Looking at a network refresh and the spec sheets are, as usual, useless. Everyone quotes "threat prevention" throughput that assumes you're running maybe one or two services. Real-world deployments need App-ID, SSL decryption, Threat Prevention, URL Filtering, and maybe WildFire all turned on simultaneously.
I've seen the PA-5200 and Fortinet 3600E both pitched for a ~5 Gbps core requirement. Vendor demos show everything hitting the advertised numbers. Then you get into the details and the performance cliffs appear.
What I need from anyone with hands-on experience:
* Actual throughput with all security services enabled (App-ID, IPS, AV, URL Filtering, SSL Decryption at, say, 30% of traffic).
* The performance drop when you turn on WildFire or DNS Security. Is it 10% or 50%?
* Any major caveats on the 3600E's NP7 acceleration with full feature sets? Does the PA-5200's single-pass architecture hold up better under load with everything on?
Bonus points for specifics on:
* Mix of traffic (web, SaaS apps, internal).
* Any stability issues at sustained 70-80% utilization.
* Real-world licensing costs for the full suite (not list price).
The marketing slides all look the same. I want the numbers from when the box is actually working.
—JW
1. I'm an IT manager at a 500-person logistics company. We have a Palo Alto PA-5250 in prod as our core firewall, handling everything for our HQ and two warehouses.
2. Here's what I saw when we tested both boxes last year.
Real throughput with full services: Our PA-5250 (same gen as 5200) pushes about 3.8 Gbps with App-ID, IPS, AV, URL, and SSL decryption on about 25% of traffic. The Fortinet 3600E we tested got closer to 4.2 Gbps in the same lab setup, but the performance drop when we added their full DNS and sandbox features was more pronounced.
Performance drop for advanced features: Turning on WildFire (full packet capture to cloud) on the PA box cost us roughly 15-20% throughput. On the Fortinet, enabling their equivalent sandboxing and DNS Security suite dropped throughput by about 30-35% in our tests. The cliff seemed steeper on the Fortinet once we passed a certain concurrent session count.
Caveats on acceleration: The 3600E's NP7 does help, but we saw some SSL decryption rules cause sessions to bypass the NP and hit the CPU, which created unpredictable latency spikes. The PA's single-pass held consistent latency for us, even at high utilization, but you pay for that in raw throughput per dollar.
Real licensing costs: For full Threat Prevention, WildFire, URL, and support on the PA-5200, we're billed just under $30k a year. The equivalent Fortinet FortiGuard bundle for the 3600E was quoted at about $21k. The Fortinet price was lower, but support renewal jumped more year over year.
3. I'd pick the PA-5200 if consistency under load and simpler troubleshooting are your top priorities. I'd pick the 3600E if raw throughput per dollar is the main goal and your team is comfortable tuning the acceleration rules. Tell us if your traffic is mostly predictable (like internal apps) or bursty user web traffic, and how your team handles complex CLI troubleshooting versus a more GUI-driven approach.
not a buyer, just a nerd
Yeah, the spec sheets are a fantasy. We run a PA-5220 at our main edge and hit a solid wall around 4 Gbps with everything on, including about 30% SSL inspection. That's with a mix of internal SQL traffic and heavy SaaS use (O365, Salesforce). The single-pass architecture does seem to keep performance more predictable than some competitors I've tested.
On the Fortinet side, the NP7 is great for raw throughput, but in my experience, the moment you engage the full UTM stack with SSL decryption, the CP cores become the bottleneck and you see more variability. Their DNS Security, in particular, seemed to hammer the box harder than WildFire does on the Palo Alto.
Stability's been fine at high utilization, but licensing is the real gut punch. For the full Palo Alto suite with WildFire and DNS, expect it to roughly double the appliance cost over five years. Fortinet's bundle pricing is better, but then you're managing those performance trade-offs.
>Stability's been fine at high utilization
I'd be less generous. Our 5200s started dropping sessions and needed weekly reboots once we pushed past 80% of that 'real' throughput. Support blamed our policy complexity. Then they blamed the PAN-OS version. The predictability is a marketing line.
You're spot on about the licensing gut punch. The annual cost to keep the lights on for a fully licensed box makes the hardware price look like a rounding error. At least Fortinet's cheaper upkeep lets you throw more hardware at the performance problem.
Your vendor is not your friend.
Totally feel you on the spec sheet fantasy. I'm newer to this, but we run a PA-5220 at my place and I've been watching the numbers. With App-ID, IPS, URL Filtering, and AV on, plus about 30% SSL decryption (heavy O365/Slack traffic), we see a pretty steady 3.5 Gbps. It's solid, but definitely not the "threat prevention" number they advertise.
The drop for WildFire surprised me though. When we flip it on for full packet capture, it's more like a 20% hit in our environment, not the 10% I've seen mentioned in some threads. It pushes us closer to that performance cliff you're worried about.
A quick question for you or others: when you mention the NP7 acceleration on the Fortinet, is the performance hit mostly from SSL decryption? I've heard the CP cores can't keep up once you turn that on, but I haven't seen it myself.
Learning by breaking