Announcing indeni 5.2: Palo Alto Networks beta, improvements and bugfixes

Key takeawaysThis key takeaway was generated through LLMs crawling the page and coming up with an overview of the content.

Indeni 5.2 introduces infrastructure improvements, numerous bug fixes, and a beta for Palo Alto Networks PAN-OS 6.x.x firewall support, addressing real-world operational issues like false positives, alert noise, and device identification. The release adds support for additional product versions (CP R77.30, FortiOS V5.2.1) and new detection signatures for Check Point, F5, and others, improving monitoring accuracy for disk/inode, multicast loops, pool member limits, SSL TPS, and license/trial states. Routine interim weekly builds between minor releases are provided and customers needing earlier version support can contact support for a running build; the update also refines alert content, backup/report behaviors, and SSH/backup reliability to reduce operational impact and noise.

What new products and versions does Indeni 5.2 add support for, and how can customers request builds for versions prior to the main release?

Indeni 5.2 adds a beta for Palo Alto Networks firewalls running PAN-OS 6.x.x, support for Check Point R77.30 (IK-1675), and FortiGate FortiOS V5.2.1 (IK-1840). Customers who require support for a given product version before its inclusion in the main release can contact [email protected] to request a running build. The release notes also note that interim builds with new content and fixes are produced weekly between minor releases, and customers may have received earlier 5.2 builds and are recommended to upgrade to the newest announced build.

Which new detection signatures in 5.2 address F5 BIG-IP operational issues and what operational problems do they target?

Multiple new signatures target F5 BIG-IP operational issues: IK-1836 enhances detection of node availability problems; IK-1825 addresses ConfigSync operational status issues; IK-2020 detects near or out of disk space or inode exhaustion; IK-2021 flags possible multicast or broadcast loops on SFP NICs; IK-1834 alerts when load balancer node connection limits are nearing or reached; IK-1831 detects when the number of active pool members is lower than required; IK-1835 notifies when pool member connection limits are nearing or reached; and IK-1827 reports SSL transactions-per-second (TPS) limits nearing or reached. Together these signatures improve visibility into capacity, configuration synchronization, network loops, and pool/member health to reduce service impact.

What classes of bugs and false positives were fixed in 5.2, and how do these fixes reduce alert noise and improve monitoring accuracy?

Release 5.2 fixes many false positives and operational bugs across vendors: it reduces noisy NIC-related alerts (e.g., fewer log lines for NIC failures IK-1674; corrected packet error thresholds IK-1672, IS-1000), resolves false positives for DNS resolution on Cisco (IK-1859), SecureXL templates and cluster monitoring in Check Point (IK-1919, IK-1914), and removes or refines alerts for expired or ‘never’ expiring licenses (IK-1858). Other fixes improve alert content (adding interface details IK-1901, timestamps IS-1765/IS-1060), backup/report behavior (IS-1454, IS-1453), SSH/connection handling (IS-1077, IS-1037), and device identification (IK-1741, IK-1742). These changes lower unnecessary alerts, improve diagnostic detail, and increase confidence in automated monitoring.

Welcome 5.2!

In this release we’ve included many improvements to the underlying infrastructure and bugfixes, as well as kicked off the beta for our support of Palo Alto Networks firewalls. Please reach out to our support team to get the updated release. Note that between minor releases (such as 5.1 and 5.2) we make interim releases with new content and bugfixes on a weekly basis. You may have received a previous release of 5.2, which we recommend you upgrade to the newest one announced today.

New products and versions supported:

  • BETA of Palo Alto Networks firewalls running PAN-OS 6.x.x.
  • IK-1675: Support CP R77.30
  • IK-1840: Fortigate: Added support for FortIOS V5.2.1

NOTE: Customers who require support of a given product version prior to the main release can contact [email protected] and a running build will be provided.

Select new signatures:

  • IK-1677: Firewall is running with a trial license (Check Point)
  • IK-1836: Enhanced “BIG-IP node availability issue detected” (F5)
  • IK-1825: ConfigSync operational status issues (F5)
  • IK-2020: The BIG-IP system is near or out of disk space or inodes (SOL12263, SOL14403) (F5)
  • IK-2021: “Possible multicast or broadcast loop on SFP NICs detected” (F5)
  • IK-1834: “Load balancer node connection limit nearing (or reached)” (F5)
  • IK-1831: “Number of active members in pool is lower than required” (F5)
  • IK-1835: “Pool member connection limit nearing (or reached)” (F5)
  • IK-1827: “SSL transactions per second (TPS) limit nearing or reached” (F5)

Bugs fixed and minor improvements:

