Discard the crawler, manually collect reference material for processing

This commit is contained in:
2026-04-13 13:38:18 -05:00
parent e53a813713
commit 37eaffba3f
19 changed files with 11895 additions and 783 deletions
+140
View File
@@ -0,0 +1,140 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-242777</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where users previously reported limitations due to
session count caps when utilizing
<b class="ph b">Web Proxy</b> features on PA-5400 Series Firewalls. To
address these performance complaints and support higher traffic
volumes, we have increased the maximum session capacity on specific
<b class="ph b">PA-5400F</b> series platforms, leveraging available
system memory. This update ensures greater capacity and stability for
high-volume environments.
</div>
<div class="p">
The supported session limits are:
<div style="display: inline"></div>
<div style="display: inline"></div>
<div style="display: inline"></div>
<div style="display: inline"></div>
<div style="display: inline"></div>
<div style="display: inline"></div>
<div style="display: inline"></div>
<div style="display: inline"></div>
<div style="display: inline"></div>
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 50%" />
<col style="width: 50%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">Platform</th>
<th class="entry">Max Sessions</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">PA-5410</td>
<td class="entry relcol">95K</td>
</tr>
<tr class="row">
<td class="entry">PA-5420</td>
<td class="entry relcol">95K</td>
</tr>
<tr class="row">
<td class="entry">PA-5430</td>
<td class="entry relcol">95K</td>
</tr>
<tr class="row">
<td class="entry">PA-5440</td>
<td class="entry relcol">225K</td>
</tr>
<tr class="row">
<td class="entry">PA-5445</td>
<td class="entry relcol">250K</td>
</tr>
<tr class="row">
<td class="entry">PA-5450</td>
<td class="entry relcol">1.28M</td>
</tr>
</tbody>
</table>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291499</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Amazon Web Services (AWS) environments
only</tt
>) Fixed an issue where newly deployed firewalls were unable to
connect to the Strata Logging Service (SLS) until after a reboot,
license fetch, or management server restart.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-288726</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="keyword cmdname">useridd</span> process stopped
responding due to a Security policy rule ID being set to 0, which
caused the last configuration retrieval to fail.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287133</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where assigning a policy
rule to a group at the top or bottom of the list changed the order of
other policy rules.
</div>
</td>
</tr>
</tbody>
</table>
+34
View File
@@ -0,0 +1,34 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-304195</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where performing a private data reset
caused device telemetry to stop working. This issue also occurred
after performing a factory reset and then running the CLI command
<span class="ph systemoutput">set system ztp disable</span>.
</div>
</td>
</tr>
</tbody>
</table>
+90
View File
@@ -0,0 +1,90 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"></b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0227"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0227</a
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-306534</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue were the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process repeatedly restarted due to memory pool corruption when
processing fragmented DNS over HTTPs (DoH) JSON queries. This occurred
due to incorrect buffer length calculations during memory deallocation
when the query name field spanned multiple packets.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-305480</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process stopped responding while processing DoH JSON format traffic
with DoH Security enabled, which caused missing cross-packet bytes in
the decoded DNS query type field, and the dataplane went down.
</div>
</td>
</tr>
</tbody>
</table>
+180
View File
@@ -0,0 +1,180 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300334</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the ADEM plugin was not compatible with PAN-OS
12.1.2, which prevented installation of the plugin and disabled the
ability to monitor remote sites on firewalls using the ADEM
functionality.
</div>
<div class="p">
To use this fix, you need the following compatible versions: ADEM
1.1.0-h3 and SD-WAN plugin 3.4.0.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-298241</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the NAT IP address pool was exhausted, which led
to intermittent connectivity issues with call applications and
outbound call failures. This occurred due to the firewall not properly
releasing NAT dynamic ports back to the address pool.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-296490</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">FIPS CC mode enabled only</tt>) Fixed an issue
where Panorama on GCP rebooted every hour after upgrading to
11.1.6-h10.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-289249</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory leak occurred on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process when a WildFire update was initiated while device telemetry
data collection was in progress. This resulted in an OOM condition.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-286576</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process restarted, which caused heartbeat failures to occur and a slot
to go down due to path monitor failure.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-272245</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>dnsproxy</a
>
process crashed due to memory corruption caused by a race condition
when the allow list downloading was impacted by config change.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267450</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process stopped responding with a SIGSEGV at
<span class="ph systemoutput">schedule_report_es_response</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262831</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5400f Series firewalls only</tt>) Fixed an
intermittent issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding, which caused the firewall to restart.
</div>
</td>
</tr>
</tbody>
</table>
+77
View File
@@ -0,0 +1,77 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-311938</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where autocommits failed after an upgrade due to
configuration memory allocation issues and 100% policy rule cache
usage when both DNS Rewrite and URL Custom Category Match were
configured.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-306451</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls on AWS environments only</tt>)
Fixed an issue where, after upgrading the firewall to an affected
release, GlobalProtect clients did not connect with IPSec and instead
connected using SSL due to traffic flow being disabled when checking
for health check packets.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-304496</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after unregistering an IP tag and registering a
different IP tag for the same IP address via XML API, the dynamic
address group membership was not updated on the dataplane, which
resulted in Security policy rules being enforced incorrectly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-304195</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where performing a private data reset
caused device telemetry to stop working. This issue also occurred
after performing a factory reset and then running the CLI command
<span class="ph systemoutput">set system ztp disable</span>.
</div>
</td>
</tr>
</tbody>
</table>
+59
View File
@@ -0,0 +1,59 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-313572</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the dataplane restarted due to a segmentation fault.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300664</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama and firewall web interface where
Applications pages became unresponsive after activating the SaaS
Inline license.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-292447</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not display data in the
<span class="ph uicontrol">Feature Adoption</span> tab in Strata Cloud
Manager due to the system creating and deleting a CLI user for each
interval instead of reusing a permanent CLI user for telemetry.
