Firepower 2100 Sizing, Interfaces, and Deployment Guide

The Cisco Firepower 2100 Series comprises four 1RU security appliances: FPR-2110, FPR-2120, FPR-2130, and FPR-2140. The platforms are designed for firewall, next-generation firewall, VPN, and dedicated IPS deployments. They run either Cisco Secure Firewall ASA software or Cisco Secure Firewall Threat Defense software managed through Cisco Firepower Management Center or Cisco Defense Orchestrator, depending on the selected operating model.

The family uses a dual multicore CPU architecture intended to separate and optimize firewall, cryptographic, and threat inspection processing. The published performance range extends from 2.6 Gbps of Threat Defense firewall and IPS throughput on the FPR-2110 to 10.5 Gbps of IPS throughput on the FPR-2140.

The correct model should be selected against the enabled security functions, packet sizes, protocol mix, concurrent session count, connection establishment rate, TLS inspection load, VPN population, interface speed, and availability design. The nominal firewall figures should not be treated as interchangeable with full threat inspection capacity.

SKU Matrix and Hardware Positioning

The source data identifies four appliance SKUs. All are fixed 1RU appliances with integrated Ethernet interfaces. The FPR-2130 and FPR-2140 support network module expansion; the FPR-2110 and FPR-2120 do not.

SKU Appliance type in supplied data Integrated data interfaces Network module support Maximum Ethernet interfaces Primary performance tier
FPR-2110 Fixed 1RU appliance 12 x 10M/100M/1GBASE-T RJ-45, 4 x 1G SFP None 16 Entry platform; 2.6 Gbps Threat Defense FW plus AVC
FPR-2120 Fixed 1RU appliance 12 x 10M/100M/1GBASE-T RJ-45, 4 x 1G SFP None 16 Midrange platform; 3.4 Gbps Threat Defense FW plus AVC
FPR-2130 Fixed 1RU appliance with modular expansion 12 x 10M/100M/1GBASE-T RJ-45, 4 x 10G SFP+ 10G SFP+ or 1/10G FTW options 24 Higher-throughput platform; 5.4 Gbps Threat Defense FW plus AVC
FPR-2140 Fixed 1RU appliance with modular expansion 12 x 10M/100M/1GBASE-T RJ-45, 4 x 10G SFP+ 10G SFP+ or 1/10G FTW options 24 Highest platform; 10.4 Gbps Threat Defense FW plus AVC

No separate compact appliance SKUs are listed in the supplied product data. The documented family consists of fixed rack-mount appliances, with modular network expansion available only on the FPR-2130 and FPR-2140.

The FPR-2110 and FPR-2120 are suitable where sixteen total Ethernet ports are sufficient and 1G optical interfaces meet the network design. The FPR-2130 and FPR-2140 should be considered where 10G SFP+ connectivity, fail-to-wire network modules, or a higher interface count is required.

The appliances also include one 10M/100M/1GBASE-T RJ-45 management port, one RJ-45 console port, and one USB 2.0 Type-A port rated at 500 mA. These ports are separate from the maximum data-interface counts.

Threat Defense Throughput and Session Sizing

The Threat Defense performance figures use 1024-byte traffic for the firewall, AVC, IPS, and VPN measurements unless otherwise stated.

Metric FPR-2110 FPR-2120 FPR-2130 FPR-2140
FW plus AVC 2.6 Gbps 3.4 Gbps 5.4 Gbps 10.4 Gbps
FW plus AVC plus IPS 2.6 Gbps 3.4 Gbps 5.4 Gbps 10.4 Gbps
IPS throughput 2.6 Gbps 3.5 Gbps 5.4 Gbps 10.5 Gbps
Concurrent sessions with AVC 1 million 1.5 million 2 million 3 million
New connections per second with AVC 14,000 18,000 30,000 57,000
TLS throughput 365 Mbps 475 Mbps 760 Mbps 1.4 Gbps
IPSec VPN throughput, 1024-byte TCP with Fastpath 950 Mbps 1.2 Gbps 1.9 Gbps 3.6 Gbps
Maximum VPN peers 1,500 3,500 7,500 10,000

The FPR-2110 and FPR-2120 provide the same published 2.6 Gbps and 3.4 Gbps FW plus AVC figures as their combined FW plus AVC plus IPS figures. This does not mean that every traffic profile will produce identical results. The datasheet states that performance varies with activated features, traffic protocol mix, packet size, and software releases.

