diff --git a/reference/GlobalProtect/addressed/6.2.8-h11.html b/reference/GlobalProtect/addressed/6.2.8-h11.html new file mode 100644 index 0000000..1d587be --- /dev/null +++ b/reference/GlobalProtect/addressed/6.2.8-h11.html @@ -0,0 +1,132 @@ +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
GPC-26311 |
+
+
+ Fixed an issue where GlobalProtect users were unable to submit Host
+ Information Profile (HIP) reports, which prevented security rules
+ requiring a HIP match from applying. This occurred when you connected
+ to an NGPA gateway using a dual-stack network, such as a mobile
+ hotspot. With this fix, GlobalProtect successfully submits HIP reports
+ regardless of your network configuration.
+
+ |
+
GPC-25946 |
+
+
+ Fixed an issue where your GlobalProtect client did not send Host
+ Information Profile (HIP) check and report messages after you
+ established a connection to the gateway. This occurred even when a HIP
+ report was generated shortly before the connection, which could have
+ impacted security posture assessment. With this fix, your
+ GlobalProtect client now correctly sends HIP check and report messages
+ after establishing a connection.
+
+ |
+
GPC-25776 |
+
+
+ Fixed an issue where GlobalProtect clients displayed an incorrect
+ "Connecting" status after a GlobalProtect Portal or Gateway
+ authentication failure, specifically when "Portal auth failed but
+ SAML/CAS auth is successful". This misleading status persisted even
+ though the connection had actually failed, preventing users from
+ understanding the true connection state.
+
+ |
+
GPC-25541 |
+
+
+ Fixed an issue where MacOS GlobalProtect client version 6.2.8-416 was
+ unable to connect to the GlobalProtect gateway, getting stuck in a
+ connecting state.
+
+ |
+
GPC-25490 |
+
+
+ (MacBook devices) Fixed an issue where your GlobalProtect enabled
+ device lost internet access after returning from hibernation. This
+ occurred when your computer completely lost network connectivity,
+ requiring a restart to restore internet access. With this fix, your
+ device maintains network connectivity after resuming from hibernation.
+
+ |
+
GPC-25394 |
+
+
+ Fixed an issue where your traffic continued to pass through the
+ GlobalProtect tunnel interface after you disconnected GobalProtect,
+ preventing it from reverting to your local interface. With this fix,
+ your traffic properly reverts to the local interface after
+ GlobalProtect disconnects.
+
+ |
+
GPC-25320 |
+
+
+ Fixed an issue where GlobalProtect intermittently appeared in the
+ foreground of your user session. This occurred even when you
+ configured GlobalProtect for on-demand connections and were not
+ actively trying to connect, causing it to overshadow other
+ applications. With this fix, GlobalProtect remains in the background
+ until you actively initiate a connection.
+
+ |
+
GPC-25280 |
+
+
+ Fixed an issue where GlobalProtect clients on macOS devices would
+ intermittently get stuck in a "Connecting" state for several minutes
+ after waking from modern standby. This occurred due to a race
+ condition between DNS proxy reconfiguration and the VPN connection
+ process during wake from sleep, where the macOS DNS proxy would
+ temporarily stop and restart, causing the PanGPS service to time out
+ when attempting to send DNS configuration commands. This led to
+ repeated connection failures until the DNS proxy fully stabilized, a
+ condition that was exacerbated by the presence of multiple network
+ extensions on the macOS device.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ —
+ |
+
+
+ Fixes were made to address
+ CVE-2026-0273
+ and
+ CVE-2026-0272.
+
+ |
+
| Issue ID | +Description | +
|---|---|
|
+ PAN-321340
+ |
+
+
+ (Firewalls in FIPS mode only) Fixed an issue
+ where GlobalProtect unexpectedly prompted for RADIUS authentication
+ instead of client certificate authentication due to an OSCP validation
+ error and subsequent CRL verification failure, which led to
+ certificates being marked as invalid.
+
+ |
+
|
+ PAN-319288
+ |
+
+
+ Fixed an issue where a DPC in Slot 4 restarted repeatedly, which
+ caused internal path monitoring failures and a failover event.
+
+ |
+
|
+ PAN-318580
+ |
+
+
+ Fixed an issue where processes restarted and the firewall unexpectedly
+ rebooted when you configured a Security policy rule with
+ Source Device > quarantine.
