Update PAN-OS 11.1 files
This commit is contained in:
@@ -6,92 +6,67 @@ version: 11.1.4-h4
|
||||
|
||||
## PAN-265963
|
||||
|
||||
Fixed an issue where the escd process caused a memory
|
||||
leak when session resiliency was enabled on the firewall.
|
||||
Fixed an issue where the escd process caused a memory leak when session resiliency was enabled on the firewall.
|
||||
|
||||
## PAN-265349
|
||||
|
||||
Fixed an issue where multiple segments of HTTP proxy connect messages
|
||||
were not handled correctly by proxy.
|
||||
Fixed an issue where multiple segments of HTTP proxy connect messages were not handled correctly by proxy.
|
||||
|
||||
## PAN-264421
|
||||
|
||||
Fixed an issue on Panorama where Push Scope
|
||||
did not populate automatically after changing the device group
|
||||
configuration.
|
||||
Fixed an issue on Panorama where **Push Scope** did not populate automatically after changing the device group configuration.
|
||||
|
||||
## PAN-263987
|
||||
|
||||
Fixed an issue on the firewall where, when a NAT transversal IPSec
|
||||
tunnel was terminated, and the NAT rule that was applied to the
|
||||
NAT-T IPSec tunnel was on the same firewall, traffic flowing through
|
||||
the tunnel was not correctly translated.
|
||||
Fixed an issue on the firewall where, when a NAT transversal IPSec tunnel was terminated, and the NAT rule that was applied to the NAT-T IPSec tunnel was on the same firewall, traffic flowing through the tunnel was not correctly translated.
|
||||
|
||||
## PAN-263559
|
||||
|
||||
Fixed an issue where the dataplane stopped responding and the
|
||||
firewall unexpectedly rebooted due to multiple process restarts.
|
||||
Fixed an issue where the dataplane stopped responding and the firewall unexpectedly rebooted due to multiple process restarts.
|
||||
|
||||
## PAN-263226
|
||||
|
||||
Fixed an issue where, when SSL decryption was enabled and Client
|
||||
Hello messages spanned multiple TCP segments, some SSL decrypted
|
||||
sessions failed.
|
||||
Fixed an issue where, when SSL decryption was enabled and Client Hello messages spanned multiple TCP segments, some SSL decrypted sessions failed.
|
||||
|
||||
## PAN-262593
|
||||
|
||||
Fixed an issue where traffic to websites failed on the Google Chrome
|
||||
web browser on Secure Web Gateway (SWG) nodes.
|
||||
Fixed an issue where traffic to websites failed on the Google Chrome web browser on Secure Web Gateway (SWG) nodes.
|
||||
|
||||
## PAN-262340
|
||||
|
||||
Fixed an issue where FQDN resolution failed for address objects, and
|
||||
all FQDN traffic was denied by the interzone-default policy
|
||||
rule.
|
||||
Fixed an issue where FQDN resolution failed for address objects, and all FQDN traffic was denied by the interzone-default policy rule.
|
||||
|
||||
## PAN-262287
|
||||
|
||||
Fixed an issue where dereferencing a NULL pointer that occurred when
|
||||
App-ID stopped responding caused the firewall to restart.
|
||||
Fixed an issue where dereferencing a NULL pointer that occurred when App-ID stopped responding caused the firewall to restart.
|
||||
|
||||
## PAN-261991
|
||||
|
||||
Fixed an issue where traffic that did not match a decryption policy
|
||||
rule, or matched a no-decrypt policy rule, failed when accumulation
|
||||
proxy was enabled and a Zone Protection profile was configured with
|
||||
syn-cookies enabled.
|
||||
Fixed an issue where traffic that did not match a decryption policy rule, or matched a no-decrypt policy rule, failed when accumulation proxy was enabled and a Zone Protection profile was configured with syn-cookies enabled.
|
||||
|
||||
## PAN-261917
|
||||
|
||||
Fixed an issue where websites with a no-decrypt policy rule were
|
||||
decrypted in traffic log when using a Google Chrome browser with PQC
|
||||
enabled.
|
||||
Fixed an issue where websites with a no-decrypt policy rule were decrypted in traffic log when using a Google Chrome browser with PQC enabled.
|
||||
|
||||
## PAN-261909
|
||||
|
||||
Fixed an issue where the GlobalProtect client did not display the
|
||||
dialog box for an MFA verification code.
|
||||
Fixed an issue where the GlobalProtect client did not display the dialog box for an MFA verification code.
|
||||
|
||||
## PAN-261489
|
||||
|
||||
Fixed an issue where an out-of-memory (OOM) condition caused a
|
||||
firewall outage.
|
||||
Fixed an issue where an out-of-memory (OOM) condition caused a firewall outage.
|
||||
|
||||
## PAN-261484
|
||||
|
||||
Fixed an issue on the firewall where DPDK allocated twice the amount
|
||||
of memory as requested for pre-allocation.
