Revise PAN-OS 11.2 known issues
This commit is contained in:
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,874 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 34%" />
|
||||
<col style="width: 66%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">WF500-6271</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
A WildFire cluster node that has been configured with an IPv6
|
||||
management port might not display the signature status when using the
|
||||
following CLI:
|
||||
<span class="ph codeph"
|
||||
>show wildfire global signature-status sha256 equal
|
||||
<SHA_256_Value></span
|
||||
>
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Gracefully restart the affected
|
||||
Wildfire cluster nodes.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">WF500-6259</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When a WildFire cluster node configured as a server or worker node is
|
||||
rebooted, issuing the CLI command,
|
||||
<span class="ph codeph">global sample-status</span> does not update
|
||||
the samples processed list on the active controller and non-server
|
||||
worker nodes.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Gracefully restart the affected
|
||||
WildFire active controller and passive controller in the cluster.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">WF500-6270</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The WildFire cluster server and worker nodes might disconnect from the
|
||||
Wildfire cluster management network, resulting in a notifier process
|
||||
exit on WildFire cluster controllers.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Gracefully restart the WildFire
|
||||
cluster node where the process exit occurred.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">WF500-6222</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When WildFire secure cluster communication is enabled using a custom
|
||||
DNS, the cluster formation might fail due to cluster management
|
||||
communication issues.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Do not configure a custom DNS when
|
||||
WildFire secure cluster communication is enabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">WF500-6176</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When Panorama is used to manage a WildFire cluster, switchover
|
||||
functionality for active and passive controller roles is not
|
||||
available.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308564</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Packets are dropped on SD-WAN interfaces if they require fragmentation
|
||||
for an interface but have the
|
||||
<span class="ph uicontrol">Don't Fragment (DF)</span> bit set. This
|
||||
results in unexpected packet drops. This affects client to server
|
||||
sessions when using SD-WAN for NGFW.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Allow fragmenting packets with DF bit
|
||||
set (<span class="ph userinput"
|
||||
>debug dataplane set ip4-ignore-df yes</span
|
||||
>).
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308507</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Strata Logging Service (SLS) log-forwarding streams intermittently
|
||||
show as inactive. When checking the status of log-forwarding
|
||||
connections, one or more streams are reported as inactive. Restarting
|
||||
the <span class="ph codeph">log-receiver</span> process temporarily
|
||||
resolves the issue, but the streams become inactive again after
|
||||
approximately 1-2 hours. This intermittent inactivity results in log
|
||||
loss.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-295645</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When a WildFire cluster is configured centrally using Panorama, it
|
||||
initiates a series of processes, including a software install and
|
||||
reboot, in an order that will leave the resulting WildFire cluster in
|
||||
an unusable state.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-288525</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When the Enterprise DLP data filtering profile is configured with a
|
||||
<span class="ph uicontrol">Block</span> action and is used in
|
||||
conjunction with Advanced Threat Prevention, which is configured with
|
||||
an action of <span class="ph uicontrol">reset-both</span>,
|
||||
<span class="ph uicontrol">reset-server</span>,
|
||||
<span class="ph uicontrol">reset-client</span>, or
|
||||
<span class="ph uicontrol">drop</span> for the
|
||||
<span class="ph uicontrol">HTTP Command and Control detector</span>,
|
||||
Dropbox file uploads that exceed the maximum configured file size
|
||||
action will fail.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Configure the Advanced Threat
|
||||
Prevention Inline Cloud analysis (<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Objects</span
|
||||
><span class="ph uicontrol">Security Profiles</span
|
||||
><span class="ph uicontrol">Anti-Spyware</span></span
|
||||
>) action for the HTTP Command and Control detector to
|
||||
<span class="ph uicontrol">alert</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-285061</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When Enterprise DLP is enabled, file uploads might unexpectedly fail
