Add some PAN-OS 11.1 references and URLs

This commit is contained in:
2026-04-14 17:01:57 -05:00
parent 99b0420a4d
commit 245c34705f
15 changed files with 13767 additions and 18 deletions
+988
View File
@@ -0,0 +1,988 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-241230</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the SNMP get request status value for Panorama
connections was incorrect.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253187</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
the class of service (CoS) priority bit was not modified, causing
access points to lose connectivity to the wireless controller when
traffic was routed through the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253778</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-7500 Series firewalls in a cluster configuration only</tt
>) Fixed an issue where users were able to enable or disable certain
configurations.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-290239</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-455 firewalls in active/passive HA configurations only</tt
>) Fixed an issue where, after an upgrade, the TCP session for syslog
forwarding did not resume after the syslog server service was disabled
and then re-enabled, which caused logs to be dropped. This occurred
when the syslog server was down for more than 16 minutes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-290088</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory leak occurred related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process when pushing configurations from Panorama to a firewall. This
occurred when the configurations contained shared policy rules.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-289304</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7500 firewalls only</tt>) Fixed an issue where
SNMP polling failed due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>snmpd</a
>
process becoming unresponsive to incoming requests, which resulted in
high CPU usage.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-289102</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a race condition issue related to predict processing on
multi-core platforms, which resulted in a dataplane restart and
traffic loss.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-288930</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic from cloud applications intermittently
matched an incorrect
<span class="ph uicontrol">cloud-apps</span> policy rule when ACE
(App-ID Cloud Engine) was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-288893</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in multi-vsys configurations only</tt>)
Fixed an issue where HTTP/2 traffic failed due when one virtual system
(vsys) had a decryption policy rule enabled and another vsys had a
no-decrypt policy rule for the same session.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-288363</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the MIB ID returned an incorrect value via SNMP.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-287838</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue on
the web interface where resetting the rule hit counter for multiple
policy rules failed with the error message
<span class="ph systemoutput">Failed to reset rule-hit job</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-287818</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where sessions timed out sooner than expected due to
the <span class="ph systemoutput">pan_proxy_accumulation_</span>
<span class="ph systemoutput">restore_timeout</span> not initiating
when the accumulation
<span class="ph systemoutput"> session_init</span> failed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-287734</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">Scan ERR: Internal Err 1002</span> messages
were unexpectedly generated when WIF shared memory use was high.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-287621</b></div>
</td>
<td class="entry relcol">
<div class="p">
Added debug logs for an issue where a slow IP address pool NAT leak
occurred when persistent NAT was enabled, which led to NAT IP pool
exhaustion.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-287584</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where the address object pop up
window only displayed a maximum of four address objects in the policy
rule even after expanding the window.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-287056</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where BGP export policy rules with next-hop matching
failed to block the advertisement of static routes, and the firewall
incorrectly matched the egress interface IP address instead of the
original next-hop IP address of the static route, which caused the
deny rule to fail.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-287023</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a large number of logs caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process to stop responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-286857</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where only failed Kerberos authentication events were
logged in <span class="ph systemoutput">auth.log</span>, and
successful authentication events were not logged.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-286848</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where ECMP incorrectly balanced sessions across links
based on the configured metric, which led to an imbalance in traffic
distribution and resulted in traffic assignment shifting
disproportionately to routes with lower metrics.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-286443</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after an upgrade, the firewall was unable to be
managed via HTTPS or SSH.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-286306</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when getting transceiver information from ESCC
for SFP 25G modules, the transceiver code was incorrectly updated with
<span class="ph systemoutput">Unknown</span> instead of
<span class="ph systemoutput">25GBase-SR</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-285894</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding, which caused the firewall to reboot
unexpectedly, and traffic failures occurred.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-285818</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a tool was needed to display leaked NAT port
numbers without requiring a forced synchronization.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-284908</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where retrieving filenames from OneDrive resulted in a
cache miss.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-284067</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
process experienced OOM conditions due to the
<span class="ph systemoutput"
>show running application statistics </span
>CLI command, which caused the firewall to reboot.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-284003</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where clients did not receive a valid response when
when searching a website due to a compression error.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-283979</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall became non-functional due to high
root partition use.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-283813</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the web interface performance was
slower than usual when retrieving read-only configurations from
Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-282394</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a firewall was only able to display a maximum of
14 permitted IP addresses from a Panorama Template Variable.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-282277</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an OOM condition on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process caused interface flapping, and the interface unexpectedly went
down and then recovered without intervention.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-281509</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue where
log exports were slower than expected or failed when filtering logs
after an upgrade, which resulted in timeouts or delays in displaying
logs on the web interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-280101</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where set and edit commands took longer than expected
when adding address objects with a large number of dynamic groups due
to the completion cache being enabled. With this fix, the completion
cache is disabled by default.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-279706</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">M-600 appliances only</tt>) Fixed an issue where
Panorama did not update all
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>panreplay</a
>
database entries after performing a commit and full push to all
devices.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-279500</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TLS connections failed to establish in asymmetric
routing environments if the firewall did not see server-to-client
(s2c) packets of the TLS handshake.
</div>
<div class="p">
To use this fix, run the following CLI command:
<span class="ph systemoutput"
>debug dataplane set ssl-decrypt accumulate-client-hello
asym-disable yes</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-278836</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after an upgrade, GlobalProtect attempted to use
the embedded browser instead of the default browser for gateway
authentication even when it was configured to use the default browser.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-278812</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where authentication to GlobalProtect failed with the
error message
<span class="ph systemoutput">User not in allowed list</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-278150</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall removed the Authentication Key
Identifier (AKID) from the certificate during SSL decryption, which
caused Python 3.13 to fail with a certificate verification error.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-277808</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>eproxy</a
>
process stopped responding when running a long duration test using
IXload with hybrid SWG SAML authentication bypass for HTTPS payloads,
which caused the proxy to become unreachable.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-277617</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where deleting the NTP server address caused a commit
validation error. This occurred when the configuration included both
primary and secondary NTP servers and the secondary server was
removed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-277234</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a device group import resulted in a Security
policy rule being created with
<span class="ph uicontrol">Application</span> set to
<span class="ph uicontrol">none</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-276920</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where web-advertisement traffic was not immediately
blocked which resulted in pages loading indefinitely.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-276678</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama became unresponsive while performing a
dynamic address update without a lock.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-275451</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue where
sequence numbers were lost when forwarded from Panorama, which
resulted in missing or lost logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-275133</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where HTTP 503 server errors occurred while browsing
websites due to slow Secure Web Gateway (SWG) bypass rule lookup.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-275047</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue
where, after an upgrade, the firewall was unable to send logs to the
Strata Logging Service (SLS) when using a specific proxy server, and
the SSL connection status displayed as failed when attempting to
forward logs through the web proxy.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-274797</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a DPC on slot 3 failed intermittently due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pktlog_forwarding</a
>
process restarting, which resulted in an unexpected HA failover.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-273964</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SNMP scans to a firewall timed out after
upgrading to a PAN-OS 10.2 release.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-272395</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where informational logs caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>distributord</a
>
process log file to be frequently overwritten.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-272175</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where session rematch caused ACE cloud application
traffic to match the wrong policy.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-271810</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where auto-negotiation advertised and negotiated 10/100
half and full duplex.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-271432</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to decrypt SSL traffic
when using forward proxy and HSM with an ECDSA signing certificate.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-271425</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/active HA configurations only</tt
>) Fixed an issue with SSL inbound decryption on firewalls on a vwire
setup with asymmetric routing.
</div>
<div class="p">
To use this fix, enter the CLI command
<span class="ph systemoutput"
>set system setting ssl-decrypt ha-vwire-mac-learn global yes</span
>
on both firewalls in an HA pair.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-269700</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where commits to service connection firewalls from
Panorama failed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-269057</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>routed</a
>
process stopped responding due to accessing freed memory from a hash
table when the route vectors were resized. This occurred when a large
number of static routes were configured.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-268787</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where users were unable to log in to Panorama and the
following error message was displayed:
<span class="ph systemoutput"
>Timed out while getting config lock. Please try again</span
>. This occurred when pushing configurations to a large number of
devices.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-268313</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Priority Code Point (PCP) bits in the VLAN
header were not reset to 0 when a packet was received from one Layer 3
tagged interface and forwarded to another, which resulted in dropped
packets.
</div>
<div class="p">
To use this fix, run the CLI command
<span class="ph systemoutput">set force-vlan-pcp-reset yes</span> and
reboot the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-267759 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Prisma Access gateway downloads were slower than
expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-267328</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding, which caused the firewall to stop
processing traffic.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-264708</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a selective push was blocked when a configuration
load was done.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259727</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances in HA configurations only</tt>)
Fixed an issue where Panorama became unresponsive and displayed a 504
gateway timeout error when accessing the web interface or the CLI.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253778</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-7500 Series firewalls in a cluster configuration only</tt
>) Fixed an issue where users were able to enable or disable certain
configurations.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253187</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
the class of service (CoS) priority bit was not modified, causing
access points to lose connectivity to the wireless controller when
traffic was routed through the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-241230</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the SNMP get request status value for Panorama
connections was incorrect.
