Homepage | Collection | 繁体中文
Product
没有小类
没有小类
没有小类
没有小类
没有小类
没有小类
没有小类
没有小类
H3C
没有小类
没有小类
没有小类
没有小类
没有小类
没有小类
Contact Us


Company Name:Kino Technology Limited

Website:www.kino86.com

Address :Room 312, Honghua Building, No. 1 Guangyayuan Road, Bantian Street, Longgang District, Shenzhen city, Guangdong Province, China



Contact Person:kiki

Tel :+8613040881925 

E-mail:kiki@szkiki.com

Wechat:+8613040881925

Whatspp: +8613040881925

Teams:kiki@szkiki.com





Products
 Product >> Cisco >> ALL
 
Product_Id:
72912501516
ProductName:
ASA5585-X-SSP20
Specification:
Product Notes:
Product Category:
Cisco
 
   Product Description

Cisco ASA5585-X-SSP20 Full Official Product Description

1. Product Overview & Model Naming Definition

Official Full Name

Cisco ASA 5585-X Adaptive Security Appliance with Security Services Processor 20 (SSP-20), Part Number:ASA5585-X-SSP20

Model Breakdown

  1. ASA: Adaptive Security Appliance, Cisco enterprise & data center next-generation firewall platform
  2. 5585-X: High-end modular 2RU dual-slot chassis for large enterprise HQ, data center core and service provider edge security deployments
  3. SSP: Security Services Processor, primary compute module delivering firewall, VPN, routing, application control and threat defense
  4. 20: Mid-tier high-performance compute processor, upgraded hardware vs SSP-10 with doubled memory and crypto acceleration for higher throughput and session capacityCisco

Core Positioning

The Cisco ASA 5585-X SSP-20 is a modular carrier-grade NGFW built in a 2RU dual hot-swappable slot chassis. The SSP-20 occupies Slot 0 (bottom mandatory slot) and delivers integrated stateful firewall, IPsec/SSL VPN, AVC application visibility control, and optional FirePOWER NGIPS intrusion prevention. The vacant top Slot 1 supports matching IPS SSP-20 module to converge firewall + IPS threat defense within a single appliance, eliminating separate standalone IPS racks. It targets large multi-building campus networks, mid-to-large data center perimeters, multi-tenant service provider edge gateways and high-volume remote access VPN deployments.

2. Chassis, Hardware & Base I/O Specifications

Chassis Form Factor

  • Rack unit size: Standard 2RU EIA 19-inch rack-mount chassis
  • Dual hot-swappable module slots: Slot0 = Main Firewall/VPN SSP; Slot1 = Optional IPS SSP or high-density I/O expansion modules
  • Base fixed I/O on SSP-20 module: 8 × 10/100/1000BASE-T copper Gigabit Ethernet ports + 2 × SFP+ 10 Gigabit Ethernet uplink ports
  • Expansion capacity: Additional high-density Gigabit/10G I/O modules installable in Slot1 to scale port density up to 50 GbE or 20 × 10GbE total interfaces

Compute, Memory & Crypto Hardware

  • CPU Architecture: Dual multi-core high-performance processors
  • System DRAM: 12 GB total memory (double SSP-10’s 6GB); expands to 24GB when paired with IPS SSP-20 module in Slot1Cisco
  • Onboard flash storage: 2 GB internal flash for ASA OS firmware, configuration files, system logs; dual SSP configuration upgrades total flash capacity to 4GB
  • Crypto Acceleration: Four dedicated embedded hardware crypto accelerators (double SSP-10’s two accelerators) for AES, 3DES, RSA, ECC encryption to fully offload VPN traffic without consuming general CPU resourcesCisco

Power & Thermal Design

  • Standard base configuration: Single AC power supply + single hot-swappable fan tray
  • Redundancy support: Replace the fan tray with a secondary redundant AC power supply to implement fully redundant power input for high-availability production environments
  • Cooling architecture: Front-to-back forced airflow, fully compatible with standard data center hot/cold aisle rack layout standards

3. Official Performance Benchmarks (SSP-20 Tier)

  1. Stateful firewall throughput (64-byte packets): Up to 10 Gbps
  2. Standalone AVC application control throughput: 7 GbpsCisco
  3. Combined AVC + FirePOWER NGIPS threat defense throughput: 3.5 GbpsCisco
  4. 3DES/AES IPsec VPN throughput: Up to 2 Gbps
  5. Maximum concurrent TCP/UDP sessions: 1,000,000 simultaneous active sessions (double SSP-10’s capacity)Cisco
  6. New connection establishment rate: Up to 75,000 new sessions per secondCisco
  7. Supported logical VLAN interfaces: 1,024 VLANs for multi-zone network segmentation
  8. Maximum IPsec site-to-site VPN tunnels: 10,000 tunnels
  9. Concurrent Cisco AnyConnect SSL VPN remote worker peers: Up to 10,000 concurrent mobile/remote access users
  10. Application identification library: Recognizes more than 3,000 distinct network applications for granular AVC bandwidth control and policy enforcementCisco

