Deskripsi
Model PA-5020 PA-5050 PA-5060
Performance and Capacities Specifications
Firewall throughput (App-ID enabled) 5 Gbps 10 Gbps 20 Gbps
Threat prevention throughput 2 Gbps 5 Gbps 10 Gbps
IPSec VPN throughput 2 Gbps 4 Gbps 4 Gbps
New sessions per second 120,000 120,000 120,000
Max sessions 1,000,000 2,000,000 4,000,000
IPSec VPN tunnels/tunnel interfaces 2,000 4,000 8,000
GlobalProtect (SSL VPN) concurrent users 5,000 10,000 20,000
SSL decrypt sessions 15,000 45,000 90,000
SSL Inbound Certificates 100 300 1,000
Virtual routers 20 125 225
Virtual systems (base/max2) 10/20* 25/125* 25/225*
Security zones 80 500 900
Max. number of policies 10,000 20,000 40,000
Hardware Specifications
I/O (12)10/100/1000, (8) Gigabit SFP (12) 10/100/1000, (8) Gigabit SFP, (4) 10 Gigabit SFP+ (12) 10/100/1000, (8) Gigabit SFP, (4) 10 Gigabit SFP+
Management I/O (2) 10/100/1000 high availability,
(1) 10/100/1000 out-of-band management,
(1) RJ45 console port
Storage Options Single or dual solid state disk drives
Storage Capacity 120GB, 240GB SSD, RAID 1
Power supply (Avg/max power consumption) Redundant 450W AC (270W/340W) Redundant 450W AC (270W/340W) Redundant 450W AC (330W/415W)
Max BTU/HR 1,160 1,160 1,416
Input Voltage (Input Frequency) 100-240VAC (50-60Hz); -40 to -72 VDC
Max Current Consumption 8A@100VAC, 14A@48VDC
Mean Time Between Failure (MTBF) 6.5 Years
Max Inrush Current 80A@230VAC; 40A@120VAC; 40A@48VDC
Rack Mountable 2U, 19″ standard rack
Dimensions 3.5″H x 20″D x 17.5″W
Weight (Stand alone device/as shipped) 41lbs/55lbs
Safety UL, CUL, CB
EMI FCC Class A, CE Class A, VCCI Class A
Certifications NEBS Level 3, FIPS level 2, ICSA
Environment
Operating temperature 32° to 122° F, 0° to 50° C
Non-operating temperature -4° to 158° F, -20° to 70° C

Networking Specifications:

Interface Modes

  • L2, L3, Tap, Virtual wire (transparent mode)

Routing

  • Modes: OSPF, RIP, BGP, Static
  • Forwarding table size (entries per device/per VR): 64,000/64,000
  • Policy-based forwarding
  • Point-to-Point Protocol over Ethernet (PPPoE)
  • Jumbo frames: 9,210 bytes max frame size
  • Multicast: PIM-SM, PIM-SSM, IGMP v1, v2, and v3

High-Availability

  • Modes: Active/Active, Active/Passive
  • Failure detection: Path monitoring, Interface monitoring

Address Assignment

  • Address assignment for device: DHCP Client/PPPoE/Static
  • Address assignment for users: DHCP Server/DHCP Relay/Static

IPV6

  • Features: L2, L3, Tap, Virtual Wire (transparent mode)
  • Services: App-ID, User-ID, Content-ID, WildFire and SSL Decryption
VLANS

  • 802.1q VLAN tags per device/per interface: 4,094/4,094
  • Max interfaces: 4,096 (PA-5060, PA-5050), 2,048 (PA-5020)
  • Aggregate interfaces (802.3ad)

NAT/PAT:

  • Max NAT rules: 8,000 (PA-5060), 4,000 (PA-5050), 1,000 (PA-5020)
  • Max NAT rules (DIPP): 450 (PA-5060), 250 (PA-5050), 200 (PA-5020)
  • Dynamic IP and port pool: 254
  • Dynamic IP pool: 32,000
  • NAT Modes: 1:1 NAT, n:n NAT, m:n NAT
  • DIPP oversubscription (Unique destination IPs per source port and IP): 8 (PA-5060, PA-5050), 4 (PA-5020)
  • NAT64

