diff --git a/reference/PAN-OS/addressed/12.2.2.html b/reference/PAN-OS/addressed/12.2.2.html new file mode 100644 index 0000000..cc71f3a --- /dev/null +++ b/reference/PAN-OS/addressed/12.2.2.html @@ -0,0 +1,38 @@ +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-242777
+ |
+
+
+ Fixed an issue where running debug online diagnostics run on a 5G
+ supported PA-400 firewall models reported "Missing device on I2C bus"
+ errors and did not execute cellular modem diagnostic tests. This
+ occurred because the diagnostics script used an incorrect I2C device
+ list for the 5G supported PA-400 hardware variants and did not
+ recognize it as a cellular-capable platform. With this fix, the I2C
+ scan correctly reflects the 5G supported PA-400 hardware configuration
+ and cellular modem tests run as expected.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WIF-495
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, edits made to an existing data
+ filtering profile (Objects > DLP > Data Filtering Profiles) can result in matching traffic not being detected by Enterprise
+ DLP.
+
+ |
+
|
+ WF500-5754
+ |
+
+
+ In WildFire appliance clusters, issuing the
+ show cluster controller CLI command
+ generates an error when an IPv6 address is configured for the
+ management interface but not for the cluster interface.
+
+
+ Workaround: Ensure all WildFire appliance
+ interfaces that are enabled use matching protocols (all IPv4 or all
+ IPv6).
+
+ |
+
|
+ WF500-5632
+ |
+
+
+ The number of registered WildFire appliances reported in Panorama
+ () does not accurately reflect the current status of connected
+ WildFire appliances.
+
+ |
+
|
+ PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues.
+
+ |
+
+
+ A race condition may cause the dataplane to restart unexpectedly when
+ a zip decompression offload result is returned for a session that has
+ already closed. The session state is not validated before processing
+ the result because the offload result does not follow the fastpath
+ where these checks are normally performed.
+
+
+ Workaround: Disable zip hardware offloading (may
+ cause higher CPU usage).
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See PAN-OS 10.2.13-h18 Addressed Issuesand
+ PAN-OS 10.2.16-h6 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-297610
+ |
+
+
+ A firewall may become unresponsive after an upgrade due to the
+ fsck command scanning drive
+ partitions in parallel with the root partition, causing the process to
+ take an extended amount of time.
+
+ |
+
|
+ PAN-297295
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent
+ process restarts multiple times and exhausts its restart limit,
+ resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-295803
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-295255
+ |
+
+
+ Palo Alto Networks next-generation firewalls may experience service
+ disruptions due to all_task process
+ crashes when deployed in environments having non-uniform MTU and are
+ terminating IPSec tunnels.
+
+ |
+
|
+ PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues.
+
+ |
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM)
+ condition due to a memory leak and displays an error message. This
+ issue causes the device to crash and reboot unexpectedly.
+
+ |
+
|
+ PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues
+
+ |
+
+
+ A memory leak in the configd process
+ might lead to an active firewall to reboot due to an Out-of-Memory
+ (OOM) condition. This issue is observed when specific status commands,
+ such as
+ request log-collector forwarding status
+ are executed at high frequencies.
+
+ |
+
|
+ PAN-288097
+ |
+
+
+ (Firewalls in HA configurations only) Routed
+ process may stop responding after changing MTU or any link parameters
+ when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-286231
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-284073
+ |
+
+
+ The firewall web interface becomes inaccessible and commits fail.
+
+ |
+
|
+ PAN-284067
+ |
+
+
+ A cumulative memory leak in the
+ devsrvr
+ process gets progressively worse whenever the CLI command
+ show running application statistics
+ is issued. This memory leak will gradually consume system memory and
+ produce an out-of-memory (OOM) condition, leading to an eventual
+ firewall reboot.
+
+
+ Workaround: Avoid using the CLI command:
+ show running application statistics.
+
+ |
+
|
+ PAN-281370
+ |
+
+
+ The Advanced WildFire Inline ML models
+ OOXML and
+ Mach-O erroneously display as being
+ available from the CLI; however, they are only available on PAN-OS
+ 11.1.3 and later releases.
+
+ |
+
|
+ PAN-273158
+ |
+
+
+ (PA-7000 Series firewalls only) Due to an
+ incorrect configuration on the ASIC, receiving a mix of jumbo and
+ non-jumbo packets may cause silent packet drops or application
+ slowness.
+
+ |
+
|
+ PAN-264281
+ |
+
+
+ When upgrading a ZTP firewall from PAN-OS 10.2 to PAN-OS 11.1 or later
+ versions, if you use the
+ To SW Version column to specify the
+ target PAN-OS version, the upgrade process downloads and installs the
+ intermediary base version containing an expired root certificate. This
+ causes the ZTP firewall to lose connection with Panorama
+
+
+ Workaround: Follow the standard upgrade process
+ from Panorama, which you use for non-ZTP firewalls, to upgrade to the
+ target PAN-OS version that contains the valid root certificate.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
| PAN-259769 | +
+
+ GlobalProtect portal is not accessible via a web browser and the app
+ displays the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-243951
+ |
+
+
+ On the Panorama management sever in an active/passive High
+ Availability (HA) configuration, managed devices () display as out-of-sync on the
+ passive HA peer when configuration changes are made to the SD-WAN
+ () configuration on the active HA peer.
+
+
+ Workaround: Manually synchronize the Panorama HA
+ peers.
+
+
|
+
|
+ PAN-241536
+ |
+
+
+ On the Panorama management server, a user with an Admin Role is unable
+ to modify or add filters to profiles under
+ , despite having the necessary read and write privileges.
+
+ |
+
|
+ PAN-234408
+ |
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for
+ ChatGPT from traffic forwarded to the DLP cloud service from an NGFW.
+
+ |
+
|
+ PAN-229702
+ |
+
+
+ After upgrading a Panorama HA pair to PAN-OS 11.1, the ElasticSearch
+ connectivity might fail to establish. The issue occurs because the
+ client certificate on one of the Panorama devices does not have the
+ necessary Extended Key Usage (EKU) set for server authentication,
+ which is required for secure TLS communication.
+
+
+ Workaround:Contact Customer Support to renew the
+ root client certificate.
+
+ |
+
|
+ PAN-227344
+ |
+
+
+ On the Panorama management server, PDF Summary Reports () display no data and are blank when predefined reports are included
+ in the summary report.
+
+ |
+
|
+ PAN-225337
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, the configuration push to a
+ multi-vsys firewall fails if you:
+
+
+ Workaround: Select
+
+ and edit the Panorama Settings to enable one of the following:
+
+
+ Alternatively, you can remove the duplicate address objects from the
+ device group configuration to allow only the
+ Shared objects in your
+ configuration.
+
+ |
+
|
+ PAN-223488
+
+ This issue is now resolved. See
+ PAN-OS 10.2.7 Addressed Issues.
+
+ |
+ + Closed ElasticSearch shards are not deleted from a Panorama M-Series or + virtual appliance. This causes the ElasticSearch shard purging to not + work as expected, resulting in high disk usage. + | +
|
+ PAN-223365
+ |
+
+
+ The Panorama management server is unable to query any logs if the
+ ElasticSearch health status for any Log Collector (
+ is degraded.
+
+
+ Workaround:
+ Log in to the Log Collector CLI
+ and restart ElasticSearch.
+
+
+
+
+
+ |
+
|
+ PAN-222586
+ |
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus,
+ Forward Methods, and Built-In Actions for Correlation Log settings
+ () are not displayed and cannot be configured.
+
+ |
+
|
+ PAN-222253
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, policy rulebase reordering when you
+ View Rulebase by Groups () does not persist if you reorder the policy rulebase by dragging and
+ dropping individual policy rules and then moving the entire tag group.
+
+ |
+
|
+ PAN-221775
+ |
+
+
+ A Malformed Request error is
+ displayed when you
+ Test Connection for an email server
+ profile () using SMTP over TLS and the
+ Password includes an ampersand
+ (&).
+
+ |
+
|
+ PAN-221015
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ On M-600 appliances in Panorama or Log Collector mode, the
+ es-1 and
+ es-2 ElasticSearch processes fail
+ to restart when the M-600 appliance is rebooted. The results in the
+ Managed Collector ES health
+ status () to be degraded.
+
+
+ Workaround:
+ Log in to the Panorama or Log Collector CLI
+ experiencing degraded ElasticSearch health and restart all
+ ElasticSearch processes.
+
+
+
+
+
+ |
+
|
+ PAN-219644
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ Firewalls forwarding logs to a syslog server over TLS () use the default Palo Alto Networks certificate instead of the
+ custom certificate configured on the firewall.
+
+ |
+
|
+ PAN-218521
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ The ElasticSearch process on the M-600 appliance in Log Collector mode
+ may enter a continuous reboot cycle. This results in the M-600
+ appliance becoming unresponsive, consuming logging disk space, and
+ preventing new log ingestion.
+
+ |
+
|
+ PAN-217307
+
+ This issue is now resolved. See PAN-OS 10.2.11 Addressed Issues.
+
+ |
+
+
+ The following Security policy rule () filters return no results:
+
+
+ log-start eq no
+
+ log-end eq no
+ log-end eq yes
+ |
+
|
+ PAN-215778
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues.
+
+ |
+
+
+ On the M-600 appliance in Management Only mode, XML API Get requests
+ for /config fail with the
+ following error due to exceeding the
+ total configuration size
+ supported on the M-600 appliance.
+
+
+
+
+
+ |
+
|
+ PAN-215082
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ M-300 and M-700 appliances may generate erroneous system logs () to alert that the M-Series appliance memory usage limits are
+ reached.
+
+ |
+
|
+ PAN-213746
+ |
+
+
+ On the Panorama management server, the
+ Hostkey displayed as
+ undefined undefined if you
+ override an SSH Service Profile () Hostkey configured in a Template from the Template Stack.
+
+ |
+
|
+ PAN-213119
+ |
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you
+ view the Block IP list ():
+
+
+ show -> dis-block-table is unexpected
+
+ |
+
|
+ PAN-212889
+
+ This issue is now resolved. See
+ PAN-OS 10.2.14 Addressed Issues
+
+ |
+
+
+ On the Panorama management server, different threat names are used
+ when querying the same threat in the Threat Monitor () and ACC. This results in the ACC
+ displaying
+ no data to display when you are
+ redirected to the ACC after clicking a threat name in the Threat
+ Monitor and filtering the same threat name in the Global Filters.
+
+ |
+
|
+ PAN-212533
+ |
+
+
+ Modifying the Administrator Type for
+ an existing administrator (
+ or
+ ) from Superuser to a
+ Role-Based custom admin, or vice
+ versa, does not modify the access privileges of the administrator.
+
+ |
+
|
+ PAN-211531
+ |
+ + On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (). + | +
|
+ PAN-209937
+ |
+
+
+ Certificate-based authentication for administrator accounts may be
+ unable to log into the Panorama or firewall web interface with the
+ following error:
+
+
+ Bad Request - Your browser sent a request that this server could
+ not understand
+
+ |
+
|
+ PAN-208325
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues.
+
+ |
+
+
+ The following NextGen firewalls and Panorama management server models
+ are unable to automatically renew the device certificate (
+ or
+ ).
+
+
+ Workaround: Log in to the
+ firewall CLI
+ or
+ Panorama CLI
+ and fetch the device certificate.
+
+
+
+
+
+ |
+
|
+ PAN-207629
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, selective push fails to managed
+ firewalls if the managed firewalls are enabled with multiple vsys and
+ the Push Scope contains shared objects in device groups.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the
+ configd process crashes. This
+ results in the Dedicated Log Collector losing connectivity to Panorama
+ despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-206268
+ |
+
+
+ On the Panorama management server, the Auth Key field was erroneously
+ displayed when you configure the Panorama Settings () as part of a template or template stack configuration.
+
+ |
+
|
+ PAN-206253
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ For PA-3400 Series firewalls, the default log rate is set too low and
+ the max configurable log rate is incorrectly capped resulting in the
+ firewall not generating more than 6,826 logs per second.
+
+ |
+
|
+ PAN-206243
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ The PA-220 firewall reaches the maximum disk usage capacity multiple a
+ day that requires a disk cleanup. A critical system log () is generated each time the firewall reaches maximum disk usage
+ capacity.
+
+ |
+
|
+ PAN-205187
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ ElasticSearch may not start properly when a newly installed Panorama
+ virtual appliance powers on for the first time, resulting in the
+ Panorama virtual appliance being unable to query logs forwarded from
+ the managed firewall to a Log Collector.
+
+
+ Workaround:
+ Log in to the Panorama CLI
+ and start the PAN-OS software.
+
+
+
+
+
+ |
+
|
+ PAN-204663
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, you are unable to Context Switch
+ from one managed firewall to another.
+
+
+ Workaround: After you Context Switch to a managed
+ firewall, you must first Context Switch back to Panorama before you
+ can continue to Context Switch to a different managed firewall.
+
+ |
+
|
+ PAN-201855
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, cloning any template () corrupts certificates () with the
+ Block Private Key Export setting
+ enabled across all templates. This results in managed firewalls
+ experiencing issues wherever the corrupted certificate is referenced.
+
+
+ For example, you have template A, B, and C where templates A and B
+ have certificates with the
+ Block Private Key Export setting
+ enabled. Cloning template C corrupts the certificates with
+ Block Private Key Export setting
+ enabled in templates A and B.
+
+
+ Workaround: After cloning a template, delete and
+ re-import the corrupted certificates.
+
+ |
+
|
+ PAN-199557
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues.
+
+ |
+
+
+ On M-600 appliances in an Active/Passive high availability (HA)
+ configuration, the
+ configd process restarts due to a
+ memory leak on the
+ Active Panorama HA peer. This
+ causes the Panorama web interface and CLI to become unresponsive.
+
+
+ Workaround: Manually reboot the
+ Active Panorama HA peer.
+
+ |
+
|
+ PAN-197341
+ |
+
+
+ On the Panorama management server, if you create multiple device group
+ Objects with the same name in the
+ Shared device group and any additional device groups () under the same device group hierarchy that are used in one or more
+ Policies, renaming the object with a
+ shared name in any device group causes the object name to change in
+ the policies where it is used. This issue applies only to device group
+ objects that can be referenced in a Security policy rule.
+
+ For example:
+
+ Changing the name of the address object in the
+ Shared device group causes the
+ references in the Policy rule to use the renamed
+ Shared object instead of the
+ device group object.
+
+ |
+
|
+ PAN-197097
+ |
+
+
+ Large Scale VPN (LSVPN) does not support IPv6 addresses on the
+ satellite firewall.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-196720
+ |
+
+
+ During the CN-Series firewall deployment on Oracle OKEplatform, when
+ you delete the deployment by deleting yamls, the MP/DP pods are stuck
+ in Terminating state.
+
+
+ Workaround: Delete the CN-Series DP pods, MP pods,
+ and then the pan-cni yaml file in a sequential order.
+
+ |
+
|
+ PAN-194826
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ (WF-500 appliance only) System log forwarding
+ does not work over a TLS connection.
+
+ |
+
|
+ PAN-194519
+ |
+
+
+ (PA-5450 firewall only) Trying to configure a
+ custom payload format under
+
+ yields a Javascript error.
+
+ |
+
|
+ PAN-194515
+ |
+
+
+ (PA-5450 firewall only) The Panorama web
+ interface does not display any predefined template stack variables in
+ the dropdown menu under
+ .
+
+
+ Workaround: Configure the log interface IP address
+ on the individual firewall web interface instead of on Panorama.
+
+ |
+
|
+ PAN-193251
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ If SAML is configured as the authentication method for GlobalProtect,
+ authentication on the Portal page is not successful in the browser.
+
+
+ Workaround: Use the GlobalProtect app installed on
+ the endpoint to authenticate.
+
+ |
+
|
+ PAN-192403
+ |
+
+
+ (PA-5450 firewall only) There is no commit
+ warning in the web interface when configuring the management interface
+ and logging interface in the same subnetwork. Having both interfaces
+ in the same subnetwork can cause routing and connectivity issues.
+
+ |
+
|
+ PAN-191570
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ The Traffic Activity and SSL/TLS widgets in the
+ ACC erroneously display
+ Report Error if there is no SSL
+ data to display.
+
+ |
+
|
+ PAN-190727
+ |
+
+
+ (PA-5450 firewall only) Documentation for
+ configuring the log interface is unavailable on the web interface and
+ in the PAN-OS Administrator’s Guide.
+
+ |
+
|
+ PAN-190435
+ |
+
+
+ When you Commit a configuration
+ change, the Task Manager commit
+ Status goes directly from
+ 0% to
+ Completed and does accurately
+ reflect the commit job progress.
+
+ |
+
|
+ PAN-190311
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues.
+
+ |
+
+
+ (PA-220 and PA-220R firewalls and PA-800 Series firewalls only) There is an issue where management connectivity to the firewall is
+ lost due to the expiration of the DHCP lease, which causes the IP
+ configuration on the management port to be purged.
+
+ |
+
|
+ PAN-189425
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server,
+ Export Panorama and devices config bundle
+ () fails to export. When the export fails, you are redirected to a new
+ window and the following error is displayed:
+
+
+ Failed to redirect error to /var/log/pan/appweb3-panmodule.log
+ (Permission denied)
+
+ |
+
|
+ PAN-189395
+
+ This issue is now resolved. See PAN-OS 10.2.2 Addressed Issues.
+
+ |
+
+
+ Running any version of PAN-OS 10.2 on a PA-400 Series firewall can
+ cause the dataplane process to restart unexpectedly and trigger a
+ crash.
+
+ |
+
|
+ PAN-189380
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ After you successfully upgrade a PA-3000 Series firewall to PAN-OS
+ 10.2.0 or later release and Enterprise data loss prevention (DLP)
+ plugin 3.0.0 or later release, the first configuration push from the
+ Panorama management server causes the firewall dataplane to crash.
+
+
+ Workaround: Restart the firewall to restore
+ dataplane functionality.
+
+
|
+
|
+ PAN-189361
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues.
+
+ |
+
+
+ Panorama is unable to distribute antivirus signature updates to
+ firewalls with only an Advanced Threat Prevention license. Firewalls
+ with previously installed and active Threat Prevention license are
+ unaffected.
+
+ |
+
|
+ PAN-189298
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues.
+
+ |
+
+
+ On deploying the HA with 10.2.0-98 in Packet-mmap mode, the session
+ sync for an existing session fails after restarting an active DP in
+ Packet-mmap mode.
+
+ |
+
|
+ PAN-189214
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues.
+
+ |
+
+
+ When the Advanced Threat Prevention license is present on a firewall
+ without a Threat Prevention license, the antivirus signature update
+ packages that are normally available to install under
+
+ are not displayed.
+
+
+ Workaround: Use the
+ request anti-virus upgrade {info | download | install}
+ CLI commands to retrieve a list of available antivirus updates and the
+ download and installation status, download specific antivirus
+ packages, and to install antivirus packages.Optionally, you can
+ schedule recurring automatic updates using the following CLI command:
+ set deviceconfig system update-schedule anti-virus recurring.
+
+ |
+
|
+ PAN-189206
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues.
+
+ |
+
+
+ Device Group and Template administrator roles don't support a context
+ switch between the Panorama and firewall web interface.
+
+
+ Workaround: Use a Superuser or Panorama
+ administrator role to context switch.
+
+ |
+
|
+ PAN-189111
+ |
+
+
+ After deleting an MP pod and it comes up, the
+ show routing command output
+ appears empty and traffic stops working.
+
+ |
+
|
+ PAN-189106
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, you must uninstall the ZTP Plugin
+ 2.0 before you can successfully downgrade to PAN-OS 10.1. After
+ successful downgrade, you must reinstall the latest ZTP Plugin 1.0
+ version.
+
+
+ Workaround: Before you downgrade Panorama to
+ PAN-OS 10.1, uninstall ZTP Plugin 2.0. After you successfully
+ downgrade Panorama to PAN-OS 10.1, re-install ZTP Plugin 1.0 and
+ re-enable ZTP functionality.
+
+
|
+
|
+ PAN-189076
+ |
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a
+ broadcast link and a designated router (DR) priority of 0 (zero) are
+ stuck in a two-way state after HA failover.
+
+
+ Workaround: Configure at least one OSPFv3 neighbor
+ with a non-zero priority setting in the same broadcast domain.
+
+ |
+
|
+ PAN-189057
+
+ This issue is now resolved. See PAN-OS 10.2.2 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, Panorama enters a
+ non-functional state due to
+ php.debug.log life taking up too
+ much space.
+
+
+ Workaround: Disable the debug flag for Panorama.
+
+
|
+
|
+ PAN-189032
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues.
+
+ |
+
+
+ When the firewall has Advanced Routing enabled, an OSPFv3 interface
+ configured with the p2mp link type causes the commit to fail.
+
+ |
+
|
+ PAN-188956
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues.
+
+ |
+
+
+ After successful upgrade to PAN-OS 10.2, logging in to the firewall or
+ Panorama web interface from the same Internet browser window or
+ session from which the firewall or Panorama was upgraded displays the
+ following error:
+
+
+ Your login session has expired and you have been logged out for
+ security reasons. Please log in again if you wish to continue.
+
+
+ Workaround: The following are different ways to
+ log in to the firewall or Panorama web interface after upgrading to
+ PAN-OS 10.2.
+
+
|
+
|
+ PAN-188904
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ Certain web pages and web page contents might not properly load when
+ cloud inline categorization is enabled on the firewall.
+
+ |
+
|
+ PAN-188489
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, dynamic content updates are not
+ automatically pushed to VM-Series firewalls licensed using the
+ Panorama Software Firewall License plugin when
+ Automatically push content when software device registers to
+ Panorama
+ () is enabled.
+
+ |
+
|
+ PAN-188358
+ |
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management
+ port LEDs do not light up when a 10G Ethernet cable is plugged in.
+
+ |
+
|
+ PAN-188064
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ The SCP Server Profile configuration (
+ are not automatically deleted after downgrade from PAN-OS 10.2.0 to
+ PAN-OS 10.1 or earlier release.
+
+ |
+
|
+ PAN-188052
+ |
+
+
+ Devices in FIPS-CC mode are unable to connect to servers utilizing
+ ECDSA-based host keys that impacts exporting logs (), exporting configurations (), or the scp export command in the
+ CLI.
+
+
+ Workaround: Use RSA-based host keys on the
+ destination server.
+
+ |
+
|
+ PAN-187846
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, a selective push (
+ and
+ ) may push an incorrect configuration to managed firewalls causing
+ the firewalls to display as Out of Sync if the
+ Panorama pushed version for the Shared Policy and Template
+ configuration () are 20 version or more older than the current local running
+ configuration on Panorama.
+
+
+ To determine the current configuration version, select
+ and expand the
+ Local Running config menu to review
+ the list of Panorama configuration versions.
+
+
+ Workaround: Push a more recent configuration to
+ your managed firewalls before performing a selective push.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187643
+ |
+
+
+ If you enable SCTP security using a Panorama template when
+ SCTP INIT Flood Protection is
+ enabled in the Zone Protection profile using Panorama and you commit
+ all changes, the commit is successful but the
+ SCTP INIT option is not available in
+ the Zone Protection profile.
+
+
+ Workaround: Log out of the firewall and log in
+ again to make the SCIT INIT option
+ available on the web interface.
+
+ |
+
|
+ PAN-187612
+ |
+
+
+ On the Panorama management server, not all data profiles () are displayed after you:
+
+
+ Workaround: Log in to the Panorama CLI and reset
+ the DLP plugin.
+
+ admin > request plugins dlp reset
+ |
+
|
+ PAN-187429
+
+ This issue is now resolved. See PAN-OS 10.2.2 Addressed Issues.
+
+ |
+
+
+ On PA-3400 & PA-5400 series firewalls (minus the PA-5450), the CLI
+ and SNMP MIB walk do not display the Model and Serial-number of the
+ Fan tray and PSUs.
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-187370
+ |
+
+
+ On a firewall with Advanced Routing enabled, if there is also a
+ logical router instance that uses the default configuration and has no
+ interfaces assigned to it, this will result in terminating the
+ management daemon and main routing daemon in the firewall during
+ commit.
+
+
+ Workaround: Do not use a logical router instance
+ with no interfaces bound to it.
+
+ |
+
|
+ PAN-187234
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ Certain web pages submitted for analysis by Advanced URL Filtering
+ cloud inline categorization might experience high latency.
+
+ |
+
|
+ PAN-186913
+
+ This issue is now resolved. See PAN-OS 10.2.2 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server,
+ Validate Device Group (
+ erroneously issues a CommitAll operation instead of a ValidateAll
+ operation when multiple device groups are included in the push and
+ results in no configuration validation.
+
+
+ Workaround: Validate device group configurations
+ using one of the following methods.
+
+
|
+
|
+ PAN-186886
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues.
+
+ |
+
+
+ Individual configuration objects cannot be viewed when you commit
+ selective configuration changes () on a multi-vsys firewall.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-186282
+ |
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match
+ criteria automatically when adding dynamic address groups.
+
+
+ Workaround: Reboot the Panorama HA pair.
+
+ |
+
|
+ PAN-186262
+ |
+
+
+ The Panorama management server in Panorama or Log Collector mode may
+ become unresponsive as Elasticsearch accumulates internal connections
+ related to logging processes. The chances Panorama becomes
+ unresponsive increases the longer Panorama remains powered on.
+
+
+ Workaround: Reboot Panorama if it becomes
+ unresponsive.
+
+ |
+
|
+ PAN-186137
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues.
+
+ |
+
+
+ The management interface of the PA-3400 Series firewall incorrectly
+ displays 10G port speed as an option. 10G speed is not supported on
+ the PA-3400 Series firewall management port and cannot be configured.
+
+ |
+
|
+ PAN-186134
+ |
+
+
+ On the Panorama management server, performing a
+ Commit and Push (Commit > Commit and Push) may intermittently not push the committed configuration changes to
+ managed firewalls.
+
+
+ Workaround: Select
+ Commit > Push to Devices to push
+ the committed configuration changes to your managed firewalls.
+
+ |
+
|
+ PAN-185966
+ |
+
+
+ The
+ debug skip-cert-renewal-check-syslog yes
+ command is not available on Log Collector CLI to stop the Dedicated
+ Log Collector from trying to renew the device certificate and
+ displaying the following error:
+
+
+ No valid device certificate found
+
+ |
+
|
+ PAN-185286
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ (PA-5400 Series firewalls only) On the Panorama
+ management server, the device health resources () do not populate.
+
+ |
+
|
+ PAN-184708
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
|
+
|
+ PAN-184702
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, an M-700 appliance in Log Collector
+ mode fails to connect to Panorama when added as a managed collector
+ ().
+
+
+ Workaround:
+ Log in to the M-700 CLI
+ and
+ recover the Log Collector connectivity to Panorama.
+
+ |
+
|
+ PAN-184474
+ |
+
+
+ When the firewall has Advanced Routing enabled, a static route stays
+ active after the interface goes down.
+
+
+ Workaround: For firewalls that support
+ Bidirectional Forwarding Detection (BFD), configure BFD for the static
+ route.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183567
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, you must download and install the
+ ZTP Plugin 2.0 after successful upgrade to PAN-OS 10.2. After upgrade
+ to PAN-OS 10.2, the
+ show plugins installed command does
+ not display the ZTP plugin until you install ZTP Plugin 2.0.
+
+
+ Workaround: After Panorama successfully upgrades
+ to PAN-OS 10.2, manually download and install the ZTP Plugin 2.0.
+
+
|
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-182734
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues.
+
+ |
+
+
+ On an Advanced Routing Engine, if you change the IPSec tunnel
+ configuration, BGP flaps.
+
+ |
+
|
+ PAN-182492
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues.
+
+ |
+
+
+ The WildFire analysis report cannot be viewed from the firewall
+ WildFire submission log entry page.
+
+
+ Workaround: You can retrieve the Wildfire analysis
+ reports through the WildFire API or the WildFire portal.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-180661
+ |
+
+
+ On the Panorama management server, pushing an unsupported Minimum
+ Password Complexity () to a managed firewall erroneously displays
+ commit time out as the reason the
+ commit failed.
+
+ |
+
|
+ PAN-180104
+ |
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2,
+ CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster
+ previously had a CN-Series as a DaemonSet deployment running PAN-OS
+ 10.0 or 10.1.
+
+
+ Workaround: Reboot the worker nodes before
+ upgrading to PAN-OS 10.2.
+
+ |
+
|
+ PAN-179420
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, a selective push (
+ and
+
+ to managed firewalls fails if you rename an existing device group,
+ template, or template stack that was already pushed to your managed
+ firewalls and you selectively committed specific configuration objects
+ from the renamed device group, template, or template stack.
+
+
+ Workaround: After you rename the existing device
+ group, template, or template stack,
+ Push (
+ all configuration changes for the named device group, template, or
+ template stack.
+
+ |
+
|
+ PAN-178195
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues.
+
+ |
+
+
+ The URL filtering logs generated by traffic analyzed by Advanced URL
+ filtering cloud inline categorization does not display the name of the
+ URL.
+
+ |
+
|
+ PAN-177455
+
+ This issue is now resolved. See PAN-OS 10.2.2 Addressed Issues.
+
+ |
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA
+ (High Availability) clustering enabled and using an HA4 communication
+ link. Attempting to load PAN-OS 10.2.0 on the firewall causes the
+ PA-7000 100G NPC to go offline. As a result, the firewall fails to
+ boot normally and enters maintenance mode. HA Pairs of Active-Passive
+ and Active-Active firewalls are not affected.
+
+ |
+
|
+ PAN-176693
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues.
+
+ |
+
+
+ The Activity (ACT) LEDs on the RJ-45 ports of the M-300 and M-700
+ appliances do not blink while processing network traffic.
+
+ |
+
|
+ PAN-176156
+
+ This issue is now resolved. See PAN-OS 10.2.2 Addressed Issues
+
+ .
+ |
+
+
+ Executing
+ show running resource-monitor with
+ the ingress-backlogs option produces
+ the following server error:
+ Dataplane is not up or invalid target-dp(*.dp*).
+
+ |
+
|
+ PAN-175915
+ |
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks
+ and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network
+ Protection Profile, the traffic logs do not display network slice SST
+ and SD values.
+
+ |
+
|
+ PAN-174982
+ |
+
+
+ In HA active/active configurations where, when interfaces that were
+ associated with a virtual router were deleted, the configuration
+ change did not sync.
+
+ |
+
|
+ PAN-172274
+ |
+
+
+ When you activate the advanced URL filtering license, your license
+ entitlements for PAN-DB and advanced URL filtering might not display
+ correctly on the firewall — this is a display anomaly, not a licensing
+ issue, and does not affect access to the services.
+
+
+ Workaround: Issue the following command to
+ retrieve and update the licenses:
+ license request fetch.
+
+ |
+
|
+ PAN-172132
+
+ This issue is now resolved by PAN-189643. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ QoS fails to run on a tunnel interface (for example, tunnel.1).
+
+ |
+
|
+ PAN-171938
+ |
+
+
+ No results are displayed when you
+ Show Application Filter for a
+ Security policy rule ().
+
+ |
+
|
+ PAN-171069
+ |
+
+
+ Local Log Collectors for Panorama management servers in active/passive
+ high availability (HA) configuration cannot be added to the same
+ Collector Group ().
+
+
+ Workaround: Before you upgrade your Panorama
+ servers to PAN-OS 10.1.0, configure HA (), add the local Log Collectors of the HA peers to the same Collector
+ Group, and upgrade to PAN 10.1.0.
+
+ |
+
|
+ PAN-164885
+
+ This issue is now resolved. See PAN-OS 10.2.10 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, pushes to managed firewalls (
+ or Commit and Push) may fail when an
+ EDL () is configured to
+ Check for updates every 5 minutes
+ due to the commit and EDL fetch processes overlapping. This is more
+ likely to occur when multiple EDLs are configured to check for updates
+ every 5 minutes.
+
+ |
+
|
+ PAN-163676
+ |
+
+
+ Next-Gen Firewalls are unable to connect to a syslog server when the
+ certificates required to connect to the syslog server are part of a
+ Certificate Profile () if the Use OCSP setting is
+ enabled to check the revocation status of certificates.
+
+
+ Workaround: Enable
+ Use CRL to check the revocation
+ status of certificates in the Certificate Profile.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-5781
+ |
+
+
+ The WildFire appliance might erroneously generate and log the
+ following device certification error:
+ Device certificate is missing or invalid. It cannot be
+ renewed.
+
+ |
+
|
+ WF500-5754
+ |
+
+
+ In WildFire appliance clusters, issuing the
+ show cluster controller CLI command
+ generates an error when an IPv6 address is configured for the
+ management interface but not for the cluster interface.
+
+
+ Workaround: Ensure all WildFire appliance
+ interfaces that are enabled use matching protocols (all IPv4 or all
+ IPv6).
+
+ |
+
|
+ WF500-5632
+ |
+
+
+ The number of registered WildFire appliances reported in Panorama
+ () does not accurately reflect the current status of connected
+ WildFire appliances.
+
+ |
+
|
+ PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues.
+
+ |
+
+
+ A race condition may cause the dataplane to restart unexpectedly when
+ a zip decompression offload result is returned for a session that has
+ already closed. The session state is not validated before processing
+ the result because the offload result does not follow the fastpath
+ where these checks are normally performed.
+
+
+ Workaround: Disable zip hardware offloading (may
+ cause higher CPU usage).
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See PAN-OS 10.2.13-h18 Addressed Issuesand
+ PAN-OS 10.2.16-h6 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-297610
+ |
+
+
+ A firewall may become unresponsive after an upgrade due to the
+ fsck command scanning drive
+ partitions in parallel with the root partition, causing the process to
+ take an extended amount of time.
+
+ |
+
|
+ PAN-297295
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent
+ process restarts multiple times and exhausts its restart limit,
+ resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-295803
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-295255
+ |
+
+
+ Palo Alto Networks next-generation firewalls may experience service
+ disruptions due to all_task process
+ crashes when deployed in environments having non-uniform MTU and are
+ terminating IPSec tunnels.
+
+ |
+
|
+ PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues.
+
+ |
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM)
+ condition due to a memory leak and displays an error message. This
+ issue causes the device to crash and reboot unexpectedly.
+
+ |
+
|
+ PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues
+
+ |
+
+
+ A memory leak in the configd process
+ might lead to an active firewall to reboot due to an Out-of-Memory
+ (OOM) condition. This issue is observed when specific status commands,
+ such as
+ request log-collector forwarding status
+ are executed at high frequencies.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues
+
+ |
+
+
+ (Firewalls in HA configurations only) Routed
+ process may stop responding after changing MTU or any link parameters
+ when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-286231
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-284073
+ |
+
+
+ The firewall web interface becomes inaccessible and commits fail.
+
+ |
+
|
+ PAN-284067
+ |
+
+
+ A cumulative memory leak in the
+ devsrvr
+ process gets progressively worse whenever the CLI command
+ show running application statistics
+ is issued. This memory leak will gradually consume system memory and
+ produce an out-of-memory (OOM) condition, leading to an eventual
+ firewall reboot.
+
+
+ Workaround: Avoid using the CLI command:
+ show running application statistics.
+
+ |
+
|
+ PAN-281370
+ |
+
+
+ The Advanced WildFire Inline ML models
+ OOXML and
+ Mach-O erroneously display as being
+ available from the CLI; however, they are only available on PAN-OS
+ 11.1.3 and later releases.
+
+ |
+
|
+ PAN-273158
+ |
+
+
+ (PA-7000 Series firewalls only) Due to an
+ incorrect configuration on the ASIC, receiving a mix of jumbo and
+ non-jumbo packets may cause silent packet drops or application
+ slowness.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
| PAN-259769 | +
+
+ GlobalProtect portal is not accessible via a web browser and the app
+ displays the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-243951
+ |
+
+
+ On the Panorama management sever in an active/passive High
+ Availability (HA) configuration, managed devices () display as out-of-sync on the
+ passive HA peer when configuration changes are made to the SD-WAN
+ () configuration on the active HA peer.
+
+
+ Workaround: Manually synchronize the Panorama HA
+ peers.
+
+
|
+
|
+ PAN-234408
+ |
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for
+ ChatGPT from traffic forwarded to the DLP cloud service from an NGFW.
+
+ |
+
|
+ PAN-228273
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server in FIPS-CC mode, the ElasticSearch
+ cluster fails to come up and the
+ show log-collector-es-cluster health
+ command displays the status is
+ red. This results in log
+ ingestion issues for Panorama in Panorama only or Log Collector mode.
+
+ |
+
|
+ PAN-227344
+ |
+
+
+ On the Panorama management server, PDF Summary Reports () display no data and are blank when predefined reports are included
+ in the summary report.
+
+ |
+
|
+ PAN-225337
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, the configuration push to a
+ multi-vsys firewall fails if you:
+
+
+ Workaround: Select
+
+ and edit the Panorama Settings to enable one of the following:
+
+
+ Alternatively, you can remove the duplicate address objects from the
+ device group configuration to allow only the
+ Shared objects in your
+ configuration.
+
+ |
+
|
+ PAN-223488
+
+ This issue is now resolved. See
+ PAN-OS 10.2.7 Addressed Issues.
+
+ |
+ + Closed ElasticSearch shards are not deleted from a Panorama M-Series or + virtual appliance. This causes the ElasticSearch shard purging to not + work as expected, resulting in high disk usage. + | +
|
+ PAN-223365
+ |
+
+
+ The Panorama management server is unable to query any logs if the
+ ElasticSearch health status for any Log Collector (
+ is degraded.
+
+
+ Workaround:
+ Log in to the Log Collector CLI
+ and restart ElasticSearch.
+
+
+
+
+
+ |
+
|
+ PAN-222586
+ |
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus,
+ Forward Methods, and Built-In Actions for Correlation Log settings
+ () are not displayed and cannot be configured.
+
+ |
+
|
+ PAN-222253
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, policy rulebase reordering when you
+ View Rulebase by Groups () does not persist if you reorder the policy rulebase by dragging and
+ dropping individual policy rules and then moving the entire tag group.
+
+ |
+
|
+ PAN-221775
+ |
+
+
+ A Malformed Request error is
+ displayed when you
+ Test Connection for an email server
+ profile () using SMTP over TLS and the
+ Password includes an ampersand
+ (&).
+
+ |
+
|
+ PAN-221015
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ On M-600 appliances in Panorama or Log Collector mode, the
+ es-1 and
+ es-2 ElasticSearch processes fail
+ to restart when the M-600 appliance is rebooted. The results in the
+ Managed Collector ES health
+ status () to be degraded.
+
+
+ Workaround:
+ Log in to the Panorama or Log Collector CLI
+ experiencing degraded ElasticSearch health and restart all
+ ElasticSearch processes.
+
+
+
+
+
+ |
+
|
+ PAN-219644
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ Firewalls forwarding logs to a syslog server over TLS () use the default Palo Alto Networks certificate instead of the
+ custom certificate configured on the firewall.
+
+ |
+
|
+ PAN-218521
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ The ElasticSearch process on the M-600 appliance in Log Collector mode
+ may enter a continuous reboot cycle. This results in the M-600
+ appliance becoming unresponsive, consuming logging disk space, and
+ preventing new log ingestion.
+
+ |
+
|
+ PAN-217307
+
+ This issue is now resolved. See PAN-OS 10.2.11 Addressed Issues.
+
+ |
+
+
+ The following Security policy rule () filters return no results:
+
+
+ log-start eq no
+
+ log-end eq no
+ log-end eq yes
+ |
+
|
+ PAN-215778
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues.
+
+ |
+
+
+ On the M-600 appliance in Management Only mode, XML API Get requests
+ for /config fail with the
+ following error due to exceeding the
+ total configuration size
+ supported on the M-600 appliance.
+
+
+
+
+
+ |
+
|
+ PAN-215082
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ M-300 and M-700 appliances may generate erroneous system logs () to alert that the M-Series appliance memory usage limits are
+ reached.
+
+ |
+
|
+ PAN-213746
+ |
+
+
+ On the Panorama management server, the
+ Hostkey displayed as
+ undefined undefined if you
+ override an SSH Service Profile () Hostkey configured in a Template from the Template Stack.
+
+ |
+
|
+ PAN-213119
+ |
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you
+ view the Block IP list ():
+
+
+ show -> dis-block-table is unexpected
+
+ |
+
|
+ PAN-212889
+
+ This issue is now resolved. See
+ PAN-OS 10.2.14 Addressed Issues
+
+ |
+
+
+ On the Panorama management server, different threat names are used
+ when querying the same threat in the Threat Monitor () and ACC. This results in the ACC
+ displaying
+ no data to display when you are
+ redirected to the ACC after clicking a threat name in the Threat
+ Monitor and filtering the same threat name in the Global Filters.
+
+ |
+
|
+ PAN-212533
+ |
+
+
+ Modifying the Administrator Type for
+ an existing administrator (
+ or
+ ) from Superuser to a
+ Role-Based custom admin, or vice
+ versa, does not modify the access privileges of the administrator.
+
+ |
+
|
+ PAN-211531
+ |
+ + On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (). + | +
|
+ PAN-209288
+ |
+
+
+ Certificates are not successfully generated using SCEP ().
+
+ |
+
|
+ PAN-208325
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues.
+
+ |
+
+
+ The following NextGen firewalls and Panorama management server models
+ are unable to automatically renew the device certificate (
+ or
+ ).
+
+
+ Workaround: Log in to the
+ firewall CLI
+ or
+ Panorama CLI
+ and fetch the device certificate.
+
+
+
+
+
+ |
+
|
+ PAN-207629
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, selective push fails to managed
+ firewalls if the managed firewalls are enabled with multiple vsys and
+ the Push Scope contains shared objects in device groups.
+
+ |
+
|
+ PAN-206268
+ |
+
+
+ On the Panorama management server, the Auth Key field was erroneously
+ displayed when you configure the Panorama Settings () as part of a template or template stack configuration.
+
+ |
+
|
+ PAN-206253
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ For PA-3400 Series firewalls, the default log rate is set too low and
+ the max configurable log rate is incorrectly capped resulting in the
+ firewall not generating more than 6,826 logs per second.
+
+ |
+
|
+ PAN-206243
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ The PA-220 firewall reaches the maximum disk usage capacity multiple a
+ day that requires a disk cleanup. A critical system log () is generated each time the firewall reaches maximum disk usage
+ capacity.
+
+ |
+
|
+ PAN-205187
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ ElasticSearch may not start properly when a newly installed Panorama
+ virtual appliance powers on for the first time, resulting in the
+ Panorama virtual appliance being unable to query logs forwarded from
+ the managed firewall to a Log Collector.
+
+
+ Workaround:
+ Log in to the Panorama CLI
+ and start the PAN-OS software.
+
+
+
+
+
+ |
+
|
+ PAN-204663
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, you are unable to Context Switch
+ from one managed firewall to another.
+
+
+ Workaround: After you Context Switch to a managed
+ firewall, you must first Context Switch back to Panorama before you
+ can continue to Context Switch to a different managed firewall.
+
+ |
+
|
+ PAN-201855
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, cloning any template () corrupts certificates () with the
+ Block Private Key Export setting
+ enabled across all templates. This results in managed firewalls
+ experiencing issues wherever the corrupted certificate is referenced.
+
+
+ For example, you have template A, B, and C where templates A and B
+ have certificates with the
+ Block Private Key Export setting
+ enabled. Cloning template C corrupts the certificates with
+ Block Private Key Export setting
+ enabled in templates A and B.
+
+
+ Workaround: After cloning a template, delete and
+ re-import the corrupted certificates.
+
+ |
+
|
+ PAN-199557
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues.
+
+ |
+
+
+ On M-600 appliances in an Active/Passive high availability (HA)
+ configuration, the
+ configd process restarts due to a
+ memory leak on the
+ Active Panorama HA peer. This
+ causes the Panorama web interface and CLI to become unresponsive.
+
+
+ Workaround: Manually reboot the
+ Active Panorama HA peer.
+
+ |
+
|
+ PAN-197097
+ |
+
+
+ Large Scale VPN (LSVPN) does not support IPv6 addresses on the
+ satellite firewall.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-194826
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ (WF-500 appliance only) System log forwarding
+ does not work over a TLS connection.
+
+ |
+
|
+ PAN-194708
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ URL filtering logs () erroneously truncate a 16KB Header value and do not display the
+ Header values that follow the truncated 16KB header.
+
+
+ For example, a URL filtering log has 5 Headers. The second Header has
+ a 16KB value. In the URL filtering log, the first header and the value
+ are displayed, second Header value is truncated, and remaining three
+ headers are not displayed.
+
+ |
+
|
+ PAN-194519
+ |
+
+
+ (PA-5450 firewall only) Trying to configure a
+ custom payload format under
+
+ yields a Javascript error.
+
+ |
+
|
+ PAN-194515
+ |
+
+
+ (PA-5450 firewall only) The Panorama web
+ interface does not display any predefined template stack variables in
+ the dropdown menu under
+ .
+
+
+ Workaround: Configure the log interface IP address
+ on the individual firewall web interface instead of on Panorama.
+
+ |
+
|
+ PAN-193251
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ If SAML is configured as the authentication method for GlobalProtect,
+ authentication on the Portal page is not successful in the browser.
+
+
+ Workaround: Use the GlobalProtect app installed on
+ the endpoint to authenticate.
+
+ |
+
|
+ PAN-192403
+ |
+
+
+ (PA-5450 firewall only) There is no commit
+ warning in the web interface when configuring the management interface
+ and logging interface in the same subnetwork. Having both interfaces
+ in the same subnetwork can cause routing and connectivity issues.
+
+ |
+
|
+ PAN-190735
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ Certain webpages that use chunked-encoded data transfers might not
+ load properly when analyzed by Advanced URL Filtering cloud inline
+ categorization.
+
+ |
+
|
+ PAN-190727
+ |
+
+
+ (PA-5450 firewall only) Documentation for
+ configuring the log interface is unavailable on the web interface and
+ in the PAN-OS Administrator’s Guide.
+
+ |
+
|
+ PAN-190435
+ |
+
+
+ When you Commit a configuration
+ change, the Task Manager commit
+ Status goes directly from
+ 0% to
+ Completed and does accurately
+ reflect the commit job progress.
+
+ |
+
|
+ PAN-189425
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server,
+ Export Panorama and devices config bundle
+ () fails to export. When the export fails, you are redirected to a new
+ window and the following error is displayed:
+
+
+ Failed to redirect error to /var/log/pan/appweb3-panmodule.log
+ (Permission denied)
+
+ |
+
|
+ PAN-189395
+
+ This issue is now resolved. See PAN-OS 10.2.2 Addressed Issues.
+
+ |
+
+
+ Running any version of PAN-OS 10.2.1 on a PA-400 Series firewall can
+ cause the dataplane process to restart unexpectedly and trigger a
+ crash.
+
+ |
+
|
+ PAN-189380
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ After you successfully upgrade a PA-3000 Series firewall to PAN-OS
+ 10.2.0 or later release and Enterprise data loss prevention (DLP)
+ plugin 3.0.0 or later release, the first configuration push from the
+ Panorama management server causes the firewall dataplane to crash.
+
+
+ Workaround: Restart the firewall to restore
+ dataplane functionality.
+
+
|
+
|
+ PAN-189111
+ |
+
+
+ After deleting an MP pod and it comes up, the
+ show routing command output
+ appears empty and traffic stops working.
+
+ |
+
|
+ PAN-189076
+ |
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a
+ broadcast link and a designated router (DR) priority of 0 (zero) are
+ stuck in a two-way state after HA failover.
+
+
+ Workaround: Configure at least one OSPFv3 neighbor
+ with a non-zero priority setting in the same broadcast domain.
+
+ |
+
|
+ PAN-189057
+
+ This issue is now resolved. See PAN-OS 10.2.2 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, Panorama enters a
+ non-functional state due to
+ php.debug.log life taking up too
+ much space.
+
+
+ Workaround: Disable the debug flag for Panorama.
+
+
|
+
|
+ PAN-188904
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ Certain web pages and web page contents might not properly load when
+ cloud inline categorization is enabled on the firewall.
+
+ |
+
|
+ PAN-188489
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, dynamic content updates are not
+ automatically pushed to VM-Series firewalls licensed using the
+ Panorama Software Firewall License plugin when
+ Automatically push content when software device registers to
+ Panorama
+ () is enabled.
+
+ |
+
|
+ PAN-188358
+ |
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management
+ port LEDs do not light up when a 10G Ethernet cable is plugged in.
+
+ |
+
|
+ PAN-188064
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ The SCP Server Profile configuration (
+ are not automatically deleted after downgrade from PAN-OS 10.2.0 to
+ PAN-OS 10.1 or earlier release.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187643
+ |
+
+
+ If you enable SCTP security using a Panorama template when
+ SCTP INIT Flood Protection is
+ enabled in the Zone Protection profile using Panorama and you commit
+ all changes, the commit is successful but the
+ SCTP INIT option is not available in
+ the Zone Protection profile.
+
+
+ Workaround: Log out of the firewall and log in
+ again to make the SCIT INIT option
+ available on the web interface.
+
+ |
+
|
+ PAN-187612
+ |
+
+
+ On the Panorama management server, not all data profiles () are displayed after you:
+
+
+ Workaround: Log in to the Panorama CLI and reset
+ the DLP plugin.
+
+ admin > request plugins dlp reset
+ |
+
|
+ PAN-187429
+
+ This issue is now resolved. See PAN-OS 10.2.2 Addressed Issues.
+
+ |
+
+
+ On PA-3400 & PA-5400 series firewalls (minus the PA-5450), the CLI
+ and SNMP MIB walk do not display the Model and Serial-number of the
+ Fan tray and PSUs.
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-187370
+ |
+
+
+ On a firewall with Advanced Routing enabled, if there is also a
+ logical router instance that uses the default configuration and has no
+ interfaces assigned to it, this will result in terminating the
+ management daemon and main routing daemon in the firewall during
+ commit.
+
+
+ Workaround: Do not use a logical router instance
+ with no interfaces bound to it.
+
+ |
+
|
+ PAN-187234
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ Certain web pages submitted for analysis by Advanced URL Filtering
+ cloud inline categorization might experience high latency.
+
+ |
+
|
+ PAN-186913
+
+ This issue is now resolved. See PAN-OS 10.2.2 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server,
+ Validate Device Group (
+ erroneously issues a CommitAll operation instead of a ValidateAll
+ operation when multiple device groups are included in the push and
+ results in no configuration validation.
+
+
+ Workaround: Validate device group configurations
+ using one of the following methods.
+
+
|
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-186282
+ |
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match
+ criteria automatically when adding dynamic address groups.
+
+
+ Workaround: Reboot the Panorama HA pair.
+
+ |
+
|
+ PAN-186262
+ |
+
+
+ The Panorama management server in Panorama or Log Collector mode may
+ become unresponsive as Elasticsearch accumulates internal connections
+ related to logging processes. The chances Panorama becomes
+ unresponsive increases the longer Panorama remains powered on.
+
+
+ Workaround: Reboot Panorama if it becomes
+ unresponsive.
+
+ |
+
|
+ PAN-186134
+ |
+
+
+ On the Panorama management server, performing a
+ Commit and Push (Commit > Commit and Push) may intermittently not push the committed configuration changes to
+ managed firewalls.
+
+
+ Workaround: Select
+ Commit > Push to Devices to push
+ the committed configuration changes to your managed firewalls.
+
+ |
+
|
+ PAN-185286
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ (PA-5400 Series firewalls only) On the Panorama
+ management server, the device health resources () do not populate.
+
+ |
+
|
+ PAN-184708
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
|
+
|
+ PAN-184702
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, an M-700 appliance in Log Collector
+ mode fails to connect to Panorama when added as a managed collector
+ ().
+
+
+ Workaround:
+ Log in to the M-700 CLI
+ and
+ recover the Log Collector connectivity to Panorama.
+
+ |
+
|
+ PAN-184474
+
+ This issue is now resolved. See PAN-OS 10.2.2 Addressed Issues.
+
+ |
+
+
+ When the firewall has Advanced Routing enabled, a static route stays
+ active after the interface goes down.
+
+
+ Workaround: For firewalls that support
+ Bidirectional Forwarding Detection (BFD), configure BFD for the static
+ route.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-182734
+
+ This issue is now resolved. See
+ PAN-OS 10.2.5 Addressed Issues.
+
+ |
+
+
+ On an Advanced Routing Engine, if you change the IPSec tunnel
+ configuration, BGP flaps.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-181823
+ |
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer
+ port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports
+ on the firewall to go down if they are set to Auto.
+
+ |
+
|
+ PAN-180661
+ |
+
+
+ On the Panorama management server, pushing an unsupported Minimum
+ Password Complexity () to a managed firewall erroneously displays
+ commit time out as the reason the
+ commit failed.
+
+ |
+
|
+ PAN-180104
+ |
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2,
+ CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster
+ previously had a CN-Series as a DaemonSet deployment running PAN-OS
+ 10.0 or 10.1.
+
+
+ Workaround: Reboot the worker nodes before
+ upgrading to PAN-OS 10.2.
+
+ |
+
|
+ PAN-178194
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ A user interface issue in PAN-OS renders the contents of the
+ Inline ML tab in the
+ URL Filtering Profile inaccessible
+ on firewalls licensed for Advanced URL Filtering. Additionally, a
+ message indicating that a
+ License required for URL filtering to function
+ is unavailable displays at the bottom of the UI. These errors do not
+ affect the operation of Advanced URL Filtering or URL Filtering Inline
+ ML.
+
+
+ Workaround: Configuration settings for URL
+ Filtering Inline ML must be applied through the CLI. The following
+ configuration commands are available:
+
+
|
+
|
+ PAN-177455
+
+ This issue is now resolved. See PAN-OS 10.2.2 Addressed Issues.
+
+ |
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA
+ (High Availability) clustering enabled and using an HA4 communication
+ link. Attempting to load PAN-OS 10.2.0 on the firewall causes the
+ PA-7000 100G NPC to go offline. As a result, the firewall fails to
+ boot normally and enters maintenance mode. HA Pairs of Active-Passive
+ and Active-Active firewalls are not affected.
+
+ |
+
|
+ PAN-176156
+
+ This issue is now resolved. See PAN-OS 10.2.2 Addressed Issues
+
+ |
+
+
+ Executing
+ show running resource-monitor with
+ the ingress-backlogs option produces
+ the following server error:
+ Dataplane is not up or invalid target-dp(*.dp*).
+
+ |
+
|
+ PAN-175915
+ |
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks
+ and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network
+ Protection Profile, the traffic logs do not display network slice SST
+ and SD values.
+
+ |
+
|
+ PAN-174982
+ |
+
+
+ In HA active/active configurations where, when interfaces that were
+ associated with a virtual router were deleted, the configuration
+ change did not sync.
+
+ |
+
|
+ PAN-172274
+ |
+
+
+ When you activate the advanced URL filtering license, your license
+ entitlements for PAN-DB and advanced URL filtering might not display
+ correctly on the firewall — this is a display anomaly, not a licensing
+ issue, and does not affect access to the services.
+
+
+ Workaround: Issue the following command to
+ retrieve and update the licenses:
+ license request fetch.
+
+ |
+
|
+ PAN-172132
+
+ This issue is now resolved by PAN-189643. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ QoS fails to run on a tunnel interface (for example, tunnel.1).
+
+ |
+
|
+ PAN-171938
+ |
+
+
+ No results are displayed when you
+ Show Application Filter for a
+ Security policy rule ().
+
+ |
+
|
+ PAN-164885
+
+ This issue is now resolved. See PAN-OS 10.2.10 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, pushes to managed firewalls (
+ or Commit and Push) may fail when an
+ EDL () is configured to
+ Check for updates every 5 minutes
+ due to the commit and EDL fetch processes overlapping. This is more
+ likely to occur when multiple EDLs are configured to check for updates
+ every 5 minutes.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-5854
+ |
+
+
+ The WildFire analysis report on the firewall log viewer () does not display the following data fields: File Type, SHA-256,
+ MD-5, and File Size".
+
+
+ Workaround: Download and open the WildFire
+ analysis report in the PDF format using the link in the upper
+ right-hand corner of the
+ Detailed Log View.
+
+ |
+
|
+ WF500-5843
+ |
+
+
+ In a WildFire appliance cluster, issuing the
+ show cluster-all peers CLI command
+ when a node within the cluster is being rebooted generates the
+ following error:
+ Server error : An error occured.
+
+ |
+
|
+ WF500-5840
+ |
+
+
+ The sample analysis statistics that are returned when issuing the
+ show wildfire local statistics CLI
+ command in WildFire appliance cluster deployments may not accurately
+ reflect the number of samples that have been processed.
+
+ |
+
|
+ WF500-5823
+ |
+
+
+ The following WildFire appliance CLI command does not return a
+ signature generation status as expected:
+ show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance
+ from analyzing a sample.
+
+ |
+
|
+ WF500-5781
+ |
+
+
+ The WildFire appliance might erroneously generate and log the
+ following device certification error:
+ Device certificate is missing or invalid. It cannot be
+ renewed.
+
+ |
+
|
+ WF500-5754
+ |
+
+
+ In WildFire appliance clusters, issuing the
+ show cluster controller CLI command
+ generates an error when an IPv6 address is configured for the
+ management interface but not for the cluster interface.
+
+
+ Workaround: Ensure all WildFire appliance
+ interfaces that are enabled use matching protocols (all IPv4 or all
+ IPv6).
+
+ |
+
|
+ WF500-5632
+ |
+
+
+ The number of registered WildFire appliances reported in Panorama
+ () does not accurately reflect the current status of connected
+ WildFire appliances.
+
+ |
+
|
+ PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues.
+
+ |
+
+
+ A race condition may cause the dataplane to restart unexpectedly when
+ a zip decompression offload result is returned for a session that has
+ already closed. The session state is not validated before processing
+ the result because the offload result does not follow the fastpath
+ where these checks are normally performed.
+
+
+ Workaround: Disable zip hardware offloading (may
+ cause higher CPU usage).
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See PAN-OS 10.2.13-h18 Addressed Issuesand
+ PAN-OS 10.2.16-h6 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-303959
+ |
+
+
+ Traffic that is incorrectly identified as
+ unknown-tcp/unknown-udp
+ eventually drops due to an App-ID resource limitation issue.
+
+ |
+
|
+ PAN-280196
+ |
+
+
+ After generating hipmatch/userid logs, the hipmatch logs written
+ counter is missing from
+ debug log-receiver statistics. This causes the firewall to match a HIP object but not on the HIP
+ profile that contained the object.
+
+ |
+
|
+ PAN-297610
+ |
+
+
+ A firewall may become unresponsive after an upgrade due to the
+ fsck command scanning drive
+ partitions in parallel with the root partition, causing the process to
+ take an extended amount of time.
+
+ |
+
|
+ PAN-297295
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent
+ process restarts multiple times and exhausts its restart limit,
+ resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-295803
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-295255
+ |
+
+
+ Palo Alto Networks next-generation firewalls may experience service
+ disruptions due to all_task process
+ crashes when deployed in environments having non-uniform MTU and are
+ terminating IPSec tunnels.
+
+ |
+
|
+ PAN-292344
+ |
+
+
+ When upgrading from PAN-OS 10.2.9-h1 to PAN-OS 10.2.13-h5, the
+ firewall reboots repeatedly and enters maintenance mode.
+
+ |
+
|
+ PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues.
+
+ |
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM)
+ condition due to a memory leak and displays an error message. This
+ issue causes the device to crash and reboot unexpectedly.
+
+ |
+
|
+ PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues
+
+ |
+
+
+ A memory leak in the configd process
+ might lead to an active firewall to reboot due to an Out-of-Memory
+ (OOM) condition. This issue is observed when specific status commands,
+ such as
+ request log-collector forwarding status
+ are executed at high frequencies.
+
+ |
+
|
+ PAN-290996
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues
+
+ |
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS)
+ counters incorrectly return a value of 0 for each virtual system
+ (VSYS), despite the firewall actively processing connections.
+
+ |
+
|
+ PAN-290088
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues
+
+ |
+
+
+ (Firewalls in HA configurations only) Routed
+ process may stop responding after changing MTU or any link parameters
+ when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-287871
+
+ This issue affects PAN-OS 10.2.10-h2
+
+ |
+
+
+ When SSL Inbound Inspection is enabled and the firewall receives
+ fragmented Client Hello packets that include the TCP timestamp option,
+ the Client Hello message is forwarded to the destination server
+ without the timestamp option.
+
+ |
+
|
+ PAN-287803
+ |
+
+
+ Users might be unable to access some URLs due to issues involving the
+ accumulation proxy and the Path Maximum Transmission Unit (MTU).
+
+
+ To address this issue, use one of the following workarounds:
+
+
|
+
|
+ PAN-286306
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues
+
+ |
+
+
+ When getting transceiver information from ESCC for SFP 25G modules,
+ the transceiver code incorrectly displays
+ Unknown instead of
+ 25GBase-SR.
+
+ |
+
|
+ PAN-286255
+
+ This issue affects PAN-OS 10.2.10-h17
+
+ |
+
+
+ When a firewall receives an unexpected termination request for certain
+ SSL sessions , NGFW dataplane might experience a slow buffer resource
+ leak.
+
+
+ Workaround: Disable accumulation proxy on the
+ NGFW.
+
+ |
+
|
+ PAN-286231
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-285894
+
+ This issue is now resolved. See PAN-OS 10.2.13-h10 Addressed Issues
+
+ |
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may
+ occur, which could result in firewall reboots.
+
+
+ Workaround: Disable the Preserve Pre-NAT feature
+ using the
+ set deviceconfig setting preserve-prenat-feature no
+ CLI command.
+
+ |
+
|
+ PAN-284073
+ |
+
+
+ The firewall web interface becomes inaccessible and commits fail.
+
+ |
+
|
+ PAN-284067
+ |
+
+
+ A cumulative memory leak in the
+ devsrvr
+ process gets progressively worse whenever the CLI command
+ show running application statistics
+ is issued. This memory leak will gradually consume system memory and
+ produce an out-of-memory (OOM) condition, leading to an eventual
+ firewall reboot.
+
+
+ Workaround: Avoid using the CLI command:
+ show running application statistics.
+
+ |
+
|
+ PAN-282236
+ |
+
+
+ The firewall doesn't reassemble IPv6 packets correctly after they are
+ fragmented.
+
+ |
+
|
+ PAN-281370
+ |
+
+
+ The Advanced WildFire Inline ML models
+ OOXML and
+ Mach-O erroneously display as being
+ available from the CLI; however, they are only available on PAN-OS
+ 11.1.3 and later releases.
