Sizing a Firewall for Your Network
Firewalls are sized against the wrong number more often than any other network device. The figure on the front of the datasheet is raw throughput with everything switched off. The figure you will actually experience is several times lower, and it is printed further down the same page.
Size against these, in order
- Threat protection throughput — with IPS and antivirus enabled. This is your real number.
- TLS inspection throughput, if you will decrypt. Lower again.
- Your internet link speed, plus any internal traffic crossing the firewall.
- Headroom for growth, a faster link later, and features you have not enabled yet.
The throughput figures, and what each means
| Figure | What it measures |
|---|---|
| Firewall throughput | Stateful filtering only, usually with large packets under ideal conditions. The headline number, and the least representative. |
| IPS throughput | With intrusion prevention active. Substantially lower. |
| Threat protection throughput | IPS plus antivirus and application control together. Closest to a realistic business configuration, and the number to size against. |
| TLS/SSL inspection throughput | With decryption enabled. Typically the lowest figure published, and the one that surprises people most. |
| IPsec VPN throughput | Encrypted tunnel capacity. Matters for site-to-site links and remote access. |
| Concurrent sessions | How many connections it can track. Rarely a limit for small offices; occasionally a limit where many devices make many short connections. |
| New sessions per second | How fast it can establish connections. Matters more than raw throughput in some workloads. |
If you buy a firewall whose raw throughput comfortably exceeds your internet link, then enable IPS, antivirus, and TLS inspection, you can easily end up with a firewall slower than your connection — and the symptom is that "the internet got slow" right after the security features were switched on. Look up the threat protection figure before ordering, and size against that.
Working out what you need
- Start with your internet link speed Including any planned upgrade. Firewalls last several years and links get faster; sizing to today's connection means resizing when it changes.
- Add internal traffic that crosses the firewall If VLANs are routed through it — guest to internet, or segmented networks talking to each other — that traffic counts too. In segmented networks this can exceed internet traffic.
- Decide which inspection features you will enable Be realistic. Features bought and never enabled protect nothing; features enabled on an undersized box cause complaints.
- Add VPN load Site-to-site tunnels and remote workers. Encrypted throughput is separately rated for a reason.
- Add headroom Traffic grows, links get upgraded, and you may enable TLS inspection later. Sizing to exactly today's peak means being at the limit within the device's life.
- Check session counts if you have many devices Guest Wi-Fi in a busy retail or hospitality setting can generate far more concurrent sessions than the user count suggests.
These devices rarely die. They get replaced because the internet link was upgraded, or because enabling a security feature made them the bottleneck. Buying one class above what today's numbers require frequently costs less than replacing it two years early — and it means you can turn features on without a conversation about performance.
What else to specify
| Consideration | Guidance |
|---|---|
| Port count and speed | Enough for your WAN links, LAN, DMZ, and any separately routed segments. Check whether higher-speed ports are copper or need optics. |
| Multiple WAN links | If you have or plan a second internet connection for resilience, the firewall must support it — and SD-WAN features make it genuinely useful rather than just a failover. |
| Wireless built in | Some small units include Wi-Fi. Convenient for a very small office; separate access points are better anywhere with real coverage requirements. |
| PoE ports | A few models offer them, which can avoid a small switch in a compact deployment. |
| High availability | A second unit in failover pair. Worth it where an internet outage stops the business; check whether the licensing model requires a full second subscription. |
| Central management | For multiple sites, managing policy centrally is the difference between consistent configuration and eight firewalls that have drifted apart. |
| Subscription bundle and term | Budget the recurring cost properly — see what a next-generation firewall does. |
A worked example
A 45-person professional services office with a 500 Mbps internet connection, a site-to-site VPN to a second office, and about a dozen remote workers.
- Internet link: 500 Mbps, with a plan to move to 1 Gbps within the device's life
- Segmented guest, voice, and staff VLANs routed through the firewall: additional internal traffic
- Intended features: application control, IPS, antivirus, web and DNS filtering — with TLS inspection likely later
- VPN: one site-to-site tunnel plus a dozen remote users
- Size against threat protection throughput comfortably above 1 Gbps, not against the 500 Mbps link
Sizing to the current 500 Mbps link on raw throughput would produce a device that becomes the bottleneck the moment the link is upgraded or TLS inspection is enabled — which is exactly when nobody wants to be buying a firewall.
Everything crossing your network boundary goes through it. If the business stops when the internet stops, consider a high-availability pair, and at minimum keep a known-good configuration backup and understand your replacement path. A spare configuration file is worth very little until the day it is worth everything.
A shortlist that avoids the usual regrets
- Find the threat protection throughput figure and size against it.
- Include planned internet link upgrades, not just today's speed.
- Count internal traffic that crosses the firewall between segments.
- Check VPN throughput separately if you run tunnels.
- Budget the subscription as a recurring cost with a renewal reminder.
- Buy one class up if the numbers are close.
- Decide on high availability based on what an outage costs you.
Official manufacturer resources
Throughput figures are measured under specific test conditions that vary by vendor. Compare like with like, and confirm against the datasheet for the exact model.
Send us your link speed and user count
Plus which security features you intend to enable. We will size against the throughput figure that actually applies and tell you honestly whether the model you were considering will keep up.
Still stuck? Talk to someone who works on this hardware daily.
Tell us the model, what you have already tried, and what you are seeing. We will tell you whether it is a setting, a consumable, or a part — and we will say so if you do not need to buy anything.