Discard the crawler, manually collect reference material for processing
This commit is contained in:
@@ -0,0 +1,140 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-242777</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where users previously reported limitations due to
|
||||
session count caps when utilizing
|
||||
<b class="ph b">Web Proxy</b> features on PA-5400 Series Firewalls. To
|
||||
address these performance complaints and support higher traffic
|
||||
volumes, we have increased the maximum session capacity on specific
|
||||
<b class="ph b">PA-5400F</b> series platforms, leveraging available
|
||||
system memory. This update ensures greater capacity and stability for
|
||||
high-volume environments.
|
||||
</div>
|
||||
<div class="p">
|
||||
The supported session limits are:
|
||||
|
||||
<div style="display: inline"></div>
|
||||
<div style="display: inline"></div>
|
||||
<div style="display: inline"></div>
|
||||
<div style="display: inline"></div>
|
||||
<div style="display: inline"></div>
|
||||
<div style="display: inline"></div>
|
||||
<div style="display: inline"></div>
|
||||
<div style="display: inline"></div>
|
||||
<div style="display: inline"></div>
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 50%" />
|
||||
<col style="width: 50%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row">
|
||||
<th class="entry">Platform</th>
|
||||
<th class="entry">Max Sessions</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">PA-5410</td>
|
||||
<td class="entry relcol">95K</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PA-5420</td>
|
||||
<td class="entry relcol">95K</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PA-5430</td>
|
||||
<td class="entry relcol">95K</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PA-5440</td>
|
||||
<td class="entry relcol">225K</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PA-5445</td>
|
||||
<td class="entry relcol">250K</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PA-5450</td>
|
||||
<td class="entry relcol">1.28M</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-291499</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>VM-Series firewalls on Amazon Web Services (AWS) environments
|
||||
only</tt
|
||||
>) Fixed an issue where newly deployed firewalls were unable to
|
||||
connect to the Strata Logging Service (SLS) until after a reboot,
|
||||
license fetch, or management server restart.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-288726</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<span class="keyword cmdname">useridd</span> process stopped
|
||||
responding due to a Security policy rule ID being set to 0, which
|
||||
caused the last configuration retrieval to fail.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-287133</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the Panorama web interface where assigning a policy
|
||||
rule to a group at the top or bottom of the list changed the order of
|
||||
other policy rules.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,34 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-304195</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the firewall where performing a private data reset
|
||||
caused device telemetry to stop working. This issue also occurred
|
||||
after performing a factory reset and then running the CLI command
|
||||
<span class="ph systemoutput">set system ztp disable</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,90 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">—</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
A fix was made to address
|
||||
<a
|
||||
class="xref"
|
||||
href="https://security.paloaltonetworks.com/CVE-2026-0227"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>CVE-2026-0227</a
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-306534</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue were the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>all_task</a
|
||||
>
|
||||
process repeatedly restarted due to memory pool corruption when
|
||||
processing fragmented DNS over HTTPs (DoH) JSON queries. This occurred
|
||||
due to incorrect buffer length calculations during memory deallocation
|
||||
when the query name field spanned multiple packets.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-305480</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>pan_task</a
|
||||
>
|
||||
process stopped responding while processing DoH JSON format traffic
|
||||
with DoH Security enabled, which caused missing cross-packet bytes in
|
||||
the decoded DNS query type field, and the dataplane went down.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,180 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300334</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the ADEM plugin was not compatible with PAN-OS
|
||||
12.1.2, which prevented installation of the plugin and disabled the
|
||||
ability to monitor remote sites on firewalls using the ADEM
|
||||
functionality.
|
||||
</div>
|
||||
<div class="p">
|
||||
To use this fix, you need the following compatible versions: ADEM
|
||||
1.1.0-h3 and SD-WAN plugin 3.4.0.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-298241</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the NAT IP address pool was exhausted, which led
|
||||
to intermittent connectivity issues with call applications and
|
||||
outbound call failures. This occurred due to the firewall not properly
|
||||
releasing NAT dynamic ports back to the address pool.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-296490</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">FIPS CC mode enabled only</tt>) Fixed an issue
|
||||
where Panorama on GCP rebooted every hour after upgrading to
|
||||
11.1.6-h10.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-289249</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a memory leak occurred on the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>reportd</a
|
||||
>
|
||||
process when a WildFire update was initiated while device telemetry
|
||||
data collection was in progress. This resulted in an OOM condition.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-286576</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>all_pktproc</a
|
||||
>
|
||||
process restarted, which caused heartbeat failures to occur and a slot
|
||||
to go down due to path monitor failure.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-272245</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>dnsproxy</a
|
||||
>
|
||||
process crashed due to memory corruption caused by a race condition
|
||||
when the allow list downloading was impacted by config change.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-267450</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>reportd</a
|
||||
>
|
||||
process stopped responding with a SIGSEGV at
|
||||
<span class="ph systemoutput">schedule_report_es_response</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-262831</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-5400f Series firewalls only</tt>) Fixed an
|
||||
intermittent issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>all_task</a
|
||||
>
|
||||
process stopped responding, which caused the firewall to restart.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,77 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-311938</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where autocommits failed after an upgrade due to
|
||||
configuration memory allocation issues and 100% policy rule cache
|
||||
usage when both DNS Rewrite and URL Custom Category Match were
|
||||
configured.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-306451</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">VM-Series firewalls on AWS environments only</tt>)
|
||||
Fixed an issue where, after upgrading the firewall to an affected
|
||||
release, GlobalProtect clients did not connect with IPSec and instead
|
||||
connected using SSL due to traffic flow being disabled when checking
|
||||
for health check packets.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-304496</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after unregistering an IP tag and registering a
|
||||
different IP tag for the same IP address via XML API, the dynamic
|
||||
address group membership was not updated on the dataplane, which
|
||||
resulted in Security policy rules being enforced incorrectly.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-304195</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the firewall where performing a private data reset
|
||||
caused device telemetry to stop working. This issue also occurred
|
||||
after performing a factory reset and then running the CLI command
|
||||
<span class="ph systemoutput">set system ztp disable</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,59 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-313572</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
||||
the dataplane restarted due to a segmentation fault.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300664</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the Panorama and firewall web interface where
|
||||
Applications pages became unresponsive after activating the SaaS
|
||||
Inline license.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-292447</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where Panorama did not display data in the
|
||||
<span class="ph uicontrol">Feature Adoption</span> tab in Strata Cloud
|
||||
Manager due to the system creating and deleting a CLI user for each
|
||||
interval instead of reusing a permanent CLI user for telemetry.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,623 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">—</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
A fix was made to address
|
||||
<a
|
||||
class="xref"
|
||||
href="https://security.paloaltonetworks.com/CVE-2026-0227"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>CVE-2026-0227</a
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-305480</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>pan_task</a
|
||||
>
|
||||
process stopped responding while processing DoH JSON format traffic
|
||||
with DoH Security enabled, which caused missing cross-packet bytes in
|
||||
the decoded DNS query type field, and the dataplane went down.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-305151</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the configuration was not updated on the AI
|
||||
Firewall in AWS after a successful configuration push from Strata
|
||||
Cloud Manager (SCM).
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-304195</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the firewall where performing a private data reset
|
||||
caused device telemetry to stop working. This issue also occurred
|
||||
after performing a factory reset and then running the CLI command
|
||||
<span class="ph systemoutput">set system ztp disable</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-304075</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall did not detect evasions due to TCP
|
||||
checksum offloading not being enabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-303836</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Resolved an issue in which intermittent session-table resets on the
|
||||
AIRS VM triggered packet drops, leading to packet loss in egress
|
||||
response traffic
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-303700</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where GlobalProtect users were incorrectly dropped by
|
||||
the default Security policy rule after upgrading to PAN-OS 12.1.2 when
|
||||
IPv6 firewalling was disabled. This occurred due to policy rules
|
||||
configured with geographic regions matching traffic incorrectly.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-303559</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after manuallly creating a device telemetry
|
||||
bundle, the
|
||||
<span class="ph systemoutput">hour_cli_output.txt</span> file within
|
||||
the bundle had a file size of 0 bytes. This occurred when checking the
|
||||
bundle content after enabling device telemetry and setting the device
|
||||
telemetry upload endpoint.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-302908</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall did not forward STP frames on Layer
|
||||
2 VLAN interfaces, which prevented the construction of loop-free
|
||||
topologies with connected switches.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-301801</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Log Collectors where the Elasticsearch process
|
||||
fluctuated intermittently between green and red states, which led to
|
||||
interruptions in log collection. This issue occurred when the number
|
||||
of shards exceeded the cluster's maximum supported threshold of
|
||||
greater than 1000 shards per Elasticsearch instance.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-301496</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the DNS cache capacity was insufficient for
|
||||
environments with a large number of FQDN address objects, which caused
|
||||
the firewall to repeatedly send DNS requests for the same FQDN objects
|
||||
even after it received valid responses.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300837</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where firewalls experienced multiple reboots due to the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>pan_task</a
|
||||
>
|
||||
process restarting with a SIGSEGV signal. This occurred because the
|
||||
client-to-firewall side assumed TLS 1.3 for the firewall-server side.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300372</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">Panorama virtual appliances only</tt>) Fixed an
|
||||
issue where maintenance mode was not accessible to do Factory Reset or
|
||||
switch to FIPSCC mode.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300096</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a local commit on a firewall breaks template
|
||||
stack overrides, preventing the enabling of LACP (Link Aggregation
|
||||
Control Protocol). After a local commit, the LACP enable check was
|
||||
unexpectedly unchecked, causing an outage. Attempting to re-enable
|
||||
LACP through the web interface was unsuccessful, requiring manual
|
||||
removal of the LACP configuration from the Panorama CLI.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-299815</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on multi-vsys firewalls where a host was not removed
|
||||
from the quarantine list after receiving a redistribution message from
|
||||
Panorama. This occurred when Panorama was configured to redistribute
|
||||
quarantine messages to a firewall cluster, and the GlobalProtect
|
||||
configuration and redistribution were built out in a vsys other than
|
||||
vsys1.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-299678</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall repeatedly rebooted when downgrading
|
||||
to an affected release.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-299193</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the firewall where, after upgrading, autocommits
|
||||
repeatedly failed until after a second reboot due to a timing issue
|
||||
between content loading on the management plane card (MPC) and the log
|
||||
receiver startup.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-298684</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where an Application Override policy rule was not
|
||||
applied using an IPv4 source IP address with IPv6 enabled and
|
||||
<span class="ph uicontrol">Network</span> >
|
||||
<span class="ph uicontrol">Zones</span> >
|
||||
<span class="ph uicontrol">Pre-NAT Identification</span> enabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-298654</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall generated false positive threat logs
|
||||
during updates to a large domain list (EDL) when a DNS lookup for a
|
||||
domain being added or removed occurred during the update process. This
|
||||
resulted in a threat log being generated for a different, unrelated
|
||||
domain that remained on the list.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-298514</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where WildFire clusters operating in FIPS-CC mode were
|
||||
not supported in earlier PAN-OS 12.1 releases.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-297972</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a dataplane crash occurred when traffic matched
|
||||
Inline Cloud Analysis prefiltering signatures, even when Inline Cloud
|
||||
Analysis features were not enabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-297797</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, during a refresh of a large External Dynamic
|
||||
List (EDL), traffic that matched a domain on the list was incorrectly
|
||||
identified as a different domain, which resulted in false positive
|
||||
threat logs.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-297708</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a long-lived session with many Machine Learning
|
||||
(ML) model triggers caused a memory leak of feature states associated
|
||||
with the ML model runs. This resulted in Spyware_State failure
|
||||
increases, allocation max outs, and impaired policy matching.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-297005</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where exporting custom reports resulted in empty CSV
|
||||
files.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-296635</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>reportd</a
|
||||
>
|
||||
process on passive Panorama management servers leaked memory due to
|
||||
scheduled report handling from the Strata Logging Service (SLS). This
|
||||
memory leak occurred daily, consuming available memory until the
|
||||
process was restarted.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-296478</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after upgrading to PAN-OS 10.2.13-h10,
|
||||
GlobalProtect Clientless VPN on PA-3250 firewalls failed to execute
|
||||
JavaScript links, resulting in an authorization error. This occurred
|
||||
because the firewall was incorrectly injecting text into URLs when
|
||||
JavaScript buttons or dropdown menus were clicked within the
|
||||
Clientless VPN portal.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-296453</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where decryption exclusion lists were not working for
|
||||
untrusted certificates, and SSL sessions were still being decrypted
|
||||
even after adding them to the exclusion list. This occurred because
|
||||
the firewall was not adding sessions to the exclude cache until after
|
||||
receiving a non-RFC alert (BadCertificate) from the server. The fix
|
||||
ensures that the first session is added to the exclude cache, allowing
|
||||
subsequent sessions to skip decryption. This issue affects firewalls
|
||||
configured as clients in server-client communication.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-296202</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>Firewalls in active/active HA configurations only</tt
|
||||
>) Fixed an issue where, when a commit operation was in progress,
|
||||
newly deployed IP address tags that used the XML API were not
|
||||
immediately reflected in address group resolution, which delayed IP
|
||||
address mapping to address groups and caused traffic to be incorrectly
|
||||
allowed or denied.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-295221</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after upgrading Panorama and Log Collectors from
|
||||
PAN-OS 10.2.9 to PAN-OS 11.1.6-h6, Traffic and Threat logs were not
|
||||
forwarded to a Splunk server over UDP.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-292393</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where TFTP file transfers intermittently timed out in
|
||||
active-active HA pairs when the TFTP control channel was processed by
|
||||
one firewall and the data channel was processed by the other. This
|
||||
occurred because the firewall receiving the data channel failed to
|
||||
match the predicted session due to asynchronous processing of HA
|
||||
messages.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-291716</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where during a commit, the firewall experienced an
|
||||
out-of-memory (OOM) condition due to a memory leak and displayed an
|
||||
error message. This issue caused the device to stop responding and
|
||||
reboot unexpectedly.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-291661</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama appliances and Log Collectors where, after
|
||||
an upgrade, Elasticsearch intermittently entered into a Red state
|
||||
before automatically recovering.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-290665</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue with firewalls enabled with Security profiles where
|
||||
certain traffic conditions caused high dataplane CPU utilization and
|
||||
packet buffer exhaustion, which caused LACP flapping conditions.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-290640</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>VM-Series firewalls on Microsoft Azure environments in HA
|
||||
configurations only</tt
|
||||
>) Fixed an issue where, when an interface was configured with IPv6,
|
||||
the firewall displayed the message
|
||||
<span class="ph uicontrol">Unknown error</span> during validation
|
||||
after the client secret expired, which caused DNS resolution to fail
|
||||
when resolving FQDNs and HA failovers to occur.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-290453</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where PA-7500 firewalls experienced silent traffic
|
||||
drops. During migration from PA-7050 to PA-7500 firewalls connected in
|
||||
series, intermittent connection losses occurred for some applications.
