Skip to content
Notifications
Clear all

Which model is best for a 1Gbps fiber connection with full DPI?

2 Posts
2 Users
0 Reactions
2 Views
(@mattk88)
Eminent Member
Joined: 1 week ago
Posts: 16
Topic starter   [#5538]

Hey folks,

Looking to upgrade our office firewall and we've just gotten a symmetric 1Gbps fiber line installed. I'm trying to pick a SonicWall model that can actually handle this throughput with **full Deep Packet Inspection (DPI) and all security services turned on**. I've heard some models claim gigabit but then performance tanks when you enable the good stuff.

Our setup:
- About 75 users, mix of on-site and remote
- Heavy use of cloud apps (O365, G Suite), some VoIP
- A few on-prem servers (file, backup)
- We want to implement SSL decryption for most traffic

I've been eyeing the TZ670 or maybe the NSa 5700, but the spec sheets can be a bit... optimistic. Does anyone have real-world experience with these or another model pushing a full gig with DPI/IPS/AV on? I'm especially curious about:

- Actual throughput numbers with all security services enabled
- Any performance hits with SSL decryption turned on
- How they handle multiple VPN tunnels (we'll have about 10 site-to-site)
- Management overhead – I'm used to CLI for some things, but GUI is fine if it's solid

Bonus points if you've integrated it into a monitoring pipeline. I'd love to pull metrics (SNMP or API) into our Grafana dashboard.

Thanks in advance for any insights or config tips!

mattk


Keep shipping.


   
Quote
(@larryh)
Trusted Member
Joined: 1 week ago
Posts: 42
 

I'm a one-man-IT-department for a 90-person engineering consultancy, migrating us off a fossilized ASA 5505, and I've been beating a SonicWall TZ670 into submission for the last six months on a 1G/300M connection.

Here's the grisly breakdown from the trenches:

1. **Real DPI Throughput:** Forget the marketing "Gigabit" number. With DPI, IPS, AV, and App Control all enabled, my TZ670 pushes about 650-750 Mbps of real traffic before CPU starts whimpering. SSL decryption? That's a tax. Enable it for everything and expect that number to drop by 30-40%. The NSa 5700 has a bigger engine, but it's still not magical - plan for 1.2-1.4 Gbps *max* with everything on, assuming your traffic mix isn't all 64-byte packets.

2. **SSL Decryption Overhead:** It's a config nightmare and a performance hog. You'll need to fiddle endlessly with bypass lists (banking, healthcare, some Microsoft URLs) to avoid breaking things. The CPU cost is real, and you'll see it first in VPN latency and VoIP jitter if you go too broad.

3. **VPN Capacity:** The 10 site-to-site tunnels are fine; that's a checkbox feature. The real limit is concurrent client VPNs. The TZ series gets fussy with more than 25-30 active Global VPN Client or NetExtender users. If your remote crew is all on at once, spring for the NSa.

4. **Management & Monitoring:** The GUI is...adequate. SNMP OIDs are oddly limited for security events. I'm pulling basic interface stats and tunnel status into Grafana via their semi-documented REST API, but it's a weekend project, not turn-key. Forget a CLI for real work; it's GUI or bust.

For your 75-user shop with SSL decryption goals, the TZ670 is the bare minimum and you'll be riding close to its limits. Go with the NSa 5700 if the budget allows - it's the right tool for a gig with all the bells on. If your choice hinges on anything, tell us your actual monthly throughput average and what percentage of traffic you *really* plan to SSL decrypt.



   
ReplyQuote