Capacity runway chart
Current and horizon utilization will appear after calculation.
Estimate when a firewall will reach its rule, expanded-entry, capacity-unit, or object limitโand how many rules must be retired to stay below your planning ceiling. This is rulebase capacity planning, not throughput sizing: it does not size bandwidth, sessions per second, TLS inspection, or packet-processing performance.
Example data loaded: the starting values describe an illustrative enterprise edge. Replace them with your own counts before using the result.
Current and horizon utilization will appear after calculation.
| Month | Low primary | Expected primary | High primary | Primary utilization | Address / util. | Service / util. | Groups / util. |
|---|---|---|---|---|---|---|---|
| Calculate capacity to populate the forecast. | |||||||
Use read-only views or exports and keep the count, limit, and scope aligned. Average additions and retirements over several representative months; exclude an exceptional migration from the normal rate and enter it as a one-time spike.
CheckCapacity API estimates WCU for a JSON rule set. AWS explains that WCU varies by rule complexity and that a web ACL has a 5,000-WCU maximum. AWS WAF capacity-unit documentation.show system state filter cfg.general.max* reports model limits; the official knowledge base also lists maximum security policies for several platforms. Confirm the current PAN-OS release and whether the value applies per device or virtual system. Palo Alto rule-object limits.Planning ceiling: hard limit ร selected utilization
Expected net growth: monthly additions โ monthly retirements
Low / high net growth: additions ร (1 โ variation) โ retirements
Expected runway: the first simulated month where expected usage, including a configured temporary spike, meets the planning ceiling. The earliest threshold uses the high-growth scenario.
Object net growth: requested additions ร (1 โ reuse or consolidation %) โ object retirements
Cleanup target: max(0, expected count at horizon โ planning ceiling). A temporary spike is added once and removed after its duration; it is not treated as recurring growth.
Logical rules, expanded entries, and vendor units are not interchangeable. AWS WAF WCU reflects relative processing cost, while Cisco documents that object groups can expand logical rules into multiple deployed ACEs. The calculator blocks a documented preset if its metric and the selected capacity basis no longer match.
Inputs: 1,800 current logical rules; 10,000 maximum; 168 added and 55 retired monthly; 75% planning ceiling; 12-month horizon.
Substitution: ceiling = 10,000 ร 0.75 = 7,500; net growth = 168 โ 55 = 113/month; runway = (7,500 โ 1,800) รท 113 = 50.4 months; horizon count = 1,800 + 12 ร 113 = 3,156.
Decision: no horizon cleanup is required, but growth measurements should be refreshed because the expected ceiling is roughly four years away.
Inputs: 9,000 current entries; 15,000 maximum; 260 added and 100 retired monthly; 80% ceiling; 2,000-entry spike beginning month 3 and removed after 6 months.
Substitution: ceiling = 15,000 ร 0.80 = 12,000; normal net = 160/month; month 7 during overlap = 9,000 + 7 ร 160 + 2,000 = 12,120; month 9 after removal = 9,000 + 9 ร 160 = 10,440.
Decision: the temporary migration breaches the planning ceiling even though normal growth does not yet do so. Stage cleanup earlier, reduce overlap, or add temporary platform headroom.
Inputs: 280 current rules; 1,500 maximum; 10 added and 14 retired monthly; 70% ceiling.
Substitution: net growth = 10 โ 14 = โ4/month; the ceiling is 1,500 ร 0.70 = 1,050.
Decision: expected runway is stable because the count is shrinking. Continue governance: negative primary growth does not prove object pools or future projects are safe.
There is no universal number. The supported count depends on vendor, model, software release, policy type, virtual context, and whether objects expand into deployed entries. Use the official model limit or a verified device-reported limit.
A hard limit is enforced by the platform. An operational ceiling is an organization-selected planning threshold below that maximum, leaving headroom for urgent changes, migration overlap, and uncertainty.
No. One logical policy can expand into multiple deployed entries when object groups or other conditions are compiled. Compare a deployed-entry count only with a deployed-entry limit.
Vendor behavior differs. Use the calculator choice that matches the count and limit reported by your platform; disabled rules can still create operational review and cleanup work even when excluded from an enforced limit.
Do not add unrelated scopes unless the vendor enforces one shared limit across them. Run one calculation per enforced scopeโsuch as per device, policy, virtual system, VDOM, domain, account, or Regionโor aggregate only when the official quota is aggregate.
Use an organization-approved operational ceiling based on emergency-change demand, migration overlap, measurement uncertainty, and platform behavior. Example values such as 70% or 80% are policy choices, not universal safe limits.
Negative growth means monthly retirements exceed additions. The calculator reports the runway as stable, but reviews should continue because project spikes and other capacity pools can still create constraints.
Prefer cleanup or consolidation when confirmed stale candidates cover the forecast requirement, duplicate objects drive expansion, or governance can make additions sustainable. Consider expansion when valid business rules exceed supported capacity despite effective cleanup, or a temporary migration cannot fit within safe headroom.
AWS WAF uses weighted web ACL capacity units whose cost varies by rule complexity. AWS Network Firewall documents stateful and stateless rule capacity per firewall policy. They are different metrics and must not be compared directly.
Yes. Inputs and results stay in the browser unless you choose Share, Copy, or Download.
This is an infrastructure planning aid. Confirm vendor support limits, licensed features, management-server limits, HA behavior, audit requirements, security policy ownership, and change-control approval before making firewall changes.