|
||||
Traffic leaving the PA-7050 was not received or processed by the
|
||||
PA-7500, even with direct connections and replaced cables/SFPs. Global
|
||||
counters did not indicate any drops on the PA-7500.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-288598</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where Panorama exported the serial number of a managed
|
||||
collector instead of the collector name when exporting a PDF or CSV
|
||||
file.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-287387</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where API jobs failed with the error
|
||||
message
|
||||
<span class="ph systemoutput"
|
||||
>Server error: Timed out while getting config lock</span
|
||||
>. This occurred due to slow set request performance when setting a
|
||||
large number of address objects in a single set call.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-282640</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where custom reports showed incomplete data when
|
||||
exported in CSV format from Panorama.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-274333</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the Logging Service License Status displayed as
|
||||
red even though a valid license was installed on the firewall.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-262353</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, when Panorama was upgraded but log collectors
|
||||
were on an earlier version, logs from a log collector group were not
|
||||
viewable on a Panorama.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,198 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-316911</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>VM-Series firewalls on Amazon Web Services (AWS) environments
|
||||
only</tt
|
||||
>) Fixed an issue where a newly bootstrapped firewall required a
|
||||
management server restart, relicensing, or license push from Panorama
|
||||
to invoke the device certificate.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-314201</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on PAN-OS 12.1 releases where intermittent traffic
|
||||
drops occurred over IPSec VPN tunnels to third-party firewalls during
|
||||
the IPSec rekey due to the firewall failing to inform the peer to
|
||||
delete the old SA after moving to the new one.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-313216</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where firewalls with Prisma Access incorrectly
|
||||
displayed some traffic as unsanctioned in traffic logs for cloud
|
||||
applications that were tagged as
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>sanctioned</a
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-311512</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where HIP (Host Information Profile) reports were
|
||||
blocked on GlobalProtect when
|
||||
<span class="ph uicontrol"
|
||||
>Authentication Cookie Usage Restrictions</span
|
||||
>
|
||||
was enabled and the Prisma Access Agent protocol was in use. This
|
||||
occurred because the system failed to correctly process HIP messages
|
||||
that were relayed via IPSec tunnels with a Virtual IP as the source,
|
||||
leading to their rejection.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-311412</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<span class="ph systemoutput">show advanced-routing resource</span>
|
||||
CLI command failed to execute successfully when invoked through the
|
||||
XML API and returned an error message.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-311261</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall generated duplicate URL Filtering
|
||||
logs due to an error condition when the new XFF feature was
|
||||
enabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-311250</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">Panorama appliances and Log Collectors only</tt>)
|
||||
Fixed an issue where logs from multiple devices were not visible on
|
||||
Panorama even though the Elasticsearch health status on the dedicated
|
||||
Log Collectors appeared green.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-310362</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where IPv6 Routed HA did not function correctly when
|
||||
the HA1 (control link) was configured with an IPv6 routed connection.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-310240</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where software packet buffers were completely utilized
|
||||
when performing a Data Loss Prevention longevity test.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308507</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">Panorama managed firewalls only</tt>) Fixed an
|
||||
issue where the firewall intermittently failed to maintain active log
|
||||
forwarding streams to Strata Logging Service (SLS) even when duplicate
|
||||
logging and enhanced application logging were enabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308418</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, when Advanced DNS Security was enabled and
|
||||
experienced unusually high loads, DNS resolution failures occurred
|
||||
with the error
|
||||
<span class="ph uicontrol">resources-unavailable</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308261</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall failed to send SNMPv3 traps when the
|
||||
SNMP destination was configured with an FQDN that resolved to multiple
|
||||
IP address through DNS load balancing.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,876 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 34%" />
|
||||
<col style="width: 66%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-314201</b></div>
|
||||
<div class="p">
|
||||
<tt class="ph tt">This issue is now resolved. See </tt
|
||||
><a
|
||||
class="xref"
|
||||
href="/content/techdocs/en_US/ngfw/release-notes/12-1/pan-os-12-1-6-known-and-addressed-issues/pan-os-12-1-6-addressed-issues.html"
|
||||
title=""
|
||||
data-scope="local"
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>PAN-OS 12.1.6 Addressed Issues</a
|
||||
>
|
||||
</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
On firewalls running PAN-OS 12.1, IPsec VPN tunnels to third-party
|
||||
peer devices may experience intermittent traffic loss during rekey
|
||||
operations. When a new Security Association (SA) forms before the old
|
||||
SA expires, traffic may stop flowing until the older SA naturally
|
||||
expires or you manually clear it. During this time, the output of show
|
||||
vpn ipsec-sa may show two SAs for the same proxy ID. This issue
|
||||
primarily affects tunnels to third-party peer devices and does not
|
||||
occur with Palo Alto Networks to Palo Alto Networks tunnels.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Manually clear the affected Security
|
||||
Association using the command
|
||||
<span class="ph userinput"
|
||||
>clear vpn ipsec-sa tunnel <tunnel-name></span
|
||||
>
|
||||
to restore connectivity.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-313779</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-7500 series only</tt>) PA-7500 series firewalls
|
||||
running PAN-OS 12.1.5 release do not support encryption on HA1 and
|
||||
HA1-backup interfaces. As a result, attempting to execute the
|
||||
<span class="ph codeph"
|
||||
>request high-availability session-reestablish</span
|
||||
>
|
||||
command will fail with the following error.
|
||||
</div>
|
||||
<div class="p">
|
||||
<pre
|
||||
id="panos-known-issues-12.1.5_screen-ilq_djv_h3c"
|
||||
class="pre screen"
|
||||
>
|
||||
ERROR: Encryption is not enabled for HA</pre
|
||||
>
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-313669</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>PA-5500 Series firewalls in cluster configurations only</tt
|
||||
>) When a firewall node is removed from a PA-5500 Series cluster,
|
||||
after the cluster commit and reboot, the node starts in standalone
|
||||
mode with a default virtual wire (vwire) configuration loaded. This
|
||||
default configuration is missing zone assignments for ports eth1/1 and
|
||||
eth1/2, which causes commit operations to fail. Even if zones are
|
||||
manually assigned to these ports, subsequent commit attempts will fail
|
||||
with a
|
||||
<span data-outputclass="response" class="ph systemoutput"
|
||||
>no UUId for rule1</span
|
||||
>
|
||||
error.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> To resolve this, either:
|
||||
</div>
|
||||
<div class="p">
|
||||
<ul id="panos-known-issues-12.1.5_ul-ybs_j3g_k3c" class="ul">
|
||||
<li class="li">
|
||||
Manually assign zone configurations to ports eth1/1 (for example,
|
||||
untrust) and eth1/2 (for example, trust), then open and close
|
||||
security policy rule1 without making changes, and
|
||||
<span class="ph uicontrol">Commit</span>.
|
||||
</li>
|
||||
<li class="li">
|
||||
Delete the default rule and the default virtual wire Ethernet
|
||||
interfaces, then commit.
|
||||
</li>
|
||||
</ul>
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-313623</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
On firewalls with TPM (Trusted Platform Module) support, device
|
||||
certificate renewals may fail due to a disk partition being full. This
|
||||
latter occurs because temporary files aren't being deleted during
|
||||
device certificate status checks.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-312247</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
In generated PDF upgrade check reports, long remediation URLs might be
|
||||
truncated due to UI framework export limitations, leaving only the
|
||||
first line hyperlinked. However, these links remain fully functional
|
||||
within the Panorama web interface. The PDF link directs to the correct
|
||||
destination if the complete URL is copied from the PDF and pasted in
|
||||
the browser.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-309604</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-5500 series only</tt>) In some rare cases, the
|
||||
front panel PSU status LED might show amber, even when the LEDs on the
|
||||
PSU show green.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-309602</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-5500 series only</tt>) When the firewall is
|
||||
initially powered on, the FAN-0 LED does not turn on. The fan
|
||||
functions correctly, but the LED doesn't reflect the status.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Remove and reinsert the fan to turn on
|
||||
the LED.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308564</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Packets are dropped on SD-WAN interfaces if they require fragmentation
|
||||
for an interface but have the
|
||||
<span class="ph uicontrol">Don't Fragment (DF)</span> bit set. This
|
||||
results in unexpected packet drops. This affects client to server
|
||||
sessions when using SD-WAN for NGFW.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Allow fragmenting packets with DF bit
|
||||
set (<span class="ph userinput"
|
||||
>debug dataplane set ip4-ignore-df yes</span
|
||||
>).
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308507</b></div>
|
||||
<div class="p">
|
||||
<tt class="ph tt">This issue is now resolved. See </tt
|
||||
><a
|
||||
class="xref"
|
||||
href="/content/techdocs/en_US/ngfw/release-notes/12-1/pan-os-12-1-6-known-and-addressed-issues/pan-os-12-1-6-addressed-issues.html"
|
||||
title=""
|
||||
data-scope="local"
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>PAN-OS 12.1.6 Addressed Issues</a
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Strata Logging Service (SLS) log-forwarding streams intermittently
|
||||
show as inactive. When checking the status of log-forwarding
|
||||
connections, one or more streams are reported as inactive. Restarting
|
||||
the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>log-receiver</a
|
||||
>
|
||||
process temporarily resolves the issue, but the streams become
|
||||
inactive again after approximately 1-2 hours. This intermittent
|
||||
inactivity results in log loss.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300850</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Manual scheduling of cloud verdicts is required if a new host in an
|
||||
Host Compliance Service-enabled environment has a refresh event entry
|
||||
without a corresponding update event entry.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300809</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Host Compliance Service connectivity will not work if it is connected
|
||||
with management IP which is configured with DHCP mode.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300677</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Panorama cannot display Threat log entries (<b class="ph b"
|
||||
>Monitor > Logs > Threat</b
|
||||
>) when the managed log collector is running a lower PAN-OS release
|
||||
than Panorama.
|
||||
</div>
|
||||
<div class="p">
|
||||
Workaround: Upgrade the log collectors to the same version as
|
||||
Panorama.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300627</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
AutoCommit fails when the Traffic Object is used on AI Runtime
|
||||
Security, which consequently impacts the workloads that utilize
|
||||
overlapping subnets.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300483</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-7500 firewall only</tt>) Enabling FIPS-CC mode
|
||||
causes the firewall to go into maintenance mode.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: After the firewall goes into
|
||||
maintenance mode, perform an additional reboot. The firewall will
|
||||
successfully start up in FIPS-CC mode.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300467</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
WildFire WF-500 appliances running PAN-OS 10.x or PAN-OS 11.x cannot
|
||||
be managed by Panorama running PAN-OS 12.1.2 due to connectivity
|
||||
issues.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Upgrade your WildFire appliances to
|
||||
PAN-OS 12.1.2 or later.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300407</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The Release Note URL column in the Panorama > Plugins page is
|
||||
empty.
|
||||
</div>
|
||||
<div class="p">
|
||||
Release Notes for the plugins are available in the
|
||||
<a
|
||||
class="xref"
|
||||
href="https://docs.paloaltonetworks.com/plugins/vm-series-and-panorama-plugins-release-notes"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>plugins release notes</a
|
||||
>
|
||||
or in their individual product release notes.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300230</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">NGFW Cluster</tt>) In an NGFW cluster, your pings
|
||||
to the HSCI-B link might fail, even when the link indicates it is up.
|
||||
In the event that the HSCI-A link is brought down or unplugged, the
|
||||
cluster node will transition to failed state, avoiding split brain as
|
||||
both HSCI links are down in this case.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Reboot the cluster node to resolve the
|
||||
HSCI-B ping issue.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300192</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
If the Host Compliance Service is configured with a service route
|
||||
pointing to an unreachable IP address, the
|
||||
<span class="ph systemoutput">gp_broker</span> process may stop
|
||||
working when you enable-disable the Host Compliance Service.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300114</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
VM entered maintenance mode during a downgrade from version 12.1.2 to
|
||||
11.2.7, when executed through the CLI.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Download and install the required
|
||||
version of PAN-OS through the UI instead of the CLI.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300069</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-410 firewall only</tt>) Loading a saved config
|
||||
file can take up to 5 minutes.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300053</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When you use the CLI command
|
||||
<span class="ph userinput">request system fqdn refresh</span> to
|
||||
trigger another IP address resolution of configured FQDN entries, the
|
||||
firewall might get into an error state where the DNS Proxy cache
|
||||
received and stored a new IP address for a particular FQDN entry via
|
||||
this command. However, the Device-Server (and the Security rule) still
|
||||
have the old IP address for that FQDN entry.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Avoid using the CLI command:
|
||||
<span class="ph userinput">request system fqdn refresh</span>. Use the
|
||||
following command instead (for a particular domain-name or an entire
|
||||
list):
|
||||
<span class="ph userinput"
|
||||
>clear dns-proxy cache all domain-name <domain_name></span
|
||||
>. To correct the error state where the DNS Proxy cache and
|
||||
Device-Server and Security rule are already storing different IP
|
||||
addresses, use the following CLI command:
|
||||
<span class="ph userinput"
|
||||
>debug device-server dump fqdn type resync vsys <vsys_name>
|
||||
fqdn-name <domain_name></span
|
||||
>
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300025</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
If Azure hotplug events occur, the firewall may experience a
|
||||
<span class="ph userinput">brdagent</span> crash and data interfaces
|
||||
may transition to an unknown state, leading to traffic disruption.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Reboot the VM if the
|
||||
<span class="ph userinput">brdagent</span> crash does not trigger a
|
||||
device reboot.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-299562</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
SSL proxy sessions fail when clients send a Client Hello with TLSv1.2
|
||||
and TLSv1.3, and exclusively prefer the secp192 elliptic curve.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: To address this, configure a
|
||||
decryption profile to use TLSv1.2 as the maximum supported TLS
|
||||
version. Then, apply this profile to the decryption policy rules for
|
||||
the affected clients and servers. This enables the client to modify
|
||||
its preferred curves, facilitating successful session establishment.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry"><b class="ph b">PAN-299387</b></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">NGFW Cluster</tt>) When an NGFW cluster has only
|
||||
one firewall node present and powered up, that node is stuck in
|
||||
UNKNOWN state after you reboot it and it comes back up. The issue
|
||||
occurs in two scenarios:
|
||||
</div>
|
||||
<ul id="panos-known-issues-12.1.5_ul-pfz_hyt_tgc" class="ul">
|
||||
<li class="li">
|
||||
When there is only one node configured in the cluster (no peer is
|
||||
available or configured).
|
||||
</li>
|
||||
<li class="li">
|
||||
When the peer device in the cluster is completely powered down or
|
||||
unable to autonegotiate its connected HSCI ports. That is, two nodes
|
||||
are in the cluster, but only one node is booting up while the other
|
||||
remains down completely.
|
||||
</li>
|
||||
</ul>
|
||||
<div class="p">
|
||||
The expected behavior is that if no peer device is available (at a
|
||||
port autonegotiation or link level for HSCI-A or HSCI-B), then a
|
||||
cluster device should go to INITIAL state, followed by ONLINE state
|
||||
(and not remain in UNKNOWN state).
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: To avoid this issue, connect the
|
||||
HSCI-A to HSCI-B in loopback to create a link partner.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry"><b class="ph b">PAN-299229</b></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
On PA-5400 Series and PA-7500 Series firewalls, if you run certain
|
||||
types of CLI commands during or shortly after a commit, the commands
|
||||
will time out. The types of CLI commands impacted by this issue are
|
||||
IoT, Cloud-User-ID, and App-ID Cloud Engine CLI commands.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Don't execute IoT, Cloud-User-ID, or
|
||||
App-ID Cloud Engine CLI commands during or shortly after a commit on a
|
||||
PA-5400 Series or PA-7500 Series firewall.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry"><b class="ph b">PAN-299170</b></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The remediation link included in the generated PDF of an upgrade check
|
||||
report might be pruned due to a text length limitation of the export
|
||||
function. The link remains fully functional and works correctly on the
|
||||
Panorama web interface.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry"><b class="ph b">PAN-299114</b></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
After you enable the
|
||||
<span class="ph uicontrol"
|
||||
>Enable Duplicate Logging (Cloud and On-Premise) </span
|
||||
>setting on a firewall, clicking
|
||||
<span class="ph uicontrol">Status for Cloud Logging</span>, does not
|
||||
display the logging service connection status.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry"><b class="ph b">PAN-298540</b></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-5500 Series firewalls only</tt>) The
|
||||
<span class="ph uicontrol">Monitor</span> tab in the Web Interface
|
||||
does not display a pop-up to indicate that high-speed log forwarding
|
||||
is enabled and that logs are only viewable from Panorama.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry"><b class="ph b">PAN-298083</b></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
After you change the system mode on an M-700 appliance from Panorama
|
||||
mode to PAN-DB private cloud mode, the
|
||||
<span class="ph codeph">snmpd</span> process fails to work.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry"><b class="ph b">PAN-298047</b></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
In an AI Runtime Security environment, the Azure Container outbound
|
||||
traffic does not seem to be functional and the egress traffic is being
|
||||
misdirected to an incorrect cluster node port.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry"><b class="ph b">PAN-297772</b></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When an Intel e810 NIC is configured in SR-IOV mode, sharing Virtual
|
||||
Functions (VFs) among multiple HSF cluster nodes and subsequently
|
||||
rebooting a cluster node while traffic is active may result in traffic
|
||||
disruption on other HSF cluster nodes utilizing the same NIC. It is
|
||||
recommended to refrain from sharing Intel e810 VFs across cluster
|
||||
nodes and to allocate one VF per Intel e810 PF.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-297114</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
After successfully generating a health check report for managed
|
||||
firewalls from Panorama, the progress bar does not appear and the
|
||||
latest health check reports are not displayed (<span
|
||||
class="ph uicontrol"
|
||||
>Panorama > Device Deployment > Upgrade Check</span
|
||||
>).
