The following table provides the Firewall-related capacity values for the various NS-series Sensor models.
Model | Effective Access Rules | Cumulative rule object member count of all the rule objects selected | DNS Rule Objects | Rule Object Groups (such as Application Groups and Service Groups) | Custom Rule Objects |
|---|---|---|---|---|---|
NS9600 stack (2-node) - 120 Gbps throughput | 80000 | 960000 | 7000 | 1500 | 2000 |
NS9600 standalone - 60 Gbps throughput | 80000 | 960000 | 7000 | 1500 | 2000 |
NS9600 standalone - 40 Gbps throughput | 40000 | 480000 | 6000 | 1250 | 2000 |
NS9600 standalone - 20 Gbps throughput | 30000 | 360000 | 5000 | 1000 | 2000 |
NS9500 stack - 100 Gbps throughput | 20000 | 240000 | 5000 | 1000 | 2000 |
NS9500 stack - 60 Gbps throughput | 20000 | 240000 | 5000 | 1000 | 2000 |
NS9500 stack - 40 Gbps throughput | 20000 | 170000 | 5000 | 1000 | 2000 |
NS9500 standalone - 30 Gbps throughput | 20000 | 240000 | 5000 | 1000 | 2000 |
NS9500 standalone - 20 Gbps throughput | 20000 | 240000 | 5000 | 1000 | 2000 |
NS9500 standalone - 10 Gbps throughput | 10000 | 170000 | 2500 | 500 | 1000 |
NS9300 | 20000 | 240000 | 5000 | 1000 | 2000 |
NS9200 | 20000 | 240000 | 5000 | 1000 | 2000 |
NS9100 | 10000 | 170000 | 2500 | 500 | 1000 |
NS7600 - 20 Gbps throughput | 4000 | 135000 | 1250 | 400 | 500 |
NS7600 - 15 Gbps throughput | 4000 | 135000 | 1250 | 400 | 500 |
NS7600 - 10 Gbps throughput | 4000 | 135000 | 1250 | 400 | 500 |
NS7600 - 5 Gbps throughput | 4000 | 135000 | 1250 | 400 | 500 |
NS7500 - 7.5 Gbps throughput | 4000 | 135000 | 1250 | 400 | 500 |
NS7500 - 5 Gbps throughput | 4000 | 135000 | 1250 | 400 | 500 |
NS7500 - 3Gbps throughput | 4000 | 135000 | 1250 | 400 | 500 |
NS7350 | 4000 | 135000 | 1250 | 400 | 500 |
NS7250 | 3000 | 121000 | 1000 | 300 | 500 |
NS7150 | 3000 | 121000 | 1000 | 300 | 500 |
NS7300 | 5000 | 135000 | 1250 | 400 | 500 |
NS7200 | 3000 | 121000 | 1000 | 300 | 500 |
NS7100 | 3000 | 121000 | 1000 | 300 | 500 |
NS5200 | 2000 | 34000 | 750 | 200 | 250 |
NS5100 | 2000 | 34000 | 750 | 200 | 250 |
NS3600 - 5 Gbps throughput | 4000 | 135000 | 1250 | 400 | 500 |
NS3600 - 3 Gbps throughput | 4000 | 135000 | 1250 | 400 | 500 |
NS3600 - 1 Gbps throughput | 4000 | 135000 | 1250 | 400 | 500 |
NS3500 | 1000 | 17000 | 500 | 100 | 150 |
NS3200/NS3100 | 1000 | 17000 | 500 | 100 | 150 |
Notes:
Config Update of Sensors fail if you exceed the limits in the table above.
At a Sensor level, there are limits to the number of entities that you can refer to in the Firewall policies. For a given Sensor model, these limits are the same as the limit for Effective Access Rules
The Sensor derives the limit by totaling rules in all the policies assigned to it. The number of rules in each policy is derived by totaling the rules assigned to each interfaces.
Even if you refer to the same rule in all your policies, each reference is counted. For example, a policy with the following rule lines are applied to the Sensor interface.
Source 10.1.1.10 | Destination 20.1.1.10 | Application: Gmail
Source 10.1.1.10 | Destination 20.1.1.20 | Application: Gmail
Source 10.1.1.10 | Destination 20.1.1.10 | Application: Gmail
Though the first and third rule line are same in the above policy, both the references are counted. So, the number of policies here is 1 and the number of rule lines is 3.
If you use a Group Rule Object such as Network Group, then entire Group is counted as one rule. Consider that a rule refers to a Network Group as the Source. This Network Group contains 3 HostIPv4 Rule Objects. These 3 Rule Objects refer to 10 IPv4 addresses each. In this case, the count for Source remains as one and the rule line is considered as single entity.