Add PAN-OS 11.0 known issues
This commit is contained in:
@@ -0,0 +1,726 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.0
|
||||||
|
---
|
||||||
|
|
||||||
|
## WF500-5632
|
||||||
|
|
||||||
|
The number of registered WildFire appliances
|
||||||
|
reported in Panorama (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the
|
||||||
|
current status of connected WildFire appliances.
|
||||||
|
|
||||||
|
## PAN-260851
|
||||||
|
|
||||||
|
From the NGFW or Panorama CLI, you can override the existing
|
||||||
|
application tag even if Disable Override is enabled for the
|
||||||
|
application (ObjectsApplications) tag.
|
||||||
|
|
||||||
|
## PAN-250062
|
||||||
|
|
||||||
|
Device telemetry might fail at configured intervals due to bundle generation issues.
|
||||||
|
|
||||||
|
## PAN-234408
|
||||||
|
|
||||||
|
Enterprise DLP cannot detect and block non-file based traffic for
|
||||||
|
ChatGPT from traffic forwarded to the DLP cloud service from an
|
||||||
|
NGFW.
|
||||||
|
|
||||||
|
## PAN-234015
|
||||||
|
|
||||||
|
The X-Forwarded-For (XFF) value is not displayed in traffic logs.
|
||||||
|
|
||||||
|
## PAN-243951
|
||||||
|
|
||||||
|
On the Panorama management sever in an active/passive High
|
||||||
|
Availability (HA) configuration, managed devices (PanoramaManaged DevicesSummary) display as out-of-sync
|
||||||
|
on the passive HA peer when configuration changes are made to the
|
||||||
|
SD-WAN (PanoramaSD-WAN) configuration on the active HA peer.
|
||||||
|
|
||||||
|
Workaround: Manually synchronize the Panorama HA peers.
|
||||||
|
|
||||||
|
1. Log in to the Panorama web
|
||||||
|
interface on the active HA peer.
|
||||||
|
2. Select Commit and Commit to
|
||||||
|
Panorama the SD-WAN configuration changes on
|
||||||
|
the active HA peer.
|
||||||
|
On the passive HA peer, select PanoramaManaged DevicesSummary and observe that the managed devices are now
|
||||||
|
out-of-sync.
|
||||||
|
3. Log in to the primary HA peer Panorama CLI and
|
||||||
|
trigger a manual synchronization between the active and
|
||||||
|
secondary HA peers.
|
||||||
|
request high-availability sync-to-remote
|
||||||
|
running-config
|
||||||
|
4. Log back in to the active HA peer Panorama web interface and
|
||||||
|
select CommitPush to Devices and Push.
|
||||||
|
|
||||||
|
## PAN-242910
|
||||||
|
|
||||||
|
On the Panorama management server, Panorama administrators (PanoramaAdministrators) that are assigned a custom Panorama admin role (PanoramaAdmin Roles) with Push All Changes enabled
|
||||||
|
are unable to push configuration changes to managed firewalls when
|
||||||
|
Managed Devices and Push For
|
||||||
|
Other Admins are disabled.
|
||||||
|
|
||||||
|
## PAN-241041
|
||||||
|
|
||||||
|
On the Panorama management server exporting template or template
|
||||||
|
stack variables (PanoramaTemplates) in CSV format results in an empty CSV file.
|
||||||
|
|
||||||
|
## PAN-229702
|
||||||
|
|
||||||
|
After upgrading a Panorama HA pair to PAN-OS 11.1, the ElasticSearch
|
||||||
|
connectivity might fail to establish. The issue occurs because the
|
||||||
|
client certificate on one of the Panorama devices does not have the
|
||||||
|
necessary Extended Key Usage (EKU) set for server authentication,
|
||||||
|
which is required for secure TLS communication.
|
||||||
|
|
||||||
|
Workaround:Contact Customer Support to renew the root client
|
||||||
|
certificate.
|
||||||
|
|
||||||
|
## PAN-228515
|
||||||
|
|
||||||
|
The EleasticSearch SSH flaps on the M-600 appliance in Panorama or
|
||||||
|
Log Collector mode. This causes logs to not display on the Panorama
|
||||||
|
management server (MonitorLogs) and the Log Collector health status (PanoramaManaged CollectorsStatus) to display as degraded.
|
||||||
|
|
||||||
|
## PAN-228273
|
||||||
|
|
||||||
|
On the Panorama management server in FIPS-CC mode, the ElasticSearch
|
||||||
|
cluster fails to come up and the show
|
||||||
|
log-collector-es-cluster health command displays
|
||||||
|
the status is
|
||||||
|
red. This results in log ingestion
|
||||||
|
issues for Panorama in Panorama only or Log Collector mode.
|
||||||
|
|
||||||
|
## PAN-227344
|
||||||
|
|
||||||
|
On the Panorama management server, PDF Summary Reports (MonitorPDF ReportsManage PDF Summary) display no data and are blank when predefined
|
||||||
|
reports are included in the summary report.
|
||||||
|
|
||||||
|
## PAN-225886
|
||||||
|
|
||||||
|
If you enable explicit proxy mode for the web proxy, intermittent
|
||||||
|
errors and unexpected TCP reconnections may occur.
|
||||||
|
|
||||||
|
## PAN-225337
|
||||||
|
|
||||||
|
On the Panorama management server, the configuration push to a
|
||||||
|
multi-vsys firewall fails if you:
|
||||||
|
|
||||||
|
1. Create a Shared and vsys-specific
|
||||||
|
device group configuration object with an indentical name.
|
||||||
|
For example, a Shared address object
|
||||||
|
called SharedAO1 and a
|
||||||
|
vsys-specific address object also called
|
||||||
|
SharedAO1.
|
||||||
|
2. Reference the Shared object in another
|
||||||
|
Shared configuration. For
|
||||||
|
example, reference the Shared address
|
||||||
|
object (SharedAO1) in a
|
||||||
|
Shared address group called
|
||||||
|
SharedAG1.
|
||||||
|
3. Use the Shared configuration object
|
||||||
|
with the reference in a vsys-specific configuration. For
|
||||||
|
example, reference the Shared address
|
||||||
|
group (SharedAG1) in a
|
||||||
|
vsys-specific policy rule.
|
||||||
|
|
||||||
|
Workaround: Select PanoramaSetupManagement and edit the Panorama Settings to enable one of the
|
||||||
|
following:
|
||||||
|
|
||||||
|
- Shared Unused Address and Service Objects with
|
||||||
|
Devices—This options pushes all
|
||||||
|
Shared objects, along with device
|
||||||
|
group specific objects, to managed firewalls.
|
||||||
|
This is a global setting and applies to all managed
|
||||||
|
firewalls, and may result in pushing too many configuration
|
||||||
|
objects to your managed firewalls.
|
||||||
|
- Objects defined in ancestors will take higher
|
||||||
|
precedence—This option specifies that in the event
|
||||||
|
of objects with the same name, ancestor object take
|
||||||
|
precedence over descendent objects. In this case, the
|
||||||
|
Shared objects take precedence
|
||||||
|
over the vsys-specific object.
|
||||||
|
This is a global setting and applies to all managed
|
||||||
|
firewalls. In the example above, if the IP address for the
|
||||||
|
Shared
|
||||||
|
SharedAO1 object was
|
||||||
|
10.1.1.1 and the device
|
||||||
|
group specific SharedAO1 was
|
||||||
|
10.2.2.2, the
|
||||||
|
10.1.1.1 IP address takes
|
||||||
|
precedence.
|
||||||
|
|
||||||
|
Alternatively, you can remove the duplicate address objects from the
|
||||||
|
device group configuration to allow only the
|
||||||
|
Shared objects in your configuration.
|
||||||
|
|
||||||
|
## PAN-223488
|
||||||
|
|
||||||
|
Closed ElasticSearch shards are not deleted from the Panorama
|
||||||
|
M-Series and virtual appliance. This causes the ElasticSearch shard
|
||||||
|
purging to not work as expected, resulting in high disk usage.
|
||||||
|
|
||||||
|
## PAN-223365
|
||||||
|
|
||||||
|
The Panorama management server is unable to query any logs if the
|
||||||
|
ElasticSearch health status for any Log Collector (PanoramaManaged Collector is degraded.
|
||||||
|
|
||||||
|
Workaround:
|
||||||
|
Log in to the Log Collector
|
||||||
|
CLI and restart ElasticSearch.
|
||||||
|
|
||||||
|
admindebug elasticsearch es-restart all
|
||||||
|
|
||||||
|
## PAN-222586
|
||||||
|
|
||||||
|
On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter
|
||||||
|
dropdown menus, Forward Methods, and Built-In Actions for
|
||||||
|
Correlation Log settings (DeviceLog Settings) are not displayed and cannot be configured.
|
||||||
|
|
||||||
|
## PAN-222253
|
||||||
|
|
||||||
|
On the Panorama management server, policy rulebase reordering when
|
||||||
|
you View Rulebase by Groups (Policy<policy-rulebase>) does not persist if you reorder the policy rulebase
|
||||||
|
by dragging and dropping individual policy rules and then moving the
|
||||||
|
entire tag group.
|
||||||
|
|
||||||
|
## PAN-221015
|
||||||
|
|
||||||
|
On M-600 appliances in Panorama or Log Collector mode, the
|
||||||
|
es-1 and
|
||||||
|
es-2 ElasticSearch processes fail
|
||||||
|
to restart when the M-600 appliance is rebooted. The results in the
|
||||||
|
Managed Collector ES health status (PanoramaManaged CollectorsHealth Status) to be degraded.
|
||||||
|
|
||||||
|
Workaround:
|
||||||
|
Log in to the Panorama or Log
|
||||||
|
Collector CLI experiencing degraded ElasticSearch health
|
||||||
|
and restart all ElasticSearch processes.
|
||||||
|
|
||||||
|
admin>debug elasticsearch es-restart optional all
|
||||||
|
|
||||||
|
Code copied to clipboard
|
||||||
|
|
||||||
|
Unable to copy due to lack of browser support.
|
||||||
|
|
||||||
|
Copy
|
||||||
|
|
||||||
|
## PAN-220180
|
||||||
|
|
||||||
|
Configured botnet reports (MonitorBotnet) are not generated.
|
||||||
|
|
||||||
|
## PAN-219644
|
||||||
|
|
||||||
|
Firewalls forwarding logs to a syslog server over TLS (ObjectsLog Forwarding) use the default Palo Alto Networks certificate
|
||||||
|
instead of the custom certificate configured on the firewall.
|
||||||
|
|
||||||
|
## PAN-218521
|
||||||
|
|
||||||
|
The ElasticSearch process on the M-600 appliance in Log Collector
|
||||||
|
mode may enter a continuous reboot cycle. This results in the M-600
|
||||||
|
appliance becoming unresponsive, consuming logging disk space, and
|
||||||
|
preventing new log ingestion.
|
||||||
|
|
||||||
|
## PAN-217307
|
||||||
|
|
||||||
|
The following Security policy rule (PoliciesSecurity) filters return no results:
|
||||||
|
|
||||||
|
log-start eq no
|
||||||
|
|
||||||
|
log-end eq no
|
||||||
|
|
||||||
|
log-end eq yes
|
||||||
|
|
||||||
|
## PAN-216214
|
||||||
|
|
||||||
|
For Panorama-managed firewalls in an Active/Active High Availability
|
||||||
|
(HA) configuration where you configure the firewall HA settings (DeviceHigh Availability) in a template or template stack (PanoramaTemplates), performing a local commit on one of the HA
|
||||||
|
firewalls triggers an HA config sync on the peer firewall. This
|
||||||
|
causes the HA peer configuration to go Out of
|
||||||
|
Sync.
|
||||||
|
|
||||||
|
## PAN-215778
|
||||||
|
|
||||||
|
On the M-600 appliance in Management Only mode, XML API Get requests
|
||||||
|
for /config fail with the following
|
||||||
|
error due to exceeding the total configuration size
|
||||||
|
supported on the M-600 appliance.
|
||||||
|
|
||||||
|
504 Gateway timeout
|
||||||
|
|
||||||
|
## PAN-215082
|
||||||
|
|
||||||
|
M-300 and M-700 appliances may generate erroneous system logs (MonitorLogsSystem) to alert that the M-Series appliance memory usage
|
||||||
|
limits are reached.
|
||||||
|
|
||||||
|
## PAN-213746
|
||||||
|
|
||||||
|
On the Panorama management server, the Hostkey
|
||||||
|
displayed as undefined undefined if you
|
||||||
|
override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template
|
||||||
|
Stack.
|
||||||
|
|
||||||
|
## PAN-213119
|
||||||
|
|
||||||
|
PA-5410 and PA-5420 firewalls display the following error when you
|
||||||
|
view the Block IP list (MonitorBlock IP):
|
||||||
|
|
||||||
|
show -> dis-block-table is
|
||||||
|
unexpected
|
||||||
|
|
||||||
|
## PAN-212889
|
||||||
|
|
||||||
|
On the Panorama management server, different threat names are used
|
||||||
|
when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the
|
||||||
|
ACC displaying no data to display when
|
||||||
|
you are redirected to the ACC after clicking a threat name in the
|
||||||
|
Threat Monitor and filtering the same threat name in the Global
|
||||||
|
Filters.
|
||||||
|
|
||||||
|
## PAN-212533
|
||||||
|
|
||||||
|
Modifying the Administrator Type for an
|
||||||
|
existing administrator (DeviceAdministrators or PanoramaAdministrators) from Superuser to a
|
||||||
|
Role-Based custom admin, or vice versa,
|
||||||
|
does not modify the access privileges of the administrator.
|
||||||
|
|
||||||
|
## PAN-211531
|
||||||
|
|
||||||
|
On the Panorama management server, admins can still
|
||||||
|
perform a selective push to managed firewalls when Push All
|
||||||
|
Changes and Push for Other Admins
|
||||||
|
are disabled in the admin role profile (PanoramaAdmin Roles).
|
||||||
|
|
||||||
|
## PAN-209937
|
||||||
|
|
||||||
|
Certificate-based authentication for administrator accounts may be
|
||||||
|
unable to log into the Panorama or firewall web interface with the
|
||||||
|
following error:
|
||||||
|
|
||||||
|
Bad Request - Your browser sent a request that this
|
||||||
|
server could not understand
|
||||||
|
|
||||||
|
## PAN-208325
|
||||||
|
|
||||||
|
The following NextGen firewalls and Panorama management server models
|
||||||
|
are unable to automatically renew the device certificate (DeviceSetupManagement or PanoramaSetupManagement).
|
||||||
|
|
||||||
|
- M-300 and M-700
|
||||||
|
- PA-410 Firewall
|
||||||
|
- PA-415 and PA-445 Firewalls
|
||||||
|
- PA-440, PA-450, and PA-460 Firewalls
|
||||||
|
- PA-1400 Series
|
||||||
|
- PA-3400 Series
|
||||||
|
- PA-5410, PA-5420, and PA-5430 Firewalls
|
||||||
|
- PA-5440 Firewall
|
||||||
|
- PA-5450 Firewall
|
||||||
|
|
||||||
|
Workaround: Log in to the firewall CLI or Panorama CLI and fetch the
|
||||||
|
device certificate.
|
||||||
|
|
||||||
|
admin>request certificate fetch
|
||||||
|
|
||||||
|
## PAN-208189
|
||||||
|
|
||||||
|
Traffic fails to match and reach all destinations if a Security
|
||||||
|
policy rule includes FQDN objects that resolve to two or more IP
|
||||||
|
addresses.
|
||||||
|
|
||||||
|
## PAN-207770
|
||||||
|
|
||||||
|
Data filtering logs (MonitorLogsData Filtering)
|
||||||
|
incorrectly display the traffic Direction as server-to-client instead
|
||||||
|
of client-to-server for upload traffic
|
||||||
|
that matches Enterprise data loss prevention (DLP) data patterns (ObjectsDLPData
|
||||||
|
Filtering Patterns) in an Enterprise DLP data
|
||||||
|
filtering profile (ObjectsDLPData Filtering Profiles).
|
||||||
|
|
||||||
|
## PAN-207733
|
||||||
|
|
||||||
|
When a DHCPv6 client is configured on HA
|
||||||
|
Active/Passive firewalls, if the DHCPv6 server goes down, after
|
||||||
|
the lease time expires, the DHCPv6 client should enter SOLICIT state
|
||||||
|
on both the Active and Passive firewalls. Instead, the client is
|
||||||
|
stuck in BOUND state with an IPv6 address having lease time 0 on
|
||||||
|
the Passive firewall.
|
||||||
|
|
||||||
|
## PAN-207629
|
||||||
|
|
||||||
|
On the Panorama management server, selective push fails to managed
|
||||||
|
firewalls if the managed firewalls are enabled with multiple vsys
|
||||||
|
and the Push Scope contains shared objects in device groups.
|
||||||
|
|
||||||
|
## PAN-207616
|
||||||
|
|
||||||
|
On the Panorama management server, after
|
||||||
|
selecting managed firewalls and creating a new Tag (PanoramaManaged DevicesSummary) the managed firewalls are
|
||||||
|
automatically unselected and any new tag created is applied to the
|
||||||
|
managed firewalls for which you initially created the new tag.
|
||||||
|
|
||||||
|
Workaround: Select
|
||||||
|
and then unselect the managed firewalls for which you created a
|
||||||
|
new tag.
|
||||||
|
|
||||||
|
## PAN-207611
|
||||||
|
|
||||||
|
When a DHCPv6 client is configured on HA
|
||||||
|
Active/Passive firewalls, the Passive firewall sometimes crashes.
|
||||||
|
|
||||||
|
## PAN-207040
|
||||||
|
|
||||||
|
If you disable Advanced Routing, remove
|
||||||
|
logical routers, and downgrade from PAN-OS 11.0.0 to a PAN-OS 10.2.x
|
||||||
|
or 10.1.x release, subsequent commits fail and SD-WAN devices on
|
||||||
|
Panorama have no Virtual Router name.
|
||||||
|
|
||||||
|
## PAN-206913
|
||||||
|
|
||||||
|
When a DHCPv6 client is configured on HA
|
||||||
|
Active/Passive firewalls, releasing the IPv6 address from the client
|
||||||
|
(using Release in the UI or using the request dhcp client ipv6 release all CLI
|
||||||
|
command) releases the IPv6 address from the Active firewall, but
|
||||||
|
not the Passive firewall.
|
||||||
|
|
||||||
|
## PAN-206909
|
||||||
|
|
||||||
|
The Dedicated Log Collector is unable to
|
||||||
|
reconnect to the Panorama management server if the configd process
|
||||||
|
crashes. This results in the Dedicated Log Collector losing connectivity
|
||||||
|
to Panorama despite the managed collector connection Status (PanoramaManaged Collector)
|
||||||
|
displaying connected and the managed colletor Health status displaying
|
||||||
|
as healthy.
|
||||||
|
|
||||||
|
This results in the local Panorama config and
|
||||||
|
system logs not being forwarded to the Dedicated Log Collector.
|
||||||
|
Firewall log forwarding to the disconnected Dedicated Log Collector
|
||||||
|
is not impacted.
|
||||||
|
|
||||||
|
Workaround: Restart the mgmtsrvr process
|
||||||
|
on the Dedicated Log Collector.
|
||||||
|
|
||||||
|
1. Log in to the Dedicated Log Collector
|
||||||
|
CLI.
|
||||||
|
2. Confirm the Dedicated Log Collector is disconnected from
|
||||||
|
Panorama.
|
||||||
|
admin> show panorama-status
|
||||||
|
Verify
|
||||||
|
the Connected status is no.
|
||||||
|
3. Restart the mgmtsrvr process.
|
||||||
|
admin> debug software restart process management-server
|
||||||
|
|
||||||
|
## PAN-206416
|
||||||
|
|
||||||
|
On the Panorama management server, no data
|
||||||
|
filtering log (MonitorLogsData Filtering) is generated
|
||||||
|
when the managed firewall loses connectivity to the following cloud services,
|
||||||
|
and as a result fails to forward matched traffic for inspection.
|
||||||
|
|
||||||
|
- DLP cloud service
|
||||||
|
- Advanced Threat Protection inline cloud analysis service
|
||||||
|
- Advanced URL Filtering cloud service
|
||||||
|
|
||||||
|
## PAN-206315
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1420 firewall only
|
||||||
|
```
|
||||||
|
|
||||||
|
In an active/passive high
|
||||||
|
availability (HA) configuration, the show session info CLI
|
||||||
|
command shows that the passive firewall has packet rate and throughput
|
||||||
|
values. The packet rate and throughput of the passive firewall should
|
||||||
|
be zero since it is not processing traffic.
|
||||||
|
|
||||||
|
## PAN-206253
|
||||||
|
|
||||||
|
For PA-1400 and PA-3400 Series firewalls, the default log rate is set
|
||||||
|
too low and the max configurable log rate is incorrectly capped
|
||||||
|
resulting in the firewall not generating more than 6,826 logs per
|
||||||
|
second.
|
||||||
|
|
||||||
|
## PAN-206005
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1400 Series, PA-3400 Series, and PA-5440 firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
The I7_misc memory pool on these platforms
|
||||||
|
is undersized and can cause a loss of connectivity when reaching
|
||||||
|
the limit of the memory pool. Certain features, like using a decryption
|
||||||
|
profile with Strip ALPN disabled, can lead to depleting the memory
|
||||||
|
pool and causing a connection loss.
|
||||||
|
|
||||||
|
Workaround: Disable
|
||||||
|
HTTP2 by enabling Strip ALPN in the decryption profile or avoid
|
||||||
|
usage of the I7_misc memory pool.
|
||||||
|
|
||||||
|
## PAN-205255
|
||||||
|
|
||||||
|
There is a rare PAN-OS issue that causes the dataplane to restart unexpectedly.
|
||||||
|
|
||||||
|
## PAN-205187
|
||||||
|
|
||||||
|
ElasticSearch may not start properly when a newly installed Panorama
|
||||||
|
virtual appliance powers on for the first time, resulting in the
|
||||||
|
Panorama virtual appliance being unable to query logs forwarded from
|
||||||
|
the managed firewall to a Log Collector.
|
||||||
|
|
||||||
|
Workaround:
|
||||||
|
Log in to the Panorama CLI
|
||||||
|
and start the PAN-OS software.
|
||||||
|
|
||||||
|
admin>request restart software
|
||||||
|
|
||||||
|
## PAN-205009
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1420 firewall only
|
||||||
|
```
|
||||||
|
|
||||||
|
In an active/passive high
|
||||||
|
availability (HA) configuration, the show interface all, show-high availability interface ha2,
|
||||||
|
and show high-availability all CLI
|
||||||
|
commands display the HSCI port state as unknown on both the active
|
||||||
|
and passive firewalls.
|
||||||
|
|
||||||
|
## PAN-204615
|
||||||
|
|
||||||
|
BGP sessions can flap even when an unrelated configuration is
|
||||||
|
committed. This results in the BGP session going down and getting
|
||||||
|
established again. As a result, BGP routes get exchanged again,
|
||||||
|
which can lead to momentary traffic disruption if BGP routes were in
|
||||||
|
use for establishing traffic.
|
||||||
|
|
||||||
|
## PAN-201910
|
||||||
|
|
||||||
|
PAN-OS security profiles might consume a
|
||||||
|
large amount of memory depending on the profile configuration and
|
||||||
|
quantity. In some cases, this might reduce the number of supported security
|
||||||
|
profiles below the stated maximum for a given platform.