|
||||
Fixed an issue on the firewall where DPDK allocated twice the amount of memory as requested for pre-allocation.
|
||||
|
||||
## PAN-261001
|
||||
|
||||
Fixed an issue where GlobalProtect users were unable to switch
|
||||
gateways after upgrading to GlobalProtect version 6.2.3.
|
||||
Fixed an issue where GlobalProtect users were unable to switch gateways after upgrading to GlobalProtect version 6.2.3.
|
||||
|
||||
## PAN-260974
|
||||
|
||||
Fixed an issue where the Cloud Identity Engine (CIE) user context did
|
||||
not correctly redistribute user/IP address port mapping to
|
||||
on-premises firewalls.
|
||||
Fixed an issue where the Cloud Identity Engine (CIE) user context did not correctly redistribute user/IP address port mapping to on-premises firewalls.
|
||||
|
||||
## PAN-259997
|
||||
|
||||
@@ -99,35 +74,23 @@ on-premises firewalls.
|
||||
PA-3410, PA-3420, and PA-3430 firewalls only
|
||||
```
|
||||
|
||||
Fixed an
|
||||
issue where the install failed when upgrading from PAN-OS 10.2.3-h3
|
||||
and later 10.2 releases to PAN-OS 10.2.10 due to the number of
|
||||
configured vsys zones exceeding the zone limit in PAN-OS
|
||||
10.2.10.
|
||||
Fixed an issue where the install failed when upgrading from PAN-OS 10.2.3-h3 and later 10.2 releases to PAN-OS 10.2.10 due to the number of configured vsys zones exceeding the zone limit in PAN-OS 10.2.10.
|
||||
|
||||
## PAN-259769
|
||||
|
||||
Fixed an issue where the GlobalProtect portal was not accessible via
|
||||
a web browser and displayed the error
|
||||
ERR_EMPTY_RESPONSE.
|
||||
Fixed an issue where the GlobalProtect portal was not accessible via a web browser and displayed the error ERR_EMPTY_RESPONSE.
|
||||
|
||||
## PAN-259151
|
||||
|
||||
Fixed an issue where unused objects were pushed to the firewall,
|
||||
which caused configuration pushes to fail with the error
|
||||
Number of address groups exceed platform
|
||||
capacity.
|
||||
Fixed an issue where unused objects were pushed to the firewall, which caused configuration pushes to fail with the error Number of address groups exceed platform capacity.
|
||||
|
||||
## PAN-258736
|
||||
|
||||
Fixed an issue where policy rule configurations pushed from Panorama
|
||||
were not reflected on the firewall if the rule had 63
|
||||
characters.
|
||||
Fixed an issue where policy rule configurations pushed from Panorama were not reflected on the firewall if the rule had 63 characters.
|
||||
|
||||
## PAN-258225
|
||||
|
||||
Fixed an issue on the Panorama web interface where Security policy
|
||||
rules loaded more slowly than expected.
|
||||
Fixed an issue on the Panorama web interface where Security policy rules loaded more slowly than expected.
|
||||
|
||||
## PAN-257957
|
||||
|
||||
@@ -135,8 +98,7 @@ rules loaded more slowly than expected.
|
||||
Firewalls and Panorama appliances in FIPS-CC mode only
|
||||
```
|
||||
|
||||
Fixed an issue where the authd process restarted if RADIUS
|
||||
PAP/CHAP authentication was used.
|
||||
Fixed an issue where the *authd*process restarted if RADIUS PAP/CHAP authentication was used.
|
||||
|
||||
## PAN-257925
|
||||
|
||||
@@ -144,22 +106,15 @@ PAP/CHAP authentication was used.
|
||||
CN-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the CLI
|
||||
command show system setting ctd state did not
|
||||
work as expected.
|
||||
Fixed an issue where the CLI command show system setting ctd state did not work as expected.
|
||||
|
||||
## PAN-256725
|
||||
|
||||
Fixed an issue on the Panorama interface where
|
||||
Traffic and
|
||||
Unified event details loaded more slowly
|
||||
than expected.
|
||||
Fixed an issue on the Panorama interface where **Traffic** and **Unified** event details loaded more slowly than expected.
|
||||
|
||||
## PAN-256666
|
||||
|
||||
Fixed an issue where the configdprocess stopped responding
|
||||
when Commit and Push operations were performed on multiple
|
||||
device groups.
|
||||
Fixed an issue where the *configd*process stopped responding when **Commit and Push**operations were performed on multiple device groups.
|
||||
|
||||
## PAN-256385
|
||||
|
||||
@@ -167,17 +122,11 @@ device groups.
|
||||
CN-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where
|
||||
communication was broken between the management plane and the
|
||||
dataplane when anti-spyware profiles were configured in a Security
|
||||
policy rule.
