Cisco Firepower NGIPS is a dedicated network threat prevention platform that combines inline intrusion prevention, contextual network visibility, security intelligence, malware analysis, application control, URL filtering, and centralized policy management. The appliance family spans branch, enterprise edge, data center, private cloud, carrier, and high-performance environments, with NGIPS throughput ranging from 1.5 Gbps to 175 Gbps depending on packet size and platform.

Architecture and operating model

Firepower NGIPS continuously discovers network context, including users, applications, devices, operating systems, vulnerabilities, files, services, processes, and network behavior. This information is used to build network maps and host profiles, enrich intrusion events, and support automated security decisions.

The platform is built on Snort technology and uses vulnerability-based and anomaly-based inspection. Its security controls include:

  • IPS rules that identify and block traffic targeting known vulnerabilities.
  • IP-, URL-, and DNS-based security intelligence.
  • Advanced Malware Protection for detection, blocking, tracking, analysis, and containment.
  • Sandboxing and behavioral analysis for evasive, zero-day, and unknown threats.
  • Application Visibility and Control for more than 4000 commercial applications.
  • OpenAppID support for custom, localized, and cloud application identification.
  • URL filtering across more than 80 categories and more than 280 million categorized URLs for the 2100, 4100, and 9300 families.
  • URL filtering across more than 120 categories for the 3100 and 4200 families.
  • Automated threat feed and IPS signature updates from Cisco Talos.
  • Centralized configuration, event collection, monitoring, logging, and reporting through Firepower Management Center.
  • Open APIs for integration with third-party products.
  • Integration with Cisco Identity Services Engine for actions such as quarantine and blocking.
  • Integration with endpoint malware protection for event correlation and remediation.

The appliances can operate inline using Fail-To-Wire network modules. Fail-To-Wire design is relevant where traffic continuity is required during appliance failure or power interruption. The correct network module must be selected for the required copper, multimode fiber, single-mode fiber, and interface speed.

Security functions and presales value

Intrusion prevention

The core IPS function uses Snort-based inspection, vulnerability-focused signatures, anomaly detection, and contextual policy conditions. Security teams can prioritize events associated with exploitable weaknesses instead of treating every signature match as equally important.

Firepower NGIPS correlates intrusion events with known network vulnerabilities. It can identify attacks that are more likely to succeed and recommend security policies intended to address observed weaknesses. Indications of Compromise can correlate events from IPS, security intelligence, network malware protection, and endpoint malware protection to identify potentially compromised hosts.

Contextual awareness

The platform associates network activity with:

  • Users and directory identities.
  • Applications and custom applications.
  • Devices and operating systems.
  • Client-side applications and services.
  • Vulnerabilities and network behavior.
  • Files and detected threats.
  • Mobile devices and associated activity.

Active Directory, LDAP, and captive portal integration can associate users with IPS events. This is useful for incident investigation, user-level reporting, and policy enforcement.

Malware protection and sandboxing

Advanced Malware Protection is available as an additional capability. It addresses file-based and persistent threats through detection, tracking, containment, analysis, and remediation. Sandboxing can be deployed in the cloud or on premises and uses behavioral indicators to identify unknown or evasive content.

The platform can alert administrators when content is subsequently classified as malicious, even if the initial inspection allowed it. This supports retrospective detection and investigation of files that were not known to be malicious when first observed.

Application and URL control

Application Visibility and Control supports policy decisions for more than 4000 commercial applications. OpenAppID enables identification and control of custom, localized, and cloud applications.

URL filtering is an optional capability. For the 2100, 4100, and 9300 families, the specification identifies more than 80 categories and more than 280 million categorized URLs. For the 3100 and 4200 families, the specification identifies more than 120 categories. The datasheet does not provide a URL count for the latter group.

Performance and platform selection

Performance depends on packet size, traffic protocol mix, activated features, and software release. The 450-byte figures are lower than the 1024-byte figures and should be used when sizing traffic with smaller packets or high packet-per-second rates.

