Feature Request List

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

Feature Request List

L7 Applicator

Hi community


In a lot of topics there are discussions and questions about PAN-OS enhancements and missing (not yet implemented) features. So far the PaloAlto Feature Request list isn't available to the public but in a lot of these existing topics feature request IDs (FR ID) are mentionned. Even knowing that PAN-OS is already a feature rich firewall operating system, there is always room for improvement, so I thought it might be helpful for others (and myself) to collect these existing public available FR IDs and summarize them in one topic.


ID Description Additional Information/Workaround Implemented in
130 Filter Logs by Adress Groups - -
204 Automatic rollback to last "good" configuration - -
241 SMTP authentication in Email server profile - -
339 Add negate function to all security policy columns    
776 increase custom report limit beyound Top 500 Also in FR ID 1636 and 1693 -
889 Mac Address as match criteria in security policy - -
913 Preview response pages directly in the WebUI without having to download them - -
919 Support for ICAP (Internet Content Adaption Protocol) - -
986 Custom Reports for System logs - -
1172 Ignore usergroup from User-ID - -
1225 Participation of PA firewalls in Spannin Tree - -
1370 URL column length limit in Reports - -
1696 Include Interface IP in SNMP MIB - -
2153 Terminal Server Agent for Linux - -
2287 Different ACLs for https, snmp, ... - -
2666 VRRP Support for clusters between PA and other devices - -
2924 Optain Global Protect IP from DHCP Server - -
3051 User Activity Report Enhancement (detailed web-browsing statistics including time spent) - -
3060 DHCPv6 client support - -
3495 Custom reports for system Logs - -
3591 /31 subnetmask support for HA1 link - -
4035 Dedicated Log category for Global Protect - -
4443 Support for USB modems (3G/4G/5G ...) - -
4454 gray out policies with expired schedules - -
4507 Show current interface bandwidth in a dashboard widget and log over time. - Not a dashboard widget but throughbut statistics and other device health metrics are implemented in PAN-OS 8.1
4603 Concurrent GP VPN session limit per User - -
4669 Generate system log upon schedule end - -
4670 Proactive notification for policies with soon expiring scheduled - -
4788 Block emails based on domains in "to", "cc" or "bcc", also log these in addition to only "to" and reply with smtp 541 when blocked - -
4920 Display SFP, SFP+ and QSFP serial number - -
5000 SCEP Server integrated in the firewall - -
5078 per-IP Traffic shaping - -
5357 Global Protect Agent Uninstall Password - -
5612 Automatically disable and remove policies with expired schedules - -
5678 Log the TLS version of websites and enable reporting about this - -
5686 DHCP Client Class-ID Setting - -
5844 BGP SNMP monitorings - -
6186 Log and report search keywords - -
6548 Customizable SMTP Response for Vulnerability Protection - -
6609 Add "Threat Email" to email subject when something malicious was detected and also log "cc" and "bcc" - -
7365 DHCPv6 Server support - -
7654 Support of DIPP with non-strict recognition by devices (Cisco ASA like) - -
7832 User-ID for Azure-AD authenticated users - -
9113 Integrated addressobjects for well-known cloud services - -
9195 OCSP stapling support for inbound decryption - -
9285 Custom configrable MFA integration - -
9509 DoH (DNS over HTTPS)/DoT (DNS over TLS) Support for DNS Sinkhole Feature - -
9522 App-ID for DoH (DNS over HTTPS) / DoT (DNS over TLS) Custom App-ID for DoH -
9563 Configurable Time when Global Protect Captive Portal Notification should be shown Captive Portal Notification Delay GlobalProtect 4.1
9958 Azure Information Protection (AIP) Tag support for Data Filtering Release Notes Content Version 8129 PAN-OS 8.0 starting with Content Update 8129
10173 Automatically open browser when Global Protects a Captive Portal and opens a configurable website Automatically Launch Webpage in Default Browser Upon Captive Portal Detection Global Protect 5.0.4 starting with Content Update 8181
10931 use logd disk space (33%) for elasric search in Panorama Panorama disk space allocation -
11012 Windows Server 2019 Support for User-ID Agent - User-ID Agent/PAN-OS 9.0.2
11153 Completely remove Global Protect 4.0 Design out of Global Protect 5+ - -
11211 Forced Global Protect network rediscover after IP change - -
11251 Panorama High Availability: MFA using SAML (Okta) - -
11524 Use FIB for route monitoring instead of gateway of the route itself - -
11763 Include the username in the csv with the URL logs when running a user activity report Download thelogs directly from the URL logs -
11764 Allow for more "User Activity Report" customization - pie charts, different bar charts, color, tables, etc. - -
11765 WebUI Color/Theme changes (Dark mode) already possible with some browser extensions (or maybe even directly in the browser) by modifying the css -
12264 Reporting based on HIP match failures, specially which failed items - -
12783 Log E-Mail links forwarded to Wildfire - -
13046 Support gMSA accounts for User-IP-Mappings - -
13414 Negate source User - -
15246 Import/Export ACC and Dashboard Widgets. - -


