UK’s trusted IT infrastructure partner since 2003
sales@servnetuk.com
0800 987 4111
Servnet
ConfiguratorGet in Touch
← Comparison Tool

🛡️ Palo Alto PA-820 vs PA-850

AI-powered analysis across 22 matched specifications

Palo Alto Networks PA-820 1U rack-mounted NGFW appliance front view
Palo Alto PA-820
Palo Alto
7.7
Overall Score
Best for UK branch offices and mid-size sites up to ~300 users that need full PAN-OS NGFW capability, App-ID and Threat Prevention on a single 1GbE-centric uplink without paying for 10GbE headroom.
View Full Details
Palo Alto Networks PA-850 1U rack-mounted NGFW appliance front view
Palo Alto PA-850
Palo Alto
8.1
Overall Score
Best for mid-enterprise campus or regional datacentre edges up to ~500 users requiring dual 10GbE uplinks, redundant power as standard, and session headroom for SSL decryption and high-density IoT or guest traffic.
View Full Details

Performance Overview

Scores based on quantifiable specification values (1-10 scale)

PerformanceConnectivitySecurity servicesManageabilityResilienceValue
Palo Alto PA-820
Palo Alto PA-850
Performance
Palo Alto PA-820
7.2
Palo Alto PA-850
7.8
Connectivity
Palo Alto PA-820
7.4
Palo Alto PA-850
8.1
Security services
Palo Alto PA-820
8.5
Palo Alto PA-850
8.5
Manageability
Palo Alto PA-820
8.6
Palo Alto PA-850
8.6
Resilience
Palo Alto PA-820
7.5
Palo Alto PA-850
8.2
Value
Palo Alto PA-820
7.8
Palo Alto PA-850
7.5

Detailed Specifications

Specification
Palo Alto PA-820
Palo Alto
Palo Alto PA-850
Palo Alto
Key Metrics
Firewall throughput (App-ID)1.5 Gbps1.9 Gbps
Threat Prevention throughput800 Mbps900 Mbps
IPSec VPN throughput1.2 Gbps1.6 Gbps
Maximum concurrent sessions128,000192,000
Form factor1U rackmount1U rackmount
Performance
App-ID firewall throughput1.5 Gbps1.9 Gbps
Threat Prevention throughput800 Mbps900 Mbps
IPSec VPN throughput1.2 Gbps1.6 Gbps
Concurrent sessions128,000192,000
Session capacity uplift vs siblingBaseline+50% sessions, +27% throughput
Connectivity
10/100/1000 RJ45 ports1212
1GbE SFP ports48
10GbE SFP+ ports24
Total data interfaces1824
Dedicated management / HAMGT + console (standard PA-800 layout)MGT + console + dedicated HA ports
Resilience & Management
High availability modesActive/Passive, Active/ActiveActive/Passive, Active/Active
Redundant power supplyOptionalIncluded (redundant PSU)
ManagementPAN-OS, Panorama, CLI, web UIPAN-OS, Panorama, CLI, web UI
Cloud-delivered security servicesThreat Prevention, WildFire, URL Filtering, DNS Security (subscription)Threat Prevention, WildFire, URL Filtering, DNS Security (subscription)
Deployment Fit
Target deploymentMid-size branch / small datacentre edgeMid-enterprise campus / regional datacentre
Typical user countUp to ~300 usersUp to ~500 users
Suited to SSL inspection at full rateLimited headroomModerate headroom

Expert Analysis

AI-generated based on published specifications

The practical gap between the PA-820 and PA-850 is modest but real: roughly 27% more App-ID throughput, 50% more concurrent sessions, double the SFP+ count, and redundant power as standard rather than optional. PAN-OS, the security subscriptions (Threat Prevention, WildFire, URL Filtering, DNS Security) and the management experience via Panorama are identical, so the choice is purely a sizing and resilience decision, not a feature one.

The PA-820 is the right pick when the site genuinely fits inside its envelope — typically a UK branch or mid-size office of up to around 300 users with a single uplink and modest SSL decryption requirements. It is the more cost-effective box and gives you the full PAN-OS feature set, but it has limited headroom once you turn on Threat Prevention plus decryption plus logging at peak. Buyers who expect any of those workloads to grow should size up rather than refresh early.

The PA-850 earns its premium in two specific places: session capacity (192k vs 128k matters for sites with lots of short-lived flows, IoT or guest Wi-Fi) and the extra 10GbE SFP+ pair, which is what most UK regional datacentres or HQ edges actually need for dual-uplink resilience to two carriers. Redundant PSU as standard also removes a line item that many procurement teams forget on the 820.

Recommendation: choose the PA-820 for a stable branch with a known user count and a single ISP; choose the PA-850 where you need dual 10GbE uplinks, HA with redundant power, or any prospect of enabling SSL decryption across the user base. Note that both models are end-of-sale from Palo Alto — UK buyers should weigh remaining support life and consider the PA-400 series for new deployments where lifecycle matters under NIS2 and NCSC guidance.

Palo Alto PA-820
Best for UK branch offices and mid-size sites up to ~300 users that need full PAN-OS NGFW capability, App-ID and Threat Prevention on a single 1GbE-centric uplink without paying for 10GbE headroom.
Palo Alto PA-850
Best for mid-enterprise campus or regional datacentre edges up to ~500 users requiring dual 10GbE uplinks, redundant power as standard, and session headroom for SSL decryption and high-density IoT or guest traffic.

Ready to proceed?

Want to compare different products or add more to this comparison?

Open Interactive Comparison Tool →