Progent's Palo Alto Networks firewall experts and certified cybersecurity consultants can help you modernize your legacy port-based firewall environment by providing a range of services including system architecture design, migration planning, policy creation, configuration, management, tuning and troubleshooting. Progent can help you protect on-premises, cloud or hybrid deployments and consolidate diverse firewall management tools into a simple, integrated solution based on the Panorama management platform. Progent can provide online or onsite support and is available for engagements ranging from as-needed guidance to comprehensive project management. Progent's team of network infrastructure experts includes Cisco CCIE-certified consultants and can help you integrate Palo Alto Networks firewalls seamlessly with other components of your IT ecosystem.
Palo Alto Networks PA-Series Firewalls Supported by Progent
The PA-Series of firewalls from Palo Alto Networks includes appliances designed and priced to meet the needs of environments ranging from retail locations and branch offices to large enterprises and service providers. All PA-Series firewalls support a common set of next-generation features that include:
Palo Alto Networks PA-220R firewall is a ruggedized appliance that delivers the same performance and capacity as the PA-220 firewall and is certified to comply with IEC 61850-3 and IEEE 1613 standards for operation in the harsh conditions of industrial networks like power plants, factories, refineries, and utility substations. For App-IDs, PA-220R firewalls work with major industrial protocols and applications like DNP3, IEC 60870-5-104, Modbus, and Siemens S7. The PA-220R firewall includes six 10/100/1000 ports and two SFP optical ports and runs off dual 12-48V DC power. Mounting options include DIN rail, rack, and wall mount.
Palo Alto Networks PA-400 Series Next-Generation Firewalls
Palo Alto Networks PA-400 Series Firewalls are value-priced desktop, wall mount, and rackmount next-generation firewalls (NGFWs) designed for small and mid-sized organizations and the branches of distributed enterprises. PA-400 Series firewalls work with Palo Alto Networks Cloud-Delivered Security Services, allowing unified management of distributed networks and supporting advanced features such as Credential Phishing Prevention, WildFire Malware Prevention, IoT Security, DNS Security, Data Loss Prevention, Advanced URL Filtering, inline SaaS Security, and Policy Optimization.
The PA-410 firewall includes seven 1G RJ45 interfaces and delivers firewall throughput of 1.4 Gbps, threat prevention throughput of 0.8 Gbps, and IPsec VPN throughput of 0.65 Gbps. The PA-410 supports 11,000 new sessions per second and a maximum of 64,000 concurrent sessions. The PA-415 firewall includes a combo 1G SFP/RJ45 port, four 1G RJ45 ports, and four 1G RJ45 ports with PoE. The PA-415 offers firewall performance of 1.5 Gbps, threat prevention throughput of 0.8 Gbps, and IPsec VPN performance of 0.65 Gbps. The PA-415 allows 11,000 new sessions per second and up to 64,000 concurrent sessions. For high availability, the PA-415-5g adds an integrated 5G cellular modem which can be used for primary or backup connectivity and for ISP load balancing.
Palo Alto Networks PA-440 series firewalls include eight 1G RJ45 ports and provide firewall throughput of 2.6 Gbps, threat prevention throughput of 1.2 Gbps, and IPsec VPN throughput of 1.1 Gbps. The PA-440 supports 200,000 new sessions per second and up to 34,000 concurrent sessions. The PA-445 firewall includes a combination 1G SFP/RJ45 port, four 1G RJ45 ports, and four 1G RJ45 ports with PoE. The PA-445 offers firewall performance of 2.7 Gbps, threat prevention throughput of 1.25 Gbps, and IPsec VPN performance of 1.1 Gbps. The PA-445 allows 200,000 new sessions per second and up to 34,000 concurrent sessions.