So far I found a few and I'll try to update this topic regularly. If you also know about existing requests, please write them here.




134 REPLIES 134

L0 Member

Can Partners vote for Feature Requests?

If I'm not wrong, you SE can only vote. You will need to request them.

L0 Member

#2689, Suppress Warnings in Commit.

L0 Member

The ability to use a BGP ASN in Addresses and/or Address Groups.


Instead of adding all addresses from the ASN manually to an address group, It would be awesome to add the BGP ASN and all addresses from that ASN are added to a dynamic list. This would obviously require a query to a BGP lookup site (assuming Palo Alto would use their own) but would make rule management far easier. Especially for cloud services for example.


Feature Request# 17279


Do you have an FR number for this request? If not, reach out to your SE and have them put it together, or check if one already exists, and post it here once you know what it is. That way others can add their vote to it if it's something they find would be a useful addition to the platform (and it would be, at least IMHO). 

Hey @Remo ,


I just found that there was FR2729 - pull groups from Radius.

Ref - https://live.paloaltonetworks.com/t5/general-topics/how-to-use-quot-retrieve-user-group-quot-feature...


Not sure if it is still active.

Thanks again, just got a response with FR# 17279

L0 Member

Two requests.  


1.  Add ability to put a time limit on a Security Policy.   Use Case:  Allowing a specific user the ability to use say SMS but only for X time then the rule disables automatically for security. 


2. Add ability to click a record in the traffic logs and then add that to the security policies.  For example, X traffic was blocked by Y rule.  I right click on the record in the logs shown on the Monitor tab, select "add to security rules" and Palo Alto creates the inverse of the block.  

L0 Member



I work at huge palo alto infrastrucutres, most of them using Panorama. I would like to see the Routing Table Information ("More Runtime Stats") and the VPN Tunnel Interface Status (Up/Down for Phase1 and Phase2) at the Panorama GUI.


At the moment I need to do a context switch to every single location to gather these information, only if there is an monitoring system at the customer site, then I can use SNMP. 


Where can I lead this subject as a feature request? 


Kind regards

Philipp Raabe


L1 Bithead

Hello Team.

Can you add Feature Request ID: 11882 ? --> "allow HTTP partial response for a specific application or ip" option, as it is discouraged and is a global setting.


Thank you so much


Kinds regards

Yes, i totally agree. Trend Micro does it with a voting feature.

L0 Member

FR ID 12468 - lsvpn with dual ISP setup for redundancy.

L0 Member

Please oh please add colour schemes and tone down the login screens.


We've recently upgraded Panorama from 9.1 to 10.1 and it actually hurts to log in, especially after being woken up at 2AM on-call to investigate an issue. 


My colleagues have declared the current colour scheme as baby poo yellow and thoroughly dislike it. Because I'm the administrator, I get the full force of their feelings 😭



L2 Linker

Allow Threat exceptions to change the severity of the threat as well as the action so that we can choose to reset-both / drop / or block IP etc, AND change the severity level so that it doesn't email if our log fowarding level is set to only send high's or critical's. I'm getting tired of netgear and gpon threat critical warnings when I don't have a netgear or gpon router.

--Why so many drops! Firewall stop telling me I made the rule wrong and tell me how to fix it 😛


You'll need to actually submit feature requests through your SE so they can add your vote to an existing FR or create a new FR for you. Once you have that number and add it to your comment, others who also want the feature will now what FR # to site if they would like to add their vote to the request.

As for the log forwarding level, you could always change the filter so that these threats are excluded when they are detected so the system doesn't process them. That would at least provide you some reprieve. 

  • 134 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!