|
||||
Fixed an issue where communication was broken between the management plane and the dataplane when anti-spyware profiles were configured in a Security policy rule.
|
||||
|
||||
## PAN-256350
|
||||
|
||||
Fixed an issue where, when you cloned an admin role or an LDAP server
|
||||
profile and then changed the name of the clone, the configuration
|
||||
change was not reflected on the managed firewall after pushing the
|
||||
configuration from Panorama.
|
||||
Fixed an issue where, when you cloned an admin role or an LDAP server profile and then changed the name of the clone, the configuration change was not reflected on the managed firewall after pushing the configuration from Panorama.
|
||||
|
||||
## PAN-256320
|
||||
|
||||
@@ -185,103 +134,79 @@ configuration from Panorama.
|
||||
Firewalls in active/passive HA configurations only
|
||||
```
|
||||
|
||||
Fixed
|
||||
an issue where GTP sessions remained as allocated sessions on the
|
||||
passive firewall even when there were no active sessions.
|
||||
Fixed an issue where GTP sessions remained as allocated sessions on the passive firewall even when there were no active sessions.
|
||||
|
||||
## PAN-255930
|
||||
|
||||
Fixed an issue where persistent DIPP NAT entries were deleted even
|
||||
when being used during an active session.
|
||||
Fixed an issue where persistent DIPP NAT entries were deleted even when being used during an active session.
|
||||
|
||||
## PAN-255266
|
||||
|
||||
Fixed an issue where you were unable to clone a template stack with
|
||||
the Pre-Shared Key variable.
|
||||
Fixed an issue where you were unable to clone a template stack with the Pre-Shared Key variable.
|
||||
|
||||
## PAN-254826
|
||||
|
||||
Fixed an issue where the firewall stopped responding when processing
|
||||
traffic.
|
||||
Fixed an issue where the firewall stopped responding when processing traffic.
|
||||
|
||||
## PAN-254671
|
||||
|
||||
Fixed an issue where excessive Timed out while getting
|
||||
config lock error messages were generated when
|
||||
making bulk changes via XML API.
|
||||
Fixed an issue where excessive Timed out while getting config lock error messages were generated when making bulk changes via XML API.
|
||||
|
||||
## PAN-254423
|
||||
|
||||
Fixed an issue on Panorama where custom role-based admin users with
|
||||
read only access were able to make changes to configurations.
|
||||
Fixed an issue on Panorama where custom role-based admin users with read only access were able to make changes to configurations.
|
||||
|
||||
## PAN-253626
|
||||
|
||||
Fixed an issue on Panorama where unused objects were pushed to the
|
||||
firewall, which caused the push operations to intermittently fail.
|
||||
Fixed an issue on Panorama where unused objects were pushed to the firewall, which caused the push operations to intermittently fail.
|
||||
|
||||
## PAN-253213
|
||||
|
||||
Fixed an issue where the firewall sent HIP notifications every time
|
||||
it received a HIP report instead of every two hours.
|
||||
Fixed an issue where the firewall sent HIP notifications every time it received a HIP report instead of every two hours.
|
||||
|
||||
## PAN-252300
|
||||
|
||||
Fixed an issue where you were unable to select device groups in the
|
||||
push scope for user accounts.
|
||||
Fixed an issue where you were unable to select device groups in the push scope for user accounts.
|
||||
|
||||
## PAN-251676
|
||||
|
||||
Fixed an issue on Panorama appliances in large-scale deployments
|
||||
where configd process core files consumed more space in
|
||||
the /opt/panlogs partition than was available.
|
||||
Fixed an issue on Panorama appliances in large-scale deployments where configd process core files consumed more space in the /opt/panlogs partition than was available.
|
||||
|
||||
## PAN-251655
|
||||
|
||||
Fixed an issue where the firewall stopped forwarding files to the
|
||||
WildFire cloud and a restart of the varrcvr process was
|
||||
required.
|
||||
Fixed an issue where the firewall stopped forwarding files to the WildFire cloud and a restart of the varrcvr process was required.
|
||||
|
||||
## PAN-250787
|
||||
|
||||
Fixed an issue where network issues between the firewall and the log
|
||||
collector caused logrcvr process memory exhaustion.
|
||||
Fixed an issue where network issues between the firewall and the log collector caused logrcvr process memory exhaustion.
|
||||
|
||||
## PAN-250419
|
||||
|
||||
Fixed an issue where XML API explorer inserted a plus (+) character
|
||||
in the Xpath when a space was used in the object name.
|
||||
Fixed an issue where XML API explorer inserted a plus (+) character in the Xpath when a space was used in the object name.
|
||||
|
||||
## PAN-250062
|
||||
|
||||
Fixed an issue where device telemetry failed after upgrading due to
|
||||
bundle generation failure.