+
+ |
+
|
+ PAN-279746
+ |
+
+
+ An SSL/TLS Client Hello may not be sent if the Client Hello arrives at
+ the firewall in multiple TCP segments and the traffic is not subject
+ to SSL decryption.
+
+ |
+
|
+ PAN-275077
+ (PAN-OS 10.2.10-h9 only)
+ |
+
+
+ DNS Security intermittently logs malicious domain URLs as alert
+ instead of taking a sinkhole action,
+ even when configured to sinkhole malicious DNS domains.
+
+ |
+
|
+ PAN-273158
+ |
+
+
+ (PA-7000 Series firewalls only) Due to an
+ incorrect configuration on the ASIC, receiving a mix of jumbo and
+ non-jumbo packets may cause silent packet drops or application
+ slowness.
+
+ |
+
|
+
+ PAN-270549 (PAN-OS 10.2.10-h2 through PAN-OS 10.2.10-h12)
+
+
+ This issue is now resolved. See
+ PAN-OS 10.2.10-h14 Addressed Issues.
+
+ |
+
+
+ Some TLS connections are not handled correctly leading to an
+ instability in the dataplane of PAN-OS.
+
+ |
+
|
+
+ PAN-269106 (PAN-OS 10.2.10-h9 only)
+
+ |
+
+
+ When using a cloud-based ML detection engine (MICA), the
+ wifclient might crash during
+ server cert verification for MICA gRPC connections and cause the
+ dataplane to restart. On certain platforms, this might cause the
+ firewall to reboot.
+
+
+ Workaround: Disable CRL using the following CLI
+ command:debug iot eal key-value PAN_ICD_SERVER_CERT_USE_CRL=False
+
+ |
+
|
+
+ PAN-269052 (PAN-OS 10.2.10-h9 only)
+
+ |
+
+
+ Traffic might be blocked by a URL Filtering profile that isn't
+ associated with the Security policy rule that the traffic matches.
+
+ |
+
|
+
+ PAN-268823 (PAN-OS 10.2.10-h9 only)
+
+
+ This issue is now resolved. See PAN-OS 10.2.10-h10 Addressed Issues.
+
+ |
+
+
+ (PA-5250 firewall only) Applying filters under
+
+ either causes the logs to load slowly or not load at all.
+
+ |
+
|
+
+ PAN-268815 (PAN-OS 10.2.10-h9 only)
+
+
+ This issue is now resolved. See PAN-OS 10.2.13-h5 Addressed Issues.
+
+ |
+
+
+ When using IoT Security, the
+ wifclient might exit multiple
+ times causing the firewall to reboot.
+
+
+ Workaround: Uninstall the IoT Security license and
+ disable
+ Enable enhanced application logging
+ ().
+
+ |
+
|
+
+ PAN-268260 (PAN-OS 10.2.10-h9 only)
+
+ |
+
+
+ On hardware firewalls where, when SSL decryption was enabled on layer
+ 2, vwire, TAP, VLAN deployments, and Client Hello messages spanned
+ multiple TCP segments, some SSL decryption sessions failed.
+
+ |
+
|
+ PAN-267671
+ (PAN-OS 10.2.10-h9 only)
+ |
+
+
+ Exporting reports in PDF or CSV format and processing hourly scheduled
+ report results can potentially trigger memory leaks. As a result, this
+ can lead to process crashes and firewall reboots.
+
+ |
+
| + PAN-266900 (PAN-OS 10.2.10-h9 only) + | +
+
+ In Panorama, the OK button does not
+ work when trying to install configurations to a managed firewall from
+ the
+
+ section, even after selecting the update type and file from the
+ drop-down menu and choosing the firewall.
+
+ |
+
| + PAN-263226 (PAN-OS 10.2.10-h2 and 10.2.10-h3 only) + | +
+
+ When SSL decryption is enabled and Client Hello messages span multiple
+ TCP segments, elements from the proxy_l2info memory pool may not be
+ freed properly. Memory leaks in this pool cause some SSL decryption
+ sessions to fail.
+
+
+ Workaround: Disable Client Hello accumulation
+ using the
+ debug dataplane set ssl-decrypt accumulate-client-hello disable
+ yes
+ CLI command.
+
+ |
+
|
+ PAN-262287
+
+ This issue is now resolved. See PAN-OS 10.2.13 Addressed Issues.
+
+ |
+
+
+ Dereferencing a NULL pointer that occurs might cause
+ pan_task
+ processes to crash.
+
+ |
+
|
+ PAN-261429
+
+ This issue is now resolved. See PAN-OS 10.2.15 Addressed Issues
+
+ |
+
+
+ The command
+ show auth radius-require-msg-authentic
+ might return no output.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-259997
+
+ This issue is now resolved. See PAN-OS 10.2.10-h3 Addressed Issues.
+
+ |
+
+
+ On PA-3410, PA-3420, and PA-3430 firewalls, the install fails when
+ upgrading from PAN-OS 10.2.3-h3 and later 10.2 releases to PAN-OS
+ 10.2.10 due the number of configured vsys zones exceeding the zone
+ limit in PAN-OS 10.2.10.
+
+
+ Workaround: Before installing PAN-OS 10.2.10,
+ reduce the number of security zones to 40 zones or fewer for PA-3410
+ and PA-3420 firewalls, and to 100 zones or fewer for PA-3430
+ firewalls.
+
+ |
+
| PAN-259769 | +
+
+ GlobalProtect portal is not accessible via a web browser and the app
+ displays the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-259733
+
+ This issue is now resolved. See PAN-OS 10.2.10-h2 Addressed Issues.
+
+ |
+
+
+ Custom reports created in PAN-OS are not deleted as expected,
+ resulting in high memory use by the
+ reportd
+ process. This can lead to issues, such as out-of-memory conditions,
+ content installation failures, and unexpected firewall reboots.
+
+ |
+
|
+ PAN-259344
+
+ This issue is now resolved. See PAN-OS 10.2.10-h3 Addressed Issues.
+
+ |
+
+
+ Performing a configuration commit on a firewall, either locally or
+ from Panorama, causes a memory leak by the
+ configd
+ process and results in an out-of-memory (OOM) condition.
+
+ |
+
|
+ PAN-258570
+ (PAN-OS 10.2.10-h9 only)
+
+ This issue is now resolved. See
+ PAN-OS 10.2.13 Addressed Issues.
+
+ |
+
+
+ The
+ varrcvr
+ process might progressively use more memory resulting in unexpected
+ reboots when WildFire file forwarding is handling PE files.
+
+ |
+
|
+ PAN-257957
+
+ This issue is now resolved. See PAN-OS 10.2.12 Addressed Issues.Affects 10.2.10-h3 and later 10.2 releases.
+
+ |
+
+
+ If you enable FIPS-CC mode and use the PAP or CHAP authentication
+ methods for your RADIUS server, the authd process may restart
+ unexpectedly. To avoid this issue, use one of the following
+ workarounds:
+
+
|
+
|
+ PAN-237106
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-226361
+
+ This issue is now resolved. See PAN-OS 10.2.10-h7 Addressed Issues.
+
+ |
+
+
+ Sessions might end unexpectedly with the error
+ resources-unavailable when the
+ firewall incorrectly interprets the Content and Threat Detection (CTD)
+ global packet queue as being full.
+
+ |
+
|
+ PAN-223365
+ |
+
+
+ The Panorama management server is unable to query any logs if the
+ ElasticSearch health status for any Log Collector (
+ is degraded.
+
+
+ Workaround:
+ Log in to the Log Collector CLI
+ and restart ElasticSearch.
+
+
+
+
+
+ |
+
|
+ PAN-229865
+ |
+
+
+ Upgrading a PA-220 firewall running a PAN-OS 10.1 release fails when
+ the target PAN-OS upgrade version is PAN-OS 10.2.5.
+
+
+ Workaround: On your upgrade path to PAN-OS 10.2.5,
+ first upgrade to PAN-OS 10.2.4 and then upgrade to PAN-OS 10.2.5.
+
+ |
+
|
+ PAN-223677
+ |
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, and PA-5430
+ firewalls) By enabling
+ Lockless QoS
+ feature, a slight degradation in App-ID and Threat performance is
+ expected.
+
+ |
+
|
+ PAN-222586
+ |
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus,
+ Forward Methods, and Built-In Actions for Correlation Log settings
+ () are not displayed and cannot be configured.
+
+ |
+
|
+ PAN-221775
+ |
+
+
+ A Malformed Request error is
+ displayed when you
+ Test Connection for an email server
+ profile () using SMTP over TLS and the
+ Password includes an ampersand
+ (&).
+
+ |
+
|
+ PAN-217307
+
+ This issue is now resolved. See PAN-OS 10.2.11 Addressed Issues.
+
+ |
+
+
+ The following Security policy rule () filters return no results:
+
+
+ log-start eq no
+
+ log-end eq no
+ log-end eq yes
+ |
+
|
+ PAN-213746
+ |
+
+
+ On the Panorama management server, the
+ Hostkey displayed as
+ undefined undefined if you
+ override an SSH Service Profile () Hostkey configured in a Template from the Template Stack.
+
+ |
+
|
+ PAN-213119
+ |
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you
+ view the Block IP list ():
+
+
+ show -> dis-block-table is unexpected
+
+ |
+
|
+ PAN-212889
+
+ This issue is now resolved. See
+ PAN-OS 10.2.14 Addressed Issues
+
+ |
+
+
+ On the Panorama management server, different threat names are used
+ when querying the same threat in the Threat Monitor () and ACC. This results in the ACC
+ displaying
+ no data to display when you are
+ redirected to the ACC after clicking a threat name in the Threat
+ Monitor and filtering the same threat name in the Global Filters.
+
+ |
+
|
+ PAN-212533
+ |
+
+
+ Modifying the Administrator Type for
+ an existing administrator (
+ or
+ ) from Superuser to a
+ Role-Based custom admin, or vice
+ versa, does not modify the access privileges of the administrator.
+
+ |
+
|
+ PAN-211531
+ |
+ + On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (). + | +
|
+ PAN-209288
+ |
+
+
+ Certificates are not successfully generated using SCEP ().
+
+ |
+
|
+ PAN-208622
+ |
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to
+ upload if you specify an Enterprise DLP data filtering profile (
+ with the Action set to Block to a
+ Security policy rule ().
+
+ |
+
|
+ PAN-204689
+ |
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do
+ not work:
+
+
|
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-196504
+ |
+ + License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). + | +
|
+ PAN-194996
+ |
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma
+ Access 3.1.2 deployment, allocating bandwidth for a remote network
+ deployment fails (the OK button is grayed out).
+
+
+ Workaround: Retry the operation.
+
+ |
+
|
+ PAN-194519
+ |
+
+
+ (PA-5450 firewall only) Trying to configure a
+ custom payload format under
+
+ yields a Javascript error.
+
+ |
+
|
+ PAN-194515
+ |
+
+
+ (PA-5450 firewall only) The Panorama web
+ interface does not display any predefined template stack variables in
+ the dropdown menu under
+ .
+
+
+ Workaround: Configure the log interface IP address
+ on the individual firewall web interface instead of on Panorama.
+
+ |
+
|
+ PAN-194424
+ |
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS
+ 10.2.2 while having a log interface configured can cause both the log
+ interface and the management interface to remain connected to the log
+ collector.
+
+
+ Workaround: Restart the log receiver service by
+ running the following CLI command:
+
+
+
+
+
+ |
+
|
+ PAN-194202
+ |
+
+
+ (PA-5450 firewall only) If the management
+ interface and logging interface are configured on the same subnetwork,
+ the firewall conducts log forwarding using the management interface
+ instead of the logging interface.
+
+ |
+
|
+ PAN-190727
+ |
+
+
+ (PA-5450 firewall only) Documentation for
+ configuring the log interface is unavailable on the web interface and
+ in the PAN-OS Administrator’s Guide.
+
+ |
+
|
+ PAN-189111
+ |
+
+
+ After deleting an MP pod and it comes up, the
+ show routing command output
+ appears empty and traffic stops working.
+
+ |
+
|
+ PAN-189076
+ |
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a
+ broadcast link and a designated router (DR) priority of 0 (zero) are
+ stuck in a two-way state after HA failover.
+
+
+ Workaround: Configure at least one OSPFv3 neighbor
+ with a non-zero priority setting in the same broadcast domain.
+
+ |
+
|
+ PAN-188358
+ |
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management
+ port LEDs do not light up when a 10G Ethernet cable is plugged in.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187643
+ |
+
+
+ If you enable SCTP security using a Panorama template when
+ SCTP INIT Flood Protection is
+ enabled in the Zone Protection profile using Panorama and you commit
+ all changes, the commit is successful but the
+ SCTP INIT option is not available in
+ the Zone Protection profile.
+
+
+ Workaround: Log out of the firewall and log in
+ again to make the SCIT INIT option
+ available on the web interface.
+
+ |
+
|
+ PAN-187612
+ |
+
+
+ On the Panorama management server, not all data profiles () are displayed after you:
+
+
+ Workaround: Log in to the Panorama CLI and reset
+ the DLP plugin.
+
+ admin > request plugins dlp reset
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-187370
+ |
+
+
+ On a firewall with Advanced Routing enabled, if there is also a
+ logical router instance that uses the default configuration and has no
+ interfaces assigned to it, this will result in terminating the
+ management daemon and main routing daemon in the firewall during
+ commit.
+
+
+ Workaround: Do not use a logical router instance
+ with no interfaces bound to it.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-186282
+ |
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match
+ criteria automatically when adding dynamic address groups.
+
+
+ Workaround: Reboot the Panorama HA pair.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-181823
+ |
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer
+ port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports
+ on the firewall to go down if they are set to Auto.
+
+ |
+
|
+ PAN-180661
+ |
+
+
+ On the Panorama management server, pushing an unsupported Minimum
+ Password Complexity () to a managed firewall erroneously displays
+ commit time out as the reason the
+ commit failed.
+
+ |
+
|
+ PAN-180104
+ |
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2,
+ CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster
+ previously had a CN-Series as a DaemonSet deployment running PAN-OS
+ 10.0 or 10.1.
+
+
+ Workaround: Reboot the worker nodes before
+ upgrading to PAN-OS 10.2.
+
+ |
+
|
+ PAN-178194
+ |
+
+
+ A user interface issue in PAN-OS renders the contents of the
+ Inline ML tab in the
+ URL Filtering Profile inaccessible
+ on firewalls licensed for Advanced URL Filtering. Additionally, a
+ message indicating that a
+ License required for URL filtering to function
+ is unavailable displays at the bottom of the UI. These errors do not
+ affect the operation of Advanced URL Filtering or URL Filtering Inline
+ ML.
+
+
+ Workaround: Configuration settings for URL
+ Filtering Inline ML must be applied through the CLI. The following
+ configuration commands are available:
+
+
|
+
|
+ PAN-177455
+ |
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA
+ (High Availability) clustering enabled and using an HA4 communication
+ link. Attempting to load PAN-OS 10.2.0 on the firewall causes the
+ PA-7000 100G NPC to go offline. As a result, the firewall fails to
+ boot normally and enters maintenance mode. HA Pairs of Active-Passive
+ and Active-Active firewalls are not affected.
+
+ |
+
|
+ PAN-175915
+ |
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks
+ and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network
+ Protection Profile, the traffic logs do not display network slice SST
+ and SD values.
+
+ |
+
|
+ PAN-174982
+ |
+
+
+ In HA active/active configurations where, when interfaces that were
+ associated with a virtual router were deleted, the configuration
+ change did not sync.
+
+ |
+
|
+ PAN-172274
+ |
+
+
+ When you activate the advanced URL filtering license, your license
+ entitlements for PAN-DB and advanced URL filtering might not display
+ correctly on the firewall — this is a display anomaly, not a licensing
+ issue, and does not affect access to the services.
+
+
+ Workaround: Issue the following command to
+ retrieve and update the licenses:
+ license request fetch.
+
+ |
+
|
+ PAN-171938
+ |
+
+
+ No results are displayed when you
+ Show Application Filter for a
+ Security policy rule ().
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-5854
+ |
+
+
+ The WildFire analysis report on the firewall log viewer () does not display the following data fields: File Type, SHA-256,
+ MD-5, and File Size".
+
+
+ Workaround: Download and open the WildFire
+ analysis report in the PDF format using the link in the upper
+ right-hand corner of the
+ Detailed Log View.
+
+ |
+
|
+ WF500-5843
+ |
+
+
+ In a WildFire appliance cluster, issuing the
+ show cluster-all peers CLI command
+ when a node within the cluster is being rebooted generates the
+ following error:
+ Server error : An error occured.
+
+ |
+
|
+ WF500-5840
+ |
+
+
+ The sample analysis statistics that are returned when issuing the
+ show wildfire local statistics CLI
+ command in WildFire appliance cluster deployments may not accurately
+ reflect the number of samples that have been processed.
+
+ |
+
|
+ WF500-5823
+ |
+
+
+ The following WildFire appliance CLI command does not return a
+ signature generation status as expected:
+ show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance
+ from analyzing a sample.
+
+ |
+
|
+ WF500-5781
+ |
+
+
+ The WildFire appliance might erroneously generate and log the
+ following device certification error:
+ Device certificate is missing or invalid. It cannot be
+ renewed.
+
+ |
+
|
+ WF500-5754
+ |
+
+
+ In WildFire appliance clusters, issuing the
+ show cluster controller CLI command
+ generates an error when an IPv6 address is configured for the
+ management interface but not for the cluster interface.
+
+
+ Workaround: Ensure all WildFire appliance
+ interfaces that are enabled use matching protocols (all IPv4 or all
+ IPv6).
+
+ |
+
|
+ WF500-5632
+ |
+
+
+ The number of registered WildFire appliances reported in Panorama
+ () does not accurately reflect the current status of connected
+ WildFire appliances.
+
+ |
+
|
+ PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues.
+
+ |
+
+
+ A race condition may cause the dataplane to restart unexpectedly when
+ a zip decompression offload result is returned for a session that has
+ already closed. The session state is not validated before processing
+ the result because the offload result does not follow the fastpath
+ where these checks are normally performed.
+
+
+ Workaround: Disable zip hardware offloading (may
+ cause higher CPU usage).
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See PAN-OS 10.2.13-h18 Addressed Issuesand
+ PAN-OS 10.2.16-h6 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-297610
+ |
+
+
+ A firewall may become unresponsive after an upgrade due to the
+ fsck command scanning drive
+ partitions in parallel with the root partition, causing the process to
+ take an extended amount of time.
+
+ |
+
|
+ PAN-297295
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent
+ process restarts multiple times and exhausts its restart limit,
+ resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-295803
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-295255
+ |
+
+
+ Palo Alto Networks next-generation firewalls may experience service
+ disruptions due to all_task process
+ crashes when deployed in environments having non-uniform MTU and are
+ terminating IPSec tunnels.
+
+ |
+
|
+ PAN-292344
+ |
+
+
+ When upgrading from PAN-OS 10.2.9-h1 to PAN-OS 10.2.13-h5, the
+ firewall reboots repeatedly and enters maintenance mode.
+
+ |
+
|
+ PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues.
+
+ |
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM)
+ condition due to a memory leak and displays an error message. This
+ issue causes the device to crash and reboot unexpectedly.
+
+ |
+
|
+ PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues
+
+ |
+
+
+ A memory leak in the configd process
+ might lead to an active firewall to reboot due to an Out-of-Memory
+ (OOM) condition. This issue is observed when specific status commands,
+ such as
+ request log-collector forwarding status
+ are executed at high frequencies.
+
+ |
+
|
+ PAN-290996
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues
+
+ |
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS)
+ counters incorrectly return a value of 0 for each virtual system
+ (VSYS), despite the firewall actively processing connections.
+
+ |
+
|
+ PAN-290088
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues
+
+ |
+
+
+ (Firewalls in HA configurations only) Routed
+ process may stop responding after changing MTU or any link parameters
+ when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-287871
+ |
+
+
+ When SSL Inbound Inspection is enabled and the firewall receives
+ fragmented Client Hello packets that include the TCP timestamp option,
+ the Client Hello message is forwarded to the destination server
+ without the timestamp option.
+
+ |
+
|
+ PAN-287803
+ |
+
+
+ Users might be unable to access some URLs due to issues involving the
+ accumulation proxy and the Path Maximum Transmission Unit (MTU).
+
+
+ To address this issue, use one of the following workarounds:
+
+
|
+
|
+ PAN-286231
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-285894
+
+ This issue is now resolved. See PAN-OS 10.2.13-h10 Addressed Issues
+
+ |
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may
+ occur, which could result in firewall reboots.
+
+
+ Workaround: Disable the Preserve Pre-NAT feature
+ using the
+ set deviceconfig setting preserve-prenat-feature no
+ CLI command.
+
+ |
+
|
+ PAN-284073
+ |
+
+
+ The firewall web interface becomes inaccessible and commits fail.
+
+ |
+
|
+ PAN-284067
+ |
+
+
+ A cumulative memory leak in the
+ devsrvr
+ process gets progressively worse whenever the CLI command
+ show running application statistics
+ is issued. This memory leak will gradually consume system memory and
+ produce an out-of-memory (OOM) condition, leading to an eventual
+ firewall reboot.
+
+
+ Workaround: Avoid using the CLI command:
+ show running application statistics.
+
+ |
+
|
+ PAN-281370
+ |
+
+
+ The Advanced WildFire Inline ML models
+ OOXML and
+ Mach-O erroneously display as being
+ available from the CLI; however, they are only available on PAN-OS
+ 11.1.3 and later releases.
+
+ |
+
| PAN-279746 | +
+
+ An SSL/TLS Client Hello may not be sent if the Client Hello arrives at
+ the firewall in multiple TCP segments and the traffic is not subject
+ to SSL decryption.
+
+ |
+
|
+ PAN-273158
+ |
+
+
+ (PA-7000 Series firewalls only) Due to an
+ incorrect configuration on the ASIC, receiving a mix of jumbo and
+ non-jumbo packets may cause silent packet drops or application
+ slowness.
+
+ |
+
|
+ PAN-265336
+
+ This issue is now resolved. See PAN-OS 10.2.11-h2 Addressed Issues.
+
+ |
+
+
+ Copper ports flap when generating a technical support file, executing
+ telemetry, or retrieving port status using a Management Data
+ Input/Output (MDIO) read.
+
+ |
+
|
+ PAN-264680
+
+ This issue is now resolved. See PAN-OS 10.2.11-h3 Addressed Issues.
+
+ |
+
+
+ (PA-220 firewalls only)
+
+ is not displayed when the Enterprise Data Loss Prevention (E-DLP)
+ plugin is installed.
+
+
+ Workaround: Uninstall the Enterprise DLP plugin.
+
+
|
+
|
+ PAN-264580
+ |
+
+
+ (PA-3400 Series firewalls only) Upgrading to
+ PAN-OS 10.2.11 results in the following error:
+ Target image validation failed with error invalid literal for int()
+ with base 10.
+
+ |
+
| PAN-263226 | +
+
+ When SSL decryption is enabled and Client Hello messages span multiple
+ TCP segments, elements from the proxy_l2info memory pool may not be
+ freed properly. Memory leaks in this pool cause some SSL decryption
+ sessions to fail.
+
+
+ Workaround: Disable Client Hello accumulation
+ using the
+ debug dataplane set ssl-decrypt accumulate-client-hello disable
+ yes
+ CLI command.
+
+ |
+
|
+ PAN-262287
+
+ This issue is now resolved. See PAN-OS 10.2.13 Addressed Issues.
+
+ |
+
+
+ Dereferencing a NULL pointer that occurs might cause
+ pan_task
+ processes to crash.
+
+ |
+
|
+ PAN-261429
+
+ This issue is now resolved. See PAN-OS 10.2.15 Addressed Issues
+
+ |
+
+
+ The command
+ show auth radius-require-msg-authentic
+ might return no output.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
| PAN-259769 | +
+
+ GlobalProtect portal is not accessible via a web browser and the app
+ displays the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-257957
+
+ This issue is now resolved. See PAN-OS 10.2.12 Addressed Issues.Affects 10.2.11-h1 and later 10.2 releases.
+
+ |
+
+
+ If you enable FIPS-CC mode and use the PAP or CHAP authentication
+ methods for your RADIUS server, the authd process may restart
+ unexpectedly. To avoid this issue, use one of the following
+ workarounds:
+
+
|
+
|
+ PAN-257601
+
+ Fixed in
+ PAN-OS 10.2.11. Affects 10.2.11-h2 and later 10.2 releases.
+
+ |
+
+
+ (PA-5450 firewalls only) Networking cards can
+ experience an internal link fault, causing path monitoring failure on
+ the Dataplane Processing Card (DPC).
+
+ |
+
|
+ PAN-237106
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in Traffic logs.
+
+ |
+
|
+ PAN-223365
+ |
+
+
+ The Panorama management server is unable to query any logs if the
+ ElasticSearch health status for any Log Collector (
+ is degraded.
+
+
+ Workaround:
+ Log in to the Log Collector CLI
+ and restart ElasticSearch.
+
+
+
+
+
+ |
+
|
+ PAN-229865
+ |
+
+
+ Upgrading a PA-220 firewall running a PAN-OS 10.1 release fails when
+ the target PAN-OS upgrade version is PAN-OS 10.2.5.
+
+
+ Workaround: On your upgrade path to PAN-OS 10.2.5,
+ first upgrade to PAN-OS 10.2.4 and then upgrade to PAN-OS 10.2.5.
+
+ |
+
|
+ PAN-226361
+
+ This issue is now resolved. See PAN-OS 10.2.11-h4 Addressed Issues.
+
+ |
+
+
+ Sessions might end unexpectedly with the error
+ resources-unavailable when the
+ firewall incorrectly interprets the Content and Threat Detection (CTD)
+ global packet queue as being full.
+
+ |
+
|
+ PAN-223677
+ |
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, and PA-5430
+ firewalls) By enabling the
+ Lockless QoS
+ feature, a slight degradation in App-ID and Threat performance is
+ expected.
+
+ |
+
|
+ PAN-222586
+ |
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus,
+ Forward Methods, and Built-In Actions for Correlation Log settings
+ () are not displayed and cannot be configured.
+
+ |
+
|
+ PAN-221775
+ |
+
+
+ A Malformed Request error is
+ displayed when you
+ Test Connection for an email server
+ profile () using SMTP over TLS and the
+ Password includes an ampersand
+ (&).
+
+ |
+
|
+ PAN-213746
+ |
+
+
+ On the Panorama management server, the
+ Hostkey displayed as
+ undefined undefined if you
+ override an SSH Service Profile () Hostkey configured in a Template from the Template Stack.
+
+ |
+
|
+ PAN-213119
+ |
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you
+ view the Block IP list ():
+
+
+ show -> dis-block-table is unexpected
+
+ |
+
|
+ PAN-212889
+
+ This issue is now resolved. See
+ PAN-OS 10.2.14 Addressed Issues
+
+ |
+
+
+ On the Panorama management server, different threat names are used
+ when querying the same threat in the Threat Monitor () and ACC. This results in the ACC
+ displaying
+ no data to display when you are
+ redirected to the ACC after clicking a threat name in the Threat
+ Monitor and filtering the same threat name in the Global Filters.
+
+ |
+
|
+ PAN-212533
+ |
+
+
+ Modifying the Administrator Type for
+ an existing administrator (
+ or
+ ) from Superuser to a
+ Role-Based custom admin, or vice
+ versa, does not modify the access privileges of the administrator.
+
+ |
+
|
+ PAN-211531
+ |
+ + On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (). + | +
|
+ PAN-209288
+ |
+
+
+ Certificates are not successfully generated using SCEP ().
+
+ |
+
|
+ PAN-208622
+ |
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to
+ upload if you specify an Enterprise DLP data filtering profile (
+ with the Action set to Block to a
+ Security policy rule ().
+
+ |
+
|
+ PAN-204689
+ |
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do
+ not work:
+
+
|
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-196504
+ |
+ + License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). + | +
|
+ PAN-194996
+ |
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma
+ Access 3.1.2 deployment, allocating bandwidth for a remote network
+ deployment fails (the OK button is grayed out).
+
+
+ Workaround: Retry the operation.
+
+ |
+
|
+ PAN-194519
+ |
+
+
+ (PA-5450 firewall only) Trying to configure a
+ custom payload format under
+
+ yields a JavaScript error.
+
+ |
+
|
+ PAN-194515
+ |
+
+
+ (PA-5450 firewall only) The Panorama web
+ interface does not display any predefined template stack variables in
+ the dropdown menu under
+ .
+
+
+ Workaround: Configure the log interface IP address
+ on the individual firewall web interface instead of on Panorama.
+
+ |
+
|
+ PAN-194424
+ |
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS
+ 10.2.2 while having a log interface configured can cause both the log
+ interface and the management interface to remain connected to the log
+ collector.
+
+
+ Workaround: Restart the log receiver service by
+ running the following CLI command:
+
+
+
+
+
+ |
+
|
+ PAN-194202
+ |
+
+
+ (PA-5450 firewall only) If the management
+ interface and logging interface are configured on the same subnetwork,
+ the firewall conducts log forwarding using the management interface
+ instead of the logging interface.
+
+ |
+
|
+ PAN-190727
+ |
+
+
+ (PA-5450 firewall only) Documentation for
+ configuring the log interface is unavailable on the web interface and
+ in the PAN-OS Administrator’s Guide.
+
+ |
+
|
+ PAN-189111
+ |
+
+
+ After deleting an MP pod and it comes up, the
+ show routing command output
+ appears empty and traffic stops working.
+
+ |
+
|
+ PAN-189076
+ |
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a
+ broadcast link and a designated router (DR) priority of 0 (zero) are
+ stuck in a two-way state after HA failover.
+
+
+ Workaround: Configure at least one OSPFv3 neighbor
+ with a non-zero priority setting in the same broadcast domain.
+
+ |
+
|
+ PAN-188358
+ |
+
+
+ After triggering a soft reboot on an M-700 appliance, the Management
+ port LEDs do not light up when a 10G Ethernet cable is plugged in.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187643
+ |
+
+
+ If you enable SCTP security using a Panorama template when
+ SCTP INIT Flood Protection is
+ enabled in the Zone Protection profile using Panorama and you commit
+ all changes, the commit is successful but the
+ SCTP INIT option is not available in
+ the Zone Protection profile.
+
+
+ Workaround: Log out of the firewall and log in
+ again to make the SCIT INIT option
+ available on the web interface.
+
+ |
+
|
+ PAN-187612
+ |
+
+
+ On the Panorama management server, not all data profiles () are displayed after you:
+
+
+ Workaround: Log in to the Panorama CLI and reset
+ the DLP plugin.
+
+ admin > request plugins dlp reset
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-187370
+ |
+
+
+ On a firewall with Advanced Routing enabled, if there is also a
+ logical router instance that uses the default configuration and has no
+ interfaces assigned to it, this will result in terminating the
+ management daemon and main routing daemon in the firewall during
+ commit.
+
+
+ Workaround: Do not use a logical router instance
+ with no interfaces bound to it.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-186282
+ |
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match
+ criteria automatically when adding dynamic address groups.
+
+
+ Workaround: Reboot the Panorama HA pair.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to an M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 Series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-181823
+ |
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer
+ port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports
+ on the firewall to go down if they are set to Auto.
+
+ |
+
|
+ PAN-180661
+ |
+
+
+ On the Panorama management server, pushing an unsupported Minimum
+ Password Complexity () to a managed firewall erroneously displays
+ commit time out as the reason the
+ commit failed.
+
+ |
+
|
+ PAN-180104
+ |
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2,
+ CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster
+ previously had a CN-Series as a DaemonSet deployment running PAN-OS
+ 10.0 or 10.1.
+
+
+ Workaround: Reboot the worker nodes before
+ upgrading to PAN-OS 10.2.
+
+ |
+
|
+ PAN-178194
+ |
+
+
+ A user interface issue in PAN-OS renders the contents of the
+ Inline ML tab in the
+ URL Filtering Profile inaccessible
+ on firewalls licensed for Advanced URL Filtering. Additionally, a
+ message indicating that a
+ License required for URL filtering to function
+ is unavailable displays at the bottom of the UI. These errors do not
+ affect the operation of Advanced URL Filtering or URL Filtering inline
+ ML.
+
+
+ Workaround: Configuration settings for URL
+ Filtering inline ML must be applied through the CLI. The following
+ configuration commands are available:
+
+
|
+
|
+ PAN-177455
+ |
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA
+ (high availability) clustering enabled and using an HA4 communication
+ link. Attempting to load PAN-OS 10.2.0 on the firewall causes the
+ PA-7000 100G NPC to go offline. As a result, the firewall fails to
+ boot normally and enters maintenance mode. HA pairs of Active-Passive
+ and Active-Active firewalls are not affected.
+
+ |
+
|
+ PAN-175915
+ |
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks
+ and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network
+ Protection Profile, the Traffic logs do not display network slice SST
+ and SD values.
+
+ |
+
|
+ PAN-174982
+ |
+
+
+ In HA active/active configurations where, when interfaces that were
+ associated with a virtual router were deleted, the configuration
+ change did not sync.
+
+ |
+
|
+ PAN-172274
+ |
+
+
+ When you activate the Advanced URL Filtering license, your license
+ entitlements for PAN-DB and Advanced URL Filtering might not display
+ correctly on the firewall — this is a display anomaly, not a licensing
+ issue, and does not affect access to the services.
+
+
+ Workaround: Issue the following command to
+ retrieve and update the licenses:
+ license request fetch.
+
+ |
+
|
+ PAN-171938
+ |
+
+
+ No results are displayed when you
+ Show Application Filter for a
+ Security policy rule ().
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-5854
+ |
+
+
+ The WildFire analysis report on the firewall log viewer () does not display the following data fields: File Type, SHA-256,
+ MD-5, and File Size".
+
+
+ Workaround: Download and open the WildFire
+ analysis report in the PDF format using the link in the upper
+ right-hand corner of the
+ Detailed Log View.
+
+ |
+
|
+ WF500-5843
+ |
+
+
+ In a WildFire appliance cluster, issuing the
+ show cluster-all peers CLI command
+ when a node within the cluster is being rebooted generates the
+ following error:
+ Server error : An error occured.
+
+ |
+
|
+ WF500-5840
+ |
+
+
+ The sample analysis statistics that are returned when issuing the
+ show wildfire local statistics CLI
+ command in WildFire appliance cluster deployments may not accurately
+ reflect the number of samples that have been processed.
+
+ |
+
|
+ WF500-5823
+ |
+
+
+ The following WildFire appliance CLI command does not return a
+ signature generation status as expected:
+ show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance
+ from analyzing a sample.
+
+ |
+
|
+ WF500-5781
+ |
+
+
+ The WildFire appliance might erroneously generate and log the
+ following device certification error:
+ Device certificate is missing or invalid. It cannot be
+ renewed.
+
+ |
+
|
+ WF500-5754
+ |
+
+
+ In WildFire appliance clusters, issuing the
+ show cluster controller CLI command
+ generates an error when an IPv6 address is configured for the
+ management interface but not for the cluster interface.
+
+
+ Workaround: Ensure all WildFire appliance
+ interfaces that are enabled use matching protocols (all IPv4 or all
+ IPv6).
+
+ |
+
|
+ WF500-5632
+ |
+
+
+ The number of registered WildFire appliances reported in Panorama
+ () does not accurately reflect the current status of connected
+ WildFire appliances.
+
+ |
+
|
+ PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues.
+
+ |
+
+
+ A race condition may cause the dataplane to restart unexpectedly when
+ a zip decompression offload result is returned for a session that has
+ already closed. The session state is not validated before processing
+ the result because the offload result does not follow the fastpath
+ where these checks are normally performed.
+
+
+ Workaround: Disable zip hardware offloading (may
+ cause higher CPU usage).
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See PAN-OS 10.2.13-h18 Addressed Issuesand
+ PAN-OS 10.2.16-h6 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-297610
+ |
+
+
+ A firewall may become unresponsive after an upgrade due to the
+ fsck command scanning drive
+ partitions in parallel with the root partition, causing the process to
+ take an extended amount of time.
+
+ |
+
|
+ PAN-297295
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent
+ process restarts multiple times and exhausts its restart limit,
+ resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-295803
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-295255
+ |
+
+
+ Palo Alto Networks next-generation firewalls may experience service
+ disruptions due to all_task process
+ crashes when deployed in environments having non-uniform MTU and are
+ terminating IPSec tunnels.
+
+ |
+
|
+ PAN-292344
+ |
+
+
+ When upgrading from PAN-OS 10.2.9-h1 to PAN-OS 10.2.13-h5, the
+ firewall reboots repeatedly and enters maintenance mode.
+
+ |
+
|
+ PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues.
+
+ |
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM)
+ condition due to a memory leak and displays an error message. This
+ issue causes the device to crash and reboot unexpectedly.
+
+ |
+
|
+ PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues
+
+ |
+
+
+ A memory leak in the configd process
+ might lead to an active firewall to reboot due to an Out-of-Memory
+ (OOM) condition. This issue is observed when specific status commands,
+ such as
+ request log-collector forwarding status
+ are executed at high frequencies.
+
+ |
+
|
+ PAN-290996
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues
+
+ |
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS)
+ counters incorrectly return a value of 0 for each virtual system
+ (VSYS), despite the firewall actively processing connections.
+
+ |
+
|
+ PAN-290088
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues
+
+ |
+
+
+ (Firewalls in HA configurations only) Routed
+ process may stop responding after changing MTU or any link parameters
+ when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-287803
+ |
+
+
+ Users might be unable to access some URLs due to issues involving the
+ accumulation proxy and the Path Maximum Transmission Unit (MTU).
+
+
+ To address this issue, use one of the following workarounds:
+
+
|
+
|
+ PAN-286231
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-285894
+
+ This issue is now resolved. See PAN-OS 10.2.13-h10 Addressed Issues
+
+ |
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may
+ occur, which could result in firewall reboots.
+
+
+ Workaround: Disable the Preserve Pre-NAT feature
+ using the
+ set deviceconfig setting preserve-prenat-feature no
+ CLI command.
+
+ |
+
|
+ PAN-284073
+ |
+
+
+ The firewall web interface becomes inaccessible and commits fail.
+
+ |
+
|
+ PAN-284067
+ |
+
+
+ A cumulative memory leak in the
+ devsrvr
+ process gets progressively worse whenever the CLI command
+ show running application statistics
+ is issued. This memory leak will gradually consume system memory and
+ produce an out-of-memory (OOM) condition, leading to an eventual
+ firewall reboot.
+
+
+ Workaround: Avoid using the CLI command:
+ show running application statistics.
+
+ |
+
|
+ PAN-281370
+ |
+
+
+ The Advanced WildFire Inline ML models
+ OOXML and
+ Mach-O erroneously display as being
+ available from the CLI; however, they are only available on PAN-OS
+ 11.1.3 and later releases.
+
+ |
+
| PAN-279746 | +
+
+ An SSL/TLS Client Hello may not be sent if the Client Hello arrives at
+ the firewall in multiple TCP segments and the traffic is not subject
+ to SSL decryption.
+
+ |
+
|
+ PAN-273158
+ |
+
+
+ (PA-7000 Series firewalls only) Due to an
+ incorrect configuration on the ASIC, receiving a mix of jumbo and
+ non-jumbo packets may cause silent packet drops or application
+ slowness.
+
+ |
+
|
+ PAN-262287
+
+ This issue is now resolved. See PAN-OS 10.2.13 Addressed Issues.
+
+ |
+
+
+ Dereferencing a NULL pointer that occurs might cause
+ pan_task
+ processes to crash.
+
+ |
+
|
+ PAN-261429
+
+ This issue is now resolved. See PAN-OS 10.2.15 Addressed Issues
+
+ |
+
+
+ The command
+ show auth radius-require-msg-authentic
+ might return no output.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
| PAN-259769 | +
+
+ GlobalProtect portal is not accessible via a web browser and the app
+ displays the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-257601
+
+ Fixed in
+ PAN-OS 10.2.11. Affects 10.2.11-h2 and later 10.2 releases.
+
+ |
+
+
+ (PA-5450 firewalls only) Networking cards can
+ experience an internal link fault, causing path monitoring failure on
+ the Dataplane Processing Card (DPC).
+
+ |
+
|
+ PAN-237106
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-223365
+ |
+
+
+ The Panorama management server is unable to query any logs if the
+ ElasticSearch health status for any Log Collector (
+ is degraded.
+
+
+ Workaround:
+ Log in to the Log Collector CLI
+ and restart ElasticSearch.
+
+
+
+
+
+ |
+
|
+ PAN-229865
+ |
+
+
+ Upgrading a PA-220 firewall running a PAN-OS 10.1 release fails when
+ the target PAN-OS upgrade version is PAN-OS 10.2.5.
+
+
+ Workaround: On your upgrade path to PAN-OS 10.2.5,
+ first upgrade to PAN-OS 10.2.4 and then upgrade to PAN-OS 10.2.5.
+
+ |
+
|
+ PAN-223677
+ |
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, and PA-5430
+ firewalls) By enabling
+ Lockless QoS
+ feature, a slight degradation in App-ID and Threat performance is
+ expected.
+
+ |
+
|
+ PAN-222586
+ |
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus,
+ Forward Methods, and Built-In Actions for Correlation Log settings
+ () are not displayed and cannot be configured.
+
+ |
+
|
+ PAN-221775
+ |
+
+
+ A Malformed Request error is
+ displayed when you
+ Test Connection for an email server
+ profile () using SMTP over TLS and the
+ Password includes an ampersand
+ (&).
+
+ |
+
|
+ PAN-213746
+ |
+
+
+ On the Panorama management server, the
+ Hostkey displayed as
+ undefined undefined if you
+ override an SSH Service Profile () Hostkey configured in a Template from the Template Stack.
+
+ |
+
|
+ PAN-213119
+ |
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you
+ view the Block IP list ():
+
+
+ show -> dis-block-table is unexpected
+
+ |
+
|
+ PAN-212889
+
+ This issue is now resolved. See
+ PAN-OS 10.2.14 Addressed Issues
+
+ |
+
+
+ On the Panorama management server, different threat names are used
+ when querying the same threat in the Threat Monitor () and ACC. This results in the ACC
+ displaying
+ no data to display when you are
+ redirected to the ACC after clicking a threat name in the Threat
+ Monitor and filtering the same threat name in the Global Filters.
+
+ |
+
|
+ PAN-212533
+ |
+
+
+ Modifying the Administrator Type for
+ an existing administrator (
+ or
+ ) from Superuser to a
+ Role-Based custom admin, or vice
+ versa, does not modify the access privileges of the administrator.
+
+ |
+
|
+ PAN-211531
+ |
+ + On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (). + | +
|
+ PAN-209288
+ |
+
+
+ Certificates are not successfully generated using SCEP ().
+
+ |
+
|
+ PAN-208622
+ |
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to
+ upload if you specify an Enterprise DLP data filtering profile (
+ with the Action set to Block to a
+ Security policy rule ().
+
+ |
+
|
+ PAN-204689
+ |
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do
+ not work:
+
+
|
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-196504
+ |
+ + License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). + | +
|
+ PAN-194996
+ |
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma
+ Access 3.1.2 deployment, allocating bandwidth for a remote network
+ deployment fails (the OK button is grayed out).
+
+
+ Workaround: Retry the operation.
+
+ |
+
|
+ PAN-194519
+ |
+
+
+ (PA-5450 firewall only) Trying to configure a
+ custom payload format under
+
+ yields a Javascript error.
+
+ |
+
|
+ PAN-194515
+ |
+
+
+ (PA-5450 firewall only) The Panorama web
+ interface does not display any predefined template stack variables in
+ the dropdown menu under
+ .
+
+
+ Workaround: Configure the log interface IP address
+ on the individual firewall web interface instead of on Panorama.
+
+ |
+
|
+ PAN-194424
+ |
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS
+ 10.2.2 while having a log interface configured can cause both the log
+ interface and the management interface to remain connected to the log
+ collector.
+
+
+ Workaround: Restart the log receiver service by
+ running the following CLI command:
+
+
+
+
+
+ |
+
|
+ PAN-194202
+ |
+
+
+ (PA-5450 firewall only) If the management
+ interface and logging interface are configured on the same subnetwork,
+ the firewall conducts log forwarding using the management interface
+ instead of the logging interface.
+
+ |
+
|
+ PAN-190727
+ |
+
+
+ (PA-5450 firewall only) Documentation for
+ configuring the log interface is unavailable on the web interface and
+ in the PAN-OS Administrator’s Guide.
+
+ |
+
|
+ PAN-189111
+ |
+
+
+ After deleting an MP pod and it comes up, the
+ show routing command output
+ appears empty and traffic stops working.
+
+ |
+
|
+ PAN-189076
+ |
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a
+ broadcast link and a designated router (DR) priority of 0 (zero) are
+ stuck in a two-way state after HA failover.
+
+
+ Workaround: Configure at least one OSPFv3 neighbor
+ with a non-zero priority setting in the same broadcast domain.
+
+ |
+
|
+ PAN-188358
+ |
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management
+ port LEDs do not light up when a 10G Ethernet cable is plugged in.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187643
+ |
+
+
+ If you enable SCTP security using a Panorama template when
+ SCTP INIT Flood Protection is
+ enabled in the Zone Protection profile using Panorama and you commit
+ all changes, the commit is successful but the
+ SCTP INIT option is not available in
+ the Zone Protection profile.
+
+
+ Workaround: Log out of the firewall and log in
+ again to make the SCIT INIT option
+ available on the web interface.
+
+ |
+
|
+ PAN-187612
+ |
+
+
+ On the Panorama management server, not all data profiles () are displayed after you:
+
+
+ Workaround: Log in to the Panorama CLI and reset
+ the DLP plugin.
+
+ admin > request plugins dlp reset
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-187370
+ |
+
+
+ On a firewall with Advanced Routing enabled, if there is also a
+ logical router instance that uses the default configuration and has no
+ interfaces assigned to it, this will result in terminating the
+ management daemon and main routing daemon in the firewall during
+ commit.
+
+
+ Workaround: Do not use a logical router instance
+ with no interfaces bound to it.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-186282
+ |
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match
+ criteria automatically when adding dynamic address groups.
+
+
+ Workaround: Reboot the Panorama HA pair.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-181823
+ |
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer
+ port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports
+ on the firewall to go down if they are set to Auto.
+
+ |
+
|
+ PAN-180661
+ |
+
+
+ On the Panorama management server, pushing an unsupported Minimum
+ Password Complexity () to a managed firewall erroneously displays
+ commit time out as the reason the
+ commit failed.
+
+ |
+
|
+ PAN-180104
+ |
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2,
+ CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster
+ previously had a CN-Series as a DaemonSet deployment running PAN-OS
+ 10.0 or 10.1.
+
+
+ Workaround: Reboot the worker nodes before
+ upgrading to PAN-OS 10.2.
+
+ |
+
|
+ PAN-178194
+ |
+
+
+ A user interface issue in PAN-OS renders the contents of the
+ Inline ML tab in the
+ URL Filtering Profile inaccessible
+ on firewalls licensed for Advanced URL Filtering. Additionally, a
+ message indicating that a
+ License required for URL filtering to function
+ is unavailable displays at the bottom of the UI. These errors do not
+ affect the operation of Advanced URL Filtering or URL Filtering Inline
+ ML.
+
+
+ Workaround: Configuration settings for URL
+ Filtering Inline ML must be applied through the CLI. The following
+ configuration commands are available:
+
+
|
+
|
+ PAN-177455
+ |
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA
+ (High Availability) clustering enabled and using an HA4 communication
+ link. Attempting to load PAN-OS 10.2.0 on the firewall causes the
+ PA-7000 100G NPC to go offline. As a result, the firewall fails to
+ boot normally and enters maintenance mode. HA Pairs of Active-Passive
+ and Active-Active firewalls are not affected.
+
+ |
+
|
+ PAN-175915
+ |
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks
+ and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network
+ Protection Profile, the traffic logs do not display network slice SST
+ and SD values.
+
+ |
+
|
+ PAN-174982
+ |
+
+
+ In HA active/active configurations where, when interfaces that were
+ associated with a virtual router were deleted, the configuration
+ change did not sync.
+
+ |
+
|
+ PAN-172274
+ |
+
+
+ When you activate the advanced URL filtering license, your license
+ entitlements for PAN-DB and advanced URL filtering might not display
+ correctly on the firewall — this is a display anomaly, not a licensing
+ issue, and does not affect access to the services.
+
+
+ Workaround: Issue the following command to
+ retrieve and update the licenses:
+ license request fetch.
+
+ |
+
|
+ PAN-171938
+ |
+
+
+ No results are displayed when you
+ Show Application Filter for a
+ Security policy rule ().
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-5854
+ |
+
+
+ The WildFire analysis report on the firewall log viewer () does not display the following data fields: File Type, SHA-256,
+ MD-5, and File Size".
+
+
+ Workaround: Download and open the WildFire
+ analysis report in the PDF format using the link in the upper
+ right-hand corner of the
+ Detailed Log View.
+
+ |
+
|
+ WF500-5843
+ |
+
+
+ In a WildFire appliance cluster, issuing the
+ show cluster-all peers CLI command
+ when a node within the cluster is being rebooted generates the
+ following error:
+ Server error : An error occured.
+
+ |
+
|
+ WF500-5840
+ |
+
+
+ The sample analysis statistics that are returned when issuing the
+ show wildfire local statistics CLI
+ command in WildFire appliance cluster deployments may not accurately
+ reflect the number of samples that have been processed.
+
+ |
+
|
+ WF500-5823
+ |
+
+
+ The following WildFire appliance CLI command does not return a
+ signature generation status as expected:
+ show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance
+ from analyzing a sample.
+
+ |
+
|
+ WF500-5781
+ |
+
+
+ The WildFire appliance might erroneously generate and log the
+ following device certification error:
+ Device certificate is missing or invalid. It cannot be
+ renewed.
+
+ |
+
|
+ WF500-5754
+ |
+
+
+ In WildFire appliance clusters, issuing the
+ show cluster controller CLI command
+ generates an error when an IPv6 address is configured for the
+ management interface but not for the cluster interface.
+
+
+ Workaround: Ensure all WildFire appliance
+ interfaces that are enabled use matching protocols (all IPv4 or all
+ IPv6).
+
+ |
+
|
+ WF500-5632
+ |
+
+
+ The number of registered WildFire appliances reported in Panorama
+ () does not accurately reflect the current status of connected
+ WildFire appliances.
+
+ |
+
|
+ PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues.
+
+ |
+
+
+ A race condition may cause the dataplane to restart unexpectedly when
+ a zip decompression offload result is returned for a session that has
+ already closed. The session state is not validated before processing
+ the result because the offload result does not follow the fastpath
+ where these checks are normally performed.
+
+
+ Workaround: Disable zip hardware offloading (may
+ cause higher CPU usage).
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See PAN-OS 10.2.13-h18 Addressed Issuesand
+ PAN-OS 10.2.16-h6 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-303959
+ |
+
+
+ Traffic that is incorrectly identified as
+ unknown-tcp/unknown-udp
+ eventually drops due to an App-ID resource limitation issue.
+
+ |
+
|
+ PAN-297775
+ |
+
+
+ The wrong vsys is referenced under Visible Virtual System after every
+ local firewall commit (auto-commit, commit, content install) if the
+ display name of the vsys matches another vsys ID (for example, the
+ vsys2 display name is vsys1). The incorrect vsys reference causes
+ inter-vsys routing to fail.
+
+
+ Workaround: Change the vsys display name so that
+ it doesn't reference an existing vsys ID.
+
+ |
+
|
+ PAN-297610
+ |
+
+
+ A firewall may become unresponsive after an upgrade due to the
+ fsck command scanning drive
+ partitions in parallel with the root partition, causing the process to
+ take an extended amount of time.
+
+ |
+
|
+ PAN-297295
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent
+ process restarts multiple times and exhausts its restart limit,
+ resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-295803
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-295255
+ |
+
+
+ Palo Alto Networks next-generation firewalls may experience service
+ disruptions due to all_task process
+ crashes when deployed in environments having non-uniform MTU and are
+ terminating IPSec tunnels.
+
+ |
+
|
+ PAN-293673
+ |
+
+
+ When the firewall generates a high volume of logs and attempts to
+ export these logs to an FTP server, it may consume excessive memory
+ leading to all PAN-OS processes crashing.
+
+ |
+
|
+ PAN-292344
+ |
+
+
+ When upgrading from PAN-OS 10.2.9-h1 to PAN-OS 10.2.13-h5, the
+ firewall reboots repeatedly and enters maintenance mode.
+
+ |
+
|
+ PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues.
+
+ |
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM)
+ condition due to a memory leak and displays an error message. This
+ issue causes the device to crash and reboot unexpectedly.
+
+ |
+
|
+ PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues
+
+ |
+
+
+ A memory leak in the configd process
+ might lead to an active firewall to reboot due to an Out-of-Memory
+ (OOM) condition. This issue is observed when specific status commands,
+ such as
+ request log-collector forwarding status
+ are executed at high frequencies.
+
+ |
+
|
+ PAN-290996
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues
+
+ |
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS)
+ counters incorrectly return a value of 0 for each virtual system
+ (VSYS), despite the firewall actively processing connections.
+
+ |
+
|
+ PAN-290088
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-289102
+
+ (This issue affects PAN-OS 10.2.13-h7)
+
+
+ This issue is now resolved. See PAN-OS 10.2.13-h10 Addressed Issues
+
+ |
+
+
+ (PA-7500 Series, PA-5410, PA-5420, PA-5430, PA-5440, PA-5445,
+ PA-3400 Series, PA-1400 Series, PA-400 Series, VM-Series, and
+ CN-Series firewalls only) A race condition issue leads to a dataplane restart when a predict
+ session is hit at the moment when it's timing out.
+
+ |
+
|
+ PAN-288930
+ (PAN-OS 10.2.13-h7 only)
+
+ This issue is now resolved. See PAN-OS 10.2.15 Addressed Issues
+
+ |
+
+
+ When ACE (App-ID Cloud Engine) is enabled, traffic from cloud
+ applications might intermittently match an incorrect
+ cloud-apps policy rule.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues
+
+ |
+
+
+ (Firewalls in HA configurations only) Routed
+ process may stop responding after changing MTU or any link parameters
+ when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-287803
+ |
+
+
+ Users might be unable to access some URLs due to issues involving the
+ accumulation proxy and the Path Maximum Transmission Unit (MTU).
+
+
+ To address this issue, use one of the following workarounds:
+
+
|
+
|
+ PAN-287056
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues
+
+ |
+
+
+ A BGP export policy rule that matches on a next hop fails to block the
+ advertisement of static routes, and the firewall incorrectly matches
+ the egress interface IP address instead of the original next-hop IP
+ address of the static route, which causes the deny rule to fail.
+
+ |
+
|
+ PAN-286306
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues
+
+ |
+
+
+ When getting transceiver information from ESCC for SFP 25G modules,
+ the transceiver code incorrectly displays
+ Unknown instead of
+ 25GBase-SR.
+
+ |
+
|
+ PAN-286255
+
+ This issue affects PAN-OS 10.2.13-h5
+
+
+ This issue is now resolved. See
+ PAN-OS 10.2.13-h7 Addressed Issues.
+
+ |
+
+
+ When a firewall receives an unexpected termination request for certain
+ SSL sessions , NGFW dataplane might experience a slow buffer resource
+ leak.
+
+
+ Workaround: Disable accumulation proxy on the
+ NGFW.
+
+ |
+
|
+ PAN-286231
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-285894
+
+ This issue is now resolved. See PAN-OS 10.2.13-h10 Addressed Issues
+
+ |
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may
+ occur, which could result in firewall reboots.
+
+
+ Workaround: Disable the Preserve Pre-NAT feature
+ using the
+ set deviceconfig setting preserve-prenat-feature no
+ CLI command.
+
+ |
+
|
+
+ PAN-285941This issue is now resolved. See PAN-OS 10.2.16 Addressed Issues
+
+ |
+
+
+ When netflow is enabled, the
+ logrcvr process might get stuck,
+ resulting in the local logging and log forwarding to stop functioning.
+ Running
+ debug log-receiver queue-stats on the
+ CLI will show the
+ "Logs discarded (queue full)" field
+ incrementing over time.
+
+ |
+
|
+ PAN-284073
+ |
+
+
+ The firewall web interface becomes inaccessible and commits fail.
+
+ |
+
|
+ PAN-284067
+ |
+
+
+ A cumulative memory leak in the
+ devsrvr
+ process gets progressively worse whenever the CLI command
+ show running application statistics
+ is issued. This memory leak will gradually consume system memory and
+ produce an out-of-memory (OOM) condition, leading to an eventual
+ firewall reboot.
+
+
+ Workaround: Avoid using the CLI command:
+ show running application statistics.
+
+ |
+
|
+ PAN-284066
+
+ This issue is now resolved. See PAN-OS 10.2.13-h10 Addressed Issues
+
+ |
+
+
+ After an upgrade, the
+ IF-MIB::ifInErrors SNMP polled
+ values display errors that don't match the results from the
+ show interface CLI command.
+
+ |
+
|
+ PAN-283467
+
+ This issue is now resolved. See PAN-OS 10.2.15 Addressed Issues
+
+ |
+
+
+ (PA-3400 Series firewalls only) The firewall
+ might unexpectedly reboot and enter maintenance mode due to a
+ ctd-agent
+ out-of-memory (OOM) condition when undergoing advanced services load
+ testing with a high volume of IoT EAL log forwarding.
+
+
+ Workaround: Limit the number of EAL logs generated
+ by the firewall using the following CLI command:
+ debug iot eal key-value EAL_PENDING_BYTES=1000.
+
+ |
+
|
+ PAN-283331
+
+ This issue is now resolved. See PAN-OS 10.2.13-h10 Addressed Issues
+
+ |
+
+
+ Selective pushes to managed devices fail when the
+ User ID Master Device is configured.
+
+ |
+
|
+ PAN-282236
+ |
+
+
+ The firewall doesn't reassemble IPv6 packets correctly after they are
+ fragmented.
+
+ |
+
|
+ PAN-281370
+ |
+
+
+ The Advanced WildFire Inline ML models
+ OOXML and
+ Mach-O erroneously display as being
+ available from the CLI; however, they are only available on PAN-OS
+ 11.1.3 and later releases.
+
+ |
+
|
+ PAN-279901
+ |
+
+
+ When decryption is enabled, segmented Client Hello packets can cause
+ website access issues and memory leaks under the following conditions:
+
+
|
+
|
+
+ PAN-279746 (PAN-OS 10.2.13-h1 through PAN-OS 10.2.13-h4)
+
+
+ This issue is now resolved. See
+ PAN-OS 10.2.13-h5 Addressed Issues.
+
+ |
+
+
+ An SSL/TLS Client Hello may not be transmitted out of the firewall if
+ the Client Hello arrives in multiple TCP segments and the traffic is
+ not subject to SSL decryption (for example, SMTP over SSL).
+
+ |
+
|
+ PAN-279604
+ (PAN-OS 10.2.13-h3 only)
+
+ This issue is now resolved. See PAN-OS 10.2.13-h4 Addressed Issues.
+
+ |
+
+
+ The scheduled SaaS application usage reports are incorrectly generated
+ and only the login page appears instead of the intended report
+ content.
+
+ |
+
|
+ PAN-275077
+ (PAN-OS 10.2.13-h4 only)
+
+ This issue is now resolved. See
+ PAN-OS 10.2.14 Addressed Issues
+
+ |
+
+
+ DNS Security intermittently logs malicious domain URLs as alert
+ instead of taking a sinkhole action,
+ even when configured to sinkhole malicious DNS domains.
+
+ |
+
|
+ PAN-273158
+ |
+
+
+ (PA-7000 Series firewalls only) Due to an
+ incorrect configuration on the ASIC, receiving a mix of jumbo and
+ non-jumbo packets may cause silent packet drops or application
+ slowness.
+
+ |
+
|
+ PAN-270849
+
+ This issue is now resolved. See PAN-OS 10.2.13-h10 Addressed Issues
+
+ |
+
+
+ The configd process leaks a small
+ amount of memory in every commit.
+
+ |
+
|
+
+ PAN-269106 (PAN-OS 10.2.13-h4 only)
+
+
+ This issue is now resolved. See
+ PAN-OS 10.2.14 Addressed Issues
+
+ |
+
+
+ When using a cloud-based ML detection engine (MICA), the
+ wifclient might crash during
+ server cert verification for MICA gRPC connections and cause the
+ dataplane to restart. On certain platforms, this might cause the
+ firewall to reboot.
+
+
+ Workaround: Disable CRL using the following CLI
+ command:debug iot eal key-value PAN_ICD_SERVER_CERT_USE_CRL=False
+
+ |
+
|
+
+ PAN-269052 (PAN-OS 10.2.13-h4 and later 10.2.13 releases)
+
+
+ This issue is now resolved. See
+ PAN-OS 10.2.14 Addressed Issues
+
+ |
+
+
+ Traffic might be blocked by a URL Filtering profile that isn't
+ associated with the Security policy rule that the traffic matches.
+
+ |
+
|
+
+ PAN-268815 (PAN-OS 10.2.13-h4 only)
+
+
+ This issue is now resolved. See PAN-OS 10.2.13-h5 Addressed Issues.
+
+ |
+
+
+ When using IoT Security, the
+ wifclient might exit multiple
+ times causing the firewall to reboot.
+
+
+ Workaround: Uninstall the IoT Security license and
+ disable
+ Enable enhanced application logging
+ ().
+
+ |
+
| PAN-266900 | +
+
+ In Panorama, the OK button does not
+ work when trying to install configurations to a managed firewall from
+ the
+
+ section, even after selecting the update type and file from the
+ drop-down menu and choosing the firewall.
+
+ |
+
|
+ PAN-262287
+
+ This issue is now resolved. See PAN-OS 10.2.13 Addressed Issues.
+
+ |
+
+
+ Dereferencing a NULL pointer that occurs might cause
+ pan_task
+ processes to crash.
+
+ |
+
|
+ PAN-261429
+
+ This issue is now resolved. See PAN-OS 10.2.15 Addressed Issues
+
+ |
+
+
+ The command
+ show auth radius-require-msg-authentic
+ might return no output.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
| PAN-259769 | +
+
+ GlobalProtect portal is not accessible via a web browser and the app
+ displays the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-237106
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-223365
+ |
+
+
+ The Panorama management server is unable to query any logs if the
+ ElasticSearch health status for any Log Collector (
+ is degraded.
+
+
+ Workaround:
+ Log in to the Log Collector CLI
+ and restart ElasticSearch.
+
+
+
+
+
+ |
+
|
+ PAN-229865
+ |
+
+
+ Upgrading a PA-220 firewall running a PAN-OS 10.1 release fails when
+ the target PAN-OS upgrade version is PAN-OS 10.2.5.
