Homepage | Collection | 繁体中文
Product
没有小类
没有小类
没有小类
没有小类
没有小类
没有小类
没有小类
没有小类
H3C
没有小类
没有小类
没有小类
没有小类
没有小类
没有小类
Contact Us


Company Name:Kino Technology Limited

Website:www.kino86.com

Address :Room 312, Honghua Building, No. 1 Guangyayuan Road, Bantian Street, Longgang District, Shenzhen city, Guangdong Province, China



Contact Person:kiki

Tel :+8613040881925 

E-mail:kiki@szkiki.com

Wechat:+8613040881925

Whatspp: +8613040881925

Teams:kiki@szkiki.com





Products
 Product >> Cisco >> ALL
 
Product_Id:
72016173316
ProductName:
ASA5585-X-SSP60-K9
Specification:
Product Notes:
Product Category:
Cisco
 
   Product Description

Full English Description for Cisco ASA5585-X-SSP60-K9 (ASA 5585-X SSP-60 Security Plus Unrestricted K9 Flagship Bundle)

1. Official Short Order Description

Cisco ASA5585-X-SSP60-K9: Top-of-line flagship 2RU rack-mount modular next-generation Adaptive Security Appliance (NGFW) from Cisco ASA 5585-X series, dual high-performance SSP-60 security services processor blade with factory permanent Security Plus K9 unrestricted license, dual hot-swappable redundant AC power supplies standard. Equipped with 6 built-in 10/100/1000 Gigabit copper ports, 4 native SFP+ 10GE fiber uplink slots, one dedicated out-of-band Fast Ethernet management port, one half-width empty SSP expansion slot for optional FirePOWER NGIPS SSP or CX unified content security blades, running full ASA OS 8.x and final supported ASA OS 9.1 firmware. Built on Cisco Adaptive Security Algorithm, it delivers wire-speed stateful SPI firewall, full hardware-accelerated DES/3DES/AES IKEv1/IKEv2 IPsec/DMVPN/FlexVPN, AnyConnect Premium SSL/DTLS remote access VPN, NAT/PAT, unified communications TLS proxy, VoIP fixup inspection, multi-context virtual firewalls, and both Active/Standby & Active/Active stateful failover with native multi-chassis firewall/VPN clustering. Performance benchmarks: up to 40 Gbps jumbo frame stateful firewall throughput (20 Gbps multiprotocol HTTP traffic), 10,000,000 maximum concurrent TCP/UDP connections, 350,000 new connections per second, 5 Gbps full 3DES/AES VPN throughput, supporting 10,000 simultaneous IPsec IKE peers and 1024 logical routed VLAN interfaces. K9 license unlocks unrestricted DES/3DES/AES strong enterprise crypto, unlimited TLS proxy sessions, full multi-context segmentation and complete dual-mode high availability/clustering functions. Managed via serial console, embedded ASDM web GUI, Cisco Security Manager (CSM), Syslog and SNMPv3. Fully End-of-Sale (Aug 25, 2017) and End-of-Support (Aug 31, 2022) obsolete hardware, superseded by Firepower 4100/9300 modular next-generation firewalls.

2. Complete Detailed Product Overview

Product Line Positioning

The Cisco ASA5585-X-SSP60-K9 is the absolute flagship performance model of the entire legacy ASA 5500-X datacenter NGFW family, positioned above high-performance ASA5585-X-SSP40 mid-top chassis. Designed exclusively for tier-1 service provider central office backbone peering gateways, hyperscale multi-tenant MSP colocation boundaries, and ultra-large hyperscale enterprise multi-datacenter core security edges requiring maximum native 10GE fiber uplink density, industry-leading massive concurrent session scale, carrier-grade dual redundant power supply reliability, expandable integrated FirePOWER threat defense blades and unrestricted enterprise strong crypto capabilities.
The K9 suffix stands for factory pre-activated full Security Plus unrestricted license, eliminating all DES-only limitations of K8 base SKUs, enabling unlimited TLS proxy capacity, maximum multi-context virtual firewall segmentation, and load-balanced Active/Active failover for distributed multi-customer traffic isolation. The ASA 5585-X platform reached End-of-Sale August 25, 2017 and End-of-Support August 31, 2022; no official firmware patches, vulnerability fixes or Cisco TAC technical support are available today, replaced by modern Firepower modular NGFW platforms.