</div>
</td>
</tr>
</tbody>
</table>
+623
View File
@@ -0,0 +1,623 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"></b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0227"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0227</a
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-305480</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process stopped responding while processing DoH JSON format traffic
with DoH Security enabled, which caused missing cross-packet bytes in
the decoded DNS query type field, and the dataplane went down.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-305151</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the configuration was not updated on the AI
Firewall in AWS after a successful configuration push from Strata
Cloud Manager (SCM).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-304195</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where performing a private data reset
caused device telemetry to stop working. This issue also occurred
after performing a factory reset and then running the CLI command
<span class="ph systemoutput">set system ztp disable</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-304075</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not detect evasions due to TCP
checksum offloading not being enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-303836</b></div>
</td>
<td class="entry relcol">
<div class="p">
Resolved an issue in which intermittent session-table resets on the
AIRS VM triggered packet drops, leading to packet loss in egress
response traffic
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-303700</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect users were incorrectly dropped by
the default Security policy rule after upgrading to PAN-OS 12.1.2 when
IPv6 firewalling was disabled. This occurred due to policy rules
configured with geographic regions matching traffic incorrectly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-303559</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after manuallly creating a device telemetry
bundle, the
<span class="ph systemoutput">hour_cli_output.txt</span> file within
the bundle had a file size of 0 bytes. This occurred when checking the
bundle content after enabling device telemetry and setting the device
telemetry upload endpoint.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-302908</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not forward STP frames on Layer
2 VLAN interfaces, which prevented the construction of loop-free
topologies with connected switches.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-301801</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Log Collectors where the Elasticsearch process
fluctuated intermittently between green and red states, which led to
interruptions in log collection. This issue occurred when the number
of shards exceeded the cluster's maximum supported threshold of
greater than 1000 shards per Elasticsearch instance.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-301496</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the DNS cache capacity was insufficient for
environments with a large number of FQDN address objects, which caused
the firewall to repeatedly send DNS requests for the same FQDN objects
even after it received valid responses.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-300837</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls experienced multiple reboots due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process restarting with a SIGSEGV signal. This occurred because the
client-to-firewall side assumed TLS 1.3 for the firewall-server side.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-300372</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama virtual appliances only</tt>) Fixed an
issue where maintenance mode was not accessible to do Factory Reset or
switch to FIPSCC mode.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-300096</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a local commit on a firewall breaks template
stack overrides, preventing the enabling of LACP (Link Aggregation
Control Protocol). After a local commit, the LACP enable check was
unexpectedly unchecked, causing an outage. Attempting to re-enable
LACP through the web interface was unsuccessful, requiring manual
removal of the LACP configuration from the Panorama CLI.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-299815</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on multi-vsys firewalls where a host was not removed
from the quarantine list after receiving a redistribution message from
Panorama. This occurred when Panorama was configured to redistribute
quarantine messages to a firewall cluster, and the GlobalProtect
configuration and redistribution were built out in a vsys other than
vsys1.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-299678</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall repeatedly rebooted when downgrading
to an affected release.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-299193</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where, after upgrading, autocommits
repeatedly failed until after a second reboot due to a timing issue
between content loading on the management plane card (MPC) and the log
receiver startup.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-298684</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an Application Override policy rule was not
applied using an IPv4 source IP address with IPv6 enabled and
<span class="ph uicontrol">Network</span> &gt;
<span class="ph uicontrol">Zones</span> &gt;
<span class="ph uicontrol">Pre-NAT Identification</span> enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-298654</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall generated false positive threat logs
during updates to a large domain list (EDL) when a DNS lookup for a
domain being added or removed occurred during the update process. This
resulted in a threat log being generated for a different, unrelated
domain that remained on the list.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-298514</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where WildFire clusters operating in FIPS-CC mode were
not supported in earlier PAN-OS 12.1 releases.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-297972</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a dataplane crash occurred when traffic matched
Inline Cloud Analysis prefiltering signatures, even when Inline Cloud
Analysis features were not enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-297797</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, during a refresh of a large External Dynamic
List (EDL), traffic that matched a domain on the list was incorrectly
identified as a different domain, which resulted in false positive
threat logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-297708</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a long-lived session with many Machine Learning
(ML) model triggers caused a memory leak of feature states associated
with the ML model runs. This resulted in Spyware_State failure
increases, allocation max outs, and impaired policy matching.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-297005</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where exporting custom reports resulted in empty CSV
files.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-296635</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process on passive Panorama management servers leaked memory due to
scheduled report handling from the Strata Logging Service (SLS). This
memory leak occurred daily, consuming available memory until the
process was restarted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-296478</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to PAN-OS 10.2.13-h10,
GlobalProtect Clientless VPN on PA-3250 firewalls failed to execute
JavaScript links, resulting in an authorization error. This occurred
because the firewall was incorrectly injecting text into URLs when
JavaScript buttons or dropdown menus were clicked within the
Clientless VPN portal.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-296453</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where decryption exclusion lists were not working for
untrusted certificates, and SSL sessions were still being decrypted
even after adding them to the exclusion list. This occurred because
the firewall was not adding sessions to the exclude cache until after
receiving a non-RFC alert (BadCertificate) from the server. The fix
ensures that the first session is added to the exclude cache, allowing
subsequent sessions to skip decryption. This issue affects firewalls
configured as clients in server-client communication.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-296202</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/active HA configurations only</tt
>) Fixed an issue where, when a commit operation was in progress,
newly deployed IP address tags that used the XML API were not
immediately reflected in address group resolution, which delayed IP
address mapping to address groups and caused traffic to be incorrectly
allowed or denied.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-295221</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading Panorama and Log Collectors from
PAN-OS 10.2.9 to PAN-OS 11.1.6-h6, Traffic and Threat logs were not
forwarded to a Splunk server over UDP.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-292393</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TFTP file transfers intermittently timed out in
active-active HA pairs when the TFTP control channel was processed by
one firewall and the data channel was processed by the other. This
occurred because the firewall receiving the data channel failed to
match the predicted session due to asynchronous processing of HA
messages.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-291716</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where during a commit, the firewall experienced an
out-of-memory (OOM) condition due to a memory leak and displayed an
error message. This issue caused the device to stop responding and
reboot unexpectedly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-291661</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama appliances and Log Collectors where, after
an upgrade, Elasticsearch intermittently entered into a Red state
before automatically recovering.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-290665</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with firewalls enabled with Security profiles where
certain traffic conditions caused high dataplane CPU utilization and
packet buffer exhaustion, which caused LACP flapping conditions.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-290640</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Microsoft Azure environments in HA
configurations only</tt
>) Fixed an issue where, when an interface was configured with IPv6,
the firewall displayed the message
<span class="ph uicontrol">Unknown error</span> during validation
after the client secret expired, which caused DNS resolution to fail
when resolving FQDNs and HA failovers to occur.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-290453</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where PA-7500 firewalls experienced silent traffic
drops. During migration from PA-7050 to PA-7500 firewalls connected in
series, intermittent connection losses occurred for some applications.
Traffic leaving the PA-7050 was not received or processed by the
PA-7500, even with direct connections and replaced cables/SFPs. Global
counters did not indicate any drops on the PA-7500.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-288598</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama exported the serial number of a managed
collector instead of the collector name when exporting a PDF or CSV
file.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-287387</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where API jobs failed with the error
message
<span class="ph systemoutput"
>Server error: Timed out while getting config lock</span
>. This occurred due to slow set request performance when setting a
large number of address objects in a single set call.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-282640</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where custom reports showed incomplete data when
exported in CSV format from Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-274333</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Logging Service License Status displayed as
red even though a valid license was installed on the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262353</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when Panorama was upgraded but log collectors
were on an earlier version, logs from a log collector group were not
viewable on a Panorama.
