Sizing an edge firewall for a university campus and would appreciate real-world input from people running decryption at scale.
Requirements:
- Internet edge only — no east-west/inter-VLAN (core switches handle that)
- Current internet traffic: ~3 Gbps, growing to 8–9 Gbps over the appliance's 5–7 year lifecycle
- Security profile: Threat Prevention (IPS/AV/anti-spyware), URL Filtering, DNS Security, WildFire
- SSL Forward Proxy (deep decryption) on ~80% of traffic — managed devices get decrypted; BYOD/pinned apps/exempt categories bypass
- LAN side: 2x 10G LACP to core (MLAG), so interface capacity is not the constraint
My concern: the datasheets publish Threat Prevention throughput (e.g., PA-3430 = 10.5 Gbps appmix) but no decryption throughput figures. From what I've read, enabling SSL Forward Proxy cuts effective throughput by roughly 60–70%, which would put a PA-3430 at ~3–4 Gbps of decrypted capacity — i.e., at my day-one load with zero growth room.
Questions:
- Is the ~60–70% decryption penalty accurate in practice on the PA-3400 series, or has it improved on recent PAN-OS releases?
- For 8–9 Gbps total with ~7 Gbps decrypted at peak, what's the honest minimum model — PA-3440? PA-5410? Something else?
- What decrypt percentages are you actually achieving at a campus/university edge once QUIC, pinned apps, and exemptions are accounted for?
- Any sizing rule of thumb you use for decryption headroom (2x? more?) given datasheet figures are best-case?