Skip to main content

1. Introduction

The sizing requirements of the OneFirewall Alliance solution, depending on the Service Level Agreement (SLA) and the log throughput, are summarized in the following table:
OFA TypeSizeSLACapabilityLicense
P-Micro (Collaudo/Test)8 vCPU / 24–32 GB RAM / 300 GB SSD99% (No High Availability)1 Tenant, no backup, 100–300 log/s, Non-scalableTrial License
P-08 vCPU / 32 GB RAM / 1000 GB SSD99.9% (No High Availability)1 Tenant, up to 10 users per tenant, daily backup, 100–300 log/s, Non-scalableSingle Tenant License
P-13× 8 vCPU / 3× 32 GB RAM / 3× 10 000 GB SSD99.999% (High Availability)2–6 Tenants, up to 15 users per tenant, daily backup, 300–700 log/s, Non-scalableSingle Tenant License
P-23–5× 8 vCPU / 3–5× 32 GB RAM / 3× 1000 GB SSD99.9999% (High Availability)7+ Tenants, up to 30 users per tenant, daily backup, 700–1600 log/s, ScalableWhile Label License
In the next sections we explore the different installation types by OFA configuration, providing a typical sizing example for a cloud provider (GCP) along with indicative infrastructure costs.

2. P-Micro

The P-Micro sizing solution targets a testing environment, enabling the installation of the OneFirewall solution on a single VM.

Requirements and Costs

RequirementsDescriptionMonthly Cost (USD)
1 VM (Compute Engine)n2-standard-8 (Spot Instance)39.40
1 SSD (gp3)500 GB98.60
Cloud NATInternet update, app.onefirewall.com, gitlab.com41.50 (100 GB/month)
SnapshotN/A0
Total179.50 USD/month
For Compute Engine (CE) or Google Kubernetes Engine (GKE), the system or Kubernetes user must be able to independently configure the environment (sudoers privileges or unrestricted RBAC management).

3. P-0 (ProdSmall)

Requirements and Costs

RequirementsDescriptionMonthly Cost (USD)
1 VM (Compute Engine)n2-standard-8 (Committed Use Discount)148.04
1 SSD (gp3)1000 GB197.20
Cloud NATInternet update, app.onefirewall.com, gitlab.com41.50 (100 GB/month)
External Load Balancer 443e.g. onefirewall.example.it (or ingress GKE equivalent)Variable
Snapshot1 per day
Total376.74 USD/month
Compute Engine or GKE users must have privileges to configure the environment (sudoers or unrestricted RBAC), and IAM rules for ingress and external load balancer 443.

4. P-1 (ProdMedium)

Requirements and Costs

RequirementsDescriptionMonthly Cost (USD)
3 VM (Compute Engine) — one per AZ (or GKE Multi-Node, Multi-AZ)n2-standard-8 (Committed Use Discount)73 (GKE) + 444.12
3 SSD (gp3)1000 GB each591.60
Cloud NATInternet update, app.onefirewall.com, gitlab.com41.50 (100 GB/month)
External Load Balancer 443e.g. onefirewall.example.it (or ingress GKE equivalent)Variable
Snapshot1 per day
Total1108.72 USD/month
Users must be able to configure the environment independently (sudoers or unrestricted RBAC), and manage IAM rules for ingress and external load balancer 443.

5. P-2 (ProdEnterprise)

Requirements and Costs

RequirementsDescriptionMonthly Cost (USD)
3–5 VM (Compute Engine) — one per AZ (or GKE Multi-Node, Multi-AZ)n2-standard-8 (Committed Use Discount)73 (GKE) + 740.20
3 SSD (gp3)1000 GB each986.00
Cloud NATInternet update, app.onefirewall.com, gitlab.com41.50 (100 GB/month)
External Load Balancer 443e.g. onefirewall.example.it (or ingress GKE equivalent)Variable
Snapshot1 per day
Total (up to)1840.70 USD/month
For Compute Engine or GKE, users must have sudoers or unrestricted RBAC access, and appropriate IAM rules for ingress and external Load Balancer 443.