Firewalls in India — NGFW Sizing, Real Throughput and How to Choose

  • Home
  • Firewalls in India — NGFW Sizing, Real Throughput and How to Choose
Firewalls in India — NGFW Sizing, Real Throughput and How to Choose
Firewalls in India — NGFW Sizing, Real Throughput and How to Choose
Firewalls in India — NGFW Sizing, Real Throughput and How to Choose
Firewalls in India — NGFW Sizing, Real Throughput and How to Choose

A buyer’s guide · Operating since 2002

FirewallsWhat the throughput numbers actually mean, how to size properly, and how to compare vendors

The most expensive mistake in firewall buying is not choosing the wrong brand. It is sizing the appliance from the largest number on the datasheet, enabling the inspection you bought it for, and discovering the box cannot carry your traffic with those features on.

This page is about avoiding that. What the five published throughput figures mean, how to size against the traffic you will actually inspect, where NGFW and UTM genuinely differ, and the questions that make a quote comparable.

Our bias, stated up front. We are a Fortinet partner. That shapes what we deploy most and it should shape how you read the vendor section below. A comparison page written by a partner pretending to neutrality is worth nothing — so ours discloses instead, and we would rather talk about what your team can operate than argue a feature chart.
3K+
Projects delivered
1,000+
Enterprises protected
50+
In-house NOC & SOC engineers
24+
Years, since 2002
ISO/IEC 27001:2022
Certified — SOC in scope

The number

Why the throughput on the datasheet is not what you get

Every vendor publishes five throughput figures for the same appliance. They descend, often steeply, and only the first one tends to reach a proposal.

Every one of these is on your vendor’s datasheetThe same appliance. Five different numbers.Firewall throughputpacket forwarding, inspection offIPS throughputintrusion prevention enabledNGFW throughputIPS plus application controlThreat protectionplus antivirus and filteringWith TLS inspectiondecrypting the traffic that mattersquoted in the proposalcloser to what you will actually run,once you inspect the encrypted trafficBar lengths show the pattern, not your model’s figures. Read your own datasheet — all five are on it.Sizing from the top number is the most expensive mistake in firewall buying.

Nothing is being hidden

All five numbers are printed on the datasheet. The headline is measured with inspection disabled, on a traffic profile chosen to produce the largest figure — commonly large-packet UDP, which no real network carries.

Vendors also publish figures for mixed profiles such as IMIX and APPMIX, which resemble real traffic far more closely and produce far lower numbers. That buyers now search for those terms by name tells you the industry has worked this out.

What to do about it

Read the datasheet yourself before the meeting. It is the highest-value ten minutes in the whole purchase, and it converts a sales conversation into a technical one immediately.

Then size against the row that matches the features you actually intend to run — which, if you plan to inspect encrypted traffic, is the bottom one. Undersizing is not a performance problem you can tune your way out of. It is an unplanned capital purchase in year two.

Sizing

Six things to size against

In this order. Step two is the one that changes the answer most, and step three is the one that produces the fault nobody can diagnose.

Rule bases grow. The rules that matter do not.Illustrative of a pattern, not measured from one estate.yr 0yr 1yr 2yr 3yr 4yr 5Total rulesRules still matching trafficthe gap isdead permitsRemoving a rule is how you cause an outage, so nobody does — which is exactly why it needs a scheduled review.

Illustrative of a pattern rather than measured from one estate — but the widening gap is real, and it is why a rule review belongs on a schedule rather than in a project.

Step 1

Start from the traffic you inspect, not the link you bought

A one-gigabit internet circuit does not need a one-gigabit firewall — it needs one that can inspect a gigabit with the features you intend to run. Those are very different numbers on the same datasheet.

Step 2

Assume TLS inspection, or decide not to and say why

The overwhelming majority of traffic is encrypted. A firewall not decrypting is inspecting the envelope. Decrypting is the most expensive thing you can ask it to do, and it must be in the sizing from the start rather than enabled later on a box that cannot take it.

