Add 10.0 issue data
This commit is contained in:
@@ -0,0 +1,223 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 10.0.10
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-190175
|
||||||
|
|
||||||
|
A fix was made to address an OpenSSL infinite loop vulnerability in the PAN-OS software ([CVE-2022-0778](https://security.paloaltonetworks.com/CVE-2022-0778)).
|
||||||
|
|
||||||
|
## PAN-190223
|
||||||
|
|
||||||
|
A fix was made to address an OpenSSL infinite loop vulnerability in the PAN-OS software ([CVE-2022-0778](https://security.paloaltonetworks.com/CVE-2022-0778)).
|
||||||
|
|
||||||
|
## PAN-189665
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
FIPS-CC enabled firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall was unable to connect to log collectors after an upgrade due to missing cipher suites.
|
||||||
|
|
||||||
|
## PAN-185616
|
||||||
|
|
||||||
|
Fixed an issue where the firewall sent fewer logs to the system log server than expected. With this fix, the firewall accommodates a larger send queue for syslog forwarding to TCP syslog receivers.
|
||||||
|
|
||||||
|
## PAN-185163
|
||||||
|
|
||||||
|
Fixed an issue where the distributord process hit the FD limit, which caused User-ID redistribution to not function properly.
|
||||||
|
|
||||||
|
## PAN-184693
|
||||||
|
|
||||||
|
Fixed an issue that caused the slotd process to stop responding due to an incorrect response from etcd lock API.
|
||||||
|
|
||||||
|
## PAN-183862
|
||||||
|
|
||||||
|
Fixed an issue where, after a CN-NGFW pod failed-over to the second CN-MGMT pod, the configuration was not synchronized between the new CN-MGMT pod and the CN-NGFW pod.
|
||||||
|
|
||||||
|
## PAN-183774
|
||||||
|
|
||||||
|
Fixed an memory leak issue in the mgmtsrvr process, which resulted in an out-of-memory (OOM) condition and high availability (HA) failover.
|
||||||
|
|
||||||
|
## PAN-183239
|
||||||
|
|
||||||
|
Fixed an issue where the firewall randomly disconnected from the WildFire URL cloud.
|
||||||
|
|
||||||
|
## PAN-182903
|
||||||
|
|
||||||
|
Fixed an issue where SD-WAN failover on a hub or branch in full mesh took longer than expected.
|
||||||
|
|
||||||
|
## PAN-181839
|
||||||
|
|
||||||
|
Fixed an issue where Panorama Global Search reported **No Matches found** while still returning results for matching entries on large configurations.
|
||||||
|
|
||||||
|
## PAN-181039
|
||||||
|
|
||||||
|
Fixed an issue with DNS cache depletion that caused continuous DNS retries.
|
||||||
|
|
||||||
|
## PAN-181031
|
||||||
|
|
||||||
|
Fixed an issue where the CN-NGFW (DP) folder on the CN-MGMT pod eventually consumed a large amount of space in the /var/log/pan because the old registered stale next-generation firewall logs were not being cleared.
|
||||||
|
|
||||||
|
## PAN-180916
|
||||||
|
|
||||||
|
Fixed an issue where DNS security caused the TTL (time-to-live) value of the pointer record (PTR) to be overwritten with a value of 30 seconds.
|
||||||
|
|
||||||
|
## PAN-179982
|
||||||
|
|
||||||
|
Fixed an issue where an OOM condition occurred due to quarantine list redistribution.
|
||||||
|
|
||||||
|
## PAN-179976
|
||||||
|
|
||||||
|
Fixed an issue where the WildFire Inline Machine Learning (ML) did not detect mlav-test-pe-file.exe when traffic was decrypted.
|
||||||
|
|
||||||
|
## PAN-179703
|
||||||
|
|
||||||
|
Fixed an issue where dataplane interfaces weren't released when the secured application pods were deleted.
|
||||||
|
|
||||||
|
## PAN-179413
|
||||||
|
|
||||||
|
Fixed an issue where GRE tunnels flapped during commit jobs.
|
||||||
|
|
||||||
|
## PAN-179321
|
||||||
|
|
||||||
|
A validation error was added to inform an administrator when a policy field contained the value **any**.
|
||||||
|
|
||||||
|
## PAN-179274
|
||||||
|
|
||||||
|
Fixed an issue on high availability configurations where, after upgrading to PAN-OS 9.1.10, PAN-OS 10.0.6, or PAN-OS 10.1.0, the HA1 and HA1-Backup link stayed down. This issue occurred when the peer firewall IP address was in a different subnet.
|
||||||
|
|
||||||
|
## PAN-179164
|
||||||
|
|
||||||
|
Fixed an issue where a web-proxy port number was added to the destination URL when captive portal authentication was run.
|
||||||
|
|
||||||
|
## PAN-179059
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to delete dynamic address groups one at a time using XML API.
|
||||||
|
|
||||||
|
## PAN-178947
|
||||||
|
|
||||||
|
Fixed an issue where the useridd process stopped responding when a NULL reference attempted to be dereferenced. This issue occurred to IP address users being added.
|
||||||
|
|
||||||
|
## PAN-177907
|
||||||
|
|
||||||
|
Fixed an issue where, after rebooting the firewall, FQDN address objects referred in rules in a virtual system (vsys) did not resolve when the vsys used a custom DNS proxy.
|
||||||
|
|
||||||
|
## PAN-177878
|
||||||
|
|
||||||
|
Fixed an issue where a role-based admin with **Operational Requests** enabled under the XML API section was unable to set the License Deactivation API key.
|
||||||
|
|
||||||
|
## PAN-177626
|
||||||
|
|
||||||
|
Fixed an issue where aggressive situations caused on-chip descriptor exhaustion.
|
||||||
|
|
||||||
|
## PAN-177551
|
||||||
|
|
||||||
|
A fix was made to address a vulnerability that enabled an authenticated network-based administrator to upload a specifically created configuration that disrupted system processes and was able to execute arbitrary code with root privileges when the configuration was committed ([CVE-2022-0024](https://security.paloaltonetworks.com/CVE-2022-0024)).
|
||||||
|
|
||||||
|
## PAN-177187
|
||||||
|
|
||||||
|
Fixed an issue where reports using the decryption summary database and Panorama as data sources returned no results.
|
||||||
|
|
||||||
|
## PAN-177170
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where a log collector group commit deleted the proxy settings configured on dedicated log collectors.
|
||||||
|
|
||||||
|
## PAN-176889
|
||||||
|
|
||||||
|
Fixed an issue where the log collector continuously disconnected from Panorama due to high latency and a high number of packets in Send-Q.
|
||||||
|
|
||||||
|
## PAN-176703
|
||||||
|
|
||||||
|
Fixed an issue that occurred after upgrading to a PAN-OS 9.0 or later release where commits to the firewall configuration failed with the following error message: statistics-service is invalid.
|
||||||
|
|
||||||
|
## PAN-176348
|
||||||
|
|
||||||
|
Fixed an issue where scheduled email alerts were not forwarded to all recipients in the override list.
|
||||||
|
|
||||||
|
## PAN-175716
|
||||||
|
|
||||||
|
Fixed an issue where sorting address groups by name, address, or location did not work on a device group that was part of a nested device group.
|
||||||
|
|
||||||
|
## PAN-175628
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall was unable to monitor AUX1 and AUX2 interfaces through SNMP.
|
||||||
|
|
||||||
|
## PAN-175259
|
||||||
|
|
||||||
|
Fixed an issue where a Security policy configured with App-ID and set to **web-browsing** and **application-default service** allowed clear-text web-browsing on tcp/443.
|
||||||
|
|
||||||
|
## PAN-175161
|
||||||
|
|
||||||
|
Fixed an issue where changing SSL connection validation settings for system logs caused the mgmtsrvr process to stop responding.
|
||||||
|
|
||||||
|
## PAN-174809
|
||||||
|
|
||||||
|
Fixed an issue where a process (all_pktproc) restarted.
|
||||||
|
|
||||||
|
## PAN-174607
|
||||||
|
|
||||||
|
Fixed an intermittent issue where, when Security profiles were attached to a policy, files that were downloaded across TLS sessions decrypted by the firewall were malformed.
|
||||||
|
|
||||||
|
## PAN-174587
|
||||||
|
|
||||||
|
Fixed an issue where, in the case of multiple AWS Partner Network (APN) connections, the GPRS tunneling protocol (GTPv2) Create Session Requests were sent to the firewall within a short interval, which caused the firewall to create the GTP-sessions incorrectly.
|
||||||
|
|
||||||
|
## PAN-174011
|
||||||
|
|
||||||
|
Fixed an issue where Panorama failed to update shared policies during partial commits when a new device group was created but not yet committed.
|
||||||
|
|
||||||
|
## PAN-171345
|
||||||
|
|
||||||
|
Fixed an issue where firewalls experienced high packet descriptor usage due to internal communication associated with WildFire.
|
||||||
|
|
||||||
|
## PAN-171181
|
||||||
|
|
||||||
|
Fixed an issue where the IPSec tunnel configuration didn't load when a double quotation mark was added to the comment section of the IPSec tunnel **General** tab.
|
||||||
|
|
||||||
|
## PAN-171104
|
||||||
|
|
||||||
|
Fixed an issue where a race-condition check returned a false negative, which caused a process (all_task) to stop responding and generate a core file.
|
||||||
|
|
||||||
|
## PAN-170952
|
||||||
|
|
||||||
|
Fixed script issues that caused diagnostic data to not be collected after path monitor failure.
|
||||||
|
|
||||||
|
## PAN-168400
|
||||||
|
|
||||||
|
Fixed an issue where, after installing Cloud Services plugin 10.2, the **Plugin cloud_services** status (**Dashboard > High Availability**) displayed as **Mismatch**.
|
||||||
|
|
||||||
|
## PAN-168286
|
||||||
|
|
||||||
|
Fixed a memory leak issue in the mgmtsrvr process that was caused by failed commit all operations.
|
||||||
|
|
||||||
|
## PAN-167849
|
||||||
|
|
||||||
|
Fixed an issue where URL Filtering incorrectly identified the firewall serial number in the certificate **Common Name** field as the IP address.
|
||||||
|
|
||||||
|
## PAN-164871
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an intermittent issue where deactivating the firewall via XML API using manual mode failed. This occurred because the size of the license token file was incorrect.
|
||||||
|
|
||||||
|
## PAN-163245
|
||||||
|
|
||||||
|
Fixed an issue where a commit-all or push to the firewall from Panorama failed with the following error message: client routed requesting last config in the middle of a commit/validate. Aborting current commit/validate.
|
||||||
|
|
||||||
|
## PAN-161297
|
||||||
|
|
||||||
|
Fixed an interoperability issue with other vendors when IKEv2 used SHA2-based certificate authentication.
|
||||||
|
|
||||||
|
## PAN-155448
|
||||||
|
|
||||||
|
Fixed an issue where credential detection didn't work in IP address-to-username mapping mode because the firewall compared the unnormalized IP-address-to-username mapping format to the normalized username extracted from the payload where the username and password were submitted.
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 10.0.11-h1
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-192999
|
||||||
|
|
||||||
|
A fix was made to address [CVE-2022-0028](https://security.paloaltonetworks.com/CVE-2022-0028).
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 10.0.11-h3
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-202450
|
||||||
|
|
||||||
|
Fixed an issue where the device-client-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
|
||||||
|
|
||||||
|
## PAN-198372
|
||||||
|
|
||||||
|
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
|
||||||
|
|
||||||
|
## PAN-193004
|
||||||
|
|
||||||
|
Fixed an issue where /opt/pancfg partition utilization reached 100%, which caused access to the Panorama web interface to fail.
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 10.0.11-h4
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-237876
|
||||||
|
|
||||||
|
Extended the firewall Panorama root CA certificate which was previously set to expire on April 7th, 2024.
|
||||||
|
|
||||||
|
## PAN-215576
|
||||||
|
|
||||||
|
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
|
||||||
@@ -0,0 +1,23 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 10.0.12-h5
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-239241
|
||||||
|
|
||||||
|
Extended the root certificate for WildFire appliances to December 31, 2032.
|
||||||
|
|
||||||
|
## PAN-237935
|
||||||
|
|
||||||
|
Extended the offline PAN-DB, Panorama, and WildFire certificates which were previously set to expire on September 2, 2024.
|
||||||
|
|
||||||
|
## PAN-237876
|
||||||
|
|
||||||
|
Extended the firewall Panorama root CA certificate which was previously set to expire on April 7th, 2024.
|
||||||
|
|
||||||
|
## PAN-215576
|
||||||
|
|
||||||
|
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
|
||||||
@@ -0,0 +1,167 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 10.0.4
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-161613
|
||||||
|
|
||||||
|
Fixed an issue where the **Dashboard** incorrectly displayed the Log Forwarding Card (LFC) port status.
|
||||||
|
|
||||||
|
## PAN-161121
|
||||||
|
|
||||||
|
Fixed an issue on the Panorama management server that caused invalid reference errors when attempting to delete an address object (**Objects > Addresses**) after removing the address object reference from an address group (**Objects > Address Groups**) resulting in you being unable commit and push the configuration to managed firewalls.
|
||||||
|
|
||||||
|
## PAN-160974
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where, if **Source Address Exclusion** **(Network > Zone Protection > Reconnaissance Protection**) was configured, **Flood Protection** was disabled.
|
||||||
|
|
||||||
|
## PAN-160376
|
||||||
|
|
||||||
|
Fixed an issue where, for local administrators using an authentication profile, the **save filter** (**Monitor > Logs**) option was grayed out.
|
||||||
|
|
||||||
|
## PAN-160163
|
||||||
|
|
||||||
|
Fixed an issue where icons in the left sidebar had multiple layers.
|
||||||
|
|
||||||
|
## PAN-159856
|
||||||
|
|
||||||
|
Fixed an issue where, when a factory reset was performed on a Panorama appliance with PAN-OS 10.0, the appliance repeatedly rebooted.
|
||||||
|
|
||||||
|
## PAN-159850
|
||||||
|
|
||||||
|
Fixed an issue where syslog server monitoring stopped working when the first tuple in regex matching was always a whole string.
|
||||||
|
|
||||||
|
## PAN-159826
|
||||||
|
|
||||||
|
Fixed an issue where SSL VPN leaked when the default browser feature on GlobalProtect was not enabled.
|
||||||
|
|
||||||
|
## PAN-159508
|
||||||
|
|
||||||
|
Fixed an IPSec tunnel memory leak issue where IPSec tunnels failed during rekey.
|
||||||
|
|
||||||
|
## PAN-158988
|
||||||
|
|
||||||
|
Fixed an issue with HTTP Header Insertion where the payload was truncated when processing a segmented TCP stream and when the client retransmitted the packet with the same sequence number that was previously received segmented.
|
||||||
|
|
||||||
|
## PAN-158650
|
||||||
|
|
||||||
|
Fixed an issue where several operations and processes stopped responding due to a deadlock issue between the CLI thread and the Terminal Server (TS) agent message processing the thread.
|
||||||
|
|
||||||
|
## PAN-158461
|
||||||
|
|
||||||
|
Fixed an issue where editing an application filter object caused excluded applications to be included.
|
||||||
|
|
||||||
|
## PAN-157885
|
||||||
|
|
||||||
|
Fixed an issue where you could not prioritize the tunnel preference for your branches and hubs in SD-WAN full mesh VPN clusters.
|
||||||
|
|
||||||
|
## PAN-157620
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls deployed in Amazon Web Services (AWS) instance types M5 and C5 only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where a Panorama Virtual Appliance in a high availability (HA) configuration entered a suspended state due to a virtual machine (VM) memory size mismatch.
|
||||||
|
|
||||||
|
## PAN-157319
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls with Log Forwarding Cards (LFCs) only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where GlobalProtect logs showed the incorrect client version and did not show event ID information.
|
||||||
|
|
||||||
|
## PAN-156728
|
||||||
|
|
||||||
|
Fixed an issue where GlobalProtect user traffic did not correctly match Security policy rules that had host information profile (HIP) objects and profiles.
|
||||||
|
|
||||||
|
## PAN-156549
|
||||||
|
|
||||||
|
Fixed an issue where the download link was omitted on scheduled email reports for SaaS application usage.
|
||||||
|
|
||||||
|
## PAN-156240
|
||||||
|
|
||||||
|
A fix was made to address an issue where a cryptographically weak pseudo-random number generator (PRNG) was used during authentication to the PAN-OS web interface to enable an attacker to observe their own authenticated secrets on the firewall over a long duration, which enabled them to impersonate another authenticated web interface administrator’s session ([CVE-2021-3047](https://security.paloaltonetworks.com/CVE-2021-3047)).
|
||||||
|
|
||||||
|
## PAN-156115
|
||||||
|
|
||||||
|
Fixed an issue where, if the firewall had the standard support license, the **License** tab did not display the license details after an upgrade to PAN-OS 10.0.1.
|
||||||
|
|
||||||
|
## PAN-155824
|
||||||
|
|
||||||
|
Fixed a rare issue where Open Shortest Path First (OSPF) links flapped.
|
||||||
|
|
||||||
|
## PAN-155672
|
||||||
|
|
||||||
|
Fixed an issue where inserting or removing copper and optic modules in PAN-OS 10.0.1 caused a process (brdagent) to stop responding.
|
||||||
|
|
||||||
|
## PAN-154365
|
||||||
|
|
||||||
|
Fixed an issue where Security policy rules targeted by tags incorrectly displayed as deleted when previewing commit changes.
|
||||||
|
|
||||||
|
## PAN-154323
|
||||||
|
|
||||||
|
Fixed an issue in Panorama where frequent API requests caused the Panorama web interface to become unresponsive. This issue occurred because the web interface automatically refreshed after each request.
|
||||||
|
|
||||||
|
## PAN-154208
|
||||||
|
|
||||||
|
Fixed an issue where the **Device** icon was not displayed (**Policies > Security > Name > Source > Source Device > Add** or **Policies > Security > Name > Destination > Destination Device > Add**).
|
||||||
|
|
||||||
|
## PAN-154190
|
||||||
|
|
||||||
|
Fixed an issue where Data Loss Prevention (DLP) did not support the upload of Office Open XML (OOXML) files generated from Google suite applications such as Google Docs, Slides, and Sheets.
|
||||||
|
|
||||||
|
## PAN-153705
|
||||||
|
|
||||||
|
Fixed an issue where packets were not evenly distributed among a process (pan_tasks), which caused latency and poor performance.
|
||||||
|
|
||||||
|
## PAN-153547
|
||||||
|
|
||||||
|
Fixed an issue where the login banner size increased.
|
||||||
|
|
||||||
|
## PAN-151997
|
||||||
|
|
||||||
|
Fixed an issue where the option to sinkhole was not displayed in the ACC filter drop-down (**ACC > Threat Activity > Global filters > Action**).
|
||||||
|
|
||||||
|
## PAN-151872
|
||||||
|
|
||||||
|
Fixed an issue where MAC addresses containing certain characters in sequential order caused an issue with TCP connections
|
||||||
|
|
||||||
|
## PAN-151803
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where commits failed when using device-id as a template variable.
|
||||||
|
|
||||||
|
## PAN-151458
|
||||||
|
|
||||||
|
Fixed an issue on firewalls with HA active/active configurations where GlobalProtect gateways timed out on-demand connections. This occurred because the **Inactivity Logout** timer did not reset.
|
||||||
|
|
||||||
|
## PAN-150968
|
||||||
|
|
||||||
|
Fixed a rare issue with HTTP/2 decryption that caused packet header bytes to be corrupted, which caused packet drops.
|
||||||
|
|
||||||
|
## PAN-147792
|
||||||
|
|
||||||
|
Fixed an issue where a process (configd) stopped responding due to a buffer overflow.
|
||||||
|
|
||||||
|
## PAN-147221
|
||||||
|
|
||||||
|
Improved QoS scheduling for Bidirectional Forwarding Detection (BFD) and BGP to address the internal handling of BGP and BFD packets under high resource constraints
|
||||||
|
|
||||||
|
## PAN-145417
|
||||||
|
|
||||||
|
Debug commands were added to address an issue where the firewall connect to Cortex Data Lake due to the Online Certificate Status Protocol (OSCP) message missing the nextUpdate value in the OSCP response.
|
||||||
|
|
||||||
|
## PAN-134461
|
||||||
|
|
||||||
|
Fixed an issue where an admin user authenticated to Panorama with RADIUS and assigned a Device Group and Template Admin role using access domains was unable to add a managed firewall to Panorama and received the following error message: Import failed user <username> does not exist.
|
||||||
|
|
||||||
|
## PAN-133863
|
||||||
|
|
||||||
|
Fixed an issue where the Panorama Virtual Appliance in Log Collector mode went into maintenance mode due to a process (reportd) not responding.
|
||||||
|
|
||||||
|
## PAN-122281
|
||||||
|
|
||||||
|
An error check process (mcelog) was added to capture hardware failure reasons detected by the processor.
|
||||||
@@ -0,0 +1,333 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 10.0.5
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-164922
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where a context switch to a managed firewall running PAN-OS 8.1.0 to PAN-OS 8.1.19 failed.
|
||||||
|
|
||||||
|
To utilize this fix, upgrade Panorama to PAN-OS 10.0.5.
|
||||||
|
|
||||||
|
## PAN-164674
|
||||||
|
|
||||||
|
Fixed a memory leak issue related to a process (mprelay) that was caused by ARP and route entries not being freed after skipping duplicate updates.
|
||||||
|
|
||||||
|
## PAN-163538
|
||||||
|
|
||||||
|
Fixed an issue on multi-dataplane platforms where traffic through Large Scale VPN (LSVPN) tunnels dropped with the error message tunnel resolution failure.
|
||||||
|
|
||||||
|
## PAN-163503
|
||||||
|
|
||||||
|
Fixed an issue on the passive firewall in a high availability (HA) configuration where a SD-WAN virtual network interface (VIF) status check caused associated static routes to be incorrectly withdrawn from the FIB.
|
||||||
|
|
||||||
|
## PAN-163489
|
||||||
|
|
||||||
|
Fixed an issue where an SD-WAN VIF was incorrectly detected as inactive during the commit time, which caused associated route withdrawal.
|
||||||
|
|
||||||
|
## PAN-163415
|
||||||
|
|
||||||
|
Fixed an issue where a memory leak related to the configd process occurred if the SD-WAN plugin was installed and many templates were configured on Panorama.
|
||||||
|
|
||||||
|
## PAN-163274
|
||||||
|
|
||||||
|
Fixed an issue where the SD-WAN hub firewall sent traffic via a VPN tunnel interface that was inactive.
|
||||||
|
|
||||||
|
## PAN-162746
|
||||||
|
|
||||||
|
Fixed an issue where DNS over TCP caused a process (dnsproxy) to run out of memory.
|
||||||
|
|
||||||
|
## PAN-162743
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not receive updates for the Device Dictionary, which caused the firewall to replace new attributes in the IP address-to-device mappings with unknown.
|
||||||
|
|
||||||
|
## PAN-162534
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls on Amazon Web Services (AWS) using a Gateway Load Balancer (GWLB) only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where when the VM-Series firewall on AWS is integrated with a GWLB, GlobalProtect did not work.
|
||||||
|
|
||||||
|
## PAN-162256
|
||||||
|
|
||||||
|
Fixed an issue where incorrect WildFire verdicts displayed on Panorama from Cortex Data Lake.
|
||||||
|
|
||||||
|
## PAN-162059
|
||||||
|
|
||||||
|
Fixed an issue where, after a new Layer 3 interface was created in PAN-OS 10.0.3 or 10.0.4, a downgrade to a PAN-OS 9.0 version failed with the error message U pstream NAT not supported in older version. This issue occurred whether SD-WAN was configured on the firewall or not.
|
||||||
|
|
||||||
|
## PAN-161767
|
||||||
|
|
||||||
|
Fixed an issue where, due to a dataplane sync issue, SD-WAN traffic was forwarded to a tunnel that was inactive.
|
||||||
|
|
||||||
|
## PAN-161745
|
||||||
|
|
||||||
|
Fixed an issue where the time-to-live (TTL) value received from the DNS server reset to 0 on DNS secure TCP transactions when anti-spyware profiles were used, which caused DNS dynamic updates to fail.
|
||||||
|
|
||||||
|
## PAN-161562
|
||||||
|
|
||||||
|
Enhanced security in how Palo Alto Networks next-generation VM-Series and PA-Series firewalls handle asymmetric traffic.
|
||||||
|
|
||||||
|
## PAN-161428
|
||||||
|
|
||||||
|
Fixed an issue where multiple restarts on a process (all_pktproc) occurred on firewalls in an active/passive HA configuration.
|
||||||
|
|
||||||
|
## PAN-160782
|
||||||
|
|
||||||
|
Fixed an issue where the routed process stopped responding when the BGP peer sent AS_PATHs with more than 255 AS numbers in all of the segments combined. There can now be a maximum of 255 AS numbers in an AS_PATH list for a prefix.
|
||||||
|
|
||||||
|
## PAN-160556
|
||||||
|
|
||||||
|
Fixed an issue that prevented decryption and IP-tag logs from being forwarded to the syslog over TCP.
|
||||||
|
|
||||||
|
## PAN-160499
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where, after an upgrade to a PAN-OS 10.0 release version, configuration pushes failed with the error Need to config WMI account and password for querying Microsoft directory servers.
|
||||||
|
|
||||||
|
## PAN-160455
|
||||||
|
|
||||||
|
A fix was made to address an issue where certain invalid URL entries contained in an External Dynamic List (EDL) caused the devsrvr process to stop responding ([CVE-2021-3048](https://security.paloaltonetworks.com/CVE-2021-3048)).
|
||||||
|
|
||||||
|
## PAN-159692
|
||||||
|
|
||||||
|
Fixed an issue where the **/dev/shm** partition increased to 100% disk usage with multiple older versions of WildFire content updates.
|
||||||
|
|
||||||
|
## PAN-159393
|
||||||
|
|
||||||
|
Fixed an issue where some TSL1.3 websites were not accessible when decryption was enabled.
|
||||||
|
|
||||||
|
## PAN-159135
|
||||||
|
|
||||||
|
Fixed an issue where the firewall rejected SAML Assertions, which caused user authentication failure when the **Validate Identity Provider Certificate** was enabled in the SAML Server Profile in vsys3 or above.
|
||||||
|
|
||||||
|
## PAN-158844
|
||||||
|
|
||||||
|
Adds additional debugging to be used in identifying the malformed references causing process crashes during FQDN refresh.
|
||||||
|
|
||||||
|
## PAN-158774
|
||||||
|
|
||||||
|
Fixed an issue where random DNS queries dropped with the counter ctd_dns_wait_pkt_drop when DNS security was enabled.
|
||||||
|
|
||||||
|
## PAN-158723
|
||||||
|
|
||||||
|
A fix was made to address an improper handling of exception conditions in the PAN-OS dataplane that enabled an unauthenticated network-based attacker to send specifically crafted traffic through the firewall that caused the service to crash ([CVE-2021-3053](https://security.paloaltonetworks.com/CVE-2021-3053)).
|
||||||
|
|
||||||
|
## PAN-158638
|
||||||
|
|
||||||
|
Fixed an issue where the firewall returned the following error message when attempting to request a device certificate using a one-time password (OTP): invalid ocsp response sig-alg.
|
||||||
|
|
||||||
|
## PAN-158585
|
||||||
|
|
||||||
|
Fixed a memory leak issue related to the X-Forwarded-For (XFF) security feature.
|
||||||
|
|
||||||
|
## PAN-158328
|
||||||
|
|
||||||
|
Fixed an issue where the firewall stopped populating the multicast FIB table with OIL entries for multicast groups.
|
||||||
|
|
||||||
|
## PAN-158293
|
||||||
|
|
||||||
|
Fixed an issue where a sudden increase in packet buffer descriptors disrupted traffic.
|
||||||
|
|
||||||
|
## PAN-158122
|
||||||
|
|
||||||
|
Fixed an issue where SNMP readings reported 0 for dataplane interface packet statistics when using PacketMMAP mode. This issue occurred because the physical port counters read from MAC addresses were reported as 0.
|
||||||
|
|
||||||
|
## PAN-157735
|
||||||
|
|
||||||
|
Fixed an issue where the new PA-7000100G network processing card (NPC) took 25 minutes to start after rebooting the PA-7080 chassis.
|
||||||
|
|
||||||
|
## PAN-157721
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped GPRS tunneling protocol (GTPv2) Create Session Requests and Responses that had IEs 201 and 202 with the error Abnormal GTPv2-C message with invalid IE.
|
||||||
|
|
||||||
|
## PAN-157346
|
||||||
|
|
||||||
|
Fixed an issue where HIP custom checks for plist failed when the HIP exclusion category were configured under (**Mobile User Template > Network > GlobalProtect > Portal<portal-config> > Agent<agent-config> > HIP Data Collection**).
|
||||||
|
|
||||||
|
## PAN-157271
|
||||||
|
|
||||||
|
Fixed an issue where **Panorama > Cloud Services** was visible to users with device group and template admin roles even if the admin role was disabled.
|
||||||
|
|
||||||
|
## PAN-157266
|
||||||
|
|
||||||
|
Fixed an issue with the logrcvr process that caused inaccurate netflow values.
|
||||||
|
|
||||||
|
## PAN-157168
|
||||||
|
|
||||||
|
Fixed an issue where a process (mprelay) stopped responding when displaying debug PDT commands
|
||||||
|
|
||||||
|
## PAN-157049
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall processed internal path monitoring packets more slowly than expected when processing large amounts of traffic, which caused the dataplane to restart.
|
||||||
|
|
||||||
|
## PAN-156982
|
||||||
|
|
||||||
|
Fixed an issue where the firewall didn't resolve domain names with multiple nested Canonical Name (CNAME) records when caching was enabled.
|
||||||
|
|
||||||
|
## PAN-156891
|
||||||
|
|
||||||
|
Fixed an issue where some zip files did not download and the following error message displayed: resources-unavailable.
|
||||||
|
|
||||||
|
## PAN-156716
|
||||||
|
|
||||||
|
Fixed an issue where the firewall sent ARP replies without checking the ingress interface when the requested IP address was configured as a destination NAT (DNAT) address.
|
||||||
|
|
||||||
|
## PAN-156498
|
||||||
|
|
||||||
|
Fixed an issue where the User-ID Agent did not reconnect after being disconnected.
|
||||||
|
|
||||||
|
## PAN-156264
|
||||||
|
|
||||||
|
Fixed an issue where the firewall displayed **IP address** **Netmask** and **default gateway** as **unknown** on the web interface as well as the CLI.
|
||||||
|
|
||||||
|
## PAN-156225
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the HA1-B port remained down after an upgrade from PAN-OS 9.1.4 to PAN-OS 9.1.5.
|
||||||
|
|
||||||
|
## PAN-155656
|
||||||
|
|
||||||
|
Fixed an issue where multicast RTP traffic triggered unicast RTP Control Protocol (RTCP), and the predict session failed to install, which blocked the parent RTP session from forwarding packets.