|
||||
when 100 continue response is received from the server during file
|
||||
uploads.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-284700</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
File downloads for content encoded with zstd (Zstandard), such as
|
||||
specific content from box.com, fail when using Enterprise DLP because
|
||||
zstd decompression is not supported in PAN-OS.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-283429</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When you use custom certificates for the connection between Panorama
|
||||
and a log collector, the automated renewal for the predefined
|
||||
ElasticSearch certificates gets disrupted.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Remove the custom certificates before
|
||||
the ElasticSearch certificates expire. This allows the system to
|
||||
correctly identify and renew the predefined ElasticSearch
|
||||
certificates. After the renewal is complete, re-install the custom
|
||||
certificates.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-260851</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
From the NGFW or Panorama CLI, you can override the existing
|
||||
application tag even if Disable Override is enabled for the
|
||||
application (<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Objects</span
|
||||
><span class="ph uicontrol">Applications</span></span
|
||||
>) tag.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-260212</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When viewing <span class="ph uicontrol">Applications</span> (<span
|
||||
class="ph menucascade"
|
||||
><span class="ph uicontrol">Objects</span
|
||||
><span class="ph uicontrol">Applications</span></span
|
||||
>), child App-IDs may be listed under the incorrect container App-ID.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-259853</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When the DHCP server is enabled for GlobalProtect, the commit error
|
||||
message is not properly displayed when
|
||||
<span class="ph uicontrol">Any</span> is selected as the source
|
||||
interface in the service router configuration (
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Device</span
|
||||
><span class="ph uicontrol">Setup</span
|
||||
><span class="ph uicontrol">Service</span
|
||||
><span class="ph uicontrol"></span
|
||||
><span class="ph uicontrol"
|
||||
>Service Router Configuration</span
|
||||
></span
|
||||
>).
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-259423</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When the GlobalProtect DHCP feature is enabled with two primary DHCP
|
||||
servers on the GlobalProtect gateway, the gpsvc gets stuck during
|
||||
renewal and after HA failover.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-254236</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
TLSv1.3 hybridized Kyber support in the latest versions of Chrome and
|
||||
Edge browsers results in dropped Client Hello packets when SSL/TLS
|
||||
handshake inspection is enabled.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Disable
|
||||
<a
|
||||
class="xref"
|
||||
href="https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/inspect-ssl-tls-handshakes"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>SSL/TLS handshake inspection</a
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-254108</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
when upgrading or downgrading a Panorama management server (<span
|
||||
class="ph menucascade"
|
||||
><span class="ph uicontrol">Panorama</span
|
||||
><span class="ph uicontrol">Software</span></span
|
||||
>), managed device (<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Panorama</span
|
||||
><span class="ph uicontrol">Device Deployment</span
|
||||
><span class="ph uicontrol">Software</span></span
|
||||
>), or standalone firewall (<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Device</span
|
||||
><span class="ph uicontrol">Software</span></span
|
||||
>), <span class="ph uicontrol">Base Releases</span> and
|
||||
<span class="ph uicontrol">Preferred Releases</span> settings are
|
||||
checked (enabled) by default and cause no PAN-OS software images to
|
||||
display.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Uncheck (disable)
|
||||
<span class="ph uicontrol">Base Releases</span> or
|
||||
<span class="ph uicontrol">Preferred Releases</span> to display either
|
||||
the available base PAN-OS or preferred PAN-OS releases available to
|
||||
download and install.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-253963</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The auto commit job may take longer than expected to complete when the
|
||||
Panorama management server is in Panorama or Log Collector mode.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-252661</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
If you change the service route of gp-ip-mgmt in
|
||||
<b class="ph b"
|
||||
>Device > Setup > Services > Service Features >
|
||||
gp-ip-mgmt</b
|
||||
>
|
||||
and <b class="ph b">Commit</b>, the change won’t take effect.
|
||||
gp-ip-mgmt continues to use the last committed service route.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> After you change the service route
|
||||
interface for gp-ip-mgmt, navigate to either a GlobalProtect portal or
|
||||
gateway, click <b class="ph b">OK </b>to save the configuration, and
|
||||
<b class="ph b">Commit </b>the changes. This commit will include the
|
||||
service route change.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-250246</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Panorama and the firewall display inconsistent IP addresses for
|
||||
dynamic address group members after manually syncing.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-250062</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Device telemetry might fail at configured intervals due to bundle
|
||||
generation issues.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-248836</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The Advanced DNS Security trial license and trial license information
|
||||
cannot be activated and viewed, respectively, on a managed firewall
|
||||
(with expired or active status) from Panorama. These tasks can only be
|
||||
performed on the firewall.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-247728</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When Advanced Routing is enabled, IP multicast is not supported. An
|
||||
upcoming version will provide support for this feature. Customers who
|
||||
have multicast configured or who plan to deploy multicast routing
|
||||
should not upgrade to 11.2.0. Additionally, when Advanced Routing is
|
||||
enabled, the BGP dampening configuration isn't applied to any peers or
|
||||
peer group; the configuration is preserved but has no effect on BGP.
|
||||
Customers can use BGP even if they have applied a Dampening profile to
|
||||
a specific set of peers. The issue doesn't affect any other BGP
|
||||
features.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-241994</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The VMX hardware version was upgraded from vmx-10 to vmx-15 on ESXi
|
||||
and NSX-T. Support for vmx-15 is supported on ESXi 6.7 U2 and onwards.
|
||||
Palo Alto Networks recommends that you upgrade your ESXi version if it
|
||||
is less than 6.7 U2. For more information, see the
|
||||
<a
|
||||
class="xref"
|
||||
href="https://kb.vmware.com/s/article/2007240"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
rel="nofollow"
|
||||
>compatibility matrix</a
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-239612</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When the firewall is running PAN-OS 11.2.0 and Advanced Routing is
|
||||
enabled, DHCPv4 relay agent functions successfully, but DHCPv6 relay
|
||||
agent doesn't work.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-237106</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
LSVPN satellite certificates may be generated with serial numbers
|
||||
exceeding 40 hexadecimal characters. This causes certificate
|
||||
revocation and deletion operations to fail with the following error
|
||||
messages:
|
||||
</div>
|
||||
<ul id="panos-known-issues-11.2.11_ul-t2x_dxs_wgc" class="ul">
|
||||
<li class="li">
|
||||
<span class="ph systemoutput"
|
||||
>db-serialno can be at most 40 characters</span
|
||||
>
|
||||
</li>
|
||||
<li class="li">
|
||||
<span class="ph systemoutput">db-serialno is invalid</span>
|
||||
</li>
|
||||
</ul>
|
||||
<b class="ph b">Workaround:</b>
|
||||
<div class="p">
|
||||
To resolve this issue, use the following CLI commands with the LSVPN
|
||||
satellite serial number to manually delete or revoke the affected
|
||||
certificates:
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Delete certificate information</b>:<span
|
||||
class="ph userinput"
|
||||
>delete sslmgr-store certificate-info portal name
|
||||
<var class="keyword varname"><name></var> serialno
|
||||
<var class="keyword varname"><satellite_serial></var></span
|
||||
>
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Revoke satellite certificates</b>:<span
|
||||
class="ph userinput"
|
||||
>delete sslmgr-store satellite-info-revoke-certificate portal
|
||||
<var class="keyword varname"><name></var> serialno
|
||||
<var class="keyword varname"
|
||||
><list_of_satellite_serials></var
|
||||
></span
|
||||
>
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-236649</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
If you change the configuration of a firewall acting as a PPPoEv4 or
|
||||
PPPoEv6 client, old routes from the Forwarding Information Base (FIB)
|
||||
and route table for an inherited configuration with dynamic-identifier
|
||||
or client remain visible. Old routes also remain visible for an
|
||||
inherited interface when you execute the CLI command,
|
||||
<span class="ph userinput">show interface all</span>.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Unconfigure and configure the
|
||||
Inherited Interface.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-234015</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The X-Forwarded-For (XFF) value is not displayed in traffic logs.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-207442</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
For M-700 appliances in an active/passive high availability (<span
|
||||
class="ph menucascade"
|
||||
><span class="ph uicontrol">Panorama</span
|
||||
><span class="ph uicontrol">High Availability</span></span
|
||||
>) configuration, the
|
||||
<span class="ph systemoutput">active-primary</span> HA peer
|
||||
configuration sync to the
|
||||
<span class="ph systemoutput">secondary-passive</span> HA peer may
|
||||
fail. When the config sync fails, the job Results is
|
||||
<span class="ph systemoutput">Successful</span>
|
||||
(<span class="ph uicontrol">Tasks</span>), however the sync status on
|
||||
the <span class="ph uicontrol">Dashboard</span> displays as
|
||||
<span class="ph systemoutput">Out of Sync</span> for both HA peers.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Perform a local commit on the
|
||||
<span class="ph systemoutput">active-primary</span> HA peer and then
|
||||
synchronize the HA configuration.
