Panorama Network Discovery Plugin
Focus
Focus
Device Security

Panorama Network Discovery Plugin

Table of Contents

Panorama Network Discovery Plugin

Use the Network Discovery plugin with Panorama to provide Device Security features.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by PAN-OS or Panorama)
One of the following subscriptions:
  • Device Security subscription
  • Precision AI bundle subscription
  • Device Security X subscription
The release notes for the Network Discovery plugin for Panorama includes information about new features, enhancements, and addressed and known issues for each version of the Network Discovery plugin.
For configuration information regarding using the Network Discovery plugin for Panorama, see the firewall configuration information in the Device Security Getting Started Guide.
When needed, use the CLI to Test and Debug the Network Discovery Plugin. If you need to reach out to customer support, you must run those commands first to capture their output in your Technical Support File (TSF).

Supported Firewalls and PAN-OS Versions

Strata Cloud Manager does not support plugin management. If you use Strata Cloud Manager to access Device Security, you still need to use Panorama or PAN-OS to manage the Network Discovery plugin.
Firewalls
The following firewalls don't support the Network Discovery plugin:
  • PA-410
  • PA-410R
  • PA-410R-5G
  • PA-415
  • PA-415-5G
PAN-OS
PAN-OS VersionNetwork Discovery Plugin Version
PAN-OS 12.1 and laterNetwork Discovery plugin version 3.0 and later
PAN-OS 11.2 and earlierNetwork Discovery plugin version 2.x and earlier
PAN-OS 10.2.14 and later 10.2 releasesNetwork Discovery plugin version 2.1 and later 2.x releases
The table below describes the which versions of the Network Discovery plugin are supported on which versions of PAN-OS. You can also find this table on the Panorama Plugins page of the Compatibility Matrix.
The following table shows the features introduced in each version of the Panorama™ Network Discovery plugin.
Plugin Version
Panorama PAN-OS Version
(Minimum)
Maximum Panorama PAN-OS Version
Features
3.2.0
12.1.2
Latest 12 release
Parity with Network Discovery 2.4.0, to include:
  • Expanded SNMPv3 protocol support for additional authentication protocols (SHA-224, SHA-256, SHA-384, and SHA-512) and privacy protocols (AES-192, AES-256, and 3DES).
  • Additional OT polling protocol support for Beckhoff (UDP), Siemens Webserver, Codesys (TCP), and GE Carescape patient monitors.
  • Introduces test and debug CLI commands to validate connectivity, test polling queries, and gather diagnostic data for the Network Discovery plugin directly from the firewall.
3.1.0
12.1.2
Latest 12 release
Parity with Network Discovery 2.3.0, to include:
  • Introduces configurable multi-threading for SNMP neighbor discovery jobs.
  • Includes fixes for known issues.
3.0.1
12.1.2
Latest 12 release
Parity with Network Discovery 2.2.3, to include:
  • Introduces option to exclude IP phones from neighbor discovery when doing SNMP crawling.
  • Includes fixes for known issues.
3.0.0
12.1.2
Latest 12 release
Parity with Network Discovery 2.2.2.
2.4.0
10.2.17
11.1
Latest 10.2 release
Latest 11 release
Expanded SNMPv3 protocol support for additional authentication protocols (SHA-224, SHA-256, SHA-384, and SHA-512) and privacy protocols (AES-192, AES-256, and 3DES).
Additional OT polling protocol support for Beckhoff (UDP), Siemens Webserver, Codesys (TCP), and GE Carescape patient monitors.
Introduces test and debug CLI commands to validate connectivity, test polling queries, and gather diagnostic data for the Network Discovery plugin directly from the firewall.
2.3.3
10.2.17
11.1
Latest 10.2 release
Latest 11 release
Includes fixes for known issues.
2.3.2
10.2.17
11.1
Latest 10.2 release
Latest 11 release
Includes fixes for known issues.
2.3.1
10.2.17
11.1
Latest 10.2 release
Latest 11 release
Includes fixes for known issues.
2.3.0
10.2.17
11.1
Latest 10.2 release
Latest 11 release
Introduces configurable multi-threading for SNMP neighbor discovery jobs.
Includes a fix for a known issue.
2.2.5
10.2.17
11.1
Latest 10.2 release
Latest 11 release
Includes a fix for a known issue.
2.2.4
10.2.17
11.1
Latest 10.2 release
Latest 11 release
Includes a fix for a known issue.
2.2.3
10.2.17
11.1
Latest 10.2 release
Latest 11 release
Introduces option to exclude IP phones from neighbor discovery when doing SNMP crawling.
Includes fixes for known issues.
2.2.2
10.2.17
11.1
Latest 10.2 release
Latest 11 release
Includes fixes for known issues.
2.2.1
10.2.14
11.1
Latest 10.2 release
Latest 11 release
Includes fixes for known issues.
2.2.0
10.2.14
11.1
Latest 10.2 release
Latest 11 release
Introduces new protocols for device polling.
2.1.2
10.2.14
11.1
Latest 10.2 release
Latest 11 release
Includes fixes for known issues.
2.1.1
10.2.14
11.1
Latest 10.2 release
Latest 11 release
Includes fixes for known issues.
2.1.0
10.2.14
11.1
Latest 10.2 release
Latest 11 release
Introduces support for multiple entry switches and multiple SNMP credentials.
Supports site creation and site overwrite for existing subnets learned through SNMP crawling.
2.0.2
11.1
Latest 11 release
Introduces new protocols for device polling.
Introduces new settings options for configuring SNMP network discovery and network data refreshment jobs.
Includes a fix for a known issue.
2.0.1
11.1
Latest 11 release
Introduces debug logs and fixes for a known issue.
2.0.0
11.1
Latest 11 release
Introduces device polling using various protocols. Use polling to learn new device attributes to send to Device Security.
1.0.1
11.1
Latest 11 release
Introduces the capability to specify a network discovery protocol using the CLI.
1.0.0
11.1
Latest 11 release
Introduces SNMP querying for switches and network devices. Use SNMP querying to learn bindings and network data to send to Device Security.

Network Discovery Plugin Versions

To see what changed in each version of the Network Discovery plugin, see the release notes for the versions below: