Revise PAN-OS 12.1 issues
This commit is contained in:
@@ -14,6 +14,10 @@ On firewalls running PAN-OS 12.1, IPsec VPN tunnels to third-party peer devices
|
||||
|
||||
**Workaround:** Manually clear the affected Security Association using the command `clear vpn ipsec-sa tunnel <tunnel-name>` to restore connectivity.
|
||||
|
||||
## PAN-313623
|
||||
|
||||
On firewalls with TPM (Trusted Platform Module) support, device certificate renewals may fail due to a disk partition being full. This latter occurs because temporary files aren't being deleted during device certificate status checks.
|
||||
|
||||
## PAN-309604
|
||||
|
||||
```caveat
|
||||
@@ -32,6 +36,28 @@ When the firewall is initially powered on, the FAN-0 LED does not turn on. The f
|
||||
|
||||
**Workaround:** Remove and reinsert the fan to turn on the LED.
|
||||
|
||||
## PAN-308564
|
||||
|
||||
Packets are dropped on SD-WAN interfaces if they require fragmentation for an interface but have the **Don't Fragment (DF)** bit set. This results in unexpected packet drops. This affects client to server sessions when using SD-WAN for NGFW.
|
||||
|
||||
**Workaround:** Allow fragmenting packets with DF bit set (`debug dataplane set ip4-ignore-df yes`).
|
||||
|
||||
## PAN-308507
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. See PAN-OS 12.1.6 Addressed Issues.
|
||||
```
|
||||
|
||||
Strata Logging Service (SLS) log-forwarding streams intermittently show as inactive. When checking the status of log-forwarding connections, one or more streams are reported as inactive. Restarting the log-receiver process temporarily resolves the issue, but the streams become inactive again after approximately 1-2 hours. This intermittent inactivity results in log loss.
|
||||
|
||||
## PAN-307702
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. See PAN-OS 12.1.5 Addressed Issues.
|
||||
```
|
||||
|
||||
When LACP pre-negotiation is enabled on firewalls in HA configurations, traffic passing through aggregate Ethernet (AE) interfaces may be interrupted for several minutes during HA failovers. This occurs because the suspended (formerly active) firewall continues to forward packets for active sessions even after the failover completes, causing MAC address flapping on neighboring switches.
|
||||
|
||||
## PAN-305880
|
||||
|
||||
```caveat
|
||||
@@ -50,6 +76,16 @@ The timing of GlobalProtect lifetime expiry or inactivity logout notifications u
|
||||
|
||||
**Workaround:** Select **Network > GlobalProtect > Gateways > <gateway-config> > Agent > <agent-config> > Connection Settings** and change the value of both **Notify Before Lifetime Expires (min)** and **Notify Before Inactivity Logout (min)** to 0.
|
||||
|
||||
## PAN-304718
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. See PAN-OS 12.1.5 Addressed Issues.
|
||||
```
|
||||
|
||||
When using GlobalProtect Clientless VPN, the firewall may restart unexpectedly, causing routing protocol (OSPF and BGP) outages. This issue occurs during web content processing for clientless VPN sessions.
|
||||
|
||||
**Workaround:** To prevent this issue until you can upgrade to a fixed release, disable clientless VPN in your GlobalProtect portal configuration.
|
||||
|
||||
## PAN-304576
|
||||
|
||||
```caveat
|
||||
@@ -90,6 +126,14 @@ Panorama cannot display Threat log entries (**Monitor > Logs > Threat**) when th
|
||||
|
||||
Workaround: Upgrade the log collectors to the same version as Panorama.
|
||||
|
||||
## PAN-300671
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. See PAN-OS 12.1.5 Addressed Issues.
|
||||
```
|
||||
|
||||
Traffic reports that display destination/source IP addresses or destination/source hostnames may incorrectly show IPv4 addresses in IPv6 format (for example, ::ffff:x.x.x.x). This issue affects both custom reports and scheduled reports, including PDF exports.
|
||||
|
||||
## PAN-300627
|
||||
|
||||
AutoCommit fails when the Traffic Object is used on AI Runtime Security, which consequently impacts the workloads that utilize overlapping subnets.
|
||||
@@ -199,10 +243,6 @@ PA-5500 Series firewalls only
|
||||
|
||||
The **Monitor** tab in the Web Interface does not display a pop-up to indicate that high-speed log forwarding is enabled and that logs are only viewable from Panorama.
|
||||
|
||||
## PAN-298505
|
||||
|
||||
After upgrading multi-vsys firewalls, the sequence of the virtual system IDs (vsys ID) changes causing autocommit failures with validation errors. This occurs when the multi-vsys firewall has virtual systems created and managed via Panorama, and the vsys ID sequence is broken because an unused virtual system was deleted and the change was pushed to the firewall.
|
||||
|
||||
## PAN-298083
|
||||
|
||||
After you change the system mode on an M-700 appliance from Panorama mode to PAN-DB private cloud mode, the snmpd process fails to work.
|
||||
|
||||
Reference in New Issue
Block a user