For presales sizing, use the FW plus AVC plus IPS value when the design requires all three functions concurrently. Use TLS throughput separately when encrypted traffic inspection is required. TLS capacity is substantially lower than cleartext firewall throughput on every model, so an appliance selected only from the firewall figure may be undersized for encrypted traffic.

Session capacity and connection rate are separate constraints. A site with a large installed user population and relatively stable long-lived sessions may be limited by concurrent sessions. A service provider, web-facing application, or highly dynamic workload may instead be limited by new connections per second. Both values should be checked against the proposed traffic profile.

The published threat inspection figures do not provide a license-independent guarantee for a particular application mix. Sizing should account for security policies, URL filtering, malware inspection, IPS policies, TLS decryption, logging volume, and expected growth.

ASA Firewall Performance and Capabilities

ASA figures are distinct from Threat Defense figures and use different test conditions.

ASA metric FPR-2110 FPR-2120 FPR-2130 FPR-2140
Stateful inspection throughput 3 Gbps 6 Gbps 10 Gbps 20 Gbps
Stateful inspection throughput, multiprotocol 1.5 Gbps 3 Gbps 5 Gbps 10 Gbps
Concurrent firewall connections 1 million 1.5 million 2 million 3 million
New connections per second 18,000 28,000 40,000 75,000
IPSec VPN throughput, 450-byte UDP L2L test 500 Mbps 700 Mbps 1 Gbps 2 Gbps
Maximum VPN peers 1,500 3,500 7,500 10,000
Security contexts included; maximum 2; 25 2; 25 2; 30 2; 40
Firewall latency, UDP 64-byte Not specified Not specified Not specified Not specified

Stateful inspection throughput is measured with 1500-byte UDP traffic under ideal test conditions. The multiprotocol result represents a profile consisting primarily of TCP-based protocols and applications such as HTTP, SMTP, FTP, IMAPv4, BitTorrent, and DNS.

The ASA platform supports active/active and active/standby high availability. The supplied data also lists clustering scalability and VPN load balancing. The clustering row does not provide a numeric cluster limit.

For ASA presales work, use the multiprotocol value when traffic is expected to contain normal enterprise application mixes rather than large UDP flows. The gap between the ideal UDP figure and the multiprotocol figure is material, particularly on the lower models. VPN sizing should use the ASA-specific 450-byte UDP L2L measurement rather than the Threat Defense VPN figure.

Security Software and Management Paths

The Firepower 2100 platforms support two software operating approaches:

  • Cisco Secure Firewall ASA for stateful firewall deployments and ASA feature sets.
  • Cisco Secure Firewall Threat Defense for next-generation firewall and threat inspection deployments.

Threat Defense supports local management through Cisco Firepower Device Manager on all four models. Centralized configuration, logging, monitoring, and reporting are performed by Management Center, or alternatively through Cisco Defense Orchestrator in the cloud.

The listed Threat Defense security capabilities include:

  • Application Visibility and Control as a standard capability.
  • Visibility for more than 4000 applications, along with geolocations, users, and websites.
  • OpenAppID support for custom and open-source application detectors.
  • Cisco Security Intelligence using IP, URL, and DNS threat intelligence.
  • Cisco Firepower NGIPS for passive endpoint and infrastructure detection, threat correlation, and Indicators of Compromise intelligence.
  • Cisco AMP for Networks for detection, blocking, tracking, analysis, and containment of targeted and persistent malware.
  • Optional integrated threat correlation with Cisco Secure Endpoint.
  • Cisco AMP Threat Grid sandboxing.
  • URL filtering with more than 80 categories and more than 280 million categorized URLs.
  • Automated threat feed and IPS signature updates through Collective Security Intelligence from the Cisco Talos Group.
  • Open APIs for third-party integrations.
  • Snort and OpenAppID community resources for new and specific threats.
  • Cisco Trust Anchor Technologies for supply chain and software image assurance.

ASA deployments use Cisco Security Manager for centralized configuration, logging, monitoring, and reporting, or Cisco Defense Orchestrator as a cloud alternative. Adaptive Security Device Manager provides web-based local management for small-scale ASA deployments.

