VMware ESXi 6.7 is no longer supported for VM-Series running PAN-OS 11.1 or higher. Upgrade to ESXi 7.0 or 8.0.

| Your Current Version | Recommendation | | :--- | :--- | | | Do not upgrade directly to 11.x. First go to 10.1.10, then 10.2.8, then follow path above. Better yet – refresh hardware. | | PAN-OS 10.0.x | Upgrade to 10.2.8-h4, test AIOps staging, then plan 11.1.x migration in 2024 Q3. | | PAN-OS 10.2.5+ | Safe to upgrade to 11.1.4. Start with non-production firewalls. | | New deployment (greenfield) | Deploy directly with PAN-OS 11.1.4. Avoid 11.0.x entirely. |

Use request system software upgrade from CLI or Panorama’s Device Deployment.

This article breaks down the official PAN-OS 11 release notes into digestible sections: version lifecycles, major new features, critical behavioral changes, upgrade caveats, and resolved issues.

Using deep learning to stop zero-day attacks in real-time.

Technical Overview: PAN-OS 11 "Nova" Release Series Palo Alto Networks introduced PAN-OS 11 (Nova)

: Reimagines IPS with inline deep learning to stop zero-day injection attacks, detecting 60% more unknown injection attacks than previous solutions. Advanced DNS Security