Endpoint Management
Backup & Cyber Resilience
Identity & Access
Network Security & SASE
A next-generation firewall inspects traffic at your edge: it identifies the application, decrypts what it is allowed to decrypt, matches it against threat signatures, logs it, and decides. Every one of those steps costs throughput, and the headline figure on the front page of the datasheet includes none of them.
Palo Alto publishes 7.5–20 Gbps threat prevention across the PA-3400 series and states exactly what was enabled — App-ID, IPS, antivirus, anti-spyware, WildFire, DNS Security, file blocking and logging. Most vendors lead with a raw firewall figure several times higher.
Already decided — before the sizing call
Still yours to weigh
A device — physical, virtual or cloud — that sits where your network meets everything else and decides what may pass. The “next-generation” part means it identifies the application rather than just the port, can decrypt and inspect TLS, matches traffic against threat intelligence, and enforces policy per user rather than per IP address. Around that core, vendors add SD-WAN for connecting sites, sandboxing, DNS security and web filtering — usually as subscriptions.
Two numbers decide the purchase and only one is printed large. Inspected throughput — what the box does with threat prevention and logging enabled — and TLS inspection throughput, which is lower again and matters because most traffic is encrypted. Everything else is the commercial shape: what is in the subscription bundle, what management costs, and what happens at renewal. When enforcement should follow users off your network instead, that is the SASE & SSE guide.
The most common mis-purchase
Sizing on the datasheet’s headline figure and hitting a wall at a fraction of it once TLS inspection is on. Ask for the threat-prevention-enabled number, then ask for the TLS-inspection number, then add headroom for three years of traffic growth.
Often confused withSASE & SSE — enforcement in a provider's cloud instead of your edge →·Zero Trust Access — replacing the VPN that terminates on this firewall →·Secure Web & DNS — the cheapest control, deployed in front of everything →
The four routes of network security — and which one is yours →
Two pairs this buyer confuses. Neither is a maturity ladder — each term describes a different scope or a different enforcement location, with different failure modes and different cost behaviour.
Firewall vs NGFW
A classic firewall allows or blocks by port, protocol and address — it knows nothing about what the traffic is. An NGFW identifies the application regardless of port, ties policy to user identity, decrypts TLS and matches against threat intelligence. The name is a generation, not a tier: nobody sells the classic kind for a perimeter any more, but plenty of internal segmentation still runs on it.
UTM vs NGFW
Unified threat management bundles many functions — firewall, antivirus, web filtering, mail filtering, VPN — into one box for a small estate that cannot run five. NGFW is about deep application inspection at scale. The engineering overlaps almost entirely today; the difference is where the vendor points the product. A UTM box asked to do enterprise inspection is where sizing disasters happen.
SD-WAN vs MPLS
MPLS is a carrier circuit with guaranteed behaviour and a long contract. SD-WAN is software that steers traffic across whatever links you have — broadband, 4G, MPLS — choosing per application and healing around problems. SD-WAN replaces the expensive circuit, not the inspection; you still decide where inspection happens, which is the next card.
SD-WAN vs SASE
SD-WAN connects sites and steers traffic; SASE moves the security enforcement itself into a provider's cloud so it applies wherever the user is. SASE is not 'firewall, evolved' — it is a different enforcement location with different failure modes (PoP latency instead of appliance capacity), different cost behaviour (subscription instead of refresh), and a different renewal trap. Many buyers need SD-WAN and no SASE; many need SASE and no SD-WAN.
Seven variables decide this purchase. The instrument tests what documentation establishes (published inspected and TLS figures, form factor, SD-WAN, management, the vendor’s own SASE, India presence); real-world sizing, renewal behaviour and RMA turnaround are prose because the honest answers come from a proof of concept and a delivery team.
Real throughput with threat prevention, TLS inspection and logging enabled
The single most misleading spec in enterprise networking. Use the vendor's own inspected figure, note what was enabled when it was measured, and never accept the headline number.
TLS / SSL inspection performance
Most traffic is encrypted and decryption is the expensive part. A box sized on threat-prevention throughput can still fall over here — and the certificate rollout is a project of its own.
Form factor and HA model
Appliance, virtual, scale-out or cloud; active-passive or active-active. Scale-out (Maestro) changes how you grow — you add members rather than replace the box.
SD-WAN integrated or separate
In the licence (Fortinet, Versa), a separate product from the same vendor (Check Point, Cisco), or absent. It decides whether branch connectivity is one purchase or two.
Centralised management across sites
Included (Check Point, Versa, Sophos Central) or a separate product to licence and run (Panorama, FortiManager, Firewall Management Center). At ten sites it is a convenience; at a hundred it is the product.
Subscription bundling and renewal
Which features are in the bundle, which are add-ons, and what the same bundle costs in year four. Over five years the subscription usually exceeds the hardware.
Refresh cycle and the SASE question
A five-year appliance bought eighteen months before a SASE decision strands most of its value. Every vendor here except Sophos NDR sells its own SASE — negotiate the migration path before you sign, not after.
Set what is true for you. A product that misses a constraint fades with its reason printed on it; where a vendor publishes no headline inspected figure it is flagged and stays, never eliminated on a number nobody published. Every chip is reversible.
Form factor
How you will size it
The network half
Management
The SASE question
India
Estate size
Real-world sizing, renewal behaviour and RMA turnaround are in the notes below rather than chips — the first needs your traffic mix, and the other two need a delivery team’s scar tissue.

