See which plugin versions are associated with PAN-OS
10.2.
PAN OS 10.2 is enhanced with upgraded plugins to increase
reliability and robustness.
The following minimum plugin versions are compatible with PAN-OS
10.2.
Plugin Name
Minimum Compatible
Plugin Version with PAN-OS 10.2
AWS Plugin
4.0.0
Azure Plugin
4.0.0
Cloud Services Plugin
3.2.0
Kubernetes Plugin
3.0.0
SW FW Licensing Plugin (VM licensing plugin
and the previous version is supported)
1.0.0
Panorama VM-Series Plugin
3.0.0
SD-WAN Plugin
3.0.0
IPS Signature Converter Plugin
2.0.0
ZTP Plugin
2.0.0
DLP Plugin
3.0.0
OpenConfig Plugin
1.1.0
GCP Plugin
3.0.0
Cisco ACI Plugin
3.0.0
VCenter Plugin
2.0.0
Nutanix Plugin
2.0.0
Cisco TrustSec Plugin
2.0.0
Important considerations for upgrading
your plugins
The plugin versions listed in the above
table are the only plugins that are compatible with PAN-OS 10.2.
If you use any other plugins, you should not upgrade to PAN-OS 10.2
until you upgrade all plugins to the minimum version.
Starting with PAN-OS 10.2, the VM-Series plugin is installed
by default. This option is currently available only in PAN OS 10.2,
which means that Panorama software requires that you download a
compatible version of the VM-Series plugin if you downgrade your
firewall from PAN-OS 10.2.
Each upgraded Panorama plugin supports both existing
firewalls and PAN OS 10.2 firewalls.
The VM-Series plugin is required only for Azure deployments
and not for any other Panorama plugins.
Supported Migration Paths for Plugins
Plugin Name
Upgrade/ Downgrade
Base PAN-OS
Base Plugin Version
Target PAN-OS
Target Plugin Version
AWS
Upgrade
10.1.x
3.0.x
AWS Plugin 2.x.x should be upgraded to
3.0.x in PAN OS 10.1.x before upgrading to PAN OS 10.2.0
10.2.0
4.0.0
Downgrade
10.2.0
4.0.0
10.1.x
3.0.x
Azure Plugin
Upgrade
10.1.x
3.1.x
10.2.0
4.0.0
Downgrade
10.2.0
4.0.0
10.1.x
3.2.X (yet to be released)
Downgrading is
not possible until the Azure Plugin 3.2.x is released.
Kubernetes Plugin
Upgrade
10.1.x
2.0.x
10.2.0
3.0.0
Downgrade
10.2.0
3.0.0
10.1.x
2.0.x
If you have a custom certificate
size greater than 32k, the auto commit (which happens after downgrade) will
fail. To avoid this, you can save the config file, add a dummy value
in the custom certificate which is less than 16K and then downgrade
to 2.0.x(k8s plugin cannot contact the API server). You can upgrade
the plugin to 2.1.x (after release) and use the 32k original certificate.
GCP Plugin
Upgrade
10.1.x
2.0.0
10.2.0
3.0.0
Downgrade
10.2.0
3.0.0
10.1.x
2.0.0
Cisco ACI Plugin
Upgrade
10.1.x
2.0.x
10.2.0
3.0.0
Downgrade
10.2.0
3.0.0
10.1.x
2.0.x
VCenter Plugin
Upgrade
10.1.x
1.0.x
10.2.0
2.0.0
Downgrade
10.2.0
2.0.0
10.1.x
1.0.x
Nutanix Plugin
Upgrade
10.1.x
1.0.0
10.2.0
2.0.0
Downgrade
10.2.0
2.0.0
10.1.x
1.0.0
For more information on upgrade and downgrade, see: