
Palo Alto Networks PAN-PA-5550-AC Rackmount Firewall with 16x 10/25G SFP28, AC Power
Overview
The Palo Alto Networks PA-5500 Series is a quantum-optimized data-centre platform spanning multiple hardware tiers. The PA-5540 through PA-5580 models provide 100/400GbE QSFP-DD interfaces, a cold-swap 3.84 TB RAID1 SSD pair for system and log storage (optional in the specification table, listed as included with this part number in the ordering table), and redundant power arranged 2+2 at 220 V or 3+1 at 110 V. It runs PAN-OS with the advanced routing engine, supports a maximum of 225 virtual systems (25 in the base, the rest separately licensed, and 25 at most in an active/active NGFW cluster), and carries two 100/400 gigabit HSCI ports and two dedicated 10 gigabit log ports. NGFW clustering allows horizontal scaling across appliances. The PAN-PA-5550-AC is the AC-powered model on the front panel with sixteen SFP28, sixteen QSFP28 and four 100/400G QSFP-DD ports, rated at 175 Gbps of firewall throughput. This SKU is supplied as Appliance Only: PAN-OS and its base platform capabilities are included. The Cloud-Delivered Security Services, such as Advanced Threat Prevention, Advanced WildFire, Advanced URL Filtering and Advanced DNS Security, are licensed for a term and sold separately, as is the support contract.
Technical Details
The Palo Alto Networks PAN-PA-5550-AC is a rackmount next-generation firewall with 16×10/25GbE SFP28, 16×40/100GbE QSFP28, 4×100/400GbE QSFP-DD, running PAN-OS. Firewall throughput (appmix) is 175 Gbps, measured with App-ID and logging enabled. Threat Prevention throughput (appmix) is 120 Gbps, measured with App-ID, IPS, antivirus, antispyware, WildFire, file blocking, and logging enabled. IPsec VPN throughput is 100 Gbps on 64 KB HTTP transactions with logging enabled. It holds 49,000,000 concurrent sessions and opens 1,670,000 new sessions per second. Palo Alto Networks support and security subscriptions are sold separately. It operates 32°F to 122°F (0°C to 50°C) and is used at a data-centre edge for north-south inspection, DMZ segmentation and high-throughput VPN aggregation.
Best For
The PAN-PA-5550-AC suits a data-centre edge that needs 120 Gbps of Threat Prevention throughput with 49,000,000 concurrent sessions behind it. Its interfaces are 16×10/25GbE SFP28, 16×40/100GbE QSFP28, 4×100/400GbE QSFP-DD. Firewall throughput (appmix) is 175 Gbps, measured with App-ID and logging enabled. Compare it with the PAN-PA-5560-AC, its nearest model in the same family, on those two figures and on the interface set, since the two models differ in ports.
Not suitable if:
- your inspected traffic exceeds 120 Gbps, since that is the published Threat Prevention throughput
- you need the Cloud-Delivered Security Services included in the part number, since an Appliance Only SKU carries PAN-OS only and the subscriptions are sold separately
- you need Power over Ethernet, since this model provides none
- you need a hardened appliance for a plant floor or outdoor cabinet, since this unit is rated only for 32°F to 122°F (0°C to 50°C)
PAN-PA-5550-AC Specifications
| Ports & Uplinks | |
|---|---|
| Fixed Interfaces | 16×10/25GbE SFP28, 16×40/100GbE QSFP28, 4×100/400GbE QSFP-DD |
| Max Port Speed | 400 GbE |
| Management & Console Ports | 2×1/10GbE SFP+ out-of-band management, 1×RJ45 console, 1×USB-C console, 1×USB 3.2 Gen1 Type-A bootstrap, 2×100/400GbE QSFP-DD HSCI, 2×10GbE SFP+ log |
| Performance & Scale | |
| Firewall Throughput | 175 Gbps (appmix) |
| Threat Prevention Throughput | 120 Gbps (appmix) |
| TLS/SSL Inspection Throughput | Not published |
| IPsec VPN Throughput | 100 Gbps (64 KB HTTP) |
| Hardware & Memory | |
| Onboard Storage | 3.84 TB RAID1 SSD pair for system and log storage, cold swap |
| Power & Thermal | |
| Power Supply | 2+2 redundant for 220 V, 3+1 redundant for 110 V; 100-240 VAC input (50-60 Hz); 2,700 W per power supply at 220 V or 1,200 W at 110 V; maximum current consumption 20.3 A @ 110 VAC and 9.3 A @ 240 VAC |
| Redundant Power Supply | Yes |
| Maximum Power Consumption | 3,100 W (2,100 W average) |
| Cooling | Front-to-back airflow (port side to power supply side) |
| Physical & Environmental | |
| Operating System | PAN-OS |
| Form Factor | 3U Rackmount |
| Dimensions (H x W x D) | 5.2 × 17.3 × 29.8 in (13.21 × 43.94 × 75.69 cm) |
| Weight | 70 lb (31.75 kg) |
| Operating Temperature | 32°F to 122°F (0°C to 50°C) |
| Software | |
| Central Management Platform | Panorama, Strata Cloud Manager |
| Routing Protocols & IPv6 | Advanced routing engine only; OSPFv2/v3 and MP-BGP with graceful restart, RIP, static routing, policy-based forwarding, PPPoE and DHCP client for IPv4 and IPv6, DHCPv4 server and relay, multicast (PIM-SM, PIM-SSM, IGMPv2/v3), Bidirectional Forwarding Detection (BFD) and multihop BFD; IPv6 dual-stack and IPv6-only with geolocation, OSPFv3, MP-BGP, NAT64, NPTv6, DHCPv6 client with prefix delegation and SLAAC server |
| Other | |
| Maximum Concurrent Sessions | 49,000,000 |
| New Sessions per Second | 1,670,000 |
| High Availability | NGFW clustering with Active/Active; Active/Passive listed as a future release |
PAN-PA-5550-AC Accessories
| Included (PAN-PA-5550-AC) | 4 × PAN-PA-5500-PWR-2700-AC; 5 × PAN-PA-FAN-2RU-A; 1 × PAN-PA-5500-ACC-A accessory kit; 1 × PAN-PA-3RU-RACK-A; 2 × PAN-SFP-CG; 1 × PAN-PA-5500-SSD-3.84TB-PAIR |
| Optional / Spares | PAN-PA-5500-SSD-3.84TB-PAIR (spare); PAN-PA-5500-ACC-A (spare kit with AC power cables, USB cable, Cat6); PAN-PA-5500-ACC-B (spare kit with DC cables, USB, Cat6) |
FAQ
Does the Palo Alto Networks PAN-PA-5550-AC support PoE?
