sizing firewall

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

sizing firewall

L4 Transporter

Hi,

I am looking for a firewall  for 3000 users, 

and 500  vdi  access 

expecting approximately igb  internet traffic 

Please help to size,

Ho much throughput I needed 

 

Thanks 

6 REPLIES 6

Cyber Elite
Cyber Elite

if you're a partner you can use 'popsicle' from the NextWave portal https://www.paloaltonetworks.com/partners/nextwave-partner-portal/cyberforce/cyberforce-members-only

 

to get a decent sizing you'll need to estimate how much ipsec, app-id and ssl throughput you will expect, and then guesstimate how much l7 scanning you're going to apply

 

ie.

1gbps app-ID sizes to pa-820,

1gbps threat-ID sizes to pa-3220,

1gbps ssl decryption + threat-ID sizes to pa-5220

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Hi @reaper 

Can you please  elaborate How I determine the app-id throughput 

Thanks

Cyber Elite
Cyber Elite

Hello,

Here is a link to the comparison sheet:

https://www.paloaltonetworks.com/products/product-selection

Then select the devices you think might work. In your case, start with the 3410 and 5410 as a comparison.

 

I always look a the smallest number and go from there, even if I'm not using it. This way if in the future you need that feature, you have it sized correctly, if nothing else changes. Also dont skimp on the licenses and features. They help you more than you know.

 

I'm only guessing but I bet a 3410 would work for you (but dont go by my advice only since I dont know your environment). Stay with the models that have the 4 as the second number, they are the newest architecture.

 

Cheers!

What is the best way to size that for an existing customer, on an existing firewall?

Cyber Elite
Cyber Elite

Hello,

If the Palo Alto has already been deployed, check the CPU utilization. This is a good indicator (not the only one) of the performance of the existing system. If you are looking to replace another vendors firewall, What I do is take the amount of bandwidth that the traffic is going through and them spec the Palo Alto with that number using the most restrictive numbers, usually the 'Threat Prevent' numbers. Then make sure that its less than 50% of that. This give room for growth etc.

 

Regards,

Cyber Elite
Cyber Elite

Hello,

For those specs, I would go with a PA-5410 series.

Regards,

  • 4637 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!