Best Practice Assessment Release Notes

Here you will find content that will no longer be featured across LIVEcommunity. Although the content will soon be retired, it may still be relevant for your needs. For the most accurate and updated information on BPA, please visit the AIOps for NGFW articles.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
About Best Practice Assessment Release Notes

Here you will find content that will no longer be featured across LIVEcommunity. Although the content will soon be retired, it may still be relevant for your needs. For the most accurate and updated information on BPA, please visit the AIOps for NGFW articles.

New Ransomware URL Filtering Category   Starting September 27, 2022, Palo Alto Networks started to publish URLs into the newly introduced category “Ransomware” available with content release version 8592 and above.   Action: (If the content release version is 8592 and above) Ransomware category “Site Access” action set to “block” only for the default profile. If customer has multiple URL Filtering security profiles, they will need to update “Site Access” action to “BLOCK” for each profiles. This applies to all versions of PAN-OS software.   More information can be found at New Advanced URL Filtering/PANDB Category: Ransomware   This new category was added in BPA version 7.3.0
View full article
 BPA Release Notes (Version 6.4.0)   Starting BPA Version 6.0.0 Prisma Access BPA report will provide Health Check information about your Prisma Access. Health checks are essential in establishing a solid foundation upon which cybersecurity infrastructure is built, it will help to identify weakest security areas, and will also recommend the best practice actions to mitigate any potential risks.   The Service Health option under Best Practice Assessment tab will provide you with the detailed information about each health check and the necessary actions that are required to pass each one of them.    Figure 1: Service Health under Best Practice Assessment To learn more about health checks in Prisma Access BPA report please click here   Health Checks added to BPA in BPA V6.4.0 Category Health Checks Security  UserID Remote Network Redistribution UserID Agent from On-Prem  Mobile Users Authentication SAML Connectivity Mobile Users Authentication Sequence       Review the latest Known Issues Severity Description S2 HTML Report > Deployment Type missing from Mapping Definitions: Deployment Type showing as undefined, whereas it should actually show the correct mapping definitions S2 - Major Action on DNS Queries for DNS Sinkhole is not set to “sinkhole” and still passes S3 - Minor Reloading the HTML Report will repeatedly show New Features pop up S3 - Minor SNMP tab text not matching main screen text Enhancement Distinguish between authentication profile and profiles and authentication sequence and sequences for better user experience S3-Minor Device management license should have the same SN as host SN S3 - Minor Target Device is being set as none instead of the serial number of the device S3 - Minor Filter is capitalization sensitive - The local filters are capitalization sensitive when typing in a search query. The filter should be able to take in both capitalized words and non capitalized words. Review the Addressed Issues from the last release Severity Description S3-Minor Authentication tab text not matching main screen text S2-Major Change to ECMP Load Balancing tag in 10.1 caused issue processing TSF file S1-Critical Error while running BPA Report for Prisma Access. Authentication Cookie timeout is not set for customer S3-Minor Batch license info shows empty even if there are batch licenses. S2-Major When we generate a BPA report for strata we need to exclude any PA HC. S3-Minor Global Protect Checks fails due to incorrect SAML flag S3-Minor BPA API HTML Issue which prevented downloading and viewing a report offline For BPA support, please contact us at bpa@paloaltonetworks.com   Resources   How to generate a Prisma Access BPA Report How to Generate a BPA Report Health Check Demo Video BPA Solution Brief  Best Practice Assessment (BPA) Tool LIVEcommunity Page   Configuration Wizard Demos Best Practice Assessment Plus (BPA+) Overview Video Best Practice Assessment Video Playlist  
View full article
