Add some PAN-OS 11.1 references and URLs
This commit is contained in:
@@ -0,0 +1,988 @@
|
|||||||
|
<table class="table colsep rowsep table-striped">
|
||||||
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||||
|
|
||||||
|
<colgroup>
|
||||||
|
<col style="width: 25%" />
|
||||||
|
<col style="width: 75%" />
|
||||||
|
</colgroup>
|
||||||
|
<thead class="thead">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||||
|
</th>
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Description</b></div>
|
||||||
|
</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
|
||||||
|
<tbody class="tbody">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-241230</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the SNMP get request status value for Panorama
|
||||||
|
connections was incorrect.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-253187</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
|
||||||
|
the class of service (CoS) priority bit was not modified, causing
|
||||||
|
access points to lose connectivity to the wireless controller when
|
||||||
|
traffic was routed through the firewall.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-253778</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>PA-7500 Series firewalls in a cluster configuration only</tt
|
||||||
|
>) Fixed an issue where users were able to enable or disable certain
|
||||||
|
configurations.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-290239</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>PA-455 firewalls in active/passive HA configurations only</tt
|
||||||
|
>) Fixed an issue where, after an upgrade, the TCP session for syslog
|
||||||
|
forwarding did not resume after the syslog server service was disabled
|
||||||
|
and then re-enabled, which caused logs to be dropped. This occurred
|
||||||
|
when the syslog server was down for more than 16 minutes.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-290088</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a memory leak occurred related to the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>configd</a
|
||||||
|
>
|
||||||
|
process when pushing configurations from Panorama to a firewall. This
|
||||||
|
occurred when the configurations contained shared policy rules.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-289304</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-7500 firewalls only</tt>) Fixed an issue where
|
||||||
|
SNMP polling failed due to the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>snmpd</a
|
||||||
|
>
|
||||||
|
process becoming unresponsive to incoming requests, which resulted in
|
||||||
|
high CPU usage.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-289102</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed a race condition issue related to predict processing on
|
||||||
|
multi-core platforms, which resulted in a dataplane restart and
|
||||||
|
traffic loss.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-288930</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where traffic from cloud applications intermittently
|
||||||
|
matched an incorrect
|
||||||
|
<span class="ph uicontrol">cloud-apps</span> policy rule when ACE
|
||||||
|
(App-ID Cloud Engine) was enabled.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-288893</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Firewalls in multi-vsys configurations only</tt>)
|
||||||
|
Fixed an issue where HTTP/2 traffic failed due when one virtual system
|
||||||
|
(vsys) had a decryption policy rule enabled and another vsys had a
|
||||||
|
no-decrypt policy rule for the same session.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-288363</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the MIB ID returned an incorrect value via SNMP.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287838</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue on
|
||||||
|
the web interface where resetting the rule hit counter for multiple
|
||||||
|
policy rules failed with the error message
|
||||||
|
<span class="ph systemoutput">Failed to reset rule-hit job</span>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287818</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where sessions timed out sooner than expected due to
|
||||||
|
the <span class="ph systemoutput">pan_proxy_accumulation_</span>
|
||||||
|
<span class="ph systemoutput">restore_timeout</span> not initiating
|
||||||
|
when the accumulation
|
||||||
|
<span class="ph systemoutput"> session_init</span> failed.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287734</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where
|
||||||
|
<span class="ph uicontrol">Scan ERR: Internal Err 1002</span> messages
|
||||||
|
were unexpectedly generated when WIF shared memory use was high.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287621</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Added debug logs for an issue where a slow IP address pool NAT leak
|
||||||
|
occurred when persistent NAT was enabled, which led to NAT IP pool
|
||||||
|
exhaustion.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287584</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on the web interface where the address object pop up
|
||||||
|
window only displayed a maximum of four address objects in the policy
|
||||||
|
rule even after expanding the window.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287056</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where BGP export policy rules with next-hop matching
|
||||||
|
failed to block the advertisement of static routes, and the firewall
|
||||||
|
incorrectly matched the egress interface IP address instead of the
|
||||||
|
original next-hop IP address of the static route, which caused the
|
||||||
|
deny rule to fail.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287023</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a large number of logs caused the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>logrcvr</a
|
||||||
|
>
|
||||||
|
process to stop responding.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-286857</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where only failed Kerberos authentication events were
|
||||||
|
logged in <span class="ph systemoutput">auth.log</span>, and
|
||||||
|
successful authentication events were not logged.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-286848</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where ECMP incorrectly balanced sessions across links
|
||||||
|
based on the configured metric, which led to an imbalance in traffic
|
||||||
|
distribution and resulted in traffic assignment shifting
|
||||||
|
disproportionately to routes with lower metrics.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-286443</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after an upgrade, the firewall was unable to be
|
||||||
|
managed via HTTPS or SSH.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-286306</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, when getting transceiver information from ESCC
|
||||||
|
for SFP 25G modules, the transceiver code was incorrectly updated with
|
||||||
|
<span class="ph systemoutput">Unknown</span> instead of
|
||||||
|
<span class="ph systemoutput">25GBase-SR</span>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-285894</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>all_task</a
|
||||||
|
>
|
||||||
|
process stopped responding, which caused the firewall to reboot
|
||||||
|
unexpectedly, and traffic failures occurred.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-285818</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a tool was needed to display leaked NAT port
|
||||||
|
numbers without requiring a forced synchronization.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-284908</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where retrieving filenames from OneDrive resulted in a
|
||||||
|
cache miss.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-284067</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>devsrvr</a
|
||||||
|
>
|
||||||
|
process experienced OOM conditions due to the
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>show running application statistics </span
|
||||||
|
>CLI command, which caused the firewall to reboot.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-284003</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where clients did not receive a valid response when
|
||||||
|
when searching a website due to a compression error.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-283979</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall became non-functional due to high
|
||||||
|
root partition use.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-283813</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where the web interface performance was
|
||||||
|
slower than usual when retrieving read-only configurations from
|
||||||
|
Panorama.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-282394</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a firewall was only able to display a maximum of
|
||||||
|
14 permitted IP addresses from a Panorama Template Variable.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-282277</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where an OOM condition on the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>logrcvr</a
|
||||||
|
>
|
||||||
|
process caused interface flapping, and the interface unexpectedly went
|
||||||
|
down and then recovered without intervention.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-281509</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue where
|
||||||
|
log exports were slower than expected or failed when filtering logs
|
||||||
|
after an upgrade, which resulted in timeouts or delays in displaying
|
||||||
|
logs on the web interface.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-280101</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where set and edit commands took longer than expected
|
||||||
|
when adding address objects with a large number of dynamic groups due
|
||||||
|
to the completion cache being enabled. With this fix, the completion
|
||||||
|
cache is disabled by default.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-279706</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">M-600 appliances only</tt>) Fixed an issue where
|
||||||
|
Panorama did not update all
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>panreplay</a
|
||||||
|
>
|
||||||
|
database entries after performing a commit and full push to all
|
||||||
|
devices.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-279500</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where TLS connections failed to establish in asymmetric
|
||||||
|
routing environments if the firewall did not see server-to-client
|
||||||
|
(s2c) packets of the TLS handshake.
|
||||||
|
</div>
|
||||||
|
<div class="p">
|
||||||
|
To use this fix, run the following CLI command:
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>debug dataplane set ssl-decrypt accumulate-client-hello
|
||||||
|
asym-disable yes</span
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-278836</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after an upgrade, GlobalProtect attempted to use
|
||||||
|
the embedded browser instead of the default browser for gateway
|
||||||
|
authentication even when it was configured to use the default browser.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-278812</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where authentication to GlobalProtect failed with the
|
||||||
|
error message
|
||||||
|
<span class="ph systemoutput">User not in allowed list</span>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-278150</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall removed the Authentication Key
|
||||||
|
Identifier (AKID) from the certificate during SSL decryption, which
|
||||||
|
caused Python 3.13 to fail with a certificate verification error.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-277808</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>eproxy</a
|
||||||
|
>
|
||||||
|
process stopped responding when running a long duration test using
|
||||||
|
IXload with hybrid SWG SAML authentication bypass for HTTPS payloads,
|
||||||
|
which caused the proxy to become unreachable.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-277617</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where deleting the NTP server address caused a commit
|
||||||
|
validation error. This occurred when the configuration included both
|
||||||
|
primary and secondary NTP servers and the secondary server was
|
||||||
|
removed.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-277234</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a device group import resulted in a Security
|
||||||
|
policy rule being created with
|
||||||
|
<span class="ph uicontrol">Application</span> set to
|
||||||
|
<span class="ph uicontrol">none</span>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-276920</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where web-advertisement traffic was not immediately
|
||||||
|
blocked which resulted in pages loading indefinitely.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-276678</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Panorama became unresponsive while performing a
|
||||||
|
dynamic address update without a lock.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-275451</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue where
|
||||||
|
sequence numbers were lost when forwarded from Panorama, which
|
||||||
|
resulted in missing or lost logs.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-275133</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where HTTP 503 server errors occurred while browsing
|
||||||
|
websites due to slow Secure Web Gateway (SWG) bypass rule lookup.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-275047</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue
|
||||||
|
where, after an upgrade, the firewall was unable to send logs to the
|
||||||
|
Strata Logging Service (SLS) when using a specific proxy server, and
|
||||||
|
the SSL connection status displayed as failed when attempting to
|
||||||
|
forward logs through the web proxy.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-274797</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a DPC on slot 3 failed intermittently due to the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>pktlog_forwarding</a
|
||||||
|
>
|
||||||
|
process restarting, which resulted in an unexpected HA failover.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-273964</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where SNMP scans to a firewall timed out after
|
||||||
|
upgrading to a PAN-OS 10.2 release.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-272395</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where informational logs caused the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>distributord</a
|
||||||
|
>
|
||||||
|
process log file to be frequently overwritten.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-272175</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where session rematch caused ACE cloud application
|
||||||
|
traffic to match the wrong policy.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-271810</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where auto-negotiation advertised and negotiated 10/100
|
||||||
|
half and full duplex.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-271432</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall was unable to decrypt SSL traffic
|
||||||
|
when using forward proxy and HSM with an ECDSA signing certificate.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-271425</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>Firewalls in active/active HA configurations only</tt
|
||||||
|
>) Fixed an issue with SSL inbound decryption on firewalls on a vwire
|
||||||
|
setup with asymmetric routing.
|
||||||
|
</div>
|
||||||
|
<div class="p">
|
||||||
|
To use this fix, enter the CLI command
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>set system setting ssl-decrypt ha-vwire-mac-learn global yes</span
|
||||||
|
>
|
||||||
|
on both firewalls in an HA pair.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-269700</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where commits to service connection firewalls from
|
||||||
|
Panorama failed.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-269057</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>routed</a
|
||||||
|
>
|
||||||
|
process stopped responding due to accessing freed memory from a hash
|
||||||
|
table when the route vectors were resized. This occurred when a large
|
||||||
|
number of static routes were configured.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-268787</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where users were unable to log in to Panorama and the
|
||||||
|
following error message was displayed:
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>Timed out while getting config lock. Please try again</span
|
||||||
|
>. This occurred when pushing configurations to a large number of
|
||||||
|
devices.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-268313</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the Priority Code Point (PCP) bits in the VLAN
|
||||||
|
header were not reset to 0 when a packet was received from one Layer 3
|
||||||
|
tagged interface and forwarded to another, which resulted in dropped
|
||||||
|
packets.
