Call a Specialist Today! 844-294-0778
End-of-Life Notice
The PA-5020 has reached end-of-life and is no longer available for new deployments. The designated replacement is the PA-5410, delivering approximately 10x faster firewall throughput while reducing rack space by 75%.
View the PA-5410 Contact a specialist
The PA-5020 was the entry-level model in the PA-5000 Series chassis, delivering up to 5 Gbps of firewall throughput with dedicated processing for networking, security, and threat prevention. Designed for high-speed data center and Internet gateway deployments, the PA-5020 required a 4RU chassis shared across the PA-5000 Series line. This model is no longer sold or supported for new deployments.
Designated replacement
High-performance 1RU NGFW with ML-powered security, 52 Gbps firewall throughput, and modern 25G/100G interfaces for data center and campus deployments.
View PA-5410Related end-of-life model
Mid-tier model in the legacy PA-5000 Series chassis, also discontinued. Replaced by the PA-5400 Series platform.
View PA-5050 EOL detailsRelated end-of-life model
Top-tier model in the legacy PA-5000 Series chassis, also discontinued. Replaced by the PA-5400 Series platform.
View PA-5060 EOL detailsUpgrade path
The PA-5400 Series represents a fundamental architectural shift from the legacy PA-5000 chassis, addressing the performance, density, and power consumption limitations that constrained previous-generation deployments.
The PA-5020 delivers 5 Gbps of firewall throughput. The PA-5410 achieves 52 Gbps, providing the headroom needed for encrypted traffic inspection at scale without performance degradation.
The PA-5000 Series requires a 4RU chassis. The PA-5410 consolidates equivalent and superior performance into a single 1RU appliance, freeing three rack units per deployment.
The PA-5410 integrates inline machine learning to block zero-day threats in real time. The PA-5020 relies on signature-based detection, which cannot address novel attack vectors without prior analysis.
The PA-5410 supports 25G and 100G interfaces natively, aligning with current data center fabric standards. The PA-5020 is limited to 1G and 10G connectivity.
A direct specification comparison between the end-of-life PA-5020 and its designated replacement, the PA-5410.
| Specification | PA-5020 (Legacy) | PA-5410 (Current) | Improvement |
|---|---|---|---|
| Firewall throughput | 5 Gbps | 52 Gbps | ~10x faster |
| Threat prevention throughput | 2 Gbps | 35 Gbps | ~17x faster |
| IPSec VPN throughput | 2 Gbps | 29 Gbps | ~14x faster |
| New sessions per second | 8,000 | 295,000 | ~36x capacity |
| Max sessions | 250,000 | 8,000,000 | 32x capacity |
| Form factor | 4RU chassis | 1RU appliance | 75% smaller |
| Power consumption | 340W max (chassis) | 450W max (1RU) | Higher efficiency per Gbps |
Trade-in programs may be available for existing PA-5020 deployments. Contact a specialist for details.
View PA-5410 details Compare all modelsReference specifications for the end-of-life PA-5020 platform.
| Firewall throughput | 5 Gbps |
| Threat prevention throughput | 2 Gbps |
| IPSec VPN throughput | 2 Gbps |
| New sessions per second | 8,000 |
| Max sessions | 250,000 |
| SSL decrypt sessions | 15,000 |
| IPSec VPN tunnels / tunnel interfaces | 2,000 |
| GlobalProtect (SSL VPN) concurrent users | 5,000 |
| SSL inbound certificates | 100 |
| Virtual systems (base / max) | 10 / 20 |
| Virtual routers | 20 |
| Security zones | 80 |
| Max number of policies | 10,000 |
| I/O | (12) 10/100/1000, (8) Gigabit SFP |
| Management I/O | (2) 10/100/1000 high availability, (1) 10/100/1000 out-of-band management, (1) RJ-45 console port |
| Storage capacity | 120GB, 240GB SSD, RAID 1 |
| Form factor | 4RU chassis (2U device + 2U fans/power) |
| Power supply (avg / max consumption) | Redundant 450W AC (270W / 340W) |
| Max BTU/HR | 1,160 BTU |
| Input voltage (input frequency) | 100-240VAC (50-60Hz); -40 to -72 VDC |
| Max current consumption | 8A @ 100VAC, 14A @ 48VDC |
| Mean time between failure (MTBF) | 6.5 years |
| Rack mountable | 2U, 19" standard rack |
| Dimensions | 3.5"H x 20"D x 17.5"W |
| Weight (standalone / as shipped) | 41 lbs / 55 lbs |
| Safety | UL, CUL, CB |
| EMI | FCC Class A, CE Class A, VCCI Class A |
| Certifications | NEBS Level 3, FIPS Level 2, ICSA |
| Operating temperature | 32° to 122° F, 0° to 50° C |
| Non-operating temperature | -4° to 158° F, -20° to 70° C |
| Interface modes | L2, L3, Tap, Virtual Wire (transparent mode) |
| Routing | OSPF, RIP, BGP, Static, Policy-based forwarding, Multicast (PIM-SM, PIM-SSM, IGMP v1-v3) |
| High availability | Active/Active, Active/Passive |
| Address assignment (device) | DHCP Client / PPPoE / Static |
| Address assignment (users) | DHCP Server / DHCP Relay / Static |
| IPv6 | L2, L3, Tap, Virtual Wire; App-ID, User-ID, Content-ID, WildFire, SSL Decryption |
| 802.1q VLAN tags | 4,094 per device / 4,094 per interface |
Reference datasheets for the PA-5020 and the current PA-Series platforms.
Original hardware specifications and performance data for the legacy PA-5000 Series platform including the PA-5020.
Download PDFComprehensive overview of Palo Alto Networks next-generation firewall capabilities and security features.
Download PDFRecommended products
Threat protection, web filtering, data loss prevention, and IoT security available as subscriptions for all PA-Series platforms.
Learn moreUnified management and operations across NGFW and SASE deployments with predictive analytics and AI-powered policy analysis.
Learn moreComplete listing of end-of-life Palo Alto Networks hardware with designated replacements and upgrade paths.
View all legacy productsDiscuss upgrade options, evaluate trade-in programs, and plan the transition from PA-5020 to the current PA-5400 Series.