Revise PAN-OS 12.1 issues

This commit is contained in:
2026-04-13 14:14:35 -05:00
parent ebaa13ca39
commit 53a6e311ce
12 changed files with 343 additions and 86 deletions
+41 -1
View File
@@ -7,7 +7,7 @@ version: 12.1.2
## PAN-314201
```caveat
This issue is now resolved. See PAN-OS 12.1.6 Addressed Issues
This issue is now resolved. See PAN-OS 12.1.6 Addressed Issues.
```
On firewalls running PAN-OS 12.1, IPsec VPN tunnels to third-party peer devices may experience intermittent traffic loss during rekey operations. When a new Security Association (SA) forms before the old SA expires, traffic may stop flowing until the older SA naturally expires or you manually clear it. During this time, the output of show vpn ipsec-sa may show two SAs for the same proxy ID. This issue primarily affects tunnels to third-party peer devices and does not occur with Palo Alto Networks to Palo Alto Networks tunnels.
@@ -24,6 +24,28 @@ When the firewall is initially powered on, the FAN-0 LED does not turn on. The f
**Workaround:** Remove and reinsert the fan to turn on the LED.
## PAN-308564
Packets are dropped on SD-WAN interfaces if they require fragmentation for an interface but have the **Don't Fragment (DF)** bit set. This results in unexpected packet drops. This affects client to server sessions when using SD-WAN for NGFW.
**Workaround:** Allow fragmenting packets with DF bit set (`debug dataplane set ip4-ignore-df yes`).
## PAN-308507
```caveat
This issue is now resolved. See PAN-OS 12.1.6 Addressed Issues.
```
Strata Logging Service (SLS) log-forwarding streams intermittently show as inactive. When checking the status of log-forwarding connections, one or more streams are reported as inactive. Restarting the log-receiver process temporarily resolves the issue, but the streams become inactive again after approximately 1-2 hours. This intermittent inactivity results in log loss.
## PAN-307702
```caveat
This issue is now resolved. See PAN-OS 12.1.5 Addressed Issues.
```
When LACP pre-negotiation is enabled on firewalls in HA configurations, traffic passing through aggregate Ethernet (AE) interfaces may be interrupted for several minutes during HA failovers. This occurs because the suspended (formerly active) firewall continues to forward packets for active sessions even after the failover completes, causing MAC address flapping on neighboring switches.
## PAN-305301
```caveat
@@ -34,6 +56,16 @@ The timing of GlobalProtect lifetime expiry or inactivity logout notifications u
**Workaround:** Select **Network > GlobalProtect > Gateways > <gateway-config> > Agent > <agent-config> > Connection Settings** and change the value of both **Notify Before Lifetime Expires (min)** and **Notify Before Inactivity Logout (min)** to 0.
## PAN-304718
```caveat
This issue is now resolved. See PAN-OS 12.1.5 Addressed Issues.
```
When using GlobalProtect Clientless VPN, the firewall may restart unexpectedly, causing routing protocol (OSPF and BGP) outages. This issue occurs during web content processing for clientless VPN sessions.
**Workaround:** To prevent this issue until you can upgrade to a fixed release, disable clientless VPN in your GlobalProtect portal configuration.
## PAN-303959
```caveat
@@ -64,6 +96,14 @@ Panorama cannot display Threat log entries (**Monitor > Logs > Threat**) when th
Workaround: Upgrade the log collectors to the same version as Panorama.
## PAN-300671
```caveat
This issue is now resolved. See PAN-OS 12.1.5 Addressed Issues.
```
Traffic reports that display destination/source IP addresses or destination/source hostnames may incorrectly show IPv4 addresses in IPv6 format (for example, ::ffff:x.x.x.x). This issue affects both custom reports and scheduled reports, including PDF exports.
## PAN-300627
AutoCommit fails when the Traffic Object is used on AI Runtime Security, which consequently impacts the workloads that utilize overlapping subnets.
+44 -4
View File
@@ -14,6 +14,10 @@ On firewalls running PAN-OS 12.1, IPsec VPN tunnels to third-party peer devices
**Workaround:** Manually clear the affected Security Association using the command `clear vpn ipsec-sa tunnel <tunnel-name>` to restore connectivity.
## PAN-313623
On firewalls with TPM (Trusted Platform Module) support, device certificate renewals may fail due to a disk partition being full. This latter occurs because temporary files aren't being deleted during device certificate status checks.
## PAN-309604
```caveat
@@ -32,6 +36,28 @@ When the firewall is initially powered on, the FAN-0 LED does not turn on. The f
**Workaround:** Remove and reinsert the fan to turn on the LED.
## PAN-308564
Packets are dropped on SD-WAN interfaces if they require fragmentation for an interface but have the **Don't Fragment (DF)** bit set. This results in unexpected packet drops. This affects client to server sessions when using SD-WAN for NGFW.
**Workaround:** Allow fragmenting packets with DF bit set (`debug dataplane set ip4-ignore-df yes`).
## PAN-308507
```caveat
This issue is now resolved. See PAN-OS 12.1.6 Addressed Issues.
```
Strata Logging Service (SLS) log-forwarding streams intermittently show as inactive. When checking the status of log-forwarding connections, one or more streams are reported as inactive. Restarting the log-receiver process temporarily resolves the issue, but the streams become inactive again after approximately 1-2 hours. This intermittent inactivity results in log loss.
## PAN-307702
```caveat
This issue is now resolved. See PAN-OS 12.1.5 Addressed Issues.
```
When LACP pre-negotiation is enabled on firewalls in HA configurations, traffic passing through aggregate Ethernet (AE) interfaces may be interrupted for several minutes during HA failovers. This occurs because the suspended (formerly active) firewall continues to forward packets for active sessions even after the failover completes, causing MAC address flapping on neighboring switches.
## PAN-305880
```caveat
@@ -50,6 +76,16 @@ The timing of GlobalProtect lifetime expiry or inactivity logout notifications u
**Workaround:** Select **Network > GlobalProtect > Gateways > <gateway-config> > Agent > <agent-config> > Connection Settings** and change the value of both **Notify Before Lifetime Expires (min)** and **Notify Before Inactivity Logout (min)** to 0.
## PAN-304718
```caveat
This issue is now resolved. See PAN-OS 12.1.5 Addressed Issues.
```
When using GlobalProtect Clientless VPN, the firewall may restart unexpectedly, causing routing protocol (OSPF and BGP) outages. This issue occurs during web content processing for clientless VPN sessions.
**Workaround:** To prevent this issue until you can upgrade to a fixed release, disable clientless VPN in your GlobalProtect portal configuration.
## PAN-304576
```caveat
@@ -90,6 +126,14 @@ Panorama cannot display Threat log entries (**Monitor > Logs > Threat**) when th
Workaround: Upgrade the log collectors to the same version as Panorama.
## PAN-300671
```caveat
This issue is now resolved. See PAN-OS 12.1.5 Addressed Issues.
```
Traffic reports that display destination/source IP addresses or destination/source hostnames may incorrectly show IPv4 addresses in IPv6 format (for example, ::ffff:x.x.x.x). This issue affects both custom reports and scheduled reports, including PDF exports.
## PAN-300627
AutoCommit fails when the Traffic Object is used on AI Runtime Security, which consequently impacts the workloads that utilize overlapping subnets.
@@ -199,10 +243,6 @@ PA-5500 Series firewalls only
The **Monitor** tab in the Web Interface does not display a pop-up to indicate that high-speed log forwarding is enabled and that logs are only viewable from Panorama.
## PAN-298505
After upgrading multi-vsys firewalls, the sequence of the virtual system IDs (vsys ID) changes causing autocommit failures with validation errors. This occurs when the multi-vsys firewall has virtual systems created and managed via Panorama, and the vsys ID sequence is broken because an unused virtual system was deleted and the change was pushed to the firewall.