4. Integrated Security & Networking Feature Suite

Core Stateful Firewall Functions

  • Full stateful packet inspection (SPI) for TCP, UDP, ICMP and all standard IP protocols
  • Multi-context virtual firewall mode: Partition one physical appliance into multiple fully isolated virtual firewalls for multi-tenant business unit segmentation
  • Object-group ACL policy management, time-based access control rules
  • Comprehensive NAT services: Static NAT, dynamic PAT, large-scale carrier-grade LSN NAT, NAT64 for seamless IPv4/IPv6 dual-stack network transition

Enterprise & Service Provider VPN Encryption Services

  • IPsec site-to-site VPN tunnels with AES-256, 3DES, SHA-256 encryption and hashing algorithms
  • Cisco AnyConnect Secure Mobility SSL VPN for remote workforce, cross-platform support for Windows, macOS, iOS, Android endpoints
  • DMVPN Dynamic Multipoint VPN for hub-spoke enterprise WAN architectures
  • Hardware-accelerated crypto offload eliminates CPU bottlenecks under high-volume VPN traffic loads

Application Visibility & Advanced Threat Defense

  • Cisco AVC (Application Visibility and Control): Deep packet inspection to identify thousands of applications, with per-application bandwidth shaping, blocking, logging and QoS policy enforcement
  • Optional FirePOWER Next-Generation IPS (NGIPS): Install matching IPS SSP-20 module in Slot1 to add intrusion prevention, malware threat protection, URL web filtering (80+ URL categories, over 280 million classified websites), and advanced threat analytics
  • Cisco Cloud Web Security integration to forward internet web traffic to cloud-based security scanning for additional malware and content filtering

Routing & Dual-Stack Network Integration

  • Full support for static routing, RIP v1/v2, OSPF, EIGRP, BGP dynamic routing protocols
  • Integrated Routing and Bridging (IRB) for transparent firewall mode deployments
  • Complete IPv4 / IPv6 dual-stack protocol support for smooth network IPv6 migration

5. Carrier-Grade High Availability Capabilities

  1. Active/Standby & Active/Active Firewall Failover
    Supports dual ASA 5585-X appliances deployed as HA failover pairs for zero downtime during hardware faults, firmware upgrades or scheduled maintenance. Stateful session synchronization preserves all active user VPN and data sessions during switchover.
  2. OIR Online Insertion and Removal
    All SSP compute modules, IPS threat modules, power supplies and fan trays support full hot-swap replacement without full chassis power shutdown; existing firewall forwarding traffic remains uninterrupted during component maintenance.
  3. ISSU In-Service Software Upgrade
    Non-disruptive ASA OS firmware upgrades across HA firewall clusters, eliminating full network security outage during operating system version updates.
  4. Synchronized Configuration & Centralized Logging
    Automatic configuration synchronization between HA paired firewalls; centralized event logging support for syslog servers, Cisco Security Manager, and FireSIGHT Management Center for unified global policy control and cross-network threat reporting.

6. Physical & Environmental Specifications

  • SSP Module Dimensions: 43.7 cm (W) × 39.6 cm (D) × 4.3 cm (H)
  • Single SSP-20 module net weight: 5.2 kg
  • Standard data center operating temperature range: 5°C to 40°C (41°F ~ 104°F)
  • Short-term extended operating temperature: -5°C to 55°C (23°F ~ 131°F), maximum continuous runtime 96 hours, annual cumulative usage limit 15 days
  • Continuous operating relative humidity: 10% – 85% non-condensing; storage & transit humidity: 5% – 95% non-condensing
  • Storage & transit temperature range: -40°C to 70°C (-40°F ~ 158°F)

7. Regulatory & Global Compliance Certifications

  1. Electrical Safety Standards: UL 60950-1, CSA C22.2 No.60950-1, IEC 60950, EN 60950-1
  2. Laser Safety Certification: IEC/EN 60825 for front-panel SFP+ 10G optical transceivers
  3. EMC & EMI Electromagnetic Compatibility: FCC Part 15 Class A, ICES-003 Class A, VCCI Class A, CISPR 22 (EN55022) Class A, CISPR 24, full EN 61000 series ESD, electrical surge, radiated & conducted immunity compliance
  4. Telecom Carrier Industry Standards: NEBS Level 3 (GR-63-Core environmental protection, GR-1089-Core EMC and safety specifications)
  5. Cryptographic Security Compliance: FIPS 140-2 validated cryptographic module for government, financial and regulated industry deployments
  6. Environmental Directives: EU RoHS hazardous substance restriction compliance, EU WEEE waste electrical and electronic equipment recycling directive compliant

