Homepage | Collection | 繁体中文
Product
没有小类
没有小类
没有小类
没有小类
没有小类
没有小类
没有小类
没有小类
H3C
没有小类
没有小类
没有小类
没有小类
没有小类
没有小类
Contact Us


Company Name:Kino Technology Limited

Website:www.kino86.com

Address :Room 312, Honghua Building, No. 1 Guangyayuan Road, Bantian Street, Longgang District, Shenzhen city, Guangdong Province, China



Contact Person:kiki

Tel :+8613040881925 

E-mail:kiki@szkiki.com

Wechat:+8613040881925

Whatspp: +8613040881925

Teams:kiki@szkiki.com





Products
 Product >> Cisco >> ALL
 
Product_Id:
7291303716
ProductName:
ASA5580-SSP20
Specification:
Product Notes:
Product Category:
Cisco
 
   Product Description

Cisco ASA5580-SSP20 Full Official Product Description

Model Clarification

Cisco ASA 5580 series is a legacy 4RU rack-mount security platform released before the ASA 5585-X modular blade architecture. The naming ASA5580-SSP20 refers to the ASA 5580-20 performance tier. Unlike the ASA 5585-X with hot-swappable SSP blades, the ASA 5580 integrates the security processor onto a fixed motherboard without separate pluggable SSP modules. This hardware platform reached End-of-Sale (EoS) on September 10, 2007, and all technical support has expired.

1. Product Overview & Naming Breakdown

Official Full Name

Cisco ASA 5580-20 High Performance Adaptive Security Appliance (market alias: ASA5580-SSP20)

Naming Explanation

  1. ASA: Adaptive Security Appliance, Cisco unified firewall and VPN security platform
  2. 5580: Legacy top-tier 4RU high-throughput security chassis for large data centers and service provider edge networks
  3. SSP20 / 20: Mid-high performance processing tier with dedicated crypto and multi-core packet processing hardware

Core Positioning

The Cisco ASA 5580-20 (ASA5580-SSP20) is a high-capacity integrated next-generation firewall designed for large enterprise headquarters, core campus networks, data center perimeters, and multi-tenant service provider edge deployments. It combines stateful firewall, IPsec/SSL remote access VPN, deep packet inspection, and hardware-accelerated encryption in a single 4RU rack unit chassis. It serves as a predecessor to the modular ASA 5585-X platform.

2. Chassis, I/O and Hardware Specifications

Chassis Form Factor

  • Rack size: 4RU standard 19-inch EIA rack-mount chassis
  • Chassis architecture: Fixed integrated mainboard (no removable SSP blades)
  • Built-in management interfaces: RJ45 console port, auxiliary port, two dedicated Gigabit Ethernet out-of-band management ports

Fixed Front Panel I/O Ports

  • 8 × 10/100/1000BASE-T copper Gigabit Ethernet data interfaces
  • 4 × SFP slots supporting 1G fiber transceivers (SFP modules sold separately)

Memory, Storage and Crypto Hardware

  • System DRAM: 12 GB high-speed memory for session table storage and deep packet inspection
  • Internal flash storage: 2 GB flash memory for ASA OS firmware, device configurations, system logs and signature databases
  • Dedicated hardware crypto accelerators: Four independent encryption engines for full offloading of AES, 3DES, RSA and ECC encryption and SHA hash algorithms, eliminating CPU bottlenecks under heavy VPN traffic loads
  • CPU architecture: Dual multi-core general-purpose processors for high-volume packet forwarding and security policy processing

Power and Thermal Design

  • Standard configuration: Single AC power supply plus hot-swappable fan tray
  • Redundancy option: Dual load-sharing redundant AC power supplies for production high-availability environments
  • Cooling design: Front-to-back forced airflow, compatible with standard data center hot and cold aisle rack layouts
  • All fan trays and power supplies support hot-swap replacement without full chassis power shutdown

3. Official Performance Benchmarks (Tier 20)

  1. Stateful firewall throughput: Up to 10 Gbps
  2. IPsec 3DES/AES VPN throughput: Up to 2 Gbps
  3. Maximum concurrent TCP/UDP active sessions: 1,000,000 simultaneous sessions
  4. New connection establishment rate: Up to 75,000 new sessions per second
  5. Supported logical VLAN interfaces: 1,024 segmented VLANs
  6. Maximum site-to-site IPsec VPN tunnels: 10,000 persistent tunnels
  7. Concurrent Cisco AnyConnect SSL VPN remote access users: Up to 7,500 simultaneous endpoints
  8. Application recognition: Support for thousands of network applications for granular bandwidth control and access filtering

4. Integrated Security and Networking Feature Set

Core Stateful Firewall Functions

  • Full stateful packet inspection (SPI) for TCP, UDP, ICMP and all standard IPv4 protocols
  • Multi-context virtual firewall mode to split one physical appliance into multiple isolated security domains for multi-tenant environments
  • Object-group access control lists, time-based access policies, modular policy frameworks
  • Comprehensive NAT functionality: Static NAT, dynamic PAT, large-scale LSN carrier-grade NAT and NAT64 for IPv4/IPv6 transition

Enterprise and Service Provider VPN Services

  • Site-to-site IPsec VPN tunnels with AES-256, 3DES, SHA-256 encryption and hash algorithms
  • Cisco AnyConnect Secure Mobility SSL VPN for distributed remote workforces, compatible with Windows, macOS, iOS and Android endpoints
  • DMVPN Dynamic Multipoint VPN for hub-and-spoke enterprise WAN architectures
  • Hardware crypto offload ensures stable throughput under massive concurrent VPN tunnel loads

Application Visibility and Threat Defense

  • Deep packet inspection for application identification, bandwidth shaping, traffic blocking and logging per application
  • Optional Cisco IPS module expansion for integrated intrusion prevention, malware detection and URL web content filtering
  • Integration with Cisco Cloud Web Security for additional cloud-based malware and content compliance scanning

Routing and Network Integration

  • Full support for static routing, RIP v1/v2, OSPF, EIGRP and BGP dynamic routing protocols
  • Integrated routing and bridging (IRB) for transparent firewall mode deployments
  • Native IPv4 / IPv6 dual-stack protocol support for seamless enterprise IPv6 migration

5. High Availability Carrier-Grade Capabilities

  1. Active/Standby and Active/Active Firewall Failover
    Dual ASA 5580 appliances can be deployed as HA failover pairs to eliminate downtime during hardware faults, firmware upgrades or scheduled maintenance. Stateful session synchronization preserves all active data and VPN sessions during switchover.
  2. Hot-Swap Replaceable Components
    All power supply units and fan trays support online hot-swap replacement without shutting down the entire chassis; existing forwarding traffic remains uninterrupted during component maintenance.
  3. ISSU In-Service Software Upgrade
    Non-disruptive ASA operating system firmware upgrades across HA firewall clusters, avoiding full network security outages during OS version updates.
  4. Synchronized Configuration and Centralized Logging
    Automatic configuration synchronization between paired HA firewalls; centralized event logging support for external syslog servers, Cisco Security Manager and IPS management platforms for unified global policy control and cross-network threat reporting.

6. Physical and Environmental Specifications

Physical Dimensions & Weight

  • Chassis dimensions: 48.3 cm width × 76.2 cm depth × 17.8 cm height (4RU rack unit)
  • Chassis weight (single power supply): 31.8 kg
  • Chassis weight (dual redundant power supplies): 36.3 kg

Operating Environmental Parameters

  • Standard data center operating temperature range: 5°C to 40°C (41°F ~ 104°F)
  • Short-term extended operating temperature: -5°C to 55°C (23°F ~ 131°F), maximum continuous runtime 96 hours, annual cumulative limit 15 days
  • Operating relative humidity: 10% – 85% non-condensing
  • Storage and transit humidity: 5% – 95% non-condensing
  • Storage and transit temperature range: -40°C to 70°C (-40°F ~ 158°F)

