Palo Alto Networks PA-52R-5G
A fanless, ruggedized 1U next-generation firewall with an integrated dual-SIM 5G RedCap/LTE modem, built to secure critical-infrastructure OT/IT edge sites such as substations and remote cabinets in -40 to 70C environments.
Performance
- Firewall throughput (appmix)
- 2.0 Gbps
- Threat prevention throughput (appmix)
- 1.0 Gbps
- IPsec VPN throughput
- 0.8 Gbps
- Max. concurrent sessions
- 64,000
- New sessions per second
- 2,000
- Virtual systems (base/max)
- 1 / 2 (license required above base)
- Test conditions
- Measured on PAN-OS 12.2
Interfaces
- Data ports
- 8 x 1GbE RJ-45
- SFP
- 2 x 1G SFP
- Cellular
- Dual-SIM, single modem (5G RedCap / LTE)
- Management
- 1 x 1GbE management port
- Console
- 1 x RJ-45 console port
- Bootstrap
- USB 3.0
- Digital I/O
- N/A (not equipped on this model)
- Antenna
- 2x1 MIMO, 615-960 MHz / 1,500-1,600 MHz / 1,710-2,690 MHz / 3,300-3,700 MHz
- Certifications
- PTCRB, GCF
Switching
- Layer 2 switching
- Supported on all data ports
- VLAN trunking
- Transport of multiple VLANs over a single physical link
- Intra-VLAN inspection
- Microsegment and inspect (up to Layer 7) intra-VLAN traffic
- Spanning tree
- Multiple Spanning Tree Protocol (loop-free L2 domains)
- Storm control
- Prevents unknown unicast, multicast and broadcast storms
- VLAN tags
- 802.1Q, 4,094 per device / 4,094 per interface
- Aggregate interfaces
- 802.3ad with LACP
Routing
- Interface modes
- L2, L3, tap, virtual wire (transparent mode)
- Dynamic routing
- OSPFv2/v3, multiprotocol BGP with graceful restart, RIP, static routing
- Policy routing
- Policy-based forwarding
- Dynamic addressing
- PPPoE and DHCP clients (IPv4/IPv6); DHCP client (IPv4)
- Multicast
- PIM-SM, PIM-SSM, IGMP v2/v3/v6
- SD-WAN
- Active/active and active/standby WAN across 5G/LTE, copper, fiber, optional satellite; path quality measurement (jitter, loss, latency); bandwidth monitoring with dynamic path change; multi-VR/LR over SD-WAN overlay; Prisma Access Hub (hybrid SASE); ADEM support
- IPv6
- Dual-stack and IPv6-only networks; geolocalization, OSPFv3, MP-BGP, NAT64, NPTv6; DHCPv6 client with prefix delegation; SLAAC server support
Wireless
- 5G NR (FR1, RedCap)
- n1, n2, n3, n5, n7, n8, n12, n13, n14, n18, n20, n25, n26, n28, n30, n34, n38, n39, n40, n41, n42, n43, n48, n66, n70, n71, n77, n78, n79
- 4G LTE
- B1, B2, B3, B4, B5, B7, B8, B12, B13, B14, B17, B18, B19, B20, B25, B26, B28, B29, B30, B34, B38, B39, B40, B41, B42, B43, B48, B66, B70, B71, B106
- 3G WCDMA
- Not supported
- SIM configuration
- Dual-SIM, single modem
Security services
- Core engines
- App-ID, User-ID, Content-ID, WildFire, SSL decryption
- Threat prevention
- Advanced Threat Prevention; Frontier Virtual Patching for unpatchable/EOL industrial assets
- OT/industrial protocols
- App-ID decodes and controls Modbus, DNP3, IEC-104, Siemens S7, PROFINET, BACnet, EtherNet/IP and other SCADA protocols
- Microsegmentation
- Proxy ARP and DHCP-server-response-overwrite traffic steering for legacy flat OT networks
- Remote access
- Prisma Browser: browser-native RDP/SSH/VNC with just-in-time controls, audit logs, session recording, password vault
VPN
- Key exchange
- Manual key, IKEv1 (not with NGFW clustering), IKEv2 (pre-shared key and certificate-based)
- Encryption
- 3DES, AES (128/192/256-bit)
- Authentication
- MD5, SHA-1, SHA-256, SHA-384, SHA-512
- Post-quantum
- Post-quantum cipher (PQC) VPN; post-quantum PPK for SD-WAN key exchange
- Client VPN
- IPsec and SSL VPN via GlobalProtect gateway/portal (requires GlobalProtect license)
Power
- Consumption (max/avg)
- 40.0 / 25.0 W
- Max current draw
- 3.0 A @ 12 VDC
- Input voltage
- 12-48 VDC; 100-240 VAC (50-60 Hz) with optional AC adapter
- Optional AC adapter
- 66 W, 12 V (PAN-PWR-66W-12V-AC-R)
- Heat output
- 136.5 BTU/hr
Storage
- Capacity
- 128 GB
- Trusted Platform Module
- TPM 2.0
Management
- Cloud management
- Strata Cloud Manager
- On-prem management
- Panorama (for air-gapped/sovereign deployments)
- Provisioning
- Zero touch provisioning (ZTP) via serial or QR-code registration
- Certificate management
- Optional Next-Generation Trust Security (NGTS) for PKI certificate lifecycle automation
- Deployment modes
- Cloud-connected (Strata Cloud Manager, Precision AI, predictive AIOps) or on-premises/air-gapped (Panorama, offline/data-diode updates)
Physical
- Dimensions
- 1.7" H x 8.0" W x 8.0" D
- Mounting
- 1RU (side-by-side mounting optional), optional DIN rail mount, optional wall mount
- Weight
- 5.5 lb / 2.5 kg (product), 7.0 lb / 3.2 kg (shipping)
- MTBF
- 350,000 hours @ 25°C
- Construction
- Fanless, silent convection-cooled metal housing, no moving parts
Environmental
- Operating temperature
- -40°C to 70°C (requires 240 LFM external airflow at 70°C)
- Non-operating temperature
- -40°C to 70°C
- Cooling
- Passive (fanless)
- Humidity
- 10%-90%
- Max altitude
- 10,000 ft / 3,048 m
- Ingress protection
- IP-40
- Safety
- UL 62368-1 / CSA C22.2 No. 62368-1:25, IEC/EN 62368-1 (2014/2018/2023), cTUVus and CB
- EMI
- FCC Class A, CE Class A, VCCI Class A
Licensing
- Virtual systems
- 1 included, up to 2 with separately purchased license
- GlobalProtect
- Requires a GlobalProtect license for IPsec/SSL VPN gateway/portal
- NGTS
- Optional license for automated PKI certificate lifecycle management