Palo Alto Networks PA-5540-DC Next-Gen Firewall 150 Gbps, Quantum-Optimized
[shortdesc] 3U data-center NGFW, 150 Gbps FW, 90 Gbps Threat Prevention, 39M sessions, 100/400G ready, DC redundant PSUs [/shortdesc]
[properties]
| Model | PA-5540 |
| Product Type | Quantum Optimized Next-Generation Firewall (NGFW) |
| Operating System | PAN-OS |
| Firewall Throughput (appmix) | 150 Gbps |
| Threat Prevention Throughput (appmix) | 90 Gbps |
| IPsec VPN Throughput | 80 Gbps |
| Max Concurrent Sessions | 39 Million (39M) |
| New Sessions per Second | 1.33 Million (1.33M) |
| Virtual Systems (Base/Max) | 25 / 225 |
| Form Factor / Dimensions | 3U, 19” standard rack; 5.2” H × 29.8” D × 17.3” W |
| I/O Ports | 16× 10G/25G SFP28; 16× 40G/100G QSFP28; 4× 100G/400G QSFP-DD |
| Management I/O | 2× 1G/10G SFP+ (OOB Mgmt); RJ-45 console; USB-C console; USB 3.2 Gen1 Type-A (bootstrap); 2× 100G/400G QSFP-DD (HSCI); 2× 10G SFP+ (Log) |
| Storage | Optional 3.84 TB RAID1 SSD pair (cold swap) |
| Power Type | DC (Direct Current) |
| Input Voltage (DC) | −40 VDC to −60 VDC |
| Power Consumption (Avg/Max) | 2,100 W / 3,100 W |
| Power Supplies | 2+2 redundant for DC |
| Power Supply Output (DC) | 2,200 W per power supply |
| Max Current (DC) | 43.7 A @ 54 VDC |
| Thermal (Max BTU/hr) | 1638 |
| Airflow | Front to back (port side to power supply side) |
| Operating Temperature | 32 °F to 122 °F (0 °C to 50 °C) |
| Non-operating Temperature | −4 °F to 158 °F (−20 °C to 70 °C) |
| Humidity | 10%–90% |
| Maximum Altitude | 10,000 ft (3,048 m) |
| MTBF | 8.1 years |
| Safety / EMI | cTUVus, CB / FCC Class A, CE Class A, VCCI Class A |
[/properties]
[specifications]
| Interface Modes | L2, L3, tap, virtual wire (transparent) (L2 not available on MC-LAG aggregate interfaces) |
| Routing | Advanced routing engine; OSPFv2/v3, MP-BGP, RIP, static; policy-based forwarding; PPPoE, DHCP client; DHCPv4 server/relay; Multicast (PIM-SM/SSM, IGMPv2/v3); BFD & multihop BFD |
| Advanced SD-WAN | Path quality (jitter, loss, latency) measurement, bandwidth monitoring, manual/IKEv1/IKEv2 key exchange, post-quantum PPK, multi-VR/LR support over overlay, Prisma Access Hub, ADEM support |
| IPv6 | L2/L3/tap/virtual wire inspection; dual-stack & IPv6-only; IPv6 geolocation, OSPFv3, MP-BGP, NAT64, NPTv6; DHCPv6 client (PD) & SLAAC server |
| IPsec VPN | Manual, IKEv1/IKEv2; Encryption: 3DES, AES-128/192/256; Authentication: MD5, SHA-1/256/384/512; GlobalProtect Large Scale VPN; Secure access over IPsec/SSL VPN tunnels via GlobalProtect |
| VLANs / LAG | 802.1Q VLAN tags: 4,094 per device or per interface; 802.3ad aggregate interfaces & LACP |
| NAT | Static IP, dynamic IP, dynamic IP & port (PAT); NAT64, NPTv6; dynamic IP reservation, tunable dynamic IP, port oversubscription |
| High Availability / Clustering | NGFW clustering (active/active); HA active/passive |
| Mobile Network | 5G security (Future release; not supported with NGFW clustering) |
| Management | Managed with Strata™ Cloud Manager, the industry's first AI-powered unified management and operations solution. |
[/specifications]
[accesories]
| Included in the box (DC SKU) | 4× PAN-PA-5500-PWR-2000-DC; 5× PAN-PA-FAN-2RU-A; 1× PAN-PA-5500-ACC-B accessory kit; 1× PAN-PA-3RU-RACK-A; 2× PAN-SFP-CG; 1× PAN-PA-5500-SSD-3.84TB-PAIR |
| Spare – SSD Pair | PAN-PA-5500-SSD-3.84TB-PAIR (spare replacement drive) |
| Spare – Accessory Kit (AC) | PAN-PA-5500-ACC-A (includes 4× PAN-PWR-C19-US-120V cable, 1× USB cable, and 1× Cat6 cable) |
| Spare – Accessory Kit (DC) | PAN-PA-5500-ACC-B (includes 4× PAN-PWR-DC-CBL-C cable, 1× USB cable, and 1× Cat6 cable) |
[/accesories]
Solve High-Speed Edge Risk with Quantum-Ready Security
Growing east-west traffic, encrypted threats, and 100/400G uplinks put pressure on legacy edge firewalls. The Palo Alto Networks PA-5540-DC delivers data-center-class performance in a compact 3U chassis with Precision AI defenses and post-quantum cryptography readiness, giving you predictable security at scale without compromising throughput.
Key Benefits & Features
Quantum-Optimized & PQC-Ready NGFW
Designed as the world's first quantum-optimized Next-Generation Firewall (NGFW), the PA-5500 Series supports PQC use cases (PQC TLS decryption and PQC site-to-site VPN) and includes a PCIe slot for future PQ capabilities—ideal for long-lived data and compliance roadmaps.
Inline Prevention at Data-Center Speeds
Achieve 150 Gbps firewall throughput (AppMix) and 90 Gbps Threat Prevention, plus 80 Gbps IPsec VPN, 39M max concurrent sessions, and 1.33M new sessions per second—built for large east-west and internet edge workloads.
100/400G I/O for Modern Fabrics
Connect fabrics and spines with a high-density I/O of 16 × 10G/25G SFP28, 16 × 40G/100G QSFP28, and 4 × 100G/400G QSFP-DD ports; dedicated management and logging ports simplify operations.
Unified, AI-Powered Operations with Strata Cloud Manager
Operate at scale with Strata Cloud Manager, the industry's first AI-powered unified management solution. Leverage Strata Copilot for policy hygiene, anomaly detection, proactive issue resolution, and faster troubleshooting, unified across NGFW, SASE, and security services.
App- and User-Aware Control
PAN-OS natively classifies all traffic, including applications, threats, and content, tying them to the user regardless of location. App-ID and identity-based policies deliver precise Layer-7 control, safe SaaS access, and zero-trust segmentation without port-based guesswork.
Ideal Use Cases for the PA-5540-DC
- Internet Gateways and Data-Center Edges consolidating high-bandwidth threat prevention with 100G/400G connectivity.
- Service Provider POPs needing predictable, low-latency performance and massive session scale.
- 5G-Native and Encrypted Traffic Environments planning for PQC migration and requiring 5G identifier-based visibility.
- Enterprises standardizing on AI-assisted, centralized policy and lifecycle management to strengthen their security posture.
Technical Specifications at a Glance
- Firewall Throughput (AppMix): 150 Gbps
- Threat Prevention Throughput: 90 Gbps
- IPsec VPN Throughput: 80 Gbps
- Max Concurrent Sessions / New SPS: 39M / 1.33M
- Interfaces: 16 × 10/25G SFP28; 16 × 40/100G QSFP28; 4 × 100/400G QSFP-DD
- Form Factor & Airflow: 3U, front-to-back
- Power (DC Model): −40 to −60 VDC input, 2+2 redundant DC PSUs
- High Availability: NGFW clustering (Active/Active) and HA (Active/Passive)
Lock Down Your Edge with Headroom to Grow
Ready for quantum-safe futures and 400G fabrics, the Palo Alto Networks PA-5540-DC delivers the performance, visibility, and manageability modern, high-speed network edges demand.
