链接:  密码: isa8


  • Base License 永久许可

    Includes: Base Firewall Capabilities, Application Visibility and Control

  • Subscription Licenses 订阅许可免费90天试用








防火墙领域的领导者

在 Gartner 的《2019 年企业网络防火墙魔力象限》中,思科荣列领导者象限。

市场领导者

思科防火墙在 Ovum Firewall Market Radar 报告中获得高度评价。

客户之选

思科荣获 Gartner Peer Insights 企业网络防火墙的“客户之选”称号。

检测时间






Firepower 管理中心

对防火墙、应用控制、入侵防御、URL 过滤和高级恶意软件防护进行统一管理。



Firepower 设备管理器


Firepower 设备管理器




Cisco Firepower NGFW Virtual (NGFWv)

Features and specifications

Table 1. Features and specifications for NGFWv

Features Specifications
Cisco Firepower Device Manager (local management) ESXi and KVM; Azure: Version 6.5 and above; AWS: 6.6 and above
Centralized management Centralized configuration, logging, monitoring, and reporting are performed by the Cisco Firepower Management Center (all platforms including on-premises and in AWS and Azure) or alternatively in the cloud with Cisco Defense Orchestrator (ESXi and KVM; Azure: Version 6.5 and above)
Application Visibility and Control (AVC) Standard, supporting more than 4000 applications, as well as geolocations, users, and websites
AVC: OpenAppID support for custom, open-source, application detectors Standard
Cisco Security Intelligence Standard, with IP, URL, and DNS threat intelligence
Cisco Firepower Next-Generation Intrusion Prevention System (NGIPS) Available; can passively detect endpoints and infrastructure for threat correlation and Indicators of Compromise (IoC) intelligence
Cisco Advanced Malware Protection (AMP) for Networks Available; enables detection, blocking, tracking, analysis, and containment of targeted and persistent malware, addressing the attack continuum both during and after attacks. Integrated threat correlation with Cisco AMP for Endpoints is also optionally available.
Cisco AMP Threat Grid sandboxing Available
URL filtering: number of categories More than 80
URL filtering: number of URLs categorized More than 280 million
Automated threat feed and IPS signature updates Yes: Class-leading Collective Security Intelligence (CSI) from the Cisco Talos® group (
Third-party and open-source ecosystem Open API for integrations with third-party products; Snort® and OpenAppID community resources for new and specific threats
High availability and clustering Active/standby (ESXi and KVM only)
Deployment modes Routed, transparent (inline set — IPS-only), and passive; AWS and Azure: routed mode only

Note: Performance will vary depending on features activated, network traffic protocol mix, and packet size characteristics. Performance is subject to change with new software releases. Consult your Cisco representative for detailed sizing guidance.

Product performance guidelines

Note: Your performance may vary from the below. These should be considered general guidelines. Your actual performance will depend on your test environment, including CPU type, CPU speed, cache, number of interfaces, etc.

Table 2. Performance specifications for NGFWv

Specification 4 vCPU 8 vCPU 12 vCPU
Throughput: FW + AVC (1024B) 3 Gbps 5.5 Gbps 10 Gbps
Throughput: FW + AVC + IPS (1024B) 3 Gbps 5.5 Gbps 10 Gbps
Throughput: FW + AVC (450B) 1.5 Gbps 3 Gbps 5 Gbps
Throughput: FW + AVC + IPS (450B) 1 Gbps 2 Gbps 3 Gbps
Maximum concurrent sessions 100,000 250,000 500,000
Maximum new connections per second 20,000 20,000 40,000
Maximum VPN peers 250 250 750

System requirements

Table 3. System requirements for NGFWv

Specification Description
VMware and KVM: Virtual CPUs and memory (6.4 and above) ● 4 vCPU/8GB ● 8 vCPU/16GB ● 12 vCPU/24GB
VMware and KVM: Virtual CPUs and memory (6.3 and earlier) 4 vCPU/8GB
Storage 50GB for all FTDv configurations
Hypervisor support ESXi 6.0, 6.5, 6.7; KVM
AWS Support ● Instances: c3.xlarge, c4.xlarge ● Instances: c5.xlarge, c5.2xlarge, & c5.4xlarge (6.6 and above) ● Gov Marketplace ● China Marketplace ● Auto-Scale ● Enhanced Networking
Azure Support ● Instances: D3, D3_V2, ● Instances: D4_v2 and D5_v2 (6.5 and above) ● Gov Marketplace ● China Marketplace ● Auto-Scale

Ordering information

Table 4. Ordering information for NGFWv

Part number Description
FPRTD-V-K9 Cisco Firepower Threat Defense (TD) Virtual Appliance
L-FPRTD-V-T Cisco Firepower TD Virtual Threat Protection
L-FPRTD-V-TM Cisco Firepower TD Virtual Threat and Malware Protection
L-FPRTD-V-TC Cisco Firepower TD Virtual Threat Protection and URL
L-FPRTD-V-TMC Cisco Firepower TD Virtual Threat, Malware, and URL Filtering
L-FPRTD-V-AMP Cisco Firepower TD Virtual Malware Protect
L-FPRTD-V-URL Cisco Firepower Threat Defense Virtual URL Filtering


