Limitations in Strata Cloud Manager
Focus
Focus
Strata Cloud Manager

Limitations in Strata Cloud Manager

Table of Contents

Limitations in Strata Cloud Manager

Known limitations in Strata Cloud Manager.
The following table details known limitations in Strata Cloud Manager.
FeatureStrata Cloud Manager ReleaseLimitation
Zero Touch Provisioning
Strata Cloud Manager Release 2026.r3.0
When you onboard devices through Zero Touch Provisioning (ZTP), the onboarding process uses the Strata Cloud Manager tenant-level routing mode setting to determine the routing mode for each device. The device is onboarded in that routing mode regardless of any device-specific routing mode requirements.
We recommend that you use only greenfield devices for ZTP onboarding to avoid unintended routing mode configurations on existing deployments.
Routing Mode Change
Strata Cloud Manager Release 2026.r3.0
When you switch a firewall between Advanced Routing and Legacy routing mode in Strata Cloud Manager, the commit does not complete if the firewall has existing local configuration. The routing mode on the firewall remains unchanged after the push.
Strata Cloud Manager supports routing mode changes only on firewalls with factory-default configuration. Firewalls with existing local configuration are not supported for this operation.
Workaround: Factory reset the firewall to remove local configuration before switching routing modes in Strata Cloud Manager.
Panorama Synchronization
Strata Cloud Manager Release 2026.r3.0
When you push a zone configuration from Strata Cloud Manager to Panorama, the push does not complete if the zone's user-ACL include-list references address objects or address groups defined outside the Shared Device Group. Panorama validation rejects these references because the zone's user-ACL only accepts addresses from the vsys-specific or shared address space.
This is a PAN-OS limitation. Strata Cloud Manager cannot override Panorama's address reference validation.
Workaround: Move the address objects and address groups referenced in zone user-ACL include-lists to the Shared Device Group before pushing the configuration to Panorama.