what does "SWITCH" in hardware architecture mean?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

what does "SWITCH" in hardware architecture mean?

L5 Sessionator

One of my customers is using PA-3020 and thinking about replace.

When I comparing following diagrams, I have one question.

 

PA-3020 has dedicated "signature matching", "security processing", and "network processing" as below

Image 004.png

 

Compare to above, PA-400 has ONE dedicated processor with 3 features included.

Image 003.png

 

PA-3200 has THREE dedicated processors which are same as PA-3020.

Image 001.png

 

Here is question.

I can see Security Processor but can't find "signature matching" nor "network processing".

Instead, I can see "switch". What this switch really does? Is this same as "network processing"??

 

Image 002.png

 

Regards,

Emr

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

the PA-3400 has a switch fabric instead of the fpga based network processor in the PA-3200, hence the relabelling

there's no FPGA's in the PA-3400 so no signature lookups on dedicated hardware

the PA-3200 slide is slightly misleading as the 3220 also doesn't have signature lookups on dedicated hardware

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

3 REPLIES 3

Cyber Elite
Cyber Elite

the PA-3400 has a switch fabric instead of the fpga based network processor in the PA-3200, hence the relabelling

there's no FPGA's in the PA-3400 so no signature lookups on dedicated hardware

the PA-3200 slide is slightly misleading as the 3220 also doesn't have signature lookups on dedicated hardware

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Cyber Elite
Cyber Elite

What is best resource for this info or is it internal only?

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

@reaper 
Thank you, I understood that.

 

@Raido_Rattameister 

The articles I know is only this one (except legacy platforms):

https://www.paloaltonetworks.com/resources/pa-series-next-generation-firewalls-hardware-architecture...

For more details, I believe that would be internal.

  • 1 accepted solution
  • 2688 Views
  • 3 replies
  • 2 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!