During the initial test of PAN-OS 11.2.8-c537, NSS Labs was able to bypass protection using Layer 3 IP and Layer 4 TCP evasions. Following receipt of test results published on November 5, 2025, Palo Alto Networks responded quickly to develop an updated PAN-OS firmware package (PAN-OS 11.2.10-c37) that NSS Labs then tested using the identical test methodology and tools employed in the original evaluation.

This document provides updated test results for the Palo Alto Networks PA-1410 Enterprise Firewall utilizing PAN-OS version 11.2.10-c37. Palo Alto Networks confirmed that PAN-OS version 11.2.10-c37 was provided as a pre-release and will be designated as PAN-OS 11.2.10 upon reaching general availability. 

Product ratings give decision-makers clear, forward-looking insight into the effectiveness of products tested. The Comparative Security Map (CSM) assesses Enterprise Firewall products based on Security Effectiveness and False Positive Accuracy.

Products with high Security Effectiveness and False Positive Accuracy are given ‘Recommended’ ratings. Products rated ‘Neutral’ can still be suitable for organizations that can tolerate a slightly higher level of false positives. Products receiving a ‘Caution’ rating have below-average Security Effectiveness and should be reviewed for potential alternatives.