Cisco FPR9K-SM24 Full Official Product Description
1. Part Number & Naming Definition
Official Full Name
Cisco FPR9K-SM24 24-Core NEBS-Ready Security Processing Module for Cisco Firepower 9300 Modular Chassis
Naming Breakdown
-
FPR9K: Firepower 9000 series modular security chassis platform identifier (compatible exclusively with Firepower 9300 3RU rack-mount chassis)Cisco
-
SM: Security Module – dedicated processing blade responsible for all firewall, threat defense, VPN and security inspection workloads
-
24: 24 physical CPU cores integrated for high-volume security traffic processing
-
Suffix-NEBvariant (FPR9K-SM24-NEB): NEBS Level 3 certified version for carrier central office deployments
Core Positioning
The FPR9K-SM24 is a hot-swappable, single-width security processing blade designed to plug into any of the three dedicated security module slots on the Cisco Firepower 9300 chassis. It delivers enterprise and mid-tier data center next-generation firewall (NGFW), intrusion prevention (NGIPS), encrypted traffic inspection, and IPsec/AnyConnect VPN performance. Equipped with redundant RAID-1 SSD local storage and a multi-core high-throughput CPU complex, this module supports standalone single-blade deployment or multi-module chassis clustering for linear performance scaling. It is NEBS Level 3 compliant for service provider carrier-grade environmentsCisco.
2. Chassis & Software Compatibility
Supported Hardware Platforms
-
Only compatible withCisco Firepower 9300 3RU modular security chassis
-
Chassis hardware slots: 3 independent hot-swappable security module slots; the FPR9K-SM24 occupies one single-width slot
-
Chassis I/O expansion: Works with all Firepower 9000 series network modules (8x10G SFP+, 4x40G QSFP+, 2x100G QSFP28, fixed copper/fiber FTW bypass modules) installed on the supervisor card’s dual network module slots
Mandatory Supported Firmware & OS Versions
-
FXOS Chassis Manager: All FXOS 2.x stable releases prior to FXOS 2.17
-
Firepower Threat Defense (FTD): Supported up to FTD 7.2;not supported on FTD 7.3 and later releases
-
Cisco ASA Classic Firewall OS: Supported up to ASA 9.18; unsupported on ASA 9.19 and newer firmware branchesCisco
Hardware Restrictions
-
Hot-swap capable only when the Firepower 9300 chassis is powered and running FXOS; no full chassis power cycle required for module replacement
-
RAID-1 storage is fixed onboard; no field-upgradable SSD drives
-
Cannot be mixed with SM-36/SM-44 high-performance modules in certain FTD clustering firmware versions
-
Not compatible with Firepower 4100, Firepower 9200, or standalone fixed-form-factor Firepower appliances
3. Onboard Hardware Specifications
CPU & Memory Complex
-
Processor: 24 physical x86 multi-core enterprise-grade CPU complex optimized for parallel security inspection workloads
-
System RAM: High-capacity error-correcting (ECC) memory dedicated to firewall session tables, threat signature databases, and encrypted traffic analytics processing
Local Storage Subsystem
-
Dual enterprise-grade solid-state drives (SSD) configured in hardware RAID-1 mirroring
-
RAID-1 redundancy eliminates single point of failure for local OS images, threat signature updates, logging databases, and session state storage
Environmental & Physical Parameters
-
Form Factor: Single-width hot-swappable blade for Firepower 9300 chassis security slots
-
Module Weight: Approximately 2 lbs (0.9 kg)
-
Operating Temperature (NEBS compliance):
-
Continuous long-term operation: 0°C to 45°C at altitudes up to 6,000 ft (1829 m)
-
Continuous long-term operation: 0°C to 35°C at altitudes between 6,000 ft and 13,000 ft (3964 m)
-
Short-term transient operation: -5°C to 55°C at altitudes up to 6,000 ft
-
Operating Humidity: 5% to 95% non-condensing
-
Storage/Transport Temperature: -40°C to 65°C
-
Maximum Supported Altitude: 13,000 ft (3962 m) above sea levelCisco
4. Key Performance Benchmarks (Single FPR9K-SM24 Module)
All metrics measured under standard enterprise mixed-traffic test conditionsCisco Russ...
