PA-3430 Next Generation Firewall

World’s first ML-Powered NGFW Ten-time Leader in the Gartner® Magic Quadrant™ for Network Firewalls Leader in the Forrester Wave™: Enterprise Firewalls, Q3 2020 Highest Security Effectiveness score in the 2019 NSS Labs NGFW Test Report, with 100% of evasions blocked Extends visibility and security to all devices, including unmanaged IoT devices, without the need to deploy additional sensors Supports high availability with active active and active/passive

Category : PaloAlto Firewall
Brand : Palo Alto
Model : PA-3430

Description

Highlights 
  •  World’s first ML-Powered NGFWrn
  • Ten-time Leader in the Gartner® MagicrnQuadrant™ for Network Firewalls
  • Leader in the Forrester Wave™: Enterprise Firewalls, Q3 2020
  •  Highest Security Effectiveness score in the 2019 NSS Labs NGFW Test Report, with 100% of evasions blocked
  •  Extends visibility and security to all devices, including unmanaged IoT devices, without
  • t the need to deployrnadditional sensors
  •  Supports high availability with active/rnactive and active/passive modesrn
  •  Delivers predictable performance withrnsecurity servicesrn
  • Simplifies deployment of large numbersrnof firewalls with Zero Touch Provisioningrn(ZTP)
  • Supports centralized administration withrnPanorama™ network security management    
  • The world’s first ML-Powered Next-Generation Firewall (NGFW) enables you to prevent unknown threats,rnsee and secure everything—including the Internet of Things (IoT)—and reduce errors with automaticrnpolicy recommendations.rnThe controlling element of the PA-3400 Series is PAN-OS®, the same software that runs all Palo AltornNetworks NGFWs. PAN-OS natively classifies all traffic, inclusive of applications, threats, and content,rnand then ties that traffic to the user regardless of location or device type. The application, content, andrnuser—in other words, the elements that run your business—then serve as the basis of your securityrnpolicies, resulting in improved security posture and reduced incident response time.
Key Security and Connectivity Features

ML-Powered Next-Generation Firewallrn

  • Embeds machine learning (ML) in the core of the firewall to provide inline signatureless attackrnprevention for file-based attacks while identifying and immediately stopping never-before-seenrnphishing attempts.
  • Leverages cloud-based ML processes to push zero-delay signatures and instructions back to the NGFW.
  •  Uses behavioral analysis to detect IoT devices and make policy recommendations; cloud-delivered andrnnatively integrated service on the NGFW Automates policy recommendations that save time and reduce the chance of human error.rnIdentifies and Categorizes All Applications, on All Ports, All the Time, with FullrnLayer 7 Inspection
  • Identifies the applications traversing your network irrespective of port, protocol, evasive techniques,rnor encryption (TLS/SSL). In addition, it automatically discovers and controls new applications to keeprnpace with the SaaS explosion with SaaS Security subscription.
  •  Uses the application, not the port, as the basis for all your safe enablement policy decisions: allow,rndeny, schedule, inspect, and apply traffic-shaping.rn
  •  Offers the ability to create custom App-ID™ tags for proprietary applications or request App-IDrndevelopment for new applications from Palo Alto Networks.
  •  Identifies all payload data within the application (e.g., files and data patterns) to block malicious filesrnand thwart data exfiltration attempts.
  •  Creates standard and customized application usage reports, including software-as-a-service (SaaS)rnreports that provide insight into all sanctioned and unsanctioned SaaS traffic on your network.
  •  Enables safe migration of legacy Layer 4 rule sets to App-ID-based rules with built-in PolicyrnOptimizer, giving you a rule set that is more secure and easier to manage.
  • Check out the App-ID tech brief for more information.rnEnforces Security for Users at Any Location, on Any Device, While AdaptingrnPolicy Based on User Activity
  •  Enables visibility, security policies, reporting, and forensics based on users and groups—not just IPrnaddresses.
  •  Easily integrates with a wide range of repositories to leverage user information: wireless LAN controllers,rnVPNs, directory servers, SIEMs, proxies, and more.rn
  •  Allows you to define Dynamic User Groups (DUGs) on the firewall to take time-bound security actionsrnwithout waiting for changes to be applied to user directories
  •  Applies consistent policies irrespective of users’ locations (office, home, travel, etc.) and devices (iOSrnand Android® mobile devices, macOS®, Windows®, Linux desktops, laptops; Citrix and Microsoft VDIrnand Terminal Servers).rn
  •  Prevents corporate credentials from leaking to third-party websites and prevents reuse of stolenrncredentials by enabling multi-factor authentication (MFA) at the network layer for any applicationrnwithout any application changes.rn
  •  Provides dynamic security actions based on user behavior to restrict suspicious or malicious users.
  •  Consistently authenticates and authorizes your users, regardless of location and where user identityrnstores live, to quickly move towards a Zero Trust security posture with Cloud Identity Engine—anrnentirely new cloud-based architecture for identity-based security. Check out the Cloud IdentityrnEngine solution brief for more information.