|
||||||
|
</div>
|
||||||
|
<div class="p">
|
||||||
|
To use this fix, run the CLI command
|
||||||
|
<span class="ph systemoutput">set force-vlan-pcp-reset yes</span> and
|
||||||
|
reboot the firewall.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-267759 </b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Prisma Access gateway downloads were slower than
|
||||||
|
expected.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-267328</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>all_task</a
|
||||||
|
>
|
||||||
|
process stopped responding, which caused the firewall to stop
|
||||||
|
processing traffic.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-264708</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a selective push was blocked when a configuration
|
||||||
|
load was done.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-259727</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Panorama appliances in HA configurations only</tt>)
|
||||||
|
Fixed an issue where Panorama became unresponsive and displayed a 504
|
||||||
|
gateway timeout error when accessing the web interface or the CLI.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-253778</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>PA-7500 Series firewalls in a cluster configuration only</tt
|
||||||
|
>) Fixed an issue where users were able to enable or disable certain
|
||||||
|
configurations.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-253187</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
|
||||||
|
the class of service (CoS) priority bit was not modified, causing
|
||||||
|
access points to lose connectivity to the wireless controller when
|
||||||
|
traffic was routed through the firewall.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-241230</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the SNMP get request status value for Panorama
|
||||||
|
connections was incorrect.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
@@ -0,0 +1,528 @@
|
|||||||
|
<table class="table colsep rowsep table-striped">
|
||||||
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||||
|
|
||||||
|
<colgroup>
|
||||||
|
<col style="width: 25%" />
|
||||||
|
<col style="width: 75%" />
|
||||||
|
</colgroup>
|
||||||
|
<thead class="thead">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||||
|
</th>
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Description</b></div>
|
||||||
|
</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
|
||||||
|
<tbody class="tbody">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-306502</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where TLS connection failure occurred when traffic was
|
||||||
|
over TLS1.2 or below, header insertion was enabled on the firewall,
|
||||||
|
<span class="ph uicontrol">send TLS handshake to CTD</span> was
|
||||||
|
enabled, and traffic hit a decryption policy rule configured with the
|
||||||
|
<span class="ph uicontrol">no-decrypt</span> action.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-306306</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Panorama appliances in FIPS-CC mode only</tt>)
|
||||||
|
Fixed interdevice TLS communication failures that occurred with RSA
|
||||||
|
and RSA-PSS signature algorithms across multiple layer 7 application
|
||||||
|
services.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-306226</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the TLS handshake did not complete and the
|
||||||
|
session did not go through. This occurred if the HTTP header insertion
|
||||||
|
applied to an HTTP CONNECT request passing through the firewall, the
|
||||||
|
scan-handshake feature was enabled, the session matched a decryption
|
||||||
|
policy rule with the decrypt action, and if the TLS client hello was
|
||||||
|
in a single packet and TLS 1.2 or below.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-304496</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after unregistering an IP tag and registering a
|
||||||
|
different IP tag for the same IP address via XML API, the dynamic
|
||||||
|
address group membership was not updated on the dataplane, which
|
||||||
|
resulted in Security policy rules being enforced incorrectly.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-303954</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, when configuring Safenet HSMs in HA and
|
||||||
|
authentication HSM manually, the second HSM server failed to
|
||||||
|
authenticate due to the firewall overwriting the first HSM server's
|
||||||
|
certificate with the second HSM server's certificate.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-303051</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where a memory leak occurred related to the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>reportd</a
|
||||||
|
>
|
||||||
|
process due to retaining memory that was temporarily used for report
|
||||||
|
generation instead of releasing the memory for reuse, which resulted
|
||||||
|
in continuous accumulation and memory exhaustion.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-301801</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Log Collectors where the Elasticsearch process
|
||||||
|
fluctuated intermittently between green and red states, which led to
|
||||||
|
interruptions in log collection. This issue occurred when the number
|
||||||
|
of shards exceeded the cluster's maximum supported threshold of
|
||||||
|
greater than 1000 shards per Elasticsearch instance.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-300637</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>VM-Series firewalls on Microsoft Azure environments only</tt
|
||||||
|
>) Fixed an issue where the firewall unexpectedly rebooted due to
|
||||||
|
repeated
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>varrcvr</a
|
||||||
|
>
|
||||||
|
process restarts.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-300548</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where using the IKEv2 multiplier setting for VPN
|
||||||
|
re-authentication resulted in the firewall not re-authenticating at
|
||||||
|
the expected intervals when both sides initiated rekeying. The
|
||||||
|
internal re-authentication counter incremented when the local side
|
||||||
|
triggered the rekey, but not when the peer side triggered it.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-297975</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Panorama was unable to push the Trusted Root CA
|
||||||
|
configuration to Log Collectors via a Collector Group push due to the
|
||||||
|
Log Collector not supporting the
|
||||||
|
<span class="ph systemoutput">trusted-root-CA</span> configuration.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-297708</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a long-lived session with many Machine Learning
|
||||||
|
(ML) model triggers caused a memory leak of feature states associated
|
||||||
|
with the ML model runs. This resulted in Spyware_State failure
|
||||||
|
increases, allocation max outs, and impaired policy matching.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-297610</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall became unresponsive after an upgrade
|
||||||
|
due to the <span class="ph systemoutput">fsck</span> command scanning
|
||||||
|
drive partitions in parallel with the root partition, which caused the
|
||||||
|
process to take an extended amount of time.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-297295</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>VM-Series firewalls in Microsoft Azure environments only</tt
|
||||||
|
>) Fixed an issue where the firewall repeatedly restarted due to high
|
||||||
|
packet rates on the synthetic path in DPDK mode.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-297005</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where exporting custom reports resulted in empty CSV
|
||||||
|
files.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-296977</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the web interface became unresponsive when
|
||||||
|
attempting to view
|
||||||
|
<span class="ph uicontrol">Ethernet</span> interface details after
|
||||||
|
applying a filter in
|
||||||
|
<span class="ph uicontrol">Network > Interfaces</span>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-296397</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on the Panorama web interface where previewing changes
|
||||||
|
after a commit to shared objects were not accurately displayed in the
|
||||||
|
push scope.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b"> PAN-295578</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where GlobalProtect HIP data file download and
|
||||||
|
installation failed with the error message
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>An error occurred while processing request. Please try again after
|
||||||
|
some time or contact support</span
|
||||||
|
>
|
||||||
|
or <span class="ph systemoutput">No ETAG from response</span> due to a
|
||||||
|
script exiting prematurely.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-294307</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where a
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>configd</a
|
||||||
|
>
|
||||||
|
SIGSEGV crash occurred when renaming objects within policy rules,
|
||||||
|
objects, or zones.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b"> PAN-291009</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after a web server returned a 401 or 403 error,
|
||||||
|
the firewall was unable to decrypt HTTP/2 traffic, and the firewall
|
||||||
|
rejected all subsequent streams from the client.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b"> PAN-290665</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue with firewalls enabled with Security profiles where
|
||||||
|
certain traffic conditions caused high dataplane CPU utilization and
|
||||||
|
packet buffer exhaustion, which caused LACP flapping conditions.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-288158</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
||||||
|
the firewall became inaccessible via the web interface and SSH and
|
||||||
|
remained in an initializing state.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-288097</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where on the firewall where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>routed</a
|
||||||
|
>
|
||||||
|
process stopped responding after changing the MTU or any link state
|
||||||
|
parameters when OSPF and PIM were enabled on the same interface.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-284866</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the LFC failed to validate Certificate Revocation
|
||||||
|
Lists (CRL) for SSL syslog connections, which caused a failure to
|
||||||
|
forward logs to external syslog servers.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-280725</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>all_pktproc</a
|
||||||
|
>
|
||||||
|
process repeatedly restarted, which caused dataplane failure and loss
|
||||||
|
of connectivity, including PAN-DB URL resolution. This occurred after
|
||||||
|
a commit push from Panorama and resulted in the firewall becoming
|
||||||
|
non-functional due to internal path monitoring failure and
|
||||||
|
configuration memory exhaustion.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-278126</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the number of registered IP Tags on Panorama did
|
||||||
|
not match the number of registered IP Tags on the managed firewalls
|
||||||
|
due to a change in file format between PAN-OS releases.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-276484 </b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Panorama did not display license information for
|
||||||
|
Cloud NGFW firewalls under (<span class="ph uicontrol"
|
||||||
|
>Device Deployment > Licenses</span
|
||||||
|
>) due to the inability to perform batch-license refreshes.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-276321</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where User-ID mappings were not correctly redistributed
|
||||||
|
from Panorama to firewalls, causing some users to be identified as
|
||||||
|
<span class="ph uicontrol">unknown</span>, which prevented access to
|
||||||
|
resources based on AD group membership.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-274086</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall incorrectly assembled SIP NOTIFY and
|
||||||
|
REFER messages when processing SIP TCP packets that contained a
|
||||||
|
partial content-body from a previous SIP message and a complete header
|
||||||
|
and content-body from the next SIP message.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-272245</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>dnsproxy</a
|
||||||
|
>
|
||||||
|
process stopped responding due to memory corruption caused by a race
|
||||||
|
condition when the allow list downloading was impacted by a
|
||||||
|
configuration change.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-257616</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where selective push operations from Panorama to
|
||||||
|
managed firewalls failed with the error message
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>Failed to generate selective push configuration. Schema validation
|
||||||
|
failed. Please try a full push</span
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-241694</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where memory leaks related to the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>devsrvr</a
|
||||||
|
>
|
||||||
|
process occurred when downloading and pushing updates from the App-ID
|
||||||
|
Cloud Engine to the dataplane.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
@@ -0,0 +1,750 @@
|
|||||||
|
<table class="table colsep rowsep table-striped">
|
||||||
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||||
|
|
||||||
|
<colgroup>
|
||||||
|
<col style="width: 25%" />
|
||||||
|
<col style="width: 75%" />
|
||||||
|
</colgroup>
|
||||||
|
<thead class="thead">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||||
|
</th>
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Description</b></div>
|
||||||
|
</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
|
||||||
|
<tbody class="tbody">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-309392</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the scroll bar did not appear when editing
|
||||||
|
<span class="ph uicontrol">Destination Addresses</span> for Policy
|
||||||
|
Based forwarding policy rules.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-309379</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>logrcvr</a
|
||||||
|
>
|
||||||
|
process stopped responding on DPCs, which prevented logs from being
|
||||||
|
forwarded.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-308085</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>VM-Series firewalls in Microsoft Azure environments only</tt
|
||||||
|
>) Fixed an issue where, after resizing the VM, the HA2 link became
|
||||||
|
unstable. Frequent keep-alive failures occurred, and HA2 keep-alive
|
||||||
|
packets were simultaneously transmitted to multiple destination MAC
|
||||||
|
addresses and the peer firewall's interface MAC). This issue occurred
|
||||||
|
on firewalls with Accelerated Networking enabled.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-308060</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>Firewalls in active/active HA configurations only</tt
|
||||||
|
>) Fixed an issue where the BFD session went down and did not recover
|
||||||
|
even though the BGP remained in an established state, which caused the
|
||||||
|
firewall to cease route learning and advertisement with the peer, even
|
||||||
|
though BGP keep-alives were exchanged correctly.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-307795</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Panorama incorrectly generated system logs
|
||||||
|
indicating a lost connection to its peer after an upgrade even when
|
||||||
|
High Availability was not configured.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-305835</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where firewalls with Memory Integrity Checking
|
||||||
|
Architecture enabled rebooted unexpectedly due to accessing an invalid
|
||||||
|
memory address. This occurred because the forwarding data structure
|
||||||
|
index exceeded its designed limit.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-305412</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the Logging Service License Status displays a
|
||||||
|
license failure when the license status transitions from valid to
|
||||||
|
expired and then back to valid even when the connection to the
|
||||||
|
Security Logging Service (SLS) was working.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-305301</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the timing of GlobalProtect lifetime expiry or
|
||||||
|
inactivity logout notifications used for GlobalProtect SSL tunnels
|
||||||
|
could cause the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>pan_task</a
|
||||||
|
>
|
||||||
|
process to stop responding and the dataplane to restart.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-304636</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where BGP aggregate routes were not created and discard
|
||||||
|
routes were not installed in the routing table.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-303959</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where traffic is incorrectly identified as
|
||||||
|
unknown-tcp/unknown-udp due to App-ID resource leak and eventually
|
||||||
|
dropped.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-303627</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after committing a configuration change, the
|
||||||
|
firewall experienced traffic issues,
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>pan_task</a
|
||||||
|
>
|
||||||
|
crashes, and LACP interface failures.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-303559</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after manuallly creating a device telemetry
|
||||||
|
bundle, the
|
||||||
|
<span class="ph systemoutput">hour_cli_output.txt</span> file within
|
||||||
|
the bundle had a file size of 0 bytes. This occurred when checking the
|
||||||
|
bundle content after enabling device telemetry and setting the device
|
||||||
|
telemetry upload endpoint.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-302551</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall displayed as disconnected in the SLS
|
||||||
|
due to the serial number not being retrieved
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-301975</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
|
||||||
|
issue where the passive firewall incorrectly triggered PBP alerts even
|
||||||
|
with low packet rates.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-301937</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Microsoft Defender for Cloud detected cleartext
|
||||||
|
SSH private keys in the /var/appweb and /etc/appweb directories on
|
||||||
|