## PAN-298083
After you change the system mode on an M-700 appliance from Panorama mode to PAN-DB private cloud mode, the snmpd process fails to work.
+44 -4
View File
@@ -14,6 +14,10 @@ On firewalls running PAN-OS 12.1, IPsec VPN tunnels to third-party peer devices
**Workaround:** Manually clear the affected Security Association using the command `clear vpn ipsec-sa tunnel <tunnel-name>` to restore connectivity.
## PAN-313623
On firewalls with TPM (Trusted Platform Module) support, device certificate renewals may fail due to a disk partition being full. This latter occurs because temporary files aren't being deleted during device certificate status checks.
## PAN-312706
```caveat
@@ -40,6 +44,28 @@ When the firewall is initially powered on, the FAN-0 LED does not turn on. The f
**Workaround:** Remove and reinsert the fan to turn on the LED.
## PAN-308564
Packets are dropped on SD-WAN interfaces if they require fragmentation for an interface but have the **Don't Fragment (DF)** bit set. This results in unexpected packet drops. This affects client to server sessions when using SD-WAN for NGFW.
**Workaround:** Allow fragmenting packets with DF bit set (`debug dataplane set ip4-ignore-df yes`).
## PAN-308507
```caveat
This issue is now resolved. See PAN-OS 12.1.6 Addressed Issues.
```
Strata Logging Service (SLS) log-forwarding streams intermittently show as inactive. When checking the status of log-forwarding connections, one or more streams are reported as inactive. Restarting the log-receiver process temporarily resolves the issue, but the streams become inactive again after approximately 1-2 hours. This intermittent inactivity results in log loss.
## PAN-307702
```caveat
This issue is now resolved. See PAN-OS 12.1.5 Addressed Issues.
```
When LACP pre-negotiation is enabled on firewalls in HA configurations, traffic passing through aggregate Ethernet (AE) interfaces may be interrupted for several minutes during HA failovers. This occurs because the suspended (formerly active) firewall continues to forward packets for active sessions even after the failover completes, causing MAC address flapping on neighboring switches.
## PAN-305880
```caveat
@@ -58,6 +84,16 @@ The timing of GlobalProtect lifetime expiry or inactivity logout notifications u
**Workaround:** Select **Network > GlobalProtect > Gateways > <gateway-config> > Agent > <agent-config> > Connection Settings** and change the value of both **Notify Before Lifetime Expires (min)** and **Notify Before Inactivity Logout (min)** to 0.
## PAN-304718
```caveat
This issue is now resolved. See PAN-OS 12.1.5 Addressed Issues.
```
When using GlobalProtect Clientless VPN, the firewall may restart unexpectedly, causing routing protocol (OSPF and BGP) outages. This issue occurs during web content processing for clientless VPN sessions.
**Workaround:** To prevent this issue until you can upgrade to a fixed release, disable clientless VPN in your GlobalProtect portal configuration.
## PAN-304576
```caveat
@@ -98,6 +134,14 @@ Panorama cannot display Threat log entries (**Monitor > Logs > Threat**) when th
Workaround: Upgrade the log collectors to the same version as Panorama.
## PAN-300671
```caveat
This issue is now resolved. See PAN-OS 12.1.5 Addressed Issues.
```
Traffic reports that display destination/source IP addresses or destination/source hostnames may incorrectly show IPv4 addresses in IPv6 format (for example, ::ffff:x.x.x.x). This issue affects both custom reports and scheduled reports, including PDF exports.
## PAN-300627
AutoCommit fails when the Traffic Object is used on AI Runtime Security, which consequently impacts the workloads that utilize overlapping subnets.
@@ -207,10 +251,6 @@ PA-5500 Series firewalls only
The **Monitor** tab in the Web Interface does not display a pop-up to indicate that high-speed log forwarding is enabled and that logs are only viewable from Panorama.
