Cisco Firewall 6100 is a high-performance firewall platform designed for demanding data-center, service-provider, and telecommunications security environments. The series combines high-throughput firewalling with advanced threat inspection, encrypted-traffic processing, VPN termination, application visibility, and scalable interface options in a 2RU hardware platform.
The current Cisco Secure Firewall 6100 Series includes the 6160 and 6170 models. The platform supports both Cisco Secure Firewall Threat Defense (FTD) and Cisco ASA software, allowing organizations to select the appropriate security architecture according to their operational and technical requirements.
Series Highlights
- Designed for high-performance data-center and telecommunications environments
- Available as Cisco Secure Firewall 6160 and 6170
- Supports Cisco Secure Firewall Threat Defense and ASA
- Up to 700 Gbps firewall throughput with FTD on the 6170
- Supports IPS, application visibility, VPN, TLS inspection, and advanced threat protection
- Supports network modules from 1G through high-performance 400G QSFP-DD interfaces
- Dedicated cryptographic hardware accelerates IPsec and TLS processing
Review Cisco Firewall 6100 Price List and request a quote tailored to your licensing needs.

Cisco Firewall 6100 At a glance
What it is: High-performance Cisco Secure Firewall platform for data-center, service-provider, and telecommunications security.
Product family: Cisco Firewall License
Current models: Cisco Secure Firewall 6160 and Cisco Secure Firewall 6170
Form factor: 2RU
Software: Cisco Secure Firewall Threat Defense and Cisco ASA
Primary use: High-throughput firewalling, NGFW inspection, VPN, IPS, encrypted-traffic security, and carrier-grade security
FTD throughput: Up to 600 Gbps on 6160 and 700 Gbps on 6170 for firewall plus application visibility and control under Cisco’s documented test conditions.
NGFW throughput: Up to 550 Gbps on 6160 and 600 Gbps on 6170 under the documented FTD test configuration.
IPsec VPN: Up to 450 Gbps on 6160 and 550 Gbps on 6170 under the documented test conditions.
Series Overview
Cisco Firewall 6100 is designed for environments where firewall throughput and security inspection must scale together. The platform uses a multi-socket, multi-core architecture and dedicated cryptographic processing to handle demanding firewall, IPsec, and TLS workloads without relying entirely on general-purpose processing.
The series is particularly suited to data-center perimeter security, high-volume internet gateways, telecommunications infrastructure, and service-provider environments. Cisco also positions the platform for carrier-grade functions such as CGNAT, scalable security gateways, and inspection of protocols including GTP, SIP, and Diameter.
The 6100 is not simply a higher-throughput version of a smaller branch firewall. Its value is primarily in the combination of performance density, modular interfaces, cryptographic acceleration, advanced threat inspection, and carrier-oriented capabilities.
Licensing and Part Number Guidance
Selecting the correct Cisco Firewall 6100 configuration requires more than choosing the 6160 or 6170 appliance. The final configuration should account for the firewall software, required security services, network modules, interface speeds, throughput expectations, management platform, and support term.
With Firewall Threat Defense, organizations can build a next-generation firewall architecture around capabilities such as application visibility and control, intrusion prevention, malware protection, URL filtering, security intelligence, and encrypted-traffic inspection. The exact subscription requirements depend on the selected software and security services.
ASA provides a different operating model and can deliver higher stateful-inspection throughput for environments where traditional firewall functionality is the primary requirement. Cisco documents both FTD and ASA performance separately for the 6100 platform.
The quotation should therefore distinguish between:
- Firewall appliance model
- FTD or ASA software
- Required security subscriptions
- Network modules
- Interface and transceiver requirements
- VPN requirements
- TLS inspection requirements
- Management platform
- High-availability or clustering requirements
- Support and subscription term
Common Use Cases
| Use Case | Why it matters |
|---|---|
| Data Center Perimeter Security | Provides high-throughput firewalling and threat inspection between internal infrastructure, external networks, and internet-facing applications |
| Service-Provider Security | Supports large traffic volumes, carrier-grade firewalling, CGNAT, and specialized security gateway deployments |
| Telecommunications Security | Supports inspection of telecom protocols and high-scale IPsec termination for mobile and carrier environments |
| Internet Edge | Provides high-capacity security inspection for large internet-facing network gateways |
| VPN Aggregation | Supports large-scale IPsec connectivity for site-to-site and other VPN architectures |
| Encrypted Traffic Inspection | Uses dedicated cryptographic processing and TLS capabilities for large encrypted-traffic environments |
| NGFW Deployment | Combines stateful firewalling with application visibility, IPS, and advanced threat-defense capabilities |
| High-Availability Security | Supports resilient architectures using clustering, redundant power, and other availability mechanisms |
Cisco documents up to 550 Gbps of IPsec tunnel termination on the 6100 Series for applicable security-gateway deployments, demonstrating the platform’s focus on high-volume encrypted connectivity.
