How Ideco Measures NGFW Performance Using TRex ASTF and RFC 9411 Methodology
Ideco has shared a comprehensive look at how its engineering team measures the performance of Ideco NGFW Novum on the Ideco EX platform. The article explains why raw performance numbers are meaningless without a clearly documented methodology and describes every parameter used in their lab tests.
Why Performance Numbers Vary Across Tests
The same NGFW device can produce very different results on two different test beds even when both tests are honest. Performance depends on packet size, enabled security functions, number of rules, test duration, and the acceptable loss threshold. Ideco therefore publishes its full methodology so that any reader can reproduce the measurements and understand exactly what each figure represents.
Traffic Generator and Test Modes
The team selected the open-source TRex generator running in ASTF (Advanced Stateful) mode. This choice enables realistic TCP session handling and L7 emulation, which is essential for testing stateful inspection engines. Stateless mode is used only for raw UDP throughput tests with 1518-byte frames. When TLS decryption is enabled on the firewall, the team switches to the hardware-based Keysight BreakingPoint system.
Test Bed Configuration
Both the device under test and the traffic generator use identical server hardware:
- CPU: Xeon Gold 6338N
- RAM: 128 GB
- NICs: Intel E810 2xQSFP28 (100 Gbps)
The topology is a simple two-port setup with TRex port 0 connected to the DUT and TRex port 1 returning the traffic.
Key Metrics and Traffic Profiles
The methodology measures four primary metrics: throughput in Gbit/s, connections per second (CPS), concurrent connections (CC), and latency. Tests are performed with the following profiles:
- UDP 1518-byte frames (raw L2/L3 ceiling)
- TCP/HTTP with 64 KB objects
- TCP/HTTP with 16 KB objects
- EMIX mixed corporate traffic
- TCP CPS and TCP CC specific tests
All tests run with a fixed set of firewall rules, IPS signatures, and application control profiles. TLS decryption remains disabled during these runs.
Loss Criterion and Test Duration
Loss is defined as dropped sessions rather than individual packets. The formula uses TRex counters for TCP connection drops, established session drops, and UDP keepalive drops. A test point passes only when session loss stays at or below 1 %. Each load point is held for 300 seconds after a 30-second ramp-up phase to reveal queue buildup, memory pressure, and thermal effects that short bursts would miss.
Results Summary
On the Ideco EX platform the measured maximums are:
- UDP 1518 B: 200 Gbit/s
- TCP/HTTP 64 KB: 100 Gbit/s
- TCP/HTTP 16 KB: 62 Gbit/s
- EMIX (firewall only): 92 Gbit/s
- EMIX + IPS: 31 Gbit/s
- Full NGFW stack: 15.5 Gbit/s
- TCP CPS: 800 000 new sessions per second
- TCP CC: 21 000 000 concurrent sessions
The article concludes that performance is always a range that depends on the actual traffic mix and enabled security functions. Full configuration files and commands are provided so the community can replicate the tests.
Related articles
Siemens Industrial AI Drives Green Efficiency Revolution in Infrastructure Cooling, Parks, and Data Centers
The article explores how Siemens is applying industrial AI to transform physical infrastructure operations across buildings, industrial parks, and data centers in China. It details the company's non-invasive AI BOX solution that optimizes cooling systems in hotels and other facilities without replacing existing equipment, achieving around 7% additional energy savings. The Smart ECX platform enables integrated source-grid-load-storage management for zero-carbon factories, delivering 30% cost reductions and over 90% overall energy efficiency. Siemens also supplies critical power distribution hardware such as NXAirS medium-voltage switchgear and SIVACON S8 low-voltage cabinets to support high-reliability AI data center operations. The coverage highlights alignment with China's 15th Five-Year Plan carbon peaking policies and real-world deployments at venues including the Shanghai Yingyi Crowne Plaza Holiday Hotel and Sichuan Chuanrun's Chengdu factory. Overall, Siemens emphasizes combining domain physics models with machine learning to deliver verifiable, replicable industrial value rather than generic AI concepts.
RuBackup 2.9.0 Receives Official Compatibility Certificate with BAUM-Inform Storage Systems
RuBackup version 2.9.0 from the Astra Group has successfully passed compatibility testing with storage systems produced by BAUM-Inform. The verification confirmed that the backup solution can reliably perform data backup and recovery operations using BAUM-Inform hardware. Testing followed a predefined program and methodology, although detailed results and the full list of tested configurations were not disclosed. BAUM-Inform systems are designed for corporate data storage and processing, while RuBackup supports servers, workstations, virtualization environments, mail systems, databases, and domain infrastructure. The certification allows organizations to deploy both products together without additional integration validation. Both companies stated that the verified combination reduces deployment risks and supports the development of fully domestic data protection infrastructures.
VK WorkSpace Adds Guest Access Without Accounts, Password Protection, Polls, and File Uploads Up to 30 MB
VK Tech has updated the cloud version of its VK WorkSpace Board to allow external participants such as clients, contractors, and other guests to join collaborative boards without creating an account. Access can be protected by a password set by the owner, who can also assign specific permissions including view-only, commenting, or full editing rights while restricting guests from creating new boards or viewing version history. Domain administrators can enforce mandatory password protection across all boards that permit guest access. Additional features include built-in polls with automatic result counting, support for uploading files up to 30 MB that are scanned by antivirus software, a mini-map for navigating large projects, and export options in SVG, PNG, JPG, PDF, and CSV formats. The service also received an English-language interface, addressing key use cases involving external collaboration as highlighted by VK Tech executive Petr Shcheglov.
Solar SIEM 2026.2 Adds Full Solar JSOC Detection Library, TI Feeds Support, Enhanced AI Agent and Multi-Tenancy
GC Solar has released Solar SIEM 2026.2, which now includes the complete detection rule library developed by Solar JSOC over 14 years of monitoring approximately 300 customer infrastructures. The update eliminates the need for organizations to spend months building custom rule sets by providing ready-made detection scenarios that identify sophisticated attacks from the earliest implementation stages. In 2025, Solar JSOC recorded 1.16 million security events after false-positive filtering and confirmed more than 33,000 incidents, with malware accounting for 36 percent and unauthorized access attempts for 23 percent. The product also gained native support for TI Feeds, allowing automatic ingestion and correlation of indicators of compromise from Solar 4RAYS and customer-owned sources. The built-in AI agent has been significantly expanded so it can now independently query raw event data, perform deeper analysis, and recommend next steps, reducing manual workload for analysts. Multi-tenancy capabilities enable multiple organizations to share a single SIEM instance while keeping their event streams fully separated, targeting holdings, MSSP providers, and large enterprises with numerous divisions. More than 40 companies of various sizes participated in the pilot program.