Cisco ASA5580-SSP40 Full Official Product Description
Critical Model Clarification
Cisco ASA5580-SSP40 is the market alias forCisco ASA 5580-40, a legacy fixed-chassis high-performance adaptive security appliance, completely different from the later modular 2RU ASA 5585-X with removable SSP blades. The ASA 5580 series uses an integrated motherboard without hot-swappable security processor blades. This product reached End-of-Sale (EoS) on September 10, 2007, and all official technical support has expired.
1. Product Overview & Naming Breakdown
Official Full Name
Cisco ASA 5580-40 High-Performance Adaptive Security Appliance (Marketing Alias: ASA5580-SSP40)
Naming Definition
-
ASA: Adaptive Security Appliance, Cisco unified all-in-one firewall and VPN security platform
-
5580: Legacy flagship 4RU rack-mount high-throughput security chassis designed for large data centers and service provider edge networks
-
SSP40 / 40: Top-tier quad-core multiprocessor performance tier with enhanced packet processing and memory capacity compared to ASA 5580-20
Core Positioning
The Cisco ASA 5580-40 (ASA5580-SSP40) is Cisco’s highest-capacity integrated next-generation firewall of the ASA 5580 product line. It unifies stateful firewall, IPsec/SSL remote access VPN, multi-context virtual security, and hardware-accelerated encryption within a single 4RU rack unit chassis. Target deployment scenarios include large enterprise headquarters, core campus networks, high-traffic data center perimeters, and multi-tenant service provider edge gateways.
2. Chassis, I/O and Hardware Specifications
Chassis Form Factor
-
Rack size: 4RU standard 19-inch EIA rack-mount chassis
-
Architecture: Fixed integrated mainboard with 4 dedicated multicore processors (double the 2 processors of ASA 5580-20)
-
Built-in management interfaces: 2 independent Gigabit Ethernet out-of-band management ports, RJ45 console port, auxiliary serial port
-
Expansion slots: 6 PCI-based interface card slots for flexible port expansionCisco
Supported Interface Card Options
-
4×10/100/1000BASE-T copper Gigabit Ethernet card
-
4×1G SFP fiber Gigabit Ethernet card (SR LC transceivers)
-
2×10G SFP+ fiber 10-Gigabit Ethernet card (SR LC transceivers)
Base bundled variants:
-
ASA5580-40-8GE-K9: Pre-installed 8-port copper Gigabit Ethernet
-
ASA5580-40-10GE-K9: Pre-installed 4-port 10-Gigabit Ethernet fiberCisco
Memory, Storage and Crypto Hardware
-
System DRAM: 12 GB high-speed memory (8 GB on ASA 5580-20) for massive session table storage and deep packet inspection
-
Internal flash storage: 1 GB flash memory for ASA OS firmware, device configurations, system logs and security signature databases
-
Dedicated hardware crypto accelerators: Four independent encryption engines for full offloading of AES-256, 3DES, RSA and ECC encryption plus SHA hash algorithms, eliminating general CPU bottlenecks under heavy concurrent VPN tunnel traffic
-
CPU architecture: Quad multicore general-purpose processors for high-volume packet forwarding and complex multi-context security policy processing
Power and Thermal Design
-
Standard factory configuration: Single AC 800W power supply plus hot-swappable fan tray
-
Redundancy upgrade option: Dual load-sharing redundant AC power supplies for production high-availability environments
-
Cooling design: Front-to-back forced airflow, fully compatible with standard data center hot/cold aisle rack layout standards
-
Hot-swap components: All power supply units and fan trays support online replacement without full chassis power shutdown; existing forwarding traffic remains uninterrupted during component maintenanceCisco
3. Official Verified Performance Benchmarks (Tier 40 Flagship)
-
