Skip to main content

NSS Labs Enterprise Firewalls Report Details Evasion and Encrypted Throughput

NSS Labs’ 2025 Q4 enterprise firewall comparative report tested seven firewall products against real-world attack traffic, exploit and malware samples, and 53 evasion categories, then measured throughput under enterprise workloads. The findings show uneven evasion resistance and varying performance with encrypted sessions.

Research Overview

The evaluation covered seven widely deployed enterprise firewall products placed in-line between trusted and untrusted networks. NSS Labs used real-world network traffic alongside exploit, malware, evasion, and sustained stress tests to assess resilience, reliability, and performance.

The test set included 3,326 exploit samples tied to vulnerabilities found in the wild, 11,311 malware samples from active campaigns, and 5,752 evasion variations across 53 evasion categories. Performance testing used 55 stress tests across HTTP, HTTPS, and UDP to measure throughput, stability, and reliability under load.

Key Findings

NSS Labs reported that most products blocked the majority of exploit and malware payloads, but several products failed to resist low-level evasion techniques. The results were described as uneven across the tested evasion categories.

Three firewalls received “Recommended” ratings: Check Point, Juniper Networks, and Versa Networks. The remaining three received “Caution” ratings: Cisco, Fortinet, and Palo Alto Networks, with failures linked to evasion resistance despite high overall exploit and malware handling rates.

Technical Breakdown

The report said malware and exploit detection rates were above 99 percent for most products, while evasion results were used to identify real-world risk. It stated that a single missed evasion can enable reuse of entire classes of exploits without detection.

Specific evasion category outcomes were reported for individual vendors: Cisco failed one TCP-segmentation evasion, reducing exploit-evasion resistance to 40 percent; Fortinet missed one transport-layer variant at 60 percent; and Palo Alto Networks failed both network and transport-layer categories, resulting in 0 percent exploit-evasion resistance. The report framed these results as a recurring issue dating back to the inception of NSS Labs 1.0 in 2007.

Operational Impact and Performance

NSS Labs used a throughput metric that weighted encrypted traffic at 95 percent to reflect enterprise conditions. Versa delivered the highest sustained throughput at 7.6 Gbps, while Juniper balanced speed and protection, Fortinet offered “excellent value,” and Palo Alto trailed on throughput while achieving strong accuracy.

The report also described operational overhead using false-positive accuracy. It reported that Cisco’s 80 percent accuracy implies legitimate traffic was incorrectly blocked one-fifth of the time, while Palo Alto, Versa, and Fortinet exceeded 99 percent resistance in false-positive scenarios.

Product Update and Vendor Responsiveness

The post included a follow-on theme focused on how vendors responded to issues identified in the independent tests. It said Palo Alto Networks and Fortinet confirmed patches for the identified issues within days of publication and scheduled retests for affected products.

NSS Labs linked that responsiveness to transparency and engineering follow-through, describing a need for vendors to fix issues quickly and participate in validation cycles. The post also noted that early summary ratings in the CSM might change as fixes are validated and retested.

NSS Labs’ 2025 Q4 enterprise firewall report measured seven products against exploit, malware, evasion, false-positive, and throughput tests, finding uneven evasion resistance and variable performance on encrypted traffic. The vendor response to identified evasion failures, along with the reported false-positive and throughput results, are central considerations for enterprise decision-makers; this “Blog Signals brief” is a fact-based summary of the vendor blog.