Cisco ASA5585-X-SSP60 Full Official Product Description
1. Product Overview & Model Naming Definition
Official Full Name
Cisco ASA 5585-X Adaptive Security Appliance with Security Services Processor 60 (SSP-60), Part Number:ASA5585-X-SSP60
Model Breakdown
-
ASA: Adaptive Security Appliance, Cisco enterprise & data center next-generation firewall (NGFW) platform
-
5585-X: Flagship high-performance modular 2RU dual-slot chassis, designed for large data center perimeters, multi-tenant service provider edge, and large enterprise campus core security deployments
-
SSP: Security Services Processor, primary compute blade integrating stateful firewall, IPsec/SSL VPN, routing, AVC application visibility & control
-
60: Top-tier flagship performance compute module, the highest-spec SSP in the ASA 5585-X series, equipped with quad-core CPUs, maximum memory capacity, eight dedicated hardware crypto accelerators, and high-density 10G fiber uplinksCisco
Core Positioning
The Cisco ASA 5585-X SSP-60 is Cisco’s highest-performance modular NGFW within the ASA 5585-X 2RU dual-slot chassis. The SSP-60 occupies the mandatory bottom Slot 0 as the primary firewall/VPN compute blade, delivering industry-leading throughput, massive concurrent session capacity, integrated AVC deep application inspection, and optional FirePOWER Next-Generation IPS (NGIPS) threat defense by installing a matching IPS SSP-60 expansion blade in vacant upper Slot 1Cisco.
This flagship platform targets high-throughput data center security boundaries, multi-service provider multi-tenant edge gateways, large global enterprise headquarters, and environments requiring massive remote access SSL VPN capacity and integrated advanced threat prevention.
Discontinuation Note
The Cisco ASA 5585-X series including SSP-60 reached End-of-Sale effective October 7, 2020.
2. Chassis, Hardware & Base I/O Specifications
Chassis Form Factor
-
Rack unit size: Standard 2RU EIA 19-inch rack-mount chassis
-
Dual module slots (non-hot-swappable SSP blades; chassis power down required for SSP replacement):
-
Slot 0 (Bottom): Mandatory primary SSP-60 firewall/VPN blade
-
Slot 1 (Top): Optional matching IPS/FirePOWER SSP-60 blade for integrated NGIPS threat defense
-
Built-in dedicated out-of-band management ports: 2 independent Gigabit Ethernet management interfaces (Management 0/0, Management 0/1) for box-only administrative traffic, plus RJ45 console & auxiliary serial portCisco
Base Fixed I/O on Standalone SSP-60 Blade
-
6 × 10/100/1000BASE-T copper Gigabit Ethernet ports
-
4 × SFP+ 10 Gigabit Ethernet dual uplink fiber ports (supports 1G SFP or 10G SFP+ transceivers, transceivers sold separately)Cisco
-
Total base interface count: 10 data ports
-
Full dual SSP configuration (SSP-60 + IPS SSP-60): Total 20 interfaces (16 × GbE copper + 4 × 10G SFP+ fiber)Cisco
Compute, Memory & Crypto Hardware
-
CPU Architecture: Quad multi-core high-performance processors (4 total CPUs) for maximum packet processing throughputCisco
-
System DRAM: 24 GB onboard memory for standalone single SSP-60 chassis; expands to 72 GB total system memory when paired with matching IPS SSP-60 blade in Slot 1Cisco
-
Onboard flash storage: 2 GB internal flash for ASA OS firmware, device configurations, system logs; dual SSP chassis expands total flash capacity to 4 GBCisco
-
Crypto Acceleration: Eight dedicated embedded hardware crypto accelerators (the highest count among all ASA 5585-X SSP tiers) for fully offloaded AES-256, 3DES, RSA, ECC encryption and SHA hashing, eliminating general CPU resource consumption for high-volume VPN trafficCisco
Power & Thermal Design
-
Standard chassis configuration: Dual load-sharing redundant AC power supply modules factory-shipped with SSP-60 units (recommended for production HA deployments)Cisco
-
Fan tray design: Hot-swappable fan assembly for thermal cooling; fan tray can be replaced with a secondary power supply for fully redundant power input
-
Cooling architecture: Front-to-back forced airflow, fully compatible with standard data center hot/cold aisle rack layout standards
3. Official Verified Performance Benchmarks (SSP-60 Flagship Tier)
-
