**PLEASE NOTE:*** All technical data provided on this webpage should be used as a guide only.* Manufacturer's specifications, dimensions, and product details may vary from those listed here.* We are not responsible for any errors or inaccuracies in the information provided.* It is your responsibility to verify all specifications and part numbers through official channels before makinga purchase.By continuing to use this website, you acknowledge that you have read, understood, and agree to this disclaimer.

The Palo Alto Networks PA-400 Series Series Next-Generation Firewalls, comprising the PA410, PA-415, PA-415- 5G, PA-440, PA-445, PA-450, and PA-460, brings ML-Powered NGFW capabilities to distributed enterprise branch offices, retail locations, and midsize businesses. The world’s first ML-Powered Next-Generation Firewall enables you to prevent unknown threats, see and secure everything—including the Internet of Things (IoT)—and reduce errors with automatic policy recommendations.
The controlling element of the PA-400 Series is PAN-OS®, the same software that runs all Palo Alto Networks NGFWs. PAN-OS natively classifies all traffic, inclusive of applications, threats, and content, and then ties that traffic to the user regardless of location or device type. The application, content, and user—in other words, the elements that run your business—then serve as the basis of your security pol- icies, resulting in improved security posture and reduced incident response times.
The traditional approach of using siloed security tools causes challenges for organizations, including security gaps, increased overhead for security teams, and disruptions in business productivity. Seamlessly integrated with our industry-leading NGFWs, our Cloud-Delivered Security Services share threat intelligence across 65,000 customers to prevent known and unknown threats across all threat vectors in real time. Eliminate security gaps in your entire network and take advantage of inline AI-powered security services that provide real-time protection everywhere.
Services include:
The integrated 5G Next-Generation Firewall is expanding the entry-level appliance portfolio to include the PA-415-5G, with integrated 5G cellular modem. With this new appliance, enterprise and remote branches can ensure optimal uptime with 5G leveraged as a backup WAN transport for business-critical applications. In addition, other mobile businesses that require cellular as their primary WAN can simply deploy this appliance and ensure rapid deployment without the hassle of adding additional appliances to leverage 5G.
3.2 Gbps
1.9 Gbps
1.7 Gbps
48,000
200,000
1/5
11.2
10/100/1000 (8)
10/100/1000 out-of-band management (1), RJ-45 console (1), USB (2), Micro USB console (1)
1.74" H x 8.83" D x 8.07" W
Dual redundant 50 W
Yes (Optional)
128 GB eMMC
Fanless
Can be purchased in 1, 3 or 5 year terms
Type
SKU
Brand
Description
Product Notes
Long Description
Support
PAN-SVC-STND-###
Palo Alto
Standard support
Can be purchased in 1, 3 or 5 year terms
You can learn more information about this product:
HereSupport
PAN-SVC-4HR-###
Palo Alto
4-Hour Premium Support
Can be purchased in 1, 3 or 5 year terms
You can learn more information about this product:
HereSupport
PAN-SVC-4HR-PLAT-###
Palo Alto
4-Hour Platinum Support
Can be purchased in 1, 3 or 5 year terms
You can learn more information about this product:
HereFeature
PAN-PA-###-BND-CORESEC
Palo Alto
Core Security Subscription Bundle (Advanced Threat Prevention, Advanced URL Filtering, Advanced Wildfire, DNS Security and SD-WAN )
Can be purchased in 1, 3 or 5 year terms
You can learn more information about this product
hereFeature
PAN-PA-###-SDWAN
Palo Alto
PA-440, SD-WAN subscription, 1 year (12 months), term.
Can be purchased in 1, 3 or 5 year terms
Provides intelligent and dynamic path selection on top of the industry-leading security that PAN-OS software already delivers. Managed by Panorama, the SD-WAN implementation includes: Centralized configuration management Automatic VPN topology creation Traffic distribution Monitoring and troubleshooting
You can learn more information about this product
hereFeature
PAN-PA-###-IOT-ENT
Palo Alto
PA-440, Enterprise IoT subscription, 1 year (12 months) term.
Can be purchased in 1, 3 or 5 year terms
You can learn more information about this product
hereFeature
PAN-PA-###-IOT-DRDL
Palo Alto
PA-440, IoT subscription, does not require data lake, 1 year (12 months), term.
