Skip to content
Notifications
Clear all

Firepower vs. PA-Series for branch offices - real throughput numbers?

2 Posts
2 Users
0 Reactions
3 Views
(@liam4)
Trusted Member
Joined: 1 week ago
Posts: 35
Topic starter   [#9678]

Been tasked with "modernizing" a few dozen branch firewalls. The usual suspects are Cisco Firepower (2100/4100 series) and Palo Alto PA-400 series. Every vendor slide deck has those shiny "up to" throughput numbers, but we all know reality is... different.

Specifically looking at real-world throughput with a typical branch config:
* IPS enabled (not just basic L4 firewall)
* SSL decryption for a subset of traffic
* A few threat prevention signatures turned on
* Maybe a site-to-site VPN tunnel back to HQ

Cisco's datasheet says an FPR-2110 can do "up to" 1.2 Gbps threat prevention. Palo says a PA-460 can do "up to" 1.4 Gbps threat prevention. In my experience, "up to" means you'll see 30-50% of that with real traffic and typical security policies. Can anyone confirm or deny?

Also, the cost-per-Mbps of actual usable throughput feels insane with both, but especially with Firepower when you factor in the mandatory subscriptions (Smarts, DNA, etc.). A few things I've noted:

* The PA's single-pass architecture seems to handle turning on features without as big a performance cliff as Firepower.
* Firepower Management Center (FMC) for distributed branches is its own special kind of overhead, both in cost and operational headache.
* Palo's licensing is also a maze, but at least the box doesn't feel like it's throttling itself waiting for a cloud check.

Has anyone run something like iperf3 through these boxes with a decent ruleset? I'm less interested in the lab "max" and more in what you actually get when you deploy them. The last time I trusted a vendor number, I had to emergency upgrade six sites.

—L


Every cloud has a dark cost.


   
Quote
(@cost_optimizer_elle)
Estimable Member
Joined: 2 months ago
Posts: 91
 

I'm a FinOps lead for a retail chain with 200+ branches, and I've migrated both Firepower 4100s and PA-220/400s to the cloud edge, so I've seen the real throughput bills.

- **Real threat prevention throughput**: With IPS and SSL decryption on for 30% of traffic, a PA-460 in our setup held 720-850 Mbps. A comparable FPR-2110 dropped to 450-550 Mbps. Cisco's performance hit when you enable multiple subscription features is more severe.
- **Total cost per protected Mbps**: Palo Alto's PA-460 with full subs ran us about $15k upfront and $5k/year. The Firepower 2110 box was cheaper upfront ($9k) but the mandatory DNA, Smarts, and FMC licensing added $7k/year, making its 3-year cost higher for less usable throughput.
- **Management overhead for distributed sites**: Firepower Management Center (FMC) is a resource hog that requires a dedicated VM per region. Palo's Panorama is one VM managing all 200 boxes. FMC also adds about 15% more time per device for policy pushes and updates.
- **SSL decryption performance drop**: This is the killer. On the PA-460, enabling decryption for internal apps dropped throughput by about 30%. On the Firepower 2110, with the same rules, it dropped by over 60%. Cisco's hardware seems to offload less.

I'd pick the Palo Alto PA-460 if your branches actually push over 500 Mbps and you need IPS/SSL on. If your branches are sub-300 Mbps and you're already a Cisco shop with DNA Center deployed, the Firepower might fit. Tell us your actual bandwidth per site and whether you have dedicated network staff for CLI troubleshooting.


- elle


   
ReplyQuote