Firewall Technical Catalog
This page provides a more technical, model-wise catalog for firewall platforms supported by MBAS Innovations. It is structured to help customers review public datasheet values, compare branch-fit models, and move into final sizing with MBAS.
Catalog notes
Values on this page are based on current public vendor datasheets, vendor comparison tables, or public vendor-datasheet mirrors available at build time. Bundle names and commercial combinations can vary by region, term, support level, and distributor quote.
Throughput
Firewall, NGFW, IPS, threat, or TLS values are shown exactly as publicly available source families present them.
Interfaces
Port summaries focus on practical presales comparison rather than deep board-level documentation.
HA details
HA information highlights whether the model family is commonly positioned for redundancy or whether details remain quote-dependent.
Licensing
Licensing bundle notes identify the public bundle family, while final commercials still require distributor or vendor quoting.
Palo Alto
PA-400 family entries are positioned for branch and SMB environments that want premium application-aware next-generation firewall security.
| Model | Best fit | Firewall throughput | Security throughput | VPN capacity | Ports / interfaces | HA details | Licensing bundles | Source note |
|---|---|---|---|---|---|---|---|---|
| PA-410 | Branch / SMB | 1.9 / 1.5 Gbps appmix | 940 Mbps threat prevention | N/A in public family snippet | Fixed desktop interfaces; PA-400 family | Active/Passive supported at family level | Subscriptions sold separately | Family datasheet published by Palo Alto Networks |
| PA-440 | Growing branch | 2.6 / 2.3 Gbps appmix | 1.0 Gbps threat prevention | N/A in public family snippet | Fixed desktop interfaces; PA-400 family | Active/Passive supported at family level | Subscriptions sold separately | Family datasheet published by Palo Alto Networks |
| PA-450 | Larger branch | 4.1 / 3.6 Gbps appmix | 1.8 Gbps threat prevention | N/A in public family snippet | Fixed desktop interfaces; PA-400 family | Active/Passive supported at family level | Subscriptions sold separately | Family datasheet published by Palo Alto Networks |
| PA-460 | Large branch | 5.2 / 4.7 Gbps appmix | 2.2 Gbps threat prevention | N/A in public family snippet | Fixed desktop interfaces; PA-400 family | Active/Passive supported at family level | Subscriptions sold separately | Family datasheet published by Palo Alto Networks |
Fortinet
FortiGate entries provide broad SMB and branch coverage with practical security, VPN, and operational flexibility.
| Model | Best fit | Firewall throughput | Security throughput | VPN capacity | Ports / interfaces | HA details | Licensing bundles | Source note |
|---|---|---|---|---|---|---|---|---|
| FortiGate 40F | Small office | 5.0 / 5.0 / 3.0 Gbps UDP | N/A in current source set | 6.0 Gbps IPsec VPN | 5 x GE RJ45 | HA capable | FortiCare + FortiGuard bundles vary | Vendor datasheet family entry |
| FortiGate 60F | SMB edge | 10 / 10 / 6 Gbps UDP | 1.0 Gbps threat protection | 6.5 Gbps IPsec VPN | 10 x GE RJ45 | HA capable | FortiCare + FortiGuard bundles vary | Vendor datasheet family entry |
| FortiGate 80F | Growing branch | 10 / 10 / 9 Gbps UDP | 1.4 Gbps threat protection | 6.5 Gbps IPsec VPN | 10 x GE RJ45 + 2 x GE SFP | HA capable | FortiCare + FortiGuard bundles vary | Vendor or mirrored datasheet family entry |
| FortiGate 100F | Larger branch | 20 / 20 / 12 Gbps UDP | 2.2 Gbps threat protection | 11 Gbps IPsec VPN | 16 x GE RJ45 + 4 x GE SFP | HA capable | FortiCare + FortiGuard bundles vary | Vendor datasheet family entry |
Check Point
Quantum Spark entries align to compact branch deployments where policy-led protection and gateway simplicity matter.
| Model | Best fit | Firewall throughput | Security throughput | VPN capacity | Ports / interfaces | HA details | Licensing bundles | Source note |
|---|---|---|---|---|---|---|---|---|
| 1530 Pro | Small branch | N/A in current source set | 340 Mbps threat prevention; 600 Mbps NGFW; 660 Mbps IPS | Site-to-site and remote access supported | 5 x 1G LAN, 1 x 1G WAN | Cluster/HA not positioned as standard pair bundle | Quantum Spark subscriptions; SD-WAN and IoT add-ons listed | Vendor datasheet / official PDF mirror |
| 1550 Pro | Growing branch | N/A in current source set | 450 Mbps threat prevention; 800 Mbps NGFW; 900 Mbps IPS | Site-to-site and remote access supported | 5 x 1G LAN, 1 x 1G WAN | Cluster/HA not positioned as standard pair bundle | Quantum Spark subscriptions; SD-WAN and IoT add-ons listed | Vendor datasheet / official PDF mirror |
| 1590 Pro | Larger branch | N/A in current source set | 610 Mbps threat prevention; 1.0 Gbps NGFW; 1.1 Gbps IPS | Site-to-site and remote access supported | 8 x 1GbE LAN switch, 1 x 1GbE DMZ, 1 x 1GbE WAN | Cluster/HA not positioned as standard pair bundle | Quantum Spark subscriptions; SD-WAN and IoT add-ons listed | Vendor datasheet / official PDF mirror |
Sophos
Sophos XGS desktop entries suit SMB and branch offices looking for all-in-one security with easy model comparison.