PA-VM firewalls deployed in Azure.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-301912</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Panorama stopped responding when deploying
|
||||||
|
dynamic updates to managed devices.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-301600</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on the firewall where, after upgrading Panorama, OSPF
|
||||||
|
adjacencies remained in the exchange start state, which resulted in an
|
||||||
|
incomplete routing table.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-301456</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where the
|
||||||
|
<span class="ph codeph">debug system reset-ztp</span> CLI command was
|
||||||
|
unavailable.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-301409</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Panorama failed to perform a selective push to a
|
||||||
|
managed device when device tags were added or modified on the policy
|
||||||
|
rules. The selective push failed with the error message
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>Failed to generate selective push configuration. Schema validation
|
||||||
|
failed. Please try a full push</span
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-300837</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where firewalls experienced multiple reboots due to the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>pan_task</a
|
||||||
|
>
|
||||||
|
process restarting with a SIGSEGV signal. This occurred because the
|
||||||
|
client-to-firewall side assumed TLS 1.3 for the firewall-server side.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-299751</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall was unable to connect to the
|
||||||
|
Subscription License Service (SLS) due to a public and private key
|
||||||
|
pair mismatch with the device certificate.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-299622</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the MFA timestamp was not redistributed between
|
||||||
|
standalone firewalls behind an Azure load balancer after upgrading,
|
||||||
|
which resulted in users being prompted to reauthenticate multiple
|
||||||
|
times.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-298907</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on PA-VM in AWS where, in a two-arm deployment
|
||||||
|
integrated with Gateway Load Balancer (GWLB), the firewall did not
|
||||||
|
preserve the GENEVE source port for internet traffic, resulting in
|
||||||
|
increased latency. The fix ensures the firewall preserves the outer
|
||||||
|
UDP source port of GENEVE encapsulation when sending traffic back to
|
||||||
|
GWLB.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-297263</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-5220 firewalls only</tt>) Fixed an issue where
|
||||||
|
the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>ikemgr</a
|
||||||
|
>
|
||||||
|
process crashed intermittently, causing IPSec tunnels to go down
|
||||||
|
randomly. The fix ensures that the IKE security association data
|
||||||
|
structures are accessed in a thread-safe manner. This prevents the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>ikemgr</a
|
||||||
|
>
|
||||||
|
process from referencing an invalid memory pointer during teardown
|
||||||
|
operations and provides stability.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-296208</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall did not accept address groups in the
|
||||||
|
filter condition of a Log Forwarding Match list.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-295796</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall intermittently failed to forward
|
||||||
|
VXLAN GARP packets, which led to connectivity issues for wireless
|
||||||
|
clients in environments that used VXLAN tunnels for wireless access
|
||||||
|
points.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-292447</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Panorama did not display data in the
|
||||||
|
<span class="ph uicontrol">Feature Adoption</span> tab in Strata Cloud
|
||||||
|
Manager due to the system creating and deleting a CLI user for each
|
||||||
|
interval instead of reusing a permanent CLI user for telemetry.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-291067</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>devsrvr</a
|
||||||
|
>
|
||||||
|
process periodically exceeded its virtual memory limit and restarted,
|
||||||
|
which led to intermittent outages.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-290241</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>useridd</a
|
||||||
|
>
|
||||||
|
process became unresponsive, which caused User-ID CLI commands to time
|
||||||
|
out.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-290235</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>dscd</a
|
||||||
|
>
|
||||||
|
process crashed continuously on MIPS platforms (for example, PA-850
|
||||||
|
firewalls) due to a runtime error related to an invalid memory address
|
||||||
|
or nil pointer dereference. This was caused by a golang library
|
||||||
|
upgrade in CIE that is incompatible with the MIPS platform.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-289652</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue related to external URL lists where pushing
|
||||||
|
configuration changes from Panorama failed.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-288427</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where commit jobs were not queued and the
|
||||||
|
system reported that the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>useridd</a
|
||||||
|
>
|
||||||
|
was not connected.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287921</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
||||||
|
the maximum registered IP address for was incorrectly set to 100,000
|
||||||
|
instead of the expected 500,000.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-285208</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall did not automatically recover after
|
||||||
|
a machine check exception (MCE) occurred.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-283237</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where traffic logs incorrectly displayed the action as
|
||||||
|
<span class="ph uicontrol">allow</span> for traffic matching a
|
||||||
|
Security policy rule configured with the action set to
|
||||||
|
<span class="ph uicontrol">deny</span>. This issue occurred due to the
|
||||||
|
child session being used for policy rule lookup when a configuration
|
||||||
|
update triggered a rematch if the FTP-data application was not in the
|
||||||
|
rule.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-281588</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where packet buffer depletion occurred due to the a
|
||||||
|
high number of
|
||||||
|
<span class="ph systemoutput">tcp_pkt_queued</span> packets when Jumbo
|
||||||
|
was enabled.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-277464</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue with intermittent access and slower than expected
|
||||||
|
loading times when accessing websites. This occurred when Anti-Spyware
|
||||||
|
inline cloud analysis was enabled and the
|
||||||
|
<span class="ph uicontrol">SSL Command and Control</span> action was
|
||||||
|
not either <span class="ph uicontrol">allow</span> or
|
||||||
|
<span class="ph uicontrol">alert</span> and server hello packets were
|
||||||
|
out of order.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-269535</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the mib ID returned an incorrect value via SNMP.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-263691</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall rebooted unexpectedly due to a
|
||||||
|
memory leak in the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>all_task</a
|
||||||
|
>
|
||||||
|
process.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-262831</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-5400f Series firewalls only</tt>) Fixed an
|
||||||
|
intermittent issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>all_task</a
|
||||||
|
>
|
||||||
|
process stopped responding, which caused the firewall to restart.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-255654</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, when QoS was enabled on aggregate interfaces,
|
||||||
|
the maximum aggregate interface throughput was capped, which limited
|
||||||
|
network traffic. This occurred even with default QoS settings and no
|
||||||
|
configured egress max-bandwidth.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-236794</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where SNMP walk reported incorrect interface speeds.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-185731</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall was unable to parse the URL path and
|
||||||
|
host when the host header was located in a different packet, which
|
||||||
|
resulted in the firewall not logging the URL path in the first packet.
|
||||||
|
The fix is disabled by default. The following CLI commands can be used
|
||||||
|
to enable/disable the feature:
|
||||||
|
<ul id="panos-addressed-issues-11.1.10-h12_ul-fmq_kc3_yhc" class="ul">
|
||||||
|
<li class="li">
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>set system setting ctd url-crosspkt-host-path-caching
|
||||||
|
enable</span
|
||||||
|
>
|
||||||
|
</li>
|
||||||
|
<li class="li">
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>set system setting ctd url-crosspkt-host-path-caching
|
||||||
|
disable</span
|
||||||
|
>
|
||||||
|
</li>
|
||||||
|
<li class="li">
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>set system setting ctd url-crosspkt-host-path-caching
|
||||||
|
default</span
|
||||||
|
>
|
||||||
|
</li>
|
||||||
|
</ul>
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
@@ -0,0 +1,973 @@
|
|||||||
|
<table class="table colsep rowsep table-striped">
|
||||||
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||||
|
|
||||||
|
<colgroup>
|
||||||
|
<col style="width: 25%" />
|
||||||
|
<col style="width: 75%" />
|
||||||
|
</colgroup>
|
||||||
|
<thead class="thead">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||||
|
</th>
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Description</b></div>
|
||||||
|
</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
|
||||||
|
<tbody class="tbody">
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-316911</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>VM-Series firewalls on Amazon Web Services (AWS) environments
|
||||||
|
only</tt
|
||||||
|
>) Fixed an issue where a newly bootstrapped firewall required a
|
||||||
|
management server restart, relicensing, or license push from Panorama
|
||||||
|
to invoke the device certificate.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-315176</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Added an enable and disable CLI command to address an issue where the
|
||||||
|
firewall experienced increased packet drops and slower performance
|
||||||
|
after an upgrade due to high burst traffic.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-314319</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall experienced increased packet drops
|
||||||
|
and slower performance after an upgrade due to high burst traffic.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-314142</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where establishing log forwarding connections to the
|
||||||
|
Strata Logging Service (SLS) took longer than expected, which resulted
|
||||||
|
in delayed log visibility on SLS.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-314061</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where traffic was disrupted during IPSec rekey
|
||||||
|
operations due to a 2 second delay in sending the DELETE message for
|
||||||
|
the previous Security Association (SA) to the peer gateway after a new
|
||||||
|
SA was negotiated.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-313850</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>PA-1400 Series firewalls in HA configurations only</tt
|
||||||
|
>) Fixed an issue where a split-brain condition occurred and HA1/HA2
|
||||||
|
links went down while upgrading when the HA configuration used
|
||||||
|
dataplane interfaces for HA1 and a combination of HSCI and Ethernet
|
||||||
|
interfaces for HA2.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-313623</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<span class="ph systemoutput">/opt/pancfg/mgmt/ssl/private/</span>
|
||||||
|
directory on Palo Alto Networks devices with TPM support became 100%
|
||||||
|
utilized due to an accumulation of undeleted
|
||||||
|
<span class="ph systemoutput">.pub_pem</span> files. This occurred
|
||||||
|
because executing the
|
||||||
|
<span class="ph systemoutput">show device-certificate status</span>
|
||||||
|
CLI command initiated a process that generated these files but failed
|
||||||
|
to remove them, which prevented the fetching of new device
|
||||||
|
certificates.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-313572</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
||||||
|
the dataplane restarted due to a segmentation fault.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-312706</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewalls restarted due to a function lacking
|
||||||
|
a NULL-pointer sanity check.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-311285</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Firewalls in HA conditions only</tt>) Fixed an
|
||||||
|
issue where a memory leak occurred related to the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>ospfd</a
|
||||||
|
>
|
||||||
|
process, which caused RAM usage to continuously increase on active
|
||||||
|
devices in an HA cluster until the device stopped responding, even
|
||||||
|
after an HA failover.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-311250</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Panorama appliances and Log Collectors only</tt>)
|
||||||
|
Fixed an issue where logs from multiple devices were not visible on
|
||||||
|
Panorama even though the Elasticsearch health status on the dedicated
|
||||||
|
Log Collectors appeared green.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-311073</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>Panorama managed firewalls in HA configurations only</tt
|
||||||
|
>) Fixed an issue where firewalls incorrectly updated the modified
|
||||||
|
date and MD5 hash of policy rules during an HA sync commit job or a
|
||||||
|
subsequent local commit, even when no changes were made to the policy
|
||||||
|
rules.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-309300</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where management plane system resources configuration
|
||||||
|
size exceeded 28 MB for over 4 hours, and the following error message
|
||||||
|
was displayed:
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>Configuration size reaching device capacity limit</span
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-308786</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue where
|
||||||
|
traffic log queries using the
|
||||||
|
<span class="ph systemoutput">device_name</span> filter returned no
|
||||||
|
results, and complex log queries that included negation operators
|
||||||
|
produced incorrect outputs.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-308654</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the Elasticsearch Close Indices process closed
|
||||||
|
more indices than expected and dropped the number of open shards below
|
||||||
|
the minimum of 800 per Elasticsearch instance. This occurred because
|
||||||
|
the process did not correctly account for the number of Elasticsearch
|
||||||
|
instances when calculating the maximum number of allowed open shards.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-308507</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Panorama managed firewalls only</tt>) Fixed an
|
||||||
|
issue where the firewall intermittently failed to maintain active log
|
||||||
|
forwarding streams to Cortex Data Lake even when duplicate logging and
|
||||||
|
enhanced application logging were enabled.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-307702</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
|
||||||
|
issue where traffic passing through AE layer 2 interfaces was
|
||||||
|
interrupted during HA failovers.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-307597</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where BGP peering sessions between a hub firewall and a
|
||||||
|
satellite firewall over GlobalProtect LSVPN failed to connect.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-306555</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall stopped responding, which led to
|
||||||
|
service outages.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b"> PAN-305700</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a reboot loop occurred when OSPF interfaces were
|
||||||
|
configured with a link type of
|
||||||
|
<span class="ph uicontrol">point-to-point</span>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-305552</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where DLP logs displayed an incorrect file type when
|
||||||
|
the firewall did not set the file type field.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-304718</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where OSPF and BGP outages occurred due to an
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>all_task</a
|
||||||
|
>
|
||||||
|
process restart during clientless VPN content rewrite processing.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-304696</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the Cloud User-ID connection timed out because
|
||||||
|
the firewall took too long to process the OCSP response.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-304576</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall entered a non-functional state due
|
||||||
|
to segmentation fault within the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>all_pktproc</a
|
||||||
|
>
|
||||||
|
process that was caused by a session that involved http2 cleartext
|
||||||
|
traffic.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-304205</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where, after upgrading to an affected
|
||||||
|
release, a partial commit via the API did not push configuration
|
||||||
|
changes to managed firewalls, and a full commit was required to
|
||||||
|
synchronize the configuration.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-303959</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where traffic was incorrectly identified as
|
||||||
|
unknown-tcp/unknown-udp due to App-ID resource leak and eventually
|
||||||
|
dropped.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-303745</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where inter-dataplane forwarding did not work for
|
||||||
|
sessions ingressing on Slot 2, which resulted in intermittent ping
|
||||||
|
failures to interfaces on Network Card 2 when traffic was forwarded to
|
||||||
|
Slot 3.
