Discard the crawler, manually collect reference material for processing

This commit is contained in:
2026-04-13 13:38:18 -05:00
parent e53a813713
commit 37eaffba3f
19 changed files with 11895 additions and 783 deletions
+140
View File
@@ -0,0 +1,140 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-242777</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where users previously reported limitations due to
session count caps when utilizing
<b class="ph b">Web Proxy</b> features on PA-5400 Series Firewalls. To
address these performance complaints and support higher traffic
volumes, we have increased the maximum session capacity on specific
<b class="ph b">PA-5400F</b> series platforms, leveraging available
system memory. This update ensures greater capacity and stability for
high-volume environments.
</div>
<div class="p">
The supported session limits are:
<div style="display: inline"></div>
<div style="display: inline"></div>
<div style="display: inline"></div>
<div style="display: inline"></div>
<div style="display: inline"></div>
<div style="display: inline"></div>
<div style="display: inline"></div>
<div style="display: inline"></div>
<div style="display: inline"></div>
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 50%" />
<col style="width: 50%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">Platform</th>
<th class="entry">Max Sessions</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">PA-5410</td>
<td class="entry relcol">95K</td>
</tr>
<tr class="row">
<td class="entry">PA-5420</td>
<td class="entry relcol">95K</td>
</tr>
<tr class="row">
<td class="entry">PA-5430</td>
<td class="entry relcol">95K</td>
</tr>
<tr class="row">
<td class="entry">PA-5440</td>
<td class="entry relcol">225K</td>
</tr>
<tr class="row">
<td class="entry">PA-5445</td>
<td class="entry relcol">250K</td>
</tr>
<tr class="row">
<td class="entry">PA-5450</td>
<td class="entry relcol">1.28M</td>
</tr>
</tbody>
</table>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291499</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Amazon Web Services (AWS) environments
only</tt
>) Fixed an issue where newly deployed firewalls were unable to
connect to the Strata Logging Service (SLS) until after a reboot,
license fetch, or management server restart.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-288726</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="keyword cmdname">useridd</span> process stopped
responding due to a Security policy rule ID being set to 0, which
caused the last configuration retrieval to fail.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287133</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where assigning a policy
rule to a group at the top or bottom of the list changed the order of
other policy rules.
</div>
</td>
</tr>
</tbody>
</table>
+34
View File
@@ -0,0 +1,34 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-304195</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where performing a private data reset
caused device telemetry to stop working. This issue also occurred
after performing a factory reset and then running the CLI command
<span class="ph systemoutput">set system ztp disable</span>.
</div>
</td>
</tr>
</tbody>
</table>
+90
View File
@@ -0,0 +1,90 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"></b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0227"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0227</a
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-306534</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue were the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process repeatedly restarted due to memory pool corruption when
processing fragmented DNS over HTTPs (DoH) JSON queries. This occurred
due to incorrect buffer length calculations during memory deallocation
when the query name field spanned multiple packets.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-305480</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process stopped responding while processing DoH JSON format traffic
with DoH Security enabled, which caused missing cross-packet bytes in
the decoded DNS query type field, and the dataplane went down.
</div>
</td>
</tr>
</tbody>
</table>
+180
View File
@@ -0,0 +1,180 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300334</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the ADEM plugin was not compatible with PAN-OS
12.1.2, which prevented installation of the plugin and disabled the
ability to monitor remote sites on firewalls using the ADEM
functionality.
</div>
<div class="p">
To use this fix, you need the following compatible versions: ADEM
1.1.0-h3 and SD-WAN plugin 3.4.0.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-298241</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the NAT IP address pool was exhausted, which led
to intermittent connectivity issues with call applications and
outbound call failures. This occurred due to the firewall not properly
releasing NAT dynamic ports back to the address pool.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-296490</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">FIPS CC mode enabled only</tt>) Fixed an issue
where Panorama on GCP rebooted every hour after upgrading to
11.1.6-h10.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-289249</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory leak occurred on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process when a WildFire update was initiated while device telemetry
data collection was in progress. This resulted in an OOM condition.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-286576</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process restarted, which caused heartbeat failures to occur and a slot
to go down due to path monitor failure.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-272245</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>dnsproxy</a
>
process crashed due to memory corruption caused by a race condition
when the allow list downloading was impacted by config change.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267450</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process stopped responding with a SIGSEGV at
<span class="ph systemoutput">schedule_report_es_response</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262831</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5400f Series firewalls only</tt>) Fixed an
intermittent issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding, which caused the firewall to restart.