appliance capex plus a UTP or Enterprise subscription bundle per year; the ASIC design is why the inspected figure holds up better than software-only rivals at the same price
Estates that want the best inspected throughput per rupee, SD-WAN in the same box, and a single vendor from branch to data centre to SASE.
The catch: The value comes from buying into the Fabric — FortiManager and FortiAnalyzer are separate purchases, and the subscription bundle you need (UTP vs Enterprise) changes the five-year cost more than the appliance does. Feature depth in the console lags the marketing.

no separate SD-WAN licence — it runs on the FortiGate you already bought, which is the commercial argument; FortiManager for orchestration is separate
Multi-site estates that want application-steering, link remediation and security in one box rather than an overlay bought from someone else.
The catch: SD-WAN throughput with inspection enabled is not published as a separate figure — size from the FortiGate model's threat-protection number, not from an SD-WAN claim. Orchestration at scale needs FortiManager.

appliance capex plus Cloud-Delivered Security Services subscriptions per year; Panorama for central management is separate; Mumbai cloud location documented since 2021
Enterprises that want the deepest application identification and the most honest datasheet — Palo Alto states exactly which engines were enabled when the throughput was measured.
The catch: The premium option on both licence and subscription: CDSS bundles are where the five-year cost sits, and Panorama is another line. The full value assumes you adopt the platform rather than one appliance.

appliance capex plus a threat-prevention subscription; SmartConsole management is included rather than a separate product, which changes the comparison against Palo Alto and Fortinet
Security-first estates that want the strongest prevention posture and a management console included in the price rather than sold beside it.
The catch: SD-WAN is a separate product (Quantum SD-WAN), not a mode of the firewall; the appliance range is wide and model selection is unforgiving — the 9100's inspected figure is a fraction of the 29200's at a fraction of the price.

a hyperscale orchestrator that binds many gateways into one logical firewall — you buy the orchestrator plus the appliances it scales; throughput is the sum of the members, not a published single figure
Data centres that would otherwise buy a chassis: scale by adding gateways instead of replacing the box, with one policy across all of them.
The catch: No single inspected throughput figure exists for a scale-out cluster — it depends entirely on the member appliances, so size the members, not the orchestrator. It solves scaling, not the per-appliance inspection cost.

a software blade on Quantum gateways rather than a separate appliance; application steering and link selection with Check Point inspection in path
Check Point estates adding branch connectivity without introducing a second vendor's overlay.
The catch: Newer than Fortinet's or Versa's SD-WAN and documented at smaller scale; no separate inspected throughput figure is published, so size from the underlying gateway.

appliance capex plus threat-defence subscriptions; Firewall Management Center is a separate deployment; the natural choice where Cisco already owns the network layer
Cisco-centric networks that want the firewall, the switching and the routing under one support contract and one account team.
The catch: Model-by-model inspected throughput figures vary widely across the 1000, 3100 and 4200 series and are not summarised here — pull the figure for your exact model from the datasheet and confirm which engines were enabled. Management is a separate deployment to run.

appliance capex plus a Standard or Xstream Protection bundle; Sophos Central management is cloud-hosted and included, and the firewall shares signal with the Sophos endpoint agent
Mid-market estates — especially those already running Intercept X — that want firewall and endpoint sharing telemetry from one cloud console.
The catch: XGS models publish their inspection figures per model rather than as a headline series number; pull yours from the datasheet. Documented deployments are mid-market rather than large-enterprise, and the security heartbeat's value depends on running Sophos endpoints too.

per deployed sensor, on quote; watches east-west traffic for anomalies and feeds Sophos XDR — it detects, it does not enforce
Estates that need to see lateral movement inside the network, where a perimeter firewall has no visibility at all.
The catch: Detection only: no inspection throughput figure applies because it blocks nothing. It is an addition to a firewall, never a replacement, and its value is realised through Sophos XDR or MDR.

SecureEdge is licensed per site for the firewall and per user for the access side, with bundled bandwidth; the same platform spans appliance, virtual and cloud-delivered enforcement
Distributed mid-market estates — retail, manufacturing, many small sites — that want one platform for branch firewalls and remote access without an enterprise project.
The catch: Inspected throughput figures are published per appliance model rather than as a series headline; documented deployments are mid-market. The per-site plus per-user split makes quotes hard to compare against per-appliance rivals.

software-first, licensed by subscription on your hardware or Versa's; the same code runs the branch, the data centre and the SASE PoP, which is the architectural argument
Estates that want one software stack for SD-WAN, firewall and SASE rather than an appliance vendor's cloud service bolted on later.
The catch: Software-defined throughput depends on the hardware you run it on, so no single inspected figure applies — benchmark on your own platform. Smaller channel and support footprint in India than Fortinet or Palo Alto.

per branch site per year, with security services layered on the same instance; frequently sold through carriers as a managed service in India
Multi-site networks replacing MPLS that want routing, steering and inspection converged in software they can also run in the cloud later.
The catch: Often reached through a carrier's managed service rather than bought directly, which changes who holds the support relationship. No standalone inspected throughput figure — it is a function of your platform.
Physical applianceRules out Check Point Quantum Maestro — software or scale-out only, no physical appliance form. That leaves Fortinet FortiGate (FortiOS), Fortinet Secure SD-WAN, Palo Alto Strata NGFW (PA-Series), Check Point Quantum Force, Check Point Quantum SD-WAN, Cisco Secure Firewall (Firepower), Sophos Firewall (XGS), Sophos NDR, Barracuda Network Protection (SecureEdge), Versa NGFW and Versa Secure SD-WAN.
Virtual formRules out Check Point Quantum Maestro — no virtual form documented. That leaves Fortinet FortiGate (FortiOS), Fortinet Secure SD-WAN, Palo Alto Strata NGFW (PA-Series), Check Point Quantum Force, Check Point Quantum SD-WAN, Cisco Secure Firewall (Firepower), Sophos Firewall (XGS), Sophos NDR, Barracuda Network Protection (SecureEdge), Versa NGFW and Versa Secure SD-WAN.
Scale-out capacityRules out Fortinet FortiGate (FortiOS), Fortinet Secure SD-WAN, Palo Alto Strata NGFW (PA-Series), Check Point Quantum Force, Check Point Quantum SD-WAN, Cisco Secure Firewall (Firepower), Sophos Firewall (XGS), Sophos NDR, Barracuda Network Protection (SecureEdge), Versa NGFW and Versa Secure SD-WAN — capacity is bounded by the appliance model; growing means a bigger box. That leaves Check Point Quantum Maestro.
A published inspected figureRules nothing out on published terms. It flags Fortinet Secure SD-WAN — No headline inspected figure published for this product, Check Point Quantum Maestro — No headline inspected figure published for this product, Check Point Quantum SD-WAN — No headline inspected figure published for this product, Cisco Secure Firewall (Firepower) — No headline inspected figure published for this product, Sophos Firewall (XGS) — No headline inspected figure published for this product, Sophos NDR — No headline inspected figure published for this product, Barracuda Network Protection (SecureEdge) — No headline inspected figure published for this product, Versa NGFW — No headline inspected figure published for this product and Versa Secure SD-WAN — No headline inspected figure published for this product — marked on the cards, not removed.
A published TLS figureRules out Fortinet Secure SD-WAN, Check Point Quantum Maestro, Check Point Quantum SD-WAN, Cisco Secure Firewall (Firepower), Sophos NDR, Barracuda Network Protection (SecureEdge), Versa NGFW and Versa Secure SD-WAN — no TLS inspection throughput figure published; encrypted traffic performance is unproven on paper. That leaves Fortinet FortiGate (FortiOS), Palo Alto Strata NGFW (PA-Series), Check Point Quantum Force and Sophos Firewall (XGS).
SD-WAN integratedRules out Check Point Quantum Force and Cisco Secure Firewall (Firepower) — SD-WAN is a separate product from the same vendor; Check Point Quantum Maestro and Sophos NDR — no SD-WAN capability. That leaves Fortinet FortiGate (FortiOS), Fortinet Secure SD-WAN, Palo Alto Strata NGFW (PA-Series), Check Point Quantum SD-WAN, Sophos Firewall (XGS), Barracuda Network Protection (SecureEdge), Versa NGFW and Versa Secure SD-WAN.
Management includedRules out Fortinet FortiGate (FortiOS), Fortinet Secure SD-WAN, Palo Alto Strata NGFW (PA-Series) and Cisco Secure Firewall (Firepower) — central management is a separate product to licence and deploy. That leaves Check Point Quantum Force, Check Point Quantum Maestro, Check Point Quantum SD-WAN, Sophos Firewall (XGS), Sophos NDR, Barracuda Network Protection (SecureEdge), Versa NGFW and Versa Secure SD-WAN.
The vendor's own SASERules out Sophos NDR — no SASE platform from this vendor; a move means a second vendor and a parallel estate. That leaves Fortinet FortiGate (FortiOS), Fortinet Secure SD-WAN, Palo Alto Strata NGFW (PA-Series), Check Point Quantum Force, Check Point Quantum Maestro, Check Point Quantum SD-WAN, Cisco Secure Firewall (Firepower), Sophos Firewall (XGS), Barracuda Network Protection (SecureEdge), Versa NGFW and Versa Secure SD-WAN.
India support presenceRules nothing out on published terms. It flags Fortinet FortiGate (FortiOS) — India support reaches you through the channel rather than a documented in-country vendor operation, Fortinet Secure SD-WAN — India support reaches you through the channel rather than a documented in-country vendor operation, Check Point Quantum Force — India support reaches you through the channel rather than a documented in-country vendor operation, Check Point Quantum Maestro — India support reaches you through the channel rather than a documented in-country vendor operation, Check Point Quantum SD-WAN — India support reaches you through the channel rather than a documented in-country vendor operation, Sophos Firewall (XGS) — India support reaches you through the channel rather than a documented in-country vendor operation, Sophos NDR — India support reaches you through the channel rather than a documented in-country vendor operation, Barracuda Network Protection (SecureEdge) — India support reaches you through the channel rather than a documented in-country vendor operation, Versa NGFW — India support reaches you through the channel rather than a documented in-country vendor operation and Versa Secure SD-WAN — India support reaches you through the channel rather than a documented in-country vendor operation — marked on the cards, not removed.
Data-centre scaleRules nothing out on published terms. It flags Check Point Quantum SD-WAN — Unverified at data-centre scale, Sophos Firewall (XGS) — Unverified at data-centre scale, Sophos NDR — Unverified at data-centre scale and Barracuda Network Protection (SecureEdge) — Unverified at data-centre scale — marked on the cards, not removed.
The only throughput number worth readingEvery firewall datasheet leads with a raw firewall figure measured with inspection switched off. It tells you nothing about the box you will actually run. The figures on this page are the vendors' own threat-prevention-enabled numbers, and where a vendor publishes one it is stated with what was enabled: Palo Alto's PA-3400 series at 7.5–20 Gbps is measured with App-ID, IPS, antivirus, anti-spyware, WildFire, DNS Security, file blocking and logging on; Fortinet's 100F at 1.6 Gbps threat protection; Check Point's Force 9100 at 6.5 Gbps rising to 75 Gbps on the 29200. Where no headline inspected figure is published — Cisco, Sophos and Barracuda publish per model, Versa is software, Maestro is scale-out, Sophos NDR blocks nothing — it is marked and not derived. Never size from a raw figure, and never let a reseller do it either.
TLS inspection is where appliances actually fall overMost traffic is encrypted, and decryption is far more expensive than inspection. A box sized on threat-prevention throughput can still collapse when TLS inspection is switched on for real traffic. Palo Alto, Fortinet, Check Point and Sophos publish TLS or SSL inspection figures; the rest on this page do not — flagged, not ruled out. Ask for the figure with your own cipher mix, and plan the certificate deployment before the purchase order.
The subscription is the bigger numberOver five years the security subscription usually exceeds the appliance it runs on, and the renewal is where the surprise lives. Read which features are in the bundle you are quoted (Fortinet UTP vs Enterprise, Palo Alto's CDSS set, Check Point's threat-prevention package, Sophos Standard vs Xstream) and what the same bundle costs in year four. Central management — Panorama, FortiManager, Firewall Management Center — is a separate line at three of these vendors and included at two.
Refresh cycles and the SASE decisionAn appliance bought today is a five-year commitment; a SASE decision taken eighteen months from now strands most of it. Every vendor here except Sophos NDR sells its own SASE, which makes a phased move commercially easier — but it does not make the appliance's remaining book value disappear. If a SASE evaluation is plausible within the refresh window, size shorter or negotiate a migration path into the contract now.
India support and RMAPalo Alto and Cisco document in-country operations; the rest reach you through the channel, which is not worse but is different — the RMA clock, the spares depot and the escalation path belong to your partner, not the vendor. Real RMA turnaround by vendor and city is delivery-team knowledge: [TechBag to confirm].
