| Palo Alto PA-5440-DC Firewall |
|
| Firewall throughput (HTTP/appmix) ( Firewall throughput is measured with App-ID and logging enabled, utilizing 64 KB HTTP/appmix transactions.) |
93.5/72.0 Gbps |
Threat Prevention throughput (HTTP/appmix) (Threat Prevention throughput is measured with App-ID, IPS, antivirus, antispyware, WildFire, DNS Security, file blocking, and logging enabled, utilizing 64 KB HTTP/appmix transactions.) |
61.5/52.0 Gbps |
| IPsec VPN throughput (IPsec VPN throughput is measured with 64 KB HTTP transactions and logging enabled.) |
58 Gbps |
| Max sessions |
20M (This session count requires PAN-OS 11.0.1.) |
| New sessions per second (New sessions per second is measured with application-override, utilizing 1 byte HTTP transactions.) |
390.000 |
| Virtual systems (base/max) (Adding virtual systems over base quantity requires a separately purchased license.) |
25/225 |
| PA-5400 Series Specifications |
|
| Interface Modes |
L2, L3, tap, virtual wire (transparent mode) |
| Routing |
OSPFv2/v3 with graceful restart, BGP with graceful restart, RIP, static routing Policy-based forwarding Point-to-Point Protocol over Ethernet (PPPoE) and DHCP supported for dynamic address assignment Multicast: PIM-SM, PIM-SSM, IGMP v1, v2, and v3 Bidirectional Forwarding Detection (BFD) |
| SD-WAN |
Path quality measurement (jitter, packet loss, latency) Initial path selection (PBF) Key exchange: manual key, IKEv1, and IKEv2 (pre-shared key, certificate-based authentication) |
| IPv6 |
L2, L3, tap, virtual wire (transparent mode) Features: App-ID, User-ID, Content-ID, WildFire, and SSL Decryption SLAAC |
| IPsec and SSL VPN |
Key exchange: manual key, IKEv1, and IKEv2 (pre-shared key, certificate-based authentication) Encryption: 3des, AES (128-bit, 192-bit, 256-bit) Authentication: MD5, SHA-1, SHA-256, SHA-384, SHA-512 GlobalProtect Large Scale VPN for simplified configuration and management* Secure access over IPsec and SSL VPN tunnels using GlobalProtect gateway and portals* |
| VLANs |
802.1Q VLAN tags per device/per interface: 4,094/4,094 Aggregate interfaces (802.3ad), LACP |
| Network Address Translation |
NAT modes (IPv4): static IP, dynamic IP, Dynamic IP and Port (port address translation) NAT64, NPTv6 Additional NAT features: dynamic IP reservation, tunable Dynamic IP and Port oversubscription |
| High Availability |
Modes: active/active, active/passive, HA clustering Failure detection: path monitoring, interface monitoring |
| Mobile Network Infrastructure |
5G Security GTP Security SCTP Security * Requires GlobalProtect license |
| Hardware Specifications |
|
| 1/O |
1G/2.5G/5G/10G (8), 1G/10G SFP/SFP+ (12), 1G/10G/25G SFP/SFP+/SFP28 (4), 40G/100G QSFP+/QSFP28 (4) |
| Management I/O |
1G/10G SFP/SFP+ out-of-band management port (1), 1G/10G SFP/SFP+ high availability (2), 40G QSFP+ high availability (1), RJ-45 console port (1), Micro USB |
| Storage Capacity |
480 GB SSD pair, system storage |
| Power Supply (Avg/Max Power Consumption) |
630/760 W |
| Max BTU/hr |
1638 |
| Power Supplies (Base/Max) |
1:1 fully redundant (2/2) |
| AC Input Voltage (Input Hz) |
100–240 VAC (50–60 Hz) |
| AC Power Supply Output |
1,200 watts/power supply |
| Max Current Consumption |
AC: 7 A @ 100 VAC, 3 A @ 240 VAC DC: 15 A @ -48 VDC, 12 A @ -60 VDC |
| Max Inrush Current |
AC: 50 A @ 230 VAC, 50 A @ 120 VAC DC: 200 A @ 72 VDC |
| Mean Time Between Failure (MTBF) |
22 years |
| Rack Mount Dimensions |
2U, 19" standard rack (3.45" H x 22.5" D x 17.34" W) |
| Weight (Standalone Device/As Shipped) |
35.2 lbs/48.8 lbs |
| Safety |
cTUVus, CB |
| EMI |
FCC Class A, CE Class A, VCCI Class A |
| Environment |
Operating temperature: 32°F to 122°F, 0°C to 50°C Nonoperating temperature: -4°F to 158°F, -20°C to 70°C Humidity tolerance: 10% to 90% Maximum altitude: 10,000 ft/3,048 m Airflow: front to back |