The management selection should be made early in the design. FDM is appropriate for local management of an individual appliance. Centralized management is more suitable where policy consistency, consolidated reporting, multi-device administration, or coordinated event handling is required.

Interface Design and Network Modules

The FPR-2110 and FPR-2120 provide twelve copper Ethernet ports supporting 10M, 100M, and 1GBASE-T, plus four 1G SFP ports. Their maximum data-interface count is sixteen.

The FPR-2130 and FPR-2140 provide the same twelve copper ports, but their four optical ports support 10G SFP+. Their network module slots support either 10G SFP+ or 1/10G FTW options, increasing the maximum interface count to twenty-four.

The supplied data states that the appliances may also be deployed as dedicated threat sensors with fail-to-wire network modules. Detailed fail-to-wire module specifications are not provided. A dedicated IPS design must therefore validate the selected module, physical bypass topology, link behavior, and operational mode before final quotation.

The interface count includes data ports and should not be confused with the separate management, console, and USB ports. Interface planning should account for inside, outside, DMZ, dedicated management, HA, monitoring, and IPS bypass connections as applicable to the deployment.

High Availability and Dedicated IPS Use

Threat Defense high availability is listed as active/standby. ASA supports both active/active and active/standby high availability on all four models.

The FPR-2130 and FPR-2140 support redundant power configurations and hot-swappable components that are not available on the FPR-2110 and FPR-2120. This makes the higher models better aligned with installations that require power or fan service continuity, subject to the selected power configuration and site procedures.

A dedicated IPS deployment changes the sizing emphasis. Throughput, interface placement, bypass behavior, fail-to-wire requirements, and sensor management must be considered independently from a routed firewall design. The platform supports dedicated threat sensor use, but the source data does not provide separate dedicated-sensor throughput figures.

Rack, Power, Storage, and Serviceability

All four models occupy 1RU and measure 1.73 x 16.90 x 19.76 inches, or 4.4 x 42.9 x 50.2 cm.

Hardware attribute FPR-2110 FPR-2120 FPR-2130 FPR-2140
Storage 1 x 100 GB, 1 spare slot for MSP 1 x 100 GB, 1 spare slot for MSP 1 x 200 GB, 1 spare slot for MSP 1 x 200 GB, 1 spare slot for MSP
AC power Single integrated 250W AC Single integrated 250W AC Single 400W AC; dual 400W AC optional Dual 400W AC
DC power Not specified Not specified Single or dual 350W DC optional Single or dual 350W DC optional
AC input voltage 100 to 240V AC 100 to 240V AC 100 to 240V AC 100 to 240V AC
AC maximum input current Less than 2.7A at 100V Less than 2.7A at 100V Less than 6A at 100V Less than 6A at 100V
AC maximum output power 250W 250W 400W 400W
AC frequency 50 to 60 Hz 50 to 60 Hz 50 to 60 Hz 50 to 60 Hz
AC efficiency Greater than 88% at 50% load Greater than 88% at 50% load Greater than 89% at 50% load Greater than 89% at 50% load
DC input voltage Not specified Not specified -48V to -60VDC -48V to -60VDC
DC maximum input current Not specified Not specified Less than 12.5A at -48V Less than 12.5A at -48V
DC maximum output power Not specified Not specified 350W 350W
DC efficiency Not specified Not specified Greater than 88% at 50% load Greater than 88% at 50% load
Power redundancy None None 1+1 AC or DC with dual supplies 1+1 AC or DC with dual supplies
Weight 16.1 lb, 7.3 kg, with two SSDs 16.1 lb, 7.3 kg, with two SSDs 19.4 lb, 8.8 kg, with one power supply, one network module, one fan module, and two SSDs 21 lb, 9.53 kg, with two power supplies, one network module, one fan module, and two SSDs

The FPR-2110 and FPR-2120 have four integrated fans, consisting of two internal and two exhaust fans. The FPR-2130 and FPR-2140 use one hot-swappable fan module containing four fans. The fan arrangement operates in a 3+1 redundant configuration; the system continues to function with three operational fans, while the remaining fans run at full speed.

Fixed mounting brackets are included for the FPR-2110 and FPR-2120 for two-post racks. Mount rails are optional for four-post EIA-310-D racks. Mount rails are included with the FPR-2130 and FPR-2140 for four-post EIA-310-D racks.

