Verify the PA-5400 Series Firewall NC Configuration..............57 Service the PA-5400 Series Firewall Hardware........59 Replace a PA-5400 Series Firewall AC or DC Power Supply............61 Interpret the PA-5400 Series Firewall Power Supply LEDs..........61 Replace a PA-5450 AC or DC Power Supply............... 61 Replace a PA-5400 Series Base Card (BC)..................63...
Page 4
Replace a PA-5450 Fan Assembly...................65 Replace a PA-5400 Series Firewall Front Slot Card.................68 Replace a PA-5400 Series Management Processor Card (MPC)........68 Replace a PA-5400 Series Networking Card (NC)............... 69 Replace a PA-5400 Series Data Processor Card (DPC)............72 PA-5400 Series Front Slot and Card States................73 PA-5400 Series Logical Card Slots..................
Before You Begin Read the following topics before you install or service a Palo Alto Networks next-generation ® firewall or appliance. The following topics apply to all Palo Alto Networks firewalls and appliances except where noted. > Upgrade/Downgrade Considerations for Firewalls and Appliances >...
Page 12
French Translation: La source d’alimentation c.c. doit se trouver dans les mêmes locaux que ce pare-feu. • The DC battery return wiring on the firewall must be connected as an isolated DC (DC-I) return. PA-5400 SERIES NEXT-GEN FIREWALL HARDWARE REFERENCE | Before You Begin 2021 Palo Alto Networks, Inc.
The PA-5400 Series firewalls (currently only the PA-5450) are high performance modular appliances designed for large enterprise environments, data centers, and internet gateway deployments. The PA-5400 Series can leverage either AC or DC power and utilizes Networking Cards (NCs) and Data Processor Cards (DPCs) to scale network interfaces and data processing power as needed.
The following image shows the back panel of the PA-5450 firewall (with two AC power supplies installed) and the table describes each back panel component. PA-5400 SERIES NEXT-GEN FIREWALL HARDWARE REFERENCE | PA-5400 Series Firewall Overview 2021 Palo Alto Networks, Inc.
PA-5400 Series Firewall Module and Interface Card Information The PA-5400 Series firewalls are modular systems that require a Base Card (BC) and a Management Processor Card (MPC) to operate. The BC is an internal baseboard that provides connections to the front card slots, power supplies, and fan assemblies. The two types of front slot cards, Networking Cards (NC) and Data Processing Cards (DPC), are interfaced with the BC on the front of the appliance.
PA-5400 Series Firewall Base Card (BC) The PA-5400 Series Base Card (BC) serves as the link between all static and modular components of the appliance. It functions as a control plane ethernet switch, a data plane traffic manager, and first packet processor subsystem.
PA-5400 Series Firewall Management Processor Card (MPC) The PA-5400 Series firewall Management Processor Card (MPC) is a mandatory interface that connects to PA-5400 Series Firewall Base Card (BC). The MPC enables management, logging, and high availability functions via SFP+ ports and features two system drives and one logging drive.
Page 25
(HA) control and synchronization. Connect this port directly from the HA1-A port on the first firewall in an HA pair PA-5400 SERIES NEXT-GEN FIREWALL HARDWARE REFERENCE | PA-5400 Series Firewall Module and Interface Card Information 2021 Palo Alto Networks, Inc.
PA-5400 Series Firewall Networking Card (NC) Networking Cards (NCs) provide network connectivity for a PA-5400 Series firewall. To scale performance and capacity, you can install up to two NCs in a PA-5450 firewall. When viewing the NCs from the web interface, the NCs are organized by slot and you click the icon to the left of the slot number to show the NC ports.
Page 29
Enter the following command to view the status of the SVC LED on all cards that have this LED: PA-5400 SERIES NEXT-GEN FIREWALL HARDWARE REFERENCE | PA-5400 Series Firewall Module and Interface Card Information 2021 Palo Alto Networks, Inc.
The following image shows how to identify the activity and link LEDs for the port types available on PA-5400 Series firewall NCs. The image shows the port orientation if the NC is in a horizontal position. For details on the functions and states of the LEDS, see Interpret the PA-5400 NC-A LEDs.
PA-5400 Series Firewall Data Processor Card (DPC) The PA-5400 Series Data Processor Card (DPC) is a front slot card that improves the processing capacity of the firewall. You can install up to four or five DPCs depending on your scaling needs and slot configuration.
Page 34
Enter the following command to enable the SVC LED on the card in a specific slot: admin@PA-5450> set system setting service-led enable slot s3 yes LED is off. LED is solid blue. PA-5400 SERIES NEXT-GEN FIREWALL HARDWARE REFERENCE | PA-5400 Series Firewall Module and Interface Card Information...
PA-5400 Series Firewall Installation The PA-5400 Series firewalls are modular systems that require you to install several components, such as network cards, during the installation process. Due to the weight of the firewalls, we recommend that you first install the firewall appliance into the rack and then install the front slot cards.
PA-5400 Series Firewall Equipment Rack Installation. • Elevated ambient operating temperature—If the PA-5400 Series firewall is installed in a closed or multi- unit rack assembly, the ambient operating temperature of the rack environment may be greater than the ambient room temperature. Verify that the ambient temperature of the rack assembly does not exceed...
Page 38
Similarly, align the slotted holes in the adjustable mounting bracket to the holes on the rear of the equipment frame. PA-5400 SERIES NEXT-GEN FIREWALL HARDWARE REFERENCE | PA-5400 Series Firewall Installation 2021 Palo Alto Networks, Inc.
Page 42
PA-5450 appliance. If adjustment is needed, only loosen the screws on one side at a time. PA-5400 SERIES NEXT-GEN FIREWALL HARDWARE REFERENCE | PA-5400 Series Firewall Installation 2021 Palo Alto Networks, Inc.
Install the Mandatory PA-5400 Series Firewall Front Slot Cards The PA-5400 Series firewalls require a minimum of three cards that you install in the front slots of the appliance. These cards are shipped separately from the firewall and include the following: The Management Processor Card (MPC) provides management connectivity to the appliance and HA connectivity;...
Gently push the MPC into slot 1 until the card reaches the end of the slot. PA-5400 SERIES NEXT-GEN FIREWALL HARDWARE REFERENCE | PA-5400 Series Firewall Installation 2021 Palo Alto Networks, Inc.
Page 49
You will have to enter the serial number (12-digit number identified as S/N) and claim key (8- digit number). These numbers are stickers attached to the back of the device. PA-5400 SERIES NEXT-GEN FIREWALL HARDWARE REFERENCE | PA-5400 Series Firewall Installation 2021 Palo Alto Networks, Inc.
Determine PA-5400 Series Firewall Power Configuration Requirements At least one active AC or DC power supply is required to operate a PA-5400 Series firewall. Factors that can change your power requirements are the number of Networking Cards (NCs) and Data Processor Cards (DPCs) used and your power redundancy requirement.
Page 52
1. Prepare the DC power cable by crimping the bare wire ends of the cables using lugs (not included) designed for your DC power source. Each cable dongle has one red wire and one black wire. Connect PA-5400 SERIES NEXT-GEN FIREWALL HARDWARE REFERENCE | PA-5400 Series Firewall Installation 2021 Palo Alto Networks, Inc.
View PA-5400 Series Firewall Power Statistics Use the following information to learn how to view active power statistics on a PA-5400 Series firewall to help you ensure power redundancy and to plan for growth. You can view the amount of power that each power supply is producing as well as the power rating for each hardware component.
Configuration When you first set up a PA-5400 Series firewall, both NC slots are ready to use. If you are working with a firewall that is already deployed, you should check slot status before adding a new NC to ensure that the NC slot is ready.
Page 58
For example, to enable NCs installed in slot 2 of both appliances, run the following command: admin@PA-5450> request chassis power-on slot s2 target ha-pair For information on installing NCs, see Install a PA-5400 Series Firewall Networking Card (NC). PA-5400 SERIES NEXT-GEN FIREWALL HARDWARE REFERENCE | PA-5400 Series Firewall Installation...
Service the PA-5400 Series Firewall Hardware The following topics describes how to replace field-serviceable components on a PA-5400 Series firewall. For an overview of the hardware components, see PA-5400 Series Firewall Overview. > Replace a PA-5400 Series Firewall AC or DC Power Supply >...
Replace a PA-5400 Series Firewall AC or DC Power Supply The following topics describe how to interpret the power supply LEDs and how to replace a PA-5400 Series firewall power supply. • Interpret the PA-5400 Series Firewall Power Supply LEDs •...
Page 62
It is best to route and secure the cable first and then plug the cable into the power supply. PA-5400 SERIES NEXT-GEN FIREWALL HARDWARE REFERENCE | Service the PA-5400 Series Firewall Hardware 2021 Palo Alto Networks, Inc.
Replace a PA-5400 Series Base Card (BC) The PA-5400 Series Base Card (BC) is not hot-swappable. In the case of a failure, you must power off the appliance and disconnect all power sources before removing the BC. • Replace a PA-5450 Base Card (BC)
Replace a PA-5400 Series Firewall Fan Assembly The following topics describe how to replace a PA-5400 Series firewall fan tray. • Replace a PA-5450 Fan Assembly Replace a PA-5450 Fan Assembly The PA-5450 has four dual-rotor, single fan assemblies on its rear side. Each single fan assembly can be individually removed and replaced.
