Platform — Network Security
Strata
Network Security Platform
ML-powered next-generation firewalls from branch to data center, managed through a single cloud-native control plane.
Hardware
NGFW Hardware Lineup
Purpose-built appliances for every deployment — from the smallest branch to the largest hyperscale data center. Click any card to explore details.
- FE400 custom ASIC
- 1.5+ Tbps App-ID performance
- 400M+ concurrent L7 sessions
- Quantum-ready architecture
Key Specs
| Metric | Value |
|---|---|
| FW Throughput (App-ID) | >1.5 Tbps |
| Threat Prevention | 1,440 Gbps |
| Max Sessions | 440 million |
| Form Factor | 14U modular chassis |
| ASIC | Custom FE400 (5th gen) |
| Concurrent L7 Sessions | 400M+ |
| Ports (per NPC) | 8× QSFP-DD (400G) + 12× SFP-DD |
| HA | Active/passive + A/A clustering |
Target Deployment
Large enterprise data centers, hyperscale internet gateway, service providers, high-bandwidth network perimeters requiring 400G+ interfaces.
Why Customers Choose This
- World's first NGFW on the FE400 ASIC — highest performance in the industry
- Full L7 inspection across all 1.5 Tbps — no bypass
- Hardware-accelerated PQC: ML-KEM, ML-DSA, SLH-DSA
- 440M concurrent sessions for carrier/hyperscale scale
Refresh Path
Replaces: PA-7000 Series
PA-7000 EOS: Dec 31, 2025. EoL: Dec 31, 2030. Customers on PA-7050/PA-7080 face end-of-sale now. PA-7500 delivers ~3–4× throughput improvement vs PA-7080. Same PAN-OS policies transfer via Panorama/SCM template migration.
Competitive Notes
vs. Fortinet 7000: Full L7 inspection across all throughput; FortiGate offloads to SPU ASICs, bypassing inspection.
vs. Check Point Quantum: Native ML-based threat prevention at hyperscale; CP requires separate IPS appliances at this throughput.
vs. Cisco Firepower 9300: No single-chassis solution matching 1.5 Tbps with full App-ID.
- FE400 ASIC
- Up to 300 Gbps threat performance
- Post-quantum encrypted traffic visibility
- Enterprise data center form factor
Models & Specs
| Model | FW | Threat | Sessions |
|---|---|---|---|
| PA-5540 | 150 Gbps | 90 Gbps | ~66M |
| PA-5550 | 175 Gbps | 120 Gbps | ~80M |
| PA-5560 | 240 Gbps | 180 Gbps | ~90M |
| PA-5570 | 300 Gbps | 240 Gbps | ~95M |
| PA-5580 | 375 Gbps | 300 Gbps | 99M |
3RU fixed config · PAN-OS 12.1.2 or later (current train: PAN-OS 12.2 "Ceres") · Up to 25 vSystems · Up to eight 400G interfaces · FE-400 ASIC
Target & Selling Motion
High-speed enterprise data centers, internet gateway, service provider edge, large campus segmentation.
- Up to 300 Gbps threat and 375 Gbps App-ID — up to 4× the threat performance of the PA-5400 Series
- Only NGFW with hardware-accelerated PQC at 300 Gbps threat throughput
- Single-pass architecture — no throughput degradation with all CDSS enabled
- 3RU delivers more throughput-per-rack-unit than modular competitors
- NGFW clustering (A/A) for scale-out deployments
Refresh Path
Replaces: PA-5200 Series
PA-5200 EOS: Aug 31, 2023. EoL: Aug 31, 2028. PA-5500 vs PA-5280: ~5–8× threat prevention improvement. Quantum compliance mandates (NIST PQC 2024) create urgency. Use the Quantum Readiness Dashboard in SCM to show PQC gaps.
Competitive Notes
vs. Fortinet 4800F: Tops out at ~198 Gbps with fewer PQC algorithms.
vs. Check Point: Single-pass vs multi-pass — no throughput degradation when CDSS enabled.
- 150 Gbps threat performance
- End-of-Sale Nov 22, 2026 → PA-5500 Series
- Supported to Nov 21, 2031 · last OS PAN-OS 12.2
Key Specs
| Config | FW | Threat | Sessions |
|---|---|---|---|
| Single DPC | 75 Gbps | 55 Gbps | 20M |
| Full (2 NIC + 4 DPC) | 200 Gbps | 189 Gbps | 100M |
Modular chassis · Up to 225 vSystems · PAN-OS 10.2 or later; last supported release PAN-OS 12.2
Target & Why Choose
Hyperscale data center, internet edge, large enterprise campus segmentation. Mid-tier hyperscale between PA-5400 and PA-7500.
- 189 Gbps threat prevention — 4× the PA-5260
- Modular design: start small, expand by adding DPC cards
- New SWG proxy mode support (Aug 2025)
- Prisma SD-WAN Data Center anchor integration
Positioning — End-of-Sale
PA-5450 EOS: Nov 22, 2026. EoL: Nov 21, 2031. Last supported OS: PAN-OS 12.2. Replaced by the PA-5500 Series. Do not quote PA-5450 for net-new after Nov 22, 2026 — position PA-5500 Series instead. Existing PA-5450 estates are supported to Nov 21, 2031, so frame the conversation as a planned migration, not an emergency.
- PA-5445 delivers 2.5x vs PA-5260
- Compact 2RU form factor
- Enterprise DC edge deployment
Key Specs (PA-5440)
| Metric | Value |
|---|---|
| FW Throughput (appmix) | ~96 Gbps |
| Threat Prevention | ~80 Gbps |
| Max Sessions | ~64M |
| Form Factor | 2RU fixed |
Models: PA-5410, PA-5420, PA-5430, PA-5440
Target & Selling Motion
Enterprise data centers, internet gateway, campus segmentation. Direct like-for-like 2RU replacement for PA-5220/5250.
- PA-5440 delivers 2.5× threat prevention vs PA-5260
- Fixed-form 2RU for customers preferring non-modular
- Recommended by PAN as PA-5000/5200 replacement
Refresh Path
Replaces: PA-5200 / PA-5000 Series
PA-5200 EOS: Aug 31, 2023. PA-5000 already past EoL (Jan 31, 2024 — critical risk). Strong choice when fixed 2RU is preferred over modular PA-5450.
- Mid-range enterprise performance
- Campus and regional DC
- Full App-ID and threat prevention
Models & Specs
| Model | FW | Threat | Sessions |
|---|---|---|---|
| PA-3410 | 11.3 Gbps | ~5 Gbps | ~5.5M |
| PA-3420 | 16.5 Gbps | ~7 Gbps | ~7M |
| PA-3430 | 19.6 Gbps | ~10 Gbps | ~9M |
| PA-3440 | 24 Gbps | ~13 Gbps | ~11M |
1RU · 100G QSFP28 uplinks · 480 GB SSD · Up to 11 vSystems
Target & Why Choose
High-speed internet gateway, mid-enterprise network perimeter, data center aggregation, campus core.
- 1RU with 100G QSFP28 — Fortinet FortiGate 600G needs 2RU
- Deep App-ID across all 27.5 Gbps — no bypass
- BFD and multihop BFD for advanced routing
- ZTP for zero-touch deployment
Refresh Path
Replaces: PA-3200 / PA-3000 Series
PA-3200 EOS: Aug 31, 2023. EoL: Aug 31, 2028. PA-3000 already past EoL (Jan 2024). Customers on PA-3200s are in active compliance/support risk. PA-3440 delivers significantly higher throughput in 1RU vs PA-3260 in 2RU.
- PoE support
- Virtual systems (VSYS)
- mGig and fiber connectivity
Models & Specs
| Model | FW | Threat | Sessions |
|---|---|---|---|
| PA-1410 | 8.5 Gbps | 4.5 Gbps | 945K |
| PA-1420 | 9.5 Gbps | 6.2 Gbps | 1.4M |
1RU · PoE 151W budget · 10G SFP+ uplinks · Up to 6 vSystems
Target & Why Choose
Smaller campus, large distributed enterprise branches, midsize businesses.
- PoE support (151W) for IP phones, cameras, APs
- UEFI Secure Boot + TPM for key storage
- Multi-Gig ports up to 10G
- ZTP via SCM or Panorama
Refresh Path
Replaces: PA-800 Series
PA-820/PA-850 approaching EOL. PA-1400 adds PoE + 10G SFP+ uplinks that PA-800 cannot match. Future-proofing through higher port speed and PAN-OS 12.2 "Ceres" PQC support.
- Up to 24 high-speed ports
- 330W PoE budget
- ZTP on Strata Cloud Manager
- Modern enterprise branch deployment
Full Model Lineup
| Model | FW | Threat | Sessions |
|---|---|---|---|
| PA-505 | 1.2 Gbps | 0.8 Gbps | 64K |
| PA-510 | 1.8 Gbps | ~1.2 Gbps | 98K |
| PA-520 | 2.8 Gbps | 1.8 Gbps | 148K |
| PA-540 | 3.8 Gbps | 2.2 Gbps | 248K |
| PA-545-POE | 5.0 Gbps | 3 Gbps | 298K |
| PA-550 | 6.5 Gbps | ~5 Gbps | 398K |
| PA-555-POE | 7.5 Gbps | ~6 Gbps | 448K |
| PA-560 | 8.5 Gbps | 6 Gbps | 598K |
Desktop/1U · PAN-OS 12.1.2 or later (current train: PAN-OS 12.2 "Ceres") · PoE up to 330 W · up to 24 high-speed ports · ZTP via Strata Cloud Manager · A/A HA
Target & Why Choose
Modern enterprise branch, retail, MSPs. Fills the gap between PA-400 and PA-1400.
- 8 models covering 0.8–6 Gbps threat prevention — no coverage gaps
- Up to 2× PA-400 Series performance
- PA-555-POE: 330W PoE — unmatched for branch with cameras/APs
- Fail-to-wire on select models for critical uptime
- Full CDSS + Precision AI at the branch, not "lite"
- ZTP simplifies large-scale branch rollouts
Refresh Path
Replaces: PA-220 / PA-200
PA-220 EOS: Jan 31, 2023. EoL: Jan 31, 2028. Customers on PA-220 are on expired hardware. PA-500 delivers 6–8× throughput while adding PoE, fail-to-wire, and PAN-OS 12.2 "Ceres" features.
Competitive Notes
vs. Fortinet: 8 models covering 1.2–8.5 Gbps vs Fortinet coverage gaps in this range. Full CDSS at branch, not a "lite" tier.
- PA-415-5G with cellular connectivity
- PA-455 for standard small branch
- Compact and fanless options
Models & Specs
| Model | FW | Threat | Sessions |
|---|---|---|---|
| PA-410 | 1.1 Gbps | 0.68 Gbps | 64K |
| PA-415 | 1.2 Gbps | 0.69 Gbps | 64K |
| PA-440 | 2.2 Gbps | 1.0 Gbps | 200K |
| PA-450 | 2.9 Gbps | 1.6 Gbps | 300K |
| PA-460 | 4.4 Gbps | 2.4 Gbps | 400K |
Desktop · Fanless on PA-410/415 · 5G models: PA-415-5G, PA-455-5G
Target & Why Choose
Distributed enterprise branches, retail, SMB HQ, home-office/satellite sites.
- 5G models (PA-415-5G, PA-455-5G) for cellular WAN
- Fanless PA-410/415 for silent open-office use
- Active/active HA — unique for this form factor
- ZTP for large-scale deployment automation
- Full ML-NGFW capabilities inline
Refresh Path
Replaces: PA-200 / PA-220
PA-200 EOL: Dec 31, 2019. PA-220 EOS: Jan 31, 2023. 10× performance increase vs PA-220. 5G models address SD-WAN / cellular backup that PA-220 cannot. Full ML-NGFW vs PA-220's legacy signature-only engine.
- IP65-rated, fanless enclosure
- −40 °C to 70 °C operating range
- 5G models for remote OT sites
- 150 W PoE budget
Models & Environmentals
- PA-410R, PA-410R-5G, PA-450R, PA-450R-5G, PA-455R-5G
- IP65 ingress protection — dust and water jets
- Operating range −40 °C to 70 °C
- Up to 150 W PoE for cameras, sensors, industrial APs
- 5G variants for sites with no wired WAN
Target & Why Choose
Substations, water and wastewater plants, mining, oil and gas, rail, manufacturing cells, outdoor and unconditioned spaces.
- Same PAN-OS, same policy, same App-ID as the data center — one policy model across IT and OT
- IoT/OT Security subscription for asset discovery and OT protocol visibility
- PAN-OS 12.2 adds proactive OT microsegmentation
- Managed with the rest of the fleet in Strata Cloud Manager, ZTP for unstaffed sites
Positioning
This is the current ruggedized answer for OT and critical infrastructure. K2-Series is end-of-life (Feb 28, 2026) and must not be quoted. For 5G-first industrial sites also scope the new PA-50R family.
- Announced Aug 2026 at Black Hat
- Ruggedized 5G family for OT sites
- Model numbers and throughput not yet published
What Is Confirmed
- New ruggedized 5G NGFW family for OT and critical infrastructure
- Announced Aug 4, 2026 as part of the Black Hat network security launch
- Individual model numbers, throughput figures and environmentals are not yet published
Do not quote PA-50R performance numbers until the datasheet publishes — use PA-400R figures for sizing conversations.
