Consistent Architecture, High-Performance Versatility

The PA-5000 Series next-generation firewalls prevent threats, and safely enable applications, across a versatile set of high-performance use cases (e.g., Internet Gateway, DC, and SP environments). The series includes the PA-5060, PA-5050, and PA-5020, which are based on the same architectural foundation as all of our next-generation firewalls.

The PA-5000 Series enables you to secure your organization through advanced visibility and control of applications, users, and content at throughput speeds of up to 20 Gbps. Dedicated processing resources assigned to networking, security, signature matching, and management functions ensure predictable performance.


  • 20 Gbps firewall throughput (App-ID enabled1)
  • 10 Gbps threat prevention throughput
  • 4 Gbps IPSec VPN throughput
  • 4,000,000 max sessions
  • 120,000 new sessions per second
  • 8,000 IPSec VPN tunnels/tunnel interfaces
  • 20,000 SSL VPN Users
  • 225 virtual routers
  • 25/225 virtual systems (base/max2)
  • 900 security zones
  • 40,000 max number of policies


  • 10 Gbps firewall throughput (App-ID enabled1)
  • 5 Gbps threat prevention throughput
  • 4 Gbps IPSec VPN throughput
  • 2,000,000 max sessions
  • 120,000 new sessions per second
  • 4,000 IPSec VPN tunnels/tunnel interfaces
  • 10,000 SSL VPN Users
  • 125 virtual routers
  • 25/125 virtual systems (base/max2)
  • 500 security zones
  • 20,000 max number of policies


  • 5 Gbps firewall throughput (App-ID enabled1)
  • 2 Gbps threat prevention throughput
  • 2 Gbps IPSec VPN throughput
  • 1,000,000 max sessions
  • 120,000 new sessions per second
  • 2,000 IPSec VPN tunnels/tunnel interfaces
  • 5,000 SSL VPN Users
  • 20 virtual routers
  • 10/20 virtual systems (base/max2)
  • 80 security zones
  • 10,000 max number of policies


PA-5000 Series Specsheet

Key features, performance capacities and specifications for our PA-5000 Series.

  • 5
  • 58476

University of Arkansas

University cut through complexity to strengthen security while enabling open network access for unrestricted learning

  • 0
  • 481


At Bank OCBC NISP, Palo Alto Networks PA-5060 next-generation firewall prevents threats and safely enables applications over the bank’s internet gateways across two data centers. In addition, the WF-500 appliance provides WildFire™ threat analysis service as an on-premise, private cloud to analyze suspicious files in a sandbox environment without the need to send them outside the bank’s network.

  • 0
  • 444

Türk Elektrik Dağıtım Şirketi Ağ Güvenliğine Yeni Bir Enerji Sağlıyor

Turkish Deputy Energy Brings New Network Security

  • 1
  • 664

Next-Generation Security Platform

To enable organisations to securely roll out new services and apps, Palo Alto Networks built the Next-Generation Security Platform to provide prevention through automation, applied consistently across the network, endpoint and cloud.

  • 0
  • 52

Brigham Young University - Hawaii

Brigham-Young University chose Palo Alto Networks to redesign its IT security infrastructure on a zero trust model with a next-generation firewall as the linchpin.

Santa Clara, CA
  • 1
  • 939