This release provides support for Per Security Policy-based Express Forwarding. This
feature is a low latency solution designed for high frequency trading in Financial
Technology environments where ultra-low latency is critical for operations. This
solution introduces an express forwarding path to select PA-5500 series firewalls,
allowing mission-critical traffic (like FIX protocol trading feeds) to bypass deep
buffer bottlenecks by significantly reducing latency. Specifically, it provides
security performance at low latency required by major financial institutions without
sacrificing the next generation firewall visibility required to protect such
environments. Security policy-based express forwarding:
- Achieves latency of sub 10 microseconds for hardware-offloaded packets.
- Introduces a pathway within the NGFW architecture express pass App-ID
overridden packets.
This feature is available on PA-5540, PA-5550,
PA-5560, PA-5570 and PA-5580.
You can configure Per Security Policy-based Express Forwarding using Panorama or
through the REST APIs. It requires no device reboots while providing explicit
logging and session flags for easy troubleshooting.