+
+ |
+
|
+ PAN-317755
+ |
+
+
+ Fixed an issue on Panorama where selective push operations failed when
+ plugin configurations included access-domain or log-collector
+ references.
+
+ |
+
|
+ PAN-317466
+ |
+
+
+ Fixed an issue where SIP sessions stopped progressing after the
+ firewall received fragmented packets, fragmented at header field.
+
+ |
+
|
+ PAN-316556
+ |
+
+
+ Fixed an issue where a race condition between the session ager and
+ packet processing resulted in memory corruption and caused the
+ pan_task process to stop responding, which resulted in the firewall
+ becoming unresponsive
+
+ |
+
|
+ PAN-315337
+ |
+
+
+ Fixed an issue where GlobalProtect throughput was reduced after an
+ upgrade.
+
+ |
+
|
+ PAN-315314
+ |
+
+
+ Fixed an issue where, when a push operation from Panorama to the
+ firewall failed, accounting logs stopped forwarding.
+
+ |
+
|
+ PAN-315160
+ |
+
+
+ (PA-7500 firewalls only) Fixed an issue where
+ internal path monitoring logs incorrectly reported internal path
+ monitoring failures when they did not occur.
+
+ |
+
|
+ PAN-314623
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where, after a failover, routing information within
+ OSPF protocol was not correctly translated or propagated, which
+ affected network path convergence and FRR capabilities.
+
+ |
+
|
+ PAN-313827
+ |
+
+
+ Fixed an issue where a memory leak occurred related to the
+ reportd process when custom
+ reports were run via API.
+
+ |
+
|
+ PAN-313606
+ |
+
+
+ Fixed an issue where Panorama pushed commits took longer than expected
+ to complete without displaying an error message when committing due to
+ slow cloud-app compilation.
+
+ |
+
|
+ PAN-311658
+ |
+
+
+ Fixed an issue where the
+ reportd
+ process stopped responding, which caused the firewall to reboot.
+
+ |
+
|
+ PAN-311248
+ |
+
+
+ Fixed an issue where the ABR failed to translate and advertise the
+ default route (0.0.0.0/0) from an OSPF NSSA area into the OSPF
+ backbone area as a Type-5 LSA.
+
+ |
+
|
+ PAN-310240
+ |
+
+
+ Fixed an issue where software packet buffers were completely utilized
+ when performing a Data Loss Prevention longevity test.
+
+ |
+
|
+ PAN-309853
+ |
+
+
+ (Firewalls with FIPS-CC enabled only) Fixed an
+ issue where, when attempting to make changes to the GlobalProtect
+ portal, an error message was displayed and configuration updates
+ failed.
+
+ |
+
|
+ PAN-308775
+ |
+
+
+ (Firewalls in active/passive configurations only) Fixed an issue where NTP status intermittently showed as rejected
+ on the active firewall, which prevented the firewalls from
+ synchronizing time.
+
+ |
+
|
+ PAN-308668
+ |
+
+
+ Fixed an issue on Prisma Access Remote Network firewalls where high
+ CPU utilization caused slowness and command timeouts.
+
+ |
+
|
+ PAN-297819
+ |
+
+
+ Fixed an issue where the firewall was unable to send device telemetry
+ files to Cortex Data Lake due to the firewall receiving an invalid
+ upload token.
+
+ |
+
|
+ PAN-293142
+ |
+
+
+ Fixed an issue where firewall components became unresponsive during
+ sustained operation.
+
+ |
+
|
+ PAN-291660
+ |
+
+
+ Fixed an issue where the firewall incorrectly reported the speed of
+ 25G interfaces as 1G when queried using SNMP for the ifHighSpeed OID.
+
+ |
+
|
+ PAN-289460
+ |
+
+
+ Fixed an issue where the timestamp value in SNMPv3 trap headers was
+ incorrect.
+
+
+ To use this fix, run the CLI command
+ debug log-receiver enginetime-from-snmptime yes.
+
+ |
+
|
+ PAN-282335
+ |
+
+
+ Fixed an issue where firewalls in a cluster experienced approximately
+ 50% packet loss on IPSec NATT tunnels when tunnel acceleration was
+ enabled.
+
+ |
+
|
+ PAN-280536
+ |
+
+
+ Fixed an issue where firewalls that were connected to the same Cloud
+ Identity Engine displayed inconsistent group membership information,
+ with some firewalls showing only a subset of users belonging to a
+ group. This occurred due to a full or incremental group sync failure.
+
+
+ This fix introduces a retry mechanism for failed group queries to the
+ Cloud Identity Engine. To use this feature, run the following CLI
+ commands.
+
+
+ To enable the retry mechanism:
+ debug user-id dscd retry-enable on.
+
+
+ To set the retry time:
+ debug user-id dscd retry-time set-time <1-10>. The default value is 5 seconds.
+
+
+ To set the number of retry attempts:
+ debug user-id dscd retry attempts set-attempts <3-10>. The default value is 5 attempts.
+
+
+ To disable the retry mechanism:
+ debug user-id dscd retry-enable off.
+
+
+ Additionally, a system log is now generated when a group sync fails,
+ and you are able to monitor the group sync status with the following
+ CLI commands:
+
+
|
+
|
+ PAN-213491
+ |
+
+
+ Fixed an issue where the management CPU was high, which caused the web
+ interface to be slower than expected.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ —
+ |
+
+
+ Fixes were made to address
+ CVE-2026-0273
+ and
+ CVE-2026-0272.
+
+ |
+
| Issue ID | +Description | +
|---|---|
|
+ PAN-321340
+ |
+
+
+ (Firewalls in FIPS mode only) Fixed an issue
+ where GlobalProtect unexpectedly prompted for RADIUS authentication
+ instead of client certificate authentication due to an OSCP validation
+ error and subsequent CRL verification failure, which led to
+ certificates being marked as invalid.
+
+ |
+
|
+ PAN-320598
+ |
+
+
+ Fixed an issue where internal and external DNS names did not resolve
+ when connected to a GlobalProtect gateway.
+
+ |
+
|
+ PAN-319288
+ |
+
+
+ Fixed an issue where a DPC in Slot 4 restarted repeatedly, which
+ caused internal path monitoring failures and a failover event.
+
+ |
+
|
+ PAN-318580
+ |
+
+
+ Fixed an issue where processes restarted and the firewall unexpectedly
+ rebooted when you configured a Security policy rule with
+ Source Device > quarantine.
+
+ |
+
|
+ PAN-317755
+ |
+
+
+ Fixed an issue on Panorama where selective push operations failed when
+ plugin configurations included access-domain or log-collector
+ references.
+
+ |
+
|
+ PAN-316556
+ |
+
+
+ Fixed an issue where a race condition between the session ager and
+ packet processing resulted in memory corruption and caused the
+ pan_task process to stop responding, which resulted in the firewall
+ becoming unresponsive
+
+ |
+
|
+ PAN-316120
+ |
+
+
+ Fixed an issue where, after Advanced Routing was enabled, the firewall
+ advertised routes to internal BGP neighbors with the original external
+ BGP next-hop address.
+
+ |
+
|
+ PAN-315337
+ |
+
+
+ Fixed an issue where GlobalProtect throughput was reduced after an
+ upgrade.
+
+ |
+
|
+ PAN-315314
+ |
+
+
+ Fixed an issue where, when a push operation from Panorama to the
+ firewall failed, accounting logs stopped forwarding.
+
+ |
+
|
+ PAN-315160
+ |
+
+
+ (PA-7500 firewalls only) Fixed an issue where
+ internal path monitoring logs incorrectly reported internal path
+ monitoring failures when they did not occur.
+
+ |
+
|
+ PAN-314752
+ |
+
+
+ Fixed an issue on Panorama where, after removing a scheduled
+ configuration push, Panorama still initiated the push at its
+ previously scheduled time.
+
+ |
+
|
+ PAN-314623
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where, after a failover, routing information within
+ OSPF protocol was not correctly translated or propagated, which
+ affected network path convergence and FRR capabilities.
+
+ |
+
|
+ PAN-314385
+ |
+
+
+ (Firewalls in active/passive HA clusters only)
+ Fixed an issue where high dataplane CPU usage occurred and traffic
+ offloading decreased when a failover occurred from the active firewall
+ to the passive firewall, and then back to the active firewall.
+
+ |
+
|
+ PAN-313827
+ |
+
+
+ Fixed an issue where a memory leak occurred related to the
+ reportd process when custom
+ reports were run via API.
+
+ |
+
|
+ PAN-313700
+ |
+
+
+ Fixed an issue where an unexpected reboot occurred when Inline Cloud
+ Analysis was enabled in an Anti-Spyware and Vulnerability profile.
