CN-Series Deployment—Supported Environments
Table of Contents
10.1
Expand all | Collapse all
-
- CN-Series Deployment Checklist
- CN-Series Prerequisites
- Install a Device Certificate on the CN-Series Firewall
- Create Service Accounts for Cluster Authentication
- Install the Kubernetes Plugin and Set up Panorama for CN-Series
- Get the Images and Files for the CN-Series Deployment
- Editable Parameters in CN-Series Deployment YAML Files
- Enable Horizontal Pod Autoscaling on the CN-Series
- Secure 5G With the CN-Series Firewall
- Enable Inspection of Tagged VLAN Traffic
- Enable IPVLAN
- Uninstall the Kubernetes Plugin on Panorama
- Features Not Supported on the CN-Series
CN-Series Deployment—Supported Environments
Learn about the compatibility and version requirements
for the CN-Series firewall.
You can deploy the CN-Series firewall
in the following environments:
Product | Version |
---|---|
Container
runtime | Docker CRI-O Containerd |
Kubernetes version | 1.17 through 1.27 |
Cloud provider managed Kubernetes |
|
Customer managed Kubernetes | On the public cloud or on-premise data center. Make
sure that the Kubernetes version, CNI Types, and Host VM OS versions
are as listed in this table. VMware TKG+ version 1.1.2
|
Kubernetes Host VM | Operating System:
|
Linux Kernel Version:
| |
Linux Kernel Netfilter: Iptables | |
CNI Plugins | CNI Spec 0.3 and later:
|
OpenShift | CN-Series as a DaemonSet: 4.2, 4.4, 4.5, 4.6, 4.7, 4.8, 4.9, 4.10, 4.11, 4.12, and 4.13 CN-Series as a K8s Service: (PAN-OS 10.1.2 and later) 4.7, 4.8, 4.9, 4.10, 4.11, 4.12, and 4.13 The PAN-OS 10.1.10h1 is the minimum required version to support
4.12 and above. |
Also review the CN-Series Prerequisites, before
you Deploy the CN-Series Firewalls.