Page 1
Cisco Firepower 9300 Hardware Installation Guide First Published: 2015-07-16 Last Modified: 2018-11-14 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387) Fax: 408 527-0883...
Page 2
Cisco has more than 200 offices worldwide. Addresses and phone numbers are listed on the Cisco website at www.cisco.com/go/offices. Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: www.cisco.com...
Hardware Bypass Network Modules 40-G Network Module with Hardware Bypass 10-G SR/10-G LR Network Module with Hardware Bypass Power Supply Modules Fan Modules Supported SFP/SFP+ and QSFP Transceivers Hardware Specifications Product ID Numbers Power Cord Specifications Cisco Firepower 9300 Hardware Installation Guide...
Page 4
Remove and Replace the Single-Wide Network Module Remove and Replace the Double-Wide Network Module Remove and Replace the Power Supply Module Connect the DC Power Supply Module Connect the HVDC Power Supply Module Remove and Replace the Fan Module Cisco Firepower 9300 Hardware Installation Guide...
Power Cord Specifications, on page 33 Features The Cisco Firepower 9300 security appliance is a next generation network and content security platform. Its modular standalone chassis offers high-performance and flexible I/O options, which enable it to run multiple security services simultaneously. See...
Page 6
Overview Features Note The Firepower 9300 is certified for Common Criteria (CC) and Federal Information Processing Standards (FIPS). See "Security Certifications Compliance" in the Cisco FXOS CLI Configuration Guide for the procedure for enabling these modes using the CLI. See "Security Certifications...
Page 7
Description Security modules Cisco Firepower 9000 Security Module 24 with two SSDs in a RAID 1 configuration Cisco Firepower 9000 Security Module 36 with two SSDs in a RAID 1 configuration Cisco Firepower 9000 Security Module 44 with two SSDs in a RAID 1 configuration...
10 seconds before turning power back ON. The Firepower 9300 chassis has a standby power switch at the rear of the chassis. It controls both power supply modules. You must shut down the software applications gracefully before turning the switch to OFF.
Deployment Options Here are some examples of how you can deploy the Firepower 9300: • At the core/aggregation layer of a three-tier data center in a high availability configuration. • As a dedicated multifunction security service within converged infrastructure stacks (vBlock, FlexPod, for example) at the access layer.
• As a leaf that exclusively offers security functions in a spine/leaf data center design. Package Contents The following figure shows the package contents for the Firepower 9300. Note that the contents are subject to change and your exact contents might contain additional or fewer items.
Welcome to the Cisco Firepower 9300 Serial Number Location The serial number for the Firepower 9300 chassis is located on the pullout asset card on the front panel, on the side of the chassis, and on the Supervisor. Figure 3: Serial Numbers on the 9300 Chassis You can also view additional model information on the compliance label located on the bottom of the chassis.
For the procedure to remove the Supervisor so that you can see the serial number, see Remove and Replace the Supervisor, on page Front Panel The following figure shows the front panel of the Firepower 9300. Figure 5: Firepower 9300 Front Panel Cisco Firepower 9300 Hardware Installation Guide...
Power Supply Modules, on page 24 for detailed information about the power supply modules. Rear Panel The following figure shows the rear panel of the Firepower 9300. Figure 6: Firepower 9300 Rear Panel Power feed for PSU-2 Power feed for PSU-1...
Supervisor The Firepower 9300 contains a supervisor management I/O card called the Firepower 9300 Supervisor, which is located on the front panel. The Supervisor provides chassis management and eight 1- or 10-G SFP+ interfaces, and it directs traffic to/from the Firepower 9300 security modules.
Page 15
RJ-45 Console Port The Firepower 9300 has a standard RJ-45 console port. You can use the CLI to configure your Firepower 9300 through the RJ-45 serial console port by using a terminal server or a terminal emulation program on a computer.
The USB Type A port does not support Cisco Secure Package (CSP) image upload. Network Ports The Firepower 9300 chassis has eight ports for 1-G or 10-G SFPs (fiber or copper). They are numbered from left to right starting with 1 and are named Ethernet 1/1 through Ethernet 1/8.
Page 17
If you replace a security module with a new security module, you must decommission the old security module. See the "Security Module/Engine Management" chapter in the Cisco FXOS Firepower Chassis Manager Configuration Guide for the instructions. See Remove and Replace the Security Module for the procedure for replacing security modules. Cisco Firepower 9300 Hardware Installation Guide...