Physical Hardware & Dual Half-Width SSP Modular Architecture

Form Factor & Mechanical Specifications

  • Standard 2RU 19-inch rack-mount metal server-style chassis, heavy-duty rack rails included; optional rubber feet for standalone desktop placement
  • Dual hot-swappable redundant universal auto-switch AC power supply bays (dual 100–240V power supplies factory standard on SSP-60 SKUs), load-sharing power redundancy for carrier NEBS Level 3 compliance
  • Variable-speed intelligent redundant hot-swappable cooling fans with dynamic thermal load balancing, front-to-back airflow for telecom rack deployment
  • Front panel multi-color diagnostic LED array: Power, System Fault, SSP blade operational state, global traffic activity, VPN Tunnel status, dual PSU health, fan fault indicator
  • Integrated physical security lock slot for anti-tampering protection
  • Hardware core (SSP-60 firewall blade): Dual high-performance multi-core security processors, fixed 72 GB DDR2 SDRAM (maximum memory capacity of ASA 5585-X series), 128 GB internal compact flash storage for ASA OS, configurations and persistent event logs
  • Two independent half-width non-hot-swappable SSP expansion slots: Slot0 pre-loaded SSP-60 firewall blade, Slot1 empty for optional matching FirePOWER NGIPS SSP or CX unified content security blades (power cycle required for SSP blade replacement)
  • Dual rear USB 2.0 ports for external flash configuration backup, firmware upgrades and log offloading
  • Environmental compliance: 0°C to +40°C operating temperature, 10%–90% non-condensing humidity, altitude up to 3050m; NEBS Level 3, FCC Class A, CE, UL/CSA, FIPS 140-2 Level 1 certified

Rear Panel Fixed Port Layout

  1. 6 × Built-in 10/100/1000 Gigabit Ethernet Auto-MDI/MDIX RJ45 Copper Ports (GigabitEthernet0/0 – 0/5)
    Native copper Gigabit ports to deploy independent Inside trusted LAN, Outside untrusted WAN and multiple isolated DMZ server zones without extra I/O expansion modules
  2. 4 × SFP+ 10 Gigabit Fiber Slots (GigabitEthernet0/6 – 0/9)
    Supports SFP+ SR/LR/ER fiber transceivers for long-distance 10G backbone interconnections between datacenters or upstream carrier peering links
  3. 1 × Dedicated 10/100 Fast Ethernet Out-of-Band Management Port (Management0/0)
    Fully segregated out-of-band management interface completely isolated from production data plane traffic for secure device administration
  4. 1 × SSP Expansion Slot Bay
    Compatible field-installable matching service blades:
    • FirePOWER SSP-60: Integrated next-generation NGIPS, AVC application control, malware protection, URL filtering threat defense, NGIPS throughput up to 15 Gbps
    • CX SSP-60: Unified content security (cloud web filtering, anti-spam, antivirus, anti-malware, user-based content control, maximum licensed user capacity 10,000)
  5. RJ45 RS-232 Serial Console Port
    Out-of-band CLI management at default 9600 baud for initial bootstrap, password recovery and offline bulk configuration editing
  6. DB-15 Dedicated Inter-Chassis Stateful Failover Serial Port
    Used for real-time stateful session synchronization between redundant ASA5585-X chassis pairs to retain active VPN/NAT/UC sessions during sub-second traffic failover
  7. Dual IEC AC power input sockets for factory bundled hot-swappable redundant power supply units
  8. Multiple rear USB 2.0 storage ports for external flash archival and OS image deployment

Core Performance & K9 Security Plus Full License Capabilities

Throughput & Connection Benchmarks (SSP-60 Blade)