</div>
</td>
</tr>
</tbody>
</table>
+528
View File
@@ -0,0 +1,528 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-306502</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TLS connection failure occurred when traffic was
over TLS1.2 or below, header insertion was enabled on the firewall,
<span class="ph uicontrol">send TLS handshake to CTD</span> was
enabled, and traffic hit a decryption policy rule configured with the
<span class="ph uicontrol">no-decrypt</span> action.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-306306</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances in FIPS-CC mode only</tt>)
Fixed interdevice TLS communication failures that occurred with RSA
and RSA-PSS signature algorithms across multiple layer 7 application
services.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-306226</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the TLS handshake did not complete and the
session did not go through. This occurred if the HTTP header insertion
applied to an HTTP CONNECT request passing through the firewall, the
scan-handshake feature was enabled, the session matched a decryption
policy rule with the decrypt action, and if the TLS client hello was
in a single packet and TLS 1.2 or below.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-304496</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after unregistering an IP tag and registering a
different IP tag for the same IP address via XML API, the dynamic
address group membership was not updated on the dataplane, which
resulted in Security policy rules being enforced incorrectly.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-303954</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when configuring Safenet HSMs in HA and
authentication HSM manually, the second HSM server failed to
authenticate due to the firewall overwriting the first HSM server's
certificate with the second HSM server's certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-303051</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a memory leak occurred related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process due to retaining memory that was temporarily used for report
generation instead of releasing the memory for reuse, which resulted
in continuous accumulation and memory exhaustion.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-301801</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Log Collectors where the Elasticsearch process
fluctuated intermittently between green and red states, which led to
interruptions in log collection. This issue occurred when the number
of shards exceeded the cluster's maximum supported threshold of
greater than 1000 shards per Elasticsearch instance.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-300637</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Microsoft Azure environments only</tt
>) Fixed an issue where the firewall unexpectedly rebooted due to
repeated
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>varrcvr</a
>
process restarts.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300548</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where using the IKEv2 multiplier setting for VPN
re-authentication resulted in the firewall not re-authenticating at
the expected intervals when both sides initiated rekeying. The
internal re-authentication counter incremented when the local side
triggered the rekey, but not when the peer side triggered it.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297975</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama was unable to push the Trusted Root CA
configuration to Log Collectors via a Collector Group push due to the
Log Collector not supporting the
<span class="ph systemoutput">trusted-root-CA</span> configuration.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-297708</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a long-lived session with many Machine Learning
(ML) model triggers caused a memory leak of feature states associated
with the ML model runs. This resulted in Spyware_State failure
increases, allocation max outs, and impaired policy matching.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297610</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall became unresponsive after an upgrade
due to the <span class="ph systemoutput">fsck</span> command scanning
drive partitions in parallel with the root partition, which caused the
process to take an extended amount of time.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-297295</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls in Microsoft Azure environments only</tt
>) Fixed an issue where the firewall repeatedly restarted due to high
packet rates on the synthetic path in DPDK mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297005</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where exporting custom reports resulted in empty CSV
files.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-296977</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the web interface became unresponsive when
attempting to view
<span class="ph uicontrol">Ethernet</span> interface details after
applying a filter in
<span class="ph uicontrol">Network &gt; Interfaces</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-296397</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where previewing changes
after a commit to shared objects were not accurately displayed in the
push scope.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"> PAN-295578</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect HIP data file download and
installation failed with the error message
<span class="ph systemoutput"
>An error occurred while processing request. Please try again after
some time or contact support</span
>
or <span class="ph systemoutput">No ETAG from response</span> due to a
script exiting prematurely.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-294307</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
SIGSEGV crash occurred when renaming objects within policy rules,
objects, or zones.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"> PAN-291009</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after a web server returned a 401 or 403 error,
the firewall was unable to decrypt HTTP/2 traffic, and the firewall
rejected all subsequent streams from the client.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"> PAN-290665</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with firewalls enabled with Security profiles where
certain traffic conditions caused high dataplane CPU utilization and
packet buffer exhaustion, which caused LACP flapping conditions.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-288158</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the firewall became inaccessible via the web interface and SSH and
remained in an initializing state.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-288097</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where on the firewall where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>routed</a
>
process stopped responding after changing the MTU or any link state
parameters when OSPF and PIM were enabled on the same interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-284866</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the LFC failed to validate Certificate Revocation
Lists (CRL) for SSL syslog connections, which caused a failure to
forward logs to external syslog servers.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-280725</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process repeatedly restarted, which caused dataplane failure and loss
of connectivity, including PAN-DB URL resolution. This occurred after
a commit push from Panorama and resulted in the firewall becoming
non-functional due to internal path monitoring failure and
configuration memory exhaustion.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-278126</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the number of registered IP Tags on Panorama did
not match the number of registered IP Tags on the managed firewalls
due to a change in file format between PAN-OS releases.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-276484 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not display license information for
Cloud NGFW firewalls under (<span class="ph uicontrol"
>Device Deployment &gt; Licenses</span
>) due to the inability to perform batch-license refreshes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-276321</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where User-ID mappings were not correctly redistributed
from Panorama to firewalls, causing some users to be identified as
<span class="ph uicontrol">unknown</span>, which prevented access to
resources based on AD group membership.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-274086</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall incorrectly assembled SIP NOTIFY and
REFER messages when processing SIP TCP packets that contained a
partial content-body from a previous SIP message and a complete header
and content-body from the next SIP message.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-272245</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>dnsproxy</a
>
process stopped responding due to memory corruption caused by a race
condition when the allow list downloading was impacted by a
configuration change.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-257616</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where selective push operations from Panorama to
managed firewalls failed with the error message
<span class="ph systemoutput"
>Failed to generate selective push configuration. Schema validation
failed. Please try a full push</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-241694</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where memory leaks related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
process occurred when downloading and pushing updates from the App-ID
Cloud Engine to the dataplane.