</div>
</td>
</tr>
</tbody>
</table>
+77
View File
@@ -0,0 +1,77 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-311938</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where autocommits failed after an upgrade due to
configuration memory allocation issues and 100% policy rule cache
usage when both DNS Rewrite and URL Custom Category Match were
configured.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-306451</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls on AWS environments only</tt>)
Fixed an issue where, after upgrading the firewall to an affected
release, GlobalProtect clients did not connect with IPSec and instead
connected using SSL due to traffic flow being disabled when checking
for health check packets.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-304496</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after unregistering an IP tag and registering a
different IP tag for the same IP address via XML API, the dynamic
address group membership was not updated on the dataplane, which
resulted in Security policy rules being enforced incorrectly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-304195</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where performing a private data reset
caused device telemetry to stop working. This issue also occurred
after performing a factory reset and then running the CLI command
<span class="ph systemoutput">set system ztp disable</span>.
</div>
</td>
</tr>
</tbody>
</table>
+59
View File
@@ -0,0 +1,59 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-313572</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the dataplane restarted due to a segmentation fault.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300664</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama and firewall web interface where
Applications pages became unresponsive after activating the SaaS
Inline license.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-292447</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not display data in the
<span class="ph uicontrol">Feature Adoption</span> tab in Strata Cloud
Manager due to the system creating and deleting a CLI user for each
interval instead of reusing a permanent CLI user for telemetry.
</div>
</td>
</tr>
</tbody>
</table>
+623
View File
@@ -0,0 +1,623 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"></b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0227"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0227</a
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-305480</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process stopped responding while processing DoH JSON format traffic
with DoH Security enabled, which caused missing cross-packet bytes in
the decoded DNS query type field, and the dataplane went down.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-305151</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the configuration was not updated on the AI
Firewall in AWS after a successful configuration push from Strata
Cloud Manager (SCM).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-304195</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where performing a private data reset
caused device telemetry to stop working. This issue also occurred
after performing a factory reset and then running the CLI command
<span class="ph systemoutput">set system ztp disable</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-304075</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not detect evasions due to TCP
checksum offloading not being enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-303836</b></div>
</td>
<td class="entry relcol">
<div class="p">
Resolved an issue in which intermittent session-table resets on the
AIRS VM triggered packet drops, leading to packet loss in egress
response traffic
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-303700</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect users were incorrectly dropped by
the default Security policy rule after upgrading to PAN-OS 12.1.2 when
IPv6 firewalling was disabled. This occurred due to policy rules
configured with geographic regions matching traffic incorrectly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-303559</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after manuallly creating a device telemetry
bundle, the
<span class="ph systemoutput">hour_cli_output.txt</span> file within
the bundle had a file size of 0 bytes. This occurred when checking the
bundle content after enabling device telemetry and setting the device
telemetry upload endpoint.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-302908</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not forward STP frames on Layer
2 VLAN interfaces, which prevented the construction of loop-free
topologies with connected switches.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-301801</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Log Collectors where the Elasticsearch process
fluctuated intermittently between green and red states, which led to
interruptions in log collection. This issue occurred when the number
of shards exceeded the cluster's maximum supported threshold of
greater than 1000 shards per Elasticsearch instance.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-301496</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the DNS cache capacity was insufficient for
environments with a large number of FQDN address objects, which caused
the firewall to repeatedly send DNS requests for the same FQDN objects
even after it received valid responses.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-300837</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls experienced multiple reboots due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process restarting with a SIGSEGV signal. This occurred because the
client-to-firewall side assumed TLS 1.3 for the firewall-server side.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-300372</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama virtual appliances only</tt>) Fixed an
issue where maintenance mode was not accessible to do Factory Reset or
switch to FIPSCC mode.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-300096</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a local commit on a firewall breaks template
stack overrides, preventing the enabling of LACP (Link Aggregation
Control Protocol). After a local commit, the LACP enable check was
unexpectedly unchecked, causing an outage. Attempting to re-enable
LACP through the web interface was unsuccessful, requiring manual
removal of the LACP configuration from the Panorama CLI.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-299815</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on multi-vsys firewalls where a host was not removed
from the quarantine list after receiving a redistribution message from