  • Maximum cleartext stateful firewall throughput: 20 Gbps real-world multiprotocol HTTP traffic, 40 Gbps jumbo frame UDP throughput
  • Maximum concurrent TCP/UDP connection table entries: 10,000,000
  • Maximum new connections per second: 350,000
  • Maximum 64-byte small packet forwarding rate: 9,000,000 packets per second
  • IPsec VPN throughput (hardware-accelerated full 3DES/AES): Up to 5 Gbps
  • NGIPS throughput with FirePOWER SSP-60 top-tier hardware module: Up to 15 Gbps

K9 Unrestricted License Exclusive Advantages vs ASA5585-X-SSP60-K8 Base DES License

  1. Encryption suite: Full native DES, 3DES-168, AES-128/AES-192/AES-256 strong enterprise crypto (K8 locked to DES weak encryption only)
  2. Simultaneous IPsec IKEv1/IKEv2 tunnels (site-to-site + remote access): Max 10,000 permanent peers (hard cap on K8)
  3. Logical routed VLAN interfaces: Up to 1024 separate security zones (identical hardware VLAN limit across K8/K9)
  4. TLS proxy sessions for encrypted SIP/SCCP unified communications inspection: Unlimited chassis-wide capacity (1000 hard cap on K8 base license)
  5. High Availability: Supports both stateless Active/Standby and load-balanced Active/Active multi-context failover (K8 limited to Active/Standby redundant pairs only)
  6. Multi-context virtual firewalls: Up to 250 independent isolated virtual security contexts (completely disabled on K8 DES license)
  7. Native multi-chassis firewall/VPN clustering and load balancing fully enabled for distributed carrier WAN hub aggregation
  8. AnyConnect Premium SSL/DTLS remote access peers: 2 permanent base seats, expandable via separate add-on SSL peer license packs
  9. Internal LAN host capacity: Unlimited, no hard-coded user count throttling

Full Integrated Security & Networking Feature Suite (ASA OS 8.x / 9.1 Final Supported Release)

1. Stateful Adaptive Security Algorithm Firewall

  • Wire-speed full stateful packet inspection tracking all TCP/UDP connection states to eliminate stateless filter bypass attacks
  • Object-group based inbound/outbound ACLs for granular multi-zone traffic permission/denial rule management
  • Multi-vector carrier-grade DoS/DDoS mitigation: SYN flood protection, port scan detection, full TCP normalization, malformed packet filtering, IP spoof suppression
  • Layer 7 application fixup inspection engines for FTP, H.323, SIP, SCCP Skinny, RTSP, NetBIOS, GTP/GPRS to preserve NAT traversal for VoIP and mobile carrier workloads
  • Native Transparent Layer 2 firewall mode for inline datacenter security deployment without network re-addressing
  • Third-party URL web content filtering integration (expandable via optional CX SSP unified content security blade)

2. Standards-Based Multi-Protocol VPN Suite

  • Site-to-site LAN-to-LAN IPsec tunnels for secure inter-datacenter private backbone connectivity over public internet
  • Remote access IPsec VPN for legacy Cisco VPN Client software teleworker tunnels
  • Clientless SSL VPN + AnyConnect Premium SSL/DTLS remote access for browser/software-based global mobile workforce connectivity
  • Dual IKEv1/IKEv2 key exchange protocol support, full X.509 digital certificate enrollment via SCEP for scalable multi-site carrier deployments
  • GRE tunnel encapsulation for routed non-IPsec traffic across VPN fabrics
  • Dedicated on-board hardware crypto acceleration to eliminate CPU bottlenecks for 10,000 concurrent IPsec tunnels
  • Native multi-chassis VPN clustering and load balancing for distributed regional remote access hub deployments

3. Broadband & Datacenter Routing / NAT Services

  • Static one-to-one NAT, dynamic NAT pools, PAT port address translation for multi-tenant public IP address sharing
  • Native PPPoE client for large-scale broadband ISP aggregation deployments
  • Local DHCP server supporting up to 4096 internal IP address leases for wired LAN endpoints
  • Static routing, policy-based routing (PBR), BGP, OSPF, EIGRP dynamic interior/exterior routing protocol support
  • Dual-stack native IPv4 protocol stack, limited partial IPv6 functionality on ASA OS 9.1
  • Local persistent DNS caching to reduce external DNS lookup latency and bandwidth consumption