|
||||||
|
|
||||||
|
## PAN-201855
|
||||||
|
|
||||||
|
On the Panorama management server, cloning any template (PanoramaTemplates) corrupts certificates (DeviceCertificate ManagementCertificates) with the Block Private Key
|
||||||
|
Export setting enabled across all templates. This
|
||||||
|
results in managed firewalls experiencing issues wherever the
|
||||||
|
corrupted certificate is referenced.
|
||||||
|
|
||||||
|
For example, you have template A, B, and C where templates A and B
|
||||||
|
have certificates with the Block Private Key
|
||||||
|
Export setting enabled. Cloning template C corrupts
|
||||||
|
the certificates with Block Private Key
|
||||||
|
Export setting enabled in templates A and B.
|
||||||
|
|
||||||
|
Workaround: After cloning a template, delete and re-import the
|
||||||
|
corrupted certificates.
|
||||||
|
|
||||||
|
## PAN-199557
|
||||||
|
|
||||||
|
On M-600 appliances in an Active/Passive high availability (HA)
|
||||||
|
configuration, the configd process
|
||||||
|
restarts due to a memory leak on the
|
||||||
|
Active Panorama HA peer. This
|
||||||
|
causes the Panorama web interface and CLI to become unresponsive.
|
||||||
|
|
||||||
|
Workaround: Manually reboot the
|
||||||
|
Active Panorama HA peer.
|
||||||
|
|
||||||
|
## PAN-197588
|
||||||
|
|
||||||
|
The PAN-OS ACC (Application Command Center)
|
||||||
|
does not display a widget detailing statistics and data associated
|
||||||
|
with vulnerability exploits that have been detected using inline
|
||||||
|
cloud analysis.
|
||||||
|
|
||||||
|
## PAN-197419
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
In NetworkInterfaceEthernet, the power over Ethernet
|
||||||
|
(PoE) ports do not display a Tag value.
|
||||||
|
|
||||||
|
## PAN-197097
|
||||||
|
|
||||||
|
Large Scale VPN (LSVPN) does not support
|
||||||
|
IPv6 addresses on the satellite firewall.
|
||||||
|
|
||||||
|
## PAN-196758
|
||||||
|
|
||||||
|
On the Panorama management server, pushing
|
||||||
|
a configuration change to firewalls leveraging SD-WAN erroneously
|
||||||
|
show the auto-provisioned BGP configurations for SD-WAN as being
|
||||||
|
edited or deleted despite no edits or deletions being made when
|
||||||
|
you Preview Changes (CommitPush to DevicesEdit Selections or CommitCommit and PushEdit Selections).
|
||||||
|
|
||||||
|
## PAN-196146
|
||||||
|
|
||||||
|
The VM-Series firewall on Azure does not
|
||||||
|
boot up with a hostname (specified in an init-cgf.txt or user data)
|
||||||
|
when bootstrapped.
|
||||||
|
|
||||||
|
## PAN-195968
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
When using the CLI to configure power over Ethernet (PoE) on a non-PoE
|
||||||
|
port, the CLI prints an error depending on whether an interface
|
||||||
|
type was selected on the non-PoE port or not. If an interface type, such
|
||||||
|
as tap, Layer 2, or virtual wire, was selected before PoE was configured,
|
||||||
|
the error message will not include the interface name (eg. ethernet1/4).
|
||||||
|
If an interface type was not selected before PoE was configured,
|
||||||
|
the error message will include the interface name.
|
||||||
|
|
||||||
|
## PAN-195568
|
||||||
|
|
||||||
|
When PAN-OS 11.0 is installed on multiple data plane platforms, users
|
||||||
|
are unable to connect to the GlobalProtect portal or gateway.
|
||||||
|
|
||||||
|
## PAN-195342
|
||||||
|
|
||||||
|
On the Panorama management server, Context
|
||||||
|
Switch fails when you try to Context Switch from a managed firewall running
|
||||||
|
PAN-OS 10.1.7 or earlier release back to Panorama and the following
|
||||||
|
error is displayed:
|
||||||
|
|
||||||
|
Could not find start token '@start@'
|
||||||
|
|
||||||
|
## PAN-194978
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
In NetworkInterfaceEthernet, hovering the mouse over
|
||||||
|
a power over Ethernet (PoE) Link State icon
|
||||||
|
does not display link speed and link duplex details.
|
||||||
|
|
||||||
|
## PAN-194424
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5450 firewall only
|
||||||
|
```
|
||||||
|
|
||||||
|
Upgrading
|
||||||
|
to PAN-OS 10.2.2 while having a log interface configured can cause
|
||||||
|
both the log interface and the management interface to remain connected
|
||||||
|
to the log collector.
|
||||||
|
|
||||||
|
Workaround: Restart the log receiver service
|
||||||
|
by running the following CLI command:
|
||||||
|
|
||||||
|
debug software restart process log-receiver
|
||||||
|
|
||||||
|
## PAN-192282
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-415 and PA-445 firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
In 1G mode, the MGT and Ethernet 1/1 port LEDs glow amber instead of
|
||||||
|
green.
|
||||||
|
|
||||||
|
## PAN-187685
|
||||||
|
|
||||||
|
On the Panorama management server, the Template Status
|
||||||
|
displays no synchronization status (PanoramaManaged DevicesSummary)
|
||||||
|
after a bootstrapped firewall is successfully added to Panorama.
|
||||||
|
|
||||||
|
Workaround: After
|
||||||
|
the bootstrapped firewall is successfully added to Panorama, log in to the Panorama web interface and
|
||||||
|
select CommitPush
|
||||||
|
to Devices.
|
||||||
|
|
||||||
|
## PAN-187407
|
||||||
|
|
||||||
|
The configured Advanced Threat Prevention
|
||||||
|
inline cloud analysis action for a given model might not be honored
|
||||||
|
under the following condition: If the firewall is set to Hold
|
||||||
|
client request for category lookup and the action set
|
||||||
|
to Reset-Both and the URL cache has been
|
||||||
|
cleared, the first request for inline cloud analysis will be bypassed.
|
||||||
|
|
||||||
|
## PAN-186283
|
||||||
|
|
||||||
|
Templates appear out-of-sync on Panorama
|
||||||
|
after successfully deploying the CFT stack using the Panorama plugin for
|
||||||
|
AWS.
|
||||||
|
|
||||||
|
Workaround: Use CommitPush to Devices to synchronize
|
||||||
|
the templates.
|
||||||
|
|
||||||
|
## PAN-184708
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama managed firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if:
|
||||||
|
|
||||||
|
- A scheduled report email contains
|
||||||
|
a Report Group (MonitorPDF
|
||||||
|
ReportsReport Group)
|
||||||
|
which includes a SaaS Application Usage report.
|
||||||
|
- A scheduled report contains only a SaaS Application Usage Report.
|
||||||
|
|
||||||
|
Workaround: To
|
||||||
|
receive a scheduled report email for all other PDF report types:
|
||||||
|
|
||||||
|
1. Select MonitorPDF ReportsReport Groups and
|
||||||
|
remove all SaaS Application Usage reports from all Report Groups.
|
||||||
|
2. Select MonitorPDF
|
||||||
|
ReportsEmail Scheduler and
|
||||||
|
edit the scheduled report email that contains only a SaaS Application Usage
|
||||||
|
report. For the Recurrence, select Disable and
|
||||||
|
click OK.
|
||||||
|
Repeat this step for all scheduled
|
||||||
|
report emails that contain only a SaaS Application Usage report.
|
||||||
|
3. Commit.
|
||||||
|
()
|
||||||
|
Select CommitCommit
|
||||||
|
and Push
|
||||||
|
|
||||||
|
## PAN-184406
|
||||||
|
|
||||||
|
Using the CLI to add a RAID disk pair to
|
||||||
|
an M-700 appliance causes the dmdb process to crash.
|
||||||
|
|
||||||
|
Workaround: Contact
|
||||||
|
customer support to stop the dmdb process before adding a RAID disk
|
||||||
|
pair to a M-700 appliance.
|
||||||
|
|
||||||
|
## PAN-183404
|
||||||
|
|
||||||
|
Static IP addresses are not recognized when
|
||||||
|
"and" operators are used with IP CIDR range.
|
||||||
|
|
||||||
|
## PAN-182734
|
||||||
|
|
||||||
|
On an Advanced Routing Engine, if you change
|
||||||
|
the IPSec tunnel configuration, BGP flaps.
|
||||||
|
|
||||||
|
## PAN-181933
|
||||||
|
|
||||||
|
If you use multiple log forwarding cards
|
||||||
|
(LFCs) on the PA-7000 series, all of the cards may not receive all
|
||||||
|
of the updates and the mappings for the clients may become out of sync,
|
||||||
|
which causes the firewall to not correctly populate the Source User
|
||||||
|
column in the session logs.
|
||||||
|
|
||||||
|
## PAN-171938
|
||||||
|
|
||||||
|
No results are displayed when you Show Application
|
||||||
|
Filter for a Security policy rule (PoliciesSecurityApplicationValueShow Application Filter).
|
||||||
|
|
||||||
|
## PAN-164885
|
||||||
|
|
||||||
|
On the Panorama management server, pushes to managed firewalls (CommitPush to Devices or Commit and Push) may fail
|
||||||
|
when an EDL (ObjectsExternal Dynamic Lists) is configured to Check for
|
||||||
|
updates every 5 minutes due to the commit and EDL
|
||||||
|
fetch processes overlapping. This is more likely to occur when
|
||||||
|
multiple EDLs are configured to check for updates every 5
|
||||||
|
minutes.
|
||||||
@@ -0,0 +1,699 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.1
|
||||||
|
---
|
||||||
|
|
||||||
|
## WF500-5632
|
||||||
|
|
||||||
|
The number of registered WildFire appliances
|
||||||
|
reported in Panorama (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the
|
||||||
|
current status of connected WildFire appliances.
|
||||||
|
|
||||||
|
## PAN-260851
|
||||||
|
|
||||||
|
From the NGFW or Panorama CLI, you can override the existing
|
||||||
|
application tag even if Disable Override is enabled for the
|
||||||
|
application (ObjectsApplications) tag.
|
||||||
|
|
||||||
|
## PAN-250062
|
||||||
|
|
||||||
|
Device telemetry might fail at configured intervals due to bundle generation issues.
|
||||||
|
|
||||||
|
## PAN-243951
|
||||||
|
|
||||||
|
On the Panorama management sever in an active/passive High
|
||||||
|
Availability (HA) configuration, managed devices (PanoramaManaged DevicesSummary) display as out-of-sync
|
||||||
|
on the passive HA peer when configuration changes are made to the
|
||||||
|
SD-WAN (PanoramaSD-WAN) configuration on the active HA peer.
|
||||||
|
|
||||||
|
Workaround: Manually synchronize the Panorama HA peers.
|
||||||
|
|
||||||
|
1. Log in to the Panorama web
|
||||||
|
interface on the active HA peer.
|
||||||
|
2. Select Commit and Commit to
|
||||||
|
Panorama the SD-WAN configuration changes on
|
||||||
|
the active HA peer.
|
||||||
|
On the passive HA peer, select PanoramaManaged DevicesSummary and observe that the managed devices are now
|
||||||
|
out-of-sync.
|
||||||
|
3. Log in to the primary HA peer Panorama CLI and
|
||||||
|
trigger a manual synchronization between the active and
|
||||||
|
secondary HA peers.
|
||||||
|
request high-availability sync-to-remote
|
||||||
|
running-config
|
||||||
|
4. Log back in to the active HA peer Panorama web interface and
|
||||||
|
select CommitPush to Devices and Push.
|
||||||
|
|
||||||
|
## PAN-234408
|
||||||
|
|
||||||
|
Enterprise DLP cannot detect and block non-file based traffic for
|
||||||
|
ChatGPT from traffic forwarded to the DLP cloud service from an
|
||||||
|
NGFW.
|
||||||
|
|
||||||
|
## PAN-234015
|
||||||
|
|
||||||
|
The X-Forwarded-For (XFF) value is not displayed in traffic logs.
|
||||||
|
|
||||||
|
## PAN-242910
|
||||||
|
|
||||||
|
On the Panorama management server, Panorama administrators (PanoramaAdministrators) that are assigned a custom Panorama admin role (PanoramaAdmin Roles) with Push All Changes enabled
|
||||||
|
are unable to push configuration changes to managed firewalls when
|
||||||
|
Managed Devices and Push For
|
||||||
|
Other Admins are disabled.
|
||||||
|
|
||||||
|
## PAN-241041
|
||||||
|
|
||||||
|
On the Panorama management server exporting template or template
|
||||||
|
stack variables (PanoramaTemplates) in CSV format results in an empty CSV file.
|
||||||
|
|
||||||
|
## PAN-228515
|
||||||
|
|
||||||
|
The EleasticSearch SSH flaps on the M-600 appliance in Panorama or
|
||||||
|
Log Collector mode. This causes logs to not display on the Panorama
|
||||||
|
management server (MonitorLogs) and the Log Collector health status (PanoramaManaged CollectorsStatus) to display as degraded.
|
||||||
|
|
||||||
|
## PAN-228273
|
||||||
|
|
||||||
|
On the Panorama management server in FIPS-CC mode, the ElasticSearch
|
||||||
|
cluster fails to come up and the show
|
||||||
|
log-collector-es-cluster health command displays
|
||||||
|
the status is
|
||||||
|
red. This results in log ingestion
|
||||||
|
issues for Panorama in Panorama only or Log Collector mode.
|
||||||
|
|
||||||
|
## PAN-227344
|
||||||
|
|
||||||
|
On the Panorama management server, PDF Summary Reports (MonitorPDF ReportsManage PDF Summary) display no data and are blank when predefined
|
||||||
|
reports are included in the summary report.
|
||||||
|
|
||||||
|
## PAN-225886
|
||||||
|
|
||||||
|
If you enable explicit proxy mode for the web proxy, intermittent
|
||||||
|
errors and unexpected TCP reconnections may occur.
|
||||||
|
|
||||||
|
## PAN-225337
|
||||||
|
|
||||||
|
On the Panorama management server, the configuration push to a
|
||||||
|
multi-vsys firewall fails if you:
|
||||||
|
|
||||||
|
1. Create a Shared and vsys-specific
|
||||||
|
device group configuration object with an indentical name.
|
||||||
|
For example, a Shared address object
|
||||||
|
called SharedAO1 and a
|
||||||
|
vsys-specific address object also called
|
||||||
|
SharedAO1.
|
||||||
|
2. Reference the Shared object in another
|
||||||
|
Shared configuration. For
|
||||||
|
example, reference the Shared address
|
||||||
|
object (SharedAO1) in a
|
||||||
|
Shared address group called
|
||||||
|
SharedAG1.
|
||||||
|
3. Use the Shared configuration object
|
||||||
|
with the reference in a vsys-specific configuration. For
|
||||||
|
example, reference the Shared address
|
||||||
|
group (SharedAG1) in a
|
||||||
|
vsys-specific policy rule.
|
||||||
|
|
||||||
|
Workaround: Select PanoramaSetupManagement and edit the Panorama Settings to enable one of the
|
||||||
|
following:
|
||||||
|
|
||||||
|
- Shared Unused Address and Service Objects with
|
||||||
|
Devices—This options pushes all
|
||||||
|
Shared objects, along with device
|
||||||
|
group specific objects, to managed firewalls.
|
||||||
|
This is a global setting and applies to all managed
|
||||||
|
firewalls, and may result in pushing too many configuration
|
||||||
|
objects to your managed firewalls.
|
||||||
|
- Objects defined in ancestors will take higher
|
||||||
|
precedence—This option specifies that in the event
|
||||||
|
of objects with the same name, ancestor object take
|
||||||
|
precedence over descendent objects. In this case, the
|
||||||
|
Shared objects take precedence
|
||||||
|
over the vsys-specific object.
|
||||||
|
This is a global setting and applies to all managed
|
||||||
|
firewalls. In the example above, if the IP address for the
|
||||||
|
Shared
|
||||||
|
SharedAO1 object was
|
||||||
|
10.1.1.1 and the device
|
||||||
|
group specific SharedAO1 was
|
||||||
|
10.2.2.2, the
|
||||||
|
10.1.1.1 IP address takes
|
||||||
|
precedence.
|
||||||
|
|
||||||
|
Alternatively, you can remove the duplicate address objects from the
|
||||||
|
device group configuration to allow only the
|
||||||
|
Shared objects in your configuration.
|
||||||
|
|
||||||
|
## PAN-223488
|
||||||
|
|
||||||
|
Closed ElasticSearch shards are not deleted from the Panorama
|
||||||
|
M-Series and virtual appliance. This causes the ElasticSearch shard
|
||||||
|
purging to not work as expected, resulting in high disk usage.
|
||||||
|
|
||||||
|
## PAN-223365
|
||||||
|
|
||||||
|
The Panorama management server is unable to query any logs if the
|
||||||
|
ElasticSearch health status for any Log Collector (PanoramaManaged Collector is degraded.
|
||||||
|
|
||||||
|
Workaround:
|
||||||
|
Log in to the Log Collector
|
||||||
|
CLI and restart ElasticSearch.
|
||||||
|
|
||||||
|
admindebug elasticsearch es-restart all
|
||||||
|
|
||||||
|
## PAN-222586
|
||||||
|
|
||||||
|
On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter
|
||||||
|
dropdown menus, Forward Methods, and Built-In Actions for
|
||||||
|
Correlation Log settings (DeviceLog Settings) are not displayed and cannot be configured.
|
||||||
|
|
||||||
|
## PAN-222253
|
||||||
|
|
||||||
|
On the Panorama management server, policy rulebase reordering when
|
||||||
|
you View Rulebase by Groups (Policy<policy-rulebase>) does not persist if you reorder the policy rulebase
|
||||||
|
by dragging and dropping individual policy rules and then moving the
|
||||||
|
entire tag group.
|
||||||
|
|
||||||
|
## PAN-221126
|
||||||
|
|
||||||
|
Email server profiles (DeviceServer ProfilesEmail and PanoramaServer ProfilesEmail) to forward logs as email notifications are not
|
||||||
|
forwarded in a readable format.
|
||||||
|
|
||||||
|
Workaround: Use a Custom Log Format to
|
||||||
|
forward logs as email notifications in a readable format.
|
||||||
|
|
||||||
|
## PAN-221015
|
||||||
|
|
||||||
|
On M-600 appliances in Panorama or Log Collector mode, the
|
||||||
|
es-1 and
|
||||||
|
es-2 ElasticSearch processes fail
|
||||||
|
to restart when the M-600 appliance is rebooted. The results in the
|
||||||
|
Managed Collector ES health status (PanoramaManaged CollectorsHealth Status) to be degraded.
|
||||||
|
|
||||||
|
Workaround:
|
||||||
|
Log in to the Panorama or Log
|
||||||
|
Collector CLI experiencing degraded ElasticSearch health
|
||||||
|
and restart all ElasticSearch processes.
|
||||||
|
|
||||||
|
admin>debug elasticsearch es-restart optional all
|
||||||
|
|
||||||
|
Code copied to clipboard
|
||||||
|
|
||||||
|
Unable to copy due to lack of browser support.
|
||||||
|
|
||||||
|
Copy
|
||||||
|
|
||||||
|
## PAN-220180
|
||||||
|
|
||||||
|
Configured botnet reports (MonitorBotnet) are not generated.
|
||||||
|
|
||||||
|
## PAN-220176
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 11.0.1-h2 hotfix
|
||||||
|
```
|
||||||
|
|
||||||
|
System process crashes might occur
|
||||||
|
with VoIP traffic when NAT is enabled with Persistent Dynamic IP and
|
||||||
|
Port settings.
|
||||||
|
|
||||||
|
## PAN-219644
|
||||||
|
|
||||||
|
Firewalls forwarding logs to a syslog server over TLS (ObjectsLog Forwarding) use the default Palo Alto Networks certificate
|
||||||
|
instead of the custom certificate configured on the firewall.
|
||||||
|
|
||||||
|
## PAN-218521
|
||||||
|
|
||||||
|
The ElasticSearch process on the M-600 appliance in Log Collector
|
||||||
|
mode may enter a continuous reboot cycle. This results in the M-600
|
||||||
|
appliance becoming unresponsive, consuming logging disk space, and
|
||||||
|
preventing new log ingestion.
|
||||||
|
|
||||||
|
## PAN-217307
|
||||||
|
|
||||||
|
The following Security policy rule (PoliciesSecurity) filters return no results:
|
||||||
|
|
||||||
|
log-start eq no
|
||||||
|
|
||||||
|
log-end eq no
|
||||||
|
|
||||||
|
log-end eq yes
|
||||||
|
|
||||||
|
## PAN-216821
|
||||||
|
|
||||||
|
The reportd process crashes after you
|
||||||
|
successfully upgrade an M-200 appliance to PAN-OS 10.2.4.
|
||||||
|
|
||||||
|
## PAN-216314
|
||||||
|
|
||||||
|
Upon upgrade or downgrade to or from PAN-OS 10.1.9 or 10.1.9-h1,
|
||||||
|
offloaded application traffic sessions may disconnect after a period
|
||||||
|
of time even if a session is active. The disconnect occurs after the
|
||||||
|
application's default session timeout value is exceeded. This
|
||||||
|
behavior affects only PAN-OS 10.1.9 and 10.1.9-h1. If you are on
|
||||||
|
PAN-OS 10.1.9 and 10.1.9-h1, please use the following workaround. If
|
||||||
|
you have already upgraded or downgraded to another PAN-OS version,
|
||||||
|
use the following workaround in that version.
|
||||||
|
|
||||||
|
Workaround: Run the CLI command debug dataplane
|
||||||
|
internal pdt fe100 csr wr_sem_ctrl_ctr_scan_dis value
|
||||||
|
0 to set the value to zero (0).
|
||||||
|
|
||||||
|
## PAN-216214
|
||||||
|
|
||||||
|
For Panorama-managed firewalls in an Active/Active High Availability
|
||||||
|
(HA) configuration where you configure the firewall HA settings (DeviceHigh Availability) in a template or template stack (PanoramaTemplates), performing a local commit on one of the HA
|
||||||
|
firewalls triggers an HA config sync on the peer firewall. This
|
||||||
|
causes the HA peer configuration to go Out of
|
||||||
|
Sync.
|
||||||
|
|
||||||
|
## PAN-215778
|
||||||
|
|
||||||
|
On the M-600 appliance in Management Only mode, XML API Get requests
|
||||||
|
for /config fail with the following
|
||||||
|
error due to exceeding the total configuration size
|
||||||
|
supported on the M-600 appliance.
|
||||||
|
|
||||||
|
504 Gateway timeout
|
||||||
|
|
||||||
|
## PAN-215082
|
||||||
|
|
||||||
|
M-300 and M-700 appliances may generate erroneous system logs (MonitorLogsSystem) to alert that the M-Series appliance memory usage
|
||||||
|
limits are reached.
|
||||||
|
|
||||||
|
## PAN-213746
|
||||||
|
|
||||||
|
On the Panorama management server, the Hostkey
|
||||||
|
displayed as undefined undefined if you
|
||||||
|
override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template
|
||||||
|
Stack.
|
||||||
|
|
||||||
|
## PAN-213119
|
||||||
|
|
||||||
|
PA-5410 and PA-5420 firewalls display the following error when you
|
||||||
|
view the Block IP list (MonitorBlock IP):
|
||||||
|
|
||||||
|
show -> dis-block-table is
|
||||||
|
unexpected
|
||||||
|
|
||||||
|
## PAN-212889
|
||||||
|
|
||||||
|
On the Panorama management server, different threat names are used
|
||||||
|
when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the
|
||||||
|
ACC displaying no data to display when
|
||||||
|
you are redirected to the ACC after clicking a threat name in the
|
||||||
|
Threat Monitor and filtering the same threat name in the Global
|
||||||
|
Filters.
|
||||||
|
|
||||||
|
## PAN-211531
|
||||||
|
|
||||||
|
On the Panorama management server, admins can still
|
||||||
|
perform a selective push to managed firewalls when Push All
|
||||||
|
Changes and Push for Other Admins
|
||||||
|
are disabled in the admin role profile (PanoramaAdmin Roles).
|
||||||
|
|
||||||
|
## PAN-209937
|
||||||
|
|
||||||
|
Certificate-based authentication for administrator accounts may be
|
||||||
|
unable to log into the Panorama or firewall web interface with the
|
||||||
|
following error:
|
||||||
|
|
||||||
|
Bad Request - Your browser sent a request that this
|
||||||
|
server could not understand
|
||||||
|
|
||||||
|
## PAN-208325
|
||||||
|
|
||||||
|
The following NextGen firewalls and Panorama management server models
|
||||||
|
are unable to automatically renew the device certificate (DeviceSetupManagement or PanoramaSetupManagement).
|
||||||
|
|
||||||
|
- M-300 and M-700
|
||||||
|
- PA-410 Firewall
|
||||||
|
- PA-415 and PA-445 Firewalls
|
||||||
|
- PA-440, PA-450, and PA-460 Firewalls
|
||||||
|
- PA-1400 Series
|
||||||
|
- PA-3400 Series
|
||||||
|
- PA-5410, PA-5420, and PA-5430 Firewalls
|
||||||
|
- PA-5440 Firewall
|
||||||
|
- PA-5450 Firewall
|
||||||
|
|
||||||
|
Workaround: Log in to the firewall CLI or Panorama CLI and fetch the
|
||||||
|
device certificate.
|
||||||
|
|
||||||
|
admin>request certificate fetch
|
||||||
|
|
||||||
|
## PAN-208189
|
||||||
|
|
||||||
|
Traffic fails to match and reach all destinations if a Security
|
||||||
|
policy rule includes FQDN objects that resolve to two or more IP
|
||||||
|
addresses.
|
||||||
|
|
||||||
|
## PAN-207770
|
||||||
|
|
||||||
|
Data filtering logs (MonitorLogsData Filtering)
|
||||||
|
incorrectly display the traffic Direction as server-to-client instead
|
||||||
|
of client-to-server for upload traffic
|
||||||
|
that matches Enterprise data loss prevention (DLP) data patterns (ObjectsDLPData
|
||||||
|
Filtering Patterns) in an Enterprise DLP data
|
||||||
|
filtering profile (ObjectsDLPData Filtering Profiles).
|
||||||
|
|
||||||
|
## PAN-207733
|
||||||
|
|
||||||
|
When a DHCPv6 client is configured on HA
|
||||||
|
Active/Passive firewalls, if the DHCPv6 server goes down, after
|
||||||
|
the lease time expires, the DHCPv6 client should enter SOLICIT state
|
||||||
|
on both the Active and Passive firewalls. Instead, the client is
|
||||||
|
stuck in BOUND state with an IPv6 address having lease time 0 on
|
||||||
|
the Passive firewall.
|
||||||
|
|
||||||
|
## PAN-207616
|
||||||
|
|
||||||
|
On the Panorama management server, after
|
||||||
|
selecting managed firewalls and creating a new Tag (PanoramaManaged DevicesSummary) the managed firewalls are
|
||||||
|
automatically unselected and any new tag created is applied to the
|
||||||
|
managed firewalls for which you initially created the new tag.
|
||||||
|
|
||||||
|
Workaround: Select
|
||||||
|
and then unselect the managed firewalls for which you created a
|
||||||
|
new tag.
|
||||||
|
|
||||||
|
## PAN-207611
|
||||||
|
|
||||||
|
When a DHCPv6 client is configured on HA
|
||||||
|
Active/Passive firewalls, the Passive firewall sometimes crashes.
|
||||||
|
|
||||||
|
## PAN-207442
|
||||||
|
|
||||||
|
For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the
|
||||||
|
active-primary HA peer
|
||||||
|
configuration sync to the
|
||||||
|
secondary-passive HA peer may fail.
|
||||||
|
When the config sync fails, the job Results is
|
||||||
|
Successful
|
||||||
|
(Tasks), however the sync status on the
|
||||||
|
Dashboard displays as Out
|
||||||
|
of Sync for both HA peers.
|
||||||
|
|
||||||
|
Workaround: Perform a local commit on the
|
||||||
|
active-primary HA peer and then
|
||||||
|
synchronize the HA configuration.
|
||||||
|
|
||||||
|
1. Log in to the Panorama
|
||||||
|
web interface of the
|
||||||
|
active-primary HA peer.
|
||||||
|
2. Select Commit and Commit to
|
||||||
|
Panorama.
|
||||||
|
3. In the active-primary HA peer
|
||||||
|
Dashboard, click Sync
|
||||||
|
to Peer in the High Availability widget.
|
||||||
|
|
||||||
|
## PAN-207040
|
||||||
|
|
||||||
|
If you disable Advanced Routing, remove
|
||||||
|
logical routers, and downgrade from PAN-OS 11.0.0 to a PAN-OS 10.2.x
|
||||||
|
or 10.1.x release, subsequent commits fail and SD-WAN devices on
|
||||||
|
Panorama have no Virtual Router name.
|
||||||
|
|
||||||
|
## PAN-206913
|
||||||
|
|
||||||
|
When a DHCPv6 client is configured on HA
|
||||||
|
Active/Passive firewalls, releasing the IPv6 address from the client
|
||||||
|
(using Release in the UI or using the request dhcp client ipv6 release all CLI
|
||||||
|
command) releases the IPv6 address from the Active firewall, but
|
||||||
|
not the Passive firewall.
|
||||||
|
|
||||||
|
## PAN-206909
|
||||||
|
|
||||||
|
The Dedicated Log Collector is unable to
|
||||||
|
reconnect to the Panorama management server if the configd process
|
||||||
|
crashes. This results in the Dedicated Log Collector losing connectivity
|
||||||
|
to Panorama despite the managed collector connection Status (PanoramaManaged Collector)
|
||||||
|
displaying connected and the managed colletor Health status displaying
|
||||||
|
as healthy.
|
||||||
|
|
||||||
|
This results in the local Panorama config and
|
||||||
|
system logs not being forwarded to the Dedicated Log Collector.
|
||||||
|
Firewall log forwarding to the disconnected Dedicated Log Collector
|
||||||
|
is not impacted.
|
||||||
|
|
||||||
|
Workaround: Restart the mgmtsrvr process
|
||||||
|
on the Dedicated Log Collector.
|
||||||
|
|
||||||
|
1. Log in to the Dedicated Log Collector
|
||||||
|
CLI.
|
||||||
|
2. Confirm the Dedicated Log Collector is disconnected from
|
||||||
|
Panorama.
|
||||||
|
admin> show panorama-status
|
||||||
|
Verify
|
||||||
|
the Connected status is no.
|
||||||
|
3. Restart the mgmtsrvr process.
|
||||||
|
admin> debug software restart process management-server
|
||||||
|
|
||||||
|
## PAN-206416
|
||||||
|
|
||||||
|
On the Panorama management server, no data
|
||||||
|
filtering log (MonitorLogsData Filtering) is generated
|
||||||
|
when the managed firewall loses connectivity to the following cloud services,
|
||||||
|
and as a result fails to forward matched traffic for inspection.
|
||||||
|
|
||||||
|
- DLP cloud service
|
||||||
|
- Advanced Threat Protection inline cloud analysis service
|
||||||
|
- Advanced URL Filtering cloud service
|
||||||
|
|
||||||
|
## PAN-206315
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1420 firewall only
|
||||||
|
```
|
||||||
|
|
||||||
|
In an active/passive high
|
||||||
|
availability (HA) configuration, the show session info CLI
|
||||||
|
command shows that the passive firewall has packet rate and throughput
|
||||||
|
values. The packet rate and throughput of the passive firewall should
|
||||||
|
be zero since it is not processing traffic.
|
||||||
|
|
||||||
|
## PAN-205009
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1420 firewall only
|
||||||
|
```
|
||||||
|
|
||||||
|
In an active/passive high
|
||||||
|
availability (HA) configuration, the show interface all, show-high availability interface ha2,
|
||||||
|
and show high-availability all CLI
|
||||||
|
commands display the HSCI port state as unknown on both the active
|
||||||
|
and passive firewalls.
|
||||||
|
|
||||||
|
## PAN-204689
|
||||||
|
|
||||||
|
Upon upgrade to PAN-OS 11.0.1, the following GlobalProtect settings
|
||||||
|
do not work:
|
||||||
|
|
||||||
|
- Allow user to disconnect GlobalProtect
|
||||||
|
AppAllow with Passcode
|
||||||
|
- Allow user to Disable GlobalProtect
|
||||||
|
AppAllow with Passcode
|
||||||
|
- Allow User to Uninstall GlobalProtect
|
||||||
|
AppAllow with Password
|
||||||
|
|
||||||
|
## PAN-201910
|
||||||
|
|
||||||
|
PAN-OS security profiles might consume a
|
||||||
|
large amount of memory depending on the profile configuration and
|
||||||
|
quantity. In some cases, this might reduce the number of supported security
|
||||||
|
profiles below the stated maximum for a given platform.
|
||||||
|
|
||||||
|
## PAN-199557
|
||||||
|
|
||||||
|
On M-600 appliances in an Active/Passive high availability (HA)
|
||||||
|
configuration, the configd process
|
||||||
|
restarts due to a memory leak on the
|
||||||
|
Active Panorama HA peer. This
|
||||||
|
causes the Panorama web interface and CLI to become unresponsive.
|
||||||
|
|
||||||
|
Workaround: Manually reboot the
|
||||||
|
Active Panorama HA peer.
|
||||||
|
|
||||||
|
## PAN-197588
|
||||||
|
|
||||||
|
The PAN-OS ACC (Application Command Center)
|
||||||
|
does not display a widget detailing statistics and data associated
|
||||||
|
with vulnerability exploits that have been detected using inline
|
||||||
|
cloud analysis.
|
||||||
|
|
||||||
|
## PAN-197419
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
In NetworkInterfaceEthernet, the power over Ethernet
|
||||||
|
(PoE) ports do not display a Tag value.
|
||||||
|
|
||||||
|
## PAN-197097
|
||||||
|
|
||||||
|
Large Scale VPN (LSVPN) does not support
|
||||||
|
IPv6 addresses on the satellite firewall.
|
||||||
|
|
||||||
|
## PAN-196758
|
||||||
|
|
||||||
|
On the Panorama management server, pushing
|
||||||
|
a configuration change to firewalls leveraging SD-WAN erroneously
|
||||||
|
show the auto-provisioned BGP configurations for SD-WAN as being
|
||||||
|
edited or deleted despite no edits or deletions being made when
|
||||||
|
you Preview Changes (CommitPush to DevicesEdit Selections or CommitCommit and PushEdit Selections).
|
||||||
|
|
||||||
|
## PAN-196146
|
||||||
|
|
||||||
|
The VM-Series firewall on Azure does not
|
||||||
|
boot up with a hostname (specified in an init-cgf.txt or user data)
|
||||||
|
when bootstrapped.
|
||||||
|
|
||||||
|
## PAN-195968
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
When using the CLI to configure power over Ethernet (PoE) on a non-PoE
|
||||||
|
port, the CLI prints an error depending on whether an interface
|
||||||
|
type was selected on the non-PoE port or not. If an interface type, such
|
||||||
|
as tap, Layer 2, or virtual wire, was selected before PoE was configured,
|
||||||
|
the error message will not include the interface name (eg. ethernet1/4).
|
||||||
|
If an interface type was not selected before PoE was configured,
|
||||||
|
the error message will include the interface name.
|
||||||
|
|
||||||
|
## PAN-195342
|
||||||
|
|
||||||
|
On the Panorama management server, Context
|
||||||
|
Switch fails when you try to Context Switch from a managed firewall running
|
||||||
|
PAN-OS 10.1.7 or earlier release back to Panorama and the following
|
||||||
|
error is displayed:
|
||||||
|
|
||||||
|
Could not find start token '@start@'
|
||||||
|
|
||||||
|
## PAN-194978
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
In NetworkInterfaceEthernet, hovering the mouse over
|
||||||
|
a power over Ethernet (PoE) Link State icon
|
||||||
|
does not display link speed and link duplex details.
|
||||||
|
|
||||||
|
## PAN-194424
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5450 firewall only
|
||||||
|
```
|
||||||
|
|
||||||
|
Upgrading
|
||||||
|
to PAN-OS 10.2.2 while having a log interface configured can cause
|
||||||
|
both the log interface and the management interface to remain connected
|
||||||
|
to the log collector.
|
||||||
|
|
||||||
|
Workaround: Restart the log receiver service
|
||||||
|
by running the following CLI command:
|
||||||
|
|
||||||
|
debug software restart process log-receiver
|
||||||
|
|
||||||
|
## PAN-187685
|
||||||
|
|
||||||
|
On the Panorama management server, the Template Status
|
||||||
|
displays no synchronization status (PanoramaManaged DevicesSummary)
|
||||||
|
after a bootstrapped firewall is successfully added to Panorama.
|
||||||
|
|
||||||
|
Workaround: After
|
||||||
|
the bootstrapped firewall is successfully added to Panorama, log in to the Panorama web interface and
|
||||||
|
select CommitPush
|
||||||
|
to Devices.
|
||||||
|
|
||||||
|
## PAN-187407
|
||||||
|
|
||||||
|
The configured Advanced Threat Prevention
|
||||||
|
inline cloud analysis action for a given model might not be honored
|
||||||
|
under the following condition: If the firewall is set to Hold
|
||||||
|
client request for category lookup and the action set
|
||||||
|
to Reset-Both and the URL cache has been
|
||||||
|
cleared, the first request for inline cloud analysis will be bypassed.
|
||||||
|
|
||||||
|
## PAN-186283
|
||||||
|
|
||||||
|
Templates appear out-of-sync on Panorama
|
||||||
|
after successfully deploying the CFT stack using the Panorama plugin for
|
||||||
|
AWS.
|
||||||
|
|
||||||
|
Workaround: Use CommitPush to Devices to synchronize
|
||||||
|
the templates.
|
||||||
|
|
||||||
|
## PAN-184708
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama managed firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if:
|
||||||
|
|
||||||
|
- A scheduled report email contains
|
||||||
|
a Report Group (MonitorPDF
|
||||||
|
ReportsReport Group)
|
||||||
|
which includes a SaaS Application Usage report.
|
||||||
|
- A scheduled report contains only a SaaS Application Usage Report.
|
||||||
|
|
||||||
|
Workaround: To
|
||||||
|
receive a scheduled report email for all other PDF report types:
|
||||||
|
|
||||||
|
1. Select MonitorPDF ReportsReport Groups and
|
||||||
|
remove all SaaS Application Usage reports from all Report Groups.
|
||||||
|
2. Select MonitorPDF
|
||||||
|
ReportsEmail Scheduler and
|
||||||
|
edit the scheduled report email that contains only a SaaS Application Usage
|
||||||
|
report. For the Recurrence, select Disable and
|
||||||
|
click OK.
|
||||||
|
Repeat this step for all scheduled
|
||||||
|
report emails that contain only a SaaS Application Usage report.
|
||||||
|
3. Commit.
|
||||||
|
()
|
||||||
|
Select CommitCommit
|
||||||
|
and Push
|
||||||
|
|
||||||
|
## PAN-184406
|
||||||
|
|
||||||
|
Using the CLI to add a RAID disk pair to
|
||||||
|
an M-700 appliance causes the dmdb process to crash.
|
||||||
|
|
||||||
|
Workaround: Contact
|
||||||
|
customer support to stop the dmdb process before adding a RAID disk
|
||||||
|
pair to a M-700 appliance.
|
||||||
|
|
||||||
|
## PAN-183404
|
||||||
|
|
||||||
|
Static IP addresses are not recognized when
|
||||||
|
"and" operators are used with IP CIDR range.
|
||||||
|
|
||||||
|
## PAN-182734
|
||||||
|
|
||||||
|
On an Advanced Routing Engine, if you change
|
||||||
|
the IPSec tunnel configuration, BGP flaps.
|
||||||
|
|
||||||
|
## PAN-181933
|
||||||
|
|
||||||
|
If you use multiple log forwarding cards
|
||||||
|
(LFCs) on the PA-7000 series, all of the cards may not receive all
|
||||||
|
of the updates and the mappings for the clients may become out of sync,
|
||||||
|
which causes the firewall to not correctly populate the Source User
|
||||||
|
column in the session logs.
|
||||||
|
|
||||||
|
## PAN-171938
|
||||||
|
|
||||||
|
No results are displayed when you Show Application
|
||||||
|
Filter for a Security policy rule (PoliciesSecurityApplicationValueShow Application Filter).
|
||||||
|
|
||||||
|
## PAN-164885
|
||||||
|
|
||||||
|
On the Panorama management server, pushes to managed firewalls (CommitPush to Devices or Commit and Push) may fail
|
||||||
|
when an EDL (ObjectsExternal Dynamic Lists) is configured to Check for
|
||||||
|
updates every 5 minutes due to the commit and EDL
|
||||||
|
fetch processes overlapping. This is more likely to occur when
|
||||||
|
multiple EDLs are configured to check for updates every 5
|
||||||
|
minutes.
|
||||||
@@ -0,0 +1,657 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.2
|
||||||
|
---
|
||||||
|
|
||||||
|
## WF500-5632
|
||||||
|
|
||||||
|
The number of registered WildFire appliances
|
||||||
|
reported in Panorama (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the
|
||||||
|
current status of connected WildFire appliances.
|
||||||
|
|
||||||
|
## PAN-260851
|
||||||
|
|
||||||
|
From the NGFW or Panorama CLI, you can override the existing
|
||||||
|
application tag even if Disable Override is enabled for the
|
||||||
|
application (ObjectsApplications) tag.
|
||||||
|
|
||||||
|
## PAN-250062
|
||||||
|
|
||||||
|
Device telemetry might fail at configured intervals due to bundle generation issues.
|
||||||
|
|
||||||
|
## PAN-243951
|
||||||
|
|
||||||
|
On the Panorama management sever in an active/passive High
|
||||||
|
Availability (HA) configuration, managed devices (PanoramaManaged DevicesSummary) display as out-of-sync
|
||||||
|
on the passive HA peer when configuration changes are made to the
|
||||||
|
SD-WAN (PanoramaSD-WAN) configuration on the active HA peer.
|
||||||
|
|
||||||
|
Workaround: Manually synchronize the Panorama HA peers.
|
||||||
|
|
||||||
|
1. Log in to the Panorama web
|
||||||
|
interface on the active HA peer.
|
||||||
|
2. Select Commit and Commit to
|
||||||
|
Panorama the SD-WAN configuration changes on
|
||||||
|
the active HA peer.
|
||||||
|
On the passive HA peer, select PanoramaManaged DevicesSummary and observe that the managed devices are now
|
||||||
|
out-of-sync.
|
||||||
|
3. Log in to the primary HA peer Panorama CLI and
|
||||||
|
trigger a manual synchronization between the active and
|
||||||
|
secondary HA peers.
|
||||||
|
request high-availability sync-to-remote
|
||||||
|
running-config
|
||||||
|
4. Log back in to the active HA peer Panorama web interface and
|
||||||
|
select CommitPush to Devices and Push.
|
||||||
|
|
||||||
|
## PAN-234408
|
||||||
|
|
||||||
|
Enterprise DLP cannot detect and block non-file based traffic for
|
||||||
|
ChatGPT from traffic forwarded to the DLP cloud service from an
|
||||||
|
NGFW.
|
||||||
|
|
||||||
|
## PAN-234015
|
||||||
|
|
||||||
|
The X-Forwarded-For (XFF) value is not displayed in traffic logs.
|
||||||
|
|
||||||
|
## PAN-242910
|
||||||
|
|
||||||
|
On the Panorama management server, Panorama administrators (PanoramaAdministrators) that are assigned a custom Panorama admin role (PanoramaAdmin Roles) with Push All Changes enabled
|
||||||
|
are unable to push configuration changes to managed firewalls when
|
||||||
|
Managed Devices and Push For
|
||||||
|
Other Admins are disabled.
|
||||||
|
|
||||||
|
## PAN-241041
|
||||||
|
|
||||||
|
On the Panorama management server exporting template or template
|
||||||
|
stack variables (PanoramaTemplates) in CSV format results in an empty CSV file.
|
||||||
|
|
||||||
|
## PAN-231507
|
||||||
|
|
||||||
|
On PA-1400 Series firewalls only, when an HSCI interface is used as
|
||||||
|
an HA2 interface, HA2 packets are intermittently dropped on the
|
||||||
|
passive device, which can cause the HA2 connection to flap due to
|
||||||
|
missing HA2 keepalive messages. Workaround: use data ports
|
||||||
|
configured as HA2 interface.
|
||||||
|
|
||||||
|
## PAN-228515
|
||||||
|
|
||||||
|
The EleasticSearch SSH flaps on the M-600 appliance in Panorama or
|
||||||
|
Log Collector mode. This causes logs to not display on the Panorama
|
||||||
|
management server (MonitorLogs) and the Log Collector health status (PanoramaManaged CollectorsStatus) to display as degraded.
|
||||||
|
|
||||||
|
## PAN-228273
|
||||||
|
|
||||||
|
On the Panorama management server in FIPS-CC mode, the ElasticSearch
|
||||||
|
cluster fails to come up and the show
|
||||||
|
log-collector-es-cluster health command displays
|
||||||
|
the status is
|
||||||
|
red. This results in log ingestion
|
||||||
|
issues for Panorama in Panorama only or Log Collector mode.
|
||||||
|
|
||||||
|
## PAN-227344
|
||||||
|
|
||||||
|
On the Panorama management server, PDF Summary Reports (MonitorPDF ReportsManage PDF Summary) display no data and are blank when predefined
|
||||||
|
reports are included in the summary report.
|
||||||
|
|
||||||
|
## PAN-225886
|
||||||
|
|
||||||
|
If you enable explicit proxy mode for the web proxy, intermittent
|
||||||
|
errors and unexpected TCP reconnections may occur.
|
||||||
|
|
||||||
|
## PAN-225337
|
||||||
|
|
||||||
|
On the Panorama management server, the configuration push to a
|
||||||
|
multi-vsys firewall fails if you:
|
||||||
|
|
||||||
|
1. Create a Shared and vsys-specific
|
||||||
|
device group configuration object with an indentical name.
|
||||||
|
For example, a Shared address object
|
||||||
|
called SharedAO1 and a
|
||||||
|
vsys-specific address object also called
|
||||||
|
SharedAO1.
|
||||||
|
2. Reference the Shared object in another
|
||||||
|
Shared configuration. For
|
||||||
|
example, reference the Shared address
|
||||||
|
object (SharedAO1) in a
|
||||||
|
Shared address group called
|
||||||
|
SharedAG1.
|
||||||
|
3. Use the Shared configuration object
|
||||||
|
with the reference in a vsys-specific configuration. For
|
||||||
|
example, reference the Shared address
|
||||||
|
group (SharedAG1) in a
|
||||||
|
vsys-specific policy rule.
|
||||||
|
|
||||||
|
Workaround: Select PanoramaSetupManagement and edit the Panorama Settings to enable one of the
|
||||||
|
following:
|
||||||
|
|
||||||
|
- Shared Unused Address and Service Objects with
|
||||||
|
Devices—This options pushes all
|
||||||
|
Shared objects, along with device
|
||||||
|
group specific objects, to managed firewalls.
|
||||||
|
This is a global setting and applies to all managed
|
||||||
|
firewalls, and may result in pushing too many configuration
|
||||||
|
objects to your managed firewalls.
|
||||||
|
- Objects defined in ancestors will take higher
|
||||||
|
precedence—This option specifies that in the event
|
||||||
|
of objects with the same name, ancestor object take
|
||||||
|
precedence over descendent objects. In this case, the
|
||||||
|
Shared objects take precedence
|
||||||
|
over the vsys-specific object.
|
||||||
|
This is a global setting and applies to all managed
|
||||||
|
firewalls. In the example above, if the IP address for the
|
||||||
|
Shared
|
||||||
|
SharedAO1 object was
|
||||||
|
10.1.1.1 and the device
|
||||||
|
group specific SharedAO1 was
|
||||||
|
10.2.2.2, the
|
||||||
|
10.1.1.1 IP address takes
|
||||||
|
precedence.
|
||||||
|
|
||||||
|
Alternatively, you can remove the duplicate address objects from the
|
||||||
|
device group configuration to allow only the
|
||||||
|
Shared objects in your configuration.
|
||||||
|
|
||||||
|
## PAN-223488
|
||||||
|
|
||||||
|
Closed ElasticSearch shards are not deleted from the Panorama
|
||||||
|
M-Series and virtual appliance. This causes the ElasticSearch shard
|
||||||
|
purging to not work as expected, resulting in high disk usage.
|
||||||
|
|
||||||
|
## PAN-223365
|
||||||
|
|
||||||
|
The Panorama management server is unable to query any logs if the
|
||||||
|
ElasticSearch health status for any Log Collector (PanoramaManaged Collector is degraded.
|
||||||
|
|
||||||
|
Workaround:
|
||||||
|
Log in to the Log Collector
|
||||||
|
CLI and restart ElasticSearch.
|
||||||
|
|
||||||
|
admindebug elasticsearch es-restart all
|
||||||
|
|
||||||
|
## PAN-227368
|
||||||
|
|
||||||
|
The GlobalProtect app cannot connect to a portal or gateway and
|
||||||
|
GlobalProtect Clientless VPN users cannot access applications if
|
||||||
|
authentication takes longer than 20 seconds.
|
||||||
|
|
||||||
|
Workaround: Increase the TCP handshake timeout to the maximum
|
||||||
|
value of 60 seconds.
|
||||||
|
|
||||||
|
## PAN-222586
|
||||||
|
|
||||||
|
On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter
|
||||||
|
dropdown menus, Forward Methods, and Built-In Actions for
|
||||||
|
Correlation Log settings (DeviceLog Settings) are not displayed and cannot be configured.
|
||||||
|
|
||||||
|
## PAN-222253
|
||||||
|
|
||||||
|
On the Panorama management server, policy rulebase reordering when
|
||||||
|
you View Rulebase by Groups (Policy<policy-rulebase>) does not persist if you reorder the policy rulebase
|
||||||
|
by dragging and dropping individual policy rules and then moving the
|
||||||
|
entire tag group.
|
||||||
|
|
||||||
|
## PAN-221126
|
||||||
|
|
||||||
|
Email server profiles (DeviceServer ProfilesEmail and PanoramaServer ProfilesEmail) to forward logs as email notifications are not
|
||||||
|
forwarded in a readable format.
|
||||||
|
|
||||||
|
Workaround: Use a Custom Log Format to
|
||||||
|
forward logs as email notifications in a readable format.
|
||||||
|
|
||||||
|
## PAN-221015
|
||||||
|
|
||||||
|
On M-600 appliances in Panorama or Log Collector mode, the
|
||||||
|
es-1 and
|
||||||
|
es-2 ElasticSearch processes fail
|
||||||
|
to restart when the M-600 appliance is rebooted. The results in the
|
||||||
|
Managed Collector ES health status (PanoramaManaged CollectorsHealth Status) to be degraded.
|
||||||
|
|
||||||
|
Workaround:
|
||||||
|
Log in to the Panorama or Log
|
||||||
|
Collector CLI experiencing degraded ElasticSearch health
|
||||||
|
and restart all ElasticSearch processes.
|
||||||
|
|
||||||
|
admin>debug elasticsearch es-restart optional all
|
||||||
|
|
||||||
|
Code copied to clipboard
|
||||||
|
|
||||||
|
Unable to copy due to lack of browser support.
|
||||||
|
|
||||||
|
Copy
|
||||||
|
|
||||||
|
## PAN-220180
|
||||||
|
|
||||||
|
Configured botnet reports (MonitorBotnet) are not generated.
|
||||||
|
|
||||||
|
## PAN-220176
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 11.0.1-h2 hotfix
|
||||||
|
```
|
||||||
|
|
||||||
|
System process crashes might occur
|
||||||
|
with VoIP traffic when NAT is enabled with Persistent Dynamic IP and
|
||||||
|
Port settings.
|
||||||
|
|
||||||
|
## PAN-219644
|
||||||
|
|
||||||
|
Firewalls forwarding logs to a syslog server over TLS (ObjectsLog Forwarding) use the default Palo Alto Networks certificate
|
||||||
|
instead of the custom certificate configured on the firewall.
|
||||||
|
|
||||||
|
## PAN-218521
|
||||||
|
|
||||||
|
The ElasticSearch process on the M-600 appliance in Log Collector
|
||||||
|
mode may enter a continuous reboot cycle. This results in the M-600
|
||||||
|
appliance becoming unresponsive, consuming logging disk space, and
|
||||||
|
preventing new log ingestion.
|
||||||
|
|
||||||
|
## PAN-217307
|
||||||
|
|
||||||
|
The following Security policy rule (PoliciesSecurity) filters return no results:
|
||||||
|
|
||||||
|
log-start eq no
|
||||||
|
|
||||||
|
log-end eq no
|
||||||
|
|
||||||
|
log-end eq yes
|
||||||
|
|
||||||
|
## PAN-216314
|
||||||
|
|
||||||
|
Upon upgrade or downgrade to or from PAN-OS 10.1.9 or 10.1.9-h1,
|
||||||
|
offloaded application traffic sessions may disconnect after a period
|
||||||
|
of time even if a session is active. The disconnect occurs after the
|
||||||
|
application's default session timeout value is exceeded. This
|
||||||
|
behavior affects only PAN-OS 10.1.9 and 10.1.9-h1. If you are on
|
||||||
|
PAN-OS 10.1.9 and 10.1.9-h1, please use the following workaround. If
|
||||||
|
you have already upgraded or downgraded to another PAN-OS version,
|
||||||
|
use the following workaround in that version.
|
||||||
|
|
||||||
|
Workaround: Run the CLI command debug dataplane
|
||||||
|
internal pdt fe100 csr wr_sem_ctrl_ctr_scan_dis value
|
||||||
|
0 to set the value to zero (0).
|
||||||
|
|
||||||
|
## PAN-216214
|
||||||
|
|
||||||
|
For Panorama-managed firewalls in an Active/Active High Availability
|
||||||
|
(HA) configuration where you configure the firewall HA settings (DeviceHigh Availability) in a template or template stack (PanoramaTemplates), performing a local commit on one of the HA
|
||||||
|
firewalls triggers an HA config sync on the peer firewall. This
|
||||||
|
causes the HA peer configuration to go Out of
|
||||||
|
Sync.
|
||||||
|
|
||||||
|
## PAN-213746
|
||||||
|
|
||||||
|
On the Panorama management server, the Hostkey
|
||||||
|
displayed as undefined undefined if you
|
||||||
|
override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template
|
||||||
|
Stack.
|
||||||
|
|
||||||
|
## PAN-213119
|
||||||
|
|
||||||
|
PA-5410 and PA-5420 firewalls display the following error when you
|
||||||
|
view the Block IP list (MonitorBlock IP):
|
||||||
|
|
||||||
|
show -> dis-block-table is
|
||||||
|
unexpected
|
||||||
|
|
||||||
|
## PAN-212978
|
||||||
|
|
||||||
|
The Palo Alto Networks firewall stops responding when executing an
|
||||||
|
SD-WAN debug operational CLI command.
|
||||||
|
|
||||||
|
## PAN-212889
|
||||||
|
|
||||||
|
On the Panorama management server, different threat names are used
|
||||||
|
when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the
|
||||||
|
ACC displaying no data to display when
|
||||||
|
you are redirected to the ACC after clicking a threat name in the
|
||||||
|
Threat Monitor and filtering the same threat name in the Global
|
||||||
|
Filters.
|
||||||
|
|
||||||
|
## PAN-211531
|
||||||
|
|
||||||
|
On the Panorama management server, admins can still
|
||||||
|
perform a selective push to managed firewalls when Push All
|
||||||
|
Changes and Push for Other Admins
|
||||||
|
are disabled in the admin role profile (PanoramaAdmin Roles).
|
||||||
|
|
||||||
|
## PAN-207770
|
||||||
|
|
||||||
|
Data filtering logs (MonitorLogsData Filtering)
|
||||||
|
incorrectly display the traffic Direction as server-to-client instead
|
||||||
|
of client-to-server for upload traffic
|
||||||
|
that matches Enterprise data loss prevention (DLP) data patterns (ObjectsDLPData
|
||||||
|
Filtering Patterns) in an Enterprise DLP data
|
||||||
|
filtering profile (ObjectsDLPData Filtering Profiles).
|
||||||
|
|
||||||
|
## PAN-207733
|
||||||
|
|
||||||
|
When a DHCPv6 client is configured on HA
|
||||||
|
Active/Passive firewalls, if the DHCPv6 server goes down, after
|
||||||
|
the lease time expires, the DHCPv6 client should enter SOLICIT state
|
||||||
|
on both the Active and Passive firewalls. Instead, the client is
|
||||||
|
stuck in BOUND state with an IPv6 address having lease time 0 on
|
||||||
|
the Passive firewall.
|
||||||
|
|
||||||
|
## PAN-207616
|
||||||
|
|
||||||
|
On the Panorama management server, after
|
||||||
|
selecting managed firewalls and creating a new Tag (PanoramaManaged DevicesSummary) the managed firewalls are
|
||||||
|
automatically unselected and any new tag created is applied to the
|
||||||
|
managed firewalls for which you initially created the new tag.
|
||||||
|
|
||||||
|
Workaround: Select
|
||||||
|
and then unselect the managed firewalls for which you created a
|
||||||
|
new tag.
|
||||||
|
|
||||||
|
## PAN-207611
|
||||||
|
|
||||||
|
When a DHCPv6 client is configured on HA
|
||||||
|
Active/Passive firewalls, the Passive firewall sometimes crashes.
|
||||||
|
|
||||||
|
## PAN-207442
|
||||||
|
|
||||||
|
For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the
|
||||||
|
active-primary HA peer
|
||||||
|
configuration sync to the
|
||||||
|
secondary-passive HA peer may fail.
|
||||||
|
When the config sync fails, the job Results is
|
||||||
|
Successful
|
||||||
|
(Tasks), however the sync status on the
|
||||||
|
Dashboard displays as Out
|
||||||
|
of Sync for both HA peers.
|
||||||
|
|
||||||
|
Workaround: Perform a local commit on the
|
||||||
|
active-primary HA peer and then
|
||||||
|
synchronize the HA configuration.
|
||||||
|
|
||||||
|
1. Log in to the Panorama
|
||||||
|
web interface of the
|
||||||
|
active-primary HA peer.
|
||||||
|
2. Select Commit and Commit to
|
||||||
|
Panorama.
|
||||||
|
3. In the active-primary HA peer
|
||||||
|
Dashboard, click Sync
|
||||||
|
to Peer in the High Availability widget.
|
||||||
|
|
||||||
|
## PAN-207040
|
||||||
|
|
||||||
|
If you disable Advanced Routing, remove
|
||||||
|
logical routers, and downgrade from PAN-OS 11.0.0 to a PAN-OS 10.2.x
|
||||||
|
or 10.1.x release, subsequent commits fail and SD-WAN devices on
|
||||||
|
Panorama have no Virtual Router name.
|
||||||
|
|
||||||
|
## PAN-206913
|
||||||
|
|
||||||
|
When a DHCPv6 client is configured on HA
|
||||||
|
Active/Passive firewalls, releasing the IPv6 address from the client
|
||||||
|
(using Release in the UI or using the request dhcp client ipv6 release all CLI
|
||||||
|
command) releases the IPv6 address from the Active firewall, but
|
||||||
|
not the Passive firewall.
|
||||||
|
|
||||||
|
## PAN-206909
|
||||||
|
|
||||||
|
The Dedicated Log Collector is unable to
|
||||||
|
reconnect to the Panorama management server if the configd process
|
||||||
|
crashes. This results in the Dedicated Log Collector losing connectivity
|
||||||
|
to Panorama despite the managed collector connection Status (PanoramaManaged Collector)
|
||||||
|
displaying connected and the managed colletor Health status displaying
|
||||||
|
as healthy.
|
||||||
|
|
||||||
|
This results in the local Panorama config and
|
||||||
|
system logs not being forwarded to the Dedicated Log Collector.
|
||||||
|
Firewall log forwarding to the disconnected Dedicated Log Collector
|
||||||
|
is not impacted.
|
||||||
|
|
||||||
|
Workaround: Restart the mgmtsrvr process
|
||||||
|
on the Dedicated Log Collector.
|
||||||
|
|
||||||
|
1. Log in to the Dedicated Log Collector
|
||||||
|
CLI.
|
||||||
|
2. Confirm the Dedicated Log Collector is disconnected from
|
||||||
|
Panorama.
|
||||||
|
admin> show panorama-status
|
||||||
|
Verify
|
||||||
|
the Connected status is no.
|
||||||
|
3. Restart the mgmtsrvr process.
|
||||||
|
admin> debug software restart process management-server
|
||||||
|
|
||||||
|
## PAN-206416
|
||||||
|
|
||||||
|
On the Panorama management server, no data
|
||||||
|
filtering log (MonitorLogsData Filtering) is generated
|
||||||
|
when the managed firewall loses connectivity to the following cloud services,
|
||||||
|
and as a result fails to forward matched traffic for inspection.
|
||||||
|
|
||||||
|
- DLP cloud service
|
||||||
|
- Advanced Threat Protection inline cloud analysis service
|
||||||
|
- Advanced URL Filtering cloud service
|
||||||
|
|
||||||
|
## PAN-206315
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1420 firewall only
|
||||||
|
```
|
||||||
|
|
||||||
|
In an active/passive high
|
||||||
|
availability (HA) configuration, the show session info CLI
|
||||||
|
command shows that the passive firewall has packet rate and throughput
|
||||||
|
values. The packet rate and throughput of the passive firewall should
|
||||||
|
be zero since it is not processing traffic.
|
||||||
|
|
||||||
|
## PAN-205009
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1420 firewall only
|
||||||
|
```
|
||||||
|
|
||||||
|
In an active/passive high
|
||||||
|
availability (HA) configuration, the show interface all, show-high availability interface ha2,
|
||||||
|
and show high-availability all CLI
|
||||||
|
commands display the HSCI port state as unknown on both the active
|
||||||
|
and passive firewalls.
|
||||||
|
|
||||||
|
## PAN-204689
|
||||||
|
|
||||||
|
Upon upgrade to PAN-OS 11.0.1, the following GlobalProtect settings
|
||||||
|
do not work:
|
||||||
|
|
||||||
|
- Allow user to disconnect GlobalProtect
|
||||||
|
AppAllow with Passcode
|
||||||
|
- Allow user to Disable GlobalProtect
|
||||||
|
AppAllow with Passcode
|
||||||
|
- Allow User to Uninstall GlobalProtect
|
||||||
|
AppAllow with Password
|
||||||
|
|
||||||
|
## PAN-201910
|
||||||
|
|
||||||
|
PAN-OS security profiles might consume a
|
||||||
|
large amount of memory depending on the profile configuration and
|
||||||
|
quantity. In some cases, this might reduce the number of supported security
|
||||||
|
profiles below the stated maximum for a given platform.
|
||||||
|
|
||||||
|
## PAN-197588
|
||||||
|
|
||||||
|
The PAN-OS ACC (Application Command Center)
|
||||||
|
does not display a widget detailing statistics and data associated
|
||||||
|
with vulnerability exploits that have been detected using inline
|
||||||
|
cloud analysis.
|
||||||
|
|
||||||
|
## PAN-197419
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
In NetworkInterfaceEthernet, the power over Ethernet
|
||||||
|
(PoE) ports do not display a Tag value.
|
||||||
|
|
||||||
|
## PAN-197097
|
||||||
|
|
||||||
|
Large Scale VPN (LSVPN) does not support
|
||||||
|
IPv6 addresses on the satellite firewall.
|
||||||
|
|
||||||
|
## PAN-196758
|
||||||
|
|
||||||
|
On the Panorama management server, pushing
|
||||||
|
a configuration change to firewalls leveraging SD-WAN erroneously
|
||||||
|
show the auto-provisioned BGP configurations for SD-WAN as being
|
||||||
|
edited or deleted despite no edits or deletions being made when
|
||||||
|
you Preview Changes (CommitPush to DevicesEdit Selections or CommitCommit and PushEdit Selections).
|
||||||
|
|
||||||
|
## PAN-196146
|
||||||
|
|
||||||
|
The VM-Series firewall on Azure does not
|
||||||
|
boot up with a hostname (specified in an init-cgf.txt or user data)
|
||||||
|
when bootstrapped.
|
||||||
|
|
||||||
|
## PAN-195968
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
When using the CLI to configure power over Ethernet (PoE) on a non-PoE
|
||||||
|
port, the CLI prints an error depending on whether an interface
|
||||||
|
type was selected on the non-PoE port or not. If an interface type, such
|
||||||
|
as tap, Layer 2, or virtual wire, was selected before PoE was configured,
|
||||||
|
the error message will not include the interface name (eg. ethernet1/4).
|
||||||
|
If an interface type was not selected before PoE was configured,
|
||||||
|
the error message will include the interface name.
|
||||||
|
|
||||||
|
## PAN-195342
|
||||||
|
|
||||||
|
On the Panorama management server, Context
|
||||||
|
Switch fails when you try to Context Switch from a managed firewall running
|
||||||
|
PAN-OS 10.1.7 or earlier release back to Panorama and the following
|
||||||
|
error is displayed:
|
||||||
|
|
||||||
|
Could not find start token '@start@'
|
||||||
|
|
||||||
|
## PAN-194978
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
In NetworkInterfaceEthernet, hovering the mouse over
|
||||||
|
a power over Ethernet (PoE) Link State icon
|
||||||
|
does not display link speed and link duplex details.
|
||||||
|
|
||||||
|
## PAN-194424
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5450 firewall only
|
||||||
|
```
|
||||||
|
|
||||||
|
Upgrading
|
||||||
|
to PAN-OS 10.2.2 while having a log interface configured can cause
|
||||||
|
both the log interface and the management interface to remain connected
|
||||||
|
to the log collector.
|
||||||
|
|
||||||
|
Workaround: Restart the log receiver service
|
||||||
|
by running the following CLI command:
|
||||||
|
|
||||||
|
debug software restart process log-receiver
|
||||||
|
|
||||||
|
## PAN-193004
|
||||||
|
|
||||||
|
The Panorama management server fails to delete old IP Tag data. This
|
||||||
|
causes the /opt/pancfg partition to
|
||||||
|
reach maximum capacity which impacts Panorama performance.
|
||||||
|
|
||||||
|
## PAN-187685
|
||||||
|
|
||||||
|
On the Panorama management server, the Template Status
|
||||||
|
displays no synchronization status (PanoramaManaged DevicesSummary)
|
||||||
|
after a bootstrapped firewall is successfully added to Panorama.
|
||||||
|
|
||||||
|
Workaround: After
|
||||||
|
the bootstrapped firewall is successfully added to Panorama, log in to the Panorama web interface and
|
||||||
|
select CommitPush
|
||||||
|
to Devices.
|
||||||
|
|
||||||
|
## PAN-187407
|
||||||
|
|
||||||
|
The configured Advanced Threat Prevention
|
||||||
|
inline cloud analysis action for a given model might not be honored
|
||||||
|
under the following condition: If the firewall is set to Hold
|
||||||
|
client request for category lookup and the action set
|
||||||
|
to Reset-Both and the URL cache has been
|
||||||
|
cleared, the first request for inline cloud analysis will be bypassed.
|
||||||
|
|
||||||
|
## PAN-186283
|
||||||
|
|
||||||
|
Templates appear out-of-sync on Panorama
|
||||||
|
after successfully deploying the CFT stack using the Panorama plugin for
|
||||||
|
AWS.
|
||||||
|
|
||||||
|
Workaround: Use CommitPush to Devices to synchronize
|
||||||
|
the templates.
|
||||||
|
|
||||||
|
## PAN-184708
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama managed firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if:
|
||||||
|
|
||||||
|
- A scheduled report email contains
|
||||||
|
a Report Group (MonitorPDF
|
||||||
|
ReportsReport Group)
|
||||||
|
which includes a SaaS Application Usage report.
|
||||||
|
- A scheduled report contains only a SaaS Application Usage Report.
|
||||||
|
|
||||||
|
Workaround: To
|
||||||
|
receive a scheduled report email for all other PDF report types:
|
||||||
|
|
||||||
|
1. Select MonitorPDF ReportsReport Groups and
|
||||||
|
remove all SaaS Application Usage reports from all Report Groups.
|
||||||
|
2. Select MonitorPDF
|
||||||
|
ReportsEmail Scheduler and
|
||||||
|
edit the scheduled report email that contains only a SaaS Application Usage
|
||||||
|
report. For the Recurrence, select Disable and
|
||||||
|
click OK.
|
||||||
|
Repeat this step for all scheduled
|
||||||
|
report emails that contain only a SaaS Application Usage report.
|
||||||
|
3. Commit.
|
||||||
|
()
|
||||||
|
Select CommitCommit
|
||||||
|
and Push
|
||||||
|
|
||||||
|
## PAN-184406
|
||||||
|
|
||||||
|
Using the CLI to add a RAID disk pair to
|
||||||
|
an M-700 appliance causes the dmdb process to crash.
|
||||||
|
|
||||||
|
Workaround: Contact
|
||||||
|
customer support to stop the dmdb process before adding a RAID disk
|
||||||
|
pair to a M-700 appliance.
|
||||||
|
|
||||||
|
## PAN-183404
|
||||||
|
|
||||||
|
Static IP addresses are not recognized when
|
||||||
|
"and" operators are used with IP CIDR range.
|
||||||
|
|
||||||
|
## PAN-181933
|
||||||
|
|
||||||
|
If you use multiple log forwarding cards
|
||||||
|
(LFCs) on the PA-7000 series, all of the cards may not receive all
|
||||||
|
of the updates and the mappings for the clients may become out of sync,
|
||||||
|
which causes the firewall to not correctly populate the Source User
|
||||||
|
column in the session logs.
|
||||||
|
|
||||||
|
## PAN-171938
|
||||||
|
|
||||||
|
No results are displayed when you Show Application
|
||||||
|
Filter for a Security policy rule (PoliciesSecurityApplicationValueShow Application Filter).
|
||||||
|
|
||||||
|
## PAN-164885
|
||||||
|
|
||||||
|
On the Panorama management server, pushes to managed firewalls (CommitPush to Devices or Commit and Push) may fail
|
||||||
|
when an EDL (ObjectsExternal Dynamic Lists) is configured to Check for
|
||||||
|
updates every 5 minutes due to the commit and EDL
|
||||||
|
fetch processes overlapping. This is more likely to occur when
|
||||||
|
multiple EDLs are configured to check for updates every 5
|
||||||
|
minutes.
