Cisco Firepower NGIPS is a dedicated network threat prevention platform that combines inline intrusion prevention, contextual network visibility, security intelligence, malware analysis, application control, URL filtering, and centralized policy management. The appliance family spans branch, enterprise edge, data center, private cloud, carrier, and high-performance environments, with NGIPS throughput ranging from 1.5 Gbps to 175 Gbps depending on packet size and platform.
Architecture and operating model
Firepower NGIPS continuously discovers network context, including users, applications, devices, operating systems, vulnerabilities, files, services, processes, and network behavior. This information is used to build network maps and host profiles, enrich intrusion events, and support automated security decisions.
The platform is built on Snort technology and uses vulnerability-based and anomaly-based inspection. Its security controls include:
- IPS rules that identify and block traffic targeting known vulnerabilities.
- IP-, URL-, and DNS-based security intelligence.
- Advanced Malware Protection for detection, blocking, tracking, analysis, and containment.
- Sandboxing and behavioral analysis for evasive, zero-day, and unknown threats.
- Application Visibility and Control for more than 4000 commercial applications.
- OpenAppID support for custom, localized, and cloud application identification.
- URL filtering across more than 80 categories and more than 280 million categorized URLs for the 2100, 4100, and 9300 families.
- URL filtering across more than 120 categories for the 3100 and 4200 families.
- Automated threat feed and IPS signature updates from Cisco Talos.
- Centralized configuration, event collection, monitoring, logging, and reporting through Firepower Management Center.
- Open APIs for integration with third-party products.
- Integration with Cisco Identity Services Engine for actions such as quarantine and blocking.
- Integration with endpoint malware protection for event correlation and remediation.
The appliances can operate inline using Fail-To-Wire network modules. Fail-To-Wire design is relevant where traffic continuity is required during appliance failure or power interruption. The correct network module must be selected for the required copper, multimode fiber, single-mode fiber, and interface speed.
Security functions and presales value
Intrusion prevention
The core IPS function uses Snort-based inspection, vulnerability-focused signatures, anomaly detection, and contextual policy conditions. Security teams can prioritize events associated with exploitable weaknesses instead of treating every signature match as equally important.
Firepower NGIPS correlates intrusion events with known network vulnerabilities. It can identify attacks that are more likely to succeed and recommend security policies intended to address observed weaknesses. Indications of Compromise can correlate events from IPS, security intelligence, network malware protection, and endpoint malware protection to identify potentially compromised hosts.
Contextual awareness
The platform associates network activity with:
- Users and directory identities.
- Applications and custom applications.
- Devices and operating systems.
- Client-side applications and services.
- Vulnerabilities and network behavior.
- Files and detected threats.
- Mobile devices and associated activity.
Active Directory, LDAP, and captive portal integration can associate users with IPS events. This is useful for incident investigation, user-level reporting, and policy enforcement.
Malware protection and sandboxing
Advanced Malware Protection is available as an additional capability. It addresses file-based and persistent threats through detection, tracking, containment, analysis, and remediation. Sandboxing can be deployed in the cloud or on premises and uses behavioral indicators to identify unknown or evasive content.
The platform can alert administrators when content is subsequently classified as malicious, even if the initial inspection allowed it. This supports retrospective detection and investigation of files that were not known to be malicious when first observed.
Application and URL control
Application Visibility and Control supports policy decisions for more than 4000 commercial applications. OpenAppID enables identification and control of custom, localized, and cloud applications.
URL filtering is an optional capability. For the 2100, 4100, and 9300 families, the specification identifies more than 80 categories and more than 280 million categorized URLs. For the 3100 and 4200 families, the specification identifies more than 120 categories. The datasheet does not provide a URL count for the latter group.
Performance and platform selection
Performance depends on packet size, traffic protocol mix, activated features, and software release. The 450-byte figures are lower than the 1024-byte figures and should be used when sizing traffic with smaller packets or high packet-per-second rates.
Firepower 2100, 4100, and 9300 performance
| Model | NGIPS throughput, 1024-byte | NGIPS throughput, 450-byte | Concurrent sessions | New connections/sec | Integrated interfaces | Best For |
|---|---|---|---|---|---|---|
| 2130 | 4.7 Gbps | 1.5 Gbps | 2M | 27K | 12 x 1GE RJ45, 4 x SFP+ | Small enterprise edge and dedicated IPS deployments |
| 2140 | 9 Gbps | 3 Gbps | 3M | 57K | 12 x 1GE RJ45, 4 x SFP+ | Higher-capacity enterprise edge and aggregation |
| 4115 | 27 Gbps | 9 Gbps | 15M | 200K | 8 x SFP+ | Enterprise edge and data center inspection |
| 4125 | 41 Gbps | 15 Gbps | 25M | 265K | 8 x SFP+ | High-throughput enterprise and data center traffic |
| 4145 | 55 Gbps | 19 Gbps | 30M | 350K | 8 x SFP+ | Large data center and Internet-edge inspection |
| 9300 with SM-40 | 57 Gbps | 21 Gbps | 35M | 380K | 8 x SFP+ | Modular high-throughput environments |
| 9300 with SM-48 | 66 Gbps | 23 Gbps | 35M | 450K | 8 x SFP+ | Larger modular security deployments |
| 9300 with SM-56 | 73 Gbps | 27 Gbps | 35M | 490K | 8 x SFP+ | High-scale data center and service-provider environments |
| 9300 with SM-56 x 3 | 175 Gbps | 64 Gbps | 60M | 1.1M | 8 x SFP+ | Maximum listed modular throughput and session scale |
The 2100 Series provides four threat-focused security platforms and supports Network Equipment Building Standards compliance. The 4100 Series consists of four platforms with maximum throughput from 12 to 24 Gbps as described in the platform overview, while the detailed table lists NGIPS performance from 9 to 55 Gbps for the 4115, 4125, and 4145 models. The 9300 is a modular, carrier-grade platform supporting flow offloading, programmatic orchestration, RESTful APIs, and optional NEBS-compliant configurations. Its stated low-latency use cases include environments requiring less than 5-microsecond offload latency.
Firepower 3100 and 4200 performance
| Model | NGIPS throughput, 1024-byte | NGIPS throughput, 450-byte | Concurrent sessions | New connections/sec | Integrated interfaces | Best For |
|---|---|---|---|---|---|---|
| 3105 | 10 Gbps | 4.7 Gbps | 1.5M | 110K | 8 x RJ45, 8 x 1/10G SFP+ | Branch aggregation and midrange enterprise edge |
| 3110 | 17 Gbps | 7 Gbps | 2M | 130K | 8 x RJ45, 8 x 1/10G SFP+ | Enterprise edge with mixed copper and fiber |
| 3120 | 21 Gbps | 9.8 Gbps | 4M | 170K | 8 x RJ45, 8 x 1/10G SFP+ | Growing data center and private cloud deployments |
| 3130 | 38 Gbps | 15 Gbps | 6M | 240K | 8 x RJ45, 8 x 1/10G SFP+ | High-throughput data center inspection |
| 3140 | 45 Gbps | 19 Gbps | 10M | 300K | 8 x RJ45, 8 x 1/10G SFP+ | Upper-range 3100 deployments |
| 4215 | 65 Gbps | 24 Gbps | 15M | 350K | 8 x 1/10/25G SFP+ | High-capacity Internet edge |
| 4225 | 80 Gbps | 38 Gbps | 30M | 600K | 8 x 1/10/25G SFP+ | Data center and service-provider protection |
| 4245 | 140 Gbps | 71 Gbps | 60M | 800K | 8 x 1/10/25G SFP+ | Large data center and Telco service-provider networks |
The 3100 Series includes five platforms with maximum throughput from 10 to 45 Gbps. The 4200 Series includes three platforms with maximum throughput from 65 to 140 Gbps. Both families support Trust Anchor Technologies for supply-chain and software-image assurance.
