Omnixon Global
Palo Alto Networks PA-5220 Next-Generation Firewall

Palo Alto Networks PA-5220 Next-Generation Firewall

Brand: Palo Alto Networks | Category: Network Security

SKU: PA-5220 | Part #: PA-5220 | MPN: PA-5220

Contact for Pricing — Request a Quote

Request a Quote Contact Us

About the Palo Alto Networks PA-5220 Next-Generation Firewall

Intrusion Prevention System (IPS), application visibility, SSL/TLS inspection, and threat prevention capabilities form the core security architecture of the Palo Alto Networks PA-5220 Next-Generation Firewall. This 2U rack-mounted appliance delivers enterprise-grade threat defense with a threat prevention throughput of 22 Gbps and SSL/TLS decryption throughput of 15 Gbps, enabling organizations to inspect encrypted traffic without sacrificing performance. The PA-5220 processes up to 120,000 new sessions per second and maintains a maximum session capacity of 4,000,000, supporting large-scale deployments with robust state management.

Built for network engineers and IT infrastructure teams requiring high-performance security, the PA-5220 combines application-layer visibility with firewall throughput of 36 Gbps when App-ID is enabled. The appliance provides extensive connectivity through 4 × 10GBase-T (RJ-45) ports, 16 × SFP+ (10 GbE) ports, and 4 × QSFP+ (40 GbE) ports, alongside out-of-band management and console interfaces. With support for up to 65,000 security rules and virtual system scaling from 1 to 25 instances, the PA-5220 offers granular policy enforcement and multi-tenant isolation. IPsec VPN throughput reaches 22 Gbps, and redundancy options include both Active/Active and Active/Passive high availability modes backed by dual redundant, hot-swappable AC power supplies. Operating within a 0°C to 40°C temperature range, the PA-5220 is engineered for stable performance in diverse data center environments.

Enterprise Deployment Use Cases

  • Data center perimeter security with multi-gigabit threat inspection and encrypted traffic decryption
  • Branch consolidation and IPsec VPN aggregation supporting remote site connectivity at scale
  • Multi-tenant service provider environments leveraging virtual system segmentation (up to 25 instances)
  • High-volume transaction processing environments requiring sub-millisecond session establishment (120,000 sessions/second)
  • Compliance-driven deployments demanding detailed application visibility and SSL inspection across 65,000 policy rules

For detailed specifications, compatibility requirements, and licensing options for the PA-5220, contact Omnixon Global to request a quotation.

Technical Specifications

BrandPalo Alto Networks
CategoryNetwork Security
SKUPA-5220
Part NumberPA-5220
ConditionNew
Form Factor2U
ModelPA-5220
Form Factor2U rack-mounted appliance
Firewall Throughput (App-ID enabled)36 Gbps
Threat Prevention Throughput22 Gbps
IPsec VPN Throughput22 Gbps
New Sessions Per Second120,000
Max Sessions4,000,000
SSL/TLS Decryption Throughput15 Gbps
Max Security Rules65,000
Virtual Systems (base / max)1 / 25
10GBase-T (RJ-45) Ports4
SFP+ (10 GbE) Ports16
QSFP+ (40 GbE) Ports4
Management Ports1 x 10/100/1000 out-of-band management, 1 x RJ-45 console, 1 x Micro-USB console
High AvailabilityActive/Active and Active/Passive
Power SupplyDual redundant AC power supplies (hot-swappable)
StorageSSD (internal)
Rack Units2U
Operating Temperature0°C to 40°C (32°F to 104°F)

Frequently Asked Questions about Palo Alto Networks PA-5220 Next-Generation Firewall

What does the Palo Alto Networks PA-5220 Next-Generation Firewall do?

The Palo Alto Networks PA-5220 Next-Generation Firewall is enterprise networking hardware for data-center, campus, and branch deployments. Common roles include core/distribution switching, server uplinks, top-of-rack fabric, and edge connectivity in mixed Cisco/Juniper/Arista environments.

What are the headline specs of the Palo Alto Networks PA-5220 Next-Generation Firewall?

Key specifications for the Palo Alto Networks PA-5220 Next-Generation Firewall: new condition; brand Palo Alto Networks; series PA-5200 Series; model PA-5220; type ML-Powered NGFW; firewall throughput 18 Gbps; threat prevention throughput 9 Gbps. Manufacturer part number PA-5220. For the full datasheet with electrical, environmental, and compliance details, contact our pre-sales engineering team.

Is the Palo Alto Networks PA-5220 Next-Generation Firewall compatible with my infrastructure?

The Palo Alto Networks PA-5220 Next-Generation Firewall interoperates with standard switching protocols (LACP, MLAG/VPC, 802.1Q, OSPF/BGP). For specific cross-vendor scenarios — Cisco-to-Arista MLAG peering, fabric integration with Cumulus/SONiC, or migration from legacy Catalyst — our network engineers map a compatibility plan as part of the RFQ.