Hi, My customer is asking what is the average performance drop we can expect when enabling only application control for tcp based applications. Do we have any benchmark or rough estimate that we can safely tell to the customer. We are competing against PANW and they are bragging a lot about their application inspection throughput. I tried looking at the data sheets but there is no TCP based or application based throughput performance nos. Any help would be helpful. Regards Sebastan
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
It's always hard to determine the true throughput of a device without testing it yourself.
I usually rely on NSS labs to help determine how truthful vendors are with their datasheets vs actual throughput. I'd recommend looking at the NSS lab report on NGFWs found here.
In essence the PAN device they tested was rated at 1Gbps NGFW (app control + IPS) throughput on the datasheet but the NSS test had it at 719Mbps (71.9% of the claimed throughput).
The FGT 1500D was rated at 11Gbps on the datasheet and tested at 9597Mbps (87.25% of the claimed throughput).
The FGT 3600 was rated at 14Gbps on the datasheet and tested at 17Gbps (121.79% of the claimed throughput).
I feel Fortinet are more honest when it comes to their datasheets vs real world throughput than PAN are.
On top of that look at the security scores... PAN was the only NGFW vendor to score a caution. PAN were not happy with the score and wrote a post about it here. NSS labs replied back with interest :)
Hi,
Thanks a lot for your prompt response. But the customer is seeking the information based on just application control as for IPS they are going ahead with dedicated standalone IPS products. In the NSS labs reports you can see fortinet has opted out for testing application control and only tested on IPS throughput.
Atleast there should be some standard average metrics that we can use in sizing the appliance.
Regards
Sebastan
Hi Sebastan,
Where does it say that FortiGate opted out for testing app control? I can't find it in the report and was under the impression all the tests done were with app control enabled.
*edit*
I just read through the NGFW Test Methodology and they state that all the tests are done with application control.
FYI application control on a FortiGate uses the same engine as the IPS, so when spec'ing application control throughput I use the IPS throughput as the guideline.
Hi Neon,
I had seen the NSS labs NGIPS testing report in which I saw PAN was the only guys who did the application control test as well. Most of the other vendors had opted out in that test since it's optional test.
Regards
Sebastan
I believe you can't get an average rated due to so many factors;
virtual iron or real iron
the size of a appliance ( a FGT90D vrs a 3140 )
the quanity and type of interfaces
the number of NPU devices
the raw size of CPU/MEM present
OP, can you request a demo with the appliance of interest & with the FTNT sales team to determine the numbers to be expected?
As far as the more honest, neither PANW or FTNT can provide specific number but provides a generic number that can vary pos/neg depending on so many factors including but not limited to the above
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.