ASA 5585-X with SSP10

ASA 5585-X with SSP20

ASA 5585-X with SSP40

ASA 5585-X with SSP60

ASA Services Module

Expand all

Stateful Inspection throughput (max1)4 Gbps10 Gbps20 Gbps40 Gbps20 Gbps
Stateful Inspection throughput (multiprotocol2)2 Gbps5 Gbps10 Gbps20 Gbps16 Gbps
Next-Generation throughput3(multiprotocol)2 Gbps5 GbpsNot availableNot availableNot available
(with ASA CX SSP-10)(with ASA CX SSP-20)
IPS throughput4(multiprotocol)2 Gbps3 Gbps5 Gbps10 GbpsNot available
(with IPS SSP-10)(with IPS SSP-20)(with IPS SSP-40)(with IPS SSP-60)
Concurrent sessions1000000200000040000001000000010000000
Connections per second50000125000200000350000300000
Packets per second (64 byte)15000003000000500000090000005000000
3DES/AES VPN throughput51 Gbps2 Gbps3 Gbps5 Gbps2 Gbps
Site-to-site and IPsec IKEv1 client VPN user sessions500010000100001000010000
AnyConnect or clientless VPN user sessions500010000100001000010000
Cisco Cloud Web Security users75007500750075007500
Integtrated I/O8-port 10/100/1000 and 2-port 10 GE (SFP+)68-port 10/100/1000 and 2-port 10 GE (SFP+)66-port 10/100/1000 and 4-port 10 GE (SFP+)6-port 10/100/1000 and 4-port 10 GE (SFP+)Provided by the switch or router
Expansion I/O78-port 10 GE(SFP/SFP+) or Provided by the switch or router
4-port 10 GE(SFP/SFP+) or
20-port 1 GE (12-port 1 GE SFP and 8-port 10/100/100)
Dual power suppliesYesYesYesYesYes. Provided by the switch or router
High-availability support810241024102410241000
PowerACACACACAC/DC provided by the switch or router

1 Maximum throughput with UDP traffic measured under ideal test conditions
2 Multiprotocol = Traffic profile consisting primarily of TCP-based protocols/applications like HTTP, SMTP, FTP, IMAPv4, BitTorrent, and DNS.
3Throughput was measured using ASA CX Software Release 9.1.1 with multi-protocol traffic profile with both Application Visibility Control (AVC) and Web Security Essentials (WSE). Traffic logging was enabled as well.
4 Firewall traffic that does not go through IPS SSP module can have higher throughput.
5 VPN throughput and sessions count depend on the ASA device configuration and VPN traffic patterns. These elements should be taken into consideration as part of your capacity planning.
6 Requires a separate license 
7 Half-width modules
8 A/A = Active/Active; A/S = Active/Standby