Revise PAN-OS 12.1 issues
This commit is contained in:
@@ -37,6 +37,10 @@ When a firewall node is removed from a PA-5500 Series cluster, after the cluster
|
||||
- Manually assign zone configurations to ports eth1/1 (for example, untrust) and eth1/2 (for example, trust), then open and close security policy rule1 without making changes, and **Commit**.
|
||||
- Delete the default rule and the default virtual wire Ethernet interfaces, then commit.
|
||||
|
||||
## PAN-313623
|
||||
|
||||
On firewalls with TPM (Trusted Platform Module) support, device certificate renewals may fail due to a disk partition being full. This latter occurs because temporary files aren't being deleted during device certificate status checks.
|
||||
|
||||
## PAN-312247
|
||||
|
||||
In generated PDF upgrade check reports, long remediation URLs might be truncated due to UI framework export limitations, leaving only the first line hyperlinked. However, these links remain fully functional within the Panorama web interface. The PDF link directs to the correct destination if the complete URL is copied from the PDF and pasted in the browser.
|
||||
@@ -59,6 +63,20 @@ When the firewall is initially powered on, the FAN-0 LED does not turn on. The f
|
||||
|
||||
**Workaround:** Remove and reinsert the fan to turn on the LED.
|
||||
|
||||
## PAN-308564
|
||||
|
||||
Packets are dropped on SD-WAN interfaces if they require fragmentation for an interface but have the **Don't Fragment (DF)** bit set. This results in unexpected packet drops. This affects client to server sessions when using SD-WAN for NGFW.
|
||||
|
||||
**Workaround:** Allow fragmenting packets with DF bit set (`debug dataplane set ip4-ignore-df yes`).
|
||||
|
||||
## PAN-308507
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. See PAN-OS 12.1.6 Addressed Issues.
|
||||
```
|
||||
|
||||
Strata Logging Service (SLS) log-forwarding streams intermittently show as inactive. When checking the status of log-forwarding connections, one or more streams are reported as inactive. Restarting the log-receiver process temporarily resolves the issue, but the streams become inactive again after approximately 1-2 hours. This intermittent inactivity results in log loss.
|
||||
|
||||
## PAN-300850
|
||||
|
||||
Manual scheduling of cloud verdicts is required if a new host in an Host Compliance Service-enabled environment has a refresh event entry without a corresponding update event entry.
|
||||
|
||||
Reference in New Issue
Block a user