Overview Network Modules Network Modules The Firepower 9300 contains two network module slots that provide optical or electrical network interfaces. Network modules are optional, removable I/O modules that provide either additional ports or different interface types (1/10/40/100 G). The Firepower network modules plug into the chassis on the front panel. You can also remove the divider between the two network module slots and insert a double-wide network module.
The following figure shows the front panel of the 40-G network module (FPR9K-NM-4X40G.) The FPR9K-NM-4X40G is a single-wide module that supports hot swapping. The four ports are numbered left to right. Note The FPR9K-NM-4X40G is NEBS-compliant. Cisco Firepower 9300 Hardware Installation Guide...
FPRK9-NM-2X100G is a single-wide module that supports hot swapping. The two ports are numbered left to right. Note You must upgrade your Firepower 9300 to firmware package 1.0.16 or later and have FXOS 2.3.2 or later installed to support this network module. Cisco Firepower 9300 Hardware Installation Guide...
100-G Network Module (Four Ports Single Wide) The following figure shows the front panel of the 100-G network module ( FPR-NM-4X100G). The FPR-NM-4X100G is a single-wide module that supports hot swapping. The four ports are numbered left to right. Cisco Firepower 9300 Hardware Installation Guide...
Overview 100-G Network Module (Double Wide) Note You must upgrade your Firepower 9300 to firmware package 1.0.16 or later and have FXOS 2.3.2 or later installed to support this network module. Figure 12: FPR-NM-4X100G Power LED Ethernet X/1 Ethernet X/2...
Hardware bypass is supported only on a fixed set of ports. You can pair Port 1 with Port 2, Port 3 with Port 4, but you cannot pair Port 1 with Port 4 for example. Note Hardware bypass is only supported in inline mode. Also, hardware bypass support depends on your software application. Cisco Firepower 9300 Hardware Installation Guide...
The following figure shows the front panel of the 40-G fail-to-wire network module (FPR9K-NM-2X40G-F). The FPR9K-NM-2X40G-F is a single-wide module that does not support hot swapping. The two ports are numbered left to right. Pair the two ports to create a hardware bypass paired set. Cisco Firepower 9300 Hardware Installation Guide...
Page 25
The following table describes the cable specifications needed to keep the insertion loss as low as possible. Table 2: 40-G BASE-SR Cable Specifications Interface Supported Cable Ethernet 40-G BASE-SR4 50 microns core diameter 850 nm wavelength 2000/4700 (OM3/4) modal bandwidth (MHz*km) MPO-12 port adapter 50 m cable distance Cisco Firepower 9300 Hardware Installation Guide...
10-G SR/10-G LR Network Module with Hardware Bypass Note See the Cisco 40GBASE QSFP Modules Data Sheet for specifications of the QSFP for the 40-G BASE-SR-4. We recommend the following Cisco OM3 MTP/MPO cables. Table 3: Cisco Cables Cisco Part Number Cable Length CAB-ETH-40G-5M...
Page 27
41 m 2000 (OM3) 150 m 4700 (OM4) 200 m Table 5: 10-G LR Network Module (FPR9K-NM-6X10LR-F) Operating Mode Typical Maximum Insertion loss Normal 1.2 dB 1.6 dB Hardware bypass 1.5 dB 1.9 dB Cisco Firepower 9300 Hardware Installation Guide...
Power Supply Modules The Firepower 9300 supports two AC, two DC, or two high-voltage DC (HVDC) power supply modules so that dual power supply redundancy protection is available. Facing the front of the chassis, the power supply modules are numbered left to right, for example, PSU-1 and PSU-2.
• See Connect the HVDC Power Supply Module, on page 72 for the procedure for connecting the HVDC power supply module. • See Hardware Specifications, on page 29 for the power supply hardware specifications. Cisco Firepower 9300 Hardware Installation Guide...
Fan Modules Fan Modules The Firepower 9300 requires four fan modules, which are hot-swappable. They are installed in the rear of the chassis. When you remove a fan module, make sure you replace it quickly to avoid overheating the system.
Page 31
Caution For some earlier production Firepower 9300 chassis, you may experience difficulty using the GLC-TE SFP on the management port or fixed ports. Contact Cisco TAC for support if you encounter problems with the GLC-TE SFP. The following table lists the Cisco supported transceivers.
(FPR-NM-2X100G and FPR-NM-4X100G). Hardware Specifications The following table contains hardware specifications for the Firepower 9300. Physical Specifications for the 9300 Chassis Dimensions (H x W x D) 5.25 x 17.5 x 32 in. (13.3 x 44.5 x 81.3 cm) Weight 105 lb (47.7 kg) with 1 security module...
40,000 ft (12,192 m) Acoustic noise 75.5 dBa at maximum fan speed Product ID Numbers The following table lists all of the PIDs associated with the Firepower 9300. Table 9: Firepower 9300 PIDs Description FPR-C9300= Firepower 9300 chassis, no power supply modules...
Page 35
Overview Product ID Numbers Description FPR-C9300-FIPSKIT= Firepower 9300 chassis FIPS kit (spare) FPR9K-SUP Firepower 9000 series Supervisor FPR9K-SUP= Firepower 9000 series Supervisor (spare) FPR9K-SM-24 Firepower 9000 series security module FPR9K-SM-24= Firepower 9000 series security module (spare) FPR9K-SM-24-NEB Firepower 9000 series NEBS security module...
Page 36
Firepower 9000 series DC power supply module (spare) FPR9K-PS-HVDC Firepower 9000 series HVDC power supply module FPR9K-PS-HVDC= Firepower 9000 series HVDC power supply module (spare) FPR9K-FAN Firepower 9000 series fan module FPR9K-FAN= Firepower 9000 series fan module (spare) Cisco Firepower 9300 Hardware Installation Guide...
Only the approved power cords or jumper power cords provided with the security appliance are supported. The following power cords are supported: Figure 17: Argentina CAB-IR2073-C19-AR Plug: IRAM 2073 Cord set rating: 16 A, 250 V Connector: IEC 60320/C19 Cisco Firepower 9300 Hardware Installation Guide...
Page 38
Figure 19: Brazil UCSB-CABL-C19-BRZ Plug: NBR 14136 Cord set rating: 16 A, 250 V Connector: IEC 60320/C19 Figure 20: Cabinet Jumper Power Cord CAB-C19-CBN Plug: IEC 60320/20 Cord set rating: 16 A, 250 V Connector: IEC 60320/C19 Cisco Firepower 9300 Hardware Installation Guide...
Page 39
Figure 22: Europe CAB-AC-2500-EU Plug: CEE 7 VII Cord set rating: 16 A, 250 V Connector: IEC 60320/C19 Figure 23: India CAB-SABS-C19-IND Plug: SABS1641:1992 Cord set rating: 16 A, 250 V Connector: IEC 60320/C19 Cisco Firepower 9300 Hardware Installation Guide...
Page 40
Figure 25: Israel CAB-AC-2500W-ISRL and CAB-S132-C19-ISRL Plug: SI 32 PART 1.01 Cord set rating: 16 A, 250 V Connector: IEC 60320/C19 Figure 26: Italy CAB-C2316-C19-IT Plug: CEI 23-50 Cord set rating: 16 A, 250 V Connector: IEC 60320/C19 Cisco Firepower 9300 Hardware Installation Guide...
Page 41
Figure 28: Korea CAB-9K16A-KOR Plug: KTL SUO4007-1001 Cord set rating: 16 A, 250 V Connector: IEC 60320/C19 Figure 29: Molded CAB-US620P-C19-US Plug: NEMA L6-20P Cord set rating: 16 A, 250 V Connector: IEC 60320/C19 Cisco Firepower 9300 Hardware Installation Guide...
Page 42
Figure 31: Twist Lock CAB-AC-C6K-TWLK Plug: NEMA L6-20P Cord set rating: 16 A, 250 V Connector: IEC 60320/C19 Figure 32: United Kingdom CAB-BS1363-C19-UK Plug: BS1363A Cord set rating: 13 A, 250 V Connector: IEC 60320/C19 Cisco Firepower 9300 Hardware Installation Guide...
SAVE THESE INSTRUCTIONS Warning Statement 12—Power Supply Disconnection Warning Before working on a chassis or working near power supplies, unplug the power cord on AC units; disconnect the power at the circuit breaker on DC units. Cisco Firepower 9300 Hardware Installation Guide...
Page 44
This equipment must be grounded. Never defeat the ground conductor or operate the equipment in the absence of a suitably installed ground conductor. Contact the appropriate electrical inspection authority or an electrician if you are uncertain that suitable grounding is available. Cisco Firepower 9300 Hardware Installation Guide...