How To Use It Now
- Use it to hold the OT/5G opportunity open where a customer would otherwise buy a competitor's industrial box
- Where the deal must close now, quote PA-400R (including PA-455R-5G) and flag PA-50R as the roadmap item
- Pair with IoT/OT Security and PAN-OS 12.2 proactive OT microsegmentation in the same conversation
- Software NGFW for cloud and virtualization
- AWS, Azure, GCP, private cloud
- Consistent security policy everywhere
Models & Specs
| Model | App-ID FW | Use Case |
|---|---|---|
| VM-50/Lite | 200 Mbps | Multi-tenant, minimal |
| VM-100 | 2 Gbps | Hybrid cloud, gateway |
| VM-300 | 4 Gbps | Hybrid cloud, segment. |
| VM-500 | 8 Gbps | Large enterprise, NFV |
| VM-700 | 16 Gbps | Hyperscale virtual DC |
AWS, Azure, GCP, OCI, VMware, KVM, Hyper-V, Nutanix · PAYG + BYOL
Software NGFW Credits
- Credits remain the licensing model (reconfirmed June 19, 2026) — one credit pool funds VM-Series, CN-Series, CDSS and virtual Panorama, and now also funds Prisma AIRS
- Fixed vCPU or Flexible vCPU licences; max 64 vCPUs per deployment profile
- Credits are reclaimable when a deployment is torn down
- 1–5 year terms
Why Choose
- Identical PAN-OS as hardware — true policy parity
- Consistent App-ID inspection (vs Fortinet NP7 ASIC bypass in VM deployments)
- PAYG in cloud marketplaces — low barrier to entry
- Full CDSS in cloud-native deployments
- Managed by SCM alongside hardware NGFWs
Competitive Notes
vs. Fortinet VM: Consistent App-ID vs NP7 bypass model. In VM deployments, PAN's consistent inspection is a key advantage.
vs. Check Point CloudGuard: VM-Series runs identical PAN-OS as hardware; CP has feature gaps between hardware and cloud.
vs. Cisco FTDv: Full App-ID, User-ID, Content-ID in the VM; Cisco lacks App-ID equivalence.
AI / Kubernetes Path
A "Migrate VM-Series to AI Runtime Firewall" path shipped June 2026. For AI workloads and Kubernetes, position AI Runtime Firewall (Prisma AIRS) rather than CN-Series, which is end-of-sale Nov 1, 2026. VM-Series itself is not end-of-sale.
- End-of-Sale Nov 1, 2026
- Replaced by AI Runtime Firewall (Prisma AIRS)
- Kubernetes-native NGFW — installed base only
Architecture
- Industry's first ML-Powered NGFW built natively for K8s
- Deployed as Kubernetes DaemonSet — scales with nodes
- Full L7 visibility using K8s labels/namespaces
- Supports GKE, EKS, AKS, OpenShift, on-prem K8s
- Metadata-driven policy — no IP-based rules needed
Why Choose
Secures east-west traffic between pods, outbound traffic to internet/C2, and encrypted SSL from containers.
- Fortinet has no native K8s container firewall
- Calico/Cilium provide no L7 inspection or threat prevention
- Full CDSS subscriptions available
- Managed by SCM alongside hardware NGFWs
Stop Selling — Positioning Change
CN-Series is end-of-sale Nov 1, 2026 and is explicitly replaced by AI Runtime Firewall (AIRS). Do not open new Kubernetes opportunities on CN-Series. Existing CN-Series and VM-Series customers use the "Migrate VM-Series to AI Runtime Firewall" path that shipped June 2026. Both CN-Series and Prisma AIRS draw on the same Software NGFW Credits pool, so a customer with credits can move without a new purchase order.
- End-of-Life Feb 28, 2026
- Replacements: PA-5445, PA-7500
- For ruggedized OT use PA-400R / PA-50R
Architecture (Historical)
- Purpose-built for mobile network infrastructure (4G/5G, IoT, MEC) — installed base only
- Express Mode (high-throughput GTP) or Secure Mode (full NGFW)
- Natively parses GTP for 5G subscriber identity visibility
- Per-subscriber policy: IMSI, MSISDN, APN, QoS class
- 5G N-series interface inspection (Gi/SGi, N3, N6, N4)
What To Sell Instead
K2-Series reached End-of-Life on Feb 28, 2026. It is not a current platform for OT, industrial or mobile-core deals and must be removed from any proposal.
- Mobile core / high-throughput: PA-5445 or PA-7500 — the named replacements
- Ruggedized OT and industrial sites: PA-400R Series, plus the new PA-50R ruggedized 5G family
- OT visibility and segmentation: IoT/OT Security subscription with PAN-OS 12.2 proactive OT microsegmentation
- Customers still running K2 are on unsupported hardware — lead with the risk, not the feature comparison
Software
PAN-OS 12.2 "Ceres"
Released July 30, 2026 and launched publicly Aug 4, 2026 at Black Hat. Newest maintenance release observed: 12.2.2. PAN-OS 12.1 "Orion" (Aug 28, 2025) remains the prior supported train.
What's New in 12.2
Also in 12.2: redesigned MICA cloud transport (12.2.2), HTTP header logging, automatic certificate renewal for passive HA peers, SD-WAN bandwidth as a path-quality metric.
PAN-OS Support Status — Current vs. End-of-Life
| Release | Status | Date |
|---|---|---|
| 12.2 "Ceres" | Current — supported | EOL Jul 30, 2029 |
| 12.1 "Orion" | Supported (prior train) | EOL Aug 28, 2028 |
| 11.2 | Supported | EOL May 2, 2027 |
| 11.1 | Supported | EOL May 3, 2027 |
| 11.0 | End-of-life | — |
| 10.2 | End-of-life | EOL Aug 27, 2025 |
| 10.1 | End-of-life | — |
| 9.1 | End-of-life | — |
Any customer still on 11.0, 10.2, 10.1 or 9.1 is unsupported — that is the opening for a software upgrade plus hardware refresh conversation.
Launched Aug 4, 2026
Black Hat 2026 Network Security Launch
55+ innovations announced Aug 4, 2026 across PAN-OS 12.2, two new protection engines, six AI agents in Strata Cloud Manager, and the 5th-generation hardware envelope.
Advanced Virtual Patching
NewFrontier-AI vulnerability discovery feeding a "vaulted protection" detection engine. Positioned as collapsing the industry-average 55-day exposure window between disclosure and patch. Sell it to customers whose change-control cycle is the real reason they stay exposed.
Licensing and SKU detail are not yet published — do not quote a price or a subscription name.
Advanced IP Defense
GA Aug 4, 2026New cloud-delivered security subscription. Zero-trust IP enforcement built on telemetry from 70,000+ customers, using DNS-resolution validation plus 40+ security attributes. Blocks command-and-control that bypasses DNS and URL inspection — without requiring TLS decryption, so it lands in accounts that refuse to decrypt.
Enforced via an Advanced IP Defense profile attached to a zone. Requires its own Advanced IP Defense licence.
Six Network Security Agents
Via SCMSix AI-powered Network Security Agents delivered through Strata Cloud Manager. Each runs in a chosen autonomy mode — human-in-the-loop (agent proposes, admin approves), human-on-the-loop (agent acts, admin supervises) or human-out-of-the-loop (fully autonomous). The autonomy-mode question is the governance conversation to have with the network team.
5th-Gen Hardware Envelope
400G interfaces, 300 Gbps threat inspection, active clustering to 1.4 Tbps, and 5-microsecond latency. Delivered by the FE400/FE-400 ASIC across PA-7500 and PA-5500 Series. Also announced: the PA-50R ruggedized 5G family for OT and critical infrastructure.
NOVA, the Network and Open-Source Vulnerability Analyzer, found 14,090 confirmed vulnerabilities across 3,915 open-source projects in two months.
Management
Strata Cloud Manager
AI-powered, unified management and operations for all NGFWs and SASE — the single pane of glass for network security.
Subscriptions
Cloud-delivered Security Subscriptions (CDSS)
Cloud-delivered security services that keep every NGFW up to date with the latest threat intelligence. The eight current subscriptions are Advanced Threat Prevention, Advanced WildFire, Advanced URL Filtering, Advanced DNS Security, IoT/OT Security, Enterprise DLP, Enterprise CASB and AI Access Security. Two 2026 additions — Quantum-Safe Security (GA Jan 30, 2026) and Advanced IP Defense (GA Aug 4, 2026) — are newer than the official CDSS list page, so expect them to be missing from customer-facing collateral. Click any subscription to explore details.
What It Does
The industry's first IPS that blocks zero-day threats inline using deep learning models. Goes beyond signature-based IPS with inline ML for C2 traffic, injection attacks, exploits, and malware — all analyzed on the firewall without cloud queries.
- Exfiltration Shield — ML model detects stealthy data exfiltration via DNS relay attacks and HTTP header tunneling
- Local Deep Learning — Runs DL analysis locally on the firewall, no cloud required
- 7 advanced ML models in production, cloud-updated without FW upgrades
- Now available for Prisma Access (Nov 2025 CDSS)
Competitive Edge
Inline deep learning for zero-day C2 blocking vs. signature-only in Fortinet/Check Point. ML verdicts in milliseconds without cloud wait. SQL/command injection ML models in real-time. Cloud-side model updates — no FW upgrade needed.
What It Does
The industry's largest cloud-based malware prevention engine. Combines static analysis, dynamic sandboxing, ML, and deep learning across 40+ file types. Generates and distributes protections within minutes of encountering new malware.
- PDF Phishing Detection — CNN-based DL model analyzes visual appearance of embedded URLs in PDFs
- API Vector Categorization — ML behavioral fingerprinting of API call sequences for fileless attacks
- Multi-CPU Sandboxing — Defeats malware that evades single-CPU sandbox detection
- WildFire Dashboard in SCM (March 2026) — manage submissions without leaving SCM
Competitive Edge
CNN visual analysis of PDFs is unique (competitors parse text only). Multi-CPU sandboxing counters modern evasion. WildFire verdicts feed ATP inline models in near real-time. 8 dedicated ML detection engines.