Step 3

Size for concurrent sessions, not just bandwidth

Session table exhaustion produces a firewall that is not saturated on any bandwidth graph and is nonetheless dropping connections. It is a miserable fault to diagnose and it is a specification you can check before buying.

Step 4

Add headroom for what the business will do next

Three to five years of growth, plus the VPN concentration or SD-WAN role the box may be asked to take on. Undersizing is not a performance problem; it is an unplanned capital purchase in year two.

Step 5

Check the interface count and type, not just the throughput

Enough ports of the right speed, and the right transceivers. This is dull and it is the most common reason a delivery cannot be racked on the planned day.

Step 6

Plan high availability from the start

An active-passive pair is roughly double the hardware and considerably less than double the pain. Retrofitting HA means a maintenance window and a reconfiguration on a device already carrying production.

Session table exhaustion deserves its own mention: a firewall that has run out of session capacity is dropping connections while every bandwidth graph looks healthy. It is a genuinely miserable fault to trace, and it is a specification you can simply check before buying.

The categories

NGFW, UTM, stateful, cloud — what actually differs

Five things quoted against each other, two of which have largely merged. The last column is the part the comparison chart leaves out.

Scroll the table sideways →

Category What it is What it does well The honest limitation
Next-generation firewallNGFW Stateful firewalling plus application awareness, user identity and integrated intrusion prevention. The default enterprise choice. Policy can be written about applications and people rather than ports and addresses. Every feature you enable costs throughput. The headline number on the datasheet has all of them switched off.
UTMunified threat management Historically the same idea packaged for smaller organisations — firewall, antivirus, web filtering, VPN in one box. Simple to buy and run. Genuinely enough for many small sites. The distinction from NGFW has largely dissolved — the same vendors ship the same code. Treat it as a licensing and sizing tier, not an architecture.
Traditional stateful firewall Port and protocol filtering with connection tracking, no application awareness. Fast, predictable, cheap. Still correct deep inside a network where the traffic is known. Cannot distinguish two applications sharing a port, which today is most of them. Not sufficient at an internet edge.
Cloud firewall / FWaaS Inspection delivered as a service rather than as an appliance you rack. No hardware refresh, scales without a forklift, follows users off the network. You are buying someone else’s capacity planning. Assess egress costs and what happens to policy if you leave.
Host and cloud-native controls Security groups, host firewalls, Kubernetes network policy. The only thing that segments workloads that never cross a physical boundary. Not a substitute for an edge device, and configuration lives with whoever owns the workload — which is how it drifts.

On UTM versus NGFW specifically: the same vendors ship the same code to both segments. The distinction survives in licensing tiers and form factors rather than in architecture, so treat it as a sizing and packaging question and move on to the numbers.

Straight answers

What buyers get wrong about firewalls

Fact

The datasheet publishes five throughput numbers

Firewall throughput, IPS throughput, NGFW throughput, threat protection throughput, and throughput with TLS inspection enabled. They descend, often steeply. The first is measured with inspection off on an ideal packet profile, and it is the one that reaches proposals. Every vendor publishes all five, which is why reading the datasheet yourself is the highest-value ten minutes in a firewall purchase.

Ask

“What traffic profile is that measured on?”

Headline figures are commonly quoted on large-packet UDP. Vendors also publish figures for mixed profiles such as IMIX and APPMIX, which look far more like real traffic and produce far lower numbers. The fact that buyers now search for these terms tells you the industry has noticed.

Fact

Undersizing is a capital problem, not a performance problem

A firewall at capacity is not fixed by tuning. Either you disable the inspection you bought it for, or you buy another one. That is why sizing conservatively at purchase is cheaper than being right about the minimum.

Fact

UTM and NGFW have largely converged

The same vendors ship the same code to both segments. Today the distinction is mostly about licensing tier, form factor and expected throughput rather than architecture. Treat a UTM-versus-NGFW debate as a sizing and licensing question.

Ask

“Are we inspecting encrypted traffic?”

If the answer is no, a large share of what the firewall is meant to catch passes it unread. If yes, it must be in the sizing. Both answers are defensible; only having no answer is not.

Fact

The old rule base is the real migration risk

Most estates carry rules nobody can justify, permitting things nobody uses, written by people who left. Automated conversion carries them faithfully to the new platform. A migration is the rare moment when removing them is politically possible.

Before you sign

Ten questions for any firewall quote

Use these on us and on everyone else. Questions one and two will tell you within a minute whether the quote was sized or merely priced.

Numbers

Which throughput figure is this quote sized against?

Ask which line of the datasheet. If the answer is the headline firewall number and you intend to run inspection, the sizing is wrong before anything is racked.

TLS

Does the sizing assume TLS inspection is on?

Most traffic is encrypted, and decryption is the most expensive function on the box. This single question separates a real sizing exercise from a price.

Sessions

What is the concurrent session limit, and what is ours today?

Bandwidth graphs will not warn you about session exhaustion. Get both numbers before you buy.

Licensing

What is included, what is subscription, and what does year four cost?

Hardware is frequently the smaller number. IPS, antivirus, filtering, sandboxing and support renew, and the renewal is where the real total lives.

Migration

How does the existing rule base move across?

Automated conversion always leaves residue. Ask who reviews the output, and treat a migration as the opportunity to remove the rules nobody has justified in years.

HA

Is high availability in this quote, and has failover been tested?

A pair that has never failed over is a theory. Ask for the test to be part of commissioning, in writing.

Management

Who holds administrative access, and how are changes logged?

Whether managed by you or by a provider, change attribution on a firewall is what makes an incident investigation possible at all.

Support

What is the RMA path and the realistic replacement time at our site?

Advance replacement and next-business-day mean different things in different cities. Ask specifically about your locations, not the national average.

Bias

What do you sell, and what would you recommend if you did not?

Every partner has a preferred vendor, including us. The answer you want is a straight disclosure and a reason, not a claim of neutrality.

Exit

If we change vendor in five years, what is portable?

Rule bases translate imperfectly and operational knowledge does not translate at all. Understanding that cost now makes the renewal conversation an informed one.

Working with us

How we sell and run firewalls

We have deployed and managed enterprise firewall estates since 2002, and we run the operations centre that watches them afterwards. Being the people who get called at 3 a.m. changes how we size things at the quotation stage.

Sized against inspection

We quote against the throughput row matching the features you will run, and we will tell you which row that is. If the honest answer is a larger model, we would rather say so now.

Five-year total, not a price

Subscriptions and support renew and commonly exceed the appliance across a lifecycle. You get the whole number up front.

Rule-base review at migration

Conversion tools carry every unjustifiable rule across faithfully. Migration is the one moment removing them is politically possible, and we use it.

Multi-vendor estates

Fortinet primarily, and we manage Cisco, Palo Alto and Sophos alongside it — see technology partners.

HA tested at commissioning

A pair that has never failed over is a theory. The test is part of handover, in writing.

Buy, rent or managed

Purchase, rental or fully managed — and we will say which suits your cash flow rather than which suits ours.

3K+
Projects delivered
1,000+
Enterprises protected
50+
In-house NOC & SOC engineers
24+
Years, since 2002
ISO/IEC 27001:2022
Certified — SOC in scope

Questions we get asked

Firewalls, answered

What is a next-generation firewall?

An NGFW adds application awareness, user identity and integrated intrusion prevention to traditional stateful filtering. The practical difference is what a policy can say: instead of permitting a port, you permit an application to a group of people, which is the only workable approach now that most applications share the same handful of ports. Every major enterprise firewall sold today is an NGFW.

What is the difference between UTM and NGFW?

Historically UTM meant an all-in-one appliance for smaller organisations and NGFW meant the enterprise product. That distinction has largely dissolved — the same vendors ship the same code across both, and the differences are now licensing tier, form factor and expected throughput. Treat it as a sizing and packaging question rather than an architectural one, and ignore anyone presenting it as a fundamental choice.

How do I size a firewall properly?

Start from the traffic you intend to inspect and the features you intend to run, not from the speed of your internet circuit. Assume TLS inspection unless you have consciously decided against it. Check concurrent session capacity as well as bandwidth. Add three to five years of growth plus any VPN or SD-WAN role the device may take on. Then verify interface count and speeds. The sizing section above walks through each of those in order.

Why is the throughput on the datasheet not what I get?

Because the headline figure is measured with inspection disabled, on a traffic profile chosen to produce the largest number. The same datasheet also publishes IPS throughput, NGFW throughput, threat protection throughput and throughput with TLS inspection enabled, and those descend steeply. Nothing is being hidden — all five are printed. The problem is that only the first reaches the proposal.

What are IMIX and APPMIX?

Traffic profiles used for benchmarking. Rather than measuring with uniform large packets, which flatters any device, they use a mix of packet sizes and application types that resembles real network traffic more closely. Figures measured on these profiles are lower and considerably more useful for sizing. If a vendor publishes them, use them; if they do not, ask why.

Do we need TLS inspection?

It is a genuine decision with costs on both sides. Without it, the majority of traffic is inspected only at the envelope, so a large share of what the firewall exists to catch passes unread. With it, throughput falls sharply, some applications break on certificate pinning and must be excluded, and there are privacy and legal considerations to work through. What is not defensible is having no position — or deciding to enable it later on hardware sized as though you never would.

Fortinet or Palo Alto — which is better?

We are a Fortinet partner, so treat our answer with that in mind. Both are capable enterprise platforms and either will serve a competent team well. The honest differentiators are rarely the feature matrix: they are what your team already knows, what the local support and replacement path actually looks like in your cities, how the licensing behaves at renewal, and whether you want the firewall to also carry SD-WAN or switching in a single fabric. We would rather talk about those than argue a comparison chart.

What does a firewall cost in India?

Hardware is frequently the smaller part. Subscriptions for intrusion prevention, antivirus, web filtering and sandboxing renew annually, as does support, and across a typical five-year life the recurring cost commonly exceeds the appliance. Ask for the five-year total including renewals rather than the purchase price, and compare quotes on the same feature set — two quotes with different subscription bundles are not comparable numbers.

What is the best firewall for a small business?

An entry-level model from any major vendor, sized for the traffic you will actually inspect rather than for your circuit speed, with the subscription bundle you will genuinely use. The most common small-business mistake is not buying the wrong brand — it is buying a box sized on the headline figure, enabling inspection, and discovering it cannot cope. Our FortiGate entry-level guide covers that segment specifically.

Should we buy or rent?

Renting suits organisations that want the capability without the capital outlay, or that expect requirements to change before a refresh cycle completes. Buying is usually cheaper across a full lifecycle if requirements are stable. It is a cash-flow and flexibility decision rather than a technical one — see firewall on rent.

How does a firewall migration work?

The rule base is the risk, not the hardware. Automated conversion tools carry your existing policy across faithfully, including every rule nobody can justify, permitting things nobody uses, written by people who have left. The valuable part of a migration is the review that removes them — and a migration is the rare moment when that is politically possible. Expect a parallel run and a rollback plan for cutover.

Do you manage firewalls after deployment?

Yes — policy changes, subscription and firmware lifecycle, rule-base review and monitoring, across multi-vendor estates rather than only the ones we sell. That is covered on firewall services, and the monitoring side connects to our operations centre.

What about high availability?

Plan it at purchase. An active-passive pair roughly doubles the hardware cost and removes a single point of failure sitting directly in the path of everything. Retrofitting it later means a maintenance window and reconfiguration on a device already carrying production traffic, which is a far worse afternoon than specifying it correctly at the start.

Which vendors do you work with?

Fortinet primarily — we are a partner and say so — along with Cisco, Palo Alto Networks and Sophos, and we manage mixed estates containing all of them. See technology partners. If your team already runs one platform well, that is usually a stronger argument than any feature comparison.

Next step

Send us your circuit speed and what you want inspected

Your internet bandwidth, rough user and site counts, whether you intend to inspect encrypted traffic, and any VPN or SD-WAN role the device should take on. We will size it against the right row of the datasheet, quote the five-year total including renewals, and tell you plainly if a smaller model would do.

sanjay@azure-spider-636418.hostingersite.com