Page 5
PA‐5200 Series Firewall Overview Front Panel Description Item Component (Continued) Description HSCI port These ports vary depending on your firewall model: • PA‐5220 firewall—One QSFP+ 40Gbps port (supports only a 40Gbps (QSFP+) transceiver or QSFP+ active optical cable). • PA‐5250 and PA‐5260 firewalls—One QSFP28 40/100Gbps port (supports 40Gbps (QSFP+) or 100Gbps transceiver (QSFP28) or equivalent active optical cables). The link speed is based on the installed transceiver. Use this port to connect two PA‐5200 Series firewalls in a high availability (HA) configuration as follows: • In an active/passive configuration, this port is for HA2 (data link). • In an active/active configuration, you can configure this port for HA2 and/or HA3. HA3 is used for packet forwarding for asymmetrically routed sessions that require Layer 7 inspection for App‐ID™ and Content‐ID™. The HSCI ports must be connected directly between the two firewalls in the HA configuration (not between a network switch or router). When directly connecting the HSCI ports between two PA‐5220 firewalls that are physically located near each other, Palo Alto Networks recommends that you use a 40Gbps QSFP+ Active Optical Cable (AOC). When directly connecting two PA‐5250 or two PA‐5260 firewalls, use either a 40Gbps QSFP+ Active Optical Cable (AOC) or a 100Gbps QSFP28 Active Optical Cable (AOC). For installations where the two firewalls are not near each other and you cannot use an AOC cable, use a standard 40Gbps or 100Gbps transceivers and the appropriate cable length. AUX 1 and AUX 2 ports Use these SFP+ ports for HA1, management functions, or log forwarding to Panorama. For information on configuring the port, refer to the on‐device Help content in Device > Setup > Interfaces or refer to the PAN‐OS 8.0 Web Interface ...
Page 6
Front Panel Description PA‐5200 Series Firewall Overview Item Component (Continued) Description CONSOLE port Use this port to connect a management computer to the firewall using a 9‐pin serial to RJ‐45 cable and terminal emulation software. (RJ‐45) The console connection provides access to firewall boot messages, the Maintenance Recovery Tool (MRT), and the command line interface (CLI). If your management computer does not have a serial port, use a USB‐to‐serial converter. Cable Pin‐outs Signal: DB‐9/RJ45 CTS: 8/8 DSR: 6/7 RXD: 2/6 GND: 5/5,4 TXD: 3/3 DTR: 4/2 RTS: 7/1 Serial Settings Data rate: 9600 Data bits: 8 Parity: none Stop bits: 1 Flow control: None USB port Use this port to bootstrap the firewall. Bootstrapping enables you to provision the firewall with a specific PAN‐OS configuration and then license it and make it operational on your network. MGT port Use this Ethernet 10/100/1000Mbps port to access the management web interface and perform administrative tasks. The firewall also uses this port for management services, such as retrieving licenses and updating the threat and application signatures. LED status indicators Five LEDs that indicate the status of the firewall hardware components (see Interpret the LEDs on a PA‐5200 Series Firewall). Intake air filters Two filters for air entering the firewall.
Need help?
Do you have a question about the PA-5200 Series and is the answer not in the manual?
Questions and answers