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Manually refresh the page to see the
|
||||
latest reports.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-294687</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">NGFW Clusters</tt>) In an NGFW cluster, the leader
|
||||
can't retrieve the HIP Report from Panorama, nor synchronize it to the
|
||||
non-leader nodes. Unlike HA Active/Passive mode, both leader and
|
||||
non-leader nodes receive traffic in cluster mode. If the relevant HIP
|
||||
Report is missing, policies involving HIP may not work properly. The
|
||||
expected behavior is that when a non-leader node receives related
|
||||
traffic, it should request the corresponding HIP Report from the
|
||||
leader.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-293754</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">NGFW Clusters</tt>) Firewalls in an NGFW cluster
|
||||
indicate they are in ONLINE state even though their configurations are
|
||||
different (they aren't synchronized).
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Push the configuration from Panorama
|
||||
to all cluster members at the same time; don't push to an individual
|
||||
firewall. If a cluster member isn't connected to Panorama during the
|
||||
push, the push will fail to the disconnected firewall, but will
|
||||
succeed to all connected firewalls.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-293718</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When high speed logging is enabled on a PA-5560 device, the expected
|
||||
warning message is not displayed on the web interface. This prevents
|
||||
administrators from being notified that logs can only be viewed from
|
||||
Panorama.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-292601</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
PAN-OS 12.1.2 and later 12.1 releases support a Load Balanced DNS
|
||||
configuration for an address object. If there are two address objects
|
||||
with same FQDN, but one object has Load Balanced DNS enabled and other
|
||||
object has Load Balanced DNS disabled, then the policy match for the
|
||||
removed IP addresses doesn't work as expected.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Enable (or disable) Load Balanced DNS
|
||||
consistently for an FQDN that is used with multiple address objects.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-290692</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
In Host Compliance Service, when you create a 'Shared' type Host
|
||||
Compliance Object for the 'Disk-Encryption' category, the State
|
||||
drop-down is automatically selected and cannot be edited. However, you
|
||||
can change the state later by editing the object, if required.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-289524</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
In PAN-OS 12.1.2 and later 12.1 releases, PAN-OS can obtain resolved
|
||||
IP addresses from a Load balanced DNS server and use them in a policy
|
||||
match. However, this functionality does not work as intended when the
|
||||
DNS cache reuse flag is enabled. When the DNS cache reuse flag is
|
||||
enabled, the DNS resolution works as if the Load balanced DNS flag
|
||||
(for an Address object) is disabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-286496</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">NGFW Clusters</tt>) URL-continue and override
|
||||
continue selections will function like a general URL-block action.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-283429</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When you use custom certificates for the connection between Panorama
|
||||
and a log collector, the automated renewal for the predefined
|
||||
ElasticSearch certificates gets disrupted.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Remove the custom certificates before
|
||||
the ElasticSearch certificates expire. This allows the system to
|
||||
correctly identify and renew the predefined ElasticSearch
|
||||
certificates. After the renewal is complete, re-install the custom
|
||||
certificates.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-237106</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
LSVPN satellite certificates may be generated with serial numbers
|
||||
exceeding 40 hexadecimal characters. This causes certificate
|
||||
revocation and deletion operations to fail with the following error
|
||||
messages:
|
||||
</div>
|
||||
<ul id="panos-known-issues-12.1.5_ul-t2x_dxs_wgc" class="ul">
|
||||
<li class="li">
|
||||
<span class="ph systemoutput"
|
||||
>db-serialno can be at most 40 characters</span
|
||||
>
|
||||
</li>
|
||||
<li class="li">
|
||||
<span class="ph systemoutput">db-serialno is invalid</span>
|
||||
</li>
|
||||
</ul>
|
||||
<b class="ph b">Workaround:</b>
|
||||
<div class="p">
|
||||
To resolve this issue, use the following CLI commands with the LSVPN
|
||||
satellite serial number to manually delete or revoke the affected
|
||||
certificates:
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Delete certificate information</b>:<span
|
||||
class="ph userinput"
|
||||
>delete sslmgr-store certificate-info portal name
|
||||
<var class="keyword varname"><name></var> serialno
|
||||
<var class="keyword varname"><satellite_serial></var></span
|
||||
>
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Revoke satellite certificates</b>:<span
|
||||
class="ph userinput"
|
||||
>delete sslmgr-store satellite-info-revoke-certificate portal
|
||||
<var class="keyword varname"><name></var> serialno
|
||||
<var class="keyword varname"
|
||||
><list_of_satellite_serials></var
|
||||
></span
|
||||
>
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PLUG-21065</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div dir="ltr" class="p">
|
||||
In a PA-VM or AI Runtime Security environment, it is observed that the
|
||||
Software Firewall Orchestration plugin deployed with a VM-Flex license
|
||||
and configured with 8-14 GB of memory may encounter traffic
|
||||
disruptions when jumbo frames are enabled. It is recommended to
|
||||
disable jumbo frames on these lower-end VMs in version 12.1.2 by
|
||||
executing the command: set system setting jumbo-frame off.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PLUG-19238</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Enabling Advanced Routing through bootstrap on VM-Series and Prisma
|
||||
AIRS is not supported.
|
||||
</div>
|
||||
<b class="ph b">Workaround</b>: After the firewall boots up, enable
|
||||
advanced routing using the CLI command set device-management
|
||||
general-settings advance-routing yes or enable
|
||||
<a
|
||||
class="xref"
|
||||
href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-networking-admin/advanced-routing/enable-advanced-routing"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>advanced routing</a
|
||||
>
|
||||
through the UI.
