Sizing help — university internet edge, 3 Gbps today, 4,000–5,000 students, 7-year lifespan. PA-3430 / PA-3440 / PA-5410?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Sizing help — university internet edge, 3 Gbps today, 4,000–5,000 students, 7-year lifespan. PA-3430 / PA-3440 / PA-5410?

L4 Transporter

Looking for sizing advice from anyone running PAN at a university/campus internet edge.

Environment:

  • University with 4,000–5,000 students plus staff/faculty
  • Current internet bandwidth: 3 Gbps — expect this to grow substantially over the appliance's life (bandwidth per student keeps climbing; wouldn't be surprised to hit 8–10 Gbps by end of life)
  • Firewall lifespan target: 7 years
  • Role: internet edge only — no east-west (core switches handle inter-VLAN)
  • Planned security stack: Threat Prevention, Advanced URL Filtering, DNS Security, WildFire
  • SSL Forward Proxy on managed devices (~70–80% of traffic decrypted; BYOD/student devices get certificate inspection or bypass)
  • DMZ with published services (web, LMS)
  • LAN side: 2x 10G LACP to core, so ports aren't the issue

Where I'm stuck: datasheets show Threat Prevention throughput (PA-3430 = 10.5, PA-3440 = 12.8, PA-5410 = 35 Gbps appmix) but no decryption figures. I've read decryption cuts effective throughput 60–70%, which would make the 3400 series marginal by mid-life if traffic grows as expected.

Questions:

  1. For this profile over 7 years, what would you deploy — PA-3440 or PA-5410? Is the 3430 out of the question?
  2. What's the realistic decrypted throughput people see on the 3440 vs the 5410 (with its hardware SSL acceleration)?
  3. For those at universities: what decryption percentage do you actually achieve with a large BYOD population, once QUIC and pinned apps are accounted for?
  4. Any experience with how appmix numbers translate to real campus traffic (heavy streaming/CDN, thousands of concurrent users)?
  5. Sessions: with 5,000+ concurrent users, is the 3440's 3M session cap comfortable, or have campuses hit session/CPS limits before throughput limits?

Evaluating against FortiGate 701G and Check Point 9700/9800 quotes, so trying to identify PAN's genuinely right-sized model rather than the cheapest one that passes on paper.

0 REPLIES 0
  • 31 Views
  • 0 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!