: PA-1500 Series Firewall Components
Focus
Focus

PA-1500 Series Firewall Components

Table of Contents

PA-1500 Series Firewall Components

View the components and descriptions of the PA-1500 Series firewall.
Refer to the following sections to view the front and back panel components of the PA-1500 Series firewalls.
To review the specifications of supported Palo Alto Networks® interfaces and transceivers, refer to the datasheet.

PA-1510-POE Components

View the front and back panel components and descriptions of the PA-1510-POE.
The following image shows the front panel of the PA-1510-POE and the table describes each front panel component.
Item
Component
Description
1
RJ-45 Ports
Twelve 1Gbps copper RJ-45 ports. Port 1 is used for Zero Touch Provisioning (ZTP).
Ports 5 through 20 are PoE (Power over Ethernet) ports that can each transfer up to 90W of power to a connected device. The maximum PoE budget is 485W. Refer to the PA-1500 Series Firewall Electrical Specifications for more information about the PoE ports.
Ports 3-4 and 5-6 are fail-open pairs. They can be configured to provide a pass-through connection despite power or operating system failure.
2
RJ-45 Ports
Eight 5Gbps copper RJ-45 ports.
3
SFP Ports
Four 1Gbps fiber SFP ports.
4
SFP+ Ports
Eight 10Gbps fiber SFP+ ports.
5
HSCI Port
One SFP+/SFP (10Gbps/1Gbps) port.
Use this port to connect two PA-1500 Series firewalls in a high availability (HA) configuration as follows:
  • In an active/passive configuration, this port is for HA2 (data link).
  • In an active/active configuration, you can configure this port for HA2 and HA3. HA3 is used for packet forwarding for asymmetrically routed sessions that require Layer 7 inspection for App-ID and Content-ID.
The HSCI ports must be connected directly between the two firewalls in the HA configuration (without a switch or router between them). When directly connecting the HSCI ports between two PA-1500 Series firewalls that are physically located near each other, Palo Alto Networks recommends that you use a passive SFP+ cable.
For installations where the two firewalls are not near each other and you cannot use a passive SFP+ cable, use a standard SFP+ transceiver and the appropriate cable length.
Do not assign an IP address to the HSCI port. The port carries raw Layer 1 traffic that is not routable or switchable and does not support IP addressing. Assigning an IP address to the HSCI port causes the firewall to enter a permanent suspended state.
For high-throughput deployments, do not use a 1Gbps copper interface for HA2. Use the HSCI port or a 10Gbps/40Gbps fiber interface to ensure sufficient bandwidth for HA data synchronization.
When you configure path monitoring, do not use your HA peer's data interface IP address as the monitored destination. Using the peer's IP address causes the firewall to incorrectly detect a path failure and trigger an unnecessary failover.
6
HA1-A and HA1-B ports
Two 1Gbps RJ-45 ports for high availability (HA) control.
If the firewall dataplane restarts due to a failure or manual restart, the HA1-B link will also restart. If this occurs and the HA1-A link is not connected and configured, then a split brain condition occurs. Therefore, we recommend that you connect and configure the HA1-A ports and the HA1-B ports to provide redundancy and to avoid split brain issues.
7
Console port (USB-C)
Use this port to connect a management computer to the firewall using a standard Type-C USB cable.
The console connection provides access to firewall boot messages, the Maintenance Recovery Tool (MRT), and the command line interface (CLI).
8
Console Port (RJ-45)
Use this port to connect a management computer to the firewall using a 9-pin serial-to-RJ-45 cable and terminal emulation software.
The console connection provides access to firewall boot messages, the Maintenance Recovery Tool (MRT), and the command line interface (CLI).
If your management computer does not have a serial port, use a USB-to-serial converter.
Use the following settings to configure your terminal emulation software to connect to the console port:
  • Data rate: 115,200
  • Data bits: 8
  • Parity: None
  • Stop bits: 1
  • Flow control: None
9
USB-A Port
One USB-A port used for debugging and administration only. Use it to bootstrap the firewall or perform self-service enhanced factory reset (EFR).
  • Bootstrapping enables you to provision the firewall with a specific PAN-OS configuration and then license it and make it operational on your network.
  • EFR provides remediation of a compromised or potentially compromised firewall to initiate a complete cleanup of the device.
10
Management Port
One 1Gbps RJ-45 Management port used to access the management web interface and perform administrative tasks. The firewall uses this port for management services, such as retrieving licenses and updating threat and application signatures.
11
Reset Button
A button that reboots the appliance.
12
LED Indicators
Nine LEDs that indicate the status of various hardware components. For details on the LEDs, see PA-1500 Series Firewall LED Definitions.
The following image shows the back panel of the PA-1510-POE and the table describes each back panel component.
Item
Component
Description
1
Fans
Six dual-rotor fans that provide the appliance with cooling and ventilation. The fans are not field replaceable.
The firewall is designed to continue operating even if one fan rotor has failed.
2
Ground Stud
A stud used to ground the appliance to earth ground.
3
Power Supplies
One power supply that provides AC or DC power to the appliance.

