Skip to main content
sebastan_bach
New Member
November 25, 2015
Question

Average performance drop with application control

  • November 25, 2015
  • 1 reply
  • 6473 views

Hi,    My customer is asking what is the average performance drop we can expect when enabling only application control for tcp based applications. Do we have any benchmark or rough estimate that we can safely tell to the customer. We are competing against PANW and they are bragging a lot about their application inspection throughput. I tried looking at the data sheets but there is no TCP based or application based throughput performance nos.    Any help would be helpful.   Regards   Sebastan

    1 reply

    neonbit
    New Member
    November 25, 2015

    It's always hard to determine the true throughput of a device without testing it yourself.

     

    I usually rely on NSS labs to help determine how truthful vendors are with their datasheets vs actual throughput. I'd recommend looking at the NSS lab report on NGFWs found here.

     

    In essence the PAN device they tested was rated at 1Gbps NGFW (app control + IPS) throughput on the datasheet but the NSS test had it at 719Mbps (71.9% of the claimed throughput).

     

    The FGT 1500D was rated at 11Gbps on the datasheet and tested at 9597Mbps (87.25% of the claimed throughput).

     

    The FGT 3600 was rated at 14Gbps on the datasheet and tested at 17Gbps (121.79% of the claimed throughput).

     

    I feel Fortinet are more honest when it comes to their datasheets vs real world throughput than PAN are.

     

    On top of that look at the security scores... PAN was the only NGFW vendor to score a caution. PAN were not happy with the score and wrote a post about it here. NSS labs replied back with interest :)

    sebastan_bach
    New Member
    November 26, 2015

    Hi, 

     

    Thanks a lot for your prompt response. But the customer is seeking the information based on just application control as for IPS they are going ahead with dedicated standalone IPS products. In the NSS labs reports you can see fortinet has opted out for testing application control and only tested on IPS throughput. 

     

    Atleast there should be some standard average metrics that we can use in sizing the appliance. 

     

    Regards

     

    Sebastan

     

     

    neonbit
    New Member
    November 26, 2015

    Hi Sebastan,

     

    Where does it say that FortiGate opted out for testing app control? I can't find it in the report and was under the impression all the tests done were with app control enabled.

     

    *edit*

     

    I just read through the NGFW Test Methodology and they state that all the tests are done with application control.

     

    FYI application control on a FortiGate uses the same engine as the IPS, so when spec'ing application control throughput I use the IPS throughput as the guideline.