Skip to main contentSkip to main content
RAMOJ

Firewall Sizing: Throughput, Connections, and Threat Inspection Overhead

R
RAMOJ Security Team
·2 March 2026·1 min read
Firewall Sizing: Throughput, Connections, and Threat Inspection Overhead

The Three Numbers That Matter

  1. Firewall throughput (64-byte packets) — marketing number, ignore
  2. Firewall throughput (1518-byte packets, real-world) — usable baseline
  3. NGFW / Threat Prevention throughput — actual number when IPS/AV/TLS inspection are on

Typical Degradation

FeatureThroughput Impact
Stateful firewall onlyBaseline
+ Application Control-20%
+ IPS-40%
+ AV + URL filtering-55%
+ TLS/SSL inspection-70%

Rule of Thumb

Size the NGFW/Threat Prevention number (not datasheet throughput) to be 1.5× your peak internet bandwidth. For a 500 Mbps ILL, you need ~750 Mbps threat-inspected throughput → which typically means a firewall rated 2.5 Gbps datasheet.

Concurrent Connections

Often overlooked. A 200-user office with cloud apps, video calls, and IoT easily hits 300,000+ concurrent connections. Check the datasheet 'Concurrent Sessions' figure and give yourself 2× headroom.

Our Sizing Cheatsheet (India SMB)

  • Up to 50 users / 200 Mbps WAN — FortiGate 60F / 70F, SonicWall TZ470
  • 50–200 users / 500 Mbps — FortiGate 100F/200F, Palo Alto PA-450
  • 200–500 users / 1 Gbps — FortiGate 400F, Palo Alto PA-1410, Check Point 6200
  • 500+ users / 5+ Gbps — FortiGate 900G, Palo Alto PA-3420, Check Point 7000

Looking for the right hardware?

Browse our full range of enterprise IT hardware with expert pre-sales support.

Browse Products →

Need a custom quote?

Our certified engineers respond within 2 business hours.

Request Quote
Firewall Sizing for Indian SMBs — Throughput & Connections | RAMOJ IT Hardware