What does it do?
Palo Alto Networks PA-Series is a family of NGFW-class firewalls running the PAN-OS operating system. PAN-OS classifies traffic not by port number but by application (App-ID), user (User-ID) and content, and security rules are written on these elements. From the smallest branch model to the largest central model, every device runs the same PAN-OS software, so the rule structure is the same everywhere.
Packets are processed in a single-pass architecture: networking, policy lookup, application identification and signature matching happen in one pass. That is why the Threat Prevention figures in the datasheets are measured with security services enabled. Encrypted traffic, including TLS 1.3, can be decrypted and inspected; decryption is enabled selectively by URL category, zone, user and port.
App-ID, User-ID, SSL/TLS decryption and site-to-site IPsec VPN are built into PAN-OS. Threat prevention, sandboxing, URL and DNS filtering, SD-WAN and similar functions are added through cloud-delivered subscriptions (Cloud-Delivered Security Services). A single device is managed from its own interface; multi-device estates move to central management with Panorama or Strata Cloud Manager.
Who is it for, and at what scale?
Desktop, fanless chassis; no rack cabinet needed. Firewall throughput 1.4–4.2 Gbps. PoE on PA-415, PA-445 and PA-455; integrated 5G modem on PA-415-5G and PA-455-5G for backup or primary WAN. For branches connecting to headquarters over IPsec VPN or SD-WAN.
Nine models, 0.8–8.5 Gbps firewall throughput, up to 24 copper and fiber interfaces. IEEE 802.3bt PoE (90 W per port) on PA-545-POE and PA-555-POE: cameras, access points and IP phones powered from the same device.
1U rack, 8.5–9.5 Gbps firewall throughput, 10G SFP+ uplinks and a dedicated 10G HA port. At the campus internet edge, medical devices, the administrative network and the guest network are kept in separate zones. Unmanaged IoT devices become visible with the Device Security subscription.
Between the OT network and the corporate network, or in a government building's DMZ, inter-zone traffic is controlled per application and user. Virtual wire (transparent) mode can be used to insert the firewall without changing the existing topology. Depending on bandwidth, PA-1400 is chosen, or PA-3400 for a high-speed internet gateway.
Key features
- App-ID, User-ID and Content-ID: rules are written by application, user and content instead of port
- SSL/TLS decryption (including TLS 1.3); selective by URL category, zone, user and port
- Single-pass architecture: Threat Prevention figures are measured with IPS, antivirus, antispyware, WildFire and logging enabled
- High availability: active/passive and active/active on all series; dedicated 10G HSCI HA port on PA-1400, plus HA clustering on PA-3400
- PoE: 4 ports with a 91 W total on PA-415 / PA-445 / PA-455; 181 W on PA-545-POE, 330 W on PA-555-POE (90 W per port); 151 W on PA-1410 / PA-1420
- Integrated 5G: embedded 5G cellular module on PA-415-5G and PA-455-5G
- Site-to-site IPsec VPN (IKEv1/IKEv2, 256-bit AES); remote access VPN with a GlobalProtect license
- SD-WAN: path quality measurement (jitter, packet loss, latency) and dynamic path change; requires the Advanced SD-WAN subscription
- Post-quantum cryptography with PAN-OS 12.1: decryption and site-to-site VPN supporting ML-KEM, ML-DSA, SLH-DSA; Zero Touch Provisioning and TPM-based secure boot
Series and model comparison
| PA-440 | PA-460 | PA-520 | PA-560 | PA-1410 | PA-1420 | PA-3410 | |
|---|---|---|---|---|---|---|---|
| Series / target | PA-400 · branch, small office | PA-400 · branch, small office | PA-500 · branch, midsize | PA-500 · branch, midsize | PA-1400 · midsize, campus edge | PA-1400 · midsize, campus edge | PA-3400 · high-speed internet gateway |
| Firewall throughput (appmix) | 2.4 Gbps | 4.2 Gbps | 2.8 Gbps | 8.5 Gbps | 8.5 Gbps | 9.5 Gbps | 14 Gbps |
| Threat Prevention (appmix) | 1.2 Gbps | 3.0 Gbps | 1.8 Gbps | 6.0 Gbps | 4.5 Gbps | 6.2 Gbps | 7.5 Gbps |
| IPsec VPN | 1.1 Gbps | 2.3 Gbps | 1.5 Gbps | 5.5 Gbps | 4.1 Gbps | 5.6 Gbps | 6.6 Gbps |
| Max concurrent sessions | 200,000 | 400,000 | 148,000 | 598,000 | 945,000 | 1.4 million | 1.4 million |
| New sessions / s | 34,000 | 67,000 | 25,000 | 100,000 | 100,000 | 140,000 | 145,000 |
| Virtual systems (base / max) | 1 / 2 | 1 / 5 | — | 1 / 5 | 1 / 6 | 1 / 6 | 1 / 11 |
| Data ports | 8 × 1G RJ45 | 8 × 1G RJ45 | 8 × 1G RJ45 | 16 × 1G RJ45, 4 × 1G SFP, 4 × 1G/10G SFP/SFP+ | 8 × 10/100/1000, 4 × 1G/2.5G/5G PoE, 6 × 1G SFP, 4 × 1G/10G SFP/SFP+ | 4 × 10/100/1000, 4 × 1G/2.5G/5G, 4 × 1G/2.5G/5G PoE, 2 × 1G SFP, 8 × 1G/10G SFP/SFP+ | 12 × 1G/2.5G/5G/10G, 10 × 1G/10G SFP/SFP+, 4 × 25G SFP28 |
| PoE budget | — | — | — | — | 151 W (max 90 W per port) | 151 W (max 90 W per port) | — |
| Chassis / cooling | Desktop, fanless | Desktop, fanless | Compact chassis, passive cooling; optional 1U rack kit | Compact chassis, active cooling; optional 1U rack kit | 1U 19" rack; optional 2nd power supply | 1U 19" rack; optional 2nd power supply | 1U 19" rack; redundant 450 W AC power supplies |
| Max power consumption | 34.3 W | 41.3 W | 30 W | 106 W | 290 W | 300 W | 190 W |
Source: Palo Alto Networks PA-400 Series (022326), PA-500 Series (031026), PA-1400 Series (012726) and PA-3400 Series (021126) datasheets; all values measured on PAN-OS 12.1. Firewall throughput: App-ID and logging enabled, appmix. Threat Prevention: App-ID, IPS, antivirus, antispyware, WildFire, file blocking and logging enabled (plus DNS Security on PA-400 and PA-1400), appmix. IPsec VPN: 64 KB HTTP. Concurrent sessions: HTTP; new sessions/s: application override, 1-byte HTTP. Virtual systems above the base quantity require a separate license. The exact model is confirmed during the site survey together with the traffic profile and the services to be enabled.
Migration and refresh
Refreshing end-of-sale Palo Alto appliances
According to Palo Alto Networks, PA-220 reached end of sale on 31.01.2023 and its support ends on 31.01.2028; the recommended replacement is the PA-400 or PA-500 Series. The PA-800 Series (PA-820/850) reached end of sale on 31.08.2024 and its support ends on 31.08.2029; the replacement is PA-1400. The PA-3200 Series reached end of sale on 31.08.2023 and its support ends on 31.08.2028; the replacement is PA-3400. Promark moves the existing configuration to the new appliance and re-plans the subscriptions for it.
Migrating from another firewall brand
The existing rule set, NAT and VPN definitions are inventoried during the survey and imported into PAN-OS. After migration, Policy Optimizer in PAN-OS identifies port-based rules and helps convert them safely into application-based (App-ID) rules. The cutover is done in stages while monitoring traffic.
From single devices to central management
As the number of branches grows, individually managed devices are imported into Panorama (Device Configuration Import). Shared rules are distributed from one place with device groups and network settings with template stacks; new branches are brought online with Zero Touch Provisioning.
PA-400 or PA-1400?