+
+
+ Workaround: On your upgrade path to PAN-OS 10.2.5,
+ first upgrade to PAN-OS 10.2.4 and then upgrade to PAN-OS 10.2.5.
+
+ |
+
|
+ PAN-223677
+ |
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, and PA-5430
+ firewalls) By enabling
+ Lockless QoS
+ feature, a slight degradation in App-ID and Threat performance is
+ expected.
+
+ |
+
|
+ PAN-222586
+ |
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus,
+ Forward Methods, and Built-In Actions for Correlation Log settings
+ () are not displayed and cannot be configured.
+
+ |
+
|
+ PAN-221775
+ |
+
+
+ A Malformed Request error is
+ displayed when you
+ Test Connection for an email server
+ profile () using SMTP over TLS and the
+ Password includes an ampersand
+ (&).
+
+ |
+
|
+ PAN-213746
+ |
+
+
+ On the Panorama management server, the
+ Hostkey displayed as
+ undefined undefined if you
+ override an SSH Service Profile () Hostkey configured in a Template from the Template Stack.
+
+ |
+
|
+ PAN-213119
+ |
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you
+ view the Block IP list ():
+
+
+ show -> dis-block-table is unexpected
+
+ |
+
|
+ PAN-212889
+
+ This issue is now resolved. See
+ PAN-OS 10.2.14 Addressed Issues
+
+ |
+
+
+ On the Panorama management server, different threat names are used
+ when querying the same threat in the Threat Monitor () and ACC. This results in the ACC
+ displaying
+ no data to display when you are
+ redirected to the ACC after clicking a threat name in the Threat
+ Monitor and filtering the same threat name in the Global Filters.
+
+ |
+
|
+ PAN-212533
+ |
+
+
+ Modifying the Administrator Type for
+ an existing administrator (
+ or
+ ) from Superuser to a
+ Role-Based custom admin, or vice
+ versa, does not modify the access privileges of the administrator.
+
+ |
+
|
+ PAN-211531
+ |
+ + On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (). + | +
|
+ PAN-209288
+ |
+
+
+ Certificates are not successfully generated using SCEP ().
+
+ |
+
|
+ PAN-208622
+ |
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to
+ upload if you specify an Enterprise DLP data filtering profile (
+ with the Action set to Block to a
+ Security policy rule ().
+
+ |
+
|
+ PAN-204689
+ |
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do
+ not work:
+
+
|
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-196504
+ |
+ + License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). + | +
|
+ PAN-194996
+ |
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma
+ Access 3.1.2 deployment, allocating bandwidth for a remote network
+ deployment fails (the OK button is grayed out).
+
+
+ Workaround: Retry the operation.
+
+ |
+
|
+ PAN-194519
+ |
+
+
+ (PA-5450 firewall only) Trying to configure a
+ custom payload format under
+
+ yields a Javascript error.
+
+ |
+
|
+ PAN-194515
+ |
+
+
+ (PA-5450 firewall only) The Panorama web
+ interface does not display any predefined template stack variables in
+ the dropdown menu under
+ .
+
+
+ Workaround: Configure the log interface IP address
+ on the individual firewall web interface instead of on Panorama.
+
+ |
+
|
+ PAN-194424
+ |
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS
+ 10.2.2 while having a log interface configured can cause both the log
+ interface and the management interface to remain connected to the log
+ collector.
+
+
+ Workaround: Restart the log receiver service by
+ running the following CLI command:
+
+
+
+
+
+ |
+
|
+ PAN-194202
+ |
+
+
+ (PA-5450 firewall only) If the management
+ interface and logging interface are configured on the same subnetwork,
+ the firewall conducts log forwarding using the management interface
+ instead of the logging interface.
+
+ |
+
|
+ PAN-190727
+ |
+
+
+ (PA-5450 firewall only) Documentation for
+ configuring the log interface is unavailable on the web interface and
+ in the PAN-OS Administrator’s Guide.
+
+ |
+
|
+ PAN-189111
+ |
+
+
+ After deleting an MP pod and it comes up, the
+ show routing command output
+ appears empty and traffic stops working.
+
+ |
+
|
+ PAN-189076
+ |
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a
+ broadcast link and a designated router (DR) priority of 0 (zero) are
+ stuck in a two-way state after HA failover.
+
+
+ Workaround: Configure at least one OSPFv3 neighbor
+ with a non-zero priority setting in the same broadcast domain.
+
+ |
+
|
+ PAN-188358
+ |
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management
+ port LEDs do not light up when a 10G Ethernet cable is plugged in.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187643
+ |
+
+
+ If you enable SCTP security using a Panorama template when
+ SCTP INIT Flood Protection is
+ enabled in the Zone Protection profile using Panorama and you commit
+ all changes, the commit is successful but the
+ SCTP INIT option is not available in
+ the Zone Protection profile.
+
+
+ Workaround: Log out of the firewall and log in
+ again to make the SCIT INIT option
+ available on the web interface.
+
+ |
+
|
+ PAN-187612
+ |
+
+
+ On the Panorama management server, not all data profiles () are displayed after you:
+
+
+ Workaround: Log in to the Panorama CLI and reset
+ the DLP plugin.
+
+ admin > request plugins dlp reset.
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-187370
+ |
+
+
+ On a firewall with Advanced Routing enabled, if there is also a
+ logical router instance that uses the default configuration and has no
+ interfaces assigned to it, this will result in terminating the
+ management daemon and main routing daemon in the firewall during
+ commit.
+
+
+ Workaround: Do not use a logical router instance
+ with no interfaces bound to it.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-186282
+ |
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match
+ criteria automatically when adding dynamic address groups.
+
+
+ Workaround: Reboot the Panorama HA pair.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-181823
+ |
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer
+ port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports
+ on the firewall to go down if they are set to Auto.
+
+ |
+
|
+ PAN-180661
+ |
+
+
+ On the Panorama management server, pushing an unsupported Minimum
+ Password Complexity () to a managed firewall erroneously displays
+ commit time out as the reason the
+ commit failed.
+
+ |
+
|
+ PAN-180104
+ |
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2,
+ CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster
+ previously had a CN-Series as a DaemonSet deployment running PAN-OS
+ 10.0 or 10.1.
+
+
+ Workaround: Reboot the worker nodes before
+ upgrading to PAN-OS 10.2.
+
+ |
+
|
+ PAN-178194
+ |
+
+
+ A user interface issue in PAN-OS renders the contents of the
+ Inline ML tab in the
+ URL Filtering Profile inaccessible
+ on firewalls licensed for Advanced URL Filtering. Additionally, a
+ message indicating that a
+ License required for URL filtering to function
+ is unavailable displays at the bottom of the UI. These errors do not
+ affect the operation of Advanced URL Filtering or URL Filtering Inline
+ ML.
+
+
+ Workaround: Configuration settings for URL
+ Filtering Inline ML must be applied through the CLI. The following
+ configuration commands are available:
+
+
|
+
|
+ PAN-177455
+ |
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA
+ (High Availability) clustering enabled and using an HA4 communication
+ link. Attempting to load PAN-OS 10.2.0 on the firewall causes the
+ PA-7000 100G NPC to go offline. As a result, the firewall fails to
+ boot normally and enters maintenance mode. HA Pairs of Active-Passive
+ and Active-Active firewalls are not affected.
+
+ |
+
|
+ PAN-175915
+ |
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks
+ and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network
+ Protection Profile, the traffic logs do not display network slice SST
+ and SD values.
+
+ |
+
|
+ PAN-174982
+ |
+
+
+ In HA active/active configurations where, when interfaces that were
+ associated with a virtual router were deleted, the configuration
+ change did not sync.
+
+ |
+
|
+ PAN-172274
+ |
+
+
+ When you activate the advanced URL filtering license, your license
+ entitlements for PAN-DB and advanced URL filtering might not display
+ correctly on the firewall — this is a display anomaly, not a licensing
+ issue, and does not affect access to the services.
+
+
+ Workaround: Issue the following command to
+ retrieve and update the licenses:
+ license request fetch.
+
+ |
+
|
+ PAN-171938
+ |
+
+
+ No results are displayed when you
+ Show Application Filter for a
+ Security policy rule ().
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-5854
+ |
+
+
+ The WildFire analysis report on the firewall log viewer () does not display the following data fields: File Type, SHA-256,
+ MD-5, and File Size".
+
+
+ Workaround: Download and open the WildFire
+ analysis report in the PDF format using the link in the upper
+ right-hand corner of the
+ Detailed Log View.
+
+ |
+
|
+ WF500-5843
+ |
+
+
+ In a WildFire appliance cluster, issuing the
+ show cluster-all peers CLI command
+ when a node within the cluster is being rebooted generates the
+ following error:
+ Server error : An error occured.
+
+ |
+
|
+ WF500-5840
+ |
+
+
+ The sample analysis statistics that are returned when issuing the
+ show wildfire local statistics CLI
+ command in WildFire appliance cluster deployments may not accurately
+ reflect the number of samples that have been processed.
+
+ |
+
|
+ WF500-5823
+ |
+
+
+ The following WildFire appliance CLI command does not return a
+ signature generation status as expected:
+ show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance
+ from analyzing a sample.
+
+ |
+
|
+ WF500-5781
+ |
+
+
+ The WildFire appliance might erroneously generate and log the
+ following device certification error:
+ Device certificate is missing or invalid. It cannot be
+ renewed.
+
+ |
+
|
+ WF500-5754
+ |
+
+
+ In WildFire appliance clusters, issuing the
+ show cluster controller CLI command
+ generates an error when an IPv6 address is configured for the
+ management interface but not for the cluster interface.
+
+
+ Workaround: Ensure all WildFire appliance
+ interfaces that are enabled use matching protocols (all IPv4 or all
+ IPv6).
+
+ |
+
|
+ WF500-5632
+ |
+
+
+ The number of registered WildFire appliances reported in Panorama
+ () does not accurately reflect the current status of connected
+ WildFire appliances.
+
+ |
+
|
+ PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues.
+
+ |
+
+
+ A race condition may cause the dataplane to restart unexpectedly when
+ a zip decompression offload result is returned for a session that has
+ already closed. The session state is not validated before processing
+ the result because the offload result does not follow the fastpath
+ where these checks are normally performed.
+
+
+ Workaround: Disable zip hardware offloading (may
+ cause higher CPU usage).
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-297610
+ |
+
+
+ A firewall may become unresponsive after an upgrade due to the
+ fsck command scanning drive
+ partitions in parallel with the root partition, causing the process to
+ take an extended amount of time.
+
+ |
+
|
+ PAN-297295
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent
+ process restarts multiple times and exhausts its restart limit,
+ resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-295803
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-295255
+ |
+
+
+ Palo Alto Networks next-generation firewalls may experience service
+ disruptions due to all_task process
+ crashes when deployed in environments having non-uniform MTU and are
+ terminating IPSec tunnels.
+
+ |
+
|
+ PAN-292344
+ |
+
+
+ When upgrading from PAN-OS 10.2.9-h1 to PAN-OS 10.2.13-h5, the
+ firewall reboots repeatedly and enters maintenance mode.
+
+ |
+
|
+ PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues.
+
+ |
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM)
+ condition due to a memory leak and displays an error message. This
+ issue causes the device to crash and reboot unexpectedly.
+
+ |
+
|
+ PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues
+
+ |
+
+
+ A memory leak in the configd process
+ might lead to an active firewall to reboot due to an Out-of-Memory
+ (OOM) condition. This issue is observed when specific status commands,
+ such as
+ request log-collector forwarding status
+ are executed at high frequencies.
+
+ |
+
|
+ PAN-290996
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues
+
+ |
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS)
+ counters incorrectly return a value of 0 for each virtual system
+ (VSYS), despite the firewall actively processing connections.
+
+ |
+
|
+ PAN-290088
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-289102
+
+ This issue is now resolved. See
+ PAN-OS 10.2.16 Addressed Issues
+
+ |
+
+
+ (PA-7500 Series, PA-5410, PA-5420, PA-5430, PA-5440, PA-5445,
+ PA-3400 Series, PA-1400 Series, PA-400 Series, VM-Series, and
+ CN-Series firewalls only) A race condition issue leads to a dataplane restart when a predict
+ session is hit at the moment when it's timing out.
+
+ |
+
|
+ PAN-288930
+
+ This issue is now resolved. See
+ PAN-OS 10.2.15 Addressed Issues.
+
+ |
+
+
+ When ACE (App-ID Cloud Engine) is enabled, traffic from cloud
+ applications might intermittently match an incorrect
+ cloud-apps policy rule.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues
+
+ |
+
+
+ (Firewalls in HA configurations only) Routed
+ process may stop responding after changing MTU or any link parameters
+ when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-287803
+ |
+
+
+ Users might be unable to access some URLs due to issues involving the
+ accumulation proxy and the Path Maximum Transmission Unit (MTU).
+
+
+ To address this issue, use one of the following workarounds:
+
+
|
+
|
+ PAN-287056
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues
+
+ |
+
+
+ A BGP export policy rule that matches on a next hop fails to block the
+ advertisement of static routes, and the firewall incorrectly matches
+ the egress interface IP address instead of the original next-hop IP
+ address of the static route, which causes the deny rule to fail.
+
+ |
+
|
+ PAN-286306
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues
+
+ |
+
+
+ When getting transceiver information from ESCC for SFP 25G modules,
+ the transceiver code incorrectly displays
+ Unknown instead of
+ 25GBase-SR.
+
+ |
+
|
+ PAN-286255
+
+ This issue is now resolved. See
+ PAN-OS 10.2.14-h1 Addressed Issues.
+
+ |
+
+
+ When a firewall receives an unexpected termination request for certain
+ SSL sessions , NGFW dataplane might experience a slow buffer resource
+ leak.
+
+
+ Workaround: Disable accumulation proxy on the
+ NGFW.
+
+ |
+
|
+ PAN-286231
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-285941
+ (PAN-OS 10.2.13-h7 only)
+ |
+
+
+ When netflow is enabled, the
+ logrcvr process might get stuck,
+ resulting in the local logging and log forwarding to stop functioning.
+ Running
+ debug log-receiver queue-stats on the
+ CLI will show the
+ "Logs discarded (queue full)" field
+ incrementing over time.
+
+ |
+
|
+ PAN-284073
+ |
+
+
+ The firewall web interface becomes inaccessible and commits fail.
+
+ |
+
|
+ PAN-284067
+ |
+
+
+ A cumulative memory leak in the
+ devsrvr
+ process gets progressively worse whenever the CLI command
+ show running application statistics
+ is issued. This memory leak will gradually consume system memory and
+ produce an out-of-memory (OOM) condition, leading to an eventual
+ firewall reboot.
+
+
+ Workaround: Avoid using the CLI command:
+ show running application statistics.
+
+ |
+
|
+ PAN-284066
+ |
+
+
+ After an upgrade, the
+ IF-MIB::ifInErrors SNMP polled
+ values display errors that don't match the results from the
+ show interface CLI command.
+
+ |
+
|
+ PAN-283331
+ |
+
+
+ Selective pushes to managed devices fail when the
+ User ID Master Device is configured.
+
+ |
+
|
+ PAN-281370
+ |
+
+
+ The Advanced WildFire Inline ML models
+ OOXML and
+ Mach-O erroneously display as being
+ available from the CLI; however, they are only available on PAN-OS
+ 11.1.3 and later releases.
+
+ |
+
|
+ PAN-279901
+ |
+
+
+ When decryption is enabled, segmented Client Hello packets can cause
+ website access issues and memory leaks under the following conditions:
+
+
|
+
|
+ PAN-273158
+ |
+
+
+ (PA-7000 Series firewalls only) Due to an
+ incorrect configuration on the ASIC, receiving a mix of jumbo and
+ non-jumbo packets may cause silent packet drops or application
+ slowness.
+
+ |
+
| PAN-266900 | +
+
+ In Panorama, the OK button does not
+ work when trying to install configurations to a managed firewall from
+ the
+
+ section, even after selecting the update type and file from the
+ drop-down menu and choosing the firewall.
+
+ |
+
|
+ PAN-261429
+
+ This issue is now resolved. See PAN-OS 10.2.15 Addressed Issues
+
+ |
+
+
+ The command
+ show auth radius-require-msg-authentic
+ might return no output.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-259769
+ |
+
+
+ GlobalProtect portal is not accessible via a web browser and the app
+ displays the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-237106
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-223365
+ |
+
+
+ The Panorama management server is unable to query any logs if the
+ ElasticSearch health status for any Log Collector (
+ is degraded.
+
+
+ Workaround:
+ Log in to the Log Collector CLI
+ and restart ElasticSearch.
+
+
+
+
+
+ |
+
|
+ PAN-229865
+ |
+
+
+ Upgrading a PA-220 firewall running a PAN-OS 10.1 release fails when
+ the target PAN-OS upgrade version is PAN-OS 10.2.5.
+
+
+ Workaround: On your upgrade path to PAN-OS 10.2.5,
+ first upgrade to PAN-OS 10.2.4 and then upgrade to PAN-OS 10.2.5.
+
+ |
+
|
+ PAN-223677
+ |
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, and PA-5430
+ firewalls) By enabling
+ Lockless QoS
+ feature, a slight degradation in App-ID and Threat performance is
+ expected.
+
+ |
+
|
+ PAN-222586
+ |
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus,
+ Forward Methods, and Built-In Actions for Correlation Log settings
+ () are not displayed and cannot be configured.
+
+ |
+
|
+ PAN-221775
+ |
+
+
+ A Malformed Request error is
+ displayed when you
+ Test Connection for an email server
+ profile () using SMTP over TLS and the
+ Password includes an ampersand
+ (&).
+
+ |
+
|
+ PAN-213746
+ |
+
+
+ On the Panorama management server, the
+ Hostkey displayed as
+ undefined undefined if you
+ override an SSH Service Profile () Hostkey configured in a Template from the Template Stack.
+
+ |
+
|
+ PAN-213119
+ |
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you
+ view the Block IP list ():
+
+
+ show -> dis-block-table is unexpected
+
+ |
+
|
+ PAN-212889
+ |
+
+
+ On the Panorama management server, different threat names are used
+ when querying the same threat in the Threat Monitor () and ACC. This results in the ACC
+ displaying
+ no data to display when you are
+ redirected to the ACC after clicking a threat name in the Threat
+ Monitor and filtering the same threat name in the Global Filters.
+
+ |
+
|
+ PAN-212533
+ |
+
+
+ Modifying the Administrator Type for
+ an existing administrator (
+ or
+ ) from Superuser to a
+ Role-Based custom admin, or vice
+ versa, does not modify the access privileges of the administrator.
+
+ |
+
|
+ PAN-211531
+ |
+ + On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (). + | +
|
+ PAN-209288
+ |
+
+
+ Certificates are not successfully generated using SCEP ().
+
+ |
+
|
+ PAN-208622
+ |
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to
+ upload if you specify an Enterprise DLP data filtering profile (
+ with the Action set to Block to a
+ Security policy rule ().
+
+ |
+
|
+ PAN-204689
+ |
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do
+ not work:
+
+
|
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-196504
+ |
+ + License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). + | +
|
+ PAN-194996
+ |
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma
+ Access 3.1.2 deployment, allocating bandwidth for a remote network
+ deployment fails (the OK button is grayed out).
+
+
+ Workaround: Retry the operation.
+
+ |
+
|
+ PAN-194519
+ |
+
+
+ (PA-5450 firewall only) Trying to configure a
+ custom payload format under
+
+ yields a Javascript error.
+
+ |
+
|
+ PAN-194515
+ |
+
+
+ (PA-5450 firewall only) The Panorama web
+ interface does not display any predefined template stack variables in
+ the dropdown menu under
+ .
+
+
+ Workaround: Configure the log interface IP address
+ on the individual firewall web interface instead of on Panorama.
+
+ |
+
|
+ PAN-194424
+ |
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS
+ 10.2.2 while having a log interface configured can cause both the log
+ interface and the management interface to remain connected to the log
+ collector.
+
+
+ Workaround: Restart the log receiver service by
+ running the following CLI command:
+
+
+
+
+
+ |
+
|
+ PAN-194202
+ |
+
+
+ (PA-5450 firewall only) If the management
+ interface and logging interface are configured on the same subnetwork,
+ the firewall conducts log forwarding using the management interface
+ instead of the logging interface.
+
+ |
+
|
+ PAN-190727
+ |
+
+
+ (PA-5450 firewall only) Documentation for
+ configuring the log interface is unavailable on the web interface and
+ in the PAN-OS Administrator’s Guide.
+
+ |
+
|
+ PAN-189111
+ |
+
+
+ After deleting an MP pod and it comes up, the
+ show routing command output
+ appears empty and traffic stops working.
+
+ |
+
|
+ PAN-189076
+ |
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a
+ broadcast link and a designated router (DR) priority of 0 (zero) are
+ stuck in a two-way state after HA failover.
+
+
+ Workaround: Configure at least one OSPFv3 neighbor
+ with a non-zero priority setting in the same broadcast domain.
+
+ |
+
|
+ PAN-188358
+ |
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management
+ port LEDs do not light up when a 10G Ethernet cable is plugged in.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187643
+ |
+
+
+ If you enable SCTP security using a Panorama template when
+ SCTP INIT Flood Protection is
+ enabled in the Zone Protection profile using Panorama and you commit
+ all changes, the commit is successful but the
+ SCTP INIT option is not available in
+ the Zone Protection profile.
+
+
+ Workaround: Log out of the firewall and log in
+ again to make the SCIT INIT option
+ available on the web interface.
+
+ |
+
|
+ PAN-187612
+ |
+
+
+ On the Panorama management server, not all data profiles () are displayed after you:
+
+
+ Workaround: Log in to the Panorama CLI and reset
+ the DLP plugin.
+
+ admin > request plugins dlp reset.
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-187370
+ |
+
+
+ On a firewall with Advanced Routing enabled, if there is also a
+ logical router instance that uses the default configuration and has no
+ interfaces assigned to it, this will result in terminating the
+ management daemon and main routing daemon in the firewall during
+ commit.
+
+
+ Workaround: Do not use a logical router instance
+ with no interfaces bound to it.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-186282
+ |
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match
+ criteria automatically when adding dynamic address groups.
+
+
+ Workaround: Reboot the Panorama HA pair.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-181823
+ |
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer
+ port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports
+ on the firewall to go down if they are set to Auto.
+
+ |
+
|
+ PAN-180661
+ |
+
+
+ On the Panorama management server, pushing an unsupported Minimum
+ Password Complexity () to a managed firewall erroneously displays
+ commit time out as the reason the
+ commit failed.
+
+ |
+
|
+ PAN-180104
+ |
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2,
+ CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster
+ previously had a CN-Series as a DaemonSet deployment running PAN-OS
+ 10.0 or 10.1.
+
+
+ Workaround: Reboot the worker nodes before
+ upgrading to PAN-OS 10.2.
+
+ |
+
|
+ PAN-178194
+ |
+
+
+ A user interface issue in PAN-OS renders the contents of the
+ Inline ML tab in the
+ URL Filtering Profile inaccessible
+ on firewalls licensed for Advanced URL Filtering. Additionally, a
+ message indicating that a
+ License required for URL filtering to function
+ is unavailable displays at the bottom of the UI. These errors do not
+ affect the operation of Advanced URL Filtering or URL Filtering Inline
+ ML.
+
+
+ Workaround: Configuration settings for URL
+ Filtering Inline ML must be applied through the CLI. The following
+ configuration commands are available:
+
+
|
+
|
+ PAN-177455
+ |
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA
+ (High Availability) clustering enabled and using an HA4 communication
+ link. Attempting to load PAN-OS 10.2.0 on the firewall causes the
+ PA-7000 100G NPC to go offline. As a result, the firewall fails to
+ boot normally and enters maintenance mode. HA Pairs of Active-Passive
+ and Active-Active firewalls are not affected.
+
+ |
+
|
+ PAN-175915
+ |
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks
+ and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network
+ Protection Profile, the traffic logs do not display network slice SST
+ and SD values.
+
+ |
+
|
+ PAN-174982
+ |
+
+
+ In HA active/active configurations where, when interfaces that were
+ associated with a virtual router were deleted, the configuration
+ change did not sync.
+
+ |
+
|
+ PAN-172274
+ |
+
+
+ When you activate the advanced URL filtering license, your license
+ entitlements for PAN-DB and advanced URL filtering might not display
+ correctly on the firewall — this is a display anomaly, not a licensing
+ issue, and does not affect access to the services.
+
+
+ Workaround: Issue the following command to
+ retrieve and update the licenses:
+ license request fetch.
+
+ |
+
|
+ PAN-171938
+ |
+
+
+ No results are displayed when you
+ Show Application Filter for a
+ Security policy rule ().
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-5854
+ |
+
+
+ The WildFire analysis report on the firewall log viewer () does not display the following data fields: File Type, SHA-256,
+ MD-5, and File Size".
+
+
+ Workaround: Download and open the WildFire
+ analysis report in the PDF format using the link in the upper
+ right-hand corner of the
+ Detailed Log View.
+
+ |
+
|
+ WF500-5843
+ |
+
+
+ In a WildFire appliance cluster, issuing the
+ show cluster-all peers CLI command
+ when a node within the cluster is being rebooted generates the
+ following error:
+ Server error : An error occured.
+
+ |
+
|
+ WF500-5840
+ |
+
+
+ The sample analysis statistics that are returned when issuing the
+ show wildfire local statistics CLI
+ command in WildFire appliance cluster deployments may not accurately
+ reflect the number of samples that have been processed.
+
+ |
+
|
+ WF500-5823
+ |
+
+
+ The following WildFire appliance CLI command does not return a
+ signature generation status as expected:
+ show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance
+ from analyzing a sample.
+
+ |
+
|
+ WF500-5781
+ |
+
+
+ The WildFire appliance might erroneously generate and log the
+ following device certification error:
+ Device certificate is missing or invalid. It cannot be
+ renewed.
+
+ |
+
|
+ WF500-5754
+ |
+
+
+ In WildFire appliance clusters, issuing the
+ show cluster controller CLI command
+ generates an error when an IPv6 address is configured for the
+ management interface but not for the cluster interface.
+
+
+ Workaround: Ensure all WildFire appliance
+ interfaces that are enabled use matching protocols (all IPv4 or all
+ IPv6).
+
+ |
+
|
+ WF500-5632
+ |
+
+
+ The number of registered WildFire appliances reported in Panorama
+ () does not accurately reflect the current status of connected
+ WildFire appliances.
+
+ |
+
|
+ PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues.
+
+ |
+
+
+ A race condition may cause the dataplane to restart unexpectedly when
+ a zip decompression offload result is returned for a session that has
+ already closed. The session state is not validated before processing
+ the result because the offload result does not follow the fastpath
+ where these checks are normally performed.
+
+
+ Workaround: Disable zip hardware offloading (may
+ cause higher CPU usage).
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-297610
+ |
+
+
+ A firewall may become unresponsive after an upgrade due to the
+ fsck command scanning drive
+ partitions in parallel with the root partition, causing the process to
+ take an extended amount of time.
+
+ |
+
|
+ PAN-297295
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent
+ process restarts multiple times and exhausts its restart limit,
+ resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-295803
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-295255
+ |
+
+
+ Palo Alto Networks next-generation firewalls may experience service
+ disruptions due to all_task process
+ crashes when deployed in environments having non-uniform MTU and are
+ terminating IPSec tunnels.
+
+ |
+
|
+ PAN-292344
+ |
+
+
+ When upgrading from PAN-OS 10.2.9-h1 to PAN-OS 10.2.13-h5, the
+ firewall reboots repeatedly and enters maintenance mode.
+
+ |
+
|
+ PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues.
+
+ |
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM)
+ condition due to a memory leak and displays an error message. This
+ issue causes the device to crash and reboot unexpectedly.
+
+ |
+
|
+ PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues
+
+ |
+
+
+ A memory leak in the configd process
+ might lead to an active firewall to reboot due to an Out-of-Memory
+ (OOM) condition. This issue is observed when specific status commands,
+ such as
+ request log-collector forwarding status
+ are executed at high frequencies.
+
+ |
+
|
+ PAN-290996
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues
+
+ |
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS)
+ counters incorrectly return a value of 0 for each virtual system
+ (VSYS), despite the firewall actively processing connections.
+
+ |
+
|
+ PAN-290088
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-289102
+
+ This issue is now resolved. See
+ PAN-OS 10.2.16 Addressed Issues
+
+ |
+
+
+ (PA-7500 Series, PA-5410, PA-5420, PA-5430, PA-5440, PA-5445,
+ PA-3400 Series, PA-1400 Series, PA-400 Series, VM-Series, and
+ CN-Series firewalls only) A race condition issue leads to a dataplane restart when a predict
+ session is hit at the moment when it's timing out.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues
+
+ |
+
+
+ (Firewalls in HA configurations only) Routed
+ process may stop responding after changing MTU or any link parameters
+ when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-287803
+ |
+
+
+ Users might be unable to access some URLs due to issues involving the
+ accumulation proxy and the Path Maximum Transmission Unit (MTU).
+
+
+ To address this issue, use one of the following workarounds:
+
+
|
+
|
+ PAN-287056
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues
+
+ |
+
+
+ A BGP export policy rule that matches on a next hop fails to block the
+ advertisement of static routes, and the firewall incorrectly matches
+ the egress interface IP address instead of the original next-hop IP
+ address of the static route, which causes the deny rule to fail.
+
+ |
+
|
+ PAN-286306
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues
+
+ |
+
+
+ When getting transceiver information from ESCC for SFP 25G modules,
+ the transceiver code incorrectly displays
+ Unknown instead of
+ 25GBase-SR.
+
+ |
+
|
+ PAN-286231
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-285941
+ (PAN-OS 10.2.13-h7 only)
+
+ This issue is now resolved. See
+ PAN-OS 10.2.16 Addressed Issues
+
+ |
+
+
+ When netflow is enabled, the
+ logrcvr process might get stuck,
+ resulting in the local logging and log forwarding to stop functioning.
+ Running
+ debug log-receiver queue-stats on the
+ CLI will show the
+ "Logs discarded (queue full)" field
+ incrementing over time.
+
+ |
+
|
+ PAN-284073
+ |
+
+
+ The firewall web interface becomes inaccessible and commits fail.
+
+ |
+
|
+ PAN-284067
+ |
+
+
+ A cumulative memory leak in the
+ devsrvr
+ process gets progressively worse whenever the CLI command
+ show running application statistics
+ is issued. This memory leak will gradually consume system memory and
+ produce an out-of-memory (OOM) condition, leading to an eventual
+ firewall reboot.
+
+
+ Workaround: Avoid using the CLI command:
+ show running application statistics.
+
+ |
+
|
+ PAN-284066
+
+ This issue is now resolved. See
+ PAN-OS 10.2.16 Addressed Issues
+
+ |
+
+
+ After an upgrade, the
+ IF-MIB::ifInErrors SNMP polled
+ values display errors that don't match the results from the
+ show interface CLI command.
+
+ |
+
|
+ PAN-281370
+ |
+
+
+ The Advanced WildFire Inline ML models
+ OOXML and
+ Mach-O erroneously display as being
+ available from the CLI; however, they are only available on PAN-OS
+ 11.1.3 and later releases.
+
+ |
+
|
+ PAN-279901
+ |
+
+
+ When decryption is enabled, segmented Client Hello packets can cause
+ website access issues and memory leaks under the following conditions:
+
+
|
+
|
+ PAN-273158
+ |
+
+
+ (PA-7000 Series firewalls only) Due to an
+ incorrect configuration on the ASIC, receiving a mix of jumbo and
+ non-jumbo packets may cause silent packet drops or application
+ slowness.
+
+ |
+
| PAN-266900 | +
+
+ In Panorama, the OK button does not
+ work when trying to install configurations to a managed firewall from
+ the
+
+ section, even after selecting the update type and file from the
+ drop-down menu and choosing the firewall.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-259769
+ |
+
+
+ GlobalProtect portal is not accessible via a web browser and the app
+ displays the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-237106
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-223365
+ |
+
+
+ The Panorama management server is unable to query any logs if the
+ ElasticSearch health status for any Log Collector (
+ is degraded.
+
+
+ Workaround:
+ Log in to the Log Collector CLI
+ and restart ElasticSearch.
+
+
+
+
+
+ |
+
|
+ PAN-229865
+ |
+
+
+ Upgrading a PA-220 firewall running a PAN-OS 10.1 release fails when
+ the target PAN-OS upgrade version is PAN-OS 10.2.5.
+
+
+ Workaround: On your upgrade path to PAN-OS 10.2.5,
+ first upgrade to PAN-OS 10.2.4 and then upgrade to PAN-OS 10.2.5.
+
+ |
+
|
+ PAN-223677
+ |
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, and PA-5430
+ firewalls) By enabling
+ Lockless QoS
+ feature, a slight degradation in App-ID and Threat performance is
+ expected.
+
+ |
+
|
+ PAN-222586
+ |
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus,
+ Forward Methods, and Built-In Actions for Correlation Log settings
+ () are not displayed and cannot be configured.
+
+ |
+
|
+ PAN-221775
+ |
+
+
+ A Malformed Request error is
+ displayed when you
+ Test Connection for an email server
+ profile () using SMTP over TLS and the
+ Password includes an ampersand
+ (&).
+
+ |
+
|
+ PAN-213746
+ |
+
+
+ On the Panorama management server, the
+ Hostkey displayed as
+ undefined undefined if you
+ override an SSH Service Profile () Hostkey configured in a Template from the Template Stack.
+
+ |
+
|
+ PAN-213119
+ |
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you
+ view the Block IP list ():
+
+
+ show -> dis-block-table is unexpected
+
+ |
+
|
+ PAN-212889
+ |
+
+
+ On the Panorama management server, different threat names are used
+ when querying the same threat in the Threat Monitor () and ACC. This results in the ACC
+ displaying
+ no data to display when you are
+ redirected to the ACC after clicking a threat name in the Threat
+ Monitor and filtering the same threat name in the Global Filters.
+
+ |
+
|
+ PAN-212533
+ |
+
+
+ Modifying the Administrator Type for
+ an existing administrator (
+ or
+ ) from Superuser to a
+ Role-Based custom admin, or vice
+ versa, does not modify the access privileges of the administrator.
+
+ |
+
|
+ PAN-211531
+ |
+ + On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (). + | +
|
+ PAN-209288
+ |
+
+
+ Certificates are not successfully generated using SCEP ().
+
+ |
+
|
+ PAN-208622
+ |
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to
+ upload if you specify an Enterprise DLP data filtering profile (
+ with the Action set to Block to a
+ Security policy rule ().
+
+ |
+
|
+ PAN-204689
+ |
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do
+ not work:
+
+
|
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-196504
+ |
+ + License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). + | +
|
+ PAN-194996
+ |
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma
+ Access 3.1.2 deployment, allocating bandwidth for a remote network
+ deployment fails (the OK button is grayed out).
+
+
+ Workaround: Retry the operation.
+
+ |
+
|
+ PAN-194519
+ |
+
+
+ (PA-5450 firewall only) Trying to configure a
+ custom payload format under
+
+ yields a Javascript error.
+
+ |
+
|
+ PAN-194515
+ |
+
+
+ (PA-5450 firewall only) The Panorama web
+ interface does not display any predefined template stack variables in
+ the dropdown menu under
+ .
+
+
+ Workaround: Configure the log interface IP address
+ on the individual firewall web interface instead of on Panorama.
+
+ |
+
|
+ PAN-194424
+ |
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS
+ 10.2.2 while having a log interface configured can cause both the log
+ interface and the management interface to remain connected to the log
+ collector.
+
+
+ Workaround: Restart the log receiver service by
+ running the following CLI command:
+
+
+
+
+
+ |
+
|
+ PAN-194202
+ |
+
+
+ (PA-5450 firewall only) If the management
+ interface and logging interface are configured on the same subnetwork,
+ the firewall conducts log forwarding using the management interface
+ instead of the logging interface.
+
+ |
+
|
+ PAN-190727
+ |
+
+
+ (PA-5450 firewall only) Documentation for
+ configuring the log interface is unavailable on the web interface and
+ in the PAN-OS Administrator’s Guide.
+
+ |
+
|
+ PAN-189111
+ |
+
+
+ After deleting an MP pod and it comes up, the
+ show routing command output
+ appears empty and traffic stops working.
+
+ |
+
|
+ PAN-189076
+ |
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a
+ broadcast link and a designated router (DR) priority of 0 (zero) are
+ stuck in a two-way state after HA failover.
+
+
+ Workaround: Configure at least one OSPFv3 neighbor
+ with a non-zero priority setting in the same broadcast domain.
+
+ |
+
|
+ PAN-188358
+ |
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management
+ port LEDs do not light up when a 10G Ethernet cable is plugged in.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187643
+ |
+
+
+ If you enable SCTP security using a Panorama template when
+ SCTP INIT Flood Protection is
+ enabled in the Zone Protection profile using Panorama and you commit
+ all changes, the commit is successful but the
+ SCTP INIT option is not available in
+ the Zone Protection profile.
+
+
+ Workaround: Log out of the firewall and log in
+ again to make the SCIT INIT option
+ available on the web interface.
+
+ |
+
|
+ PAN-187612
+ |
+
+
+ On the Panorama management server, not all data profiles () are displayed after you:
+
+
+ Workaround: Log in to the Panorama CLI and reset
+ the DLP plugin.
+
+ admin > request plugins dlp reset.
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-187370
+ |
+
+
+ On a firewall with Advanced Routing enabled, if there is also a
+ logical router instance that uses the default configuration and has no
+ interfaces assigned to it, this will result in terminating the
+ management daemon and main routing daemon in the firewall during
+ commit.
+
+
+ Workaround: Do not use a logical router instance
+ with no interfaces bound to it.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-186282
+ |
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match
+ criteria automatically when adding dynamic address groups.
+
+
+ Workaround: Reboot the Panorama HA pair.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-181823
+ |
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer
+ port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports
+ on the firewall to go down if they are set to Auto.
+
+ |
+
|
+ PAN-180661
+ |
+
+
+ On the Panorama management server, pushing an unsupported Minimum
+ Password Complexity () to a managed firewall erroneously displays
+ commit time out as the reason the
+ commit failed.
+
+ |
+
|
+ PAN-180104
+ |
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2,
+ CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster
+ previously had a CN-Series as a DaemonSet deployment running PAN-OS
+ 10.0 or 10.1.
+
+
+ Workaround: Reboot the worker nodes before
+ upgrading to PAN-OS 10.2.
+
+ |
+
|
+ PAN-178194
+ |
+
+
+ A user interface issue in PAN-OS renders the contents of the
+ Inline ML tab in the
+ URL Filtering Profile inaccessible
+ on firewalls licensed for Advanced URL Filtering. Additionally, a
+ message indicating that a
+ License required for URL filtering to function
+ is unavailable displays at the bottom of the UI. These errors do not
+ affect the operation of Advanced URL Filtering or URL Filtering Inline
+ ML.
+
+
+ Workaround: Configuration settings for URL
+ Filtering Inline ML must be applied through the CLI. The following
+ configuration commands are available:
+
+
|
+
|
+ PAN-177455
+ |
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA
+ (High Availability) clustering enabled and using an HA4 communication
+ link. Attempting to load PAN-OS 10.2.0 on the firewall causes the
+ PA-7000 100G NPC to go offline. As a result, the firewall fails to
+ boot normally and enters maintenance mode. HA Pairs of Active-Passive
+ and Active-Active firewalls are not affected.
+
+ |
+
|
+ PAN-175915
+ |
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks
+ and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network
+ Protection Profile, the traffic logs do not display network slice SST
+ and SD values.
+
+ |
+
|
+ PAN-174982
+ |
+
+
+ In HA active/active configurations where, when interfaces that were
+ associated with a virtual router were deleted, the configuration
+ change did not sync.
+
+ |
+
|
+ PAN-172274
+ |
+
+
+ When you activate the advanced URL filtering license, your license
+ entitlements for PAN-DB and advanced URL filtering might not display
+ correctly on the firewall — this is a display anomaly, not a licensing
+ issue, and does not affect access to the services.
+
+
+ Workaround: Issue the following command to
+ retrieve and update the licenses:
+ license request fetch.
+
+ |
+
|
+ PAN-171938
+ |
+
+
+ No results are displayed when you
+ Show Application Filter for a
+ Security policy rule ().
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-5854
+ |
+
+
+ The WildFire analysis report on the firewall log viewer () does not display the following data fields: File Type, SHA-256,
+ MD-5, and File Size".
+
+
+ Workaround: Download and open the WildFire
+ analysis report in the PDF format using the link in the upper
+ right-hand corner of the
+ Detailed Log View.
+
+ |
+
|
+ WF500-5843
+ |
+
+
+ In a WildFire appliance cluster, issuing the
+ show cluster-all peers CLI command
+ when a node within the cluster is being rebooted generates the
+ following error:
+ Server error : An error occured.
+
+ |
+
|
+ WF500-5840
+ |
+
+
+ The sample analysis statistics that are returned when issuing the
+ show wildfire local statistics CLI
+ command in WildFire appliance cluster deployments may not accurately
+ reflect the number of samples that have been processed.
+
+ |
+
|
+ WF500-5823
+ |
+
+
+ The following WildFire appliance CLI command does not return a
+ signature generation status as expected:
+ show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance
+ from analyzing a sample.
+
+ |
+
|
+ WF500-5781
+ |
+
+
+ The WildFire appliance might erroneously generate and log the
+ following device certification error:
+ Device certificate is missing or invalid. It cannot be
+ renewed.
+
+ |
+
|
+ WF500-5754
+ |
+
+
+ In WildFire appliance clusters, issuing the
+ show cluster controller CLI command
+ generates an error when an IPv6 address is configured for the
+ management interface but not for the cluster interface.
+
+
+ Workaround: Ensure all WildFire appliance
+ interfaces that are enabled use matching protocols (all IPv4 or all
+ IPv6).
+
+ |
+
|
+ WF500-5632
+ |
+
+
+ The number of registered WildFire appliances reported in Panorama
+ () does not accurately reflect the current status of connected
+ WildFire appliances.
+
+ |
+
|
+ PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues.
+
+ |
+
+
+ A race condition may cause the dataplane to restart unexpectedly when
+ a zip decompression offload result is returned for a session that has
+ already closed. The session state is not validated before processing
+ the result because the offload result does not follow the fastpath
+ where these checks are normally performed.
+
+
+ Workaround: Disable zip hardware offloading (may
+ cause higher CPU usage).
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-303959
+ |
+
+
+ Traffic that is incorrectly identified as
+ unknown-tcp/unknown-udp
+ eventually drops due to an App-ID resource limitation issue.
+
+ |
+
|
+ PAN-297775
+ |
+
+
+ The wrong vsys is referenced under Visible Virtual System after every
+ local firewall commit (auto-commit, commit, content install) if the
+ display name of the vsys matches another vsys ID (for example, the
+ vsys2 display name is vsys1). The incorrect vsys reference causes
+ inter-vsys routing to fail.
+
+
+ Workaround: Change the vsys display name so that
+ it doesn't reference an existing vsys ID.
+
+ |
+
|
+ PAN-297610
+ |
+
+
+ A firewall may become unresponsive after an upgrade due to the
+ fsck command scanning drive
+ partitions in parallel with the root partition, causing the process to
+ take an extended amount of time.
+
+ |
+
|
+ PAN-297295
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent
+ process restarts multiple times and exhausts its restart limit,
+ resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-295803
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-295255
+ |
+
+
+ Palo Alto Networks next-generation firewalls may experience service
+ disruptions due to all_task process
+ crashes when deployed in environments having non-uniform MTU and are
+ terminating IPSec tunnels.
+
+ |
+
|
+ PAN-293673
+
+ This issue is now resolved. See PAN-OS 10.2.16-h4 Addressed Issues
+
+ |
+
+
+ When the firewall generates a high volume of logs and attempts to
+ export these logs to an FTP server, it may consume excessive memory
+ leading to all PAN-OS processes crashing.
+
+ |
+
|
+ PAN-292344
+ |
+
+
+ When upgrading from PAN-OS 10.2.9-h1 to PAN-OS 10.2.13-h5, the
+ firewall reboots repeatedly and enters maintenance mode.
+
+ |
+
|
+ PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues.
+
+ |
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM)
+ condition due to a memory leak and displays an error message. This
+ issue causes the device to crash and reboot unexpectedly.
+
+ |
+
|
+ PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues
+
+ |
+
+
+ A memory leak in the configd process
+ might lead to an active firewall to reboot due to an Out-of-Memory
+ (OOM) condition. This issue is observed when specific status commands,
+ such as
+ request log-collector forwarding status
+ are executed at high frequencies.
+
+ |
+
|
+ PAN-290996
+
+ This issue is now resolved. See
+ PAN-OS 10.2.16-h1 Addressed Issues
+
+ |
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS)
+ counters incorrectly return a value of 0 for each virtual system
+ (VSYS), despite the firewall actively processing connections.
+
+ |
+
|
+ PAN-290088
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues
+
+ |
+
+
+ (Firewalls in HA configurations only) Routed
+ process may stop responding after changing MTU or any link parameters
+ when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-287803
+ |
+
+
+ Users might be unable to access some URLs due to issues involving the
+ accumulation proxy and the Path Maximum Transmission Unit (MTU).
+
+
+ To address this issue, use one of the following workarounds:
+
+
|
+
|
+ PAN-287056
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues
+
+ |
+
+
+ A BGP export policy rule that matches on a next hop fails to block the
+ advertisement of static routes, and the firewall incorrectly matches
+ the egress interface IP address instead of the original next-hop IP
+ address of the static route, which causes the deny rule to fail.
+
+ |
+
|
+ PAN-286306
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues
+
+ |
+
+
+ When getting transceiver information from ESCC for SFP 25G modules,
+ the transceiver code incorrectly displays
+ Unknown instead of
+ 25GBase-SR.
+
+ |
+
|
+ PAN-286231
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-284073
+ |
+
+
+ The firewall web interface becomes inaccessible and commits fail.
+
+ |
+
|
+ PAN-284067
+ |
+
+
+ A cumulative memory leak in the
+ devsrvr
+ process gets progressively worse whenever the CLI command
+ show running application statistics
+ is issued. This memory leak will gradually consume system memory and
+ produce an out-of-memory (OOM) condition, leading to an eventual
+ firewall reboot.
+
+
+ Workaround: Avoid using the CLI command:
+ show running application statistics.
+
+ |
+
|
+ PAN-281370
+ |
+
+
+ The Advanced WildFire Inline ML models
+ OOXML and
+ Mach-O erroneously display as being
+ available from the CLI; however, they are only available on PAN-OS
+ 11.1.3 and later releases.
+
+ |
+
|
+ PAN-279901
+
+ (PAN-OS 10.2.16 and PAN-OS 10.2.16-h1)
+
+ |
+
+
+ When decryption is enabled, segmented Client Hello packets can cause
+ website access issues and memory leaks under the following conditions:
+
+
|
+
|
+ PAN-273158
+ |
+
+
+ (PA-7000 Series firewalls only) Due to an
+ incorrect configuration on the ASIC, receiving a mix of jumbo and
+ non-jumbo packets may cause silent packet drops or application
+ slowness.
+
+ |
+
|
+ PAN-237106
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-221775
+ |
+
+
+ A Malformed Request error is
+ displayed when you
+ Test Connection for an email server
+ profile () using SMTP over TLS and the
+ Password includes an ampersand
+ (&).
+
+ |
+
|
+ PAN-213119
+ |
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you
+ view the Block IP list ():
+
+
+ show -> dis-block-table is unexpected
+
+ |
+
|
+ PAN-211531
+ |
+ + On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (). + | +
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-194996
+ |
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma
+ Access 3.1.2 deployment, allocating bandwidth for a remote network
+ deployment fails (the OK button is grayed out).
+
+
+ Workaround: Retry the operation.
+
+ |
+
|
+ PAN-194519
+ |
+
+
+ (PA-5450 firewall only) Trying to configure a
+ custom payload format under
+
+ yields a Javascript error.
+
+ |
+
|
+ PAN-194515
+ |
+
+
+ (PA-5450 firewall only) The Panorama web
+ interface does not display any predefined template stack variables in
+ the dropdown menu under
+ .
+
+
+ Workaround: Configure the log interface IP address
+ on the individual firewall web interface instead of on Panorama.
+
+ |
+
|
+ PAN-194424
+ |
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS
+ 10.2.2 while having a log interface configured can cause both the log
+ interface and the management interface to remain connected to the log
+ collector.
+
+
+ Workaround: Restart the log receiver service by
+ running the following CLI command:
+
+
+
+
+
+ |
+
|
+ PAN-194202
+ |
+
+
+ (PA-5450 firewall only) If the management
+ interface and logging interface are configured on the same subnetwork,
+ the firewall conducts log forwarding using the management interface
+ instead of the logging interface.
+
+ |
+
|
+ PAN-190727
+ |
+
+
+ (PA-5450 firewall only) Documentation for
+ configuring the log interface is unavailable on the web interface and
+ in the PAN-OS Administrator’s Guide.
+
+ |
+
|
+ PAN-189076
+ |
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a
+ broadcast link and a designated router (DR) priority of 0 (zero) are
+ stuck in a two-way state after HA failover.
+
+
+ Workaround: Configure at least one OSPFv3 neighbor
+ with a non-zero priority setting in the same broadcast domain.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187643
+ |
+
+
+ If you enable SCTP security using a Panorama template when
+ SCTP INIT Flood Protection is
+ enabled in the Zone Protection profile using Panorama and you commit
+ all changes, the commit is successful but the
+ SCTP INIT option is not available in
+ the Zone Protection profile.
+
+
+ Workaround: Log out of the firewall and log in
+ again to make the SCIT INIT option
+ available on the web interface.
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-187370
+ |
+
+
+ On a firewall with Advanced Routing enabled, if there is also a
+ logical router instance that uses the default configuration and has no
+ interfaces assigned to it, this will result in terminating the
+ management daemon and main routing daemon in the firewall during
+ commit.
+
+
+ Workaround: Do not use a logical router instance
+ with no interfaces bound to it.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-186282
+ |
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match
+ criteria automatically when adding dynamic address groups.
+
+
+ Workaround: Reboot the Panorama HA pair.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-181823
+ |
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer
+ port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports
+ on the firewall to go down if they are set to Auto.
+
+ |
+
|
+ PAN-180661
+ |
+
+
+ On the Panorama management server, pushing an unsupported Minimum
+ Password Complexity () to a managed firewall erroneously displays
+ commit time out as the reason the
+ commit failed.
+
+ |
+
|
+ PAN-180104
+ |
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2,
+ CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster
+ previously had a CN-Series as a DaemonSet deployment running PAN-OS
+ 10.0 or 10.1.
+
+
+ Workaround: Reboot the worker nodes before
+ upgrading to PAN-OS 10.2.
+
+ |
+
|
+ PAN-178194
+ |
+
+
+ A user interface issue in PAN-OS renders the contents of the
+ Inline ML tab in the
+ URL Filtering Profile inaccessible
+ on firewalls licensed for Advanced URL Filtering. Additionally, a
+ message indicating that a
+ License required for URL filtering to function
+ is unavailable displays at the bottom of the UI. These errors do not
+ affect the operation of Advanced URL Filtering or URL Filtering Inline
+ ML.
+
+
+ Workaround: Configuration settings for URL
+ Filtering Inline ML must be applied through the CLI. The following
+ configuration commands are available:
+
+
|
+
|
+ PAN-175915
+ |
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks
+ and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network
+ Protection Profile, the traffic logs do not display network slice SST
+ and SD values.
+
+ |
+
|
+ PAN-171938
+ |
+
+
+ No results are displayed when you
+ Show Application Filter for a
+ Security policy rule ().
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-5854
+ |
+
+
+ The WildFire analysis report on the firewall log viewer () does not display the following data fields: File Type, SHA-256,
+ MD-5, and File Size".
+
+
+ Workaround: Download and open the WildFire
+ analysis report in the PDF format using the link in the upper
+ right-hand corner of the
+ Detailed Log View.
+
+ |
+
|
+ WF500-5843
+ |
+
+
+ In a WildFire appliance cluster, issuing the
+ show cluster-all peers CLI command
+ when a node within the cluster is being rebooted generates the
+ following error:
+ Server error : An error occured.
+
+ |
+
|
+ WF500-5840
+ |
+
+
+ The sample analysis statistics that are returned when issuing the
+ show wildfire local statistics CLI
+ command in WildFire appliance cluster deployments may not accurately
+ reflect the number of samples that have been processed.
+
+ |
+
|
+ WF500-5823
+ |
+
+
+ The following WildFire appliance CLI command does not return a
+ signature generation status as expected:
+ show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance
+ from analyzing a sample.
+
+ |
+
|
+ WF500-5781
+ |
+
+
+ The WildFire appliance might erroneously generate and log the
+ following device certification error:
+ Device certificate is missing or invalid. It cannot be
+ renewed.
+
+ |
+
|
+ WF500-5754
+ |
+
+
+ In WildFire appliance clusters, issuing the
+ show cluster controller CLI command
+ generates an error when an IPv6 address is configured for the
+ management interface but not for the cluster interface.
+
+
+ Workaround: Ensure all WildFire appliance
+ interfaces that are enabled use matching protocols (all IPv4 or all
+ IPv6).
+
+ |
+
|
+ WF500-5632
+ |
+
+
+ The number of registered WildFire appliances reported in Panorama
+ () does not accurately reflect the current status of connected
+ WildFire appliances.
+
+ |
+
|
+ PAN-317466
+ |
+
+
+ SIP sessions over TCP stop progressing when the firewall receives SIP
+ packets that are fragmented at a header field boundary. The firewall
+ fails to correctly handle the fragmented SIP header, causing the
+ session to stall and the SIP endpoint (phone) to reset the session,
+ resulting in dropped calls or failed call setup.
+
+
+ Workaround: Configure an App Override policy to
+ bypass application inspection for all SIP traffic destined to the call
+ manager. Clear existing SIP sessions after applying the policy. This
+ prevents the firewall from reassembling fragmented SIP packets and
+ eliminates the stalled session behavior.
+
+ |
+
|
+ PAN-308990
+ |
+
+
+ On firewalls where the management interface and a dataplane interface
+ are in the same broadcast domain, ARP replies for IP addresses
+ configured on the dataplane interfaces are incorrectly sent using the
+ management interface's MAC address. This causes
+ Received conflicting ARP messages to appear
+ continuously in the system logs.
+
+ |
+
|
+ PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues.
+
+ |
+
+
+ A race condition may cause the dataplane to restart unexpectedly when
+ a zip decompression offload result is returned for a session that has
+ already closed. The session state is not validated before processing
+ the result because the offload result does not follow the fastpath
+ where these checks are normally performed.
+
+
+ Workaround: Disable zip hardware offloading (may
+ cause higher CPU usage).
+
+ |
+
|
+ PAN-304756
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-303959
+ |
+
+
+ Traffic that is incorrectly identified as
+ unknown-tcp/unknown-udp
+ eventually drops due to an App-ID resource limitation issue.
+
+ |
+
|
+ PAN-297610
+ |
+
+
+ A firewall may become unresponsive after an upgrade due to the
+ fsck command scanning drive
+ partitions in parallel with the root partition, causing the process to
+ take an extended amount of time.
+
+ |
+
|
+ PAN-297295
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent
+ process restarts multiple times and exhausts its restart limit,
+ resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-295803
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-295255
+ |
+
+
+ Palo Alto Networks next-generation firewalls may experience service
+ disruptions due to all_task process
+ crashes when deployed in environments having non-uniform MTU and are
+ terminating IPSec tunnels.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues
+
+ |
+
+
+ (Firewalls in HA configurations only) Routed
+ process may stop responding after changing MTU or any link parameters
+ when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-287803
+ |
+
+
+ Users might be unable to access some URLs due to issues involving the
+ accumulation proxy and the Path Maximum Transmission Unit (MTU).
+
+
+ To address this issue, use one of the following workarounds:
+
+
|
+
|
+ PAN-284067
+ |
+
+
+ A cumulative memory leak in the
+ devsrvr
+ process gets progressively worse whenever the CLI command
+ show running application statistics
+ is issued. This memory leak will gradually consume system memory and
+ produce an out-of-memory (OOM) condition, leading to an eventual
+ firewall reboot.
+
+
+ Workaround: Avoid using the CLI command:
+ show running application statistics.
+
+ |
+
|
+ PAN-281370
+ |
+
+
+ The Advanced WildFire Inline ML models
+ OOXML and
+ Mach-O erroneously display as being
+ available from the CLI; however, they are only available on PAN-OS
+ 11.1.3 and later releases.
+
+ |
+
|
+ PAN-273158
+ |
+
+
+ (PA-7000 Series firewalls only) Due to an
+ incorrect configuration on the ASIC, receiving a mix of jumbo and
+ non-jumbo packets may cause silent packet drops or application
+ slowness.
+
+ |
+
| PAN-266900 | +
+
+ In Panorama, the OK button does not
+ work when trying to install configurations to a managed firewall from
+ the
+
+ section, even after selecting the update type and file from the
+ drop-down menu and choosing the firewall.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-259769
+ |
+
+
+ GlobalProtect portal is not accessible via a web browser and the app
+ displays the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-237106
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-223365
+ |
+
+
+ The Panorama management server is unable to query any logs if the
+ ElasticSearch health status for any Log Collector (
+ is degraded.
+
+
+ Workaround:
+ Log in to the Log Collector CLI
+ and restart ElasticSearch.
+
+
+
+
+
+ |
+
|
+ PAN-229865
+ |
+
+
+ Upgrading a PA-220 firewall running a PAN-OS 10.1 release fails when
+ the target PAN-OS upgrade version is PAN-OS 10.2.5.
+
+
+ Workaround: On your upgrade path to PAN-OS 10.2.5,
+ first upgrade to PAN-OS 10.2.4 and then upgrade to PAN-OS 10.2.5.
+
+ |
+
|
+ PAN-223677
+ |
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, and PA-5430
+ firewalls) By enabling
+ Lockless QoS
+ feature, a slight degradation in App-ID and Threat performance is
+ expected.
+
+ |
+
|
+ PAN-222586
+ |
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus,
+ Forward Methods, and Built-In Actions for Correlation Log settings
+ () are not displayed and cannot be configured.
+
+ |
+
|
+ PAN-221775
+ |
+
+
+ A Malformed Request error is
+ displayed when you
+ Test Connection for an email server
+ profile () using SMTP over TLS and the
+ Password includes an ampersand
+ (&).
+
+ |
+
|
+ PAN-213746
+ |
+
+
+ On the Panorama management server, the
+ Hostkey displayed as
+ undefined undefined if you
+ override an SSH Service Profile () Hostkey configured in a Template from the Template Stack.
+
+ |
+
|
+ PAN-213119
+ |
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you
+ view the Block IP list ():
+
+
+ show -> dis-block-table is unexpected
+
+ |
+
|
+ PAN-212889
+ |
+
+
+ On the Panorama management server, different threat names are used
+ when querying the same threat in the Threat Monitor () and ACC. This results in the ACC
+ displaying
+ no data to display when you are
+ redirected to the ACC after clicking a threat name in the Threat
+ Monitor and filtering the same threat name in the Global Filters.
+
+ |
+
|
+ PAN-212533
+ |
+
+
+ Modifying the Administrator Type for
+ an existing administrator (
+ or
+ ) from Superuser to a
+ Role-Based custom admin, or vice
+ versa, does not modify the access privileges of the administrator.
+
+ |
+
|
+ PAN-211531
+ |
+ + On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (). + | +
|
+ PAN-209288
+ |
+
+
+ Certificates are not successfully generated using SCEP ().
+
+ |
+
|
+ PAN-208622
+ |
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to
+ upload if you specify an Enterprise DLP data filtering profile (
+ with the Action set to Block to a
+ Security policy rule ().
+
+ |
+
|
+ PAN-204689
+ |
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do
+ not work:
+
+
|
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-196504
+ |
+ + License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). + | +
|
+ PAN-194996
+ |
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma
+ Access 3.1.2 deployment, allocating bandwidth for a remote network
+ deployment fails (the OK button is grayed out).
+
+
+ Workaround: Retry the operation.
+
+ |
+
|
+ PAN-194519
+ |
+
+
+ (PA-5450 firewall only) Trying to configure a
+ custom payload format under
+
+ yields a Javascript error.
+
+ |
+
|
+ PAN-194515
+ |
+
+
+ (PA-5450 firewall only) The Panorama web
+ interface does not display any predefined template stack variables in
+ the dropdown menu under
+ .
+
+
+ Workaround: Configure the log interface IP address
+ on the individual firewall web interface instead of on Panorama.
+
+ |
+
|
+ PAN-194424
+ |
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS
+ 10.2.2 while having a log interface configured can cause both the log
+ interface and the management interface to remain connected to the log
+ collector.
+
+
+ Workaround: Restart the log receiver service by
+ running the following CLI command:
+
+
+
+
+
+ |
+
|
+ PAN-194202
+ |
+
+
+ (PA-5450 firewall only) If the management
+ interface and logging interface are configured on the same subnetwork,
+ the firewall conducts log forwarding using the management interface
+ instead of the logging interface.
+
+ |
+
|
+ PAN-190727
+ |
+
+
+ (PA-5450 firewall only) Documentation for
+ configuring the log interface is unavailable on the web interface and
+ in the PAN-OS Administrator’s Guide.
+
+ |
+
|
+ PAN-189111
+ |
+
+
+ After deleting an MP pod and it comes up, the
+ show routing command output
+ appears empty and traffic stops working.
+
+ |
+
|
+ PAN-189076
+ |
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a
+ broadcast link and a designated router (DR) priority of 0 (zero) are
+ stuck in a two-way state after HA failover.
+
+
+ Workaround: Configure at least one OSPFv3 neighbor
+ with a non-zero priority setting in the same broadcast domain.
+
+ |
+
|
+ PAN-188358
+ |
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management
+ port LEDs do not light up when a 10G Ethernet cable is plugged in.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187643
+ |
+
+
+ If you enable SCTP security using a Panorama template when
+ SCTP INIT Flood Protection is
+ enabled in the Zone Protection profile using Panorama and you commit
+ all changes, the commit is successful but the
+ SCTP INIT option is not available in
+ the Zone Protection profile.
+
+
+ Workaround: Log out of the firewall and log in
+ again to make the SCIT INIT option
+ available on the web interface.
+
+ |
+
|
+ PAN-187612
+ |
+
+
+ On the Panorama management server, not all data profiles () are displayed after you:
+
+
+ Workaround: Log in to the Panorama CLI and reset
+ the DLP plugin.
+
+ admin > request plugins dlp reset.