  • IK-1674: “A NIC has failed recently (SA#24915)”: reduced the number of log lines shown
  • IK-1518: “Cluster Members Identical Kernel Parameter Values Verification (SA#66322)”: additional dynamic parameters ignored
  • IK-1859: “DNS server resolution test failed” – eliminate false positive in Cisco devices
  • IK-1672: “Errors have been found in packets received by NIC (SA#24915)” triggered for very low packet count
  • IK-1704: “Communication with device suspended due to 2 reboots” false positive
  • IK-1712: “Hardware has reached end of support” is auto-resolving
  • IK-1683: “Hardware temperature sensor reading too high” false positive
  • IK-1391: “High storage usage has been measured” doesn’t show list of large files in Cisco devices
  • IK-1871: “HSRP cluster members differ in VLAN configuration” false positive
  • IK-1858: “License(s) have expired” false positive for CP licenses with expiration “never”
  • IS-1349: “Max SSH Session Count” remains at default
  • IK-1976: “Monitoring Suspended” creating too many alerts
  • IK-1958: “NAT cache (fwx_cache) table limit approaching or reached” false positive
  • IK-1879: “NAT connections (fwx_alloc) table limit approaching or reached” false positive
  • IK-1901: “RX traffic drastically reduced post fail over, possible ARP issue” add specific interface details
  • IK-1919: “SecureXL templates are partially disabled” false positive
  • IK-1914: “Some members of the same cluster are not being monitored” false positive
  • IK-1731: “Some proxy ARPs required by NAT are missing” – signature removed
  • IS-1000: “Some received packets have been dropped by NIC (SA#24915)” – duplicate text in e-mail alert details
  • IK-1628: “Two cluster members differ in their routing tables” failing to create alert
  • IK-1870: “Use of NTP is configured but no servers are defined” false positive
  • IK-1684: “Voltage too high or too low” false positive
  • IK-1702: “Voltage too high or too low” – don’t alert if hi/low limits are unknown
  • IS-1454: Backup: sometimes old backups are not deleted
  • IK-1501: “Proxy ARP is enabled” flapping in Cisco
  • IK-1696: GAiA R77.10: Replace use of ckp_regedit with cpinfo
  • IK-1846: ClusterXL member differences alerts are referring to the wrong cluster members
  • IK-2133: Configuration Check – “Hotfix(es) Installed” does not handle comma delimited string of HFs correctly
  • IS-1077: Connection to SecurePlatform with SSH private key fails
  • IK-1741: Correctly identify device model for CP 21700
  • IK-1742: Correctly identify device model for CP 4400
  • IK-1670: Live Configuration – all NICS are showing as Down
  • IK-1856: Hardware alert false positives from Check Point open server
  • IS-1346: Prevent “service indeni4it start” from starting the application more than one time
  • IK-1690: “Route overlap identified” – don’t alert when next-hop is the same
  • IK-1688: NIC stats alerts (e.g. packet errors) should contain the total number of packets that we compare against
  • IK-2066: SmartCenter degradation due to hanging “fw log” processes
  • IK-1993: SmartCenter backup: use “migrate export” for R75.40 and above
  • IK-2067: Reduce “sshd[xxx]: Did not receive identification string from <indeni server>” in device messages log
  • IS-1037: Update by UPD fails to restart the service
  • IK-1966: Crossbeam discovery failure
  • IS-1453: Backup Report – empty “Failed Backups” section header
  • IS-1348: Scheduled Reports delivery does not follow DST changes
  • IS-1441: F5 – wc should not show the groups common/device_trust_group and common/gtm
  • IS-1036: E-mail Alerts: remove PDFs from e-mail alerts
  • S-1019: Tools-Troubleshooting – add “cpstat os -f sensors” for Check Point firewalls
  • IS-1765: Alert Report – add alert timestamps&nbsp;
  • IS-1060: Alerts e-mails – add alert timestamp

Get in touch

We’re the DDI provider you’ve been looking for.
Drop us a line and let’s talk.

Related content

Isometric dashboard illustration showing a circular "33 Total Devices" donut chart, issue counts, and filter controls

BlueCat moves agentic AI from insight to action with new AI integrations

Extends its Intelligent NetOps platform to help organizations unlock measurable AI value through a unified data foundation

Read more
Headshot of a man in a suit and striped tie wearing rectangular glasses against a blurred office background

BlueCat appoints Jeff McCullough as Vice President, Worldwide Channel and Alliance

Experienced channel leader will drive partner-led growth and support partners in generating revenue and value within BlueCat’s global ecosystem

Read more
BlueCat logo above Horizon product name with stylized network horizon graphic and glowing center

BlueCat introduces BlueCat Horizon, a SaaS-first Intelligent NetOps platform for cross-domain network operations

The platform delivers a unified control plane for DNS, DHCP, IPAM, security, and observability, empowering rapid, automated action across networks

Read more
Report cover titled "The Network Observability Maturity Model" with EMA and BlueCat logos and purple design accents

Fewer than half of enterprises are fully successful with network observability tools

Fragmented tools and cloud blind spots are straining NetOps, but a new five-stage maturity model charts the path to excellence.

Read more