Virtual Wire

  • Max virtual wires: 2,048 (PA-5060, PA-5050), 1,024 (PA-5020)
  • Interface types mapped to virtual wires: physical and subinterfaces

L2 Forwarding

  • ARP table size/device: 32,000 (PA-5060, PA-5050), 20,000 (PA-5020)
  • MAC table size/device: 32,000 (PA-5060, PA-5050), 20,000 (PA-5020)
  • IPv6 neighbor table size: 5,000 (PA-5060, PA-5050), 2,000 (PA-5020)

Security Specifications:

Firewall

  • Policy-based control over applications, users and content
  • Fragmented packet protection
  • Reconnaissance scan protection
  • Denial of Service (DoS)/Distributed Denial of Services (DDoS) protection
  • Decryption: SSL (inbound and outbound), SSH

Wildfire

  • Identify and analyze targeted and unknown files for more than 100 malicious behaviors
  • Generate and automatically deliver protection for newly discovered malware via signature updates
  • Signature update delivery in less than 1 hour, integrated logging/reporting; access to WildFire API for programmatic submission of up to 100 samples per day and up to 1,000 report queries by file hash per day (Subscription Required)

File and Data Filtering

  • File transfer: Bi-directional control over more than 60 unique file types
  • Data transfer: Bi-directional control over unauthorized transfer of CC# and SSN
  • Drive-by download protection

User Integration (User-ID)

  • Microsoft Active Directory, Novell eDirectory, Sun One and other LDAP-based directories
  • Microsoft Windows Server 2003/2008/2008r2, Microsoft Exchange Server 2003/2007/2010
  • Microsoft Terminal Services, Citrix XenApp
  • XML API to facilitate integration with non-standard user repositories

IPSEC VPN (Site-To-Site)

  • Key Exchange: Manual key, IKE v1
  • Encryption: 3DES, AES (128-bit, 192-bit, 256-bit)
  • Authentication: MD5, SHA-1, SHA-256, SHA-384, SHA-512
  • Dynamic VPN tunnel creation (GlobalProtect)
Threat Prevention (Subscription Required)

  • Application, operating system vulnerability exploit protection
  • Stream-based protection against viruses (including those embedded in HTML, Javascript, PDF and compressed), spyware, worms

URL Filtering (Subscription Required)

  • Pre-defined and custom URL categories
  • Device cache for most recently accessed URLs
  • URL category as part of match criteria for security policies
  • Browse time information

Quality of Service (QOS)

  • Policy-based traffic shaping by application, user, source, destination, interface, IPSec VPN tunnel and more
  • 8 traffic classes with guaranteed, maximum and priority bandwidth parameters
  • Real-time bandwidth monitor
  • Per policy diffserv marking
  • Physical interfaces supported for QoS: 12

SSL VPN/Remote Access (GlobalProtect)

  • GlobalProtect Gateway
  • GlobalProtect Portal
  • Transport: IPSec with SSL fall-back
  • Authentication: LDAP, SecurID, or local DB
  • Client OS: Mac OS X 10.6, 10.7 (32/64 bit), 10.8 (32/64 bit), Windows XP, Windows Vista (32/64 bit), Windows 7 (32/64 bit)
  • Third party client support: Apple iOS, Android 4.0 and greater, VPNC IPSec for Linux

Management, Reporting, Visibility Tools

  • Integrated web interface, CLI or central management (Panorama)
  • Multi-language user interface
  • Syslog, Netflow v9 and SNMP v2/v3
  • XML-based REST API
  • Graphical summary of applications, URL categories, threats and data (ACC)
  • View, filter and export traffic, threat, WildFire, URL, and data filtering logs
  • Fully customizable reporting

specsheet-pa-5000-specsheet-de DS.pdf