Compatibility Matrix Reference
Compatibility Matrix Reference
Matrix
docs.paloaltonetworks.com
Contact Information
Corporate Headquarters:
Palo Alto Networks
3000 Tannery Way
Santa Clara, CA 95054
www.paloaltonetworks.com/company/contact-support
Copyright
Palo Alto Networks, Inc.
www.paloaltonetworks.com
© 2016-2024 Palo Alto Networks, Inc. Palo Alto Networks is a registered trademark of Palo
Alto Networks. A list of our trademarks can be found at www.paloaltonetworks.com/company/
trademarks.html. All other marks mentioned herein may be trademarks of their respective companies.
Last Revised
December 4, 2024
Palo Alto Networks Compatibility Matrix 2 ©2024 Palo Alto Networks, Inc.
Table of Contents
Supported OS Releases by Model................................................................. 9
Palo Alto Networks Next-Generation Firewalls................................................................ 10
Palo Alto Networks Appliances............................................................................................. 13
WF-500 Appliance Analysis Environment Support............................................... 13
Palo Alto Networks PA-7000 Series Cards........................................................................ 15
Palo Alto Networks PA-5450 Cards.....................................................................................17
Palo Alto Networks PA-7500 Cards.....................................................................................18
HA Port and Processor Support............................................................................................19
Breakout Port Support.............................................................................................................23
VM-Series Firewalls.........................................................................................27
VM-Series Firewall Hypervisor Support.............................................................................. 28
Private Cloud Deployments........................................................................................ 28
Public Cloud Deployments.......................................................................................... 36
VM-Series Firewall for VMware Cloud on AWS....................................................37
PacketMMAP and DPDK Drivers on VM-Series Firewalls............................................. 39
SR-IOV Access Mode................................................................................................... 39
PacketMMAP Driver Versions....................................................................................39
DPDK Driver Versions..................................................................................................42
Partner Interoperability for VM-Series Firewalls...............................................................43
Palo Alto Networks Certified Integrations.............................................................. 43
Partner-Qualified Integrations.................................................................................... 49
VM-Series Plugin....................................................................................................................... 54
VM-Series Plugin 5.1.x................................................................................................. 54
VM-Series Plugin 5.0.x................................................................................................. 54
VM-Series Plugin 4.0.x................................................................................................. 55
VM-Series Plugin 3.0.x................................................................................................. 55
VM-Series Plugin 2.1.x................................................................................................. 56
VM-Series Plugin 2.0.x................................................................................................. 57
VM-Series Plugin 1.0.x................................................................................................. 59
AWS Regions..............................................................................................................................61
Azure Regions............................................................................................................................ 63
Google Cloud Regions..............................................................................................................64
Alibaba Cloud Regions............................................................................................................. 65
VM-Series Firewall Amazon Machine Images (AMI).........................................................66
PAN-OS Images for AWS GovCloud........................................................................ 66
CN-Series Firewalls......................................................................................... 69
CN-Series Supported Environments.....................................................................................70
Palo Alto Networks Compatibility Matrix 3 ©2024 Palo Alto Networks, Inc.
Table of Contents
Panorama............................................................................................................77
Panorama Plugins...................................................................................................................... 78
Cisco ACI..........................................................................................................................78
Cisco TrustSec................................................................................................................ 82
Panorama CloudConnector Plugin (Formerly, AIOps Plugin for
Panorama)........................................................................................................................ 84
Cloud Services................................................................................................................ 85
Enterprise Data Loss Prevention (DLP)....................................................................85
Panorama Interconnect................................................................................................ 92
IPS Signature Converter...............................................................................................93
Kubernetes.......................................................................................................................95
Clustering Plugin............................................................................................................ 97
Network Discovery........................................................................................................97
Nutanix............................................................................................................................. 99
OpenConfig..................................................................................................................... 99
Panorama Software Firewall License Plugin.........................................................100
Public Cloud—AWS, Azure, and GCP.....................................................................101
SD-WAN........................................................................................................................ 107
VMware NSX................................................................................................................115
VMware vCenter......................................................................................................... 117
Zero Touch Provisioning (ZTP)................................................................................ 118
Compatible Plugin Versions for PAN-OS 10.2................................................................ 120
Panorama Management Compatibility.............................................................................. 125
Panorama Hypervisor Support............................................................................................ 127
Device Certificate for a Palo Alto Networks Cloud Service.........................................131
Palo Alto Networks Compatibility Matrix 4 ©2024 Palo Alto Networks, Inc.
Table of Contents
Palo Alto Networks Compatibility Matrix 5 ©2024 Palo Alto Networks, Inc.
Table of Contents
GlobalProtect..................................................................................................219
Where Can I Install the GlobalProtect App?....................................................................220
Apple macOS................................................................................................................ 220
Microsoft Windows.................................................................................................... 222
Linux................................................................................................................................223
Apple iOS and iPadOS............................................................................................... 228
Google Android............................................................................................................229
Google Chrome............................................................................................................231
Internet of Things (IoT)..............................................................................................231
Hypervisors................................................................................................................... 232
Third-Party VPN Client Support......................................................................................... 233
What Third-Party VPN Clients are Supported?................................................... 233
What GlobalProtect Features Do Third-Party Clients Support?......................233
How Many Third-Party Clients Does Each Firewall Model Support?............. 234
What Features Does GlobalProtect Support?................................................................. 237
TEST: What Features Does GlobalProtect Support?..................................................... 252
Authentication Features............................................................................................ 252
Single Sign-On..............................................................................................................254
What Features Does GlobalProtect Support for IoT?................................................... 255
What GlobalProtect Features Do Third-Party Mobile Device Management Systems
Support?.................................................................................................................................... 258
Prisma Access.................................................................................................259
What Features Does Prisma Access Support?................................................................ 260
Prisma Access Feature Support.......................................................................................... 261
Management.............................................................................................................................262
Remote Networks...................................................................................................................264
Service Connections...............................................................................................................265
Mobile Users—GlobalProtect............................................................................................... 266
Mobile Users—Explicit Proxy............................................................................................... 269
Security Services..................................................................................................................... 270
Network Services....................................................................................................................273
Identity Services......................................................................................................................275
Policy Objects.......................................................................................................................... 278
Logs.............................................................................................................................................281
Reports.......................................................................................................................................282
Integration with Other Palo Alto Networks Products................................................... 283
Palo Alto Networks Compatibility Matrix 6 ©2024 Palo Alto Networks, Inc.
Table of Contents
Palo Alto Networks Compatibility Matrix 7 ©2024 Palo Alto Networks, Inc.
Table of Contents
Palo Alto Networks Compatibility Matrix 8 ©2024 Palo Alto Networks, Inc.
Supported OS Releases by Model
Use the tables throughout this Palo Alto Networks Compatibility Matrix to determine support for
Palo Alto Networks Next-Generation Firewalls, appliances, and agents. Additionally, refer to the
product comparison tool for detailed information about Palo Alto Networks firewalls by model,
including specifications for throughput, maximum number of sessions, rules, objects, tunnels, and
zones.
For supported operating systems on firewalls and appliances and for high-availability (HA) port
and processor support on firewalls, review the following topics:
• Palo Alto Networks Next-Generation Firewalls
• Palo Alto Networks Appliances
• WF-500 Appliance Analysis Environment Support
• Palo Alto Networks PA-7000 Series Firewall Cards
• HA Port and Processor Support
• Breakout Port Support
9
Supported OS Releases by Model
Hardware Firewalls
PA-220 Firewall √ √ √ — — —
PA-220R Firewall √ √ √ — — —
PA-410 Firewall — √ √ √ √ √
10.1.2 &
later
PA-410R Firewall — — — — √ √
11.1.3 &
later
PA-410R-5G — — — — √ √
Firewall
11.1.4 &
later
PA-415-5G — — — — √ √
Firewall
PA-415 and — — — √ √ √
PA-445 Firewalls
PA-440, PA-450, — √ √ √ √ √
and PA-460
Firewalls
PA-450R Firewall — — — — √ √
PA-450R-5G — — — — √ √
PA-455 Firewall — — — — √ √
PA-455-5G — — — — — √
Palo Alto Networks Compatibility Matrix 10 ©2024 Palo Alto Networks, Inc.
Supported OS Releases by Model
PA-800 Series √ √ √ √ √ —
Firewalls
PA-1400 Series — — — √ √ √
Firewalls
PA-3200 Series √ √ √ √ √ —
Firewalls
PA-3400 Series — — √ √ √ √
Firewalls
PA-5200 Series √ √ √ √ √ √
Firewalls
PA-5410, — — √ √ √ √
PA-5420, and
PA-5430 Firewalls
PA-5440 Firewall — — — √ √ √
PA-5445 Firewall — — — — √ √
PA-5450 Firewall — √ √ √ √ √
PA-7000 Series √ √ √ √ √ √
Firewalls
PA-7500 Firewall — — — — √ √
VM-Series Firewalls
Flexible vCPU — √ √ √ √ √
Firewalls
(Up to 32 cores)
Flexible vCPU — — √ √ √ √
Firewalls
(Up to 64 cores)
VM-50 Firewall √ √ √ √ √ √
Palo Alto Networks Compatibility Matrix 11 ©2024 Palo Alto Networks, Inc.
Supported OS Releases by Model
VM-100 Firewall √ √ √ √ √ √
VM-200 Firewall √ √ √ √ √ √
VM-300 Firewall √ √ √ √ √ √
VM-500 Firewall √ √ √ √ √ √
VM-700 Firewall √ √ √ √ √ √
VM-1000-HV √ √ √ √ √ √
Firewall
CN-Series Firewall
CN-Series Small — √ √ √ √ √
CN-MGMT Mem:
2GB
CN-NGFW Mem:
2 to 2.5GB
CN-Series — √ √ √ √ √
Medium
CN-MGMT Mem:
2GB
CN-NGFW Mem:
6GB
CN-Series Large — √ √ √ √ √
CN-MGMT Mem:
4GB
CN-NGFW Mem:
48GB
* You should also review the hardware EoL information for more specific information about
firewalls and appliances that have reached end-of-sale (EoS) status.
Palo Alto Networks Compatibility Matrix 12 ©2024 Palo Alto Networks, Inc.
Supported OS Releases by Model
Panorama Virtual √ √ √ √ √ √
Appliance
M-200 Appliance √ √ √ √ √ √
M-300 Appliance — — √ √ √ √
M-500 Appliance √ √ — — — —
(EoS**)
M-600 Appliance √ √ √ √ √ √
M-700 Appliance — — √ √ √ √
WF-500 √ √ √ √ √ √
Appliance(*)
10.2.2 &
later
WF-500-B — — √ √ √ √
Appliance(*)
10.2.2 &
later
* WF-500 appliances have optional guest VM images that provide support for additional analysis
environments. For information about which VMs are available for a specific PAN-OS® (WildFire®)
release, refer to WF-500 Appliance Analysis Environment Support.
** For more specific information about firewalls and appliances that have reached end-of-sale
(EoS) status, review our hardware EoL web page.
Make sure to download and install the correct WildFire VM image for your WF-500
appliances. Installing a WildFire VM image that the PAN-OS (WildFire) release running on
your appliance does not support will produce error messages, fail to process samples, and
won't detect malware as expected.
Palo Alto Networks Compatibility Matrix 13 ©2024 Palo Alto Networks, Inc.
Supported OS Releases by Model
* You cannot select this WF-500 appliance analysis environment through the WF-500
appliance CLI.
Palo Alto Networks Compatibility Matrix 14 ©2024 Palo Alto Networks, Inc.
Supported OS Releases by Model
PAN- √ √ — — — —
PA-7000-20GXM-NPC
PAN- √ √ — — — —
PA-7000-20GQXM-
NPC
PAN-PA-7000-100G- √ √ √ √ √ √
NPC-A
PAN-PA-7000-DPC-A — √ √ √ √ √
System Cards
PAN-PA-7050-SMC √ √* — — — —
(*until
February
28,
2026)
PAN-PA-7050-SMC √ √* — — — —
(v2)
(*until
February
28,
2026)
PAN-PA-7050-SMC-B √ √ √ √ √ √
PAN-PA-7080-SMC √ √* — — — —
(*until
February
28,
2026)
Palo Alto Networks Compatibility Matrix 15 ©2024 Palo Alto Networks, Inc.
Supported OS Releases by Model
PAN-PA-7080-SMC √ √* — — — —
(v2)
(*until
February
28,
2026)
PAN-PA-7080-SMC-B √ √ √ √ √ √
PAN-PA-7000-LPC √ √* — — — —
(*until
February
28,
2026)
PAN-PA-7000-LFC-A √ √ √ √ √ √
Palo Alto Networks Compatibility Matrix 16 ©2024 Palo Alto Networks, Inc.
Supported OS Releases by Model
PAN-PA-5400-NC-A √ √ √ √ √
PAN-PA-5400-DPC-A √ √ √ √ √
System Cards
PAN-PA-5400-BC-A √ √ √ √ √
PAN-PA-5400-MPC-A √ √ √ √ √
Palo Alto Networks Compatibility Matrix 17 ©2024 Palo Alto Networks, Inc.
Supported OS Releases by Model
PA-7500 Firewall Cards PAN-OS 10.1 PAN-OS 10.2 PAN-OS 11.0 PAN-OS 11.1
PAN-PA-7500-NPC-A — — — √
PAN-PA-7500-DPC-A — — — √
System Cards
PAN-PA-7500-MPC-A — — — √
PAN-PA-7500-SFC-A — — — √
Palo Alto Networks Compatibility Matrix 18 ©2024 Palo Alto Networks, Inc.
Supported OS Releases by Model
Palo Alto Networks Separate Network Offload First HA1 HA2 HSCI
Firewall Model Mgmt Processor Processor Packet Port Port Port
Plane Processor
Processor
Firewalls
PA-220 (EoS)* — — — — — — —
PA-220R (EoS)* — — — — — — —
PA-410 — — — — — — —
PA-415 — — — — — — —
PA-415-5G — — — — — — —
PA-440 — — — — — — —
PA-445 — — — — — — —
PA-450 — — — — — — —
PA-450R — — — — — — —
PA-455 — — — — — — —
PA-455-5G — — — — — — —
PA-460 — — — — — — —
PA-820* — — — — √ √ —
PA-850* — — — — √ √ —
PA-1410 — — — — √ — √
(x2)
Palo Alto Networks Compatibility Matrix 19 ©2024 Palo Alto Networks, Inc.
Supported OS Releases by Model
Palo Alto Networks Separate Network Offload First HA1 HA2 HSCI
Firewall Model Mgmt Processor Processor Packet Port Port Port
Plane Processor
Processor
PA-1420 — — — — √ — √
(x2)
PA-3220 (EoS)* √ √ — — √ — √
(x2)
PA-3250 (EoS)* √ √ √ — √ — √
(CE) (x2)
PA-3260 (EoS)* √ √ √ — √ — √
(CE) (x2)
PA-3410 √ √ — — √ — √
(x2)
PA-3420 √ √ — — √ — √
(x2)
PA-3430 √ √ — — √ — √
(x2)
PA-3440 √ √ — — √ — √
(x2)
PA-5220 (EoS)* √ √ √ √ √ — √
(CE or (x2)
CA)
PA-5250 (EoS)* √ √ √ √ √ — √
(CE or (x2)
CA)
PA-5260 (EoS)* √ √ √ √ √ — √
(CE or (x2)
CA)
PA-5280 (EoS)* √ √ √ √ √ — √
Palo Alto Networks Compatibility Matrix 20 ©2024 Palo Alto Networks, Inc.