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-187370
+ |
+
+
+ On a firewall with Advanced Routing enabled, if there is also a
+ logical router instance that uses the default configuration and has no
+ interfaces assigned to it, this will result in terminating the
+ management daemon and main routing daemon in the firewall during
+ commit.
+
+
+ Workaround: Do not use a logical router instance
+ with no interfaces bound to it.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-186282
+ |
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match
+ criteria automatically when adding dynamic address groups.
+
+
+ Workaround: Reboot the Panorama HA pair.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-181823
+ |
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer
+ port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports
+ on the firewall to go down if they are set to Auto.
+
+ |
+
|
+ PAN-180661
+ |
+
+
+ On the Panorama management server, pushing an unsupported Minimum
+ Password Complexity () to a managed firewall erroneously displays
+ commit time out as the reason the
+ commit failed.
+
+ |
+
|
+ PAN-180104
+ |
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2,
+ CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster
+ previously had a CN-Series as a DaemonSet deployment running PAN-OS
+ 10.0 or 10.1.
+
+
+ Workaround: Reboot the worker nodes before
+ upgrading to PAN-OS 10.2.
+
+ |
+
|
+ PAN-178194
+ |
+
+
+ A user interface issue in PAN-OS renders the contents of the
+ Inline ML tab in the
+ URL Filtering Profile inaccessible
+ on firewalls licensed for Advanced URL Filtering. Additionally, a
+ message indicating that a
+ License required for URL filtering to function
+ is unavailable displays at the bottom of the UI. These errors do not
+ affect the operation of Advanced URL Filtering or URL Filtering Inline
+ ML.
+
+
+ Workaround: Configuration settings for URL
+ Filtering Inline ML must be applied through the CLI. The following
+ configuration commands are available:
+
+
|
+
|
+ PAN-177455
+ |
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA
+ (High Availability) clustering enabled and using an HA4 communication
+ link. Attempting to load PAN-OS 10.2.0 on the firewall causes the
+ PA-7000 100G NPC to go offline. As a result, the firewall fails to
+ boot normally and enters maintenance mode. HA Pairs of Active-Passive
+ and Active-Active firewalls are not affected.
+
+ |
+
|
+ PAN-175915
+ |
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks
+ and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network
+ Protection Profile, the traffic logs do not display network slice SST
+ and SD values.
+
+ |
+
|
+ PAN-174982
+ |
+
+
+ In HA active/active configurations where, when interfaces that were
+ associated with a virtual router were deleted, the configuration
+ change did not sync.
+
+ |
+
|
+ PAN-172274
+ |
+
+
+ When you activate the advanced URL filtering license, your license
+ entitlements for PAN-DB and advanced URL filtering might not display
+ correctly on the firewall — this is a display anomaly, not a licensing
+ issue, and does not affect access to the services.
+
+
+ Workaround: Issue the following command to
+ retrieve and update the licenses:
+ license request fetch.
+
+ |
+
|
+ PAN-171938
+ |
+
+
+ No results are displayed when you
+ Show Application Filter for a
+ Security policy rule ().
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-5854
+ |
+
+
+ The WildFire analysis report on the firewall log viewer () does not display the following data fields: File Type, SHA-256,
+ MD-5, and File Size".
+
+
+ Workaround: Download and open the WildFire
+ analysis report in the PDF format using the link in the upper
+ right-hand corner of the
+ Detailed Log View.
+
+ |
+
|
+ WF500-5843
+ |
+
+
+ In a WildFire appliance cluster, issuing the
+ show cluster-all peers CLI command
+ when a node within the cluster is being rebooted generates the
+ following error:
+ Server error : An error occured.
+
+ |
+
|
+ WF500-5840
+ |
+
+
+ The sample analysis statistics that are returned when issuing the
+ show wildfire local statistics CLI
+ command in WildFire appliance cluster deployments may not accurately
+ reflect the number of samples that have been processed.
+
+ |
+
|
+ WF500-5823
+ |
+
+
+ The following WildFire appliance CLI command does not return a
+ signature generation status as expected:
+ show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance
+ from analyzing a sample.
+
+ |
+
|
+ WF500-5781
+ |
+
+
+ The WildFire appliance might erroneously generate and log the
+ following device certification error:
+ Device certificate is missing or invalid. It cannot be
+ renewed.
+
+ |
+
|
+ WF500-5754
+ |
+
+
+ In WildFire appliance clusters, issuing the
+ show cluster controller CLI command
+ generates an error when an IPv6 address is configured for the
+ management interface but not for the cluster interface.
+
+
+ Workaround: Ensure all WildFire appliance
+ interfaces that are enabled use matching protocols (all IPv4 or all
+ IPv6).
+
+ |
+
|
+ WF500-5632
+ |
+
+
+ The number of registered WildFire appliances reported in Panorama
+ () does not accurately reflect the current status of connected
+ WildFire appliances.
+
+ |
+
|
+ PAN-317466
+ |
+
+
+ SIP sessions over TCP stop progressing when the firewall receives SIP
+ packets that are fragmented at a header field boundary. The firewall
+ fails to correctly handle the fragmented SIP header, causing the
+ session to stall and the SIP endpoint (phone) to reset the session,
+ resulting in dropped calls or failed call setup.
+
+
+ Workaround: Configure an App Override policy to
+ bypass application inspection for all SIP traffic destined to the call
+ manager. Clear existing SIP sessions after applying the policy. This
+ prevents the firewall from reassembling fragmented SIP packets and
+ eliminates the stalled session behavior.
+
+ |
+
|
+ PAN-308990
+ |
+
+
+ On firewalls where the management interface and a dataplane interface
+ are in the same broadcast domain, ARP replies for IP addresses
+ configured on the dataplane interfaces are incorrectly sent using the
+ management interface's MAC address. This causes
+ Received conflicting ARP messages to appear
+ continuously in the system logs.
+
+ |
+
|
+ PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues.
+
+ |
+
+
+ A race condition may cause the dataplane to restart unexpectedly when
+ a zip decompression offload result is returned for a session that has
+ already closed. The session state is not validated before processing
+ the result because the offload result does not follow the fastpath
+ where these checks are normally performed.
+
+
+ Workaround: Disable zip hardware offloading (may
+ cause higher CPU usage).
+
+ |
+
|
+ PAN-304756
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-303959
+ |
+
+
+ Traffic that is incorrectly identified as
+ unknown-tcp/unknown-udp
+ eventually drops due to an App-ID resource limitation issue.
+
+ |
+
|
+ PAN-297610
+ |
+
+
+ A firewall may become unresponsive after an upgrade due to the
+ fsck command scanning drive
+ partitions in parallel with the root partition, causing the process to
+ take an extended amount of time.
+
+ |
+
| PAN-297295 | +
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent
+ process restarts multiple times and exhausts its restart limit,
+ resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-295803
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-295255
+ |
+
+
+ Palo Alto Networks next-generation firewalls may experience service
+ disruptions due to all_task process
+ crashes when deployed in environments having non-uniform MTU and are
+ terminating IPSec tunnels.
+
+ |
+
|
+ PAN-287803
+ |
+
+
+ Users might be unable to access some URLs due to issues involving the
+ accumulation proxy and the Path Maximum Transmission Unit (MTU).
+
+
+ To address this issue, use one of the following workarounds:
+
+
|
+
|
+ PAN-284067
+ |
+
+
+ A cumulative memory leak in the
+ devsrvr
+ process gets progressively worse whenever the CLI command
+ show running application statistics
+ is issued. This memory leak will gradually consume system memory and
+ produce an out-of-memory (OOM) condition, leading to an eventual
+ firewall reboot.
+
+
+ Workaround: Avoid using the CLI command:
+ show running application statistics.
+
+ |
+
|
+ PAN-281370
+ |
+
+
+ The Advanced WildFire Inline ML models
+ OOXML and
+ Mach-O erroneously display as being
+ available from the CLI; however, they are only available on PAN-OS
+ 11.1.3 and later releases.
+
+ |
+
|
+ PAN-273158
+ |
+
+
+ (PA-7000 Series firewalls only) Due to an
+ incorrect configuration on the ASIC, receiving a mix of jumbo and
+ non-jumbo packets may cause silent packet drops or application
+ slowness.
+
+ |
+
| PAN-266900 | +
+
+ In Panorama, the OK button does not
+ work when trying to install configurations to a managed firewall from
+ the
+
+ section, even after selecting the update type and file from the
+ drop-down menu and choosing the firewall.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-259769
+ |
+
+
+ GlobalProtect portal is not accessible via a web browser and the app
+ displays the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-237106
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-223365
+ |
+
+
+ The Panorama management server is unable to query any logs if the
+ ElasticSearch health status for any Log Collector (
+ is degraded.
+
+
+ Workaround:
+ Log in to the Log Collector CLI
+ and restart ElasticSearch.
+
+
+
+
+
+ |
+
|
+ PAN-229865
+ |
+
+
+ Upgrading a PA-220 firewall running a PAN-OS 10.1 release fails when
+ the target PAN-OS upgrade version is PAN-OS 10.2.5.
+
+
+ Workaround: On your upgrade path to PAN-OS 10.2.5,
+ first upgrade to PAN-OS 10.2.4 and then upgrade to PAN-OS 10.2.5.
+
+ |
+
|
+ PAN-223677
+ |
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, and PA-5430
+ firewalls) By enabling
+ Lockless QoS
+ feature, a slight degradation in App-ID and Threat performance is
+ expected.
+
+ |
+
|
+ PAN-222586
+ |
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus,
+ Forward Methods, and Built-In Actions for Correlation Log settings
+ () are not displayed and cannot be configured.
+
+ |
+
|
+ PAN-221775
+ |
+
+
+ A Malformed Request error is
+ displayed when you
+ Test Connection for an email server
+ profile () using SMTP over TLS and the
+ Password includes an ampersand
+ (&).
+
+ |
+
|
+ PAN-213746
+ |
+
+
+ On the Panorama management server, the
+ Hostkey displayed as
+ undefined undefined if you
+ override an SSH Service Profile () Hostkey configured in a Template from the Template Stack.
+
+ |
+
|
+ PAN-213119
+ |
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you
+ view the Block IP list ():
+
+
+ show -> dis-block-table is unexpected
+
+ |
+
|
+ PAN-212889
+ |
+
+
+ On the Panorama management server, different threat names are used
+ when querying the same threat in the Threat Monitor () and ACC. This results in the ACC
+ displaying
+ no data to display when you are
+ redirected to the ACC after clicking a threat name in the Threat
+ Monitor and filtering the same threat name in the Global Filters.
+
+ |
+
|
+ PAN-212533
+ |
+
+
+ Modifying the Administrator Type for
+ an existing administrator (
+ or
+ ) from Superuser to a
+ Role-Based custom admin, or vice
+ versa, does not modify the access privileges of the administrator.
+
+ |
+
|
+ PAN-211531
+ |
+ + On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (). + | +
|
+ PAN-209288
+ |
+
+
+ Certificates are not successfully generated using SCEP ().
+
+ |
+
|
+ PAN-208622
+ |
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to
+ upload if you specify an Enterprise DLP data filtering profile (
+ with the Action set to Block to a
+ Security policy rule ().
+
+ |
+
|
+ PAN-204689
+ |
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do
+ not work:
+
+
|
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-196504
+ |
+ + License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). + | +
|
+ PAN-194996
+ |
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma
+ Access 3.1.2 deployment, allocating bandwidth for a remote network
+ deployment fails (the OK button is grayed out).
+
+
+ Workaround: Retry the operation.
+
+ |
+
|
+ PAN-194519
+ |
+
+
+ (PA-5450 firewall only) Trying to configure a
+ custom payload format under
+
+ yields a Javascript error.
+
+ |
+
|
+ PAN-194515
+ |
+
+
+ (PA-5450 firewall only) The Panorama web
+ interface does not display any predefined template stack variables in
+ the dropdown menu under
+ .
+
+
+ Workaround: Configure the log interface IP address
+ on the individual firewall web interface instead of on Panorama.
+
+ |
+
|
+ PAN-194424
+ |
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS
+ 10.2.2 while having a log interface configured can cause both the log
+ interface and the management interface to remain connected to the log
+ collector.
+
+
+ Workaround: Restart the log receiver service by
+ running the following CLI command:
+
+
+
+
+
+ |
+
|
+ PAN-194202
+ |
+
+
+ (PA-5450 firewall only) If the management
+ interface and logging interface are configured on the same subnetwork,
+ the firewall conducts log forwarding using the management interface
+ instead of the logging interface.
+
+ |
+
|
+ PAN-190727
+ |
+
+
+ (PA-5450 firewall only) Documentation for
+ configuring the log interface is unavailable on the web interface and
+ in the PAN-OS Administrator’s Guide.
+
+ |
+
|
+ PAN-189111
+ |
+
+
+ After deleting an MP pod and it comes up, the
+ show routing command output
+ appears empty and traffic stops working.
+
+ |
+
|
+ PAN-189076
+ |
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a
+ broadcast link and a designated router (DR) priority of 0 (zero) are
+ stuck in a two-way state after HA failover.
+
+
+ Workaround: Configure at least one OSPFv3 neighbor
+ with a non-zero priority setting in the same broadcast domain.
+
+ |
+
|
+ PAN-188358
+ |
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management
+ port LEDs do not light up when a 10G Ethernet cable is plugged in.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187643
+ |
+
+
+ If you enable SCTP security using a Panorama template when
+ SCTP INIT Flood Protection is
+ enabled in the Zone Protection profile using Panorama and you commit
+ all changes, the commit is successful but the
+ SCTP INIT option is not available in
+ the Zone Protection profile.
+
+
+ Workaround: Log out of the firewall and log in
+ again to make the SCIT INIT option
+ available on the web interface.
+
+ |
+
|
+ PAN-187612
+ |
+
+
+ On the Panorama management server, not all data profiles () are displayed after you:
+
+
+ Workaround: Log in to the Panorama CLI and reset
+ the DLP plugin.
+
+ admin > request plugins dlp reset.
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-187370
+ |
+
+
+ On a firewall with Advanced Routing enabled, if there is also a
+ logical router instance that uses the default configuration and has no
+ interfaces assigned to it, this will result in terminating the
+ management daemon and main routing daemon in the firewall during
+ commit.
+
+
+ Workaround: Do not use a logical router instance
+ with no interfaces bound to it.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-186282
+ |
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match
+ criteria automatically when adding dynamic address groups.
+
+
+ Workaround: Reboot the Panorama HA pair.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-181823
+ |
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer
+ port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports
+ on the firewall to go down if they are set to Auto.
+
+ |
+
|
+ PAN-180661
+ |
+
+
+ On the Panorama management server, pushing an unsupported Minimum
+ Password Complexity () to a managed firewall erroneously displays
+ commit time out as the reason the
+ commit failed.
+
+ |
+
|
+ PAN-180104
+ |
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2,
+ CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster
+ previously had a CN-Series as a DaemonSet deployment running PAN-OS
+ 10.0 or 10.1.
+
+
+ Workaround: Reboot the worker nodes before
+ upgrading to PAN-OS 10.2.
+
+ |
+
|
+ PAN-178194
+ |
+
+
+ A user interface issue in PAN-OS renders the contents of the
+ Inline ML tab in the
+ URL Filtering Profile inaccessible
+ on firewalls licensed for Advanced URL Filtering. Additionally, a
+ message indicating that a
+ License required for URL filtering to function
+ is unavailable displays at the bottom of the UI. These errors do not
+ affect the operation of Advanced URL Filtering or URL Filtering Inline
+ ML.
+
+
+ Workaround: Configuration settings for URL
+ Filtering Inline ML must be applied through the CLI. The following
+ configuration commands are available:
+
+
|
+
|
+ PAN-177455
+ |
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA
+ (High Availability) clustering enabled and using an HA4 communication
+ link. Attempting to load PAN-OS 10.2.0 on the firewall causes the
+ PA-7000 100G NPC to go offline. As a result, the firewall fails to
+ boot normally and enters maintenance mode. HA Pairs of Active-Passive
+ and Active-Active firewalls are not affected.
+
+ |
+
|
+ PAN-175915
+ |
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks
+ and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network
+ Protection Profile, the traffic logs do not display network slice SST
+ and SD values.
+
+ |
+
|
+ PAN-174982
+ |
+
+
+ In HA active/active configurations where, when interfaces that were
+ associated with a virtual router were deleted, the configuration
+ change did not sync.
+
+ |
+
|
+ PAN-172274
+ |
+
+
+ When you activate the advanced URL filtering license, your license
+ entitlements for PAN-DB and advanced URL filtering might not display
+ correctly on the firewall — this is a display anomaly, not a licensing
+ issue, and does not affect access to the services.
+
+
+ Workaround: Issue the following command to
+ retrieve and update the licenses:
+ license request fetch.
+
+ |
+
|
+ PAN-171938
+ |
+
+
+ No results are displayed when you
+ Show Application Filter for a
+ Security policy rule ().
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-5854
+ |
+
+
+ The WildFire analysis report on the firewall log viewer () does not display the following data fields: File Type, SHA-256,
+ MD-5, and File Size".
+
+
+ Workaround: Download and open the WildFire
+ analysis report in the PDF format using the link in the upper
+ right-hand corner of the
+ Detailed Log View.
+
+ |
+
|
+ WF500-5843
+ |
+
+
+ In a WildFire appliance cluster, issuing the
+ show cluster-all peers CLI command
+ when a node within the cluster is being rebooted generates the
+ following error:
+ Server error : An error occured.
+
+ |
+
|
+ WF500-5840
+ |
+
+
+ The sample analysis statistics that are returned when issuing the
+ show wildfire local statistics CLI
+ command in WildFire appliance cluster deployments may not accurately
+ reflect the number of samples that have been processed.
+
+ |
+
|
+ WF500-5823
+ |
+
+
+ The following WildFire appliance CLI command does not return a
+ signature generation status as expected:
+ show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance
+ from analyzing a sample.
+
+ |
+
|
+ WF500-5781
+ |
+
+
+ The WildFire appliance might erroneously generate and log the
+ following device certification error:
+ Device certificate is missing or invalid. It cannot be
+ renewed.
+
+ |
+
|
+ WF500-5754
+ |
+
+
+ In WildFire appliance clusters, issuing the
+ show cluster controller CLI command
+ generates an error when an IPv6 address is configured for the
+ management interface but not for the cluster interface.
+
+
+ Workaround: Ensure all WildFire appliance
+ interfaces that are enabled use matching protocols (all IPv4 or all
+ IPv6).
+
+ |
+
|
+ WF500-5632
+ |
+
+
+ The number of registered WildFire appliances reported in Panorama
+ () does not accurately reflect the current status of connected
+ WildFire appliances.
+
+ |
+
|
+ PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues.
+
+ |
+
+
+ A race condition may cause the dataplane to restart unexpectedly when
+ a zip decompression offload result is returned for a session that has
+ already closed. The session state is not validated before processing
+ the result because the offload result does not follow the fastpath
+ where these checks are normally performed.
+
+
+ Workaround: Disable zip hardware offloading (may
+ cause higher CPU usage).
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See PAN-OS 10.2.13-h18 Addressed Issuesand
+ PAN-OS 10.2.16-h6 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-297610
+ |
+
+
+ A firewall may become unresponsive after an upgrade due to the
+ fsck command scanning drive
+ partitions in parallel with the root partition, causing the process to
+ take an extended amount of time.
+
+ |
+
|
+ PAN-297295
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent
+ process restarts multiple times and exhausts its restart limit,
+ resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-295255
+ |
+
+
+ Palo Alto Networks next-generation firewalls may experience service
+ disruptions due to all_task process
+ crashes when deployed in environments having non-uniform MTU and are
+ terminating IPSec tunnels.
+
+ |
+
|
+ PAN-295803
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues.
+
+ |
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM)
+ condition due to a memory leak and displays an error message. This
+ issue causes the device to crash and reboot unexpectedly.
+
+ |
+
|
+ PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues
+
+ |
+
+
+ A memory leak in the configd process
+ might lead to an active firewall to reboot due to an Out-of-Memory
+ (OOM) condition. This issue is observed when specific status commands,
+ such as
+ request log-collector forwarding status
+ are executed at high frequencies.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues
+
+ |
+
+
+ (Firewalls in HA configurations only) Routed
+ process may stop responding after changing MTU or any link parameters
+ when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-286231
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-284073
+ |
+
+
+ The firewall web interface becomes inaccessible and commits fail.
+
+ |
+
|
+ PAN-284067
+ |
+
+
+ A cumulative memory leak in the
+ devsrvr
+ process gets progressively worse whenever the CLI command
+ show running application statistics
+ is issued. This memory leak will gradually consume system memory and
+ produce an out-of-memory (OOM) condition, leading to an eventual
+ firewall reboot.
+
+
+ Workaround: Avoid using the CLI command:
+ show running application statistics.
+
+ |
+
|
+ PAN-281370
+ |
+
+
+ The Advanced WildFire Inline ML models
+ OOXML and
+ Mach-O erroneously display as being
+ available from the CLI; however, they are only available on PAN-OS
+ 11.1.3 and later releases.
+
+ |
+
|
+ PAN-273158
+ |
+
+
+ (PA-7000 Series firewalls only) Due to an
+ incorrect configuration on the ASIC, receiving a mix of jumbo and
+ non-jumbo packets may cause silent packet drops or application
+ slowness.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
| PAN-259769 | +
+
+ GlobalProtect portal is not accessible via a web browser and the app
+ displays the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-243951
+ |
+
+
+ On the Panorama management sever in an active/passive High
+ Availability (HA) configuration, managed devices () display as out-of-sync on the
+ passive HA peer when configuration changes are made to the SD-WAN
+ () configuration on the active HA peer.
+
+
+ Workaround: Manually synchronize the Panorama HA
+ peers.
+
+
|
+
|
+ PAN-234408
+ |
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for
+ ChatGPT from traffic forwarded to the DLP cloud service from an NGFW.
+
+ |
+
|
+ PAN-228273
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server in FIPS-CC mode, the ElasticSearch
+ cluster fails to come up and the
+ show log-collector-es-cluster health
+ command displays the status is
+ red. This results in log
+ ingestion issues for Panorama in Panorama only or Log Collector mode.
+
+ |
+
|
+ PAN-227344
+ |
+
+
+ On the Panorama management server, PDF Summary Reports () display no data and are blank when predefined reports are included
+ in the summary report.
+
+ |
+
|
+ PAN-225337
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, the configuration push to a
+ multi-vsys firewall fails if you:
+
+
+ Workaround: Select
+
+ and edit the Panorama Settings to enable one of the following:
+
+
+ Alternatively, you can remove the duplicate address objects from the
+ device group configuration to allow only the
+ Shared objects in your
+ configuration.
+
+ |
+
|
+ PAN-223488
+
+ This issue is now resolved. See
+ PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ Closed ElasticSearch shards are not deleted from the Panorama M-Series
+ and virtual appliance. This causes the ElasticSearch shard purging to
+ not work as expected, resulting in high disk usage.
+
+ |
+
|
+ PAN-223365
+ |
+
+
+ The Panorama management server is unable to query any logs if the
+ ElasticSearch health status for any Log Collector (
+ is degraded.
+
+
+ Workaround:
+ Log in to the Log Collector CLI
+ and restart ElasticSearch.
+
+
+
+
+
+ |
+
|
+ PAN-222586
+ |
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus,
+ Forward Methods, and Built-In Actions for Correlation Log settings
+ () are not displayed and cannot be configured.
+
+ |
+
|
+ PAN-222253
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, policy rulebase reordering when you
+ View Rulebase by Groups () does not persist if you reorder the policy rulebase by dragging and
+ dropping individual policy rules and then moving the entire tag group.
+
+ |
+
|
+ PAN-221775
+ |
+
+
+ A Malformed Request error is
+ displayed when you
+ Test Connection for an email server
+ profile () using SMTP over TLS and the
+ Password includes an ampersand
+ (&).
+
+ |
+
|
+ PAN-221015
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ On M-600 appliances in Panorama or Log Collector mode, the
+ es-1 and
+ es-2 ElasticSearch processes fail
+ to restart when the M-600 appliance is rebooted. The results in the
+ Managed Collector ES health
+ status () to be degraded.
+
+
+ Workaround:
+ Log in to the Panorama or Log Collector CLI
+ experiencing degraded ElasticSearch health and restart all
+ ElasticSearch processes.
+
+
+
+
+
+ |
+
|
+ PAN-219644
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ Firewalls forwarding logs to a syslog server over TLS () use the default Palo Alto Networks certificate instead of the
+ custom certificate configured on the firewall.
+
+ |
+
|
+ PAN-218521
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ The ElasticSearch process on the M-600 appliance in Log Collector mode
+ may enter a continuous reboot cycle. This results in the M-600
+ appliance becoming unresponsive, consuming logging disk space, and
+ preventing new log ingestion.
+
+ |
+
|
+ PAN-217307
+
+ This issue is now resolved. See PAN-OS 10.2.11 Addressed Issues.
+
+ |
+
+
+ The following Security policy rule () filters return no results:
+
+
+ log-start eq no
+
+ log-end eq no
+ log-end eq yes
+ |
+
|
+ PAN-215778
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues.
+
+ |
+
+
+ On the M-600 appliance in Management Only mode, XML API Get requests
+ for /config fail with the
+ following error due to exceeding the
+ total configuration size
+ supported on the M-600 appliance.
+
+
+
+
+
+ |
+
|
+ PAN-215082
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ M-300 and M-700 appliances may generate erroneous system logs () to alert that the M-Series appliance memory usage limits are
+ reached.
+
+ |
+
|
+ PAN-213746
+ |
+
+
+ On the Panorama management server, the
+ Hostkey displayed as
+ undefined undefined if you
+ override an SSH Service Profile () Hostkey configured in a Template from the Template Stack.
+
+ |
+
|
+ PAN-213119
+ |
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you
+ view the Block IP list ():
+
+
+ show -> dis-block-table is unexpected
+
+ |
+
|
+ PAN-212889
+
+ This issue is now resolved. See
+ PAN-OS 10.2.14 Addressed Issues
+
+ |
+
+
+ On the Panorama management server, different threat names are used
+ when querying the same threat in the Threat Monitor () and ACC. This results in the ACC
+ displaying
+ no data to display when you are
+ redirected to the ACC after clicking a threat name in the Threat
+ Monitor and filtering the same threat name in the Global Filters.
+
+ |
+
|
+ PAN-212533
+ |
+
+
+ Modifying the Administrator Type for
+ an existing administrator (
+ or
+ ) from Superuser to a
+ Role-Based custom admin, or vice
+ versa, does not modify the access privileges of the administrator.
+
+ |
+
|
+ PAN-211531
+ |
+ + On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (). + | +
|
+ PAN-210366
+
+ This issue is now resolved. See PAN-OS 10.2.4-h3 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server in a high availability (HA)
+ configuration, the primary HA peer may enter a
+ primary-non-functional state and
+ generate a system log () with the following message:
+
+
+ High root partition usage: going to state Non-Functional
+
+ |
+
|
+ PAN-209288
+ |
+
+
+ Certificates are not successfully generated using SCEP ().
+
+ |
+
|
+ PAN-208325
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues.
+
+ |
+
+
+ The following NextGen firewalls and Panorama management server models
+ are unable to automatically renew the device certificate (
+ or
+ ).
+
+
+ Workaround: Log in to the
+ firewall CLI
+ or
+ Panorama CLI
+ and fetch the device certificate.
+
+
+
+
+
+ |
+
|
+ PAN-207629
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, selective push fails to managed
+ firewalls if the managed firewalls are enabled with multiple vsys and
+ the Push Scope contains shared objects in device groups.
+
+ |
+
|
+ PAN-206268
+ |
+
+
+ On the Panorama management server, the Auth Key field was erroneously
+ displayed when you configure the Panorama Settings () as part of a template or template stack configuration.
+
+ |
+
|
+ PAN-206253
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ For PA-3400 Series firewalls, the default log rate is set too low and
+ the max configurable log rate is incorrectly capped resulting in the
+ firewall not generating more than 6,826 logs per second.
+
+ |
+
|
+ PAN-206243
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ The PA-220 firewall reaches the maximum disk usage capacity multiple a
+ day that requires a disk cleanup. A critical system log () is generated each time the firewall reaches maximum disk usage
+ capacity.
+
+ |
+
|
+ PAN-205187
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ ElasticSearch may not start properly when a newly installed Panorama
+ virtual appliance powers on for the first time, resulting in the
+ Panorama virtual appliance being unable to query logs forwarded from
+ the managed firewall to a Log Collector.
+
+
+ Workaround:
+ Log in to the Panorama CLI
+ and start the PAN-OS software.
+
+
+
+
+
+ |
+
|
+ PAN-204663
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, you are unable to Context Switch
+ from one managed firewall to another.
+
+
+ Workaround: After you Context Switch to a managed
+ firewall, you must first Context Switch back to Panorama before you
+ can continue to Context Switch to a different managed firewall.
+
+ |
+
|
+ PAN-201855
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, cloning any template () corrupts certificates () with the
+ Block Private Key Export setting
+ enabled across all templates. This results in managed firewalls
+ experiencing issues wherever the corrupted certificate is referenced.
+
+
+ For example, you have template A, B, and C where templates A and B
+ have certificates with the
+ Block Private Key Export setting
+ enabled. Cloning template C corrupts the certificates with
+ Block Private Key Export setting
+ enabled in templates A and B.
+
+
+ Workaround: After cloning a template, delete and
+ re-import the corrupted certificates.
+
+ |
+
|
+ PAN-200019
+
+ PAN-OS 10.2.2-h1 and later releases.
+
+ |
+
+
+ On the Panorama management server, the Virtual Routers () setting is not available when configuring a custom Panorama admin
+ role ().
+
+ |
+
|
+ PAN-199557
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues.
+
+ |
+
+
+ On M-600 appliances in an Active/Passive high availability (HA)
+ configuration, the
+ configd process restarts due to a
+ memory leak on the
+ Active Panorama HA peer. This
+ causes the Panorama web interface and CLI to become unresponsive.
+
+
+ Workaround: Manually reboot the
+ Active Panorama HA peer.
+
+ |
+
|
+ PAN-199099
+ |
+
+
+ When decryption is enabled, Safari and Google Chrome browsers on Mac
+ computers running macOS Monterey or later reject the server
+ certificates firewalls present. The browsers cannot validate the chain
+ of trust for the certificates because the Authority Key Identifier
+ (AKID) of the server certificates and the Subject Key Identifier
+ (SKID) of the forward trust certificate do not match.
+
+
+ Workaround: Use a forward trust certificate that
+ does not contain AKID or SKID extensions.
+
+ |
+
|
+ PAN-198174
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ When viewing traffic or threat logs from the firewall ACC or Monitor,
+ performing a reverse DNS lookup, for example, when resolving IP
+ addresses to domain names using the
+ Resolve Hostname feature, can cause
+ the appliance to crash and restart if DNS server settings have not
+ been configured.
+
+
+ Workaround: Provide a DNS server setting for the
+ firewall (). If you cannot reference a valid DNS server, you can add a dummy
+ address.
+
+ |
+
|
+ PAN-197097
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ Large Scale VPN (LSVPN) does not support IPv6 addresses on the
+ satellite firewall.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-196784
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ Palo Alto Networks® Next-Gen firewalls experience a logs per second
+ (LPS) degradation after upgrade to PAN-OS 10.2.2.
+
+ |
+
|
+ PAN-196504
+ |
+ + License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). + | +
|
+ PAN-196146
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ The VM-Series firewall on Azure does not boot up with a hostname
+ (specified in an init-cgf.txt or user data) when bootstrapped.
+
+ |
+
|
+ PAN-195541
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ When a DNS request is submitted to the DNS Security service for
+ inspection, the dataplane pan-task process (all_pktproc) might fail
+ during the DNS request process, or when the dataplane cache is reset,
+ or if the cache output is generated through the CLI, resulting in
+ firewall crashes or the inability/reduced capability to process
+ network traffic.
+
+
+ The following CLI commands can trigger a crash of the all_pktproc
+ process:
+
+
|
+
|
+ PAN-194996
+ |
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma
+ Access 3.1.2 deployment, allocating bandwidth for a remote network
+ deployment fails (the OK button is grayed out).
+
+
+ Workaround: Retry the operation.
+
+ |
+
|
+ PAN-194925
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma
+ Access 3.1.2 deployment, when making changes in the Service Connection
+ and Remote Networks area, the configuration changes do not display in
+ the Push Scope during a commit.
+
+
+ Workaround: For service connection changes, make
+ sure that Service Setup is selected in the Push Scope before you
+ commit. For remote network changes, make sure that Remote Networks is
+ selected in the Push Scope before you commit.
+
+ |
+
|
+ PAN-194859
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma
+ Access 3.1.2 deployment, after migrating from a single tenant to a
+ multi-tenant Prisma Access deployment and making configuration
+ changes, the Cloud Services plugin shows
+ No pending changes to commit when
+ you hover over the Commit tab, even though there are pending changes
+ to commit.
+
+
+ Workaround: The status shown when hovering over
+ the Commit tab is a cosmetic issue. Commit the pending changes, if
+ required.
+
+ |
+
|
+ PAN-194826
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ (WF-500 and WF-500-B appliance only) System log
+ forwarding does not work over a TLS connection.
+
+ |
+
|
+ PAN-194708
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ URL filtering logs () erroneously truncate a 16KB Header value and do not display the
+ Header values that follow the truncated 16KB header.
+
+
+ For example, a URL filtering log has 5 Headers. The second Header has
+ a 16KB value. In the URL filtering log, the first header and the value
+ are displayed, second Header value is truncated, and remaining three
+ headers are not displayed.
+
+ |
+
|
+ PAN-194519
+ |
+
+
+ (PA-5450 firewall only) Trying to configure a
+ custom payload format under
+
+ yields a Javascript error.
+
+ |
+
|
+ PAN-194515
+ |
+
+
+ (PA-5450 firewall only) The Panorama web
+ interface does not display any predefined template stack variables in
+ the dropdown menu under
+ .
+
+
+ Workaround: Configure the log interface IP address
+ on the individual firewall web interface instead of on Panorama.
+
+ |
+
|
+ PAN-194424
+ |
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS
+ 10.2.2 while having a log interface configured can cause both the log
+ interface and the management interface to remain connected to the log
+ collector.
+
+
+ Workaround: Restart the log receiver service by
+ running the following CLI command:
+
+
+
+
+
+ |
+
|
+ PAN-194202
+ |
+
+
+ (PA-5450 firewall only) If the management
+ interface and logging interface are configured on the same subnetwork,
+ the firewall conducts log forwarding using the management interface
+ instead of the logging interface.
+
+ |
+
|
+ PAN-193251
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ If SAML is configured as the authentication method for GlobalProtect,
+ authentication on the Portal page is not successful in the browser.
+
+
+ Workaround: Use the GlobalProtect app installed on
+ the endpoint to authenticate.
+
+ |
+
|
+ PAN-190735
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ Certain webpages that use chunked-encoded data transfers might not
+ load properly when analyzed by Advanced URL Filtering cloud inline
+ categorization.
+
+ |
+
|
+ PAN-190727
+ |
+
+
+ (PA-5450 firewall only) Documentation for
+ configuring the log interface is unavailable on the web interface and
+ in the PAN-OS Administrator’s Guide.
+
+ |
+
|
+ PAN-190435
+ |
+
+
+ When you Commit a configuration
+ change, the Task Manager commit
+ Status goes directly from
+ 0% to
+ Completed and does accurately
+ reflect the commit job progress.
+
+ |
+
|
+ PAN-189425
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server,
+ Export Panorama and devices config bundle
+ () fails to export. When the export fails, you are redirected to a new
+ window and the following error is displayed:
+
+
+ Failed to redirect error to /var/log/pan/appweb3-panmodule.log
+ (Permission denied)
+
+ |
+
|
+ PAN-189380
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ After you successfully upgrade a PA-3000 Series firewall to PAN-OS
+ 10.2.0 or later release and Enterprise data loss prevention (DLP)
+ plugin 3.0.0 or later release, the first configuration push from the
+ Panorama management server causes the firewall dataplane to crash.
+
+
+ Workaround: Restart the firewall to restore
+ dataplane functionality.
+
+
|
+
|
+ PAN-189111
+ |
+
+
+ After deleting an MP pod and it comes up, the
+ show routing command output
+ appears empty and traffic stops working.
+
+ |
+
|
+ PAN-189076
+ |
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a
+ broadcast link and a designated router (DR) priority of 0 (zero) are
+ stuck in a two-way state after HA failover.
+
+
+ Workaround: Configure at least one OSPFv3 neighbor
+ with a non-zero priority setting in the same broadcast domain.
+
+ |
+
|
+ PAN-188904
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ Certain web pages and web page contents might not properly load when
+ cloud inline categorization is enabled on the firewall.
+
+ |
+
|
+ PAN-188489
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, dynamic content updates are not
+ automatically pushed to VM-Series firewalls licensed using the
+ Panorama Software Firewall License plugin when
+ Automatically push content when software device registers to
+ Panorama
+ () is enabled.
+
+ |
+
|
+ PAN-188358
+ |
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management
+ port LEDs do not light up when a 10G Ethernet cable is plugged in.
+
+ |
+
|
+ PAN-188064
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ The SCP Server Profile configuration (
+ are not automatically deleted after downgrade from PAN-OS 10.2.0 to
+ PAN-OS 10.1 or earlier release.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187643
+ |
+
+
+ If you enable SCTP security using a Panorama template when
+ SCTP INIT Flood Protection is
+ enabled in the Zone Protection profile using Panorama and you commit
+ all changes, the commit is successful but the
+ SCTP INIT option is not available in
+ the Zone Protection profile.
+
+
+ Workaround: Log out of the firewall and log in
+ again to make the SCIT INIT option
+ available on the web interface.
+
+ |
+
|
+ PAN-187612
+ |
+
+
+ On the Panorama management server, not all data profiles () are displayed after you:
+
+
+ Workaround: Log in to the Panorama CLI and reset
+ the DLP plugin.
+
+ admin > request plugins dlp reset
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-187370
+ |
+
+
+ On a firewall with Advanced Routing enabled, if there is also a
+ logical router instance that uses the default configuration and has no
+ interfaces assigned to it, this will result in terminating the
+ management daemon and main routing daemon in the firewall during
+ commit.
+
+
+ Workaround: Do not use a logical router instance
+ with no interfaces bound to it.
+
+ |
+
|
+ PAN-187234
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ Certain web pages submitted for analysis by Advanced URL Filtering
+ cloud inline categorization might experience high latency.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-186282
+ |
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match
+ criteria automatically when adding dynamic address groups.
+
+
+ Workaround: Reboot the Panorama HA pair.
+
+ |
+
|
+ PAN-186134
+ |
+
+
+ On the Panorama management server, performing a
+ Commit and Push (Commit > Commit and Push) may intermittently not push the committed configuration changes to
+ managed firewalls.
+
+
+ Workaround: Select
+ Commit > Push to Devices to push
+ the committed configuration changes to your managed firewalls.
+
+ |
+
|
+ PAN-185286
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ (PA-5400 Series firewalls only) On the Panorama
+ management server, the device health resources () do not populate.
+
+ |
+
|
+ PAN-184708
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
|
+
|
+ PAN-184702
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, an M-700 appliance in Log Collector
+ mode fails to connect to Panorama when added as a managed collector
+ ().
+
+
+ Workaround:
+ Log in to the M-700 CLI
+ and
+ recover the Log Collector connectivity to Panorama.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-182734
+
+ This issue is now resolved. See
+ PAN-OS 10.2.5 Addressed Issues.
+
+ |
+
+
+ On an Advanced Routing Engine, if you change the IPSec tunnel
+ configuration, BGP flaps.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-181823
+ |
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer
+ port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports
+ on the firewall to go down if they are set to Auto.
+
+ |
+
|
+ PAN-180661
+ |
+
+
+ On the Panorama management server, pushing an unsupported Minimum
+ Password Complexity () to a managed firewall erroneously displays
+ commit time out as the reason the
+ commit failed.
+
+ |
+
|
+ PAN-180104
+ |
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2,
+ CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster
+ previously had a CN-Series as a DaemonSet deployment running PAN-OS
+ 10.0 or 10.1.
+
+
+ Workaround: Reboot the worker nodes before
+ upgrading to PAN-OS 10.2.
+
+ |
+
|
+ PAN-178194
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues.
+
+ |
+
+
+ A user interface issue in PAN-OS renders the contents of the
+ Inline ML tab in the
+ URL Filtering Profile inaccessible
+ on firewalls licensed for Advanced URL Filtering. Additionally, a
+ message indicating that a
+ License required for URL filtering to function
+ is unavailable displays at the bottom of the UI. These errors do not
+ affect the operation of Advanced URL Filtering or URL Filtering Inline
+ ML.
+
+
+ Workaround: Configuration settings for URL
+ Filtering Inline ML must be applied through the CLI. The following
+ configuration commands are available:
+
+
|
+
|
+ PAN-177455
+ |
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA
+ (High Availability) clustering enabled and using an HA4 communication
+ link. Attempting to load PAN-OS 10.2.0 on the firewall causes the
+ PA-7000 100G NPC to go offline. As a result, the firewall fails to
+ boot normally and enters maintenance mode. HA Pairs of Active-Passive
+ and Active-Active firewalls are not affected.
+
+ |
+
|
+ PAN-175915
+ |
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks
+ and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network
+ Protection Profile, the traffic logs do not display network slice SST
+ and SD values.
+
+ |
+
|
+ PAN-174982
+ |
+
+
+ In HA active/active configurations where, when interfaces that were
+ associated with a virtual router were deleted, the configuration
+ change did not sync.
+
+ |
+
|
+ PAN-172274
+ |
+
+
+ When you activate the advanced URL filtering license, your license
+ entitlements for PAN-DB and advanced URL filtering might not display
+ correctly on the firewall — this is a display anomaly, not a licensing
+ issue, and does not affect access to the services.
+
+
+ Workaround: Issue the following command to
+ retrieve and update the licenses:
+ license request fetch.
+
+ |
+
|
+ PAN-172132
+
+ This issue is now resolved by PAN-189643. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ QoS fails to run on a tunnel interface (for example, tunnel.1).
+
+ |
+
|
+ PAN-171938
+ |
+
+
+ No results are displayed when you
+ Show Application Filter for a
+ Security policy rule ().
+
+ |
+
|
+ PAN-164885
+
+ This issue is now resolved. See PAN-OS 10.2.10 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, pushes to managed firewalls (
+ or Commit and Push) may fail when an
+ EDL () is configured to
+ Check for updates every 5 minutes
+ due to the commit and EDL fetch processes overlapping. This is more
+ likely to occur when multiple EDLs are configured to check for updates
+ every 5 minutes.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-5854
+ |
+
+
+ The WildFire analysis report on the firewall log viewer () does not display the following data fields: File Type, SHA-256,
+ MD-5, and File Size".
+
+
+ Workaround: Download and open the WildFire
+ analysis report in the PDF format using the link in the upper
+ right-hand corner of the
+ Detailed Log View.
+
+ |
+
|
+ WF500-5843
+ |
+
+
+ In a WildFire appliance cluster, issuing the
+ show cluster-all peers CLI command
+ when a node within the cluster is being rebooted generates the
+ following error:
+ Server error : An error occured.
+
+ |
+
|
+ WF500-5840
+ |
+
+
+ The sample analysis statistics that are returned when issuing the
+ show wildfire local statistics CLI
+ command in WildFire appliance cluster deployments may not accurately
+ reflect the number of samples that have been processed.
+
+ |
+
|
+ WF500-5823
+ |
+
+
+ The following WildFire appliance CLI command does not return a
+ signature generation status as expected:
+ show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance
+ from analyzing a sample.
+
+ |
+
|
+ WF500-5781
+ |
+
+
+ The WildFire appliance might erroneously generate and log the
+ following device certification error:
+ Device certificate is missing or invalid. It cannot be
+ renewed.
+
+ |
+
|
+ WF500-5754
+ |
+
+
+ In WildFire appliance clusters, issuing the
+ show cluster controller CLI command
+ generates an error when an IPv6 address is configured for the
+ management interface but not for the cluster interface.
+
+
+ Workaround: Ensure all WildFire appliance
+ interfaces that are enabled use matching protocols (all IPv4 or all
+ IPv6).
+
+ |
+
|
+ WF500-5632
+ |
+
+
+ The number of registered WildFire appliances reported in Panorama
+ () does not accurately reflect the current status of connected
+ WildFire appliances.
+
+ |
+
|
+ PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues.
+
+ |
+
+
+ A race condition may cause the dataplane to restart unexpectedly when
+ a zip decompression offload result is returned for a session that has
+ already closed. The session state is not validated before processing
+ the result because the offload result does not follow the fastpath
+ where these checks are normally performed.
+
+
+ Workaround: Disable zip hardware offloading (may
+ cause higher CPU usage).
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See PAN-OS 10.2.13-h18 Addressed Issuesand
+ PAN-OS 10.2.16-h6 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-297610
+ |
+
+
+ A firewall may become unresponsive after an upgrade due to the
+ fsck command scanning drive
+ partitions in parallel with the root partition, causing the process to
+ take an extended amount of time.
+
+ |
+
|
+ PAN-297295
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent
+ process restarts multiple times and exhausts its restart limit,
+ resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-295803
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-295255
+ |
+
+
+ Palo Alto Networks next-generation firewalls may experience service
+ disruptions due to all_task process
+ crashes when deployed in environments having non-uniform MTU and are
+ terminating IPSec tunnels.
+
+ |
+
|
+ PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues.
+
+ |
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM)
+ condition due to a memory leak and displays an error message. This
+ issue causes the device to crash and reboot unexpectedly.
+
+ |
+
|
+ PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues
+
+ |
+
+
+ A memory leak in the configd process
+ might lead to an active firewall to reboot due to an Out-of-Memory
+ (OOM) condition. This issue is observed when specific status commands,
+ such as
+ request log-collector forwarding status
+ are executed at high frequencies.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues
+
+ |
+
+
+ (Firewalls in HA configurations only) Routed
+ process may stop responding after changing MTU or any link parameters
+ when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-286231
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-284073
+ |
+
+
+ The firewall web interface becomes inaccessible and commits fail.
+
+ |
+
|
+ PAN-284067
+ |
+
+
+ A cumulative memory leak in the
+ devsrvr
+ process gets progressively worse whenever the CLI command
+ show running application statistics
+ is issued. This memory leak will gradually consume system memory and
+ produce an out-of-memory (OOM) condition, leading to an eventual
+ firewall reboot.
+
+
+ Workaround: Avoid using the CLI command:
+ show running application statistics.
+
+ |
+
|
+ PAN-281370
+ |
+
+
+ The Advanced WildFire Inline ML models
+ OOXML and
+ Mach-O erroneously display as being
+ available from the CLI; however, they are only available on PAN-OS
+ 11.1.3 and later releases.
+
+ |
+
|
+ PAN-273158
+ |
+
+
+ (PA-7000 Series firewalls only) Due to an
+ incorrect configuration on the ASIC, receiving a mix of jumbo and
+ non-jumbo packets may cause silent packet drops or application
+ slowness.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
| PAN-259769 | +
+
+ GlobalProtect portal is not accessible via a web browser and the app
+ displays the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-243951
+ |
+
+
+ On the Panorama management sever in an active/passive High
+ Availability (HA) configuration, managed devices () display as out-of-sync on the
+ passive HA peer when configuration changes are made to the SD-WAN
+ () configuration on the active HA peer.
+
+
+ Workaround: Manually synchronize the Panorama HA
+ peers.
+
+
|
+
|
+ PAN-234408
+ |
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for
+ ChatGPT from traffic forwarded to the DLP cloud service from an NGFW.
+
+ |
+
|
+ PAN-228273
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server in FIPS-CC mode, the ElasticSearch
+ cluster fails to come up and the
+ show log-collector-es-cluster health
+ command displays the status is
+ red. This results in log
+ ingestion issues for Panorama in Panorama only or Log Collector mode.
+
+ |
+
|
+ PAN-227344
+ |
+
+
+ On the Panorama management server, PDF Summary Reports () display no data and are blank when predefined reports are included
+ in the summary report.
+
+ |
+
|
+ PAN-225337
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, the configuration push to a
+ multi-vsys firewall fails if you:
+
+
+ Workaround: Select
+
+ and edit the Panorama Settings to enable one of the following:
+
+
+ Alternatively, you can remove the duplicate address objects from the
+ device group configuration to allow only the
+ Shared objects in your
+ configuration.
+
+ |
+
|
+ PAN-223488
+
+ This issue is now resolved. See
+ PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ Closed ElasticSearch shards are not deleted from the Panorama M-Series
+ and virtual appliance. This causes the ElasticSearch shard purging to
+ not work as expected, resulting in high disk usage.
+
+ |
+
|
+ PAN-223365
+ |
+
+
+ The Panorama management server is unable to query any logs if the
+ ElasticSearch health status for any Log Collector (
+ is degraded.
+
+
+ Workaround:
+ Log in to the Log Collector CLI
+ and restart ElasticSearch.
+
+
+
+
+
+ |
+
|
+ PAN-222586
+ |
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus,
+ Forward Methods, and Built-In Actions for Correlation Log settings
+ () are not displayed and cannot be configured.
+
+ |
+
|
+ PAN-222253
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, policy rulebase reordering when you
+ View Rulebase by Groups () does not persist if you reorder the policy rulebase by dragging and
+ dropping individual policy rules and then moving the entire tag group.
+
+ |
+
|
+ PAN-221775
+ |
+
+
+ A Malformed Request error is
+ displayed when you
+ Test Connection for an email server
+ profile () using SMTP over TLS and the
+ Password includes an ampersand
+ (&).
+
+ |
+
|
+ PAN-221015
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ On M-600 appliances in Panorama or Log Collector mode, the
+ es-1 and
+ es-2 ElasticSearch processes fail
+ to restart when the M-600 appliance is rebooted. The results in the
+ Managed Collector ES health
+ status () to be degraded.
+
+
+ Workaround:
+ Log in to the Panorama or Log Collector CLI
+ experiencing degraded ElasticSearch health and restart all
+ ElasticSearch processes.
+
+
+
+
+
+ |
+
|
+ PAN-219644
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ Firewalls forwarding logs to a syslog server over TLS () use the default Palo Alto Networks certificate instead of the
+ custom certificate configured on the firewall.
+
+ |
+
|
+ PAN-218521
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ The ElasticSearch process on the M-600 appliance in Log Collector mode
+ may enter a continuous reboot cycle. This results in the M-600
+ appliance becoming unresponsive, consuming logging disk space, and
+ preventing new log ingestion.
+
+ |
+
|
+ PAN-217307
+
+ This issue is now resolved. See PAN-OS 10.2.11 Addressed Issues.
+
+ |
+
+
+ The following Security policy rule () filters return no results:
+
+
+ log-start eq no
+
+ log-end eq no
+ log-end eq yes
+ |
+
|
+ PAN-215778
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues.
+
+ |
+
+
+ On the M-600 appliance in Management Only mode, XML API Get requests
+ for /config fail with the
+ following error due to exceeding the
+ total configuration size
+ supported on the M-600 appliance.
+
+
+
+
+
+ |
+
|
+ PAN-215082
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ M-300 and M-700 appliances may generate erroneous system logs () to alert that the M-Series appliance memory usage limits are
+ reached.
+
+ |
+
|
+ PAN-213746
+ |
+
+
+ On the Panorama management server, the
+ Hostkey displayed as
+ undefined undefined if you
+ override an SSH Service Profile () Hostkey configured in a Template from the Template Stack.
+
+ |
+
|
+ PAN-213119
+ |
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you
+ view the Block IP list ():
+
+
+ show -> dis-block-table is unexpected
+
+ |
+
|
+ PAN-212978
+
+ This issue is now resolved. See PAN-OS 10.2.4-h3 Addressed Issues.
+
+ |
+
+
+ The Palo Alto Networks firewall stops responding when executing an
+ SD-WAN debug operational CLI command.
+
+ |
+
|
+ PAN-212889
+
+ This issue is now resolved. See
+ PAN-OS 10.2.14 Addressed Issues
+
+ |
+
+
+ On the Panorama management server, different threat names are used
+ when querying the same threat in the Threat Monitor () and ACC. This results in the ACC
+ displaying
+ no data to display when you are
+ redirected to the ACC after clicking a threat name in the Threat
+ Monitor and filtering the same threat name in the Global Filters.
+
+ |
+
|
+ PAN-212533
+ |
+
+
+ Modifying the Administrator Type for
+ an existing administrator (
+ or
+ ) from Superuser to a
+ Role-Based custom admin, or vice
+ versa, does not modify the access privileges of the administrator.
+
+ |
+
|
+ PAN-211531
+ |
+ + On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (). + | +
|
+ PAN-210366
+
+ This issue is now resolved. See PAN-OS 10.2.4-h3 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server in a high availability (HA)
+ configuration, the primary HA peer may enter a
+ primary-non-functional state and
+ generate a system log () with the following message:
+
+
+ High root partition usage: going to state Non-Functional
+
+ |
+
|
+ PAN-209288
+ |
+
+
+ Certificates are not successfully generated using SCEP ().
+
+ |
+
|
+ PAN-208622
+ |
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to
+ upload if you specify an Enterprise DLP data filtering profile (
+ with the Action set to Block to a
+ Security policy rule ().
+
+ |
+
|
+ PAN-208325
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues.
+
+ |
+
+
+ The following NextGen firewalls and Panorama management server models
+ are unable to automatically renew the device certificate (
+ or
+ ).
+
+
+ Workaround: Log in to the
+ firewall CLI
+ or
+ Panorama CLI
+ and fetch the device certificate.
+
+
+
+
+
+ |
+
|
+ PAN-208189
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ Traffic fails to match and reach all destinations if a Security policy
+ rule includes FQDN objects that resolve to two or more IP addresses.
+
+ |
+
|
+ PAN-207629
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, selective push fails to managed
+ firewalls if the managed firewalls are enabled with multiple vsys and
+ the Push Scope contains shared objects in device groups.
+
+ |
+
|
+ PAN-206253
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ For PA-3400 Series firewalls, the default log rate is set too low and
+ the max configurable log rate is incorrectly capped resulting in the
+ firewall not generating more than 6,826 logs per second.
+
+ |
+
|
+ PAN-206243
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ The PA-220 firewall reaches the maximum disk usage capacity multiple a
+ day that requires a disk cleanup. A critical system log () is generated each time the firewall reaches maximum disk usage
+ capacity.
+
+ |
+
|
+ PAN-206005
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ (PA-3400 Series firewalls only) The I7_misc
+ memory pool on this platform is undersized and can cause a loss of
+ connectivity when reaching the limit of the memory pool. Certain
+ features, like using a decryption profile with Strip ALPN disabled,
+ can lead to depleting the memory pool and causing a connection loss.
+
+
+ Workaround: Disable HTTP2 by enabling Strip ALPN
+ in the decryption profile or avoid usage of the I7_misc memory pool.
+
+ |
+
|
+ PAN-205187
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ ElasticSearch may not start properly when a newly installed Panorama
+ virtual appliance powers on for the first time, resulting in the
+ Panorama virtual appliance being unable to query logs forwarded from
+ the managed firewall to a Log Collector.
+
+
+ Workaround:
+ Log in to the Panorama CLI
+ and start the PAN-OS software.
+
+
+
+
+
+ |
+
|
+ PAN-204663
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, you are unable to Context Switch
+ from one managed firewall to another.
+
+
+ Workaround: After you Context Switch to a managed
+ firewall, you must first Context Switch back to Panorama before you
+ can continue to Context Switch to a different managed firewall.
+
+ |
+
|
+ PAN-201855
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, cloning any template () corrupts certificates () with the
+ Block Private Key Export setting
+ enabled across all templates. This results in managed firewalls
+ experiencing issues wherever the corrupted certificate is referenced.
+
+
+ For example, you have template A, B, and C where templates A and B
+ have certificates with the
+ Block Private Key Export setting
+ enabled. Cloning template C corrupts the certificates with
+ Block Private Key Export setting
+ enabled in templates A and B.
+
+
+ Workaround: After cloning a template, delete and
+ re-import the corrupted certificates.
+
+ |
+
|
+ PAN-199557
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues.
+
+ |
+
+
+ On M-600 appliances in an Active/Passive high availability (HA)
+ configuration, the
+ configd process restarts due to a
+ memory leak on the
+ Active Panorama HA peer. This
+ causes the Panorama web interface and CLI to become unresponsive.
+
+
+ Workaround: Manually reboot the
+ Active Panorama HA peer.
+
+ |
+
|
+ PAN-198708
+ |
+
+
+ On the Panorama management server, the
+ File Type field does not display
+ any data when you view the Detailed Log View in the Data Filtering log
+ ().
+
+ |
+
|
+ PAN-198174
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ When viewing traffic or threat logs from the firewall ACC or Monitor,
+ performing a reverse DNS lookup, for example, when resolving IP
+ addresses to domain names using the
+ Resolve Hostname feature, can cause
+ the appliance to crash and restart if DNS server settings have not
+ been configured.
+
+
+ Workaround: Provide a DNS server setting for the
+ firewall (). If you cannot reference a valid DNS server, you can add a dummy
+ address.
+
+ |
+
|
+ PAN-197097
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ Large Scale VPN (LSVPN) does not support IPv6 addresses on the
+ satellite firewall.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-196504
+ |
+ + License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). + | +
|
+ PAN-196146
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ The VM-Series firewall on Azure does not boot up with a hostname
+ (specified in an init-cgf.txt or user data) when bootstrapped.
+
+ |
+
|
+ PAN-195541
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ When a DNS request is submitted to the DNS Security service for
+ inspection, the dataplane pan-task process (all_pktproc) might fail
+ during the DNS request process, or when the dataplane cache is reset,
+ or if the cache output is generated through the CLI, resulting in
+ firewall crashes or the inability/reduced capability to process
+ network traffic.
+
+
+ The following CLI commands can trigger a crash of the all_pktproc
+ process:
+
+
|
+
|
+ PAN-194996
+ |
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma
+ Access 3.1.2 deployment, allocating bandwidth for a remote network
+ deployment fails (the OK button is grayed out).
+
+
+ Workaround: Retry the operation.
+
+ |
+
|
+ PAN-194519
+ |
+
+
+ (PA-5450 firewall only) Trying to configure a
+ custom payload format under
+
+ yields a Javascript error.
+
+ |
+
|
+ PAN-194515
+ |
+
+
+ (PA-5450 firewall only) The Panorama web
+ interface does not display any predefined template stack variables in
+ the dropdown menu under
+ .
+
+
+ Workaround: Configure the log interface IP address
+ on the individual firewall web interface instead of on Panorama.
+
+ |
+
|
+ PAN-194424
+ |
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS
+ 10.2.2 while having a log interface configured can cause both the log
+ interface and the management interface to remain connected to the log
+ collector.
+
+
+ Workaround: Restart the log receiver service by
+ running the following CLI command:
+
+
+
+
+
+ |
+
|
+ PAN-194202
+ |
+
+
+ (PA-5450 firewall only) If the management
+ interface and logging interface are configured on the same subnetwork,
+ the firewall conducts log forwarding using the management interface
+ instead of the logging interface.
+
+ |
+
|
+ PAN-190727
+ |
+
+
+ (PA-5450 firewall only) Documentation for
+ configuring the log interface is unavailable on the web interface and
+ in the PAN-OS Administrator’s Guide.
+
+ |
+
|
+ PAN-190435
+ |
+
+
+ When you Commit a configuration
+ change, the Task Manager commit
+ Status goes directly from
+ 0% to
+ Completed and does accurately
+ reflect the commit job progress.
+
+ |
+
|
+ PAN-189425
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server,
+ Export Panorama and devices config bundle
+ () fails to export. When the export fails, you are redirected to a new
+ window and the following error is displayed:
+
+
+ Failed to redirect error to /var/log/pan/appweb3-panmodule.log
+ (Permission denied)
+
+ |
+
|
+ PAN-189111
+ |
+
+
+ After deleting an MP pod and it comes up, the
+ show routing command output
+ appears empty and traffic stops working.
+
+ |
+
|
+ PAN-189076
+ |
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a
+ broadcast link and a designated router (DR) priority of 0 (zero) are
+ stuck in a two-way state after HA failover.
+
+
+ Workaround: Configure at least one OSPFv3 neighbor
+ with a non-zero priority setting in the same broadcast domain.
+
+ |
+
|
+ PAN-188904
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ Certain web pages and web page contents might not properly load when
+ cloud inline categorization is enabled on the firewall.
+
+ |
+
|
+ PAN-188358
+ |
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management
+ port LEDs do not light up when a 10G Ethernet cable is plugged in.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187643
+ |
+
+
+ If you enable SCTP security using a Panorama template when
+ SCTP INIT Flood Protection is
+ enabled in the Zone Protection profile using Panorama and you commit
+ all changes, the commit is successful but the
+ SCTP INIT option is not available in
+ the Zone Protection profile.
+
+
+ Workaround: Log out of the firewall and log in
+ again to make the SCIT INIT option
+ available on the web interface.
+
+ |
+
|
+ PAN-187612
+ |
+
+
+ On the Panorama management server, not all data profiles () are displayed after you:
+
+
+ Workaround: Log in to the Panorama CLI and reset
+ the DLP plugin.
+
+ admin > request plugins dlp reset
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-187370
+ |
+
+
+ On a firewall with Advanced Routing enabled, if there is also a
+ logical router instance that uses the default configuration and has no
+ interfaces assigned to it, this will result in terminating the
+ management daemon and main routing daemon in the firewall during
+ commit.
+
+
+ Workaround: Do not use a logical router instance
+ with no interfaces bound to it.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-186282
+ |
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match
+ criteria automatically when adding dynamic address groups.
+
+
+ Workaround: Reboot the Panorama HA pair.
+
+ |
+
|
+ PAN-186134
+ |
+
+
+ On the Panorama management server, performing a
+ Commit and Push (Commit > Commit and Push) may intermittently not push the committed configuration changes to
+ managed firewalls.
+
+
+ Workaround: Select
+ Commit > Push to Devices to push
+ the committed configuration changes to your managed firewalls.
+
+ |
+
|
+ PAN-185286
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ (PA-5400 Series firewalls only) On the Panorama
+ management server, the device health resources () do not populate.
+
+ |
+
|
+ PAN-184708
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
|
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-182734
+
+ This issue is now resolved. See
+ PAN-OS 10.2.5 Addressed Issues.
+
+ |
+
+
+ On an Advanced Routing Engine, if you change the IPSec tunnel
+ configuration, BGP flaps.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-181823
+ |
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer
+ port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports
+ on the firewall to go down if they are set to Auto.
