PA-7000 20GQ NPC.....................57 PA-7000 20GQXM NPC....................60 PA-7000 100G NPC..................... 60 Idenfy PA-7000 Series NPC Port Acvity and Link LEDs......... 64 PA-7000 Series Firewall Data Processing Card (DPC)............. 65 Interpret the PA-7000 Series DPC LEDS..............65 PA-7000 Series Firewall Installaon............69 PA-7000 Series Firewall Equipment Rack Installaon............70...
Page 4
Install the PA-7080 Firewall EMI Filter................122 Service the PA-7000 Series Firewall Hardware........123 Replace a PA-7000 Series Firewall AC or DC Power Supply........124 Interpret the PA-7000 Series Firewall Power Supply LEDs.......124 Replace a PA-7000 Series AC Power Supply............125 Replace a PA-7000 Series DC Power Supply............
Page 5
Table of Contents Replace a PA-7050-SMC-B or PA-7080-SMC-B Drive..........180 Increase the PA-7000 Series Firewall LPC Log Storage Capacity....... 185 PA-7000 Series Firewall Specificaons............195 PA-7000 Series Firewall Physical Specificaons............. 196 PA-7000 Series Firewall Electrical Specificaons............199 PA-7000 Series Firewall Component Electrical Specificaons......199 PA-7000 Series Firewall Power Cord Types............
Before You Begin Read the following topics before you install or service a Palo Alto Networks next- ® generaon firewall or appliance. The following topics apply to all Palo Alto Networks firewalls and appliances except where noted. > Upgrade/Downgrade Consideraons for Firewalls and Appliances >...
• The integrity of the warranty label on the firewall or appliance is not compromised. (PA-7000 Series firewalls only) PA-7000 Series firewalls are modular systems and therefore do not include a warranty label on the firewall. PA-7000 Series Firewall Hardware Reference 2021 Palo Alto Networks, Inc.
Page 12
• (PA-7000 Series firewalls only) When removing a fan tray from a PA-7000 Series firewall, first pull the fan tray out about 1 inch (2.5cm) and then wait a minimum of 10 seconds before extracng the enre fan tray. This allows the fans to stop spinning and helps you avoid serious injury when removing the fan tray.
firewalls also include a dedicated high availability (HA) control port (HA1), as well as two dedicated 80Gb QSFP HA ports for HA2 (data link) and HA3 (packet forwarding) funcons. These dedicated HA ports enable PA-7000 Series firewalls to funcon with full hardware redundancy in either an acve/passive or acve/acve configuraon.
Page 17
HA1-A, and HA1-B ports. You can use these or replace them with a transceiver of your choice. There are two PA-7050 SMC models as described in PA-7000 Series Firewall Switch Management Cards (SMCs). The PAN-OS soware is preinstalled on the ®...
DC model is that the DC model has four front DC power supplies instead of four AC power supplies. For descripons of the front panel components, see PA-7050 Front Panel (AC) and for informaon on connecng DC power, see Connect Power to a PA-7000 Series Firewall. PA-7000 Series Firewall Hardware Reference 2021 Palo Alto Networks, Inc.
Page 25
HA1-A, and HA1-B ports. You can use these or replace them with a transceiver of your choice. There are two PA-7050 SMC models as described in PA-7000 Series Firewall Switch Management Cards (SMCs). The PAN-OS soware is preinstalled on the ®...
The only differences between the back panel AC model and the back panel DC model is that the DC model has two DC Power Entry Modules (PEMs) instead of two AC PEMs. Each DC PEM PA-7000 Series Firewall Hardware Reference 2021 Palo Alto Networks, Inc.
PA-7000 Series Firewall Module and Interface Card Informaon The PA-7000 Series firewalls are modular systems and requires a minimum set of front slot cards. The required cards include the Switch Management Card (SMC), Log Processing Card (LPC) or Log Forwarding Card (LFC), and at least one Network Processing Card (NPC).
SMC-B or PA-7080-SMC-B) must be paired with a second-generaon logging card (PA-7000-LFC-A). When using PA-7000 Series firewalls in a High Availability (HA) pair, both firewalls must have SMCs of the same generaon installed. Use the following topics to learn about requirements, descripons of the SMC components, and how to interpret the LEDs.
Page 35
PA-7000 Series Firewall Module and Interface Card Informaon same install and release levers as the LPC—version 1 does not; and the USB port is in a different locaon. There are no funconal differences between the two versions. Figure 1: PA-7050 Version 1 SMC, First Generation...
Page 36
PA-7000 Series Firewall Module and Interface Card Informaon Item Component Descripon You cannot configure HA1 (control) on NPC data ports or the MGT port. Ethernet 10/100/1000Mbps port used to access the management interface. To manage the firewall, change your management computer IP address to 192.168.1.2, connect an RJ-45 cable from your computer to the MGT port and browse to hps:/ / 192.168.1.1.
PA-7000 Series Firewall Module and Interface Card Informaon Item Component Descripon dataplane port and an HSCI port for either HA2 or HA2- Backup will result in a commit failure. HSCI-B (High Speed See the HSCI-A descripon above for details. Chassis Interconnect) The purpose of HSCI-B is to increase the bandwidth for HA2/HA3 processing.
Page 38
PA-7000 Series Firewall Module and Interface Card Informaon Figure 4: PA-7050-SMC-B Figure 5: PA-7080-SMC-B Item Component Descripon MGT-A and MGT-B Two redundant SFP/SFP+ Ethernet ports used to access the management interface. If both ports are connected, one port is primary and the other port is secondary. If a link failure occurs on the primary port, the firewall...
Page 39
PA-7000 Series Firewall Module and Interface Card Informaon Item Component Descripon two PA-7000 Series firewalls in a high availability (HA) configuraon as follows: • In an acve/passive configuraon, this port is for HA2 (data link). • In an acve/acve configuraon, you can configure this port for HA2 and/or HA3.
Page 40
PA-7000 Series Firewall Module and Interface Card Informaon Item Component Descripon If your management computer does not have a serial port, use a USB-to-serial converter. Use the following sengs to configure your terminal emulaon soware to connect to the console port:Data...
10,000 or greater because the PA-7050 will have the second-generaon fan trays installed and the PA-7080 will have a built-in EMI filter. • PAN-OS 9.0 or later. • Install the PA-7000 Series Firewall Log Forwarding Card (LFC) • (PA-7050 only) Install the second-generaon fan tray to increase cooling capacity. The...
Page 42
PA-7000 Series Firewall Module and Interface Card Informaon State Descripon PWR (POWER) Green The chassis is powered. Off The chassis power is off. STS (STATUS) Green The chassis is operang normally. Yellow The chassis is boong up. Green The chassis is the current acve firewall.
Page 43
PA-7000 Series Firewall Module and Interface Card Informaon State Descripon • When the state returns to a funconal state (any acve or passive state) the LED turns off. • If you intenonally suspend HA, the LED will not turn red.
Page 44
PA-7000 Series Firewall Module and Interface Card Informaon State Descripon s12 empty Off Enter the following command to view the status for a card in a specific slot: (Connued) admin@PA-7080> show system service-led status slot s3 Enter the following command to enable all SVC LEDs: admin@PA-7080>set system setting service-led enable ye...
Page 45
PA-7000 Series Firewall Module and Interface Card Informaon The following table describes the funcons and states of the SMC HSCI-A and HSCI-B port LEDs. Descripon Le The LED is solid green if there is a network link. Because this interface is comprised of four 10Gbps links, the LED uses an AND operaon for all...
PA-7000 Series Firewall Module and Interface Card Informaon PA-7000 Series Firewall Log Cards The PA-7000 Series firewalls support two log card models: the Log Processing Card (LPC) and the Log Forwarding Card (LFC). The difference between the LPC and the LFC is that the LPC stores logs locally and forward logs;...
Page 47
PA-7000 Series Firewall Module and Interface Card Informaon Item Component Descripon Log Processing Card (LPC) that processes all logs and then stores the logs on the four Advanced Mezzanine Cards (AMCs) that contain one disk drive each. Four Advanced Mezzanine Cards (AMCs) and drives used for log storage.
PA-7000 Series Firewall Module and Interface Card Informaon Interpret the PA-7000 Series Firewall AMC LEDs Use the following informaon to learn how to interpret the LED dashboard located on the front of the AMC. The Log Processing Card (LPC) does not have LEDs. If there is a hardware issue with the LPC, the LOG LED on the Switch Management Card (SMC) changes to red and the firewall...
Page 49
PA-7000 Series Firewall Module and Interface Card Informaon Item Component Descripon QSFP+ ports Two quad small form-factor pluggable (QSFP+) 10Gbps/40Gbps Ethernet interfaces as defined by the IEEE 802.3ba standard. The two physical QSFP+ interfaces operate at 40Gbps each. The firewall uses the ports to forward all dataplane logs to an external system, such as Panorama, Firewall Data Lake, or a syslog server.
Page 50
PA-7000 Series Firewall Module and Interface Card Informaon Item Component Descripon Ports 1 and 9 share the same LED and ports 5 and 10 share the same LED. Port transfer rate is differenated by color. Green indicates 10Gbps and yellow indicates 40Gbps.
Page 51
PA-7000 Series Firewall Module and Interface Card Informaon State Descripon STS (STATUS) Green The LFC is operang normally. Yellow The LFC is boong up. There is a hardware failure, which may include the following: (Alarm) • Voltage issue. • Power supply detected but not operaonal.
Page 52
PA-7000 Series Firewall Module and Interface Card Informaon State Descripon s6 PA-7080-SMC-B On s7 PA-7000-LFC On s8 empty Off s9 empty Off s10 empty Off s11 empty Off s12 empty Off Enter the following command to view the status for a card in a specific slot: (Connued)
Page 53
PA-7000 Series Firewall Module and Interface Card Informaon To learn about the orientaon of the LED indicators, see Idenfy PA-7000 Series NPC Port Acvity and Link LEDs. PA-7000 Series Firewall LFC Requirements The following informaon describes the system and hardware requirements for upgrading to the Log Forwarding Card (LFC).
NPCs in a PA-7050 firewall and up to ten NPCs in a PA-7080 firewall. If you plan on fully populang a PA-7000 Series firewall with NPCs, Determine PA-7000 Series Firewall Power Configuraon Requirements to ensure that you provide enough power to the firewall.
Page 55
PA-7000 Series Firewall Module and Interface Card Informaon PA-7000 20G NPC Component Descripons The following images show the two types of PA-7000 20G NPCs and the table describes the NPC components. The only difference between the two versions is the levers used to install and remove the cards.
Page 56
PA-7000 Series Firewall Module and Interface Card Informaon Item Component Descripon NPC installaon and • Screws, lever release latches, and ejector levers used removal hardware to install and remove a version 1 NPC card. The lever release latches on each side slides upward to release the levers used to eject the card from the chassis.
4 million sessions and the PA-7000 20GXM NPC supports up to 8 million sessions. As of PAN-OS 9.0 and later, the PA-7000-20G NPC supports 3.2 million sessions. The PA-7000 Series firewall must have PAN-OS 7.1 or later installed to use the PA-7000-20GXM-NPC.
Page 58
PA-7000 Series Firewall Module and Interface Card Informaon The PA-7000 Series firewall must have PAN-OS 7.0 or later installed to use the PA-7000-20GQ-NPC. If you purchase a PA-7050 firewall running a PAN-OS 6.1 or earlier release and you only have a PA-7000-20GQ available (or, if you have more than one NPC and all are this model), refer to KB arcle...
