How We Tested the Palo Alto PA-5060 firewall
Network World - We assessed the performance of the Palo Alto PA-5060 firewall using three sets of tests, covering rates with mixed content, rates with static content, and TCP connection behavior. Two pairs of Spirent Avalanche 3100 GT traffic generator/analyzers, each equipped with two 10G Ethernet interfaces, served as the primary test tool.
For tests that measured forwarding rates, we configured each of the PA-5060's four 10G Ethernet interfaces to act as a gateway for a different IP subnet. We also configured static NAT on the device's unprotected interfaces for all tests, and installed more than 200 access rules. We configured Spirent Avalanche to emulate 200 clients and 40 servers, distributed across the four subnets.
In the mixed-content tests, we offered the same combination of HTTP object types and sizes as in a previous Network World test of the Palo Alto PA-4020 firewall. Object types included text, images, and other binary content such as PDF files. Object sizes ranged from 1 kbyte to 1,536 kbytes, all requested over HTTP. We also reran the same tests using SSL with an RC4-MD5 cipher.
The static-content tests also used HTTP and SSL, but in this case involved separate tests with 10- and 512-kbyte text objects. We chose 10-kbyte objects because they are close to the average object size seen in multiple studies of Web object size distribution, and 512-kbyte objects to represent a large object that should produce a high forwarding rate.
To determine concurrent TCP connection count, we configured clients emulated by Spirent Avalanche to request one object every 60 seconds, building up progressively larger numbers of connections. The maximum concurrent connection count was determined to be the largest count at which the firewall serviced all requests with no failed requests (measured to the nearest 100,000 requests).
To determine connection setup rate, we configured clients and servers emulated by Spirent Avalanche to use HTTP version 1.0, forcing the use of a new TCP connection for each HTTP request. Using a binary search, we determined the maximum rate at which the firewall could service requests for 60 seconds with no failed transactions.
Calling All Next-Generation Firewall Vendors
Network World invites all vendors of next-generation firewalls to have their products undergo the same rigorous tests used with Palo Alto's PA-5060. By "next generation," we mean firewalls with UTM capabilities; multiple 10-gigabit Ethernet interfaces; and the ability to inspect and act upon traffic at the application layer (for example, by distinguishing between Google Talk file-transfer and voice traffic, even though both use the same 5-tuple). Please send inquiries to Neal Weinberg.
Read more about wide area network in Network World's Wide Area Network section.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- How to Improve Disaster Recovery for the Enterprise:
- Ready to accelerate disaster recovery across your entire enterprise? Read this Taneja report to find out how you can increase WAN efficiency, overcome...
- Unleashing Cloud Performance
- In this whitepaper, we explore how WAN optimization from Riverbed can deliver on the promise of accelerated cloud performance for widely distributed enterprises.
- ESG - Avoiding the Hazards of IT Consolidation
- In an effort to reduce costs and streamline operations, today's large, distributed organizations are investing more in data center transformation, consolidation, and server...
- Assessing ROI for Mobile Acceleration Clients
- This ENTERPRISE MANAGEMENT ASSOCIATES® (EMA) paper examines the business case for deploying mobile WAN optimization client software and builds a Return on Investment...
- The Changing Requirements of WAN Optimization
- Companies looking to drive greater IT performance will do well to begin their search with WAN optimization, which has evolved into a complete... All LAN/WAN White Papers
- North Pole to South Seas: Overcoming the Pitfalls of remote Performance
- In today's always-on world, connectivity is a business requirement. You need the tools that allow you to operate as if you were on...
- Configure, Don't Customize Your Service Desk
- Join Pink Elephant Analyst George Spalding and Nimsoft Service Desk expert Tim Rochte to learn the perils of customizing your service desk and...
- Distributed Database Security with Real-time Monitoring
- View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
- InfoSphere Warehouse Packs Demo
- These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
- Delivery Management -- Extending Lifecycle Management
- Date: Wednesday, June 20, 2012, 1:00 PM EDT
Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,...
All LAN/WAN Webcasts