Call a Specialist Today! 888-785-4402

Cisco IronPort S695 Web Security Appliance

Cisco has acquired Ironport. Please visit our Cisco site for the latest re-branded Ironport products.

IronPort S695 Web Security Appliance

Cisco IronPort S695 Web Security Appliance is now Cisco Web Security Appliance S695, please go here for purchasing. Need help? Contact us.

IronPort Products
Cisco Web Security Appliance S695
Cisco S695 Web Security Appliance
Get a Quote!

Additional Pricing and Options available below, click here!


For security, your network needs malware protection, application visibility and control, acceptable use policy controls, insightful reporting and secure mobility. Cisco offers this protection, all on a single platform: the Cisco® Web Security Appliance (WSA)

In our highly connected and increasingly mobile world, more complex and sophisticated threats require the right mix of security solutions. Cisco delivers security for all layers of network infrastructure with the strong protection, complete control, and investment value businesses need. We also offer a broad set of web security deployment options, along with market-leading global threat intelligence. The Cisco WSA simplifies security with a high performance, dedicated appliance, and the Cisco Web Security Virtual Appliance (WSAV) lets businesses deploy web security quickly and easily, wherever and whenever it’s needed.

The Cisco WSA was one of the first secure web gateways to combine leading protections to help organizations address the growing challenges of securing and controlling web traffic. It enables simpler, faster deployment with fewer maintenance requirements, reduced latency, and lower operating costs. ”Set and forget” technology frees staff after initial automated policy settings go live, and automatic security updates are pushed to network devices every 3 to 5 minutes. Flexible deployment options and integration with your existing security infrastructure help you meet quickly evolving security requirements.

Features and Benefits:

Talos Security Intelligence

Receive fast and comprehensive web protection backed by the largest threat detection network in the world, with the broadest visibility and largest footprint, including:

  • 100 TB of security intelligence daily
  • 1.6 million deployed security devices, including firewall, IPS, web, and email appliances
  • 150 million endpoints
  • 13 billion web requests per day
  • 35% of the world’s enterprise email traffic

Providing a 24x7 view into global traffic activity to analyze anomalies, uncover new threats, and monitor traffic trends. Talos prevents zero-hour attacks by continually generating new rules that feed updates to the WSA every three to five minutes, enabling industry-leading threat defense hours and even days ahead of competitors.

Cisco Web Usage Controls

Combine traditional URL filtering with dynamic content analysis to mitigate compliance, liability, and productivity risks. Cisco’s continuously updated URL filtering database of over 50 million blocked sites provides exceptional coverage for known websites, and the Dynamic Content Analysis (DCA) engine accurately identifies 90 percent of unknown URLs in real time; it scans text, scores the text for relevancy, calculates model document proximity, and returns the closest category match. Administrators can also select specific categories for intelligent HTTPS inspection.

Advanced Malware Protection

Advanced Malware Protection (AMP) is an additionally licensed feature available to all Cisco WSA customers. AMP is a comprehensive malware-defeating solution that enables malware detection and blocking, continuous analysis, and retrospective alerting. It takes advantage of the vast cloud security intelligence networks of both Cisco and Sourcefire® technology. AMP augments the malware detection and blocking capabilities already offered in the Cisco WSA with enhanced file reputation capabilities, detailed file-behavior reporting, continuous file analysis, and retrospective verdict alerting. The Cisco AMP Threat Grid delivers malware protection through an on-premises appliance for organizations that have compliance or policy restrictions on submitting malware samples to the cloud. The Layer 4 Traffic Monitor continuously scans activity, detecting and blocking spyware ”phone-home” communications. By tracking all network applications, the Layer 4 Traffic Monitor effectively stops malware that attempts to bypass classic web security solutions. It dynamically adds IP addresses of known malware domains to its list of malicious entities to block.

Cognitive Threat Analytics

Cisco Cognitive Threat Analytics is a cloud-based solution that reduces time to discovery of threats operating inside the network. It addresses gaps in perimeter-based defenses by identifying the symptoms of a malware infection or data breach using behavioral analysis and anomaly detection. Take advantage of Cisco Cognitive Threat Analytics with a simple add-on license to your Web Security solution. Reduce complexity while gaining superior protection that evolves with your changing threat landscape.

