Balancing Performance and Value for Enterprise Threat Defense
The ASA-SSP-20-INC is a Security Services Processor module designed exclusively for Cisco’s ASA 5585-X firewall series. As the mid-tier option in the SSP lineup, it transforms the base chassis into a dedicated threat defense appliance capable of handling medium-to-large enterprise traffic loads while maintaining rigorous security inspection.
Here’s how the SSP-20 stacks up against its siblings:
Specification | SSP-10 | SSP-20 (INC) | SSP-40 |
---|---|---|---|
Max Firewall Throughput | 4 Gbps | 10 Gbps | 20 Gbps |
IPS Throughput | 350 Mbps | 800 Mbps | 1.5 Gbps |
VPN Throughput | 300 Mbps | 600 Mbps | 1.2 Gbps |
Concurrent Sessions | 500,000 | 1,000,000 | 2,000,000 |
RAM | 8 GB | 12 GB | 24 GB |
Storage | 16 GB SSD | 32 GB SSD | 64 GB SSD |
Power Draw (Max) | 75W | 125W | 215W |
Real-World Impact: Handles 3,000+ employees with multiple security services enabled simultaneously.
Multi-Threat Inspection: Concurrent IPS, malware scanning, and application visibility
Encryption: Supports IPsec/SSL VPNs at wire speed
High Availability: Seamless failover with <500ms disruption
Granular Controls: Application-aware firewalling and user-based policies
Form Factor: Hot-swappable blade (fits rear slot of ASA 5585-X chassis)
Dimensions: 30.5 cm x 3.8 cm x 25.4 cm (LxHxW)
Cooling: Dual centrifugal fans with speed monitoring
Indicators: Multi-color LED status panel (System/Active/Fail)
Weight: 2.3 kg (5.1 lbs)
Installation:
Power down chassis
Slide module into Slot 1 until audible click
Reboot – auto-recognized in ASDM/CLI
Administration:
ASDM Interface: Drag-and-drop policy configuration
CLI Access: Full Cisco IOS-style commands
Reporting: Real-time threat visualization dashboards
Maintenance:
Fan replacement without tools
Predictive failure alerts via syslog
New: Discontinued (Original MSRP: 28,000-
35,000 USD)
Refurbished: 6,500-
9,200 USD (with 1-year warranty)
Cost Efficiency: 40% cheaper per Gbps than SSP-40
Idle Consumption: 85W
Peak Load: 125W
Heat Output: 427 BTU/hr (requires 15°C ambient cooling)
Annual Energy Cost: ≈110 USD (at
0.12/kWh)
Compatibility | Status | Notes |
---|---|---|
ASA 5585-X Chassis | ✔️ Native | Slot 1 or 2 |
ASA 5525-X/5545-X | ✘ | Different architecture |
FPR 4100 Firewalls | ⚠️ | Requires service module adapter |
Cisco ISE Integration | ✔️ | For identity-based policies |
VMware vSphere | ✔️ | Virtual management extensions |
Minimum OS: ASA 9.1(4)
Recommended OS: 9.8(4) for full feature support
End-of-Support: 2024 (Limited firmware patches available)
Critical Note: Incompatible with ASA FirePOWER 6.7+
Choose SSP-20-INC when:
✅ You need 5-8 Gbps of inspected throughput
✅ Running IPS + URL filtering + VPN simultaneously
✅ Budget requires future-proofing beyond SSP-10
Avoid if:
❌ You require 10Gbps+ encrypted throughput
❌ Operating in ambient >35°C environments
❌ Deploying new Cisco FirePOWER TD stacks