Call a Specialist Today! 844-294-0778
End-of-Life Notice
The PA-5280 has reached end-of-life and is no longer available for new deployments. The designated replacement is the PA-5430, delivering 2x faster threat prevention throughput with 100G QSFP28 interfaces and ML-powered security.
View the PA-5430 Contact a specialist
The PA-5280 was the top-tier data center next-generation firewall in the PA-5200 Series, delivering up to 60 Gbps of firewall throughput with 64 million session capacity and dedicated processing for networking, security, and management. It featured 40G QSFP+ interfaces for high-speed data center connectivity. This model is no longer sold or supported for new deployments.
Designated replacement
Data center NGFW with ML-powered security, 100G QSFP28 interfaces, and 80 Gbps firewall throughput for high-performance environments.
View PA-5430Related end-of-life model
Entry-level PA-5200 Series model, also discontinued. Both models are replaced by the PA-5400 Series.
View PA-5250 EOL detailsRelated end-of-life model
Mid-range PA-5200 Series model, also discontinued. Replaced by the PA-5400 Series platforms.
View PA-5260 EOL detailsUpgrade path
The PA-5400 Series delivers a generational leap in data center firewall performance, addressing the threat prevention ceilings and interface limitations that constrain PA-5200 Series deployments.
Threat prevention throughput increases from 30 Gbps on the PA-5280 to 60 Gbps on the PA-5430. This ensures that full security inspection does not become a bottleneck for production traffic flows.
The PA-5280 is limited to 40G QSFP+ connectivity. The PA-5430 supports 100G QSFP28 interfaces, eliminating bandwidth bottlenecks as data center fabrics migrate to higher-speed interconnects.
The PA-5430 uses inline machine learning to block zero-day threats in real time, without relying solely on signature-based detection. This addresses evasive attacks that bypass legacy prevention engines.
The PA-5430 features dedicated hardware for SSL/TLS decryption, enabling inspection of encrypted traffic at scale without the performance degradation common in legacy platforms.
A direct specification comparison between the end-of-life PA-5280 and its designated replacement, the PA-5430.
| Specification | PA-5280 (Legacy) | PA-5430 (Current) | Improvement |
|---|---|---|---|
| Firewall throughput | 60 Gbps | 80 Gbps | 1.3x faster |
| Threat prevention throughput | 30 Gbps | 60 Gbps | 2x faster |
| IPSec VPN throughput | 24 Gbps | 53 Gbps | 2.2x faster |
| New sessions per second | 469,000 | 550,000 | 1.2x capacity |
| Max sessions | 64,000,000 | 30,000,000 | Different architecture |
| Network interfaces | 40G QSFP+ | 100G QSFP28 | 2.5x bandwidth |
| Threat intelligence | Signature-based | ML-powered inline | Real-time ML |
Trade-in programs may be available for existing PA-5280 deployments. Contact a specialist for details.
View PA-5430 details Compare all modelsReference specifications for the end-of-life PA-5280 platform.
| Firewall throughput | 60 Gbps |
| Threat prevention throughput | 30 Gbps |
| IPSec VPN throughput | 24 Gbps |
| New sessions per second | 469,000 |
| Max sessions | 64,000,000 |
| Virtual systems (base/max) | 25/225 |
| I/O | (4) 100/1000/10G Cu, (16) 1G/10G SFP/SFP+, (4) 40G/100G QSFP28 |
| Management I/O | (2) 10/100/1000, (1) 40G/100G QSFP28 HA, (1) 10/100/1000 out-of-band management, (1) RJ-45 console port |
| Storage capacity | 240GB SSD RAID1 (system), 2TB HDD RAID1 (log) |
| Power supply (max consumption) | 870W, 1+1 redundant |
| Max BTU/HR | 2,970 |
| Input voltage (input frequency) | 100-240VAC (50-60Hz) |
| Max current consumption | 6.5A @ 100-240VAC |
| Mean time between failure (MTBF) | 9.23 years |
| Rack mount (dimensions) | 3U, 19" standard rack (5.25"H x 20.5"D x 17.25"W) |
| Weight (standalone / as shipped) | 46 lbs / 62 lbs |
| Safety | cCSAus, CB IEC60950-1 |
| EMI | FCC Class A, CE Class A, VCCI Class A |
| Operating temperature | 32° to 122° F, 0° to 50° C |
| Non-operating temperature | -4° to 158° F, -20° to 70° C |
| Interface modes | L2, L3, Tap, Virtual Wire (transparent mode) |
| Routing | OSPFv2/v3, BGP, RIP, Static, Policy-based forwarding |
| High availability | Active/Active, Active/Passive |
| IPv6 | L2, L3, Tap, Virtual Wire; App-ID, User-ID, Content-ID, WildFire, SSL Decryption |
| 802.1q VLAN tags | 4,094 per device / 4,094 per interface |
Reference datasheets for the PA-5280 and the current PA-Series platforms.
Original hardware specifications and performance data for the legacy PA-5200 Series platforms including the PA-5280.
Download PDFComprehensive overview of Palo Alto Networks next-generation firewall capabilities and security features.
Download PDFRecommended products
Threat protection, web filtering, data loss prevention, and IoT security available as subscriptions for all PA-Series platforms.
Learn moreUnified management and operations across NGFW and SASE deployments with predictive analytics and AI-powered policy analysis.
Learn moreComplete listing of end-of-life Palo Alto Networks hardware with designated replacements and upgrade paths.
View all legacy productsDiscuss upgrade options, evaluate trade-in programs, and plan the transition from PA-5280 to the current PA-5400 Series.