Homepage | Collection | 繁体中文
Product
没有小类
没有小类
没有小类
没有小类
没有小类
没有小类
没有小类
没有小类
H3C
没有小类
没有小类
没有小类
没有小类
没有小类
没有小类
Contact Us


Company Name:Kino Technology Limited

Website:www.kino86.com

Address :Room 312, Honghua Building, No. 1 Guangyayuan Road, Bantian Street, Longgang District, Shenzhen city, Guangdong Province, China



Contact Person:kiki

Tel :+8613040881925 

E-mail:kiki@szkiki.com

Wechat:+8613040881925

Whatspp: +8613040881925

Teams:kiki@szkiki.com





Products
 Product >> Cisco >> ALL
 
Product_Id:
72115352916
ProductName:
FTDv20
Specification:
Product Notes:
Product Category:
Cisco
 
   Product Description

Cisco FTDv20 Full English Product Description

1. Short Official Tier & License Label

FTDv20 / L-FTDV-20S-BSE-K9=: Cisco Secure Firewall Threat Defense Virtual Tier 20 Mid-Range Virtual NGFW, Hard Rate-Licensed for 3 Gbps Full FW+AVC+NGIPS Inspection Throughput, Base VM Spec: 4 vCPU / 8GB Dedicated RAM, Cisco Smart Software Licensing, Supports VMware ESXi, KVM, OpenStack, AWS, Azure, GCP, OCI, Unified All-in-One Threat Stack (Snort 3 NGIPS, AMP, URL Filter, Identity Policy, SD-WAN), Max 250 Concurrent AnyConnect RA VPN Sessions, Local FDM GUI & Centralized FMC Management, Active/Standby HA Supported, Cloud Clustering Compatible

2. Full Product Overview

Cisco Secure Firewall Threat Defense Virtual 20 (FTDv20, previously NGFWv20) is a mid-range virtual next-generation firewall powered by Firepower Threat Defense (FTD) unified OS, positioned above FTDv10 for medium-to-large virtual branch gateways, hybrid multi-cloud perimeters, medium-volume SDDC east-west segmentation, and mid-tier MSSP multi-tenant virtual security nodes across private hypervisors and all mainstream public cloud platformsCisco.
Unlike legacy ASAv virtual firewalls built on traditional ASA OS, FTDv20 integrates a complete unified threat defense suite within a single virtual instance, combining stateful firewall, Snort 3 NGIPS intrusion prevention, Advanced Malware Protection (AMP), global URL filtering, identity-aware zero-trust access control, and native SD-WAN functionality. This tier enforces a fixed 3 Gbps maximum full inspection throughput cap via license throttling, with a hard limit of 250 simultaneous AnyConnect remote access VPN users, balancing robust multi-threat inspection and cost efficiency for medium-bandwidth production workloadsCisco.
FTDv20 delivers broad deployment flexibility across VMware ESXi 7.x/8.x, KVM, OpenStack private clouds plus AWS, Azure, GCP, OCI public cloud environments. It supports vmxnet3/ixgbe paravirtual vNICs, SR-IOV hardware passthrough, and RSS multi-queue tuning to cut virtualization overhead and sustain wire-rate encrypted traffic under peak loads. It adopts Cisco Smart Software Licensing with flexible perpetual or term-based base entitlements, with optional add-on Threat, Malware, URL, and AnyConnect Apex/Plus subscriptions to unlock full advanced threat capabilities. Operators can manage standalone instances via lightweight Firepower Device Manager (FDM) local GUI, or centrally orchestrate hybrid physical/virtual firewall fleets through Firepower Management Center (FMC) for unified policy distribution, logging, and cross-device reportingCisco.
Key Capability Upgrade vs FTDv10: FTDv20 supports virtual clustering on AWS/Azure/GCP to linearly scale throughput across multiple FTDv20 nodes; Active/Standby stateful failover HA is also available for basic redundancy.

3. Virtual Machine Hardware Resource Specifications

Mandatory & Optimal VM Allocation for Full 3 Gbps Licensed Throughput

  • Virtual CPU: Minimum 4 dedicated pinned vCPUs (official baseline for FTDv20 tier; expandable to 8 vCPUs for heavy TLS decryption workloads)
  • System Memory: Minimum 8GB dedicated VM RAM; expandable to 16GB for high-session traffic profiles
  • Storage: Minimum 100GB high-performance thin-provisioned virtual disk for OS, configuration backups, persistent event logs, AMP malware cache, and Talos global threat signature databasesCisco
  • Supported Private Hypervisors: VMware ESXi 7.x / 8.x, KVM, OpenStack, Cisco HyperFlex, Nutanix AHV
  • Supported Public Cloud Platforms: Amazon AWS, Microsoft Azure, Google Cloud GCP, Oracle Cloud OCI
  • Virtual NIC Compatibility: vmxnet3, ixgbe, SR-IOV hardware passthrough vNICs, RSS multi-queue offload for low-latency encrypted traffic processing
  • Max Virtual Interfaces: Up to 16 vNICs for multi-segment network isolation and layered east-west workload segmentation
  • VLAN Capacity: Up to 1024 VLAN tagged subinterfaces
  • Jumbo Frame Support: Up to 9000 MTU for data center storage and high-volume cloud workload traffic

Official FTDv20 Licensed Performance Benchmarks (450B packet size)

