPN peers and AnyConnect or clientless sessions on ASAv100.
OCI
| License | Shape type | Maximum inspection | Multiprotocol | IPsec VPN | Connections per second | Sessions | Best For |
|---|---|---|---|---|---|---|---|
| ASAv5 | VM.Standard3.4 | 100 Mbps | 100 Mbps | 100 Mbps | 12,500 | 50,000 | Small OCI perimeter |
| ASAv10 | VM.Standard3.4 | 1 Gbps | 1 Gbps | 1 Gbps | 120,000 | 100,000 | High connection-rate 1 Gbps edge |
| ASAv30 | VM.Standard3.4 | 2 Gbps | 2 Gbps | 2 Gbps | 250,000 | 500,000 | Medium OCI deployment |
| ASAv50 | VM.Standard3.8 | 8 Gbps | 8 Gbps | 7.5 Gbps | 450,000 | 2,000,000 | High-volume OCI edge |
| ASAv100 | VM.Standard3.8 | 8 Gbps | 8 Gbps | 7.5 Gbps | 450,000 | 4,000,000 | Large-session OCI deployment |
OCI figures were measured with SR-IOV interfaces. The ASAv50 and ASAv100 entries have the same published throughput and connection-rate figures, but ASAv100 provides the higher session, VPN peer, and remote-access session limits.
ASAc container deployments
The extracted performance tables also define ASAc deployments on Catalyst 9300 and Catalyst 9300X App Hosting, as well as standalone ASAc deployments on Kubernetes and Docker.
| Deployment | License | CPU and memory | Maximum inspection | Firewall throughput at 450 bytes | IPsec VPN | Connections per second | Sessions | Best For |
|---|---|---|---|---|---|---|---|---|
| Catalyst 9300 | ASAc5 | 1 vCPU, 2 GB | 100 Mbps | 100 Mbps | 100 Mbps | 1,400 | 50,000 | Small branch or embedded firewall |
| Catalyst 9300 | ASAc10 | 2 vCPU, 2 GB | 1 Gbps | 500 Mbps | 250 Mbps | 6,000 | 100,000 | Integrated campus security |
| Catalyst 9300X | ASAc10 | 2 vCPU, 4 GB | 1 Gbps | 700 Mbps | 450 Mbps | 8,000 | 100,000 | Higher-performance campus edge |
| Catalyst 9300X | ASAc10 | 4 vCPU, 8 GB | 1 Gbps | 900 Mbps | 600 Mbps | 8,000 | 100,000 | Maximum listed Catalyst ASAc profile |
| Standalone Kubernetes or Docker | ASAc5 | 1 vCPU, 2 GB | 100 Mbps | 100 Mbps | 100 Mbps | 1,400 | 50,000 | Small containerized firewall |
| Standalone Kubernetes or Docker | ASAc10 | 1 vCPU, 2 GB | 1 Gbps | 500 Mbps | 250 Mbps | 6,000 | 100,000 | Basic containerized 1 Gbps entitlement |
Standalone ASAc5 supports 25 VLANs, 12 bridge groups, 50 VPN peers, and 50 AnyConnect or clientless sessions. ASAc10 supports 50 VLANs, 25 bridge groups, 250 VPN peers, and 250 AnyConnect or clientless sessions.
Performance on Catalyst App Hosting can be affected when multiple applications are running on the switch at the same time, depending on available compute resources.
Presales sizing rules
Sizing should use the most restrictive requirement, not only the nominal firewall throughput.
- Select the deployment platform first. AWS, Azure, GCP, OCI, ESXi, KVM, and Catalyst App Hosting have different performance profiles.
- Compare both maximum inspection and multiprotocol throughput. Application traffic should be sized against the multiprotocol figure when traffic is primarily TCP-based.
- Size VPN capacity independently from firewall throughput. VPN throughput depends on device configuration and traffic patterns.
- Check connections per second for environments with high churn, short-lived sessions, web transactions, or scanning activity.
- Check concurrent sessions for large application estates, NAT-heavy environments, and shared cloud edges.
- Check VPN peer count for hub-and-spoke designs and remote-access session count for workforce access.
- Allocate the documented vCPU and memory values when the target is the published performance level.
- On public clouds, select the instance or shape type shown for the required entitlement rather than assuming a generic instance with similar memory is equivalent.
- For Azure, enable Accelerated Networking where the performance figures require it.