|
||||||
|
</div>
|
||||||
|
<div class="p">
|
||||||
|
<b class="ph b">Note</b>: With this fix, after a slot restart, the
|
||||||
|
global counter will still show dot1q errors for a short period.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-303722</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on the firewall where configuring spyware and
|
||||||
|
vulnerability profiles in Security policy rules caused a memory leak
|
||||||
|
in the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>devsrvr</a
|
||||||
|
>
|
||||||
|
process with each configuration commit.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-302654</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>Firewalls in active/passive HA configurations only</tt
|
||||||
|
>) Fixed an issue where, when the HA configuration had multiple
|
||||||
|
logical routers, static or connected routes redistributed into OSPF
|
||||||
|
aged out in the LSDB, which caused the routes to be removed on peer
|
||||||
|
OSPF neighbors.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-301731</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, when the firewall was unable to establish an SCM
|
||||||
|
connection due to the discovery service returning a 404 error when the
|
||||||
|
device was not yet known to the service, the firewall did not retry
|
||||||
|
the attempt as expected.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-300671</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where traffic reports that were generated with
|
||||||
|
destination/source and destination/source hostnames were not displayed
|
||||||
|
in IPv4 format.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-300664</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on the Panorama and firewall web interface where
|
||||||
|
Applications pages became unresponsive after activating the SaaS
|
||||||
|
Inline license.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-300423</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Data Processing Cards (DPCs) installed in slots 5
|
||||||
|
and 6 remained stuck in a starting state with the error
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>Signal detected for port xeS5-DP0 but Link Down</span
|
||||||
|
>
|
||||||
|
alerts, which resulted in device instability.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-299705</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where API calls to commit changes on Panorama
|
||||||
|
intermittently failed when using the XML API with refresh=no, which
|
||||||
|
caused changes to not be applied to the partial-commit configuration.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-299495</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>show system setting ssl-decrypt certificate</span
|
||||||
|
>
|
||||||
|
CLI command did not display certificates when XML output was enabled.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-298945</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where OSCP HTTP POST requests were not formatted
|
||||||
|
correctly, which caused failures with strict responders.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-298617</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Optimized the commit workflow to reduce the size of the effective
|
||||||
|
configuration, resulting in lower memory consumption.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-296694</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall rebooted due to the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>useridd</a
|
||||||
|
>
|
||||||
|
process repeatedly restarting during an IP-port data type writes to
|
||||||
|
the redis from multiple sources such as TSA or XML in a scale
|
||||||
|
environment.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-295803</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Addressed a memory leak issue under sc3 and automatic commit recovery
|
||||||
|
(ACR) code path.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-295802</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a memory leak related to the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>configd</a
|
||||||
|
>
|
||||||
|
process occurred.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-296202</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>Firewalls in active/active HA configurations only</tt
|
||||||
|
>) Added a log enhancement to capture an issue where, when a commit
|
||||||
|
operation was in progress, newly deployed IP address tags that used
|
||||||
|
the XML API were not immediately reflected in address group
|
||||||
|
resolution, which delayed IP address mapping to address groups and
|
||||||
|
caused traffic to be incorrectly allowed or denied.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-294379</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, when all interfaces configured for SD-WAN SaaS
|
||||||
|
Application path monitoring failed, the firewall stopped forwarding
|
||||||
|
traffic even if the ISP links and default gateway probing were still
|
||||||
|
active.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-292306</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>authd</a
|
||||||
|
>
|
||||||
|
process stopped handling RADIUS authentication requests and required a
|
||||||
|
restart.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-291094</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue the firewall experienced packet descriptor on chip and
|
||||||
|
buffer spikes, which led to dropped traffic due to an unidentified
|
||||||
|
traffic pattern.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-290938</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where multiple memory leaks occurred related to the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>configd</a
|
||||||
|
>
|
||||||
|
process.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-288175</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Addressed a stack buffer overflow memory leak under plugin management
|
||||||
|
code path.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287392</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed the issue on the web interface where
|
||||||
|
<span class="ph uicontrol">ACC</span> graphs displayed
|
||||||
|
<span class="ph uicontrol">No data to display</span> when a filter was
|
||||||
|
applied to <span class="ph uicontrol">Source IP</span> or
|
||||||
|
<span class="ph uicontrol">Destination IP</span>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287159</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where file uploads to Dropbox stalled when using a
|
||||||
|
PA-CPT device with MLC2 and DLP Mirror mode enabled for HTTP2 traffic.
|
||||||
|
This occurred because the proxy was unable to decrement packet counts
|
||||||
|
properly when the queue was large, resulting in a receive window size
|
||||||
|
of 0 for the parent session.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-283237</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where traffic logs incorrectly displayed the action as
|
||||||
|
<span class="ph uicontrol">allow</span> for traffic matching a
|
||||||
|
Security policy rule configured with the action set to
|
||||||
|
<span class="ph uicontrol">deny</span>. This issue occurred due to the
|
||||||
|
child session being used for policy rule lookup when a configuration
|
||||||
|
update triggered a rematch if the FTP-data application was not in the
|
||||||
|
rule.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-279364</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">VM-Series firewalls with multiple NICs only</tt>)
|
||||||
|
Fixed an issue were the queue count in the task dump displayed an
|
||||||
|
incorrect number of queues for SR-IOV interfaces due to the queue
|
||||||
|
mapping logic incorrectly using a non-multi-NIC function.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-279209</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where changes made to the management interface
|
||||||
|
permitted IP address list in a global template were not pushed to the
|
||||||
|
template stack or firewalls.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-278688</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where DNS Security threat logs were not displayed on
|
||||||
|
the firewall when packet capture was enabled and the domain name
|
||||||
|
length was 62 characters.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-278628</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
|
||||||
|
issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>configd</a
|
||||||
|
>
|
||||||
|
process restarted during a configuration push from Panorama, which
|
||||||
|
caused the active firewall to lose management access for 20-30
|
||||||
|
minutes.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-277987</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">VM-Series firewalls in AWS environments only</tt>)
|
||||||
|
Fixed an issue where HA failover mode incorrectly changed from
|
||||||
|
<span class="ph uicontrol">interface move</span> to
|
||||||
|
<span class="ph uicontrol">secondary IP move</span> after a reboot.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-274742</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
||||||
|
the <span class="ph systemoutput">task-queue dump</span> CLI command
|
||||||
|
returned incorrect information in multi-nic mode.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-273487</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>distributord</a
|
||||||
|
>
|
||||||
|
process restarted on firewalls in multi-vsys environments with User-ID
|
||||||
|
configured and Panorama as a redistribution client. This occurred when
|
||||||
|
a large volume of IP address-to-user mappings were learned.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-273158</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-7000 Series firewalls only</tt>) Fixed an issue
|
||||||
|
where an incorrect ASIC configuration caused silent packet drops or
|
||||||
|
application slowness when receiving a mix of jumbo and non-jumbo
|
||||||
|
packets.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-262353</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, when Panorama was upgraded but log collectors
|
||||||
|
were on an earlier version, logs from a log collector group were not
|
||||||
|
viewable on a Panorama.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-259785</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>devsrvr</a
|
||||||
|
>
|
||||||
|
process restarted and created a core dump because two threads did not
|
||||||
|
terminate correctly.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-245686</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where memory leaks occurred when checking for,
|
||||||
|
downloading, or installing dynamic updates.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-243507</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on the firewall web interface where
|
||||||
|
<span class="ph uicontrol">Logical Router</span> did not load after an
|
||||||
|
Advanced Routing Engine stack upgrade.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,464 @@
|
|||||||
|
<table class="table colsep rowsep table-striped">
|
||||||
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||||
|
|
||||||
|
<colgroup>
|
||||||
|
<col style="width: 25%" />
|
||||||
|
<col style="width: 75%" />
|
||||||
|
</colgroup>
|
||||||
|
<thead class="thead">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||||
|
</th>
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Description</b></div>
|
||||||
|
</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
|
||||||
|
<tbody class="tbody">
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-300906</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where XML API commands failed with a
|
||||||
|
<span class="ph systemoutput">Method not found (policy_xml)</span>
|
||||||
|
error in dagger.log. The issue was due to missing XML-related
|
||||||
|
functions for inline-cloud-proxy and session-distribution commands in
|
||||||
|
dagger files handling.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-300096</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a local commit on a firewall breaks template
|
||||||
|
stack overrides, preventing the enabling of LACP (Link Aggregation
|
||||||
|
Control Protocol). After a local commit, the LACP enable check was
|
||||||
|
unexpectedly unchecked, causing an outage. Attempting to re-enable
|
||||||
|
LACP through the web interface was unsuccessful, requiring manual
|
||||||
|
removal of the LACP configuration from the Panorama CLI.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-299785</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-7500 and PA-5450 firewalls in FIPS-CC mode</tt>)
|
||||||
|
Fixed an issue where the affected firewalls would boot into
|
||||||
|
maintenance mode when a reboot was initiated from the web interface.
|
||||||
|
This was due to a device reboot triggering a power down to all slots,
|
||||||
|
leading to maintenance mode. A hard reboot would allow the firewall to
|
||||||
|
boot normally.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-297972</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a dataplane crash occurred when traffic matched
|
||||||
|
Inline Cloud Analysis pre-filtering signatures, even when Inline Cloud
|
||||||
|
Analysis features were not enabled.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-297240</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where attempting to generate reports in a WildFire FIPS
|
||||||
|
Private Cloud or WF-500 deployment returned 401 errors.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-296490</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">FIPS CC mode enabled only</tt>) Fixed an issue
|
||||||
|
where Panorama on GCP reboots every hour after upgrading to
|
||||||
|
11.1.6-h10. Panorama will run for up to an hour and then crash.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-296453</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where decryption exclusion lists were not working for
|
||||||
|
untrusted certificates, and SSL sessions were still being decrypted
|
||||||
|
even after adding them to the exclusion list. This occurred because
|
||||||
|
the firewall was not adding sessions to the exclude cache until after
|
||||||
|
receiving a non-RFC alert (BadCertificate) from the server. The fix
|
||||||
|
ensures that the first session is added to the exclude cache, allowing
|
||||||
|
subsequent sessions to skip decryption. This issue affects firewalls
|
||||||
|
configured as clients in server-client communication.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-295944</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where static routes remained active in the FIB and RIB
|
||||||
|
even when the associated physical port interface was down, which
|
||||||
|
resulted in traffic being incorrectly routed through a non-operational
|
||||||
|
interface.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-295560</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after upgrading Panorama and Log Collectors,
|
||||||
|
tunnel logs were not visible in Panorama or Splunk even though traffic
|
||||||
|
and threat logs were received.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-295257</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after onboarding a firewall to Panorama, IPsec
|
||||||
|
tunnels displayed IKEv2 in Panorama, even though the tunnels were
|
||||||
|
configured with IKEv1 locally on the firewall.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-294893</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where firewalls with the
|
||||||
|
<span class="ph uicontrol"
|
||||||
|
>Send handshake messages to CTD for inspection</span
|
||||||
|
>
|
||||||
|
setting enabled caused incorrect security policy rules to be matched.
|
||||||
|
Specifically, traffic not identified as openai-base or openai-chatgpt
|
||||||
|
applications was incorrectly matched by the
|
||||||
|
ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected
|
||||||
|
response page for blocked URLs was not displayed.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-294770</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Firewalls in active/passive HA configurations</tt>)
|
||||||
|
Fixed an issue on firewalls where, after failover, certain subnets
|
||||||
|
were missing from the Link State Database, which prevented OSPF routes
|
||||||
|
from being immediately learned due to a Type-7 to Type-5 LSA
|
||||||
|
translation conflict in the ABR when the same LSA was advertised by
|
||||||
|
two peers in the NSSA area.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-294524</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where firewalls and Panorama management servers were
|
||||||
|
unable to view or download WildFire reports from a WF-500 appliance,
|
||||||
|
resulting in a 401 error in the report tab.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-292393</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where TFTP file transfers intermittently timed out in
|
||||||
|
active-active HA pairs when the TFTP control channel was processed by
|
||||||
|
one firewall and the data channel was processed by the other. This
|
||||||
|
occurred because the firewall receiving the data channel failed to
|
||||||
|
match the predicted session due to asynchronous processing of HA
|
||||||
|
messages.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-291716</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where PA-460 firewalls experienced out-of-memory (OOM)
|
||||||
|
conditions, leading to device crashes and reboots.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-291288</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall rebooted unexpectedly due to a
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>pan_task</a
|
||||||
|
>
|
||||||
|
process restart related to page allocation failures.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-290453</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-7500 firewalls only</tt>) Fixed an issue where
|
||||||
|
PA-7500 firewalls experienced silent traffic drops. During migration
|
||||||
|
from PA-7050 to PA-7500 firewalls connected in series, intermittent
|
||||||
|
connection losses occurred for some applications. Traffic leaving the
|
||||||
|
PA-7050 was not received or processed by the PA-7500, even with direct
|
||||||
|
connections and replaced cables/SFPs. Global counters did not indicate
|
||||||
|
any drops on the PA-7500.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-289249</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a memory leak occurred on the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>reportd</a
|
||||||
|
>
|
||||||
|
process when a WildFire update was initiated while device telemetry
|
||||||
|
data collection was in progress. This resulted in an OOM condition.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287803</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after upgrading firewalls to PAN-OS 11.1.6-h1,
|
||||||
|
certain websites weren't accessible when the accumulation proxy was
|
||||||
|
enabled. The proxy did not use the same DF bit state as the original
|
||||||
|
traffic, causing it to be fragmented and dropped elsewhere in the
|
||||||
|
network.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287782</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where firewalls configured in vwire mode modified DSCP
|
||||||
|
values from AF11 to CS0 on traffic passing through the firewall, even
|
||||||
|
when QoS policy rules and DSCP rewrite settings were not configured.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287622</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where IPv6 traffic was affected after upgrading the
|
||||||
|
firewall to PAN-OS 11.1.6-h4 and later versions. With SSL decryption
|
||||||
|
enabled and a decryption policy configured for the traffic, the
|
||||||
|
firewall dropped packets due to receiving a
|
||||||
|
<span class="ph systemoutput">Packet Too Big</span> ICMP message. This
|
||||||
|
occurred because the PathMTU information update was incorrect for the
|
||||||
|
TCB (pan-server) when the firewall was acting as a server.