Environmental Limits and Acoustic Planning

Environmental attribute All models unless noted
Operating temperature 32 to 104 degrees F, 0 to 40 degrees C
Nonoperating temperature -4 to 149 degrees F, -20 to 65 degrees C
Operating humidity 10 to 85 percent, noncondensing
Nonoperating humidity 5 to 95 percent, noncondensing
Maximum operating altitude 10,000 feet
Maximum nonoperating altitude 40,000 feet
Idle or stated baseline noise 56 dBA at 25 degrees C
Highest system performance noise 74 dBA for FPR-2110 and FPR-2120; 77 dBA for FPR-2130 and FPR-2140

The FPR-2130 is identified as NEBS ready, with NEBS certification availability pending in the supplied data. Its NEBS operating envelope is:

  • Operating altitude from 0 to 13,000 feet, or 3962 meters.
  • Long-term operating temperature from 0 to 45 degrees C up to 6,000 feet, or 1829 meters.
  • Long-term operating temperature from 0 to 35 degrees C from 6,000 to 13,000 feet, or 1829 to 3964 meters.
  • Short-term operating temperature from -5 to 55 degrees C up to 6,000 feet, or 1829 meters.

The acoustic figures are significant for office, branch, and shared-equipment-room placement. The highest-performance figures reach 74 or 77 dBA, so rack location and room noise limits should be checked before installation. The source data does not list MTBF values. MTBF should therefore not be used as a quantified proposal assumption from this specification set.

Regulatory and EMC Compliance

The listed safety standards are:

  • UL 60950-1
  • CAN/CSA-C22.2 No. 60950-1
  • EN 60950-1
  • IEC 60950-1
  • AS/NZS 60950-1
  • GB4943

The listed EMC emissions standards include FCC Class A, AS/NZS CISPR22 Class A, CISPR22 Class A, EN55022 Class A, ICES003 Class A, VCCI Class A, EN61000-3-2, EN61000-3-3, KN22 Class A, CNS13438 Class A, EN300386, and TCVN7189.

The listed EMC immunity standards include EN55024, CISPR24, EN300386, KN24, TVCN 7317, and the EN61000-4 series covering electrostatic discharge, radiated immunity, electrical fast transients, surge, conducted immunity, power-frequency magnetic fields, and voltage dips or interruptions.

Warranty and Service Entitlements

The supplied product data does not specify warranty duration, replacement terms, software support entitlement, hardware support response times, advance replacement conditions, or service-level options.

A presales proposal should therefore treat warranty and support as separate commercial line items requiring confirmation. The bill of materials should identify the required hardware support level, software subscription or entitlement, management platform licensing, IPS and threat intelligence subscriptions, and any service coverage for optional network modules, power supplies, fan modules, and storage components.

Cisco Capital is listed as a financing option for hardware, software, services, and complementary third-party equipment. The supplied data describes flexible payment arrangements but does not define product warranty or technical support terms.

Engineering Selection Rules

Use the following rules when narrowing the appliance choice:

  1. Select against the enabled security feature set, not the highest stateful firewall number.
  2. Use FW plus AVC plus IPS throughput for a Threat Defense design requiring concurrent firewall, application visibility, and IPS inspection.
  3. Apply the TLS throughput value independently when encrypted traffic inspection is part of the requirement.
  4. Compare both concurrent sessions and new connections per second with measured or forecast workload values.
  5. Use the multiprotocol ASA throughput for mixed enterprise traffic rather than the ideal 1500-byte UDP result.
  6. Use the correct VPN test basis for the selected software: 1024-byte TCP with Fastpath for Threat Defense or 450-byte UDP L2L for ASA.
  7. Select the FPR-2130 or FPR-2140 when 10G SFP+, fail-to-wire network modules, twenty-four Ethernet ports, DC power, or redundant power are required.
  8. Allow for acoustic output up to 74 or 77 dBA in rack-room and branch-site planning.
  9. Validate rack hardware, airflow, altitude, humidity, and power-feed requirements before shipment.
  10. Do not assume MTBF, warranty duration, service response, or module-specific performance where the supplied specifications provide no value.

The Firepower 2100 family provides a consistent 1RU mechanical platform across all four models, while throughput, optical interface speed, network module support, power redundancy, storage capacity, and environmental operating options distinguish the individual SKUs. Final sizing should use the selected software mode and the actual traffic and security policy profile.