Processed new reference files
This commit is contained in:
@@ -0,0 +1,157 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.13-h8
|
||||
---
|
||||
|
||||
## PAN-321340
|
||||
|
||||
```caveat
|
||||
Firewalls in FIPS mode only
|
||||
```
|
||||
|
||||
Fixed an issue where GlobalProtect unexpectedly prompted for RADIUS authentication instead of client certificate authentication due to an OSCP validation error and subsequent CRL verification failure, which led to certificates being marked as invalid.
|
||||
|
||||
## PAN-320598
|
||||
|
||||
Fixed an issue where internal and external DNS names did not resolve when connected to a GlobalProtect gateway.
|
||||
|
||||
## PAN-319288
|
||||
|
||||
Fixed an issue where a DPC in Slot 4 restarted repeatedly, which caused internal path monitoring failures and a failover event.
|
||||
|
||||
## PAN-318580
|
||||
|
||||
Fixed an issue where processes restarted and the firewall unexpectedly rebooted when you configured a Security policy rule with **Source Device > quarantine**.
|
||||
|
||||
## PAN-317755
|
||||
|
||||
Fixed an issue on Panorama where selective push operations failed when plugin configurations included access-domain or log-collector references.
|
||||
|
||||
## PAN-316556
|
||||
|
||||
Fixed an issue where a race condition between the session ager and packet processing resulted in memory corruption and caused the pan_task process to stop responding, which resulted in the firewall becoming unresponsive
|
||||
|
||||
## PAN-316120
|
||||
|
||||
Fixed an issue where, after Advanced Routing was enabled, the firewall advertised routes to internal BGP neighbors with the original external BGP next-hop address.
|
||||
|
||||
## PAN-315337
|
||||
|
||||
Fixed an issue where GlobalProtect throughput was reduced after an upgrade.
|
||||
|
||||
## PAN-315314
|
||||
|
||||
Fixed an issue where, when a push operation from Panorama to the firewall failed, accounting logs stopped forwarding.
|
||||
|
||||
## PAN-315160
|
||||
|
||||
```caveat
|
||||
PA-7500 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where internal path monitoring logs incorrectly reported internal path monitoring failures when they did not occur.
|
||||
|
||||
## PAN-314752
|
||||
|
||||
Fixed an issue on Panorama where, after removing a scheduled configuration push, Panorama still initiated the push at its previously scheduled time.
|
||||
|
||||
## PAN-314623
|
||||
|
||||
```caveat
|
||||
Firewalls in active/passive HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where, after a failover, routing information within OSPF protocol was not correctly translated or propagated, which affected network path convergence and FRR capabilities.
|
||||
|
||||
## PAN-314385
|
||||
|
||||
```caveat
|
||||
Firewalls in active/passive HA clusters only
|
||||
```
|
||||
|
||||
Fixed an issue where high dataplane CPU usage occurred and traffic offloading decreased when a failover occurred from the active firewall to the passive firewall, and then back to the active firewall.
|
||||
|
||||
## PAN-313827
|
||||
|
||||
Fixed an issue where a memory leak occurred related to the reportd process when custom reports were run via API.
|
||||
|
||||
## PAN-313700
|
||||
|
||||
Fixed an issue where an unexpected reboot occurred when Inline Cloud Analysis was enabled in an Anti-Spyware and Vulnerability profile.
|
||||
|
||||
## PAN-313606
|
||||
|
||||
Fixed an issue where Panorama pushed commits took longer than expected to complete without displaying an error message when committing due to slow cloud-app compilation.
|
||||
|
||||
## PAN-313443
|
||||
|
||||
Fixed an issue where firewalls acting as an accumulation proxy sent a server hello with an earlier TCP timestamp value than a preceding ACK packet, which prevented successful session establishment. This occurred when the client hello messages were split across multiple network segments.
|
||||
|
||||
To use this fix, run the CLI command debug dataplane set ssl-decrypt accumulate-client-hello ts-relay yes.
|
||||
|
||||
## PAN-313036
|
||||
|
||||
Fixed an issue where the firewall dataplane continuously accumulated packets in the ctd_pkt_queue and packet buffers, which caused resource exhaustion and prematurely terminated sessions.
|
||||
|
||||
## PAN-311658
|
||||
|
||||
Fixed an issue where the reportd process stopped responding, which caused the firewall to reboot.
|
||||
|
||||
## PAN-311098
|
||||
|
||||
Fixed an issue where firewalls entered a nonfunctional state due to L7 running out of resources due to a high volume of traffic.
|
||||
|
||||
## PAN-309853
|
||||
|
||||
```caveat
|
||||
Firewalls with FIPS-CC enabled only
|
||||
```
|
||||
|
||||
Fixed an issue where, when attempting to make changes to the GlobalProtect portal, an error message was displayed and configuration updates failed.
|
||||
|
||||
## PAN-308775
|
||||
|
||||
```caveat
|
||||
Firewalls in active/passive configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where NTP status intermittently showed as rejected on the active firewall, which prevented the firewalls from synchronizing time.
|
||||
|
||||
## PAN-308668
|
||||
|
||||
Fixed an issue on Prisma Access Remote Network firewalls where high CPU utilization caused slowness and command timeouts.
|
||||
|
||||
## PAN-308444
|
||||
|
||||
Fixed an issue where pushing multiple policy rules failed when the policy rules contained a large number of dynamic address object groups or user groups.
|
||||
|
||||
## PAN-297819
|
||||
|
||||
Fixed an issue where the firewall was unable to send device telemetry files to Cortex Data Lake due to the firewall receiving an invalid upload token.
|
||||
|
||||
## PAN-295082
|
||||
|
||||
Fixed an issue on the Panorama web interface where you were unable to delete or change a logical router for tunnel, SD-WAN, VLAN, or loopback interfaces under a template.
|
||||
|
||||
## PAN-293142
|
||||
|
||||
Fixed an issue where firewall components became unresponsive during sustained operation.
|
||||
|
||||
## PAN-289460
|
||||
|
||||
Fixed an issue where the timestamp value in SNMPv3 trap headers was incorrect.
|
||||
|
||||
To use this fix, run the CLI command debug log-receiver enginetime-from-snmptime yes.
|
||||
|
||||
## PAN-282335
|
||||
|
||||
Fixed an issue where firewalls in a cluster experienced approximately 50% packet loss on IPSec NATT tunnels when tunnel acceleration was enabled.
|
||||
|
||||
## PAN-240066
|
||||
|
||||
Fixed a duplicate MAC address issue where an ethernet interface sent out Gratuitous ARP (GARP) messages for an IP address that was not configured on it.
|
||||
|
||||
## PAN-213491
|
||||
|
||||
Fixed an issue where the management CPU was high, which caused the web interface to be slower than expected.
|
||||
Reference in New Issue
Block a user