Palo Alto Networks PA-5540-AC Next-Gen Firewall 150 Gbps, PQC-Ready
[shortdesc] 3U rack mount, 150 Gbps firewall, 90 Gbps threat prevention, 39M sessions, 16x10/25G SFP28, 16x40/100G QSFP28, 4x100/400G QSFP-DD [/shortdesc]
[properties]
| Model | PA-5540 |
| Series | PA-5500 Series |
| Product Type | Next-Generation Firewall (Quantum-optimized) |
| Operating System | PAN-OS® (measurements cited on PAN-OS 12.1) |
| Form Factor | 3U, 19" rack |
| Dimensions (H × D × W) | 5.2 in × 29.8 in × 17.3 in (3U) |
| Weight | 70 lb (standalone) |
| Airflow | Front to back (port side to power supply side) |
| Operating Temperature | 0 °C to 50 °C (32 °F to 122 °F) |
| Storage Temperature | −20 °C to 70 °C (−4 °F to 158 °F) |
| Humidity (Operating) | 10%–90% |
| Max Operating Altitude | 3,048 m (10,000 ft) |
| I/O (Data) | 16 × 10/25G SFP28; 16 × 40/100G QSFP28; 4 × 100/400G QSFP-DD |
| Management / Console I/O | 2 × 1G/10G SFP+ (OOB mgmt); RJ-45 console; USB-C console; USB 3.2 Gen1 Type-A (bootstrap); 2 × 10G SFP+ (Log); 2 × 100G/400G QSFP-DD (HSCI) |
| Storage | Optional 3.84 TB RAID1 SSD pair (cold swap) |
| Power (Input) | AC 100–240 VAC (50–60 Hz); DC −40 to −60 VDC |
| Power Supplies | AC: 2+2 redundant (220 V) / 3+1 (110 V); DC: 2+2 redundant |
| Power – Avg / Max | 2,100 W / 3,100 W |
| Max BTU/hr | 1,638 |
| MTBF | 8.1 years |
| Safety / EMI | cTUVus, CB; FCC Class A, CE Class A, VCCI Class A |
[/properties]
[specifications]
| Firewall Throughput (appmix) | 150 Gbps |
| Threat Prevention Throughput (appmix) | 90 Gbps |
| IPsec VPN Throughput | 80 Gbps |
| Max Concurrent Sessions | 39 million |
| New Sessions per Second | 1.33 million |
| Virtual Systems | 25 base / 225 max |
| VLANs | 802.1Q VLAN tags per device/per interface: 4,094 / 4,094 |
| Routing | OSPFv2/v3, MP-BGP, RIP, static; policy-based forwarding; DHCPv4 server/relay; PPPoE; Multicast (PIM-SM/SSM, IGMPv2/v3); BFD & multihop BFD |
| Network Address Translation | IPv4: Static, Dynamic IP, Dynamic IP & Port (PAT); NAT64; NPTv6; plus dynamic IP reservation and oversubscription |
| IPv6 | Inspection in L2/L3/tap/virtual wire; dual-stack & IPv6-only; OSPFv3, MP-BGP, NAT64, NPTv6; DHCPv6 PD; SLAAC server; geolocation |
| IPsec VPN | IKEv1/IKEv2; manual key; Encryption: 3DES, AES-128/192/256; Authentication: MD5, SHA-1/256/384/512; GlobalProtect® VPN support |
| High Availability / Clustering | NGFW clustering (A/A) and HA A/P (note: some elements are roadmap-dependent) |
| TLS/Decryption | Outbound/inbound SSL/TLS (v1.1/1.2/1.3); classical RSA/ECDHE/DHE and post-quantum ML-KEM/HQC key exchanges; policy-based controls |
| Management | Strata™ Cloud Manager; single-pass architecture; App-ID™, User-ID, Precision AI® services (CDSS) |
[/specifications]
[accesories]
| Included (PA-5540-AC bundle) | 4 × PAN-PA-5500-PWR-2700-AC; 5 × PAN-PA-FAN-2RU-A; 1 × PAN-PA-5500-ACC-A accessory kit; 1 × PAN-PA-3RU-RACK-A; 2 × PAN-SFP-CG; 1 × PAN-PA-5500-SSD-3.84TB-PAIR |
| Spare / Optional | PAN-PA-5500-SSD-3.84TB-PAIR (spare); PAN-PA-5500-ACC-A (AC kit: 4 × PAN-PWR-C19-US-120V + USB cable + Cat6); PAN-PA-5500-ACC-B (DC kit: 4 × PAN-PWR-DC-CBL-C + USB cable + Cat6) |
[/accesories]
High Speed Protection for Modern Data Centers
The Palo Alto Networks PA-5540 delivers data center grade throughput with deep security inspection in a compact 3U chassis. It brings ML powered defenses, predictable latency, and unified operations so you can scale east west and internet edge security without sacrificing performance or manageability.
