CUSTOMER ADVISORY: Required Action for Azure hosted VM-Series & AIRS Instances

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

CUSTOMER ADVISORY: Required Action for Azure hosted VM-Series & AIRS Instances

L0 Member

Subject: Mechanism to prevent pairing to Microsoft Azure Network Adapter (MANA) for VM-Series and AIRS Firewalls to avoid throughput degradation.

Overview

Microsoft is rolling out the new Microsoft Azure Network Adapter (MANA) hardware across existing Azure VM sizes families. While MANA is designed to enhance performance for modern workloads, certain versions of the Palo Alto Networks VM-Series firewall are not yet fully optimized for this hardware.

The Issue

On all PAN-OS versions below 12.1.5, if VM-Series instances are paired with MANA NICs the instance will default to the mmap synthetic path rather than the high-performance DPDK (Data Plane Development Kit) driver. This pairing can occur to any VMs that are stop-deallocated and restarted or redeployed.

Critical Impact: This fallback can result in a 50% or greater reduction in maximum firewall throughput, significantly impacting the performance of your security infrastructure.

Affected Configurations

  • Platform: Azure VM-Series and AIRS (AI Runtime Security) instances.
  • Software: Any PAN-OS version lesser than 12.1.5.
  • Hardware: Any instance recently migrated by Azure to MANA-capable hardware (typically indicated by the presence of a MANA Virtual Function in the guest OS).

Required Action

To maintain current performance levels and prevent an automatic transition to the synthetic path for stop-deallocated and restarted or redeployed VMs, customers on affected versions must opt-out of MANA NIC eligibility for their instances. Please refer to FAQs provided by Microsoft https://learn.microsoft.com/en-us/azure/virtual-network/accelerated-networking-mana-network-virtual-... for further details.

Long-term Resolution

To take full advantage of MANA hardware and Azure Boost performance benefits without degradation, Palo Alto Networks recommends:

  • Upgrading to PAN-OS 12.1.5 or higher, which includes native support for MANA NICs via optimized DPDK drivers.
6 REPLIES 6

L2 Linker

will this affect VM Panoramas and VM Log Collectors on Azure as well? If not, why only the VM Firewalls. I have a customer that uses Azure and these two questions will be asked. 

Customer Success Engineer, NGFW

Do you use accelerated networking on the VM Panoramas and VM Log Collectors? If not, then those VMs wouldn't/shouldn't be in-scope from my understanding of this situation. That's my scenario at least. We only enable accelerated networking on our firewall data interface(s).

L0 Member

For those of you out there waiting for the 12.1 track to become a preferred track, you should pay close attention to the Microsoft article linked in the original post. Specifically, the fact that the tag opting out will only be recognized until the end of September 2026. 

 

"The tag will be usable until the end of September 2026. After this time, the systems will be updated to ignore the tag, allowing the NVAs to be deployed on MANA-enabled hardware."

 

 

 

L0 Member

For me did not work it. I'm with 12.1.5 and when I associated/map the NIC to the interfaces and restarting VM for take the changes, the VM did not upload and some reboots were launched automatically in loop  until the Maintance mode menu appears on cli console. When we unassigned NICs in azure and restarted VM, it works. 

I cannot find the solution. 

 

Could you please create TAC ticket for this, we'd like to investigate.

During our weekly call with PAN this week I was informed that Microsoft has no longer made Sep 2026 the deadline. Have you heard the same?

  • 11782 Views
  • 6 replies
  • 2 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!