Each shortlist states how you would size it and what the subscription does to the five-year number. If a SASE decision is plausible in your refresh window, start from the fourth row.
Why: FortiGate's ASIC design keeps the threat-protection figure high relative to price and includes SD-WAN; Sophos and Barracuda target the same band with cloud management included.
The trade-off: Fortinet's value assumes buying into the Fabric (FortiManager, FortiAnalyzer); Sophos and Barracuda are documented at mid-market rather than data-centre scale.
Why: Palo Alto's PA-3400 series publishes 7.5–20 Gbps threat prevention with every engine named; Check Point's Force line reaches 35–75 Gbps inspected on the 19100 and 29200; Maestro scales by adding gateways instead of replacing the chassis.
The trade-off: Maestro has no single inspected figure — it is the sum of its members, so the sizing work moves to the member appliances rather than disappearing.
Why: Versa is software-first and often delivered as a carrier-managed service in India; Fortinet includes SD-WAN in the FortiGate licence with no separate SKU; Check Point runs it as a blade on Quantum gateways.
The trade-off: None of the three publishes a separate inspected SD-WAN throughput figure — size from the underlying platform. Carrier-managed delivery changes who owns your support relationship.
Why: All three vendors sell their own SASE, so the appliance and the future cloud enforcement come from one contract and one policy model — Versa most literally, since the same software runs both.
The trade-off: Same-vendor continuity does not recover the appliance's book value. Negotiate the migration terms into the appliance contract now, while you still have leverage.
Why: One support contract and one account team across switching, routing and firewall is a real operational argument; the alternatives win on published inspection transparency.
The trade-off: Cisco's inspected figures must be pulled per model rather than read off a series headline, and Firewall Management Center is a separate deployment to run.
Why: Sophos Firewall and Intercept X exchange a security heartbeat from one cloud console; Fortinet does the equivalent through the Fabric; Sophos NDR adds east-west visibility a perimeter firewall cannot have.
The trade-off: The heartbeat's value depends on running that vendor's endpoint too — a second lock-in. NDR detects and enforces nothing.
Why: Check Point includes SmartConsole management, Versa includes its director, and Sophos Central is cloud-hosted and included — against Panorama, FortiManager and Firewall Management Center as separate lines.
The trade-off: Included management is not always equivalent management: compare multi-site policy, role separation and reporting depth, not just the licence line.
Why: Barracuda SecureEdge licenses per site for the firewall and per user for access on one platform; Sophos and Fortinet cover the same estate from cloud consoles.
The trade-off: Barracuda's split meter is hard to compare against per-appliance quotes — normalise to a per-site annual cost including the subscription before choosing.
Every datasheet publishes a ladder of figures that fall as you enable the features you bought the box for. Read them in this order, and size on the last one you will actually run.
Figure 1
Raw firewall throughput
Packets forwarded with inspection off. The number on the front page, the number in the reseller's email, and the number that describes no box anyone deploys. Useful only for comparing interface capacity.
Figure 2
IPS or application-control throughput
One engine enabled. Better, still not your configuration — nobody buys a next-generation firewall to run one engine.
Figure 3
Threat prevention enabled
The engines you actually paid for, running together, with logging on. This is the figure to size against. Palo Alto's PA-3400 series: 7.5–20 Gbps with threat prevention enabled. Fortinet 100F: 1.6 Gbps threat protection. Check Point Force 9100: 6.5 Gbps threat prevention, rising to 75 Gbps on the 29200.
Figure 4
TLS inspection enabled
Lower again, and the one most estates need because most traffic is encrypted. Published by Palo Alto, Fortinet, Check Point and Sophos; not published by the others here — flagged, not assumed.
The sizing test
Ask these before the quote, in this order.
The three-line cost
An appliance purchase is never one number.
Firewalls scale by inspected throughput and by site count, and the two need different answers. The bill follows the appliance tier; the operational load follows the number of policies and consoles.
Sizing honesty is the constraint
Put this in your PoC
Run the proof of concept with TLS inspection on and your own traffic. If the vendor resists, that is the finding.
TLS and management are the constraint
Put this in your PoC
Ask three vendors for their inspected and TLS figures on the exact models quoted, in writing, with the datasheet date. The spread will decide the shortlist.
