Tường lửa Cisco Firepower 2130 12 x 1G RJ-45 + 4 x 10G SFP+, 1 khe module, firewall 5,4 Gbps, IPS 5,4 Gbps
Cisco Firepower 2130 (FPR2130-NGFW-K9) là tường lửa 1RU dòng Firepower 2100 cho doanh nghiệp vừa và lớn, 12 x 1G RJ-45 + 4 x 10G SFP+, 1 khe module, thông lượng firewall 5,4 Gbps, IPS 5,4 Gbps, VPN 1,9 Gbps, 2 triệu phiên đồng thời. Bản NGFW chạy Threat Defense với IPS Snort, AMP, lọc URL. Thiết Bị Mạng Cisco cung cấp chính hãng kèm giấy phép Threat, Malware, URL theo nhu cầu.
So sánh Firepower 2100
| Model | Cổng | FW + AVC | IPS | VPN | Phiên |
|---|---|---|---|---|---|
| FPR2110 | 12 x 1G + 4 SFP | 2,6 Gbps | 2,6 Gbps | 950 Mbps | 1 triệu |
| FPR2120 | 12 x 1G + 4 SFP | 3,4 Gbps | 3,5 Gbps | 1,2 Gbps | 1,5 triệu |
| FPR2130 | 12 x 1G + 4 SFP+ | 5,4 Gbps | 5,4 Gbps | 1,9 Gbps | 2 triệu |
| FPR2140 | 12 x 1G + 4 SFP+ | 10,4 Gbps | 10,5 Gbps | 3,6 Gbps | 3 triệu |
Điểm nổi bật
- 5,4 Gbps firewall + AVC, 5,4 Gbps IPS, 1,9 Gbps IPsec.
- 12 x 1G RJ-45 + 4 x 10G SFP+, 1 khe module.
- Chip mã hoá riêng: hiệu năng ổn định khi bật IPS và VPN cùng lúc.
- Quản trị tại chỗ bằng FDM hoặc tập trung nhiều máy bằng Management Center.
Ứng dụng và triển khai
Cisco Firepower 2130 đặt ở biên trụ sở 1.000 tới 2.000 người dùng, làm hub VPN cho chi nhánh và bảo vệ máy chủ nội bộ. Thay ASA 5525-X/5545-X/5555-X đã ngừng bán bằng công cụ Firepower Migration Tool. Bản 2130/2140 có cổng 10G nối thẳng core Catalyst 9500.
Sản phẩm dùng kèm
Khi mua Cisco Firepower 2130, khách hàng thường lấy thêm switch Cisco Catalyst C9300-24T-E và module quang SFP-10G-SR-S để đủ bộ triển khai. Thiết Bị Mạng Cisco tư vấn cấu hình và báo giá chung một đơn.
Giá bán và đặt hàng
Cisco Firepower 2130 bán theo báo giá, giá tốt theo số lượng và dự án. Gọi hotline hoặc gửi yêu cầu để nhận giá, tồn kho và thời gian giao. Hàng chính hãng Cisco, đủ CO/CQ, xuất hoá đơn VAT, bảo hành theo chính sách Cisco Việt Nam.
Thông số kỹ thuật Cisco Firepower 2130
| Mã sản phẩm | FPR2130-NGFW-K9 |
|---|---|
| Dòng | Cisco Firepower 2100 Series |
| Phần mềm | Secure Firewall Threat Defense (NGFW) |
| Cổng mạng | 12 x 1G RJ-45 + 4 x 10G SFP+, 1 khe module |
| Thông lượng firewall + AVC | 5,4 Gbps |
| Thông lượng IPS | 5,4 Gbps |
| Thông lượng IPsec VPN | 1,9 Gbps |
| Firewall ASA (stateful) | 10 Gbps |
| Phiên đồng thời | 2 triệu |
| Kết nối mới/giây | 30.000 |
| VPN peer tối đa | 7.500 |
| Kích thước | 1RU, nguồn AC tích hợp, tuỳ chọn nguồn thứ hai |
| Quản trị | FDM tại chỗ, Secure Firewall Management Center, Cisco Defense Orchestrator |
| Bảo hành | Theo chính sách Cisco |
| Throughput: FW + AVC (1024B) | 5.4 Gbps |
|---|---|
| Throughput: FW + AVC + IPS (1024B) | 5.4 Gbps |
| Maximum concurrent sessions, with AVC | 2 million |
| Maximum new connections per second, with AVC | 30K |
| TLS | 760 Mbps |
| Throughput: IPS (1024B) | 5.4 Gbps |
| IPSec VPN Throughput (1024B TCP w/Fastpath) | 1.9 Gbps |
| Maximum VPN Peers | 7,500 |
| Cisco Firepower Device Manager (local management) | Yes |
| Centralized management | Centralized configuration, logging, monitoring, and reporting are performed by the Management Center or alternatively in the cloud with Cisco Defense Orchestrator |
| Application Visibility and Control (AVC) | Standard, supporting more than 4000 applications, as well as geolocations, users, and websites |
| AVC: OpenAppID support for custom, open source, application detectors | Standard |
| Cisco Security Intelligence | Standard, with IP, URL, and DNS threat intelligence |
| Cisco Firepower NGIPS | Available; can passively detect endpoints and infrastructure for threat correlation and Indicators of Compromise (IoC) intelligence |
| Cisco AMP for Networks | Available; enables detection, blocking, tracking, analysis, and containment of targeted and persistent malware, addressing the attack continuum both during and after attacks. Integrated threat correlation with Cisco Secure Endpoint is also optionally available |
| Cisco AMP Threat Grid sandboxing | Available |
| URL Filtering: number of categories | More than 80 |
| URL Filtering: number of URLs categorized | More than 280 million |
| Automated threat feed and IPS signature updates | Yes: class-leading Collective Security Intelligence (CSI) from the Cisco Talos Group |
| Third-party and open-source ecosystem | Open API for integrations with third-party products; Snort® and OpenAppID community resources for new and specific threats |
| High availability and clustering | Active/standby |
| Cisco Trust Anchor Technologies | Firepower 2100 Series platforms include Trust Anchor Technologies for supply chain and software image assurance. Please see the section below for additional details |
| Stateful inspection firewall throughput1 | 10 Gbps |
|---|---|
| Stateful inspection firewall throughput (multiprotocol)2 | 5 Gbps |
| Concurrent firewall connections | 2 million |
| New connections per second | 40,000 |
| IPsec VPN throughput (450B UDP L2L test) | 1 Gbps |
| Security contexts (included; maximum) | 2; 30 |
| High availability | Active/active and active/standby |
| Scalability | VPN Load Balancing |
| Centralized management | Centralized configuration, logging, monitoring, and reporting are performed by Cisco Security Manager or alternatively in the cloud with Cisco Defense Orchestrator |
| Adaptive Security Device Manager | Web-based, local management for small-scale deployments |















