Palo Alto Networks PA-220 bringsML-Powered Next-Generation Firewallcapabilities to distributed enterprisebranch offices, retail locations, and midsize businesses.
Highlights
• High availability with active/activeand active/passive modes
• Redundant power input forincreased reliability
• Fanless design
• Simplified deployments of largenumbers of firewalls through USB
Key Security and ConnectivityFeatures
Classifies all applications, on all ports, all the time
• Identifies the application, regardless of port, SSL/SSHencryption, or evasive technique employed. • Uses the application, not the port, as the basis for all yoursafe enablement policy decisions: allow, deny, schedule,inspect, and apply traffic-shaping.
• Categorizes unidentified applications for policy control,threat forensics, or App-ID™ technology development.
• Provides full visibility into the details of all TLS-encryptedconnections and stops threats hidden in encrypted traffic,including traffic that uses TLS 1.3 and HTTP/2 protocols.
Enforces security policies for any user, at anylocation
• Deploys consistent policies to local and remote usersrunning on the Windows®, macOS®, Linux, Android®, orApple iOS platforms.
• Enables agentless integration with Microsoft Active Directory® and Terminal Services, LDAP, Novell eDirectory™, andCitrix.
• Easily integrates your firewall policies with 802.1X wireless, proxies, network access control, and any other sourceof user identity information.
Extends native protection across all attack vectorswith cloud-delivered security subscriptions
• Threat Prevention—inspects all traffic to automaticallyblock known vulnerabilities, malware, vulnerability exploits,spyware, command and control (C2), and custom intrusionprevention system (IPS) signatures.
• WildFire® malware prevention—protects against unknownfile-based threats, delivering automated prevention inseconds for most new threats across networks, endpoints,and clouds.
• URL Filtering—prevents access to malicious sites andprotects users against web-based threats.
• DNS Security—detects and blocks known and unknownthreats over DNS while predictive analytics disrupt attacksusing DNS for C2 or data theft.
• IoT Security—discovers all unmanaged devices in yournetwork, identifies risks and vulnerabilities, and automatesenforcement policies for your ML-Powered NGFW using anew Device-ID™ policy construct.
Enables SD-WAN functionality
• Allows you to easily adopt SD-WAN by simply enabling iton your existing firewalls.
• Enables you to safely implement SD-WAN, which is nativelyintegrated with our industry-leading security.
• Delivers an exceptional end user experience by minimizinglatency, jitter, and packet loss.

