: Known Issues in Panorama Plugin for AWS 5.2.2
Focus
Focus

Known Issues in Panorama Plugin for AWS 5.2.2

Table of Contents

Known Issues in Panorama Plugin for AWS 5.2.2

The following list describes known issues in the Panorama plugin for AWS 5.2.2.

PLUG-15577

Fixed an issue where the Panorama plugin for AWS retrieves IP addresses only from the first interface of AWS EC2 instances associated with a security group.

PLUG-12161

Description of PLUG-12711
The VM Monitoring and Orchestration on AWS plugin 3.0.0 and above is not supported on AWS GovCloud.
AWS Plugin 3.0.0 and above does not orchestrate VM-Series firewall deployments on AWS GovCloud.
Workaround:
To support VM monitoring on AWS Plugin 3.0.0 and above on AWS GovCloud, perform the following steps for a workaround:
  1. Set the AWS region running the op-command.
    Following is an example to set the AWS region using the op-command:
    request plugins aws set-aws-region region <aws-govcloud-region>
  2. Configure the AWS region under monitoring definition using the CLI and commit the changes.
    Run the following command on CLI:
    set plugins aws monitoring-definition <vm-mon-name> aws-regions <aws-govcloud-region>
    On successful execution of the above command, the VPCs will be displayed on the UI and you will be able to select VPCs on the AWS GovCloud.

FWAAS-5817

The Panorama UI does not display any error message when cloud manager or cloud NGFW service push fails. You will only know about push failure when the firewall commit fails.

FWAAS-6961

On the Panorama AWS Plugin for Cloud NGFW service, the first time tenant linked to Panorama will not be able to see any VPCs under the Discovered VPC tab.
Workaround: The first time tenant must click Refresh Vpc button under Discover VPC tab to get a list of VPCs.

FWAAS-7721

In a scaled environment, the AWS plugin user interface crashes when displaying IP address-to-tags payload in the Monitoring Definition dashboard.
Workaround: Use the Panorama CLI to run command: show plugins aws details-dashboard.

FWAAS-7766

The Discovered VPC page on Cloud NGFW UI does not show the failure reason if the Monitoring Status is Failed for a discovered VPC.