Firewall Throughput Calculator for Home Labs

May 30, 2026

Firewall Throughput Calculator

Estimate real usable firewall capacity after NAT, rules, packet size, IDS or IPS inspection, VPN encryption, logging, QoS, and CPU headroom.

1 Real firewall presets
2 Traffic and firewall inputs
Pick the closest CPU and port class, then tune packet and feature load.
Deep inspection reduces usable throughput before headroom is applied.
Use this for inter-VLAN, lab storage, or DMZ traffic crossing the firewall.
Smaller packets stress PPS before line-rate Mbps.
Home labs feel better when firewall CPU does not sit at 90% during bursts.
Usable Firewall Capacity
0
Mbps after features and headroom
Capacity Headroom
0%
versus buffered design load
Packet Ceiling
0
kpps at average packet size
Sizing Verdict
Check
feature-aware recommendation

Throughput Breakdown

Run the calculator to see the packet-rate and feature derate path.
3 Selected profile spec grid
4.0G
Baseline NAT
650k
Packet Rate
1.0M
State Table
1.2G
VPN Class
4 Device profile reference
Profile Good fit Baseline NAT Packet-rate class
Intel N100 mini PC1G to 2.5G home labs, OPNsense, pfSenseAbout 4 Gbps650 kpps class
Core i5 mini PC10G lab routing, IDS testing, fast VPNAbout 12 Gbps1.8 Mpps class
Older Core i3 applianceGigabit NAT, light IDS, small branch labAbout 2 Gbps300 kpps class
pfSense or OPNsense VMVirtual lab edge with dedicated vNICsAbout 3 Gbps450 kpps class
RB5009 class routerFast routed VLANs with lighter inspectionAbout 7 Gbps1.0 Mpps class
UDM Pro class gatewayUniFi home office with IDS or IPS togglesAbout 8 Gbps850 kpps class
Netgate 6100 classMulti-gig pfSense appliance with VPNAbout 9 Gbps1.2 Mpps class
FortiGate 60F classBranch UTM features and hardware assistAbout 10 Gbps1.5 Mpps class

Profiles are planning classes for comparison. Vendor data sheets often publish multiple numbers for firewall, IPS, threat protection, VPN, and IMIX traffic.

5 Inspection and feature derates
Mode Typical home-lab use Capacity factor What to watch
Stateful NATWAN edge, port forwards, basic policy0.90 to 1.00Packet size and state table growth
IDS monitorSuricata mirror or alert-only WAN inspection0.55 to 0.75Rule set size, CPU cache, packet capture drops
Inline IPSBlocking rules for WAN or VLAN choke points0.35 to 0.60Latency, false positives, single-thread ceilings
VPN-heavy edgeWireGuard, IPsec, road warrior users0.45 to 0.75AES acceleration, tunnel count, MTU overhead
TLS proxy stackLab proxy, filtering gateway, reverse proxy0.25 to 0.45Certificate handling and per-flow CPU load
6 Packet size and PPS planning
Traffic mix Avg packet Why it matters Planning note
Bulk downloads1200-1500 BMbps usually limits firstGood for speed tests and backup traffic
Mixed home use700-1000 BBalanced Mbps and PPS loadReasonable default for home firewalls
Gaming and VoIP200-500 BPPS can limit before MbpsWatch latency under shaping or IPS
VPN with overhead500-1200 BEncryption and encapsulation add CPUTest with real tunnel MTU and cipher
Telemetry heavy lab128-400 BMany small flows stress interruptsUse NIC offload carefully with IDS
7 Common sizing scenarios
Scenario Feature stack Suggested target Extra margin
1 Gbps fiber homeNAT, 40-80 rules, light VLANs1.3-1.8 Gbps usableEnough for speed tests plus bursts
IDS learning labSuricata alert-only, 100k states2x WAN capacityRule updates can change CPU fast
Multi-gig VLAN routerInter-VLAN routing, ACLs, no IPS3-8 Gbps usableCheck switch uplinks and LACP flow limits
Remote work VPNWireGuard or IPsec plus QoS1.5x encrypted loadLeave CPU for DNS, logs, and updates
Inline IPS officeIPS, verbose logs, smart queues2.5x WAN capacityPrefer tested threat-protection numbers
8 Practical sizing tips
Use IMIX thinking. A firewall that can pass a 1 Gbps speed test with large packets may still struggle with many small gaming, VoIP, DNS, and telemetry packets. If you enable IPS, test packet drops and latency, not just download speed.
Separate routing and inspection when needed. For a 10G lab, it can be cleaner to route trusted VLANs on a switch or fast router and send only WAN, DMZ, or risky segments through heavy IDS or IPS inspection.

Firewall throughput is a measurement of how much data an firewall can process. The throughput of a firewall can change significant when you enable specific features on that firewall. Many people believes that the throughput of a firewall is correlated to the throughput of the internet connection a user have.

The throughput of a firewall, however, is influenced by many different factor. Some of these factors are the number of packets per second that the firewall must evaluate, the number of connection state that the firewall must keep track of, and the amount of encryption that the firewall must process. Firewall throughput is also affected by the number of feature a firewall has.

Things That Affect Firewall Speed

Every rule that you add to your firewall requires that the firewall to perform a lookup. Every VLAN that you add to your firewall will require that the firewall also perform additional lookups. Additionally, if you enable logging or Quality of Service setting on your firewall, it will also require that the firewall examines the packet in additional ways.

These settings will also reduce the total throughput of the firewall. Deep packet inspection will also reduce the throughput of a firewall since the firewall must also examine the content of the packets. Deep packet inspection will reduce the throughput of a firewall more greater than stateful NAT will.

Additionally, if your firewall is configured to have virtual private network (VPN) connection, it will also affect the throughput of your firewall. This is because all VPN traffic will require encrypting to protect the traffic. The CPU will have to perform mathematical calculation to encrypt the traffic, which will reduce the throughput of the firewall.

The more VPN tunnels your firewall has, the more greater of an impact encryption will have on your firewall throughput. This factor is separate from the routed traffic because VPN traffic use the CPU of the firewall in a different way than routed traffic does. Your firewall will need to be size based off more than just the throughput of your internet connection.

In addition to internet traffic, firewalls will also handle traffic between VLAN, as well as local service and VPN connections. The total amount of traffic that a firewall must handle may be much more than the throughput of the internet connection. The total demand on a firewall may even be more than the capacity of that firewall.

The calculator also consider both WAN targets and internal target for firewalls to determine the total amount of traffic a firewall must handle. When selecting a firewall, you should also provide some headroom for the firewall. If you run your firewall at a very high level of CPU utilization, you will have very little headroom for other process, such as updating the firewall signature database.

Many firewall administrator find a CPU utilization of 90% to be sufficient, but leave 25 to 40% of the firewalls capacity available for the firewall to have headroom for unexpected traffic volume. Additionally, if you use the buffer setting for your firewall, this will provide headroom for your firewall in the future. You may want to add new service or users at a later date to the network, and having headroom for this will save your organization the effort of having to immediately purchase new hardware.

The calculator also provide a verdict based on the answer you enter into the calculator. A comfortable verdict means that the firewall you have selected can handle the traffic. A tight or upgrade verdict means that the firewall may have issue handling the traffic that is specified in your inputs.

A tight or upgrade verdict on the calculator suggests that you may need to reduce the number of inspection rules on your firewall, or that you should change to a faster firewall platform. While this calculator is not a replacement for actual testing of the firewall you are creating, it will give you a better understanding of some of the factor that will influence the firewall throughput.

Firewall Throughput Calculator for Home Labs

Related posts

Leave a Comment