Prevents Malicious Activity Concealed in Encrypted Traffic

  •  Inspects and applies policy to TLS/SSL-encrypted traffic, both inbound and outbound, including forrntraffic that uses TLS 1.3 and HTTP/2.rn
  • Offers rich visibility into TLS traffic, such as amount of encrypted traffic, TLS/SSL versions, cipherrnsuites, and more, without decrypting.rn
  • Enables control over use of legacy TLS protocols, insecure ciphers, and misconfigured certificates tornmitigate risks.rn
  •  Facilitates easy deployment of decryption and lets you use built-in logs to troubleshoot issues, such asrnapplications with pinned certificates.rn
  •  Lets you enable or disable decryption flexibly based on URL category and source and destination zone,rnaddress, user, user group, device, and port, for privacy and regulatory compliance purposes.rn
  •  Allows you to create a copy of decrypted traffic from the firewall (i.e., decryption mirroring) and sendrnit to traffic collection tools for forensics, historical purposes, or data loss prevention (DLP).
  •  Allows you to intelligently forward all traffic (decrypted TLS, non-decrypted TLS, and non-TLS) tornthird-party security tools with Network Packet Broker and optimize your network performance andrnreduce operating expenses.rn
  •  Refer to this decryption white paper to learn where, when and how to decrypt to prevent threats andrnsecure your business.

rnOffers Centralized Management and Visibility

  •  Benefits from centralized management, configuration, and visibility for multiple distributed Palo AltornNetworks NGFWs (irrespective of location or scale) through Panorama network security managementrnin one unified user interface.
  •  Streamlines configuration sharing through Panorama with templates and device groups and scales logrncollection as logging needs increase.
  •  Enables users, through the Application Command Center (ACC), to obtain deep visibility andrncomprehensive insights into network traffic and threats.rn

Maximize Your Security Investment and Prevent Business Disruption with AIOps

  • AIOps for NGFW delivers continuous best practice recommendations customized to your unique deployment to strengthen your security posture and get the most out of your security investment.rn
  •  Intelligently predicts firewall health, performance and capacity problems based on ML powered byrnadvanced telemetry data. It also provides actionable insights to resolve the predicted disruptions.

rnDetects and Prevents Advanced Threats with Cloud-Delivered Security Servicesrn

  • Today’s sophisticated cyberattacks can spawn 45,000 variants in 30 minutes using multiple threat vectorsrnand advanced techniques to deliver malicious payloads. Traditional siloed security causes challenges forrnorganizations by introducing security gaps, increasing overhead for security teams, and hindering businessrnproductivity with inconsistent access and visibility.rnSeamlessly integrated with our industry-leading NGFWs, our Cloud-Delivered Security Services use thernnetwork effect of 80,000 customers to instantly coordinate intelligence and protect against all threatsrnacross all vectors. Eliminate coverage gaps across your locations and take advantage of bestin-classrnsecurity delivered consistently in a platform to stay safe from even the most advanced and evasive threats.rnServices include:rn

Advanced Threat Prevention

  • Stop known exploits, malware, malicious URLs, spyware, and commandrnand control (C2) with 96% prevention of web-based Cobalt Strike C2 and 48% more unknown C2rndetected than the industry’s leading intrusion prevention (IPS) solution.rn

WildFire+ malware prevention

  • Ensure files are safe by automatically detecting and preventingrnunknown malware 180X faster with industry-largest threat intelligence and malware preventionrnengine

Advanced URL Filtering:

  • Enable safe access to the internet with the industry’s first real-timernprevention of known and unknown websites, stopping 76% of malicious URLs 24 hours beforernother vendors.

DNS Security:

  • Gain 40% more DNS-attack coverage and disrupt the 80% of attacks that use DNS forrncommand and control and data theft, without requiring any changes to your infrastructure.

Enterprise DLP:

  • Minimize risk of a data breach, stop out-of-policy data transfers, and enablerncompliance consistently across your enterprise, with 2X greater coverage of any cloud-deliveredrnenterprise DLP.

SaaS Security

  • Stay ahead of the SaaS explosion with the industry’s only Next-Generation CASB tornautomatically see and secure all apps across all protocols.rn

IoT Security

  •  Safeguard every “thing” and implement Zero Trust device security 20X faster, with thernindustry’s smartest security for smart devices.rn

Delivers a Unique Approach to Packet Processing with Single-Pass Architecturern

  •  Performs networking, policy lookup, application and decoding, and signature matching—for allrnthreats and content—in a single pass. This significantly reduces the amount of processing overheadrnrequired to perform multiple functions in one security device.rn
  • Avoids introducing latency by scanning traffic for all signatures in a single pass, using stream-based,rnuniform signature matching.
  • Enables consistent and predictable performance when security subscriptions are enabled. (In table 1,rn“Threat Prevention throughput” is measured with multiple subscriptions enabled.)