Fail-To-Wire and interface planning
Fail-To-Wire capacity varies by platform and module selection.
The 2100 Series supports the following maximum FTW options:
- 8 x 1GE RJ45.
- 6 x 1GE SX.
- 6 x 10G SR.
- 6 x 10G LR.
The 4100 and 9300 families support FTW modules providing:
- 16 x 1GE RJ45.
- 12 x 1GE SX.
- 12 x 10G SR.
- 12 x 10G LR.
- 4 x 40G SR.
For the 3100 Series, FTW is not listed for the 3105, 3110, and 3120. The 3130 and 3140 support:
- 8 x 1GE RJ45.
- 6 x 1GE SX.
- 6 x 10G SR.
- 6 x 10G LR.
- 6 x 25G SR.
- 6 x 25G LR.
The 4200 Series supports:
- 16 x 1GE RJ45.
- 12 x 1GE SX.
- 12 x 10G SR.
- 12 x 10G LR.
- 12 x 25G SR.
- 12 x 25G LR.
Presales rules:
- Select FTW speed and optic type from the physical adjacent network devices, not only from appliance throughput.
- Confirm whether the deployment requires copper, multimode, or single-mode fiber.
- Size the appliance using the 450-byte throughput when packet rates are expected to be high.
- Include inspection overhead from AMP, URL filtering, application control, and logging in the capacity review.
- Validate the required FTW module before finalizing the appliance bundle.
- For high-availability designs, provision equivalent interface types and compatible module capacity on both appliances.
Ordering matrix
Appliance bundles
| Part number | Description | Best For |
|---|---|---|
| FPR2130-BUN | Cisco 2130 Series Appliance – Functions as Dedicated IPS | Dedicated IPS at smaller enterprise edge sites |
| FPR2140-BUN | Cisco 2140 Series Appliance – Functions as Dedicated IPS | Dedicated IPS at higher-capacity enterprise edges |
| FPR4115-BUN | Cisco Firepower 4115 NGIPS Appliance, 1RU, 2 x Network Module Bays | 1RU enterprise and data center deployments |
| FPR4125-BUN | Cisco Firepower 4125 NGIPS Appliance, 1RU, 2 x Network Module Bays | Higher-throughput 1RU inspection |
| FPR4145-BUN | Cisco Firepower 4145 NGIPS Appliance, 1RU, 2 x Network Module Bays | Large-scale 1RU inspection |
| FPR4215-K9 | Cisco 4215 Series Appliance – Functions as Dedicated IPS | High-capacity edge and data center inspection |
| FPR4225-K9 | Cisco 4225 Series Appliance – Functions as Dedicated IPS | Higher session and connection scale |
| FPR4245-K9 | Cisco 4245 Series Appliance – Functions as Dedicated IPS | Maximum listed 4200 performance |
| FPR3105-NGFW-K9 | Cisco 3105 Series Appliance – Functions as Dedicated IPS | Entry 3100 deployments |
| FPR3110-NGFW-K9 | Cisco 3110 Series Appliance – Functions as Dedicated IPS | Mixed copper and fiber enterprise edge |
| FPR3120-NGFW-K9 | Cisco 3120 Series Appliance – Functions as Dedicated IPS | Midrange data center and private cloud |
| FPR3130-NGFW-K9 | Cisco 3130 Series Appliance – Functions as Dedicated IPS | High-throughput 3100 deployments |
| FPR3140-NGFW-K9 | Cisco 3140 Series Appliance – Functions as Dedicated IPS | Maximum listed 3100 performance |
| FPR9K-SM40-FTD-BUN | Cisco Firepower 9300 SM-40 FTD Bundle | Modular high-throughput environments |
| FPR9K-SM48-FTD-BUN | Cisco Firepower 9300 SM-48 FTD Bundle | Larger modular security deployments |
| FPR9K-SM56-FTD-BUN | Cisco Firepower 9300 SM-56 FTD Bundle | High-scale modular inspection |
The source lists the parenthetical software identifiers FPR2140-NGFW-K9 for the FPR2130-BUN entry and FPR2140-NGFW-K9 for the FPR2140-BUN entry. These identifiers should be checked against the applicable ordering guide before quotation.