Stateful firewall throughput (64-byte small packet testing): Up to 20 Gbps; cluster scaling up to 128 Gbps with 8-node ASA 5585-X SSP-60 clusterCisco
-
Standalone AVC application visibility & control throughput: 15 GbpsCisco
-
Combined integrated AVC + FirePOWER NGIPS threat defense throughput: 10 GbpsCisco
-
3DES/AES IPsec site-to-site VPN throughput: Up to 5 Gbps
-
Maximum concurrent active TCP/UDP sessions: 4,000,000 simultaneous sessions (the maximum capacity of the entire ASA 5585-X platform lineup)Cisco
-
New TCP/UDP connection establishment rate: Up to 160,000 new sessions per secondCisco
-
Supported logical VLAN segmentation interfaces: 1,024 independent VLANs for multi-zone network isolation
-
Maximum IPsec site-to-site VPN tunnels: 10,000 persistent tunnels
-
Concurrent Cisco AnyConnect Secure Mobility SSL VPN remote workforce peers: Up to 10,000 simultaneous mobile/remote access users
-
Application identification library: Recognizes more than 3,000 distinct network applications for granular per-application bandwidth shaping, access blocking, logging and QoS policy enforcement
-
URL web filtering database: 80+ web content categories, over 280 million classified public websites for internet content control and compliance filteringCisco
4. Integrated Security & Networking Feature Suite
Core Stateful Firewall Functions
-
Full stateful packet inspection (SPI) for TCP, UDP, ICMP and all standard IPv4/IPv6 network protocols
-
Multi-context virtual firewall mode: Partition one physical ASA appliance into up to 250 fully isolated independent virtual firewalls for multi-tenant business unit and customer network segmentation
-
Object-group ACL policy management, time-based access control rules and modular unified policy frameworks
-
Comprehensive NAT services: Static NAT, dynamic PAT, large-scale carrier-grade LSN NAT, NAT64 for seamless IPv4/IPv6 dual-stack enterprise network migration
Enterprise & Service Provider VPN Encryption Services
-
IPsec site-to-site VPN tunnels with AES-256, 3DES, SHA-256 encryption and hashing algorithms
-
Cisco AnyConnect Secure Mobility SSL VPN for distributed remote workforce, cross-platform endpoint support for Windows, macOS, iOS, Android operating systems
-
DMVPN Dynamic Multipoint VPN for hub-spoke enterprise wide-area network architectures
-
Full hardware-accelerated crypto offload eliminates CPU bottlenecks under high-volume concurrent VPN tunnel traffic loads
Application Visibility & Advanced Threat Defense
-
Cisco AVC (Application Visibility and Control): Deep full packet inspection to identify thousands of applications, with per-application bandwidth shaping, access blocking, event logging and granular QoS policy enforcement
-
Optional FirePOWER Next-Generation IPS (NGIPS): Install matching IPS SSP-60 expansion blade in Slot1 to add intrusion prevention, advanced malware threat protection, URL web filtering, encrypted traffic inspection and global threat analytics
-
Cisco Cloud Web Security integration to forward internet web traffic to cloud-based security scanning for additional malware and content compliance filtering
Routing & Dual-Stack Network Integration
-
Full support for static routing, RIP v1/v2, OSPF, EIGRP, BGP dynamic routing protocols
-
Integrated Routing and Bridging (IRB) for transparent firewall mode deployments
-
Complete IPv4 / IPv6 dual-stack protocol support for smooth enterprise network IPv6 migration
5. Carrier-Grade High Availability Capabilities
-
Active/Standby & Active/Active Firewall Failover
Supports dual ASA 5585-X appliances deployed as HA failover pairs for zero downtime during hardware faults, firmware upgrades or scheduled maintenance. Stateful full session synchronization preserves all active user VPN and data forwarding sessions during failover switchover.
-
ISSU In-Service Software Upgrade
Non-disruptive ASA OS firmware upgrades across HA firewall clusters, eliminating full network security outage during operating system version updates.
-
Synchronized Configuration & Centralized Logging
Automatic configuration synchronization between HA paired firewalls; centralized event logging support for syslog servers, Cisco Security Manager, and FireSIGHT Management Center for unified global policy control and cross-network threat reporting.