Can be purchased in 1, 3 or 5 year terms
You can learn more information about this product
hereFeature
PAN-PA-###-SAAS-INLINE
Palo Alto
SaaS Inline subscription, PA-440
Can be purchased in 1, 3 or 5 year terms
The SaaS Security solution works with Strata Logging Service to discover all of the SaaS applications in use on your network. SaaS Security Inline can discover thousands of Shadow IT applications and their users and usage details. SaaS Security Inline also enforces SaaS policy rule recommendations seamlessly across your existing Palo Alto Networks firewalls. App-ID Cloud Engine (ACE) also requires SaaS Security Inline.
You can learn more information about this product
hereFeature
PAN-PA-###-IOT
Palo Alto
PA-440, IoT subscription, 1 year (12 months), term.
Can be purchased in 1, 3 or 5 year terms
The IoT Security solution works with next-generation firewalls to dynamically discover and maintain a real-time inventory of the IoT devices on your network. Through AI and machine-learning algorithms, the IoT Security solution achieves a high level of accuracy, even classifying IoT device types encountered for the first time. And because it’s dynamic, your IoT device inventory is always up to date. IoT Security also provides the automatic generation of policy recommendations to control IoT device traffic, as well as the automatic creation of IoT device attributes for use in firewall policies.
You can learn more information about this product
hereFeature
PAN-PA-###-DNS
Palo Alto
PA-440, DNS security subscription, 1 year (12 months), term.
Can be purchased in 1, 3 or 5 year terms
Provides enhanced DNS sinkholing capabilities by querying DNS Security, an extensible cloud-based service capable of generating DNS signatures using advanced predictive analytics and machine learning. This service provides full access to the continuously expanding DNS-based threat intelligence produced by Palo Alto Networks. To set up DNS Security, you must first purchase and install a Threat Prevention license. In addition to all of the features included with DNS Security, the Advanced DNS Security subscription provides access to the Advanced DNS Security cloud, which operates cloud-based domain detection engines that inspect changes to DNS responses. This enables NGFWs to detect and categorize hijacked and misconfigured domains in real-time to block malicious activity.
You can learn more information about this product
hereFeature
PAN-PA-###-GP
Palo Alto
PA-440, GlobalProtect subscription, 1 year (12 months), term.
Can be purchased in 1, 3 or 5 year terms
Provides mobility solutions and/or large-scale VPN capabilities. By default, you can deploy GlobalProtect portals and gateways (without HIP checks) without a license. If you want to use advanced GlobalProtect features (HIP checks and related content updates, the GlobalProtect Mobile App, IPv6 connections, or a GlobalProtect Clientless VPN) you will need a GlobalProtect Gateway license for each gateway.
You can learn more information about this product
hereFeature
PAN-PA-###-WF
Palo Alto
WildFire subscription
Can be purchased in 1, 3 or 5 year terms
Although basic WildFire® support is included as part of the Threat Prevention license, the WildFire subscription service provides enhanced services for organizations that require immediate coverage for threats, frequent WildFire signature updates, advanced file type forwarding (APK, PDF, Microsoft Office, and Java Applet), as well as the ability to upload files using the WildFire API. A WildFire subscription is also required if your firewalls will be forwarding files to an on-premise WF-500 appliance.
You can learn more information about this product
hereFeature
PAN-PA-###-DLP
Palo Alto
PA-440, DLP subscription, 1 year (12 months), term.
Can be purchased in 1, 3 or 5 year terms
Provides cloud-based protection against unauthorized access, misuse, extraction, and sharing of sensitive information. Enterprise DLP provides a single engine for accurate detection and consistent policy enforcement for sensitive data at rest and in motion using machine learning-based data classification, hundreds of data patterns using regular expressions or keywords, and data profiles using Boolean logic to scan for collective types of data.
You can learn more information about this product
hereFeature
PAN-PA-###-AWF
Palo Alto
Advanced WildFire subscription
Can be purchased in 1, 3 or 5 year terms
Advanced WildFire is a subscription offering that provides access to Intelligent Run-time Memory Analysis: a cloud-based advanced analysis engine that complements static and dynamic analysis, to detect and prevent evasive malware threats. By leveraging a cloud-based detection infrastructure, Intelligent Run-time Memory Analysis detection engines operate a wide array of detection mechanisms to target these highly-evasive malware.
You can learn more information about this product
hereFeature
PAN-PA-###-AIOPS-NGFW
Palo Alto
AIOps and Cloud Manager for NGFW subscription
Can be purchased in 1, 3 or 5 year terms
You can learn more information about this product
hereFeature
PAN-PA-###-ATP
Palo Alto
Advanced Threat Prevention subscription
Can be purchased in 1, 3 or 5 year terms
In addition to all of the features included with Threat Prevention, the Advanced Threat Prevention subscription provides an inline cloud-based threat detection and prevention engine, leveraging deep learning models trained on high fidelity threat intelligence gathered by Palo Alto Networks, to defend your network from evasive and unknown command-and-control (C2) threats by inspecting all network traffic.
You can learn more information about this product
hereFeature
PAN-PA-###-ADVURL
Palo Alto
Advanced URL Filtering subscription
Can be purchased in 1, 3 or 5 year terms
Provides the ability to not only control web-access, but how users interact with online content based on dynamic URL categories. You can also prevent credential theft by controlling the sites to which users can submit their corporate credentials. To set up URL Filtering, you must purchase and install a subscription for the supported URL filtering database, PAN-DB. With PAN-DB, you can set up access to the PAN-DB public cloud or to the PAN-DB private cloud.
You can learn more information about this product
hereFeature
PAN-PA-###-TP
Palo Alto
Threat prevention subscription
Can be purchased in 1, 3 or 5 year terms
Threat Prevention provides: Antivirus, anti-spyware (command-and-control), and vulnerability protection. Built-in external dynamic lists that you can use to secure your network against malicious hosts. Ability to identify infected hosts that try to connect to malicious domains.
You can learn more information about this product
here
| Type | Component | Description | 
|---|
1
Ethernet Ports
Eight RJ-45 10/100/1000Mbps ports for network traffic. You can set the link speed and duplex mode or choose auto-negotiate.
2
Management Port
Use this Ethernet 1Gbps port to access the management web interface and perform administrative tasks. The firewall also uses this port for management services, such as retrieving licenses and updating threat and application signatures.
3
CONSOLE port (Micro USB)
Use this port to connect a management computer to the firewall using a standard Type-A USB-to-micro USB cable. The console connection provides access to firewall boot messages, the Maintenance Recovery Tool (MRT), and the command line interface (CLI). Refer to Micro USB Console Port for more information and to download the Windows driver or to learn how to connect from a Mac or Linux computer.
4
CONSOLE port (RJ-45)
Use this port to connect a management computer to the firewall using a 9-pin serial to RJ-45 cable and terminal emulation software. The console connection provides access to firewall boot messages, the Maintenance Recovery Tool (MRT), and the command line interface (CLI). If your management computer does not have a serial port, use a USB-to-serial converter. Use the following settings to configure your terminal emulation software to connect to the console port: Data rate: 9600 Data bits: 8 Parity: none Stop bits: 1 Flow control: None
5
USB Ports
Two USB ports for debugging and administration only. Use one of these ports to bootstrap the firewall. Bootstrapping enables you to provision the firewall with a specific PAN-OS configuration and then license it and make it operational on your network.
6
LED status indicators
Six LEDs that indicate the status of the firewall hardware components (see Interpret the LEDs on a PA-400 Series Firewall).
7
Ground Stud
Use the single post ground stud to connect the firewall to earth ground (ground cable not included).
8
Power adapter inputs (PWR 1 and PWR 2)
Use the power inputs to connect power to the firewall. The PA-440, PA-450, and PA-460 ship with one 50W power adapter. A second adapter can be used for redundancy. Use only the PA-400 Series external power adapters provided by Palo Alto Networks.
Type
SKU
Description
Long Description
Rack Tray
PAN-PA-400-RACKTRAY
Rack mountable tray for up to two PA-400s and 4 power adapters for a 4 post rack mount (PA-440/450/460 models only)
Power Adapter
PAN-PWR-50W-AC
50W AC power adapter for PA-440, PA-450 and PA-460