Cisco Firepower 9300 is a 3RU modular security appliance for carrier-grade firewalls, dedicated threat sensors, high-performance computing centers, large data centers, campus cores, service-provider networks, and other network locations requiring high throughput and low latency. The platform supports Cisco Secure Firewall ASA or Threat Defense software and can scale beyond 1 Tbps when clustered.
Its architecture separates the chassis, supervisor, security modules, and network modules. A single chassis supports up to three security modules and two network module slots. The security module determines the primary processing capacity, while the network modules provide interface density, higher-speed connectivity, or fail-to-wire operation.
Platform architecture and deployment role
The Firepower 9300 chassis contains:
- Three security module slots.
- Two network module slots located within the supervisor.
- A Cisco Firepower 9000 Supervisor.
- Eight integrated 10 Gigabit Ethernet ports on the supervisor.
- One Gigabit Ethernet copper management port.
- One RJ-45 console port.
- One USB 2.0 port.
- Four hot-swappable fans.
- Redundant 1+1 power supply capability.
The security module options are SM-40, SM-48, and SM-56. A chassis can be populated with one, two, or three modules, subject to the supported deployment design. The performance table identifies a three-module SM-56 configuration as “3 x SM-56.” This is a chassis configuration rather than a separate physical security module model.
The platform supports both firewall and security inspection roles:
- Cisco Secure Firewall Threat Defense provides firewall, Application Visibility and Control, intrusion prevention, VPN, URL filtering, malware defense, and related security functions.
- Cisco Secure Firewall ASA provides stateful firewall, VPN, security contexts, clustering, and related firewall capabilities.
- Fail-to-wire network modules allow deployment as a dedicated threat sensor or inline security device.
- Active/active and active/standby high availability are supported.
- Threat Defense clustering supports up to six security modules across up to six Firepower 9300 chassis.
- ASA clustering supports up to 16 security modules across up to 16 Firepower 9300 chassis.
The platform supports flow offloading, programmatic orchestration, RESTful APIs, SD-WAN functions, on-demand site-to-site tunnels, and dynamic application path selection across multiple WAN interfaces. The supplied material also identifies multi-threaded Snort 3 processing, AI/ML-based anomaly detection, threat remediation, firewall policy optimization, and an AI chatbot for guidance, troubleshooting, and policy configuration.
Model and configuration selection
| Designation | FTD firewall plus AVC | FTD firewall plus AVC plus IPS | FTD NGIPS | FTD maximum concurrent sessions with AVC | FTD new connections per second with AVC | Best For |
|---|---|---|---|---|---|---|
| SM-40 | 55 Gbps | 55 Gbps | 60 Gbps | 35 million | 380K | High-throughput firewall, VPN, and inspection deployments requiring the lowest module capacity in the series |
| SM-48 | 65 Gbps | 65 Gbps | 68 Gbps | 35 million | 450K | Larger data center or campus edge deployments requiring additional inspection and connection rate capacity |
| SM-56 | 70 Gbps | 68 Gbps | 73 Gbps | 35 million | 490K | Highest single-module FTD performance and higher application inspection capacity |
| 3 x SM-56 | 190 Gbps | 190 Gbps | 190 Gbps | 60 million | 1.1 million | High-density chassis deployments requiring modular scale and clustering capability |
The model overview table also identifies the following headline values:
| Designation | Firewall | NGFW | NGIPS | Fixed interfaces | Optional interfaces | Best For |
|---|---|---|---|---|---|---|
| SM-40 | 80 Gbps | 55 Gbps | 60 Gbps | 8 x SFP+ on chassis | Two network modules supporting 1/10/40/100G and FTW | Standard security services with moderate inspection scale |
| SM-48 | 80 Gbps | 65 Gbps | 68 Gbps | 8 x SFP+ on chassis | Two network modules supporting 1/10/40/100G and FTW | Higher-throughput NGFW and NGIPS services |
| SM-56 | 80 Gbps | 68 Gbps | 73 Gbps | 8 x SFP+ on chassis | Two network modules supporting 1/10/40/100G and FTW | Highest single-module security processing |
| SM-56 x 3 | 235 Gbps | 190 Gbps | 190 Gbps | 8 x SFP+ on chassis | Two network modules supporting 1/10/40/100G and FTW | Modular chassis scale and high connection density |
The two tables use different test definitions and software feature combinations. The model overview values should not be treated as interchangeable with the detailed FTD or ASA figures. During sizing, the selected figure must match the intended software, enabled services, traffic profile, packet size, and inspection policy.
