
Palo Alto Networks PAN-PA-460 Desktop Firewall with 8x 1G RJ45
Overview
The Palo Alto Networks PA-400 Series brings ML-powered next-generation firewalling to distributed enterprise branch offices and midsize businesses in a fanless desktop chassis. Every model runs PAN-OS with the single-pass architecture, so App-ID, User-ID, Content-ID and SSL/TLS decryption run once over the same packet rather than in a chain of separate engines, and performance stays predictable when security subscriptions are switched on. High availability is supported in active/active and active/passive modes, and NGFW clustering allows horizontal scaling across several appliances. The PAN-PA-460 is the 8-port data-only configuration in that line-up, rated at 4.2 Gbps of firewall throughput. Palo Alto Networks has announced an end-of-sale date of March 22, 2027 for this model and names the PA-500 Series as the recommended replacement. This SKU is supplied as Appliance Only: PAN-OS and its base platform capabilities are included. The Cloud-Delivered Security Services, such as Advanced Threat Prevention, Advanced WildFire, Advanced URL Filtering and Advanced DNS Security, are licensed for a term and sold separately, as is the support contract.
Technical Details
The Palo Alto Networks PAN-PA-460 is a desktop next-generation firewall with 8×1GbE RJ45, running PAN-OS. Firewall throughput (appmix) is 4.2 Gbps, measured with App-ID and logging enabled. Threat Prevention throughput (appmix) is 3.0 Gbps, measured with App-ID, IPS, antivirus, antispyware, WildFire, DNS Security, file blocking, and logging enabled. IPsec VPN throughput is 2.3 Gbps on 64 KB HTTP transactions with logging enabled. It holds 400,000 concurrent sessions and opens 67,000 new sessions per second. Palo Alto Networks support and security subscriptions are sold separately. It operates 32°F to 104°F (0°C to 40°C) and is used at a branch office, retail site or midsize business for internet-edge protection, segmentation and site-to-site VPN.
Best For
The PAN-PA-460 suits a branch office, retail site or midsize business that needs 3.0 Gbps of Threat Prevention throughput with 400,000 concurrent sessions behind it. Its interfaces are 8×1GbE RJ45. Firewall throughput (appmix) is 4.2 Gbps, measured with App-ID and logging enabled. Compare it with the PAN-PA-455-5G, its nearest model in the same family, on those two figures and on the interface set, since the two models differ in ports. This model supports optional power redundancy using an additional power adapter.
Not suitable if:
- your inspected traffic exceeds 3.0 Gbps, since that is the published Threat Prevention throughput
- you need the Cloud-Delivered Security Services included in the part number, since an Appliance Only SKU carries PAN-OS only and the subscriptions are sold separately
- you need Power over Ethernet, since this model provides none
- you need a hardened appliance for a plant floor or outdoor cabinet, since this unit is rated only for 32°F to 104°F (0°C to 40°C)
PAN-PA-460 Specifications
| Ports & Uplinks | |
|---|---|
| Fixed Interfaces | 8×1GbE RJ45 |
| Max Port Speed | 1 GbE |
| Management & Console Ports | 1×1GbE RJ45 out-of-band management, 1×RJ45 console, 2×USB, 1×micro-USB console |
| Performance & Scale | |
| Firewall Throughput | 4.2 Gbps (appmix) |
| Threat Prevention Throughput | 3.0 Gbps (appmix) |
| TLS/SSL Inspection Throughput | Not published |
| IPsec VPN Throughput | 2.3 Gbps (64 KB HTTP) |
| Hardware & Memory | |
| Onboard Storage | 128 GB eMMC |
| Power & Thermal | |
| Power Supply | 100-240 VAC input (50-60 Hz) via external power adapter; maximum current consumption 3.4 A @ 12 VDC |
| Redundant Power Supply | Optional |
| Maximum Power Consumption | 41.3 W (32.6 W average) |
| Cooling | Passive cooling |
| Physical & Environmental | |
| Operating System | PAN-OS |
| Form Factor | Desktop |
| Dimensions (H x W x D) | 1.74 × 8.07 × 8.83 in (4.42 × 20.50 × 22.43 cm) |
| Weight | 5.0 lb (2.27 kg) |
| Operating Temperature | 32°F to 104°F (0°C to 40°C) |
| Software | |
| Central Management Platform | Panorama, Strata Cloud Manager |
| Routing Protocols & IPv6 | OSPFv2/v3 with graceful restart, BGP with graceful restart, RIP, static routing, policy-based forwarding, PPPoE, multicast (PIM-SM, PIM-SSM, IGMP v1/v2/v3); IPv6 in L2, L3, tap and virtual wire modes with SLAAC |
| Other | |
| Maximum Concurrent Sessions | 400,000 |
| New Sessions per Second | 67,000 |
| High Availability | Active/Active, Active/Passive |
FAQ
Does the Palo Alto Networks PAN-PA-460 support PoE?
No. The PAN-PA-460 provides no Power over Ethernet, so cameras, access points and IP phones need their own power source or a PoE switch between them and the firewall. Its interfaces are 8×1GbE RJ45, all data-only. Other models in the Palo Alto range do carry PoE ports on separate part numbers.
What interfaces does the PAN-PA-460 have?
The PAN-PA-460 provides 8×1GbE RJ45. Management and console connectivity is separate: 1×1GbE RJ45 out-of-band management, 1×RJ45 console, 2×USB, 1×micro-USB console.
How does high availability work on the Palo Alto Networks PAN-PA-460?
The PAN-PA-460 supports active/active and active/passive high availability. NGFW clustering is also supported for horizontal scaling.
How much traffic can the PAN-PA-460 handle?
Palo Alto publishes no user count, so compare the PAN-PA-460 on its published capacity figures. Firewall throughput (appmix) is 4.2 Gbps, measured with App-ID and logging enabled. Threat Prevention throughput (appmix) is 3.0 Gbps, measured with App-ID, IPS, antivirus, antispyware, WildFire, DNS Security, file blocking, and logging enabled. It holds 400,000 concurrent sessions, measured with HTTP transactions, and opens 67,000 new sessions per second, measured with application override on 1-byte HTTP transactions. All figures were measured on PAN-OS 12.1.
What is the difference between the PAN-PA-460 and the PAN-PA-455-5G?
Both run the same PAN-OS and share the family's platform capabilities. The PAN-PA-460 is rated at 4.2 Gbps firewall throughput, 3.0 Gbps Threat Prevention throughput and 400,000 concurrent sessions; the PAN-PA-455-5G is rated at 3.2 Gbps, 1.8 Gbps and 300,000. Their interface sets differ: the PAN-PA-460 has 8×1GbE RJ45, while the PAN-PA-455-5G has 1×embedded 5G cellular module, 2×1GbE SFP/RJ45 combo, 6×1GbE RJ45, 4×1GbE RJ45 PoE.
Does the PAN-PA-460 require a subscription to operate?
No. The PAN-PA-460 runs PAN-OS without any subscription, and its base platform capabilities include stateful firewalling and NAT, App-ID, User-ID, Content-ID, SSL/TLS decryption, IPsec VPN, dynamic routing, IPv6 and high availability. The Cloud-Delivered Security Services, including Advanced Threat Prevention, Advanced WildFire, Advanced URL Filtering and Advanced DNS Security, are licensed for a term and sold separately.
Does the PAN-PA-460 need a support contract?
Yes, unless your organisation holds an active Enterprise Support Agreement. A support service contract is required with the PAN-PA-460, and one-, three- and five-year options are available. Network Devices Inc. confirms the correct support option and any additional Palo Alto Networks licenses the deployment needs before the order is placed.
What is the SSL/TLS decryption throughput of the PAN-PA-460?
Palo Alto Networks does not publish a separate SSL/TLS decryption throughput figure for the PAN-PA-460. The datasheet lists SSL/TLS decryption as a platform capability but provides no bandwidth figure; do not infer decryption throughput from the Threat Prevention throughput.
Is the PAN-PA-460 end of sale or end of life?
Not yet, but Palo Alto Networks has announced both dates. Its hardware end-of-life listing gives the PAN-PA-460 an end-of-sale date of March 22, 2027 and an end-of-life date of March 21, 2032. The last supported software release is PAN-OS 12.2, and the recommended replacement is the PA-500 Series.
What condition is the PAN-PA-460 sold in, and what warranty applies?
Network Devices Inc. supplies the PAN-PA-460 new and factory sealed. It is covered by a one-year Network Devices Inc. warranty. Orders ship from our New Jersey and Texas warehouses.