-
Stateful Firewall Throughput (maximum single-protocol): 75 Gbps
-
Multiprotocol Stateful Firewall Throughput: 50 Gbps
-
Maximum Concurrent Firewall Connections: 55 million
-
New Connection Establishment Rate: 600,000 connections per second
-
IPsec VPN Throughput: 15 Gbps
-
Maximum Supported VPN Tunnels (IPsec site-to-site + AnyConnect Remote Access): 15,000
-
Firewall Latency (64-byte UDP packets, cut-through mode): 3.5 microseconds
-
Maximum Supported Security Contexts (virtual firewalls): 250
-
Maximum Supported VLAN Interfaces: 1024
5. Core Security & Functional Features
-
Full NGFW Feature Suite
-
Stateful packet inspection, application control visibility (AVC), user-based policy enforcement, NAT/PAT, policy-based routing, QoS traffic shaping
-
Next-Generation Intrusion Prevention System (NGIPS)
-
Real-time threat signature matching, vulnerability protection, exploit blocking, custom signature creation, intrusion event logging
-
Encrypted Traffic Analytics (ETA)
-
Deep inspection of TLS 1.0/1.1/1.2/1.3 encrypted traffic without full packet decryption, malware and suspicious flow identification
-
Advanced Malware Protection (AMP)
-
Cloud-based file reputation analysis, malware sandboxing, retrospective threat detection for malicious file transfers
-
URL Filtering & Web Control
-
Global URL category database, customizable website allow/block policies, bandwidth restriction for high-risk web categories
-
Comprehensive VPN Capabilities
-
IPsec IKEv1/IKEv2 site-to-site tunnels, Cisco AnyConnect SSL remote access VPN, full tunnel split-tunnel routing support
-
Virtual Multi-Context Firewall
-
Up to 250 independent security virtual contexts to segregate multi-tenant enterprise, MSSP, and departmental network traffic
-
High Availability & Chassis Clustering
-
Active/standby failover for single-chassis dual-module deployments; inter-chassis clustering with multiple Firepower 9300 chassis for linear throughput scaling
-
NEBS Level 3 Carrier-Grade Compliance
-
Meets GR-63-Core environmental standards and GR-1089-Core EMC/safety specifications for telecom central office deploymentsCisco
-
Centralized Management Support
-
Fully managed via Cisco Firepower Management Center (FMC) for unified policy deployment, threat monitoring, reporting, and firmware updates
6. Typical Enterprise & Service Provider Deployment Use Cases
-
Mid-Tier Enterprise Data Center Perimeter Security
Deployed as the primary security blade in a standalone Firepower 9300 chassis for internet edge NGFW, IPS, remote access VPN, and web filtering for medium-sized corporate networks
-
Multi-Tenant Managed Security Service Provider (MSSP)
Utilizes multi-context virtual firewall functionality to isolate independent customer network traffic on a single chassis blade, delivering dedicated security policy enforcement per tenant
-
Carrier Service Provider Central Office Security
NEBS-certified variant (FPR9K-SM24-NEB) deployed in telecom central offices to secure ISP peering links, residential broadband aggregation points, and carrier VPN infrastructure
-
Cross-Datacenter Interconnect (DCI) Inline Threat Inspection
Paired with Firepower 9000 series fiber network modules (10G/40G/100G SFP+/QSFP+/QSFP28) to provide inline security filtering for long-distance inter-data-center fiber links
-
Regulated Industry Secure Network Segmentation (Finance, Healthcare)
Delivers full compliance support for PCI-DSS, HIPAA, NERC-CIP via deep traffic logging, threat audit trails, encrypted traffic monitoring, and granular access control policies
7. Regulatory & Certification Compliance
-
Electrical Safety Standards: UL 60950-1, CSA C22.2 No.60950-1, IEC/EN 60950-1
-
Telecom Carrier Standards: NEBS Level 3 (GR-63-Core environmental, GR-1089-Core EMC & safety)
-
Electromagnetic Compatibility (EMC): CE Mark, FCC Part 15 Class A, ICES-003 Class A, VCCI Class A, CISPR 22 Class A, CISPR 24, full EN 61000 series ESD, surge, radiated and conducted immunity compliance
-
Cryptographic Validation: FIPS 140-2 Level 2 validated cryptographic processing module for government and regulated industry encrypted traffic workloads
-
Environmental Directives: EU RoHS hazardous substance restriction compliant, EU WEEE waste electrical and electronic equipment recycling directive compliant
8. Standard Factory Packaging Contents
-
FPR9K-SM24 hot-swappable security processing module main blade
-
Integrated front panel extraction handle and captive installation retention screw
-
ESD anti-static protective packaging and ESD wrist strap for safe module handling
-
Hardware installation quick start guide covering Firepower 9300 chassis blade insertion, hot-swap replacement procedures, and RAID-1 storage maintenance notes
-
Full regulatory compliance and certification documentation packet
Supplementary UNSPSC Classification Code
43222501 – Cisco FPR9K-SM24 24-core NEBS-ready hot-swappable security processing blade for Firepower 9300 modular chassis, featuring hardware RAID-1 dual SSD storage, ECC enterprise memory, 75Gbps maximum stateful firewall throughput, support for up to 250 virtual security contexts, NGIPS, AMP, ETA, IPsec/AnyConnect VPN, NEBS Level 3 carrier compliance, compatible with Firepower 9000 series high-speed fiber/copper network I/O expansion modules
Standard Hardware Warranty Information
All factory-new FPR9K-SM24 security modules include a 1-year limited hardware warranty covering manufacturing defects and component failures under rated standard operating environmental conditions. Cisco Smart Net Total Care extended service contracts are available for active lifecycle units, delivering 24×7 priority Cisco TAC technical support, advance genuine spare hardware replacement service, validated stable FXOS/FTD/ASA firmware upgrade releases, and comprehensive security policy configuration and network fault troubleshooting support.
|