</div>
</td>
</tr>
</tbody>
</table>
File diff suppressed because it is too large Load Diff
+198
View File
@@ -0,0 +1,198 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-316911</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Amazon Web Services (AWS) environments
only</tt
>) Fixed an issue where a newly bootstrapped firewall required a
management server restart, relicensing, or license push from Panorama
to invoke the device certificate.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-314201</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on PAN-OS 12.1 releases where intermittent traffic
drops occurred over IPSec VPN tunnels to third-party firewalls during
the IPSec rekey due to the firewall failing to inform the peer to
delete the old SA after moving to the new one.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-313216</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls with Prisma Access incorrectly
displayed some traffic as unsanctioned in traffic logs for cloud
applications that were tagged as
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>sanctioned</a
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-311512</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where HIP (Host Information Profile) reports were
blocked on GlobalProtect when
<span class="ph uicontrol"
>Authentication Cookie Usage Restrictions</span
>
was enabled and the Prisma Access Agent protocol was in use. This
occurred because the system failed to correctly process HIP messages
that were relayed via IPSec tunnels with a Virtual IP as the source,
leading to their rejection.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-311412</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">show advanced-routing resource</span>
CLI command failed to execute successfully when invoked through the
XML API and returned an error message.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-311261</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall generated duplicate URL Filtering
logs due to an error condition&nbsp;when the new XFF feature was
enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-311250</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances and Log Collectors only</tt>)
Fixed an issue where logs from multiple devices were not visible on
Panorama even though the Elasticsearch health status on the dedicated
Log Collectors appeared green.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-310362</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IPv6 Routed HA did not function correctly when
the HA1 (control link) was configured with an IPv6 routed connection.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-310240</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where software packet buffers were completely utilized
when performing a Data Loss Prevention longevity test.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-308507</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama managed firewalls only</tt>) Fixed an
issue where the firewall intermittently failed to maintain active log
forwarding streams to Strata Logging Service (SLS) even when duplicate
logging and enhanced application logging were enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-308418</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when Advanced DNS Security was enabled and
experienced unusually high loads, DNS resolution failures occurred
with the error
<span class="ph uicontrol">resources-unavailable</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-308261</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall failed to send SNMPv3 traps when the
SNMP destination was configured with an FQDN that resolved to multiple
IP address through DNS load balancing.
</div>
</td>
</tr>
</tbody>
</table>
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
+876
View File
@@ -0,0 +1,876 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 34%" />
<col style="width: 66%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-314201</b></div>
<div class="p">
<tt class="ph tt">This issue is now resolved. See </tt
><a
class="xref"
href="/content/techdocs/en_US/ngfw/release-notes/12-1/pan-os-12-1-6-known-and-addressed-issues/pan-os-12-1-6-addressed-issues.html"
title=""
data-scope="local"
data-format="dita"
data-type=""
target="_self"
>PAN-OS 12.1.6 Addressed Issues</a
>
</div>
</td>
<td class="entry relcol">
<div class="p">
On firewalls running PAN-OS 12.1, IPsec VPN tunnels to third-party
peer devices may experience intermittent traffic loss during rekey
operations. When a new Security Association (SA) forms before the old
SA expires, traffic may stop flowing until the older SA naturally
expires or you manually clear it. During this time, the output of show
vpn ipsec-sa may show two SAs for the same proxy ID. This issue
primarily affects tunnels to third-party peer devices and does not
occur with Palo Alto Networks to Palo Alto Networks tunnels.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Manually clear the affected Security
Association using the command
<span class="ph userinput"
>clear vpn ipsec-sa tunnel &lt;tunnel-name&gt;</span
>
to restore connectivity.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-313779</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7500 series only</tt>) PA-7500 series firewalls
running PAN-OS 12.1.5 release do not support encryption on HA1 and
HA1-backup interfaces. As a result, attempting to execute the
<span class="ph codeph"
>request high-availability session-reestablish</span
>
command will fail with the following error.
</div>
<div class="p">
<pre
id="panos-known-issues-12.1.5_screen-ilq_djv_h3c"
class="pre screen"
>
ERROR: Encryption is not enabled for HA</pre
>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-313669</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-5500 Series firewalls in cluster configurations only</tt
>) When a firewall node is removed from a PA-5500 Series cluster,
after the cluster commit and reboot, the node starts in standalone
mode with a default virtual wire (vwire) configuration loaded. This
default configuration is missing zone assignments for ports eth1/1 and
eth1/2, which causes commit operations to fail. Even if zones are
manually assigned to these ports, subsequent commit attempts will fail
with a
<span data-outputclass="response" class="ph systemoutput"
>no UUId for rule1</span
>
error.
</div>
<div class="p">
<b class="ph b">Workaround:</b> To resolve this, either:
</div>
<div class="p">
<ul id="panos-known-issues-12.1.5_ul-ybs_j3g_k3c" class="ul">
<li class="li">
Manually assign zone configurations to ports eth1/1 (for example,
untrust) and eth1/2 (for example, trust), then open and close
security policy rule1 without making changes, and
<span class="ph uicontrol">Commit</span>.
</li>
<li class="li">
Delete the default rule and the default virtual wire Ethernet
interfaces, then commit.
</li>
</ul>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-313623</b></div>
</td>
<td class="entry relcol">
<div class="p">
On firewalls with TPM (Trusted Platform Module) support, device
certificate renewals may fail due to a disk partition being full. This
latter occurs because temporary files aren't being deleted during
device certificate status checks.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-312247</b></div>
</td>
<td class="entry relcol">
<div class="p">
In generated PDF upgrade check reports, long remediation URLs might be
truncated due to UI framework export limitations, leaving only the
first line hyperlinked. However, these links remain fully functional
within the Panorama web interface. The PDF link directs to the correct
destination if the complete URL is copied from the PDF and pasted in
the browser.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-309604</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5500 series only</tt>) In some rare cases, the
front panel PSU status LED might show amber, even when the LEDs on the
PSU show green.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-309602</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5500 series only</tt>) When the firewall is
initially powered on, the FAN-0 LED does not turn on. The fan
functions correctly, but the LED doesn't reflect the status.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Remove and reinsert the fan to turn on
the LED.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-308564</b></div>
</td>
<td class="entry relcol">
<div class="p">
Packets are dropped on SD-WAN interfaces if they require fragmentation
for an interface but have the
<span class="ph uicontrol">Don't Fragment (DF)</span> bit set. This
results in unexpected packet drops. This affects client to server
sessions when using SD-WAN for NGFW.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Allow fragmenting packets with DF bit
set (<span class="ph userinput"
>debug dataplane set ip4-ignore-df yes</span
>).
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-308507</b></div>
<div class="p">
<tt class="ph tt">This issue is now resolved. See </tt
><a
class="xref"
href="/content/techdocs/en_US/ngfw/release-notes/12-1/pan-os-12-1-6-known-and-addressed-issues/pan-os-12-1-6-addressed-issues.html"
title=""
data-scope="local"
data-format="dita"
data-type=""
target="_self"
>PAN-OS 12.1.6 Addressed Issues</a
>.
</div>
</td>
<td class="entry relcol">
<div class="p">
Strata Logging Service (SLS) log-forwarding streams intermittently
show as inactive. When checking the status of log-forwarding
connections, one or more streams are reported as inactive. Restarting
the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>log-receiver</a
>
process temporarily resolves the issue, but the streams become
inactive again after approximately 1-2 hours. This intermittent
inactivity results in log loss.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300850</b></div>
</td>
<td class="entry relcol">
<div class="p">
Manual scheduling of cloud verdicts is required if a new host in an
Host Compliance Service-enabled environment has a refresh event entry
without a corresponding update event entry.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300809</b></div>
</td>
<td class="entry relcol">
<div class="p">
Host Compliance Service connectivity will not work if it is connected
with management IP which is configured with DHCP mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300677</b></div>
</td>
<td class="entry relcol">
<div class="p">
Panorama cannot display Threat log entries (<b class="ph b"
>Monitor &gt; Logs &gt; Threat</b
>) when the managed log collector is running a lower PAN-OS release
than Panorama.