Architecture and the refresh horizon are the constraint
Put this in your PoC
Model the five-year cost of appliances plus subscriptions against the same estate on SASE. If nobody has done that comparison, the refresh decision is being made blind.
Fortinet, Palo Alto, Check Point, Cisco and Versa document data-centre-scale deployments; Sophos Firewall, Sophos NDR, Barracuda Network Protection and Check Point Quantum SD-WAN are flagged unverified above 10 Gbps inspected. Where a specific product strains for your traffic profile: [TechBag to confirm].
The appliance is the easy part. The rule base — grown over years, full of exceptions nobody remembers — is what actually moves, and it rarely moves cleanly.
The rule base
Thousands of rules, many redundant, some load-bearing for an application nobody can name. Automated converters get most of the way; the last 10% is manual and is where outages come from.
Certificates and TLS
The decryption trust chain is per platform: new certificates deployed to every endpoint before the cut-over, or inspection silently stops working for someone.
The parallel run
Both estates live while sites cut over one at a time, which means two support contracts and two subscription bills for a quarter or more.
The remaining book value
The appliance you are leaving is on a depreciation schedule that does not care about your architecture decision. Finance will ask; have the number before they do.
Rule-base conversion effort, certificate rollout and parallel-run cost for your estate: [TechBag to confirm] — TechBag scopes it from your rule count, site count and refresh dates.
What you may already hold, the appliance and subscription shape at three estate sizes, and what the licence line leaves out — which, for firewalls, starts with the box you are still paying for.
Four things that may already inspect part of this. Two of them genuinely do.
If the capability you need is already inside a subscription you renew every year, we say so. It costs us a sale and saves you one.
Firewall pricing is quoted, not listed — the honest thing to publish is the shape of the bill rather than invented per-unit numbers. Three lines at three estate sizes, with the vendors that publish per-user or per-site meters named explicitly, and the India-built and mid-market options covered because no global comparison does.
The published meters — where they exist, and the mid-market and India options
TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.
If SASE arrives mid-refresh, the remaining book value does not disappear — and the parallel run is a real line for a quarter or more. This is the double-spend the category opens with, and it belongs in the business case before the purchase order.
The links the firewall sits on, the bandwidth upgrade the inspection makes necessary, and the TLS certificate rollout to every endpoint — none of it is in the quote, all of it is in the timeline.
Policy migration, exception review, and the people to run the console day to day. A firewall with an unaudited rule base is an expensive router. Your hours: [TechBag to confirm].
Documented behaviour and sizing outcomes, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover at the traffic peak.
Sizing on datasheet throughput and hitting a wall with TLS on
The headline figure was raw; the box met a fraction of it once decryption was enabled for real traffic. Size on the threat-prevention figure, then check the TLS figure.
Subscription renewals costing more than the hardware
The appliance was negotiated hard and the year-four renewal was not. Over five years the subscription is usually the larger number — get year four in writing at signature.
HA pairs that fail over but drop sessions
The cluster worked in the test and dropped long-lived sessions in production. Test failover with real application sessions, not pings.
RMA times that don't match the SLA in India
The contract said four hours; the spare was in another country. Confirm the depot, the city and the escalation path with your partner, in the contract.
Buying a five-year appliance eighteen months before a SASE decision
Two enforcement estates, overlapping capability, and a depreciation schedule that does not care. Reconcile the roadmap before the refresh, not after.
The bundle that didn't include the feature demonstrated
Sandboxing or DNS security was in the demo and not in the quoted tier. Compare enabled features, not model numbers.
Certificate deployment stalling the inspection rollout
TLS inspection was licensed, configured and never switched on because the certificates never reached the endpoints. It is a device-management project, and it belongs in the plan.
A rule base nobody audited
Years of accumulated exceptions, some load-bearing, most redundant. Migration exposed it, and the outage came from the 10% no converter could translate.
Vendor-neutral. No gated content.