Palo Alto Networks PA-5550-AC Next-Gen Firewall 175 Gbps, Quantum-Optimized
[shortdesc]3U rack-mount, ML-powered NGFW, 175 Gbps FW, 120 Gbps threat prevention, 100 Gbps IPsec, 49M sessions[/shortdesc]
[properties]
| Model | PA-5550-AC |
| Product Type | Next-Generation Firewall (NGFW) |
| Firewall Throughput (App-mix) | 175 Gbps |
| Threat Prevention Throughput (App-mix) | 120 Gbps |
| IPsec VPN Throughput | 100 Gbps |
| Max Concurrent Sessions | 49,000,000 |
| New Sessions per Second | 1,670,000 |
| Virtual Systems (Base/Max) | 25 / 225 |
| I/O (Data Ports) | 16 × 10/25G SFP28; 16 × 40/100G QSFP28; 4 × 100/400G QSFP-DD |
| Management / Other I/O | 2 × 1G/10G SFP+ (OOB mgmt); RJ-45 console; USB-C console; USB 3.2 Type-A (bootstrap); 2 × HSCI 100/400G QSFP-DD; 2 × 10G SFP+ (Log) |
| Storage | Optional 3.84 TB RAID1 SSD pair (cold-swap) |
| Power (Avg/Max) | 2,100 W / 3,100 W |
| Power Supplies | AC: 2+2 redundant (220 V) or 3+1 (110 V) |
| Input Voltage | 100–240 VAC, 50–60 Hz |
| Max BTU/hr | 1638 |
| Rack Size / Dimensions | 3U, 19" rack; 5.2" H × 29.8" D × 17.3" W |
| Weight | 70 lb (standalone) / 116 lb (as shipped) |
| Operating Environment | 0–50 °C (32–122 °F); 10–90% RH; up to 10,000 ft (3,048 m) |
| Compliance | Safety: cTUVus, CB; EMI: FCC/CE/VCCI Class A |
[/properties]
[specifications]
| Routing & L3 Features | Advanced routing engine; OSPFv2/v3, MP-BGP, RIP, static; policy-based forwarding; multicast (PIM-SM/SSM, IGMPv2/v3); BFD & multihop BFD |
| Interface Modes | L2, L3, Tap, Virtual Wire (transparent) |
| IPv6 | Dual-stack & IPv6-only; IPv6 inspection (L2/L3/Tap/VWire); IPv6 geolocation, OSPFv3, MP-BGP, NAT64, NPTv6; DHCPv6 client (PD) & SLAAC server |
| VLANs | 802.1Q; 4,094 VLAN tags per device / per interface |
| NAT | Static, Dynamic IP, Dynamic IP & Port (PAT); NAT64, NPTv6; dynamic IP reservation & oversubscription |
| IPsec VPN | IKEv1/IKEv2, manual key; 3DES, AES-128/192/256; MD5, SHA-1/256/384/512; GlobalProtect LSVPN |
| SD-WAN | Path quality measurement (jitter/loss/latency), bandwidth monitoring; Prisma Access Hub (hybrid SASE); ADEM for NGFW |
| TLS/Decryption | Inspect SSL/TLS (SSLv3, TLS1.1–1.3); decrypt classical (RSA/ECDHE/DHE) & post-quantum KEX (ML-KEM, HQC; experimental BIKE/Frodo-KEM) |
| Post-Quantum Readiness | PQC for SSL/TLS decryption, site-to-site VPN, Cipher Translation Proxy; PQC algorithms inc. ML-KEM, ML-DSA, SLH-DSA; PCIe slot for future PQ |
| High Availability | NGFW clustering (active/active) with dual-active data plane & single control plane; HA active/passive |
| Management | Strata Cloud Manager with AI-powered operations; Strata Copilot assistant |
| MTBF | 8.1 years (PA-5540/PA-5550) |
| Certifications (Summary) | Safety: cTUVus, CB; EMI: FCC/CE/VCCI Class A |
[/specifications]
[accesories]
| Included (PAN-PA-5550-AC) | 4 × PAN-PA-5500-PWR-2700-AC; 5 × PAN-PA-FAN-2RU-A; 1 × PAN-PA-5500-ACC-A accessory kit; 1 × PAN-PA-3RU-RACK-A; 2 × PAN-SFP-CG; 1 × PAN-PA-5500-SSD-3.84TB-PAIR |
| Optional / Spares | PAN-PA-5500-SSD-3.84TB-PAIR (spare); PAN-PA-5500-ACC-A (spare kit with AC power cables, USB cable, Cat6); PAN-PA-5500-ACC-B (spare kit with DC cables, USB, Cat6) |
[/accesories]
High-Throughput, AI-Ready Protection for Core and Edge
The Palo Alto Networks PA-5550 secures high-speed data centers and internet gateways with ML-powered threat prevention and post-quantum readiness. Built on the PA-5500 Series architecture, it delivers predictable performance with single-pass processing and Precision AI to analyze and stop threats in real time.