Product Information
Product Information
Shipping & Returns
Shipping & Returns

Palo Alto Networks PA-5540-DC Next-Gen Firewall 150 Gbps, Quantum-Optimized
Palo Alto Networks PA-5540-DC Next-Gen Firewall 150 Gbps, Quantum-Optimized
[shortdesc] 3U data-center NGFW, 150 Gbps FW, 90 Gbps Threat Prevention, 39M sessions, 100/400G ready, DC redundant PSUs [/shortdesc]
[properties]
| Model | PA-5540 |
| Product Type | Quantum Optimized Next-Generation Firewall (NGFW) |
| Operating System | PAN-OS |
| Firewall Throughput (appmix) | 150 Gbps |
| Threat Prevention Throughput (appmix) | 90 Gbps |
| IPsec VPN Throughput | 80 Gbps |
| Max Concurrent Sessions | 39 Million (39M) |
| New Sessions per Second | 1.33 Million (1.33M) |
| Virtual Systems (Base/Max) | 25 / 225 |
| Form Factor / Dimensions | 3U, 19” standard rack; 5.2” H × 29.8” D × 17.3” W |
| I/O Ports | 16× 10G/25G SFP28; 16× 40G/100G QSFP28; 4× 100G/400G QSFP-DD |
| Management I/O | 2× 1G/10G SFP+ (OOB Mgmt); RJ-45 console; USB-C console; USB 3.2 Gen1 Type-A (bootstrap); 2× 100G/400G QSFP-DD (HSCI); 2× 10G SFP+ (Log) |
| Storage | Optional 3.84 TB RAID1 SSD pair (cold swap) |
| Power Type | DC (Direct Current) |
| Input Voltage (DC) | −40 VDC to −60 VDC |
| Power Consumption (Avg/Max) | 2,100 W / 3,100 W |
| Power Supplies | 2+2 redundant for DC |
| Power Supply Output (DC) | 2,200 W per power supply |
| Max Current (DC) | 43.7 A @ 54 VDC |
| Thermal (Max BTU/hr) | 1638 |
| Airflow | Front to back (port side to power supply side) |
| Operating Temperature | 32 °F to 122 °F (0 °C to 50 °C) |
| Non-operating Temperature | −4 °F to 158 °F (−20 °C to 70 °C) |
| Humidity | 10%–90% |
| Maximum Altitude | 10,000 ft (3,048 m) |
| MTBF | 8.1 years |
| Safety / EMI | cTUVus, CB / FCC Class A, CE Class A, VCCI Class A |
[/properties]
[specifications]
| Interface Modes | L2, L3, tap, virtual wire (transparent) (L2 not available on MC-LAG aggregate interfaces) |
| Routing | Advanced routing engine; OSPFv2/v3, MP-BGP, RIP, static; policy-based forwarding; PPPoE, DHCP client; DHCPv4 server/relay; Multicast (PIM-SM/SSM, IGMPv2/v3); BFD & multihop BFD |
| Advanced SD-WAN | Path quality (jitter, loss, latency) measurement, bandwidth monitoring, manual/IKEv1/IKEv2 key exchange, post-quantum PPK, multi-VR/LR support over overlay, Prisma Access Hub, ADEM support |
| IPv6 | L2/L3/tap/virtual wire inspection; dual-stack & IPv6-only; IPv6 geolocation, OSPFv3, MP-BGP, NAT64, NPTv6; DHCPv6 client (PD) & SLAAC server |
| IPsec VPN | Manual, IKEv1/IKEv2; Encryption: 3DES, AES-128/192/256; Authentication: MD5, SHA-1/256/384/512; GlobalProtect Large Scale VPN; Secure access over IPsec/SSL VPN tunnels via GlobalProtect |
| VLANs / LAG | 802.1Q VLAN tags: 4,094 per device or per interface; 802.3ad aggregate interfaces & LACP |
| NAT | Static IP, dynamic IP, dynamic IP & port (PAT); NAT64, NPTv6; dynamic IP reservation, tunable dynamic IP, port oversubscription |
| High Availability / Clustering | NGFW clustering (active/active); HA active/passive |
| Mobile Network | 5G security (Future release; not supported with NGFW clustering) |
| Management | Managed with Strata™ Cloud Manager, the industry's first AI-powered unified management and operations solution. |
[/specifications]
[accesories]
| Included in the box (DC SKU) | 4× PAN-PA-5500-PWR-2000-DC; 5× PAN-PA-FAN-2RU-A; 1× PAN-PA-5500-ACC-B accessory kit; 1× PAN-PA-3RU-RACK-A; 2× PAN-SFP-CG; 1× PAN-PA-5500-SSD-3.84TB-PAIR |