4. Threat Defense & Unified Security Stack

  1. Base built-in signature-based IDS engine with hundreds of predefined exploit, worm and brute-force scan signatures; advanced next-generation IPS functionality requires matching optional FirePOWER SSP-60 blade
  2. Automatic dynamic host blacklisting to quarantine malicious source IP addresses after detected security breaches
  3. Unicast Reverse Path Forwarding (URPF) strict/loose anti-spoof filtering to block forged source IP traffic in multi-tenant environments
  4. Persistent local flash/HDD event logging + remote Syslog export to centralized SIEM platforms for regulatory compliance audit trails
  5. Encrypted administrative access only: SSHv2 remote CLI, HTTPS ASDM web GUI, encrypted SNMPv3 secure device monitoring

5. AAA Access Control & Audit Logging

  • Complete AAA authentication, authorization and accounting via external RADIUS and TACACS+ servers for multi-tenant segregated administrative access control
  • Local user credential database for standalone device emergency administrative login
  • Comprehensive logging architecture supporting buffered flash storage, internal hot-swappable hard drive archival and USB flash log offloading
  • SNMPv3 secure monitoring for real-time device health, throughput utilization, PSU/fan fault and VPN tunnel status alert reporting

6. Application-Aware Hierarchical QoS & Bandwidth Management

  • Four-level priority queuing to prioritize real-time voice/video unified communications over recreational streaming, SaaS and P2P file-sharing traffic
  • Per-port bandwidth shaping and policing on all Gigabit copper/10GE fiber WAN/LAN/DMZ interfaces to eliminate congestion across multi-tenant segments
  • DSCP marking preservation across IPsec and SSL VPN tunnels for consistent enterprise end-to-end QoS policy enforcement

Management & Configuration Tools

  1. ASA CLI Console: Modern full IOS-style command-line interface via serial console or encrypted SSHv2 remote access for bulk scripting and advanced troubleshooting
  2. Adaptive Security Device Manager (ASDM): Embedded HTTPS graphical web GUI for single-chassis visual configuration, real-time traffic utilization dashboards, VPN tunnel monitoring and security event reporting
  3. Cisco Security Manager (CSM): Centralized enterprise/carrier policy management platform for bulk multi-ASA deployment orchestration, mass firmware upgrades and cross-device compliance audit reporting
  4. TFTP + USB flash dual methods for OS firmware and full configuration backup/restore; offline config editing supported

Key Differentiators vs Related ASA Platforms

  1. vs ASA5585-X-SSP60-K8 Base DES License:
    • Full unrestricted 3DES/AES strong encryption suite (K8 locked to DES weak encryption only)
    • Unlimited TLS proxy sessions vs K8’s hard 1000 TLS proxy cap
    • Enables up to 250 multi-context virtual firewalls and Active/Active load-balanced failover (K8 lacks both core carrier-grade features)
  2. vs ASA5585-X-SSP40-K9 High-Performance Model: Dual multi-core SSP-60 processors (quad-core on SSP-40), massive 72 GB memory (4 GB on SSP-40), 40 Gbps jumbo frame firewall throughput (20 Gbps on SSP-40), 10 million concurrent sessions (4 million on SSP-40), factory dual redundant power supplies (single PSU standard on SSP-40)
  3. vs ASA5585-X-SSP20-K9 Mid-Tier Model: Industry-leading 40 Gbps throughput, 10 million concurrent sessions, dual redundant factory power supplies, carrier-grade VPN clustering capability
  4. vs Legacy ASA5580-20B/40B-K9: Compact 2RU chassis with native integrated 10GE SFP+ ports (ASA5580 requires separate I/O expansion cards), dual SSP modular slots for integrated FirePOWER IPS blades, unified ASA/FirePOWER coexistence architecture
  5. vs Discontinued PIX-10000 / PIX-535: Modern unified ASA OS architecture, native IPv6 support, ASDM graphical GUI, AnyConnect SSL VPN capability, modular 10GE expansion slots and flexible multi-context virtual segmentation

