Pa 800
Pa 800
Pa 800
Identifies and Categorizes All Applications, on All Ports, All the Time, with
Full Layer 7 Inspection
• Identifies the applications traversing your network irrespective of port, protocol, evasive techniques,
or encryption (TLS/SSL).
• Automatically discovers and controls new applications to keep pace with the SaaS explosion with
SaaS Security subscription.
• Uses the application, not the port, as the basis for all your safe enablement policy decisions: allow,
deny, schedule, inspect, and apply traffic-shaping.
• Offers the ability to create custom App-ID tags for proprietary applications or request App-ID
development for new applications from Palo Alto Networks.
• Identifies all payload data within the application (e.g., files and data patterns) to block malicious files
and thwart data exfiltration attempts.
• Creates standard and customized application usage reports, including software-as-a-service (SaaS)
reports that provide insight into all sanctioned and unsanctioned SaaS traffic on your network.
• Enables safe migration of legacy Layer 4 rule sets to App-ID-based rules with built-in Policy
Optimizer, giving you a rule set that is more secure and easier to manage.
• Check out the App-ID tech brief for more information.
Enforces Security for Users at Any Location, on Any Device, While Adapting
Policy Based on User Activity
• Enables visibility, security policies, reporting, and forensics based on users and groups—not just IP
addresses.
• Easily integrates with a wide range of repositories to leverage user information: wireless LAN
controllers, VPNs, d
irectory servers, SIEMs, proxies, and more.
• Allows you to define Dynamic User Groups (DUGs) on the firewall to take time-bound security actions
without waiting for changes to be applied to user directories.
• Applies consistent policies irrespective of users’ locations (office, home, travel, etc.) and d
evices
(iOS and Android mobile devices, macOS, Windows, Linux desktops, laptops; Citrix and M icrosoft
VDI and Terminal Servers).
• Prevents corporate credentials from leaking to third-party websites and prevents reuse of stolen
credentials by enabling multifactor authentication (MFA) at the network layer for any application
without any application changes.
• Provides dynamic security actions based on user behavior to restrict suspicious or malicious users.
• Consistently authenticates and authorizes your users, regardless of location and where user i dentity
stores live, to move quickly toward a Zero Trust security posture with Cloud Identity Engine—an
entirely new cloud-based architecture for identity-based security. Check out the Cloud Identity
Engine solution brief for more information.
Maximize Your Security Investment and Prevent Business Disruption with AIOps
• AIOps for NGFW delivers continuous best practice recommendations customized to your unique de-
ployment to strengthen your security posture and get the most out of your security investment.
• Intelligently predicts firewall health, performance, and capacity problems based on ML powered by
advanced telemetry data. It also provides actionable insights to resolve the predicted disruptions.
PA-820 PA-850
PA-800 Series ML-Powered NGFWs support a wide range of networking features that enable you to
more easily integrate our security features into your existing network.
Interface Modes
Routing
OSPFv2/v3 with graceful restart, BGP with graceful restart, RIP, static routing
Policy-based forwarding
SD-WAN
IPv6
SLAAC
Key exchange: manual key, IKEv1, and IKEv2 (preshared key, certificate-based authentication)
Secure access over IPsec and SSL VPN tunnels using GlobalProtect Gateway and Portals*
VLANs
NAT modes (IPv4): static IP, Dynamic IP, Dynamic IP and Port (port address translation)
NAT64, NPTv6
Additional NAT features: Dynamic IP reservation, tunable Dynamic IP and Port oversubscription
High Availability
I/O
Management I/O
240 GB SSD
Power Supply
Power Consumption
Max BTU/hr
256
Safety
cTUVus, CB
EMI
Certifications
See paloaltonetworks.com/company/certifications.html
Environment
Airflow
Front to back
3000 Tannery Way © 2023 Palo Alto Networks, Inc. Palo Alto Networks and the Palo Alto Networks
Santa Clara, CA 95054 logo are registered trademarks of Palo Alto Networks, Inc. A list of our trademarks
can be found at https://www.paloaltonetworks.com/company/trademarks.html.
Main: +1.408.753.4000 All other marks mentioned herein may be trademarks of their respective companies.
Sales: +1.866.320.4788 strata_ds_pa-800-series_071423
Support: +1.866.898.9087
www.paloaltonetworks.com