Key Benefits & Features
The PA-5550 brings deep visibility, Layer 7 control, and inline prevention to environments that demand scale and resiliency. It supports post-quantum cryptography options, advanced URL and DNS defenses, and NGFW clustering for high availability.
Proven Performance at Scale
Handle growth confidently with 175 Gbps firewall throughput (appmix), 120 Gbps threat prevention, 100 Gbps IPsec VPN, 49 million concurrent sessions, and 1.67 million new sessions per second. These figures enable large east-west and north-south inspection without bottlenecks.
AI-Driven Prevention and L7 Visibility
Inline machine learning and App-ID provide accurate application identification and signatureless prevention against zero-day malware and phishing. Policies are enforced by user and application for precise control, improving security posture while reducing incident response time.
Post-Quantum Readiness
Prepare for future cryptographic shifts with support for PQC use cases across SSL/TLS inspection and VPN, including NIST algorithms such as ML-KEM and ML-DSA.
Operational Consistency and HA
Manage at scale through Strata Cloud Manager with AI-assisted insights, and deploy NGFW clustering for active-active scale and redundancy. The series also supports traditional HA.
Ideal Use Cases
- Data centers and internet edges that need high throughput with deep inspection.
- Service providers requiring large session capacity and resilient clustering.
- Enterprises consolidating security with AI-powered visibility and user-based policy.
Technical Specifications
- Throughput (appmix): 175 Gbps firewall, 120 Gbps threat prevention, 100 Gbps IPsec VPN
- Sessions: 49M max, 1.67M new sessions per second
- Form factor: 3U, front-to-back airflow, 19-inch rack, 5.2 in H x 29.8 in D x 17.3 in W
- Interface mix: 16 x 10/25G SFP28, 16 x 40/100G QSFP28, 4 x 100/400G QSFP-DD; 2 x 1G/10G SFP+ management; 2 x QSFP-DD HSCI; 2 x 10G SFP+ log
- Storage: Optional 3.84 TB RAID1 SSD pair for system and logs
- Power: Approx. 2100 W average, multi-supply redundancy options
- Management: Strata Cloud Manager, user-based policy, App-ID, URL and DNS security services
- Operating range: 0°C to 50°C, front-to-back airflow, MTBF ~8.1 years
Make Your Core Security Future-Ready
Upgrade to the PA-5550 for high-capacity, AI-powered protection with post-quantum options and resilient clustering.
Product Information
Product Information
Shipping & Returns
Shipping & Returns

Palo Alto Networks PA-5550-AC Next-Gen Firewall 175 Gbps, Quantum-Optimized
Palo Alto Networks PA-5550-AC Next-Gen Firewall 175 Gbps, Quantum-Optimized
[shortdesc]3U rack-mount, ML-powered NGFW, 175 Gbps FW, 120 Gbps threat prevention, 100 Gbps IPsec, 49M sessions[/shortdesc]
[properties]
| Model | PA-5550-AC |
| Product Type | Next-Generation Firewall (NGFW) |
| Firewall Throughput (App-mix) | 175 Gbps |
| Threat Prevention Throughput (App-mix) | 120 Gbps |
| IPsec VPN Throughput | 100 Gbps |
| Max Concurrent Sessions | 49,000,000 |
| New Sessions per Second | 1,670,000 |
| Virtual Systems (Base/Max) | 25 / 225 |
| I/O (Data Ports) | 16 × 10/25G SFP28; 16 × 40/100G QSFP28; 4 × 100/400G QSFP-DD |
| Management / Other I/O | 2 × 1G/10G SFP+ (OOB mgmt); RJ-45 console; USB-C console; USB 3.2 Type-A (bootstrap); 2 × HSCI 100/400G QSFP-DD; 2 × 10G SFP+ (Log) |
| Storage | Optional 3.84 TB RAID1 SSD pair (cold-swap) |
| Power (Avg/Max) | 2,100 W / 3,100 W |
| Power Supplies | AC: 2+2 redundant (220 V) or 3+1 (110 V) |
