Cisco Adaptive Security Appliance Software Version (latest)
8.4
8.4
8.4
8.4
8.4
8.4
Application-Layer Firewall Services
Yes
Yes
Yes
Yes
Yes
Yes
Layer 2 Transparent Firewalling
Yes
Yes
Yes
Yes
Yes
Yes
Security Contexts (included/maximum3)
2/250
2/250
2/100
2/250
2/250
2/250
GTP/GPRS Inspection3
Yes
Yes
Yes
Yes
Yes
Yes
High-Availability Support4
A/A and A/S
A/A and A/S
A/A and A/S
A/A and A/S
A/A and A/S
A/A and A/S
SSL and IPsec VPN Services
Yes
Yes
Yes
Yes
Yes
Yes
VPN Clustering and Load Balancing
Yes
Yes
Yes
Yes
Yes
Yes
Advanced Endpoint Assessment3
Yes
Yes
Yes
Yes
Yes
Yes
1 Maximum throughput measured under ideal test conditions 2 VPN throughput and sessions count depend on the ASA device configuration and VPN traffic patterns. These elements should be taken in to consideration as part of your capacity planning. 3 Licensed features 4 A/S = Active/Standby; A/A = Active/Active
Cisco ASA 5500 Series Model/License
Cisco ASA 5505 Base /
Security Plus
Cisco ASA 5510 Base /
Security Plus
Cisco ASA 5520
Cisco ASA 5540
Cisco ASA 5550
Product Image
(click to enlarge)
Network Location
Small Business, Branch Office, Enterprise Teleworker
Internet Edge
Internet Edge
Internet Edge
Internet Edge, Campus
Performance Summary
Maximum Firewall throughput
150 Mbps
300 Mbps
450 Mbps
650 Mbps
1.2 Gbps
Maximum Firewall Connections
10,000 /
25,000
50,000 /
130,000
280,000
400,000
650,000
Maximum Firewall Connections/Second
4000
9000
12,000
25,000
33,000
Packets Per Second (64 byte)
85,000
190,000
320,000
500,000
600,000
Maximum 3DES/AES VPN Throughput
100 Mbps
170 Mbps
225 Mbps
325 Mbps
425 Mbps
Maximum Site-to-Site and IPsec IKEv1 Client VPN User Sessions
10 /25
250
750
5000
5000
Maximum AnyConnect or Clientless VPN User Sessions
25
250
750
2500
5000
Bundled SSL VPN User Session
2
2
2
2
2
Technical Summary
Memory
512 MB
1 GB
2 GB
2 GB
4 GB
Minimum System Flash
128 MB
256 MB
256 MB
256 MB
256 MB
Integrated Ports
8 port 10/100 switch with 2 Power over Ethernet (PoE) ports
1 Licensed features 2 A/S = Active/Standby; A/A = Active/Active 3 Two regular zones and one restricted zone that can only communicate with one other zone