Sizing Advanced Firewalls for Enterprise Inspection
Learn how to accurately size enterprise firewalls by focusing on threat prevention throughput instead of raw speed when deploying SSL/TLS decryption.
Why this matters
2-3 concrete sentences on what goes wrong without this knowledge. When an enterprise network is undersized for security inspection, the firewall becomes a catastrophic bottleneck that forces administrators to disable security features just to maintain internet connectivity. This decision leaves the entire organization exposed to malware and data exfiltration, effectively nullifying the investment in advanced perimeter security.
The core idea
the concept in plain language, defining each term precisely the first time it is used. Advanced firewalls are not simple traffic routers; they are high-performance security appliances that perform deep packet inspection, which is the process of examining the data portion of a packet to identify malicious content. In modern environments, most traffic is encrypted via SSL/TLS, which stands for Secure Sockets Layer and Transport Layer Security. To inspect this traffic, a firewall must perform SSL/TLS decryption, a resource-intensive operation where the firewall intercepts, decrypts, scans, and re-encrypts packets.
Because decryption requires significant computational power, looking at raw total throughput—the theoretical maximum speed of unencrypted data passing through the device—is useless. Instead, you must focus on threat prevention throughput, which measures the device’s performance when all security features, including antivirus, intrusion prevention, and deep packet inspection, are active at the same time.
How it works in practice
the specific steps, numbers, tools and rules that apply in this business; name real products, carriers, documents or processes where relevant. When designing a network for a client using platforms like Fortinet FortiGate, Palo Alto Networks, or Cisco Firepower, you must ignore the headline Mbps numbers found on the box or the front of a datasheet. These marketing numbers represent a best-case scenario with no security features running. The real-world performance is found in the device's specific technical specification sheet under the section labeled Threat Protection or Threat Prevention Throughput.
First, calculate the total expected internet bandwidth utilization of the client. If they have a 1 Gbps fiber connection, your firewall must be able to handle at least 1 Gbps of threat prevention throughput, not just raw switching capacity. If you cannot find a device that matches their bandwidth with all features enabled, you must recommend a higher-tier chassis or a load-balanced cluster of two firewalls. Always review the vendor-specific sizing guide for the exact firmware version being deployed, as performance metrics can change significantly with security feature updates or hardware acceleration chipsets like the Fortinet SPU.
Worked example
one realistic scenario (a customer call, an order, a troubleshooting case) walked through step by step, showing the wrong handling and then the right handling. Imagine a customer, Acme Logistics, wants to upgrade their firewall. They have a 1 Gbps dedicated internet circuit and want full decryption enabled for their 500 employees. The wrong handling occurs when you look at the datasheet for an entry-level firewall that claims a 2 Gbps firewall throughput and recommend it. The customer installs it, turns on SSL inspection, and immediately sees their internet speed crawl to 150 Mbps.
Users report timed-out connections and internal applications crashing because the firewall CPU is pegged at 100 percent. The right handling begins by asking the customer for their active feature set requirements. You identify they need SSL inspection, application control, and IPS. You then locate the vendor datasheet and scan specifically for the Threat Prevention Throughput line item. You find a model that lists 1.2 Gbps for this specific metric.
You present this model to the customer, explaining that it is sized to handle their encrypted traffic without throttling, ensuring their security policies remain active without impacting productivity. The customer agrees, and the deployment succeeds because the hardware capacity aligns with their actual operational requirements.
Where people go wrong
the three or four most common mistakes, including the specific one from the question above, and how to avoid each. The most common mistake is focusing on total throughput in Mbps, which is essentially the speed of the device as a transparent bridge with no security features engaged. This leads to massive performance degradation once policies are applied. Another mistake is ignoring the impact of SSL/TLS protocol versions. Modern inspection requires handling TLS 1.3, which is more computationally expensive than older versions; if you do not account for this in your sizing, your security appliance will become a bottleneck.
Finally, many professionals fail to account for the headroom required for traffic spikes. Always size for the peak traffic load plus a twenty-five percent buffer to ensure the CPU can handle encrypted handshakes during high-activity periods without dropping connections.
Key takeaways
4 to 6 short bullets the employee can apply on their next call. Always prioritize threat prevention throughput over raw throughput numbers. Verify that the performance specifications account for all enabled security features, especially SSL/TLS decryption. Check vendor-specific hardware acceleration capabilities to ensure the firewall is optimized for modern encryption protocols. Leave at least twenty-five percent overhead in your sizing to accommodate unexpected traffic spikes and future network growth. When in doubt, consult the manufacturer's official sizing calculator or pre-sales engineering team for the specific hardware model.
