A firewall that looks adequate on a datasheet can become the source of a business outage once full security inspection, remote access, and cloud traffic are enabled. This firewall throughput sizing guide helps decision-makers select capacity for real operating conditions, not an optimistic headline number. The goal is straightforward: maintain protection against malware, ransomware, unauthorized access, and data loss without slowing the applications employees and customers depend on.
Why Firewall Throughput Is More Than One Number
Firewall vendors publish several throughput figures because a firewall performs several different jobs. A basic firewall throughput figure may measure traffic flowing through the appliance with only minimal policy processing. That number is useful, but it is rarely the number that should drive a business purchase.
When security services are switched on, the firewall must inspect traffic, apply policies, identify applications, check IPS signatures, filter web activity, scan files, and sometimes decrypt encrypted sessions for inspection. Each action consumes processing capacity. A device that can pass several gigabits per second in firewall-only testing may deliver far less when threat protection is active.
For most organizations, the most meaningful metrics are threat protection throughput and NGFW throughput. Threat protection usually reflects a combination of firewalling, intrusion prevention, application control, and malware protection. NGFW throughput generally focuses on application awareness and intrusion prevention. Neither metric is identical across every vendor or test methodology, so compare like for like and confirm exactly which services are included.
VPN throughput is separate again. Remote staff, branch offices, suppliers, and cloud connections can create substantial IPsec or SSL VPN demand. If a firewall is sized only for office internet traffic, it may struggle when a large group connects remotely during an incident, weather disruption, or business-continuity event.
Start With the Traffic Your Business Actually Uses
Sizing begins with measurement rather than user count alone. Two companies with 100 employees can have completely different requirements. A professional-services office using email, SaaS platforms, video meetings, and cloud backups has a different traffic profile from a warehouse with cameras, a retailer with multiple sites, or a company moving large design files between offices and cloud storage.
Review peak internet utilization over at least 30 days, not only the average. A connection that averages 150 Mbps may reach 700 Mbps during backups, software updates, video conferences, or file transfers. The firewall must handle those peaks while inspection is enabled. If the business has more than one WAN link, calculate the potential combined traffic that could pass through the firewall under normal load or failover conditions.
Collect these inputs before comparing firewall models:
- Current WAN bandwidth and measured peak inbound and outbound use
- Number of office users, remote users, guest users, and connected devices
- Cloud applications, video conferencing, backups, VoIP, cameras, and large-file workflows
- Site-to-site VPN tunnels, remote-access VPN users, and expected encrypted traffic
- Planned growth in staff, branches, internet speed, cloud adoption, and security services
This information turns a broad question such as, “Which firewall should we buy?” into a capacity requirement that can be tested against a specific appliance.
How to Use This Firewall Throughput Sizing Guide
A practical sizing method is to take your expected peak traffic and apply a security and growth margin. For a company with a 1 Gbps internet connection that regularly reaches 600 Mbps, a firewall should not be chosen simply because its basic firewall rating exceeds 1 Gbps. The relevant question is whether its threat protection performance can sustain the 600 Mbps peak, plus room for future demand.
As a general planning approach, aim for inspected throughput of at least 1.5 to 2 times your expected peak traffic. This margin supports traffic bursts, policy growth, signature updates, new applications, and the performance effect of enabling additional protections. It also reduces the chance that the appliance reaches sustained high utilization, where user experience and security-event response can suffer.
The right margin depends on the organization. A small office with stable bandwidth and limited application change may be comfortable near the lower end. A growing business, a multi-site organization, or a company that handles sensitive data should normally allow more headroom. Security requirements can also change after deployment. If encrypted traffic inspection, sandboxing, or expanded web filtering becomes necessary later, an undersized appliance may require an earlier replacement.
Do not treat bandwidth as the only sizing factor. Concurrent sessions matter because every active browser tab, cloud application, phone, endpoint agent, and server connection can create sessions. New sessions per second also matter in environments with many users, public-facing services, or a high volume of short-lived connections. A firewall may have enough Mbps capacity but still become constrained by session volume.
A Simple Sizing Example
Consider a 150-user business with dual 1 Gbps internet links. Its normal peak is 500 Mbps, but it expects to add cloud backup, more video calls, and 50 additional remote users within 18 months. The company also needs site-to-site VPN links to two branches and intends to inspect encrypted web traffic for selected user groups.
A firewall with 1 Gbps of basic firewall throughput may appear suitable on paper. It is not necessarily suitable once intrusion prevention, application control, web filtering, antivirus, and VPN traffic are active. A more appropriate starting point is an appliance with materially higher threat protection capacity than the 500 Mbps peak, adequate IPsec VPN performance, and sufficient session capacity for users, endpoints, servers, and guest devices.
The decision may be between a lower-cost model that meets today’s measured traffic and a higher model that supports planned internet growth. The lower model can be sensible if the business has a stable environment and a short refresh cycle. The higher model is usually the better continuity decision when expansion is confirmed, security inspection will increase, or downtime has a high cost.
Include Security Features in the Performance Calculation
Disabling security services to preserve speed defeats the reason for deploying a next-generation firewall. Size for the policy set you expect to enforce, including intrusion prevention, antivirus, application control, DNS and web filtering, botnet protection, and VPN access where required.
SSL or TLS inspection deserves particular attention. Much business traffic is encrypted, which protects privacy but can hide malicious content from ordinary inspection. Decrypting, inspecting, and re-encrypting authorized traffic adds processing load. Not every organization needs to inspect every encrypted session, and privacy, legal, certificate-management, and application-compatibility concerns must be considered. Still, if SSL inspection is part of the security plan, it must be included in the sizing discussion from the start.
High availability also changes the design. In an active-passive firewall pair, each unit should usually be capable of carrying the required traffic if its partner fails. Buying two undersized appliances does not create adequate capacity. In active-active designs, traffic distribution, session synchronization, and application behavior need careful design rather than assuming capacity is simply doubled.
Avoid Common Procurement Mistakes
The first mistake is comparing a FortiGate model with another appliance using only the largest advertised throughput figure. Ask for the figures relevant to the security services you will use. The second is sizing solely by employee count. Device density, cloud traffic, remote access, and bandwidth peaks often matter more.
The third mistake is forgetting licenses and support. Security subscriptions enable services such as threat intelligence, intrusion prevention, web filtering, and advanced protection. A firewall installed without the required licensing may route traffic but fail to provide the intended security coverage. Ongoing support also matters when an urgent policy change, VPN issue, hardware fault, or renewal deadline affects operations.
Finally, avoid gray-market or unsupported equipment. Authentic hardware, valid licenses, and a clear support path protect both the investment and the ability to respond quickly when an issue occurs.
Match the Firewall to a Growth Plan, Not Just a Quote
The best firewall is not automatically the highest-capacity model. Oversizing can waste budget that could be used for endpoint security, switching, wireless coverage, backup, or staff training. Undersizing creates a more serious risk: users experience slow applications, administrators turn off inspection to restore performance, or the organization faces an unplanned replacement.
A suitable FortiGate deployment balances current measured demand, active security features, VPN requirements, session load, redundancy, and realistic growth. For businesses in Dubai, the UAE, and Saudi Arabia that need help translating those inputs into a model and license plan, Digital World Technology can assess the environment, supply genuine Fortinet equipment, and support installation and ongoing maintenance.
Before approving a firewall purchase, ask for a sizing recommendation that states the assumed peak traffic, enabled security services, VPN demand, growth allowance, licenses, and support coverage. A clear answer now is far less expensive than discovering capacity limits when your business needs protection most.