Palo Alto Networks PAN-PA-3410 1U Rackmount Firewall with 12x 10G RJ45, 10x 10G SFP+ and 4x 25G SFP28

Brand:
Palo Alto
Part Number:
PAN-PA-3410

A support service contract is required unless your organization has an active Enterprise Support Agreement (ESA). 1-year, 3-year, and 5-year support options are available. Please contact us before fulfillment to confirm the correct support option or any additional Palo Alto licenses you may need.

$30,730.00 $27,657.00 Instant Savings $3,073.00

Net 30 or as low as $—/month Apply Now

Quote

Overview

The Palo Alto Networks PA-3400 Series is the campus-edge tier: 1U appliances with multigigabit copper, 10 gigabit SFP+ and 25 gigabit SFP28 interfaces, redundant 450 W power supplies as standard, and dedicated high-availability ports including a 10 gigabit SFP+ HA link. It runs PAN-OS with the single-pass architecture, supports a maximum of eleven virtual systems (one in the base, the rest separately licensed), and allows NGFW clustering for horizontal scaling across appliances. The PAN-PA-3410 is the copper and SFP28 configuration in that line-up, rated at 14 Gbps of firewall throughput. This SKU is supplied as Appliance Only: PAN-OS and its base platform capabilities are included. The Cloud-Delivered Security Services, such as Advanced Threat Prevention, Advanced WildFire, Advanced URL Filtering and Advanced DNS Security, are licensed for a term and sold separately, as is the support contract.

Technical Details

The Palo Alto Networks PAN-PA-3410 is a 1U rackmount next-generation firewall with 12×1/2.5/5/10GbE RJ45, 10×1/10GbE SFP/SFP+, 4×25GbE SFP28, running PAN-OS. Firewall throughput (appmix) is 14 Gbps, measured with App-ID and logging enabled. Threat Prevention throughput (appmix) is 7.5 Gbps, measured with App-ID, IPS, antivirus, antispyware, WildFire, file blocking, and logging enabled. IPsec VPN throughput is 6.6 Gbps on 64 KB HTTP transactions with logging enabled. It holds 1,400,000 concurrent sessions and opens 145,000 new sessions per second. Palo Alto Networks support and security subscriptions are sold separately. It operates 32°F to 104°F (0°C to 40°C) and is used at a campus or main-office internet edge, in the DMZ, and for internal segmentation between user and server segments.

Best For

The PAN-PA-3410 suits a campus or main-office internet edge that needs 7.5 Gbps of Threat Prevention throughput with 1,400,000 concurrent sessions behind it. Its interfaces are 12×1/2.5/5/10GbE RJ45, 10×1/10GbE SFP/SFP+, 4×25GbE SFP28. Firewall throughput (appmix) is 14 Gbps, measured with App-ID and logging enabled. Compare it with the PAN-PA-3420, its nearest model in the same family, on those two figures rather than on port count.

Not suitable if:

  • your inspected traffic exceeds 7.5 Gbps, since that is the published Threat Prevention throughput
  • you need 40G or 100G interfaces, since the fastest ports on this model are 25G SFP28
  • you need the Cloud-Delivered Security Services included in the part number, since an Appliance Only SKU carries PAN-OS only and the subscriptions are sold separately
  • you need Power over Ethernet, since this model provides none
  • you need a hardened appliance for a plant floor or outdoor cabinet, since this unit is rated only for 32°F to 104°F (0°C to 40°C)

PAN-PA-3410 Specifications

Ports & Uplinks
Fixed Interfaces12×1/2.5/5/10GbE RJ45, 10×1/10GbE SFP/SFP+, 4×25GbE SFP28
Max Port Speed25 GbE
Management & Console Ports1×1GbE RJ45 out-of-band management, 2×1GbE high availability, 1×10GbE SFP+ high availability, 1×RJ45 console, 1×micro-USB
Performance & Scale
Firewall Throughput14 Gbps (appmix)
Threat Prevention Throughput7.5 Gbps (appmix)
TLS/SSL Inspection ThroughputNot published
IPsec VPN Throughput6.6 Gbps (64 KB HTTP)
Hardware & Memory
Onboard Storage480 GB SSD
Power & Thermal
Power SupplyRedundant 450 W AC; 100-240 VAC input (50-60 Hz); maximum current consumption 1.9 A @ 100 VAC, 0.8 A @ 240 VAC
Redundant Power SupplyYes
Maximum Power Consumption190 W (133 W average)
CoolingFront-to-back airflow
Physical & Environmental
Operating SystemPAN-OS
Form Factor1U Rackmount
Dimensions (H x W x D)1.70 × 17.15 × 14.15 in (4.32 × 43.56 × 35.94 cm)
Weight15.5 lb (7.03 kg)
Operating Temperature32°F to 104°F (0°C to 40°C)
Software
Central Management PlatformPanorama, Strata Cloud Manager
Routing Protocols & IPv6OSPFv2/v3 with graceful restart, BGP with graceful restart, RIP, static routing, policy-based forwarding, PPPoE, multicast (PIM-SM, PIM-SSM, IGMP v1/v2/v3), Bidirectional Forwarding Detection (BFD), NAT64 and NPTv6
Other
Maximum Concurrent Sessions1,400,000
New Sessions per Second145,000
High AvailabilityActive/Active, Active/Passive, HA Clustering

