Marketing Information: Palo Alto Networks PA-500 Series Next-Generation Firewalls (NGFWs) comprise the PA-505, PA-510, PA520, PA-540, PA-545-POE, PA-550, PA-555-POE, and PA-560 models. This series brings ML-Powered NGFW capabilities to distributed enterprise branch offices, retail locations, and midsize businesses.
The controlling element of the PA-500 Series NGFWs is PAN-OS®, the same software that runs all Palo Alto Networks NGFWs. PAN-OS natively classifies all traffic, including applications, threats, and content, and then ties that traffic to the user regardless of location or device type. The application, content, and user-the elements that run your business-serve as the basis of your security policies, resulting in an improved security posture and reduced incident response time. PAN-OS embeds machine learning (ML) in the core of the firewall to provide inline signatureless attack prevention for filebased attacks while identifying and immediately stopping never-before-seen phishing attempts.
Post-Quantum Cryptography Optimizations
The PA-500 Series is a post-quantum cryptography (PQC)-ready NGFW that helps you achieve quantum-safe security in hardware and software with PAN-OS 12.1. PA-500 Series NGFWs support:
- PQC for PQC SSL/TLS decryption, PQC VPN site-to-site, PQC SSL/TLS Cipher Translation Proxy, and PQC SSL/TLS Service Profile for Management Access to the firewall.
- PQC algorithms, including NIST standards, like ML-KEM, ML-DSA, and SLH-DSA, as well as experimental PQCs, like Classic McEliece, BIKE, HQC, Frodo-KEM, and NTRU-Prime.
Prevention of Malicious Activity Concealed in Encrypted Traffic
PA-500 Series NGFWs provide the ability to:
- Inspect and apply policies to SSL/TLS-encrypted traffic (both inbound and outbound), traffic that uses SSLv3, TLSv1.1, TLSv1.2, and TLSv1.3, as well as application protocols SMTP, WebSocket, gRPC, HTTP/1.0, HTTP/1.1, and HTTP/2.
- Decrypt and inspect SSL/TLS sessions with the classical key exchange algorithms RSA, ECDHE, DHE, and post-quantum key exchange standards ML-KEM, HQC, as well as experimental BIKE and Frodo-KEM.
- Let you enable or disable decryption flexibly-based on URL category, source and destination zone, address, user, user group, device, and port-for privacy and regulatory compliance purposes.
Application Identification and Categorization with Full Layer 7 Inspection
App-ID™ identifies and categorizes all applications, on all ports, all the time, with full Layer 7 inspection, supporting the following capabilities:
- Uses advanced techniques, such as protocol decoding, heuristics, and signature matching, to accurately identify applications across the network, regardless of the port, protocol, or encryption methods used. The optional App-ID Cloud Engine (ACE) service provides on-demand App-IDs for SaaS applications.
- Allows for the effective enforcement of security policies tailored to specific applications, by centralizing the identification and control of applications at the firewall level.