Palo Alto Networks
Palo Alto Networks PAN-PA-1420 firewall appliance
Rack-mountable next-generation firewall with 9.5 Gbps firewall throughput, 6.2 Gbps threat prevention and 151 W PoE budget across four multi-gigabit ports
- Form FactorRack Mountable
- Ports4 x 10/100/1000, 4 x 1G/2.5G/5G, 4 x 1G/2.5G/5G PoE, 2 x 1G
- VPNFirewall throughput (appmix): 9.5 Gbps Threat Prevention thr
- PoE Interface4 x 1G/2.5G/5G PoE
- Max Power ConsumptionPoE Total PoE Power Budget: 151W Maximum load on single port
- FeaturesNETWORKING FEATURES Interface Modes: L2, L3, tap, virtual wi
- App-ID and App-Control secure traffic by identifying 1.4M concurrent sessions
- Threat Prevention inspects data at 6.2 Gbps throughput for inline protection
- ML-powered NGFW stops unknown threats using inline machine-learning analysis
- Flexible 1G/2.5G/5G PoE ports deliver 151W budget to power endpoints
- High availability active/active and active/passive modes maintain uptime during failures
Enterprise firewall appliance
The Palo Alto Networks PAN-PA-1420 is a rack-mountable next-generation firewall designed for branch offices and small enterprises that need integrated threat prevention and SD-WAN capabilities. It consolidates networking, security, and PoE switching in a single 1U chassis to reduce appliance sprawl.
Throughput capacity and session limits
Firewall throughput reaches 9.5 Gbps with appmix traffic, while threat prevention throughput sustains 6.2 Gbps and IPsec VPN throughput peaks at 5.6 Gbps. The platform supports 1.4 million concurrent sessions and 140,000 new sessions per second, with a base of one virtual system expandable to six via licence.
Interface constraints and PoE budget
The unit provides four 10/100/1000 ports, eight 1G/2.5G/5G ports (four with PoE), two 1G SFP ports, and eight 1G/10G SFP/SFP+ ports. Total PoE power budget is 151 W with a maximum of 90 W on a single port, while overall system power draw reaches 300 W.
Highlights
- App-ID and App-Control secure traffic by identifying 1.4M concurrent sessions
- Threat Prevention inspects data at 6.2 Gbps throughput for inline protection
- ML-powered NGFW stops unknown threats using inline machine-learning analysis
- Flexible 1G/2.5G/5G PoE ports deliver 151W budget to power endpoints
- High availability active/active and active/passive modes maintain uptime during failures
Specifications
| Brand | Palo Alto Networks |
|---|---|
| Series | PA-1400 Series |
| Model | PA-1420 |
| Part Number | PAN-PA-1420 |
| Form Factor | Rack Mountable |
| Ports | 4 x 10/100/1000, 4 x 1G/2.5G/5G, 4 x 1G/2.5G/5G PoE, 2 x 1G SFP, 8 x 1G/10G SFP/SFP+ |
| VPN | Firewall throughput (appmix): 9.5 Gbps Threat Prevention throughput (appmix): 6.2 Gbps IPsec VPN throughput: 5.6 Gbps Max concurrent sessions: 1.4M New sessions per second: 140,000 Virtual systems (base/max)*: 1/6 *Adding virtual systems over base quantity requires a separately purchased license. |
| PoE Interface | 4 x 1G/2.5G/5G PoE |
| Max Power Consumption | PoE Total PoE Power Budget: 151W Maximum load on single port: 90W Max Power Consumption: 300 W |
| Features | NETWORKING FEATURES Interface Modes: L2, L3, tap, virtual wire (transparent mode) Routing: OSPFv2/v3 with graceful restart, BGP with graceful restart, RIP, static routing Policy-based forwarding Point-to-Point Protocol over Ethernet (PPPoE) Multicast: PIM-SM, PIM-SSM, IGMP v1, v2, and v3 SD-WAN: Path quality measurement (jitter, packet loss, latency) Initial path selection (PBF) Dynamic path change IPv6: L2, L3, tap, virtual wire (transparent mode) Features: App-ID, User-ID, Content-ID, WildFire, and SSL decryption SLAAC IPsec and SSL VPN: Key exchange: manual key, IKEv1, and IKEv2 ( |
| Dimensions | 1.70" H x 14.15" D x 17.15" W |
| Weight | 15.5 lbs |
| Shipping weight | 10.95 kg |
| Package size | 572 × 559 × 254 mm |
Questions about this item
Will the PA-1420's 10/100/1000 ports link with my existing 100 Mbps switches?
Yes. The four 10/100/1000 ports auto-negotiate down to 100 Mbps full-duplex so they will interoperate with older 100 Mbps gear without configuration changes.
How can I confirm the 151 W PoE budget is actually delivering power to my access points after installation?
In the web UI or CLI, run "show poe interface all" to see real-time per-port draw and verify the total stays within the 151 W budget.
Does the box include SFP+ transceivers for the 1G/10G uplinks or must I order them separately?
The appliance ships without transceivers; you must purchase compatible 1G SFP or 10G SFP+ modules separately for the eight SFP/SFP+ ports.
Also in this aisle
People compared these
Same shelf, same checkout — eight coins and a 30-minute rate lock.
SonicWall 01-SSC-1465 Capture Advanced Threat Protection hardware license 1 Year TZ600 Series
- Capture Advance Thr…



