- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
04-07-2018 02:00 PM - last edited on 10-07-2020 08:08 AM by BPry
Hi community
In a lot of topics there are discussions and questions about PAN-OS enhancements and missing (not yet implemented) features. So far the PaloAlto Feature Request list isn't available to the public but in a lot of these existing topics feature request IDs (FR ID) are mentionned. Even knowing that PAN-OS is already a feature rich firewall operating system, there is always room for improvement, so I thought it might be helpful for others (and myself) to collect these existing public available FR IDs and summarize them in one topic.
ID | Description | Additional Information/Workaround | Implemented in |
130 | Filter Logs by Adress Groups | - | - |
204 | Automatic rollback to last "good" configuration | - | - |
241 | SMTP authentication in Email server profile | - | - |
339 | Add negate function to all security policy columns | ||
776 | increase custom report limit beyound Top 500 | Also in FR ID 1636 and 1693 | - |
889 | Mac Address as match criteria in security policy | - | - |
913 | Preview response pages directly in the WebUI without having to download them | - | - |
919 | Support for ICAP (Internet Content Adaption Protocol) | - | - |
986 | Custom Reports for System logs | - | - |
1172 | Ignore usergroup from User-ID | - | - |
1225 | Participation of PA firewalls in Spannin Tree | - | - |
1370 | URL column length limit in Reports | - | - |
1696 | Include Interface IP in SNMP MIB | - | - |
2153 | Terminal Server Agent for Linux | - | - |
2287 | Different ACLs for https, snmp, ... | - | - |
2666 | VRRP Support for clusters between PA and other devices | - | - |
2924 | Optain Global Protect IP from DHCP Server | - | - |
3051 | User Activity Report Enhancement (detailed web-browsing statistics including time spent) | - | - |
3060 | DHCPv6 client support | - | - |
3495 | Custom reports for system Logs | - | - |
3591 | /31 subnetmask support for HA1 link | - | - |
4035 | Dedicated Log category for Global Protect | - | - |
4443 | Support for USB modems (3G/4G/5G ...) | - | - |
4454 | gray out policies with expired schedules | - | - |
4507 | Show current interface bandwidth in a dashboard widget and log over time. | - | Not a dashboard widget but throughbut statistics and other device health metrics are implemented in PAN-OS 8.1 |
4603 | Concurrent GP VPN session limit per User | - | - |
4669 | Generate system log upon schedule end | - | - |
4670 | Proactive notification for policies with soon expiring scheduled | - | - |
4788 | Block emails based on domains in "to", "cc" or "bcc", also log these in addition to only "to" and reply with smtp 541 when blocked | - | - |
4920 | Display SFP, SFP+ and QSFP serial number | - | - |
5000 | SCEP Server integrated in the firewall | - | - |
5078 | per-IP Traffic shaping | - | - |
5357 | Global Protect Agent Uninstall Password | - | - |
5612 | Automatically disable and remove policies with expired schedules | - | - |
5678 | Log the TLS version of websites and enable reporting about this | - | - |
5686 | DHCP Client Class-ID Setting | - | - |
5844 | BGP SNMP monitorings | - | - |
6186 | Log and report search keywords | - | - |
6548 | Customizable SMTP Response for Vulnerability Protection | - | - |
6609 | Add "Threat Email" to email subject when something malicious was detected and also log "cc" and "bcc" | - | - |
7365 | DHCPv6 Server support | - | - |
7654 | Support of DIPP with non-strict recognition by devices (Cisco ASA like) | - | - |
7832 | User-ID for Azure-AD authenticated users | - | - |
9113 | Integrated addressobjects for well-known cloud services | - | - |
9195 | OCSP stapling support for inbound decryption | - | - |
9285 | Custom configrable MFA integration | - | - |
9509 | DoH (DNS over HTTPS)/DoT (DNS over TLS) Support for DNS Sinkhole Feature | - | - |
9522 | App-ID for DoH (DNS over HTTPS) / DoT (DNS over TLS) | Custom App-ID for DoH | - |
9563 | Configurable Time when Global Protect Captive Portal Notification should be shown | Captive Portal Notification Delay | GlobalProtect 4.1 |
9958 | Azure Information Protection (AIP) Tag support for Data Filtering | Release Notes Content Version 8129 | PAN-OS 8.0 starting with Content Update 8129 |
10173 | Automatically open browser when Global Protects a Captive Portal and opens a configurable website | Automatically Launch Webpage in Default Browser Upon Captive Portal Detection | Global Protect 5.0.4 starting with Content Update 8181 |
10931 | use logd disk space (33%) for elasric search in Panorama | Panorama disk space allocation | - |
11012 | Windows Server 2019 Support for User-ID Agent | - | User-ID Agent/PAN-OS 9.0.2 |
11153 | Completely remove Global Protect 4.0 Design out of Global Protect 5+ | - | - |
11211 | Forced Global Protect network rediscover after IP change | - | - |
11251 | Panorama High Availability: MFA using SAML (Okta) | - | - |
11524 | Use FIB for route monitoring instead of gateway of the route itself | - | - |
11763 | Include the username in the csv with the URL logs when running a user activity report | Download thelogs directly from the URL logs | - |
11764 | Allow for more "User Activity Report" customization - pie charts, different bar charts, color, tables, etc. | - | - |
11765 | WebUI Color/Theme changes (Dark mode) | already possible with some browser extensions (or maybe even directly in the browser) by modifying the css | - |
12264 | Reporting based on HIP match failures, specially which failed items | - | - |
12783 | Log E-Mail links forwarded to Wildfire | - | - |
13046 | Support gMSA accounts for User-IP-Mappings | - | - |
13414 | Negate source User | - | - |
15246 | Import/Export ACC and Dashboard Widgets. | - | - |
So far I found a few and I'll try to update this topic regularly. If you also know about existing requests, please write them here.
Regards,
Remo
03-12-2022 07:47 PM
I'd like the ability to run mtr (my traceroute) from my firewalls.
03-22-2022 03:03 AM
This is an amazing initiative! Is this list still up-to-date?
KR,
Kim
05-18-2022 06:01 AM
I'd like to submit a request to add the IP address column to the address-group Export. This will allow an export of each member of the address-group including the IP address of each member.
Thanks,
Travis
05-18-2022 07:03 AM
You'll want to reach out to your SE to actually put in the feature request. Then once you have that FR number from your SE, share it here so that others can add their vote to the FR through their own account team.
05-18-2022 08:17 AM
FR ID: 19916
Export of Address Group to display actual IP Address of Object
05-18-2022 10:48 AM
This is available in the pan-os-php tool. It will give you the group name, whether it is static/dynamic, tags, IPs and members with nested-group members.
05-19-2022 05:13 AM
It didn't bother me that much, but I had some admins that were alarmed at the color. It's still a topic they bring up when we're screen sharing 🙂
05-24-2022 02:13 AM
Would be so nice if there was a way to disable the "Clone" function for admins.
07-19-2022 01:39 PM
We would like to vote for #4603. For IL4/Gov environments this is a requirement, so I would think that it would be pretty important for Palo Alto to support the requirements of these high security environments.
08-26-2022 05:37 AM
I would like to have able to make named rule bundle with expand/collapse button.
08-26-2022 06:23 AM
I would like to delete expired trial license on CSP.
08-31-2022 05:44 AM
Would be nice to check client certificate on HIP profile.
01-25-2023 12:25 PM - edited 01-25-2023 12:26 PM
Add 11765 For Panorama please this bright yellow is killing me every morning
02-15-2023 10:28 AM
Here's my feature request...
It still baffles me that you can configure an SSL/TLS service profile in Panorama to be centrally managed and pushed out to all of your managed firewalls, but in order to reconfigure/disallow weaker keys and ciphers you need to manually override the template on each firewall and make the CLI changes on each firewall.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmqeCAC
The fact that you can't manage this globally within Panorama is a huge shortcoming. Please add this ability in future releases.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!