<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CUSTOMER ADVISORY: Required Action for Azure hosted VM-Series &amp;amp; AIRS Instances in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/customer-advisory-required-action-for-azure-hosted-vm-series-amp/m-p/1250475#M2444</link>
    <description>&lt;P&gt;&lt;STRONG&gt;Subject:&lt;/STRONG&gt;&lt;SPAN&gt; Mechanism to prevent pairing to Microsoft Azure Network Adapter (MANA) for VM-Series and AIRS Firewalls to avoid throughput degradation.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Overview&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&lt;A href="https://techcommunity.microsoft.com/blog/azureinfrastructureblog/announcing-microsoft-azure-network-adapter-mana-support-for-existing-vm-skus/4493279" target="_blank"&gt;&lt;SPAN&gt;Microsoft is rolling out the new &lt;/SPAN&gt;&lt;STRONG&gt;Microsoft Azure Network Adapter (MANA)&lt;/STRONG&gt;&lt;/A&gt;&lt;SPAN&gt; hardware across existing Azure VM sizes families. While MANA is designed to enhance performance for modern workloads, certain versions of the Palo Alto Networks VM-Series firewall are not yet fully optimized for this hardware.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;The Issue&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN&gt;On all &lt;/SPAN&gt;&lt;STRONG&gt;PAN-OS versions below 12.1.5&lt;/STRONG&gt;&lt;SPAN&gt;, if VM-Series instances are paired with MANA NICs the instance will default to the &lt;/SPAN&gt;&lt;STRONG&gt;mmap synthetic path&lt;/STRONG&gt;&lt;SPAN&gt; rather than the high-performance &lt;/SPAN&gt;&lt;STRONG&gt;DPDK (Data Plane Development Kit)&lt;/STRONG&gt;&lt;SPAN&gt; driver. This pairing can occur to any VMs that are stop-deallocated and restarted or redeployed.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Critical Impact:&lt;/STRONG&gt;&lt;SPAN&gt; This fallback can result in a &lt;/SPAN&gt;&lt;STRONG&gt;50% or greater reduction&lt;/STRONG&gt;&lt;SPAN&gt; in maximum firewall throughput, significantly impacting the performance of your security infrastructure.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Affected Configurations&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Platform:&lt;/STRONG&gt;&lt;SPAN&gt; Azure VM-Series and AIRS (AI Runtime Security) instances.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Software:&lt;/STRONG&gt;&lt;SPAN&gt; Any PAN-OS version &lt;/SPAN&gt;&lt;STRONG&gt;lesser than 12.1.5&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Hardware:&lt;/STRONG&gt;&lt;SPAN&gt; Any instance recently migrated by Azure to MANA-capable hardware (typically indicated by the presence of a MANA Virtual Function in the guest OS).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;&lt;STRONG&gt;Required Action&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN&gt;To maintain current performance levels and prevent an automatic transition to the synthetic path for stop-deallocated and restarted or redeployed VMs, customers on affected versions must &lt;/SPAN&gt;&lt;STRONG&gt;opt-out&lt;/STRONG&gt;&lt;SPAN&gt; of MANA NIC eligibility for their instances. Please refer to FAQs provided by Microsoft &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/virtual-network/accelerated-networking-mana-network-virtual-appliance-opt-out" target="_blank"&gt;&lt;SPAN&gt;https://learn.microsoft.com/en-us/azure/virtual-network/accelerated-networking-mana-network-virtual-appliance-opt-out&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; for further details.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Long-term Resolution&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN&gt;To take full advantage of MANA hardware and Azure Boost performance benefits without degradation, Palo Alto Networks recommends:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Upgrading to PAN-OS 12.1.5 or higher&lt;/STRONG&gt;&lt;SPAN&gt;, which includes native support for MANA NICs via optimized DPDK drivers.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Wed, 18 Mar 2026 23:45:06 GMT</pubDate>
    <dc:creator>vsivetskiy</dc:creator>
    <dc:date>2026-03-18T23:45:06Z</dc:date>
    <item>
