Guide to the New Cisco Firepower 2100 Series

The Cisco Firepower 2100 series security appliance includes the Firepower 2110, 2120, 2130, and 2140.

Firepower 2110/2120 and Firepower 2130/2140

Cisco Firepower 2100 Series Features

The following table lists the features for the Firepower 2100 series.

Compare Features of Firepower 2110, 2120, 2130, and 2140

Feature 2110 2120 2130 2140
Form factor 1 RU (fits standard 19-in. (48.3-cm) square-hole rack)
Rack mountable Yes

2 two-post mount brackets

(Optional) 4-post EIA-310-D rack

Yes

4-post EIA-310-D rack

(Optional) 2-two-post mount brackets

Airflow Front to rear (cold aisle to hot aisle)
Intel x86 processor Single 4-core at 1.8G Single 6-core at 1.9G Single 8-core at 2.0G Single 16-core at 1.3G
Intel x86 memory 16 GB 32 GB 64 GB
Cavium Network Processor Unit (NPU) Single 6-core at 1.2G Single 8-core at 1.2G Single 12-core at 1.2G Single 16-core at 1.8G
Cavium NPU RAM 8G 16G
Flash 8G (nominal)
Maximum number of interfaces 16 24
Management port 1 Gigabit Ethernet (10M/100M/1G Base-T)
Console port RJ-45 serial port
USB port Type A 2.0 (500mA)
Network ports 12 fixed RJ-45 1G/100M/10M ports (named Ethernet 1/1 through 1/12 )
Small Form-Factor Pluggable (SFP) ports 4 fixed 1G SFP ports 4 fixed 1G/10G SFP+ ports
Pullout label card Yes (displays serial number)
Grounding lug Yes
Locator beacon Yes
Power switch Yes
Network modules No 1 network module slot

Not hot swappable

AC power supply 1 fixed AC power supply module 2 power supply slots

Ships with one 400W AC power supply

Hot swappable

2 power supply slots

Ships with two 400W AC power supplies

Hot swappable

DC power supply No Yes (optional)
Redundant power No Yes
Fan 4 fixed fans 1 hot-swappable fan tray with 4 fans
Storage 2 SSD slots (100GB )

Ships with one 100GB SSD installed in slot 1. The second slot is reserved for the MSP SSD.

2 SSD slots (200GB )

Ships with one 200GB SSD installed in slot 1. The second slot is reserved for the MSP SSD.

Malware Storage Pack (MSP) Yes (installed in SSD slot 2)
Cisco Firepower 2100 Series-Deployment Options

You can deploy the Firepower 2100 in the following ways:

  • As a firewall:
    • At the enterprise Internet edge deployed in a high availability configuration
    • At branch offices in either an HA pair or standalone
  • As a device that provides additional application control, URL filtering, or IPS/threat-centric capabilities:
    • Behind an enterprise Internet edge firewall in an inline in a transparent bump-in-the-wire configuration or as a standalone (requires hardware fail open network module support)
    • Deployed passively off a SPAN port on a switch or a tap on a network, or standalone
  • As a VPN device:
    • For remote access VPN
    • For site-to-site VPN
Supported SFP/SFP+ Transceivers

First of all you should take note of the following warnings:

  • Warning: Statement 1053—Class 1M Laser Radiation; Class 1M laser radiation when open. Do not view directly with optical instruments.
  • Warning: Statement 1055—Class I and Class 1M Laser; Class I (CDRH) and Class 1M (IEC) laser products.
  • Warning: Statement 1056—Unterminated Fiber Cable

Invisible laser radiation may be emitted from the end of the unterminated fiber cable or connector. Do not view directly with optical instruments. Viewing the laser output with certain optical instruments (for example, eye loupes, magnifiers, and microscopes) within a distance of 100 mm may pose an eye hazard.

  • Warning: Statement 1057—Hazardous Radiation Exposure

Use of controls or adjustments or performance of procedures other than those specified may result in hazardous radiation exposure.

The SFP/SFP+ transceiver is a bidirectional device with a transmitter and receiver in the same physical package. It is a hot-swappable optical or electrical (copper) interface that plugs into the SFP/SFP+ ports on the fixed ports and the network module ports, and provides Ethernet connectivity.

SFP

1 Dust plug 2 Bail clasp
3 Receive optical bore 4 Transmit optical bore
  1. Warning: Use appropriate ESD procedures when inserting the transceiver. Avoid touching the contacts at the rear, and keep the contacts and ports free of dust and dirt. Keep unused transceivers in the ESD packing that they were shipped in.
  2. Note: The 1G transceivers are limited to 1GB operation only (no auto-negotiation support). 100M/10M modes are not supported.
  3. Caution: Although non-Cisco SFPs are allowed, we do not recommend using them because they have not been tested and validated by Cisco. Cisco TAC may refuse support for any interoperability problems that result from using an untested third-party SFP transceiver.
Supported SFPs

The following table lists the supported transceivers.

Optics Type
PID
Ports Supported
SFP 1G
1G-SX GLC-SX-MMD Ports 13 through 16

Ports 1 though 8 of the 8X10G network module (available only on the 2130 and 2140)

1G-LH GLC-LH-SMD
1G-EX GLC-EX-SMD
1G-ZX GLC-ZX-SMD
1G 1000Base-T GLC-T
1G 1000Base-T GLC-TE
SFP+ 10G
10G-SR SFP-10G-SR Ports 13 through 16

Ports 1 though 8 of the 8X10G network module (available only on the 2130 and 2140)

10G-LR SFP-10G-LR
10G-LRM SFP-10G-LRM
10G-ER SFP-10G-ER
10G-SR-S SFP-10G-SR-S
10G-LR-S SFP-10G-LR-S
10G-ZR-S SFP-10G-ZR-S
10G-ER-S SFP-10G-ER-S
H10GB-CU 1M, 1.5M, 2M, 2.5M, 3M, 5M SFP-H10GB-CU1M

SFP-H10GB-CU1-5M

SFP-H10GB-CU2M

SFP-H10GB-CU2-5

SFP-H10GB-CU3M

SFP-H10GB-CU5M

H10GB-ACU 7M, 10M SFP-H10GB-ACU7M

SFP-H10GB-ACU10M

10G-AOC 1M, 2M, 3M, 5M, 7M, 10M SFP-10G-AOC1M

SFP-10G-AOC2M

SFP-10G-AOC3M

SFP-10G-AOC5M

SFP-10G-AOC7M

SFP-10G-AOC10M

Get the Best Prices on Cisco SFP GLC Modules

Hardware Specifications for the Firepower 2100 series

The following table contains hardware specifications for the Firepower 2100 series security appliance.

Specification
2110
2120
2130
2140
Physical
Form factor 1 RU (fits standard 19-in. (48.3-cm) square-hole rack)
Rack mountable Yes

Fixed 2-post mount brackets included

Optional: 4-post EIA-310-D mount rails

Yes

4-post EIA-31-D mount rails included

Optional: 2-post mount brackets

Dimensions (H x W x D) 1.73 x 16.90 x 19.76 in. (4.4 x 42.9 x 50.2 cm)
Weight 16.1 lb (7.3 kg) 19.4 lb (8.79 kg) 21 lb (9.52 kg)
Storage
SSD 100 GB

Note    The storage SSD must be installed in slot 1.
200 GB

Note    The storage SSD must be installed in slot 1.
MSP 800 GB

Note    The MSP SSD must be installed in slot 2.
Memory
DDR4 DRAM 16 GB 16 GB 32 GB 64 GB
Power
System power 100/240VAC 1.9A (at 100VAC), 50 to 60 Hz

Note    The power supply module is rated at 4A, but the system power is limited to 1.9A.
100/240VAC 2.9A (at 100VAC), 50 to 60 Hz

Note    The power supply module is rated at 6.3A, but the system power is limited to 2.9A.
Power supply module AC AC or DC
Redundant power supply No Yes
Environmental
Temperature Operating: 32⁰ to 104⁰F (0 to 40⁰C)

Nonoperating: -40 to 149°F (-40 to 65°C) maximum altitude is 40,000 ft

NEBS Operating altitude: 0 to 13,000 ft (3962 m)

Operating temperature:

  • Long Term: 0 to 45°C up to 6000 ft (1829 m)
  • Long Term: 0 to 35°C 6000-13000 ft (1829-3964 m)
  • Short Term: -5 to 55°C up to 6000 ft (1829 m)
Note    Firepower 2100 series NEBS Compliance applies only to the 2130.

 

Note    NEBS operation is not supported when the 8X10G (FPR-NM-8x10G) network module is installed.
Humidity Operating: 10 to 85 percent noncondensing

Nonoperating: 5 to 95 percent noncondensing

Altitude Operating: 10,000 ft maximum

Nonoperating: 40,000 ft maximum

Acoustic Noise
Sound pressure 47.3 dBA (typical)

73.4 dBA (maximum)

55.7 dBA (typical)

76.7 dBA (maximum)

Sound power 60.2 (typical)

85.1 (maximum)

66 (typical)

84.5 (maximum)

Air flow Front to back
System Cooling Requirements

Get the Best Prices on Cisco Firepower 2100 Series

More Related

Finding the Sweet Spot–Firepower 2100

The New Cisco Firepower 2100 Series

How to Deploy the Cisco ASA FirePOWER Services in the Internet Edge, VPN Scenarios and Data Center?

The Most Common NGFW Deployment Scenarios

UTM vs. NGFW

Share This Post

Post Comment