A buyer’s guide · Operating since 2002
The most expensive mistake in firewall buying is not choosing the wrong brand. It is sizing the appliance from the largest number on the datasheet, enabling the inspection you bought it for, and discovering the box cannot carry your traffic with those features on.
This page is about avoiding that. What the five published throughput figures mean, how to size against the traffic you will actually inspect, where NGFW and UTM genuinely differ, and the questions that make a quote comparable.
The number
Why the throughput on the datasheet is not what you get
Every vendor publishes five throughput figures for the same appliance. They descend, often steeply, and only the first one tends to reach a proposal.
Nothing is being hidden
All five numbers are printed on the datasheet. The headline is measured with inspection disabled, on a traffic profile chosen to produce the largest figure — commonly large-packet UDP, which no real network carries.
Vendors also publish figures for mixed profiles such as IMIX and APPMIX, which resemble real traffic far more closely and produce far lower numbers. That buyers now search for those terms by name tells you the industry has worked this out.
What to do about it
Read the datasheet yourself before the meeting. It is the highest-value ten minutes in the whole purchase, and it converts a sales conversation into a technical one immediately.
Then size against the row that matches the features you actually intend to run — which, if you plan to inspect encrypted traffic, is the bottom one. Undersizing is not a performance problem you can tune your way out of. It is an unplanned capital purchase in year two.
Sizing
Six things to size against
In this order. Step two is the one that changes the answer most, and step three is the one that produces the fault nobody can diagnose.
Illustrative of a pattern rather than measured from one estate — but the widening gap is real, and it is why a rule review belongs on a schedule rather than in a project.
Start from the traffic you inspect, not the link you bought
A one-gigabit internet circuit does not need a one-gigabit firewall — it needs one that can inspect a gigabit with the features you intend to run. Those are very different numbers on the same datasheet.
Assume TLS inspection, or decide not to and say why
The overwhelming majority of traffic is encrypted. A firewall not decrypting is inspecting the envelope. Decrypting is the most expensive thing you can ask it to do, and it must be in the sizing from the start rather than enabled later on a box that cannot take it.
Size for concurrent sessions, not just bandwidth
Session table exhaustion produces a firewall that is not saturated on any bandwidth graph and is nonetheless dropping connections. It is a miserable fault to diagnose and it is a specification you can check before buying.
Add headroom for what the business will do next
Three to five years of growth, plus the VPN concentration or SD-WAN role the box may be asked to take on. Undersizing is not a performance problem; it is an unplanned capital purchase in year two.
Check the interface count and type, not just the throughput
Enough ports of the right speed, and the right transceivers. This is dull and it is the most common reason a delivery cannot be racked on the planned day.
Plan high availability from the start
An active-passive pair is roughly double the hardware and considerably less than double the pain. Retrofitting HA means a maintenance window and a reconfiguration on a device already carrying production.
Session table exhaustion deserves its own mention: a firewall that has run out of session capacity is dropping connections while every bandwidth graph looks healthy. It is a genuinely miserable fault to trace, and it is a specification you can simply check before buying.
The categories
NGFW, UTM, stateful, cloud — what actually differs
Five things quoted against each other, two of which have largely merged. The last column is the part the comparison chart leaves out.
Scroll the table sideways →
| Category | What it is | What it does well | The honest limitation |
|---|---|---|---|
| Next-generation firewallNGFW | Stateful firewalling plus application awareness, user identity and integrated intrusion prevention. | The default enterprise choice. Policy can be written about applications and people rather than ports and addresses. | Every feature you enable costs throughput. The headline number on the datasheet has all of them switched off. |
| UTMunified threat management | Historically the same idea packaged for smaller organisations — firewall, antivirus, web filtering, VPN in one box. | Simple to buy and run. Genuinely enough for many small sites. | The distinction from NGFW has largely dissolved — the same vendors ship the same code. Treat it as a licensing and sizing tier, not an architecture. |
| Traditional stateful firewall | Port and protocol filtering with connection tracking, no application awareness. | Fast, predictable, cheap. Still correct deep inside a network where the traffic is known. | Cannot distinguish two applications sharing a port, which today is most of them. Not sufficient at an internet edge. |
| Cloud firewall / FWaaS | Inspection delivered as a service rather than as an appliance you rack. | No hardware refresh, scales without a forklift, follows users off the network. | You are buying someone else’s capacity planning. Assess egress costs and what happens to policy if you leave. |
| Host and cloud-native controls | Security groups, host firewalls, Kubernetes network policy. | The only thing that segments workloads that never cross a physical boundary. | Not a substitute for an edge device, and configuration lives with whoever owns the workload — which is how it drifts. |
On UTM versus NGFW specifically: the same vendors ship the same code to both segments. The distinction survives in licensing tiers and form factors rather than in architecture, so treat it as a sizing and packaging question and move on to the numbers.
Straight answers
What buyers get wrong about firewalls
The datasheet publishes five throughput numbers
Firewall throughput, IPS throughput, NGFW throughput, threat protection throughput, and throughput with TLS inspection enabled. They descend, often steeply. The first is measured with inspection off on an ideal packet profile, and it is the one that reaches proposals. Every vendor publishes all five, which is why reading the datasheet yourself is the highest-value ten minutes in a firewall purchase.
“What traffic profile is that measured on?”
Headline figures are commonly quoted on large-packet UDP. Vendors also publish figures for mixed profiles such as IMIX and APPMIX, which look far more like real traffic and produce far lower numbers. The fact that buyers now search for these terms tells you the industry has noticed.
Undersizing is a capital problem, not a performance problem
A firewall at capacity is not fixed by tuning. Either you disable the inspection you bought it for, or you buy another one. That is why sizing conservatively at purchase is cheaper than being right about the minimum.
UTM and NGFW have largely converged
The same vendors ship the same code to both segments. Today the distinction is mostly about licensing tier, form factor and expected throughput rather than architecture. Treat a UTM-versus-NGFW debate as a sizing and licensing question.
“Are we inspecting encrypted traffic?”
If the answer is no, a large share of what the firewall is meant to catch passes it unread. If yes, it must be in the sizing. Both answers are defensible; only having no answer is not.
The old rule base is the real migration risk
Most estates carry rules nobody can justify, permitting things nobody uses, written by people who left. Automated conversion carries them faithfully to the new platform. A migration is the rare moment when removing them is politically possible.
Before you sign
Ten questions for any firewall quote
Use these on us and on everyone else. Questions one and two will tell you within a minute whether the quote was sized or merely priced.
Which throughput figure is this quote sized against?
Ask which line of the datasheet. If the answer is the headline firewall number and you intend to run inspection, the sizing is wrong before anything is racked.
Does the sizing assume TLS inspection is on?
Most traffic is encrypted, and decryption is the most expensive function on the box. This single question separates a real sizing exercise from a price.
What is the concurrent session limit, and what is ours today?
Bandwidth graphs will not warn you about session exhaustion. Get both numbers before you buy.
What is included, what is subscription, and what does year four cost?
Hardware is frequently the smaller number. IPS, antivirus, filtering, sandboxing and support renew, and the renewal is where the real total lives.
How does the existing rule base move across?
Automated conversion always leaves residue. Ask who reviews the output, and treat a migration as the opportunity to remove the rules nobody has justified in years.
Is high availability in this quote, and has failover been tested?
A pair that has never failed over is a theory. Ask for the test to be part of commissioning, in writing.
Who holds administrative access, and how are changes logged?
Whether managed by you or by a provider, change attribution on a firewall is what makes an incident investigation possible at all.
What is the RMA path and the realistic replacement time at our site?
Advance replacement and next-business-day mean different things in different cities. Ask specifically about your locations, not the national average.
What do you sell, and what would you recommend if you did not?
Every partner has a preferred vendor, including us. The answer you want is a straight disclosure and a reason, not a claim of neutrality.
If we change vendor in five years, what is portable?
Rule bases translate imperfectly and operational knowledge does not translate at all. Understanding that cost now makes the renewal conversation an informed one.
Working with us
How we sell and run firewalls
We have deployed and managed enterprise firewall estates since 2002, and we run the operations centre that watches them afterwards. Being the people who get called at 3 a.m. changes how we size things at the quotation stage.
Sized against inspection
We quote against the throughput row matching the features you will run, and we will tell you which row that is. If the honest answer is a larger model, we would rather say so now.
Five-year total, not a price
Subscriptions and support renew and commonly exceed the appliance across a lifecycle. You get the whole number up front.
Rule-base review at migration
Conversion tools carry every unjustifiable rule across faithfully. Migration is the one moment removing them is politically possible, and we use it.
Multi-vendor estates
Fortinet primarily, and we manage Cisco, Palo Alto and Sophos alongside it — see technology partners.
HA tested at commissioning
A pair that has never failed over is a theory. The test is part of handover, in writing.
Questions we get asked
Firewalls, answered
What is a next-generation firewall?
An NGFW adds application awareness, user identity and integrated intrusion prevention to traditional stateful filtering. The practical difference is what a policy can say: instead of permitting a port, you permit an application to a group of people, which is the only workable approach now that most applications share the same handful of ports. Every major enterprise firewall sold today is an NGFW.