      <title>CUSTOMER ADVISORY: Required Action for Azure hosted VM-Series &amp; AIRS Instances</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/customer-advisory-required-action-for-azure-hosted-vm-series-amp/m-p/1250475#M2444</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Subject:&lt;/STRONG&gt;&lt;SPAN&gt; Mechanism to prevent pairing to Microsoft Azure Network Adapter (MANA) for VM-Series and AIRS Firewalls to avoid throughput degradation.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Overview&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&lt;A href="https://techcommunity.microsoft.com/blog/azureinfrastructureblog/announcing-microsoft-azure-network-adapter-mana-support-for-existing-vm-skus/4493279" target="_blank"&gt;&lt;SPAN&gt;Microsoft is rolling out the new &lt;/SPAN&gt;&lt;STRONG&gt;Microsoft Azure Network Adapter (MANA)&lt;/STRONG&gt;&lt;/A&gt;&lt;SPAN&gt; hardware across existing Azure VM sizes families. While MANA is designed to enhance performance for modern workloads, certain versions of the Palo Alto Networks VM-Series firewall are not yet fully optimized for this hardware.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;The Issue&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN&gt;On all &lt;/SPAN&gt;&lt;STRONG&gt;PAN-OS versions below 12.1.5&lt;/STRONG&gt;&lt;SPAN&gt;, if VM-Series instances are paired with MANA NICs the instance will default to the &lt;/SPAN&gt;&lt;STRONG&gt;mmap synthetic path&lt;/STRONG&gt;&lt;SPAN&gt; rather than the high-performance &lt;/SPAN&gt;&lt;STRONG&gt;DPDK (Data Plane Development Kit)&lt;/STRONG&gt;&lt;SPAN&gt; driver. This pairing can occur to any VMs that are stop-deallocated and restarted or redeployed.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Critical Impact:&lt;/STRONG&gt;&lt;SPAN&gt; This fallback can result in a &lt;/SPAN&gt;&lt;STRONG&gt;50% or greater reduction&lt;/STRONG&gt;&lt;SPAN&gt; in maximum firewall throughput, significantly impacting the performance of your security infrastructure.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Affected Configurations&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Platform:&lt;/STRONG&gt;&lt;SPAN&gt; Azure VM-Series and AIRS (AI Runtime Security) instances.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Software:&lt;/STRONG&gt;&lt;SPAN&gt; Any PAN-OS version &lt;/SPAN&gt;&lt;STRONG&gt;lesser than 12.1.5&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Hardware:&lt;/STRONG&gt;&lt;SPAN&gt; Any instance recently migrated by Azure to MANA-capable hardware (typically indicated by the presence of a MANA Virtual Function in the guest OS).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;&lt;STRONG&gt;Required Action&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN&gt;To maintain current performance levels and prevent an automatic transition to the synthetic path for stop-deallocated and restarted or redeployed VMs, customers on affected versions must &lt;/SPAN&gt;&lt;STRONG&gt;opt-out&lt;/STRONG&gt;&lt;SPAN&gt; of MANA NIC eligibility for their instances. Please refer to FAQs provided by Microsoft &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/virtual-network/accelerated-networking-mana-network-virtual-appliance-opt-out" target="_blank"&gt;&lt;SPAN&gt;https://learn.microsoft.com/en-us/azure/virtual-network/accelerated-networking-mana-network-virtual-appliance-opt-out&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; for further details.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Long-term Resolution&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN&gt;To take full advantage of MANA hardware and Azure Boost performance benefits without degradation, Palo Alto Networks recommends:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Upgrading to PAN-OS 12.1.5 or higher&lt;/STRONG&gt;&lt;SPAN&gt;, which includes native support for MANA NICs via optimized DPDK drivers.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 18 Mar 2026 23:45:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/customer-advisory-required-action-for-azure-hosted-vm-series-amp/m-p/1250475#M2444</guid>
      <dc:creator>vsivetskiy</dc:creator>
      <dc:date>2026-03-18T23:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: CUSTOMER ADVISORY: Required Action for Azure hosted VM-Series &amp; AIRS Instances</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/customer-advisory-required-action-for-azure-hosted-vm-series-amp/m-p/1250738#M2445</link>
      <description>&lt;P&gt;will this affect VM Panoramas and VM Log Collectors on Azure as well? If not, why only the VM Firewalls. I have a customer that uses Azure and these two questions will be asked.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2026 17:55:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/customer-advisory-required-action-for-azure-hosted-vm-series-amp/m-p/1250738#M2445</guid>
      <dc:creator>zahmed01</dc:creator>
