Update PAN-OS 11.1 files
This commit is contained in:
@@ -6,6 +6,10 @@ version: 11.1.10-h21
|
||||
|
||||
## PAN-316911
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls on Amazon Web Services (AWS) environments only
|
||||
```
|
||||
|
||||
Fixed an issue where a newly bootstrapped firewall required a management server restart, relicensing, or license push from Panorama to invoke the device certificate.
|
||||
|
||||
## PAN-315176
|
||||
@@ -26,6 +30,10 @@ Fixed an issue where traffic was disrupted during IPSec rekey operations due to
|
||||
|
||||
## PAN-313850
|
||||
|
||||
```caveat
|
||||
PA-1400 Series firewalls in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where a split-brain condition occurred and HA1/HA2 links went down while upgrading when the HA configuration used dataplane interfaces for HA1 and a combination of HSCI and Ethernet interfaces for HA2.
|
||||
|
||||
## PAN-313623
|
||||
@@ -34,6 +42,10 @@ Fixed an issue where the /opt/pancfg/mgmt/ssl/private/ directory on Palo Alto Ne
|
||||
|
||||
## PAN-313572
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the dataplane restarted due to a segmentation fault.
|
||||
|
||||
## PAN-312706
|
||||
@@ -42,14 +54,26 @@ Fixed an issue where the firewalls restarted due to a function lacking a NULL-po
|
||||
|
||||
## PAN-311285
|
||||
|
||||
```caveat
|
||||
Firewalls in HA conditions only
|
||||
```
|
||||
|
||||
Fixed an issue where a memory leak occurred related to the ospfd process, which caused RAM usage to continuously increase on active devices in an HA cluster until the device stopped responding, even after an HA failover.
|
||||
|
||||
## PAN-311250
|
||||
|
||||
```caveat
|
||||
Panorama appliances and Log Collectors only
|
||||
```
|
||||
|
||||
Fixed an issue where logs from multiple devices were not visible on Panorama even though the Elasticsearch health status on the dedicated Log Collectors appeared green.
|
||||
|
||||
## PAN-311073
|
||||
|
||||
```caveat
|
||||
Panorama managed firewalls in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where firewalls incorrectly updated the modified date and MD5 hash of policy rules during an HA sync commit job or a subsequent local commit, even when no changes were made to the policy rules.
|
||||
|
||||
## PAN-309300
|
||||
@@ -58,6 +82,10 @@ Fixed an issue where management plane system resources configuration size exceed
|
||||
|
||||
## PAN-308786
|
||||
|
||||
```caveat
|
||||
Panorama appliances only
|
||||
```
|
||||
|
||||
Fixed an issue where traffic log queries using the device_name filter returned no results, and complex log queries that included negation operators produced incorrect outputs.
|
||||
|
||||
## PAN-308654
|
||||
@@ -66,10 +94,18 @@ Fixed an issue where the Elasticsearch Close Indices process closed more indices
|
||||
|
||||
## PAN-308507
|
||||
|
||||
```caveat
|
||||
Panorama managed firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall intermittently failed to maintain active log forwarding streams to Cortex Data Lake even when duplicate logging and enhanced application logging were enabled.
|
||||
|
||||
## PAN-307702
|
||||
|
||||
```caveat
|
||||
Firewalls in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where traffic passing through AE layer 2 interfaces was interrupted during HA failovers.
|
||||
|
||||
## PAN-307597
|
||||
@@ -120,6 +156,10 @@ Fixed an issue on the firewall where configuring spyware and vulnerability profi
|
||||
|
||||
## PAN-302654
|
||||
|
||||
```caveat
|
||||
Firewalls in active/passive HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where, when the HA configuration had multiple logical routers, static or connected routes redistributed into OSPF aged out in the LSDB, which caused the routes to be removed on peer OSPF neighbors.
|
||||
|
||||
## PAN-301731
|
||||
@@ -168,6 +208,10 @@ Fixed an issue where a memory leak related to the configd process occurred.
|
||||
|
||||
## PAN-296202
|
||||
|
||||
```caveat
|
||||
Firewalls in active/active HA configurations only
|
||||
```
|
||||
|
||||
Added a log enhancement to capture an issue where, when a commit operation was in progress, newly deployed IP address tags that used the XML API were not immediately reflected in address group resolution, which delayed IP address mapping to address groups and caused traffic to be incorrectly allowed or denied.
|
||||
|
||||
## PAN-294379
|
||||
@@ -204,6 +248,10 @@ Fixed an issue where traffic logs incorrectly displayed the action as **allow**
|
||||
|
||||
## PAN-279364
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls with multiple NICs only
|
||||
```
|
||||
|
||||
Fixed an issue were the queue count in the task dump displayed an incorrect number of queues for SR-IOV interfaces due to the queue mapping logic incorrectly using a non-multi-NIC function.
|
||||
|
||||
## PAN-279209
|
||||
@@ -216,14 +264,26 @@ Fixed an issue where DNS Security threat logs were not displayed on the firewall
|
||||
|
||||
## PAN-278628
|
||||
|
||||
```caveat
|
||||
Firewalls in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where the configd process restarted during a configuration push from Panorama, which caused the active firewall to lose management access for 20-30 minutes.
|
||||
|
||||
## PAN-277987
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls in AWS environments only
|
||||
```
|
||||
|
||||
Fixed an issue where HA failover mode incorrectly changed from **interface move** to **secondary IP move** after a reboot.
|
||||
|
||||
## PAN-274742
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the task-queue dump CLI command returned incorrect information in multi-nic mode.
|
||||
|
||||
## PAN-273487
|
||||
@@ -232,6 +292,10 @@ Fixed an issue where the distributord process restarted on firewalls in multi-vs
|
||||
|
||||
## PAN-273158
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where an incorrect ASIC configuration caused silent packet drops or application slowness when receiving a mix of jumbo and non-jumbo packets.
|
||||
|
||||
## PAN-262353
|
||||
@@ -248,4 +312,4 @@ Fixed an issue where memory leaks occurred when checking for, downloading, or in
|
||||
|
||||
## PAN-243507
|
||||
|
||||
Fixed an issue on the firewall web interface where **Logical Router** did not load after an FRR stack upgrade.
|
||||
Fixed an issue on the firewall web interface where **Logical Router** did not load after an Advanced Routing Engine stack upgrade.
|
||||
|
||||
Reference in New Issue
Block a user