← All blog articles

Palo Alto PA-220 and PA-800 End of Life: Dates, PAN-OS Limits and What Replaces Them

Jacky De Schepper
Palo Alto PA-220 and PA-800 End of Life: Dates, PAN-OS Limits and What Replaces Them

The Palo Alto Networks PA-220 reaches end of life on 31 January 2028. The PA-820 and PA-850 follow on 31 August 2029, and the ruggedised PA-220R on 31 January 2030. All four are already past end of sale.

Those dates suggest plenty of time. The date that decides how safe these firewalls are is a different one: the PAN-OS version each model can run. The PA-220 is capped at PAN-OS 10.2, which left standard support in August 2025. The PA-800 series is capped at PAN-OS 11.1, which leaves standard support in May 2027.

There is also news for anyone planning a like-for-like refresh. On 22 September 2026, Palo Alto announced end of sale for the non-rugged PA-400 series, the usual replacement for the PA-220.

When do the PA-220 and PA-800 series reach end of life?

The PA-220 reached end of sale on 31 January 2023 and reaches end of life on 31 January 2028. The PA-820 and PA-850 reached end of sale on 31 August 2024 and reach end of life on 31 August 2029. The PA-220R follows on 31 January 2030. After end of life, Palo Alto provides no support, software updates or hardware replacement.

Model End-of-sale announced End of sale End of life Last supported PAN-OS Standard support of that PAN-OS ends
PA-220 1 August 2022 31 January 2023 31 January 2028 10.2 27 August 2025 (ended)
PA-220R 31 July 2024 31 January 2025 31 January 2030 10.2 27 August 2025 (ended)
PA-820 2024 31 August 2024 31 August 2029 11.1 3 May 2027
PA-850 2024 31 August 2024 31 August 2029 11.1 3 May 2027

Source: Palo Alto Networks hardware end-of-life dates and end-of-sale announcements. After standard support ends, the last supported PAN-OS version stays on extended support until the hardware reaches end of life.

One policy detail catches teams out. Palo Alto expects continuous support coverage. If a support contract lapses during the end-of-life period, administrators on Palo Alto’s own community report that it cannot be reinstated later. Keep renewals running until you decide the unit’s final date.

Hardware support is not the same as a supported firewall

This is the gap in most end-of-life pages: they list when the box stops being supported and stop there.

Between end of sale and end of life, the hardware is covered, but the software is frozen at a version the rest of the product line has moved past. On extended support, Palo Alto maintains the last version for these models, focused on fixes rather than new capability. Fixes are generally developed on current branches and carried back to the older ones. That keeps the unit patched, but it also means the model does not get the newer inspection features of PAN-OS 11 and 12, and administrators report that the smaller units struggle with late 10.2 releases.

The PA-220 is the clearest example. Administrators on r/paloaltonetworks describe commit times of several minutes and reboots where the login service needs close to twenty minutes before it accepts credentials. On a unit like that, every patch window is long, and long patch windows get postponed.

For organisations under NIS2, that is where the hardware date and the compliance question separate. Article 21 asks for vulnerability handling and basic cyber hygiene on systems like a perimeter firewall. In Belgium, CyFun asks for security updates at every assurance level. A firewall that is technically under support but frozen on an old branch, with patches that are slow to apply, is harder to defend in an audit than the end-of-life date suggests.

The security exposure on older PAN-OS

Perimeter firewalls with GlobalProtect or an exposed management interface have been among the most targeted devices of the last two years. CISA lists several PAN-OS vulnerabilities as exploited in the wild:

CVE What it is Relevance for these models
CVE-2024-3400 (CVSS 10.0) Command injection in the GlobalProtect feature Affected PAN-OS 10.2, 11.0 and 11.1; hotfixes were released for 10.2 and 11.1
CVE-2024-0012 (CVSS 9.8) Authentication bypass in the management web interface Affected 10.2 through 11.2; fixed in maintenance releases
CVE-2024-9474 Privilege escalation in the management web interface, chained with CVE-2024-0012 Fixed alongside CVE-2024-0012
CVE-2026-0257 Authentication bypass in PAN-OS Added to the CISA catalogue on 29 May 2026 based on active exploitation

Source: CISA Known Exploited Vulnerabilities catalogue and Palo Alto Networks security advisories.

