Guest

ASA 5520

ASA 5525-X

ASA 5540

ASA 5545-X

ASA 5550

ASA 5555-X

Expand all

Stateful Inspection throughput (max1)450 Mbps2 Gbps650 Mbps3 Gbps1.2 Gbps4 Gbps
Stateful Inspection throughput (multiprotocol2)-1 Gbps-1.5 Gbps-2 Gbps
Next-Generation throughput3(multiprotocol)-650 Mbps-1 Gbps-1.4 Gbps
IPS throughput4Up to 225 Mbps with AIP SSM-10; 375 Mbps with AIP SSM-20; 450 Mbps with AIP SSM-40600 MbpsUp to 500 Mbps with AIP SSM-20; 650 Mbps with AIP SSM-40900 MbpsNot Available1.3 Gbps
(Extra hardware module not required) (Extra hardware module not required) (Extra hardware module not required)
Concurrent sessions2800005000004000007500006500001000000
Connections per second120002000025000300003300050000
Packets per second (64 byte)3200007000005000009000006000001100000
3DES/AES VPN throughput5225 Mbps300 Mbps325 Mbps400 Mbps425 Mbps700 Mbps
Site-to-site and IPsec IKEv1 client VPN user sessions7507505000250050005000
AnyConnect or clientless VPN user sessions7507502500250050005000
Cisco Cloud Web Security users3005001000150020003000
VLANs150200200300400500
High-availability support6A/A and A/SA/A and A/SA/A and A/SA/A and A/SA/A and A/SA/A and A/S
Integrated I/O4-port 10/100/1000 and 1-port FE8-port 10/100/10004-port 10/100/1000 + 1-port FE8-port 10/100/10008-port 10/100/1000 + 1-port FE8-port 10/100/1000
Expansion I/O4-port 10/100/1000 or 4-port GE (SFP)6-port 10/100/1000 or 6-port GE (SFP)4-port 10/100/1000 or 4-port GE (SFP)6-port 10/100/1000 or 6-port GE (SFP)None6-port 10/100/1000 or 6-port GE (SFP)
Dual Power SuppliesNot availableNot availableNot availableNot availableNot availableYes
PowerAC/DCAC/DCAC/DCAC/DCAC/DCAC/DC

1 Maximum throughput with UDP traffic measured under ideal test conditions
2 Multiprotocol = Traffic profile consisting primarily of TCP-based protocols or applications like HTTP, SMTP, FTP, IMAPv4, BitTorrent, and DNS.
3Throughput was measured using ASA CX Software Release 9.1.1 with multi-protocol traffic profile with both Application Visibility Control (AVC) and Web Security Essentials (WSE). Traffic logging was enabled as well.
4 Firewall traffic that does not go through IPS service can have higher throughput.
5 VPN throughput and sessions count depend on the ASA device configuration and VPN traffic patterns. These elements should be taken into consideration as part of your capacity planning.
6 A/A = Active/Active; A/S = Active/Standby