|
||||
</div>
|
||||
<ol id="panos-known-issues-11.2.11_ol_aqy_kbp_qxb" class="ol">
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
<a
|
||||
class="xref"
|
||||
href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-web-interface"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>Log in to the Panorama web interface</a
|
||||
>
|
||||
of the <span class="ph systemoutput">active-primary</span> HA
|
||||
peer.
|
||||
</div>
|
||||
</li>
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
Select <span class="ph uicontrol">Commit</span> and
|
||||
<span class="ph uicontrol">Commit to Panorama</span>.
|
||||
</div>
|
||||
</li>
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
In the <span class="ph systemoutput">active-primary</span> HA peer
|
||||
<span class="ph uicontrol">Dashboard</span>, click
|
||||
<span class="ph uicontrol">Sync to Peer</span> in the High
|
||||
Availability widget.
|
||||
</div>
|
||||
</li>
|
||||
</ol>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-206909</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The Dedicated Log Collector is unable to reconnect to the Panorama
|
||||
management server if the <span class="ph systemoutput">configd</span>
|
||||
process crashes. This results in the Dedicated Log Collector losing
|
||||
connectivity to Panorama despite the managed collector connection
|
||||
<span class="ph systemoutput">Status</span> (<span
|
||||
class="ph menucascade"
|
||||
><span class="ph uicontrol">Panorama</span
|
||||
><span class="ph uicontrol">Managed Collector</span></span
|
||||
>) displaying <span class="ph systemoutput">connected</span> and the
|
||||
managed colletor <span class="ph systemoutput">Health</span> status
|
||||
displaying as healthy.
|
||||
</div>
|
||||
<div class="p">
|
||||
This results in the local Panorama config and system logs not being
|
||||
forwarded to the Dedicated Log Collector. Firewall log forwarding to
|
||||
the disconnected Dedicated Log Collector is not impacted.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Restart the
|
||||
<span class="ph systemoutput">mgmtsrvr</span> process on the Dedicated
|
||||
Log Collector.
|
||||
</div>
|
||||
<ol id="panos-known-issues-11.2.11_ol_pdy_4bm_lvb" class="ol">
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
<a
|
||||
class="xref"
|
||||
href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>Log in to the Dedicated Log Collector CLI</a
|
||||
>.
|
||||
</div>
|
||||
</li>
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
Confirm the Dedicated Log Collector is disconnected from Panorama.
|
||||
</div>
|
||||
<!-- FM Dita Overlay for Code -->
|
||||
<div class="code-wrap">
|
||||
<pre
|
||||
class="pre codeblock"
|
||||
data-label="PRE CODEBLOCK"
|
||||
><div style="display: inline;"><span class="ph systemoutput hljs">admin></span><span class="ph userinput hljs sql"> <span class="hljs-keyword">show</span> panorama-<span class="hljs-keyword">status</span></span></div></pre>
|
||||
<div class="p">
|
||||
Verify the <span class="ph systemoutput">Connected</span> status
|
||||
is <span class="ph systemoutput">no</span>.