|
||||||
|
|
||||||
|
## PAN-155294
|
||||||
|
|
||||||
|
Fixed an issue where iPad devices did not display Authentication Portal multi-factor authentication (MFA) pages correctly when using Okta for push notifications.
|
||||||
|
|
||||||
|
## PAN-154899
|
||||||
|
|
||||||
|
Fixed an out-of-memory (OOM) issue on the firewalls that caused LACP, BGP, and OSPF to go down, resulting in the firewall not receiving LACPDU messages.
|
||||||
|
|
||||||
|
## PAN-154844
|
||||||
|
|
||||||
|
Fixed an issue where commits and autocommits repeatedly failed due to an OOM condition that disrupted the processes pan_task and devsrvr.
|
||||||
|
|
||||||
|
## PAN-154812
|
||||||
|
|
||||||
|
Fixed a memory leak issue related to a process (configd) that was caused by log queries filtering by address.
|
||||||
|
|
||||||
|
## PAN-154376
|
||||||
|
|
||||||
|
Fixed an issue where a process (mgmtsrvr) stopped responding and was inaccessible through SSH or HTTPS until the firewall was power cycled.
|
||||||
|
|
||||||
|
## PAN-154195
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped VoIP traffic over IPSec with counters flow_predict_convert_rtp_drop and flow_predict_convert_failed.
|
||||||
|
|
||||||
|
## PAN-154145
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the management plane CPU was incorrectly reported to be high.
|
||||||
|
|
||||||
|
## PAN-153614
|
||||||
|
|
||||||
|
Fixed an issue where user-based policies did not correctly match if the same user was included in both a policy with the username in NetBIOS format and another policy with the username in FQDN format.
|
||||||
|
|
||||||
|
## PAN-153213
|
||||||
|
|
||||||
|
Fixed a rare issue where TCP packets randomly dropped due to reassembly failure.
|
||||||
|
|
||||||
|
## PAN-152998
|
||||||
|
|
||||||
|
Fixed an issue where the User-ID process CPU usage remained high when a large number of Terminal Server (TS) agents were configured but only a few were connected.
|
||||||
|
|
||||||
|
## PAN-152813
|
||||||
|
|
||||||
|
Fixed an issue with configuration memory leaks on Panorama that caused a process (configd) to restart.
|
||||||
|
|
||||||
|
## PAN-152458
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls on Microsoft Hyper-V only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where, when upgrading to PAN-OS 9.0.8 or later, ethernet packets dropped after adding VLAN tags during egress from a subinterface. To leverage this fix, set the interface level maximum transmission unit (MTU) to 1496 or less.
|
||||||
|
|
||||||
|
## PAN-151808
|
||||||
|
|
||||||
|
Fixed an issue where an EDL refresh job did not complete when the configuration for EDL servers used certificate profiles, due to the large server certificates.
|
||||||
|
|
||||||
|
## PAN-151218
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the `crashinfo` file was not generated after a process (all_pktproc) stopped responding on the dataplane before path monitoring triggered a device reboot.
|
||||||
|
|
||||||
|
## PAN-150867
|
||||||
|
|
||||||
|
An enhancement was made to enable additional logging during kernel panic/oops that helps identify the cause.
|
||||||
|
|
||||||
|
## PAN-150798
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where Network Processing Cards (NPC) took longer than expected or failed to boot.
|
||||||
|
|
||||||
|
## PAN-150023
|
||||||
|
|
||||||
|
A fix was made to address an issue where an improper authentication vulnerability enabled a Security Assertion Markup Language (SAML) authenticated user to impersonate any user in the GlobalProtect portal and GlobalProtect gateway when they were configured to use SAML authentication ([CVE-2021-3046](https://security.paloaltonetworks.com/CVE-2021-3046)).
|
||||||
|
|
||||||
|
## PAN-148549
|
||||||
|
|
||||||
|
Fixed an issue where newly created interface management profiles were unable to be linked to subinterfaces.
|
||||||
|
|
||||||
|
## PAN-147783
|
||||||
|
|
||||||
|
Checks were added to help prevent the dataplane from restarting.
|
||||||
|
|
||||||
|
## PAN-147228
|
||||||
|
|
||||||
|
Fixed an issue where an application's domain name didn't resolve if the cache was disabled on the DNS Proxy object being used in the GlobalProtect Clientless VPN.
|
||||||
|
|
||||||
|
## PAN-144538
|
||||||
|
|
||||||
|
Fixed an issue where locally disabling the rule hit-count feature on Panorama caused a memory leak.
|
||||||
|
|
||||||
|
## PAN-144470
|
||||||
|
|
||||||
|
Fixed an issue where driver descriptor rings were out of sync in the control plane to dataplane direction, which caused internal path monitoring heartbeat failures.
|
||||||
|
|
||||||
|
## PAN-142473
|
||||||
|
|
||||||
|
Fixed an issue where a commit failed with the following error message: Disk quotas add up to more than 100%. Invalid configuration. due to an integration issue.
|
||||||
|
|
||||||
|
## PAN-136478
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
where syslog forwarding over TCP did not work in a multi-vsys environment.
|
||||||
|
|
||||||
|
## PAN-136347
|
||||||
|
|
||||||
|
Fixed an issue wherer DNS proxy TCP connections were processed incorrectly, which caused a process (dnsproxy) to stop responding.
|
||||||
|
|
||||||
|
## PAN-134799
|
||||||
|
|
||||||
|
Fixed an issue where packets of the same session were forwarded through a different member of an Aggregate Ethernet (AE) group once the session was offloaded.
|
||||||
|
|
||||||
|
## PAN-129927
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where firewalls with Layer 3 subinterfaces reset Class of Service (CoS) bits in 802.1q.
|
||||||
@@ -0,0 +1,319 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 10.0.6
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-168298
|
||||||
|
|
||||||
|
Fixed an issue where a firewall superuser using an LDAP authentication profile that was pushed from Panorama was unable to save the filter under **Monitor > Logs**.
|
||||||
|
|
||||||
|
## PAN-167401
|
||||||
|
|
||||||
|
Fixed an issue where, when a firewall or Panorama appliance configured with a proxy was upgraded to PAN-OS 10.0.3 or a later release, it failed to connect to edge service.
|
||||||
|
|
||||||
|
## PAN-166994
|
||||||
|
|
||||||
|
Fixed an issue where the management failed to publish custom metrics to cloud monitoring tools, which caused pod auto-scaling to not work.
|
||||||
|
|
||||||
|
## PAN-166677
|
||||||
|
|
||||||
|
Fixed an issue on the firewall where a process (devsrvr) stopped responding during a commit.
|
||||||
|
|
||||||
|
## PAN-166570
|
||||||
|
|
||||||
|
Fixed an issue where authentication failure messages were overwritten when a commit was in progress.
|
||||||
|
|
||||||
|
## PAN-166306
|
||||||
|
|
||||||
|
Fixed an issue where commit jobs failed when validating HIP objects and profiles.
|
||||||
|
|
||||||
|
## PAN-166241
|
||||||
|
|
||||||
|
A fix was made to address an improper restriction of XML external identity (XXE) reference in the PAN-OS web interface that enabled an authenticated administrator to read any arbitrary file from the file system and send a specifically crafted request to the firewall that caused the service to crash ([CVE-2021-3055](https://security.paloaltonetworks.com/CVE-2021-3055)).
|
||||||
|
|
||||||
|
## PAN-165194
|
||||||
|
|
||||||
|
Fixed an issue where multiple messages were exchanged between secondary and primary Data Plane Development Kit (DPDK) processes, which caused a process (brdagent) to stop responding.
|
||||||
|
|
||||||
|
## PAN-164846
|
||||||
|
|
||||||
|
Fixed an issue where packet buffers were depleted.
|
||||||
|
|
||||||
|
## PAN-164564
|
||||||
|
|
||||||
|
Fixed an issue where stats API attempted to get stats from an unavailable port.
|
||||||
|
|
||||||
|
## PAN-164328
|
||||||
|
|
||||||
|
Fixed an issue where the firewall incorrectly dropped GPRS tunneling protocol (GTPv2) Bearer Resource Failure Indication messages with the following error message: Abnormal GTPv2-C message with missing mandatory IE.
|
||||||
|
|
||||||
|
## PAN-164094
|
||||||
|
|
||||||
|
Fixed an issue where two process (devsrvr and useridd) did not synchronize IP tags, which caused Dynamic Address Groups to not populate.
|
||||||
|
|
||||||
|
## PAN-163261
|
||||||
|
|
||||||
|
Fixed an intermittent issue where the firewall dropped GTPv2 Modify Bearer Request packets with the following error message: Abnormal GTPv2-C message with missing mandatory IE.
|
||||||
|
|
||||||
|
## PAN-162663
|
||||||
|
|
||||||
|
Fixed an intermittent issue on the firewall where packets dropped in decrypted SSL/TLS sessions.
|
||||||
|
|
||||||
|
## PAN-162594
|
||||||
|
|
||||||
|
Fixed an issue where blank configuration for tokens in a content-driven FreeDNS Afraid.org Dynamic API v1 DDNS configuration were not enabled.
|
||||||
|
|
||||||
|
## PAN-161499
|
||||||
|
|
||||||
|
Fixed an issue where, after an upgrade from PAN-OS 9.1.5 to PAN-OS 10.0.3, Panorama admin sessions were created with 30 days to expire on the firewalls.
|
||||||
|
|
||||||
|
## PAN-161112
|
||||||
|
|
||||||
|
Fixed an issue where a process (useridd) repeatedly exceeded the virtual memory limit, which caused the process to stop responding.
|
||||||
|
|
||||||
|
## PAN-160939
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped GTPv1 Forward Relocation Requests with the following error message: Abnormal GTP-U message with invalid IE.
|
||||||
|
|
||||||
|
## PAN-160870
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
ZTP-capable firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the default Zero Touch Provisioning (ZTP) configuration was still present on the firewall even when ZTP was disabled, which caused commit failures.
|
||||||
|
|
||||||
|
## PAN-160744
|
||||||
|
|
||||||
|
Fixed an issue where the negative time difference between the dataplane and the management plane during the client certificate info check prevented the GlobalProtect client from connecting to the GlobalProtect gateway with the following error message: Required client certificate not found.
|
||||||
|
|
||||||
|
## PAN-160434
|
||||||
|
|
||||||
|
Fixed an issue where firewalls stopped processing Layer-3-tagged traffic after Panorama pushed VLAN sub-interface configurations to the firewall with the **commit_all** operation.
|
||||||
|
|
||||||
|
## PAN-159944
|
||||||
|
|
||||||
|
Fixed an issue where a process (dnsproxyd) stopped responding due to an error in the DNS cache operation.
|
||||||
|
|
||||||
|
## PAN-159936
|
||||||
|
|
||||||
|
Fixed an issue where BGP route stopped advertising a redistribute route when a similar new redistribute route was configured.
|
||||||
|
|
||||||
|
## PAN-159054
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to add more than 500 DHCP relay agent objects in the firewall templates from Panorama.
|
||||||
|
|
||||||
|
## PAN-158972
|
||||||
|
|
||||||
|
Fixed an issue on the firewall where a process (useridd) stopped responding and generated a core dump after being restarted by the administrator.
|
||||||
|
|
||||||
|
## PAN-158407
|
||||||
|
|
||||||
|
Fixed an issue where configuring the BGP export policy with the match criteria set to next hops, redistributed connected routes incorrectly matched this criteria.
|
||||||
|
|
||||||
|
## PAN-158262
|
||||||
|
|
||||||
|
A buffer overflow vulnerability in the Telnet-based administrative management service included with PAN-OS software allows remote attackers to execute arbitrary code.
|
||||||
|
|
||||||
|
A fix was made to address a buffer overflow vulnerability in the Telnet-based administrative management service included with PAN-OS that allowed a remote attacker to execute arbitrary code ([CVE-2020-10188](https://security.paloaltonetworks.com/CVE-2020-10188)).
|
||||||
|
|
||||||
|
## PAN-158036
|
||||||
|
|
||||||
|
Fixed an issue on the firewall where custom application signatures based on PROPFIND http-method didn't trigger if webdav application ID was blocked by a Security policy.
|
||||||
|
|
||||||
|
Note: To utilize this fix, you must install content version 8367-6513 or later.
|
||||||
|
|
||||||
|
## PAN-157964
|
||||||
|
|
||||||
|
Fixed an issue where adding a container application from the **Apps Seen** list did not remove the child application from the list.
|
||||||
|
|
||||||
|
## PAN-157834
|
||||||
|
|
||||||
|
Fixed an issue with missing zone entries in CSV or PDF export files.
|
||||||
|
|
||||||
|
## PAN-157479
|
||||||
|
|
||||||
|
Fixed an issue on the firewall where a process (useridd) stopped responding when group-mapping profiles were configured with an LDAP server profile with the type **e-dictionary**.
|
||||||
|
|
||||||
|
## PAN-157447
|
||||||
|
|
||||||
|
Fixed an issue where a process (flow_mgmt) repeatedly restarted with a segmentation violation (SIGSEGV) signal and the following trace: flow_mgmt:pan_flow_dos_ager_invoke pan_sw_timer_100ms pan_sw_timer_invoke.
|
||||||
|
|
||||||
|
## PAN-157311
|
||||||
|
|
||||||
|
Fixed an issue where, if the **OK** button is clicked before tags are loaded when editing an address object that contained tags via the firewall web interface, associated tags are removed.
|
||||||
|
|
||||||
|
## PAN-157238
|
||||||
|
|
||||||
|
Fixed an issue where, when a non-SAML authentication policy was used, the SAML **Use Single Sign-On** option was displayed.
|
||||||
|
|
||||||
|
## PAN-157136
|
||||||
|
|
||||||
|
Fixed an issue where a memory leak associated with a process (pan_dha) caused an OOM condition on the firewall due to a configuration sync triggered by a commit on an HA cluster.
|
||||||
|
|
||||||
|
## PAN-156896
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall frequently stopped responding with the following log: CONFIG_UPDATE_INC : Incremental update to DP failed please try to commit force the latest config.
|
||||||
|
|
||||||
|
## PAN-156669
|
||||||
|
|
||||||
|
Fixed an issue in Panorama where, when a variable object description was set, the description was automatically copied to template description.
|
||||||
|
|
||||||
|
## PAN-156396
|
||||||
|
|
||||||
|
Fixed an issue where the CTD queue was full, which caused traffic to be dropped with the counter ctd_exceed_pkt_limit.
|
||||||
|
|
||||||
|
## PAN-156380
|
||||||
|
|
||||||
|
Fixed an issue where running show commands related to SD-WAN caused a process (pan_comm) to stop responding.
|
||||||
|
|
||||||
|
## PAN-156199
|
||||||
|
|
||||||
|
Fixed an issue where, in the **Email Scheduler** (**Monitor > PDF Reports**), the **Recurrence** parameter unexpectedly changed from **Daily** to **Disable** when the web interface language was not English.
|
||||||
|
|
||||||
|
## PAN-156113
|
||||||
|
|
||||||
|
Fixed an issue where the management interface incorrectly used the configured default gateway for local network traffic when service routes were configured.
|
||||||
|
|
||||||
|
## PAN-156098
|
||||||
|
|
||||||
|
Fixed an issue where netflow packets sent from the firewall contained excess padding, which resulted in the packet length exceeding 1400 bytes.
|
||||||
|
|
||||||
|
## PAN-156001
|
||||||
|
|
||||||
|
Fixed an issue where the downloaded GTP event packet capture from **Monitor > Logs > GTP** displayed a different packet than the one that actually triggered the event.
|
||||||
|
|
||||||
|
## PAN-155772
|
||||||
|
|
||||||
|
Fixed an issue where the Panorama web interface did not display the secondary IP address configuring it under the template stack.
|
||||||
|
|
||||||
|
## PAN-155758
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
7000-Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where, when a subinterface was configured as a Log Card interface, the commit failed unless an IP address was assigned to the parent interface.
|
||||||
|
|
||||||
|
## PAN-155593
|
||||||
|
|
||||||
|
Fixed an issue where the firewall was unable to match HIP objects with a 3-digit code version.
|
||||||
|
|
||||||
|
## PAN-155457
|
||||||
|
|
||||||
|
Fixed an issue where PAN-OS custom logos were not uploaded due to the upper case file extensions.
|
||||||
|
|
||||||
|
## PAN-155147
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls on Microsoft Azure that use accelerated networking interfaces with DPDK mode
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where hot plug notifications caused traffic disruption.
|
||||||
|
|
||||||
|
## PAN-155126
|
||||||
|
|
||||||
|
Fixed an issue where editing the LDAP server IP address (**Device > Templates > Server Profiles > LDAP > LDAP Server Profile**) removed the bind password.
|
||||||
|
|
||||||
|
## PAN-155049
|
||||||
|
|
||||||
|
Fixed an issue with SSLVPN memory leaks related to the GlobalProtect portal **Config Selection Criteria**.
|
||||||
|
|
||||||
|
## PAN-154820
|
||||||
|
|
||||||
|
Fixed an issue where policy-based forwarding (PBF) monitoring failed when the egress interface was a tunnel.
|
||||||
|
|
||||||
|
## PAN-154603
|
||||||
|
|
||||||
|
Fixed an issue where, when SSL/TLS was required, LDAP server authentication attempted StartTLS first.
|
||||||
|
|
||||||
|
## PAN-154602
|
||||||
|
|
||||||
|
Fixed an issue where GlobalProtect users got disconnected after modifying floating IP HA configuration.
|
||||||
|
|
||||||
|
## PAN-154571
|
||||||
|
|
||||||
|
Fixed an issue where, if source-ip-enforcement.enable was true, GlobalProtect configurations on the template stack level were unable to be modified, and the schema used the default choice.
|
||||||
|
|
||||||
|
## PAN-154557
|
||||||
|
|
||||||
|
Fixed an issue that caused a process (useridd) core dump when parsing the Subject Alternative Name from a client certificate sent in the HIP report.
|
||||||
|
|
||||||
|
## PAN-154487
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect log description field size decreased.
|
||||||
|
|
||||||
|
## PAN-154403
|
||||||
|
|
||||||
|
Fixed an issue with HIP matching logic for missing patches where previous behavior indicated missing patches when no patches were missing.
|
||||||
|
|
||||||
|
## PAN-154109
|
||||||
|
|
||||||
|
Fixed an issue where using XML special characters in the **Uninstalled GlobalProtect APP** password in the application configuration (**Networks > GlobalProtect > Portals > Agent > App**) disrupted portal connectivity.
|
||||||
|
|
||||||
|
## PAN-153816
|
||||||
|
|
||||||
|
Fixed an issue where the firewall booted up in Extensible Firmware Interface (EFI) Shell when performing factory reset with selected image file.
|
||||||
|
|
||||||
|
## PAN-153592
|
||||||
|
|
||||||
|
Fixed an issue where, after upgrading Panorama from PAN-OS 8.1.9 to PAN-OS 9.1.3, the option to preview changes for dynamic address groups or templates from Panorama did not work.
|
||||||
|
|
||||||
|
## PAN-153316
|
||||||
|
|
||||||
|
CLI commands were added to address an issue where virtual memory on a process (configd) exceeded the new 32G limit. -To disable the virtual memory limit, use debug software disable-virt-limit. -To enable the virtual memory limit, use debug software enable-virt-limit.
|
||||||
|
|
||||||
|
## PAN-152497
|
||||||
|
|
||||||
|
Fixed an issue where the firewall was unable to create a new GTP-U session when it received Create Session Response messages, which caused the following error message to display in the GTP log: GTPv1 message failed stateful inspection.
|
||||||
|
|
||||||
|
## PAN-151521
|
||||||
|
|
||||||
|
Fixed an issue where a process (logrcvr) continuously restarted at pan_hash_iter_next_i.
|
||||||
|
|
||||||
|
## PAN-151395
|
||||||
|
|
||||||
|
Fixed an issue where the firewall repeatedly logged connection failures to a configured Log Collector.
|
||||||
|
|
||||||
|
## PAN-150298
|
||||||
|
|
||||||
|
Fixed an issue where Android clients matched HIP objects configured for Apple products.
|
||||||
|
|
||||||
|
## PAN-149867
|
||||||
|
|
||||||
|
Fixed an issue where a process (authd) ignored null domain authentication profiles in a sequence and only returned non-null domains to GlobalProtect.
|
||||||
|
|
||||||
|
## PAN-149853
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where the **loc** attribute was not set as **shared** when creating dynamic-address-group-specific configurations during a Panorama commit.
|
||||||
|
|
||||||
|
## PAN-147827
|
||||||
|
|
||||||
|
Fixed an issue where, when SIP traffic traversing the firewall was sent with a high QoS Differentiated Services Code Point (DSCP) value, the DSCP value was reset to the default setting (CS0).
|
||||||
|
|
||||||
|
## PAN-147081
|
||||||
|
|
||||||
|
Fixed an issue where routes learned from the GlobalProtect Large Scale VPN (LSVPN) Gateway were cleared from the routing table when ECMP was toggled (enabled or disabled).
|
||||||
|
|
||||||
|
## PAN-146048
|
||||||
|
|
||||||
|
Fixed an issue where a satellite firewall was unable to authenticate to a LSVPN gateway when the issued certificate from Simple Certificate Enrollment Protocol (SCEP) had encryption bits set to 3072. With this fix, the maximum private key size of 3072 bits, along with the 1024-bit size and the 2048-bit size, is able to authenticate when selected to create the SCEP profile.
|
||||||
|
|
||||||
|
## PAN-142621
|
||||||
|
|
||||||
|
Fixed an issue where the firewall was unable to log debug information in case of kernel panic.
|
||||||
|
|
||||||
|
## PAN-140243
|
||||||
|
|
||||||
|
Fixed an issue where non-web-based traffic that was part of the User-ID zone exclude list still matched the configured authentication policy.
|
||||||
|
|
||||||
|
## PAN-134007
|
||||||
|
|
||||||
|
Fixed an issue where the Log Forwarding Card (LFC) advertised the wrong MAC Address to the connected switch.
|
||||||
@@ -0,0 +1,587 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 10.0.7
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## WF500-5568
|
||||||
|
|
||||||
|
Fixed an issue where a firewall in FIPS mode running PAN-OS 8.1.18 or a later version failed to connect with a WildFire appliance in normal mode.
|
||||||
|
|
||||||
|
## WF500-5559
|
||||||
|
|
||||||
|
Fixed an issue where an intermittent error while analyzing signed PE samples on the WildFire appliance might have caused analysis failures.
|
||||||
|
|
||||||
|
## WF500-5509
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
WF-500 appliance only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where cloud inquiries were logged under the **SD-WAN** subtype.
|
||||||
|
|
||||||
|
## PAN-173080
|
||||||
|
|
||||||
|
Fixed an issue where the User-ID connection limit was reached even when only a few User-ID agents were connected to the service.
|
||||||
|
|
||||||
|
## PAN-172518
|
||||||
|
|
||||||
|
Fixed an issue where a race condition occurred and caused a process (useridd) to restart.
|
||||||
|
|
||||||
|
## PAN-172125
|
||||||
|
|
||||||
|
Fixed an intermittent issue where processing HIP messages in the (useridd) process caused a memory leak.
|
||||||
|
|
||||||
|
## PAN-171878
|
||||||
|
|
||||||
|
Fixed an issue with SD-WAN path selection logic that caused a dataplane to stop responding.
|
||||||
|
|
||||||
|
## PAN-171442
|
||||||
|
|
||||||
|
Fixed an issue on Amazon Web Services (AWS) Gateway Load Balancer (GWLB) deployments with overlay routing and cross-zone load balancing enabled where packets were forwarded to the incorrect GWLB interface.
|
||||||
|
|
||||||
|
## PAN-171203
|
||||||
|
|
||||||
|
Fixed an issue in a high availability (HA) configuration where, when one firewall was active and its peer was in a suspended state, the suspended firewall continued to send traffic, which triggered the detection of duplicate MAC addresses.
|
||||||
|
|
||||||
|
## PAN-170989
|
||||||
|
|
||||||
|
Fixed an issue memory usage consumption issue on a process (useridd).
|
||||||
|
|
||||||
|
## PAN-170932
|
||||||
|
|
||||||
|
Fixed an issue in Telemetry settings where the **OK** button was disabled when **Telemetry Region** was set to **None**.
|
||||||
|
|
||||||
|
## PAN-170825
|
||||||
|
|
||||||
|
Fixed an issue where, when a partial **Preview Change** job failed, a process (configd) stopped responding.
|
||||||
|
|
||||||
|
## PAN-170740
|
||||||
|
|
||||||
|
Fixed an issue with the google-docs-uploading application that occurred if a Security policy rule was applied to a Security profile and traffic was decrypted.
|
||||||
|
|
||||||
|
## PAN-170681
|
||||||
|
|
||||||
|
Fixed an issue where the data redistribution agent and the data redistribution client failed to connect due to the agent not sending a SSL Server hello response.
|
||||||
|
|
||||||
|
## PAN-170610
|
||||||
|
|
||||||
|
Fixed an issue where SD-WAN SaaS monitoring traffic was incorrectly dropped by a Security policy that included a deny rule.
|
||||||
|
|
||||||
|
## PAN-170314
|
||||||
|
|
||||||
|
Fixed an issue where PAN-DB URL cloud updates failed because a process (devsrvr) did not fetch serial numbers, which prevented the PAN_DB URL cloud from connecting after first deployment.
|
||||||
|
|
||||||
|
## PAN-170083
|
||||||
|
|
||||||
|
Fixed an intermittent issue where packet pointer corruption occurred, which resulted in a dataplane restart.
|
||||||
|
|
||||||
|
## PAN-169712
|
||||||
|
|
||||||
|
Fixed an intermittent issue where traffic falsely matched a converted Suricata rule.
|
||||||
|
|
||||||
|
## PAN-169197
|
||||||
|
|
||||||
|
Fixed a rare issue where generating a tech support file caused the useridd process to stop responding.
|
||||||
|
|
||||||
|
## PAN-169161
|
||||||
|
|
||||||
|
Fixed an issue where, after a pan_comm process restart, the configuration wasn't synced between the management and the dataplane pod.
|
||||||
|
|
||||||
|
## PAN-169064
|
||||||
|
|
||||||
|
Fixed an issue where the management CPU remained at 100% due to a large number of configured User-ID agents.
|
||||||
|
|
||||||
|
## PAN-168888
|
||||||
|
|
||||||
|
Fixed an issue where, when a maximum session count was configured, the SD-WAN plugin caused commit failures on Panorama.
|
||||||
|
|
||||||
|
## PAN-168718
|
||||||
|
|
||||||
|
Fixed an issue where, when a client or server received partial application data, the record was partially processed by legacy code. This caused decryption to fail when a decryption profile protocol was set to a maximum of TLSv1.3.
|
||||||
|
|
||||||
|
## PAN-168574
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where, after an upgrade to a PAN-OS 10.0 release version, a configuration pushed to firewalls running on PAN-OS 9.1 failed during an autocommit with the following error message: Need to config WMI account and password for querying Microsoft directory servers.
|
||||||
|
|
||||||
|
## PAN-168418
|
||||||
|
|
||||||
|
Fixed an issue where, when an MLAV URL with an exception list was configured and forward proxy was enabled, a process (all_pktproc) repeatedly restarted, which resulted in the firewall rebooting.
|
||||||
|
|
||||||
|
## PAN-167989
|
||||||
|
|
||||||
|
Fixed a timing issue between downloading and installing threads that occurred when Panorama pushed content updates and the firewall fetched content updates simultaneously.
|
||||||
|
|
||||||
|
## PAN-167872
|
||||||
|
|
||||||
|
Fixed an issue related to a process (all_pktproc) that occurred in long-lived sessions that spanned two content upgrades.
|
||||||
|
|
||||||
|
## PAN-167637
|
||||||
|
|
||||||
|
Fixed an issue where users connecting to the US East gateway encountered a delay in DNS responses.
|
||||||
|
|
||||||
|
## PAN-167541
|
||||||
|
|
||||||
|
Fixed an issue where large External Dynamic Lists (EDLs) caused commit issues due to a hard limit being reached.
|
||||||
|
|
||||||
|
## PAN-167443
|
||||||
|
|
||||||
|
Fixed an issue where commits failed and generated pan_comm SIGSEGV CORE files.
|
||||||
|
|
||||||
|
## PAN-167306
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls on Microsoft Azure only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where, when a second disk was added, /opt/panlogs was mounted on an incorrect partition.
|
||||||
|
|
||||||
|
## PAN-167099
|
||||||
|
|
||||||
|
Fixed a configuration management issue that resulted in a process (ikemgr) failing to recognize changes in subsequent commits.
|
||||||
|
|
||||||
|
## PAN-167098
|
||||||
|
|
||||||
|
Fixed an issue where a configd process memory corruption occurred when Panorama was exposed to multiple XML API calls on Dynamic Address Groups updates.
|
||||||
|
|
||||||
|
## PAN-166836
|
||||||
|
|
||||||
|
Fixed an issue where session failed due to resource unavailability.
|
||||||
|
|
||||||
|
## PAN-166572
|
||||||
|
|
||||||
|
Fixed an issue where a process (configd) restarted when browsing policies on Panorama.
|
||||||
|
|
||||||
|
## PAN-166420
|
||||||
|
|
||||||
|
In 10.0.x Query Traffic log option is missing for Address groups under source and destination in the security policy tab
|
||||||
|
|
||||||
|
## PAN-166328
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls with NPCs only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where path monitoring failure occurred while hot inserting a 100G NPC (network processing card) into the firewall.
|
||||||
|
|
||||||
|
## PAN-166296
|
||||||
|
|
||||||
|
Fixed an issue where an unavailable certificate revocation list (CRL) from the server side caused an infinite loop on a process (sslmgr), which resulted in it not responding for other tasks.
|
||||||
|
|
||||||
|
## PAN-166021
|
||||||
|
|
||||||
|
Fixed an issue where log queries that included a username did not return with any output.
|
||||||
|
|
||||||
|
## PAN-165661
|
||||||
|
|
||||||
|
Fixed an issue in an HA active/active configuration where an administrative shutdown message was not sent to the BGP peer when the firewall went into a suspended state, which delayed convergence.
|
||||||
|
|
||||||
|
## PAN-165399
|
||||||
|
|
||||||
|
Fixed an issue where the multi-factor authentication (MFA) Challenge message did not display during login when the GlobalProtect portal was accessed by the web browser.
|
||||||
|
|
||||||
|
## PAN-165235
|
||||||
|
|
||||||
|
Fixed an issue where the handover handling between LTE and 3G on S5 and S8 to Gn/Gp was not working properly and led to stateful inspection failures.
|
||||||
|
|
||||||
|
## PAN-165025
|
||||||
|
|
||||||
|
Fixed an issue where, when default interzone and intrazone Security policy rules were overwritten, the rules did not display hit counts.