FAQ

Does the Palo Alto Networks PAN-PA-3410 support PoE?

No. The PAN-PA-3410 provides no Power over Ethernet, so cameras, access points and IP phones need their own power source or a PoE switch between them and the firewall. Its interfaces are 12×1/2.5/5/10GbE RJ45, 10×1/10GbE SFP/SFP+, 4×25GbE SFP28, all data-only. Other models in the Palo Alto range do carry PoE ports on separate part numbers.

What interfaces does the PAN-PA-3410 have?

The PAN-PA-3410 provides 12×1/2.5/5/10GbE RJ45, 10×1/10GbE SFP/SFP+, 4×25GbE SFP28. Management and console connectivity is separate: 1×1GbE RJ45 out-of-band management, 2×1GbE high availability, 1×10GbE SFP+ high availability, 1×RJ45 console, 1×micro-USB. Pluggable transceivers are sold separately.

How does high availability work on the Palo Alto Networks PAN-PA-3410?

The PAN-PA-3410 supports active/active and active/passive high availability. This model has dedicated high-availability ports, listed among its management interfaces. NGFW clustering is also supported, which scales capacity horizontally across several appliances.

How much traffic can the PAN-PA-3410 handle?

Palo Alto publishes no user count, so compare the PAN-PA-3410 on its published capacity figures. Firewall throughput (appmix) is 14 Gbps, measured with App-ID and logging enabled. Threat Prevention throughput (appmix) is 7.5 Gbps, measured with App-ID, IPS, antivirus, antispyware, WildFire, file blocking, and logging enabled. It holds 1,400,000 concurrent sessions, measured with HTTP transactions, and opens 145,000 new sessions per second, measured with application override on 1-byte HTTP transactions. All figures were measured on PAN-OS 12.1.

What is the difference between the PAN-PA-3410 and the PAN-PA-3420?

Both run the same PAN-OS and share the family's platform capabilities. The PAN-PA-3410 is rated at 14 Gbps firewall throughput, 7.5 Gbps Threat Prevention throughput and 1,400,000 concurrent sessions; the PAN-PA-3420 is rated at 19 Gbps, 10 Gbps and 2,200,000. The two models have the same fixed interface set.

Does the PAN-PA-3410 require a subscription to operate?

No. The PAN-PA-3410 runs PAN-OS without any subscription, and its base platform capabilities include stateful firewalling and NAT, App-ID, User-ID, Content-ID, SSL/TLS decryption, IPsec VPN, dynamic routing, IPv6 and high availability. The Cloud-Delivered Security Services, including Advanced Threat Prevention, Advanced WildFire, Advanced URL Filtering and Advanced DNS Security, are licensed for a term and sold separately.

Does the PAN-PA-3410 need a support contract?

Yes, unless your organisation holds an active Enterprise Support Agreement. A support service contract is required with the PAN-PA-3410, and one-, three- and five-year options are available. Network Devices Inc. confirms the correct support option and any additional Palo Alto Networks licenses the deployment needs before the order is placed.

What is the SSL/TLS decryption throughput of the PAN-PA-3410?

Palo Alto Networks does not publish a separate SSL/TLS decryption throughput figure for the PAN-PA-3410. The datasheet lists SSL/TLS decryption as a platform capability but provides no bandwidth figure; do not infer decryption throughput from the Threat Prevention throughput.

What condition is the PAN-PA-3410 sold in, and what warranty applies?

Network Devices Inc. supplies the PAN-PA-3410 new and factory sealed, in original Palo Alto Networks packaging with the standard accessories. It is covered by a one-year Network Devices Inc. warranty and a 30-day return window. Orders ship from our New Jersey and Texas warehouses.

Reviews