SSL Inspection Calculator
Size TLS interception: how much traffic you actually decrypt after bypass, and whether the device's derated capacity covers it.
Inputs
Decryption Capacity Utilisation
122.4%
Traffic Actually Decrypted
6.12Gbps
Derated Inspection Capacity
5.00Gbps
TLS Bypassed by Policy
1.08Gbps
Share of All Traffic Inspected
76.5%
Handshake Capacity Used
33.3%
Sizing Verdict
Undersized — decrypt load exceeds inspection capacity
Step by step
Values used
Rated L4 throughput of the device = 20 Gbps; Peak offered load = 8 Gbps; Share of traffic that is TLS = 90 %; Share of TLS bypassed by policy = 15 %; Throughput remaining with TLS inspection enabled = 25 %; TLS handshakes per second = 4,000 handshakes/s; Device handshake capacity = 12,000 handshakes/s
SSL Inspection
decrypted = offered load × TLS share × (1 − bypass share); capacity = rated throughput × TLS derate (typically 20–30%).
Decryption Capacity Utilisation
= 122.4
Traffic Actually Decrypted
= 6.12 Gbps
Derated Inspection Capacity
= 5.00 Gbps
TLS Bypassed by Policy
= 1.08 Gbps
Share of All Traffic Inspected
= 76.5
Handshake Capacity Used
= 33.3
How it works
TLS interception is the most expensive inspection a device performs: it terminates the client session, re-establishes an outbound session and does full crypto in both directions, which typically leaves only 20–30% of rated throughput. Bypass policy is the main lever — every category you exempt comes straight off the decrypt load. TLS inspection sizing errors are the most common cause of security-driven outages, because the derate is a factor of four or five and datasheets lead with the L4 number.
Formula
SSL Inspection
decrypted = offered load × TLS share × (1 − bypass share); capacity = rated throughput × TLS derate (typically 20–30%).
- TLS derate
- Fraction of rated L4 throughput left once decrypt and re-encrypt are enabled
- bypass share
- Portion of TLS exempted from interception by policy
Frequently Asked Questions
How is SSL Inspection calculated?
decrypted = offered load × TLS share × (1 − bypass share); capacity = rated throughput × TLS derate (typically 20–30%). TLS interception is the most expensive inspection a device performs: it terminates the client session, re-establishes an outbound session and does full crypto in both directions, which typically leaves only 20–30% of rated throughput. Bypass policy is the main lever — every category you exempt comes straight off the decrypt load.
Why does SSL Inspection matter?
TLS inspection sizing errors are the most common cause of security-driven outages, because the derate is a factor of four or five and datasheets lead with the L4 number.
What values do I need to enter?
This calculator takes 7 inputs: Rated L4 throughput of the device, Peak offered load, Share of traffic that is TLS, Share of TLS bypassed by policy, Throughput remaining with TLS inspection enabled, TLS handshakes per second, Device handshake capacity. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
What has to be bypassed regardless of capacity?
Anything using certificate pinning will simply break — many mobile apps, update services and API clients validate the expected certificate and reject your interception certificate. Add to that whatever your jurisdiction or policy exempts on privacy grounds, typically banking, healthcare and government sites. Build the bypass list from pinning failures first, then privacy, then capacity.