Page 59
PA-7000 Series Firewall Module and Interface Card Informaon Interpret the PA-7000 20GQ NPC LEDs Use the following informaon to learn how to interpret the LED dashboard and port LEDs located on the PA-7000 20GQ Network Processing Card (NPC). The following table describes the funcons and states of the NPC LED dashboard.
4 million sessions and the PA-7000 20GQXM NPC supports up to 8 million sessions. As of PAN-OS 9.0 and later, the PA-7000-20GQ NPC supports 3.2 million sessions. The PA-7000 Series firewall must have PAN-OS 7.1 or later installed to use the PA-7000-20GQXM-NPC.
Page 61
PA-7000 Series Firewall Module and Interface Card Informaon Item Component Descripon To properly breakout the QSFP ports, your transceiver must be either the PAN-QSFP-40GBASE-SR4 or PAN- QSFP28-100GBASE-SR4, and you must use an appropriate passive breakout cable. LED dashboard Five LEDs that provide NPC status. For details on the...
Page 62
PA-7000 Series Firewall Module and Interface Card Informaon State Descripon Green The card temperature is normal. (Temperature) Yellow The card temperature is outside the temperature tolerance. Allows a remote administrator to illuminate the SVC LED on a specific front-slot (Service) card so an on-site technician can locate the card.
Page 63
PA-7000 Series Firewall Module and Interface Card Informaon State Descripon LED is solid blue. The following table describes funcons and states of the SFP+ port LEDs. Descripon Le The LED shows green if there is a network link. Right Blinks green or stays green if there is network acvity.
The following image shows how to idenfy the acvity and link LEDs for the port types available on PA-7000 Series firewall NPCs. The image shows the port orientaon if the NPC is in a horizontal posion. For details on the funcons and states of the LEDS, see...
PA-7000 Series Firewall Module and Interface Card Informaon PA-7000 Series Firewall Data Processing Card (DPC) The PA-7000 Series Data Processing Card (PA-7000-DPC-A) is an oponal interface card that can be installed to improve the processing capacity of the chassis. Similar in physical design to the PA-7000 100G NPC, the DPC offers scalability in the form of four addional data plane instances.
Page 66
PA-7000 Series Firewall Module and Interface Card Informaon State Descripon The card hardware failed. (Alarm) Off The card is operang normally. Green The card temperature is normal. (Temperature) Yellow The card temperature is outside the temperature tolerance. Allows a remote administrator to illuminate the SVC LED on a specific front-slot (Service) card so an on-site technician can locate the card.
PA-7000 Series Firewall Installaon The PA-7000 Series firewalls are modular systems that require you to install several components, such as network cards, during the installaon process. Due to the weight of the firewalls, we recommend that you first install the firewall chassis into the rack...
PA-7000 Series Firewall Installaon PA-7000 Series Firewall Equipment Rack Installaon PA-7000 Series firewalls are designed for installaon in a standard 19-inch equipment rack in a mid-mount or front-mount posion. Before you install the hardware, read PA-7000 Series Firewall Rack Install Safety Informaon.
This will prevent any damage to the cards that could occur during rack mounng and will reduce the weight of the chassis. STEP 1 | Read PA-7000 Series Firewall Rack Install Safety Informaon. PA-7000 Series Firewall Hardware Reference 2021 Palo Alto Networks, Inc.
Page 77
(8 upper bracket screws and 4 lower bracket screws). The upper bracket is designed for Ethernet cables and the console cable and the lower bracket is designed for fiber opc PA-7000 Series Firewall Hardware Reference 2021 Palo Alto Networks, Inc.
Page 78
Align the rack-mount bracket mounng holes on each side of the chassis with the holes on the rack rail, ensuring that the chassis is level. Secure the chassis to the rack using eight PA-7000 Series Firewall Hardware Reference 2021 Palo Alto Networks, Inc.
This will prevent any damage to the cards that could occur during rack mounng and will reduce the weight of the chassis. STEP 1 | Read PA-7000 Series Firewall Rack Install Safety Informaon. PA-7000 Series Firewall Hardware Reference 2021 Palo Alto Networks, Inc.
Page 80
(8 upper bracket screws and 4 lower bracket screws). The upper bracket is designed for Ethernet cables and the console cable and the lower bracket is designed for fiber opc PA-7000 Series Firewall Hardware Reference 2021 Palo Alto Networks, Inc.
Page 81
Align the rack-mount bracket mounng holes on each side of the chassis with the holes on the rack rail, ensuring that the chassis is level. Secure the chassis to the rack using eight PA-7000 Series Firewall Hardware Reference 2021 Palo Alto Networks, Inc.
Install the Mandatory PA-7000 Series Firewall Front Slot Cards The PA-7000 Series firewalls require a minimum of three cards that you install in the front slots of the chassis. These cards are shipped separately from the chassis and include the following: The Switch Management Card (SMC) provides management connecvity to the chassis and HA...
Page 85
Proceed to Install the PA-7000 Series Firewall Log Processing Card (LPC). Install the PA-7000 Series Firewall Switch Management Card (SMC-B) Switch Management Card (SMC) is required for chassis operaon. On a PA-7050 firewall, you must install the SMC in slot 4 and on the PA-7080 firewall, you must install the SMC in slot 6.
Install a PA-7000 Series Firewall Log Card The PA-7000 Series firewall must have a log card installed to operate. You can install a Log Processing Card (LPC) or a Log Forwarding Card (LFC). To learn about the available log cards to...