|
||||||
|
|
||||||
|
## PAN-164646
|
||||||
|
|
||||||
|
Fixed an issue where tunnel monitoring in the Large Scale VPN (LSVPN) displayed as down in both the CLI and the web interface due to incorrect dataplane ownership.
|
||||||
|
|
||||||
|
## PAN-164571
|
||||||
|
|
||||||
|
Fixed an issue where DHCP leases were not properly synchronized between HA peers after a device or dhcpd process restart. With this fix, the DHCP lease details display correctly on both the active and the passive device.
|
||||||
|
|
||||||
|
## PAN-164446
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where a commit failed with the following error message: Local-AS number does not fit in 2-byte AS format, even though the AS format was set to 4 bytes.
|
||||||
|
|
||||||
|
## PAN-164431
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall rebooted into maintenance mode after installing a capacity license in FIPS-CC mode.
|
||||||
|
|
||||||
|
## PAN-164392
|
||||||
|
|
||||||
|
Fixed an issue where an out-of-memory (OOM) condition occurred due to a memory leak related to a process (logrcvr).
|
||||||
|
|
||||||
|
## PAN-164338
|
||||||
|
|
||||||
|
Fixed an issue where, when using the CLI or API, configurations for policy rule services or applications that either used custom settings and default settings together, or used multiple default settings together, successfully commit instead of failing or displaying a warning.
|
||||||
|
|
||||||
|
**Note** To use this fix, you must delete previous application or service settings in the configuration.
|
||||||
|
|
||||||
|
## PAN-164056
|
||||||
|
|
||||||
|
Fixed a memory issue for Large Scale VPN with multiple dataplane systems.
|
||||||
|
|
||||||
|
## PAN-163940
|
||||||
|
|
||||||
|
Fixed an issue where the firewall truncated the application name when doing a NetFlow export to the NetFlow analyzer.
|
||||||
|
|
||||||
|
## PAN-163800
|
||||||
|
|
||||||
|
Fixed an intermittent issue where the presence of an Anti-Spyware profile in a Security policy rule that matched DNS traffic caused DNS responses to be malformed in transit.
|
||||||
|
|
||||||
|
## PAN-163280
|
||||||
|
|
||||||
|
Fixed an issue where, after upgrading to a PAN-OS 10.0 release version, a commit failed due to an admin-role-related validation error that displayed the following message: device unexpected here.
|
||||||
|
|
||||||
|
## PAN-163270
|
||||||
|
|
||||||
|
Fixed an issue where the login banner was not aligned properly when it contained multiple sequential whitespaces.
|
||||||
|
|
||||||
|
## PAN-162600
|
||||||
|
|
||||||
|
Fixed an issue where, when the GlobalProtect client sent UDP/4501 traffic that was destined for the GlobalProtect gateway inside the GlobalProtect tunnel, the firewall still processed the traffic, which caused routing loops.
|
||||||
|
|
||||||
|
## PAN-161869
|
||||||
|
|
||||||
|
Fixed an issue where a core dump occurred on a process (flow_ctrl) after a commit if a policy-based forwarding (PBF) rule referenced an interface that had a DHCP IP address assignment.
|
||||||
|
|
||||||
|
## PAN-161289
|
||||||
|
|
||||||
|
Fixed an issue where predict session didn't update the associated rules when Security policies shifted after a commit.
|
||||||
|
|
||||||
|
## PAN-161218
|
||||||
|
|
||||||
|
The following CLI commands were added to enable the customer to set the dataplane utilization limit. The default setting is the recommended value of 500; a value of 0 removes dataplane CTD limits: -debug dataplane show ctd wildfire max -debug dataplane set ctd wildfire max <0-5000>
|
||||||
|
|
||||||
|
## PAN-161025
|
||||||
|
|
||||||
|
Fixed an issue in Panorama where an administrator with the role of Panorama administrator did not have the option to download or install GlobalProtect clients (**Panorama > Device Deployment > GlobalProtect**).
|
||||||
|
|
||||||
|
## PAN-160997
|
||||||
|
|
||||||
|
Fixed an issue where the metadata from the firewall's authentication profile was unable to export. This issue occurred when the authentication profile and the SAML Identity Provider sever profile were created with **VSYS** in the **Location**and were pushed from Panorama template stack values. To utilize this fix, you must upgrade both Panorama and the firewall.
|
||||||
|
|
||||||
|
## PAN-160843
|
||||||
|
|
||||||
|
Fixed an issue where the Multiprotocol Label Switching (MPLS) interface wasn't monitored when private traffic wasn't VPN encapsulated.
|
||||||
|
|
||||||
|
## PAN-160831
|
||||||
|
|
||||||
|
Fixed an intermittent issue where importing a new firewalls configuration into Panorama failed due to conflicting virtual system (vsys) names, even when the **Device Group Name Prefix** was used to make the name unique.
|
||||||
|
|
||||||
|
## PAN-160818
|
||||||
|
|
||||||
|
Fixed an issue where Panorama repeatedly displayed the following error message: HA Failover: updates not received from all sources: Pending plugins.
|
||||||
|
|
||||||
|
## PAN-160540
|
||||||
|
|
||||||
|
Fixed an issue where tunnel traffic was dropped intermittently when Quality of Service (QoS) Profile was assigned but the profile had no limits defined.
|
||||||
|
|
||||||
|
## PAN-160432
|
||||||
|
|
||||||
|
Fixed an issue where, after selecting a PAN-OS release to upgrade to in **Device Association > To SW Version**, the upgrade failed after connecting to Panorama.
|
||||||
|
|
||||||
|
## PAN-160254
|
||||||
|
|
||||||
|
Fixed a memory leak issue related to a process (reportd) where memory was not freed after an ElasticSearch request.
|
||||||
|
|
||||||
|
## PAN-160253
|
||||||
|
|
||||||
|
Fixed an issue where only one medium-severity system log was generated if either the EDL file wasn't updated at the remote end or the downloaded file wasn't a text file.
|
||||||
|
|
||||||
|
## PAN-160247
|
||||||
|
|
||||||
|
Fixed an issue where system logs incorrectly displayed as **Critical**.
|
||||||
|
|
||||||
|
## PAN-160238
|
||||||
|
|
||||||
|
Fixed an issue where intermittent virtual extensible LAN (VXLAN) packet drops occurred if the TCI was not configured for inspecting VXLAN traffic. This issue occurred when traffic was migrated from a firewall running a PAN-OS version earlier than PAN-OS 9.0 to a firewall running PAN-OS 9.0 or later.
|
||||||
|
|
||||||
|
## PAN-160150
|
||||||
|
|
||||||
|
Fixed an intermittent issue where, when a race condition occurred, a process (rasmgr) stopped responding, which caused GlobalProtect user authentication failure.
|
||||||
|
|
||||||
|
## PAN-160053
|
||||||
|
|
||||||
|
Fixed an issue in Panorama where a process (configd) stopped responding due to a race condition in the mongodb process.
|
||||||
|
|
||||||
|
## PAN-159973
|
||||||
|
|
||||||
|
Fixed an issue where a local commit in the Panorama management server caused the status to get out of sync on the managed WildFire appliance.
|
||||||
|
|
||||||
|
## PAN-159700
|
||||||
|
|
||||||
|
Fixed an issue where importing PAN-TRAPS.my to the SNMP manager caused the following error to display: Registration failed, registration failed, because there are unreferenced definition names in the MIB file.
|
||||||
|
|
||||||
|
## PAN-159592
|
||||||
|
|
||||||
|
Fixed an issue where a Japanese keyword search displayed garbled characters during SAML authentication.
|
||||||
|
|
||||||
|
## PAN-159536
|
||||||
|
|
||||||
|
Fixed an issue where, when the CLI command oscp-exclude-nonce-yes was enabled for a certificate profile, a nonce value was still included in the Online Certificate Status Protocol (OCSP) request.
|
||||||
|
|
||||||
|
## PAN-159499
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to select the configured QoS profile under the template stack.
|
||||||
|
|
||||||
|
## PAN-159293
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the Certification Revocation List (CRL) in Distinguished Encoding Rules (DER) format incorrectly returned errors despite being able to successfully pull the CRL to verify that the syslog server certificate was still valid.
|
||||||
|
|
||||||
|
## PAN-159224
|
||||||
|
|
||||||
|
Fixed an memory leak issue related to a process (mgmtsrvr), which was caused by a certificate loading operation.
|
||||||
|
|
||||||
|
## PAN-159214
|
||||||
|
|
||||||
|
Fixed an issue where a .txt file was corrupted, which caused the web interface to not display the requested information.
|
||||||
|
|
||||||
|
## PAN-159122
|
||||||
|
|
||||||
|
Fixed an issue where, when a new tag was created, a custom application with the same name was also created.
|
||||||
|
|
||||||
|
## PAN-158932
|
||||||
|
|
||||||
|
Fixed an issue where an increase was observed on spyware_state, which caused latency.
|
||||||
|
|
||||||
|
## PAN-158654
|
||||||
|
|
||||||
|
Fixed a memory leak issue in the management server process.
|
||||||
|
|
||||||
|
## PAN-158649
|
||||||
|
|
||||||
|
Fixed an issue where commits to the Prisma Access Remote networks from Panorama were failing when the management server on the cloud firewall failed to exit cleanly and reported the following error: pan_check_cert_status(pan_crl_ocsp.c:284): sysd write failed (TIMEOUT)
|
||||||
|
|
||||||
|
## PAN-158639
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where logs that were forwarded to a collector group did not appear, and the log collector displayed the following error message: es.init-status not ready in logjobq.
|
||||||
|
|
||||||
|
## PAN-158450
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where, for SNMPv2-MIB:sysServices, snmpwalk returned the following error message: No Such Instance currently exists at this OID.
|
||||||
|
|
||||||
|
## PAN-158372
|
||||||
|
|
||||||
|
Fixed a buffer overflow issue related to the useridd process.
|
||||||
|
|
||||||
|
## PAN-158337
|
||||||
|
|
||||||
|
Fixed an issue where warnings displayed during a commit or validate when BGP peers used in an import/export rule were disabled.
|
||||||
|
|
||||||
|
## PAN-158161
|
||||||
|
|
||||||
|
Fixed an issue where the policy-based forwarding (PBF) monitor was failing on the tunnel interface when QoS was enabled.
|
||||||
|
|
||||||
|
## PAN-158119
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where TFTP traffic with a high packet rate was not offloaded even after hitting an application override policy with a custom application.
|
||||||
|
|
||||||
|
## PAN-158020
|
||||||
|
|
||||||
|
Fixed an issue where HIP reports were not visible on the web interface due to a domain override configuration.
|
||||||
|
|
||||||
|
## PAN-157938
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls with multiple DHCP interfaces only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where leases renewed more quickly than needed, which caused unnecessary SPF recalculations.
|
||||||
|
|
||||||
|
## PAN-157908
|
||||||
|
|
||||||
|
Fixed an issue where false system alarms for the IP tag log database exceeded the alarm threshold value.
|
||||||
|
|
||||||
|
## PAN-157903
|
||||||
|
|
||||||
|
Fixed an issue where the **To** field of an email was truncated in threat logs when the field of the original email exceeded 512 bytes.
|
||||||
|
|
||||||
|
## PAN-157835
|
||||||
|
|
||||||
|
Fixed an issue where DNS Proxy rules that contained uppercase characters were not normalized to lowercase, which prevented the rules from being matched.
|
||||||
|
|
||||||
|
## PAN-157715
|
||||||
|
|
||||||
|
Fixed an intermittent issue where SMB file transfer operations failed due to packet drops that were caused by the Content and Threat Detection (CTD) queue filling up quickly. This fix introduces a new CLI command which, when enabled, prevents these failures: set system setting ctd nonblocking-pattern-match-qsizecheck [enable|disable].
|
||||||
|
|
||||||
|
## PAN-157632
|
||||||
|
|
||||||
|
Fixed an intermittent issue where the firewall dropped GTP-U traffic with the message TEID=0x00000000.
|
||||||
|
|
||||||
|
## PAN-157570
|
||||||
|
|
||||||
|
Fixed an issue where device deployment from Panorama to the firewalls failed with the error message Failed to get DLSRVR client key. This issue occurred only on firewalls where the request system-private-data-reset CLI command had been issued in the past.
|
||||||
|
|
||||||
|
## PAN-157518
|
||||||
|
|
||||||
|
Fixed an issue where using tags to target a device group in a Security policy rule did not work, and the rule was displayed in all device groups (**Preview Rules**).
|
||||||
|
|
||||||
|
## PAN-157472
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA_5200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where, after a factory reset, the firewall displayed the following error message: data_plane_X: Exited 1 times, must be manually recovered..
|
||||||
|
|
||||||
|
## PAN-157213
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
ZTP firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall failed to connect to Panorama when Zero Touch Provisioning (ZTP) was disabled.
|
||||||
|
|
||||||
|
## PAN-157074
|
||||||
|
|
||||||
|
Fixed an issue where a process (configd) stopped responding, which caused corruption.
|
||||||
|
|
||||||
|
## PAN-157035
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an intermittent issue where multicast packets traversing the firewall in VLAN configurations experienced higher drop rates than expected.
|
||||||
|
|
||||||
|
## PAN-157027
|
||||||
|
|
||||||
|
Fixed an issue where, when stateless GTP-U traffic hit a multi-dataplane firewall, an inter-dataplane fragmentation loop occurred, which caused high dataplane resource usage.
|
||||||
|
|
||||||
|
## PAN-157026
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not display unified logs.
|
||||||
|
|
||||||
|
## PAN-156552
|
||||||
|
|
||||||
|
Fixed a discrepancy in Panorama between application usage data and the application name in the **ACC** tab.
|
||||||
|
|
||||||
|
## PAN-156393
|
||||||
|
|
||||||
|
Fixed an issue where NetFlow updates were sent without honoring the configured active timeout value.
|
||||||
|
|
||||||
|
## PAN-156388
|
||||||
|
|
||||||
|
Fixed an issue where a process (useridd) stopped responding while attempting to remove all HIP reports on the disk.
|
||||||
|
|
||||||
|
## PAN-155903
|
||||||
|
|
||||||
|
Fixed an issue where zone protection and spoofed IP address protection didn't properly drop unroutable packets.
|
||||||
|
|
||||||
|
## PAN-155659
|
||||||
|
|
||||||
|
Fixed an issue where individual users were unable to populate the **allowed user/user group** field when configuring the GlobalProtect Clientless VPN.
|
||||||
|
|
||||||
|
## PAN-155657
|
||||||
|
|
||||||
|
Fixed an issue where the default log level for mprelay was set to INFO and caused commits to stop working on VM-Series firewalls in AWS using EBS backed volumes when route monitor was configured.
|
||||||
|
|
||||||
|
## PAN-154905
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama appliances on PAN-OS 10.0 releases only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue with Security policy rule configuration where, in the **Source** and **Destination** tabs, the **Query Traffic** setting was not available for Address Groups.
|
||||||
|
|
||||||
|
## PAN-154526
|
||||||
|
|
||||||
|
Fixed an issue where a process (genindex.sh) caused high memory usage on the management plane. Due to the resulting out-of-memory (OOM) condition, multiple processes stopped responding.
|
||||||
|
|
||||||
|
## PAN-154441
|
||||||
|
|
||||||
|
Fixed an issue where the Radius EAP authentication stopped working and the authd process restarted.
|
||||||
|
|
||||||
|
## PAN-154433
|
||||||
|
|
||||||
|
Fixed an issue where the firewall was unable to detect end-user IP address spoofing on the GTP-U for a user data session when using an IPv6 address.
|
||||||
|
|
||||||
|
## PAN-154362
|
||||||
|
|
||||||
|
Fixed an issue where Panorama failed to push dynamic user groups to the managed firewalls.
|
||||||
|
|
||||||
|
## PAN-154334
|
||||||
|
|
||||||
|
Fixed an issue where the inactivity logout timeout did not reflect on the GlobalProtect mapping timeout.
|
||||||
|
|
||||||
|
## PAN-153288
|
||||||
|
|
||||||
|
Fixed an issue where the software QoS shaping queue processing was not properly applied on multicast traffic.
|
||||||
|
|
||||||
|
## PAN-151751
|
||||||
|
|
||||||
|
Fixed an issue where GlobalProtect logs did not populate on the destination syslog server in Log Event Extended Format (LEEF) and common event format (CEF).
|
||||||
|
|
||||||
|
## PAN-151273
|
||||||
|
|
||||||
|
Fixed an issue where the commit event was not recorded in the config logs during a **Commit and Push** on the Panorama management server.
|
||||||
|
|
||||||
|
## PAN-150530
|
||||||
|
|
||||||
|
Fixed an issue in the External Dynamic List (EDL) where printed log messages repeated until the end of the description field.
|
||||||
|
|
||||||
|
## PAN-150388
|
||||||
|
|
||||||
|
Fixed an issue where a process (mgmtsrvr) stopped responding when viewing logs in the web interface.
|
||||||
|
|
||||||
|
## PAN-150080
|
||||||
|
|
||||||
|
Fixed an issue where, even when tunnel interface was set to **down**, the following alert displayed: Tunnel GRE_Tunnels is going down(critical).
|
||||||
|
|
||||||
|
## PAN-147736
|
||||||
|
|
||||||
|
Fixed an issue on the firewall web interface where the Cortex Data Lake **Logging Service Status** pop-up window did not show correct information.
|
||||||
|
|
||||||
|
## PAN-146250
|
||||||
|
|
||||||
|
Fixed an issue where, in two separate but simultaneous sessions, the same software packet buffer was owned and processed.
|
||||||
|
|
||||||
|
## PAN-144305
|
||||||
|
|
||||||
|
Fixed an issue where merged configurations were unable to be exported from Panorama-managed firewalls using the PAN-OS XML API.
|
||||||
|
|
||||||
|
## PAN-144057
|
||||||
|
|
||||||
|
Fixed a rare issue where, when aggregate ethernet (AE) groups were deleted and re-added, the AE interface no longer had an SDB node to send link the location to. As a result, the dataplane was unable to identify a connected route for the interface address.
|
||||||
|
|
||||||
|
## PAN-141494
|
||||||
|
|
||||||
|
Fixed an issue with the group-mapping mode credential detection feature that failed to block users when logging in using corporate credentials.
|
||||||
|
|
||||||
|
## PAN-138727
|
||||||
|
|
||||||
|
A fix was made to address a time-of-check to time-of-use (TOCTOU) race condition in the PAN-OS web interface that enabled an authenticated administrator with permission to upload plugins to execute arbitrary code with root user privileges ([CVE-2021-3054](https://security.paloaltonetworks.com/CVE-2021-3054)).
|
||||||
|
|
||||||
|
## PAN-138134
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where a template configuration push was blocked when the managed firewall did not have a plugin referenced in the template configuration.
|
||||||
|
|
||||||
|
## PAN-138066
|
||||||
|
|
||||||
|
Fixed an issue where an incorrect Certificate Authority (CA) was used for communicating to the Zero Touch Provisioning (ZTP) service.
|
||||||
|
|
||||||
|
## PAN-116515
|
||||||
|
|
||||||
|
Fixed an issue where IKE Gateway configurations with different crypto profiles on the same IP address with dynamic peers failed with the following error message: IKEv1 gateway should use the same crypto profiles configured on the same interface or local IP address.
|
||||||
|
|
||||||
|
With this fix, you are able to configure IKE Gateways with different crypto profiles on the same IP address with dynamic peers when IKEv1 auto mode is applied.
|
||||||
|
|
||||||
|
## PAN-113093
|
||||||
|
|
||||||
|
Fixed an intermittent issue where, when the DNS Security cloud was not reachable, DNS responses had bad UDP checksums.
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 10.0.8-h10
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-202450
|
||||||
|
|
||||||
|
Fixed an issue where the device-client-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
|
||||||
|
|
||||||
|
## PAN-198372
|
||||||
|
|
||||||
|
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
|
||||||
|
|
||||||
|
## PAN-193004
|
||||||
|
|
||||||
|
Fixed an issue where /opt/pancfg partition utilization reached 100%, which caused access to the Panorama web interface to fail.
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 10.0.8-h11
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-237876
|
||||||
|
|
||||||
|
Extended the firewall Panorama root CA certificate which was previously set to expire on April 7th, 2024.
|
||||||
|
|
||||||
|
## PAN-215576
|
||||||
|
|
||||||
|
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
|
||||||
@@ -0,0 +1,23 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 10.0.8-h4
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-178283
|
||||||
|
|
||||||
|
Fixed an intermittent issue where connections to the URL cloud went down due to a failure to resolve DNS.
|
||||||
|
|
||||||
|
## PAN-177762
|
||||||
|
|
||||||
|
Fixed an issue where wificlient in PAN-OS 10.0 and later releases caused processing delays, on-chip descriptor spikes, and buffer usage.
|
||||||
|
|
||||||
|
## PAN-174244
|
||||||
|
|
||||||
|
Fixed an issue where a sudden increase in URL data approached the maximum cache capacity of the firewall.
|
||||||
|
|
||||||
|
## PAN-173469
|
||||||
|
|
||||||
|
Fixed an intermittent issue where websites were blocked and categorized as not resolved.
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 10.0.8-h8
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-184592
|
||||||
|
|
||||||
|
A fix was made to address a remote code execution vulnerability in Elasticsearch included with Panorama management servers known as Log4Shell ([CVE-2021-44228](https://security.paloaltonetworks.com/CVE-2021-44228)).
|
||||||
|
|
||||||
|
## PAN-183767
|
||||||
|
|
||||||
|
Fixed an issue where downloading Dynamic Updates files failed when connected to the static update server at us-static.updates.paloaltonetworks.com.
|
||||||
@@ -0,0 +1,617 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 10.0.1
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## APL-8269
|
||||||
|
|
||||||
|
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
|
||||||
|
|
||||||
|
## PLUG-380
|
||||||
|
|
||||||
|
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||||
|
|
||||||
|
## WF500-5471
|
||||||
|
|
||||||
|
After using the firewall CLI to add a WildFire appliance with an IPv6 address, the initial connection may fail.
|
||||||
|
|
||||||
|
**Workaround:** Retry connecting after you restart the web server with the following command: `debug software restart process web-server`.
|
||||||
|
|
||||||
|
## PAN-178194
|
||||||
|
|
||||||
|
A UI issue in PAN-OS renders the contents of the **Inline ML** tab in the **URL Filtering Profile** inaccessible on firewalls licensed for Advanced URL Filtering. Additionally, a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI. These errors do not affect the operation of Advanced URL Filtering or URL Filtering Inline ML.
|
||||||
|
|
||||||
|
**Workaround:** Configuration settings for URL Filtering Inline ML must be applied through the CLI. The following configuration commands are available:
|
||||||
|
|
||||||
|
- Define URL exceptions for specific web sites—
|
||||||
|
`admin#``set profiles url-filtering <url_filtering_profile_name> mlav-category-exception`
|
||||||
|
|
||||||
|
- Configuration settings for each inline ML model—
|
||||||
|
`admin#``set profiles url-filtering <url_filtering_profile_name> mlav-engine-urlbased-enabled`
|
||||||
|
|
||||||
|
## PAN-162743
|
||||||
|
|
||||||
|
In some cases, the firewall may not receive updates for the Device Dictionary, which causes the firewall to replace new attributes in the IP address-to-device mappings with “unknown.”
|
||||||
|
|
||||||
|
**Workaround**: Reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-157240
|
||||||
|
|
||||||
|
When a firewall has hardware offloading turned on and OSPF enabled, if ECMP is enabled or disabled for a virtual router during a configuration commit, OSPF sessions may get stuck in Exchange Start state.
|
||||||
|
|
||||||
|
**Workaround:** Disable OSPF when enabling or disabling ECMP, and then re-enable OSPF in the next commit.
|
||||||
|
|
||||||
|
## PAN-156023
|
||||||
|
|
||||||
|
If the firewall fails a file system integrity check while FIPS-CC mode is enabled, the appliance will receive a hash mismatch error and enter maintenance mode on the next reboot.
|
||||||
|
|
||||||
|
**Workaround:** Upgrade to PAN-OS 10.0.2.
|
||||||
|
|
||||||
|
## PAN-154292
|
||||||
|
|
||||||
|
On the Panorama management server, downgrading from a PAN-OS 10.0 release to a PAN-OS 9.1 release causes Panorama commit (**Commit** > **Commit to Panorama**) failures if a custom report (**Monitor** > **Manage Custom Reports**) is configured to Group By **Session ID**.
|
||||||
|
|
||||||
|
**Workaround:** After successful downgrade, reconfigure the Group By setting in the custom report.
|
||||||
|
|
||||||
|
## PAN-154247
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 10.0.2 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
|
||||||
|
|
||||||
|
**Workaround:** Log out and back in to the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-154034
|
||||||
|
|
||||||
|
On the Panorama management server, the Type column in the System logs (**Monitor** > **Logs** > **System**) for managed firewalls running a PAN-OS 9.1 release erroneously display `iot` as the type.
|
||||||
|
|
||||||
|
## PAN-154032
|
||||||
|
|
||||||
|
On the Panorama management server, downgrading to PAN-OS 9.1 with the Panorama plugin for Cisco TrustSec version 1.0.2 installed does not automatically transform the plugin to be compatible with PAN-OS 9.1
|
||||||
|
|
||||||
|
**Workaround:** After successful downgrade to PAN-OS 9.1, **Remove Config** (**Panorama** > **Plugins**) of the Panorama plugin for Cisco TrustSec and then reconfigure the plugin.
|
||||||
|
|
||||||
|
## PAN-153803
|
||||||
|
|
||||||
|
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
|
||||||
|
|
||||||
|
## PAN-153557
|
||||||
|
|
||||||
|
On the Panorama management server CLI, the overall report status for a report query is marked as `Done` despite reports generated from logs in the Cortex Data Lake (CDL) from the PODamericas Collector Group jobs are still in a `Running` state.
|
||||||
|
|
||||||
|
## PAN-153231
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 10.0.2 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
PA-7080 Series firewalls deployed with 100G-NPC cards and legacy cards using older system management controllers (SMC) with over 2,500 IPSec tunnels commit successfully but the 100G-NPC cards fail and display as `down`.
|
||||||
|
|
||||||
|
## PAN-153068
|
||||||
|
|
||||||
|
The Bonjour Reflector option is supported on up to 16 interfaces. If you enable it on more than 16 interfaces, the commit succeeds and the Bonjour Reflector option is enabled only for the first 16 interfaces and ignored for any additional interfaces.
|
||||||
|
|
||||||
|
## PAN-152825
|
||||||
|
|
||||||
|
On the Panorama management server, you cannot view the SD-WAN license installed on an SD-WAN firewall (**Panorama** > **Device Deployment** > **Licenses**).
|
||||||
|
|
||||||
|
**Workaround:** [Log in to the Panorama CLI](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli.html) and enter the following command to view the SDWAN license information for your managed firewalls.
|
||||||
|
|
||||||
|
`admin>``request batch license info`
|
||||||
|
|
||||||
|
## PAN-152433
|
||||||
|
|
||||||
|
When you have an active/passive HA pair of PA-3200 Series firewalls running PAN-OS 10.0.0 with NAT configured, if you upgrade one firewall to PAN-OS 10.0.1, the firewall goes to non-functional state due to a NAT oversubscription mismatch between the HA peers. The same non-functional state results if both HA peers are running PAN-OS 10.0.1 and you downgrade one to PAN-OS 10.00. The upgraded or downgraded firewall goes to non-functional state because PAN-OS 10.0.0 and 10.0.1 have different default NAT oversubscription rates.
|
||||||
|
|
||||||
|
**Workaround**: After an upgrade or downgrade, modify the NAT oversubscription rate on one firewall so that the rates on the HA pair match.
|
||||||
|
|
||||||
|
## PAN-151238
|
||||||
|
|
||||||
|
There is a known issue where M-100 appliances are able to download and install a PAN-OS 10.0 release image even though the M-100 appliance is no longer supported after PAN-OS 9.1. (Refer to the [hardware end-of-life dates](https://www.paloaltonetworks.com/services/support/end-of-life-announcements/hardware-end-of-life-dates.html).)
|
||||||
|
|
||||||
|
## PAN-151198
|
||||||
|
|
||||||
|
On the Panorama management server, read-only Panorama administrators (**Panorama** > **Administrators**) can load managed firewall configuration Backups (**Panorama** > **Managed Devices** > **Summary**).
|
||||||
|
|
||||||
|
## PAN-151085
|
||||||
|
|
||||||
|
On a PA-7000 Series firewall chassis having multiple slots, when HA clustering is enabled on an active/active HA pair, the session table count for one of the peers can show a higher count than the actual number of active sessions on that peer. This behavior can be seen when the session is being set up on a non-cache slot (for example, when a session distribution policy is set to round-robin or session-load); it is caused by the additional cache lookup that happens when HA cluster participation is enabled.
|
||||||
|
|
||||||
|
## PAN-150801
|
||||||
|
|
||||||
|
Automatic quarantine of a device based on forwarding profile or log setting does not work on the PA-7000 Series firewalls.
|
||||||
|
|
||||||
|
## PAN-150345
|
||||||
|
|
||||||
|
During updates to the Device Dictionary, the IoT Security service does not push new Device-ID attributes (such as new device profiles) to the firewall until a manual commit occurs.
|
||||||
|
|
||||||
|
**Workaround:** Perform a force commit to push the attributes in the content update to the firewall.
|
||||||
|
|
||||||
|
## PAN-150361
|
||||||
|
|
||||||
|
In an Active-Passive high availability (HA) configuration, an error displays if you create a device object on the passive device.
|
||||||
|
|
||||||
|
**Workaround:** Load the running configuration and perform a force commit to sync the devices.
|
||||||
|
|
||||||
|
## PAN-148971
|
||||||
|
|
||||||
|
If you enter a search term for Events that are related to IoT in the System logs and apply the filter, the page displays an `Invalid term` error.
|
||||||
|
|
||||||
|
**Workaround:** Specify `iot` as the **Type Attribute** to filter the logs and use the search term as the **Description Attribute**. For example: `( subtype eq iot ) and ( description contains 'gRPC connection' )`.
|
||||||
|
|
||||||
|
## PAN-148924
|
||||||
|
|
||||||
|
In an active-passive HA configuration, tags for dynamic user groups are not persistent after rebooting the firewall because the active firewall does not sync the tags to the passive firewall during failover.
|
||||||
|
|
||||||
|
## PAN-146995
|
||||||
|
|
||||||
|
After downgrading a Panorama management server from PAN-OS 10.0 to PAN-OS 9.1, the `VLD` and `logd` processes may crash when Panorama reboots.
|
||||||
|
|
||||||
|
**Workaround:** Panorama automatically restarts the `VLD` and `logd` processes.
|
||||||
|
|
||||||
|
## PAN-146807
|
||||||
|
|
||||||
|
Changing the device group configured in a monitoring definition from a child DG to a parent DG, or vice versa, might cause firewalls configured in the child DG to lose IP tag mapping information received from the monitoring definition. Only firewalls assigned to the parent DG receive IP tag mapping updates.