</div>
</td>
</tr>
</tbody>
</table>
+750
View File
@@ -0,0 +1,750 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-309392</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the scroll bar did not appear when editing
<span class="ph uicontrol">Destination Addresses</span> for Policy
Based forwarding policy rules.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-309379</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process stopped responding on DPCs, which prevented logs from being
forwarded.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-308085</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls in Microsoft Azure environments only</tt
>) Fixed an issue where, after resizing the VM, the HA2 link became
unstable. Frequent keep-alive failures occurred, and HA2 keep-alive
packets were simultaneously transmitted to multiple destination MAC
addresses and the peer firewall's interface MAC). This issue occurred
on firewalls with Accelerated Networking enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-308060</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/active HA configurations only</tt
>) Fixed an issue where the BFD session went down and did not recover
even though the BGP remained in an established state, which caused the
firewall to cease route learning and advertisement with the peer, even
though BGP keep-alives were exchanged correctly.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-307795</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama incorrectly generated system logs
indicating a lost connection to its peer after an upgrade even when
High Availability was not configured.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-305835</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls with Memory Integrity Checking
Architecture enabled rebooted unexpectedly due to accessing an invalid
memory address. This occurred because the forwarding data structure
index exceeded its designed limit.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-305412</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Logging Service License Status displays a
license failure when the license status transitions from valid to
expired and then back to valid even when the connection to the
Security Logging Service (SLS) was working.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-305301</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the timing of GlobalProtect lifetime expiry or
inactivity logout notifications used for GlobalProtect SSL tunnels
could cause the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process to stop responding and the dataplane to restart.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-304636</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where BGP aggregate routes were not created and discard
routes were not installed in the routing table.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-303959</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic is incorrectly identified as
unknown-tcp/unknown-udp due to App-ID resource leak and eventually
dropped.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-303627</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after committing a configuration change, the
firewall experienced traffic issues,
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
crashes, and LACP interface failures.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-303559</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after manuallly creating a device telemetry
bundle, the
<span class="ph systemoutput">hour_cli_output.txt</span> file within
the bundle had a file size of 0 bytes. This occurred when checking the
bundle content after enabling device telemetry and setting the device
telemetry upload endpoint.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-302551</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall displayed as disconnected in the SLS
due to the serial number not being retrieved
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-301975</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
issue where the passive firewall incorrectly triggered PBP alerts even
with low packet rates.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-301937</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Microsoft Defender for Cloud detected cleartext
SSH private keys in the /var/appweb and /etc/appweb directories on
PA-VM firewalls deployed in Azure.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-301912</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama stopped responding when deploying
dynamic updates to managed devices.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-301600</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where, after upgrading Panorama, OSPF
adjacencies remained in the exchange start state, which resulted in an
incomplete routing table.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-301456</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the
<span class="ph codeph">debug system reset-ztp</span> CLI command was
unavailable.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-301409</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama failed to perform a selective push to a
managed device when device tags were added or modified on the policy
rules. The selective push failed with the error message
<span class="ph systemoutput"
>Failed to generate selective push configuration. Schema validation
failed. Please try a full push</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300837</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls experienced multiple reboots due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process restarting with a SIGSEGV signal. This occurred because the
client-to-firewall side assumed TLS 1.3 for the firewall-server side.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-299751</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to connect to the
Subscription License Service (SLS) due to a public and private key
pair mismatch with the device certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-299622</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the MFA timestamp was not redistributed between
standalone firewalls behind an Azure load balancer after upgrading,
which resulted in users being prompted to reauthenticate multiple
times.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-298907</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on PA-VM in AWS where, in a two-arm deployment
integrated with Gateway Load Balancer (GWLB), the firewall did not
preserve the GENEVE source port for internet traffic, resulting in
increased latency. The fix ensures the firewall preserves the outer
UDP source port of GENEVE encapsulation when sending traffic back to
GWLB.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297263</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5220 firewalls only</tt>) Fixed an issue where
the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>ikemgr</a
>
process crashed intermittently, causing IPSec tunnels to go down
randomly. The fix ensures that the IKE security association data
structures are accessed in a thread-safe manner. This prevents the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>ikemgr</a
>
process from referencing an invalid memory pointer during teardown
operations and provides stability.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-296208</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not accept address groups in the
filter condition of a Log Forwarding Match list.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-295796</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall intermittently failed to forward
VXLAN GARP packets, which led to connectivity issues for wireless
clients in environments that used VXLAN tunnels for wireless access
points.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-292447</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not display data in the
<span class="ph uicontrol">Feature Adoption</span> tab in Strata Cloud
Manager due to the system creating and deleting a CLI user for each
interval instead of reusing a permanent CLI user for telemetry.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291067</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
process periodically exceeded its virtual memory limit and restarted,
which led to intermittent outages.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-290241</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process became unresponsive, which caused User-ID CLI commands to time
out.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-290235</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>dscd</a
>
process crashed continuously on MIPS platforms (for example, PA-850
firewalls) due to a runtime error related to an invalid memory address
or nil pointer dereference. This was caused by a golang library
upgrade in CIE that is incompatible with the MIPS platform.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-289652</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue related to external URL lists where pushing
configuration changes from Panorama failed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-288427</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where commit jobs were not queued and the
system reported that the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
was not connected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287921</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the maximum registered IP address for was incorrectly set to 100,000
instead of the expected 500,000.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-285208</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not automatically recover after
a machine check exception (MCE) occurred.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-283237</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic logs incorrectly displayed the action as
<span class="ph uicontrol">allow</span> for traffic matching a
Security policy rule configured with the action set to
<span class="ph uicontrol">deny</span>. This issue occurred due to the
child session being used for policy rule lookup when a configuration
update triggered a rematch if the FTP-data application was not in the
rule.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-281588</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where packet buffer depletion occurred due to the a
high number of
<span class="ph systemoutput">tcp_pkt_queued</span> packets when Jumbo
was enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-277464</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with intermittent access and slower than expected
loading times when accessing websites. This occurred when Anti-Spyware
inline cloud analysis was enabled and the
<span class="ph uicontrol">SSL Command and Control</span> action was
not either <span class="ph uicontrol">allow</span> or
<span class="ph uicontrol">alert</span> and server hello packets were
out of order.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269535</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the mib ID returned an incorrect value via SNMP.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263691</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted unexpectedly due to a
memory leak in the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262831</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5400f Series firewalls only</tt>) Fixed an
intermittent issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding, which caused the firewall to restart.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-255654</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when QoS was enabled on aggregate interfaces,
the maximum aggregate interface throughput was capped, which limited
network traffic. This occurred even with default QoS settings and no
configured egress max-bandwidth.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-236794</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SNMP walk reported incorrect interface speeds.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-185731</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to parse the URL path and
host when the host header was located in a different packet, which
resulted in the firewall not logging the URL path in the first packet.
The fix is disabled by default. The following CLI commands can be used
to enable/disable the feature:
<ul id="panos-addressed-issues-11.1.10-h12_ul-fmq_kc3_yhc" class="ul">
<li class="li">
<span class="ph systemoutput"
>set system setting ctd url-crosspkt-host-path-caching
enable</span
>
</li>
<li class="li">
<span class="ph systemoutput"
>set system setting ctd url-crosspkt-host-path-caching
disable</span
>
</li>
<li class="li">
<span class="ph systemoutput"
>set system setting ctd url-crosspkt-host-path-caching
default</span
>
</li>
</ul>
</div>
</td>
</tr>
</tbody>
</table>
+973
View File
@@ -0,0 +1,973 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-316911</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Amazon Web Services (AWS) environments
only</tt
>) Fixed an issue where a newly bootstrapped firewall required a
management server restart, relicensing, or license push from Panorama
to invoke the device certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-315176</b></div>
</td>
<td class="entry relcol">
<div class="p">
Added an enable and disable CLI command to address an issue where the
firewall experienced increased packet drops and slower performance
after an upgrade due to high burst traffic.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-314319</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall experienced increased packet drops
and slower performance after an upgrade due to high burst traffic.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-314142</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where establishing log forwarding connections to the
Strata Logging Service (SLS) took longer than expected, which resulted
in delayed log visibility on SLS.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-314061</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic was disrupted during IPSec rekey
operations due to a 2 second delay in sending the DELETE message for
the previous Security Association (SA) to the peer gateway after a new
SA was negotiated.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-313850</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-1400 Series firewalls in HA configurations only</tt
>) Fixed an issue where a split-brain condition occurred and HA1/HA2
links went down while upgrading when the HA configuration used
dataplane interfaces for HA1 and a combination of HSCI and Ethernet
interfaces for HA2.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-313623</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">/opt/pancfg/mgmt/ssl/private/</span>
directory on Palo Alto Networks devices with TPM support became 100%
utilized due to an accumulation of undeleted
<span class="ph systemoutput">.pub_pem</span> files. This occurred
because executing the
<span class="ph systemoutput">show device-certificate status</span>
CLI command initiated a process that generated these files but failed
to remove them, which prevented the fetching of new device
certificates.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-313572</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the dataplane restarted due to a segmentation fault.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-312706</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewalls restarted due to a function lacking
a NULL-pointer sanity check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-311285</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in HA conditions only</tt>) Fixed an
issue where a memory leak occurred related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>ospfd</a
>
process, which caused RAM usage to continuously increase on active
devices in an HA cluster until the device stopped responding, even
after an HA failover.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-311250</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances and Log Collectors only</tt>)
Fixed an issue where logs from multiple devices were not visible on
Panorama even though the Elasticsearch health status on the dedicated
Log Collectors appeared green.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-311073</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Panorama managed firewalls in HA configurations only</tt
>) Fixed an issue where firewalls incorrectly updated the modified
date and MD5 hash of policy rules during an HA sync commit job or a
subsequent local commit, even when no changes were made to the policy
rules.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-309300</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where management plane system resources configuration
size exceeded 28 MB for over 4 hours, and the following error message
was displayed:
<span class="ph systemoutput"
>Configuration size reaching device capacity limit</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-308786</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue where
traffic log queries using the
<span class="ph systemoutput">device_name</span> filter returned no
results, and complex log queries that included negation operators
produced incorrect outputs.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-308654</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Elasticsearch Close Indices process closed
more indices than expected and dropped the number of open shards below
the minimum of 800 per Elasticsearch instance. This occurred because
the process did not correctly account for the number of Elasticsearch
instances when calculating the maximum number of allowed open shards.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-308507</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama managed firewalls only</tt>) Fixed an
issue where the firewall intermittently failed to maintain active log
forwarding streams to Cortex Data Lake even when duplicate logging and
enhanced application logging were enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-307702</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
issue where traffic passing through AE layer 2 interfaces was
interrupted during HA failovers.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-307597</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where BGP peering sessions between a hub firewall and a
satellite firewall over GlobalProtect LSVPN failed to connect.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-306555</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding, which led to
service outages.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"> PAN-305700</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a reboot loop occurred when OSPF interfaces were
configured with a link type of
<span class="ph uicontrol">point-to-point</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-305552</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DLP logs displayed an incorrect file type when
the firewall did not set the file type field.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-304718</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where OSPF and BGP outages occurred due to an
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process restart during clientless VPN content rewrite processing.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-304696</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Cloud User-ID connection timed out because
the firewall took too long to process the OCSP response.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-304576</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall entered a non-functional state due
to segmentation fault within the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process that was caused by a session that involved http2 cleartext
traffic.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-304205</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where, after upgrading to an affected
release, a partial commit via the API did not push configuration
changes to managed firewalls, and a full commit was required to
synchronize the configuration.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-303959</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic was incorrectly identified as
unknown-tcp/unknown-udp due to App-ID resource leak and eventually
dropped.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-303745</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where inter-dataplane forwarding did not work for
sessions ingressing on Slot 2, which resulted in intermittent ping
failures to interfaces on Network Card 2 when traffic was forwarded to
Slot 3.