+
+ |
+
|
+ PAN-180661
+ |
+
+
+ On the Panorama management server, pushing an unsupported Minimum
+ Password Complexity () to a managed firewall erroneously displays
+ commit time out as the reason the
+ commit failed.
+
+ |
+
|
+ PAN-180104
+ |
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2,
+ CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster
+ previously had a CN-Series as a DaemonSet deployment running PAN-OS
+ 10.0 or 10.1.
+
+
+ Workaround: Reboot the worker nodes before
+ upgrading to PAN-OS 10.2.
+
+ |
+
|
+ PAN-177455
+ |
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA
+ (High Availability) clustering enabled and using an HA4 communication
+ link. Attempting to load PAN-OS 10.2.0 on the firewall causes the
+ PA-7000 100G NPC to go offline. As a result, the firewall fails to
+ boot normally and enters maintenance mode. HA Pairs of Active-Passive
+ and Active-Active firewalls are not affected.
+
+ |
+
|
+ PAN-175915
+ |
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks
+ and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network
+ Protection Profile, the traffic logs do not display network slice SST
+ and SD values.
+
+ |
+
|
+ PAN-174982
+ |
+
+
+ In HA active/active configurations where, when interfaces that were
+ associated with a virtual router were deleted, the configuration
+ change did not sync.
+
+ |
+
|
+ PAN-172274
+ |
+
+
+ When you activate the advanced URL filtering license, your license
+ entitlements for PAN-DB and advanced URL filtering might not display
+ correctly on the firewall — this is a display anomaly, not a licensing
+ issue, and does not affect access to the services.
+
+
+ Workaround: Issue the following command to
+ retrieve and update the licenses:
+ license request fetch.
+
+ |
+
|
+ PAN-172132
+
+ This issue is now resolved by PAN-189643. See PAN-OS 10.2.4 Addressed Issues.
+
+ |
+
+
+ QoS fails to run on a tunnel interface (for example, tunnel.1).
+
+ |
+
|
+ PAN-171938
+ |
+
+
+ No results are displayed when you
+ Show Application Filter for a
+ Security policy rule ().
+
+ |
+
|
+ PAN-164885
+
+ This issue is now resolved. See PAN-OS 10.2.10 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, pushes to managed firewalls (
+ or Commit and Push) may fail when an
+ EDL () is configured to
+ Check for updates every 5 minutes
+ due to the commit and EDL fetch processes overlapping. This is more
+ likely to occur when multiple EDLs are configured to check for updates
+ every 5 minutes.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-5854
+ |
+
+
+ The WildFire analysis report on the firewall log viewer () does not display the following data fields: File Type, SHA-256,
+ MD-5, and File Size".
+
+
+ Workaround: Download and open the WildFire
+ analysis report in the PDF format using the link in the upper
+ right-hand corner of the
+ Detailed Log View.
+
+ |
+
|
+ WF500-5843
+ |
+
+
+ In a WildFire appliance cluster, issuing the
+ show cluster-all peers CLI command
+ when a node within the cluster is being rebooted generates the
+ following error:
+ Server error : An error occured.
+
+ |
+
|
+ WF500-5840
+ |
+
+
+ The sample analysis statistics that are returned when issuing the
+ show wildfire local statistics CLI
+ command in WildFire appliance cluster deployments may not accurately
+ reflect the number of samples that have been processed.
+
+ |
+
|
+ WF500-5823
+ |
+
+
+ The following WildFire appliance CLI command does not return a
+ signature generation status as expected:
+ show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance
+ from analyzing a sample.
+
+ |
+
|
+ WF500-5781
+ |
+
+
+ The WildFire appliance might erroneously generate and log the
+ following device certification error:
+ Device certificate is missing or invalid. It cannot be
+ renewed.
+
+ |
+
|
+ WF500-5754
+ |
+
+
+ In WildFire appliance clusters, issuing the
+ show cluster controller CLI command
+ generates an error when an IPv6 address is configured for the
+ management interface but not for the cluster interface.
+
+
+ Workaround: Ensure all WildFire appliance
+ interfaces that are enabled use matching protocols (all IPv4 or all
+ IPv6).
+
+ |
+
|
+ WF500-5632
+ |
+
+
+ The number of registered WildFire appliances reported in Panorama
+ () does not accurately reflect the current status of connected
+ WildFire appliances.
+
+ |
+
|
+ PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues.
+
+ |
+
+
+ A race condition may cause the dataplane to restart unexpectedly when
+ a zip decompression offload result is returned for a session that has
+ already closed. The session state is not validated before processing
+ the result because the offload result does not follow the fastpath
+ where these checks are normally performed.
+
+
+ Workaround: Disable zip hardware offloading (may
+ cause higher CPU usage).
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See PAN-OS 10.2.13-h18 Addressed Issuesand
+ PAN-OS 10.2.16-h6 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-297610
+ |
+
+
+ A firewall may become unresponsive after an upgrade due to the
+ fsck command scanning drive
+ partitions in parallel with the root partition, causing the process to
+ take an extended amount of time.
+
+ |
+
|
+ PAN-297295
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent
+ process restarts multiple times and exhausts its restart limit,
+ resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-295803
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-295255
+ |
+
+
+ Palo Alto Networks next-generation firewalls may experience service
+ disruptions due to all_task process
+ crashes when deployed in environments having non-uniform MTU and are
+ terminating IPSec tunnels.
+
+ |
+
|
+ PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues.
+
+ |
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM)
+ condition due to a memory leak and displays an error message. This
+ issue causes the device to crash and reboot unexpectedly.
+
+ |
+
|
+ PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues
+
+ |
+
+
+ A memory leak in the configd process
+ might lead to an active firewall to reboot due to an Out-of-Memory
+ (OOM) condition. This issue is observed when specific status commands,
+ such as
+ request log-collector forwarding status
+ are executed at high frequencies.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues
+
+ |
+
+
+ (Firewalls in HA configurations only) Routed
+ process may stop responding after changing MTU or any link parameters
+ when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-287871
+ |
+
+
+ When SSL Inbound Inspection is enabled and the firewall receives
+ fragmented Client Hello packets that include the TCP timestamp option,
+ the Client Hello message is forwarded to the destination server
+ without the timestamp option.
+
+ |
+
|
+ PAN-286231
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-284073
+ |
+
+
+ The firewall web interface becomes inaccessible and commits fail.
+
+ |
+
|
+ PAN-284067
+ |
+
+
+ A cumulative memory leak in the
+ devsrvr
+ process gets progressively worse whenever the CLI command
+ show running application statistics
+ is issued. This memory leak will gradually consume system memory and
+ produce an out-of-memory (OOM) condition, leading to an eventual
+ firewall reboot.
+
+
+ Workaround: Avoid using the CLI command:
+ show running application statistics.
+
+ |
+
|
+ PAN-281370
+ |
+
+
+ The Advanced WildFire Inline ML models
+ OOXML and
+ Mach-O erroneously display as being
+ available from the CLI; however, they are only available on PAN-OS
+ 11.1.3 and later releases.
+
+ |
+
|
+ PAN-273158
+ |
+
+
+ (PA-7000 Series firewalls only) Due to an
+ incorrect configuration on the ASIC, receiving a mix of jumbo and
+ non-jumbo packets may cause silent packet drops or application
+ slowness.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
| PAN-259769 | +
+
+ GlobalProtect portal is not accessible via a web browser and the app
+ displays the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-243951
+ |
+
+
+ On the Panorama management sever in an active/passive High
+ Availability (HA) configuration, managed devices () display as out-of-sync on the
+ passive HA peer when configuration changes are made to the SD-WAN
+ () configuration on the active HA peer.
+
+
+ Workaround: Manually synchronize the Panorama HA
+ peers.
+
+
|
+
|
+ PAN-234408
+ |
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for
+ ChatGPT from traffic forwarded to the DLP cloud service from an NGFW.
+
+ |
+
|
+ PAN-228273
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server in FIPS-CC mode, the ElasticSearch
+ cluster fails to come up and the
+ show log-collector-es-cluster health
+ command displays the status is
+ red. This results in log
+ ingestion issues for Panorama in Panorama only or Log Collector mode.
+
+ |
+
|
+ PAN-227344
+ |
+
+
+ On the Panorama management server, PDF Summary Reports () display no data and are blank when predefined reports are included
+ in the summary report.
+
+ |
+
|
+ PAN-227342
+ |
+
+
+ (PA-7000 Series firewalls only) In an
+ Active/Active High Availability (HA) setup, enabling hardware offload
+ can result in web traffic being blocked.
+
+ |
+
|
+ PAN-225337
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, the configuration push to a
+ multi-vsys firewall fails if you:
+
+
+ Workaround: Select
+
+ and edit the Panorama Settings to enable one of the following:
+
+
+ Alternatively, you can remove the duplicate address objects from the
+ device group configuration to allow only the
+ Shared objects in your
+ configuration.
+
+ |
+
|
+ PAN-223488
+
+ This issue is now resolved. See
+ PAN-OS 10.2.7 Addressed Issues.
+
+ |
+ + Closed ElasticSearch shards are not deleted from a Panorama M-Series or + virtual appliance. This causes the ElasticSearch shard purging to not + work as expected, resulting in high disk usage. + | +
|
+ PAN-223365
+ |
+
+
+ The Panorama management server is unable to query any logs if the
+ ElasticSearch health status for any Log Collector (
+ is degraded.
+
+
+ Workaround:
+ Log in to the Log Collector CLI
+ and restart ElasticSearch.
+
+
+
+
+
+ |
+
|
+ PAN-222586
+ |
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus,
+ Forward Methods, and Built-In Actions for Correlation Log settings
+ () are not displayed and cannot be configured.
+
+ |
+
|
+ PAN-222253
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, policy rulebase reordering when you
+ View Rulebase by Groups () does not persist if you reorder the policy rulebase by dragging and
+ dropping individual policy rules and then moving the entire tag group.
+
+ |
+
|
+ PAN-221775
+ |
+
+
+ A Malformed Request error is
+ displayed when you
+ Test Connection for an email server
+ profile () using SMTP over TLS and the
+ Password includes an ampersand
+ (&).
+
+ |
+
|
+ PAN-221015
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ On M-600 appliances in Panorama or Log Collector mode, the
+ es-1 and
+ es-2 ElasticSearch processes fail
+ to restart when the M-600 appliance is rebooted. The results in the
+ Managed Collector ES health
+ status () to be degraded.
+
+
+ Workaround:
+ Log in to the Panorama or Log Collector CLI
+ experiencing degraded ElasticSearch health and restart all
+ ElasticSearch processes.
+
+
+
+
+
+ |
+
|
+ PAN-220180
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ Configured botnet reports () are not generated.
+
+ |
+
|
+ PAN-219644
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ Firewalls forwarding logs to a syslog server over TLS () use the default Palo Alto Networks certificate instead of the
+ custom certificate configured on the firewall.
+
+ |
+
|
+ PAN-218521
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ The ElasticSearch process on the M-600 appliance in Log Collector mode
+ may enter a continuous reboot cycle. This results in the M-600
+ appliance becoming unresponsive, consuming logging disk space, and
+ preventing new log ingestion.
+
+ |
+
|
+ PAN-217307
+
+ This issue is now resolved. See PAN-OS 10.2.11 Addressed Issues.
+
+ |
+
+
+ The following Security policy rule () filters return no results:
+
+
+ log-start eq no
+
+ log-end eq no
+ log-end eq yes
+ |
+
|
+ PAN-216821
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues.
+
+ |
+
+
+ The reportd process crashes after
+ you successfully upgrade an M-200 appliance to PAN-OS 10.2.4.
+
+ |
+
|
+ PAN-215778
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues.
+
+ |
+
+
+ On the M-600 appliance in Management Only mode, XML API Get requests
+ for /config fail with the
+ following error due to exceeding the
+ total configuration size
+ supported on the M-600 appliance.
+
+
+
+
+
+ |
+
|
+ PAN-215082
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ M-300 and M-700 appliances may generate erroneous system logs () to alert that the M-Series appliance memory usage limits are
+ reached.
+
+ |
+
|
+ PAN-213746
+ |
+
+
+ On the Panorama management server, the
+ Hostkey displayed as
+ undefined undefined if you
+ override an SSH Service Profile () Hostkey configured in a Template from the Template Stack.
+
+ |
+
|
+ PAN-213119
+ |
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you
+ view the Block IP list ():
+
+
+ show -> dis-block-table is unexpected
+
+ |
+
|
+ PAN-212978
+
+ This issue is now resolved. See PAN-OS 10.2.4-h3 Addressed Issues.
+
+ |
+
+
+ The Palo Alto Networks firewall stops responding when executing an
+ SD-WAN debug operational CLI command.
+
+ |
+
|
+ PAN-212889
+
+ This issue is now resolved. See
+ PAN-OS 10.2.14 Addressed Issues
+
+ |
+
+
+ On the Panorama management server, different threat names are used
+ when querying the same threat in the Threat Monitor () and ACC. This results in the ACC
+ displaying
+ no data to display when you are
+ redirected to the ACC after clicking a threat name in the Threat
+ Monitor and filtering the same threat name in the Global Filters.
+
+ |
+
|
+ PAN-212533
+ |
+
+
+ Modifying the Administrator Type for
+ an existing administrator (
+ or
+ ) from Superuser to a
+ Role-Based custom admin, or vice
+ versa, does not modify the access privileges of the administrator.
+
+ |
+
|
+ PAN-211531
+ |
+ + On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (). + | +
|
+ PAN-210366
+
+ This issue is now resolved. See PAN-OS 10.2.4-h3 Addressed Issues
+
+ |
+
+
+ On the Panorama management server in a high availability (HA)
+ configuration, the primary HA peer may enter a
+ primary-non-functional state and
+ generate a system log () with the following message:
+
+
+ High root partition usage: going to state Non-Functional
+
+ |
+
|
+ PAN-209288
+ |
+
+
+ Certificates are not successfully generated using SCEP ().
+
+ |
+
|
+ PAN-208622
+ |
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to
+ upload if you specify an Enterprise DLP data filtering profile (
+ with the Action set to Block to a
+ Security policy rule ().
+
+ |
+
|
+ PAN-208325
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues.
+
+ |
+
+
+ The following NextGen firewalls and Panorama management server models
+ are unable to automatically renew the device certificate (
+ or
+ ).
+
+
+ Workaround: Log in to the
+ firewall CLI
+ or
+ Panorama CLI
+ and fetch the device certificate.
+
+
+
+
+
+ |
+
|
+ PAN-204689
+ |
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do
+ not work:
+
+
|
+
|
+ PAN-201855
+ |
+
+
+ On the Panorama management server, cloning any template () corrupts certificates () with the
+ Block Private Key Export setting
+ enabled across all templates. This results in managed firewalls
+ experiencing issues wherever the corrupted certificate is referenced.
+
+
+ For example, you have template A, B, and C where templates A and B
+ have certificates with the
+ Block Private Key Export setting
+ enabled. Cloning template C corrupts the certificates with
+ Block Private Key Export setting
+ enabled in templates A and B.
+
+
+ Workaround: After cloning a template, delete and
+ re-import the corrupted certificates.
+
+ |
+
|
+ PAN-199557
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues.
+
+ |
+
+
+ On M-600 appliances in an Active/Passive high availability (HA)
+ configuration, the
+ configd process restarts due to a
+ memory leak on the
+ Active Panorama HA peer. This
+ causes the Panorama web interface and CLI to become unresponsive.
+
+
+ Workaround: Manually reboot the
+ Active Panorama HA peer.
+
+ |
+
|
+ PAN-198708
+ |
+
+
+ On the Panorama management server, the
+ File Type field does not display
+ any data when you view the Detailed Log View in the Data Filtering log
+ ().
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-196504
+ |
+ + License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). + | +
|
+ PAN-196146
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ The VM-Series firewall on Azure does not boot up with a hostname
+ (specified in an init-cgf.txt or user data) when bootstrapped.
+
+ |
+
|
+ PAN-194996
+ |
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma
+ Access 3.1.2 deployment, allocating bandwidth for a remote network
+ deployment fails (the OK button is grayed out).
+
+
+ Workaround: Retry the operation.
+
+ |
+
|
+ PAN-194519
+ |
+
+
+ (PA-5450 firewall only) Trying to configure a
+ custom payload format under
+
+ yields a Javascript error.
+
+ |
+
|
+ PAN-194515
+ |
+
+
+ (PA-5450 firewall only) The Panorama web
+ interface does not display any predefined template stack variables in
+ the dropdown menu under
+ .
+
+
+ Workaround: Configure the log interface IP address
+ on the individual firewall web interface instead of on Panorama.
+
+ |
+
|
+ PAN-194424
+ |
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS
+ 10.2.2 while having a log interface configured can cause both the log
+ interface and the management interface to remain connected to the log
+ collector.
+
+
+ Workaround: Restart the log receiver service by
+ running the following CLI command:
+
+
+
+
+
+ |
+
|
+ PAN-194202
+ |
+
+
+ (PA-5450 firewall only) If the management
+ interface and logging interface are configured on the same subnetwork,
+ the firewall conducts log forwarding using the management interface
+ instead of the logging interface.
+
+ |
+
|
+ PAN-190727
+ |
+
+
+ (PA-5450 firewall only) Documentation for
+ configuring the log interface is unavailable on the web interface and
+ in the PAN-OS Administrator’s Guide.
+
+ |
+
|
+ PAN-190435
+ |
+
+
+ When you Commit a configuration
+ change, the Task Manager commit
+ Status goes directly from
+ 0% to
+ Completed and does accurately
+ reflect the commit job progress.
+
+ |
+
|
+ PAN-189111
+ |
+
+
+ After deleting an MP pod and it comes up, the
+ show routing command output
+ appears empty and traffic stops working.
+
+ |
+
|
+ PAN-189076
+ |
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a
+ broadcast link and a designated router (DR) priority of 0 (zero) are
+ stuck in a two-way state after HA failover.
+
+
+ Workaround: Configure at least one OSPFv3 neighbor
+ with a non-zero priority setting in the same broadcast domain.
+
+ |
+
|
+ PAN-188358
+ |
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management
+ port LEDs do not light up when a 10G Ethernet cable is plugged in.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187643
+ |
+
+
+ If you enable SCTP security using a Panorama template when
+ SCTP INIT Flood Protection is
+ enabled in the Zone Protection profile using Panorama and you commit
+ all changes, the commit is successful but the
+ SCTP INIT option is not available in
+ the Zone Protection profile.
+
+
+ Workaround: Log out of the firewall and log in
+ again to make the SCIT INIT option
+ available on the web interface.
+
+ |
+
|
+ PAN-187612
+ |
+
+
+ On the Panorama management server, not all data profiles () are displayed after you:
+
+
+ Workaround: Log in to the Panorama CLI and reset
+ the DLP plugin.
+
+ admin > request plugins dlp reset
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-187370
+ |
+
+
+ On a firewall with Advanced Routing enabled, if there is also a
+ logical router instance that uses the default configuration and has no
+ interfaces assigned to it, this will result in terminating the
+ management daemon and main routing daemon in the firewall during
+ commit.
+
+
+ Workaround: Do not use a logical router instance
+ with no interfaces bound to it.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-186282
+ |
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match
+ criteria automatically when adding dynamic address groups.
+
+
+ Workaround: Reboot the Panorama HA pair.
+
+ |
+
|
+ PAN-185286
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ (PA-5400 Series firewalls only) On the Panorama
+ management server, the device health resources () do not populate.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-182734
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues.
+
+ |
+
+
+ On an Advanced Routing Engine, if you change the IPSec tunnel
+ configuration, BGP flaps.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-181823
+ |
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer
+ port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports
+ on the firewall to go down if they are set to Auto.
+
+ |
+
|
+ PAN-180661
+ |
+
+
+ On the Panorama management server, pushing an unsupported Minimum
+ Password Complexity () to a managed firewall erroneously displays
+ commit time out as the reason the
+ commit failed.
+
+ |
+
|
+ PAN-180104
+ |
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2,
+ CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster
+ previously had a CN-Series as a DaemonSet deployment running PAN-OS
+ 10.0 or 10.1.
+
+
+ Workaround: Reboot the worker nodes before
+ upgrading to PAN-OS 10.2.
+
+ |
+
|
+ PAN-178194
+ |
+
+
+ A user interface issue in PAN-OS renders the contents of the
+ Inline ML tab in the
+ URL Filtering Profile inaccessible
+ on firewalls licensed for Advanced URL Filtering. Additionally, a
+ message indicating that a
+ License required for URL filtering to function
+ is unavailable displays at the bottom of the UI. These errors do not
+ affect the operation of Advanced URL Filtering or URL Filtering Inline
+ ML.
+
+
+ Workaround: Configuration settings for URL
+ Filtering Inline ML must be applied through the CLI. The following
+ configuration commands are available:
+
+
|
+
|
+ PAN-177455
+ |
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA
+ (High Availability) clustering enabled and using an HA4 communication
+ link. Attempting to load PAN-OS 10.2.0 on the firewall causes the
+ PA-7000 100G NPC to go offline. As a result, the firewall fails to
+ boot normally and enters maintenance mode. HA Pairs of Active-Passive
+ and Active-Active firewalls are not affected.
+
+ |
+
|
+ PAN-175915
+ |
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks
+ and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network
+ Protection Profile, the traffic logs do not display network slice SST
+ and SD values.
+
+ |
+
|
+ PAN-174982
+ |
+
+
+ In HA active/active configurations where, when interfaces that were
+ associated with a virtual router were deleted, the configuration
+ change did not sync.
+
+ |
+
|
+ PAN-172274
+ |
+
+
+ When you activate the advanced URL filtering license, your license
+ entitlements for PAN-DB and advanced URL filtering might not display
+ correctly on the firewall — this is a display anomaly, not a licensing
+ issue, and does not affect access to the services.
+
+
+ Workaround: Issue the following command to
+ retrieve and update the licenses:
+ license request fetch.
+
+ |
+
|
+ PAN-171938
+ |
+
+
+ No results are displayed when you
+ Show Application Filter for a
+ Security policy rule ().
+
+ |
+
|
+ PAN-164885
+
+ This issue is now resolved. See PAN-OS 10.2.10 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, pushes to managed firewalls (
+ or Commit and Push) may fail when an
+ EDL () is configured to
+ Check for updates every 5 minutes
+ due to the commit and EDL fetch processes overlapping. This is more
+ likely to occur when multiple EDLs are configured to check for updates
+ every 5 minutes.
+
+ |
+
|
+ PAN-160633
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues.
+
+ |
+
+
+ (PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls
+ only) The dataplane restarts repeatedly due to internal path monitoring
+ failures until a power cycle.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-5854
+ |
+
+
+ The WildFire analysis report on the firewall log viewer () does not display the following data fields: File Type, SHA-256,
+ MD-5, and File Size".
+
+
+ Workaround: Download and open the WildFire
+ analysis report in the PDF format using the link in the upper
+ right-hand corner of the
+ Detailed Log View.
+
+ |
+
|
+ WF500-5843
+ |
+
+
+ In a WildFire appliance cluster, issuing the
+ show cluster-all peers CLI command
+ when a node within the cluster is being rebooted generates the
+ following error:
+ Server error : An error occured.
+
+ |
+
|
+ WF500-5840
+ |
+
+
+ The sample analysis statistics that are returned when issuing the
+ show wildfire local statistics CLI
+ command in WildFire appliance cluster deployments may not accurately
+ reflect the number of samples that have been processed.
+
+ |
+
|
+ WF500-5823
+ |
+
+
+ The following WildFire appliance CLI command does not return a
+ signature generation status as expected:
+ show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance
+ from analyzing a sample.
+
+ |
+
|
+ WF500-5781
+ |
+
+
+ The WildFire appliance might erroneously generate and log the
+ following device certification error:
+ Device certificate is missing or invalid. It cannot be
+ renewed.
+
+ |
+
|
+ WF500-5754
+ |
+
+
+ In WildFire appliance clusters, issuing the
+ show cluster controller CLI command
+ generates an error when an IPv6 address is configured for the
+ management interface but not for the cluster interface.
+
+
+ Workaround: Ensure all WildFire appliance
+ interfaces that are enabled use matching protocols (all IPv4 or all
+ IPv6).
+
+ |
+
|
+ WF500-5632
+ |
+
+
+ The number of registered WildFire appliances reported in Panorama
+ () does not accurately reflect the current status of connected
+ WildFire appliances.
+
+ |
+
|
+ PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues.
+
+ |
+
+
+ A race condition may cause the dataplane to restart unexpectedly when
+ a zip decompression offload result is returned for a session that has
+ already closed. The session state is not validated before processing
+ the result because the offload result does not follow the fastpath
+ where these checks are normally performed.
+
+
+ Workaround: Disable zip hardware offloading (may
+ cause higher CPU usage).
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See PAN-OS 10.2.13-h18 Addressed Issuesand
+ PAN-OS 10.2.16-h6 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-297610
+ |
+
+
+ A firewall may become unresponsive after an upgrade due to the
+ fsck command scanning drive
+ partitions in parallel with the root partition, causing the process to
+ take an extended amount of time.
+
+ |
+
|
+ PAN-297295
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent
+ process restarts multiple times and exhausts its restart limit,
+ resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-295803
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-295255
+ |
+
+
+ Palo Alto Networks next-generation firewalls may experience service
+ disruptions due to all_task process
+ crashes when deployed in environments having non-uniform MTU and are
+ terminating IPSec tunnels.
+
+ |
+
|
+ PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues.
+
+ |
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM)
+ condition due to a memory leak and displays an error message. This
+ issue causes the device to crash and reboot unexpectedly.
+
+ |
+
|
+ PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues
+
+ |
+
+
+ A memory leak in the configd process
+ might lead to an active firewall to reboot due to an Out-of-Memory
+ (OOM) condition. This issue is observed when specific status commands,
+ such as
+ request log-collector forwarding status
+ are executed at high frequencies.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues
+
+ |
+
+
+ (Firewalls in HA configurations only) Routed
+ process may stop responding after changing MTU or any link parameters
+ when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-286231
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-284073
+ |
+
+
+ The firewall web interface becomes inaccessible and commits fail.
+
+ |
+
|
+ PAN-284067
+ |
+
+
+ A cumulative memory leak in the
+ devsrvr
+ process gets progressively worse whenever the CLI command
+ show running application statistics
+ is issued. This memory leak will gradually consume system memory and
+ produce an out-of-memory (OOM) condition, leading to an eventual
+ firewall reboot.
+
+
+ Workaround: Avoid using the CLI command:
+ show running application statistics.
+
+ |
+
|
+ PAN-281370
+ |
+
+
+ The Advanced WildFire Inline ML models
+ OOXML and
+ Mach-O erroneously display as being
+ available from the CLI; however, they are only available on PAN-OS
+ 11.1.3 and later releases.
+
+ |
+
|
+ PAN-273158
+ |
+
+
+ (PA-7000 Series firewalls only) Due to an
+ incorrect configuration on the ASIC, receiving a mix of jumbo and
+ non-jumbo packets may cause silent packet drops or application
+ slowness.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
| PAN-259769 | +
+
+ GlobalProtect portal is not accessible via a web browser and the app
+ displays the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-243951
+ |
+
+
+ On the Panorama management sever in an active/passive High
+ Availability (HA) configuration, managed devices () display as out-of-sync on the
+ passive HA peer when configuration changes are made to the SD-WAN
+ () configuration on the active HA peer.
+
+
+ Workaround: Manually synchronize the Panorama HA
+ peers.
+
+
|
+
|
+ PAN-237106
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-234408
+ |
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for
+ ChatGPT from traffic forwarded to the DLP cloud service from an NGFW.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-228273
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server in FIPS-CC mode, the ElasticSearch
+ cluster fails to come up and the
+ show log-collector-es-cluster health
+ command displays the status is
+ red. This results in log
+ ingestion issues for Panorama in Panorama only or Log Collector mode.
+
+ |
+
|
+ PAN-227344
+ |
+
+
+ On the Panorama management server, PDF Summary Reports () display no data and are blank when predefined reports are included
+ in the summary report.
+
+ |
+
|
+ PAN-225337
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, the configuration push to a
+ multi-vsys firewall fails if you:
+
+
+ Workaround: Select
+
+ and edit the Panorama Settings to enable one of the following:
+
+
+ Alternatively, you can remove the duplicate address objects from the
+ device group configuration to allow only the
+ Shared objects in your
+ configuration.
+
+ |
+
|
+ PAN-227368
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ The GlobalProtect app cannot connect to a portal or gateway and
+ GlobalProtect Clientless VPN users cannot access applications if
+ authentication takes longer than 20 seconds.
+
+
+ Workaround: Increase the TCP handshake timeout to
+ the maximum value of 60 seconds.
+
+ |
+
|
+ PAN-229865
+
+ This issue is now resolved. See PAN-OS 10.2.6 Addressed Issues.
+
+ |
+
+
+ Upgrading a PA-220 firewall running a PAN-OS 10.1 release fails when
+ the target PAN-OS upgrade version is PAN-OS 10.2.5.
+
+
+ Workaround: On your upgrade path to PAN-OS 10.2.5,
+ first upgrade to PAN-OS 10.2.4 and then upgrade to PAN-OS 10.2.5.
+
+ |
+
|
+ PAN-226768
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ When the GlobalProtect app is installed on iOS endpoints and the
+ gateway is configured to accept cookies, the app stays in
+ Connecting stage after
+ authentication and the GlobalProtect log displays the error message,
+ User is not in allow list. This
+ happens when the app is restarted or when the app tries to reconnect
+ after disconnection.
+
+ |
+
|
+ PAN-223677
+ |
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, and PA-5430
+ firewalls) By enabling
+ Lockless QoS
+ feature, a slight degradation in App-ID and Threat performance is
+ expected.
+
+ |
+
|
+ PAN-223488
+
+ This issue is now resolved. See
+ PAN-OS 10.2.7 Addressed Issues.
+
+ |
+ + Closed ElasticSearch shards are not deleted from a Panorama M-Series or + virtual appliance. This causes the ElasticSearch shard purging to not + work as expected, resulting in high disk usage. + | +
|
+ PAN-223457
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ If the number of group queries exceeds the Okta rate limit threshold,
+ the firewall clears the cache for the groups. To avoid encountering
+ this issue, disable the Okta rate limit.
+
+ |
+
|
+ PAN-223365
+ |
+
+
+ The Panorama management server is unable to query any logs if the
+ ElasticSearch health status for any Log Collector (
+ is degraded.
+
+
+ Workaround:
+ Log in to the Log Collector CLI
+ and restart ElasticSearch.
+
+
+
+
+
+ |
+
|
+ PAN-222586
+ |
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus,
+ Forward Methods, and Built-In Actions for Correlation Log settings
+ () are not displayed and cannot be configured.
+
+ |
+
|
+ PAN-222418
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ The firewall intermittently records a reconnection message to the
+ authentication server as a error, even if no disconnection occurs.
+
+ |
+
|
+ PAN-222253
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, policy rulebase reordering when you
+ View Rulebase by Groups () does not persist if you reorder the policy rulebase by dragging and
+ dropping individual policy rules and then moving the entire tag group.
+
+ |
+
|
+ PAN-221775
+ |
+
+
+ A Malformed Request error is
+ displayed when you
+ Test Connection for an email server
+ profile () using SMTP over TLS and the
+ Password includes an ampersand
+ (&).
+
+ |
+
|
+ PAN-221857
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ Users are unable to log in to the GlobalProtect app using SAML
+ authentication after the app is upgraded to 10.2.3-h4 and the
+ GlobalProtect logs display the following error message:
+ Username from SAML SSO response is different from the input..
+
+ |
+
|
+ PAN-221126
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ Email server profiles (
+ and
+ ) to forward logs as email notifications are not forwarded in a
+ readable format.
+
+
+ Workaround: Use a
+ Custom Log Format to forward logs as
+ email notifications in a readable format.
+
+ |
+
|
+ PAN-221015
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ On M-600 appliances in Panorama or Log Collector mode, the
+ es-1 and
+ es-2 ElasticSearch processes fail
+ to restart when the M-600 appliance is rebooted. The results in the
+ Managed Collector ES health
+ status () to be degraded.
+
+
+ Workaround:
+ Log in to the Panorama or Log Collector CLI
+ experiencing degraded ElasticSearch health and restart all
+ ElasticSearch processes.
+
+
+
+
+
+ |
+
|
+ PAN-220180
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ Configured botnet reports () are not generated.
+
+ |
+
|
+ PAN-219644
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ Firewalls forwarding logs to a syslog server over TLS () use the default Palo Alto Networks certificate instead of the
+ custom certificate configured on the firewall.
+
+ |
+
|
+ PAN-218521
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ The ElasticSearch process on the M-600 appliance in Log Collector mode
+ may enter a continuous reboot cycle. This results in the M-600
+ appliance becoming unresponsive, consuming logging disk space, and
+ preventing new log ingestion.
+
+ |
+
|
+ PAN-217307
+
+ This issue is now resolved. See PAN-OS 10.2.11 Addressed Issues.
+
+ |
+
+
+ The following Security policy rule () filters return no results:
+
+
+ log-start eq no
+
+ log-end eq no
+ log-end eq yes
+ |
+
|
+ PAN-216214
+ |
+
+
+ For Panorama-managed firewalls in an Active/Active High Availability
+ (HA) configuration where you configure the firewall HA settings () in a template or template stack (), performing a local commit on one of the HA firewalls triggers an
+ HA config sync on the peer firewall. This causes the HA peer
+ configuration to go Out of Sync.
+
+ |
+
|
+ PAN-215082
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ M-300 and M-700 appliances may generate erroneous system logs () to alert that the M-Series appliance memory usage limits are
+ reached.
+
+ |
+
|
+ PAN-213746
+ |
+
+
+ On the Panorama management server, the
+ Hostkey displayed as
+ undefined undefined if you
+ override an SSH Service Profile () Hostkey configured in a Template from the Template Stack.
+
+ |
+
|
+ PAN-213119
+ |
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you
+ view the Block IP list ():
+
+
+ show -> dis-block-table is unexpected
+
+ |
+
|
+ PAN-212889
+
+ This issue is now resolved. See
+ PAN-OS 10.2.14 Addressed Issues
+
+ |
+
+
+ On the Panorama management server, different threat names are used
+ when querying the same threat in the Threat Monitor () and ACC. This results in the ACC
+ displaying
+ no data to display when you are
+ redirected to the ACC after clicking a threat name in the Threat
+ Monitor and filtering the same threat name in the Global Filters.
+
+ |
+
|
+ PAN-212533
+ |
+
+
+ Modifying the Administrator Type for
+ an existing administrator (
+ or
+ ) from Superuser to a
+ Role-Based custom admin, or vice
+ versa, does not modify the access privileges of the administrator.
+
+ |
+
|
+ PAN-211531
+ |
+ + On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (). + | +
|
+ PAN-209288
+ |
+
+
+ Certificates are not successfully generated using SCEP ().
+
+ |
+
|
+ PAN-208622
+ |
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to
+ upload if you specify an Enterprise DLP data filtering profile (
+ with the Action set to Block to a
+ Security policy rule ().
+
+ |
+
|
+ PAN-204689
+ |
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do
+ not work:
+
+
|
+
|
+ PAN-198708
+ |
+
+
+ On the Panorama management server, the
+ File Type field does not display
+ any data when you view the Detailed Log View in the Data Filtering log
+ ().
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-196504
+ |
+ + License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). + | +
|
+ PAN-196146
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ The VM-Series firewall on Azure does not boot up with a hostname
+ (specified in an init-cgf.txt or user data) when bootstrapped.
+
+ |
+
|
+ PAN-194996
+ |
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma
+ Access 3.1.2 deployment, allocating bandwidth for a remote network
+ deployment fails (the OK button is grayed out).
+
+
+ Workaround: Retry the operation.
+
+ |
+
|
+ PAN-194519
+ |
+
+
+ (PA-5450 firewall only) Trying to configure a
+ custom payload format under
+
+ yields a Javascript error.
+
+ |
+
|
+ PAN-194515
+ |
+
+
+ (PA-5450 firewall only) The Panorama web
+ interface does not display any predefined template stack variables in
+ the dropdown menu under
+ .
+
+
+ Workaround: Configure the log interface IP address
+ on the individual firewall web interface instead of on Panorama.
+
+ |
+
|
+ PAN-194424
+ |
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS
+ 10.2.2 while having a log interface configured can cause both the log
+ interface and the management interface to remain connected to the log
+ collector.
+
+
+ Workaround: Restart the log receiver service by
+ running the following CLI command:
+
+
+
+
+
+ |
+
|
+ PAN-194202
+ |
+
+
+ (PA-5450 firewall only) If the management
+ interface and logging interface are configured on the same subnetwork,
+ the firewall conducts log forwarding using the management interface
+ instead of the logging interface.
+
+ |
+
|
+ PAN-193004
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ The Panorama management server fails to delete old IP Tag data. This
+ causes the /opt/pancfg partition
+ to reach maximum capacity which impacts Panorama performance.
+
+ |
+
|
+ PAN-190727
+ |
+
+
+ (PA-5450 firewall only) Documentation for
+ configuring the log interface is unavailable on the web interface and
+ in the PAN-OS Administrator’s Guide.
+
+ |
+
|
+ PAN-189111
+ |
+
+
+ After deleting an MP pod and it comes up, the
+ show routing command output
+ appears empty and traffic stops working.
+
+ |
+
|
+ PAN-189076
+ |
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a
+ broadcast link and a designated router (DR) priority of 0 (zero) are
+ stuck in a two-way state after HA failover.
+
+
+ Workaround: Configure at least one OSPFv3 neighbor
+ with a non-zero priority setting in the same broadcast domain
+
+ |
+
|
+ PAN-188358
+ |
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management
+ port LEDs do not light up when a 10G Ethernet cable is plugged in.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187643
+ |
+
+
+ If you enable SCTP security using a Panorama template when
+ SCTP INIT Flood Protection is
+ enabled in the Zone Protection profile using Panorama and you commit
+ all changes, the commit is successful but the
+ SCTP INIT option is not available in
+ the Zone Protection profile.
+
+
+ Workaround: Log out of the firewall and log in
+ again to make the SCIT INIT option
+ available on the web interface.
+
+ |
+
|
+ PAN-187612
+ |
+
+
+ On the Panorama management server, not all data profiles () are displayed after you:
+
+
+ Workaround: Log in to the Panorama CLI and reset
+ the DLP plugin.
+
+ admin > request plugins dlp reset
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-187370
+ |
+
+
+ On a firewall with Advanced Routing enabled, if there is also a
+ logical router instance that uses the default configuration and has no
+ interfaces assigned to it, this will result in terminating the
+ management daemon and main routing daemon in the firewall during
+ commit.
+
+
+ Workaround: Do not use a logical router instance
+ with no interfaces bound to it.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-186282
+ |
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match
+ criteria automatically when adding dynamic address groups.
+
+
+ Workaround: Reboot the Panorama HA pair.
+
+ |
+
|
+ PAN-185286
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ (PA-5400 Series firewalls only) On the Panorama
+ management server, the device health resources () do not populate.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-181823
+ |
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer
+ port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports
+ on the firewall to go down if they are set to Auto.
+
+ |
+
|
+ PAN-180661
+ |
+
+
+ On the Panorama management server, pushing an unsupported Minimum
+ Password Complexity () to a managed firewall erroneously displays
+ commit time out as the reason the
+ commit failed.
+
+ |
+
|
+ PAN-180104
+ |
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2,
+ CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster
+ previously had a CN-Series as a DaemonSet deployment running PAN-OS
+ 10.0 or 10.1.
+
+
+ Workaround: Reboot the worker nodes before
+ upgrading to PAN-OS 10.2.
+
+ |
+
|
+ PAN-178194
+ |
+
+
+ A user interface issue in PAN-OS renders the contents of the
+ Inline ML tab in the
+ URL Filtering Profile inaccessible
+ on firewalls licensed for Advanced URL Filtering. Additionally, a
+ message indicating that a
+ License required for URL filtering to function
+ is unavailable displays at the bottom of the UI. These errors do not
+ affect the operation of Advanced URL Filtering or URL Filtering Inline
+ ML.
+
+
+ Workaround: Configuration settings for URL
+ Filtering Inline ML must be applied through the CLI. The following
+ configuration commands are available:
+
+
|
+
|
+ PAN-177455
+ |
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA
+ (High Availability) clustering enabled and using an HA4 communication
+ link. Attempting to load PAN-OS 10.2.0 on the firewall causes the
+ PA-7000 100G NPC to go offline. As a result, the firewall fails to
+ boot normally and enters maintenance mode. HA Pairs of Active-Passive
+ and Active-Active firewalls are not affected.
+
+ |
+
|
+ PAN-175915
+ |
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks
+ and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network
+ Protection Profile, the traffic logs do not display network slice SST
+ and SD values.
+
+ |
+
|
+ PAN-174982
+ |
+
+
+ In HA active/active configurations where, when interfaces that were
+ associated with a virtual router were deleted, the configuration
+ change did not sync.
+
+ |
+
|
+ PAN-172274
+ |
+
+
+ When you activate the advanced URL filtering license, your license
+ entitlements for PAN-DB and advanced URL filtering might not display
+ correctly on the firewall — this is a display anomaly, not a licensing
+ issue, and does not affect access to the services.
+
+
+ Workaround: Issue the following command to
+ retrieve and update the licenses:
+ license request fetch.
+
+ |
+
|
+ PAN-171938
+ |
+
+
+ No results are displayed when you
+ Show Application Filter for a
+ Security policy rule ().
+
+ |
+
|
+ PAN-164885
+
+ This issue is now resolved. See PAN-OS 10.2.10 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, pushes to managed firewalls (
+ or Commit and Push) may fail when an
+ EDL () is configured to
+ Check for updates every 5 minutes
+ due to the commit and EDL fetch processes overlapping. This is more
+ likely to occur when multiple EDLs are configured to check for updates
+ every 5 minutes.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-5854
+ |
+
+
+ The WildFire analysis report on the firewall log viewer () does not display the following data fields: File Type, SHA-256,
+ MD-5, and File Size".
+
+
+ Workaround: Download and open the WildFire
+ analysis report in the PDF format using the link in the upper
+ right-hand corner of the
+ Detailed Log View.
+
+ |
+
|
+ WF500-5843
+ |
+
+
+ In a WildFire appliance cluster, issuing the
+ show cluster-all peers CLI command
+ when a node within the cluster is being rebooted generates the
+ following error:
+ Server error : An error occured.
+
+ |
+
|
+ WF500-5840
+ |
+
+
+ The sample analysis statistics that are returned when issuing the
+ show wildfire local statistics CLI
+ command in WildFire appliance cluster deployments may not accurately
+ reflect the number of samples that have been processed.
+
+ |
+
|
+ WF500-5823
+ |
+
+
+ The following WildFire appliance CLI command does not return a
+ signature generation status as expected:
+ show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance
+ from analyzing a sample.
+
+ |
+
|
+ WF500-5781
+ |
+
+
+ The WildFire appliance might erroneously generate and log the
+ following device certification error:
+ Device certificate is missing or invalid. It cannot be
+ renewed.
+
+ |
+
|
+ WF500-5754
+ |
+
+
+ In WildFire appliance clusters, issuing the
+ show cluster controller CLI command
+ generates an error when an IPv6 address is configured for the
+ management interface but not for the cluster interface.
+
+
+ Workaround: Ensure all WildFire appliance
+ interfaces that are enabled use matching protocols (all IPv4 or all
+ IPv6).
+
+ |
+
|
+ WF500-5632
+ |
+
+
+ The number of registered WildFire appliances reported in Panorama
+ () does not accurately reflect the current status of connected
+ WildFire appliances.
+
+ |
+
|
+ PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues.
+
+ |
+
+
+ A race condition may cause the dataplane to restart unexpectedly when
+ a zip decompression offload result is returned for a session that has
+ already closed. The session state is not validated before processing
+ the result because the offload result does not follow the fastpath
+ where these checks are normally performed.
+
+
+ Workaround: Disable zip hardware offloading (may
+ cause higher CPU usage).
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See PAN-OS 10.2.13-h18 Addressed Issuesand
+ PAN-OS 10.2.16-h6 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-297610
+ |
+
+
+ A firewall may become unresponsive after an upgrade due to the
+ fsck command scanning drive
+ partitions in parallel with the root partition, causing the process to
+ take an extended amount of time.
+
+ |
+
|
+ PAN-297295
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent
+ process restarts multiple times and exhausts its restart limit,
+ resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-295803
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-295255
+ |
+
+
+ Palo Alto Networks next-generation firewalls may experience service
+ disruptions due to all_task process
+ crashes when deployed in environments having non-uniform MTU and are
+ terminating IPSec tunnels.
+
+ |
+
|
+ PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues.
+
+ |
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM)
+ condition due to a memory leak and displays an error message. This
+ issue causes the device to crash and reboot unexpectedly.
+
+ |
+
|
+ PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues
+
+ |
+
+
+ A memory leak in the configd process
+ might lead to an active firewall to reboot due to an Out-of-Memory
+ (OOM) condition. This issue is observed when specific status commands,
+ such as
+ request log-collector forwarding status
+ are executed at high frequencies.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues
+
+ |
+
+
+ (Firewalls in HA configurations only) Routed
+ process may stop responding after changing MTU or any link parameters
+ when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-286231
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-284073
+ |
+
+
+ The firewall web interface becomes inaccessible and commits fail.
+
+ |
+
|
+ PAN-284067
+ |
+
+
+ A cumulative memory leak in the
+ devsrvr
+ process gets progressively worse whenever the CLI command
+ show running application statistics
+ is issued. This memory leak will gradually consume system memory and
+ produce an out-of-memory (OOM) condition, leading to an eventual
+ firewall reboot.
+
+
+ Workaround: Avoid using the CLI command:
+ show running application statistics.
+
+ |
+
|
+ PAN-281370
+ |
+
+
+ The Advanced WildFire Inline ML models
+ OOXML and
+ Mach-O erroneously display as being
+ available from the CLI; however, they are only available on PAN-OS
+ 11.1.3 and later releases.
+
+ |
+
|
+ PAN-273158
+ |
+
+
+ (PA-7000 Series firewalls only) Due to an
+ incorrect configuration on the ASIC, receiving a mix of jumbo and
+ non-jumbo packets may cause silent packet drops or application
+ slowness.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
| PAN-259769 | +
+
+ GlobalProtect portal is not accessible via a web browser and the app
+ displays the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-244648
+ |
+
+
+ (PA-5200 Series firewalls only) After a factory
+ reset, the firewall may get stuck in maintenance mode and be unable to
+ load the boot image. The firewall fails to enable FIPS-CC mode during
+ this time.
+
+
+ Workaround: The following workaround allows the
+ firewall to boot in normal mode but does not apply to FIPS-CC mode.
+ Attempting to enable FIPS-CC mode after using this workaround will
+ cause the firewall to reboot and re-enter maintenace mode.
+
+
|
+
|
+ PAN-243951
+ |
+
+
+ On the Panorama management sever in an active/passive High
+ Availability (HA) configuration, managed devices () display as out-of-sync on the
+ passive HA peer when configuration changes are made to the SD-WAN
+ () configuration on the active HA peer.
+
+
+ Workaround: Manually synchronize the Panorama HA
+ peers.
+
+
|
+
|
+ PAN-237106
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-234408
+ |
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for
+ ChatGPT from traffic forwarded to the DLP cloud service from an NGFW.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-234929
+
+ This issue is now resolved. See PAN-OS 10.2.7-h3 Addressed Issues.
+
+ |
+
+
+ The tabs in the ACC, such as
+ Network Activity,
+ Threat Activity, and
+ Blocked Activity, may not display
+ any data when you apply a Time filter for the Last 15 minutes, Last
+ Hour, Last 6 Hours, or Last 12 Hours. With the Last 24 Hours filter,
+ the data displayed may not be accurate. Additionally, reports run
+ against summary logs may not display accurate results.
+
+ |
+
|
+ PAN-228515
+ |
+
+
+ The EleasticSearch SSH flaps on the M-600 appliance in Panorama or Log
+ Collector mode. This causes logs to not display on the Panorama
+ management server () and the Log Collector health status () to display as degraded.
+
+ |
+
|
+ PAN-228273
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server in FIPS-CC mode, the ElasticSearch
+ cluster fails to come up and the
+ show log-collector-es-cluster health
+ command displays the status is
+ red. This results in log
+ ingestion issues for Panorama in Panorama only or Log Collector mode.
+
+ |
+
|
+ PAN-227344
+ |
+
+
+ On the Panorama management server, PDF Summary Reports () display no data and are blank when predefined reports are included
+ in the summary report.
+
+ |
+
|
+ PAN-225337
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, the configuration push to a
+ multi-vsys firewall fails if you:
+
+
+ Workaround: Select
+
+ and edit the Panorama Settings to enable one of the following:
+
+
+ Alternatively, you can remove the duplicate address objects from the
+ device group configuration to allow only the
+ Shared objects in your
+ configuration.
+
+ |
+
|
+ PAN-223365
+ |
+
+
+ The Panorama management server is unable to query any logs if the
+ ElasticSearch health status for any Log Collector (
+ is degraded.
+
+
+ Workaround:
+ Log in to the Log Collector CLI
+ and restart ElasticSearch.
+
+
+
+
+
+ |
+
|
+ PAN-227368
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ The GlobalProtect app cannot connect to a portal or gateway and
+ GlobalProtect Clientless VPN users cannot access applications if
+ authentication takes longer than 20 seconds.
+
+
+ Workaround: Increase the TCP handshake timeout to
+ the maximum value of 60 seconds.
+
+ |
+
|
+ PAN-226768
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ When the GlobalProtect app is installed on iOS endpoints and the
+ gateway is configured to accept cookies, the app stays in
+ Connecting stage after
+ authentication and the GlobalProtect log displays the error message,
+ User is not in allow list. This
+ happens when the app is restarted or when the app tries to reconnect
+ after disconnection.
+
+ |
+
|
+ PAN-223677
+ |
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, and PA-5430
+ firewalls) By enabling
+ Lockless QoS
+ feature, a slight degradation in App-ID and Threat performance is
+ expected.
+
+ |
+
|
+ PAN-223488
+
+ This issue is now resolved. See
+ PAN-OS 10.2.7 Addressed Issues.
+
+ |
+ + Closed ElasticSearch shards are not deleted from a Panorama M-Series or + virtual appliance. This causes the ElasticSearch shard purging to not + work as expected, resulting in high disk usage. + | +
|
+ PAN-223457
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ If the number of group queries exceeds the Okta rate limit threshold,
+ the firewall clears the cache for the groups. To avoid encountering
+ this issue, disable the Okta rate limit.
+
+ |
+
|
+ PAN-222586
+ |
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus,
+ Forward Methods, and Built-In Actions for Correlation Log settings
+ () are not displayed and cannot be configured.
+
+ |
+
|
+ PAN-222418
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ The firewall intermittently records a reconnection message to the
+ authentication server as a error, even if no disconnection occurs.
+
+ |
+
|
+ PAN-222253
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, policy rulebase reordering when you
+ View Rulebase by Groups () does not persist if you reorder the policy rulebase by dragging and
+ dropping individual policy rules and then moving the entire tag group.
+
+ |
+
|
+ PAN-221775
+ |
+
+
+ A Malformed Request error is
+ displayed when you
+ Test Connection for an email server
+ profile () using SMTP over TLS and the
+ Password includes an ampersand
+ (&).
+
+ |
+
|
+ PAN-221857
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ Users are unable to log in to the GlobalProtect app using SAML
+ authentication after the app is upgraded to 10.2.3-h4 and the
+ GlobalProtect logs display the following error message:
+ Username from SAML SSO response is different from the input..
+
+ |
+
|
+ PAN-221126
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ Email server profiles (
+ and
+ ) to forward logs as email notifications are not forwarded in a
+ readable format.
+
+
+ Workaround: Use a
+ Custom Log Format to forward logs as
+ email notifications in a readable format.
+
+ |
+
|
+ PAN-221015
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ On M-600 appliances in Panorama or Log Collector mode, the
+ es-1 and
+ es-2 ElasticSearch processes fail
+ to restart when the M-600 appliance is rebooted. The results in the
+ Managed Collector ES health
+ status () to be degraded.
+
+
+ Workaround:
+ Log in to the Panorama or Log Collector CLI
+ experiencing degraded ElasticSearch health and restart all
+ ElasticSearch processes.
+
+
+
+
+
+ |
+
|
+ PAN-220180
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ Configured botnet reports () are not generated.
+
+ |
+
|
+ PAN-219644
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ Firewalls forwarding logs to a syslog server over TLS () use the default Palo Alto Networks certificate instead of the
+ custom certificate configured on the firewall.
+
+ |
+
|
+ PAN-218521
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ The ElasticSearch process on the M-600 appliance in Log Collector mode
+ may enter a continuous reboot cycle. This results in the M-600
+ appliance becoming unresponsive, consuming logging disk space, and
+ preventing new log ingestion.
+
+ |
+
|
+ PAN-217307
+
+ This issue is now resolved. See PAN-OS 10.2.11 Addressed Issues.
+
+ |
+
+
+ The following Security policy rule () filters return no results:
+
+
+ log-start eq no
+
+ log-end eq no
+ log-end eq yes
+ |
+
|
+ PAN-215082
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ M-300 and M-700 appliances may generate erroneous system logs () to alert that the M-Series appliance memory usage limits are
+ reached.
+
+ |
+
|
+ PAN-213746
+ |
+
+
+ On the Panorama management server, the
+ Hostkey displayed as
+ undefined undefined if you
+ override an SSH Service Profile () Hostkey configured in a Template from the Template Stack.
+
+ |
+
|
+ PAN-213119
+ |
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you
+ view the Block IP list ():
+
+
+ show -> dis-block-table is unexpected
+
+ |
+
|
+ PAN-212889
+
+ This issue is now resolved. See
+ PAN-OS 10.2.14 Addressed Issues
+
+ |
+
+
+ On the Panorama management server, different threat names are used
+ when querying the same threat in the Threat Monitor () and ACC. This results in the ACC
+ displaying
+ no data to display when you are
+ redirected to the ACC after clicking a threat name in the Threat
+ Monitor and filtering the same threat name in the Global Filters.
+
+ |
+
|
+ PAN-212533
+ |
+
+
+ Modifying the Administrator Type for
+ an existing administrator (
+ or
+ ) from Superuser to a
+ Role-Based custom admin, or vice
+ versa, does not modify the access privileges of the administrator.
+
+ |
+
|
+ PAN-211531
+ |
+ + On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (). + | +
|
+ PAN-209288
+ |
+
+
+ Certificates are not successfully generated using SCEP ().
+
+ |
+
|
+ PAN-208622
+ |
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to
+ upload if you specify an Enterprise DLP data filtering profile (
+ with the Action set to Block to a
+ Security policy rule ().
+
+ |
+
|
+ PAN-204689
+ |
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do
+ not work:
+
+
|
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-196504
+ |
+ + License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). + | +
|
+ PAN-196146
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ The VM-Series firewall on Azure does not boot up with a hostname
+ (specified in an init-cgf.txt or user data) when bootstrapped.
+
+ |
+
|
+ PAN-194996
+ |
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma
+ Access 3.1.2 deployment, allocating bandwidth for a remote network
+ deployment fails (the OK button is grayed out).
+
+
+ Workaround: Retry the operation.
+
+ |
+
|
+ PAN-194519
+ |
+
+
+ (PA-5450 firewall only) Trying to configure a
+ custom payload format under
+
+ yields a Javascript error.
+
+ |
+
|
+ PAN-194515
+ |
+
+
+ (PA-5450 firewall only) The Panorama web
+ interface does not display any predefined template stack variables in
+ the dropdown menu under
+ .
+
+
+ Workaround: Configure the log interface IP address
+ on the individual firewall web interface instead of on Panorama.
+
+ |
+
|
+ PAN-194424
+ |
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS
+ 10.2.2 while having a log interface configured can cause both the log
+ interface and the management interface to remain connected to the log
+ collector.
+
+
+ Workaround: Restart the log receiver service by
+ running the following CLI command:
+
+
+
+
+
+ |
+
|
+ PAN-194202
+ |
+
+
+ (PA-5450 firewall only) If the management
+ interface and logging interface are configured on the same subnetwork,
+ the firewall conducts log forwarding using the management interface
+ instead of the logging interface.
+
+ |
+
|
+ PAN-193004
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues.
+
+ |
+
+
+ The Panorama management server fails to delete old IP Tag data. This
+ causes the /opt/pancfg partition
+ to reach maximum capacity which impacts Panorama performance.
+
+ |
+
|
+ PAN-190727
+ |
+
+
+ (PA-5450 firewall only) Documentation for
+ configuring the log interface is unavailable on the web interface and
+ in the PAN-OS Administrator’s Guide.
+
+ |
+
|
+ PAN-189111
+ |
+
+
+ After deleting an MP pod and it comes up, the
+ show routing command output
+ appears empty and traffic stops working.
+
+ |
+
|
+ PAN-189076
+ |
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a
+ broadcast link and a designated router (DR) priority of 0 (zero) are
+ stuck in a two-way state after HA failover.
+
+
+ Workaround: Configure at least one OSPFv3 neighbor
+ with a non-zero priority setting in the same broadcast domain.
+
+ |
+
|
+ PAN-188358
+ |
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management
+ port LEDs do not light up when a 10G Ethernet cable is plugged in.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187643
+ |
+
+
+ If you enable SCTP security using a Panorama template when
+ SCTP INIT Flood Protection is
+ enabled in the Zone Protection profile using Panorama and you commit
+ all changes, the commit is successful but the
+ SCTP INIT option is not available in
+ the Zone Protection profile.
+
+
+ Workaround: Log out of the firewall and log in
+ again to make the SCIT INIT option
+ available on the web interface.
+
+ |
+
|
+ PAN-187612
+ |
+
+
+ On the Panorama management server, not all data profiles () are displayed after you:
+
+
+ Workaround: Log in to the Panorama CLI and reset
+ the DLP plugin.
+
+ admin > request plugins dlp reset
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-187370
+ |
+
+
+ On a firewall with Advanced Routing enabled, if there is also a
+ logical router instance that uses the default configuration and has no
+ interfaces assigned to it, this will result in terminating the
+ management daemon and main routing daemon in the firewall during
+ commit.
+
+
+ Workaround: Do not use a logical router instance
+ with no interfaces bound to it.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-186282
+ |
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match
+ criteria automatically when adding dynamic address groups.
+
+
+ Workaround: Reboot the Panorama HA pair.
+
+ |
+
|
+ PAN-185286
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ (PA-5400 Series firewalls only) On the Panorama
+ management server, the device health resources () do not populate.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-181823
+ |
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer
+ port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports
+ on the firewall to go down if they are set to Auto.
+
+ |
+
|
+ PAN-180661
+ |
+
+
+ On the Panorama management server, pushing an unsupported Minimum
+ Password Complexity () to a managed firewall erroneously displays
+ commit time out as the reason the
+ commit failed.
+
+ |
+
|
+ PAN-180104
+ |
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2,
+ CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster
+ previously had a CN-Series as a DaemonSet deployment running PAN-OS
+ 10.0 or 10.1.
+
+
+ Workaround: Reboot the worker nodes before
+ upgrading to PAN-OS 10.2.
+
+ |
+
|
+ PAN-178194
+ |
+
+
+ A user interface issue in PAN-OS renders the contents of the
+ Inline ML tab in the
+ URL Filtering Profile inaccessible
+ on firewalls licensed for Advanced URL Filtering. Additionally, a
+ message indicating that a
+ License required for URL filtering to function
+ is unavailable displays at the bottom of the UI. These errors do not
+ affect the operation of Advanced URL Filtering or URL Filtering Inline
+ ML.
+
+
+ Workaround: Configuration settings for URL
+ Filtering Inline ML must be applied through the CLI. The following
+ configuration commands are available:
+
+
|
+
|
+ PAN-177455
+ |
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA
+ (High Availability) clustering enabled and using an HA4 communication
+ link. Attempting to load PAN-OS 10.2.0 on the firewall causes the
+ PA-7000 100G NPC to go offline. As a result, the firewall fails to
+ boot normally and enters maintenance mode. HA Pairs of Active-Passive
+ and Active-Active firewalls are not affected.
+
+ |
+
|
+ PAN-175915
+ |
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks
+ and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network
+ Protection Profile, the traffic logs do not display network slice SST
+ and SD values.
+
+ |
+
|
+ PAN-174982
+ |
+
+
+ In HA active/active configurations where, when interfaces that were
+ associated with a virtual router were deleted, the configuration
+ change did not sync.
+
+ |
+
|
+ PAN-172274
+ |
+
+
+ When you activate the advanced URL filtering license, your license
+ entitlements for PAN-DB and advanced URL filtering might not display
+ correctly on the firewall — this is a display anomaly, not a licensing
+ issue, and does not affect access to the services.
+
+
+ Workaround: Issue the following command to
+ retrieve and update the licenses:
+ license request fetch.
+
+ |
+
|
+ PAN-171938
+ |
+
+
+ No results are displayed when you
+ Show Application Filter for a
+ Security policy rule ().
+
+ |
+
|
+ PAN-164885
+
+ This issue is now resolved. See PAN-OS 10.2.10 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, pushes to managed firewalls (
+ or Commit and Push) may fail when an
+ EDL () is configured to
+ Check for updates every 5 minutes
+ due to the commit and EDL fetch processes overlapping. This is more
+ likely to occur when multiple EDLs are configured to check for updates
+ every 5 minutes.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-5854
+ |
+
+
+ The WildFire analysis report on the firewall log viewer () does not display the following data fields: File Type, SHA-256,
+ MD-5, and File Size".
+
+
+ Workaround: Download and open the WildFire
+ analysis report in the PDF format using the link in the upper
+ right-hand corner of the
+ Detailed Log View.
+
+ |
+
|
+ WF500-5843
+ |
+
+
+ In a WildFire appliance cluster, issuing the
+ show cluster-all peers CLI command
+ when a node within the cluster is being rebooted generates the
+ following error:
+ Server error : An error occured.
+
+ |
+
|
+ WF500-5840
+ |
+
+
+ The sample analysis statistics that are returned when issuing the
+ show wildfire local statistics CLI
+ command in WildFire appliance cluster deployments may not accurately
+ reflect the number of samples that have been processed.
+
+ |
+
|
+ WF500-5823
+ |
+
+
+ The following WildFire appliance CLI command does not return a
+ signature generation status as expected:
+ show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance
+ from analyzing a sample.
+
+ |
+
|
+ WF500-5781
+ |
+
+
+ The WildFire appliance might erroneously generate and log the
+ following device certification error:
+ Device certificate is missing or invalid. It cannot be
+ renewed.
