Call a Specialist Today! 844-294-0778
End-of-Life Notice
The PA-5260 has reached end-of-life and is no longer available for new deployments. The designated replacement is the PA-5430, delivering approximately 1.5x faster firewall throughput with 2.1x threat prevention improvement and 100G QSFP28 interfaces.
View the PA-5430 Contact a specialist
The PA-5260 was a high-performance data center next-generation firewall in the PA-5200 Series, delivering up to 53 Gbps of firewall throughput with dedicated processing for networking, security, and management. It served as the mid-range option in the PA-5200 lineup with 40G QSFP+ interfaces. This model is no longer sold or supported for new deployments.
Designated replacement
Data center NGFW with ML-powered security, 100G QSFP28 interfaces, and 80 Gbps firewall throughput for high-performance environments.
View PA-5430Related end-of-life model
Lower-throughput variant in the PA-5200 Series, also discontinued. Both models are replaced by the PA-5400 Series.
View PA-5250 EOL detailsRelated end-of-life model
Top-tier PA-5200 Series model, also discontinued. Replaced by the PA-5400 Series platforms.
View PA-5280 EOL detailsUpgrade path
The PA-5400 Series delivers a generational leap in data center firewall performance, addressing the throughput ceilings and interface limitations that constrain PA-5200 Series deployments.
The PA-5260 delivers 53 Gbps of firewall throughput. The PA-5430 reaches 80 Gbps, providing additional headroom for growing data center traffic without requiring a chassis-based deployment.
Threat prevention throughput increases from 28 Gbps to 60 Gbps. This ensures that enabling full security inspection does not create a performance bottleneck for production traffic flows.
The PA-5260 is limited to 40G QSFP+ connectivity. The PA-5430 supports 100G QSFP28 interfaces, eliminating bandwidth bottlenecks as data center fabrics migrate to higher-speed interconnects.
The PA-5430 uses inline machine learning to block zero-day threats in real time, without relying solely on signature-based detection. This addresses evasive attacks that bypass legacy prevention engines.
A direct specification comparison between the end-of-life PA-5260 and its designated replacement, the PA-5430.
| Specification | PA-5260 (Legacy) | PA-5430 (Current) | Improvement |
|---|---|---|---|
| Firewall throughput | 53 Gbps | 80 Gbps | 1.5x faster |
| Threat prevention throughput | 28 Gbps | 60 Gbps | 2.1x faster |
| IPSec VPN throughput | 20 Gbps | 53 Gbps | 2.7x faster |
| New sessions per second | 382,000 | 550,000 | 1.4x capacity |
| Max sessions | 32,000,000 | 30,000,000 | Comparable capacity |
| Network interfaces | 40G QSFP+ | 100G QSFP28 | 2.5x bandwidth |
| Threat intelligence | Signature-based | ML-powered inline | Real-time ML |
Trade-in programs may be available for existing PA-5260 deployments. Contact a specialist for details.
View PA-5430 details Compare all modelsReference specifications for the end-of-life PA-5260 platform.
| Firewall throughput | 53 Gbps |
| Threat prevention throughput | 28 Gbps |
| IPSec VPN throughput | 20 Gbps |
| New sessions per second | 382,000 |
| Max sessions | 32,000,000 |
| Virtual systems (base/max) | 25/225 |
| I/O | (4) 100/1000/10G Cu, (16) 1G/10G SFP/SFP+, (4) 40G/100G QSFP28 |
| Management I/O | (2) 10/100/1000, (1) 40G/100G QSFP28 HA, (1) 10/100/1000 out-of-band management, (1) RJ-45 console port |
| Storage capacity | 240GB SSD RAID1 (system), 2TB HDD RAID1 (log) |
| Power supply (max consumption) | 870W, 1+1 redundant |
| Max BTU/HR | 2,970 |
| Input voltage (input frequency) | 100-240VAC (50-60Hz) |
| Max current consumption | 6.5A @ 100-240VAC |
| Mean time between failure (MTBF) | 9.23 years |
| Rack mount (dimensions) | 3U, 19" standard rack (5.25"H x 20.5"D x 17.25"W) |
| Weight (standalone / as shipped) | 46 lbs / 62 lbs |
| Safety | cCSAus, CB IEC60950-1 |
| EMI | FCC Class A, CE Class A, VCCI Class A |
| Operating temperature | 32° to 122° F, 0° to 50° C |
| Non-operating temperature | -4° to 158° F, -20° to 70° C |
| Interface modes | L2, L3, Tap, Virtual Wire (transparent mode) |
| Routing | OSPFv2/v3, BGP, RIP, Static, Policy-based forwarding |
| High availability | Active/Active, Active/Passive |
| IPv6 | L2, L3, Tap, Virtual Wire; App-ID, User-ID, Content-ID, WildFire, SSL Decryption |
| 802.1q VLAN tags | 4,094 per device / 4,094 per interface |
Reference datasheets for the PA-5260 and the current PA-Series platforms.
Original hardware specifications and performance data for the legacy PA-5200 Series platforms including the PA-5260.
Download PDFComprehensive overview of Palo Alto Networks next-generation firewall capabilities and security features.
Download PDFRecommended products
Threat protection, web filtering, data loss prevention, and IoT security available as subscriptions for all PA-Series platforms.
Learn moreUnified management and operations across NGFW and SASE deployments with predictive analytics and AI-powered policy analysis.
Learn moreComplete listing of end-of-life Palo Alto Networks hardware with designated replacements and upgrade paths.
View all legacy productsDiscuss upgrade options, evaluate trade-in programs, and plan the transition from PA-5260 to the current PA-5400 Series.