Skip to content


Product Line: Palo alto PA-4000 Series
Product Type: firewall
Sold out
Original price $0.00 - Original price $0.00
Original price
$0.00 - $0.00
Current price $0.00
Title: Surplus

Orders typically ship within 1-3 Business days, if you need an item to ship sooner please contact us.

Product Description

The PA-4020 Palo Alto is equipped with a firewall throughput of 2 Gbps and threat prevention throughput of 2 Gbps, ensuring efficient data processing and security threat management. It supports up to 2,000 IPSec VPN tunnels/interfaces and 5,000 SSL VPN concurrent users, accommodating a high number of secure connections. The device features (16) 10/100/1000 + (8) Gigabit SFP I/O ports, redundant 400W AC power supply, and operates within a temperature range of 32° to 122° F, making it suitable for a variety of network environments.

FAQs for the PA-4020

  • What is the firewall throughput capability?
    The firewall throughput capability is 2 Gbps.
  • How many IPSec VPN tunnels/interfaces does the device support?
    The device supports 2,000 IPSec VPN tunnels/interfaces.
  • What throughput can be expected for threat prevention?
    Threat prevention throughput is also 2 Gbps.
  • Can you detail the SSL VPN user support?
    The system can support up to 5,000 concurrent SSL VPN users.
  • What is the maximum number of new sessions per second?
    The maximum number of new sessions per second is 60,000.
  • What are the specifications for I/O ports?
    The device includes (16) 10/100/1000 and (8) Gigabit SFP I/O ports.
  • What power supply specifications does the device have?
    It has redundant 400W AC power supplies, with average/max power consumption of 175W/200W.
  • What are the rack mount dimensions?
    The device is rack mountable in a 2U space, with dimensions of 3.5”H x 16.5”D x 17.5”W.
  • What operating temperatures is the device designed to handle?
    The operating temperature range is from 32° to 122° F (0° to 50° C).
  • Does the device offer high availability features?
    Yes, it offers high availability features including active/passive modes, configuration and session synchronization, as well as interface and IP tracking.

Product Review

The Palo Alto PA-4020 offers a firewall and threat prevention throughput of 2 Gbps, alongside IPSec VPN throughput of 1 Gbps, which supports high-speed data transmission and secure remote access efficiently. However, its limitation to 2,000 IPSec VPN tunnels/interfaces and a maximum of 500,000 sessions may not meet the needs of larger organizations with extensive networking requirements. Additionally, the device boasts a comprehensive range of I/O options, including 16 10/100/1000 Ethernet ports and 8 Gigabit SFP ports, providing flexible connectivity options, but requires a subscription for URL Filtering, adding to the total cost of ownership.


The Palo Alto PA-4020 is designed to meet the demands of modern network environments, offering comprehensive security features alongside high-performance hardware specifications. This firewall is engineered to provide both high-speed connectivity and robust security measures to protect against a wide range of threats. The PA-4020 delivers a firewall throughput of 2 Gbps and an equal threat prevention throughput, ensuring that security measures do not compromise network performance. For secure remote access, it offers an IPSec VPN throughput of 1 Gbps. The device supports up to 2,000 IPSec VPN tunnels/interfaces, accommodating large-scale deployments and remote workforces. Additionally, it can handle up to 5,000 SSL VPN concurrent users, making it suitable for organizations with extensive remote access needs. This model is capable of initiating up to 60,000 new sessions per second, and it can manage a maximum of 500,000 sessions concurrently. This capacity ensures the device can handle heavy traffic and maintain performance under load. Regarding connectivity, the PA-4020 is equipped with an array of I/O ports, including: - Sixteen 10/100/1000 Ethernet ports plus eight Gigabit SFP ports for high-speed network connections. - Two 10/100/1000 high availability ports, one 10/100/1000 out-of-band management port, and one DB9 console port for management purposes. The device features redundant 400W AC power supplies, with an average power consumption of 175W and a maximum of 200W. It operates within a voltage range of 100-240Vac and supports input frequencies of 50-60Hz. The maximum input current is 50A@230Vac and 30A@120Vac, ensuring stable operation under various power conditions. The PA-4020's form factor is a 2U, 19” standard rack, with dimensions of 3.5”H x 16.5”D x 17.5”W, making it suitable for installation in standard data center racks. It operates within a temperature range of 32° to 122° F (0° to 50° C) and has a non-operating temperature tolerance between -4° to 158° F (-20° to 70° C), ensuring reliability in diverse environments. Key features include high availability configurations such as active/passive modes, configuration and session synchronization, interface and IP tracking, and link and path failure monitoring. These features ensure continuous operation and minimal downtime. The PA-4020 also offers advanced security features such as: - URL Filtering, which requires a subscription and includes a 76-category customizable database. - IPSec transport with SSL fallback and unique policy enforcement for SSL VPN traffic. - The ability to enable or disable split tunneling to control client access. - Full IPv6 content inspection via Content-ID in virtual wire mode. - DHCP server and DHCP relay support for up to 3 servers, facilitating network management and integration. Overall, the Palo Alto PA-4020 is a comprehensive solution for organizations looking to bolster their network security without sacrificing performance. Its wide range of features and high capacity make it a versatile choice for any enterprise environment.


Part Number and Manufacturer Palo Alto PA-4020
Data Throughput Capacity 2 Gbps
Threat Detection and Prevention Rate 2 Gbps
VPN Throughput Using IPSec 1 Gbps
IPSec VPN Capacity 2,000 Tunnels/Interfaces
SSL VPN Maximum Concurrent Users 5,000 Users
Session Initiation Rate 60,000 Sessions/Second
Maximum Concurrent Sessions 500,000 Sessions
Network Interfaces (16) 10/100/1000 Ethernet + (8) Gigabit SFP Ports
Management Network Ports (2) 10/100/1000 for HA, (1) 10/100/1000 OOBM, (1) DB9 Serial Port
Power Supply Specification Redundant 400W AC (175W/200W Consumption)
Electrical Input Requirements 100-240Vac (50-60Hz)
Maximum Current at 230Vac 50A
Maximum Current at 120Vac 30A
Physical Rack Compatibility 2U Standard 19” Rack (3.5”H x 16.5”D x 17.5”W)
Operational Temperature Range 32° to 122° F (0° to 50° C)
Storage Temperature Range -4° to 158° F (-20° to 70° C)
Availability Features Active/Passive with Configuration and Session Synchronization, Interface/IP Monitoring, Link/Path Failure Detection
Web Filtering Requires Subscription, 76-category Customizable On-device Database
VPN Protocol Support IPSec with SSL Backup
SSL VPN Policy Management Enables SSL VPN Traffic Specific Policies, Toggle Split Tunneling
IPv6 Inspection Content-ID Full Inspection in Virtual Wire Mode
DHCP Services Supports Server/Relay Functions for up to 3 Servers

Compare products

{"one"=>"Select 2 or 3 items to compare", "other"=>"{{ count }} of 3 items selected"}

Select first item to compare

Select second item to compare

Select third item to compare