Changes to Default Behavior in PAN-OS 12.1
Focus
Focus
Next-Generation Firewall

Changes to Default Behavior in PAN-OS 12.1

Table of Contents

Changes to Default Behavior in PAN-OS 12.1

What default behavior changes impact PAN-OS 12.1?
The following table details the changes in default behavior upon upgrade to PAN-OS® 12.1. You may also want to review the Upgrade/Downgrade Considerations before upgrading to this release.
FeatureChange
IKE protocol version support
We have changed the default IKE protocol version support from IKEv1 to IKEv2.
  • If you have not configured the IKE protocol version in the IKE gateway configuration, then PAN-OS supports the IKEv2 protocol version by default.
  • For VPN clusters, PAN-OS supports IKEv2 only mode by default and the support for IKEv1 only mode and IKEv2 preferred mode configuration are removed.
Maintenance Mode Password Change
After upgrading to 12.1, you must change the default maintenance password using the following CLI commands:
Generate the <passwd-hash>: request password-hash password <password>
Update the maintenance password: set deviceconfig system maintenance-user password-hash <passwd-hash>
The firewall serial number is no longer valid for maintenance use.
OpenConfig
In 12.1.2, the OpenConfig 2.1.4 plugin will be bundled with the PAN-OS release. If you upgrade to 12.1.2, the plugin will only be reinstalled automatically if you had manually installed it in the previous release. For security reasons, if you had autoinstalled in the prior release, the plugin will not be installed.
Minimum Memory Requirements for Software Firewalls (VM-Series and Prisma AIRS)
A minimum of 8GB of memory is required to upgrade to PAN-OS version 12.1.2 from any prior PAN-OS version. If you are upgrading to PAN-OS 12.1.2 with memory configurations of 8GB-14GB, then the session capacity reduces.
Change in Maximum Supported Sessions on Software Firewalls (VM-Series and Prisma AIRS )
Starting with PAN-OS 12.1.2, the maximum number of supported sessions has been reduced.
For Flex Licenses:
  • 8 GB: 64K sessions
  • 9 GB: 128K sessions
  • 10 GB: 128K sessions
  • 12 GB: 256K sessions
  • 14 GB: 512K sessions
For Fixed Licenses:
  • VM-100: 64K
  • VM-300: 128K
Minimum Disk Size for VM Panorama
Starting in PAN-OS 12.1.2, the VM Panorama requires a minimum 224GB disk. Before upgrading to 12.1.2, you must perform a disk migration to 224GB.
New Confirmation Prompt When Loading a Saved Configuration using the CLI and Web Interface
A new prompt for confirmation is displayed when a saved config is loaded.
This new prompt was added to avoid losing uncommitted changes in case of system/process restart. We recommend that you commit pending changes both before and after partial config load operations.
TLS 1.3 Decryption Limited to RFC-Compliant Key Exchange Groups
Starting in PAN-OS 12.1, the firewall enforces RFC 8446 for SSL Forward Proxy decryption. Only the following key exchange groups are supported for TLS 1.3 decryption: X25519, X448, secp256r1, secp384r1, secp521r1.
Sessions that exclusively negotiate any other elliptic-curve group — including P-192 (secp192k1), secp160k1, secp256k1, sect163k1, and related Koblitz and binary curves — don't complete through SSL Forward Proxy. This affects firewalls upgraded from PAN-OS 11.2 or earlier.
Workaround: Set TLSv1.2 as the maximum supported TLS version in the decryption profile and apply it to the decryption policy rules that handle traffic to servers that exclusively negotiate non-compliant groups. Alternatively, work with the server operator to enable RFC 8446-compliant groups.
Show System Resources Output Changed
show system resources process names get truncated at 8 characters compared to 10 characters in earlier releases. The change was due to a kernel upgrade in PAN-OS 12.1.2.
SSH Server Host Key Algorithm Restriction in FIPS-CC Mode
Starting in PAN-OS 12.1.8, firewalls running in FIPS-CC mode exclusively advertise rsa-sha2-512 for RSA host key authentication on the management SSH server. The previously supported ssh-rsa and rsa-sha2-256 algorithms are no longer permitted in FIPS-CC mode. This change is not applicable to normal (non-FIPS-CC) operation mode.
This restriction is required to comply with the collaborative Protection Profile for Network Devices Version 4.0 (NDcPPv4.0e).
SSH clients that do not support rsa-sha2-512 (OpenSSH older than 7.2 or SecureCRT older than 9.0) will fail to connect to a firewall running PAN-OS 12.1.8 or later in FIPS-CC mode using default RSA host keys.
Workaround: Configure the default SSH host key for management SSH to an ECDSA key type and commit. ECDSA-based host key authentication is not restricted by this change.