Data Sheet

Data Sheet
© 2011 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 14 of 22
Security Services Processors, Modules and Cards
The Cisco ASA 5500 Series brings a new level of integrated security performance to networks with its highly effective
IPS services and multiprocessor hardware architecture. This architecture allows businesses to adapt and extend the
high-performance security services profile of the Cisco ASA 5500 Series. Customers can add additional high-
performance services using security services modules with dedicated security co-processors, and can custom-tailor
flow-specific policies using a highly flexible policy framework. This adaptable architecture enables businesses to
deploy new security services when and where they are needed, such as adding the broad range of intrusion
prevention and advanced anti-worm services delivered by the IPS modules via IPS SSP, AIP SSM and AIP SSC, or
the comprehensive malware protection and content security services enabled by the CSC SSM. Further, the
architecture allows Cisco to introduce new services to address new threats, giving businesses outstanding
investment protection for the Cisco ASA 5500 Series.
Cisco ASA 5500 Series IPS Modules
The Cisco ASA 5500 Series IPS SSP, AIP SSM, and AIP SSC are inline, network-based solutions that accurately
identify, classify, and stop malicious traffic before it affects business continuity for IPv4, IPv6, and hybrid IPv6 and
IPv4 networks. They combine inline prevention services with innovative technologies, resulting in total confidence in
the provided protection of the deployed IPS solution, without the fear of legitimate traffic being dropped. The IPS
SSP, AIP SSM and AIP SSC also offer comprehensive network protection through their unique ability to collaborate
with other network security resources, providing a proactive approach to protecting the network. Accurate inline
prevention technologies provide unparalleled confidence to take preventive action on a broader range of threats
without the risk of dropping legitimate traffic. These unique technologies offer intelligent, automated, contextual
analysis of data and help ensure that businesses are getting the most out of their intrusion prevention solutions.
Furthermore, the IPS SSP, AIP SSM and AIP SSC use multivector threat identification to protect the network from
policy violations, vulnerability exploitations, and anomalous activity through detailed inspection of traffic in Layers 2
through 7.
Table 10 and 11 detail the IPS SSP, AIP SSM and AIP SSC models that are available, and their respective
performance and physical characteristics.
Table 10. Characteristics of Cisco ASA 5500 Series AIP SSM and SSC Models
Feature
Cisco ASA 5500 Series
AIP SSC-5
Cisco ASA 5500 Series
AIP SSM-10
Cisco ASA 5500 Series
AIP SSM-20
Cisco ASA 5500 Series
AIP SSM-40
Concurrent Threat Mitigation
Throughput (Firewall + IPS
Services)
75 Mbps with Cisco
ASA 5505
150 Mbps with Cisco
ASA 5510
225 Mbps with Cisco
ASA 5520
300 Mbps with Cisco
ASA 5510
375 Mbps with Cisco
ASA 5520
500 Mbps with Cisco
ASA 5540
450 Mbps with Cisco
ASA 5520
650 Mbps with Cisco
ASA 5540
Technical Specifications
Memory
512 MB
1 GB
2 GB
4 GB
Flash
512 MB
256 MB
256 MB
2 GB
Environmental Operating Ranges
Operating
Temperature
32 to 104ºF (0 to 40ºC)
Relative humidity
5 to 95 percent noncondensing