 BPA Release Notes (Version 6.3.0)   Starting BPA Version 6.0.0 Prisma Access BPA report will provide Health Check information about your Prisma Access. Health checks are essential in establishing a solid foundation upon which cybersecurity infrastructure is built, it will help to identify weakest security areas, and will also recommend the best practice actions to mitigate any potential risks.   The Service Health option under Best Practice Assessment tab will provide you with the detailed information about each health check and the necessary actions that are required to pass each one of them.    Figure 1: Service Health under Best Practice Assessment To learn more about health checks in Prisma Access BPA report please click here Health Checks added to BPA in BPA V6.3.0   Category Health Checks Security Mobile Users Policy Security Policy zones untrust Remote Network Policy Security Policy zones untrust Mobile Users Security Policy UserID Mobile Users Policy Security Policy Sensitive Traffic Remote Network Policy Security Policy Sensitive Traffic  Infrastructure Mobile User Deployment Service Connection Presence Mobile Users Gateway Regions Mobile User Deployment IP Pool Allocation Mobile Users Onboarding Prisma Access Subnet Service Connection Onboarding Prisma Access Service Subnet Connectivity QoS Remote Network     Review the latest Known Issues Severity Description S2 HTML Report > Deployment Type missing from Mapping Definitions. Deployment Type showing as undefined, whereas it should actually show the correct mapping definitions. S2 - Major Action on DNS Queries for DNS Sinkhole is not set to “sinkhole” and still passes S3 - Minor Reloading the HTML Report will repeatedly show New Features pop up S3-Minor Authentication tab text not matching main screen text S3 - Minor SNMP tab text not matching main screen text S3-Minor Device management license should have the same SN as host SN S3 - Minor Target Device is being set as none instead of the serial number of the device S3 - Minor The local filters are capitalization sensitive when typing in a search query. The filter should be able to take in both capitalized words and non capitalized words.    Review the Addressed Issues from the last release Severity Description S2 Error After Uploading TSF to CSS S3-Minor Batch license info showing empty S1 Error while running BPA Report for Prisma Access. Authentication Cookie timeout is not set for customer S2 Report generation is failing for strata  S3 Global Protect Checks fails For BPA support, please contact us at bpa@paloaltonetworks.com Resources   How to generate a Prisma Access BPA Report How to Generate a BPA Report Health Check Demo Video BPA Solution Brief  Best Practice Assessment (BPA) Tool LIVEcommunity Page Configuration Wizard Demos Best Practice Assessment Plus (BPA+) Overview Video Best Practice Assessment Video Playlist  
View full article
BPA Release Notes (Version 6.2.0) Starting BPA Version 6.0.0 Prisma Access BPA report will provide Health Check information about your Prisma Access. Health checks are essential in establishing a solid foundation upon which cybersecurity infrastructure is built, it will help to identify weakest security areas, and will also recommend the best practice actions to mitigate any potential risks.   The Service Health option under Best Practice Assessment tab will provide you with the detailed information about each health check and the necessary actions that are required to pass each one of them.  Figure 1: Service Health under Best Practice Assessment   To learn more about health checks in Prisma Access BPA report please click here Health Checks added to BPA in BPA V6.2.0   Category Health Checks Security MU_Security_Policy_zones RN_Security_Policy_zones UserID_MU_Groupmapping_include_list UserID_RN_Groupmapping_include_list RN_Security_Policy_userid MU_Security_Policy_userid MU_Cookie_Lifetime Connectivity RN_Routing_overlapping_subnets MU_VPN_Protocol MU_APP_Connection_Timers MU_Authentication_LDAP_Bindtime     Review the latest Known Issues Severity Description S2 Error After Uploading TSF to Customer Success Site and Customer Support Portal S2 Under HMTL report "Deployment Type" missing from the Mapping Definitions S2 Action on DNS Queries for DNS Sinkhole is not set to “sinkhole” still passes S3 Reloading the HTML report will repeatedly show New Features pop up S3 Batch license info showing empty S3 Authentication tab text not matching main screen text     For BPA support, please contact us at bpa@paloaltonetworks.com   Resources How to generate a Prisma Access BPA Report How to Generate a BPA Report Health Check Demo Video BPA Solution Brief  Best Practice Assessment (BPA) Tool LIVEcommunity Page   Configuration Wizard Demos Best Practice Assessment Plus (BPA+) Overview Video Best Practice Assessment Video Playlist
View full article
