Cisco Secure Firewall 200 Series Data Sheet

Data Sheet

Available Languages

Download Options

  • PDF
    (587.3 KB)
    View with Adobe Reader on a variety of devices
Updated:October 6, 2026

Bias-Free Language

The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.

Available Languages

Download Options

  • PDF
    (587.3 KB)
    View with Adobe Reader on a variety of devices
Updated:October 6, 2026

Table of Contents

 

 

Introduction

The Cisco® Secure Firewall 200 Series offers next-generation firewall capabilities specifically designed for distributed enterprises and small branch locations. It provides robust, cost-effective security and simplified management within a compact form factor, ensuring secure and optimized connectivity at the network edge. The 200 Series extends Cisco’s Hybrid Mesh Firewall architecture to branch edges, providing AI-powered inspection and consistent security policies. It integrates SD-WAN capabilities for enhanced application performance and reliable user access. Additionally, the 200 Series delivers application and user control, efficient segmentation, and advanced security features tailored for cost-sensitive environments.

Related image, diagram or screenshot

Table 1.        Key capabilities of the Cisco Secure Firewall 200

Cisco Secure Firewall 200 with Cisco Firewall Threat Defense Software

Robust connectivity

●  Achieve up to 3Gbps throughput from a fanless desktop firewall when next-generation firewall capabilities are enabled. Enable the high-availability feature for continuous uptime.
●  Connect branch offices to the hybrid mesh firewall architecture using the 1G Small Form-factor Pluggable (SFP) port. Network and cryptographic operations are accelerated inline by leveraging the System on a Chip (SoC).

Superior visibility

●  Leverage the AI-powered Encrypted Visibility Engine to gain visibility and control for encrypted and unencrypted traffic, including TLS 1.3, QUIC, and HTTP. EVE provides enhanced application visibility and intelligent threat detection in modern networks.
●  Protect networks against zero-day vulnerabilities with SnortML—a machine learning-based exploit detection technology integrated into the industry-leading Snort 3 Intrusion Prevention System (IPS).

Simplified management

●  Scale effortlessly: Manage up to 1,500 firewalls now, scaling to 2,000, via Security in Cloud Control Firewall, Manager optimized for Hybrid Mesh Firewall and MSSP environments. Use prebuilt templates and streamlined migration tools for fast, consistent global deployment without extra overhead.
●  Unified management, smarter security: A single intuitive console unifies logging and event viewing. Integrated AIOps converts telemetry into actionable insights and automated policy recommendations, enabling faster resolution, less alert fatigue, and proactive threat response.

Seamless integration

●  Achieve comprehensive end-to-end protection through native integration with Cisco Umbrella ®, Cisco Secure Access, and Cisco Secure Endpoint.
●  Optimize application performance and user experience through seamlessly integrated SD-WAN capabilities, accelerated by Zero-Touch Provisioning (ZTP).

Hardware overview

Related image, diagram or screenshot

Figure 1.       

3D view of the Cisco Secure Firewall 220 model

Related image, diagram or screenshot

Figure 2.         

Front panel of the Cisco Secure Firewall 220 model

Related image, diagram or screenshot

Figure 3.         

3D view of the Cisco Secure Firewall 240P model

Related image, diagram or screenshot

Figure 4.         

Front panel of the Cisco Secure Firewall 240P model 

Performance

The Cisco Secure Firewall 200 series support both Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) software. While the FTD software offers all the advanced next-generation security capabilities, ASA software delivers higher throughput for stateful inspection.