## PAN-298505
After upgrading multi-vsys firewalls, the sequence of the virtual system IDs (vsys ID) changes causing autocommit failures with validation errors. This occurs when the multi-vsys firewall has virtual systems created and managed via Panorama, and the vsys ID sequence is broken because an unused virtual system was deleted and the change was pushed to the firewall.
## PAN-298083
After you change the system mode on an M-700 appliance from Panorama mode to PAN-DB private cloud mode, the snmpd process fails to work.
+18
View File
@@ -37,6 +37,10 @@ When a firewall node is removed from a PA-5500 Series cluster, after the cluster
- Manually assign zone configurations to ports eth1/1 (for example, untrust) and eth1/2 (for example, trust), then open and close security policy rule1 without making changes, and **Commit**.
- Delete the default rule and the default virtual wire Ethernet interfaces, then commit.
## PAN-313623
On firewalls with TPM (Trusted Platform Module) support, device certificate renewals may fail due to a disk partition being full. This latter occurs because temporary files aren't being deleted during device certificate status checks.
## PAN-312247
In generated PDF upgrade check reports, long remediation URLs might be truncated due to UI framework export limitations, leaving only the first line hyperlinked. However, these links remain fully functional within the Panorama web interface. The PDF link directs to the correct destination if the complete URL is copied from the PDF and pasted in the browser.
@@ -59,6 +63,20 @@ When the firewall is initially powered on, the FAN-0 LED does not turn on. The f
**Workaround:** Remove and reinsert the fan to turn on the LED.
## PAN-308564
Packets are dropped on SD-WAN interfaces if they require fragmentation for an interface but have the **Don't Fragment (DF)** bit set. This results in unexpected packet drops. This affects client to server sessions when using SD-WAN for NGFW.
**Workaround:** Allow fragmenting packets with DF bit set (`debug dataplane set ip4-ignore-df yes`).
## PAN-308507
```caveat
This issue is now resolved. See PAN-OS 12.1.6 Addressed Issues.
```
Strata Logging Service (SLS) log-forwarding streams intermittently show as inactive. When checking the status of log-forwarding connections, one or more streams are reported as inactive. Restarting the log-receiver process temporarily resolves the issue, but the streams become inactive again after approximately 1-2 hours. This intermittent inactivity results in log loss.
## PAN-300850
Manual scheduling of cloud verdicts is required if a new host in an Host Compliance Service-enabled environment has a refresh event entry without a corresponding update event entry.
+10
View File
@@ -27,6 +27,10 @@ When a firewall node is removed from a PA-5500 Series cluster, after the cluster
- Manually assign zone configurations to ports eth1/1 (for example, untrust) and eth1/2 (for example, trust), then open and close security policy rule1 without making changes, and **Commit**.
- Delete the default rule and the default virtual wire Ethernet interfaces, then commit.
## PAN-313623
On firewalls with TPM (Trusted Platform Module) support, device certificate renewals may fail due to a disk partition being full. This latter occurs because temporary files aren't being deleted during device certificate status checks.
## PAN-312247
In generated PDF upgrade check reports, long remediation URLs might be truncated due to UI framework export limitations, leaving only the first line hyperlinked. However, these links remain fully functional within the Panorama web interface. The PDF link directs to the correct destination if the complete URL is copied from the PDF and pasted in the browser.
@@ -49,6 +53,12 @@ When the firewall is initially powered on, the FAN-0 LED does not turn on. The f
**Workaround:** Remove and reinsert the fan to turn on the LED.
## PAN-308564
Packets are dropped on SD-WAN interfaces if they require fragmentation for an interface but have the **Don't Fragment (DF)** bit set. This results in unexpected packet drops. This affects client to server sessions when using SD-WAN for NGFW.
**Workaround:** Allow fragmenting packets with DF bit set (`debug dataplane set ip4-ignore-df yes`).
## PAN-300850
Manual scheduling of cloud verdicts is required if a new host in an Host Compliance Service-enabled environment has a refresh event entry without a corresponding update event entry.