Supported OS Releases by Model
Palo Alto Networks Separate Network Offload First HA1 HA2 HSCI
Firewall Model Mgmt Processor Processor Packet Port Port Port
Plane Processor
Processor
(CE or (x2)
CA)
PA-5410 — — — — √ — √
(x2)
PA-5420 — — — — √ — √
(x2)
PA-5430 — — — — √ — √
(x2)
PA-5440 — — — — √ — √
(x2)
PA-5445 — — — — √ — √
(x2)
PA-5450 √ √ √ √ √ — √
(CE or (x2) (x2)
CA)
PA-7050 √ √ √ √ √ — √
(CE or (x2) (x2)
CA)
PA-7080 √ √ √ √ √ — √
(CE or (x2) (x2)
CA)
PA-7500 √ √ √ √ — — √
(CE or (x2)
CA)
PA-7050-SMC √ — — √ √ — √
(EoS)* (x2) (x2)
Palo Alto Networks Compatibility Matrix 21 ©2024 Palo Alto Networks, Inc.
Supported OS Releases by Model
Palo Alto Networks Separate Network Offload First HA1 HA2 HSCI
Firewall Model Mgmt Processor Processor Packet Port Port Port
Plane Processor
Processor
PA-7080-SMC √ — — √ √ — √
(EoS)* (x2) (x2)
PA-7050-SMC-B √ — — √ √ — √
(x2) (x2)
PA-7080-SMC-B √ — — √ √ — √
(x2) (x2)
PA-7000-20GXM- — √ √ — — — —
NPC
(CE x2)
(EoS)*
PA-7000-20GQXM- — √ √ — — — —
NPC
(CE x2)
(EoS)*
PA-7000-100G- — √ √ — — — —
NPC-A
(CE or
CA)
PA-7000-DPC-A — — √ — — — —
(CA x2)
* Some of the firewalls and firewall cards in this table have reached end-of-sale (EoS), are not
supported in newer versions of PAN-OS software, or both. Be sure to review the specific
information for your firewalls, firewall cards, and appliances on the hardware EoL web page.
Palo Alto Networks Compatibility Matrix 22 ©2024 Palo Alto Networks, Inc.
Supported OS Releases by Model
PA-220 — — —
PA-220R — — —
PA-410 — — —
PA-410R — — —
PA-410R-5G — — —
PA-415 — — —
PA-415-5G — — —
PA-440 — — —
PA-445 — — —
PA-450 — — —
PA-450R — — —
PA-450R-5G — — —
PA-455 — — —
PA-455-5G — — —
PA-460 — — —
PA-820 — — —
PA-850 — — —
PA-1410 — — —
Palo Alto Networks Compatibility Matrix 23 ©2024 Palo Alto Networks, Inc.
Supported OS Releases by Model
PA-1420 — — —
PA-3220 — — —
PA-3250 — — —
PA-3260 — — —
PA-3410 — — —
PA-3420 — — —
PA-5220 — — —
PA-5250 — — —
PA-5260 — — —
PA-5280 — — —
Palo Alto Networks Compatibility Matrix 24 ©2024 Palo Alto Networks, Inc.
Supported OS Releases by Model
Palo Alto Networks Compatibility Matrix 25 ©2024 Palo Alto Networks, Inc.
Supported OS Releases by Model
Palo Alto Networks Compatibility Matrix 26 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
The hypervisors and the public cloud regions in which you can deploy the VM-Series firewalls:
• VM-Series Firewall Hypervisor Support
• PacketMMAP and DPDK Drivers on VM-Series Firewalls
• Partner Interoperability for VM-Series Firewalls
• VM-Series Plugin
• AWS and AWS Gov Cloud Regions
• Azure Regions
• Google Cloud Regions
• Alibaba Cloud Regions
• AWS CFT Amazon Machine Images (AMI) List
For the best instance types for optimal VM-Series capacity and performance, review the
VM-Series Capacity & Performance document.
27
VM-Series Firewalls
Access mode with SR-IOV on VMware ESXi is supported on PAN-OS 9.1.5 and later PAN-
OS 9.1 versions and all later PAN-OS versions but only with VM-Series plugin 2.0.5 and
later plugin versions. However, you must enable VLAN access mode for ESXi where
needed.
Palo Alto Networks Compatibility Matrix 28 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
Palo Alto Networks Compatibility Matrix 29 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
• VMware has announced EoS for NSX-V and Palo Alto Networks will continue to support the
VM-Series on NSX-V running PAN-OS 9.1 when managed by Panorama management servers
running PAN-OS 10.1 or PAN-OS 10.2 software.
• Palo Alto Networks does not support VMware NSX-V on Panorama management servers
running PAN-OS 11.0 or later versions.
• There aren't any VM-Series for VMware NSX-V base images for PAN-OS 10.1 or later PAN-
OS versions.
• You cannot upgrade the VM-Series firewall for NSX-V to PAN-OS 10.1 or later PAN-OS
versions.
• The Panorama management server running PAN-OS 10.1 or PAN-OS 10.2 supports PAN-
OS 9.1 base images until June 30, 2024.
See the Palo Alto Networks End-of-Life Summary for more information about the PAN-OS EoL
schedule.
VMware NSX 4.0.x Service Deployments for partner Service Virtual Machines (SVM)
sometimes experience a known traffic redirect issue. Contact VMware NSX Technical
Support for details.
Palo Alto Networks Compatibility Matrix 30 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
Palo Alto Networks Compatibility Matrix 31 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
PAN-OS Version VM-Series for KVM I/O Enhancement Support PAN-OS for VM-
Support (Minimum) Version Support Series KVM Base
(Minimum) Images
Palo Alto Networks Compatibility Matrix 32 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
PAN-OS Version VM-Series for KVM I/O Enhancement Support PAN-OS for VM-
Support (Minimum) Version Support Series KVM Base
(Minimum) Images
The VM-Series firewall for Nutanix uses the VM-Series firewall for KVM base image
(qcow2).
PAN-OS Version VM-Series for I/O Enhancement Support VM-Series for KVM
Support (Minimum) Nutanix Version Base Image
Support (Minimum)
Palo Alto Networks Compatibility Matrix 33 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
PAN-OS Version VM-Series for I/O Enhancement Support VM-Series for KVM
Support (Minimum) Nutanix Version Base Image
Support (Minimum)
deployments with
Service Chaining.
Palo Alto Networks Compatibility Matrix 34 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
Palo Alto Networks Compatibility Matrix 35 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
VM-Series on AWS PAN-OS 9.1.x (9.1.0) In PAN-OS 11.1.x (11.1.0) and later,
ARM support is available on AWS
List of supported AWS PAN-OS 10.1.x (10.1.0)
Graviton 3 and AWS Graviton 2
Regions.
PAN-OS 10.2.x (10.2.0) instances.
Support for AWS Outposts
PAN-OS 11.0.x (11.0.0)
on PAN-OS 9.1 and later.
PAN-OS 11.1.x (11.1.0)
VM-Series on Oracle Cloud PAN-OS 9.1.x (9.1.0) • DPDK is supported and enabled
Infrastructure by default.
PAN-OS 10.1.x (10.1.0)
Palo Alto Networks Compatibility Matrix 36 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
Further I/O Enhancement support is detailed in PacketMMAP and DPDK Drivers on VM-Series
Firewalls.
To view the hypervisor support for Panorama versions, see Panorama Hypervisor Support. To
view the Panorama plugin requirements for public clouds, see Public Cloud-AWS, Azure, GCP.
Further I/O Enhancement support is detailed in the list of PacketMMAP and DPDK Drivers on
VM-Series Firewalls.
Palo Alto Networks Compatibility Matrix 37 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
VMware Cloud on AWS does not support the VM-Series firewall on VMware NSX-V or
NSX-T.
Palo Alto Networks Compatibility Matrix 38 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
iavf 4.0.2
Palo Alto Networks Compatibility Matrix 39 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
igb 5.6.0
igbvf 2.4.0
mlnx-en 4.9
iavf 4.0.2
igb 5.6.0
igbvf 2.4.0
mlnx-en 4.9
i40e 2.14.13
iavf 4.0.2
igb 5.6.0
igbvf 2.4.0
mlnx-en 4.9
Palo Alto Networks Compatibility Matrix 40 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
i40e 2.13.10
igb 5.4.0
igbvf 2.4.0
mlnx-en 4.9
i40e 2.13.10
igb 5.4.0
igbvf 2.4.0
mlnx-en 4.9
i40e 2.3.2
igb 5.4.0
igbvf 2.4.0
Palo Alto Networks Compatibility Matrix 41 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
KVM virtio ixgbe, ixgbevf, i40e, i40evf, and mlnx-en (PAN-OS 10.1 and later)
ARM KVM virtio I40e and mlx5 (PAN_OS 11.1 and later)
See VM-Series for KVM and VM-Series for VMWare vSphere Hypervisor (ESXi) for
PAN-OS versions that support DPDK, DPDK with SR-IOV, or DPDK with Virtio.
11.2 22.11.1
11.1 22.11.1
11.0 20.11.1
10.2 20.11.1
10.1 19.11.3
9.1 18.11
Palo Alto Networks Compatibility Matrix 42 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
Palo Alto Networks Compatibility Matrix 43 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
The partner software version and the PAN-OS® version columns display the range of
versions and the minimum version in parentheses. For example, if the PAN-OS Version
column displays PAN-OS 10.1.x (10.1.4), then integration support begins with PAN-OS
10.1 but not until PAN-OS 10.1.4. and later PAN-OS versions.
• Ciena
• Cisco Cloud Services Platform
• Cisco Enterprise Computer System (ENCS)
• Citrix SD-WAN
• Juniper NFX Network Services Platform
• NSX SD-WAN by VeloCloud
• Nuage Networks
• Versa Networks
• Vyatta
Ciena
The following table shows the Ciena products with which VM-Series firewalls interoperate.
Hardware Hypervisor
SAOS SAOS PAN-OS Deployment Documentation
Supported Tested Version Modes
Software Software Supported
(Minimum)
Version Version
(Minimum) (Minimum)
Palo Alto Networks Compatibility Matrix 44 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
Hardware CSP
Hypervisor CSP Tested PAN-OS Deployment Documentation
Supported Software Version Modes
Software Version Supported
Version (Minimum)
(Minimum)
(Minimum)
CSP 5200 KVM 2.6.x 2.6.x 10.2.x Layer 2, Layer3, Set Up the
Series (2.6.1) (2.6.1) (10.2.0) Virtual wire VM-Series
deployments Firewall on
on all VM- Cisco CSP
Series models (PAN-OS
except VM-50 10.2)
VM-Series
CSP 5400 4.6.x (4.6) 4.6.x 10.1.x Set Up the
Firewalls
Series (4.6.1- (10.1.0) VM-Series
in an HA
FC1) Firewall on
configuration
Cisco CSP
SR-IOV, Packet (PAN-OS
MMAP, and 10.1)
DPDK mode
CSP 5400 2.x.x 2.4.x 9.1.x Set Up the
Series (2.4.0) (2.4.0) (9.1.0) VM-Series
Firewall on
CSP 2100
Cisco CSP
Series
(PAN-OS 9.1)
Palo Alto Networks Compatibility Matrix 45 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
Hardware NFVIS
Hypervisor Tested PAN-OS Deployment Documentation
Supported Version Modes
NFVIS
Software Supported
Software (Minimum)
Version
Version
(Minimum)
(Minimum)
For PAN-OS 11.1.x, you must use the NFVIS CLI to upload the PAN-OS image. The PAN-
OS file size exceeds the file size limit of the ENCS UI.
Citrix SD-WAN
The following table shows the Citrix SD-WAN products with which VM-Series firewalls
interoperate.
Supported
Hardware Hypervisor Tested PAN-OS Deployment Documentation
Software Version Modes
Software
Version Supported
Version (Minimum)
(Minimum)
(Minimum)
Palo Alto Networks Compatibility Matrix 46 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
Supported
Hardware Hypervisor Tested PAN-OS Deployment Documentation
Software Version Modes
Software
Version Supported
Version (Minimum)
(Minimum)
(Minimum)
cmd-dpdk-
pkt-io=off
in the init-
cfg.txt
file used for
bootstrapping
or use the
CLI command
set system
setting
dpdk-pkt-io
off
Hardware Hypervisor
Junos Software PAN-OS Deployment Modes Documentation
Version Version Supported
(Minimum) (Minimum)
NFX 250 KVM 15.1X53-D470.x 9.1.x (9.1.0) Layer 2, Layer 3, Juniper NFX
Virtual Wire documentation
(15.1X53-
D470.5) DPDK mode
Palo Alto Networks Compatibility Matrix 47 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
Hardware VCE
Hypervisor Tested VCE PAN-OS Deployment Documentation
Supported Software Version Modes
Software Version Supported
Version (Minimum)
(Minimum)
(Minimum)
Nuage Networks
The following table shows the Nuage Networks products with which VM-Series firewalls
interoperate.
Hardware VSP
Hypervisor Tested VSP PAN-OS Deployment Documentation
Supported Software Version Modes
Software Version Supported
Version (Minimum)
(Minimum) (Minimum)
Palo Alto Networks Compatibility Matrix 48 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
Versa Networks
The following table shows the Versa Networks products with which VM-Series firewalls
interoperate.
Hardware Hypervisor
Supported Tested PAN-OS Deployment Documentation
Versa Versa Version Modes
FlexVNF FlexVNF Supported
(Minimum)
Software Software
Version Version
(Minimum) (Minimum)
Vyatta
The following table shows the Vyatta products with which VM-Series firewalls interoperate.
Platform Hypervisor
Vyatta PAN-OS Deployment Modes Documentation
Software Version Supported
Version
(Minimum)
Partner-Qualified Integrations
Review these lists of partner-qualified products with which VM-Series firewalls interoperate. The
tables include details about hardware platforms and software versions on which you can deploy
VM-Series firewalls.
The partner software version and PAN-OS® version columns display the range of versions
and the minimum version in parentheses. For example, if the PAN-OS Version column
displays PAN-OS 10.1.x (10.1.4), then integration support begins with PAN-OS 10.1 but
not until PAN-OS 10.1.4. and later PAN-OS versions.
• ADVA
• Aryaka
• Corsa
Palo Alto Networks Compatibility Matrix 49 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
• iS5Com
• Megaport
• SEL
• Siemens
• Stratus
• ZPE
• Zededa
ADVA
The following table shows the ADVA products with which VM-Series firewalls interoperate.
Aryaka
The following table shows the Aryaka products with which VM-Series firewalls interoperate.
Corsa
The following table shows the Corsa products with which VM-Series firewalls interoperate.
Palo Alto Networks Compatibility Matrix 50 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
iS5Com
The following table shows the iS5Com products with which VM-Series firewalls interoperate.
Megaport
The following table shows the Megaport products with which VM-Series firewalls interoperate.
SEL
The following table shows the SEL products with which VM-Series firewalls interoperate.
Palo Alto Networks Compatibility Matrix 51 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
Siemens
The following table shows the Siemens products with which VM-Series firewalls interoperate.
Stratus
The following table shows the Stratus products with which VM-Series firewalls interoperate.
Palo Alto Networks Compatibility Matrix 52 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
ZPE
The following table shows the ZPE products with which VM-Series firewalls interoperate.
Zededa
The following table shows the Zededa products with which VM-Series firewalls interoperate.
Palo Alto Networks Compatibility Matrix 53 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
VM-Series Plugin
The VM-Series plugin is built in to the VM-Series firewalls. You can configure this plugin directly
on the VM-Series firewall or install it on a Panorama™ M-Series or virtual appliance.
To manage the VM-Series plugin configuration on your managed firewalls from Panorama, you
must manually install the VM-Series plugin on Panorama. Refer to Panorama Plugins. You can also
compare VM-Series Plugin and Panorama Plugins.
The following table briefly describes the features introduced in each version of the VM-Series
plugin. For additional information about each version, refer to the VM-Series plugin release notes.
5.1.4 11.1.5 Includes new fixes to improve your experience with the VM-
Series firewall.
5.1.3 — Includes new fixes to improve your experience with the VM-
Series firewall.
5.1.1 11.2.0 Includes new fixes to improve your experience with the VM-
Series firewall.
