The Cisco Firepower 8000 Series is a modular network security appliance family providing next-generation intrusion prevention system protection across inspected-throughput tiers from 2 Gbps to 60 Gbps. The platform combines configurable network modules, integrated fail-open and bypass options, solid-state storage, redundant hot-swappable power supplies, lights-out management, and chassis stacking on selected models.
The appliances form the hardware base for the Cisco FirePOWER NGIPS threat protection solution. The platform provides integrated contextual awareness, full-stack visibility, and security automation. Optional subscription licensing extends the solution with Advanced Malware Protection and application visibility and control.
Product Architecture and Deployment Role
The 8000 Series is designed for inline, passive, fail-closed, and monitoring deployments. Its primary engineering distinction is the use of configurable network modules, or NetMods, rather than a fixed high-end appliance port layout.
A NetMod can be selected according to the network medium and deployment mode:
- Integrated fail-open/bypass modules support inline designs where traffic continuity is required during appliance failure or maintenance.
- Non-bypass modules support passive monitoring and fail-closed designs.
- Copper and fiber options are available at 1 Gbps.
- Fiber options are available at 10 Gbps using short-reach or long-reach optics.
- A 40-Gbps, two-port fiber short-reach module is available in the integrated fail-open/bypass category.
- Chassis support ranges from three modules in the 8100 Series to seven modules in selected 8200 and 8300 models.
This modular design supports staged expansion. A deployment can begin with 1-Gbps copper or fiber connectivity and later change or add NetMods for higher-speed fiber interfaces, subject to the selected chassis slot count and the required module type.
The appliances include a dedicated RJ45 management interface operating at 10/100/1000 Mbps. All listed models provide lights-out management, an LCD management interface, and serial-over-Ethernet console access. These functions support remote administration and reduce the need for physical access during configuration and troubleshooting.
NetMod Selection
| NetMod category | Available interface options | Presales application |
|---|---|---|
| Integrated fail-open/bypass | Four-port 1-Gbps copper | Inline copper segments requiring bypass capability |
| Integrated fail-open/bypass | Four-port 1-Gbps fiber | Inline fiber segments requiring bypass capability |
| Integrated fail-open/bypass | Two-port 10-Gbps fiber SR | Inline short-reach 10-Gbps fiber links |
| Integrated fail-open/bypass | Two-port 10-Gbps fiber LR | Inline long-reach 10-Gbps fiber links |
| Integrated fail-open/bypass | Two-port 40-Gbps fiber SR | High-bandwidth short-reach inline fiber deployments |
| Non-bypass | Four-port 1-Gbps copper | Passive or fail-closed copper monitoring |
| Non-bypass | Four-port 1-Gbps fiber | Passive or fail-closed fiber monitoring |
| Non-bypass | Four-port 10-Gbps fiber SR | Passive or fail-closed short-reach 10-Gbps monitoring |
| Non-bypass | Four-port 10-Gbps fiber LR | Passive or fail-closed long-reach 10-Gbps monitoring |
SR means short-reach and LR means long-reach. The datasheet does not provide optical distance limits, transceiver compatibility lists, connector types, or cabling specifications. Those items must be validated against the intended switching infrastructure before final ordering.
A module count is not the same as a port count. The number of usable interfaces depends on the selected NetMod type. For example, a four-port module and a two-port module consume one slot each but provide different interface density. Presales bills of material should therefore identify both the number of modules and the number of physical ports required.
Throughput and Performance Interpretation
The published IPS throughput values range from 2 Gbps to 60 Gbps. The datasheet also lists a separate Model Throughput value for each appliance. IPS throughput should be used as the primary sizing reference when the appliance is being evaluated for intrusion prevention inspection.
The stated performance can vary according to protocol mix and average packet size inspected. Throughput values should therefore not be treated as a universal line-rate guarantee for every traffic profile. Sizing should use the expected inspected traffic profile, not only the aggregate capacity of the connected switch ports.
Typical latency is listed as less than 150 microseconds for every model. The datasheet does not provide separate latency values by NetMod type, packet size, inspection policy, or enabled subscription feature.
The published performance range is:
- 8100 Series: 2 to 6 Gbps IPS throughput.
- 8200 Series: 10 to 40 Gbps IPS throughput.
- 8300 Series: 15 to 60 Gbps IPS throughput.
Model Throughput is listed at twice the IPS throughput for the 8100, 8200, and 8300 product tables except for the 8140, which is listed at 10 Gbps Model Throughput against 6 Gbps IPS throughput. The datasheet does not define the calculation or intended engineering use of the Model Throughput field. It should not replace IPS throughput during security inspection sizing.
Complete Appliance Comparison
| Model | IPS throughput | Model throughput | RAM | NetMod capacity | Cooling fans | Stacking capability | Best For |
|---|---|---|---|---|---|---|---|
| 8120 | 2 Gbps | 4 Gbps | 24 GB | Up to 3 modules | 10 | Not stackable | Smaller inspected traffic loads with modular interface requirements |
| 8130 | 4 Gbps | 8 Gbps | 24 GB | Up to 3 modules | 10 | Not stackable | Midrange branch, campus, or smaller data center security inspection |
| 8140 | 6 Gbps | 10 Gbps | 24 GB | Up to 3 modules | 10 | One stacking kit; stack size of two and 12-Gbps IPS | 8100 deployment requiring higher throughput or limited scale-out |
| 8250 | 10 Gbps | 20 Gbps | 48 GB | Up to 7 modules | 6 | Up to four chassis and 40-Gbps IPS | Entry 8200 deployment with high interface density and future stacking |
| 8260 | 20 Gbps | 40 Gbps | 96 GB | Up to 6 modules | 12 | Up to four chassis and 40-Gbps IPS | Higher-throughput deployments requiring expansion headroom |
| 8270 | 30 Gbps | 60 Gbps | 144 GB | Up to 5 modules | 18 | Stackable to four chassis; see 8290 for stack details | Large inspection environments needing scale-out capacity |
| 8290 | 40 Gbps | 80 Gbps | 192 GB | Up to 4 modules | 24 | Fully stacked; no further expansion | Highest single-model 8200 throughput and completed stack designs |
| 8350 | 15 Gbps | 30 Gbps | 128 GB | Up to 7 modules | 6 | Up to four chassis and 60-Gbps IPS | 8300 entry platform with maximum NetMod flexibility |
| 8360 | 30 Gbps | 60 Gbps | 256 GB | Up to 6 modules | 12 | Up to four chassis and 60-Gbps IPS | High-throughput deployments requiring substantial memory |
| 8370 | 45 Gbps | 90 Gbps | 384 GB | Up to 5 modules | 18 | Stackable to four chassis; see 8390 for stack details | Large enterprise inspection with stack-based growth |
| 8390 | 60 Gbps | 120 Gbps | 512 GB | Up to 4 modules | 24 | Fully stacked; no further expansion | Highest listed IPS capacity and fully expanded 8300 stack endpoint |
All listed models include FirePOWER functionality, dual power supplies, solid-state drives, lights-out management, and RJ45 management connectivity at 10/100/1000 Mbps.
Monitoring and Bypass Interfaces
Every model table lists the same monitoring interface selections, independent of appliance performance tier.
Configurable bypass monitoring interfaces include:
- Four 1-Gbps copper ports.
- Four 1-Gbps fiber ports.
- Two 10-Gbps SR fiber ports.
- Two 10-Gbps LR fiber ports.
Non-bypass monitoring interfaces include:
- Four 1-Gbps copper ports.
- Four 1-Gbps fiber ports.
- Four 10-Gbps SR fiber ports.
- Four 10-Gbps LR fiber ports.
The configurable bypass interface set provides two-port 10-Gbps options, while the non-bypass set provides four-port 10-Gbps options. This difference should be reflected in port-density calculations. If the design requires physical bypass behavior, the selected traffic path must use an integrated fail-open/bypass NetMod. A standard non-bypass module should not be represented as equivalent to a bypass module in a proposal.
The datasheet does not identify the maximum number of active monitoring interfaces supported concurrently, the relationship between monitoring interfaces and NetMod slots, or the supported bypass failure modes. These points require design validation for deployments with multiple protected links.
Stacking and Capacity Expansion
The 8200 and 8300 Series support chassis stacking to increase IPS capacity while occupying less rack space than equivalent collections of individual appliances. The maximum stack size is four chassis for the supported 8200 and 8300 configurations.
8200 stacking behavior is as follows:
- 8250 supports up to three stacking kits for a four-chassis stack delivering 40-Gbps IPS.
- 8260 supports up to two stacking kits for a four-chassis stack delivering 40-Gbps IPS.
- 8270 supports one stacking kit and can form a four-chassis stack when combined with the 8290 configuration.
- 8290 is fully stacked and has no further expansion capability.
8300 stacking behavior is as follows:
- 8350 supports up to three stacking kits for a four-chassis stack delivering 60-Gbps IPS.
- 8360 supports up to two stacking kits for a four-chassis stack delivering 60-Gbps IPS.
- 8370 supports one stacking kit and references the 8390 for the four-chassis configuration.
- 8390 is fully stacked and has no further expansion capability.
The 8100 Series has more limited stacking:
- 8120 is not stackable.
- 8130 is not stackable.
- 8140 supports one stacking kit for a two-chassis stack delivering 12-Gbps IPS.
Stacking should be selected when the expected traffic growth exceeds the capacity of a single chassis and the deployment can accommodate the required stacking kits and chassis. The datasheet does not provide stacking cable specifications, inter-chassis topology, stack resiliency behavior, or operational restrictions. Those details must be included in the implementation design.
Memory, Storage, Power, and Cooling
Memory increases with model capacity in the 8200 and 8300 families. The 8100 models each provide 24 GB of RAM. The 8200 models provide 48 GB, 96 GB, 144 GB, and 192 GB, respectively. The 8300 models provide 128 GB, 256 GB, 384 GB, and 512 GB, respectively.
Every listed appliance uses solid-state drives. The datasheet does not state drive capacity, RAID arrangement, replacement procedure, endurance rating, or data-retention behavior.
All models provide dual power supplies. The datasheet identifies the power supplies as redundant and hot-swappable in the common platform feature list. It does not provide input voltage range, frequency, wattage, connector type, power consumption, power budget, or power supply part numbers.
PoE is not specified. These appliances are security inspection platforms and the supplied material does not list PoE ports or a PoE power budget. PoE requirements must be handled by the connected switching infrastructure.
Cooling fan counts vary by model:
- 8100 models: 10 fans.
- 8250 and 8350: 6 fans.
- 8260 and 8360: 12 fans.
- 8270 and 8370: 18 fans.
- 8290 and 8390: 24 fans.
The datasheet does not identify fan redundancy, fan replacement status, airflow direction, rack-unit height, acoustic output, or thermal design limits.
Environmental and Physical Planning
The supplied product specifications do not state the following environmental or physical values:
| Planning requirement | Published value |
|---|---|
| MTBF | Not specified |
| Operating temperature | Not specified |
| Non-operating temperature | Not specified |
| Operating humidity | Not specified |
| Non-operating humidity | Not specified |
| Operating altitude | Not specified |
| Storage altitude | Not specified |
| Dimensions | Not specified |
| Weight | Not specified |
| Rack-unit height | Not specified |
| Acoustic noise | Not specified |
| Heat dissipation | Not specified |
| Input power range | Not specified |
| Maximum power draw | Not specified |
These omissions are material for presales engineering. Rack planning cannot be completed from the supplied datasheet alone. The final design should obtain verified chassis dimensions, weight, rack height, power draw, circuit requirements, airflow clearance, acoustic rating, operating temperature range, and environmental humidity limits.
The number of fans and dual power supplies indicate a serviceable, redundant hardware design, but they do not establish a specific environmental rating or acoustic level. Fan count must not be used to infer noise performance or cooling capacity.
Security Functions and Licensing
The base appliances support FirePOWER functionality and serve as the hardware platform for NGIPS protection. The feature set includes real-time contextual awareness, full-stack visibility, and intelligent security automation.
Optional subscription licenses can extend the platform with:
- Advanced Malware Protection.
- Application visibility and control.
The ordering table lists chassis and subscription bundles rather than bare chassis-only part numbers. The bundle names do not specify subscription duration, license quantities, feature entitlements, renewal terms, or support coverage. Those commercial and service details must be confirmed in the quotation and entitlement documentation.
Presales proposals should separate hardware capacity from software licensing. IPS throughput alone does not identify the full commercial configuration when AMP or application visibility and control are required.
Ordering Matrix
| Product name | Part number | IPS throughput | Best For |
|---|---|---|---|
| Cisco FirePOWER 8120 Chassis and Subscription Bundle | FP8120-BUN | 2 Gbps | Smallest listed modular appliance tier |
| Cisco FirePOWER 8130 Chassis and Subscription Bundle | FP8130-BUN | 4 Gbps | Small to midrange inspection deployment |
| Cisco FirePOWER 8140 Chassis and Subscription Bundle | FP8140-BUN | 6 Gbps | Higher-capacity 8100 deployment with optional two-chassis stack |
| Cisco FirePOWER 8250 Chassis and Subscription Bundle | FP8250-BUN | 10 Gbps | Entry 8200 platform with up to seven NetMods |
| Cisco FirePOWER 8260 Chassis and Subscription Bundle | FP8260-BUN | 20 Gbps | Midrange high-throughput inspection |
| Cisco FirePOWER 8270 Chassis and Subscription Bundle | FP8270-BUN | 30 Gbps | Enterprise inspection with four-chassis scale-out path |
| Cisco FirePOWER 8290 Chassis and Subscription Bundle | FP8290-BUN | 40 Gbps | Highest listed 8200 appliance and stack endpoint |
| Cisco FirePOWER 8350 Chassis and Subscription Bundle | FP8350-BUN | 15 Gbps | Entry 8300 platform with up to seven NetMods |
| Cisco FirePOWER 8360 Chassis and Subscription Bundle | FP8360-BUN | 30 Gbps | High-capacity inspection with 256 GB RAM |
| Cisco FirePOWER 8370 Chassis and Subscription Bundle | FP8370-BUN | 45 Gbps | Large enterprise inspection with stack expansion |
| Cisco FirePOWER 8390 Chassis and Subscription Bundle | FP8390-BUN | 60 Gbps | Highest listed single-model IPS throughput |
Warranty and Service Considerations
The supplied datasheet does not state a standard warranty period, warranty scope, advance replacement terms, hardware replacement target, software support entitlement, technical support access model, or subscription support conditions.
The ordering information identifies chassis and subscription bundles, but it does not define the included service level. A complete proposal should therefore identify, as separate commercial line items where required:
- Hardware warranty coverage.
- Software support and maintenance.
- Subscription entitlement for AMP.
- Subscription entitlement for application visibility and control.
- Renewal requirements.
- Replacement logistics.
- Technical assistance coverage.
- Software update and upgrade rights.
No warranty duration or service response commitment should be inferred from the chassis specification. These terms must be documented in the applicable quotation, contract, or service description.
Presales Sizing Rules
Use the following rules when preparing a design:
- Size against IPS throughput, not Model Throughput.
- Measure the traffic that will actually be inspected, including both directions where applicable.
- Account for protocol mix and average packet size because the datasheet states that these affect experienced performance.
- Select integrated fail-open/bypass NetMods for inline designs requiring bypass capability.
- Select non-bypass NetMods for passive or fail-closed monitoring designs.
- Count module slots separately from physical interface ports.
- Reserve unused module capacity when future 10-Gbps or 40-Gbps connectivity is a stated requirement.
- Use stacking only where the required chassis combination, stacking kit count, and target IPS capacity are supported.
- Treat 8290 and 8390 as fully stacked endpoints with no further stacking expansion.
- Do not claim PoE support or include a PoE budget; none is specified.
- Validate rack dimensions, power draw, thermal requirements, and acoustic output before site approval.
- Confirm subscription and warranty terms independently from the hardware throughput selection.