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">DRS-6556</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
For Host Compliance Service, while configuring Mappings & Tags in
|
||||
CIE and when you click on the
|
||||
<span class="ph uicontrol">HIP Report</span> tab, the following error
|
||||
message is displayed even when the response is successful:
|
||||
</div>
|
||||
<div class="p">
|
||||
<span class="ph uicontrol">getaddrinfo ENOTFOUND null</span>
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,797 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 34%" />
|
||||
<col style="width: 66%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-313779</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-7500 series only</tt>) PA-7500 series firewalls
|
||||
running PAN-OS 12.1.5 release do not support encryption on HA1 and
|
||||
HA1-backup interfaces. As a result, attempting to execute the
|
||||
<span class="ph codeph"
|
||||
>request high-availability session-reestablish</span
|
||||
>
|
||||
command will fail with the following error.
|
||||
</div>
|
||||
<div class="p">
|
||||
<pre
|
||||
id="panos-known-issues-12.1.6_screen-ilq_djv_h3c"
|
||||
class="pre screen"
|
||||
>
|
||||
ERROR: Encryption is not enabled for HA</pre
|
||||
>
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-313669</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>PA-5500 Series firewalls in cluster configurations only</tt
|
||||
>) When a firewall node is removed from a PA-5500 Series cluster,
|
||||
after the cluster commit and reboot, the node starts in standalone
|
||||
mode with a default virtual wire (vwire) configuration loaded. This
|
||||
default configuration is missing zone assignments for ports eth1/1 and
|
||||
eth1/2, which causes commit operations to fail. Even if zones are
|
||||
manually assigned to these ports, subsequent commit attempts will fail
|
||||
with a
|
||||
<span data-outputclass="response" class="ph systemoutput"
|
||||
>no UUId for rule1</span
|
||||
>
|
||||
error.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> To resolve this, either:
|
||||
</div>
|
||||
<div class="p">
|
||||
<ul id="panos-known-issues-12.1.6_ul-ybs_j3g_k3c" class="ul">
|
||||
<li class="li">
|
||||
Manually assign zone configurations to ports eth1/1 (for example,
|
||||
untrust) and eth1/2 (for example, trust), then open and close
|
||||
security policy rule1 without making changes, and
|
||||
<span class="ph uicontrol">Commit</span>.
|
||||
</li>
|
||||
<li class="li">
|
||||
Delete the default rule and the default virtual wire Ethernet
|
||||
interfaces, then commit.
|
||||
</li>
|
||||
</ul>
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-313623</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
On firewalls with TPM (Trusted Platform Module) support, device
|
||||
certificate renewals may fail due to a disk partition being full. This
|
||||
latter occurs because temporary files aren't being deleted during
|
||||
device certificate status checks.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-312247</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
In generated PDF upgrade check reports, long remediation URLs might be
|
||||
truncated due to UI framework export limitations, leaving only the
|
||||
first line hyperlinked. However, these links remain fully functional
|
||||
within the Panorama web interface. The PDF link directs to the correct
|
||||
destination if the complete URL is copied from the PDF and pasted in
|
||||
the browser.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-309604</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-5500 series only</tt>) In some rare cases, the
|
||||
front panel PSU status LED might show amber, even when the LEDs on the
|
||||
PSU show green.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-309602</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-5500 series only</tt>) When the firewall is
|
||||
initially powered on, the FAN-0 LED does not turn on. The fan
|
||||
functions correctly, but the LED doesn't reflect the status.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Remove and reinsert the fan to turn on
|
||||
the LED.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308564</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Packets are dropped on SD-WAN interfaces if they require fragmentation
|
||||
for an interface but have the
|
||||
<span class="ph uicontrol">Don't Fragment (DF)</span> bit set. This
|
||||
results in unexpected packet drops. This affects client to server
|
||||
sessions when using SD-WAN for NGFW.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Allow fragmenting packets with DF bit
|
||||
set (<span class="ph userinput"
|
||||
>debug dataplane set ip4-ignore-df yes</span
|
||||
>).
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300850</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Manual scheduling of cloud verdicts is required if a new host in an
|
||||
Host Compliance Service-enabled environment has a refresh event entry
|
||||
without a corresponding update event entry.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300809</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Host Compliance Service connectivity will not work if it is connected
|
||||
with management IP which is configured with DHCP mode.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300677</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Panorama cannot display Threat log entries (<b class="ph b"
|
||||
>Monitor > Logs > Threat</b
|
||||
>) when the managed log collector is running a lower PAN-OS release
|
||||
than Panorama.
|
||||
</div>
|
||||
<div class="p">
|
||||
Workaround: Upgrade the log collectors to the same version as
|
||||
Panorama.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300627</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
AutoCommit fails when the Traffic Object is used on AI Runtime
|
||||
Security, which consequently impacts the workloads that utilize
|
||||
overlapping subnets.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300483</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-7500 firewall only</tt>) Enabling FIPS-CC mode
|
||||
causes the firewall to go into maintenance mode.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: After the firewall goes into
|
||||
maintenance mode, perform an additional reboot. The firewall will
|
||||
successfully start up in FIPS-CC mode.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300467</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
WildFire WF-500 appliances running PAN-OS 10.x or PAN-OS 11.x cannot
|
||||
be managed by Panorama running PAN-OS 12.1.2 due to connectivity
|
||||
issues.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Upgrade your WildFire appliances to
|
||||
PAN-OS 12.1.2 or later.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300407</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The Release Note URL column in the Panorama > Plugins page is
|
||||
empty.
|
||||
</div>
|
||||
<div class="p">
|
||||
Release Notes for the plugins are available in the
|
||||
<a
|
||||
class="xref"
|
||||
href="https://docs.paloaltonetworks.com/plugins/vm-series-and-panorama-plugins-release-notes"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>plugins release notes</a
|
||||
>
|
||||
or in their individual product release notes.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300230</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">NGFW Cluster</tt>) In an NGFW cluster, your pings
|
||||
to the HSCI-B link might fail, even when the link indicates it is up.
|
||||
In the event that the HSCI-A link is brought down or unplugged, the
|
||||
cluster node will transition to failed state, avoiding split brain as
|
||||
both HSCI links are down in this case.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Reboot the cluster node to resolve the
|
||||
HSCI-B ping issue.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300192</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
If the Host Compliance Service is configured with a service route
|
||||
pointing to an unreachable IP address, the
|
||||
<span class="ph systemoutput">gp_broker</span> process may stop
|
||||
working when you enable-disable the Host Compliance Service.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300114</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
VM entered maintenance mode during a downgrade from version 12.1.2 to
|
||||
11.2.7, when executed through the CLI.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Download and install the required
|
||||
version of PAN-OS through the UI instead of the CLI.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300069</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-410 firewall only</tt>) Loading a saved config
|
||||
file can take up to 5 minutes.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300053</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When you use the CLI command
|
||||
<span class="ph userinput">request system fqdn refresh</span> to
|
||||
trigger another IP address resolution of configured FQDN entries, the
|
||||
firewall might get into an error state where the DNS Proxy cache
|
||||
received and stored a new IP address for a particular FQDN entry via
|
||||
this command. However, the Device-Server (and the Security rule) still
|
||||
have the old IP address for that FQDN entry.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Avoid using the CLI command:
|
||||
<span class="ph userinput">request system fqdn refresh</span>. Use the
|
||||
following command instead (for a particular domain-name or an entire
|
||||
list):
|
||||
<span class="ph userinput"
|
||||
>clear dns-proxy cache all domain-name <domain_name></span
|
||||
>. To correct the error state where the DNS Proxy cache and
|
||||
Device-Server and Security rule are already storing different IP
|
||||
addresses, use the following CLI command:
|
||||
<span class="ph userinput"
|
||||
>debug device-server dump fqdn type resync vsys <vsys_name>
|
||||
fqdn-name <domain_name></span
|
||||
>
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300025</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
If Azure hotplug events occur, the firewall may experience a
|
||||
<span class="ph userinput">brdagent</span> crash and data interfaces
|
||||
may transition to an unknown state, leading to traffic disruption.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Reboot the VM if the
|
||||
<span class="ph userinput">brdagent</span> crash does not trigger a
|
||||
device reboot.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-299562</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
SSL proxy sessions fail when clients send a Client Hello with TLSv1.2
|
||||
and TLSv1.3, and exclusively prefer the secp192 elliptic curve.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: To address this, configure a
|
||||
decryption profile to use TLSv1.2 as the maximum supported TLS
|
||||
version. Then, apply this profile to the decryption policy rules for
|
||||
the affected clients and servers. This enables the client to modify
|
||||
its preferred curves, facilitating successful session establishment.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry"><b class="ph b">PAN-299387</b></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">NGFW Cluster</tt>) When an NGFW cluster has only
|
||||
one firewall node present and powered up, that node is stuck in
|
||||
UNKNOWN state after you reboot it and it comes back up. The issue
|
||||
occurs in two scenarios:
|
||||
</div>
|
||||
<ul id="panos-known-issues-12.1.6_ul-pfz_hyt_tgc" class="ul">
|
||||
<li class="li">
|
||||
When there is only one node configured in the cluster (no peer is
|
||||
available or configured).
|
||||
</li>
|
||||
<li class="li">
|
||||
When the peer device in the cluster is completely powered down or
|
||||
unable to autonegotiate its connected HSCI ports. That is, two nodes
|
||||
are in the cluster, but only one node is booting up while the other
|
||||
remains down completely.
|
||||
</li>
|
||||
</ul>
|
||||
<div class="p">
|
||||
The expected behavior is that if no peer device is available (at a
|
||||
port autonegotiation or link level for HSCI-A or HSCI-B), then a
|
||||
cluster device should go to INITIAL state, followed by ONLINE state
|
||||
(and not remain in UNKNOWN state).
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: To avoid this issue, connect the
|
||||
HSCI-A to HSCI-B in loopback to create a link partner.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry"><b class="ph b">PAN-299229</b></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
On PA-5400 Series and PA-7500 Series firewalls, if you run certain
|
||||
types of CLI commands during or shortly after a commit, the commands
|
||||
will time out. The types of CLI commands impacted by this issue are
|
||||
IoT, Cloud-User-ID, and App-ID Cloud Engine CLI commands.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Don't execute IoT, Cloud-User-ID, or
|
||||
App-ID Cloud Engine CLI commands during or shortly after a commit on a
|
||||
PA-5400 Series or PA-7500 Series firewall.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry"><b class="ph b">PAN-299170</b></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The remediation link included in the generated PDF of an upgrade check
|
||||
report might be pruned due to a text length limitation of the export
|
||||
function. The link remains fully functional and works correctly on the
|
||||
Panorama web interface.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry"><b class="ph b">PAN-299114</b></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
After you enable the
|
||||
<span class="ph uicontrol"
|
||||
>Enable Duplicate Logging (Cloud and On-Premise) </span
|
||||
>setting on a firewall, clicking
|
||||
<span class="ph uicontrol">Status for Cloud Logging</span>, does not
|
||||
display the logging service connection status.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry"><b class="ph b">PAN-298540</b></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-5500 Series firewalls only</tt>) The
|
||||
<span class="ph uicontrol">Monitor</span> tab in the Web Interface
|
||||
does not display a pop-up to indicate that high-speed log forwarding
|
||||
is enabled and that logs are only viewable from Panorama.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry"><b class="ph b">PAN-298083</b></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
After you change the system mode on an M-700 appliance from Panorama
|
||||
mode to PAN-DB private cloud mode, the
|
||||
<span class="ph codeph">snmpd</span> process fails to work.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry"><b class="ph b">PAN-298047</b></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
In an AI Runtime Security environment, the Azure Container outbound
|
||||
traffic does not seem to be functional and the egress traffic is being
|
||||
misdirected to an incorrect cluster node port.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry"><b class="ph b">PAN-297772</b></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When an Intel e810 NIC is configured in SR-IOV mode, sharing Virtual
|
||||
Functions (VFs) among multiple HSF cluster nodes and subsequently
|
||||
rebooting a cluster node while traffic is active may result in traffic
|
||||
disruption on other HSF cluster nodes utilizing the same NIC. It is
|
||||
recommended to refrain from sharing Intel e810 VFs across cluster
|
||||
nodes and to allocate one VF per Intel e810 PF.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-297114</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
After successfully generating a health check report for managed
|
||||
firewalls from Panorama, the progress bar does not appear and the
|
||||
latest health check reports are not displayed (<span
|
||||
class="ph uicontrol"
|
||||
>Panorama > Device Deployment > Upgrade Check</span
|
||||
>).
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Manually refresh the page to see the
|
||||
latest reports.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-294687</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">NGFW Clusters</tt>) In an NGFW cluster, the leader
|
||||
can't retrieve the HIP Report from Panorama, nor synchronize it to the
|
||||
non-leader nodes. Unlike HA Active/Passive mode, both leader and
|
||||
non-leader nodes receive traffic in cluster mode. If the relevant HIP
|
||||
Report is missing, policies involving HIP may not work properly. The
|
||||
expected behavior is that when a non-leader node receives related
|
||||
traffic, it should request the corresponding HIP Report from the
|
||||
leader.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-293754</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">NGFW Clusters</tt>) Firewalls in an NGFW cluster
|
||||
indicate they are in ONLINE state even though their configurations are
|
||||
different (they aren't synchronized).
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Push the configuration from Panorama
|
||||
to all cluster members at the same time; don't push to an individual
|
||||
firewall. If a cluster member isn't connected to Panorama during the
|
||||
push, the push will fail to the disconnected firewall, but will
|
||||
succeed to all connected firewalls.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-293718</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When high speed logging is enabled on a PA-5560 device, the expected
|
||||
warning message is not displayed on the web interface. This prevents
|
||||
administrators from being notified that logs can only be viewed from
|
||||
Panorama.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-292601</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
PAN-OS 12.1.2 and later 12.1 releases support a Load Balanced DNS
|
||||
configuration for an address object. If there are two address objects
|
||||
with same FQDN, but one object has Load Balanced DNS enabled and other
|
||||
object has Load Balanced DNS disabled, then the policy match for the
|
||||
removed IP addresses doesn't work as expected.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Enable (or disable) Load Balanced DNS
|
||||
consistently for an FQDN that is used with multiple address objects.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-290692</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
In Host Compliance Service, when you create a 'Shared' type Host
|
||||
Compliance Object for the 'Disk-Encryption' category, the State
|
||||
drop-down is automatically selected and cannot be edited. However, you
|
||||
can change the state later by editing the object, if required.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-289524</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
In PAN-OS 12.1.2 and later 12.1 releases, PAN-OS can obtain resolved
|
||||
IP addresses from a Load balanced DNS server and use them in a policy
|
||||
match. However, this functionality does not work as intended when the
|
||||
DNS cache reuse flag is enabled. When the DNS cache reuse flag is
|
||||
enabled, the DNS resolution works as if the Load balanced DNS flag
|
||||
(for an Address object) is disabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-286496</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">NGFW Clusters</tt>) URL-continue and override
|
||||
continue selections will function like a general URL-block action.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-283429</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When you use custom certificates for the connection between Panorama
|
||||
and a log collector, the automated renewal for the predefined
|
||||
ElasticSearch certificates gets disrupted.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Remove the custom certificates before
|
||||
the ElasticSearch certificates expire. This allows the system to
|
||||
correctly identify and renew the predefined ElasticSearch
|
||||
certificates. After the renewal is complete, re-install the custom
|
||||
certificates.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-237106</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
LSVPN satellite certificates may be generated with serial numbers
|
||||
exceeding 40 hexadecimal characters. This causes certificate
|
||||
revocation and deletion operations to fail with the following error
|
||||
messages:
|
||||
</div>
|
||||
<ul id="panos-known-issues-12.1.6_ul-t2x_dxs_wgc" class="ul">
|
||||
<li class="li">
|
||||
<span class="ph systemoutput"
|
||||
>db-serialno can be at most 40 characters</span
|
||||
>
|
||||
</li>
|
||||
<li class="li">
|
||||
<span class="ph systemoutput">db-serialno is invalid</span>
|
||||
</li>
|
||||
</ul>
|
||||
<b class="ph b">Workaround:</b>
|
||||
<div class="p">
|
||||
To resolve this issue, use the following CLI commands with the LSVPN
|
||||
satellite serial number to manually delete or revoke the affected
|
||||
certificates:
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Delete certificate information</b>:<span
|
||||
class="ph userinput"
|
||||
>delete sslmgr-store certificate-info portal name
|
||||
<var class="keyword varname"><name></var> serialno
|
||||
<var class="keyword varname"><satellite_serial></var></span
|
||||
>
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Revoke satellite certificates</b>:<span
|
||||
class="ph userinput"
|
||||
>delete sslmgr-store satellite-info-revoke-certificate portal
|
||||
<var class="keyword varname"><name></var> serialno
|
||||
<var class="keyword varname"
|
||||
><list_of_satellite_serials></var
|
||||
></span
|
||||
>
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PLUG-21065</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div dir="ltr" class="p">
|
||||
In a PA-VM or AI Runtime Security environment, it is observed that the
|
||||
Software Firewall Orchestration plugin deployed with a VM-Flex license
|
||||
and configured with 8-14 GB of memory may encounter traffic
|
||||
disruptions when jumbo frames are enabled. It is recommended to
|
||||
disable jumbo frames on these lower-end VMs in version 12.1.2 by
|
||||
executing the command: set system setting jumbo-frame off.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PLUG-19238</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Enabling Advanced Routing through bootstrap on VM-Series and Prisma
|
||||
AIRS is not supported.