| Spare – SSD Pair | PAN-PA-5500-SSD-3.84TB-PAIR (spare replacement drive) |
| Spare – Accessory Kit (AC) | PAN-PA-5500-ACC-A (includes 4× PAN-PWR-C19-US-120V cable, 1× USB cable, and 1× Cat6 cable) |
| Spare – Accessory Kit (DC) | PAN-PA-5500-ACC-B (includes 4× PAN-PWR-DC-CBL-C cable, 1× USB cable, and 1× Cat6 cable) |
[/accesories]
Solve High-Speed Edge Risk with Quantum-Ready Security
Growing east-west traffic, encrypted threats, and 100/400G uplinks put pressure on legacy edge firewalls. The Palo Alto Networks PA-5540-DC delivers data-center-class performance in a compact 3U chassis with Precision AI defenses and post-quantum cryptography readiness, giving you predictable security at scale without compromising throughput.
Key Benefits & Features
Quantum-Optimized & PQC-Ready NGFW
Designed as the world's first quantum-optimized Next-Generation Firewall (NGFW), the PA-5500 Series supports PQC use cases (PQC TLS decryption and PQC site-to-site VPN) and includes a PCIe slot for future PQ capabilities—ideal for long-lived data and compliance roadmaps.
Inline Prevention at Data-Center Speeds
Achieve 150 Gbps firewall throughput (AppMix) and 90 Gbps Threat Prevention, plus 80 Gbps IPsec VPN, 39M max concurrent sessions, and 1.33M new sessions per second—built for large east-west and internet edge workloads.
100/400G I/O for Modern Fabrics
Connect fabrics and spines with a high-density I/O of 16 × 10G/25G SFP28, 16 × 40G/100G QSFP28, and 4 × 100G/400G QSFP-DD ports; dedicated management and logging ports simplify operations.
Unified, AI-Powered Operations with Strata Cloud Manager
Operate at scale with Strata Cloud Manager, the industry's first AI-powered unified management solution. Leverage Strata Copilot for policy hygiene, anomaly detection, proactive issue resolution, and faster troubleshooting, unified across NGFW, SASE, and security services.
App- and User-Aware Control
PAN-OS natively classifies all traffic, including applications, threats, and content, tying them to the user regardless of location. App-ID and identity-based policies deliver precise Layer-7 control, safe SaaS access, and zero-trust segmentation without port-based guesswork.
Ideal Use Cases for the PA-5540-DC
- Internet Gateways and Data-Center Edges consolidating high-bandwidth threat prevention with 100G/400G connectivity.
- Service Provider POPs needing predictable, low-latency performance and massive session scale.
- 5G-Native and Encrypted Traffic Environments planning for PQC migration and requiring 5G identifier-based visibility.
- Enterprises standardizing on AI-assisted, centralized policy and lifecycle management to strengthen their security posture.
Technical Specifications at a Glance
- Firewall Throughput (AppMix): 150 Gbps
- Threat Prevention Throughput: 90 Gbps
- IPsec VPN Throughput: 80 Gbps
- Max Concurrent Sessions / New SPS: 39M / 1.33M
- Interfaces: 16 × 10/25G SFP28; 16 × 40/100G QSFP28; 4 × 100/400G QSFP-DD
- Form Factor & Airflow: 3U, front-to-back
- Power (DC Model): −40 to −60 VDC input, 2+2 redundant DC PSUs
- High Availability: NGFW clustering (Active/Active) and HA (Active/Passive)
Lock Down Your Edge with Headroom to Grow
Ready for quantum-safe futures and 400G fabrics, the Palo Alto Networks PA-5540-DC delivers the performance, visibility, and manageability modern, high-speed network edges demand.
