Secure Edge Simplified: Announcing Native Layer 2 Switching on Palo Alto Networks NGFWs

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Community Blogs
4 min read
L2 Linker

Secure Edge.png

 

If you manage branch locations, whether retail stores, clinics, bank branches, or kiosks, you know the pain. Every site requires a firewall, a router, and a switch. That's three separate devices to procure, deploy, configure, monitor, upgrade, and troubleshoot, multiplied across dozens or hundreds of locations. 

 

The result? Spiraling capital costs, management overhead across multiple consoles, and, most critically, the gaps in your security posture where east-west traffic within the branch passes between devices without deep inspection. For example, isolating guest or third-party device networks (HVAC, IoT like lightswitches and sensors, cameras) and PCI-DSS compliant point of sale (PoS) systems requires additional network infrastructure and complex configurations.

 

The Solution: Three Tiers, One Cohesive Box

 

Today, we are thrilled to break down these operational walls. With the release of PAN-OS 12.2 Ceres, we are introducing native Layer 2 Switching support on our Next-Generation Firewalls (NGFWs). This brings advanced protections against Frontier AI driven threat velocity and novelty of attacks into all parts of your network.

 

For the first time, a single Palo Alto Networks NGFW can serve as your branch firewall, router, and switch — delivering best-in-class security across every traffic flow, including intra-VLAN east-west traffic that traditional switches forward blindly.

 

This capability is rolling out across:

 

  • Select 5th-Generation PA-500 Series Platforms (Supported in the PAN-OS 12.2.2 release)
  • All 5th-Generation PA-1500 Series Platforms (Supported in a future release at product launch)

 

Table 1: PA-Series platforms support for Layer 2 switching

Model

Data Ports

PA-1530-POE*

32 ports (16 PoE)

(1Gx8, 5Gx4, 10Gx16, 25Gx4)

PA-1520-POE*

32 ports (16 PoE)

(1Gx8, 5Gx8, 10Gx12, 25Gx4)

PA-1510-POE*

32 ports (16 PoE)

(1Gx16, 5Gx8, 10Gx8)

PA-560

24 ports

(1Gbps x 20, 10Gbps x 4)

PA-555-POE

16 ports (8 PoE)

(1Gbps x 10, 2.5Gbps x 4, 10Gbps x 2)

PA-550

16 ports

(1Gbps x 14, 10Gbps x 2)

PA-545-POE

16 ports (4 PoE)

(1Gbps x 12, 2.5Gbps x 4)

Note: *PA-1500 series support is planned for a future PAN-OS release. 



Front panel view of PA-560

PA-560.png

 

What We're Delivering

 

Full Layer 2 switching capabilities built into the NGFW, including:

 

  • VLAN Trunking — Transport multiple VLANs over a single physical link, just as you would with a dedicated switch.
  • Intra-VLAN Security Inspection — Micro-segment your network and inspect east-west traffic up to Layer 7 with App-ID, Threat Prevention, and the full Palo Alto Networks security stack. A compromised IoT device on VLAN 10 attempting lateral movement to another device on the same VLAN? Now you see it, and you stop it.
  • Multiple Spanning Tree Protocol (MSTP) — Maintain loop-free topologies across your switching environment.
  • Storm Control — Protect against broadcast, multicast, and unicast storms that can degrade network performance.


Suitable for: Small/Medium size branches

 

The select PA-500 series in the Table 1 above and PA-1500 series platforms cater to small & medium branch environments. This covers a wide range of edge/branch deployments as covered in the table below.

 

Table 2: Sample deployment categories which can benefit from the device with firewall, routing and switching functions.

Category

Example customer type

Kiosks

ATMs, Airline counters, Currency exchange

Food & Retail

Sandwich shops, Cafes, Neighborhood stores

Branch Office

Tax services, Real Estate, DMV location

Financials

Bank branch, Insurance agency

Clinics

Dentist, Dialysis center, Chiropractor

Manufacturing/Services

OT remote location, Rental car office 

Education

Math academy, Art/Music tutor

 

Use case: Operational simplicity

 

  • Condense 3 Layers Into 1: Replace your branch router, switch, and firewall devices with the purpose-built PA-500 or PA-1500 series converged platforms for branches.
  • Unified Management Plane: One management plane for security, routing, and switching. One device to upgrade. One policy framework. For organizations managing hundreds of branch locations with templatized infrastructure, this dramatically reduces operational complexity and the number of upgrade touchpoints.
  • Zero Extra Licensing Costs: This isn't a feature hidden behind an aggressive paywall. Layer 2 switching is natively included with PAN-OS. As long as your device has a valid support entitlement, you are ready to switch.

 

before-after.png

 

Use case: Segment and inspect East-West traffic

 

  • Uncompromised Security: Gain visibility into the branch local traffic and use the rich feature stack to secure the east west traffic.
  • Predictable Performance: With our Single-Pass Architecture, get consistent and predictable performance even with advanced security capabilities turned on.

 

WAN connectivity.png

 

Conclusion 

 

The branch network doesn't need more devices. It needs fewer devices doing more, without compromising security. That's exactly what Layer 2 switching on Palo Alto Networks NGFWs delivers.

 

To learn more, visit the tech docs.

  • 42 Views
  • 0 comments
  • 0 Likes
Labels
Contributors