|
||||||
|
|
||||||
|
**Workaround**: Perform a manual config sync on the device group that lost the IP tag mapping information.
|
||||||
|
|
||||||
|
## PAN-146573
|
||||||
|
|
||||||
|
PA-7000 Series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||||
|
|
||||||
|
## PAN-146485
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
|
||||||
|
|
||||||
|
## PAN-146030
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 10.0.2 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
Enhanced application logging is not supported for firewalls connected to Cortex Data Lake through a proxy server.
|
||||||
|
|
||||||
|
## PAN-145460
|
||||||
|
|
||||||
|
CN-MGMT pods fail to connect to the Panorama management server when using the Kubernetes plugin.
|
||||||
|
|
||||||
|
**Workaround:** **Commit** the Panorama configuration after the CN-MGMT pod successfully registers with Panorama.
|
||||||
|
|
||||||
|
## PAN-144889
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
|
||||||
|
|
||||||
|
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
|
||||||
|
|
||||||
|
## PAN-143132
|
||||||
|
|
||||||
|
Fetching the device certificate from the Palo Alto Networks Customer Support Portal (CSP) may fail and displays the following error in the CLI:
|
||||||
|
|
||||||
|
`ERROR Failed to process S1C msg: Error`
|
||||||
|
|
||||||
|
**Workaround:** Retrying fetching the device certificate from the Palo Alto Networks CSP.
|
||||||
|
|
||||||
|
## PAN-141630
|
||||||
|
|
||||||
|
Current performance limitation: single data plane use only. The PA-5200 Series and PA-7000 Series firewalls that support 5G network slice security, 5G equipment ID security, and 5G subscriber ID security use a single data plane only, which currently limits the firewall performance.
|
||||||
|
|
||||||
|
## PAN-140959
|
||||||
|
|
||||||
|
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
|
||||||
|
|
||||||
|
## PAN-140008
|
||||||
|
|
||||||
|
ElasticSearch is forced to restart when the `masterd` process misses too many heartbeat messages on the Panorama management server resulting in a delay in a log query and ingestion.
|
||||||
|
|
||||||
|
## PAN-136763
|
||||||
|
|
||||||
|
On the Panorama management server, managed firewalls display as `disconnected` when installing a PAN-OS software update (**Panorama** > **Device Deployment** > **Software**) but display as `connected` when you view your managed firewalls Summary (**Panorama** > **Managed Devices** > **Summary**) and from the CLI.
|
||||||
|
|
||||||
|
**Workaround:** Log out and log back in to the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-136701
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000b Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Packets for new sessions drop when handling predict sessions.
|
||||||
|
|
||||||
|
**Workaround:** Use the following CLi commands to bypass this issue:
|
||||||
|
|
||||||
|
- `set session hwpredict disable yes`
|
||||||
|
- `show session hwpredict status`
|
||||||
|
|
||||||
|
## PAN-135742
|
||||||
|
|
||||||
|
There is an issue in HTTP2 session decryption where the App-ID in the decryption log is the App-ID of the parent session (which is web-browsing).
|
||||||
|
|
||||||
|
## PAN-134053
|
||||||
|
|
||||||
|
ACC does not filter WildFire logs from Dynamic User Groups.
|
||||||
|
|
||||||
|
## PAN-132598
|
||||||
|
|
||||||
|
The Panorama management server does not check for duplicate addresses in address groups (**Objects** > **Address Groups**) and duplicate services in service groups (**Objects** > **Service Groups**) when created from the CLI.
|
||||||
|
|
||||||
|
## PAN-130550
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
|
||||||
|
|
||||||
|
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
|
||||||
|
|
||||||
|
## PAN-127813
|
||||||
|
|
||||||
|
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches don’t communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
|
||||||
|
|
||||||
|
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
|
||||||
|
|
||||||
|
## PAN-127550
|
||||||
|
|
||||||
|
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
|
||||||
|
|
||||||
|
## PAN-127206
|
||||||
|
|
||||||
|
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
|
||||||
|
|
||||||
|
## PAN-123805
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See the PAN-OS 10.0.2 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
On the managed firewall web interface, the Secure Communication Settings (**Device** > **Setup** > **Management**) configuration does display a green cog widget to indicate that the configuration was pushed from the Panorama management server.
|
||||||
|
|
||||||
|
## PAN-123277
|
||||||
|
|
||||||
|
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-123040
|
||||||
|
|
||||||
|
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules don’t display. A workaround exists for this issue. Please contact Support for information about the workaround.
|
||||||
|
|
||||||
|
## PAN-121678
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000b Series only
|
||||||
|
```
|
||||||
|
|
||||||
|
The following error during secure boot has no impact and can be ignored:
|
||||||
|
|
||||||
|
`[ 0.672461] Device 'efifb.0' does not have a release() function, it is broken and must be fixed.[ 2.026107] EFI: Problem loading in-kernel X.509 certificate (-65)Maintenance Mode filesystem size: 2.0G`
|
||||||
|
|
||||||
|
## PAN-120440
|
||||||
|
|
||||||
|
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||||
|
|
||||||
|
## PAN-120423
|
||||||
|
|
||||||
|
PAN-OS 10.0.0 does not support the XML API for GlobalProtect logs.
|
||||||
|
|
||||||
|
## PAN-120303
|
||||||
|
|
||||||
|
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||||
|
|
||||||
|
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||||
|
|
||||||
|
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||||
|
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||||
|
2. **Commit** your changes.
|
||||||
|
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||||
|
4. **Commit** your changes.
|
||||||
|
- Restart the firewall (devsrvr) process.
|
||||||
|
1. Log in to the firewall CLI.
|
||||||
|
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||||
|
|
||||||
|
## PAN-116017
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Google Cloud Platform (GCP) only
|
||||||
|
```
|
||||||
|
|
||||||
|
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||||
|
|
||||||
|
## PAN-115816
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Microsoft Azure only
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-114495
|
||||||
|
|
||||||
|
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||||
|
|
||||||
|
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||||
|
|
||||||
|
## PAN-112694
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls with multiple virtual systems only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||||
|
|
||||||
|
## PAN-112456
|
||||||
|
|
||||||
|
You can temporarily submit a change request for a URL Category with three suggested categories; however, only two categories are supported. Do not add more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, only the first two categories in the change request are evaluated.
|
||||||
|
|
||||||
|
## PAN-112135
|
||||||
|
|
||||||
|
You cannot unregister tags for a subnet or range in a dynamic address group from the web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use an XML API request to unregister the tags for the subnet or range.
|
||||||
|
|
||||||
|
## PAN-111928
|
||||||
|
|
||||||
|
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||||
|
|
||||||
|
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||||
|
|
||||||
|
## PAN-111866
|
||||||
|
|
||||||
|
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||||
|
|
||||||
|
**Workaround:** Perform one of the following tasks.
|
||||||
|
|
||||||
|
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||||
|
- Manually select the devices that belong to the modified device group and template configurations.
|
||||||
|
|
||||||
|
## PAN-111729
|
||||||
|
|
||||||
|
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-111670
|
||||||
|
|
||||||
|
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||||
|
|
||||||
|
## PAN-110794
|
||||||
|
|
||||||
|
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||||
|
|
||||||
|
## PAN-109759
|
||||||
|
|
||||||
|
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
|
||||||
|
|
||||||
|
## PAN-109526
|
||||||
|
|
||||||
|
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||||
|
|
||||||
|
## PAN-106675
|
||||||
|
|
||||||
|
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||||
|
|
||||||
|
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||||
|
|
||||||
|
## PAN-104780
|
||||||
|
|
||||||
|
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||||
|
|
||||||
|
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||||
|
|
||||||
|
## PAN-103276
|
||||||
|
|
||||||
|
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||||
|
|
||||||
|
## PAN-101688
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama plugins
|
||||||
|
```
|
||||||
|
|
||||||
|
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||||
|
|
||||||
|
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||||
|
|
||||||
|
## PAN-101537
|
||||||
|
|
||||||
|
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||||
|
|
||||||
|
**Workaround:** Specify the vsys in the query string:
|
||||||
|
|
||||||
|
`admin>` `set system target-vsys <vsys-name>`
|
||||||
|
|
||||||
|
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||||
|
|
||||||
|
## PAN-98520
|
||||||
|
|
||||||
|
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||||
|
|
||||||
|
## PAN-97757
|
||||||
|
|
||||||
|
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||||
|
|
||||||
|
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||||
|
|
||||||
|
## PAN-97524
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama management server only
|
||||||
|
```
|
||||||
|
|
||||||
|
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||||
|
|
||||||
|
## PAN-96446
|
||||||
|
|
||||||
|
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||||
|
|
||||||
|
## PAN-95773
|
||||||
|
|
||||||
|
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||||
|
|
||||||
|
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||||
|
|
||||||
|
## PAN-95511
|
||||||
|
|
||||||
|
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||||
|
|
||||||
|
## PAN-95028
|
||||||
|
|
||||||
|
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||||
|
|
||||||
|
## PAN-94846
|
||||||
|
|
||||||
|
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||||
|
|
||||||
|
## PAN-94093
|
||||||
|
|
||||||
|
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||||
|
|
||||||
|
## PAN-93968
|
||||||
|
|
||||||
|
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||||
|
|
||||||
|
## PAN-93607
|
||||||
|
|
||||||
|
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||||
|
|
||||||
|
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||||
|
|
||||||
|
## PAN-93532
|
||||||
|
|
||||||
|
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||||
|
|
||||||
|
## PAN-93193
|
||||||
|
|
||||||
|
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||||
|
|
||||||
|
- Switch to the firewall **Context** on the Panorama management server.
|
||||||
|
- Commit changes when a dynamic update is being installed.
|
||||||
|
- Generate a custom report when a dynamic update is being installed.
|
||||||
|
- Generate custom reports during a commit.
|
||||||
|
|
||||||
|
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||||
|
|
||||||
|
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||||
|
|
||||||
|
## PAN-91802
|
||||||
|
|
||||||
|
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||||
|
|
||||||
|
## PAN-83610
|
||||||
|
|
||||||
|
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||||
|
|
||||||
|
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-83236
|
||||||
|
|
||||||
|
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||||
|
|
||||||
|
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||||
|
|
||||||
|
## PAN-83215
|
||||||
|
|
||||||
|
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||||
|
|
||||||
|
## PAN-81521
|
||||||
|
|
||||||
|
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||||
|
|
||||||
|
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||||
|
|
||||||
|
## PAN-77125
|
||||||
|
|
||||||
|
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||||
|
|
||||||
|
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-75457
|
||||||
|
|
||||||
|
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||||
|
|
||||||
|
## PAN-73530
|
||||||
|
|
||||||
|
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||||
|
|
||||||
|
## PAN-73401
|
||||||
|
|
||||||
|
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||||
|
|
||||||
|
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||||
|
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||||
|
|
||||||
|
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||||
|
|
||||||
|
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||||
|
- Configure a worker list on the cluster controller:
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||||
|
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||||
|
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||||
|
or
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||||
|
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||||
|
|
||||||
|
## PAN-70906
|
||||||
|
|
||||||
|
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||||
|
|
||||||
|
## PAN-69505
|
||||||
|
|
||||||
|
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||||
|
|
||||||
|
## PAN-41558
|
||||||
|
|
||||||
|
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||||
|
|
||||||
|
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||||
|
|
||||||
|
## PAN-40079
|
||||||
|
|
||||||
|
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||||
|
|
||||||
|
## PAN-39636
|
||||||
|
|
||||||
|
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||||
|
|
||||||
|
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||||
|
|
||||||
|
## PAN-38255
|
||||||
|
|
||||||
|
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||||
|
|
||||||
|
## PAN-31832
|
||||||
|
|
||||||
|
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||||
|
|
||||||
|
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||||
|
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||||
|
|
||||||
|
## PAN-118887
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 10.0.2 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
The new pattern-matching engine in PAN-OS 10.0 does not support the regular expression (regex) character `\C`. If you try to use this character in a pattern that is only compatible with the new engine, you will see a warning when you try to save the signature.
|
||||||
|
|
||||||
|
Example of an invalid signature: `ab\Cde`
|
||||||
|
|
||||||
|
Explanation: Only the new engine allows you to create signatures with fewer than seven literal characters.
|
||||||
|
|
||||||
|
Example of a valid signature: `ab\Cdefgh`
|
||||||
|
|
||||||
|
Explanation: This signature is compatible with the former pattern-matching engine, which matches `\C` to any literal character.
|
||||||
@@ -0,0 +1,609 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 10.0.2
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## APL-8269
|
||||||
|
|
||||||
|
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
|
||||||
|
|
||||||
|
## PLUG-380
|
||||||
|
|
||||||
|
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||||
|
|
||||||
|
## WF500-5471
|
||||||
|
|
||||||
|
After using the firewall CLI to add a WildFire appliance with an IPv6 address, the initial connection may fail.
|
||||||
|
|
||||||
|
**Workaround:** Retry connecting after you restart the web server with the following command: `debug software restart process web-server`.
|
||||||
|
|
||||||
|
## PAN-178194
|
||||||
|
|
||||||
|
A UI issue in PAN-OS renders the contents of the **Inline ML** tab in the **URL Filtering Profile** inaccessible on firewalls licensed for Advanced URL Filtering. Additionally, a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI. These errors do not affect the operation of Advanced URL Filtering or URL Filtering Inline ML.
|
||||||
|
|
||||||
|
**Workaround:** Configuration settings for URL Filtering Inline ML must be applied through the CLI. The following configuration commands are available:
|
||||||
|
|
||||||
|
- Define URL exceptions for specific web sites—
|
||||||
|
`admin#``set profiles url-filtering <url_filtering_profile_name> mlav-category-exception`
|
||||||
|
|
||||||
|
- Configuration settings for each inline ML model—
|
||||||
|
`admin#``set profiles url-filtering <url_filtering_profile_name> mlav-engine-urlbased-enabled`
|
||||||
|
|
||||||
|
## PAN-162743
|
||||||
|
|
||||||
|
In some cases, the firewall may not receive updates for the Device Dictionary, which causes the firewall to replace new attributes in the IP address-to-device mappings with “unknown.”
|
||||||
|
|
||||||
|
**Workaround**: Reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-157444
|
||||||
|
|
||||||
|
As a result of a telemetry handling update, the Source Zone field in the DNS analytics logs (viewable in the DNS Analytics tab within AutoFocus) might not display correct results.
|
||||||
|
|
||||||
|
## PAN-157327
|
||||||
|
|
||||||
|
On downgrade to PAN-OS 9.1, Enterprise Data Loss Prevention (DLP) filtering settings (**Device** > **Setup** > **DLP**) are not removed and cause commit errors for the downgraded firewall if you do not uninstall the Enterprise DLP plugin before downgrade.
|
||||||
|
|
||||||
|
**Workaround:** After you successfully downgrade a managed firewall to PAN-OS 9.1, commit and push from Panorama to remove the Enterprise DLP filtering settings and complete the downgrade.
|
||||||
|
|
||||||
|
1. Downgrade your managed firewall to PAN-OS 9.1
|
||||||
|
2. Log in to the firewall web interface and view the **Tasks** to verify all auto commits related to the downgrade have completed successfully.
|
||||||
|
3. Log in to the Panorama web interface and **Commit** > **Commit and Push** to your managed firewall downgraded to PAN-OS 9.1.
|
||||||
|
|
||||||
|
## PAN-157103
|
||||||
|
|
||||||
|
Multi-channel functionality may not be properly utilized on an VM-Series firewall deployed in VMware NSX-V after the service is first deployed.
|
||||||
|
|
||||||
|
**Workaround**: Execute the command `debug dataplane pow status` to view the number of channels being utilized by the dataplane.
|
||||||
|
|
||||||
|
Per pan-task Netx statisticsCounter Name 1 2 3 4 5 6 Total---------------------------------------------ready_dvf 2 0 0 0 0 0 2
|
||||||
|
|
||||||
|
If multi-channel functionality is not working, disable your NSX-V security policy and reapply it. Then reboot the VM-Series firewall. When the firewall is back up, verify that multi-channel functionality is working by executing the command `debug dataplane pow status`. It should now show multiple channels being utilized.
|
||||||
|
|
||||||
|
Per pan-task Netx statisticsCounter Name 1 2 3 4 5 6 Total---------------------------------------------ready_dvf 1 1 0 0 0 0 2
|
||||||
|
|
||||||
|
## PAN-156645
|
||||||
|
|
||||||
|
If the SD-WAN interface was Down and it comes Up during a commit (for example, if you configure it from Down to Auto), SD-WAN ignores the change and keeps the link Down in the SD-WAN connection. In this case, SD-WAN won't choose to send traffic to this link. If this is the only link to the internet, this behavior may cause an outage, including failure of the IKE negotiation between the Branch and Hub, and such Tunnel will be down.
|
||||||
|
|
||||||
|
**Workaround**: Commit again or toggle the interface link Down and Up; the SD-WAN statistics will be correct and the problem will resolve.
|
||||||
|
|
||||||
|
## PAN-156598
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure a standard custom vulnerability signature in a custom Vulnerability Protection profile in a shared device group, the shared profile custom signatures do not populate in the other device groups when you configure a combination custom vulnerability signature.
|
||||||
|
|
||||||
|
**Workaround:** Use the CLI to update the combination signature.
|
||||||
|
|
||||||
|
## PAN-154292
|
||||||
|
|
||||||
|
On the Panorama management server, downgrading from a PAN-OS 10.0 release to a PAN-OS 9.1 release causes Panorama commit (**Commit** > **Commit to Panorama**) failures if a custom report (**Monitor** > **Manage Custom Reports**) is configured to Group By **Session ID**.
|
||||||
|
|
||||||
|
**Workaround:** After successful downgrade, reconfigure the Group By setting in the custom report.
|
||||||
|
|
||||||
|
## PAN-154266
|
||||||
|
|
||||||
|
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
|
||||||
|
|
||||||
|
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
|
||||||
|
|
||||||
|
## PAN-154034
|
||||||
|
|
||||||
|
On the Panorama management server, the Type column in the System logs (**Monitor** > **Logs** > **System**) for managed firewalls running a PAN-OS 9.1 release erroneously display `iot` as the type.
|
||||||
|
|
||||||
|
## PAN-154032
|
||||||
|
|
||||||
|
On the Panorama management server, downgrading to PAN-OS 9.1 with the Panorama plugin for Cisco TrustSec version 1.0.2 installed does not automatically transform the plugin to be compatible with PAN-OS 9.1
|
||||||
|
|
||||||
|
**Workaround:** After successful downgrade to PAN-OS 9.1, **Remove Config** (**Panorama** > **Plugins**) of the Panorama plugin for Cisco TrustSec and then reconfigure the plugin.
|
||||||
|
|
||||||
|
## PAN-153803
|
||||||
|
|
||||||
|
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
|
||||||
|
|
||||||
|
## PAN-153557
|
||||||
|
|
||||||
|
On the Panorama management server CLI, the overall report status for a report query is marked as `Done` despite reports generated from logs in the Cortex Data Lake (CDL) from the PODamericas Collector Group jobs are still in a `Running` state.
|
||||||
|
|
||||||
|
## PAN-153068
|
||||||
|
|
||||||
|
The Bonjour Reflector option is supported on up to 16 interfaces. If you enable it on more than 16 interfaces, the commit succeeds and the Bonjour Reflector option is enabled only for the first 16 interfaces and ignored for any additional interfaces.
|
||||||
|
|
||||||
|
## PAN-152825
|
||||||
|
|
||||||
|
On the Panorama management server, you cannot view the SD-WAN license installed on an SD-WAN firewall (**Panorama** > **Device Deployment** > **Licenses**).
|
||||||
|
|
||||||
|
**Workaround:** [Log in to the Panorama CLI](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli.html) and enter the following command to view the SDWAN license information for your managed firewalls.
|
||||||
|
|
||||||
|
`admin>``request batch license info`
|
||||||
|
|
||||||
|
## PAN-152433
|
||||||
|
|
||||||
|
When you have an active/passive HA pair of PA-3200 Series firewalls running PAN-OS 10.0.0 with NAT configured, if you upgrade one firewall to PAN-OS 10.0.1, the firewall goes to non-functional state due to a NAT oversubscription mismatch between the HA peers. The same non-functional state results if both HA peers are running PAN-OS 10.0.1 and you downgrade one to PAN-OS 10.00. The upgraded or downgraded firewall goes to non-functional state because PAN-OS 10.0.0 and 10.0.1 have different default NAT oversubscription rates.
|
||||||
|
|
||||||
|
**Workaround**: After an upgrade or downgrade, modify the NAT oversubscription rate on one firewall so that the rates on the HA pair match.
|
||||||
|
|
||||||
|
## PAN-151238
|
||||||
|
|
||||||
|
There is a known issue where M-100 appliances are able to download and install a PAN-OS 10.0 release image even though the M-100 appliance is no longer supported after PAN-OS 9.1. (Refer to the [hardware end-of-life dates](https://www.paloaltonetworks.com/services/support/end-of-life-announcements/hardware-end-of-life-dates.html).)
|
||||||
|
|
||||||
|
## PAN-151198
|
||||||
|
|
||||||
|
On the Panorama management server, read-only Panorama administrators (**Panorama** > **Administrators**) can load managed firewall configuration Backups (**Panorama** > **Managed Devices** > **Summary**).
|
||||||
|
|
||||||
|
## PAN-151115
|
||||||
|
|
||||||
|
If a Security rule uses a IP Address External Dynamic List (EDL) for IPv6 traffic, the information for the EDL does not display in the Source EDL or Destination EDL columns in the logs.
|
||||||
|
|
||||||
|
## PAN-151085
|
||||||
|
|
||||||
|
On a PA-7000 Series firewall chassis having multiple slots, when HA clustering is enabled on an active/active HA pair, the session table count for one of the peers can show a higher count than the actual number of active sessions on that peer. This behavior can be seen when the session is being set up on a non-cache slot (for example, when a session distribution policy is set to round-robin or session-load); it is caused by the additional cache lookup that happens when HA cluster participation is enabled.
|
||||||
|
|
||||||
|
## PAN-150801
|
||||||
|
|
||||||
|
Automatic quarantine of a device based on forwarding profile or log setting does not work on the PA-7000 Series firewalls.
|
||||||
|
|
||||||
|
## PAN-150515
|
||||||
|
|
||||||
|
After you install the device certificate on a new Panorama management server, Panorama is not able to connect to the IoT Security edge service.
|
||||||
|
|
||||||
|
**Workaround:** Restart Panorama to connect to the IoT Security edge service.
|
||||||
|
|
||||||
|
## PAN-150345
|
||||||
|
|
||||||
|
During updates to the Device Dictionary, the IoT Security service does not push new Device-ID attributes (such as new device profiles) to the firewall until a manual commit occurs.
|
||||||
|
|
||||||
|
**Workaround:** Perform a force commit to push the attributes in the content update to the firewall.
|
||||||
|
|
||||||
|
## PAN-150361
|
||||||
|
|
||||||
|
In an Active-Passive high availability (HA) configuration, an error displays if you create a device object on the passive device.
|
||||||
|
|
||||||
|
**Workaround:** Load the running configuration and perform a force commit to sync the devices.
|
||||||
|
|
||||||
|
## PAN-148971
|
||||||
|
|
||||||
|
If you enter a search term for Events that are related to IoT in the System logs and apply the filter, the page displays an `Invalid term` error.
|
||||||
|
|
||||||
|
**Workaround:** Specify `iot` as the **Type Attribute** to filter the logs and use the search term as the **Description Attribute**. For example: `( subtype eq iot ) and ( description contains 'gRPC connection' )`.
|
||||||
|
|
||||||
|
## PAN-148924
|
||||||
|
|
||||||
|
In an active-passive HA configuration, tags for dynamic user groups are not persistent after rebooting the firewall because the active firewall does not sync the tags to the passive firewall during failover.
|
||||||
|
|
||||||
|
## PAN-146995
|
||||||
|
|
||||||
|
After downgrading a Panorama management server from PAN-OS 10.0 to PAN-OS 9.1, the `VLD` and `logd` processes may crash when Panorama reboots.
|
||||||
|
|
||||||
|
**Workaround:** Panorama automatically restarts the `VLD` and `logd` processes.
|
||||||
|
|
||||||
|
## PAN-146807
|
||||||
|
|
||||||
|
Changing the device group configured in a monitoring definition from a child DG to a parent DG, or vice versa, might cause firewalls configured in the child DG to lose IP tag mapping information received from the monitoring definition. Only firewalls assigned to the parent DG receive IP tag mapping updates.
|
||||||
|
|
||||||
|
**Workaround**: Perform a manual config sync on the device group that lost the IP tag mapping information.
|
||||||
|
|
||||||
|
## PAN-146573
|
||||||
|
|
||||||
|
PA-7000 Series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||||
|
|
||||||
|
## PAN-146485
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
|
||||||
|
|
||||||
|
## PAN-145460
|
||||||
|
|
||||||
|
CN-MGMT pods fail to connect to the Panorama management server when using the Kubernetes plugin.
|
||||||
|
|
||||||
|
**Workaround:** **Commit** the Panorama configuration after the CN-MGMT pod successfully registers with Panorama.
|
||||||
|
|
||||||
|
## PAN-144889
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
|
||||||
|
|
||||||
|
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
|
||||||
|
|
||||||
|
## PAN-143132
|
||||||
|
|
||||||
|
Fetching the device certificate from the Palo Alto Networks Customer Support Portal (CSP) may fail and displays the following error in the CLI:
|
||||||
|
|
||||||
|
`ERROR Failed to process S1C msg: Error`
|
||||||
|
|
||||||
|
**Workaround:** Retrying fetching the device certificate from the Palo Alto Networks CSP.
|
||||||
|
|
||||||
|
## PAN-141630
|
||||||
|
|
||||||
|
Current performance limitation: single data plane use only. The PA-5200 Series and PA-7000 Series firewalls that support 5G network slice security, 5G equipment ID security, and 5G subscriber ID security use a single data plane only, which currently limits the firewall performance.
|
||||||
|
|
||||||
|
## PAN-140959
|
||||||
|
|
||||||
|
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
|
||||||
|
|
||||||
|
## PAN-140008
|
||||||
|
|
||||||
|
ElasticSearch is forced to restart when the `masterd` process misses too many heartbeat messages on the Panorama management server resulting in a delay in a log query and ingestion.
|
||||||
|
|
||||||
|
## PAN-136763
|
||||||
|
|
||||||
|
On the Panorama management server, managed firewalls display as `disconnected` when installing a PAN-OS software update (**Panorama** > **Device Deployment** > **Software**) but display as `connected` when you view your managed firewalls Summary (**Panorama** > **Managed Devices** > **Summary**) and from the CLI.
|
||||||
|
|
||||||
|
**Workaround:** Log out and log back in to the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-136701
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000b Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Packets for new sessions drop when handling predict sessions.
|
||||||
|
|
||||||
|
**Workaround:** Use the following CLi commands to bypass this issue:
|
||||||
|
|
||||||
|
- `set session hwpredict disable yes`
|
||||||
|
- `show session hwpredict status`
|
||||||
|
|
||||||
|
## PAN-135742
|
||||||
|
|
||||||
|
There is an issue in HTTP2 session decryption where the App-ID in the decryption log is the App-ID of the parent session (which is web-browsing).
|
||||||
|
|
||||||
|
## PAN-134053
|
||||||
|
|
||||||
|
ACC does not filter WildFire logs from Dynamic User Groups.
|
||||||
|
|
||||||
|
## PAN-132598
|
||||||
|
|
||||||
|
The Panorama management server does not check for duplicate addresses in address groups (**Objects** > **Address Groups**) and duplicate services in service groups (**Objects** > **Service Groups**) when created from the CLI.
|
||||||
|
|
||||||
|
## PAN-130550
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
|
||||||
|
|
||||||
|
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
|
||||||
|
|
||||||
|
## PAN-127813
|
||||||
|
|
||||||
|
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches don’t communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
|
||||||
|
|
||||||
|
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
|
||||||
|
|
||||||
|
## PAN-127206
|
||||||
|
|
||||||
|
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
|
||||||
|
|
||||||
|
## PAN-123277
|
||||||
|
|
||||||
|
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-123040
|
||||||
|
|
||||||
|
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules don’t display. A workaround exists for this issue. Please contact Support for information about the workaround.
|
||||||
|
|
||||||
|
## PAN-121678
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000b Series only
|
||||||
|
```
|
||||||
|
|
||||||
|
The following error during secure boot has no impact and can be ignored:
|
||||||
|
|
||||||
|
`[ 0.672461] Device 'efifb.0' does not have a release() function, it is broken and must be fixed.[ 2.026107] EFI: Problem loading in-kernel X.509 certificate (-65)Maintenance Mode filesystem size: 2.0G`
|
||||||
|
|
||||||
|
## PAN-120440
|
||||||
|
|
||||||
|
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||||
|
|
||||||
|
## PAN-120423
|
||||||
|
|
||||||
|
PAN-OS 10.0.0 does not support the XML API for GlobalProtect logs.
|
||||||
|
|
||||||
|
## PAN-120303
|
||||||
|
|
||||||
|
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||||
|
|
||||||
|
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||||
|
|
||||||
|
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||||
|
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||||
|
2. **Commit** your changes.
|
||||||
|
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||||
|
4. **Commit** your changes.
|
||||||
|
- Restart the firewall (devsrvr) process.
|
||||||
|
1. Log in to the firewall CLI.
|
||||||
|
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||||
|
|
||||||
|
## PAN-116017
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Google Cloud Platform (GCP) only
|
||||||
|
```
|
||||||
|
|
||||||
|
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||||
|
|
||||||
|
## PAN-115816
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Microsoft Azure only
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-114495
|
||||||
|
|
||||||
|
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||||
|
|
||||||
|
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||||
|
|
||||||
|
## PAN-112694
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls with multiple virtual systems only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||||
|
|
||||||
|
## PAN-112456
|
||||||
|
|
||||||
|
You can temporarily submit a change request for a URL Category with three suggested categories; however, only two categories are supported. Do not add more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, only the first two categories in the change request are evaluated.
|
||||||
|
|
||||||
|
## PAN-112135
|
||||||
|
|
||||||
|
You cannot unregister tags for a subnet or range in a dynamic address group from the web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use an XML API request to unregister the tags for the subnet or range.
|
||||||
|
|
||||||
|
## PAN-111928
|
||||||
|
|
||||||
|
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||||
|
|
||||||
|
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||||
|
|
||||||
|
## PAN-111866
|
||||||
|
|
||||||
|
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||||
|
|
||||||
|
**Workaround:** Perform one of the following tasks.
|
||||||
|
|
||||||
|
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||||
|
- Manually select the devices that belong to the modified device group and template configurations.
