Skip to content
Notifications
Clear all

What's the real-world throughput difference between NSa 2700 and 3700?

1 Posts
1 Users
0 Reactions
3 Views
(@infra_architect_rebel_alt)
Estimable Member
Joined: 2 months ago
Posts: 142
Topic starter   [#676]

Having just completed yet another firewall "upgrade" project where the actual throughput achieved was roughly half of what was promised on the data sheet, I feel compelled to ask this community for some ground truth. The marketing material for the SonicWall NSa 2700 and 3700 is, like most in this industry, a masterpiece of optimistic specification under ideal laboratory conditions that bear little resemblance to the messy reality of a production network.

So, for those who have deployed these boxes outside of a vendor's slide deck: what is the actual, real-world throughput delta between the NSa 2700 and the 3700 when you turn on the security services you actually need? I'm specifically interested in scenarios with:
* Full Gateway Security Suite (IPS, AV, Anti-Spyware) enabled
* SSL/TLS decryption turned on for at least a portion of traffic
* A mix of traffic profiles—some large file transfers, but plenty of small, chatty application traffic

The spec sheets claim a massive jump. The NSa 2700 lists 2.5 Gbps Threat Prevention throughput, while the 3700 claims 5 Gbps. In my experience, you can usually take those numbers and apply a "real-world tax" of 50-70%. But does the scaling hold? Is the 3700 genuinely capable of moving twice the inspected traffic of the 2700, or are you just paying a premium for a bigger model number and slightly higher connection counts?

I'm particularly skeptical because these mid-range appliances often hit bottlenecks that aren't reflected in the headline throughput number—things like SSL inspection performance, which brings even robust hardware to its knees, or the impact of enabling application control. I've seen setups where the quoted "firewall throughput" is 10 Gbps, but turn on SSL inspection and you're struggling to push 800 Mbps.

If anyone has run comparative tests, or better yet, has monitoring data from a migration from one to the other, I'd love to see the numbers. What were your actual observed throughputs with a real security policy loaded? Did the 3700 justify its cost with tangible performance headroom, or did it just give you a more expensive box that also became the bottleneck?


keep it simple


   
Quote