|
||||||
@@ -0,0 +1,667 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.3
|
||||||
|
---
|
||||||
|
|
||||||
|
## WF500-5632
|
||||||
|
|
||||||
|
The number of registered WildFire appliances
|
||||||
|
reported in Panorama (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the
|
||||||
|
current status of connected WildFire appliances.
|
||||||
|
|
||||||
|
## PAN-260851
|
||||||
|
|
||||||
|
From the NGFW or Panorama CLI, you can override the existing
|
||||||
|
application tag even if Disable Override is enabled for the
|
||||||
|
application (ObjectsApplications) tag.
|
||||||
|
|
||||||
|
## PAN-250062
|
||||||
|
|
||||||
|
Device telemetry might fail at configured intervals due to bundle generation issues.
|
||||||
|
|
||||||
|
## PAN-243951
|
||||||
|
|
||||||
|
On the Panorama management sever in an active/passive High
|
||||||
|
Availability (HA) configuration, managed devices (PanoramaManaged DevicesSummary) display as out-of-sync
|
||||||
|
on the passive HA peer when configuration changes are made to the
|
||||||
|
SD-WAN (PanoramaSD-WAN) configuration on the active HA peer.
|
||||||
|
|
||||||
|
Workaround: Manually synchronize the Panorama HA peers.
|
||||||
|
|
||||||
|
1. Log in to the Panorama web
|
||||||
|
interface on the active HA peer.
|
||||||
|
2. Select Commit and Commit to
|
||||||
|
Panorama the SD-WAN configuration changes on
|
||||||
|
the active HA peer.
|
||||||
|
On the passive HA peer, select PanoramaManaged DevicesSummary and observe that the managed devices are now
|
||||||
|
out-of-sync.
|
||||||
|
3. Log in to the primary HA peer Panorama CLI and
|
||||||
|
trigger a manual synchronization between the active and
|
||||||
|
secondary HA peers.
|
||||||
|
request high-availability sync-to-remote
|
||||||
|
running-config
|
||||||
|
4. Log back in to the active HA peer Panorama web interface and
|
||||||
|
select CommitPush to Devices and Push.
|
||||||
|
|
||||||
|
## PAN-241536
|
||||||
|
|
||||||
|
On the Panorama management server, a user with an Admin Role is
|
||||||
|
unable to modify or add filters to profiles under PanoramaNetworkRoutingRouting ProfilesFilters, despite having the necessary read and write
|
||||||
|
privileges.
|
||||||
|
|
||||||
|
## PAN-234408
|
||||||
|
|
||||||
|
Enterprise DLP cannot detect and block non-file based traffic for
|
||||||
|
ChatGPT from traffic forwarded to the DLP cloud service from an
|
||||||
|
NGFW.
|
||||||
|
|
||||||
|
## PAN-234015
|
||||||
|
|
||||||
|
The X-Forwarded-For (XFF) value is not displayed in traffic logs.
|
||||||
|
|
||||||
|
## PAN-242910
|
||||||
|
|
||||||
|
On the Panorama management server, Panorama administrators (PanoramaAdministrators) that are assigned a custom Panorama admin role (PanoramaAdmin Roles) with Push All Changes enabled
|
||||||
|
are unable to push configuration changes to managed firewalls when
|
||||||
|
Managed Devices and Push For
|
||||||
|
Other Admins are disabled.
|
||||||
|
|
||||||
|
## PAN-242837
|
||||||
|
|
||||||
|
Default login credentials and SSH fail after enabling FIPS-CC Mode on
|
||||||
|
a firewall or Panorama after converting through the Maintenance
|
||||||
|
Recovery Tool (MRT). The firewall or Panorama becomes stuck and
|
||||||
|
requires a factory reset to recover.
|
||||||
|
|
||||||
|
## PAN-241041
|
||||||
|
|
||||||
|
On the Panorama management server exporting template or template
|
||||||
|
stack variables (PanoramaTemplates) in CSV format results in an empty CSV file.
|
||||||
|
|
||||||
|
## PAN-238769
|
||||||
|
|
||||||
|
FIPS-CC VM only. Upgrading to 10.1.10-h2 or 10.1.11 will change all
|
||||||
|
locally created security Policy actions to Deny. Re-load the back-up
|
||||||
|
config taken before upgrading or the last version to get the
|
||||||
|
previous config back. Also, Unable to login to FIPSCC Mode devices
|
||||||
|
with default credentials after converting the mode for 10.1.12
|
||||||
|
release , 10.2.7 release , 11.1.0 , 11.1.1, 11.0.3 versions.
|
||||||
|
|
||||||
|
## PAN-234929
|
||||||
|
|
||||||
|
The tabs in the ACC, such as
|
||||||
|
Network Activity, Threat
|
||||||
|
Activity, and Blocked
|
||||||
|
Activity, may not display any data when you apply a
|
||||||
|
Time filter for the Last 15 minutes, Last Hour, Last 6 Hours, or
|
||||||
|
Last 12 Hours. With the Last 24 Hours filter, the data displayed may
|
||||||
|
not be accurate. Additionally, reports run against summary logs may
|
||||||
|
not display accurate results.
|
||||||
|
|
||||||
|
## PAN-231507
|
||||||
|
|
||||||
|
On PA-1400 Series firewalls only, when an HSCI interface is used as
|
||||||
|
an HA2 interface, HA2 packets are intermittently dropped on the
|
||||||
|
passive device, which can cause the HA2 connection to flap due to
|
||||||
|
missing HA2 keepalive messages. Workaround: use data ports
|
||||||
|
configured as HA2 interface.
|
||||||
|
|
||||||
|
## PAN-228515
|
||||||
|
|
||||||
|
The EleasticSearch SSH flaps on the M-600 appliance in Panorama or
|
||||||
|
Log Collector mode. This causes logs to not display on the Panorama
|
||||||
|
management server (MonitorLogs) and the Log Collector health status (PanoramaManaged CollectorsStatus) to display as degraded.
|
||||||
|
|
||||||
|
## PAN-227344
|
||||||
|
|
||||||
|
On the Panorama management server, PDF Summary Reports (MonitorPDF ReportsManage PDF Summary) display no data and are blank when predefined
|
||||||
|
reports are included in the summary report.
|
||||||
|
|
||||||
|
## PAN-225886
|
||||||
|
|
||||||
|
If you enable explicit proxy mode for the web proxy, intermittent
|
||||||
|
errors and unexpected TCP reconnections may occur.
|
||||||
|
|
||||||
|
## PAN-225337
|
||||||
|
|
||||||
|
On the Panorama management server, the configuration push to a
|
||||||
|
multi-vsys firewall fails if you:
|
||||||
|
|
||||||
|
1. Create a Shared and vsys-specific
|
||||||
|
device group configuration object with an indentical name.
|
||||||
|
For example, a Shared address object
|
||||||
|
called SharedAO1 and a
|
||||||
|
vsys-specific address object also called
|
||||||
|
SharedAO1.
|
||||||
|
2. Reference the Shared object in another
|
||||||
|
Shared configuration. For
|
||||||
|
example, reference the Shared address
|
||||||
|
object (SharedAO1) in a
|
||||||
|
Shared address group called
|
||||||
|
SharedAG1.
|
||||||
|
3. Use the Shared configuration object
|
||||||
|
with the reference in a vsys-specific configuration. For
|
||||||
|
example, reference the Shared address
|
||||||
|
group (SharedAG1) in a
|
||||||
|
vsys-specific policy rule.
|
||||||
|
|
||||||
|
Workaround: Select PanoramaSetupManagement and edit the Panorama Settings to enable one of the
|
||||||
|
following:
|
||||||
|
|
||||||
|
- Shared Unused Address and Service Objects with
|
||||||
|
Devices—This options pushes all
|
||||||
|
Shared objects, along with device
|
||||||
|
group specific objects, to managed firewalls.
|
||||||
|
This is a global setting and applies to all managed
|
||||||
|
firewalls, and may result in pushing too many configuration
|
||||||
|
objects to your managed firewalls.
|
||||||
|
- Objects defined in ancestors will take higher
|
||||||
|
precedence—This option specifies that in the event
|
||||||
|
of objects with the same name, ancestor object take
|
||||||
|
precedence over descendent objects. In this case, the
|
||||||
|
Shared objects take precedence
|
||||||
|
over the vsys-specific object.
|
||||||
|
This is a global setting and applies to all managed
|
||||||
|
firewalls. In the example above, if the IP address for the
|
||||||
|
Shared
|
||||||
|
SharedAO1 object was
|
||||||
|
10.1.1.1 and the device
|
||||||
|
group specific SharedAO1 was
|
||||||
|
10.2.2.2, the
|
||||||
|
10.1.1.1 IP address takes
|
||||||
|
precedence.
|
||||||
|
|
||||||
|
Alternatively, you can remove the duplicate address objects from the
|
||||||
|
device group configuration to allow only the
|
||||||
|
Shared objects in your configuration.
|
||||||
|
|
||||||
|
## PAN-233677
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, PA-5430, and PA-5440 firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
By enabling Lockless QoS feature, a
|
||||||
|
slight degradation in App-ID and Threat performance is expected.
|
||||||
|
|
||||||
|
## PAN-223365
|
||||||
|
|
||||||
|
The Panorama management server is unable to query any logs if the
|
||||||
|
ElasticSearch health status for any Log Collector (PanoramaManaged Collector is degraded.
|
||||||
|
|
||||||
|
Workaround:
|
||||||
|
Log in to the Log Collector
|
||||||
|
CLI and restart ElasticSearch.
|
||||||
|
|
||||||
|
admindebug elasticsearch es-restart all
|
||||||
|
|
||||||
|
## PAN-227368
|
||||||
|
|
||||||
|
The GlobalProtect app cannot connect to a portal or gateway and
|
||||||
|
GlobalProtect Clientless VPN users cannot access applications if
|
||||||
|
authentication takes longer than 20 seconds.
|
||||||
|
|
||||||
|
Workaround: Increase the TCP handshake timeout to the maximum
|
||||||
|
value of 60 seconds.
|
||||||
|
|
||||||
|
## PAN-222586
|
||||||
|
|
||||||
|
On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter
|
||||||
|
dropdown menus, Forward Methods, and Built-In Actions for
|
||||||
|
Correlation Log settings (DeviceLog Settings) are not displayed and cannot be configured.
|
||||||
|
|
||||||
|
## PAN-222253
|
||||||
|
|
||||||
|
On the Panorama management server, policy rulebase reordering when
|
||||||
|
you View Rulebase by Groups (Policy<policy-rulebase>) does not persist if you reorder the policy rulebase
|
||||||
|
by dragging and dropping individual policy rules and then moving the
|
||||||
|
entire tag group.
|
||||||
|
|
||||||
|
## PAN-221015
|
||||||
|
|
||||||
|
On M-600 appliances in Panorama or Log Collector mode, the
|
||||||
|
es-1 and
|
||||||
|
es-2 ElasticSearch processes fail
|
||||||
|
to restart when the M-600 appliance is rebooted. The results in the
|
||||||
|
Managed Collector ES health status (PanoramaManaged CollectorsHealth Status) to be degraded.
|
||||||
|
|
||||||
|
Workaround:
|
||||||
|
Log in to the Panorama or Log
|
||||||
|
Collector CLI experiencing degraded ElasticSearch health
|
||||||
|
and restart all ElasticSearch processes.
|
||||||
|
|
||||||
|
admin>debug elasticsearch es-restart optional all
|
||||||
|
|
||||||
|
Code copied to clipboard
|
||||||
|
|
||||||
|
Unable to copy due to lack of browser support.
|
||||||
|
|
||||||
|
Copy
|
||||||
|
|
||||||
|
## PAN-220176
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 11.0.1-h2 hotfix
|
||||||
|
```
|
||||||
|
|
||||||
|
System process crashes might occur
|
||||||
|
with VoIP traffic when NAT is enabled with Persistent Dynamic IP and
|
||||||
|
Port settings.
|
||||||
|
|
||||||
|
## PAN-218521
|
||||||
|
|
||||||
|
The ElasticSearch process on the M-600 appliance in Log Collector
|
||||||
|
mode may enter a continuous reboot cycle. This results in the M-600
|
||||||
|
appliance becoming unresponsive, consuming logging disk space, and
|
||||||
|
preventing new log ingestion.
|
||||||
|
|
||||||
|
## PAN-217307
|
||||||
|
|
||||||
|
The following Security policy rule (PoliciesSecurity) filters return no results:
|
||||||
|
|
||||||
|
log-start eq no
|
||||||
|
|
||||||
|
log-end eq no
|
||||||
|
|
||||||
|
log-end eq yes
|
||||||
|
|
||||||
|
## PAN-216314
|
||||||
|
|
||||||
|
Upon upgrade or downgrade to or from PAN-OS 10.1.9 or 10.1.9-h1,
|
||||||
|
offloaded application traffic sessions may disconnect after a period
|
||||||
|
of time even if a session is active. The disconnect occurs after the
|
||||||
|
application's default session timeout value is exceeded. This
|
||||||
|
behavior affects only PAN-OS 10.1.9 and 10.1.9-h1. If you are on
|
||||||
|
PAN-OS 10.1.9 and 10.1.9-h1, please use the following workaround. If
|
||||||
|
you have already upgraded or downgraded to another PAN-OS version,
|
||||||
|
use the following workaround in that version.
|
||||||
|
|
||||||
|
Workaround: Run the CLI command debug dataplane
|
||||||
|
internal pdt fe100 csr wr_sem_ctrl_ctr_scan_dis value
|
||||||
|
0 to set the value to zero (0).
|
||||||
|
|
||||||
|
## PAN-216214
|
||||||
|
|
||||||
|
For Panorama-managed firewalls in an Active/Active High Availability
|
||||||
|
(HA) configuration where you configure the firewall HA settings (DeviceHigh Availability) in a template or template stack (PanoramaTemplates), performing a local commit on one of the HA
|
||||||
|
firewalls triggers an HA config sync on the peer firewall. This
|
||||||
|
causes the HA peer configuration to go Out of
|
||||||
|
Sync.
|
||||||
|
|
||||||
|
## PAN-213746
|
||||||
|
|
||||||
|
On the Panorama management server, the Hostkey
|
||||||
|
displayed as undefined undefined if you
|
||||||
|
override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template
|
||||||
|
Stack.
|
||||||
|
|
||||||
|
## PAN-213119
|
||||||
|
|
||||||
|
PA-5410 and PA-5420 firewalls display the following error when you
|
||||||
|
view the Block IP list (MonitorBlock IP):
|
||||||
|
|
||||||
|
show -> dis-block-table is
|
||||||
|
unexpected
|
||||||
|
|
||||||
|
## PAN-212978
|
||||||
|
|
||||||
|
The Palo Alto Networks firewall stops responding when executing an
|
||||||
|
SD-WAN debug operational CLI command.
|
||||||
|
|
||||||
|
## PAN-212889
|
||||||
|
|
||||||
|
On the Panorama management server, different threat names are used
|
||||||
|
when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the
|
||||||
|
ACC displaying no data to display when
|
||||||
|
you are redirected to the ACC after clicking a threat name in the
|
||||||
|
Threat Monitor and filtering the same threat name in the Global
|
||||||
|
Filters.
|
||||||
|
|
||||||
|
## PAN-211531
|
||||||
|
|
||||||
|
On the Panorama management server, admins can still
|
||||||
|
perform a selective push to managed firewalls when Push All
|
||||||
|
Changes and Push for Other Admins
|
||||||
|
are disabled in the admin role profile (PanoramaAdmin Roles).
|
||||||
|
|
||||||
|
## PAN-207770
|
||||||
|
|
||||||
|
Data filtering logs (MonitorLogsData Filtering)
|
||||||
|
incorrectly display the traffic Direction as server-to-client instead
|
||||||
|
of client-to-server for upload traffic
|
||||||
|
that matches Enterprise data loss prevention (DLP) data patterns (ObjectsDLPData
|
||||||
|
Filtering Patterns) in an Enterprise DLP data
|
||||||
|
filtering profile (ObjectsDLPData Filtering Profiles).
|
||||||
|
|
||||||
|
## PAN-207733
|
||||||
|
|
||||||
|
When a DHCPv6 client is configured on HA
|
||||||
|
Active/Passive firewalls, if the DHCPv6 server goes down, after
|
||||||
|
the lease time expires, the DHCPv6 client should enter SOLICIT state
|
||||||
|
on both the Active and Passive firewalls. Instead, the client is
|
||||||
|
stuck in BOUND state with an IPv6 address having lease time 0 on
|
||||||
|
the Passive firewall.
|
||||||
|
|
||||||
|
## PAN-207616
|
||||||
|
|
||||||
|
On the Panorama management server, after
|
||||||
|
selecting managed firewalls and creating a new Tag (PanoramaManaged DevicesSummary) the managed firewalls are
|
||||||
|
automatically unselected and any new tag created is applied to the
|
||||||
|
managed firewalls for which you initially created the new tag.
|
||||||
|
|
||||||
|
Workaround: Select
|
||||||
|
and then unselect the managed firewalls for which you created a
|
||||||
|
new tag.
|
||||||
|
|
||||||
|
## PAN-207611
|
||||||
|
|
||||||
|
When a DHCPv6 client is configured on HA
|
||||||
|
Active/Passive firewalls, the Passive firewall sometimes crashes.
|
||||||
|
|
||||||
|
## PAN-207442
|
||||||
|
|
||||||
|
For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the
|
||||||
|
active-primary HA peer
|
||||||
|
configuration sync to the
|
||||||
|
secondary-passive HA peer may fail.
|
||||||
|
When the config sync fails, the job Results is
|
||||||
|
Successful
|
||||||
|
(Tasks), however the sync status on the
|
||||||
|
Dashboard displays as Out
|
||||||
|
of Sync for both HA peers.
|
||||||
|
|
||||||
|
Workaround: Perform a local commit on the
|
||||||
|
active-primary HA peer and then
|
||||||
|
synchronize the HA configuration.
|
||||||
|
|
||||||
|
1. Log in to the Panorama
|
||||||
|
web interface of the
|
||||||
|
active-primary HA peer.
|
||||||
|
2. Select Commit and Commit to
|
||||||
|
Panorama.
|
||||||
|
3. In the active-primary HA peer
|
||||||
|
Dashboard, click Sync
|
||||||
|
to Peer in the High Availability widget.
|
||||||
|
|
||||||
|
## PAN-207040
|
||||||
|
|
||||||
|
If you disable Advanced Routing, remove
|
||||||
|
logical routers, and downgrade from PAN-OS 11.0.0 to a PAN-OS 10.2.x
|
||||||
|
or 10.1.x release, subsequent commits fail and SD-WAN devices on
|
||||||
|
Panorama have no Virtual Router name.
|
||||||
|
|
||||||
|
## PAN-206913
|
||||||
|
|
||||||
|
When a DHCPv6 client is configured on HA
|
||||||
|
Active/Passive firewalls, releasing the IPv6 address from the client
|
||||||
|
(using Release in the UI or using the request dhcp client ipv6 release all CLI
|
||||||
|
command) releases the IPv6 address from the Active firewall, but
|
||||||
|
not the Passive firewall.
|
||||||
|
|
||||||
|
## PAN-206909
|
||||||
|
|
||||||
|
The Dedicated Log Collector is unable to
|
||||||
|
reconnect to the Panorama management server if the configd process
|
||||||
|
crashes. This results in the Dedicated Log Collector losing connectivity
|
||||||
|
to Panorama despite the managed collector connection Status (PanoramaManaged Collector)
|
||||||
|
displaying connected and the managed colletor Health status displaying
|
||||||
|
as healthy.
|
||||||
|
|
||||||
|
This results in the local Panorama config and
|
||||||
|
system logs not being forwarded to the Dedicated Log Collector.
|
||||||
|
Firewall log forwarding to the disconnected Dedicated Log Collector
|
||||||
|
is not impacted.
|
||||||
|
|
||||||
|
Workaround: Restart the mgmtsrvr process
|
||||||
|
on the Dedicated Log Collector.
|
||||||
|
|
||||||
|
1. Log in to the Dedicated Log Collector
|
||||||
|
CLI.
|
||||||
|
2. Confirm the Dedicated Log Collector is disconnected from
|
||||||
|
Panorama.
|
||||||
|
admin> show panorama-status
|
||||||
|
Verify
|
||||||
|
the Connected status is no.
|
||||||
|
3. Restart the mgmtsrvr process.
|
||||||
|
admin> debug software restart process management-server
|
||||||
|
|
||||||
|
## PAN-206416
|
||||||
|
|
||||||
|
On the Panorama management server, no data
|
||||||
|
filtering log (MonitorLogsData Filtering) is generated
|
||||||
|
when the managed firewall loses connectivity to the following cloud services,
|
||||||
|
and as a result fails to forward matched traffic for inspection.
|
||||||
|
|
||||||
|
- DLP cloud service
|
||||||
|
- Advanced Threat Protection inline cloud analysis service
|
||||||
|
- Advanced URL Filtering cloud service
|
||||||
|
|
||||||
|
## PAN-206315
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1420 firewall only
|
||||||
|
```
|
||||||
|
|
||||||
|
In an active/passive high
|
||||||
|
availability (HA) configuration, the show session info CLI
|
||||||
|
command shows that the passive firewall has packet rate and throughput
|
||||||
|
values. The packet rate and throughput of the passive firewall should
|
||||||
|
be zero since it is not processing traffic.
|
||||||
|
|
||||||
|
## PAN-205009
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1420 firewall only
|
||||||
|
```
|
||||||
|
|
||||||
|
In an active/passive high
|
||||||
|
availability (HA) configuration, the show interface all, show-high availability interface ha2,
|
||||||
|
and show high-availability all CLI
|
||||||
|
commands display the HSCI port state as unknown on both the active
|
||||||
|
and passive firewalls.
|
||||||
|
|
||||||
|
## PAN-204689
|
||||||
|
|
||||||
|
Upon upgrade to PAN-OS 11.0.1, the following GlobalProtect settings
|
||||||
|
do not work:
|
||||||
|
|
||||||
|
- Allow user to disconnect GlobalProtect
|
||||||
|
AppAllow with Passcode
|
||||||
|
- Allow user to Disable GlobalProtect
|
||||||
|
AppAllow with Passcode
|
||||||
|
- Allow User to Uninstall GlobalProtect
|
||||||
|
AppAllow with Password
|
||||||
|
|
||||||
|
## PAN-201910
|
||||||
|
|
||||||
|
PAN-OS security profiles might consume a
|
||||||
|
large amount of memory depending on the profile configuration and
|
||||||
|
quantity. In some cases, this might reduce the number of supported security
|
||||||
|
profiles below the stated maximum for a given platform.
|
||||||
|
|
||||||
|
## PAN-197588
|
||||||
|
|
||||||
|
The PAN-OS ACC (Application Command Center)
|
||||||
|
does not display a widget detailing statistics and data associated
|
||||||
|
with vulnerability exploits that have been detected using inline
|
||||||
|
cloud analysis.
|
||||||
|
|
||||||
|
## PAN-197419
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
In NetworkInterfaceEthernet, the power over Ethernet
|
||||||
|
(PoE) ports do not display a Tag value.
|
||||||
|
|
||||||
|
## PAN-197097
|
||||||
|
|
||||||
|
Large Scale VPN (LSVPN) does not support
|
||||||
|
IPv6 addresses on the satellite firewall.
|
||||||
|
|
||||||
|
## PAN-196758
|
||||||
|
|
||||||
|
On the Panorama management server, pushing
|
||||||
|
a configuration change to firewalls leveraging SD-WAN erroneously
|
||||||
|
show the auto-provisioned BGP configurations for SD-WAN as being
|
||||||
|
edited or deleted despite no edits or deletions being made when
|
||||||
|
you Preview Changes (CommitPush to DevicesEdit Selections or CommitCommit and PushEdit Selections).