|
||||||
|
|
||||||
|
## PAN-111729
|
||||||
|
|
||||||
|
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-111670
|
||||||
|
|
||||||
|
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||||
|
|
||||||
|
## PAN-110794
|
||||||
|
|
||||||
|
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||||
|
|
||||||
|
## PAN-109759
|
||||||
|
|
||||||
|
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
|
||||||
|
|
||||||
|
## PAN-109526
|
||||||
|
|
||||||
|
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||||
|
|
||||||
|
## PAN-106675
|
||||||
|
|
||||||
|
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||||
|
|
||||||
|
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||||
|
|
||||||
|
## PAN-104780
|
||||||
|
|
||||||
|
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||||
|
|
||||||
|
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||||
|
|
||||||
|
## PAN-103276
|
||||||
|
|
||||||
|
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||||
|
|
||||||
|
## PAN-101688
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama plugins
|
||||||
|
```
|
||||||
|
|
||||||
|
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||||
|
|
||||||
|
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||||
|
|
||||||
|
## PAN-101537
|
||||||
|
|
||||||
|
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||||
|
|
||||||
|
**Workaround:** Specify the vsys in the query string:
|
||||||
|
|
||||||
|
`admin>` `set system target-vsys <vsys-name>`
|
||||||
|
|
||||||
|
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||||
|
|
||||||
|
## PAN-98520
|
||||||
|
|
||||||
|
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||||
|
|
||||||
|
## PAN-97757
|
||||||
|
|
||||||
|
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||||
|
|
||||||
|
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||||
|
|
||||||
|
## PAN-97524
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama management server only
|
||||||
|
```
|
||||||
|
|
||||||
|
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||||
|
|
||||||
|
## PAN-96446
|
||||||
|
|
||||||
|
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||||
|
|
||||||
|
## PAN-95773
|
||||||
|
|
||||||
|
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||||
|
|
||||||
|
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||||
|
|
||||||
|
## PAN-95511
|
||||||
|
|
||||||
|
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||||
|
|
||||||
|
## PAN-95028
|
||||||
|
|
||||||
|
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||||
|
|
||||||
|
## PAN-94846
|
||||||
|
|
||||||
|
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||||
|
|
||||||
|
## PAN-94093
|
||||||
|
|
||||||
|
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||||
|
|
||||||
|
## PAN-93968
|
||||||
|
|
||||||
|
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||||
|
|
||||||
|
## PAN-93607
|
||||||
|
|
||||||
|
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||||
|
|
||||||
|
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||||
|
|
||||||
|
## PAN-93532
|
||||||
|
|
||||||
|
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||||
|
|
||||||
|
## PAN-93193
|
||||||
|
|
||||||
|
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||||
|
|
||||||
|
- Switch to the firewall **Context** on the Panorama management server.
|
||||||
|
- Commit changes when a dynamic update is being installed.
|
||||||
|
- Generate a custom report when a dynamic update is being installed.
|
||||||
|
- Generate custom reports during a commit.
|
||||||
|
|
||||||
|
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||||
|
|
||||||
|
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||||
|
|
||||||
|
## PAN-91802
|
||||||
|
|
||||||
|
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||||
|
|
||||||
|
## PAN-83610
|
||||||
|
|
||||||
|
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||||
|
|
||||||
|
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-83236
|
||||||
|
|
||||||
|
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||||
|
|
||||||
|
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||||
|
|
||||||
|
## PAN-83215
|
||||||
|
|
||||||
|
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||||
|
|
||||||
|
## PAN-81521
|
||||||
|
|
||||||
|
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||||
|
|
||||||
|
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||||
|
|
||||||
|
## PAN-77125
|
||||||
|
|
||||||
|
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||||
|
|
||||||
|
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-75457
|
||||||
|
|
||||||
|
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||||
|
|
||||||
|
## PAN-73530
|
||||||
|
|
||||||
|
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||||
|
|
||||||
|
## PAN-73401
|
||||||
|
|
||||||
|
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||||
|
|
||||||
|
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||||
|
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||||
|
|
||||||
|
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||||
|
|
||||||
|
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||||
|
- Configure a worker list on the cluster controller:
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||||
|
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||||
|
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||||
|
or
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||||
|
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||||
|
|
||||||
|
## PAN-70906
|
||||||
|
|
||||||
|
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||||
|
|
||||||
|
## PAN-69505
|
||||||
|
|
||||||
|
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||||
|
|
||||||
|
## PAN-41558
|
||||||
|
|
||||||
|
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||||
|
|
||||||
|
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||||
|
|
||||||
|
## PAN-40079
|
||||||
|
|
||||||
|
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||||
|
|
||||||
|
## PAN-39636
|
||||||
|
|
||||||
|
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||||
|
|
||||||
|
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||||
|
|
||||||
|
## PAN-38255
|
||||||
|
|
||||||
|
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||||
|
|
||||||
|
## PAN-31832
|
||||||
|
|
||||||
|
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||||
|
|
||||||
|
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||||
|
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||||
@@ -0,0 +1,647 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 10.0.3
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## APL-8269
|
||||||
|
|
||||||
|
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
|
||||||
|
|
||||||
|
## PLUG-380
|
||||||
|
|
||||||
|
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||||
|
|
||||||
|
## WF500-5471
|
||||||
|
|
||||||
|
After using the firewall CLI to add a WildFire appliance with an IPv6 address, the initial connection may fail.
|
||||||
|
|
||||||
|
**Workaround:** Retry connecting after you restart the web server with the following command: `debug software restart process web-server`.
|
||||||
|
|
||||||
|
## PAN-178194
|
||||||
|
|
||||||
|
A UI issue in PAN-OS renders the contents of the **Inline ML** tab in the **URL Filtering Profile** inaccessible on firewalls licensed for Advanced URL Filtering. Additionally, a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI. These errors do not affect the operation of Advanced URL Filtering or URL Filtering Inline ML.
|
||||||
|
|
||||||
|
**Workaround:** Configuration settings for URL Filtering Inline ML must be applied through the CLI. The following configuration commands are available:
|
||||||
|
|
||||||
|
- Define URL exceptions for specific web sites—
|
||||||
|
`admin#``set profiles url-filtering <url_filtering_profile_name> mlav-category-exception`
|
||||||
|
|
||||||
|
- Configuration settings for each inline ML model—
|
||||||
|
`admin#``set profiles url-filtering <url_filtering_profile_name> mlav-engine-urlbased-enabled`
|
||||||
|
|
||||||
|
## PAN-162743
|
||||||
|
|
||||||
|
In some cases, the firewall may not receive updates for the Device Dictionary, which causes the firewall to replace new attributes in the IP address-to-device mappings with “unknown.”
|
||||||
|
|
||||||
|
**Workaround**: Reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-162059
|
||||||
|
|
||||||
|
When you create a new Layer 3 interface in PAN-OS 10.0.3 or 10.0.4 and then downgrade to PAN-OS 9.1.x, the downgrade fails with the message `Upstream NAT not supported in older version`, whether or not SD-WAN is configured on the firewall.
|
||||||
|
|
||||||
|
**Workaround:** After you create a Layer 3 interface in PAN-OS 10.0.3 or 10.0.4, to downgrade to PAN-OS 9.1.x, perform the following steps:
|
||||||
|
|
||||||
|
1. Issue the following CLI command for each Layer 3 interface you created: `delete network interface ethernet [ethernetslot/port] layer3 sdwan-link-settings upstream-nat`.
|
||||||
|
2. Commit the changes.
|
||||||
|
3. Downgrade the PAN-OS version.
|
||||||
|
|
||||||
|
## PAN-161121
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 10.0.4 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
On the Panorama management server, invalid reference errors occur when attempting to delete an address object (**Objects** > **Addresses**) after removing the address object reference from an address group (**Objects** > **Address Groups**) resulting in you being unable commit and push the configuration to managed firewalls.
|
||||||
|
|
||||||
|
**Workaround:** Log in to the [Panorama CLI](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli.html) and restart `configd`.
|
||||||
|
|
||||||
|
`admin>``debug software restart process configd`
|
||||||
|
|
||||||
|
## PAN-160163
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 10.0.4 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
Icons in the left sidebar have multiple layers. This issue does not affect any functionality.
|
||||||
|
|
||||||
|
## PAN-157885
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 10.0.4 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
When you configure an SD-WAN full mesh VPN cluster, Auto VPN automatically creates an M x N mesh between all devices you add, regardless of whether they are branches or hubs. This mesh configuration will have tunnels that connect low-cost services to higher-cost services and there is no way for you to prioritize the tunnel preference. For example, a low-cost broadband link at site A will create a VPN tunnel to a high-cost LTE link at site B and traffic will be sent over the tunnel members of the virtual interface without prioritization.
|
||||||
|
|
||||||
|
## PAN-157444
|
||||||
|
|
||||||
|
As a result of a telemetry handling update, the Source Zone field in the DNS analytics logs (viewable in the DNS Analytics tab within AutoFocus) might not display correct results.
|
||||||
|
|
||||||
|
## PAN-157327
|
||||||
|
|
||||||
|
On downgrade to PAN-OS 9.1, Enterprise Data Loss Prevention (DLP) filtering settings (**Device** > **Setup** > **DLP**) are not removed and cause commit errors for the downgraded firewall if you do not uninstall the Enterprise DLP plugin before downgrade.
|
||||||
|
|
||||||
|
**Workaround:** After you successfully downgrade a managed firewall to PAN-OS 9.1, commit and push from Panorama to remove the Enterprise DLP filtering settings and complete the downgrade.
|
||||||
|
|
||||||
|
1. Downgrade your managed firewall to PAN-OS 9.1
|
||||||
|
2. Log in to the firewall web interface and view the **Tasks** to verify all auto commits related to the downgrade have completed successfully.
|
||||||
|
3. Log in to the Panorama web interface and **Commit** > **Commit and Push** to your managed firewall downgraded to PAN-OS 9.1.
|
||||||
|
|
||||||
|
## PAN-157103
|
||||||
|
|
||||||
|
Multi-channel functionality may not be properly utilized on an VM-Series firewall deployed in VMware NSX-V after the service is first deployed.
|
||||||
|
|
||||||
|
**Workaround**: Execute the command `debug dataplane pow status` to view the number of channels being utilized by the dataplane.
|
||||||
|
|
||||||
|
Per pan-task Netx statisticsCounter Name 1 2 3 4 5 6 Total---------------------------------------------ready_dvf 2 0 0 0 0 0 2
|
||||||
|
|
||||||
|
If multi-channel functionality is not working, disable your NSX-V security policy and reapply it. Then reboot the VM-Series firewall. When the firewall is back up, verify that multi-channel functionality is working by executing the command `debug dataplane pow status`. It should now show multiple channels being utilized.
|
||||||
|
|
||||||
|
Per pan-task Netx statisticsCounter Name 1 2 3 4 5 6 Total---------------------------------------------ready_dvf 1 1 0 0 0 0 2
|
||||||
|
|
||||||
|
## PAN-156645
|
||||||
|
|
||||||
|
If the SD-WAN interface was Down and it comes Up during a commit (for example, if you configure it from Down to Auto), SD-WAN ignores the change and keeps the link Down in the SD-WAN connection. In this case, SD-WAN won't choose to send traffic to this link. If this is the only link to the internet, this behavior may cause an outage, including failure of the IKE negotiation between the Branch and Hub, and such Tunnel will be down.
|
||||||
|
|
||||||
|
**Workaround**: Commit again or toggle the interface link Down and Up; the SD-WAN statistics will be correct and the problem will resolve.
|
||||||
|
|
||||||
|
## PAN-156598
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure a standard custom vulnerability signature in a custom Vulnerability Protection profile in a shared device group, the shared profile custom signatures do not populate in the other device groups when you configure a combination custom vulnerability signature.
|
||||||
|
|
||||||
|
**Workaround:** Use the CLI to update the combination signature.
|
||||||
|
|
||||||
|
## PAN-154292
|
||||||
|
|
||||||
|
On the Panorama management server, downgrading from a PAN-OS 10.0 release to a PAN-OS 9.1 release causes Panorama commit (**Commit** > **Commit to Panorama**) failures if a custom report (**Monitor** > **Manage Custom Reports**) is configured to Group By **Session ID**.
|
||||||
|
|
||||||
|
**Workaround:** After successful downgrade, reconfigure the Group By setting in the custom report.
|
||||||
|
|
||||||
|
## PAN-154266
|
||||||
|
|
||||||
|
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
|
||||||
|
|
||||||
|
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
|
||||||
|
|
||||||
|
## PAN-154034
|
||||||
|
|
||||||
|
On the Panorama management server, the Type column in the System logs (**Monitor** > **Logs** > **System**) for managed firewalls running a PAN-OS 9.1 release erroneously display `iot` as the type.
|
||||||
|
|
||||||
|
## PAN-154032
|
||||||
|
|
||||||
|
On the Panorama management server, downgrading to PAN-OS 9.1 with the Panorama plugin for Cisco TrustSec version 1.0.2 installed does not automatically transform the plugin to be compatible with PAN-OS 9.1
|
||||||
|
|
||||||
|
**Workaround:** After successful downgrade to PAN-OS 9.1, **Remove Config** (**Panorama** > **Plugins**) of the Panorama plugin for Cisco TrustSec and then reconfigure the plugin.
|
||||||
|
|
||||||
|
## PAN-153803
|
||||||
|
|
||||||
|
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
|
||||||
|
|
||||||
|
## PAN-153557
|
||||||
|
|
||||||
|
On the Panorama management server CLI, the overall report status for a report query is marked as `Done` despite reports generated from logs in the Cortex Data Lake (CDL) from the PODamericas Collector Group jobs are still in a `Running` state.
|
||||||
|
|
||||||
|
## PAN-153068
|
||||||
|
|
||||||
|
The Bonjour Reflector option is supported on up to 16 interfaces. If you enable it on more than 16 interfaces, the commit succeeds and the Bonjour Reflector option is enabled only for the first 16 interfaces and ignored for any additional interfaces.
|
||||||
|
|
||||||
|
## PAN-152825
|
||||||
|
|
||||||
|
On the Panorama management server, you cannot view the SD-WAN license installed on an SD-WAN firewall (**Panorama** > **Device Deployment** > **Licenses**).
|
||||||
|
|
||||||
|
**Workaround:** [Log in to the Panorama CLI](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli.html) and enter the following command to view the SDWAN license information for your managed firewalls.
|
||||||
|
|
||||||
|
`admin>``request batch license info`
|
||||||
|
|
||||||
|
## PAN-152433
|
||||||
|
|
||||||
|
When you have an active/passive HA pair of PA-3200 Series firewalls running PAN-OS 10.0.0 with NAT configured, if you upgrade one firewall to PAN-OS 10.0.1, the firewall goes to non-functional state due to a NAT oversubscription mismatch between the HA peers. The same non-functional state results if both HA peers are running PAN-OS 10.0.1 and you downgrade one to PAN-OS 10.00. The upgraded or downgraded firewall goes to non-functional state because PAN-OS 10.0.0 and 10.0.1 have different default NAT oversubscription rates.
|
||||||
|
|
||||||
|
**Workaround**: After an upgrade or downgrade, modify the NAT oversubscription rate on one firewall so that the rates on the HA pair match.
|
||||||
|
|
||||||
|
## PAN-151238
|
||||||
|
|
||||||
|
There is a known issue where M-100 appliances are able to download and install a PAN-OS 10.0 release image even though the M-100 appliance is no longer supported after PAN-OS 9.1. (Refer to the [hardware end-of-life dates](https://www.paloaltonetworks.com/services/support/end-of-life-announcements/hardware-end-of-life-dates.html).)
|
||||||
|
|
||||||
|
## PAN-151198
|
||||||
|
|
||||||
|
On the Panorama management server, read-only Panorama administrators (**Panorama** > **Administrators**) can load managed firewall configuration Backups (**Panorama** > **Managed Devices** > **Summary**).
|
||||||
|
|
||||||
|
## PAN-151115
|
||||||
|
|
||||||
|
If a Security rule uses a IP Address External Dynamic List (EDL) for IPv6 traffic, the information for the EDL does not display in the Source EDL or Destination EDL columns in the logs.
|
||||||
|
|
||||||
|
## PAN-151085
|
||||||
|
|
||||||
|
On a PA-7000 Series firewall chassis having multiple slots, when HA clustering is enabled on an active/active HA pair, the session table count for one of the peers can show a higher count than the actual number of active sessions on that peer. This behavior can be seen when the session is being set up on a non-cache slot (for example, when a session distribution policy is set to round-robin or session-load); it is caused by the additional cache lookup that happens when HA cluster participation is enabled.
|
||||||
|
|
||||||
|
## PAN-150801
|
||||||
|
|
||||||
|
Automatic quarantine of a device based on forwarding profile or log setting does not work on the PA-7000 Series firewalls.
|
||||||
|
|
||||||
|
## PAN-150515
|
||||||
|
|
||||||
|
After you install the device certificate on a new Panorama management server, Panorama is not able to connect to the IoT Security edge service.
|
||||||
|
|
||||||
|
**Workaround:** Restart Panorama to connect to the IoT Security edge service.
|
||||||
|
|
||||||
|
## PAN-150345
|
||||||
|
|
||||||
|
During updates to the Device Dictionary, the IoT Security service does not push new Device-ID attributes (such as new device profiles) to the firewall until a manual commit occurs.
|
||||||
|
|
||||||
|
**Workaround:** Perform a force commit to push the attributes in the content update to the firewall.
|
||||||
|
|
||||||
|
## PAN-150361
|
||||||
|
|
||||||
|
In an Active-Passive high availability (HA) configuration, an error displays if you create a device object on the passive device.
|
||||||
|
|
||||||
|
**Workaround:** Load the running configuration and perform a force commit to sync the devices.
|
||||||
|
|
||||||
|
## PAN-148971
|
||||||
|
|
||||||
|
If you enter a search term for Events that are related to IoT in the System logs and apply the filter, the page displays an `Invalid term` error.
|
||||||
|
|
||||||
|
**Workaround:** Specify `iot` as the **Type Attribute** to filter the logs and use the search term as the **Description Attribute**. For example: `( subtype eq iot ) and ( description contains 'gRPC connection' )`.
|
||||||
|
|
||||||
|
## PAN-148924
|
||||||
|
|
||||||
|
In an active-passive HA configuration, tags for dynamic user groups are not persistent after rebooting the firewall because the active firewall does not sync the tags to the passive firewall during failover.
|
||||||
|
|
||||||
|
## PAN-146995
|
||||||
|
|
||||||
|
After downgrading a Panorama management server from PAN-OS 10.0 to PAN-OS 9.1, the `VLD` and `logd` processes may crash when Panorama reboots.
|
||||||
|
|
||||||
|
**Workaround:** Panorama automatically restarts the `VLD` and `logd` processes.
|
||||||
|
|
||||||
|
## PAN-146807
|
||||||
|
|
||||||
|
Changing the device group configured in a monitoring definition from a child DG to a parent DG, or vice versa, might cause firewalls configured in the child DG to lose IP tag mapping information received from the monitoring definition. Only firewalls assigned to the parent DG receive IP tag mapping updates.
|
||||||
|
|
||||||
|
**Workaround**: Perform a manual config sync on the device group that lost the IP tag mapping information.
|
||||||
|
|
||||||
|
## PAN-146573
|
||||||
|
|
||||||
|
PA-7000 Series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||||
|
|
||||||
|
## PAN-146485
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
|
||||||
|
|
||||||
|
## PAN-145460
|
||||||
|
|
||||||
|
CN-MGMT pods fail to connect to the Panorama management server when using the Kubernetes plugin.
|
||||||
|
|
||||||
|
**Workaround:** **Commit** the Panorama configuration after the CN-MGMT pod successfully registers with Panorama.
|
||||||
|
|
||||||
|
## PAN-144889
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
|
||||||
|
|
||||||
|
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
|
||||||
|
|
||||||
|
## PAN-143132
|
||||||
|
|
||||||
|
Fetching the device certificate from the Palo Alto Networks Customer Support Portal (CSP) may fail and displays the following error in the CLI:
|
||||||
|
|
||||||
|
`ERROR Failed to process S1C msg: Error`
|
||||||
|
|
||||||
|
**Workaround:** Retrying fetching the device certificate from the Palo Alto Networks CSP.
|
||||||
|
|
||||||
|
## PAN-141630
|
||||||
|
|
||||||
|
Current performance limitation: single data plane use only. The PA-5200 Series and PA-7000 Series firewalls that support 5G network slice security, 5G equipment ID security, and 5G subscriber ID security use a single data plane only, which currently limits the firewall performance.
|
||||||
|
|
||||||
|
## PAN-140959
|
||||||
|
|
||||||
|
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
|
||||||
|
|
||||||
|
## PAN-140008
|
||||||
|
|
||||||
|
ElasticSearch is forced to restart when the `masterd` process misses too many heartbeat messages on the Panorama management server resulting in a delay in a log query and ingestion.
|
||||||
|
|
||||||
|
## PAN-136763
|
||||||
|
|
||||||
|
On the Panorama management server, managed firewalls display as `disconnected` when installing a PAN-OS software update (**Panorama** > **Device Deployment** > **Software**) but display as `connected` when you view your managed firewalls Summary (**Panorama** > **Managed Devices** > **Summary**) and from the CLI.
|
||||||
|
|
||||||
|
**Workaround:** Log out and log back in to the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-136701
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000b Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Packets for new sessions drop when handling predict sessions.
|
||||||
|
|
||||||
|
**Workaround:** Use the following CLi commands to bypass this issue:
|
||||||
|
|
||||||
|
- `set session hwpredict disable yes`
|
||||||
|
- `show session hwpredict status`
|
||||||
|
|
||||||
|
## PAN-135742
|
||||||
|
|
||||||
|
There is an issue in HTTP2 session decryption where the App-ID in the decryption log is the App-ID of the parent session (which is web-browsing).
|
||||||
|
|
||||||
|
## PAN-134053
|
||||||
|
|
||||||
|
ACC does not filter WildFire logs from Dynamic User Groups.
|
||||||
|
|
||||||
|
## PAN-132598
|
||||||
|
|
||||||
|
The Panorama management server does not check for duplicate addresses in address groups (**Objects** > **Address Groups**) and duplicate services in service groups (**Objects** > **Service Groups**) when created from the CLI.
|
||||||
|
|
||||||
|
## PAN-130550
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
|
||||||
|
|
||||||
|
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
|
||||||
|
|
||||||
|
## PAN-127813
|
||||||
|
|
||||||
|
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches don’t communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
|
||||||
|
|
||||||
|
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
|
||||||
|
|
||||||
|
## PAN-127206
|
||||||
|
|
||||||
|
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
|
||||||
|
|
||||||
|
## PAN-123277
|
||||||
|
|
||||||
|
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-123040
|
||||||
|
|
||||||
|
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules don’t display. A workaround exists for this issue. Please contact Support for information about the workaround.
|
||||||
|
|
||||||
|
## PAN-121678
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000b Series only
|
||||||
|
```
|
||||||
|
|
||||||
|
The following error during secure boot has no impact and can be ignored:
|
||||||
|
|
||||||
|
`[ 0.672461] Device 'efifb.0' does not have a release() function, it is broken and must be fixed.[ 2.026107] EFI: Problem loading in-kernel X.509 certificate (-65)Maintenance Mode filesystem size: 2.0G`
|
||||||
|
|
||||||
|
## PAN-120440
|
||||||
|
|
||||||
|
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||||
|
|
||||||
|
## PAN-120423
|
||||||
|
|
||||||
|
PAN-OS 10.0.0 does not support the XML API for GlobalProtect logs.
|
||||||
|
|
||||||
|
## PAN-120303
|
||||||
|
|
||||||
|
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||||
|
|
||||||
|
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||||
|
|
||||||
|
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||||
|
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||||
|
2. **Commit** your changes.
|
||||||
|
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||||
|
4. **Commit** your changes.
|
||||||
|
- Restart the firewall (devsrvr) process.
|
||||||
|
1. Log in to the firewall CLI.
|
||||||
|
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||||
|
|
||||||
|
## PAN-116017
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Google Cloud Platform (GCP) only
|
||||||
|
```
|
||||||
|
|
||||||
|
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||||
|
|
||||||
|
## PAN-115816
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Microsoft Azure only
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-114495
|
||||||
|
|
||||||
|
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||||
|
|
||||||
|
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||||
|
|
||||||
|
## PAN-112694
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls with multiple virtual systems only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||||
|
|
||||||
|
## PAN-112456
|
||||||
|
|
||||||
|
You can temporarily submit a change request for a URL Category with three suggested categories; however, only two categories are supported. Do not add more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, only the first two categories in the change request are evaluated.
|
||||||
|
|
||||||
|
## PAN-112135
|
||||||
|
|
||||||
|
You cannot unregister tags for a subnet or range in a dynamic address group from the web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use an XML API request to unregister the tags for the subnet or range.
|
||||||
|
|
||||||
|
## PAN-111928
|
||||||
|
|
||||||
|
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||||
|
|
||||||
|
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||||
|
|
||||||
|
## PAN-111866
|
||||||
|
|
||||||
|
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||||
|
|
||||||
|
**Workaround:** Perform one of the following tasks.
|
||||||
|
|
||||||
|
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||||
|
- Manually select the devices that belong to the modified device group and template configurations.
|
||||||
|
|
||||||
|
## PAN-111729
|
||||||
|
|
||||||
|
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-111670
|
||||||
|
|
||||||
|
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||||
|
|
||||||
|
## PAN-110794
|
||||||
|
|
||||||
|
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||||
|
|
||||||
|
## PAN-109759
|
||||||
|
|
||||||
|
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
|
||||||
|
|
||||||
|
## PAN-109526
|
||||||
|
|
||||||
|
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||||
|
|
||||||
|
## PAN-106675
|
||||||
|
|
||||||
|
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||||
|
|
||||||
|
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||||
|
|
||||||
|
## PAN-104780
|
||||||
|
|
||||||
|
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||||
|
|
||||||
|
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||||
|
|
||||||
|
## PAN-103276
|
||||||
|
|
||||||
|
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||||
|
|
||||||
|
## PAN-101688
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama plugins
|
||||||
|
```
|
||||||
|
|
||||||
|
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||||
|
|
||||||
|
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||||
|
|
||||||
|
## PAN-101537
|
||||||
|
|
||||||
|
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||||
|
|
||||||
|
**Workaround:** Specify the vsys in the query string:
|
||||||
|
|
||||||
|
`admin>` `set system target-vsys <vsys-name>`
|
||||||
|
|
||||||
|
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||||
|
|
||||||
|
## PAN-98520
|
||||||
|
|
||||||
|
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||||
|
|
||||||
|
## PAN-97757
|
||||||
|
|
||||||
|
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||||
|
|
||||||
|
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||||
|
|
||||||
|
## PAN-97524
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama management server only
|
||||||
|
```
|
||||||
|
|
||||||
|
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||||
|
|
||||||
|
## PAN-96446
|
||||||
|
|
||||||
|
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||||
|
|
||||||
|
## PAN-95773
|
||||||
|
|
||||||
|
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||||
|
|
||||||
|
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||||
|
|
||||||
|
## PAN-95511
|
||||||
|
|
||||||
|
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||||
|
|
||||||
|
## PAN-95028
|
||||||
|
|
||||||
|
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||||
|
|
||||||
|
## PAN-94846
|
||||||
|
|
||||||
|
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||||
|
|
||||||
|
## PAN-94093
|
||||||
|
|
||||||
|
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||||
|
|
||||||
|
## PAN-93968
|
||||||
|
|
||||||
|
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||||
|
|
||||||
|
## PAN-93607
|
||||||
|
|
||||||
|
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||||
|
|
||||||
|
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||||
|
|
||||||
|
## PAN-93532
|
||||||
|
|
||||||
|
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||||
|
|
||||||
|
## PAN-93193
|
||||||
|
|
||||||
|
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||||
|
|
||||||
|
- Switch to the firewall **Context** on the Panorama management server.
|
||||||
|
- Commit changes when a dynamic update is being installed.
|
||||||
|
- Generate a custom report when a dynamic update is being installed.
|
||||||
|
- Generate custom reports during a commit.
|
||||||
|
|
||||||
|
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||||
|
|
||||||
|
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||||
|
|
||||||
|
## PAN-91802
|
||||||
|
|
||||||
|
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||||
|
|
||||||
|
## PAN-83610
|
||||||
|
|
||||||
|
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||||
|
|
||||||
|
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-83236
|
||||||
|
|
||||||
|
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||||
|
|
||||||
|
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||||
|
|
||||||
|
## PAN-83215
|
||||||
|
|
||||||
|
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||||
|
|
||||||
|
## PAN-81521
|
||||||
|
|
||||||
|
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||||
|
|
||||||
|
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||||
|
|
||||||
|
## PAN-77125
|
||||||
|
|
||||||
|
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||||
|
|
||||||
|
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-75457
|
||||||
|
|
||||||
|
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||||
|
|
||||||
|
## PAN-73530
|
||||||
|
|
||||||
|
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||||
|
|
||||||
|
## PAN-73401
|
||||||
|
|
||||||
|
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||||
|
|
||||||
|
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||||
|
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||||
|
|
||||||
|
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||||
|
|
||||||
|
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||||
|
- Configure a worker list on the cluster controller:
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||||
|
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||||
|
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||||
|
or
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||||
|
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||||
|
|
||||||
|
## PAN-70906
|
||||||
|
|
||||||
|
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||||
|
|
||||||
|
## PAN-69505
|
||||||
|
|
||||||
|
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||||
|
|
||||||
|
## PAN-41558
|
||||||
|
|
||||||
|
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||||
|
|
||||||
|
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||||
|
|
||||||
|
## PAN-40079
|
||||||
|
|
||||||
|
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||||
|
|
||||||
|
## PAN-39636
|
||||||
|
|
||||||
|
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||||
|
|
||||||
|
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||||
|
|
||||||
|
## PAN-38255
|
||||||
|
|
||||||
|
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||||
|
|
||||||
|
## PAN-31832
|
||||||
|
|
||||||
|
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||||
|
|
||||||
|
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||||
|
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||||
@@ -0,0 +1,603 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 10.0.5
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## APL-8269
|
||||||
|
|
||||||
|
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
|
||||||
|
|
||||||
|
## PLUG-380
|
||||||
|
|
||||||
|
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||||
|
|
||||||
|
## WF500-5471
|
||||||
|
|
||||||
|
After using the firewall CLI to add a WildFire appliance with an IPv6 address, the initial connection may fail.
|
||||||
|
|
||||||
|
**Workaround:** Retry connecting after you restart the web server with the following command: `debug software restart process web-server`.
|
||||||
|
|
||||||
|
## PAN-178194
|
||||||
|
|
||||||
|
A UI issue in PAN-OS renders the contents of the **Inline ML** tab in the **URL Filtering Profile** inaccessible on firewalls licensed for Advanced URL Filtering. Additionally, a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI. These errors do not affect the operation of Advanced URL Filtering or URL Filtering Inline ML.
|
||||||
|
|
||||||
|
**Workaround:** Configuration settings for URL Filtering Inline ML must be applied through the CLI. The following configuration commands are available:
|
||||||
|
|
||||||
|
- Define URL exceptions for specific web sites—
|
||||||
|
`admin#``set profiles url-filtering <url_filtering_profile_name> mlav-category-exception`
|
||||||
|
|
||||||
|
- Configuration settings for each inline ML model—
|
||||||
|
`admin#``set profiles url-filtering <url_filtering_profile_name> mlav-engine-urlbased-enabled`
|
||||||
|
|
||||||
|
## PAN-157444
|
||||||
|
|
||||||
|
As a result of a telemetry handling update, the Source Zone field in the DNS analytics logs (viewable in the DNS Analytics tab within AutoFocus) might not display correct results.
|
||||||
|
|
||||||
|
## PAN-157327
|
||||||
|
|
||||||
|
On downgrade to PAN-OS 9.1, Enterprise Data Loss Prevention (DLP) filtering settings (**Device** > **Setup** > **DLP**) are not removed and cause commit errors for the downgraded firewall if you do not uninstall the Enterprise DLP plugin before downgrade.
|
||||||
|
|
||||||
|
**Workaround:** After you successfully downgrade a managed firewall to PAN-OS 9.1, commit and push from Panorama to remove the Enterprise DLP filtering settings and complete the downgrade.
|
||||||
|
|
||||||
|
1. Downgrade your managed firewall to PAN-OS 9.1
|
||||||
|
2. Log in to the firewall web interface and view the **Tasks** to verify all auto commits related to the downgrade have completed successfully.
|
||||||
|
3. Log in to the Panorama web interface and **Commit** > **Commit and Push** to your managed firewall downgraded to PAN-OS 9.1.
|
||||||
|
|
||||||
|
## PAN-157103
|
||||||
|
|
||||||
|
Multi-channel functionality may not be properly utilized on an VM-Series firewall deployed in VMware NSX-V after the service is first deployed.
|
||||||
|
|
||||||
|
**Workaround**: Execute the command `debug dataplane pow status` to view the number of channels being utilized by the dataplane.
|
||||||
|
|
||||||
|
Per pan-task Netx statisticsCounter Name 1 2 3 4 5 6 Total---------------------------------------------ready_dvf 2 0 0 0 0 0 2
|
||||||
|
|
||||||
|
If multi-channel functionality is not working, disable your NSX-V security policy and reapply it. Then reboot the VM-Series firewall. When the firewall is back up, verify that multi-channel functionality is working by executing the command `debug dataplane pow status`. It should now show multiple channels being utilized.
|
||||||
|
|
||||||
|
Per pan-task Netx statisticsCounter Name 1 2 3 4 5 6 Total---------------------------------------------ready_dvf 1 1 0 0 0 0 2
|
||||||
|
|
||||||
|
## PAN-156645
|
||||||
|
|
||||||
|
If the SD-WAN interface was Down and it comes Up during a commit (for example, if you configure it from Down to Auto), SD-WAN ignores the change and keeps the link Down in the SD-WAN connection. In this case, SD-WAN won't choose to send traffic to this link. If this is the only link to the internet, this behavior may cause an outage, including failure of the IKE negotiation between the Branch and Hub, and such Tunnel will be down.
|
||||||
|
|
||||||
|
**Workaround**: Commit again or toggle the interface link Down and Up; the SD-WAN statistics will be correct and the problem will resolve.
|
||||||
|
|
||||||
|
## PAN-156598
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure a standard custom vulnerability signature in a custom Vulnerability Protection profile in a shared device group, the shared profile custom signatures do not populate in the other device groups when you configure a combination custom vulnerability signature.
|
||||||
|
|
||||||
|
**Workaround:** Use the CLI to update the combination signature.
|
||||||
|
|
||||||
|
## PAN-154292
|
||||||
|
|
||||||
|
On the Panorama management server, downgrading from a PAN-OS 10.0 release to a PAN-OS 9.1 release causes Panorama commit (**Commit** > **Commit to Panorama**) failures if a custom report (**Monitor** > **Manage Custom Reports**) is configured to Group By **Session ID**.
|
||||||
|
|
||||||
|
**Workaround:** After successful downgrade, reconfigure the Group By setting in the custom report.
|
||||||
|
|
||||||
|
## PAN-154266
|
||||||
|
|
||||||
|
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
|
||||||
|
|
||||||
|
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
|
||||||
|
|
||||||
|
## PAN-154034
|
||||||
|
|
||||||
|
On the Panorama management server, the Type column in the System logs (**Monitor** > **Logs** > **System**) for managed firewalls running a PAN-OS 9.1 release erroneously display `iot` as the type.
|
||||||
|
|
||||||
|
## PAN-154032
|
||||||
|
|
||||||
|
On the Panorama management server, downgrading to PAN-OS 9.1 with the Panorama plugin for Cisco TrustSec version 1.0.2 installed does not automatically transform the plugin to be compatible with PAN-OS 9.1
|
||||||
|
|
||||||
|
**Workaround:** After successful downgrade to PAN-OS 9.1, **Remove Config** (**Panorama** > **Plugins**) of the Panorama plugin for Cisco TrustSec and then reconfigure the plugin.
|
||||||
|
|
||||||
|
## PAN-153803
|
||||||
|
|
||||||
|
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
|
||||||
|
|
||||||
|
## PAN-153557
|
||||||
|
|
||||||
|
On the Panorama management server CLI, the overall report status for a report query is marked as `Done` despite reports generated from logs in the Cortex Data Lake (CDL) from the PODamericas Collector Group jobs are still in a `Running` state.
|
||||||
|
|
||||||
|
## PAN-153068
|
||||||
|
|
||||||
|
The Bonjour Reflector option is supported on up to 16 interfaces. If you enable it on more than 16 interfaces, the commit succeeds and the Bonjour Reflector option is enabled only for the first 16 interfaces and ignored for any additional interfaces.
|
||||||
|
|
||||||
|
## PAN-152825
|
||||||
|
|
||||||
|
On the Panorama management server, you cannot view the SD-WAN license installed on an SD-WAN firewall (**Panorama** > **Device Deployment** > **Licenses**).
|
||||||
|
|
||||||
|
**Workaround:** [Log in to the Panorama CLI](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli.html) and enter the following command to view the SDWAN license information for your managed firewalls.
|
||||||
|
|
||||||
|
`admin>``request batch license info`
|
||||||
|
|
||||||
|
## PAN-152433
|
||||||
|
|
||||||
|
When you have an active/passive HA pair of PA-3200 Series firewalls running PAN-OS 10.0.0 with NAT configured, if you upgrade one firewall to PAN-OS 10.0.1, the firewall goes to non-functional state due to a NAT oversubscription mismatch between the HA peers. The same non-functional state results if both HA peers are running PAN-OS 10.0.1 and you downgrade one to PAN-OS 10.00. The upgraded or downgraded firewall goes to non-functional state because PAN-OS 10.0.0 and 10.0.1 have different default NAT oversubscription rates.
|
||||||
|
|
||||||
|
**Workaround**: After an upgrade or downgrade, modify the NAT oversubscription rate on one firewall so that the rates on the HA pair match.
|
||||||
|
|
||||||
|
## PAN-151238
|
||||||
|
|
||||||
|
There is a known issue where M-100 appliances are able to download and install a PAN-OS 10.0 release image even though the M-100 appliance is no longer supported after PAN-OS 9.1. (Refer to the [hardware end-of-life dates](https://www.paloaltonetworks.com/services/support/end-of-life-announcements/hardware-end-of-life-dates.html).)
|
||||||
|
|
||||||
|
## PAN-151198
|
||||||
|
|
||||||
|
On the Panorama management server, read-only Panorama administrators (**Panorama** > **Administrators**) can load managed firewall configuration Backups (**Panorama** > **Managed Devices** > **Summary**).
|
||||||
|
|
||||||
|
## PAN-151115
|
||||||
|
|
||||||
|
If a Security rule uses a IP Address External Dynamic List (EDL) for IPv6 traffic, the information for the EDL does not display in the Source EDL or Destination EDL columns in the logs.
|
||||||
|
|
||||||
|
## PAN-151085
|
||||||
|
|
||||||
|
On a PA-7000 Series firewall chassis having multiple slots, when HA clustering is enabled on an active/active HA pair, the session table count for one of the peers can show a higher count than the actual number of active sessions on that peer. This behavior can be seen when the session is being set up on a non-cache slot (for example, when a session distribution policy is set to round-robin or session-load); it is caused by the additional cache lookup that happens when HA cluster participation is enabled.
|
||||||
|
|
||||||
|
## PAN-150801
|
||||||
|
|
||||||
|
Automatic quarantine of a device based on forwarding profile or log setting does not work on the PA-7000 Series firewalls.
|
||||||
|
|
||||||
|
## PAN-150515
|
||||||
|
|
||||||
|
After you install the device certificate on a new Panorama management server, Panorama is not able to connect to the IoT Security edge service.
|
||||||
|
|
||||||
|
**Workaround:** Restart Panorama to connect to the IoT Security edge service.
|
||||||
|
|
||||||
|
## PAN-150345
|
||||||
|
|
||||||
|
During updates to the Device Dictionary, the IoT Security service does not push new Device-ID attributes (such as new device profiles) to the firewall until a manual commit occurs.
|
||||||
|
|
||||||
|
**Workaround:** Perform a force commit to push the attributes in the content update to the firewall.
|
||||||
|
|
||||||
|
## PAN-150361
|
||||||
|
|
||||||
|
In an Active-Passive high availability (HA) configuration, an error displays if you create a device object on the passive device.
|
||||||
|
|
||||||
|
**Workaround:** Load the running configuration and perform a force commit to sync the devices.
|
||||||
|
|
||||||
|
## PAN-148971
|
||||||
|
|
||||||
|
If you enter a search term for Events that are related to IoT in the System logs and apply the filter, the page displays an `Invalid term` error.
|
||||||
|
|
||||||
|
**Workaround:** Specify `iot` as the **Type Attribute** to filter the logs and use the search term as the **Description Attribute**. For example: `( subtype eq iot ) and ( description contains 'gRPC connection' )`.
|
||||||
|
|
||||||
|
## PAN-148924
|
||||||
|
|
||||||
|
In an active-passive HA configuration, tags for dynamic user groups are not persistent after rebooting the firewall because the active firewall does not sync the tags to the passive firewall during failover.
|
||||||
|
|
||||||
|
## PAN-146995
|
||||||
|
|
||||||
|
After downgrading a Panorama management server from PAN-OS 10.0 to PAN-OS 9.1, the `VLD` and `logd` processes may crash when Panorama reboots.
|
||||||
|
|
||||||
|
**Workaround:** Panorama automatically restarts the `VLD` and `logd` processes.
|
||||||
|
|
||||||
|
## PAN-146807
|
||||||
|
|
||||||
|
Changing the device group configured in a monitoring definition from a child DG to a parent DG, or vice versa, might cause firewalls configured in the child DG to lose IP tag mapping information received from the monitoring definition. Only firewalls assigned to the parent DG receive IP tag mapping updates.
|
||||||
|
|
||||||
|
**Workaround**: Perform a manual config sync on the device group that lost the IP tag mapping information.
|
||||||
|
|
||||||
|
## PAN-146573
|
||||||
|
|
||||||
|
PA-7000 Series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||||
|
|
||||||
|
## PAN-146485
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
|
||||||
|
|
||||||
|
## PAN-145460
|
||||||
|
|
||||||
|
CN-MGMT pods fail to connect to the Panorama management server when using the Kubernetes plugin.
|
||||||
|
|
||||||
|
**Workaround:** **Commit** the Panorama configuration after the CN-MGMT pod successfully registers with Panorama.
|
||||||
|
|
||||||
|
## PAN-144889
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
|
||||||
|
|
||||||
|
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
|
||||||
|
|
||||||
|
## PAN-143132
|
||||||
|
|
||||||
|
Fetching the device certificate from the Palo Alto Networks Customer Support Portal (CSP) may fail and displays the following error in the CLI:
|
||||||
|
|
||||||
|
`ERROR Failed to process S1C msg: Error`
|
||||||
|
|
||||||
|
**Workaround:** Retrying fetching the device certificate from the Palo Alto Networks CSP.
|
||||||
|
|
||||||
|
## PAN-141630
|
||||||
|
|
||||||
|
Current performance limitation: single data plane use only. The PA-5200 Series and PA-7000 Series firewalls that support 5G network slice security, 5G equipment ID security, and 5G subscriber ID security use a single data plane only, which currently limits the firewall performance.
|
||||||
|
|
||||||
|
## PAN-140959
|
||||||
|
|
||||||
|
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
|
||||||
|
|
||||||
|
## PAN-140008
|
||||||
|
|
||||||
|
ElasticSearch is forced to restart when the `masterd` process misses too many heartbeat messages on the Panorama management server resulting in a delay in a log query and ingestion.
|
||||||
|
|
||||||
|
## PAN-136763
|
||||||
|
|
||||||
|
On the Panorama management server, managed firewalls display as `disconnected` when installing a PAN-OS software update (**Panorama** > **Device Deployment** > **Software**) but display as `connected` when you view your managed firewalls Summary (**Panorama** > **Managed Devices** > **Summary**) and from the CLI.
|
||||||
|
|
||||||
|
**Workaround:** Log out and log back in to the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-136701
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000b Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Packets for new sessions drop when handling predict sessions.
|
||||||
|
|
||||||
|
**Workaround:** Use the following CLi commands to bypass this issue:
|
||||||
|
|
||||||
|
- `set session hwpredict disable yes`
|
||||||
|
- `show session hwpredict status`
|
||||||
|
|
||||||
|
## PAN-135742
|
||||||
|
|
||||||
|
There is an issue in HTTP2 session decryption where the App-ID in the decryption log is the App-ID of the parent session (which is web-browsing).
|
||||||
|
|
||||||
|
## PAN-134053
|
||||||
|
|
||||||
|
ACC does not filter WildFire logs from Dynamic User Groups.
|
||||||
|
|
||||||
|
## PAN-132598
|
||||||
|
|
||||||
|
The Panorama management server does not check for duplicate addresses in address groups (**Objects** > **Address Groups**) and duplicate services in service groups (**Objects** > **Service Groups**) when created from the CLI.
|
||||||
|
|
||||||
|
## PAN-130550
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
|
||||||
|
|
||||||
|
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
|
||||||
|
|
||||||
|
## PAN-127813
|
||||||
|
|
||||||
|
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches don’t communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
|
||||||
|
|
||||||
|
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
|
||||||
|
|
||||||
|
## PAN-127206
|
||||||
|
|
||||||
|
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
|
||||||
|
|
||||||
|
## PAN-123277
|
||||||
|
|
||||||
|
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-123040
|
||||||
|
|
||||||
|
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules don’t display. A workaround exists for this issue. Please contact Support for information about the workaround.
|
||||||
|
|
||||||
|
## PAN-121678
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000b Series only
|
||||||
|
```
|
||||||
|
|
||||||
|
The following error during secure boot has no impact and can be ignored:
|
||||||
|
|
||||||
|
`[ 0.672461] Device 'efifb.0' does not have a release() function, it is broken and must be fixed.[ 2.026107] EFI: Problem loading in-kernel X.509 certificate (-65)Maintenance Mode filesystem size: 2.0G`
|
||||||
|
|
||||||
|
## PAN-120440
|
||||||
|
|
||||||
|
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||||
|
|
||||||
|
## PAN-120423
|
||||||
|
|
||||||
|
PAN-OS 10.0.0 does not support the XML API for GlobalProtect logs.
|
||||||
|
|
||||||
|
## PAN-120303
|
||||||
|
|
||||||
|
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||||
|
|
||||||
|
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||||
|
|
||||||
|
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||||
|
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||||
|
2. **Commit** your changes.
|
||||||
|
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||||
|
4. **Commit** your changes.
|
||||||
|
- Restart the firewall (devsrvr) process.
|
||||||
|
1. Log in to the firewall CLI.
|
||||||
|
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||||
|
|
||||||
|
## PAN-116017
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Google Cloud Platform (GCP) only
|
||||||
|
```
|
||||||
|
|
||||||
|
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||||
|
|
||||||
|
## PAN-115816
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Microsoft Azure only
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-114495
|
||||||
|
|
||||||
|
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||||
|
|
||||||
|
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||||
|
|
||||||
|
## PAN-112694
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls with multiple virtual systems only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||||
|
|
||||||
|
## PAN-112456
|
||||||
|
|
||||||
|
You can temporarily submit a change request for a URL Category with three suggested categories; however, only two categories are supported. Do not add more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, only the first two categories in the change request are evaluated.
|
||||||
|
|
||||||
|
## PAN-112135
|
||||||
|
|
||||||
|
You cannot unregister tags for a subnet or range in a dynamic address group from the web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use an XML API request to unregister the tags for the subnet or range.
|
||||||
|
|
||||||
|
## PAN-111928
|
||||||
|
|
||||||
|
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||||
|
|
||||||
|
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||||
|
|
||||||
|
## PAN-111866
|
||||||
|
|
||||||
|
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||||
|
|
||||||
|
**Workaround:** Perform one of the following tasks.
|
||||||
|
|
||||||
|
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||||
|
- Manually select the devices that belong to the modified device group and template configurations.
|
||||||
|
|
||||||
|
## PAN-111729
|
||||||
|
|
||||||
|
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-111670
|
||||||
|
|
||||||
|
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||||
|
|
||||||
|
## PAN-110794
|
||||||
|
|
||||||
|
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||||
|
|
||||||
|
## PAN-109759
|
||||||
|
|
||||||
|
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
|
||||||
|
|
||||||
|
## PAN-109526
|
||||||
|
|
||||||
|
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||||
|
|
||||||
|
## PAN-106675
|
||||||
|
|
||||||
|
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||||
|
|
||||||
|
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||||
|
|
||||||
|
## PAN-104780
|
||||||
|
|
||||||
|
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||||
|
|
||||||
|
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||||
|
|
||||||
|
## PAN-103276
|
||||||
|
|
||||||
|
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||||
|
|
||||||
|
## PAN-101688
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama plugins
|
||||||
|
```
|
||||||
|
|
||||||
|
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||||
|
|
||||||
|
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||||
|
|
||||||
|
## PAN-101537
|
||||||
|
|
||||||
|
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||||
|
|
||||||
|
**Workaround:** Specify the vsys in the query string:
|
||||||
|
|
||||||
|
`admin>` `set system target-vsys <vsys-name>`
|
||||||
|
|
||||||
|
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||||
|
|
||||||
|
## PAN-98520
|
||||||
|
|
||||||
|
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||||
|
|
||||||
|
## PAN-97757
|
||||||
|
|
||||||
|
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||||
|
|
||||||
|
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||||
|
|
||||||
|
## PAN-97524
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama management server only
|
||||||
|
```
|
||||||
|
|
||||||
|
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||||
|
|
||||||
|
## PAN-96446
|
||||||
|
|
||||||
|
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||||
|
|
||||||
|
## PAN-95773
|
||||||
|
|
||||||
|
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||||
|
|
||||||
|
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||||
|
|
||||||
|
## PAN-95511
|
||||||
|
|
||||||
|
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||||
|
|
||||||
|
## PAN-95028
|
||||||
|
|
||||||
|
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||||
|
|
||||||
|
## PAN-94846
|
||||||
|
|
||||||
|
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||||
|
|
||||||
|
## PAN-94093
|
||||||
|
|
||||||
|
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||||
|
|
||||||
|
## PAN-93968
|
||||||
|
|
||||||
|
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||||
|
|
||||||
|
## PAN-93607
|
||||||
|
|
||||||
|
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||||
|
|
||||||
|
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||||
|
|
||||||
|
## PAN-93532
|
||||||
|
|
||||||
|
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||||
|
|
||||||
|
## PAN-93193
|
||||||
|
|
||||||
|
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||||
|
|
||||||
|
- Switch to the firewall **Context** on the Panorama management server.
|
||||||
|
- Commit changes when a dynamic update is being installed.
|
||||||
|
- Generate a custom report when a dynamic update is being installed.
|
||||||
|
- Generate custom reports during a commit.
|
||||||
|
|
||||||
|
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||||
|
|
||||||
|
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||||
|
|
||||||
|
## PAN-91802
|
||||||
|
|
||||||
|
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||||
|
|
||||||
|
## PAN-83610
|
||||||
|
|
||||||
|
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||||
|
|
||||||
|
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-83236
|
||||||
|
|
||||||
|
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||||
|
|
||||||
|
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||||
|
|
||||||
|
## PAN-83215
|
||||||
|
|
||||||
|
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||||
|
|
||||||
|
## PAN-81521
|
||||||
|
|
||||||
|
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||||
|
|
||||||
|
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||||
|
|
||||||
|
## PAN-77125
|
||||||
|
|
||||||
|
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||||
|
|
||||||
|
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-75457
|
||||||
|
|
||||||
|
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||||
|
|
||||||
|
## PAN-73530
|
||||||
|
|
||||||
|
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||||
|
|
||||||
|
## PAN-73401
|
||||||
|
|
||||||
|
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||||
|
|
||||||
|
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||||
|
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||||
|
|
||||||
|
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||||
|
|
||||||
|
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||||
|
- Configure a worker list on the cluster controller:
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||||
|
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||||
|
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||||
|
or
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||||
|
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||||
|
|
||||||
|
## PAN-70906
|
||||||
|
|
||||||
|
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||||
|
|
||||||
|
## PAN-69505
|
||||||
|
|
||||||
|
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||||
|
|
||||||
|
## PAN-41558
|
||||||
|
|
||||||
|
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||||
|
|
||||||
|
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||||
|
|
||||||
|
## PAN-40079
|
||||||
|
|
||||||
|
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||||
|
|
||||||
|
## PAN-39636
|
||||||
|
|
||||||
|
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||||
|
|
||||||
|
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||||
|
|
||||||
|
## PAN-38255
|
||||||
|
|
||||||
|
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||||
|
|
||||||
|
## PAN-31832
|
||||||
|
|
||||||
|
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||||
|
|
||||||
|
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||||
|
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||||
@@ -0,0 +1,603 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 10.0.6
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## APL-8269
|
||||||
|
|
||||||
|
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
|
||||||
|
|
||||||
|
## PLUG-380
|
||||||
|
|
||||||
|
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||||
|
|
||||||
|
## WF500-5471
|
||||||
|
|
||||||
|
After using the firewall CLI to add a WildFire appliance with an IPv6 address, the initial connection may fail.
|
||||||
|
|
||||||
|
**Workaround:** Retry connecting after you restart the web server with the following command: `debug software restart process web-server`.
|
||||||
|
|
||||||
|
## PAN-178194
|
||||||
|
|
||||||
|
A UI issue in PAN-OS renders the contents of the **Inline ML** tab in the **URL Filtering Profile** inaccessible on firewalls licensed for Advanced URL Filtering. Additionally, a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI. These errors do not affect the operation of Advanced URL Filtering or URL Filtering Inline ML.
|
||||||
|
|
||||||
|
**Workaround:** Configuration settings for URL Filtering Inline ML must be applied through the CLI. The following configuration commands are available:
|
||||||
|
|
||||||
|
- Define URL exceptions for specific web sites—
|
||||||
|
`admin#``set profiles url-filtering <url_filtering_profile_name> mlav-category-exception`
|
||||||
|
|
||||||
|
- Configuration settings for each inline ML model—
|
||||||
|
`admin#``set profiles url-filtering <url_filtering_profile_name> mlav-engine-urlbased-enabled`
|
||||||
|
|
||||||
|
## PAN-157444
|
||||||
|
|
||||||
|
As a result of a telemetry handling update, the Source Zone field in the DNS analytics logs (viewable in the DNS Analytics tab within AutoFocus) might not display correct results.
|
||||||
|
|
||||||
|
## PAN-157327
|
||||||
|
|
||||||
|
On downgrade to PAN-OS 9.1, Enterprise Data Loss Prevention (DLP) filtering settings (**Device** > **Setup** > **DLP**) are not removed and cause commit errors for the downgraded firewall if you do not uninstall the Enterprise DLP plugin before downgrade.
|
||||||
|
|
||||||
|
**Workaround:** After you successfully downgrade a managed firewall to PAN-OS 9.1, commit and push from Panorama to remove the Enterprise DLP filtering settings and complete the downgrade.
|
||||||
|
|
||||||
|
1. Downgrade your managed firewall to PAN-OS 9.1
|
||||||
|
2. Log in to the firewall web interface and view the **Tasks** to verify all auto commits related to the downgrade have completed successfully.
|
||||||
|
3. Log in to the Panorama web interface and **Commit** > **Commit and Push** to your managed firewall downgraded to PAN-OS 9.1.
|
||||||
|
|
||||||
|
## PAN-157103
|
||||||
|
|
||||||
|
Multi-channel functionality may not be properly utilized on an VM-Series firewall deployed in VMware NSX-V after the service is first deployed.
|
||||||
|
|
||||||
|
**Workaround**: Execute the command `debug dataplane pow status` to view the number of channels being utilized by the dataplane.
|
||||||
|
|
||||||
|
Per pan-task Netx statisticsCounter Name 1 2 3 4 5 6 Total---------------------------------------------ready_dvf 2 0 0 0 0 0 2
|
||||||
|
|
||||||
|
If multi-channel functionality is not working, disable your NSX-V security policy and reapply it. Then reboot the VM-Series firewall. When the firewall is back up, verify that multi-channel functionality is working by executing the command `debug dataplane pow status`. It should now show multiple channels being utilized.
|
||||||
|
|
||||||
|
Per pan-task Netx statisticsCounter Name 1 2 3 4 5 6 Total---------------------------------------------ready_dvf 1 1 0 0 0 0 2
|
||||||
|
|
||||||
|
## PAN-156645
|
||||||
|
|
||||||
|
If the SD-WAN interface was Down and it comes Up during a commit (for example, if you configure it from Down to Auto), SD-WAN ignores the change and keeps the link Down in the SD-WAN connection. In this case, SD-WAN won't choose to send traffic to this link. If this is the only link to the internet, this behavior may cause an outage, including failure of the IKE negotiation between the Branch and Hub, and such Tunnel will be down.
|
||||||
|
|
||||||
|
**Workaround**: Commit again or toggle the interface link Down and Up; the SD-WAN statistics will be correct and the problem will resolve.
|
||||||
|
|
||||||
|
## PAN-156598
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure a standard custom vulnerability signature in a custom Vulnerability Protection profile in a shared device group, the shared profile custom signatures do not populate in the other device groups when you configure a combination custom vulnerability signature.
|
||||||
|
|
||||||
|
**Workaround:** Use the CLI to update the combination signature.
|
||||||
|
|
||||||
|
## PAN-154292
|
||||||
|
|
||||||
|
On the Panorama management server, downgrading from a PAN-OS 10.0 release to a PAN-OS 9.1 release causes Panorama commit (**Commit** > **Commit to Panorama**) failures if a custom report (**Monitor** > **Manage Custom Reports**) is configured to Group By **Session ID**.
|
||||||
|
|
||||||
|
**Workaround:** After successful downgrade, reconfigure the Group By setting in the custom report.
|
||||||
|
|
||||||
|
## PAN-154266
|
||||||
|
|
||||||
|
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
|
||||||
|
|
||||||
|
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
|
||||||
|
|
||||||
|
## PAN-154034
|
||||||
|
|
||||||
|
On the Panorama management server, the Type column in the System logs (**Monitor** > **Logs** > **System**) for managed firewalls running a PAN-OS 9.1 release erroneously display `iot` as the type.
|
||||||
|
|
||||||
|
## PAN-154032
|
||||||
|
|
||||||
|
On the Panorama management server, downgrading to PAN-OS 9.1 with the Panorama plugin for Cisco TrustSec version 1.0.2 installed does not automatically transform the plugin to be compatible with PAN-OS 9.1
|
||||||
|
|
||||||
|
**Workaround:** After successful downgrade to PAN-OS 9.1, **Remove Config** (**Panorama** > **Plugins**) of the Panorama plugin for Cisco TrustSec and then reconfigure the plugin.
|
||||||
|
|
||||||
|
## PAN-153803
|
||||||
|
|
||||||
|
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
|
||||||
|
|
||||||
|
## PAN-153557
|
||||||
|
|
||||||
|
On the Panorama management server CLI, the overall report status for a report query is marked as `Done` despite reports generated from logs in the Cortex Data Lake (CDL) from the PODamericas Collector Group jobs are still in a `Running` state.
|
||||||
|
|
||||||
|
## PAN-153068
|
||||||
|
|
||||||
|
The Bonjour Reflector option is supported on up to 16 interfaces. If you enable it on more than 16 interfaces, the commit succeeds and the Bonjour Reflector option is enabled only for the first 16 interfaces and ignored for any additional interfaces.
|
||||||
|
|
||||||
|
## PAN-152825
|
||||||
|
|
||||||
|
On the Panorama management server, you cannot view the SD-WAN license installed on an SD-WAN firewall (**Panorama** > **Device Deployment** > **Licenses**).
|
||||||
|
|
||||||
|
**Workaround:** [Log in to the Panorama CLI](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli.html) and enter the following command to view the SDWAN license information for your managed firewalls.
|
||||||
|
|
||||||
|
`admin>``request batch license info`
|
||||||
|
|
||||||
|
## PAN-152433
|
||||||
|
|
||||||
|
When you have an active/passive HA pair of PA-3200 Series firewalls running PAN-OS 10.0.0 with NAT configured, if you upgrade one firewall to PAN-OS 10.0.1, the firewall goes to non-functional state due to a NAT oversubscription mismatch between the HA peers. The same non-functional state results if both HA peers are running PAN-OS 10.0.1 and you downgrade one to PAN-OS 10.00. The upgraded or downgraded firewall goes to non-functional state because PAN-OS 10.0.0 and 10.0.1 have different default NAT oversubscription rates.
|
||||||
|
|
||||||
|
**Workaround**: After an upgrade or downgrade, modify the NAT oversubscription rate on one firewall so that the rates on the HA pair match.
|
||||||
|
|
||||||
|
## PAN-151238
|
||||||
|
|
||||||
|
There is a known issue where M-100 appliances are able to download and install a PAN-OS 10.0 release image even though the M-100 appliance is no longer supported after PAN-OS 9.1. (Refer to the [hardware end-of-life dates](https://www.paloaltonetworks.com/services/support/end-of-life-announcements/hardware-end-of-life-dates.html).)
|
||||||
|
|
||||||
|
## PAN-151198
|
||||||
|
|
||||||
|
On the Panorama management server, read-only Panorama administrators (**Panorama** > **Administrators**) can load managed firewall configuration Backups (**Panorama** > **Managed Devices** > **Summary**).
|
||||||
|
|
||||||
|
## PAN-151115
|
||||||
|
|
||||||
|
If a Security rule uses a IP Address External Dynamic List (EDL) for IPv6 traffic, the information for the EDL does not display in the Source EDL or Destination EDL columns in the logs.