Enables SD-WAN Functionality

  •  Allows you to easily adopt SD-WAN by simply enabling it on your existing firewalls.rn
  •  Enables you to safely implement SD-WAN, which is natively integrated with our industry-leadingrnsecurity.rn
  •  Delivers an exceptional end-user experience by minimizing latency, jitter, and packet loss.
  • Firewall throughput is measured with App-ID and logging enabled, utilizing 64 KB HTTP/appmix transactions.
  •  Threat Prevention throughput is measured with App-ID, IPS, antivirus, antispyware, WildFire, DNS Security, file blocking, and loggingrnenabled, utilizing 64 KB HTTP/appmix transactions.rn
  •  IPsec VPN throughput is measured with 64 KB HTTP transactions and logging enabled.rn§ New sessions per second is measured with application-override, utilizing 1 byte HTTP transactions.
  •  Adding virtual systems over base quantity requires a separately purchased license.
PA-3400 Series Performance and Capacities:

Firewall throughput (HTTP/appmix)

  •  30.2/24 Gbps, 25.5/20.5 Gbps, 20.8/16.9 Gbps ,14.5/11.6 Gbpsrn

Threat Threat Prevention throughput (HTTP/rnappmix)

  •  11.0/12.8 Gbps, 9.2/10.5, Gbps 7.6/8.7 Gbps, 5.2/5.9 Gbps

rnIPsec VPN throughput

  •  14.5 Gbps, 12.2 Gbps ,9.9 Gbps, 6.8 Gbps

rnMax sessions

  • 3M, 2.5M ,2M ,1.4M

rnNew sessions per second§ 

  •  268,000: 240,000 :205,000 :145,000

Virtual systems (base/max)

  • 1/11, 1/11, 1/11, 1/11
PA-3400 Series Networking Features
  • L2, L3, tap, virtual wire (transparent mode)rn

Routingrn

  • OSPFv2/v3 with graceful restart, BGP with graceful restart, RIP, static routingrn
  • Policy-based forwarding
  • rnPoint-to-point protocol over Ethernet (PPPoE)
  • rnMulticast: PIM-SM, PIM-SSM, IGMP v1, v2, and v3
  • rnBidirectional Forwarding Detection (BFD)

Table 2: PA-3400 Series Networking Features (continued)

IPsec VPNrn

  • Key exchange: manual key, IKEv1, and IKEv2 (pre-shared key, certificate-based authentication)
  • rnEncryption: 3DES, AES (128-bit, 192-bit, 256-bit)rn
  • Authentication: MD5, SHA-1, SHA-256, SHA-384, SHA-512

VLANsrn

  • 802.1Q VLAN tags per device/per interface: 4,094/4,094
  • rnAggregate interfaces (802.3ad), LACP

rnNetwork Address Translationrn

  • NAT modes (IPv4): static IP, dynamic IP, dynamic IP and port (port address translation)rnNAT64, NPTv6rn
  • Additional NAT features: dynamic IP reservation, tunable dynamic IP and port oversubscription

rnHigh Availabilityrn

  • Modes: active/active, active/passive, HA clusteringrn
  • Failure detection: path monitoring, interface monitoringrn

Mobile Network Infrastructure* (PA-3440 and PA-3430)rn

  • 5G Security
  • rn5G MEC (multi-access edge computing) Securit
  • yrnGTP Securityrn
  • SCTP Security
  • For additional information, refer to our ML-Powered NGFWs for 5G datasheet.

Table 3: PA-3400 Series Hardware Specifications

  •  PA-3430: 1G/2.5G/5G/10G (12), 1G/10G SFP/SFP+ (10), 25G SFP28 (4), 40G/100G QSFP/QSFP28 (2)

Management I/O

  • rn100/1000 out-of-band management port (1)rn
  • 100/1000 high availability (2), 10G SFP+ high availability (1)rn
  • RJ-45 console port (1), Micro USB (1)

rnStorage Capacity

  • rn480 GB SSD

rnPower Supply (Avg/Max Power Consumption)

  • rnRedundant 450-watt AC (155W/190W)rn

Max BTU/hr

  • rn650rn

Input Voltage Frequency

  • rnAC: 100–240 VAC (50–60Hz)

rnMax Current Consumptionrn

  • AC: 1.9 A @ 100 VAC, 0.8 A @ 240 VAC
Table 3: PA-3400 Series Hardware Specifications (continued)rn

Mean Time Between Failure (MTBF)rn

  • 22 yearsrn

Rack Mount Dimensions

  • rn1U, 19” standard rack 14.15” x 17.15” x 1.70”rn

Weight (Standalone Device/As Shipped)

  • rn15.5 lbs / 25 lbsrn

Safety

  • rncTUVus, CBrn

EMIrn

  • FCC Class A, CE Class A, VCCI Class A

rnEnvironmentrn

  • Operating temperature: 32° to 122° F, 0° to 50° C
  • rnNon-operating temperature: -4° to 158° F, -20° to 70° Crn
  • Humidity tolerance: 10% to 90%
  • Maximum altitude: 10,000 ft/3,048 mrn
  • Airflow: front to backrn
  • To view additional information about the features and associated capacities of the PA-3400 Series,rnplease visit