Page 89
PA-7000 Series Firewall Installaon Install the PA-7000 Series Firewall Log Processing Card (LPC) Log Processing Card (LPC) is required for chassis operaon and the same LPC model is used in both the PA-7050 and PA-7080 firewalls. On a PA-7050 firewall, you must install the LPC in slot 8 and on the PA-7080 firewall, you must install the LPC in slot 7.
Page 91
Ensure that the handle on the front of each AMC is pulled out to the unlocked posion and then install each of the four AMCs into the four slots on the LPC. PA-7000 Series Firewall Hardware Reference 2021 Palo Alto Networks, Inc.
Page 92
Proceed to Install a PA-7000 Series Firewall Network Processing Card (NPC). Install the PA-7000 Series Firewall Log Forwarding Card (LFC) Log Forwarding Card (LFC) is required for chassis operaon and the same LFC model is used in both the PA-7050 and PA-7080 firewalls. On a PA-7050 firewall, you must install the LFC in slot 8 and on the PA-7080 firewall, you must install the LPC in slot 7.
Page 93
Remove the LFC from the anstac bag and slide it into the log card slot (slot 8 on a PA-7050 firewall or slot 7 on a PA-7080 firewall) ensuring that the handles are in the open PA-7000 Series Firewall Hardware Reference 2021 Palo Alto Networks, Inc.
Proceed to Install a PA-7000 Series Firewall Network Processing Card (NPC). Install a PA-7000 Series Firewall Network Processing Card (NPC) You can install up to 6 NPCs in a PA-7050 firewall and up to 10 NPCs in a PA-7080 firewall to expand port density and throughput.
Page 96
Firewall. • Install a PA-7000 Series Firewall NPC in a Single Chassis • Install a PA-7000 Series Firewall NPC in a High Availability (HA) Configuraon • Configure a Log Card Port on a PA-7000 Series Firewall • Configure Session Distribuon on a PA-7000 Series Firewall...
Page 97
The following images show how to install NPCs. PA-7000 Series Firewall Hardware Reference 2021 Palo Alto Networks, Inc.
Page 99
(NPC) must also match and must be installed in the same slots on each firewall. Important: When installing new NPCs in a PA-7000 Series firewall with high availability (HA) configured, PAN-OS puts the cards in a disabled state. This allows you to bring up both cards (one in each firewall) at the same me, so HA can start monitoring the cards.
Page 100
PA-7000 Series Firewall, connue the following steps to bring up the NPCs in the HA pair. Refer to Verify the PA-7000 Series Firewall NPC Configuraon for informaon on how to check the status of the NPCs. Run the following command to power-on both NPCs in the HA pair: admin@PA-7050>...
Page 101
Network Processing Card (NPC) using the type Log Card. This is required because the traffic processing and logging capabilies of a PA-7000 Series firewall exceeds the capabilies of the management port, which is the port used for these services on other firewall models.
PAN-OS Administrator’s Guide. Configure Session Distribuon on a PA-7000 Series Firewall Aer the firewall is installed and powered on, you can review the available session distribuon policies to determine if it make sense for you to change the default policy to beer fit your environment.
Connect DC Power to a PA-7080 Firewall PA-7000 Series Power Configuraon Opons This topic describes power configuraon opons for PA-7000 Series firewalls. • PA-7050 firewall—Ships with either four AC or four DC power supplies preinstalled in the front power supply slots; you can change the power type (AC or DC) in the field.
Determine PA-7000 Series Firewall Power Configuraon Requirements The number of acve power supplies required to operate a PA-7000 Series firewall depends on the power input that you connect to the power supplies (120VAC, 240VAC, or -48VDC), the number of Network Processing Cards (NPCs), and your power redundancy requirement.
The following procedure describes how to connect power to a PA-7050 firewall with AC power supplies installed. The power supplies require 120VAC 15-amp or 240VAC 20-amp power input. For details on power requirements, see Determine PA-7000 Series Firewall Power Configuraon Requirements. STEP 1 |...
The following procedure describes how to connect power to DC power supplies in a PA-7050 firewall. The DC power supplies require -40VDC to -60VDC power input. For details on power requirements, see Determine PA-7000 Series Firewall Power Configuraon Requirements. For the DC input circuit, make sure there is a 60-amp protected circuit breaker, minimum -40VDC to -60VDC, and a double pole on the input to the DC power.
The following procedure describes how to connect power to a PA-7080 firewall with AC power supplies installed. The power supplies require 120VAC 15-amp or 240VAC 20-amp power input. For details on power requirements, see Determine PA-7000 Series Firewall Power Configuraon Requirements. STEP 1 |...
The following procedure describes how to connect power to DC power supplies in a PA-7080 firewall. The power supplies require -40VDC to -60VDC power input. For details on power requirements, see Determine PA-7000 Series Firewall Power Configuraon Requirements. You must connect each of the eight DC power connecons (four on each PEM) to separate 60-amp protected circuit breakers, minimum -48VDC, and a double pole on the input to the DC power.
View PA-7000 Series Firewall Power Stascs Use the following informaon to learn how to view acve power stascs on a PA-7000 Series firewall to help you ensure power redundancy and to plan for growth. You can view the amount of power that each power supply is producing as well as the power rang for each hardware...
PA-7000 Series Firewall Installaon Connect Cables to a PA-7000 Series Firewall Aer you Connect Power to a PA-7000 Series Firewall, connect your management computer to the management port (MGT) on the firewall so you can begin the inial configuraon. You can oponally connect your management computer to the console port, which provides a serial...
Verify the PA-7000 Series Firewall LPC and NPC Configuraon Aer you install the front-slot cards and power on the PA-7000 Series firewall (described in Connect Power to a PA-7000 Series Firewall), you can use the following informaon to verify the status of the Log Processing Card (LPC) and the Network Processing Cards (NPCs).
Verify the PA-7000 Series Firewall NPC Configuraon When you first set up a PA-7000 Series firewall, all NPC slots are ready to use. If you are working with a firewall that is already deployed, you should check slot status before adding a new NPC to ensure that the NPC slot is ready.
Page 121
For example, to enable NPCs installed in slot 3 of both chassis, run the following command: admin@PA-7050> request chassis power-on slot s3 target ha-pair For informaon on installing NPCs, see Replace a PA-7000 Series Network Processing Card (NPC) and for informaon on slot status indicators, see PA-7000 Series Front Slot States.
Service the PA-7000 Series Firewall Hardware The following topics describes how to replace field-serviceable components on a PA-7000 Series firewall. For an overview of the hardware components, see PA-7000 Series Firewall Overview. > Replace a PA-7000 Series Firewall AC or DC Power Supply >...
Service the PA-7000 Series Firewall Hardware Replace a PA-7000 Series Firewall AC or DC Power Supply The following topics describe how to interpret the power supply LEDs and how to replace a PA-7000 Series firewall power supply. • Interpret the PA-7000 Series Firewall Power Supply LEDs •...
• Warning—Yellow indicates that the power supply temperature is exceeded and off indicates no warning. • Fault—Red indicates a power supply failure and off indicates no issues. Replace a PA-7000 Series AC Power Supply • Replace a PA-7050 AC Power Supply •...
Page 126
A red LED indicates a failed power supply. For details on the power supply LEDs, see Interpret the PA-7000 Series Firewall Power Supply LEDs STEP 3 | Power off the failed power supply; the switch is on the back of the chassis. Then unplug and remove the power cord (leaving the cord in place can cause arcing inside the chassis).
Page 127
Locate the failed power supply by viewing the system logs or by viewing the LED on the front of the power supply. A red LED indicates a failed power supply. For details on the power supply LEDs, see Interpret the PA-7000 Series Firewall Power Supply LEDs. STEP 3 | Power off...
Page 128
Service the PA-7000 Series Firewall Hardware supply door toward you from the le side to eject the power supply from the chassis. Then pull the power supply toward you and remove it. STEP 5 | Remove the replacement power supply from the packaging and open the front ejector door unl it is fully open.
Plug the power cable into the corresponding AC power module on the back of the chassis and turn on the power switch. The new power supply will turn on and the LED will turn green. Replace a PA-7000 Series DC Power Supply • Replace a PA-7050 DC Power Supply •...
Page 130
Service the PA-7000 Series Firewall Hardware STEP 6 | Pull the power supply ejector handle out and down from the top center of the power supply to disengage it from the chassis and then slide the power supply out of the chassis using the power supply handle.
Page 131
Service the PA-7000 Series Firewall Hardware STEP 8 | Slide the new power supply into the empty power supply slot unl it almost fully seated. Ensure that the notch near the hinged part of the ejector handle inserts into the chassis so that when you close the handle, it properly seats the power supply.
Page 132
Locate the failed power supply by viewing the system logs or by viewing the LED on the front of the power supply. A red LED indicates a failed power supply. For details on the power supply LEDs, see Interpret the PA-7000 Series Firewall Power Supply LEDs. STEP 3 | Turn off...
Page 133
Service the PA-7000 Series Firewall Hardware will eject the power supply from the chassis. Pull the power supply toward you and remove STEP 5 | Remove the replacement power supply from the packaging and open the front ejector door unl it is fully open. Remember to push the metal clip located on the boom le to release the door.
Service the PA-7000 Series Firewall Hardware Replace a PA-7080 DC PEM The DC Power Entry Module (PEM) is located on the back of the chassis and connects the power source to the power supplies located on the front of the chassis, which then distributes power to all chassis components.
Page 135
Service the PA-7000 Series Firewall Hardware STEP 4 | Remove the eight screws that secure the PEM to the chassis. STEP 5 | Remove the failed PEM from the chassis using the handles on each side of the PEM. STEP 6 | Carefully slide the replacement PEM into the PEM slot and secure it with the eight screws.
Service the PA-7000 Series Firewall Hardware Replace a PA-7000 Series Firewall Fan Tray The following topics describe how to replace a PA-7050 or PA-7080 fan tray. • Replace a PA-7050 Fan Tray • Replace a PA-7080 Fan Tray Replace a PA-7050 Fan Tray The following procedure describes how to replace a PA-7050 fan tray.
Page 137
Service the PA-7000 Series Firewall Hardware STEP 4 | Turn the top and boom fan tray thumb screws counter-clockwise unl the screws stop. This will move the latches to the open posion in preparaon for the fan tray removal. If you replace the PA-7050-FANTRAY-R-A fan tray, remove the air filter that is part of the fan tray.
Page 138
Service the PA-7000 Series Firewall Hardware Figure 10: PA-7050-FANTRAY-L-A and PA-7050-FANTRAY-R-A STEP 5 | Grasp the fan tray handles and pull the tray out about two inches. Aer all working fans have stopped spinning, remove the fan tray from the chassis. The fan tray is heavy, so be prepared to support the weight of the tray when removing it.
Page 139
Service the PA-7000 Series Firewall Hardware STEP 7 | Turn the thumb screws to the right unl they stop. This will lock the top and boom latches to secure the tray to the chassis. Use a Phillips-head screwdriver to ghten the thumb screws.
Page 140
Service the PA-7000 Series Firewall Hardware Figure 12: PA-7050-FANTRAY-L-A and PA-7050-FANTRAY-R-A STEP 8 | Verify that the fan tray is operaonal by nong the status of the fan tray LEDs and the fan LED on the SMC (slot 4). The Fault LED on the fan tray turns off, the Power LED on the fan tray illuminates green, and the fan LED on the SMC changes from red to green.
