North-South Security Calculator
Derate a perimeter inspection stack stage by stage to find real capacity, added latency and unmonitored public endpoints.
Inputs
For example firewall, IPS, TLS inspection, WAF.
Effective Perimeter Capacity
41.76Gbps
Total North-South Traffic
30.00Gbps
Perimeter Utilisation
71.8%
Headroom
11.76Gbps
Latency Added by the Chain
1.60ms
Endpoint Inspection Coverage
80.0%
Endpoints Bypassing Inspection
24
Step by step
Values used
Peak ingress traffic = 12 Gbps; Peak egress traffic = 18 Gbps; Inspection stages in the chain = 4 stages; Throughput lost per stage = 15 %; Rated perimeter capacity = 80 Gbps; Latency added per stage = 0.4000 ms; Internet-facing endpoints = 120 endpoints; Endpoints behind the inspection stack = 96 endpoints
North-South Security
effective capacity = rated capacity × (1 − per-stage derate)^stages; added latency = stages × latency per stage.
Effective Perimeter Capacity
= 41.76 Gbps
Total North-South Traffic
= 30.00 Gbps
Perimeter Utilisation
= 71.8
Headroom
= 11.76 Gbps
Latency Added by the Chain
= 1.60 ms
Endpoint Inspection Coverage
= 80.0
How it works
Service chains compound multiplicatively, not additively: four stages each costing 15% leave 0.85⁴, or about 52% of rated capacity — not 40%. Latency, by contrast, is additive, so each stage adds its full delay to every session in both directions. The endpoints bypassing the stack matter more than the capacity number: one internet-facing service that routes around the perimeter makes the whole chain irrelevant for that path.
Formula
North-South Security
effective capacity = rated capacity × (1 − per-stage derate)^stages; added latency = stages × latency per stage.
- per-stage derate
- Throughput lost to each inspection function in the chain
- stages
- Number of chained inspection functions traffic traverses
Frequently Asked Questions
How is North-South Security calculated?
effective capacity = rated capacity × (1 − per-stage derate)^stages; added latency = stages × latency per stage. Service chains compound multiplicatively, not additively: four stages each costing 15% leave 0.85⁴, or about 52% of rated capacity — not 40%. Latency, by contrast, is additive, so each stage adds its full delay to every session in both directions.
Why does North-South Security matter?
The endpoints bypassing the stack matter more than the capacity number: one internet-facing service that routes around the perimeter makes the whole chain irrelevant for that path.
What values do I need to enter?
This calculator takes 8 inputs: Peak ingress traffic, Peak egress traffic, Inspection stages in the chain, Throughput lost per stage, Rated perimeter capacity, Latency added per stage, Internet-facing endpoints, Endpoints behind the inspection stack. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Is a longer inspection chain always better security?
No. Each stage adds latency, a failure domain and an operational owner, and overlapping stages often detect the same things twice while nobody owns the gaps between them. Consolidating four single-function appliances into one platform that runs the same four engines usually gives better coverage at lower latency, provided you size the derate honestly.
You might also need
- East-West Security CalculatorCommonly used together
- DMZ Capacity CalculatorCommonly used together
- Network Security Score CalculatorCommonly used together
- DDoS Capacity CalculatorCommonly used together
- Reverse Proxy Security CalculatorCommonly used together
- DDoS Mitigation CalculatorCommonly used together