PA-3000 Series: Key Security Features

Download as pdf or txt
Download as pdf or txt
You are on page 1of 2

PA-3000

Series
Palo Alto Networks® PA-3000 Series of next-generation
firewall appliances comprises the PA-3060, PA-3050 and
PA-3020, all of which are targeted at high-speed internet
gateway deployments. The PA-3000 Series manages network
traffic flows using dedicated processing and memory for
­networking, security, threat prevention and management.

Key Security Features


Classifies all applications, on all ports, all the time PA-3060
• Identifies the application, regardless of port, encryption
(SSL or SSH), or evasive technique employed.
• Uses the application, not the port, as the basis for all PA-3050 PA-3020
of your safe enablement policy decisions: allow, deny,
schedule, inspect and apply traffic-shaping. The controlling element of the PA-3000 Series is PAN-OS®, a
security-specific operating system that natively classifies all
• Categorizes unidentified applications for policy control, traffic, inclusive of applications, threats and content, and then
threat forensics or App-ID™ development. ties that traffic to the user, regardless of location or device type.
The application, content and user – in other words, the elements
Enforces security policies for any user, at any location that run your business – are then used as the basis of your
• Deploys consistent policies to local and remote security policies, resulting in an improved security posture and a
­users running on the Windows®, Mac® OS X®, Linux, reduction in incident response time.
Android®, or Apple® iOS platforms.
Performance
• Enables agentless integration with Microsoft® Active and Capacities PA-3050 PA-3060 PA-3020
­Directory® and Terminal Services, LDAP, Novell®
­eDirectory™ and Citrix®. Firewall throughput
(App-ID enabled) 4 Gbps 4 Gbps 2 Gbps
• Easily integrates your firewall policies with 802.1X
Threat prevention
wireless, proxies, NAC solutions, and any other source throughput 2 Gbps 2 Gbps 1 Gbps
of user identity information.
IPsec VPN
throughput 500 Mbps 500 Mbps 500 Mbps
Prevent known and unknown threats
New sessions
• Blocks a range of known threats, including exploits,
per second 50,000 50,000 50,000
malware and spyware, across all ports, regardless of
common threat-evasion tactics employed. Max sessions 500,000 500,000 250,000

• Limits the unauthorized transfer of files and sensitive Virtual systems


(base/max1) 1/6 1/6 1/6
data, and safely enables non-work-related web surfing.
• Identifies unknown malware, analyzes it based 1
Adding virtual systems to the base quantity requires a separately
on h­ undreds of malicious behaviors, and then
­purchased license.
­automatically creates and delivers protection.

Palo Alto Networks | PA-3000 Series | Datasheet 1


Networking Features Hardware Specifications

Interface Modes I/O


L2, L3, Tap, Virtual wire (transparent mode) PA-3060 - (8) 10/100/1000, (8) Gigabit SFP, (2) 10 Gigabit SFP+
Routing PA-3050 | PA-3020 - (12) 10/100/1000, (8) SFP Gigabit
OSPFv2/v3 with graceful restart, BGP with graceful restart, RIP, Management I/O
static routing
(1) 10/100/1000 out-of-band management port, (2) 10/100/1000
Policy-based forwarding high availability, (1) RJ-45 console port
Point-to-Point Protocol over Ethernet (PPPoE) Storage Capacity
Multicast: PIM-SM, PIM-SSM, IGMP v1, v2, and v3 120GB SSD
Bidirectional Forwarding Detection (BFD) Power Supply (Avd/Max Power Consumption)
IPv6 PA-3060 – Redundant 400W AC (160/200)
L2, L3, Tap, Virtual Wire (transparent mode) PA-3050 | PA-3020 – Single 250W AC (150/200)
Features: App-ID™, User-ID™, Content-ID™, WildFire® and SSL Max BTU/hr
decryption
683
SLAAC
Input Voltage (Input Frequency)
IPsec VPN
100-240VAC (50-60Hz)
Key Exchange: Manual key, IKEv1 and IKEv2 (pre-shared key,
­certificate-based authentication) Max Current Consumption
Encryption: 3DES, AES (128-bit, 192-bit, 256-bit) 2A@100VAC

Authentication: MD5, SHA-1, SHA-256, SHA-384, SHA-512 Rack Mountable (Dimensions)


VLANs PA-3060 - 1.5U, 19” standard rack (2.6”H x 14”D x 17.5”W)

802.1q VLAN tags per device/per interface: 4,094/4,094 PA-3050 | PA-3020 -1U, 19” standard rack (1.75”H x 17”D x 17”W)

Aggregate interfaces (802.3ad), LACP Weight (Stand-Alone Device/As Shipped)


Network Address Translation (NAT) PA-3060 - 18lbs/27.5lbs

NAT modes (IPv4): Static IP, dynamic IP, dynamic IP and port PA-3050 | PA-3020 - 15lbs/20lbs
(port address translation) Safety
NAT64, NPTv6 UL, CUL, CB, cCSAus
Additional NAT features: dynamic IP reservation, tunable dynamic IP
EMI
and port oversubscription
FCC Class A, CE Class A, VCCI Class A
High Availability
Modes: Active/Active, Active/Passive Certifications

Failure detection: Path monitoring, interface monitoring See https://www.paloaltonetworks.com/company/certifications.html


Environment
Operating temperature: 32 to 122 F, 0 to 50 C
Non-operating temperature: -4 to 158 F, -20 to 70 C

To view additional information about the features and associated capacities of the PA-3000 Series, please visit
www.paloaltonetworks.com/products.

3000 Tannery Way © 2017 Palo Alto Networks, Inc. Palo Alto Networks is a registered trademark
Santa Clara, CA 95054 of Palo Alto Networks. A list of our trademarks can be found at https://www.
Main: +1.408.753.4000 paloaltonetworks.com/company/trademarks.html. All other marks mentioned
Sales: +1.866.320.4788 herein may be trademarks of their respective companies.
Support: +1.866.898.9087 pan-ds-pa-3000-series-112717

www.paloaltonetworks.com

You might also like