- Firewall throughput 1.4–4.2 Gbps, Threat Prevention 0.8–3.0 Gbps (appmix)
- Desktop, fanless chassis: branches, shops and offices without a rack cabinet
- 64,000–400,000 concurrent sessions, 1G copper ports
- 91 W PoE on PA-415 / PA-445 / PA-455, cellular WAN with the 5G models
- Firewall throughput 8.5–9.5 Gbps, Threat Prevention 4.5–6.2 Gbps (appmix)
- 1U 19" rack; 1G/2.5G/5G multi-gig and 10G SFP+ ports
- 945,000 / 1.4 million sessions, up to 6 virtual systems, dedicated 10G HA port
- Native web proxy and a 151 W PoE budget
Promark's scope of services
- Site survey: inventory of the existing firewall, rule set, internet lines, VPNs and branches
- Datasheet-based sizing (bandwidth, subscriptions to enable, session and port requirements); BOM and subscription list within 24–48 hours
- Installation and commissioning: zone/segmentation design, NAT, IPsec and GlobalProtect VPN, SSL/TLS decryption policy, HA pair
- Rule migration from the existing firewall and conversion to App-ID-based rules
- Central management setup with Panorama or Strata Cloud Manager
- Tracking of subscription and support renewals, PAN-OS updates and annual maintenance
- On-site service across Türkiye and in Turkmenistan
Sectors
Related catalog products
Frequently asked questions
Which model fits which bandwidth?
Sizing is based on the Threat Prevention figure, measured with security services enabled, rather than the raw firewall figure. This value is 0.8 Gbps on PA-410, 3.0 Gbps on PA-460, 1.8 Gbps on PA-520, 6.0 Gbps on PA-560, 4.5 Gbps on PA-1410, 6.2 Gbps on PA-1420 and 7.5–20 Gbps on the PA-3400 Series. Besides internet line speed, concurrent sessions, ports and PoE requirements are assessed together during the survey.
Which subscriptions are available, and which are mandatory?
App-ID, User-ID, SSL/TLS decryption and site-to-site IPsec VPN are built into PAN-OS; technically no subscription is mandatory. The subscriptions in the current datasheets are Advanced Threat Prevention, Advanced WildFire, Advanced URL Filtering, Advanced DNS Security, Device Security, SaaS Security, AI Access Security and Advanced SD-WAN; remote access VPN requires a GlobalProtect license. Because the datasheet Threat Prevention figures are measured with IPS, antivirus and WildFire enabled, the threat prevention subscriptions are planned together for each scenario. Threat prevention subscriptions are licensed per device, independent of user count.
Is Panorama required?
No. One or a few devices can be managed from their own interface. In multi-branch estates Panorama distributes shared rules from one place using device groups and template stacks; the M-300 appliance manages up to 1000 firewalls and the M-700 up to 5000, and it can also run as a virtual appliance on VMware ESXi, KVM, Nutanix and Hyper-V. The cloud-based alternative is Strata Cloud Manager: the Essentials version is free, the Pro version is paid, and PAN-OS 10.1 or later is required.
Is high availability (HA) supported?
Yes. The PA-400, PA-500, PA-1400 and PA-3400 Series all support active/passive and active/active HA; failures are detected through path and interface monitoring. PA-1400 has a dedicated 10G HSCI port for the HA link, and PA-3400 additionally supports HA clustering. We set up the HA pair and test failover as part of commissioning.
How do we migrate from our current firewall?
First, the existing rule set, NAT and VPN definitions are inventoried and imported into PAN-OS. After migration, Policy Optimizer identifies port-based rules and helps convert them into application-based rules. For end-of-sale Palo Alto appliances (PA-220, PA-800, PA-3200), the replacement series recommended by Palo Alto Networks is selected and the configuration is moved to the new appliance.
How do subscription and support renewals work?
Subscriptions and the support contract are purchased per device and are valid for a defined term. Palo Alto Networks support programs are Standard, Premium and Platinum; Premium includes next-business-day hardware replacement (RMA). Promark tracks expiry dates and sends the renewal quote before the term ends.
Just send us on WhatsApp the number of locations, internet line speed, user and device count, required services (VPN, SD-WAN, URL filtering) and your current firewall model. We return a BOM and quote within 24–48 hours. Across Türkiye and in Turkmenistan.