Revise PAN-OS 12.1 issues
This commit is contained in:
@@ -7,7 +7,7 @@ version: 12.1.2
|
||||
## PAN-314201
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. See PAN-OS 12.1.6 Addressed Issues
|
||||
This issue is now resolved. See PAN-OS 12.1.6 Addressed Issues.
|
||||
```
|
||||
|
||||
On firewalls running PAN-OS 12.1, IPsec VPN tunnels to third-party peer devices may experience intermittent traffic loss during rekey operations. When a new Security Association (SA) forms before the old SA expires, traffic may stop flowing until the older SA naturally expires or you manually clear it. During this time, the output of show vpn ipsec-sa may show two SAs for the same proxy ID. This issue primarily affects tunnels to third-party peer devices and does not occur with Palo Alto Networks to Palo Alto Networks tunnels.
|
||||
@@ -24,6 +24,28 @@ When the firewall is initially powered on, the FAN-0 LED does not turn on. The f
|
||||
|
||||
**Workaround:** Remove and reinsert the fan to turn on the LED.
|
||||
|
||||
## PAN-308564
|
||||
|
||||
Packets are dropped on SD-WAN interfaces if they require fragmentation for an interface but have the **Don't Fragment (DF)** bit set. This results in unexpected packet drops. This affects client to server sessions when using SD-WAN for NGFW.
|
||||
|
||||
**Workaround:** Allow fragmenting packets with DF bit set (`debug dataplane set ip4-ignore-df yes`).
|
||||
|
||||
## PAN-308507
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. See PAN-OS 12.1.6 Addressed Issues.
|
||||
```
|
||||
|
||||
Strata Logging Service (SLS) log-forwarding streams intermittently show as inactive. When checking the status of log-forwarding connections, one or more streams are reported as inactive. Restarting the log-receiver process temporarily resolves the issue, but the streams become inactive again after approximately 1-2 hours. This intermittent inactivity results in log loss.
|
||||
|
||||
## PAN-307702
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. See PAN-OS 12.1.5 Addressed Issues.
|
||||
```
|
||||
|
||||
When LACP pre-negotiation is enabled on firewalls in HA configurations, traffic passing through aggregate Ethernet (AE) interfaces may be interrupted for several minutes during HA failovers. This occurs because the suspended (formerly active) firewall continues to forward packets for active sessions even after the failover completes, causing MAC address flapping on neighboring switches.
|
||||
|
||||
## PAN-305301
|
||||
|
||||
```caveat
|
||||
@@ -34,6 +56,16 @@ The timing of GlobalProtect lifetime expiry or inactivity logout notifications u
|
||||
|
||||
**Workaround:** Select **Network > GlobalProtect > Gateways > <gateway-config> > Agent > <agent-config> > Connection Settings** and change the value of both **Notify Before Lifetime Expires (min)** and **Notify Before Inactivity Logout (min)** to 0.
|
||||
|
||||
## PAN-304718
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. See PAN-OS 12.1.5 Addressed Issues.
|
||||
```
|
||||
|
||||
When using GlobalProtect Clientless VPN, the firewall may restart unexpectedly, causing routing protocol (OSPF and BGP) outages. This issue occurs during web content processing for clientless VPN sessions.
|
||||
|
||||
**Workaround:** To prevent this issue until you can upgrade to a fixed release, disable clientless VPN in your GlobalProtect portal configuration.
|
||||
|
||||
## PAN-303959
|
||||
|
||||
```caveat
|
||||
@@ -64,6 +96,14 @@ Panorama cannot display Threat log entries (**Monitor > Logs > Threat**) when th
|
||||
|
||||
Workaround: Upgrade the log collectors to the same version as Panorama.
|
||||
|
||||
## PAN-300671
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. See PAN-OS 12.1.5 Addressed Issues.
|
||||
```
|
||||
|
||||
Traffic reports that display destination/source IP addresses or destination/source hostnames may incorrectly show IPv4 addresses in IPv6 format (for example, ::ffff:x.x.x.x). This issue affects both custom reports and scheduled reports, including PDF exports.
|
||||
|
||||
## PAN-300627
|
||||
|
||||
AutoCommit fails when the Traffic Object is used on AI Runtime Security, which consequently impacts the workloads that utilize overlapping subnets.
|
||||
|
||||
Reference in New Issue
Block a user