Statement 1074—Comply with Local and National Electrical Codes Installation of the equipment must comply with local and national electrical codes. Safety Recommendations Observe these safety guidelines: • Keep the area clear and dust-free before, during, and after installation. Cisco Firepower 9300 Hardware Installation Guide...
• Use the chassis within its marked electrical ratings and product usage instructions. Prevent ESD Damage ESD occurs when electronic components are improperly handled, and it can damage equipment and impair electrical circuitry, resulting in intermittent or complete failure. Cisco Firepower 9300 Hardware Installation Guide...
Regulatory and Compliance Safety Information document for more detailed information about power supply modules in the Firepower 9300. When installing the chassis, consider the following: • Check the power at the site before installing the chassis to ensure that it is “clean” (free of spikes and noise).
• Baffles can help to isolate exhaust air from intake air, which also helps to draw cooling air through the chassis. The best placement of the baffles depends on the airflow patterns in the rack. Experiment with different arrangements to position the baffles effectively. Cisco Firepower 9300 Hardware Installation Guide...
Check for damage and report any discrepancies or damage to your customer service representative. Have the following information ready: • Invoice number of shipper (see the packing slip) • Model and serial number of the damaged unit • Description of damage • Effect of damage on the installation Cisco Firepower 9300 Hardware Installation Guide...
Maintenance and Upgrade, on page You can mount the Firepower 9300 in a 4-post EIA-310-D rack. The static rail adjusts to fit racks with a 24 to 36-in. span between front and rear rails. The 9300 ships with rack accessories.
Page 51
Step 6 Set the rear of the empty Firepower 9300 chassis on the static rails. Step 7 Carefully push the empty chassis into the rack until the chassis ears sit flush to the rack posts.
Page 52
Secure the chassis ears to the rack with the four 10-32-in. screws and retention nuts (if you did not already install them in Step 5) that were provided in the Firepower 9300 accessory kit. Cisco Firepower 9300 Hardware Installation Guide...
Page 53
Install the FIPS opacity shield if necessary. See Install the FIPS Opacity Shield, on page 52 for the procedure. Continue with Connect Cables, Turn on Power, and Verify Connectivity, on page Cisco Firepower 9300 Hardware Installation Guide...
Use a wire-stripping tool to remove approximately 0.75 in. (19 mm) of the covering from the end of the grounding cable. Step 2 Insert the stripped end of the grounding cable into the open end of the grounding lug. Cisco Firepower 9300 Hardware Installation Guide...
Page 55
Make sure that the lug and cable do not interfere with other equipment. Step 7 Prepare the other end of the grounding cable and connect it to an appropriate grounding point in your site to ensure adequate earth ground. Cisco Firepower 9300 Hardware Installation Guide...
Crypto Officer. This procedure describes how to install the FIPS opacity shield on the front of a Firepower 9300 that is already rack-mounted. The FIPS opacity shield has an access cover that is already attached with two captive screws.
Page 57
FIPS opacity shield Rack-mount rails Step 3 Unscrew the two captive screws on the front of the access cover to remove the access cover so that you can connect the cables to the ports. Cisco Firepower 9300 Hardware Installation Guide...
Page 58
Connect Cables, Turn on Power, and Verify Connectivity, on page 56 for the procedure. Step 5 Run the cables through the openings on either side of the FIPS opacity shield and reattach the FIPS access cover by tightening the captive screws. Cisco Firepower 9300 Hardware Installation Guide...
Page 59
When the SYS LED is solid green, the chassis has booted up successfully. Step 9 See the quick start guide for your operating software for further configuration information. • Cisco ASA for Firepower 9300 Quick Start Guide Cisco Firepower 9300 Hardware Installation Guide...
Cisco Firepower Threat Defense for Firepower 9300 Quick Start Guide Connect Cables, Turn on Power, and Verify Connectivity After rack mounting and grounding the Firepower 9300 chassis, follow these steps to connect cables, turn on power, and verify connectivity. Step 1 Console port—Using a serial console cable, connect a computer or terminal server to the RJ-45 serial console port (baud...
Page 61
Step 5 Power—Connect the power cords to the Firepower 9300, and plug the other end into your power source. The chassis has a power switch on the rear. Toggle it to the ON position. The initial AC-power chassis does not have an on/off switch; it powers on when you plug it into a power source.
Page 62
Mount and Connect Connect Cables, Turn on Power, and Verify Connectivity Cisco Firepower 9300 Hardware Installation Guide...