Service the PA-7000 Series Firewall Hardware Replace a PA-7080 Fan Tray The following procedure describes how to replace a PA-7080 fan tray. If one fan on a fan tray fails, the fault LED on the fan tray will turn red. If this occurs, replace the fan tray immediately to avoid service interrupon.
Page 142
Service the PA-7000 Series Firewall Hardware STEP 4 | Grasp both handles on the failed fan tray and gently push them outward as you slide the fan tray toward you about 1 inch. Wait 10 seconds to allow enough me for the working fans to stop spinning.
Page 143
Service the PA-7000 Series Firewall Hardware tray illuminates green, and the FAN LED on the SMC changes from red to green. You can view the status of the fan trays by running the CLI command: admin@PA-7080> show system environmentals fan-tray To view the status of each fan on a fan tray, run the following command: admin@PA-7080>...
Service the PA-7000 Series Firewall Hardware Replace a PA-7000 Series Firewall Air Filter The air filter is a crical part of the chassis cooling system that ensures that air entering the chassis does not contain debris. We recommend that you replace the first-generaon filter every six months or less, depending on the environment where the firewall is located, to prevent...
Page 145
Service the PA-7000 Series Firewall Hardware STEP 3 | Push the filter in unl the rear ball joint(s) snap into place. If you are installing a PA-7050- FANTRAY-R-A air filter, turn the air filter screws clockwise unl ght. Figure 13: PA-7050 Chassis Air Filter PA-7000 Series Firewall Hardware Reference 2021 Palo Alto Networks, Inc.
Service the PA-7000 Series Firewall Hardware Replace a PA-7000 Series Firewall Front Slot Card The PA-7000 Series firewalls require one Switch Management Card (SMC), one Log Processing Card (LPC), and at least one Network Processing Card (NPC). The procedures to replace a front slot card on a PA-7050 and PA-7080 firewall are almost idencal.
Page 150
Service the PA-7000 Series Firewall Hardware STEP 5 | Remove the replacement SMC from the anstac bag. If you are replacing a failed PA-7050- SMC-B or PA-7080-SMC-B, install the SSDs that you removed in the previous step. STEP 6 | Slide it into the SMC slot, ensuring that the handles are in the open posion.
Replace a PA-7000 Series Log Card Use the following topics to learn how to replace a PA-7000 Series Log Processing Card (LPC) or a PA-7000 Series Log Forwarding Card (LFC). The LPC has disk drives that must be removed and re- installed, while the LFC does not contain disk drives.
Page 152
Service the PA-7000 Series Firewall Hardware STEP 5 | Remove the LPC by pulling the inner release lever to unlock the outer release lever and then use the outer release lever to pull the LPC out of the chassis. The LPC has a double-lever on each side of the card. Aer loosening the thumb screws, you must pull the inner lever toward you to unlock the outer lever from the chassis and then pull the outer lever to release the card.
Page 153
Service the PA-7000 Series Firewall Hardware STEP 6 | Remove the new LPC from the anstac bag. Slide the LPC into the LPC slot, ensuring that the handles are in the open posion. When the card is about 1/4-inch from being fully inserted, adjust the levers to align with the chassis and then close the levers to seat the card in place.
Page 154
Re-Index the LPC Drives before powering on the chassis. Replace a PA-7000 Series Log Forwarding Card (LFC) If the LFC fails, the chassis reboots and will aempt to recover the LFC. If the LFPC connues to fail and the chassis reboots more than 3 mes in 30 minutes, it enters maintenance mode at which me you must power off...
Page 155
Service the PA-7000 Series Firewall Hardware STEP 4 | Remove the LFC by pulling the inner release lever to unlock the outer release lever and then use the outer release lever to pull the LFC out of the chassis. The LFC has a double-lever on each side of the card. Aer loosening the thumb screws, you must pull the inner lever toward you to unlock the outer lever from the chassis and then pull the outer lever to release the card.
Tighten the thumb screws on each side of the LFC to secure it to the chassis. Replace a PA-7000 Series Network Processing Card (NPC) If a Network Processing Card (NPC) fails, the card will reboot and aempt to recover. If the card does not recover, it will change to a down state.
Page 157
NPC. • Replace PA-7000 Series Firewall NPC in a Single Chassis • Replace PA-7000 Series Firewall NPC in a High Availability (HA) Configuraon • PA-7000 Series Front Slot and Card States • PA-7000 Series Firewall Network Processing Card (NPC) Troubleshoong Commands...
Page 158
Service the PA-7000 Series Firewall Hardware STEP 4 | Remove the NPC using the appropriate procedure below depending on the version of the installed NPC. There are two versions of the PA-7000 20G NPC as described in PA-7000 NPC. Version 1 has a black slide switch on each side of the card that is used to release the ejector lever.
Page 159
Service the PA-7000 Series Firewall Hardware ejector levers. Wait for the green power LED to go off and then pull the release lever toward you to pull the card out of the chassis. The following images show the two versions of the PA-7000 20G NPCs.
Page 160
Service the PA-7000 Series Firewall Hardware Figure 19: Install or Remove a PA-7000 20G Version 2 NPC STEP 5 | Remove the replacement NPC from the anstac bag and slide it into the empty slot, ensuring that the handles are in the open posion. When the card is about 1/4-inch from being fully inserted, adjust the levers to align with the chassis and then close the levers to seat the card in place.
Page 161
PA-7000 Series Firewall Network Processing Card (NPC) Troubleshoong Commands. Replace PA-7000 Series Firewall NPC in a High Availability (HA) Configuraon When HA is configured on the firewall, the firewall is designed to allow the inseron of new Network Processing Cards (NPCs) without causing a failover. This is accomplished by the system not allowing a new card to come up in one chassis unl an NPC is installed in the same slot on the...
