Cisco Secure Firewall ISA3000

The Cisco Secure Firewall ISA3000 is a true industrial firewall that provides OT-targeted protection based on proven enterprise-class security. The ISA3000, with four data links, is a DIN rail mount, a ruggedized appliance that provides the widest range of access, threat, and application controls for the harshest and most demanding industrial environments.
The ISA3000 bundles the proven security of the Cisco Secure Firewall with the visibility and control of industrial protocols and applications developed by leading automation vendors such as Omron, Rockwell, GE, Schneider, Siemens, and others. The ISA3000 is key as you start converging IT and OT security and capturing the benefits of your industrial digitization efforts.

The Cisco Secure Firewall ISA3000 Models:

Product number Base software Copper 10/100/1000 (all bypass enabled) SFP fiber ports
ISA-3000-2C2F-K9 ASA 2 2
ISA-3000-4C-K9 ASA 4 0
ISA-3000-2C2F-FTD FTD 2 2
ISA-3000-4C-FTD FTD 4 0

 

 

Physical Specifications Firewall ISA3000:

Description Specification
Hardware ●  4-core Intel ® Atom ® processor (industrial temp.) 

●  8-GB DRAM (soldered down)

●  16-GB onboard flash memory

●  mSATA 64 GB

●  1-GB removable SD flash memory card (industrial temp.)

●  Mini-USB connector for console

●  RJ-45 traditional console connector

●  Dedicated 10/100/1000 management port

●  Hardware-based anti-counterfeit, anti-tamper chip

●  Factory reset option

Alarm I/O ●  Two alarm inputs to detect dry contact open or closed 

●  One Form C alarm output relay

Dimensions (WxHxD) ●  11.2 x 13 x 16 cm (4.41 x 5.12 x 6.30 in.)
Weight ●  1.9 kg (4.2 lb)
Power supply and ranges ●  Dual internal DC 

●  Nominal: ± 12V DC, 24V DC, or 48V DC

●  Maximum range: 9.6V DC to 60V DC

●  Power consumption: 24W

Mean time between failures (MTBF) ●  ISA-3000-4C: 398,130 hours 

●  ISA-3000-2C2F: 376,580 hours

 

Networking standards:

Description Specification
IEEE standards ●  IEEE 802.1D MAC Bridges, Spanning Tree Protocol (STP) 

●  IEEE 802.1p Layer2 class-of-service (COS) prioritization

●  IEEE 802.1q VLAN

●  IEEE 802.1s Multiple Spanning-Trees

●  IEEE 802.1w Rapid Spanning-Tree

●  IEEE 802.1x Port Access Authentication

●  IEEE 802.1AB Link Layer Discovery Protocol (LLDP)

●  IEEE 802.3ad Link Aggregation (LACP)

●  IEEE 802.3ah 100BASE-X single-mode fiber (SMF)/multimode fiber (MMF) only 

●  IEEE 802.3x full duplex on 10BASE-T

●  IEEE 802.3 10BASE-T specification

●  IEEE 802.3u 100BASE-TX specification

●  IEEE 802.3ab 1000BASE-T specification

●  IEEE 802.3z 1000BASE-X specification

●  IEEE 1588v2 PTP

RFC compliance ●  RFC 768: User Datagram Protocol (UDP) 

●  RFC 783: Trivial FTP (TFTP)

●  RFC 791: IPv4

●  RFC 792: Internet Control Message Protocol (ICMP)

●  RFC 793: TCP

●  RFC 826: Address Resolution Protocol (ARP)

●  RFC 854: Telnet

●  RFC 951: BOOTP

●  RFC 959: FTP

●  RFC 1157: SNMPv1

●  RFC 1901,1902-1907 SNMPv2

●  RFC 2273-2275: SNMPv3

●  RFC 2571: SNMP Management

●  RFC 1166: IP Addresses

●  RFC 1256: ICMP Router Discovery

●  RFC 1305: NTP 

●  RFC 1492: TACACS+

●  RFC 1493: Bridge MIB Objects

●  RFC 1534: DHCP and BOOTP interop.

●  RFC 1542: Bootstrap Protocol

●  RFC 1643: Ethernet Interface MIB

●  RFC 1757: RMON

●  RFC 2068: HTTP

●  RFC 2131, 2132: DHCP

●  RFC 2236: IGMP v2

●  RFC 3376: IGMP v3

●  RFC 2474: DiffServ Precedence

●  RFC 3046: DHCP Relay Agent Information option

●  RFC 3580: 802.1X RADIUS

●  RFC 4250-4252 SSH Protocol