Remove and Replace the Fan Module, on page 74 Remove and Replace the Supervisor You can remove the Firepower 9300 Supervisor while the system is powered on without damage to the Supervisor hardware or system. However, because the supervisor is controlling the entire chassis, including the power system, we recommend that you use the power switch on the rear panel of chassis to put the system in standby mode.
Remove and Replace the Security Module You can remove the Firepower 9300 security module while the system is running, but we recommend that you use the power switch on the rear of the chassis to put the security module in standby mode before removal.
There are two SSDs in each security module. They are configured in a RAID 1 configuration. If one or both SSDs fail, you must decommission the security module and acknowledge the slot to start the SSD installation Cisco Firepower 9300 Hardware Installation Guide...
Page 66
To replace the SSD, hold the SSD in front of slot 1, push it in gently until it is seated, and close the handle. Step 4 Tighten the captive screws on the either side of the SSD. Step 5 Acknowledge the slot to start the SSD installation. Cisco Firepower 9300 Hardware Installation Guide...
The following figure shows the front panel of the 10-G non-fail-to-wire network module. The location of the captive screw, ports, and LEDs is shown. See Network Modules, on page 14 for more information about the other single-wide network modules. Cisco Firepower 9300 Hardware Installation Guide...
Page 68
Chassis Components, on page 4 for more information about the power switch. b) Bring the network module offline using the appropriate CLI command (if removing a network module that supports hot swapping). All network module configuration is saved. Cisco Firepower 9300 Hardware Installation Guide...
Page 69
Gently push on the handle until it is fully seated on the network module faceplate and the module is fully seated in the chassis. Step 6 Tighten the captive screw on the left of the network module. Cisco Firepower 9300 Hardware Installation Guide...
The Firepower 100-G network module is an optional, removable I/O module that provides two fiber 100 Gigabit Ethernet interfaces. It takes up two slots in the Firepower 9300 and supports single and multimode. Although the hardware supports removing and replacing the network module while the system is running, the software does not currently support hot swapping.
Page 71
• Green, flashing—Network activity. Before you begin Your Firepower 9300 security appliance must have firmware package 1.0.10 or later installed before you can use the Firepower 100-G network module. For instructions on how to verify your firmware package version and to upgrade the firmware if necessary, see the "Firmware Upgrade" topic in the Cisco FXOS CLI Configuration Guide, 1.1(4)
Page 72
Hold the 100-G network module in front of the double network module slot on the right side of the chassis with the handle rotated fully out. Slowly push the module into the network module slot until the handle catches on the mating feature in the chassis. The handle should engage correctly. Cisco Firepower 9300 Hardware Installation Guide...
FXOS Configuration Guide to connect to the network module and make sure that it has been discovered correctly by the Firepower 9300. Remove and Replace the Power Supply Module You can remove and replace the power supply module while the system is running. Make sure that at least one of the power supply modules is active while hot-swapping.
Page 74
Tighten the captive screw on the right. Step 8 Verify the power supply module is operating correctly by checking the power supply module LED. See Power Supply Modules, on page 24 for more information. Cisco Firepower 9300 Hardware Installation Guide...
Using the screws, connect the green ground wires to the chassis ground terminal. Only one ground connection is required even though there may be up to 2 DC connections. Step 6 Using the screws, connect the two 2-hole lugs to the power supply module terminal block. Cisco Firepower 9300 Hardware Installation Guide...
Verify power supply operation by checking the power supply LED on the front of the chassis. Power Supply Modules, on page 24 for the LED values. Connect the HVDC Power Supply Module Take note of the following warnings: Cisco Firepower 9300 Hardware Installation Guide...
Page 77
Verify that the power is off to the DC circuit on the power supply module that you are installing. Step 3 Make sure that all site power and grounding requirements have been met. Step 4 Plug the HVDC power cord into the power feeds for PSU-1 and/or PSU-2. Cisco Firepower 9300 Hardware Installation Guide...
Remove and Replace the Fan Module You can remove and replace fan modules while the system is running. The airflow moves from front to back. Fan Modules, on page 26 for more information about the fan module. Cisco Firepower 9300 Hardware Installation Guide...
Page 79
Verify that the fan is operational by checking the fan module LED. It takes about a minute for the Fan LED to be updated. Fan Modules, on page 26 for a description of the fan module LEDs. Cisco Firepower 9300 Hardware Installation Guide...
Page 80
Maintenance and Upgrade Remove and Replace the Fan Module Cisco Firepower 9300 Hardware Installation Guide...