Product Information
Product Information
Shipping & Returns
Shipping & Returns
Description
[shortdesc] 3U data-center NGFW, 150 Gbps FW, 90 Gbps Threat Prevention, 39M sessions, 100/400G ready, DC redundant PSUs [/shortdesc]
[properties]
| Model | PA-5540 |
| Product Type | Quantum Optimized Next-Generation Firewall (NGFW) |
| Operating System | PAN-OS |
| Firewall Throughput (appmix) | 150 Gbps |
| Threat Prevention Throughput (appmix) | 90 Gbps |
| IPsec VPN Throughput | 80 Gbps |
| Max Concurrent Sessions | 39 Million (39M) |
| New Sessions per Second | 1.33 Million (1.33M) |
| Virtual Systems (Base/Max) | 25 / 225 |
| Form Factor / Dimensions | 3U, 19” standard rack; 5.2” H × 29.8” D × 17.3” W |
| I/O Ports | 16× 10G/25G SFP28; 16× 40G/100G QSFP28; 4× 100G/400G QSFP-DD |
| Management I/O | 2× 1G/10G SFP+ (OOB Mgmt); RJ-45 console; USB-C console; USB 3.2 Gen1 Type-A (bootstrap); 2× 100G/400G QSFP-DD (HSCI); 2× 10G SFP+ (Log) |
| Storage | Optional 3.84 TB RAID1 SSD pair (cold swap) |
| Power Type | DC (Direct Current) |
| Input Voltage (DC) | −40 VDC to −60 VDC |
| Power Consumption (Avg/Max) | 2,100 W / 3,100 W |
| Power Supplies | 2+2 redundant for DC |
| Power Supply Output (DC) | 2,200 W per power supply |
| Max Current (DC) | 43.7 A @ 54 VDC |
| Thermal (Max BTU/hr) | 1638 |
| Airflow | Front to back (port side to power supply side) |
| Operating Temperature | 32 °F to 122 °F (0 °C to 50 °C) |
| Non-operating Temperature | −4 °F to 158 °F (−20 °C to 70 °C) |
| Humidity | 10%–90% |
| Maximum Altitude | 10,000 ft (3,048 m) |
| MTBF | 8.1 years |
| Safety / EMI | cTUVus, CB / FCC Class A, CE Class A, VCCI Class A |
[/properties]
[specifications]
| Interface Modes | L2, L3, tap, virtual wire (transparent) (L2 not available on MC-LAG aggregate interfaces) |
| Routing | Advanced routing engine; OSPFv2/v3, MP-BGP, RIP, static; policy-based forwarding; PPPoE, DHCP client; DHCPv4 server/relay; Multicast (PIM-SM/SSM, IGMPv2/v3); BFD & multihop BFD |
| Advanced SD-WAN | Path quality (jitter, loss, latency) measurement, bandwidth monitoring, manual/IKEv1/IKEv2 key exchange, post-quantum PPK, multi-VR/LR support over overlay, Prisma Access Hub, ADEM support |
| IPv6 | L2/L3/tap/virtual wire inspection; dual-stack & IPv6-only; IPv6 geolocation, OSPFv3, MP-BGP, NAT64, NPTv6; DHCPv6 client (PD) & SLAAC server |
| IPsec VPN | Manual, IKEv1/IKEv2; Encryption: 3DES, AES-128/192/256; Authentication: MD5, SHA-1/256/384/512; GlobalProtect Large Scale VPN; Secure access over IPsec/SSL VPN tunnels via GlobalProtect |
| VLANs / LAG | 802.1Q VLAN tags: 4,094 per device or per interface; 802.3ad aggregate interfaces & LACP |
| NAT | Static IP, dynamic IP, dynamic IP & port (PAT); NAT64, NPTv6; dynamic IP reservation, tunable dynamic IP, port oversubscription |
| High Availability / Clustering | NGFW clustering (active/active); HA active/passive |
| Mobile Network | 5G security (Future release; not supported with NGFW clustering) |
| Management | Managed with Strata™ Cloud Manager, the industry's first AI-powered unified management and operations solution. |
[/specifications]
[accesories]
| Included in the box (DC SKU) | 4× PAN-PA-5500-PWR-2000-DC; 5× PAN-PA-FAN-2RU-A; 1× PAN-PA-5500-ACC-B accessory kit; 1× PAN-PA-3RU-RACK-A; 2× PAN-SFP-CG; 1× PAN-PA-5500-SSD-3.84TB-PAIR |
