Short answer
A firewall should be sized on your real peak inspected traffic, not on your internet line speed. FirstNet gathers sizing inputs during discovery before recommending a model or hosted option, because enabled security features and SSL inspection change the answer most.
In detail
What FirstNet looks at:
- Users: total, peak concurrent and remote VPN users
- Devices: endpoints, BYOD, IoT and servers, since devices drive sessions and traffic
- Peak throughput: internet, inter-site and encrypted traffic that will be inspected
- Security features: IPS, application control, antivirus, web and DNS filtering, sandboxing
- SSL/TLS inspection: often the biggest sizing factor, treated separately from basic firewall throughput
- VPN tunnels, concurrent sessions, new sessions per second, interfaces, HA, the firewall's role and growth over the next 12 to 36 months
These inputs are then matched against datasheet metrics such as threat protection throughput, SSL inspection throughput and IPsec VPN throughput. FirstNet documents whether the recommendation assumes basic firewalling, NGFW services or full threat protection with SSL inspection, which prevents under-sizing once advanced inspection is switched on.
Source: FirstNet Hosted Firewall & Network Security service page →
