PA-5400 Series Firewall Module and Interface Card Informaon
Item
Component
3
USB Port
4
Console Port
5
HSCI-A and HSCI-B
(High Speed Chassis
Interconnect) Ports
6
Logging Ports
PA-5400 Series Next-Gen Firewall Hardware Reference
Descripon
about installing a logging drive, see
Drive.
One USB port that accepts a USB flash drive that contains
a bootstrap bundle (PAN-OS configuraon) that enables
you to bootstrap the firewall. Bootstrapping enables you
to provision the firewall with a specific configuraon,
license it, and make it operaonal on the network.
Use this port to connect a management computer to the
firewall using a 9-pin serial-to-RJ-45 cable and terminal
emulaon soware.
The console connecon provides access to firewall boot
messages, the Maintenance Recovery Tool (MRT), and the
command line interface (CLI).
If your management computer does not have a
serial port, use a USB-to-serial converter.
Quad-SFP+ (QSFP+/QSFP28) interfaces used to connect
two PA-5400 Series firewalls for a high availability (HA)
configuraon. Each port offers 80GE (two 40Gbps links)
or 200GE (two 100Gbps links) connecvity and is used for
HA2 data link in an acve/passive configuraon. When in
acve/acve mode, the port is also used for HA3 packet
forwarding for asymmetrically routed sessions that require
Layer 7 inspecon for App-ID
In a typical installaon, HSCI-A on the first firewall
connects directly to HSCI-A on the second firewall and
HSCI-B on the first firewall connects to HSCI-B on the
second firewall. The purpose of HSCI-B is to increase the
bandwidth for HA2/HA3 processing. This provides full
80-200Gbps transfer rates. In soware, both ports (HSCI-
A and HSCI-B) are treated as one HA interface.
The HSCI ports are not routable and must be connected
directly to each other, not through a switch.
You can configure HA2 (data link) on the HSCI ports or on
NC data ports. When configuring on dataplane ports, you
must ensure that both the HA2 and HA2-Backup links are
configured on dataplane interfaces. A mix of a dataplane
port and an HSCI port for either HA2 or HA2-Backup will
result in a commit failure.
Two SFP/SFP+ logging ports that offer 1/10GE
connecvity.
22
Install an MPC Logging
and Content#ID
.
™
™
2021 Palo Alto Networks, Inc.
©