The following table describes the supported NS9500 (stack and standalone) Sensor capacity:
Maximum Type | NS9500 stack | NS9500 standalone | ||||
|---|---|---|---|---|---|---|
100 Gbps throughput | 60 Gbps throughput | 40 Gbps throughput | 30 Gbps throughput | 20 Gbps throughput | 10 Gbps throughput | |
Aggregate HTTP Performance | 100 Gbps | 60 Gbps | 40 Gbps | 30 Gbps | 20 Gbps | 10 Gbps |
Max Throughput with test equipment sending UDP packet size of 1512 Bytes | upto 100 Gbps | upto 70 Gbps | upto 50 Gbps | upto 35 Gbps | upto 25 Gbps | upto 15 Gbps |
Concurrent Connections | 64,000,000 | 32,000,000 | 26,000,000 | 16,000,000 | 13,000,000 | 10,000,000 |
Connections established per second | 2,500,000 | 1,300,000 | 1,000,000 | 650,000 | 525,000 | 450,000 |
Latency (Average UDP per packet Latency) | 20 µs | 20 µs | 20 µs | 20 µs | 20 µs | 20 µs |
SSL Flow Count | 6,400,000 | 3,200,000 | 2,600,000 | 1,600,000 | 1,300,000 | 1,000,000 |
Number of SSL certificates that can be imported into the Sensor | 1,024 | 1,024 | 1,024 | 1,024 | 1,024 | 1,024 |
Throughput with Inbound SSL Decryption (based on 10% SSL traffic)
| 90 Gbps | 52 Gbps | 36 Gbps | 26 Gbps | 18 Gbps | 10 Gbps |
Quarantine rules per Sensor- IPv4 | 7,999 | 7,999 | 7,999 | 7,999 | 7,999 | 7,999 |
Quarantine rules per Sensor- IPv6 | 500 | 500 | 500 | 500 | 500 | 500 |
Quarantine Zones per Sensor | 50 | 50 | 50 | 50 | 50 | 50 |
Quarantine Zone ACLs per Sensor | 1,000 | 1,000 | 1,000 | 1,000 | 1,000 | 1,000 |
Virtual Interfaces (VIDS) per Sensor (Number of Virtual IPS Systems) | 1,000 | 1,000 | 1,000 | 1,000 | 1,000 | 1,000 |
VLAN / CIDR Blocks per Sensor | 3,000 | 3,000 | 3,000 | 3,000 | 3,000 | 3,000 |
VLAN / CIDR Blocks per Interface | 254 | 254 | 254 | 254 | 254 | 254 |
Customized attacks See the note below on how the number of customized attacks is affected. | 100,000 | 100,000 | 100,000 | 100,000 | 100,000 | 100,000 |
Ignore rules | 262,144 | 262,144 | 262,144 | 262,144 | 262,144 | 262,144 |
Number of attacks with ignore rules | 128,000 | 128,000 | 128,000 | 128,000 | 128,000 | 128,000 |
DoS Profiles | 5,000 | 5,000 | 5,000 | 5,000 | 5,000 | 5,000 |
SYN cookie rate (64 ‑ byte packets per second) | 54,000,000 | 27,000,000 | 18,000,000 | 13,500,000 | 9,000,000 | 5,000,000 |
Effective (Firewall) access rules | 30,000 | 30,000 | 20,000 | 30,000 | 20,000 | 10,000 |
Firewall rule objects | 140,000 | 140,000 | 140,000 | 140,000 | 140,000 | 70,000 |
Firewall DNS rule objects | 5,000 | 5,000 | 5,000 | 5,000 | 5,000 | 2,500 |
Firewall rule object groups | 1,000 | 1,000 | 1,000 | 1,000 | 1,000 | 500 |
Application on Custom Port rule objects | 2,000 | 2,000 | 2,000 | 2,000 | 2,000 | 1,000 |
Firewall user-based rule objects | 5,000 | 5,000 | 5,000 | 5,000 | 5,000 | 2,500 |
Firewall user groups in access rules | 10,000 | 10,000 | 10,000 | 10,000 | 10,000 | 10,000 |
Number of exclusion list entries permitted for IP Reputation | 128 | 128 | 128 | 128 | 128 | 128 |
Maximum host entries supported for Connection Limiting policies | 256,000 | 256,000 | 256,000 | 256,000 | 256,000 | 256,000 |
Maximum file size during packet capture | 100 MB | 100 MB | 100 MB | 100 MB | 100 MB | 100 MB |
Passive device profile limits | 100,000 | 100,000 | 100,000 | 100,000 | 100,000 | 100,000 |
Advanced Malware - Maximum simultaneous file scan capacity when the file is saved in the Sensor See the note below for more information. | 4,000 | 2,000 | 2,000 | 1,000 | 1,000 | 1,000 |
Advanced Malware - Maximum simultaneous file scan capacity without saving files in the Sensor See the note below for more information. | 4,096 | 2,048 | 2,048 | 1,024 | 1,024 | 1,024 |
New HTTP connections per second (using 1 GET with 5000 HTTP response) | 1,400,000 | 700,000 | 600,000 | 350,000 | 300,000 | 260,000 |