Front of Palo Alto 1420

The ML-based next-generation firewalls in the PA-1400 series from Palo Alto Networks, consisting of the PA-1420 and PA-1410 models, have been specially developed to provide secure connectivity for branch offices and medium-sized businesses. These firewalls are based on PAN-OS, the same software that runs all Palo Alto Networks NGFWs, and are capable of natively classifying all traffic, including applications, threats and content, and linking this traffic to the user regardless of location or device type. By using applications, content and users as the basis for your security policies, which are the essential elements of your business, the PA-1400 series can help improve your security posture and reduce incident response time.

Highlights

• As the world's first ML-powered NGFW, this product has been named a leader in the Gartner Magic Quadrant for Network Firewalls eleven times and a leader in The Forrester Wave: Enterprise Firewalls, Q4 2022.
• It delivers predictable performance with security services and simplifies the deployment of large numbers of firewalls with optional Zero Touch Provisioning (ZTP).
• The NGFW's native web proxy support also simplifies and consolidates the management of firewall and proxy functions.
• In addition, the product supports centralised management with Panorama network security management and extends visibility and security to all devices, including unmanaged IoT devices, without the need to deploy additional sensors.
• With support for high availability in active/active and active/passive modes, this product maximises security investments and prevents business interruptions with AIOp.



Key security and connectivity features

• ML-powered next-generation firewall

• The core of the firewall integrates machine learning (ML) to enable signatureless inline attack prevention for file-based attacks, while quickly detecting and stopping previously unknown phishing attempts.
   o The PA-1400 series is capable of continuously identifying and categorising all applications, regardless of the port used, with full Layer 7 inspection. The firewall can identify applications moving through your network, regardless of the port used, protocol, evasion manoeuvres or encryption (TLS/SSL). In addition, with the SaaS security subscription, it can automatically detect and control new applications as they emerge to keep pace with the explosive growth of SaaS. This gives you complete visibility and control over the applications used on your network at all times.

• Enforces security for users at any location and on any device, while adapting policies to user activities This solution enables improved visibility, security policies, reporting, and forensics based on user and group identities rather than relying solely on IP addresses. In addition, it integrates seamlessly with various repositories such as Wi-Fi controllers, VPNs, directory servers, SIEMs, proxies and more to leverage user information.

• Prevents malicious activities hidden in encrypted traffic
   o The PA-1400 series is capable of inspecting and enforcing policies for both inbound and outbound TLS/SSL-encrypted traffic, including traffic using TLS 1.3 and HTTP/2. It provides detailed insights into TLS traffic, such as the amount of encrypted traffic, TLS/SSL versions, encryption suites and other relevant information, without the need for decryption. In addition, it enables control over the use of older TLS protocols, insecure ciphers and misconfigured certificates, helping to mitigate potential risks.

• Provides centralised management and visibility
    o Centralised management, configuration, and visibility for multiple Palo Alto Networks NGFWs (regardless of location or scale) can be achieved through Panorama network security management. This provides a unified user interface for all devices and enables simplified management and monitoring.

• Native web proxy support for next-generation firewalls
   o Palo Alto NG firewalls enable the consolidation of firewall and proxy functions on a single platform that can be managed via a centralised management platform to create and implement policies.

• Offers a unique approach to packet processing with single-pass architecture PA-1400 products use a stream-based, unified signature comparison approach that allows traffic to be scanned for all signatures in a single pass, avoiding potential latency issues.