Page 162
Service the PA-7000 Series Firewall Hardware STEP 2 | Make note of the cable connecons and then loosen the screws on each side of the card that secure the NPC to the chassis. Releasing the eject levers on the NPC triggers a micro switch that powers down the card to prepare it for removal.
Page 163
For slot status informaon and troubleshoong, see the following secons: PA-7000 Series Front Slot States PA-7000 Series Firewall Network Processing Card (NPC) Troubleshoong Commands. PA-7000 Series Front Slot and Card States You can view the slot and card status informaon on a PA-7000 firewall using the web interface or the command line interface (CLI).
Page 164
The card has failed and needs to be replaced. Unsupported The card is not a supported type for this slot. PA-7000 Series Firewall Network Processing Card (NPC) Troubleshoong Commands The following table describes common commands that you can use to troubleshoot NPC issues on a PA-7000 Series firewall.
Page 165
Service the PA-7000 Series Firewall Hardware Purpose Command stays powered off, even aer a chassis reboot. Enable a slot so the NPC can admin@PA-7080> request pass traffic. chassis enable slot <slot-number> Enable new NPCs on In an HA configuraon, you must install the same number and...
Service the PA-7000 Series Firewall Hardware Replace a PA-7000 Series SMC Boot Drive The first generaon switch management cards (PA-7050-SMC and PA-7080-SMC) come with an mSATA solid-state drive (SSD) that contains the PAN-OS boot images and configuraon files. If your PAN-OS configuraon file is too large to fit on the pre-installed SSD, you can replace the stock SSD with the PAN-PA-7000-MSATA-IMG.
Page 167
Service the PA-7000 Series Firewall Hardware STEP 6 | Gently press the two clips to release the mSATA. Once the mSATA pops up, carefully remove it from the socket. STEP 7 | Carefully place the new mSATA into the socket. Ensure that the label displaying the Palo Alto Networks SKU and bar codes is facing up.
Page 168
Service the PA-7000 Series Firewall Hardware STEP 11 | Boot the chassis with the new mSATA installed. When prompted, log in and reset the firewall to factory default sengs. Aer the reset operaon is complete, load your preferred version and configuraon of PAN-OS.
Service the PA-7000 Series Firewall Hardware Replace a PA-7000 Series Firewall LPC Drive The Log Processing Card (LPC) contains four Advanced Mezzanine Cards (AMCs) used to house one 2.5” SATA drive each. The first two drives (A1 and A2) are configured in a RAID 1 array and the second two drives (B1 and B2) are configured in a second RAID 1 array.
Page 170
Service the PA-7000 Series Firewall Hardware system raid slot s7 remove A2 This procedure is based on a PA-7080 firewall where the LPC is installed in slot s7. If you are working on a PA-7050 firewall, the LPC is installed in slot s8. For a PA-7050 firewall, replace slots7 with slot s8 in those commands that specify the LPC slot...
Page 171
Service the PA-7000 Series Firewall Hardware STEP 4 | Gently pull the AMC release handle of the failed drive toward you unl it stops to unlock the AMC from the chassis and then completely remove the AMC. The FAULT LED on the AMC that contains the failed drive will show red.
Page 172
Service the PA-7000 Series Firewall Hardware STEP 5 | Remove the replacement drive from the packaging and compare the drive model on the label with the drive model of the failed drive. Proceed as follows based on your findings: • If the replacement drive is the same model number of the failed drive that you removed, then connue to 6.
Page 173
Service the PA-7000 Series Firewall Hardware STEP 6 | (Same model replacement drive only) Install a replacement drive that is the same model as the other drive in the RAID 1 array: 1. Pull the AMC handle on the replacement drive outward unl it stops to prepare it for installaon into the LPC.
Page 174
Service the PA-7000 Series Firewall Hardware STEP 7 | (Different model replacement drive only) Install a replacement drive that is a different model than the other drive in the RAID 1 array: When you iniate the copy command as described in the following steps, logging and log query will not be available on the drive array unl the copy is complete and the disk...
Page 175
Service the PA-7000 Series Firewall Hardware 6. Install the second replacement drive. In this example, physically remove the drive from slot A1 and then install the second replacement drive—one that is the same model as you installed in slot A2—into slot A1.
firewall using the console port because you will shut down all NPCs to avoid generang new traffic logs during indexing. STEP 1 | Aer replacing an LPC as described in Replace a PA-7000 Series Log Processing Card (LPC), power on the chassis. STEP 2 | If the firewall is in a high availability (HA) configuraon, run the following commands to...
Page 177
Service the PA-7000 Series Firewall Hardware chassis admin-power-off slot <slot-number> For example, if there is an NPC in slot 1, run the following command: admin@PA-7050> request chassis admin-power-off slot s1 Do the same for each installed NPC unl all NPCs show AdminPowerOff. This ensures that network traffic will not traverse the firewall during indexing.
Page 178
Service the PA-7000 Series Firewall Hardware STEP 7 | If you powered off the NPCs, power them back on by running the following commands: To view the status of each NPC: admin@PA-7050> show chassis status For each NPC that is in the AdminPowerOff state, run the following command: admin@PA-7050>...
Page 179
Service the PA-7000 Series Firewall Hardware EDM-Vsys5-Sec-Pol-2 allow EDM-Vwire-Vsys5 10.5.40.161 aged-out You can also use the web interface to view logs. For example, to view the traffic logs, select Monitor > Logs > Traffic. PA-7000 Series Firewall Hardware Reference 2021 Palo Alto Networks, Inc.
Service the PA-7000 Series Firewall Hardware Replace a PA-7050-SMC-B or PA-7080-SMC-B Drive The PA-7050-SMC-B and PA-7080-SMC-B have two SSD drives in a RAID 1 configuraon. This configuraon provides redundancy so if a drive in a RAID 1 array fails there is no unplanned service interrupon or loss of data.
