that is correct. total system throughput is combined scanning capability across all monitoring ports.
however, when enabling additional features (layer 7, ssl decrypt, application identification, etc.) the capable throughput begins to drop.
you *could* exceed 600 mbps (or determined total throughput), but obviously you risk dropped alerts, system instability, dropped packets, link errors, etc. which is obviously bad and worse if monitoring inline.