Detection/Remediation of Azure MANA NIC Rollout on VM-Series and Prisma AIRS Firewall and Assessing Its Performance Impact (DPDK/AN Disabled, Reduced Throughput) and MANA opt-out policy.
Symptom
If Firewall end up on MANA hardware and on the version prior to 12.1.7-h2, then DPDK and Accelerated Networking will be turned off by default. This can happen on new VM instance or VM recently stopped/started (deallocated/started) from Azure Portal and landed on MANA NIC enabled Hardware. Reboot from PAN-OS does not trigger MANA NIC roll out.
Here is how you check the settings.
- DPDK disabled.
admin@mana-panvm1> show system setting dpdk-pkt-io Device current Packet I0 mode: Packet MMAP Device DPDK Packet I0 capable: no Device default Packet I0 mode: Packet MMAP - "Acc-Netw" OFF on PA-VM firewall; but Accelerated Networking ON in Azure Portal
admin@mana-panvm1> debug show vm-series interfaces all Interface_name Base-OS_port Base-OS_MAC PCI-ID Driver Acc-Netw mgt eth0 7c:1e:52:dd:a7:a3 hv_netvsc Ethernet1/1 eth1 7c:1e:52:dd:ab:ea f8615163-0001-1000-2000-7c1e52d hv_netvsc OFF Ethernet1/2 eth2 7c:1e:52:dd:a0:cb f8615163-0002-1000-2000-7c1e52d hv_netvsc OFF
To verify if Firewall is on Mana Hardware verify using following command. "less mp-log messages" - Following log seen in messages.log: "vm kernel: [ 83.526249] mana 7870:00:00.0:"
messages.log vm kernel: [ 83.526249] mana 7870:00:00.0: enabling device (0000 -> 0002) vm kernel: [ 83.538169] mana 7870:00:00.0: HWC: Failed hw_channel req: 0xc00000bb vm kernel: [ 83.538170] mana 7870:00:00.0: VfVerifyVersionOutput: -71, status=0xc00000bb vm kernel: [ 83.551127] mana 7870:00:00.0: gdma probe failed: err = -71 vm kernel: [ 83.551142] mana probe of 7870:00:00.0 failed with error -71 - Alternatively you can also use command
pantac@hshahgen2-2> debug show vm-series system platform-info <Output Truncated > Hugetlb: 15376384 kB DirectMap4k: 257152 kB DirectMap2M: 7077888 kB DirectMap1G: 28311552 kB PCI Information: =================== 0db8:00:00.0 Non-Volatile memory controller: Microsoft Corporation Device b111 (rev 01) 7870:00:00.0 Ethernet controller: Microsoft Corporation Device 00ba >>>>>>>>>>>>>>>>>>> Indicates FW is on MANA Hardware c05b:00:00.0 Non-Volatile memory controller: Microsoft Corporation Device 00a9
"7870:00:00.0" is tied to MANA HW, Reference doc: https://learn.microsoft.com/en-us/azure/virtual-network/setup-dpdk-mana
Environment
-
Platform: Microsoft Azure VM-Series and AIRS instances.
-
Software: Any PAN-OS version lower than 12.1.7-h2
- AN and DPDK should be enabled for the FW
Cause
-
Microsoft is rolling out new hardware in the Azure environment codenamed MANA(Microsoft Azure Network Adapter)Azure MANA NICs are only supported with PAN-OS 12.1.7-h2 and above, because of compatibility and stability issue.
Resolution
Workaround1 [Recommended Workaround to stay on 11.x image]:
-
To prevent an automatic transition to MANA for deallocated/restarted or redeployed VMs the customer must add necessary opt-out Azure policy for MANA NIC eligibility in their Azure account.
- Customer can apply opt out policy, as per latest update from MS Azure, the opt-out tag expires on May 2027.
- MS Announcement : https://learn.microsoft.com/en-us/azure/virtual-network/accelerated-networking-mana-network-virtual-appliance-opt-out
- After May 2027 upgrade to >12.1.7-h2 is required because opt-out tag expires on May 2027 and 11.x code is end of life in May 2027
Workaround2
-
- Upgrade to 12.1.7-h2, which is expected to become the recommended release in the 12.1.x train by the end of July.
- In certain scenarios, VM-Series instances running on Azure V2 or V3 instance types may use the CX3 driver. In such cases, the VM can still be affected by the hot-plug(PAN-300025) issue. Therefore, it is recommended to migrate to a V4, V5, or V6 instance type.
Scenario 1: Proactively prevent PAN-OS 11.x Firewall from Landing on MANA-Enabled Hardware
To avoid placement on MANA-enabled hardware, customers can proactively apply an opt-out tag at the VM or VMSS level.
After setting specific VM tag using policy and apply tag from the Azure CLI is required for existing instances to ensure enforcement.
Scenario 2: PAN-OS 11.x Firewall Already Running on MANA-Enabled Hardware
If a firewall is already deployed on MANA NIC-enabled infrastructure, customers can either apply opt out policy(recommended) or upgrade to a supported PAN-OS version.
Opting out involves setting a specific VM tag using policy and apply tag from the Azure CLI to move the instance to non-MANA hardware, once the tag is applied, you must stop and then start the VM from the Azure portal.
Alternatively, upgrading to PAN-OS 12.1.7-h2 or later enables native support for MANA NIC. For stability, migrate VM to newer Azure instance types (V4/V5/V6).
NOTE : As per MS Azure, tags can be applied at any time through May 31, 2027, and will be honored once in place.
NOTE: If Panorama(with one interface) on 12.1.x image is running on a V5 instance type, it may encounter bug PAN-313020, which is scheduled to be resolved in version 12.1.8. As a workaround, please disable AN on the management interface of Panorama; this should allow it to boot successfully.
NOTE : Gen1 image can be upgraded to 12.x. V6 hardware requires a Gen2 image, Gen2 image is available only with 12.x base images.
Additional Information
This article applies to VM-Series and AIRS. Not Azure CNGFW.
FAQs on PAN-OS:
-
PANOS FAQs:
-
Impacted Platforms:
-
VM-Series firewalls deployed in Azure
-
AIRS firewalls in Azure
-
CNGFW on Azure (remediation is being handled by PM team — no customer action required)
-
-
What is the recommended workaround to avoid Azure MANA update on PANW FWs?
-
Apply opt-out policy provided by MS Azure.
-
-
Is PAN-OS 12.1.7-h2 a Recommended Release?
-
Yes
-
-
Will This Feature Be Backported to PANOS 11.1 or 11.2?
-
No — there are currently no plans to backport this feature to PANOS 11.1 or 11.2.
-
-
Are Panorama / Log Collectors Impacted?
-
Panorama and Log Collectors are not directly impacted. They do not use AN, so they are unaffected by this change.
-
However: If PAVM is upgraded to 12.1.x, a Panorama upgrade may still be required.
-
-
Is Panorama Upgrade Required if PAVM is Upgraded to 12.1.x?
- Yes — upgrading Panorama may be required when upgrading PAVM to 12.1.x.
-
Does 12.1.5 supports both MANA and Mellanox NIC ?
- Yes, but 12.1.7-h2 is expected to become the recommended release in the 12.1.x train by the end of July. This will also required to increase Panorama System disk to 224 GB as explained in the document.
-
What if one PA-VM in HA pair falls on MANA HW ?
- That PA-VM will not have both DPDK and AN. An HA pair can still be formed; however, during failover, the secondary IP addresses will not move.
-
Apart from performance degradation resulted because of MANA Hardware, will there be any other impact?
-
No other impact observed as of now.
-
-