Next-Generation Firewall
Panorama Features
Table of Contents
Expand All
|
Collapse All
Next-Generation Firewall Docs
-
-
-
-
-
-
-
- PAN-OS 12.1
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 11.0 (EoL)
- PAN-OS 10.2
- PAN-OS 10.1
- PAN-OS 10.0 (EoL)
- PAN-OS 9.1 (EoL)
- PAN-OS 9.0 (EoL)
- PAN-OS 8.1 (EoL)
-
- PAN-OS 12.1
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 10.2
- PAN-OS 10.1
Panorama Features
What new Panorama™ management server features are in PAN-OS 12.1?
The following section describes new Panorama features introduced in PAN-OS 12.1.
Log Collector Scaling Optimization
|
August 2025
|
PAN-OS® 12.1 introduces support for Log Collector Scaling. This feature allows
you to explicitly select master-eligible nodes to address performance bottlenecks in
large-scale log collection environments. This optimization provides a more
predictable failover behavior and more efficient resource utilization across your
Collector Group.
To achieve the best performance, select a maximum of four Log Collectors per
Collector Group to be master-eligible. Previously, all Log Collectors within a
Collector Group were eligible to become the master node. When the active master
failed, the system dynamically elected a new one. This election process involved
continuous communication among numerous nodes, creating significant overhead,
particularly in larger deployments.
This feature supports all platforms, enabling a significantly higher logging rate.
For example, with a Collector Group using up to 16 M-700 appliances, you can scale
log ingestion rates to over 1 million Logs Per Second (lps). This level of scaling
is currently supported only on M-700 appliances.
You can designate specific Log Collectors as master-eligible nodes based on strategic
criteria such as hardware capacity, network resiliency, or geographic distribution.
You can configure master-eligible nodes through either the Panorama web interface or
the command-line interface.
When you implement this feature, consider selecting nodes with the best hardware
specifications, network connectivity, and geographic placement to ensure optimal
performance and availability. By strategically designating your master-eligible
nodes, you can create a more resilient logging infrastructure that maintains high
performance even under demanding conditions.
Enhanced Shared Optimization
|
August 2025
|
The Enhanced Shared Optimization feature now
significantly improves how Panorama pushes configurations to multi-vsys firewalls,
resolving critical challenges like object duplication, memory exhaustion, and commit
failures.
The feature introduces the Full optimization mode, which lets you move all
firewall objects into the shared location of the firewall. This includes the
previously excluded objects, such as external dynamic lists (EDLs), Custom URL
categories, and various Security Profiles, such as antivirus, antispyware, URL
Filtering, and HIP objects. This eliminates object replication across individual
virtual systems. It drastically reduces configuration size in typical deployments
and prevents commit failures caused by exceeding object limits.
This enhancement streamlines management, increases scalability, and
prevents deployments from hitting object limits.
Optimized Global Find and Policy Management
|
August 2025
|
The Global Find feature is now optimized to enhance search experiences by
significantly improving responsiveness when multiple administrators work
simultaneously on the system.
Enabling the Optimized Search prioritizes and searches for the most
relevant records based on admin-usage patterns. The new usage-based reference search
returns results in batches based, preventing the GUI from freezing during intensive
searches. This substantially reduces search times across large configurations. You
can also choose to exclusively search for UUIDs or Template References by selecting
the Search UUIDs and Include Template References options respectively.
In Policy Management, by default, the Rule Usage and App Usage columns and
the Policy Optimizer are hidden after an upgrade. This prevents automatic data
fetching for these components, which prevent significant slowdowns. The system now
fetches data for these columns only when you explicitly make them visible.
For best performance, you can customize your view to display Rule Usage,
App Usage columns, and Policy Optimizer only when needed.
High Availability Firewall Pair Upgrade Orchestration from Panorama
|
August 2025
|
With the High Availability (HA) Firewall Pair Upgrade
Orchestration feature, you can simplify and automate the process of
upgrading HA firewall pairs. When you use this feature, Panorama orchestrates the
entire upgrade process for you, eliminating most of the manual steps that you need
to execute on each device. The feature intelligently manages the upgrade sequence by
following a careful and automated sequence:
- Upgrades the passive (or active-secondary) peer first.
- Automatically reboots the passive peer.
- After the first passive peer is back online and the HA status is synchronized, the system initiates HA failover and upgrades the other peer.
The system automatically performs pre-checks to validate that your
environment is ready for the upgrade. It verifies that both firewalls are connected
to Panorama, confirms configuration synchronization, and validates that the HA links
are operational. If these checks pass, the upgrade process begins automatically.
After upgrade, the system automatically performs the necessary reboots without your
intervention. In the event of an upgrade failure, you must perform a manual upgrade
on the failed firewall.
This feature supports upgrading up to 200 HA pairs in a single workflow
job. The feature supports both upgrade and downgrade operations, giving you
flexibility in managing your firewall software versions. By automating and
orchestrating what was previously a manual process, this feature reduces operational
overhead and minimizes the potential for human error during firewall upgrades.
For this feature to be available, Panorama must be running 12.1.2 or a
later release, and the HA firewalls must be running PAN-OS 10.2.0 or a later
release.
Plugin Bundling
|
August 2025
|
The new Plugin Bundling feature fundamentally
changes the upgrade process by automating plugin management. Previously, you had to
manually compare and download plugins to ensure they were compatible with the PAN-OS
version. This process was prone to errors that could lead to network outages and
data loss, such as overwritten VPN pre-shared keys.
By bundling compatible plugins directly with the base image, this feature eliminates
the risk of version mismatches and preserves your configurations. When you upgrade,
the system automatically downloads the correct plugin versions, so you no longer
have to manually download them. This ensures a seamless and conflict-free update.
The Plugins interface now provides a single location to manage all bundled plugins.
The interface displays and sorts plugins, allowing you to easily install the ones
you need. If you have the required license, you can manage Cloud Services in a
separate, dedicated section.