Call a Specialist Today! 844-294-0778
End-of-Life Notice
The PA-200 has reached end-of-life and is no longer available for new deployments. The designated replacement is the PA-440, delivering up to 30x faster firewall throughput in the same fanless desktop form factor.
View the PA-440 Contact a specialist
The PA-200 was a desktop next-generation firewall designed for distributed enterprise branch offices, delivering up to 100 Mbps of firewall throughput with dedicated processing for networking, security, and threat prevention. This model is no longer sold or supported for new deployments.
Designated replacement
Desktop NGFW with ML-powered security, fanless design, and 3.0 Gbps firewall throughput for branch offices and small businesses.
View PA-440Related end-of-life model
The successor to the PA-200, also discontinued. Both models are replaced by the PA-400 Series.
View PA-220 EOL detailsRelated end-of-life model
Legacy mid-range branch firewall, also discontinued. Replaced by the PA-400 and PA-500 Series platforms.
View PA-500 EOL detailsUpgrade path
The PA-400 Series is not an incremental update. It represents a complete architectural overhaul that addresses the performance and operational limitations of legacy branch firewalls.
The PA-200 maxes out at 100 Mbps of firewall throughput. The PA-440 delivers 3.0 Gbps, enabling full utilization of modern gigabit connections without security-imposed limitations.
Policy commits and reboots on the PA-200 can take extended periods. The PA-440 features a modern quad-core processor that reduces commit times to seconds, improving operational efficiency.
Like the PA-200, the PA-440 maintains a fanless desktop form factor suitable for open offices, retail locations, and healthcare environments where noise is a concern.
Unlike the PA-200 single power supply, the PA-440 supports an optional redundant power supply, providing branch offices with enterprise-grade reliability and uptime.
A direct specification comparison between the end-of-life PA-200 and its designated replacement, the PA-440.
| Specification | PA-200 (Legacy) | PA-440 (Current) | Improvement |
|---|---|---|---|
| Firewall throughput | 100 Mbps | 3.0 Gbps | 30x faster |
| Threat prevention throughput | 50 Mbps | 1.2 Gbps | 24x faster |
| IPSec VPN throughput | 50 Mbps | 1.8 Gbps | 36x faster |
| Max sessions | 64,000 | 300,000 | 4.7x capacity |
| Management speed | Dual core | Quad core | Faster commits |
| Power supply | Single only | Redundant optional | Higher uptime |
| Cooling | Fanless | Fanless | Same silent design |
Trade-in programs may be available for existing PA-200 deployments. Contact a specialist for details.
View PA-440 details Compare all modelsReference specifications for the end-of-life PA-200 platform.
| Firewall throughput | 100 Mbps |
| Threat prevention throughput | 50 Mbps |
| IPSec VPN throughput | 50 Mbps |
| New sessions per second | 1,000 |
| Max sessions | 64,000 |
| SSL decrypt sessions | 1,000 |
| IPSec VPN tunnels / tunnel interfaces | 25 |
| GlobalProtect (SSL VPN) concurrent users | 25 |
| SSL inbound certificates | 25 |
| Virtual routers | 3 |
| Security zones | 10 |
| Max number of policies | 250 |
| I/O | (4) 10/100/1000 |
| Management I/O | (1) 10/100/1000 out-of-band management port, (1) RJ-45 console port |
| Storage capacity | 16GB SSD |
| Power supply (avg / max consumption) | 40W (20W / 30W) |
| Max BTU/HR | 102 BTU |
| Input voltage (input frequency) | 100-240VAC (50-60Hz) |
| Max current consumption | 3.3A @ 100VAC |
| Mean time between failure (MTBF) | 13 years |
| Dimensions | 1.75"H x 7"D x 9.25"W |
| Weight (standalone / as shipped) | 2.8 lbs / 5.0 lbs |
| Safety | UL, CUL, CB |
| EMI | FCC Class B, CE Class B, VCCI Class B |
| Certifications | ICSA |
| Operating temperature | 32° to 104° F, 0° to 40° C |
| Non-operating temperature | -4° to 158° F, -20° to 70° C |
| Interface modes | L2, L3, Tap, Virtual Wire (transparent mode) |
| Routing | OSPF, RIP, BGP, Static |
| Forwarding table size | 1,000 entries per device / per VR |
| High availability | Active/Passive with no session synchronization |
| Address assignment (device) | DHCP Client / PPPoE / Static |
| Address assignment (users) | DHCP Server / DHCP Relay / Static |
| IPv6 | L2, L3, Tap, Virtual Wire; App-ID, User-ID, Content-ID, WildFire, SSL Decryption |
| 802.1q VLAN tags | 4,094 per device / 4,094 per interface |
| Max NAT rules | 125 |
| Max virtual wires | 50 |
| ARP table size | 500 per device |
Reference datasheets for the PA-200 and the current PA-Series platforms.
Original hardware specifications and performance data for the legacy PA-200 platform.
Download PDFComprehensive overview of Palo Alto Networks next-generation firewall capabilities and security features.
Download PDFRecommended products
Threat protection, web filtering, data loss prevention, and IoT security available as subscriptions for all PA-Series platforms.
Learn moreUnified management and operations across NGFW and SASE deployments with predictive analytics and AI-powered policy analysis.
Learn moreComplete listing of end-of-life Palo Alto Networks hardware with designated replacements and upgrade paths.
View all legacy productsDiscuss upgrade options, evaluate trade-in programs, and plan the transition from PA-200 to the current PA-400 Series.