Skip to content
Notifications
Clear all

Anyone running Cisco firewalls in a data center? Real throughput numbers

3 Posts
3 Users
0 Reactions
2 Views
(@jackson2m)
Estimable Member
Joined: 1 week ago
Posts: 67
Topic starter   [#12332]

Having recently concluded a significant data center firewall refresh project, I was tasked with evaluating several next-generation firewall platforms, with Cisco Firepower being a primary contender due to our existing Cisco network ecosystem. While vendor datasheets provide a starting point, their "maximum" or "theoretical" throughput figures—especially for the critical Threat (NGIPS) and TLS/SSL Decryption inspection metrics—are, in my experience, rarely attainable in production.

My primary question for the community is this: what are your real-world, sustained throughput numbers for Firepower 4100 series (or the newer 9300 appliances) in an active/standby HA pair, with a realistic set of security policies enabled? I am particularly interested in deployments where you have:

* A mix of inbound and outbound internet traffic, including encrypted traffic (TLS 1.2/1.3) with a selective decryption policy applied.
* NGIPS mode enabled with a Cisco-recommended subset of intrusion policies (e.g., Connectivity Over Security, Balanced Security and Connectivity).
* Identity policies (AD integration) for user-based access rules.
* A moderate volume of site-to-site VPN tunnels (IKEv2).

From our own lab testing with a Firepower 4110, we observed a consistent 60-65% throughput degradation when comparing "bare metal" routing to a fully-configured NGFW deployment with the above features active. For example, a stated 4 Gbps Threat throughput quickly became a sustainable 1.5 Gbps under our test load. The performance impact of SSL decryption was the most significant single factor.

I am compiling a comparative matrix that includes:
* Appliance model and software version (FTD)
* Stated datasheet throughput for Threat/IPS
* Measured throughput with your specific feature set
* Any specific performance-limiting configurations (e.g., certain inspection types, geolocation filters, URL filtering categories)
* Hardware expansion modules in use (e.g., network modules, SSD)

This data is crucial for accurate capacity planning and avoiding costly oversizing (or dangerous undersizing). I am happy to share anonymized excerpts from our own test spreadsheet upon request, in exchange for your operational data points.


Data over opinions


   
Quote
(@jenniferm)
Trusted Member
Joined: 1 week ago
Posts: 43
 

Yeah, the datasheet to reality gap is real. We're about a year into a 4100 deployment.

Our numbers are definitely lower than spec, but acceptable for our needs. With NGIPS balanced policy and about 40% TLS decryption, we see sustained throughput around 1.8 Gbps on 4110s. That's with all your conditions - HA, mixed traffic, AD integration. The decryption load hits hard.

Our main pain point isn't raw throughput, it's the management overhead. Tuning policies to avoid false positives without sacrificing security feels like a part-time job. Curious if others see that too, or if we just have a noisy traffic profile.


Learning every day


   
ReplyQuote
(@contrarian_kevin)
Estimable Member
Joined: 1 week ago
Posts: 123
 

Those "Cisco-recommended" policies are the first mistake. They're a generic baseline that assumes your traffic looks like Cisco's lab traffic. It never does.

You're right to question the spec sheets, but you're still letting them frame the test. Real throughput is whatever's left after you finish tuning out the constant false positives and application breaks from NGIPS. The number on the box doesn't matter.

Why are you even considering them if your main reason is the existing ecosystem? That's how you get locked in for another five years of management headaches.


Just saying.


   
ReplyQuote