DEV Community

Cover image for A 39 Gbps Firewall May Not Be a 39 Gbps Security Appliance
Sistro Networks
Sistro Networks

Posted on

A 39 Gbps Firewall May Not Be a 39 Gbps Security Appliance

Firewall throughput numbers can be misleading when used without context.

A next-generation firewall may perform multiple operations on every flow:

Firewall
→ IPS
→ Application Control
→ Malware Inspection
→ Logging
→ TLS Inspection

Each layer adds work.

Fortinet's current product matrix gives a useful example.

The FortiGate 120G is rated at up to 39 Gbps raw firewall throughput.

Its published NGFW throughput is 3.1 Gbps.

Threat Protection is 2.8 Gbps.

SSL Inspection is 3 Gbps.

Nothing is wrong with the appliance.

The tests simply represent different workloads.

This leads to a useful rule:

Never size security infrastructure using the largest number on the datasheet.

Instead ask:

Which security profiles will be enabled?
How much encrypted traffic exists?
How much VPN traffic?
What WAN speed?
How many concurrent sessions?
How much growth?

The same principle applies regardless of vendor.

I used FortiGate 70G, 90G and 120G as a practical comparison:

https://sistro.net/fortigate-70g-vs-90g-vs-120g

Tags: networking cybersecurity security infrastructure

Top comments (0)