Security Calculators

Chapter 9 — Five interactive real-time calculators for network security perimeter sizing and planning


📡 Calculator 1: Network Bandwidth Sizing

Size required provisioned bandwidth for internet egress or WAN links, accounting for peak utilization targets, growth projections, and redundancy requirements.

Current measured peak, e.g., 2.0 Gbps
Recommended: 60–70%
70%
Typical: 20–40% per year
30%
Typical: 2–3 years
2 yr
N+1 adds 30% headroom for failover
Future Peak
Gbps
Base Capacity
Gbps
Recommended Circuit
Gbps

💾 Calculator 2: SIEM Log Storage Capacity

Estimate total SIEM storage requirements for hot (fast-access) and cold (archive) retention tiers, accounting for event rate, event size, compression, and indexing overhead.

Typical enterprise: 5,000–50,000 EPS
Firewall logs: 500–1500 bytes typical
Fast-access tier for active investigation
45d
Archive tier for compliance (total period)
365d
0.6 = 40% size reduction
0.60
0.4 = 60% size reduction
0.40
Daily Raw Data
GB/day
Hot Storage
TB
Cold Storage
TB
Total Required
TB

⚡ Calculator 3: PoE Power Budget

Ensure PoE switches and UPS can support perimeter security devices (CCTV cameras, wireless APs, IoT sensors) with appropriate power headroom and UPS runtime.

Total count of cameras, APs, sensors
IEEE 802.3at/bt: 4/7/15.4/30/60/90W
% of devices drawing max power simultaneously
85%
Typical: 0.88–0.95
0.92
Minimum runtime during power outage
15min
Typically 230V (EU) or 120V (US)
Total Device Load
Watts
Required PoE Budget
Watts
UPS Energy Needed
Wh
UPS Battery (Ah)
Ah

🛡 Calculator 4: Firewall Throughput & Session Sizing

Determine the minimum required NGFW throughput, CPS (connections per second), and concurrent session capacity based on current traffic measurements and safety headroom factors.

Measured at 95th percentile with all inspection enabled
% of traffic requiring SSL/TLS decryption
60%
Measured peak CPS from monitoring
Measured peak from firewall monitoring
Recommended: 1.5× (50% headroom)
1.5×
Recommended: 2.0× for spike resilience
2.0×
Min L7 Throughput
Gbps
Min TLS Inspect TPS
Gbps
Min CPS Required
K/sec
Min Sessions Required
Million

⏳ Calculator 5: HA Failover RTO Budget

Estimate the total Recovery Time Objective (RTO) for a firewall HA failover event, breaking down the time budget across detection, convergence, and restoration phases.

Typical: 200–1000ms
Typical: 3–5 missed before failover
State sync preserves existing sessions
Time for routing to re-converge after failover
30s
Time for apps to re-establish sessions after failover
10s
Your SLA requirement for failover
Detection Time
seconds
Switchover Time
seconds
Total Estimated RTO
seconds
RTO vs Target