
Product overview
A fully operational next-generation firewall platform under the Adaptive Security Appliance (ASA) software image, the Cisco Firepower 1120 ASA (FPR1120-ASA-K9) is a small, next-generation firewall platform. It is optimized to run secure internet edge or high performance branch deployments requiring high stateful firewalling, site to site and remote access VPN as well as simple policy control, without the complexity of a full NGFW stack. Its whopping small size, low acoustic noise and power consumption ensure that it can fit in wiring closets or office racks.
The 1120 is based on Cisco Firepower hardware, version 1100 and it provides a high level of interface flexibility of the WAN, LAN, and DMZ segments together with the responsive packet handling of high-traffic sites. You have proven ASA functionality, such as object-based policies, enhanced NAT, high-availability, and the rich logging/monitoring features, as well as, simplified zero-touch onboarding and current APIs to connect to your existing management operations.
Key features
-
ASA firewall services are enterprise-class with easy to understand object-based policies.
-
Flexible VPN site-to-site IPsec, and remote-access (IKEv2/AnyConnect-ready) Flexible VPN.
-
Support that is high-availability (active/standby) to facilitate seamless failover.
-
Silent, small desktop/rack-mountable low-power consumption appliance.
-
Eight copper Giga ports with SFP uplink flexibility in case of WAN/metro hand off.
-
Separate users, servers, and IoT with advanced NAT, VLANs, and virtual interfaces.
-
The compatibility of centralized management and API/automation support.
-
Quick and reliable packet processing performance under load with hardware-acceleration.
Technical specifications
|
Category |
Details |
|
Model |
FPR1120-ASA-K9 |
|
Platform |
Cisco Firepower 1120 running the ASA software image |
|
Performance class |
Stateful firewall throughput suitable for high-performance branches and small/medium internet edges (class-leading within the 1100 family tier) |
|
VPN capabilities |
Site-to-site IPsec and remote-access VPN (license/config dependent) |
|
Interfaces |
8 × 1G RJ-45 data ports, 1 × 1G SFP slot (uplink flexibility); console and management ports |
|
Switching/routing |
Layer 3 routed firewall with sub-interfaces, static/dynamic routing (protocol support per ASA image) |
|
High availability |
Active/standby failover (optional, license/config dependent) |
|
Segmentation |
VLANs, security zones, policy-based segmentation, multiple contexts (model/license dependent) |
|
NAT |
Dynamic/static PAT/NAT, policy-based NAT, dual-ISP designs |
|
Security features |
Stateful inspection, ACLs/objects, zone policies, identity options, logging and eventing |
|
Management |
Local CLI/GUI, centralized manager compatibility, RESTful APIs, zero-touch provisioning options |
|
Form factor |
Compact desktop appliance; rack-mount kit option |
|
Power |
AC power supply; low typical consumption suitable for office closets |
|
Cooling |
Quiet, fan-assisted cooling |
|
Operating environment |
Standard office/IT closet temperature and humidity ranges |
|
Typical use cases |
Branch internet edge, SD-WAN underlay security, small DC/DMZ firewall, VPN hub/spoke termination |