What It Does
Real-time, ML-powered protection against phishing, malicious sites, and credential theft. Inline ML analyzes previously unseen URLs in real time — no waiting for database updates.
- QR Code Phishing (Quishing) — Inline ML scans and blocks malicious QR codes embedded in web pages
- Deepfake Content Detection — DL model identifies and blocks deepfake video content
- New categories: "Compromised website" and "File converter" for granular control
Competitive Edge
Inline ML for unknown URLs vs static lists. QR code phishing protection (no competitor has this). Deepfake video detection. Native NGFW integration — no proxy hop required.
What It Does
Inspects every DNS request and response inline, using AI to detect malicious domains, DNS tunneling, C2 callbacks, DGA domains, and DNS hijacking. First vendor to inspect both DNS requests AND responses.
- ADNSR (Advanced DNS Security Resolver) — Cloud-delivered DNS resolver extends security to ALL devices, even without NGFW
- DNS Hijacking Prevention — Detects and blocks DNS hijacking and misconfigurations
- TDS Protection — Blocks sophisticated traffic distribution system attacks
- Domain masquerading / typosquatting detection via AI/ML
Competitive Edge
ADNSR extends DNS security to IoT, BYOD, unmanaged endpoints without NGFW routing. Response monitoring catches compromised DNS infrastructure. Deeper ML models than Cisco Umbrella/OpenDNS.
What It Does
AI-driven discovery, profiling, and risk assessment of every device on the network — IoT, OT, medical, BYOD — without additional sensors. Recommends and enforces least-privilege policies and virtual patches.
- Device Security X — Full SCM integration; Enterprise, OT, and Medical tiers
- FedRAMP High — Dec 2025 authorization enables federal/classified deployments
- Integrations: Siemens Industrial Hub, SentinelOne, Cisco Meraki, NetBox IPAM
- Inbound Policy Rule Recommendations (PAN-OS 11.1.11)
Competitive Edge
Integrated enforcement in NGFW policy (vs. Claroty/Nozomi detection-only). No 802.1X/NAC required (vs. Cisco ISE). Cloud-delivered, no on-prem appliance (vs. Fortinet FortiNAC).
Use Cases
- Healthcare: Protect infusion pumps and imaging systems
- Manufacturing: Virtual patching for Siemens/Schneider PLCs
- Campus: IoT discovery without separate NAC
What It Does
Cloud-delivered DLP using ML classification, Exact Data Matching, and fingerprinting across web traffic, SaaS apps, cloud email, and endpoint egress. Single policy engine spans all enforcement points.
- Granular Data Profiles — Differentiated inline inspection per rule
- ICAP Integration — Hybrid cloud/on-prem DLP for regulated industries
- Multi-region EDM for GDPR/data sovereignty compliance
- SIEM/SOAR audit log forwarding + 90-day retention
Competitive Edge
No on-prem DLP appliance required (vs. Symantec/Forcepoint). Native NGFW inline enforcement. SaaS + network + email unified in single console. Pre-built templates: GDPR, HIPAA, PCI-DSS, SOX, CCPA.
Use Cases
- Financial: Block PCI data uploads to shadow SaaS
- Healthcare: Prevent PHI/HIPAA data leakage
- Insider threat: Alert on unusual data transfers
What It Does
Three integrated layers: (1) Data Security — API scanning of SaaS data at rest, (2) SaaS Inline — real-time policy enforcement through NGFW, (3) SSPM — continuous SaaS misconfiguration monitoring. Covers O365, Google Drive, Box, Slack, Salesforce, 50+ apps.
- Identity Threat Detection in SSPM — Human vs non-human identity risk across all SaaS
- LLM-Powered User Risk Summary — AI-generated narratives for top 0.1% risky users
- User Session Tracking — Allow corporate accounts, block personal within same tenant
- App Health Monitoring with real-time status indicators
Competitive Edge
Inline + API dual-mode (vs. Netskope/Zscaler single-mode). Multi-vendor SaaS + NGFW integration (vs. Microsoft MDCA ecosystem lock). SSPM + behavior analytics included (vs. Proofpoint email-focused).
Use Cases
- Shadow IT discovery and governance
- Prevent public sharing on Google Drive/OneDrive
- Detect departing employee mass-downloading
What It Does
Unlocks SD-WAN natively within PAN-OS — no separate appliance. Path quality measurement, application-based traffic steering, link failover, ADEM for end-to-end observability. Converged security + SD-WAN in one platform.
- NGFW as SD-WAN DC Anchor — PA-5450 serves as data center anchor for Prisma SD-WAN branches
- GCM Encryption — AES-GCM for authenticated fabric tunnel encryption
- Cisco TrustSec SGT propagation across SD-WAN fabric
- Prisma SD-WAN Copilot — GenAI troubleshooting assistant
Competitive Edge
Full NGFW security parity at every branch (vs. Fortinet partial, Cisco separate stack). App-ID for 5000+ apps for path steering (vs. basic app signatures). Unified management in SCM (vs. FortiManager/Meraki separate).
