PasteZap
🌐 Nederlands
Gratis · Zonder account

Gratis · Netwerk en IT-infrastructuur

Firewalldimensionering.

Dimensioneer een next-generation firewall: doorvoer voor dreigingsbescherming, TLS-inspectie en VPN, sessies en verbindingssnelheid om met datasheets te vergelijken.

Voordat je begint

Sommige technische bedieningselementen zijn in het Engels. Unicode-tekst wordt ondersteund; formaten en uitvoertalen hangen af van de tool.

De technische limieten staan hieronder in het Engels. Controleer ze voordat je grote bestanden verwerkt of het resultaat gebruikt.

CALCULATED IN YOUR BROWSER · NOTHING IS UPLOADED

Users and links

Security features enabled

Banking, health and pinned apps are usually excluded.

VPN

Sessions and headroom

Browsers and sync clients keep dozens of connections open.

Threat prevention / threat protection throughput needed1.86 Gbps74,286 sessions
Peak one-direction traffic
1 Gbps
Both directions combined
3.71 Gbps
Some datasheets add both directions; compare with this figure if yours does
TLS inspection throughput
1 Gbps
VPN throughput
1.02 Gbps
Concurrent sessions
74,286
New sessions per second
2,477
WAN port speed
1 GbE
Headroom factor
× 1.86

Compare with the vendor datasheet

Datasheet lineRequiredHow to read it
Firewall throughput (stateful, L4)1.86 GbpsUsually measured with large UDP packets: the most optimistic figure. Never size on this alone.
Threat prevention / threat protection throughput1.86 GbpsThe figure to size on. Check the traffic mix and that logging was enabled in the vendor test.
TLS / SSL inspection throughput1 GbpsOften the lowest datasheet figure; it varies with cipher, key size and session reuse.
IPsec VPN throughput1.02 GbpsCheck whether the figure uses large packets; real VPN traffic mixes small packets.
Concurrent sessions74,286Connection-table size.
New sessions per second2,477Connection setup rate; matters for busy web servers and NAT.
Remote-access VPN users65Licensed or maximum concurrent clients.
Site-to-site tunnels3IPsec tunnel capacity.
  • Vendor-neutral estimate. Datasheet conditions differ between vendors; RFC 9411 and NetSecOPEN describe a common test methodology you can ask vendors about.
  • Plan high availability as a pair of identical units: each unit must carry the full load alone.
  • Inspection throughput falls as features are added; ask the vendor for a figure with your exact feature set enabled.

Zo gebruik je deze tool: Firewalldimensionering

Voer gegevens in of kies een bestand. Pas de instellingen aan, maak het resultaat en controleer het voordat je het kopieert of downloadt.

Limieten en ondersteunde formaten

Je invoer wordt op je apparaat verwerkt.

Technische opmerkingen in het Engels

Vendor-neutral estimate; datasheet test conditions differ between vendors. Session counts per device are an assumption you should check against a current firewall. Everything is calculated in your browser; nothing is sent or probed on the network.

Peak traffic (largest direction plus inspected internal traffic) is scaled by growth and divided by the maximum load. TLS throughput applies the encrypted and decrypted shares; sessions are devices × sessions per device; new sessions per second divide sessions by their lifetime.

250 users with 2 devices each on a 1 Gbps link with IPS, application control, anti-malware and TLS inspection need about 1.9 Gbps threat-protection throughput and 74,000 sessions.