DEV Community

Cover image for Two Firewalls Can Have the Same Throughput and Still Be Very Different
Sistro Networks
Sistro Networks

Posted on

Two Firewalls Can Have the Same Throughput and Still Be Very Different

Firewall sizing often starts with one metric:

Throughput

But consider two appliances with the same 1 Gbps firewall rating.

Appliance A:

50,000 concurrent sessions
75 site-to-site VPN tunnels
200 recommended devices

Appliance B:

125,000 concurrent sessions
200 site-to-site VPN tunnels
250 recommended devices

Same firewall throughput.

Different scale.

This is exactly what makes the Cisco Meraki MX75 vs MX85 comparison interesting.

It demonstrates that firewall sizing should consider:

flows
VPN tunnels
device population
security services
interface requirements
growth
topology

There is another complication.

Advanced security features change effective throughput.

Cisco currently rates both MX75 and MX85 at lower NGFW throughput when prevention features are enabled than their raw firewall figure.

So the useful engineering question is not:

“How fast is the firewall?”

It is:

“How does it perform with my actual traffic and feature set?”

Practical comparison:

https://sistro.net/cisco-meraki-mx75-vs-mx85

Tags: networking cybersecurity sdwan infrastructure

Top comments (0)