Use Cases
- Replace SD-WAN appliance + NGFW with single PA-400/500/1400
- UCaaS QoE optimization (Teams, Zoom, Webex) at branch
- SASE hybrid: on-prem NGFW SD-WAN + Prisma Access
What It Does
SCM is the cloud management platform that absorbed AIOps. Provides unified management, predictive analytics, anomaly detection, ADEM, and Strata Copilot (GenAI assistant). Two tiers: Essentials (free) and Pro (paid).
- SCM Essentials + Pro — New licensing replacing AIOps Free/Premium
- Strata Copilot — Natural language security analytics queries
- Redesigned UI: Monitor, Investigate, Configure workflows
- Dynamic Baseline Anomaly Detection reduces alert fatigue
Competitive Edge
Cloud-native (vs. Panorama on-prem). Native AIOps predictive analytics (vs. Fortinet FortiManager lacking this). Single platform for security + SD-WAN + SASE — no competitor has this convergence.
Use Cases
- Manage 100+ NGFW devices from the cloud
- Proactive health issue identification before outages
- NOC/SOC natural language querying via Copilot
What It Does
Secure remote access via SSL/IPsec VPN with full App-ID, User-ID, Content-ID policies — same security for remote users as on-prem. Evolving toward ZTNA with per-app VPN and HIP (Host Information Profile) posture checks.
- ZTNA Connector Rolling Upgrade — Zero-disruption software upgrades (March 2026)
- Zero Trust Posture Center — New continuous posture monitoring dashboard
- PQC-Enabled VPN — Post-quantum pre-shared key for quantum-safe tunnels
- Per-App VPN with Intune/JAMF for iOS/Android
Competitive Edge
Full PAN-OS policy on remote traffic (vs. Cisco AnyConnect transport-only). Native NGFW integration (vs. Fortinet FortiClient requiring FortiEMS). Post-quantum VPN — no pure-play VPN vendor can match today.
Use Cases
- Zero Trust remote access replacing legacy VPN
- PQC VPN for government/defense PQC compliance
- Hybrid SASE: GP on-prem + Prisma Access cloud
What It Does
Enables safe adoption of generative AI applications with real-time visibility, granular access controls, data protection, and threat prevention. Discovers 2,250+ GenAI apps via App-ID and the AI Correlation Engine (ACE), classifying them as sanctioned, tolerated, or unsanctioned with 60+ risk attributes.
- 500+ GenAI App Dictionary — Broadest coverage of GenAI applications with AI-powered categorization and risk scoring
- 300+ LLM-Powered Data Classifiers — ML-driven detection of sensitive data in prompts, uploads, and GenAI responses
- Inline Threat Inspection — Scans files, URLs, and code snippets in GenAI responses for malware and malicious content
- User coaching and real-time notifications to guide safe GenAI usage
- Managed via Strata Cloud Manager — single pane of glass across all enforcement points
Competitive Edge
Native NGFW + Prisma Access + Prisma Browser enforcement — no separate proxy or CASB bolt-on required. Enterprise DLP integration inspects GenAI traffic inline. Strata Copilot provides AI-recommended actions. Competitors require separate point products for GenAI visibility and control.
Licensing & Deployment
- Available as standalone subscription or included with CASB-PA / CASB-X
- Included with Prisma Browser standalone license
- Requires PAN-OS 11.2.2-h1 or later and Prisma Access 5.1 Innovation or later — current releases are PAN-OS 12.2 "Ceres" and Prisma Access 6.2
- Works across NGFW, Prisma Access, and Prisma Browser enforcement points
What It Does
Cloud-delivered zero-trust IP enforcement. Built on telemetry from 70,000+ customers, it validates DNS resolution and scores every destination IP against 40+ security attributes, then blocks command-and-control traffic that never touches a domain or URL and therefore bypasses DNS and URL inspection entirely.
- Works without TLS decryption — enforcement is at the IP layer, so it lands in accounts that will not decrypt
- DNS-resolution validation plus 40+ security attributes per IP
- Enforced via an Advanced IP Defense profile attached to a zone
- Newer than the official CDSS list page — not yet in most collateral
Licensing & Deployment
- Requires its own Advanced IP Defense licence — not bundled into ATP or Advanced DNS Security
- Configured as a profile and attached per zone, so you can pilot on one zone
- Add it to every net-new NGFW quote from Aug 4, 2026 onward
What It Does
Cloud-delivered subscription for the post-quantum transition on the NGFW — visibility into quantum-vulnerable encrypted traffic and enforcement of quantum-safe key exchange. PAN-OS 12.2 extends PQC to GlobalProtect remote access.
