Cisco FPR9K-SM24-K9 Full English Product Description
1. Short Official Part Label
FPR9K-SM24-K9: Cisco Firepower 9000 Series SM-24 Hot-Swap Security Compute Module, 24 Physical CPU Cores, 256GB DDR4 RAM, Dual 800GB SSD RAID1 Storage, Integrated Security Acceleration ASIC, NEBS Level 3 Certified, Compatible with FPR9300-K9 Chassis, Supports FTD & ASA Multi-Instance Virtualization
2. Full Product Overview
The Cisco FPR9K-SM24-K9 (SM-24) is the entry-tier hot-swappable security compute module exclusively designed for deployment inside the Cisco Firepower 9300 3U modular carrier-grade security chassis. As a mid-capacity processing blade in the legacy SM-24/SM-36/SM-44 generation, it delivers balanced throughput, multi-tenant virtualization and carrier-grade compliance for medium-scale data center perimeters, enterprise core segmentation and mid-sized MSSP multi-tenant inspection nodesCisco.
This module integrates dedicated security acceleration hardware to offload deep packet inspection, TLS decryption and threat matching workloads, significantly reducing CPU latency under full inspection traffic. It supports logical device virtualization, enabling multiple independent FTD or ASA security instances to run concurrently on a single blade for isolated multi-customer or multi-segment security policies.
Notably, SM-24 is fully NEBS Level 3 certified when deployed within the FPR9300 chassis, making it suitable for telecom service provider central office environments. Cisco has marked SM-24 series as End-of-Sale (EoS); official software support ends on FTD 7.2 / ASA 9.18, with no compatibility for newer major firmware releases (FTD 7.3+ / ASA 9.19+)Cisco. All available stock consists of fully tested surplus and certified refurbished modules.
3. Complete Hardware Specifications
Core Compute Resources
-
CPU: 24 physical multi-threaded processor cores for parallel threat inspection and traffic processing
-
System Memory: 256GB enterprise-grade DDR4 RAM to handle massive concurrent connections, signature databases and AMP file cachingCisco
-
Storage: Dual 800GB industrial SSDs pre-configured in hardware RAID 1, delivering redundant local storage for event logs, malware cache, security rule sets and audit records; dedicated fault LED indicators for each SSD drive
-
Acceleration Hardware: Onboard security acceleration ASIC for hardware offload of IPS matching, TLS/SSL decryption, IPsec VPN crypto operations and flow table processing
-
Form Factor: Hot-swappable vertical blade, pluggable into any of the three security module slots of FPR9300 chassis; zero chassis power-down required for module replacement
Environmental & Compliance
-
Operating Temperature: 0°C to 40°C continuous below 1829m altitude; restricted thermal profile above 1829m
-
Humidity: 5%–90% non-condensing relative humidity
-
Certification: NEBS Level 3, UL, CE, FCC Class A EMC, telecom safety standards for carrier-grade deploymentsCisco Live
-
Cooling: Shared front-to-rear airflow via FPR9300 chassis hot-swap fan trays
Inter-Chassis Fabric Connectivity
-
High-speed internal chassis fabric links to the supervisor module and rear network modules, supporting full wire-rate traffic forwarding between I/O blades and compute SM-24
-
Works with all Firepower 9300 network modules: 10G SFP+, 40G QSFP+, 100G QSFP28 bypass and non-bypass I/O modules
-
Supports intra-chassis resource sharing, port-channel aggregation and cross-module traffic load balancing
Official Performance Benchmarks (Single SM-24 with FTD)
-
Firewall + AVC Throughput: 30 Gbps
-
Full NGIPS Threat Inspection Throughput: 22 Gbps
-
TLS/SSL Decryption Throughput: 12 Gbps
-
Maximum Concurrent Active Sessions: 2,000,000
-
New Connections Per Second: 320,000
-
Max independent logical security instances (multi-tenant): Up to 8 isolated FTD/ASA virtual devices per module
4. Supported Software & Unified Security Feature Stack
Managed via FXOS chassis orchestration layer on FPR9300, the SM-24 supports both Firepower Threat Defense (FTD) and Classic ASA operating systems, delivering full security feature set:
-
Next-Generation IPS with Snort Multi-Threaded Engine
Full deep packet inspection, protocol anomaly detection, exploit signature matching, evasion mitigation and hardware flow offloading
-
Advanced Malware Protection (AMP) for Networks
Cloud sandboxing, retrospective malware analysis, global file trajectory tracking and real-time outbreak alerting
-
Application Visibility & Control (AVC)
Layer 7 full application identification, granular traffic filtering, QoS bandwidth shaping and policy-based application blocking
-
Global URL & IP/Domain Reputation Filtering
Cloud-updated web category database, malicious IP/domain reputation lookup and encrypted web threat identification
-
Identity-Aware Policy Enforcement
Native integration with Active Directory, Cisco ISE, user/group context-based access control across all virtual instances
-
Integrated VPN & SD-WAN
Site-to-site IPsec VPN, remote access SSL VPN, dynamic SD-WAN multi-path selection for hybrid WAN deployments
-
Multi-Instance Virtual Segmentation
Isolated logical security domains for MSSP multi-tenant or enterprise internal network segmentation without separate physical hardware
-
High Availability & Clustering
Supports Active/Passive and Active/Active HA pairs; intra-chassis clustering with identical SM-24 blades for linear throughput scaling
-
Centralized Management & API Automation
Unified policy deployment, logging and reporting via Firepower Management Center (FMC); RESTful APIs for SecOps workflow automation
-
Compliance Audit Logging
Built-in logging for PCI DSS, HIPAA, GDPR and telecom regulatory compliance requirements
5. Typical Deployment Scenarios
-
Medium enterprise internet border north-south traffic inspection inside FPR9300 chassis
-
Enterprise data center east-west internal traffic micro-segmentation
-
Telecom carrier central office multi-tenant security gateways (NEBS compliant)
-
Mid-tier MSSP shared security inspection nodes with virtual multi-instance isolation
-
Regional headquarters multi-branch traffic aggregation security blade
-
Hybrid copper/fiber inline security deployments requiring redundant RAID storage and hot-swap serviceability
6. Short Sales Listing Tagline
Cisco FPR9K-SM24-K9 Firepower 9000 Series Hot-Swap Security Module for FPR9300 Chassis, 24 Physical CPU Cores, 256GB DDR4 RAM, Dual 800GB SSD RAID1 Storage, Integrated Security Acceleration ASIC, NEBS Level 3 Certified, Up to 30Gbps Firewall / 22Gbps Full IPS Throughput, Multi-Instance FTD/ASA Virtualization, FXOS Orchestrated, EoS Legacy Compute Blade
|