<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sizing help — university internet edge, 3 Gbps today, 4,000–5,000 students, 7-year lifespan. PA-3430 / PA-3440 / PA-5410? in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sizing-help-university-internet-edge-3-gbps-today-4-000-5-000/m-p/1259363#M7032</link>
    <description>&lt;P class="font-claude-response-body break-words whitespace-normal"&gt;Looking for sizing advice from anyone running PAN at a university/campus internet edge.&lt;/P&gt;
&lt;P class="font-claude-response-body break-words whitespace-normal"&gt;&lt;STRONG&gt;Environment:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL class="[li_&amp;amp;]:mb-0 [li_&amp;amp;]:mt-1 [li_&amp;amp;]:gap-1 [&amp;amp;:not(:last-child)_ul]:pb-1 [&amp;amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3" dir="auto"&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;University with 4,000–5,000 students plus staff/faculty&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Current internet bandwidth: 3 Gbps — expect this to grow substantially over the appliance's life (bandwidth per student keeps climbing; wouldn't be surprised to hit 8–10 Gbps by end of life)&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Firewall lifespan target: &lt;STRONG&gt;7 years&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Role: internet edge only — no east-west (core switches handle inter-VLAN)&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Planned security stack: Threat Prevention, Advanced URL Filtering, DNS Security, WildFire&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;&lt;STRONG&gt;SSL Forward Proxy on managed devices&lt;/STRONG&gt; (~70–80% of traffic decrypted; BYOD/student devices get certificate inspection or bypass)&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;DMZ with published services (web, LMS)&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;LAN side: 2x 10G LACP to core, so ports aren't the issue&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="font-claude-response-body break-words whitespace-normal"&gt;&lt;STRONG&gt;Where I'm stuck:&lt;/STRONG&gt; datasheets show Threat Prevention throughput (PA-3430 = 10.5, PA-3440 = 12.8, PA-5410 = 35 Gbps appmix) but no decryption figures. I've read decryption cuts effective throughput 60–70%, which would make the 3400 series marginal by mid-life if traffic grows as expected.&lt;/P&gt;
&lt;P class="font-claude-response-body break-words whitespace-normal"&gt;&lt;STRONG&gt;Questions:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL class="[li_&amp;amp;]:mb-0 [li_&amp;amp;]:mt-1 [li_&amp;amp;]:gap-1 [&amp;amp;:not(:last-child)_ul]:pb-1 [&amp;amp;:not(:last-child)_ol]:pb-1 list-decimal flex flex-col gap-1 pl-8 mb-3" dir="auto"&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;For this profile over 7 years, what would you deploy — PA-3440 or PA-5410? Is the 3430 out of the question?&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;What's the realistic decrypted throughput people see on the 3440 vs the 5410 (with its hardware SSL acceleration)?&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;For those at universities: what decryption percentage do you actually achieve with a large BYOD population, once QUIC and pinned apps are accounted for?&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Any experience with how appmix numbers translate to real campus traffic (heavy streaming/CDN, thousands of concurrent users)?&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Sessions: with 5,000+ concurrent users, is the 3440's 3M session cap comfortable, or have campuses hit session/CPS limits before throughput limits?&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="font-claude-response-body break-words whitespace-normal"&gt;Evaluating against FortiGate 701G and Check Point 9700/9800 quotes, so trying to identify PAN's genuinely right-sized model rather than the cheapest one that passes on paper.&lt;/P&gt;</description>
    <pubDate>Mon, 20 Jul 2026 05:02:19 GMT</pubDate>
    <dc:creator>simsim</dc:creator>
    <dc:date>2026-07-20T05:02:19Z</dc:date>
    <item>
      <title>Sizing help — university internet edge, 3 Gbps today, 4,000–5,000 students, 7-year lifespan. PA-3430 / PA-3440 / PA-5410?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sizing-help-university-internet-edge-3-gbps-today-4-000-5-000/m-p/1259363#M7032</link>
      <description>&lt;P class="font-claude-response-body break-words whitespace-normal"&gt;Looking for sizing advice from anyone running PAN at a university/campus internet edge.&lt;/P&gt;
&lt;P class="font-claude-response-body break-words whitespace-normal"&gt;&lt;STRONG&gt;Environment:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL class="[li_&amp;amp;]:mb-0 [li_&amp;amp;]:mt-1 [li_&amp;amp;]:gap-1 [&amp;amp;:not(:last-child)_ul]:pb-1 [&amp;amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3" dir="auto"&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;University with 4,000–5,000 students plus staff/faculty&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Current internet bandwidth: 3 Gbps — expect this to grow substantially over the appliance's life (bandwidth per student keeps climbing; wouldn't be surprised to hit 8–10 Gbps by end of life)&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Firewall lifespan target: &lt;STRONG&gt;7 years&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Role: internet edge only — no east-west (core switches handle inter-VLAN)&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Planned security stack: Threat Prevention, Advanced URL Filtering, DNS Security, WildFire&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;&lt;STRONG&gt;SSL Forward Proxy on managed devices&lt;/STRONG&gt; (~70–80% of traffic decrypted; BYOD/student devices get certificate inspection or bypass)&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;DMZ with published services (web, LMS)&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;LAN side: 2x 10G LACP to core, so ports aren't the issue&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="font-claude-response-body break-words whitespace-normal"&gt;&lt;STRONG&gt;Where I'm stuck:&lt;/STRONG&gt; datasheets show Threat Prevention throughput (PA-3430 = 10.5, PA-3440 = 12.8, PA-5410 = 35 Gbps appmix) but no decryption figures. I've read decryption cuts effective throughput 60–70%, which would make the 3400 series marginal by mid-life if traffic grows as expected.&lt;/P&gt;
&lt;P class="font-claude-response-body break-words whitespace-normal"&gt;&lt;STRONG&gt;Questions:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL class="[li_&amp;amp;]:mb-0 [li_&amp;amp;]:mt-1 [li_&amp;amp;]:gap-1 [&amp;amp;:not(:last-child)_ul]:pb-1 [&amp;amp;:not(:last-child)_ol]:pb-1 list-decimal flex flex-col gap-1 pl-8 mb-3" dir="auto"&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;For this profile over 7 years, what would you deploy — PA-3440 or PA-5410? Is the 3430 out of the question?&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;What's the realistic decrypted throughput people see on the 3440 vs the 5410 (with its hardware SSL acceleration)?&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;For those at universities: what decryption percentage do you actually achieve with a large BYOD population, once QUIC and pinned apps are accounted for?&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Any experience with how appmix numbers translate to real campus traffic (heavy streaming/CDN, thousands of concurrent users)?&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Sessions: with 5,000+ concurrent users, is the 3440's 3M session cap comfortable, or have campuses hit session/CPS limits before throughput limits?&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="font-claude-response-body break-words whitespace-normal"&gt;Evaluating against FortiGate 701G and Check Point 9700/9800 quotes, so trying to identify PAN's genuinely right-sized model rather than the cheapest one that passes on paper.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2026 05:02:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/sizing-help-university-internet-edge-3-gbps-today-4-000-5-000/m-p/1259363#M7032</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2026-07-20T05:02:19Z</dc:date>
    </item>
  </channel>
</rss>

