Palo Alto Networks PA-1520-POE
The mid model of Palo Alto Networks' PA-1500 Series, a post-quantum-optimized NGFW with built-in Layer 2 switching and up to 545 W of PoE++, aimed at smaller campuses and larger distributed branch offices.
Performance
- Firewall throughput (appmix)
- 25 Gbps
- Threat prevention throughput (appmix)
- 18 Gbps
- IPsec VPN throughput
- 14 Gbps
- Max concurrent sessions
- 1,495,000
- New sessions/sec
- 180,000
- Virtual systems (base/max)
- 1 / 11
Interfaces
- Data ports
- 10/100/1000 Cu (8), 1G/2.5G/5G Cu (8), 1G/2.5G/5/10G Cu (4), 1/10G SFP+ (8), 10G/25G SFP28 (4)
- Out-of-band management
- 10/100/1000 Cu (1)
- Console
- RJ-45 (1), USB-C (1)
- Bootstrap
- USB 3.2 Gen1 Type-A (1)
- HA
- 10/100/1000 Cu (2)
- HSCI
- 25G SFP28 (1)
Switching
- Layer 2 switching
- On all data ports; VLAN trunking of multiple VLANs over one physical link
- Microsegmentation
- Intra-VLAN traffic inspection up to Layer 7
- Loop prevention
- Multiple Spanning Tree Protocol
- Storm control
- Unknown unicast, multicast and broadcast storm control
- VLANs
- 802.1Q, 4,094 tags per device/interface
- Link aggregation
- 802.3ad LACP
Routing
- Interface modes
- L2, L3, tap, virtual wire (transparent mode)
- Routing protocols
- Advanced routing engine (ARE); OSPFv2/v3, MP-BGP with graceful restart, RIP, static routing, policy-based forwarding
- Dynamic addressing
- PPPoE and DHCP client (IPv4/IPv6); DHCPv4 server and relay
- Multicast
- PIM-SM, PIM-SSM, IGMPv2/v3
- SD-WAN
- Path quality measurement (jitter, loss, latency), bandwidth monitoring, Multi-VR/LR over SD-WAN overlay, Prisma Access Hub, ADEM support
- IPv6
- L2/L3/tap/virtual wire inspection, dual-stack and IPv6-only, IPv6 geolocalization, OSPFv3, MP-BGP, NAT64, NPTv6, DNSv6, IPv6 multicast routing, DHCPv6-PD, SLAAC
- NAT
- Static IP, dynamic IP, PAT (IPv4); NAT64, NPTv6; dynamic IP reservation, tunable dynamic IP, port oversubscription
- High availability
- Active/active and active/passive; failure detection via path and interface monitoring
- Mobile network
- 5G Security (identifier-based visibility, traffic correlation, enforcement)
VPN
- Key exchange
- Manual key, IKEv1, IKEv2 (pre-shared key and certificate-based)
- Post-quantum
- Post-quantum PPK
- Encryption
- 3DES, AES (128/192/256-bit)
- Authentication
- MD5, SHA-1, SHA-256, SHA-384, SHA-512
- Remote access
- GlobalProtect Large Scale VPN, gateway/portal (license required)
Power
- PoE
- 545 W total budget, 90 W max per port, available on ports 5-20
- Power supply
- 1 × AC 1,200 W (included); optional 2nd AC 1,200 W or DC 1,200 W FRU
- Max/avg consumption
- 910 W max (with 545 W PoE load)
- Input voltage
- AC 100-240 VAC (50-60 Hz); DC -48 to -60 VDC
- Power supply output
- 1,200 W per supply @ 220V/110V AC or 48V DC
- Max current
- 8.3 A @ 110 VAC / 3.8 A @ 240 VAC / 19 A @ 48 VDC (with 545 W PoE)
- Max inrush current
- AC 30 A @ 230 VAC, 50 A @ 120 VAC; DC 30 A @ 48 VDC
- Max heat output
- 1,057.8 BTU/hr (max system power dissipation 310 W)
Storage
- Onboard storage
- 480 GB
Management
- Platforms
- Strata Cloud Manager (cloud) or Panorama (on-prem/air-gapped)
- Provisioning
- Zero-touch provisioning (ZTP)
Physical
- Dimensions
- 1U, 19" standard rack: 1.70" H x 19.68" D x 17.34" W (with PSU inserted)
- Weight
- 19.8 lb standalone (one power supply inserted) / 22 lb as shipped (with accessory kit, rack kit, packaging)
- MTBF
- 27 years @ 25°C
- Safety
- cMETus and CB
- EMI
- FCC Class A, CE Class A, VCCI Class A
- Operating temperature
- 32-104°F / 0-40°C
- Nonoperating temperature
- -4-158°F / -20-70°C
- Humidity
- 10%-90%
- Max altitude
- 10,000 ft / 3,048 m