</div>
<div class="p">
Workaround: Upgrade the log collectors to the same version as
Panorama.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300627</b></div>
</td>
<td class="entry relcol">
<div class="p">
AutoCommit fails when the Traffic Object is used on AI Runtime
Security, which consequently impacts the workloads that utilize
overlapping subnets.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300483</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7500 firewall only</tt>) Enabling FIPS-CC mode
causes the firewall to go into maintenance mode.
</div>
<div class="p">
<b class="ph b">Workaround</b>: After the firewall goes into
maintenance mode, perform an additional reboot. The firewall will
successfully start up in FIPS-CC mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300467</b></div>
</td>
<td class="entry relcol">
<div class="p">
WildFire WF-500 appliances running PAN-OS 10.x or PAN-OS 11.x cannot
be managed by Panorama running PAN-OS 12.1.2 due to connectivity
issues.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Upgrade your WildFire appliances to
PAN-OS 12.1.2 or later.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300407</b></div>
</td>
<td class="entry relcol">
<div class="p">
The Release Note URL column in the Panorama &gt; Plugins page is
empty.
</div>
<div class="p">
Release Notes for the plugins are available in the
<a
class="xref"
href="https://docs.paloaltonetworks.com/plugins/vm-series-and-panorama-plugins-release-notes"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>plugins release notes</a
>
or in their individual product release notes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300230</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">NGFW Cluster</tt>) In an NGFW cluster, your pings
to the HSCI-B link might fail, even when the link indicates it is up.
In the event that the HSCI-A link is brought down or unplugged, the
cluster node will transition to failed state, avoiding split brain as
both HSCI links are down in this case.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Reboot the cluster node to resolve the
HSCI-B ping issue.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300192</b></div>
</td>
<td class="entry relcol">
<div class="p">
If the Host Compliance Service is configured with a service route
pointing to an unreachable IP address, the
<span class="ph systemoutput">gp_broker</span> process may stop
working when you enable-disable the Host Compliance Service.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300114</b></div>
</td>
<td class="entry relcol">
<div class="p">
VM entered maintenance mode during a downgrade from version 12.1.2 to
11.2.7, when executed through the CLI.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Download and install the required
version of PAN-OS through the UI instead of the CLI.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300069</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-410 firewall only</tt>) Loading a saved config
file can take up to 5 minutes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300053</b></div>
</td>
<td class="entry relcol">
<div class="p">
When you use the CLI command
<span class="ph userinput">request system fqdn refresh</span> to
trigger another IP address resolution of configured FQDN entries, the
firewall might get into an error state where the DNS Proxy cache
received and stored a new IP address for a particular FQDN entry via
this command. However, the Device-Server (and the Security rule) still
have the old IP address for that FQDN entry.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Avoid using the CLI command:
<span class="ph userinput">request system fqdn refresh</span>. Use the
following command instead (for a particular domain-name or an entire
list):
<span class="ph userinput"
>clear dns-proxy cache all domain-name &lt;domain_name&gt;</span
>. To correct the error state where the DNS Proxy cache and
Device-Server and Security rule are already storing different IP
addresses, use the following CLI command:
<span class="ph userinput"
>debug device-server dump fqdn type resync vsys &lt;vsys_name&gt;
fqdn-name &lt;domain_name&gt;</span
>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300025</b></div>
</td>
<td class="entry relcol">
<div class="p">
If Azure hotplug events occur, the firewall may experience a
<span class="ph userinput">brdagent</span> crash and data interfaces
may transition to an unknown state, leading to traffic disruption.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Reboot the VM if the
<span class="ph userinput">brdagent</span> crash does not trigger a
device reboot.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-299562</b></div>
</td>
<td class="entry relcol">
<div class="p">
SSL proxy sessions fail when clients send a Client Hello with TLSv1.2
and TLSv1.3, and exclusively prefer the secp192 elliptic curve.
</div>
<div class="p">
<b class="ph b">Workaround</b>: To address this, configure a
decryption profile to use TLSv1.2 as the maximum supported TLS
version. Then, apply this profile to the decryption policy rules for
the affected clients and servers. This enables the client to modify
its preferred curves, facilitating successful session establishment.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">PAN-299387</b></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">NGFW Cluster</tt>) When an NGFW cluster has only
one firewall node present and powered up, that node is stuck in
UNKNOWN state after you reboot it and it comes back up. The issue
occurs in two scenarios:
</div>
<ul id="panos-known-issues-12.1.5_ul-pfz_hyt_tgc" class="ul">
<li class="li">
When there is only one node configured in the cluster (no peer is
available or configured).
</li>
<li class="li">
When the peer device in the cluster is completely powered down or
unable to autonegotiate its connected HSCI ports. That is, two nodes
are in the cluster, but only one node is booting up while the other
remains down completely.
</li>
</ul>
<div class="p">
The expected behavior is that if no peer device is available (at a
port autonegotiation or link level for HSCI-A or HSCI-B), then a
cluster device should go to INITIAL state, followed by ONLINE state
(and not remain in UNKNOWN state).
</div>
<div class="p">
<b class="ph b">Workaround</b>: To avoid this issue, connect the
HSCI-A to HSCI-B in loopback to create a link partner.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">PAN-299229</b></td>
<td class="entry relcol">
<div class="p">
On PA-5400 Series and PA-7500 Series firewalls, if you run certain
types of CLI commands during or shortly after a commit, the commands
will time out. The types of CLI commands impacted by this issue are
IoT, Cloud-User-ID, and App-ID Cloud Engine CLI commands.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Don't execute IoT, Cloud-User-ID, or
App-ID Cloud Engine CLI commands during or shortly after a commit on a
PA-5400 Series or PA-7500 Series firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">PAN-299170</b></td>
<td class="entry relcol">
<div class="p">
The remediation link included in the generated PDF of an upgrade check
report might be pruned due to a text length limitation of the export
function. The link remains fully functional and works correctly on the
Panorama web interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">PAN-299114</b></td>
<td class="entry relcol">
<div class="p">
After you enable the
<span class="ph uicontrol"
>Enable Duplicate Logging (Cloud and On-Premise) </span
>setting on a firewall, clicking
<span class="ph uicontrol">Status for Cloud Logging</span>, does not
display the logging service connection status.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">PAN-298540</b></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5500 Series firewalls only</tt>) The
<span class="ph uicontrol">Monitor</span> tab in the Web Interface
does not display a pop-up to indicate that high-speed log forwarding
is enabled and that logs are only viewable from Panorama.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">PAN-298083</b></td>
<td class="entry relcol">
<div class="p">
After you change the system mode on an M-700 appliance from Panorama
mode to PAN-DB private cloud mode, the
<span class="ph codeph">snmpd</span> process fails to work.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">PAN-298047</b></td>
<td class="entry relcol">
<div class="p">
In an AI Runtime Security environment, the Azure Container outbound
traffic does not seem to be functional and the egress traffic is being
misdirected to an incorrect cluster node port.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">PAN-297772</b></td>
<td class="entry relcol">
<div class="p">
When an Intel e810 NIC is configured in SR-IOV mode, sharing Virtual
Functions (VFs) among multiple HSF cluster nodes and subsequently
rebooting a cluster node while traffic is active may result in traffic
disruption on other HSF cluster nodes utilizing the same NIC. It is
recommended to refrain from sharing Intel e810 VFs across cluster
nodes and to allocate one VF per Intel e810 PF.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297114</b></div>
</td>
<td class="entry relcol">
<div class="p">
After successfully generating a health check report for managed
firewalls from Panorama, the progress bar does not appear and the
latest health check reports are not displayed (<span
class="ph uicontrol"
>Panorama &gt; Device Deployment &gt; Upgrade Check</span
>).
