Brand: Cisco | Category: Network Security
SKU: CISC-FPR1230NGFWK9 | Part #: FPR1230-NGFW-K9 | MPN: FPR1230-NGFW-K9
Contact for Pricing — Request a Quote
The Cisco Secure Firewall 1230 Series represents a ground-up refresh of the branch-office firewall portfolio, succeeding the 1100 line with a new hardware platform engineered to meet the demands of modern distributed enterprises. Built around a purpose-designed ASIC-accelerated forwarding architecture, the 1230 delivers significantly higher VPN throughput than its predecessors, supporting large-scale IPsec and SSL/TLS remote-access tunnels simultaneously without sacrificing stateful inspection performance. The appliance ships with Cisco Secure Firewall Threat Defense (formerly Firepower Threat Defense) pre-installed, unifying next-generation firewall policy, intrusion prevention, URL filtering, advanced malware protection, and encrypted traffic analytics into a single software image managed through Cisco Security Cloud Control or on-premises Cisco Secure Firewall Management Center.
The 1230 Series is purpose-sized for medium-to-large branch offices, retail aggregation points, and industrial edge deployments where rack space is constrained but security posture must match headquarters standards. The compact 1RU form factor integrates onboard copper and optional fiber WAN interfaces, a built-in hardware security module for key storage, and dedicated out-of-band management connectivity. Cisco TrustSec and Encrypted Visibility Engine (EVE) capabilities allow the 1230 to classify and enforce policy on encrypted flows using machine-learning telemetry without requiring full TLS decryption, reducing latency and computational overhead at bandwidth-sensitive sites.
Deep integration with Cisco's broader security ecosystem—including Cisco Umbrella for DNS-layer enforcement, Cisco Duo for identity-based access, Cisco XDR for unified threat visibility, and SD-WAN fabrics via Cisco Catalyst SD-WAN—positions the 1230 as a Secure Access Service Edge (SASE) on-ramp appliance. Zero-touch provisioning through Cisco Defense Orchestrator dramatically reduces deployment complexity for IT teams managing dozens or hundreds of branch locations, while day-2 operations benefit from streaming telemetry, automated threat correlation, and centralized policy versioning.
| Manufacturer | Cisco |
| Product Series | Cisco Secure Firewall 1230 |
| Form Factor | 1U Rack-Mount Appliance |
| Firewall Throughput | Up to 10 Gbps (stateful FW) |
| Threat Defense (NGFW+IPS) Throughput | Up to 4 Gbps |
| VPN Throughput (IPsec) | Up to 5 Gbps |
| Maximum Concurrent VPN Sessions | 10,000 (IPsec + SSL combined) |
| Maximum Concurrent Connections | 4,000,000 |
| New Connections Per Second | 100,000 |
| Integrated Network Interfaces | 8x 1G RJ-45, 4x 10G SFP+, 1x dedicated Management RJ-45, 1x Console |
| Optional Interface Expansion | 1x Network Module Slot supporting 4x 10G SFP+ or 4x 1G copper |
| Hardware Security Module | Onboard TPM 2.0 for secure key storage and measured boot |
| Storage | 256 GB M.2 SSD (internal, for local logging and diagnostics) |
| Memory (RAM) | 16 GB DDR4 ECC |
| Power Supply | Dual redundant hot-swap AC power supplies (250W each) |
| Operating System / Software | Cisco Secure Firewall Threat Defense (FTD) 7.x |
| Management Options | Cisco Security Cloud Control (cloud), Cisco Secure Firewall Management Center (on-prem), Local Device Manager (FDM) |
| High Availability | Active/Standby and Active/Active failover with stateful session synchronization |
| Routing Protocols Supported | BGP, OSPF, EIGRP, RIP, IS-IS, Static, PBR |
| VLAN Support | Up to 1,024 802.1Q VLANs |
| Security Intelligence Features | Intrusion Prevention (Snort 3), Application Visibility and Control (AVC), URL Filtering, Advanced Malware Protection (AMP), Encrypted Visibility Engine (EVE), TLS 1.3 inspection |
| Zero-Touch Provisioning | Supported via Cisco Defense Orchestrator and Cisco Plug-and-Play (PnP) |
| Dimensions (H x W x D) | 1.73 in x 17.2 in x 16.9 in (43.9 mm x 437 mm x 429 mm) |
| Weight | 8.5 kg (18.7 lb) |
| Operating Temperature | 0°C to 40°C (32°F to 104°F) |
| Compliance & Certifications | Common Criteria EAL4+, FIPS 140-2 Level 2, IPv6 Ready Logo, UL/CE/FCC Class A |
Available from Omnixon Global. Submit an RFQ and our team will confirm configuration and availability for your order.