|
||||||
|
|
||||||
|
## PAN-151085
|
||||||
|
|
||||||
|
On a PA-7000 Series firewall chassis having multiple slots, when HA clustering is enabled on an active/active HA pair, the session table count for one of the peers can show a higher count than the actual number of active sessions on that peer. This behavior can be seen when the session is being set up on a non-cache slot (for example, when a session distribution policy is set to round-robin or session-load); it is caused by the additional cache lookup that happens when HA cluster participation is enabled.
|
||||||
|
|
||||||
|
## PAN-150801
|
||||||
|
|
||||||
|
Automatic quarantine of a device based on forwarding profile or log setting does not work on the PA-7000 Series firewalls.
|
||||||
|
|
||||||
|
## PAN-150515
|
||||||
|
|
||||||
|
After you install the device certificate on a new Panorama management server, Panorama is not able to connect to the IoT Security edge service.
|
||||||
|
|
||||||
|
**Workaround:** Restart Panorama to connect to the IoT Security edge service.
|
||||||
|
|
||||||
|
## PAN-150345
|
||||||
|
|
||||||
|
During updates to the Device Dictionary, the IoT Security service does not push new Device-ID attributes (such as new device profiles) to the firewall until a manual commit occurs.
|
||||||
|
|
||||||
|
**Workaround:** Perform a force commit to push the attributes in the content update to the firewall.
|
||||||
|
|
||||||
|
## PAN-150361
|
||||||
|
|
||||||
|
In an Active-Passive high availability (HA) configuration, an error displays if you create a device object on the passive device.
|
||||||
|
|
||||||
|
**Workaround:** Load the running configuration and perform a force commit to sync the devices.
|
||||||
|
|
||||||
|
## PAN-148971
|
||||||
|
|
||||||
|
If you enter a search term for Events that are related to IoT in the System logs and apply the filter, the page displays an `Invalid term` error.
|
||||||
|
|
||||||
|
**Workaround:** Specify `iot` as the **Type Attribute** to filter the logs and use the search term as the **Description Attribute**. For example: `( subtype eq iot ) and ( description contains 'gRPC connection' )`.
|
||||||
|
|
||||||
|
## PAN-148924
|
||||||
|
|
||||||
|
In an active-passive HA configuration, tags for dynamic user groups are not persistent after rebooting the firewall because the active firewall does not sync the tags to the passive firewall during failover.
|
||||||
|
|
||||||
|
## PAN-146995
|
||||||
|
|
||||||
|
After downgrading a Panorama management server from PAN-OS 10.0 to PAN-OS 9.1, the `VLD` and `logd` processes may crash when Panorama reboots.
|
||||||
|
|
||||||
|
**Workaround:** Panorama automatically restarts the `VLD` and `logd` processes.
|
||||||
|
|
||||||
|
## PAN-146807
|
||||||
|
|
||||||
|
Changing the device group configured in a monitoring definition from a child DG to a parent DG, or vice versa, might cause firewalls configured in the child DG to lose IP tag mapping information received from the monitoring definition. Only firewalls assigned to the parent DG receive IP tag mapping updates.
|
||||||
|
|
||||||
|
**Workaround**: Perform a manual config sync on the device group that lost the IP tag mapping information.
|
||||||
|
|
||||||
|
## PAN-146573
|
||||||
|
|
||||||
|
PA-7000 Series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||||
|
|
||||||
|
## PAN-146485
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
|
||||||
|
|
||||||
|
## PAN-145460
|
||||||
|
|
||||||
|
CN-MGMT pods fail to connect to the Panorama management server when using the Kubernetes plugin.
|
||||||
|
|
||||||
|
**Workaround:** **Commit** the Panorama configuration after the CN-MGMT pod successfully registers with Panorama.
|
||||||
|
|
||||||
|
## PAN-144889
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
|
||||||
|
|
||||||
|
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
|
||||||
|
|
||||||
|
## PAN-143132
|
||||||
|
|
||||||
|
Fetching the device certificate from the Palo Alto Networks Customer Support Portal (CSP) may fail and displays the following error in the CLI:
|
||||||
|
|
||||||
|
`ERROR Failed to process S1C msg: Error`
|
||||||
|
|
||||||
|
**Workaround:** Retrying fetching the device certificate from the Palo Alto Networks CSP.
|
||||||
|
|
||||||
|
## PAN-141630
|
||||||
|
|
||||||
|
Current performance limitation: single data plane use only. The PA-5200 Series and PA-7000 Series firewalls that support 5G network slice security, 5G equipment ID security, and 5G subscriber ID security use a single data plane only, which currently limits the firewall performance.
|
||||||
|
|
||||||
|
## PAN-140959
|
||||||
|
|
||||||
|
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
|
||||||
|
|
||||||
|
## PAN-140008
|
||||||
|
|
||||||
|
ElasticSearch is forced to restart when the `masterd` process misses too many heartbeat messages on the Panorama management server resulting in a delay in a log query and ingestion.
|
||||||
|
|
||||||
|
## PAN-136763
|
||||||
|
|
||||||
|
On the Panorama management server, managed firewalls display as `disconnected` when installing a PAN-OS software update (**Panorama** > **Device Deployment** > **Software**) but display as `connected` when you view your managed firewalls Summary (**Panorama** > **Managed Devices** > **Summary**) and from the CLI.
|
||||||
|
|
||||||
|
**Workaround:** Log out and log back in to the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-136701
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000b Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Packets for new sessions drop when handling predict sessions.
|
||||||
|
|
||||||
|
**Workaround:** Use the following CLi commands to bypass this issue:
|
||||||
|
|
||||||
|
- `set session hwpredict disable yes`
|
||||||
|
- `show session hwpredict status`
|
||||||
|
|
||||||
|
## PAN-135742
|
||||||
|
|
||||||
|
There is an issue in HTTP2 session decryption where the App-ID in the decryption log is the App-ID of the parent session (which is web-browsing).
|
||||||
|
|
||||||
|
## PAN-134053
|
||||||
|
|
||||||
|
ACC does not filter WildFire logs from Dynamic User Groups.
|
||||||
|
|
||||||
|
## PAN-132598
|
||||||
|
|
||||||
|
The Panorama management server does not check for duplicate addresses in address groups (**Objects** > **Address Groups**) and duplicate services in service groups (**Objects** > **Service Groups**) when created from the CLI.
|
||||||
|
|
||||||
|
## PAN-130550
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
|
||||||
|
|
||||||
|
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
|
||||||
|
|
||||||
|
## PAN-127813
|
||||||
|
|
||||||
|
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches don’t communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
|
||||||
|
|
||||||
|
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
|
||||||
|
|
||||||
|
## PAN-127206
|
||||||
|
|
||||||
|
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
|
||||||
|
|
||||||
|
## PAN-123277
|
||||||
|
|
||||||
|
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-123040
|
||||||
|
|
||||||
|
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules don’t display. A workaround exists for this issue. Please contact Support for information about the workaround.
|
||||||
|
|
||||||
|
## PAN-121678
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000b Series only
|
||||||
|
```
|
||||||
|
|
||||||
|
The following error during secure boot has no impact and can be ignored:
|
||||||
|
|
||||||
|
`[ 0.672461] Device 'efifb.0' does not have a release() function, it is broken and must be fixed.[ 2.026107] EFI: Problem loading in-kernel X.509 certificate (-65)Maintenance Mode filesystem size: 2.0G`
|
||||||
|
|
||||||
|
## PAN-120440
|
||||||
|
|
||||||
|
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||||
|
|
||||||
|
## PAN-120423
|
||||||
|
|
||||||
|
PAN-OS 10.0.0 does not support the XML API for GlobalProtect logs.
|
||||||
|
|
||||||
|
## PAN-120303
|
||||||
|
|
||||||
|
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||||
|
|
||||||
|
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||||
|
|
||||||
|
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||||
|
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||||
|
2. **Commit** your changes.
|
||||||
|
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||||
|
4. **Commit** your changes.
|
||||||
|
- Restart the firewall (devsrvr) process.
|
||||||
|
1. Log in to the firewall CLI.
|
||||||
|
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||||
|
|
||||||
|
## PAN-116017
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Google Cloud Platform (GCP) only
|
||||||
|
```
|
||||||
|
|
||||||
|
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||||
|
|
||||||
|
## PAN-115816
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Microsoft Azure only
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-114495
|
||||||
|
|
||||||
|
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||||
|
|
||||||
|
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||||
|
|
||||||
|
## PAN-112694
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls with multiple virtual systems only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||||
|
|
||||||
|
## PAN-112456
|
||||||
|
|
||||||
|
You can temporarily submit a change request for a URL Category with three suggested categories; however, only two categories are supported. Do not add more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, only the first two categories in the change request are evaluated.
|
||||||
|
|
||||||
|
## PAN-112135
|
||||||
|
|
||||||
|
You cannot unregister tags for a subnet or range in a dynamic address group from the web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use an XML API request to unregister the tags for the subnet or range.
|
||||||
|
|
||||||
|
## PAN-111928
|
||||||
|
|
||||||
|
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||||
|
|
||||||
|
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||||
|
|
||||||
|
## PAN-111866
|
||||||
|
|
||||||
|
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||||
|
|
||||||
|
**Workaround:** Perform one of the following tasks.
|
||||||
|
|
||||||
|
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||||
|
- Manually select the devices that belong to the modified device group and template configurations.
|
||||||
|
|
||||||
|
## PAN-111729
|
||||||
|
|
||||||
|
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-111670
|
||||||
|
|
||||||
|
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||||
|
|
||||||
|
## PAN-110794
|
||||||
|
|
||||||
|
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||||
|
|
||||||
|
## PAN-109759
|
||||||
|
|
||||||
|
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
|
||||||
|
|
||||||
|
## PAN-109526
|
||||||
|
|
||||||
|
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||||
|
|
||||||
|
## PAN-106675
|
||||||
|
|
||||||
|
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||||
|
|
||||||
|
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||||
|
|
||||||
|
## PAN-104780
|
||||||
|
|
||||||
|
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||||
|
|
||||||
|
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||||
|
|
||||||
|
## PAN-103276
|
||||||
|
|
||||||
|
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||||
|
|
||||||
|
## PAN-101688
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama plugins
|
||||||
|
```
|
||||||
|
|
||||||
|
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||||
|
|
||||||
|
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||||
|
|
||||||
|
## PAN-101537
|
||||||
|
|
||||||
|
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||||
|
|
||||||
|
**Workaround:** Specify the vsys in the query string:
|
||||||
|
|
||||||
|
`admin>` `set system target-vsys <vsys-name>`
|
||||||
|
|
||||||
|
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||||
|
|
||||||
|
## PAN-98520
|
||||||
|
|
||||||
|
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||||
|
|
||||||
|
## PAN-97757
|
||||||
|
|
||||||
|
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||||
|
|
||||||
|
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||||
|
|
||||||
|
## PAN-97524
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama management server only
|
||||||
|
```
|
||||||
|
|
||||||
|
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||||
|
|
||||||
|
## PAN-96446
|
||||||
|
|
||||||
|
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||||
|
|
||||||
|
## PAN-95773
|
||||||
|
|
||||||
|
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||||
|
|
||||||
|
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||||
|
|
||||||
|
## PAN-95511
|
||||||
|
|
||||||
|
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||||
|
|
||||||
|
## PAN-95028
|
||||||
|
|
||||||
|
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||||
|
|
||||||
|
## PAN-94846
|
||||||
|
|
||||||
|
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||||
|
|
||||||
|
## PAN-94093
|
||||||
|
|
||||||
|
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||||
|
|
||||||
|
## PAN-93968
|
||||||
|
|
||||||
|
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||||
|
|
||||||
|
## PAN-93607
|
||||||
|
|
||||||
|
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||||
|
|
||||||
|
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||||
|
|
||||||
|
## PAN-93532
|
||||||
|
|
||||||
|
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||||
|
|
||||||
|
## PAN-93193
|
||||||
|
|
||||||
|
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||||
|
|
||||||
|
- Switch to the firewall **Context** on the Panorama management server.
|
||||||
|
- Commit changes when a dynamic update is being installed.
|
||||||
|
- Generate a custom report when a dynamic update is being installed.
|
||||||
|
- Generate custom reports during a commit.
|
||||||
|
|
||||||
|
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||||
|
|
||||||
|
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||||
|
|
||||||
|
## PAN-91802
|
||||||
|
|
||||||
|
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||||
|
|
||||||
|
## PAN-83610
|
||||||
|
|
||||||
|
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||||
|
|
||||||
|
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-83236
|
||||||
|
|
||||||
|
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||||
|
|
||||||
|
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||||
|
|
||||||
|
## PAN-83215
|
||||||
|
|
||||||
|
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||||
|
|
||||||
|
## PAN-81521
|
||||||
|
|
||||||
|
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||||
|
|
||||||
|
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||||
|
|
||||||
|
## PAN-77125
|
||||||
|
|
||||||
|
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||||
|
|
||||||
|
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-75457
|
||||||
|
|
||||||
|
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||||
|
|
||||||
|
## PAN-73530
|
||||||
|
|
||||||
|
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||||
|
|
||||||
|
## PAN-73401
|
||||||
|
|
||||||
|
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||||
|
|
||||||
|
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||||
|
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||||
|
|
||||||
|
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||||
|
|
||||||
|
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||||
|
- Configure a worker list on the cluster controller:
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||||
|
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||||
|
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||||
|
or
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||||
|
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||||
|
|
||||||
|
## PAN-70906
|
||||||
|
|
||||||
|
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||||
|
|
||||||
|
## PAN-69505
|
||||||
|
|
||||||
|
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||||
|
|
||||||
|
## PAN-41558
|
||||||
|
|
||||||
|
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||||
|
|
||||||
|
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||||
|
|
||||||
|
## PAN-40079
|
||||||
|
|
||||||
|
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||||
|
|
||||||
|
## PAN-39636
|
||||||
|
|
||||||
|
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||||
|
|
||||||
|
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||||
|
|
||||||
|
## PAN-38255
|
||||||
|
|
||||||
|
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||||
|
|
||||||
|
## PAN-31832
|
||||||
|
|
||||||
|
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||||
|
|
||||||
|
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||||
|
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||||
@@ -0,0 +1,603 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 10.0.8
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## APL-8269
|
||||||
|
|
||||||
|
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
|
||||||
|
|
||||||
|
## PLUG-380
|
||||||
|
|
||||||
|
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||||
|
|
||||||
|
## WF500-5471
|
||||||
|
|
||||||
|
After using the firewall CLI to add a WildFire appliance with an IPv6 address, the initial connection may fail.
|
||||||
|
|
||||||
|
**Workaround:** Retry connecting after you restart the web server with the following command: `debug software restart process web-server`.
|
||||||
|
|
||||||
|
## PAN-178194
|
||||||
|
|
||||||
|
A UI issue in PAN-OS renders the contents of the **Inline ML** tab in the **URL Filtering Profile** inaccessible on firewalls licensed for Advanced URL Filtering. Additionally, a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI. These errors do not affect the operation of Advanced URL Filtering or URL Filtering Inline ML.
|
||||||
|
|
||||||
|
**Workaround:** Configuration settings for URL Filtering Inline ML must be applied through the CLI. The following configuration commands are available:
|
||||||
|
|
||||||
|
- Define URL exceptions for specific web sites—
|
||||||
|
`admin#``set profiles url-filtering <url_filtering_profile_name> mlav-category-exception`
|
||||||
|
|
||||||
|
- Configuration settings for each inline ML model—
|
||||||
|
`admin#``set profiles url-filtering <url_filtering_profile_name> mlav-engine-urlbased-enabled`
|
||||||
|
|
||||||
|
## PAN-157444
|
||||||
|
|
||||||
|
As a result of a telemetry handling update, the Source Zone field in the DNS analytics logs (viewable in the DNS Analytics tab within AutoFocus) might not display correct results.
|
||||||
|
|
||||||
|
## PAN-157327
|
||||||
|
|
||||||
|
On downgrade to PAN-OS 9.1, Enterprise Data Loss Prevention (DLP) filtering settings (**Device** > **Setup** > **DLP**) are not removed and cause commit errors for the downgraded firewall if you do not uninstall the Enterprise DLP plugin before downgrade.
|
||||||
|
|
||||||
|
**Workaround:** After you successfully downgrade a managed firewall to PAN-OS 9.1, commit and push from Panorama to remove the Enterprise DLP filtering settings and complete the downgrade.
|
||||||
|
|
||||||
|
1. Downgrade your managed firewall to PAN-OS 9.1
|
||||||
|
2. Log in to the firewall web interface and view the **Tasks** to verify all auto commits related to the downgrade have completed successfully.
|
||||||
|
3. Log in to the Panorama web interface and **Commit** > **Commit and Push** to your managed firewall downgraded to PAN-OS 9.1.
|
||||||
|
|
||||||
|
## PAN-157103
|
||||||
|
|
||||||
|
Multi-channel functionality may not be properly utilized on an VM-Series firewall deployed in VMware NSX-V after the service is first deployed.
|
||||||
|
|
||||||
|
**Workaround**: Execute the command `debug dataplane pow status` to view the number of channels being utilized by the dataplane.
|
||||||
|
|
||||||
|
Per pan-task Netx statisticsCounter Name 1 2 3 4 5 6 Total---------------------------------------------ready_dvf 2 0 0 0 0 0 2
|
||||||
|
|
||||||
|
If multi-channel functionality is not working, disable your NSX-V security policy and reapply it. Then reboot the VM-Series firewall. When the firewall is back up, verify that multi-channel functionality is working by executing the command `debug dataplane pow status`. It should now show multiple channels being utilized.
|
||||||
|
|
||||||
|
Per pan-task Netx statisticsCounter Name 1 2 3 4 5 6 Total---------------------------------------------ready_dvf 1 1 0 0 0 0 2
|
||||||
|
|
||||||
|
## PAN-156645
|
||||||
|
|
||||||
|
If the SD-WAN interface was Down and it comes Up during a commit (for example, if you configure it from Down to Auto), SD-WAN ignores the change and keeps the link Down in the SD-WAN connection. In this case, SD-WAN won't choose to send traffic to this link. If this is the only link to the internet, this behavior may cause an outage, including failure of the IKE negotiation between the Branch and Hub, and such Tunnel will be down.
|
||||||
|
|
||||||
|
**Workaround**: Commit again or toggle the interface link Down and Up; the SD-WAN statistics will be correct and the problem will resolve.
|
||||||
|
|
||||||
|
## PAN-156598
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure a standard custom vulnerability signature in a custom Vulnerability Protection profile in a shared device group, the shared profile custom signatures do not populate in the other device groups when you configure a combination custom vulnerability signature.
|
||||||
|
|
||||||
|
**Workaround:** Use the CLI to update the combination signature.
|
||||||
|
|
||||||
|
## PAN-154292
|
||||||
|
|
||||||
|
On the Panorama management server, downgrading from a PAN-OS 10.0 release to a PAN-OS 9.1 release causes Panorama commit (**Commit** > **Commit to Panorama**) failures if a custom report (**Monitor** > **Manage Custom Reports**) is configured to Group By **Session ID**.
|
||||||
|
|
||||||
|
**Workaround:** After successful downgrade, reconfigure the Group By setting in the custom report.
|
||||||
|
|
||||||
|
## PAN-154266
|
||||||
|
|
||||||
|
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
|
||||||
|
|
||||||
|
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
|
||||||
|
|
||||||
|
## PAN-154034
|
||||||
|
|
||||||
|
On the Panorama management server, the Type column in the System logs (**Monitor** > **Logs** > **System**) for managed firewalls running a PAN-OS 9.1 release erroneously display `iot` as the type.
|
||||||
|
|
||||||
|
## PAN-154032
|
||||||
|
|
||||||
|
On the Panorama management server, downgrading to PAN-OS 9.1 with the Panorama plugin for Cisco TrustSec version 1.0.2 installed does not automatically transform the plugin to be compatible with PAN-OS 9.1
|
||||||
|
|
||||||
|
**Workaround:** After successful downgrade to PAN-OS 9.1, **Remove Config** (**Panorama** > **Plugins**) of the Panorama plugin for Cisco TrustSec and then reconfigure the plugin.
|
||||||
|
|
||||||
|
## PAN-153803
|
||||||
|
|
||||||
|
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
|
||||||
|
|
||||||
|
## PAN-153557
|
||||||
|
|
||||||
|
On the Panorama management server CLI, the overall report status for a report query is marked as `Done` despite reports generated from logs in the Cortex Data Lake (CDL) from the PODamericas Collector Group jobs are still in a `Running` state.
|
||||||
|
|
||||||
|
## PAN-153068
|
||||||
|
|
||||||
|
The Bonjour Reflector option is supported on up to 16 interfaces. If you enable it on more than 16 interfaces, the commit succeeds and the Bonjour Reflector option is enabled only for the first 16 interfaces and ignored for any additional interfaces.
|
||||||
|
|
||||||
|
## PAN-152825
|
||||||
|
|
||||||
|
On the Panorama management server, you cannot view the SD-WAN license installed on an SD-WAN firewall (**Panorama** > **Device Deployment** > **Licenses**).
|
||||||
|
|
||||||
|
**Workaround:** [Log in to the Panorama CLI](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli.html) and enter the following command to view the SDWAN license information for your managed firewalls.
|
||||||
|
|
||||||
|
`admin>``request batch license info`
|
||||||
|
|
||||||
|
## PAN-152433
|
||||||
|
|
||||||
|
When you have an active/passive HA pair of PA-3200 Series firewalls running PAN-OS 10.0.0 with NAT configured, if you upgrade one firewall to PAN-OS 10.0.1, the firewall goes to non-functional state due to a NAT oversubscription mismatch between the HA peers. The same non-functional state results if both HA peers are running PAN-OS 10.0.1 and you downgrade one to PAN-OS 10.00. The upgraded or downgraded firewall goes to non-functional state because PAN-OS 10.0.0 and 10.0.1 have different default NAT oversubscription rates.
|
||||||
|
|
||||||
|
**Workaround**: After an upgrade or downgrade, modify the NAT oversubscription rate on one firewall so that the rates on the HA pair match.
|
||||||
|
|
||||||
|
## PAN-151238
|
||||||
|
|
||||||
|
There is a known issue where M-100 appliances are able to download and install a PAN-OS 10.0 release image even though the M-100 appliance is no longer supported after PAN-OS 9.1. (Refer to the [hardware end-of-life dates](https://www.paloaltonetworks.com/services/support/end-of-life-announcements/hardware-end-of-life-dates.html).)
|
||||||
|
|
||||||
|
## PAN-151198
|
||||||
|
|
||||||
|
On the Panorama management server, read-only Panorama administrators (**Panorama** > **Administrators**) can load managed firewall configuration Backups (**Panorama** > **Managed Devices** > **Summary**).
|
||||||
|
|
||||||
|
## PAN-151115
|
||||||
|
|
||||||
|
If a Security rule uses a IP Address External Dynamic List (EDL) for IPv6 traffic, the information for the EDL does not display in the Source EDL or Destination EDL columns in the logs.
|
||||||
|
|
||||||
|
## PAN-151085
|
||||||
|
|
||||||
|
On a PA-7000 Series firewall chassis having multiple slots, when HA clustering is enabled on an active/active HA pair, the session table count for one of the peers can show a higher count than the actual number of active sessions on that peer. This behavior can be seen when the session is being set up on a non-cache slot (for example, when a session distribution policy is set to round-robin or session-load); it is caused by the additional cache lookup that happens when HA cluster participation is enabled.
|
||||||
|
|
||||||
|
## PAN-150801
|
||||||
|
|
||||||
|
Automatic quarantine of a device based on forwarding profile or log setting does not work on the PA-7000 Series firewalls.
|
||||||
|
|
||||||
|
## PAN-150515
|
||||||
|
|
||||||
|
After you install the device certificate on a new Panorama management server, Panorama is not able to connect to the IoT Security edge service.
|
||||||
|
|
||||||
|
**Workaround:** Restart Panorama to connect to the IoT Security edge service.
|
||||||
|
|
||||||
|
## PAN-150345
|
||||||
|
|
||||||
|
During updates to the Device Dictionary, the IoT Security service does not push new Device-ID attributes (such as new device profiles) to the firewall until a manual commit occurs.
|
||||||
|
|
||||||
|
**Workaround:** Perform a force commit to push the attributes in the content update to the firewall.
|
||||||
|
|
||||||
|
## PAN-150361
|
||||||
|
|
||||||
|
In an Active-Passive high availability (HA) configuration, an error displays if you create a device object on the passive device.
|
||||||
|
|
||||||
|
**Workaround:** Load the running configuration and perform a force commit to sync the devices.
|
||||||
|
|
||||||
|
## PAN-148971
|
||||||
|
|
||||||
|
If you enter a search term for Events that are related to IoT in the System logs and apply the filter, the page displays an `Invalid term` error.
|
||||||
|
|
||||||
|
**Workaround:** Specify `iot` as the **Type Attribute** to filter the logs and use the search term as the **Description Attribute**. For example: `( subtype eq iot ) and ( description contains 'gRPC connection' )`.
|
||||||
|
|
||||||
|
## PAN-148924
|
||||||
|
|
||||||
|
In an active-passive HA configuration, tags for dynamic user groups are not persistent after rebooting the firewall because the active firewall does not sync the tags to the passive firewall during failover.
|
||||||
|
|
||||||
|
## PAN-146995
|
||||||
|
|
||||||
|
After downgrading a Panorama management server from PAN-OS 10.0 to PAN-OS 9.1, the `VLD` and `logd` processes may crash when Panorama reboots.
|
||||||
|
|
||||||
|
**Workaround:** Panorama automatically restarts the `VLD` and `logd` processes.
|
||||||
|
|
||||||
|
## PAN-146807
|
||||||
|
|
||||||
|
Changing the device group configured in a monitoring definition from a child DG to a parent DG, or vice versa, might cause firewalls configured in the child DG to lose IP tag mapping information received from the monitoring definition. Only firewalls assigned to the parent DG receive IP tag mapping updates.
|
||||||
|
|
||||||
|
**Workaround**: Perform a manual config sync on the device group that lost the IP tag mapping information.
|
||||||
|
|
||||||
|
## PAN-146573
|
||||||
|
|
||||||
|
PA-7000 Series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||||
|
|
||||||
|
## PAN-146485
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
|
||||||
|
|
||||||
|
## PAN-145460
|
||||||
|
|
||||||
|
CN-MGMT pods fail to connect to the Panorama management server when using the Kubernetes plugin.
|
||||||
|
|
||||||
|
**Workaround:** **Commit** the Panorama configuration after the CN-MGMT pod successfully registers with Panorama.
|
||||||
|
|
||||||
|
## PAN-144889
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
|
||||||
|
|
||||||
|
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
|
||||||
|
|
||||||
|
## PAN-143132
|
||||||
|
|
||||||
|
Fetching the device certificate from the Palo Alto Networks Customer Support Portal (CSP) may fail and displays the following error in the CLI:
|
||||||
|
|
||||||
|
`ERROR Failed to process S1C msg: Error`
|
||||||
|
|
||||||
|
**Workaround:** Retrying fetching the device certificate from the Palo Alto Networks CSP.
|
||||||
|
|
||||||
|
## PAN-141630
|
||||||
|
|
||||||
|
Current performance limitation: single data plane use only. The PA-5200 Series and PA-7000 Series firewalls that support 5G network slice security, 5G equipment ID security, and 5G subscriber ID security use a single data plane only, which currently limits the firewall performance.
|
||||||
|
|
||||||
|
## PAN-140959
|
||||||
|
|
||||||
|
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
|
||||||
|
|
||||||
|
## PAN-140008
|
||||||
|
|
||||||
|
ElasticSearch is forced to restart when the `masterd` process misses too many heartbeat messages on the Panorama management server resulting in a delay in a log query and ingestion.
|
||||||
|
|
||||||
|
## PAN-136763
|
||||||
|
|
||||||
|
On the Panorama management server, managed firewalls display as `disconnected` when installing a PAN-OS software update (**Panorama** > **Device Deployment** > **Software**) but display as `connected` when you view your managed firewalls Summary (**Panorama** > **Managed Devices** > **Summary**) and from the CLI.
|
||||||
|
|
||||||
|
**Workaround:** Log out and log back in to the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-136701
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000b Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Packets for new sessions drop when handling predict sessions.
|
||||||
|
|
||||||
|
**Workaround:** Use the following CLi commands to bypass this issue:
|
||||||
|
|
||||||
|
- `set session hwpredict disable yes`
|
||||||
|
- `show session hwpredict status`
|
||||||
|
|
||||||
|
## PAN-135742
|
||||||
|
|
||||||
|
There is an issue in HTTP2 session decryption where the App-ID in the decryption log is the App-ID of the parent session (which is web-browsing).
|
||||||
|
|
||||||
|
## PAN-134053
|
||||||
|
|
||||||
|
ACC does not filter WildFire logs from Dynamic User Groups.
|
||||||
|
|
||||||
|
## PAN-132598
|
||||||
|
|
||||||
|
The Panorama management server does not check for duplicate addresses in address groups (**Objects** > **Address Groups**) and duplicate services in service groups (**Objects** > **Service Groups**) when created from the CLI.
|
||||||
|
|
||||||
|
## PAN-130550
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
|
||||||
|
|
||||||
|
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
|
||||||
|
|
||||||
|
## PAN-127813
|
||||||
|
|
||||||
|
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches don’t communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
|
||||||
|
|
||||||
|
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
|
||||||
|
|
||||||
|
## PAN-127206
|
||||||
|
|
||||||
|
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
|
||||||
|
|
||||||
|
## PAN-123277
|
||||||
|
|
||||||
|
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-123040
|
||||||
|
|
||||||
|
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules don’t display. A workaround exists for this issue. Please contact Support for information about the workaround.
|
||||||
|
|
||||||
|
## PAN-121678
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000b Series only
|
||||||
|
```
|
||||||
|
|
||||||
|
The following error during secure boot has no impact and can be ignored:
|
||||||
|
|
||||||
|
`[ 0.672461] Device 'efifb.0' does not have a release() function, it is broken and must be fixed.[ 2.026107] EFI: Problem loading in-kernel X.509 certificate (-65)Maintenance Mode filesystem size: 2.0G`
|
||||||
|
|
||||||
|
## PAN-120440
|
||||||
|
|
||||||
|
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||||
|
|
||||||
|
## PAN-120423
|
||||||
|
|
||||||
|
PAN-OS 10.0.0 does not support the XML API for GlobalProtect logs.
|
||||||
|
|
||||||
|
## PAN-120303
|
||||||
|
|
||||||
|
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||||
|
|
||||||
|
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||||
|
|
||||||
|
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||||
|
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||||
|
2. **Commit** your changes.
|
||||||
|
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||||
|
4. **Commit** your changes.
|
||||||
|
- Restart the firewall (devsrvr) process.