7. Global Regulatory & Compliance Certifications

  1. Electrical Safety Standards: UL 60950-1, CSA C22.2 No.60950-1, IEC 60950, EN 60950-1
  2. Laser Safety Certification: IEC/EN 60825 for SFP fiber optical transceivers
  3. EMC & EMI Electromagnetic Compatibility: FCC Part 15 Class A, ICES-003 Class A, VCCI Class A, CISPR 22 Class A, CISPR 24, full EN 61000 series ESD, surge, radiated and conducted immunity compliance
  4. Telecom Carrier Industry Standards: NEBS Level 3 (GR-63-Core environmental protection, GR-1089-Core EMC and safety specifications)
  5. Cryptographic Security Compliance: FIPS 140-2 validated cryptographic module for government, financial and regulated industry deployments
  6. Environmental Directives: EU RoHS hazardous substance restriction compliance, EU WEEE waste electrical and electronic equipment recycling directive compliant

8. Key Deployment Advantages

  1. Unified All-In-One Converged Security Platform
    Combines standalone firewall, VPN gateway and optional IPS threat defense functions into a single 4RU rack appliance, drastically reducing rack space occupation, power consumption and multi-device daily management overhead compared to discrete separate security hardware.
  2. Integrated High-Density Hardware Crypto Offloading
    Four dedicated independent encryption accelerators fully offload resource-intensive VPN encryption and deep packet inspection workloads from general-purpose CPUs, maintaining consistent maximum forwarding throughput even under full comprehensive security policy enforcement and peak user traffic loads.
  3. Flexible Multi-Tenant Virtualization Capability
    Multi-context virtual firewall mode enables service providers and large enterprise organizations to partition one physical ASA chassis into fully isolated independent security domains for different business divisions, separate customer tenants or segmented network zones, maximizing hardware asset utilization efficiency.
  4. Centralized Unified Enterprise-Grade Management
    Fully compatible with Cisco Security Manager for centralized global firewall policy administration and dedicated IPS management platforms for unified threat visibility, event correlation and compliance reporting across distributed fleets of ASA security appliances.
  5. Mature Interoperable Accessory Ecosystem
    Fully compatible with all dedicated ASA 5580 accessories including IPS expansion modules, redundant power supply units and all standard 1G SFP optical transceivers; all compatible hardware accessories can be reused during network security capacity expansion upgrades.

9. Standard Factory Packaging Contents

  1. ASA 5580-20 4RU rack-mount chassis with fully integrated tier 20 security processing hardware
  2. Single factory-installed AC power supply module
  3. Standard 19-inch rack mounting brackets and all installation screws
  4. Blank filler panels for unused SFP optical ports
  5. ESD anti-static wrist strap for hardware maintenance operations
  6. Hardware installation quick start guide (covers rack mounting, component hot-swap replacement and front panel LED alarm status troubleshooting procedures)
  7. Global regulatory compliance documentation packet (safety, EMC, NEBS, FIPS, RoHS certification documents)

Supplementary UNSPSC Classification Code

43222501 – Cisco ASA 5580-20 (ASA5580-SSP20) legacy high-performance integrated adaptive security appliance, 4RU fixed chassis firewall/VPN gateway with 8×GbE copper + 4×1G SFP I/O, four dedicated hardware crypto accelerators, 12GB onboard DRAM, multi-context virtual firewall support, optional integrated IPS expansion capability, designed for large enterprise campus core networks, data center perimeter security and multi-service provider edge gateway deployments.

Standard Hardware Warranty

All factory-new ASA 5580-20 security appliances include a 1-year limited hardware warranty covering manufacturing defects and component failures under rated standard operating environmental conditions. Cisco SMARTnet extended service contracts were previously available during the product lifecycle to provide 24×7 priority Cisco TAC engineering technical support, advance genuine Cisco hardware replacement service, validated stable ASA OS firmware upgrade releases, and comprehensive firewall, VPN and IPS security policy configuration and network troubleshooting support. This product line has reached end-of-support, and no new SMARTnet contracts can be purchased.
Click:3 Entry Time:2026-07-29 【Print】 【Close
 © 2026 Kino Technology Limited. All Rights Reserved. | Hong Kong Registered · Shenzhen Operation | New & Genuine Used Network Equipment Supplier 
Links:   白云搜搜   |   未来互联   |   百度   |  
Kino Technology Limited   网站技术支持:未来互联