THÔNG TIN SẢN PHẨM
Chi tiết và thông số kỹ thuật
Thiết bị tường lửa Palo Alto Networks PA-5250
| SKU | PAN-PA-5250-AC |
|---|---|
| Performance and Capacities | |
| Firewall throughput (HTTP/appmix) | 32.8/36.7 Gbps |
| Threat Prevention throughput (HTTP/appmix) | 16.9/21.4 Gbps |
| IPsec VPN throughput | 18.4 Gbps |
| Max sessions | 8M |
| New sessions per second | 368,000 |
| Virtual systems (base/max) | 25/125 |
| Hardware Specifications | |
| I/O | 100/1000/10G Cu (4), 1G/10G SFP/ SFP+ (16), 40G/100G QSFP28 (4) |
| Management I/O | 10/100/1000 (2) 40G/100G QSFP28 HA (1) 10/100/1000 out-of-band management (1) RJ45 console port (1) |
| Storage Capacity | 240 GB SSD, RAID1, system storage 2 TB HDD, RAID1, log storage |
| Power Supply (Avg/Max Power Consumption) | 571 / 685 W |
| Max BTU/hr | 2,340 |
| Power Supplies (Base/Max) | 1:1 fully redundant (2/2) |
| AC Input Voltage (Input Frequency) | 100–240 VAC (50–60 Hz) |
| AC Power Supply Output | 1,200 watts/power supply |
| Max Current Consumption | AC: 8.5 A @ 100 VAC, 3.6 A @ 240 VAC |
| Max Inrush Current | AC: 50 A @ 230 VAC, 50 A @ 120 VAC |
| Mean Time Between Failure (MTBF) | 9.23 years |
| Rack Mount (Dimensions) | 3U, 19” standard rack 5.25” H x 20.5” D x 17.25” W |
| Weight (Standalone Device/As Shipped) | 46 lbs / 62 lbs |
| Safety | cTUVus, CB |
| EMI | FCC Class A, CE Class A, VCCI Class A |
| Environment | Operating temperature: 32° to 122° F, 0° to 50° C Non-operating temperature: -4° to 158° F, -20° to 70° C |
| Networking Features | |
|---|---|
| Interface Modes | L2, L3, tap, virtual wire (transparent mode) |
| Routing | OSPFv2/v3 with graceful restart, BGP with graceful restart, RIP, static routing Policy-based forwarding Point-to-point protocol over Ethernet (PPPoE) and DHCP supported for dynamic address assignment Multicast: PIM-SM, PIM-SSM, IGMP v1, v2, and v3 Bidirectional Forwarding Detection (BFD) |
| SD-WAN | Path quality measurement (jitter, packet loss, latency) Initial path selection (PBF) Dynamic path change |
| IPv6 | L2, L3, tap, virtual wire (transparent mode) Features: App-ID, User-ID, Content-ID, WildFire, and SSL Decryption SLAAC |
| IPsec VPN | Key exchange: manual key, IKEv1, and IKEv2 (pre-shared key, certificate-based authentication) Encryption: 3DES, AES (128-bit, 192-bit, 256-bit) Authentication: MD5, SHA-1, SHA-256, SHA-384, SHA-512 GlobalProtect large-scale VPN for simplified configuration and management |
| VLANs | 802.1Q VLAN tags per device/per interface: 4,094/4,094 Aggregate interfaces (802.3ad), LACP |
| Network Address Translation | NAT modes (IPv4): static IP, dynamic IP, dynamic IP and port (port address translation) NAT64, NPTv6 Additional NAT features: dynamic IP reservation, tunable dynamic IP and port oversubscription |
| High Availability | Modes: active/active, active/passive, HA clustering Failure detection: path monitoring, interface monitoring |
| Mobile Network Infrastructure | GTP Security SCTP Security |
Data sheet Palo Alto Networks PA-5200 Series
| PA-5200 Series Hardware | |
|---|---|
| Palo Alto Networks PA-5250 with redundant AC power supplies | PAN-PA-5250-AC |
| Virtual systems upgrade – Additional 50 virtual systems for PA-5250 (max 125 per device) | PAN-PA-5250-VSYS-50 |
| Subscription | |
| DNS Security subscription year 1, PA-5250 | #PAN-PA-5250-DNS |
| GlobalProtect subscription year 1, PA-5250 | #PAN-PA-5250-GP |
| Threat prevention subscription year 1, PA-5250 | #PAN-PA-5250-TP |
| PANDB URL filtering subscription year 1, PA-5250 | #PAN-PA-5250-URL4 |
| Premium support year 1, PA-5250 | #PAN-SVC-PREM-5250 |
Extends native protection across all attack vectors with cloud-delivered security subscriptions
- Threat Prevention—inspects all traffic to automatically block known vulnerabilities, malware, vulnerability ex-ploits, spyware, command and control (C2), and custom intrusion prevention system (IPS) signatures.
- WildFire® malware prevention—unifies inline machine learning protection with robust cloud-based analysis to instantly prevent new threats in real time as well as dis-cover and remediate evasive threats faster than ever
- URL Filtering—prevents access to malicious sites and protects users against web-based threats, including cre-dential phishing attacks.
- DNS Security—detects and blocks known and unknown threats over DNS (including data exfiltration via DNS tun-neling), prevents attackers from bypassing security mea-sures, and eliminates the need for independent tools or changes to DNS routing.
- IoT Security—discovers all unmanaged devices in your network quickly and accurately with ML, without the need to deploy additional sensors. Identifies risks and vul-nerabilities, prevents known and unknown threats, pro-vides risk-based policy recommendations, and automates enforcement.
- Enterprise DLP—offers the industry’s first cloud-delivered enterprise DLP that consistently protects sensitive data across networks, clouds, and users.
- SaaS Security—delivers integrated SaaS security that lets you see and secure new SaaS applications, protect data, and prevent zero-day threats at the lowest total cost of ownership (TCO)