| Model | Best fit | Firewall throughput | Security throughput | VPN capacity | Ports / interfaces | HA details | Licensing bundles | Source note |
|---|---|---|---|---|---|---|---|---|
| XGS 87 | Starter SMB | 3700 Mbps firewall | 240 Mbps threat protection; 1015 Mbps IPS; 375 Mbps TLS | VPN supported | 4 x GE copper, 1 x SFP | Single PSU desktop | Standard / Xstream licensing varies by quote | Comparison table aligned to Sophos XGS desktop family |
| XGS 107 | Small branch | 7000 Mbps firewall | 330 Mbps threat protection; 1355 Mbps IPS; 420 Mbps TLS | VPN supported | 8 x GE copper, 1 x SFP | Optional 2nd power supply | Standard / Xstream licensing varies by quote | Comparison table aligned to Sophos XGS desktop family |
| XGS 116 | Growing branch | 7700 Mbps firewall | 685 Mbps threat protection; 2000 Mbps IPS; 650 Mbps TLS | VPN supported | 8 x GE copper, 1 x SFP, 1 x GE PoE | Optional 2nd power supply | Standard / Xstream licensing varies by quote | Comparison table aligned to Sophos XGS desktop family |
| XGS 126 | Larger SMB | 10500 Mbps firewall | 900 Mbps threat protection; 2600 Mbps IPS; 800 Mbps TLS | VPN supported | 10 x GE copper, 2 x SFP, 2 x GE PoE | Optional 2nd power supply | Standard / Xstream licensing varies by quote | Comparison table aligned to Sophos XGS desktop family |
SonicWall
TZ Gen 7 entries target modern SMB and branch offices that want desktop NGFW capability with SD-Branch alignment.
| Model | Best fit | Firewall throughput | Security throughput | VPN capacity | Ports / interfaces | HA details | Licensing bundles | Source note |
|---|---|---|---|---|---|---|---|---|
| TZ270 | Small office | 3.0 Gbps firewall | 750 Mbps threat prevention | 1.5 Gbps IPsec VPN | 8 ports; multi-gig capable family | HA supported on platform family | Essential / Advanced Protection bundles vary | Official SonicWall datasheet family |
| TZ370 | Growing branch | 6.0 Gbps firewall | 1.5 Gbps threat prevention | 3.0 Gbps IPsec VPN | 8 ports; multi-gig capable family | HA supported on platform family | Essential / Advanced Protection bundles vary | Official SonicWall datasheet family |
| TZ470 | Mid-sized branch | 9.0 Gbps firewall | 2.2 Gbps threat prevention | 4.0 Gbps IPsec VPN | 10 ports; multi-gig capable family | HA supported on platform family | Essential / Advanced Protection bundles vary | Official SonicWall datasheet family |
Barracuda
CloudGen entries are useful in branch-centric and WAN-aware deployments where secure distributed connectivity is important.
| Model | Best fit | Firewall throughput | Security throughput | VPN capacity | Ports / interfaces | HA details | Licensing bundles | Source note |
|---|---|---|---|---|---|---|---|---|
| F18 | Small branch | N/A in current source set | N/A in current source set | VPN supported | 5 x GbE | No bundled HA note in current source set | Energize Updates / Instant Replacement vary | Barracuda CloudGen public datasheet family |
| F80 | Branch office | N/A in current source set | N/A in current source set | VPN supported | 5 x GbE | No bundled HA note in current source set | Energize Updates / Instant Replacement vary | Barracuda CloudGen public datasheet family |
| F180 | Growing branch | N/A in current source set | N/A in current source set | VPN supported | 12 x GbE + 4 x SFP | Dual external PSU option by family | Energize Updates / Instant Replacement vary | Barracuda CloudGen public datasheet family |
| F280 | Larger branch | N/A in current source set | N/A in current source set | VPN supported | 12 x GbE + 4 x SFP | Dual external PSU option by family | Energize Updates / Instant Replacement vary | Barracuda CloudGen public datasheet family |
How MBAS finalizes sizing
Public datasheets are useful for shortlisting, but final selection should still be validated against internet bandwidth, encrypted traffic mix, branch topology, VPN concurrency, HA policy, rack or desktop preference, and license term. MBAS can convert this shortlist into a final BOM, deployment scope, and proposal package.
Need exact model and bundle selection?
Use the BOM Selector or proposal workflow to validate performance headroom, interface requirements, redundancy design, and subscription scope before final purchase.