The Palo Alto Networks PA-450 firewall comes with eight 1G RJ45 ports and delivers firewall performance of 3.3 Gbps, threat prevention throughput of 2.1 Gbps, and IPsec VPN performance of 1.7 Gbps. The PA-450 supports 300,000 new sessions per second and a maximum of 48,000 concurrent sessions. The PA-455 firewall includes two combination 1G SFP/RJ45 ports, two 1G RJ45 ports, and four 1G RJ45 ports with PoE. The PA-455 supports firewall throughput of 3.6 Gbps, threat prevention performance of 2.3 Gbps, and IPsec VPN throughput of 1.8 Gbps. The PA-455 supports 300,000 new sessions per second and a maximum of 56,000 concurrent sessions. The PA-460 firewall comes with eight 1G RJ45 ports and delivers firewall throughput of 4.6 Gbps, threat prevention performance of 3 Gbps, and IPsec VPN throughput of 2.3 Gbps. The PA-455 supports 400,000 new sessions per second and a maximum of 67,000 concurrent sessions.
Palo Alto Networks PA-800 Firewalls
Palo Alto Networks PA-800 Series Firewalls are 1U standard rack security appliances intended for mid-size organizations and branch offices. These firewalls include 240 GB SSD storage. Management I/O includes one 10/100/1000 out-of-band management port, two 10/100/1000 high availability ports, one RJ-45 console, one USB port, and one Micro USB console interface. The PA-820 firewall has four 10/100/1000 and eight SFP interfaces and delivers firewall throughput of 1.7 Gbps, Threat Prevention throughput of 800 Mbps, and IPsec VPN throughput of 1.2 Gbps. The PA-820 supports 8,300 new sessions per second and a maximum of 128,000 sessions.
The PA-850 firewall has four 10/100/1000 interfaces, four SFP ports, and 10 SFP+ ports. The appliance delivers firewall throughput of 2 Gbps, Threat Prevention throughput of 1 Gbps, and IPsec VPN throughput of 1.6 Gbps. The PA-850 supports 13,00 new sessions per second and a maximum of 192,000 sessions. The PA-850 also includes two 500W power supplies (one is redundant).
Palo Alto Networks PA-1400 Series Next-Generation Firewalls
Palo Alto Networks PA-1400 Series Firewalls are rackmount high-availability appliances designed to guard large distributed branch offices and small enterprise campuses. The PA-1410 NGFW firewall includes eight 10/100/1000 ports, four 1G/2.5G/5G ports with PoE, six 1G SFP ports, and four 1G/10G SFP/SFP+ ports. The PA-1410 delivers firewall throughput of 8.5 Gbps, threat prevention performance of 4.2 Gbps, and IPsec VPN throughput of 4.1 Gbps. The unit supports 945,000 new sessions per second and a maximum of 100,000 concurrent sessions. The PA-1420 firewall comes with four 10/100/1000 ports, four 1G/2.5G/5G portsd, for 1G/2.5G/5G ports with PoE, two 1G SFP ports, and eight 1G/10G SFP/SFP+ ports. The PA-1420 offers firewall performance of 9.5 Gbps, threat prevention throughput of 5.8 Gbps, and IPsec VPN performance of 5.6 Gbps. The PA-1410 allows 1,400,000 new sessions per second and up to 140,000 concurrent sessions.
Palo Alto Networks PA-3000 Firewalls
Palo Alto Networks PA-3000 Series Firewalls are designed to provide security for high-speed Internet gateways and include one 10/100/1000 out-of-band management port, two 10/100/1000 high availability ports, and one RJ-45 console port. They also include 120 GB of SSD storage. The 1U rack mount PA-3020 and PA-3050 firewalls come with 12 10/100/1000 interfaces and eight SFP Gigabit ports plus a single 250 W power supply. The 1.5U rack mount PA-3060 firewall has eight 10/100/1000 ports, eight Gigabit SFP ports, and 10 Gigabit SFP+ ports as well as redundant 400 W power supplies. The PA-3020 delivers 2 Gbps firewall throughput and 1 Gbps Threat Prevention throughput. The PA-3050 and PA-3060 both deliver 4 Gbps firewall throughput and 2 Gbps Threat Prevention throughput. All PA-3000 Series firewalls support 500 Mbps IPsec throughput and allow 50,000 new sessions per second with a maximum of 500,000 sessions.
