Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sebastan_bach
New Contributor

Average performance drop with application control

Hi,    My customer is asking what is the average performance drop we can expect when enabling only application control for tcp based applications. Do we have any benchmark or rough estimate that we can safely tell to the customer. We are competing against PANW and they are bragging a lot about their application inspection throughput. I tried looking at the data sheets but there is no TCP based or application based throughput performance nos.    Any help would be helpful.   Regards   Sebastan

5 REPLIES 5
neonbit
Valued Contributor

It's always hard to determine the true throughput of a device without testing it yourself.

 

I usually rely on NSS labs to help determine how truthful vendors are with their datasheets vs actual throughput. I'd recommend looking at the NSS lab report on NGFWs found here.

 

In essence the PAN device they tested was rated at 1Gbps NGFW (app control + IPS) throughput on the datasheet but the NSS test had it at 719Mbps (71.9% of the claimed throughput).

 

The FGT 1500D was rated at 11Gbps on the datasheet and tested at 9597Mbps (87.25% of the claimed throughput).

 

The FGT 3600 was rated at 14Gbps on the datasheet and tested at 17Gbps (121.79% of the claimed throughput).

 

I feel Fortinet are more honest when it comes to their datasheets vs real world throughput than PAN are.

 

On top of that look at the security scores... PAN was the only NGFW vendor to score a caution. PAN were not happy with the score and wrote a post about it here. NSS labs replied back with interest :)

sebastan_bach

Hi, 

 

Thanks a lot for your prompt response. But the customer is seeking the information based on just application control as for IPS they are going ahead with dedicated standalone IPS products. In the NSS labs reports you can see fortinet has opted out for testing application control and only tested on IPS throughput. 

 

Atleast there should be some standard average metrics that we can use in sizing the appliance. 

 

Regards

 

Sebastan

 

 

neonbit

Hi Sebastan,

 

Where does it say that FortiGate opted out for testing app control? I can't find it in the report and was under the impression all the tests done were with app control enabled.

 

*edit*

 

I just read through the NGFW Test Methodology and they state that all the tests are done with application control.

 

FYI application control on a FortiGate uses the same engine as the IPS, so when spec'ing application control throughput I use the IPS throughput as the guideline.

 

 

sebastan_bach

Hi Neon, 

 

I had seen the NSS labs NGIPS testing report in which I saw PAN was the only guys who did the application control test as well. Most of the other vendors had opted out in that test since it's optional test. 

 

Regards

 

Sebastan

emnoc
Esteemed Contributor III

I believe you can't get an average rated due to so many factors;

 

     virtual iron or real iron

     the size of a appliance ( a FGT90D vrs a 3140 )

     the quanity and type of interfaces

     the number of NPU devices     

     the raw size of CPU/MEM present

 

OP, can you request a demo with the appliance of interest &  with the FTNT sales team to determine the numbers to be expected? 

 

As far as the more honest, neither PANW or FTNT can provide specific number but provides a generic number that can vary  pos/neg depending on so many factors including but not limited to the above

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors