Cisco FPR1120-NGFW-K9 — Firepower 1120 Next-Generation Firewall Appliance
What it is
FPR1120-NGFW-K9 is a Cisco Firepower 1120 next-generation firewall appliance designed for small to midsize businesses, branch offices, and remote sites that need enterprise-grade firewalling, intrusion prevention, VPN, and application-aware security.
It provides 8 × Gigabit Ethernet RJ-45 ports plus 4 × Gigabit SFP ports in a compact rack-mount chassis, with support for Cisco Threat Defense software.
Why buyers pick FPR1120-NGFW-K9 (plain English)
2.3 Gbps firewall throughput: The Firepower 1120 is rated for up to 2.3 Gbps firewall + application visibility throughput, giving it enough performance for many branch and midsize business deployments.
Strong IPS performance: It delivers up to 2.6 Gbps IPS throughput, helping inspect traffic for exploits and malicious activity without heavily sacrificing performance.
Plenty of interfaces: Eight copper Gigabit ports plus four SFP ports give you flexibility for WAN, LAN, DMZ, and fiber connections.
Built for secure branch networks: Supports firewalling, application control, intrusion prevention, VPN, malware protection, URL filtering, and other Cisco security services.
Rack-mount form factor: Unlike the smaller desktop Firepower 1010, the 1120 is designed as a proper rack-mounted security appliance.
60-second spec box (FPR1120-NGFW-K9)
Network interfaces
- 8 × 10/100/1000Base-T RJ-45
- 4 × 1 Gigabit SFP
- Dedicated management connectivity
- Suitable for WAN, LAN, DMZ, and uplink connections
Firewall performance
- Up to 2.3 Gbps firewall + application visibility throughput
- Up to 2.3 Gbps firewall + AVC + IPS throughput
IPS performance
- Up to 2.6 Gbps IPS throughput
VPN
- Up to approximately 1.2 Gbps IPsec VPN throughput
- Supports site-to-site VPN
- Supports remote-access VPN
- Up to approximately 150 VPN peers
Sessions
- Up to 200,000 concurrent sessions
- Designed for branch and midsize enterprise traffic loads
Security features
- Stateful firewall
- Application visibility and control
- Intrusion Prevention System (IPS)
- URL filtering
- Malware protection
- IPsec VPN
- Remote-access VPN
- Access control policies
- NAT
- Security intelligence / reputation-based blocking
Software
- Cisco Threat Defense
- Centralized management options
- Cisco Secure Firewall Management Center support
Management
- Web-based management
- CLI
- Centralized Cisco management
- Logging and monitoring
- SNMP / syslog support
Physical
- 1RU rack-mount appliance
- Approx. 1.72 × 10.58 × 17.2 in
- Approx. 8 lb / 3.63 kg
- Internal power supply
Where it fits (and when to choose something else)
Perfect for:
- Small and midsize businesses
- Branch-office firewalls
- Secure Internet edge
- Site-to-site VPN deployments
- Remote-access VPN
- Networks requiring IPS and application control
- Customers replacing older ASA 5508-X / 5516-X appliances
Choose something else if:
- You need less throughput and a desktop form factor → consider Firepower 1010
- You need more firewall capacity → consider Firepower 1140
- You need significantly higher performance or 10G interfaces → consider Firepower 1150 or larger Secure Firewall platforms
- You need a pure ASA deployment rather than Threat Defense → use the appropriate ASA-image configuration
TL;DR
FPR1120-NGFW-K9 is a Cisco Firepower 1120 next-generation firewall with 8× Gigabit RJ-45 ports, 4× 1G SFP ports, up to 2.3 Gbps firewall throughput, 2.6 Gbps IPS performance, and IPsec VPN support — a strong fit for secure branch and midsize business networks.

