Cisco Firepower 9300 is a 3RU modular security appliance for carrier-grade firewalls, dedicated threat sensors, high-performance computing centers, large data centers, campus cores, service-provider networks, and other network locations requiring high throughput and low latency. The platform supports Cisco Secure Firewall ASA or Threat Defense software and can scale beyond 1 Tbps when clustered.

Its architecture separates the chassis, supervisor, security modules, and network modules. A single chassis supports up to three security modules and two network module slots. The security module determines the primary processing capacity, while the network modules provide interface density, higher-speed connectivity, or fail-to-wire operation.

Platform architecture and deployment role

The Firepower 9300 chassis contains:

  • Three security module slots.
  • Two network module slots located within the supervisor.
  • A Cisco Firepower 9000 Supervisor.
  • Eight integrated 10 Gigabit Ethernet ports on the supervisor.
  • One Gigabit Ethernet copper management port.
  • One RJ-45 console port.
  • One USB 2.0 port.
  • Four hot-swappable fans.
  • Redundant 1+1 power supply capability.

The security module options are SM-40, SM-48, and SM-56. A chassis can be populated with one, two, or three modules, subject to the supported deployment design. The performance table identifies a three-module SM-56 configuration as “3 x SM-56.” This is a chassis configuration rather than a separate physical security module model.

The platform supports both firewall and security inspection roles:

  • Cisco Secure Firewall Threat Defense provides firewall, Application Visibility and Control, intrusion prevention, VPN, URL filtering, malware defense, and related security functions.
  • Cisco Secure Firewall ASA provides stateful firewall, VPN, security contexts, clustering, and related firewall capabilities.
  • Fail-to-wire network modules allow deployment as a dedicated threat sensor or inline security device.
  • Active/active and active/standby high availability are supported.
  • Threat Defense clustering supports up to six security modules across up to six Firepower 9300 chassis.
  • ASA clustering supports up to 16 security modules across up to 16 Firepower 9300 chassis.

The platform supports flow offloading, programmatic orchestration, RESTful APIs, SD-WAN functions, on-demand site-to-site tunnels, and dynamic application path selection across multiple WAN interfaces. The supplied material also identifies multi-threaded Snort 3 processing, AI/ML-based anomaly detection, threat remediation, firewall policy optimization, and an AI chatbot for guidance, troubleshooting, and policy configuration.

Model and configuration selection

Designation FTD firewall plus AVC FTD firewall plus AVC plus IPS FTD NGIPS FTD maximum concurrent sessions with AVC FTD new connections per second with AVC Best For
SM-40 55 Gbps 55 Gbps 60 Gbps 35 million 380K High-throughput firewall, VPN, and inspection deployments requiring the lowest module capacity in the series
SM-48 65 Gbps 65 Gbps 68 Gbps 35 million 450K Larger data center or campus edge deployments requiring additional inspection and connection rate capacity
SM-56 70 Gbps 68 Gbps 73 Gbps 35 million 490K Highest single-module FTD performance and higher application inspection capacity
3 x SM-56 190 Gbps 190 Gbps 190 Gbps 60 million 1.1 million High-density chassis deployments requiring modular scale and clustering capability

The model overview table also identifies the following headline values:

Designation Firewall NGFW NGIPS Fixed interfaces Optional interfaces Best For
SM-40 80 Gbps 55 Gbps 60 Gbps 8 x SFP+ on chassis Two network modules supporting 1/10/40/100G and FTW Standard security services with moderate inspection scale
SM-48 80 Gbps 65 Gbps 68 Gbps 8 x SFP+ on chassis Two network modules supporting 1/10/40/100G and FTW Higher-throughput NGFW and NGIPS services
SM-56 80 Gbps 68 Gbps 73 Gbps 8 x SFP+ on chassis Two network modules supporting 1/10/40/100G and FTW Highest single-module security processing
SM-56 x 3 235 Gbps 190 Gbps 190 Gbps 8 x SFP+ on chassis Two network modules supporting 1/10/40/100G and FTW Modular chassis scale and high connection density

The two tables use different test definitions and software feature combinations. The model overview values should not be treated as interchangeable with the detailed FTD or ASA figures. During sizing, the selected figure must match the intended software, enabled services, traffic profile, packet size, and inspection policy.

Threat Defense performance

The following values apply to the Threat Defense performance table and use 1024-byte traffic unless otherwise stated.