| Input Voltage | 100–240 VAC, 50–60 Hz |
| Max BTU/hr | 1638 |
| Rack Size / Dimensions | 3U, 19" rack; 5.2" H × 29.8" D × 17.3" W |
| Weight | 70 lb (standalone) / 116 lb (as shipped) |
| Operating Environment | 0–50 °C (32–122 °F); 10–90% RH; up to 10,000 ft (3,048 m) |
| Compliance | Safety: cTUVus, CB; EMI: FCC/CE/VCCI Class A |
[/properties]
[specifications]
| Routing & L3 Features | Advanced routing engine; OSPFv2/v3, MP-BGP, RIP, static; policy-based forwarding; multicast (PIM-SM/SSM, IGMPv2/v3); BFD & multihop BFD |
| Interface Modes | L2, L3, Tap, Virtual Wire (transparent) |
| IPv6 | Dual-stack & IPv6-only; IPv6 inspection (L2/L3/Tap/VWire); IPv6 geolocation, OSPFv3, MP-BGP, NAT64, NPTv6; DHCPv6 client (PD) & SLAAC server |
| VLANs | 802.1Q; 4,094 VLAN tags per device / per interface |
| NAT | Static, Dynamic IP, Dynamic IP & Port (PAT); NAT64, NPTv6; dynamic IP reservation & oversubscription |
| IPsec VPN | IKEv1/IKEv2, manual key; 3DES, AES-128/192/256; MD5, SHA-1/256/384/512; GlobalProtect LSVPN |
| SD-WAN | Path quality measurement (jitter/loss/latency), bandwidth monitoring; Prisma Access Hub (hybrid SASE); ADEM for NGFW |
| TLS/Decryption | Inspect SSL/TLS (SSLv3, TLS1.1–1.3); decrypt classical (RSA/ECDHE/DHE) & post-quantum KEX (ML-KEM, HQC; experimental BIKE/Frodo-KEM) |
| Post-Quantum Readiness | PQC for SSL/TLS decryption, site-to-site VPN, Cipher Translation Proxy; PQC algorithms inc. ML-KEM, ML-DSA, SLH-DSA; PCIe slot for future PQ |
| High Availability | NGFW clustering (active/active) with dual-active data plane & single control plane; HA active/passive |
| Management | Strata Cloud Manager with AI-powered operations; Strata Copilot assistant |
| MTBF | 8.1 years (PA-5540/PA-5550) |
| Certifications (Summary) | Safety: cTUVus, CB; EMI: FCC/CE/VCCI Class A |
[/specifications]
[accesories]
| Included (PAN-PA-5550-AC) | 4 × PAN-PA-5500-PWR-2700-AC; 5 × PAN-PA-FAN-2RU-A; 1 × PAN-PA-5500-ACC-A accessory kit; 1 × PAN-PA-3RU-RACK-A; 2 × PAN-SFP-CG; 1 × PAN-PA-5500-SSD-3.84TB-PAIR |
| Optional / Spares | PAN-PA-5500-SSD-3.84TB-PAIR (spare); PAN-PA-5500-ACC-A (spare kit with AC power cables, USB cable, Cat6); PAN-PA-5500-ACC-B (spare kit with DC cables, USB, Cat6) |
[/accesories]
High-Throughput, AI-Ready Protection for Core and Edge
The Palo Alto Networks PA-5550 secures high-speed data centers and internet gateways with ML-powered threat prevention and post-quantum readiness. Built on the PA-5500 Series architecture, it delivers predictable performance with single-pass processing and Precision AI to analyze and stop threats in real time.
Key Benefits & Features
The PA-5550 brings deep visibility, Layer 7 control, and inline prevention to environments that demand scale and resiliency. It supports post-quantum cryptography options, advanced URL and DNS defenses, and NGFW clustering for high availability.
Proven Performance at Scale
Handle growth confidently with 175 Gbps firewall throughput (appmix), 120 Gbps threat prevention, 100 Gbps IPsec VPN, 49 million concurrent sessions, and 1.67 million new sessions per second. These figures enable large east-west and north-south inspection without bottlenecks.
AI-Driven Prevention and L7 Visibility
Inline machine learning and App-ID provide accurate application identification and signatureless prevention against zero-day malware and phishing. Policies are enforced by user and application for precise control, improving security posture while reducing incident response time.
