14 • PAN-OS 6.1 Release Notes Palo Alto Networks
Changes to Default Behavior PAN-OS 6.1 Release Information
Changes to Default Behavior
The following points describes changes to default behavior in PAN-OS 6.1.0:
The default key size for SSL/TLS Forward Proxy certificates has changed from 1024-bit RSA to Defined by
destination host
. The new default setting allows for PAN-OS to generate certificates based on the key that
the destination server uses.
A new Rule Type classification indicates whether a security rule matches intrazone traffic, interzone traffic,
or both (called universal). In releases prior to PAN-OS 6.1.0, the rule type classification did not exist and all
rules were considered universal. Existing rules in the rulebase are converted to universal rules when you
upgrade to PAN-OS 6.1.0; you can then choose to change the
Rule Type to intrazone, interzone, or leave it
classified as
universal.
The GlobalProtect agent now collects the domain that is defined for the ComputerNameDnsDomain
parameter from Windows clients. This is the DNS domain assigned to the local computer or the cluster
associated with the local computer. The value for the parameter ComputerNameDnsDomain is used to
populate the
Domain displayed in the HIP Match logs for Windows clients.
Commenti su questo manuale