Palo Alto Networks PA-3200 Firewalls
Palo Alto Networks PA-3200 Series Firewalls are intended for high-speed Internet gateway deployments and provide better performance than PA-3000 Series firewalls. These 2U rack mount appliances include one 10/100/1000 out-of-band management port, two 10/100/1000 high availability ports, one 10G SFP+ high availability port, one RJ-45 console port, and a Micro USB port. They also include 240 GB of SSD storage. The PA-3220 firewall comes with 12 10/100/1000 interfaces, four 1G/10G SFP ports, and four 1G/10G SFP/SFP+ ports. The PA-3220 delivers 5.0 Gbps firewall throughput, 2.4 Gbps Threat Prevention throughput, and 2.7 Gbps IPsec VPN performance. The firewall allows a max of 1M sessions and supports 57,000 new sessions per second.
The PA-3250 firewall includes 12 10/100/1000 ports and eight 1G/10G SFP/SFP+ ports. The firewall provides 6.6 Gbps firewall throughput, 3.0 Gbps Threat Prevention throughput, and 3.2 Gbps IPsec VPN performance. The PA-3250 supports a maximum of 2M sessions and supports 82,000 new sessions per second. The PA-3260 firewall includes 12 10/100/1000 ports, eight 1G/10G SFP/SFP+ ports, and four 40G QSFP+ ports. The PA-3260 provides 10 Gbps firewall throughput, 4.4 Gbps Threat Prevention performance, and 4.8 Gbps IPsec VPN throughput. The PA-3260 can handle 3M sessions and 114,000 new sessions per second.
Palo Alto Networks PA-3400 Series Next-Generation Firewalls
Palo Alto Networks PA-3400 Series Firewalls are high-performance 1RU units intended to protect internet edge and campus deployments. The PA-3410 firewall includes twelve 1G/2.5G/5G/10G ports, ten 1G/10G SFP/SFP+ ports, and four 25G SFP28 ports. The appliance delivers firewall throughput of 14 Gbps, threat prevention throughput of 7.5 Gbps, and IPsec VPN performance of 6.6 Gbps. The PA-3410 supports 145,000 new sessions per second and up to 1,400,000 concurrent sessions. The PA-3420 firewall comes with the same integrated I/O port selection as the PA-3410 and supports firewall throughput of 19 Gbps, threat prevention throughput of 10 Gbps, and IPsec VPN performance of 9.9 Gbps. The PA-3420 allows 220,000 new sessions per second and up to 2,200,000 concurrent sessions.
The PA-3430 firewall comes with twelve 1G/2.5G/5G/10G ports, ten 1G/10G SFP/SFP+ ports, four 25G SFP28 ports, and two 40G/100G QSFP/QSFP28 ports. The device delivers firewall throughput of 29 Gbps, threat prevention throughput of 15 Gbps, and IPsec VPN performance of 12 Gbps. The PA-3430 supports 240,000 new sessions per second and up to 2,500,000 concurrent sessions. The PA-3440 firewall features the same integrated I/O port selection as the PA-3430 and supports firewall throughput of 35 Gbps, threat prevention throughput of 20 Gbps, and IPsec VPN performance of 14.5 Gbps. The PA-3440 allows 268,000 new sessions per second and up to 3,000,000 concurrent sessions.
Palo Alto Networks PA-5200 Firewalls
Palo Alto Networks PA-5200 Series Firewalls are designed for deployment in high-traffic data centers, service providers, and internet gateways. These 3U rack mount appliances include 240 GB SSD system storage and 2 TB HDD log storage, and fully redundant power. The PA-5220 firewall includes a 40G QSFP+ HA management port, four 100/1000/10G Cu ports, 16 1G/10G SFP/SFP+ ports, and four 40G QSFP+ ports. The PA-5220 delivers 20 Gbps firewall throughput, 8.9 Gbps Threat Prevention throughput, and 10 Gbps IPsec VPN throughput. The PA-5220 also supports up to 4M sessions and 133,000 new sessions per second.
For management I/O, PA-5250, PA-5260 and PA-5280 firewalls from Palo Alto Networks include two 10/100/1000 Cu ports, a 10/100/1000 out-of-band management port, an RJ45 console, and a 40G/100G QSFP28 HA port. Interfaces include four 100/1000/10G Cu ports, 16 1G/10G SFP/SFP+ ports, and four 40G/100G QSFP28 ports. The PA-5250 firewall offers 40 Gbps firewall throughput, 21 Gbps Threat Prevention throughput, and 18 Gbps IPsec VPN throughput. The PA-5250 also allows 8M sessions and 297,000 new sessions per second. The PA-5260 firewall offers 64 Gbps firewall throughput, 31.5 Gbps Threat Prevention throughput, and 27 Gbps IPsec VPN throughput. The PA-5260 also allows 32M sessions and 450,000 new sessions per second. The high-end PA-5280 firewall delivers 64 Gbps firewall throughput, 31.5 Gbps Threat Prevention throughput, and 27 Gbps IPsec VPN performance. The PA-5280 supports 64M concurrent sessions and 450,000 new sessions per second.
Palo Alto Networks PA-5400 Series Next-Generation Firewalls
Palo Alto Networks PA-5400 Series Firewalls are designed to protexct high-speed data center, internet gateway, and service provider deployments. All PA-5400 Series firewalls are fixed-chassis, 2RU form factor appliances that include eight 1G/2.5G/5G/10G ports, twelve 1G/10G SFP/SFP+ ports, four 1G/10G/25G SFP/SFP+/SFP28 ports, and four 40G/100G QSFP+/QSFP28 ports. The PA-5410 appliance delivers firewall throughput of 52 Gbps, threat prevention throughput of 35 Gbps, and IPsec VPN performance of 20 Gbps. The PA-5410 supports 270,000 new sessions per second and up to 5,000,000 concurrent sessions. The PA-5420 supports firewall throughput of 70 Gbps, threat prevention throughput of 50 Gbps, and IPsec VPN performance of 28 Gbps. The PA-5420 allows 370,000 new sessions per second and up to 7,000,000 concurrent sessions. The PA-5430 supports firewall throughput of 82 Gbps, threat prevention throughput of 60 Gbps, and IPsec VPN performance of 42 Gbps. The PA-5430 allows 380,000 new sessions per second and up to 9,000,000 concurrent sessions. The PA-5440 supports firewall throughput of 90 Gbps, threat prevention throughput of 70 Gbps, and IPsec VPN performance of 58 Gbps. The PA-5440 allows 390,000 new sessions per second and up to 20,000,000 concurrent sessions. The PA-5445 supports firewall throughput of 90 Gbps, threat prevention throughput of 76 Gbps, and IPsec VPN performance of 64 Gbps. The PA-5440 allows 449,000 new sessions per second and a maximum of 48 million concurrent sessions.
The PA-5450 is a modular firewall designed for hyperscale data center, internet edge and campus segmentation deployments. The PA-5450's scalable architecture offers a total of six slots for Networking Cards and Data Processing Cards. Each Networking Card includes four 100/1000/10G Cu ports, twelve 1G/10G SFP/ SFP+ ports, and two 40G/100G QSFP28 ports. The PA-5450 requires a minimum of one Networking Card and acepts a maximum of two. Up to five DPCs can be placed in the six slots. The PA-5450 supports firewall throughput of 200 Gbps, threat prevention throughput of 189 Gbps, and IPsec VPN performance of 85 Gbps. The PA-5440 allows 3,600,000 new sessions per second and a maximum of 100 million concurrent sessions.