+
+ |
+
|
+ WF500-5754
+ |
+
+
+ In WildFire appliance clusters, issuing the
+ show cluster controller CLI command
+ generates an error when an IPv6 address is configured for the
+ management interface but not for the cluster interface.
+
+
+ Workaround: Ensure all WildFire appliance
+ interfaces that are enabled use matching protocols (all IPv4 or all
+ IPv6).
+
+ |
+
|
+ WF500-5632
+ |
+
+
+ The number of registered WildFire appliances reported in Panorama
+ () does not accurately reflect the current status of connected
+ WildFire appliances.
+
+ |
+
|
+ PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues.
+
+ |
+
+
+ A race condition may cause the dataplane to restart unexpectedly when
+ a zip decompression offload result is returned for a session that has
+ already closed. The session state is not validated before processing
+ the result because the offload result does not follow the fastpath
+ where these checks are normally performed.
+
+
+ Workaround: Disable zip hardware offloading (may
+ cause higher CPU usage).
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See PAN-OS 10.2.13-h18 Addressed Issuesand
+ PAN-OS 10.2.16-h6 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-297610
+ |
+
+
+ A firewall may become unresponsive after an upgrade due to the
+ fsck command scanning drive
+ partitions in parallel with the root partition, causing the process to
+ take an extended amount of time.
+
+ |
+
|
+ PAN-297295
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent
+ process restarts multiple times and exhausts its restart limit,
+ resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-295803
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-295255
+ |
+
+
+ Palo Alto Networks next-generation firewalls may experience service
+ disruptions due to all_task process
+ crashes when deployed in environments having non-uniform MTU and are
+ terminating IPSec tunnels.
+
+ |
+
|
+ PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues.
+
+ |
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM)
+ condition due to a memory leak and displays an error message. This
+ issue causes the device to crash and reboot unexpectedly.
+
+ |
+
|
+ PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues
+
+ |
+
+
+ A memory leak in the configd process
+ might lead to an active firewall to reboot due to an Out-of-Memory
+ (OOM) condition. This issue is observed when specific status commands,
+ such as
+ request log-collector forwarding status
+ are executed at high frequencies.
+
+ |
+
|
+ PAN-290996
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues
+
+ |
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS)
+ counters incorrectly return a value of 0 for each virtual system
+ (VSYS), despite the firewall actively processing connections.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues
+
+ |
+
+
+ (Firewalls in HA configurations only) Routed
+ process may stop responding after changing MTU or any link parameters
+ when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-287871
+ |
+
+
+ When SSL Inbound Inspection is enabled and the firewall receives
+ fragmented Client Hello packets that include the TCP timestamp option,
+ the Client Hello message is forwarded to the destination server
+ without the timestamp option.
+
+ |
+
|
+ PAN-286231
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-284073
+ |
+
+
+ The firewall web interface becomes inaccessible and commits fail.
+
+ |
+
|
+ PAN-284067
+ |
+
+
+ A cumulative memory leak in the
+ devsrvr
+ process gets progressively worse whenever the CLI command
+ show running application statistics
+ is issued. This memory leak will gradually consume system memory and
+ produce an out-of-memory (OOM) condition, leading to an eventual
+ firewall reboot.
+
+
+ Workaround: Avoid using the CLI command:
+ show running application statistics.
+
+ |
+
|
+ PAN-281370
+ |
+
+
+ The Advanced WildFire Inline ML models
+ OOXML and
+ Mach-O erroneously display as being
+ available from the CLI; however, they are only available on PAN-OS
+ 11.1.3 and later releases.
+
+ |
+
|
+ PAN-273730
+ |
+
+
+ (PA-7000 Series only) The web interface is
+ unresponsive after upgrading to PAN-OS 10.2.7-h18. The following error
+ is generated:
+ PHP Fatal error: require(): Failed opening required
+
+
+ Workaround: Use the CLI to downgrade or upgrade to
+ another version.
+
+ |
+
|
+ PAN-273158
+ |
+
+
+ (PA-7000 Series firewalls only) Due to an
+ incorrect configuration on the ASIC, receiving a mix of jumbo and
+ non-jumbo packets may cause silent packet drops or application
+ slowness.
+
+ |
+
|
+ PAN-262263
+ |
+
+
+ (PA-3400 and PA-5400 Series firewalls) The
+ links on the firewall's RJ-45 ports may go up and down additional
+ times during a reboot, causing unexpected downtime.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
| PAN-259769 | +
+
+ GlobalProtect portal is not accessible via a web browser and the app
+ displays the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-244673
+ |
+
+
+ Upgrading a flexible-vCPU VM-Series firewall HA deployment from 10.1.x
+ directly to 10.2.3 or later causes the active HA peer to become
+ unresponsive. In this scenario, the upgraded firewall then becomes the
+ active peer.
+
+
+ Workaround: Upgrade the VM-Series firewalls to
+ PAN-OS 10.2.2 before upgrading to the latest PAN-OS 10.2.x version.
+
+ |
+
|
+ PAN-243951
+ |
+
+
+ On the Panorama management sever in an active/passive High
+ Availability (HA) configuration, managed devices () display as out-of-sync on the
+ passive HA peer when configuration changes are made to the SD-WAN
+ () configuration on the active HA peer.
+
+
+ Workaround: Manually synchronize the Panorama HA
+ peers.
+
+
|
+
|
+ PAN-237106
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-234408
+ |
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for
+ ChatGPT from traffic forwarded to the DLP cloud service from an NGFW.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-242910
+
+ PAN-OS 10.2.7, 10.2.7-h1, and 10.2.7-h3 only
+
+ |
+
+
+ On the Panorama management server, Panorama administrators () that are assigned a custom Panorama admin role () with Push All Changes enabled are
+ unable to push configuration changes to managed firewalls when
+ Managed Devices and
+ Push For Other Admins are disabled.
+
+ |
+
|
+ PAN-242837
+ |
+
+
+ Default login credentials and SSH fail after enabling FIPS-CC Mode on
+ a firewall or Panorama after converting through the Maintenance
+ Recovery Tool (MRT). The firewall or Panorama becomes stuck and
+ requires a factory reset to recover.
+
+ |
+
|
+ PAN-242561
+ |
+
+
+ On the PAN-OS 10.2.7-h3 version, GlobalProtect tunnel might disconnect
+ shortly after being established when SSL is used as a transport
+ protocol.
+
+
+ Workaround: Disable Internet Protocol version 6
+ (TCP/IPv6) on the PANGP Virtual Network Adapter.
+
+ |
+
|
+ PAN-238769
+ |
+
+
+ FIPS-CC VM only. Upgrading to 10.1.10-h2 or 10.1.11 will change all
+ locally created security Policy actions to Deny. Re-load the back-up
+ config taken before upgrading or the last version to get the previous
+ config back. Also, Unable to login to FIPSCC Mode devices with default
+ credentials after converting the mode for 10.1.12 release , 10.2.7
+ release , 11.1.0 , 11.1.1, 11.0.3 versions.
+
+ |
+
|
+ PAN-234929
+
+ This issue is now resolved. See PAN-OS 10.2.7-h3 Addressed Issues.
+
+ |
+
+
+ The tabs in the ACC, such as
+ Network Activity,
+ Threat Activity, and
+ Blocked Activity, may not display
+ any data when you apply a Time filter for the Last 15 minutes, Last
+ Hour, Last 6 Hours, or Last 12 Hours. With the Last 24 Hours filter,
+ the data displayed may not be accurate. Additionally, reports run
+ against summary logs may not display accurate results.
+
+ |
+
|
+ PAN-228515
+ |
+
+
+ The EleasticSearch SSH flaps on the M-600 appliance in Panorama or Log
+ Collector mode. This causes logs to not display on the Panorama
+ management server () and the Log Collector health status () to display as degraded.
+
+ |
+
|
+ PAN-228273
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server in FIPS-CC mode, the ElasticSearch
+ cluster fails to come up and the
+ show log-collector-es-cluster health
+ command displays the status is
+ red. This results in log
+ ingestion issues for Panorama in Panorama only or Log Collector mode.
+
+ |
+
|
+ PAN-227344
+ |
+
+
+ On the Panorama management server, PDF Summary Reports () display no data and are blank when predefined reports are included
+ in the summary report.
+
+ |
+
|
+ PAN-223365
+ |
+
+
+ The Panorama management server is unable to query any logs if the
+ ElasticSearch health status for any Log Collector (
+ is degraded.
+
+
+ Workaround:
+ Log in to the Log Collector CLI
+ and restart ElasticSearch.
+
+
+
+
+
+ |
+
|
+ PAN-229865
+ |
+
+
+ Upgrading a PA-220 firewall running a PAN-OS 10.1 release fails when
+ the target PAN-OS upgrade version is PAN-OS 10.2.5.
+
+
+ Workaround: On your upgrade path to PAN-OS 10.2.5,
+ first upgrade to PAN-OS 10.2.4 and then upgrade to PAN-OS 10.2.5.
+
+ |
+
|
+ PAN-226768
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ When the GlobalProtect app is installed on iOS endpoints and the
+ gateway is configured to accept cookies, the app stays in
+ Connecting stage after
+ authentication and the GlobalProtect log displays the error message,
+ User is not in allow list. This
+ happens when the app is restarted or when the app tries to reconnect
+ after disconnection.
+
+ |
+
|
+ PAN-223677
+ |
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, and PA-5430
+ firewalls) By enabling
+ Lockless QoS
+ feature, a slight degradation in App-ID and Threat performance is
+ expected.
+
+ |
+
|
+ PAN-223457
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ If the number of group queries exceeds the Okta rate limit threshold,
+ the firewall clears the cache for the groups. To avoid encountering
+ this issue, disable the Okta rate limit.
+
+ |
+
|
+ PAN-222586
+ |
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus,
+ Forward Methods, and Built-In Actions for Correlation Log settings
+ () are not displayed and cannot be configured.
+
+ |
+
|
+ PAN-222418
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ The firewall intermittently records a reconnection message to the
+ authentication server as a error, even if no disconnection occurs.
+
+ |
+
|
+ PAN-222253
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, policy rulebase reordering when you
+ View Rulebase by Groups () does not persist if you reorder the policy rulebase by dragging and
+ dropping individual policy rules and then moving the entire tag group.
+
+ |
+
|
+ PAN-221775
+ |
+
+
+ A Malformed Request error is
+ displayed when you
+ Test Connection for an email server
+ profile () using SMTP over TLS and the
+ Password includes an ampersand
+ (&).
+
+ |
+
|
+ PAN-221857
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ Users are unable to log in to the GlobalProtect app using SAML
+ authentication after the app is upgraded to 10.2.3-h4 and the
+ GlobalProtect logs display the following error message:
+ Username from SAML SSO response is different from the input..
+
+ |
+
|
+ PAN-221033
+
+ This issue is now resolved. See
+ PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ The firewall is responding to an ARP request for an IP address in the
+ firewall's NAT address pool when that IP address isn't in the same
+ subnet as the IP address of the ingress interface.
+
+ |
+
|
+ PAN-220180
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ Configured botnet reports () are not generated.
+
+ |
+
|
+ PAN-219644
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ Firewalls forwarding logs to a syslog server over TLS () use the default Palo Alto Networks certificate instead of the
+ custom certificate configured on the firewall.
+
+ |
+
|
+ PAN-217307
+
+ This issue is now resolved. See PAN-OS 10.2.11 Addressed Issues.
+
+ |
+
+
+ The following Security policy rule () filters return no results:
+
+
+ log-start eq no
+
+ log-end eq no
+ log-end eq yes
+ |
+
|
+ PAN-215082
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ M-300 and M-700 appliances may generate erroneous system logs () to alert that the M-Series appliance memory usage limits are
+ reached.
+
+ |
+
|
+ PAN-213746
+ |
+
+
+ On the Panorama management server, the
+ Hostkey displayed as
+ undefined undefined if you
+ override an SSH Service Profile () Hostkey configured in a Template from the Template Stack.
+
+ |
+
|
+ PAN-213119
+ |
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you
+ view the Block IP list ():
+
+
+ show -> dis-block-table is unexpected
+
+ |
+
|
+ PAN-212889
+
+ This issue is now resolved. See
+ PAN-OS 10.2.14 Addressed Issues
+
+ |
+
+
+ On the Panorama management server, different threat names are used
+ when querying the same threat in the Threat Monitor () and ACC. This results in the ACC
+ displaying
+ no data to display when you are
+ redirected to the ACC after clicking a threat name in the Threat
+ Monitor and filtering the same threat name in the Global Filters.
+
+ |
+
|
+ PAN-212533
+ |
+
+
+ Modifying the Administrator Type for
+ an existing administrator (
+ or
+ ) from Superuser to a
+ Role-Based custom admin, or vice
+ versa, does not modify the access privileges of the administrator.
+
+ |
+
|
+ PAN-211531
+ |
+ + On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (). + | +
|
+ PAN-209288
+ |
+
+
+ Certificates are not successfully generated using SCEP ().
+
+ |
+
|
+ PAN-208622
+ |
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to
+ upload if you specify an Enterprise DLP data filtering profile (
+ with the Action set to Block to a
+ Security policy rule ().
+
+ |
+
|
+ PAN-204689
+ |
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do
+ not work:
+
+
|
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-196504
+ |
+ + License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). + | +
|
+ PAN-196146
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ The VM-Series firewall on Azure does not boot up with a hostname
+ (specified in an init-cgf.txt or user data) when bootstrapped.
+
+ |
+
|
+ PAN-194996
+ |
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma
+ Access 3.1.2 deployment, allocating bandwidth for a remote network
+ deployment fails (the OK button is grayed out).
+
+
+ Workaround: Retry the operation.
+
+ |
+
|
+ PAN-194519
+ |
+
+
+ (PA-5450 firewall only) Trying to configure a
+ custom payload format under
+
+ yields a Javascript error.
+
+ |
+
|
+ PAN-194515
+ |
+
+
+ (PA-5450 firewall only) The Panorama web
+ interface does not display any predefined template stack variables in
+ the dropdown menu under
+ .
+
+
+ Workaround: Configure the log interface IP address
+ on the individual firewall web interface instead of on Panorama.
+
+ |
+
|
+ PAN-194424
+ |
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS
+ 10.2.2 while having a log interface configured can cause both the log
+ interface and the management interface to remain connected to the log
+ collector.
+
+
+ Workaround: Restart the log receiver service by
+ running the following CLI command:
+
+
+
+
+
+ |
+
|
+ PAN-194202
+ |
+
+
+ (PA-5450 firewall only) If the management
+ interface and logging interface are configured on the same subnetwork,
+ the firewall conducts log forwarding using the management interface
+ instead of the logging interface.
+
+ |
+
|
+ PAN-190727
+ |
+
+
+ (PA-5450 firewall only) Documentation for
+ configuring the log interface is unavailable on the web interface and
+ in the PAN-OS Administrator’s Guide.
+
+ |
+
|
+ PAN-189111
+ |
+
+
+ After deleting an MP pod and it comes up, the
+ show routing command output
+ appears empty and traffic stops working.
+
+ |
+
|
+ PAN-189076
+ |
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a
+ broadcast link and a designated router (DR) priority of 0 (zero) are
+ stuck in a two-way state after HA failover.
+
+
+ Workaround: Configure at least one OSPFv3 neighbor
+ with a non-zero priority setting in the same broadcast domain.
+
+ |
+
|
+ PAN-188358
+ |
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management
+ port LEDs do not light up when a 10G Ethernet cable is plugged in.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187643
+ |
+
+
+ If you enable SCTP security using a Panorama template when
+ SCTP INIT Flood Protection is
+ enabled in the Zone Protection profile using Panorama and you commit
+ all changes, the commit is successful but the
+ SCTP INIT option is not available in
+ the Zone Protection profile.
+
+
+ Workaround: Log out of the firewall and log in
+ again to make the SCIT INIT option
+ available on the web interface.
+
+ |
+
|
+ PAN-187612
+ |
+
+
+ On the Panorama management server, not all data profiles () are displayed after you:
+
+
+ Workaround: Log in to the Panorama CLI and reset
+ the DLP plugin.
+
+ admin > request plugins dlp reset
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-187370
+ |
+
+
+ On a firewall with Advanced Routing enabled, if there is also a
+ logical router instance that uses the default configuration and has no
+ interfaces assigned to it, this will result in terminating the
+ management daemon and main routing daemon in the firewall during
+ commit.
+
+
+ Workaround: Do not use a logical router instance
+ with no interfaces bound to it.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-186282
+ |
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match
+ criteria automatically when adding dynamic address groups.
+
+
+ Workaround: Reboot the Panorama HA pair.
+
+ |
+
|
+ PAN-185286
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues.
+
+ |
+
+
+ (PA-5400 Series firewalls only) On the Panorama
+ management server, the device health resources () do not populate.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-181823
+ |
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer
+ port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports
+ on the firewall to go down if they are set to Auto.
+
+ |
+
|
+ PAN-180661
+ |
+
+
+ On the Panorama management server, pushing an unsupported Minimum
+ Password Complexity () to a managed firewall erroneously displays
+ commit time out as the reason the
+ commit failed.
+
+ |
+
|
+ PAN-180104
+ |
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2,
+ CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster
+ previously had a CN-Series as a DaemonSet deployment running PAN-OS
+ 10.0 or 10.1.
+
+
+ Workaround: Reboot the worker nodes before
+ upgrading to PAN-OS 10.2.
+
+ |
+
|
+ PAN-178194
+ |
+
+
+ A user interface issue in PAN-OS renders the contents of the
+ Inline ML tab in the
+ URL Filtering Profile inaccessible
+ on firewalls licensed for Advanced URL Filtering. Additionally, a
+ message indicating that a
+ License required for URL filtering to function
+ is unavailable displays at the bottom of the UI. These errors do not
+ affect the operation of Advanced URL Filtering or URL Filtering Inline
+ ML.
+
+
+ Workaround: Configuration settings for URL
+ Filtering Inline ML must be applied through the CLI. The following
+ configuration commands are available:
+
+
|
+
|
+ PAN-177455
+ |
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA
+ (High Availability) clustering enabled and using an HA4 communication
+ link. Attempting to load PAN-OS 10.2.0 on the firewall causes the
+ PA-7000 100G NPC to go offline. As a result, the firewall fails to
+ boot normally and enters maintenance mode. HA Pairs of Active-Passive
+ and Active-Active firewalls are not affected.
+
+ |
+
|
+ PAN-175915
+ |
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks
+ and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network
+ Protection Profile, the traffic logs do not display network slice SST
+ and SD values.
+
+ |
+
|
+ PAN-174982
+ |
+
+
+ In HA active/active configurations where, when interfaces that were
+ associated with a virtual router were deleted, the configuration
+ change did not sync.
+
+ |
+
|
+ PAN-172274
+ |
+
+
+ When you activate the advanced URL filtering license, your license
+ entitlements for PAN-DB and advanced URL filtering might not display
+ correctly on the firewall — this is a display anomaly, not a licensing
+ issue, and does not affect access to the services.
+
+
+ Workaround: Issue the following command to
+ retrieve and update the licenses:
+ license request fetch.
+
+ |
+
|
+ PAN-171938
+ |
+
+
+ No results are displayed when you
+ Show Application Filter for a
+ Security policy rule ().
+
+ |
+
|
+ PAN-164885
+
+ This issue is now resolved. See PAN-OS 10.2.10 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, pushes to managed firewalls (
+ or Commit and Push) may fail when an
+ EDL () is configured to
+ Check for updates every 5 minutes
+ due to the commit and EDL fetch processes overlapping. This is more
+ likely to occur when multiple EDLs are configured to check for updates
+ every 5 minutes.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-5854
+ |
+
+
+ The WildFire analysis report on the firewall log viewer () does not display the following data fields: File Type, SHA-256,
+ MD-5, and File Size".
+
+
+ Workaround: Download and open the WildFire
+ analysis report in the PDF format using the link in the upper
+ right-hand corner of the
+ Detailed Log View.
+
+ |
+
|
+ WF500-5843
+ |
+
+
+ In a WildFire appliance cluster, issuing the
+ show cluster-all peers CLI command
+ when a node within the cluster is being rebooted generates the
+ following error:
+ Server error : An error occured.
+
+ |
+
|
+ WF500-5840
+ |
+
+
+ The sample analysis statistics that are returned when issuing the
+ show wildfire local statistics CLI
+ command in WildFire appliance cluster deployments may not accurately
+ reflect the number of samples that have been processed.
+
+ |
+
|
+ WF500-5823
+ |
+
+
+ The following WildFire appliance CLI command does not return a
+ signature generation status as expected:
+ show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance
+ from analyzing a sample.
+
+ |
+
|
+ WF500-5781
+ |
+
+
+ The WildFire appliance might erroneously generate and log the
+ following device certification error:
+ Device certificate is missing or invalid. It cannot be
+ renewed.
+
+ |
+
|
+ WF500-5754
+ |
+
+
+ In WildFire appliance clusters, issuing the
+ show cluster controller CLI command
+ generates an error when an IPv6 address is configured for the
+ management interface but not for the cluster interface.
+
+
+ Workaround: Ensure all WildFire appliance
+ interfaces that are enabled use matching protocols (all IPv4 or all
+ IPv6).
+
+ |
+
|
+ WF500-5632
+ |
+
+
+ The number of registered WildFire appliances reported in Panorama
+ () does not accurately reflect the current status of connected
+ WildFire appliances.
+
+ |
+
|
+ PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues.
+
+ |
+
+
+ A race condition may cause the dataplane to restart unexpectedly when
+ a zip decompression offload result is returned for a session that has
+ already closed. The session state is not validated before processing
+ the result because the offload result does not follow the fastpath
+ where these checks are normally performed.
+
+
+ Workaround: Disable zip hardware offloading (may
+ cause higher CPU usage).
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See PAN-OS 10.2.13-h18 Addressed Issuesand
+ PAN-OS 10.2.16-h6 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-297610
+ |
+
+
+ A firewall may become unresponsive after an upgrade due to the
+ fsck command scanning drive
+ partitions in parallel with the root partition, causing the process to
+ take an extended amount of time.
+
+ |
+
|
+ PAN-297295
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent
+ process restarts multiple times and exhausts its restart limit,
+ resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-295803
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-295255
+ |
+
+
+ Palo Alto Networks next-generation firewalls may experience service
+ disruptions due to all_task process
+ crashes when deployed in environments having non-uniform MTU and are
+ terminating IPSec tunnels.
+
+ |
+
|
+ PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues.
+
+ |
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM)
+ condition due to a memory leak and displays an error message. This
+ issue causes the device to crash and reboot unexpectedly.
+
+ |
+
|
+ PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues
+
+ |
+
+
+ A memory leak in the configd process
+ might lead to an active firewall to reboot due to an Out-of-Memory
+ (OOM) condition. This issue is observed when specific status commands,
+ such as
+ request log-collector forwarding status
+ are executed at high frequencies.
+
+ |
+
|
+ PAN-290996
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues
+
+ |
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS)
+ counters incorrectly return a value of 0 for each virtual system
+ (VSYS), despite the firewall actively processing connections.
+
+ |
+
|
+ PAN-290088
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues
+
+ |
+
+
+ (Firewalls in HA configurations only) Routed
+ process may stop responding after changing MTU or any link parameters
+ when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-287871
+
+ This issue affects PAN-OS 10.2.8-h10
+
+ |
+
+
+ When SSL Inbound Inspection is enabled and the firewall receives
+ fragmented Client Hello packets that include the TCP timestamp option,
+ the Client Hello message is forwarded to the destination server
+ without the timestamp option.
+
+ |
+
|
+ PAN-287056
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues
+
+ |
+
+
+ A BGP export policy rule that matches on a next hop fails to block the
+ advertisement of static routes, and the firewall incorrectly matches
+ the egress interface IP address instead of the original next-hop IP
+ address of the static route, which causes the deny rule to fail.
+
+ |
+
|
+ PAN-286231
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-285894
+
+ This issue is now resolved. See PAN-OS 10.2.13-h10 Addressed Issues
+
+ |
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may
+ occur, which could result in firewall reboots.
+
+
+ Workaround: Disable the Preserve Pre-NAT feature
+ using the
+ set deviceconfig setting preserve-prenat-feature no
+ CLI command.
+
+ |
+
|
+ PAN-284073
+ |
+
+
+ The firewall web interface becomes inaccessible and commits fail.
+
+ |
+
|
+ PAN-284067
+ |
+
+
+ A cumulative memory leak in the
+ devsrvr
+ process gets progressively worse whenever the CLI command
+ show running application statistics
+ is issued. This memory leak will gradually consume system memory and
+ produce an out-of-memory (OOM) condition, leading to an eventual
+ firewall reboot.
+
+
+ Workaround: Avoid using the CLI command:
+ show running application statistics.
+
+ |
+
|
+ PAN-281370
+ |
+
+
+ The Advanced WildFire Inline ML models
+ OOXML and
+ Mach-O erroneously display as being
+ available from the CLI; however, they are only available on PAN-OS
+ 11.1.3 and later releases.
+
+ |
+
|
+ PAN-273158
+ |
+
+
+ (PA-7000 Series firewalls only) Due to an
+ incorrect configuration on the ASIC, receiving a mix of jumbo and
+ non-jumbo packets may cause silent packet drops or application
+ slowness.
+
+ |
+
|
+ PAN-262287
+
+ This issue is now resolved. See PAN-OS 10.2.13 Addressed Issues.
+
+ |
+
+
+ Dereferencing a NULL pointer that occurs might cause
+ pan_task
+ processes to crash.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
| PAN-259769 | +
+
+ GlobalProtect portal is not accessible via a web browser and the app
+ displays the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-255868
+ |
+
+
+ (PA-3400 Series firewalls only) After enabling
+ kernel data collection during a silent reboot, the firewall fails and
+ reboots to maintenance mode.
+
+
+ Workaround: To recover the firewall, initiate a
+ reboot from maintenance mode.
+
+ |
+
|
+ PAN-251895
+
+ This issue is now resolved. See PAN-OS 10.2.10 Addressed Issues.
+
+ |
+
+
+ When Inline Cloud Analysis features are enabled, the firewall
+ experiences a slow packet buffer leak, resulting in poor performance
+ and dropped traffic.
+
+
+ Workaround: Disable WildFire Inline Cloud Analysis
+ and Advanced Threat Prevention Inline Cloud Analysis on the firewall.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-243951
+ |
+
+
+ On the Panorama management sever in an active/passive High
+ Availability (HA) configuration, managed devices () display as out-of-sync on the
+ passive HA peer when configuration changes are made to the SD-WAN
+ () configuration on the active HA peer.
+
+
+ Workaround: Manually synchronize the Panorama HA
+ peers.
+
+
|
+
|
+ PAN-242910
+ |
+
+
+ On the Panorama management server, Panorama administrators () that are assigned a custom Panorama admin role () with Push All Changes enabled are
+ unable to push configuration changes to managed firewalls when
+ Managed Devices and
+ Push For Other Admins are disabled.
+
+ |
+
|
+ PAN-242627
+ |
+ + On the Panorama management server, selective configuration pushes fail + with the following error message even when a full configuration push + from Panorama was previously performed:Failed to generate selective push + configuration. Schema validation failed. Please try a full push + | +
|
+ PAN-237106
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-234408
+ |
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for
+ ChatGPT from traffic forwarded to the DLP cloud service from an NGFW.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-223365
+ |
+
+
+ The Panorama management server is unable to query any logs if the
+ ElasticSearch health status for any Log Collector (
+ is degraded.
+
+
+ Workaround:
+ Log in to the Log Collector CLI
+ and restart ElasticSearch.
+
+
+
+
+
+ |
+
|
+ PAN-229865
+ |
+
+
+ Upgrading a PA-220 firewall running a PAN-OS 10.1 release fails when
+ the target PAN-OS upgrade version is PAN-OS 10.2.5.
+
+
+ Workaround: On your upgrade path to PAN-OS 10.2.5,
+ first upgrade to PAN-OS 10.2.4 and then upgrade to PAN-OS 10.2.5.
+
+ |
+
|
+ PAN-228515
+ |
+
+
+ The EleasticSearch SSH flaps on the M-600 appliance in Panorama or Log
+ Collector mode. This causes logs to not display on the Panorama
+ management server () and the Log Collector health status () to display as degraded.
+
+ |
+
|
+ PAN-226361
+
+ This issue is now resolved. See PAN-OS 10.2.8-h13 Addressed Issues.
+
+ |
+
+
+ Sessions might end unexpectedly with the error
+ resources-unavailable when the
+ firewall incorrectly interprets the Content and Threat Detection (CTD)
+ global packet queue as being full.
+
+ |
+
|
+ PAN-223677
+ |
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, and PA-5430
+ firewalls) By enabling
+ Lockless QoS
+ feature, a slight degradation in App-ID and Threat performance is
+ expected.
+
+ |
+
|
+ PAN-222586
+ |
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus,
+ Forward Methods, and Built-In Actions for Correlation Log settings
+ () are not displayed and cannot be configured.
+
+ |
+
|
+ PAN-221775
+ |
+
+
+ A Malformed Request error is
+ displayed when you
+ Test Connection for an email server
+ profile () using SMTP over TLS and the
+ Password includes an ampersand
+ (&).
+
+ |
+
|
+ PAN-217307
+
+ This issue is now resolved. See PAN-OS 10.2.11 Addressed Issues.
+
+ |
+
+
+ The following Security policy rule () filters return no results:
+
+
+ log-start eq no
+
+ log-end eq no
+ log-end eq yes
+ |
+
|
+ PAN-213746
+ |
+
+
+ On the Panorama management server, the
+ Hostkey displayed as
+ undefined undefined if you
+ override an SSH Service Profile () Hostkey configured in a Template from the Template Stack.
+
+ |
+
|
+ PAN-213119
+ |
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you
+ view the Block IP list ():
+
+
+ show -> dis-block-table is unexpected
+
+ |
+
|
+ PAN-212889
+
+ This issue is now resolved. See
+ PAN-OS 10.2.14 Addressed Issues
+
+ |
+
+
+ On the Panorama management server, different threat names are used
+ when querying the same threat in the Threat Monitor () and ACC. This results in the ACC
+ displaying
+ no data to display when you are
+ redirected to the ACC after clicking a threat name in the Threat
+ Monitor and filtering the same threat name in the Global Filters.
+
+ |
+
|
+ PAN-212533
+ |
+
+
+ Modifying the Administrator Type for
+ an existing administrator (
+ or
+ ) from Superuser to a
+ Role-Based custom admin, or vice
+ versa, does not modify the access privileges of the administrator.
+
+ |
+
|
+ PAN-211531
+ |
+ + On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (). + | +
|
+ PAN-209288
+ |
+
+
+ Certificates are not successfully generated using SCEP ().
+
+ |
+
|
+ PAN-208622
+ |
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to
+ upload if you specify an Enterprise DLP data filtering profile (
+ with the Action set to Block to a
+ Security policy rule ().
+
+ |
+
|
+ PAN-204689
+ |
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do
+ not work:
+
+
|
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-196504
+ |
+ + License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). + | +
|
+ PAN-194996
+ |
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma
+ Access 3.1.2 deployment, allocating bandwidth for a remote network
+ deployment fails (the OK button is grayed out).
+
+
+ Workaround: Retry the operation.
+
+ |
+
|
+ PAN-194519
+ |
+
+
+ (PA-5450 firewall only) Trying to configure a
+ custom payload format under
+
+ yields a Javascript error.
+
+ |
+
|
+ PAN-194515
+ |
+
+
+ (PA-5450 firewall only) The Panorama web
+ interface does not display any predefined template stack variables in
+ the dropdown menu under
+ .
+
+
+ Workaround: Configure the log interface IP address
+ on the individual firewall web interface instead of on Panorama.
+
+ |
+
|
+ PAN-194424
+ |
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS
+ 10.2.2 while having a log interface configured can cause both the log
+ interface and the management interface to remain connected to the log
+ collector.
+
+
+ Workaround: Restart the log receiver service by
+ running the following CLI command:
+
+
+
+
+
+ |
+
|
+ PAN-194202
+ |
+
+
+ (PA-5450 firewall only) If the management
+ interface and logging interface are configured on the same subnetwork,
+ the firewall conducts log forwarding using the management interface
+ instead of the logging interface.
+
+ |
+
|
+ PAN-190727
+ |
+
+
+ (PA-5450 firewall only) Documentation for
+ configuring the log interface is unavailable on the web interface and
+ in the PAN-OS Administrator’s Guide.
+
+ |
+
|
+ PAN-189111
+ |
+
+
+ After deleting an MP pod and it comes up, the
+ show routing command output
+ appears empty and traffic stops working.
+
+ |
+
|
+ PAN-189076
+ |
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a
+ broadcast link and a designated router (DR) priority of 0 (zero) are
+ stuck in a two-way state after HA failover.
+
+
+ Workaround: Configure at least one OSPFv3 neighbor
+ with a non-zero priority setting in the same broadcast domain.
+
+ |
+
|
+ PAN-188358
+ |
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management
+ port LEDs do not light up when a 10G Ethernet cable is plugged in.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187643
+ |
+
+
+ If you enable SCTP security using a Panorama template when
+ SCTP INIT Flood Protection is
+ enabled in the Zone Protection profile using Panorama and you commit
+ all changes, the commit is successful but the
+ SCTP INIT option is not available in
+ the Zone Protection profile.
+
+
+ Workaround: Log out of the firewall and log in
+ again to make the SCIT INIT option
+ available on the web interface.
+
+ |
+
|
+ PAN-187612
+ |
+
+
+ On the Panorama management server, not all data profiles () are displayed after you:
+
+
+ Workaround: Log in to the Panorama CLI and reset
+ the DLP plugin.
+
+ admin > request plugins dlp reset
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-187370
+ |
+
+
+ On a firewall with Advanced Routing enabled, if there is also a
+ logical router instance that uses the default configuration and has no
+ interfaces assigned to it, this will result in terminating the
+ management daemon and main routing daemon in the firewall during
+ commit.
+
+
+ Workaround: Do not use a logical router instance
+ with no interfaces bound to it.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-186282
+ |
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match
+ criteria automatically when adding dynamic address groups.
+
+
+ Workaround: Reboot the Panorama HA pair.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-181823
+ |
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer
+ port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports
+ on the firewall to go down if they are set to Auto.
+
+ |
+
|
+ PAN-180661
+ |
+
+
+ On the Panorama management server, pushing an unsupported Minimum
+ Password Complexity () to a managed firewall erroneously displays
+ commit time out as the reason the
+ commit failed.
+
+ |
+
|
+ PAN-180104
+ |
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2,
+ CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster
+ previously had a CN-Series as a DaemonSet deployment running PAN-OS
+ 10.0 or 10.1.
+
+
+ Workaround: Reboot the worker nodes before
+ upgrading to PAN-OS 10.2.
+
+ |
+
|
+ PAN-178194
+ |
+
+
+ A user interface issue in PAN-OS renders the contents of the
+ Inline ML tab in the
+ URL Filtering Profile inaccessible
+ on firewalls licensed for Advanced URL Filtering. Additionally, a
+ message indicating that a
+ License required for URL filtering to function
+ is unavailable displays at the bottom of the UI. These errors do not
+ affect the operation of Advanced URL Filtering or URL Filtering Inline
+ ML.
+
+
+ Workaround: Configuration settings for URL
+ Filtering Inline ML must be applied through the CLI. The following
+ configuration commands are available:
+
+
|
+
|
+ PAN-177455
+ |
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA
+ (High Availability) clustering enabled and using an HA4 communication
+ link. Attempting to load PAN-OS 10.2.0 on the firewall causes the
+ PA-7000 100G NPC to go offline. As a result, the firewall fails to
+ boot normally and enters maintenance mode. HA Pairs of Active-Passive
+ and Active-Active firewalls are not affected.
+
+ |
+
|
+ PAN-175915
+ |
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks
+ and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network
+ Protection Profile, the traffic logs do not display network slice SST
+ and SD values.
+
+ |
+
|
+ PAN-174982
+ |
+
+
+ In HA active/active configurations where, when interfaces that were
+ associated with a virtual router were deleted, the configuration
+ change did not sync.
+
+ |
+
|
+ PAN-172274
+ |
+
+
+ When you activate the advanced URL filtering license, your license
+ entitlements for PAN-DB and advanced URL filtering might not display
+ correctly on the firewall — this is a display anomaly, not a licensing
+ issue, and does not affect access to the services.
+
+
+ Workaround: Issue the following command to
+ retrieve and update the licenses:
+ license request fetch.
+
+ |
+
|
+ PAN-171938
+ |
+
+
+ No results are displayed when you
+ Show Application Filter for a
+ Security policy rule ().
+
+ |
+
|
+ PAN-164885
+
+ This issue is now resolved. See PAN-OS 10.2.10 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, pushes to managed firewalls (
+ or Commit and Push) may fail when an
+ EDL () is configured to
+ Check for updates every 5 minutes
+ due to the commit and EDL fetch processes overlapping. This is more
+ likely to occur when multiple EDLs are configured to check for updates
+ every 5 minutes.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-5854
+ |
+
+
+ The WildFire analysis report on the firewall log viewer () does not display the following data fields: File Type, SHA-256,
+ MD-5, and File Size".
+
+
+ Workaround: Download and open the WildFire
+ analysis report in the PDF format using the link in the upper
+ right-hand corner of the
+ Detailed Log View.
+
+ |
+
|
+ WF500-5843
+ |
+
+
+ In a WildFire appliance cluster, issuing the
+ show cluster-all peers CLI command
+ when a node within the cluster is being rebooted generates the
+ following error:
+ Server error : An error occured.
+
+ |
+
|
+ WF500-5840
+ |
+
+
+ The sample analysis statistics that are returned when issuing the
+ show wildfire local statistics CLI
+ command in WildFire appliance cluster deployments may not accurately
+ reflect the number of samples that have been processed.
+
+ |
+
|
+ WF500-5823
+ |
+
+
+ The following WildFire appliance CLI command does not return a
+ signature generation status as expected:
+ show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance
+ from analyzing a sample.
+
+ |
+
|
+ WF500-5781
+ |
+
+
+ The WildFire appliance might erroneously generate and log the
+ following device certification error:
+ Device certificate is missing or invalid. It cannot be
+ renewed.
+
+ |
+
|
+ WF500-5754
+ |
+
+
+ In WildFire appliance clusters, issuing the
+ show cluster controller CLI command
+ generates an error when an IPv6 address is configured for the
+ management interface but not for the cluster interface.
+
+
+ Workaround: Ensure all WildFire appliance
+ interfaces that are enabled use matching protocols (all IPv4 or all
+ IPv6).
+
+ |
+
|
+ WF500-5632
+ |
+
+
+ The number of registered WildFire appliances reported in Panorama
+ () does not accurately reflect the current status of connected
+ WildFire appliances.
+
+ |
+
|
+ PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues.
+
+ |
+
+
+ A race condition may cause the dataplane to restart unexpectedly when
+ a zip decompression offload result is returned for a session that has
+ already closed. The session state is not validated before processing
+ the result because the offload result does not follow the fastpath
+ where these checks are normally performed.
+
+
+ Workaround: Disable zip hardware offloading (may
+ cause higher CPU usage).
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See PAN-OS 10.2.13-h18 Addressed Issuesand
+ PAN-OS 10.2.16-h6 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-297610
+ |
+
+
+ A firewall may become unresponsive after an upgrade due to the
+ fsck command scanning drive
+ partitions in parallel with the root partition, causing the process to
+ take an extended amount of time.
+
+ |
+
|
+ PAN-297295
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent
+ process restarts multiple times and exhausts its restart limit,
+ resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-295803
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-295255
+ |
+
+
+ Palo Alto Networks next-generation firewalls may experience service
+ disruptions due to all_task process
+ crashes when deployed in environments having non-uniform MTU and are
+ terminating IPSec tunnels.
+
+ |
+
|
+ PAN-292344
+
+ This issue affects PAN-OS 10.2.9-h7
+
+ |
+
+
+ When upgrading from PAN-OS 10.2.9-h1 to PAN-OS 10.2.13-h5, the
+ firewall reboots repeatedly and enters maintenance mode.
+
+ |
+
|
+ PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues.
+
+ |
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM)
+ condition due to a memory leak and displays an error message. This
+ issue causes the device to crash and reboot unexpectedly.
+
+ |
+
|
+ PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues
+
+ |
+
+
+ A memory leak in the configd process
+ might lead to an active firewall to reboot due to an Out-of-Memory
+ (OOM) condition. This issue is observed when specific status commands,
+ such as
+ request log-collector forwarding status
+ are executed at high frequencies.
+
+ |
+
|
+ PAN-290996
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues
+
+ |
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS)
+ counters incorrectly return a value of 0 for each virtual system
+ (VSYS), despite the firewall actively processing connections.
+
+ |
+
|
+ PAN-290088
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues
+
+ |
+
+
+ (Firewalls in HA configurations only) Routed
+ process may stop responding after changing MTU or any link parameters
+ when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-287871
+
+ This issue affects PAN-OS 10.2.9-h9
+
+ |
+
+
+ When SSL Inbound Inspection is enabled and the firewall receives
+ fragmented Client Hello packets that include the TCP timestamp option,
+ the Client Hello message is forwarded to the destination server
+ without the timestamp option.
+
+ |
+
|
+ PAN-286231
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-285894
+
+ This issue is now resolved. See PAN-OS 10.2.13-h10 Addressed Issues
+
+ |
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may
+ occur, which could result in firewall reboots.
+
+
+ Workaround: Disable the Preserve Pre-NAT feature
+ using the
+ set deviceconfig setting preserve-prenat-feature no
+ CLI command.
+
+ |
+
|
+ PAN-284073
+ |
+
+
+ The firewall web interface becomes inaccessible and commits fail.
+
+ |
+
|
+ PAN-284067
+ |
+
+
+ A cumulative memory leak in the
+ devsrvr
+ process gets progressively worse whenever the CLI command
+ show running application statistics
+ is issued. This memory leak will gradually consume system memory and
+ produce an out-of-memory (OOM) condition, leading to an eventual
+ firewall reboot.
+
+
+ Workaround: Avoid using the CLI command:
+ show running application statistics.
+
+ |
+
|
+ PAN-281370
+ |
+
+
+ The Advanced WildFire Inline ML models
+ OOXML and
+ Mach-O erroneously display as being
+ available from the CLI; however, they are only available on PAN-OS
+ 11.1.3 and later releases.
+
+ |
+
|
+ PAN-273158
+ |
+
+
+ (PA-7000 Series firewalls only) Due to an
+ incorrect configuration on the ASIC, receiving a mix of jumbo and
+ non-jumbo packets may cause silent packet drops or application
+ slowness.
+
+ |
+
|
+ PAN-262287
+
+ This issue is now resolved. See PAN-OS 10.2.13 Addressed Issues.
+
+ |
+
+
+ Dereferencing a NULL pointer that occurs might cause
+ pan_task
+ processes to crash.
+
+ |
+
| + PAN-263226 (PAN-OS 10.2.9-h9 only) + | +
+
+ When SSL decryption is enabled and Client Hello messages span multiple
+ TCP segments, elements from the proxy_l2info memory pool may not be
+ freed properly. Memory leaks in this pool cause some SSL decryption
+ sessions to fail.
+
+
+ Workaround: Disable Client Hello accumulation
+ using the
+ debug dataplane set ssl-decrypt accumulate-client-hello disable
+ yes
+ CLI command.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
| PAN-259769 | +
+
+ GlobalProtect portal is not accessible via a web browser and the app
+ displays the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-251895
+
+ This issue is now resolved. See PAN-OS 10.2.10 Addressed Issues.
+
+ |
+
+
+ When Inline Cloud Analysis features are enabled, the firewall
+ experiences a slow packet buffer leak, resulting in poor performance
+ and dropped traffic.
+
+
+ Workaround: Disable WildFire Inline Cloud Analysis
+ and Advanced Threat Prevention Inline Cloud Analysis on the firewall.
+
+ |
+
|
+ PAN-251639
+
+ This issue is now resolved. See.
+ PAN-OS 10.2.9-h9 Addressed Issues.
+
+
+ This issue is now resolved. See PAN-OS 10.2.10 Addressed Issues.
+
+ |
+
+
+ An out of memory condition might occur due to a memory leak in the
+ varrcvr
+ process when a Wildfire Analysis security profile is enabled.
+
+ |
+
|
+ PAN-237106
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-223365
+ |
+
+
+ The Panorama management server is unable to query any logs if the
+ ElasticSearch health status for any Log Collector (
+ is degraded.
+
+
+ Workaround:
+ Log in to the Log Collector CLI
+ and restart ElasticSearch.
+
+
+
+
+
+ |
+
|
+ PAN-229865
+ |
+
+
+ Upgrading a PA-220 firewall running a PAN-OS 10.1 release fails when
+ the target PAN-OS upgrade version is PAN-OS 10.2.5.
+
+
+ Workaround: On your upgrade path to PAN-OS 10.2.5,
+ first upgrade to PAN-OS 10.2.4 and then upgrade to PAN-OS 10.2.5.
+
+ |
+
|
+ PAN-226361
+
+ This issue is now resolved. See PAN-OS 10.2.9-h14 Addressed Issues.
+
+ |
+
+
+ Sessions might end unexpectedly with the error
+ resources-unavailable when the
+ firewall incorrectly interprets the Content and Threat Detection (CTD)
+ global packet queue as being full.
+
+ |
+
|
+ PAN-223677
+ |
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, and PA-5430
+ firewalls) By enabling
+ Lockless QoS
+ feature, a slight degradation in App-ID and Threat performance is
+ expected.
+
+ |
+
|
+ PAN-222586
+ |
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus,
+ Forward Methods, and Built-In Actions for Correlation Log settings
+ () are not displayed and cannot be configured.
+
+ |
+
|
+ PAN-221775
+ |
+
+
+ A Malformed Request error is
+ displayed when you
+ Test Connection for an email server
+ profile () using SMTP over TLS and the
+ Password includes an ampersand
+ (&).
+
+ |
+
|
+ PAN-217307
+
+ This issue is now resolved. See PAN-OS 10.2.11 Addressed Issues.
+
+ |
+
+
+ The following Security policy rule () filters return no results:
+
+
+ log-start eq no
+
+ log-end eq no
+ log-end eq yes
+ |
+
|
+ PAN-213746
+ |
+
+
+ On the Panorama management server, the
+ Hostkey displayed as
+ undefined undefined if you
+ override an SSH Service Profile () Hostkey configured in a Template from the Template Stack.
+
+ |
+
|
+ PAN-213119
+ |
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you
+ view the Block IP list ():
+
+
+ show -> dis-block-table is unexpected
+
+ |
+
|
+ PAN-212889
+
+ This issue is now resolved. See
+ PAN-OS 10.2.14 Addressed Issues
+
+ |
+
+
+ On the Panorama management server, different threat names are used
+ when querying the same threat in the Threat Monitor () and ACC. This results in the ACC
+ displaying
+ no data to display when you are
+ redirected to the ACC after clicking a threat name in the Threat
+ Monitor and filtering the same threat name in the Global Filters.
+
+ |
+
|
+ PAN-212533
+ |
+
+
+ Modifying the Administrator Type for
+ an existing administrator (
+ or
+ ) from Superuser to a
+ Role-Based custom admin, or vice
+ versa, does not modify the access privileges of the administrator.
+
+ |
+
|
+ PAN-211531
+ |
+ + On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (). + | +
|
+ PAN-209288
+ |
+
+
+ Certificates are not successfully generated using SCEP ().
+
+ |
+
|
+ PAN-208622
+ |
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to
+ upload if you specify an Enterprise DLP data filtering profile (
+ with the Action set to Block to a
+ Security policy rule ().
+
+ |
+
|
+ PAN-204689
+ |
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do
+ not work:
+
+
|
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-196504
+ |
+ + License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). + | +
|
+ PAN-194996
+ |
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma
+ Access 3.1.2 deployment, allocating bandwidth for a remote network
+ deployment fails (the OK button is grayed out).
+
+
+ Workaround: Retry the operation.
+
+ |
+
|
+ PAN-194519
+ |
+
+
+ (PA-5450 firewall only) Trying to configure a
+ custom payload format under
+
+ yields a Javascript error.
+
+ |
+
|
+ PAN-194515
+ |
+
+
+ (PA-5450 firewall only) The Panorama web
+ interface does not display any predefined template stack variables in
+ the dropdown menu under
+ .
+
+
+ Workaround: Configure the log interface IP address
+ on the individual firewall web interface instead of on Panorama.
+
+ |
+
|
+ PAN-194424
+ |
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS
+ 10.2.2 while having a log interface configured can cause both the log
+ interface and the management interface to remain connected to the log
+ collector.
+
+
+ Workaround: Restart the log receiver service by
+ running the following CLI command:
+
+
+
+
+
+ |
+
|
+ PAN-194202
+ |
+
+
+ (PA-5450 firewall only) If the management
+ interface and logging interface are configured on the same subnetwork,
+ the firewall conducts log forwarding using the management interface
+ instead of the logging interface.
+
+ |
+
|
+ PAN-190727
+ |
+
+
+ (PA-5450 firewall only) Documentation for
+ configuring the log interface is unavailable on the web interface and
+ in the PAN-OS Administrator’s Guide.
+
+ |
+
|
+ PAN-189111
+ |
+
+
+ After deleting an MP pod and it comes up, the
+ show routing command output
+ appears empty and traffic stops working.
+
+ |
+
|
+ PAN-189076
+ |
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a
+ broadcast link and a designated router (DR) priority of 0 (zero) are
+ stuck in a two-way state after HA failover.
+
+
+ Workaround: Configure at least one OSPFv3 neighbor
+ with a non-zero priority setting in the same broadcast domain.
+
+ |
+
|
+ PAN-188358
+ |
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management
+ port LEDs do not light up when a 10G Ethernet cable is plugged in.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187643
+ |
+
+
+ If you enable SCTP security using a Panorama template when
+ SCTP INIT Flood Protection is
+ enabled in the Zone Protection profile using Panorama and you commit
+ all changes, the commit is successful but the
+ SCTP INIT option is not available in
+ the Zone Protection profile.
+
+
+ Workaround: Log out of the firewall and log in
+ again to make the SCIT INIT option
+ available on the web interface.
+
+ |
+
|
+ PAN-187612
+ |
+
+
+ On the Panorama management server, not all data profiles () are displayed after you:
+
+
+ Workaround: Log in to the Panorama CLI and reset
+ the DLP plugin.
+
+ admin > request plugins dlp reset
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-187370
+ |
+
+
+ On a firewall with Advanced Routing enabled, if there is also a
+ logical router instance that uses the default configuration and has no
+ interfaces assigned to it, this will result in terminating the
+ management daemon and main routing daemon in the firewall during
+ commit.
+
+
+ Workaround: Do not use a logical router instance
+ with no interfaces bound to it.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-186282
+ |
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match
+ criteria automatically when adding dynamic address groups.
+
+
+ Workaround: Reboot the Panorama HA pair.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-181823
+ |
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer
+ port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports
+ on the firewall to go down if they are set to Auto.
+
+ |
+
|
+ PAN-180661
+ |
+
+
+ On the Panorama management server, pushing an unsupported Minimum
+ Password Complexity () to a managed firewall erroneously displays
+ commit time out as the reason the
+ commit failed.
+
+ |
+
|
+ PAN-180104
+ |
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2,
+ CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster
+ previously had a CN-Series as a DaemonSet deployment running PAN-OS
+ 10.0 or 10.1.
+
+
+ Workaround: Reboot the worker nodes before
+ upgrading to PAN-OS 10.2.
+
+ |
+
|
+ PAN-178194
+ |
+
+
+ A user interface issue in PAN-OS renders the contents of the
+ Inline ML tab in the
+ URL Filtering Profile inaccessible
+ on firewalls licensed for Advanced URL Filtering. Additionally, a
+ message indicating that a
+ License required for URL filtering to function
+ is unavailable displays at the bottom of the UI. These errors do not
+ affect the operation of Advanced URL Filtering or URL Filtering Inline
+ ML.
+
+
+ Workaround: Configuration settings for URL
+ Filtering Inline ML must be applied through the CLI. The following
+ configuration commands are available:
+
+
|
+
|
+ PAN-177455
+ |
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA
+ (High Availability) clustering enabled and using an HA4 communication
+ link. Attempting to load PAN-OS 10.2.0 on the firewall causes the
+ PA-7000 100G NPC to go offline. As a result, the firewall fails to
+ boot normally and enters maintenance mode. HA Pairs of Active-Passive
+ and Active-Active firewalls are not affected.
+
+ |
+
|
+ PAN-175915
+ |
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks
+ and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network
+ Protection Profile, the traffic logs do not display network slice SST
+ and SD values.
+
+ |
+
|
+ PAN-174982
+ |
+
+
+ In HA active/active configurations where, when interfaces that were
+ associated with a virtual router were deleted, the configuration
+ change did not sync.
+
+ |
+
|
+ PAN-172274
+ |
+
+
+ When you activate the advanced URL filtering license, your license
+ entitlements for PAN-DB and advanced URL filtering might not display
+ correctly on the firewall — this is a display anomaly, not a licensing
+ issue, and does not affect access to the services.
+
+
+ Workaround: Issue the following command to
+ retrieve and update the licenses:
+ license request fetch.
+
+ |
+
|
+ PAN-171938
+ |
+
+
+ No results are displayed when you
+ Show Application Filter for a
+ Security policy rule ().
+
+ |
+
|
+ PAN-164885
+
+ This issue is now resolved. See PAN-OS 10.2.10 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, pushes to managed firewalls (
+ or Commit and Push) may fail when an
+ EDL () is configured to
+ Check for updates every 5 minutes
+ due to the commit and EDL fetch processes overlapping. This is more
+ likely to occur when multiple EDLs are configured to check for updates
+ every 5 minutes.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-5632
+ |
+
+
+ The number of registered WildFire appliances reported in Panorama
+ () does not accurately reflect the current status of connected
+ WildFire appliances.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-234408
+ |
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for
+ ChatGPT from traffic forwarded to the DLP cloud service from an NGFW.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-243951
+ |
+
+
+ On the Panorama management sever in an active/passive High
+ Availability (HA) configuration, managed devices () display as out-of-sync on the
+ passive HA peer when configuration changes are made to the SD-WAN
+ () configuration on the active HA peer.
+
+
+ Workaround: Manually synchronize the Panorama HA
+ peers.
+
+
|
+
|
+ PAN-242910
+ |
+
+
+ On the Panorama management server, Panorama administrators () that are assigned a custom Panorama admin role () with Push All Changes enabled are
+ unable to push configuration changes to managed firewalls when
+ Managed Devices and
+ Push For Other Admins are disabled.
+
+ |
+
|
+ PAN-241041
+ |
+
+
+ On the Panorama management server exporting template or template stack
+ variables () in CSV format results in an empty CSV file.
+
+ |
+
|
+ PAN-229702
+ |
+
+
+ After upgrading a Panorama HA pair to PAN-OS 11.1, the ElasticSearch
+ connectivity might fail to establish. The issue occurs because the
+ client certificate on one of the Panorama devices does not have the
+ necessary Extended Key Usage (EKU) set for server authentication,
+ which is required for secure TLS communication.
+
+
+ Workaround:Contact Customer Support to renew the
+ root client certificate.
+
+ |
+
|
+ PAN-228515
+ |
+
+
+ The EleasticSearch SSH flaps on the M-600 appliance in Panorama or Log
+ Collector mode. This causes logs to not display on the Panorama
+ management server () and the Log Collector health status () to display as degraded.
+
+ |
+
|
+ PAN-228273
+ |
+
+
+ On the Panorama management server in FIPS-CC mode, the ElasticSearch
+ cluster fails to come up and the
+ show log-collector-es-cluster health
+ command displays the status is
+ red. This results in log
+ ingestion issues for Panorama in Panorama only or Log Collector mode.
+
+ |
+
|
+ PAN-227344
+ |
+
+
+ On the Panorama management server, PDF Summary Reports () display no data and are blank when predefined reports are included
+ in the summary report.
+
+ |
+
|
+ PAN-225886
+ |
+
+
+ If you enable explicit proxy mode for the web proxy, intermittent
+ errors and unexpected TCP reconnections may occur.
+
+ |
+
|
+ PAN-225337
+
+ This issue is now resolved. See
+ PAN-OS 11.0.4 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, the configuration push to a
+ multi-vsys firewall fails if you:
+
+
+ Workaround: Select
+
+ and edit the Panorama Settings to enable one of the following:
+
+
+ Alternatively, you can remove the duplicate address objects from the
+ device group configuration to allow only the
+ Shared objects in your
+ configuration.
+
+ |
+
|
+ PAN-223488
+
+ This issue is now resolved. See PAN-OS 11.0.3 Addressed Issues.
+
+ |
+
+
+ Closed ElasticSearch shards are not deleted from the Panorama M-Series
+ and virtual appliance. This causes the ElasticSearch shard purging to
+ not work as expected, resulting in high disk usage.
+
+ |
+
|
+ PAN-223365
+
+ This issue is now resolved. See PAN-OS 11.0.4 Addressed Issues.
+
+ |
+
+
+ The Panorama management server is unable to query any logs if the
+ ElasticSearch health status for any Log Collector (
+ is degraded.
+
+
+ Workaround:
+ Log in to the Log Collector CLI
+ and restart ElasticSearch.
+
+
+
+
+
+ |
+
|
+ PAN-222586
+ |
+
+
+ On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter
+ dropdown menus, Forward Methods, and Built-In Actions for Correlation
+ Log settings () are not displayed and cannot be configured.
+
+ |
+
|
+ PAN-222253
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, policy rulebase reordering when you
+ View Rulebase by Groups () does not persist if you reorder the policy rulebase by dragging and
+ dropping individual policy rules and then moving the entire tag group.
+
+ |
+
|
+ PAN-221015
+
+ This issue is now resolved. See
+ PAN-OS 11.0.4 Addressed Issues.
+
+ |
+
+
+ On M-600 appliances in Panorama or Log Collector mode, the
+ es-1 and
+ es-2 ElasticSearch processes fail
+ to restart when the M-600 appliance is rebooted. The results in the
+ Managed Collector ES health
+ status () to be degraded.
+
+
+ Workaround:
+ Log in to the Panorama or Log Collector CLI
+ experiencing degraded ElasticSearch health and restart all
+ ElasticSearch processes.
+
+
+
+
+
+ |
+
|
+ PAN-220180
+
+ This issue is now resolved. See PAN-OS 11.0.3 Addressed Issues.
+
+ |
+
+
+ Configured botnet reports () are not generated.
+
+ |
+
|
+ PAN-219644
+
+ This issue is now resolved. See PAN-OS 11.0.3 Addressed Issues.
+
+ |
+
+
+ Firewalls forwarding logs to a syslog server over TLS () use the default Palo Alto Networks certificate instead of the
+ custom certificate configured on the firewall.
+
+ |
+
|
+ PAN-218521
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues.
+
+ |
+
+
+ The ElasticSearch process on the M-600 appliance in Log Collector mode
+ may enter a continuous reboot cycle. This results in the M-600
+ appliance becoming unresponsive, consuming logging disk space, and
+ preventing new log ingestion.
+
+ |
+
|
+ PAN-217307
+ |
+
+
+ The following Security policy rule () filters return no results:
+
+
+ log-start eq no
+
+ log-end eq no
+ log-end eq yes
+ |
+
|
+ PAN-216214
+ |
+
+
+ For Panorama-managed firewalls in an Active/Active High Availability
+ (HA) configuration where you configure the firewall HA settings () in a template or template stack (), performing a local commit on one of the HA firewalls triggers an
+ HA config sync on the peer firewall. This causes the HA peer
+ configuration to go Out of Sync.
+
+ |
+
|
+ PAN-215778
+ |
+
+
+ On the M-600 appliance in Management Only mode, XML API Get requests
+ for /config fail with the
+ following error due to exceeding the
+ total configuration size
+ supported on the M-600 appliance.
+
+
+
+
+
+ |
+
|
+ PAN-215082
+ |
+
+
+ M-300 and M-700 appliances may generate erroneous system logs () to alert that the M-Series appliance memory usage limits are
+ reached.
+
+ |
+
|
+ PAN-213746
+ |
+
+
+ On the Panorama management server, the
+ Hostkey displayed as
+ undefined undefined if you
+ override an SSH Service Profile () Hostkey configured in a Template from the Template Stack.
+
+ |
+
|
+ PAN-213119
+ |
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you
+ view the Block IP list ():
+
+
+ show -> dis-block-table is unexpected
+
+ |
+
|
+ PAN-212889
+ |
+
+
+ On the Panorama management server, different threat names are used
+ when querying the same threat in the Threat Monitor () and ACC. This results in the ACC
+ displaying
+ no data to display when you are
+ redirected to the ACC after clicking a threat name in the Threat
+ Monitor and filtering the same threat name in the Global Filters.
+
+ |
+
|
+ PAN-212533
+ |
+
+
+ Modifying the Administrator Type for
+ an existing administrator (
+ or
+ ) from Superuser to a
+ Role-Based custom admin, or vice
+ versa, does not modify the access privileges of the administrator.
+
+ |
+
|
+ PAN-211531
+ |
+ + On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (). + | +
|
+ PAN-209937
+
+ This issue is now resolved. See PAN-OS 11.0.2 Addressed Issues.
+
+ |
+
+
+ Certificate-based authentication for administrator accounts may be
+ unable to log into the Panorama or firewall web interface with the
+ following error:
+
+
+ Bad Request - Your browser sent a request that this server could
+ not understand
+
+ |
+
|
+ PAN-208325
+
+ This issue is now resolved. See PAN-OS 11.0.2 Addressed Issues.
+
+ |
+
+
+ The following NextGen firewalls and Panorama management server models
+ are unable to automatically renew the device certificate (
+ or
+ ).
+
+
+ Workaround: Log in to the
+ firewall CLI
+ or
+ Panorama CLI
+ and fetch the device certificate.
+
+
+
+
+
+ |
+
|
+ PAN-208189
+
+ This issue is now resolved. See PAN-OS 11.0.1-h2 Addressed Issues.
+
+ |
+
+
+ Traffic fails to match and reach all destinations if a Security policy
+ rule includes FQDN objects that resolve to two or more IP addresses.
+
+ |
+
|
+ PAN-207770
+ |
+
+
+ Data filtering logs () incorrectly display the traffic Direction as
+ server-to-client instead of
+ client-to-server for upload
+ traffic that matches Enterprise data loss prevention (DLP) data
+ patterns () in an Enterprise DLP data filtering profile ().
+
+ |
+
|
+ PAN-207733
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if
+ the DHCPv6 server goes down, after the lease time expires, the DHCPv6
+ client should enter SOLICIT state on both the Active and Passive
+ firewalls. Instead, the client is stuck in BOUND state with an IPv6
+ address having lease time 0 on the Passive firewall.