|
||||
Fixed an issue where device telemetry failed after upgrading due to bundle generation failure.
|
||||
|
||||
## PAN-249266
|
||||
|
||||
Fixed an issue where the config process virtual memory
|
||||
was exceeded due to delays in post-commit processing.
|
||||
Fixed an issue where the config process virtual memory was exceeded due to delays in post-commit processing.
|
||||
|
||||
## PAN-249011
|
||||
|
||||
Fixed an issue where the firewall became unresponsive when committing
|
||||
a configuration change with a large number of uncommitted changes in
|
||||
the replay database.
|
||||
Fixed an issue where the firewall became unresponsive when committing a configuration change with a large number of uncommitted changes in the replay database.
|
||||
|
||||
## PAN-247099
|
||||
|
||||
Fixed an issue where the firewall decrypted traffic unexpectedly when
|
||||
the client hello was spread across multiple packets.
|
||||
Fixed an issue where the firewall decrypted traffic unexpectedly when the client hello was spread across multiple packets.
|
||||
|
||||
## PAN-246304
|
||||
|
||||
Fixed an issue on Panorama where commits failed due to a timeout in
|
||||
the sysd process during decryption.
|
||||
Fixed an issue on Panorama where commits failed due to a timeout in the sysd process during decryption.
|
||||
|
||||
## PAN-246220
|
||||
|
||||
Fixed an issue where a dynamic peer connection was rejected when
|
||||
using an FQDN for the peer address.
|
||||
Fixed an issue where a dynamic peer connection was rejected when using an FQDN for the peer address.
|
||||
|
||||
## PAN-244039
|
||||
|
||||
@@ -289,55 +214,40 @@ using an FQDN for the peer address.
|
||||
PA-5450 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall
|
||||
dropped packets when attempting to reuse a TCP session.
|
||||
Fixed an issue where the firewall dropped packets when attempting to reuse a TCP session.
|
||||
|
||||
## PAN-243098
|
||||
|
||||
Fixed an issue with corrupted images when SSL decryption and Security
|
||||
profiles were configured.
|
||||
Fixed an issue with corrupted images when SSL decryption and Security profiles were configured.
|
||||
|
||||
## PAN-241781
|
||||
|
||||
Fixed an issue where partial commit and commit-all operations took
|
||||
more time than expected to create the job ID.
|
||||
Fixed an issue where partial commit and commit-all operations took more time than expected to create the job ID.
|
||||
|
||||
## PAN-241044
|
||||
|
||||
Fixed an issue where traffic was denied by the interzone-default
|
||||
policy rule when a Security policy rule with an FQDN destination was
|
||||
configured.
|
||||
Fixed an issue where traffic was denied by the interzone-default policy rule when a Security policy rule with an FQDN destination was configured.
|
||||
|
||||
## PAN-234560
|
||||
|
||||
Fixed an issue where the daily summary report displayed IPv6
|
||||
addresses instead of IPv4 addresses.
|
||||
Fixed an issue where the daily summary report displayed IPv6 addresses instead of IPv4 addresses.
|
||||
|
||||
## PAN-233727
|
||||
|
||||
Fixed an issue on the web interface where the following error message
|
||||
was incorrectly displayed for an IKE gateway with a valid
|
||||
configuration: ikev2->pq-ppk->negotiation-mode is
|
||||
invalid.
|
||||
Fixed an issue on the web interface where the following error message was incorrectly displayed for an IKE gateway with a valid configuration: ikev2->pq-ppk->negotiation-mode is invalid.
|
||||
|
||||
## PAN-237582
|
||||
|
||||
Fixed an issue where logs were intermittently missing on the log
|
||||
collector due to missing aliases for some indices
|
||||
Fixed an issue where logs were intermittently missing on the log collector due to missing aliases for some indices
|
||||
|
||||
## PAN-234094
|
||||
|
||||
Fixed an issue on Panorama where Deploy Master Keyresulted in
|
||||
the error message Failed to communicate with device due to a low
|
||||
connection timeout value.
|
||||
Fixed an issue on Panorama where **Deploy Master Key**resulted in the error message Failed to communicate with device due to a low connection timeout value.
|
||||
|
||||
## PAN-232214
|
||||
|
||||
Fixed an issue where GlobalProtect clients remained in the connecting
|
||||
state during portal pre-login when Kerberos single sign-on (SSO) was
|
||||
enabled.
|
||||
Fixed an issue where GlobalProtect clients remained in the connecting state during portal pre-login when Kerberos single sign-on (SSO) was enabled.
|
||||
|
||||
## PAN-230825
|
||||
|
||||
Fixed an issue where link flaps occurred on Panorama appliances in HA
|
||||
configurations.
|
||||
Fixed an issue where link flaps occurred on Panorama appliances in HA configurations.
|
||||
|
||||
Reference in New Issue
Block a user