Stateful firewall throughput: Up to 10 Gbps real-world HTTP traffic; up to 20 Gbps jumbo frame throughput (double ASA 5580-20’s capacity)Cisco
-
Maximum packets per second (64-byte small packets): 4,000,000 pps
-
Maximum new TCP/UDP connection establishment rate: 150,000 new sessions per second
-
Maximum concurrent active TCP/UDP sessions: 2,000,000 simultaneous sessions (twice ASA 5580-20)Cisco
-
3DES/AES IPsec VPN throughput: Up to 1 Gbps
-
Maximum persistent site-to-site IPsec VPN tunnels: 10,000 tunnels
-
Concurrent Cisco AnyConnect SSL VPN remote access users: Up to 10,000 simultaneous endpoints with premium VPN license
-
Supported logical segmented VLAN interfaces: Up to 250 VLANs
-
Maximum independent multi-context virtual firewalls: Up to 250 security contextsCisco
4. Integrated Security and Networking Feature Suite
Core Stateful Firewall Functions
-
Full stateful packet inspection (SPI) for TCP, UDP, ICMP and all standard IPv4 network protocols
-
Multi-context virtual firewall mode to partition one physical chassis into hundreds of fully isolated independent security domains for multi-tenant managed security services
-
Object-group access control lists, time-based access policies and modular unified policy frameworks
-
Comprehensive NAT functionality: Static NAT, dynamic PAT, large-scale carrier-grade LSN NAT and NAT64 for smooth IPv4/IPv6 network transition
Enterprise and Service Provider VPN Services
-
Site-to-site IPsec VPN tunnels with AES-256, 3DES, SHA-256 encryption and hash algorithms
-
Cisco AnyConnect Secure Mobility SSL VPN for distributed remote workforces, cross-platform endpoint compatibility with Windows, macOS, iOS and Android operating systems
-
DMVPN Dynamic Multipoint VPN for hub-and-spoke enterprise wide-area network architectures
-
Full hardware crypto offload ensures stable maximum throughput under massive concurrent VPN tunnel loads
Traffic Inspection & Threat Defense
-
Deep packet inspection for full application identification, granular bandwidth shaping, traffic blocking and per-application event logging
-
No built-in SSM IPS expansion slots; intrusion prevention requires separate external IPS appliances
-
Integration with Cisco Cloud Web Security for cloud-based malware detection and internet content compliance filtering
Routing and Network Integration
-
Full support for static routing, RIP v1/v2, OSPF, EIGRP and BGP dynamic routing protocols
-
Integrated routing and bridging (IRB) for transparent firewall mode deployments
-
Native IPv4 / IPv6 dual-stack protocol support for seamless enterprise IPv6 migration
5. Carrier-Grade High Availability Capabilities
-
Active/Standby & Active/Active Firewall Failover
Dual ASA 5580 appliances can be deployed as HA failover pairs to eliminate network downtime caused by hardware faults, firmware upgrades or scheduled maintenance. Stateful full session synchronization preserves all active data and VPN user sessions during failover switchover.
-
Hot-Swap Replaceable Power Supplies & Fans
All power supply units and fan trays support online hot-swap replacement without shutting down the entire chassis; existing forwarding traffic remains uninterrupted during component maintenance.
-
ISSU In-Service Software Upgrade
Non-disruptive ASA operating system firmware upgrades across HA firewall clusters, avoiding full network security outages during OS version updates.
-
Synchronized Configuration and Centralized Logging
Automatic configuration synchronization between paired HA firewalls; centralized event logging support for external syslog servers, Cisco Security Manager and dedicated threat management platforms for unified global policy control and cross-network threat reporting.