Replace a PA-5400 Series Firewall Front Slot Card The PA-5400 Series firewalls require one Management Processor Card, at least one Networking Card (NC), and at least one Data Processor Card (DPC). The procedures to replace all of the front slot cards in a PA-5400 Series firewall are identical.
Page 70
Gently push the replacement NC into slot 1 or 2 until the card reaches the end of the slot. Push on both ejector handles until they lock the card into place. PA-5400 SERIES NEXT-GEN FIREWALL HARDWARE REFERENCE | Service the PA-5400 Series Firewall Hardware 2021 Palo Alto Networks, Inc.
Page 71
This allows the firewall to start HA monitoring on each NC at the same time. PA-5400 SERIES NEXT-GEN FIREWALL HARDWARE REFERENCE | Service the PA-5400 Series Firewall Hardware 2021 Palo Alto Networks, Inc.
STEP 3 | The below image shows a Management Processor Card (MPC); however, the procedure to install the DPC is the same. PA-5400 SERIES NEXT-GEN FIREWALL HARDWARE REFERENCE | Service the PA-5400 Series Firewall Hardware 2021 Palo Alto Networks, Inc.
PA-5400 Series Front Slot and Card States You can view the slot and card status information on a PA-5400 Series firewall using the web interface or the command line interface (CLI). From the web interface, select Network > Interfaces to view the status of each slot.
Unsupported The card is not a supported type for this slot. PA-5400 Series Logical Card Slots The PA-5400 Series firewall requires the use of logical card slots in order to direct processing power from the Data Processing Card (PA-5400 DPC-A) to the Networking Card (PA-5400 NC-A).
Page 75
The third column of the table gives examples of critical system logs that are received in response to certain outcomes. PA-5400 SERIES NEXT-GEN FIREWALL HARDWARE REFERENCE | Service the PA-5400 Series Firewall Hardware 2021 Palo Alto Networks, Inc.
Page 76
2. The firewall then verifies if the DPC is still in the Up or Disabled state. 3. Lastly, the firewall powers on the NC. PA-5400 SERIES NEXT-GEN FIREWALL HARDWARE REFERENCE | Service the PA-5400 Series Firewall Hardware 2021 Palo Alto Networks, Inc.
Page 78
3. Once the slots move into a Disable state, issue the following command and the slots will allow traffic to start flowing to the slot: request chassis enable slot X target ha-pair PA-5400 SERIES NEXT-GEN FIREWALL HARDWARE REFERENCE | Service the PA-5400 Series Firewall Hardware 2021 Palo Alto Networks, Inc.
Once the logging drive is fully seated, tighten the retainer screw to 4 in-lbs. Exceeding a torque of 4.5 in-lbs will damage the equipment. PA-5400 SERIES NEXT-GEN FIREWALL HARDWARE REFERENCE | Service the PA-5400 Series Firewall Hardware 2021 Palo Alto Networks, Inc.
PA-5400 Series Firewall Specifications The following topics provide appliance and component specifications for the PA-5400 Series firewalls. View the datasheet for information on features, performance, and capacity numbers. > PA-5400 Series Firewall Physical Specifications > PA-5400 Series Firewall Electrical Specifications...
PA-5400 Series Firewall Electrical Specifications Use the following topics to learn about the PA-5400 Series firewall electric specifications and the types of power cords you can use. • PA-5400 Series Firewall Component Electrical Specifications • PA-5400 Series Firewall Power Cord Types...
Value Operating temperature range 0° to 40°C (32°F to 104°F) Storage temperature range -20° to 70°C (-4°F to 158°F) Humidity 5% to 90% non-condensing Appliance airflow PA-5450—Front to back PA-5400 SERIES NEXT-GEN FIREWALL HARDWARE REFERENCE | PA-5400 Series Firewall Specifications...
Our products meet standards for product safety and electromagnetic compatibility when used for their intended purpose. To view compliance statements for the PA-5400 Series firewalls, see PA-5400 Series Firewall Compliance Statements.
• NEBS Requirements The following lists the Network Equipment Building System (NEBS) requirements for PA-5400 Series firewalls. • The firewall is intended to be installed in a Network Telecommunication Facility (Central Office) as part of a Common Bonding Network (CBN) or Isolated Bonding Network (IBN).
Page 92
• Technischer Überwachungsverein (TUV) Risk of explosion if battery is replaced by an incorrect type. Dispose of used battery according to local regulations. PA-5400 SERIES NEXT-GEN FIREWALL HARDWARE REFERENCE | PA-5400 Series Firewall Hardware Compliance Statements...
Need help?
Do you have a question about the PA-5400 Series and is the answer not in the manual?
Questions and answers