Palo Alto Networks Compatibility Matrix 54 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
Palo Alto Networks Compatibility Matrix 55 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
3.0.3 10.2.3 Addresses known issues and introduces two new features—
Configuring OCI CloudWatch monitoring and Publishing custom
metrics in the OCI console.
3.0.1 10.2.1 Introduces one new feature—PAYG License Support for VM-
Series on AWS, OCI, GCP and Azure.
Palo Alto Networks Compatibility Matrix 56 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
Palo Alto Networks Compatibility Matrix 57 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
2.0.7 9.1.10 Introduces management interface swap support for the VM-
Series on VMware ESXi and KVM and addresses known issues.
10.0.6*
2.0.5 — Addresses known issues and adds 1500 MTU for Google Cloud
Platform and SR-IOV access mode on ESXi with PAN-OS 9.1.5
and later or 10.0.1 and later.
2.0.4 10.0.4* Addresses known issues and adds licensing support for future
PAN-OS releases.
2.0.3 10.0.3* • Introduces custom image creation for the VM-Series firewall
on Microsoft Azure.
• Introduces Pay-As-You-Go license support for the VM-
Series on Oracle Cloud Infrastructure.
• Introduces enhancements for the VM-Series firewall on
Alibaba Cloud.
• Addresses known issues.
Palo Alto Networks Compatibility Matrix 58 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
1.0.12 9.1.4 • Additional PAN-OS custom metrics for AWS, Azure, and
GCP public clouds (panSessionConnectionsPerSecond,
9.1.5
panSessionThroughputKbps, and
panSessionThroughputPps).
• New system startup updates, system health periodic
updates, and live health failure updates for AWS
CloudWatch.
• Addresses known issues.
Palo Alto Networks Compatibility Matrix 59 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
1.0.7 — Addresses known issues, including bug fixes and support for
high availability (HA) on Azure Government for the VM-Series
on Azure.
Earliest version on which you can enable (HA) on Azure
Government for the VM-Series on Azure.
Palo Alto Networks Compatibility Matrix 60 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
AWS Regions
The AWS regions—public, GovCloud, and AWS Outposts—in which you can deploy the VM-Series
firewall from the AWS Marketplace.
EU (Frankfurt) eu-central-1
Palo Alto Networks Compatibility Matrix 61 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
EU (Zurich) eu-central-2
EU (Ireland) eu-west-1
EU (London) eu-west-2
EU (Paris) eu-west-3
EU (Stockholm) eu-north-1
EU (Milan) eu-south-1
EU (Spain) eu-south-2
us-gov-east
Palo Alto Networks Compatibility Matrix 62 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
Azure Regions
The VM-Series firewall is available on the Azure public and the Azure Government Marketplace.
Azure Israel
Azure DoD
Palo Alto Networks Compatibility Matrix 63 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
Palo Alto Networks Compatibility Matrix 64 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
Palo Alto Networks Compatibility Matrix 65 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
Palo Alto Networks Compatibility Matrix 66 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
Palo Alto Networks Compatibility Matrix 67 ©2024 Palo Alto Networks, Inc.
VM-Series Firewalls
Palo Alto Networks Compatibility Matrix 68 ©2024 Palo Alto Networks, Inc.
CN-Series Firewalls
The CN-Series firewall is supported only in certain environments and is compatible with or
requires a specific set of files to do so.
• CN-Series Supported Environments
• CN-Series Firewall Image and File Compatibility
69
CN-Series Firewalls
Product PAN-OS 10.1 PAN-OS 10.2 PAN-OS 11.0 PAN-OS 11.1 PAN-OS 11.2
Kubernetes
1.17 through 1.17 through 1.17 through 1.17 through 1.17 through
version 1.27 1.31 1.31 1.31 1.31
Palo Alto Networks Compatibility Matrix 70 ©2024 Palo Alto Networks, Inc.
CN-Series Firewalls
Product PAN-OS 10.1 PAN-OS 10.2 PAN-OS 11.0 PAN-OS 11.1 PAN-OS 11.2
through as a CNF as a CNF as a CNF as a CNF
1.22) mode of mode of mode of mode of
deployment.) deployment.) deployment.) deployment.)
CN- • EKS on • EKS on • EKS on • EKS on
Series AWS AWS AWS AWS
for Outpost Outpost Outpost Outpost
EKS (1.17 (1.17 (1.17 (1.17
on through through through through
AWS 1.31) 1.31) 1.31) 1.31)
Outpost
does CN- CN- CN- CN-
not Series Series Series Series
support for for for for
SR- EKS EKS EKS EKS
IOV on on on on
or AWS AWS AWS AWS
Multus. Outpost Outpost Outpost Outpost
• Azure does does does does
AKS (1.17 not not not not
through support support support support
1.27) SR- SR- SR- SR-
IOV IOV IOV IOV
In or or or or
Azure Multus. Multus. Multus. Multus.
AKS, • Azure • Azure • Azure • Azure
the AKS (1.17 AKS (1.17 AKS (1.17 AKS (1.17
PAN- through through through through
OS 1.31) 1.31) 1.31) 1.31)
10.1.10h1
is In In In In
the Azure Azure Azure Azure
minimum AKS, AKS, AKS, AKS,
required the the the the
version PAN- PAN- PAN- PAN-
to OS OS OS OS
support 10.2.4h3 11.0.2 11.0.2 11.0.2
Kubernetes is is is is
1.25 the the the the
and minimum minimum minimum minimum
above. required required required required
• AliCloud version version version version
ACK (1.26) to to to to
• GCP GKE support support support support
(1.17 Kubernetes Kubernetes Kubernetes Kubernetes
through 1.25 1.25 1.25 1.25
1.27) and and and and
above. above. above. above.
Palo Alto Networks Compatibility Matrix 71 ©2024 Palo Alto Networks, Inc.
CN-Series Firewalls
Product PAN-OS 10.1 PAN-OS 10.2 PAN-OS 11.0 PAN-OS 11.1 PAN-OS 11.2
• GCP GKE • GCP GKE • GCP GKE • GCP GKE
(1.17 (1.17 (1.17 (1.17
through through through through
1.31) 1.31) 1.31) 1.31)
• OCI OKE • OCI OKE • OCI OKE
In (1.23) (1.23) (1.23)
GCP
GKE,
the
PAN-
OS
10.2.4h3
is
the
minimum
required
version
to
support
Kubernetes
1.25
and
above.
• Google
Anthos
1.12.3
• OCI OKE
(1.23)
CustomerOn the public On the public On the public On the public On the public
managed cloud or on- cloud or on- cloud or on- cloud or on- cloud or on-
Kubernetes
premises data premises data premises data premises data premises data
center. center. center. center. center.
Make sure Make sure Make sure Make sure Make sure
that the that the that the that the that the
Kubernetes Kubernetes Kubernetes Kubernetes Kubernetes
version, CNI version, CNI version, CNI version, CNI version, CNI
Types, and Types, and Types, and Types, and Types, and
Host VM OS Host VM OS Host VM OS Host VM OS Host VM OS
versions are versions are versions are versions are versions are
included in this included in this included in this included in this included in this
table. table. table. table. table.
VMware TKG+ VMware TKG+ VMware TKG+ VMware TKG+ VMware TKG+
version 1.1.2 version 1.1.2 version 1.1.2 version 1.1.2 version 1.1.2
Palo Alto Networks Compatibility Matrix 72 ©2024 Palo Alto Networks, Inc.
CN-Series Firewalls
Product PAN-OS 10.1 PAN-OS 10.2 PAN-OS 11.0 PAN-OS 11.1 PAN-OS 11.2
• Infrastructure • Infrastructure • Infrastructure • Infrastructure • Infrastructure
Platform— Platform— Platform— Platform— Platform—
vSphere 7.0 vSphere 7.0 vSphere 7.0 vSphere 7.0 vSphere 7.0
• Kubernetes • Kubernetes • Kubernetes • Kubernetes • Kubernetes
Host VM Host VM Host VM Host VM Host VM
OS—Photon OS—Photon OS—Photon OS—Photon OS—
OS OS OS OS Photon OS
Kubernetes
Operating Operating Operating Operating Operating
Host System: System: System: System: System:
VM
• Ubuntu • Ubuntu • Ubuntu • Ubuntu • Ubuntu
16.04 16.04 16.04 16.04 16.04
• Ubuntu • Ubuntu • Ubuntu • Ubuntu • Ubuntu
18.04 18.04 18.04 18.04 18.04
• Ubuntu-22.04 • Ubuntu-22.04 • Ubuntu-22.04 • Ubuntu-22.04 • Ubuntu-22.04
• RHEL/ • RHEL/ • RHEL/ • RHEL/ • RHEL/
CentOS 7.3 CentOS 7.3 CentOS 7.3 CentOS 7.3 CentOS 7.3
and later and later and later and later and later
• CoreOS • CoreOS • CoreOS • CoreOS • CoreOS
21XX, 21XX, 21XX, 21XX, 21XX,
22XX 22XX 22XX 22XX 22XX
• Container- • Container- • Container- • Container- • Container-
Optimized Optimized Optimized Optimized Optimized
OS OS OS OS OS
Linux Kernel Linux kernel Linux kernel Linux kernel Linux kernel
Netfilter: version: version: version: version:
Iptables
• 4.18 or • 4.18 or • 4.18 or • 4.18 or
later (K8s later (K8s later (K8s later (K8s
Service Service Service Service
Mode only) Mode only) Mode only) Mode only)
• 5.4 or later • 5.4 or later • 5.4 or later • 5.4 or later
required required required required
to enable to enable to enable to enable
AF_XDP AF_XDP AF_XDP AF_XDP
mode. See mode. See mode. See mode. See
Editable Editable Editable Editable
Parameters Parameters Parameters Parameters
in CN- in CN- in CN- in CN-
Series Series Series Series
Deployment Deployment Deployment Deployment
YAML Files YAML Files YAML Files YAML Files
for more for more for more for more
information. information. information. information.
Palo Alto Networks Compatibility Matrix 73 ©2024 Palo Alto Networks, Inc.
CN-Series Firewalls
Product PAN-OS 10.1 PAN-OS 10.2 PAN-OS 11.0 PAN-OS 11.1 PAN-OS 11.2
Linux kernel Linux kernel Linux kernel Linux kernel Linux kernel
version: Netfilter: Netfilter: Netfilter: Netfilter:
Iptables Iptables Iptables Iptables
• 4.18 or
later (K8s
Service
Mode only)
• 5.4 or later
required
to enable
AF_XDP
mode. See
Editable
Parameters
in CN-
Series
Deployment
YAML Files
for more
information.
CNI CNI Spec 0.3 CNI Spec 0.3 CNI Spec 0.3 CNI Spec 0.3 CNI Spec 0.3
Plugins and later: and later: and later: and later: and later:
• AWS-VPC • AWS-VPC • AWS-VPC • AWS-VPC • AWS-VPC
• Azure • Azure • Azure • Azure • Azure
• Calico • Calico • Calico • Calico • Calico
• Flannel • Flannel • Flannel • Flannel • Flannel
• Weave • Weave • Weave • Weave • Weave
• For • For • For • For • For
AliCloud, Openshift, Openshift, Openshift, Openshift,
Terway OpenshiftSDN, OpenshiftSDN, OpenshiftSDN, OpenshiftSDN,
• For OVN OVN OVN OVN
Openshift, Kubernetes Kubernetes Kubernetes Kubernetes
OpenshiftSDN • The • The • The • The
• The following following following following
following are are are are
are supported supported supported supported
supported on the on the on the on the
on the CN-Series CN-Series CN-Series CN-Series
CN-Series
Palo Alto Networks Compatibility Matrix 74 ©2024 Palo Alto Networks, Inc.
CN-Series Firewalls
Product PAN-OS 10.1 PAN-OS 10.2 PAN-OS 11.0 PAN-OS 11.1 PAN-OS 11.2
firewall as a firewall as a firewall as a firewall as a firewall as a
DaemonSet. DaemonSet. DaemonSet. DaemonSet. DaemonSet.
• Multus • Multus • Multus • Multus • Multus
• Bridge • Bridge • Bridge • Bridge • Bridge
• SR-IOV • SR-IOV • SR-IOV • SR-IOV • SR-IOV
• Macvlan • Macvlan • Macvlan • Macvlan • Macvlan
Palo Alto Networks Compatibility Matrix 75 ©2024 Palo Alto Networks, Inc.
CN-Series Firewalls
Palo Alto Networks Compatibility Matrix 76 ©2024 Palo Alto Networks, Inc.
Panorama
This section includes information about Panorama™ and compatible versions for devices that
Panorama can manage, as well as about plugins that are available for Panorama.
• Plugins
• Compatible Plugin Versions for PAN-OS 10.2
• Panorama Management Compatibility
• Panorama Hypervisor Support
• Device Certificate for a Palo Alto Networks Cloud Service
77
Panorama
Panorama Plugins
The following tables describe the features and functionality introduced with the Panorama™
extensible plugin architecture.
• Cisco ACI
• Cisco TrustSec
• Panorama CloudConnector Plugin (Formerly, AIOps Plugin for Panorama)
• Cloud Services
• Enterprise Data Loss Prevention (DLP)
• Panorama Interconnect
• IPS Signature Converter
• Kubernetes
• Clustering Plugin
• Network Discovery
• Nutanix
• OpenConfig
• Panorama Software Firewall License Plugin
• Public Cloud—AWS, Azure, and GCP
• SD-WAN
• VMware NSX
• VMware vCenter
• Zero Touch Provisioning (ZTP)
For more information on Panorama plugin versions, refer to the VM-Series and Panorama Plugins
Release Notes.
Cisco ACI
The following table shows the features introduced in each version of the Panorama™ plugin for
Cisco ACI. The plugin uses device groups on Panorama to push the configuration to the managed
firewalls.
End-of-life (EoL) software versions are included in this table. Review the Software End-of-
Life Summary website to check whether we are still supporting your software version.
Palo Alto Networks Compatibility Matrix 78 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 79 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 80 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 81 ©2024 Palo Alto Networks, Inc.
Panorama
Cisco TrustSec
The following table shows the features introduced in each version of Panorama™ plugin for Cisco
TrustSec.
End-of-life (EoL) software versions are included in this table. Review the Software End-of-
Life Summary website to check whether we are still supporting your software version.
Palo Alto Networks Compatibility Matrix 82 ©2024 Palo Alto Networks, Inc.
Panorama
• ISE 3.1
• ISE 2.7
Palo Alto Networks Compatibility Matrix 83 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 84 ©2024 Palo Alto Networks, Inc.
Panorama
Cloud Services
You use the Cloud Services plugin to activate Panorama Managed Prisma Access and to retrieve
logs from Panorama-managed firewalls using Strata Logging Service. Review the following table to
see the minimum Panorama and plugin versions for your deployment type.
Strata Logging Service Strata Logging Service Software Compatibility has the minimum
log retrieval from Panorama and plugin requirements.
Panorama-managed
firewalls only
End-of-life (EoL) software versions are included in this table. Review the Software End-of-
Life Summary website to check whether we are still supporting your software version.
Palo Alto Networks Compatibility Matrix 85 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 86 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 87 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 88 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 89 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 90 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 91 ©2024 Palo Alto Networks, Inc.
Panorama
Panorama Interconnect
The following table shows the features introduced in each version of the Panorama™
Interconnect plugin.
End-of-life (EoL) software versions are included in this table. Review the Software End-of-
Life Summary website to check whether we are still supporting your software version.
Palo Alto Networks Compatibility Matrix 92 ©2024 Palo Alto Networks, Inc.
Panorama
End-of-life (EoL) software versions are included in this table. Review the Software End-of-
Life Summary website to check whether we are still supporting your software version.
Palo Alto Networks Compatibility Matrix 93 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 94 ©2024 Palo Alto Networks, Inc.
Panorama
Kubernetes
The following table displays the features introduced in each version of the Panorama™
Kubernetes plugin.
End-of-life (EoL) software versions are included in this table. Review the Software End-of-
Life Summary website to check whether we are still supporting your software version.