</div>
<div class="p">
<b class="ph b">Workaround</b>: Manually refresh the page to see the
latest reports.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-294687</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">NGFW Clusters</tt>) In an NGFW cluster, the leader
can't retrieve the HIP Report from Panorama, nor synchronize it to the
non-leader nodes. Unlike HA Active/Passive mode, both leader and
non-leader nodes receive traffic in cluster mode. If the relevant HIP
Report is missing, policies involving HIP may not work properly. The
expected behavior is that when a non-leader node receives related
traffic, it should request the corresponding HIP Report from the
leader.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-293754</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">NGFW Clusters</tt>) Firewalls in an NGFW cluster
indicate they are in ONLINE state even though their configurations are
different (they aren't synchronized).
</div>
<div class="p">
<b class="ph b">Workaround</b>: Push the configuration from Panorama
to all cluster members at the same time; don't push to an individual
firewall. If a cluster member isn't connected to Panorama during the
push, the push will fail to the disconnected firewall, but will
succeed to all connected firewalls.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-293718</b></div>
</td>
<td class="entry relcol">
<div class="p">
When high speed logging is enabled on a PA-5560 device, the expected
warning message is not displayed on the web interface. This prevents
administrators from being notified that logs can only be viewed from
Panorama.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-292601</b></div>
</td>
<td class="entry relcol">
<div class="p">
PAN-OS 12.1.2 and later 12.1 releases support a Load Balanced DNS
configuration for an address object. If there are two address objects
with same FQDN, but one object has Load Balanced DNS enabled and other
object has Load Balanced DNS disabled, then the policy match for the
removed IP addresses doesn't work as expected.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Enable (or disable) Load Balanced DNS
consistently for an FQDN that is used with multiple address objects.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-290692</b></div>
</td>
<td class="entry relcol">
<div class="p">
In Host Compliance Service, when you create a 'Shared' type Host
Compliance Object for the 'Disk-Encryption' category, the State
drop-down is automatically selected and cannot be edited. However, you
can change the state later by editing the object, if required.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-289524</b></div>
</td>
<td class="entry relcol">
<div class="p">
In PAN-OS 12.1.2 and later 12.1 releases, PAN-OS can obtain resolved
IP addresses from a Load balanced DNS server and use them in a policy
match. However, this functionality does not work as intended when the
DNS cache reuse flag is enabled. When the DNS cache reuse flag is
enabled, the DNS resolution works as if the Load balanced DNS flag
(for an Address object) is disabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286496</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">NGFW Clusters</tt>) URL-continue and override
continue selections will function like a general URL-block action.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-283429</b></div>
</td>
<td class="entry relcol">
<div class="p">
When you use custom certificates for the connection between Panorama
and a log collector, the automated renewal for the predefined
ElasticSearch certificates gets disrupted.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Remove the custom certificates before
the ElasticSearch certificates expire. This allows the system to
correctly identify and renew the predefined ElasticSearch
certificates. After the renewal is complete, re-install the custom
certificates.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-237106</b></div>
</td>
<td class="entry relcol">
<div class="p">
LSVPN satellite certificates may be generated with serial numbers
exceeding 40 hexadecimal characters. This causes certificate
revocation and deletion operations to fail with the following error
messages:
</div>
<ul id="panos-known-issues-12.1.5_ul-t2x_dxs_wgc" class="ul">
<li class="li">
<span class="ph systemoutput"
>db-serialno can be at most 40 characters</span
>
</li>
<li class="li">
<span class="ph systemoutput">db-serialno is invalid</span>
</li>
</ul>
<b class="ph b">Workaround:</b>
<div class="p">
To resolve this issue, use the following CLI commands with the LSVPN
satellite serial number to manually delete or revoke the affected
certificates:
</div>
<div class="p">
<b class="ph b">Delete certificate information</b>:<span
class="ph userinput"
>delete sslmgr-store certificate-info portal name
<var class="keyword varname">&lt;name&gt;</var> serialno
<var class="keyword varname">&lt;satellite_serial&gt;</var></span
>
</div>
<div class="p">
<b class="ph b">Revoke satellite certificates</b>:<span
class="ph userinput"
>delete sslmgr-store satellite-info-revoke-certificate portal
<var class="keyword varname">&lt;name&gt;</var> serialno
<var class="keyword varname"
>&lt;list_of_satellite_serials&gt;</var
></span
>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PLUG-21065</b></div>
</td>
<td class="entry relcol">
<div dir="ltr" class="p">
In a PA-VM or AI Runtime Security environment, it is observed that the
Software Firewall Orchestration plugin deployed with a VM-Flex license
and configured with 8-14 GB of memory may encounter traffic
disruptions when jumbo frames are enabled. It is recommended to
disable jumbo frames on these lower-end VMs in version 12.1.2 by
executing the command: set system setting jumbo-frame off.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PLUG-19238</b></div>
</td>
<td class="entry relcol">
<div class="p">
Enabling Advanced Routing through bootstrap on VM-Series and Prisma
AIRS is not supported.
</div>
<b class="ph b">Workaround</b>: After the firewall boots up, enable
advanced routing using the CLI command set device-management
general-settings advance-routing yes or enable
<a
class="xref"
href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-networking-admin/advanced-routing/enable-advanced-routing"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>advanced routing</a
>
through the UI.
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">DRS-6556</b></div>
</td>
<td class="entry relcol">
<div class="p">
For Host Compliance Service, while configuring Mappings &amp; Tags in
CIE and when you click on the
<span class="ph uicontrol">HIP Report</span> tab, the following error
message is displayed even when the response is successful:
</div>
<div class="p">
<span class="ph uicontrol">getaddrinfo ENOTFOUND null</span>
</div>
</td>
</tr>
</tbody>
</table>
+797
View File
@@ -0,0 +1,797 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 34%" />
<col style="width: 66%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-313779</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7500 series only</tt>) PA-7500 series firewalls
running PAN-OS 12.1.5 release do not support encryption on HA1 and
HA1-backup interfaces. As a result, attempting to execute the
<span class="ph codeph"
>request high-availability session-reestablish</span
>
command will fail with the following error.