Post-Quantum Readiness
Prepare for future cryptographic shifts with support for PQC use cases across SSL/TLS inspection and VPN, including NIST algorithms such as ML-KEM and ML-DSA.
Operational Consistency and HA
Manage at scale through Strata Cloud Manager with AI-assisted insights, and deploy NGFW clustering for active-active scale and redundancy. The series also supports traditional HA.
Ideal Use Cases
- Data centers and internet edges that need high throughput with deep inspection.
- Service providers requiring large session capacity and resilient clustering.
- Enterprises consolidating security with AI-powered visibility and user-based policy.
Technical Specifications
- Throughput (appmix): 175 Gbps firewall, 120 Gbps threat prevention, 100 Gbps IPsec VPN
- Sessions: 49M max, 1.67M new sessions per second
- Form factor: 3U, front-to-back airflow, 19-inch rack, 5.2 in H x 29.8 in D x 17.3 in W
- Interface mix: 16 x 10/25G SFP28, 16 x 40/100G QSFP28, 4 x 100/400G QSFP-DD; 2 x 1G/10G SFP+ management; 2 x QSFP-DD HSCI; 2 x 10G SFP+ log
- Storage: Optional 3.84 TB RAID1 SSD pair for system and logs
- Power: Approx. 2100 W average, multi-supply redundancy options
- Management: Strata Cloud Manager, user-based policy, App-ID, URL and DNS security services
- Operating range: 0°C to 50°C, front-to-back airflow, MTBF ~8.1 years
Make Your Core Security Future-Ready
Upgrade to the PA-5550 for high-capacity, AI-powered protection with post-quantum options and resilient clustering.
Product Information
Product Information
Shipping & Returns
Shipping & Returns
Description
[shortdesc]3U rack-mount, ML-powered NGFW, 175 Gbps FW, 120 Gbps threat prevention, 100 Gbps IPsec, 49M sessions[/shortdesc]
[properties]
| Model | PA-5550-AC |
| Product Type | Next-Generation Firewall (NGFW) |
| Firewall Throughput (App-mix) | 175 Gbps |
| Threat Prevention Throughput (App-mix) | 120 Gbps |
| IPsec VPN Throughput | 100 Gbps |
| Max Concurrent Sessions | 49,000,000 |
| New Sessions per Second | 1,670,000 |
| Virtual Systems (Base/Max) | 25 / 225 |
| I/O (Data Ports) | 16 × 10/25G SFP28; 16 × 40/100G QSFP28; 4 × 100/400G QSFP-DD |
| Management / Other I/O | 2 × 1G/10G SFP+ (OOB mgmt); RJ-45 console; USB-C console; USB 3.2 Type-A (bootstrap); 2 × HSCI 100/400G QSFP-DD; 2 × 10G SFP+ (Log) |
| Storage | Optional 3.84 TB RAID1 SSD pair (cold-swap) |
| Power (Avg/Max) | 2,100 W / 3,100 W |
| Power Supplies | AC: 2+2 redundant (220 V) or 3+1 (110 V) |
| Input Voltage | 100–240 VAC, 50–60 Hz |
| Max BTU/hr | 1638 |
| Rack Size / Dimensions | 3U, 19" rack; 5.2" H × 29.8" D × 17.3" W |
| Weight | 70 lb (standalone) / 116 lb (as shipped) |
| Operating Environment | 0–50 °C (32–122 °F); 10–90% RH; up to 10,000 ft (3,048 m) |
| Compliance | Safety: cTUVus, CB; EMI: FCC/CE/VCCI Class A |
[/properties]
[specifications]
| Routing & L3 Features | Advanced routing engine; OSPFv2/v3, MP-BGP, RIP, static; policy-based forwarding; multicast (PIM-SM/SSM, IGMPv2/v3); BFD & multihop BFD |
| Interface Modes | L2, L3, Tap, Virtual Wire (transparent) |
| IPv6 | Dual-stack & IPv6-only; IPv6 inspection (L2/L3/Tap/VWire); IPv6 geolocation, OSPFv3, MP-BGP, NAT64, NPTv6; DHCPv6 client (PD) & SLAAC server |
| VLANs | 802.1Q; 4,094 VLAN tags per device / per interface |
| NAT | Static, Dynamic IP, Dynamic IP & Port (PAT); NAT64, NPTv6; dynamic IP reservation & oversubscription |
| IPsec VPN | IKEv1/IKEv2, manual key; 3DES, AES-128/192/256; MD5, SHA-1/256/384/512; GlobalProtect LSVPN |
| SD-WAN | Path quality measurement (jitter/loss/latency), bandwidth monitoring; Prisma Access Hub (hybrid SASE); ADEM for NGFW |
| TLS/Decryption | Inspect SSL/TLS (SSLv3, TLS1.1–1.3); decrypt classical (RSA/ECDHE/DHE) & post-quantum KEX (ML-KEM, HQC; experimental BIKE/Frodo-KEM) |
