Panorama Management Compatibility
Table of Contents
Expand all | Collapse all
- CN-Series Firewalls
- MFA Vendor Support
-
- Cloud Identity Engine Cipher Suites
-
- PAN-OS 11.2 GlobalProtect Cipher Suites
- PAN-OS 11.2 IPSec Cipher Suites
- PAN-OS 11.2 IKE and Web Certificate Cipher Suites
- PAN-OS 11.2 Decryption Cipher Suites
- PAN-OS 11.2 Administrative Session Cipher Suites
- PAN-OS 11.2 HA1 SSH Cipher Suites
- PAN-OS 11.2 PAN-OS-to-Panorama Connection Cipher Suites
- PAN-OS 11.2 Cipher Suites Supported in FIPS-CC Mode
-
- PAN-OS 11.1 GlobalProtect Cipher Suites
- PAN-OS 11.1 IPSec Cipher Suites
- PAN-OS 11.1 IKE and Web Certificate Cipher Suites
- PAN-OS 11.1 Decryption Cipher Suites
- PAN-OS 11.1 Administrative Session Cipher Suites
- PAN-OS 11.1 HA1 SSH Cipher Suites
- PAN-OS 11.1 PAN-OS-to-Panorama Connection Cipher Suites
- PAN-OS 11.1 Cipher Suites Supported in FIPS-CC Mode
-
- PAN-OS 11.0 GlobalProtect Cipher Suites
- PAN-OS 11.0 IPSec Cipher Suites
- PAN-OS 11.0 IKE and Web Certificate Cipher Suites
- PAN-OS 11.0 Decryption Cipher Suites
- PAN-OS 11.0 Administrative Session Cipher Suites
- PAN-OS 11.0 HA1 SSH Cipher Suites
- PAN-OS 11.0 PAN-OS-to-Panorama Connection Cipher Suites
- PAN-OS 11.0 Cipher Suites Supported in FIPS-CC Mode
-
- PAN-OS 10.2 GlobalProtect Cipher Suites
- PAN-OS 10.2 IPSec Cipher Suites
- PAN-OS 10.2 IKE and Web Certificate Cipher Suites
- PAN-OS 10.2 Decryption Cipher Suites
- PAN-OS 10.2 Administrative Session Cipher Suites
- PAN-OS 10.2 HA1 SSH Cipher Suites
- PAN-OS 10.2 PAN-OS-to-Panorama Connection Cipher Suites
- PAN-OS 10.2 Cipher Suites Supported in FIPS-CC Mode
-
- PAN-OS 10.1 GlobalProtect Cipher Suites
- PAN-OS 10.1 IPSec Cipher Suites
- PAN-OS 10.1 IKE and Web Certificate Cipher Suites
- PAN-OS 10.1 Decryption Cipher Suites
- PAN-OS 10.1 Administrative Session Cipher Suites
- PAN-OS 10.1 HA1 SSH Cipher Suites
- PAN-OS 10.1 PAN-OS-to-Panorama Connection Cipher Suites
- PAN-OS 10.1 Cipher Suites Supported in FIPS-CC Mode
-
- PAN-OS 9.1 GlobalProtect Cipher Suites
- PAN-OS 9.1 IPSec Cipher Suites
- PAN-OS 9.1 IKE and Web Certificate Cipher Suites
- PAN-OS 9.1 Decryption Cipher Suites
- PAN-OS 9.1 Administrative Session Cipher Suites
- PAN-OS 9.1 HA1 SSH Cipher Suites
- PAN-OS 9.1 PAN-OS-to-Panorama Connection Cipher Suites
- PAN-OS 9.1 Cipher Suites Supported in FIPS-CC Mode
- Prisma Access
- Strata Cloud Manager and Panorama Feature Parity
- User-ID Agent
- Terminal Server (TS) Agent
- Strata Logging Service Software Compatibility
- Cortex XDR
- Endpoint Security Manager (ESM)
- IPv6 Support by Feature
- Mobile Network Infrastructure Feature Support
Panorama Management Compatibility
Review the Panorama™ management server compatibility
based on the installed PAN-OS® version.
Review the table below to understand
which Palo Alto Networks Next-Generation Firewall, Dedicated Log
Collector, and WildFire® appliances a Panorama™ management server
can manage based on the installed PAN-OS version. Palo Alto Networks
recommends management of currently supported Palo Alto Networks Next-Generation Firewalls, Dedicated
Log collector, and WildFire appliance running a supported PAN-OS
version.
Dedicated Log Collectors must be running the same or later PAN-OS version than managed
firewalls from which logs are forwarded. Palo Alto Networks does not support forwarding
logs from managed firewalls to a Dedicated Log Collector if the Dedicated Log Collector
is running an earlier PAN-OS version than that installed on your managed firewalls. This
may lead to log forwarding and ingestion issues.
(PAN-OS 10.1.2 and earlier PAN-OS 10.1 releases) The device registration authentication key length
is increased when you upgrade Panorama to PAN-OS 10.1.3 or later release:
- Panorama running PAN-OS 10.1.2 or earlier PAN-OS 10.1 releases— Supports onboarding firewalls, Dedicated Log Collectors, and WildFire appliances running PAN-OS 10.1.2 or earlier PAN-OS 10.1 release, or running PAN-OS 10.0 or earlier PAN-OS release.
- Panorama running PAN-OS 10.1.3 or later releases— Supports onboarding firewalls, Dedicated Log Collectors, and WildFire appliances running PAN-OS 10.1.3 or later release, or running PAN-OS 10.0 or earlier PAN-OS release.
Despite these onboarding requirements, Panorama supports managing firewalls, Dedicated Log
Collectors, and WildFire appliances running the PAN-OS versions described below.
PAN-OS software versions that are End-of-Life (EoL) are not displayed. See
the Palo Alto Networks End of Life
Announcements for additional information. EoL PAN-OS versions are
supported only for End-of-Sale (EoS) firewall models until
they reach EoL.
Management of End-of-Life (EoL) PAN-OS versions may
result in unexpected issues, particularly if there is a large gap between the PAN-OS
version installed on Panorama and the one installed on the firewall. For example,
you may run into unexpected or unknown issues if you attempt to manage a firewall
running the EoL PAN-OS 7.1 release from a Panorama management server running PAN-OS
10.2 or a later version.
Panorama Version | Managed Device Version |
---|---|
11.2
|
11.2
11.1
11.0
10.2
10.1
9.1
|
11.1
|
11.1
11.0
10.2
10.1
9.1
|
11.0 | 11.0 10.2 10.1 9.1 |
10.2 | 10.2 10.1 9.1 |
10.1 | 10.1 9.1 |
9.1 | 9.1 |