Cisco FPR9K-SM36-K9 Full English Product Description
1. Short Official Part Number Label
FPR9K-SM36-K9: Cisco Firepower 9000 Series SM-36 Hot-Swap High-Performance Security Compute Module, 36 Multi-Core Processors, 384GB DDR4 RAM, Dual 800GB SSD RAID1 Storage, Integrated Security Acceleration ASIC, NEBS Level 3 Certified, Exclusive for FPR9300-K9 Chassis, Supports Concurrent FTD & ASA Multi-Instance Virtualization
2. Full Product Overview
The Cisco FPR9K-SM36-K9 (SM-36) is a mid-high tier hot-swappable security processing blade designed exclusively for deployment inside the Cisco Firepower 9300 3U carrier-grade modular security chassis, positioned between entry-level SM-24 and high-end SM-44 modules within the legacy SM generation lineup.
Built with robust multi-core x86 architecture and dedicated crypto/inspection offload silicon, this blade delivers significantly higher throughput, larger concurrent session capacity and enhanced multi-tenant virtualization capabilities compared to SM-24. It enables independent logical security instances running Firepower Threat Defense (FTD) or classic ASA OS on one single module, ideal for segregating enterprise business segments or MSSP multi-customer traffic without separate physical hardware.
Fully NEBS Level 3 certified when installed in FPR9300, the SM-36 meets strict telecom central office environmental and EMC standards. Cisco issued End-of-Sale (EoS) notices for SM-24/SM-36/SM-44 series, with final hardware support ending August 31, 2025. Official firmware compatibility caps at FTD 7.2 and ASA 9.18; newer major OS releases are unsupported. All available inventory consists of fully inspected surplus and certified refurbished modules.
3. Complete Hardware Specifications
Core Compute & Memory Resources
-
CPU: 36 physical multi-threaded processing cores for parallel Snort 3 IPS inspection, TLS decryption and massive traffic workloads
-
System Memory: 384GB enterprise-grade DDR4 RAM, optimized to sustain millions of concurrent connections, threat signature databases and AMP file caching
-
Storage: Dual 800GB industrial SSDs pre-configured as hardware RAID 1, redundant local storage for event logs, malware cache, audit records and security rule sets; individual drive fault LED indicators
-
Dedicated Acceleration ASIC: Hardware offload for deep packet inspection, SSL/TLS decryption, IPsec VPN crypto operations and flow table forwarding to reduce CPU latency under full traffic load
-
Form Factor: Vertical hot-swappable blade, pluggable into any of the three security module slots of FPR9300 chassis; no full chassis power shutdown required for module replacement
Environmental & Compliance Credentials
-
Operating Temperature: 0°C to 40°C continuous operation below 1829m altitude
-
Humidity Range: 5%–90% non-condensing relative humidity
-
Certifications: NEBS Level 3, UL safety, CE, FCC Class A EMC, compliant with carrier-grade telecom deployment standards
-
Cooling: Shares front-to-rear airflow managed by FPR9300 chassis hot-swappable fan trays
Chassis Fabric & I/O Compatibility
-
High-speed internal backplane fabric links with supervisor module and rear network modules for wire-rate traffic forwarding
-
Fully compatible with all Firepower 9300 network modules: 10G SFP+, 40G QSFP+, 100G QSFP28 bypass and non-bypass I/O blades
-
Supports intra-chassis port-channel aggregation, cross-module load balancing and resource pooling with identical SM-36 blades
Official FTD Performance Benchmarks (Single SM-36)
-
Firewall + AVC Throughput: 34 Gbps
-
Full NGIPS Threat Inspection Throughput: 29 Gbps
-
TLS/SSL Decryption Throughput: 16 Gbps
-
Maximum Concurrent Active Sessions: 3,000,000
-
New Connections Per Second: 460,000
-
Max Isolated Logical Security Instances (Multi-Tenant): Up to 12 independent FTD/ASA virtual devices per blade
4. Supported Software & Unified Security Feature Stack
Orchestrated via FXOS chassis management layer on FPR9300, SM-36 supports dual operating systems (Firepower Threat Defense FTD / Classic ASA) and delivers the complete enterprise/carrier security suite:
-
Next-Generation IPS with Snort 3 Multi-Threaded Engine
Full deep packet inspection, protocol anomaly detection, exploit signature matching, evasion mitigation and hardware flow offloading for low-latency traffic filtering
-
Advanced Malware Protection (AMP) for Networks
Cloud-based file sandboxing, retrospective malware analysis, global file trajectory tracking and real-time threat outbreak alerting
-
Application Visibility & Control (AVC)
Comprehensive Layer 7 application identification, granular traffic filtering, QoS bandwidth shaping and policy-based application blocking
-
Global URL & IP/Domain Reputation Filtering
Cloud-updated web category database, malicious IP/domain reputation lookup and encrypted web threat identification
-
Identity-Aware Policy Enforcement
Native integration with Active Directory, Cisco ISE, user/group context-based access control across all virtual logical devices
-
Integrated VPN & SD-WAN
Site-to-site IPsec VPN, remote access SSL VPN, dynamic SD-WAN multi-path selection for hybrid WAN aggregation deployments
-
Multi-Instance Virtual Segmentation
Isolated logical security domains for MSSP multi-tenant or enterprise internal network micro-segmentation without extra physical hardware
-
High Availability & Intra/Inter-Chassis Clustering
Supports Active/Passive and Active/Active HA pairs; linear throughput scaling via clustering with multiple SM-36 blades inside one FPR9300 chassis or across multiple 9300 units
-
Centralized Management & API Automation
Unified policy deployment, centralized logging and cross-device reporting via Firepower Management Center (FMC); RESTful APIs for SecOps workflow automation
-
Compliance Audit Logging
Built-in persistent logging to satisfy PCI DSS, HIPAA, GDPR and telecom carrier regulatory audit requirements
5. Typical Deployment Scenarios
-
Large enterprise internet border north-south high-throughput traffic inspection inside FPR9300 chassis
-
Enterprise data center east-west internal traffic micro-segmentation
-
Telecom carrier central office multi-tenant security gateways (NEBS certified)
-
Mid-to-high capacity MSSP shared security inspection nodes with virtual multi-instance isolation
-
Regional headquarters multi-branch high-volume traffic aggregation security blade
-
Low-latency inline security deployments requiring redundant RAID storage and hot-swap serviceability
6. Short Sales Listing Tagline
Cisco FPR9K-SM36-K9 Firepower 9000 Series Hot-Swap Mid-High Performance Security Module for FPR9300 Chassis, 36 Multi-Core CPUs, 384GB DDR4 RAM, Dual 800GB SSD RAID1 Storage, Integrated Security Acceleration ASIC, NEBS Level 3 Certified, Up to 34Gbps Firewall / 29Gbps Full NGIPS Throughput, Multi-Instance FTD & ASA Virtualization, FXOS Orchestrated, EoS Legacy Compute Blade
|