Cisco ASA5585-X-SSP40 Full Official Product Description
1. Product Overview & Model Naming Definition
Official Full Name
Cisco ASA 5585-X Adaptive Security Appliance with Security Services Processor 40 (SSP-40), Part Number:ASA5585-X-SSP40
Model Breakdown
-
ASA: Adaptive Security Appliance, Cisco enterprise & data center next-generation firewall (NGFW) platform
-
5585-X: High-end modular 2RU dual hot-swappable slot chassis for large enterprise HQ, data center perimeter, multi-tenant service provider edge deployments
-
SSP: Security Services Processor, primary compute blade integrating firewall, VPN, routing, AVC application control and optional FirePOWER NGIPS threat defense
-
40: High-performance tier compute module, upgraded from SSP-10/SSP-20 with doubled CPU cores, expanded memory, six dedicated crypto accelerators and increased 10G fiber port densityCisco
Core Positioning
The Cisco ASA 5585-X SSP-40 is a carrier-grade modular NGFW housed in a 2RU dual-slot chassis. The SSP-40 occupies the mandatory bottom Slot 0 as the primary firewall/VPN compute blade, delivering integrated stateful firewall, IPsec/SSL remote access VPN, Cisco AVC deep application visibility & control, and optional FirePOWER Next-Generation IPS intrusion prevention. The vacant upper Slot 1 supports a matching IPS SSP-40 expansion blade to converge firewall + full threat defense on a single physical appliance, eliminating discrete standalone IPS racks. Target deployments include large multi-building enterprise campus core networks, mid-to-large data center security perimeters, multi-tenant service provider edge gateways, and high-volume remote access VPN environmentsCisco.
2. Chassis, Hardware & Base I/O Specifications
Chassis Form Factor
-
Rack unit size: Standard 2RU EIA 19-inch rack-mount chassis
-
Dual hot-swappable module slots: Slot0 = Main Firewall/VPN SSP; Slot1 = Optional IPS SSP, CX SSP or FirePOWER expansion blade
-
Base fixed I/O on standalone SSP-40 blade: 6 × 10/100/1000BASE-T copper Gigabit Ethernet ports + 4 × SFP+ 10 Gigabit Ethernet fiber uplink ports (higher fiber density than SSP-10/SSP-20) + 2 dedicated Gigabit Ethernet management portsCisco.
-
Expansion port capacity: When paired with matching IPS SSP-40 blade in Slot1, total interface count expands to 20 ports (16 × GbE copper + 4 × 10G SFP+ fiber)Cisco.
Compute, Memory & Crypto Hardware
-
CPU Architecture: Dual multi-core high-performance processors (four total CPU cores when deployed with IPS SSP-40)Cisco
-
System DRAM: 24 GB onboard memory, double the memory capacity of SSP-20 (12GB)Cisco
-
Onboard flash storage: 8 GB internal flash for ASA OS firmware, configuration files, system logs and threat signature databases
-
Crypto Acceleration: Six dedicated embedded hardware crypto accelerators, exceeding SSP-20’s four accelerators, fully offloading AES, 3DES, RSA, ECC encryption and hashing workloads without consuming general-purpose CPU resourcesCisco.
Power & Thermal Design
-
Standard base chassis configuration: Single AC power supply module + single hot-swappable fan tray
-
Redundancy support: Replace the standard fan tray with a secondary redundant AC power supply module to implement fully redundant load-sharing power input for production high-availability environments
-
Cooling architecture: Front-to-back forced airflow, fully compatible with standard data center hot/cold aisle rack layout standardsCisco.
3. Official Performance Benchmarks (SSP-40 Tier)
-
Stateful firewall throughput: Up to 15 Gbps
-
Standalone AVC application visibility & control throughput: 10 Gbps
-
Combined AVC + FirePOWER NGIPS integrated threat defense throughput: 6 Gbps
-
3DES/AES IPsec site-to-site VPN throughput: Up to 3 Gbps
-
Maximum concurrent TCP/UDP active sessions: 1,800,000 simultaneous sessions
-
New TCP/UDP connection establishment rate: Up to 120,000 new sessions per second
-
Supported logical VLAN segmentation interfaces: 1,024 independent VLANs
-
Maximum IPsec site-to-site VPN tunnels: 10,000 tunnels
-
Concurrent Cisco AnyConnect SSL VPN remote workforce peers: Up to 10,000 simultaneous mobile/remote access users
-
Application identification library: Recognizes more than 3,000 distinct network applications for granular per-application bandwidth shaping, access blocking and logging
-
URL filtering database: 80+ web content categories, over 280 million classified websites for internet content controlCisco.
