The prospective customer has provided precise performance requirements for their firewall purchase, and the systems engineer must recommend a suitable Palo Alto Networks Strata Hardware Firewall (e.g., PA-Series) model. The requirements include a minimum of 200,000 connections per second (CPS) and 15 Gbps of throughput with App-ID and Threat Prevention enabled. Let’s evaluate the best approach to meet these needs.
Step 1: Understand the Requirements
Connections per Second (CPS): 200,000 new sessions per second, indicating the firewall’s ability to handle high transaction rates (e.g., web traffic, API calls).
Throughput with App-ID and Threat Prevention: 15 Gbps, measured with applicationidentification and threat prevention features active, reflecting real-world NGFW performance.
Goal: Identify a PA-Series model that meets or exceeds these specs while considering the customer’s actual traffic profile for optimal sizing.
[Reference:PA-Series Hardware Datasheets(www.paloaltonetworks.com/resources/datasheets/pa-series)., Step 2: Define Firewall Sizing Needs, Sizing a firewall requires aligning hardware capabilities (CPS, throughput, max sessions) with the customer’s traffic demands., Palo Alto Networks provides tools and datasheets:, Datasheets: List specs like “New sessions per second†and “Threat Prevention throughput†(e.g., PA-5220: 270,000 CPS, 18 Gbps Threat Prevention)., Tools: Offer detailed sizing based on traffic logs or manual inputs., The customer’s requirements are specific, but real-world traffic patterns (e.g., session duration, app mix) impact performance, necessitating a data-driven approach., Step 3: Evaluate Each Option, A. Upload 30 days of customer firewall traffic logs to the firewall calculator tool on the Palo Alto Networks support portal., Description: The Firewall Throughput Calculator (or similar tool) on the Palo Alto Networks Customer Support Portal (support.paloaltonetworks.com) allows users with a valid account to upload traffic logs (e.g., from an existing firewall) for analysis. It assesses throughput, CPS, and session usage over 30 days to recommend a model., Process:, Obtain 30 days of traffic logs from the customer’s current firewall (e.g., CSV export of session data)., Log into the support portal (Support > Tools)., Upload logs to the calculator tool., Review the output, which matches the customer’s traffic profile against PA-Series specs, ensuring 200,000 CPS and 15 Gbps are met with App-ID and Threat Prevention., Benefits:, Uses real traffic data for precise sizing., Accounts for app mix, session behavior, and peak loads beyond raw minimums., Validates against NGFW-specific metrics (e.g., Threat Prevention throughput)., Fit: Ideal, as it provides a tailored recommendation based on empirical data., Reference: Palo Alto Networks Support Portal tools (support.paloaltonetworks.com, requires login; tool availability confirmed via partner and SE resources)., B. Download the firewall sizing tool from the Palo Alto Networks support portal., Description: A downloadable sizing tool (if available) would allow offline analysis of traffic data or manual input of requirements. However, no such standalone downloadable tool is widely documented for public access on the support portal as of PAN-OS 10.2 or prior versions., Analysis:, The support portal offers web-based tools (e.g., Firewall Throughput Calculator), but downloadable tools are typically partner-specific (e.g., “Popsicle†on NextWave Partner Portal) or internal SE tools, not customer-facing., Manual input of 200,000 CPS and 15 Gbps is possible, but lacks traffic context., Limitations: Without traffic logs, it’s less accurate than A; availability is unconfirmed for customers., Fit: Less effective and potentially unavailable to non-partners., C. Use the online product configurator tool provided on the Palo Alto Networks website., Description: The Palo Alto Networks website (www.paloaltonetworks.com) may offer a product configurator for building hardware bundles (e.g., firewall + subscriptions), not sizing based on performance metrics., Analysis:, Configurators focus on quoting or specifying hardware options, not performance analysis., Cannot input CPS or throughput requirements or analyze traffic logs., Fit: Incorrect, as it’s for purchasing, not sizing., Reference:Palo Alto Networks Website(www.paloaltonetworks.com/products)., D. Use the product selector tool available on the Palo Alto Networks website., Description: The Product Selector tool (www.paloaltonetworks.com/network-security/firewalls/product-selection) lets users filter PA-Series models by features (e.g., throughput range, ports)., Process:, Visit the product selection page., Filter by throughput (e.g., >10 Gbps) and review CPS in datasheets., Compare manually (e.g., PA-5220: 18 Gbps, 270,000 CPS)., Limitations:, Static comparison, no traffic log analysis., Requires manual cross-referencing with datasheets, risking oversights (e.g., session mix impact)., Fit: Useful for initial research but insufficient for precise sizing., Reference:PA-Series Product Selection(www.paloaltonetworks.com/network-security/firewalls/product-selection)., Step 4: Select the Best Approach, A is the most suitable:, Accuracy: Analyzes 30 days of real traffic, ensuring the model meets 200,000 CPS and 15 Gbps under customer-specific conditions., NGFW-Specific: Accounts for App-ID and Threat Prevention overhead, critical for realistic sizing., Efficiency: Leverages an official tool designed for this purpose, accessible via the support portal (requires customer registration)., Why not B, C, or D?, B: No confirmed downloadable customer tool; less precise without logs., C: Configurator is for purchasing, not performance sizing., D: Product selector lacks traffic analysis, relying on manual datasheet checks., Step 5: Verification with Palo Alto Resources, Firewall Calculator Tool: Referenced in partner discussions (e.g., LIVEcommunity) and SE workflows for log-based sizing, available on the support portal., PA-Series Specs: Models like PA-5220 (270,000 CPS, 18 Gbps Threat Prevention) or PA-3250 (210,000 CPS, 6.3 Gbps) can be validated, but logs ensure the right fit (PA-Series Datasheets)., Other Tools: Product selector and configurator are public but lack sizing depth (Palo Alto Website)., , , ]