ASA 5510 Security Appliance with SW, 5FE,3DES/AES, Cisco ASA 5500 Series Firewall Edition Bundles

ASA5510-BUN-K9 Overview

Cisco ASA 5510 Adaptive Security Appliance ASA5510-BUN-K9 is designed to protect networks for small and medium-sized businesses and enterprise remote/branch offices in an easy-to-deploy, cost-effective way. The Cisco ASA 5510 has high-performance firewall, VPN services and five 10/100 integrated Fast Ethernet ports. It also supports high-performance intrusion prevention and worm mitigation services through the AIP SSM, or comprehensive malware protection services through the CSC SSM, from which modules make ASA5510-BUN-K9 an excellent choice for different businesses requiring.

Security Plus license can upgrade two of the Cisco ASA 5510 interfaces to Gigabit Ethernet and enable integration into switches through VLAN support. Simultaneously this upgrade license enables Active/Active and Active/Standby high-availability services. Moreover, up to 250 IPsec VPN peers supported on the base platform, up to 250 AnyConnect and/or clientless VPN peers supported on an Essential or a Premium AnyConnect VPN license makes the Cisco ASA 5510 a perfect choice for businesses want to extend their number of mobile workers, remote sites, and business partners.


  • Market-proven security capabilities
  • Extensible integrated services architecture
  • Reduced deployment and operations costs
  • Comprehensive management interfaces



LED Color State Description
Power Green On The system has power
Status Green Flashing The power-up diagnostics are running or the system is booting
Solid The system has passed power-up diagnostics
Amber Solid The power-up diagnostics have failed
Active Green Solid This unit is the Active unit in the failover pair
Amber Solid This unit is the Standby unit
VPN Green Solid A VPN tunnel has been established
Flash Green Solid The CompactFlash is being accessed

Security Services Processors, Modules and Cards:

The Cisco ASA 5500 Series brings a new level of integrated security performance to networks with its highly effective IPS services and multiprocessor hardware architecture. This architecture allows businesses to adapt and extend the high-performance security services profile of the Cisco ASA 5500 Series. Customers can add additional high-performance services using security services modules with dedicated security co-processors, and can custom-tailor flow-specific policies using a highly flexible policy framework. This adaptable architecture enables businesses to deploy new security services when and where they are needed, such as adding the broad range of intrusion prevention and advanced anti-worm services delivered by the IPS modules via IPS SSP, AIP SSM and AIP SSC, or the comprehensive malware protection and content security services enabled by the CSC SSM. Further, the architecture allows Cisco to introduce new services to address new threats, giving businesses outstanding investment protection for the Cisco ASA 5500 Series.


Characteristics of Cisco AIP SSM and SSC Models for ASA5510:

Cisco ASA 5500 Series AIP SSM-10 Concurrent Threat Mitigation Throughput (Firewall + IPS Services)
150 Mbps with Cisco ASA 5510
Cisco ASA 5500 Series AIP SSM-20
                300 Mbps with Cisco ASA 5510
Cisco ASA 5500 Series CSC-SSM-10 Optional User license (Total Users)
• 50 users

• 100 users

• 250 users

• 500 users

Cisco ASA 5500 Series CSC-SSM-20
• 500 users

• 750 users

• 1000 users

Cisco ASA 5500 Series 4-Port GE SSM Integrated Ports
Five Fast Ethernet and four Gigabit Ethernet ports

Product FAQ

Q: Please confirm if the ASA5510-BUN-K9 will assist me in the following: 1. Act as a firewall, were I can configure access control on at port level, 2. I can also control protocol control at application level 3. Extract audit logs on who has access denials and allowance. 4. Securely provide web and remote access to application. 5. Support VPN implementation.

A: YES, they are all the basic features of ASA device.

Q: Kindly advice on which ASA i will find below features: Content Security [anti-virus, anti-spyware, file blocking, anti-spam, anti-phishing, and URL filtering] (Max users).

A: ASA5510-CSC20-K9 ASA 5510 Appl w/ CSC20, SW, 500 Usr AV/Spy, 1 YR Subscript.

Q: Can ASA5510-BUN-K9setup SITE TO SITE VPN without SEC license?

A: YSE, Cisco ASA 5510 Firewall Edition includes 5 Fast Ethernet interfaces, 250 IPsec VPN peers, 2 Premium VPN peers, 3DES/AES license.

250 IPsec VPN peers is SITE TO SITE VPN.


Q: How can configure my ASA 5510 to Router 3925 via vpn (if its is possible dmvpn)?

A: The ASA soes not support DMVPN so you’ll just have to configure a regular S to S.

Q: I’ve recently taken over a new role from a co-worker and could really use some expert advice. I’m attempting to setup Outlook Web Access and a secondary MX record over at my failover datacenter. There I have a 5510 which already has an IP assigned by our ISP bound to the WAN interface. I purchased a new block of addresses on a different subnet that I’d like to use for OWA and a secondary MX record at my datacenter. I can’t seem to bind more than one public address in a different subnet to the WAN interface which is how I thought this would work. I further read that the work-around is to use Proxy ARP and NAT. Being new to this I could really use some step-by-step help in configuring the ASA so the new addresses I have are properly forwarded to Exchange (OWA) and Websense (secondary MX). I can have Cisco support do it but I want to understand how this works so I can be more useful in the future. Many thanks in advance for any assistance!

A: You do not need to assign the public IP to an interface to use it for NAT. You simply configure NAT and allow the traffic in your acl (if you have one). What version of code are you running on your ASA because NAT is very different from 8.3 onwards. “sh run” will show the version right at the top.

