Buying Guide

Firewall Sizing: Why Headline Throughput Misleads

Sarah Jane Sep 08, 2026 5 min read

Firewall throughput figures are quoted under conditions you will never run in. Sizing against the headline number is how organisations end up with an appliance that becomes the bottleneck the moment they enable the features they bought it for.

The headline figure is not the working figure

Firewall specifications typically quote several throughput numbers, and they differ substantially.

Raw firewall throughput is packet filtering with minimal inspection. It is the largest number and the least representative of production.

Throughput with inspection enabled — application awareness, intrusion prevention, malware scanning — is considerably lower, because each of those requires examining traffic rather than passing it.

Throughput with encrypted traffic inspection is lower again, and this is the one that matters most now. The overwhelming majority of traffic is encrypted, and inspecting it means decrypting, examining and re-encrypting every session. That is computationally expensive.

The practical rule: size against the figure for the features you will actually enable, including encrypted inspection if you intend to use it. An appliance sized on raw throughput will disappoint immediately.

Concurrent sessions and connection rate

Two specifications that matter more than throughput in some environments and are frequently ignored.

Concurrent sessions is how many connections the firewall tracks at once. Modern applications open many connections per user — a single page load can open dozens — so session counts rise faster than user counts.

New connections per second is how quickly it can establish them. This is what bites at peak, and it is what a burst of activity exhausts first.

An environment with modest bandwidth but many users and many small connections can exhaust session capacity while throughput sits comfortably low. Guest wireless is a classic case.

Where the firewall sits changes the requirement

Three positions with different sizing.

Internet edge. Sized against your internet bandwidth plus growth. This is the conventional case, and the one where encrypted inspection cost dominates.

Between internal segments. Sized against internal traffic, which is frequently far higher than internet bandwidth. Routing all inter-VLAN traffic through a firewall is a common design that produces a bottleneck if the appliance was sized for the internet link. Our segmentation guide covers when to route on a switch instead.

Remote sites. Sized against the site link and user count, usually much smaller, but with the same feature requirements — which is why small-branch appliances exist as a category.

Sizing an internal firewall against internet bandwidth is one of the more common and more expensive mistakes here.

Licensing decides ongoing cost

The commercial structure matters as much as the hardware, and it works differently from most equipment.

Firewalls typically separate the appliance from subscriptions for the services that make it useful — threat intelligence, application identification, content filtering, malware signatures.

Those subscriptions expire. When they do, the appliance keeps passing traffic while the protection stops being updated, which is worse than obvious failure because nothing appears wrong.

Three things to establish before buying.

What is included and what is subscription. The appliance price alone is not the cost.

What happens at expiry. Some features stop, some continue with stale data. Know which.

Whether subscriptions transfer on secondary-market hardware. This is the key question for refurbished firewalls, and it is frequently the answer that decides whether refurbished makes sense at all — unlike switches, where the hardware alone is often the whole purchase.

Availability

A firewall at the internet edge is a single point of failure for everything behind it.

High availability pairs run two appliances with one taking over on failure. That doubles hardware and frequently subscription cost, so it is a business decision rather than a technical default.

The question to ask is what an outage costs per hour, against the cost of the second appliance. For many organisations a spare unit on the shelf with a saved configuration is a proportionate middle ground — recovery in an hour rather than seconds, at a fraction of the cost.

If you take that route, test restoring the configuration to the spare. An untested configuration restore is an assumption, the same as an untested backup. Our backup guide makes the same point about restores generally.

Also ensure firewall configuration is included in your backups — it is one of the things most commonly missing when a rebuild is needed.

Practical checks

Measure current throughput at peak rather than estimating from bandwidth. Count concurrent sessions if your existing equipment reports them. Decide which inspection features you will actually enable, and size against that figure. Establish the subscription structure and renewal cost as part of the purchase. Confirm where the appliance sits and what traffic it will carry. And plan how you recover if it fails.

Also worth arranging: out-of-band console access. A firewall configuration change that cuts off network access is a common way to lose a site, and console access turns that from a visit into a two-minute revert.

Common questions

Why is my firewall slower than its rated throughput?

Because the headline figure is raw filtering with minimal inspection. Throughput with application awareness and intrusion prevention is considerably lower, and with encrypted traffic inspection lower again — and most traffic is now encrypted.

What should I size against besides throughput?

Concurrent sessions and new connections per second. Modern applications open many connections per user, so session counts rise faster than user counts, and an environment with modest bandwidth can exhaust session capacity while throughput sits low.

Can I use one firewall for internet and internal segmentation?

Only if sized for it. Internal traffic is frequently far higher than internet bandwidth, so routing all inter-VLAN traffic through an appliance sized for the internet link creates a bottleneck. Consider routing on a layer 3 switch instead.

What happens when firewall subscriptions expire?

Typically the appliance keeps passing traffic while protection stops being updated, which is worse than obvious failure because nothing appears wrong. Establish before buying which features stop and which continue with stale data.

Do I need a high availability pair?

It depends what an outage costs per hour against a second appliance and its subscriptions. A spare unit with a tested configuration restore is a proportionate middle ground for many organisations — recovery in an hour rather than seconds, at a fraction of the cost.

Tell us your peak throughput, user count and which inspection features you need, and we will size it against the right figure.

Sarah Jane

Sarah Jane

Senior IT Hardware Specialist · TechSellerUSA
Sarah helps businesses and IT teams source the right enterprise hardware at wholesale prices. View profile →