THÔNG TIN SẢN PHẨM
Chi tiết và thông số kỹ thuật
Thiết bị tường lửa công nghiệp Palo Alto Networks PA-220R (PAN-PA-220R)
| SKU | PAN-PA-220R |
| Performance and Capacities | |
| Firewall throughput (HTTP/appmix) | 545 / 535 Mbps |
| Threat Prevention throughput (HTTP/appmix) | 265 / 320 Mbps |
| IPsec VPN throughput | 550 Mbps |
| Max sessions | 64,000 |
| New sessions per second | 4,200 |
| Hardware Specifications | |
| I/O | 10/100/1000 (6), SFP (2) |
| Management I/O | – 10/100/1000 out-of-band management port (1) – RJ-45 console port (1) – USB port (1) – Micro USB console port (1) |
| Storage Capacity | 32 GB EMMC |
| Power Supply (Avg/Max Power Consumption) | Optional: dual redundant DC power feeds (13 W / 16 W) |
| Max BTU/hr | 55 |
| Input Voltage (Input Frequency) | 12 – 48 VDC 1.4A |
| Max Current Consumption | Firewall: 1.4 A @ 12 VDC Max inrush current 4.9 A @ 12 VDC |
| Weight (Standalone Device/As Shipped) | 4.5 lbs / 6.0 lbs |
| Safety | cTUVus, CB |
| EMI | FCC Class A, CE Class A, VCCI Class A |
| Environment | – Operating temperature: -40° to 158° F, -40° to 70° C – Non-operating temperature: -40° to 167° F, -40° to 75° C – Passive cooling |
| Networking Features | |
|---|---|
| Interface Modes | L2, L3, tap, virtual wire (transparent mode) |
| Routing | OSPFv2/v3 with graceful restart, BGP with graceful restart, RIP, static routing Policy-based forwarding Point-to-Point Protocol over Ethernet (PPPoE) Multicast: PIM-SM, PIM-SSM, IGMP v1, v2, and v3 |
| SD-WAN | Path quality measurement (jitter, packet loss, latency) Initial path selection (PBF) Dynamic path change |
| IPv6 | L2, L3, tap, virtual wire (transparent mode) Features: App-ID, User-ID, Content-ID, WildFire, and SSL Decryption SLAAC |
| IPsec VPN | Key exchange: manual key, IKEv1, and IKEv2 (pre-shared key, certificate-based authentication) Encryption: 3DES, AES (128-bit, 192-bit, 256-bit) Authentication: MD5, SHA-1, SHA-256, SHA-384, SHA-512 |
| VLANs | 802.1Q VLAN tags per device/per interface: 4,094/4,094 |
| Network Address Translation | NAT modes (IPv4): static IP, dynamic IP, dynamic IP and port (port address translation) NAT64, NPTv6 Additional NAT features: dynamic IP reservation, tunable dynamic IP and port oversubscription |
| High Availability | Modes: active/active, active/passive Failure detection: path monitoring, interface monitoring |
| Industrial Protocols and Applications | App-IDs for ICS and SCADA sheet |
| Zero Touch Provisioning (ZTP) | Available with -ZTP SKUs (PA-220R-ZTP) Requires Panorama 9.1.3 or higher |
Data sheet Palo Alto Networks PA-220R
| PA-220R Series Hardware | |
| Palo Alto Networks PA-220R | #PAN-PA-220R |
| Subscription | |
| Partner enabled premium support year 1, PA-220R | #PAN-SVC-BKLN-220R |
| Advanced URL Filtering Subscription, 1-year, PA-220R | #PAN-PA-220R-ADVURL |
| SaaS Inline subscription, PA-220R | #PAN-PA-220R-SAAS-INLINE |
| DLP subscription, PA-220R | #PAN-PA-220R-DLP |
| IOT subscription year 1, PA-220R, Requires Data Lake | #PAN-PA-220R-IOT |
| SD-WAN subscription year 1, PA-220R | #PAN-PA-220R-SDWAN |
| DNS Security subscription year 1, PA-220R | #PAN-PA-220R-DNS |
| GlobalProtect subscription year 1, PA-220R | #PAN-PA-220R-GP |
| Threat prevention subscription year 1, PA-220R | #PAN-PA-220R-TP |
| WildFire subscription year 1, PA-220R | #PAN-PA-220R-WF |
| PANDB URL filtering subscription year 1, PA-220R | #PAN-PA-220R-URL4 |
Detect and Prevent Advanced Threats with Cloud-Delivered Security Services
- Advanced Threat Prevention — Stop known exploits, malware, malicious URLs, spyware, and com-mand and control (C2) with 96% prevention of web-based Cobalt Strike C2 and 48% more unknown C2 detected than the industry’s leading intrusion prevention (IPS) solution.
- WildFire® malware prevention — Ensure files are safe by automatically detecting and preventing unknown malware 180X faster with the industry’s largest threat intelligence and malware prevention engine.
- Advanced URL Filtering — Enable safe access to the internet, with the industry’s first real-time pre-vention of known and unknown websites, stopping 76% of malicious URLs 24 hours before other vendors.
- DNS Security — Gain 40% more DNS-attack coverage and disrupt the 80% of attacks that use DNS for command and control and data theft without requiring any changes to your infrastructure.
- Enterprise DLP — Minimize the risk of a data breach, stop out-of-policy data transfers, and enable compliance consistently across your enterprise, with 2X greater coverage of any cloud-delivered enterprise DLP.
- SaaS Security — Stay ahead of the SaaS explosion with the industry’s only Next-Generation CASB to automatically see and secure all apps across all protocols.
- IoT Security — Safeguard every “thing” and implement Zero Trust device security 20X faster, with the industry’s smartest security for smart devices.




