Buying Guide

Hardware Firewall Explained: Do You Need One and How to Size It

Sarah Jane Sep 12, 2026 5 min read
Hardware Firewall Explained: Do You Need One and How to Size It

A hardware firewall is a dedicated appliance rather than software on a server, and the question of whether you need one has a clearer answer than most vendors give. This covers what it is, when it is the right choice, and how to size one.

What is a hardware firewall?

A purpose-built appliance that sits between your network and the internet, inspecting traffic and enforcing rules in dedicated hardware.

The distinction from software firewalls is where the work happens. A software firewall runs on a general-purpose machine and shares its resources. A hardware firewall has processing dedicated to the task, frequently with accelerators for encryption and inspection, and it runs nothing else.

Most modern appliances are more accurately next-generation firewalls: they do packet filtering plus application awareness, intrusion prevention, and inspection of encrypted traffic.

Do I need a hardware firewall?

Being honest about where the line sits.

Your router already has a firewall. Every business router does basic packet filtering and network address translation. For a very small office with no servers exposed and no compliance requirement, that may genuinely be enough.

You need a dedicated appliance when: you host services reachable from the internet, you have compliance requirements that specify it, you need site-to-site or remote access VPN at scale, you want traffic visibility and logging, or you need to segment an internal network. Our segmentation guide covers the last one.

You may not need one when: everything is cloud-hosted with no on-premises services, the site is small with no compliance driver, and the router’s capabilities cover the requirement.

The honest framing: a firewall appliance is worth its cost when there is something on your network worth protecting from the internet, or when someone requires you to have one.

How do I size a firewall?

Three numbers, and the one on the box is the least useful.

Throughput with inspection enabled. Vendors quote a headline figure for raw packet forwarding, which is not what you will get. The number that matters is throughput with the features you will actually run — intrusion prevention, application control, encrypted traffic inspection. That figure is frequently a fraction of the headline.

Concurrent sessions. How many connections it can track at once. Busy networks with many users and cloud applications generate far more sessions than people expect.

VPN throughput and tunnel count, if you terminate VPNs on it.

Size against the inspected throughput and leave headroom. A firewall running at its limit drops traffic or disables inspection, and either is worse than a bigger appliance would have cost. Our firewall sizing guide covers this in more detail.

The cost people miss

Subscriptions.

A firewall appliance without its security subscriptions is a router with logging. Intrusion prevention signatures, application databases, URL filtering and malware inspection are licensed annually, and those licences frequently cost more over a few years than the appliance did.

Two consequences. Budget for the subscription life, not the purchase. And a used firewall appliance may have no transferable licence, which is the single most important thing to check before buying one second-hand. Our entitlement guide covers checking, and our support guide covers what varies.

Buying a used firewall

Four things to confirm.

Licence transferability. Ask before buying. Many vendors do not transfer security subscriptions, which can make a cheap appliance expensive.

Software support status. An appliance past software support receives no signature updates, which defeats the purpose.

It has been factory reset and carries no previous configuration.

Throughput matches your requirement with inspection on.

Where those check out, used firewall appliances are good value, particularly for branch sites and lab use. Our branch guide covers small-site equipment.

Frequently asked questions

What is the difference between a hardware and software firewall?

Where the work happens. A hardware firewall is a dedicated appliance with processing reserved for the task and nothing else running on it. A software firewall shares the resources of a general-purpose machine.

Do I need a hardware firewall if my router has one?

Not always. For a very small office with no internet-facing services and no compliance driver, the router may be enough. You need a dedicated appliance when you host services, have compliance requirements, run VPNs at scale, or need internal segmentation.

How do I size a firewall appliance?

By throughput with inspection enabled, not the headline figure. Also concurrent sessions and VPN throughput. The inspected figure is frequently a fraction of the number on the box, so size against it and leave headroom.

Why does a firewall need a subscription?

Intrusion prevention signatures, application databases, URL filtering and malware inspection are licensed annually. Without them the appliance is a router with logging. The subscriptions frequently cost more over a few years than the appliance did.

Can I buy a used firewall appliance?

Yes, but confirm licence transferability first. Many vendors do not transfer security subscriptions. Also check software support status, that it has been factory reset, and that throughput matches your requirement with inspection on.

What happens if a firewall runs at its throughput limit?

It drops traffic or disables inspection features to keep up. Either outcome is worse than the cost difference of a larger appliance, so size with headroom.

Tell us your internet link speed, user count and whether you terminate VPNs, and we will size the appliance against inspected throughput rather than the headline figure.

Sarah Jane

Sarah Jane

Senior IT Hardware Specialist · TechSellerUSA
Sarah helps businesses and IT teams source the right enterprise hardware at wholesale prices. View profile →