Key Benefits & Features
- Quantum ready decryption and VPN: Post quantum cryptography support in PAN-OS helps future proof SSL/TLS inspection and site to site VPN while maintaining strong performance.
- Single pass architecture for consistency: Networking, policy lookup, application decoding, and signature matching run in one pass to keep latency low even with full security services enabled.
- AI assisted operations and visibility: Strata Cloud Manager and Strata Copilot provide real time insights, best practice guidance, and proactive issue detection across deployments.
- Application and identity aware control: App-ID and User-ID enforce precise policies by application and user to secure SaaS, reduce lateral movement, and align with Zero Trust.
- Built to scale and stay online: High availability and clustering options increase resiliency, while rich routing and SD-WAN features integrate cleanly into complex networks.
Ideal Use Cases
- Data centers and internet gateways requiring high throughput with deep inspection
- Large campus cores consolidating advanced security at scale
- Enterprises standardizing on centralized, cloud managed operations
- Zero Trust initiatives needing app and identity based control across encrypted traffic
Technical Specifications
- Firewall Throughput: up to 150 Gbps
- Threat Prevention Throughput: up to 90 Gbps
- IPsec VPN Throughput: up to 80 Gbps
- Max Concurrent Sessions: up to 39,000,000
- New Sessions per Second: up to 1,330,000
- Interfaces: 16x10/25G SFP28, 16x40/100G QSFP28, 4x100/400G QSFP-DD
- Form Factor: 3U 19 inch rack mount, front to back airflow
- Management: Strata™ Cloud Manager; single-pass architecture; App-ID™, User-ID, Precision AI® services (CDSS)
Scale Security With Confidence
Upgrade to the PA-5540 for high speed, low latency protection with AI assisted operations. Contact us for a tailored quote and deployment guidance.
Product Information
Product Information
Shipping & Returns
Shipping & Returns

Palo Alto Networks PA-5540-AC Next-Gen Firewall 150 Gbps, PQC-Ready
Palo Alto Networks PA-5540-AC Next-Gen Firewall 150 Gbps, PQC-Ready
[shortdesc] 3U rack mount, 150 Gbps firewall, 90 Gbps threat prevention, 39M sessions, 16x10/25G SFP28, 16x40/100G QSFP28, 4x100/400G QSFP-DD [/shortdesc]
[properties]
| Model | PA-5540 |
| Series | PA-5500 Series |
| Product Type | Next-Generation Firewall (Quantum-optimized) |
| Operating System | PAN-OS® (measurements cited on PAN-OS 12.1) |
| Form Factor | 3U, 19" rack |
| Dimensions (H × D × W) | 5.2 in × 29.8 in × 17.3 in (3U) |
| Weight | 70 lb (standalone) |
| Airflow | Front to back (port side to power supply side) |
| Operating Temperature | 0 °C to 50 °C (32 °F to 122 °F) |
| Storage Temperature | −20 °C to 70 °C (−4 °F to 158 °F) |
| Humidity (Operating) | 10%–90% |
| Max Operating Altitude | 3,048 m (10,000 ft) |
| I/O (Data) | 16 × 10/25G SFP28; 16 × 40/100G QSFP28; 4 × 100/400G QSFP-DD |
