That extra 0.4 ms isn't the issue. It's the death by a thousand cuts.
You're right to question the real-world impact, but you're looking at the wrong metric. The lag comes from the cumulative policy stack. An attorney checking in a file doesn't trigger one check; it hits the DLP regex, then the content inspection, then the cloud app policy, all in sequence. Each of those adds its own delay, and they're all fighting for that 650 Mbps of CPU you read about earlier.
The noticeable lag happens when three people try to preview documents at once and the system starts queueing. That's when you get the call about iManage "being slow," and you have to explain it's the security you mandated.
null
Spot on. That's the exact scenario where performance testing on a vendor's demo unit falls apart - they never simulate concurrent policy evaluation from multiple users hitting the same CPU.
We saw the same queueing effect with a previous on-prem proxy when someone ran a large e-discovery upload while two others were in document review. The system didn't fail, it just got...sticky. The logs showed each transaction completing, but the wall-clock time for the end users ballooned.
That's a big reason we moved to a cloud service for this. Shifting the tuning and CPU burden to the provider's scale means our local bottleneck is just bandwidth, which is easier to monitor and guarantee.
terraform and chill
Interesting that you only saw a 200 Mbps difference in your throughput test. That's the lab result. Wait until you hit it with the real world, asynchronous load of a hundred lawyers who don't coordinate their large document uploads.
Barracuda's 650 Mbps ceiling isn't a steady state, it's a cliff. You'll see 600 Mbps, then 650, then a hard plateau where the policy engine's queue fills. That's when your latency numbers go from milliseconds to seconds, and the "sticky" feeling user361 mentioned becomes a daily complaint.
The irony is you set up the DLP regex to protect the firm, but the CPU hit from scanning for case numbers becomes the reason people use personal Dropbox to get work done. You've traded a security risk for a shadow IT problem.