</div>
<div class="p">
<b class="ph b">Note</b>: With this fix, after a slot restart, the
global counter will still show dot1q errors for a short period.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-303722</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where configuring spyware and
vulnerability profiles in Security policy rules caused a memory leak
in the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
process with each configuration commit.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-302654</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/passive HA configurations only</tt
>) Fixed an issue where, when the HA configuration had multiple
logical routers, static or connected routes redistributed into OSPF
aged out in the LSDB, which caused the routes to be removed on peer
OSPF neighbors.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-301731</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the firewall was unable to establish an SCM
connection due to the discovery service returning a 404 error when the
device was not yet known to the service, the firewall did not retry
the attempt as expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-300671</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic reports that were generated with
destination/source and destination/source hostnames were not displayed
in IPv4 format.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-300664</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama and firewall web interface where
Applications pages became unresponsive after activating the SaaS
Inline license.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300423</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Data Processing Cards (DPCs) installed in slots 5
and 6 remained stuck in a starting state with the error
<span class="ph systemoutput"
>Signal detected for port xeS5-DP0 but Link Down</span
>
alerts, which resulted in device instability.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-299705</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where API calls to commit changes on Panorama
intermittently failed when using the XML API with refresh=no, which
caused changes to not be applied to the partial-commit configuration.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-299495</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput"
>show system setting ssl-decrypt certificate</span
>
CLI command did not display certificates when XML output was enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-298945</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where OSCP HTTP POST requests were not formatted
correctly, which caused failures with strict responders.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-298617</b></div>
</td>
<td class="entry relcol">
<div class="p">
Optimized the commit workflow to reduce the size of the effective
configuration, resulting in lower memory consumption.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-296694</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process repeatedly restarting during an IP-port data type writes to
the redis from multiple sources such as TSA or XML in a scale
environment.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-295803</b></div>
</td>
<td class="entry relcol">
<div class="p">
Addressed a memory leak issue under sc3 and automatic commit recovery
(ACR) code path.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-295802</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory leak related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process occurred.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-296202</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/active HA configurations only</tt
>) Added a log enhancement to capture an issue where, when a commit
operation was in progress, newly deployed IP address tags that used
the XML API were not immediately reflected in address group
resolution, which delayed IP address mapping to address groups and
caused traffic to be incorrectly allowed or denied.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-294379</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when all interfaces configured for SD-WAN SaaS
Application path monitoring failed, the firewall stopped forwarding
traffic even if the ISP links and default gateway probing were still
active.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-292306</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>authd</a
>
process stopped handling RADIUS authentication requests and required a
restart.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291094</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue the firewall experienced packet descriptor on chip and
buffer spikes, which led to dropped traffic due to an unidentified
traffic pattern.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-290938</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where multiple memory leaks occurred related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-288175</b></div>
</td>
<td class="entry relcol">
<div class="p">
Addressed a stack buffer overflow memory leak under plugin management
code path.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-287392</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed the issue on the web interface where
<span class="ph uicontrol">ACC</span> graphs displayed
<span class="ph uicontrol">No data to display</span> when a filter was
applied to <span class="ph uicontrol">Source IP</span> or
<span class="ph uicontrol">Destination IP</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-287159</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where file uploads to Dropbox stalled when using a
PA-CPT device with MLC2 and DLP Mirror mode enabled for HTTP2 traffic.
This occurred because the proxy was unable to decrement packet counts
properly when the queue was large, resulting in a receive window size
of 0 for the parent session.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-283237</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic logs incorrectly displayed the action as
<span class="ph uicontrol">allow</span> for traffic matching a
Security policy rule configured with the action set to
<span class="ph uicontrol">deny</span>. This issue occurred due to the
child session being used for policy rule lookup when a configuration
update triggered a rematch if the FTP-data application was not in the
rule.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279364</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls with multiple NICs only</tt>)
Fixed an issue were the queue count in the task dump displayed an
incorrect number of queues for SR-IOV interfaces due to the queue
mapping logic incorrectly using a non-multi-NIC function.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-279209</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where changes made to the management interface
permitted IP address list in a global template were not pushed to the
template stack or firewalls.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-278688</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DNS Security threat logs were not displayed on
the firewall when packet capture was enabled and the domain name
length was 62 characters.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-278628</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process restarted during a configuration push from Panorama, which
caused the active firewall to lose management access for 20-30
minutes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-277987</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls in AWS environments only</tt>)
Fixed an issue where HA failover mode incorrectly changed from
<span class="ph uicontrol">interface move</span> to
<span class="ph uicontrol">secondary IP move</span> after a reboot.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-274742</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the <span class="ph systemoutput">task-queue dump</span> CLI command
returned incorrect information in multi-nic mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273487</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>distributord</a
>
process restarted on firewalls in multi-vsys environments with User-ID
configured and Panorama as a redistribution client. This occurred when
a large volume of IP address-to-user mappings were learned.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273158</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7000 Series firewalls only</tt>) Fixed an issue
where an incorrect ASIC configuration caused silent packet drops or
application slowness when receiving a mix of jumbo and non-jumbo
packets.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-262353</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when Panorama was upgraded but log collectors
were on an earlier version, logs from a log collector group were not
viewable on a Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259785</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
process restarted and created a core dump because two threads did not
terminate correctly.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-245686</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where memory leaks occurred when checking for,
downloading, or installing dynamic updates.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-243507</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall web interface where
<span class="ph uicontrol">Logical Router</span> did not load after an
Advanced Routing Engine stack upgrade.
</div>
</td>
</tr>
</tbody>
</table>
File diff suppressed because it is too large Load Diff
+464
View File
@@ -0,0 +1,464 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300906</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where XML API commands failed with a
<span class="ph systemoutput">Method not found (policy_xml)</span>
error in dagger.log. The issue was due to missing XML-related
functions for inline-cloud-proxy and session-distribution commands in
dagger files handling.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300096</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a local commit on a firewall breaks template
stack overrides, preventing the enabling of LACP (Link Aggregation
Control Protocol). After a local commit, the LACP enable check was
unexpectedly unchecked, causing an outage. Attempting to re-enable
LACP through the web interface was unsuccessful, requiring manual
removal of the LACP configuration from the Panorama CLI.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-299785</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7500 and PA-5450 firewalls in FIPS-CC mode</tt>)
Fixed an issue where the affected firewalls would boot into
maintenance mode when a reboot was initiated from the web interface.
This was due to a device reboot triggering a power down to all slots,
leading to maintenance mode. A hard reboot would allow the firewall to
boot normally.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297972</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a dataplane crash occurred when traffic matched
Inline Cloud Analysis pre-filtering signatures, even when Inline Cloud
Analysis features were not enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297240</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where attempting to generate reports in a WildFire FIPS
Private Cloud or WF-500 deployment returned 401 errors.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-296490</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">FIPS CC mode enabled only</tt>) Fixed an issue
where Panorama on GCP reboots every hour after upgrading to
11.1.6-h10. Panorama will run for up to an hour and then crash.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-296453</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where decryption exclusion lists were not working for
untrusted certificates, and SSL sessions were still being decrypted
even after adding them to the exclusion list. This occurred because
the firewall was not adding sessions to the exclude cache until after
receiving a non-RFC alert (BadCertificate) from the server. The fix
ensures that the first session is added to the exclude cache, allowing
subsequent sessions to skip decryption. This issue affects firewalls
configured as clients in server-client communication.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-295944</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where static routes remained active in the FIB and RIB
even when the associated physical port interface was down, which
resulted in traffic being incorrectly routed through a non-operational
interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-295560</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading Panorama and Log Collectors,
tunnel logs were not visible in Panorama or Splunk even though traffic
and threat logs were received.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-295257</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after onboarding a firewall to Panorama, IPsec
tunnels displayed IKEv2 in Panorama, even though the tunnels were
configured with IKEv1 locally on the firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-294893</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls with the
<span class="ph uicontrol"
>Send handshake messages to CTD for inspection</span
>
setting enabled caused incorrect security policy rules to be matched.