|
||||
</div>
|
||||
</div>
|
||||
</li>
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
Restart the <span class="ph systemoutput">mgmtsrvr</span> process.
|
||||
</div>
|
||||
<!-- FM Dita Overlay for Code -->
|
||||
<div class="code-wrap">
|
||||
<pre
|
||||
class="pre codeblock"
|
||||
data-label="PRE CODEBLOCK"
|
||||
><div style="display: inline;"><span class="ph systemoutput hljs">admin></span><span class="ph userinput hljs nginx"> <span class="hljs-attribute">debug</span> software restart process management-server</span></div></pre>
|
||||
</div>
|
||||
</li>
|
||||
</ol>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-197588</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The PAN-OS ACC (Application Command Center) does not display a widget
|
||||
detailing statistics and data associated with vulnerability exploits
|
||||
that have been detected using inline cloud analysis.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-197419</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-1400 Series firewalls only</tt>) In
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Network</span
|
||||
><span class="ph uicontrol">Interface</span
|
||||
><span class="ph uicontrol">Ethernet</span></span
|
||||
>, the power over Ethernet (PoE) ports do not display a
|
||||
<span class="ph uicontrol">Tag</span> value.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-196758</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
On the Panorama management server, pushing a configuration change to
|
||||
firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
|
||||
configurations for SD-WAN as being edited or deleted despite no edits
|
||||
or deletions being made when you
|
||||
<span class="ph uicontrol">Preview Changes</span> (<span
|
||||
class="ph menucascade"
|
||||
><span class="ph uicontrol">Commit</span
|
||||
><span class="ph uicontrol">Push to Devices</span
|
||||
><span class="ph uicontrol">Edit Selections</span></span
|
||||
>
|
||||
or
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Commit</span
|
||||
><span class="ph uicontrol">Commit and Push</span
|
||||
><span class="ph uicontrol">Edit Selections</span></span
|
||||
>).
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-195968</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-1400 Series firewalls only</tt>) When using the
|
||||
CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
|
||||
prints an error depending on whether an interface type was selected on
|
||||
the non-PoE port or not. If an interface type, such as tap, Layer 2,
|
||||
or virtual wire, was selected before PoE was configured, the error
|
||||
message will not include the interface name (eg. ethernet1/4). If an
|
||||
interface type was not selected before PoE was configured, the error
|
||||
message will include the interface name.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-187685</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
On the Panorama management server, the Template Status displays no
|
||||
synchronization status (<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Panorama</span
|
||||
><span class="ph uicontrol">Managed Devices</span
|
||||
><span class="ph uicontrol">Summary</span></span
|
||||
>) after a bootstrapped firewall is successfully added to Panorama.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> After the bootstrapped firewall is
|
||||
successfully added to Panorama,
|
||||
<a
|
||||
class="xref"
|
||||
href="https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-web-interface.html"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>log in to the Panorama web interface</a
|
||||
>
|
||||
and select
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Commit</span
|
||||
><span class="ph uicontrol">Push to Devices</span></span
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-187407</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The configured Advanced Threat Prevention inline cloud analysis action
|
||||
for a given model might not be honored under the following condition:
|
||||
If the firewall is set to
|
||||
<span class="ph uicontrol"
|
||||
>Hold client request for category lookup </span
|
||||
>and the action set to
|
||||
<span class="ph uicontrol">Reset-Both</span> and the URL cache has
|
||||
been cleared, the first request for inline cloud analysis will be
|
||||
bypassed.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-184406</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Using the CLI to add a RAID disk pair to an M-700 appliance causes the
|
||||
dmdb process to crash.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Contact customer support to stop the
|
||||
dmdb process before adding a RAID disk pair to a M-700 appliance.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-183404</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Static IP addresses are not recognized when "and" operators are used
|
||||
with IP CIDR range.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-181933</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
|
||||
all of the cards may not receive all of the updates and the mappings
|
||||
for the clients may become out of sync, which causes the firewall to
|
||||
not correctly populate the Source User column in the session logs.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user