04-04-2025 09:58 AM
We currently have a Cisco Nexus 93180yc-ex that houses all of the company's VLAN interfaces.
To provide better security, we plan to migrate only the server VLAN interface to a Cisco firewall, and we need to sizing it.
This firewall will handle: IPS, AMP, and URL filtering.
I was considering the new Cisco line, specifically the 1220cx model, but I don't think it's powerful enough.
The company currently has 500 employees and 140 servers.
Any ideas on sizing?
04-04-2025 10:11 AM
@lnacional what kind of performance/throughput do you expect out of the firewall? The Firepower 1220CX has the following performance, note the more features you enabled (IPS, AMP, etc) the less performance you get from the hardware.
If the 1200 series is not powerful enough consider the 3100 series hardware. https://www.cisco.com/c/en/us/products/collateral/security/firewalls/secure-firewall-3100-series-ds.html
If you contact your Cisco partner they can use the NGFW performance estimator tool to determine the right hardware based on enabled features.
04-04-2025 11:19 AM
Hello Rob, thanks for answering.
We are trying to figure out how to measure the current throughput of our server vlan, we tried with netflow using our network monitoring tool but it seems to be unable to group netflow results. Do you have any advice on how we could measure it?
04-04-2025 11:29 AM
@lnacional SNMP monitoring of the relevant interfaces/vlans etc will provide you link utilisation.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide