मुफ़्त · नेटवर्क और आईटी इन्फ्रास्ट्रक्चर
फ़ायरवॉल साइज़िंग कैलकुलेटर.
नेक्स्ट-जनरेशन फ़ायरवॉल का आकार तय करें: थ्रेट प्रोटेक्शन, TLS इंस्पेक्शन और VPN थ्रूपुट, सेशन और कनेक्शन दर, डेटाशीट से तुलना के लिए।
Users and links
Security features enabled
Banking, health and pinned apps are usually excluded.
VPN
Sessions and headroom
Browsers and sync clients keep dozens of connections open.
- Peak one-direction traffic
- 1 Gbps
- Both directions combined
- 3.71 Gbps Some datasheets add both directions; compare with this figure if yours does
- TLS inspection throughput
- 1 Gbps
- VPN throughput
- 1.02 Gbps
- Concurrent sessions
- 74,286
- New sessions per second
- 2,477
- WAN port speed
- 1 GbE
- Headroom factor
- × 1.86
Compare with the vendor datasheet
| Datasheet line | Required | How to read it |
|---|---|---|
| Firewall throughput (stateful, L4) | 1.86 Gbps | Usually measured with large UDP packets: the most optimistic figure. Never size on this alone. |
| Threat prevention / threat protection throughput | 1.86 Gbps | The figure to size on. Check the traffic mix and that logging was enabled in the vendor test. |
| TLS / SSL inspection throughput | 1 Gbps | Often the lowest datasheet figure; it varies with cipher, key size and session reuse. |
| IPsec VPN throughput | 1.02 Gbps | Check whether the figure uses large packets; real VPN traffic mixes small packets. |
| Concurrent sessions | 74,286 | Connection-table size. |
| New sessions per second | 2,477 | Connection setup rate; matters for busy web servers and NAT. |
| Remote-access VPN users | 65 | Licensed or maximum concurrent clients. |
| Site-to-site tunnels | 3 | IPsec tunnel capacity. |
- Vendor-neutral estimate. Datasheet conditions differ between vendors; RFC 9411 and NetSecOPEN describe a common test methodology you can ask vendors about.
- Plan high availability as a pair of identical units: each unit must carry the full load alone.
- Inspection throughput falls as features are added; ask the vendor for a figure with your exact feature set enabled.
इस टूल का उपयोग कैसे करें: फ़ायरवॉल साइज़िंग कैलकुलेटर
डेटा दर्ज करें या फ़ाइल चुनें। विकल्प बदलें, परिणाम बनाएं और कॉपी या डाउनलोड करने से पहले उसकी जांच करें।
सीमाएं और समर्थित फ़ॉर्मैट
आपका डेटा आपके उपकरण पर संसाधित होता है।
अंग्रेज़ी में तकनीकी जानकारी
Vendor-neutral estimate; datasheet test conditions differ between vendors. Session counts per device are an assumption you should check against a current firewall. Everything is calculated in your browser; nothing is sent or probed on the network.
Peak traffic (largest direction plus inspected internal traffic) is scaled by growth and divided by the maximum load. TLS throughput applies the encrypted and decrypted shares; sessions are devices × sessions per device; new sessions per second divide sessions by their lifetime.
250 users with 2 devices each on a 1 Gbps link with IPS, application control, anti-malware and TLS inspection need about 1.9 Gbps threat-protection throughput and 74,000 sessions.