Capability SM-40 SM-48 SM-56 3 x SM-56
Firewall plus AVC 55 Gbps 65 Gbps 70 Gbps 190 Gbps
Firewall plus AVC plus IPS 55 Gbps 65 Gbps 68 Gbps 190 Gbps
Concurrent sessions with AVC 35 million 35 million 35 million 60 million
New connections per second with AVC 380K 450K 490K 1.1 million
TLS hardware decryption 10 Gbps 11 Gbps 12 Gbps 28 Gbps
NGIPS 60 Gbps 68 Gbps 73 Gbps 190 Gbps
IPsec VPN, TCP/Fastpath 27 Gbps 33 Gbps 36 Gbps 110 Gbps
Maximum VPN peers 20,000 20,000 20,000 60,000

The TLS results were measured with 50 percent TLS 1.2 traffic using AES256-SHA and RSA 2048-bit keys. The 3 x SM-56 VPN throughput value is identified as applying to an unclustered configuration.

FTD includes AVC as a standard capability, supporting more than 4,000 applications and classification by geolocation, user, and website. OpenAppID support is available for custom, open-source application detectors. Cisco Security Intelligence provides IP, URL, and DNS threat intelligence.

Additional security functions are available as licensing or service options:

  • Cisco IPS License for passive endpoint and infrastructure detection, threat correlation, and Indicator of Compromise intelligence.
  • Cisco Malware Defense for Networks for malware detection, blocking, tracking, analysis, and containment.
  • Optional threat correlation with Cisco Secure Endpoint.
  • Cisco Malware Analytics sandboxing.
  • URL filtering across more than 120 categories.
  • URL categorization covering more than 280 million URLs.
  • Automated threat feed and IPS signature updates through Cisco Talos Collective Security Intelligence.
  • Open APIs for third-party integration.
  • Snort and OpenAppID community resources for custom or emerging threat detection.

Performance varies with enabled features, protocol mix, and packet size. A design based only on raw firewall throughput is unsuitable where TLS decryption, AVC, IPS, URL filtering, malware inspection, or extensive logging will be enabled.

ASA performance and capabilities

Capability SM-40 SM-48 SM-56 3 x SM-56
Stateful inspection firewall throughput 80 Gbps 80 Gbps 80 Gbps 235 Gbps
Stateful inspection, multiprotocol 55 Gbps 60 Gbps 64 Gbps 172 Gbps
Concurrent firewall connections 55 million 60 million 60 million 195 million
Firewall latency, UDP 64-byte test 3.5 microseconds 3.5 microseconds 3.5 microseconds 3.5 microseconds
New connections per second 1.6 million 1.8 million 2 million 4.75 million
IPsec VPN, 450-byte UDP site-to-site test 25 Gbps 27 Gbps 30 Gbps 74 Gbps
Maximum VPN peers 20,000 20,000 20,000 60,000

The stateful inspection figures were measured using 1500-byte UDP traffic under ideal test conditions. The multiprotocol figures represent traffic consisting primarily of TCP-based protocols and applications such as HTTP, SMTP, FTP, IMAPv4, BitTorrent, and DNS.

ASA includes 10 security contexts, with a maximum of 250. It supports active/active and active/standby high availability, VPN load balancing, and firewall clustering. Local management is available through Adaptive Security Device Manager for small-scale deployments. Centralized configuration, logging, monitoring, and reporting are performed through Cisco Security Manager or Cisco Defense Orchestrator.

Presales selection should distinguish between an ASA firewall design and an FTD inspection design. ASA figures are generally relevant to stateful firewall, VPN, and connection-rate sizing. FTD figures are relevant when AVC, IPS, TLS decryption, malware controls, and application-aware policy are part of the service definition.

Interfaces and network modules

The supervisor provides eight 10 Gigabit Ethernet ports and two network module slots. Supported network module types include:

  • 8-port 10 Gigabit Ethernet SFP+ module.
  • 4-port 40 Gigabit Ethernet QSFP+ module.
  • 2-port 100 Gigabit Ethernet QSFP28 module.
  • 4-port 100 Gigabit Ethernet QSFP28 module.
  • 6-port 10 Gbps SR fiber fail-to-wire module.
  • 6-port 10 Gbps LR fiber fail-to-wire module.
  • 2-port 40 Gbps SR fail-to-wire module.

With two network modules, the chassis supports up to:

  • 24 x 10 Gigabit Ethernet SFP+ interfaces.
  • 8 x 40 Gigabit Ethernet QSFP+ interfaces.
  • 8 x 100 Gigabit Ethernet interfaces.
  • 24 x 1 Gigabit Ethernet SFP ports when network modules and fixed ports are combined.

Fail-to-wire modules support inline designs and dedicated threat-sensor deployments. The interface plan should account for inside, outside, management, high-availability, cluster, monitoring, and service-chain connections. Network module selection should be completed before rack installation because it affects optical requirements, port density, cabling, and failover behavior.

Storage, power, and physical installation

Each security module contains two SSDs in a RAID-1 configuration. Storage capacity is up to 1.6 TB per security module and up to 4.8 TB per chassis.

The chassis is 3RU and fits a standard 19-inch square-hole rack. Mount rails are included for a 4-post EIA-310-D rack.