PA-1520-POE Components

View the front and back panel components and descriptions of the PA-1520-POE.
The following image shows the front panel of the PA-1520-POE and the table describes each front panel component.
Item
Component
Description
1
RJ-45 Ports
Eight 1Gbps copper RJ-45 ports. Port 1 is used for Zero Touch Provisioning (ZTP).
Ports 5 through 20 are PoE (Power over Ethernet) ports that can each transfer up to 90W of power to a connected device. The maximum PoE budget is 545W. Refer to the PA-1500 Series Firewall Electrical Specifications for more information about the PoE ports.
Ports 3-4 and 5-6 are fail-open pairs. They can be configured to provide a pass-through connection despite power or operating system failure.
2
RJ-45 Ports
Eight 5Gbps copper RJ-45 ports.
3
RJ-45 Ports
Four 10Gbps copper RJ-45 ports.
4
SFP+ Ports
Twelve 10Gbps fiber SFP+ ports.
5
HSCI Port
One SFP28/SFP+/SFP (25Gbps/10Gbps/1Gbps) port.
Use this port to connect two PA-1500 Series firewalls in a high availability (HA) configuration as follows:
  • In an active/passive configuration, this port is for HA2 (data link).
  • In an active/active configuration, you can configure this port for HA2 and HA3. HA3 is used for packet forwarding for asymmetrically routed sessions that require Layer 7 inspection for App-ID and Content-ID.
The HSCI ports must be connected directly between the two firewalls in the HA configuration (without a switch or router between them). When directly connecting the HSCI ports between two PA-1500 Series firewalls that are physically located near each other, Palo Alto Networks recommends that you use a passive SFP+ cable.
For installations where the two firewalls are not near each other and you cannot use a passive SFP+ cable, use a standard SFP+ transceiver and the appropriate cable length.
Do not assign an IP address to the HSCI port. The port carries raw Layer 1 traffic that is not routable or switchable and does not support IP addressing. Assigning an IP address to the HSCI port causes the firewall to enter a permanent suspended state.
For high-throughput deployments, do not use a 1Gbps copper interface for HA2. Use the HSCI port or a 10Gbps/40Gbps fiber interface to ensure sufficient bandwidth for HA data synchronization.
When you configure path monitoring, do not use your HA peer's data interface IP address as the monitored destination. Using the peer's IP address causes the firewall to incorrectly detect a path failure and trigger an unnecessary failover.
6
HA1-A and HA1-B ports
Two 1Gbps RJ-45 ports for high availability (HA) control.
If the firewall dataplane restarts due to a failure or manual restart, the HA1-B link will also restart. If this occurs and the HA1-A link is not connected and configured, then a split brain condition occurs. Therefore, we recommend that you connect and configure the HA1-A ports and the HA1-B ports to provide redundancy and to avoid split brain issues.
7
Console port (USB-C)
Use this port to connect a management computer to the firewall using a standard Type-C USB cable.
The console connection provides access to firewall boot messages, the Maintenance Recovery Tool (MRT), and the command line interface (CLI).
8
Console Port (RJ-45)
Use this port to connect a management computer to the firewall using a 9-pin serial-to-RJ-45 cable and terminal emulation software.
The console connection provides access to firewall boot messages, the Maintenance Recovery Tool (MRT), and the command line interface (CLI).
If your management computer does not have a serial port, use a USB-to-serial converter.
Use the following settings to configure your terminal emulation software to connect to the console port:
  • Data rate: 115,200
  • Data bits: 8
  • Parity: None
  • Stop bits: 1
  • Flow control: None
9
USB-A Port
One USB-A port used for debugging and administration only. Use it to bootstrap the firewall or perform self-service enhanced factory reset (EFR).
  • Bootstrapping enables you to provision the firewall with a specific PAN-OS configuration and then license it and make it operational on your network.
  • EFR provides remediation of a compromised or potentially compromised firewall to initiate a complete cleanup of the device.
10
Management Port
One 1Gbps RJ-45 Management port used to access the management web interface and perform administrative tasks. The firewall uses this port for management services, such as retrieving licenses and updating threat and application signatures.
11
Reset Button
A button that reboots the appliance.
12
LED Indicators
Nine LEDs that indicate the status of various hardware components. For details on the LEDs, see PA-1500 Series Firewall LED Definitions.
The following image shows the back panel of the PA-1520-POE and the table describes each back panel component.
Item
Component
Description
1
Fans
Six dual-rotor fans that provide the appliance with cooling and ventilation. The fans are not field replaceable.
The firewall is designed to continue operating even if one fan rotor has failed.
2
Ground Stud
A stud used to ground the appliance to earth ground.
3
Power Supplies
One power supply that provides AC or DC power to the appliance.