Palo Alto Networks Compatibility Matrix 95 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 96 ©2024 Palo Alto Networks, Inc.
Panorama
Clustering Plugin
The following table shows the features introduced in Panorama Clustering plugin.
(Minimum)
Network Discovery
The following table shows the features introduced in each version of the Panorama™ plugin for
Network Discovery.
Palo Alto Networks Compatibility Matrix 97 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 98 ©2024 Palo Alto Networks, Inc.
Panorama
Nutanix
The following table shows the features introduced in each version of the Panorama™ plugin for
Nutanix.
End-of-life (EoL) software versions are included in this table. Review the Software End-of-
Life Summary website to check whether we are still supporting your software version.
2.0.0 Introduces
enhancements to
increase reliability and
robustness.
OpenConfig
The following table shows the features introduced in each version of the OpenConfig plugin.
End-of-life (EoL) software versions are included in this table. Review the Software End-of-
Life Summary website to check whether we are still supporting your software version.
Palo Alto Networks Compatibility Matrix 99 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 100 ©2024 Palo Alto Networks, Inc.
Panorama
End-of-life (EoL) software versions are included in this table. Review the Software End-of-
Life Summary website to check whether we are still supporting your software version.
End-of-life (EoL) software versions are included in this table. Review the Software End-of-
Life Summary website to check whether we are still supporting your software version.
Palo Alto Networks Compatibility Matrix 101 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 102 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 103 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 104 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 105 ©2024 Palo Alto Networks, Inc.
Panorama
9.1 1.0.4
Palo Alto Networks Compatibility Matrix 106 ©2024 Palo Alto Networks, Inc.
Panorama
SD-WAN
The following table shows the features introduced in each version of the Panorama™ plugin for
SD-WAN.
End-of-life (EoL) software versions are included in this table. Review the Software End-of-
Life Summary website to check whether we are still supporting your software version.
Palo Alto Networks Compatibility Matrix 107 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 108 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 109 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 110 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 111 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 112 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 113 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 114 ©2024 Palo Alto Networks, Inc.
Panorama
VMware NSX
The following table shows the features introduced in each version of the VM-Series firewall
VMware NSX plugin. For additional information about each plugin, see the release notes on the
Customer Support Portal.
End-of-life (EoL) software versions are included in this table. Review the Software End-of-
Life Summary website to check whether we are still supporting your software version.
Palo Alto Networks Compatibility Matrix 115 ©2024 Palo Alto Networks, Inc.
Panorama
4.0.1 Introduces
fixes for known
issues.
4.0.0 Introduces
Security-Centric
Deployment
Workflow (East-
West) for the
VM-Series on
VMware NSX-T.
• NSX-T E/W:
9.1
Palo Alto Networks Compatibility Matrix 116 ©2024 Palo Alto Networks, Inc.
Panorama
VMware vCenter
The following table shows the features introduced in each version of the Panorama™ plugin for
VMware vCenter.
End-of-life (EoL) software versions are included in this table. Review the Software End-of-
Life Summary website to check whether we are still supporting your software version.
2.0.0 Introduces
enhancements to
increase reliability and
robustness.
Palo Alto Networks Compatibility Matrix 117 ©2024 Palo Alto Networks, Inc.
Panorama
End-of-life (EoL) software versions are included in this table. Review the Software End-of-
Life Summary website to check whether we are still supporting your software version.
Palo Alto Networks Compatibility Matrix 118 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 119 ©2024 Palo Alto Networks, Inc.
Panorama
For more information about plugins compatible with PAN-OS 10.2 and all other
supported PAN-OS releases, refer to the Panorama Plugins page.
Cloud Services plugin (for use 3.1 (Compatible with PAN-OS 10.2.1 and later PAN-OS
with Strata™ Logging Service 10.2 versions)
only)
Cloud Services plugin (for use • 3.2 (compatible with PAN-OS 10.2.3 and later PAN-OS
with Panorama Managed Prisma 10.2 versions)
Access) • 3.1 starting with version 3.1.0-h50 (compatible with
PAN-OS 10.2.2-h1 and later PAN-OS 10.2 versions)
IMPORTANT: Review the PAN-OS and Prisma
Access Known Issues that are applicable to Panorama
deployments running PAN-OS 10.2.2 with Prisma Access
3.1.
Palo Alto Networks Compatibility Matrix 120 ©2024 Palo Alto Networks, Inc.
Panorama
Each upgraded Panorama plugin supports any supported PAN-OS release in addition to
PAN-OS 10.2.
Plugin Name Upgrade/ Base PAN-OS Base Plugin Target PAN- Target Plugin
Downgrade Version Version OS Version Version
Palo Alto Networks Compatibility Matrix 121 ©2024 Palo Alto Networks, Inc.
Panorama
Plugin Name Upgrade/ Base PAN-OS Base Plugin Target PAN- Target Plugin
Downgrade Version Version OS Version Version
You
should
upgrade
AWS
plugin
2.x.x
to
3.0.x
in
PAN-
OS
10.1.x
version
before
you
upgrade
to
PAN-
OS
10.2.
Palo Alto Networks Compatibility Matrix 122 ©2024 Palo Alto Networks, Inc.
Panorama
Plugin Name Upgrade/ Base PAN-OS Base Plugin Target PAN- Target Plugin
Downgrade Version Version OS Version Version
If
you
have
a
custom
certificate
size
greater
than
32k,
the
autocommit
(which
happens
after
downgrade)
will
fail.
To
avoid
this,
save
the
config
file,
add
a
dummy
value
in
the
custom
certificate
that
is
less
than
16K,
and
then
downgrade
to
2.0.x
(k8s
plugin
cannot
contact
the
API
server).
Palo Alto Networks Compatibility Matrix 123 ©2024 Palo Alto Networks, Inc.
Then
upgrade
the
Panorama
Plugin Name Upgrade/ Base PAN-OS Base Plugin Target PAN- Target Plugin
Downgrade Version Version OS Version Version
Palo Alto Networks Compatibility Matrix 124 ©2024 Palo Alto Networks, Inc.
Panorama
PAN-OS software versions that are End-of-Life (EoL) are not displayed. See the Palo Alto
Networks End of Life Announcements for additional information. EoL PAN-OS versions
are supported only for End-of-Sale (EoS) firewall models until they reach EoL.
Management of End-of-Life (EoL) PAN-OS versions may result in unexpected issues,
particularly if there is a large gap between the PAN-OS version installed on Panorama and
the one installed on the firewall. For example, you may run into unexpected or unknown
issues if you attempt to manage a firewall running the EoL PAN-OS 7.1 release from a
Panorama management server running PAN-OS 10.2 or a later version.
11.2 11.2
11.1
11.0
10.2
10.1
9.1
11.1 11.1
Palo Alto Networks Compatibility Matrix 125 ©2024 Palo Alto Networks, Inc.
Panorama
11.0 11.0
10.2
10.1
9.1
10.2 10.2
10.1
9.1
10.1 10.1
9.1
9.1 9.1
Palo Alto Networks Compatibility Matrix 126 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 127 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 128 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 129 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 130 ©2024 Palo Alto Networks, Inc.
Panorama
Palo Alto Networks Compatibility Matrix 131 ©2024 Palo Alto Networks, Inc.
Panorama
ZTP No Yes
Palo Alto Networks Compatibility Matrix 132 ©2024 Palo Alto Networks, Inc.
MFA Vendor Support
Palo Alto Networks Next-Generation Firewalls and Panorama™ appliances can integrate with
multi-factor authentication (MFA) vendors using RADIUS and SAML. Firewalls can additionally
integrate with specific MFA vendors using the API to enforce MFA through Authentication policy.
Next- √ √ √ —
Generation
Firewall and
Panorama
Administrator
Web Interface
Next- √ √ — —
Generation
Firewall and
Panorama
Administrator
CLI
GlobalProtect™ √ √ √ —
Portal and
Gateway
Authentication
Authentication √ √ √ √
Policy
Vendor / Min. Content Version *
(Formerly
• RSA SecurID Access / 752
Captive Portal
Policy) • PingID / 655
• Okta Adaptive / 655
• Duo v2 / 655
* Palo Alto Networks provides support for MFA vendors through Applications content
updates, which means that if you use Panorama to push device group configurations to
firewalls, you must install the same Applications release version on managed firewalls
as you install on Panorama to avoid mismatches in vendor support.
133
MFA Vendor Support
Palo Alto Networks Compatibility Matrix 134 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
Use this table in the Palo Alto Networks Compatibility Matrix to determine support for cipher
suites according to function and PAN-OS® software release.
• Cloud Identity Engine Cipher Suites
• Cipher Suites Supported in PAN-OS 11.2
• Cipher Suites Supported in PAN-OS 11.1
• Cipher Suites Supported in PAN-OS 11.0
• Cipher Suites Supported in PAN-OS 10.2
• Cipher Suites Supported in PAN-OS 10.1
• Cipher Suites Supported in PAN-OS 9.1
135
Supported Cipher Suites
Palo Alto Networks Compatibility Matrix 136 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 11.2 Cipher Suites
Supported in FIPS-CC Mode.
Palo Alto Networks Compatibility Matrix 137 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
Palo Alto Networks Compatibility Matrix 138 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 11.2 Cipher Suites
Supported in FIPS-CC Mode.
IPSec—Post-Quantum You can use these cipher suites to secure the rekey operations for
Cryptographic Suites your IPSec tunnels.
(PQCs)
• ML-KEM—512-bit, 768-bit, and 1024-bit keys
• HQC—128-bit, 192-bit, and 256-bit keys
• BIKE—bike-L1, bike-L3, & bike-L5
• Classic McEliece—348,864-bit and 348,864f-bit
• FrodoKEM:
• 640-AES, 976-AES, and 1344-AES
• 640-SHAKE, 976-SHAKE, and 1344-SHAKE
• NTRU-Prime—sntrup761
IPSec—Encryption • NULL
• 3DES
Palo Alto Networks Compatibility Matrix 139 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
IPSec—Message • NONE
Authentication • HMAC-MD5
• HMAC-SHA-1
• HMAC-SHA-256
• HMAC-SHA-384
• HMAC-SHA-512
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 11.2 Cipher Suites
Supported in FIPS-CC Mode.
Palo Alto Networks Compatibility Matrix 140 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
IKE—Encryption • 3DES
• AES-128-CBC
• AES-192-CBC
• AES-256-CBC
Starting with PAN-OS 10.0.3:
• AES-128-GCM
• AES-256-GCM
IKE—Message • HMAC-MD5
Authentication • HMAC-SHA-1
• HMAC-SHA-256
• HMAC-SHA-384
Palo Alto Networks Compatibility Matrix 141 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 11.2 Cipher Suites
Supported in FIPS-CC Mode.
Palo Alto Networks Compatibility Matrix 142 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
SSL/TLS Decryption • SSLv3, TLSv1.0, TLSv1.1, TLSv1.2, and TLSv1.3 cipher suites
• RSA 512-bit, 1024-bit, 2048-bit, 3072-bit, 4096-bit, and 8192-
bit keys
Palo Alto Networks Compatibility Matrix 143 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
Palo Alto Networks Compatibility Matrix 144 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 11.2 Cipher Suites
Supported in FIPS-CC Mode.
• RSA-SEED-SHA1
• RSA-CAMELLIA-128-SHA1
• RSA-CAMELLIA-256-SHA1
• RSA-AES-128-SHA1
• RSA-AES-256-SHA1
• RSA-AES-256-CBC-SHA1
• RSA-AES-128-CBC-SHA-256
• RSA-AES-256-CBC-SHA-256
• RSA-AES-128-GCM-SHA-256
• RSA-AES-256-GCM-SHA-384
• DHE-RSA-AES-128-GCM-SHA-256
• DHE-RSA-AES-256-GCM-SHA-384
Palo Alto Networks Compatibility Matrix 145 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
Palo Alto Networks Compatibility Matrix 146 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 11.2 Cipher Suites
Supported in FIPS-CC Mode.
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 11.2 Cipher Suites
Supported in FIPS-CC Mode.
Palo Alto Networks Compatibility Matrix 147 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in normal (non-FIPS-CC) operational mode, see Cipher Suites
Supported in PAN-OS 11.2
ECC key pair generation (NIST curves FIPS PUB 186-4 Appliances:
P-256, P-384)
<TBD>
VMs:
<TBD>
Palo Alto Networks Compatibility Matrix 148 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
Palo Alto Networks Compatibility Matrix 149 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
Cryptographic hashing
Palo Alto Networks Compatibility Matrix 150 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 11.1 Cipher Suites
Supported in FIPS-CC Mode.
Palo Alto Networks Compatibility Matrix 151 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
Palo Alto Networks Compatibility Matrix 152 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 11.1 Cipher Suites
Supported in FIPS-CC Mode.
• IPSec—Encryption
• IPSec—Message Authentication
• IPSec—Key Exchange
IPSec—Encryption • NULL
• 3DES
• AES-128-CBC
• AES-192-CBC
• AES-256-CBC
• AES-128-CCM
• AES-128-GCM
• AES-256-GCM
IPSec—Message • NONE
Authentication • HMAC-MD5
• HMAC-SHA-1
• HMAC-SHA-256
• HMAC-SHA-384
Palo Alto Networks Compatibility Matrix 153 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 11.1 Cipher Suites
Supported in FIPS-CC Mode.
Palo Alto Networks Compatibility Matrix 154 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
IKE—Encryption • 3DES
• AES-128-CBC
• AES-192-CBC
• AES-256-CBC
Starting with PAN-OS 10.0.3:
• AES-128-GCM
• AES-256-GCM
IKE—Message • HMAC-MD5
Authentication • HMAC-SHA-1
• HMAC-SHA-256
• HMAC-SHA-384
• HMAC-SHA-512
Palo Alto Networks Compatibility Matrix 155 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 11.1 Cipher Suites
Supported in FIPS-CC Mode.
Palo Alto Networks Compatibility Matrix 156 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
SSL/TLS Decryption • SSLv3, TLSv1.0, TLSv1.1, TLSv1.2, and TLSv1.3 cipher suites
• RSA 512-bit, 1024-bit, 2048-bit, 3072-bit, 4096-bit, and 8192-
bit keys
Palo Alto Networks Compatibility Matrix 157 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 11.1 Cipher Suites
Supported in FIPS-CC Mode.
Palo Alto Networks Compatibility Matrix 158 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
• RSA-SEED-SHA1
• RSA-CAMELLIA-128-SHA1
• RSA-CAMELLIA-256-SHA1
• RSA-AES-128-SHA1
• RSA-AES-256-SHA1
• RSA-AES-256-CBC-SHA1
• RSA-AES-128-CBC-SHA-256
• RSA-AES-256-CBC-SHA-256
• RSA-AES-128-GCM-SHA-256
• RSA-AES-256-GCM-SHA-384
• DHE-RSA-AES-128-GCM-SHA-256
• DHE-RSA-AES-256-GCM-SHA-384
• ECDHE-RSA-AES-128-GCM-SHA-256
• ECDHE-RSA-AES-256-GCM-SHA-384
• ECDHE-ECDSA-AES-128-SHA1
• ECDHE-ECDSA-AES-256-SHA1
• ECDHE-ECDSA-AES-128-GCM-SHA-256
• ECDHE-ECDSA-AES-256-GCM-SHA-384
• TLS-AES-128-CCM-SHA256
• TLS-AES-128-GCM-SHA256
• TLS-AES-256-GCM-SHA384
• TLS-CHACHA20-POLY1305-SHA256
Palo Alto Networks Compatibility Matrix 159 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 11.1 Cipher Suites
Supported in FIPS-CC Mode.
Palo Alto Networks Compatibility Matrix 160 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 11.1 Cipher Suites
Supported in FIPS-CC Mode.