| Post-Quantum Readiness | PQC for SSL/TLS decryption, site-to-site VPN, Cipher Translation Proxy; PQC algorithms inc. ML-KEM, ML-DSA, SLH-DSA; PCIe slot for future PQ |
| High Availability | NGFW clustering (active/active) with dual-active data plane & single control plane; HA active/passive |
| Management | Strata Cloud Manager with AI-powered operations; Strata Copilot assistant |
| MTBF | 8.1 years (PA-5540/PA-5550) |
| Certifications (Summary) | Safety: cTUVus, CB; EMI: FCC/CE/VCCI Class A |
[/specifications]
[accesories]
| Included (PAN-PA-5550-AC) | 4 × PAN-PA-5500-PWR-2700-AC; 5 × PAN-PA-FAN-2RU-A; 1 × PAN-PA-5500-ACC-A accessory kit; 1 × PAN-PA-3RU-RACK-A; 2 × PAN-SFP-CG; 1 × PAN-PA-5500-SSD-3.84TB-PAIR |
| Optional / Spares | PAN-PA-5500-SSD-3.84TB-PAIR (spare); PAN-PA-5500-ACC-A (spare kit with AC power cables, USB cable, Cat6); PAN-PA-5500-ACC-B (spare kit with DC cables, USB, Cat6) |
[/accesories]
High-Throughput, AI-Ready Protection for Core and Edge
The Palo Alto Networks PA-5550 secures high-speed data centers and internet gateways with ML-powered threat prevention and post-quantum readiness. Built on the PA-5500 Series architecture, it delivers predictable performance with single-pass processing and Precision AI to analyze and stop threats in real time.
Key Benefits & Features
The PA-5550 brings deep visibility, Layer 7 control, and inline prevention to environments that demand scale and resiliency. It supports post-quantum cryptography options, advanced URL and DNS defenses, and NGFW clustering for high availability.
Proven Performance at Scale
Handle growth confidently with 175 Gbps firewall throughput (appmix), 120 Gbps threat prevention, 100 Gbps IPsec VPN, 49 million concurrent sessions, and 1.67 million new sessions per second. These figures enable large east-west and north-south inspection without bottlenecks.
AI-Driven Prevention and L7 Visibility
Inline machine learning and App-ID provide accurate application identification and signatureless prevention against zero-day malware and phishing. Policies are enforced by user and application for precise control, improving security posture while reducing incident response time.
Post-Quantum Readiness
Prepare for future cryptographic shifts with support for PQC use cases across SSL/TLS inspection and VPN, including NIST algorithms such as ML-KEM and ML-DSA.
Operational Consistency and HA
Manage at scale through Strata Cloud Manager with AI-assisted insights, and deploy NGFW clustering for active-active scale and redundancy. The series also supports traditional HA.
Ideal Use Cases
- Data centers and internet edges that need high throughput with deep inspection.
- Service providers requiring large session capacity and resilient clustering.
- Enterprises consolidating security with AI-powered visibility and user-based policy.
Technical Specifications
- Throughput (appmix): 175 Gbps firewall, 120 Gbps threat prevention, 100 Gbps IPsec VPN
- Sessions: 49M max, 1.67M new sessions per second
- Form factor: 3U, front-to-back airflow, 19-inch rack, 5.2 in H x 29.8 in D x 17.3 in W
- Interface mix: 16 x 10/25G SFP28, 16 x 40/100G QSFP28, 4 x 100/400G QSFP-DD; 2 x 1G/10G SFP+ management; 2 x QSFP-DD HSCI; 2 x 10G SFP+ log
- Storage: Optional 3.84 TB RAID1 SSD pair for system and logs
- Power: Approx. 2100 W average, multi-supply redundancy options
- Management: Strata Cloud Manager, user-based policy, App-ID, URL and DNS security services
- Operating range: 0°C to 50°C, front-to-back airflow, MTBF ~8.1 years
Make Your Core Security Future-Ready
Upgrade to the PA-5550 for high-capacity, AI-powered protection with post-quantum options and resilient clustering.