|
||||||
|
Additionally, the flow label under the IPv6 header was set to zero
|
||||||
|
while the packet was being transmitted out of the firewall.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287423</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where content loading issues occurred on IPv6 websites
|
||||||
|
due to the firewall incorrectly setting the IPv6 header flow label to
|
||||||
|
0.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-285648</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the log receiver process crashed on PA-7050
|
||||||
|
firewalls due to system log processing threads becoming blocked when
|
||||||
|
the queue was full. This resulted in a heartbeat failure.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-283053</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall experienced high disk space
|
||||||
|
utilization, which caused the firewall to become non-functional.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-278322</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>VM-Series firewalls on Amazon Web Services (AWS) Gateway Load
|
||||||
|
Balancer (GWLB) deployments only</tt
|
||||||
|
>) Fixed an issue where the firewall did not display the correct
|
||||||
|
source user in traffic logs and session details.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-277034</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where WildFire reports were not fully displayed and
|
||||||
|
were not downloadable due to static resources not being found.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-267450</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>reported</a
|
||||||
|
>
|
||||||
|
process stopped responding with a SIGSEGV at
|
||||||
|
<span class="ph systemoutput">schedule_report_es_response</span>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-260185</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a dataplane crash occurred in Inline Cloud
|
||||||
|
Analysis action lookup because there were no vulnerability or
|
||||||
|
antispyware profiles in the security policy rule.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-253963</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>Panorama appliances in Panorama mode and Log Collector mode
|
||||||
|
only</tt
|
||||||
|
>) Fixed an issue where autocommits took longer than expected to
|
||||||
|
complete.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,34 @@
|
|||||||
|
<table class="table colsep rowsep table-striped">
|
||||||
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||||
|
|
||||||
|
<colgroup>
|
||||||
|
<col style="width: 25%" />
|
||||||
|
<col style="width: 75%" />
|
||||||
|
</colgroup>
|
||||||
|
<thead class="thead">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||||
|
</th>
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Description</b></div>
|
||||||
|
</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
|
||||||
|
<tbody class="tbody">
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-297295</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>VM-Series firewalls in Microsoft Azure environments only</tt
|
||||||
|
>) Fixed an issue where the firewall repeatedly restarted due to high
|
||||||
|
packet rates on the synthetic path in DPDK mode.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
@@ -0,0 +1,526 @@
|
|||||||
|
<table class="table colsep rowsep table-striped">
|
||||||
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||||
|
|
||||||
|
<colgroup>
|
||||||
|
<col style="width: 25%" />
|
||||||
|
<col style="width: 75%" />
|
||||||
|
</colgroup>
|
||||||
|
<thead class="thead">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||||
|
</th>
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Description</b></div>
|
||||||
|
</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
|
||||||
|
<tbody class="tbody">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-288693</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where importing a device configuration into Panorama
|
||||||
|
failed with a validation error if the configuration included a shared
|
||||||
|
gateway with shared address objects.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-286897</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>pan_task</a
|
||||||
|
>
|
||||||
|
process stopped responding when the firewall attempted to forward
|
||||||
|
files to the WildFire public cloud, which caused the dataplane to
|
||||||
|
experience heartbeat failures.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-286475</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the option to sort sequence numbers was missing
|
||||||
|
from <span class="ph uicontrol">Filters prefix list</span> in the
|
||||||
|
advanced routing filters.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-285590</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>VM-Series firewalls on Amazon Web Services (AWS) GWLB environments
|
||||||
|
only</tt
|
||||||
|
>) Fixed an issue where the firewall CPU usage reached 100% after
|
||||||
|
upgrading to PAN-OS 11.1.6-h1.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-284840</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-5220 firewalls only</tt>) Fixed an issue where
|
||||||
|
custom reports were delayed when sent via email instead of being sent
|
||||||
|
at the scheduled time.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-284116</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where mTLS decryption bypass did not work when the
|
||||||
|
decryption profile was configured with the maximum TLS version as TLS
|
||||||
|
1.3.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-284066</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after an upgrade, the SNMP polled values for
|
||||||
|
<span class="ph systemoutput">IF-MIB::ifInErrors</span> displayed a
|
||||||
|
high number of errors that did not match the values in the CLI show
|
||||||
|
interface command.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-283789</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>Firewalls in high availability (HA) configurations only</tt
|
||||||
|
>) Fixed an issue where, after an upgrade, the
|
||||||
|
<span class="ph uicontrol">mac receive error</span> counter in
|
||||||
|
<span class="ph uicontrol">receive incoming errors</span> increased,
|
||||||
|
which resulted in SNMP alerts.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-283467</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-3400 Series firewalls only</tt>) Fixed an issue
|
||||||
|
where the firewall unexpectedly rebooted and entered maintenance mode
|
||||||
|
due to a ctd-agent out-of-memory (OOM) condition. This occurred during
|
||||||
|
advanced services load testing and a high volume of IoT EAL log
|
||||||
|
forwarding.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-283331</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where selective pushes to managed devices failed when
|
||||||
|
the <span class="ph uicontrol">User ID Master Device</span> was
|
||||||
|
configured.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-282640</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where custom reports showed incomplete data when
|
||||||
|
exported in CSV format from Panorama.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-281776</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on the Panorama web interface where the error message
|
||||||
|
<span class="ph uicontrol"
|
||||||
|
>PPPoEv6 Client Interface cannot be enabled with DHCPv6 client</span
|
||||||
|
>
|
||||||
|
was generated when overriding aggregate interfaces even when no DHCPv6
|
||||||
|
or PPPoE was configured.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-280698</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall removed the TCP timestamp from
|
||||||
|
client hello messages that did not fit in a single packet, which
|
||||||
|
resulted in connection issues.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-280532</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after disabling and re-enabling the external
|
||||||
|
syslog server, the TCP session was not resumed, which caused all logs
|
||||||
|
that were forwarded to the syslog server to be dropped.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-280335</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue with an SNMPv3 EngineBoots value discrepancy that
|
||||||
|
prevented to SNMP server from logging.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-278981</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where DNS domain resolutions experienced intermittent
|
||||||
|
delays due to the firewall not connecting to the DNS Security cloud.
|
||||||
|
</div>
|
||||||
|
<div class="p">
|
||||||
|
To use this fix, enable DNS monitoring on the dataplane via the CLI
|
||||||
|
command
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>debug dnsproxyd enable-rtsig-health-monitor yes</span
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
<div class="p">
|
||||||
|
To show the current setting, run the CLI command
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>debug dnsproxyd enable-rtsig-health-monitor show</span
|
||||||
|
>. If the
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>cfg.general.dns-rtsig-monitor-interval</span
|
||||||
|
>
|
||||||
|
shows a non-zero value, DNS monitoring is enabled.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-276276</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-450 firewalls only</tt>) Fixed an issue where,
|
||||||
|
after an upgrade, data that was excluded using the query builder in a
|
||||||
|
custom report was still visible in the report, and the logs displayed
|
||||||
|
errors related to invalid threat names being queried.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-275601</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, when Panorama was not internet connected and you
|
||||||
|
attempted to upload images to managed firewalls using the
|
||||||
|
<span class="ph uicontrol">Validate</span> option, the upload failed
|
||||||
|
with the error
|
||||||
|
<span class="ph uicontrol"
|
||||||
|
>Failed to create multi-upload job. No valid software deploy targets
|
||||||
|
found</span
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-274806</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-5250 firewalls only</tt>) Fixed an issue where
|
||||||
|
IPv6 pings experienced a high number of dropped packets when forwarded
|
||||||
|
to another dataplane, which resulted in ping failures. This occurred
|
||||||
|
when initiating a ping to the link local address of the firewall and
|
||||||
|
the packet drop percentage depended on the number of dataplanes.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-274496</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the root partition reached 100% which caused the
|
||||||
|
system to become non-functional and fail over even when aggressive
|
||||||
|
cleaning was enabled.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-272812</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where SNMP monitoring of tunnel interfaces displayed
|
||||||
|
zero values for received bytes and packets.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-271560</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where DNS requests to malware sites were not blocked as
|
||||||
|
expected, and the
|
||||||
|
<span class="ph systemoutput">dns-security-categories log-level</span>
|
||||||
|
and action displayed default values instead of
|
||||||
|
<span class="ph systemoutput">unavailable</span>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-271215</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
A fix was made to address
|
||||||
|
<a
|
||||||
|
class="xref"
|
||||||
|
href="https://security.paloaltonetworks.com/CVE-2025-4230"
|
||||||
|
title=""
|
||||||
|
data-scope="external"
|
||||||
|
data-format="html"
|
||||||
|
data-type=""
|
||||||
|
target="_blank"
|
||||||
|
>CVE-2025-4230</a
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-270379</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where socket files created in the /tmp directory were
|
||||||
|
not cleared.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-269155</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where an OOM condition occurred, which caused processes
|
||||||
|
to stop responding.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-269139</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>Firewalls with DPDK enabled in Azure, GCP, AWS, and KVM
|
||||||
|
environments only</tt
|
||||||
|
>) Fixed an issue where, after an upgrade to PAN-OS 11.1.4, the
|
||||||
|
<span class="ph uicontrol">mac receive error</span> counter increased
|
||||||
|
without an error even though traffic was not impacted.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-268922</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-3220 firewalls in HA configurations only</tt>)
|
||||||
|
Fixed an intermittent issue where the firewalls went out of sync after
|
||||||
|
a configuration push from Panorama.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-268680</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>configd</a
|
||||||
|
>
|
||||||
|
process stopped responding when a configuration merge operation
|
||||||
|
changed.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-268032</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where importing a device configuration into Panorama
|
||||||
|
failed with a validation error if the configuration included a shared
|
||||||
|
gateways containing NAT/PBF rules.
|
||||||
|
</div>
|
||||||
|
<div class="p">To use this fix:</div>
|
||||||
|
<ol class="ol">
|
||||||
|
<li class="li">
|
||||||
|
Enable the configuration. Commit failures may occur if the device is
|
||||||
|
not able to support the number of objects.
|
||||||
|
</li>
|
||||||
|
<li class="li">Export and push the device group only.</li>
|
||||||
|
<li class="li">Push the template.</li>
|
||||||
|
</ol>
|
||||||
|
<div class="p">
|
||||||
|
Note: This fix is supported on PAN-OS 10.2 and later releases.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-264982</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>VM-Series firewalls on Kernel-based Virtual Machine (KVM) only</tt
|
||||||
|
>) Fixed an issue where the firewall entered maintenance mode after an
|
||||||
|
auto-commit when sending an ARP packet through the loopback interface
|
||||||
|
using an IPv6 address.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-263504</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where exporting managed device information from
|
||||||
|
Panorama in CSV format included extraneous characters.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-260661</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where daily email reports generated from the custom
|
||||||
|
report did not display the report details in PDF or CSV files.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-209516</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, when creating an interface, an error occurred
|
||||||
|
when you clicked <span class="ph uicontrol">OK</span> without
|
||||||
|
providing a value in the <span class="ph uicontrol">Tag</span> field
|
||||||
|
even though the field was not displayed as mandatory.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,650 @@
|
|||||||
|
<table class="table colsep rowsep table-striped">
|
||||||
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||||
|
|
||||||
|
<colgroup>
|
||||||
|
<col style="width: 25%" />
|
||||||
|
<col style="width: 75%" />
|
||||||
|
</colgroup>
|
||||||
|
<thead class="thead">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||||
|
</th>
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Description</b></div>
|
||||||
|
</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
|
||||||
|
<tbody class="tbody">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-303737</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where XML API commands failed with a
|
||||||
|
<span class="ph systemoutput">Method not found (policy_xml)</span>
|
||||||
|
error in dagger.log. The issue was due to session-distribution
|
||||||
|
commands in dagger files handling.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-300916</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Panorama management servers failed to forward
|
||||||
|
syslog messages via TLS to a syslog server when DNS resolution for
|
||||||
|
IPv6 addresses failed, and the system did not automatically fall back
|
||||||
|
to IPv4.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-300906</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where XML API commands failed with a
|
||||||
|
<span class="ph systemoutput">Method not found (policy_xml)</span>
|
||||||
|
error in dagger.log. The issue was due to missing XML-related
|
||||||
|
functions for inline-cloud-proxy.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-300837</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where firewalls experienced multiple reboots due to the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>pan_task</a
|
||||||
|
>
|
||||||
|
process restarting with a SIGSEGV signal. This occurred because the
|
||||||
|
client-to-firewall side assumed TLS 1.3 for the firewall-server side.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-300612</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-7500 firewalls only</tt>) Fixed an issue where
|
||||||
|
the firewall incorrectly reported the speed of 400G interfaces as 1G
|
||||||
|
when queried using SNMP
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-300096</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a local commit on a firewall breaks template
|
||||||
|
stack overrides, preventing the enabling of LACP (Link Aggregation
|
||||||
|
Control Protocol). After a local commit, the LACP enable check was
|
||||||
|
unexpectedly unchecked, causing an outage. Attempting to re-enable
|
||||||
|
LACP through the web interface was unsuccessful, requiring manual
|
||||||
|
removal of the LACP configuration from the Panorama CLI.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-299815</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on multi-vsys firewalls where a host was not removed
|
||||||
|
from the quarantine list after receiving a redistribution message from
|
||||||
|
Panorama. This occurred when Panorama was configured to redistribute
|
||||||
|
quarantine messages to a firewall cluster, and the GlobalProtect
|
||||||
|
configuration and redistribution were built out in a vsys other than
|
||||||
|
vsys1.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-299785</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-7500 and PA-5450 firewalls in FIPS-CC mode</tt>)
|
||||||
|
Fixed an issue where the affected firewalls would boot into
|
||||||
|
maintenance mode when a reboot was initiated from the web interface.
|
||||||
|
This was due to a device reboot triggering a power down to all slots,
|
||||||
|
leading to maintenance mode. A hard reboot would allow the firewall to
|
||||||
|
boot normally.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-299772</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>VM-Series firewalls in active/passive configurations only</tt
|
||||||
|
>) Fixed an issue where, after an HA failover event, the newly active
|
||||||
|
firewall DHCP client interfaces failed to obtain IP addresses
|
||||||
|
automatically. This occurred because the DHCP client processes did not
|
||||||
|
initiate the necessary DHCP discover or renew requests
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-298872</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>PA-400 Series firewalls in HA configurations only</tt
|
||||||
|
>) Fixed an issue where ports went down after an HA failover.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-298654</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall generated false positive threat logs
|
||||||
|
during updates to a large domain list (EDL) when a DNS lookup for a
|
||||||
|
domain being added or removed occurred during the update process. This
|
||||||
|
resulted in a threat log being generated for a different, unrelated
|
||||||
|
domain that remained on the list.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-298505</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after upgrading an HA pair of PA-7050 firewalls,
|
||||||
|
the vsys ID changed in sequence, causing autocommit failures with
|
||||||
|
validation errors. This occurred when the multi-vsys firewall had
|
||||||
|
virtual systems created and pushed from Panorama, and the vsys ID was
|
||||||
|
not in a correct sequence because the unused vsys was deleted from
|
||||||
|
Panorama and pushed to devices.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-297972</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a dataplane crash occurred when traffic matched
|
||||||
|
Inline Cloud Analysis prefiltering signatures, even when Inline Cloud
|
||||||
|
Analysis features were not enabled.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-297797</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, during a refresh of a large External Dynamic
|
||||||
|
List (EDL), traffic that matched a domain on the list was incorrectly
|
||||||
|
identified as a different domain, which resulted in false positive
|
||||||
|
threat logs.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-297759</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on PA-7500 firewalls running in a cluster where
|
||||||
|
sub-interfaces were not discoverable via SNMP, which prevented proper
|
||||||
|
monitoring and statistics collection for sub-interfaces using
|
||||||
|
SNMP-based tools.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-297708</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a long-lived session with many Machine Learning
|
||||||
|
(ML) model triggers caused a memory leak of feature states associated
|
||||||
|
with the ML model runs. This resulted in Spyware_State failure
|
||||||
|
increases, allocation max outs, and impaired policy matching.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-297610</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall became unresponsive after an upgrade
|
||||||
|
due to the <span class="ph systemoutput">fsck</span> command scanning
|
||||||
|
drive partitions in parallel with the root partition, which caused the
|
||||||
|
process to take an extended amount of time.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-296490</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">FIPS CC mode enabled only</tt>) Fixed an issue
|
||||||
|
where Panorama on GCP rebooted every hour after upgrading to
|
||||||
|
11.1.6-h10. Panorama will run for up to an hour and then crash.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-296453</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where decryption exclusion lists were not working for
|
||||||
|
untrusted certificates, and SSL sessions were still being decrypted
|
||||||
|
even after adding them to the exclusion list. This occurred because
|
||||||
|
the firewall was not adding sessions to the exclude cache until after
|
||||||
|
receiving a non-RFC alert (BadCertificate) from the server. The fix
|
||||||
|
ensures that the first session is added to the exclude cache, allowing
|
||||||
|
subsequent sessions to skip decryption. This issue affects firewalls
|
||||||
|
configured as clients in server-client communication.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-295221</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after upgrading Panorama and Log Collectors from
|
||||||
|
PAN-OS 10.2.9 to PAN-OS 11.1.6-h6, Traffic and Threat logs were not
|
||||||
|
forwarded to a Splunk server over UDP.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-294893</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where firewalls with the
|
||||||
|
<span class="ph uicontrol"
|
||||||
|
>Send handshake messages to CTD for inspection</span
|
||||||
|
>
|
||||||
|
setting enabled caused incorrect Security policy rules to be matched.
|
||||||
|
Specifically, traffic not identified as openai-base or openai-chatgpt
|
||||||
|
applications was incorrectly matched by the
|
||||||
|
ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected
|
||||||
|
response page for blocked URLs was not displayed.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-293848</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Panorama failed to push the default value of
|
||||||
|
<span class="ph uicontrol">None</span> for the secondary NTP server
|
||||||
|
address to managed firewalls, resulting in a commit validation error.
|
||||||
|
This occurred even when configuring the secondary NTP server address
|
||||||
|
as <span class="ph uicontrol">None</span> in Panorama's web interface,
|
||||||
|
and affected both newly deployed and long-standing production
|
||||||
|
firewalls after upgrading.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-292447</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Panorama did not display data in the
|
||||||
|
<span class="ph uicontrol">Feature Adoption</span> tab in Strata Cloud
|
||||||
|
Manager due to the system creating and deleting a CLI user for each
|
||||||
|
interval instead of reusing a permanent CLI user for telemetry.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-292393</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where TFTP file transfers intermittently timed out in
|
||||||
|
active-active HA pairs when the TFTP control channel was processed by
|
||||||
|
one firewall and the data channel was processed by the other. This
|
||||||
|
occurred because the firewall receiving the data channel failed to
|
||||||
|
match the predicted session due to asynchronous processing of HA
|
||||||
|
messages.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-291716</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where PA-460 firewalls experienced out-of-memory (OOM)
|
||||||
|
conditions, leading to device crashes and reboots.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-291174</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Real Time Streaming Protocol (RTSP) video streams
|
||||||
|
did not work when connected through GlobalProtect due to the firewall
|
||||||
|
blocking 200 OK responses. This occurred because of incorrect NAT
|
||||||
|
translations for the 200 OK message from the server.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-291067</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>devsrvr</a
|
||||||
|
>
|
||||||
|
process periodically exceeded its virtual memory limit and restarted,
|
||||||
|
which led to intermittent outages.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-290453</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where PA-7500 firewalls experienced silent traffic
|
||||||
|
drops. During migration from PA-7050 to PA-7500 firewalls connected in
|
||||||
|
series, intermittent connection losses occurred for some applications.
|
||||||
|
Traffic leaving the PA-7050 was not received or processed by the
|
||||||
|
PA-7500, even with direct connections and replaced cables/SFPs. Global
|
||||||
|
counters did not indicate any drops on the PA-7500.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-289714</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Prisma Access only</tt>) Fixed an issue where
|
||||||
|
persistent commit failures occurred due to a missing transformation
|
||||||
|
script when downgrading from PAN-OS 10.2.0 to PAN-OS 10.1.0.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-288388</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after an EDL certificate update or repository
|
||||||
|
migration, authentication failures caused the firewall to not fall
|
||||||
|
back to the last successfully cached EDL entries, which led to policy
|
||||||
|
rules that referenced the EDL to not be enforced.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287803</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after upgrading firewalls to PAN-OS 11.1.6-h1,
|
||||||
|
certain websites weren't accessible when the accumulation proxy was
|
||||||
|
enabled. The proxy did not use the same DF bit state as the original
|
||||||
|
traffic, causing it to be fragmented and dropped elsewhere in the
|
||||||
|
network.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287693</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Panorama did not use the configured proxy
|
||||||
|
settings to check WildFire private cloud content and instead connected
|
||||||
|
directly to the WildFire device using the management interface. This
|
||||||
|
occurred even when
|
||||||
|
<span class="ph uicontrol">Use Proxy Settings for Private Cloud</span>
|
||||||
|
was enabled.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287622</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where IPv6 traffic was affected after upgrading the
|
||||||
|
firewall to PAN-OS 11.1.6-h4 and later versions. With SSL decryption
|
||||||
|
enabled and a decryption policy configured for the traffic, the
|
||||||
|
firewall dropped packets due to receiving a
|
||||||
|
<span class="ph systemoutput">Packet Too Big</span> ICMP message. This
|
||||||
|
occurred because the PathMTU information update was incorrect for the
|
||||||
|
TCB (pan-server) when the firewall was acting as a server.
|
||||||
|
Additionally, the flow label under the IPv6 header was set to zero
|
||||||
|
while the packet was being transmitted out of the firewall.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-285648</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the log receiver process crashed on PA-7050
|
||||||
|
firewalls due to system log processing threads becoming blocked when
|
||||||
|
the queue was full. This resulted in a heartbeat failure.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-285315</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where the log forwarding queue depth was
|
||||||
|
not accurately displayed in the logd.log files.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-285169</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where Kerberos superusers were unable to
|
||||||
|
edit policy rules because the target device tab was grayed out.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-272245</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>dnsproxy</a
|
||||||
|
>
|
||||||
|
process crashed due to memory corruption caused by a race condition
|
||||||
|
when the allow list downloading was impacted by config change.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-267704</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall did not send an ICMP error packet to
|
||||||
|
Envoy when the MSS was exceeded.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-267450</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>reportd</a
|
||||||
|
>
|
||||||
|
process stopped responding with a SIGSEGV at
|
||||||
|
<span class="ph systemoutput">schedule_report_es_response</span>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-262444</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall did not refresh the external dynamic
|
||||||
|
list due to the first entry in the list being removed from the global
|
||||||
|
external list and breaking out of the loop.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-251646</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where commits failed with the error message
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>Error: Error unserializing profile objects</span
|
||||||
|
>. This occurred due to memory allocation issues when a large number
|
||||||
|
of scan profiles were configured.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
@@ -0,0 +1,746 @@
|
|||||||
|
<table class="table colsep rowsep table-striped">
|
||||||
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||||
|
|
||||||
|
<colgroup>
|
||||||
|
<col style="width: 25%" />
|
||||||
|
<col style="width: 75%" />
|
||||||
|
</colgroup>
|
||||||
|
<thead class="thead">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||||
|
</th>
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Description</b></div>
|
||||||
|
</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
|
||||||
|
<tbody class="tbody">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-309392</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the scroll bar did not appear when editing
|
||||||
|
<span class="ph uicontrol">Destination Addresses</span> for Policy
|
||||||
|
Based forwarding policy rules.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-309379</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>logrcvr</a
|
||||||
|
>
|
||||||
|
process stopped responding on DPCs, which prevented logs from being
|
||||||
|
forwarded.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-308085</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>VM-Series firewalls in Microsoft Azure environments only</tt
|
||||||
|
>) Fixed an issue where, after resizing the VM, the HA2 link became
|
||||||
|
unstable. Frequent keep-alive failures occurred, and HA2 keep-alive
|
||||||
|
packets were simultaneously transmitted to multiple destination MAC
|
||||||
|
addresses and the peer firewall's interface MAC). This issue occurred
|
||||||
|
on firewalls with Accelerated Networking enabled.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-308060</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>Firewalls in active/active HA configurations only</tt
|
||||||
|
>) Fixed an issue where the BFD session went down and did not recover
|
||||||
|
even though the BGP remained in an established state, which caused the
|
||||||
|
firewall to cease route learning and advertisement with the peer, even
|
||||||
|
though BGP keep-alives were exchanged correctly.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-307901</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a leak in decryption counters caused resource
|
||||||
|
exhaustion, which led to a GlobalProtect service outage.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-307795</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Panorama incorrectly generated system logs
|
||||||
|
indicating a lost connection to its peer after an upgrade even when
|
||||||
|
High Availability was not configured.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-305835</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where firewalls with Memory Integrity Checking
|
||||||
|
Architecture enabled rebooted unexpectedly due to accessing an invalid
|
||||||
|
memory address. This occurred because the forwarding data structure
|
||||||
|
index exceeded its designed limit.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-305412</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the Logging Service License Status displays a
|
||||||
|
license failure when the license status transitions from valid to
|
||||||
|
expired and then back to valid even when the connection to the
|
||||||
|
Security Logging Service (SLS) was working.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-305411</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after creating a logical interface with an
|
||||||
|
assigned IP address and adding it to a virtual router, the connected
|
||||||
|
route for the interface did not appear in the
|
||||||
|
<span class="ph systemoutput">show routing route</span> CLI command
|
||||||
|
output. This occurred even when the interface was up and learning ARP
|
||||||
|
entries.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-305301</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the timing of GlobalProtect lifetime expiry or
|
||||||
|
inactivity logout notifications used for GlobalProtect SSL tunnels
|
||||||
|
could cause the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>pan_task</a
|
||||||
|
>
|
||||||
|
process to stop responding and the dataplane to restart.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-304756</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where, after you disabled the shared
|
||||||
|
optimization feature, a full configuration push to multi-vsys devices
|
||||||
|
caused a validation error.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-304636</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where BGP aggregate routes were not created and discard
|
||||||
|
routes were not installed in the routing table.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-304075</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall did not detect evasions due to TCP
|
||||||
|
checksum offloading not being enabled.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-303959</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where traffic was incorrectly identified as
|
||||||
|
unknown-tcp/unknown-udp due to App-ID resource leak and eventually
|
||||||
|
dropped.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-303954</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, when configuring Safenet HSMs in HA and
|
||||||
|
authentication HSM manually, the second HSM server failed to
|
||||||
|
authenticate due to the firewall overwriting the first HSM server's
|
||||||
|
certificate with the second HSM server's certificate.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-303627</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after committing a configuration change, the
|
||||||
|
firewall experienced traffic issues,
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>pan_task</a
|
||||||
|
>
|
||||||
|
crashes, and LACP interface failures.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-303559</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after manually creating a device telemetry
|
||||||
|
bundle, the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>hour_cli_output.txt</a
|
||||||
|
>
|
||||||
|
file within the bundle had a file size of 0 bytes. This occurred when
|
||||||
|
checking the bundle content after enabling device telemetry and
|
||||||
|
setting the device telemetry upload endpoint.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-302983</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after committing changes on Panorama, a shared
|
||||||
|
post-rule moved to the end of the
|
||||||
|
<span class="ph systemoutput">post shared rulebase</span> on the
|
||||||
|
managed device instead of remaining at the top.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-302551</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall displayed as disconnected in the SLS
|
||||||
|
due to the serial number not being retrieved
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-302428</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where daily scheduled report emails for
|
||||||
|
custom reports were delivered with no content and instead incorrectly
|
||||||
|
displayed the message
|
||||||
|
<span class="ph uicontrol">No matching data found</span>. With this
|
||||||
|
fix, the content is displayed correctly.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-302085</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where network values were not displayed in Panorama
|
||||||
|
with the error message
|
||||||
|
<span class="ph uicontrol"
|
||||||
|
>There is no value for the selected item</span
|
||||||
|
>. This was due to the device group passing vsysName in Panorama.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-301975</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
|
||||||
|
issue where the passive firewall incorrectly triggered PBP alerts even
|
||||||
|
with low packet rates.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-301937</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Microsoft Defender for Cloud detected cleartext
|
||||||
|
SSH private keys in the /var/appweb and /etc/appweb directories on
|
||||||
|
PA-VM firewalls deployed in Azure.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-301912</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Panorama stopped responding when deploying
|
||||||
|
dynamic updates to managed devices.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-301600</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on the firewall where, after upgrading Panorama, OSPF
|
||||||
|
adjacencies remained in the exchange start state, which resulted in an
|
||||||
|
incomplete routing table.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-301456</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where the
|
||||||
|
<span class="ph systemoutput">debug system reset-ztp</span> CLI
|
||||||
|
command was unavailable.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-301409</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Panorama failed to perform a selective push to a
|
||||||
|
managed device when device tags were added or modified on the policy
|
||||||
|
rules. The selective push failed with the error message
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>Failed to generate selective push configuration. Schema validation
|
||||||
|
failed. Please try a full push</span
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-300837</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where firewalls experienced multiple reboots due to the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>pan_task</a
|
||||||
|
>
|
||||||
|
process restarting with a SIGSEGV signal. This occurred because the
|
||||||
|
client-to-firewall side assumed TLS 1.3 for the firewall-server side.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-300671</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where traffic reports that were generated with
|
||||||
|
destination/source and destination/source hostnames were not displayed
|
||||||
|
in IPv4 format.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-299751</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall was unable to connect to the
|
||||||
|
Subscription License Service (SLS) due to a public and private key
|
||||||
|
pair mismatch with the device certificate.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-299622</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the MFA timestamp was not redistributed between
|
||||||
|
standalone firewalls behind an Azure load balancer after upgrading,
|
||||||
|
which resulted in users being prompted to reauthenticate multiple
|
||||||
|
times.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-297263</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-5220 firewalls only</tt>) Fixed an issue where
|
||||||
|
the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>ikemgr</a
|
||||||
|
>
|
||||||
|
process stopped responding intermittently, which caused IPSec tunnels
|
||||||
|
to go down randomly. With this fix, the IKE Security association data
|
||||||
|
structures are accessed in a thread-safe manner, and the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>ikemgr</a
|
||||||
|
>
|
||||||
|
process does not reference an invalid memory pointer during teardown
|
||||||
|
operations.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-299622</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the MFA timestamp was not redistributed between
|
||||||
|
standalone firewalls behind an Azure load balancer after upgrading,
|
||||||
|
which resulted in users being prompted to reauthenticate multiple
|
||||||
|
times.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-295796</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall intermittently failed to forward
|
||||||
|
VXLAN GARP packets, which led to connectivity issues for wireless
|
||||||
|
clients in environments that used VXLAN tunnels for wireless access
|
||||||
|
points.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-292447</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Panorama did not display data in the
|
||||||
|
<span class="ph uicontrol">Feature Adoption</span> tab in Strata Cloud
|
||||||
|
Manager due to the system creating and deleting a CLI user for each
|
||||||
|
interval instead of reusing a permanent CLI user for telemetry.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-291945</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on PA-5220 firewalls where denied traffic logs
|
||||||
|
incorrectly displayed a byte count of 0. This occurred because the
|
||||||
|
bytes_sent value was stored in the most significant bits of
|
||||||
|
u_bytes_sent, resulting in a zero value when a small value was
|
||||||
|
assigned to u_bytes_sent.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-285208</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall did not automatically recover after
|
||||||
|
a machine check exception (MCE) occurred.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-283237</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where traffic logs incorrectly displayed the action as
|
||||||
|
<span class="ph uicontrol">allow</span> for traffic matching a
|
||||||
|
Security policy rule configured with the action set to
|
||||||
|
<span class="ph uicontrol">deny</span>. This issue occurred due to the
|
||||||
|
child session being used for policy rule lookup when a configuration
|
||||||
|
update triggered a rematch if the FTP-data application was not in the
|
||||||
|
rule.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-281588</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where packet buffer depletion occurred due to the a
|
||||||
|
high number of
|
||||||
|
<span class="ph systemoutput">tcp_pkt_queued</span> packets when Jumbo
|
||||||
|
was enabled.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-269535</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the mib ID returned an incorrect value via SNMP.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-263691</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall rebooted unexpectedly due to a
|
||||||
|
memory leak in the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>all_task</a
|
||||||
|
>
|
||||||
|
process.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-262831</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-5400f Series firewalls only</tt>) Fixed an
|
||||||
|
intermittent issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>all_task</a
|
||||||
|
>
|
||||||
|
process stopped responding, which caused the firewall to restart.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-241694</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where memory leaks related to the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>devsrvr</a
|
||||||
|
>
|
||||||
|
process occurred when downloading and pushing updates from the App-ID
|
||||||
|
Cloud Engine to the dataplane.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-185731</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall was unable to parse the URL path and
|
||||||
|
host when the host header was located in a different packet, which
|
||||||
|
resulted in the firewall not logging the URL path in the first packet.
|
||||||
|
The fix is disabled by default. The following CLI commands can be used
|
||||||
|
to enable/disable the feature:
|
||||||
|
<ul id="panos-addressed-issues-11.1.13-h1_ul-fmq_kc3_yhc" class="ul">
|
||||||
|
<li class="li">
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>set system setting ctd url-crosspkt-host-path-caching
|
||||||
|
enable</span
|
||||||
|
>
|
||||||
|
</li>
|
||||||
|
<li class="li">
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>set system setting ctd url-crosspkt-host-path-caching
|
||||||
|
disable</span
|
||||||
|
>
|
||||||
|
</li>
|
||||||
|
<li class="li">
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>set system setting ctd url-crosspkt-host-path-caching
|
||||||
|
default</span
|
||||||
|
>
|
||||||
|
</li>
|
||||||
|
</ul>
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
@@ -0,0 +1,630 @@
|
|||||||
|
<table class="table colsep rowsep table-striped">
|
||||||
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||||
|
|
||||||
|
<colgroup>
|
||||||
|
<col style="width: 25%" />
|
||||||
|
<col style="width: 75%" />
|
||||||
|
</colgroup>
|
||||||
|
<thead class="thead">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||||
|
</th>
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Description</b></div>
|
||||||
|
</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
|
||||||
|
<tbody class="tbody">
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-314319</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall experienced increased packet drops
|
||||||
|
and slower performance after an upgrade due to high burst traffic.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b"></b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p"></div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-313572</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
||||||
|
the dataplane restarted due to a segmentation fault.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-312706</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewalls restarted due to a function lacking
|
||||||
|
a NULL-pointer sanity check.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-311524</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where config-lock was not displayed on the web
|
||||||
|
interface.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-311250</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Panorama appliances and Log Collectors only</tt>)
|
||||||
|
Fixed an issue where logs from multiple devices were not visible on
|
||||||
|
Panorama even though the Elasticsearch health status on the dedicated
|
||||||
|
Log Collectors appeared green.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-311073</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>Panorama managed firewalls in HA configurations only</tt
|
||||||
|
>) Fixed an issue where firewalls incorrectly updated the modified
|
||||||
|
date and MD5 hash of policy rules during an HA sync commit job or a
|
||||||
|
subsequent local commit, even when no changes were made to the policy
|
||||||
|
rules.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-308786</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue where
|
||||||
|
traffic log queries using the
|
||||||
|
<span class="ph systemoutput">device_name</span> filter returned no
|
||||||
|
results, and, additionally complex log queries that included negation
|
||||||
|
operators produced incorrect outputs.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-308654</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the Elasticsearch Close Indices process closed
|
||||||
|
more indices than expected and dropped the number of open shards below
|
||||||
|
the minimum of 800 per Elasticsearch instance. This occurred because
|
||||||
|
the process did not correctly account for the number of Elasticsearch
|
||||||
|
instances when calculating the maximum number of allowed open shards.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-307702</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
|
||||||
|
issue where traffic passing through AE layer 2 interfaces was
|
||||||
|
interrupted during HA failovers.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-307597</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where BGP peering sessions between a hub firewall and a
|
||||||
|
satellite firewall over GlobalProtect LSVPN failed to connect.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-306555</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall stopped responding, which led to
|
||||||
|
service outages.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-306451</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">VM-Series firewalls on AWS environments only</tt>)
|
||||||
|
Fixed an issue where, after upgrading the firewall to an affected
|
||||||
|
release, GlobalProtect clients did not connect with IPSec and instead
|
||||||
|
connected using SSL due to traffic flow being disabled when checking
|
||||||
|
for health check packets.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-305700</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a reboot loop occurred when OSPF interfaces were
|
||||||
|
configued with a link type of
|
||||||
|
<span class="ph uicontrol">point-to-point</span>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-305552</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where DLP logs displayed an incorrect file type when
|
||||||
|
the firewall did not set the file type field.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-304746</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>Panorama appliances and Panorama virtual appliances only</tt
|
||||||
|
>) Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>configd</a
|
||||||
|
>
|
||||||
|
process restarted when committing and pushing configuration for a new
|
||||||
|
WildFire cluster.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-304718</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where OSPF and BGP outages occurred due to an
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>all_task</a
|
||||||
|
>
|
||||||
|
process restart during clientless VPN content rewrite processing.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-304696</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the Cloud User-ID connection timed out because
|
||||||
|
the firewall took too long to process the OCSP response.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-304576</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall entered a non-functional state due
|
||||||
|
to segmentation fault within the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>all_pktproc</a
|
||||||
|
>
|
||||||
|
process that was caused by a session that involved http2 cleartext
|
||||||
|
traffic
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-303745</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where inter-dataplane forwarding did not work for
|
||||||
|
sessions ingressing on Slot 2, which resulted in intermittent ping
|
||||||
|
failures to interfaces on Network Card 2 when traffic was forwarded to
|
||||||
|
Slot 3. Note: With this fix, after a slot restart, the global counter
|
||||||
|
will still show dot1q errors for a short period.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-303722</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on the firewall where configuring spyware and
|
||||||
|
vulnerability profiles in Security policy rules caused a memory leak
|
||||||
|
in the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>devsrvr</a
|
||||||
|
>
|
||||||
|
process with each configuration commit.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-301731</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, when the firewall was unable to establish an SCM
|
||||||
|
connection due to the discovery service returning a 404 error when the
|
||||||
|
device was not yet known to the service, the firewall did not retry
|
||||||
|
the attempt as expected.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-300664</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on the Panorama and firewall web interface where
|
||||||
|
Applications pages became unresponsive after activating the SaaS
|
||||||
|
Inline license.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-299705</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where API calls to commit changes on Panorama
|
||||||
|
intermittently failed when using the XML API with refresh=<span
|
||||||
|
class="ph systemoutput"
|
||||||
|
>no</span
|
||||||
|
>, which caused changes to not be applied to the partial-commit
|
||||||
|
configuration.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-299495</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>show system setting ssl-decrypt certificate</span
|
||||||
|
>
|
||||||
|
CLI command did not display certificates when XML output was enabled.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-298945</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where OSCP HTTP POST requests were not formatted
|
||||||
|
correctly, which caused failures with strict responders.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b"> PAN-297540 </b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>Panorama managed firewalls in HA configurations only</tt
|
||||||
|
>) Fixed an issue where the HA-Link-Monitor configuration pushed from
|
||||||
|
Panorama was converted to a local configuration on the peer device
|
||||||
|
after an HA sync, which caused subsequent Panorama pushes of link
|
||||||
|
monitor changes to be flagged as overwritten, and a forced template
|
||||||
|
push or manual clearing of the configuration on the firewall was
|
||||||
|
required.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-296694</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall rebooted due to the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>useridd</a
|
||||||
|
>
|
||||||
|
process repeatedly restarting during an IP-port data type writes to
|
||||||
|
the redis from multiple sources such as TSA or XML in a scale
|
||||||
|
environment.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-295803</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Addressed a memory leak issue under sc3 and automatic commit recovery
|
||||||
|
(ACR) code path.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-295802</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a memory leak related to the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>configd</a
|
||||||
|
>
|
||||||
|
process occurred.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-294379</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, when SD-WAN SaaS Application path monitoring
|
||||||
|
failed for all interfaces, the firewall stopped forwarding traffic
|
||||||
|
even if the ISP links and default gateway probing were still active.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-292306</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>authd</a
|
||||||
|
>
|
||||||
|
process stopped handling RADIUS authentication requests and required a
|
||||||
|
restart.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-290938</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where multiple memory leaks occurred related to the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>configd</a
|
||||||
|
>
|
||||||
|
process.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-288175</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Addressed a stack buffer overflow memory leak under plugin management
|
||||||
|
code path.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287159</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where file uploads to Dropbox stalled when using a
|
||||||
|
PA-CPT device with MLC2 and DLP Mirror mode enabled for HTTP2 traffic.
