PA-5450 Front and Back Panel Descripons..............14 PA-5450 Front Panel....................14 PA-5450 Back Panel..................... 15 PA-5400 Series Firewall Module and Interface Card Informaon..19 PA-5400 Series Firewall Base Card (BC)................20 PA-5400 BC-A........................ 20 PA-5400 Series Firewall Management Processor Card (MPC)........21 PA-5400 MPC-A......................
Page 4
Table of Contents Service the PA-5400 Series Firewall Hardware........61 Replace a PA-5400 Series Firewall AC or DC Power Supply..........62 Interpret the PA-5400 Series Firewall Power Supply LEDs.........62 Replace a PA-5450 AC or DC Power Supply............63 Replace a PA-5400 Series Base Card (BC)................65 Replace a PA-5450 Base Card (BC)................65...
Before You Begin Read the following topics before you install or service a Palo Alto Networks next- ® generaon firewall or appliance. The following topics apply to all Palo Alto Networks firewalls and appliances except where noted. > Upgrade/Downgrade Consideraons for Firewalls and Appliances >...
The PA-5400 Series firewalls (currently only the PA-5450) are high performance modular appliances designed for large enterprise environments, data centers, and internet gateway deployments. The PA-5400 Series can leverage either AC or DC power and ulizes Networking Cards (NCs) and Data Processor Cards (DPCs) to scale network interfaces and data processing power as needed.
Page 16
For informaon on connecng power to the appliance, see Connect Power to a PA-5400 Series Firewall. PA-5400 Series Next-Gen Firewall Hardware Reference 2021 Palo Alto Networks, Inc.
PA-5400 Series Firewall Module and Interface Card Informaon The PA-5400 Series firewalls are modular systems that require a Base Card (BC) and a Management Processor Card (MPC) to operate. The BC is an internal baseboard that provides connecons to the front card slots, power supplies, and fan assemblies.
PA-5400 Series Firewall Module and Interface Card Informaon PA-5400 Series Firewall Base Card (BC) The PA-5400 Series Base Card (BC) serves as the link between all stac and modular components of the appliance. It funcons as a control plane ethernet switch, a data plane traffic manager, and first packet processor subsystem.
PA-5400 Series Firewall Module and Interface Card Informaon PA-5400 Series Firewall Management Processor Card (MPC) The PA-5400 Series firewall Management Processor Card (MPC) is a mandatory interface that connects to the PA-5400 Series Firewall Base Card (BC). The MPC enables management, logging, and high availability funcons via SFP+ ports and features two system drives and one logging...
Page 22
HSCI-A and HSCI-B Quad-SFP+ (QSFP+/QSFP28) interfaces used to connect (High Speed Chassis two PA-5400 Series firewalls for a high availability (HA) Interconnect) Ports configuraon. Each port offers 80GE (two 40Gbps links) or 200GE (two 100Gbps links) connecvity and is used for HA2 data link in an acve/passive configuraon.
Page 23
PA-5400 Series Firewall Module and Interface Card Informaon Item Component Descripon Management Ports Two SFP/SFP+ management ethernet ports providing 1/10GE connecvity that are used to access the management interface. To manage the firewall, change your management computer IP address to 192.168.1.2, connect an RJ-45 cable from your computer to one of the MGT ports and browse to hps:/ / 192.168.1.1.
Page 24
PA-5400 Series Firewall Module and Interface Card Informaon State Descripon Green The card is operang normally. (STATUS) Yellow The card is boong up. Green The card is powered on. Off The card is powered off. PS (Power Green All power supplies are operang normally.
Page 25
PA-5400 Series Firewall Module and Interface Card Informaon State Descripon admin@PA-5450> set system setting service-led enable no Enter the following command to enable the SVC LED on the card in a specific slot: admin@PA-5450> set system setting service-led enable slo t s3 yes Off...
PA-5400 Series Firewall Module and Interface Card Informaon PA-5400 Series Firewall Networking Card (NC) Networking Cards (NCs) provide network connecvity for a PA-5400 Series firewall. To scale performance and capacity, you can install up to two NCs in a PA-5450 firewall.
Page 27
PA-5400 Series Firewall Module and Interface Card Informaon Item Component Descripon LED Indicators Five LEDs that indicate the status of various hardware components. For details on the LEDs, see Interpret the PA-5400 NC-A LEDs Ethernet Ports Four 1Gbps/10Gbps BaseT RJ45 Ethernet ports.
Page 28
PA-5400 Series Firewall Module and Interface Card Informaon State Descripon Yellow The card temperature is outside the temperature tolerance. The card hardware failed. (Alarm) Off The card is operang normally. Green The card is operang normally. (STATUS) Yellow The card is boong up.
