DEV Community

Cover image for Firewall Sizing: Why User Count Is a Bad Metric
Sistro Networks
Sistro Networks

Posted on

Firewall Sizing: Why User Count Is a Bad Metric

“How many users does this firewall support?”

It sounds like a reasonable sizing question.

Unfortunately, it tells us very little about the actual workload.

Consider two companies with 100 users.

Company A:

SaaS applications
light browsing
one office
limited VPN

Company B:

multiple branches
site-to-site VPNs
SSL inspection
public servers
VoIP
cameras
hundreds of connected devices

Same number of employees.

Completely different firewall workload.

Better sizing inputs include:

inspected throughput
concurrent sessions
new connections per second
VPN traffic
security services enabled
WAN bandwidth
branch topology
growth
availability requirements

This is also why moving between firewall product families should be based on architecture, not a simple user-count table.

I used SonicWall TZ vs NSa as a practical example here:

https://sistro.net/sonicwall-tz-vs-nsa-que-firewall-elegir

Top comments (0)