Cisco FTDv5 Full English Product Description
1. Short Official Tier & License Label
FTDv5 / L-FTDV-5-K9=: Cisco Secure Firewall Threat Defense Virtual Tier 5 Entry-Level NGFW Virtual Appliance, Licensed for 100 Mbps Maximum Inspection Throughput, Mandatory 4 vCPU / 8GB VM Memory, Smart Software Licensing, Supports VMware ESXi, KVM, OpenStack, AWS & Azure Public Clouds, Full Unified Threat Defense Stack including NGIPS, AMP, URL Filtering, Identity Policy, Limited AnyConnect RA VPN (50 Concurrent Sessions), FMC & FDM Local Management
2. Full Product Overview
Cisco Secure Firewall Threat Defense Virtual 5 (FTDv5, formerly NGFWv5) is the entry-tier virtual next-generation firewall built on the Firepower Threat Defense unified security OS, designed for small branch virtual gateways, remote office cloud workload protection, low-traffic test environments, tiny multi-tenant customer segments and lightweight east-west workload segmentation across private hypervisors and mainstream public cloud platformsCisco.
Unlike ASAv which runs classic ASA OS, FTDv5 delivers a fully integrated all-in-one threat protection suite combining stateful firewall, Snort 3 NGIPS intrusion prevention, Advanced Malware Protection (AMP), cloud URL filtering, identity-aware access control and SD-WAN functionality within a single lightweight virtual instance. This tier enforces a hard 100 Mbps throughput rate limit via built-in license throttling, with a cap of 50 simultaneous AnyConnect remote access VPN users, making it ideal for low-bandwidth small-scale deployments without heavy traffic inspection demandsCisco.
FTDv5 supports flexible deployment across VMware ESXi, KVM, OpenStack private clouds plus AWS and Azure public cloud environments, with paravirtualized vNICs and SR-IOV passthrough for reduced virtualization latency. It adopts Cisco Smart Software Licensing with term or perpetual base entitlements, plus optional add-on Threat, Malware, URL and AnyConnect Apex/Plus licenses to unlock full feature capabilities. Unified management options include local Firepower Device Manager (FDM) GUI for standalone instances or centralized Firepower Management Center (FMC) for multi-device hybrid orchestrationCisco.
Key Restriction: FTDv5 does not support AWS GWLB and Azure Gateway Load Balancer clustering modes; only basic Active/Standby HA is available for redundancyCisco Syst....
3. Virtual Machine Hardware Resource Specifications
Mandatory VM Allocation for FTDv5 Tier
-
Virtual CPU: Minimum 4 dedicated vCPUs (required to meet licensed 100 Mbps throughput ceiling)
-
System Memory: Minimum 8GB dedicated VM RAM
-
Storage: Minimum 40GB thin-provisioned virtual disk for OS, configuration backups, local event logs, AMP file cache and signature databases
-
Supported Private Hypervisors: VMware ESXi 7.x/8.x, KVM, OpenStack
-
Supported Public Cloud Platforms: Amazon AWS, Microsoft Azure (GWLB clustering unsupported)
-
Virtual NIC Compatibility: vmxnet3, ixgbe, SR-IOV hardware passthrough vNICs for low-latency traffic processing
-
Max Virtual Interfaces: Up to 10 vNICs for multi-segment network isolation
-
VLAN Support: Up to 256 VLAN tagged subinterfaces
-
Jumbo Frame Support: Up to 9000 MTU for storage and cloud workload traffic
Official FTDv5 Licensed Performance Benchmarks
-
Maximum Licensed Firewall + AVC + IPS Throughput: 100 Mbps (hard rate-limited)Cisco Syst...