Threat Defense performance
The following values apply to the Threat Defense performance table and use 1024-byte traffic unless otherwise stated.
| Capability | SM-40 | SM-48 | SM-56 | 3 x SM-56 |
|---|---|---|---|---|
| Firewall plus AVC | 55 Gbps | 65 Gbps | 70 Gbps | 190 Gbps |
| Firewall plus AVC plus IPS | 55 Gbps | 65 Gbps | 68 Gbps | 190 Gbps |
| Concurrent sessions with AVC | 35 million | 35 million | 35 million | 60 million |
| New connections per second with AVC | 380K | 450K | 490K | 1.1 million |
| TLS hardware decryption | 10 Gbps | 11 Gbps | 12 Gbps | 28 Gbps |
| NGIPS | 60 Gbps | 68 Gbps | 73 Gbps | 190 Gbps |
| IPsec VPN, TCP/Fastpath | 27 Gbps | 33 Gbps | 36 Gbps | 110 Gbps |
| Maximum VPN peers | 20,000 | 20,000 | 20,000 | 60,000 |
The TLS results were measured with 50 percent TLS 1.2 traffic using AES256-SHA and RSA 2048-bit keys. The 3 x SM-56 VPN throughput value is identified as applying to an unclustered configuration.
FTD includes AVC as a standard capability, supporting more than 4,000 applications and classification by geolocation, user, and website. OpenAppID support is available for custom, open-source application detectors. Cisco Security Intelligence provides IP, URL, and DNS threat intelligence.
Additional security functions are available as licensing or service options:
- Cisco IPS License for passive endpoint and infrastructure detection, threat correlation, and Indicator of Compromise intelligence.
- Cisco Malware Defense for Networks for malware detection, blocking, tracking, analysis, and containment.
- Optional threat correlation with Cisco Secure Endpoint.
- Cisco Malware Analytics sandboxing.
- URL filtering across more than 120 categories.
- URL categorization covering more than 280 million URLs.
- Automated threat feed and IPS signature updates through Cisco Talos Collective Security Intelligence.
- Open APIs for third-party integration.
- Snort and OpenAppID community resources for custom or emerging threat detection.
Performance varies with enabled features, protocol mix, and packet size. A design based only on raw firewall throughput is unsuitable where TLS decryption, AVC, IPS, URL filtering, malware inspection, or extensive logging will be enabled.
ASA performance and capabilities
| Capability | SM-40 | SM-48 | SM-56 | 3 x SM-56 |
|---|---|---|---|---|
| Stateful inspection firewall throughput | 80 Gbps | 80 Gbps | 80 Gbps | 235 Gbps |
| Stateful inspection, multiprotocol | 55 Gbps | 60 Gbps | 64 Gbps | 172 Gbps |
| Concurrent firewall connections | 55 million | 60 million | 60 million | 195 million |
| Firewall latency, UDP 64-byte test | 3.5 microseconds | 3.5 microseconds | 3.5 microseconds | 3.5 microseconds |
| New connections per second | 1.6 million | 1.8 million | 2 million | 4.75 million |
| IPsec VPN, 450-byte UDP site-to-site test | 25 Gbps | 27 Gbps | 30 Gbps | 74 Gbps |
| Maximum VPN peers | 20,000 | 20,000 | 20,000 | 60,000 |
The stateful inspection figures were measured using 1500-byte UDP traffic under ideal test conditions. The multiprotocol figures represent traffic consisting primarily of TCP-based protocols and applications such as HTTP, SMTP, FTP, IMAPv4, BitTorrent, and DNS.
ASA includes 10 security contexts, with a maximum of 250. It supports active/active and active/standby high availability, VPN load balancing, and firewall clustering. Local management is available through Adaptive Security Device Manager for small-scale deployments. Centralized configuration, logging, monitoring, and reporting are performed through Cisco Security Manager or Cisco Defense Orchestrator.
Presales selection should distinguish between an ASA firewall design and an FTD inspection design. ASA figures are generally relevant to stateful firewall, VPN, and connection-rate sizing. FTD figures are relevant when AVC, IPS, TLS decryption, malware controls, and application-aware policy are part of the service definition.
Interfaces and network modules
The supervisor provides eight 10 Gigabit Ethernet ports and two network module slots. Supported network module types include:
- 8-port 10 Gigabit Ethernet SFP+ module.
- 4-port 40 Gigabit Ethernet QSFP+ module.
- 2-port 100 Gigabit Ethernet QSFP28 module.
- 4-port 100 Gigabit Ethernet QSFP28 module.
- 6-port 10 Gbps SR fiber fail-to-wire module.
- 6-port 10 Gbps LR fiber fail-to-wire module.
- 2-port 40 Gbps SR fail-to-wire module.
With two network modules, the chassis supports up to:
- 24 x 10 Gigabit Ethernet SFP+ interfaces.
- 8 x 40 Gigabit Ethernet QSFP+ interfaces.
- 8 x 100 Gigabit Ethernet interfaces.
- 24 x 1 Gigabit Ethernet SFP ports when network modules and fixed ports are combined.
Fail-to-wire modules support inline designs and dedicated threat-sensor deployments. The interface plan should account for inside, outside, management, high-availability, cluster, monitoring, and service-chain connections. Network module selection should be completed before rack installation because it affects optical requirements, port density, cabling, and failover behavior.
Storage, power, and physical installation
Each security module contains two SSDs in a RAID-1 configuration. Storage capacity is up to 1.6 TB per security module and up to 4.8 TB per chassis.
The chassis is 3RU and fits a standard 19-inch square-hole rack. Mount rails are included for a 4-post EIA-310-D rack.
| Attribute | Specification |
|---|---|
| Dimensions | 5.25 x 17.5 x 32 inches; 13.3 x 44.5 x 81.3 cm |
| Weight with one security module | 105 lb; 47.7 kg |
| Fully configured weight | 135 lb; 61.2 kg |
| Fans | Four hot-swappable fans |
| Maximum acoustic noise | 75.5 dBA at maximum fan speed |
| Rack installation | Supported; mount rails included |
| Management port | One Gigabit Ethernet copper port |
| Console | One RJ-45 serial console |
| USB | One USB 2.0 port |
Power supply variants are available for AC, -48V DC, and HVDC input.
| Power characteristic | AC | -48V DC | HVDC |
|---|---|---|---|
| Input voltage | 200 to 240V AC | -40V to -60V DC | 240 to 380V DC |
| Maximum input current | 15.5A to 12.9A | 69A to 42A | Less than 14A at 200V |
| Maximum output power | 2,500W | 2,500W | 2,500W |
| Frequency | 50 to 60 Hz | Not applicable | Not applicable |
| Efficiency at 50 percent load | 92% | 92% | 92% |
| Redundancy | 1+1 | 1+1 | 1+1 |
The minimum turn-on voltage for the -48V DC supply is -44V DC. Power planning must consider the fully configured chassis, redundant feed requirements, upstream circuit capacity, and the heat load associated with the maximum 2,500W output rating. The 75.5 dBA maximum fan noise is significant for office-adjacent installations and should be considered during rack-room planning.
Environmental operating limits
Standard operating temperature for SM-40 and SM-48 configurations is 0 to 40 degrees C at the stated altitude limit. For SM-56, the maximum temperature is 35 degrees C, with a 1 degree C reduction for every 1,000 feet above sea level. The SM-56 operating altitude limit is 10,000 feet. SM-40 and SM-48 configurations support operation up to 13,000 feet.
| Environmental condition | Specification |
|---|---|
| Standard operating temperature | 0 to 40 degrees C for SM-40 and SM-48 |
| SM-56 temperature limit | 35 degrees C, reduced by 1 degree C per 1,000 feet above sea level |
| Operating altitude, SM-40 and SM-48 | 0 to 13,000 feet; 0 to 3,962 m |
| Operating altitude, SM-56 | 0 to 10,000 feet; 0 to 3,048 m |
| Nonoperating temperature | -40 to 65 degrees C |
| Nonoperating altitude | Up to 40,000 feet; 12,192 m |
| Operating humidity | 5 to 95 percent, noncondensing |
| Nonoperating humidity | 5 to 95 percent, noncondensing |
NEBS compliance applies to SM-40 and SM-48 configurations. NEBS operating limits are:
- Long-term operation from 0 to 45 degrees C up to 6,000 feet.
- Long-term operation from 0 to 35 degrees C between 6,000 and 13,000 feet.
- Short-term operation from -5 to 55 degrees C up to 6,000 feet.
The supplied hardware specifications do not state a Mean Time Between Failures value. MTBF should therefore be treated as not specified for presales documentation unless a separate approved reliability document provides it.
Compliance and assurance
The Firepower 9300 platform includes Cisco Trust Anchor Technologies for supply-chain and software-image assurance.
The documented compliance areas include:
- NEBS compliance for SM-40 and SM-48 configurations.
- CE marking.
- UL, CSA, EN, IEC, AS/NZS, and GB safety standards.
- FCC Class A and other regional Class A emissions requirements.
- EMC immunity standards covering electrostatic discharge, radiated immunity, electrical fast transients, surge, conducted immunity, power-frequency magnetic fields, and voltage dips or interruptions.
The installation environment must support Class A equipment, the required rack depth, the fully configured chassis weight, redundant power feeds, and the thermal output associated with the selected module and power configuration.
Management, availability, and presales sizing rules
Centralized FTD management is provided through Management Center or Cisco Defense Orchestrator. ASA management uses Cisco Security Manager or Cisco Defense Orchestrator, with Adaptive Security Device Manager available for small-scale local management.
Sizing should follow these rules:
- Select the software image first. ASA and FTD performance figures are not interchangeable.
- Use the detailed workload figure, not the headline firewall value, when inspection features are enabled.
- Size for the expected traffic mix and packet size, especially for multiprotocol traffic.
- Account separately for sustained throughput, TLS decryption throughput, concurrent sessions, and new connections per second.
- Validate VPN throughput against the actual packet size and test profile.
- Include growth, failover, maintenance, and clustering overhead in the capacity plan.
- Confirm interface speed and optical requirements before selecting network modules.
- Use SM-40 or SM-48 where NEBS compliance is required; the supplied specifications do not identify SM-56 as NEBS compliant.
- Validate rack depth, power draw, noise, and weight before approving installation.
- Treat licensing and optional security services as separate design elements rather than assuming every inspection feature is included in the base hardware.
Warranty terms, entitlement levels, response targets, and hardware replacement service details are not specified in the supplied Firepower 9300 hardware and performance material. Service coverage should therefore be quoted and validated separately. Cisco Capital is identified as a financing option for hardware, software, services, and complementary third-party equipment through predictable payments.