Have an account?
  •   Personalized content
  •   Your products and support

Need an account?

Create an account

ASA 5505 / Security Plus

ASA 5510 / Security Plus

ASA 5512-X / Security Plus

ASA 5515-X

Expand all

Stateful Inspection throughput (max1)Up to 150 Mbps Up to 300 Mbps 1 Gbps 1.2 Gbps
Stateful Inspection throughput (multiprotocol2)--500 Mbps 600 Mbps
Next-Generation throughput3 (multiprotocol) --200 Mbps 350 Mbps
IPS throughput4 Up to 75 Mbps with AIP SSC-5 Up to 150 Mbps with AIP SSM-10; 300 Mbps with AIP SSM-20 250 Mbps (Extra hardware module not required)400 Mbps (Extra hardware module not required)
Concurrent sessions 10 ,000 / 25, 00050 ,000 / 130, 000100, 000250, 000
Connections per second 4000900010 ,00015, 000
Packets per second (64 byte) 85, 000190, 000450, 000500, 000
3DES/AES VPN throughput5 100 Mbps 170 Mbps 200 Mbps 250 Mbps
Site-to-site and IPsec IKEv1 client VPN user sessions 25250250250
AnyConnect or clientless VPN user sessions25250250250
Cisco Cloud Web Security users 2575100250
VLANs 3 (trunking disabled) / 20 (trunking enabled) 50 / 10050 / 100100
High-availability support6 Not available Not available; A/A and A/S Not available; A/A and A/S A/A and A/S
Integrated I/O 8-port FE with 2 Power over Ethernet (PoE) ports 5-port FE / 2-port 10/100/1000, 3-port FE 6-port 10/100/1000 6-port 10/100/1000
Expansion I/ONot available4-port 10/100/1000 or 4-port GE (SFP)6-port 10/100/1000 or 6-port GE (SFP)6-port 10/100/1000 or 6-port GE (SFP)
Dual power suppliesNot availableNot availableNot availableNot available
PowerAC/DCAC/DCAC/DCAC/DC

1 Maximum throughput with UDP traffic measured under ideal test conditions
2 Multiprotocol = Traffic profile consisting primarily of TCP-based protocols/applications like HTTP, SMTP, FTP, IMAPv4, BitTorrent, and DNS
3Throughput was measured using ASA CX Software Release 9.1.1 with multi-protocol traffic profile with both Application Visibility Control (AVC) and Web Security Essentials (WSE). Traffic logging was enabled as well.
4 Firewall traffic that does not go through IPS service can have higher throughput. 
5 VPN throughput and sessions count depend on the ASA device configuration and VPN traffic patterns. These elements should be taken into consideration as part of your capacity planning. 
6 A/A = Active/Active; A/S = Active/Standby