+
+ |
+
|
+ PAN-207629
+ |
+
+
+ On the Panorama management server, selective push fails to managed
+ firewalls if the managed firewalls are enabled with multiple vsys and
+ the Push Scope contains shared objects in device groups.
+
+ |
+
|
+ PAN-207616
+ |
+
+
+ On the Panorama management server, after selecting managed firewalls
+ and creating a new Tag () the managed firewalls are automatically unselected and any new tag
+ created is applied to the managed firewalls for which you initially
+ created the new tag.
+
+
+ Workaround: Select and then unselect the managed
+ firewalls for which you created a new tag.
+
+ |
+
|
+ PAN-207611
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the
+ Passive firewall sometimes crashes.
+
+ |
+
|
+ PAN-207040
+ |
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade
+ from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
+ commits fail and SD-WAN devices on Panorama have no Virtual Router
+ name.
+
+ |
+
|
+ PAN-206913
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls,
+ releasing the IPv6 address from the client (using Release in the UI or
+ using the
+ request dhcp client ipv6 release all
+ CLI command) releases the IPv6 address from the Active firewall, but
+ not the Passive firewall.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the
+ configd process crashes. This
+ results in the Dedicated Log Collector losing connectivity to Panorama
+ despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-206416
+ |
+
+
+ On the Panorama management server, no data filtering log () is generated when the managed firewall loses connectivity to the
+ following cloud services, and as a result fails to forward matched
+ traffic for inspection.
+
+
|
+
|
+ PAN-206315
+ |
+
+
+ (PA-1420 firewall only) In an active/passive
+ high availability (HA) configuration, the
+ show session info CLI command
+ shows that the passive firewall has packet rate and throughput values.
+ The packet rate and throughput of the passive firewall should be zero
+ since it is not processing traffic.
+
+ |
+
|
+ PAN-206253
+
+ This issue is now resolved. See PAN-OS 11.0.2 Addressed Issues.
+
+ |
+
+
+ For PA-1400 and PA-3400 Series firewalls, the default log rate is set
+ too low and the max configurable log rate is incorrectly capped
+ resulting in the firewall not generating more than 6,826 logs per
+ second.
+
+ |
+
|
+ PAN-206005
+
+ This issue is now resolved. See PAN-OS 11.0.1 Addressed Issues.
+
+ |
+
+
+ (PA-1400 Series, PA-3400 Series, and PA-5440 firewalls only) The I7_misc memory pool on these platforms is undersized and can
+ cause a loss of connectivity when reaching the limit of the memory
+ pool. Certain features, like using a decryption profile with Strip
+ ALPN disabled, can lead to depleting the memory pool and causing a
+ connection loss.
+
+
+ Workaround: Disable HTTP2 by enabling Strip ALPN
+ in the decryption profile or avoid usage of the I7_misc memory pool.
+
+ |
+
|
+ PAN-205255
+
+ This issue is now resolved. See PAN-OS 11.0.1 Addressed Issues.
+
+ |
+
+
+ There is a rare PAN-OS issue that causes the dataplane to restart
+ unexpectedly.
+
+ |
+
|
+ PAN-205187
+ |
+
+
+ ElasticSearch may not start properly when a newly installed Panorama
+ virtual appliance powers on for the first time, resulting in the
+ Panorama virtual appliance being unable to query logs forwarded from
+ the managed firewall to a Log Collector.
+
+
+ Workaround:
+ Log in to the Panorama CLI
+ and start the PAN-OS software.
+
+
+
+
+
+ |
+
|
+ PAN-205009
+ |
+
+
+ (PA-1420 firewall only) In an active/passive
+ high availability (HA) configuration, the
+ show interface all,
+ show-high availability interface ha2, and
+ show high-availability all CLI
+ commands display the HSCI port state as unknown on both the active and
+ passive firewalls.
+
+ |
+
|
+ PAN-204615
+
+ This issue is now resolved. See PAN-OS 11.0.0 Known Issues.
+
+ |
+
+
+ BGP sessions can flap even when an unrelated configuration is
+ committed. This results in the BGP session going down and getting
+ established again. As a result, BGP routes get exchanged again, which
+ can lead to momentary traffic disruption if BGP routes were in use for
+ establishing traffic.
+
+ |
+
|
+ PAN-201910
+ |
+
+
+ PAN-OS security profiles might consume a large amount of memory
+ depending on the profile configuration and quantity. In some cases,
+ this might reduce the number of supported security profiles below the
+ stated maximum for a given platform.
+
+ |
+
|
+ PAN-201855
+ |
+
+
+ On the Panorama management server, cloning any template () corrupts certificates () with the
+ Block Private Key Export setting
+ enabled across all templates. This results in managed firewalls
+ experiencing issues wherever the corrupted certificate is referenced.
+
+
+ For example, you have template A, B, and C where templates A and B
+ have certificates with the
+ Block Private Key Export setting
+ enabled. Cloning template C corrupts the certificates with
+ Block Private Key Export setting
+ enabled in templates A and B.
+
+
+ Workaround: After cloning a template, delete and
+ re-import the corrupted certificates.
+
+ |
+
|
+ PAN-199557
+ |
+
+
+ On M-600 appliances in an Active/Passive high availability (HA)
+ configuration, the
+ configd process restarts due to a
+ memory leak on the
+ Active Panorama HA peer. This
+ causes the Panorama web interface and CLI to become unresponsive.
+
+
+ Workaround: Manually reboot the
+ Active Panorama HA peer.
+
+ |
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-197097
+ |
+
+
+ Large Scale VPN (LSVPN) does not support IPv6 addresses on the
+ satellite firewall.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-196146
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues.
+
+ |
+
+
+ The VM-Series firewall on Azure does not boot up with a hostname
+ (specified in an init-cgf.txt or user data) when bootstrapped.
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
| PAN-195568 | +
+
+ When PAN-OS 11.0 is installed on multiple data plane platforms, users
+ are unable to connect to the GlobalProtect portal or gateway.
+
+ |
+
|
+ PAN-195342
+ |
+
+
+ On the Panorama management server, Context Switch fails when you try
+ to Context Switch from a managed firewall running PAN-OS 10.1.7 or
+ earlier release back to Panorama and the following error is displayed:
+
+
+ Could not find start token '@start@'
+
+ |
+
|
+ PAN-194978
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , hovering the mouse over a power over Ethernet (PoE)
+ Link State icon does not display
+ link speed and link duplex details.
+
+ |
+
|
+ PAN-194424
+ |
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS
+ 10.2.2 while having a log interface configured can cause both the log
+ interface and the management interface to remain connected to the log
+ collector.
+
+
+ Workaround: Restart the log receiver service by
+ running the following CLI command:
+
+
+
+
+
+ |
+
|
+ PAN-192282
+
+ This issue is now resolved. See PAN-OS 11.0.1 Addressed Issues.
+
+ |
+
+
+ (PA-415 and PA-445 firewalls only) In 1G mode,
+ the MGT and Ethernet 1/1 port LEDs glow amber instead of green.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-184708
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
|
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-182734
+
+ This issue is now resolved. See PAN-OS 11.0.2 Addressed Issues.
+
+ |
+
+
+ On an Advanced Routing Engine, if you change the IPSec tunnel
+ configuration, BGP flaps.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-171938
+ |
+
+
+ No results are displayed when you
+ Show Application Filter for a
+ Security policy rule ().
+
+ |
+
|
+ PAN-164885
+ |
+
+
+ On the Panorama management server, pushes to managed firewalls (
+ or Commit and Push) may fail when an
+ EDL () is configured to
+ Check for updates every 5 minutes
+ due to the commit and EDL fetch processes overlapping. This is more
+ likely to occur when multiple EDLs are configured to check for updates
+ every 5 minutes.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-5632
+ |
+
+
+ The number of registered WildFire appliances reported in Panorama
+ () does not accurately reflect the current status of connected
+ WildFire appliances.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-243951
+ |
+
+
+ On the Panorama management sever in an active/passive High
+ Availability (HA) configuration, managed devices () display as out-of-sync on the
+ passive HA peer when configuration changes are made to the SD-WAN
+ () configuration on the active HA peer.
+
+
+ Workaround: Manually synchronize the Panorama HA
+ peers.
+
+
|
+
|
+ PAN-234408
+ |
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for
+ ChatGPT from traffic forwarded to the DLP cloud service from an NGFW.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-242910
+ |
+
+
+ On the Panorama management server, Panorama administrators () that are assigned a custom Panorama admin role () with Push All Changes enabled are
+ unable to push configuration changes to managed firewalls when
+ Managed Devices and
+ Push For Other Admins are disabled.
+
+ |
+
|
+ PAN-241041
+ |
+
+
+ On the Panorama management server exporting template or template stack
+ variables () in CSV format results in an empty CSV file.
+
+ |
+
|
+ PAN-228515
+ |
+
+
+ The EleasticSearch SSH flaps on the M-600 appliance in Panorama or Log
+ Collector mode. This causes logs to not display on the Panorama
+ management server () and the Log Collector health status () to display as degraded.
+
+ |
+
|
+ PAN-228273
+ |
+
+
+ On the Panorama management server in FIPS-CC mode, the ElasticSearch
+ cluster fails to come up and the
+ show log-collector-es-cluster health
+ command displays the status is
+ red. This results in log
+ ingestion issues for Panorama in Panorama only or Log Collector mode.
+
+ |
+
|
+ PAN-227344
+ |
+
+
+ On the Panorama management server, PDF Summary Reports () display no data and are blank when predefined reports are included
+ in the summary report.
+
+ |
+
|
+ PAN-225886
+ |
+
+
+ If you enable explicit proxy mode for the web proxy, intermittent
+ errors and unexpected TCP reconnections may occur.
+
+ |
+
|
+ PAN-225337
+
+ This issue is now resolved. See
+ PAN-OS 11.0.4 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, the configuration push to a
+ multi-vsys firewall fails if you:
+
+
+ Workaround: Select
+
+ and edit the Panorama Settings to enable one of the following:
+
+
+ Alternatively, you can remove the duplicate address objects from the
+ device group configuration to allow only the
+ Shared objects in your
+ configuration.
+
+ |
+
|
+ PAN-223488
+
+ This issue is now resolved. See PAN-OS 11.0.3 Addressed Issues.
+
+ |
+
+
+ Closed ElasticSearch shards are not deleted from the Panorama M-Series
+ and virtual appliance. This causes the ElasticSearch shard purging to
+ not work as expected, resulting in high disk usage.
+
+ |
+
|
+ PAN-223365
+
+ This issue is now resolved. See PAN-OS 11.0.4 Addressed Issues.
+
+ |
+
+
+ The Panorama management server is unable to query any logs if the
+ ElasticSearch health status for any Log Collector (
+ is degraded.
+
+
+ Workaround:
+ Log in to the Log Collector CLI
+ and restart ElasticSearch.
+
+
+
+
+
+ |
+
|
+ PAN-222586
+ |
+
+
+ On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter
+ dropdown menus, Forward Methods, and Built-In Actions for Correlation
+ Log settings () are not displayed and cannot be configured.
+
+ |
+
|
+ PAN-222253
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, policy rulebase reordering when you
+ View Rulebase by Groups () does not persist if you reorder the policy rulebase by dragging and
+ dropping individual policy rules and then moving the entire tag group.
+
+ |
+
|
+ PAN-221126
+
+ This issue is now resolved. See PAN-OS 11.0.3 Addressed Issues.
+
+ |
+
+
+ Email server profiles (
+ and
+ ) to forward logs as email notifications are not forwarded in a
+ readable format.
+
+
+ Workaround: Use a
+ Custom Log Format to forward logs as
+ email notifications in a readable format.
+
+ |
+
|
+ PAN-221015
+
+ This issue is now resolved. See
+ PAN-OS 11.0.4 Addressed Issues.
+
+ |
+
+
+ On M-600 appliances in Panorama or Log Collector mode, the
+ es-1 and
+ es-2 ElasticSearch processes fail
+ to restart when the M-600 appliance is rebooted. The results in the
+ Managed Collector ES health
+ status () to be degraded.
+
+
+ Workaround:
+ Log in to the Panorama or Log Collector CLI
+ experiencing degraded ElasticSearch health and restart all
+ ElasticSearch processes.
+
+
+
+
+
+ |
+
|
+ PAN-220180
+
+ This issue is now resolved. See PAN-OS 11.0.3 Addressed Issues.
+
+ |
+
+
+ Configured botnet reports () are not generated.
+
+ |
+
|
+ PAN-220176
+ |
+
+
+ (PAN-OS 11.0.1-h2 hotfix) System process
+ crashes might occur with VoIP traffic when NAT is enabled with
+ Persistent Dynamic IP and Port settings.
+
+ |
+
|
+ PAN-219644
+
+ This issue is now resolved. See PAN-OS 11.0.3 Addressed Issues.
+
+ |
+
+
+ Firewalls forwarding logs to a syslog server over TLS () use the default Palo Alto Networks certificate instead of the
+ custom certificate configured on the firewall.
+
+ |
+
|
+ PAN-218521
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues.
+
+ |
+
+
+ The ElasticSearch process on the M-600 appliance in Log Collector mode
+ may enter a continuous reboot cycle. This results in the M-600
+ appliance becoming unresponsive, consuming logging disk space, and
+ preventing new log ingestion.
+
+ |
+
|
+ PAN-217307
+ |
+
+
+ The following Security policy rule () filters return no results:
+
+
+ log-start eq no
+
+ log-end eq no
+ log-end eq yes
+ |
+
|
+ PAN-216821
+
+ This issue is now resolved. See PAN-OS 11.0.2 Addressed Issues.
+
+ |
+
+
+ The reportd process crashes after
+ you successfully upgrade an M-200 appliance to PAN-OS 10.2.4.
+
+ |
+
|
+ PAN-216314
+ |
+
+
+ Upon upgrade or downgrade to or from PAN-OS 10.1.9 or 10.1.9-h1,
+ offloaded application traffic sessions may disconnect after a period
+ of time even if a session is active. The disconnect occurs after the
+ application's default session timeout value is exceeded. This behavior
+ affects only PAN-OS 10.1.9 and 10.1.9-h1. If you are on PAN-OS 10.1.9
+ and 10.1.9-h1, please use the following workaround. If you have
+ already upgraded or downgraded to another PAN-OS version, use the
+ following workaround in that version.
+
+
+ Workaround: Run the CLI command
+ debug dataplane internal pdt fe100 csr wr_sem_ctrl_ctr_scan_dis
+ value 0
+ to set the value to zero (0).
+
+ |
+
|
+ PAN-216214
+ |
+
+
+ For Panorama-managed firewalls in an Active/Active High Availability
+ (HA) configuration where you configure the firewall HA settings () in a template or template stack (), performing a local commit on one of the HA firewalls triggers an
+ HA config sync on the peer firewall. This causes the HA peer
+ configuration to go Out of Sync.
+
+ |
+
|
+ PAN-215778
+ |
+
+
+ On the M-600 appliance in Management Only mode, XML API Get requests
+ for /config fail with the
+ following error due to exceeding the
+ total configuration size
+ supported on the M-600 appliance.
+
+
+
+
+
+ |
+
|
+ PAN-215082
+ |
+
+
+ M-300 and M-700 appliances may generate erroneous system logs () to alert that the M-Series appliance memory usage limits are
+ reached.
+
+ |
+
|
+ PAN-213746
+ |
+
+
+ On the Panorama management server, the
+ Hostkey displayed as
+ undefined undefined if you
+ override an SSH Service Profile () Hostkey configured in a Template from the Template Stack.
+
+ |
+
|
+ PAN-213119
+ |
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you
+ view the Block IP list ():
+
+
+ show -> dis-block-table is unexpected
+
+ |
+
|
+ PAN-212889
+ |
+
+
+ On the Panorama management server, different threat names are used
+ when querying the same threat in the Threat Monitor () and ACC. This results in the ACC
+ displaying
+ no data to display when you are
+ redirected to the ACC after clicking a threat name in the Threat
+ Monitor and filtering the same threat name in the Global Filters.
+
+ |
+
|
+ PAN-211531
+ |
+ + On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (). + | +
|
+ PAN-209937
+
+ This issue is now resolved. See PAN-OS 11.0.2 Addressed Issues.
+
+ |
+
+
+ Certificate-based authentication for administrator accounts may be
+ unable to log into the Panorama or firewall web interface with the
+ following error:
+
+
+ Bad Request - Your browser sent a request that this server could
+ not understand
+
+ |
+
|
+ PAN-208325
+
+ This issue is now resolved. See PAN-OS 11.0.2 Addressed Issues.
+
+ |
+
+
+ The following NextGen firewalls and Panorama management server models
+ are unable to automatically renew the device certificate (
+ or
+ ).
+
+
+ Workaround: Log in to the
+ firewall CLI
+ or
+ Panorama CLI
+ and fetch the device certificate.
+
+
+
+
+
+ |
+
|
+ PAN-208189
+
+ This issue is now resolved. See PAN-OS 11.0.1-h2 Addressed Issues.
+
+ |
+
+
+ Traffic fails to match and reach all destinations if a Security policy
+ rule includes FQDN objects that resolve to two or more IP addresses.
+
+ |
+
|
+ PAN-207770
+ |
+
+
+ Data filtering logs () incorrectly display the traffic Direction as
+ server-to-client instead of
+ client-to-server for upload
+ traffic that matches Enterprise data loss prevention (DLP) data
+ patterns () in an Enterprise DLP data filtering profile ().
+
+ |
+
|
+ PAN-207733
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if
+ the DHCPv6 server goes down, after the lease time expires, the DHCPv6
+ client should enter SOLICIT state on both the Active and Passive
+ firewalls. Instead, the client is stuck in BOUND state with an IPv6
+ address having lease time 0 on the Passive firewall.
+
+ |
+
|
+ PAN-207616
+ |
+
+
+ On the Panorama management server, after selecting managed firewalls
+ and creating a new Tag () the managed firewalls are automatically unselected and any new tag
+ created is applied to the managed firewalls for which you initially
+ created the new tag.
+
+
+ Workaround: Select and then unselect the managed
+ firewalls for which you created a new tag.
+
+ |
+
|
+ PAN-207611
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the
+ Passive firewall sometimes crashes.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-207040
+ |
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade
+ from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
+ commits fail and SD-WAN devices on Panorama have no Virtual Router
+ name.
+
+ |
+
|
+ PAN-206913
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls,
+ releasing the IPv6 address from the client (using Release in the UI or
+ using the
+ request dhcp client ipv6 release all
+ CLI command) releases the IPv6 address from the Active firewall, but
+ not the Passive firewall.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the
+ configd process crashes. This
+ results in the Dedicated Log Collector losing connectivity to Panorama
+ despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-206416
+ |
+
+
+ On the Panorama management server, no data filtering log () is generated when the managed firewall loses connectivity to the
+ following cloud services, and as a result fails to forward matched
+ traffic for inspection.
+
+
|
+
|
+ PAN-206315
+ |
+
+
+ (PA-1420 firewall only) In an active/passive
+ high availability (HA) configuration, the
+ show session info CLI command
+ shows that the passive firewall has packet rate and throughput values.
+ The packet rate and throughput of the passive firewall should be zero
+ since it is not processing traffic.
+
+ |
+
|
+ PAN-205009
+ |
+
+
+ (PA-1420 firewall only) In an active/passive
+ high availability (HA) configuration, the
+ show interface all,
+ show-high availability interface ha2, and
+ show high-availability all CLI
+ commands display the HSCI port state as unknown on both the active and
+ passive firewalls.
+
+ |
+
|
+ PAN-204689
+ |
+
+
+ Upon upgrade to PAN-OS 11.0.1, the following GlobalProtect settings do
+ not work:
+
+
|
+
|
+ PAN-201910
+ |
+
+
+ PAN-OS security profiles might consume a large amount of memory
+ depending on the profile configuration and quantity. In some cases,
+ this might reduce the number of supported security profiles below the
+ stated maximum for a given platform.
+
+ |
+
|
+ PAN-199557
+ |
+
+
+ On M-600 appliances in an Active/Passive high availability (HA)
+ configuration, the
+ configd process restarts due to a
+ memory leak on the
+ Active Panorama HA peer. This
+ causes the Panorama web interface and CLI to become unresponsive.
+
+
+ Workaround: Manually reboot the
+ Active Panorama HA peer.
+
+ |
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-197097
+ |
+
+
+ Large Scale VPN (LSVPN) does not support IPv6 addresses on the
+ satellite firewall.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-196146
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues.
+
+ |
+
+
+ The VM-Series firewall on Azure does not boot up with a hostname
+ (specified in an init-cgf.txt or user data) when bootstrapped.
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-195342
+ |
+
+
+ On the Panorama management server, Context Switch fails when you try
+ to Context Switch from a managed firewall running PAN-OS 10.1.7 or
+ earlier release back to Panorama and the following error is displayed:
+
+
+ Could not find start token '@start@'
+
+ |
+
|
+ PAN-194978
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , hovering the mouse over a power over Ethernet (PoE)
+ Link State icon does not display
+ link speed and link duplex details.
+
+ |
+
|
+ PAN-194424
+ |
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS
+ 10.2.2 while having a log interface configured can cause both the log
+ interface and the management interface to remain connected to the log
+ collector.
+
+
+ Workaround: Restart the log receiver service by
+ running the following CLI command:
+
+
+
+
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-184708
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
|
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-182734
+
+ This issue is now resolved. See PAN-OS 11.0.2 Addressed Issues.
+
+ |
+
+
+ On an Advanced Routing Engine, if you change the IPSec tunnel
+ configuration, BGP flaps.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-171938
+ |
+
+
+ No results are displayed when you
+ Show Application Filter for a
+ Security policy rule ().
+
+ |
+
|
+ PAN-164885
+ |
+
+
+ On the Panorama management server, pushes to managed firewalls (
+ or Commit and Push) may fail when an
+ EDL () is configured to
+ Check for updates every 5 minutes
+ due to the commit and EDL fetch processes overlapping. This is more
+ likely to occur when multiple EDLs are configured to check for updates
+ every 5 minutes.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-5632
+ |
+
+
+ The number of registered WildFire appliances reported in Panorama
+ () does not accurately reflect the current status of connected
+ WildFire appliances.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-243951
+ |
+
+
+ On the Panorama management sever in an active/passive High
+ Availability (HA) configuration, managed devices () display as out-of-sync on the
+ passive HA peer when configuration changes are made to the SD-WAN
+ () configuration on the active HA peer.
+
+
+ Workaround: Manually synchronize the Panorama HA
+ peers.
+
+
|
+
|
+ PAN-234408
+ |
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for
+ ChatGPT from traffic forwarded to the DLP cloud service from an NGFW.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-242910
+ |
+
+
+ On the Panorama management server, Panorama administrators () that are assigned a custom Panorama admin role () with Push All Changes enabled are
+ unable to push configuration changes to managed firewalls when
+ Managed Devices and
+ Push For Other Admins are disabled.
+
+ |
+
|
+ PAN-241041
+ |
+
+
+ On the Panorama management server exporting template or template stack
+ variables () in CSV format results in an empty CSV file.
+
+ |
+
|
+ PAN-231507
+
+ This issue is now resolved. See PAN-OS 11.0.4 Addressed Issues.
+
+ |
+
+
+ On PA-1400 Series firewalls only, when an HSCI interface is used as an
+ HA2 interface, HA2 packets are intermittently dropped on the passive
+ device, which can cause the HA2 connection to flap due to missing HA2
+ keepalive messages. Workaround: use data ports configured as HA2
+ interface.
+
+ |
+
|
+ PAN-228515
+ |
+
+
+ The EleasticSearch SSH flaps on the M-600 appliance in Panorama or Log
+ Collector mode. This causes logs to not display on the Panorama
+ management server () and the Log Collector health status () to display as degraded.
+
+ |
+
|
+ PAN-228273
+ |
+
+
+ On the Panorama management server in FIPS-CC mode, the ElasticSearch
+ cluster fails to come up and the
+ show log-collector-es-cluster health
+ command displays the status is
+ red. This results in log
+ ingestion issues for Panorama in Panorama only or Log Collector mode.
+
+ |
+
|
+ PAN-227344
+ |
+
+
+ On the Panorama management server, PDF Summary Reports () display no data and are blank when predefined reports are included
+ in the summary report.
+
+ |
+
|
+ PAN-225886
+ |
+
+
+ If you enable explicit proxy mode for the web proxy, intermittent
+ errors and unexpected TCP reconnections may occur.
+
+ |
+
|
+ PAN-225337
+
+ This issue is now resolved. See
+ PAN-OS 11.0.4 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, the configuration push to a
+ multi-vsys firewall fails if you:
+
+
+ Workaround: Select
+
+ and edit the Panorama Settings to enable one of the following:
+
+
+ Alternatively, you can remove the duplicate address objects from the
+ device group configuration to allow only the
+ Shared objects in your
+ configuration.
+
+ |
+
|
+ PAN-223488
+
+ This issue is now resolved. See PAN-OS 11.0.3 Addressed Issues.
+
+ |
+
+
+ Closed ElasticSearch shards are not deleted from the Panorama M-Series
+ and virtual appliance. This causes the ElasticSearch shard purging to
+ not work as expected, resulting in high disk usage.
+
+ |
+
|
+ PAN-223365
+
+ This issue is now resolved. See PAN-OS 11.0.4 Addressed Issues.
+
+ |
+
+
+ The Panorama management server is unable to query any logs if the
+ ElasticSearch health status for any Log Collector (
+ is degraded.
+
+
+ Workaround:
+ Log in to the Log Collector CLI
+ and restart ElasticSearch.
+
+
+
+
+
+ |
+
|
+ PAN-227368
+
+ This issue is now resolved. See PAN-OS 11.0.4 Addressed Issues.
+
+ |
+
+
+ The GlobalProtect app cannot connect to a portal or gateway and
+ GlobalProtect Clientless VPN users cannot access applications if
+ authentication takes longer than 20 seconds.
+
+
+ Workaround: Increase the TCP handshake timeout to
+ the maximum value of 60 seconds.
+
+ |
+
|
+ PAN-222586
+ |
+
+
+ On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter
+ dropdown menus, Forward Methods, and Built-In Actions for Correlation
+ Log settings () are not displayed and cannot be configured.
+
+ |
+
|
+ PAN-222253
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, policy rulebase reordering when you
+ View Rulebase by Groups () does not persist if you reorder the policy rulebase by dragging and
+ dropping individual policy rules and then moving the entire tag group.
+
+ |
+
|
+ PAN-221126
+
+ This issue is now resolved. See PAN-OS 11.0.3 Addressed Issues.
+
+ |
+
+
+ Email server profiles (
+ and
+ ) to forward logs as email notifications are not forwarded in a
+ readable format.
+
+
+ Workaround: Use a
+ Custom Log Format to forward logs as
+ email notifications in a readable format.
+
+ |
+
|
+ PAN-221015
+
+ This issue is now resolved. See
+ PAN-OS 11.0.4 Addressed Issues.
+
+ |
+
+
+ On M-600 appliances in Panorama or Log Collector mode, the
+ es-1 and
+ es-2 ElasticSearch processes fail
+ to restart when the M-600 appliance is rebooted. The results in the
+ Managed Collector ES health
+ status () to be degraded.
+
+
+ Workaround:
+ Log in to the Panorama or Log Collector CLI
+ experiencing degraded ElasticSearch health and restart all
+ ElasticSearch processes.
+
+
+
+
+
+ |
+
|
+ PAN-220180
+
+ This issue is now resolved. See PAN-OS 11.0.3 Addressed Issues.
+
+ |
+
+
+ Configured botnet reports () are not generated.
+
+ |
+
|
+ PAN-220176
+ |
+
+
+ (PAN-OS 11.0.1-h2 hotfix) System process
+ crashes might occur with VoIP traffic when NAT is enabled with
+ Persistent Dynamic IP and Port settings.
+
+ |
+
|
+ PAN-219644
+
+ This issue is now resolved. See PAN-OS 11.0.3 Addressed Issues.
+
+ |
+
+
+ Firewalls forwarding logs to a syslog server over TLS () use the default Palo Alto Networks certificate instead of the
+ custom certificate configured on the firewall.
+
+ |
+
|
+ PAN-218521
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues.
+
+ |
+
+
+ The ElasticSearch process on the M-600 appliance in Log Collector mode
+ may enter a continuous reboot cycle. This results in the M-600
+ appliance becoming unresponsive, consuming logging disk space, and
+ preventing new log ingestion.
+
+ |
+
|
+ PAN-217307
+ |
+
+
+ The following Security policy rule () filters return no results:
+
+
+ log-start eq no
+
+ log-end eq no
+ log-end eq yes
+ |
+
|
+ PAN-216314
+ |
+
+
+ Upon upgrade or downgrade to or from PAN-OS 10.1.9 or 10.1.9-h1,
+ offloaded application traffic sessions may disconnect after a period
+ of time even if a session is active. The disconnect occurs after the
+ application's default session timeout value is exceeded. This behavior
+ affects only PAN-OS 10.1.9 and 10.1.9-h1. If you are on PAN-OS 10.1.9
+ and 10.1.9-h1, please use the following workaround. If you have
+ already upgraded or downgraded to another PAN-OS version, use the
+ following workaround in that version.
+
+
+ Workaround: Run the CLI command
+ debug dataplane internal pdt fe100 csr wr_sem_ctrl_ctr_scan_dis
+ value 0
+ to set the value to zero (0).
+
+ |
+
|
+ PAN-216214
+ |
+
+
+ For Panorama-managed firewalls in an Active/Active High Availability
+ (HA) configuration where you configure the firewall HA settings () in a template or template stack (), performing a local commit on one of the HA firewalls triggers an
+ HA config sync on the peer firewall. This causes the HA peer
+ configuration to go Out of Sync.
+
+ |
+
|
+ PAN-213746
+ |
+
+
+ On the Panorama management server, the
+ Hostkey displayed as
+ undefined undefined if you
+ override an SSH Service Profile () Hostkey configured in a Template from the Template Stack.
+
+ |
+
|
+ PAN-213119
+ |
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you
+ view the Block IP list ():
+
+
+ show -> dis-block-table is unexpected
+
+ |
+
|
+ PAN-212978
+ |
+
+
+ The Palo Alto Networks firewall stops responding when executing an
+ SD-WAN debug operational CLI command.
+
+ |
+
|
+ PAN-212889
+ |
+
+
+ On the Panorama management server, different threat names are used
+ when querying the same threat in the Threat Monitor () and ACC. This results in the ACC
+ displaying
+ no data to display when you are
+ redirected to the ACC after clicking a threat name in the Threat
+ Monitor and filtering the same threat name in the Global Filters.
+
+ |
+
|
+ PAN-211531
+ |
+ + On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (). + | +
|
+ PAN-207770
+ |
+
+
+ Data filtering logs () incorrectly display the traffic Direction as
+ server-to-client instead of
+ client-to-server for upload
+ traffic that matches Enterprise data loss prevention (DLP) data
+ patterns () in an Enterprise DLP data filtering profile ().
+
+ |
+
|
+ PAN-207733
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if
+ the DHCPv6 server goes down, after the lease time expires, the DHCPv6
+ client should enter SOLICIT state on both the Active and Passive
+ firewalls. Instead, the client is stuck in BOUND state with an IPv6
+ address having lease time 0 on the Passive firewall.
+
+ |
+
|
+ PAN-207616
+ |
+
+
+ On the Panorama management server, after selecting managed firewalls
+ and creating a new Tag () the managed firewalls are automatically unselected and any new tag
+ created is applied to the managed firewalls for which you initially
+ created the new tag.
+
+
+ Workaround: Select and then unselect the managed
+ firewalls for which you created a new tag.
+
+ |
+
|
+ PAN-207611
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the
+ Passive firewall sometimes crashes.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-207040
+ |
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade
+ from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
+ commits fail and SD-WAN devices on Panorama have no Virtual Router
+ name.
+
+ |
+
|
+ PAN-206913
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls,
+ releasing the IPv6 address from the client (using Release in the UI or
+ using the
+ request dhcp client ipv6 release all
+ CLI command) releases the IPv6 address from the Active firewall, but
+ not the Passive firewall.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the
+ configd process crashes. This
+ results in the Dedicated Log Collector losing connectivity to Panorama
+ despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-206416
+ |
+
+
+ On the Panorama management server, no data filtering log () is generated when the managed firewall loses connectivity to the
+ following cloud services, and as a result fails to forward matched
+ traffic for inspection.
+
+
|
+
|
+ PAN-206315
+ |
+
+
+ (PA-1420 firewall only) In an active/passive
+ high availability (HA) configuration, the
+ show session info CLI command
+ shows that the passive firewall has packet rate and throughput values.
+ The packet rate and throughput of the passive firewall should be zero
+ since it is not processing traffic.
+
+ |
+
|
+ PAN-205009
+ |
+
+
+ (PA-1420 firewall only) In an active/passive
+ high availability (HA) configuration, the
+ show interface all,
+ show-high availability interface ha2, and
+ show high-availability all CLI
+ commands display the HSCI port state as unknown on both the active and
+ passive firewalls.
+
+ |
+
|
+ PAN-204689
+ |
+
+
+ Upon upgrade to PAN-OS 11.0.1, the following GlobalProtect settings do
+ not work:
+
+
|
+
|
+ PAN-201910
+ |
+
+
+ PAN-OS security profiles might consume a large amount of memory
+ depending on the profile configuration and quantity. In some cases,
+ this might reduce the number of supported security profiles below the
+ stated maximum for a given platform.
+
+ |
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-197097
+ |
+
+
+ Large Scale VPN (LSVPN) does not support IPv6 addresses on the
+ satellite firewall.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-196146
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues.
+
+ |
+
+
+ The VM-Series firewall on Azure does not boot up with a hostname
+ (specified in an init-cgf.txt or user data) when bootstrapped.
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-195342
+ |
+
+
+ On the Panorama management server, Context Switch fails when you try
+ to Context Switch from a managed firewall running PAN-OS 10.1.7 or
+ earlier release back to Panorama and the following error is displayed:
+
+
+ Could not find start token '@start@'
+
+ |
+
|
+ PAN-194978
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , hovering the mouse over a power over Ethernet (PoE)
+ Link State icon does not display
+ link speed and link duplex details.
+
+ |
+
|
+ PAN-194424
+ |
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS
+ 10.2.2 while having a log interface configured can cause both the log
+ interface and the management interface to remain connected to the log
+ collector.
+
+
+ Workaround: Restart the log receiver service by
+ running the following CLI command:
+
+
+
+
+
+ |
+
|
+ PAN-193004
+
+ This issue is now resolved. See
+ PAN-OS 11.0.4 Addressed Issues.
+
+ |
+
+
+ The Panorama management server fails to delete old IP Tag data. This
+ causes the /opt/pancfg partition
+ to reach maximum capacity which impacts Panorama performance.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-184708
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
|
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-171938
+ |
+
+
+ No results are displayed when you
+ Show Application Filter for a
+ Security policy rule ().
+
+ |
+
|
+ PAN-164885
+ |
+
+
+ On the Panorama management server, pushes to managed firewalls (
+ or Commit and Push) may fail when an
+ EDL () is configured to
+ Check for updates every 5 minutes
+ due to the commit and EDL fetch processes overlapping. This is more
+ likely to occur when multiple EDLs are configured to check for updates
+ every 5 minutes.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-5632
+ |
+
+
+ The number of registered WildFire appliances reported in Panorama
+ () does not accurately reflect the current status of connected
+ WildFire appliances.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-243951
+ |
+
+
+ On the Panorama management sever in an active/passive High
+ Availability (HA) configuration, managed devices () display as out-of-sync on the
+ passive HA peer when configuration changes are made to the SD-WAN
+ () configuration on the active HA peer.
+
+
+ Workaround: Manually synchronize the Panorama HA
+ peers.
+
+
|
+
|
+ PAN-241536
+ |
+
+
+ On the Panorama management server, a user with an Admin Role is unable
+ to modify or add filters to profiles under
+ , despite having the necessary read and write privileges.
+
+ |
+
|
+ PAN-234408
+ |
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for
+ ChatGPT from traffic forwarded to the DLP cloud service from an NGFW.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-242910
+
+ PAN-OS 11.0.3, 11.0.3-h1, 11.0.3-h3, and 11.0.3-h5
+
+ |
+
+
+ On the Panorama management server, Panorama administrators () that are assigned a custom Panorama admin role () with Push All Changes enabled are
+ unable to push configuration changes to managed firewalls when
+ Managed Devices and
+ Push For Other Admins are disabled.
+
+ |
+
|
+ PAN-242837
+ |
+
+
+ Default login credentials and SSH fail after enabling FIPS-CC Mode on
+ a firewall or Panorama after converting through the Maintenance
+ Recovery Tool (MRT). The firewall or Panorama becomes stuck and
+ requires a factory reset to recover.
+
+ |
+
|
+ PAN-241041
+ |
+
+
+ On the Panorama management server exporting template or template stack
+ variables () in CSV format results in an empty CSV file.
+
+ |
+
|
+ PAN-238769
+ |
+
+
+ FIPS-CC VM only. Upgrading to 10.1.10-h2 or 10.1.11 will change all
+ locally created security Policy actions to Deny. Re-load the back-up
+ config taken before upgrading or the last version to get the previous
+ config back. Also, Unable to login to FIPSCC Mode devices with default
+ credentials after converting the mode for 10.1.12 release , 10.2.7
+ release , 11.1.0 , 11.1.1, 11.0.3 versions.
+
+ |
+
|
+ PAN-234929
+ |
+
+
+ The tabs in the ACC, such as
+ Network Activity,
+ Threat Activity, and
+ Blocked Activity, may not display
+ any data when you apply a Time filter for the Last 15 minutes, Last
+ Hour, Last 6 Hours, or Last 12 Hours. With the Last 24 Hours filter,
+ the data displayed may not be accurate. Additionally, reports run
+ against summary logs may not display accurate results.
+
+ |
+
|
+ PAN-231507
+
+ This issue is now resolved. See PAN-OS 11.0.4 Addressed Issues.
+
+ |
+
+
+ On PA-1400 Series firewalls only, when an HSCI interface is used as an
+ HA2 interface, HA2 packets are intermittently dropped on the passive
+ device, which can cause the HA2 connection to flap due to missing HA2
+ keepalive messages. Workaround: use data ports configured as HA2
+ interface.
+
+ |
+
|
+ PAN-228515
+ |
+
+
+ The EleasticSearch SSH flaps on the M-600 appliance in Panorama or Log
+ Collector mode. This causes logs to not display on the Panorama
+ management server () and the Log Collector health status () to display as degraded.
+
+ |
+
|
+ PAN-227344
+ |
+
+
+ On the Panorama management server, PDF Summary Reports () display no data and are blank when predefined reports are included
+ in the summary report.
+
+ |
+
|
+ PAN-225886
+ |
+
+
+ If you enable explicit proxy mode for the web proxy, intermittent
+ errors and unexpected TCP reconnections may occur.
+
+ |
+
|
+ PAN-225337
+
+ This issue is now resolved. See
+ PAN-OS 11.0.4 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, the configuration push to a
+ multi-vsys firewall fails if you:
+
+
+ Workaround: Select
+
+ and edit the Panorama Settings to enable one of the following:
+
+
+ Alternatively, you can remove the duplicate address objects from the
+ device group configuration to allow only the
+ Shared objects in your
+ configuration.
+
+ |
+
|
+ PAN-233677
+ |
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, PA-5430, and
+ PA-5440 firewalls) By enabling
+ Lockless QoS feature, a slight degradation in App-ID and Threat performance is expected.
+
+ |
+
|
+ PAN-223365
+
+ This issue is now resolved. See PAN-OS 11.0.4 Addressed Issues.
+
+ |
+
+
+ The Panorama management server is unable to query any logs if the
+ ElasticSearch health status for any Log Collector (
+ is degraded.
+
+
+ Workaround:
+ Log in to the Log Collector CLI
+ and restart ElasticSearch.
+
+
+
+
+
+ |
+
|
+ PAN-227368
+
+ This issue is now resolved. See PAN-OS 11.0.4 Addressed Issues.
+
+ |
+
+
+ The GlobalProtect app cannot connect to a portal or gateway and
+ GlobalProtect Clientless VPN users cannot access applications if
+ authentication takes longer than 20 seconds.
+
+
+ Workaround: Increase the TCP handshake timeout to
+ the maximum value of 60 seconds.
+
+ |
+
|
+ PAN-222586
+ |
+
+
+ On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter
+ dropdown menus, Forward Methods, and Built-In Actions for Correlation
+ Log settings () are not displayed and cannot be configured.
+
+ |
+
|
+ PAN-222253
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, policy rulebase reordering when you
+ View Rulebase by Groups () does not persist if you reorder the policy rulebase by dragging and
+ dropping individual policy rules and then moving the entire tag group.
+
+ |
+
|
+ PAN-221015
+
+ This issue is now resolved. See
+ PAN-OS 11.0.4 Addressed Issues.
+
+ |
+
+
+ On M-600 appliances in Panorama or Log Collector mode, the
+ es-1 and
+ es-2 ElasticSearch processes fail
+ to restart when the M-600 appliance is rebooted. The results in the
+ Managed Collector ES health
+ status () to be degraded.
+
+
+ Workaround:
+ Log in to the Panorama or Log Collector CLI
+ experiencing degraded ElasticSearch health and restart all
+ ElasticSearch processes.
+
+
+
+
+
+ |
+
|
+ PAN-220176
+ |
+
+
+ (PAN-OS 11.0.1-h2 hotfix) System process
+ crashes might occur with VoIP traffic when NAT is enabled with
+ Persistent Dynamic IP and Port settings.
+
+ |
+
|
+ PAN-218521
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues.
+
+ |
+
+
+ The ElasticSearch process on the M-600 appliance in Log Collector mode
+ may enter a continuous reboot cycle. This results in the M-600
+ appliance becoming unresponsive, consuming logging disk space, and
+ preventing new log ingestion.
+
+ |
+
|
+ PAN-217307
+ |
+
+
+ The following Security policy rule () filters return no results:
+
+
+ log-start eq no
+
+ log-end eq no
+ log-end eq yes
+ |
+
|
+ PAN-216314
+ |
+
+
+ Upon upgrade or downgrade to or from PAN-OS 10.1.9 or 10.1.9-h1,
+ offloaded application traffic sessions may disconnect after a period
+ of time even if a session is active. The disconnect occurs after the
+ application's default session timeout value is exceeded. This behavior
+ affects only PAN-OS 10.1.9 and 10.1.9-h1. If you are on PAN-OS 10.1.9
+ and 10.1.9-h1, please use the following workaround. If you have
+ already upgraded or downgraded to another PAN-OS version, use the
+ following workaround in that version.
+
+
+ Workaround: Run the CLI command
+ debug dataplane internal pdt fe100 csr wr_sem_ctrl_ctr_scan_dis
+ value 0
+ to set the value to zero (0).
+
+ |
+
|
+ PAN-216214
+ |
+
+
+ For Panorama-managed firewalls in an Active/Active High Availability
+ (HA) configuration where you configure the firewall HA settings () in a template or template stack (), performing a local commit on one of the HA firewalls triggers an
+ HA config sync on the peer firewall. This causes the HA peer
+ configuration to go Out of Sync.
+
+ |
+
|
+ PAN-213746
+ |
+
+
+ On the Panorama management server, the
+ Hostkey displayed as
+ undefined undefined if you
+ override an SSH Service Profile () Hostkey configured in a Template from the Template Stack.
+
+ |
+
|
+ PAN-213119
+ |
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you
+ view the Block IP list ():
+
+
+ show -> dis-block-table is unexpected
+
+ |
+
|
+ PAN-212978
+ |
+
+
+ The Palo Alto Networks firewall stops responding when executing an
+ SD-WAN debug operational CLI command.
+
+ |
+
|
+ PAN-212889
+ |
+
+
+ On the Panorama management server, different threat names are used
+ when querying the same threat in the Threat Monitor () and ACC. This results in the ACC
+ displaying
+ no data to display when you are
+ redirected to the ACC after clicking a threat name in the Threat
+ Monitor and filtering the same threat name in the Global Filters.
+
+ |
+
|
+ PAN-211531
+ |
+ + On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (). + | +
|
+ PAN-207770
+ |
+
+
+ Data filtering logs () incorrectly display the traffic Direction as
+ server-to-client instead of
+ client-to-server for upload
+ traffic that matches Enterprise data loss prevention (DLP) data
+ patterns () in an Enterprise DLP data filtering profile ().
+
+ |
+
|
+ PAN-207733
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if
+ the DHCPv6 server goes down, after the lease time expires, the DHCPv6
+ client should enter SOLICIT state on both the Active and Passive
+ firewalls. Instead, the client is stuck in BOUND state with an IPv6
+ address having lease time 0 on the Passive firewall.
+
+ |
+
|
+ PAN-207616
+ |
+
+
+ On the Panorama management server, after selecting managed firewalls
+ and creating a new Tag () the managed firewalls are automatically unselected and any new tag
+ created is applied to the managed firewalls for which you initially
+ created the new tag.
+
+
+ Workaround: Select and then unselect the managed
+ firewalls for which you created a new tag.
+
+ |
+
|
+ PAN-207611
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the
+ Passive firewall sometimes crashes.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-207040
+ |
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade
+ from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
+ commits fail and SD-WAN devices on Panorama have no Virtual Router
+ name.
+
+ |
+
|
+ PAN-206913
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls,
+ releasing the IPv6 address from the client (using Release in the UI or
+ using the
+ request dhcp client ipv6 release all
+ CLI command) releases the IPv6 address from the Active firewall, but
+ not the Passive firewall.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the
+ configd process crashes. This
+ results in the Dedicated Log Collector losing connectivity to Panorama
+ despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-206416
+ |
+
+
+ On the Panorama management server, no data filtering log () is generated when the managed firewall loses connectivity to the
+ following cloud services, and as a result fails to forward matched
+ traffic for inspection.
+
+
|
+
|
+ PAN-206315
+ |
+
+
+ (PA-1420 firewall only) In an active/passive
+ high availability (HA) configuration, the
+ show session info CLI command
+ shows that the passive firewall has packet rate and throughput values.
+ The packet rate and throughput of the passive firewall should be zero
+ since it is not processing traffic.
+
+ |
+
|
+ PAN-205009
+ |
+
+
+ (PA-1420 firewall only) In an active/passive
+ high availability (HA) configuration, the
+ show interface all,
+ show-high availability interface ha2, and
+ show high-availability all CLI
+ commands display the HSCI port state as unknown on both the active and
+ passive firewalls.
+
+ |
+
|
+ PAN-204689
+ |
+
+
+ Upon upgrade to PAN-OS 11.0.1, the following GlobalProtect settings do
+ not work:
+
+
|
+
|
+ PAN-201910
+ |
+
+
+ PAN-OS security profiles might consume a large amount of memory
+ depending on the profile configuration and quantity. In some cases,
+ this might reduce the number of supported security profiles below the
+ stated maximum for a given platform.
+
+ |
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-197097
+ |
+
+
+ Large Scale VPN (LSVPN) does not support IPv6 addresses on the
+ satellite firewall.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-196146
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues.
+
+ |
+
+
+ The VM-Series firewall on Azure does not boot up with a hostname
+ (specified in an init-cgf.txt or user data) when bootstrapped.
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-195342
+ |
+
+
+ On the Panorama management server, Context Switch fails when you try
+ to Context Switch from a managed firewall running PAN-OS 10.1.7 or
+ earlier release back to Panorama and the following error is displayed:
+
+
+ Could not find start token '@start@'
+
+ |
+
|
+ PAN-194978
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , hovering the mouse over a power over Ethernet (PoE)
+ Link State icon does not display
+ link speed and link duplex details.
+
+ |
+
|
+ PAN-194424
+ |
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS
+ 10.2.2 while having a log interface configured can cause both the log
+ interface and the management interface to remain connected to the log
+ collector.
+
+
+ Workaround: Restart the log receiver service by
+ running the following CLI command:
+
+
+
+
+
+ |
+
|
+ PAN-193004
+
+ This issue is now resolved. See
+ PAN-OS 11.0.4 Addressed Issues.
+
+ |
+
+
+ The Panorama management server fails to delete old IP Tag data. This
+ causes the /opt/pancfg partition
+ to reach maximum capacity which impacts Panorama performance.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-184708
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
|
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-171938
+ |
+
+
+ No results are displayed when you
+ Show Application Filter for a
+ Security policy rule ().
+
+ |
+
|
+ PAN-164885
+ |
+
+
+ On the Panorama management server, pushes to managed firewalls (
+ or Commit and Push) may fail when an
+ EDL () is configured to
+ Check for updates every 5 minutes
+ due to the commit and EDL fetch processes overlapping. This is more
+ likely to occur when multiple EDLs are configured to check for updates
+ every 5 minutes.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-5632
+ |
+
+
+ The number of registered WildFire appliances reported in Panorama
+ () does not accurately reflect the current status of connected
+ WildFire appliances.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-252744
+ |
+
+
+ After upgrading PA-3200 Series, PA-5200 Series, or PA-7000 Series
+ firewalls that are equipped with OCTEON 7x00 dataplane chips to PAN-OS
+ 11.0.4 or 11.0.4-h1, the firewall might see continuous crashes, reboot
+ repeatedly, and/or go into a non-functional state.
+
+
+ Workaround: If you have already upgraded to one of
+ those releases, downgrade to an earlier release or upgrade to PAN-OS
+ 11.0.4-h2.
+
+ |
+
|
+ PAN-241041
+ |
+
+
+ On the Panorama management server exporting template or template stack
+ variables () in CSV format results in an empty CSV file.
+
+ |
+
|
+ PAN-234929
+ |
+
+
+ The tabs in the ACC, such as
+ Network Activity,
+ Threat Activity, and
+ Blocked Activity, may not display
+ any data when you apply a Time filter for the Last 15 minutes, Last
+ Hour, Last 6 Hours, or Last 12 Hours. With the Last 24 Hours filter,
+ the data displayed may not be accurate. Additionally, reports run
+ against summary logs may not display accurate results.
+
+ |
+
|
+ PAN-225886
+ |
+
+
+ If you enable explicit proxy mode for the web proxy, intermittent
+ errors and unexpected TCP reconnections may occur.
+
+ |
+
|
+ PAN-233677
+ |
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, PA-5430, and
+ PA-5440 firewalls) By enabling
+ Lockless QoS feature, a slight degradation in App-ID and Threat performance is expected.
+
+ |
+
|
+ PAN-222586
+ |
+
+
+ On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter
+ dropdown menus, Forward Methods, and Built-In Actions for Correlation
+ Log settings () are not displayed and cannot be configured.
+
+ |
+
|
+ PAN-222253
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, policy rulebase reordering when you
+ View Rulebase by Groups () does not persist if you reorder the policy rulebase by dragging and
+ dropping individual policy rules and then moving the entire tag group.
+
+ |
+
|
+ PAN-221033
+ |
+
+
+ The firewall is responding to an ARP request for an IP address in the
+ firewall's NAT address pool when that IP address isn't in the same
+ subnet as the IP address of the ingress interface.
+
+ |
+
|
+ PAN-220176
+ |
+
+
+ (PAN-OS 11.0.1-h2 hotfix) System process
+ crashes might occur with VoIP traffic when NAT is enabled with
+ Persistent Dynamic IP and Port settings.
+
+ |
+
|
+ PAN-218521
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues.
+
+ |
+
+
+ The ElasticSearch process on the M-600 appliance in Log Collector mode
+ may enter a continuous reboot cycle. This results in the M-600
+ appliance becoming unresponsive, consuming logging disk space, and
+ preventing new log ingestion.
+
+ |
+
|
+ PAN-216314
+ |
+
+
+ Upon upgrade or downgrade to or from PAN-OS 10.1.9 or 10.1.9-h1,
+ offloaded application traffic sessions may disconnect after a period
+ of time even if a session is active. The disconnect occurs after the
+ application's default session timeout value is exceeded. This behavior
+ affects only PAN-OS 10.1.9 and 10.1.9-h1. If you are on PAN-OS 10.1.9
+ and 10.1.9-h1, please use the following workaround. If you have
+ already upgraded or downgraded to another PAN-OS version, use the
+ following workaround in that version.
+
+
+ Workaround: Run the CLI command
+ debug dataplane internal pdt fe100 csr wr_sem_ctrl_ctr_scan_dis
+ value 0
+ to set the value to zero (0).
+
+ |
+
|
+ PAN-216214
+ |
+
+
+ For Panorama-managed firewalls in an Active/Active High Availability
+ (HA) configuration where you configure the firewall HA settings () in a template or template stack (), performing a local commit on one of the HA firewalls triggers an
+ HA config sync on the peer firewall. This causes the HA peer
+ configuration to go Out of Sync.
+
+ |
+
|
+ PAN-213746
+ |
+
+
+ On the Panorama management server, the
+ Hostkey displayed as
+ undefined undefined if you
+ override an SSH Service Profile () Hostkey configured in a Template from the Template Stack.
+
+ |
+
|
+ PAN-213119
+ |
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you
+ view the Block IP list ():
+
+
+ show -> dis-block-table is unexpected
+
+ |
+
|
+ PAN-212978
+ |
+
+
+ The Palo Alto Networks firewall stops responding when executing an
+ SD-WAN debug operational CLI command.
+
+ |
+
|
+ PAN-212889
+ |
+
+
+ On the Panorama management server, different threat names are used
+ when querying the same threat in the Threat Monitor () and ACC. This results in the ACC
+ displaying
+ no data to display when you are
+ redirected to the ACC after clicking a threat name in the Threat
+ Monitor and filtering the same threat name in the Global Filters.
+
+ |
+
|
+ PAN-211531
+ |
+ + On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (). + | +
|
+ PAN-207770
+ |
+
+
+ Data filtering logs () incorrectly display the traffic Direction as
+ server-to-client instead of
+ client-to-server for upload
+ traffic that matches Enterprise data loss prevention (DLP) data
+ patterns () in an Enterprise DLP data filtering profile ().
+
+ |
+
|
+ PAN-207733
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if
+ the DHCPv6 server goes down, after the lease time expires, the DHCPv6
+ client should enter SOLICIT state on both the Active and Passive
+ firewalls. Instead, the client is stuck in BOUND state with an IPv6
+ address having lease time 0 on the Passive firewall.
+
+ |
+
|
+ PAN-207616
+ |
+
+
+ On the Panorama management server, after selecting managed firewalls
+ and creating a new Tag () the managed firewalls are automatically unselected and any new tag
+ created is applied to the managed firewalls for which you initially
+ created the new tag.
+
+
+ Workaround: Select and then unselect the managed
+ firewalls for which you created a new tag.
+
+ |
+
|
+ PAN-207611
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the
+ Passive firewall sometimes crashes.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-207040
+ |
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade
+ from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
+ commits fail and SD-WAN devices on Panorama have no Virtual Router
+ name.
+
+ |
+
|
+ PAN-206913
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls,
+ releasing the IPv6 address from the client (using Release in the UI or
+ using the
+ request dhcp client ipv6 release all
+ CLI command) releases the IPv6 address from the Active firewall, but
+ not the Passive firewall.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the
+ configd process crashes. This
+ results in the Dedicated Log Collector losing connectivity to Panorama
+ despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-206416
+ |
+
+
+ On the Panorama management server, no data filtering log () is generated when the managed firewall loses connectivity to the
+ following cloud services, and as a result fails to forward matched
+ traffic for inspection.
+
+
|
+
|
+ PAN-206315
+ |
+
+
+ (PA-1420 firewall only) In an active/passive
+ high availability (HA) configuration, the
+ show session info CLI command
+ shows that the passive firewall has packet rate and throughput values.
+ The packet rate and throughput of the passive firewall should be zero
+ since it is not processing traffic.
+
+ |
+
|
+ PAN-205009
+ |
+
+
+ (PA-1420 firewall only) In an active/passive
+ high availability (HA) configuration, the
+ show interface all,
+ show-high availability interface ha2, and
+ show high-availability all CLI
+ commands display the HSCI port state as unknown on both the active and
+ passive firewalls.
+
+ |
+
|
+ PAN-204689
+ |
+
+
+ Upon upgrade to PAN-OS 11.0.1, the following GlobalProtect settings do
+ not work:
+
+
|
+
|
+ PAN-201910
+ |
+
+
+ PAN-OS security profiles might consume a large amount of memory
+ depending on the profile configuration and quantity. In some cases,
+ this might reduce the number of supported security profiles below the
+ stated maximum for a given platform.
+
+ |
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-197097
+ |
+
+
+ Large Scale VPN (LSVPN) does not support IPv6 addresses on the
+ satellite firewall.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-196146
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues.
+
+ |
+
+
+ The VM-Series firewall on Azure does not boot up with a hostname
+ (specified in an init-cgf.txt or user data) when bootstrapped.
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-195342
+ |
+
+
+ On the Panorama management server, Context Switch fails when you try
+ to Context Switch from a managed firewall running PAN-OS 10.1.7 or
+ earlier release back to Panorama and the following error is displayed:
+
+
+ Could not find start token '@start@'
+
+ |
+
|
+ PAN-194978
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , hovering the mouse over a power over Ethernet (PoE)
+ Link State icon does not display
+ link speed and link duplex details.
+
+ |
+
|
+ PAN-194424
+ |
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS
+ 10.2.2 while having a log interface configured can cause both the log
+ interface and the management interface to remain connected to the log
+ collector.
+
+
+ Workaround: Restart the log receiver service by
+ running the following CLI command:
+
+
+
+
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-184708
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
|
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-171938
+ |
+
+
+ No results are displayed when you
+ Show Application Filter for a
+ Security policy rule ().
+
+ |
+
|
+ PAN-164885
+ |
+
+
+ On the Panorama management server, pushes to managed firewalls (
+ or Commit and Push) may fail when an
+ EDL () is configured to
+ Check for updates every 5 minutes
+ due to the commit and EDL fetch processes overlapping. This is more
+ likely to occur when multiple EDLs are configured to check for updates
+ every 5 minutes.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-5632
+ |
+
+
+ The number of registered WildFire appliances reported in Panorama
+ () does not accurately reflect the current status of connected
+ WildFire appliances.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-252744
+ |
+
+
+ After upgrading PA-3200 Series, PA-5200 Series, or PA-7000 Series
+ firewalls that are equipped with OCTEON 7x00 dataplane chips to PAN-OS
+ 11.0.4 or 11.0.4-h1, the firewall might see continuous crashes, reboot
+ repeatedly, and/or go into a non-functional state.
+
+
+ Workaround: If you have already upgraded to one of
+ those releases, downgrade to an earlier release or upgrade to PAN-OS
+ 11.0.4-h2.
+
+ |
+
|
+ PAN-241041
+ |
+
+
+ On the Panorama management server exporting template or template stack
+ variables () in CSV format results in an empty CSV file.
+
+ |
+
|
+ PAN-234929
+ |
+
+
+ The tabs in the ACC, such as
+ Network Activity,
+ Threat Activity, and
+ Blocked Activity, may not display
+ any data when you apply a Time filter for the Last 15 minutes, Last
+ Hour, Last 6 Hours, or Last 12 Hours. With the Last 24 Hours filter,
+ the data displayed may not be accurate. Additionally, reports run
+ against summary logs may not display accurate results.
+
+ |
+
|
+ PAN-225886
+ |
+
+
+ If you enable explicit proxy mode for the web proxy, intermittent
+ errors and unexpected TCP reconnections may occur.
+
+ |
+
|
+ PAN-233677
+ |
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, PA-5430, and
+ PA-5440 firewalls) By enabling
+ Lockless QoS feature, a slight degradation in App-ID and Threat performance is expected.
+
+ |
+
|
+ PAN-222586
+ |
+
+
+ On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter
+ dropdown menus, Forward Methods, and Built-In Actions for Correlation
+ Log settings () are not displayed and cannot be configured.
+
+ |
+
|
+ PAN-220176
+ |
+
+
+ (PAN-OS 11.0.1-h2 hotfix) System process
+ crashes might occur with VoIP traffic when NAT is enabled with
+ Persistent Dynamic IP and Port settings.
+
+ |
+
|
+ PAN-216314
+ |
+
+
+ Upon upgrade or downgrade to or from PAN-OS 10.1.9 or 10.1.9-h1,
+ offloaded application traffic sessions may disconnect after a period
+ of time even if a session is active. The disconnect occurs after the
+ application's default session timeout value is exceeded. This behavior
+ affects only PAN-OS 10.1.9 and 10.1.9-h1. If you are on PAN-OS 10.1.9
+ and 10.1.9-h1, please use the following workaround. If you have
+ already upgraded or downgraded to another PAN-OS version, use the
+ following workaround in that version.
+
+
+ Workaround: Run the CLI command
+ debug dataplane internal pdt fe100 csr wr_sem_ctrl_ctr_scan_dis
+ value 0
+ to set the value to zero (0).
+
+ |
+
|
+ PAN-216214
+ |
+
+
+ For Panorama-managed firewalls in an Active/Active High Availability
+ (HA) configuration where you configure the firewall HA settings () in a template or template stack (), performing a local commit on one of the HA firewalls triggers an
+ HA config sync on the peer firewall. This causes the HA peer
+ configuration to go Out of Sync.
+
+ |
+
|
+ PAN-213746
+ |
+
+
+ On the Panorama management server, the
+ Hostkey displayed as
+ undefined undefined if you
+ override an SSH Service Profile () Hostkey configured in a Template from the Template Stack.
+
+ |
+
|
+ PAN-213119
+ |
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you
+ view the Block IP list ():
+
+
+ show -> dis-block-table is unexpected
+
+ |
+
|
+ PAN-212978
+ |
+
+
+ The Palo Alto Networks firewall stops responding when executing an
+ SD-WAN debug operational CLI command.
+
+ |
+
|
+ PAN-212889
+ |
+
+
+ On the Panorama management server, different threat names are used
+ when querying the same threat in the Threat Monitor () and ACC. This results in the ACC
+ displaying
+ no data to display when you are
+ redirected to the ACC after clicking a threat name in the Threat
+ Monitor and filtering the same threat name in the Global Filters.
+
+ |
+
|
+ PAN-211531
+ |
+ + On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (). + | +
|
+ PAN-207770
+ |
+
+
+ Data filtering logs () incorrectly display the traffic Direction as
+ server-to-client instead of
+ client-to-server for upload
+ traffic that matches Enterprise data loss prevention (DLP) data
+ patterns () in an Enterprise DLP data filtering profile ().
+
+ |
+
|
+ PAN-207733
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if
+ the DHCPv6 server goes down, after the lease time expires, the DHCPv6
+ client should enter SOLICIT state on both the Active and Passive
+ firewalls. Instead, the client is stuck in BOUND state with an IPv6
+ address having lease time 0 on the Passive firewall.