      <dc:date>2026-03-23T17:55:14Z</dc:date>
    </item>
    <item>
      <title>Re: CUSTOMER ADVISORY: Required Action for Azure hosted VM-Series &amp; AIRS Instances</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/customer-advisory-required-action-for-azure-hosted-vm-series-amp/m-p/1250827#M2446</link>
      <description>&lt;P&gt;Do you use accelerated networking on the VM Panoramas and VM Log Collectors? If not, then those VMs wouldn't/shouldn't be in-scope from my understanding of this situation. That's my scenario at least. We only enable accelerated networking on our firewall data interface(s).&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2026 13:33:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/customer-advisory-required-action-for-azure-hosted-vm-series-amp/m-p/1250827#M2446</guid>
      <dc:creator>BenNikkel</dc:creator>
      <dc:date>2026-03-24T13:33:02Z</dc:date>
    </item>
    <item>
      <title>Re: CUSTOMER ADVISORY: Required Action for Azure hosted VM-Series &amp; AIRS Instances</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/customer-advisory-required-action-for-azure-hosted-vm-series-amp/m-p/1250841#M2447</link>
      <description>&lt;P&gt;For those of you out there waiting for the 12.1 track to become a preferred track, you should pay close attention to the Microsoft article linked in the original post. Specifically, the fact that the tag opting out will only be recognized until the end of September 2026.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"&lt;SPAN&gt;The tag will be usable until the end of September 2026. After this time, the systems will be updated to ignore the tag, allowing the NVAs to be deployed on MANA-enabled hardware."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="tinyMceEditor_14ab8bd3190348Mrhall_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2026 18:34:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/customer-advisory-required-action-for-azure-hosted-vm-series-amp/m-p/1250841#M2447</guid>
      <dc:creator>Mrhall</dc:creator>
      <dc:date>2026-03-24T18:34:31Z</dc:date>
    </item>
    <item>
      <title>Re: CUSTOMER ADVISORY: Required Action for Azure hosted VM-Series &amp; AIRS Instances</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/customer-advisory-required-action-for-azure-hosted-vm-series-amp/m-p/1252189#M2449</link>
      <description>&lt;P&gt;For me did not work it. I'm with 12.1.5 and when I associated/map the NIC to the interfaces and restarting VM for take the changes, the VM did not upload and some reboots were launched automatically in loop&amp;nbsp; until the Maintance mode menu appears on cli console. When we unassigned NICs in azure and restarted VM, it works.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I cannot find the solution.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2026 03:42:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/customer-advisory-required-action-for-azure-hosted-vm-series-amp/m-p/1252189#M2449</guid>
      <dc:creator>ePANGMS</dc:creator>
      <dc:date>2026-04-15T03:42:22Z</dc:date>
    </item>
    <item>
      <title>Re: CUSTOMER ADVISORY: Required Action for Azure hosted VM-Series &amp; AIRS Instances</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/customer-advisory-required-action-for-azure-hosted-vm-series-amp/m-p/1252232#M2450</link>
      <description>&lt;P&gt;Could you please create TAC ticket for this, we'd like to investigate.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2026 15:13:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/customer-advisory-required-action-for-azure-hosted-vm-series-amp/m-p/1252232#M2450</guid>
      <dc:creator>vsivetskiy</dc:creator>
      <dc:date>2026-04-15T15:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: CUSTOMER ADVISORY: Required Action for Azure hosted VM-Series &amp; AIRS Instances</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/customer-advisory-required-action-for-azure-hosted-vm-series-amp/m-p/1252815#M2451</link>
      <description>&lt;P&gt;During our weekly call with PAN this week I was informed that Microsoft has no longer made Sep 2026 the deadline. Have you heard the same?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2026 23:05:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/customer-advisory-required-action-for-azure-hosted-vm-series-amp/m-p/1252815#M2451</guid>
      <dc:creator>BenNikkel</dc:creator>
      <dc:date>2026-04-22T23:05:30Z</dc:date>
    </item>
  </channel>
</rss>

