Palo Alto Next-Generation Firewall PA 3220

Palo Alto Next-Generation Firewall PA 3220

From
$31,536.70
Rewards Banner

Palo Alto Next-Generation Firewall PA 3220

PAN-PA-3220
Item Condition : Brand New

Earn 31,536 points when you buy me!

Hurry! Other 2 people are watching this product
SKU
Palo-Alto-Next-Generation-Firewall-PA-3220
$31,536.70
In stock
Free shipping
could be yours in 1 - 5 days
Hurry! Other 2 people are watching this product

Palo Alto Networks PA-3200 Series next-generation firewalls—comprising the PA-3260, PA-3250, and PA-3220—are targeted at high-speed internet gateway deployments. PA-3200 Series appliances secure all traffic, including encrypted traffic, using dedicated processing and memory for networking, security, threat prevention, and management.

Details

Scalable, Intelligent Firewall Architecture

The Palo Alto Networks PA-3220 is built on a scalable architecture that intelligently assigns processing power to three key functional tasks: networking, security, and management. Each subsystem is backed by dedicated high-performance processing and memory, ensuring uncompromised performance across use cases.

PA-3220 Architecture Overview

ML-Powered Next-Generation Firewall

  • Embedded machine learning (ML) enables inline, signatureless prevention of file-based attacks and blocks novel phishing attempts instantly.
  • Cloud-based ML services provide zero-delay signatures and real-time response instructions to the firewall.
  • IoT devices are detected using behavioral analysis, with automated policy recommendations available through cloud integration.
  • Security policy automation reduces human error and accelerates deployment time.
ML-Powered Firewall

Full Application Visibility with Layer 7 Inspection

  • Identifies all applications across all ports and protocols—even if encrypted or using evasive tactics—via full Layer 7 inspection.
  • Empowers safe enablement using App-ID, allowing traffic control based on application identity rather than port numbers.
  • Supports creation of custom App-IDs and provides a mechanism to request new App-ID development for custom applications.
  • Detects malicious files and data patterns inside application payloads to block threats and prevent data exfiltration.
App-ID and Layer 7 Inspection

Single-Pass Architecture for High Performance

PA-3220 leverages a single-pass architecture that:

  • Performs all processing—networking, policy lookup, application decoding, and threat scanning—in a single unified flow.
  • Reduces processing overhead and eliminates latency introduced by multiple scan engines.
  • Ensures consistent and predictable throughput even with all security subscriptions enabled.
PA-3220 SD-WAN Support

Built-in SD-WAN Capability

  • Activate SD-WAN functionality directly on existing firewalls—no additional hardware required.
  • Seamless integration with Palo Alto’s industry-leading security stack ensures safe and reliable WAN connectivity.
  • Enhances user experience by minimizing latency, jitter, and packet loss through intelligent path selection and monitoring.
Tech Specs

Tech Specs & Customization

expert_image
Still have Questions?
Call +1 833 631 7912

Performance and Capacities

  • Firewall throughput (HTTP/appmix): 4 Gbps
  • Threat Prevention throughput (HTTP/appmix): 2.2 Gbps
  • IPsec VPN throughput: 2.4 Gbps
  • Max sessions: 1 million
  • New sessions per second: 46,000
  • Virtual systems (base/max): 1/6

Manufacturing Number

  • MFG Part Number: PAN-PA-3220

Networking Features

  • Interface Modes: L2, L3, tap, virtual wire (transparent mode)
  • Routing: OSPFv2/v3, BGP, Policy-based forwarding, PPPoE, DHCP
  • Multicast: PIM-SM, PIM-SSM, IGMP v1/v2/v3
  • Bidirectional Forwarding Detection (BFD)
  • SD-WAN: path quality measurement, dynamic path change
  • IPv6 support in all modes; features: App-ID, User-ID, Content-ID, WildFire, SSL Decryption
  • SLAAC

IPsec VPN

  • Key exchange: Manual, IKEv1, IKEv2 (PSK, certificate)
  • Encryption: 3DES, AES (128/192/256-bit)
  • Authentication: MD5, SHA-1, SHA-256, SHA-384, SHA-512

Network Address Translation (NAT)

  • NAT modes (IPv4): static IP, dynamic IP, dynamic IP and port (PAT)
  • NAT64, NPTv6
  • Dynamic IP reservation and oversubscription tuning

High Availability

  • Modes: Active/Active, Active/Passive
  • Failure detection: Path and Interface monitoring

Hardware Specifications

  • I/O: (12) 10/100/1000, (4) 1G SFP, (4) 1G/10G SFP/SFP+

Management I/O

  • (1) 10/100/1000 out-of-band management port
  • (2) 10/100/1000 HA ports
  • (1) 10G SFP+ HA port
  • (1) RJ-45 console port
  • (1) Micro USB

Storage

  • 240 GB SSD

Power Supply

  • Redundant 650W AC or DC (Avg: 180W / Max: 240W)

Electrical Specifications

  • AC Input Voltage: 100–240 VAC (50–60 Hz)
  • DC Input: -48 V @ 4.7 A, -60 V @ 3.8 A
  • Max Current Consumption: AC 2.3 A @ 100 VAC, 1.0 A @ 240 VAC
  • BTU/hr (max): 819

Environmental

  • Operating Temperature: 32° to 122°F (0° to 50°C)
  • Non-operating Temperature: -4° to 158°F (-20° to 70°C)
  • Humidity: 10% to 90%
  • Altitude: up to 10,000 ft (3,048 m)
  • Airflow: Front to back

Form Factor

  • 2U, 19” standard rack

Dimensions & Weight

  • Height: 3.5 inches
  • Depth: 20.53 inches
  • Width: 17.34 inches
  • Weight: 29 lbs (device) / 41.5 lbs (as shipped)

MTBF

  • 14 years

Certifications

  • Safety: TUV CB report, TUV NRTL
  • EMI: FCC Class A, CE Class A, VCCI Class A
Models
Reviews

Write Your Own Review

You're reviewing: Palo Alto Next-Generation Firewall PA 3220


^Top