stacks_image_C1B8C8AC-CD5B-496C-B677-6450D5D86B5C


Palo Alto Networks

stacks_image_1721D798-04C9-41A9-89A6-F9F20F85813F
Palo Alto Networks offers a fresh approach—one that focuses on accurately identifying the actual application, not just the port it uses; one that inspects all traffic, not just a selective sampling; and one that accomplishes it all at line speed.
Starting with a blank sheet of paper, Palo Alto Networks is redefining the firewall with innovative technologies based on business-relevant elements – applications, users, and content – which enables effective risk management on enterprise networks.


Think of traditional stateful firewalls, forget the bolt on on UTM solutions, limited performance and start thinking high performance firewalls with source/dest control, but with the added functionality of user/group control and true application visibility into over 800 applications versus primitive and now useless port control.

App-ID, an application identification technology that classifies traffic irrespective of port, protocol, SSL encryption, or evasive tactics.

Content-ID, a high performance content inspection engine that prevents a wide range of threats, blocks file transfers and controls web surfing.

Purpose-built platform with dedicated processing resources for security, networking, threat prevention and management to provide line-rate, low-latency performance under load.

NEW - QoS Traffic Shaping to set maximum, guaranteed or priority for bandwidth by application (e.g. YouTube, FaceBook at lowest priority, but still allowed).

NEW - SSL VPN to allow users to connect to corporate networks via browsers along with application based control.

If you are faced with dealing with malware, various threats, viruses and tired of “barking dog” IDS approaches, look at this solution.

Tired of paying per user fees for content filtering, look at high performance filtering and no per user fees.

PA-500 Enterprise Firewall
  • PA-500 - 250 Mbps Firewall throughput, 8 x 10/100/100
  • PA-2020 - 500 Mbps firewall throughput, 12 x 10/100/1000 + 2 SFP
  • PA-2050 - 1 Gbps firewall throughput, 16 x 10/100/1000 + 4 SFP
  • PA-4020 - 2 Gbps firewall throughput, 16 x 10/100/1000 + 8 SFP
  • PA-4050 - 10 Gbps firewall throughput, 16 x 10/100/1000 + 8 SFP
  • PA-4060 - 10 Gbps firewall throughput, 4 x 10 Gigabit XFP + 4 Gigabit SFP
stacks_image_28407167-2539-4944-A743-086FCEB62A1C
PA-500 Enterprise Firewall
The Palo Alto Networks PA-500 is ideally suited for Internet gateway deployments within medium to large branch offices and medium sized enterprises. The PA-500 manages network traffic flows with high performance processing and dedicated memory for networking, security, threat prevention and management. A high speed backplane smoothes the pathway between processors and the separation of data and control plane ensures that management access is always available, irrespective of the traffic load.
stacks_image_2CE1D7EB-7D8B-409D-A949-1D2F1EE7D365
stacks_image_CBD4F5D6-D1B2-4FC5-B8F6-3F4FE7EF1730
  • 250 Mbps firewall throughput
  • 100 Mbps threat prevention throughput
  • 50 Mbps IPSec VPN throughput
  • 250 IPSec VPN tunnels and tunnel interfaces
  • 7,500 new sessions per second
  • 64,000 max sessions
  • (8) 10/100/1000
  • (1) 10/100/1000 out of band management interface
  • (1) 1 RJ-45 console interface
PA-2000 Series Enterprise Firewall
The Palo Alto Networks PA-2000 Series is comprised of two high performance platforms, the PA-2020 and the PA-2050, both of which are ideally suited for high speed Internet gateway deployments within large branch offices and medium sized enterprises. The PA-2000 Series manages network traffic flows using dedicated processing and memory for networking, security, threat prevention and management. A high speed backplane smoothes the pathway between processors and the separation of data and control plane ensures that management access is always available, irrespective of the traffic load.
PA-2020
stacks_image_4FB05F85-C06C-4703-9C71-5A2375347E4B
  • 500 Mbps firewall throughput
  • 200 Mbps threat prevention throughput
  • 200 Mbps IPSec VPN throughput
  • 1,000 IPSec VPN tunnels and tunnel interfaces
  • 15,000 new sessions per second
  • 125,000 max sessions
  • (12) 10/100/1000 + (2) SFP optical gigabit interfaces
  • (1) 10/100/1000 out of band management interface
  • (1) 1 RJ-45 console interface
PA-2050
stacks_image_4C9A2CF3-586D-46FA-AACE-BAE8343BE0B6
  • 1 Gbps firewall throughput
  • 500 Mbps threat prevention throughput
  • 300 Mbps IPSec VPN throughput
  • 2,000 IPSec VPN tunnels and tunnel interfaces
  • 15,000 new sessions per second
  • 250,000 max sessions
  • (16) 10/100/1000 + (4) SFP optical gigabit interfaces
  • (1) 10/100/1000 out of band management interface
  • (1) 1 RJ-45 console interface
PA-4000 Series Enterprise Firewall
The Palo Alto Networks PA-4000 Series is comprised of three high performance platforms, the PA-4060, the PA-4050 and the PA-4020, all of which are targeted at high speed Internet gateway deployments within enterprise environments. The PA-4000 Series manages multi-Gbps traffic flows using dedicated processing and memory for networking, security, threat prevention and management. A 10 Gbps backplane smoothes the pathway between processors and the physical separation of data and control plane ensures that management access is always available, irrespective of the traffic load.
 
stacks_image_AD4B6F18-F331-4228-A5BB-EB02A17ADDB6
PA-4020
  • 2 Gbps firewall throughput
  • 2 Gbps threat prevention throughput
  • 1 Gbps IPSec VPN throughput
  • 2,000 IPSec VPN tunnels and tunnel interfaces
  • 60,000 new sessions per second
  • 500,000 max sessions
  • (16) 10/100/1000 + (8) SFP optical gigabit interfaces
  • (2) Dedicated high availability interfaces (10/100/1000)
  • (1) Dedicated out of band management interface (10/100/1000)
  • (1) DB9 interface
PA-4050
stacks_image_71022F9E-6DFE-4DE8-A4A1-87A621A6B742
  • 10 Gbps firewall throughput
  • 5 Gbps threat prevention throughput
  • 2 Gbps IPSec VPN throughput
  • 4,000 IPSec VPN tunnels and tunnel interfaces
  • 60,000 new sessions per second
  • 2,000,000 max sessions
  • (16) 10/100/1000 + (8) SFP optical gigabit interfaces
  • (2) Dedicated high availability interfaces (10/100/1000)
  • (1) Dedicated out of band management interface (10/100/1000)
  • (1) DB9 interface
PA-4060
stacks_image_C375E511-ABC6-4EC1-854F-3BDE76ACE255
  • 10 Gbps firewall throughput
  • 5 Gbps threat prevention throughput
  • 2 Gbps IPSec VPN throughput
  • 4,000 IPSec VPN tunnels and tunnel interfaces
  • 60,000 new sessions per second
  • 2,000,000 max sessions
  • (4) 10 Gigabit XFP + (4) Gigabit SFP
  • (2) Dedicated high availability interfaces (10/100/1000)
  • (1) Dedicated out of band management interface (10/100/1000)
  • (1) DB9 interface

Flexible Deployment Topologies (per port!)

Use for application visibility, user and content visibility via mirror port without inline deployment.
Use for firewall replacement along with application visibility and control. Offers consolidation for Firewall, VPN, IPS and URL Filtering.
Use for IPS features along with application visibility and control. Offers consolidation of IPS and URL filtering without replacing firewall.
stacks_image_480627B3-CB57-42D5-BC37-D446964D99CC
stacks_image_25986650-30FF-48E0-8CDE-8EB904ECB1D0
stacks_image_458DB8AD-B42F-4204-8F4B-8A2D649BDC2C
Intrusion Prevention (IDP and IDS)

The world of stand-alone IPS products will soon be gone, as IPS functionality becomes integrated as a standard feature of Next-Generation Firewalls. Threats target applications, and enterprises struggle to control modern applications with existing security infrastructure. The current web services based landscape dictates a new set of requirements for comprehensive intrusion prevention, and Palo Alto Networks next-generation firewalls deliver, where IPS products cannot:
  • Control applications (not just ports)
  • Scan allowed traffic for threats
  • Real-world, multi-Gbps performance
  • Current research and support
Palo Alto Networks advantage:
  • Over 900 applications can be controlled by user or group access versus just a few "bad" applications from traditional IDPs.
  • Since Palo Alto Networks is application aware, it can scan the allowed traffic for threats or entirely disallow unapproved applications regardless of payload.
  • Includes 1,000s of signatures for scanning.
  • Best in-house IPS research team discovered 3 Microsoft vulnerabilities in the last 6 months. Some competitors haven't done anything for two years.
  • You get superior port density to cover multiple segments with an easier and more cost effective solution than traditional stand-alone IPS.
stacks_image_69C9E281-125C-4982-83E7-FBE0CFBB8D98
For more information, please contact us.