FTW network modules
| Part number | Description | Best For |
|---|---|---|
| FPR2K-NM-6X10LR-F | 6-port 10G LR FTW Network Module | 10G single-mode inline links on 2100 |
| FPR2K-NM-6X10LR-F= | Spare version of FPR2K-NM-6X10LR-F | Field replacement stock |
| FPR2K-NM-6X10SR-F | 6-port 10G SR FTW Network Module | 10G multimode inline links on 2100 |
| FPR2K-NM-6X10SR-F= | Spare version of FPR2K-NM-6X10SR-F | Field replacement stock |
| FPR2K-NM-6X1SX-F | 6-port 1G SX Fiber FTW Network Module | 1G multimode inline links on 2100 |
| FPR2K-NM-6X1SX-F= | Spare version of FPR2K-NM-6X1SX-F | Field replacement stock |
| FPR2K-NM-8X1G-F | 8-port 1G Copper FTW Network Module | 1G copper inline links on 2100 |
| FPR2K-NM-8X1G-F= | Spare version of FPR2K-NM-8X1G-F | Field replacement stock |
| FPR4K-NM-2X40G-F | 2-port 40G SR FTW Network Module | 40G multimode links on 4100 or 9300 module family |
| FPR4K-NM-2X40G-F= | Spare version | Field replacement stock |
| FPR4K-NM-6X10LR-F | 6-port 10G LR FTW Network Module | 10G single-mode links on 4100 |
| FPR4K-NM-6X10LR-F= | Spare version | Field replacement stock |
| FPR4K-NM-6X10SR-F | 6-port 10G SR FTW Network Module | 10G multimode links on 4100 |
| FPR4K-NM-6X10SR-F= | Spare version | Field replacement stock |
| FPR4K-NM-6X1SX-F | 6-port 1G SX Fiber FTW Network Module | 1G multimode links on 4100 |
| FPR4K-NM-6X1SX-F= | Spare version | Field replacement stock |
| FPR4K-NM-8X1G-F | 8-port 1G Copper FTW Network Module | 1G copper links on 4100 |
| FPR4K-NM-8X1G-F= | Spare version | Field replacement stock |
| FPR4K-XNM-6X1SXF | 4200 6-port 1G SX multimode FTW Netmod | 1G multimode inline links on 4200 |
| FPR4K-XNM-6X1SXF= | Spare version | Field replacement stock |
| FPR4K-XNM-6X10SRF | 4200 6-port 10G SR multimode FTW Netmod | 10G multimode inline links on 4200 |
| FPR4K-XNM-6X10SRF= | Spare version | Field replacement stock |
| FPR4K-XNM-6X25SRF | 4200 6-port 25G SR multimode FTW Netmod | 25G multimode inline links on 4200 |
| FPR4K-XNM-6X25SRF= | Spare version | Field replacement stock |
| FPR4K-XNM-6X25LRF | 4200 6-port 25G LR single-mode FTW Netmod | 25G single-mode inline links on 4200 |
| FPR4K-XNM-6X25LRF= | Spare version | Field replacement stock |
| FPR3K-XNM-6X1SXF | 3100 6-port 1G SX multimode FTW Netmod | 1G multimode links on supported 3100 models |
| FPR3K-XNM-6X1SXF= | Spare version | Field replacement stock |
| FPR3K-XNM-6X10SRF | 3100 6-port 10G SR multimode FTW Netmod | 10G multimode links on supported 3100 models |
| FPR3K-XNM-6X10SRF= | Spare version | Field replacement stock |
| FPR3K-XNM-6X25SRF | 3100 6-port 25G SR multimode FTW Netmod | 25G multimode links on supported 3100 models |
| FPR3K-XNM-6X25SRF= | Spare version | Field replacement stock |
| FPR3K-XNM-6X25LRF | 3100 6-port 25G LR single-mode FTW Netmod | 25G single-mode links on supported 3100 models |
| FPR3K-XNM-6X25LRF= | Spare version | Field replacement stock |
| FPR9K-NM-2X40G-F | 2-port 40G SR FTW Network Module | 40G multimode links on 9300 |
| FPR9K-NM-2X40G-F= | Spare version | Field replacement stock |
| FPR9K-NM-6X10LR-F | 6-port 10G LR FTW Network Module | 10G single-mode links on 9300 |
| FPR9K-NM-6X10LR-F= | Spare version | Field replacement stock |
| FPR9K-NM-6X10SR-F | 6-port 10G SR FTW Network Module | 10G multimode links on 9300 |