Table 2.        Cisco Secure Firewall 200 performance with Cisco Secure Firepower Threat Defense (FTD) software

Metric

220

240P

Throughput: Firewall + Application Visibility and Control (AVC) (1024B)

1.5 Gbps

3.2 Gbps

Throughput: AVC + Intrusion Prevention System (IPS) (1024B)

1.5 Gbps

3 Gbps

NGFW Throughput: FW + AVC + IPS (1024B)

1.5 Gbps

3 Gbps

IPSec VPN Throughput (1024B TCP w/Fastpath)

1.2 Gbps

3 Gbps

TLS Decryption[1]

0.7 Gbps

0.9 Gbps

Application Visibility and Control (AVC)

Standard, supporting more than 8100 applications, as well as geolocations, users, and websites

Table 3.        Cisco Secure Firewall 200 performance with the Cisco Adaptive Security Appliance (ASA) software

Metric

220

240P

Stateful inspection firewall throughput (150B UDP)[2]

2 Gbps

4.5 Gbps

Stateful inspection firewall throughput (HTTP 1024 Byte)

2 Gbps

3.5 Gbps

IPsec VPN throughput (450B UDP L2L test)

1.5 Gbps

2 Gbps

Note: Performance will vary depending on features activated, network traffic protocol mix, and packet size characteristics. Performance is subject to change with new software releases. Consult your Cisco representative for detailed sizing guidance.

Scalability

Table 4.        Cisco Secure Firewall 200 scalability with the Cisco Secure Firewall Threat Defense (FTD) software

Metric

220

240P

Maximum concurrent sessions, with AVC

30K

50K

Maximum new connections per second, with AVC

6K

15K

Maximum VPN peers

50

75

Maximum Virtual Router Instances (VRF)

5

5

High availability

Active/Standby

Active/Standby

Instances (multi-instance)

Not supported

Not supported

Clustering

Not supported

Not supported

Table 5.        Cisco Secure Firewall 200 scalability with the Cisco Adaptive Security Appliance (ASA) software

Metric

220

240P

New connections per second

80K

95K

Concurrent firewall connections

100K

200K

Maximum VPN Peers

50

75

High availability

Active/Standby

Active/Standby

Security contexts

Not supported

Not supported

Clustering

Not supported

Not supported

Hardware specifications

Table 6.        Cisco Secure Firewall 200 hardware specifications

Specification

220

240P

Form factor

Compact (Can be placed on desktop. Rackmount and wall mount accessories are also available)

Fixed ports

4x 1000BASE-T

8x 1000BASE-T

1x1G SFP

2x1G SFP

Management Ethernet

1000BASE-T port

1000BASE-T port

Network modules

N/A

N/A

Maximum number of interfaces

Up to 5 total Ethernet ports
(4 x 1000Base-T, 1x 1 Gigabit SFP)

Up to 10 total Ethernet ports
(8 x 1000Base-T, 2x 1 Gigabit SFP)

Console port

USB Type-C and RJ-45

USB Type-C and RJ-45

(Cisco serial)

(Cisco serial)

USB port

USB 3 Type A port

USB 3 Type A port

Storage

64GB

64GB

Power over Ethernet

N/A

4 of the Ethernet ports support IEEE 802.3at PoE+
for delivery of up to 25.5W per port (120W total)
to compatible PD endpoints.

Transceiver support

Refer to Cisco Secure Firewall (CSF) 200 Hardware Installation Guide

Mean Time Between Failures (MTBF)

700,000 Hours

600,000 Hours

Chassis dimensions (HxWxD)

1.15” x 9.2” x 7.8”

1.65” x 9.2” x 8.5”

(2.9 x 23.4 x 19.8 cm)

(4.1 x 23.3 x 21.5 cm)

Weight

2.6lb (1.17kg)

3.3lb (1.49kg)

Cooling

Passive (fanless)

Passive (fanless)

Rack mountable

Yes

Yes

Power supply

Configuration

Single AC External 30W power supply

Single AC External 190W power supply, input (POE)

AC input voltage

100–240V AC

100–240V AC

AC input frequency

50-60Hz

50-60Hz

AC current draw, maximum

1A

4A

Power consumption, typical

12.7 Watts

19 Watts (excluding POE)

Power consumption, maximum

19 Watts

35.6 Watts (excluding POE)

160.6 Watts (including POE)

Redundancy

N/A

N/A

Operating Range

Temperature: operating

32° to 104°F (0° to 40°C)