Typical Historical Deployment Scenarios

  1. Tier-1 service provider central office backbone security gateway aggregating tens of thousands of wholesale enterprise IPsec VPN customer tunnels
  2. Ultra-large hyperscale enterprise multi-datacenter core internet edge firewall with multi-isolated DMZ zones for web, email, database and cloud application servers
  3. Large MSP multi-tenant colocation boundary security gateway with independent multi-context virtual firewall segmentation for segregated customer network traffic
  4. Active/Active redundant chassis pair for load-balanced multi-tenant remote access SSL VPN services and zero-traffic-loss mission-critical disaster recovery business continuity
  5. High-fidelity legacy network lab training platform for carrier-grade ASA OS stateful firewall, massive VPN clustering, multi-context virtual firewalls and high-density 10GE datacenter security architecture learning

3. E-commerce Short Marketing Description

Cisco ASA5585-X-SSP60-K9 Security Plus Premium Flagship 2RU Rack-Mount Carrier-Grade Gigabit Modular Adaptive Security Appliance, legacy ASA 5500-X series top-of-line unrestricted K9 chassis with six built-in 10/100/1000 Gigabit copper ports, four native SFP+ 10GE fiber uplinks, dedicated Fast Ethernet out-of-band management port and one empty half-width SSP expansion slot for FirePOWER IPS/CX unified content security blades, dual redundant hot-swappable AC power supplies factory standard, running ASA OS 8.x / final supported ASA OS 9.1 firmware. K9 bundle unlocks full DES/3DES/AES strong encryption, unlimited internal host capacity, stateful SPI firewall, IPsec site-to-site/AnyConnect SSL remote access VPN, optional hardware inline NGIPS, NAT/PAT, PPPoE broadband aggregation client, VoIP unified communications TLS proxy inspection, multi-context virtual firewalls and dual Active/Standby/Active/Active stateful failover with native chassis VPN clustering. Up to 40 Gbps jumbo frame cleartext firewall throughput, 10,000,000 concurrent TCP/UDP sessions and 10,000 simultaneous IPsec VPN tunnels with hardware crypto offload, managed via serial CLI, embedded ASDM web GUI and Cisco Security Manager. Obsolete end-of-support flagship carrier-grade core/data center modular firewall for tier-1 ISP central office PoPs, hyperscale multi-tenant MSP colocation and ultra-large hyperscale enterprise multi-datacenter VPN aggregation deployments.