| Management / Console I/O | 2 × 1G/10G SFP+ (OOB mgmt); RJ-45 console; USB-C console; USB 3.2 Gen1 Type-A (bootstrap); 2 × 10G SFP+ (Log); 2 × 100G/400G QSFP-DD (HSCI) |
| Storage | Optional 3.84 TB RAID1 SSD pair (cold swap) |
| Power (Input) | AC 100–240 VAC (50–60 Hz); DC −40 to −60 VDC |
| Power Supplies | AC: 2+2 redundant (220 V) / 3+1 (110 V); DC: 2+2 redundant |
| Power – Avg / Max | 2,100 W / 3,100 W |
| Max BTU/hr | 1,638 |
| MTBF | 8.1 years |
| Safety / EMI | cTUVus, CB; FCC Class A, CE Class A, VCCI Class A |
[/properties]
[specifications]
| Firewall Throughput (appmix) | 150 Gbps |
| Threat Prevention Throughput (appmix) | 90 Gbps |
| IPsec VPN Throughput | 80 Gbps |
| Max Concurrent Sessions | 39 million |
| New Sessions per Second | 1.33 million |
| Virtual Systems | 25 base / 225 max |
| VLANs | 802.1Q VLAN tags per device/per interface: 4,094 / 4,094 |
| Routing | OSPFv2/v3, MP-BGP, RIP, static; policy-based forwarding; DHCPv4 server/relay; PPPoE; Multicast (PIM-SM/SSM, IGMPv2/v3); BFD & multihop BFD |
| Network Address Translation | IPv4: Static, Dynamic IP, Dynamic IP & Port (PAT); NAT64; NPTv6; plus dynamic IP reservation and oversubscription |
| IPv6 | Inspection in L2/L3/tap/virtual wire; dual-stack & IPv6-only; OSPFv3, MP-BGP, NAT64, NPTv6; DHCPv6 PD; SLAAC server; geolocation |
| IPsec VPN | IKEv1/IKEv2; manual key; Encryption: 3DES, AES-128/192/256; Authentication: MD5, SHA-1/256/384/512; GlobalProtect® VPN support |
| High Availability / Clustering | NGFW clustering (A/A) and HA A/P (note: some elements are roadmap-dependent) |
| TLS/Decryption | Outbound/inbound SSL/TLS (v1.1/1.2/1.3); classical RSA/ECDHE/DHE and post-quantum ML-KEM/HQC key exchanges; policy-based controls |
| Management | Strata™ Cloud Manager; single-pass architecture; App-ID™, User-ID, Precision AI® services (CDSS) |
[/specifications]
[accesories]
| Included (PA-5540-AC bundle) | 4 × PAN-PA-5500-PWR-2700-AC; 5 × PAN-PA-FAN-2RU-A; 1 × PAN-PA-5500-ACC-A accessory kit; 1 × PAN-PA-3RU-RACK-A; 2 × PAN-SFP-CG; 1 × PAN-PA-5500-SSD-3.84TB-PAIR |
| Spare / Optional | PAN-PA-5500-SSD-3.84TB-PAIR (spare); PAN-PA-5500-ACC-A (AC kit: 4 × PAN-PWR-C19-US-120V + USB cable + Cat6); PAN-PA-5500-ACC-B (DC kit: 4 × PAN-PWR-DC-CBL-C + USB cable + Cat6) |
[/accesories]
High Speed Protection for Modern Data Centers
The Palo Alto Networks PA-5540 delivers data center grade throughput with deep security inspection in a compact 3U chassis. It brings ML powered defenses, predictable latency, and unified operations so you can scale east west and internet edge security without sacrificing performance or manageability.
Key Benefits & Features
- Quantum ready decryption and VPN: Post quantum cryptography support in PAN-OS helps future proof SSL/TLS inspection and site to site VPN while maintaining strong performance.
- Single pass architecture for consistency: Networking, policy lookup, application decoding, and signature matching run in one pass to keep latency low even with full security services enabled.