  • Maximum Licensed FW+AVC+NGIPS Full Inspection Throughput: 3 Gbps (hard-enforced rate limit)Cisco
  • IPsec VPN Encrypted Throughput (AES-256 Fastpath): Up to 3 Gbps
  • Maximum Concurrent Active Stateful Connections: 2,000,000
  • New Connections Per Second: Up to 20,000
  • Max Site-to-Site IPsec VPN Peer Tunnels: 750
  • Max Concurrent AnyConnect SSL Remote Access VPN Sessions: 250 (license-enforced hard cap)Cisco
  • TLS/SSL Decryption Throughput: Up to 1.8 Gbps for bulk encrypted web, SaaS and application traffic

4. Complete Unified Threat Security Feature Suite

1. Next-Generation Stateful Firewall & AVC

Full Layer 3–4 stateful packet inspection, static/dynamic NAT, PAT, NAT64/NAT46 dual-stack translation, granular object-group access control policies, Layer 7 Application Visibility and Control covering thousands of enterprise, cloud, social media and SaaS applications, traffic policing and QoS bandwidth shaping. Native IPv4/IPv6 dual-stack support with static routing, OSPF, EIGRP and BGP dynamic routing protocols for seamless hybrid on-prem/cloud connectivity.

2. Snort 3 NGIPS Intrusion Prevention System

High-performance Deep Packet Inspection (DPI), protocol anomaly detection, exploit signature matching, advanced evasion mitigation, custom IOC import and real-time threat correlation powered by Cisco Talos global threat intelligence to block exploits, malware lateral movement and intrusion attempts.

3. Advanced Malware Protection (AMP) for Networks

Cloud-based file sandboxing, retrospective malware analysis, global file trajectory tracking, real-time outbreak alerting and file reputation filtering to detect and contain zero-day malicious file transfers across virtual workloads.

4. Global URL & DNS Reputation Filtering

Cloud-updated web category database covering 280+ million URLs across 80+ risk categories, malicious domain/IP reputation lookup, DNS sinkholing and encrypted DNS (DoH/DoT) threat identification to block phishing, malware and high-risk web destinations.

5. Identity-Aware Zero Trust Policy Enforcement

Native integration with Active Directory, Cisco ISE and Secure Client to apply user/group context-based security rules, enabling zero-trust access control tied to real user identities instead of only IP addresses.

6. Integrated SD-WAN & Full VPN Services

Dynamic SD-WAN multi-path selection for hybrid broadband/MPLS WAN aggregation; site-to-site IPsec IKEv1/IKEv2 tunnels with AES-256 encryption; AnyConnect SSL remote access VPN with split tunneling, clientless web portal and secure mobility for distributed remote workforce.

7. High Availability & Virtual Scalability

  • Active/Standby stateful failover HA with full session synchronization to eliminate connection drops during VM maintenance or hardware failure
  • Multi-node virtual clustering supported on AWS/Azure/GCP for linear throughput scaling across multiple FTDv20 instances
  • Fully compatible with hypervisor and cloud-native VM redundancy groups and auto-scaling workflowsCisco

8. Traffic Visibility, Logging & Compliance

Real-time traffic monitoring via FDM local web GUI; secure syslog, SNMP v3 and NetFlow Secure Event Logging (NSEL) export to third-party SIEM platforms. Persistent audit logging meets regulatory compliance requirements for medium enterprise PCI DSS, HIPAA and GDPR audit frameworks.

9. DevOps Automation & Centralized Orchestration

Local FDM lightweight web GUI for standalone single-instance administration; RESTful API for automated VM provisioning, policy deployment and lifecycle management; unified cross-platform policy distribution, centralized logging and cross-device reporting via Firepower Management Center (FMC); centralized license entitlement tracking via Cisco Smart License Manager.

5. Typical Deployment Scenarios

  • Medium-to-large remote office virtual security gateway with 3Gbps internet bandwidth
  • Hybrid multi-cloud perimeter inspection gateway for AWS/Azure/GCP/OCI SaaS workload protection
  • Medium-scale east-west segmentation for virtualized server clusters in Software-Defined Data Centers (SDDC)
  • Mid-tier MSSP virtual security nodes for medium-traffic small and medium business customers
  • Virtual branch consolidation replacing mid-range physical FTD hardware for cost and space optimization
  • Lab, training and pre-production security testing environments with medium-to-high traffic volume
  • Cloud-native auto-scaling security gateways for elastic container and virtual machine workloads

6. Short Sales Listing Tagline

Cisco FTDv20 Secure Firewall Threat Defense Virtual Mid-Range NGFW, Licensed for 3Gbps Max Full Inspection Throughput, Base 4 vCPU / 8GB VM RAM, Smart Software License L-FTDV-20S-BSE-K9=, Supports VMware ESXi/KVM/OpenStack/AWS/Azure/GCP/OCI, Integrated Snort 3 NGIPS/AMP/URL Filter/SD-WAN Unified Threat Stack, 250 Concurrent AnyConnect RA VPN Sessions, Active/Standby HA & Cloud Virtual Clustering Support, Managed via Local FDM GUI or Centralized FMC, Mid-Tier Virtual NGFW for Large Remote Branches & Medium-Volume Multi-Cloud Workloads
Click:16 Entry Time:2026-07-21 【Print】 【Close
 © 2026 Kino Technology Limited. All Rights Reserved. | Hong Kong Registered · Shenzhen Operation | New & Genuine Used Network Equipment Supplier 
Links:   白云搜搜   |   未来互联   |   百度   |  
Kino Technology Limited   网站技术支持:未来互联