1. Trang chủ
  2. Firewalls
  3. Firewall
  4. PaloAlto PA-220R

PaloAlto PA-220R

PaloAlto PA-220R

Brand: Palo Alto Networks
Category: Firewall

Đánh giá của chúng tôi

Đánh giá dựa trên nhận định của chuyên gia

5
  • Hiệu năng 5 / 10

The PA-220R is a next-generation firewall appliance in a ruggedized form factor, providing rock-solid network security for severe environments, such as utility substations, power plants, manufacturing plants, oil and gas facilities, building management systems and healthcare networks.

The controlling element of the Palo Alto Networks® PA-220R is PAN-OS® security operating system, which natively classifies all traffic, inclusive of applications, threats and content, and then ties that traffic to the user, regardless of location or device type. The application, content and user – in other words, the elements that run your business – are then used as the basis of your security policies, resulting in an improved security posture and a reduction in incident response time.

Specification

STTTính năngPalo Alto PA-220R
1Thông số kỹ thuật
Firewall Throughput500/560 Mbps
Threat Prevention throughput150/260 Mbps
IPSec VPN throughput500 Mbps
New sessions per second4200
Maximum sessions64000
Interfaces supported(6) 10/100/1000, (2) SFP
Management I/O(1) 10/100/100 out-of-band management
(1) RJ-45 console
(1) USB, (1) Micro USB console
Size2.0” H x 8.66” D x 9.25” W
Flexible mounting options including DIN rail, rack and wall mount
Power Supply (Avg/Max Power Consumption)Dual DC power feeds (13 W/16 W)
Redundant Power SupplyNone
Storage capacity32GB EMMC
Hot-swappable fansNo
Max BTU/hr55
Input Voltage (Input Frequency)12–48VDC 1.4A
Max Current ConsumptionFirewall – 1.4A @ 12VDC
Max inrush current 4.9A @ 12VDC
Weight (Stand-Alone Device/ As Shipped)4.5 lbs / 6.0 lbs
SafetyTUV CB report and TUV NRTL
EMIFCC Class A, CE Class A, VCCI Class A
CertificationsIEC 61850-3 and IEEE 1613 environmental and testing standards.
For more certifications, see:
https://www.paloaltonetworks.com/company/certifications.html
EnviromentOperating temperature: -40° to 158° F, -40° to 70° C
Non-operating temperature: -40° to 167° F, -40° to 75° C
Passive cooling
2Network Feature
Interface modeL2, L3, tap, virtual wire (transparent mode)
RoutingOSPFv2/v3 with graceful restart, BGP with graceful restart, RIP,
static routing
Policy-based forwarding
Point-to-Point Protocol over Ethernet (PPPoE)
Multicast: PIM-SM, PIM-SSM, IGMP v1, v2 and v3
IPv6L2, L3, tap, virtual wire (transparent mode)
Features: App-ID, User-ID, Content-ID, WildFire and SSL
decryption
SLAAC
IPSec VPNKey exchange: manual key, IKEv1 and IKEv2 (pre-shared key,
certificate-based authentication)
Encryption: 3DES, AES (128-bit, 192-bit, 256-bit)
Authentication: MD5, SHA-1, SHA-256, SHA-384, SHA-512
VLANs802.1Q VLAN tags per device/per interface: 4,094/4,094
Network Address TranslationNAT modes (IPv4): static IP, dynamic IP, dynamic IP and port
(port address translation)
NAT64, NPTv6
Additional NAT features: dynamic IP reservation, tunable dynamic
IP and port oversubscription
High AvailabilityModes: active/active, active/passive
Failure detection: path monitoring, interface monitoring

Subscriptions

The following Palo Alto Networks subscriptions unlock certain firewall features or enable the firewall to leverage a Palo Alto Networks cloud-delivered service (or both). Here you can read more about each service or feature that requires a subscription to work with the firewall. To enable a subscription, you must first Activate Subscription Licenses; once active, most subscription services can use Dynamic Content Updates to provide new and updated functionality to the firewall.

Subscriptions You Can Use With the Firewall
Threat Prevention Threat Prevention provides: • Antivirus, anti-spyware (command-and-control), and vulnerability protection. • Built-in external dynamic lists that you can use to secure your network against malicious hosts. • Ability to identify infected hosts that try to connect to malicious domains. • Get Started with Threat Prevention
DNS Security Provides enhanced DNS sinkholing capabilities by querying DNS Security, an extensible cloud-based service capable of generating DNS signatures using advanced predictive analytics and machine learning. This service provides full access to the continuously expanding DNS-based threat intelligence produced by Palo Alto Networks. To set up DNS Security, you must first purchase and install a Threat Prevention license. • Get Started with DNS Security
URL Filtering Provides the ability to not only control web-access, but how users interact with online content based on dynamic URL categories. You can also prevent credential theft by controlling the sites to which users can submit their corporate credentials. To set up URL Filtering, you must purchase and install a subscription for one of the supported URL filtering databases: PAN-DB or BrightCloud. With PAN-DB, you can set up access to the PAN-DB public cloud or to the PAN-DB private cloud. • Get Started with URL Filtering
WildFire Although basic WildFire® support is included as part of the Threat Prevention license, the WildFire subscription service provides enhanced services for organizations that require immediate coverage for threats, frequent WildFire signature updates, advanced file type forwarding (APK, PDF, Microsoft Office, and Java Applet), as well as the ability to upload files using the WildFire API. A WildFire subscription is also required if your firewalls will be forwarding files to an on-premise WF-500 appliance. • Get Started with WildFire
AutoFocus Provides a graphical analysis of firewall traffic logs and identifies potential risks to your network using threat intelligence from the AutoFocus portal. With an active license, you can also open an AutoFocus search based on logs recorded on the firewall. • Get Started with AutoFocus
Cortex Data Lake Cortex Data Lake was previously called the Logging Service. The Customer Support Portal and firewall web interface both still reference the Logging Service in some places, including the device license name that’s displayed in the firewall web interface (Device > Licenses). Provides cloud-based, centralized log storage and aggregation. The Logging Service is required or highly-recommended to support several other cloud-delivered services, including Magnifier, GlobalProtect cloud service, and Traps management service. • Get Started with Cortex Data Lake
GlobalProtect Provides mobility solutions and/or large-scale VPN capabilities. By default, you can deploy GlobalProtect portals and gateways (without HIP checks) without a license. If you want to use advanced GlobalProtect features (HIP checks and related content updates, the GlobalProtect Mobile App, IPv6 connections, or a GlobalProtect Clientless VPN) you will need a GlobalProtect license (subscription) for each gateway. • Get Started with GlobalProtect
Virtual Systems This license is required to enable support for multiple virtual systems on PA-3200 Series firewalls. In addition, you must purchase a Virtual Systems license if you want to increase the number of virtual systems beyond the base number provided by default on PA-5200 Series, and PA-7000 Series firewalls (the base number varies by platform). The PA-800 Series, PA-220, and VM-Series firewalls do not support virtual systems. • Get Started with Virtual Systems

Specs

System Performance

Firewall throughput 500/560 Mbps
Concurrent connections 64,000
New connections/sec 4,200
IPS throughput 150 Mbps
Threat Protection Throughput 150/260 Mbps
IPSec VPN throughput 100 Mbps

Physical interfaces

GE RJ45 Ports 6 x 10/100/1000
GE SFP Slots 2 SFP
I/O ports 1 x 10/100/1000 out-of-band management port | 1 x RJ-45 console port | 1 x USB port | 1 x Micro USB console port
Storage 32 GB EMMC

Dimensions & Enviroment

Mounting 2.0” H x 8.66” D x 9.25” W Flexible mounting options including DIN rail, rack and wall mount
Dimensions Width x Depth x Height (inches) 2.0” H x 8.66” D x 9.25” W
Weight 4.5 lbs / 6.0 lbs (Stand-Alone Device/As Shipped)
Power supply Dual DC power feeds (13 W/16 W)
Safety TUV CB report and TUV NRTL
Max BTU/hr 55
Input Voltage (Input Frequency) 12–48VDC 1.4A
Max Current Consumption Firewall – 1.4A @ 12VDC | Max inrush current 4.9A @ 12VDC
EMI FCC Class A, CE Class A, VCCI Class A
Operating Temperature -40° to 158° F, -40° to 70° C
Non-operating temperature -40° to 167° F, -40° to 75° C
Certifications IEC 61850-3 and IEEE 1613 environmental and testing standards. For more certifications, see: https://www.paloaltonetworks.com/company/certifications.html

Wireless Specification (XG Wireless only)

Product Certifications

Documentation

Datasheet Palo Alto 220R

Reviews

  • Be the first to add a Review

    Please post a user review only if you have / had this product.

  • Rate this Product

  • 5
  • 6 / 10 based on your selection

Thương hiệuView All

Show More Brands