The New Cisco ASA 5506-X, More Comparisons

The New Cisco ASA 5506-X, More Comparisons

What’s the ASA 5506-X? Yes, it’s also the part of the ASA 5500-X of next-generation mid-range ASAs and is built on the same security platform as the rest of the ASA family. The new ASA 5506-X and the ASA 5508-X, both of them are with FirePOWER and gigabit ports. It’s an awesome firewall for your home. It will probably become the successors of the ASA5505. Will the new Cisco ASA 5506-X replace ASA 5505? Let’s have a look some comparisons among the ASA 5500-X series.

The following table shows the next-generation firewall capabilities and capacities of the Cisco ASA with FirePOWER Services for Cisco ASA 5506-X, 5512-X and 5515-X Models.

Cisco ASA Models

From left to right: ASA 5505/Security Plus, ASA 5506-X/Security Plus, ASA 5512-X/ Security Plus and ASA 5515-X

Cisco ASA Model

ASA 5505 / Security PlusASA 5506-X / Security PlusASA 5512-X / Security PlusASA 5515-X
Stateful Inspection throughput (max1)Up to 150 Mbps750 Mbps1 Gbps1.2 Gbps
Stateful Inspection throughput (multiprotocol2)300 Mbps500 Mbps600 Mbps
Maximum application control (AVC) throughput250 Mbps300 Mbps500 Mbps
Maximum AVC and NGIPS throughput125 Mbps150 Mbps250 Mbps
Maximum Concurrent sessions10,000 /25,00020,000/50,000100,000250,000
Maximum new Connections per second4,0005,00010,00015,000
Application control (AVC)
or
NGIPS sizing throughput [440 byte HTTP]3
90 Mbps100 Mbps150 Mbps
Packets per second (64 byte)85,000246,900450,000500,000
Maximum 3DES/AES VPN throughput4100 Mbps100 Mbps200 Mbps250 Mbps
Maximum Site-to-site and IPsec IKEv1 client VPN user sessions4(requires Security Plus license)10/2510 / 50250250
Maximum Cisco AnyConnect®or Clientless VPN User Sessions5 (AnyConnect/Apex license required)252 / 50250250
Cisco Cloud Web Security users252752,0003,000
VLANs3 (trunking disabled) / 20 (trunking enabled)5 / 5050 / 100100
High-availability support6Stateless Active/Standby Only*A/S*Active/Active* and Active/Standby*A/A and A/S
Integrated I/O8-port FE with 2 Power over Ethernet (PoE) ports8 x 1 Gigabit Ethernet (GE)6-port 10/100/10006-port 10/100/1000
Expansion I/ONot availableNot available6-port 10/100/1000 or 6-port GE (SFP)6-port 10/100/1000 or 6-port GE (SFP)
Dual power suppliesNot availableNot availableNot availableNot available
PowerAC/DCAC onlyAC/DCAC/DC

1 Maximum throughput with UDP traffic measured under ideal test conditions
2 Multiprotocol = Traffic profile consisting primarily of TCP-based protocols/applications like HTTP, SMTP, FTP, IMAPv4, BitTorrent, and DNS
3Activating more features will change performance
4 VPN throughput and maximum sessions depend on the ASA device configuration and VPN traffic patterns, including average packet size. These elements should be taken into consideration as part of your capacity planning. Throughput represents the maximum possible IPsec throughput. Maximum users may be further limited by your throughput requirements.
5 Requires AnyConnect Plus/Apex license. Apex license required for clientless VPN. See the AnyConnect Ordering Guide for details. Maximum users may be further limited by your throughput requirements.
6 A/A = Active/Active; A/S = Active/Standby
* requires security plus license

 

More Comparison: the Cisco ASA with FirePOWER Services for Cisco ASA 5500-X Series

FeatureASA 5506-XASA 5512-XASA 5515-XASA 5525-XASA 5545-XASA 5555-X
Maximum application control (AVC) throughput250 Mbps300 Mbps500 Mbps1100 Mbps1500 Mbps1750 Mbps
Maximum AVC and IPS throughput125 Mbps300 Mbps250 Mbps650 Mbps1000 Mbps1250 Mbps
Maximum concurrent sessions20,000;
500001
100,000250,000500,000750,0001,000,000
Maximum new connections per second5,00010,00015,00020,00030,00050,000
AVC or IPS sizing throughput [440-byte HTTP]290 Mbps100 Mbps150 Mbps375 Mbps575 Mbps725 Mbps
Supported applicationsMore than 3000
URL categories80+
Number of URLs categorizedMore than 280 million
Centralized configuration, logging, monitoring, and reportingMultidevice Cisco Security Manager and Cisco FireSIGHT Management Center

1Higher specifications are associated with the Security Plus license.

2Activating more features will change performance.

What’s the exact Cisco ASA 5506-X after you read the main info and comparisons of the new Cisco ASA 5500-X model? We will tell you in the next article…

 

More Related Cisco ASA Topics

What are the Considerations While Buying a Cisco Next-Generation Firewall?

Cisco ASA 5500-X Series’ New Features & Main Model Comparison

Does Cisco ASA 5500-X Series Support Both IPS and AVC/WSE in One Box?

ASA 5505 vs. ASA 5510 vs. ASA 5512-X vs. ASA 5515-X

Share This Post

Post Comment