| Brand | Cisco |
| Category | Network Security |
| SKU | CISC-FPR1230NGFWK9 |
| Part Number | FPR1230-NGFW-K9 |
| Condition | New |
| Product Series | Cisco Secure Firewall 1230 |
| Form Factor | 1U Rack-Mount Appliance |
| Firewall Throughput | Up to 10 Gbps (stateful FW) |
| Threat Defense (NGFW+IPS) Throughput | Up to 4 Gbps |
| VPN Throughput (IPsec) | Up to 5 Gbps |
| Maximum Concurrent VPN Sessions | 10,000 (IPsec + SSL combined) |
| Maximum Concurrent Connections | 4,000,000 |
| New Connections Per Second | 100,000 |
| Integrated Network Interfaces | 8x 1G RJ-45, 4x 10G SFP+, 1x dedicated Management RJ-45, 1x Console |
| Optional Interface Expansion | 1x Network Module Slot supporting 4x 10G SFP+ or 4x 1G copper |
| Hardware Security Module | Onboard TPM 2.0 for secure key storage and measured boot |
| Storage | 256 GB M.2 SSD (internal, for local logging and diagnostics) |
| Memory (RAM) | 16 GB DDR4 ECC |
| Power Supply | Dual redundant hot-swap AC power supplies (250W each) |
| Operating System / Software | Cisco Secure Firewall Threat Defense (FTD) 7.x |
| Management Options | Cisco Security Cloud Control (cloud), Cisco Secure Firewall Management Center (on-prem), Local Device Manager (FDM) |
| High Availability | Active/Standby and Active/Active failover with stateful session synchronization |
| Routing Protocols Supported | BGP, OSPF, EIGRP, RIP, IS-IS, Static, PBR |
| VLAN Support | Up to 1,024 802.1Q VLANs |
| Security Intelligence Features | Intrusion Prevention (Snort 3), Application Visibility and Control (AVC), URL Filtering, Advanced Malware Protection (AMP), Encrypted Visibility Engine (EVE), TLS 1.3 inspection |
| Zero-Touch Provisioning | Supported via Cisco Defense Orchestrator and Cisco Plug-and-Play (PnP) |
| Dimensions (H x W x D) | 1.73 in x 17.2 in x 16.9 in (43.9 mm x 437 mm x 429 mm) |
| Weight | 8.5 kg (18.7 lb) |
| Operating Temperature | 0°C to 40°C (32°F to 104°F) |
| Compliance & Certifications | Common Criteria EAL4+, FIPS 140-2 Level 2, IPv6 Ready Logo, UL/CE/FCC Class A |
The Cisco Secure Firewall 1230 Series is enterprise networking hardware for data-center, campus, and branch deployments. Common roles include core/distribution switching, server uplinks, top-of-rack fabric, and edge connectivity in mixed Cisco/Juniper/Arista environments.
The Cisco Secure Firewall 1230 Series is enterprise networking hardware for data-center, campus, and branch deployments. Common roles include core/distribution switching, server uplinks, top-of-rack fabric, and edge connectivity in mixed Cisco/Juniper/Arista environments.
Key specifications for the Cisco Secure Firewall 1230 Series: new condition; manufacturer Cisco; product series Cisco Secure Firewall 1230; form factor 1U Rack-Mount Appliance; firewall throughput Up to 10 Gbps (stateful FW); threat defense (ngfw+ips) throughput Up to 4 Gbps; vpn throughput (ipsec) Up to 5 Gbps. Manufacturer part number FPR1230-NGFW-K9. For the full datasheet with electrical, environmental, and compliance details, contact our pre-sales engineering team.
Key specifications for the Cisco Secure Firewall 1230 Series: new condition; manufacturer Cisco; product series Cisco Secure Firewall 1230; form factor 1U Rack-Mount Appliance; firewall throughput Up to 10 Gbps (stateful FW); threat defense (ngfw+ips) throughput Up to 4 Gbps; vpn throughput (ipsec) Up to 5 Gbps. Manufacturer part number FPR1230-NGFW-K9. For the full datasheet with electrical, environmental, and compliance details, contact our pre-sales engineering team.
The Cisco Secure Firewall 1230 Series interoperates with standard switching protocols (LACP, MLAG/VPC, 802.1Q, OSPF/BGP). For specific cross-vendor scenarios — Cisco-to-Arista MLAG peering, fabric integration with Cumulus/SONiC, or migration from legacy Catalyst — our network engineers map a compatibility plan as part of the RFQ.