No. The PAN-PA-5550-AC provides no Power over Ethernet, so cameras, access points and IP phones need their own power source or a PoE switch between them and the firewall. Its interfaces are 16×10/25GbE SFP28, 16×40/100GbE QSFP28, 4×100/400GbE QSFP-DD, all data-only. Other models in the Palo Alto range do carry PoE ports on separate part numbers.
What interfaces does the PAN-PA-5550-AC have?
The PAN-PA-5550-AC provides 16×10/25GbE SFP28, 16×40/100GbE QSFP28, 4×100/400GbE QSFP-DD. Management and console connectivity is separate: 2×1/10GbE SFP+ out-of-band management, 1×RJ45 console, 1×USB-C console, 1×USB 3.2 Gen1 Type-A bootstrap, 2×100/400GbE QSFP-DD HSCI, 2×10GbE SFP+ log. The ordering table lists two PAN-SFP-CG modules with this part number; other transceivers are sold separately.
How does high availability work on the Palo Alto Networks PAN-PA-5550-AC?
The PAN-PA-5550-AC supports NGFW clustering in active/active mode; the datasheet lists active/passive high availability as a future release. This model has two 100/400G HSCI ports among its management interfaces, and NGFW clustering provides horizontal scaling across appliances.
How much traffic can the PAN-PA-5550-AC handle?
Palo Alto publishes no user count, so compare the PAN-PA-5550-AC on its published capacity figures. Firewall throughput (appmix) is 175 Gbps, measured with App-ID and logging enabled. Threat Prevention throughput (appmix) is 120 Gbps, measured with App-ID, IPS, antivirus, antispyware, WildFire, file blocking, and logging enabled. It holds 49,000,000 concurrent sessions, measured with HTTP transactions, and opens 1,670,000 new sessions per second, measured with application override on 1-byte HTTP transactions. All figures were measured on PAN-OS 12.1.
What is the difference between the PAN-PA-5550-AC and the PAN-PA-5560-AC?
Both run the same PAN-OS and share the family's platform capabilities. The PAN-PA-5550-AC is rated at 175 Gbps firewall throughput, 120 Gbps Threat Prevention throughput and 49,000,000 concurrent sessions; the PAN-PA-5560-AC is rated at 240 Gbps, 180 Gbps and 74,000,000. Their interface sets differ: the PAN-PA-5550-AC has 16×10/25GbE SFP28, 16×40/100GbE QSFP28, 4×100/400GbE QSFP-DD, while the PAN-PA-5560-AC has 8×10/25GbE SFP28, 12×40/100GbE QSFP28, 8×100/400GbE QSFP-DD.
Does the PAN-PA-5550-AC require a subscription to operate?
No. The PAN-PA-5550-AC runs PAN-OS without any subscription, and its base platform capabilities include stateful firewalling and NAT, App-ID, User-ID, Content-ID, SSL/TLS decryption, IPsec VPN, dynamic routing, IPv6 and high availability. The Cloud-Delivered Security Services, including Advanced Threat Prevention, Advanced WildFire, Advanced URL Filtering and Advanced DNS Security, are licensed for a term and sold separately.
Does the PAN-PA-5550-AC need a support contract?
Yes, unless your organisation holds an active Enterprise Support Agreement. A support service contract is required with the PAN-PA-5550-AC, and one-, three- and five-year options are available. Network Devices Inc. confirms the correct support option and any additional Palo Alto Networks licenses the deployment needs before the order is placed.
What is the SSL/TLS decryption throughput of the PAN-PA-5550-AC?
Palo Alto Networks does not publish a separate SSL/TLS decryption throughput figure for the PAN-PA-5550-AC. The datasheet lists SSL/TLS decryption as a platform capability but provides no bandwidth figure; do not infer decryption throughput from the Threat Prevention throughput.
What condition is the PAN-PA-5550-AC sold in, and what warranty applies?
Network Devices Inc. supplies the PAN-PA-5550-AC new and factory sealed, in original Palo Alto Networks packaging with the standard accessories. It is covered by a one-year Network Devices Inc. warranty and a 30-day return window. Orders ship from our New Jersey and Texas warehouses.