Palo Alto Networks PA-7000 Firewalls
Palo Alto Networks PA-7000 Series Firewalls are modular, chassis-based appliances designed for large enterprises and service providers who need the highest levels of security and performance at the network perimeter. The scalable architecture of the PA-7000 Series future proofs your firewall investment and allows you to configure the appropriate type and volume of processing power for networking, security, and management. Network Processing Cards (NPCs) handle network processing tasks, deliver up to 70 Gbps each, and can be combined for up to 700 Gbps throughput with the top-of-the-line PA-7080. The Switch Management Card (SMC) handles management functions and coordinates all traffic, and a Logging Card or Log Forwarding Card offload logging activities for reports and queries. Management I/O includes two SFP/SFP+ MGT ports, two SFP/SFP+ HA1 ports, two HSCI HA2/HA3 QSFP+/QSFP28 ports, one RJ45 serial console, and one micro-USB serial console.
The 9U rackmount PA-7050 firewall supports up to 72 10/100/1000 ports, 48 SFP/ SFP+ ports, and 24 QSFP+/QSFP28 ports. The PA-7050 fully loaded can deliver up to 420 Gbps firewall throughput, 366 Gbps Threat Prevention throughput, and 168 Gbps IPsec VPN throughput. The device supports a maximum of 192M sessions and 2.73M new sessions per second.
The 19U rackmount PA-7080 firewall supports up to 120 10/100/1000 ports, 80 SFP/ SFP+ ports, and 40 QSFP+/QSFP28 ports. The PA-7080 fully loaded can deliver up to 700 Gbps firewall throughput, 610 Gbps Threat Prevention throughput, and 280 Gbps IPsec VPN throughput. The firewall supports up to 320M sessions and 4.56M new sessions per second.
Palo Alto Networks PA-7500 Firewall
The 14U rack mount PA-7500 is a massively scalable firewall designed to allow large enterprises and service providers to protect high-performance environments like large data centers and high-bandwidth network perimeters. The PA-7500's versatile architecture offers a total of nine slots to accommodate Networking Cards, Data Processing Cards, and Management Processing Cards. At least one card of each type must be installed. The scalable design of the PA-7500 supports up to seven Data Processing Cards or up to seven Networking Cards to optimize processing or performence. Also, up to two Switching Fabric Cards with optional redundancy can be rear mounted for orthogonal mating. Each Networking Card includes eight QSFP-DD ports - with support for 400 Gbps/100 Gbps/40 Gbps and hardware support for breakout mode twelve SFP-DD - 100 Gbps/25 Gbps/10 Gbps ports.
With six Data Processing Cards and two Networking Cards installed, the PA-7500 can support firewall throughput of 1,500 Gbps, threat prevention throughput of 1,440 Gbps, and IPsec VPN performance of 407 Gbps. This configuration also allows the PA-7500 to support 7,200,000 new sessions per second and up to 440 million concurrent sessions.
How Progent Can Help with Palo Alto Networks Firewall Solutions
Progent's Palo Alto Networks consultants can assist you to plan and deploy Palo Alto Networks PA Series firewalls and manage them from a single pane of glass using Panorama. Progent can help you configure a firewall solution that provides consistent integrated security and visibility for data centers and branch offices as well as private and public cloud solutions and that protects any device, anywhere, running any OS. Progent can help you migrate efficiently to Palo Alto Networks firewalls from outdated port-based and protocol-based security appliances and can help you with policy creation and enforcement based on industry best practices. Progent's certified cybersecurity experts offer security vulnerability assessments and penetration testing consultants to determine or validate your network's current security profile.
Progent can save you time and money by providing online consulting and debugging services for Palo Alto Networks technology, eliminating travel delays and expenses and maximizing network availability. Progent has successfully delivered remote support to businesses in every state in the United States (see Progent's customer testimonials).
Find out how to contact a Progent security consultant.