During an upgrade from PAN-OS 10.2.3 to PAN-OS 10.2.12-h2 we saw the upgraded firewall go non-functional due to NAT Oversubscription mismatch.
I have seen this when upgrading between major versions, but not in such a minor change.
Is it expected to have a change like this when upgrading maintenance versions?
It's been required to have NAT oversubscription be identical on both peers since a long time
It's possible that in 10.2 this setting was actually not checked due to a bug and with the upgrade this was fixed (had a similar issue with HA1 going down due to ping on aux interfaces going from implied to explicit between 11.1.4 and 11.1.5 recently)