February VM-Series and CN-Series Updates

Showing results for 
Show  only  | Search instead for 
Did you mean: 
L3 Networker

We’ve made February a month of more flexibility — flexibility to do things your way so you can meet your organization’s unique security needs. That’s why this month’s edition of our software firewall update starts with news about the just-announced flexible consumption model, which is designed to enable you to rapidly scale as needed through credit-based licensing. 


You’ll also learn how new features in our CN-Series container firewall make protecting Kubernetes environments easier and you’ll discover new CloudFormation Templates for VM-Series firewall integrations with the AWS Gateway Load Balancer (GWLB). Plus you’ll see how to keep VM-Series firewalls humming along in Azure and find ways to scale your security in Cisco ACI environments.


Leverage the Industry’s Most Flexible Software NGFW Consumption Model

The industry’s most comprehensive and flexible firewall licensing and consumption model is here. Now you can easily size, procure, and scale software-based firewalls in response to your immediate needs instead of based on projected requirements. 

  • Simply purchase Software NGFW Credits and consume Palo Alto Networks firewall-as-a-platform components: VM-Series virtual firewalls, CN-Series container firewalls, all of our current and future Security subscriptions, virtual Panorama appliances for management, and, of course, log collection.


Here’s how easy it is to customize the capabilities of your software firewalls in minutes:

Screen Shot 2021-02-18 at 10.00.29 AM.png


  • Read our announcement blog to discover more about this new way to consume software firewalls and also get more details in this solution brief.
  • Be sure to check out the End-of-Sale and End-of-Support announcement for the current VM-Series firewalls so that you can plan for adoption of Software NGFW Credits moving forward.
  • Register today for our flexible consumption webinar scheduled for Wednesday February 24, 2021 at 10:00 AM PST to find out how you can deploy cloud network security in just minutes. 


Get the Latest CN-Series Firewalls for More Container Flexibility

Flexibility goes beyond procurement. That’s why we continue to enhance the industry’s first next-generation firewall for Kubernetes with features vital for securing containerized environments with ease and efficiency:

  • 5G VLAN Tagging Support—Tagging VLAN traffic is now supported when you use the Multus container network interface (CNI) plugin. This feature is available beginning in PAN-OS 10.0.4.
  • Kubernetes Plugin 1.0.2 Keeps Nodes Licensed—The Panorama Plugin for Kubernetes 1.0.2 is here. This maintenance release fixes an issue that prevented firewall nodes from being licensed after cluster creation. This plugin is available beginning in PAN-OS 10.0.4. Make sure to review the compatibility requirements in the Plugin Compatibility Matrix before you install this plugin.
  • Make the Most of Kubernetes 1.18 GKE Qualification—Customers using Google Kubernetes Engine (GKE) can now use CN-Series firewalls in Kubernetes 1.18 environments. This feature is available beginning in PAN-OS 10.0.


Leverage AWS GWLB CloudFormation Template Enhancements

You can extend the number of AZs for your firewalls from two to four and implement NAT gateway support for VM-Series firewall management. Use community-supported CloudFormation Templates published on GitHub for customizing your AWS Gateway Load Balancer (GWLB) integration with VM-Series firewalls. 


Keep Accelerated Networking in Azure Humming with VM-Series Plugin 2.0.4

You’ll want to take a look at this latest release to ensure agility in Azure. Now you can deploy a VM-Series firewall on Azure with accelerated networking enabled on an F32s_v2 instance (32 vCPUs, 64 GB memory) Additionally, the instance will boot up in DPDK mode if you enable jumbo frame support. Get the details about VM-Series Plugin 2.0.4 here.


Discover More Scalability with this Panorama Plugin for Cisco ACI

The Panorama Plugin for Cisco ACI 2.0.1 introduces enhancements and fixes for known issues that address critical scaling needs. This plugin is available beginning in Panorama 9.0 but make sure you review the compatibility requirements in the Plugin Compatibility Matrix before you install this plugin.


Stay Caught Up with VM-Series and CN-Series Firewall Technical News

Did you catch our January update? It’s worth taking a look to see how we kicked off the new year by making firewall deployments in public clouds faster, simpler, and more efficient. You’ll find several exciting developments about VM-Series firewalls in Azure, as well as in Alibaba and Oracle Cloud. Plus, get the latest on VMware NSX certifications, find news about Aryaka partner qualification, and more.



  • 324 Subscriptions
Register or Sign-in