Panorama. This occurred when Panorama was configured to redistribute
quarantine messages to a firewall cluster, and the GlobalProtect
configuration and redistribution were built out in a vsys other than
vsys1.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-299678</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall repeatedly rebooted when downgrading
to an affected release.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-299193</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where, after upgrading, autocommits
repeatedly failed until after a second reboot due to a timing issue
between content loading on the management plane card (MPC) and the log
receiver startup.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-298684</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an Application Override policy rule was not
applied using an IPv4 source IP address with IPv6 enabled and
<span class="ph uicontrol">Network</span> &gt;
<span class="ph uicontrol">Zones</span> &gt;
<span class="ph uicontrol">Pre-NAT Identification</span> enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-298654</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall generated false positive threat logs
during updates to a large domain list (EDL) when a DNS lookup for a
domain being added or removed occurred during the update process. This
resulted in a threat log being generated for a different, unrelated
domain that remained on the list.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-298514</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where WildFire clusters operating in FIPS-CC mode were
not supported in earlier PAN-OS 12.1 releases.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-297972</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a dataplane crash occurred when traffic matched
Inline Cloud Analysis prefiltering signatures, even when Inline Cloud
Analysis features were not enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-297797</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, during a refresh of a large External Dynamic
List (EDL), traffic that matched a domain on the list was incorrectly
identified as a different domain, which resulted in false positive
threat logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-297708</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a long-lived session with many Machine Learning
(ML) model triggers caused a memory leak of feature states associated
with the ML model runs. This resulted in Spyware_State failure
increases, allocation max outs, and impaired policy matching.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-297005</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where exporting custom reports resulted in empty CSV
files.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-296635</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process on passive Panorama management servers leaked memory due to
scheduled report handling from the Strata Logging Service (SLS). This
memory leak occurred daily, consuming available memory until the
process was restarted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-296478</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to PAN-OS 10.2.13-h10,
GlobalProtect Clientless VPN on PA-3250 firewalls failed to execute
JavaScript links, resulting in an authorization error. This occurred
because the firewall was incorrectly injecting text into URLs when
JavaScript buttons or dropdown menus were clicked within the
Clientless VPN portal.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-296453</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where decryption exclusion lists were not working for
untrusted certificates, and SSL sessions were still being decrypted
even after adding them to the exclusion list. This occurred because
the firewall was not adding sessions to the exclude cache until after
receiving a non-RFC alert (BadCertificate) from the server. The fix
ensures that the first session is added to the exclude cache, allowing
subsequent sessions to skip decryption. This issue affects firewalls
configured as clients in server-client communication.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-296202</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/active HA configurations only</tt
>) Fixed an issue where, when a commit operation was in progress,
newly deployed IP address tags that used the XML API were not
immediately reflected in address group resolution, which delayed IP
address mapping to address groups and caused traffic to be incorrectly
allowed or denied.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-295221</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading Panorama and Log Collectors from
PAN-OS 10.2.9 to PAN-OS 11.1.6-h6, Traffic and Threat logs were not
forwarded to a Splunk server over UDP.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-292393</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TFTP file transfers intermittently timed out in
active-active HA pairs when the TFTP control channel was processed by
one firewall and the data channel was processed by the other. This
occurred because the firewall receiving the data channel failed to
match the predicted session due to asynchronous processing of HA
messages.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-291716</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where during a commit, the firewall experienced an
out-of-memory (OOM) condition due to a memory leak and displayed an
error message. This issue caused the device to stop responding and
reboot unexpectedly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-291661</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama appliances and Log Collectors where, after
an upgrade, Elasticsearch intermittently entered into a Red state
before automatically recovering.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-290665</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with firewalls enabled with Security profiles where
certain traffic conditions caused high dataplane CPU utilization and
packet buffer exhaustion, which caused LACP flapping conditions.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-290640</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Microsoft Azure environments in HA
configurations only</tt
>) Fixed an issue where, when an interface was configured with IPv6,
the firewall displayed the message
<span class="ph uicontrol">Unknown error</span> during validation
after the client secret expired, which caused DNS resolution to fail
when resolving FQDNs and HA failovers to occur.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-290453</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where PA-7500 firewalls experienced silent traffic
drops. During migration from PA-7050 to PA-7500 firewalls connected in
series, intermittent connection losses occurred for some applications.
Traffic leaving the PA-7050 was not received or processed by the
PA-7500, even with direct connections and replaced cables/SFPs. Global
counters did not indicate any drops on the PA-7500.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-288598</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama exported the serial number of a managed
collector instead of the collector name when exporting a PDF or CSV
file.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-287387</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where API jobs failed with the error
message
<span class="ph systemoutput"
>Server error: Timed out while getting config lock</span
>. This occurred due to slow set request performance when setting a
large number of address objects in a single set call.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-282640</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where custom reports showed incomplete data when
exported in CSV format from Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-274333</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Logging Service License Status displayed as
red even though a valid license was installed on the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262353</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when Panorama was upgraded but log collectors
were on an earlier version, logs from a log collector group were not
viewable on a Panorama.
</div>
</td>
</tr>
</tbody>
</table>
File diff suppressed because it is too large Load Diff
+198
View File
@@ -0,0 +1,198 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-316911</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Amazon Web Services (AWS) environments
only</tt
>) Fixed an issue where a newly bootstrapped firewall required a
management server restart, relicensing, or license push from Panorama
to invoke the device certificate.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-314201</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on PAN-OS 12.1 releases where intermittent traffic
drops occurred over IPSec VPN tunnels to third-party firewalls during
the IPSec rekey due to the firewall failing to inform the peer to
delete the old SA after moving to the new one.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-313216</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls with Prisma Access incorrectly
displayed some traffic as unsanctioned in traffic logs for cloud
applications that were tagged as
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>sanctioned</a
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-311512</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where HIP (Host Information Profile) reports were
blocked on GlobalProtect when
<span class="ph uicontrol"
>Authentication Cookie Usage Restrictions</span
>
was enabled and the Prisma Access Agent protocol was in use. This
occurred because the system failed to correctly process HIP messages
that were relayed via IPSec tunnels with a Virtual IP as the source,
leading to their rejection.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-311412</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">show advanced-routing resource</span>
CLI command failed to execute successfully when invoked through the
XML API and returned an error message.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-311261</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall generated duplicate URL Filtering
logs due to an error condition&nbsp;when the new XFF feature was
enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-311250</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances and Log Collectors only</tt>)
Fixed an issue where logs from multiple devices were not visible on
Panorama even though the Elasticsearch health status on the dedicated
Log Collectors appeared green.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-310362</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IPv6 Routed HA did not function correctly when
the HA1 (control link) was configured with an IPv6 routed connection.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-310240</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where software packet buffers were completely utilized
when performing a Data Loss Prevention longevity test.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-308507</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama managed firewalls only</tt>) Fixed an
issue where the firewall intermittently failed to maintain active log
forwarding streams to Strata Logging Service (SLS) even when duplicate
logging and enhanced application logging were enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-308418</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when Advanced DNS Security was enabled and
experienced unusually high loads, DNS resolution failures occurred
with the error
<span class="ph uicontrol">resources-unavailable</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-308261</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall failed to send SNMPv3 traps when the
SNMP destination was configured with an FQDN that resolved to multiple
IP address through DNS load balancing.
</div>
</td>
</tr>
</tbody>
</table>