-
IPsec VPN Encrypted Throughput: Up to 100 Mbps AES encrypted traffic
-
Maximum Concurrent Active Stateful Connections: 250,000
-
New Connections Per Second: Up to 4,900
-
Max Site-to-Site IPsec VPN Peers: 250
-
Max Concurrent AnyConnect SSL Remote Access VPN Sessions: 50 (license enforced cap)Cisco
-
TLS/SSL Decryption Throughput: Up to 60 Mbps for encrypted web & application traffic
4. Complete Unified Threat Security Feature Suite
1. Next-Generation Stateful Firewall & AVC
Full Layer 3–4 stateful inspection, static/dynamic NAT, PAT, NAT64/NAT46 dual-stack translation, granular object-group access control policies, Layer 7 Application Visibility and Control for thousands of cloud, social media and enterprise applications, traffic policing and QoS bandwidth shaping. Native IPv4/IPv6 dual-stack support with static routing, OSPF, EIGRP and BGP dynamic routing protocols for hybrid on-prem/cloud connectivity.
2. Snort 3 NGIPS Intrusion Prevention System
Deep Packet Inspection (DPI), protocol anomaly detection, exploit signature matching, advanced evasion mitigation, intrusion rule tuning and custom IOC import powered by real-time Cisco Talos global threat intelligence to block malware, exploits and lateral movement attacks.
3. Advanced Malware Protection (AMP) for Networks
Cloud-based file sandboxing, retrospective malware analysis, global file trajectory tracking, outbreak alerting and file reputation filtering to detect and contain zero-day malicious file transfers across virtual workloads.
4. Global URL & DNS Reputation Filtering
Cloud-updated web category database, malicious domain/IP reputation lookup, DNS sinkholing and encrypted DNS (DoH/DoT) threat identification to block risky web destinations and phishing domains.
5. Identity-Aware Zero Trust Policy Enforcement
Native integration with Active Directory, Cisco ISE and Secure Client to apply user/group context-based security rules, linking traffic policies to real user identities instead of only IP addresses.
6. Integrated SD-WAN & Full VPN Services
Dynamic SD-WAN multi-path selection for hybrid broadband/MPLS WAN aggregation; site-to-site IPsec IKEv1/IKEv2 tunnels with AES-256 encryption; AnyConnect SSL remote access VPN with split tunneling, clientless web portal and secure mobility for remote staff.
7. High Availability & Virtual Resilience
Only Active/Standby stateful failover HA supported (Active/Active and multi-node clustering unavailable for FTDv5). Full session synchronization between HA peers prevents connection drops during VM maintenance or failure, compatible with hypervisor and cloud native VM redundancy groups.
8. Visibility, Logging & Compliance
Real-time traffic monitoring via FDM local GUI; secure syslog, SNMP v3 and NetFlow Secure Event Logging (NSEL) export to third-party SIEM tools. Persistent audit logging meets baseline regulatory requirements for small business PCI DSS, HIPAA and GDPR compliance.
9. Centralized Management & DevOps Automation
Local FDM web GUI for single-instance lightweight administration; RESTful API for automated VM provisioning and policy lifecycle management; unified cross-platform policy deployment, logging and reporting via Firepower Management Center (FMC); centralized license entitlement tracking via Cisco Smart License Manager.
5. Typical Deployment Scenarios
-
Small remote office virtual security gateway with low-bandwidth internet connectivity
-
Cloud test/development environment workload perimeter protection on AWS/Azure
-
Lightweight east-west segmentation for tiny virtualized server clusters
-
Minimal footprint MSSP micro-segments for low-traffic small business customers
-
Virtual branch consolidation replacing low-end physical FTD hardware for cost optimization
-
Lab, training and pre-production security testing environments with limited traffic volume
6. Short Sales Listing Tagline
Cisco FTDv5 Secure Firewall Threat Defense Virtual Entry-Tier NGFW, Licensed for 100Mbps Max Inspection Throughput, Requires 4 vCPU / 8GB VM RAM, Smart Software License L-FTDV-5-K9=, Supports VMware ESXi/KVM/OpenStack/AWS/Azure, Full NGIPS/AMP/URL Filter/SD-WAN Stack, 50 Concurrent AnyConnect RA VPN Sessions, Active/Standby HA Only, Managed via FDM Local GUI or Centralized FMC, Lightweight Virtual NGFW for Small Branches & Low-Traffic Cloud Workloads
|