+
+ |
+
|
+ PAN-313606
+ |
+
+
+ Fixed an issue where Panorama pushed commits took longer than expected
+ to complete without displaying an error message when committing due to
+ slow cloud-app compilation.
+
+ |
+
|
+ PAN-313443
+ |
+
+
+ Fixed an issue where firewalls acting as an accumulation proxy sent a
+ server hello with an earlier TCP timestamp value than a preceding ACK
+ packet, which prevented successful session establishment. This
+ occurred when the client hello messages were split across multiple
+ network segments.
+
+
+ To use this fix, run the CLI command
+ debug dataplane set ssl-decrypt accumulate-client-hello ts-relay
+ yes.
+
+ |
+
|
+ PAN-313036
+ |
+
+
+ Fixed an issue where the firewall dataplane continuously accumulated
+ packets in the ctd_pkt_queue and
+ packet buffers, which caused resource exhaustion and prematurely
+ terminated sessions.
+
+ |
+
|
+ PAN-311658
+ |
+
+
+ Fixed an issue where the
+ reportd
+ process stopped responding, which caused the firewall to reboot.
+
+ |
+
|
+ PAN-311098
+ |
+
+
+ Fixed an issue where firewalls entered a nonfunctional state due to L7
+ running out of resources due to a high volume of traffic.
+
+ |
+
|
+ PAN-309853
+ |
+
+
+ (Firewalls with FIPS-CC enabled only) Fixed an
+ issue where, when attempting to make changes to the GlobalProtect
+ portal, an error message was displayed and configuration updates
+ failed.
+
+ |
+
|
+ PAN-308775
+ |
+
+
+ (Firewalls in active/passive configurations only) Fixed an issue where NTP status intermittently showed as rejected
+ on the active firewall, which prevented the firewalls from
+ synchronizing time.
+
+ |
+
|
+ PAN-308668
+ |
+
+
+ Fixed an issue on Prisma Access Remote Network firewalls where high
+ CPU utilization caused slowness and command timeouts.
+
+ |
+
|
+ PAN-308444
+ |
+
+
+ Fixed an issue where pushing multiple policy rules failed when the
+ policy rules contained a large number of dynamic address object groups
+ or user groups.
+
+ |
+
|
+ PAN-297819
+ |
+
+
+ Fixed an issue where the firewall was unable to send device telemetry
+ files to Cortex Data Lake due to the firewall receiving an invalid
+ upload token.
+
+ |
+
|
+ PAN-295082
+ |
+
+
+ Fixed an issue on the Panorama web interface where you were unable to
+ delete or change a logical router for tunnel, SD-WAN, VLAN, or
+ loopback interfaces under a template.
+
+ |
+
|
+ PAN-293142
+ |
+
+
+ Fixed an issue where firewall components became unresponsive during
+ sustained operation.
+
+ |
+
|
+ PAN-289460
+ |
+
+
+ Fixed an issue where the timestamp value in SNMPv3 trap headers was
+ incorrect.
+
+
+ To use this fix, run the CLI command
+ debug log-receiver enginetime-from-snmptime yes.
+
+ |
+
|
+ PAN-282335
+ |
+
+
+ Fixed an issue where firewalls in a cluster experienced approximately
+ 50% packet loss on IPSec NATT tunnels when tunnel acceleration was
+ enabled.
+
+ |
+
|
+ PAN-240066
+ |
+
+
+ Fixed a duplicate MAC address issue where an ethernet interface sent
+ out Gratuitous ARP (GARP) messages for an IP address that was not
+ configured on it.
+
+ |
+
|
+ PAN-213491
+ |
+
+
+ Fixed an issue where the management CPU was high, which caused the web
+ interface to be slower than expected.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ —
+ |
+
+
+ Fixes were made to address
+ CVE-2026-0273
+ and
+ CVE-2026-0272.
+
+ |
+
| Issue ID | +Description | +
|---|---|
|
+ PAN-321340
+ |
+
+
+ (Firewalls in FIPS mode only) Fixed an issue
+ where GlobalProtect unexpectedly prompted for RADIUS authentication
+ instead of client certificate authentication due to an OSCP validation
+ error and subsequent CRL verification failure, which led to
+ certificates being marked as invalid.
+
+ |
+
|
+ PAN-319288
+ |
+
+
+ Fixed an issue where a DPC in Slot 4 restarted repeatedly, which
+ caused internal path monitoring failures and a failover event.
+
+ |
+
|
+ PAN-318580
+ |
+
+
+ Fixed an issue where processes restarted and the firewall unexpectedly
+ rebooted when you configured a Security policy rule with
+ Source Device > quarantine.
+
+ |
+
|
+ PAN-316556
+ |
+
+
+ Fixed an issue where a race condition between the session ager and
+ packet processing resulted in memory corruption and caused the
+ pan_task process to stop responding, which resulted in the firewall
+ becoming unresponsive
+
+ |
+
|
+ PAN-315314
+ |
+
+
+ Fixed an issue where, when a push operation from Panorama to the
+ firewall failed, accounting logs stopped forwarding.
+
+ |
+
|
+ PAN-308775
+ |
+
+
+ (Firewalls in active/passive configurations only) Fixed an issue where NTP status intermittently showed as rejected
+ on the active firewall, which prevented the firewalls from
+ synchronizing time.
+
+ |
+
|
+ PAN-308668
+ |
+
+
+ Fixed an issue on Prisma Access Remote Network firewalls where high
+ CPU utilization caused slowness and command timeouts.
+
+ |
+
|
+ PAN-291660
+ |
+
+
+ Fixed an issue where the firewall incorrectly reported the speed of
+ 25G interfaces as 1G when queried using SNMP for the ifHighSpeed OID.
+
+ |
+
|
+ PAN-213491
+ |
+
+
+ Fixed an issue where the management CPU was high, which caused the web
+ interface to be slower than expected.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-321150
+ |
+
+
+ Fixed an issue where the interface remained down after an upgrade.
+
+ |
+
|
+ PAN-320598
+ |
+
+
+ Fixed an issue where internal and external DNS names did not resolve
+ when connected to a GlobalProtect gateway.
+
+ |
+
|
+ PAN-319266
+ |
+
+
+ (Cloud IPS only) Increased scale limit for zone
+ mappings.
+
+ |
+
|
+ PAN-317755
+ |
+
+
+ Fixed an issue on Panorama where selective push operations failed when
+ plugin configurations included access-domain or log-collector
+ references.
+
+ |
+
|
+ PAN-315337
+ |
+
+
+ Fixed an issue where GlobalProtect throughput was reduced after an
+ upgrade.
+
+ |
+
|
+ PAN-315314
+ |
+
+
+ Fixed an issue where, when a push operation from Panorama to the
+ firewall failed, accounting logs stopped forwarding.
+
+ |
+
|
+ PAN-314319
+ |
+
+
+ Added a CLI command to enable and disable AHO software offload
+ optimization.
+
+ |
+
|
+ PAN-313828
+ |
+
+
+ Fixed an issue where the firewall did not forward traffic due to
+ memory issues on a forwarding component.
+
+ |
+
|
+ PAN-313606
+ |
+
+
+ Fixed an issue where Panorama pushed commits took longer than expected
+ to complete without displaying an error message when committing due to
+ slow cloud-app compilation.
+
+ |
+
|
+ PAN-310263
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ enabling TLS1.3 in a decryption profile prevented access to websites.
+
+ |
+
|
+ PAN-310240
+ |
+
+
+ Fixed an issue where software packet buffers were completely utilized
+ when performing a Data Loss Prevention longevity test.
+
+ |
+
|
+ PAN-307976
+ |
+
+
+ (Firewalls in active/active HA configurations only) Fixed an issue where tunnels failed to come up with the error
+ message
+ failed to find a socket for transmission.
+
+ |
+
|
+ PAN-307618
+ |
+
+
+ Added a debug CLI command to address where remote networks for Prisma
+ Access tenants randomly dropped monitoring packets from peer devices,
+ which caused tunnels to be marked as down. This occurred when a CPU
+ core suddenly experienced high utilization.
+
+
+ To utilize this fix, run
+ debug dataplane set ssl-decrypt use-new-peek-window yes.
+
+ |
+
|
+ PAN-292306
+ |
+
+
+ Fixed an issue where the
+ authd
+ process stopped handling RADIUS authentication requests and required a
+ restart.
+
+ |
+
|
+ PAN-234302
+ |
+
+
+ Fixed an issue where commit operations took longer than expected to
+ complete due to EDL timeouts occurring on passive nodes when a service
+ route was enabled.
+
+ |
+