Appendix A: Concurrent VPN sessions of Firewall Threat Defense devices

This topic provides maximum concurrent remote access VPN session limits for different Firewall Threat Defense device models to support capacity planning and system performance optimization.

Concurrent VPN sessions (Firewall Threat Defense Virtual models)

The number of concurrent remote access VPN sessions on a Firewall Threat Defense Virtual device is governed by the smart-licensed entitlement tier and enforced by a rate limiter. Each device model has a maximum session limit to maintain acceptable system performance. Use these limits when planning capacity.

Device Model

Maximum Concurrent Remote Access VPN Sessions

Firewall Threat Defense Virtual5

50

Firewall Threat Defense Virtual10

250

Firewall Threat Defense Virtual20

250

Firewall Threat Defense Virtual30

250

Firewall Threat Defense Virtual50

750

Firewall Threat Defense Virtual100

10,000

Concurrent VPN sessions (hardware models)

The maximum concurrent VPN sessions are governed by platform-specific limits and are not dependent on the license. There is a maximum limit to the number of concurrent remote access VPN sessions allowed on a device based on the device model. This limit is designed so that system performance does not degrade to unacceptable levels. Use these limits for capacity planning.

Device Model

Maximum Concurrent Remote Access VPN Sessions

Secure Firewall 220

50

Firepower 1010

75

Firepower 1120

150

Firepower 1140

400

Firepower 2110

1500

Firepower 2120

3500

Firepower 2130

7500

Firepower 2140

10,000

Secure Firewall 3110

3000

Secure Firewall 3120

6000

Secure Firewall 3130

15,000

Secure Firewall 3140

20,000

Secure Firewall 6100

60,000

Secure Firewall 4215

20,000

Secure Firewall 4225

25,000

Secure Firewall 4245

30,000

Firepower 4100, all models

10,000

Firepower 9300 appliance, all models

20,000

ISA 3000

25

For capacity of other hardware models, check the data sheets.

Note

Once the maximum session limit is reached, the Firewall Threat Defense device denies incoming VPN connections and generates a syslog message. Refer to the syslog messages %FTD-4-113029 and %FT-4-113038 in the syslog messaging guide. For more information, refer to Cisco Secure Firewall Threat Defense Syslog Messages.