- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-18-2026 04:45 PM
Subject: Mechanism to prevent pairing to Microsoft Azure Network Adapter (MANA) for VM-Series and AIRS Firewalls to avoid throughput degradation.
Microsoft is rolling out the new Microsoft Azure Network Adapter (MANA) hardware across existing Azure VM sizes families. While MANA is designed to enhance performance for modern workloads, certain versions of the Palo Alto Networks VM-Series firewall are not yet fully optimized for this hardware.
On all PAN-OS versions below 12.1.5, if VM-Series instances are paired with MANA NICs the instance will default to the mmap synthetic path rather than the high-performance DPDK (Data Plane Development Kit) driver. This pairing can occur to any VMs that are stop-deallocated and restarted or redeployed.
Critical Impact: This fallback can result in a 50% or greater reduction in maximum firewall throughput, significantly impacting the performance of your security infrastructure.
To maintain current performance levels and prevent an automatic transition to the synthetic path for stop-deallocated and restarted or redeployed VMs, customers on affected versions must opt-out of MANA NIC eligibility for their instances. Please refer to FAQs provided by Microsoft https://learn.microsoft.com/en-us/azure/virtual-network/accelerated-networking-mana-network-virtual-... for further details.
To take full advantage of MANA hardware and Azure Boost performance benefits without degradation, Palo Alto Networks recommends: