The Cisco Secure Firewall 220 is a compact, fanless branch firewall designed for distributed enterprises and small branch locations. It provides fixed Gigabit Ethernet connectivity, next-generation firewall capabilities with Cisco Firewall Threat Defense software, higher stateful inspection throughput with Cisco Adaptive Security Appliance software, active/standby high availability, integrated VPN functions, and centralized management options for hybrid mesh firewall deployments.

Product Positioning

The Secure Firewall 220 is intended for branch-edge and distributed-enterprise deployments where the firewall must combine security inspection, VPN connectivity, application control, segmentation, and simplified operations in a small desktop-sized chassis.

The platform is the first model in the Secure Firewall 200 Series. It is available with either:

  • Cisco Firewall Threat Defense software, identified by SKU CSF220-TD-K9
  • Cisco Adaptive Security Appliance software, identified by SKU CSF220-ASA-K9

The software choice is a primary design decision. FTD provides the next-generation security feature set, including Application Visibility and Control, Intrusion Prevention System functions, encrypted traffic visibility, Snort 3 IPS, SnortML exploit detection, and integrated SD-WAN capabilities. ASA provides higher reported stateful firewall throughput and higher connection establishment rates, but the datasheet does not identify the advanced FTD inspection functions as part of the ASA performance profile.

The appliance is suitable for locations that need:

  • A compact branch firewall with no fan noise
  • Up to 1.5 Gbps of reported FTD next-generation firewall throughput
  • Up to 2 Gbps of reported ASA stateful firewall throughput
  • One Gigabit SFP interface for optical or supported transceiver connectivity
  • Active/standby high availability
  • Local management and console access
  • Centralized management across large numbers of distributed firewalls
  • Integration with Cisco security, access, endpoint, and SD-WAN services

The appliance does not provide Power over Ethernet, network module expansion, multi-instance deployment, clustering, ASA security contexts, or redundant power supplies.

Software Selection: FTD or ASA

Cisco Firewall Threat Defense

FTD is the appropriate choice when the design requires next-generation firewall inspection rather than stateful inspection alone. The reported FTD performance remains 1.5 Gbps for each of the following profiles:

FTD performance profile Reported throughput
Firewall plus Application Visibility and Control, 1024-byte traffic 1.5 Gbps
Application Visibility and Control plus IPS, 1024-byte traffic 1.5 Gbps
Firewall plus Application Visibility and Control plus IPS, 1024-byte traffic 1.5 Gbps
IPsec VPN, 1024-byte TCP with Fastpath 1.2 Gbps
TLS decryption 0.7 Gbps

FTD Application Visibility and Control provides standard support for more than 8100 applications, along with geolocations, users, and websites.

The FTD scalability limits are:

  • 30,000 maximum concurrent sessions with AVC
  • 6,000 maximum new connections per second with AVC
  • 50 maximum VPN peers
  • Five maximum virtual router instances using VRF
  • Active/standby high availability
  • Multi-instance deployment not supported
  • Clustering not supported

FTD also supports the AI-powered Encrypted Visibility Engine for visibility into encrypted traffic, including TLS 1.3, without requiring traffic decryption. SnortML is integrated with Snort 3 IPS for machine-learning-based exploit detection.

Cisco Adaptive Security Appliance

ASA is appropriate where the priority is stateful firewall throughput, high connection establishment rates, or an existing ASA operational model. Reported ASA performance is:

ASA performance profile Reported throughput
Stateful inspection firewall, 1500-byte UDP 2 Gbps
Stateful inspection firewall, HTTP 1024-byte traffic 2 Gbps
IPsec VPN, 450-byte UDP site-to-site test 1.8 Gbps

ASA scalability is:

  • 80,000 new connections per second
  • 100,000 concurrent firewall connections
  • 50 maximum VPN peers
  • Active/standby high availability
  • Security contexts not supported
  • Clustering not supported

The ASA figures should not be directly compared with the FTD NGFW figures as equivalent workloads. The traffic protocols, packet sizes, enabled features, and test conditions differ. A proposal should identify the intended software, inspection profile, VPN use, traffic mix, and connection behavior before selecting a performance figure.

Security and Management Capabilities

The platform extends Cisco hybrid mesh firewall architecture to branch locations. The 1G SFP interface provides a connectivity option for branch uplinks and hybrid mesh integration. The system-on-chip architecture accelerates network and cryptographic operations inline.

