Firewall throughput (HTTP/appmix) ( Firewall throughput is measured with App-ID and logging enabled, utilizing 64 KB HTTP/appmix transactions.) 63/59.4 Gbps
Threat Prevention throughput (HTTP/appmix) (Threat Prevention throughput is measured with App-ID, IPS, antivirus, antispyware, WildFire, DNS Security, file blocking, and logging enabled,
utilizing 64 KB HTTP/appmix transactions.) 37.6/40.9 Gbps
IPsec VPN throughput (IPsec VPN throughput is measured with 64 KB HTTP transactions and logging enabled.) 42 Gbps
Max sessions 8.3M
New sessions per second (New sessions per second is measured with application-override, utilizing 1 byte HTTP transactions.) 366.000
Virtual systems (base/max) (Adding virtual systems over base quantity requires a separately purchased license.) 25/125
PA-5400 Series Specifications
Interface Modes L2, L3, tap, virtual wire (transparent mode)
Routing OSPFv2/v3 with graceful restart, BGP with graceful restart, RIP, static routing
Policy-based forwarding
Point-to-Point Protocol over Ethernet (PPPoE) and DHCP supported for dynamic address assignment
Multicast: PIM-SM, PIM-SSM, IGMP v1, v2, and v3
Bidirectional Forwarding Detection (BFD)
SD-WAN Path quality measurement (jitter, packet loss, latency)
Initial path selection (PBF)
Key exchange: manual key, IKEv1, and IKEv2 (pre-shared key, certificate-based authentication)
IPv6 L2, L3, tap, virtual wire (transparent mode)
Features: App-ID, User-ID, Content-ID, WildFire, and SSL Decryption
SLAAC
IPsec and SSL VPN Key exchange: manual key, IKEv1, and IKEv2 (pre-shared key, certificate-based authentication)
Encryption: 3des, AES (128-bit, 192-bit, 256-bit)
Authentication: MD5, SHA-1, SHA-256, SHA-384, SHA-512
GlobalProtect Large Scale VPN for simplified configuration and management*
Secure access over IPsec and SSL VPN tunnels using GlobalProtect gateway and portals*
VLANs 802.1Q VLAN tags per device/per interface: 4,094/4,094
Aggregate interfaces (802.3ad), LACP
Network Address Translation NAT modes (IPv4): static IP, dynamic IP, Dynamic IP and Port (port address translation)
NAT64, NPTv6
Additional NAT features: dynamic IP reservation, tunable Dynamic IP and Port oversubscription
High Availability Modes: active/active, active/passive, HA clustering
Failure detection: path monitoring, interface monitoring
Mobile Network Infrastructure 5G Security
GTP Security
SCTP Security
* Requires GlobalProtect license
Hardware Specifications
1/O PA-5430: 1G/2.5G/5G/10G (8), 1G/10G SFP/SFP+ (12), 25G SFP28 (4), 40G/100G QSPF+/QSFP28 (4)
Management I/O 1G/10G SFP/SFP+ out-of-band management port (1),
1G/10G SFP/SFP+ high availability (2), 40G QSFP+ high availability (1),
RJ-45 console port (1), Micro USB
Storage Capacity 480 GB SSD pair, system storage
Power Supply (Avg/Max Power Consumption) 630/760 W
Max BTU/hr 1638
Power Supplies (Base/Max) 1:1 fully redundant (2/2)
AC Input Voltage (Input Hz) 100–240 VAC (50–60 Hz)
AC Power Supply Output 1,200 watts/power supply
Max Current Consumption AC: 7 A @ 100 VAC, 3 A @ 240 VAC
DC: 15 A @ -48 VDC, 12 A @ -60 VDC
Max Inrush Current AC: 50 A @ 230 VAC, 50 A @ 120 VAC
DC: 200 A @ 72 VDC
Mean Time Between Failure (MTBF) 22 years
Rack Mount Dimensions 2U, 19" standard rack (3.45" H x 22.5" D x 17.34" W)
Weight (Standalone Device/As Shipped) 35.2 lbs/48.8 lbs
Safety cTUVus, CB
EMI FCC Class A, CE Class A, VCCI Class A
Environment Operating temperature: 32°F to 122°F, 0°C to 50°C
Nonoperating temperature: -4°F to 158°F, -20°C to 70°C
Humidity tolerance: 10% to 90%
Maximum altitude: 10,000 ft/3,048 m
Airflow: front to back