|
||||
</div>
|
||||
<b class="ph b">Workaround</b>: After the firewall boots up, enable
|
||||
advanced routing using the CLI command set device-management
|
||||
general-settings advance-routing yes or enable
|
||||
<a
|
||||
class="xref"
|
||||
href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-networking-admin/advanced-routing/enable-advanced-routing"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>advanced routing</a
|
||||
>
|
||||
through the UI.
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">DRS-6556</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
For Host Compliance Service, while configuring Mappings & Tags in
|
||||
CIE and when you click on the
|
||||
<span class="ph uicontrol">HIP Report</span> tab, the following error
|
||||
message is displayed even when the response is successful:
|
||||
</div>
|
||||
<div class="p">
|
||||
<span class="ph uicontrol">getaddrinfo ENOTFOUND null</span>
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,135 @@
|
||||
#!/usr/bin/env node
|
||||
/**
|
||||
* Convert downloaded issue table HTML files into web/data/issues/ markdown files.
|
||||
*
|
||||
* Usage:
|
||||
* node process_issues.mjs [--crawl CC-MAIN-2026-12] [--product PAN-OS] [--date YYYY-MM-DD]
|
||||
*
|
||||
* After this script, run:
|
||||
* python scripts/update_products_from_issues.py
|
||||
*/
|
||||
|
||||
import { JSDOM } from 'jsdom';
|
||||
import { readFileSync, writeFileSync, mkdirSync, readdirSync } from 'node:fs';
|
||||
import { join } from 'node:path';
|
||||
import { fileURLToPath } from 'node:url';
|
||||
import { parseArgs } from 'node:util';
|
||||
|
||||
const __dirname = fileURLToPath(new URL('.', import.meta.url));
|
||||
|
||||
const { values: args } = parseArgs({
|
||||
options: {
|
||||
crawl: { type: 'string', default: 'CC-MAIN-2026-12' },
|
||||
product: { type: 'string', default: 'PAN-OS' },
|
||||
date: { type: 'string' },
|
||||
},
|
||||
strict: false,
|
||||
});
|
||||
|
||||
function isoWeekStartDate(year, week) {
|
||||
const jan4 = new Date(Date.UTC(year, 0, 4));
|
||||
const jan4Day = jan4.getUTCDay() || 7;
|
||||
const week1Monday = new Date(jan4);
|
||||
week1Monday.setUTCDate(jan4.getUTCDate() - (jan4Day - 1));
|
||||
|
||||
const target = new Date(week1Monday);
|
||||
target.setUTCDate(week1Monday.getUTCDate() + (week - 1) * 7);
|
||||
return target.toISOString().slice(0, 10);
|
||||
}
|
||||
|
||||
function dateFromCrawlId(crawlId) {
|
||||
const match = /^CC-MAIN-(\d{4})-(\d{2})$/i.exec(String(crawlId || '').trim());
|
||||
if (!match) {
|
||||
return null;
|
||||
}
|
||||
const year = Number(match[1]);
|
||||
const week = Number(match[2]);
|
||||
if (!Number.isInteger(year) || !Number.isInteger(week) || week < 1 || week > 53) {
|
||||
return null;
|
||||
}
|
||||
return isoWeekStartDate(year, week);
|
||||
}
|
||||
|
||||
const inferredDate = dateFromCrawlId(args.crawl);
|
||||
const outputDate = args.date || inferredDate || new Date().toISOString().slice(0, 10);
|
||||
|
||||
// Set up DOMParser global before importing modules that rely on it.
|
||||
const { window } = new JSDOM('<!doctype html><html><body></body></html>');
|
||||
globalThis.DOMParser = window.DOMParser;
|
||||
|
||||
const { parseIssuesFromHtmlTable } = await import(
|
||||
new URL('../../web/js/process.js', import.meta.url).href
|
||||
);
|
||||
const { buildIssueMarkdownDocument } = await import(
|
||||
new URL('../../web/js/markdown.js', import.meta.url).href
|
||||
);
|
||||
|
||||
const REPO_ROOT = join(__dirname, '..', '..');
|
||||
const dataDir = join(__dirname, '..', 'data', args.crawl, args.product);
|
||||
|
||||
let files;
|
||||
try {
|
||||
files = readdirSync(dataDir).filter(f => f.endsWith('.html'));
|
||||
} catch {
|
||||
console.error(`No data directory found: ${dataDir}`);
|
||||
console.error('Run crawl_cc.py first to download issue tables.');
|
||||
process.exit(1);
|
||||
}
|
||||
|
||||
if (files.length === 0) {
|
||||
console.log(`No HTML files found in ${dataDir}`);
|
||||
process.exit(0);
|
||||
}
|
||||
|
||||
let writtenCount = 0;
|
||||
|
||||
for (const file of files.sort()) {
|
||||
// Filename format: {version}-{type}.html
|
||||
// where type is 'addressed' or 'known'.
|
||||
// Version may itself contain hyphens (e.g. '10.2.1-h3'), so split on
|
||||
// the *last* hyphen-prefixed token that is a known issue type.
|
||||
const baseName = file.replace(/\.html$/, '');
|
||||
const lastDash = baseName.lastIndexOf('-');
|
||||
if (lastDash === -1) {
|
||||
console.warn(`Skipping unexpected filename: ${file}`);
|
||||
continue;
|
||||
}
|
||||
const version = baseName.slice(0, lastDash);
|
||||
const issueType = baseName.slice(lastDash + 1);
|
||||
|
||||
if (issueType !== 'addressed' && issueType !== 'known') {
|
||||
console.warn(`Skipping unexpected issue type in filename: ${file}`);
|
||||
continue;
|
||||
}
|
||||
|
||||
const capitalizedType = issueType.charAt(0).toUpperCase() + issueType.slice(1);
|
||||
const html = readFileSync(join(dataDir, file), 'utf-8');
|
||||
|
||||
const parsedIssues = parseIssuesFromHtmlTable(html, { type: capitalizedType });
|
||||
if (parsedIssues.length === 0) {
|
||||
console.warn(`No issues parsed from ${file} — skipping`);
|
||||
continue;
|
||||
}
|
||||
|
||||
const markdown = buildIssueMarkdownDocument({
|
||||
type: capitalizedType,
|
||||
product: args.product,
|
||||
version,
|
||||
issues: parsedIssues,
|
||||
metadata: {
|
||||
source: 'common-crawl',
|
||||
crawl: args.crawl,
|
||||
},
|
||||
});
|
||||
|
||||
const outDir = join(REPO_ROOT, 'web', 'data', 'issues', args.product, issueType);
|
||||
mkdirSync(outDir, { recursive: true });
|
||||
const outFile = join(outDir, `${version}_${outputDate}.md`);
|
||||
writeFileSync(outFile, markdown, 'utf-8');
|
||||
writtenCount++;
|
||||
}
|
||||
|
||||
console.log(`Wrote ${writtenCount} markdown file(s) to web/data/issues/${args.product}/`);
|
||||
if (writtenCount > 0) {
|
||||
console.log('Next step: python scripts/update_products_from_issues.py');
|
||||
}
|
||||
Reference in New Issue
Block a user