Predictable performance, broad threat coverage
Classify all applications on all ports, all the time Identify any application, regardless of port, encryption (SSL or SSH) or evasive technique employed, and use the application – not the port – as the basis for all your safe enablement policy decisions: allow, deny, schedule, inspect and apply traffic-shaping. You can also categorize unidentified applications for policy control, threat forensics or custom App-ID™ technology development.
Enforce consistent policies for any user, at any location Deploy consistent policies to local and remote users running on Windows®, macOS®, Linux, Android® or Apple iOS platforms. You can choose from a multitude of ways to identify users, including GlobalProtect™ network security for endpoints, captive portal, AAA servers, Microsoft Active Directory®, Terminal Services, LDAP and Novell eDirectory™, as well as other sources you can add using XML API. Our SD-WAN subscription also lets you leverage the PA-3200 Series appliances as an SD-WAN hub to interconnect all your branch locations.
Prevent known and unknown threats Block a range of threats, including exploits, malware and spyware, across all ports, regardless of threat-evasion tactics employed. Gain full visibility into the details of all TLS encrypted connections and stop threats hidden within encrypted traffic, including traffic that uses TLS1.3 and HTTP/2 protocols. These appliances limit the unauthorized transfer of files and sensitive data to safely enable web and application access. They also identify unknown malware, analyze it based on malicious behaviors, and then automatically create and deliver protection.
Enterprise Firewall Leader

Learn why an independent research firm named us a Leader in enterprise firewalls and ranked us highest in the Strategy category. We also achieved the highest possible scores in usability, threat intelligence, automated malware analysis, IDS/IPS, ICS/OT/IoT and 12 other evaluated criteria.

Get report
Meet the family
PA-3260 9.2 Gbps App-ID throughput
PA-3250 6.2 Gbps App-ID throughput
PA-3220 5.0 Gbps App-ID throughput

Schedule a Test Drive

If you're ready to take the test drive, pick the best time for you below!

All times are displayed in Pacific Standard Time

Related products & services
VM-Series Protect your private and public cloud deployments with our virtualized firewalls that provide consistent security and superior integration with cloud infrastructures.
CN-Series Keep cloud native applications nimble and secure with the industry’s first container next-generation firewall built specifically for Kubernetes environments.
Security Subscriptions Cloud delivered security subscriptions that extend security policies with threat protection that is constantly kept up to date.
Panorama Reduce management complexity while gaining greater visibility into your network, as well as enhanced security context so you can respond to threats quickly and effectively.
Platinum Support Platinum Support delivers optimal support for your Next-Generation Firewalls, exactly when you need it the most.
QuickStart Services Expedite your successful deployment of the firewall-as-a-service components with day-one protection.