Enterprise Firewall Performance Tester


Enterprise IT
Network Security
System Integrators
Data Centers


Network Security


Performance Testing
Functional Testing
Quality of Service

About Safire

Enterprise firewalls improve network security by segmenting corporate LANs. However, each of the advanced security functions (e.g. antivirus, app-control, IPS and SSL decryption) has a performance penalty. Combined, these features can seriously reduce network performance (in some instance up to 90%) – frustrating users and reducing business performance.

Safire is the only solution on the market that solves this problem quickly and cost-effectively.

Simply connect Safire to your firewall, define a traffic profile that matches your network, and select the features you want to measure. Initiate the test and in minutes Safire will compile a PDF report detailing how each feature impacts performance, with easy-to-understand graphs that clearly pinpoint the firewall’s breaking point and a wealth of other data.

Safire is a simple and cost-efficient tool for testing firewall performance prior to deployment:

  • Comparing different enterprise firewalls prior to purchasing
  • Validating performance prior to installation

It can also pay to test firewall performance after it has been deployed:

  • Checking performance after firewall software updates and patches
  • Verifying performance following significant LAN traffic changes
  • Measuring performance impact of emerging applications

The no-fuss way to test

Enterprise Firewall Performance


Enterprise Firewalls

Firewalls are essential for securing corporate networks. Understanding their impact on network performance is essential for business efficiency.

That’s why Xena developed Safire.


IT Managers

IT managers must constantly balance the need for network security with the need for fast, ubiquitous access to network resources.

Firewalls are great for security but they can seriously impact network performance. That’s frustrating for users and bad for business. Up until now, pinpointing the problem has been a real headache for IT managers. That’s why Xena developed Safire.

System Diagram



Safire is controlled via a simple web-interface called SafireManager. Users are guided through the few simple steps of connecting to the firewall and defining each variable relevant to the test – which network scenario and traffic mix to use, how many users to be emulated, which firewall features to test and so on. This typically takes only a few  clicks, and then Safire is ready to start testing.

Every network has a unique traffic profile defined by the applications being used, the number of users, the data and security policies, the network topology and so on. Performance testing enterprise firewalls – where application-awareness is widely used for policing the traffic – requires unique traffic that matches the traffic profile of that network. To help you do this, Safire includes an extensive library of application traffic and protocols in pcap format to maximize the accuracy of the test.

Once each test is complete, Safire generates a simple-to-read PDF report that summarizes the the key findings on the front page, followed by a wealth of graphical data so you can instantly spot any serious performance issues.


Here you can see the traffic mix derived from Safire’s library of applications and protocols.


The graphs show various test parameters such as goodput, errors, latency, sessions and so. They can be resized to speed up result analysis.


This is where you configure Safire and initiate new or view existing tests.

Easy to transport


A lightweight, easy-to-transport chassis with 2 x 10GE test ports and access to 24 packet engines.

– W: 19” (48.26cm)
– H: 1.75” (4.45cm)
– D: 9.8” (25cm)
– Weight: 10lbs (4.5kg)


Extend traffic & protocol library

Added 75 traffic applications and 12 pre-define profiles to match enterprise and data center networks for even greater realism and flexibility

Source & Destination NAT support

These important features enable Safire to better support for enterprise perimeter firewall testing & data center testing

1G Testing

Safire is now able to test firewalls that only have 1GE ports

Import & Export Test Config settings

Having the ability to import and export test configurations and results between Safire chassis means more efficient testing.

Variable delay between test iterations

Option to configure the delay between test iterations

Topology in Report

Added a section covering the network topology in the Safire report PDF.


IPv6 traffic generation

This feature will enable Safire to test firewalls using IPv6.

TLS traffic profile

This will let you create TLS traffic profile and select different SSL cipher suites, version, and key size for TLS throughput testing.

More interface types and speeds support

Two more hardware variants will enable testing of both optical and copper interfaces at speeds of 100Mb/1G/2.5G/5G/10G/25G

  Try our demo

Play with our products

- takes just seconds