Wednesday 14 June 2017

Palo Alto Datasheet - PA-500


App-ID firewall throughput250 Mbps
Threat prevention throughput100 Mbps
Connections per second7,500
Max sessions (IPv4 or IPv6)64,000


Performance

App-ID firewall throughput250 Mbps
Threat prevention throughput100 Mbps
IPSec VPN throughput50 Mbps
Connections per second7,500

Sessions

Max sessions (IPv4 or IPv6)64,000

Policies

Security rules1,000
Security rule schedules256
NAT rules160
Decryption rules100
App override rules100
QoS rules100
Tunnel content inspection rules100
Policy based forwarding rules100
Captive portal rules100
DoS protection rules100

Security Zones

Max security zones20

Objects (addresses and services)

Address objects2,500
Address groups250
Members per address group2,500
Service objects1,000
Service groups250
Members per service group500
FQDN address objects2,000
Max IP addresses registered per system*1,000
Tags per IP address32

Security Profiles

Security profiles75

App-ID

Custom App-ID signatures6,000
Shared custom App-IDs512
Custom App-IDs (virtual system specific)6,416

User-ID

User-IP mappings (management plane)512,000
User-IP mappings (data plane)64,000
Active and unique groups used in policy1,000
Number of agents100
Monitored servers per agent100
Maximum terminal services agents400

SSL Decryption

Max SSL inbound certificates25
SSL certificate cache (forward proxy)128
Max concurrent decryption sessions1,024

URL Filtering

Total entries for allow list, block list and custom categories25,000
Max custom categories2,849
Max custom categories (virtual system specific)500
Dataplane cache size for URL filtering10,000
Management plane dynamic cache size1,000,000

Interfaces

Mgmt - out-of-band10/100/1000, RJ45 console
Mgmt - 10/100/1000 high availabilityNA
Mgmt - 40Gbps high availabilityNA
Traffic - 10/100/10008
Traffic - 100/1000/10000NA
Traffic - 1Gbps SFPNA
Traffic - 10Gbps SFP+NA
Traffic - 10Gbps XFPNA
Traffic - 40Gbps QSFPNA
802.1q tags per device4,094
802.1q tags per physical interface4,094
Max interfaces (logical and physical)288
Maximum aggregate interfaces4

Virtual Routers

Virtual routers3

Virtual Wires

Virtual wires144

Virtual Systems

Base virtual systems1
Max virtual systems*NA

Routing

IPv4 forwarding table size*625
IPv6 forwarding table size*625
System total forwarding table size1,250
Max route maps per virtual router50
Max routing peers (protocol dependent)500
Static entries - DNS proxy1,024
Bidirectional Forwarding Detection (BFD) SessionsNA

L2 Forwarding

ARP table size per device2,000
IPv6 neighbor table size2,000
MAC table size per device2,000
Max ARP entries per broadcast domain2,000
Max MAC entries per broadcast domain2,000

NAT

Total NAT rule capacity160
Max NAT rules (static)*160
Max NAT rules (DIP)*160
Max NAT rules (DIPP)160
Max translated IPs (DIP)16,000
Max translated IPs (DIPP)*160
Default DIPP pool oversubscription*1

Address Assignment

DHCP servers3
Max number of assigned addresses64,000

High Availability

Devices supported2
Max virtual addresses32

QoS

Number of QoS policies100
Physical interfaces supporting QoS6
Clear text nodes per physical interface31
DSCP marking by policyYes
Subinterfaces supportedSystem limit

IPSec VPN

Site to site250
Max IKE Peers1,000

GlobalProtect Client VPN

Max tunnels (SSL, IPSec, and IKE with XAUTH)100

GlobalProtect Clientless VPN

Max SSL tunnels25

Multicast

Replication (egress interfaces)100
Routes1,000

Product Notes

End-of-saleN
A

No comments:

PAN-OS Supported ciphers

Following is a list of supported ciphers for PAN-OS 7.1 and later: SSLv3 Ciphers Supported (No change from PAN-OS 7.0) Non-FIPS mod...