+
+ |
+
|
+ PAN-207616
+ |
+
+
+ On the Panorama management server, after selecting managed firewalls
+ and creating a new Tag () the managed firewalls are automatically unselected and any new tag
+ created is applied to the managed firewalls for which you initially
+ created the new tag.
+
+
+ Workaround: Select and then unselect the managed
+ firewalls for which you created a new tag.
+
+ |
+
|
+ PAN-207611
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the
+ Passive firewall sometimes crashes.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-207040
+ |
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade
+ from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
+ commits fail and SD-WAN devices on Panorama have no Virtual Router
+ name.
+
+ |
+
|
+ PAN-206913
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls,
+ releasing the IPv6 address from the client (using Release in the UI or
+ using the
+ request dhcp client ipv6 release all
+ CLI command) releases the IPv6 address from the Active firewall, but
+ not the Passive firewall.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the
+ configd process crashes. This
+ results in the Dedicated Log Collector losing connectivity to Panorama
+ despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-206416
+ |
+
+
+ On the Panorama management server, no data filtering log () is generated when the managed firewall loses connectivity to the
+ following cloud services, and as a result fails to forward matched
+ traffic for inspection.
+
+
|
+
|
+ PAN-206315
+ |
+
+
+ (PA-1420 firewall only) In an active/passive
+ high availability (HA) configuration, the
+ show session info CLI command
+ shows that the passive firewall has packet rate and throughput values.
+ The packet rate and throughput of the passive firewall should be zero
+ since it is not processing traffic.
+
+ |
+
|
+ PAN-205009
+ |
+
+
+ (PA-1420 firewall only) In an active/passive
+ high availability (HA) configuration, the
+ show interface all,
+ show-high availability interface ha2, and
+ show high-availability all CLI
+ commands display the HSCI port state as unknown on both the active and
+ passive firewalls.
+
+ |
+
|
+ PAN-204689
+ |
+
+
+ Upon upgrade to PAN-OS 11.0.1, the following GlobalProtect settings do
+ not work:
+
+
|
+
|
+ PAN-201910
+ |
+
+
+ PAN-OS security profiles might consume a large amount of memory
+ depending on the profile configuration and quantity. In some cases,
+ this might reduce the number of supported security profiles below the
+ stated maximum for a given platform.
+
+ |
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-197097
+ |
+
+
+ Large Scale VPN (LSVPN) does not support IPv6 addresses on the
+ satellite firewall.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-195342
+ |
+
+
+ On the Panorama management server, Context Switch fails when you try
+ to Context Switch from a managed firewall running PAN-OS 10.1.7 or
+ earlier release back to Panorama and the following error is displayed:
+
+
+ Could not find start token '@start@'
+
+ |
+
|
+ PAN-194978
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , hovering the mouse over a power over Ethernet (PoE)
+ Link State icon does not display
+ link speed and link duplex details.
+
+ |
+
|
+ PAN-194424
+ |
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS
+ 10.2.2 while having a log interface configured can cause both the log
+ interface and the management interface to remain connected to the log
+ collector.
+
+
+ Workaround: Restart the log receiver service by
+ running the following CLI command:
+
+
+
+
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-184708
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
|
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-171938
+ |
+
+
+ No results are displayed when you
+ Show Application Filter for a
+ Security policy rule ().
+
+ |
+
|
+ PAN-164885
+ |
+
+
+ On the Panorama management server, pushes to managed firewalls (
+ or Commit and Push) may fail when an
+ EDL () is configured to
+ Check for updates every 5 minutes
+ due to the commit and EDL fetch processes overlapping. This is more
+ likely to occur when multiple EDLs are configured to check for updates
+ every 5 minutes.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-5632
+ |
+
+
+ The number of registered WildFire appliances reported in Panorama
+ () does not accurately reflect the current status of connected
+ WildFire appliances.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-252744
+ |
+
+
+ After upgrading PA-3200 Series, PA-5200 Series, or PA-7000 Series
+ firewalls that are equipped with OCTEON 7x00 dataplane chips to PAN-OS
+ 11.0.4 or 11.0.4-h1, the firewall might see continuous crashes, reboot
+ repeatedly, and/or go into a non-functional state.
+
+
+ Workaround: If you have already upgraded to one of
+ those releases, downgrade to an earlier release or upgrade to PAN-OS
+ 11.0.4-h2.
+
+ |
+
|
+ PAN-241041
+ |
+
+
+ On the Panorama management server exporting template or template stack
+ variables () in CSV format results in an empty CSV file.
+
+ |
+
|
+ PAN-234929
+ |
+
+
+ The tabs in the ACC, such as
+ Network Activity,
+ Threat Activity, and
+ Blocked Activity, may not display
+ any data when you apply a Time filter for the Last 15 minutes, Last
+ Hour, Last 6 Hours, or Last 12 Hours. With the Last 24 Hours filter,
+ the data displayed may not be accurate. Additionally, reports run
+ against summary logs may not display accurate results.
+
+ |
+
|
+ PAN-225886
+ |
+
+
+ If you enable explicit proxy mode for the web proxy, intermittent
+ errors and unexpected TCP reconnections may occur.
+
+ |
+
|
+ PAN-233677
+ |
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, PA-5430, and
+ PA-5440 firewalls) By enabling
+ Lockless QoS feature, a slight degradation in App-ID and Threat performance is expected.
+
+ |
+
|
+ PAN-222586
+ |
+
+
+ On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter
+ dropdown menus, Forward Methods, and Built-In Actions for Correlation
+ Log settings () are not displayed and cannot be configured.
+
+ |
+
|
+ PAN-220176
+ |
+
+
+ (PAN-OS 11.0.1-h2 hotfix) System process
+ crashes might occur with VoIP traffic when NAT is enabled with
+ Persistent Dynamic IP and Port settings.
+
+ |
+
|
+ PAN-216314
+ |
+
+
+ Upon upgrade or downgrade to or from PAN-OS 10.1.9 or 10.1.9-h1,
+ offloaded application traffic sessions may disconnect after a period
+ of time even if a session is active. The disconnect occurs after the
+ application's default session timeout value is exceeded. This behavior
+ affects only PAN-OS 10.1.9 and 10.1.9-h1. If you are on PAN-OS 10.1.9
+ and 10.1.9-h1, please use the following workaround. If you have
+ already upgraded or downgraded to another PAN-OS version, use the
+ following workaround in that version.
+
+
+ Workaround: Run the CLI command
+ debug dataplane internal pdt fe100 csr wr_sem_ctrl_ctr_scan_dis
+ value 0
+ to set the value to zero (0).
+
+ |
+
|
+ PAN-216214
+ |
+
+
+ For Panorama-managed firewalls in an Active/Active High Availability
+ (HA) configuration where you configure the firewall HA settings () in a template or template stack (), performing a local commit on one of the HA firewalls triggers an
+ HA config sync on the peer firewall. This causes the HA peer
+ configuration to go Out of Sync.
+
+ |
+
|
+ PAN-213746
+ |
+
+
+ On the Panorama management server, the
+ Hostkey displayed as
+ undefined undefined if you
+ override an SSH Service Profile () Hostkey configured in a Template from the Template Stack.
+
+ |
+
|
+ PAN-213119
+ |
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you
+ view the Block IP list ():
+
+
+ show -> dis-block-table is unexpected
+
+ |
+
|
+ PAN-212978
+ |
+
+
+ The Palo Alto Networks firewall stops responding when executing an
+ SD-WAN debug operational CLI command.
+
+ |
+
|
+ PAN-212889
+ |
+
+
+ On the Panorama management server, different threat names are used
+ when querying the same threat in the Threat Monitor () and ACC. This results in the ACC
+ displaying
+ no data to display when you are
+ redirected to the ACC after clicking a threat name in the Threat
+ Monitor and filtering the same threat name in the Global Filters.
+
+ |
+
|
+ PAN-211531
+ |
+ + On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (). + | +
|
+ PAN-207770
+ |
+
+
+ Data filtering logs () incorrectly display the traffic Direction as
+ server-to-client instead of
+ client-to-server for upload
+ traffic that matches Enterprise data loss prevention (DLP) data
+ patterns () in an Enterprise DLP data filtering profile ().
+
+ |
+
|
+ PAN-207733
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if
+ the DHCPv6 server goes down, after the lease time expires, the DHCPv6
+ client should enter SOLICIT state on both the Active and Passive
+ firewalls. Instead, the client is stuck in BOUND state with an IPv6
+ address having lease time 0 on the Passive firewall.
+
+ |
+
|
+ PAN-207616
+ |
+
+
+ On the Panorama management server, after selecting managed firewalls
+ and creating a new Tag () the managed firewalls are automatically unselected and any new tag
+ created is applied to the managed firewalls for which you initially
+ created the new tag.
+
+
+ Workaround: Select and then unselect the managed
+ firewalls for which you created a new tag.
+
+ |
+
|
+ PAN-207611
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the
+ Passive firewall sometimes crashes.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-207040
+ |
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade
+ from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
+ commits fail and SD-WAN devices on Panorama have no Virtual Router
+ name.
+
+ |
+
|
+ PAN-206913
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls,
+ releasing the IPv6 address from the client (using Release in the UI or
+ using the
+ request dhcp client ipv6 release all
+ CLI command) releases the IPv6 address from the Active firewall, but
+ not the Passive firewall.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the
+ configd process crashes. This
+ results in the Dedicated Log Collector losing connectivity to Panorama
+ despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-206416
+ |
+
+
+ On the Panorama management server, no data filtering log () is generated when the managed firewall loses connectivity to the
+ following cloud services, and as a result fails to forward matched
+ traffic for inspection.
+
+
|
+
|
+ PAN-206315
+ |
+
+
+ (PA-1420 firewall only) In an active/passive
+ high availability (HA) configuration, the
+ show session info CLI command
+ shows that the passive firewall has packet rate and throughput values.
+ The packet rate and throughput of the passive firewall should be zero
+ since it is not processing traffic.
+
+ |
+
|
+ PAN-205009
+ |
+
+
+ (PA-1420 firewall only) In an active/passive
+ high availability (HA) configuration, the
+ show interface all,
+ show-high availability interface ha2, and
+ show high-availability all CLI
+ commands display the HSCI port state as unknown on both the active and
+ passive firewalls.
+
+ |
+
|
+ PAN-204689
+ |
+
+
+ Upon upgrade to PAN-OS 11.0.1, the following GlobalProtect settings do
+ not work:
+
+
|
+
|
+ PAN-201910
+ |
+
+
+ PAN-OS security profiles might consume a large amount of memory
+ depending on the profile configuration and quantity. In some cases,
+ this might reduce the number of supported security profiles below the
+ stated maximum for a given platform.
+
+ |
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-197097
+ |
+
+
+ Large Scale VPN (LSVPN) does not support IPv6 addresses on the
+ satellite firewall.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-195342
+ |
+
+
+ On the Panorama management server, Context Switch fails when you try
+ to Context Switch from a managed firewall running PAN-OS 10.1.7 or
+ earlier release back to Panorama and the following error is displayed:
+
+
+ Could not find start token '@start@'
+
+ |
+
|
+ PAN-194978
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , hovering the mouse over a power over Ethernet (PoE)
+ Link State icon does not display
+ link speed and link duplex details.
+
+ |
+
|
+ PAN-194424
+ |
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS
+ 10.2.2 while having a log interface configured can cause both the log
+ interface and the management interface to remain connected to the log
+ collector.
+
+
+ Workaround: Restart the log receiver service by
+ running the following CLI command:
+
+
+
+
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-184708
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
|
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-171938
+ |
+
+
+ No results are displayed when you
+ Show Application Filter for a
+ Security policy rule ().
+
+ |
+
|
+ PAN-164885
+ |
+
+
+ On the Panorama management server, pushes to managed firewalls (
+ or Commit and Push) may fail when an
+ EDL () is configured to
+ Check for updates every 5 minutes
+ due to the commit and EDL fetch processes overlapping. This is more
+ likely to occur when multiple EDLs are configured to check for updates
+ every 5 minutes.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-317755
+
+ This issue is now resolved. See PAN-OS 11.1.16 Addressed Issues.
+
+ |
+
+
+ A selective push from Panorama to managed firewalls fail when plugin
+ configurations reference certain Panorama settings, such as
+ log-collector groups or access domains.
+
+ |
+
|
+ PAN-314624
+
+ This issue is now resolved. See PAN-OS 11.1.16 Addressed Issues.
+
+ |
+
+
+ The
+ useridd
+ process restarts when you attempt to dump the Host Information Profile
+ (HIP) database using the
+ debug user-id dump hip-profile-database
+ command. This occurs while the firewall is actively processing HIP
+ reports, such as logouts or updates. The command initially hangs and
+ times out before the
+ useridd
+ process restarts.
+
+ |
+
|
+ PAN-303959
+ |
+
+
+ Traffic that is incorrectly identified as unknown-tcp/unknown-udp
+ eventually drops due to an App-ID resource limitation issue.
+
+ |
+
|
+ PAN-292202
+ |
+
+
+ The system logs repeatedly displayed the alert
+ Clearing snmpd.log due to log overflow
+ due to the SNMP counters rolling over. This is a benign message and
+ does not impact device functionality.
+
+ |
+
|
+ PAN-289432
+ |
+
+
+ Generating a certificate with the
+ block-private-key yes command on
+ Panorama fails with the error:
+
+
+ Could not get parameters for double encryption.
+ This occurred when the certificate was signed by an external
+ Certificate Authority (CA).
+
+ |
+
|
+ PAN-286848
+ |
+
+
+ ECMP incorrectly balances sessions across links based on the
+ configured metric, which leads to an imbalance in traffic distribution
+ and results in traffic assignment shifting disproportionately to
+ routes with lower metrics.
+
+ |
+
|
+ PAN-286496
+ |
+
+
+ (NGFW Clusters) URL-continue and override
+ continue selections will function like a general URL-block action.
+
+ |
+
|
+ PAN-285894
+ |
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may
+ occur, which could result in firewall reboots.
+
+
+ Workaround: Disable the Preserve Pre-NAT feature
+ using the
+ set deviceconfig setting preserve-prenat-feature no
+ CLI command.
+
+ |
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-279415
+ |
+
+
+ Service routes configured for a data plane interface might incorrectly
+ route traffic through the management plane interface instead. This
+ issue impacts Syslog and CRL status traffic when the service route
+ lacks a specific destination custom service route.
+
+ |
+
|
+ PAN-275047
+ |
+
+
+ (VM-Series firewalls only) After an upgrade,
+ the firewall is unable to send logs to the Strata Logging Service
+ (SLS) when using a specific proxy server, and the SSL connection
+ status displays as failed when attempting to forward logs through the
+ web proxy.
+
+ |
+
|
+ PAN-262556
+ |
+
+
+ The ElasticSearch cluster health status might continue to remain
+ yellow for an extended period after upgrading to PAN-OS 11.1
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-254240
+ |
+
+
+ In the event of an HSCI flap on an NGFW cluster node, traffic
+ reconvergence takes three to four seconds.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
|
+ PAN-251551
+ |
+
+
+ When an NGFW cluster agent crashes and doesn't recover, leader
+ election will take approximately 45 seconds to begin and traffic
+ failover will occur during that time.
+
+ |
+
|
+ PAN-250903
+ |
+
+
+ In a congestion scenario on an HSCI port of an NGFW cluster node, the
+ QoS priorities of cross node traffic streams might be reversed if
+ you're using the default QoS profile with class1 to class8 set as high
+ to low.
+
+ |
+
|
+ PAN-247974
+ |
+
+
+ LACP flap is expected during a device failover in an NGFW cluster due
+ to an L2 ctrld restart on the new leader node.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-224502
+ |
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0
+ might take longer than expected.
+
+ |
+
|
+ PAN-220180
+ |
+
+
+ Configured botnet reports () are not generated.
+
+ |
+
|
+ PAN-207733
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if
+ the DHCPv6 server goes down, after the lease time expires, the DHCPv6
+ client should enter SOLICIT state on both the Active and Passive
+ firewalls. Instead, the client is stuck in BOUND state with an IPv6
+ address having lease time 0 on the Passive firewall.
+
+ |
+
|
+ PAN-207611
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the
+ Passive firewall sometimes crashes.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-207040
+ |
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade
+ from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
+ commits fail and SD-WAN devices on Panorama have no Virtual Router
+ name.
+
+ |
+
|
+ PAN-206913
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls,
+ releasing the IPv6 address from the client (using Release in the UI or
+ using the
+ request dhcp client ipv6 release all
+ CLI command) releases the IPv6 address from the Active firewall, but
+ not the Passive firewall.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-194978
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , hovering the mouse over a power over Ethernet (PoE)
+ Link State icon does not display
+ link speed and link duplex details.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-184708
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
|
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-303959
+ |
+
+
+ Traffic that is incorrectly identified as unknown-tcp/unknown-udp
+ eventually drops due to an App-ID resource limitation issue.
+
+ |
+
|
+ PAN-292202
+ |
+
+
+ The system logs repeatedly displayed the alert
+ Clearing snmpd.log due to log overflow
+ due to the SNMP counters rolling over. This is a benign message and
+ does not impact device functionality.
+
+ |
+
|
+ PAN-289432
+ |
+
+
+ Generating a certificate with the
+ block-private-key yes command on
+ Panorama fails with the error:
+
+
+ Could not get parameters for double encryption.
+ This occurred when the certificate was signed by an external
+ Certificate Authority (CA).
+
+ |
+
|
+ PAN-286848
+ |
+
+
+ ECMP incorrectly balances sessions across links based on the
+ configured metric, which leads to an imbalance in traffic distribution
+ and results in traffic assignment shifting disproportionately to
+ routes with lower metrics.
+
+ |
+
|
+ PAN-286496
+ |
+
+
+ (NGFW Clusters) URL-continue and override
+ continue selections will function like a general URL-block action.
+
+ |
+
|
+ PAN-285894
+ |
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may
+ occur, which could result in firewall reboots.
+
+
+ Workaround: Disable the Preserve Pre-NAT feature
+ using the
+ set deviceconfig setting preserve-prenat-feature no
+ CLI command.
+
+ |
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-279415
+ |
+
+
+ Service routes configured for a data plane interface might incorrectly
+ route traffic through the management plane interface instead. This
+ issue impacts Syslog and CRL status traffic when the service route
+ lacks a specific destination custom service route.
+
+ |
+
|
+ PAN-275047
+ |
+
+
+ (VM-Series firewalls only) After an upgrade,
+ the firewall is unable to send logs to the Strata Logging Service
+ (SLS) when using a specific proxy server, and the SSL connection
+ status displays as failed when attempting to forward logs through the
+ web proxy.
+
+ |
+
|
+ PAN-262556
+ |
+
+
+ The ElasticSearch cluster health status might continue to remain
+ yellow for an extended period after upgrading to PAN-OS 11.1
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-254240
+ |
+
+
+ In the event of an HSCI flap on an NGFW cluster node, traffic
+ reconvergence takes three to four seconds.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
|
+ PAN-251551
+ |
+
+
+ When an NGFW cluster agent crashes and doesn't recover, leader
+ election will take approximately 45 seconds to begin and traffic
+ failover will occur during that time.
+
+ |
+
|
+ PAN-250903
+ |
+
+
+ In a congestion scenario on an HSCI port of an NGFW cluster node, the
+ QoS priorities of cross node traffic streams might be reversed if
+ you're using the default QoS profile with class1 to class8 set as high
+ to low.
+
+ |
+
|
+ PAN-247974
+ |
+
+
+ LACP flap is expected during a device failover in an NGFW cluster due
+ to an L2 ctrld restart on the new leader node.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-224502
+ |
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0
+ might take longer than expected.
+
+ |
+
|
+ PAN-220180
+ |
+
+
+ Configured botnet reports () are not generated.
+
+ |
+
|
+ PAN-207733
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if
+ the DHCPv6 server goes down, after the lease time expires, the DHCPv6
+ client should enter SOLICIT state on both the Active and Passive
+ firewalls. Instead, the client is stuck in BOUND state with an IPv6
+ address having lease time 0 on the Passive firewall.
+
+ |
+
|
+ PAN-207611
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the
+ Passive firewall sometimes crashes.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-207040
+ |
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade
+ from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
+ commits fail and SD-WAN devices on Panorama have no Virtual Router
+ name.
+
+ |
+
|
+ PAN-206913
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls,
+ releasing the IPv6 address from the client (using Release in the UI or
+ using the
+ request dhcp client ipv6 release all
+ CLI command) releases the IPv6 address from the Active firewall, but
+ not the Passive firewall.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-194978
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , hovering the mouse over a power over Ethernet (PoE)
+ Link State icon does not display
+ link speed and link duplex details.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-184708
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
|
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
admin> show panorama-status
+ >admin> debug software restart process management-server
+ >|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-6271
+ |
+
+
+ A WildFire cluster node that has been configured with an IPv6
+ management port might not display the signature status when using the
+ following CLI:
+ show wildfire global signature-status sha256 equal
+ <SHA_256_Value>
+
+
+ Workaround: Gracefully restart the affected
+ Wildfire cluster nodes.
+
+ |
+
|
+ WF500-6259
+ |
+
+
+ When a WildFire cluster node configured as a server or worker node is
+ rebooted, issuing the CLI command,
+ global sample-status does not update
+ the samples processed list on the active controller and non-server
+ worker nodes.
+
+
+ Workaround: Gracefully restart the affected
+ WildFire active controller and passive controller in the cluster.
+
+ |
+
|
+ WF500-6270
+ |
+
+
+ The WildFire cluster server and worker nodes might disconnect from the
+ Wildfire cluster management network, resulting in a notifier process
+ exit on WildFire cluster controllers.
+
+
+ Workaround: Gracefully restart the WildFire
+ cluster node where the process exit occurred.
+
+ |
+
|
+ WF500-6222
+ |
+
+
+ When WildFire secure cluster communication is enabled using a custom
+ DNS, the cluster formation might fail due to cluster management
+ communication issues.
+
+
+ Workaround: Do not configure a custom DNS when
+ WildFire secure cluster communication is enabled.
+
+ |
+
|
+ WF500-6176
+ |
+
+
+ When Panorama is used to manage a WildFire cluster, switchover
+ functionality for active and passive controller roles is not
+ available.
+
+ |
+
|
+ PAN-317755
+ |
+
+
+ A selective push from Panorama to managed firewalls fail when plugin
+ configurations reference certain Panorama settings, such as
+ log-collector groups or access domains.
+
+
+ Workaround: Perform a full push instead of a
+ selective push as a temporary measure. Note that selective push
+ attempts will continue to fail until you upgrade to the release that
+ includes the fix.
+
+ |
+
|
+ PAN-308564
+ |
+
+
+ Packets are dropped on SD-WAN interfaces if they require fragmentation
+ for an interface but have the
+ Don't Fragment (DF) bit set. This
+ results in unexpected packet drops. This affects client to server
+ sessions when using SD-WAN for NGFW.
+
+
+ Workaround: Allow fragmenting packets with DF bit
+ set (debug dataplane set ip4-ignore-df yes).
+
+ |
+
|
+ PAN-308507
+ |
+
+
+ Strata Logging Service (SLS) log-forwarding streams intermittently
+ show as inactive. When checking the status of log-forwarding
+ connections, one or more streams are reported as inactive. Restarting
+ the log-receiver process temporarily
+ resolves the issue, but the streams become inactive again after
+ approximately 1-2 hours. This intermittent inactivity results in log
+ loss.
+
+ |
+
|
+ PAN-295645
+ |
+
+
+ When a WildFire cluster is configured centrally using Panorama, it
+ initiates a series of processes, including a software install and
+ reboot, in an order that will leave the resulting WildFire cluster in
+ an unusable state.
+
+ |
+
|
+ PAN-288525
+ |
+
+
+ When the Enterprise DLP data filtering profile is configured with a
+ Block action and is used in
+ conjunction with Advanced Threat Prevention, which is configured with
+ an action of reset-both,
+ reset-server,
+ reset-client, or
+ drop for the
+ HTTP Command and Control detector,
+ Dropbox file uploads that exceed the maximum configured file size
+ action will fail.
+
+
+ Workaround: Configure the Advanced Threat
+ Prevention Inline Cloud analysis () action for the HTTP Command and Control detector to
+ alert.
+
+ |
+
|
+ PAN-285061
+ |
+
+
+ When Enterprise DLP is enabled, file uploads might unexpectedly fail
+ when 100 continue response is received from the server during file
+ uploads.
+
+ |
+
|
+ PAN-284700
+ |
+
+
+ File downloads for content encoded with zstd (Zstandard), such as
+ specific content from box.com, fail when using Enterprise DLP because
+ zstd decompression is not supported in PAN-OS.
+
+ |
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-260212
+ |
+
+
+ When viewing Applications (), child App-IDs may be listed under the incorrect container App-ID.
+
+ |
+
|
+ PAN-259853
+ |
+
+
+ When the DHCP server is enabled for GlobalProtect, the commit error
+ message is not properly displayed when
+ Any is selected as the source
+ interface in the service router configuration (
+ ).
+
+ |
+
|
+ PAN-259423
+ |
+
+
+ When the GlobalProtect DHCP feature is enabled with two primary DHCP
+ servers on the GlobalProtect gateway, the gpsvc gets stuck during
+ renewal and after HA failover.
+
+ |
+
|
+ PAN-254108
+ |
+
+
+ when upgrading or downgrading a Panorama management server (), managed device (), or standalone firewall (), Base Releases and
+ Preferred Releases settings are
+ checked (enabled) by default and cause no PAN-OS software images to
+ display.
+
+
+ Workaround: Uncheck (disable)
+ Base Releases or
+ Preferred Releases to display either
+ the available base PAN-OS or preferred PAN-OS releases available to
+ download and install.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
|
+ PAN-252661
+ |
+
+
+ If you change the service route of gp-ip-mgmt in
+ Device > Setup > Services > Service Features >
+ gp-ip-mgmt
+ and Commit, the change won’t take effect.
+ gp-ip-mgmt continues to use the last committed service route.
+
+
+ Workaround: After you change the service route
+ interface for gp-ip-mgmt, navigate to either a GlobalProtect portal or
+ gateway, click OK to save the configuration, and
+ Commit the changes. This commit will include the
+ service route change.
+
+ |
+
|
+ PAN-250246
+ |
+
+
+ Panorama and the firewall display inconsistent IP addresses for
+ dynamic address group members after manually syncing.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-248836
+ |
+
+
+ The Advanced DNS Security trial license and trial license information
+ cannot be activated and viewed, respectively, on a managed firewall
+ (with expired or active status) from Panorama. These tasks can only be
+ performed on the firewall.
+
+ |
+
|
+ PAN-247728
+
+ This issue is now resolved. See PAN-OS 11.2.1 Addressed Issues
+
+ |
+
+
+ When Advanced Routing is enabled, IP multicast is not supported. An
+ upcoming version will provide support for this feature. Customers who
+ have multicast configured or who plan to deploy multicast routing
+ should not upgrade to 11.2.0. Additionally, when Advanced Routing is
+ enabled, the BGP dampening configuration isn't applied to any peers or
+ peer group; the configuration is preserved but has no effect on BGP.
+ Customers can use BGP even if they have applied a Dampening profile to
+ a specific set of peers. The issue doesn't affect any other BGP
+ features.
+
+ |
+
|
+ PAN-241994
+ |
+
+
+ The VMX hardware version was upgraded from vmx-10 to vmx-15 on ESXi
+ and NSX-T. Support for vmx-15 is supported on ESXi 6.7 U2 and onwards.
+ Palo Alto Networks recommends that you upgrade your ESXi version if it
+ is less than 6.7 U2. For more information, see the
+ compatibility matrix.
+
+ |
+
|
+ PAN-239612
+ |
+
+
+ When the firewall is running PAN-OS 11.2.0 and Advanced Routing is
+ enabled, DHCPv4 relay agent functions successfully, but DHCPv6 relay
+ agent doesn't work.
+
+ |
+
|
+ PAN-237106
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-236649
+ |
+
+
+ If you change the configuration of a firewall acting as a PPPoEv4 or
+ PPPoEv6 client, old routes from the Forwarding Information Base (FIB)
+ and route table for an inherited configuration with dynamic-identifier
+ or client remain visible. Old routes also remain visible for an
+ inherited interface when you execute the CLI command,
+ show interface all.
+
+
+ Workaround: Unconfigure and configure the
+ Inherited Interface.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-6271
+ |
+
+
+ A WildFire cluster node that has been configured with an IPv6
+ management port might not display the signature status when using the
+ following CLI:
+ show wildfire global signature-status sha256 equal
+ <SHA_256_Value>
+
+
+ Workaround: Gracefully restart the affected
+ Wildfire cluster nodes.
+
+ |
+
|
+ WF500-6259
+ |
+
+
+ When a WildFire cluster node configured as a server or worker node is
+ rebooted, issuing the CLI command,
+ global sample-status does not update
+ the samples processed list on the active controller and non-server
+ worker nodes.
+
+
+ Workaround: Gracefully restart the affected
+ WildFire active controller and passive controller in the cluster.
+
+ |
+
|
+ WF500-6270
+ |
+
+
+ The WildFire cluster server and worker nodes might disconnect from the
+ Wildfire cluster management network, resulting in a notifier process
+ exit on WildFire cluster controllers.
+
+
+ Workaround: Gracefully restart the WildFire
+ cluster node where the process exit occurred.
+
+ |
+
|
+ WF500-6222
+ |
+
+
+ When WildFire secure cluster communication is enabled using a custom
+ DNS, the cluster formation might fail due to cluster management
+ communication issues.
+
+
+ Workaround: Do not configure a custom DNS when
+ WildFire secure cluster communication is enabled.
+
+ |
+
|
+ WF500-6176
+ |
+
+
+ When Panorama is used to manage a WildFire cluster, switchover
+ functionality for active and passive controller roles is not
+ available.
+
+ |
+
|
+ PAN-317755
+ |
+
+
+ A selective push from Panorama to managed firewalls fail when plugin
+ configurations reference certain Panorama settings, such as
+ log-collector groups or access domains.
+
+
+ Workaround: Perform a full push instead of a
+ selective push as a temporary measure. Note that selective push
+ attempts will continue to fail until you upgrade to the release that
+ includes the fix.
+
+ |
+
|
+ PAN-308564
+ |
+
+
+ Packets are dropped on SD-WAN interfaces if they require fragmentation
+ for an interface but have the
+ Don't Fragment (DF) bit set. This
+ results in unexpected packet drops. This affects client to server
+ sessions when using SD-WAN for NGFW.
+
+
+ Workaround: Allow fragmenting packets with DF bit
+ set (debug dataplane set ip4-ignore-df yes).
+
+ |
+
|
+ PAN-308507
+ |
+
+
+ Strata Logging Service (SLS) log-forwarding streams intermittently
+ show as inactive. When checking the status of log-forwarding
+ connections, one or more streams are reported as inactive. Restarting
+ the log-receiver process temporarily
+ resolves the issue, but the streams become inactive again after
+ approximately 1-2 hours. This intermittent inactivity results in log
+ loss.
+
+ |
+
|
+ PAN-295645
+ |
+
+
+ When a WildFire cluster is configured centrally using Panorama, it
+ initiates a series of processes, including a software install and
+ reboot, in an order that will leave the resulting WildFire cluster in
+ an unusable state.
+
+ |
+
|
+ PAN-288525
+ |
+
+
+ When the Enterprise DLP data filtering profile is configured with a
+ Block action and is used in
+ conjunction with Advanced Threat Prevention, which is configured with
+ an action of reset-both,
+ reset-server,
+ reset-client, or
+ drop for the
+ HTTP Command and Control detector,
+ Dropbox file uploads that exceed the maximum configured file size
+ action will fail.
+
+
+ Workaround: Configure the Advanced Threat
+ Prevention Inline Cloud analysis () action for the HTTP Command and Control detector to
+ alert.
+
+ |
+
|
+ PAN-285061
+ |
+
+
+ When Enterprise DLP is enabled, file uploads might unexpectedly fail
+ when 100 continue response is received from the server during file
+ uploads.
+
+ |
+
|
+ PAN-284700
+ |
+
+
+ File downloads for content encoded with zstd (Zstandard), such as
+ specific content from box.com, fail when using Enterprise DLP because
+ zstd decompression is not supported in PAN-OS.
+
+ |
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-260212
+ |
+
+
+ When viewing Applications (), child App-IDs may be listed under the incorrect container App-ID.
+
+ |
+
|
+ PAN-259853
+ |
+
+
+ When the DHCP server is enabled for GlobalProtect, the commit error
+ message is not properly displayed when
+ Any is selected as the source
+ interface in the service router configuration (
+ ).
+
+ |
+
|
+ PAN-259423
+ |
+
+
+ When the GlobalProtect DHCP feature is enabled with two primary DHCP
+ servers on the GlobalProtect gateway, the gpsvc gets stuck during
+ renewal and after HA failover.
+
+ |
+
|
+ PAN-254108
+ |
+
+
+ when upgrading or downgrading a Panorama management server (), managed device (), or standalone firewall (), Base Releases and
+ Preferred Releases settings are
+ checked (enabled) by default and cause no PAN-OS software images to
+ display.
+
+
+ Workaround: Uncheck (disable)
+ Base Releases or
+ Preferred Releases to display either
+ the available base PAN-OS or preferred PAN-OS releases available to
+ download and install.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
|
+ PAN-252661
+ |
+
+
+ If you change the service route of gp-ip-mgmt in
+ Device > Setup > Services > Service Features >
+ gp-ip-mgmt
+ and Commit, the change won’t take effect.
+ gp-ip-mgmt continues to use the last committed service route.
+
+
+ Workaround: After you change the service route
+ interface for gp-ip-mgmt, navigate to either a GlobalProtect portal or
+ gateway, click OK to save the configuration, and
+ Commit the changes. This commit will include the
+ service route change.
+
+ |
+
|
+ PAN-250246
+ |
+
+
+ Panorama and the firewall display inconsistent IP addresses for
+ dynamic address group members after manually syncing.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-248836
+ |
+
+
+ The Advanced DNS Security trial license and trial license information
+ cannot be activated and viewed, respectively, on a managed firewall
+ (with expired or active status) from Panorama. These tasks can only be
+ performed on the firewall.
+
+ |
+
|
+ PAN-247728
+
+ This issue is now resolved. See PAN-OS 11.2.1 Addressed Issues
+
+ |
+
+
+ When Advanced Routing is enabled, IP multicast is not supported. An
+ upcoming version will provide support for this feature. Customers who
+ have multicast configured or who plan to deploy multicast routing
+ should not upgrade to 11.2.0. Additionally, when Advanced Routing is
+ enabled, the BGP dampening configuration isn't applied to any peers or
+ peer group; the configuration is preserved but has no effect on BGP.
+ Customers can use BGP even if they have applied a Dampening profile to
+ a specific set of peers. The issue doesn't affect any other BGP
+ features.
+
+ |
+
|
+ PAN-241994
+ |
+
+
+ The VMX hardware version was upgraded from vmx-10 to vmx-15 on ESXi
+ and NSX-T. Support for vmx-15 is supported on ESXi 6.7 U2 and onwards.
+ Palo Alto Networks recommends that you upgrade your ESXi version if it
+ is less than 6.7 U2. For more information, see the
+ compatibility matrix.
+
+ |
+
|
+ PAN-239612
+ |
+
+
+ When the firewall is running PAN-OS 11.2.0 and Advanced Routing is
+ enabled, DHCPv4 relay agent functions successfully, but DHCPv6 relay
+ agent doesn't work.
+
+ |
+
|
+ PAN-237106
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-236649
+ |
+
+
+ If you change the configuration of a firewall acting as a PPPoEv4 or
+ PPPoEv6 client, old routes from the Forwarding Information Base (FIB)
+ and route table for an inherited configuration with dynamic-identifier
+ or client remain visible. Old routes also remain visible for an
+ inherited interface when you execute the CLI command,
+ show interface all.
+
+
+ Workaround: Unconfigure and configure the
+ Inherited Interface.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-330836
+ |
+
+
+ (VM-Series software firewalls with 16 GB of memory and 16 vCPUs
+ only) Starting in PAN-OS 12.1.5, memory usage increases to approximately
+ 6 GB for firewalls running a maximum configuration, compared to
+ approximately 5 GB in PAN-OS 12.1.2. This increase eliminates the
+ available memory buffer, leaving no capacity to absorb additional
+ memory demand during peak load. The firewall may become unstable or
+ unresponsive under high-load conditions.
+
+
+ Firewalls operating with 12 dp cores, or processing more than 512K
+ sessions, are specifically at risk for memory issues. To ensure
+ continued stability for firewalls matching this criteria, Palo Alto
+ Networks recommends an increase of overall memory allocation by 2 GB.
+
+ |
+
|
+
+ PAN-317755This issue is now resolved. See
+ PAN-OS 12.1.7-h1 Addressed Issues
+
+ |
+
+
+ A selective push from Panorama to managed firewalls fail when plugin
+ configurations reference certain Panorama settings, such as
+ log-collector groups or access domains.
+
+
+ Workaround: Perform a full push instead of a
+ selective push as a temporary measure. Note that selective push
+ attempts will continue to fail until you upgrade to the release that
+ includes the fix.
+
+ |
+
|
+ PAN-312143
+ |
+
+
+ (Firewalls in active/passive high availability (HA) configurations
+ only) When attempting to synchronize the running configuration with an
+ HA peer, particularly during script runs involving different topology
+ builds (e.g., during a smoke runlist), the synchronization process
+ fails. This results in an error indicating that the running
+ configuration could not be synchronized with the HA peer.
+
+ |
+
|
+ PAN-311601
+ |
+
+
+ If the node is seen stuck with fault "session clearing fault". Node
+ reboot is the workaround to get the node back in online state after
+ all other fault conditions are removed.
+
+ |
+
|
+ PAN-310328
+ |
+
+
+ If the node is seen stuck with fault "session clearing fault". Node
+ reboot is the workaround to get the node back in online state after
+ all other fault conditions are removed.
+
+ |
+
|
+ PAN-300667
+ |
+
+
+ Panorama cannot display Threat log entries (Monitor > Logs >
+ Threat) when the managed log collector is running a lower PAN-OS
+ release than Panorama. Workaround: Upgrade the log collectors to the
+ same version as Panorama.
+
+ |
+
|
+ PAN-300230
+ |
+
+
+ (NGFW Cluster) In an NGFW cluster, your pings to the HSCI-B link might
+ fail, even when the link indicates it is up. In the event that the
+ HSCI-A link is brought down or unplugged, the cluster node will
+ transition to failed state, avoiding split brain as both HSCI links
+ are down in this case. Workaround: Reboot the cluster node to resolve
+ the HSCI-B ping issue.
+
+ |
+
|
+ PAN-299562
+ |
+
+
+ When a client sends a Client Hello with Transport Layer Security (TLS)
+ 1.3 or TLS 1.2, using only the p-192 elliptic curve and some
+ non-perfect forward secrecy (PFS) ciphers, the firewall discards the
+ Client Hello. The firewall should allow the connection to proceed
+ using TLS 1.2, maintaining backward compatibility with previous
+ releases.
+
+ |
+
|
+ PAN-298083
+ |
+
+
+ Draft for review: After you change the system mode on an M-700
+ appliance from Panorama mode to PAN-DB private cloud mode, the snmpd
+ process fails to work.
+
+ |
+
|
+ PAN-295946
+ |
+
+
+ When a Panorama appliance (running PAN-OS 12.1.2 or higher) manages
+ firewalls running PAN-OS versions lower than 12.1.2, and an NTP server
+ configuration template includes SHA256 or SHA512 as the authentication
+ mechanism, pushing this template to the firewalls running PAN-OS
+ versions lower than 12.1.2 will cause the commit operation to fail.
+ Workaround: Create two separate templates: one for firewalls running
+ PAN-OS 12.1.2 or higher (which can include SHA256/SHA512
+ authentication) and another for firewalls running PAN-OS versions
+ lower than 12.1.2 (which should use other authentication algorithms
+ such as SHA1, MD5, or Autokey). Then, push the appropriate template to
+ the corresponding devices from Panorama.
+
+ |
+
|
+ PAN-292601
+ |
+
+
+ PAN-OS 12.1.2 and later 12.1 releases support a Load Balanced DNS
+ configuration for an address object. If there are two address objects
+ with same FQDN, but one object has Load Balanced DNS enabled and other
+ object has Load Balanced DNS disabled, then the policy match for the
+ removed IP addresses doesn't work as expected. Workaround: Enable (or
+ disable) Load Balanced DNS consistently for an FQDN that is used with
+ multiple address objects.
+
+ |
+
|
+ PAN-289524
+ |
+
+
+ In PAN-OS 12.1.2 and later 12.1 releases, PAN-OS can obtain resolved
+ IP addresses from a Load balanced DNS server and use them in a policy
+ match. However, this functionality does not work as intended when the
+ DNS cache reuse flag is enabled. When the DNS cache reuse flag is
+ enabled, the DNS resolution works as if the Load balanced DNS flag
+ (for an Address object) is disabled.
+
+ |
+
|
+ PAN-283028
+ |
+
+
+ The following error is thrown when an existing template overrides the
+ SD-WAN configuration followed by the commit and push from Panorama to
+ the firewall.
+
+
+ BGP is invalid. AS number does not fit in 2 byte AS format
+
+
+ This issue occurs because different AS formats are present on the
+ Panorama and the firewall (the firewall configuration is generated by
+ the SD-WAN plugin). That is, both the hub and branch firewall must
+ have the same AS format in hub-and-spoke topology. In full mesh
+ topology, all the firewalls must have the same AS format.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-330995
+ |
+
+
+ Within GCP NSI environments, egress traffic logs fail to accurately
+ reflect the designated NAT IP addresses.
+
+ |
+
|
+ PAN-330964
+ |
+
+
+ In PA-VM deployed on GCP instances, it is observed that the gVNIC
+ interfaces appear inactive after enabling jumbo frames.
+
+ |
+
|
+ PAN-330906
+ |
+
+
+ On Panorama, the configuration Push Scope might not include the shared
+ Devices object entries, even though
+ these objects are visible in the staged configuration changes for the
+ specified administrator and device group.
+
+ |
+
|
+ PAN-330902
+ |
+
+
+ After restarting MongoDB (mdb) on Panorama using the
+ request mongo set mongo-update-sort-limit
+ CLI command, push to devices (both full push and selective push)
+ fails.
+
+
+ Workaround: Restart
+ configd on Panorama.
+
+ |
+
|
+ PAN-330836
+ |
+
+
+ (VM-Series software firewalls with 16 GB of memory and 16 vCPUs
+ only) Starting in PAN-OS 12.1.5, memory usage increases to approximately
+ 6 GB for firewalls running a maximum configuration, compared to
+ approximately 5 GB in PAN-OS 12.1.2. This increase eliminates the
+ available memory buffer, leaving no capacity to absorb additional
+ memory demand during peak load. The firewall may become unstable or
+ unresponsive under high-load conditions.
+
+
+ Firewalls operating with 12 dp cores, or processing more than 512K
+ sessions, are specifically at risk for memory issues. To ensure
+ continued stability for firewalls matching this criteria, Palo Alto
+ Networks recommends an increase of overall memory allocation by 2 GB.
+
+ |
+
|
+ PAN-329146
+ |
+
+
+ Within GCP NSI environments, it is observed that the Prisma AIRS
+ license activates geneve parsing as a
+ default setting, permitting intraVPC traffic flow
+ regardless of NSI status. Hence, you will not be able to disable this
+ feature through CLI.
+
+ |
+
PAN-313669 |
+
+
+ (PA-5500 Series firewalls in cluster configurations only) When a
+ firewall node is removed from a PA-5500 Series cluster, after the
+ cluster commit and reboot, the node starts in standalone mode with a
+ default virtual wire (vwire) configuration loaded. This default
+ configuration is missing zone assignments for ports eth1/1 and eth1/2,
+ which causes commit operations to fail. Even if zones are manually
+ assigned to these ports, subsequent commit attempts will fail with a
+ "no UUId for rule1" error.
+
+
+ Workaround: To resolve this, either:
+
+
|
+
PAN-312143 |
+
+
+ (Firewalls in active/passive high availability (HA) configurations
+ only) When attempting to synchronize the running configuration with an
+ HA peer, particularly during script runs involving different topology
+ builds (e.g., during a smoke runlist), the synchronization process
+ fails. This results in an error indicating that the running
+ configuration could not be synchronized with the HA peer.
+
+ |
+
PAN-311601 |
+
+
+ If the node is seen stuck with fault "session clearing fault". Node
+ reboot is the workaround to get the node back in online state after
+ all other fault conditions are removed.
+
+ |
+
PAN-310328 |
+
+
+ If the node is seen stuck with fault "session clearing fault". Node
+ reboot is the workaround to get the node back in online state after
+ all other fault conditions are removed.
+
+ |
+
PAN-300667 |
+
+
+ Panorama cannot display Threat log entries (Monitor > Logs >
+ Threat) when the managed log collector is running a lower PAN-OS
+ release than Panorama. Workaround: Upgrade the log collectors to the
+ same version as Panorama.
+
+ |
+
PAN-300230 |
+
+
+ (NGFW Cluster) In an NGFW cluster, your pings to the HSCI-B link might
+ fail, even when the link indicates it is up. In the event that the
+ HSCI-A link is brought down or unplugged, the cluster node will
+ transition to failed state, avoiding split brain as both HSCI links
+ are down in this case. Workaround: Reboot the cluster node to resolve
+ the HSCI-B ping issue.
+
+ |
+
PAN-299562 |
+
+
+ When a client sends a Client Hello with Transport Layer Security (TLS)
+ 1.3 or TLS 1.2, using only the p-192 elliptic curve and some
+ non-perfect forward secrecy (PFS) ciphers, the firewall discards the
+ Client Hello. The firewall should allow the connection to proceed
+ using TLS 1.2, maintaining backward compatibility with previous
+ releases.
+
+ |
+
PAN-298083 |
+
+
+ Draft for review: After you change the system mode on an M-700
+ appliance from Panorama mode to PAN-DB private cloud mode, the snmpd
+ process fails to work.
+
+ |
+
PAN-295946 |
+
+
+ When a Panorama appliance (running PAN-OS 12.1.2 or higher) manages
+ firewalls running PAN-OS versions lower than 12.1.2, and an NTP server
+ configuration template includes SHA256 or SHA512 as the authentication
+ mechanism, pushing this template to the firewalls running PAN-OS
+ versions lower than 12.1.2 will cause the commit operation to fail.
+ Workaround: Create two separate templates: one for firewalls running
+ PAN-OS 12.1.2 or higher (which can include SHA256/SHA512
+ authentication) and another for firewalls running PAN-OS versions
+ lower than 12.1.2 (which should use other authentication algorithms
+ such as SHA1, MD5, or Autokey). Then, push the appropriate template to
+ the corresponding devices from Panorama.
+
+ |
+
PAN-293718 |
+
+
+ Draft for review: When high speed logging is enabled on a PA-5560
+ device, the expected warning message is not displayed on the web
+ interface. This prevents administrators from being notified that logs
+ can only be viewed from Panorama.
+
+ |
+
PAN-292601 |
+
+
+ PAN-OS 12.1.2 and later 12.1 releases support a Load Balanced DNS
+ configuration for an address object. If there are two address objects
+ with same FQDN, but one object has Load Balanced DNS enabled and other
+ object has Load Balanced DNS disabled, then the policy match for the
+ removed IP addresses doesn't work as expected. Workaround: Enable (or
+ disable) Load Balanced DNS consistently for an FQDN that is used with
+ multiple address objects.
+
+ |
+
PAN-289524 |
+
+
+ In PAN-OS 12.1.2 and later 12.1 releases, PAN-OS can obtain resolved
+ IP addresses from a Load balanced DNS server and use them in a policy
+ match. However, this functionality does not work as intended when the
+ DNS cache reuse flag is enabled. When the DNS cache reuse flag is
+ enabled, the DNS resolution works as if the Load balanced DNS flag
+ (for an Address object) is disabled.
+
+ |
+
PAN-283028 |
+
+
+ The following error is thrown when an existing template overrides the
+ SD-WAN configuration followed by the commit and push from Panorama to
+ the firewall.
+
+
+ BGP is invalid. AS number does not fit in 2 byte AS format
+
+
+ This issue occurs because different AS formats are present on the
+ Panorama and the firewall (the firewall configuration is generated by
+ the SD-WAN plugin). That is, both the hub and branch firewall must
+ have the same AS format in hub-and-spoke topology. In full mesh
+ topology, all the firewalls must have the same AS format.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
| PAN-332943 | +
+
+ When you upgrade a PA-450R, PA-450R-5G, PA-410R, or PA-410R-5G
+ firewall to PAN-OS 12.2.2 from an earlier release with Fail-to-Wire
+ enabled, subsequent manual commits fail with the following validation
+ error: network -> interface -> fail-open is invalid. This occurs
+ because PAN-OS 12.2.2 introduced a configuration schema change for the
+ Fail-to-Wire feature that is not automatically migrated during
+ upgrade. Fail-to-Wire also does not function correctly after the
+ upgrade.
+
+
+ Workaround:Remove and re-add the Fail-to-Wire
+ configuration.
+
+
+ delete network interface fail-open
+
+ commit
+
+ set network interface fail-open
+
+ commit
+ |
+
| PAN-332874 | +
+
+ On 5G firewalls, Zero Touch Provisioning (ZTP) over cellular does not
+ complete when the cellular carrier MTU is 1428. During ZTP, the
+ firewall does not correctly account for cellular tunnel header
+ overhead when negotiating the TCP maximum segment size (MSS). The
+ firewall advertises an MSS value that is too large for the 1428 MTU
+ cellular link, causing the certificate server's response packets to
+ exceed the link MTU. The certificate fetch does not complete, and the
+ firewall does not finish provisioning.
+
+
+ This issue occurs when using a cellular connection with a
+ carrier-negotiated MTU of 1428, which is the standard MTU for cellular
+ wireless. ZTP process will succeed when carrier provided Network MTU
+ is greater than or equal to 1500.
+
+ |
+
| PAN-332576 | +
+
+ On HA pairs running PAN-OS 12.2.2, the useridd process may exhaust its
+ ID manager (type 17) when the passive firewall accumulates more than
+ 1,000,000 user entries. When this occurs, useridd consumes 100% CPU
+ and becomes unresponsive, causing commits to fail with the error
+ Management server failed to send phase 1 to client useridd or to stall
+ at 0%.
+
+ |
+
| PAN-332130 | +
+
+ On firewalls with cellular interfaces configured with parent and
+ sub-interfaces, APN authentication fails on sub-interfaces when the
+ PDP type is set to both (IPv4 and IPv6). Data sessions on the parent
+ interface establish successfully for both IPv4 and IPv6, but
+ sub-interfaces fail to bring up their data sessions when using PAP or
+ CHAP authentication with PDP type both.
+
+
+ Workaround: Set the PDP type to IPv4 only on
+ sub-interfaces.
+
+ |
+
| PAN-331987 | +
+
+ (PA-5450, PA-5500, and PA-7500 firewalls with PAN-OS Shield enabled)
+ When connecting to GlobalProtect Portal or Gateway, users receive a
+ `Portal unreachable` error. GlobalProtect connections are frequently
+ unsuccessful, though they may connect successfully after multiple
+ attempts.
+
+
+ Workaround: Change the session distribution policy
+ to Round-robin.
+
+ |
+
| PAN-331722 | +
+
+ On PA-54R-POE (BH/Eagle) firewalls, the PAN-S-SFP-100BASE-FX
+ transceiver on fiber interfaces does not link up when the interface
+ link speed is explicitly set to 100 Mbps. The interface links up
+ correctly when the link speed is set to auto.
+
+
+ Workaround: Set the interface link speed to auto.
+
+ |
+
| PAN-331659 | +
+
+ Running the CLI command debug dataplane packet-path-test counter on
+ PAN-OS 12.2.2 returns a server error instead of counter output.
+
+ |
+
| PAN-330995 | +
+
+ Within GCP NSI environments, egress traffic logs fail to accurately
+ reflect the designated NAT IP addresses.
+
+ |
+
| PAN-330974 | +
+
+ If Azure hotplug events occur, the firewall may experience a crash and
+ data interfaces may transition to an unknown state, leading to traffic
+ disruption.
+
+ |
+
| PAN-330964 | +
+
+ In PA-VM deployed on GCP instances, gVNIC interfaces appear inactive
+ after enabling jumbo frames.
+
+ |
+
| PAN-330381 | +
+
+ When firewalls are configured in a cluster operating in default mode,
+ IP-Tag, User-Tag, and IP-Port mappings registered on the leader node
+ do not synchronize to the follower node. On the follower node,
+ commands such as `show object registered-ip all` and `show object
+ registered-user all` display no registered entries for these data
+ types, even though they are present on the leader. This prevents
+ Dynamic Address Group (DAG) and Dynamic User Group (DUG) based
+ security policies, which rely on these mappings, from functioning
+ correctly on the follower node. As a result, traffic routed through
+ the follower node does not match these policies, leading to an
+ inconsistent security posture across the cluster.
+
+
+ Workaround: Configure the firewall cluster to
+ operate in ICD mode. This enables the correct synchronization of
+ IP-Tag, User-Tag, and IP-Port mappings between the leader and follower
+ nodes.
+
+ |
+
| PAN-329606 | +
+
+ On PA-54R-POE (BH) firewalls, SCP export and import of cellular
+ firmware files fail from the CLI. Running
+ request cellular firmware scp-export or
+ request cellular firmware scp-import
+ returns a server error.
+
+ |
+
| PAN-329515 | +
+
+ When scheduling cellular firmware downloads on Panorama (Device Deployment > Cellular Firmware > Schedule), the Files and Devices fields are not populated in the UI for
+ PA-54R-POE-5G (BH/Eagle) devices. As a result, scheduled Download Only
+ and Download and Install operations for cellular firmware cannot be
+ configured through Panorama.
+
+ |
+
| PAN-329146 | +
+
+ Within GCP NSI environments, the Prisma® AIRS license activates geneve
+ parsing as a default setting, permitting intraVPC traffic flow
+ regardless of NSI status. You cannot disable this feature through CLI.
+
+ |
+
| PAN-328647 | +
+
+ When you configure ML7-CUID in a multi-vsys environment on PAN-OS
+ 12.2.2, data upload only supports the hub vsys configuration. When a
+ publisher is configured on a non-hub vsys, data from that vsys is not
+ uploaded to the cloud. All vsys must share the same segment
+ configuration for data upload to function correctly in this release.
+
+
+ Workaround: Configure the publisher on the hub
+ vsys and ensure all vsys use the same segment configuration.
+
+ |
+
| PAN-327958 | +
+
+ (PA-5450 Firewalls only) Basic authentication for web proxy is not
+ supported in 12.2.2.
+
+ |
+
| PAN-326791 | +
+
+ When a Hyperscale Security Fabric (HSF) cluster uses an offline
+ license, the system allows the removal of configuration and
+ uninstallation of the Security Fabric License (SFL) plugin. If the SFL
+ plugin is uninstalled under these conditions, subsequent undeploy
+ operations do not complete successfully.
+
+
+ Workaround: To allow the undeploy operation to
+ complete, reinstall the Security Fabric License (SFL) plugin.
+
+ |
+
| PAN-316972 | +
+
+ After downgrading a PA-520 firewall from PAN-OS 12.2.0 to 12.1.5 or
+ later 12.1.x releases, auto-commit repeatedly fails after the
+ downgrade completes, leaving the firewall unable to apply its
+ configuration automatically.
+
+ |
+
| PAN-314625 | +
+
+ The `useridd` process restarts when you attempt to dump the Host
+ Information Profile (HIP) database using the `debug user-id dump
+ hip-profile-database` command. This occurs while the firewall is
+ actively processing HIP reports, such as logouts or updates. The
+ command initially hangs and times out before the `useridd` process
+ restarts.
+
+ |
+
| PAN-313669 | +
+
+ (PA-5500 Series firewalls in cluster configurations only) When a
+ firewall node is removed from a PA-5500 Series cluster, after the
+ cluster commit and reboot, the node starts in standalone mode with a
+ default virtual wire (vwire) configuration loaded. This default
+ configuration is missing zone assignments for ports eth1/1 and eth1/2,
+ which causes commit operations to fail. Even if zones are manually
+ assigned to these ports, subsequent commit attempts fail with a "no
+ UUId for rule1" error.
+
+
+ Workaround: Manually assign zone configurations to
+ ports eth1/1 (for example, untrust) and eth1/2 (for example, trust),
+ then open and close security policy rule1 without making changes, and
+ commit. Alternatively, delete the default rule and the default virtual
+ wire Ethernet interfaces, then commit.
+
+ |
+
| PAN-312143 | +
+
+ (Firewalls in active/passive high availability (HA) configurations
+ only) When you synchronize the running configuration with an HA peer,
+ particularly during script runs involving different topology builds,
+ the synchronization process fails with an error indicating that the
+ running configuration could not be synchronized with the HA peer.
+
+ |
+
| PAN-311601 | +
+
+ If a node is stuck with a "session clearing fault," reboot the node to
+ restore it to an online state after all other fault conditions are
+ removed.
+
+ |
+
| PAN-310328 | +
+
+ If a node is stuck with a "session clearing fault," reboot the node to
+ restore it to an online state after all other fault conditions are
+ removed.
+
+ |
+
| PAN-309410 | +
+
+ Subscriber Identity and Equipment Identity values are missing from URL
+ filtering and Data Filtering logs for GTP mobility traffic.
+
+ |
+
| PAN-305734 | +
+
+ On firewalls with 5G cellular interfaces, the default auto MTU value
+ of 1428 bytes causes IP fragmentation errors and out-of-order packets,
+ resulting in degraded throughput performance on cellular connections.
+
+
+ Workaround: Manually set the cellular interface
+ MTU to 1500 bytes instead of using the auto MTU default.
+
+ |
+
| PAN-300667 | +
+
+ Panorama cannot display Threat log entries (Monitor > Logs > Threat) when the managed log collector is running a lower PAN-OS release
+ than Panorama.
+
+
+ Workaround: Upgrade the log collectors to the same
+ version as Panorama.
+
+ |
+
| PAN-300230 | +
+
+ (NGFW Cluster) In an NGFW cluster, pings to the HSCI-B link may fail
+ even when the link indicates it is up. If the HSCI-A link is brought
+ down or unplugged, the cluster node transitions to a failed state,
+ avoiding split brain because both HSCI links are down.
+
+
+ Workaround: Reboot the cluster node to resolve the
+ HSCI-B ping issue.
+
+ |
+
| PAN-299562 | +
+
+ When a client sends a Client Hello with TLS 1.3 or TLS 1.2 using only
+ the p-192 elliptic curve and some non-perfect forward secrecy (PFS)
+ ciphers, the firewall discards the Client Hello. The firewall should
+ allow the connection to proceed using TLS 1.2, maintaining backward
+ compatibility with previous releases.
+
+ |
+
| PAN-299286 | +
+
+ When configuring a PIM6 neighbor filter, you must include both the
+ primary and secondary IPv6 addresses of each neighbor in the prefix
+ list. Filtering on the primary address alone is not sufficient because
+ PIM6 Hello messages (Option 5) advertise both addresses to peers. A
+ filter that allows only the primary address will prevent neighbor
+ adjacency from forming.
+
+ |
+
| PAN-298083 | +
+
+ After you change the system mode on an M-700 appliance from Panorama
+ mode to PAN-DB private cloud mode, the snmpd process fails to work.
+
+ |
+
| PAN-295946 | +
+
+ When a Panorama appliance running PAN-OS 12.1.2 or later manages
+ firewalls running earlier PAN-OS versions, and an NTP server
+ configuration template includes SHA256 or SHA512 as the authentication
+ mechanism, pushing the template to firewalls running PAN-OS versions
+ earlier than 12.1.2 causes the commit operation to fail.
+
+
+ Workaround: Create two separate templates: one for
+ firewalls running PAN-OS 12.1.2 or later (which can include
+ SHA256/SHA512 authentication) and another for firewalls running
+ earlier PAN-OS versions (which should use SHA1, MD5, or Autokey). Push
+ the appropriate template to the corresponding devices from Panorama.
+
+ |
+
| PAN-294752 | +
+
+ In any 15-second interval, if connectivity (CI or management) on a
+ GW-Node (not P-Node) changes more than once, with each change
+ occurring on a different node and affecting a different link, the
+ cluster loses its leader, all routing protocols fail, and traffic is
+ blackholed if route changes occur in the network.
+
+
+ Workaround: Reboot nodes that are in a FAILED
+ state or suspend and unsuspend any online GW-Node (not P-Node).
+
+ |
+
| PAN-293718 | +
+
+ When high-speed logging is enabled on a PA-5560 firewall, the expected
+ warning message does not appear on the web interface. This prevents
+ you from being notified that logs can only be viewed from Panorama.
+
+ |
+
| PAN-292601 | +
+
+ PAN-OS 12.1.2 and later 12.1 releases support a load-balanced DNS
+ configuration for an address object. If two address objects share the
+ same FQDN but one has load-balanced DNS enabled and the other has it
+ disabled, the policy match for removed IP addresses does not work as
+ expected.
+
+
+ Workaround: Enable or disable load-balanced DNS
+ consistently for any FQDN used with multiple address objects.
+
+ |
+
| PAN-289524 | +
+
+ In PAN-OS 12.1.2 and later and PAN-OS 12.2.2 and later releases,
+ PAN-OS can obtain resolved IP addresses from a load-balanced DNS
+ server and use them in a policy match. However, this functionality
+ does not work as intended when the DNS cache reuse flag is enabled.
+ When the DNS cache reuse flag is enabled, the DNS resolution works as
+ if the load-balanced DNS flag (for an address object) is disabled.
+
+ |
+
| PAN-283028 | +
+
+ When an existing template overrides the SD-WAN configuration followed
+ by a commit and push from Panorama to the firewall, the following
+ error occurs: BGP is invalid. AS number does not fit in 2 byte AS
+ format. This issue occurs because different AS formats are present on
+ Panorama and the firewall (the firewall configuration is generated by
+ the SD-WAN plugin). In hub-and-spoke topology, both the hub and branch
+ firewall must have the same AS format. In full mesh topology, all
+ firewalls must have the same AS format.
+
+ |
+
| PLUG-23656 | +
+
+ In Software Firewall Licensed HSF environments, serial numbers linked
+ to stale entries can be manually released for reuse. This procedure
+ allows for the recovery of Software Firewall License credits when
+ virtual instances are deleted without being formally decommissioned.
+ For optimal resource management, it is recommended to utilize
+ Orchestration plugin workflows for VM operations rather than manual
+ intervention.
+
+ |
+