PasteZap
🌐 Français
Gratuit · Sans compte

Gratuit · Réseau et infrastructure IT

Dimensionnement de pare-feu.

Dimensionnez un pare-feu nouvelle génération : débits de prévention des menaces, d’inspection TLS et VPN, sessions et nouvelles connexions à comparer aux fiches techniques.

Avant de commencer

Certains contrôles techniques restent en anglais. Les textes Unicode sont acceptés ; les formats et langues de sortie dépendent de l’outil.

Les limites techniques sont indiquées en anglais ci-dessous. Vérifiez-les avant de traiter de gros fichiers ou d’utiliser le résultat.

CALCULATED IN YOUR BROWSER · NOTHING IS UPLOADED

Users and links

Security features enabled

Banking, health and pinned apps are usually excluded.

VPN

Sessions and headroom

Browsers and sync clients keep dozens of connections open.

Threat prevention / threat protection throughput needed1.86 Gbps74,286 sessions
Peak one-direction traffic
1 Gbps
Both directions combined
3.71 Gbps
Some datasheets add both directions; compare with this figure if yours does
TLS inspection throughput
1 Gbps
VPN throughput
1.02 Gbps
Concurrent sessions
74,286
New sessions per second
2,477
WAN port speed
1 GbE
Headroom factor
× 1.86

Compare with the vendor datasheet

Datasheet lineRequiredHow to read it
Firewall throughput (stateful, L4)1.86 GbpsUsually measured with large UDP packets: the most optimistic figure. Never size on this alone.
Threat prevention / threat protection throughput1.86 GbpsThe figure to size on. Check the traffic mix and that logging was enabled in the vendor test.
TLS / SSL inspection throughput1 GbpsOften the lowest datasheet figure; it varies with cipher, key size and session reuse.
IPsec VPN throughput1.02 GbpsCheck whether the figure uses large packets; real VPN traffic mixes small packets.
Concurrent sessions74,286Connection-table size.
New sessions per second2,477Connection setup rate; matters for busy web servers and NAT.
Remote-access VPN users65Licensed or maximum concurrent clients.
Site-to-site tunnels3IPsec tunnel capacity.
  • Vendor-neutral estimate. Datasheet conditions differ between vendors; RFC 9411 and NetSecOPEN describe a common test methodology you can ask vendors about.
  • Plan high availability as a pair of identical units: each unit must carry the full load alone.
  • Inspection throughput falls as features are added; ask the vendor for a figure with your exact feature set enabled.

Comment utiliser cet outil: Dimensionnement de pare-feu

Saisissez ou sélectionnez vos données. Réglez les options, générez le résultat puis vérifiez-le avant de le copier ou de le télécharger.

Limites et formats acceptés

Vos données sont traitées sur votre appareil.

Notes techniques en anglais

Vendor-neutral estimate; datasheet test conditions differ between vendors. Session counts per device are an assumption you should check against a current firewall. Everything is calculated in your browser; nothing is sent or probed on the network.

Peak traffic (largest direction plus inspected internal traffic) is scaled by growth and divided by the maximum load. TLS throughput applies the encrypted and decrypted shares; sessions are devices × sessions per device; new sessions per second divide sessions by their lifetime.

250 users with 2 devices each on a 1 Gbps link with IPS, application control, anti-malware and TLS inspection need about 1.9 Gbps threat-protection throughput and 74,000 sessions.