</div>
<div class="p">
<pre
id="panos-known-issues-12.1.6_screen-ilq_djv_h3c"
class="pre screen"
>
ERROR: Encryption is not enabled for HA</pre
>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-313669</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-5500 Series firewalls in cluster configurations only</tt
>) When a firewall node is removed from a PA-5500 Series cluster,
after the cluster commit and reboot, the node starts in standalone
mode with a default virtual wire (vwire) configuration loaded. This
default configuration is missing zone assignments for ports eth1/1 and
eth1/2, which causes commit operations to fail. Even if zones are
manually assigned to these ports, subsequent commit attempts will fail
with a
<span data-outputclass="response" class="ph systemoutput"
>no UUId for rule1</span
>
error.
</div>
<div class="p">
<b class="ph b">Workaround:</b> To resolve this, either:
</div>
<div class="p">
<ul id="panos-known-issues-12.1.6_ul-ybs_j3g_k3c" class="ul">
<li class="li">
Manually assign zone configurations to ports eth1/1 (for example,
untrust) and eth1/2 (for example, trust), then open and close
security policy rule1 without making changes, and
<span class="ph uicontrol">Commit</span>.
</li>
<li class="li">
Delete the default rule and the default virtual wire Ethernet
interfaces, then commit.
</li>
</ul>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-313623</b></div>
</td>
<td class="entry relcol">
<div class="p">
On firewalls with TPM (Trusted Platform Module) support, device
certificate renewals may fail due to a disk partition being full. This
latter occurs because temporary files aren't being deleted during
device certificate status checks.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-312247</b></div>
</td>
<td class="entry relcol">
<div class="p">
In generated PDF upgrade check reports, long remediation URLs might be
truncated due to UI framework export limitations, leaving only the
first line hyperlinked. However, these links remain fully functional
within the Panorama web interface. The PDF link directs to the correct
destination if the complete URL is copied from the PDF and pasted in
the browser.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-309604</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5500 series only</tt>) In some rare cases, the
front panel PSU status LED might show amber, even when the LEDs on the
PSU show green.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-309602</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5500 series only</tt>) When the firewall is
initially powered on, the FAN-0 LED does not turn on. The fan
functions correctly, but the LED doesn't reflect the status.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Remove and reinsert the fan to turn on
the LED.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-308564</b></div>
</td>
<td class="entry relcol">
<div class="p">
Packets are dropped on SD-WAN interfaces if they require fragmentation
for an interface but have the
<span class="ph uicontrol">Don't Fragment (DF)</span> bit set. This
results in unexpected packet drops. This affects client to server
sessions when using SD-WAN for NGFW.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Allow fragmenting packets with DF bit
set (<span class="ph userinput"
>debug dataplane set ip4-ignore-df yes</span
>).
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300850</b></div>
</td>
<td class="entry relcol">
<div class="p">
Manual scheduling of cloud verdicts is required if a new host in an
Host Compliance Service-enabled environment has a refresh event entry
without a corresponding update event entry.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300809</b></div>
</td>
<td class="entry relcol">
<div class="p">
Host Compliance Service connectivity will not work if it is connected
with management IP which is configured with DHCP mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300677</b></div>
</td>
<td class="entry relcol">
<div class="p">
Panorama cannot display Threat log entries (<b class="ph b"
>Monitor &gt; Logs &gt; Threat</b
>) when the managed log collector is running a lower PAN-OS release
than Panorama.
</div>
<div class="p">
Workaround: Upgrade the log collectors to the same version as
Panorama.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300627</b></div>
</td>
<td class="entry relcol">
<div class="p">
AutoCommit fails when the Traffic Object is used on AI Runtime
Security, which consequently impacts the workloads that utilize
overlapping subnets.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300483</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7500 firewall only</tt>) Enabling FIPS-CC mode
causes the firewall to go into maintenance mode.
</div>
<div class="p">
<b class="ph b">Workaround</b>: After the firewall goes into
maintenance mode, perform an additional reboot. The firewall will
successfully start up in FIPS-CC mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300467</b></div>
</td>
<td class="entry relcol">
<div class="p">
WildFire WF-500 appliances running PAN-OS 10.x or PAN-OS 11.x cannot
be managed by Panorama running PAN-OS 12.1.2 due to connectivity
issues.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Upgrade your WildFire appliances to
PAN-OS 12.1.2 or later.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300407</b></div>
</td>
<td class="entry relcol">
<div class="p">
The Release Note URL column in the Panorama &gt; Plugins page is
empty.
</div>
<div class="p">
Release Notes for the plugins are available in the
<a
class="xref"
href="https://docs.paloaltonetworks.com/plugins/vm-series-and-panorama-plugins-release-notes"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>plugins release notes</a
>
or in their individual product release notes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300230</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">NGFW Cluster</tt>) In an NGFW cluster, your pings
to the HSCI-B link might fail, even when the link indicates it is up.
In the event that the HSCI-A link is brought down or unplugged, the
cluster node will transition to failed state, avoiding split brain as
both HSCI links are down in this case.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Reboot the cluster node to resolve the
HSCI-B ping issue.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300192</b></div>
</td>
<td class="entry relcol">
<div class="p">
If the Host Compliance Service is configured with a service route
pointing to an unreachable IP address, the
<span class="ph systemoutput">gp_broker</span> process may stop
working when you enable-disable the Host Compliance Service.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300114</b></div>
</td>
<td class="entry relcol">
<div class="p">
VM entered maintenance mode during a downgrade from version 12.1.2 to
11.2.7, when executed through the CLI.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Download and install the required
version of PAN-OS through the UI instead of the CLI.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300069</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-410 firewall only</tt>) Loading a saved config
file can take up to 5 minutes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300053</b></div>
</td>
<td class="entry relcol">
<div class="p">
When you use the CLI command
<span class="ph userinput">request system fqdn refresh</span> to
trigger another IP address resolution of configured FQDN entries, the
firewall might get into an error state where the DNS Proxy cache
received and stored a new IP address for a particular FQDN entry via
this command. However, the Device-Server (and the Security rule) still
have the old IP address for that FQDN entry.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Avoid using the CLI command:
<span class="ph userinput">request system fqdn refresh</span>. Use the
following command instead (for a particular domain-name or an entire
list):
<span class="ph userinput"
>clear dns-proxy cache all domain-name &lt;domain_name&gt;</span
>. To correct the error state where the DNS Proxy cache and
Device-Server and Security rule are already storing different IP
addresses, use the following CLI command:
<span class="ph userinput"
>debug device-server dump fqdn type resync vsys &lt;vsys_name&gt;
fqdn-name &lt;domain_name&gt;</span
>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300025</b></div>
</td>
<td class="entry relcol">
<div class="p">
If Azure hotplug events occur, the firewall may experience a
<span class="ph userinput">brdagent</span> crash and data interfaces
may transition to an unknown state, leading to traffic disruption.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Reboot the VM if the
<span class="ph userinput">brdagent</span> crash does not trigger a
device reboot.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-299562</b></div>
</td>
<td class="entry relcol">
<div class="p">
SSL proxy sessions fail when clients send a Client Hello with TLSv1.2
and TLSv1.3, and exclusively prefer the secp192 elliptic curve.
