Product Description
Palo Alto Networks PA-220 Firewall
The Palo Alto Networks PA-220 is a compact next-generation firewall designed to protect small organizations and branch offices. It combines application visibility, user identification, content inspection and advanced threat prevention in a small desktop form factor.
Palo Alto Networks designed the PA-220 with eight Ethernet ports, passive cooling and dual power-adapter support for power redundancy. It also supports both active/passive and active/active high-availability deployments.
Next-Generation Security
Unlike a traditional stateful firewall, the PA-220 uses Palo Alto Networks’ security architecture to provide visibility and control over applications, users and content.
The platform supports technologies including App-ID, User-ID, Content-ID, WildFire and SSL decryption, depending on software version and applicable subscriptions.
Therefore, the PA-220 can provide more detailed application-level security than a basic network firewall.
Firewall Performance
Palo Alto Networks’ published PA-220 specifications list 550/560 Mbps firewall throughput, depending on the test methodology. Threat Prevention throughput is listed at 270/300 Mbps, while IPsec VPN throughput is 570 Mbps.
These are published performance measurements rather than guaranteed real-world speeds. Actual throughput can vary depending on traffic patterns, security profiles, PAN-OS version and enabled features.
Key Features
- Model: Palo Alto Networks PA-220
- Next-generation firewall architecture
- 8 × 10/100/1000 Ethernet ports
- Application visibility with App-ID
- User-based security policies with User-ID
- Content inspection with Content-ID
- WildFire integration
- SSL decryption support
- SD-WAN capabilities
- IPsec VPN
- Active/Active HA
- Active/Passive HA
- Passive cooling
- Dual power-adapter support
- Compact desktop form factor
- Up to 560 Mbps firewall throughput
- Up to 300 Mbps Threat Prevention throughput
- Up to 570 Mbps IPsec VPN throughput
- Up to 64,000 maximum sessions
- Up to 4,200 new sessions per second
8 Gigabit Ethernet Ports
The PA-220 includes eight 10/100/1000 Ethernet interfaces, providing flexible connectivity for WAN, LAN, DMZ and other network segments.
Because all eight interfaces support Gigabit Ethernet, the appliance can be integrated into standard business networks without requiring separate interface expansion.
Compact and Silent Design
The PA-220 uses passive cooling, so it does not contain fans. As a result, it operates without fan noise and can be suitable for office and branch environments where quiet operation is desirable. Palo Alto Networks lists a maximum power consumption of 25W and average power consumption of 21W.
The firewall can also be installed on a flat surface or mounted in a 19-inch equipment rack using the appropriate rack accessories.
High Availability
The PA-220 supports both active/passive and active/active high availability. It also supports dual power adapters, allowing a second adapter to be installed for power redundancy.
Consequently, businesses can use the PA-220 in redundant firewall architectures where availability is important.
VPN and SD-WAN
The PA-220 supports IPsec VPN and SD-WAN functionality. Palo Alto Networks publishes 570 Mbps IPsec VPN throughput for the PA-220.
Furthermore, Palo Alto Networks documentation identifies SD-WAN capabilities including path-quality measurement, initial path selection and dynamic path changes.
Ideal Applications
The Palo Alto Networks PA-220 can be suitable for:
- Small businesses
- Branch offices
- Remote offices
- Retail locations
- Professional offices
- Small enterprise networks
- Secure internet gateways
- Network segmentation
- IPsec VPN deployments
- SD-WAN deployments
- Palo Alto replacement hardware
- Legacy PA-220 replacement requirements






Reviews
There are no reviews yet.