Panorama Management Compatibility
Focus
Focus
Compatibility Matrix

Panorama Management Compatibility

Table of Contents

Panorama Management Compatibility

Review the Panorama™ management server compatibility based on the installed PAN-OS® version.
Review the table below to understand which Palo Alto Networks Next-Generation Firewall, Dedicated Log Collector, and WildFire® appliances a Panorama™ management server can manage based on the installed PAN-OS version. Palo Alto Networks recommends management of currently supported Palo Alto Networks Next-Generation Firewalls, Dedicated Log collector, and WildFire appliance running a supported PAN-OS version.
By default, Palo Alto Networks supports management and log forwarding only when Panorama and Dedicated Log Collectors run the same or a later PAN-OS version than the firewalls and WildFire appliances they manage. Palo Alto Networks does not support forwarding logs from managed firewalls to a Dedicated Log Collector running an earlier PAN-OS version than that installed on your managed firewalls, as this may lead to log forwarding and ingestion issues.
(PAN-OS 10.2.7 and later releases) Starting with PAN-OS 10.2.7, Panorama and Dedicated Log Collectors can manage or receive logs from firewalls running a later patch version within the same PAN-OS release train. For example, a Panorama appliance on PAN-OS 10.2.7 can manage a firewall on PAN-OS 10.2.8, and a Dedicated Log Collector on PAN-OS 10.2.7 can receive logs from a firewall on PAN-OS 10.2.8. Panorama does not support new features, optimizations, or platforms introduced in later versions of PAN-OS or installed plugins; see the PAN-OS or Plugin Release Notes for details. It is a best practice that Panorama and Dedicated Log Collectors run the same or a later PAN-OS version than the firewalls they manage.
(PAN-OS 10.1.2 and earlier PAN-OS 10.1 releases) The device registration authentication key length is increased when you upgrade Panorama to PAN-OS 10.1.3 or later release:
Despite these onboarding requirements, Panorama supports managing firewalls, Dedicated Log Collectors, and WildFire appliances running the PAN-OS versions described below.
PAN-OS software versions that are End-of-Life (EoL) are not displayed. See the Palo Alto Networks End of Life Announcements for additional information. EoL PAN-OS versions are supported only for End-of-Sale (EoS) firewall models until they reach EoL.
Management of End-of-Life (EoL) PAN-OS versions may result in unexpected issues, particularly if there is a large gap between the PAN-OS version installed on Panorama and the one installed on the firewall. For example, you may run into unexpected or unknown issues if you attempt to manage a firewall running the EoL PAN-OS 7.1 release from a Panorama management server running PAN-OS 10.2 or a later version.
Panorama Version
Managed Device Version
12.1
12.1
11.2
11.1
10.2
10.1
11.2
11.2
11.1
10.2
10.1
11.1
11.1
10.2
10.1
10.2
10.2
10.1
10.1
10.1