</div>
<div class="p">
<b class="ph b">Workaround</b>: To address this, configure a
decryption profile to use TLSv1.2 as the maximum supported TLS
version. Then, apply this profile to the decryption policy rules for
the affected clients and servers. This enables the client to modify
its preferred curves, facilitating successful session establishment.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">PAN-299387</b></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">NGFW Cluster</tt>) When an NGFW cluster has only
one firewall node present and powered up, that node is stuck in
UNKNOWN state after you reboot it and it comes back up. The issue
occurs in two scenarios:
</div>
<ul id="panos-known-issues-12.1.6_ul-pfz_hyt_tgc" class="ul">
<li class="li">
When there is only one node configured in the cluster (no peer is
available or configured).
</li>
<li class="li">
When the peer device in the cluster is completely powered down or
unable to autonegotiate its connected HSCI ports. That is, two nodes
are in the cluster, but only one node is booting up while the other
remains down completely.
</li>
</ul>
<div class="p">
The expected behavior is that if no peer device is available (at a
port autonegotiation or link level for HSCI-A or HSCI-B), then a
cluster device should go to INITIAL state, followed by ONLINE state
(and not remain in UNKNOWN state).
</div>
<div class="p">
<b class="ph b">Workaround</b>: To avoid this issue, connect the
HSCI-A to HSCI-B in loopback to create a link partner.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">PAN-299229</b></td>
<td class="entry relcol">
<div class="p">
On PA-5400 Series and PA-7500 Series firewalls, if you run certain
types of CLI commands during or shortly after a commit, the commands
will time out. The types of CLI commands impacted by this issue are
IoT, Cloud-User-ID, and App-ID Cloud Engine CLI commands.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Don't execute IoT, Cloud-User-ID, or
App-ID Cloud Engine CLI commands during or shortly after a commit on a
PA-5400 Series or PA-7500 Series firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">PAN-299170</b></td>
<td class="entry relcol">
<div class="p">
The remediation link included in the generated PDF of an upgrade check
report might be pruned due to a text length limitation of the export
function. The link remains fully functional and works correctly on the
Panorama web interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">PAN-299114</b></td>
<td class="entry relcol">
<div class="p">
After you enable the
<span class="ph uicontrol"
>Enable Duplicate Logging (Cloud and On-Premise) </span
>setting on a firewall, clicking
<span class="ph uicontrol">Status for Cloud Logging</span>, does not
display the logging service connection status.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">PAN-298540</b></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5500 Series firewalls only</tt>) The
<span class="ph uicontrol">Monitor</span> tab in the Web Interface
does not display a pop-up to indicate that high-speed log forwarding
is enabled and that logs are only viewable from Panorama.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">PAN-298083</b></td>
<td class="entry relcol">
<div class="p">
After you change the system mode on an M-700 appliance from Panorama
mode to PAN-DB private cloud mode, the
<span class="ph codeph">snmpd</span> process fails to work.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">PAN-298047</b></td>
<td class="entry relcol">
<div class="p">
In an AI Runtime Security environment, the Azure Container outbound
traffic does not seem to be functional and the egress traffic is being
misdirected to an incorrect cluster node port.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">PAN-297772</b></td>
<td class="entry relcol">
<div class="p">
When an Intel e810 NIC is configured in SR-IOV mode, sharing Virtual
Functions (VFs) among multiple HSF cluster nodes and subsequently
rebooting a cluster node while traffic is active may result in traffic
disruption on other HSF cluster nodes utilizing the same NIC. It is
recommended to refrain from sharing Intel e810 VFs across cluster
nodes and to allocate one VF per Intel e810 PF.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297114</b></div>
</td>
<td class="entry relcol">
<div class="p">
After successfully generating a health check report for managed
firewalls from Panorama, the progress bar does not appear and the
latest health check reports are not displayed (<span
class="ph uicontrol"
>Panorama &gt; Device Deployment &gt; Upgrade Check</span
>).
</div>
<div class="p">
<b class="ph b">Workaround</b>: Manually refresh the page to see the
latest reports.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-294687</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">NGFW Clusters</tt>) In an NGFW cluster, the leader
can't retrieve the HIP Report from Panorama, nor synchronize it to the
non-leader nodes. Unlike HA Active/Passive mode, both leader and
non-leader nodes receive traffic in cluster mode. If the relevant HIP
Report is missing, policies involving HIP may not work properly. The
expected behavior is that when a non-leader node receives related
traffic, it should request the corresponding HIP Report from the
leader.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-293754</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">NGFW Clusters</tt>) Firewalls in an NGFW cluster
indicate they are in ONLINE state even though their configurations are
different (they aren't synchronized).
</div>
<div class="p">
<b class="ph b">Workaround</b>: Push the configuration from Panorama
to all cluster members at the same time; don't push to an individual
firewall. If a cluster member isn't connected to Panorama during the
push, the push will fail to the disconnected firewall, but will
succeed to all connected firewalls.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-293718</b></div>
</td>
<td class="entry relcol">
<div class="p">
When high speed logging is enabled on a PA-5560 device, the expected
warning message is not displayed on the web interface. This prevents
administrators from being notified that logs can only be viewed from
Panorama.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-292601</b></div>
</td>
<td class="entry relcol">
<div class="p">
PAN-OS 12.1.2 and later 12.1 releases support a Load Balanced DNS
configuration for an address object. If there are two address objects
with same FQDN, but one object has Load Balanced DNS enabled and other
object has Load Balanced DNS disabled, then the policy match for the
removed IP addresses doesn't work as expected.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Enable (or disable) Load Balanced DNS
consistently for an FQDN that is used with multiple address objects.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-290692</b></div>
</td>
<td class="entry relcol">
<div class="p">
In Host Compliance Service, when you create a 'Shared' type Host
Compliance Object for the 'Disk-Encryption' category, the State
drop-down is automatically selected and cannot be edited. However, you
can change the state later by editing the object, if required.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-289524</b></div>
</td>
<td class="entry relcol">
<div class="p">
In PAN-OS 12.1.2 and later 12.1 releases, PAN-OS can obtain resolved
IP addresses from a Load balanced DNS server and use them in a policy
match. However, this functionality does not work as intended when the
DNS cache reuse flag is enabled. When the DNS cache reuse flag is
enabled, the DNS resolution works as if the Load balanced DNS flag
(for an Address object) is disabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286496</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">NGFW Clusters</tt>) URL-continue and override
continue selections will function like a general URL-block action.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-283429</b></div>
</td>
<td class="entry relcol">
<div class="p">
When you use custom certificates for the connection between Panorama
and a log collector, the automated renewal for the predefined
ElasticSearch certificates gets disrupted.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Remove the custom certificates before
the ElasticSearch certificates expire. This allows the system to
correctly identify and renew the predefined ElasticSearch
certificates. After the renewal is complete, re-install the custom
certificates.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-237106</b></div>
</td>
<td class="entry relcol">
<div class="p">
LSVPN satellite certificates may be generated with serial numbers
exceeding 40 hexadecimal characters. This causes certificate
revocation and deletion operations to fail with the following error
messages:
</div>
<ul id="panos-known-issues-12.1.6_ul-t2x_dxs_wgc" class="ul">
<li class="li">
<span class="ph systemoutput"
>db-serialno can be at most 40 characters</span
>
</li>
<li class="li">
<span class="ph systemoutput">db-serialno is invalid</span>
</li>
</ul>
<b class="ph b">Workaround:</b>
<div class="p">
To resolve this issue, use the following CLI commands with the LSVPN
satellite serial number to manually delete or revoke the affected
certificates:
</div>
<div class="p">
<b class="ph b">Delete certificate information</b>:<span
class="ph userinput"
>delete sslmgr-store certificate-info portal name
<var class="keyword varname">&lt;name&gt;</var> serialno
<var class="keyword varname">&lt;satellite_serial&gt;</var></span
>
</div>
<div class="p">
<b class="ph b">Revoke satellite certificates</b>:<span
class="ph userinput"
>delete sslmgr-store satellite-info-revoke-certificate portal
<var class="keyword varname">&lt;name&gt;</var> serialno
<var class="keyword varname"
>&lt;list_of_satellite_serials&gt;</var
></span
>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PLUG-21065</b></div>
</td>
<td class="entry relcol">
<div dir="ltr" class="p">
In a PA-VM or AI Runtime Security environment, it is observed that the
Software Firewall Orchestration plugin deployed with a VM-Flex license
and configured with 8-14 GB of memory may encounter traffic
disruptions when jumbo frames are enabled. It is recommended to
disable jumbo frames on these lower-end VMs in version 12.1.2 by
executing the command: set system setting jumbo-frame off.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PLUG-19238</b></div>
</td>
<td class="entry relcol">
<div class="p">
Enabling Advanced Routing through bootstrap on VM-Series and Prisma
AIRS is not supported.
</div>
<b class="ph b">Workaround</b>: After the firewall boots up, enable
advanced routing using the CLI command set device-management
general-settings advance-routing yes or enable
<a
class="xref"
href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-networking-admin/advanced-routing/enable-advanced-routing"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>advanced routing</a
>
through the UI.
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">DRS-6556</b></div>
</td>
<td class="entry relcol">
<div class="p">
For Host Compliance Service, while configuring Mappings &amp; Tags in
CIE and when you click on the
<span class="ph uicontrol">HIP Report</span> tab, the following error
message is displayed even when the response is successful:
</div>
<div class="p">
<span class="ph uicontrol">getaddrinfo ENOTFOUND null</span>
</div>
</td>
</tr>
</tbody>
</table>
+135
View File
@@ -0,0 +1,135 @@
#!/usr/bin/env node
/**
* Convert downloaded issue table HTML files into web/data/issues/ markdown files.
*
* Usage:
* node process_issues.mjs [--crawl CC-MAIN-2026-12] [--product PAN-OS] [--date YYYY-MM-DD]
*
* After this script, run:
* python scripts/update_products_from_issues.py
*/
import { JSDOM } from 'jsdom';
import { readFileSync, writeFileSync, mkdirSync, readdirSync } from 'node:fs';
import { join } from 'node:path';
import { fileURLToPath } from 'node:url';
import { parseArgs } from 'node:util';
const __dirname = fileURLToPath(new URL('.', import.meta.url));
const { values: args } = parseArgs({
options: {
crawl: { type: 'string', default: 'CC-MAIN-2026-12' },
product: { type: 'string', default: 'PAN-OS' },
date: { type: 'string' },
},
strict: false,
});
function isoWeekStartDate(year, week) {
const jan4 = new Date(Date.UTC(year, 0, 4));
const jan4Day = jan4.getUTCDay() || 7;
const week1Monday = new Date(jan4);
week1Monday.setUTCDate(jan4.getUTCDate() - (jan4Day - 1));
const target = new Date(week1Monday);
target.setUTCDate(week1Monday.getUTCDate() + (week - 1) * 7);
return target.toISOString().slice(0, 10);
}
function dateFromCrawlId(crawlId) {
const match = /^CC-MAIN-(\d{4})-(\d{2})$/i.exec(String(crawlId || '').trim());
if (!match) {
return null;
}
const year = Number(match[1]);
const week = Number(match[2]);
if (!Number.isInteger(year) || !Number.isInteger(week) || week < 1 || week > 53) {
return null;
}
return isoWeekStartDate(year, week);
}
const inferredDate = dateFromCrawlId(args.crawl);
const outputDate = args.date || inferredDate || new Date().toISOString().slice(0, 10);
// Set up DOMParser global before importing modules that rely on it.
const { window } = new JSDOM('<!doctype html><html><body></body></html>');
globalThis.DOMParser = window.DOMParser;
const { parseIssuesFromHtmlTable } = await import(
new URL('../../web/js/process.js', import.meta.url).href
);
const { buildIssueMarkdownDocument } = await import(
new URL('../../web/js/markdown.js', import.meta.url).href
);
const REPO_ROOT = join(__dirname, '..', '..');
const dataDir = join(__dirname, '..', 'data', args.crawl, args.product);
let files;
try {
files = readdirSync(dataDir).filter(f => f.endsWith('.html'));
} catch {
console.error(`No data directory found: ${dataDir}`);
console.error('Run crawl_cc.py first to download issue tables.');
process.exit(1);
}
if (files.length === 0) {
console.log(`No HTML files found in ${dataDir}`);
process.exit(0);
}
let writtenCount = 0;
for (const file of files.sort()) {
// Filename format: {version}-{type}.html
// where type is 'addressed' or 'known'.
// Version may itself contain hyphens (e.g. '10.2.1-h3'), so split on
// the *last* hyphen-prefixed token that is a known issue type.
const baseName = file.replace(/\.html$/, '');
const lastDash = baseName.lastIndexOf('-');
if (lastDash === -1) {
console.warn(`Skipping unexpected filename: ${file}`);
continue;
}
const version = baseName.slice(0, lastDash);
const issueType = baseName.slice(lastDash + 1);
if (issueType !== 'addressed' && issueType !== 'known') {
console.warn(`Skipping unexpected issue type in filename: ${file}`);
continue;
}
const capitalizedType = issueType.charAt(0).toUpperCase() + issueType.slice(1);
const html = readFileSync(join(dataDir, file), 'utf-8');
const parsedIssues = parseIssuesFromHtmlTable(html, { type: capitalizedType });
if (parsedIssues.length === 0) {
console.warn(`No issues parsed from ${file} — skipping`);
continue;
}
const markdown = buildIssueMarkdownDocument({
type: capitalizedType,
product: args.product,
version,
issues: parsedIssues,
metadata: {
source: 'common-crawl',
crawl: args.crawl,
},
});
const outDir = join(REPO_ROOT, 'web', 'data', 'issues', args.product, issueType);
mkdirSync(outDir, { recursive: true });
const outFile = join(outDir, `${version}_${outputDate}.md`);
writeFileSync(outFile, markdown, 'utf-8');
writtenCount++;
}
console.log(`Wrote ${writtenCount} markdown file(s) to web/data/issues/${args.product}/`);
if (writtenCount > 0) {
console.log('Next step: python scripts/update_products_from_issues.py');
}