Where It Lands
- Government, defence, financial services and healthcare with long data-confidentiality horizons
- Any customer with a documented "harvest now, decrypt later" concern
- Pairs with FE400/FE-400 hardware-accelerated PQC on PA-7500 and PA-5500 Series
- Newer than the official CDSS list page — expect it to be missing from customer-facing collateral
What It Does
Enables the NGFW to inspect encrypted SSL/TLS and SSH traffic. Without decryption, 85–95% of enterprise traffic is invisible to security. Supports SSL Forward Proxy, SSL Inbound Inspection, SSH Proxy — all single-pass.
- PQC TLS Decryption — Inspect TLSv1.3 with ML-KEM, ML-DSA, SLH-DSA (PAN-OS 12.1 and later; 12.2 "Ceres" adds PQC for GlobalProtect)
- PQC Cipher Translation Proxy — Upgrades non-PQC apps transparently to quantum-safe
- Full TLS 1.3 support including AES-GCM/CHACHA20-POLY1305
- Configurable PQC algorithm preferences per profile
Competitive Edge
PQC TLS decryption — Fortinet and Check Point do not offer this yet. PQC cipher translation proxy is industry-first. FE400 hardware-accelerated decryption (PA-5500/7500). PA-5500 throughput measured with decryption enabled — competitors often don't disclose.
Enterprise Support Agreement (ESA)
Partners can sell and manage ESA directly — no PAN involvement required. This is a partner-led motion you can take to your customers yourself.
What It Is
A single agreement that covers support for all PA-Series NGFWs — existing assets, projected purchases, and even unplanned acquisitions. One auth code activates Premium Support + Strata Cloud Manager Pro across the entire NGFW deployment.
Why Partners Should Lead
- You quote and close ESA with your customer — no PAN SE needed
- Covers every NGFW they own or buy during the term — instant coverage on new devices
- Predictable cost for the customer — no per-device support SKU math
- Locks in multi-year support revenue for your practice
- Customers get 24/7 global Premium Support + SCM Pro at one price
What's Included
- Premium Support — 24×7×365 phone + online, <1hr Sev-1 response, NBD advance replacement
- SCM Pro for NGFW — Advanced monitoring, reporting, predictive analytics, and Strata Copilot (included with ESA, no separate purchase)
- Software & Content Updates — PAN-OS upgrades, App-ID, threat signatures, all CDSS content updates
- Growth Allowance — Built-in hardware estate cap accommodates projected growth without renegotiation
Talk to your Palo Partner Architect or PAN channel team about adding ESA to your next customer renewal or net-new deal.
Pre-Sales
Scoping Checklist
Information to gather before any Strata engagement. Use current 2026 platform, SKU and tier names — wrong names here produce wrong quotes.
Conversations
Discovery Questions
Questions to open network security conversations and uncover refresh opportunities.
AI Security — Managed via SCM
Prisma AIRS 3.0
Prisma AIRS 3.0 (March 23, 2026) is positioned around securing agentic AI — protecting models, agents, tools and LLM applications across the entire AI lifecycle. Deployed and managed through Strata Cloud Manager, funded by Software NGFW Credits, and now the stated replacement for CN-Series in Kubernetes and AI contexts as AI Runtime Firewall.
AI Model Security
Scans AI model files for malicious payloads, backdoors, and tampering across 35+ file types and 25+ threat categories.
AI Red Teaming
Automated adversarial testing with adaptive AI agents. Finds prompt injection, jailbreaks, and data extraction vulnerabilities.
AI Posture Management
Discovers all AI models, datasets, and pipelines. Maps data flows, permissions, dependencies. Identifies shadow AI.
AI Runtime Security
Real-time protection for LLM apps in production. Guards against prompt injection, data leakage, hallucination attacks, and toxic output.
AI Agent Security
Secures autonomous AI agents from identity impersonation, memory manipulation, and tool misuse as agentic AI proliferates.
Protect AI
Completed$650-700M acquisition. AI model vulnerability scanning and red teaming. Guardian + Recon products form the foundation of the AIRS Model Security and Red Teaming modules. Protect AI is now fully absorbed — completed with AIRS 2.0 in Oct 2025, so do not describe it as a separate product.
Koi Security
Closed Apr 14, 2026Closed April 14, 2026; value undisclosed officially (~$400M per Calcalist — press-reported, caveat it). Creates the Agentic Endpoint Security (AES) category on the Wings AI engine. GA as an integral part of the Cortex XDR agent with XDR 5.2, and also folded into Prisma AIRS.
Portkey
Closed May 29, 2026Closed May 29, 2026 and becomes the AI Gateway for Prisma AIRS — the inline control point in front of model and agent traffic. Value officially undisclosed; ~$120–140M is press-reported by Economic Times and must be caveated as such.