Skip to content
Calcrivo

North-South Security Calculator

Derate a perimeter inspection stack stage by stage to find real capacity, added latency and unmonitored public endpoints.

Inputs

Gbps
Gbps
stages

For example firewall, IPS, TLS inspection, WAF.

%
Gbps
ms
endpoints
endpoints

Effective Perimeter Capacity

41.76Gbps

Total North-South Traffic

30.00Gbps

Perimeter Utilisation

71.8%

Headroom

11.76Gbps

Latency Added by the Chain

1.60ms

Endpoint Inspection Coverage

80.0%

Endpoints Bypassing Inspection

24

Step by step

  1. Values used

    Peak ingress traffic = 12 Gbps; Peak egress traffic = 18 Gbps; Inspection stages in the chain = 4 stages; Throughput lost per stage = 15 %; Rated perimeter capacity = 80 Gbps; Latency added per stage = 0.4000 ms; Internet-facing endpoints = 120 endpoints; Endpoints behind the inspection stack = 96 endpoints

  2. North-South Security

    effective capacity = rated capacity × (1 − per-stage derate)^stages; added latency = stages × latency per stage.

  3. Effective Perimeter Capacity

    = 41.76 Gbps

  4. Total North-South Traffic

    = 30.00 Gbps

  5. Perimeter Utilisation

    = 71.8

  6. Headroom

    = 11.76 Gbps

  7. Latency Added by the Chain

    = 1.60 ms

  8. Endpoint Inspection Coverage

    = 80.0

How it works

Service chains compound multiplicatively, not additively: four stages each costing 15% leave 0.85⁴, or about 52% of rated capacity — not 40%. Latency, by contrast, is additive, so each stage adds its full delay to every session in both directions. The endpoints bypassing the stack matter more than the capacity number: one internet-facing service that routes around the perimeter makes the whole chain irrelevant for that path.

Formula

North-South Security

effective capacity = rated capacity × (1 − per-stage derate)^stages; added latency = stages × latency per stage.

per-stage derate
Throughput lost to each inspection function in the chain
stages
Number of chained inspection functions traffic traverses

Frequently Asked Questions

How is North-South Security calculated?

effective capacity = rated capacity × (1 − per-stage derate)^stages; added latency = stages × latency per stage. Service chains compound multiplicatively, not additively: four stages each costing 15% leave 0.85⁴, or about 52% of rated capacity — not 40%. Latency, by contrast, is additive, so each stage adds its full delay to every session in both directions.

Why does North-South Security matter?

The endpoints bypassing the stack matter more than the capacity number: one internet-facing service that routes around the perimeter makes the whole chain irrelevant for that path.

What values do I need to enter?

This calculator takes 8 inputs: Peak ingress traffic, Peak egress traffic, Inspection stages in the chain, Throughput lost per stage, Rated perimeter capacity, Latency added per stage, Internet-facing endpoints, Endpoints behind the inspection stack. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Is a longer inspection chain always better security?

No. Each stage adds latency, a failure domain and an operational owner, and overlapping stages often detect the same things twice while nobody owns the gaps between them. Consolidating four single-function appliances into one platform that runs the same four engines usually gives better coverage at lower latency, provided you size the derate honestly.

You might also need