Palo Alto Networks PAN-PA-520 Desktop Firewall with 8x 1G RJ45

Brand:
Palo Alto
Part Number:
PAN-PA-520
A support service contract is required unless your organization has an active Enterprise Support Agreement (ESA). 1-year, 3-year, and 5-year support options are available. Please contact us before fulfillment to confirm the correct support option or any additional Palo Alto licenses you may need.
$1,914.75

Net 30 or as low as $—/month Apply Now

Quote

Overview

The Palo Alto Networks PA-500 Series is a post-quantum cryptography (PQC)-ready branch line of nine models, from a seven-port unit to a 24-port appliance with 10 gigabit uplinks. It runs PAN-OS with the advanced routing engine and the single-pass architecture, and the range includes two PoE models for sites that power cameras, access points or phones from the firewall itself. High availability is supported in active/active and active/passive modes. The PAN-PA-520 is the 8-port data-only configuration in that line-up, rated at 2.8 Gbps of firewall throughput. This SKU is supplied as Appliance Only: PAN-OS and its base platform capabilities are included. The Cloud-Delivered Security Services, such as Advanced Threat Prevention, Advanced WildFire, Advanced URL Filtering and Advanced DNS Security, are licensed for a term and sold separately, as is the support contract.

Technical Details

The Palo Alto Networks PAN-PA-520 is a desktop next-generation firewall with 8×1GbE RJ45, running PAN-OS. Firewall throughput (appmix) is 2.8 Gbps, measured with App-ID and logging enabled. Threat Prevention throughput (appmix) is 1.8 Gbps, measured with App-ID, IPS, antivirus, antispyware, WildFire, file blocking, and logging enabled. IPsec VPN throughput is 1.5 Gbps on 64 KB HTTP transactions with logging enabled. It holds 148,000 concurrent sessions and opens 25,000 new sessions per second. Palo Alto Networks support and security subscriptions are sold separately. It operates 32°F to 104°F (0°C to 40°C) and is used at a branch office, retail site or midsize business for internet-edge protection, segmentation and site-to-site VPN.

Best For

The PAN-PA-520 suits a branch office, retail site or midsize business that needs 1.8 Gbps of Threat Prevention throughput with 148,000 concurrent sessions behind it. Its interfaces are 8×1GbE RJ45. Firewall throughput (appmix) is 2.8 Gbps, measured with App-ID and logging enabled. Compare it with the PAN-PA-540, its nearest model in the same family, on those two figures and on the interface set, since the two models differ in ports. This model supports optional power redundancy using an additional power adapter.

Not suitable if:

  • your inspected traffic exceeds 1.8 Gbps, since that is the published Threat Prevention throughput
  • you need the Cloud-Delivered Security Services included in the part number, since an Appliance Only SKU carries PAN-OS only and the subscriptions are sold separately
  • you need Power over Ethernet, since this model provides none
  • you need a hardened appliance for a plant floor or outdoor cabinet, since this unit is rated only for 32°F to 104°F (0°C to 40°C)

PAN-PA-520 Specifications

Ports & Uplinks
Fixed Interfaces8×1GbE RJ45
Max Port Speed1 GbE
Management & Console Ports1×1GbE RJ45 out-of-band management, 1×USB, 1×RJ45 console, 1×USB-C console
Performance & Scale
Firewall Throughput2.8 Gbps (appmix)
Threat Prevention Throughput1.8 Gbps (appmix)
TLS/SSL Inspection ThroughputNot published
IPsec VPN Throughput1.5 Gbps (64 KB HTTP)
Hardware & Memory
Onboard Storage120 GB
Power & Thermal
Power Supply100-240 VAC input (50-60 Hz) via external power adapter; maximum current consumption 4 A @ 12 VDC
Redundant Power SupplyOptional
Maximum Power Consumption30 W
CoolingPassive cooling
Physical & Environmental
Operating SystemPAN-OS
Form FactorDesktop
Dimensions (H x W x D)1.74 × 8.0 × 10.4 in (4.42 × 20.32 × 26.42 cm)
Weight5.8 lb (2.63 kg)
Operating Temperature32°F to 104°F (0°C to 40°C)
Software
Central Management PlatformPanorama, Strata Cloud Manager
Routing Protocols & IPv6Advanced routing engine only; OSPFv2/v3 and MP-BGP with graceful restart, RIP, static routing, policy-based forwarding, PPPoE and DHCP client for IPv4 and IPv6, DHCPv4 server, multicast (PIM-SM, PIM-SSM, IGMPv2/v3); IPv6 dual-stack and IPv6-only with geolocation, OSPFv3, MP-BGP, NAT64, NPTv6, DHCPv6 client with prefix delegation and SLAAC server
Other
Maximum Concurrent Sessions148,000
New Sessions per Second25,000
High AvailabilityActive/Active, Active/Passive

