
Palo Alto Networks Enterprise Firewall PA-220
Next-Generation Firewall in a Small Footprint
Looking for sizing recommendation? Take our Firewall Sizing Survey
Please Note: We cannot provide sizing recommendations for Palo Alto firewalls being deployed outside of the United States. Palo Alto firewalls are only available for
licensed businesses (not home users). Palo Alto firewalls cannot be sold outside of the United States
excluding Canada. 1 Year minimum of Partner Enabled Backline Support is required for all new Palo Alto firewall purchases
Sorry, this product is no longer available, please contact us for a replacement.
Click here to jump to more pricing!
Overview:
Classifies all applications, on all ports, all the time
- Identifies the application, regardless of port, encryption (SSL or SSH), or evasive technique employed
- Uses the application, not the port, as the basis for all of your safe enablement policy decisions: allow, deny, schedule, inspect and apply traffic-shaping
- Categorizes unidentified applications for policy control, threat forensics or App-ID™ application identification technology development
Enforces security policies for any user, at any location
- Deploys consistent policies to local and remote users running on the Windows®, Mac® OS X®, Linux®, Android®, or Apple® iOS platforms
- Enables agentless integration with Microsoft® Active Directory® and Terminal Services, LDAP, Novell® eDirectory™ and Citrix®
- Easily integrates your firewall policies with 802.1X wireless, proxies, NAC solutions, and any other source of user identity information
Prevents known and unknown threats
- Blocks a range of known threats, including exploits, malware and spyware, across all ports, regardless of common threat-evasion tactics employed
- Limits the unauthorized transfer of files and sensitive data, and safely enables non-work-related web surfing
- Identifies unknown malware, analyzes it based on hundreds of malicious behaviors, and then automatically creates and delivers protection
The controlling element of the Palo Alto Networks® PA-220 is PAN-OS® security operating system, which natively classifies all traffic, inclusive of applications, threats and content, and then ties that traffic to the user, regardless of location or device type. The application, content and user – in other words, the business elements that run your business – are then used as the basis of your security policies, resulting in an improved security posture and a reduction in incident response time.
Highlights
- High availability with active/active and active/passive modes
- Redundant power input for increased reliability
- Fan-less design
- Simplified deployments of large numbers of firewalls through USB
Performance and Capacities1 | PA-220 |
Firewall throughput (App-ID enabled)2, 4 | 500 Mbps |
Threat prevention throughput3, 4 | 150 Mbps |
IPsec VPN throughput2, 4 | 100 Mbps |
New sessions per second5 | 4,200 |
Max sessions | 64,000 |
- Performance and capacities are measured under ideal testing conditions.
- Firewall throughput measured with App-ID and User-ID features enabled utilizing 64K HTTP transactions
- Threat prevention throughput measured with App-ID, User-ID, IPS, AntiVirus and Anti-Spyware features enabled utilizing 64K HTTP transactions
- New sessions per second is measured with 4K HTTP transactions
- Adding virtual systems base quantity requires a separately purchased license
Networking Features:
The PA-220 supports a wide range of networking features that enable you to more easily integrate our security features into your existing network.
Interface Modes |
L2, L3, Tap, Virtual wire (transparent mode) |
Routing |
OSPFv2/v3 with graceful restart, BGP with graceful restart, RIP, Static routing |
Policy-based forwarding |
Point-to-Point Protocol over Ethernet (PPPoE) |
Multicast: PIM-SM, PIM-SSM, IGMP v1, v2, and v3 |
Bidirectional Forwarding Detection (BFD) |
IPv6 |
L2, L3, Tap, Virtual wire (transparent mode) |
Features: App-ID, User-ID™, Content-ID™, WildFire™ and SSL |
SLAAC |
IPsec VPN |
Key exchange: Manual key, IKEv1 and IKEv2 (pre-shared key, certificate-based authentication) |
Encryption: 3DES, AES (128-bit, 192-bit, 256-bit) |
Authentication: MD5, SHA-1, SHA-256, SHA-384, SHA-512 |
VLANs |
802.1q VLAN tags per device/per interface: 4,094/4,094 |
Network Address Translation (NAT) |
NAT modes (IPv4): Static IP, dynamic IP, dynamic IP and port (port address translation) |
NAT64, NPTv6 |
Additional NAT features: Dynamic IP reservation, tunable dynamic IP and port oversubscription |
High Availability |
Modes: Active/Active, Active/Passive |
Failure detection: path monitoring, interface monitoring |
Technical Specifications:
I/O |
(8) 10/100/1000 |
Management I/O |
(1) 10/100/1000 out-of-band management port, (1) RJ-45 console port (1) USB port (1) Micro USB console port |
Storage Capacity |
32GB SSD |
Power Supply (Avg/Max Power Consumption) |
Dual redundant 40W (21W/25W) |
Max BTU/hr |
102 BTU |
Input Voltage (Input Frequency) |
100-240VAC (50-60Hz) |
Max Current Consumption |
Firewall—1.75A @ 12VDC Power supply (AC side)—0.5A @ 100VAC, 0.2A @ 240VAC |
Weight (Stand-Alone Device/As Shipped) |
3.0 lbs / 5.4 lbs |
Safety |
cCSAus, CB |
EMI |
FCC Class B, CE Class B, VCCI Class B |
Certifications |
See: https://www.paloaltonetworks.com/company/certifications.html |
Environment |
Operating temperature: 32° to 104° F, 0° to 40° C Non-operating temperature: -4° to 158° F, -20° to 70° C Passive cooling |
Documentation:
Download the Palo Alto Networks Firewall Overview Datasheet (PDF).