Models, Licenses, and Ordering Scope
| Area to check | What to confirm |
|---|---|
| Firewall model | Cisco Secure Firewall 6160 or 6170 |
| Software | Cisco Secure Firewall Threat Defense or Cisco ASA |
| Firewall throughput | Required normal and peak traffic levels |
| NGFW throughput | Traffic requiring AVC and IPS inspection |
| VPN | IPsec throughput, tunnel requirements, and encryption architecture |
| TLS inspection | Encrypted traffic volume and decryption requirements |
| Network modules | Required module type, port density, interface speed, and optics |
| Security services | IPS, malware protection, URL filtering, application visibility, and related subscriptions |
| Management | Firewall Management Center or supported centralized management architecture |
| High availability | Redundancy, clustering, and failover requirements |
| Carrier features | CGNAT, GTP, SIP, Diameter, SEG, and other telecom requirements |
| Support | Cisco support level, subscription term, and renewal requirements |
The 6160 and 6170 have different published performance levels, so the model should be selected according to the actual inspection workload rather than simply choosing the higher model based on interface count. Cisco’s current specifications show up to 600 Gbps FTD firewall plus AVC throughput on the 6160 and 700 Gbps on the 6170.
What to Check Before Requesting a Quote
Before requesting a quote for Cisco Firewall 6100, determine the expected traffic profile first. Standard firewall traffic, application inspection, IPS, VPN, and TLS decryption can produce substantially different processing requirements.
The next step is to select the appropriate appliance model and software architecture. Confirm whether the environment requires FTD’s next-generation security capabilities or ASA for a more traditional stateful firewall deployment.
Also prepare the required network-module and interface design. The 6100 Series supports a wide range of interface options, extending from 1G connectivity to high-performance 400G QSFP-DD interfaces.
For an existing environment, collect:
- Current firewall model and serial information
- Software version
- Current throughput
- Enabled security services
- Network-module configuration
- Interface and transceiver inventory
- VPN usage
- TLS inspection requirements
- Management platform
- Support and subscription status
- HA or clustering configuration
This information makes it easier to distinguish a new deployment from an expansion, replacement, migration, or renewal request.
Activation and Delivery Notes
After the Cisco Firewall 6100 appliance and required licensing are selected, the deployment begins with the appropriate software image and management architecture. Cisco’s getting-started documentation recommends confirming the software version, obtaining the required licenses, and ensuring connectivity before beginning deployment.
For FTD deployments, the firewall can be managed through Cisco Secure Firewall Management Center. The management architecture should be selected before deployment because it affects configuration, policy administration, event visibility, and operational workflows.
During delivery and installation, verify that the hardware configuration matches the quotation. In particular, confirm the firewall model, network modules, interface configuration, optics, software version, licensing, and support coverage.
For a new installation, the general workflow is:
Hardware Installation
→ Install the 6100 appliance and required network modules.
Software Preparation
→ Verify and install the supported FTD or ASA software.
License Activation
→ Apply the applicable licensing and security subscriptions.
Management Configuration
→ Connect the firewall to the selected management platform.
Security Configuration
→ Configure interfaces, routing, access policies, NAT, VPN, IPS, and other required services.
Validation
→ Test traffic forwarding, security inspection, VPN connectivity, logging, and high-availability functions.
Cisco Firewall 6100 Pricing and Quote
Cisco Firewall 6100 pricing depends on the selected appliance model, software, security subscriptions, network modules, interface requirements, support level, and contract term.
The quote should be based on the actual security architecture rather than the appliance model alone. A deployment using FTD with IPS, malware protection, TLS inspection, and high-speed network modules can have a substantially different licensing and hardware scope from an ASA-based stateful firewall deployment.
For an accurate quotation, provide:
- Required 6160 or 6170 model
- FTD or ASA requirement
- Expected firewall throughput
- IPS and NGFW throughput
- IPsec requirements
- TLS decryption requirements
- Required network modules
- Interface and optic requirements
- Security subscriptions
- Management platform
- HA or clustering requirements
- Carrier features where applicable
- Support and subscription term
Cisco Firewall pricing depends on your license type, deployment model and support requirements.