|
||||||
|
1. Log in to the firewall CLI.
|
||||||
|
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||||
|
|
||||||
|
## PAN-116017
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Google Cloud Platform (GCP) only
|
||||||
|
```
|
||||||
|
|
||||||
|
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||||
|
|
||||||
|
## PAN-115816
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Microsoft Azure only
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-114495
|
||||||
|
|
||||||
|
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||||
|
|
||||||
|
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||||
|
|
||||||
|
## PAN-112694
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls with multiple virtual systems only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||||
|
|
||||||
|
## PAN-112456
|
||||||
|
|
||||||
|
You can temporarily submit a change request for a URL Category with three suggested categories; however, only two categories are supported. Do not add more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, only the first two categories in the change request are evaluated.
|
||||||
|
|
||||||
|
## PAN-112135
|
||||||
|
|
||||||
|
You cannot unregister tags for a subnet or range in a dynamic address group from the web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use an XML API request to unregister the tags for the subnet or range.
|
||||||
|
|
||||||
|
## PAN-111928
|
||||||
|
|
||||||
|
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||||
|
|
||||||
|
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||||
|
|
||||||
|
## PAN-111866
|
||||||
|
|
||||||
|
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||||
|
|
||||||
|
**Workaround:** Perform one of the following tasks.
|
||||||
|
|
||||||
|
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||||
|
- Manually select the devices that belong to the modified device group and template configurations.
|
||||||
|
|
||||||
|
## PAN-111729
|
||||||
|
|
||||||
|
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-111670
|
||||||
|
|
||||||
|
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||||
|
|
||||||
|
## PAN-110794
|
||||||
|
|
||||||
|
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||||
|
|
||||||
|
## PAN-109759
|
||||||
|
|
||||||
|
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
|
||||||
|
|
||||||
|
## PAN-109526
|
||||||
|
|
||||||
|
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||||
|
|
||||||
|
## PAN-106675
|
||||||
|
|
||||||
|
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||||
|
|
||||||
|
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||||
|
|
||||||
|
## PAN-104780
|
||||||
|
|
||||||
|
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||||
|
|
||||||
|
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||||
|
|
||||||
|
## PAN-103276
|
||||||
|
|
||||||
|
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||||
|
|
||||||
|
## PAN-101688
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama plugins
|
||||||
|
```
|
||||||
|
|
||||||
|
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||||
|
|
||||||
|
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||||
|
|
||||||
|
## PAN-101537
|
||||||
|
|
||||||
|
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||||
|
|
||||||
|
**Workaround:** Specify the vsys in the query string:
|
||||||
|
|
||||||
|
`admin>` `set system target-vsys <vsys-name>`
|
||||||
|
|
||||||
|
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||||
|
|
||||||
|
## PAN-98520
|
||||||
|
|
||||||
|
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||||
|
|
||||||
|
## PAN-97757
|
||||||
|
|
||||||
|
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||||
|
|
||||||
|
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||||
|
|
||||||
|
## PAN-97524
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama management server only
|
||||||
|
```
|
||||||
|
|
||||||
|
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||||
|
|
||||||
|
## PAN-96446
|
||||||
|
|
||||||
|
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||||
|
|
||||||
|
## PAN-95773
|
||||||
|
|
||||||
|
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||||
|
|
||||||
|
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||||
|
|
||||||
|
## PAN-95511
|
||||||
|
|
||||||
|
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||||
|
|
||||||
|
## PAN-95028
|
||||||
|
|
||||||
|
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||||
|
|
||||||
|
## PAN-94846
|
||||||
|
|
||||||
|
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||||
|
|
||||||
|
## PAN-94093
|
||||||
|
|
||||||
|
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||||
|
|
||||||
|
## PAN-93968
|
||||||
|
|
||||||
|
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||||
|
|
||||||
|
## PAN-93607
|
||||||
|
|
||||||
|
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||||
|
|
||||||
|
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||||
|
|
||||||
|
## PAN-93532
|
||||||
|
|
||||||
|
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||||
|
|
||||||
|
## PAN-93193
|
||||||
|
|
||||||
|
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||||
|
|
||||||
|
- Switch to the firewall **Context** on the Panorama management server.
|
||||||
|
- Commit changes when a dynamic update is being installed.
|
||||||
|
- Generate a custom report when a dynamic update is being installed.
|
||||||
|
- Generate custom reports during a commit.
|
||||||
|
|
||||||
|
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||||
|
|
||||||
|
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||||
|
|
||||||
|
## PAN-91802
|
||||||
|
|
||||||
|
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||||
|
|
||||||
|
## PAN-83610
|
||||||
|
|
||||||
|
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||||
|
|
||||||
|
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-83236
|
||||||
|
|
||||||
|
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||||
|
|
||||||
|
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||||
|
|
||||||
|
## PAN-83215
|
||||||
|
|
||||||
|
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||||
|
|
||||||
|
## PAN-81521
|
||||||
|
|
||||||
|
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||||
|
|
||||||
|
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||||
|
|
||||||
|
## PAN-77125
|
||||||
|
|
||||||
|
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||||
|
|
||||||
|
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-75457
|
||||||
|
|
||||||
|
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||||
|
|
||||||
|
## PAN-73530
|
||||||
|
|
||||||
|
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||||
|
|
||||||
|
## PAN-73401
|
||||||
|
|
||||||
|
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||||
|
|
||||||
|
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||||
|
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||||
|
|
||||||
|
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||||
|
|
||||||
|
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||||
|
- Configure a worker list on the cluster controller:
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||||
|
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||||
|
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||||
|
or
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||||
|
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||||
|
|
||||||
|
## PAN-70906
|
||||||
|
|
||||||
|
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||||
|
|
||||||
|
## PAN-69505
|
||||||
|
|
||||||
|
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||||
|
|
||||||
|
## PAN-41558
|
||||||
|
|
||||||
|
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||||
|
|
||||||
|
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||||
|
|
||||||
|
## PAN-40079
|
||||||
|
|
||||||
|
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||||
|
|
||||||
|
## PAN-39636
|
||||||
|
|
||||||
|
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||||
|
|
||||||
|
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||||
|
|
||||||
|
## PAN-38255
|
||||||
|
|
||||||
|
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||||
|
|
||||||
|
## PAN-31832
|
||||||
|
|
||||||
|
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||||
|
|
||||||
|
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||||
|
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||||
@@ -0,0 +1,603 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 10.0.9
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## APL-8269
|
||||||
|
|
||||||
|
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
|
||||||
|
|
||||||
|
## PLUG-380
|
||||||
|
|
||||||
|
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||||
|
|
||||||
|
## WF500-5471
|
||||||
|
|
||||||
|
After using the firewall CLI to add a WildFire appliance with an IPv6 address, the initial connection may fail.
|
||||||
|
|
||||||
|
**Workaround:** Retry connecting after you restart the web server with the following command: `debug software restart process web-server`.
|
||||||
|
|
||||||
|
## PAN-178194
|
||||||
|
|
||||||
|
A UI issue in PAN-OS renders the contents of the **Inline ML** tab in the **URL Filtering Profile** inaccessible on firewalls licensed for Advanced URL Filtering. Additionally, a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI. These errors do not affect the operation of Advanced URL Filtering or URL Filtering Inline ML.
|
||||||
|
|
||||||
|
**Workaround:** Configuration settings for URL Filtering Inline ML must be applied through the CLI. The following configuration commands are available:
|
||||||
|
|
||||||
|
- Define URL exceptions for specific web sites—
|
||||||
|
`admin#``set profiles url-filtering <url_filtering_profile_name> mlav-category-exception`
|
||||||
|
|
||||||
|
- Configuration settings for each inline ML model—
|
||||||
|
`admin#``set profiles url-filtering <url_filtering_profile_name> mlav-engine-urlbased-enabled`
|
||||||
|
|
||||||
|
## PAN-157444
|
||||||
|
|
||||||
|
As a result of a telemetry handling update, the Source Zone field in the DNS analytics logs (viewable in the DNS Analytics tab within AutoFocus) might not display correct results.
|
||||||
|
|
||||||
|
## PAN-157327
|
||||||
|
|
||||||
|
On downgrade to PAN-OS 9.1, Enterprise Data Loss Prevention (DLP) filtering settings (**Device** > **Setup** > **DLP**) are not removed and cause commit errors for the downgraded firewall if you do not uninstall the Enterprise DLP plugin before downgrade.
|
||||||
|
|
||||||
|
**Workaround:** After you successfully downgrade a managed firewall to PAN-OS 9.1, commit and push from Panorama to remove the Enterprise DLP filtering settings and complete the downgrade.
|
||||||
|
|
||||||
|
1. Downgrade your managed firewall to PAN-OS 9.1
|
||||||
|
2. Log in to the firewall web interface and view the **Tasks** to verify all auto commits related to the downgrade have completed successfully.
|
||||||
|
3. Log in to the Panorama web interface and **Commit** > **Commit and Push** to your managed firewall downgraded to PAN-OS 9.1.
|
||||||
|
|
||||||
|
## PAN-157103
|
||||||
|
|
||||||
|
Multi-channel functionality may not be properly utilized on an VM-Series firewall deployed in VMware NSX-V after the service is first deployed.
|
||||||
|
|
||||||
|
**Workaround**: Execute the command `debug dataplane pow status` to view the number of channels being utilized by the dataplane.
|
||||||
|
|
||||||
|
Per pan-task Netx statisticsCounter Name 1 2 3 4 5 6 Total---------------------------------------------ready_dvf 2 0 0 0 0 0 2
|
||||||
|
|
||||||
|
If multi-channel functionality is not working, disable your NSX-V security policy and reapply it. Then reboot the VM-Series firewall. When the firewall is back up, verify that multi-channel functionality is working by executing the command `debug dataplane pow status`. It should now show multiple channels being utilized.
|
||||||
|
|
||||||
|
Per pan-task Netx statisticsCounter Name 1 2 3 4 5 6 Total---------------------------------------------ready_dvf 1 1 0 0 0 0 2
|
||||||
|
|
||||||
|
## PAN-156645
|
||||||
|
|
||||||
|
If the SD-WAN interface was Down and it comes Up during a commit (for example, if you configure it from Down to Auto), SD-WAN ignores the change and keeps the link Down in the SD-WAN connection. In this case, SD-WAN won't choose to send traffic to this link. If this is the only link to the internet, this behavior may cause an outage, including failure of the IKE negotiation between the Branch and Hub, and such Tunnel will be down.
|
||||||
|
|
||||||
|
**Workaround**: Commit again or toggle the interface link Down and Up; the SD-WAN statistics will be correct and the problem will resolve.
|
||||||
|
|
||||||
|
## PAN-156598
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure a standard custom vulnerability signature in a custom Vulnerability Protection profile in a shared device group, the shared profile custom signatures do not populate in the other device groups when you configure a combination custom vulnerability signature.
|
||||||
|
|
||||||
|
**Workaround:** Use the CLI to update the combination signature.
|
||||||
|
|
||||||
|
## PAN-154292
|
||||||
|
|
||||||
|
On the Panorama management server, downgrading from a PAN-OS 10.0 release to a PAN-OS 9.1 release causes Panorama commit (**Commit** > **Commit to Panorama**) failures if a custom report (**Monitor** > **Manage Custom Reports**) is configured to Group By **Session ID**.
|
||||||
|
|
||||||
|
**Workaround:** After successful downgrade, reconfigure the Group By setting in the custom report.
|
||||||
|
|
||||||
|
## PAN-154266
|
||||||
|
|
||||||
|
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
|
||||||
|
|
||||||
|
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
|
||||||
|
|
||||||
|
## PAN-154034
|
||||||
|
|
||||||
|
On the Panorama management server, the Type column in the System logs (**Monitor** > **Logs** > **System**) for managed firewalls running a PAN-OS 9.1 release erroneously display `iot` as the type.
|
||||||
|
|
||||||
|
## PAN-154032
|
||||||
|
|
||||||
|
On the Panorama management server, downgrading to PAN-OS 9.1 with the Panorama plugin for Cisco TrustSec version 1.0.2 installed does not automatically transform the plugin to be compatible with PAN-OS 9.1
|
||||||
|
|
||||||
|
**Workaround:** After successful downgrade to PAN-OS 9.1, **Remove Config** (**Panorama** > **Plugins**) of the Panorama plugin for Cisco TrustSec and then reconfigure the plugin.
|
||||||
|
|
||||||
|
## PAN-153803
|
||||||
|
|
||||||
|
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
|
||||||
|
|
||||||
|
## PAN-153557
|
||||||
|
|
||||||
|
On the Panorama management server CLI, the overall report status for a report query is marked as `Done` despite reports generated from logs in the Cortex Data Lake (CDL) from the PODamericas Collector Group jobs are still in a `Running` state.
|
||||||
|
|
||||||
|
## PAN-153068
|
||||||
|
|
||||||
|
The Bonjour Reflector option is supported on up to 16 interfaces. If you enable it on more than 16 interfaces, the commit succeeds and the Bonjour Reflector option is enabled only for the first 16 interfaces and ignored for any additional interfaces.
|
||||||
|
|
||||||
|
## PAN-152825
|
||||||
|
|
||||||
|
On the Panorama management server, you cannot view the SD-WAN license installed on an SD-WAN firewall (**Panorama** > **Device Deployment** > **Licenses**).
|
||||||
|
|
||||||
|
**Workaround:** [Log in to the Panorama CLI](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli.html) and enter the following command to view the SDWAN license information for your managed firewalls.
|
||||||
|
|
||||||
|
`admin>``request batch license info`
|
||||||
|
|
||||||
|
## PAN-152433
|
||||||
|
|
||||||
|
When you have an active/passive HA pair of PA-3200 Series firewalls running PAN-OS 10.0.0 with NAT configured, if you upgrade one firewall to PAN-OS 10.0.1, the firewall goes to non-functional state due to a NAT oversubscription mismatch between the HA peers. The same non-functional state results if both HA peers are running PAN-OS 10.0.1 and you downgrade one to PAN-OS 10.00. The upgraded or downgraded firewall goes to non-functional state because PAN-OS 10.0.0 and 10.0.1 have different default NAT oversubscription rates.
|
||||||
|
|
||||||
|
**Workaround**: After an upgrade or downgrade, modify the NAT oversubscription rate on one firewall so that the rates on the HA pair match.
|
||||||
|
|
||||||
|
## PAN-151238
|
||||||
|
|
||||||
|
There is a known issue where M-100 appliances are able to download and install a PAN-OS 10.0 release image even though the M-100 appliance is no longer supported after PAN-OS 9.1. (Refer to the [hardware end-of-life dates](https://www.paloaltonetworks.com/services/support/end-of-life-announcements/hardware-end-of-life-dates.html).)
|
||||||
|
|
||||||
|
## PAN-151198
|
||||||
|
|
||||||
|
On the Panorama management server, read-only Panorama administrators (**Panorama** > **Administrators**) can load managed firewall configuration Backups (**Panorama** > **Managed Devices** > **Summary**).
|
||||||
|
|
||||||
|
## PAN-151115
|
||||||
|
|
||||||
|
If a Security rule uses a IP Address External Dynamic List (EDL) for IPv6 traffic, the information for the EDL does not display in the Source EDL or Destination EDL columns in the logs.
|
||||||
|
|
||||||
|
## PAN-151085
|
||||||
|
|
||||||
|
On a PA-7000 Series firewall chassis having multiple slots, when HA clustering is enabled on an active/active HA pair, the session table count for one of the peers can show a higher count than the actual number of active sessions on that peer. This behavior can be seen when the session is being set up on a non-cache slot (for example, when a session distribution policy is set to round-robin or session-load); it is caused by the additional cache lookup that happens when HA cluster participation is enabled.
|
||||||
|
|
||||||
|
## PAN-150801
|
||||||
|
|
||||||
|
Automatic quarantine of a device based on forwarding profile or log setting does not work on the PA-7000 Series firewalls.
|
||||||
|
|
||||||
|
## PAN-150515
|
||||||
|
|
||||||
|
After you install the device certificate on a new Panorama management server, Panorama is not able to connect to the IoT Security edge service.
|
||||||
|
|
||||||
|
**Workaround:** Restart Panorama to connect to the IoT Security edge service.
|
||||||
|
|
||||||
|
## PAN-150345
|
||||||
|
|
||||||
|
During updates to the Device Dictionary, the IoT Security service does not push new Device-ID attributes (such as new device profiles) to the firewall until a manual commit occurs.
|
||||||
|
|
||||||
|
**Workaround:** Perform a force commit to push the attributes in the content update to the firewall.
|
||||||
|
|
||||||
|
## PAN-150361
|
||||||
|
|
||||||
|
In an Active-Passive high availability (HA) configuration, an error displays if you create a device object on the passive device.
|
||||||
|
|
||||||
|
**Workaround:** Load the running configuration and perform a force commit to sync the devices.
|
||||||
|
|
||||||
|
## PAN-148971
|
||||||
|
|
||||||
|
If you enter a search term for Events that are related to IoT in the System logs and apply the filter, the page displays an `Invalid term` error.
|
||||||
|
|
||||||
|
**Workaround:** Specify `iot` as the **Type Attribute** to filter the logs and use the search term as the **Description Attribute**. For example: `( subtype eq iot ) and ( description contains 'gRPC connection' )`.
|
||||||
|
|
||||||
|
## PAN-148924
|
||||||
|
|
||||||
|
In an active-passive HA configuration, tags for dynamic user groups are not persistent after rebooting the firewall because the active firewall does not sync the tags to the passive firewall during failover.
|
||||||
|
|
||||||
|
## PAN-146995
|
||||||
|
|
||||||
|
After downgrading a Panorama management server from PAN-OS 10.0 to PAN-OS 9.1, the `VLD` and `logd` processes may crash when Panorama reboots.
|
||||||
|
|
||||||
|
**Workaround:** Panorama automatically restarts the `VLD` and `logd` processes.
|
||||||
|
|
||||||
|
## PAN-146807
|
||||||
|
|
||||||
|
Changing the device group configured in a monitoring definition from a child DG to a parent DG, or vice versa, might cause firewalls configured in the child DG to lose IP tag mapping information received from the monitoring definition. Only firewalls assigned to the parent DG receive IP tag mapping updates.
|
||||||
|
|
||||||
|
**Workaround**: Perform a manual config sync on the device group that lost the IP tag mapping information.
|
||||||
|
|
||||||
|
## PAN-146573
|
||||||
|
|
||||||
|
PA-7000 Series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||||
|
|
||||||
|
## PAN-146485
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
|
||||||
|
|
||||||
|
## PAN-145460
|
||||||
|
|
||||||
|
CN-MGMT pods fail to connect to the Panorama management server when using the Kubernetes plugin.
|
||||||
|
|
||||||
|
**Workaround:** **Commit** the Panorama configuration after the CN-MGMT pod successfully registers with Panorama.
|
||||||
|
|
||||||
|
## PAN-144889
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
|
||||||
|
|
||||||
|
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
|
||||||
|
|
||||||
|
## PAN-143132
|
||||||
|
|
||||||
|
Fetching the device certificate from the Palo Alto Networks Customer Support Portal (CSP) may fail and displays the following error in the CLI:
|
||||||
|
|
||||||
|
`ERROR Failed to process S1C msg: Error`
|
||||||
|
|
||||||
|
**Workaround:** Retrying fetching the device certificate from the Palo Alto Networks CSP.
|
||||||
|
|
||||||
|
## PAN-141630
|
||||||
|
|
||||||
|
Current performance limitation: single data plane use only. The PA-5200 Series and PA-7000 Series firewalls that support 5G network slice security, 5G equipment ID security, and 5G subscriber ID security use a single data plane only, which currently limits the firewall performance.
|
||||||
|
|
||||||
|
## PAN-140959
|
||||||
|
|
||||||
|
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
|
||||||
|
|
||||||
|
## PAN-140008
|
||||||
|
|
||||||
|
ElasticSearch is forced to restart when the `masterd` process misses too many heartbeat messages on the Panorama management server resulting in a delay in a log query and ingestion.
|
||||||
|
|
||||||
|
## PAN-136763
|
||||||
|
|
||||||
|
On the Panorama management server, managed firewalls display as `disconnected` when installing a PAN-OS software update (**Panorama** > **Device Deployment** > **Software**) but display as `connected` when you view your managed firewalls Summary (**Panorama** > **Managed Devices** > **Summary**) and from the CLI.
|
||||||
|
|
||||||
|
**Workaround:** Log out and log back in to the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-136701
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000b Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Packets for new sessions drop when handling predict sessions.
|
||||||
|
|
||||||
|
**Workaround:** Use the following CLi commands to bypass this issue:
|
||||||
|
|
||||||
|
- `set session hwpredict disable yes`
|
||||||
|
- `show session hwpredict status`
|
||||||
|
|
||||||
|
## PAN-135742
|
||||||
|
|
||||||
|
There is an issue in HTTP2 session decryption where the App-ID in the decryption log is the App-ID of the parent session (which is web-browsing).
|
||||||
|
|
||||||
|
## PAN-134053
|
||||||
|
|
||||||
|
ACC does not filter WildFire logs from Dynamic User Groups.
|
||||||
|
|
||||||
|
## PAN-132598
|
||||||
|
|
||||||
|
The Panorama management server does not check for duplicate addresses in address groups (**Objects** > **Address Groups**) and duplicate services in service groups (**Objects** > **Service Groups**) when created from the CLI.
|
||||||
|
|
||||||
|
## PAN-130550
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
|
||||||
|
|
||||||
|
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
|
||||||
|
|
||||||
|
## PAN-127813
|
||||||
|
|
||||||
|
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches don’t communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
|
||||||
|
|
||||||
|
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
|
||||||
|
|
||||||
|
## PAN-127206
|
||||||
|
|
||||||
|
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
|
||||||
|
|
||||||
|
## PAN-123277
|
||||||
|
|
||||||
|
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-123040
|
||||||
|
|
||||||
|
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules don’t display. A workaround exists for this issue. Please contact Support for information about the workaround.
|
||||||
|
|
||||||
|
## PAN-121678
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000b Series only
|
||||||
|
```
|
||||||
|
|
||||||
|
The following error during secure boot has no impact and can be ignored:
|
||||||
|
|
||||||
|
`[ 0.672461] Device 'efifb.0' does not have a release() function, it is broken and must be fixed.[ 2.026107] EFI: Problem loading in-kernel X.509 certificate (-65)Maintenance Mode filesystem size: 2.0G`
|
||||||
|
|
||||||
|
## PAN-120440
|
||||||
|
|
||||||
|
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||||
|
|
||||||
|
## PAN-120423
|
||||||
|
|
||||||
|
PAN-OS 10.0.0 does not support the XML API for GlobalProtect logs.
|
||||||
|
|
||||||
|
## PAN-120303
|
||||||
|
|
||||||
|
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||||
|
|
||||||
|
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||||
|
|
||||||
|
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||||
|
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||||
|
2. **Commit** your changes.
|
||||||
|
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||||
|
4. **Commit** your changes.
|
||||||
|
- Restart the firewall (devsrvr) process.
|
||||||
|
1. Log in to the firewall CLI.
|
||||||
|
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||||
|
|
||||||
|
## PAN-116017
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Google Cloud Platform (GCP) only
|
||||||
|
```
|
||||||
|
|
||||||
|
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||||
|
|
||||||
|
## PAN-115816
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Microsoft Azure only
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-114495
|
||||||
|
|
||||||
|
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||||
|
|
||||||
|
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||||
|
|
||||||
|
## PAN-112694
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls with multiple virtual systems only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||||
|
|
||||||
|
## PAN-112456
|
||||||
|
|
||||||
|
You can temporarily submit a change request for a URL Category with three suggested categories; however, only two categories are supported. Do not add more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, only the first two categories in the change request are evaluated.
|
||||||
|
|
||||||
|
## PAN-112135
|
||||||
|
|
||||||
|
You cannot unregister tags for a subnet or range in a dynamic address group from the web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use an XML API request to unregister the tags for the subnet or range.
|
||||||
|
|
||||||
|
## PAN-111928
|
||||||
|
|
||||||
|
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||||
|
|
||||||
|
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||||
|
|
||||||
|
## PAN-111866
|
||||||
|
|
||||||
|
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||||
|
|
||||||
|
**Workaround:** Perform one of the following tasks.
|
||||||
|
|
||||||
|
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||||
|
- Manually select the devices that belong to the modified device group and template configurations.
|
||||||
|
|
||||||
|
## PAN-111729
|
||||||
|
|
||||||
|
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-111670
|
||||||
|
|
||||||
|
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||||
|
|
||||||
|
## PAN-110794
|
||||||
|
|
||||||
|
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||||
|
|
||||||
|
## PAN-109759
|
||||||
|
|
||||||
|
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
|
||||||
|
|
||||||
|
## PAN-109526
|
||||||
|
|
||||||
|
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||||
|
|
||||||
|
## PAN-106675
|
||||||
|
|
||||||
|
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||||
|
|
||||||
|
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||||
|
|
||||||
|
## PAN-104780
|
||||||
|
|
||||||
|
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||||
|
|
||||||
|
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||||
|
|
||||||
|
## PAN-103276
|
||||||
|
|
||||||
|
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||||
|
|
||||||
|
## PAN-101688
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama plugins
|
||||||
|
```
|
||||||
|
|
||||||
|
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||||
|
|
||||||
|
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||||
|
|
||||||
|
## PAN-101537
|
||||||
|
|
||||||
|
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||||
|
|
||||||
|
**Workaround:** Specify the vsys in the query string:
|
||||||
|
|
||||||
|
`admin>` `set system target-vsys <vsys-name>`
|
||||||
|
|
||||||
|
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||||
|
|
||||||
|
## PAN-98520
|
||||||
|
|
||||||
|
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||||
|
|
||||||
|
## PAN-97757
|
||||||
|
|
||||||
|
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||||
|
|
||||||
|
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||||
|
|
||||||
|
## PAN-97524
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama management server only
|
||||||
|
```
|
||||||
|
|
||||||
|
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||||
|
|
||||||
|
## PAN-96446
|
||||||
|
|
||||||
|
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||||
|
|
||||||
|
## PAN-95773
|
||||||
|
|
||||||
|
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||||
|
|
||||||
|
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||||
|
|
||||||
|
## PAN-95511
|
||||||
|
|
||||||
|
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||||
|
|
||||||
|
## PAN-95028
|
||||||
|
|
||||||
|
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||||
|
|
||||||
|
## PAN-94846
|
||||||
|
|
||||||
|
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||||
|
|
||||||
|
## PAN-94093
|
||||||
|
|
||||||
|
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||||
|
|
||||||
|
## PAN-93968
|
||||||
|
|
||||||
|
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||||
|
|
||||||
|
## PAN-93607
|
||||||
|
|
||||||
|
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||||
|
|
||||||
|
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||||
|
|
||||||
|
## PAN-93532
|
||||||
|
|
||||||
|
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||||
|
|
||||||
|
## PAN-93193
|
||||||
|
|
||||||
|
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||||
|
|
||||||
|
- Switch to the firewall **Context** on the Panorama management server.
|
||||||
|
- Commit changes when a dynamic update is being installed.
|
||||||
|
- Generate a custom report when a dynamic update is being installed.
|
||||||
|
- Generate custom reports during a commit.
|
||||||
|
|
||||||
|
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||||
|
|
||||||
|
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||||
|
|
||||||
|
## PAN-91802
|
||||||
|
|
||||||
|
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||||
|
|
||||||
|
## PAN-83610
|
||||||
|
|
||||||
|
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||||
|
|
||||||
|
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-83236
|
||||||
|
|
||||||
|
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||||
|
|
||||||
|
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||||
|
|
||||||
|
## PAN-83215
|
||||||
|
|
||||||
|
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||||
|
|
||||||
|
## PAN-81521
|
||||||
|
|
||||||
|
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||||
|
|
||||||
|
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||||
|
|
||||||
|
## PAN-77125
|
||||||
|
|
||||||
|
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||||
|
|
||||||
|
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-75457
|
||||||
|
|
||||||
|
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||||
|
|
||||||
|
## PAN-73530
|
||||||
|
|
||||||
|
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||||
|
|
||||||
|
## PAN-73401
|
||||||
|
|
||||||
|
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||||
|
|
||||||
|
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||||
|
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||||
|
|
||||||
|
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||||
|
|
||||||
|
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||||
|
- Configure a worker list on the cluster controller:
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||||
|
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||||
|
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||||
|
or
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||||
|
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||||
|
|
||||||
|
## PAN-70906
|
||||||
|
|
||||||
|
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||||
|
|
||||||
|
## PAN-69505
|
||||||
|
|
||||||
|
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||||
|
|
||||||
|
## PAN-41558
|
||||||
|
|
||||||
|
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||||
|
|
||||||
|
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||||
|
|
||||||
|
## PAN-40079
|
||||||
|
|
||||||
|
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||||
|
|
||||||
|
## PAN-39636
|
||||||
|
|
||||||
|
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||||
|
|
||||||
|
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||||
|
|
||||||
|
## PAN-38255
|
||||||
|
|
||||||
|
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||||
|
|
||||||
|
## PAN-31832
|
||||||
|
|
||||||
|
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||||
|
|
||||||
|
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||||
|
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||||
@@ -366,6 +366,44 @@
|
|||||||
"10.1.13_2026-03-16.md",
|
"10.1.13_2026-03-16.md",
|
||||||
"10.1.14_2026-03-16.md"
|
"10.1.14_2026-03-16.md"
|
||||||
]
|
]
|
||||||
|
},
|
||||||
|
"10.0": {
|
||||||
|
"addressed": [
|
||||||
|
"10.0.4_2026-03-16.md",
|
||||||
|
"10.0.5_2026-03-16.md",
|
||||||
|
"10.0.6_2026-03-16.md",
|
||||||
|
"10.0.7_2026-03-16.md",
|
||||||
|
"10.0.8-h4_2026-03-16.md",
|
||||||
|
"10.0.8-h8_2026-03-16.md",
|
||||||
|
"10.0.8-h10_2026-03-16.md",
|
||||||
|
"10.0.8-h11_2026-03-16.md",
|
||||||
|
"10.0.10_2026-03-16.md",
|
||||||
|
"10.0.11-h1_2026-03-16.md",
|
||||||
|
"10.0.11-h3_2026-03-16.md",
|
||||||
|
"10.0.11-h4_2026-03-16.md",
|
||||||
|
"10.0.12-h5_2026-03-16.md"
|
||||||
|
],
|
||||||
|
"known": [
|
||||||
|
"10.0.1_2026-03-16.md",
|
||||||
|
"10.0.2_2026-03-16.md",
|
||||||
|
"10.0.3_2026-03-16.md",
|
||||||
|
"10.0.5_2026-03-16.md",
|
||||||
|
"10.0.6_2026-03-16.md",
|
||||||
|
"10.0.8_2026-03-16.md",
|
||||||
|
"10.0.9_2026-03-16.md"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"9.1": {
|
||||||
|
"addressed": [],
|
||||||
|
"known": []
|
||||||
|
},
|
||||||
|
"9.0": {
|
||||||
|
"addressed": [],
|
||||||
|
"known": []
|
||||||
|
},
|
||||||
|
"8.1": {
|
||||||
|
"addressed": [],
|
||||||
|
"known": []
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
|||||||
Reference in New Issue
Block a user