What is the difference between UTM and NGFW?
Historically UTM meant an all-in-one appliance for smaller organisations and NGFW meant the enterprise product. That distinction has largely dissolved — the same vendors ship the same code across both, and the differences are now licensing tier, form factor and expected throughput. Treat it as a sizing and packaging question rather than an architectural one, and ignore anyone presenting it as a fundamental choice.
How do I size a firewall properly?
Start from the traffic you intend to inspect and the features you intend to run, not from the speed of your internet circuit. Assume TLS inspection unless you have consciously decided against it. Check concurrent session capacity as well as bandwidth. Add three to five years of growth plus any VPN or SD-WAN role the device may take on. Then verify interface count and speeds. The sizing section above walks through each of those in order.
Why is the throughput on the datasheet not what I get?
Because the headline figure is measured with inspection disabled, on a traffic profile chosen to produce the largest number. The same datasheet also publishes IPS throughput, NGFW throughput, threat protection throughput and throughput with TLS inspection enabled, and those descend steeply. Nothing is being hidden — all five are printed. The problem is that only the first reaches the proposal.
What are IMIX and APPMIX?
Traffic profiles used for benchmarking. Rather than measuring with uniform large packets, which flatters any device, they use a mix of packet sizes and application types that resembles real network traffic more closely. Figures measured on these profiles are lower and considerably more useful for sizing. If a vendor publishes them, use them; if they do not, ask why.
Do we need TLS inspection?
It is a genuine decision with costs on both sides. Without it, the majority of traffic is inspected only at the envelope, so a large share of what the firewall exists to catch passes unread. With it, throughput falls sharply, some applications break on certificate pinning and must be excluded, and there are privacy and legal considerations to work through. What is not defensible is having no position — or deciding to enable it later on hardware sized as though you never would.
Fortinet or Palo Alto — which is better?
We are a Fortinet partner, so treat our answer with that in mind. Both are capable enterprise platforms and either will serve a competent team well. The honest differentiators are rarely the feature matrix: they are what your team already knows, what the local support and replacement path actually looks like in your cities, how the licensing behaves at renewal, and whether you want the firewall to also carry SD-WAN or switching in a single fabric. We would rather talk about those than argue a comparison chart.
What does a firewall cost in India?
Hardware is frequently the smaller part. Subscriptions for intrusion prevention, antivirus, web filtering and sandboxing renew annually, as does support, and across a typical five-year life the recurring cost commonly exceeds the appliance. Ask for the five-year total including renewals rather than the purchase price, and compare quotes on the same feature set — two quotes with different subscription bundles are not comparable numbers.
What is the best firewall for a small business?
An entry-level model from any major vendor, sized for the traffic you will actually inspect rather than for your circuit speed, with the subscription bundle you will genuinely use. The most common small-business mistake is not buying the wrong brand — it is buying a box sized on the headline figure, enabling inspection, and discovering it cannot cope. Our FortiGate entry-level guide covers that segment specifically.
Should we buy or rent?
Renting suits organisations that want the capability without the capital outlay, or that expect requirements to change before a refresh cycle completes. Buying is usually cheaper across a full lifecycle if requirements are stable. It is a cash-flow and flexibility decision rather than a technical one — see firewall on rent.
How does a firewall migration work?
The rule base is the risk, not the hardware. Automated conversion tools carry your existing policy across faithfully, including every rule nobody can justify, permitting things nobody uses, written by people who have left. The valuable part of a migration is the review that removes them — and a migration is the rare moment when that is politically possible. Expect a parallel run and a rollback plan for cutover.
Do you manage firewalls after deployment?
Yes — policy changes, subscription and firmware lifecycle, rule-base review and monitoring, across multi-vendor estates rather than only the ones we sell. That is covered on firewall services, and the monitoring side connects to our operations centre.
What about high availability?
Plan it at purchase. An active-passive pair roughly doubles the hardware cost and removes a single point of failure sitting directly in the path of everything. Retrofitting it later means a maintenance window and reconfiguration on a device already carrying production traffic, which is a far worse afternoon than specifying it correctly at the start.
Which vendors do you work with?
Fortinet primarily — we are a partner and say so — along with Cisco, Palo Alto Networks and Sophos, and we manage mixed estates containing all of them. See technology partners. If your team already runs one platform well, that is usually a stronger argument than any feature comparison.
Next step
Send us your circuit speed and what you want inspected
Your internet bandwidth, rough user and site counts, whether you intend to inspect encrypted traffic, and any VPN or SD-WAN role the device should take on. We will size it against the right row of the datasheet, quote the five-year total including renewals, and tell you plainly if a smaller model would do.