4. Integrated Security & Networking Feature Suite
Core Stateful Firewall Functions
-
Full stateful packet inspection (SPI) for TCP, UDP, ICMP and all standard IP network protocols
-
Multi-context virtual firewall mode: Partition one physical ASA appliance into up to 250 fully isolated independent virtual firewalls for multi-tenant business unit and customer segmentation
-
Object-group ACL policy management, time-based access control rules and modular policy frameworks
-
Comprehensive NAT services: Static NAT, dynamic PAT, large-scale carrier-grade LSN NAT, NAT64 for seamless IPv4/IPv6 dual-stack network migration.
Enterprise & Service Provider VPN Encryption Services
-
IPsec site-to-site VPN tunnels with AES-256, 3DES, SHA-256 encryption and hashing algorithms
-
Cisco AnyConnect Secure Mobility SSL VPN for remote workforce, cross-platform support for Windows, macOS, iOS, Android endpoints
-
DMVPN Dynamic Multipoint VPN for hub-spoke enterprise WAN architectures
-
Hardware-accelerated crypto offload eliminates CPU bottlenecks under high-volume concurrent VPN tunnel traffic loads
Application Visibility & Advanced Threat Defense
-
Cisco AVC (Application Visibility and Control): Deep packet inspection to identify thousands of applications, with per-application bandwidth shaping, access blocking, logging and QoS policy enforcement
-
Optional FirePOWER Next-Generation IPS (NGIPS): Install matching IPS SSP-40 expansion blade in Slot1 to add intrusion prevention, malware threat protection, URL web filtering, encrypted traffic inspection and advanced threat analytics
-
Cisco Cloud Web Security integration to forward internet web traffic to cloud-based security scanning for additional malware and content filtering
Routing & Dual-Stack Network Integration
-
Full support for static routing, RIP v1/v2, OSPF, EIGRP, BGP dynamic routing protocols
-
Integrated Routing and Bridging (IRB) for transparent firewall mode deployments
-
Complete IPv4 / IPv6 dual-stack protocol support for smooth enterprise network IPv6 migration
5. Carrier-Grade High Availability Capabilities
-
Active/Standby & Active/Active Firewall Failover
Supports dual ASA 5585-X appliances deployed as HA failover pairs for zero downtime during hardware faults, firmware upgrades or scheduled maintenance. Stateful session synchronization preserves all active user VPN and data sessions during failover switchover.
-
OIR Online Insertion and Removal
All SSP compute blades, IPS threat expansion blades, power supply modules and fan trays support full hot-swap replacement without full chassis power shutdown; existing firewall forwarding traffic remains uninterrupted during component maintenance.
-
ISSU In-Service Software Upgrade
Non-disruptive ASA OS firmware upgrades across HA firewall clusters, eliminating full network security outage during operating system version updates.
-
Synchronized Configuration & Centralized Logging
Automatic configuration synchronization between HA paired firewalls; centralized event logging support for syslog servers, Cisco Security Manager, and FireSIGHT Management Center for unified global policy control and cross-network threat reporting.
6. Physical & Environmental Specifications
SSP Module Physical Dimensions
-
Width: 43.69 cm (19 inches)
-
Depth: 39.62 cm
-
Height: 4.32 cm
-
Single SSP-40 module net weight: 5.2 kg
Full Chassis Dimensions
-
Chassis total size: 48.3 cm (W) × 67.3 cm (D) × 8.8 cm (H) (2RU rack height)
-
Chassis weight (single SSP + single power supply): 22.7 kg
-
Chassis weight (dual SSP blades + dual redundant power supplies): 28.2 kg
Operating Environmental Parameters
-
Standard data center operating temperature range: 5°C to 40°C (41°F ~ 104°F)
-
Short-term extended operating temperature: -5°C to 55°C (23°F ~ 131°F), maximum continuous runtime 96 hours, annual cumulative usage limit 15 days
-
Continuous operating relative humidity: 10% – 85% non-condensing; storage & transit humidity: 5% – 95% non-condensing
-
Storage & transit temperature range: -40°C to 70°C (-40°F ~ 158°F)Cisco.
