Add some PAN-OS 11.1 references and URLs
This commit is contained in:
@@ -0,0 +1,526 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-288693</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where importing a device configuration into Panorama
|
||||
failed with a validation error if the configuration included a shared
|
||||
gateway with shared address objects.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-286897</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>pan_task</a
|
||||
>
|
||||
process stopped responding when the firewall attempted to forward
|
||||
files to the WildFire public cloud, which caused the dataplane to
|
||||
experience heartbeat failures.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-286475</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the option to sort sequence numbers was missing
|
||||
from <span class="ph uicontrol">Filters prefix list</span> in the
|
||||
advanced routing filters.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-285590</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>VM-Series firewalls on Amazon Web Services (AWS) GWLB environments
|
||||
only</tt
|
||||
>) Fixed an issue where the firewall CPU usage reached 100% after
|
||||
upgrading to PAN-OS 11.1.6-h1.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-284840</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-5220 firewalls only</tt>) Fixed an issue where
|
||||
custom reports were delayed when sent via email instead of being sent
|
||||
at the scheduled time.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-284116</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where mTLS decryption bypass did not work when the
|
||||
decryption profile was configured with the maximum TLS version as TLS
|
||||
1.3.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-284066</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after an upgrade, the SNMP polled values for
|
||||
<span class="ph systemoutput">IF-MIB::ifInErrors</span> displayed a
|
||||
high number of errors that did not match the values in the CLI show
|
||||
interface command.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-283789</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>Firewalls in high availability (HA) configurations only</tt
|
||||
>) Fixed an issue where, after an upgrade, the
|
||||
<span class="ph uicontrol">mac receive error</span> counter in
|
||||
<span class="ph uicontrol">receive incoming errors</span> increased,
|
||||
which resulted in SNMP alerts.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-283467</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-3400 Series firewalls only</tt>) Fixed an issue
|
||||
where the firewall unexpectedly rebooted and entered maintenance mode
|
||||
due to a ctd-agent out-of-memory (OOM) condition. This occurred during
|
||||
advanced services load testing and a high volume of IoT EAL log
|
||||
forwarding.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-283331</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where selective pushes to managed devices failed when
|
||||
the <span class="ph uicontrol">User ID Master Device</span> was
|
||||
configured.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-282640</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where custom reports showed incomplete data when
|
||||
exported in CSV format from Panorama.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-281776</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the Panorama web interface where the error message
|
||||
<span class="ph uicontrol"
|
||||
>PPPoEv6 Client Interface cannot be enabled with DHCPv6 client</span
|
||||
>
|
||||
was generated when overriding aggregate interfaces even when no DHCPv6
|
||||
or PPPoE was configured.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-280698</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall removed the TCP timestamp from
|
||||
client hello messages that did not fit in a single packet, which
|
||||
resulted in connection issues.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-280532</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after disabling and re-enabling the external
|
||||
syslog server, the TCP session was not resumed, which caused all logs
|
||||
that were forwarded to the syslog server to be dropped.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-280335</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue with an SNMPv3 EngineBoots value discrepancy that
|
||||
prevented to SNMP server from logging.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-278981</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where DNS domain resolutions experienced intermittent
|
||||
delays due to the firewall not connecting to the DNS Security cloud.
|
||||
</div>
|
||||
<div class="p">
|
||||
To use this fix, enable DNS monitoring on the dataplane via the CLI
|
||||
command
|
||||
<span class="ph systemoutput"
|
||||
>debug dnsproxyd enable-rtsig-health-monitor yes</span
|
||||
>.
|
||||
</div>
|
||||
<div class="p">
|
||||
To show the current setting, run the CLI command
|
||||
<span class="ph systemoutput"
|
||||
>debug dnsproxyd enable-rtsig-health-monitor show</span
|
||||
>. If the
|
||||
<span class="ph systemoutput"
|
||||
>cfg.general.dns-rtsig-monitor-interval</span
|
||||
>
|
||||
shows a non-zero value, DNS monitoring is enabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-276276</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-450 firewalls only</tt>) Fixed an issue where,
|
||||
after an upgrade, data that was excluded using the query builder in a
|
||||
custom report was still visible in the report, and the logs displayed
|
||||
errors related to invalid threat names being queried.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-275601</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, when Panorama was not internet connected and you
|
||||
attempted to upload images to managed firewalls using the
|
||||
<span class="ph uicontrol">Validate</span> option, the upload failed
|
||||
with the error
|
||||
<span class="ph uicontrol"
|
||||
>Failed to create multi-upload job. No valid software deploy targets
|
||||
found</span
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-274806</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-5250 firewalls only</tt>) Fixed an issue where
|
||||
IPv6 pings experienced a high number of dropped packets when forwarded
|
||||
to another dataplane, which resulted in ping failures. This occurred
|
||||
when initiating a ping to the link local address of the firewall and
|
||||
the packet drop percentage depended on the number of dataplanes.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-274496</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the root partition reached 100% which caused the
|
||||
system to become non-functional and fail over even when aggressive
|
||||
cleaning was enabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-272812</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where SNMP monitoring of tunnel interfaces displayed
|
||||
zero values for received bytes and packets.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-271560</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where DNS requests to malware sites were not blocked as
|
||||
expected, and the
|
||||
<span class="ph systemoutput">dns-security-categories log-level</span>
|
||||
and action displayed default values instead of
|
||||
<span class="ph systemoutput">unavailable</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-271215</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
A fix was made to address
|
||||
<a
|
||||
class="xref"
|
||||
href="https://security.paloaltonetworks.com/CVE-2025-4230"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>CVE-2025-4230</a
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-270379</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where socket files created in the /tmp directory were
|
||||
not cleared.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-269155</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where an OOM condition occurred, which caused processes
|
||||
to stop responding.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-269139</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>Firewalls with DPDK enabled in Azure, GCP, AWS, and KVM
|
||||
environments only</tt
|
||||
>) Fixed an issue where, after an upgrade to PAN-OS 11.1.4, the
|
||||
<span class="ph uicontrol">mac receive error</span> counter increased
|
||||
without an error even though traffic was not impacted.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-268922</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-3220 firewalls in HA configurations only</tt>)
|
||||
Fixed an intermittent issue where the firewalls went out of sync after
|
||||
a configuration push from Panorama.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-268680</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>configd</a
|
||||
>
|
||||
process stopped responding when a configuration merge operation
|
||||
changed.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-268032</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where importing a device configuration into Panorama
|
||||
failed with a validation error if the configuration included a shared
|
||||
gateways containing NAT/PBF rules.
|
||||
</div>
|
||||
<div class="p">To use this fix:</div>
|
||||
<ol class="ol">
|
||||
<li class="li">
|
||||
Enable the configuration. Commit failures may occur if the device is
|
||||
not able to support the number of objects.
|
||||
</li>
|
||||
<li class="li">Export and push the device group only.</li>
|
||||
<li class="li">Push the template.</li>
|
||||
</ol>
|
||||
<div class="p">
|
||||
Note: This fix is supported on PAN-OS 10.2 and later releases.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-264982</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>VM-Series firewalls on Kernel-based Virtual Machine (KVM) only</tt
|
||||
>) Fixed an issue where the firewall entered maintenance mode after an
|
||||
auto-commit when sending an ARP packet through the loopback interface
|
||||
using an IPv6 address.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-263504</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where exporting managed device information from
|
||||
Panorama in CSV format included extraneous characters.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-260661</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where daily email reports generated from the custom
|
||||
report did not display the report details in PDF or CSV files.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-209516</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, when creating an interface, an error occurred
|
||||
when you clicked <span class="ph uicontrol">OK</span> without
|
||||
providing a value in the <span class="ph uicontrol">Tag</span> field
|
||||
even though the field was not displayed as mandatory.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
Reference in New Issue
Block a user