Changes to Default Behavior in PAN-OS 12.2
Focus
Focus
Next-Generation Firewall

Changes to Default Behavior in PAN-OS 12.2

Table of Contents

Changes to Default Behavior in PAN-OS 12.2

What default behavior changes impact PAN-OS 12.2?
The following table details the changes in default behavior upon upgrade to PAN-OS® 12.2. You may also want to review the Upgrade/Downgrade Considerations before upgrading to this release.
FeatureChange
APN/DNN Profile Relocation to Network Profiles
Starting with PAN-OS 12.2, the APN/DNN profile configuration has moved from the cellular interface to Network > Profiles. This change supports platforms with multiple cellular interfaces and scales to deployments requiring 32 or more APN/DNN profiles. The UI, CLI, and XML API all adopt the new configuration format. If you upgrade from a previous release, reconfigure your APN/DNN profiles under Network > Profiles and update any automation or scripts that reference the previous configuration path.
BGP Filtering Profile Deletion
Starting with PAN-OS 12.2, the firewall enforces referential integrity for BGP routing profile filtering profiles. If any BGP peer configuration references a filtering profile, you must remove that reference before you can delete the profile. Attempting to delete a referenced filtering profile returns a server error. After removing the reference, commit the configuration, then delete the filtering profile.
Minimum Memory Requirement for VM-Series and AIRS Upgrades
To deploy or upgrade to PAN-OS 12.2.2 or later, ensure your VM-Series or AIRS instance is configured with at least 14GB of memory before initiating the upgrade.
Max Session Capacity Reduction for VM-Series Tiers
Starting with PAN-OS 12.2, the max session capacity for 16GB has been reduced from 1,100,000 to 512,000. Tier mapping has been updated as follows.In addition, memory tier assignments have been updated for higher memory configurations. If your VM-Series firewall uses one of the memory sizes below, note that it will now be assigned to a different tier than in previous releases, which may affect your session capacity.
Review your VM-Series memory configuration before upgrading to ensure the new tier assignment meets your session capacity requirements.
Memory in GBTier in PAN-OS 12.1 and earlierTier in PAN-OS 12.2 and later
20T3-20T2-18
36T3-36T3-32
40T3-40T3-32
44T3-44T3-32
48T3-48T3-32
52T3-52T3-32
Admin-Based Selective Push from Panorama
When you change the device group hierarchy in Panorama — for example, by making a device group a child of another device group — Panorama blocks any subsequent admin-based selective push to the affected device group. An error message indicates that a full push is required because the hierarchy has changed since the last full push. Previously, admin-based selective pushes succeeded even after a hierarchy change.
To resolve this, perform a full push from Panorama after making device group hierarchy changes before attempting an admin-based selective push.
Custom Application Validation on Security Rules
If you configure a custom application on a security rule that already has any set, PAN-OS displays a validation error. Previously, this configuration was accepted without error but caused a commit failure, making the root cause difficult to identify.
Application Ping Configuration Validation
Configuring an application ping with any as the application returns a server error. Previously, this configuration was accepted without an error even though any is not a valid selection for application ping.
IKE Configuration Error Message Improvements
When you configure an IKE gateway with an invalid peer-ID or commit an invalid IKE configuration, PAN-OS displays improved error messages with actionable information to help you identify and resolve the issue.
Multicast Traffic Processing
PAN-OS correctly processes out-of-order multicast traffic received from clients. Previously, out-of-order multicast packets were not received correctly, which caused inconsistencies in multicast session statistics.