7. Regulatory & Global Compliance Certifications
-
Electrical Safety Standards: UL 60950-1, CSA C22.2 No.60950-1, IEC 60950, EN 60950-1
-
Laser Safety Certification: IEC/EN 60825 for front-panel SFP+ 10G optical transceivers
-
EMC & EMI Electromagnetic Compatibility: FCC Part 15 Class A, ICES-003 Class A, VCCI Class A, CISPR 22 (EN55022) Class A, CISPR 24, full EN 61000 series ESD, electrical surge, radiated & conducted immunity compliance
-
Telecom Carrier Industry Standards: NEBS Level 3 (GR-63-Core environmental protection, GR-1089-Core EMC and safety specifications)
-
Cryptographic Security Compliance: FIPS 140-2 validated cryptographic module for government, financial and regulated industry deployments
-
Environmental Directives: EU RoHS hazardous substance restriction compliance, EU WEEE waste electrical and electronic equipment recycling directive compliant
8. Key Deployment Advantages
-
Converged All-in-One Unified Security Platform
Consolidates discrete firewall, VPN, application control and optional NGIPS threat defense onto a single 2RU rack appliance, drastically reducing physical rack space occupation, total power consumption and multi-device daily management overhead compared to separate standalone security hardware.
-
Modular Scalable Dual-Slot Chassis Architecture
The two-slot chassis design enables incremental capacity expansion without full hardware replacement: add matching IPS SSP-40 expansion blades to enable full threat prevention, or deploy high-density I/O expansion cards to scale Ethernet port counts as network traffic volume and subscriber user base grow. Only identical tier SSP blades can coexist in one chassis (SSP-40 paired only with IPS SSP-40).
-
High-Density Hardware Crypto & Multi-Core Offloading
Six dedicated encryption accelerators and dual multi-core compute architecture fully offload resource-intensive VPN encryption and deep packet inspection workloads from general-purpose CPUs, maintaining consistent maximum forwarding throughput even under full comprehensive security policy enforcement.
-
Flexible Multi-Tenant Virtualization Capability
Multi-context virtual firewall mode enables service providers and large enterprise organizations to split one physical ASA appliance into fully isolated independent security domains for different business divisions, separate customer tenants or segmented network zones, maximizing hardware asset utilization efficiency.
-
Unified Centralized Enterprise-Grade Management
Fully compatible with Cisco Security Manager for centralized global firewall policy administration and FireSIGHT Management Center for unified NGIPS threat visibility, event correlation and compliance reporting across distributed fleets of ASA security appliances.
-
Long-Term Investment Protection
Fully interoperable with the complete ASA 5585-X accessory ecosystem including IPS SSP expansion blades, 1G/10G I/O expansion cards, redundant power supplies, and all compatible SFP/SFP+ optical transceivers; existing compatible hardware accessories can be fully reused during network security capacity expansion upgrades.
9. Standard Factory Packaging Contents
-
ASA 5585-X 2RU chassis pre-installed with SSP-40 main security services processor module
-
ESD anti-static protective transport bag for SSP compute modules
-
Standard 19-inch rack mounting brackets and all installation screws
-
Blank filler panels for unused chassis slots and empty SFP/SFP+ optical ports
-
Hardware installation quick start guide (covers rack mounting, SSP module OIR hot-swap, front panel LED alarm status troubleshooting procedures)
-
Global regulatory compliance documentation packet (safety, EMC, NEBS, FIPS, RoHS certification documents)
-
Dual ejector lever assemblies pre-installed on the SSP module front panel for simple chassis slot insertion and removal
Supplementary UNSPSC Classification Code
43222501 – Cisco ASA 5585-X SSP-40 modular next-generation adaptive security appliance, 2RU dual-slot chassis firewall/VPN compute module with 6×GbE copper + 4×10G SFP+ base I/O, six dedicated hardware crypto accelerators, 24GB onboard DRAM, integrated AVC application control, optional matching IPS SSP-40 expansion slot for FirePOWER NGIPS threat defense, designed for large enterprise campus core networks, mid-sized data center perimeter security and multi-service provider edge gateway deployments.
Standard Hardware Warranty
All factory-new ASA 5585-X SSP-40 security appliances include a 1-year limited hardware warranty covering manufacturing defects and component failures under rated standard operating environmental conditions. Optional extended 3-year / 5-year Cisco SMARTnet service contracts are available, providing 24×7 priority Cisco TAC engineering technical support, advance genuine Cisco hardware replacement service, validated stable ASA OS firmware upgrade releases, and comprehensive firewall, VPN, AVC and NGIPS security policy configuration and network troubleshooting support throughout the multi-year hardware operational lifecycle.
|