|
||||||
|
|
||||||
|
## PAN-196146
|
||||||
|
|
||||||
|
The VM-Series firewall on Azure does not
|
||||||
|
boot up with a hostname (specified in an init-cgf.txt or user data)
|
||||||
|
when bootstrapped.
|
||||||
|
|
||||||
|
## PAN-195968
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
When using the CLI to configure power over Ethernet (PoE) on a non-PoE
|
||||||
|
port, the CLI prints an error depending on whether an interface
|
||||||
|
type was selected on the non-PoE port or not. If an interface type, such
|
||||||
|
as tap, Layer 2, or virtual wire, was selected before PoE was configured,
|
||||||
|
the error message will not include the interface name (eg. ethernet1/4).
|
||||||
|
If an interface type was not selected before PoE was configured,
|
||||||
|
the error message will include the interface name.
|
||||||
|
|
||||||
|
## PAN-195342
|
||||||
|
|
||||||
|
On the Panorama management server, Context
|
||||||
|
Switch fails when you try to Context Switch from a managed firewall running
|
||||||
|
PAN-OS 10.1.7 or earlier release back to Panorama and the following
|
||||||
|
error is displayed:
|
||||||
|
|
||||||
|
Could not find start token '@start@'
|
||||||
|
|
||||||
|
## PAN-194978
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
In NetworkInterfaceEthernet, hovering the mouse over
|
||||||
|
a power over Ethernet (PoE) Link State icon
|
||||||
|
does not display link speed and link duplex details.
|
||||||
|
|
||||||
|
## PAN-194424
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5450 firewall only
|
||||||
|
```
|
||||||
|
|
||||||
|
Upgrading
|
||||||
|
to PAN-OS 10.2.2 while having a log interface configured can cause
|
||||||
|
both the log interface and the management interface to remain connected
|
||||||
|
to the log collector.
|
||||||
|
|
||||||
|
Workaround: Restart the log receiver service
|
||||||
|
by running the following CLI command:
|
||||||
|
|
||||||
|
debug software restart process log-receiver
|
||||||
|
|
||||||
|
## PAN-193004
|
||||||
|
|
||||||
|
The Panorama management server fails to delete old IP Tag data. This
|
||||||
|
causes the /opt/pancfg partition to
|
||||||
|
reach maximum capacity which impacts Panorama performance.
|
||||||
|
|
||||||
|
## PAN-187685
|
||||||
|
|
||||||
|
On the Panorama management server, the Template Status
|
||||||
|
displays no synchronization status (PanoramaManaged DevicesSummary)
|
||||||
|
after a bootstrapped firewall is successfully added to Panorama.
|
||||||
|
|
||||||
|
Workaround: After
|
||||||
|
the bootstrapped firewall is successfully added to Panorama, log in to the Panorama web interface and
|
||||||
|
select CommitPush
|
||||||
|
to Devices.
|
||||||
|
|
||||||
|
## PAN-187407
|
||||||
|
|
||||||
|
The configured Advanced Threat Prevention
|
||||||
|
inline cloud analysis action for a given model might not be honored
|
||||||
|
under the following condition: If the firewall is set to Hold
|
||||||
|
client request for category lookup and the action set
|
||||||
|
to Reset-Both and the URL cache has been
|
||||||
|
cleared, the first request for inline cloud analysis will be bypassed.
|
||||||
|
|
||||||
|
## PAN-186283
|
||||||
|
|
||||||
|
Templates appear out-of-sync on Panorama
|
||||||
|
after successfully deploying the CFT stack using the Panorama plugin for
|
||||||
|
AWS.
|
||||||
|
|
||||||
|
Workaround: Use CommitPush to Devices to synchronize
|
||||||
|
the templates.
|
||||||
|
|
||||||
|
## PAN-184708
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama managed firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if:
|
||||||
|
|
||||||
|
- A scheduled report email contains
|
||||||
|
a Report Group (MonitorPDF
|
||||||
|
ReportsReport Group)
|
||||||
|
which includes a SaaS Application Usage report.
|
||||||
|
- A scheduled report contains only a SaaS Application Usage Report.
|
||||||
|
|
||||||
|
Workaround: To
|
||||||
|
receive a scheduled report email for all other PDF report types:
|
||||||
|
|
||||||
|
1. Select MonitorPDF ReportsReport Groups and
|
||||||
|
remove all SaaS Application Usage reports from all Report Groups.
|
||||||
|
2. Select MonitorPDF
|
||||||
|
ReportsEmail Scheduler and
|
||||||
|
edit the scheduled report email that contains only a SaaS Application Usage
|
||||||
|
report. For the Recurrence, select Disable and
|
||||||
|
click OK.
|
||||||
|
Repeat this step for all scheduled
|
||||||
|
report emails that contain only a SaaS Application Usage report.
|
||||||
|
3. Commit.
|
||||||
|
()
|
||||||
|
Select CommitCommit
|
||||||
|
and Push
|
||||||
|
|
||||||
|
## PAN-184406
|
||||||
|
|
||||||
|
Using the CLI to add a RAID disk pair to
|
||||||
|
an M-700 appliance causes the dmdb process to crash.
|
||||||
|
|
||||||
|
Workaround: Contact
|
||||||
|
customer support to stop the dmdb process before adding a RAID disk
|
||||||
|
pair to a M-700 appliance.
|
||||||
|
|
||||||
|
## PAN-183404
|
||||||
|
|
||||||
|
Static IP addresses are not recognized when
|
||||||
|
"and" operators are used with IP CIDR range.
|
||||||
|
|
||||||
|
## PAN-181933
|
||||||
|
|
||||||
|
If you use multiple log forwarding cards
|
||||||
|
(LFCs) on the PA-7000 series, all of the cards may not receive all
|
||||||
|
of the updates and the mappings for the clients may become out of sync,
|
||||||
|
which causes the firewall to not correctly populate the Source User
|
||||||
|
column in the session logs.
|
||||||
|
|
||||||
|
## PAN-171938
|
||||||
|
|
||||||
|
No results are displayed when you Show Application
|
||||||
|
Filter for a Security policy rule (PoliciesSecurityApplicationValueShow Application Filter).
|
||||||
|
|
||||||
|
## PAN-164885
|
||||||
|
|
||||||
|
On the Panorama management server, pushes to managed firewalls (CommitPush to Devices or Commit and Push) may fail
|
||||||
|
when an EDL (ObjectsExternal Dynamic Lists) is configured to Check for
|
||||||
|
updates every 5 minutes due to the commit and EDL
|
||||||
|
fetch processes overlapping. This is more likely to occur when
|
||||||
|
multiple EDLs are configured to check for updates every 5
|
||||||
|
minutes.
|
||||||
@@ -0,0 +1,493 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.4
|
||||||
|
---
|
||||||
|
|
||||||
|
## WF500-5632
|
||||||
|
|
||||||
|
The number of registered WildFire appliances
|
||||||
|
reported in Panorama (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the
|
||||||
|
current status of connected WildFire appliances.
|
||||||
|
|
||||||
|
## PAN-260851
|
||||||
|
|
||||||
|
From the NGFW or Panorama CLI, you can override the existing
|
||||||
|
application tag even if Disable Override is enabled for the
|
||||||
|
application (ObjectsApplications) tag.
|
||||||
|
|
||||||
|
## PAN-234015
|
||||||
|
|
||||||
|
The X-Forwarded-For (XFF) value is not displayed in traffic logs.
|
||||||
|
|
||||||
|
## PAN-252744
|
||||||
|
|
||||||
|
After upgrading PA-3200 Series, PA-5200 Series, or PA-7000 Series
|
||||||
|
firewalls that are equipped with OCTEON 7x00 dataplane chips to
|
||||||
|
PAN-OS 11.0.4 or 11.0.4-h1, the firewall might see continuous
|
||||||
|
crashes, reboot repeatedly, and/or go into a non-functional
|
||||||
|
state.
|
||||||
|
|
||||||
|
Workaround: If you have already upgraded to one of those
|
||||||
|
releases, downgrade to an earlier release or upgrade to PAN-OS
|
||||||
|
11.0.4-h2.
|
||||||
|
|
||||||
|
## PAN-241041
|
||||||
|
|
||||||
|
On the Panorama management server exporting template or template
|
||||||
|
stack variables (PanoramaTemplates) in CSV format results in an empty CSV file.
|
||||||
|
|
||||||
|
## PAN-234929
|
||||||
|
|
||||||
|
The tabs in the ACC, such as
|
||||||
|
Network Activity, Threat
|
||||||
|
Activity, and Blocked
|
||||||
|
Activity, may not display any data when you apply a
|
||||||
|
Time filter for the Last 15 minutes, Last Hour, Last 6 Hours, or
|
||||||
|
Last 12 Hours. With the Last 24 Hours filter, the data displayed may
|
||||||
|
not be accurate. Additionally, reports run against summary logs may
|
||||||
|
not display accurate results.
|
||||||
|
|
||||||
|
## PAN-225886
|
||||||
|
|
||||||
|
If you enable explicit proxy mode for the web proxy, intermittent
|
||||||
|
errors and unexpected TCP reconnections may occur.
|
||||||
|
|
||||||
|
## PAN-233677
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, PA-5430, and PA-5440 firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
By enabling Lockless QoS feature, a
|
||||||
|
slight degradation in App-ID and Threat performance is expected.
|
||||||
|
|
||||||
|
## PAN-222586
|
||||||
|
|
||||||
|
On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter
|
||||||
|
dropdown menus, Forward Methods, and Built-In Actions for
|
||||||
|
Correlation Log settings (DeviceLog Settings) are not displayed and cannot be configured.
|
||||||
|
|
||||||
|
## PAN-222253
|
||||||
|
|
||||||
|
On the Panorama management server, policy rulebase reordering when
|
||||||
|
you View Rulebase by Groups (Policy<policy-rulebase>) does not persist if you reorder the policy rulebase
|
||||||
|
by dragging and dropping individual policy rules and then moving the
|
||||||
|
entire tag group.
|
||||||
|
|
||||||
|
## PAN-221033
|
||||||
|
|
||||||
|
The firewall is responding to an ARP request for an IP address in the
|
||||||
|
firewall's NAT address pool when that IP address isn't in the same
|
||||||
|
subnet as the IP address of the ingress interface.
|
||||||
|
|
||||||
|
## PAN-220176
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 11.0.1-h2 hotfix
|
||||||
|
```
|
||||||
|
|
||||||
|
System process crashes might occur
|
||||||
|
with VoIP traffic when NAT is enabled with Persistent Dynamic IP and
|
||||||
|
Port settings.
|
||||||
|
|
||||||
|
## PAN-218521
|
||||||
|
|
||||||
|
The ElasticSearch process on the M-600 appliance in Log Collector
|
||||||
|
mode may enter a continuous reboot cycle. This results in the M-600
|
||||||
|
appliance becoming unresponsive, consuming logging disk space, and
|
||||||
|
preventing new log ingestion.
|
||||||
|
|
||||||
|
## PAN-216314
|
||||||
|
|
||||||
|
Upon upgrade or downgrade to or from PAN-OS 10.1.9 or 10.1.9-h1,
|
||||||
|
offloaded application traffic sessions may disconnect after a period
|
||||||
|
of time even if a session is active. The disconnect occurs after the
|
||||||
|
application's default session timeout value is exceeded. This
|
||||||
|
behavior affects only PAN-OS 10.1.9 and 10.1.9-h1. If you are on
|
||||||
|
PAN-OS 10.1.9 and 10.1.9-h1, please use the following workaround. If
|
||||||
|
you have already upgraded or downgraded to another PAN-OS version,
|
||||||
|
use the following workaround in that version.
|
||||||
|
|
||||||
|
Workaround: Run the CLI command debug dataplane
|
||||||
|
internal pdt fe100 csr wr_sem_ctrl_ctr_scan_dis value
|
||||||
|
0 to set the value to zero (0).
|
||||||
|
|
||||||
|
## PAN-216214
|
||||||
|
|
||||||
|
For Panorama-managed firewalls in an Active/Active High Availability
|
||||||
|
(HA) configuration where you configure the firewall HA settings (DeviceHigh Availability) in a template or template stack (PanoramaTemplates), performing a local commit on one of the HA
|
||||||
|
firewalls triggers an HA config sync on the peer firewall. This
|
||||||
|
causes the HA peer configuration to go Out of
|
||||||
|
Sync.
|
||||||
|
|
||||||
|
## PAN-213746
|
||||||
|
|
||||||
|
On the Panorama management server, the Hostkey
|
||||||
|
displayed as undefined undefined if you
|
||||||
|
override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template
|
||||||
|
Stack.
|
||||||
|
|
||||||
|
## PAN-213119
|
||||||
|
|
||||||
|
PA-5410 and PA-5420 firewalls display the following error when you
|
||||||
|
view the Block IP list (MonitorBlock IP):
|
||||||
|
|
||||||
|
show -> dis-block-table is
|
||||||
|
unexpected
|
||||||
|
|
||||||
|
## PAN-212978
|
||||||
|
|
||||||
|
The Palo Alto Networks firewall stops responding when executing an
|
||||||
|
SD-WAN debug operational CLI command.
|
||||||
|
|
||||||
|
## PAN-212889
|
||||||
|
|
||||||
|
On the Panorama management server, different threat names are used
|
||||||
|
when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the
|
||||||
|
ACC displaying no data to display when
|
||||||
|
you are redirected to the ACC after clicking a threat name in the
|
||||||
|
Threat Monitor and filtering the same threat name in the Global
|
||||||
|
Filters.
|
||||||
|
|
||||||
|
## PAN-211531
|
||||||
|
|
||||||
|
On the Panorama management server, admins can still
|
||||||
|
perform a selective push to managed firewalls when Push All
|
||||||
|
Changes and Push for Other Admins
|
||||||
|
are disabled in the admin role profile (PanoramaAdmin Roles).
|
||||||
|
|
||||||
|
## PAN-207770
|
||||||
|
|
||||||
|
Data filtering logs (MonitorLogsData Filtering)
|
||||||
|
incorrectly display the traffic Direction as server-to-client instead
|
||||||
|
of client-to-server for upload traffic
|
||||||
|
that matches Enterprise data loss prevention (DLP) data patterns (ObjectsDLPData
|
||||||
|
Filtering Patterns) in an Enterprise DLP data
|
||||||
|
filtering profile (ObjectsDLPData Filtering Profiles).
|
||||||
|
|
||||||
|
## PAN-207733
|
||||||
|
|
||||||
|
When a DHCPv6 client is configured on HA
|
||||||
|
Active/Passive firewalls, if the DHCPv6 server goes down, after
|
||||||
|
the lease time expires, the DHCPv6 client should enter SOLICIT state
|
||||||
|
on both the Active and Passive firewalls. Instead, the client is
|
||||||
|
stuck in BOUND state with an IPv6 address having lease time 0 on
|
||||||
|
the Passive firewall.
|
||||||
|
|
||||||
|
## PAN-207616
|
||||||
|
|
||||||
|
On the Panorama management server, after
|
||||||
|
selecting managed firewalls and creating a new Tag (PanoramaManaged DevicesSummary) the managed firewalls are
|
||||||
|
automatically unselected and any new tag created is applied to the
|
||||||
|
managed firewalls for which you initially created the new tag.
|
||||||
|
|
||||||
|
Workaround: Select
|
||||||
|
and then unselect the managed firewalls for which you created a
|
||||||
|
new tag.
|
||||||
|
|
||||||
|
## PAN-207611
|
||||||
|
|
||||||
|
When a DHCPv6 client is configured on HA
|
||||||
|
Active/Passive firewalls, the Passive firewall sometimes crashes.
|
||||||
|
|
||||||
|
## PAN-207442
|
||||||
|
|
||||||
|
For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the
|
||||||
|
active-primary HA peer
|
||||||
|
configuration sync to the
|
||||||
|
secondary-passive HA peer may fail.
|
||||||
|
When the config sync fails, the job Results is
|
||||||
|
Successful
|
||||||
|
(Tasks), however the sync status on the
|
||||||
|
Dashboard displays as Out
|
||||||
|
of Sync for both HA peers.
|
||||||
|
|
||||||
|
Workaround: Perform a local commit on the
|
||||||
|
active-primary HA peer and then
|
||||||
|
synchronize the HA configuration.
|
||||||
|
|
||||||
|
1. Log in to the Panorama
|
||||||
|
web interface of the
|
||||||
|
active-primary HA peer.
|
||||||
|
2. Select Commit and Commit to
|
||||||
|
Panorama.
|
||||||
|
3. In the active-primary HA peer
|
||||||
|
Dashboard, click Sync
|
||||||
|
to Peer in the High Availability widget.
|
||||||
|
|
||||||
|
## PAN-207040
|
||||||
|
|
||||||
|
If you disable Advanced Routing, remove
|
||||||
|
logical routers, and downgrade from PAN-OS 11.0.0 to a PAN-OS 10.2.x
|
||||||
|
or 10.1.x release, subsequent commits fail and SD-WAN devices on
|
||||||
|
Panorama have no Virtual Router name.
|
||||||
|
|
||||||
|
## PAN-206913
|
||||||
|
|
||||||
|
When a DHCPv6 client is configured on HA
|
||||||
|
Active/Passive firewalls, releasing the IPv6 address from the client
|
||||||
|
(using Release in the UI or using the request dhcp client ipv6 release all CLI
|
||||||
|
command) releases the IPv6 address from the Active firewall, but
|
||||||
|
not the Passive firewall.
|
||||||
|
|
||||||
|
## PAN-206909
|
||||||
|
|
||||||
|
The Dedicated Log Collector is unable to
|
||||||
|
reconnect to the Panorama management server if the configd process
|
||||||
|
crashes. This results in the Dedicated Log Collector losing connectivity
|
||||||
|
to Panorama despite the managed collector connection Status (PanoramaManaged Collector)
|
||||||
|
displaying connected and the managed colletor Health status displaying
|
||||||
|
as healthy.
|
||||||
|
|
||||||
|
This results in the local Panorama config and
|
||||||
|
system logs not being forwarded to the Dedicated Log Collector.
|
||||||
|
Firewall log forwarding to the disconnected Dedicated Log Collector
|
||||||
|
is not impacted.
|
||||||
|
|
||||||
|
Workaround: Restart the mgmtsrvr process
|
||||||
|
on the Dedicated Log Collector.
|
||||||
|
|
||||||
|
1. Log in to the Dedicated Log Collector
|
||||||
|
CLI.
|
||||||
|
2. Confirm the Dedicated Log Collector is disconnected from
|
||||||
|
Panorama.
|
||||||
|
admin> show panorama-status
|
||||||
|
Verify
|
||||||
|
the Connected status is no.
|
||||||
|
3. Restart the mgmtsrvr process.
|
||||||
|
admin> debug software restart process management-server
|
||||||
|
|
||||||
|
## PAN-206416
|
||||||
|
|
||||||
|
On the Panorama management server, no data
|
||||||
|
filtering log (MonitorLogsData Filtering) is generated
|
||||||
|
when the managed firewall loses connectivity to the following cloud services,
|
||||||
|
and as a result fails to forward matched traffic for inspection.
|
||||||
|
|
||||||
|
- DLP cloud service
|
||||||
|
- Advanced Threat Protection inline cloud analysis service
|
||||||
|
- Advanced URL Filtering cloud service
|
||||||
|
|
||||||
|
## PAN-206315
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1420 firewall only
|
||||||
|
```
|
||||||
|
|
||||||
|
In an active/passive high
|
||||||
|
availability (HA) configuration, the show session info CLI
|
||||||
|
command shows that the passive firewall has packet rate and throughput
|
||||||
|
values. The packet rate and throughput of the passive firewall should
|
||||||
|
be zero since it is not processing traffic.
|
||||||
|
|
||||||
|
## PAN-205009
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1420 firewall only
|
||||||
|
```
|
||||||
|
|
||||||
|
In an active/passive high
|
||||||
|
availability (HA) configuration, the show interface all, show-high availability interface ha2,
|
||||||
|
and show high-availability all CLI
|
||||||
|
commands display the HSCI port state as unknown on both the active
|
||||||
|
and passive firewalls.
|
||||||
|
|
||||||
|
## PAN-204689
|
||||||
|
|
||||||
|
Upon upgrade to PAN-OS 11.0.1, the following GlobalProtect settings
|
||||||
|
do not work:
|
||||||
|
|
||||||
|
- Allow user to disconnect GlobalProtect
|
||||||
|
AppAllow with Passcode
|
||||||
|
- Allow user to Disable GlobalProtect
|
||||||
|
AppAllow with Passcode
|
||||||
|
- Allow User to Uninstall GlobalProtect
|
||||||
|
AppAllow with Password
|
||||||
|
|
||||||
|
## PAN-201910
|
||||||
|
|
||||||
|
PAN-OS security profiles might consume a
|
||||||
|
large amount of memory depending on the profile configuration and
|
||||||
|
quantity. In some cases, this might reduce the number of supported security
|
||||||
|
profiles below the stated maximum for a given platform.
|
||||||
|
|
||||||
|
## PAN-197588
|
||||||
|
|
||||||
|
The PAN-OS ACC (Application Command Center)
|
||||||
|
does not display a widget detailing statistics and data associated
|
||||||
|
with vulnerability exploits that have been detected using inline
|
||||||
|
cloud analysis.
|
||||||
|
|
||||||
|
## PAN-197419
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
In NetworkInterfaceEthernet, the power over Ethernet
|
||||||
|
(PoE) ports do not display a Tag value.
|
||||||
|
|
||||||
|
## PAN-197097
|
||||||
|
|
||||||
|
Large Scale VPN (LSVPN) does not support
|
||||||
|
IPv6 addresses on the satellite firewall.
|
||||||
|
|
||||||
|
## PAN-196758
|
||||||
|
|
||||||
|
On the Panorama management server, pushing
|
||||||
|
a configuration change to firewalls leveraging SD-WAN erroneously
|
||||||
|
show the auto-provisioned BGP configurations for SD-WAN as being
|
||||||
|
edited or deleted despite no edits or deletions being made when
|
||||||
|
you Preview Changes (CommitPush to DevicesEdit Selections or CommitCommit and PushEdit Selections).
|
||||||
|
|
||||||
|
## PAN-196146
|
||||||
|
|
||||||
|
The VM-Series firewall on Azure does not
|
||||||
|
boot up with a hostname (specified in an init-cgf.txt or user data)
|
||||||
|
when bootstrapped.
|
||||||
|
|
||||||
|
## PAN-195968
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
When using the CLI to configure power over Ethernet (PoE) on a non-PoE
|
||||||
|
port, the CLI prints an error depending on whether an interface
|
||||||
|
type was selected on the non-PoE port or not. If an interface type, such
|
||||||
|
as tap, Layer 2, or virtual wire, was selected before PoE was configured,
|
||||||
|
the error message will not include the interface name (eg. ethernet1/4).
|
||||||
|
If an interface type was not selected before PoE was configured,
|
||||||
|
the error message will include the interface name.
|
||||||
|
|
||||||
|
## PAN-195342
|
||||||
|
|
||||||
|
On the Panorama management server, Context
|
||||||
|
Switch fails when you try to Context Switch from a managed firewall running
|
||||||
|
PAN-OS 10.1.7 or earlier release back to Panorama and the following
|
||||||
|
error is displayed:
|
||||||
|
|
||||||
|
Could not find start token '@start@'
|
||||||
|
|
||||||
|
## PAN-194978
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
In NetworkInterfaceEthernet, hovering the mouse over
|
||||||
|
a power over Ethernet (PoE) Link State icon
|
||||||
|
does not display link speed and link duplex details.