| Spare – SSD Pair | PAN-PA-5500-SSD-3.84TB-PAIR (spare replacement drive) |
| Spare – Accessory Kit (AC) | PAN-PA-5500-ACC-A (includes 4× PAN-PWR-C19-US-120V cable, 1× USB cable, and 1× Cat6 cable) |
| Spare – Accessory Kit (DC) | PAN-PA-5500-ACC-B (includes 4× PAN-PWR-DC-CBL-C cable, 1× USB cable, and 1× Cat6 cable) |
[/accesories]
Solve High-Speed Edge Risk with Quantum-Ready Security
Growing east-west traffic, encrypted threats, and 100/400G uplinks put pressure on legacy edge firewalls. The Palo Alto Networks PA-5540-DC delivers data-center-class performance in a compact 3U chassis with Precision AI defenses and post-quantum cryptography readiness, giving you predictable security at scale without compromising throughput.
Key Benefits & Features
Quantum-Optimized & PQC-Ready NGFW
Designed as the world's first quantum-optimized Next-Generation Firewall (NGFW), the PA-5500 Series supports PQC use cases (PQC TLS decryption and PQC site-to-site VPN) and includes a PCIe slot for future PQ capabilities—ideal for long-lived data and compliance roadmaps.
Inline Prevention at Data-Center Speeds
Achieve 150 Gbps firewall throughput (AppMix) and 90 Gbps Threat Prevention, plus 80 Gbps IPsec VPN, 39M max concurrent sessions, and 1.33M new sessions per second—built for large east-west and internet edge workloads.
100/400G I/O for Modern Fabrics
Connect fabrics and spines with a high-density I/O of 16 × 10G/25G SFP28, 16 × 40G/100G QSFP28, and 4 × 100G/400G QSFP-DD ports; dedicated management and logging ports simplify operations.
Unified, AI-Powered Operations with Strata Cloud Manager
Operate at scale with Strata Cloud Manager, the industry's first AI-powered unified management solution. Leverage Strata Copilot for policy hygiene, anomaly detection, proactive issue resolution, and faster troubleshooting, unified across NGFW, SASE, and security services.
App- and User-Aware Control
PAN-OS natively classifies all traffic, including applications, threats, and content, tying them to the user regardless of location. App-ID and identity-based policies deliver precise Layer-7 control, safe SaaS access, and zero-trust segmentation without port-based guesswork.
Ideal Use Cases for the PA-5540-DC
- Internet Gateways and Data-Center Edges consolidating high-bandwidth threat prevention with 100G/400G connectivity.
- Service Provider POPs needing predictable, low-latency performance and massive session scale.
- 5G-Native and Encrypted Traffic Environments planning for PQC migration and requiring 5G identifier-based visibility.
- Enterprises standardizing on AI-assisted, centralized policy and lifecycle management to strengthen their security posture.
Technical Specifications at a Glance
- Firewall Throughput (AppMix): 150 Gbps
- Threat Prevention Throughput: 90 Gbps
- IPsec VPN Throughput: 80 Gbps
- Max Concurrent Sessions / New SPS: 39M / 1.33M
- Interfaces: 16 × 10/25G SFP28; 16 × 40/100G QSFP28; 4 × 100/400G QSFP-DD
- Form Factor & Airflow: 3U, front-to-back
- Power (DC Model): −40 to −60 VDC input, 2+2 redundant DC PSUs
- High Availability: NGFW clustering (Active/Active) and HA (Active/Passive)
Lock Down Your Edge with Headroom to Grow
Ready for quantum-safe futures and 400G fabrics, the Palo Alto Networks PA-5540-DC delivers the performance, visibility, and manageability modern, high-speed network edges demand.














