| Specifications |
Palo Alto PAN-PA-1420 Firewall |
| Performance and Capacities |
|
| Firewall throughput (HTTP/appmix) (Firewall throughput is measured with App-ID and logging enabled, with 64 KB HTTP/appmix transactions.) |
9.9/9.5 Gbps |
| Threat Prevention throughput (HTTP/appmix) (Threat Prevention throughput measured with App-ID, IPS, antivirus, antispyware, WildFire, DNS Security, file blocking, and logging enabled, utilizing 64 KB HTTP/appmix transactions) |
5.0/4.8 Gbps |
| IPsec VPN throughput ( IPsec VPN throughput is measured with 64 KB HTTP transactions, and logging enabled.) |
6.5 Gbps |
| Max concurrent sessions (Max concurrent sessions are measured utilizing HTTP transactions.) |
1,400,000 |
| New sessions per second (New sessions per second is measured with application override, utilizing 1 byte HTTP transactions.) |
140.000 |
| Virtual systems (base/max) (Adding virtual systems over base quantity requires a separately purchased license) |
(1/6) |
| Note: Results were measured on PAN-OS 11.0. |
| Networking Features |
|
| Interface Modes |
L2, L3, tap, virtual wire (transparent mode) |
| Routing |
OSPFv2/v3 with graceful restart, BGP with graceful restart, RIP, static routing Policy-based forwarding Point-to-Point Protocol over Ethernet (PPPoE) Multicast: PIM-SM, PIM-SSM, IGMP v1, v2, and v3 |
| SD-WAN |
Path quality measurement (jitter, packet loss, latency) Initial path selection (PBF) Dynamic path change |
| IPv6 |
L2, L3, tap, virtual wire (transparent mode) Features: App-ID, User-ID, Content-ID, WildFire, and SSL decryption SLAAC |
| IPsec and SSL VPN |
Key exchange: manual key, IKEv1, and IKEv2 (pre-shared key, certificate-based authentication) Encryption: 3des, AES (128-bit, 192-bit, 256-bit) Authentication: MD5, SHA-1, SHA-256, SHA-384, SHA-512 GlobalProtect Large Scale VPN for simplified configuration and management (Requires GlobalProtect license.) Secure access over IPsec and SSL VPN tunnels using GlobalProtect gateway and portals (Requires GlobalProtect license.) |
| VLANs |
802.1Q VLAN tags per device/per interface: 4,094/4,094 Aggregate interfaces (802.3ad), LACP |
| Network Address Translation |
NAT modes (IPv4): static IP, Dynamic IP, Dynamic IP and Port (port address translation) NAT64, NPTv6 Additional NAT features: Dynamic IP reservation, tunable Dynamic IP and Port oversubscription |
| High Availability |
Modes: active/active, active/passive Failure detection: path monitoring, interface monitoring |
| Zero Touch Provisioning (ZTP) |
Requires Panorama 9.1.3 or higher that is managing PA-1400 Series with PAN-OS 11.0 or higher |
| Hardware Specifications |
|
| I/O |
10/100/1000 (4), 1G/2.5G/5G (4), 1G/2.5G/5G (4)/PoE, 1G SFP (2), 1G/10G SFP/SFP+ (8) |
| Management I/O |
10/100/1000 out-of-band management port (1) HSCI 10 gigabit high availability (1) RJ-45 console port (1) USB port (1) Micro USB console port (1) |
| Power over Ethernet (PoE) |
Total PoE Power Budget: 151W, Maximum load on single port: 90W |
| Storage Capacity |
240 GB SSD |
| Power Supply (Avg/Max Power Consumption) |
AC 450W power supply (1); Optional for purchase 2nd AC 450W power supply (1) |
| Power Consumption (Avg/Max) |
260 W/300 W (Power consumption values include a 150 W PoE load.) |
| Mean Time Before Failure (MTBF) |
24 Years |
| Input Voltage Frequency |
100–240 VAC (50–60 Hz) |
| Rack Mount Dimensions |
PA-1420: 1U, 19" standard rack (1.70" H x 14.15" D x 17.15" W) |
| Weight (Standalone Device/As Shipped) |
15.5 lbs |
| Safety |
cTUVus, CB |
| EMI |
FCC Class A, CE Class A, VCCI Class A |
| Environment |
Operating temperature: 0°C to 40°C at 10,000 feet Nonoperating temperature: -4°F to 158°F; -20°C to 70°C |
| Airflow |
Front to back |