6. Physical & Environmental Specifications
Physical Dimensions & Weight
-
Chassis dimensions (H × W × D): 17.6 cm × 48.3 cm × 67.3 cm (6.94 × 19 × 26.5 inches), standard 4RU rack unit height
-
Chassis weight (single power supply): 29.9 kg (66 lb)
-
Chassis weight (dual redundant power supplies): Approximately 36.3 kg
Operating Environmental Parameters
-
Standard data center operating temperature range: 5°C to 40°C (41°F ~ 104°F)
-
Short-term extended operating temperature: -5°C to 55°C (23°F ~ 131°F), maximum continuous runtime 96 hours, annual cumulative usage limit 15 days
-
Operating relative humidity: 10% – 85% non-condensing
-
Storage and transit humidity: 5% – 95% non-condensing
-
Storage and transit temperature range: -40°C to 70°C (-40°F ~ 158°F)
-
Maximum operating altitude: 9144 meters (30,000 ft)
-
Maximum acoustic noise: 55 dBa at normal operating loadCisco
7. Global Regulatory & Compliance Certifications
-
Electrical Safety Standards: UL 60950-1, CSA C22.2 No.60950-1, IEC 60950, EN 60950-1, AS/NZS60950
-
Laser Safety Certification: IEC/EN 60825 for SFP/SFP+ fiber optical transceivers
-
EMC & EMI Electromagnetic Compatibility: CE marking, FCC Part 15 Class A, ICES-003 Class A, VCCI Class A, CISPR 22 Class A, CISPR 24, full EN 61000 series ESD, surge, radiated and conducted immunity compliance
-
Telecom Carrier Industry Standards: NEBS Level 3 (GR-63-Core environmental protection, GR-1089-Core EMC and safety specifications)
-
Cryptographic Security Compliance: FIPS 140-2 validated cryptographic module for government, financial and regulated industry deployments
-
Environmental Directives: EU RoHS hazardous substance restriction compliance, EU WEEE waste electrical and electronic equipment recycling directive compliant
8. Key Deployment Advantages
-
Unified All-In-One Converged High-Capacity Security Platform
Combines standalone high-throughput firewall, enterprise VPN gateway and multi-tenant virtual security functions into a single compact 4RU rack appliance, drastically reducing rack space occupation, total power consumption and multi-device daily management overhead compared to discrete separate security hardware clusters.
-
Quad-Core Multiprocessor Architecture with Dedicated Crypto Offloading
Four independent encryption accelerators and quad multicore general-purpose CPUs fully offload resource-intensive VPN encryption and deep packet inspection workloads, maintaining consistent maximum forwarding throughput even under full comprehensive security policy enforcement and peak user traffic loads.
-
Flexible Multi-Tenant Virtualization Capability
Multi-context virtual firewall mode enables service providers and large enterprise organizations to partition one physical ASA chassis into up to 250 fully isolated independent security domains for different business divisions, separate customer tenants or segmented network zones, maximizing hardware asset utilization efficiency.
-
Centralized Unified Enterprise-Grade Management
Fully compatible with Cisco Security Manager for centralized global firewall policy administration and dedicated external IPS management platforms for unified threat visibility, event correlation and compliance reporting across distributed fleets of ASA security appliances.
-
Expandable I/O Ecosystem
6 PCI expansion slots support flexible port expansion via Gigabit copper, Gigabit fiber and 10-Gigabit fiber interface cards, allowing customers to customize port density and media types according to specific data center and WAN connectivity requirements.
9. Standard Factory Packaging Contents
-
ASA 5580-40 4RU rack-mount chassis with fully integrated quad-processor tier 40 security processing hardware
-
Single factory-installed AC 800W power supply module
-
Complete 19-inch rack sliding rail kit including chassis rails, slide assemblies, cable management arm, Velcro straps, zip ties and installation screws
-
Two yellow Ethernet patch cables, one blue console cable and PC terminal DB-9 adapter
-
Blank filler panels for unused PCI interface card slots and empty SFP optical ports
-
ESD anti-static wrist strap for hardware maintenance operations
-
Hardware installation quick start guide (covers rack mounting, component hot-swap replacement and front panel LED alarm status troubleshooting procedures)
-
Global regulatory compliance documentation packet (safety, EMC, NEBS, FIPS, RoHS certification documents)
-
Software & documentation CD containing ASDM management software, OS documentation and configuration guides
Supplementary UNSPSC Classification Code
43222501 – Cisco ASA 5580-40 (ASA5580-SSP40) legacy top-tier high-performance integrated adaptive security appliance, 4RU fixed chassis firewall/VPN gateway with 6 PCI I/O expansion slots, quad multicore processors, four dedicated hardware crypto accelerators, 12GB onboard DRAM, multi-context virtual firewall support, designed for large enterprise campus core networks, high-traffic data center perimeter security and multi-service provider edge gateway deployments.
Standard Hardware Warranty
All factory-new ASA 5580-40 security appliances include a 1-year limited hardware warranty covering manufacturing defects and component failures under rated standard operating environmental conditions. Cisco SMARTnet extended service contracts were available during the product lifecycle to provide 24×7 priority Cisco TAC engineering technical support, advance genuine Cisco hardware replacement service, validated stable ASA OS firmware upgrade releases, and comprehensive firewall, VPN security policy configuration and network troubleshooting support. This product line has reached end-of-support, and no new SMARTnet service contracts can be purchased.
|