The following table describes the supported NS5x00 Sensor capacity:
Maximum Type | NS5200 | NS5100 |
|---|---|---|
Aggregate HTTP Performance | 1 Gbps | 600 Mbps |
Max Throughput with test equipment sending UDP packet size of 1512 Bytes | up to 3 Gbps | up to 1.5 Gbps |
Concurrent Connections | 1,350,000 | 750,000 |
Connections established per second | 45,000 | 40,000 |
Latency (Average UDP per packet Latency) | <100 µs | <100 µs |
SSL Flow Count | 75,000 | 40,000 |
Number of SSL certificates that can be imported into the Sensor | 1,024 | 1,024 |
Throughput with Inbound SSL Decryption (based on 10% SSL traffic) | 1 Gbps | 600 Mbps |
Quarantine rules per Sensor- IPv4 | 7,999 | 7,999 |
Quarantine rules per Sensor- IPv6 | 500 | 500 |
Quarantine Zones per Sensor | 50 | 50 |
Quarantine Zone ACLs per Sensor | 1,000 | 1,000 |
Virtual Interfaces (VIDS) per Sensor (Number of Virtual IPS Systems) | 1,000 | 100 |
VLAN / CIDR Blocks per Sensor | 300 | 300 |
VLAN / CIDR Blocks per Interface | 254 | 254 |
Customized attacks See the note below on how the number of customized attacks is affected. | 100,000 | 100,000 |
Ignore rules | 131072 | 131,072 |
Number of attacks with ignore rules | 100,000 | 100,000 |
DoS Profiles | 5,000 | 300 |
SYN cookie rate (64 ‑ byte packets per second) | 1,000,000 | 750,000 |
Effective (Firewall) access rules | 2,000 | 2,000 |
Firewall rule objects | 14,000 | 14,000 |
Firewall DNS rule objects | 750 | 750 |
Firewall rule object groups | 200 | 200 |
Application on Custom Port rule objects | 250 | 250 |
Firewall user-based rule objects | 750 | 750 |
Firewall user groups in access rules | 10,000 | 10,000 |
Number of exclusion list entries permitted for IP Reputation | 64 | 64 |
Maximum host entries supported for Connection Limiting policies | 128,000 | 128,000 |
Maximum file size during packet capture | 58 MB | 58 MB |
Passive device profile limits | 15,000 | 15,000 |
Advanced Malware - Maximum simultaneous file scan capacity when the file is saved in the Sensor See the note below for more information. | 32 | 32 |
Advanced Malware - Maximum simultaneous file scan capacity without saving files in the Sensor See the note below for more information. | 1,024 | 1,024 |
New HTTP connections per second(using 1 GET with 5000 HTTP response) | 30,000 | 25,000 |