Specifically, traffic not identified as openai-base or openai-chatgpt
applications was incorrectly matched by the
ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected
response page for blocked URLs was not displayed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-294770</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in active/passive HA configurations</tt>)
Fixed an issue on firewalls where, after failover, certain subnets
were missing from the Link State Database, which prevented OSPF routes
from being immediately learned due to a Type-7 to Type-5 LSA
translation conflict in the ABR when the same LSA was advertised by
two peers in the NSSA area.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-294524</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls and Panorama management servers were
unable to view or download WildFire reports from a WF-500 appliance,
resulting in a 401 error in the report tab.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-292393</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TFTP file transfers intermittently timed out in
active-active HA pairs when the TFTP control channel was processed by
one firewall and the data channel was processed by the other. This
occurred because the firewall receiving the data channel failed to
match the predicted session due to asynchronous processing of HA
messages.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291716</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where PA-460 firewalls experienced out-of-memory (OOM)
conditions, leading to device crashes and reboots.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291288</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted unexpectedly due to a
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process restart related to page allocation failures.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-290453</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7500 firewalls only</tt>) Fixed an issue where
PA-7500 firewalls experienced silent traffic drops. During migration
from PA-7050 to PA-7500 firewalls connected in series, intermittent
connection losses occurred for some applications. Traffic leaving the
PA-7050 was not received or processed by the PA-7500, even with direct
connections and replaced cables/SFPs. Global counters did not indicate
any drops on the PA-7500.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-289249</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory leak occurred on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process when a WildFire update was initiated while device telemetry
data collection was in progress. This resulted in an OOM condition.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287803</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading firewalls to PAN-OS 11.1.6-h1,
certain websites weren't accessible when the accumulation proxy was
enabled. The proxy did not use the same DF bit state as the original
traffic, causing it to be fragmented and dropped elsewhere in the
network.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287782</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls configured in vwire mode modified DSCP
values from AF11 to CS0 on traffic passing through the firewall, even
when QoS policy rules and DSCP rewrite settings were not configured.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287622</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IPv6 traffic was affected after upgrading the
firewall to PAN-OS 11.1.6-h4 and later versions. With SSL decryption
enabled and a decryption policy configured for the traffic, the
firewall dropped packets due to receiving a
<span class="ph systemoutput">Packet Too Big</span> ICMP message. This
occurred because the PathMTU information update was incorrect for the
TCB (pan-server) when the firewall was acting as a server.
Additionally, the flow label under the IPv6 header was set to zero
while the packet was being transmitted out of the firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287423</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where content loading issues occurred on IPv6 websites
due to the firewall incorrectly setting the IPv6 header flow label to
0.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-285648</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the log receiver process crashed on PA-7050
firewalls due to system log processing threads becoming blocked when
the queue was full. This resulted in a heartbeat failure.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-283053</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall experienced high disk space
utilization, which caused the firewall to become non-functional.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-278322</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Amazon Web Services (AWS) Gateway Load
Balancer (GWLB) deployments only</tt
>) Fixed an issue where the firewall did not display the correct
source user in traffic logs and session details.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-277034</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where WildFire reports were not fully displayed and
were not downloadable due to static resources not being found.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267450</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reported</a
>
process stopped responding with a SIGSEGV at
<span class="ph systemoutput">schedule_report_es_response</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260185</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a dataplane crash occurred in Inline Cloud
Analysis action lookup because there were no vulnerability or
antispyware profiles in the security policy rule.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-253963</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Panorama appliances in Panorama mode and Log Collector mode
only</tt
>) Fixed an issue where autocommits took longer than expected to
complete.
</div>
</td>
</tr>
</tbody>
</table>
File diff suppressed because it is too large Load Diff
@@ -0,0 +1,34 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297295</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls in Microsoft Azure environments only</tt
>) Fixed an issue where the firewall repeatedly restarted due to high
packet rates on the synthetic path in DPDK mode.
</div>
</td>
</tr>
</tbody>
</table>
+526
View File
@@ -0,0 +1,526 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-288693</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where importing a device configuration into Panorama
failed with a validation error if the configuration included a shared
gateway with shared address objects.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-286897</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process stopped responding when the firewall attempted to forward
files to the WildFire public cloud, which caused the dataplane to
experience heartbeat failures.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-286475</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the option to sort sequence numbers was missing
from <span class="ph uicontrol">Filters prefix list</span> in the
advanced routing filters.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-285590</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Amazon Web Services (AWS) GWLB environments
only</tt
>) Fixed an issue where the firewall CPU usage reached 100% after
upgrading to PAN-OS 11.1.6-h1.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-284840</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5220 firewalls only</tt>) Fixed an issue where
custom reports were delayed when sent via email instead of being sent
at the scheduled time.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-284116</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where mTLS decryption bypass did not work when the
decryption profile was configured with the maximum TLS version as TLS
1.3.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-284066</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after an upgrade, the SNMP polled values for
<span class="ph systemoutput">IF-MIB::ifInErrors</span> displayed a
high number of errors that did not match the values in the CLI show
interface command.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-283789</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in high availability (HA) configurations only</tt
>) Fixed an issue where, after an upgrade, the
<span class="ph uicontrol">mac receive error</span> counter in
<span class="ph uicontrol">receive incoming errors</span> increased,
which resulted in SNMP alerts.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-283467</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-3400 Series firewalls only</tt>) Fixed an issue
where the firewall unexpectedly rebooted and entered maintenance mode
due to a ctd-agent out-of-memory (OOM) condition. This occurred during
advanced services load testing and a high volume of IoT EAL log
forwarding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-283331</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where selective pushes to managed devices failed when
the <span class="ph uicontrol">User ID Master Device</span> was
configured.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-282640</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where custom reports showed incomplete data when
exported in CSV format from Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-281776</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where the error message
<span class="ph uicontrol"
>PPPoEv6 Client Interface cannot be enabled with DHCPv6 client</span
>
was generated when overriding aggregate interfaces even when no DHCPv6
or PPPoE was configured.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-280698</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall removed the TCP timestamp from
client hello messages that did not fit in a single packet, which
resulted in connection issues.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-280532</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after disabling and re-enabling the external
syslog server, the TCP session was not resumed, which caused all logs
that were forwarded to the syslog server to be dropped.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-280335</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with an SNMPv3 EngineBoots value discrepancy that
prevented to SNMP server from logging.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-278981</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DNS domain resolutions experienced intermittent
delays due to the firewall not connecting to the DNS Security cloud.
</div>
<div class="p">
To use this fix, enable DNS monitoring on the dataplane via the CLI
command
<span class="ph systemoutput"
>debug dnsproxyd enable-rtsig-health-monitor yes</span
>.
</div>
<div class="p">
To show the current setting, run the CLI command
<span class="ph systemoutput"
>debug dnsproxyd enable-rtsig-health-monitor show</span
>. If the
<span class="ph systemoutput"
>cfg.general.dns-rtsig-monitor-interval</span
>
shows a non-zero value, DNS monitoring is enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-276276</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-450 firewalls only</tt>) Fixed an issue where,
after an upgrade, data that was excluded using the query builder in a
custom report was still visible in the report, and the logs displayed
errors related to invalid threat names being queried.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-275601</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when Panorama was not internet connected and you
attempted to upload images to managed firewalls using the
<span class="ph uicontrol">Validate</span> option, the upload failed
with the error
<span class="ph uicontrol"
>Failed to create multi-upload job. No valid software deploy targets
found</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-274806</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5250 firewalls only</tt>) Fixed an issue where
IPv6 pings experienced a high number of dropped packets when forwarded
to another dataplane, which resulted in ping failures. This occurred
when initiating a ping to the link local address of the firewall and
the packet drop percentage depended on the number of dataplanes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-274496</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the root partition reached 100% which caused the
system to become non-functional and fail over even when aggressive
cleaning was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-272812</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SNMP monitoring of tunnel interfaces displayed
zero values for received bytes and packets.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-271560</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DNS requests to malware sites were not blocked as
expected, and the
<span class="ph systemoutput">dns-security-categories log-level</span>
and action displayed default values instead of
<span class="ph systemoutput">unavailable</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271215</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-4230"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-4230</a
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-270379</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where socket files created in the /tmp directory were
not cleared.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-269155</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an OOM condition occurred, which caused processes
to stop responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-269139</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls with DPDK enabled in Azure, GCP, AWS, and KVM
environments only</tt
>) Fixed an issue where, after an upgrade to PAN-OS 11.1.4, the
<span class="ph uicontrol">mac receive error</span> counter increased
without an error even though traffic was not impacted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-268922</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-3220 firewalls in HA configurations only</tt>)
Fixed an intermittent issue where the firewalls went out of sync after
a configuration push from Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-268680</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding when a configuration merge operation
changed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-268032</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where importing a device configuration into Panorama
failed with a validation error if the configuration included a shared
gateways containing NAT/PBF rules.