If your firewall is running in normal (non-FIPS-CC) operational mode, see Cipher Suites
Supported in PAN-OS 11.1
Palo Alto Networks Compatibility Matrix 161 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
ECC key pair generation (NIST curves FIPS PUB 186-4 Appliances:
P-256, P-384)
#A3453
VMs:
#A3454
Palo Alto Networks Compatibility Matrix 162 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
• NIST SP 800-38A/C/
D/F
• FIPS PUB 197
Cryptographic hashing
Palo Alto Networks Compatibility Matrix 163 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
Palo Alto Networks Compatibility Matrix 164 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 11.0 Cipher Suites
Supported in FIPS-CC Mode.
Palo Alto Networks Compatibility Matrix 165 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
Palo Alto Networks Compatibility Matrix 166 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 11.0 Cipher Suites
Supported in FIPS-CC Mode.
• IPSec—Encryption
• IPSec—Message Authentication
• IPSec—Key Exchange
IPSec—Encryption • NULL
• 3DES
• AES-128-CBC
• AES-192-CBC
• AES-256-CBC
• AES-128-CCM
• AES-128-GCM
• AES-256-GCM
IPSec—Message • NONE
Authentication • HMAC-MD5
• HMAC-SHA-1
• HMAC-SHA-256
• HMAC-SHA-384
• HMAC-SHA-512
Palo Alto Networks Compatibility Matrix 167 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 11.0 Cipher Suites
Supported in FIPS-CC Mode.
Palo Alto Networks Compatibility Matrix 168 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
IKE—Encryption • 3DES
• AES-128-CBC
• AES-192-CBC
• AES-256-CBC
Starting with PAN-OS 10.0.3:
• AES-128-GCM
• AES-256-GCM
IKE—Message • HMAC-MD5
Authentication • HMAC-SHA-1
• HMAC-SHA-256
• HMAC-SHA-384
• HMAC-SHA-512
Palo Alto Networks Compatibility Matrix 169 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 11.0 Cipher Suites
Supported in FIPS-CC Mode.
SSL/TLS Decryption • SSLv3, TLSv1.0, TLSv1.1, TLSv1.2, and TLSv1.3 cipher suites
Palo Alto Networks Compatibility Matrix 170 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
Palo Alto Networks Compatibility Matrix 171 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 11.0 Cipher Suites
Supported in FIPS-CC Mode.
Palo Alto Networks Compatibility Matrix 172 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
• RSA-SEED-SHA1
• RSA-CAMELLIA-128-SHA1
• RSA-CAMELLIA-256-SHA1
• RSA-AES-128-SHA1
• RSA-AES-256-SHA1
• RSA-AES-256-CBC-SHA1
• RSA-AES-128-CBC-SHA-256
• RSA-AES-256-CBC-SHA-256
• RSA-AES-128-GCM-SHA-256
• RSA-AES-256-GCM-SHA-384
• DHE-RSA-AES-128-GCM-SHA-256
• DHE-RSA-AES-256-GCM-SHA-384
• ECDHE-RSA-AES-128-GCM-SHA-256
• ECDHE-RSA-AES-256-GCM-SHA-384
• ECDHE-ECDSA-AES-128-SHA1
• ECDHE-ECDSA-AES-256-SHA1
• ECDHE-ECDSA-AES-128-GCM-SHA-256
• ECDHE-ECDSA-AES-256-GCM-SHA-384
• TLS-AES-128-CCM-SHA256
• TLS-AES-128-GCM-SHA256
• TLS-AES-256-GCM-SHA384
• TLS-CHACHA20-POLY1305-SHA256
Palo Alto Networks Compatibility Matrix 173 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 11.0 Cipher Suites
Supported in FIPS-CC Mode.
Palo Alto Networks Compatibility Matrix 174 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 11.0 Cipher Suites
Supported in FIPS-CC Mode.
If your firewall is running in normal (non-FIPS-CC) operational mode, see Cipher Suites
Supported in PAN-OS 11.0
Palo Alto Networks Compatibility Matrix 175 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
ECC key pair generation (NIST curves FIPS PUB 186-4 Appliances:
P-256, P-384)
#A3453
VMs:
#A3454
Palo Alto Networks Compatibility Matrix 176 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
• NIST SP 800-38A/C/
D/F
• FIPS PUB 197
Cryptographic hashing
Palo Alto Networks Compatibility Matrix 177 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
Palo Alto Networks Compatibility Matrix 178 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 10.2 Cipher Suites
Supported in FIPS-CC Mode.
Palo Alto Networks Compatibility Matrix 179 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
Palo Alto Networks Compatibility Matrix 180 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 10.2 Cipher Suites
Supported in FIPS-CC Mode.
• IPSec—Encryption
• IPSec—Message Authentication
• IPSec—Key Exchange
IPSec—Encryption • NULL
• 3DES
• AES-128-CBC
• AES-192-CBC
• AES-256-CBC
• AES-128-CCM
• AES-128-GCM
• AES-256-GCM
IPSec—Message • NONE
Authentication • HMAC-MD5
• HMAC-SHA-1
• HMAC-SHA-256
• HMAC-SHA-384
• HMAC-SHA-512
Palo Alto Networks Compatibility Matrix 181 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 10.2 Cipher Suites
Supported in FIPS-CC Mode.
Palo Alto Networks Compatibility Matrix 182 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
IKE—Encryption • 3DES
• AES-128-CBC
• AES-192-CBC
• AES-256-CBC
Starting with PAN-OS 10.0.3:
• AES-128-GCM
• AES-256-GCM
IKE—Message • HMAC-MD5
Authentication • HMAC-SHA-1
• HMAC-SHA-256
• HMAC-SHA-384
• HMAC-SHA-512
Palo Alto Networks Compatibility Matrix 183 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 10.2 Cipher Suites
Supported in FIPS-CC Mode.
SSL/TLS Decryption • SSLv3, TLSv1.0, TLSv1.1, TLSv1.2, and TLSv1.3 cipher suites
Palo Alto Networks Compatibility Matrix 184 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
Palo Alto Networks Compatibility Matrix 185 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 10.2 Cipher Suites
Supported in FIPS-CC Mode.
Palo Alto Networks Compatibility Matrix 186 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
Palo Alto Networks Compatibility Matrix 187 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 10.2 Cipher Suites
Supported in FIPS-CC Mode.
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 10.2 Cipher Suites
Supported in FIPS-CC Mode.
Palo Alto Networks Compatibility Matrix 188 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in normal (non-FIPS-CC) operational mode, see Cipher Suites
Supported in PAN-OS 10.2
FFC key pair generation (key size 2048 FIPS PUB 186-4 Appliances:
bits)
#A2906
VMs:
#A2907
ECC key pair generation (NIST curves FIPS PUB 186-4 Appliances:
P-256, P-384)
#A2906
VMs:
#A2907
Palo Alto Networks Compatibility Matrix 189 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
Palo Alto Networks Compatibility Matrix 190 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
Cryptographic hashing
Palo Alto Networks Compatibility Matrix 191 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
Palo Alto Networks Compatibility Matrix 192 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 10.1 Cipher Suites
Supported in FIPS-CC Mode.
Palo Alto Networks Compatibility Matrix 193 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
Palo Alto Networks Compatibility Matrix 194 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 10.1 Cipher Suites
Supported in FIPS-CC Mode.
• IPSec—Encryption
• IPSec—Message Authentication
• IPSec—Key Exchange
IPSec—Encryption • NULL
• DES
• 3DES
• AES-128-CBC
• AES-192-CBC
• AES-256-CBC
• AES-128-CCM
• AES-128-GCM
• AES-256-GCM
IPSec—Message • NONE
Authentication • HMAC-MD5
• HMAC-SHA-1
• HMAC-SHA-256
• HMAC-SHA-384
• HMAC-SHA-512
Palo Alto Networks Compatibility Matrix 195 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 10.1 Cipher Suites
Supported in FIPS-CC Mode.
IKE—Encryption • DES
• 3DES
• AES-128-CBC
Palo Alto Networks Compatibility Matrix 196 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
IKE—Message • HMAC-MD5
Authentication • HMAC-SHA-1
• HMAC-SHA-256
• HMAC-SHA-384
• HMAC-SHA-512
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 10.1 Cipher Suites
Supported in FIPS-CC Mode.
Palo Alto Networks Compatibility Matrix 197 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
SSL/TLS Decryption • SSLv3, TLSv1.0, TLSv1.1, TLSv1.2, and TLSv1.3 cipher suites
• RSA 512-bit, 1024-bit, 2048-bit, 3072-bit, 4096-bit, and 8192-
bit keys
Palo Alto Networks Compatibility Matrix 198 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
Palo Alto Networks Compatibility Matrix 199 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 10.1 Cipher Suites
Supported in FIPS-CC Mode.
Palo Alto Networks Compatibility Matrix 200 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
Palo Alto Networks Compatibility Matrix 201 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 10.1 Cipher Suites
Supported in FIPS-CC Mode.
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 10.1 Cipher Suites
Supported in FIPS-CC Mode.
Palo Alto Networks Compatibility Matrix 202 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in normal (non-FIPS-CC) operational mode, see Cipher Suites
Supported in PAN-OS 10.1
FFC key pair generation (key size 2048 FIPS PUB 186-4 Appliances:
bits)
#A2137
VMs:
#A2244
ECC key pair generation (NIST curves FIPS PUB 186-4 Appliances:
P-256, P-384)
#A2137
VMs:
#A2244
Palo Alto Networks Compatibility Matrix 203 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
RSA Digital Signature Algorithm (rDSA) FIPS PUB 186-4, “Digital Appliances:
(2048 bits or greater) Signature Standard
#A2137
(DSS)”, Section 5.5,
using PKCS #1 v2.1 VMs:
Signature Schemes
#A2244
RSASSA-PSS and/or
RSASSAPKCS1v1_5;
ISO/IEC 9796-2, Digital
signature scheme 2
or
Digital Signature scheme
3
Palo Alto Networks Compatibility Matrix 204 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
Cryptographic hashing
Palo Alto Networks Compatibility Matrix 205 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 9.1 Cipher Suites
Supported in FIPS-CC Mode.
• GlobalProtect App/Agent—SSL
• GlobalProtect App/Agent—IPSec mode
• GlobalProtect Portal—Browser Access
Palo Alto Networks Compatibility Matrix 206 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
Palo Alto Networks Compatibility Matrix 207 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 9.1 Cipher Suites
Supported in FIPS-CC Mode.
• IPSec—Encryption
• IPSec—Message Authentication
• IPSec—Key Exchange
IPSec—Encryption • NULL
• DES
• 3DES
• AES-128-CBC
• AES-192-CBC
• AES-256-CBC
• AES-128-CCM
• AES-128-GCM
• AES-256-GCM
IPSec—Message • NONE
Authentication • HMAC-MD5
• HMAC-SHA-1
• HMAC-SHA-256
• HMAC-SHA-384
• HMAC-SHA-512
Palo Alto Networks Compatibility Matrix 208 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 9.1 Cipher Suites
Supported in FIPS-CC Mode.
IKE—Encryption • DES
• 3DES
• AES-128-CBC
Palo Alto Networks Compatibility Matrix 209 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
IKE—Message • HMAC-MD5
Authentication • HMAC-SHA-1
• HMAC-SHA-256
• HMAC-SHA-384
• HMAC-SHA-512
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 9.1 Cipher Suites
Supported in FIPS-CC Mode.
Palo Alto Networks Compatibility Matrix 210 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
Palo Alto Networks Compatibility Matrix 211 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 9.1 Cipher Suites
Supported in FIPS-CC Mode.
Palo Alto Networks Compatibility Matrix 212 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
Palo Alto Networks Compatibility Matrix 213 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 9.1 Cipher Suites
Supported in FIPS-CC Mode.
Palo Alto Networks Compatibility Matrix 214 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in FIPS-CC mode, see the list of PAN-OS 9.1 Cipher Suites
Supported in FIPS-CC Mode.
Palo Alto Networks Compatibility Matrix 215 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
If your firewall is running in normal (non-FIPS-CC) operational mode, see Cipher Suites
Supported in PAN-OS 9.1
Functions Standards
FFC key pair generation (key size 2048 bits) FIPS PUB 186-4
ECC key pair generation (NIST curves P-256, P-384) FIPS PUB 186-4
ECDSA key pair generation (NIST curves P-256, P-384) FIPS PUB 186-4
RSA Digital Signature Algorithm (rDSA) (2048 bits or FIPS PUB 186-4, “Digital Signature
greater) Standard (DSS)”, Section 5.5,
using PKCS #1 v2.1 Signature
Schemes RSASSA-PSS and/or
RSASSAPKCS1v1_5; ISO/IEC
9796-2, Digital signature scheme 2
or
Digital Signature scheme 3
Palo Alto Networks Compatibility Matrix 216 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
Functions Standards
ECDSA (NIST curves P-256, P-384, and P-521) FIPS PUB 186-4, “Digital Signature
Standard (DSS)”, Section 6 and
Appendix D, Implementing "NIST
curves" P-256, P-384, ISO/IEC
14888-3, Section 6.4
Cryptographic hashing
Palo Alto Networks Compatibility Matrix 217 ©2024 Palo Alto Networks, Inc.
Supported Cipher Suites
Palo Alto Networks Compatibility Matrix 218 ©2024 Palo Alto Networks, Inc.
GlobalProtect
The following topics provide support information for the GlobalProtect™ app (originally referred
to as the GlobalProtect agent on Windows and Mac).
• Where Can I Install the GlobalProtect App?
• Third-Party IPSec Client Support
• What Features Does GlobalProtect Support?
• TEST: What Features Does GlobalProtect Support?
• What Features Does GlobalProtect Support for IoT?
• What GlobalProtect Features Do Third-Party Mobile Device Management Systems Support?
219
GlobalProtect
The compatibility lists that follow show compatibility with major versions for each
platform only and does specifically call out minor versions. However, support the stated
support for the major versions implicitly includes support for all minor versions for the
listed major versions.
• Apple macOS
• Microsoft Windows
• Linux
• Apple iOS and iPadOS
• Google Android
• Google Chrome
• Internet of Things (IoT)
• Hypervisors
Use the OS compatibility information to determine what version of the GlobalProtect app you
want your users to run on their endpoints.
Because the version that an end user must download and install to enable successful
connectivity to your network depends on your environment, there is no direct download
link for the GlobalProtect app on the Palo Alto Networks site. In addition, the way you
deploy the GlobalProtect app to your users depends on the OS of the endpoint.
Apple macOS
The following table shows which macOS versions support which versions of the GlobalProtect
app. For instructions on installing the GlobalProtect app on a macOS endpoint, see the installation
instructions for 5.1, 5.2, and 6.0, 6.1, 6.2, and 6.3.
OS GP App 5.1 GP App 5.2 GP App 6.0 GP App 6.1 GP App 6.2 GP App 6.3
FIPS-CC
macOS √ √ — — —
10.11 (El
Capitan)
macOS √ √ — — — —
10.12
(Sierra)
Palo Alto Networks Compatibility Matrix 220 ©2024 Palo Alto Networks, Inc.
GlobalProtect
OS GP App 5.1 GP App 5.2 GP App 6.0 GP App 6.1 GP App 6.2 GP App 6.3
FIPS-CC
macOS √ √ — — — —
10.13
(High
Sierra)
macOS √ √ — — — —
10.14
5.2.12 &
(Mojave)
earlier
macOS √ √ √* √ √* —
10.15
(Catalina)
macOS 11 √ √ √* √ √* —
(Big Sur)
5.1.7 & 5.2.4 &
later (x86 later (x86-
& ARM- based
Based MacBooks)
MacBooks
5.2.5 &
Using
later (x86
Rosetta
& ARM-
Translation)
Based
MacBooks
Using
Rosetta
Translation)
5.2.6 &
later (x86
& ARM-
Based
MacBooks)
macOS 12 — √ √* √ √* √
(Monterey)
5.2.10 or
later (x86
& ARM-
Based
MacBooks)
macOS 13 — √ √* √ √* √
(Ventura)
5.2.12 or 6.0.3 or
later (x86 later (x86
& ARM- & ARM-
Palo Alto Networks Compatibility Matrix 221 ©2024 Palo Alto Networks, Inc.
