<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Threat Protection in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/threat-protection/m-p/12168#M8921</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1) You can see the various performance numbers (which depends on model) for throughput with threat preventation enabled in the datasheets:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA-5060&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20 Gbps firewall throughput&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 Gbps threat prevention throughput&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA-5050&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 Gbps firewall throughput&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 Gbps threat prevention throughput&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA-5020&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 Gbps firewall throughput&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 Gbps threat prevention throughput&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA-4060&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 Gbps firewall throughput&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 Gbps threat prevention throughput&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA-4050&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 Gbps firewall throughput&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 Gbps threat prevention throughput&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA-4020&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 Gbps firewall throughput&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 Gbps threat prevention throughput&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA-2050&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 Gbps firewall throughput&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 500 Mbps threat prevention throughput&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA-2020&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 500 Mbps firewall throughput&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 200 Mbps threat prevention throughput&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA-500&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 250 Mbps firewall throughput&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 100 Mbps threat prevention throughput&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA-200&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 100 Mbps firewall throughput&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 50 Mbps threat prevention throughput&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order to monitor the throughput you can use snmp, here is some info on how to do this with cacti: &lt;A __default_attr="4367" __jive_macro_name="thread" class="jive_macro jive_macro_thread" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) As I understand it the singlepass engine in PA will work no matter if you have a specific rule using threat protection or not. Some benchmarks published on the Internet even shows that throughput went down when you disabled threat preventation compared to a rule with everything enabled. Also the figures mentioned in PA's datasheets isnt max values (like most competitors) but rather low values (NSS Labs found that actual performance was 115% of stated in the datasheet - of course this might vary depending on what kind of traffic, packetsizes, segmentsizes etc).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edit: I guess these two docs might be of interrest:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="1886" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="3094" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 26 Jul 2012 12:36:06 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2012-07-26T12:36:06Z</dc:date>
    <item>
      <title>Threat Protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-protection/m-p/12167#M8920</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="color: #000000; font-family: arial; font-size: small; text-align: -webkit-auto;"&gt;I hope you may be able to answer a couple of quick questions for me as&amp;nbsp; i am planning on switching Threat Protection on in the next few weeks.&lt;/P&gt;&lt;P style="color: #000000; font-family: arial; font-size: small; text-align: -webkit-auto;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: arial; font-size: small; text-align: -webkit-auto;"&gt;1.&amp;nbsp; When we turn on Threat Protection i remember you saying that the throughput for the dataplane is cut in half,&amp;nbsp; Is there any way of monitoring the throughput of the dataplane?&lt;/P&gt;&lt;P style="color: #000000; font-family: arial; font-size: small; text-align: -webkit-auto;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: arial; font-size: small; text-align: -webkit-auto;"&gt;2.&amp;nbsp; When Threat protection is enabled will it limit the throughput for every Network/Port on the Firewall. From what I have read you have to configure Threat Protection on every policy,&amp;nbsp; does that mean only limits the throughput on the zones.&lt;/P&gt;&lt;P style="color: #000000; font-family: arial; font-size: small; text-align: -webkit-auto;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: arial; font-size: small; text-align: -webkit-auto;"&gt;If you could help me with this it would be great.&lt;/P&gt;&lt;P style="color: #000000; font-family: arial; font-size: small; text-align: -webkit-auto;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: arial; font-size: small; text-align: -webkit-auto;"&gt;Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jul 2012 11:50:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-protection/m-p/12167#M8920</guid>
      <dc:creator>BBHLTD</dc:creator>
      <dc:date>2012-07-26T11:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-protection/m-p/12168#M8921</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1) You can see the various performance numbers (which depends on model) for throughput with threat preventation enabled in the datasheets:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA-5060&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20 Gbps firewall throughput&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 Gbps threat prevention throughput&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA-5050&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 Gbps firewall throughput&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 Gbps threat prevention throughput&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA-5020&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 Gbps firewall throughput&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 Gbps threat prevention throughput&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA-4060&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 Gbps firewall throughput&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 Gbps threat prevention throughput&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA-4050&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 Gbps firewall throughput&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 Gbps threat prevention throughput&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA-4020&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 Gbps firewall throughput&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 Gbps threat prevention throughput&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA-2050&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 Gbps firewall throughput&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 500 Mbps threat prevention throughput&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA-2020&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 500 Mbps firewall throughput&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 200 Mbps threat prevention throughput&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA-500&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 250 Mbps firewall throughput&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 100 Mbps threat prevention throughput&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA-200&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 100 Mbps firewall throughput&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 50 Mbps threat prevention throughput&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order to monitor the throughput you can use snmp, here is some info on how to do this with cacti: &lt;A __default_attr="4367" __jive_macro_name="thread" class="jive_macro jive_macro_thread" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) As I understand it the singlepass engine in PA will work no matter if you have a specific rule using threat protection or not. Some benchmarks published on the Internet even shows that throughput went down when you disabled threat preventation compared to a rule with everything enabled. Also the figures mentioned in PA's datasheets isnt max values (like most competitors) but rather low values (NSS Labs found that actual performance was 115% of stated in the datasheet - of course this might vary depending on what kind of traffic, packetsizes, segmentsizes etc).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edit: I guess these two docs might be of interrest:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="1886" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="3094" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jul 2012 12:36:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-protection/m-p/12168#M8921</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-07-26T12:36:06Z</dc:date>
    </item>
  </channel>
</rss>