Attribute Specification
Dimensions 5.25 x 17.5 x 32 inches; 13.3 x 44.5 x 81.3 cm
Weight with one security module 105 lb; 47.7 kg
Fully configured weight 135 lb; 61.2 kg
Fans Four hot-swappable fans
Maximum acoustic noise 75.5 dBA at maximum fan speed
Rack installation Supported; mount rails included
Management port One Gigabit Ethernet copper port
Console One RJ-45 serial console
USB One USB 2.0 port

Power supply variants are available for AC, -48V DC, and HVDC input.

Power characteristic AC -48V DC HVDC
Input voltage 200 to 240V AC -40V to -60V DC 240 to 380V DC
Maximum input current 15.5A to 12.9A 69A to 42A Less than 14A at 200V
Maximum output power 2,500W 2,500W 2,500W
Frequency 50 to 60 Hz Not applicable Not applicable
Efficiency at 50 percent load 92% 92% 92%
Redundancy 1+1 1+1 1+1

The minimum turn-on voltage for the -48V DC supply is -44V DC. Power planning must consider the fully configured chassis, redundant feed requirements, upstream circuit capacity, and the heat load associated with the maximum 2,500W output rating. The 75.5 dBA maximum fan noise is significant for office-adjacent installations and should be considered during rack-room planning.

Environmental operating limits

Standard operating temperature for SM-40 and SM-48 configurations is 0 to 40 degrees C at the stated altitude limit. For SM-56, the maximum temperature is 35 degrees C, with a 1 degree C reduction for every 1,000 feet above sea level. The SM-56 operating altitude limit is 10,000 feet. SM-40 and SM-48 configurations support operation up to 13,000 feet.

Environmental condition Specification
Standard operating temperature 0 to 40 degrees C for SM-40 and SM-48
SM-56 temperature limit 35 degrees C, reduced by 1 degree C per 1,000 feet above sea level
Operating altitude, SM-40 and SM-48 0 to 13,000 feet; 0 to 3,962 m
Operating altitude, SM-56 0 to 10,000 feet; 0 to 3,048 m
Nonoperating temperature -40 to 65 degrees C
Nonoperating altitude Up to 40,000 feet; 12,192 m
Operating humidity 5 to 95 percent, noncondensing
Nonoperating humidity 5 to 95 percent, noncondensing

NEBS compliance applies to SM-40 and SM-48 configurations. NEBS operating limits are:

  • Long-term operation from 0 to 45 degrees C up to 6,000 feet.
  • Long-term operation from 0 to 35 degrees C between 6,000 and 13,000 feet.
  • Short-term operation from -5 to 55 degrees C up to 6,000 feet.

The supplied hardware specifications do not state a Mean Time Between Failures value. MTBF should therefore be treated as not specified for presales documentation unless a separate approved reliability document provides it.

Compliance and assurance

The Firepower 9300 platform includes Cisco Trust Anchor Technologies for supply-chain and software-image assurance.

The documented compliance areas include:

  • NEBS compliance for SM-40 and SM-48 configurations.
  • CE marking.
  • UL, CSA, EN, IEC, AS/NZS, and GB safety standards.
  • FCC Class A and other regional Class A emissions requirements.
  • EMC immunity standards covering electrostatic discharge, radiated immunity, electrical fast transients, surge, conducted immunity, power-frequency magnetic fields, and voltage dips or interruptions.

The installation environment must support Class A equipment, the required rack depth, the fully configured chassis weight, redundant power feeds, and the thermal output associated with the selected module and power configuration.

Management, availability, and presales sizing rules

Centralized FTD management is provided through Management Center or Cisco Defense Orchestrator. ASA management uses Cisco Security Manager or Cisco Defense Orchestrator, with Adaptive Security Device Manager available for small-scale local management.

Sizing should follow these rules:

  1. Select the software image first. ASA and FTD performance figures are not interchangeable.
  2. Use the detailed workload figure, not the headline firewall value, when inspection features are enabled.
  3. Size for the expected traffic mix and packet size, especially for multiprotocol traffic.
  4. Account separately for sustained throughput, TLS decryption throughput, concurrent sessions, and new connections per second.
  5. Validate VPN throughput against the actual packet size and test profile.
  6. Include growth, failover, maintenance, and clustering overhead in the capacity plan.
  7. Confirm interface speed and optical requirements before selecting network modules.
  8. Use SM-40 or SM-48 where NEBS compliance is required; the supplied specifications do not identify SM-56 as NEBS compliant.
  9. Validate rack depth, power draw, noise, and weight before approving installation.
  10. Treat licensing and optional security services as separate design elements rather than assuming every inspection feature is included in the base hardware.

Warranty terms, entitlement levels, response targets, and hardware replacement service details are not specified in the supplied Firepower 9300 hardware and performance material. Service coverage should therefore be quoted and validated separately. Cisco Capital is identified as a financing option for hardware, software, services, and complementary third-party equipment through predictable payments.