Following closely on the heals of the release of the 4Gbps IPS appliance, Cisco released the ASA5580 Firewall. It comes in two models, a 5Gbps (ASA5580-20) and a 10 Gbps model (ASA5580-40).
Now those aren't backplane speeds or pie in the sky, UDP 1500 byte packet throughput numbers with protection turned off either. Vendors marketing teams love to quote us numbers that are meaningless in the real world. The performance numbers Cisco is quoting are real world performance numbers based on a mix of various rich media traffic samples with recommended firewall protection features turned on.
More performance numbers:
Now that's light your hair on fire, raw speed! My ears are bleeding just thinking about it.
The ASA 5580 also does VPN, both IPSEC and SSLVPN. It can support up to 10,000 tunnels per box, and scales to 100,000 tunnels if you cluster 10 of them together.
How do they achieve this performance? I thought you'd never ask.
The ASA 5580 series is the first ASA to support multi-threading in both software and hardware. The hardware is cutting edge with both multi-cores and multi-processors. Also, the ASA 5580 code has been written to take advantage of this new hardware.
Cisco has definitely entered the high performance security market with a bang, perhaps even a sonic boom! 150,000 connections per second with firewall inspection enabled; it nuts, just nuts.
Jamey Heary, CCIE #7680, sits on the PCI Security Standards Council- Board of Advisors where he provides strategic and technical guidance for future PCI standards. Jamey is the author of Cisco NAC Appliance: Enforcing Host Security with Clean Access. (Check out all of Jamey Heary's books from Cisco Press.) He also has a patent pending on a new DDoS mitigation technique.
Jamey sits on several security advisory boards for Cisco Systems and is a founding member of the Colorado Healthcare InfoSec Users Group. He is an experienced speaker who is recognized as an expert in network security architecture, regulatory compliance, and routing and switching. His other certifications include CISSP, CCSP, and he is a Certified HIPAA Security Professional. He has been working in the IT field for 15 years and in IT security for 10 years. Jamey is currently a Distinguished Systems Engineer at Cisco Systems.