Firewall Sizing: Throughput, Connections, and Threat Inspection Overhead
R
RAMOJ Security Team
The Three Numbers That Matter
- Firewall throughput (64-byte packets) — marketing number, ignore
- Firewall throughput (1518-byte packets, real-world) — usable baseline
- NGFW / Threat Prevention throughput — actual number when IPS/AV/TLS inspection are on
Typical Degradation
| Feature | Throughput Impact |
|---|---|
| Stateful firewall only | Baseline |
| + Application Control | -20% |
| + IPS | -40% |
| + AV + URL filtering | -55% |
| + TLS/SSL inspection | -70% |
Rule of Thumb
Size the NGFW/Threat Prevention number (not datasheet throughput) to be 1.5× your peak internet bandwidth. For a 500 Mbps ILL, you need ~750 Mbps threat-inspected throughput → which typically means a firewall rated 2.5 Gbps datasheet.
Concurrent Connections
Often overlooked. A 200-user office with cloud apps, video calls, and IoT easily hits 300,000+ concurrent connections. Check the datasheet 'Concurrent Sessions' figure and give yourself 2× headroom.
Our Sizing Cheatsheet (India SMB)
- Up to 50 users / 200 Mbps WAN — FortiGate 60F / 70F, SonicWall TZ470
- 50–200 users / 500 Mbps — FortiGate 100F/200F, Palo Alto PA-450
- 200–500 users / 1 Gbps — FortiGate 400F, Palo Alto PA-1410, Check Point 6200
- 500+ users / 5+ Gbps — FortiGate 900G, Palo Alto PA-3420, Check Point 7000
Looking for the right hardware?
Browse our full range of enterprise IT hardware with expert pre-sales support.
Need a custom quote?
Our certified engineers respond within 2 business hours.