PA-1530-POE Components

View the front and back panel components and descriptions of the PA-1530-POE.
The following image shows the front panel of the PA-1530-POE and the table describes each front panel component.
Item
Component
Description
1
RJ-45 Ports
Eight 1Gbps copper RJ-45 ports. Port 1 is used for Zero Touch Provisioning (ZTP).
Ports 5 through 20 are PoE (Power over Ethernet) ports that can each transfer up to 90W of power to a connected device. The maximum PoE budget is 724W. Refer to the PA-1500 Series Firewall Electrical Specifications for more information about the PoE ports.
Ports 3-4 and 5-6 are fail-open pairs. They can be configured to provide a pass-through connection despite power or operating system failure.
2
RJ-45 Ports
Four 5Gbps copper RJ-45 ports.
3
RJ-45 Ports
Eight 10Gbps copper RJ-45 ports.
4
SFP+ Ports
Eight 10Gbps fiber SFP+ ports.
5
SFP28 Ports
Four 25Gbps fiber SFP28 ports.
6
HSCI Port
One SFP28/SFP+/SFP (25Gbps/10Gbps/1Gbps) port.
Use this port to connect two PA-1500 Series firewalls in a high availability (HA) configuration as follows:
  • In an active/passive configuration, this port is for HA2 (data link).
  • In an active/active configuration, you can configure this port for HA2 and HA3. HA3 is used for packet forwarding for asymmetrically routed sessions that require Layer 7 inspection for App-ID and Content-ID.
The HSCI ports must be connected directly between the two firewalls in the HA configuration (without a switch or router between them). When directly connecting the HSCI ports between two PA-1500 Series firewalls that are physically located near each other, Palo Alto Networks recommends that you use a passive SFP+ cable.
For installations where the two firewalls are not near each other and you cannot use a passive SFP+ cable, use a standard SFP+ transceiver and the appropriate cable length.
Do not assign an IP address to the HSCI port. The port carries raw Layer 1 traffic that is not routable or switchable and does not support IP addressing. Assigning an IP address to the HSCI port causes the firewall to enter a permanent suspended state.
For high-throughput deployments, do not use a 1Gbps copper interface for HA2. Use the HSCI port or a 10Gbps/40Gbps fiber interface to ensure sufficient bandwidth for HA data synchronization.
When you configure path monitoring, do not use your HA peer's data interface IP address as the monitored destination. Using the peer's IP address causes the firewall to incorrectly detect a path failure and trigger an unnecessary failover.
7
HA1-A and HA1-B ports
Two 1Gbps RJ-45 ports for high availability (HA) control.
If the firewall dataplane restarts due to a failure or manual restart, the HA1-B link will also restart. If this occurs and the HA1-A link is not connected and configured, then a split brain condition occurs. Therefore, we recommend that you connect and configure the HA1-A ports and the HA1-B ports to provide redundancy and to avoid split brain issues.
8
Console port (USB-C)
Use this port to connect a management computer to the firewall using a standard Type-C USB cable.
The console connection provides access to firewall boot messages, the Maintenance Recovery Tool (MRT), and the command line interface (CLI).
9
Console Port (RJ-45)
Use this port to connect a management computer to the firewall using a 9-pin serial-to-RJ-45 cable and terminal emulation software.
The console connection provides access to firewall boot messages, the Maintenance Recovery Tool (MRT), and the command line interface (CLI).
If your management computer does not have a serial port, use a USB-to-serial converter.
Use the following settings to configure your terminal emulation software to connect to the console port:
  • Data rate: 115,200
  • Data bits: 8
  • Parity: None
  • Stop bits: 1
  • Flow control: None
10
USB-A Port
One USB-A port used for debugging and administration only. Use it to bootstrap the firewall or perform self-service enhanced factory reset (EFR).
  • Bootstrapping enables you to provision the firewall with a specific PAN-OS configuration and then license it and make it operational on your network.
  • EFR provides remediation of a compromised or potentially compromised firewall to initiate a complete cleanup of the device.
11
Management Port
One 1Gbps RJ-45 Management port used to access the management web interface and perform administrative tasks. The firewall uses this port for management services, such as retrieving licenses and updating threat and application signatures.
12
Reset Button
A button that reboots the appliance.
13
LED Indicators
Nine LEDs that indicate the status of various hardware components. For details on the LEDs, see PA-1500 Series Firewall LED Definitions.
The following image shows the back panel of the PA-1530-POE and the table describes each back panel component.
Item
Component
Description
1
Fans
Six dual-rotor fans that provide the appliance with cooling and ventilation. The fans are not field replaceable.
The firewall is designed to continue operating even if one fan rotor has failed.
2
Ground Stud
A stud used to ground the appliance to earth ground.
3
Power Supplies
Two power supplies that provide AC or DC power to the appliance.
The power supplies are numbered 1 through 2 from left to right.