|
||||||
|
This occurred because the proxy was unable to decrement packet counts
|
||||||
|
properly when the queue was large, resulting in a receive window size
|
||||||
|
of 0 for the parent session.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-279364</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">VM-Series firewalls with multiple NICs only</tt>)
|
||||||
|
Fixed an issue were the queue count in the task dump displayed an
|
||||||
|
incorrect number of queues for SR-IOV interfaces due to the queue
|
||||||
|
mapping logic incorrectly using a non-multi-NIC function.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-278688</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where DNS Security threat logs were not displayed on
|
||||||
|
the firewall when packet capture was enabled and the domain name
|
||||||
|
length was 62 characters.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-274742</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
||||||
|
the <span class="ph systemoutput">task-queue dump</span> CLI command
|
||||||
|
returned incorrect information in multi-nic mode.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-259785</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>devsrvr</a
|
||||||
|
>
|
||||||
|
process restarted and created a core dump because two threads did not
|
||||||
|
terminate correctly.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
@@ -0,0 +1,229 @@
|
|||||||
|
<table class="table colsep rowsep table-striped">
|
||||||
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||||
|
|
||||||
|
<colgroup>
|
||||||
|
<col style="width: 25%" />
|
||||||
|
<col style="width: 75%" />
|
||||||
|
</colgroup>
|
||||||
|
<thead class="thead">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||||
|
</th>
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Description</b></div>
|
||||||
|
</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
|
||||||
|
<tbody class="tbody">
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b"> PAN-316911</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>VM-Series firewalls on Amazon Web Services (AWS) environments
|
||||||
|
only</tt
|
||||||
|
>) Fixed an issue where a newly bootstrapped firewall required a
|
||||||
|
management server restart, relicensing, or license push from Panorama
|
||||||
|
to invoke the device certificate.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-315176</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Added an enable and disable CLI command to address an issue where the
|
||||||
|
firewall experienced increased packet drops and slower performance
|
||||||
|
after an upgrade due to high burst traffic.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-314061</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where traffic was disrupted during IPSec rekey
|
||||||
|
operations due to a 2 second delay in sending the DELETE message for
|
||||||
|
the previous Security Association (SA) to the peer gateway after a new
|
||||||
|
SA was negotiated.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-313850</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>PA-1400 Series firewalls in HA configurations only</tt
|
||||||
|
>) Fixed an issue where a split-brain condition occurred and HA1/HA2
|
||||||
|
links went down while upgrading when the HA configuration used
|
||||||
|
dataplane interfaces for HA1 and a combination of HSCI and Ethernet
|
||||||
|
interfaces for HA2.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-313623</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<span class="ph systemoutput">/opt/pancfg/mgmt/ssl/private/</span>
|
||||||
|
directory on Palo Alto Networks devices with TPM support became 100%
|
||||||
|
utilized due to an accumulation of undeleted
|
||||||
|
<span class="ph systemoutput">.pub_pem</span> files. This occurred
|
||||||
|
because executing the
|
||||||
|
<span class="ph systemoutput">show device-certificate status</span>
|
||||||
|
CLI command initiated a process that generated these files but failed
|
||||||
|
to remove them, which prevented the fetching of new device
|
||||||
|
certificates.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-311285</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Firewalls in HA conditions only</tt>) Fixed an
|
||||||
|
issue where a memory leak occurred related to the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>ospfd</a
|
||||||
|
>
|
||||||
|
process, which caused RAM usage to continuously increase on active
|
||||||
|
devices in an HA cluster until the device stopped responding, even
|
||||||
|
after an HA failover.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-308507</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Panorama managed firewalls only</tt>) Fixed an
|
||||||
|
issue where the firewall intermittently failed to maintain active log
|
||||||
|
forwarding streams to Cortex Data Lake even when duplicate logging and
|
||||||
|
enhanced application logging were enabled.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-309300</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where management plane system resources configuration
|
||||||
|
size exceeded 28 MB for over 4 hours, and the following error message
|
||||||
|
was displayed:
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>Configuration size reaching device capacity limit</span
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-302654</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>Firewalls in active/passive HA configurations only</tt
|
||||||
|
>) Fixed an issue where, when the HA configuration had multiple
|
||||||
|
logical routers, static or connected routes redistributed into OSPF
|
||||||
|
aged out in the LSDB, which caused the routes to be removed on peer
|
||||||
|
OSPF neighbors.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b"> PAN-300423</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Data Processing Cards (DPCs) installed in slots 5
|
||||||
|
and 6 remained stuck in a starting state with the error
|
||||||
|
<span class="ph uicontrol"
|
||||||
|
>Signal detected for port xeS5-DP0 but Link Down</span
|
||||||
|
>
|
||||||
|
alerts, which resulted in device instability.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-298617</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Optimized the commit workflow to reduce the size of the effective
|
||||||
|
configuration, resulting in lower memory consumption.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-296202</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>Firewalls in active/active HA configurations only</tt
|
||||||
|
>) Added a log enhancement to capture an issue where, when a commit
|
||||||
|
operation was in progress, newly deployed IP address tags that used
|
||||||
|
the XML API were not immediately reflected in address group
|
||||||
|
resolution, which delayed IP address mapping to address groups and
|
||||||
|
caused traffic to be incorrectly allowed or denied.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b"> PAN-273158</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-7000 Series firewalls only</tt>) Fixed an issue
|
||||||
|
where an incorrect ASIC configuration caused silent packet drops or
|
||||||
|
application slowness when receiving a mix of jumbo and non-jumbo
|
||||||
|
packets.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
+18
-18
@@ -246,50 +246,50 @@
|
|||||||
},
|
},
|
||||||
"11.1.9": {
|
"11.1.9": {
|
||||||
"addressed": "",
|
"addressed": "",
|
||||||
"known": ""
|
"known": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-9-known-and-addressed-issues/pan-os-11-1-9-known-issues"
|
||||||
},
|
},
|
||||||
"11.1.10": {
|
"11.1.10": {
|
||||||
"addressed": "",
|
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-10-known-and-addressed-issues/pan-os-11-1-10-addressed-issues",
|
||||||
"known": ""
|
"known": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-10-known-and-addressed-issues/pan-os-11-1-10-known-issues"
|
||||||
},
|
},
|
||||||
"11.1.10-h1": {
|
"11.1.10-h1": {
|
||||||
"addressed": "",
|
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-10-known-and-addressed-issues/pan-os-11-1-10-h1-addressed-issues",
|
||||||
"known": ""
|
"known": ""
|
||||||
},
|
},
|
||||||
"11.1.10-h4": {
|
"11.1.10-h4": {
|
||||||
"addressed": "",
|
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-10-known-and-addressed-issues/pan-os-11-1-10-h4-addressed-issues",
|
||||||
"known": ""
|
"known": ""
|
||||||
},
|
},
|
||||||
"11.1.10-h5": {
|
"11.1.10-h5": {
|
||||||
"addressed": "",
|
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-10-known-and-addressed-issues/pan-os-11-1-10-h5-addressed-issues",
|
||||||
"known": ""
|
"known": ""
|
||||||
},
|
},
|
||||||
"11.1.10-h7": {
|
"11.1.10-h7": {
|
||||||
"addressed": "",
|
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-10-known-and-addressed-issues/pan-os-11-1-10-h7-addressed-issues",
|
||||||
"known": ""
|
"known": ""
|
||||||
},
|
},
|
||||||
"11.1.10-h9": {
|
"11.1.10-h9": {
|
||||||
"addressed": "",
|
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-10-known-and-addressed-issues/pan-os-11-1-10-h9-addressed-issues",
|
||||||
"known": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-9-known-and-addressed-issues/pan-os-11-1-9-known-issues"
|
"known": ""
|
||||||
},
|
},
|
||||||
"11.1.10-h10": {
|
"11.1.10-h10": {
|
||||||
"addressed": "",
|
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-10-known-and-addressed-issues/pan-os-11-1-10-h10-addressed-issues",
|
||||||
"known": ""
|
"known": ""
|
||||||
},
|
},
|
||||||
"11.1.10-h12": {
|
"11.1.10-h12": {
|
||||||
"addressed": "",
|
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-10-known-and-addressed-issues/pan-os-11-1-10-h12-addressed-issues",
|
||||||
"known": ""
|
"known": ""
|
||||||
},
|
},
|
||||||
"11.1.10-h21": {
|
"11.1.10-h21": {
|
||||||
"addressed": "",
|
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-10-known-and-addressed-issues/pan-os-11-1-10-h21-addressed-issues",
|
||||||
"known": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-10-known-and-addressed-issues/pan-os-11-1-10-known-issues"
|
"known": ""
|
||||||
},
|
},
|
||||||
"11.1.11": {
|
"11.1.11": {
|
||||||
"addressed": "",
|
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-11-known-and-addressed-issues/pan-os-11-1-11-addressed-issues",
|
||||||
"known": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-11-known-and-addressed-issues/pan-os-11-1-11-known-issues"
|
"known": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-11-known-and-addressed-issues/pan-os-11-1-11-known-issues"
|
||||||
},
|
},
|
||||||
"11.1.12": {
|
"11.1.12": {
|
||||||
"addressed": "",
|
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-12-known-and-addressed-issues/pan-os-11-1-12-addressed-issues",
|
||||||
"known": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-12-known-and-addressed-issues/pan-os-11-1-12-known-issues"
|
"known": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-12-known-and-addressed-issues/pan-os-11-1-12-known-issues"
|
||||||
},
|
},
|
||||||
"11.1.13": {
|
"11.1.13": {
|
||||||
@@ -297,15 +297,15 @@
|
|||||||
"known": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-13-known-and-addressed-issues/pan-os-11-1-13-known-issues"
|
"known": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-13-known-and-addressed-issues/pan-os-11-1-13-known-issues"
|
||||||
},
|
},
|
||||||
"11.1.13-h1": {
|
"11.1.13-h1": {
|
||||||
"addressed": "",
|
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-13-known-and-addressed-issues/pan-os-11-1-13-h1-addressed-issues",
|
||||||
"known": ""
|
"known": ""
|
||||||
},
|
},
|
||||||
"11.1.13-h2": {
|
"11.1.13-h2": {
|
||||||
"addressed": "",
|
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-13-known-and-addressed-issues/pan-os-11-1-13-h2-addressed-issues",
|
||||||
"known": ""
|
"known": ""
|
||||||
},
|
},
|
||||||
"11.1.13-h3": {
|
"11.1.13-h3": {
|
||||||
"addressed": "",
|
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-13-known-and-addressed-issues/pan-os-11-1-13-h3-addressed-issues",
|
||||||
"known": ""
|
"known": ""
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user