Specifications include, but are not limited to: Tier 1 Branch Firewall These devices will serve branches that are offering network-intensive services to other locations. Devices will have higher throughput requirements and may have high availability requirements. Tier 2 Branch Firewall Tier 2 Devices are for use at branches that are only consuming network services. Core Firewall All internet-bound traffic will pass through the Core Firewall, as well as traffic to and from central servers. Because of this, it will have higher throughput requirements than branch devices. High availability should be assumed for core networking devices. Throughput and Latency Bandwidth requirements are constantly growing over time, and the penalty for not keeping up is longer wait times for all users of the network. This causes a slowdown in productivity for staff and patrons alike and can have a negative impact in user confidence in Library-provided equipment. With this in mind, the following requirements and recommendations have been established. Note that devices MUST be capable of the following requirements with all firewall features enabled and in use. All Firewalls • Site-to-site VPN connections MUST run at full line speed of Internet/WAN interface. • Traffic passing through an interface under 80% load MUST NOT introduce more than 3ms of latency. Tier 1 Branch Firewall • Internet/WAN physical interfaces MUST be capable of at least 10 Gbps (SFP+ or better). • Aggregate traffic passing through device is REQUIRED to pass at 12 Gbps or higher (calculated as 10 Gbps + 20% safety/expansion margin). Tier 2 Branch Firewall • Internet/WAN physical interfaces MUST be capable of at least 10 Gbps (SFP+ or better). • Aggregate traffic passing through device is REQUIRED to pass at 6 Gbps or higher (calculated as 5 Gbps + 20% safety/expansion margin). Core Firewall • Internet physical interface MUST be capable of at least 10 Gbps (SFP+ or better). • Six or more physical interfaces for internal use MUST be capable of at least 25 Gbps (SFP28 or better).