- AI assisted operations and visibility: Strata Cloud Manager and Strata Copilot provide real time insights, best practice guidance, and proactive issue detection across deployments.
- Application and identity aware control: App-ID and User-ID enforce precise policies by application and user to secure SaaS, reduce lateral movement, and align with Zero Trust.
- Built to scale and stay online: High availability and clustering options increase resiliency, while rich routing and SD-WAN features integrate cleanly into complex networks.
Ideal Use Cases
- Data centers and internet gateways requiring high throughput with deep inspection
- Large campus cores consolidating advanced security at scale
- Enterprises standardizing on centralized, cloud managed operations
- Zero Trust initiatives needing app and identity based control across encrypted traffic
Technical Specifications
- Firewall Throughput: up to 150 Gbps
- Threat Prevention Throughput: up to 90 Gbps
- IPsec VPN Throughput: up to 80 Gbps
- Max Concurrent Sessions: up to 39,000,000
- New Sessions per Second: up to 1,330,000
- Interfaces: 16x10/25G SFP28, 16x40/100G QSFP28, 4x100/400G QSFP-DD
- Form Factor: 3U 19 inch rack mount, front to back airflow
- Management: Strata™ Cloud Manager; single-pass architecture; App-ID™, User-ID, Precision AI® services (CDSS)
Scale Security With Confidence
Upgrade to the PA-5540 for high speed, low latency protection with AI assisted operations. Contact us for a tailored quote and deployment guidance.
Product Information
Product Information
Shipping & Returns
Shipping & Returns
Description
[shortdesc] 3U rack mount, 150 Gbps firewall, 90 Gbps threat prevention, 39M sessions, 16x10/25G SFP28, 16x40/100G QSFP28, 4x100/400G QSFP-DD [/shortdesc]
[properties]
| Model | PA-5540 |
| Series | PA-5500 Series |
| Product Type | Next-Generation Firewall (Quantum-optimized) |
| Operating System | PAN-OS® (measurements cited on PAN-OS 12.1) |
| Form Factor | 3U, 19" rack |
| Dimensions (H × D × W) | 5.2 in × 29.8 in × 17.3 in (3U) |
| Weight | 70 lb (standalone) |
| Airflow | Front to back (port side to power supply side) |
| Operating Temperature | 0 °C to 50 °C (32 °F to 122 °F) |
| Storage Temperature | −20 °C to 70 °C (−4 °F to 158 °F) |
| Humidity (Operating) | 10%–90% |
| Max Operating Altitude | 3,048 m (10,000 ft) |
| I/O (Data) | 16 × 10/25G SFP28; 16 × 40/100G QSFP28; 4 × 100/400G QSFP-DD |
| Management / Console I/O | 2 × 1G/10G SFP+ (OOB mgmt); RJ-45 console; USB-C console; USB 3.2 Gen1 Type-A (bootstrap); 2 × 10G SFP+ (Log); 2 × 100G/400G QSFP-DD (HSCI) |
| Storage | Optional 3.84 TB RAID1 SSD pair (cold swap) |
| Power (Input) | AC 100–240 VAC (50–60 Hz); DC −40 to −60 VDC |
| Power Supplies | AC: 2+2 redundant (220 V) / 3+1 (110 V); DC: 2+2 redundant |
| Power – Avg / Max | 2,100 W / 3,100 W |
| Max BTU/hr | 1,638 |
| MTBF | 8.1 years |
| Safety / EMI | cTUVus, CB; FCC Class A, CE Class A, VCCI Class A |
[/properties]
[specifications]
| Firewall Throughput (appmix) | 150 Gbps |
| Threat Prevention Throughput (appmix) | 90 Gbps |
| IPsec VPN Throughput | 80 Gbps |
| Max Concurrent Sessions | 39 million |
| New Sessions per Second | 1.33 million |
| Virtual Systems | 25 base / 225 max |
| VLANs | 802.1Q VLAN tags per device/per interface: 4,094 / 4,094 |
| Routing | OSPFv2/v3, MP-BGP, RIP, static; policy-based forwarding; DHCPv4 server/relay; PPPoE; Multicast (PIM-SM/SSM, IGMPv2/v3); BFD & multihop BFD |
| Network Address Translation | IPv4: Static, Dynamic IP, Dynamic IP & Port (PAT); NAT64; NPTv6; plus dynamic IP reservation and oversubscription |
| IPv6 | Inspection in L2/L3/tap/virtual wire; dual-stack & IPv6-only; OSPFv3, MP-BGP, NAT64, NPTv6; DHCPv6 PD; SLAAC server; geolocation |
| IPsec VPN | IKEv1/IKEv2; manual key; Encryption: 3DES, AES-128/192/256; Authentication: MD5, SHA-1/256/384/512; GlobalProtect® VPN support |
| High Availability / Clustering | NGFW clustering (A/A) and HA A/P (note: some elements are roadmap-dependent) |
| TLS/Decryption | Outbound/inbound SSL/TLS (v1.1/1.2/1.3); classical RSA/ECDHE/DHE and post-quantum ML-KEM/HQC key exchanges; policy-based controls |
| Management | Strata™ Cloud Manager; single-pass architecture; App-ID™, User-ID, Precision AI® services (CDSS) |
[/specifications]
[accesories]
| Included (PA-5540-AC bundle) | 4 × PAN-PA-5500-PWR-2700-AC; 5 × PAN-PA-FAN-2RU-A; 1 × PAN-PA-5500-ACC-A accessory kit; 1 × PAN-PA-3RU-RACK-A; 2 × PAN-SFP-CG; 1 × PAN-PA-5500-SSD-3.84TB-PAIR |
| Spare / Optional | PAN-PA-5500-SSD-3.84TB-PAIR (spare); PAN-PA-5500-ACC-A (AC kit: 4 × PAN-PWR-C19-US-120V + USB cable + Cat6); PAN-PA-5500-ACC-B (DC kit: 4 × PAN-PWR-DC-CBL-C + USB cable + Cat6) |
[/accesories]
High Speed Protection for Modern Data Centers
The Palo Alto Networks PA-5540 delivers data center grade throughput with deep security inspection in a compact 3U chassis. It brings ML powered defenses, predictable latency, and unified operations so you can scale east west and internet edge security without sacrificing performance or manageability.
Key Benefits & Features
- Quantum ready decryption and VPN: Post quantum cryptography support in PAN-OS helps future proof SSL/TLS inspection and site to site VPN while maintaining strong performance.
- Single pass architecture for consistency: Networking, policy lookup, application decoding, and signature matching run in one pass to keep latency low even with full security services enabled.
- AI assisted operations and visibility: Strata Cloud Manager and Strata Copilot provide real time insights, best practice guidance, and proactive issue detection across deployments.
- Application and identity aware control: App-ID and User-ID enforce precise policies by application and user to secure SaaS, reduce lateral movement, and align with Zero Trust.
- Built to scale and stay online: High availability and clustering options increase resiliency, while rich routing and SD-WAN features integrate cleanly into complex networks.
Ideal Use Cases
- Data centers and internet gateways requiring high throughput with deep inspection
- Large campus cores consolidating advanced security at scale
- Enterprises standardizing on centralized, cloud managed operations
- Zero Trust initiatives needing app and identity based control across encrypted traffic
Technical Specifications
- Firewall Throughput: up to 150 Gbps
- Threat Prevention Throughput: up to 90 Gbps
- IPsec VPN Throughput: up to 80 Gbps
- Max Concurrent Sessions: up to 39,000,000
- New Sessions per Second: up to 1,330,000
- Interfaces: 16x10/25G SFP28, 16x40/100G QSFP28, 4x100/400G QSFP-DD
- Form Factor: 3U 19 inch rack mount, front to back airflow
- Management: Strata™ Cloud Manager; single-pass architecture; App-ID™, User-ID, Precision AI® services (CDSS)
Scale Security With Confidence
Upgrade to the PA-5540 for high speed, low latency protection with AI assisted operations. Contact us for a tailored quote and deployment guidance.














