PA-5250: PA-5250 is the intermediate PA-5200 capacity tier between PA-5220 and the PA-5260/PA-5280 models. Official values are thirty-five-point-nine-gigabit App-ID firewall throughput
PA-5250 is the intermediate PA-5200 capacity tier between PA-5220 and the PA-5260/PA-5280 models. Official values are thirty-five-point-nine-gigabit App-ID firewall throughput, twenty-point-three-gigabit threat prevention, fourteen-gigabit IPsec VPN throughput and eight-million sessions.
| Datasheet series | Palo Alto PA-5200 Series Firewalls |
| Exact model | PAN-PA-5250FIREWALL |
| Security check | Confirm PAN-OS compatibility, subscriptions, support term, HA design and interface requirements |
| Official datasheet | Palo Alto PA-5200 Series official hardware reference |
Model | PA-5250 |
Performance and Capacities Specifications | |
Firewall throughput (App-ID enabled) | 35.9 Gbps |
Threat prevention throughput | 20.3 Gbps |
IPsec VPN throughput | 14 Gbps |
Max sessions | 8,000,000 |
New sessions per second | 348,000 |
Virtual systems (base/max) | 25/125 |
Networking Features | |
Interface Modes | L2, L3, Tap, Virtual wire (transparent mode) Point-to-point protocol over Ethernet (PPPoE) and DHCP supported for dynamic address assignment |
Routing | OSPFv2/v3 with graceful restart, BGP with graceful restart, RIP, Static routing Policy-based forwarding Multicast: PIM-SM, PIM-SSM, IGMP v1, v2, and v3 Bidirectional Forwarding Detection (BFD) |
IPv6 | L2, L3, Tap, Virtual Wire (transparent mode) Features: App-ID, User-ID, Content-ID, WildFire, and SSL decryption SLAAC |
IPsec VPN | Key exchange: Manual key, IKE v1 and IKEv2 (pre-shared key, certificate-based authentication) Encryption: 3DES, AES (128-bit, 192-bit, 256-bit) Authentication: MD5, SHA-1, SHA-256, SHA-384, SHA-512 GlobalProtect large-scale VPN (LSVPN) for simplified configuration and management |
VLANs | 802.1q VLAN tags per device/per interface: 4,094/4,094 Aggregate interfaces (802.3ad), LACP |
Network Address Translation (NAT) | NAT modes (IPv4): static IP, dynamic IP, dynamic IP and port (port address translation) NAT64, NPTv6 Additional NAT features: Dynamic IP reservation, tun- able dynamic IP and port oversubscription |
High Availability | Modes: Active/Active, Active/Passive Failure detection: Path monitoring, interface monitoring |
Hardware Specifications | |
I/O | (4) 100/1000/10G Cu, (16) Gig/10Gig SFP/SFP+, (4) 40G/100G QSFP28 |
Management I/O | (2) 10/100/1000, (1) 40G/100G QSFP28 HA, (1) 10/100/1000 out-of-band management, (1) RJ45 console port |
Storage Options | Dual Solid State Disk Drives |
Storage Capacity | 240GB SSD, RAID1, System Storage 2TB HDD, RAID1, Log Storage |
Power (Max Power Consumption) | 870 Watts |
Max BTU/hr | 2,970 |
Power Supplies (base/max) | 1:1 Fully Redundant (2/2) |
AC Input Voltage (input Hz) | 100-240VAC (50-60Hz) |
AC Power Supply Output | 1200 Watt/power supply |
Dimensions | 5.25”H X 20.5”D X 17.25”W |
Safety | cCSAus, CB IEC60950-1 |
EMI | FCC Class A, CE Class A, VCCI Class A |
Environment | |
Operating temperature | 32°F to 122°F (0° to 50°C) |
Non-operating temperature | -20° to 70°C (-4°F to 158°F) |
Low Price Guarantee | ![]() | Quality Assurance | |
100% Money Back Guarantee | Commodity Refund Guarantee | ||
Diversified and Flexible Transportation Services | ![]() | Standard Policy |
For PA-5250, the manufacturer specification lists firewall throughput (app-id enabled) as 35.9 Gbps.
For PA-5250, the manufacturer specification lists threat prevention throughput as 20.3 Gbps.
For PA-5250, the manufacturer specification lists ipsec vpn throughput as 14 Gbps.
Related products

PA-5220 is the entry capacity model in this PA-5200 comparison. It is specified for eighteen-point-five-gigabit App-ID firewall throughput, nine-point-two-gigabit threat prevention, five-gigabit IPsec VPN throughput and four-million sessions. The shared redundant power and storage layout does not imply the performance of the higher PA-5200 models.

PA-5260 has the highest listed App-ID firewall throughput in this PA-5200 comparison at seventy-two-point-two gigabits. It supports thirty-two-million sessions, thirty-gigabit threat prevention and twenty-one-gigabit IPsec VPN throughput. PA-5280 favors greater session scale, while PA-5250 and PA-5220 are lower-capacity tiers.

PA-5280 combines the largest session scale in this PA-5200 group with sixty-eight-gigabit App-ID firewall throughput. It supports sixty-four-million sessions, thirty-gigabit threat prevention and twenty-four-gigabit IPsec VPN throughput. PA-5260 has slightly higher firewall throughput but half the session ceiling.

PAN-PA-7080 Palo Alto security firewall appliance for security refresh projects. Contact YYST Global for stock, lead time and quote support.

PAN-PA-7050 Palo Alto security firewall appliance for security refresh projects. Contact YYST Global for stock, lead time and quote support.

PAN-PA-3060 Palo Alto security firewall appliance for security refresh projects. Contact YYST Global for stock, lead time and quote support.

PA-3250 has the following distinguishing entries in the manufacturer specification. Performance and Capacities Specifications Firewall throughput: six.three Gbps. Threat Prevention throughput: three Gbps. IPSec VPN throughput: three.two Gbps. Max sessions: two,zero,zero. New sessions per second: ninety-four,zero.

PA-220R Palo Alto security firewall appliance for security refresh projects. Contact YYST Global for stock, lead time and quote support.