PAN-PA-520 Accessories

Power AdaptersPAN-PWR-150W-12V-AC-A - 150W spare AC power adapter (compatible with PA-520)
Rack MountsPAN-1RU-4POST-RACK-11 - 1RU 4-post rack (supports two PA-520 units & four adapters)

FAQ

Does the Palo Alto Networks PAN-PA-520 support PoE?

No. The PAN-PA-520 provides no Power over Ethernet, so cameras, access points and IP phones need their own power source or a PoE switch between them and the firewall. Its interfaces are 8×1GbE RJ45, all data-only. Other models in the Palo Alto range do carry PoE ports on separate part numbers.

What interfaces does the PAN-PA-520 have?

The PAN-PA-520 provides 8×1GbE RJ45. Management and console connectivity is separate: 1×1GbE RJ45 out-of-band management, 1×USB, 1×RJ45 console, 1×USB-C console.

How does high availability work on the Palo Alto Networks PAN-PA-520?

The PAN-PA-520 supports active/active and active/passive high availability.

How much traffic can the PAN-PA-520 handle?

Palo Alto publishes no user count, so compare the PAN-PA-520 on its published capacity figures. Firewall throughput (appmix) is 2.8 Gbps, measured with App-ID and logging enabled. Threat Prevention throughput (appmix) is 1.8 Gbps, measured with App-ID, IPS, antivirus, antispyware, WildFire, file blocking, and logging enabled. It holds 148,000 concurrent sessions, measured with HTTP transactions, and opens 25,000 new sessions per second, measured with application override on 1-byte HTTP transactions. All figures were measured on PAN-OS 12.1.

What is the difference between the PAN-PA-520 and the PAN-PA-540?

Both run the same PAN-OS and share the family's platform capabilities. The PAN-PA-520 is rated at 2.8 Gbps firewall throughput, 1.8 Gbps Threat Prevention throughput and 148,000 concurrent sessions; the PAN-PA-540 is rated at 3.8 Gbps, 2.2 Gbps and 248,000. Their interface sets differ: the PAN-PA-520 has 8×1GbE RJ45, while the PAN-PA-540 has 8×1GbE RJ45, 2×1GbE SFP.

Does the PAN-PA-520 require a subscription to operate?

No. The PAN-PA-520 runs PAN-OS without any subscription, and its base platform capabilities include stateful firewalling and NAT, App-ID, User-ID, Content-ID, SSL/TLS decryption, IPsec VPN, dynamic routing, IPv6 and high availability. The Cloud-Delivered Security Services, including Advanced Threat Prevention, Advanced WildFire, Advanced URL Filtering and Advanced DNS Security, are licensed for a term and sold separately.

Does the PAN-PA-520 need a support contract?

Yes, unless your organisation holds an active Enterprise Support Agreement. A support service contract is required with the PAN-PA-520, and one-, three- and five-year options are available. Network Devices Inc. confirms the correct support option and any additional Palo Alto Networks licenses the deployment needs before the order is placed.

What is the SSL/TLS decryption throughput of the PAN-PA-520?

Palo Alto Networks does not publish a separate SSL/TLS decryption throughput figure for the PAN-PA-520. The datasheet lists SSL/TLS decryption as a platform capability but provides no bandwidth figure; do not infer decryption throughput from the Threat Prevention throughput.

What condition is the PAN-PA-520 sold in, and what warranty applies?

Network Devices Inc. supplies the PAN-PA-520 new and factory sealed, in original Palo Alto Networks packaging with the standard accessories. It is covered by a one-year Network Devices Inc. warranty and a 30-day return window. Orders ship from our New Jersey and Texas warehouses.

Reviews