32 to 104F (0 to 40C)

Humidity: operating

5% to 85% (non-condensing)

5 to 85% (non-condensing)

Altitude: operating

up to 10,000 feet (3048 m)

up to 10,000 feet (3048m)

Acoustic noise

0 dBA

0 dBA

Non-operating/storage environment

Temperature: nonoperating

-13° to 158°F (-25° to 70°C)

-13° to 158°F (-25° to 70°C)

Humidity: nonoperating

5% to 95% (non-condensing)

5% to 95% (non-condensing)

Altitude: nonoperating

0 to 15,000 ft (4570 m)

up to 15,000 feet (4570m)

Compliance

For details on product regulatory compliance in a specific market, consult the Cisco Product Approvals tool.

Table 7.        Cisco Secure Firewall 200 Network Equipment-Building System (NEBS), Regulatory, Safety, Environmental and EMC Compliance

Specification

Description

Regulatory compliance

Products comply with CE markings per directives 2004/108/EC and 2006/108/EC

Safety

●  UL 60950-1
●  UL 62368-1
●  CAN/CSA-C22.2 No. 62368-1
●  EN 62368-1
●  IEC 62368-1
●  AS/NZS 62368-1

EMC: Emissions

●  47CFR Part 15 (CFR 47) Class A (FCC Class A)
●  AS/NZS CISPR 32 Class A
●  CISPR 32 Class A
●  EN55032 Class A
●  ICES003 Class A
●  VCCI Class A
●  EN61000-3-2
●  EN61000-3-3
●  KS C 9832 Class A
●  CNS15936 Class A
●  EN300386
●  QCVN 118:2018

EMC: Immunity

●  EN55035
●  CISPR 35
●  EN300386
●  KS C 9835
●  QCVN 18:2022
●  EN61000-3-2/-3
●  EN61000-4-2/-3/-4/-5/-6/-8/-11

Ordering information

Cisco Secure Firewall 200 Series hardware appliances are listed below. For information on licenses, subscriptions, and other options associated with the product, refer to the Network Security Ordering Guide.

Table 8.        Cisco Secure Firewall 200 Series Product IDs

Product ID

Description

CSF220-ASA-K9
CSF220-ASA-K9++

Cisco Secure Firewall 220 Appliance, ASA

CSF220-TD-K9
CSF220-TD-K9++

Cisco Secure Firewall 220 Appliance, Threat Defense

CSF240P-ASA-K9

Cisco Secure Firewall 240P Appliance, ASA

CSF240P-TD-K9

Cisco Secure Firewall 240P Appliance, Threat Defense

Cisco environmental sustainability

Information about Cisco’s environmental sustainability policies and initiatives for our products, solutions, operations, and extended operations or supply chain is provided in the “Environmental Sustainability” section of Cisco’s Corporate Social Responsibility (CSR) report.

Reference links to information about key environmental sustainability topics (mentioned in the “Environment Sustainability” section of the CSR Report) are provided in the following table:

Sustainability topic

Reference

Information on product material content laws and regulations

Materials

Information on electronic waste laws and regulations, including products, batteries, and packaging

WEEE compliance

Cisco makes the packaging data available for informational purposes only. It may not reflect the most current legal developments, and Cisco does not represent, warrant, or guarantee that it is complete, accurate, or up to date. This information is subject to change without notice.

 



[1] Throughput measured with 50% TLS 1.2 traffic with AES256-SHA with RSA 2048B keys.

[2] Throughput measured with 1500B User Datagram Protocol (UDP) traffic measured under ideal test conditions.

Our experts recommend

Learn more

Hello, how can I help?
Ask Cisco
Expand the window to see more details and enjoy a clearer chat!