<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA-NGFW Sizing in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-ngfw-sizing/m-p/1240533#M125404</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;In simple terms I first look at the throughput of Gbps. Then I choose the device that meets the minimum.&lt;/P&gt;
&lt;P&gt;Example: I need to push through 10Gbps. I would look at which device has that as its slowest and start there and then maybe go higher.&lt;/P&gt;
&lt;P&gt;So in this case I would start with the 3430.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_0-1761161621000.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/69666iA945E06E8B714552/image-size/medium?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_0-1761161621000.png" alt="OtakarKlier_0-1761161621000.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Depending on other aspects etc, might go to a higher model, i.e. the 5410.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Wed, 22 Oct 2025 19:34:53 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2025-10-22T19:34:53Z</dc:date>
    <item>
      <title>PA-NGFW Sizing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-ngfw-sizing/m-p/1239651#M125293</link>
      <description>&lt;P data-start="0" data-end="8"&gt;Hello,&lt;/P&gt;
&lt;P data-start="10" data-end="258" data-is-last-node="" data-is-only-node=""&gt;I’m new to firewall sizing and would appreciate some expert guidance. Could someone help me understand the process to follow, the key questions to ask, and the important factors to consider when sizing a data center or edge firewall?&lt;/P&gt;
&lt;P data-start="10" data-end="258" data-is-last-node="" data-is-only-node=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="10" data-end="258" data-is-last-node="" data-is-only-node=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="10" data-end="258" data-is-last-node="" data-is-only-node=""&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Oct 2025 07:28:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-ngfw-sizing/m-p/1239651#M125293</guid>
      <dc:creator>JeanPaul222</dc:creator>
      <dc:date>2025-10-08T07:28:11Z</dc:date>
    </item>
    <item>
      <title>Re: PA-NGFW Sizing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-ngfw-sizing/m-p/1239667#M125296</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1035429259"&gt;@JeanPaul222&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sizing a firewall is a critical process that begins with a fundamental understanding of your network's behavior. It's a critical process that ensures your security device becomes a force multiplier, not a bottleneck.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First you need to gather data and ask the right questions. What's the current and projected throughput, not just for the raw firewall but with all security bells and whistles enabled? &lt;SPAN class="citation-18 citation-end-18"&gt;This distinction is vital, as features like Threat Prevention, URL Filtering, and especially SSL Decryption can significantly reduce performance on any firewall.&lt;/SPAN&gt; Beyond simple bandwidth, you must also understand your network's pulse: its session count and new session rate. A firewall can be brought to its knees by a high number of rapid, short-lived connections, even if the total bandwidth is low.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you gather this data, consider the nature of your traffic. Is it predominantly large file transfers, which are less CPU-intensive, or a flurry of small packets from a diverse range of applications? Knowing your application mix is also crucial, especially which applications are using SSL encryption, as inspecting that traffic is a heavy lift for any firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is also where you must make a fundamental decision: will you deploy a physical appliance or a virtual firewall?&lt;/P&gt;
&lt;P&gt;If your environment is heavily virtualized or lives in the cloud, a virtual firewall (VM-Series) might be the perfect fit. The sizing process here is a bit different; instead of just looking at hardware models, you'll need to determine the required CPU cores, RAM, and disk space. The performance of a virtual firewall is directly tied to the underlying hypervisor, host hardware, and resource allocation. You'll need to factor in hypervisor overhead and whether the virtual machine will have dedicated resources or share them with other VMs. &lt;SPAN class="citation-17 citation-end-17"&gt;This offers incredible flexibility, allowing you to scale up resources as your network grows without a hardware refresh.&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="source-inline-chip-container ng-star-inserted"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;Once you have this detailed picture, you can begin the sizing calculation. A simple rule of thumb is to always size for the Threat Prevention throughput, as this represents the real-world performance you will experience.&amp;nbsp;&amp;nbsp;Threat prevention throughput is the maximum speed a firewall can process traffic when all security and inspection features are enabled. Normal throughput, on the other hand, is the maximum speed when those same security features are disabled and the device is only performing basic packet forwarding.&amp;nbsp;The reason for the difference is that threat prevention services require significantly more processing power. When a firewall has to inspect every packet for threats, analyze URLs, and decrypt SSL traffic, it uses a lot of resources. Normal throughput is a raw, often theoretical number for a device acting as a basic router. Therefore, when sizing a firewall, you should always use the threat prevention throughput metric to get a realistic idea of its performance in an operational environment.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;You must also think ahead and consider your business's growth projections, anticipated increases in traffic, and new applications.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Finally, your sizing process should always involve a collaborative effort. Work with a trusted partner or the vendor's engineers to validate your findings. Also, don't forget the practicalities: ensure you plan for high availability with an Active/Passive or Active/Active pair to ensure uninterrupted operation.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Oct 2025 15:19:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-ngfw-sizing/m-p/1239667#M125296</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2025-10-08T15:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: PA-NGFW Sizing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-ngfw-sizing/m-p/1239717#M125301</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1035429259"&gt;@JeanPaul222&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I would highly recommend doing as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;mentioned and making sure that the first couple of times you size an environment that you have someone who actually knows everything you need to consider guide you in this process. There's a lot of traffic analysis that &lt;EM&gt;should&amp;nbsp;&lt;/EM&gt;be part of this when you're starting from ground zero, and someone gathering that data will also need to consider what your business cycle actually looks like (IE: You don't want to look at traffic patterns from a slow business period and use them for sizing if your busy period will be 2X that data or drastically change traffic patterns).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is something that you really won't want to get wrong, but you also won't want to needlessly oversize things just because proper analysis wasn't performed.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2025 00:53:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-ngfw-sizing/m-p/1239717#M125301</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2025-10-09T00:53:34Z</dc:date>
    </item>
    <item>
      <title>Re: PA-NGFW Sizing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-ngfw-sizing/m-p/1240533#M125404</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;In simple terms I first look at the throughput of Gbps. Then I choose the device that meets the minimum.&lt;/P&gt;
&lt;P&gt;Example: I need to push through 10Gbps. I would look at which device has that as its slowest and start there and then maybe go higher.&lt;/P&gt;
&lt;P&gt;So in this case I would start with the 3430.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_0-1761161621000.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/69666iA945E06E8B714552/image-size/medium?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_0-1761161621000.png" alt="OtakarKlier_0-1761161621000.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Depending on other aspects etc, might go to a higher model, i.e. the 5410.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 22 Oct 2025 19:34:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-ngfw-sizing/m-p/1240533#M125404</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2025-10-22T19:34:53Z</dc:date>
    </item>
  </channel>
</rss>