4. Product Catalog Keyword Tags

Cisco, ASA5585-X-SSP60-K9, ASA 5500-X Series Flagship Carrier-Grade Security Plus Adaptive Security Appliance, Legacy Top-Tier Stateful Inspection Next-Generation Firewall, 2RU 19-inch Rack-Mount Chassis, Dual Hot-Swappable Redundant Universal AC Power Supplies (Factory Standard), 6 × 10/100/1000 Gigabit Copper Auto-MDI/MDIX Ports, 4 × SFP+ 10GE Fiber Transceiver Slots, Dedicated FastEthernet Out-of-Band Management 0/0 Port, Dual Half-Width Non-Hot-Swap SSP Expansion Slots, Pre-Loaded Dual Multi-Core SSP-60 Firewall Blade, Optional Matching FirePOWER SSP-60 NGIPS / CX SSP-60 Unified Content Security Blades, Dual USB 2.0 Storage Ports, RJ45 Serial Out-of-Band Console Port, DB-15 Inter-Chassis Stateful Failover Serial Port, 72288 MB DDR2 SDRAM, 128 GB Internal Compact Flash Storage, Cisco Adaptive Security Algorithm ASA, ASA OS 8.x / 9.1 Final Supported Firmware, Stateful Packet Inspection SPI, 20 Gbps Max Multiprotocol HTTP Firewall Throughput, 40 Gbps Jumbo Frame UDP Firewall Throughput, 5 Gbps Hardware-Accelerated 3DES/AES VPN Throughput, IPsec IKEv1/IKEv2 DMVPN FlexVPN Site-to-Site & AnyConnect SSL/DTLS Remote Access VPN, Full DES/3DES-AES Unrestricted Strong Encryption Suite, Optional FirePOWER SSP-60 Next-Generation Inline NGIPS Intrusion Prevention System, CX SSP Unified Web Filter/Anti-Spam/Anti-Virus Content Security, NAT PAT Static Dynamic Address Translation, PPPoE DSL Broadband Aggregation Client, VoIP H.323 SIP SCCP Skinny GTP Fixup Protocol Inspection, Transparent Layer 2 Firewall Mode, Multi-Context Virtual Firewall Segmentation (Up to 250 Independent Contexts), Active/Standby & Active/Active Load-Balanced Stateful Failover Redundancy, Native Multi-Chassis Firewall/VPN Clustering & Load Balancing, 1024 Logical Routed VLAN Maximum (Security Plus License), 10,000 Max Simultaneous IPsec VPN Peers, Unlimited TLS Proxy UC Sessions, 10,000,000 Concurrent TCP/UDP Connections, ASDM Adaptive Security Device Manager Embedded Web GUI, Cisco Security Manager CSM Centralized Carrier Policy Orchestration, Syslog SNMPv3 Secure Monitoring, Dual-Stack IPv4 / Limited IPv6 Native Support, Application-Aware Hierarchical QoS Scheduling, NEBS Level 3 FIPS 140-2 Level 1 Telecom Certified, End-of-Sale Aug 25 2017 End-of-Support Aug 31 2023 Obsolete Legacy Hardware, Flagship Unrestricted K9 Upgrade Over ASA5585-X-SSP60-K8 DES Base License, Predecessor to Firepower 4100/9300 Modular Next-Generation Firewall Series, Tier-1 Service Provider Central Office Backbone PoP Multi-Tenant Boundary Firewall, Hyperscale MSP Multi-Tenant Colocation Security Gateway, Ultra-Large Hyperscale Enterprise Multi-Datacenter Core Internet Edge Large-Scale IPsec/DMVPN Aggregation Clustering Hub

Naming Rule Explanation

  • ASA: Adaptive Security Appliance, Cisco post-PIX unified firewall product family integrating stateful firewall, VPN and optional next-generation IPS threat defense services, fully replaced by Firepower NGFW platforms
  • 5585-X: Modular 2RU datacenter-focused chassis model within the legacy ASA 5500-X next-generation firewall series, supporting dual interchangeable SSP processing blades for linear performance scalability
  • SSP60: SSP-60 security services processor blade identifier, flagship dual multi-core firewall blade with 72 GB memory, 40 Gbps jumbo frame stateful throughput, the performance ceiling of the entire ASA 5500 legacy hardware series
  • K9: Premium unrestricted Security Plus license identifier unlocking full 3DES/AES strong encryption, unlimited TLS proxy sessions, maximum multi-context virtual firewalls and Active/Active load-balanced failover; contrasted with K8 base DES-only limited license
  • Hardware Distinction Note: The ASA5585-X-SSP60-K9 is the highest-specification chassis of the entire ASA 5500-X legacy product line, factory equipped with dual redundant hot-swappable power supplies and maximum 72 GB system memory, a unique feature unavailable on lower SSP-10/20/40 variants. All ASA5585-X hardware is fully obsolete with no official Cisco firmware updates, vulnerability patches or Cisco TAC technical support available today.
Click:12 Entry Time:2026-07-20 【Print】 【Close
 © 2026 Kino Technology Limited. All Rights Reserved. | Hong Kong Registered · Shenzhen Operation | New & Genuine Used Network Equipment Supplier 
Links:   白云搜搜   |   未来互联   |   百度   |  
Kino Technology Limited   网站技术支持:未来互联