The IDS/IPS (Threat Analysis) firewall feature requires taking apart and analyzing every single byte of every packet, including TCP reassembly, and so it's a substantial workout even for a Cavium. It maxes out about 220 Mb/s. For example, another speedtest with IDS/IPS enabled:
The
S2S VPN speeds are very dependent on the path delay between the sites
and the VPN hub in the cloud. For some really terrible paths (over an
AT&T LTE link, for example) I've
measured as low as a few megabits/second. Typically we see between 50
and 70 megabits/second. There are some customers that have S2S VPNs
within the same carrier subnet that get up to 90 megabits/second.