6. Physical & Environmental Specifications
SSP-60 Module Physical Dimensions
-
Width: 43.69 cm (19 inches)
-
Depth: 39.62 cm
-
Height: 4.32 cm
-
Single SSP-60 module net weight: 5.2 kg
Full Chassis Dimensions
-
Chassis total size: 48.3 cm (W) × 67.3 cm (D) × 8.8 cm (H) (2RU rack height)
-
Chassis weight (single SSP-60 + dual redundant power supplies): 28.2 kg
Operating Environmental Parameters
-
Standard data center operating temperature range: 0°C to 40°C (32°F ~ 104°F)
-
Short-term extended operating temperature: -5°C to 55°C (23°F ~ 131°F), maximum continuous runtime 96 hours, annual cumulative usage limit 15 days
-
Continuous operating relative humidity: 10% – 90% non-condensing; storage & transit humidity: 5% – 95% non-condensing
-
Storage & transit temperature range: -40°C to 70°C (-40°F ~ 158°F)
7. Regulatory & Global Compliance Certifications
-
Electrical Safety Standards: UL 60950-1, CSA C22.2 No.60950-1, IEC 60950, EN 60950-1
-
Laser Safety Certification: IEC/EN 60825 for front-panel SFP+ 10G optical transceivers
-
EMC & EMI Electromagnetic Compatibility: FCC Part 15 Class A, ICES-003 Class A, VCCI Class A, CISPR 22 (EN55022) Class A, CISPR 24, full EN 61000 series ESD, electrical surge, radiated & conducted immunity compliance
-
Telecom Carrier Industry Standards: NEBS Level 3 (GR-63-Core environmental protection, GR-1089-Core EMC and safety specifications)
-
Cryptographic Security Compliance: FIPS 140-2 validated cryptographic module for government, financial and regulated industry deployments
-
Environmental Directives: EU RoHS hazardous substance restriction compliance, EU WEEE waste electrical and electronic equipment recycling directive compliant
8. Key Deployment Advantages
-
Flagship Converged All-in-One Unified Security Platform
Consolidates discrete high-throughput firewall, enterprise VPN, deep application control and optional full NGIPS threat defense onto a single compact 2RU rack appliance, drastically reducing physical rack space occupation, total power consumption and multi-device daily management overhead compared to separate standalone security hardware clusters.
-
Modular Scalable Dual-Slot Chassis Architecture
The two-slot chassis design enables incremental capacity expansion without full hardware replacement: add matching IPS SSP-60 expansion blades to enable full integrated threat prevention, no chassis replacement required. Only identical tier SSP blades can coexist in one chassis (SSP-60 paired exclusively with IPS SSP-60).
-
Maximum-Density Hardware Crypto & Multi-Core Offloading
Eight dedicated encryption accelerators and quad multi-core compute architecture fully offload resource-intensive VPN encryption and deep packet inspection workloads from general-purpose CPUs, maintaining consistent maximum forwarding throughput even under full comprehensive security policy enforcement and maximum concurrent subscriber load.
-
Flexible Multi-Tenant Virtualization Capability
Multi-context virtual firewall mode enables service providers and large enterprise organizations to split one physical ASA appliance into fully isolated independent security domains for different business divisions, separate customer tenants or segmented network zones, maximizing hardware asset utilization efficiency.
-
Unified Centralized Enterprise-Grade Management
Fully compatible with Cisco Security Manager for centralized global firewall policy administration and FireSIGHT Management Center for unified NGIPS threat visibility, event correlation and compliance reporting across distributed fleets of ASA security appliances.
-
Long-Term Investment Protection
Fully interoperable with the complete ASA 5585-X accessory ecosystem including IPS SSP expansion blades, 1G/10G I/O expansion cards, redundant power supplies, and all compatible SFP/SFP+ optical transceivers; existing compatible hardware accessories can be fully reused during network security capacity expansion upgrades.
9. Standard Factory Packaging Contents
-
ASA 5585-X 2RU chassis pre-installed with SSP-60 main security services processor module
-
Dual factory-shipped redundant AC power supply modules
-
ESD anti-static protective transport bag for SSP compute modules
-
Standard 19-inch rack mounting brackets and all installation screws
-
Blank filler panels for unused chassis slots and empty SFP/SFP+ optical ports
-
Hardware installation quick start guide (covers rack mounting, SSP module installation procedures, front panel LED alarm status troubleshooting procedures)
-
Global regulatory compliance documentation packet (safety, EMC, NEBS, FIPS, RoHS certification documents)
-
Dual ejector lever assemblies pre-installed on the SSP module front panel for simple chassis slot insertion and removal
Supplementary UNSPSC Classification Code
43222501 – Cisco ASA 5585-X SSP-60 flagship modular next-generation adaptive security appliance, 2RU dual-slot chassis firewall/VPN compute module with 6×GbE copper + 4×10G SFP+ base I/O, eight dedicated hardware crypto accelerators, 24GB onboard DRAM, integrated AVC application control, optional matching IPS SSP-60 expansion slot for FirePOWER NGIPS integrated threat defense, designed for high-throughput data center perimeter security, multi-service provider multi-tenant edge gateways and large global enterprise headquarters deployments.
Standard Hardware Warranty
All factory-new ASA 5585-X SSP-60 security appliances include a 1-year limited hardware warranty covering manufacturing defects and component failures under rated standard operating environmental conditions. Optional extended 3-year / 5-year Cisco SMARTnet service contracts are available, providing 24×7 priority Cisco TAC engineering technical support, advance genuine Cisco hardware replacement service, validated stable ASA OS firmware upgrade releases, and comprehensive firewall, VPN, AVC and NGIPS security policy configuration and network troubleshooting support throughout the multi-year hardware operational lifecycle.
|