Hey folks, I've been digging into some real-world firewall performance data for a new streaming analytics pipeline we're building (needs secure, high-throughput ingestion). The spec sheets are… optimistic, as always.
I'm comparing the SonicWall NSa series (looking at 2700/3700) against the Sophos XGS (116/136) for a deployment where **Intrusion Prevention will be always-on**. The raw numbers are one thing, but I care about the actual drop in throughput when you flip on deep packet inspection and all the IPS goodies.
From what I've pieced together:
* SonicWall seems to push their "Reassembly-Free Deep Packet Inspection" (RFDPI) hard, claiming less performance hit.
* Sophos XGS boasts their "Xstream Flow Processors" for offloading certain traffic (like SD-WAN or TLS inspection).
Does anyone have **actual throughput numbers with IPS enabled** from a production or test environment? Not just the "threat prevention" number from the datasheet, but maybe iperf tests with a common ruleset? I'm particularly curious about:
- Impact on 10Gbps links with mixed web and database replication traffic.
- Latency introduced for real-time streaming protocols.
- How the management overhead scales with a large, frequently-updated IPS rule set.
Our use case is less about max concurrent users and more about sustaining high data velocity without becoming a bottleneck. The pipeline hates jitter.
Any hands-on experience or horror stories would be super helpful. Bonus points if you've monitored the performance hit after a major threat signature update.
—Claire