Starting BPA Version 6.0.0 Prisma Access BPA report will provide Health Check information about your Prisma Access. Health checks are essential in establishing a solid foundation upon which cybersecurity infrastructure is built, it will help to identify weakest security areas, and will also recommend the best practice actions to mitigate any potential risks.   The Service Health option under Best Practice Assessment tab will provide you with the detailed information about each health check and the necessary actions that are required to pass each one of them.    Figure 1: Service Health under Best Practice Assessment   To learn more about health checks in Prisma Access BPA report please click here   Health Checks added to BPA in BPA V6.1.2   Category Health Checks Security MU_Log_Forwarding_Policy RN_Log_Forwarding_Policy RN_Log_Forwarding_Profile MU_APP_Invalid_Portal_Cert MU_Authentication_LDAP_SSL Connectivity SC_VPN_Monitoring_Dead_peer_all_enable SC_VPN_Monitoring_Tunnel_BGP RN_VPN_Monitoring_Tunnel_BGP SC_VPN_Monitoring_Tunnel_all_enable MU_App_Pre_Logon_Tunnel_Rename_Timeout MU_APP_Disable_GlobalProtect_App MU_App_TCP_Connection_Timeout MU_App_Portal_Connection_Timeout MU_App_Preserve_Tunnel_on_User_Logoff_Timeout Review the latest Known Issues Severity Description S2 HMTL Report > Deployment Type missing from Mapping Definitions  S2 Action on DNS Queries for DNS Sinkhole is not set to “sinkhole” still passes S3 Reloading the HTML Report will repeatedly show New Features pop up For BPA support, please contact us at bpa@paloaltonetworks.com     Resources   How to generate a Prisma Access BPA Report How to Generate a BPA Report Health Check Demo Video BPA Solution Brief  Best Practice Assessment (BPA) Tool LIVEcommunity Page   Configuration Wizard Demos Configuration Wizard Overview Video Best Practice Assessment Video Playlist
View full article
BPA Release Notes (Version 6.0.0)     New Feature   Prisma Access BPA report will provide Health Check information about your Prisma Access. Health checks become essential in establishing a solid foundation upon which cybersecurity infrastructure is built, it will help to identify weakest security areas, and will also recommend the best practice actions to mitigate any potential risks.   The Service Health option under Best Practice Assessment tab will provide you with the detailed information about each health check and the necessary actions that are required to pass each one of them.      Figure 1: Service Health under Best Practice Assessment To learn more about health checks in Prisma Access BPA report please click here Review the latest Known Issues Severity Description S2 - Major Action on DNS Queries for DNS Sinkhole is not set to “sinkhole” still passes. S3 - Minor Reloading the HTML Report will repeatedly show New Features pop up. For BPA support, please contact us at bpa@paloaltonetworks.com Resources   How to generate a Prisma Access BPA Report How to Generate a BPA Report BPA Solution Brief  Best Practice Assessment (BPA) Tool LIVEcommunity Page   BPA+ (Configuration Wizard) Demos Best Practice Assessment Plus (BPA+) Overview Video Best Practice Assessment Video Playlist  
View full article
BPA Release Notes v5.10.1   Bugs Unexpected Error when Uploading Tech Support File Addressed an error that occasionally occurs when uploading a Tech Support File to the Customer Support Portal and Customer Success Portal, preventing the completion of the BPA generation process Improvements Refinement of Best Practice Checks for NGFW’s Managed by Panorama For a BPA generated from a NGFW managed by a Panorama the checks under Dynamic Updates will no longer fail. Instead it will be marked as “Note” since these can be configured at the Panorama level.   New Features New Best Practice Check for ‘Dynamic Filtering’ in ‘URL Filtering Profiles’ Under Objects > Security Profiles > URL Filtering, any Engine under the Dynamic Classification tab of a URL Filtering Profile must be set to “Block” in order to pass the Best Practice Check “URL Profile ML Action.” Please note that this Best Practice check only applies to PAN-OS versions 10.0 and greater.       
View full article
BPA Release Notes v5.9.0   Bugs Skip the Best Practice checks for “Failed Attempts” and “Lockout Time” on SAML Authentication Profiles and Authentication Sequences BP Checks for only SAML Authentication Profiles. When a user selected a SAML Authentication Profile under the Device tab, they were not given an option in GUI to configure “Lockout Time” and “Failed Attempts.”  “Lockout Time” and “Failed Attempts” Best Practice checks for SAML Authentication Profiles will now be skipped. If multiple types of Authentication Profiles exist in addition to SAML, then all Authentication types will be processed except for SAML.     Inaccurately calculating the adoption of DNS Sinkhole and URL Filtering in the Heatmap section. When a user has a URL Filtering and DNS Sinkhole configured in a Security policy, adoptions were being miscalculated and the Rule Detail tab in the Best Practice Assessment shows them as disabled. Application Filters and Application Groups that were previously ignored are now accounted for. 
View full article
  BPA Release Notes v5.2   Bugs 'IPSec Crypto Profile Encryption' check update  When a user selects GCM Encryption algorithm on IPSec crypto profiles as it inherently has Authentication capability too we would not fail if Authentication algorithm is not defined.   Improvements Added file size units for Wildfire file types  Wildfire File size units are added to understand the scope of file that needs sandbox. Wildfire File Types and its sizes   Update on 'Server Monitoring' BP check  Under User ID feature we were processing server monitors redundancy under 'server monitoring' section only. Now we also factor User ID agents configured in addition to Server Monitoring section. As far as there are 2 methods of obtaining User ID information as redundancy the check would pass.   New Feature Added SD-Wan configuration for visibility We have added SD-Wan configuration objects from Policies, Objects and Network Tabs respectively.   SD-WAN Policies Traffic Distribution profile under SD-Wan Link Management SD-WAN Interface Profiles      
View full article
  BPA Release Notes v5.1   Bugs Rule Detail tab Export option not exporting the list properly In the BPA report, "Rule Detail" tab - Export option at the bottom was not exporting all the Security rules. This issue has been fixed and the export captures all the rules.   'Enable Packet Buffer Protection' BP Check failing On 10.0 PanOS versions the best practice check 'Enable Packet Buffer Protection' was failing. This was happening due to change in xpath config and we have updated so this check is processed as expected and provide the correct result.   New Feature Tracking DNS Security as a new capability in Adoption Heatmap We have added a new column for DNS Security feature so a user can validate if the necessary security rules have DNS Security enabled and identify the security gaps.   DNS Security capability in Adoption Heatmaps  
View full article
  BPA Release Notes v4.0   This is a major feature release. Below are the highlights of the release,   Complete UI styleguide redesign aligning with other company products. Front end tech stack has been upgraded for improved performance and scalability. Created almost 200 short videos for each Best Practice Check that is embedded within the BPA HTML report. Developed a new splash page to enable users to learn about any new capabilities within the product. Created a usability improvement by linking different sections with in the BPA report to take customers from the summary graphs to individual checks - this guides the customer focus to the priority improvement areas. The spreadsheet has been updated to not only show the failed checks but also including the passed checks with added column for BPA Verdict. On a Panorama run BPA report, we now can show a Heatmap adoption for selected Device group in relation to their device group hierarchy so that total context is clear and evident.
View full article
  BPA Release Notes v3.36   Bugs Fixed an issue on BP check "PanOS Release Date" PanOS Release date in certain conditions was not being accurately getting the right value and inaccurately reporting the analysis.   Fixed an issue on BP check "Local Admins" Local Admins BP check will validate minimum password complexity check but it was failing for this check. The criteria needed to be updated.   Fixed an issue on BP check "Authentication Profile" Local admin count was not being calculated as expected and the Authentication Profile BP check was failing. This has been corrected and we have added new field for Local Admin user count.    
View full article
  BPA Release Notes v3.35   Bugs Fixed 'Inbound Malicious IP Address' BP Check with Hierarchy An issue was identified that was not taking into account for a security rule configured in the hierarchical device groups and failing.  
View full article
  BPA Release Notes v3.34   Bugs   Intrazone Rule with Action Deny We have fixed this best practice check now. If the Intrazone rule is set with Action=Deny then that security rule is excluded from this check analysis.      
View full article
  BPA Release Notes v3.33   New Features   Improvements on 'Mapping Definitions' section  We have added, a - 'Passing Occurence' column - Now we can know how many number of times a single BP check has been parsed in a configuration and check how many times it has passed out of total occurrences seen in the configuration. b - On mouse over the '?' button we can identify the details on how the calculation is made for Passing %, Previous Passing % and Passing Occurence c - Total - How the total value is derived and its calculation on the filtered results.   Passing Occurence and details on calculation for Passing % and Total values      HTTP/2 Protocol inspection We have added a new check to ensure if customer expecting HTTP/2 protocol traffic then they have the right configuration in place to permit this traffic through the firewall.   'Security Profile Verdict' New filter in 'Rule Detail' Tab Now we can have the ability to filter security rules which have security profiles with pass or fail BP check verdicts. We can export the list of rules to fix them or scope the work.   Security Profile Verdict - Filter in BPA   Bugs   Fixed some text typos in BPA informational section  
View full article
  BPA Release Notes v3.32   Bugs Quic App Deny rule BP check This BP check was failing in a scenario when it was supposed to pass. Needed an update ordering of pre-rulebase, post-rulebase to resolve the issue.   User ID timeout BP check update This BP check was failing due to overwriting of data. This has been fixed and correct configuration value is parsed and BP check verdict is created.   BPA report generation issue There was an encoding issue that needed to be updated that fixed the issue and user could generate the BPA report.  
View full article
Read about the recent BPA Release Notes in v3.31. See what improvements have been made and what bugs have been resolved.
View full article
Read the BPA Release Notes v3.30 and see what's new. Find out if there were any new features or bugs that were addressed in the release notes.
View full article
Review the new BPA Release Notes for v3.27. See how the new features and bug fixes can help you with checking your system for vulnerabilities. 
View full article
Review the improvements and bug fixes for the BPA. See how the fixed BP Mode Summary Graph can help you.
View full article
   BPA Release Notes v3.29   Improvements   Update to NIST Security Controls We have renamed 'Control Category Summary' graph to 'NIST Security Controls' in the BPA Summary report, PDF Executive reports and other places as needed.   Bugs   BPA report bundle generation through API Fixed an error where a large file could not be processed to generate the BPA report bundle through BPA API.    
View full article
Read about the new features in this BPA release notes v3.26, which includes: Filter option added in BPA for Pass/Fail checks.
View full article
Read about the new features, updates, and bug fixes in the BPA Release Notes v3.25.
View full article
Review BPA Release Notes v3.24 to learn about the new features, improvements, and current bug fixes that will help improve the BPA tool experience. 
View full article
Review the BPA release notes for V3.23. Learn how we added managed devices count on the Panorama report and a forwarding decryption check. We also explain some of the bugs that were fixed.
View full article
Review BPA Release Notes for V3.21. Learn about the updates to bug fixes such as updated file blocking profile check, updated Intrazone rule check, and an Xpath evaluation error update.
View full article
View the BPA Release Notes for V3.22. Learn about the added new URL category Grayware part of blocked categories and a check for DNS Security License. We also corrected a bug about parsing accurately.
View full article
  New Features   Number of Managed Devices on Panorama Now we can start tracking how many firewalls are being managed by the Panorama. At times, our adoption percentage values may change due to addition/removal of firewalls, and having the ability to know a change in the managed devices helps explain the change in adoption values.   BPA tracking columns for firewalls managed by Panorama.   New link added in CIS Critical Security Controls The second link that is added helps map CIS Critical Security Controls to other security controls and frameworks.   CIS Critical Security Controls 7.0 Summary with a highlighted section for a link to frameworks and standards information.   Class Summary Documentation Added the Class Summary reference to Control Category   Class Summary reference in Control Category   Bug Fixes Wildfire Profile File Types: Fixed a bug on Wildfire profile if customer defined specific file types then validate if all the relevant file types are defined to ensure all zero-day file types are inspected in sandbox.   Failed Attempts: Fixed a bug where Admin user login failed attempt was passing when the value was set at 0. Failed attempt for admin users should be a fixed value in the range 1 - 5   Idle Timeout: Fixed a bug where Admin user Idle timeout was passing when the value was set at 0. Idle timeout for admin users should be a fixed value in the range 1 - 10   Included Networks: Fixed a bug for Included Networks check where it needed an update on the error message and that is updated now.   Interface Management Profile: Fixed a bug where the protocols enabled for Interface management profile are correctly parsed on a Template configuration.   Mapping Definitions Control Category: Fixes a calculation error for Risk Assessment control category under Mapping Definitions  
View full article
v3.19.0 - Released on 9/9/2019   In addition to the enhancements and bug fixes included in this release, the team is hard at work on a major update of the HTML report to be more consistent with the company’s product style guide. Stay tuned for more!   Enhancements Updated check #207 – Credential Theft feature now ensures that business credentials compromising URL categories are set to “Block”   Update logic for WildFire file size checks on PAN-OS < 8.1 to provide a note if the file sizes exceed the recommended value   Added logic to rename "Captive Portal Policy" to "Authentication Policy" if PAN-OS 8.0+   Bug Fixes Updated formula for Zone Protection Profile Adoption calculation to use all enabled rules Fixed a bug with the Rules using Profile % calculations v3.19.1 (Hotfix) - Released on 9/13/2019 Fixed a display issue where Interface Mgmt Network Profiles were missing from the HTML report v3.19.2 (Hotfix) - Released on 9/19/2019 Fixed a bug related to parsing template variables
View full article
v3.18.0 - Released on 8/26/2019 At face value, this release squashes several bugs from our backlog. Behind the scenes, however, we are refactoring the codebase to support a larger re-write of the HTML report. More to follow in future releases!   Bug Fixes Fixed GRE Tunnel Keep Alive default values Fixed location of BPA check #71 – GP Portal Agent Config – App Configurations: Enforce GlobalProtect Connection for Network Access in the HTML report
View full article
  • 34 Posts
  • 236 Subscriptions
Customer Advisories

Your security posture is important to us. If you’re a Palo Alto Networks customer, be sure to login to see the latest critical announcements and updates in our Customer Advisories area.

Learn how to subscribe to and receive email notifications here.

Listen to PANCast

PANCast is a Palo Alto Networks podcast that provides actionable insights to customers, helping you maximize your investment while improving your cybersecurity posture.

Top Contributors