Redefining high-performance network security, the PA-7000 Series of next-generation firewall appliances offers the perfect blend of power, intelligence and simplicity. Power, derived from a proven architecture, blends ultra-efficient software with nearly 700 function-specific processors for networking, security, content inspection and management. Its intelligence maximizes security-processing resource utilization and automatically scales as new computing power becomes available. The PA-7000 Series offers simplicity defined by a single-system approach to management and licensing.
Key Security Features:
- Classifies all applications, on all ports, all the time
- Identifies the application, regardless of port, encryption (SSL or SSH), or evasive technique employed.
- Uses the application, not the port, as the basis for all of your safe enablement policy decisions: allow, deny, schedule, inspect and apply traffic-shaping.
- Categorizes unidentified applications for policy control, threat forensics or App-ID™ development. Enforces security policies for any user, at any location
- Deploys consistent policies to local and remote users running on the Windows®, MacOS™, Linux®, Android®, or Apple® iOS platforms.
- Enables agentless integration with Microsoft® Active Directory® and Terminal Services, LDAP, Novell® eDirectory™ and Citrix®.
- Easily integrates your firewall policies with 802.1X wireless, proxies, NAC solutions, and any other source of user identity information. Prevents known and unknown threats
- Blocks a range of known threats, including exploits, malware and spyware, across all ports, regardless of common threat-evasion tactics employed.
- Limits the unauthorized transfer of files and sensitive data, and safely enables non-work-related web surfing.
- Identifies unknown malware, analyzes it based on hundreds of malicious behaviors, and then automatically creates and delivers protection.
- Threat prevention throughput is measured with App-ID, User-ID, IPS, antivirus, anti-spyware and Disable Server Response Inspection(DSRI) features enabled
- Throughput is measured with 64Kb HTTP transactions
- Connections per second is measured with 4Kb HTTP transactions
PaloAlto PA-7080 - Subscriptions
The following Palo Alto Networks subscriptions unlock certain firewall features or enable the firewall to
leverage a Palo Alto Networks cloud-delivered service (or both). Here you can read more about each service
or feature that requires a subscription to work with the firewall. To enable a subscription, you must first
Activate Subscription Licenses; once active, most subscription services can use Dynamic Content Updates
to provide new and updated functionality to the firewall.
|Subscriptions You Can Use With the Firewall|
|Threat Prevention||Threat Prevention provides:
• Antivirus, anti-spyware (command-and-control), and vulnerability
• Built-in external dynamic lists that you can use to secure your
network against malicious hosts.
• Ability to identify infected hosts that try to connect to malicious
• Get Started with Threat Prevention
|DNS Security||Provides enhanced DNS sinkholing capabilities by querying DNS
Security, an extensible cloud-based service capable of generating
DNS signatures using advanced predictive analytics and machine
learning. This service provides full access to the continuously
expanding DNS-based threat intelligence produced by Palo Alto
To set up DNS Security, you must first purchase and install a Threat
• Get Started with DNS Security
|URL Filtering||Provides the ability to not only control web-access, but how users
interact with online content based on dynamic URL categories. You
can also prevent credential theft by controlling the sites to which
users can submit their corporate credentials.
To set up URL Filtering, you must purchase and install a subscription
for one of the supported URL filtering databases: PAN-DB or
BrightCloud. With PAN-DB, you can set up access to the PAN-DB
public cloud or to the PAN-DB private cloud.
• Get Started with URL Filtering
|WildFire||Although basic WildFire® support is included as part of the Threat
Prevention license, the WildFire subscription service provides
enhanced services for organizations that require immediate coverage
for threats, frequent WildFire signature updates, advanced file
type forwarding (APK, PDF, Microsoft Office, and Java Applet), as
well as the ability to upload files using the WildFire API. A WildFire
subscription is also required if your firewalls will be forwarding files
to an on-premise WF-500 appliance.
• Get Started with WildFire
|AutoFocus||Provides a graphical analysis of firewall traffic logs and identifies
potential risks to your network using threat intelligence from the
AutoFocus portal. With an active license, you can also open an
AutoFocus search based on logs recorded on the firewall.
• Get Started with AutoFocus
|Cortex Data Lake
and firewall web
Service in some
in the firewall
|Provides cloud-based, centralized log storage and aggregation. The
Logging Service is required or highly-recommended to support
several other cloud-delivered services, including Magnifier,
GlobalProtect cloud service, and Traps management service.
• Get Started with Cortex Data Lake
|GlobalProtect||Provides mobility solutions and/or large-scale VPN capabilities.
By default, you can deploy GlobalProtect portals and gateways
(without HIP checks) without a license. If you want to use advanced
GlobalProtect features (HIP checks and related content updates,
the GlobalProtect Mobile App, IPv6 connections, or a GlobalProtect
Clientless VPN) you will need a GlobalProtect license (subscription)
for each gateway.
• Get Started with GlobalProtect
|Virtual Systems||This license is required to enable support for multiple virtual systems
on PA-3200 Series firewalls. In addition, you must purchase a
Virtual Systems license if you want to increase the number of virtual
systems beyond the base number provided by default on PA-5200
Series, and PA-7000 Series firewalls (the base number varies by
platform). The PA-800 Series, PA-220, and VM-Series firewalls do
not support virtual systems.
• Get Started with Virtual Systems
PaloAlto PA-7080 - Specs
Firewall throughput630/720 Gbps
Threat Protection Throughput610 Gbps (DSRI enabled), 294/350 Gbps (HTTP/appmix)
IPSec VPN throughput240 Gbps
NPC-100G (PA-7000-100G-NPC-A)(80) SFP/SFP+ (40) QSFP+/QSFP28
NPC-20G XM Option 11: (PA-7000-20GQXM-NPC)(20) QSFP+, (120) SFP+
NPC-20G XM Option 21: (PA-7000-20GXM-NPC)(120) 10/100/1000, (80) SFP, (40) SFP+
I/O ports(2) 10/100/1000, (2) QSFP+ high availability, (1) 10/100/1000 out-of-band management, (1) RJ45 console port
Storage(1) 80 GB SSD System Drive, (4) 1 TB default or (4) 2 TB optional HDD on Log Processing Card, RAID
Dimensions & Enviroment
Mounting19U, 19” standard rack (32.22” H x 19” W x 24.66” D)
Dimensions Width x Depth x Height (inches)32.22”H x 19”W x 24.66”D
Weight299.3 lbs. AC / 298.3 lbs. DC (stand-alone device/as shipped)
Power supply75ADC @ >40VDC In
AC input voltage90–305VAC (47–66 Hz)
DC input voltage-36 to -75VDC
DC power output2500 W / power supply
SafetycTUVus, cCSAus, CB
Maximum Current12ADC @ 240VAC In
Power Supplies (Base/Max)4/8
AC Power Supply Output2500 W @ 240VAC | 1200 W @ 120VAC
Mean Time Between Failure (MTBF)Configuration dependent; contact your Palo Alto Networks representative for MTBF details.
EMIFCC Class A, CE Class A, VCCI Class A
Max Inrush Current30AAC / 100ADC peak
CertificationsNEBS Level 3