Application Visibility and Control (AVC)

Easily control the use of hundreds of Web 2.0 applications and 150,000+ micro-applications. Granular policy control allows administrators to permit the use of applications such as Dropbox or Facebook while blocking users from activities such as uploading documents or clicking the ”Like” button. The WSA supports visibility of activity across an entire network. New: Customers can deploy customized bandwidth and time quotas per user, per group, and per policy.

Data Loss Prevention (DLP)

Prevent confidential data from leaving the network by creating context-based rules for basic DLP. The Cisco WSA also uses Internet Content Adaptation Protocol (ICAP) to integrate with third-party DLP solutions for deep content inspection and enforcement of DLP policies. The Cisco WSA also supports Secure ICAP to encrypt the traffic exchanged between WSA and third-party DLP solutions.

Roaming-User Protection

The Cisco WSA protects roaming users by integrating with the Cisco AnyConnect® Secure Mobility Client, which provides web security to remote clients by initiating a VPN tunnel that redirects traffic back to the on-premises solution. Cisco AnyConnect technology analyzes traffic in real time prior to permitting access.

The Cisco WSA is also integrated with Cisco Identity Services Engine (ISE). With this exciting enhancement, customers can now take advantage of the power of Cisco ISE for Cisco WSA upon request. Cisco ISE integration allows admins to create policy on the Cisco WSA based on profile or membership information gathered by Cisco ISE through its single sign-on process.

Centralized Management and Reporting

Receive actionable insights across threats, data, and applications. The Cisco WSA provides an easy-to-use, centralized management tool to control operations, manage policies, and view reports.

The Cisco M-Series Content Security Management Appliance provides central management and reporting across multiple appliances and multiple locations, including virtual instances.

Cisco® Web Security Reporting Application is a reporting solution that rapidly indexes and analyzes logs produced by Cisco Web Security Appliances (WSA) and Cisco Umbrella. This tool provides scalable reporting for customers with high traffic and storage needs. It allows reporting administrators to gather detailed insight into web usage and malware threats.

Flexible Deployment

WSA can be an effective protection against web-based threats for your workloads running in the cloud. Alternatively, if your organization uses on-premises WSA for web security, as a good security practice you can deploy a similar security stack for your cloud-based applications using WSAV on AWS. Furthermore, using Security Management Appliance virtual (SMAV) on AWS, you can configure and monitor a large number of WSA farms in your cloud environment itself.

The Cisco WSAV offers all the same features as the Cisco WSA, with the added convenience and cost savings of a virtual deployment model, including instant self-service provisioning. With a Cisco WSAV license, businesses can deploy web security virtual gateways without being connected to the Internet, by applying the license to a new Cisco WSAV virtual image file stored locally. Pristine virtual image files can be cloned, if needed, to deploy several web security gateways immediately.

Run hardware and virtual machines in the same deployment. Small branch offices or remote locations can have the same protection the Cisco WSA provides without having to install and support hardware at that location. Custom deployment is easily managed with the Cisco M-Series Content Security Management Appliance.


WSA S695- Large Office

Disk Space 9.6 TB (16x600 GB SAS)
RAID Mirroring Yes (RAID 10)
Memory 64 GB, DDR4
CPUs 2 x 2.6 Ghz, 12C
Rack units (RU) 2RU
Dimensions including handles (H x W x D) 3.5 in. x 17 in. x 30.5 in.
Redundant P/S Yes
Remote power cycling Yes
DC Power Option No
Hot-swappable hard disk Yes
Power Consumption 2216.5 BTU/hr
Power Supply 1050W
Ethernet interfaces 6 port 1G Base-T copper network interface (NICs), RJ - 45
Speed (Mbps) 10/100/1000, auto negotiate
Fiber option Yes, separate SKU, 6-port 1GBASE-SX Fiber or 10GBASE-SR Fiber selectable upon ordering (modules included): WSA-S695F
HD Size Sixteen 600 GB hard disk drives (2.5” 12G SAS 10K RPM) are installed into front-panel drive bays that provide hot-swappable access for SAS drives
CPU Two 2.6GHz 12c 2666MHz processor
RAM Four 16GB DDR4-2666 DIMM1


The Cisco WSA is a forward proxy that can be deployed in either Explicit mode (Proxy Automatic Configuration [PAC] files, Web Proxy Auto-Discovery [WPAD], browser settings) or Transparent mode (Web Cache Communication Protocol [WCCP], Policy-Based Routing [PBR], load balancers). WCCP-compatible devices, such as Cisco Catalyst® 6000 Series Switches, Cisco ASR 1000 Series Aggregation Services Routers, Cisco Integrated Services Routers, and Cisco ASA 5500-X Series Next-Generation Firewalls, reroute web traffic to the Cisco WSA.

The Cisco WSA can proxy HTTP, HTTPS, SOCKS, native FTP, and FTP over HTTP traffic to deliver additional capabilities such as data-loss prevention, mobile user security, and advanced visibility and control.


A Cisco WSAV license is included in all Cisco Web Security software bundles (Cisco Web Security Essentials, Cisco Web Security Antimalware, and Cisco Web Security Premium). This license has the same term as the other software services in the bundle and can be used for as many virtual machines as needed.

Term-Based Subscription Licenses
Licenses are term-based subscriptions of one, three, or five years.

Quantity-Based Subscription Licenses
The Cisco Web Security portfolio uses tiered pricing based on a range of users, not devices. Sales and partner representatives can help to determine the correct sizing for each customer deployment.

The major components of each software offering are:

Web Security Software Licenses
Four web security software licenses are available: Cisco Web Security Essentials, Cisco Anti-Malware, Cisco Web Security Premium, and McAfee Anti-Malware. The major components of each software offering follow:

Cisco Web Security Essentials

  • Threat Intelligence via Cisco Talos
  • Layer 4 traffic monitoring
  • Application Visibility and Control (AVC)
  • Policy management
  • Actionable reporting
  • URL filtering
  • Third-party DLP integration via ICAP

Cisco Anti-Malware

  • Real-time malware scanning

Cisco Web Security Premium

  • Web Security Essentials
  • Real-time malware scanning

Cisco Web Security Shield

  • Web Security Premium
  • Advanced malware protection
  • Cognitive threat analytics
  • Threat Grid file analysis

Advanced Malware Protection

  • AMP augments anti-malware detection and blocking capabilities with file reputation scoring and blocking, static and dynamic file analysis (sandboxing), and file retrospection for continuous analysis of threats.

Cognitive Threat Analytics

  • CTA relies on advanced statistical modeling and machine learning to independently identify new threats, learn from what it sees, and adapt over time.

McAfee Anti-Malware

  • McAfee real-time malware scanning is available as a single, a-la-carte license.

Software License Agreements
The Cisco End-User License Agreement (EULA) and the Cisco Web Security Supplemental End-User License Agreement (SEULA) are provided with each software license purchase.

Software Subscription Support
All Cisco Web Security licenses include software subscription support essential to keeping business-critical applications available, secure, and operating at peak performance. This support entitles customers to the following services for the full term of the purchased software subscription:

  • Software updates and major upgrades to keep applications performing optimally at the most current feature set
  • Access to Cisco Technical Assistance Center (TAC) for fast, specialized support
  • Online tools to build and expand in-house expertise and boost business agility
  • Collaborative learning for additional knowledge and training opportunities


Download the Cisco Web Security Appliance Data Sheet (PDF).

Pricing Notes:

IronPort Products
Cisco Web Security Appliance S695
Cisco S695 Web Security Appliance
Get a Quote!
WSA S695 Fiber Web Security Appliances
Get a Quote!
Cisco SMARTnet Support
Smart Net Total Care Service For Web Security Appliances Service - 8 x 5 Next Business Day - Exchange - Physical and Electronic Service
Get a Quote!
Solution Support 24 X 7 4Hour For S695 Fiber Web Security Appliances US Only
Get a Quote!
Smart Net Total Care 3 Year Service For Web Security Appliances Service - 8 x 5 Next Business Day - Exchange - Physical and Electronic Service
Get a Quote!