8. Key Deployment Advantages

  1. Converged All-in-One Unified Security Platform
    Consolidates discrete firewall, VPN, application control and optional NGIPS threat defense onto a single 2RU rack appliance, drastically reducing physical rack space occupation, total power consumption and multi-device daily management overhead compared to separate standalone security hardware.
  2. Modular Scalable Dual-Slot Chassis Architecture
    The two-slot chassis design enables incremental capacity expansion without full hardware replacement: add matching IPS SSP-20 modules to enable full threat prevention, or deploy high-density I/O expansion cards to scale Ethernet port counts as network traffic volume and subscriber user base grow. Mixed tier SSP modules (SSP-20 paired with SSP-10/40/60) are not supported; only identical tier SSPs can coexist in the same chassisCisco.
  3. High-Density Hardware Crypto & Multi-Core Offloading
    Four dedicated encryption accelerators and dual multi-core compute architecture fully offload resource-intensive VPN encryption and deep packet inspection workloads from general-purpose CPUs, maintaining consistent maximum forwarding throughput even under full comprehensive security policy enforcement.
  4. Flexible Multi-Tenant Virtualization Capability
    Multi-context virtual firewall mode enables service providers and large enterprise organizations to split one physical ASA appliance into fully isolated independent security domains for different business divisions, separate customer tenants or segmented network zones, maximizing hardware asset utilization efficiency.
  5. Unified Centralized Enterprise-Grade Management
    Fully compatible with Cisco Security Manager for centralized global firewall policy administration and FireSIGHT Management Center for unified NGIPS threat visibility, event correlation and compliance reporting across distributed fleets of ASA security appliances.
  6. Long-Term Investment Protection
    Fully interoperable with the complete ASA 5585-X accessory ecosystem including IPS SSP modules, 1G/10G I/O expansion cards, redundant power supplies, and all compatible SFP/SFP+ optical transceivers; existing compatible hardware accessories can be fully reused during network security capacity expansion upgrades.

9. Standard Factory Packaging Contents

  1. ASA 5585-X 2RU chassis pre-installed with SSP-20 main security services processor module
  2. ESD anti-static protective transport bag for SSP compute modules
  3. Standard 19-inch rack mounting brackets and all installation screws
  4. Blank filler panels for unused chassis slots and empty SFP/SFP+ optical ports
  5. Hardware installation quick start guide (covers rack mounting, SSP module OIR hot-swap, front panel LED alarm status troubleshooting procedures)
  6. Global regulatory compliance documentation packet (safety, EMC, NEBS, FIPS, RoHS certification documents)
  7. Dual ejector lever assemblies pre-installed on the SSP module front panel for simple chassis slot insertion and removal

Supplementary UNSPSC Classification Code

43222501 – Cisco ASA 5585-X SSP-20 modular next-generation adaptive security appliance, 2RU dual-slot chassis firewall/VPN compute module with 8×GbE copper + 2×10G SFP+ base I/O, four dedicated hardware crypto accelerators, 12GB onboard DRAM, integrated AVC application control, optional matching IPS SSP-20 expansion slot for FirePOWER NGIPS threat defense, designed for large enterprise campus core networks, mid-sized data center perimeter security and multi-service provider edge gateway deployments.

Standard Hardware Warranty

All factory-new ASA 5585-X SSP-20 security appliances include a 1-year limited hardware warranty covering manufacturing defects and component failures under rated standard operating environmental conditions. Optional extended 3-year / 5-year Cisco SMARTnet service contracts are available, providing 24×7 priority Cisco TAC engineering technical support, advance genuine Cisco hardware replacement service, validated stable ASA OS firmware upgrade releases, and comprehensive firewall, VPN, AVC and NGIPS security policy configuration and network troubleshooting support throughout the multi-year hardware operational lifecycle.
Click:2 Entry Time:2026-07-29 【Print】 【Close
 © 2026 Kino Technology Limited. All Rights Reserved. | Hong Kong Registered · Shenzhen Operation | New & Genuine Used Network Equipment Supplier 
Links:   白云搜搜   |   未来互联   |   百度   |  
Kino Technology Limited   网站技术支持:未来互联