Two lessons follow. Multi-factor authentication does not help against flaws that are exploited before authentication, as CVE-2024-3400 was. And a management interface reachable from the internet turns every such flaw into an incident. Keep management access on a separate, internal network, whatever you decide about the hardware.

The successors, and a successor that is already leaving

Palo Alto positions the PA-400 series as the branch replacement for the PA-220 and the PA-1400 series as the replacement for the PA-800 series.

PA-220 PA-440 PA-820 PA-850 PA-1410
Firewall throughput (App-ID, vendor datasheet) 540 Mbps 3.0 Gbps 1.6 Gbps 2.0 Gbps 8.5 Gbps
Interfaces 8x 1G RJ-45 8x 1G RJ-45 4x 1G RJ-45, 8x 1G SFP 4x 1G RJ-45, 4x 1G SFP, 4x 10G SFP+ Includes 10G SFP+ and multi-gigabit ports
Highest PAN-OS 10.2 12.2 11.1 11.1 Current releases
End of sale 31 January 2023 22 March 2027 31 August 2024 31 August 2024 Not announced
End of life 31 January 2028 21 March 2032 31 August 2029 31 August 2029 Not announced

Throughput figures are vendor datasheet values for App-ID enabled firewall throughput. Measurement conditions change between hardware generations, so compare using current datasheets for your traffic mix.

On raw capacity, both successors are a clear step up. The catch is the lifecycle. Palo Alto’s end-of-sale announcement of 22 September 2026 covers the non-rugged, non-cellular PA-400 models: the PA-410, 415, 440, 445, 450 and 460. Their end of sale is 22 March 2027. A team that replaces a PA-220 with a PA-440 in the coming months buys a model with less than six months of sales life left, even though support runs until 2032.

Replacing hardware also means replacing licences. Subscriptions are tied to the serial number of the old unit, so a refresh means buying new subscriptions and usually paying for both during the parallel run. Features such as GlobalProtect host checks need their own licence on the new unit.

What staying on the old units really costs

For a PA-220 or PA-800 you keep, the cost is mostly not the support invoice.

  • Frozen features. No access to the inspection features of newer PAN-OS versions, for as long as you keep the unit.
  • Slower patching. Fixes arrive through extended support, and on the PA-220 each patch window is long because of slow commits and reboots.
  • A migration that grows with time. Moving a configuration to a new unit requires the old unit to be on a compatible PAN-OS train. Units kept on older versions for speed have to step through several upgrades before their configuration can move, on hardware that is slow to upgrade.
  • No resale value. Palo Alto’s secondary market policy does not recertify end-of-sale or end-of-life hardware, so a used unit cannot be brought back under support by a new owner.

When a like-for-like refresh is the wrong answer

A hardware refresh is still the right call in some places. Sites with heavy internal traffic between local networks, such as production environments, warehouses or hospitals, benefit from inspection on site. Operational technology networks that may not depend on a cloud service need a local enforcement point. Data centres serving an on-site workforce keep a clear role for a physical firewall.

Many PA-220 and PA-800 deployments look different. They sit in offices where most users work partly remotely, most applications run in Microsoft 365 or other SaaS, and the firewall mainly does three jobs: remote access through GlobalProtect, internet egress, and basic site connectivity. Remote users are backhauled through the office to reach the internet, and the VPN portal is the most exposed service on the network.

For those sites, the more useful question is which of the three jobs needs a box at all. Remote access can move to zero trust network access, with no listening portal on the perimeter. Web security can move to a secure web gateway that inspects traffic close to the user. The site then needs little more than a router. An EU-sovereign single platform such as Jimber covers those jobs from one place. The trade-offs against Palo Alto’s own cloud service are covered in Prisma Access versus Jimber, and GlobalProtect migration alternatives looks at the remote-access part on its own.

The case for refreshing with Palo Alto

An experienced Palo Alto administrator will make three good arguments.

“Single-pass inspection on site beats a cloud detour.” Palo Alto’s architecture inspects traffic in one pass at high speed, and sending local traffic to the cloud adds latency. That holds for traffic that stays local. For remote users going to SaaS, the detour already exists today: it runs through the office.

“Extended support is still support.” Palo Alto does backport critical fixes to the last version for each model until end of life, and with management kept off the internet, some flaws are much harder to reach. A disciplined team can run these units safely for a while. The question is how long the budget and the patch windows allow it, especially on the PA-220.

“Hardware is a known cost; subscriptions grow.” A physical firewall depreciates over years, while cloud platforms charge per user per month. For a stable, office-based workforce that can favour hardware. For a growing or hybrid workforce, the hardware refresh, the new subscriptions and the next refresh five years later belong in the same comparison.

What to do next

List your PA-220 and PA-800 units with their PAN-OS version, their support end date and the jobs each one actually does. Units on 10.2 with a public GlobalProtect portal deserve the first attention. Before you order PA-400 hardware, check the September 2026 end-of-sale notice against your planned installation date. The cross-vendor end-of-life tracker puts these dates next to other firewall lines you may run.

If remote access and web security are the main reasons these units exist, try Jimber free with one site or one user group. Or book a demo and we will go through your sites together.

Frequently asked questions

When is the Palo Alto PA-220 end of life?

The PA-220 reached end of sale on 31 January 2023 and reaches end of life on 31 January 2028. Its software is capped at PAN-OS 10.2, which left standard support on 27 August 2025 and remains on extended support until the hardware end of life.

What is the end-of-life date for the PA-820 and PA-850?

Both reached end of sale on 31 August 2024 and reach end of life on 31 August 2029. They are capped at PAN-OS 11.1, which leaves standard support on 3 May 2027 and stays on extended support until 31 August 2029.

What is the maximum PAN-OS version for the PA-220?

PAN-OS 10.2. The PA-220 and PA-220R cannot run PAN-OS 11 or 12. Standard support for 10.2 ended on 27 August 2025; the version remains on extended support for these models until their hardware end of life.

Can the PA-820 or PA-850 run PAN-OS 12?

No. The PA-800 series is capped at PAN-OS 11.1. It cannot run 11.2 or any 12.x release.

What replaces the PA-220?

Palo Alto positions the PA-400 series, such as the PA-440, as the branch replacement. Note that Palo Alto announced end of sale for the non-rugged PA-400 models on 22 September 2026, with end of sale on 22 March 2027 and end of life on 21 March 2032.

What replaces the PA-820 and PA-850?

The PA-1400 series, such as the PA-1410. It offers considerably more throughput, 10G and multi-gigabit interfaces, and runs current PAN-OS releases. Subscriptions from the old unit do not transfer and must be purchased again.

Can I keep running a PA-220 after 2028 with third-party maintenance?

Third-party maintenance can replace failed hardware, but it cannot provide PAN-OS updates, security fixes or threat content. An internet-facing firewall without vendor software maintenance is not a defensible setup under NIS2.

Does multi-factor authentication protect GlobalProtect on these units?

Not against every flaw. Vulnerabilities such as CVE-2024-3400 were exploited before authentication, so MFA did not stop them. Patching quickly and keeping management interfaces off the internet matter more.

Can I sell or buy a used PA-220?

Palo Alto’s secondary market policy does not recertify end-of-sale or end-of-life hardware, so a used PA-220 cannot be brought back under support by a new owner. Recycle retired units instead of reselling them.