Hi everyone. I’ve been tasked with evaluating a Check Point Quantum Spark 1600 appliance as a potential edge firewall for a few of our smaller branch offices. We’re planning some cloud migrations soon, but the on-prem gear needs to be solid first.
I set up a lab to see if it could genuinely handle the 1 Gbps throughput it's rated for with mixed traffic. My test used a ~70/30 mix of UDP and TCP, with IMIX packet sizes, and had rules for threat prevention and IPS enabled on the relevant traffic profiles.
The results were… okay, but not what I hoped for. With all the security services turned on, throughput dropped to around 650-700 Mbps. The CPU was consistently maxed out. For just plain routing with basic firewall rules, it did hit line rate.
This has me nervous. Our branches sometimes see bursts close to a gigabit. Has anyone else run similar tests? Is a 30-35% performance hit with full protection normal for this tier? I’m trying to figure out if I misconfigured something or if we need to look at a more powerful model for a realistic safety margin.
One step at a time