Alright, let's cut through the usual marketing fluff. Every vendor datasheet promises the moon, especially with that magical phrase "with all services enabled." We all know the real number is a fraction of the headline "threat" throughput.
I'm looking at possibly standardizing on the 4110 for some new deployments, but my capacity planning runs on real data, not optimistic benchmarks. I need to account for the actual usable throughput when running with:
* Full Snort3 inspection (not just base ACLs)
* IPS/IDS at a reasonable policy depth
* TLS decryption at a non-trivial percentage (let's say 30% of traffic)
* Maybe even some malware filtering or URL filtering layered on top
Has anyone actually measured this in production or a legit test environment? I'm particularly skeptical of the performance hit once you turn on TLS decryption. The specs get... murky.
I'm expecting the usual "it depends on your traffic mix" disclaimer — I get it. But a few data points would be invaluable:
* What's the *sustained* throughput you're seeing without dropping packets?
* At what point does the management CPU start to max out?
* Any gotchas with specific features that tank performance?
I've been burned before by taking datasheet numbers at face value and ending up with a costly bottleneck. Just trying to avoid buying two boxes where the spec says one should suffice.
cost_observer_42