The following image shows how to idenfy the acvity and link LEDs for the port types available on PA-5400 Series firewall NCs. The image shows the port orientaon if the NC is in a horizontal posion. For details on the funcons and states of the LEDS, see Interpret the PA-5400 NC-A LEDs.
PA-5400 Series Firewall Data Processor Card (DPC) The PA-5400 Series Data Processor Card (DPC) is a front slot card that improves the processing capacity of the firewall. You can install up to four or five DPCs depending on your scaling needs and slot configuraon.
Page 32
PA-5400 Series Firewall Module and Interface Card Informaon Item Component Descripon LED Indicators Five LEDs that indicate the status of various hardware components. For details on the LEDs, see Interpret the PA-5400 Series DPC-A LEDs Ejector Tabs Push tabs that are used to...
Page 33
PA-5400 Series Firewall Module and Interface Card Informaon State Descripon Service LED Slot Description Status s1 PA-5400-NC-A On s2 empty Off s3 empty Off s4 empty Off s5 empty Off s6 PA-5400-DPC-A On s7 PA-5400-MPC-A On Enter the following command to view the status for a card in a specific slot: (Connued)
PA-5400 Series Firewall Installaon The PA-5400 Series firewalls are modular systems that require you to install several components, such as network cards, during the installaon process. Due to the weight of the firewalls, we recommend that you first install the firewall appliance into the rack...
PA-5400 Series Firewall Installaon PA-5400 Series Firewall Equipment Rack Installaon PA-5400 Series firewalls are designed for installaon in a standard 19-inch equipment rack. Before you install the hardware, read PA-5400 Series Firewall Rack Install Safety Informaon. • Install the PA-5450 Firewall in an Equipment Rack PA-5400 Series Firewall Rack Install Safety Informaon...
Page 37
Posion the boom edges of the fixed and adjustable brackets to the boom of the 5 RU rack space reserved for the PA-5450. Align the sloed holes of the fixed mounng bracket PA-5400 Series Next-Gen Firewall Hardware Reference 2021 Palo Alto Networks, Inc.
Page 38
Similarly, align the sloed holes in the adjustable mounng bracket to the holes on the rear of the equipment frame. PA-5400 Series Next-Gen Firewall Hardware Reference 2021 Palo Alto Networks, Inc.
Install the Mandatory PA-5400 Series Firewall Front Slot Cards The PA-5400 Series firewalls require a minimum of three cards that you install in the front slots of the appliance. These cards are shipped separately from the firewall and include the following: The Management Processor Card (MPC) provides management connecvity to the appliance and HA...
STEP 4 | Push on both ejector handles unl they lock the card into place. Install a PA-5400 Series Firewall Networking Card (NC) STEP 1 | Aach the provided ESD strap to your wrist and plug the other end in to the ESD port locaon on the front of the appliance.
Session Distribuon Policies in the PAN-OS Networking Administrator’s Guide. Install a PA-5400 Series Firewall Data Processor Card (DPC) STEP 1 | Aach the provided ESD strap to your wrist and plug the other end in to the ESD port locaon on the front of the appliance. See PA-5450 Front Panel for the locaon of the ESD...
Determine PA-5400 Series Firewall Power Configuraon Requirements At least one acve AC or DC power supply is required to operate a PA-5400 Series firewall. Factors that can change your power requirements are the number of Networking Cards (NCs) and Data Processor Cards (DPCs) used and your power redundancy requirement.
DC power supplies installed. The AC power supplies support 100 to 240VAC power input and the DC power supplies support 48 to 60VDC power input. For details on power requirements, see Determine PA-5400 Series Firewall Power Configuraon Requirements. Learn how to Set Up a Connecon to the Firewall...
Page 52
1. Connect the first two power supplies to a 120VAC 15-amp circuit breaker or 240VAC 20-amp circuit breaker using the provided power cords and then connect the second two PA-5400 Series Next-Gen Firewall Hardware Reference 2021 Palo Alto Networks, Inc.
Page 53
Do this for each of the four power supplies, ensuring that the first two power supplies on the le are connected to one power circuit breaker and the second pair on the right PA-5400 Series Next-Gen Firewall Hardware Reference 2021 Palo Alto Networks, Inc.
PA-5400 Series Firewall Installaon View PA-5400 Series Firewall Power Stascs Use the following informaon to learn how to view acve power stascs on a PA-5400 Series firewall to help you ensure power redundancy and to plan for growth. You can view the amount of power that each power supply is producing as well as the power rang for each hardware...
