Sizing a Firewall for a UAE SME Without Overpaying

Firewall datasheets are written to be read optimistically. The headline throughput figure is measured with inspection turned off and large packets, which is not how any office uses a firewall. Size on the inspected figure, and a surprising number of quotations shrink by a model or two.

Here is how to size one honestly for a UAE business.

Read the datasheet in the right order

Vendors publish several throughput numbers for the same box, and they differ by a large factor. Firewall throughput is raw packet forwarding. Threat protection or next generation throughput is the figure with application control, intrusion prevention and antivirus enabled. Inspected HTTPS throughput is lower again, and since nearly all traffic is encrypted now, that is the number closest to your reality.

Read them in reverse order to how they are printed. Start at the bottom of the table, size against the inspected figure, and treat the headline number as marketing.

Work out the load you actually have

Three inputs decide the model.

Circuit speed. A firewall cannot usefully inspect faster than your circuit delivers, but it does need to keep up with it. If you have a 500 Mbps circuit and plan to grow, the inspected throughput should comfortably exceed that.

Concurrent users and sessions. Session count matters more than people. A modern browser opens many connections per page, and video calls, cloud storage sync and messaging all hold sessions open. Small appliances have session ceilings that a busy office reaches sooner than expected.

What the firewall must do besides filter. Remote access VPN for a distributed team, site to site tunnels to other UAE branches, and inspection of encrypted traffic all consume capacity. VPN throughput is a separate line on the datasheet, and on smaller models it is much lower than firewall throughput.

Where money is wasted

  • Buying two sizes up for comfort. Headroom is sensible. Two models of headroom usually pays for features the business will never enable, and the licensing scales with the model.
  • Buying a bundle of subscriptions you will not operate. Sandboxing and advanced modules produce alerts. Alerts nobody reads are a cost with no benefit. Buy what someone will actually act on.
  • Ignoring the renewal. The appliance is the small part of the lifetime cost. Three years of subscriptions often exceeds the hardware. Compare quotations over the full term, not on the box price.
  • Sizing for a headcount that includes everyone in the company. Size for concurrent users in the office, plus remote workers connecting at once.

Where money is saved wrongly

  • Turning inspection off to fix performance. This is common and it quietly removes the reason you bought the device. If performance forces that choice, the appliance was undersized.
  • Running an appliance past end of support. An internet facing device with no more firmware updates is the highest risk item in a small network.
  • Buying grey market to save on the appliance. Firewall value lives in the subscription and the update path, both of which are tied to the serial and the sales channel. A cheap unit with no entitlement is an expensive mistake, which we cover in our guide to genuine, grey market and counterfeit hardware.

High availability, and whether you need it

A second appliance in a high availability pair doubles the hardware cost and removes the single point of failure at the edge. The question is simple: what does an outage of half a working day cost this business, and how quickly can a replacement be in the rack.

For a trading business, a logistics operation or anything where orders stop when the internet stops, the pair is justified. For a twenty person consultancy, a cold spare with a saved configuration is usually the better value, provided somebody has actually tested restoring that configuration.

The configuration decisions that matter more than the model

A well configured mid range appliance beats a badly configured expensive one every time.

  • Segment the network so cameras, guest Wi-Fi, voice and corporate devices sit on separate VLANs with rules between them. Most UAE offices we see run flat networks, which means one compromised device sees everything.
  • Remove the permit any rules that accumulate during troubleshooting and never get cleaned up.
  • Turn on logging, and send logs somewhere they survive the device failing.
  • Restrict management access to specific addresses, and never expose the management interface to the internet.
  • Enable multi-factor authentication on remote access. Credential reuse is the most common way into a small business network.

A sensible specification

For a UAE office of 30 to 100 staff on a fibre circuit, with remote workers and one or two branch tunnels: a desktop or small rack appliance whose inspected HTTPS throughput comfortably exceeds the circuit speed, session capacity sized for three sessions per device, VPN capacity for the remote headcount, a three year subscription priced into the comparison, protected power, and either a cold spare or a high availability pair depending on what downtime costs.

Codeeo Tech supplies security platforms from Fortinet, SonicWall, Cisco and Juniper to businesses across the UAE. Send us your circuit speed, headcount and remote access requirement through the contact page and we will size against the inspected figures rather than the headline ones.

Cover photo: Sheikh Zayed Road, Dubai (8971328903) by Fabio Achilli from Milano, Italy, via Wikimedia Commons (CC BY 2.0).