How Ideco Measures NGFW Performance Using TRex ASTF and RFC 9411 Methodology
Ideco has shared a comprehensive look at how its engineering team measures the performance of Ideco NGFW Novum on the Ideco EX platform. The article explains why raw performance numbers are meaningless without a clearly documented methodology and describes every parameter used in their lab tests.
Why Performance Numbers Vary Across Tests
The same NGFW device can produce very different results on two different test beds even when both tests are honest. Performance depends on packet size, enabled security functions, number of rules, test duration, and the acceptable loss threshold. Ideco therefore publishes its full methodology so that any reader can reproduce the measurements and understand exactly what each figure represents.
Traffic Generator and Test Modes
The team selected the open-source TRex generator running in ASTF (Advanced Stateful) mode. This choice enables realistic TCP session handling and L7 emulation, which is essential for testing stateful inspection engines. Stateless mode is used only for raw UDP throughput tests with 1518-byte frames. When TLS decryption is enabled on the firewall, the team switches to the hardware-based Keysight BreakingPoint system.
Test Bed Configuration
Both the device under test and the traffic generator use identical server hardware:
- CPU: Xeon Gold 6338N
- RAM: 128 GB
- NICs: Intel E810 2xQSFP28 (100 Gbps)
The topology is a simple two-port setup with TRex port 0 connected to the DUT and TRex port 1 returning the traffic.
Key Metrics and Traffic Profiles
The methodology measures four primary metrics: throughput in Gbit/s, connections per second (CPS), concurrent connections (CC), and latency. Tests are performed with the following profiles:
- UDP 1518-byte frames (raw L2/L3 ceiling)
- TCP/HTTP with 64 KB objects
- TCP/HTTP with 16 KB objects
- EMIX mixed corporate traffic
- TCP CPS and TCP CC specific tests
All tests run with a fixed set of firewall rules, IPS signatures, and application control profiles. TLS decryption remains disabled during these runs.
Loss Criterion and Test Duration
Loss is defined as dropped sessions rather than individual packets. The formula uses TRex counters for TCP connection drops, established session drops, and UDP keepalive drops. A test point passes only when session loss stays at or below 1 %. Each load point is held for 300 seconds after a 30-second ramp-up phase to reveal queue buildup, memory pressure, and thermal effects that short bursts would miss.
Results Summary
On the Ideco EX platform the measured maximums are:
- UDP 1518 B: 200 Gbit/s
- TCP/HTTP 64 KB: 100 Gbit/s
- TCP/HTTP 16 KB: 62 Gbit/s
- EMIX (firewall only): 92 Gbit/s
- EMIX + IPS: 31 Gbit/s
- Full NGFW stack: 15.5 Gbit/s
- TCP CPS: 800 000 new sessions per second
- TCP CC: 21 000 000 concurrent sessions
The article concludes that performance is always a range that depends on the actual traffic mix and enabled security functions. Full configuration files and commands are provided so the community can replicate the tests.
Related articles
Bots Overload OT Commerce Store on OT Box, Spike Paid OTAPI Calls Mistaken for DDoS Attack
An online store running OT Commerce experienced CPU loads reaching 98-100% and a 6-7x increase in paid OTAPI calls over three days due to automated bot traffic rather than a traditional DDoS. The site owner had already deployed a paid anti-bot module on the VPS, yet behavioral bots continued to bypass protections and force expensive calls to the external OTAPI platform for product data from Taobao, Tmall, 1688 and other marketplaces. Traffic analysis after switching to the CRONARMOR WAF revealed that 41.9% of page requests were automated, with 99.3% of early-stage automation blocked before reaching the origin server. Only 0.5% were behavioral bots visible in analytics, while legitimate search crawlers accounted for 27,190 requests that were explicitly allowed. The WAF approach stopped requests at the reverse proxy layer, preventing PHP execution, database queries and OTAPI billing events on the origin. Post-deployment CPU dropped to single digits for most of the day, eliminating both performance issues and the anomalous rise in paid API usage.
Teenage Smartphone Addiction: Causes, Consequences, and Treatment Approaches
Smartphone use has become an integral part of adolescent life, but problematic usage patterns rather than device ownership itself are the focus of concern. Medical experts avoid the term smartphone addiction and instead address issues like disrupted self-control, social media overuse, and gaming disorder that interfere with sleep, studies, relationships, and mental health. Data from Pew Research indicates nearly 50% of U.S. teens aged 13-17 are online almost constantly, while CDC findings link four or more hours of daily screen time to elevated anxiety and depression symptoms. Family digital habits strongly influence teen behavior, and rigid bans often fail without addressing underlying issues such as boredom, anxiety, or social isolation. Parents are advised to track specific disruptions over a week and consider professional help when signs of depression, bullying, or self-harm appear alongside device overuse.
VK WorkSpace Federation Enables Secure Multi-Organization On-Premise Messaging Without Infrastructure Merge
VK Tech has released federation capabilities for its VK WorkSpace corporate messenger that connect independent On-Premise installations while preserving each organization's full control over data, administration, and security policies. The feature, first piloted in November 2025 and expanded in the July 2026 26.2 release, supports multi-party chats across more than two separate environments. Federation relies on mutual trust establishment and per-user access grants rather than full directory replication or proxy access to a single host instance. Each participating organization maintains local copies of messages, files, and chat metadata, allowing continued access even if a partner installation becomes unavailable. The architecture deliberately avoids both centralized hosting and open protocols such as Matrix to keep changes to the existing messenger core minimal. Administrators retain independent levers to create or revoke trusts and to limit which employees may communicate externally.
Sergey Volkov of Cloud.ru Named Top CISO in Russian IT Sector Ranking
Sergey Volkov, Director of the Cyber Protection Center at Cloud.ru, has secured first place in the information security category of the annual Top-1000 Russian Managers ranking. The ranking, published by the Association of Managers in the Kommersant newspaper since 2001, is compiled through peer evaluations by top executives followed by review from expert commissions. Volkov oversees information security strategy and operations for Cloud.ru, and his top position reflects professional recognition of his leadership results. The Association also analyzed broader achievements among laureates and identified key trends in Russian management. Artificial intelligence adoption for business process optimization appeared in 80 percent of reviewed accomplishments. Client orientation through user experience analysis and personalized solutions ranked second, while operational efficiency via cost reduction, automation, and digitalization took third place.