FTD deployments can use the following capabilities:

  • Application Visibility and Control for applications, users, websites, and geolocations
  • Snort 3 Intrusion Prevention System
  • SnortML exploit detection
  • Encrypted Visibility Engine for encrypted traffic analysis
  • Cisco Umbrella integration
  • Cisco Secure Access integration
  • Cisco Endpoint Security integration
  • Integrated SD-WAN capabilities
  • Zero-Touch Provisioning
  • Active/standby high availability
  • Centralized logging and event viewing
  • AIOps-based telemetry analysis and policy recommendations

Security Cloud Control Firewall Manager is described as supporting management of up to 1,500 firewalls, with scaling to 2,000. The management model is optimized for hybrid mesh firewall and managed security service provider environments. Prebuilt templates and migration tools are available for consistent deployment across distributed locations.

A presales design should separate appliance capacity from management scale. The 1,500-to-2,000 firewall management figures describe centralized management scope, not the number of local sessions, VPN peers, interfaces, or security policies supported by an individual Secure Firewall 220.

Connectivity and Interface Design

The fixed interface configuration is:

Interface type Quantity Expansion Total maximum
1000BASE-T data ports 4 None 4
1 Gigabit SFP 1 None 1
1000BASE-T management port 1 None 1

The chassis has no network module slots despite the interface table referencing two expansion positions; the hardware specification identifies network modules as not applicable and lists no expansion interfaces.

Additional ports and storage include:

  • USB Type-C console port
  • RJ-45 Cisco serial console port
  • USB 3 Type-A port
  • 64 GB storage

The 1G SFP port should be treated as a single Gigabit uplink or branch connectivity interface. Transceiver compatibility is not enumerated in the datasheet; the Cisco Secure Firewall 200 Hardware Installation Guide is identified as the source for supported transceivers.

There is no PoE capability. The appliance cannot directly power access points, IP phones, cameras, or other powered Ethernet devices. PoE requirements must be handled by an external switch or injector.

Interface planning rules

For presales design:

  1. Reserve the management Ethernet port for out-of-band or dedicated management where the operational model requires separation.
  2. Count the four 1000BASE-T interfaces as the complete copper data interface set.
  3. Do not plan additional ports through network modules.
  4. Do not use the appliance as a PoE source.
  5. Confirm the required SFP type and optical or copper media against the installation guide.
  6. If active/standby high availability is required, allow for a second appliance and the associated physical and logical connectivity.
  7. Do not propose clustering or multi-instance segmentation because both are listed as unsupported for FTD.
  8. Do not propose ASA security contexts because they are listed as unsupported.

Performance Sizing

The published FTD NGFW figure is 1.5 Gbps with firewall, AVC, and IPS enabled using 1024-byte traffic. The FTD VPN figure is 1.2 Gbps under the stated TCP Fastpath test. TLS decryption is reported at 0.7 Gbps using a test profile with 50 percent TLS 1.2 traffic, AES256-SHA, and RSA 2048-bit keys.

These values are not universal traffic guarantees. The datasheet states that performance varies with activated features, traffic protocol mix, and packet size characteristics. Performance may also change with software releases.

A sizing exercise should therefore document:

  • Expected aggregate traffic rate
  • Internet and inter-site VPN traffic separately
  • Proportion of encrypted traffic
  • Whether TLS decryption is required
  • IPS policy scope
  • Application control requirements
  • Average packet size
  • New connection rate
  • Concurrent session count
  • High-availability requirements
  • Growth allowance

For an FTD proposal, the 1.5 Gbps NGFW figure should be treated as the relevant reference only when the traffic profile resembles the published test conditions. The 0.7 Gbps TLS decryption figure must be used when decrypted inspection is part of the requirement. The 1.2 Gbps IPsec value should be used for VPN sizing rather than the general firewall figure.

For an ASA proposal, use the stateful inspection and ASA VPN figures only for the corresponding traffic models. The 2 Gbps stateful inspection values and 1.8 Gbps VPN value are not substitutes for FTD NGFW or TLS decryption capacity.

High Availability and Resilience

The Secure Firewall 220 supports active/standby high availability with both FTD and ASA software. High availability requires two appliances and should be considered when the branch cannot tolerate a single-device outage.

The appliance uses a single external AC power supply. Power supply redundancy is not supported. A high-availability pair improves firewall service continuity, but it does not create redundant power supplies within either chassis.

There is no clustering support for either software profile. FTD also does not support multi-instance deployments, and ASA does not support security contexts. These limitations make the appliance suitable for single-tenant or straightforward branch segmentation designs rather than dense virtualized firewall consolidation.

Physical and Environmental Specifications

The Secure Firewall 220 is a compact desktop appliance with passive cooling. It can be placed on a desktop, and rackmount and wall-mount accessories are available. The chassis is also identified as rack-mountable.

Physical specification Value
Dimensions, H x W x D 1.15 x 9.2 x 7.8 inches
Dimensions, metric 2.9 x 23.4 x 19.8 cm
Weight 2.6 lb, 1.17 kg
Cooling Passive, fanless
Acoustic noise 0 dBA
MTBF 700,000 hours
Rack mountable Yes
Desktop placement Supported
Wall-mount accessories Available
Storage 64 GB

The fanless design is relevant for quiet branch offices, retail environments, classrooms, clinics, and other locations where audible equipment noise is undesirable. Passive cooling does not remove the need for airflow clearance. Installation planning should avoid enclosed spaces that could exceed the stated operating temperature.

Power

The power configuration is a single external 30 W AC power supply.

Power specification Value
AC input voltage 100-240V AC
AC input frequency 50-60 Hz
Maximum AC current draw 1.0 A
Typical power consumption 12.7 W
Maximum power consumption 19 W
Power redundancy N/A

The 30 W supply rating and maximum reported appliance consumption should be considered when planning UPS capacity, branch power budgets, and cabinet thermal load. The appliance does not include redundant power input.

Operating environment

Environmental condition Operating Non-operating or storage
Temperature 32 to 104 degrees F, 0 to 40 degrees C -13 to 158 degrees F, -25 to 70 degrees C
Humidity 5% to 85%, noncondensing 5% to 95%, noncondensing
Altitude Up to 10,000 ft, 3048 m 0 to 15,000 ft, 4570 m
Acoustic noise 0 dBA Not specified

The operating limits apply to the installation environment. High-altitude deployments should be checked against the stated operating altitude limit. Storage conditions must not be used as operating limits.

Compliance

The appliance is identified as compliant with CE marking requirements under the directives listed in the datasheet. Safety standards include:

  • UL 60950-1
  • UL 62368-1
  • CAN/CSA-C22.2 No. 62368-1
  • EN 62368-1
  • IEC 62368-1
  • AS/NZS 62368-1

Listed electromagnetic compatibility emissions standards include:

  • FCC Class A under 47CFR Part 15
  • AS/NZS CISPR 32 Class A
  • CISPR 32 Class A
  • EN55032 Class A
  • ICES003 Class A
  • VCCI Class A
  • EN61000-3-2
  • EN61000-3-3
  • KS C 9832 Class A
  • CNS15936 Class A
  • EN300386
  • QCVN 118:2018

Listed immunity standards include EN55035, CISPR 35, EN300386, KS C 9835, QCVN 18:2022, EN61000-3-2/-3, and the EN61000-4 series covering electrostatic discharge, radiated and conducted disturbances, fast transients, surge, immunity to conducted disturbances, power-frequency magnetic fields, and voltage dips or interruptions.

Market-specific regulatory approval should be checked through the applicable product approvals process before shipment or installation.

Ordering Matrix

Product ID Software Description Best For
CSF220-ASA-K9 Cisco Adaptive Security Appliance Secure Firewall 220 appliance with ASA software Branches requiring stateful firewall operation, higher reported connection rates, ASA operational continuity, and up to 2 Gbps reported stateful inspection throughput
CSF220-TD-K9 Cisco Firewall Threat Defense Secure Firewall 220 appliance with Threat Defense software Branches requiring NGFW inspection, AVC, IPS, Snort 3, SnortML, encrypted traffic visibility, SD-WAN integration, and centralized FTD management

Licenses, subscriptions, and other associated options are handled through the Cisco Network Security Ordering Guide. The appliance SKU alone should not be assumed to include every software entitlement or service option required for deployment.

Warranty and Service Planning

The supplied datasheet does not specify warranty duration, hardware replacement terms, technical support coverage, software entitlement period, response targets, advance replacement conditions, or service-level options. These items must be selected and validated separately during quoting.

For a complete proposal, document:

  • Hardware warranty coverage
  • Software support entitlement
  • Technical assistance access
  • Hardware replacement process
  • Required response or replacement targets
  • Software update and maintenance rights
  • High-availability pair coverage
  • Transceiver and accessory coverage
  • Central management licensing
  • Subscription requirements for security services

Do not treat the published MTBF as a warranty period or service-level commitment. MTBF is a reliability metric and does not define replacement timing, support availability, or guaranteed uptime.

Sustainability and Deployment Considerations

The product sustainability references cover material-content regulations and electronic-waste compliance, including products, batteries, and packaging. Packaging information may change and should be checked through the applicable Cisco sustainability resources when environmental reporting or disposal documentation is required.

For deployment, the key operational characteristics are low power consumption, passive cooling, compact dimensions, and zero acoustic noise. These characteristics support desktop and branch installations, but the site still requires suitable AC power, environmental control, physical protection, network cabling, and a support model aligned with the selected software.