|
||||||
|
|
||||||
|
## PAN-194424
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5450 firewall only
|
||||||
|
```
|
||||||
|
|
||||||
|
Upgrading
|
||||||
|
to PAN-OS 10.2.2 while having a log interface configured can cause
|
||||||
|
both the log interface and the management interface to remain connected
|
||||||
|
to the log collector.
|
||||||
|
|
||||||
|
Workaround: Restart the log receiver service
|
||||||
|
by running the following CLI command:
|
||||||
|
|
||||||
|
debug software restart process log-receiver
|
||||||
|
|
||||||
|
## PAN-187685
|
||||||
|
|
||||||
|
On the Panorama management server, the Template Status
|
||||||
|
displays no synchronization status (PanoramaManaged DevicesSummary)
|
||||||
|
after a bootstrapped firewall is successfully added to Panorama.
|
||||||
|
|
||||||
|
Workaround: After
|
||||||
|
the bootstrapped firewall is successfully added to Panorama, log in to the Panorama web interface and
|
||||||
|
select CommitPush
|
||||||
|
to Devices.
|
||||||
|
|
||||||
|
## PAN-187407
|
||||||
|
|
||||||
|
The configured Advanced Threat Prevention
|
||||||
|
inline cloud analysis action for a given model might not be honored
|
||||||
|
under the following condition: If the firewall is set to Hold
|
||||||
|
client request for category lookup and the action set
|
||||||
|
to Reset-Both and the URL cache has been
|
||||||
|
cleared, the first request for inline cloud analysis will be bypassed.
|
||||||
|
|
||||||
|
## PAN-186283
|
||||||
|
|
||||||
|
Templates appear out-of-sync on Panorama
|
||||||
|
after successfully deploying the CFT stack using the Panorama plugin for
|
||||||
|
AWS.
|
||||||
|
|
||||||
|
Workaround: Use CommitPush to Devices to synchronize
|
||||||
|
the templates.
|
||||||
|
|
||||||
|
## PAN-184708
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama managed firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if:
|
||||||
|
|
||||||
|
- A scheduled report email contains
|
||||||
|
a Report Group (MonitorPDF
|
||||||
|
ReportsReport Group)
|
||||||
|
which includes a SaaS Application Usage report.
|
||||||
|
- A scheduled report contains only a SaaS Application Usage Report.
|
||||||
|
|
||||||
|
Workaround: To
|
||||||
|
receive a scheduled report email for all other PDF report types:
|
||||||
|
|
||||||
|
1. Select MonitorPDF ReportsReport Groups and
|
||||||
|
remove all SaaS Application Usage reports from all Report Groups.
|
||||||
|
2. Select MonitorPDF
|
||||||
|
ReportsEmail Scheduler and
|
||||||
|
edit the scheduled report email that contains only a SaaS Application Usage
|
||||||
|
report. For the Recurrence, select Disable and
|
||||||
|
click OK.
|
||||||
|
Repeat this step for all scheduled
|
||||||
|
report emails that contain only a SaaS Application Usage report.
|
||||||
|
3. Commit.
|
||||||
|
()
|
||||||
|
Select CommitCommit
|
||||||
|
and Push
|
||||||
|
|
||||||
|
## PAN-184406
|
||||||
|
|
||||||
|
Using the CLI to add a RAID disk pair to
|
||||||
|
an M-700 appliance causes the dmdb process to crash.
|
||||||
|
|
||||||
|
Workaround: Contact
|
||||||
|
customer support to stop the dmdb process before adding a RAID disk
|
||||||
|
pair to a M-700 appliance.
|
||||||
|
|
||||||
|
## PAN-183404
|
||||||
|
|
||||||
|
Static IP addresses are not recognized when
|
||||||
|
"and" operators are used with IP CIDR range.
|
||||||
|
|
||||||
|
## PAN-181933
|
||||||
|
|
||||||
|
If you use multiple log forwarding cards
|
||||||
|
(LFCs) on the PA-7000 series, all of the cards may not receive all
|
||||||
|
of the updates and the mappings for the clients may become out of sync,
|
||||||
|
which causes the firewall to not correctly populate the Source User
|
||||||
|
column in the session logs.
|
||||||
|
|
||||||
|
## PAN-171938
|
||||||
|
|
||||||
|
No results are displayed when you Show Application
|
||||||
|
Filter for a Security policy rule (PoliciesSecurityApplicationValueShow Application Filter).
|
||||||
|
|
||||||
|
## PAN-164885
|
||||||
|
|
||||||
|
On the Panorama management server, pushes to managed firewalls (CommitPush to Devices or Commit and Push) may fail
|
||||||
|
when an EDL (ObjectsExternal Dynamic Lists) is configured to Check for
|
||||||
|
updates every 5 minutes due to the commit and EDL
|
||||||
|
fetch processes overlapping. This is more likely to occur when
|
||||||
|
multiple EDLs are configured to check for updates every 5
|
||||||
|
minutes.
|
||||||
@@ -0,0 +1,471 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.5
|
||||||
|
---
|
||||||
|
|
||||||
|
## WF500-5632
|
||||||
|
|
||||||
|
The number of registered WildFire appliances
|
||||||
|
reported in Panorama (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the
|
||||||
|
current status of connected WildFire appliances.
|
||||||
|
|
||||||
|
## PAN-260851
|
||||||
|
|
||||||
|
From the NGFW or Panorama CLI, you can override the existing
|
||||||
|
application tag even if Disable Override is enabled for the
|
||||||
|
application (ObjectsApplications) tag.
|
||||||
|
|
||||||
|
## PAN-250062
|
||||||
|
|
||||||
|
Device telemetry might fail at configured intervals due to bundle generation issues.
|
||||||
|
|
||||||
|
## PAN-234015
|
||||||
|
|
||||||
|
The X-Forwarded-For (XFF) value is not displayed in traffic logs.
|
||||||
|
|
||||||
|
## PAN-252744
|
||||||
|
|
||||||
|
After upgrading PA-3200 Series, PA-5200 Series, or PA-7000 Series
|
||||||
|
firewalls that are equipped with OCTEON 7x00 dataplane chips to
|
||||||
|
PAN-OS 11.0.4 or 11.0.4-h1, the firewall might see continuous
|
||||||
|
crashes, reboot repeatedly, and/or go into a non-functional
|
||||||
|
state.
|
||||||
|
|
||||||
|
Workaround: If you have already upgraded to one of those
|
||||||
|
releases, downgrade to an earlier release or upgrade to PAN-OS
|
||||||
|
11.0.4-h2.
|
||||||
|
|
||||||
|
## PAN-241041
|
||||||
|
|
||||||
|
On the Panorama management server exporting template or template
|
||||||
|
stack variables (PanoramaTemplates) in CSV format results in an empty CSV file.
|
||||||
|
|
||||||
|
## PAN-234929
|
||||||
|
|
||||||
|
The tabs in the ACC, such as
|
||||||
|
Network Activity, Threat
|
||||||
|
Activity, and Blocked
|
||||||
|
Activity, may not display any data when you apply a
|
||||||
|
Time filter for the Last 15 minutes, Last Hour, Last 6 Hours, or
|
||||||
|
Last 12 Hours. With the Last 24 Hours filter, the data displayed may
|
||||||
|
not be accurate. Additionally, reports run against summary logs may
|
||||||
|
not display accurate results.
|
||||||
|
|
||||||
|
## PAN-225886
|
||||||
|
|
||||||
|
If you enable explicit proxy mode for the web proxy, intermittent
|
||||||
|
errors and unexpected TCP reconnections may occur.
|
||||||
|
|
||||||
|
## PAN-233677
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, PA-5430, and PA-5440 firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
By enabling Lockless QoS feature, a
|
||||||
|
slight degradation in App-ID and Threat performance is expected.
|
||||||
|
|
||||||
|
## PAN-222586
|
||||||
|
|
||||||
|
On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter
|
||||||
|
dropdown menus, Forward Methods, and Built-In Actions for
|
||||||
|
Correlation Log settings (DeviceLog Settings) are not displayed and cannot be configured.
|
||||||
|
|
||||||
|
## PAN-220176
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 11.0.1-h2 hotfix
|
||||||
|
```
|
||||||
|
|
||||||
|
System process crashes might occur
|
||||||
|
with VoIP traffic when NAT is enabled with Persistent Dynamic IP and
|
||||||
|
Port settings.
|
||||||
|
|
||||||
|
## PAN-216314
|
||||||
|
|
||||||
|
Upon upgrade or downgrade to or from PAN-OS 10.1.9 or 10.1.9-h1,
|
||||||
|
offloaded application traffic sessions may disconnect after a period
|
||||||
|
of time even if a session is active. The disconnect occurs after the
|
||||||
|
application's default session timeout value is exceeded. This
|
||||||
|
behavior affects only PAN-OS 10.1.9 and 10.1.9-h1. If you are on
|
||||||
|
PAN-OS 10.1.9 and 10.1.9-h1, please use the following workaround. If
|
||||||
|
you have already upgraded or downgraded to another PAN-OS version,
|
||||||
|
use the following workaround in that version.
|
||||||
|
|
||||||
|
Workaround: Run the CLI command debug dataplane
|
||||||
|
internal pdt fe100 csr wr_sem_ctrl_ctr_scan_dis value
|
||||||
|
0 to set the value to zero (0).
|
||||||
|
|
||||||
|
## PAN-216214
|
||||||
|
|
||||||
|
For Panorama-managed firewalls in an Active/Active High Availability
|
||||||
|
(HA) configuration where you configure the firewall HA settings (DeviceHigh Availability) in a template or template stack (PanoramaTemplates), performing a local commit on one of the HA
|
||||||
|
firewalls triggers an HA config sync on the peer firewall. This
|
||||||
|
causes the HA peer configuration to go Out of
|
||||||
|
Sync.
|
||||||
|
|
||||||
|
## PAN-213746
|
||||||
|
|
||||||
|
On the Panorama management server, the Hostkey
|
||||||
|
displayed as undefined undefined if you
|
||||||
|
override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template
|
||||||
|
Stack.
|
||||||
|
|
||||||
|
## PAN-213119
|
||||||
|
|
||||||
|
PA-5410 and PA-5420 firewalls display the following error when you
|
||||||
|
view the Block IP list (MonitorBlock IP):
|
||||||
|
|
||||||
|
show -> dis-block-table is
|
||||||
|
unexpected
|
||||||
|
|
||||||
|
## PAN-212978
|
||||||
|
|
||||||
|
The Palo Alto Networks firewall stops responding when executing an
|
||||||
|
SD-WAN debug operational CLI command.
|
||||||
|
|
||||||
|
## PAN-212889
|
||||||
|
|
||||||
|
On the Panorama management server, different threat names are used
|
||||||
|
when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the
|
||||||
|
ACC displaying no data to display when
|
||||||
|
you are redirected to the ACC after clicking a threat name in the
|
||||||
|
Threat Monitor and filtering the same threat name in the Global
|
||||||
|
Filters.
|
||||||
|
|
||||||
|
## PAN-211531
|
||||||
|
|
||||||
|
On the Panorama management server, admins can still
|
||||||
|
perform a selective push to managed firewalls when Push All
|
||||||
|
Changes and Push for Other Admins
|
||||||
|
are disabled in the admin role profile (PanoramaAdmin Roles).
|
||||||
|
|
||||||
|
## PAN-207770
|
||||||
|
|
||||||
|
Data filtering logs (MonitorLogsData Filtering)
|
||||||
|
incorrectly display the traffic Direction as server-to-client instead
|
||||||
|
of client-to-server for upload traffic
|
||||||
|
that matches Enterprise data loss prevention (DLP) data patterns (ObjectsDLPData
|
||||||
|
Filtering Patterns) in an Enterprise DLP data
|
||||||
|
filtering profile (ObjectsDLPData Filtering Profiles).
|
||||||
|
|
||||||
|
## PAN-207733
|
||||||
|
|
||||||
|
When a DHCPv6 client is configured on HA
|
||||||
|
Active/Passive firewalls, if the DHCPv6 server goes down, after
|
||||||
|
the lease time expires, the DHCPv6 client should enter SOLICIT state
|
||||||
|
on both the Active and Passive firewalls. Instead, the client is
|
||||||
|
stuck in BOUND state with an IPv6 address having lease time 0 on
|
||||||
|
the Passive firewall.
|
||||||
|
|
||||||
|
## PAN-207616
|
||||||
|
|
||||||
|
On the Panorama management server, after
|
||||||
|
selecting managed firewalls and creating a new Tag (PanoramaManaged DevicesSummary) the managed firewalls are
|
||||||
|
automatically unselected and any new tag created is applied to the
|
||||||
|
managed firewalls for which you initially created the new tag.
|
||||||
|
|
||||||
|
Workaround: Select
|
||||||
|
and then unselect the managed firewalls for which you created a
|
||||||
|
new tag.
|
||||||
|
|
||||||
|
## PAN-207611
|
||||||
|
|
||||||
|
When a DHCPv6 client is configured on HA
|
||||||
|
Active/Passive firewalls, the Passive firewall sometimes crashes.
|
||||||
|
|
||||||
|
## PAN-207442
|
||||||
|
|
||||||
|
For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the
|
||||||
|
active-primary HA peer
|
||||||
|
configuration sync to the
|
||||||
|
secondary-passive HA peer may fail.
|
||||||
|
When the config sync fails, the job Results is
|
||||||
|
Successful
|
||||||
|
(Tasks), however the sync status on the
|
||||||
|
Dashboard displays as Out
|
||||||
|
of Sync for both HA peers.
|
||||||
|
|
||||||
|
Workaround: Perform a local commit on the
|
||||||
|
active-primary HA peer and then
|
||||||
|
synchronize the HA configuration.
|
||||||
|
|
||||||
|
1. Log in to the Panorama
|
||||||
|
web interface of the
|
||||||
|
active-primary HA peer.
|
||||||
|
2. Select Commit and Commit to
|
||||||
|
Panorama.
|
||||||
|
3. In the active-primary HA peer
|
||||||
|
Dashboard, click Sync
|
||||||
|
to Peer in the High Availability widget.
|
||||||
|
|
||||||
|
## PAN-207040
|
||||||
|
|
||||||
|
If you disable Advanced Routing, remove
|
||||||
|
logical routers, and downgrade from PAN-OS 11.0.0 to a PAN-OS 10.2.x
|
||||||
|
or 10.1.x release, subsequent commits fail and SD-WAN devices on
|
||||||
|
Panorama have no Virtual Router name.
|
||||||
|
|
||||||
|
## PAN-206913
|
||||||
|
|
||||||
|
When a DHCPv6 client is configured on HA
|
||||||
|
Active/Passive firewalls, releasing the IPv6 address from the client
|
||||||
|
(using Release in the UI or using the request dhcp client ipv6 release all CLI
|
||||||
|
command) releases the IPv6 address from the Active firewall, but
|
||||||
|
not the Passive firewall.
|
||||||
|
|
||||||
|
## PAN-206909
|
||||||
|
|
||||||
|
The Dedicated Log Collector is unable to
|
||||||
|
reconnect to the Panorama management server if the configd process
|
||||||
|
crashes. This results in the Dedicated Log Collector losing connectivity
|
||||||
|
to Panorama despite the managed collector connection Status (PanoramaManaged Collector)
|
||||||
|
displaying connected and the managed colletor Health status displaying
|
||||||
|
as healthy.
|
||||||
|
|
||||||
|
This results in the local Panorama config and
|
||||||
|
system logs not being forwarded to the Dedicated Log Collector.
|
||||||
|
Firewall log forwarding to the disconnected Dedicated Log Collector
|
||||||
|
is not impacted.
|
||||||
|
|
||||||
|
Workaround: Restart the mgmtsrvr process
|
||||||
|
on the Dedicated Log Collector.
|
||||||
|
|
||||||
|
1. Log in to the Dedicated Log Collector
|
||||||
|
CLI.
|
||||||
|
2. Confirm the Dedicated Log Collector is disconnected from
|
||||||
|
Panorama.
|
||||||
|
admin> show panorama-status
|
||||||
|
Verify
|
||||||
|
the Connected status is no.
|
||||||
|
3. Restart the mgmtsrvr process.
|
||||||
|
admin> debug software restart process management-server
|
||||||
|
|
||||||
|
## PAN-206416
|
||||||
|
|
||||||
|
On the Panorama management server, no data
|
||||||
|
filtering log (MonitorLogsData Filtering) is generated
|
||||||
|
when the managed firewall loses connectivity to the following cloud services,
|
||||||
|
and as a result fails to forward matched traffic for inspection.
|
||||||
|
|
||||||
|
- DLP cloud service
|
||||||
|
- Advanced Threat Protection inline cloud analysis service
|
||||||
|
- Advanced URL Filtering cloud service
|
||||||
|
|
||||||
|
## PAN-206315
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1420 firewall only
|
||||||
|
```
|
||||||
|
|
||||||
|
In an active/passive high
|
||||||
|
availability (HA) configuration, the show session info CLI
|
||||||
|
command shows that the passive firewall has packet rate and throughput
|
||||||
|
values. The packet rate and throughput of the passive firewall should
|
||||||
|
be zero since it is not processing traffic.
|
||||||
|
|
||||||
|
## PAN-205009
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1420 firewall only
|
||||||
|
```
|
||||||
|
|
||||||
|
In an active/passive high
|
||||||
|
availability (HA) configuration, the show interface all, show-high availability interface ha2,
|
||||||
|
and show high-availability all CLI
|
||||||
|
commands display the HSCI port state as unknown on both the active
|
||||||
|
and passive firewalls.
|
||||||
|
|
||||||
|
## PAN-204689
|
||||||
|
|
||||||
|
Upon upgrade to PAN-OS 11.0.1, the following GlobalProtect settings
|
||||||
|
do not work:
|
||||||
|
|
||||||
|
- Allow user to disconnect GlobalProtect
|
||||||
|
AppAllow with Passcode
|
||||||
|
- Allow user to Disable GlobalProtect
|
||||||
|
AppAllow with Passcode
|
||||||
|
- Allow User to Uninstall GlobalProtect
|
||||||
|
AppAllow with Password
|
||||||
|
|
||||||
|
## PAN-201910
|
||||||
|
|
||||||
|
PAN-OS security profiles might consume a
|
||||||
|
large amount of memory depending on the profile configuration and
|
||||||
|
quantity. In some cases, this might reduce the number of supported security
|
||||||
|
profiles below the stated maximum for a given platform.
|
||||||
|
|
||||||
|
## PAN-197588
|
||||||
|
|
||||||
|
The PAN-OS ACC (Application Command Center)
|
||||||
|
does not display a widget detailing statistics and data associated
|
||||||
|
with vulnerability exploits that have been detected using inline
|
||||||
|
cloud analysis.
|
||||||
|
|
||||||
|
## PAN-197419
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
In NetworkInterfaceEthernet, the power over Ethernet
|
||||||
|
(PoE) ports do not display a Tag value.
|
||||||
|
|
||||||
|
## PAN-197097
|
||||||
|
|
||||||
|
Large Scale VPN (LSVPN) does not support
|
||||||
|
IPv6 addresses on the satellite firewall.
|
||||||
|
|
||||||
|
## PAN-196758
|
||||||
|
|
||||||
|
On the Panorama management server, pushing
|
||||||
|
a configuration change to firewalls leveraging SD-WAN erroneously
|
||||||
|
show the auto-provisioned BGP configurations for SD-WAN as being
|
||||||
|
edited or deleted despite no edits or deletions being made when
|
||||||
|
you Preview Changes (CommitPush to DevicesEdit Selections or CommitCommit and PushEdit Selections).
|
||||||
|
|
||||||
|
## PAN-195968
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
When using the CLI to configure power over Ethernet (PoE) on a non-PoE
|
||||||
|
port, the CLI prints an error depending on whether an interface
|
||||||
|
type was selected on the non-PoE port or not. If an interface type, such
|
||||||
|
as tap, Layer 2, or virtual wire, was selected before PoE was configured,
|
||||||
|
the error message will not include the interface name (eg. ethernet1/4).
|
||||||
|
If an interface type was not selected before PoE was configured,
|
||||||
|
the error message will include the interface name.
|
||||||
|
|
||||||
|
## PAN-195342
|
||||||
|
|
||||||
|
On the Panorama management server, Context
|
||||||
|
Switch fails when you try to Context Switch from a managed firewall running
|
||||||
|
PAN-OS 10.1.7 or earlier release back to Panorama and the following
|
||||||
|
error is displayed:
|
||||||
|
|
||||||
|
Could not find start token '@start@'
|
||||||
|
|
||||||
|
## PAN-194978
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
In NetworkInterfaceEthernet, hovering the mouse over
|
||||||
|
a power over Ethernet (PoE) Link State icon
|
||||||
|
does not display link speed and link duplex details.
|
||||||
|
|
||||||
|
## PAN-194424
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5450 firewall only
|
||||||
|
```
|
||||||
|
|
||||||
|
Upgrading
|
||||||
|
to PAN-OS 10.2.2 while having a log interface configured can cause
|
||||||
|
both the log interface and the management interface to remain connected
|
||||||
|
to the log collector.
|
||||||
|
|
||||||
|
Workaround: Restart the log receiver service
|
||||||
|
by running the following CLI command:
|
||||||
|
|
||||||
|
debug software restart process log-receiver
|
||||||
|
|
||||||
|
## PAN-187685
|
||||||
|
|
||||||
|
On the Panorama management server, the Template Status
|
||||||
|
displays no synchronization status (PanoramaManaged DevicesSummary)
|
||||||
|
after a bootstrapped firewall is successfully added to Panorama.
|
||||||
|
|
||||||
|
Workaround: After
|
||||||
|
the bootstrapped firewall is successfully added to Panorama, log in to the Panorama web interface and
|
||||||
|
select CommitPush
|
||||||
|
to Devices.
|
||||||
|
|
||||||
|
## PAN-187407
|
||||||
|
|
||||||
|
The configured Advanced Threat Prevention
|
||||||
|
inline cloud analysis action for a given model might not be honored
|
||||||
|
under the following condition: If the firewall is set to Hold
|
||||||
|
client request for category lookup and the action set
|
||||||
|
to Reset-Both and the URL cache has been
|
||||||
|
cleared, the first request for inline cloud analysis will be bypassed.
|
||||||
|
|
||||||
|
## PAN-186283
|
||||||
|
|
||||||
|
Templates appear out-of-sync on Panorama
|
||||||
|
after successfully deploying the CFT stack using the Panorama plugin for
|
||||||
|
AWS.
|
||||||
|
|
||||||
|
Workaround: Use CommitPush to Devices to synchronize
|
||||||
|
the templates.
|
||||||
|
|
||||||
|
## PAN-184708
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama managed firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if:
|
||||||
|
|
||||||
|
- A scheduled report email contains
|
||||||
|
a Report Group (MonitorPDF
|
||||||
|
ReportsReport Group)
|
||||||
|
which includes a SaaS Application Usage report.
|
||||||
|
- A scheduled report contains only a SaaS Application Usage Report.
|
||||||
|
|
||||||
|
Workaround: To
|
||||||
|
receive a scheduled report email for all other PDF report types:
|
||||||
|
|
||||||
|
1. Select MonitorPDF ReportsReport Groups and
|
||||||
|
remove all SaaS Application Usage reports from all Report Groups.
|
||||||
|
2. Select MonitorPDF
|
||||||
|
ReportsEmail Scheduler and
|
||||||
|
edit the scheduled report email that contains only a SaaS Application Usage
|
||||||
|
report. For the Recurrence, select Disable and
|
||||||
|
click OK.
