For the complete documentation index, see llms.txt. This page is also available as Markdown.

33.02 (Build 33.02.134)

The following table outlines the release particulars:

Build

33.02.134

Code name

Pascal Update 2 (with Hotfix)

Release date

Nov 27, 2024

Type

Minor release

SHA-256

1a0618ea885553777d79bb7d9ab557d8055a0ad7b63f3bdaafac4c7d15eabdcb

Review the system requirements to learn about the supported operating systems, hypervisors, runtimes, tools, and orchestrators.

You can download the release image from the Palo Alto Networks Customer Support Portal, or use a program or script (such as curl, wget) to download the release image directly from our CDN:

<URL available from the Support Portal>

Lifecycle Support Update

Prisma Cloud officially guarantees backward compatibility with up to two previous major versions (n-2).

Although the support lifecycle remains unchanged, starting from version 33.xx, Prisma Cloud will not restrict the usage of Defender versions or REST API calls from up to three major releases before the current version (upto n-3 major releases).

For example, with the current version at 33.xx, API calls and Defenders from version 30.xx will be allowed. However, support and complete backward compatibility is guaranteed for the 32.xx and 31.xx releases.

Upgrade from Previous Releases

Upgrade Defenders

Starting with the v33.00 release, the Defender versions supported (n, n-1, and n-2) are v33.00, v32.00, and v31.00 respectively. In addition, starting from release 33.00, Prisma Cloud will not restrict the usage of Defender versions or REST API calls from the n-3 version. So the current release will allow Defenders and REST API calls from release 30.xx also. Failure to upgrade Defenders below version v30.00, such as v22.12, will result in disconnection of the Defenders from the Console.

However, to maintain full support, you must upgrade your Defenders to v31.xx or a higher release.

To summarize, the level of support for the different versions of Defenders is as follows:

  • Defender versions 33.xx, 32.xx, and 31.xx have full support

  • Defender versions 30.xx are functional (will be able to connect to version 33.xx Console) but support is not available for such Defenders

  • Defender versions previous to 30.xx, such as 22.12, are neither supported nor functional (cannot connect to version 33.xx Console)

Upgrade the Prisma Cloud Console

Starting with the v33.00 release, the supported Console versions (n, n-1, and n-2) are v33.00, v32.00, and v31.00 respectively.

Defenders from the n-3 release will remain functional as described above.

You can upgrade the Prisma Cloud console directly from any n-1 version to n. For example, with v33.00 as n and v32.00 as n-1, you can upgrade directly from v32.05.124 to v33.01.137.

You have to upgrade any version of v31.00 to v32.00 before upgrading to v33.00. For example, you must upgrade from v31.02.137 to v32.07.123 before you upgrade to v33.01.137.

Announcement

Prisma Cloud will use the following additional NAT IP addresses on the Google Cloud for the respective Prisma Cloud Enterprise Edition (SaaS) regions.

The following table lists the regions and the additional reserved Ingress IP addresses.

Region

Additional Ingress IP Addresses

us-east1

  • 34.23.229.147

  • 34.74.93.165

  • 35.185.127.202

us-west1

  • 34.19.57.46

  • 34.83.186.93

  • 34.168.3.165

northamerica-northeast1

  • 34.118.176.160

  • 34.47.2.35

europe-west9

  • 34.163.241.103

  • 34.163.12.56

europe-west3

  • 35.198.174.6

  • 34.141.93.246

  • 34.141.89.174

  • 34.141.2.56

  • 35.198.185.51

europe-west2

  • 34.142.29.59

  • 34.89.33.47

australia-southeast1

  • 34.116.88.189

  • 35.189.14.189

asia-southeast1

  • 35.186.153.185

  • 34.87.100.14

asia-south1

  • 34.93.124.157

  • 34.47.154.73

asia-northeast1

  • 35.187.195.198

  • 34.85.99.145

Enhancements

Scanning Support for Red Hat UBI Micro-images

Prisma Cloud now supports scanning of Red Hat UBI micro-images (versions 7, 8, and 9).

Improved Vulnerability Detection for non-RPM OpenShift Packages

Vulnerability reports for OpenShift non-RPM container components now ensure consistent vulnerability matching across all OpenShift packages. This improvement reduces false positives by applying only relevant CVEs and excluding CVEs that have already been patched.

Improved Vulnerability Detection for Google Kubernetes Engine (GKE) Clusters

Vulnerability detection for Google Kubernetes Engine (GKE) Clusters includes the following enhancements:

  • Integration with Google security bulletins

  • Aligning CVEs with specific GKE cluster types and versions

  • Expanded support for all GKE modes, including Autopilot

Last updated

Was this helpful?