GlobalProtect
OS GP App 5.1 GP App 5.2 GP App 6.0 GP App 6.1 GP App 6.2 GP App 6.3
FIPS-CC
Based Based
MacBooks) MacBooks)
macOS 14 — — √* √ √* √
(Sonoma)
6.0.7 or 6.1.2 or 6.2.1 or
later later later
Microsoft Windows
The following table shows which Microsoft Windows versions support which versions of the
GlobalProtect app. For instructions on installing the GlobalProtect app on a Windows endpoint,
see the installation instructions for 5.1, 5.2 6.0, 6.1, 6.2, and 6.3.
OS GP App 5.1 GP App 5.2 GP App 6.0 GP App 6.1 GP App 6.2 GP App 6.3
FIPS-CC
Windows 7 √ — — — — —
Service Upgrades
Pack 1 from
5.1.10 to
5.2.x or
later are
blocked.
Windows 8 — — — — — —
Windows √ √ — — — —
8.1
Windows √ √ √* √ √* √
10
Palo Alto Networks Compatibility Matrix 222 ©2024 Palo Alto Networks, Inc.
GlobalProtect
OS GP App 5.1 GP App 5.2 GP App 6.0 GP App 6.1 GP App 6.2 GP App 6.3
FIPS-CC
64-bit 64-bit 64-bit
(x64), (x64), (x64),
32-bit 32-bit 32-bit
(x86), and (x86), and (x86), and
ARM64 ARM64 ARM64
devices devices devices
Windows √ √ √ √ √ —
10 UWP
x86 and x86 and
ARM ARM
devices devices
Windows — √ √* √ √* √
11
64-bit 64-bit 64-bit
(x64) and (x64) and (x64) and
ARM64 ARM64 ARM64
devices devices devices
Windows — — — — √ √
365 Cloud
6.2.5 and
PC
later
Linux
The following table shows compatibility between Linux versions and GlobalProtect app versions.
For instructions on installing the GlobalProtect app on a Linux endpoint, see the installation
instructions for 5.1, 5.2, 6.0, and 6.1.
Only 64-bit Linux versions are supported. 32-bit versions are not supported.
OS GP App 5.1 GP App 5.2 GP App 5.3 GP App 6.0 GP App 6.1 GP App 6.2
FIPS-CC
CentOS √ √ — — — N/A
7.0
CLI-based CLI-based
and GUI- and GUI-
based based
Palo Alto Networks Compatibility Matrix 223 ©2024 Palo Alto Networks, Inc.
GlobalProtect
OS GP App 5.1 GP App 5.2 GP App 5.3 GP App 6.0 GP App 6.1 GP App 6.2
FIPS-CC
GlobalProtectGlobalProtect
app app
CentOS √ √ — — — N/A
7.1
CLI-based CLI-based
and GUI- and GUI-
based based
GlobalProtectGlobalProtect
app app
CentOS √ √ — — — N/A
7.2
CLI-based CLI-based
and GUI- and GUI-
based based
GlobalProtectGlobalProtect
app app
CentOS √ √ — — — N/A
7.3
CLI-based CLI-based
and GUI- and GUI-
based based
GlobalProtectGlobalProtect
app app
CentOS √ √ — — — N/A
7.4
CLI-based CLI-based
and GUI- and GUI-
based based
GlobalProtectGlobalProtect
app app
CentOS √ √ — — — N/A
7.5
CLI-based CLI-based
and GUI- and GUI-
based based
GlobalProtectGlobalProtect
app app
CentOS √ √ — — — N/A
7.6
CLI-based CLI-based
and GUI- and GUI-
based based
Palo Alto Networks Compatibility Matrix 224 ©2024 Palo Alto Networks, Inc.
GlobalProtect
OS GP App 5.1 GP App 5.2 GP App 5.3 GP App 6.0 GP App 6.1 GP App 6.2
FIPS-CC
GlobalProtectGlobalProtect
app app
CentOS √ √ — — — N/A
7.7
CLI-based CLI-based
and GUI- and GUI-
based based
GlobalProtectGlobalProtect
app app
CentOS √ √ — — — N/A
8.0
CLI-based CLI-based
GlobalProtectGlobalProtect
app app
CentOS — — √ √ √ N/A
8.3
CLI-based Supported CLI-based
and GUI- on and GUI-
based GlobalProtect based
GlobalProtect 6.0.4 or GlobalProtect
app earlier app
versions
only
CLI-based
and GUI-
based
GlobalProtect
app
Palo Alto Networks Compatibility Matrix 225 ©2024 Palo Alto Networks, Inc.
GlobalProtect
OS GP App 5.1 GP App 5.2 GP App 5.3 GP App 6.0 GP App 6.1 GP App 6.2
FIPS-CC
GlobalProtect GlobalProtect
app app
Red Hat √
Enterprise
Supported
Linux
on
(RHEL) 8.9
GlobalProtect
6.2.0 and
later
Red Hat — — — — √ √
Enterprise
(Supported
Linux
on
(RHEL) 9.1
GlobalProtect
6.1.1 and
later.)
Red Hat — — — — — √
Enterprise
(Supported
Linux
on 6.2.1
(RHEL) 9.3
and later)
Ubuntu √ √ √ — — N/A
14.04
CLI-based CLI-based CLI-based
and GUI- and GUI- and GUI-
based based based
GlobalProtectGlobalProtectGlobalProtect
app app app
running
Palo Alto Networks Compatibility Matrix 226 ©2024 Palo Alto Networks, Inc.
GlobalProtect
OS GP App 5.1 GP App 5.2 GP App 5.3 GP App 6.0 GP App 6.1 GP App 6.2
FIPS-CC
5.3.2 or
later
Ubuntu √ √ √ √ √ N/A
16.04 LTS
CLI-based CLI-based CLI-based CLI-based CLI-based
and GUI- and GUI- and GUI- and GUI- and GUI-
based based based based based
GlobalProtectGlobalProtectGlobalProtect GlobalProtect GlobalProtect
app app app app app
running
5.3.2 or
later
Ubuntu √ √ √ √ √ N/A
18.04 LTS
CLI-based CLI-based CLI-based CLI-based CLI-based
and GUI- and GUI- and GUI- and GUI- and GUI-
based based based based based
GlobalProtectGlobalProtectGlobalProtect GlobalProtect GlobalProtect
app app app app app
running
5.3.2 or
later
Ubuntu √ √ √ √ √ N/A
19.04
CLI-based CLI-based CLI-based CLI-based CLI-based
and GUI- and GUI- and GUI- and GUI- and GUI-
based based based based based
GlobalProtectGlobalProtectGlobalProtect GlobalProtect GlobalProtect
app app app app app
running
5.3.2 or
later
Ubuntu √ √ √ √ √ √
20.04
CLI-based CLI-based CLI-based CLI only CLI-based (Supported
GlobalProtectGlobalProtectGlobalProtect and GUI- on 6.2.1
app only app only app based and later)
running GlobalProtect
5.3.2 or app
later
Ubuntu — — — — √ √
22.04
CLI-based CLI-based
and GUI- and GUI-
Palo Alto Networks Compatibility Matrix 227 ©2024 Palo Alto Networks, Inc.
GlobalProtect
OS GP App 5.1 GP App 5.2 GP App 5.3 GP App 6.0 GP App 6.1 GP App 6.2
FIPS-CC
based based
GlobalProtect GlobalProtect
app app
Ubuntu √
24.04
Fedora — — — — — √
Linux 38
Fedora — — — — — √
Linux 40
(Supported
on
GlobalProtect
6.2.1 and
later.)
OS GP App 5.1 GP App 5.2 GP App 6.0 GP App 6.1 GP App 6.2
FIPS-CC
iOS 10 √ √ √ √ N/A
(64-bit (64-bit (64-bit (GlobalProtect
devices only) devices only) devices only) app 6.1.0 or
later)
iOS 11 √ √ √ √ N/A
(64-bit (64-bit (64-bit (GlobalProtect
devices only) devices only) devices only) app 6.1.0 or
later)
iOS 12 √ √ √ √ N/A
(64-bit (64-bit (64-bit (GlobalProtect
devices only) devices only) devices only) app 6.1.0 or
later)
iOS 13 √ √ √ √ N/A
Palo Alto Networks Compatibility Matrix 228 ©2024 Palo Alto Networks, Inc.
GlobalProtect
OS GP App 5.1 GP App 5.2 GP App 6.0 GP App 6.1 GP App 6.2
FIPS-CC
5.0.8 & later (64-bit (64-bit (GlobalProtect
devices only) devices only) app 6.1.0 or
(64-bit
later)
devices only)
iOS 14 — √ √ √ N/A
(64-bit (64-bit (GlobalProtect
devices only) devices only) app 6.1.0 or
later)
iOS 15 — √ √ √ N/A
(64-bit (64-bit (GlobalProtect
devices only devices only) app 6.1.0 or
running later)
GlobalProtect
app 5.2.12
or later)
iOS 16 — — √ √ N/A
(64-bit (GlobalProtect
devices only app 6.1.0 or
running later)
GlobalProtect
app 6.0.4 or
later)
iOS 17 — — — √ N/A
(GlobalProtect
app 6.1.0 or
later)
iOS 18 — — — √ N/A
(GlobalProtect
app 6.1.6 or
later)
Google Android
The following table shows compatibility between Google Android versions and GlobalProtect app
versions. For instructions on installing the GlobalProtect app on a Google Android endpoint, see
the installation instructions for 5.1, 5.2, and 6.0.
Palo Alto Networks Compatibility Matrix 229 ©2024 Palo Alto Networks, Inc.
GlobalProtect
OS GP App 5.1 GP App 5.2 GP App 6.0 GP App 6.1 GP App 6.2
FIPS-CC
Google √ √ √ √ N/A
Android 8.x
(GlobalProtect
app version
6.1.0 or later)
Google √ √ √ √ N/A
Android 9.x
(GlobalProtect
app version
6.1.0 or later)
Google √ √ √ √ N/A
Android 10.x
(GlobalProtect
app version
6.1.0 or later)
Google — √ √ √ N/A
Android 11.x
(GlobalProtect
app version
6.1.0 or later)
Google — √ √ √ N/A
Android 12.x
Starting with (GlobalProtect
GlobalProtect app version
app version 6.1.0 or later)
5.2.10
Palo Alto Networks Compatibility Matrix 230 ©2024 Palo Alto Networks, Inc.
GlobalProtect
OS GP App 5.1 GP App 5.2 GP App 6.0 GP App 6.1 GP App 6.2
FIPS-CC
Google — — √ √ N/A
Android 13.x
6.0.3 or later (GlobalProtect
app version
6.1.0 or later)
Google — — — √ N/A
Android 14.x
(GlobalProtect
app version
6.1.0 or later)
Google — — — √ N/A
Android 15.x
(GlobalProtect
app version
6.1.6 or later)
Chrome OS √ √ √ √ N/A
Systems
(GlobalProtect
Supporting
app version
Android Apps
6.1.0 or later)
Google Chrome
The following table shows compatibility between Google Chrome OS systems supporting Android
apps and GlobalProtect app versions. For instructions on installing the GlobalProtect app on a
Google Chrome endpoint, see the installation instructions for 5.1, and 5.2, and 6.0.
OS GP App 5.1 GP App 5.2 GP App 6.0 GP App 6.1 GP App 6.2
Palo Alto Networks Compatibility Matrix 231 ©2024 Palo Alto Networks, Inc.
GlobalProtect
OS GP App 5.1 GP App 5.2 GP App 5.3 GP App 6.0 GP App 6.1 GP App 6.2
Raspbian √ √ — √ √ N/A
Ubuntu √ √ — √ √ N/A
Windows √ √ — √ √ N/A
IoT
Enterprise
Hypervisors
The following table shows hypervisor support on each GlobalProtect app version.
OS GP App 5.1 GP App 5.2 GP App 5.3 GP App 6.0 GP App 6.1 GP App 6.2
Citrix Xen — — — √ √ √
Desktop
6.0.3 and
later
VMWare √ √ √ √ √ √
Horizon
and
Vcenter
Palo Alto Networks Compatibility Matrix 232 ©2024 Palo Alto Networks, Inc.
GlobalProtect
For stronger security, higher tunnel capacities, and a greater breadth of features, we
recommend that you use the GlobalProtect™ app instead of a third-party VPN client.
VPNC on Ubuntu Linux 10.04 and later versions and CentOS 9.1
6 and later versions
* To set up authentication for strongSwan Ubuntu and CentOS clients for PAN-OS 9.1 and
later releases, refer to the GlobalProtect Administrator’s Guide for your release.
Mixed Authentication √ √ √ √
Method Support for
Palo Alto Networks Compatibility Matrix 233 ©2024 Palo Alto Networks, Inc.
GlobalProtect
IPv4 Addressing √ √ √ √
Gateway-Level IP Pools √ √ √ √
Hardware Firewalls
PA-7080 2,000
PA-7050 2,000
PA-5450 4,000
PA-5440 4,000
PA-5430 4,000
PA-5420 4,000
PA-5410 4,000
PA-5280 2,500
PA-5260 2,500
Palo Alto Networks Compatibility Matrix 234 ©2024 Palo Alto Networks, Inc.
GlobalProtect
PA-5250 2,000
PA-5220 1,500
PA-3440 2,000
PA-3430 2,000
PA-3420 1,500
PA-3410 1,500
PA-3260 1,500
PA-3250 1,500
PA-3220 1,000
PA-1420 1,400
PA-1410 1,400
PA-850 500
PA-820 500
PA-460 1,400
PA-450 1,400
PA-445 1,400
PA-440 1,400
PA-415 500
PA-410 500
PA-220R 500
PA-220** 500
VM-Series Firewalls
VM-700 1,000
Palo Alto Networks Compatibility Matrix 235 ©2024 Palo Alto Networks, Inc.
GlobalProtect
VM-500 500
VM-300 500
VM-200 500
VM-100 500
VM-50 125
* PA-220 firewalls are supported only on PAN-OS 10.2 and earlier supported PAN-OS versions.
Refer to hardware end-of-life (EoL) dates for more information about end-of-life products.
Palo Alto Networks Compatibility Matrix 236 ©2024 Palo Alto Networks, Inc.
GlobalProtect
For Chromebook and other Chrome OS devices, use Android App 5.0 or a later version
to get GlobalProtect app features introduced in GlobalProtect app 5.0 and later releases.
(Refer also to the end-of-life (EoL) information for the GlobalProtect app.)
Authentication
Improvements 6.3.1 —
for Multi
Authentication
CIE
Experience
Palo Alto Networks Compatibility Matrix 237 ©2024 Palo Alto Networks, Inc.
GlobalProtect
Active — — — 4.1.0 — — — —
Directory
Password
Change
Using the
GlobalProtect
Credential
Provider
Palo Alto Networks Compatibility Matrix 238 ©2024 Palo Alto Networks, Inc.
GlobalProtect
SSO — — — 1.2.0 — — — —
(Credential
Provider)
SSO — — — 6.0.0 — — — —
(Smart
Windows
Card
10 or
Authentication)
later
VPN Connections
Connect Methods
Palo Alto Networks Compatibility Matrix 239 ©2024 Palo Alto Networks, Inc.
GlobalProtect
Connect — — — 5.2.0 — — — —
Before
Logon
Connection Priority
Modes
Palo Alto Networks Compatibility Matrix 240 ©2024 Palo Alto Networks, Inc.
GlobalProtect
Networking
Palo Alto Networks Compatibility Matrix 241 ©2024 Palo Alto Networks, Inc.
GlobalProtect
Customization
Palo Alto Networks Compatibility Matrix 242 ©2024 Palo Alto Networks, Inc.
GlobalProtect
Connect — — — 5.2.0 — — — —
Before
Logon
User- - - - 5.0.3 - — - -
Initiated
Pre-Logon
Connection
GlobalProtect- - - 4.1.0 - — - -
Tunnel
Preservation
On User
Logout
Palo Alto Networks Compatibility Matrix 243 ©2024 Palo Alto Networks, Inc.
GlobalProtect
Palo Alto Networks Compatibility Matrix 244 ©2024 Palo Alto Networks, Inc.
GlobalProtect
Palo Alto Networks Compatibility Matrix 245 ©2024 Palo Alto Networks, Inc.
GlobalProtect
GlobalProtect— — — 4.1.0 — — — —
Credentials
Provier
Pre-Logon
Connection
Status
Static IP — — — 4.1.0 — — — —
Address
Assignment
Pre-logon — — — 4.0.2 — — — —
tunnel
rename
timeout
Palo Alto Networks Compatibility Matrix 246 ©2024 Palo Alto Networks, Inc.
GlobalProtect
Palo Alto Networks Compatibility Matrix 247 ©2024 Palo Alto Networks, Inc.
GlobalProtect
Other
Palo Alto Networks Compatibility Matrix 248 ©2024 Palo Alto Networks, Inc.
GlobalProtect
Automatic — — 4.1.0 — — — — —
VPN
Reconnect
for
Chromebooks
Support — — — — — — — 6.2.0
for Native or
Certificate later
Store for versions
Prisma
Access
and
GloabProtect
App on
Linux
Endpoints
Palo Alto Networks Compatibility Matrix 249 ©2024 Palo Alto Networks, Inc.
GlobalProtect
Palo Alto Networks Compatibility Matrix 250 ©2024 Palo Alto Networks, Inc.
GlobalProtect
CLI — — — — — — — 6.2.1
Support or
for SAML later
Authentication versions
with
Default
Browser
for
GlobalProtect
App on
Linux
Endpoints
Palo Alto Networks Compatibility Matrix 251 ©2024 Palo Alto Networks, Inc.
GlobalProtect
For Chromebook and other Chrome OS devices, use Android App 5.0 or a later version to
get GlobalProtect app features introduced in GlobalProtect app 5.0 and later releases.
Authentication Features
GlobalProtect supports the following authentication features.
Palo Alto Networks Compatibility Matrix 252 ©2024 Palo Alto Networks, Inc.
GlobalProtect
Active — — — 5.1.0 — — —
Directory
Password
Change
Using the
GlobalProtect
Credential
Provider
Palo Alto Networks Compatibility Matrix 253 ©2024 Palo Alto Networks, Inc.
GlobalProtect
Single Sign-On
GlobalProtect supports the following single sign-on features.
SSO — — — 5.1.0 — — —
(Credential
Provider)
Palo Alto Networks Compatibility Matrix 254 ©2024 Palo Alto Networks, Inc.
GlobalProtect
IPSec VPN √ √ √ √
SSL VPN √ √ √ √
Pre-Logon — — — √
Connect Mode
User-Logon √ √ √ √
Connect Mode
Certificate or Certificate or Certificate or Certificate or
username and username and username and username and
password password password password
On-Demand — — — √
Connect Mode
External √ √ √ √
Gateway Priority
by Source
Region
Internal √ √ √
Gateway
Selection by
Source IP
Address
Internal Mode √ √ √ √
External Mode √ √ √ √
IPv4 Addressing √ √ √ √
IPv6 Addressing √ √ √ √
Split Tunnel √ √ √ √
Based on Access
Route
Split Tunnel — — — √
Based on
Destination
Palo Alto Networks Compatibility Matrix 255 ©2024 Palo Alto Networks, Inc.
GlobalProtect
Multiple Portal — — — √
Support
Resilient VPN √ √ √ √
Pre-Logon — — — √
Tunnel Rename
Timeout
Restrict √ — — √
Transparent
App Upgrades
to Internal
Network
Connections
Enforce √ — — √
GlobalProtect
for Network
Access
Deployment of √ √ √ √
SSL Forward
Proxy CA
Certificates in
the Trust Store
HIP Reports √ √ √ √
Run Scripts — √ √ √
Before and After
Sessions
Certificate — — √
Selection by
OID
Allow Users — — — √
to Disable
GlobalProtect
Palo Alto Networks Compatibility Matrix 256 ©2024 Palo Alto Networks, Inc.
GlobalProtect
Multi-Factor — — — √
Authentication
(MFA)
SAML — — — √
Authentication
Expired Active — — — √
Directory (AD)
Password
Change for
Remote Users
Active Directory — — — √
(AD) Password
Change
Using the
GlobalProtect
Credential
Provider
SSO (Credential — — — √
Provider)
Kerberos SSO — — — √
Welcome and — — — √
Help Pages
Headless-Mode √ √ √ √
Without Icon,
Pop-Up, Dialogs,
and UI
Palo Alto Networks Compatibility Matrix 257 ©2024 Palo Alto Networks, Inc.
GlobalProtect
GlobalProtect √ √ √ √ √
App
(macOS
Deployment
only;
requires
GlobalProtect
app 6.1 or
later)
Always on VPN √ √ √ √ —
Configuration
(iOS and (Android, (iOS and (Android
Android iOS, and Android only)
only) Windows 10 only)
UWP only)
Remote √ √ √ √ —
Access VPN
(iOS and (Android and (iOS only)
Configuration
Android iOS only)
only)
Per-App VPN √ √ √ — —
Configuration
(Android, (iOS only)
iOS, and
Windows 10
UWP only)
MDM √ — — — —
Integration with
HIP
VPN Lockdown √ — — — —
Palo Alto Networks Compatibility Matrix 258 ©2024 Palo Alto Networks, Inc.
Prisma Access
The following topics provide support information for Prisma® Access:
• What Features Does Prisma Access Support?
• Prisma Access and Panorama Version Compatibility
259
Prisma Access
Palo Alto Networks Compatibility Matrix 260 ©2024 Palo Alto Networks, Inc.
Prisma Access
Palo Alto Networks Compatibility Matrix 261 ©2024 Palo Alto Networks, Inc.
Prisma Access
Management
Feature Prisma Access (Cloud Prisma Access (Panorama
Managed) Managed)
Default Configurations √ —
Default settings enable you Examples include:
to get started quickly and
• Default DNS settings
securely
• Default GlobalProtect
settings, including for the
Prisma Access portal
• Default Prisma Access
infrastructure settings
Centralized Management √ —
Dashboards
Dashboards are available for
These can include best features including:
practice scores and usage
• Security Policy
information
• Security Profiles
• Decryption
Palo Alto Networks Compatibility Matrix 262 ©2024 Palo Alto Networks, Inc.
Prisma Access
Policy Optimizer √ √
Palo Alto Networks Compatibility Matrix 263 ©2024 Palo Alto Networks, Inc.
Prisma Access
Remote Networks
Feature Prisma Access (Cloud Prisma Access (Panorama
Managed) Managed)
IPSec Tunnels √ √
See the list of Supported IKE
Cryptographic Parameters.
We do not support FQDNs
for peer IPSec addresses; use
an IP address for the peer
address instead.
Tunnel Monitoring
ICMP √ √
Bidirectional Forwarding — —
Detection (BFD)
SNMP — —
Use Tunnel Monitoring
instead of SNMP to monitor
the tunnels in Prisma Access.
Palo Alto Networks Compatibility Matrix 264 ©2024 Palo Alto Networks, Inc.
Prisma Access
Service Connections
Feature Prisma Access (Cloud Prisma Access (Panorama
Managed) Managed)
IPSec Tunnels √ √
See the list of Supported IKE We do not support FQDNs
Cryptographic Parameters. for peer IPSec addresses; use
an IP address for the peer
address instead.
Tunnel Monitoring
ICMP √ √
Bidirectional Forwarding — —
Detection (BFD)
SNMP — —
Use Tunnel Monitoring
instead of SNMP to monitor
the tunnels in Prisma Access.
Palo Alto Networks Compatibility Matrix 265 ©2024 Palo Alto Networks, Inc.
Prisma Access
Mobile Users—GlobalProtect
Feature Prisma Access (Cloud Prisma Access (Panorama
Managed) Managed)
On-premises gateway √ √
integration with Prisma
We support using on-
Access
premises gateways with
Prisma Access gateways.
External Mode √ √
Internal Mode √ √
Introduced in 5.1 Preferred Introduced in 5.1 Preferred
and Innovation. and Innovation.
If you are running a version If you are running a version
below 5.1 Innovation, you can below 5.1 Innovation, you
add one or more on-premise can add one or more on-
gateways and configure them premise gateways and
as internal gateways. configure them as internal
gateways.
Palo Alto Networks Compatibility Matrix 266 ©2024 Palo Alto Networks, Inc.
Prisma Access
On-Demand √ √
Clientless VPN
DHCP — —
Prisma Access uses the IP
address pools you specify
during mobile user setup
to assign IP addresses to
Palo Alto Networks Compatibility Matrix 267 ©2024 Palo Alto Networks, Inc.
Prisma Access
Palo Alto Networks Compatibility Matrix 268 ©2024 Palo Alto Networks, Inc.
Prisma Access
Palo Alto Networks Compatibility Matrix 269 ©2024 Palo Alto Networks, Inc.
Prisma Access
Security Services
Security Policy √ √
DoS Protection √ √
The Prisma Access
infrastructure manages DoS
protection.
Includes
a guided
walkthrough
to safely
enable M365
• Google apps
• Dropbox
• YouTube
IoT Security √ √
Security Profiles
Palo Alto Networks Compatibility Matrix 270 ©2024 Palo Alto Networks, Inc.
Prisma Access
Response pages √ √
We support HTTP response
pages for mobile users and
users at remote networks.
To use HTTPS response
pages, open a CLI session
in the Panorama that
manages Prisma Access,
enter the set template
Mobile_User_Template
config deviceconfig
settingssl-decrypt
url-proxyyes command
in configuration mode, and
commit your changes.
Decryption
Decryption Policies √ √
Decryption Profiles √ √
Palo Alto Networks Compatibility Matrix 271 ©2024 Palo Alto Networks, Inc.
Prisma Access
SSH Proxy — √
Guided Walkthrough: √ —
Turn on Decryption
Palo Alto Networks Compatibility Matrix 272 ©2024 Palo Alto Networks, Inc.
Prisma Access
Network Services
Feature Prisma Access (Cloud Prisma Access (Panorama
Managed) Managed)
Network Services
Application Override √ √
IPv4 Addressing √ √
IPv6 Addressing √ √
You can access internal
(private) apps that use IPv6
addressing.
Introduced in 2.2 Preferred.
NetFlow — —
NAT √ √
Prisma Access automatically
manages outbound NAT; you
cannot configure the settings.
Routing Features
Static Routing √ √
Palo Alto Networks Compatibility Matrix 273 ©2024 Palo Alto Networks, Inc.
Prisma Access
High Availability
SMTP √ √
Prisma Access sometimes Prisma Access sometimes
blocks SMTP port 25 for blocks SMTP port 25 for
security reasons and to security reasons and to
mitigate the risk from known mitigate the risk from known
vulnerabilities that exploit vulnerabilities that exploit
nonsecure SMTP. Palo Alto nonsecure SMTP. Palo Alto
Networks recommends Networks recommends
using ports 465, 587, or using ports 465, 587, or
an alternate port 2525 for an alternate port 2525 for
SMTP. SMTP.
Palo Alto Networks Compatibility Matrix 274 ©2024 Palo Alto Networks, Inc.
Prisma Access
Identity Services
Feature Prisma Access (Cloud Prisma Access (Panorama
Managed) Managed)
Authentication Types
SAML √ √
TACACS+ √ √
RADIUS √ √
LDAP √ √
On-Premises LDAP
Authentication
Kerberos √ √
We support Kerberos only on Kerberos SSO
Windows clients.
MFA √ √
Multi-Factor Authentication
(MFA)
Local Database √ √
Authentication
Authentication Features
Authentication Rules √ √
Authentication Portal √ √
Certificate-Based √ √
Authentication
Supported for both IPSec Supported for both IPSec
and mobile users with and mobile users with
GlobalProtect. GlobalProtect.
Palo Alto Networks Compatibility Matrix 275 ©2024 Palo Alto Networks, Inc.
Prisma Access
RADIUS Vendor-Specific — —
Attributes (VSAs)
Extensible Authentication √ √
Protocol (EAP) Support for
RADIUS
Palo Alto Networks Compatibility Matrix 276 ©2024 Palo Alto Networks, Inc.
Prisma Access
Identity Redistribution √ √
• IP address-to-username
mappings
• HIP
• Device Quarantine
• IP-Tag
• User-Tag
Ingestion of IP address-to- — √
username mappings from a
third-party integration (NAC)
Palo Alto Networks Compatibility Matrix 277 ©2024 Palo Alto Networks, Inc.
Prisma Access
Policy Objects
Feature Prisma Access (Cloud Prisma Access (Panorama
Managed) Managed)
Addresses √ √
Address Groups √ √
Regions √ √
App-ID (Applications) √ √
Simplified Application √ —
Dependency Workflow (App
We do not support commit
Dependency tab for commits)
warnings for Prisma Access.
Application Groups √ √
Application Filters √ √
Services √ √
Service Groups √ √
Tags √ √
Streamlined Application- √ √
Based Policy (Tag-based
Introduced in 1.7.
application filters)
Requires Panorama running
PAN-OS 9.1.1 or a later
supported PAN-OS version.
Auto-Tag Actions √ √
Palo Alto Networks Compatibility Matrix 278 ©2024 Palo Alto Networks, Inc.
Prisma Access
HIP Objects
HIP √ √
HIP Notifications √ √
HIP Checks √ √
HIP Redistribution √ √
Introduced in 1.5.
Certificate Management
Custom Certificates √ √
Certificate Profiles √ √
Custom Certificates √ √
SSL √ √
We support SSL only for
mobile users, not for site-to-
site VPNs.
SCEPs √ √
Palo Alto Networks Compatibility Matrix 279 ©2024 Palo Alto Networks, Inc.
Prisma Access
OCSP Responders √ √
Palo Alto Networks Compatibility Matrix 280 ©2024 Palo Alto Networks, Inc.
Prisma Access
Logs
Feature Prisma Access (Cloud Prisma Access (Panorama
Managed) Managed)
Enhanced Application √ √
Logging
Palo Alto Networks Compatibility Matrix 281 ©2024 Palo Alto Networks, Inc.
Prisma Access
Reports
Feature Prisma Access (Cloud Prisma Access (Panorama
Managed) Managed)
Palo Alto Networks Compatibility Matrix 282 ©2024 Palo Alto Networks, Inc.
Prisma Access
Palo Alto Networks Compatibility Matrix 283 ©2024 Palo Alto Networks, Inc.
Prisma Access
Palo Alto Networks Compatibility Matrix 284 ©2024 Palo Alto Networks, Inc.
Prisma Access
Palo Alto Networks Compatibility Matrix 285 ©2024 Palo Alto Networks, Inc.
Prisma Access
Palo Alto Networks Compatibility Matrix 286 ©2024 Palo Alto Networks, Inc.
Prisma Access
Palo Alto Networks Compatibility Matrix 287 ©2024 Palo Alto Networks, Inc.
Prisma Access
Due to the fast-paced release cycle for Prisma Access and the Cloud Services plugin, the
software end-of-support (EoS) dates for Panorama appliances for managing Prisma
Access vary from the software end-of-life (EoL) dates for PAN-OS and Panorama releases.
These exceptions apply only to Panorama version compatibility with Prisma Access.
5.2 and 5.2.1 Preferred and • PAN-OS 11.2.3 (required for 5.2 Innovation) or PAN-
Innovation OS 11.2.4 (required for 5.2.1 Innovation)
• PAN-OS 10.2.10 (required for 5.2 and 5.2.1
Preferred)
5.1 and 5.1.1 Preferred and • PAN-OS 11.2 (required for 5.1 and 5.1.1 Innovation)
Innovation
• PAN-OS 10.2.4 (required for 5.1 and 5.1.1 Preferred)
4.0, 4.1, and 4.2 Preferred • PAN-OS 11.1.0 or a later PAN-OS 11.1 version
5.0 and 5.0.1 Preferred and • PAN-OS 11.0.0 or a later PAN-OS 11.0 version
Innovation
Running Panorama with PAN-OS 11.0 or PAN-
OS 11.1 does not give you access to PAN-OS 11.0
features in Prisma Access.
• PAN-OS 10.2.3 or a later PAN-OS 10.2 version
• PAN-OS 10.1.7 or a later PAN-OS 10.1 version
You must have a Panorama appliance running PAN-
OS 10.2 to take advantage of the PAN-OS 10.2
features in Prisma Access.
Palo Alto Networks Compatibility Matrix 288 ©2024 Palo Alto Networks, Inc.
Prisma Access
Due to the fast-paced release cycles for Prisma Access and the Cloud Services plugin,
the software compatibility end-of-support (EoS) dates for Panorama appliances that
manage Prisma Access sometimes differ from the software end-of-life (EoL) dates for
PAN-OS and Panorama software versions. The exceptions apply only to Panorama version
compatibility with Prisma Access.
To find the latest EoS compatibility information for your Panorama software with Prisma
Access, log in to the Panorama appliance that manages Prisma Access, select the Service
Setup page (Panorama > Cloud Services > Configuration > Service Setup), and view
the Panorama Alert information. (See Notifications and Alerts for Panorama, Cloud
Services Plugin, and PAN-OS Dataplane Versions for details.)
Palo Alto Networks Compatibility Matrix 289 ©2024 Palo Alto Networks, Inc.
Prisma Access
You must upgrade Panorama regardless of the Cloud Services plugin version you're running when
the Panorama software version reaches its EoS date. You cannot continue using earlier versions of
the Cloud Services plugin with an earlier unsupported version of Panorama software.
The following Panorama software versions are already EoS and you cannot use them with Prisma
Access:
• PAN-OS 10.0—EoS on July 16, 2022
• PAN-OS 9.0—EoS on February 1, 2021
Palo Alto Networks Compatibility Matrix 290 ©2024 Palo Alto Networks, Inc.
Strata Cloud Manager and
Panorama Feature Parity
Strata Cloud Manager and Panorama both enable you to centrally manage large-scale firewall
deployments. These are the features each supports.
• Software
• Management
• Optimization
• Reporting
• Hardware
• Cloud-Delivered Security Services
• Cloud
Software
Management
291
Strata Cloud Manager and Panorama Feature Parity
Templates No Yes
Multi-VSYS No Yes
Automated VPN creation Yes (no extra licensing Requires SD-WAN license
required)
Optimization
Reporting
Palo Alto Networks Compatibility Matrix 292 ©2024 Palo Alto Networks, Inc.
Strata Cloud Manager and Panorama Feature Parity
Hardware
Cloud
Palo Alto Networks Compatibility Matrix 293 ©2024 Palo Alto Networks, Inc.
Strata Cloud Manager and Panorama Feature Parity
Identity
Palo Alto Networks Compatibility Matrix 294 ©2024 Palo Alto Networks, Inc.
User-ID Agent
You install the User-ID™ agent on a domain server that is running a supported operating system
(OS) and then connect the User-ID agent to exchange or directory servers.
• Where Can I Install the User-ID Agent?
• Which Servers Can the User-ID Agent Monitor?
• Where Can I Install the User-ID Credential Service?
295
User-ID Agent
Palo Alto Networks Compatibility Matrix 296 ©2024 Palo Alto Networks, Inc.
User-ID Agent
You can install only specific releases of the Windows-based User-ID agent on supported
Microsoft Windows servers.
Microsoft • 2019—Only with Windows User-ID agent 9.0.2 and later releases or
Exchange Server with PAN-OS integrated User-ID agents running the following PAN-OS
releases:
• PAN-OS 11.0 (all releases)
• PAN-OS 10.2 (all releases)
• PAN-OS 10.1 (all releases)
• PAN-OS 9.1 (all releases)
• 2016—Only with Windows User-ID agent or with PAN-OS integrated
User-ID agents running the following PAN-OS releases:
• PAN-OS 11.0 (all releases)
• PAN-OS 10.2 (all releases)
• PAN-OS 10.1 (all releases)
• PAN-OS 9.1 (all releases)
• 2013
Palo Alto Networks Compatibility Matrix 297 ©2024 Palo Alto Networks, Inc.
User-ID Agent
Novell 8.8
eDirectory
Server
Palo Alto Networks Compatibility Matrix 298 ©2024 Palo Alto Networks, Inc.
User-ID Agent
Palo Alto Networks Compatibility Matrix 299 ©2024 Palo Alto Networks, Inc.
User-ID Agent
Palo Alto Networks Compatibility Matrix 300 ©2024 Palo Alto Networks, Inc.
Terminal Server (TS) Agent
You install the Terminal Server (TS) agent on a domain server that is running a supported
operating system (OS) and then report username-to-port mapping information to PAN-OS®
firewalls.
• Where Can I Install the Terminal Server (TS) Agent?
• How Many TS Agents Does My Firewall Support?
301
Terminal Server (TS) Agent
For optimal configuration, install the TS agent version that matches the PAN-OS version
running on your firewall. If there is not a TS agent version that matches your PAN-OS
version, install the latest version that is closest to the PAN-OS version.
Operating System TS Agent 9.1 TS Agent 10.1 TS Agent 10.2 TS Agent 11.0
Windows Server √ √ √ √
2022
9.1.4 & later
Windows Server √ √ √ √
2019
Windows Server √ √ √ √
2016
Windows Server √ √ √ √
2012 R2
Windows 11 √ √ √ √
Enterprise Multi-
9.1.4 & later
session
Windows 10 √ √ √ √
Enterprise Multi-
9.1.1 & later
session
Citrix Metaframe √ √ √ √
Presentation Server
4.x
Palo Alto Networks Compatibility Matrix 302 ©2024 Palo Alto Networks, Inc.
Terminal Server (TS) Agent
For optimal configuration, install the TS agent version that matches the PAN-OS version
running on the firewall. If there is not a TS agent version that matches the PAN-OS
version, install the latest version that is closest to the PAN-OS version.
Firewall or VM Model PAN-OS 9.1 PAN-OS 10.1 PAN-OS 10.2 PAN-OS 11.0
Hardware Firewalls
PA-5440 — — — 2,500
PA-445 — — — 800
PA-415 — — — 400
Palo Alto Networks Compatibility Matrix 303 ©2024 Palo Alto Networks, Inc.
Terminal Server (TS) Agent
Firewall or VM Model PAN-OS 9.1 PAN-OS 10.1 PAN-OS 10.2 PAN-OS 11.0
VM-Series Firewalls
Palo Alto Networks Compatibility Matrix 304 ©2024 Palo Alto Networks, Inc.
Strata Logging Service Software
Compatibility
To forward firewall log data to Strata Logging Service (formerly Cortex® Data Lake), you must
ensure that your firewalls are running a supported PAN-OS® version. The PAN-OS version you
need depends on whether you use Panorama™ to onboard several firewalls simultaneously or you
onboard firewalls individually.
To onboard firewalls to Strata Logging Service using Panorama, you must also install a supported
version of the Cloud Services plugin. If you use the Cloud Services plugin to enable Prisma®
Access, ensure that your Panorama is running supported versions of PAN-OS and the Cloud
Services plugin.
Version Requirements for Panorama Managed Firewalls
Software versions required to integrate a Panorama-managed deployment with Strata Logging
Service.
Cloud Minimum: 1.5.0-h6 The Cloud Services plugin enables you to send log data
Services from Panorama-managed firewalls. To download the
Recommended: the
plugin plugin, see the step describing how to install the plugin
latest version
when you configure Panorama for Strata Logging
Service.
305
Strata Logging Service Software Compatibility
PAN-OS Minimum: PAN-OS 9.1 Individually managed firewalls must run PAN-OS 9.1 or
a later supported PAN-OS version to authenticate to
Strata Logging Service.
Content Minimum: 8274 Install the latest content updates to ensure your
Version firewall can authenticate to Strata Logging Service.
Palo Alto Networks Compatibility Matrix 306 ©2024 Palo Alto Networks, Inc.
Cortex XDR
Compatibility information for Cortex XDR® has a new home. Going forward, when you
click the links below, you will be redirected to the Palo Alto Networks docs-cortex
website.
307
Cortex XDR
Palo Alto Networks Compatibility Matrix 308 ©2024 Palo Alto Networks, Inc.
Endpoint Security Manager (ESM)
You can install the Traps™ agent, now known as the Cortex XDR® agent, and the Endpoint
Security Manager (ESM) Components (comprised of the ESM Console, one or more ESM Servers,
and the database) only on servers and endpoints that are running a supported operating system
(OS).
309
Endpoint Security Manager (ESM)
Compatibility information for Cortex XDR (and Traps) has a new home. Going forward,
you can determine Endpoint Operating Systems Supported with Cortex XDR and
Traps by going to the Palo Alto Networks docs-cortex website.
Palo Alto Networks Compatibility Matrix 310 ©2024 Palo Alto Networks, Inc.
Endpoint Security Manager (ESM)
Compatibility information for Cortex XDR (and Traps) has a new home. Going forward,
you can determine where you can install the Cortex XDR agent by going to the Palo
Alto Networks docs-cortex website.
Palo Alto Networks Compatibility Matrix 311 ©2024 Palo Alto Networks, Inc.
Endpoint Security Manager (ESM)
Palo Alto Networks Compatibility Matrix 312 ©2024 Palo Alto Networks, Inc.
IPv6 Support by Feature
Use the following table to review PAN-OS® features (listed by category) that support IPv6 traffic.
• Security
• Management & Panorama
• SD-WAN
• Networking
• VPN
• Host Dynamic Address Configuration
• Device
• User-ID™
Security
WildFire® Appliance — √ √ √ √ √
User-ID™ √ √ √ √ √ √
Content-ID™ √ √ √ √ √ √
Zone Protection √ √ √ √ √ √
Packet-Based Attack √ √ √ √ √ √
Protection
Reconnaissance Protection √ √ √ √ √ √
URL Filtering √ √ √ √ √ √
SSL Decryption √ √ √ √ √ √
SSH Decryption √ √ √ √ √ √
313
IPv6 Support by Feature
DoS Rulebase √ √ √ √ √ √
DNS Sinkhole √ √ √ √ √ √
Panorama HA Connection √ √ √ √ √ √
Between Peers
DNS √ √ √ √ √ √
RADIUS √ √ √ √ √ √
LDAP √ √ √ √ √ √
SYSLOG √ √ √ √ √ √
SNMP √ √ √ √ √ √
NTP √ √ √ √ √ √
DNS Proxy √ √ √ √ √ √
Palo Alto Networks Compatibility Matrix 314 ©2024 Palo Alto Networks, Inc.
IPv6 Support by Feature
SD-WAN
Networking
PBF √ √ √ √ √ √
OSPFv3 √ √ √ √ √ √
MP-BGP √ √ √ √ √ √
ECMP √ √ √ √ √ √
QoS Policy √ √ √ √ √ √
QoS Marking √ √ √ √ √ √
Palo Alto Networks Compatibility Matrix 315 ©2024 Palo Alto Networks, Inc.
IPv6 Support by Feature
Virtual Wires √ √ √ √ √ √
Bidirectional Forwarding √ √ √ √ √ √
Detection (BFD)
VPN
GlobalProtect™ √ √ √ √ √ √
IKE/IPSec √ √ √ √ √ √
IKEv2 √ √ √ √ √ √
DHCPv6 Relay √ √ √ √ √ √
SLAAC (Router √ √ √ √ √ √
Advertisements)
Palo Alto Networks Compatibility Matrix 316 ©2024 Palo Alto Networks, Inc.
IPv6 Support by Feature
SLAAC (RDNSS) √ √ √ √ √ √
Device
HA—Active/Passive √ √ √ √ √ √
HA Clustering — √ √ √ √ √
User-ID
Palo Alto Networks Compatibility Matrix 317 ©2024 Palo Alto Networks, Inc.
IPv6 Support by Feature
Palo Alto Networks Compatibility Matrix 318 ©2024 Palo Alto Networks, Inc.
Mobile Network Infrastructure
Feature Support
Review the lists of Specific Palo Alto Networks firewall models and PAN-OS® software versions
that support GTP, SCTP, 5G, PFCP, and RADIUS Security, as well as 3GPP Technical Standards:
• PAN-OS Releases by Model that Support GTP, SCTP, and 5G Security
• PAN-OS Releases by Model that Support Intelligent Security Correlation (PFCP, RADIUS, and
GTP)
• 3GPP TS References for GTP Security
• 3GPP TS References for 5G Security
• 3GPP TS References for 5G Multi-Edge Security
• 3GPP TS References for UE-to-IP Address Correlation with PFCP in 4G
319
Mobile Network Infrastructure Feature Support
VM-Series Firewalls √ √ √ √ √ √
CN-Series Firewalls* — √ √ √ √ √
PA-7500 Firewalls — — — — √ √
(Standalone only)
PA-7000 Series √ √ √ √ √ √
Firewalls that
use three of the
following cards**:
• PA-7000-100G-
NPC card;
• PA-7000-LFC-A
card; and
• PA-7050-SMC-B
card
OR
PA-7080-SMC-B
card
PA-5410, PA-5420, — — √ √ √ √
and PA-5430
Firewalls
PA-5440 Firewalls — — — √ √ √
PA-5445 Firewalls — — — — √ √
Palo Alto Networks Compatibility Matrix 320 ©2024 Palo Alto Networks, Inc.
Mobile Network Infrastructure Feature Support
PA-5450 Firewalls — √ √ √ √ √
PA-5200 Series √ √ √ √ √ √
Firewalls
PA-3430 and — — √ √ √ √
PA-3440 Firewalls
* CN-Series Daemonset mode supports GTP, SCTP, and 5G security in PAN-OS 10.1 and later
PAN-OS versions. Additionally, CN-Series firewalls running PAN-OS 10.2 and later PAN-OS
versions support GTP, SCTP, and 5G security in both K8s cloud-native network (CNF) mode and
Daemonset mode.
** To verify that your PA-7000 Series firewall is installed with the cards that support
GTP and SCTP, use the show chassis inventory CLI command. However, it is
possible that cards are installed but are not functional if your firewall does not account
for all dependencies. Refer to the PA-7000 Series Firewall Hardware Reference for
installation instructions and to review the dependencies for each card.
Palo Alto Networks Compatibility Matrix 321 ©2024 Palo Alto Networks, Inc.
Mobile Network Infrastructure Feature Support
VM-Series Firewalls √ √ √
CN-Series Firewalls √ √ √
PA-5445 Firewalls — √ √
* In PAN-OS 11.0, we support only 4G CUPS architecture for Intelligent Security with PFCP.
** We support Intelligent Security with RADIUS in PAN-OS 11.0.2 and all later PAN-OS versions.
*** To verify that your PA-7000 Series firewall is installed with the cards that support
PFCP, RADIUS, and GTP, use the show chassis inventory CLI command.
However, it is possible that cards are installed but are not functional if your firewall
does not account for all dependencies. Refer to the PA-7000 Series Firewall Hardware
Reference for installation instructions and to review the dependencies for each card.
Palo Alto Networks Compatibility Matrix 322 ©2024 Palo Alto Networks, Inc.
Mobile Network Infrastructure Feature Support
— 43.129 15.0.0
— 23.401 15.12.0
Palo Alto Networks Compatibility Matrix 323 ©2024 Palo Alto Networks, Inc.
Mobile Network Infrastructure Feature Support
Palo Alto Networks Compatibility Matrix 324 ©2024 Palo Alto Networks, Inc.
Mobile Network Infrastructure Feature Support
Palo Alto Networks Compatibility Matrix 325 ©2024 Palo Alto Networks, Inc.
Mobile Network Infrastructure Feature Support
29.244 Up to 16.9.1
Palo Alto Networks Compatibility Matrix 326 ©2024 Palo Alto Networks, Inc.