 Why is the VPN throughput number on the Firebox T55 and T70 datasheets lower than expected?

The Firebox T55 and T70 devices are the only Firebox models that do not have dedicated hardware for IPSec computations. On these models, the CPU handles the IPSec computations. This means that when the Firebox is under high load, such as during the lab testing for the datasheet performance tests, the CPU is also busy handling other Firebox functions.
To increase VPN throughput on these models, we highly recommend you use the AES-GCM ciphers. These ciphers will perform much faster on Firebox models that use the CPU for IPSec computations. The datasheet performance testing is not performed using the AES-GCM ciphers on any Firebox models.