|
||||||
|
Repeat this step for all scheduled
|
||||||
|
report emails that contain only a SaaS Application Usage report.
|
||||||
|
3. Commit.
|
||||||
|
()
|
||||||
|
Select CommitCommit
|
||||||
|
and Push
|
||||||
|
|
||||||
|
## PAN-184406
|
||||||
|
|
||||||
|
Using the CLI to add a RAID disk pair to
|
||||||
|
an M-700 appliance causes the dmdb process to crash.
|
||||||
|
|
||||||
|
Workaround: Contact
|
||||||
|
customer support to stop the dmdb process before adding a RAID disk
|
||||||
|
pair to a M-700 appliance.
|
||||||
|
|
||||||
|
## PAN-183404
|
||||||
|
|
||||||
|
Static IP addresses are not recognized when
|
||||||
|
"and" operators are used with IP CIDR range.
|
||||||
|
|
||||||
|
## PAN-181933
|
||||||
|
|
||||||
|
If you use multiple log forwarding cards
|
||||||
|
(LFCs) on the PA-7000 series, all of the cards may not receive all
|
||||||
|
of the updates and the mappings for the clients may become out of sync,
|
||||||
|
which causes the firewall to not correctly populate the Source User
|
||||||
|
column in the session logs.
|
||||||
|
|
||||||
|
## PAN-171938
|
||||||
|
|
||||||
|
No results are displayed when you Show Application
|
||||||
|
Filter for a Security policy rule (PoliciesSecurityApplicationValueShow Application Filter).
|
||||||
|
|
||||||
|
## PAN-164885
|
||||||
|
|
||||||
|
On the Panorama management server, pushes to managed firewalls (CommitPush to Devices or Commit and Push) may fail
|
||||||
|
when an EDL (ObjectsExternal Dynamic Lists) is configured to Check for
|
||||||
|
updates every 5 minutes due to the commit and EDL
|
||||||
|
fetch processes overlapping. This is more likely to occur when
|
||||||
|
multiple EDLs are configured to check for updates every 5
|
||||||
|
minutes.
|
||||||
@@ -0,0 +1,471 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.6
|
||||||
|
---
|
||||||
|
|
||||||
|
## WF500-5632
|
||||||
|
|
||||||
|
The number of registered WildFire appliances
|
||||||
|
reported in Panorama (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the
|
||||||
|
current status of connected WildFire appliances.
|
||||||
|
|
||||||
|
## PAN-260851
|
||||||
|
|
||||||
|
From the NGFW or Panorama CLI, you can override the existing
|
||||||
|
application tag even if Disable Override is enabled for the
|
||||||
|
application (ObjectsApplications) tag.
|
||||||
|
|
||||||
|
## PAN-250062
|
||||||
|
|
||||||
|
Device telemetry might fail at configured intervals due to bundle generation issues.
|
||||||
|
|
||||||
|
## PAN-234015
|
||||||
|
|
||||||
|
The X-Forwarded-For (XFF) value is not displayed in traffic logs.
|
||||||
|
|
||||||
|
## PAN-252744
|
||||||
|
|
||||||
|
After upgrading PA-3200 Series, PA-5200 Series, or PA-7000 Series
|
||||||
|
firewalls that are equipped with OCTEON 7x00 dataplane chips to
|
||||||
|
PAN-OS 11.0.4 or 11.0.4-h1, the firewall might see continuous
|
||||||
|
crashes, reboot repeatedly, and/or go into a non-functional
|
||||||
|
state.
|
||||||
|
|
||||||
|
Workaround: If you have already upgraded to one of those
|
||||||
|
releases, downgrade to an earlier release or upgrade to PAN-OS
|
||||||
|
11.0.4-h2.
|
||||||
|
|
||||||
|
## PAN-241041
|
||||||
|
|
||||||
|
On the Panorama management server exporting template or template
|
||||||
|
stack variables (PanoramaTemplates) in CSV format results in an empty CSV file.
|
||||||
|
|
||||||
|
## PAN-234929
|
||||||
|
|
||||||
|
The tabs in the ACC, such as
|
||||||
|
Network Activity, Threat
|
||||||
|
Activity, and Blocked
|
||||||
|
Activity, may not display any data when you apply a
|
||||||
|
Time filter for the Last 15 minutes, Last Hour, Last 6 Hours, or
|
||||||
|
Last 12 Hours. With the Last 24 Hours filter, the data displayed may
|
||||||
|
not be accurate. Additionally, reports run against summary logs may
|
||||||
|
not display accurate results.
|
||||||
|
|
||||||
|
## PAN-225886
|
||||||
|
|
||||||
|
If you enable explicit proxy mode for the web proxy, intermittent
|
||||||
|
errors and unexpected TCP reconnections may occur.
|
||||||
|
|
||||||
|
## PAN-233677
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, PA-5430, and PA-5440 firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
By enabling Lockless QoS feature, a
|
||||||
|
slight degradation in App-ID and Threat performance is expected.
|
||||||
|
|
||||||
|
## PAN-222586
|
||||||
|
|
||||||
|
On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter
|
||||||
|
dropdown menus, Forward Methods, and Built-In Actions for
|
||||||
|
Correlation Log settings (DeviceLog Settings) are not displayed and cannot be configured.
|
||||||
|
|
||||||
|
## PAN-220176
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 11.0.1-h2 hotfix
|
||||||
|
```
|
||||||
|
|
||||||
|
System process crashes might occur
|
||||||
|
with VoIP traffic when NAT is enabled with Persistent Dynamic IP and
|
||||||
|
Port settings.
|
||||||
|
|
||||||
|
## PAN-216314
|
||||||
|
|
||||||
|
Upon upgrade or downgrade to or from PAN-OS 10.1.9 or 10.1.9-h1,
|
||||||
|
offloaded application traffic sessions may disconnect after a period
|
||||||
|
of time even if a session is active. The disconnect occurs after the
|
||||||
|
application's default session timeout value is exceeded. This
|
||||||
|
behavior affects only PAN-OS 10.1.9 and 10.1.9-h1. If you are on
|
||||||
|
PAN-OS 10.1.9 and 10.1.9-h1, please use the following workaround. If
|
||||||
|
you have already upgraded or downgraded to another PAN-OS version,
|
||||||
|
use the following workaround in that version.
|
||||||
|
|
||||||
|
Workaround: Run the CLI command debug dataplane
|
||||||
|
internal pdt fe100 csr wr_sem_ctrl_ctr_scan_dis value
|
||||||
|
0 to set the value to zero (0).
|
||||||
|
|
||||||
|
## PAN-216214
|
||||||
|
|
||||||
|
For Panorama-managed firewalls in an Active/Active High Availability
|
||||||
|
(HA) configuration where you configure the firewall HA settings (DeviceHigh Availability) in a template or template stack (PanoramaTemplates), performing a local commit on one of the HA
|
||||||
|
firewalls triggers an HA config sync on the peer firewall. This
|
||||||
|
causes the HA peer configuration to go Out of
|
||||||
|
Sync.
|
||||||
|
|
||||||
|
## PAN-213746
|
||||||
|
|
||||||
|
On the Panorama management server, the Hostkey
|
||||||
|
displayed as undefined undefined if you
|
||||||
|
override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template
|
||||||
|
Stack.
|
||||||
|
|
||||||
|
## PAN-213119
|
||||||
|
|
||||||
|
PA-5410 and PA-5420 firewalls display the following error when you
|
||||||
|
view the Block IP list (MonitorBlock IP):
|
||||||
|
|
||||||
|
show -> dis-block-table is
|
||||||
|
unexpected
|
||||||
|
|
||||||
|
## PAN-212978
|
||||||
|
|
||||||
|
The Palo Alto Networks firewall stops responding when executing an
|
||||||
|
SD-WAN debug operational CLI command.
|
||||||
|
|
||||||
|
## PAN-212889
|
||||||
|
|
||||||
|
On the Panorama management server, different threat names are used
|
||||||
|
when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the
|
||||||
|
ACC displaying no data to display when
|
||||||
|
you are redirected to the ACC after clicking a threat name in the
|
||||||
|
Threat Monitor and filtering the same threat name in the Global
|
||||||
|
Filters.
|
||||||
|
|
||||||
|
## PAN-211531
|
||||||
|
|
||||||
|
On the Panorama management server, admins can still
|
||||||
|
perform a selective push to managed firewalls when Push All
|
||||||
|
Changes and Push for Other Admins
|
||||||
|
are disabled in the admin role profile (PanoramaAdmin Roles).
|
||||||
|
|
||||||
|
## PAN-207770
|
||||||
|
|
||||||
|
Data filtering logs (MonitorLogsData Filtering)
|
||||||
|
incorrectly display the traffic Direction as server-to-client instead
|
||||||
|
of client-to-server for upload traffic
|
||||||
|
that matches Enterprise data loss prevention (DLP) data patterns (ObjectsDLPData
|
||||||
|
Filtering Patterns) in an Enterprise DLP data
|
||||||
|
filtering profile (ObjectsDLPData Filtering Profiles).
|
||||||
|
|
||||||
|
## PAN-207733
|
||||||
|
|
||||||
|
When a DHCPv6 client is configured on HA
|
||||||
|
Active/Passive firewalls, if the DHCPv6 server goes down, after
|
||||||
|
the lease time expires, the DHCPv6 client should enter SOLICIT state
|
||||||
|
on both the Active and Passive firewalls. Instead, the client is
|
||||||
|
stuck in BOUND state with an IPv6 address having lease time 0 on
|
||||||
|
the Passive firewall.
|
||||||
|
|
||||||
|
## PAN-207616
|
||||||
|
|
||||||
|
On the Panorama management server, after
|
||||||
|
selecting managed firewalls and creating a new Tag (PanoramaManaged DevicesSummary) the managed firewalls are
|
||||||
|
automatically unselected and any new tag created is applied to the
|
||||||
|
managed firewalls for which you initially created the new tag.
|
||||||
|
|
||||||
|
Workaround: Select
|
||||||
|
and then unselect the managed firewalls for which you created a
|
||||||
|
new tag.
|
||||||
|
|
||||||
|
## PAN-207611
|
||||||
|
|
||||||
|
When a DHCPv6 client is configured on HA
|
||||||
|
Active/Passive firewalls, the Passive firewall sometimes crashes.
|
||||||
|
|
||||||
|
## PAN-207442
|
||||||
|
|
||||||
|
For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the
|
||||||
|
active-primary HA peer
|
||||||
|
configuration sync to the
|
||||||
|
secondary-passive HA peer may fail.
|
||||||
|
When the config sync fails, the job Results is
|
||||||
|
Successful
|
||||||
|
(Tasks), however the sync status on the
|
||||||
|
Dashboard displays as Out
|
||||||
|
of Sync for both HA peers.
|
||||||
|
|
||||||
|
Workaround: Perform a local commit on the
|
||||||
|
active-primary HA peer and then
|
||||||
|
synchronize the HA configuration.
|
||||||
|
|
||||||
|
1. Log in to the Panorama
|
||||||
|
web interface of the
|
||||||
|
active-primary HA peer.
|
||||||
|
2. Select Commit and Commit to
|
||||||
|
Panorama.
|
||||||
|
3. In the active-primary HA peer
|
||||||
|
Dashboard, click Sync
|
||||||
|
to Peer in the High Availability widget.
|
||||||
|
|
||||||
|
## PAN-207040
|
||||||
|
|
||||||
|
If you disable Advanced Routing, remove
|
||||||
|
logical routers, and downgrade from PAN-OS 11.0.0 to a PAN-OS 10.2.x
|
||||||
|
or 10.1.x release, subsequent commits fail and SD-WAN devices on
|
||||||
|
Panorama have no Virtual Router name.
|
||||||
|
|
||||||
|
## PAN-206913
|
||||||
|
|
||||||
|
When a DHCPv6 client is configured on HA
|
||||||
|
Active/Passive firewalls, releasing the IPv6 address from the client
|
||||||
|
(using Release in the UI or using the request dhcp client ipv6 release all CLI
|
||||||
|
command) releases the IPv6 address from the Active firewall, but
|
||||||
|
not the Passive firewall.
|
||||||
|
|
||||||
|
## PAN-206909
|
||||||
|
|
||||||
|
The Dedicated Log Collector is unable to
|
||||||
|
reconnect to the Panorama management server if the configd process
|
||||||
|
crashes. This results in the Dedicated Log Collector losing connectivity
|
||||||
|
to Panorama despite the managed collector connection Status (PanoramaManaged Collector)
|
||||||
|
displaying connected and the managed colletor Health status displaying
|
||||||
|
as healthy.
|
||||||
|
|
||||||
|
This results in the local Panorama config and
|
||||||
|
system logs not being forwarded to the Dedicated Log Collector.
|
||||||
|
Firewall log forwarding to the disconnected Dedicated Log Collector
|
||||||
|
is not impacted.
|
||||||
|
|
||||||
|
Workaround: Restart the mgmtsrvr process
|
||||||
|
on the Dedicated Log Collector.
|
||||||
|
|
||||||
|
1. Log in to the Dedicated Log Collector
|
||||||
|
CLI.
|
||||||
|
2. Confirm the Dedicated Log Collector is disconnected from
|
||||||
|
Panorama.
|
||||||
|
admin> show panorama-status
|
||||||
|
Verify
|
||||||
|
the Connected status is no.
|
||||||
|
3. Restart the mgmtsrvr process.
|
||||||
|
admin> debug software restart process management-server
|
||||||
|
|
||||||
|
## PAN-206416
|
||||||
|
|
||||||
|
On the Panorama management server, no data
|
||||||
|
filtering log (MonitorLogsData Filtering) is generated
|
||||||
|
when the managed firewall loses connectivity to the following cloud services,
|
||||||
|
and as a result fails to forward matched traffic for inspection.
|
||||||
|
|
||||||
|
- DLP cloud service
|
||||||
|
- Advanced Threat Protection inline cloud analysis service
|
||||||
|
- Advanced URL Filtering cloud service
|
||||||
|
|
||||||
|
## PAN-206315
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1420 firewall only
|
||||||
|
```
|
||||||
|
|
||||||
|
In an active/passive high
|
||||||
|
availability (HA) configuration, the show session info CLI
|
||||||
|
command shows that the passive firewall has packet rate and throughput
|
||||||
|
values. The packet rate and throughput of the passive firewall should
|
||||||
|
be zero since it is not processing traffic.
|
||||||
|
|
||||||
|
## PAN-205009
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1420 firewall only
|
||||||
|
```
|
||||||
|
|
||||||
|
In an active/passive high
|
||||||
|
availability (HA) configuration, the show interface all, show-high availability interface ha2,
|
||||||
|
and show high-availability all CLI
|
||||||
|
commands display the HSCI port state as unknown on both the active
|
||||||
|
and passive firewalls.
|
||||||
|
|
||||||
|
## PAN-204689
|
||||||
|
|
||||||
|
Upon upgrade to PAN-OS 11.0.1, the following GlobalProtect settings
|
||||||
|
do not work:
|
||||||
|
|
||||||
|
- Allow user to disconnect GlobalProtect
|
||||||
|
AppAllow with Passcode
|
||||||
|
- Allow user to Disable GlobalProtect
|
||||||
|
AppAllow with Passcode
|
||||||
|
- Allow User to Uninstall GlobalProtect
|
||||||
|
AppAllow with Password
|
||||||
|
|
||||||
|
## PAN-201910
|
||||||
|
|
||||||
|
PAN-OS security profiles might consume a
|
||||||
|
large amount of memory depending on the profile configuration and
|
||||||
|
quantity. In some cases, this might reduce the number of supported security
|
||||||
|
profiles below the stated maximum for a given platform.
|
||||||
|
|
||||||
|
## PAN-197588
|
||||||
|
|
||||||
|
The PAN-OS ACC (Application Command Center)
|
||||||
|
does not display a widget detailing statistics and data associated
|
||||||
|
with vulnerability exploits that have been detected using inline
|
||||||
|
cloud analysis.
|
||||||
|
|
||||||
|
## PAN-197419
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
In NetworkInterfaceEthernet, the power over Ethernet
|
||||||
|
(PoE) ports do not display a Tag value.
|
||||||
|
|
||||||
|
## PAN-197097
|
||||||
|
|
||||||
|
Large Scale VPN (LSVPN) does not support
|
||||||
|
IPv6 addresses on the satellite firewall.
|
||||||
|
|
||||||
|
## PAN-196758
|
||||||
|
|
||||||
|
On the Panorama management server, pushing
|
||||||
|
a configuration change to firewalls leveraging SD-WAN erroneously
|
||||||
|
show the auto-provisioned BGP configurations for SD-WAN as being
|
||||||
|
edited or deleted despite no edits or deletions being made when
|
||||||
|
you Preview Changes (CommitPush to DevicesEdit Selections or CommitCommit and PushEdit Selections).
|
||||||
|
|
||||||
|
## PAN-195968
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
When using the CLI to configure power over Ethernet (PoE) on a non-PoE
|
||||||
|
port, the CLI prints an error depending on whether an interface
|
||||||
|
type was selected on the non-PoE port or not. If an interface type, such
|
||||||
|
as tap, Layer 2, or virtual wire, was selected before PoE was configured,
|
||||||
|
the error message will not include the interface name (eg. ethernet1/4).
|
||||||
|
If an interface type was not selected before PoE was configured,
|
||||||
|
the error message will include the interface name.
|
||||||
|
|
||||||
|
## PAN-195342
|
||||||
|
|
||||||
|
On the Panorama management server, Context
|
||||||
|
Switch fails when you try to Context Switch from a managed firewall running
|
||||||
|
PAN-OS 10.1.7 or earlier release back to Panorama and the following
|
||||||
|
error is displayed:
|
||||||
|
|
||||||
|
Could not find start token '@start@'
|
||||||
|
|
||||||
|
## PAN-194978
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
In NetworkInterfaceEthernet, hovering the mouse over
|
||||||
|
a power over Ethernet (PoE) Link State icon
|
||||||
|
does not display link speed and link duplex details.
|
||||||
|
|
||||||
|
## PAN-194424
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5450 firewall only
|
||||||
|
```
|
||||||
|
|
||||||
|
Upgrading
|
||||||
|
to PAN-OS 10.2.2 while having a log interface configured can cause
|
||||||
|
both the log interface and the management interface to remain connected
|
||||||
|
to the log collector.
|
||||||
|
|
||||||
|
Workaround: Restart the log receiver service
|
||||||
|
by running the following CLI command:
|
||||||
|
|
||||||
|
debug software restart process log-receiver
|
||||||
|
|
||||||
|
## PAN-187685
|
||||||
|
|
||||||
|
On the Panorama management server, the Template Status
|
||||||
|
displays no synchronization status (PanoramaManaged DevicesSummary)
|
||||||
|
after a bootstrapped firewall is successfully added to Panorama.
|
||||||
|
|
||||||
|
Workaround: After
|
||||||
|
the bootstrapped firewall is successfully added to Panorama, log in to the Panorama web interface and
|
||||||
|
select CommitPush
|
||||||
|
to Devices.
|
||||||
|
|
||||||
|
## PAN-187407
|
||||||
|
|
||||||
|
The configured Advanced Threat Prevention
|
||||||
|
inline cloud analysis action for a given model might not be honored
|
||||||
|
under the following condition: If the firewall is set to Hold
|
||||||
|
client request for category lookup and the action set
|
||||||
|
to Reset-Both and the URL cache has been
|
||||||
|
cleared, the first request for inline cloud analysis will be bypassed.
|
||||||
|
|
||||||
|
## PAN-186283
|
||||||
|
|
||||||
|
Templates appear out-of-sync on Panorama
|
||||||
|
after successfully deploying the CFT stack using the Panorama plugin for
|
||||||
|
AWS.
|
||||||
|
|
||||||
|
Workaround: Use CommitPush to Devices to synchronize
|
||||||
|
the templates.
|
||||||
|
|
||||||
|
## PAN-184708
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama managed firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if:
|
||||||
|
|
||||||
|
- A scheduled report email contains
|
||||||
|
a Report Group (MonitorPDF
|
||||||
|
ReportsReport Group)
|
||||||
|
which includes a SaaS Application Usage report.
|
||||||
|
- A scheduled report contains only a SaaS Application Usage Report.
|
||||||
|
|
||||||
|
Workaround: To
|
||||||
|
receive a scheduled report email for all other PDF report types:
|
||||||
|
|
||||||
|
1. Select MonitorPDF ReportsReport Groups and
|
||||||
|
remove all SaaS Application Usage reports from all Report Groups.
|
||||||
|
2. Select MonitorPDF
|
||||||
|
ReportsEmail Scheduler and
|
||||||
|
edit the scheduled report email that contains only a SaaS Application Usage
|
||||||
|
report. For the Recurrence, select Disable and
|
||||||
|
click OK.
|
||||||
|
Repeat this step for all scheduled
|
||||||
|
report emails that contain only a SaaS Application Usage report.
|
||||||
|
3. Commit.
|
||||||
|
()
|
||||||
|
Select CommitCommit
|
||||||
|
and Push
|
||||||
|
|
||||||
|
## PAN-184406
|
||||||
|
|
||||||
|
Using the CLI to add a RAID disk pair to
|
||||||
|
an M-700 appliance causes the dmdb process to crash.
|
||||||
|
|
||||||
|
Workaround: Contact
|
||||||
|
customer support to stop the dmdb process before adding a RAID disk
|
||||||
|
pair to a M-700 appliance.
|
||||||
|
|
||||||
|
## PAN-183404
|
||||||
|
|
||||||
|
Static IP addresses are not recognized when
|
||||||
|
"and" operators are used with IP CIDR range.
|
||||||
|
|
||||||
|
## PAN-181933
|
||||||
|
|
||||||
|
If you use multiple log forwarding cards
|
||||||
|
(LFCs) on the PA-7000 series, all of the cards may not receive all
|
||||||
|
of the updates and the mappings for the clients may become out of sync,
|
||||||
|
which causes the firewall to not correctly populate the Source User
|
||||||
|
column in the session logs.
|
||||||
|
|
||||||
|
## PAN-171938
|
||||||
|
|
||||||
|
No results are displayed when you Show Application
|
||||||
|
Filter for a Security policy rule (PoliciesSecurityApplicationValueShow Application Filter).
|
||||||
|
|
||||||
|
## PAN-164885
|
||||||
|
|
||||||
|
On the Panorama management server, pushes to managed firewalls (CommitPush to Devices or Commit and Push) may fail
|
||||||
|
when an EDL (ObjectsExternal Dynamic Lists) is configured to Check for
|
||||||
|
updates every 5 minutes due to the commit and EDL
|
||||||
|
fetch processes overlapping. This is more likely to occur when
|
||||||
|
multiple EDLs are configured to check for updates every 5
|
||||||
|
minutes.
|
||||||
@@ -211,7 +211,15 @@
|
|||||||
"11.0.6_2026-03-16.md",
|
"11.0.6_2026-03-16.md",
|
||||||
"11.0.6-h1_2026-03-16.md"
|
"11.0.6-h1_2026-03-16.md"
|
||||||
],
|
],
|
||||||
"known": []
|
"known": [
|
||||||
|
"11.0.0_2026-03-16.md",
|
||||||
|
"11.0.1_2026-03-16.md",
|
||||||
|
"11.0.2_2026-03-16.md",
|
||||||
|
"11.0.3_2026-03-16.md",
|
||||||
|
"11.0.4_2026-03-16.md",
|
||||||
|
"11.0.5_2026-03-16.md",
|
||||||
|
"11.0.6_2026-03-16.md"
|
||||||
|
]
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"10": {
|
"10": {
|
||||||
|
|||||||
Reference in New Issue
Block a user