Download the Palo Alto Networks PA-220 Series Specification Datasheet (PDF).
Pricing Notes:
- Pricing subject to change without notice.
- We cannot provide sizing recommendations for Palo Alto firewalls being deployed outside of the United States.
Palo Alto firewalls are only available for licensed businesses (not home users). Palo Alto firewalls cannot be sold outside of the United States excluding Canada. 1 Year minimum of Partner Enabled Backline Support is required for all new Palo Alto firewall purchases
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
DNS requires PAN-OS 9. and Threat Prevention Subscriptions
Get a Quote!
DNS requires PAN-OS 9. and Threat Prevention Subscriptions
Get a Quote!
DNS requires PAN-OS 9. and Threat Prevention Subscriptions
Get a Quote!
DNS requires PAN-OS 9. and Threat Prevention Subscriptions
Get a Quote!
DNS requires PAN-OS 9. and Threat Prevention Subscriptions
Get a Quote!
DNS requires PAN-OS 9. and Threat Prevention Subscriptions
Get a Quote!
DNS requires PAN-OS 9. and Threat Prevention Subscriptions
Get a Quote!
DNS requires PAN-OS 9. and Threat Prevention Subscriptions
Get a Quote!
DNS requires PAN-OS 9. and Threat Prevention Subscriptions
Get a Quote!
DNS requires PAN-OS 9. and Threat Prevention Subscriptions
Get a Quote!
DNS requires PAN-OS 9. and Threat Prevention Subscriptions
Get a Quote!
DNS requires PAN-OS 9. and Threat Prevention Subscriptions
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
SaaS Inline requires CDL
Get a Quote!
SaaS Inline requires CDL
Get a Quote!
SaaS Inline requires CDL
Get a Quote!
SaaS Inline requires CDL
Get a Quote!
SaaS Inline requires CDL
Get a Quote!
SaaS Inline requires CDL
Get a Quote!
DLP requires PAN-OS 1..2 + and Panorama
Get a Quote!
DLP requires PAN-OS 1..2 + and Panorama
Get a Quote!
DLP requires PAN-OS 1..2 + and Panorama
Get a Quote!
DLP requires PAN-OS 1..2 + and Panorama
Get a Quote!
DLP requires PAN-OS 1..2 + and Panorama
Get a Quote!
DLP requires PAN-OS 1..2 + and Panorama
Get a Quote!
DLP requires PAN-OS 1..2 + and Panorama
Get a Quote!
DLP requires PAN-OS 1..2 + and Panorama
Get a Quote!
DLP requires PAN-OS 1..2 + and Panorama
Get a Quote!
DLP requires PAN-OS 1..2 + and Panorama
Get a Quote!
DLP requires PAN-OS 1..2 + and Panorama
Get a Quote!
DLP requires PAN-OS 1..2 + and Panorama
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Requires PAN-OS 8.1 or higher
Get a Quote!
Requires PAN-OS 8.1 or higher
Get a Quote!
Requires PAN-OS 8.1 or higher
Get a Quote!
Requires PAN-OS 8.1 or higher
Get a Quote!
Requires PAN-OS 8.1 or higher
Get a Quote!
Requires PAN-OS 8.1 or higher
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
SD-WAN requires PAN-OS 9.1 or higher and Panorama
Get a Quote!
SD-WAN requires PAN-OS 9.1 or higher and Panorama
Get a Quote!
SD-WAN requires PAN-OS 9.1 or higher and Panorama
Get a Quote!
SD-WAN requires PAN-OS 9.1 or higher and Panorama
Get a Quote!
SD-WAN requires PAN-OS 9.1 or higher and Panorama
Get a Quote!
SD-WAN requires PAN-OS 9.1 or higher and Panorama
Get a Quote!
SD-WAN requires PAN-OS 9.1 or higher and Panorama
Get a Quote!
SD-WAN requires PAN-OS 9.1 or higher and Panorama
Get a Quote!
SD-WAN requires PAN-OS 9.1 or higher and Panorama
Get a Quote!
SD-WAN requires PAN-OS 9.1 or higher and Panorama
Get a Quote!
SD-WAN requires PAN-OS 9.1 or higher and Panorama
Get a Quote!
SD-WAN requires PAN-OS 9.1 or higher and Panorama
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
Get a Quote!
List Price:
Our Price: $144.00
List Price:
Our Price: $164.00
Get a Quote!