PA-5400 Series Firewall Installaon Connect Cables to a PA-5400 Series Firewall Aer you Connect Power to a PA-5400 Series Firewall, connect your management computer to the management port (MGT) on the firewall so you can begin the inial configuraon. You can oponally connect your management computer to the console port, which provides a serial...
Verify the PA-5400 Series Firewall NC Configuraon When you first set up a PA-5400 Series firewall, both NC slots are ready to use. If you are working with a firewall that is already deployed, you should check slot status before adding a new NC to ensure that the NC slot is ready.
Page 59
For example, to enable NCs installed in slot 2 of both appliances, run the following command: admin@PA-5450> request chassis power-on slot s2 target ha-pair For informaon on installing NCs, see Install a PA-5400 Series Firewall Networking Card (NC). PA-5400 Series Next-Gen Firewall Hardware Reference 2021 Palo Alto Networks, Inc.
Service the PA-5400 Series Firewall Hardware The following topics describes how to replace field-serviceable components on a PA-5400 Series firewall. For an overview of the hardware components, see PA-5400 Series Firewall Overview. > Replace a PA-5400 Series Firewall AC or DC Power Supply >...
Service the PA-5400 Series Firewall Hardware Replace a PA-5400 Series Firewall AC or DC Power Supply The following topics describe how to interpret the power supply LEDs and how to replace a PA-5400 Series firewall power supply. • Interpret the PA-5400 Series Firewall Power Supply LEDs •...
A red LED indicates a failed power supply. For details on the power supply LEDs, see Interpret the PA-5400 Series Firewall Power Supply LEDs STEP 3 | Shut off power to the failed power supply.
Page 64
Service the PA-5400 Series Firewall Hardware STEP 7 | Turn on power to the new power supply. only) Plug the power cable into the corresponding AC power module on the back of the appliance. The new power supply turns on and the LED will turn green.
Service the PA-5400 Series Firewall Hardware Replace a PA-5400 Series Base Card (BC) The PA-5400 Series Base Card (BC) is not hot-swappable. In the case of a failure, you must power off the appliance and disconnect all power sources before removing the BC.
Page 66
Service the PA-5400 Series Firewall Hardware STEP 6 | Grab both BC ejector handles and swing the handles outward at the same me. Gently pull the BC outward from inside the appliance. Support the BC with one hand while pulling it out from the appliance.
Service the PA-5400 Series Firewall Hardware Replace a PA-5400 Series Firewall Fan Assembly The following topics describe how to replace a PA-5400 Series firewall fan tray. • Replace a PA-5450 Fan Assembly Replace a PA-5450 Fan Assembly The PA-5450 has four dual-rotor, single fan assemblies on its rear side. Each single fan assembly can be individually removed and replaced.
Page 68
Service the PA-5400 Series Firewall Hardware STEP 4 | Place your thumb under the thumb tab located on the boom of the fan assembly. Gripping the fan assembly handle with your fingers, push up on the thumb tab. STEP 5 | While sll gripping the fan assembly handle, gently pull the fan assembly out of its slot.
Page 69
Service the PA-5400 Series Firewall Hardware STEP 6 | Install the replacement fan by sliding it into the vacant fan slot, ensuring that the thumb tab is on the boom. STEP 7 | Verify that the new fan assembly is operaonal by nong the status of the fan assembly LED and the fan LED on the MPC.
Service the PA-5400 Series Firewall Hardware Replace a PA-5400 Series Firewall Front Slot Card The PA-5400 Series firewalls require one Management Processor Card, at least one Networking Card (NC), and at least one Data Processor Card (DPC). The procedures to replace all of the front slot cards in a PA-5400 Series firewall are idencal.
Page 72
Service the PA-5400 Series Firewall Hardware Replace a PA-5450 Networking Card (NC) STEP 1 | Put the provided ESD wrist strap on your wrist ensuring that the metal contact is touching your skin. Then aach (snap) one end of the ground cable to the wrist strap and remove the alligator clip from the banana clip on the other end of the ESD grounding cable.
Page 73
Service the PA-5400 Series Firewall Hardware PA-5400 Series Firewall Networking Card (NC) Troubleshoong Commands The following table describes common commands that you can use to troubleshoot NC issues on a PA-5400 Series firewall. The PA-5450 firewall makes use of paired...
2 target ha-pair You can use the ha-pair opon in an HA configuraon for many of the slot control commands. Replace a PA-5400 Series Data Processor Card (DPC) Learn how to replace a DPC. • Replace a PA-5450 Data Processor Card (DPC)
Push on both ejector handles unl they lock the card into place. PA-5400 Series Front Slot and Card States You can view the slot and card status informaon on a PA-5400 Series firewall using the web interface or the command line interface (CLI). From the web interface, select Network > Interfaces to view the status of each slot.
