PasteZap
🌐 日本語
無料 · アカウント不要

無料 · ネットワーク・IT インフラ

ファイアウォール選定計算機.

次世代ファイアウォールに必要な脅威防御・TLS 復号・VPN のスループット、セッション数、新規接続レートを算出し、データシートと比較できます。

はじめる前に

一部の技術的な操作項目は英語です。Unicode テキストに対応していますが、ファイル形式と出力言語はツールによって異なります。

技術的な制限は以下に英語で記載されています。大きなファイルを処理する前や結果を使用する前に確認してください。

CALCULATED IN YOUR BROWSER · NOTHING IS UPLOADED

Users and links

Security features enabled

Banking, health and pinned apps are usually excluded.

VPN

Sessions and headroom

Browsers and sync clients keep dozens of connections open.

Threat prevention / threat protection throughput needed1.86 Gbps74,286 sessions
Peak one-direction traffic
1 Gbps
Both directions combined
3.71 Gbps
Some datasheets add both directions; compare with this figure if yours does
TLS inspection throughput
1 Gbps
VPN throughput
1.02 Gbps
Concurrent sessions
74,286
New sessions per second
2,477
WAN port speed
1 GbE
Headroom factor
× 1.86

Compare with the vendor datasheet

Datasheet lineRequiredHow to read it
Firewall throughput (stateful, L4)1.86 GbpsUsually measured with large UDP packets: the most optimistic figure. Never size on this alone.
Threat prevention / threat protection throughput1.86 GbpsThe figure to size on. Check the traffic mix and that logging was enabled in the vendor test.
TLS / SSL inspection throughput1 GbpsOften the lowest datasheet figure; it varies with cipher, key size and session reuse.
IPsec VPN throughput1.02 GbpsCheck whether the figure uses large packets; real VPN traffic mixes small packets.
Concurrent sessions74,286Connection-table size.
New sessions per second2,477Connection setup rate; matters for busy web servers and NAT.
Remote-access VPN users65Licensed or maximum concurrent clients.
Site-to-site tunnels3IPsec tunnel capacity.
  • Vendor-neutral estimate. Datasheet conditions differ between vendors; RFC 9411 and NetSecOPEN describe a common test methodology you can ask vendors about.
  • Plan high availability as a pair of identical units: each unit must carry the full load alone.
  • Inspection throughput falls as features are added; ask the vendor for a figure with your exact feature set enabled.

使い方: ファイアウォール選定計算機

データを入力するかファイルを選び、設定を調整して結果を生成します。コピーやダウンロードの前に結果を確認してください。

制限と対応形式

入力内容はお使いの端末で処理されます。

英語の技術説明

Vendor-neutral estimate; datasheet test conditions differ between vendors. Session counts per device are an assumption you should check against a current firewall. Everything is calculated in your browser; nothing is sent or probed on the network.

Peak traffic (largest direction plus inspected internal traffic) is scaled by growth and divided by the maximum load. TLS throughput applies the encrypted and decrypted shares; sessions are devices × sessions per device; new sessions per second divide sessions by their lifetime.

250 users with 2 devices each on a 1 Gbps link with IPS, application control, anti-malware and TLS inspection need about 1.9 Gbps threat-protection throughput and 74,000 sessions.