Tech Spec Spec it right!

Palo Alto Networks PA-1510-POE

A 1U branch-office NGFW with built-in Layer 2 switching and 485 W of 802.3bt PoE++ across its copper ports, aimed at smaller campuses and larger distributed branch offices and optimized for post-quantum encrypted traffic.

Performance

Firewall throughput (appmix)
15 Gbps
Threat prevention throughput (appmix)
9 Gbps
IPsec VPN throughput
7 Gbps
Max concurrent sessions
1,095,000
New sessions/sec
140,000
Virtual systems (base/max)
1 / 6

Interfaces

Data ports
12 × 10/100/1000 Cu, 8 × 1G/2.5G/5G Cu, 4 × 1G SFP, 8 × 1G/10G SFP+
Out-of-band management
1 × 10/100/1000 Cu
Console
RJ-45 (1), USB-C (1)
Bootstrap
USB 3.2 Gen1 Type-A (1)
HA
10/100/1000 Cu (2)
HSCI
10G SFP+ (1)
Interface modes
L2 mode (not on MC-LAG aggregate interfaces), L3 mode, tap, virtual wire (transparent mode)

Switching

Layer 2 switching
On all data ports; 802.1Q VLAN trunking, 4,094 VLANs per device/interface
Loop prevention
Multiple Spanning Tree Protocol
Storm control
Unknown unicast, multicast and broadcast storm control
Link aggregation
802.3ad LACP

Routing

Routing engine
Advanced Routing Engine (ARE), the only supported routing engine
Protocols
OSPFv2/v3, multiprotocol BGP with graceful restart, RIP, static routing, policy-based forwarding
Dynamic addressing
PPPoE and DHCP clients (IPv4 and IPv6); DHCPv4 server and relay
Multicast
PIM-SM, PIM-SSM, IGMPv2, IGMPv3
Failure detection
Bidirectional Forwarding Detection (BFD) and multihop BFD
SD-WAN
Path quality measurement (jitter, packet loss, latency), bandwidth monitoring, multi-VR/LR over the SD-WAN overlay, Prisma Access Hub (hybrid SASE), ADEM for NGFW support

Security services

App-ID
Layer 7 application identification on all ports via protocol decoding, heuristics and signature matching; optional App-ID Cloud Engine for SaaS apps
Threat prevention
Advanced Threat Prevention (inline zero-day/C2 IPS), Advanced WildFire malware analysis, Advanced URL Filtering, Advanced DNS Security, Advanced IP Defense
Decryption
SSL/TLS inbound and outbound decryption incl. TLSv1.3 and QUIC/HTTP3; classical (RSA, ECDHE, DHE) and post-quantum (ML-KEM, HQC, experimental BIKE/Frodo-KEM) key exchange
Post-quantum cryptography
PQC TLS decryption, PQC site-to-site VPN, PQC-classical TLS cipher translation proxy, PQC TLS service profile for management access, PQC GlobalProtect; NIST ML-KEM/ML-DSA/SLH-DSA plus experimental Classic McEliece, BIKE, HQC, Frodo-KEM, NTRU-Prime, and hybrid PQC-classical algorithms
Management/analytics
Strata Cloud Manager AI-powered unified management and policy lifecycle across enforcement points

VPN

Key exchange
Manual key, IKEv1, IKEv2 (pre-shared key and certificate-based); post-quantum PPK
Encryption
3DES, AES (128/192/256-bit)
Authentication
MD5, SHA-1, SHA-256, SHA-384, SHA-512
Remote access
GlobalProtect gateway/portal (license required); GlobalProtect Large Scale VPN

Power

Power supplies
1 × 1,200 W AC (PAN-PWR-1200W-54V-AC-A); optional 2nd AC 1,200 W for redundancy; 1,200 W DC FRU available
Max power consumption
845 W (with 485 W PoE)
Input voltage
AC 100–240 VAC (50–60 Hz); DC -48 to -60 VDC
Max current draw
7.7 A @ 110 VAC, 3.5 A @ 240 VAC, 17.6 A @ 48 VDC (with 485 W PoE)
Max inrush current
30 A @ 230 VAC / 50 A @ 120 VAC (AC); 30 A @ 48 VDC (DC)

Storage

Onboard storage
480 GB

Management

Platforms
Strata Cloud Manager
Zero-touch provisioning
Supported for simplified deployment of large firewall fleets

Physical

Dimensions
1U, 19" standard rack: 1.70" H × 19.68" D × 17.34" W (with power supply inserted)
Weight
19.8 lb standalone with one power supply; 22–23 lb as shipped (incl. accessory kit, rack kit, packaging)
MTBF
34 years @ 25°C

Environmental

Operating temperature
0°C to 40°C (32°F to 104°F)
Nonoperating temperature
-20°C to 70°C (-4°F to 158°F)
Humidity
10%–90%
Max altitude
10,000 ft / 3,048 m
Airflow
Front to back (port side to power-supply side)
Safety
cMETus and CB
EMI
FCC Class A, CE Class A, VCCI Class A