Appendix A: Concurrent VPN sessions of Firewall Threat Defense devices
This topic provides maximum concurrent remote access VPN session limits for different Firewall Threat Defense device models to support capacity planning and system performance optimization.
Concurrent VPN sessions (Firewall Threat Defense Virtual models)
The number of concurrent remote access VPN sessions on a Firewall Threat Defense Virtual device is governed by the smart-licensed entitlement tier and enforced by a rate limiter. Each device model has a maximum session limit to maintain acceptable system performance. Use these limits when planning capacity.
|
Device Model |
Maximum Concurrent Remote Access VPN Sessions |
|---|---|
|
Firewall Threat Defense Virtual5 |
50 |
|
Firewall Threat Defense Virtual10 |
250 |
|
Firewall Threat Defense Virtual20 |
250 |
|
Firewall Threat Defense Virtual30 |
250 |
|
Firewall Threat Defense Virtual50 |
750 |
|
Firewall Threat Defense Virtual100 |
10,000 |
Concurrent VPN sessions (hardware models)
The maximum concurrent VPN sessions are governed by platform-specific limits and are not dependent on the license. There is a maximum limit to the number of concurrent remote access VPN sessions allowed on a device based on the device model. This limit is designed so that system performance does not degrade to unacceptable levels. Use these limits for capacity planning.
|
Device Model |
Maximum Concurrent Remote Access VPN Sessions |
|---|---|
|
Secure Firewall 220 |
50 |
|
Firepower 1010 |
75 |
|
Firepower 1120 |
150 |
|
Firepower 1140 |
400 |
|
Firepower 2110 |
1500 |
|
Firepower 2120 |
3500 |
|
Firepower 2130 |
7500 |
|
Firepower 2140 |
10,000 |
|
Secure Firewall 3110 |
3000 |
|
Secure Firewall 3120 |
6000 |
|
Secure Firewall 3130 |
15,000 |
|
Secure Firewall 3140 |
20,000 |
|
Secure Firewall 6100 |
60,000 |
|
Secure Firewall 4215 |
20,000 |
|
Secure Firewall 4225 |
25,000 |
|
Secure Firewall 4245 |
30,000 |
|
Firepower 4100, all models |
10,000 |
|
Firepower 9300 appliance, all models |
20,000 |
|
ISA 3000 |
25 |
For capacity of other hardware models, check the data sheets.
Note | Once the maximum session limit is reached, the Firewall Threat Defense device denies incoming VPN connections and generates a syslog message. Refer to the syslog messages %FTD-4-113029 and %FT-4-113038 in the syslog messaging guide. For more information, refer to Cisco Secure Firewall Threat Defense Syslog Messages. |