• SD-WAN functionality

• Detects and prevents complex threats with cloud-based security services
   In today's digital landscape, cyber attacks are becoming increasingly sophisticated and can generate up to 45,000 variants in just 30 minutes, using multiple threat vectors and advanced techniques to deliver malicious payloads. Traditional isolated security measures can pose significant challenges for businesses, including security gaps, increased workload for security teams, and business productivity issues due to inconsistent access and visibility. Seamlessly integrated with our industry-leading NGFWs, our cloud-based security services leverage the network effect of over 80,000 customers to coordinate intelligence and provide comprehensive protection against all threats across all vectors. This eliminates gaps in coverage at your locations and provides you with best-in-class security that is consistently delivered on a single platform and protects against even the most advanced and difficult-to-detect threats.
   o Advanced threat defence: Our security solution effectively stops known exploits, malware, spyware and command-and-control threats (C2). In addition, we use prevention methods that are unique in the industry to ward off zero-day attacks. This prevents up to 60% more unknown injection attacks and 48% more hard-to-detect command-and-control traffic than traditional IPS solutions.
   o Advanced WildFire: Palo Alto has automatic protection that ensures files are protected from known, unknown and hard-to-detect malware. With the industry's largest threat intelligence and malware prevention engine, we can defend against such threats 60 times faster.
   o Advanced URL filtering Our security solution guarantees secure access to the internet and offers real-time protection against known and unknown threats, preventing 40% more web-based attacks. Thanks to our industry-unique real-time prevention capabilities, we can stop 88% of malicious URLs at least 48 hours before other vendors, providing outstanding protection against Internet-based threats.
   o DNS security: Increase your protection against DNS attacks by 40% and prevent 80% of attacks that exploit DNS for data theft and command-and-control without making any changes to your existing infrastructure.
   o Enterprise DLP: Reduce the likelihood of data breaches, prevent unauthorised data transfers, and ensure compliance across your entire organisation with twice the coverage of any other cloud-based enterprise DLP solution.
   o SaaS Security: Keep pace with the rapidly growing SaaS landscape with our next-generation CASB, the industry's only solution that can automatically discover and secure all applications across any protocol.
   o IoT security: Protect all your connected devices and implement zero-trust security for your devices 20 times faster with the industry's most intelligent security solution designed specifically for smart devices.




PA-1400 Series Performance and Capacity:

PA-1410 PA-1420
Firewall throughput (HTTP/Appmix) * 8.9/6.8 Gbps 9.9/9.5 Gbps
Threat prevention throughput (HTTP/Appmix) † 3.3/3.2 Gbps 5.0/4.8 Gbit/s
IPsec VPN throughput ‡ 4.6 Gbit/s 6.5 Gbit/s
Maximum number of sessions 945,000 1,400,000
New sessions per second § 100,000 140,000
Virtual systems (base/max) ∥ 1/6 1/6

Note: Results were measured on PAN-OS 11.0.
* Firewall throughput is measured with App-ID and logging enabled using 64 KB HTTP/Appmix transactions.
† Threat prevention throughput is measured with App-ID, IPS, antivirus, antispyware, WildFire, DNS security, file blocking, and logging enabled using 64 KB HTTP/Appmix transactions. ‡ IPsec VPN throughput is measured with 64 KB HTTP transactions and logging enabled.
§ New sessions per second were measured with application override using 1-byte HTTP transactions.
∥ Adding virtual systems beyond the base set requires a separately purchased licence and at least PAN-OS 11.0.



PA-1400 Series Network Features

Interface Modes
label.paloAlto400.overview. IPv6.1=L2, L3, Tap, Virtual Wire (transparent mode)
Routing
OSPFv2/v3 with soft restart, BGP with soft restart, RIP, static routing
Policy-based forwarding
Point-to-point protocol over Ethernet (PPPoE)
Multicast: PIM-SM, PIM-SSM, IGMP v1, v2 and v3
SD-WAN
Path quality measurement (jitter, packet loss, latency)
Initial path selection (PBF)
Dynamic Path Change
IPv6
L2, L3, Tap, Virtual Wire (transparent mode)
Features: App ID, User ID, Content ID, WildFire and SSL decryption
SLAAC
IPsec VPN
Key exchange: manual key, IKEv1 and IKEv2 (pre-shared key, certificate-based authentication)
Encryption: 3DES, AES (128-bit, 192-bit, 256-bit)
Authentication: MD5, SHA-1, SHA-256, SHA-384, SHA-512
VLANs
802.1Q VLAN tags per device/per interface: 4,094/4,094
Aggregated interfaces (802.3ad), LACP
Network address translation
NAT modes (IPv4): static IP, dynamic IP, dynamic IP and port (port address translation)
NAT64, NPTv6
Additional NAT features: dynamic IP reservation, adjustable dynamic IP and port over-allocation
High Availability
Modes: active/active, active/passive, HA clustering
Fault detection: path monitoring, interface monitoring
Zero Touch Provisioning (ZTP)
Requires Panorama 9.1.3 or higher, which manages the PA-1400 series with PAN-OS 11.0 or higher
back
Update cookies preferences TermsFeed All-in-one compliance software: Generate Privacy Policy, Terms & Conditions, Cookie Consent Notice Banner, EULA, Disclaimer and more.