cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who Me Too'd this topic

Sizing PA-Series for internet edge — 3 Gbps today, growing to 8–9 Gbps, with SSL decryption. Which model?

L4 Transporter

Sizing an edge firewall for a university campus and would appreciate real-world input from people running decryption at scale.

Requirements:

  • Internet edge only — no east-west/inter-VLAN (core switches handle that)
  • Current internet traffic: ~3 Gbps, growing to 8–9 Gbps over the appliance's 5–7 year lifecycle
  • Security profile: Threat Prevention (IPS/AV/anti-spyware), URL Filtering, DNS Security, WildFire
  • SSL Forward Proxy (deep decryption) on ~80% of traffic — managed devices get decrypted; BYOD/pinned apps/exempt categories bypass
  • LAN side: 2x 10G LACP to core (MLAG), so interface capacity is not the constraint

My concern: the datasheets publish Threat Prevention throughput (e.g., PA-3430 = 10.5 Gbps appmix) but no decryption throughput figures. From what I've read, enabling SSL Forward Proxy cuts effective throughput by roughly 60–70%, which would put a PA-3430 at ~3–4 Gbps of decrypted capacity — i.e., at my day-one load with zero growth room.

Questions:

  1. Is the ~60–70% decryption penalty accurate in practice on the PA-3400 series, or has it improved on recent PAN-OS releases?
  2. For 8–9 Gbps total with ~7 Gbps decrypted at peak, what's the honest minimum model — PA-3440? PA-5410? Something else?
  3. What decrypt percentages are you actually achieving at a campus/university edge once QUIC, pinned apps, and exemptions are accounted for?
  4. Any sizing rule of thumb you use for decryption headroom (2x? more?) given datasheet figures are best-case?
Who Me Too'd this topic