Firepower 2100, 4100, and 9300 performance

Model NGIPS throughput, 1024-byte NGIPS throughput, 450-byte Concurrent sessions New connections/sec Integrated interfaces Best For
2130 4.7 Gbps 1.5 Gbps 2M 27K 12 x 1GE RJ45, 4 x SFP+ Small enterprise edge and dedicated IPS deployments
2140 9 Gbps 3 Gbps 3M 57K 12 x 1GE RJ45, 4 x SFP+ Higher-capacity enterprise edge and aggregation
4115 27 Gbps 9 Gbps 15M 200K 8 x SFP+ Enterprise edge and data center inspection
4125 41 Gbps 15 Gbps 25M 265K 8 x SFP+ High-throughput enterprise and data center traffic
4145 55 Gbps 19 Gbps 30M 350K 8 x SFP+ Large data center and Internet-edge inspection
9300 with SM-40 57 Gbps 21 Gbps 35M 380K 8 x SFP+ Modular high-throughput environments
9300 with SM-48 66 Gbps 23 Gbps 35M 450K 8 x SFP+ Larger modular security deployments
9300 with SM-56 73 Gbps 27 Gbps 35M 490K 8 x SFP+ High-scale data center and service-provider environments
9300 with SM-56 x 3 175 Gbps 64 Gbps 60M 1.1M 8 x SFP+ Maximum listed modular throughput and session scale

The 2100 Series provides four threat-focused security platforms and supports Network Equipment Building Standards compliance. The 4100 Series consists of four platforms with maximum throughput from 12 to 24 Gbps as described in the platform overview, while the detailed table lists NGIPS performance from 9 to 55 Gbps for the 4115, 4125, and 4145 models. The 9300 is a modular, carrier-grade platform supporting flow offloading, programmatic orchestration, RESTful APIs, and optional NEBS-compliant configurations. Its stated low-latency use cases include environments requiring less than 5-microsecond offload latency.

Firepower 3100 and 4200 performance

Model NGIPS throughput, 1024-byte NGIPS throughput, 450-byte Concurrent sessions New connections/sec Integrated interfaces Best For
3105 10 Gbps 4.7 Gbps 1.5M 110K 8 x RJ45, 8 x 1/10G SFP+ Branch aggregation and midrange enterprise edge
3110 17 Gbps 7 Gbps 2M 130K 8 x RJ45, 8 x 1/10G SFP+ Enterprise edge with mixed copper and fiber
3120 21 Gbps 9.8 Gbps 4M 170K 8 x RJ45, 8 x 1/10G SFP+ Growing data center and private cloud deployments
3130 38 Gbps 15 Gbps 6M 240K 8 x RJ45, 8 x 1/10G SFP+ High-throughput data center inspection
3140 45 Gbps 19 Gbps 10M 300K 8 x RJ45, 8 x 1/10G SFP+ Upper-range 3100 deployments
4215 65 Gbps 24 Gbps 15M 350K 8 x 1/10/25G SFP+ High-capacity Internet edge
4225 80 Gbps 38 Gbps 30M 600K 8 x 1/10/25G SFP+ Data center and service-provider protection
4245 140 Gbps 71 Gbps 60M 800K 8 x 1/10/25G SFP+ Large data center and Telco service-provider networks

The 3100 Series includes five platforms with maximum throughput from 10 to 45 Gbps. The 4200 Series includes three platforms with maximum throughput from 65 to 140 Gbps. Both families support Trust Anchor Technologies for supply-chain and software-image assurance.

Fail-To-Wire and interface planning

Fail-To-Wire capacity varies by platform and module selection.

The 2100 Series supports the following maximum FTW options:

  • 8 x 1GE RJ45.
  • 6 x 1GE SX.
  • 6 x 10G SR.
  • 6 x 10G LR.

The 4100 and 9300 families support FTW modules providing:

  • 16 x 1GE RJ45.
  • 12 x 1GE SX.
  • 12 x 10G SR.
  • 12 x 10G LR.
  • 4 x 40G SR.

For the 3100 Series, FTW is not listed for the 3105, 3110, and 3120. The 3130 and 3140 support:

  • 8 x 1GE RJ45.
  • 6 x 1GE SX.
  • 6 x 10G SR.
  • 6 x 10G LR.
  • 6 x 25G SR.
  • 6 x 25G LR.

The 4200 Series supports:

  • 16 x 1GE RJ45.
  • 12 x 1GE SX.
  • 12 x 10G SR.
  • 12 x 10G LR.
  • 12 x 25G SR.
  • 12 x 25G LR.

Presales rules:

  1. Select FTW speed and optic type from the physical adjacent network devices, not only from appliance throughput.
  2. Confirm whether the deployment requires copper, multimode, or single-mode fiber.
  3. Size the appliance using the 450-byte throughput when packet rates are expected to be high.
  4. Include inspection overhead from AMP, URL filtering, application control, and logging in the capacity review.
  5. Validate the required FTW module before finalizing the appliance bundle.
  6. For high-availability designs, provision equivalent interface types and compatible module capacity on both appliances.

Ordering matrix

Appliance bundles

Part number Description Best For
FPR2130-BUN Cisco 2130 Series Appliance – Functions as Dedicated IPS Dedicated IPS at smaller enterprise edge sites
FPR2140-BUN Cisco 2140 Series Appliance – Functions as Dedicated IPS Dedicated IPS at higher-capacity enterprise edges
FPR4115-BUN Cisco Firepower 4115 NGIPS Appliance, 1RU, 2 x Network Module Bays 1RU enterprise and data center deployments
FPR4125-BUN Cisco Firepower 4125 NGIPS Appliance, 1RU, 2 x Network Module Bays Higher-throughput 1RU inspection
FPR4145-BUN Cisco Firepower 4145 NGIPS Appliance, 1RU, 2 x Network Module Bays Large-scale 1RU inspection
FPR4215-K9 Cisco 4215 Series Appliance – Functions as Dedicated IPS High-capacity edge and data center inspection
FPR4225-K9 Cisco 4225 Series Appliance – Functions as Dedicated IPS Higher session and connection scale
FPR4245-K9 Cisco 4245 Series Appliance – Functions as Dedicated IPS Maximum listed 4200 performance
FPR3105-NGFW-K9 Cisco 3105 Series Appliance – Functions as Dedicated IPS Entry 3100 deployments
FPR3110-NGFW-K9 Cisco 3110 Series Appliance – Functions as Dedicated IPS Mixed copper and fiber enterprise edge
FPR3120-NGFW-K9 Cisco 3120 Series Appliance – Functions as Dedicated IPS Midrange data center and private cloud
FPR3130-NGFW-K9 Cisco 3130 Series Appliance – Functions as Dedicated IPS High-throughput 3100 deployments
FPR3140-NGFW-K9 Cisco 3140 Series Appliance – Functions as Dedicated IPS Maximum listed 3100 performance
FPR9K-SM40-FTD-BUN Cisco Firepower 9300 SM-40 FTD Bundle Modular high-throughput environments
FPR9K-SM48-FTD-BUN Cisco Firepower 9300 SM-48 FTD Bundle Larger modular security deployments
FPR9K-SM56-FTD-BUN Cisco Firepower 9300 SM-56 FTD Bundle High-scale modular inspection

The source lists the parenthetical software identifiers FPR2140-NGFW-K9 for the FPR2130-BUN entry and FPR2140-NGFW-K9 for the FPR2140-BUN entry. These identifiers should be checked against the applicable ordering guide before quotation.

FTW network modules

Part number Description Best For
FPR2K-NM-6X10LR-F 6-port 10G LR FTW Network Module 10G single-mode inline links on 2100
FPR2K-NM-6X10LR-F= Spare version of FPR2K-NM-6X10LR-F Field replacement stock
FPR2K-NM-6X10SR-F 6-port 10G SR FTW Network Module 10G multimode inline links on 2100
FPR2K-NM-6X10SR-F= Spare version of FPR2K-NM-6X10SR-F Field replacement stock
FPR2K-NM-6X1SX-F 6-port 1G SX Fiber FTW Network Module 1G multimode inline links on 2100
FPR2K-NM-6X1SX-F= Spare version of FPR2K-NM-6X1SX-F Field replacement stock
FPR2K-NM-8X1G-F 8-port 1G Copper FTW Network Module 1G copper inline links on 2100
FPR2K-NM-8X1G-F= Spare version of FPR2K-NM-8X1G-F Field replacement stock
FPR4K-NM-2X40G-F 2-port 40G SR FTW Network Module 40G multimode links on 4100 or 9300 module family
FPR4K-NM-2X40G-F= Spare version Field replacement stock
FPR4K-NM-6X10LR-F 6-port 10G LR FTW Network Module 10G single-mode links on 4100
FPR4K-NM-6X10LR-F= Spare version Field replacement stock
FPR4K-NM-6X10SR-F 6-port 10G SR FTW Network Module 10G multimode links on 4100
FPR4K-NM-6X10SR-F= Spare version Field replacement stock
FPR4K-NM-6X1SX-F 6-port 1G SX Fiber FTW Network Module 1G multimode links on 4100
FPR4K-NM-6X1SX-F= Spare version Field replacement stock
FPR4K-NM-8X1G-F 8-port 1G Copper FTW Network Module 1G copper links on 4100
FPR4K-NM-8X1G-F= Spare version Field replacement stock
FPR4K-XNM-6X1SXF 4200 6-port 1G SX multimode FTW Netmod 1G multimode inline links on 4200
FPR4K-XNM-6X1SXF= Spare version Field replacement stock
FPR4K-XNM-6X10SRF 4200 6-port 10G SR multimode FTW Netmod 10G multimode inline links on 4200
FPR4K-XNM-6X10SRF= Spare version Field replacement stock
FPR4K-XNM-6X25SRF 4200 6-port 25G SR multimode FTW Netmod 25G multimode inline links on 4200
FPR4K-XNM-6X25SRF= Spare version Field replacement stock
FPR4K-XNM-6X25LRF 4200 6-port 25G LR single-mode FTW Netmod 25G single-mode inline links on 4200
FPR4K-XNM-6X25LRF= Spare version Field replacement stock
FPR3K-XNM-6X1SXF 3100 6-port 1G SX multimode FTW Netmod 1G multimode links on supported 3100 models
FPR3K-XNM-6X1SXF= Spare version Field replacement stock
FPR3K-XNM-6X10SRF 3100 6-port 10G SR multimode FTW Netmod 10G multimode links on supported 3100 models
FPR3K-XNM-6X10SRF= Spare version Field replacement stock
FPR3K-XNM-6X25SRF 3100 6-port 25G SR multimode FTW Netmod 25G multimode links on supported 3100 models
FPR3K-XNM-6X25SRF= Spare version Field replacement stock
FPR3K-XNM-6X25LRF 3100 6-port 25G LR single-mode FTW Netmod 25G single-mode links on supported 3100 models
FPR3K-XNM-6X25LRF= Spare version Field replacement stock
FPR9K-NM-2X40G-F 2-port 40G SR FTW Network Module 40G multimode links on 9300
FPR9K-NM-2X40G-F= Spare version Field replacement stock
FPR9K-NM-6X10LR-F 6-port 10G LR FTW Network Module 10G single-mode links on 9300
FPR9K-NM-6X10LR-F= Spare version Field replacement stock
FPR9K-NM-6X10SR-F 6-port 10G SR FTW Network Module 10G multimode links on 9300
FPR9K-NM-6X10SR-F= Spare version Field replacement stock
FPR9K-NM-6X1SX-F 6-port 1G SX Fiber FTW Network Module 1G multimode links on 9300
FPR9K-NM-6X1SX-F= Spare version Field replacement stock

Rack mounts, spare fans, power supplies, and solid-state drives are identified as accessory categories. The source does not provide accessory part numbers.

Environmental and physical planning

The supplied specification does not provide MTBF values, operating temperature ranges, storage temperature ranges, humidity limits, altitude limits, acoustic noise levels, appliance dimensions, rack-unit height for every family, weight, power consumption, power supply ratings, or heat dissipation.

The 4100 appliance descriptions explicitly identify a 1RU form factor and two network module bays. The source does not provide equivalent physical dimensions for the other families. PoE support and PoE power budgets are not specified. These platforms are threat appliances rather than documented PoE access switches, so PoE should not be included in a bill of materials or design assumption without separate confirmation.

Engineering acceptance criteria should therefore include:

  • Rack depth and mounting hardware verification.
  • Available rack units and front-to-back airflow requirements.
  • Dual-power and circuit requirements.
  • Thermal load and cooling review.
  • Acoustic limits for office or edge locations.
  • Operating and storage environmental limits.
  • MTBF and replacement planning.
  • Optic and transceiver compatibility.
  • Spare fan, power supply, and SSD requirements.

These values must be obtained from the applicable hardware installation guide or ordering documentation before site approval.

Licensing, management, and support

Firepower NGIPS is sold with Cisco Smart Licensing. Smart Licensing provides a centralized view of software, licenses, and devices. Licenses can be registered and activated through the licensing system and shifted between like hardware platforms.

Application Visibility and Control is included in the base product. Advanced Malware Protection for Networks and URL Filtering are optional licenses. The platform can be managed centrally through Firepower Management Center, which provides policy configuration, logging, monitoring, reporting, and event collection across supported Firepower deployments.

Cisco Smart Net Total Care provides round-the-clock access to Cisco Technical Assistance Center engineers and online technical resources. Hardware replacement options include two-hour, four-hour, next-business-day advance replacement, and Return For Repair. Support also includes operating system software updates within the licensed feature set. Smart Call Home provides proactive diagnostics and real-time alerts on selected devices. Onsite service can provide a field engineer to install replacement parts.

Warranty and services

Cisco hardware and software products are covered by a minimum warranty period of 90 days. Some products have longer warranty terms. The exact Firepower NGIPS warranty depends on the applicable product and warranty listing.

Additional service programs are available for network investment protection, operational optimization, deployment support, and lifecycle assistance. Cisco Capital provides financing options for hardware, software, services, and complementary equipment.