- For OCI, use SR-IOV interfaces for the published performance profile.
- Treat ASAv-U as a KVM or ESXi option only within the scope identified in the performance table.
- Include growth capacity for application expansion, VPN onboarding, and connection-rate increases rather than sizing only for average traffic.
The platform supports a maximum of 16 vCPUs and 128 GB of memory for the Secure Firewall ASA Virtual VM configuration. Public-cloud instance support lists include AWS instances from 2 to 16 vCPUs, Azure instances from 4 to 16 vCPUs, GCP machine profiles up to 16 OCPUs and 128 GB, and OCI shapes with 4 or 8 vCPUs and 60 or 120 GB.
Smart Software Licensing
Secure Firewall ASA Virtual uses Smart Software Licensing exclusively. Older licensing forms are not supported.
Smart Software Licensing provides:
- Simplified purchase and activation
- License pooling across the organization
- Centralized entitlement tracking and reporting
- Automatic activation when a virtual appliance is provisioned
- A single token for configuration and activation
- Return of an entitlement to the license pool when an appliance is decommissioned or deinstantiated in Smart Software Manager
The entitlement is associated with the organization rather than permanently tied to one supported VM footprint. This supports relocation between private-cloud and public-cloud environments, subject to platform compatibility and resource limits.
Ordering matrix
The base selection is followed by the required license type in Cisco Commerce Workspace.
| Part number | License type | Entitlement | Best For |
|---|---|---|---|
| L-ASAV5S-K9= | Perpetual selection | 100 Mbps ASAv5 | Small virtual firewall or branch |
| L-ASA-V-5S-K9= | Subscription | 100 Mbps ASAv5 | Operational expense licensing for small deployment |
| L-ASAV10S-K9= | Perpetual selection | 1 Gbps ASAv10 | Small or medium virtual perimeter |
| L-ASA-V-10S-K9= | Subscription | 1 Gbps ASAv10 | Flexible 1 Gbps cloud or data center deployment |
| L-ASAV30S-K9= | Perpetual selection | 2 Gbps ASAv30 | Medium firewall and VPN edge |
| L-ASA-V-30S-K9= | Subscription | 2 Gbps ASAv30 | Medium cloud or data center deployment |
| L-ASAV50S-K9= | Perpetual selection | 10 Gbps ASAv50 | High-throughput enterprise edge |
| L-ASA-V-50S-K9= | Subscription | 10 Gbps ASAv50 | High-throughput cloud or data center edge |
| L-ASA-V-100S-K9= | Subscription | 20 Gbps ASAv100 | Large-scale virtual firewall deployment |
There is no perpetual license option listed for ASAv100.
Environmental and physical considerations
Secure Firewall ASA Virtual is software deployed on customer-selected compute infrastructure rather than a fixed physical appliance. Consequently, the extracted product information does not specify appliance MTBF, chassis dimensions, rack dimensions, weight, fan configuration, acoustic noise, power draw, operating temperature, storage temperature, humidity range, or altitude limits.
Those characteristics must be evaluated against the selected host server, hypervisor, cloud instance, Catalyst switch, or container platform. The relevant infrastructure owner is responsible for host environmental conditions, physical redundancy, cooling, power, and hardware maintenance.
The supplied data specifies virtual resource requirements instead:
- Standard ASAv disk storage: 8 GB
- ASAv5 and ASAv10: 1 vCPU and 2 GB memory
- ASAv30: 4 vCPUs and 8 GB memory
- ASAv50: 8 vCPUs and 16 GB memory
- ASAv100: 16 vCPUs and 32 GB memory
- ASAv-U: 16 or more vCPUs and 32 GB or more memory
- Maximum supported ASAv VM configuration: 16 vCPUs and 128 GB RAM
Warranty and service considerations
The supplied product information does not define warranty duration, hardware replacement coverage, software support duration, response targets, service-level commitments, technical support entitlement, or renewal terms for the virtual appliance.
The commercial information identifies Smart Software Licensing as the licensing and entitlement mechanism. It also identifies Cisco Capital as a financing option for hardware, software, services, and complementary third-party equipment. Financing availability and payment terms are not specified in the technical data.
For a complete proposal, the bill of materials should separately identify the required ASAv entitlement, subscription or perpetual selection, support services, cloud marketplace charges, host infrastructure, and any VPN client or associated software requirements.