Unsupported The card is not a supported type for this slot. PA-5400 Series Logical Card Slots The PA-5400 Series firewall requires the use of logical card slots in order to direct processing power from the Data Processing Card (PA-5400 DPC-A) to the Networking Card (PA-5400 NC- A).
Page 77
Service the PA-5400 Series Firewall Hardware See the following table of possible CLI commands that are used to restart, power on, or power off a card. For more informaon on card states, see PA-5400 Series Front Slot and Card States.
Page 78
Service the PA-5400 Series Firewall Hardware CLI Command Result request chassis enable slot <> targe t -ha-pair The status of one card in a logical pair can have an impact on the status of the other card in the pair. The firewall will consult the logically paired card during different operaons. For example, when a DPC is brought into a Power-Off state, its corresponding NC will also be powered off.
Page 79
Service the PA-5400 Series Firewall Hardware Operaon Possible Outcomes Crical System Log Examples Powering • Using the admin-power-on or 2021/04/12 14:03:48 criti on a DPC power-on commands will only cal hw slot-po 0 power on the DPC. The Logically paired Sl •...
Service the PA-5400 Series Firewall Hardware Replace a PA-5450 Front Slot Card in a High Availability (HA) Configuraon When High Availability (HA) is configured on the firewall, you must take addional steps to remove and install a Networking Card (NC) or Data Processing Card (DPC). Although it is possible to hot-swap the front slot cards, following the procedure outlined below will prevent slot or device failures in a live HA deployment.
Page 81
Service the PA-5400 Series Firewall Hardware To install a replacement of the failed card: 1. When you receive the replacement NC or DPC, insert it into the device that needs the replacement card. 2. Issue the following command where X is the slot inserted: request chassis admin-power-on slot X target ha-pair 3.
Service the PA-5400 Series Firewall Hardware Install an MPC Logging Drive STEP 1 | Aach an ESD strap to your wrist and plug the other end in to the ESD port locaon on the front of the appliance. See PA-5450 Front Panel for the locaon of the ESD port.
Service the PA-5400 Series Firewall Hardware Replace an MPC System Drive STEP 1 | Ensure that you have access to an ESD work surface for placement of the Management Processor Card (MPC). STEP 2 | Put the provided ESD wrist strap on your wrist ensuring that the metal contact is touching your skin.
Page 84
Before re-installing the MPC, plug the banana clip end of your ESD wrist strap into one of the ESD ports located on the back of the appliance. STEP 10 | Slide the MPC back into slot 7. See Install a PA-5400 Series Firewall Management Processor Card (MPC) for more informaon. PA-5400 Series Next-Gen Firewall Hardware Reference 2021 Palo Alto Networks, Inc.
The following topics provide appliance and component specificaons for the PA-5400 Series firewalls. View the datasheet for informaon on features, performance, and capacity numbers. > PA-5400 Series Firewall Physical Specificaons > PA-5400 Series Firewall Electrical Specificaons > PA-5400 Series Firewall Environmental Specificaons...
PA-5400 Series Firewall Specificaons PA-5400 Series Firewall Electrical Specificaons Use the following topics to learn about the PA-5400 Series firewall electric specificaons and the types of power cords you can use. • PA-5400 Series Firewall Component Electrical Specificaons • PA-5400 Series Firewall Power Cord Types PA-5400 Series Firewall Component Electrical Specificaons...
PA-5400 Series Firewall Specificaons PA-5400 Series Firewall Environmental Specificaons The following table describes PA-5400 Series firewall environmental specificaons. Specificaon Value Operang temperature range 0° to 40°C (32°F to 104°F) Storage temperature range -20° to 70°C (-4°F to 158°F) Humidity 5% to 90% non-condensing Appliance airflow...
Our products meet standards for product safety and electromagnec compability when used for their intended purpose. To view compliance statements for the PA-5400 Series firewalls, see PA-5400 Series Firewall Compliance...
PA-5400 Series Firewall Hardware Compliance Statements PA-5400 Series Firewall Compliance Statements The following are the PA-5400 Series firewall hardware statements: • VCCI This secon provides the compliance statement for the Voluntary Control Council for Interference by Informaon Technology Equipment (VCCI), which governs radio frequency emissions in Japan.
Page 93
PA-5400 Series Firewall Hardware Compliance Statements • BSMI EMC Statement—User warning: This is a Class A product. When used in a residenal environment it may cause radio interference. In this case, the user will be required to take adequate measures.