</div>
<div class="p">To use this fix:</div>
<ol class="ol">
<li class="li">
Enable the configuration. Commit failures may occur if the device is
not able to support the number of objects.
</li>
<li class="li">Export and push the device group only.</li>
<li class="li">Push the template.</li>
</ol>
<div class="p">
Note: This fix is supported on PAN-OS 10.2 and later releases.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-264982</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Kernel-based Virtual Machine (KVM) only</tt
>) Fixed an issue where the firewall entered maintenance mode after an
auto-commit when sending an ARP packet through the loopback interface
using an IPv6 address.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263504</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where exporting managed device information from
Panorama in CSV format included extraneous characters.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260661</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where daily email reports generated from the custom
report did not display the report details in PDF or CSV files.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-209516</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when creating an interface, an error occurred
when you clicked <span class="ph uicontrol">OK</span> without
providing a value in the <span class="ph uicontrol">Tag</span> field
even though the field was not displayed as mandatory.
</div>
</td>
</tr>
</tbody>
</table>
File diff suppressed because it is too large Load Diff
+650
View File
@@ -0,0 +1,650 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-303737</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where XML API commands failed with a
<span class="ph systemoutput">Method not found (policy_xml)</span>
error in dagger.log. The issue was due to session-distribution
commands in dagger files handling.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-300916</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama management servers failed to forward
syslog messages via TLS to a syslog server when DNS resolution for
IPv6 addresses failed, and the system did not automatically fall back
to IPv4.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-300906</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where XML API commands failed with a
<span class="ph systemoutput">Method not found (policy_xml)</span>
error in dagger.log. The issue was due to missing XML-related
functions for inline-cloud-proxy.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-300837</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls experienced multiple reboots due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process restarting with a SIGSEGV signal. This occurred because the
client-to-firewall side assumed TLS 1.3 for the firewall-server side.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-300612</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7500 firewalls only</tt>) Fixed an issue where
the firewall incorrectly reported the speed of 400G interfaces as 1G
when queried using SNMP
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-300096</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a local commit on a firewall breaks template
stack overrides, preventing the enabling of LACP (Link Aggregation
Control Protocol). After a local commit, the LACP enable check was
unexpectedly unchecked, causing an outage. Attempting to re-enable
LACP through the web interface was unsuccessful, requiring manual
removal of the LACP configuration from the Panorama CLI.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-299815</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on multi-vsys firewalls where a host was not removed
from the quarantine list after receiving a redistribution message from
Panorama. This occurred when Panorama was configured to redistribute
quarantine messages to a firewall cluster, and the GlobalProtect
configuration and redistribution were built out in a vsys other than
vsys1.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-299785</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7500 and PA-5450 firewalls in FIPS-CC mode</tt>)
Fixed an issue where the affected firewalls would boot into
maintenance mode when a reboot was initiated from the web interface.
This was due to a device reboot triggering a power down to all slots,
leading to maintenance mode. A hard reboot would allow the firewall to
boot normally.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-299772</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls in active/passive configurations only</tt
>) Fixed an issue where, after an HA failover event, the newly active
firewall DHCP client interfaces failed to obtain IP addresses
automatically. This occurred because the DHCP client processes did not
initiate the necessary DHCP discover or renew requests
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-298872</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-400 Series firewalls in HA configurations only</tt
>) Fixed an issue where ports went down after an HA failover.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-298654</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall generated false positive threat logs
during updates to a large domain list (EDL) when a DNS lookup for a
domain being added or removed occurred during the update process. This
resulted in a threat log being generated for a different, unrelated
domain that remained on the list.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-298505</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading an HA pair of PA-7050 firewalls,
the vsys ID changed in sequence, causing autocommit failures with
validation errors. This occurred when the multi-vsys firewall had
virtual systems created and pushed from Panorama, and the vsys ID was
not in a correct sequence because the unused vsys was deleted from
Panorama and pushed to devices.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-297972</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a dataplane crash occurred when traffic matched
Inline Cloud Analysis prefiltering signatures, even when Inline Cloud
Analysis features were not enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-297797</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, during a refresh of a large External Dynamic
List (EDL), traffic that matched a domain on the list was incorrectly
identified as a different domain, which resulted in false positive
threat logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-297759</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on PA-7500 firewalls running in a cluster where
sub-interfaces were not discoverable via SNMP, which prevented proper
monitoring and statistics collection for sub-interfaces using
SNMP-based tools.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-297708</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a long-lived session with many Machine Learning
(ML) model triggers caused a memory leak of feature states associated
with the ML model runs. This resulted in Spyware_State failure
increases, allocation max outs, and impaired policy matching.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-297610</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall became unresponsive after an upgrade
due to the <span class="ph systemoutput">fsck</span> command scanning
drive partitions in parallel with the root partition, which caused the
process to take an extended amount of time.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-296490</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">FIPS CC mode enabled only</tt>) Fixed an issue
where Panorama on GCP rebooted every hour after upgrading to
11.1.6-h10. Panorama will run for up to an hour and then crash.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-296453</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where decryption exclusion lists were not working for
untrusted certificates, and SSL sessions were still being decrypted
even after adding them to the exclusion list. This occurred because
the firewall was not adding sessions to the exclude cache until after
receiving a non-RFC alert (BadCertificate) from the server. The fix
ensures that the first session is added to the exclude cache, allowing
subsequent sessions to skip decryption. This issue affects firewalls
configured as clients in server-client communication.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-295221</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading Panorama and Log Collectors from
PAN-OS 10.2.9 to PAN-OS 11.1.6-h6, Traffic and Threat logs were not
forwarded to a Splunk server over UDP.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-294893</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls with the
<span class="ph uicontrol"
>Send handshake messages to CTD for inspection</span
>
setting enabled caused incorrect Security policy rules to be matched.
Specifically, traffic not identified as openai-base or openai-chatgpt
applications was incorrectly matched by the
ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected
response page for blocked URLs was not displayed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-293848</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama failed to push the default value of
<span class="ph uicontrol">None</span> for the secondary NTP server
address to managed firewalls, resulting in a commit validation error.
This occurred even when configuring the secondary NTP server address
as <span class="ph uicontrol">None</span> in Panorama's web interface,
and affected both newly deployed and long-standing production
firewalls after upgrading.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-292447</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not display data in the
<span class="ph uicontrol">Feature Adoption</span> tab in Strata Cloud
Manager due to the system creating and deleting a CLI user for each
interval instead of reusing a permanent CLI user for telemetry.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-292393</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TFTP file transfers intermittently timed out in
active-active HA pairs when the TFTP control channel was processed by
one firewall and the data channel was processed by the other. This
occurred because the firewall receiving the data channel failed to
match the predicted session due to asynchronous processing of HA
messages.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-291716</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where PA-460 firewalls experienced out-of-memory (OOM)
conditions, leading to device crashes and reboots.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-291174</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Real Time Streaming Protocol (RTSP) video streams
did not work when connected through GlobalProtect due to the firewall
blocking 200 OK responses. This occurred because of incorrect NAT
translations for the 200 OK message from the server.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-291067</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
process periodically exceeded its virtual memory limit and restarted,
which led to intermittent outages.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-290453</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where PA-7500 firewalls experienced silent traffic
drops. During migration from PA-7050 to PA-7500 firewalls connected in
series, intermittent connection losses occurred for some applications.
Traffic leaving the PA-7050 was not received or processed by the
PA-7500, even with direct connections and replaced cables/SFPs. Global
counters did not indicate any drops on the PA-7500.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-289714</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Prisma Access only</tt>) Fixed an issue where
persistent commit failures occurred due to a missing transformation
script when downgrading from PAN-OS 10.2.0 to PAN-OS 10.1.0.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-288388</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after an EDL certificate update or repository
migration, authentication failures caused the firewall to not fall
back to the last successfully cached EDL entries, which led to policy
rules that referenced the EDL to not be enforced.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-287803</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading firewalls to PAN-OS 11.1.6-h1,
certain websites weren't accessible when the accumulation proxy was
enabled. The proxy did not use the same DF bit state as the original
traffic, causing it to be fragmented and dropped elsewhere in the
network.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-287693</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not use the configured proxy
settings to check WildFire private cloud content and instead connected
directly to the WildFire device using the management interface. This
occurred even when
<span class="ph uicontrol">Use Proxy Settings for Private Cloud</span>
was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-287622</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IPv6 traffic was affected after upgrading the
firewall to PAN-OS 11.1.6-h4 and later versions. With SSL decryption
enabled and a decryption policy configured for the traffic, the
firewall dropped packets due to receiving a
<span class="ph systemoutput">Packet Too Big</span> ICMP message. This
occurred because the PathMTU information update was incorrect for the
TCB (pan-server) when the firewall was acting as a server.
Additionally, the flow label under the IPv6 header was set to zero
while the packet was being transmitted out of the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-285648</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the log receiver process crashed on PA-7050
firewalls due to system log processing threads becoming blocked when
the queue was full. This resulted in a heartbeat failure.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-285315</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the log forwarding queue depth was
not accurately displayed in the logd.log files.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-285169</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where Kerberos superusers were unable to
edit policy rules because the target device tab was grayed out.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-272245</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>dnsproxy</a
>
process crashed due to memory corruption caused by a race condition
when the allow list downloading was impacted by config change.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-267704</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not send an ICMP error packet to
Envoy when the MSS was exceeded.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-267450</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process stopped responding with a SIGSEGV at
<span class="ph systemoutput">schedule_report_es_response</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262444</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not refresh the external dynamic
list due to the first entry in the list being removed from the global
external list and breaking out of the loop.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-251646</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where commits failed with the error message
<span class="ph systemoutput"
>Error: Error unserializing profile objects</span
>. This occurred due to memory allocation issues when a large number
of scan profiles were configured.
</div>
</td>
</tr>
</tbody>
</table>
+746
View File
@@ -0,0 +1,746 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-309392</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the scroll bar did not appear when editing
<span class="ph uicontrol">Destination Addresses</span> for Policy
Based forwarding policy rules.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-309379</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process stopped responding on DPCs, which prevented logs from being
forwarded.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-308085</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls in Microsoft Azure environments only</tt
>) Fixed an issue where, after resizing the VM, the HA2 link became
unstable. Frequent keep-alive failures occurred, and HA2 keep-alive
packets were simultaneously transmitted to multiple destination MAC
addresses and the peer firewall's interface MAC). This issue occurred
on firewalls with Accelerated Networking enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-308060</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/active HA configurations only</tt
>) Fixed an issue where the BFD session went down and did not recover
even though the BGP remained in an established state, which caused the
firewall to cease route learning and advertisement with the peer, even
though BGP keep-alives were exchanged correctly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-307901</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a leak in decryption counters caused resource
exhaustion, which led to a GlobalProtect service outage.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-307795</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama incorrectly generated system logs
indicating a lost connection to its peer after an upgrade even when
High Availability was not configured.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-305835</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls with Memory Integrity Checking
Architecture enabled rebooted unexpectedly due to accessing an invalid
memory address. This occurred because the forwarding data structure
index exceeded its designed limit.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-305412</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Logging Service License Status displays a
license failure when the license status transitions from valid to
expired and then back to valid even when the connection to the
Security Logging Service (SLS) was working.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-305411</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after creating a logical interface with an
assigned IP address and adding it to a virtual router, the connected
route for the interface did not appear in the
<span class="ph systemoutput">show routing route</span> CLI command
output. This occurred even when the interface was up and learning ARP
entries.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-305301</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the timing of GlobalProtect lifetime expiry or
inactivity logout notifications used for GlobalProtect SSL tunnels
could cause the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process to stop responding and the dataplane to restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-304756</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where, after you disabled the shared
optimization feature, a full configuration push to multi-vsys devices
caused a validation error.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-304636</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where BGP aggregate routes were not created and discard
routes were not installed in the routing table.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-304075</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not detect evasions due to TCP
checksum offloading not being enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-303959</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic was incorrectly identified as
unknown-tcp/unknown-udp due to App-ID resource leak and eventually
dropped.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-303954</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when configuring Safenet HSMs in HA and
authentication HSM manually, the second HSM server failed to
authenticate due to the firewall overwriting the first HSM server's
certificate with the second HSM server's certificate.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-303627</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after committing a configuration change, the
firewall experienced traffic issues,
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
crashes, and LACP interface failures.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-303559</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after manually creating a device telemetry
bundle, the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>hour_cli_output.txt</a
>
file within the bundle had a file size of 0 bytes. This occurred when
checking the bundle content after enabling device telemetry and
setting the device telemetry upload endpoint.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-302983</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after committing changes on Panorama, a shared
post-rule moved to the end of the
<span class="ph systemoutput">post shared rulebase</span> on the
managed device instead of remaining at the top.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-302551</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall displayed as disconnected in the SLS
due to the serial number not being retrieved
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-302428</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where daily scheduled report emails for
custom reports were delivered with no content and instead incorrectly
displayed the message
<span class="ph uicontrol">No matching data found</span>. With this
fix, the content is displayed correctly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-302085</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where network values were not displayed in Panorama
with the error message
<span class="ph uicontrol"
>There is no value for the selected item</span
>. This was due to the device group passing vsysName in Panorama.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-301975</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
issue where the passive firewall incorrectly triggered PBP alerts even
with low packet rates.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-301937</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Microsoft Defender for Cloud detected cleartext
SSH private keys in the /var/appweb and /etc/appweb directories on
PA-VM firewalls deployed in Azure.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-301912</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama stopped responding when deploying
dynamic updates to managed devices.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-301600</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where, after upgrading Panorama, OSPF
adjacencies remained in the exchange start state, which resulted in an
incomplete routing table.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-301456</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the
<span class="ph systemoutput">debug system reset-ztp</span> CLI
command was unavailable.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-301409</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama failed to perform a selective push to a
managed device when device tags were added or modified on the policy
rules. The selective push failed with the error message
<span class="ph systemoutput"
>Failed to generate selective push configuration. Schema validation
failed. Please try a full push</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300837</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls experienced multiple reboots due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process restarting with a SIGSEGV signal. This occurred because the
client-to-firewall side assumed TLS 1.3 for the firewall-server side.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300671</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic reports that were generated with
destination/source and destination/source hostnames were not displayed
in IPv4 format.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-299751</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to connect to the
Subscription License Service (SLS) due to a public and private key
pair mismatch with the device certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-299622</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the MFA timestamp was not redistributed between
standalone firewalls behind an Azure load balancer after upgrading,
which resulted in users being prompted to reauthenticate multiple
times.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297263</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5220 firewalls only</tt>) Fixed an issue where
the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>ikemgr</a
>
process stopped responding intermittently, which caused IPSec tunnels
to go down randomly. With this fix, the IKE Security association data
structures are accessed in a thread-safe manner, and the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>ikemgr</a
>
process does not reference an invalid memory pointer during teardown
operations.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-299622</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the MFA timestamp was not redistributed between
standalone firewalls behind an Azure load balancer after upgrading,
which resulted in users being prompted to reauthenticate multiple
times.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-295796</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall intermittently failed to forward
VXLAN GARP packets, which led to connectivity issues for wireless
clients in environments that used VXLAN tunnels for wireless access
points.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-292447</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not display data in the
<span class="ph uicontrol">Feature Adoption</span> tab in Strata Cloud
Manager due to the system creating and deleting a CLI user for each
interval instead of reusing a permanent CLI user for telemetry.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-291945</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on PA-5220 firewalls where denied traffic logs
incorrectly displayed a byte count of 0. This occurred because the
bytes_sent value was stored in the most significant bits of
u_bytes_sent, resulting in a zero value when a small value was
assigned to u_bytes_sent.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-285208</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not automatically recover after
a machine check exception (MCE) occurred.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-283237</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic logs incorrectly displayed the action as
<span class="ph uicontrol">allow</span> for traffic matching a
Security policy rule configured with the action set to
<span class="ph uicontrol">deny</span>. This issue occurred due to the
child session being used for policy rule lookup when a configuration
update triggered a rematch if the FTP-data application was not in the
rule.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-281588</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where packet buffer depletion occurred due to the a
high number of
<span class="ph systemoutput">tcp_pkt_queued</span> packets when Jumbo
was enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269535</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the mib ID returned an incorrect value via SNMP.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263691</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted unexpectedly due to a
memory leak in the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262831</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5400f Series firewalls only</tt>) Fixed an
intermittent issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding, which caused the firewall to restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-241694</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where memory leaks related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
process occurred when downloading and pushing updates from the App-ID
Cloud Engine to the dataplane.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-185731</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to parse the URL path and
host when the host header was located in a different packet, which
resulted in the firewall not logging the URL path in the first packet.
The fix is disabled by default. The following CLI commands can be used
to enable/disable the feature:
<ul id="panos-addressed-issues-11.1.13-h1_ul-fmq_kc3_yhc" class="ul">
<li class="li">
<span class="ph systemoutput"
>set system setting ctd url-crosspkt-host-path-caching
enable</span
>
</li>
<li class="li">
<span class="ph systemoutput"
>set system setting ctd url-crosspkt-host-path-caching
disable</span
>
</li>
<li class="li">
<span class="ph systemoutput"
>set system setting ctd url-crosspkt-host-path-caching
default</span
>
</li>
</ul>
</div>
</td>
</tr>
</tbody>
</table>
+630
View File
@@ -0,0 +1,630 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-314319</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall experienced increased packet drops
and slower performance after an upgrade due to high burst traffic.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"></b></div>
</td>
<td class="entry relcol">
<div class="p"></div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-313572</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the dataplane restarted due to a segmentation fault.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-312706</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewalls restarted due to a function lacking
a NULL-pointer sanity check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-311524</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where config-lock was not displayed on the web
interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-311250</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances and Log Collectors only</tt>)
Fixed an issue where logs from multiple devices were not visible on
Panorama even though the Elasticsearch health status on the dedicated
Log Collectors appeared green.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-311073</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Panorama managed firewalls in HA configurations only</tt
>) Fixed an issue where firewalls incorrectly updated the modified
date and MD5 hash of policy rules during an HA sync commit job or a
subsequent local commit, even when no changes were made to the policy
rules.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-308786</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue where
traffic log queries using the
<span class="ph systemoutput">device_name</span> filter returned no
results, and, additionally complex log queries that included negation
operators produced incorrect outputs.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-308654</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Elasticsearch Close Indices process closed
more indices than expected and dropped the number of open shards below
the minimum of 800 per Elasticsearch instance. This occurred because
the process did not correctly account for the number of Elasticsearch
instances when calculating the maximum number of allowed open shards.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-307702</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
issue where traffic passing through AE layer 2 interfaces was
interrupted during HA failovers.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-307597</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where BGP peering sessions between a hub firewall and a
satellite firewall over GlobalProtect LSVPN failed to connect.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-306555</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding, which led to
service outages.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-306451</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls on AWS environments only</tt>)
Fixed an issue where, after upgrading the firewall to an affected
release, GlobalProtect clients did not connect with IPSec and instead
connected using SSL due to traffic flow being disabled when checking
for health check packets.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-305700</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a reboot loop occurred when OSPF interfaces were
configued with a link type of
<span class="ph uicontrol">point-to-point</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-305552</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DLP logs displayed an incorrect file type when
the firewall did not set the file type field.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-304746</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Panorama appliances and Panorama virtual appliances only</tt
>) Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process restarted when committing and pushing configuration for a new
WildFire cluster.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-304718</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where OSPF and BGP outages occurred due to an
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process restart during clientless VPN content rewrite processing.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-304696</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Cloud User-ID connection timed out because
the firewall took too long to process the OCSP response.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-304576</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall entered a non-functional state due
to segmentation fault within the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process that was caused by a session that involved http2 cleartext
traffic
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-303745</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where inter-dataplane forwarding did not work for
sessions ingressing on Slot 2, which resulted in intermittent ping
failures to interfaces on Network Card 2 when traffic was forwarded to
Slot 3. Note: With this fix, after a slot restart, the global counter
will still show dot1q errors for a short period.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-303722</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where configuring spyware and
vulnerability profiles in Security policy rules caused a memory leak
in the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
process with each configuration commit.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-301731</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the firewall was unable to establish an SCM
connection due to the discovery service returning a 404 error when the
device was not yet known to the service, the firewall did not retry
the attempt as expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-300664</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama and firewall web interface where
Applications pages became unresponsive after activating the SaaS
Inline license.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-299705</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where API calls to commit changes on Panorama
intermittently failed when using the XML API with refresh=<span
class="ph systemoutput"
>no</span
>, which caused changes to not be applied to the partial-commit
configuration.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-299495</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput"
>show system setting ssl-decrypt certificate</span
>
CLI command did not display certificates when XML output was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-298945</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where OSCP HTTP POST requests were not formatted
correctly, which caused failures with strict responders.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"> PAN-297540 </b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Panorama managed firewalls in HA configurations only</tt
>) Fixed an issue where the HA-Link-Monitor configuration pushed from
Panorama was converted to a local configuration on the peer device
after an HA sync, which caused subsequent Panorama pushes of link
monitor changes to be flagged as overwritten, and a forced template
push or manual clearing of the configuration on the firewall was
required.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-296694</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process repeatedly restarting during an IP-port data type writes to
the redis from multiple sources such as TSA or XML in a scale
environment.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-295803</b></div>
</td>
<td class="entry relcol">
<div class="p">
Addressed a memory leak issue under sc3 and automatic commit recovery
(ACR) code path.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-295802</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory leak related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process occurred.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-294379</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when SD-WAN SaaS Application path monitoring
failed for all interfaces, the firewall stopped forwarding traffic
even if the ISP links and default gateway probing were still active.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-292306</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>authd</a
>
process stopped handling RADIUS authentication requests and required a
restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-290938</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where multiple memory leaks occurred related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-288175</b></div>
</td>
<td class="entry relcol">
<div class="p">
Addressed a stack buffer overflow memory leak under plugin management
code path.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-287159</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where file uploads to Dropbox stalled when using a
PA-CPT device with MLC2 and DLP Mirror mode enabled for HTTP2 traffic.
This occurred because the proxy was unable to decrement packet counts
properly when the queue was large, resulting in a receive window size
of 0 for the parent session.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279364</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls with multiple NICs only</tt>)
Fixed an issue were the queue count in the task dump displayed an
incorrect number of queues for SR-IOV interfaces due to the queue
mapping logic incorrectly using a non-multi-NIC function.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-278688</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DNS Security threat logs were not displayed on
the firewall when packet capture was enabled and the domain name
length was 62 characters.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-274742</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the <span class="ph systemoutput">task-queue dump</span> CLI command
returned incorrect information in multi-nic mode.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259785</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
process restarted and created a core dump because two threads did not
terminate correctly.
</div>
</td>
</tr>
</tbody>
</table>
+229
View File
@@ -0,0 +1,229 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"> PAN-316911</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Amazon Web Services (AWS) environments
only</tt
>) Fixed an issue where a newly bootstrapped firewall required a
management server restart, relicensing, or license push from Panorama
to invoke the device certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-315176</b></div>
</td>
<td class="entry relcol">
<div class="p">
Added an enable and disable CLI command to address an issue where the
firewall experienced increased packet drops and slower performance
after an upgrade due to high burst traffic.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-314061</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic was disrupted during IPSec rekey
operations due to a 2 second delay in sending the DELETE message for
the previous Security Association (SA) to the peer gateway after a new
SA was negotiated.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-313850</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-1400 Series firewalls in HA configurations only</tt
>) Fixed an issue where a split-brain condition occurred and HA1/HA2
links went down while upgrading when the HA configuration used
dataplane interfaces for HA1 and a combination of HSCI and Ethernet
interfaces for HA2.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-313623</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">/opt/pancfg/mgmt/ssl/private/</span>
directory on Palo Alto Networks devices with TPM support became 100%
utilized due to an accumulation of undeleted
<span class="ph systemoutput">.pub_pem</span> files. This occurred
because executing the
<span class="ph systemoutput">show device-certificate status</span>
CLI command initiated a process that generated these files but failed
to remove them, which prevented the fetching of new device
certificates.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-311285</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in HA conditions only</tt>) Fixed an
issue where a memory leak occurred related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>ospfd</a
>
process, which caused RAM usage to continuously increase on active
devices in an HA cluster until the device stopped responding, even
after an HA failover.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-308507</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama managed firewalls only</tt>) Fixed an
issue where the firewall intermittently failed to maintain active log
forwarding streams to Cortex Data Lake even when duplicate logging and
enhanced application logging were enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-309300</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where management plane system resources configuration
size exceeded 28 MB for over 4 hours, and the following error message
was displayed:
<span class="ph systemoutput"
>Configuration size reaching device capacity limit</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-302654</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/passive HA configurations only</tt
>) Fixed an issue where, when the HA configuration had multiple
logical routers, static or connected routes redistributed into OSPF
aged out in the LSDB, which caused the routes to be removed on peer
OSPF neighbors.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"> PAN-300423</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Data Processing Cards (DPCs) installed in slots 5
and 6 remained stuck in a starting state with the error
<span class="ph uicontrol"
>Signal detected for port xeS5-DP0 but Link Down</span
>
alerts, which resulted in device instability.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-298617</b></div>
</td>
<td class="entry relcol">
<div class="p">
Optimized the commit workflow to reduce the size of the effective
configuration, resulting in lower memory consumption.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-296202</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/active HA configurations only</tt
>) Added a log enhancement to capture an issue where, when a commit
operation was in progress, newly deployed IP address tags that used
the XML API were not immediately reflected in address group
resolution, which delayed IP address mapping to address groups and
caused traffic to be incorrectly allowed or denied.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"> PAN-273158</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7000 Series firewalls only</tt>) Fixed an issue
where an incorrect ASIC configuration caused silent packet drops or
application slowness when receiving a mix of jumbo and non-jumbo
packets.
</div>
</td>
</tr>
</tbody>
</table>