<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sizing PA-Series for internet edge — 3 Gbps today, growing to 8–9 Gbps, with SSL decryption. Which model? in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sizing-pa-series-for-internet-edge-3-gbps-today-growing-to-8-9/m-p/1259360#M7033</link>
    <description>&lt;P class="font-claude-response-body break-words whitespace-normal"&gt;Sizing an edge firewall for a university campus and would appreciate real-world input from people running decryption at scale.&lt;/P&gt;
&lt;P class="font-claude-response-body break-words whitespace-normal"&gt;Requirements:&lt;/P&gt;
&lt;UL class="[li_&amp;amp;]:mb-0 [li_&amp;amp;]:mt-1 [li_&amp;amp;]:gap-1 [&amp;amp;:not(:last-child)_ul]:pb-1 [&amp;amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3" dir="auto"&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Internet edge only — no east-west/inter-VLAN (core switches handle that)&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Current internet traffic: ~3 Gbps, growing to &lt;STRONG&gt;8–9 Gbps&lt;/STRONG&gt; over the appliance's 5–7 year lifecycle&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Security profile: Threat Prevention (IPS/AV/anti-spyware), URL Filtering, DNS Security, WildFire&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;&lt;STRONG&gt;SSL Forward Proxy (deep decryption) on ~80% of traffic&lt;/STRONG&gt; — managed devices get decrypted; BYOD/pinned apps/exempt categories bypass&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;LAN side: 2x 10G LACP to core (MLAG), so interface capacity is not the constraint&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="font-claude-response-body break-words whitespace-normal"&gt;My concern: the datasheets publish Threat Prevention throughput (e.g., PA-3430 = 10.5 Gbps appmix) but &lt;STRONG&gt;no decryption throughput figures&lt;/STRONG&gt;. From what I've read, enabling SSL Forward Proxy cuts effective throughput by roughly 60–70%, which would put a PA-3430 at ~3–4 Gbps of decrypted capacity — i.e., at my day-one load with zero growth room.&lt;/P&gt;
&lt;P class="font-claude-response-body break-words whitespace-normal"&gt;Questions:&lt;/P&gt;
&lt;OL class="[li_&amp;amp;]:mb-0 [li_&amp;amp;]:mt-1 [li_&amp;amp;]:gap-1 [&amp;amp;:not(:last-child)_ul]:pb-1 [&amp;amp;:not(:last-child)_ol]:pb-1 list-decimal flex flex-col gap-1 pl-8 mb-3" dir="auto"&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Is the ~60–70% decryption penalty accurate in practice on the PA-3400 series, or has it improved on recent PAN-OS releases?&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;For 8–9 Gbps total with ~7 Gbps decrypted at peak, what's the honest minimum model — PA-3440? PA-5410? Something else?&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;What decrypt percentages are you actually achieving at a campus/university edge once QUIC, pinned apps, and exemptions are accounted for?&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Any sizing rule of thumb you use for decryption headroom (2x? more?) given datasheet figures are best-case?&lt;/LI&gt;
&lt;/OL&gt;</description>
    <pubDate>Sun, 19 Jul 2026 11:19:22 GMT</pubDate>
    <dc:creator>simsim</dc:creator>
    <dc:date>2026-07-19T11:19:22Z</dc:date>
    <item>
      <title>Sizing PA-Series for internet edge — 3 Gbps today, growing to 8–9 Gbps, with SSL decryption. Which model?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sizing-pa-series-for-internet-edge-3-gbps-today-growing-to-8-9/m-p/1259360#M7033</link>
      <description>&lt;P class="font-claude-response-body break-words whitespace-normal"&gt;Sizing an edge firewall for a university campus and would appreciate real-world input from people running decryption at scale.&lt;/P&gt;
&lt;P class="font-claude-response-body break-words whitespace-normal"&gt;Requirements:&lt;/P&gt;
&lt;UL class="[li_&amp;amp;]:mb-0 [li_&amp;amp;]:mt-1 [li_&amp;amp;]:gap-1 [&amp;amp;:not(:last-child)_ul]:pb-1 [&amp;amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3" dir="auto"&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Internet edge only — no east-west/inter-VLAN (core switches handle that)&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Current internet traffic: ~3 Gbps, growing to &lt;STRONG&gt;8–9 Gbps&lt;/STRONG&gt; over the appliance's 5–7 year lifecycle&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Security profile: Threat Prevention (IPS/AV/anti-spyware), URL Filtering, DNS Security, WildFire&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;&lt;STRONG&gt;SSL Forward Proxy (deep decryption) on ~80% of traffic&lt;/STRONG&gt; — managed devices get decrypted; BYOD/pinned apps/exempt categories bypass&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;LAN side: 2x 10G LACP to core (MLAG), so interface capacity is not the constraint&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="font-claude-response-body break-words whitespace-normal"&gt;My concern: the datasheets publish Threat Prevention throughput (e.g., PA-3430 = 10.5 Gbps appmix) but &lt;STRONG&gt;no decryption throughput figures&lt;/STRONG&gt;. From what I've read, enabling SSL Forward Proxy cuts effective throughput by roughly 60–70%, which would put a PA-3430 at ~3–4 Gbps of decrypted capacity — i.e., at my day-one load with zero growth room.&lt;/P&gt;
&lt;P class="font-claude-response-body break-words whitespace-normal"&gt;Questions:&lt;/P&gt;
&lt;OL class="[li_&amp;amp;]:mb-0 [li_&amp;amp;]:mt-1 [li_&amp;amp;]:gap-1 [&amp;amp;:not(:last-child)_ul]:pb-1 [&amp;amp;:not(:last-child)_ol]:pb-1 list-decimal flex flex-col gap-1 pl-8 mb-3" dir="auto"&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Is the ~60–70% decryption penalty accurate in practice on the PA-3400 series, or has it improved on recent PAN-OS releases?&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;For 8–9 Gbps total with ~7 Gbps decrypted at peak, what's the honest minimum model — PA-3440? PA-5410? Something else?&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;What decrypt percentages are you actually achieving at a campus/university edge once QUIC, pinned apps, and exemptions are accounted for?&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Any sizing rule of thumb you use for decryption headroom (2x? more?) given datasheet figures are best-case?&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Sun, 19 Jul 2026 11:19:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/sizing-pa-series-for-internet-edge-3-gbps-today-growing-to-8-9/m-p/1259360#M7033</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2026-07-19T11:19:22Z</dc:date>
    </item>
  </channel>
</rss>