| FPR9K-NM-6X10SR-F= | Spare version | Field replacement stock |
| FPR9K-NM-6X1SX-F | 6-port 1G SX Fiber FTW Network Module | 1G multimode links on 9300 |
| FPR9K-NM-6X1SX-F= | Spare version | Field replacement stock |
Rack mounts, spare fans, power supplies, and solid-state drives are identified as accessory categories. The source does not provide accessory part numbers.
Environmental and physical planning
The supplied specification does not provide MTBF values, operating temperature ranges, storage temperature ranges, humidity limits, altitude limits, acoustic noise levels, appliance dimensions, rack-unit height for every family, weight, power consumption, power supply ratings, or heat dissipation.
The 4100 appliance descriptions explicitly identify a 1RU form factor and two network module bays. The source does not provide equivalent physical dimensions for the other families. PoE support and PoE power budgets are not specified. These platforms are threat appliances rather than documented PoE access switches, so PoE should not be included in a bill of materials or design assumption without separate confirmation.
Engineering acceptance criteria should therefore include:
- Rack depth and mounting hardware verification.
- Available rack units and front-to-back airflow requirements.
- Dual-power and circuit requirements.
- Thermal load and cooling review.
- Acoustic limits for office or edge locations.
- Operating and storage environmental limits.
- MTBF and replacement planning.
- Optic and transceiver compatibility.
- Spare fan, power supply, and SSD requirements.
These values must be obtained from the applicable hardware installation guide or ordering documentation before site approval.
Licensing, management, and support
Firepower NGIPS is sold with Cisco Smart Licensing. Smart Licensing provides a centralized view of software, licenses, and devices. Licenses can be registered and activated through the licensing system and shifted between like hardware platforms.
Application Visibility and Control is included in the base product. Advanced Malware Protection for Networks and URL Filtering are optional licenses. The platform can be managed centrally through Firepower Management Center, which provides policy configuration, logging, monitoring, reporting, and event collection across supported Firepower deployments.
Cisco Smart Net Total Care provides round-the-clock access to Cisco Technical Assistance Center engineers and online technical resources. Hardware replacement options include two-hour, four-hour, next-business-day advance replacement, and Return For Repair. Support also includes operating system software updates within the licensed feature set. Smart Call Home provides proactive diagnostics and real-time alerts on selected devices. Onsite service can provide a field engineer to install replacement parts.
Warranty and services
Cisco hardware and software products are covered by a minimum warranty period of 90 days. Some products have longer warranty terms. The exact Firepower NGIPS warranty depends on the applicable product and warranty listing.
Additional service programs are available for network investment protection, operational optimization, deployment support, and lifecycle assistance. Cisco Capital provides financing options for hardware, software, services, and complementary equipment.