Page 181
Service the PA-7000 Series Firewall Hardware Drive id Sys2 degraded panrepo clean Drive id Sys1 active sync Drive id Sys2 degraded swap clean Drive id Sys1 active sync Drive id Sys2 degraded STEP 2 | Run the following command to shut down the firewall: admin@PA-7080>...
Page 182
Service the PA-7000 Series Firewall Hardware STEP 5 | Remove the failed SMC-B from the chassis. The following images show the first-generaon SMCs; the procedure is the same for the second-generaon SMCs (SMC-B). PA-7000 Series Firewall Hardware Reference 2021 Palo Alto Networks, Inc.
Page 183
Service the PA-7000 Series Firewall Hardware STEP 6 | Remove the failed drive (Sys 2 in this example). Turn the screw on the SSD drive slot door counter-clockwise and then remove the door. Pull the failed drive out of the SSD drive slot.
Page 184
Service the PA-7000 Series Firewall Hardware STEP 7 | Insert the replacement drive (into the Sys 2 slot in this example), reinstall the drive slot door and turn the door screw clockwise unl ght. STEP 8 | Reinstall the SMC-B into the chassis.
You can replace the 1TB drives with 2TB drives to double the log storage capacity to 4TBs. The logs on the 1TB drives will not be available aer upgrading drives on a PA-7000 Series firewall that is running a PAN-OS 7.0.7 or earlier release. Even if this is acceptable, we recommend that you perform this upgrade during a maintenance window.If it is important...
Page 186
Service the PA-7000 Series Firewall Hardware status : active sync card serial : 002901000067 Disk id A2 Present model : ST91000640NS size : 953869 MB status : active sync card serial : 002901000369 Disk Pair S7B Available Status clean Disk id B1...
Page 187
Service the PA-7000 Series Firewall Hardware system raid slot s7 remove A1 This procedure is based on a PA-7080 firewall where the LPC is installed in slot s7. If you are working on a PA-7050 firewall, the LPC is installed in slot s8. For a PA-7050 firewall, replace slot s7 with slot s8 in those commands that...
Page 188
Service the PA-7000 Series Firewall Hardware 3. Remove a new 2TB drives from the packaging and pull the AMC handle out to prepare it for installaon into the LPC. Install the drive into the empty drive slot (A1 in this example) and then push in the release handle on the AMC to lock it to the chassis.
Page 189
Service the PA-7000 Series Firewall Hardware system raid detail Connue running this command to view the RAID detail output unl you see that the array (A1/A2 in this example) shows Available. At this point, drive A2 will show not in use because there is a drive size mismatch.
Page 190
Service the PA-7000 Series Firewall Hardware card serial : 002901000064 To upgrade the B1/B2 drive array, repeat these procedures replacing the drive designators. For example, replace A1 with B1 and A2 with B2 to upgrade the drives in the B1/B2 RAID 1 array.
Page 191
Service the PA-7000 Series Firewall Hardware :admin@PA-7080> request system raid slot s7 remove A2 This procedure is based on a PA-7080 firewall where the LPC is installed in slot s7. If you are working on a PA-7050 firewall, the LPC would be installed in slot s8.
Page 192
Service the PA-7000 Series Firewall Hardware 3. Remove two 2TB drives from their packaging and pull the AMC handle out on each drive to prepare them for installaon into the LPC. Install the drives into the empty slots (A1 and A2) and then push in the release handle on each AMC to lock the AMCs to the chassis.
Page 193
Service the PA-7000 Series Firewall Hardware system raid detail The following output shows that the S7A array is Available. At this point, drive A2 will show not in use because you have not added it to the new RAID 1 array configuraon.
filter are listed separately for each model. View the Datasheet informaon on features, performance, and capacity numbers. > PA-7000 Series Firewall Physical Specificaons > PA-7000 Series Firewall Electrical Specificaons > PA-7000 Series Firewall Environmental Specificaons...
PA-7000 Series Firewall Specificaons PA-7000 Series Firewall Electrical Specificaons Use the following topics to learn about the PA-7000 Series firewall electric specificaons and the types of power cords you can use. • PA-7000 Series Firewall Component Electrical Specificaons • PA-7000 Series Firewall Power Cord Types PA-7000 Series Firewall Component Electrical Specificaons...
• Output Power— +2500 Was PA-7000 Series Firewall Power Cord Types The PA-7000 Series firewalls ship with four AC or four DC power supplies by default. On the PA-7080 firewall, you can order up to four addional power supplies (eight total) and power cords are included with each AC power supply.
PA-7000 Series Firewall Specificaons PA-7000 Series Firewall Environmental Specificaons The following table describes PA-7050 and PA-7080 firewall environmental specificaons. Specificaon Value Operang temperature range 0° to 50°C (32°F to 122°F) Storage temperature range -20° to 70°C (-4°F to 158°F) Humidity 5% to 90% non-condensing Chassis airflow...
Our products meet standards for product safety and electromagnec compability when used for their intended purpose. To view compliance statements for the PA-7000 Series firewalls, see PA-7000 Series Firewall Compliance...
PA-7000 Series Firewall Hardware Compliance Statements PA-7000 Series Firewall Compliance Statements The following are the PA-7000 Series firewall hardware compliance statements: • VCCI This secon provides the compliance statement for the Voluntary Control Council for Interference by Informaon Technology Equipment (VCCI), which governs radio frequency emissions in Japan.
Page 205
PA-7000 Series Firewall Hardware Compliance Statements • BSMI EMC Statement—User warning: This is a Class A product. When used in a residenal environment it may cause radio interference. In this case, the user will be required to take adequate measures.
Need help?
Do you have a question about the PA-7000 Series and is the answer not in the manual?
Questions and answers