background image

©

 

Palo

 

Alto

 

Networks,

 

Inc.

PA

5200

 

Next

Gen

 

Firewall

 

Hardware

 

Reference

 

 

11

PA

5200

 

Series

 

Firewall

 

Overview

Front

 

Panel

 

Description

4

HSCI

 

port

These

 

ports

 

vary

 

depending

 

on

 

your

 

firewall

 

model:

 

PA

5220

 

firewall

—One

 

QSFP+

 

40Gbps

 

port

 

(supports

 

only

 

a

 

40Gbps

 

(QSFP+)

 

transceiver

 

or

 

QSFP+

 

active

 

optical

 

cable).

 

PA

5250

 

and

 

PA

5260

 

firewalls

—One

 

QSFP28

 

40/100Gbps

 

port

 

(supports

 

40Gbps

 

(QSFP+)

 

or

 

100Gbps

 

transceiver

 

(QSFP28)

 

or

 

equivalent

 

active

 

optical

 

cables).

 

The

 

link

 

speed

 

is

 

based

 

on

 

the

 

installed

 

transceiver.

 

Use

 

this

 

port

 

to

 

connect

 

two

 

PA

5200

 

Series

 

firewalls

 

in

 

a

 

high

 

availability

 

(HA)

 

configuration

 

as

 

follows:

 

 

In

 

an

 

active/passive

 

configuration,

 

this

 

port

 

is

 

for

 

HA2

 

(data

 

link).

 

 

In

 

an

 

active/active

 

configuration,

 

you

 

can

 

configure

 

this

 

port

 

for

 

HA2

 

and/or

 

HA3.

 

HA3

 

is

 

used

 

for

 

packet

 

forwarding

 

for

 

asymmetrically

 

routed

 

sessions

 

that

 

require

 

Layer

 

7

 

inspection

 

for

 

App

ID™

 

and

 

Content

ID™.

The

 

HSCI

 

ports

 

must

 

be

 

connected

 

directly

 

between

 

the

 

two

 

firewalls

 

in

 

the

 

HA

 

configuration

 

(not

 

between

 

a

 

network

 

switch

 

or

 

router).

 

When

 

directly

 

connecting

 

the

 

HSCI

 

ports

 

between

 

two

 

PA

5220

 

firewalls

 

that

 

are

 

physically

 

located

 

near

 

each

 

other,

 

Palo

 

Alto

 

Networks

 

recommends

 

that

 

you

 

use

 

a

 

40Gbps

 

QSFP+

 

Active

 

Optical

 

Cable

 

(AOC).

 

When

 

directly

 

connecting

 

two

 

PA

5250

 

or

 

two

 

PA

5260

 

firewalls,

 

use

 

either

 

a

 

40Gbps

 

QSFP+

 

Active

 

Optical

 

Cable

 

(AOC)

 

or

 

a

 

100Gbps

 

QSFP28

 

Active

 

Optical

 

Cable

 

(AOC).

 

For

 

installations

 

where

 

the

 

two

 

firewalls

 

are

 

not

 

near

 

each

 

other

 

and

 

you

 

cannot

 

use

 

an

 

AOC

 

cable,

 

use

 

a

 

standard

 

40Gbps

 

or

 

100Gbps

 

transceivers

 

and

 

the

 

appropriate

 

cable

 

length.

5

AUX

 

1

 

and

 

AUX

 

2

 

ports

Use

 

these

 

SFP+

 

ports

 

for

 

HA1,

 

management

 

functions,

 

or

 

log

 

forwarding

 

to

 

Panorama.
For

 

information

 

on

 

configuring

 

the

 

port,

 

refer

 

to

 

the

 

on

device

 

Help

 

content

 

in

 

Device > Setup > Interfaces

 

or

 

refer

 

to

 

the

 

PAN

OS

 

8.0

 

Web

 

Interface

 

Reference

.

6

HA1

A

 

and

 

HA1

B

Two

 

RJ

45

 

10/100/1000Mbps

 

ports

 

for

 

high

availability

 

control

 

(HA1).

Item Component

 

(Continued)

Description

Copyright © 2007-2017 Palo Alto Networks

Содержание PA-5200 Series

Страница 1: ...PA 5200 Series Next Gen Firewall Hardware Reference PA 5200 Series Firewall Overview ...

Страница 2: ...tonetworks com resources datasheets html For access to the knowledge base discussion forums and videos refer to https live paloaltonetworks com For information on support programs refer to https www paloaltonetworks com services support and for information on how to manage your account or devices or to open a support case refer to https www paloaltonetworks com company contact support For the most...

Страница 3: ...nd throughput levels to help you meet your deployment requirements All models in this series provide next generation security features to help you secure your organization through advanced visibility and control of applications users and content First Supported Software Release PAN OS 8 0 The following topics describe the hardware features of the PA 5200 Series firewalls To view or compare perform...

Страница 4: ... 1 Ethernet ports 1 through 4 Four RJ 45 100Mbps 1Gbps 10Gbps ports for network traffic The link speed and link duplex are auto negotiate only 2 SFP ports 5 through 20 Sixteen SFP SFP ports for network traffic Each port can operate as either SFP 1Gbps or SFP 10Gbps based on the installed transceiver 3 QSFP ports 21 through 24 These ports vary depending on your firewall model PA 5220 firewall Four ...

Страница 5: ...he HSCI ports must be connected directly between the two firewalls in the HA configuration not between a network switch or router When directly connecting the HSCI ports between two PA 5220 firewalls that are physically located near each other Palo Alto Networks recommends that you use a 40Gbps QSFP Active Optical Cable AOC When directly connecting two PA 5250 or two PA 5260 firewalls use either a...

Страница 6: ...p bits 1 Flow control None 8 USB port Use this port to bootstrap the firewall Bootstrapping enables you to provision the firewall with a specific PAN OS configuration and then license it and make it operational on your network 9 MGT port Use this Ethernet 10 100 1000Mbps port to access the management web interface and perform administrative tasks The firewall also uses this port for management ser...

Страница 7: ...e used to store the PAN OS system files and system logs 2 LOG 1 and LOG 2 drives Two hot swappable 2TB hard disk drives HDDs in a RAID 1 pair 2TBs total The drives are used to store network traffic logs 3 Exhaust fans trays Two fan trays that provide ventilation and cooling for the firewall Each fan tray contains four fans and a status LED While facing the back of the firewall fan tray 1 is on the...

Страница 8: ...14 PA 5200 Next Gen Firewall Hardware Reference Palo Alto Networks Inc Back Panel Description PA 5200 Series Firewall Overview Copyright 2007 2017 Palo Alto Networks ...

Отзывы: